Overview
- Type Red Team Labs
- OS Mixed
- Severity Hard
- Creator xct
- Release date 2022 Dec 29
Showcased proficiency
- Hybrid-AD Environment
- Azure cloud services
- Phishing
- Bypassing AV & EDR tools
- Bypassing Applocker & WDAC
- Reverse Engineering
- Multiple Active Directory Certificate Service Attacks
- Kerberos Delegation and Relay Attacks
- Exploiting linked MSSQL servers
- Supply Chain Attacks
Rule of Engagement (ROE)
Shinra is a company with a fairly advanced security stance.
It’s running a SOC, a SIEM and has an EDR running on all endpoints.
You can see detections in the #vl-shinra-detections channel.
Give your payload a unique name to find it there.
The entry point to the network is 172.16.10.20.
To access the network we need to use an appropriate ovpn file: rtl-aws.ovpn.
Completing the lab awards a badge.
- The EDR is primarily set to alert instead of block so you can get started without too much hassle.
- Check out the detections in the discord (#vl-detections) to see if your payload would get past all defenses!
- If some parts involve password cracking, everything is either in rockyou.txt or simple enough to be guessed, e.g. company name + year, season + year.
Enumeration
Start and join the instance via Discord /rtl lab:Shinra (Hard) and let’s go:

Nmap
$ nmap -p- -n -T5 --max-rtt-timeout 1s --min-parallelism 100 --max-retries 1 -Pn 172.16.10.20
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-10-16 10:19 JST
Nmap scan report for 172.16.10.20
Host is up (0.24s latency).
Not shown: 65525 closed tcp ports (reset)
PORT STATE SERVICE
22/tcp open ssh
25/tcp open smtp
80/tcp open http
110/tcp open pop3
143/tcp open imap
443/tcp open https
587/tcp open submission
993/tcp open imaps
995/tcp open pop3s
8220/tcp open unknown
$ nmap -p25,80,443 -sCV -Pn 172.16.10.20
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-10-16 10:24 JST
Nmap scan report for 172.16.10.20
Host is up (0.24s latency).
PORT STATE SERVICE VERSION
25/tcp open smtp Postfix smtpd
|_ssl-date: TLS randomness does not represent time
|_smtp-commands: mail.shinra.vl, PIPELINING, SIZE 10240000, VRFY, ETRN, STARTTLS, AUTH PLAIN LOGIN, ENHANCEDSTATUSCODES, 8BITMIME, DSN, CHUNKING
| ssl-cert: Subject: commonName=web01.shinra.vl/organizationName=Shinra/stateOrProvinceName=Tokyo/countryName=JP
| Not valid before: 2022-12-08T14:50:56
|_Not valid after: 2023-12-08T14:50:56
80/tcp open http Apache httpd 2.4.52 ((Ubuntu))
|_http-server-header: Apache/2.4.52 (Ubuntu)
| http-cookie-flags:
| /:
| PHPSESSID:
|_ httponly flag not set
|_http-title: \xE7\xA5\x9E\xE7\xBE\x85 VPN Gateway
443/tcp open ssl/http Apache httpd 2.4.52 ((Ubuntu))
|_http-server-header: Apache/2.4.52 (Ubuntu)
| http-cookie-flags:
| /:
| PHPSESSID:
|_ httponly flag not set
| ssl-cert: Subject: commonName=web01.shinra.vl/organizationName=Shinra/stateOrProvinceName=Tokyo/countryName=JP
| Not valid before: 2022-12-08T14:50:56
|_Not valid after: 2023-12-08T14:50:56
| tls-alpn:
|_ http/1.1
|_http-title: \xE7\xA5\x9E\xE7\xBE\x85 VPN Gateway
|_ssl-date: TLS randomness does not represent time
Service Info: Host: mail.shinra.vl
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 28.01 seconds
- Found a web server with PHP
- Add
web01.shinra.vlandmail.shinra.vlto /etc/hosts
