Skip to main content
Qubicweb logo

HackTheBox - Fries

July 25, 2026

Description

00:00 - Introduction 01:00 - Start of nmap 05:00 - Discovering PWM, then failing to find exploits/release date 08:45 - Doing a Virtual Host Brute Force, discovering a gitea instance, logging in and finding a new VHOST and credential 13:45 - Logged into PGAdmin playing with queries, shell the database but not much is gathered here 20:10 - Finding a CVE in PGAdmin which lets us run code on this container 31:45 - Some weird oddities with networking, got me to use the DB Shell as a Pivot Point (not needed) 36:50 - Running hydra to bruteforce SSH with credentials we have found so far 39:00 - Finding NFS running, getting a port forward then using NetExec to download the shadow file (doesn't get us much) 44:20 - Mounting the NFS Share then using setpriv to change our UID/GID so we can browse the NFS Share, download SSL Certs and generate our own to auth against docker 55:20 - Can auth against docker, start a new container mounting the root FS to the container, grabbing the ssh key and logging in as root 01:02:00 - Editing PWM Ldap config to point it at our server and stealing the credential it uses to bind to LDAP, then running Rusthound/Bloodhound 01:08:00 - Using ReadGMSA to get gMSA_CA_Prod$'s account, running Certipy running ESC7 but getting a denied 01:15:30 - We can modify ADCS Configuration, using Certify to make it vulnerable to ESC6 but still run into an issue 01:26:00 - The conflicting SAN/Security Extension give us an issue, enable ESC16 to disable this check and then getting a root shell

Watch on Original Source

Trust cues for videos

Internal ReadExternal SourceCuratedCommunity signalMixedSource-only
Videos - Qubicweb