{"id":633,"date":"2021-03-10T13:44:38","date_gmt":"2021-03-10T13:44:38","guid":{"rendered":"https:\/\/cas.cybercop-training.ch\/?page_id=633"},"modified":"2021-03-11T13:07:32","modified_gmt":"2021-03-11T13:07:32","slug":"crackmapexec","status":"publish","type":"page","link":"https:\/\/cas.cybercop-training.ch\/index.php\/crackmapexec\/","title":{"rendered":"CrackMapExec"},"content":{"rendered":"<h1>Lab: Lateral Movement<\/h1>\n<h2>Step 13 &#8211; Lateral Movement to WS1 (CrackMapExec)<\/h2>\n<p><strong>Teamwork &#8211; Team DaMa<\/strong><\/p>\n<h2>Description<\/h2>\n<blockquote>\n<p>In the previous challenge, you were able to retrieve password hashes of multiple local users on the machine FS2. While local users might not look as promising as domain users, chances are that you might still be able to abuse them for lateral movement.<\/p>\n<\/blockquote>\n<p>A vulnerability commonly observed in many infrastructures is something called password-reuse between multiple accounts on different systems. A good example of this is the local administrator account (which is present on all Windows systems by default), which might have the same password everywhere (or at least on some systems).<\/p>\n<p>We will now see how to efficiently check for password reuse for the recovered accounts in the Windows Attack Lab.<\/p>\n<h2>Questions to Answer<\/h2>\n<p><strong><em>Q1:<\/em><\/strong><br \/>\nWhat is the vulnerability we are actually exploiting?<\/p>\n<p><strong><em>A1:<\/em><\/strong><br \/>\nThe main vulnerability is the <code>password reuse<\/code> . For the same account on the diffrent systems the same password is used.<\/p>\n<hr \/>\n<p><strong><em>Q2:<\/em><\/strong><br \/>\nHow can you efficiently check for password reuse across multiple systems?<\/p>\n<p><strong><em>A2:<\/em><\/strong>  <\/p>\n<ul>\n<li>With <code>password spraying<\/code> it&#8217;s possible to check the password reuse over multiple systems (if passwords are known).<br \/>\n<em>e.g. kerbrute:<\/em><\/li>\n<\/ul>\n<blockquote>\n<p>.\/kerbrute passwordspray &#8211;dc 10.0.1.100 -d winattacklab.local users.txt Winter2019<\/p>\n<\/blockquote>\n<ul>\n<li>Use of <code>CrackMapExec<\/code> if the the passwords are unknown but we have access to the NTLM hash (e.g. NTDS.dit)<br \/>\n<em>e.g. CrackMapExec:<\/em><\/li>\n<\/ul>\n<blockquote>\n<p>.\/cme smb 10.0.1.0\/24 &#8211;local-auth -u cme_users.txt -H cme_hashes.txt <\/p>\n<\/blockquote>\n<hr \/>\n<p><strong><em>Q3:<\/em><\/strong><br \/>\nWhat does CrackMapExec actually do under the hood?<\/p>\n<p><strong><em>A3:<\/em><\/strong><br \/>\nCrackMapExec makes heavy use of the Impacket library and the PowerSploit Toolkit for working with network protocols and performing a variety of post-exploitation techniques.<\/p>\n<p>In our example below the toll performs the following tasks:<\/p>\n<blockquote>\n<p>.\/cme smb 10.0.1.0\/24 &#8211;local-auth -u cme_users.txt -H cme_hashes.txt <\/p>\n<\/blockquote>\n<ol>\n<li>Scans the network <code>10.0.1.0\/24<\/code>for systems with <code>SMB<\/code> (tcp\/445) running.<\/li>\n<li>For the detected systems the tool executes a <code>PTH<\/code> with the users(cme_users.txt) and hashes(cme_hashes.txt)<\/li>\n<li>Lists the successful <code>PTH<\/code> attempts<\/li>\n<\/ol>\n<p><em>Results:<\/em><br \/>\n<img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/03\/step13-1.png\" alt=\"\" \/><\/p>\n<hr \/>\n<p><strong><em>Q4:<\/em><\/strong><br \/>\nWith which user did manage to login to which target with what kind of credential (type &amp; where did you get it from)?<\/p>\n<p><strong><em>A4:<\/em><\/strong>  <\/p>\n<ol>\n<li>We get the NTLM hashes from the SAM dump on <code>FS2<\/code><\/li>\n<li>With the local <code>support<\/code> user we are able to access the <code>WS1<\/code> with the NTLM hash(<code>password-reuse<\/code>and <code>PTH<\/code>)<\/li>\n<\/ol>\n<p><em>Pwn3d:<\/em><br \/>\n<img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/03\/step13-5.png\" alt=\"\" \/><\/p>\n<p>PDF Report:<br \/>\n<a href=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/03\/Readme-Step13.pdf\" class=\"mtli_attachment mtli_pdf\" title=\"Readme-Step13\">Readme-Step13<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Lab: Lateral Movement Step 13 &#8211; Lateral Movement to WS1 (CrackMapExec) Teamwork &#8211; Team DaMa Description In the previous challenge, you were able to retrieve password hashes of multiple local users on the machine FS2. While local users might not look as promising as domain users, chances are that you might still be able to [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-633","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/633","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/comments?post=633"}],"version-history":[{"count":3,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/633\/revisions"}],"predecessor-version":[{"id":752,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/633\/revisions\/752"}],"wp:attachment":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/media?parent=633"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}