<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Machines on WE ARE THE BUG</title><link>https://wearethebug.dev/categories/machines/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Sun, 04 Oct 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/categories/machines/index.xml" rel="self" type="application/rss+xml"/><item><title>HTB: Touch</title><link>https://wearethebug.dev/posts/htb-touch/</link><pubDate>Sun, 04 Oct 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-touch/</guid><description>Touch is an Easy-rated Windows machine featuring a kiosk-mode device management application. Initial access stems from improperly secured credentials exposed through the device's API, leading to a restricted user session that requires creative exploitation to break out of its locked-down environment and reach a full shell. Privilege escalation involves abusing misconfigured service permissions and exposed database credentials to escalate to full administrative control.</description></item><item><title>HTB: Layover</title><link>https://wearethebug.dev/posts/htb-layover/</link><pubDate>Sun, 27 Sep 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-layover/</guid><description>Layover is a Medium-rated Linux machine that chains WiFi traffic sniffing and CMS RCE to pivot from a contractor foothold into a web portal's internal secrets, landing user access via password reuse. Root falls to a local CUPS vulnerability that leaks an admin token, used to write privileged files and fully compromise the box.</description></item><item><title>HTB: TrustFall</title><link>https://wearethebug.dev/posts/htb-trustfall/</link><pubDate>Sat, 12 Sep 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-trustfall/</guid><description>TrustFall is an Insane-rated hybrid machine featuring a complex, multi-stage kill chain that bridges external web exploitation with deep Active Directory and ADCS abuse. Initial access requires chaining an osTicket arbitrary file read with a legacy telnetd vulnerability to compromise a Linux pivot host. Lateral movement involves intricate ACL/OU inheritance abuse, AS-REP roasting, and a sophisticated WSUS Man-in-the-Middle attack powered by a rogue certificate (ESC17) for local privilege escalation. The endgame tests cryptographic weaknesses and PKI administration, requiring the prediction of a time-seeded VBScript PRNG to compromise a PKI Manager, ultimately leading to full Certificate Authority takeover (ESC7) and Domain Admin compromise via DCSync.</description></item><item><title>HTB: DanglingTree</title><link>https://wearethebug.dev/posts/htb-danglingtree/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-danglingtree/</guid><description>DanglingTree is a Medium-difficulty Windows machine focusing on Windows Admin Center (WAC) exploitation and cryptographic analysis. The foothold involves exploiting CVE-2026-26119 in WAC to execute PowerShell commands and abusing SmarterMail vulnerabilities (CVE-2026-23760/CVE-2026-24423) to gain initial access. The path to root requires DLL decompilation for DES decryption, DPAPI credential recovery, ACL abuse, and ADCS exploitation to escalate privileges to Administrator.</description></item><item><title>HTB: DarkZeroReturns</title><link>https://wearethebug.dev/posts/htb-darkzeroreturns/</link><pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-darkzeroreturns/</guid><description>Heron is an advanced Active Directory scenario featuring complex multi-step exploitation chains including web entry points (like SSTI leading to RCE), cross-realm Kerberos trust abuses, CI/CD runner pivots, and forest trust navigation.</description></item><item><title>HTB: Reactor</title><link>https://wearethebug.dev/posts/htb-reactor/</link><pubDate>Sun, 24 May 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-reactor/</guid><description>Reactor is an Easy-rated Linux machine where initial access is gained by exploiting CVE-2025-55182 (React2Shell), a pre-auth RCE in React Server Components triggered via a crafted Next-Action header, yielding a shell as node. Credentials are extracted from a SQLite database dump, cracked to reveal valid SSH access for lateral movement to the user engineer. Privilege escalation abuses an exposed Node.js debug port (9229), reached via SSH tunnel, to call process.mainModule.require and execute commands as root.</description></item><item><title>HTB: SmartHire</title><link>https://wearethebug.dev/posts/htb-smarthire/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-smarthire/</guid><description>SmartHire is a Medium-rated Linux machine that chains MLflow unsafe deserialization (CVE-2024-37054) to pivot from an unauthenticated web portal into a foothold as the svcweb user. Root falls to a Python .pth injection via a group-writable plugin directory, abused through a passwordless sudo misconfiguration to spawn a SUID shell and fully compromise the box.</description></item><item><title>VULNLAB: Machine Master</title><link>https://wearethebug.dev/posts/vl-machines/</link><pubDate>Sun, 09 Mar 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-machines/</guid><description>43 vulnerable standalone machines with various difficulties from easy to insane.</description></item><item><title>VULNLAB: Phantom</title><link>https://wearethebug.dev/posts/vl-phantom/</link><pubDate>Wed, 26 Feb 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-phantom/</guid><description>Phantom is a medium-difficulty Windows AD exploitation machine. The foothold involves discovering a publicly accessible SMB share, cracking a VeraCrypt container, and abusing Resource-Based Constrained Delegation (RBCD) to escalate privileges.</description></item><item><title>VULNLAB: Atlas</title><link>https://wearethebug.dev/posts/vl-atlas/</link><pubDate>Sun, 19 Jan 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-atlas/</guid><description>Atlas is a Hard-difficulty machine focusing on Java deserialization and .NET cryptographic analysis. The foothold involves exploiting a vulnerable Castor XML library in a Spring Boot app and reverse-engineering a .NET application to recover credentials.</description></item><item><title>VULNLAB: Baby2</title><link>https://wearethebug.dev/posts/vl-baby2/</link><pubDate>Sun, 19 Jan 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-baby2/</guid><description>Baby2 is a medium-rated Active Directory machine on Vulnlab. The attack path involves initial SMB enumeration, password spraying to gain low-privileged domain user access, replacing a login VBS script in SYSVOL for a reverse shell, and escalating privileges by abusing GPO (Group Policy Object) DACL misconfigurations.</description></item><item><title>VULNLAB: Odori</title><link>https://wearethebug.dev/posts/vl-odori/</link><pubDate>Fri, 17 Jan 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-odori/</guid><description>Odori is a medium-difficulty machine on Vulnlab that involves gaining access to a Bitlocker encrypted disk image, in order to retrieve DPAPI protected credentials. Furthermore we will use SFTP to bypass login restrictions and manipulate a python cache file to gain root privileges.</description></item><item><title>VULNLAB: Barrier</title><link>https://wearethebug.dev/posts/vl-barrier/</link><pubDate>Thu, 02 Jan 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-barrier/</guid><description>Barrier is a medium-rated machine that features exposed credentials and exploiting SSO authentication, privileged API access and CI/CD runners. Initial access is gained by discovering credentials in a public repository and then exploiting a SAML authentication bypass in GitLab to obtain administrative access. From there, a CI/CD runner is abused to execute code and extract sensitive information from environment variables. With the authorization token, the Authentik API can be exploited to obtain administrative control of the identity platform. Access to the Authentik admin panel allows user impersonation and access to Apache Guacamole. Then an existing connection within Guacamole provides remote access to the host. Finally, a private SSH key is recovered from MySQL and privilege escalation is achieved through credential disclosure in shell history.</description></item><item><title>VULNLAB: Redelegate</title><link>https://wearethebug.dev/posts/vl-redelegate/</link><pubDate>Fri, 22 Nov 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-redelegate/</guid><description>Redelegate is a hard-difficultly Windows machine that starts with Anonymous FTP access, which allows the attacker to download sensitive Keepass Database files. The attacker then discovers that the credentials in the database are valid for MSSQL local login, which leads to enumerate SIDs and performs a password spray attack. Being a member of the HelpDesk group, the newly compromised user account Marie.Curie has a User-Force-Change-Password Access Control setup over the Helen.Frost user account; that user account has privileges to get a PS remoting session onto the Domain Controller. The Helen.Frost user account also has the SeEnableDelegationPrivilege assigned and has full control over the FS01$ machine account, essentially allowing the attacker account to modify the msDS-AllowedToDelegateTo LDAP attribute and change the password of a computer object and perform a Constrained Delegation attack.</description></item><item><title>VULNLAB: Shibuya</title><link>https://wearethebug.dev/posts/vl-shibuya/</link><pubDate>Thu, 21 Nov 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-shibuya/</guid><description>Shibuya is a Medium Windows machine that starts of with the SMB port exposed. Enumerating possible usernames through Kerberos an attacker is able to find the valid machine account red:red. With these credentials, he can further enumerate the remote users and discover that the user svc_autojoin has a password in its description. With this account in hand, he is able to discover some Windows Imaging Format (.wmi) files that contain hashes for the user simon.watson. Now, the attacker has command execution through SSH on the remote machine and is able to enumerate that another user has an active interactive session. By performing a cross-session relay attack he is able to steal the hash and crack the password for the user nigel.mills. The new user is member of the t1_admin groups which has enrolment rights on a certificate template that's vulnerable to ESC1 and by exploiting it we are able to gain SYSTEM privileges on the machine.</description></item><item><title>VULNLAB: Ten</title><link>https://wearethebug.dev/posts/vl-ten/</link><pubDate>Fri, 11 Oct 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-ten/</guid><description>Ten is a Hard difficulty Linux machine that simulates a misconfigured shared-hosting environment. Players enumerate a public sign-up portal that provisions FTP accounts, abuse weak MySQL/FTP integration to pivot into a real local user, and finally achieve root by poisoning an etcd-driven Apache configuration reload.</description></item><item><title>VULNLAB: Baby</title><link>https://wearethebug.dev/posts/vl-baby/</link><pubDate>Sat, 28 Sep 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-baby/</guid><description>Baby is an easy difficulty Windows machine that features LDAP enumeration, password spraying and exposed credentials. For privilege escalation, the SeBackupPrivilege is exploited to extract registry hives and the NTDS.dit file. A Pass-the-Hash attack can be performed using the uncovered domain hashes ultimately achieving Administrator access.</description></item><item><title>VULNLAB: Cicada</title><link>https://wearethebug.dev/posts/vl-cicada/</link><pubDate>Thu, 26 Sep 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-cicada/</guid><description>Cicada is a Medium-rated Windows Active Directory machine hosted on the VulnLab platform, that involves discovering a password inside an image on a public share. With that password an attacker is able to discover that the machine is vulnerable to ESC8 and can use Kerberos relaying to bypass self-relay restrictions in order to get a certificate as the machine account itself. With this new certificate, we are able to dump the hashes of the Administrator user and thus compromise the whole domain.</description></item><item><title>VULNLAB: Down</title><link>https://wearethebug.dev/posts/vl-down/</link><pubDate>Fri, 20 Sep 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-down/</guid><description>Down is an easy-rated Linux machine that involves exploiting an arbitrary file read by bypassing a protocol-based filter to discover the source code of the running PHP web app, eventually, a remote code execution to gain an initial foothold. The attacker finds a readable pswm encrypted file in the user's home directory. The pwsm uses Python's cryptocode module and a master password to encrypt and decrypt the data. The attacker is supposed to write a small script to decrypt the blob and compromise the user. The compromised user is a member of the sudo group, allowing the user to escalate and obtain root access.</description></item><item><title>VULNLAB: Lustrous2</title><link>https://wearethebug.dev/posts/vl-lustrous2/</link><pubDate>Wed, 11 Sep 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-lustrous2/</guid><description>LustrousTwo is a hard-rated Windows machine that deals with LDAP signing, channel binding, and disabled NTLM authentication. The machine has a web server vulnerable to arbitrary file read, which helps attackers capture a Net-NTLMv2 hash for the service account, using it to request Service Tickets via s4u2self, a stealthier alternative to Silver Ticket, to bypass protective measures like Account is sensitive and cannot be delegated. After reversing and auditing the source code, the attacker achieves Remote Code Execution. For privilege escalation, the attacker exploits a misconfigured, insecure Velociraptor installation.</description></item><item><title>VULNLAB: Retro2</title><link>https://wearethebug.dev/posts/vl-retro2/</link><pubDate>Thu, 22 Aug 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-retro2/</guid><description>Retro2 is an easy difficulty Windows machine, which highlights AD exploitation. Initial external enumeration reveals a publicly accessible SMB Share containing a Microsoft Access Database file, which is password protected. After cracking the password, the contents of the accdb file are accessible, enabling the retrieval of the VBA script inside, where AD credentials can be retrieved. Then, by abusing pre-created computer accounts , we gain access to a computer account with the GenericWrite privilege over another account, which, when leveraged, provides access to the system via RDP . Finally, exploiting the RpcEptMapper registry key results in privilege escalation to a system account.</description></item><item><title>VULNLAB: Watcher</title><link>https://wearethebug.dev/posts/vl-watcher/</link><pubDate>Wed, 24 Jul 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-watcher/</guid><description>Watcher is a medium difficulty Linux box that involves Zabbix and is vulnerable to CVE-2024-22120, which allows an attacker to gain Remote Code Execution. After getting RCE, the attacker discovers that a web app can be backdoored, allowing them to gain credentials for a user account. The user is allowed to access TeamCity, which is running as root, and an agent terminal is active, allowing an attacker to gain a reverse shell as the root user.</description></item><item><title>VULNLAB: Manage</title><link>https://wearethebug.dev/posts/vl-manage/</link><pubDate>Fri, 28 Jun 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-manage/</guid><description>Manage is an easy Linux machine that features an exposed Java RMI service. Exploiting the underlying vulnerable JMX service leads to remote code execution and gaining a remote shell as the tomcat user. Lateral movement to the useradmin account can be achieved by discovering a misconfigured backup archive which leaks sensitive files, including SSH keys and OTP codes. Finally, a sudo misconfiguration allows for creating a privileged user and achieving full privilege escalation.</description></item><item><title>VULNLAB: Build</title><link>https://wearethebug.dev/posts/vl-build/</link><pubDate>Fri, 10 May 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-build/</guid><description>Build is an easy-level Linux machine hosted on the VulnLab platform. Its attack path relies primarily on exploiting a PowerDNSAdmin database, a configuration leak, and DNS poisoning to fully compromise the system.</description></item><item><title>VULNLAB: Reaper2</title><link>https://wearethebug.dev/posts/vl-reaper2/</link><pubDate>Fri, 10 May 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-reaper2/</guid><description>ReaperTwo is an Insane Windows machine that involves both browser and kernel exploitation. The attack chain begins with enumeration of exposed services and access to an SMB share containing development artifacts. A vulnerable web application leveraging the V8 JavaScript engine allows for arbitrary JavaScript execution, which is escalated to remote code execution through a type confusion vulnerability in Harmony Set methods, combined with WebAssembly-based shellcode execution. After gaining an initial foothold as a low-privileged user, privilege escalation is achieved by exploiting a vulnerable kernel driver that exposes a function pointer execution primitive. The exploit bypasses modern protections such as kASLR, DEP, and SMEP by leaking kernel addresses via MSRs, performing a stack pivot, and constructing a ROP chain to modify Page Table Entries (PTEs). Finally, custom kernel shellcode is executed to steal a SYSTEM token, resulting in full system compromise.</description></item><item><title>VULNLAB: Sendai</title><link>https://wearethebug.dev/posts/vl-sendai/</link><pubDate>Fri, 15 Mar 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-sendai/</guid><description>Sendai is a medium-difficulty Windows Active Directory machine focused on weak account hygiene, GMSA abuse, and ADCS misconfigurations. Initial access is gained through anonymous SMB enumeration, revealing files that hint at expired accounts with weak passwords. RID brute-forcing identifies users, and login attempts highlight accounts in a forced password reset state. By resetting thomas.powell’s password, the attacker obtains a domain foothold. BloodHound analysis shows that Powell’s group membership can be leveraged to compromise the MGTSVC$ GMSA account, enabling remote code execution on the domain controller. Further local enumeration uncovers inline credentials for clifford.davey, whose CA-OPERATORS group membership grants GenericAll rights over a certificate template. Abusing ESC4/ESC1 conditions with Certipy, the attacker forges a certificate for the administrator account, retrieves its NT hash, and authenticates via WinRM, achieving full domain compromise.</description></item><item><title>VULNLAB: Sweep</title><link>https://wearethebug.dev/posts/vl-sweep/</link><pubDate>Fri, 01 Mar 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-sweep/</guid><description>Sweep is a medium difficulty Windows box that involves Active Directory and Lansweeper, a technology asset intelligence tool. The attacker abuses an enabled guest account to gain access to Lansweeper, which has Map Credentials configured, which are login/password combinations for accessing and scanning network assets remotely. The attacker deploys a honeypot SSH server to read the configured credentials. The compromised account is a member of the Lansweeper Discovery group, which has GenericAll ACL over the Lansweeper Admins group. Any account member of the Lansweeper Admins group has administrator privileges on the Lansweeper dashboard. The attacker creates and deploys a package on the Domain Controller to gain complete control.</description></item><item><title>VULNLAB: Escape</title><link>https://wearethebug.dev/posts/vl-escape/</link><pubDate>Fri, 16 Feb 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-escape/</guid><description>Escape is an Easy Windows machine where users can log in restricted Kiosk mode via RDP without a password. By exploiting the file:// scheme in Microsoft Edge, attackers can browse the file system, bypass restrictions, and open PowerShell. Further enumeration reveals a Remote Desktop Plus profile, whose password can be extracted using BulletsPassView, allowing admin access and UAC bypass to read the root flag.</description></item><item><title>VULNLAB: Reset</title><link>https://wearethebug.dev/posts/vl-reset/</link><pubDate>Wed, 07 Feb 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-reset/</guid><description>Reset is an Easy difficulty Linux machine which showcases abusing a password reset functionality in a web application following a log poisoning attack, to achieve Remote Code Execution. For privilege escalation, Rservices are abused, then a detached tmux session is used to abuse sudo privileges on nano text editor and execute commands as the root user.</description></item><item><title>VULNLAB: Lock</title><link>https://wearethebug.dev/posts/vl-lock/</link><pubDate>Fri, 19 Jan 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-lock/</guid><description>Lock is an Easy-rated Windows machine that involves enumerating a Gitea repository to find a Personal Access Token. This token is then used to deploy an ASPX web shell on the server, which provides an initial foothold. A password is then decrypted from an mRemoteNG configuration file, providing access to a new user account. Finally, a local privilege escalation vulnerability in the PDF24 application is exploited to obtain a shell with SYSTEM privileges.</description></item><item><title>VULNLAB: Race</title><link>https://wearethebug.dev/posts/vl-race/</link><pubDate>Fri, 22 Dec 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-race/</guid><description>Race is a hard-difficulty Linux machine with a web application running Grav CMS and phpsysinfo. The phpsysinfo endpoint is protected with basic authentication, but its password is weak. The endpoint leaks credentials for the Grav CMS admin panel, which is accessible to a low-privilege user with permission to create web server backups. The attacker exploits the backup functionality to retrieve the rest token for a user with privileges to add a proxy and install themes. The attacker adds a proxy to intercept the response, uploads a custom theme, and gets a reverse shell. After gaining a reverse shell, the attacker is able to read sensitive files using a hardcoded password for the max user account. The max user account is a racers group member, which has write permission over a file vulnerable to a time-of-check / time-of-use vulnerability in a cron script. As an attacker, we will create named pipes to suspend execution and replace the file, thereby gaining command execution as root.</description></item><item><title>VULNLAB: Forgotten</title><link>https://wearethebug.dev/posts/vl-forgotten/</link><pubDate>Fri, 08 Dec 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-forgotten/</guid><description>Forgotten is an Easy Linux machine on VulnLab that challenges players to exploit an unfinished LimeSurvey installation by deploying a controlled MariaDB instance to gain admin access. Players then upload a malicious plugin for remote code execution inside a Docker container, discover an environment variable for host access, and escalate privileges by chaining low host access with container root privileges via a setuid binary.</description></item><item><title>VULNLAB: Slonik</title><link>https://wearethebug.dev/posts/vl-slonik/</link><pubDate>Fri, 27 Oct 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-slonik/</guid><description>Slonik is a Medium-difficulty Linux machine that focuses on NFS, PostgreSQL abuse, and privilege escalation through insecure backup automation. Initial access is obtained by enumerating exposed NFS shares and leveraging UID/GID trust relationships to access a home directory. History files within the share reveal database credentials and reference a locally bound PostgreSQL socket. Although direct SSH access is restricted, the socket is tunneled over SSH to interact with the database, where built-in PostgreSQL functionality is leveraged to achieve remote code execution. Privilege escalation is accomplished by monitoring system processes and identifying a root-executed backup script, ultimately leveraging pg_basebackup behavior and SUID permissions to obtain a root shell.</description></item><item><title>VULNLAB: Media</title><link>https://wearethebug.dev/posts/vl-media/</link><pubDate>Fri, 13 Oct 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-media/</guid><description>Media is a Medium-rated machine that features an Apache XAMPP stack on Windows hosting a custom PHP web application. The web application allows the upload of a Windows Media Player compatible file that can be leveraged to leak the NTLMv2 hash of the user account that opens it. This hash can be cracked to obtain user credentials that can be used to authenticate to the target via SSH. Upon gaining initial access the source code of the application can be analyzed to determine the generate storage path of uploaded files on the web application which can lead to an NTFS Junction (directory symbolic link) attack to upload a malicious PHP web shell for RCE. Once a shell under the context of the web server's service account, players can abuse the SeTcbPrivilege - Act as part of the operating system, a Windows privilege that lets code impersonate any user and achieve administrative privileges. Alternative methods for privilege escalation involve regaining the SeImpersonate privilege to elevate to NT Authority\SYSTEM.</description></item><item><title>VULNLAB: Delegate</title><link>https://wearethebug.dev/posts/vl-delegate/</link><pubDate>Fri, 06 Oct 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-delegate/</guid><description>Delegate is a medium-rated Windows machine that involves Active Directory attacks. The machine has the guest account enabled, allowing the attacker to read files that contain hard-coded credentials. The credentials allow us to WriteProperty of a user account that is allowed to have WinRM sessions on the Domain Controller. The compromised user has the SeEnableDelegationPrivilege privilege assigned, which allows us to modify the TRUSTED_FOR_DELEGATION flag for AD objects, enabling us to perform Unconstrained Delegation.</description></item><item><title>VULNLAB: Reaper</title><link>https://wearethebug.dev/posts/vl-reaper/</link><pubDate>Fri, 18 Aug 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-reaper/</guid><description>Reaper is an Insane Windows machine that begins with an exposed FTP service. Within the FTP share resides a Windows binary vulnerable to both format-string and buffer-overflow attacks. By exploiting these flaws, an attacker can leak sensitive memory regions, hijack the program’s execution flow, and ultimately obtain a reverse shell on the target as the user keysvc. After gaining initial access, the attacker discovers a file containing a DPAPI blob. Once decrypted, this blob provides valid credentials for RDP access as keysvc. Continued enumeration reveals a custom kernel driver present and actively running on the system. Through reverse-engineering the driver, the attacker determines that it permits arbitrary kernel-level writes. Leveraging this capability, the attacker is able to steal a privileged token and escalate to a full SYSTEM shell (NT AUTHORITY\SYSTEM).</description></item><item><title>VULNLAB: Retro</title><link>https://wearethebug.dev/posts/vl-retro/</link><pubDate>Fri, 11 Aug 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-retro/</guid><description>Retro is an Easy Windows machine that showcases an Active Directory Domain Controller. Through SMB enumeration and pre-created machine account exploitation, we gain access to the system. Through the exploitation of the Active Directory Certificate Service and specifically by using the ESC1 attack, which involves exploiting certificate templates to impersonate the Administrative user, privilege escalation is achieved.</description></item><item><title>VULNLAB: Bamboo</title><link>https://wearethebug.dev/posts/vl-bamboo/</link><pubDate>Sat, 10 Jun 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-bamboo/</guid><description>Bamboo is an medium-rated Linux machine that begins with discovering a Squid proxy. The proxy is used to scan internal ports and reveals a PaperCut NG instance. A known PaperCut vulnerability CVE-2023-27350 is exploited to gain a foothold. Local enumeration reveals a writable directory containing a script that runs with root privileges. By modifying the script, we obtain a shell as root.</description></item><item><title>VULNLAB: Job2</title><link>https://wearethebug.dev/posts/vl-job2/</link><pubDate>Wed, 10 May 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-job2/</guid><description>Job2 is a hard-rated Windows machine that involves a macro phishing attack for initial foothold. The machine has hMailServer installed, which includes a configuration file containing encrypted credentials for the database connection. After extracting the password database, we decrypt the SQL Server Compact database file (SDF), allowing a compromised user who can use WinRM to the machine. The machine has a vulnerable version of Veeam Backup &amp; Replication; the attacker executes a malicious executable under sqlserver.exe, which is running as SYSTEM to gain full access.</description></item><item><title>VULNLAB: Sync</title><link>https://wearethebug.dev/posts/vl-sync/</link><pubDate>Tue, 25 Apr 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-sync/</guid><description>Sync is an Easy-rated Linux machine on the Vulnlab platform that focuses on service enumeration and exploiting an insecure Rsync configuration, custom hash cracking, and privilege escalation.</description></item><item><title>VULNLAB: Dump</title><link>https://wearethebug.dev/posts/vl-dump/</link><pubDate>Mon, 13 Mar 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-dump/</guid><description>Dump is a Hard-rated Linux machine featuring a custom PHP web application that allows the creation of packet captures as well as upload and download functionality of pcap files. The machine demonstrates command argument injection through file naming to obtain initial remote code execution as www-data. Enumeration of the system reveals a sudo rule with tcpdump that can be abused for arbitrary file writes to the system and bypassing AppArmor security policy restrictions. With arbitrary file writes players can write malicious Message of The Day configurations that execute as root during system login.</description></item><item><title>VULNLAB: Store</title><link>https://wearethebug.dev/posts/vl-store/</link><pubDate>Fri, 17 Feb 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-store/</guid><description>Store is a Hard difficulty box that hosts a Node.js web application, allowing file uploads and storage. The app is vulnerable to Arbitrary File Read, which lets us read configuration files and recover SFTP credentials. We can also dump the host’s environment variables and discover the app was started with --inspect, with the Node inspector listening on port 9229. By abusing SFTP for port forwarding, we can tunnel that internal inspector port to our machine, attach and run JavaScript to spawn a reverse shell as user dev. For privilege escalation, the ChromeDriver service on port 9515 can be abused via its WebDriver API to execute a malicious script and gain a root shell.</description></item><item><title>VULNLAB: Breach</title><link>https://wearethebug.dev/posts/vl-breach/</link><pubDate>Tue, 14 Feb 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-breach/</guid><description>Breach is a medium difficulty Windows machine, where guest access to an SMB share is available. By leveraging write permissions on that SMB share, NTLMv2 hashes of a domain user are captured to obtain valid credentials. With access as a low-privileged domain user, a kerberoastable service account (svc_mssql) is revealed. After getting access to the service account, a Silver Ticket attack is performed to impersonate the `Administrator` user and gain access to Microsoft SQL Server. Through the xp_cmdshell feature, remote code execution is achieved as the svc_mssql service account. Finally, privilege escalation is performed by abusing the SeImpersonatePrivilege privilege.</description></item><item><title>VULNLAB: Bruno</title><link>https://wearethebug.dev/posts/vl-bruno/</link><pubDate>Sat, 02 Jul 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-bruno/</guid><description>Bruno is a medium-rated Windows domain box that chains insecure application configuration and weak Active Directory hygiene to go from no access to domain admin. The service-facing component is a custom .NET application that extracts ZIP entries unsafely using Path.Combine, allowing crafted archives to perform a zip-slip and place files under the app folder. That capability enables a DLL-search-path hijack - an attacker who can write to the queue share can drop a malicious dll and achieve code execution as the service user. On the network/AD side, an account svc_scan is discoverable and kerberoastable/AS-REP crackable; its recovered credentials grant write access to the queue share, which is used to trigger the DLL payload and get a low-privilege shell. From there the default machine account quota of authenticated users and RBCD are abused to perform a Kerberos relay/RBCD attack that resets the Administrator password and yields full domain compromise.</description></item><item><title>VULNLAB: Rainbow2</title><link>https://wearethebug.dev/posts/vl-rainbow2/</link><pubDate>Mon, 06 Jun 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-rainbow2/</guid><description>Rainbow2 is a Hard Windows machine centered around exploit development for a custom network file-sharing service. Initial enumeration reveals anonymous FTP access and an unknown service listening on TCP port 2121. The FTP share exposes the vulnerable service binary, a developer README, and a copy of SysWOW64\kernel32.dll. The README confirms that the service was rebuilt with ASLR, DEP, and GS enabled. Static and dynamic analysis then shows that the service is still vulnerable to a format string issue and a stack-based overflow that overwrites the SEH chain. The format string leak provides a reliable ASLR bypass by disclosing a pointer inside filesrv.exe; the SEH overwrite provides control of the exception handler; and a ROP chain calls VirtualAlloc to bypass DEP. Privilege escalation is achieved by abusing SeDebugPrivilege to migrate into a SYSTEM process.</description></item><item><title>VULNLAB: Unchained</title><link>https://wearethebug.dev/posts/vl-unchained/</link><pubDate>Fri, 04 Mar 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-unchained/</guid><description>Unchained is a Medium-rated Linux machine available on Vulnlab platform. Starting with NFS share enumeration then a source code analysis allows a JSONPICKLE deserialization to obtain a reverse shell as user. For the privilege escalation, CVE-2021-44730 (Dirty snap-confine LPE) or CVE-2022-0847 (DirtyPipe) can be exploited.</description></item><item><title>VULNLAB: Zero</title><link>https://wearethebug.dev/posts/vl-zero/</link><pubDate>Fri, 25 Feb 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-zero/</guid><description>Zero is an Insane difficulty Linux machine that features a web application that allows for the creation of credentials to be used on an SFTP server where users can create their own HTML pages. This service is exploitable by uploading a malicious .htaccess file to gain arbitrary file read access to the web servers' asset files. By viewing the source code of these files players will find hard coded credentials that allow for access to the target over SSH. The Apache server configuration is periodically managed by a cronjob that checks the integrity of the Apache configurations and can be abused by satisfying the conditions of the cronjob task to include a malicious line into the restored configuration to leak the contents of files owned by root.</description></item><item><title>VULNLAB: Data</title><link>https://wearethebug.dev/posts/vl-data/</link><pubDate>Sun, 23 Jan 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-data/</guid><description>Data is an Easy Linux machine that involves exploiting CVE-2021-43798, an arbitrary file read via path traversal in Grafana. By exploiting this vulnerability, the database file for Grafana is extracted, and the hashes in the database are converted to a format readable by Hashcat. The hash is then cracked and can be used for SSH access to the target as user boris. The compromised user has the privileges to execute docker exec as root on the system, allowing the user to escalate and obtain root access by adding the privileged flag to running containers and mounting the host filesystem.</description></item><item><title>VULNLAB: Rainbow</title><link>https://wearethebug.dev/posts/vl-rainbow/</link><pubDate>Mon, 17 Jan 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-rainbow/</guid><description>Rainbow is a medium-difficulty Windows machine exposing FTP and HTTP services on ports 21 and 80 &amp; 8080 respectively. From the FTP server, we can retrieve the web server binary and a PowerShell restart script, which is used to relaunch the server in the event of a crash automatically. The HTTP service on port 8080 is vulnerable to an SEH-based buffer overflow and exploiting this yields code execution as the rainbow user. Because rainbow is a member of the Administrators group, we achieved full elevation by bypassing UAC via the FodHelper technique.</description></item><item><title>VULNLAB: Feedback</title><link>https://wearethebug.dev/posts/vl-feedback/</link><pubDate>Sun, 12 Dec 2021 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-feedback/</guid><description>Feedback is an Easy-rated Linux machine centered around exploiting a vulnerable Log4j input field.</description></item><item><title>VULNLAB: Job</title><link>https://wearethebug.dev/posts/vl-job/</link><pubDate>Sat, 27 Nov 2021 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-job/</guid><description>Job is a Medium-rated Windows box. It runs an SMTP server and its website accepts LibreOffice-compatible documents, providing a vector to deliver a document with embedded macros that leads to remote code execution as user jack.black. jack.black is a member of the DEVELOPERS group, which has write access to the IIS web root, allowing files to be placed in the webroot and achieve code execution as the IIS AppPool service account. The IIS AppPool account has the SeImpersonate privilege, creating conditions that allow token-impersonation techniques to be used to escalate privileges to Administrator.</description></item></channel></rss>