xsspresso
xsspresso
Tags/ NTLM

NTLM

2 writeups tagged with NTLM

ADHardWindows

HTB — Flight

LFI via lang parameter captures NTLM hash with Responder. Password spray, IIS WebDAV shell upload, RunasCs for lateral movement to Domain Admin.

#AD#LFI#NTLM
Jan 21, 2025HackTheBox
WebMediumWindows

HTB — Giddy

SQL injection via stored procedure triggers NTLM hash capture. Responder catches hash, crack for WinRM. Ubiquiti UniFi privesc via service abuse.

#SQLi#NTLM#Responder
Nov 25, 2024HackTheBox