HTB - Media

TL;DR - A Windows box where a video-upload feature lets us smuggle an .asx playlist pointing at a UNC path. When the server processes it, it authenticates to our SMB listener and leaks enox’s NetNTLM hash, which we crack and reuse over SSH for the foothold. For root, the upload handler stores files in a predictable per-user directory, so we abuse a symlink to redirect our shell.php into the XAMPP webroot, get a webshell, drop to a reverse shell, and finally use FullPowers to recover the service account’s full privilege set and land as nt authority\system. ...

October 8, 2026 · 5 min