Post

Hack The Box: Jeeves Walkthrough

Hack The Box: Jeeves Walkthrough

In this walkthrough, we tackle the Windows machine Jeeves. This box demonstrates the importance of thorough enumeration on non-standard ports and dealing with Alternate Data Streams (ADS) for flag retrieval.

Tools Used

  • Nmap: Network discovery
  • Jenkins Script Console: For Remote Code Execution (RCE)
  • Hashcat: For cracking KeePass database hashes
  • PowerShell: For shell upgrades and enumeration

Video Walkthrough

Timestamps

TimeTopic
00:00Intro
01:11Nmap Scanning Methodology
03:27Going over Nmap Results
05:06Testing NULL/Guest Logins (MSRPC & SMB)
06:30Port 80 Enum
13:09Port 50000 Enum
24:21RCE and Reverse Shell using Jenkins
32:44Shell as user and Host Enumeration
35:08Upgrading to a PowerShell session
42:13Resume Enum
43:13Cracking KeePass DB using Hashcat
49:52Username/Password/Hash Spraying
57:21PWNED!
01:06:00GETTING ROOT FLAG (ADS)
This post is licensed under CC BY 4.0 by the author.