Blackfield
Blackfield
Blackfield 255
Blackfield
RETIRED MACHINE

Blackfield

Blackfield - Windows Windows
Blackfield - Hard Hard

4.9

MACHINE RATING

6105

USER OWNS

5609

SYSTEM OWNS

06/06/2020

RELEASED
Created by aas

Machine Synopsis

Backfield is a hard difficulty Windows machine featuring Windows and Active Directory misconfigurations. Anonymous / Guest access to an SMB share is used to enumerate users. Once user is found to have Kerberos pre-authentication disabled, which allows us to conduct an ASREPRoasting attack. This allows us to retrieve a hash of the encrypted material contained in the AS-REP, which can be subjected to an offline brute force attack in order to recover the plaintext password. With this user we can access an SMB share containing forensics artefacts, including an lsass process dump. This contains a username and a password for a user with WinRM privileges, who is also a member of the Backup Operators group. The privileges conferred by this privileged group are used to dump the Active Directory database, and retrieve the hash of the primary domain administrator.

Machine Matrix

Ready to start your
hacking journey?