<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>ASPX on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/aspx/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Fri, 19 Jan 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/aspx/index.xml" rel="self" type="application/rss+xml"/><item><title>VULNLAB: Lock</title><link>https://wearethebug.dev/posts/vl-lock/</link><pubDate>Fri, 19 Jan 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-lock/</guid><description>Lock is an Easy-rated Windows machine that involves enumerating a Gitea repository to find a Personal Access Token. This token is then used to deploy an ASPX web shell on the server, which provides an initial foothold. A password is then decrypted from an mRemoteNG configuration file, providing access to a new user account. Finally, a local privilege escalation vulnerability in the PDF24 application is exploited to obtain a shell with SYSTEM privileges.</description></item><item><title>VULNLAB: Job</title><link>https://wearethebug.dev/posts/vl-job/</link><pubDate>Sat, 27 Nov 2021 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-job/</guid><description>Job is a Medium-rated Windows box. It runs an SMTP server and its website accepts LibreOffice-compatible documents, providing a vector to deliver a document with embedded macros that leads to remote code execution as user jack.black. jack.black is a member of the DEVELOPERS group, which has write access to the IIS web root, allowing files to be placed in the webroot and achieve code execution as the IIS AppPool service account. The IIS AppPool account has the SeImpersonate privilege, creating conditions that allow token-impersonation techniques to be used to escalate privileges to Administrator.</description></item></channel></rss>