Around three months ago, I successfully compromised Hercules, an Insane-rated Windows Active Directory machine on Hack The Box.
Hercules was an interesting challenge because it required chaining multiple Active Directory weaknesses rather than relying on a single misconfiguration.
The attack path required understanding how seemingly limited permissions could be chained together to obtain increasingly powerful access within the domain.
Full Kill Chain:
LDAP Injection → LFI → ASP.NET Cookie Forgery → NetNTLMv2 capture → Hash cracking → BloodHound recon → OU takeover → Disabled account resurrection → certificate abuse → Certificate impersonation → WinRM lateral movement → ForceChangePassword → Computer account takeover → RBCD + S4U2Self/U2U + S4U2Proxy → Domain Admin
Key moments:
- LDAP blind injection: Wildcard wasn't filtered. Information is gathered character by character.
- Forged ASP.NET cookie: Forged an auth cookie as a privileged user via cryptography config leak.
- Certificate abuse: Smartcard Operators. Woke it up, grabbed the vulnerable template, then minted certificates for whomever I wanted. AD CS did all the work.
- RBCD-S4U2Self/S4U2Proxy: machine account had delegation rights to the DC. Synced its hash with the Kerberos session key, abused.
- S4U2Self/U2U/S4U2Proxy obtained a service ticket as a domain admin. Didn't touch their password once.
- WinRM: Imported the ticket. Full shell on the DC. Objective complete.
Full Write-up
I documented the complete methodology, enumeration process, exploitation steps, attack chain, and technical analysis in my full write-up on Medium.
Read the full Hercules write-up on Medium:
The full article goes into significantly more detail, including the complete attack path and the techniques used to compromise the machine.
Thanks to Hack The Box for creating such a challenging and technically interesting machine.
If you're working through Hercules yourself, I hope the write-up helps you understand the attack chain and the underlying Active Directory concepts.
Top comments (0)