> For the complete documentation index, see [llms.txt](https://eslam3kl.gitbook.io/blog/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://eslam3kl.gitbook.io/blog/hack-the-box-machines/legacy-walkthrough.md).

# Legacy Walkthrough

Welcome all, today we will take about one of **HackTheBox** machines “**Legacy**” which is easy, and it’s for beginners, let’s take a look at the machines info

<figure><img src="https://cdn-images-1.medium.com/max/800/1*JwUXDKhigs_T4yZKVMPX8Q.png" alt=""><figcaption></figcaption></figure>

Okay, let’s get started…

## **DNS Enumeration**

The first step is to know what open ports and the service running on them to try to take any entry point from here so the basic usage of `nmap` is `nmap -sS -sV -O <machine-ip>` it will return the system version and the OS details, and it will work only for `tcp` not `udp` ports, you can know more about these options form `nmap --help` From the results, we have this information

```
host        port   name             service
----        ----   ----             ----
10.10.10.4  139   netbios-ssn       Microsoft Windows netbios-ssn
10.10.10.4  445   microsoft-ds      Windows XP microsoft-ds
10.10.10.4  3389  ms-wbt-server  
```

So from this info we know that we have 3 ports open and 2 services running.

We have `SMB` the port is open so we will try to know the version of it because it doesn’t return with the results, so we will use `metasploit` modules to search for any module which performs this task

<figure><img src="https://cdn-images-1.medium.com/max/800/1*Hi_H5938Ik7yNJ-kQQIKQw.png" alt=""><figcaption></figcaption></figure>

Good we have one module here, type `use 0` to use it and then set options like `RHOSTS` and so on and then `run` to start exploitation

<figure><img src="https://cdn-images-1.medium.com/max/800/1*lKr3hZFedQ3k_yghUPR1uQ.png" alt=""><figcaption></figcaption></figure>

As you can see we have the version now, let’s search for CVE for this version by `metasploit` also by typing `search windows xp sp3` and you will find a bunch of CVE so choose any one of them which will be suitable to your machine and try to exploit using it, I have used the module which you see in this photo

<figure><img src="https://cdn-images-1.medium.com/max/800/1*uUy-RNzdbj8Sk4IqJ0K4hw.png" alt=""><figcaption></figcaption></figure>

It opens `meterpreter` a session for me, so I’ll type `shell` to open a reverse shell but before doing this I need to know the privileges of my account, so I will type `getuid` to know

<figure><img src="https://cdn-images-1.medium.com/max/800/1*rb136w-89XB5_k7TNMZ9HQ.png" alt=""><figcaption></figcaption></figure>

So now we are admin and have permission to access all the machine’s directories as you can see

After accessing these directories, you will find the flags

***Congrats and Thank you ❤***
