Tom Hunter's Diary: 'The Hound of the Baskervilles'

Delaying the signing is a common practice for any large company. The contract between Tom Hunter and an online pet store for a comprehensive penetration test was no exception. It was necessary to check both the website and the internal network, and even the working Wi-Fi.

It’s no surprise that he was eager to get started even before all the formalities were settled. Just a quick scan of the website — it’s unlikely that such a renowned store as 'Baskerville’s Dog' would allow mistakes at this stage. A couple of days later, Tom finally received the signed original of the contract — by that time, with his third cup of coffee, Tom was keenly evaluating the state of the inventory from the internal CMS...

Tom Hunter's Diary: 'The Hound of the Baskervilles'Source: Ehsan Taebloo

However, he couldn't do much wandering in the CMS as Tom Hunter's IP had been banned by the site's administrators. Although he could have generated some store credits and fed his beloved cat cheaply for months... 'Not this time, Darth Sidious,' Tom thought with a smile. It would have been just as amusing to navigate from the website zone to the client’s local network, but apparently, these segments aren't interconnected at large corporations, which is often the case.

After all the formalities, Tom Hunter armed himself with the provided VPN credentials and headed into the client's local network. The account was within the Active Directory domain, so it was simple to dump the AD — consolidating all publicly available information about users and workstations.

Tom launched the adfind tool and began sending LDAP queries to the domain controller. He applied a filter based on the objectCategory class, specifying 'person' as the attribute. The response came back with the following structure:

dn:CN=Guest,CN=Users,DC=domain,DC=local
>objectClass: top
>objectClass: person
>objectClass: organizationalPerson
>objectClass: user
>cn: Guest
>description: Built-in account for guest access to the computer or domain
>distinguishedName: CN=Guest,CN=Users,DC=domain,DC=local
>instanceType: 4
>whenCreated: 20120228104456.0Z
>whenChanged: 20120228104456.0Z

In addition, there was a lot of useful information, but the most interesting part lay in the field >description: >description. This is a comment on the account — essentially, a convenient place to store insignificant notes. However, the client's administrators thought that passwords could safely reside here too. After all, who would be interested in all these insignificant service accounts? Therefore, the comments that Tom received looked like this:

Created by Administrator, 2018.11.16 7po!*Vqn

You don't need to be exceptionally clever to understand the use of the combination at the end. It was just a matter of parsing a large response file from the KD by the field >description: and there it was — 20 login-password pairs. Moreover, almost half of them had RDP access rights. Not a bad foothold, time to divide the attacking forces.

Network Environment

The available shares of 'The Hound of the Baskervilles' resembled a big city in all its chaos and unpredictability. With user and RDP profiles, Tom Hunter was a poor boy in this city, but even he managed to observe a lot through the shining windows of security policy.

Parts of file servers, accounting accounts, and even related scripts — all of this was publicly accessible. In the settings of one such script, Tom found the MS SQL hash of a user. A little brute-force magic, and the user's hash turned into plain text password. Thanks to John The Ripper and Hashcat.

Tom Hunter's Diary: 'The Hound of the Baskervilles'

This key had to fit some kind of chest. The chest was found, and moreover — it was linked to ten more 'chests'. Inside six of them lay... superuser rights, nt authority system! On two, it was possible to run the stored procedure xp_cmdshell and send cmd commands in Windows. What else could one wish for?

Domain Controllers

Tom Hunter prepared his second strike for the domain controllers. In the network of 'The Hound of the Baskervilles,' there were three — corresponding to the number of geographically remote servers. Each domain controller has a public folder, like an open display in a store, where the same poor boy Tom hangs around.

And this time the boy was lucky again — they forgot to remove the script from the display, where the local server admin's password was hardcoded. Thus, the way to the domain controller was open. Come in, Tom!

Here, from the magical hat was pulled out mimikatz, which was fed by several domain administrators. Tom Hunter accessed all machines on the local network, and a devilish laugh startled the cat from the neighboring chair. This path was shorter than expected.

EternalBlue

The memory of WannaCry and Petya still lingers in the minds of pentesters, but some admins seem to have forgotten about ransomware amidst the stream of other evening news. Tom discovered three nodes vulnerable in the SMB protocol—CVE-2017-0144 or EternalBlue. This is the very vulnerability that allowed WannaCry and Petya ransomware to spread, a vulnerability that enables arbitrary code execution on a node. One of the vulnerable nodes had a domain admin session—'exploit and gain.' What can you do, time hasn’t taught everyone.

Tom Hunter's Diary: 'The Hound of the Baskervilles'

The Hound of the Baskervilles

Information security classics often repeat that the weakest link in any system is the human. Did you notice that the header above doesn’t match the store name? Perhaps not everyone is that attentive.

In the best traditions of phishing blockbusters, Tom Hunter registered a domain that differed by just one letter from the domain of 'The Hound of the Baskervilles.' The email address on this domain mimicked the information security service’s address of the store. Over 4 days, between 4:00 PM and 5:00 PM, an email like this was sent uniformly to 360 addresses from the fake address:

Tom Hunter's Diary: 'The Hound of the Baskervilles'

Perhaps only the employees’ own laziness saved them from a massive password leak. Of the 360 emails, only 61 were opened—security isn’t very popular. But it got easier from there.

Tom Hunter's Diary: 'The Hound of the Baskervilles'
Phishing Page

46 people clicked the link, and nearly half—21 employees—didn’t look at the address bar and calmly entered their usernames and passwords. A good catch, Tom.

Tom Hunter's Diary: 'The Hound of the Baskervilles'

Wi-Fi Network

Now there was no hope of the cat's assistance. Tom Hunter tossed a few gadgets into his old sedan and headed to the office of 'The Hound of the Baskervilles.' His visit wasn’t scheduled: Tom planned to test the client's Wi-Fi. Several free spots were found in the business center's parking lot, conveniently positioned within the target network's perimeter. Clearly, no one had particularly thought about its limitation—it was as if the administrators were randomly throwing in additional access points in response to any complaint about weak Wi-Fi.

How does WPA/WPA2 PSK protection work? Encryption between the access point and clients is ensured by the Pairwise Transient Key (PTK). PTK uses the Pre-Shared Key and five other parameters — SSID, Authenticator Nounce (ANounce), Supplicant Nounce (SNounce), and the MAC addresses of the access point and client. Tom intercepted all five parameters, and now he was only missing the Pre-Shared Key.

Tom Hunter's Diary: 'The Hound of the Baskervilles'

The Hashcat utility cracked this missing link in about 50 minutes — and our hero found himself on the guest network. From there, he could already see the work network — surprisingly, Tom managed to handle the password in just nine minutes. And all this without leaving the parking lot, without any VPNs. The work network opened up a vast landscape for monstrous activities, but he
 never added bonuses to the store card.

Tom paused, glanced at his watch, tossed a few bills on the table, and, bidding farewell, left the café. Maybe it was time for another pentest, or perhaps he had something else in mind... Telegram Channel I thought about writing...


Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers đŸ”„ Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster