ARCHIVE

Latest writeups

“Hacking is not a crime,
it’s a mindset.”— MR7
Mostrando 73 writeups
Hack The Box

HackTheBox - Airtouch (medium)

AirTouch es una máquina Linux de dificultad media construida alrededor de una ruta de ataque inalámbrica iniciada desde una workstation de un consultor. Comenzando con una enumerac...

Leer writeup
Wi-Fi

WifiChallengeLab - Wi-Fi - MGT

- Link del laboratorio: . - Ejemplo de una conexión MGT. Esta imagen representa el proceso de autenticación en una red utilizando 802.1 X con EAP y RADIUS . En este esquema partici...

Leer writeup
Hack The Box

HackTheBox - SecNotes (medium)

- SecNotes is a medium difficulty machine, which highlights the risks associated with weak password change mechanisms, lack of CSRF protection and insufficient validation of user i...

Leer writeup
Hack The Box

HackTheBox - Slonik (medium)

Nmap - Comenzamos escaneando puertos abiertos y servicios que corren en los puertos de la máquina por el protocolo TCP. NFS Service - Vemos que la máquina victima esta usando NFS s...

Leer writeup
PortSwigger

Path Traversal - Portswigger

Path traversal es una vulnerabilidad donde un atacante manipula una ruta de archivo para salir del directorio permitido y acceder a archivos que no debería. Lab: File path traversa...

Leer writeup
Hack The Box

HackTheBox - Certified (medium)

- Certified is a medium-difficulty Windows machine designed around an assumed breach scenario, where credentials for a low-privileged user are provided. To gain access to the manag...

Leer writeup
DockerLabs

DockerLabs - SummerVibes (hard)

- Esta Máquina es de la plataforma de DockerLabs en mi opinión es fácil pero esta catalogada como difícil. PortScan Enumeración - Estas son las tecnologías que esta usando la pagin...

Leer writeup
Hack The Box

HackTheBox - Tenten (medium)

- Tenten is a medium difficulty machine that requires some outside-the-box/CTF-style thinking to complete. It demonstrates the severity of using outdated Wordpress plugins, which i...

Leer writeup
Hack The Box

HackTheBox - Broker (easy)

- Broker is an easy difficulty Linux machine hosting a version of Apache ActiveMQ . Enumerating the version of Apache ActiveMQ shows that it is vulnerable to Unauthenticated Remote...

Leer writeup
Hack The Box

HackTheBox - Altered (hard)

- Further enchance your skills by exploring related academy modules. PortScan Enumeración - Tenemos 2 puertos abiertos el puerto 22 que corresponde al servicio ssh y el puerto 80 q...

Leer writeup
Hack The Box

HackTheBox - Schooled (medium)

- Schooled is a medium difficulty FreeBSD machine that showcases two recently disclosed vulnerabilities affecting the Moodle platform (labeled CVE-2020-25627 and CVE-2020-14321), w...

Leer writeup
Hack The Box

HackTheBox - Photobomb (easy)

- Photobomb is an easy Linux machine where plaintext credentials are used to access an internal web application with a Download functionality that is vulnerable to a blind command ...

Leer writeup
Hack The Box

HackTheBox - Poison (medium)

- Poison is a fairly easy machine which focuses mainly on log poisoning and port forwarding/tunneling. The machine is running FreeBSD which presents a few challenges for novice use...

Leer writeup
Hack The Box

HackTheBox - Waldo (medium)

- Waldo is a medium difficulty machine, which highlights the risk of insufficient input validation, provides the challenge of rbash escape or bypassing, and showcases an interestin...

Leer writeup
Hack The Box

HackTheBox - Office (hard)

- Office is a hard-difficulty Windows machine featuring various vulnerabilities including Joomla web application abuse, PCAP analysis to identify Kerberos credentials, abusing Libr...

Leer writeup
Hack The Box

HackTheBox - Anubis (insane)

- Anubis is an insane difficulty Windows machine that showcases how a writable certificate template in the Windows Public Key Infrastructure can lead to the escalation of privilege...

Leer writeup
Hack The Box

HackTheBox - Authority (medium)

- Authority is a medium-difficulty Windows machine that highlights the dangers of misconfigurations, password reuse, storing credentials on shares, and demonstrates how default set...

Leer writeup
Hack The Box

HackTheBox - Epsilon (medium)

- Epsilon is a medium difficulty Linux machine which exposes a Git repository on the webserver. AWS credentials are leaked in Git commits, which allows downloading the AWS Lambda f...

Leer writeup
Hack The Box

HackTheBox - Tenet (medium)

- Tenet is a Medium difficulty machine that features an Apache web server. It contains a Wordpress blog with a few posts. One of the comments on the blog mentions the presence of a...

Leer writeup
Hack The Box

HackTheBox - Hawk (medium)

- Hawk is a medium to hard difficulty machine, which provides excellent practice in pentesting Drupal. The exploitable H2 DBMS installation is also realistic as web-based SQL conso...

Leer writeup
Hack The Box

HackTheBox - Crafty (easy)

- Crafty is an easy-difficulty Windows machine featuring the exploitation of a Minecraft server. Enumerating the version of the server reveals that it is vulnerable to pre-authenti...

Leer writeup
Hack The Box

HackTheBox - Pressed (hard)

PortScan Enumeración - El escaneo de Nmap solo nos reporta 1 puerto abierto que esta corriendo un servicio http y esta usando un gestor de contenido que es Wordpress . - Si investi...

Leer writeup
Hack The Box

HackTheBox - Jeeves (medium)

- Jeeves is not overly complicated, however it focuses on some interesting techniques and provides a great learning experience. As the use of alternate data streams is not very com...

Leer writeup
Hack The Box

HackTheBox - Pandora (easy)

- Pandora is an easy rated Linux machine. The port scan reveals a SSH, web-server and SNMP service running on the box. Initial foothold is obtained by enumerating the SNMP service,...

Leer writeup
Hack The Box

HackTheBox - Absolute (insane)

- Absolute is an Insane Windows Active Directory machine that starts with a webpage displaying some images, whose metadata is used to create a wordlist of possible usernames that m...

Leer writeup
Hack The Box

HackTheBox - Fulcrum (insane)

- Fulcrum is one of the most challenging machines on Hack The Box. It requires multiple pivots between Linux and Windows, and focuses heavily on the use of PowerShell. PortScan - C...

Leer writeup
Hack The Box

HackTheBox - Analysis (hard)

- Analysis is a hard-difficulty Windows machine, featuring various vulnerabilities, focused on web applications, Active Directory (AD) privileges and process manipulation. Initiall...

Leer writeup
Hack The Box

HackTheBox - Wifinetic (easy)

- Wifinetic is an easy difficulty Linux machine which presents an intriguing network challenge, focusing on wireless security and network monitoring. An exposed FTP service has ano...

Leer writeup
Hack The Box

HackTheBox - Inject (easy)

- Inject is an Easy Difficulty Linux machine featuring a website with file upload functionality vulnerable to Local File Inclusion (LFI). By exploiting the LFI vulnerability, files...

Leer writeup
Hack The Box

HackTheBox - Cascade (medium)

- Cascade is a medium difficulty Windows machine configured as a Domain Controller. LDAP anonymous binds are enabled, and enumeration yields the password for user r.thompson , whic...

Leer writeup
Hack The Box

HackTheBox - Shared (medium)

- Shared is a Medium Difficulty Linux machine that features a Cookie SQL Injection leading to a foothold, which is then used to escalate privileges by reverse engineering a Golang ...

Leer writeup
Hack The Box

HackTheBox - Worker (medium)

- Worker is a medium box that teaches about software development environments and Azure DevOps pipeline abuse. It starts with extraction of source code from a SVN server, and then ...

Leer writeup
Hack The Box

HackTheBox - Hospital (medium)

- Hospital is a medium-difficulty Windows machine that hosts an Active Directory environment, a web server, and a RoundCube instance. The web application has a file upload vulnerab...

Leer writeup
Hack The Box

HackTheBox - Sizzle (insane)

- Sizzle is an Insane difficulty Windows box with an Active Directory environment. A writable directory in an SMB share allows to steal NTLM hashes which can be cracked to access t...

Leer writeup
Hack The Box

HackTheBox - Scrambled (medium)

- Scrambled is a medium Windows Active Directory machine. Enumerating the website hosted on the remote machine a potential attacker is able to deduce the credentials for the user k...

Leer writeup
Hack The Box

HackTheBox - Giddy (medium)

- En este post vamos a resolver la maquina Giddy de la plataforma de Hack The Box donde aprovechándonos de una SQL Injection vamos a robar el hash NTLMv2 de un usuario y nos podrem...

Leer writeup
Hack The Box

HackTheBox - Blackfield (hard)

- En este post vamos a estar haciendo la maquina Blackfield de la plataforma de Hack The Box donde vamos a estar enumerando por SMB, estar usando kerbrute para validar usuarios del...

Leer writeup
Hack The Box

HackTheBox - Active (easy)

- Active is a quick and fun medium box where we have to do SMB enumeration to obtain credentials of a valid user in the dc and Kerberoasting to receive a ticket to crack this ticke...

Leer writeup
Hack The Box

HackTheBox - APT (insane)

- En este post vamos a estar haciendo la maquina APT de la plataforma de Hack The Box donde mediante una enumeración por RPC encontramos que se esta empleando IPV6 en la maquina vi...

Leer writeup
Hack The Box

HackTheBox - Heist (easy)

! busqueda-avatar (https://labs.hackthebox.com/storage/avatars/131dbaba68b169bd5ff59ac09420b09f.png) En este post vamos a estar haciendo la maquina Heist de la plataforma de Hack T...

Leer writeup
Hack The Box

HackTheBox - Search (hard)

- En este post vamos a estar resolviendo la maquina Search de la plataforma de Hack The Box que es un entorno de Directorio Activo donde vamos a estar enumerando por los protocolos...

Leer writeup
Hack The Box

HackTheBox - Support (easy)

PortScan - Comenzamos escaneando los puertos abiertos y sus tecnologias con la herramienta Nmap . Enumeración - Vamos agregar en nombre del dominio al /etc/hosts . - Si listamos lo...

Leer writeup
Hack The Box

HackTheBox - Monteverde (medium)

En este post vamos a estar haciendo la maquina Monteverde de la plataforma de Hack The Box donde mediante el protocolo RPC vamos a estar enumerando usuarios del dominio y gracias a...

Leer writeup
Hack The Box

HackTheBox - Querier (medium)

En este post vamos a estar haciendo la maquina Querier de la plataforma de Hack The Box mediante la enumeración de un recurso compartido por smb vamos a descargador un archivo Exce...

Leer writeup
Hack The Box

HackTheBox - Resolute (medium)

En este post vamos a estar resolviendo la maquina Resolute de la plataforma de HackTheBox en la cual vamos a estar enumerando el protocolo RPC gracias a eso obtendremos una lista d...

Leer writeup
Hack The Box

HackTheBox - Driver (easy)

- En este post vamos a estar haciendo la maquina Driver de la plataforma de Hack The Box después de usar credenciales por defecto en el servicio web podremos subir un archivo .scf ...

Leer writeup
Hack The Box

HackTheBox - Flight (hard)

En este post vamos a estar haciendo la máquina Flight de Hackthebox de dificultad difícil vamos a estar consiguiendo hashes ntlmv2 de varios usuarios para ganar acceso ala máquina ...

Leer writeup
Hack The Box

HackTheBox - Manager (medium)

- Manager es una máquina Windows de dificultad media que alberga un entorno de Active Directory con AD CS (Active Directory Certificate Services), un servidor web y un servidor SQL...

Leer writeup
Hack The Box

HackTheBox - Mantis (hard)

- En este post vamos a hacer la maquina Mantis de la plataforma de Hackthebox donde vamos a estar encontrando una ruta en un servicio web donde nos darán credenciales para conectar...

Leer writeup
Hack The Box

HackTheBox - Sauna (easy)

- En este post estaremos resolviendo la maquina Sauna de la plataforma de Hackthebox donde estaremos tocando temas de Active Directory mediante un un script de Nmap podremos hacer ...

Leer writeup
Hack The Box

HackTheBox - Forest (easy)

- En este post vamos a resolver la maquina Forest que contempla Active Directory mediante una enumeracion por RPC vamos a poder obtender un listado potencial de usuarios para poder...

Leer writeup
Hack The Box

HackTheBox - Escape (medium)

- En este post vamos a estar resolviendo la maquina Escape de la plataforma de HackTheBox donde gracias a un archivo que encontramos por SMB podremos obtener credenciales e informa...

Leer writeup
Hack The Box

HackTheBox - Blue (easy)

PortScan Enumeracion - Pues bueno mediante Nmap podemos aplicar un script para que nos reporte si es vulnerable a esta vulnerabilidad. - Con crackmapexec vemos que efectivamente es...

Leer writeup
Hack The Box

HackTheBox - Timelapse (easy)

- En este post vamos a resolver la maquina Timelapse de la plataforma de Hackthebox donde mediante SMB vamos a obtener un zip que contiene un archivo pfx pero antes de obtenerlo te...

Leer writeup
Hack The Box

HackTheBox - Return (easy)

- En este post vamos a estar resolviendo la maquina Return de Hackthebox donde vamos a estar enumerando primero por SMB pero no encontramos nada después por el puerto 80 que esta c...

Leer writeup
VulnLab

Vulnlab - Breach

PortScan - Estos son los puertos abiertos por el protocolo TCP . Enumeracion - Vamos a añadir los dominios al /etc/hosts . - Estamos ante un Windows 10. - Si tratamos de enumerar r...

Leer writeup
VulnLab

Vulnlab - Retro

PortScan - Hacemos un escaneo buscando puertos abiertos por el protocolo TCP . SMB Enumeration - Vamos a agregar los dominios que tenemos al /etc/hosts . - Vemos que estamos ante u...

Leer writeup
VulnLab

Vulnlab - Media

PortScan - Comenzamos escaneando los puertos abiertos por el protocolo TCP de la máquina víctima. Port 80 hash NTLMv2 - Vemos que está corriendo un servicio web y vemos las tecnolo...

Leer writeup
VulnLab

Vulnlab - Escape

PortScan - Comenzamos escaneando los puertos abiertos por el protocolo TCP donde solo encontramos un puerto abierto 3389 por el protocolo TCP . xfreerdp - Vamos a conectarnos. - No...

Leer writeup
VulnLab

Vulnlab - Data

- En este post vamos a estar haciendo la máquina Data de la plataforma de Vulnlab es una máquina linux donde estaremos explotando el CVE-2021-43798 de Grafana en el cual podremos l...

Leer writeup
VulnLab

Vulnlab - Baby

- En este post vamos a estar realizando la máquina Baby de la plataforma de Vulnlab es una máquina Windows de categoría fácil creada por xct donde mediante el protocolo LDAP podrem...

Leer writeup
VulnLab

Vulnlab - FeedBack

- En este post vamos a resolver la máquina Feedback de la plataforma de Vulnlab en la cual vamos a explotar una vulnerabilidad conocida llamada log4shell qué salió en el año 2021 q...

Leer writeup
Wi-Fi

Hacking Wifi - WEP

Introducción WEP - Wired Equivalent Privacy (Privacidad Equivalente a la Conexión por Cable), es un protocolo de seguridad diseñado para proteger las redes inalámbricas. Fue uno de...

Leer writeup
Wi-Fi

Hacking Wifi - WPA2

Como ya sabemos necesitas una antena que acepte modo monitor en el anterior post deje el link de una antena que recomiendo al igual que muchas personas en este post nos vamos a est...

Leer writeup
Wi-Fi

Hacking Wifi - WifiChallenge 2

Antes de empezar - Para descargar la maquina virtual y podemos acceder al laboratorio puedes hacerlo desde aquí . - Las credenciales para acceder al laboratorio son user:user . - P...

Leer writeup
PortSwigger

SQL Injection - Portswigger

⮕ SQL Injections Lab (Puedes dar click en cualquier tipo de inyeccion que esta en el contenido para ir directamente a esa) Las inyecciones SQL se producen cuando los atacantes inse...

Leer writeup