A walkthrough of the eJPT System/Host-Based Attacks CTF 1 lab from INE, covering how to capture four flags across two Windows targets. The methodology includes HTTP Basic Auth brute-forcing with Hydra, WebDAV enumeration and ASP webshell upload via Cadaver, SMB share enumeration with smbclient, and Administrator credential brute-forcing using Metasploit's smb_login module. Key takeaway: both targets fell due to weak passwords and credential reuse, with WebDAV misconfiguration enabling remote code execution.

4m read timeFrom infosecwriteups.com
Post cover image
177 Impressions