Part 8: Hacking DarkHaven (Full Network) - Hack Smarter Labs

Part 8: Hacking DarkHaven (Full Network) - Hack Smarter Labs

Source: YouTube · Tyler Ramsbey - Hack Smarter · published Apr 17, 2026 · 17:09

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

In this eighth installment of the Dark Haven range, we leverage Inveigh on the compromised Share machine to poison LLMNR requests, capturing the NTLMv2 hash for the SVC webpool account. By utilizing a specific IT security wordlist found in earlier enumeration rather than standard tools, we successfully crack the hash to reveal the password "Dark Haven 128," granting access to the Web server.

Key Takeaways:
• Inveigh serves as the Windows equivalent to Responder for SMB/LLMNR poisoning, requiring the latest compiled version to bypass Windows Defender 13:45
• Captured hashes must be cracked using environment-specific wordlists (e.g., IT security list) rather than generic dictionaries like rockyou.txt to succeed 21:30
• The cracked credentials for SVC webpool provide access to the web.external.darkhaven.local SMB share, marking progress toward the next objective 24:15

By paying attention to subtle enumeration details like historical password lists, you can bypass common cracking failures and advance through the range. Subscribe to stay updated on future live streams and join the community for hands-on practice.

Sources:

  • 0:00 Introduction and series context
  • 0:12 Advice for new viewers
  • 0:18 Platform access instructions
  • 13:45 Using Inveigh for LLMNR poisoning
  • 21:30 Cracking the hash with specific wordlists
  • 24:15 Validating SVC webpool credentials

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

What is up everyone? Welcome to part eight of working through the Dark Haven range on the Hack Smarter platform. And as usual, this is part eight, not part one. So, if this is the first video that you're watching, I suggest starting at part one and watching this in series so that you are not lost. And hey, you'll learn even more by hacking alongside of me. So, if you haven't already, head over to hacksmarter.org, launch Dark Haven, and let's hack all of the things together. You'll also notice that there's going to be chat on the screen if people chat. I am live right now with about 80 people in the live studio audience. I stream all the time. You should join me, subscribe, bell notification, all those good things so that you're notified the next time I am live. All that being said, let's d…