rahulr.in

Security writeups
and research notes.

[email protected]:~$ whoami
Rahul R · Security Engineer · Penetration Tester
Dubai, UAE
[email protected]:~$ cat interests.txt
pentesting · active directory · cloud · android
reverse engineering · malware · hardware · ctf
[email protected]:~$ ls -la blog/
 14  posts          4  htb-writeups
  9  categories    20  tags
[email protected]:~$ htb --status
Elite Hacker · #107 global · 1536 pts · 251/232 owns
[email protected]:~$ 
tryhackme4 min

Tryhackme Ra Walkthrough

Ra is a windows machine which starts with a typical business website for Windcorp where there is a password reset function which can be used to change a user's password to gain access to a SMB share to download spark live chat application which is vulnerable that can be used to harvest a user's NTLM hash that can be used to gain initial access to the machine.On further exploring the machine a script can be seen that contains a username who's password can be changed since the user has extended rights to change password as he is a member of the account operator group.Analysing the script we can see that there is command injection vulnerability that can be abused to gain admin privilege and pwn the machine

$browse by category

all tags →