Resolute HTB Walkthrough

Oct 21, 2024    #box   #htb   #medium   #windows   #ldap   #active-directory   #nopac   #cve-2021-42278   #cve-2021-42287   #download-cradle  

Resolute Hack The Box Walkthrough/Writeup:

How I use variables & Wordlists:

1. Enumeration:

NMAP:

LDAP 389:

Using LDAP anonymous bind to enumerate further:

LDAP Group Enumeration:

Finding a hard-coded user password using LDAP User Enumeration:

Password spraying all users with our found password:

DNS 53:

Kerberos 88:

SMB 445:

Attempting to connect with NULL & Guest sessions:

Trying Usernames as Passwords:

2. Foothold:

Enumerating the domain as melanie:

Strange LDAP Behavior:

I upload SharpChrome.exe via my evil-winrm for a session:

Trying to load PowerView into memory:

Using Winpeas to enumerate:

Manual Enumeration of System Information:

Enumerating the password policy:

Enumerating the Windows Version:

Enumerating Installed Applications:

Enumerating network services:

Enumerate PATH:

Enumerate ENV’s:

Enumerating Drives:

Enumerating Scheduled Tasks:

Manual Enumeration of users:

Query Privileges, Groups & Logged in Users:

Manual Network Enumeration:

List all network interfaces, IP, and DNS:

List the ARP table:

List current routing table:

Manual Service/Program Enumeration:

Enumerating services using evil-winrm:

Enumerating Binaries with Weak Service Permissions using AccessChk & SharpUp.exe:

Enumerate Startup Programs:

Session Enumeration:

3. Privilege Escalation:

Finding out the host is vulnerable to the NoPac vuln using netexec:

4. Ownership:

Preparing the NoPac Exploit:

Using the NoPac exploit to get a shell on the victim:

5. Persistence:

Adding a user as an administrator:

Dumping NTDS.dit:

Lessons Learned:

What did I learn?

  1. LDAP is the best. But really it can be used to get alot of valuable information.

What silly mistakes did I make?

  1. Nothing terrible this time. Slow methodical manual enumeration was the way to solve this box.

Sign off:

Remember, folks as always: with great power comes great pwnage. Use this knowledge wisely, and always stay on the right side of the law!

Until next time, hack the planet!

ā€“ Bloodstiller

ā€“ Get in touch bloodstiller at proton dot me



Next: Fuse HTB Walkthrough