Mantis | Hack The Box Walkthrough | OSCP Style
In enterprise environments, a single overlooked legacy vulnerability can render complex defense-in-depth strategies completely useless…
In enterprise environments, a single overlooked legacy vulnerability can render complex defense-in-depth strategies completely useless. While initial footholds often stem from poor operational hygiene (like leaving credentials in web directories) the pivot to Domain Admin can sometimes be achieved in a single stroke if the infrastructure is missing critical patches. In this writeup, we will walk through the compromise of the Mantis machine. We will cover port enumeration, decoding layered obfuscation, and finally, exploiting the infamous MS14–068 (Kerberos PAC Validation) vulnerability to instantly escalate from a standard domain user to Domain Admin.
Let’s break down the attack path.
Reconnaissance a
As always, we begin by mapping the external attack surface with a comprehensive TCP port scan against the target IP.
sudo nmap -p- --open -sS -sV -sC --min-rate 5000 -vvv -n 10.10.10.52 -oN result.txt

The Nmap scan reveals a typical Windows Server footprint with RPC, SMB, and Kerberos exposed. However, it also highlights non-standard web services running, specifically on port 1337.
To map the web application structure, we run a directory brute-force attack using gobuster with a standard medium-sized wordlist.
gobuster dir -u http://10.10.10.52:1337/ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -t 60


Navigating through the discovered web directories, we eventually uncover hidden text files stored on the server. Developers and system administrators often use these obscure web ports to host backup scripts, notes, or internal wikis, which are goldmines for initial access.
One of these files contains a suspicious string: NmQyNDI0NzE2YzVmNTM0MDVmNTA0MDczNzM1NzMwNzI2NDIx.
Decoding the Credential Payload
At first glance, the string appears to be Base64 encoded due to its character set and length. However, encoding is not encryption. We can reverse this obfuscation directly from our terminal.

We pipe the string into base64 -d. The output is not immediate plaintext; instead, it yields a hexadecimal string. To translate this hex string into readable ASCII, we pipe the output further into xxd -ps -r.
echo "NmQyNDI0NzE2YzVmNTM0MDVmNTA0MDczNzM1NzMwNzI2NDIx" | base64 -d | xxd -ps -r; echo


The decoded output reveals what appears to be a highly complex password: J@m3s_P@ssW0rd!.
We immediately validate these credentials against the target’s SMB service using crackmapexec, guessing that the username might be james based on the password format.
crackmapexec smb 10.10.10.52 -u 'james' -p 'J@m3s_P@ssW0rd!'

The authentication is successful. We now have a valid foothold within the Active Directory domain htb.local.
Active Directory Enumeration
With a valid domain account, our next priority is to map the Active Directory environment to identify privilege escalation vectors. We extract the domain information using ldapdomaindump.
ldapdomaindump -u 'htb.local\james' -p 'J@m3s_P@ssW0rd!' 10.10.10.52


To get a visual representation of attack paths, we ingest the domain data into BloodHound using the Python ingestor:
bloodhound-python -c all -u 'James' -p 'J@m3s_P@ssW0rd!' -ns 10.10.10.52 -d htb.local

While BloodHound is excellent for finding complex ACL abuse chains, analyzing the operating system version and patching level of the Domain Controller reveals a much more direct route. The machine is vulnerable to MS14–068.
Exploiting MS14–068 (Kerberos PAC Validation)
MS14–068 (CVE-2014–6324) is a critical vulnerability in the Key Distribution Center (KDC) of Windows Server.
Under normal Kerberos operations, when a user requests a Ticket Granting Ticket (TGT), the KDC includes a Privilege Attribute Certificate (PAC) inside the ticket. The PAC contains the user’s group memberships (e.g., Domain Users) and is signed by the KDC so the user cannot tamper with it.
However, MS14–068 arises from a flaw in how the KDC validates this PAC signature. An attacker with any valid domain credentials can forge a custom PAC, inject high-privileged RIDs (like 512 for Domain Admins), sign it with an MD5 hash (without needing the KDC's secret key), and present it to the KDC. The vulnerable KDC improperly accepts the MD5 signature and issues a valid Ticket Granting Service (TGS) ticket carrying the forged Domain Admin privileges.
We exploit this using Impacket’s goldenPac.py, which automates the PAC forgery and uses PsExec to grant us a SYSTEM shell.
impacket-goldenPac htb.local/james@mantis

The exploit executes flawlessly, requesting the forged ticket, authenticating to the ADMIN$ share, and dropping us into an interactive shell as NT AUTHORITY\SYSTEM.
Conclusion
Mantis highlights a terrifying reality in enterprise networks: sophisticated perimeter defenses and complex Active Directory ACLs mean nothing if core cryptographic vulnerabilities are left unpatched. The initial foothold required basic OSINT and cryptography knowledge, but the escalation path was a straightforward execution of one of the most critical Windows vulnerabilities in history.
From a Red Team and defensive perspective:
Key Takeaways:
- Security by Obscurity Fails: Hosting “secret” files on high ports (like 1337) and encoding passwords in Base64/Hex does not protect data. It merely slows down an attacker by a few seconds. Treat all exposed web directories as public domain and use secure credential vaults.
- Patching is Non-Negotiable: MS14–068 was patched over a decade ago. Finding this in a modern environment indicates a systemic failure in patch management and vulnerability scanning. Domain Controllers must be prioritized for all security updates.
- Detecting MS14–068 Anomalies: Exploiting
goldenPac.pyleaves a massive forensic footprint. Defenders should monitor SIEM logs for Event ID 4769 (A Kerberos service ticket was requested) where the user is a standard account, but the access rights simulate a Domain Admin. Furthermore,goldenPac.pyuses Impacket's default PsExec behavior, creating highly detectable anomalous services and writing binaries to theADMIN$share. - PAC Signature Monitoring: Modern EDR and identity protection solutions can detect invalid or weak cryptographic signatures (like MD5) on Kerberos PACs, stopping forged tickets before they can be used to pivot.
If you’re interested in following my upcoming articles on OT/ICS, certifications, HTB content, and Red Team experiences, I invite you to connect with me on LinkedIn or Instagram.