Перейти к содержимому

HackTheBox - ServMon | Beginner Friendly | Road to OSCP #47

mutatedknutz

0:00 / 0:00

HackTheBox - ServMon | Beginner Friendly | Road to OSCP #47

365 просмотров · 6 лет назад
mutatedknutz
1,58 тыс. подписчиков
365 просмотров · 6 лет назад
This is a Beginner friendly pentesting video where we will be gaining system access on HackTheBox - ServMon machine. We will be obtaining credentials by exploiting NVMS directory traversal vulnerability.We will be exploiting nsclient script execution to get system access. 00:00 Intro 00:17 Enumeration using AutoRecon 04:43 Enumerating FTP port 21 and analyzing files found 10:57 Enumerating port 80 and analyzing NVMS exploit 15:16 Analyzing NVMS directory traversal in burp suite and obtaining passwords file 20:00 Directory traversal explanation 24:14 Using hydra to obtain valid ssh credentials 28:14 SSH into the box as user Nadine and manual enumeration 30:38 Enumerating port 8443 and obtaining NSClient password 33:35 Analyzing NSClient exploit POC 36:23 Enumerating the nscp service 38:31 Port forwarding using SSH 43:30 Successfully accessing NSClient application and analyzing modules 44:43 Testing nc.exe and .bat reverse shell 53:06 Creating external scripts in NSClient and getting system shell 59:24 Adding and executing script in NSClient using curl and getting system shell 1:05:10 Restarting nscp 1:06:10 Executing script using NSClient console and getting system shell #hackthebox #servmon