
HackTheBox - Axlle
Source: YouTube · IppSec · published Nov 16, 2024 · 1:00:34
The video demonstrates a Hack The Box machine focused on phishing techniques, specifically using XLL files for initial access and URL shortcuts to bypass AppLocker.
Key Takeaways:
• The initial attack vector involves creating an XLL document disguised as an Excel file, which executes code even with macros disabled 0:08.
• Although less common today due to Microsoft's default settings, this XLL technique remains a viable path to gaining a shell on the target system 0:16.
• Post-exploitation reveals that users click on URL files placed in directories, a behavior exploited to bypass AppLocker rules 0:31.
• The attacker creates a URL shortcut where the executable path replaces the URL, effectively tricking AppLocker into allowing the malicious file to run 0:38.
This walkthrough highlights how legacy file types and user trust in shortcuts can be leveraged to achieve code execution and evade security controls.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
what's going on YouTube this is IP I'm doing axle from hack the box which the theme of this box is all about fishing and LOL bins it starts off with creating an XL document which is really just a dll that Excel opens and can lead to code execution even when macros are disabled it's not really that popular nowadays because Microsoft has disabled this add-in by default but that is the path onto the box here you just create that xlll document and then email it to the user they'll open it you get a shell on the box and then from there if you look around at the config you discover an email that indicates people are clicking URL files when they're placed in a directory you may think this is silly but the technique is more commonly used as a l bin to bypass app Locker rules you create a URL short…