From 6576804a346018fb6f99538a76ccba252cfe8398 Mon Sep 17 00:00:00 2001 From: julle Date: Sun, 7 Dec 2025 09:20:22 +0100 Subject: [PATCH] add thm labs --- .obsidian/graph.json | 2 +- .obsidian/workspace.json | 71 ++++++++++--------- .../Computers/10.81.169.155/Flag.md | 3 + .../Computers/10.81.169.155/Loot.md | 11 +++ .../Computers/10.81.169.155/Ports/13400.md | 7 ++ .../Computers/10.81.169.155/Ports/21337.md | 4 ++ .../Computers/10.81.169.155/Ports/8000.md | 15 ++++ .../Computers/10.81.169.155/Ports/8080.md | 7 ++ Linux/Tunnel/chisel.md | 4 +- Linux/portscanning.md | 4 +- Tools/autorecon.md | 4 +- Tools/nc.md | 8 +++ Tools/nmap.md | 4 +- Windows/Active Directory for OSCP.md | 9 +++ Windows/Information Gathering.md | 7 +- Windows/Tunnel/chisel.md | 4 +- 16 files changed, 122 insertions(+), 42 deletions(-) create mode 100644 Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Flag.md create mode 100644 Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Loot.md create mode 100644 Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/13400.md create mode 100644 Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/21337.md create mode 100644 Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/8000.md create mode 100644 Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/8080.md create mode 100644 Tools/nc.md diff --git a/.obsidian/graph.json b/.obsidian/graph.json index fd4520d..87b263a 100644 --- a/.obsidian/graph.json +++ b/.obsidian/graph.json @@ -17,6 +17,6 @@ "repelStrength": 10, "linkStrength": 1, "linkDistance": 250, - "scale": 0.4444444444444444, + "scale": 0.13168724279835387, "close": false } \ No newline at end of file diff --git a/.obsidian/workspace.json b/.obsidian/workspace.json index d7c5c92..bf8dab4 100644 --- a/.obsidian/workspace.json +++ b/.obsidian/workspace.json @@ -13,12 +13,12 @@ "state": { "type": "markdown", "state": { - "file": "Linux/Shell.md", + "file": "Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/21337.md", "mode": "source", "source": false }, "icon": "lucide-file", - "title": "Shell" + "title": "21337" } } ] @@ -94,7 +94,7 @@ "state": { "type": "backlink", "state": { - "file": "Linux/Shell.md", + "file": "Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Flag.md", "collapseAll": false, "extraContext": false, "sortOrder": "alphabetical", @@ -104,7 +104,7 @@ "unlinkedCollapsed": true }, "icon": "links-coming-in", - "title": "Backlinks for Shell" + "title": "Backlinks for Flag" } }, { @@ -150,7 +150,8 @@ } ], "direction": "horizontal", - "width": 300 + "width": 300, + "collapsed": true }, "left-ribbon": { "hiddenItems": { @@ -166,32 +167,39 @@ }, "active": "04550972536d9a99", "lastOpenFiles": [ - "Linux/portscanning.md", - "Linux/Perm.md", - "Linux/LFI.md", - "Linux/Crontab.md", - "Linux/Cap.md", - "Linux/_etc_passwd.md", - "Linux/Tunnel/sshuttle.md", - "Linux/Tunnel/ssh.md", - "Linux/Tunnel/Socat.md", - "Linux/Tunnel/chisel.md", - "Software/php/LFI.md", - "Tools/nmap.md", - "Tools/autorecon.md", + "Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Flag.md", + "Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Loot.md", + "Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/13400.md", + "Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/21337.md", + "Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/8000.md", + "Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/8080.md", + "Labs/ad/cap1.md", + "Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/Untitled", + "Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports", + "Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155", + "Labs/THM/AOC25/Sidequest_1/Computers", + "Labs/THM/AOC25/Sidequest_1", + "Labs/THM/AOC25", + "Labs/THM", "Proof.md", "Labs.md", "2024-10-28.md", - "20 EoP - Leveraging Windows Services.md", - "Windows/WWW.md", - "Windows/SMB.md", - "Windows/Scheduled Tasks.md", - "Windows/Information Gathering.md", - "Windows/Active Directory for OSCP.md", - "Windows/Tunnel/netsh.md", - "Windows/Tunnel/ligolo.md", + "Linux/LFI.md", + "Linux/Crontab.md", + "Linux/Cap.md", + "Windows/Active Directory for OSCP/Initial Access/Scan Network.md", + "Tools/nmap.md", + "MindMap/README.md", + "Linux/Tunnel/chisel.md", "Windows/Tunnel/chisel.md", - "Windows/SMB/crackmapexec.md", + "Necronomicon/Tools/Chisel.md", + "20 EoP - Leveraging Windows Services.md", + "Labs/medtech/computers/172.16.152.0/DEV04.md", + "Tools/nc.md", + "Linux/Shell.md", + "Linux/portscanning.md", + "Linux/Perm.md", + "Linux/_etc_passwd.md", "Windows/unnamed_b656515f39144863bbdaa2d5851c417c.png", "MindMap/AD Mindmap/AD - OSCP.canvas", "MindMap/WiFi/WiFi Mindmap.canvas", @@ -214,13 +222,6 @@ "MindMap/image/Mindmap Local Port Forwarding with a Bastion host.png", "MindMap/image", "MindMap/WiFi", - "MindMap/Web Penetration Testing Mindmap/Web-Penetration-Testing-Mindmap.mm", - "MindMap/Web Penetration Testing Mindmap", - "MindMap/Shells", - "MindMap/SSTI", - "MindMap/Privilege escalation Mindmap", - "MindMap/Pivotting-tunnels", - "MindMap/LICENSE", - "MindMap/File-Transfer" + "MindMap/Web Penetration Testing Mindmap/Web-Penetration-Testing-Mindmap.mm" ] } \ No newline at end of file diff --git a/Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Flag.md b/Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Flag.md new file mode 100644 index 0000000..afda39a --- /dev/null +++ b/Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Flag.md @@ -0,0 +1,3 @@ + +Flag 1 : THM{h0pp1ing_m4d} (cells/storage) + diff --git a/Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Loot.md b/Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Loot.md new file mode 100644 index 0000000..65adf97 --- /dev/null +++ b/Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Loot.md @@ -0,0 +1,11 @@ + +Key : now_you_see_me + + +----- + +Hopkins : +guard.hopkins@hopsecasylum.com +Pizza1234$ + +------- diff --git a/Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/13400.md b/Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/13400.md new file mode 100644 index 0000000..8a5f729 --- /dev/null +++ b/Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/13400.md @@ -0,0 +1,7 @@ +http://10.81.169.155:13400/ + + + +1. password: "Johnnyboy1982!" +2. username: "guard.hopkins@hopsecasylum.com" +guard-hopkins-sr \ No newline at end of file diff --git a/Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/21337.md b/Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/21337.md new file mode 100644 index 0000000..b6b2695 --- /dev/null +++ b/Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/21337.md @@ -0,0 +1,4 @@ +Unlock other ports : + +http://10.81.169.155:21337/ +key : now_you_see_me \ No newline at end of file diff --git a/Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/8000.md b/Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/8000.md new file mode 100644 index 0000000..7d1e093 --- /dev/null +++ b/Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/8000.md @@ -0,0 +1,15 @@ +Fakebook + +http://10.81.169.155:8000/ + +create user : +aa : G7tP3xQa + + +Hopkins : +guard.hopkins@hopsecasylum.com +Pizza1234$ + +Johnnyboy + +DoorDasher \ No newline at end of file diff --git a/Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/8080.md b/Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/8080.md new file mode 100644 index 0000000..cdec75f --- /dev/null +++ b/Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/8080.md @@ -0,0 +1,7 @@ +Get flags service : + +http://10.81.169.155:8080/ + +To bypass the login , paste in console : document.getElementById("loginWindow").style.display = "none"; +document.getElementById("mapScreen").style.display = "block"; + diff --git a/Linux/Tunnel/chisel.md b/Linux/Tunnel/chisel.md index 43d16c1..fe32313 100644 --- a/Linux/Tunnel/chisel.md +++ b/Linux/Tunnel/chisel.md @@ -1,2 +1,4 @@ -client 192.168.45.224:4242 R:4343:chisel client 192.168.45.224:4242 R:4343:chisel client 192.168.45.224:4242 R:4343:**10.4.228.215**### :::4242 \ No newline at end of file +client 192.168.45.224:4242 R:4343:chisel client 192.168.45.224:4242 R:4343:chisel client 192.168.45.224:4242 R:4343:**10.4.228.215**### :::4242 + +See [[Necronomicon/Tools/Chisel]] for a cleaner command matrix and [[Windows/Tunnel/chisel]] for the Windows-side syntax. The pivoting mind maps in [[MindMap/README]] cover wider tunnel options when chisel is blocked. diff --git a/Linux/portscanning.md b/Linux/portscanning.md index 6844f96..d1a8359 100644 --- a/Linux/portscanning.md +++ b/Linux/portscanning.md @@ -1 +1,3 @@ -for i in $(seq 1 254.; do nc -zv -w 1 172.16.228.$i 445; done \ No newline at end of file +for i in $(seq 1 254.; do nc -zv -w 1 172.16.228.$i 445; done + +For fuller scans see [[Tools/nmap]] and [[Tools/autorecon]]; they pair well with SSH tunnels in [[Linux/Tunnel/ssh]] when only restricted access is available. diff --git a/Tools/autorecon.md b/Tools/autorecon.md index 3ff41f4..9c50281 100644 --- a/Tools/autorecon.md +++ b/Tools/autorecon.md @@ -5,4 +5,6 @@ autorecon ``` proxychains -q autorecon 10.1.1.65 --proxychains -``` \ No newline at end of file +``` + +Related notes: [[Tools/nmap]] for follow-up port scans and [[Windows/Information Gathering]] for host recon once access is gained. diff --git a/Tools/nc.md b/Tools/nc.md new file mode 100644 index 0000000..4e808fe --- /dev/null +++ b/Tools/nc.md @@ -0,0 +1,8 @@ +## Connect to filtred port +``` +nebi@htb[/htb]$ ncat -nv --source-port 53 10.129.2.28 50000 + +Ncat: Version 7.80 ( https://nmap.org/ncat ) +Ncat: Connected to 10.129.2.28:50000. +220 ProFTPd +``` \ No newline at end of file diff --git a/Tools/nmap.md b/Tools/nmap.md index 1ec21bc..91f78c9 100644 --- a/Tools/nmap.md +++ b/Tools/nmap.md @@ -55,4 +55,6 @@ sudo nmap 10.129.2.28 -p50000 -sS -Pn -n --disable-arp-ping --packet-trace ```bash sudo nmap 10.129.2.28 -p50000 -sS -Pn -n --disable-arp-ping --packet-trace --source-port 53 -``` \ No newline at end of file +``` + +See also: [[Tools/autorecon]] for automated port discovery, [[Linux/portscanning]] for quick Bash loops, and [[Windows/Active Directory for OSCP/Initial Access/Scan Network]] when nmap has to run through proxychains in AD-heavy networks. diff --git a/Windows/Active Directory for OSCP.md b/Windows/Active Directory for OSCP.md index fedc73d..8a7f352 100644 --- a/Windows/Active Directory for OSCP.md +++ b/Windows/Active Directory for OSCP.md @@ -1,3 +1,12 @@ (Follow Mind map for nodes) ![unnamed_b656515f39144863bbdaa2d5851c417c](unnamed_b656515f39144863bbdaa2d5851c417c.png) + +## Quick links +- Initial access: [[Windows/Active Directory for OSCP/Initial Access/Scan Network]], [[Windows/Active Directory for OSCP/Initial Access/Get User List]], [[Windows/Active Directory for OSCP/Initial Access/LDAP Search]], [[Windows/Active Directory for OSCP/Initial Access/SMB Shares]] +- Enumeration: [[Windows/Active Directory for OSCP/Enumeration]], [[Windows/Active Directory for OSCP/Enumeration/net cmd]], [[Windows/Active Directory for OSCP/Enumeration/PowerView Enumeration]], [[Windows/Active Directory for OSCP/Enumeration/script]] +- Low hanging fruit: [[Windows/Active Directory for OSCP/Low Hanging Fruit/Null Login]], [[Windows/Active Directory for OSCP/Low Hanging Fruit/Group Policy in SYSVOL]] +- Valid credentials handling: [[Windows/Active Directory for OSCP/Valid Credentials/CrackHash]], [[Windows/Active Directory for OSCP/Valid Credentials/Kerberoasting]], [[Windows/Active Directory for OSCP/Valid Credentials/Runas (Invoke-RunasCs)|Runas (Invoke-RunasCs)]], [[Windows/Active Directory for OSCP/Valid Credentials/BloodHound]] +- Usernames without passwords: [[Windows/Active Directory for OSCP/We have User Name but no Password/Password Spray]], [[Windows/Active Directory for OSCP/We have User Name but no Password/ASREP Roast]] +- Lateral movement: [[Windows/Active Directory for OSCP/Lateral Movement/RDP]], [[Windows/Active Directory for OSCP/Lateral Movement/Win-RM]], [[Windows/Active Directory for OSCP/Lateral Movement/Pass-The-Hash [psexec, impacket, CME]]], [[Windows/Active Directory for OSCP/Lateral Movement/DCOM]], [[Windows/Active Directory for OSCP/Lateral Movement/Credential SAM dumping]], [[Windows/Active Directory for OSCP/Lateral Movement/Interactive Shell]], [[Windows/Active Directory for OSCP/Lateral Movement/Pseudo-Shell]] +- Credential dumping and data handling: [[Windows/Active Directory for OSCP/Mimikatz]], [[Windows/Active Directory for OSCP/NTDS.dir cracking with SYSTEM]], [[Windows/Active Directory for OSCP/Permission Move/DC Sync]] diff --git a/Windows/Information Gathering.md b/Windows/Information Gathering.md index e8c2833..ebb4b18 100644 --- a/Windows/Information Gathering.md +++ b/Windows/Information Gathering.md @@ -7,4 +7,9 @@ - Running processes` -powershell -ep bypass -c ". .\PrivescCheck.ps1; Invoke-PrivescCheck -Extended -Report PrivescCheck_$($env:COMPUTERNAME) -Format TXT,HTML" \ No newline at end of file +powershell -ep bypass -c ". .\PrivescCheck.ps1; Invoke-PrivescCheck -Extended -Report PrivescCheck_$($env:COMPUTERNAME) -Format TXT,HTML" + +## Deep dives +- Host basics: [[Windows/Information Gathering/Username and Hostname]], [[Windows/Information Gathering/Network]], [[Windows/Information Gathering/History]] +- Local discovery: [[Windows/Information Gathering/Locate files]], [[Windows/Information Gathering/Installed Program]] +- Related tools and scans: [[Tools/nmap]], [[Tools/autorecon]], [[Windows/SMB/crackmapexec]] diff --git a/Windows/Tunnel/chisel.md b/Windows/Tunnel/chisel.md index 5134432..10bab96 100644 --- a/Windows/Tunnel/chisel.md +++ b/Windows/Tunnel/chisel.md @@ -1 +1,3 @@ -`chisel client 192.168.45.206:443 R:socks` \ No newline at end of file +`chisel client 192.168.45.206:443 R:socks` + +See also [[Necronomicon/Tools/Chisel]] for more forwarding patterns and the Linux usage cheats in [[Linux/Tunnel/chisel]].