P.O.O.
https://app.hackthebox.com/endgames/poo
IntroducciΓ³n
Enumeration
ping -c 1 10.13.38.11 -R
NMAP Scans

Bruteforce Directories

DS Enumeration Directory
IIS Shortname Scanner
Path bruteforce with WFUZZ

MSSQL Enumeration / Linkcrawler

Installing USQL for client to MSSQL

MSSQL Enumeration



Adding Username to the DB
Check Username
XP_cmdshell
Enabling external scripts
Using external scripts (example)
Type web.config for extract administrator credentials.





Evil-WinRM


Mimikatz.exe


Invoke-Kerberoast.ps1


Sharphound

PowerView.ps1


Γltima actualizaciΓ³n
