~/cpts-general-framework

General Framework

CPTS Notes3 min read

Overview

Disclaimer: This workflow took inspiration from many sources, mainly the CPTS course. This is my personal workflow, and intentionally exclude the formal process like pre-engagment & post-engagement in real pentesting. This was designed specifically for HTB-like boxes.

General steps to conquering boxes:

  1. Read the task carefully.
  2. Enumerate using nmap. Read the Enumeration with Nmap page.
  3. Identify running services.
  4. Enumerate the services further.
  5. Exploit vulnerable services.
  6. Get the inital foothold.
  7. Establish persistence.
  8. Post-exploitation. These are usually privilege escalation (privsec) or lateral movement.
  9. Get the flags.

While doing the steps, always draft a writeup (dirty is fine).

What to do with Services?

Once nmap tells you what is open, work each port. Every service has its own enumeration page; the table below is just the map from a port to where to start.

Port Service First thing to try
21 FTP Anonymous login, then list and pull files.
22 SSH Note the version, keep it for later once you have creds.
25 SMTP Enumerate users with VRFY / RCPT.
53 DNS Zone transfer, hunt for extra hostnames.
80 / 443 HTTP / HTTPS The biggest surface. Directory brute, vhosts, read the app.
88 Kerberos Active Directory is present.
111 rpcbind Lists RPC services, feed into showmount for NFS.
139 / 445 SMB List shares, check for null sessions, pull files.
161 (UDP) SNMP snmpwalk with public, it leaks a lot.
389 / 636 LDAP AD objects, try an anonymous bind.
1433 / 3306 / 5432 MSSQL / MySQL / PostgreSQL Weak creds, then read files or run commands.
3389 RDP Keep for when you have creds.
5985 / 5986 WinRM evil-winrm once you have creds.

Full list of ports and services on the Port References page.

Rule of thumb: enumerate before you exploit. Most boxes fall to something you missed, not something you lacked.

After the Initial Foothold

A shell is the middle of the box, not the end. Settle in before you escalate.

  1. Stabilise the shell. Upgrade a raw reverse shell to a proper TTY so arrow keys, tab and Ctrl-C work.
  2. Know where you are. whoami, id, hostname, and which network the box sits on.
  3. Grab the user flag if it is readable now.
  4. Enumerate for privilege escalation. Who am I, what can I run, what is scheduled, what is misconfigured.
  5. Escalate. Get to root or SYSTEM.
  6. Grab the root flag.

See the Linux and Windows privilege-escalation pages for the actual checks.

Active Directory Specifics

A domain-joined box is a different game. You are not after one host, you are after the domain.

  • Treat every credential as a key to the whole domain, not just the box it came from.
  • Enumerate the domain with the creds you have: users, groups, shares, and the trust between them.
  • Look for the common paths: Kerberoasting, AS-REP roasting, and weak ACLs.
  • Map the domain with BloodHound early. It shows the shortest path to Domain Admin.

AD gets its own series later. This page only says: notice when you are in one, and change your approach.