Hack The Box: Jeeves Walkthrough
Hack The Box: Jeeves Walkthrough
In this walkthrough, we tackle the Windows machine Jeeves. This box demonstrates the importance of thorough enumeration on non-standard ports and dealing with Alternate Data Streams (ADS) for flag retrieval.
Tools Used
- Nmap: Network discovery
- Jenkins Script Console: For Remote Code Execution (RCE)
- Hashcat: For cracking KeePass database hashes
- PowerShell: For shell upgrades and enumeration
Video Walkthrough
Timestamps
| Time | Topic |
|---|---|
| 00:00 | Intro |
| 01:11 | Nmap Scanning Methodology |
| 03:27 | Going over Nmap Results |
| 05:06 | Testing NULL/Guest Logins (MSRPC & SMB) |
| 06:30 | Port 80 Enum |
| 13:09 | Port 50000 Enum |
| 24:21 | RCE and Reverse Shell using Jenkins |
| 32:44 | Shell as user and Host Enumeration |
| 35:08 | Upgrading to a PowerShell session |
| 42:13 | Resume Enum |
| 43:13 | Cracking KeePass DB using Hashcat |
| 49:52 | Username/Password/Hash Spraying |
| 57:21 | PWNED! |
| 01:06:00 | GETTING ROOT FLAG (ADS) |
This post is licensed under CC BY 4.0 by the author.