Skip to content

Latest commit

 

History

History
82 lines (41 loc) · 2.32 KB

sauna.md

File metadata and controls

82 lines (41 loc) · 2.32 KB

SAUNA HACKTHEBOX

DEMO

https://youtu.be/KEU1l4OyYZ8

ENUMERATION

NMAP

image

Kerberos User Enum

image

User fsmith don't need password let's go to crack it!

image

I copy hash you can see in last screenshoot and i put in hash file.

image

I have first credentials!

Comprove credentials:

image

Let's go!!

SecretsDump don't work:

image

GetUsersSPN

image

This means i can generate a ticket for user hsmith

image

But no works

It's moment to connect to winrm

image

I run WinPEASx64.exe, i recomended this tool, its amazing: https://github.com/carlospolop/PEASS-ng/

I found credentials with WinPEAS.

image

Put the real username and the credentials are valid.

image

I use secretsdump:

image

WORKS!!!

I try to do Pass the Hash with admin account.

image

PWNED!!

image

DONE

DEMO

https://youtu.be/KEU1l4OyYZ8

Thanks