<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>NTLM Hash on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/ntlm-hash/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Mon, 15 Apr 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/ntlm-hash/index.xml" rel="self" type="application/rss+xml"/><item><title>VULNLAB: Vigilant</title><link>https://wearethebug.dev/posts/vl-vigilant/</link><pubDate>Mon, 15 Apr 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-vigilant/</guid><description>Vigilant is a Hard hybrid Active Directory chain. The environment consists of a domain-joined Linux system and a Windows Domain Controller, presenting a realistic enterprise attack surface. It designed to evaluate penetration testing capabilities in hybrid Windows-Linux environments. Participants begin with zero initial access and must systematically escalate privileges to achieve Domain Administrator-level compromise.</description></item><item><title>VULNLAB: Tengu</title><link>https://wearethebug.dev/posts/vl-tengu/</link><pubDate>Thu, 28 Mar 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-tengu/</guid><description>Tengu is a medium-rated chained machine on VulnLab, features a mixed environment with two Windows hosts and one Linux host. Exploiting Node-RED on Linux (with MSSQL) grants command execution, decrypts service passwords, and pivots to dump NTLM hash. Constrained delegation allows impersonating MSSQL admin for local admin access then recover Domain Admin credentials via DPAPI and Kerberos to compromise the Domain Controller (DC).</description></item><item><title>VULNLAB: Media</title><link>https://wearethebug.dev/posts/vl-media/</link><pubDate>Fri, 13 Oct 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-media/</guid><description>Media is a Medium-rated machine that features an Apache XAMPP stack on Windows hosting a custom PHP web application. The web application allows the upload of a Windows Media Player compatible file that can be leveraged to leak the NTLMv2 hash of the user account that opens it. This hash can be cracked to obtain user credentials that can be used to authenticate to the target via SSH. Upon gaining initial access the source code of the application can be analyzed to determine the generate storage path of uploaded files on the web application which can lead to an NTFS Junction (directory symbolic link) attack to upload a malicious PHP web shell for RCE. Once a shell under the context of the web server's service account, players can abuse the SeTcbPrivilege - Act as part of the operating system, a Windows privilege that lets code impersonate any user and achieve administrative privileges. Alternative methods for privilege escalation involve regaining the SeImpersonate privilege to elevate to NT Authority\SYSTEM.</description></item><item><title>VULNLAB: Reflection</title><link>https://wearethebug.dev/posts/vl-reflection/</link><pubDate>Sat, 10 Jun 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-reflection/</guid><description>Reflection is a medium-difficulty Active Directory chain that simulates a vulnerable enterprise environment and challenges users to progress from limited access to Domain Administrator. Including 3 machines, with anonymous SMB bind abuse, MSSQL abuse, NTLM relay attacks, Windows Credential Vault harvesting, Resource-Based Constrained Delegation (RBCD), and finally credential reuse.</description></item><item><title>VULNLAB: Breach</title><link>https://wearethebug.dev/posts/vl-breach/</link><pubDate>Tue, 14 Feb 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-breach/</guid><description>Breach is a medium difficulty Windows machine, where guest access to an SMB share is available. By leveraging write permissions on that SMB share, NTLMv2 hashes of a domain user are captured to obtain valid credentials. With access as a low-privileged domain user, a kerberoastable service account (svc_mssql) is revealed. After getting access to the service account, a Silver Ticket attack is performed to impersonate the `Administrator` user and gain access to Microsoft SQL Server. Through the xp_cmdshell feature, remote code execution is achieved as the svc_mssql service account. Finally, privilege escalation is performed by abusing the SeImpersonatePrivilege privilege.</description></item><item><title>VULNLAB: Intercept</title><link>https://wearethebug.dev/posts/vl-intercept/</link><pubDate>Sat, 25 Dec 2021 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-intercept/</guid><description>Intercept is a small Active Directory scenario rated as Hard that provides hands-on experience with common Active Directory vulnerabilities and misconfigurations, demonstrating relay attacks and authentication coercion attacks can be used to get access to the domain.</description></item></channel></rss>