HackTheBox - Puppy

HackTheBox - Puppy

Source: YouTube · IppSec · published Sep 27, 2025 · 58:32

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

BLUF: This video demonstrates a Hack The Box "Puppy" walkthrough, focusing on exploiting overlooked pillaged KeePass protected files and leveraging credential access in an assumed breach scenario 0:00.

Key Takeaways:
• The scenario begins with credentials that allow adding a user to a group to read a fileshare containing a KeePass database protected by a new encryption scheme 0:16.
• The attacker must use the latest version of KeePass to John the Ripper to successfully decrypt the password database 0:23.
• Password spraying is employed to gain access to the "Ant" account, which allows taking over the "Adam" account 0:28.
• A critical challenge arises because the "Adam" account is disabled; the attacker must change Adam's password to enable remote access to the server 0:31.

The walkthrough highlights the importance of securing KeePass databases and managing disabled accounts in breach simulations.

Sources:

  • 0:00 Introduction to the Hack The Box "Puppy" box.
  • 0:16 Accessing the KeePass protected fileshare.
  • 0:23 Decrypting the KeePass database with updated tools.
  • 0:28 Password spraying to target the Ant and Adam accounts.
  • 0:31 Overcoming the disabled Adam account to gain RDP access.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

What's going on YouTube? This is IPSC and we're doing puppy from hack the box which is a box I really enjoy primarily because I think many people overlook pillaging dappy protected files within user directories and that is a thing at the end of this box. Anyways, it starts off with a set of credentials because it's an assumed breach scenario. This credential lets us add ourselves to a group which enables reading a fileshare that has a key pass database using a relatively new encryption scheme. So we have to pull the latest key pass to John in order to decrypt this. From here, we password spray to get access to Ant, who can take over Adam's account, and Adam can remote into the server. The trick here is Adam is also disabled. So, when changing Adam's password, we also have to reenable his a…