<aside>
Inlanefreight Domain Controller and capture the associated flag.data, credentials, scripts, or other information within the environment to enable your pivoting attempts.any/all flags that can be found.
</aside><aside>
My machine
10.10.14.66
Foothold on 10.129.229.129 ( Web Shell )
→ after some search found id_rsa and transfer it with python3 -m http.server 8080
→ got SSH using webadmin user with id_rsa Founded
→ get creds mlefay:Plain Human work!
→ Make ip a to see if there’s another Networks and found that
<aside>
inet 172.16.5.15/16 another Network
</aside>
</aside>
<aside>
Internal Network on 172.16.5.0/16
try to found another hosts using for i in {1..254} ;do (ping -c 1 172.16.5.$i | grep "bytes from" &) ;done on compromised machine and found →
64 bytes from 172.16.5.15: icmp_seq=1 ttl=64 time=0.037 ms
64 bytes from 172.16.5.35: icmp_seq=1 ttl=128 time=1.70 ms
Now we have Windows Host on 172.16.5.35 with RDP Creds We Found before mlefay:Plain Human work!
now from Our Attack Machine and because we have Dynamic Port Forwarding on 9050 with proxychains,
we can Connect to RDP like proxychains xfreerdp /v:172.16.5.35 /u:melfay /p:'Plain Human Work!'
</aside>