GS-032: BITSTREAM (P3) — SQL Owned + Bob’s NTLM Hash Cracked (HackSmarter) | 2026-07-09

GS-032: BITSTREAM (P3) — SQL Owned + Bob’s NTLM Hash Cracked (HackSmarter) | 2026-07-09

Source: YouTube · HaxrByte · published Jul 10, 2026 · 4:21:13

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

This live stream features Haxabyte continuing the easy-rated "Bitstream" range on Hacksmarter, demonstrating how to escalate access via MSSQL to obtain a user's plaintext password 0:24.

Key Takeaways:
• After exploiting XSS and an IDOR on the web application in a previous session, the stream focuses on the SQL workstation using impacket-mssqlclient with discovered credentials 0:37.
• The xp_cmdshell module is enabled to execute system commands directly from the MSSQL context, allowing file transfers and payload execution 1:41.
• Two methods for establishing command and control are demonstrated: dropping a Beacon using the Adaptics C2 framework and catching a reverse shell with Penelopey using an MSFVenom payload 1:05.
• Privilege escalation from the MSSQL Express service account to NT AUTHORITY\SYSTEM is achieved using a "God Potato" exploit leveraging SeImpersonatePrivilege 1:47.
• Due to Windows 2025 compatibility issues with standard Mimikatz binaries, the host uses a specialized Windows LSA credentials extractor to pull the NTLM hash, which is then quickly cracked with Hashcat to reveal Bob's password ("Pokemon") 4:08.

The stream effectively highlights that even with administrative access, CTFs often require specific flag answers, and modern OS versions can break standard legacy exploitation tools.

Sources:

  • 0:24 Introduction to the Bitstream Hacksmarter range and learning objectives
  • 0:37 Using impacket-mssqlclient to connect to the database
  • 1:41 Enabling and using xp_cmdshell for remote command execution
  • 1:05 Demonstrating C2 beaconing (Adaptics) and reverse shells (Penelopey)
  • 1:47 Privilege escalation to SYSTEM using God Potato
  • 4:08 Extracting and cracking Bob's NTLM hash to get the flag

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 2 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

And there we go. We are live. Welcome welcome everyone. Welcome to the channel. Um I'm Haxabyte. This is this is our live stream where we learn about hacking and how to how to use CTFs to become I guess to train our hacker brain if you would. Uh, I've been doing this for 20 20 plus years. I do pin testing, red teaming, etc. Um, so yeah, if I can answer any questions um that you have, please feel free to to ask and um yeah, I'm going to be going through the first half of the stream will be hacksmarter. We'll carry on with Bitstream, which is a range uh rated easy on the Hacksmarter platform. And the second of the stream, I'll do a hack the box boxes perhaps. Um, depends on how how long it takes. But, uh, yeah, happy to be here. Good to see everyone. Um, I'll go through some of the chat quic…