# Setup ## Clone and Startup ![image](https://hackmd.io/_uploads/HJzkjnSWC.png) ![image](https://hackmd.io/_uploads/HJ8monBbC.png) ![image](https://hackmd.io/_uploads/HyHC4aB-C.png) ![image](https://hackmd.io/_uploads/BkLyBTHbA.png) ![image](https://hackmd.io/_uploads/ByEeBTSZR.png) Skip for now ![image](https://hackmd.io/_uploads/rkm-STH-0.png) ![image](https://hackmd.io/_uploads/rJVfHaB-A.png) Give some name ![image](https://hackmd.io/_uploads/S1oEr6HbA.png) ![image](https://hackmd.io/_uploads/ryZLHaHZA.png) ![image](https://hackmd.io/_uploads/HyiLSaHb0.png) ![image](https://hackmd.io/_uploads/ry9vH6rWC.png) ![image](https://hackmd.io/_uploads/rkmcdTBW0.png) ## Network Settings ![image](https://hackmd.io/_uploads/By0HtaSZR.png) - Turn off IPv6 - Set Static IP Address - Set DNS to DC1 ![image](https://hackmd.io/_uploads/r1LYtaHbA.png) ## Rename PC Again, I genuinely preferred the original name of DESKTOP-L9DJK5, but here we go ![image](https://hackmd.io/_uploads/H1Aw66HZA.png) If changing name after joining domain, you will need domain administrator's credentials ![image](https://hackmd.io/_uploads/Byj566B-R.png) ## Quality of Life settings ![image](https://hackmd.io/_uploads/Bk88uTHbA.png) ## Join to Domain ![image](https://hackmd.io/_uploads/Hybe9TB-0.png) ![image](https://hackmd.io/_uploads/S1Jz9aHWR.png) ![image](https://hackmd.io/_uploads/BJZtcar-A.png) - Computer Description is optional - Enter domain name and credentials of Domain administrator ![image](https://hackmd.io/_uploads/H1tsq6BbR.png) ![image](https://hackmd.io/_uploads/r1xhc6HWC.png) ![image](https://hackmd.io/_uploads/ByA3cpH-R.png) ## Autologon Vulnerability Make a new folder in C: and call it setup ![image](https://hackmd.io/_uploads/ByVOe0BZ0.png) Access shared folder on WC1. We will do it a different way this time - using cmd This command will make the shared folder available ![image](https://hackmd.io/_uploads/HkdrMRHW0.png) Copy and paste into the local setup folder on C: ![image](https://hackmd.io/_uploads/ryAvGCr-A.png) ### Install Double-click executable to begin process ![image](https://hackmd.io/_uploads/B1BoG0B-0.png) Of course we agree ![image](https://hackmd.io/_uploads/H1G2zCBZR.png) Use Lord Business credentials ![image](https://hackmd.io/_uploads/HyRZXABZA.png) ![image](https://hackmd.io/_uploads/SkVfm0B-A.png) It works! I mean, you can't tell it works because this is just a screenshot, but, them's the breaks. ![image](https://hackmd.io/_uploads/ryad7ASWA.png) ## More vulnerabilities ### IT Admins group given Admin rights over WC2 ![image](https://hackmd.io/_uploads/H1CzVRSWR.png) ![image](https://hackmd.io/_uploads/HkRuERHWA.png) ### Shared folder with Read-Write permissions on C: ![image](https://hackmd.io/_uploads/ByFHBArZ0.png)