{"id":2215,"date":"2019-10-31T14:24:33","date_gmt":"2019-10-31T13:24:33","guid":{"rendered":"http:\/\/labalec.fr\/erwan\/?p=2215"},"modified":"2019-10-31T21:29:09","modified_gmt":"2019-10-31T20:29:09","slug":"demonstrating-lateral-movement-with-nthash-part-9","status":"publish","type":"post","link":"https:\/\/labalec.fr\/erwan\/?p=2215","title":{"rendered":"Demonstrating lateral movement with NTHASH Part #9"},"content":{"rendered":"<p>This is the 9th and last article of a series of <a href=\"https:\/\/labalec.fr\/erwan\/?s=nthash&#038;searchsubmit=\" rel=\"noopener\" target=\"_blank\">articles <\/a>around performing lateral movement.<\/p>\n<p>Goal is still about performing a task as another user but without knowing that user password.<\/p>\n<p>This time, lets take a look at \u00ab\u00a0<a href=\"https:\/\/en.wikipedia.org\/wiki\/HTTP_cookie\" rel=\"noopener\" target=\"_blank\">cookies<\/a>\u00ab\u00a0.<br \/>\nQuoting Wikipedia : <em>\u00ab\u00a0&#8230;is a small piece of data sent from a website and stored on the user&rsquo;s computer by the user&rsquo;s web browser while the user is browsing&#8230;\u00a0\u00bb<\/em>.<\/p>\n<p>1.Based on previous articles, lets consider you have acquired a context\/shell running as another user.<\/p>\n<p>2.Retrieve the chrome cookie you are after with <strong>NTHASH-win64.exe \/ccookies | findstr \/i facebook.com<\/strong> or the firefox cookie you are after with <strong>NTHASH-win64.exe \/fcookies | findstr \/i facebook.com<\/strong><\/p>\n<p>3.Launch a chrome with a new\/blank profile (in your session) : <strong>\u00ab\u00a0C:\\Program File<br \/>\ns (x86)\\Google\\Chrome\\Application\\chrome\u00a0\u00bb &#8211;profile-directory=\u00a0\u00bbtemp\u00a0\u00bb<\/strong><\/p>\n<p>4.Install a \u00ab\u00a0cookie\u00a0\u00bb chrome extension like <a href=\"https:\/\/chrome.google.com\/webstore\/detail\/editthiscookie\/fngmhnnpilhplaeedifhccceomclgfbg\" rel=\"noopener\" target=\"_blank\">EditThisCookie<\/a><\/p>\n<p>5.Inject the cookie:<br \/>\n-in facebook case, you need to inject value xs and c_user<br \/>\n-in twitter case, you need to inject auth_token<\/p>\n<p>And here you go, you can log into a web service, as another user, without knowing his credentials.<\/p>\n<p>Note that this method may not be 100% bullet proof :<br \/>\n-you need to know which value(s) you need to inject<br \/>\n-some web services may perform extra checks<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This is the 9th and last article of a series of articles around performing lateral movement. Goal is still about performing a task as another user but without knowing that user password. This time, lets take a look at \u00ab\u00a0cookies\u00ab\u00a0. Quoting Wikipedia : \u00ab\u00a0&#8230;is a small piece of data sent from a website and stored <a href='https:\/\/labalec.fr\/erwan\/?p=2215' class='excerpt-more'>[&#8230;]<\/a><\/p>\n","protected":false},"author":7,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[118],"tags":[],"class_list":["post-2215","post","type-post","status-publish","format-standard","hentry","category-nthash","category-118-id","post-seq-1","post-parity-odd","meta-position-corners","fix"],"_links":{"self":[{"href":"https:\/\/labalec.fr\/erwan\/index.php?rest_route=\/wp\/v2\/posts\/2215","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/labalec.fr\/erwan\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/labalec.fr\/erwan\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/labalec.fr\/erwan\/index.php?rest_route=\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/labalec.fr\/erwan\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2215"}],"version-history":[{"count":7,"href":"https:\/\/labalec.fr\/erwan\/index.php?rest_route=\/wp\/v2\/posts\/2215\/revisions"}],"predecessor-version":[{"id":2225,"href":"https:\/\/labalec.fr\/erwan\/index.php?rest_route=\/wp\/v2\/posts\/2215\/revisions\/2225"}],"wp:attachment":[{"href":"https:\/\/labalec.fr\/erwan\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2215"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/labalec.fr\/erwan\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2215"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/labalec.fr\/erwan\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2215"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}