Blackfield - Hackthebox (OSCP Prep) TJ Nullls

Channel:
Subscribers:
1,270
Published on ● Video Link: https://www.youtube.com/watch?v=eg6VhY_k_jw



Duration: 48:47
1,993 views
81


Backfield is a hard difficulty Windows machine featuring Windows and Active Directory misconfigurations. Anonymous / Guest access to an SMB share is used to enumerate users. Once user is found to have Kerberos pre-authentication disabled, which allows us to conduct an ASREPRoasting attack. This allows us to retrieve a hash of the encrypted material contained in the AS-REP, which can be subjected to an offline brute force attack in order to recover the plaintext password. With this user we can access an SMB share containing forensics artefacts, including an lsass process dump. This contains a username and a password for a user with WinRM privileges, who is also a member of the Backup Operators group. The privileges conferred by this privileged group are used to dump the Active Directory database, and retrieve the hash of the primary domain administrator.

-------------------------
Skills Required:
- Basic Knowledge of Windows
- Basic Knowledge of Active Directory
------------------------
Skills Learned:
Leveraging Backup Operators group membership
Dumping credentials from LSASS
Anonymous / Guest Enumeration
------------------------
Tools:
- manual enumeration
- netexec
- powershell
- bloodhound
- bloodhound-python
- neo4j
- impacket-get-gpppassword
- impacket-getnpusers
- kerbrute
------------------
Certifications:
Practical Network Penetration Tester (PNPT) : TCM Security - https://certifications.tcm-sec.com/pnpt/
Practical Junior Penetration Tester (PJPT): TCM Security - https://certifications.tcm-sec.com/pjpt/
Practical Junior Web Tester (PJWT): TCM Security - https://certifications.tcm-sec.com/pjwt/
Certified Ethical Hacker (CEH): EC-Council
--------------------
Socials:
Tryhackme: https://tryhackme.com/p/NoxLumens
Hackthebox: https://app.hackthebox.com/profile/179139
Twitch: https://twitch.tv/noxlumens







Tags:
noxlumens
noxlumen
hacking
cyber security
oscp
oscp prep
kali linux
hacker
malware
active directory
pentesting
web app pentesting
network pentesting
cyber ctf
offsec
offsec oscp
offsec proving grounds
gobuster
ad pentesting
ad pentest
active directory pentesting
enumeration
hackthebox
netexec
tjnulls
tj nulls oscp
hackthebox servmon
ssh port forward
how to hack
how to be a hacker
hacking for beginners
mssql hacking
mssql enumeration
hackthebox training