/ tags/ DNS
Windows Medium machine - Voleur.
HTB Active Directory ⓘ Microsoft's directory service for managing users, computers, and permissions across a Windows domain. Windows Linux Sudo ⓘ Linux command for running as another user — misconfigured sudo rules are a common privilege escalation path. SSH ⓘ Secure Shell — encrypted remote login, targeted via key theft, brute force, or misconfigured access. Nmap ⓘ A network scanner used to enumerate open ports, services, and versions on a target. DNS ⓘ The Domain Name System — translates hostnames to IPs; often leaks subdomains and internal naming during recon. NTLM ⓘ Windows' legacy authentication protocol — vulnerable to relay and pass-the-hash attacks. WinRM ⓘ Windows Remote Management — used for remote PowerShell access, often the lateral-movement endpoint on AD boxes. SMB ⓘ Server Message Block — Windows file-sharing protocol, frequently abused for enumeration and lateral movement. Password Cracking ⓘ Recovering a plaintext password from a captured hash via brute-force or wordlist attacks. BloodHound ⓘ A tool that maps Active Directory trust relationships as a graph to reveal hidden attack paths to Domain Admin. LDAP ⓘ Lightweight Directory Access Protocol — used to query Active Directory; often vulnerable to injection or anonymous binds. Linux Intermediate machine - Updown.
HTB Linux Sudo ⓘ Linux command for running as another user — misconfigured sudo rules are a common privilege escalation path. SSH ⓘ Secure Shell — encrypted remote login, targeted via key theft, brute force, or misconfigured access. DNS ⓘ The Domain Name System — translates hostnames to IPs; often leaks subdomains and internal naming during recon. PHP LFI ⓘ Local File Inclusion — a web vulnerability letting an attacker read arbitrary files on the server. Git Brute Force ⓘ Systematically trying many credential combinations until one succeeds. SUID ⓘ A Linux permission bit that runs a binary as its owner — misconfigured SUID binaries are a classic privesc vector. Cronjob ⓘ A scheduled task on Linux — often abused for privilege escalation when it runs as root with a writable script. RFI ⓘ Remote File Inclusion — a web vulnerability allowing an attacker to include and execute a remote file. Windows Easy machine - Titanic.
HTB Windows RCE ⓘ Remote Code Execution — the ability to run arbitrary commands on a target system remotely. Linux SSH ⓘ Secure Shell — encrypted remote login, targeted via key theft, brute force, or misconfigured access. CVE ⓘ A publicly catalogued, known vulnerability with a unique identifier (Common Vulnerabilities and Exposures). Docker ⓘ A containerization platform — misconfigured sockets or escapes can lead to host compromise. DNS ⓘ The Domain Name System — translates hostnames to IPs; often leaks subdomains and internal naming during recon. Password Cracking ⓘ Recovering a plaintext password from a captured hash via brute-force or wordlist attacks. LFI ⓘ Local File Inclusion — a web vulnerability letting an attacker read arbitrary files on the server. MySQL Brute Force ⓘ Systematically trying many credential combinations until one succeeds. SQLi ⓘ SQL Injection — manipulating database queries via unsanitized input to read or alter data. Cronjob ⓘ A scheduled task on Linux — often abused for privilege escalation when it runs as root with a writable script. Windows Easy machine - **Timelapse**.
HTB Active Directory ⓘ Microsoft's directory service for managing users, computers, and permissions across a Windows domain. Windows Nmap ⓘ A network scanner used to enumerate open ports, services, and versions on a target. DNS ⓘ The Domain Name System — translates hostnames to IPs; often leaks subdomains and internal naming during recon. WinRM ⓘ Windows Remote Management — used for remote PowerShell access, often the lateral-movement endpoint on AD boxes. SMB ⓘ Server Message Block — Windows file-sharing protocol, frequently abused for enumeration and lateral movement. LDAP ⓘ Lightweight Directory Access Protocol — used to query Active Directory; often vulnerable to injection or anonymous binds. Brute Force ⓘ Systematically trying many credential combinations until one succeeds. Windows Easy machine - TheFrizz.
HTB Active Directory ⓘ Microsoft's directory service for managing users, computers, and permissions across a Windows domain. Windows RCE ⓘ Remote Code Execution — the ability to run arbitrary commands on a target system remotely. Sudo ⓘ Linux command for running as another user — misconfigured sudo rules are a common privilege escalation path. SSH ⓘ Secure Shell — encrypted remote login, targeted via key theft, brute force, or misconfigured access. Nmap ⓘ A network scanner used to enumerate open ports, services, and versions on a target. CVE ⓘ A publicly catalogued, known vulnerability with a unique identifier (Common Vulnerabilities and Exposures). DNS ⓘ The Domain Name System — translates hostnames to IPs; often leaks subdomains and internal naming during recon. PHP GPO ⓘ Group Policy Object — a Windows domain-wide configuration mechanism, abusable for code execution across all machines. SMB ⓘ Server Message Block — Windows file-sharing protocol, frequently abused for enumeration and lateral movement. BloodHound ⓘ A tool that maps Active Directory trust relationships as a graph to reveal hidden attack paths to Domain Admin. LDAP ⓘ Lightweight Directory Access Protocol — used to query Active Directory; often vulnerable to injection or anonymous binds. Password Spraying ⓘ Trying one common password against many usernames to avoid account lockouts. LFI ⓘ Local File Inclusion — a web vulnerability letting an attacker read arbitrary files on the server. MySQL Windows Easy machine - Support.
HTB Active Directory ⓘ Microsoft's directory service for managing users, computers, and permissions across a Windows domain. Windows Linux Nmap ⓘ A network scanner used to enumerate open ports, services, and versions on a target. DNS ⓘ The Domain Name System — translates hostnames to IPs; often leaks subdomains and internal naming during recon. NTLM ⓘ Windows' legacy authentication protocol — vulnerable to relay and pass-the-hash attacks. WinRM ⓘ Windows Remote Management — used for remote PowerShell access, often the lateral-movement endpoint on AD boxes. SMB ⓘ Server Message Block — Windows file-sharing protocol, frequently abused for enumeration and lateral movement. BloodHound ⓘ A tool that maps Active Directory trust relationships as a graph to reveal hidden attack paths to Domain Admin. LDAP ⓘ Lightweight Directory Access Protocol — used to query Active Directory; often vulnerable to injection or anonymous binds. Pass-the-Ticket ⓘ Reusing a stolen Kerberos ticket to authenticate as another user without their password. Reverse Engineering ⓘ Analyzing compiled binaries or obfuscated code to understand or exploit their behavior.