POSTS

VULNLAB: Shinra

Shinra is a Hard-rated Red Team lab designed for those with foundational AD and pentesting knowledge to refine covert red teaming skills. Players focus on AD enumeration, exploitation, certificate services, lateral movement, phishing, CI/CD attacks, EDR bypass, backdooring apps, and relay attacks while evading real-time detections.

VULNLAB: Shinra
16747 words · 79 min

Overview

  • Type Red Team Labs
  • OS Mixed
  • Severity Hard
  • Creator xct
  • Release date 2022 Dec 29

Showcased proficiency

  • Hybrid-AD Environment
  • Azure cloud services
  • Phishing
  • Bypassing AV & EDR tools
  • Bypassing Applocker & WDAC
  • Reverse Engineering
  • Multiple Active Directory Certificate Service Attacks
  • Kerberos Delegation and Relay Attacks
  • Exploiting linked MSSQL servers
  • Supply Chain Attacks

Rule of Engagement (ROE)

Shinra is a company with a fairly advanced security stance.

It’s running a SOC, a SIEM and has an EDR running on all endpoints.

You can see detections in the #vl-shinra-detections channel.

Give your payload a unique name to find it there.

The entry point to the network is 172.16.10.20.

To access the network we need to use an appropriate ovpn file: rtl-aws.ovpn.

Completing the lab awards a badge.

Tip
  • The EDR is primarily set to alert instead of block so you can get started without too much hassle.
  • Check out the detections in the discord (#vl-detections) to see if your payload would get past all defenses!
  • If some parts involve password cracking, everything is either in rockyou.txt or simple enough to be guessed, e.g. company name + year, season + year.

Enumeration

Start and join the instance via Discord /rtl lab:Shinra (Hard) and let’s go:

image

Nmap

$ nmap -p- -n -T5 --max-rtt-timeout 1s --min-parallelism 100 --max-retries 1 -Pn 172.16.10.20
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-10-16 10:19 JST
Nmap scan report for 172.16.10.20
Host is up (0.24s latency).
Not shown: 65525 closed tcp ports (reset)
PORT     STATE SERVICE
22/tcp   open  ssh
25/tcp   open  smtp
80/tcp   open  http
110/tcp  open  pop3
143/tcp  open  imap
443/tcp  open  https
587/tcp  open  submission
993/tcp  open  imaps
995/tcp  open  pop3s
8220/tcp open  unknown
$ nmap -p25,80,443 -sCV -Pn 172.16.10.20
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-10-16 10:24 JST
Nmap scan report for 172.16.10.20
Host is up (0.24s latency).

PORT    STATE SERVICE  VERSION
25/tcp  open  smtp     Postfix smtpd
|_ssl-date: TLS randomness does not represent time
|_smtp-commands: mail.shinra.vl, PIPELINING, SIZE 10240000, VRFY, ETRN, STARTTLS, AUTH PLAIN LOGIN, ENHANCEDSTATUSCODES, 8BITMIME, DSN, CHUNKING
| ssl-cert: Subject: commonName=web01.shinra.vl/organizationName=Shinra/stateOrProvinceName=Tokyo/countryName=JP
| Not valid before: 2022-12-08T14:50:56
|_Not valid after:  2023-12-08T14:50:56
80/tcp  open  http     Apache httpd 2.4.52 ((Ubuntu))
|_http-server-header: Apache/2.4.52 (Ubuntu)
| http-cookie-flags: 
|   /: 
|     PHPSESSID: 
|_      httponly flag not set
|_http-title: \xE7\xA5\x9E\xE7\xBE\x85 VPN Gateway
443/tcp open  ssl/http Apache httpd 2.4.52 ((Ubuntu))
|_http-server-header: Apache/2.4.52 (Ubuntu)
| http-cookie-flags: 
|   /: 
|     PHPSESSID: 
|_      httponly flag not set
| ssl-cert: Subject: commonName=web01.shinra.vl/organizationName=Shinra/stateOrProvinceName=Tokyo/countryName=JP
| Not valid before: 2022-12-08T14:50:56
|_Not valid after:  2023-12-08T14:50:56
| tls-alpn: 
|_  http/1.1
|_http-title: \xE7\xA5\x9E\xE7\xBE\x85 VPN Gateway
|_ssl-date: TLS randomness does not represent time
Service Info: Host:  mail.shinra.vl

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 28.01 seconds
  • Found a web server with PHP
  • Add web01.shinra.vl and mail.shinra.vl to /etc/hosts