<aside>

Objectives


<aside>

My machine

10.10.14.66


Foothold on 10.129.229.129 ( Web Shell )

→ after some search found id_rsa and transfer it with python3 -m http.server 8080

→ got SSH using webadmin user with id_rsa Founded

→ get creds mlefay:Plain Human work!

→ Make ip a to see if there’s another Networks and found that

<aside>

inet 172.16.5.15/16 another Network

</aside>

</aside>

<aside>

Internal Network on 172.16.5.0/16

try to found another hosts using for i in {1..254} ;do (ping -c 1 172.16.5.$i | grep "bytes from" &) ;done on compromised machine and found →

64 bytes from 172.16.5.15: icmp_seq=1 ttl=64 time=0.037 ms
64 bytes from 172.16.5.35: icmp_seq=1 ttl=128 time=1.70 ms

Now we have Windows Host on 172.16.5.35 with RDP Creds We Found before mlefay:Plain Human work!

now from Our Attack Machine and because we have Dynamic Port Forwarding on 9050 with proxychains,

we can Connect to RDP like proxychains xfreerdp /v:172.16.5.35 /u:melfay /p:'Plain Human Work!'

</aside>