Forest

1111214161727

Comments

  • edited November 2019

    Type your comment> @drdave said:

    when i use the evil method to try to walk my dog - he wont walk
    when i try the remote method i run into L**P connection errors - verbosity isnt helping much with the troubleshooting
    a PM hint would be appreciated

    I have the same problem, and i'm stuck.
    Impossible for me to walk the dog with evil...

  • edited November 2019

    Any tips for how I can extract the J**n? Iam using the main user with the e*** remote program.

  • Type your comment> @byth22 said:

    Any tips for how I can extract the J**n? Iam using the main user with the e*** remote program.

    Are you on the right track I have no Idea what you mean by the J**n.... The E*** program you speak of should get you shell with what you already know.

  • i'm completely stuck with user.. got an enumeration of users.. i can't get i*****et tool working.. tried with every syntax that went in my mind. surely i'm missing something on the syntax.. can somebody PM me?

  • edited November 2019

    @Nt3c said:
    Hey guys! need some help.
    When i run the cmd to give me D****c rights using powerview got the following error:
    Warning: Error granting principal xxxxxxxxxxxxx xxxx 'D****c' on DC=htb,DC=local : Exception calling "CommitChanges" with "0" argument(s): "A constraint violation occurred

    the comand to add the ACL seams to be ok, using evil-***rm
    any idias?
    Thanks.

    Same situation for me :(
    Already tried to do this locally with evil-**rm as well as remotely from my Windows machine with $Cred object and -Credentials argument. Both methods gave same error :/
    Could somebody help me with this?

    Moreover - when I add s-a******* to Exch**** W******* P******* group and check this with Get-DomainGroupMember everything is fine, s-a******o is in the group. But when I logout from evil-w**** and login again and execute Get-DomainGroupMember there is no s**-a******* in this group.
    I feel like Im missing something...

  • Need help overall on this box in dm please.

    tried using i*****t scripts, didnt work out.

  • Type your comment> @Looking4 said:

    Need help overall on this box in dm please.

    tried using i*****t scripts, didnt work out.

    Default Kali host contains some "wrapped" I******t programs and those do not cover features of all original python scripts. Download fresh I******t package from git, and use scripts located in its examples directory.

    bumika

  • Type your comment> @bumika said:

    Type your comment> @Looking4 said:

    Need help overall on this box in dm please.

    tried using i*****t scripts, didnt work out.

    Default Kali host contains some "wrapped" I******t programs and those do not cover features of all original python scripts. Download fresh I******t package from git, and use scripts located in its examples directory.

    That`s what i did.
    Maybe i have to do something else?

  • Type your comment> @jFlap said:

    i'm completely stuck with user.. got an enumeration of users.. i can't get i*****et tool working.. tried with every syntax that went in my mind. surely i'm missing something on the syntax.. can somebody PM me?

    I am at the same point. Tried almost every relevant scripts for hash dump but it is not working somehow. Some online examples shows the usage with the Hashes already!!!

    Any help would be appreciated.

  • edited November 2019

    Type your comment> @DeDeReporter said:

    @Nt3c said:
    Hey guys! need some help.
    When i run the cmd to give me D****c rights using powerview got the following error:
    Warning: Error granting principal xxxxxxxxxxxxx xxxx 'D****c' on DC=htb,DC=local : Exception calling "CommitChanges" with "0" argument(s): "A constraint violation occurred

    the comand to add the ACL seams to be ok, using evil-***rm
    any idias?
    Thanks.

    Same situation for me :(
    Already tried to do this locally with evil-**rm as well as remotely from my Windows machine with $Cred object and -Credentials argument. Both methods gave same error :/
    Could somebody help me with this?

    Moreover - when I add s-a******* to Exch**** W******* P******* group and check this with Get-DomainGroupMember everything is fine, s-a******o is in the group. But when I logout from evil-w**** and login again and execute Get-DomainGroupMember there is no s**-a******* in this group.
    I feel like Im missing something...

    ah, it isn't me.
    got the same problem

    whoa, i figured it out (i think,have to doublecheck)

    windows 7 is my rig :) if it can't be done on windows, i fail.

  • edited November 2019

    Type your comment> @Looking4 said:

    Type your comment> @bumika said:

    Type your comment> @Looking4 said:

    Need help overall on this box in dm please.

    tried using i*****t scripts, didnt work out.

    Default Kali host contains some "wrapped" I******t programs and those do not cover features of all original python scripts. Download fresh I******t package from git, and use scripts located in its examples directory.

    That`s what i did.
    Maybe i have to do something else?

    It is really difficult to Get the proper one of 48 scripts. It is a hint.

    bumika

  • I got username and tri3d to get password or hashes but didnt get any of them i was wrong some where couldnt figure out need help !!!

  • Type your comment> @DrCyb3r said:

    I got username and tri3d to get password or hashes but didnt get any of them i was wrong some where couldnt figure out need help !!!

    DM me, i will help u

  • Anyone here who can give me a nudge to root. I can DM and tell where I am stuck. Any Help will be really appreciated! Been Stuck here for 2 days now lol.

    Hack The Box

  • edited November 2019

    Anyone else stuck with the d..y.. right problem?

  • I can't seem to get the dog to walk using e******m. Can someone DM some clues?

  • got user and the password, what should i do next?

    PM me some small tips please!!!!

  • edited November 2019

    working on this one

  • Im trying to use multiple scripts from tool mentioned here a lot of times but all i get is
    KDC_ERR_WRONG_REALM
    can someone dm me with some tip becouse im trying for a long time now and can't do nothing

  • i found the user,found the hash,cracked it got the pass,enumerated the shares, but cant seem to connect to them.
    hints please

    Arrexel

  • Really fun box, learned so much and yet there is still so much more to learn about this, even after getting system...

    If you are like me and only have notions of this type of attack and never actually performed it, my best overall advice is: enjoy the learning experience! Read alot and document your findings and dig deeper into why some things (tools) work and why not. It's going to take some time but the time spent, will ROI on other Windows boxes

    • Got side-tracked by other user's footprints on the system, so before you map out your path make sure you are focussing on the right things, maybe reset the box before you pull out the map data.

    • About using the map: there are other tools available that plug into it and can calculate and automate a path for you. I actually needed this because the suggested PS commands to do it manually, did not work for me (Both versions of P****V***. I will get to the bottom of this, want to know why)

    If you're stuck, feel free to dm me for nudges

  • Type your comment> @wwingcomm said:

    Really fun box, learned so much and yet there is still so much more to learn about this, even after getting system...

    If you are like me and only have notions of this type of attack and never actually performed it, my best overall advice is: enjoy the learning experience! Read alot and document your findings and dig deeper into why some things (tools) work and why not. It's going to take some time but the time spent, will ROI on other Windows boxes

    • Got side-tracked by other user's footprints on the system, so before you map out your path make sure you are focussing on the right things, maybe reset the box before you pull out the map data.

    • About using the map: there are other tools available that plug into it and can calculate and automate a path for you. I actually needed this because the suggested PS commands to do it manually, did not work for me (Both versions of P****V***. I will get to the bottom of this, want to know why)

    If you're stuck, feel free to dm me for nudges

    help ..

  • so far: got k****t hashes. Now what?

  • Help on root. Have the initial shell. Can tool wont run to map things out.

  • edited November 2019

    Finally rooted. Big respect for @izzie and @Nt3c for help. Feel free to PM for nudges.
    And one more thing: can someone explain why Powe*V*** command doesnt work for granting Rep********* privilige?

  • edited November 2019

    Hey, I get the error KDC_ERR_WRONG_REALM when trying the script "Ge********s.p" (has been mentioned previously in the thread), but I don't know how to resolve the error. Basically, it cannot find the KD (entity) for K*****s, but I don't know how to get rid of that error... I've added the domain name to my hosts, so the error shouldn't be there.... any help would be appreciated!

    Update: Got it!

  • can not get the hound to work? Nudge please, never used this tool before.

  • Type your comment> @PanamaEd117 said:

    can not get the hound to work? Nudge please, never used this tool before.

    There is a well maintained Wiki available to set the tool up. Also, the remote version worked well to collect what I needed.

  • edited November 2019

    ok got user and found juicy file S********.exe but it won't run
    is not recognized as the name of a cmdlet ...?
    first win machine allready surprised i got this far.
    please advice..

    Edit: got the dog running

    Hack The Box

Sign In to comment.