A detailed walkthrough of HackTheBox's 'Fries' machine, an assume-breach Windows Active Directory box with a complex attack chain. Starting with provided credentials that only work on a Gitea instance, the path involves exploiting CVE-2025-2945 (Python eval RCE in pgAdmin 9.1), pivoting through Docker containers, abusing NFS shares by impersonating domain users to steal Docker daemon certificates, forging client certificates to access the Docker API and mount the host filesystem, recovering encrypted PWM service account credentials, reading a group managed service account password, and finally chaining three ADCS misconfigurations to forge an administrator certificate and take over the domain.
Table of contents
Box InfoReconShell as pgadmin on ContainerShell as svc on webShell as root on webAuth as svc_infraShell as gMSA_CA_prod$Shell as Administrator108 Impressions