Dancing Machine - Hack The Box - Writeup

Pasted image 20230412174621.png

Recon

To start the recon, we launch a nmap in Silent Mode to scan and know the open ports on the machine, don't apply DNS resolution and export the file to a format we can use grep.

Pasted image 20230412174814.png

Then launch a deep scan to know the version and the service running on that ports we discover open in the last scan.

Pasted image 20230412175207.png

We found an interesting port, the port 445.

Pasted image 20230412175635.png

In Windows Machines usually use this port to run the SMB Server. Link to document

Test Miss Configurations

If the SMB server has miss configurations you can list the folders on the server, as follows:

Pasted image 20230412180628.png

Lets try to get into a folder of smb server, as follows:

Pasted image 20230412180842.png

And we are inside the machine.

You can see some tricks in the next page Hack Tricks Link

Get The Flag

We can move inside the folders and search a hint to the flag, lets start with cd and you can get used to commands with the command help.

Pasted image 20230412181144.png

In this folder we found a file called worknotes.txt download it to your machine with the command get.

Go to your local machine and use the command cat to see if the file have a hints.

Pasted image 20230412181326.png

We found nothing.

Lets see the other Directory.

Pasted image 20230412181426.png

And we found the flag let's get the file to your local machine and read it with cat.

Pasted image 20230412181517.png

And congratulations you have pwned the machine.