Tag: Hacking
-
Hack the Box Walkthrough: Giddy
Giddy was a fun box that has a few interesting twists on some common ground. Not only is there SQL injection, but out of band sql injection. Powershell plays a major part along with a bit of antivirus evasion. So we have ports 80, 3389, and 5985 all open. Well, let’s do some directory busting…
-
Hack the Box Walkthrough: Active
For the first Hackthebox CTF walkthrough, I’m picking an old but good one. As the name might imply, the focus lies on Active Directory and in particular, Kerberoasting. Kerberoasting is a form of exploitation that uses a service account ticket in order to escalate privileges and gain access to an active directory domain. Without further…
-
Hack the Box Walkthrough: SteamCloud
Steamcloud is a great box for learning about kubernetes. As always, starting off with an nmap scan: So we got ports 22, 2379, 8443, 10249, 10250, and 10256 open. Taking a look at the details, ports 8443 and 10256 both reference kubernetes. Using some Google-Fu, I found a rather helpful article on Kubernetes Attack Surface…