(07-01-2024, 01:55 AM)bl4ckp4nth3r3 Wrote: (06-30-2024, 12:17 PM)ritualist Wrote: (06-30-2024, 12:14 PM)pwns4k3 Wrote: (06-30-2024, 09:52 AM)ritualist Wrote: (06-30-2024, 09:24 AM)jeff1998 Wrote: i am at Remote_Support_Administrators user now. any nudge for root?
I'm in the same place. You can abuse WriteSPN to get the hash of RSA_4810 and crack it. Check Bloodhound for details.
I have noticed RSA_4810 can write to
C:\Windows\SYSVOL\domain\scripts\A32FF3AEAA23
C:\Windows\SYSVOL\sysvol\blazorized.htb\scripts\A32FF3AEAA23
No idea if that's useful.
How did you get NU_1055 password? NTLMv2-SSP Hash isn't crackable
You don't need it.
Set-DomainObject -Identity RSA_4810 -SET @{serviceprincipalname='nonexistent/BLAHBLAH'}
Get-DomainSPNTicket -SPN nonexistent/BLAHBLAH
Does resulting passwd have space in it? Output of hashcat show password like this: "Ex@mPl3 #"
This accurate? I cannot use resulting hash cracked to auth via smb/winrm/etc... with RSA_4810 user
same, even the # too, so I am going out on a limb here, but I think we goofed up the same thing up.
T think the hash is for whatever/blahblah....well I made mine kittycat/MOEWMOEW, soI think we got the wrong user given we got the same results; unles you were using meowmoew too?