P.O.O.
https://app.hackthebox.com/endgames/poo
Introducción
Professional Offensive Operations
Professional Offensive Operations is a rising name in the cyber security world.
Lately they've been working into migrating core services and components to a state of the art cluster which offers cutting edge software and hardware.
P.O.O. is designed to put your skills in enumeration, lateral movement, and privilege escalation to the test within a small Active Directory environment that is configured with the latest operating systems and technologies.
The goal is to compromise the perimeter host, escalate privileges and ultimately compromise the domain while collecting several flags along the way.
Entry Point: 10.13.38.11
Enumeration
ping -c 1 10.13.38.11 -R
NMAP Scans

Bruteforce Directories

DS Enumeration Directory
IIS Shortname Scanner
Path bruteforce with WFUZZ

MSSQL Enumeration / Linkcrawler

Installing USQL for client to MSSQL

MSSQL Enumeration



Adding Username to the DB
Check Username
XP_cmdshell
Enabling external scripts
Using external scripts (example)
Type web.config for extract administrator credentials.





Evil-WinRM


Mimikatz.exe


Invoke-Kerberoast.ps1


Sharphound

PowerView.ps1


Última actualización
¿Te fue útil?
