
HackTheBox - Puppy
Source: YouTube · IppSec · published Sep 27, 2025 · 58:32
BLUF: This video demonstrates a Hack The Box "Puppy" walkthrough, focusing on exploiting overlooked pillaged KeePass protected files and leveraging credential access in an assumed breach scenario 0:00.
Key Takeaways:
• The scenario begins with credentials that allow adding a user to a group to read a fileshare containing a KeePass database protected by a new encryption scheme 0:16.
• The attacker must use the latest version of KeePass to John the Ripper to successfully decrypt the password database 0:23.
• Password spraying is employed to gain access to the "Ant" account, which allows taking over the "Adam" account 0:28.
• A critical challenge arises because the "Adam" account is disabled; the attacker must change Adam's password to enable remote access to the server 0:31.
The walkthrough highlights the importance of securing KeePass databases and managing disabled accounts in breach simulations.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
What's going on YouTube? This is IPSC and we're doing puppy from hack the box which is a box I really enjoy primarily because I think many people overlook pillaging dappy protected files within user directories and that is a thing at the end of this box. Anyways, it starts off with a set of credentials because it's an assumed breach scenario. This credential lets us add ourselves to a group which enables reading a fileshare that has a key pass database using a relatively new encryption scheme. So we have to pull the latest key pass to John in order to decrypt this. From here, we password spray to get access to Ant, who can take over Adam's account, and Adam can remote into the server. The trick here is Adam is also disabled. So, when changing Adam's password, we also have to reenable his a…