Layover is a Medium difficulty HackTheBox machine that is part of Season 12.
1. Initial Access & Internal Network Enumeration
1.1 Remote Desktop Access
Since I had the initial access credentials, I used xfreerdp3 to RDP into the target machine as the user contractor. I will refer to this machine as airside-ws01.
1.2 Network Interface & Subnet Discovery
Since the user contractor has unrestricted administrator access to this machine, the first step was to map the resources that this machine has access to.
2. Traffic Sniffing & Credential Harvesting
3. Web Exploitation & Foothold
4. SSH Pivot & User Flag
5. Privilege Escalation & Root Flag
Writeup Pending Retirement
This machine is currently active, so the full walkthrough is temporarily unavailable. The complete writeup will be published once the machine is officially retired.
Enjoying Project Null Byte? If you'd like to support my learning journey and help me create more cybersecurity content, you can buy me a coffee.