GPP / cPassword Attacks
Overview


Check with PowerUp.ps1

GPP Attack via Metasploit
Mitigation
Last updated
Group policy preferences (GPP) allowed Administrators to create policies using embedded credentials. These credentials were encrypted and placed in a "cPassword". The encryption key was released by accident so the all the passwords are decryptable.



Be up to date on patching
Delete old GPP xml files inside the SYSVOL
Last updated
. .\PowerUp.ps1
Invoke-AllCheckuse auxiliary/scanner/smb/smb_enum_gpp