add thm labs
This commit is contained in:
Vendored
+1
-1
@@ -17,6 +17,6 @@
|
|||||||
"repelStrength": 10,
|
"repelStrength": 10,
|
||||||
"linkStrength": 1,
|
"linkStrength": 1,
|
||||||
"linkDistance": 250,
|
"linkDistance": 250,
|
||||||
"scale": 0.4444444444444444,
|
"scale": 0.13168724279835387,
|
||||||
"close": false
|
"close": false
|
||||||
}
|
}
|
||||||
Vendored
+36
-35
@@ -13,12 +13,12 @@
|
|||||||
"state": {
|
"state": {
|
||||||
"type": "markdown",
|
"type": "markdown",
|
||||||
"state": {
|
"state": {
|
||||||
"file": "Linux/Shell.md",
|
"file": "Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/21337.md",
|
||||||
"mode": "source",
|
"mode": "source",
|
||||||
"source": false
|
"source": false
|
||||||
},
|
},
|
||||||
"icon": "lucide-file",
|
"icon": "lucide-file",
|
||||||
"title": "Shell"
|
"title": "21337"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
@@ -94,7 +94,7 @@
|
|||||||
"state": {
|
"state": {
|
||||||
"type": "backlink",
|
"type": "backlink",
|
||||||
"state": {
|
"state": {
|
||||||
"file": "Linux/Shell.md",
|
"file": "Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Flag.md",
|
||||||
"collapseAll": false,
|
"collapseAll": false,
|
||||||
"extraContext": false,
|
"extraContext": false,
|
||||||
"sortOrder": "alphabetical",
|
"sortOrder": "alphabetical",
|
||||||
@@ -104,7 +104,7 @@
|
|||||||
"unlinkedCollapsed": true
|
"unlinkedCollapsed": true
|
||||||
},
|
},
|
||||||
"icon": "links-coming-in",
|
"icon": "links-coming-in",
|
||||||
"title": "Backlinks for Shell"
|
"title": "Backlinks for Flag"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
@@ -150,7 +150,8 @@
|
|||||||
}
|
}
|
||||||
],
|
],
|
||||||
"direction": "horizontal",
|
"direction": "horizontal",
|
||||||
"width": 300
|
"width": 300,
|
||||||
|
"collapsed": true
|
||||||
},
|
},
|
||||||
"left-ribbon": {
|
"left-ribbon": {
|
||||||
"hiddenItems": {
|
"hiddenItems": {
|
||||||
@@ -166,32 +167,39 @@
|
|||||||
},
|
},
|
||||||
"active": "04550972536d9a99",
|
"active": "04550972536d9a99",
|
||||||
"lastOpenFiles": [
|
"lastOpenFiles": [
|
||||||
"Linux/portscanning.md",
|
"Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Flag.md",
|
||||||
"Linux/Perm.md",
|
"Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Loot.md",
|
||||||
"Linux/LFI.md",
|
"Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/13400.md",
|
||||||
"Linux/Crontab.md",
|
"Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/21337.md",
|
||||||
"Linux/Cap.md",
|
"Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/8000.md",
|
||||||
"Linux/_etc_passwd.md",
|
"Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/8080.md",
|
||||||
"Linux/Tunnel/sshuttle.md",
|
"Labs/ad/cap1.md",
|
||||||
"Linux/Tunnel/ssh.md",
|
"Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports/Untitled",
|
||||||
"Linux/Tunnel/Socat.md",
|
"Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155/Ports",
|
||||||
"Linux/Tunnel/chisel.md",
|
"Labs/THM/AOC25/Sidequest_1/Computers/10.81.169.155",
|
||||||
"Software/php/LFI.md",
|
"Labs/THM/AOC25/Sidequest_1/Computers",
|
||||||
"Tools/nmap.md",
|
"Labs/THM/AOC25/Sidequest_1",
|
||||||
"Tools/autorecon.md",
|
"Labs/THM/AOC25",
|
||||||
|
"Labs/THM",
|
||||||
"Proof.md",
|
"Proof.md",
|
||||||
"Labs.md",
|
"Labs.md",
|
||||||
"2024-10-28.md",
|
"2024-10-28.md",
|
||||||
"20 EoP - Leveraging Windows Services.md",
|
"Linux/LFI.md",
|
||||||
"Windows/WWW.md",
|
"Linux/Crontab.md",
|
||||||
"Windows/SMB.md",
|
"Linux/Cap.md",
|
||||||
"Windows/Scheduled Tasks.md",
|
"Windows/Active Directory for OSCP/Initial Access/Scan Network.md",
|
||||||
"Windows/Information Gathering.md",
|
"Tools/nmap.md",
|
||||||
"Windows/Active Directory for OSCP.md",
|
"MindMap/README.md",
|
||||||
"Windows/Tunnel/netsh.md",
|
"Linux/Tunnel/chisel.md",
|
||||||
"Windows/Tunnel/ligolo.md",
|
|
||||||
"Windows/Tunnel/chisel.md",
|
"Windows/Tunnel/chisel.md",
|
||||||
"Windows/SMB/crackmapexec.md",
|
"Necronomicon/Tools/Chisel.md",
|
||||||
|
"20 EoP - Leveraging Windows Services.md",
|
||||||
|
"Labs/medtech/computers/172.16.152.0/DEV04.md",
|
||||||
|
"Tools/nc.md",
|
||||||
|
"Linux/Shell.md",
|
||||||
|
"Linux/portscanning.md",
|
||||||
|
"Linux/Perm.md",
|
||||||
|
"Linux/_etc_passwd.md",
|
||||||
"Windows/unnamed_b656515f39144863bbdaa2d5851c417c.png",
|
"Windows/unnamed_b656515f39144863bbdaa2d5851c417c.png",
|
||||||
"MindMap/AD Mindmap/AD - OSCP.canvas",
|
"MindMap/AD Mindmap/AD - OSCP.canvas",
|
||||||
"MindMap/WiFi/WiFi Mindmap.canvas",
|
"MindMap/WiFi/WiFi Mindmap.canvas",
|
||||||
@@ -214,13 +222,6 @@
|
|||||||
"MindMap/image/Mindmap Local Port Forwarding with a Bastion host.png",
|
"MindMap/image/Mindmap Local Port Forwarding with a Bastion host.png",
|
||||||
"MindMap/image",
|
"MindMap/image",
|
||||||
"MindMap/WiFi",
|
"MindMap/WiFi",
|
||||||
"MindMap/Web Penetration Testing Mindmap/Web-Penetration-Testing-Mindmap.mm",
|
"MindMap/Web Penetration Testing Mindmap/Web-Penetration-Testing-Mindmap.mm"
|
||||||
"MindMap/Web Penetration Testing Mindmap",
|
|
||||||
"MindMap/Shells",
|
|
||||||
"MindMap/SSTI",
|
|
||||||
"MindMap/Privilege escalation Mindmap",
|
|
||||||
"MindMap/Pivotting-tunnels",
|
|
||||||
"MindMap/LICENSE",
|
|
||||||
"MindMap/File-Transfer"
|
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
|
||||||
|
Flag 1 : THM{h0pp1ing_m4d} (cells/storage)
|
||||||
|
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
|
||||||
|
Key : now_you_see_me
|
||||||
|
|
||||||
|
|
||||||
|
-----
|
||||||
|
|
||||||
|
Hopkins :
|
||||||
|
guard.hopkins@hopsecasylum.com
|
||||||
|
Pizza1234$
|
||||||
|
|
||||||
|
-------
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
http://10.81.169.155:13400/
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
1. password: "Johnnyboy1982!"
|
||||||
|
2. username: "guard.hopkins@hopsecasylum.com"
|
||||||
|
guard-hopkins-sr
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
Unlock other ports :
|
||||||
|
|
||||||
|
http://10.81.169.155:21337/
|
||||||
|
key : now_you_see_me
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
Fakebook
|
||||||
|
|
||||||
|
http://10.81.169.155:8000/
|
||||||
|
|
||||||
|
create user :
|
||||||
|
aa : G7tP3xQa
|
||||||
|
|
||||||
|
|
||||||
|
Hopkins :
|
||||||
|
guard.hopkins@hopsecasylum.com
|
||||||
|
Pizza1234$
|
||||||
|
|
||||||
|
Johnnyboy
|
||||||
|
|
||||||
|
DoorDasher
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
Get flags service :
|
||||||
|
|
||||||
|
http://10.81.169.155:8080/
|
||||||
|
|
||||||
|
To bypass the login , paste in console : document.getElementById("loginWindow").style.display = "none";
|
||||||
|
document.getElementById("mapScreen").style.display = "block";
|
||||||
|
|
||||||
@@ -1,2 +1,4 @@
|
|||||||
|
|
||||||
client 192.168.45.224:4242 R:4343:chisel client 192.168.45.224:4242 R:4343:chisel client 192.168.45.224:4242 R:4343:**10.4.228.215**### :::4242
|
client 192.168.45.224:4242 R:4343:chisel client 192.168.45.224:4242 R:4343:chisel client 192.168.45.224:4242 R:4343:**10.4.228.215**### :::4242
|
||||||
|
|
||||||
|
See [[Necronomicon/Tools/Chisel]] for a cleaner command matrix and [[Windows/Tunnel/chisel]] for the Windows-side syntax. The pivoting mind maps in [[MindMap/README]] cover wider tunnel options when chisel is blocked.
|
||||||
|
|||||||
@@ -1 +1,3 @@
|
|||||||
for i in $(seq 1 254.; do nc -zv -w 1 172.16.228.$i 445; done
|
for i in $(seq 1 254.; do nc -zv -w 1 172.16.228.$i 445; done
|
||||||
|
|
||||||
|
For fuller scans see [[Tools/nmap]] and [[Tools/autorecon]]; they pair well with SSH tunnels in [[Linux/Tunnel/ssh]] when only restricted access is available.
|
||||||
|
|||||||
@@ -6,3 +6,5 @@ autorecon <target>
|
|||||||
```
|
```
|
||||||
proxychains -q autorecon 10.1.1.65 --proxychains
|
proxychains -q autorecon 10.1.1.65 --proxychains
|
||||||
```
|
```
|
||||||
|
|
||||||
|
Related notes: [[Tools/nmap]] for follow-up port scans and [[Windows/Information Gathering]] for host recon once access is gained.
|
||||||
|
|||||||
@@ -0,0 +1,8 @@
|
|||||||
|
## Connect to filtred port
|
||||||
|
```
|
||||||
|
nebi@htb[/htb]$ ncat -nv --source-port 53 10.129.2.28 50000
|
||||||
|
|
||||||
|
Ncat: Version 7.80 ( https://nmap.org/ncat )
|
||||||
|
Ncat: Connected to 10.129.2.28:50000.
|
||||||
|
220 ProFTPd
|
||||||
|
```
|
||||||
@@ -56,3 +56,5 @@ sudo nmap 10.129.2.28 -p50000 -sS -Pn -n --disable-arp-ping --packet-trace
|
|||||||
```bash
|
```bash
|
||||||
sudo nmap 10.129.2.28 -p50000 -sS -Pn -n --disable-arp-ping --packet-trace --source-port 53
|
sudo nmap 10.129.2.28 -p50000 -sS -Pn -n --disable-arp-ping --packet-trace --source-port 53
|
||||||
```
|
```
|
||||||
|
|
||||||
|
See also: [[Tools/autorecon]] for automated port discovery, [[Linux/portscanning]] for quick Bash loops, and [[Windows/Active Directory for OSCP/Initial Access/Scan Network]] when nmap has to run through proxychains in AD-heavy networks.
|
||||||
|
|||||||
@@ -1,3 +1,12 @@
|
|||||||
<https://whimsical.com/active-directory-YJFeAhW9GMtmLX4SWxKCCM> (Follow Mind map for nodes)
|
<https://whimsical.com/active-directory-YJFeAhW9GMtmLX4SWxKCCM> (Follow Mind map for nodes)
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
|
## Quick links
|
||||||
|
- Initial access: [[Windows/Active Directory for OSCP/Initial Access/Scan Network]], [[Windows/Active Directory for OSCP/Initial Access/Get User List]], [[Windows/Active Directory for OSCP/Initial Access/LDAP Search]], [[Windows/Active Directory for OSCP/Initial Access/SMB Shares]]
|
||||||
|
- Enumeration: [[Windows/Active Directory for OSCP/Enumeration]], [[Windows/Active Directory for OSCP/Enumeration/net cmd]], [[Windows/Active Directory for OSCP/Enumeration/PowerView Enumeration]], [[Windows/Active Directory for OSCP/Enumeration/script]]
|
||||||
|
- Low hanging fruit: [[Windows/Active Directory for OSCP/Low Hanging Fruit/Null Login]], [[Windows/Active Directory for OSCP/Low Hanging Fruit/Group Policy in SYSVOL]]
|
||||||
|
- Valid credentials handling: [[Windows/Active Directory for OSCP/Valid Credentials/CrackHash]], [[Windows/Active Directory for OSCP/Valid Credentials/Kerberoasting]], [[Windows/Active Directory for OSCP/Valid Credentials/Runas (Invoke-RunasCs)|Runas (Invoke-RunasCs)]], [[Windows/Active Directory for OSCP/Valid Credentials/BloodHound]]
|
||||||
|
- Usernames without passwords: [[Windows/Active Directory for OSCP/We have User Name but no Password/Password Spray]], [[Windows/Active Directory for OSCP/We have User Name but no Password/ASREP Roast]]
|
||||||
|
- Lateral movement: [[Windows/Active Directory for OSCP/Lateral Movement/RDP]], [[Windows/Active Directory for OSCP/Lateral Movement/Win-RM]], [[Windows/Active Directory for OSCP/Lateral Movement/Pass-The-Hash [psexec, impacket, CME]]], [[Windows/Active Directory for OSCP/Lateral Movement/DCOM]], [[Windows/Active Directory for OSCP/Lateral Movement/Credential SAM dumping]], [[Windows/Active Directory for OSCP/Lateral Movement/Interactive Shell]], [[Windows/Active Directory for OSCP/Lateral Movement/Pseudo-Shell]]
|
||||||
|
- Credential dumping and data handling: [[Windows/Active Directory for OSCP/Mimikatz]], [[Windows/Active Directory for OSCP/NTDS.dir cracking with SYSTEM]], [[Windows/Active Directory for OSCP/Permission Move/DC Sync]]
|
||||||
|
|||||||
@@ -8,3 +8,8 @@
|
|||||||
|
|
||||||
<https://github.com/itm4n/PrivescCheck>
|
<https://github.com/itm4n/PrivescCheck>
|
||||||
powershell -ep bypass -c ". .\PrivescCheck.ps1; Invoke-PrivescCheck -Extended -Report PrivescCheck_$($env:COMPUTERNAME) -Format TXT,HTML"
|
powershell -ep bypass -c ". .\PrivescCheck.ps1; Invoke-PrivescCheck -Extended -Report PrivescCheck_$($env:COMPUTERNAME) -Format TXT,HTML"
|
||||||
|
|
||||||
|
## Deep dives
|
||||||
|
- Host basics: [[Windows/Information Gathering/Username and Hostname]], [[Windows/Information Gathering/Network]], [[Windows/Information Gathering/History]]
|
||||||
|
- Local discovery: [[Windows/Information Gathering/Locate files]], [[Windows/Information Gathering/Installed Program]]
|
||||||
|
- Related tools and scans: [[Tools/nmap]], [[Tools/autorecon]], [[Windows/SMB/crackmapexec]]
|
||||||
|
|||||||
@@ -1 +1,3 @@
|
|||||||
`chisel client 192.168.45.206:443 R:socks`
|
`chisel client 192.168.45.206:443 R:socks`
|
||||||
|
|
||||||
|
See also [[Necronomicon/Tools/Chisel]] for more forwarding patterns and the Linux usage cheats in [[Linux/Tunnel/chisel]].
|
||||||
|
|||||||
Reference in New Issue
Block a user