/ tags/ Password Cracking
: Windows Medium machine - **Intelligence**.
HTB Active Directory ⓘ Microsoft's directory service for managing users, computers, and permissions across a Windows domain. Windows Sudo ⓘ Linux command for running as another user — misconfigured sudo rules are a common privilege escalation path. Nmap ⓘ A network scanner used to enumerate open ports, services, and versions on a target. DNS ⓘ The Domain Name System — translates hostnames to IPs; often leaks subdomains and internal naming during recon. NTLM ⓘ Windows' legacy authentication protocol — vulnerable to relay and pass-the-hash attacks. SMB ⓘ Server Message Block — Windows file-sharing protocol, frequently abused for enumeration and lateral movement. Password Cracking ⓘ Recovering a plaintext password from a captured hash via brute-force or wordlist attacks. BloodHound ⓘ A tool that maps Active Directory trust relationships as a graph to reveal hidden attack paths to Domain Admin. LDAP ⓘ Lightweight Directory Access Protocol — used to query Active Directory; often vulnerable to injection or anonymous binds. Password Spraying ⓘ Trying one common password against many usernames to avoid account lockouts. Windows Hard machine - Flight.
HTB Active Directory ⓘ Microsoft's directory service for managing users, computers, and permissions across a Windows domain. Windows RCE ⓘ Remote Code Execution — the ability to run arbitrary commands on a target system remotely. Sudo ⓘ Linux command for running as another user — misconfigured sudo rules are a common privilege escalation path. Nmap ⓘ A network scanner used to enumerate open ports, services, and versions on a target. DNS ⓘ The Domain Name System — translates hostnames to IPs; often leaks subdomains and internal naming during recon. PHP NTLM ⓘ Windows' legacy authentication protocol — vulnerable to relay and pass-the-hash attacks. SMB ⓘ Server Message Block — Windows file-sharing protocol, frequently abused for enumeration and lateral movement. Password Cracking ⓘ Recovering a plaintext password from a captured hash via brute-force or wordlist attacks. LDAP ⓘ Lightweight Directory Access Protocol — used to query Active Directory; often vulnerable to injection or anonymous binds. LFI ⓘ Local File Inclusion — a web vulnerability letting an attacker read arbitrary files on the server. Git Windows Intermediate machine - Escape.
HTB Active Directory ⓘ Microsoft's directory service for managing users, computers, and permissions across a Windows domain. Windows Linux Sudo ⓘ Linux command for running as another user — misconfigured sudo rules are a common privilege escalation path. Nmap ⓘ A network scanner used to enumerate open ports, services, and versions on a target. DNS ⓘ The Domain Name System — translates hostnames to IPs; often leaks subdomains and internal naming during recon. NTLM ⓘ Windows' legacy authentication protocol — vulnerable to relay and pass-the-hash attacks. WinRM ⓘ Windows Remote Management — used for remote PowerShell access, often the lateral-movement endpoint on AD boxes. SMB ⓘ Server Message Block — Windows file-sharing protocol, frequently abused for enumeration and lateral movement. Password Cracking ⓘ Recovering a plaintext password from a captured hash via brute-force or wordlist attacks. BloodHound ⓘ A tool that maps Active Directory trust relationships as a graph to reveal hidden attack paths to Domain Admin. LDAP ⓘ Lightweight Directory Access Protocol — used to query Active Directory; often vulnerable to injection or anonymous binds. RDP ⓘ Remote Desktop Protocol — Windows remote GUI access, sometimes exposed with weak credentials. Windows Medium machine - Certified.
HTB Active Directory ⓘ Microsoft's directory service for managing users, computers, and permissions across a Windows domain. Windows Sudo ⓘ Linux command for running as another user — misconfigured sudo rules are a common privilege escalation path. Nmap ⓘ A network scanner used to enumerate open ports, services, and versions on a target. DNS ⓘ The Domain Name System — translates hostnames to IPs; often leaks subdomains and internal naming during recon. NTLM ⓘ Windows' legacy authentication protocol — vulnerable to relay and pass-the-hash attacks. WinRM ⓘ Windows Remote Management — used for remote PowerShell access, often the lateral-movement endpoint on AD boxes. SMB ⓘ Server Message Block — Windows file-sharing protocol, frequently abused for enumeration and lateral movement. Password Cracking ⓘ Recovering a plaintext password from a captured hash via brute-force or wordlist attacks. Kerberoasting ⓘ Requesting service tickets for accounts with an SPN, then cracking them offline to recover the service account's password. BloodHound ⓘ A tool that maps Active Directory trust relationships as a graph to reveal hidden attack paths to Domain Admin. LDAP ⓘ Lightweight Directory Access Protocol — used to query Active Directory; often vulnerable to injection or anonymous binds. AS-REP Roasting ⓘ Requesting authentication data for accounts without Kerberos pre-auth, then cracking it offline to recover the password. Git Windows Hard machine - Blackfield.
HTB Active Directory ⓘ Microsoft's directory service for managing users, computers, and permissions across a Windows domain. Windows Sudo ⓘ Linux command for running as another user — misconfigured sudo rules are a common privilege escalation path. Nmap ⓘ A network scanner used to enumerate open ports, services, and versions on a target. DNS ⓘ The Domain Name System — translates hostnames to IPs; often leaks subdomains and internal naming during recon. PHP NTLM ⓘ Windows' legacy authentication protocol — vulnerable to relay and pass-the-hash attacks. WinRM ⓘ Windows Remote Management — used for remote PowerShell access, often the lateral-movement endpoint on AD boxes. SMB ⓘ Server Message Block — Windows file-sharing protocol, frequently abused for enumeration and lateral movement. Password Cracking ⓘ Recovering a plaintext password from a captured hash via brute-force or wordlist attacks. BloodHound ⓘ A tool that maps Active Directory trust relationships as a graph to reveal hidden attack paths to Domain Admin. LDAP ⓘ Lightweight Directory Access Protocol — used to query Active Directory; often vulnerable to injection or anonymous binds. AS-REP Roasting ⓘ Requesting authentication data for accounts without Kerberos pre-auth, then cracking it offline to recover the password. Password Spraying ⓘ Trying one common password against many usernames to avoid account lockouts. Unknown Unknown machine - Administrator.
HTB Active Directory ⓘ Microsoft's directory service for managing users, computers, and permissions across a Windows domain. Windows Linux Sudo ⓘ Linux command for running as another user — misconfigured sudo rules are a common privilege escalation path. Nmap ⓘ A network scanner used to enumerate open ports, services, and versions on a target. DNS ⓘ The Domain Name System — translates hostnames to IPs; often leaks subdomains and internal naming during recon. NTLM ⓘ Windows' legacy authentication protocol — vulnerable to relay and pass-the-hash attacks. FTP ⓘ File Transfer Protocol — frequently misconfigured with anonymous access, exposing sensitive files. WinRM ⓘ Windows Remote Management — used for remote PowerShell access, often the lateral-movement endpoint on AD boxes. SMB ⓘ Server Message Block — Windows file-sharing protocol, frequently abused for enumeration and lateral movement. Password Cracking ⓘ Recovering a plaintext password from a captured hash via brute-force or wordlist attacks. Kerberoasting ⓘ Requesting service tickets for accounts with an SPN, then cracking them offline to recover the service account's password. DCSync ⓘ Abusing domain replication permissions to ask a Domain Controller for password hashes as if you were another DC. BloodHound ⓘ A tool that maps Active Directory trust relationships as a graph to reveal hidden attack paths to Domain Admin. LDAP ⓘ Lightweight Directory Access Protocol — used to query Active Directory; often vulnerable to injection or anonymous binds.