Skip to content

Commit

Permalink
Update 2024-03-26-DGSSI-CTF-PRO-Italy-Writeup.md
Browse files Browse the repository at this point in the history
  • Loading branch information
BaadMaro authored Mar 27, 2024
1 parent 05fd2fd commit 770ab7a
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion _posts/2024-03-26-DGSSI-CTF-PRO-Italy-Writeup.md
Original file line number Diff line number Diff line change
Expand Up @@ -497,7 +497,7 @@ I didn't keep detailed notes for this part, I'll do a recap for it
![2024-03-25_00h51_50](https://github.com/BaadMaro/baadmaro.github.io/assets/72421091/3c48c7d0-8d1e-4695-ab96-eb4ac93f1762)
- Our user backup is a member of Backup Operators. We can use that to dump SAM and other hives to extract hashes [https://www.bordergate.co.uk/backup-operator-privilege-escalation/](https://www.bordergate.co.uk/backup-operator-privilege-escalation/)
- I was able to get the hives using impacket-reg [https://wadcoms.github.io/wadcoms/Impacket-Reg/](https://wadcoms.github.io/wadcoms/Impacket-Reg/)
- I had issues extracting the hashes from hives using pypykatz. I'm not sure if I tried `impacket-secretsdump`. I was also mixing registry files from `imapcket-reg` and the other ones from SMB share so maybe I got some of them corrupted.
- I had issues extracting the hashes from hives using pypykatz and `impacket-secretsdump`. I was also mixing registry files from `imapcket-reg` and the other ones from SMB share so maybe I got some of them corrupted.
- I wasn't able to get it to work so I stopped here to check other labs in the CTF.

The solution is clear after the finding. We need to get the needed registry hives to extract hashes using our backup account which is a member of Backup Operators.
Expand Down

0 comments on commit 770ab7a

Please sign in to comment.