Skip to main content
Qubicweb logo

HackTheBox - Pirate

September 5, 2026

Description

00:00 - Introduction 01:05 - Start of nmap 04:00 - Running a lot of NXC Enumeration (users, computers, groups, delegation) 07:00 - Running Rusthound and looking over Bloodhound data, discovering delegation, pre-2k compatibility group, etc 14:30 - Abusing the Pre-2k Compatibility group to login as MS01 and dump GMSA Passwords 17:00 - WinRM to DC01, pivoting to Web01 via chisel 31:00 - Stealing the NTLM Hash, discovering NTLMv1 and attempting to crack it 34:30 - Using KrbRelayX to add the ippsec DNS record 48:20 - Unable to crack, doing NTLMRelay and coercer to trick the machine account to authenticate from HTTP to DC LDAP and then using set_rbcd to add a privilege that lets us impersonate users on this box 01:00:00 - Running SecretsDump with our impersonated account to dump the SAM, get A.White's password which can reset their ADM account password whom has a path to DA 01:07:00 - Updating the SPN's to point to the DC instead of WEB01 which lets us impersonate users to the domain and getting root 01:12:10 - Unintended: Showing a direct path from Web01 to A.White with RemotePotato0 and NTLMRelay

Watch on Original Source

Trust cues for videos

Internal ReadExternal SourceQubicweb AnalysisCommunity signalMixedSource-only