<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://nuts7.github.io/</id><title>nuts7's blog</title><subtitle>A blog about security, CTF writeups, researches and more</subtitle> <updated>2024-05-02T12:05:49+02:00</updated> <author> <name>nuts7</name> <uri>https://nuts7.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://nuts7.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://nuts7.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.3.3">Jekyll</generator> <rights> © 2024 nuts7 </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>HackTheBox - Snoopy</title><link href="https://nuts7.github.io/htb-snoopy/" rel="alternate" type="text/html" title="HackTheBox - Snoopy" /><published>2023-09-19T00:00:00+02:00</published> <updated>2023-09-21T21:58:05+02:00</updated> <id>https://nuts7.github.io/htb-snoopy/</id> <content src="https://nuts7.github.io/htb-snoopy/" /> <author> <name>nuts7</name> </author> <category term="Linux" /> <summary> Snoopy is a Linux machine from the HackTheBox platform, Hard released on 06 May 2023. It addresses multiple Web vulnerabilities including an LFI to extract Bind9 credentials, an XXE in the XML parsing of ClamAV’s clamscan program. In addition, it covers MiTM SSH with a connection we can trigger with a custom Mattermost command, DNS poisoning to obtain an account takeover vulnerability on Matter... </summary> </entry> <entry><title>HackTheBox - Rebound</title><link href="https://nuts7.github.io/htb-rebound/" rel="alternate" type="text/html" title="HackTheBox - Rebound" /><published>2023-09-19T00:00:00+02:00</published> <updated>2024-05-02T12:04:29+02:00</updated> <id>https://nuts7.github.io/htb-rebound/</id> <content src="https://nuts7.github.io/htb-rebound/" /> <author> <name>nuts7</name> </author> <category term="Windows" /> <summary> Rebound is a Windows machine, with the AD DS role installed, from the HackTheBox platform noted Insane released on September 09, 2023. It covers multiple techniques on Kerberos and especially a new Kerberoasting technique discovered in September 2022. It also covers ACL missconfiguration, the OU inheritance principle, SeImpersonatePrivilege exploitation and Kerberos delegations. ☺️ Port Scanni... </summary> </entry> <entry><title>ZeroLogon 101 (CVE-2020-1472)</title><link href="https://nuts7.github.io/zerologon/" rel="alternate" type="text/html" title="ZeroLogon 101 (CVE-2020-1472)" /><published>2023-07-10T00:00:00+02:00</published> <updated>2023-09-21T21:58:05+02:00</updated> <id>https://nuts7.github.io/zerologon/</id> <content src="https://nuts7.github.io/zerologon/" /> <author> <name>nuts7</name> </author> <category term="Windows" /> <summary> ZeroLogon aka CVE-2020-1472 is a vulnerability, found on 14th September 2020 by Secura researchers, that abuses the Netlogon Remote Protocol (MS-NRPC) RPC interface using an insecure cryptographic primitive. Exploitation requirements To exploit this vulnerability, the attacker only needs internal network access to reach the EPM (DCE/RPC Endpoint Mapper) of the vulnerable domain controller (DC... </summary> </entry> <entry><title>HackTheBox - PivotAPI</title><link href="https://nuts7.github.io/htb-pivotapi/" rel="alternate" type="text/html" title="HackTheBox - PivotAPI" /><published>2022-11-07T00:00:00+01:00</published> <updated>2023-09-21T21:58:05+02:00</updated> <id>https://nuts7.github.io/htb-pivotapi/</id> <content src="https://nuts7.github.io/htb-pivotapi/" /> <author> <name>nuts7</name> </author> <category term="Windows" /> <summary> PivotAPI is a Windows machine from the HackTheBox platform noted Insane released on May 08, 2021. It covers Kerberos missconfiguration, ACL, weak password cracking on a Keepass database, FTP server missconfiguration, as well as a bit of .NET reverse engineering. 😃 Port Scanning Tout d’abord, faisons un scan nmap des ports TCP : ❯ nmap -sCV -p- 10.10.10.240 -Pn --open -T5 -oN nmap PORT S... </summary> </entry> <entry><title>HackTheBox - Tentacle</title><link href="https://nuts7.github.io/htb-tentacle/" rel="alternate" type="text/html" title="HackTheBox - Tentacle" /><published>2021-06-19T00:00:00+02:00</published> <updated>2021-06-19T00:00:00+02:00</updated> <id>https://nuts7.github.io/htb-tentacle/</id> <content src="https://nuts7.github.io/htb-tentacle/" /> <author> <name>nuts7</name> </author> <category term="Linux" /> <summary> Bonjour à tous aujourd’hui je vous présente un walkthrough sur une machine difficile de HackTheBox. Cette machine demandait une énumération assez poussée, être familié avec proxychains et de bonnes connaissances sur le protocole kerberos. 😀 Recon Port Scanning Tout d’abord, faisons un scan TCP + UDP des 65535 ports avec l’outil masscan pour plus de rapidité : ❯ sudo masscan 10.10.10.224 -p1... </summary> </entry> </feed>
