All writeupsField notes / Hack The Box

HTB PingPong

The investigation

Insane Windows AD machine with bidirectional domain trust. ADCS ESC13, cross-domain gMSA abuse, JEA, RBCD, ESC4 and DCSync.

Overview

PingPong is an Insane-difficulty Windows Active Directory machine featuring multiple advanced exploitation techniques across a bidirectional domain trust. This machine teaches:

  • Active Directory Certificate Services (ADCS) attacks
  • ESC13 (Group Enrollment) exploitation
  • Cross-domain trust abuse
  • gMSA (Group Managed Service Accounts) attacks
  • JEA (Just Enough Administration) abuse
  • Resource-Based Constrained Delegation (RBCD)
  • ESC4 template attacks
  • DCSync attacks

Network Topology

PING.HTB Domain (10.129.x.x/24)
├── DC1.ping.htb (Domain Controller)
└── Bidirectional Trust with PONG.HTB

PONG.HTB Domain (192.168.2.0/24)
└── DC2.pong.htb (Domain Controller)

Enumeration

Initial Access

You are provided with initial credentials:

  • Username: c.roberts
  • Password: AssumedBreach123
  • Domain: PING.HTB

Port Scanning

Standard AD ports are open:

  • 88/tcp - Kerberos
  • 389/tcp - LDAP
  • 445/tcp - SMB
  • 5985/tcp - WinRM
  • And more...

Certificate Services Enumeration

The domain has Active Directory Certificate Services (ADCS) installed. Look for:

  • Certificate templates
  • Enrollment permissions
  • Template vulnerabilities
  • CA configuration

Initial Foothold (ESC13)

Understanding ESC13

ESC13 is an ADCS attack where:

  1. A certificate template allows enrollment based on group membership
  2. The group is linked to the template
  3. Users can add themselves to the group
  4. Enrollment grants additional privileges

Exploitation Path

  1. Enumerate certificate templates
  2. Find vulnerable ESC13 template
  3. Enroll and obtain certificate
  4. Use certificate for authentication
  5. Gain access to restricted services

Initial Goal: WinRM access to DC1

Cross-Domain Privilege Escalation

Trust Relationship

The PING domain has a bidirectional trust with PONG domain. This means:

  • Users from PING can access resources in PONG
  • Users from PONG can access resources in PING

gMSA Abuse

Group Managed Service Accounts (gMSA) are special accounts where:

  • Passwords are managed by Active Directory
  • Multiple computers can use the same account
  • Passwords rotate automatically

Key Concept: If you control the group that manages a gMSA, you can dump its password.

Attack Chain Overview

1. ESC13 → WinRM on DC1
2. Modify PONG domain group
3. Dump gMSA password
4. Use gMSA for JEA access
5. Extract credentials
6. RBCD attack
7. DCSync PONG domain
8. ESC4 template modification
9. Request Administrator certificate
10. Root access

Key Challenges

Cross-Domain Operations

Working across trust boundaries requires:

  • Proper Kerberos ticket handling
  • Understanding SID filtering
  • Cross-domain group modifications
  • Time synchronization

JEA (Just Enough Administration)

JEA endpoints provide restricted PowerShell access. You'll need to:

  • Identify available JEA endpoints
  • Understand configured commands
  • Extract sensitive data from restricted environment

RBCD Attack

Resource-Based Constrained Delegation allows:

  • Delegation configuration on the target object
  • Impersonating users to access resources
  • Privilege escalation when combined with other attacks

Tools Required

  • netexec (crackmapexec)
  • certipy-ad
  • impacket suite
  • bloodyAD
  • evil-winrm
  • PowerShell AD cmdlets
  • Custom exploitation scripts

Difficulty Factors

What makes this Insane:

  1. Multiple exploitation chains
  2. Cross-domain attacks
  3. Advanced ADCS knowledge
  4. Time-sensitive operations
  5. Complex trust relationships
  6. Multiple technologies combined

Continue the investigation

The complete field notes.

Every command, the full exploitation chain, and all scripts used in this investigation are available to members on Buy Me a Coffee.

Get the full writeup €5 one-off · or monthly membership
End of field noteBack to the archive