HackTheBox - Nanocorp
00:00 - Introduction 01:00 - Start of nmap 05:00 - Looking at the contact form, it behaves oddly so disregarding it 07:00 - Playing with the PHP File Upload to see if we can upload PHP Files 10:00 - Using wget to download an image and see when it was uploaded to the webserver 12:30 - Looking into CVE-2025-24071, which we can create a .library-ms file that leaks NTLMv2 Hashes 17:30 - Cracking the web_svc NTLMv2 hash 19:50 - Using impacket's getTGT, then running RustHound and discovering we can take over another account via changepassword 25:00 - Using BloodyAD to add ourself to a group and then change the password 31:40 - Using WinRMexec to get a shell because Evil-WINRM doesn't support KRB+SSL Auth 36:30 - WinRM Shell returned, discovering we can write php scripts to the web directory but unfortunately this doesn't get us seimpersonate privileges 40:15 - Discovering CheckMK is running on the box, finding a privesc CVE 45:50 - Looking into the registry to discover which cached MSI is CheckMK 52:00 - Using RunasCS to switch to the web_svc user because we need an interactive login 01:04:30 - Changing the PID in the POC Script to be much lower which gets us the shell

1 Hour Full Body Strength Workout for Women Over 40

I Built Retracting Casters that are Actually GOOD

How to make your own AI Cybersecurity Mentor! (This is a game changer)

Fall asleep while I build a zoo (Part 2)

Understanding File Descriptors in Unix/Linux

Every Famous Number, Explained: From Pi to the Unknowable

Something is jamming GPS over Europe. Here's what we found

Let’s Handle 1 Million Requests per Second, It’s Scarier Than You Think!

She Was Trying to Cut It With Scissors and The Grass Was Taller Than My Mowers

HackTheBox - MonitorsFour

Politics Chat, June 18, 2026

researcher accidentally finds 0-day affecting his entire internet service provider

The Story of C++: The World's Most Consequential Programming Language | The Official Story

RL for Agents Workshop - Deep Dive on Training Agents with RL and Open Source

Creator of C++: Bell Labs, Negative Overhead Abstraction, Mistakes | Bjarne Stroustrup

Ich habe 100 Tage ARK Valguero gespielt und das ist passiert...

Andrej Karpathy: From Vibe Coding to Agentic Engineering w/ Stephanie Zhan

Birds Singing in a Tranquil Forest 🌳 Nature Sounds for Deep Sleep and Calm Mind

America's Got Talent 2026 ALL AUDITIONS | Week 2

