Dec. 10, 2022, 3:02 p.m. | IppSec

IppSec www.youtube.com

00:00 - Intro
01:00 - Running nmap
02:40 - Running CrackMapExec to enumerate the share
04:10 - Talking about a common misconception about "Null SMB Authentication"
08:00 - Downloading a PDF off the open share
08:55 - Using SWAKS to send an emailw ith a link to see if anything clicks it
10:30 - Exploring the CVE's mentioned in the PDF to see one of them is Folina
11:55 - Someone clicked our link! The User Agent Shows WindowsPowerShell/5.1.19041.906, which …

hackthebox

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Digital Trust Cyber Transformation Senior

@ KPMG India | Mumbai, Maharashtra, India

Security Consultant, Assessment Services - SOC 2 | Remote US

@ Coalfire | United States

Sr. Systems Security Engineer

@ Effectual | Washington, DC

Cyber Network Engineer

@ SonicWall | Woodbridge, Virginia, United States

Security Architect

@ Nokia | Belgium