# Tactics

## Initial Scan

```nmap
sudo nmap -T4 -Pn -sV -sC -v 10.129.123.121 -oA Tactics
```

<figure><img src="https://667808901-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTdW22AGCceN8oUXfdlKI%2Fuploads%2FiTAPLz0O5ewEWRVOB0OK%2Fimage.png?alt=media&#x26;token=819a628c-0e8f-4a04-a468-f2fc61e22623" alt=""><figcaption></figcaption></figure>

## Task 1

Which Nmap switch can we use to enumerate machines when our ping ICMP packets are blocked by the Windows firewall?

<figure><img src="https://667808901-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTdW22AGCceN8oUXfdlKI%2Fuploads%2F4JOvfLyFbuqOKd0ETDqF%2Fimage.png?alt=media&#x26;token=f8b74b32-2afb-4b25-ab21-db8b49f9522c" alt=""><figcaption></figcaption></figure>

Answer: -Pn

## Task 2

What does the 3-letter acronym SMB stand for?

Answer: Server Message Block

## Task 3

What port does SMB use to operate at?

Answer: 445

## Task 4

What command line argument do you give to `smbclient` to list available shares?

<figure><img src="https://667808901-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTdW22AGCceN8oUXfdlKI%2Fuploads%2FA2yw3OzZGt68eJPbikJT%2Fimage.png?alt=media&#x26;token=1c0f02a8-5fcb-4ed7-9cbc-a2639737a3dc" alt=""><figcaption></figcaption></figure>

Answer: -L

## Task 5

What character at the end of a share name indicates it's an administrative share?

Answer: $

## Task 6

Which Administrative share is accessible on the box that allows users to view the whole file system?

<figure><img src="https://667808901-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTdW22AGCceN8oUXfdlKI%2Fuploads%2F1tQeEtQDEodgz8qCsY3q%2Fimage.png?alt=media&#x26;token=8c1ff0fd-a7a4-4d2d-899e-5afb7a8bab7b" alt=""><figcaption></figcaption></figure>

Answer: C$

## Task 7

What command can we use to download the files we find on the SMB Share?

Answer: get

## Task 8

Which tool that is part of the Impacket collection can be used to get an interactive shell on the system?

Answer: psexec.py

## Task 9

Submit root flag

<figure><img src="https://667808901-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTdW22AGCceN8oUXfdlKI%2Fuploads%2F93DIf1mI2geFnlEMXpLu%2Fimage.png?alt=media&#x26;token=988af6a0-64ee-4cac-a9bf-a21c344b466e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://667808901-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTdW22AGCceN8oUXfdlKI%2Fuploads%2FxH97EOEq10I0Cdt5Kw9c%2Fimage.png?alt=media&#x26;token=c1082c17-0927-445b-943a-aff1e31021bd" alt=""><figcaption></figcaption></figure>

Answer: f751c19eda8f61ce81827e6930a1f40c
