Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

"Relaying hashes from SQL" exercise isn't finished #2

Closed
7MinSec opened this issue Apr 25, 2023 · 4 comments
Closed

"Relaying hashes from SQL" exercise isn't finished #2

7MinSec opened this issue Apr 25, 2023 · 4 comments

Comments

@7MinSec
Copy link
Owner

7MinSec commented Apr 25, 2023

The curriculum itself needs to be written, and I can't seem to get Inveigh relay to work even if I follow guides like this one or this one.

Our pal Jeff McJunkin recommends trying out PortBender.

@jeffmcjunkin
Copy link

Apparently https://github.com/CCob/lsarelayx is even easier, as it's a standalone executable and doesn't need a "real" C2 like Cobalt Strike to run it.

@7MinSec
Copy link
Owner Author

7MinSec commented Apr 25, 2023

The lsarelayx looks awesome but it also seems like it has to be used in combo with ntlmrelayx - and I don't know if ntlmrelayx plays nice in Windows. I'll have to try that.

@7MinSec
Copy link
Owner Author

7MinSec commented Apr 25, 2023

As an alternative, this standalone version of impacket binaries looked promising (https://github.com/ropnop/impacket_static_binaries) but I hit some issues at runtime (ropnop/impacket_static_binaries#8).

Thinking out loud, I could have the dbadmin account have a slightly more crackable password and have folks get DA that way, but I'd REALLY like to PTH as that's more fun since students will have already done a few cracking exercises by the time they get to this point.

@7MinSec
Copy link
Owner Author

7MinSec commented Apr 27, 2023

The section "relaying hashes from SQL" is now fully baked - both from a testing it out in real time perspective, as well as a curriculum perspective!

@7MinSec 7MinSec closed this as completed Apr 27, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants