
HackTheBox - Administrator
Source: YouTube · IppSec · published Apr 19, 2025 · 33:23
0:00 The IPSC channel demonstrates an assumed breach attack on the Hack The Box "Administrator" machine, leveraging Active Directory misconfigurations to escalate privileges from a domain user to full domain admin control.
Key Takeaways:
• The initial foothold is established using provided credentials, revealing that while FTP access is denied, Bludgeon shows "Generic All" rights over one user and "Force Password Change" over another 0:19.
• By changing the password of the second user, the attacker gains access to the "Moderators" group, which grants the necessary permissions to access the FTP server 0:26.
• The FTP server hosts a Password Safe database, which, when cracked, reveals credentials for another domain user 0:36.
• This new user possesses "Generic All" rights over a service account with DC Sync privileges, allowing the attacker to perform a targeted Kerberoast attack to extract the TGS ticket 0:40.
This scenario highlights how seemingly minor permission errors in Active Directory can lead to complete infrastructure compromise through chained privilege escalations.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
What's going on YouTube? This is IPSC and we'll be doing administrator from hack the box which is an assumed breach active directory machine meaning we start out with the main credentials and from end mapap we can see just active directory and FTP is running however we cannot connect to FTP because a user doesn't have permissions but we can run blunthound with our credentials that shows we have generic all over one user and force password change over another. So we can change both users password and on the second user hop it gives us access to a user in the share moderators group which grants us FTP access and that FTP server host a password safe database which cracking it gives us access to another user. This user has generic right over a user with DC sync privileges. And generic right do…