<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hard-Coded Credentials on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/hard-coded-credentials/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Thu, 22 Aug 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/hard-coded-credentials/index.xml" rel="self" type="application/rss+xml"/><item><title>VULNLAB: Retro2</title><link>https://wearethebug.dev/posts/vl-retro2/</link><pubDate>Thu, 22 Aug 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-retro2/</guid><description>Retro2 is an easy difficulty Windows machine, which highlights AD exploitation. Initial external enumeration reveals a publicly accessible SMB Share containing a Microsoft Access Database file, which is password protected. After cracking the password, the contents of the accdb file are accessible, enabling the retrieval of the VBA script inside, where AD credentials can be retrieved. Then, by abusing pre-created computer accounts , we gain access to a computer account with the GenericWrite privilege over another account, which, when leveraged, provides access to the system via RDP . Finally, exploiting the RpcEptMapper registry key results in privilege escalation to a system account.</description></item><item><title>VULNLAB: Zero</title><link>https://wearethebug.dev/posts/vl-zero/</link><pubDate>Fri, 25 Feb 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-zero/</guid><description>Zero is an Insane difficulty Linux machine that features a web application that allows for the creation of credentials to be used on an SFTP server where users can create their own HTML pages. This service is exploitable by uploading a malicious .htaccess file to gain arbitrary file read access to the web servers' asset files. By viewing the source code of these files players will find hard coded credentials that allow for access to the target over SSH. The Apache server configuration is periodically managed by a cronjob that checks the integrity of the Apache configurations and can be abused by satisfying the conditions of the cronjob task to include a malicious line into the restored configuration to leak the contents of files owned by root.</description></item></channel></rss>