HTB - Rebound
by HerVelizy - Saturday September 9, 2023 at 07:09 PM
#51
Has anyone here tried to abuse DACL for user oorend using Powerview? When trying to use Get-DomainGUIDMap, I kept getting an error:
Error in retrieving forest schema path from Get-Forest
I ended up doing this with dacledit.py, but I was wondering if anyone else got this error before and how to fix it.

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Spamming | Contact us via http://breachqr3dqbysbq5khaadg5ynnpxn2wrmw5y3rnzesun55l6lkq73yd.onion/misc.php?action=help&hid=27 if you feel this is incorrect.
Reply
#52
(Sep 12, 2023, 10:43 AM)Sundayz Wrote: I have this problem
```
getTGT.py 'rebound.htb/oorend:1GR8t@$$4u' -dc-ip 10.129.244.207
Impacket v0.11.0 - Copyright 2023 Fortra

Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great)
```

When i do :
sudo ntpdate -u pool.ntp.org
faketime '2023-09-12 12:30:09' getTGT.py 'rebound.htb/oorend:1GR8t@$$4u' -dc-ip 10.129.244.207

it not solve the problem.


you should ntp-sync with target???  "Clock skew too great" is between you and target and not between you and ntp  ¯⧵_(ツ)_/¯
Reply
#53
Here i have the Delegator NTLM hash but i don't know how i can abuse delegation Sad
Reply
#54
(Sep 12, 2023, 03:19 PM)Sundayz Wrote: Here i have the Delegator NTLM hash but i don't know how i can abuse delegation Sad

how did you get to tbrady user? constrained delegation is simple https://www.thehacker.recipes/ad/movemen...onstrained
Reply
#55
impossible to get tbrady user, i think 0x410x420x41 is hacker

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Spamming | Contact us via http://breachqr3dqbysbq5khaadg5ynnpxn2wrmw5y3rnzesun55l6lkq73yd.onion/misc.php?action=help&hid=27 if you feel this is incorrect.
Reply
#56
Got tbrady hash (and password) but honestly out of ideas of what to try next...
Reply
#57
(Sep 12, 2023, 06:47 PM)cagptgls Wrote: Got tbrady hash (and password) but honestly out of ideas of what to try next...

how did you get hash?
Reply
#58
(Sep 12, 2023, 06:56 PM)crypt1 Wrote: how did you get hash?

this one weird trick...
Reply
#59
(Sep 12, 2023, 01:55 PM)0x410x420x41 Wrote: The path to the system flag is not shorter than the user.
1. The user tbrady has the ability to read the GMSA password of the delegator$ GMSA
2. the delegator GMSA has constrained delegation configured over the DC

So as a first step a way to the user tbrady needs to be found (he has a session on the DC), next the gmsa password for delegator needs to be fetched and with this information the constrained delegation needs to be abused.

How do you know that tbrady has an active session? I see the exploit works but I don't see why...
Reply
#60
(Sep 12, 2023, 07:22 PM)al3xis Wrote:
(Sep 12, 2023, 01:55 PM)0x410x420x41 Wrote: The path to the system flag is not shorter than the user.
1. The user tbrady has the ability to read the GMSA password of the delegator$ GMSA
2. the delegator GMSA has constrained delegation configured over the DC

So as a first step a way to the user tbrady needs to be found (he has a session on the DC), next the gmsa password for delegator needs to be fetched and with this information the constrained delegation needs to be abused.

How do you know that tbrady has an active session? I see the exploit works but I don't see why...

bloodhound

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Spamming | Contact us via http://breachqr3dqbysbq5khaadg5ynnpxn2wrmw5y3rnzesun55l6lkq73yd.onion/misc.php?action=help&hid=27 if you feel this is incorrect.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] CPTS 12 FLAGS pulsebreaker 75 2,412 29 minutes ago
Last Post: rft569o7k
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 376 93,849 5 hours ago
Last Post: Sukon
  [FREE] CPTS • CWES • CDSA • CWEE Exam Hint 3midjets 233 32,396 6 hours ago
Last Post: Sukon
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 89 8,131 11 hours ago
Last Post: Xploitd
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 10 639 Yesterday, 03:44 PM
Last Post: chufoni

Forum Jump:


 Users browsing this forum: 1 Guest(s)