HackTheBox - Axlle

HackTheBox - Axlle

Source: YouTube · IppSec · published Nov 16, 2024 · 1:00:34

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

The video demonstrates a Hack The Box machine focused on phishing techniques, specifically using XLL files for initial access and URL shortcuts to bypass AppLocker.

Key Takeaways:
• The initial attack vector involves creating an XLL document disguised as an Excel file, which executes code even with macros disabled 0:08.
• Although less common today due to Microsoft's default settings, this XLL technique remains a viable path to gaining a shell on the target system 0:16.
• Post-exploitation reveals that users click on URL files placed in directories, a behavior exploited to bypass AppLocker rules 0:31.
• The attacker creates a URL shortcut where the executable path replaces the URL, effectively tricking AppLocker into allowing the malicious file to run 0:38.

This walkthrough highlights how legacy file types and user trust in shortcuts can be leveraged to achieve code execution and evade security controls.

Sources:

  • 0:08 Introduction to the XLL file attack vector
  • 0:16 Context on Microsoft's disabling of the add-in
  • 0:31 Discovery of user behavior regarding URL files
  • 0:38 Explanation of the AppLocker bypass technique

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

what's going on YouTube this is IP I'm doing axle from hack the box which the theme of this box is all about fishing and LOL bins it starts off with creating an XL document which is really just a dll that Excel opens and can lead to code execution even when macros are disabled it's not really that popular nowadays because Microsoft has disabled this add-in by default but that is the path onto the box here you just create that xlll document and then email it to the user they'll open it you get a shell on the box and then from there if you look around at the config you discover an email that indicates people are clicking URL files when they're placed in a directory you may think this is silly but the technique is more commonly used as a l bin to bypass app Locker rules you create a URL short…