HTB - Rebound
by HerVelizy - Saturday September 9, 2023 at 07:09 PM
#51
Has anyone here tried to abuse DACL for user oorend using Powerview? When trying to use Get-DomainGUIDMap, I kept getting an error:
Error in retrieving forest schema path from Get-Forest
I ended up doing this with dacledit.py, but I was wondering if anyone else got this error before and how to fix it.
Ban reason: Spamming | Contact us via http://raiddfzn73ir6iyxlf7nwytnujiflddog...on/contact if you feel this is incorrect. (Permanent)
Reply
#52
(09-12-2023, 10:43 AM)Sundayz Wrote: I have this problem
```
getTGT.py 'rebound.htb/oorend:1GR8t@$$4u' -dc-ip 10.129.244.207
Impacket v0.11.0 - Copyright 2023 Fortra

Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great)
```

When i do :
sudo ntpdate -u pool.ntp.org
faketime '2023-09-12 12:30:09' getTGT.py 'rebound.htb/oorend:1GR8t@$$4u' -dc-ip 10.129.244.207

it not solve the problem.


you should ntp-sync with target???  "Clock skew too great" is between you and target and not between you and ntp  ¯⧵_(ツ)_/¯
Reply
#53
Here i have the Delegator NTLM hash but i don't know how i can abuse delegation Sad
Reply
#54
(09-12-2023, 03:19 PM)Sundayz Wrote: Here i have the Delegator NTLM hash but i don't know how i can abuse delegation Sad

how did you get to tbrady user? constrained delegation is simple https://www.thehacker.recipes/ad/movemen...onstrained
Reply
#55
impossible to get tbrady user, i think 0x410x420x41 is hacker
Ban reason: Spamming | Contact us via http://raiddfzn73ir6iyxlf7nwytnujiflddog...on/contact if you feel this is incorrect. (Permanent)
Reply
#56
Got tbrady hash (and password) but honestly out of ideas of what to try next...
Reply
#57
(09-12-2023, 06:47 PM)cagptgls Wrote: Got tbrady hash (and password) but honestly out of ideas of what to try next...

how did you get hash?
Reply
#58
(09-12-2023, 06:56 PM)crypt1 Wrote: how did you get hash?

this one weird trick...
Reply
#59
(09-12-2023, 01:55 PM)0x410x420x41 Wrote: The path to the system flag is not shorter than the user.
1. The user tbrady has the ability to read the GMSA password of the delegator$ GMSA
2. the delegator GMSA has constrained delegation configured over the DC

So as a first step a way to the user tbrady needs to be found (he has a session on the DC), next the gmsa password for delegator needs to be fetched and with this information the constrained delegation needs to be abused.

How do you know that tbrady has an active session? I see the exploit works but I don't see why...
Reply
#60
(09-12-2023, 07:22 PM)al3xis Wrote:
(09-12-2023, 01:55 PM)0x410x420x41 Wrote: The path to the system flag is not shorter than the user.
1. The user tbrady has the ability to read the GMSA password of the delegator$ GMSA
2. the delegator GMSA has constrained delegation configured over the DC

So as a first step a way to the user tbrady needs to be found (he has a session on the DC), next the gmsa password for delegator needs to be fetched and with this information the constrained delegation needs to be abused.

How do you know that tbrady has an active session? I see the exploit works but I don't see why...

bloodhound
Ban reason: Spamming | Contact us via http://raiddfzn73ir6iyxlf7nwytnujiflddog...on/contact if you feel this is incorrect. (Permanent)
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 360 88,710 03-28-2026, 09:28 AM
Last Post: catsweet
  [FREE] HTB-ProLabs APTLABS Just Flags kewlsunny 23 2,348 03-28-2026, 03:30 AM
Last Post: lulaladrow
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 87 7,490 03-27-2026, 07:22 PM
Last Post: stn
  HTB Eloquia User and Root Flags - Insane Box 69646B 13 350 03-27-2026, 06:14 PM
Last Post: vlxw
  HTB - ALL Challenges you Stuck in osamy7593 2 646 03-27-2026, 04:24 PM
Last Post: catsweet



 Users browsing this thread: 1 Guest(s)