HackTheBox ~ Buff Walkthrough

Published: 21 November 2020
on channel: Parity InfoSec
758
15

#Buff up your enumeration skills! We walk through a very CVE focused box but touch on how to modify public exploits to run in a python3 environment. We touch on #basics like building a payload with msfvenom and port forwarding with Plink. I did get beat up on by the #demogods, but sometimes you just have to work through the issues to get root!

#bridgingthegap #cybersecurity #htb #hackthebox


00:00 Intro
02:57 NMap
03:30 Enum: website [8080]
05:47 CVE: Gym Management Software 1.0
07:42 Dirty Porting Scripts; py2.7 to py3
10:18 Exploit Gym Management Software
12:41 Upgrade shell via netcat
15:31 ~~USER.TXT~~
15:44 USER: Enumerate system [tasklist/netstat]
19:02 CVE: CloudMe 1.11.2
21:31 msfvenom: build payload executing netcat
25:00 Plink: Remote port forwarding [8888]
29:22 msfvenom: rebuild payload...again
30:41 Admin Shell access
31:12 ~~ROOT.TXT~~
31:15 Summary


On this page of the site you can watch the video online HackTheBox ~ Buff Walkthrough with a duration of hours minute second in good quality, which was uploaded by the user Parity InfoSec 21 November 2020, share the link with friends and acquaintances, this video has already been watched 758 times on youtube and it was liked by 15 viewers. Enjoy your viewing!