POSTS

VULNLAB: Wutai

Wutai is a Medium-difficulty Red Team lab featuring 15+ machines across multiple networks, domains, and forests, challenging players to achieve Enterprise Admin status. Players refine AD enumeration, exploitation, certificate services, lateral movement, EDR bypass, reverse engineering, and covert operations while abusing trust relationships.

VULNLAB: Wutai
28405 words · 134 min

Overview

  • Type Red Team Labs
  • OS Mixed
  • Severity Medium
  • Creator xct
  • Release date 2023 Apr 9

Showcased proficiency

  • Credential Phishing & Credential Spraying
  • Active Directory Attacks with 4 Domains & Forests
  • Reverse Engineering
  • Custom Backdoors
  • Lateral Movements across multiple Domains & Forests
  • PKI Attacks
  • Bypassing modern AV

Rule of Engagement (ROE)

The Wutai Group has tasked you with performing a penetration test on its networks.

This includes the Wutai Parent Company & its subsidiary Junon.

Wutai is concerned about its security posture since a leak of domain usernames was found online on pastebin.

https://pastebin.com/BBZkJGU1 (password is KE37vTed5S)

The goal of this test is to reach Enterprise Administrator in the wutai.vl domain.

Wutai employs a small SOC but its blue team capabilities are still on a rather basic level.

Wutai’s external systems can be reached through the RTL VPN on the 172.16.20.0/24 network.

Everything is in scope except the infrastructure (172.16.xx.1/172.16.xx.2).

To access the network we need to use an appropriate ovpn file: rtl-aws.ovpn.

Completing the lab awards a badge.

Enumeration

Before starting the enumeration, we will grab the users list from the pastebin:

image

$ cut -d '@' -f 1 users_pastebin.txt | sed 's/^ *//g' > usernames.txt
$ head usernames.txt    
Katie.Shaw
Marion.Green
Abdul.Evans
Hollie.Dodd
Stanley.Lee
Julia.Harvey
Jacqueline.Harrison
Rachael.Winter
Martyn.Mason
Elliott.Nixon
...

Start and join the instance via Discord /rtl lab:Wutai (Medium) and let’s go:

image

Nmap

Following the ROE, we will ignore .1 and .2:

$ nmap --top-ports 100 -n -T5 --max-rtt-timeout 1s --min-parallelism 100 --max-retries 1 -Pn 172.16.20.3-254
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-08-09 01:50 JST
...
Nmap scan report for 172.16.20.50
Host is up (0.23s latency).
Not shown: 98 filtered tcp ports (no-response)
PORT     STATE SERVICE
22/tcp   open  ssh
8080/tcp open  http-proxy
...
Nmap scan report for 172.16.20.100
Host is up (0.22s latency).
Not shown: 93 closed tcp ports (conn-refused)
PORT    STATE    SERVICE
22/tcp  open     ssh
53/tcp  filtered domain
143/tcp filtered imap
443/tcp open     https
548/tcp filtered afp
646/tcp filtered ldp
873/tcp filtered rsync
...

Found 2 machines Up.

$ nmap -p8080 -sC -sV -T4 -Pn 172.16.20.50 
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-08-09 01:58 JST
Nmap scan report for 172.16.20.50
Host is up (0.25s latency).

PORT     STATE SERVICE    VERSION
8080/tcp open  http-proxy Squid http proxy 5.2
|_http-title: ERROR: The requested URL could not be retrieved
|_http-server-header: squid/5.2

Found a proxy squid

$ nmap -p443 -sC -sV -T4 -Pn 172.16.20.100
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-08-09 01:59 JST
Nmap scan report for 172.16.20.100
Host is up (0.24s latency).

PORT    STATE SERVICE  VERSION
443/tcp open  ssl/http nginx
|_http-title: Site doesn't have a title (text/html).
| ssl-cert: Subject: commonName=wutai-vdi-gw/organizationName=None/stateOrProvinceName=VA/countryName=US
| Not valid before: 2023-03-10T15:01:48
|_Not valid after:  2028-03-08T15:01:48
|_ssl-date: TLS randomness does not represent time

Add wutai-vdi-gw in /etc/hosts

image

Found a VDI portal (for KASM Workspaces, kind of VDI through the browser)

We add the entry in our proxychains:

$ cat /etc/proxychains4.conf 
# proxychains.conf  VER 4.x
...
[ProxyList]
# add proxy here ...
# meanwile
# defaults set to "tor"
#socks4 	127.0.0.1 9050
#socks5	127.0.0.1 1080
http 172.16.20.50 8080