π΄ββ οΈPirate
https://app.hackthebox.com/machines/Pirate

Pirate β HackTheBox Writeup
Machine Information
Recon
Local Config
/etc/hosts
/etc/hosts/etc/krb5.conf
/etc/krb5.confEnumeration / Attack Path Discovery
1) Get gMSA secrets
2) WinRM to DC01 as gMSA
3) Pivot to WEB01 with Ligolo-ng
4) NTLM relay + RBCD to WEB01
5) Dump secrets from WEB01
6) ForceChangePassword on a.white_adm
a.white_adm7) Constrained Delegation abuse (S4U)
Result
Last updated