<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cross-Session Relay on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/cross-session-relay/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Thu, 21 Nov 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/cross-session-relay/index.xml" rel="self" type="application/rss+xml"/><item><title>VULNLAB: Shibuya</title><link>https://wearethebug.dev/posts/vl-shibuya/</link><pubDate>Thu, 21 Nov 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-shibuya/</guid><description>Shibuya is a Medium Windows machine that starts of with the SMB port exposed. Enumerating possible usernames through Kerberos an attacker is able to find the valid machine account red:red. With these credentials, he can further enumerate the remote users and discover that the user svc_autojoin has a password in its description. With this account in hand, he is able to discover some Windows Imaging Format (.wmi) files that contain hashes for the user simon.watson. Now, the attacker has command execution through SSH on the remote machine and is able to enumerate that another user has an active interactive session. By performing a cross-session relay attack he is able to steal the hash and crack the password for the user nigel.mills. The new user is member of the t1_admin groups which has enrolment rights on a certificate template that's vulnerable to ESC1 and by exploiting it we are able to gain SYSTEM privileges on the machine.</description></item></channel></rss>