Hashes
[User Passwords - Encoded] Qm9iIC0gIVBAJCRXMHJEITEyMw== QmlsbCAtIEp1dzRubmFNNG40MjA2OTY5NjkhJCQk
Passwords
Creds
Bob : !P@$$W0rD!123
Bill : Juw4nnaM4n420696969!$$$
========================================================
NMAP
80/tcp open http Microsoft IIS httpd 10.0 |_http-server-header: Microsoft-IIS/10.0 |http-title: IIS Windows Server | http-methods: | Potentially risky methods: TRACE 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn
445/tcp open microsoft-ds Windows Server 2016 Standard Evaluation 14393 microsoft-ds 3389/tcp open ms-wbt-server Microsoft Terminal Services |_ssl-date: 2022-05-21T20:02:04+00:00; 0s from scanner time. | ssl-cert: Subject: commonName=Relevant | Not valid before: 2022-05-20T19:48:30 |Not valid after: 2022-11-19T19:48:30 | rdp-ntlm-info: | Target_Name: RELEVANT | NetBIOS_Domain_Name: RELEVANT | NetBIOS_Computer_Name: RELEVANT | DNS_Domain_Name: Relevant | DNS_Computer_Name: Relevant | Product_Version: 10.0.14393 | System_Time: 2022-05-21T20:01:22+00:00 49663/tcp open http Microsoft IIS httpd 10.0 |http-server-header: Microsoft-IIS/10.0 | http-methods: | Potentially risky methods: TRACE |_http-title: IIS Windows Server 49667/tcp open msrpc Microsoft Windows RPC 49669/tcp open msrpc Microsoft Windows RPC Service Info: OSs: Windows, Windows Server 2008 R2 - 2012
Directory Brute Force
80: Nothing
49663: Nothing
FileBrute Force
80: Nothing
49663: Nothing
Other
========================================================
Foothdold
PrivEsc
Steps
-Found an SMB share that was accessible with the Guest account
-In the share was a password doc
-tried to RDP with Bob creds and it failed
-tried to RDP with Bill creds and it failed, password expired