Shuciran Pentesting Notes

Tentacle (Hard)

Host entries 10.10.10.224 realcorp.htb If Active Directory => NTP Synchronization with the domain controller. Content DNS Enumeration (dnsenum) SQUID Proxy WPAD Enumeration OpenSMTPD...

Chirpy Markdown

This post is to show Markdown syntax rendering on Chirpy, you can also use it as an example of writing. Now, let’s start looking at text and typography. Titles H1 - heading H2 - heading H3 - h...

AV Evasion Techniques

Placing files in writeable paths The following folders are by default writable by normal users (depends on Windows version - This is from W10 1803) C:\Windows\Tasks C:\Windows\Temp C:\windows\tra...

S3 Buckets

Passive Enumeration Domain.Glass Third-party providers such as domain.glass can provide information about the company’s infrastructure. GrayHatWarfare We can do many different searches, disco...

S3 Buckets

Basic Enumeration The site flaws.cloud is hosted as an S3 bucket. This is a great way to host a static site, similar to hosting one via github pages. Some interesting facts about S3 hosting: When ...

Fulcrum (Insane)

Host entries 10.10.10.62 upload.fulcrum.local dc.fulcrum.local If Active Directory => NTP Synchronization with the domain controller. Content API Enumeration - Endpoint Brute Force Advan...

Anubis (Insane)

Host: 10.10.11.102 windcorp.htb www.windcorp.htb If Active Directory => Synchronize your NTP with the domain controller: #Note This command does not work correctly on this machine, we circumven...

Acute (Hard)

Host entries: 10.10.11.145 atsserver.acute.local If Active Directory => NTP Synchronization with the domain controller. Content Information Leakage Abusing Windows PowerShell Web Acce...

Sizzle (Insane)

Content Parsing NMAP output FTP Enumeration (no files) SMBCacls Enumeration SMB Share with writting Permissions (SCF Attack) Hashcat cracking (NTLMv2) Ldap Enumeration (LdapDomainDump...

Scrambled (Medium)

Host entries: 10.10.11.168 scrm.local dc1.scrm.local If Active Directory => NTP Synchronization with the domain controller. Content LDAP Enumeration Web Enumeration Information Le...