> For the complete documentation index, see [llms.txt](https://0xdeco.gitbook.io/vulnlab/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://0xdeco.gitbook.io/vulnlab/intercept.md).

# Intercept

You will learn about a technique that allows to takeover domain joined workstations on default configurations & exploiting ADCS

## Enumeration

Enumerating shares we find a `dev` writable share

<figure><img src="https://3164413258-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdsVljAgb891qXyZgmwtE%2Fuploads%2FIpSjNzXn8cnKsk1OPyxY%2FPasted%20image%2020231210230246.png?alt=media" alt=""><figcaption></figcaption></figure>

Inside we find a `readme.txt` and `autologon64.exe`, this probably means that an autologon password is stored somewhere

<figure><img src="https://3164413258-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdsVljAgb891qXyZgmwtE%2Fuploads%2FiIYIZOfLpmU49kFRA3gB%2FPasted%20image%2020231210230410.png?alt=media" alt=""><figcaption></figcaption></figure>

The readme says to check the share regularly&#x20;

<figure><img src="https://3164413258-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdsVljAgb891qXyZgmwtE%2Fuploads%2F6BOuH9Ma5TtUFGj7j9ie%2FPasted%20image%2020231210230524.png?alt=media" alt=""><figcaption></figcaption></figure>

We have write perms on the share so we can try to steal a NTLMv2 hash

This time instead of using `ntlm_theft` i wanted to try a NetExec module&#x20;

<figure><img src="https://3164413258-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdsVljAgb891qXyZgmwtE%2Fuploads%2F44vepDoey6fcDMEHh2N3%2FPasted%20image%2020231210231010.png?alt=media" alt=""><figcaption></figcaption></figure>

And we get a hit

<figure><img src="https://3164413258-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdsVljAgb891qXyZgmwtE%2Fuploads%2Ft69W3HJJ4dtxiqzzhTaU%2FPasted%20image%2020231210231027.png?alt=media" alt=""><figcaption></figcaption></figure>

To clean the `.lnk` file add `CLEANUP=True` to the previous NetExec command&#x20;

<figure><img src="https://3164413258-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdsVljAgb891qXyZgmwtE%2Fuploads%2FSXiTT4uiscspIPAc5s17%2FPasted%20image%2020231210231152.png?alt=media" alt=""><figcaption></figcaption></figure>

We cracked the password&#x20;

<figure><img src="https://3164413258-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdsVljAgb891qXyZgmwtE%2Fuploads%2FJj0wSrjEtRTQAcQqNv7o%2FPasted%20image%2020231210231227.png?alt=media" alt=""><figcaption></figcaption></figure>

This user does not have any interesting privileges&#x20;

But from the Nmap scan we can see that the DC is a CA

<figure><img src="https://3164413258-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdsVljAgb891qXyZgmwtE%2Fuploads%2FLtZ2a4l8RfpOufpeOFvb%2FPasted%20image%2020231210231712.png?alt=media" alt=""><figcaption></figcaption></figure>

&#x20;This means that ADCS is probably installed

We can try to run `certipy` but it does not find anything vulnerable&#x20;

<figure><img src="https://3164413258-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdsVljAgb891qXyZgmwtE%2Fuploads%2FOqPrAQLuSAS1dZ2ff35f%2FPasted%20image%2020231210231959.png?alt=media" alt=""><figcaption></figcaption></figure>

After looking at the hints ;) i checked if ldap channel binding was enabled&#x20;

<figure><img src="https://3164413258-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdsVljAgb891qXyZgmwtE%2Fuploads%2FZ3BBJBpTjAlgzvXsf5Yo%2FPasted%20image%2020231210232529.png?alt=media&amp;token=a6f4884f-b40f-4569-a30f-a6c10ad58918" alt=""><figcaption></figcaption></figure>

If WS01 is running the `WebClient` service we can make the workstation connect back to us and abuse Resource Based Constrained Delegation

## RBCD

We checked the MachineAccountQuota and it's 10, the default

This means that we can add computer accounts to the domain&#x20;

First we need to add a DNS entry that points to the attacker machine&#x20;

<figure><img src="https://3164413258-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdsVljAgb891qXyZgmwtE%2Fuploads%2FhjvbCULzcVWy2cQpZVTL%2FPasted%20image%2020231210233532.png?alt=media&amp;token=bb5a9628-c7fb-455b-8064-ac57f7b87dfa" alt=""><figcaption></figcaption></figure>

If you get a DNS error add the DC IP to `/etc/resolv.conf`&#x20;

Now we add a computer account

<figure><img src="https://3164413258-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdsVljAgb891qXyZgmwtE%2Fuploads%2F0UwY1BXx7OBxHiBNDPzD%2FPasted%20image%2020231210233829.png?alt=media&amp;token=6f0545f3-a0b5-4ee1-891c-7c45266b0ff3" alt=""><figcaption></figcaption></figure>

Now we can start `ntlmrelayx`&#x20;

<figure><img src="https://3164413258-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdsVljAgb891qXyZgmwtE%2Fuploads%2FnyTYO8w2Hu5UqfMbBsTe%2FPasted%20image%2020231210234807.png?alt=media&amp;token=01c8f77f-c79e-4a5c-aa1d-0220b8965319" alt=""><figcaption></figcaption></figure>

Now we force authentication from `WS01$`&#x20;

<figure><img src="https://3164413258-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdsVljAgb891qXyZgmwtE%2Fuploads%2FEakUQ30YquohZslijYMo%2FPasted%20image%2020231210234857.png?alt=media&amp;token=a45c0ebc-57ff-4774-8f60-6720f0ee0e64" alt=""><figcaption></figcaption></figure>

And it worked&#x20;

<figure><img src="https://3164413258-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdsVljAgb891qXyZgmwtE%2Fuploads%2FrSHt1qVYKuFjKBUvcRU2%2FPasted%20image%2020231210234955.png?alt=media&amp;token=3758e410-4c83-47df-9340-4637bd5b6b4b" alt=""><figcaption></figcaption></figure>

I should have specified the machine account to use for `ntlmrelayx` but it's whatever

Now we can request a ticket to impersonate Administrator on `WS01`

<figure><img src="https://3164413258-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdsVljAgb891qXyZgmwtE%2Fuploads%2FvJnPeooHTnWA2htssssS%2FPasted%20image%2020231210235429.png?alt=media&amp;token=4743241c-b920-48c8-a0e4-cc65e87e0042" alt=""><figcaption></figcaption></figure>

Now if we use `secretsdump` we can also see the autologon credential from before

<figure><img src="https://3164413258-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdsVljAgb891qXyZgmwtE%2Fuploads%2FcyPtxFgZEDSkeXtuylhl%2FPasted%20image%2020231210235721.png?alt=media&amp;token=024cd901-df64-4a16-aad9-b917341d9061" alt=""><figcaption></figcaption></figure>

## ADCS

Now that we have new creds i wanted to look at certipy again in bloodhound

<figure><img src="https://3164413258-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdsVljAgb891qXyZgmwtE%2Fuploads%2FgvNUxRZImrqCOF9Iv0zg%2FPasted%20image%2020231211000912.png?alt=media&amp;token=80d2e298-2527-4652-a6a8-674e0211398d" alt=""><figcaption></figcaption></figure>

Here we can see that Simon has `GenericAll` on `CA-Managers`

It's a bit of a messy attack path but if you click on `ESC7` we can see that the certificate is vulnerable since now we are a CA-Manager&#x20;

<figure><img src="https://3164413258-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdsVljAgb891qXyZgmwtE%2Fuploads%2FBPsPuXxTyJFgbLleKy8A%2FPasted%20image%2020231211001240.png?alt=media&amp;token=9e41a1a7-d2c5-422b-8426-e0f66fccd99b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3164413258-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdsVljAgb891qXyZgmwtE%2Fuploads%2FAu79pGQrb6H3ZaD0DlPD%2FPasted%20image%2020231211001551.png?alt=media&amp;token=92f0a938-d508-4a21-9e05-0860fac60e87" alt=""><figcaption></figcaption></figure>

To abuse this first we need to add `Simon.Bowen` to the `CA-Managers` group

<figure><img src="https://3164413258-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdsVljAgb891qXyZgmwtE%2Fuploads%2F1hldan3vdM5luMA8oLoy%2FPasted%20image%2020231211002248.png?alt=media&amp;token=b29db8f7-1b90-46e9-b30a-dbfa8c4b681b" alt=""><figcaption></figcaption></figure>

Now we can use `certipy`&#x20;

<figure><img src="https://3164413258-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdsVljAgb891qXyZgmwtE%2Fuploads%2F8t9FmN3pZdwsdO5gEnbU%2FPasted%20image%2020231211002634.png?alt=media&amp;token=24c5740d-460c-4f6a-88b2-c486c232d271" alt=""><figcaption></figcaption></figure>

After issuing the certificate we can request it and authenticate to get the Administrator's NT hash&#x20;

<figure><img src="https://3164413258-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdsVljAgb891qXyZgmwtE%2Fuploads%2FX6BKNkWpEAEKkVZ0SSLX%2FPasted%20image%2020231211002934.png?alt=media&amp;token=5715e04b-39e2-498c-b9eb-2800dd308b4a" alt=""><figcaption></figcaption></figure>
