Checkpoint HackTheBox Writeup - Season11
SUMMARY
This write-up covers the Checkpoint machine from HackTheBox Season 11. Starting from provided credentials for alex.turner, bloodyAD enumeration of writable objects uncovered a deleted account inside Deleted Objects, over which alex held write permissions. The object was restored and BloodHound (collected via Kerberos due to LDAPS enforcement) confirmed a GenericWrite edge from alex to mark. Credential reuse unlocked the account without additional exploitation, and SMB enumeration revealed mark had write access to a DevDrop share described as a VS Code extension drop zone for .vsix packages targeting engine version 1.118.0. A malicious extension embedding a PowerShell reverse shell was packaged with vsce, uploaded to the share, and after a brief wait it was picked up by an automated process, delivering a shell as ryan.brooks.
BloodHound analysis of ryan’s position showed GenericWrite over the service account svc_deploy, paired with CreateChild rights on the OU=DMSAHolder container, the exact combination required for a BadSuccessor attack. A delegated Managed Service Account (dMSA) was created inside that OU and linked to svc_deploy as its superseded target. Because the DC ran a patched build (≥ 26100.4946), the msDS-Superseded* attributes had to be written on svc_deploy itself, which ryan’s GenericWrite satisfied. The KDC treated the migration as legitimate and returned svc_deploy’s Kerberos keys, exposing the account’s NT hash, which was then used to open a WinRM session.
As svc_deploy, a previously inaccessible VMBackups SMB share became readable, containing nightly VMDK snapshots of the domain controller itself. The backup was mounted locally via qemu-nbd, and the underlying NTFS partition was attached read-only. With direct filesystem access to C:\, the SAM, SYSTEM, and SECURITY hive files were extracted and fed to impacket-secretsdump. The recovered Administrator hash was still valid against the live target, completing the box with a Administrator shell via evil-winrm.
PATH TO FOLLOW
- Reconnaissance
- BloodyAD Enumeration
- Discovery and Restore Deleted Objects
- BloodHound Collection
- Password Reuse - Access as mark.davies
- SMB Enumeration - DevDrop Share Write Access
- Malicious .vsix Extension - PowerShell Reverse Shell
- Shell as ryan.brooks
- GenericWrite on svc_deploy + CreateChild on DMSAHolder
- Rubeus TGT Delegation → ccache Export
- BadSuccessor - dMSA Creation and svc_deploy Supersession
- NT Hash Recovery → WinRM as svc_deploy
- VMBackups Share - VMDK Snapshot Access
- qemu-nbd Mount + NTFS Partition Identification
- SAM / SYSTEM / SECURITY Extraction via secretsdump
- Shell as Administrator
CONTENT WILL BE RELEASED ONCE THE MACHINE IS RETIRED