HTB - Mist
by ghostess256 - Friday March 29, 2024 at 10:25 PM
ok. i think i got this getST part to impersonate admin
https://dirkjanm.io/worst-of-both-worlds...elegation/

always get confused with impacket tool sets...
Reply
i got svc_cabackup.ccache now? i also got op_sharron shell so now? dm if you can
Reply
I am exporting the klist krbtgt ticket using mimikatz then converting it with msf to ccache but it's not working...

Can someone enlight please?
Reply
(Apr 04, 2024, 05:23 PM)cavour13 Wrote: i got svc_cabackup.ccache now?  i also got op_sharron shell so now? dm if you can

god plz anyone any help on relay part , petitpotam doesnt seem to work , how did y'all get the coercion to work , webdav isn't enabled and webclient service isn't even on the machine , how dafaq does the relay part work plz , i don't wnna slap in the leaked hash
Reply
V
(Apr 04, 2024, 10:22 PM)xss_02 Wrote: how do you guys are making proxychains / tunelling working? I trade for user (MS01) hash.
Dm me

either chisel client ip:port RConfusedocks
or ligolo-ng

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Scraping | https://breachforums.ai/Forum-Ban-Appeals if you feel this is incorrect.
Reply
Lets see this post.
Reply
(Apr 04, 2024, 10:22 PM)xss_02 Wrote: how do you guys are making proxychains / tunelling working? I trade for user (MS01) hash.
Dm me

u will trade ms01 hash or , the wayy to get ms01 hash ? xDDD hahaha
Reply
(Apr 05, 2024, 06:42 AM)Prometheuss Wrote:
(Apr 04, 2024, 10:22 PM)xss_02 Wrote: how do you guys are making proxychains / tunelling working? I trade for user (MS01) hash.
Dm me

u will trade ms01 hash or , the wayy to get ms01 hash ? xDDD hahaha

this guy doesnt know how to port forwading but he trade the hash of MS01 ahahaha i never seen a skid like that
Reply
can someone give me a hint how to force the machine to authenticate to itself to grab the ntlm hash?
I've set up ligolo-ng and think it can be done with something like https://github.com/med0x2e/NTLMRelay2Self but the spooler service is stopped..

Am I on the wrong track?

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching.
Reply
(Apr 05, 2024, 11:16 AM)jonah Wrote:
(Apr 05, 2024, 06:42 AM)Prometheuss Wrote:
(Apr 04, 2024, 10:22 PM)xss_02 Wrote: how do you guys are making proxychains / tunelling working? I trade for user (MS01) hash.
Dm me

u will trade ms01 hash or , the wayy to get ms01 hash ? xDDD hahaha

this guy doesnt know how to port forwading but he trade the hash of MS01 ahahaha i never seen a skid like that

ikr xD lol , plus ms01 hash is littearlly in this thread somewhere already leaked, and how the fuk he's expecting to get through this box without even knowing how to tunnel

anyway, am still on the hunt for how to get the coercion to work lol xDD plz anyone , petitpotam or any coercion isn't working for some fuked up reason and can't enable webdav on ms01 how y'all managed to do that ? (the obvious didn't work for sure don't throw at me a script that will enable webclient service i tried didn't help )
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] CPTS 12 FLAGS pulsebreaker 68 1,941 8 hours ago
Last Post: VictorPipeau
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 601 91,586 8 hours ago
Last Post: VictorPipeau
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 371 92,799 9 hours ago
Last Post: phannguyenbaouy1
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 21 2,616 Today, 05:08 AM
Last Post: popoler
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,269 Yesterday, 02:10 PM
Last Post: kkkato

Forum Jump:


 Users browsing this forum: 2 Guest(s)