Shuciran Pentesting Notes

Acute (Hard)

Host entries: 10.10.11.145 atsserver.acute.local If Active Directory => NTP Synchronization with the domain controller. Content Information Leakage Abusing Windows PowerShell Web Acce...

Sizzle (Insane)

Content Parsing NMAP output FTP Enumeration (no files) SMBCacls Enumeration SMB Share with writting Permissions (SCF Attack) Hashcat cracking (NTLMv2) Ldap Enumeration (LdapDomainDump...

Scrambled (Medium)

Host entries: 10.10.11.168 scrm.local dc1.scrm.local If Active Directory => NTP Synchronization with the domain controller. Content LDAP Enumeration Web Enumeration Information Le...

Cascade (Medium)

Host entries: 10.10.10.182 cascade.local casc-dc1.cascade.local domaindnszones.cascade.local forestdnszones.cascade.local hostmaster.cascade.local casc-dc1 dead:beef::e476:800b:b47d:c174 cascad...

Search (Hard)

Host entries: 10.10.11.129 search.htb research.search.htb If Active Directory => NTP Synchronization with the domain controller. Content Reconnaissance Initial reconnaissance for T...

Reel (Hard)

Host entries: 10.10.10.77 reel.htb.local htb.local If Active Directory => NTP Synchronization with the domain controller. Content Metadata Inspection with exiftool Crafting a malicio...

Resolute (Medium)

Host entries: 10.10.10.169 megabank.local resolute.megabank.local If Active Directory => NTP Synchronization with the domain controller. Content Reconnaissance Initial reconnaissan...

StreamIO (Medium)

Host entries: 10.10.10.125 watch.streamio.htb streamio.htb alpblog.streamio.htb If Active Directory => NTP Synchronization with the domain controller. Content LFI using PHP wrappers Sou...

Querier (Medium)

Host entries: 10.10.10.125 QUERIER querier.htb.local querier.htb If Active Directory => NTP Synchronization with the domain controller. Content SMB Null Session Macro identification on X...

Escape (Medium)

Host entries: 10.10.11.202 sequel.htb dc.sequel.htb If Active Directory => NTP Synchronization with the domain controller. Content SMB Enumeration MSSQL Server Procedures Searching MSS...