HackTheBox - Voleur

HackTheBox - Voleur

Source: YouTube · IppSec · published Nov 1, 2025 · 1:00:23

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This video demonstrates the exploitation of the Hack the Box machine "Valora," focusing on lateral privilege escalation through Active Directory manipulation and share pilfering. 0:05

Key Takeaways:
• The initial foothold is gained by discovering credentials in a fileshare, specifically for a deleted user and two service accounts. 0:09
• An LDAP service account is identified as a member of the "Restore Users" group, enabling the restoration of the deleted user. 0:18
• The attacker performs a targeted Kerberos attack against the WinRM account using the LDAP credentials to gain initial shell access. 0:27
• Using Rubeus, the attacker switches to the LDAP context to leverage PowerShell's Active Directory module for further enumeration and exploitation. 0:32

The walkthrough highlights the importance of auditing service accounts and group memberships in Active Directory environments to prevent lateral movement.

Sources:

  • 0:05 Introduction to the Valora AD box.
  • 0:09 Discovery of credentials in fileshares.
  • 0:18 Identification of LDAP account permissions.
  • 0:27 Execution of Kerberos attack.
  • 0:32 Use of Rubeus and AD module.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

What's going on YouTube? This is IPSG me doing Valora from Hack the Box, which is a nice active directory box that's all about lateral privac and pillaging shares. It starts off with discovering a document in a fileshare, giving us credentials to a deleted user and two service accounts. One of these accounts is for LDAP and this account is a member of a group called restore users. So, it's likely we can restore a deleted user. This is automated in Net Exec, but not on the main branch yet. So, I don't expect many people to know about it. The intended path is to use this LDAP account to perform a targeted Kerros attack against the WinRM account, letting us get a shell on the box, then use run CS to switch to LDAP, giving us the ability to use PowerShell's AD module to restore the user. From …