{"version":1,"type":"rich","provider_name":"Libsyn","provider_url":"https:\/\/www.libsyn.com","height":90,"width":600,"title":"7MS #732: Tales of Pentest Pwnage \u2013 Part 86","description":"Hey friends! Welcome back to another Tales of Pentest Pwnage \u2014 my favorite mini-series where I share the good, the bad, and the \u201cwhy didn\u2019t I check THAT first?!\u201d moments from real-world engagements. Today\u2019s story has a little bit of everything: a legit path to domain admin, some late-night rabbit holes, a lesson in humility, and a villain you\u2019ve definitely met before. (Spoiler: it\u2019s DNS.) A couple of quick plugs before we dive in:  Private GOAD training is going strong!&amp;nbsp;\u2014 We just wrapped a 3-day private session (7 students \u2014 that\u2019s max capacity!) of our Active Directory pentesting class built on the&amp;nbsp;Game of Active Directory (GOAD)&amp;nbsp;framework. Over three days, students enumerate, attack, and fully pwn three separate AD environments. The private format is just *chef\u2019s kiss* \u2014 when it\u2019s a team from the same company, the conversation gets real fast. Like, \u201chey I just checked Bloodhound on break and Bob from accounting has full rights over the DC\u201d real. If you want to send 3\u20137 people from your org, hit up&amp;nbsp;7MinSec.com\/training&amp;nbsp;to line up a private session. Support the show over at&amp;nbsp;7MinSec.club&amp;nbsp;\u2014 That\u2019s our Substack, where every Tuesday I drop a short TuesdayTOOLSday video about security tools. Free subscriptions are welcome and mean a lot \u2014 you\u2019ll just get pinged when new content drops. No spam, no blindly-sent Outlook calendar invites. I promise. Pentest tips and scripts live at&amp;nbsp;7MinSec.wiki&amp;nbsp;\u2014 I reference it throughout today\u2019s episode, including some step-by-step guidance on the techniques we\u2019ll talk about below.  Now \u2014 onto the pwnage. Fair warning: I\u2019ve been burning the candle at three ends lately trying to catch up after a tough few weeks of grief (if you want the backstory, the last couple episodes cover my dad passing away). The good news is my head is semi back on straight and I put it to work on a recurring client environment \u2014 one that keeps getting better year over year. Machine account quota locked down? Check. No Kerberoastable or AS-REP roastable users? Check. No local admin rights, no web client running? Check and check. All good signs. And then&amp;nbsp;PingCastle&amp;nbsp;smiled right into my eyeballs with a big red finding:  The DC\u2019s LAN Manager authentication level was weak enough to coerce and capture a downgraded hash&amp;nbsp;\u2014 Specifically, an NTLMv1 SSP hash. Using&amp;nbsp;Coercer&amp;nbsp;to nudge the DC into authenticating to my Kali box (with Responder running), I captured the goods. Pretty little hashes all in a row. Cracking that hash: enter&amp;nbsp;Vast.ai&amp;nbsp;\u2014 The old go-to for this type of crack used to be&amp;nbsp;crack.sh, but their cracker has been offline for years. What they&amp;nbsp;do&amp;nbsp;still have is a walkthrough pointing to a tool from EvilMog on GitHub that helps you prep the raw hash material and figure out exactly how to crack it with Hashcat. For the GPU horsepower, I rented a beefy multi-GPU instance on Vast.ai \u2014 filter for 16+ GPUs, pick a Hashcat Docker image, and SSH in. The whole crack job took about 16 hours at ~$4\/hr. Do the math: $64 to reconstruct the DC\u2019s NTLM hash. Worth it. Tmux sidebar \u2014 seriously just learn it&amp;nbsp;\u2014 Vast.ai is actually what finally got me into&amp;nbsp;tmux, because the Hashcat Docker container drops you right into a tmux session. This is clutch: you can kick off a 16-hour crack job, detach, and reattach later without killing anything. On a pentest, my workflow now is SSH in \u2192 tmux \u2192 name a few session windows for Responder, Exegol, packet captures, etc. I used to fumble around with Linux screen sessions. Not anymore! From hash to DA \u2014 the usual playbook&amp;nbsp;\u2014 Once you\u2019ve got the DC\u2019s NTLM hash, you can request a Kerberos ticket and load it up, then run a DCSync to pull the KRBTGT hash. From there it\u2019s god mode: dump hashes, pass-the-hash as domain admins, and you have yourself a cool privesc POC. Except this time\u2026the POC didn\u2019t work. The part where I Jean-Claude Van Damme helicopter kick myself in the face&amp;nbsp;\u2014 DCSync failed immediately. Like, suspiciously fast \u2014 barely two lines of output and done. I tried every version of every tool I could get my hands on. I tried Windows, I tried Linux. I even asked the client to check if their endpoint protection was blocking me (it wasn\u2019t). I touched grass. I played guitar. I played some Splinter Cell Blacklist (old game, highly recommend if you like the Hitman-style vibes). Came back fresh. Rebooted both VMs. Still nothing. It was DNS. It\u2019s always DNS.&amp;nbsp;\u2014 The thing that finally caught my eye: the commands were failing&amp;nbsp;too fast. Like it wasn\u2019t even reaching the DC. I catted the resolv.conf inside my&amp;nbsp;Exegol&amp;nbsp;instance (heads up: Exegol has its own resolv.conf and hosts file, separate from your base Kali system!) and found a stale DNS entry pointing to an old DC that was no longer serving anything. Nuked the bad entry, added static hosts file entries for the live DC, ran the command again, and \u2014 hash rain. Pennies from heaven. It was midnight and I literally pushed back from my desk like a baby pushing away from a high chair going \u201cBaby Brian is all done!\u201d The lesson:&amp;nbsp;\u2014 I know the meme. \u201cIt\u2019s always DNS.\u201d I just personally hadn\u2019t hit it hard in my security life since my sysadmin days back before 2013. Now I have. So going forward I\u2019ll check DNS first (and often). Vacation attempt #3 incoming\u2026 pray for me&amp;nbsp;\u2014 My wife nearly died in Punta Cana earlier this year. Then our summer cabin trip was cold and rainy with zero water time. And now we\u2019ve got families flying in from multiple states for a lake weekend \u2014 except we just found out our reservation through Booking.com was basically vaporized because the resort changed hands and never updated their website. My wife (who is an absolute saint and my better three-quarters) almost had a 360-degree head spin (like in The Exorcist) talking to customer service. But we scrambled, found a last-minute place, and I\u2019m choosing to believe it\u2019s not in Jason Voorhees\u2019 back yard.  Could this be my last episode? Maybe. But hey \u2014 it was a good one. Talk to you next week (hopefully). ","author_name":"7 Minute Security","author_url":"https:\/\/7MinSec.com","html":"<iframe title=\"Libsyn Player\" style=\"border: none\" src=\"\/\/html5-player.libsyn.com\/embed\/episode\/id\/42177375\/height\/90\/theme\/custom\/thumbnail\/yes\/direction\/forward\/render-playlist\/no\/custom-color\/88AA3C\/\" height=\"90\" width=\"600\" scrolling=\"no\"  allowfullscreen webkitallowfullscreen mozallowfullscreen oallowfullscreen msallowfullscreen><\/iframe>","thumbnail_url":"https:\/\/assets.libsyn.com\/secure\/item\/42177375"}