<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>NTLM Relay on 633k</title>
    <link>https://633k.org/tags/ntlm-relay/</link>
    <description>Recent content in NTLM Relay on 633k</description>
    <generator>Hugo</generator>
    <language>zh-CN</language>
    <lastBuildDate>Fri, 28 Aug 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://633k.org/tags/ntlm-relay/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Pirate（HTB Hard）</title>
      <link>https://633k.org/posts/pirate/</link>
      <pubDate>Fri, 28 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://633k.org/posts/pirate/</guid>
      <description>&lt;hr&gt;
&lt;h2 id=&#34;执行摘要&#34;&gt;执行摘要&lt;/h2&gt;
&lt;p&gt;Pirate 是 Active Directory 域环境。入口为低权限域用户 &lt;code&gt;pentest&lt;/code&gt;。通过 Pre-Windows 2000 计算机账户默认密码读取 gMSA，WinRM 立足 DC01 后进入仅内网的 WEB01。WEB01 的 LSA 泄露 &lt;code&gt;a.white&lt;/code&gt; 明文，该用户可强制重置 &lt;code&gt;a.white_adm&lt;/code&gt;。&lt;code&gt;a.white_adm&lt;/code&gt; 拥有到 &lt;code&gt;HTTP/WEB01&lt;/code&gt; 的约束委派（协议转换）以及 IT 组的 WriteSPN。将 &lt;code&gt;HTTP/WEB01.pirate.htb&lt;/code&gt; 劫持到 DC01$ 后，S4U2Proxy 票可改写成 &lt;code&gt;CIFS/DC01&lt;/code&gt;，最终拿到域管。&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
