Blue

Blue, while possibly the most simple machine on Hack The Box, demonstrates the severity of the EternalBlue exploit, which has been used in multiple large-scale ransomware and crypto-mining attacks since it was leaked publicly.
Enum
Task 1
Question
How many open TCP ports are listening on Blue? Don't include any 5-digit ports.
- Performing nmap scan
╭─ ~ ─────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
╰─❯ nmap 10.10.10.40
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-12-29 17:10 IST
Nmap scan report for 10.10.10.40 (10.10.10.40)
Host is up (0.29s latency).
Not shown: 991 closed tcp ports (conn-refused)
PORT STATE SERVICE
135/tcp open msrpc
139/tcp open netbios-ssn
445/tcp open microsoft-ds
49152/tcp open unknown
49153/tcp open unknown
49154/tcp open unknown
49155/tcp open unknown
49156/tcp open unknown
49157/tcp open unknown
Nmap done: 1 IP address (1 host up) scanned in 39.10 seconds
Answer
3
Task 2
Question
What is the hostname of Blue?
- Doing nmap script scan for 3 ports
─❯ nmap 10.10.10.40 -sCV -T5 -p135,139,445
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-12-29 17:14 IST
Nmap scan report for 10.10.10.40 (10.10.10.40)
Host is up (0.41s latency).
PORT STATE SERVICE VERSION
135/tcp open msrpc Microsoft Windows RPC
139/tcp filtered netbios-ssn
445/tcp open microsoft-ds Windows 7 Professional 7601 Service Pack 1 microsoft-ds (workgroup: WORKGROUP)
Service Info: Host: HARIS-PC; OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results:
| smb-os-discovery:
| OS: Windows 7 Professional 7601 Service Pack 1 (Windows 7 Professional 6.1)
| OS CPE: cpe:/o:microsoft:windows_7::sp1:professional
| Computer name: haris-PC
| NetBIOS computer name: HARIS-PC\x00
| Workgroup: WORKGROUP\x00
|_ System time: 2024-12-29T11:44:05+00:00
| smb2-security-mode:
| 2:1:0:
|_ Message signing enabled but not required
| smb-security-mode:
| account_used: guest
| authentication_level: user
| challenge_response: supported
|_ message_signing: disabled (dangerous, but default)
|_clock-skew: mean: -12s, deviation: 2s, median: -14s
| smb2-time:
| date: 2024-12-29T11:44:03
|_ start_date: 2024-12-29T11:37:05
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 26.28 seconds
Answer
HARIS-PC
Task 3
Question
What operating system is running on the target machine? Give a two-word answer with a name and high-level version.
- From the above output we can get the answer for this question.
Answer
Windows 7
Task 4
Question
How many SMB shares are available on Blue?
- Running smbclient to get shares
╭─ ~ ────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────── ───────────────────
╰─❯ smbclient -L \\\\10.10.10.40
Password for [WORKGROUP\hexadivine]:
Sharename Type Comment
--------- ---- -------
ADMIN$ Disk Remote Admin
C$ Disk Default share
IPC$ IPC Remote IPC
Share Disk
Users Disk
Reconnecting with SMB1 for workgroup listing.
do_connect: Connection to 10.10.10.40 failed (Error NT_STATUS_RESOURCE_NAME_NOT_FOUND)
Unable to connect with SMB1 -- no workgroup available
Answer
5