{"id":278,"date":"2019-01-21T02:28:37","date_gmt":"2019-01-21T02:28:37","guid":{"rendered":"https:\/\/zineausa.com\/blog\/?p=278"},"modified":"2020-02-05T19:20:57","modified_gmt":"2020-02-05T19:20:57","slug":"hackthebox-secnotes-writeup","status":"publish","type":"post","link":"https:\/\/zineausa.com\/blog\/2019\/01\/hackthebox-secnotes-writeup\/","title":{"rendered":"Hackthebox &#8211; SecNotes Writeup"},"content":{"rendered":"\n<p>This is a write-up for the Secnotes machine on hackthebox.eu which was retired on 1\/19\/19! <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Summary<\/h2>\n\n\n\n<p>Secnotes is a medium difficulty Windows machine which will help you practice some basic SQL injection, explore SMBclient, and use some simple php scripting.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Enumeration<\/h2>\n\n\n\n<p>As always, our first step is enumeration. We use the following command in nmap to find open ports (-sV scans for versions, -sC runs some common scripts, and -Pn skips the check to make sure the host is up via Ping):<\/p>\n\n\n\n<p class=\"code\">nmap -sC -sV -Pn 10.10.10.97<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"644\" height=\"417\" src=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-11.png\" alt=\"\" class=\"wp-image-279\" srcset=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-11.png 644w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-11-600x389.png 600w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-11-300x194.png 300w\" sizes=\"auto, (max-width: 644px) 100vw, 644px\" \/><\/figure>\n\n\n\n<p>After this has been run, I always suggest running a full nmap scan in the background, which will reveal another port 8808 open<\/p>\n\n\n\n<p>nmap -p- -T4 -A -v 10.10.10.97<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"648\" height=\"97\" src=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-17.png\" alt=\"\" class=\"wp-image-285\" srcset=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-17.png 648w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-17-600x90.png 600w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-17-300x45.png 300w\" sizes=\"auto, (max-width: 648px) 100vw, 648px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Sql Injection<\/h2>\n\n\n\n<p>We could try to use enum4linux to scan the SMB but instead we will be going straight to the website hosted at 10.10.10.97<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"387\" height=\"397\" src=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-13.png\" alt=\"\" class=\"wp-image-281\" srcset=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-13.png 387w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-13-292x300.png 292w\" sizes=\"auto, (max-width: 387px) 100vw, 387px\" \/><\/figure>\n\n\n\n<p>We register with a random account and login to try and find some notes, but there are none.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"489\" src=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-14-1024x489.png\" alt=\"\" class=\"wp-image-282\" srcset=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-14-1024x489.png 1024w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-14-600x287.png 600w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-14-300x143.png 300w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-14-768x367.png 768w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-14.png 1128w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Trying some sql injection on the login page doesn&#8217;t seem to work, so we try something called second order sql injection, which is pretty much doing injection on the registration page, hoping that something in the back-end will allow the injection later (in this case, we hope the app will show us someone else&#8217;s notes).<\/p>\n\n\n\n<p>In this case, we register with:<\/p>\n\n\n\n<p>username: hello&#8217; or &#8216;1&#8217;=&#8217;1<br>password: password<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"397\" height=\"498\" src=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-15.png\" alt=\"\" class=\"wp-image-283\" srcset=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-15.png 397w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-15-239x300.png 239w\" sizes=\"auto, (max-width: 397px) 100vw, 397px\" \/><\/figure>\n\n\n\n<p>Logging in with this new account shows us someone else&#8217;s notes, interesting:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"309\" src=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-16-1024x309.png\" alt=\"\" class=\"wp-image-284\" srcset=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-16-1024x309.png 1024w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-16-600x181.png 600w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-16-300x90.png 300w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-16-768x231.png 768w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-16.png 1291w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Reverse Shell for User Flag<\/h2>\n\n\n\n<p>Now remember that nmap scan we did at the very start, and we found port 445 open? Let&#8217;s use these new creds to try and access a share with smb:<\/p>\n\n\n\n<p class=\"code\">smbclient \/\/10.10.10.97\/new-site -U tyler -W secnotes.htb<\/p>\n\n\n\n<p>It will prompt for the password so use the password we got from the notes earlier. Typing &#8220;dir&#8221; will list the contents, and this looks awfully similar to the output we get from trying to access 10.10.10.97:8808<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"722\" height=\"194\" src=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-18.png\" alt=\"\" class=\"wp-image-286\" srcset=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-18.png 722w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-18-600x161.png 600w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-18-300x81.png 300w\" sizes=\"auto, (max-width: 722px) 100vw, 722px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"451\" src=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-19-1024x451.png\" alt=\"\" class=\"wp-image-287\" srcset=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-19-1024x451.png 1024w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-19-600x264.png 600w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-19-300x132.png 300w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-19-768x338.png 768w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-19.png 1175w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Let&#8217;s go for the reverse shell. We will be using the following php file, make sure to replace the IP with the IP of your kali machine. Name this file php.php or something.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"58\" src=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-22.png\" alt=\"\" class=\"wp-image-290\" srcset=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-22.png 700w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-22-600x50.png 600w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-22-300x25.png 300w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure>\n\n\n\n<p>Now, upload the php file we made and nc.exe (we got our <u><a href=\"https:\/\/eternallybored.org\/misc\/netcat\/\">here<\/a>)<\/u> by downloading it into \/www and typing the following commands:<\/p>\n\n\n\n<p class=\"code\">lcd \/www<br>put php.php<br>put nc.exe<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"718\" height=\"184\" src=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-21.png\" alt=\"\" class=\"wp-image-289\" srcset=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-21.png 718w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-21-600x154.png 600w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-21-300x77.png 300w\" sizes=\"auto, (max-width: 718px) 100vw, 718px\" \/><\/figure>\n\n\n\n<p>now let&#8217;s listen on port 7734<\/p>\n\n\n\n<p class=\"code\">nc -lvnp 7734<\/p>\n\n\n\n<p>Let&#8217;s now kick off our php file by browsing to 10.10.10.97:8808\/php.php<\/p>\n\n\n\n<p>This should get us a reverse shell like:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"623\" height=\"124\" src=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-23.png\" alt=\"\" class=\"wp-image-291\" srcset=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-23.png 623w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-23-600x119.png 600w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-23-300x60.png 300w\" sizes=\"auto, (max-width: 623px) 100vw, 623px\" \/><\/figure>\n\n\n\n<p>Running the command whoami shows that we are tyler, so let&#8217;s go to his folder at c:\\users\\tyler\\desktop. Read the user.txt file to get user flag:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"371\" height=\"71\" src=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-28.png\" alt=\"\" class=\"wp-image-296\" srcset=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-28.png 371w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-28-300x57.png 300w\" sizes=\"auto, (max-width: 371px) 100vw, 371px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Getting Root Flag<\/h2>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"617\" height=\"345\" src=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-24.png\" alt=\"\" class=\"wp-image-292\" srcset=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-24.png 617w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-24-600x335.png 600w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-24-300x168.png 300w\" sizes=\"auto, (max-width: 617px) 100vw, 617px\" \/><\/figure>\n\n\n\n<p>We find a weird link to bash.. which is weird since this is a windows machine. When we try to run the link it seems to be a broken link, so let&#8217;s find the executable by typing the following commands:<\/p>\n\n\n\n<p class=\"code\">cd c:\\<br>dir \/s <em>bash.exe<\/em><\/p>\n\n\n\n<p>We find it here so let&#8217;s run it:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"720\" height=\"254\" src=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-25.png\" alt=\"\" class=\"wp-image-293\" srcset=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-25.png 720w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-25-600x212.png 600w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-25-300x106.png 300w\" sizes=\"auto, (max-width: 720px) 100vw, 720px\" \/><\/figure>\n\n\n\n<p class=\"code\">c:\\Windows\\WinSxS\\amd64_microsoft-windows-lxss-bash_31bf3856ad364e35_10.0.17134.1_none_251beae725bc7de5\\bash.exe<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"730\" height=\"149\" src=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-26.png\" alt=\"\" class=\"wp-image-294\" srcset=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-26.png 730w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-26-600x122.png 600w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-26-300x61.png 300w\" sizes=\"auto, (max-width: 730px) 100vw, 730px\" \/><\/figure>\n\n\n\n<p>Ah cool.. looks like we have root access to some linux terminal within windows, pretty awesome!<\/p>\n\n\n\n<p>We go to the home directory by using cd ~ and cat the .bash history to find some creds:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"631\" height=\"394\" src=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-27.png\" alt=\"\" class=\"wp-image-295\" srcset=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-27.png 631w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-27-600x375.png 600w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/image-27-300x187.png 300w\" sizes=\"auto, (max-width: 631px) 100vw, 631px\" \/><\/figure>\n\n\n\n<p>Looks like these are the admin creds to the machine. Let&#8217;s mount the C drive with smbclient and we will have the root flag:<\/p>\n\n\n\n<p class=\"code\">smbclient -U &#8216;administrator%u6!4ZwgwOM#^OBf#Nwnh&#8217;  \/\/10.10.10.97\/c$<br>lcd \/www<br>cd users\/administrator\/desktop<br>get root.txt<br>exit<br>cat \/www\/root.txt<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"697\" height=\"308\" src=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/root2.png\" alt=\"\" class=\"wp-image-297\" srcset=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/root2.png 697w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/root2-600x265.png 600w, https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/root2-300x133.png 300w\" sizes=\"auto, (max-width: 697px) 100vw, 697px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>This is a write-up for the Secnotes machine on hackthebox.eu which was retired on 1\/19\/19! Summary Secnotes is a medium difficulty Windows machine which will help you practice some basic SQL injection, explore SMBclient, and use some simple php scripting. Enumeration As always, our first step is enumeration. We use the following command in nmap [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":576,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,6],"tags":[],"class_list":["post-278","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hackthebox","category-writeups"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Hackthebox - SecNotes Writeup - Zinea InfoSec Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zineausa.com\/blog\/2019\/01\/hackthebox-secnotes-writeup\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hackthebox - SecNotes Writeup - Zinea InfoSec Blog\" \/>\n<meta property=\"og:description\" content=\"This is a write-up for the Secnotes machine on hackthebox.eu which was retired on 1\/19\/19! Summary Secnotes is a medium difficulty Windows machine which will help you practice some basic SQL injection, explore SMBclient, and use some simple php scripting. Enumeration As always, our first step is enumeration. We use the following command in nmap [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zineausa.com\/blog\/2019\/01\/hackthebox-secnotes-writeup\/\" \/>\n<meta property=\"og:site_name\" content=\"Zinea InfoSec Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/zineausa\/\" \/>\n<meta property=\"article:published_time\" content=\"2019-01-21T02:28:37+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-02-05T19:20:57+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/1_luv67Hf76w4riMMRoSuRpg.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1192\" \/>\n\t<meta property=\"og:image:height\" content=\"758\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Zinea\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@ZineaLLC\" \/>\n<meta name=\"twitter:site\" content=\"@ZineaLLC\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Zinea\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/2019\\\/01\\\/hackthebox-secnotes-writeup\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/2019\\\/01\\\/hackthebox-secnotes-writeup\\\/\"},\"author\":{\"name\":\"Zinea\",\"@id\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/#\\\/schema\\\/person\\\/e3c58d4f0650f7fb571c01fcf836b1d0\"},\"headline\":\"Hackthebox &#8211; SecNotes Writeup\",\"datePublished\":\"2019-01-21T02:28:37+00:00\",\"dateModified\":\"2020-02-05T19:20:57+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/2019\\\/01\\\/hackthebox-secnotes-writeup\\\/\"},\"wordCount\":593,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/2019\\\/01\\\/hackthebox-secnotes-writeup\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/01\\\/1_luv67Hf76w4riMMRoSuRpg.png\",\"articleSection\":[\"HackTheBox\",\"Writeups\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zineausa.com\\\/blog\\\/2019\\\/01\\\/hackthebox-secnotes-writeup\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/2019\\\/01\\\/hackthebox-secnotes-writeup\\\/\",\"url\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/2019\\\/01\\\/hackthebox-secnotes-writeup\\\/\",\"name\":\"Hackthebox - SecNotes Writeup - Zinea InfoSec Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/2019\\\/01\\\/hackthebox-secnotes-writeup\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/2019\\\/01\\\/hackthebox-secnotes-writeup\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/01\\\/1_luv67Hf76w4riMMRoSuRpg.png\",\"datePublished\":\"2019-01-21T02:28:37+00:00\",\"dateModified\":\"2020-02-05T19:20:57+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/2019\\\/01\\\/hackthebox-secnotes-writeup\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zineausa.com\\\/blog\\\/2019\\\/01\\\/hackthebox-secnotes-writeup\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/2019\\\/01\\\/hackthebox-secnotes-writeup\\\/#primaryimage\",\"url\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/01\\\/1_luv67Hf76w4riMMRoSuRpg.png\",\"contentUrl\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/01\\\/1_luv67Hf76w4riMMRoSuRpg.png\",\"width\":1192,\"height\":758},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/2019\\\/01\\\/hackthebox-secnotes-writeup\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Hackthebox &#8211; SecNotes Writeup\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/\",\"name\":\"Zinea InfoSec Blog\",\"description\":\"Cyber Security Resources\",\"publisher\":{\"@id\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/#organization\",\"name\":\"Zinea LLC\",\"url\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/zinea-square.png\",\"contentUrl\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/zinea-square.png\",\"width\":876,\"height\":876,\"caption\":\"Zinea LLC\"},\"image\":{\"@id\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/zineausa\\\/\",\"https:\\\/\\\/x.com\\\/ZineaLLC\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zineausa.com\\\/blog\\\/#\\\/schema\\\/person\\\/e3c58d4f0650f7fb571c01fcf836b1d0\",\"name\":\"Zinea\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/81f66095634a4c974693824dc72cd0db7c7c44910d60dda2d1bf1be275ee107d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/81f66095634a4c974693824dc72cd0db7c7c44910d60dda2d1bf1be275ee107d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/81f66095634a4c974693824dc72cd0db7c7c44910d60dda2d1bf1be275ee107d?s=96&d=mm&r=g\",\"caption\":\"Zinea\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Hackthebox - SecNotes Writeup - Zinea InfoSec Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zineausa.com\/blog\/2019\/01\/hackthebox-secnotes-writeup\/","og_locale":"en_US","og_type":"article","og_title":"Hackthebox - SecNotes Writeup - Zinea InfoSec Blog","og_description":"This is a write-up for the Secnotes machine on hackthebox.eu which was retired on 1\/19\/19! Summary Secnotes is a medium difficulty Windows machine which will help you practice some basic SQL injection, explore SMBclient, and use some simple php scripting. Enumeration As always, our first step is enumeration. We use the following command in nmap [&hellip;]","og_url":"https:\/\/zineausa.com\/blog\/2019\/01\/hackthebox-secnotes-writeup\/","og_site_name":"Zinea InfoSec Blog","article_publisher":"https:\/\/www.facebook.com\/zineausa\/","article_published_time":"2019-01-21T02:28:37+00:00","article_modified_time":"2020-02-05T19:20:57+00:00","og_image":[{"width":1192,"height":758,"url":"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/1_luv67Hf76w4riMMRoSuRpg.png","type":"image\/png"}],"author":"Zinea","twitter_card":"summary_large_image","twitter_creator":"@ZineaLLC","twitter_site":"@ZineaLLC","twitter_misc":{"Written by":"Zinea","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zineausa.com\/blog\/2019\/01\/hackthebox-secnotes-writeup\/#article","isPartOf":{"@id":"https:\/\/zineausa.com\/blog\/2019\/01\/hackthebox-secnotes-writeup\/"},"author":{"name":"Zinea","@id":"https:\/\/zineausa.com\/blog\/#\/schema\/person\/e3c58d4f0650f7fb571c01fcf836b1d0"},"headline":"Hackthebox &#8211; SecNotes Writeup","datePublished":"2019-01-21T02:28:37+00:00","dateModified":"2020-02-05T19:20:57+00:00","mainEntityOfPage":{"@id":"https:\/\/zineausa.com\/blog\/2019\/01\/hackthebox-secnotes-writeup\/"},"wordCount":593,"commentCount":0,"publisher":{"@id":"https:\/\/zineausa.com\/blog\/#organization"},"image":{"@id":"https:\/\/zineausa.com\/blog\/2019\/01\/hackthebox-secnotes-writeup\/#primaryimage"},"thumbnailUrl":"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/1_luv67Hf76w4riMMRoSuRpg.png","articleSection":["HackTheBox","Writeups"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zineausa.com\/blog\/2019\/01\/hackthebox-secnotes-writeup\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zineausa.com\/blog\/2019\/01\/hackthebox-secnotes-writeup\/","url":"https:\/\/zineausa.com\/blog\/2019\/01\/hackthebox-secnotes-writeup\/","name":"Hackthebox - SecNotes Writeup - Zinea InfoSec Blog","isPartOf":{"@id":"https:\/\/zineausa.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/zineausa.com\/blog\/2019\/01\/hackthebox-secnotes-writeup\/#primaryimage"},"image":{"@id":"https:\/\/zineausa.com\/blog\/2019\/01\/hackthebox-secnotes-writeup\/#primaryimage"},"thumbnailUrl":"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/1_luv67Hf76w4riMMRoSuRpg.png","datePublished":"2019-01-21T02:28:37+00:00","dateModified":"2020-02-05T19:20:57+00:00","breadcrumb":{"@id":"https:\/\/zineausa.com\/blog\/2019\/01\/hackthebox-secnotes-writeup\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zineausa.com\/blog\/2019\/01\/hackthebox-secnotes-writeup\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zineausa.com\/blog\/2019\/01\/hackthebox-secnotes-writeup\/#primaryimage","url":"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/1_luv67Hf76w4riMMRoSuRpg.png","contentUrl":"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2019\/01\/1_luv67Hf76w4riMMRoSuRpg.png","width":1192,"height":758},{"@type":"BreadcrumbList","@id":"https:\/\/zineausa.com\/blog\/2019\/01\/hackthebox-secnotes-writeup\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zineausa.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Hackthebox &#8211; SecNotes Writeup"}]},{"@type":"WebSite","@id":"https:\/\/zineausa.com\/blog\/#website","url":"https:\/\/zineausa.com\/blog\/","name":"Zinea InfoSec Blog","description":"Cyber Security Resources","publisher":{"@id":"https:\/\/zineausa.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zineausa.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zineausa.com\/blog\/#organization","name":"Zinea LLC","url":"https:\/\/zineausa.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zineausa.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2018\/05\/zinea-square.png","contentUrl":"https:\/\/zineausa.com\/blog\/wp-content\/uploads\/2018\/05\/zinea-square.png","width":876,"height":876,"caption":"Zinea LLC"},"image":{"@id":"https:\/\/zineausa.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/zineausa\/","https:\/\/x.com\/ZineaLLC"]},{"@type":"Person","@id":"https:\/\/zineausa.com\/blog\/#\/schema\/person\/e3c58d4f0650f7fb571c01fcf836b1d0","name":"Zinea","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/81f66095634a4c974693824dc72cd0db7c7c44910d60dda2d1bf1be275ee107d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/81f66095634a4c974693824dc72cd0db7c7c44910d60dda2d1bf1be275ee107d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/81f66095634a4c974693824dc72cd0db7c7c44910d60dda2d1bf1be275ee107d?s=96&d=mm&r=g","caption":"Zinea"}}]}},"_links":{"self":[{"href":"https:\/\/zineausa.com\/blog\/wp-json\/wp\/v2\/posts\/278","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zineausa.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zineausa.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zineausa.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zineausa.com\/blog\/wp-json\/wp\/v2\/comments?post=278"}],"version-history":[{"count":3,"href":"https:\/\/zineausa.com\/blog\/wp-json\/wp\/v2\/posts\/278\/revisions"}],"predecessor-version":[{"id":577,"href":"https:\/\/zineausa.com\/blog\/wp-json\/wp\/v2\/posts\/278\/revisions\/577"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/zineausa.com\/blog\/wp-json\/wp\/v2\/media\/576"}],"wp:attachment":[{"href":"https:\/\/zineausa.com\/blog\/wp-json\/wp\/v2\/media?parent=278"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zineausa.com\/blog\/wp-json\/wp\/v2\/categories?post=278"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zineausa.com\/blog\/wp-json\/wp\/v2\/tags?post=278"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}