# HTB-Escape
4 min read
Using kerbrute I was able to find the following service accounts present:
Using kerbrute I was able to find the following service accounts present:
Using the enum4linux-ng tool I was able to enumerate the following information:
Since we already got valid creds I decided to use nxc to spray the credentials
I tried the creds for winrm but they didn’t work, let’s try them for port 80 instead.
Using the given credentials we are able to login using impacket: