Kaiju (Chain)
This is not a writeup, just my notes about the machine.
Machine information

Credentials
Username
Password
Method
Scope
Information Gathering
Nmap Scan
Service Enumeration
10.10.170.134
FTP
Initial foothold on BERSRV200
Cracking the hash using Hashcat
Listing the additional disk on BERSRV200
Retrieving the FileZilla's Administrator password
Cracking Administrator's hash
Lateral Movement to sasrv200
Setting up a port forwarding
Obtaining Filezilla version
Connecting to Filezilla Server

Exporting configuration and importing configuration
Creating and SSH key file for windows
Renaming key to authorized_keys
Uploading the file using FTP server to sasrv200/.ssh/
Connecting via SSH
Privilege Escalation to Administrator
Discovering and Keepass process running

Abusing Keepass database via Malicious DLL
Disabling real time protection monitoring
Dumping LSA using netexec
Compromise Domain Controller
Discovering a vulnerable templates to ESC8
Setting up StreamDivert to redirect the port
Setting up the port forwarding using SSH
Setting up the ntlmrelayx
Coercing the authentication
Retrieving NT Hash for Domain Controller
Performing DCSync Attack
Authenticating on BERSRV100
Last updated