HackTheBox - Conceal

Share this & earn $10
IppSec
Published at : 23 Sep 2021
32417 views
457
6

01:15 - Begin of recon
02:54 - Checking SNMP with snmpwalk
03:29 - Discovering a Hashed PSK (MD5) in SNMPWalk, searching the internet for a decrypted value
04:18 - Getting more SNMP Information with snmp-check
07:35 - Going over UDP Ports discovered by snmp-check
10:55 - Running ike-scan
11:55 - Examining ike-scan results to build a IPSEC Config
13:50 - Installing Strongswan (IPSEC/VPN Program)
14:19 - Adding the PSK Found earlier to /etc/ipsec.secrets
15:30 - Begin configuring /etc/ipsec.conf
20:08 - Starting and debugging ipsec
21:55 - Explaining why we add TCP to strongswan config
24:00 - Starting IPSEC, then using NMAP through IPSEC.
(You may want to run WireShark here and see all traffic is encrypted thanks to ipsec)
25:55 - Enumerating SMB Quickly (SMBMap/cme)
26:50 - Enumerating FTP, discovering we can upload files
27:20 - Checking HTTP, hunting for our uploaded file. Then uploading files that may lead to code execution
29:44 - Grabbing an ASP Webshell from Github/tennc/webshell
32:08 - Webshell has been uploaded
32:30 - Explaining a weird MTU Issue you may run into due to the nested VPN’s
35:40 - Back to playing with the web shell, getting a reverse shell with Nishang
38:03 - Explaining RLWRAP
38:40 - whoami /all shows SEImpersonation, so we run JuicyPotato to privesc
44:35 - JuicyPotato fails with the default CLSID, changing it up to get it working.
46:30 - Doing the box again with Windows
47:15 - Setting up the IPSEC Connection through Windows Firewall
50:00 - Installing a DotNet C2 (The Covenant)
54:20 - Covenant/Elite open, starting a Listener then a Powershell Launcher
01:00:10 - Grunt activated. Running Seatbelt, then compiling Watson and reflectively running it
01:05:00 - Grabbing the Sandbox Escaper ALPC Privesc
01:08:03 - Being lazy and compiling a CPP Rev Shell in Linux because it wasn’t installed on Windows
(bunch of flailing, then reverting the machine)
01:25:35 - Box is reverted, trying the ALPC Exploit again

HackTheBoxConceal

"Crazy Youngsters" - Pitch Perfect 2 Official Music Video

"Crazy Youngsters" - Pitch Perfect 2 Official Music Video

Prone position for Covid-19 patients / Proning breathing exercises for Covid-19 patients

Prone position for Covid-19 patients / Proning breathing exercises for Covid-19 patients

Realizing Woodworking Ideas With Basic Tools // How To Build A Sturdy Table From Reclaimed Hardwood

Realizing Woodworking Ideas With Basic Tools // How To Build A Sturdy Table From Reclaimed Hardwood

Because of Who you Are-Vicki Yohe

Because of Who you Are-Vicki Yohe

12-Tone Music

12-Tone Music

Qualcomm, SSW Partners to acquire Veoneer for $37 per share

Qualcomm, SSW Partners to acquire Veoneer for $37 per share

Tears For Fears - Change

Tears For Fears - Change

Video: State workers have until midnight to comply with vaccine, testing mandate

Video: State workers have until midnight to comply with vaccine, testing mandate

Elon’s MOST VITAL new Tesla FINALLY CONFIRMED by the end of 2021? - This is MASSIVE!

Elon’s MOST VITAL new Tesla FINALLY CONFIRMED by the end of 2021? - This is MASSIVE!

Dijon - Many Times (Official Video)

Dijon - Many Times (Official Video)

Johnny Cash - Hurt (Official Music Video)

Johnny Cash - Hurt (Official Music Video)

Gary Neville On Sir Alex, His Biggest Disappointment and the 1999 Final | My Stories | @LADbible TV​

Gary Neville On Sir Alex, His Biggest Disappointment and the 1999 Final | My Stories | @LADbible TV​

Back To The 90s - 90s Greatest Hits Album - 90s Music Hits - Best Songs Of best hits 90s

Back To The 90s - 90s Greatest Hits Album - 90s Music Hits - Best Songs Of best hits 90s

Perhaps, Perhaps, Perhaps (Quizás, Quizás, Quizás) (Ao Vivo)

Perhaps, Perhaps, Perhaps (Quizás, Quizás, Quizás) (Ao Vivo)

Cardi B, Bad Bunny & J Balvin - I Like It [Official Music Video]

Cardi B, Bad Bunny & J Balvin - I Like It [Official Music Video]

Η Always Platinum είναι διαφορετική!

Η Always Platinum είναι διαφορετική!

This Fire

This Fire

Build with Glints

Build with Glints

Insights to Behavior Marketing Video HD1080p

Insights to Behavior Marketing Video HD1080p

Enya - Only Time (Official 4K Music Video)

Enya - Only Time (Official 4K Music Video)

Brad Paisley - He Didn't Have To Be (Official Video)

Brad Paisley - He Didn't Have To Be (Official Video)

LISTENING TO THIS SONG RIGHT BEFORE MY WEDDING IS A SIGN!! | NOTHING MORE - "Go to War" | (REACTION)

LISTENING TO THIS SONG RIGHT BEFORE MY WEDDING IS A SIGN!! | NOTHING MORE - "Go to War" | (REACTION)

Unisonic 'Exceptional' Official Music Video - New album 'Light Of Dawn' OUT NOW!

Unisonic 'Exceptional' Official Music Video - New album 'Light Of Dawn' OUT NOW!

DREAM | Jesus appeared as Gregory Peck 💫

DREAM | Jesus appeared as Gregory Peck 💫

D Billions - 123 Song

D Billions - 123 Song

Bride Must Find The Perfect Dress Suitable For Beach Wedding I Say Yes To The Dress UK

Bride Must Find The Perfect Dress Suitable For Beach Wedding I Say Yes To The Dress UK

iHEA Webinar - March 26, 2019 - Strategic purchasing for universal health coverage

iHEA Webinar - March 26, 2019 - Strategic purchasing for universal health coverage

7. Introduction to Permitting, Planning, Licensing & Compliance -Customer Portal  Permit Application

7. Introduction to Permitting, Planning, Licensing & Compliance -Customer Portal Permit Application

What Really Happened at the Arecibo Telescope?

What Really Happened at the Arecibo Telescope?

Enya - May It Be

Enya - May It Be

How to Pronounce SMOOTHLY - American English Pronunciation Lesson

How to Pronounce SMOOTHLY - American English Pronunciation Lesson

D-40 'The REAL You's seen in As A Rule how you spend your Free Time.' SL

D-40 'The REAL You's seen in As A Rule how you spend your Free Time.' SL

Christina Perri - A Thousand Years (Lyrics) 🎵

Christina Perri - A Thousand Years (Lyrics) 🎵

The family name is commonly used in English.

The family name is commonly used in English.

The Ultimate ReMarkable 2 Review

The Ultimate ReMarkable 2 Review

Fools Garden - Probably

Fools Garden - Probably

Chi Square and adjusted standardized Residual

Chi Square and adjusted standardized Residual

After 14 Years Matchboxes Will Be Costlier By Rupee1 |   पाहा 24 तास सुपरफास्ट

After 14 Years Matchboxes Will Be Costlier By Rupee1 | पाहा 24 तास सुपरफास्ट

joji - will he

joji - will he

Juice WRLD - Handle ft. Mac Miller, XXXTENTACION & Lil Peep (Music Video)

Juice WRLD - Handle ft. Mac Miller, XXXTENTACION & Lil Peep (Music Video)

Mac Miller - Guidelines (prod. Thelonious Martin)

Mac Miller - Guidelines (prod. Thelonious Martin)

🔴 Gentle NIGHT RAIN to Sleep Instantly, Beat Insomnia. Help Relax, Study. Rain Sound, Gentle Rain

🔴 Gentle NIGHT RAIN to Sleep Instantly, Beat Insomnia. Help Relax, Study. Rain Sound, Gentle Rain

Why You Need To Understand Local Search Engine Optimization?

Why You Need To Understand Local Search Engine Optimization?

Swagg boy Q with not particularly ( must watch😂)

Swagg boy Q with not particularly ( must watch😂)

SMALL BUSiNESS GIFT GUIDE // Buying Gifts from my FOLLOWER'S companies! // Fashion Mumblr

SMALL BUSiNESS GIFT GUIDE // Buying Gifts from my FOLLOWER'S companies! // Fashion Mumblr

9 Hormones That Lead to Weight Gain and Ways to Avoid It

9 Hormones That Lead to Weight Gain and Ways to Avoid It

Every Woman Needs to Hear This | Taking Alaina to the Pumpkin Patch and Prepping for Our Fall Trip!

Every Woman Needs to Hear This | Taking Alaina to the Pumpkin Patch and Prepping for Our Fall Trip!

E-BOOK CENA, SVE INFO + LIFE UPDATE

E-BOOK CENA, SVE INFO + LIFE UPDATE

Pronunciation of short, shot and sort and how to distinguish between similar vocabulary words

Pronunciation of short, shot and sort and how to distinguish between similar vocabulary words