<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Constrained Delegation on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/constrained-delegation/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Fri, 29 Aug 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/constrained-delegation/index.xml" rel="self" type="application/rss+xml"/><item><title>ERTLabs: MailService</title><link>https://wearethebug.dev/posts/ertlabs-mailservice/</link><pubDate>Fri, 29 Aug 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/ertlabs-mailservice/</guid><description>MailService is a multi-stage internal penetration test scenario that required chaining several techniques across both Linux and Windows domains.</description></item><item><title>ERTLabs: Ifix-Tcen-Tcen</title><link>https://wearethebug.dev/posts/ertlabs-ifix-tcen-tcen/</link><pubDate>Sat, 09 Aug 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/ertlabs-ifix-tcen-tcen/</guid><description>Ifix-Tcen-Tcen is a famous Italian onomatopoeia and cultural reference originating from the erotic *fotoromanzi* (photo-novels) of the 1970s and 1980s. In our case it's a multi-stage internal penetration test scenario focus on Active Directory.</description></item><item><title>VULNLAB: Redelegate</title><link>https://wearethebug.dev/posts/vl-redelegate/</link><pubDate>Fri, 22 Nov 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-redelegate/</guid><description>Redelegate is a hard-difficultly Windows machine that starts with Anonymous FTP access, which allows the attacker to download sensitive Keepass Database files. The attacker then discovers that the credentials in the database are valid for MSSQL local login, which leads to enumerate SIDs and performs a password spray attack. Being a member of the HelpDesk group, the newly compromised user account Marie.Curie has a User-Force-Change-Password Access Control setup over the Helen.Frost user account; that user account has privileges to get a PS remoting session onto the Domain Controller. The Helen.Frost user account also has the SeEnableDelegationPrivilege assigned and has full control over the FS01$ machine account, essentially allowing the attacker account to modify the msDS-AllowedToDelegateTo LDAP attribute and change the password of a computer object and perform a Constrained Delegation attack.</description></item></channel></rss>