Haze - Hack The Box Season 7 - Windows Hard
by ShitWhiffler - Saturday March 29, 2025 at 06:59 PM
#21
How to get user flag???
Reply
#22
user flag free:

evil-winrm -i haze.htb -u 'edward.martin' -H '09e0b3eeb2e7a6b0d419e9ff8f4d91af'
Reply
#23
(03-30-2025, 12:24 AM)fr34cker Wrote: user flag free:

evil-winrm -i haze.htb -u 'edward.martin' -H '09e0b3eeb2e7a6b0d419e9ff8f4d91af'


Thank you very much!
Does anyone know how to get root\administrator flag ?
Reply
#24
https://github.com/0xjpuff/reverse_shell_splunk

Then throw a potato at the box
Reply
#25
(03-30-2025, 01:32 AM)maggi Wrote: https://github.com/0xjpuff/reverse_shell_splunk

Then throw a potato at the box

bro is onto something for sure
Reply
#26
(03-30-2025, 01:32 AM)maggi Wrote: https://github.com/0xjpuff/reverse_shell_splunk

Then throw a potato at the box

yeah thats what I wanted to do, but how do you log into splunk? We don't have credentials that allow us to log in. We can only get the "Ld@p_Auth..." one from exploiting the LFI CVE. can't log into splunk with that one.
Reply
#27
(03-30-2025, 04:05 AM)zippo99 Wrote:
(03-30-2025, 01:32 AM)maggi Wrote: https://github.com/0xjpuff/reverse_shell_splunk

Then throw a potato at the box

yeah thats what I wanted to do, but how do you log into splunk? We don't have credentials that allow us to log in. We can only get the "Ld@p_Auth..." one from exploiting the LFI CVE. can't log into splunk with that one.


admin
Sp1unkadmin@2k24
Reply
#28
(03-30-2025, 04:14 AM)rootme1122 Wrote:
(03-30-2025, 04:05 AM)zippo99 Wrote:
(03-30-2025, 01:32 AM)maggi Wrote: https://github.com/0xjpuff/reverse_shell_splunk

Then throw a potato at the box

yeah thats what I wanted to do, but how do you log into splunk? We don't have credentials that allow us to log in. We can only get the "Ld@p_Auth..." one from exploiting the LFI CVE. can't log into splunk with that one.


admin
Sp1unkadmin@2k24

How were you able to crack the admin hash?

(03-30-2025, 12:24 AM)fr34cker Wrote: user flag free:

evil-winrm -i haze.htb -u 'edward.martin' -H '09e0b3eeb2e7a6b0d419e9ff8f4d91af'

How were you able to get the hash for this user? I was only able to get the username by using evil-winrm on mark.adams and looking around there.
Reply
#29
(03-30-2025, 04:14 AM)rootme1122 Wrote:
(03-30-2025, 04:05 AM)zippo99 Wrote:
(03-30-2025, 01:32 AM)maggi Wrote: https://github.com/0xjpuff/reverse_shell_splunk

Then throw a potato at the box

yeah thats what I wanted to do, but how do you log into splunk? We don't have credentials that allow us to log in. We can only get the "Ld@p_Auth..." one from exploiting the LFI CVE. can't log into splunk with that one.


admin
Sp1unkadmin@2k24

that's awesome! where did you find that password?
Reply
#30
(03-30-2025, 04:27 AM)zippo99 Wrote:
(03-30-2025, 04:14 AM)rootme1122 Wrote:
(03-30-2025, 04:05 AM)zippo99 Wrote:
(03-30-2025, 01:32 AM)maggi Wrote: https://github.com/0xjpuff/reverse_shell_splunk

Then throw a potato at the box

yeah thats what I wanted to do, but how do you log into splunk? We don't have credentials that allow us to log in. We can only get the "Ld@p_Auth..." one from exploiting the LFI CVE. can't log into splunk with that one.


admin
Sp1unkadmin@2k24

that's awesome! where did you find that password?
 Check Backups or Splunk...something related might stand out
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  HTB LAB MACHINE[Overflow][HARD] User & Root flags t1g35h4rk 0 129 Yesterday, 07:08 PM
Last Post: t1g35h4rk
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 24 21,123 08-28-2026, 06:17 AM
Last Post: moonfox
  HTB Eloquia User and Root Flags - Insane Box 69646B 14 19,446 08-21-2026, 07:27 PM
Last Post: tangol
  HTB - VOLEUR.HTB - MEDIUM WINDOWS chain 1 11,362 02-09-2026, 07:07 PM
Last Post: 403Forbidden
  HTB - CERTIFICATE.HTB - HARD WINDOWS chain 0 7,570 02-09-2026, 04:49 PM
Last Post: chain



 Users browsing this thread: 1 Guest(s)