Pro Labs
Premium
HackTheBox: P.O.O. Pro Lab
Complete walkthrough of the HackTheBox P.O.O. Pro Lab. Five-machine Windows AD environment compromised via IIS web.config.bak credential leak, ASPX webshell upload, IPv6 DHCPv6 poisoning with mitm6, NTLM relay to LDAP for RBCD delegation, LSASS dump for lateral movement, and ADCS ESC1 certificate SAN abuse with Certipy PKINIT for full domain takeover via DCSync.
P.O.O.
HackTheBox
Windows
Hard
Pro Lab
Members Only Content
This article is exclusively available to premium members of LazyHackers. Login or subscribe to read.