<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CVE-2024-10526 on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/cve-2024-10526/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Wed, 11 Sep 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/cve-2024-10526/index.xml" rel="self" type="application/rss+xml"/><item><title>VULNLAB: Lustrous2</title><link>https://wearethebug.dev/posts/vl-lustrous2/</link><pubDate>Wed, 11 Sep 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-lustrous2/</guid><description>LustrousTwo is a hard-rated Windows machine that deals with LDAP signing, channel binding, and disabled NTLM authentication. The machine has a web server vulnerable to arbitrary file read, which helps attackers capture a Net-NTLMv2 hash for the service account, using it to request Service Tickets via s4u2self, a stealthier alternative to Silver Ticket, to bypass protective measures like Account is sensitive and cannot be delegated. After reversing and auditing the source code, the attacker achieves Remote Code Execution. For privilege escalation, the attacker exploits a misconfigured, insecure Velociraptor installation.</description></item></channel></rss>