
HackTheBox - Infiltrator
Source: YouTube · IppSec · published Jun 14, 2025 · 1:52:22
The video details a complex Hack the Box machine exploitation involving active directory takeover, WinRM tunneling, and Output Messenger abuse to achieve domain access.
Key Takeaways:
• Initial enumeration involves scraping website names and using "username anarchy" to identify the naming convention, revealing a user named "as rep roastable" with a known password 0:05.
• Bloodhound is utilized to map an Active Directory attack chain, leading to a user with WinRM access that allows tunneling into the domain 0:13.
• The attacker gains entry to Output Messenger, cycling through accounts to find sensitive data like a net binary and reversing an API key 0:21.
• Exploiting the calendar feature of Output Messenger, the attacker schedules a task to run an application on a logged-in user 0:34.
This walkthrough highlights the critical importance of securing naming conventions and monitoring scheduled tasks in enterprise environments.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 2 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
What's going on, YouTube? This is Ipsac doing Infiltrator from Hack the Box, which is an insanely long machine. It starts off with scraping names off a website and then using username anarchy to find the naming convention because one of the kit users is as rep roastable, which gets us a password that we can run blood hound with. Then we find an active directory attack chain involving several takeovers to get to a user that has WinRM access, which we can use to tunnel into the domain to access output messenger, and we cycle through several accounts there, finding various pieces of information like a net binary. We have to reverse an API key to output messenger which we can use to read more messages and also one of the users is logged in and output messengers calendar feature enables us to r…