Group Policy Preferences (GPP) let administrators push local users, scheduled tasks, mapped drives, and services to machines, and older ones store a password in the policy XML as a cpassword field. That field is AES-encrypted with a key Microsoft published, so anyone who can read the XML can decrypt it. Because the policy files live in SYSVOL, which every authenticated domain user can read, a single cpassword is a domain-user-to-local-admin (and often reused-everywhere) credential handed out for free.
Finding and decrypting#
# NetExec: locate and decrypt cpassword across SYSVOL in one step
nxc smb <dc> -u user -p pass -M gpp_password
# Autologon credentials stored in Registry.xml preferences
nxc smb <dc> -u user -p pass -M gpp_autologin
# Manual: grep SYSVOL for cpassword, then decrypt with the published key
grep -rl 'cpassword' /mnt/sysvol/ # Groups.xml, Services.xml, Drives.xml, ScheduledTasks.xml, Datasources.xml
gpp-decrypt '<cpassword-blob>'
# On a domain host
Get-GPPPassword
The XML files that carry cpassword are Groups.xml (local users), Services.xml, ScheduledTasks.xml, Drives.xml, Datasources.xml, and Printers.xml under each policy's Machine or User preferences folder.
Why it still matters#
- Microsoft removed the ability to create new GPP passwords in 2014 (MS14-025), but it did not scrub existing ones, so legacy
cpasswordentries persist in SYSVOL for years. - The recovered account is frequently a local administrator pushed to many machines with the same password, so one find enables pass-the-hash/password reuse across the fleet.
- It needs only a single low-privileged domain account (SYSVOL read), making it a first-move credential hunt alongside reconnaissance.
Exploitation notes#
- Grep the whole SYSVOL policy tree, not just
Groups.xml; credentials hide in services, scheduled tasks, and datasource preferences too. - Autologon credentials (
gpp_autologin, fromRegistry.xml) are cleartext, notcpassword-encrypted, and often expose a privileged account set to log a kiosk or build machine in automatically. - Validate and spray the recovered credential with
nxcto map where that local account is reused.
Tools#
- NetExec (
nxc)-M gpp_password/-M gpp_autologin: find and decrypt from Linux. - gpp-decrypt: decrypt a
cpasswordblob with the published AES key. - PowerSploit
Get-GPPPassword: on-host recovery.
References#
- The Hacker Recipes: Group Policy Preferences passwords
- Microsoft: MS14-025 (Group Policy Preferences password removal)