<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Easy on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/easy/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Sun, 04 Oct 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/easy/index.xml" rel="self" type="application/rss+xml"/><item><title>HTB: Touch</title><link>https://wearethebug.dev/posts/htb-touch/</link><pubDate>Sun, 04 Oct 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-touch/</guid><description>Touch is an Easy-rated Windows machine featuring a kiosk-mode device management application. Initial access stems from improperly secured credentials exposed through the device's API, leading to a restricted user session that requires creative exploitation to break out of its locked-down environment and reach a full shell. Privilege escalation involves abusing misconfigured service permissions and exposed database credentials to escalate to full administrative control.</description></item><item><title>HTB: Reactor</title><link>https://wearethebug.dev/posts/htb-reactor/</link><pubDate>Sun, 24 May 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-reactor/</guid><description>Reactor is an Easy-rated Linux machine where initial access is gained by exploiting CVE-2025-55182 (React2Shell), a pre-auth RCE in React Server Components triggered via a crafted Next-Action header, yielding a shell as node. Credentials are extracted from a SQLite database dump, cracked to reveal valid SSH access for lateral movement to the user engineer. Privilege escalation abuses an exposed Node.js debug port (9229), reached via SSH tunnel, to call process.mainModule.require and execute commands as root.</description></item><item><title>VULNLAB: Share</title><link>https://wearethebug.dev/posts/vl-share/</link><pubDate>Wed, 08 Jan 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-share/</guid><description>Share is an easy crypto challenge where the flag is encoded in a polynomial function f(x) = flag + a₁x + a₂x² + a₃x³, with 10 known points (x, f(x)) provided.</description></item><item><title>VULNLAB: Warmup 1</title><link>https://wearethebug.dev/posts/vl-warmup1/</link><pubDate>Wed, 08 Jan 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-warmup1/</guid><description>Warmup 1 is a easy misc challenge focus on Discord bot commands.</description></item><item><title>VULNLAB: Warmup 2</title><link>https://wearethebug.dev/posts/vl-warmup2/</link><pubDate>Wed, 08 Jan 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-warmup2/</guid><description>Warmup 2 is a easy misc challenge where the flag is hidden in a provided file.</description></item><item><title>VULNLAB: Warmup 3</title><link>https://wearethebug.dev/posts/vl-warmup3/</link><pubDate>Wed, 08 Jan 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-warmup3/</guid><description>Warmup 3 is a easy misc challenge where the flag is hidden on a webpage.</description></item><item><title>VULNLAB: Baby</title><link>https://wearethebug.dev/posts/vl-baby/</link><pubDate>Sat, 28 Sep 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-baby/</guid><description>Baby is an easy difficulty Windows machine that features LDAP enumeration, password spraying and exposed credentials. For privilege escalation, the SeBackupPrivilege is exploited to extract registry hives and the NTDS.dit file. A Pass-the-Hash attack can be performed using the uncovered domain hashes ultimately achieving Administrator access.</description></item><item><title>VULNLAB: Down</title><link>https://wearethebug.dev/posts/vl-down/</link><pubDate>Fri, 20 Sep 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-down/</guid><description>Down is an easy-rated Linux machine that involves exploiting an arbitrary file read by bypassing a protocol-based filter to discover the source code of the running PHP web app, eventually, a remote code execution to gain an initial foothold. The attacker finds a readable pswm encrypted file in the user's home directory. The pwsm uses Python's cryptocode module and a master password to encrypt and decrypt the data. The attacker is supposed to write a small script to decrypt the blob and compromise the user. The compromised user is a member of the sudo group, allowing the user to escalate and obtain root access.</description></item><item><title>VULNLAB: Ifrit</title><link>https://wearethebug.dev/posts/vl-ifrit/</link><pubDate>Sun, 15 Sep 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-ifrit/</guid><description>Ifrit is an Assumed-Breach scenario with the main objective is getting domain administrator privileges in the ifrit.vl Domain. It designed for those with foundational AD and pentesting knowledge to hone covert red teaming skills. Players aim for Domain Admin while evading real-time detections, practicing AD enumeration, exploitation, certificate services, lateral movement, EDR bypass, and relay attacks across multiple forests.</description></item><item><title>VULNLAB: Retro2</title><link>https://wearethebug.dev/posts/vl-retro2/</link><pubDate>Thu, 22 Aug 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-retro2/</guid><description>Retro2 is an easy difficulty Windows machine, which highlights AD exploitation. Initial external enumeration reveals a publicly accessible SMB Share containing a Microsoft Access Database file, which is password protected. After cracking the password, the contents of the accdb file are accessible, enabling the retrieval of the VBA script inside, where AD credentials can be retrieved. Then, by abusing pre-created computer accounts , we gain access to a computer account with the GenericWrite privilege over another account, which, when leveraged, provides access to the system via RDP . Finally, exploiting the RpcEptMapper registry key results in privilege escalation to a system account.</description></item><item><title>VULNLAB: Manage</title><link>https://wearethebug.dev/posts/vl-manage/</link><pubDate>Fri, 28 Jun 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-manage/</guid><description>Manage is an easy Linux machine that features an exposed Java RMI service. Exploiting the underlying vulnerable JMX service leads to remote code execution and gaining a remote shell as the tomcat user. Lateral movement to the useradmin account can be achieved by discovering a misconfigured backup archive which leaks sensitive files, including SSH keys and OTP codes. Finally, a sudo misconfiguration allows for creating a privileged user and achieving full privilege escalation.</description></item><item><title>VULNLAB: Build</title><link>https://wearethebug.dev/posts/vl-build/</link><pubDate>Fri, 10 May 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-build/</guid><description>Build is an easy-level Linux machine hosted on the VulnLab platform. Its attack path relies primarily on exploiting a PowerDNSAdmin database, a configuration leak, and DNS poisoning to fully compromise the system.</description></item><item><title>VULNLAB: Escape</title><link>https://wearethebug.dev/posts/vl-escape/</link><pubDate>Fri, 16 Feb 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-escape/</guid><description>Escape is an Easy Windows machine where users can log in restricted Kiosk mode via RDP without a password. By exploiting the file:// scheme in Microsoft Edge, attackers can browse the file system, bypass restrictions, and open PowerShell. Further enumeration reveals a Remote Desktop Plus profile, whose password can be extracted using BulletsPassView, allowing admin access and UAC bypass to read the root flag.</description></item><item><title>VULNLAB: Reset</title><link>https://wearethebug.dev/posts/vl-reset/</link><pubDate>Wed, 07 Feb 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-reset/</guid><description>Reset is an Easy difficulty Linux machine which showcases abusing a password reset functionality in a web application following a log poisoning attack, to achieve Remote Code Execution. For privilege escalation, Rservices are abused, then a detached tmux session is used to abuse sudo privileges on nano text editor and execute commands as the root user.</description></item><item><title>VULNLAB: Lock</title><link>https://wearethebug.dev/posts/vl-lock/</link><pubDate>Fri, 19 Jan 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-lock/</guid><description>Lock is an Easy-rated Windows machine that involves enumerating a Gitea repository to find a Personal Access Token. This token is then used to deploy an ASPX web shell on the server, which provides an initial foothold. A password is then decrypted from an mRemoteNG configuration file, providing access to a new user account. Finally, a local privilege escalation vulnerability in the PDF24 application is exploited to obtain a shell with SYSTEM privileges.</description></item><item><title>VULNLAB: Forgotten</title><link>https://wearethebug.dev/posts/vl-forgotten/</link><pubDate>Fri, 08 Dec 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-forgotten/</guid><description>Forgotten is an Easy Linux machine on VulnLab that challenges players to exploit an unfinished LimeSurvey installation by deploying a controlled MariaDB instance to gain admin access. Players then upload a malicious plugin for remote code execution inside a Docker container, discover an environment variable for host access, and escalate privileges by chaining low host access with container root privileges via a setuid binary.</description></item><item><title>VULNLAB: Retro</title><link>https://wearethebug.dev/posts/vl-retro/</link><pubDate>Fri, 11 Aug 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-retro/</guid><description>Retro is an Easy Windows machine that showcases an Active Directory Domain Controller. Through SMB enumeration and pre-created machine account exploitation, we gain access to the system. Through the exploitation of the Active Directory Certificate Service and specifically by using the ESC1 attack, which involves exploiting certificate templates to impersonate the Administrative user, privilege escalation is achieved.</description></item><item><title>VULNLAB: Hybrid</title><link>https://wearethebug.dev/posts/vl-hybrid/</link><pubDate>Thu, 22 Jun 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-hybrid/</guid><description>Hybrid is an Easy-rated, simplified Active Directory chain with 2 servers MAIL01 (Roundcube webmail) and DC01. Exploited a vulnerable Roundcube plugin via a crafted email, escalated privileges via NFS, and abused AD CS with certipy to achieve Domain Admin.</description></item><item><title>VULNLAB: Sync</title><link>https://wearethebug.dev/posts/vl-sync/</link><pubDate>Tue, 25 Apr 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-sync/</guid><description>Sync is an Easy-rated Linux machine on the Vulnlab platform that focuses on service enumeration and exploiting an insecure Rsync configuration, custom hash cracking, and privilege escalation.</description></item><item><title>VULNLAB: Trusted</title><link>https://wearethebug.dev/posts/vl-trusted/</link><pubDate>Tue, 20 Sep 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-trusted/</guid><description>Trusted is an Easy small Active Directory chain involving two domain controllers (labdc.lab.trusted.vl and trusteddc.trusted.vl) that focuses on web vulnerabilities, local privilege escalation, and cross-domain trust abuse. An internal network access is provided with no credentials, and the goal is to assess the security posture of the AD environment.</description></item><item><title>VULNLAB: Data</title><link>https://wearethebug.dev/posts/vl-data/</link><pubDate>Sun, 23 Jan 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-data/</guid><description>Data is an Easy Linux machine that involves exploiting CVE-2021-43798, an arbitrary file read via path traversal in Grafana. By exploiting this vulnerability, the database file for Grafana is extracted, and the hashes in the database are converted to a format readable by Hashcat. The hash is then cracked and can be used for SSH access to the target as user boris. The compromised user has the privileges to execute docker exec as root on the system, allowing the user to escalate and obtain root access by adding the privileged flag to running containers and mounting the host filesystem.</description></item><item><title>VULNLAB: Feedback</title><link>https://wearethebug.dev/posts/vl-feedback/</link><pubDate>Sun, 12 Dec 2021 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-feedback/</guid><description>Feedback is an Easy-rated Linux machine centered around exploiting a vulnerable Log4j input field.</description></item></channel></rss>