Hashes

[User Passwords - Encoded] Qm9iIC0gIVBAJCRXMHJEITEyMw== QmlsbCAtIEp1dzRubmFNNG40MjA2OTY5NjkhJCQk

Passwords

Creds

Bob : !P@$$W0rD!123

Bill : Juw4nnaM4n420696969!$$$

========================================================

NMAP

80/tcp open http Microsoft IIS httpd 10.0 |_http-server-header: Microsoft-IIS/10.0 |http-title: IIS Windows Server | http-methods: | Potentially risky methods: TRACE 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn

445/tcp open microsoft-ds Windows Server 2016 Standard Evaluation 14393 microsoft-ds 3389/tcp open ms-wbt-server Microsoft Terminal Services |_ssl-date: 2022-05-21T20:02:04+00:00; 0s from scanner time. | ssl-cert: Subject: commonName=Relevant | Not valid before: 2022-05-20T19:48:30 |Not valid after: 2022-11-19T19:48:30 | rdp-ntlm-info: | Target_Name: RELEVANT | NetBIOS_Domain_Name: RELEVANT | NetBIOS_Computer_Name: RELEVANT | DNS_Domain_Name: Relevant | DNS_Computer_Name: Relevant | Product_Version: 10.0.14393 | System_Time: 2022-05-21T20:01:22+00:00 49663/tcp open http Microsoft IIS httpd 10.0 |http-server-header: Microsoft-IIS/10.0 | http-methods: | Potentially risky methods: TRACE |_http-title: IIS Windows Server 49667/tcp open msrpc Microsoft Windows RPC 49669/tcp open msrpc Microsoft Windows RPC Service Info: OSs: Windows, Windows Server 2008 R2 - 2012

Directory Brute Force

80: Nothing

49663: Nothing

FileBrute Force

80: Nothing

49663: Nothing

Other

========================================================

Foothdold

PrivEsc

Steps

-Found an SMB share that was accessible with the Guest account

-In the share was a password doc

-tried to RDP with Bob creds and it failed

-tried to RDP with Bill creds and it failed, password expired