<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>DLL Hijack on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/dll-hijack/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Sun, 04 Oct 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/dll-hijack/index.xml" rel="self" type="application/rss+xml"/><item><title>HTB: Touch</title><link>https://wearethebug.dev/posts/htb-touch/</link><pubDate>Sun, 04 Oct 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-touch/</guid><description>Touch is an Easy-rated Windows machine featuring a kiosk-mode device management application. Initial access stems from improperly secured credentials exposed through the device's API, leading to a restricted user session that requires creative exploitation to break out of its locked-down environment and reach a full shell. Privilege escalation involves abusing misconfigured service permissions and exposed database credentials to escalate to full administrative control.</description></item><item><title>VULNLAB: Push</title><link>https://wearethebug.dev/posts/vl-push/</link><pubDate>Fri, 22 Sep 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-push/</guid><description>Push is a Hard-rated small Windows Active Directory chain featuring a one domain controller and one member server. This chain focuses on advanced attack techniques including ClickOnce application exploitation, SCCM coercion, and ADCS exploitation via Golden Certificate attacks.</description></item><item><title>VULNLAB: Trusted</title><link>https://wearethebug.dev/posts/vl-trusted/</link><pubDate>Tue, 20 Sep 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-trusted/</guid><description>Trusted is an Easy small Active Directory chain involving two domain controllers (labdc.lab.trusted.vl and trusteddc.trusted.vl) that focuses on web vulnerabilities, local privilege escalation, and cross-domain trust abuse. An internal network access is provided with no credentials, and the goal is to assess the security posture of the AD environment.</description></item><item><title>VULNLAB: Bruno</title><link>https://wearethebug.dev/posts/vl-bruno/</link><pubDate>Sat, 02 Jul 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-bruno/</guid><description>Bruno is a medium-rated Windows domain box that chains insecure application configuration and weak Active Directory hygiene to go from no access to domain admin. The service-facing component is a custom .NET application that extracts ZIP entries unsafely using Path.Combine, allowing crafted archives to perform a zip-slip and place files under the app folder. That capability enables a DLL-search-path hijack - an attacker who can write to the queue share can drop a malicious dll and achieve code execution as the service user. On the network/AD side, an account svc_scan is discoverable and kerberoastable/AS-REP crackable; its recovered credentials grant write access to the queue share, which is used to trigger the DLL payload and get a low-privilege shell. From there the default machine account quota of authenticated users and RBCD are abused to perform a Kerberos relay/RBCD attack that resets the Administrator password and yields full domain compromise.</description></item></channel></rss>