Hi Hackers Welcome Back, Today we are going to look at Hack The Box Blue Machine.
Info Table
Title
Blue
Category
Hack The Box
OS
Windows
Difficulty
Easy
Maker
Kill Chain Summery
While enumerating ports and services we can able to find the service, which is vulnerable to infamous CVE-2017-0143. Smb vulnerabilities which can be easily exploited with publicly available scripts and Metasploit.
Mind Map
Recon
we run a quick initial nmap scan to see which ports are open and which services are running on those ports.
$nmap -Pn -sC -sV -A 10.129.102.59 -oN initial
Starting Nmap 7.92 ( https://nmap.org ) at 2022-06-08 06:35 IST
Stats: 0:01:56 elapsed;0 hosts completed (1 up), 1 undergoing Service Scan
Service scan Timing: About 77.78% done; ETC: 06:37 (0:00:18 remaining)Nmap scan report for 10.129.102.59
Host is up (0.35s latency).
Not shown: 991 closed tcp ports (conn-refused)PORT STATE SERVICE VERSION
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
445/tcp open microsoft-ds Windows 7 Professional 7601 Service Pack 1 microsoft-ds (workgroup: WORKGROUP)49152/tcp open msrpc Microsoft Windows RPC
49153/tcp open msrpc Microsoft Windows RPC
49154/tcp open msrpc Microsoft Windows RPC
49155/tcp open msrpc Microsoft Windows RPC
49156/tcp open msrpc Microsoft Windows RPC
49157/tcp open msrpc Microsoft Windows RPC
Service Info: Host: HARIS-PC; OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results:
| smb2-security-mode:
| 2.1:
|_ Message signing enabled but not required
| smb2-time:
| date: 2022-06-08T01:07:44
|_ start_date: 2022-06-07T15:32:51
| smb-security-mode:
| account_used: guest
| authentication_level: user
| challenge_response: supported
|_ message_signing: disabled (dangerous, but default)| smb-os-discovery:
| OS: Windows 7 Professional 7601 Service Pack 1(Windows 7 Professional 6.1)| OS CPE: cpe:/o:microsoft:windows_7::sp1:professional
| Computer name: haris-PC
| NetBIOS computer name: HARIS-PC\x00| Workgroup: WORKGROUP\x00|_ System time: 2022-06-08T02:07:43+01:00
|_clock-skew: mean: -19m55s, deviation: 34m36s, median: 3s
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 134.70 seconds