{"id":368,"date":"2022-05-13T23:18:11","date_gmt":"2022-05-13T23:18:11","guid":{"rendered":"https:\/\/dextersec.xyz\/?p=368"},"modified":"2022-05-13T23:18:11","modified_gmt":"2022-05-13T23:18:11","slug":"active-directory-hacking-with-kali-thm-roasted","status":"publish","type":"post","link":"https:\/\/dextersec.xyz\/?p=368","title":{"rendered":"Active Directory Hacking with Kali: THM Roasted"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\"><strong>Introduction<\/strong><\/h2>\n\n\n\n<p>For my fourth machine in the Active Directory hacking with Kali series, I\u2019ll be pwning roasted from tryhackme. Roasted is an easy active directory machine that teaches the basics of active directory enumeration and ASREPROASTING attacks.<\/p>\n\n\n\n<p><strong>Reconnaissance <\/strong><\/p>\n\n\n\n<p>Start by running an Nmap scan<\/p>\n\n\n\n<p>P.S Use the -Pn switch to suppress pings<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"736\" height=\"293\" src=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-25.png\" alt=\"\" class=\"wp-image-369\" srcset=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-25.png 736w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-25-300x119.png 300w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-25-210x84.png 210w\" sizes=\"(max-width: 736px) 100vw, 736px\" \/><\/figure>\n\n\n\n<p>From the Nmap scan above we can gather the following:<\/p>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\"><li>Port 53 indicates that DNS is running on this machine<\/li><li>Port 88 is running the Kerberos authentication service<\/li><li>Ports 389 &amp; 3628 have LDAP running<\/li><li>The host scripts reveal that SMBv2 is running on port 445<\/li><li>The host is a Domain Controller<\/li><li>LDAP provides us with the domain name vulnnet-rst.local<\/li><\/ol>\n\n\n\n<p><strong>Enumeration<\/strong><\/p>\n\n\n\n<p>Enumerate SMB with SMBMAP<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>smbmap -H vulnnet-rst.local -u guest -p \"\"<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"991\" height=\"185\" src=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-27.png\" alt=\"\" class=\"wp-image-371\" srcset=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-27.png 991w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-27-300x56.png 300w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-27-768x143.png 768w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-27-210x39.png 210w\" sizes=\"(max-width: 980px) 100vw, 980px\" \/><\/figure>\n\n\n\n<p>Enumerate domain users with crackmapexec by brute-forcing rids<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>crackmapexec smb vulnnet-rst.local -u \"guest\" -p '' --rid-brute<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"803\" height=\"224\" src=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-26.png\" alt=\"\" class=\"wp-image-370\" srcset=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-26.png 803w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-26-300x84.png 300w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-26-768x214.png 768w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-26-210x59.png 210w\" sizes=\"(max-width: 803px) 100vw, 803px\" \/><\/figure>\n\n\n\n<p>Save discovered users into a file userslist.txt<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"793\" height=\"295\" src=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-28.png\" alt=\"\" class=\"wp-image-372\" srcset=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-28.png 793w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-28-300x112.png 300w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-28-768x286.png 768w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-28-210x78.png 210w\" sizes=\"(max-width: 793px) 100vw, 793px\" \/><\/figure>\n\n\n\n<p><strong>Exploitation<\/strong><\/p>\n\n\n\n<p>Using the information gathered so far we can attempt to exploit ASREPROASTABLE (Non-Preauthenticated) users<\/p>\n\n\n\n<p>Run GETNPUSers.py from impacket against our list of gathered users<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python3 GetNPUsers.py vulnnet-rst.local\/ -usersfile userslist.txt -dc-ip 10.10.184.239<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"844\" height=\"262\" src=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-29.png\" alt=\"\" class=\"wp-image-373\" srcset=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-29.png 844w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-29-300x93.png 300w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-29-768x238.png 768w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-29-210x65.png 210w\" sizes=\"(max-width: 844px) 100vw, 844px\" \/><\/figure>\n\n\n\n<p>We are able to obtain t-skid&#8217;s hash from the AS-reply<\/p>\n\n\n\n<p>Save the hash into a file and crack with john <\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo john hash.txt --wordlist=\/usr\/share\/wordlists\/rockyou.txt<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"144\" src=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-31-1024x144.png\" alt=\"\" class=\"wp-image-375\" srcset=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-31-1024x144.png 1024w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-31-300x42.png 300w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-31-768x108.png 768w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-31-210x29.png 210w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-31.png 1091w\" sizes=\"(max-width: 980px) 100vw, 980px\" \/><\/figure>\n\n\n\n<p>We have read access to Netlogon share <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"925\" height=\"181\" src=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-32.png\" alt=\"\" class=\"wp-image-376\" srcset=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-32.png 925w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-32-300x59.png 300w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-32-768x150.png 768w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-32-210x41.png 210w\" sizes=\"(max-width: 925px) 100vw, 925px\" \/><\/figure>\n\n\n\n<p>Interesting script in the NETLOGON share&#8230; Download and Open<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"928\" height=\"226\" src=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-33.png\" alt=\"\" class=\"wp-image-377\" srcset=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-33.png 928w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-33-300x73.png 300w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-33-768x187.png 768w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-33-210x51.png 210w\" sizes=\"(max-width: 928px) 100vw, 928px\" \/><\/figure>\n\n\n\n<p>Hmnnn hardcoded password in the script<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"739\" height=\"303\" src=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-35.png\" alt=\"\" class=\"wp-image-379\" srcset=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-35.png 739w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-35-300x123.png 300w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-35-210x86.png 210w\" sizes=\"(max-width: 739px) 100vw, 739px\" \/><\/figure>\n\n\n\n<p>Lets try it with crackmap exec on smb &amp; winrm&#8230;<\/p>\n\n\n\n<p> PWNED! <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"121\" src=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-36-1024x121.png\" alt=\"\" class=\"wp-image-380\" srcset=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-36-1024x121.png 1024w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-36-300x35.png 300w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-36-768x91.png 768w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-36-210x25.png 210w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-36.png 1052w\" sizes=\"(max-width: 980px) 100vw, 980px\" \/><\/figure>\n\n\n\n<p>Login with evil-winrm<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"761\" height=\"167\" src=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-37.png\" alt=\"\" class=\"wp-image-381\" srcset=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-37.png 761w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-37-300x66.png 300w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-37-210x46.png 210w\" sizes=\"(max-width: 761px) 100vw, 761px\" \/><\/figure>\n\n\n\n<p>We&#8217;re in&#8230;<\/p>\n\n\n\n<p>We enumerate again with SMBMAP for Privesc<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"960\" height=\"206\" src=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-38.png\" alt=\"\" class=\"wp-image-382\" srcset=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-38.png 960w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-38-300x64.png 300w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-38-768x165.png 768w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-38-210x45.png 210w\" sizes=\"(max-width: 960px) 100vw, 960px\" \/><\/figure>\n\n\n\n<p>We have Read &amp; Write Access to the $ADMIN share, let&#8217;s dump secrets with impacket secretsdump.py<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"334\" src=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-39-1024x334.png\" alt=\"\" class=\"wp-image-383\" srcset=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-39-1024x334.png 1024w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-39-300x98.png 300w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-39-768x251.png 768w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-39-210x69.png 210w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-39.png 1100w\" sizes=\"(max-width: 980px) 100vw, 980px\" \/><\/figure>\n\n\n\n<p>Login and profit with admin hash<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"818\" height=\"369\" src=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-40.png\" alt=\"\" class=\"wp-image-384\" srcset=\"https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-40.png 818w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-40-300x135.png 300w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-40-768x346.png 768w, https:\/\/dextersec.xyz\/wp-content\/uploads\/2021\/09\/image-40-210x95.png 210w\" sizes=\"(max-width: 818px) 100vw, 818px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Introduction For my fourth machine in the Active Directory hacking with Kali series, I\u2019ll be pwning roasted from tryhackme. Roasted is an easy active directory machine that teaches the basics of active directory enumeration and ASREPROASTING attacks. Reconnaissance Start by running an Nmap scan P.S Use the -Pn switch to suppress pings From the Nmap [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":392,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-368","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/dextersec.xyz\/index.php?rest_route=\/wp\/v2\/posts\/368"}],"collection":[{"href":"https:\/\/dextersec.xyz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dextersec.xyz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dextersec.xyz\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dextersec.xyz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=368"}],"version-history":[{"count":2,"href":"https:\/\/dextersec.xyz\/index.php?rest_route=\/wp\/v2\/posts\/368\/revisions"}],"predecessor-version":[{"id":393,"href":"https:\/\/dextersec.xyz\/index.php?rest_route=\/wp\/v2\/posts\/368\/revisions\/393"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dextersec.xyz\/index.php?rest_route=\/wp\/v2\/media\/392"}],"wp:attachment":[{"href":"https:\/\/dextersec.xyz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=368"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dextersec.xyz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=368"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dextersec.xyz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=368"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}