> For the complete documentation index, see [llms.txt](https://hackzzz.gitbook.io/welcome/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hackzzz.gitbook.io/welcome/everything-about-and-notes/windows-and-active-directory/active-directory/post-compromise-attacks/pass-attacks/gpp-cpassword-attack.md).

# GPP cPassword Attack

## What is GPP?

* Group policies preferences allowed admins to create policies using embedded credentials.
* These credentials were encrypted and placed in a **"cPassword"**

### Why is vulnerable?

* The key was **accidentally released by Microsoft**
* Patched in **MS14-025** but doesn't prevent previous uses.
* The key was stored in **SYSVOL**
* **Any Domain User can read the policy**

### Resources

* <https://www.rapid7.com/blog/post/2016/07/27/pentesting-in-the-real-world-group-policy-pwnage/>
