DEV Community

Rafid Ahmed
Rafid Ahmed

Posted on

Hack The Box — Hercules Write-up | Advanced Active Directory & AD CS

Around three months ago, I successfully compromised Hercules, an Insane-rated Windows Active Directory machine on Hack The Box.

Hercules was an interesting challenge because it required chaining multiple Active Directory weaknesses rather than relying on a single misconfiguration.

The attack path required understanding how seemingly limited permissions could be chained together to obtain increasingly powerful access within the domain.

Full Kill Chain:

LDAP Injection → LFI → ASP.NET Cookie Forgery → NetNTLMv2 capture → Hash cracking → BloodHound recon → OU takeover → Disabled account resurrection → certificate abuse → Certificate impersonation → WinRM lateral movement → ForceChangePassword → Computer account takeover → RBCD + S4U2Self/U2U + S4U2Proxy → Domain Admin

Key moments:

  1. LDAP blind injection: Wildcard wasn't filtered. Information is gathered character by character.
  2. Forged ASP.NET cookie: Forged an auth cookie as a privileged user via cryptography config leak.
  3. Certificate abuse: Smartcard Operators. Woke it up, grabbed the vulnerable template, then minted certificates for whomever I wanted. AD CS did all the work.
  4. RBCD-S4U2Self/S4U2Proxy: machine account had delegation rights to the DC. Synced its hash with the Kerberos session key, abused.
  5. S4U2Self/U2U/S4U2Proxy obtained a service ticket as a domain admin. Didn't touch their password once.
  6. WinRM: Imported the ticket. Full shell on the DC. Objective complete.

Full Write-up

I documented the complete methodology, enumeration process, exploitation steps, attack chain, and technical analysis in my full write-up on Medium.

Read the full Hercules write-up on Medium:

https://medium.com/@rafidahmed/chained-trust-a-full-compromise-of-htb-hercules-via-ldap-injection-credential-harvesting-and-c81a033c5dcc?sk=3c12b9f28b36557b946521975a3855cb

The full article goes into significantly more detail, including the complete attack path and the techniques used to compromise the machine.

Thanks to Hack The Box for creating such a challenging and technically interesting machine.

If you're working through Hercules yourself, I hope the write-up helps you understand the attack chain and the underlying Active Directory concepts.

Top comments (0)