[HTB] Ghost after Tightened MSSQL Permissions
by Aner - Wednesday August 28, 2024 at 02:47 PM
#1
Hi,
after Tightened MSSQL Permissions i had some problems for get root flag ... here how i solved them.

Hidden Content
You must register or login to view this content.
Reply
#2
florence user does not have access to that portal
Reply
#3
(08-28-2024, 03:47 PM)kewlcat002 Wrote: florence user does not have access to that portal

Yes, only administrator...you need crack  SAML (Security Assertion Markup Language) . If you inspect the url It indicates that the login process involves SAML. For that you need ADFS_GMSA$'s account. I wrote the html response to forward for have access to web app.
Reply
#4
how do we find florence user password after patch? do we need it?

prior to patch, seems password was in florence user docker container /docker-entrypoint accessed via intranet box shell.
Reply
#5
(08-28-2024, 02:47 PM)Aner Wrote: Hi,
after Tightened MSSQL Permissions i had some problems for get root flag ... here how i solved them.

how do we find the florence user's password after the patch? do we need it?
I also have this problem
Reply
#6
Yes .. because with florence you can find NTL HASH of Justin

(08-31-2024, 08:36 PM)Detector6 Wrote: how do we find florence user password after patch? do we need it?

prior to patch, seems password was in florence user docker container /docker-entrypoint accessed via intranet box shell.

florence.ramirez -P uxLmt*udNc6t3HrF
Reply
#7
(08-28-2024, 02:47 PM)Aner Wrote: Hi,
after Tightened MSSQL Permissions i had some problems for get root flag ... here how i solved them.
I got stuck on the mssql patch?
Reply
#8
(08-28-2024, 02:47 PM)Aner Wrote: Hi,
after Tightened MSSQL Permissions i had some problems for get root flag ... here how i solved them.

ty bro, root was giving me a lot of errors, not to mention that it is more complicated without easy root
Reply
#9
This is interesting really
Reply
#10
user is still the same, root is a challenge
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 91 7,558 Yesterday, 07:45 AM
Last Post: ukaugse
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 364 88,805 04-07-2026, 07:41 PM
Last Post: napo22
  [FREE] HTB-ProLabs APTLABS Just Flags kewlsunny 23 2,358 03-28-2026, 03:30 AM
Last Post: lulaladrow
  HTB Eloquia User and Root Flags - Insane Box 69646B 13 356 03-27-2026, 06:14 PM
Last Post: vlxw
  HTB - ALL Challenges you Stuck in osamy7593 2 652 03-27-2026, 04:24 PM
Last Post: catsweet



 Users browsing this thread: 1 Guest(s)