Active | Hack The Box Walkthrough | OSCP Style

Exploiting a Group Policy Preferences password leak and Kerberoasting to fully compromise a Windows domain controller.

Exploiting a Group Policy Preferences password leak and Kerberoasting to fully compromise a Windows domain controller.

Active is a realistic Active Directory machine on Hack The Box that mirrors two issues you will genuinely run into on real engagements. First, we recover a service-account password from a Group Policy Preferences (GPP) file left readable on a share. Then we use that low-privileged account to perform a Kerberoasting attack, crack the Administrator’s service ticket offline, and take full control of the domain controller. No memory-corruption exploits here: just misconfigurations and protocol abuse, exactly the kind of thing that compromises real domains.

Reconnaissance

As always, we begin by mapping the attack surface with a full TCP scan that fingerprints services and runs the default NSE scripts:

nmap -sC -sV -p- --open 10.10.10.100 -oN nmap_full.txt

Figure 1. Full nmap scan exposing the typical Active Directory / domain controller service set.

The fingerprint is unmistakably a domain controller: Kerberos, LDAP, DNS, and SMB are all present, and the domain active.htb shows up in the output. Whenever SMB is exposed on a DC, enumerating its shares is the natural first move.

SMB Enumeration

We list the available shares and our access level with smbmap:

smbmap -H 10.10.10.100

Figure 2. smbmap enumerating the available SMB shares and our access rights.

The Replication share stands out: it is readable without credentials. We connect to it using a null session (the -N flag tells smbclient to authenticate with no password):

smbclient //10.10.10.100/Replication -N

Figure 3. Accessing the Replication share anonymously through a null session.

Inside, we find a directory named active.htb. To pull everything down recursively without being prompted for each file, we disable interactive prompting and enable recursion before grabbing the lot:

prompt off
recurse on
mget *

Figure 4. Recursively downloading the entire active.htb directory with mget.

Reviewing the directory structure locally with tree helps us spot anything interesting:

tree

Figure 5. Inspecting the downloaded directory structure with tree.

GPP Password Leak

The file that matters is Groups.xml. Reading it reveals a Group Policy Preferences entry for the account SVC_TGS, including a cpassword attribute:

cat .../Groups.xml

userName="active.htb\SVC_TGS"
cpassword="edBSHOwhZLTjt/QS9FeIcJ83mjWA98gw9guKOhJOdcqh+ZGMeXOsQbCpZ3xUjTLfCuNH8pG5aSVYdYw/NglVmQ"

This is a textbook Windows Server 2008 misconfiguration. Every time an administrator created a Group Policy Preference, Windows also wrote an XML file to SYSVOL containing the password. Here we never even touched SYSVOL directly: Replication is simply a copy of it. Microsoft encrypted the cpassword with AES, but the static AES key was published in their own documentation, so anyone can decrypt it.

Figure 6. The Groups.xml file exposing the encrypted cpassword for SVC_TGS.

Because the key is public, Kali ships a tool (gpp-decrypt) that decrypts these values instantly:

gpp-decrypt edBSHOwhZLTjt/QS9FeIcJ83mjWA98gw9guKOhJOdcqh+ZGMeXOsQbCpZ3xUjTLfCuNH8pG5aSVYdYw/NglVmQ

Figure 7. gpp-decrypt recovering the cleartext password for SVC_TGS.

We now hold valid domain credentials for SVC_TGS.

Validating the Credentials

Before going further, we confirm the credentials are valid over SMB with CrackMapExec:

crackmapexec smb 10.10.10.100 -u 'SVC_TGS' -p 'GPPstillStandingStrong2k18'

Figure 8. CrackMapExec confirms the SVC_TGS credentials are valid, but without administrative rights.

The credentials work, but the account is not a local administrator (there is no (Pwn3d!) marker) so we can't simply run commands on the host yet. Trying to land a shell with psexec confirms it:

Figure 9. psexec fails: SVC_TGS lacks the privileges needed for code execution.

Capturing the User Flag

Even without admin rights, our authenticated session lets us browse the Users share:

smbclient //10.10.10.100/Users -U active.htb\\SVC_TGS

Figure 10. Authenticating to the Users share as SVC_TGS.

Navigating to the user’s Desktop, we find and download the user flag:

get user.txt

Figure 11. Locating the user flag on the SVC_TGS Desktop.

Figure 12. The user flag retrieved successfully.

Privilege Escalation

To go from a low-privileged domain user to full domain compromise, we abuse Kerberos itself through a Kerberoasting attack. The idea is simple but powerful: any authenticated domain user can request a service ticket (TGS) for any account that has a Service Principal Name (SPN). That ticket is encrypted with the target service account’s password hash, so we can request it, take it offline, and crack it without ever touching the account directly.

Using Impacket’s GetUserSPNs.py, we first enumerate which accounts have SPNs:

python3 GetUserSPNs.py active.htb/SVC_TGS -dc-ip 10.10.10.100

Figure 14. Enumerating Service Principal Names with GetUserSPNs.py: the Administrator account is kerberoastable.

The Administrator account has an SPN, which makes it a prime target. We re-run the tool with -request to actually pull down its TGS hash:

python3 GetUserSPNs.py active.htb/SVC_TGS -dc-ip 10.10.10.100 -request

Figure 15. Requesting the Administrator’s TGS hash for offline cracking.

We crack the ticket with Hashcat. Kerberos 5 TGS-REP tickets use mode 13100, and we run it against rockyou.txt:

hashcat -m 13100 hash.txt /usr/share/wordlists/rockyou.txt

Figure 16. Launching Hashcat against the Administrator’s TGS hash (mode 13100).

Figure 17. Hashcat successfully recovers the Administrator’s cleartext password.

Domain Compromise

With the Administrator’s password in hand, we use Impacket’s psexec.py to obtain an interactive SYSTEM shell on the domain controller and grab the root flag:

python3 psexec.py active.htb/Administrator@10.10.10.100

Figure 18. psexec.py yields a SYSTEM shell on the domain controller as Administrator.

Figure 19. The root flag captured: the domain is fully compromised.

Conclusion

Active is a fantastic introduction to real-world Active Directory attacks because nothing here relies on a memory-corruption exploit. It’s all misconfiguration and protocol abuse. We recovered a service-account password from a Group Policy Preferences file that should never have been readable, then leveraged a fundamental property of Kerberos to crack the Administrator’s ticket offline and seize the entire domain.

Key takeaways:

  • GPP cpassword values are trivially decryptable: the AES key has been public for years. Never store passwords in Group Policy Preferences.
  • Anonymous/null-session access to SMB shares leaks far more than people expect.
  • Any account with an SPN is kerberoastable; service accounts should use long, random passwords (or gMSA).
  • A non-admin domain foothold is often all an attacker needs to reach Domain Admin.

References

If you’re interested in following my upcoming articles on OT/ICS, certifications, HTB content, and Red Team experiences, I invite you to connect with me on LinkedIn or Instagram.