LustrousTwo
LustrousTwo
LustrousTwo 688
LustrousTwo
RETIRED MACHINE

LustrousTwo

LustrousTwo - Windows Windows
LustrousTwo - Hard Hard

5

MACHINE RATING

34

USER OWNS

31

SYSTEM OWNS

31/07/2025

RELEASED
Created by xct

Machine Synopsis

LustrousTwo is a hard-rated Windows box that deals with LDAP signing, channel binding, and disabled NTLM authentication. The box has a web server vulnerable to arbitrary file read, which helps attackers capture a `Net-NTLMv2` hash for the service account, using it to request Service Tickets via `s4u2self`, a stealthier alternative to Silver Ticket, to bypass protective measures like `Account is sensitive and cannot be delegated`. After reversing and auditing the source code, the attacker achieves Remote Code Execution. For privilege escalation, the attacker exploits a misconfigured, insecure [Velociraptor](https://github.com/Velocidex/velociraptor) installation.

Machine Matrix

Ready to start your
hacking journey?