Report

Hack the Box Penetration Test HTB CPTS Report of Findings HTB Certifed Penetration Testing Specialist (CPTS) Exam Report

$20.00
Secure checkout
Instant digital download
PDF document

Document details

Pages
76
File size
3.55 MB
Format
Digital PDF
Category
Report
About this ebook
Sts. Peter & Paul School COM 35466 1 Statement of Confdentiality The contents of this document have been developed by Hack The Box. Hack The Box considers the contents of this document to be proprietary and business confdential information. This information is to be used only in the performance of its intended use. This document may not be released to another vendor, business partner or contractor without prior written consent from Hack The Box. Additionally, no portion of this document may be communicated, reproduced, copied or distributed without the prior consent of Hack The Box. The contents of this document do not constitute legal advice. Hack The Box's offer of services that relate to compliance, litigation or other legal interests are not intended as legal counsel and should not be taken as such. The assessment detailed herein is against a fctional company for training and examination purposes, and the vulnerabilities in no way affect Hack The Box external or internal infrastructure. HACKTHEBOX CONFIDENTIAL HTB CPTS Exam Report 4 2 Engagement Contacts Trilocor Contacts Contact Title Contact Email Yelon Musk yelon.musk@trilocor.local Assessor Contact Assessor Name Title Assessor Contact Email Tomasz Czekaj Mr. tomekczekaj@gmail.com HACKTHEBOX CONFIDENTIAL HTB CPTS Exam Report 5 3 Executive Summary Trilocor Robotics (“Trilocor” herein) contracted Tomasz Czekaj to perform a Network Penetration Test of Trilocor’s externally facing network to identify security weaknesses, determine the impact to Trilocor, document all fndings in a clear and repeatable manner, and provide remediation recommendations. 3.1 Approach Tomasz Czekaj performed testing under a “Black Box” approach from June 14, 2025, to June 24, 2025 without credentials or any advance knowledge of Trilocor’s externally facing environment with the goal of identifying unknown weaknesses. Testing was performed from a non-evasive standpoint with the goal of uncovering as many misconfgurations and vulnerabilities as possible. Testing was performed remotely from Tomasz Czekaj's assessment labs. Each weakness identifed was documented and manually investigated to determine exploitation possibilities and escalation potential. Tomasz Czekaj sought to demonstrate the full impact of every vulnerability, up to and including internal domain compromise. If Tomasz Czekaj were able to gain a foothold in the internal network, Trilocor as a result of external network testing, Trilocor allowed for further testing including lateral movement and horizontal/vertical privilege escalation to demonstrate the impact of an internal network compromise. 3.2 Scope The scope of this assessment was one external IP address, two internal network ranges, the trilocor.local Active Directory domain, and any other Active Directory domains owned by Trilocor discovered if internal network access were achieved. In Scope Assets Host/URL/IP Address Description 10.129.232.167 Entry point WEB-DMZ01 172.16.139.0/24 Trilocor internal network 172.16.210.0/24 Trilocor internal network ad.trilocor.local Trilocor internal AD domain TODO other discovered internal domain(s) TODO 3.3 Assessment Overview and Recommendations During the penetration test against Trilocor, Tomasz Czekaj identifed 19 fndings that threaten the confdentiality, integrity, and availability of Trilocor’s information systems. The fndings were categorized by severity level, with TODO

File included

PDF
CPTS_Exam_Report_TomaszCzekaj.pdf-1.pdf 3.55 MB

Topics