Temporary Advertisements:
Ad
Ad
Ad
DarkCorp Hack the Box Season 7 (Windows Insane)
by RedBlock - Saturday February 8, 2025 at 03:32 PM
(Feb 09, 2025, 07:44 PM)nothing0112358 Wrote: How did you manage to get the ntlmrelay to work ? The requests are made with SVC_ACC but how to steal his hash ?

I tried ntlmrelayx DCIP but as SVC_ACC is not admin it is not working ?

Maybe ntlmrelayx is not the way ?

Yep, it may be a rabbit hole. A user from discord told me that he didn't get svc_acc, only victor.r is required, something similar to mist box. I'm still thinking on how to approach it.
Reply
(Feb 09, 2025, 09:16 PM)spamdegratis5 Wrote:
(Feb 09, 2025, 07:44 PM)nothing0112358 Wrote: How did you manage to get the ntlmrelay to work ? The requests are made with SVC_ACC but how to steal his hash ?

I tried ntlmrelayx DCIP but as SVC_ACC is not admin it is not working ?

Maybe ntlmrelayx is not the way ?

Yep, it may be a rabbit hole. A user from discord told me that he didn't get svc_acc, only victor.r is required, something similar to mist box. I'm still thinking on how to approach it.

user.txt is on the web machine. We need to exploit the web at port 5000. But I don't know how... Tried some redirection with /status but epic fail

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
BTW, we can log in to drip.htb with the user taylor.b.adm and do 'sudo su'
Reply
(Feb 09, 2025, 10:22 PM)potato_moose Wrote: BTW, we can log in to drip.htb with the user taylor.b.adm and do 'sudo su'

Did you root the box ? How did you get taylor.b.adm ? Did you do the relay to pass from victor.r to Web-01 ? something is weird as signing is False on web-01 but True on Dc-01 encoraging us to do relay ...

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
(Feb 09, 2025, 10:57 PM)nothing0112358 Wrote:
(Feb 09, 2025, 10:22 PM)potato_moose Wrote: BTW, we can log in to drip.htb with the user taylor.b.adm and do 'sudo su'

Did you root the box ? How did you get taylor.b.adm ? Did you do the relay to pass from victor.r to Web-01 ? something is weird as signing is False on web-01 but True on Dc-01 encoraging us to do relay ...

They've got it by copypaste. Someone said it was by bruteforcing but who knows. I don't think that's the intended way.
Reply
Faster way from the drip host:

./kerbrute_linux_amd64 bruteuser -d darkcorp.htb --dc 172.16.20.1 rockyou.txt taylor.b.adm

Upload binaries and rockyou using a python web server.
Reply
I see people sharing the way to login via hash to get user and root pass. I was tracking all the way to getting elbeford's password.

I usually struggle with windows environments but this one was particularly heinous because it was my first time messing around with ligolo.

Is anyone going to release the steps they took? Was I right that it involved using the IIS server to get a hash and cracking that to get a foothold into the windows environment?

I see people charging credits for credentials but honestly the steps are more valuable.
Reply
(Feb 09, 2025, 11:57 PM)jonklem Wrote: I see people sharing the way to login via hash to get user and root pass.  I was tracking all the way to getting elbeford's password. 

I usually struggle with windows environments but this one was particularly heinous because it was my first time messing around with ligolo.

Is anyone going to release the steps they took?  Was I right that it involved using the IIS server to get a hash and cracking that to get a foothold into the windows environment?

I see people charging credits for credentials but honestly the steps are more valuable.

I think this is the intended path to play with the status, but I think I am not able to get a shell or don't understand the attack surface well

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching.
Reply
(Feb 09, 2025, 11:57 PM)jonklem Wrote: I see people sharing the way to login via hash to get user and root pass.  I was tracking all the way to getting elbeford's password. 

I usually struggle with windows environments but this one was particularly heinous because it was my first time messing around with ligolo.

Is anyone going to release the steps they took?  Was I right that it involved using the IIS server to get a hash and cracking that to get a foothold into the windows environment?

I see people charging credits for credentials but honestly the steps are more valuable.

I usually prefer Ligolo, but in this case for whatever reason (likely user error) I ended up using sshuttle for the pivot. Little bit of a latency issue when running evil-winrm through the pivot - not sure if anyone else has experienced it. Good box, nonetheless.
Reply
*Evil-WinRM* PS C:\Users\taylor.b.adm\Desktop> ./SharpGPOAbuse.exe --AddUserTask --TaskName "New Task" --Author darkcorp.htb\Administrator --Command "cmd.exe" --Arguments "/c whoami > C:\task.txt" --GPOName "SecurityUpdates"
The term './SharpGPOAbuse.exe' is not recognized as the name of a cmdlet, function, script file, or operable program. Check the spelling of the name, or if a path was included, verify that the path is correct and try again.
At line:1 char:1
+ ./SharpGPOAbuse.exe --AddUserTask --TaskName "New Task" --Author dark ...
+ ~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : ObjectNotFound: (./SharpGPOAbuse.exe:String) [], CommandNotFoundException
+ FullyQualifiedErrorId : CommandNotFoundException




any hint?
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [UPDATED] APT-Labs Prolabs Writeup z1ne99 41 5,939 4 hours ago
Last Post: morris
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 61 6,076 6 hours ago
Last Post: NIhaogt
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 441 112,629 Yesterday, 05:51 PM
Last Post: evermore
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 621 105,938 Yesterday, 03:59 PM
Last Post: user65745747
  How to Hack WiFi password Using PMKID Apvu 9 4,399 Sep 19, 2026, 09:08 PM
Last Post: anonhawk437

Forum Jump:


 Users browsing this forum: 1 Guest(s)