Nmap Scan

SMB Enum

  • Backups share is accessible
  • downloaded prod.dtsConfig file

MS-SQL connection

  • used XP_CMDSHELL; to enumerate server

Used winPEASany.exe to enumerate

  • started a webserver on my local and downloaded file to target
  • winpeas identified a history file with saved commands

Admin password

smbclient to connect to C$

  • user.txt and root.txt were found
  • Flags

Leave a Reply

Your email address will not be published. Required fields are marked *