HTB University 2024 (freedom fullpwn)
by 0xfoxy - Saturday December 14, 2024 at 09:06 PM
#21
(Dec 15, 2024, 11:38 AM)eunaosei Wrote:
(Dec 15, 2024, 11:37 AM)som3rAnd0m Wrote:
(Dec 15, 2024, 11:19 AM)eunaosei Wrote:
(Dec 15, 2024, 11:15 AM)som3rAnd0m Wrote:
(Dec 15, 2024, 11:14 AM)eunaosei Wrote: its already in, how many users do you got on your usersfile? any service accounts? the only hash i got was from e.tylar with impacket-getNPUsers (uncrackable)
I have 2 users, one is e.tylar and other is j.bret and also did you do the clouded fullpwn

i didn't made clouded, u done apolo?

(Dec 15, 2024, 11:19 AM)som3rAnd0m Wrote:
(Dec 15, 2024, 11:16 AM)eunaosei Wrote: same as me, u already pwned user.txt?
Did you try to decompile the HealthCheck.exe file ,cause  I think it has something to do with it

where is it?
Yeah I completed Appolo and that HealthCheck.exe is on the desktop of j.bret

i don't even have a shell on freedom lol, but i can help with reversing if you need
You have creds of j.bret right?

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#22
(Dec 15, 2024, 11:45 AM)som3rAnd0m Wrote:
(Dec 15, 2024, 11:38 AM)eunaosei Wrote:
(Dec 15, 2024, 11:37 AM)som3rAnd0m Wrote:
(Dec 15, 2024, 11:19 AM)eunaosei Wrote:
(Dec 15, 2024, 11:15 AM)som3rAnd0m Wrote: I have 2 users, one is e.tylar and other is j.bret and also did you do the clouded fullpwn

i didn't made clouded, u done apolo?

(Dec 15, 2024, 11:19 AM)som3rAnd0m Wrote: Did you try to decompile the HealthCheck.exe file ,cause  I think it has something to do with it

where is it?
Yeah I completed Appolo and that HealthCheck.exe is on the desktop of j.bret

i don't even have a shell on freedom lol, but i can help with reversing if you need
You have creds of j.bret right?

not yet, how do i get them?
Reply
#23
(Dec 15, 2024, 11:45 AM)eunaosei Wrote:
(Dec 15, 2024, 11:45 AM)som3rAnd0m Wrote:
(Dec 15, 2024, 11:38 AM)eunaosei Wrote:
(Dec 15, 2024, 11:37 AM)som3rAnd0m Wrote:
(Dec 15, 2024, 11:19 AM)eunaosei Wrote: i didn't made clouded, u done apolo?


where is it?
Yeah I completed Appolo and that HealthCheck.exe is on the desktop of j.bret

i don't even have a shell on freedom lol, but i can help with reversing if you need
You have creds of j.bret right?

not yet, how do i get them?
In a text file add the names e.tylar and j.bret ,
then in the /etc/hosts file edit the file with :
<Machine IP>      freedom.htb dc1.freedom.htb
now on the same directory as the text file where you save the usernames use the below command:
impacket-GetUserSPNs -no-preauth e.tylar -request -usersfile usernames.txt -dc-ip "<Machine IP>" -target-domain freedom.htb  freedom.htb/

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#24
Can you tell what should be done for solve apolo ? i saw smtp is up
Reply
#25
(Dec 15, 2024, 12:09 PM)KK1234 Wrote: Can you tell what should be done for solve apolo ? i saw smtp is up

use this in the flowise url Api/v1/credentials
It will then give you some id
Then you need to keep it as `Api/v1/credentials?<That id>`

If you want you can see this one https://www.exploit-db.com/exploits/52001

After you get the credential it should be pretty easy for you to get user.txt and even more easy privesc "to copy" root.txt

Also I did this yesterday morning so I don't remember the exact details of it

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#26
(Dec 15, 2024, 11:19 AM)som3rAnd0m Wrote:
(Dec 15, 2024, 11:16 AM)eunaosei Wrote:
(Dec 15, 2024, 11:15 AM)som3rAnd0m Wrote:
(Dec 15, 2024, 11:14 AM)eunaosei Wrote:
(Dec 15, 2024, 11:11 AM)som3rAnd0m Wrote: In /etc/hosts file add dc1.freedom.htb too after freedom.htb And also use the command sudo ntpdate -u freedom.htb

its already in, how many users do you got on your usersfile? any service accounts? the only hash i got was from e.tylar with impacket-getNPUsers (uncrackable)
I have 2 users, one is e.tylar and other is j.bret and also did you do the clouded fullpwn

same as me, u already pwned user.txt?
Did you try to decompile the HealthCheck.exe file ,cause  I think it has something to do with it

seems that we can append a string to a system call, but i don't know how
Reply
#27
this may help you

https://www.youtube.com/watch?v=oUIoH4yBT3k
Reply
#28
(Dec 15, 2024, 01:15 PM)ZzXx2020 Wrote: this may help you

https://www.youtube.com/watch?v=oUIoH4yBT3k
Hey Thanks,but I already finished that part and got user.txtand trying for root.txt ,can you help me if you have done it

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#29
(Dec 15, 2024, 02:12 PM)dede390 Wrote:
(Dec 15, 2024, 01:50 PM)asdasdasd1231 Wrote: can anyone help in finding its root



Hey bro, how did you manage to grab the user.txt file when the hashes are unbreakable?
Watch carefully the ippsec rebound machine video(first part)

Did anyone get root?, still stuck))

(Dec 15, 2024, 02:12 PM)dede390 Wrote:
(Dec 15, 2024, 01:50 PM)asdasdasd1231 Wrote: can anyone help in finding its root



Hey bro, how did you manage to grab the user.txt file when the hashes are unbreakable?
Watch carefully the ippsec rebound machine video(first part)

Did anyone get root?, still stuck))
Reply
#30
(Dec 15, 2024, 02:16 PM)0xfoxy Wrote:
(Dec 15, 2024, 02:12 PM)dede390 Wrote:
(Dec 15, 2024, 01:50 PM)asdasdasd1231 Wrote: can anyone help in finding its root



Hey bro, how did you manage to grab the user.txt file when the hashes are unbreakable?
Watch carefully the ippsec rebound machine video(first part)

Did anyone get root?, still stuck))

(Dec 15, 2024, 02:12 PM)dede390 Wrote:
(Dec 15, 2024, 01:50 PM)asdasdasd1231 Wrote: can anyone help in finding its root



Hey bro, how did you manage to grab the user.txt file when the hashes are unbreakable?
Watch carefully the ippsec rebound machine video(first part)

Did anyone get root?, still stuck))

what have you tried so far? still no luck here too
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 388 96,849 2 hours ago
Last Post: miasto
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 19 1,209 2 hours ago
Last Post: miasto
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 99 9,338 6 hours ago
Last Post: vlxw
  [FREE] CPTS 12 FLAGS pulsebreaker 88 3,525 Yesterday, 06:36 AM
Last Post: exdream
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 49 3,988 May 08, 2026, 06:58 PM
Last Post: opium0221

Forum Jump:


 Users browsing this forum: 1 Guest(s)