
HackTheBox - Vintage
Source: YouTube · IppSec · published Apr 26, 2025 · 1:19:30
The video demonstrates a complex Active Directory attack path on a Hack The Box machine where NLM authentication is disabled, requiring specific Kerberos techniques to bypass defenses and achieve privilege escalation.
Key Takeaways:
• The challenge involves a "heart-assumed breach" scenario where standard credential-based attacks are mitigated by disabling NLM and using obscure attack vectors 0:00.
• Attackers utilize provided credentials to dump user and machine lists, identifying a machine in a pre-2000 Windows compatibility group 0:21.
• Machines in this group have passwords set to their machine name, allowing attackers to authenticate and access Group Managed Service Account passwords 0:29.
• This access leads to another account with "generic all" permissions, facilitating further lateral movement and potential domain compromise 0:34.
This summary highlights the importance of understanding legacy Windows compatibility behaviors and Kerberos authentication in modern penetration testing.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
What's going on YouTube? This is IPS be doing vintage from hack the box which is a heart assumed breach active directory machine. Meaning we'll start with a set of credentials which may surprise you because normally when you get credentials to active directory it's game over. However, this box has some pretty tough to find paths that aren't easily viewable in blood hound and NLM authentication is disabled. So you have to be familiar with kobaros. To start things off, we use the credential given to us to dump a list of users and machines and discover a machine is a member of a pre200 Windows compatibility group, which means its password is going to be set to the machine name. This machine can read group manage service account passwords, which leads us to another account that has generic all…