HTB Axlle - Writeup
by macavitysworld - Sunday June 23, 2024 at 09:05 AM
#11
(06-24-2024, 05:26 AM)4rrows Wrote:
(06-24-2024, 02:11 AM)jeff1998 Wrote:
(06-23-2024, 10:41 PM)4rrows Wrote: This was helpful but when I try to dump sam, security and system hive on metasploit I get an error "specify [-k]". Can anyone please help??

you already got elevated shell. if that not work why not just load mimikatz, lazagne, or other tools that able to backup SAM.....

I have a shell as jacob.greeny but still I can't dump SAM, SYSTEM and SECURITY. I loaded mimikatz and when I run privilege::debug I get an error again

You cant dump SAM from Jacob.Greeny, but you can overwrite standalonerunner.exe as Jacob.Greeny, use your imagination, get a meterpreter shell, them use "hashdump"
#12
(06-23-2024, 09:05 AM)macavitysworld Wrote: HTB - Freelancer Writeup

https://katopia.me/HTB/Machines/Hard/axlle

Note: This is really a vague writeup, There are no passwords or hashes included.



Updated Writeup with Intended Root Exploit
#13
Hi. Thanks for this great resource, I am trying toy execute this:
x86_64-w64-mingw32-gcc -fPIC -shared -o shell.xll exploit.c -luser32
but the error says cc1: fatal error: exploit.c: No such file or directory
Are we suppose to create an empty exploit.c file ?
#14
(06-26-2024, 11:18 AM)DoesntMatter123456 Wrote: Hi. Thanks for this great resource, I am trying toy execute this:
x86_64-w64-mingw32-gcc -fPIC -shared -o shell.xll exploit.c -luser32
but the error says cc1: fatal error: exploit.c: No such file or directory
Are we suppose to create an empty exploit.c file ?

make a file named exploit.c, and put the modified script in there
#15
(06-26-2024, 11:18 AM)DoesntMatter123456 Wrote: Hi. Thanks for this great resource, I am trying toy execute this:
x86_64-w64-mingw32-gcc -fPIC -shared -o shell.xll exploit.c -luser32
but the error says cc1: fatal error: exploit.c: No such file or directory
Are we suppose to create an empty exploit.c file ?

Don't Ctrl+C & Ctrl+V Read, Understand and Do it!
#16
(06-26-2024, 12:18 PM)mxntysec Wrote:
(06-26-2024, 11:18 AM)DoesntMatter123456 Wrote: Hi. Thanks for this great resource, I am trying toy execute this:
x86_64-w64-mingw32-gcc -fPIC -shared -o shell.xll exploit.c -luser32
but the error says cc1: fatal error: exploit.c: No such file or directory
Are we suppose to create an empty exploit.c file ?

make a file named exploit.c, and put the modified script in there

Thanks bro!
#17
Quote:PS C:\Users\dallon.matrix\Documents> whoami
axlle\dallon.matrix
PS C:\Users\dallon.matrix\Documents> whoami /priv

PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                    State 
============================= ============================== ========
SeMachineAccountPrivilege    Add workstations to domain    Disabled
SeChangeNotifyPrivilege      Bypass traverse checking      Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Disabled
PS C:\Users\dallon.matrix\Documents>

Now am at dallon.matrix, someone could spoil what enumeration process should i do? already doing powerup and bloodhound but nothing that valuable.
#18
(06-26-2024, 02:17 PM)gglanaya Wrote:
Quote:PS C:\Users\dallon.matrix\Documents> whoami
axlle\dallon.matrix
PS C:\Users\dallon.matrix\Documents> whoami /priv

PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                    State 
============================= ============================== ========
SeMachineAccountPrivilege    Add workstations to domain    Disabled
SeChangeNotifyPrivilege      Bypass traverse checking      Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Disabled
PS C:\Users\dallon.matrix\Documents>

Now am at dallon.matrix, someone could spoil what enumeration process should i do? already doing powerup and bloodhound but nothing that valuable.

Try winpeas!
#19
Got it with BloodHound, WebDev member could resets passwords!
#20
Hey,

I cannot take the initial foothold, i tried with xll, but doesn`t works,


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 366 113,464 42 minutes ago
Last Post: llsdd9
  HTB Eloquia User and Root Flags - Insane Box 69646B 14 17,656 08-21-2026, 07:27 PM
Last Post: tangol
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 94 26,280 08-21-2026, 06:20 AM
Last Post: jamoski
  [FREE] HTB-ProLabs APTLABS Just Flags kewlsunny 25 19,546 08-15-2026, 06:06 PM
Last Post: m4573rx
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 603 118,194 08-15-2026, 06:00 PM
Last Post: zl4



 Users browsing this thread: 1 Guest(s)