Walkthrough of the machine called “Vault” in the OffSec Proving Grounds…This is a Windows machine rated as hard, don’t watch unless you want help getting through the machine. In this machine we use phishing type links on an open SMB share to catch hashes using responder for initial access, after quite a bit of enumeration we end up using PowerView and some other tools to determine we can abuse the Default Domain Policy using SharpGPOAbuse to privilege escalate to administrator level access.
Posted inEthical Hacking Hacking Linux Networking Offsec Security Tutorial Uncategorized Walkthrough