<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>DPAPI on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/dpapi/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/dpapi/index.xml" rel="self" type="application/rss+xml"/><item><title>HTB: DanglingTree</title><link>https://wearethebug.dev/posts/htb-danglingtree/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-danglingtree/</guid><description>DanglingTree is a Medium-difficulty Windows machine focusing on Windows Admin Center (WAC) exploitation and cryptographic analysis. The foothold involves exploiting CVE-2026-26119 in WAC to execute PowerShell commands and abusing SmarterMail vulnerabilities (CVE-2026-23760/CVE-2026-24423) to gain initial access. The path to root requires DLL decompilation for DES decryption, DPAPI credential recovery, ACL abuse, and ADCS exploitation to escalate privileges to Administrator.</description></item><item><title>VULNLAB: Odori</title><link>https://wearethebug.dev/posts/vl-odori/</link><pubDate>Fri, 17 Jan 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-odori/</guid><description>Odori is a medium-difficulty machine on Vulnlab that involves gaining access to a Bitlocker encrypted disk image, in order to retrieve DPAPI protected credentials. Furthermore we will use SFTP to bypass login restrictions and manipulate a python cache file to gain root privileges.</description></item><item><title>VULNLAB: Klendathu</title><link>https://wearethebug.dev/posts/vl-klendathu/</link><pubDate>Fri, 24 May 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-klendathu/</guid><description>Klendathu is an Insane difficulty chain hosted on Vulnlab, involved coercion with an undocumented function/procedure on MSSQL, forging a silver ticket, spoofing domain users on linux with GSSAPI authentication, and decrypting RDCMan credentials with domain backup keys.</description></item><item><title>VULNLAB: Tengu</title><link>https://wearethebug.dev/posts/vl-tengu/</link><pubDate>Thu, 28 Mar 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-tengu/</guid><description>Tengu is a medium-rated chained machine on VulnLab, features a mixed environment with two Windows hosts and one Linux host. Exploiting Node-RED on Linux (with MSSQL) grants command execution, decrypts service passwords, and pivots to dump NTLM hash. Constrained delegation allows impersonating MSSQL admin for local admin access then recover Domain Admin credentials via DPAPI and Kerberos to compromise the Domain Controller (DC).</description></item><item><title>VULNLAB: Reaper</title><link>https://wearethebug.dev/posts/vl-reaper/</link><pubDate>Fri, 18 Aug 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-reaper/</guid><description>Reaper is an Insane Windows machine that begins with an exposed FTP service. Within the FTP share resides a Windows binary vulnerable to both format-string and buffer-overflow attacks. By exploiting these flaws, an attacker can leak sensitive memory regions, hijack the program’s execution flow, and ultimately obtain a reverse shell on the target as the user keysvc. After gaining initial access, the attacker discovers a file containing a DPAPI blob. Once decrypted, this blob provides valid credentials for RDP access as keysvc. Continued enumeration reveals a custom kernel driver present and actively running on the system. Through reverse-engineering the driver, the attacker determines that it permits arbitrary kernel-level writes. Leveraging this capability, the attacker is able to steal a privileged token and escalate to a full SYSTEM shell (NT AUTHORITY\SYSTEM).</description></item><item><title>VULNLAB: Reflection</title><link>https://wearethebug.dev/posts/vl-reflection/</link><pubDate>Sat, 10 Jun 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-reflection/</guid><description>Reflection is a medium-difficulty Active Directory chain that simulates a vulnerable enterprise environment and challenges users to progress from limited access to Domain Administrator. Including 3 machines, with anonymous SMB bind abuse, MSSQL abuse, NTLM relay attacks, Windows Credential Vault harvesting, Resource-Based Constrained Delegation (RBCD), and finally credential reuse.</description></item></channel></rss>