Mist
Mist
Mist 595
Mist
RETIRED MACHINE

Mist

Mist - Windows Windows
Mist - Insane Insane

4.8

MACHINE RATING

672

USER OWNS

654

SYSTEM OWNS

30/03/2024

RELEASED
Created by Geiseric

Machine Synopsis

Mist is an Insane-difficulty machine that provides a comprehensive scenario for exploiting various misconfigurations and vulnerabilities in an Active Directory (AD) environment. The machine has multiple layers, starting with a public-facing CMS running on Apache with a path traversal vulnerability, allowing us to retrieve a backup file containing hashed credentials. Cracking this hash grants initial access as a low-privileged web user. Exploiting file-write permissions on a shared directory further elevates our access by allowing a reverse shell connection as another domain user. From there, enumeration reveals several AD misconfigurations, including LDAP signing disabled, WebDAV exploitation, and misconfigurations in ADCS templates, each step designed to escalate privileges through different AD entities. The final exploit involves creating shadow credentials to acquire the machine account’s NTLM hash, enabling a `DCSync` attack to obtain the Domain Administrator hash.

Machine Matrix

Ready to start your
hacking journey?