> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-sauna.md).

# HTB - Sauna

## Enumeration and Foothold

```bash
PORT      STATE SERVICE       VERSION
53/tcp    open  domain        Simple DNS Plus
80/tcp    open  http          Microsoft IIS httpd 10.0
88/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-06-16 09:32:10Z)
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: EGOTISTICAL-BANK.LOCAL, Site: Default-First-Site-Name)
445/tcp   open  microsoft-ds?
464/tcp   open  kpasswd5?
593/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp   open  tcpwrapped
3268/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: EGOTISTICAL-BANK.LOCAL, Site: Default-First-Site-Name)
3269/tcp  open  tcpwrapped
5985/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
9389/tcp  open  mc-nmf        .NET Message Framing
49669/tcp open  msrpc         Microsoft Windows RPC
49673/tcp open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
49674/tcp open  msrpc         Microsoft Windows RPC
49675/tcp open  msrpc         Microsoft Windows RPC
49688/tcp open  msrpc         Microsoft Windows RPC
49696/tcp open  msrpc         Microsoft Windows RPC
Service Info: Host: SAUNA; OS: Windows; CPE: cpe:/o:microsoft:windows
```

### SMB

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FNbtqr5VkwWy79TfFnHSC%2Fimage.png?alt=media&amp;token=1359c5b2-0e9c-40d4-9b41-c43c5c4e6014" alt=""><figcaption></figcaption></figure>

Anonymous access successful but cant list shares.

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F2UcSF4WP4Mz73WMsy1Wf%2Fimage.png?alt=media&amp;token=0083aea9-fbdf-42e0-b858-e1957400d641" alt=""><figcaption></figcaption></figure>

There is a Apply now page and a contact page, tried to see if i can exploit xss but nothing to exciting.

On about page, there is a list of team members working in the company.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FTNMuzN1ihmEG4Ug9uJpc%2Fimage.png?alt=media&amp;token=b9fb7b8f-3b9f-4b9f-a3bc-8fce7fa1550d" alt=""><figcaption></figcaption></figure>

What i am gonna do is extract them to a file and use username anarchy to generate a posisble usernames and validate them through kerbrute aganist the domain.

### Username-Anarchy

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FEnPjbu9e8I1iDfIg8QTO%2Fimage.png?alt=media&amp;token=a663b3e9-f06d-4ce1-a2a1-8e902e2dff02" alt=""><figcaption></figcaption></figure>

### Kerbrute

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fl3KOAhrcTfolg7IFxwWa%2Fimage.png?alt=media&amp;token=69f23099-1b8a-434f-afcb-68932990c820" alt=""><figcaption></figcaption></figure>

i dont have password for fsmith. i can try looking, if the fsmith doesnt have kerberos pre auth enabled. If so, i can perform Asreproast.

### Asreproast

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FqwmBYWakSygaAgsJBkXV%2Fimage.png?alt=media&amp;token=158d2e38-19a3-49e0-aa62-9cd1ac731aac" alt=""><figcaption></figcaption></figure>

I cna crack the hash using John or Hashcat.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FhaIMHoOYqya761XL0A9z%2Fimage.png?alt=media&amp;token=6698682f-00b5-4210-9c8d-e3e56c925787" alt=""><figcaption></figcaption></figure>

`fsmith : Thestrokes23`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FHWRwYWYdjQwN73zGe1cD%2Fimage.png?alt=media&amp;token=87e7ee93-26af-4e30-8f45-8015418edeec" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F3HRT4ZoJOHXv7R2RF2NQ%2Fimage.png?alt=media&amp;token=7d6930d6-c629-4c20-8656-afb260d711d5" alt=""><figcaption></figcaption></figure>

i can winrm using the creds, which means i have shell access.

## Shell as FSmith

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FQhfYImDrpjoh5mR3Xhkh%2Fimage.png?alt=media&amp;token=e80d295d-72a4-4e80-a178-0d433ec0fd91" alt=""><figcaption></figcaption></figure>

To escalate privileges further i can use winpeas to automate the enumeration process.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FQXDwgafbLUAjNzdBnTrw%2Fimage.png?alt=media&amp;token=59d83e78-f8d0-4361-836a-ef4a65cb0f6a" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FZqQbUjBnffkgSVArXs5T%2Fimage.png?alt=media&amp;token=e78f1337-ae3c-4f51-8bf3-80868b78df92" alt=""><figcaption></figcaption></figure>

Winpeas found autologon creds for `svc_loanmanager`.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FDNnAUIwXEpcSUvqgjfJg%2Fimage.png?alt=media&amp;token=d35f4a92-85aa-4350-a89d-6035bea85098" alt=""><figcaption></figcaption></figure>

nxc says access denied.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fpdw3e9YRYrOOamZH4QyD%2Fimage.png?alt=media&amp;token=fb8b9905-fa2b-4edd-ac05-1e5c307c5b51" alt=""><figcaption></figcaption></figure>

The users directory says there is a user called svc\_loanmgr

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FNAgN7q8UtwR2IDjMuYZj%2Fimage.png?alt=media&amp;token=2bf02926-14be-4b22-af54-1d0109f8d898" alt=""><figcaption></figcaption></figure>

i can try running the password aganist this user on the box.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FWG5qWwIgFo73iYZ8ylBX%2Fimage.png?alt=media&amp;token=16aa4480-f3ea-4a56-a976-daf4a990ea2d" alt=""><figcaption></figcaption></figure>

and the creds work. So we have a shell.

## Shell as svc\_loanmgr

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F6VFSbcbuEVab5h8eRi9X%2Fimage.png?alt=media&amp;token=b5f39786-d54c-4eda-84e7-76162d5e06bb" alt=""><figcaption></figcaption></figure>

there is nothing much i can do on the machine so have turned to bloodhound to see what rights the user have.

### Bloodhound

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FWbBVBuzhZLZeiQCq6FhR%2Fimage.png?alt=media&amp;token=9aa6d66a-3a37-4db1-bd14-ac568b43b08a" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FYKkpXLM33jCegyj5Bzl1%2Fimage.png?alt=media&amp;token=83003188-4ecf-4f4c-921d-4faec9b63493" alt=""><figcaption></figcaption></figure>

The user `SVC_LOANMGR@EGOTISTICAL-BANK.LOCAL` has:

* **GetChanges** - Permission to request replication data from the domain controller
* **GetChangesAll** - Permission to replicate **ALL** directory changes, including password hashes

This means **you can perform a DCSync attack** to dump all domain password hashes without needing domain admin credentials!

### DCSync

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FJgcmbNRg3SVABdcvO3iJ%2Fimage.png?alt=media&amp;token=087de226-0f8b-4686-bb20-04211ada5da5" alt=""><figcaption></figcaption></figure>

i can use the administrator hash to get shell as administrator.

## Shell as Administrator

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F4ULanEntHjUOqihuJPR2%2Fimage.png?alt=media&amp;token=0fd8b93b-c187-43b7-acc1-312a55104892" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-sauna.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
