Hey friends! Welcome back to another Tales of Pentest Pwnage — my favorite mini-series where I share the good, the bad, and the "why didn't I check THAT first?!" moments from real-world engagements. Today's story has a little bit of everything: a legit path to domain admin, some late-night rabbit holes, a lesson in humility, and a villain you've definitely met before. (Spoiler: it's DNS.)
A couple of quick plugs before we dive in:
Private GOAD training is going strong! — We just wrapped a 3-day private session (7 students — that's max capacity!) of our Active Directory pentesting class built on the Game of Active Directory (GOAD) framework. Over three days, students enumerate, attack, and fully pwn three separate AD environments. The private format is just *chef's kiss* — when it's a team from the same company, the conversation gets real fast. Like, "hey I just checked Bloodhound on break and Bob from accounting has full rights over the DC" real. If you want to send 3–7 people from your org, hit up 7MinSec.com/training to line up a private session.
Support the show over at 7MinSec.club — That's our Substack, where every Tuesday I drop a short TuesdayTOOLSday video about security tools. Free subscriptions are welcome and mean a lot — you'll just get pinged when new content drops. No spam, no blindly-sent Outlook calendar invites. I promise.
Pentest tips and scripts live at 7MinSec.wiki — I reference it throughout today's episode, including some step-by-step guidance on the techniques we'll talk about below.
Now — onto the pwnage. Fair warning: I've been burning the candle at three ends lately trying to catch up after a tough few weeks of grief (if you want the backstory, the last couple episodes cover my dad passing away). The good news is my head is semi back on straight and I put it to work on a recurring client environment — one that keeps getting better year over year. Machine account quota locked down? Check. No Kerberoastable or AS-REP roastable users? Check. No local admin rights, no web client running? Check and check. All good signs. And then PingCastle smiled right into my eyeballs with a big red finding:
The DC's LAN Manager authentication level was weak enough to coerce and capture a downgraded hash — Specifically, an NTLMv1 SSP hash. Using Coercer to nudge the DC into authenticating to my Kali box (with Responder running), I captured the goods. Pretty little hashes all in a row.
Cracking that hash: enter Vast.ai — The old go-to for this type of crack used to be crack.sh, but their cracker has been offline for years. What they do still have is a walkthrough pointing to a tool from EvilMog on GitHub that helps you prep the raw hash material and figure out exactly how to crack it with Hashcat. For the GPU horsepower, I rented a beefy multi-GPU instance on Vast.ai — filter for 16+ GPUs, pick a Hashcat Docker image, and SSH in. The whole crack job took about 16 hours at ~$4/hr. Do the math: $64 to reconstruct the DC's NTLM hash. Worth it.
Tmux sidebar — seriously just learn it — Vast.ai is actually what finally got me into tmux, because the Hashcat Docker container drops you right into a tmux session. This is clutch: you can kick off a 16-hour crack job, detach, and reattach later without killing anything. On a pentest, my workflow now is SSH in → tmux → name a few session windows for Responder, Exegol, packet captures, etc. I used to fumble around with Linux screen sessions. Not anymore!
From hash to DA — the usual playbook — Once you've got the DC's NTLM hash, you can request a Kerberos ticket and load it up, then run a DCSync to pull the KRBTGT hash. From there it's god mode: dump hashes, pass-the-hash as domain admins, and you have yourself a cool privesc POC. Except this time…the POC didn't work.
The part where I Jean-Claude Van Damme helicopter kick myself in the face — DCSync failed immediately. Like, suspiciously fast — barely two lines of output and done. I tried every version of every tool I could get my hands on. I tried Windows, I tried Linux. I even asked the client to check if their endpoint protection was blocking me (it wasn't). I touched grass. I played guitar. I played some Splinter Cell Blacklist (old game, highly recommend if you like the Hitman-style vibes). Came back fresh. Rebooted both VMs. Still nothing.
It was DNS. It's always DNS. — The thing that finally caught my eye: the commands were failing too fast. Like it wasn't even reaching the DC. I catted the resolv.conf inside my Exegol instance (heads up: Exegol has its own resolv.conf and hosts file, separate from your base Kali system!) and found a stale DNS entry pointing to an old DC that was no longer serving anything. Nuked the bad entry, added static hosts file entries for the live DC, ran the command again, and — hash rain. Pennies from heaven. It was midnight and I literally pushed back from my desk like a baby pushing away from a high chair going "Baby Brian is all done!"
The lesson: — I know the meme. "It's always DNS." I just personally hadn't hit it hard in my security life since my sysadmin days back before 2013. Now I have. So going forward I'll check DNS first (and often).
Vacation attempt #3 incoming… pray for me — My wife nearly died in Punta Cana earlier this year. Then our summer cabin trip was cold and rainy with zero water time. And now we've got families flying in from multiple states for a lake weekend — except we just found out our reservation through Booking.com was basically vaporized because the resort changed hands and never updated their website. My wife (who is an absolute saint and my better three-quarters) almost had a 360-degree head spin (like in The Exorcist) talking to customer service. But we scrambled, found a last-minute place, and I'm choosing to believe it's not in Jason Voorhees' back yard.
Could this be my last episode? Maybe. But hey — it was a good one. Talk to you next week (hopefully).
Podden och tillhörande omslagsbild på den här sidan tillhör
Brian Johnson. Innehållet i podden är skapat av Brian Johnson och inte av,
eller tillsammans med, Poddtoppen.