HTB Academy: Windows Fundamentals
嗯,用户让我总结这篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头。直接写描述就行。 首先,我需要快速浏览文章内容。看起来这篇文章是关于Windows基础模块的技能评估部分的。作者通过RDP连接到目标Windows机器,创建了“Company Data”文件夹,并设置了共享权限,选择了“Everyone”和管理员权限。然后回答了一些问题,涉及共享权限、NTFS安全、PowerShell命令创建用户Jim和组HR,并将Jim添加到HR组,最后调整了文件夹的共享权限。 接下来,我需要把这些关键点浓缩成大约100个字。确保涵盖主要任务:创建文件夹、设置权限、使用PowerShell创建用户和组,并调整权限。 可能的结构是:作者通过RDP连接到Windows机器,创建并配置文件夹共享权限,使用PowerShell创建用户和组,并调整权限以完成技能评估任务。 这样应该在字数限制内,并且准确传达主要内容。 </think> 文章描述了通过远程桌面协议(RDP)连接到Windows机器并完成一系列系统管理任务的过程,包括创建文件夹、设置共享权限、使用PowerShell创建用户和组,并调整文件夹的安全性和共享设置以完成HTB学院Windows基础模块的技能评估任务。 2025-10-31 07:16:54 Author: infosecwriteups.com(查看原文) 阅读量:7 收藏

KarmicDragoon92

Now in the past, I’ve gone on the record saying that I don’t like covering Academy content and that’s still true. I will do it however if one of two conditions are met, I think it’s hard and there’s not a lot of resources on the topic. Or if I personally suck at it and this one is definitely the latter as my Windows sysadmin skills are not great. With that being said, feel free to join me as I quick work on the Skills Assessment portion of the HTB Academy Windows Fundamentals module.

Here we’re given a little scenario to mentally prepare us for the daunting tasks ahead. So what are these tasks?

Oh no, creating folders? Users? Managing permissions? This is getting serious. I joke, but I honestly am not 100% certain how to do all this on Windows, which is why I am in fact making a post about it. Now we have these tasks, but we also have questions at the bottom that we need to answer as we go. So, let’s take a look at the first question and get started on these tasks.

Question 1

Well, in order to answer that, we are going to need to complete task 1. The first step in this process is RDPing into the target Windows box using xfreerdp. After running

xfreerdp /u:htb-student /p:Academy_WinFun! /w:1920 /h:1080 /v:10.129.188.92

we are dropped into our remote Windows machine. After landing on the desktop I am going to right click on the desktop and hover over New and then Folder.

Press enter or click to view image in full size

Be sure to name the folder Company Data. Now in order to share this folder, we are going to need to right click the folder and select Properties.

Now after navigating to the Sharing tab we see…

Well simple enough, let’s hit share.

Here we see a drop down menu where we can select who has access to this folder. For our purposes we will select Everyone and then click Share (shield icon means admin privileges required).

Press enter or click to view image in full size

So this is an interesting question. I am going to select no as I only want to share this folder on my local network. I could be misunderstanding the prompt, but I don’t think I’d ever want to publicly share it.

Bam, easy. Click done. Now to answer the first question we got, let’s click on the Security tab of the Properties menu.

Here we see a few users/groups listed. By default I am pretty sure SYSTEM is the default group in question here. Actually nope, we’re in the wrong place. My bad, we’re going back to the Sharing tab and then click on Advanced Sharing.

Check Share this folder and then click on Permissions.

Ah, let’s try that. That is the answer by the way, but in the Beta for the new Academy GUI there’s no cool effect for getting it right so just take my word for it. Go ahead and click OK on all these menus so we can move to our next task. Which is quick creating another Folder called HR which needs to go in the Company Data Folder. Go ahead and create it the same way we did earlier and then drag it into the Company Data folder. After I did that, I clicked on the Company Data folder to open File Explorer and see what’s inside.

Press enter or click to view image in full size

Cool looks good. Okay, moving onto Question #2.

Question 2

Oh we got this one easy. You see, earlier in the Security tab that I thought was managing the Share permissions was actually managing the local permissions. As the default file system type for Windows is NTFS Security should be our answer. Yep, got it.

Question 3

Alright, I think it’s PowerShell time.

Okay, I’m going to take some time to explain this quick. Yes, running Get-Service displays all of the services on the host. Now, as we’re looking for something to do with Windows Update I wanted to filter the output hence the -DisplayName flag. We see a few services still, but only one with Windows Update: wuauserv. BAM For more on the Get-Services command if you'd like.

Question 4

Well in order to do that, we’re finally going to need to make our Jim user finally. Now, we could do it through the Windows GUI, but as I’m trying to use PowerShell I’m going to stick with that. After a quick google search I found this.

Press enter or click to view image in full size

New-LocalUser appears to be the command we want, let’s create Jim.

Press enter or click to view image in full size

Ah, right. Needs admin, obviously. Open a new PowerShell prompt with admin privileges by right clicking and Run as Admin.

There we go. We can then find his SID with get-localuser | Select name,sid.

Perfect

Question 5

Alright, this will be the last PowerShell task we’ll do and then we’ll mess with Company Data’s permissions. Once again referring to Microsoft’s documentation it looks like our command will be New-LocalGroup.

Press enter or click to view image in full size

Awesome, let’s run this bad boy.

You see here we created the HR group and also spit out it’s SID. So that SID is the answer to our last question (woo), but we still have those tasks we need to do. It’s important to practice our sys admin skills. Quick speed run of me doing the last few tasks. Such as adding Jim to HR.

Here you see me add Jim to HR and verify it with the last command, that middle one was me trying and failing.

Press enter or click to view image in full size

Here you see me once again go into Properties, Security, I click Edit and then Add. In the box I just typed HR and clicked OK.

There we go. Now we need to change the Share permissions to add HR and also remove everyone.

Press enter or click to view image in full size

Modifying the permissions for the Share is very similar to modifying the local permissions. To disable Inheritance…

Press enter or click to view image in full size

Under Security, we go into Advanced and click Disable Inheritance (which is where Enable is here, I just disabled it already).


文章来源: https://infosecwriteups.com/htb-academy-windows-fundamentals-eefae02ee49c?source=rss----7b722bfd1b8d---4
如有侵权请联系:admin#unsafe.sh