Timelapse HTB Walkthrough

Nov 11, 2024    #box   #htb   #easy   #windows   #ldap   #active-directory   #laps   #pfx   #john  

Timelapse Hack The Box Walkthrough/Writeup:

How I use variables & Wordlists:

1. Enumeration:


Basic Scans:

Comprehensive Scans:

LDAP 389:

Using LDAP anonymous bind to enumerate further:

Updating ETC/HOSTS & Variables:

Syncing Clocks for Kerberos Exploitation:

DNS 53:

Kerberos 88:

Using Kerbrute to bruteforce Usernames:

Using netexec for ASReproasting:

SMB 445:

Attempting to connect with NULL & Guest sessions:

Enumerating Users with Impacket-lookupsid:

Using smbclient to enumerate shares:

Local Administrator Password Solution (LAPS) Primer:

2. Foothold:

Finding a backup in the Dev share:

PFX Certificates in Windows: A Primer

What’s Inside a PFX File:

Cracking the encrypted zip file using zip2john & john:

Attempting to extract the private keys from the .pfx:

Cracking the .pfx using pfx2john & john:

Extracting the private key & certificate with openssl from a .pfx:

Connecting with evil-winrm to the host using certificates:

3. Privilege Escalation:

General Enumeration:

Check group membership:

Check privileges:

Checking PowerShell history:

As our user is part of the legacy devs there may be some interesting information in their PowerShell history.

Finding clear text credentials in the PowerShell history file:

Performing a bloodhound collection:

Finding out svc_deploy has ReadLAPSPassword privileges over the DC:

Retrieving DC01 LAPS Password with PowerView via download cradle:

4. Persistence:

Dumping NTDS.dit/DC-SYNC attack:

Lessons Learned:

What did I learn?

  1. I learned alot about extracting credentials from .pfx files. That was fun.
  2. I learned that even if the box is being finnicky there will be a way to work around it.

What silly mistakes did I make?

  1. Not terrible this time. Nothing to write home about.

Sign off:

Remember, folks as always: with great power comes great pwnage. Use this knowledge wisely, and always stay on the right side of the law!

Until next time, hack the planet!

ā€“ Bloodstiller

ā€“ Get in touch bloodstiller at proton dot me

Next: Certified HTB Walkthrough