Loading...
avatar
Articles
54
Tags
52
Categories
2
Home
Writeups
Articles
Cheatsheets
Quiz
UnChleuHackerHTB - PingPong
Search
Home
Writeups
Articles
Cheatsheets
Quiz

HTB - PingPong

Created2026-08-22|Updated2026-09-14|writeups
|Post Views:
cover of previous post
Previous
HTB - Pirate
Credential Discovery and KerberoastingWe start with the credentials pentest / p3nt3st2025!&. An initial LDAP enumeration using BloodHound and a kerberoasting attack allow us to map the domain pirate.htb: 1bloodhound-python -u pentest -p 'p3nt3st2025!&' -d pirate.htb -ns 10.129.244.95 -c all In particular, the Kerberoasting reveals the account a.white_adm (a member of the group IT) as well as the managed service account gMSA_ADFS_prod$ (a member of Remote Management Users):...
cover of next post
Next
HTB - PaperWork
avatar
UnChleuHacker
Articles
54
Tags
52
Categories
2
Follow Me
Contents
  1. 1. ESC13
  2. 2. Compromise of Pong_GMSA$
  3. 3. JEA bypass
  4. 4. SeImpersonate exploit
  5. 5. Cross-forest bounce
Recent Posts
HTB - Pirate
HTB - Pirate2026-08-22
HTB - PingPong
HTB - PingPong2026-08-22
HTB - PaperWork
HTB - PaperWork2026-08-22
HTB - Bedside
HTB - Bedside2026-08-22
HTB - DanglingTree
HTB - DanglingTree2026-08-20
©2025 - 2026 By UnChleuHackerFramework Hexo 7.3.0|Theme Butterfly 5.4.0-b2
Search
Loading Database