HackTheBox - ServMon | Beginner Friendly | Road to OSCP #47
mutatedknutz
0:00 / 0:00
HackTheBox - ServMon | Beginner Friendly | Road to OSCP #47
365 просмотров · 6 лет назад
mutatedknutz
1,58 тыс. подписчиков
365 просмотров · 6 лет назад
This is a Beginner friendly pentesting video where we will be gaining system access on HackTheBox - ServMon machine. We will be obtaining credentials by exploiting NVMS directory traversal vulnerability.We will be exploiting nsclient script execution to get system access.
00:00 Intro
00:17 Enumeration using AutoRecon
04:43 Enumerating FTP port 21 and analyzing files found
10:57 Enumerating port 80 and analyzing NVMS exploit
15:16 Analyzing NVMS directory traversal in burp suite and obtaining passwords file
20:00 Directory traversal explanation
24:14 Using hydra to obtain valid ssh credentials
28:14 SSH into the box as user Nadine and manual enumeration
30:38 Enumerating port 8443 and obtaining NSClient password
33:35 Analyzing NSClient exploit POC
36:23 Enumerating the nscp service
38:31 Port forwarding using SSH
43:30 Successfully accessing NSClient application and analyzing modules
44:43 Testing nc.exe and .bat reverse shell
53:06 Creating external scripts in NSClient and getting system shell
59:24 Adding and executing script in NSClient using curl and getting system shell
1:05:10 Restarting nscp
1:06:10 Executing script using NSClient console and getting system shell
#hackthebox #servmon