Active | Hack The Box Walkthrough | OSCP Style
Exploiting a Group Policy Preferences password leak and Kerberoasting to fully compromise a Windows domain controller.
Exploiting a Group Policy Preferences password leak and Kerberoasting to fully compromise a Windows domain controller.
Active is a realistic Active Directory machine on Hack The Box that mirrors two issues you will genuinely run into on real engagements. First, we recover a service-account password from a Group Policy Preferences (GPP) file left readable on a share. Then we use that low-privileged account to perform a Kerberoasting attack, crack the Administrator’s service ticket offline, and take full control of the domain controller. No memory-corruption exploits here: just misconfigurations and protocol abuse, exactly the kind of thing that compromises real domains.
Reconnaissance
As always, we begin by mapping the attack surface with a full TCP scan that fingerprints services and runs the default NSE scripts:
nmap -sC -sV -p- --open 10.10.10.100 -oN nmap_full.txt

The fingerprint is unmistakably a domain controller: Kerberos, LDAP, DNS, and SMB are all present, and the domain active.htb shows up in the output. Whenever SMB is exposed on a DC, enumerating its shares is the natural first move.
SMB Enumeration
We list the available shares and our access level with smbmap:
smbmap -H 10.10.10.100

The Replication share stands out: it is readable without credentials. We connect to it using a null session (the -N flag tells smbclient to authenticate with no password):
smbclient //10.10.10.100/Replication -N

Inside, we find a directory named active.htb. To pull everything down recursively without being prompted for each file, we disable interactive prompting and enable recursion before grabbing the lot:
prompt off
recurse on
mget *

Reviewing the directory structure locally with tree helps us spot anything interesting:
tree

GPP Password Leak
The file that matters is Groups.xml. Reading it reveals a Group Policy Preferences entry for the account SVC_TGS, including a cpassword attribute:
cat .../Groups.xml
userName="active.htb\SVC_TGS"
cpassword="edBSHOwhZLTjt/QS9FeIcJ83mjWA98gw9guKOhJOdcqh+ZGMeXOsQbCpZ3xUjTLfCuNH8pG5aSVYdYw/NglVmQ"
This is a textbook Windows Server 2008 misconfiguration. Every time an administrator created a Group Policy Preference, Windows also wrote an XML file to
SYSVOLcontaining the password. Here we never even touchedSYSVOLdirectly: Replication is simply a copy of it. Microsoft encrypted thecpasswordwith AES, but the static AES key was published in their own documentation, so anyone can decrypt it.

Because the key is public, Kali ships a tool (gpp-decrypt) that decrypts these values instantly:
gpp-decrypt edBSHOwhZLTjt/QS9FeIcJ83mjWA98gw9guKOhJOdcqh+ZGMeXOsQbCpZ3xUjTLfCuNH8pG5aSVYdYw/NglVmQ

We now hold valid domain credentials for SVC_TGS.
Validating the Credentials
Before going further, we confirm the credentials are valid over SMB with CrackMapExec:
crackmapexec smb 10.10.10.100 -u 'SVC_TGS' -p 'GPPstillStandingStrong2k18'

The credentials work, but the account is not a local administrator (there is no (Pwn3d!) marker) so we can't simply run commands on the host yet. Trying to land a shell with psexec confirms it:

Capturing the User Flag
Even without admin rights, our authenticated session lets us browse the Users share:
smbclient //10.10.10.100/Users -U active.htb\\SVC_TGS

Navigating to the user’s Desktop, we find and download the user flag:
get user.txt


Privilege Escalation
To go from a low-privileged domain user to full domain compromise, we abuse Kerberos itself through a Kerberoasting attack. The idea is simple but powerful: any authenticated domain user can request a service ticket (TGS) for any account that has a Service Principal Name (SPN). That ticket is encrypted with the target service account’s password hash, so we can request it, take it offline, and crack it without ever touching the account directly.
Using Impacket’s GetUserSPNs.py, we first enumerate which accounts have SPNs:
python3 GetUserSPNs.py active.htb/SVC_TGS -dc-ip 10.10.10.100

The Administrator account has an SPN, which makes it a prime target. We re-run the tool with -request to actually pull down its TGS hash:
python3 GetUserSPNs.py active.htb/SVC_TGS -dc-ip 10.10.10.100 -request

We crack the ticket with Hashcat. Kerberos 5 TGS-REP tickets use mode 13100, and we run it against rockyou.txt:
hashcat -m 13100 hash.txt /usr/share/wordlists/rockyou.txt


Domain Compromise
With the Administrator’s password in hand, we use Impacket’s psexec.py to obtain an interactive SYSTEM shell on the domain controller and grab the root flag:
python3 psexec.py active.htb/Administrator@10.10.10.100


Conclusion
Active is a fantastic introduction to real-world Active Directory attacks because nothing here relies on a memory-corruption exploit. It’s all misconfiguration and protocol abuse. We recovered a service-account password from a Group Policy Preferences file that should never have been readable, then leveraged a fundamental property of Kerberos to crack the Administrator’s ticket offline and seize the entire domain.
Key takeaways:
- GPP
cpasswordvalues are trivially decryptable: the AES key has been public for years. Never store passwords in Group Policy Preferences. - Anonymous/null-session access to SMB shares leaks far more than people expect.
- Any account with an SPN is kerberoastable; service accounts should use long, random passwords (or gMSA).
- A non-admin domain foothold is often all an attacker needs to reach Domain Admin.
References
- Group Policy Preferences (Microsoft Docs)
- [MS-GPPREF]: Password Encryption
- GetUserSPNs.py: The Hacker Recipes
If you’re interested in following my upcoming articles on OT/ICS, certifications, HTB content, and Red Team experiences, I invite you to connect with me on LinkedIn or Instagram.