That said, I really appreciate the work of the HTB team. Supporting their business for another year feels worth it. Here’s to focusing on the positives!
That said, I really appreciate the work of the HTB team. Supporting their business for another year feels worth it. Here’s to focusing on the positives!
After some unsuccessful attempts, i found an vuln which seems work against the box : printnightmare (CVE-2021-1675). However after following the exploitation process, i encountered an ERROR_VIRUS_INFECTED message. So, for the first time, i'll try to obfuscate a dll
After some unsuccessful attempts, i found an vuln which seems work against the box : printnightmare (CVE-2021-1675). However after following the exploitation process, i encountered an ERROR_VIRUS_INFECTED message. So, for the first time, i'll try to obfuscate a dll
Okay, so i needed to get a file which is called SAM in Windows/System32/config
:)
Ok, let's continue
Okay, so i needed to get a file which is called SAM in Windows/System32/config
:)
Ok, let's continue
network scanned
smb open port found
connected with guest account
grap an vhd locally and mount it with guestmount
found an NTUSER.dat
and that's all.
Since i go round in circles
network scanned
smb open port found
connected with guest account
grap an vhd locally and mount it with guestmount
found an NTUSER.dat
and that's all.
Since i go round in circles