> For the complete documentation index, see [llms.txt](https://rouvin.gitbook.io/ibreakstuff/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://rouvin.gitbook.io/ibreakstuff/writeups/hackthebox/hard/object.md).

# Object

## Gaining Access

As usual, we start with an Nmap scan:

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-bab7376335ba77d925f7c8f39ce5e81f282dda2c%2Fimage.png?alt=media)

Doing a detailed scan, we can find that port 8080 was running a Jetty instance.

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-e967084b7401adb5ffbd9c93f3bd9a96fdd10836%2Fimage.png?alt=media)

### Jenkins

Port 8080 revealed a Jenkins instance login page:

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-8dcf8e45486fe15fe10f7793ce29e9495955f252%2Fimage.png?alt=media)

With Jenkins, I attempted to create a Windows batch command that would execute every minute like so:

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-797bcfc016dd60d9a3a3d7f5acd4300c5dc4b75a%2Fimage.png?alt=media)

However, this failed because the box was unable to reach my machine. I suppose there is a firewall or something within the machine that is blocking outgoing TCP traffic.

Instead, we can use this machine to enumerate the box instance. I noticed that the machine was building the workspace in this directory:

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-902ad22657ea5e77de18698e72ba694839c96592%2Fimage.png?alt=media)

I opeted to view the files in that directory using `dir /s`.

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-f65b93016e798f9ffa6e592c0b05ae6a4317223e%2Fimage.png?alt=media)

We find another `.jenkins` folder. Within that, we would find another `users` folder with some `config.xml` files:

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-edf072d72cbf31947d28784634fb475d71e5f077%2Fimage.png?alt=media)

Naturally, the admin one is more interesting. Taking a look reveals that there is an encoded password within it:

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-c86a01f4c29fe71d88b9b92bfd3f2b5fe9bd6228%2Fimage.png?alt=media)

### Decrypting Password

With Jenkins instances, we would need to extract 2 files that are used to decrypt this password, which is the `master.key` and the `hudson.util.Secret` files. These can be found within the `C:\users\oliver\AppData\Local\Jenkins\.jenkins\secrets\` folder.

Since they might be in non-printable characters, we would need to use Base64 to get them out. This can be done with a little Powershell scripting.

```powershell
powershell "[convert]::ToBase64String((Get-Content -path '<PATH>' -Encoding byte))"
```

After extracting both of these files, we can use this tool to decrypt them:

{% embed url="<https://github.com/hoto/jenkins-credentials-decryptor>" %}

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-f7d181a83da68925808829c2f1764de35ce46780%2Fimage.png?alt=media)

Then, we can `evil-winrm` in as `oliver`.

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-a42d3c4bbe5e46e4757ec505b364d08f517c9940%2Fimage.png?alt=media)

## Privilege Escalation

Once in the machine, I ran `Sharphound.ps1` to enumerate for me:

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-ba0a8c5c8ee680208dbca8ba4b470a7c857b8ab6%2Fimage.png?alt=media)

### BloodHound

We find that within Bloodhound, the `oliver` user has the `ForceChangePassword` permission over the `smith` user.

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-fad530bee212bc3cb793a1413b429a736a135112%2Fimage.png?alt=media)

The `smith` user has `GenericWrite` permissions over the `maria` user:

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-39c7d3979676b4bde618cc0518ffafb0211cddc9%2Fimage.png?alt=media)

And lastly, the `maria` user has `WriteOwner` permissions over the `Domain Admins` group:

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-2dacbcc9977510d3a5d12010efa04323e52a50cd%2Fimage.png?alt=media)

Interesting path of exploits.

### Oliver to Smith

Moving to the `smith` user is rather easy. We can simpy change his password using some Powerview

```powershell
$newpass = ConvertTo-SecureString 'Password@123' -AsPlainText -Force
. .\powerview.ps1
Set-DomainUserPassword -Identity smith -AccountPassword $newpass
```

Then we can evil-winrm in.

### Smith to Maria

Because we had `GenericWrite` over `maria` now, we can set an SPN for the user `maria` and Kerberoast the user.

However, this did not work out well as I was not able to make use of the ticket. Furthermore, the firewall was still up and I could not transfer files around easily. As such, I opted to read the `maria` user's directory to see what files are present since we cannot do anything else.

As `smith`, we can create a malicious Powershell script and change the logon script for `maria`.

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-54fe1248316e688d3464ff52a0c688314d581597%2Fimage.png?alt=media)

Within the desktop, I found this `Engines.xls` file.

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-044118e06970569f41ee5c4698efcb726a0dabaa%2Fimage.png?alt=media)

Copying it to another directory, I was able to move it to my machine using the `download` command from `evil-winrm`. Within it, we can find some credentials:

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-437a8f3808e6ad51dff32beb2eec4cc6653360a3%2Fimage.png?alt=media)

We can use the last credential to `evil-winrm` in as `maria`:

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-1f9adc06e18d4e814691170c4cb810fa8959b383%2Fimage.png?alt=media)

### Maria to Domain Admin

Because `maria` has `WriteOwner` privileges over the group, we can simply add ourselves to the Domain Admin group:

```powershell
# PowerView
Set-DomainObjectOwner -Identity "Domain Admins" -OwnerIdentity "maria"
Add-DomainObjectAcl -TargetIdentity "Domain Admins" -PrincipalIdentity maria -Rights All
net group "Domain Admins" maria /add
```

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-6408f8c31ad0398ce2e11a9e1cbc4a4628da2c01%2Fimage.png?alt=media)

Afterwards, we can re-logon using `evil-winrm` and see that we have full administrative privileges:

![](https://1617468840-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fqpzdj1tPRpELJdvxuVYh%2Fuploads%2Fgit-blob-1066823c4c21715d7a34506dfd1de0561b7a4b1d%2Fimage.png?alt=media)

We can then access the administrator desktop and capture the root flag.
