<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hard on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/hard/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Tue, 28 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/hard/index.xml" rel="self" type="application/rss+xml"/><item><title>HTB: DarkZeroReturns</title><link>https://wearethebug.dev/posts/htb-darkzeroreturns/</link><pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-darkzeroreturns/</guid><description>Heron is an advanced Active Directory scenario featuring complex multi-step exploitation chains including web entry points (like SSTI leading to RCE), cross-realm Kerberos trust abuses, CI/CD runner pivots, and forest trust navigation.</description></item><item><title>ERTLabs: Ifix-Tcen-Tcen</title><link>https://wearethebug.dev/posts/ertlabs-ifix-tcen-tcen/</link><pubDate>Sat, 09 Aug 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/ertlabs-ifix-tcen-tcen/</guid><description>Ifix-Tcen-Tcen is a famous Italian onomatopoeia and cultural reference originating from the erotic *fotoromanzi* (photo-novels) of the 1970s and 1980s. In our case it's a multi-stage internal penetration test scenario focus on Active Directory.</description></item><item><title>VULNLAB: Shinra</title><link>https://wearethebug.dev/posts/vl-shinra/</link><pubDate>Sun, 09 Mar 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-shinra/</guid><description>Shinra is a Hard-rated Red Team lab designed for those with foundational AD and pentesting knowledge to refine covert red teaming skills. Players focus on AD enumeration, exploitation, certificate services, lateral movement, phishing, CI/CD attacks, EDR bypass, backdooring apps, and relay attacks while evading real-time detections.</description></item><item><title>VULNLAB: Atlas</title><link>https://wearethebug.dev/posts/vl-atlas/</link><pubDate>Sun, 19 Jan 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-atlas/</guid><description>Atlas is a Hard-difficulty machine focusing on Java deserialization and .NET cryptographic analysis. The foothold involves exploiting a vulnerable Castor XML library in a Spring Boot app and reverse-engineering a .NET application to recover credentials.</description></item><item><title>VULNLAB: Redelegate</title><link>https://wearethebug.dev/posts/vl-redelegate/</link><pubDate>Fri, 22 Nov 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-redelegate/</guid><description>Redelegate is a hard-difficultly Windows machine that starts with Anonymous FTP access, which allows the attacker to download sensitive Keepass Database files. The attacker then discovers that the credentials in the database are valid for MSSQL local login, which leads to enumerate SIDs and performs a password spray attack. Being a member of the HelpDesk group, the newly compromised user account Marie.Curie has a User-Force-Change-Password Access Control setup over the Helen.Frost user account; that user account has privileges to get a PS remoting session onto the Domain Controller. The Helen.Frost user account also has the SeEnableDelegationPrivilege assigned and has full control over the FS01$ machine account, essentially allowing the attacker account to modify the msDS-AllowedToDelegateTo LDAP attribute and change the password of a computer object and perform a Constrained Delegation attack.</description></item><item><title>VULNLAB: Ten</title><link>https://wearethebug.dev/posts/vl-ten/</link><pubDate>Fri, 11 Oct 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-ten/</guid><description>Ten is a Hard difficulty Linux machine that simulates a misconfigured shared-hosting environment. Players enumerate a public sign-up portal that provisions FTP accounts, abuse weak MySQL/FTP integration to pivot into a real local user, and finally achieve root by poisoning an etcd-driven Apache configuration reload.</description></item><item><title>VULNLAB: Lustrous2</title><link>https://wearethebug.dev/posts/vl-lustrous2/</link><pubDate>Wed, 11 Sep 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-lustrous2/</guid><description>LustrousTwo is a hard-rated Windows machine that deals with LDAP signing, channel binding, and disabled NTLM authentication. The machine has a web server vulnerable to arbitrary file read, which helps attackers capture a Net-NTLMv2 hash for the service account, using it to request Service Tickets via s4u2self, a stealthier alternative to Silver Ticket, to bypass protective measures like Account is sensitive and cannot be delegated. After reversing and auditing the source code, the attacker achieves Remote Code Execution. For privilege escalation, the attacker exploits a misconfigured, insecure Velociraptor installation.</description></item><item><title>VULNLAB: Vigilant</title><link>https://wearethebug.dev/posts/vl-vigilant/</link><pubDate>Mon, 15 Apr 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-vigilant/</guid><description>Vigilant is a Hard hybrid Active Directory chain. The environment consists of a domain-joined Linux system and a Windows Domain Controller, presenting a realistic enterprise attack surface. It designed to evaluate penetration testing capabilities in hybrid Windows-Linux environments. Participants begin with zero initial access and must systematically escalate privileges to achieve Domain Administrator-level compromise.</description></item><item><title>VULNLAB: Kaiju</title><link>https://wearethebug.dev/posts/vl-kaiju/</link><pubDate>Fri, 02 Feb 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-kaiju/</guid><description>Kaiju is a Hard-rated Active Directory chain, from initial reconnaissance to full domain compromise, covering FileZilla exploitation, KeePass database extraction, NTLM relay attacks, and ADCS abuse (ESC8).</description></item><item><title>VULNLAB: Race</title><link>https://wearethebug.dev/posts/vl-race/</link><pubDate>Fri, 22 Dec 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-race/</guid><description>Race is a hard-difficulty Linux machine with a web application running Grav CMS and phpsysinfo. The phpsysinfo endpoint is protected with basic authentication, but its password is weak. The endpoint leaks credentials for the Grav CMS admin panel, which is accessible to a low-privilege user with permission to create web server backups. The attacker exploits the backup functionality to retrieve the rest token for a user with privileges to add a proxy and install themes. The attacker adds a proxy to intercept the response, uploads a custom theme, and gets a reverse shell. After gaining a reverse shell, the attacker is able to read sensitive files using a hardcoded password for the max user account. The max user account is a racers group member, which has write permission over a file vulnerable to a time-of-check / time-of-use vulnerability in a cron script. As an attacker, we will create named pipes to suspend execution and replace the file, thereby gaining command execution as root.</description></item><item><title>VULNLAB: Sidecar</title><link>https://wearethebug.dev/posts/vl-sidecar/</link><pubDate>Fri, 15 Dec 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-sidecar/</guid><description>Sidecar is a Hard-rated small Active Directory chain that contains 2 Windows machines, however, attacks are not for beginners on Active Directory Pentesting. From initial enumeration through to full domain compromise, including Shell via a .lnk file, NTLM relay, WebDAV coercion, Shadow Credentials, PKINIT abuse, and a Silver Ticket attack.</description></item><item><title>VULNLAB: Push</title><link>https://wearethebug.dev/posts/vl-push/</link><pubDate>Fri, 22 Sep 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-push/</guid><description>Push is a Hard-rated small Windows Active Directory chain featuring a one domain controller and one member server. This chain focuses on advanced attack techniques including ClickOnce application exploitation, SCCM coercion, and ADCS exploitation via Golden Certificate attacks.</description></item><item><title>VULNLAB: Control</title><link>https://wearethebug.dev/posts/vl-control/</link><pubDate>Fri, 21 Jul 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-control/</guid><description>Control is a Hard-rated chains focus on a small multi-host Linux environment that simulates a realistic internal network and endpoint-management infrastructure. The lab contains two primary hosts (os.control.vl and intra.control.vl) and a variety of services (web apps, OSCTRL/osquery, SSH, nginx, Docker) that chain together to a full domain compromise. It focuses on exploiting web applications, abusing management tooling (OSCTRL / osquery), and leveraging operational misconfigurations to move from an initial foothold to full root on multiple hosts.</description></item><item><title>VULNLAB: Job2</title><link>https://wearethebug.dev/posts/vl-job2/</link><pubDate>Wed, 10 May 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-job2/</guid><description>Job2 is a hard-rated Windows machine that involves a macro phishing attack for initial foothold. The machine has hMailServer installed, which includes a configuration file containing encrypted credentials for the database connection. After extracting the password database, we decrypt the SQL Server Compact database file (SDF), allowing a compromised user who can use WinRM to the machine. The machine has a vulnerable version of Veeam Backup &amp; Replication; the attacker executes a malicious executable under sqlserver.exe, which is running as SYSTEM to gain full access.</description></item><item><title>VULNLAB: Dump</title><link>https://wearethebug.dev/posts/vl-dump/</link><pubDate>Mon, 13 Mar 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-dump/</guid><description>Dump is a Hard-rated Linux machine featuring a custom PHP web application that allows the creation of packet captures as well as upload and download functionality of pcap files. The machine demonstrates command argument injection through file naming to obtain initial remote code execution as www-data. Enumeration of the system reveals a sudo rule with tcpdump that can be abused for arbitrary file writes to the system and bypassing AppArmor security policy restrictions. With arbitrary file writes players can write malicious Message of The Day configurations that execute as root during system login.</description></item><item><title>VULNLAB: Store</title><link>https://wearethebug.dev/posts/vl-store/</link><pubDate>Fri, 17 Feb 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-store/</guid><description>Store is a Hard difficulty box that hosts a Node.js web application, allowing file uploads and storage. The app is vulnerable to Arbitrary File Read, which lets us read configuration files and recover SFTP credentials. We can also dump the host’s environment variables and discover the app was started with --inspect, with the Node inspector listening on port 9229. By abusing SFTP for port forwarding, we can tunnel that internal inspector port to our machine, attach and run JavaScript to spawn a reverse shell as user dev. For privilege escalation, the ChromeDriver service on port 9515 can be abused via its WebDriver API to execute a malicious script and gain a root shell.</description></item><item><title>VULNLAB: Rainbow2</title><link>https://wearethebug.dev/posts/vl-rainbow2/</link><pubDate>Mon, 06 Jun 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-rainbow2/</guid><description>Rainbow2 is a Hard Windows machine centered around exploit development for a custom network file-sharing service. Initial enumeration reveals anonymous FTP access and an unknown service listening on TCP port 2121. The FTP share exposes the vulnerable service binary, a developer README, and a copy of SysWOW64\kernel32.dll. The README confirms that the service was rebuilt with ASLR, DEP, and GS enabled. Static and dynamic analysis then shows that the service is still vulnerable to a format string issue and a stack-based overflow that overwrites the SEH chain. The format string leak provides a reliable ASLR bypass by disclosing a pointer inside filesrv.exe; the SEH overwrite provides control of the exception handler; and a ROP chain calls VirtualAlloc to bypass DEP. Privilege escalation is achieved by abusing SeDebugPrivilege to migrate into a SYSTEM process.</description></item><item><title>VULNLAB: Intercept</title><link>https://wearethebug.dev/posts/vl-intercept/</link><pubDate>Sat, 25 Dec 2021 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-intercept/</guid><description>Intercept is a small Active Directory scenario rated as Hard that provides hands-on experience with common Active Directory vulnerabilities and misconfigurations, demonstrating relay attacks and authentication coercion attacks can be used to get access to the domain.</description></item><item><title>VULNLAB: Lustrous</title><link>https://wearethebug.dev/posts/vl-lustrous/</link><pubDate>Sat, 25 Dec 2021 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-lustrous/</guid><description>Lustrous is a Hard-rated chain consisting of 2 machines on vulnlab. Cevering AS-REP roasts, Kerberoasts, the main lesson on this chain is to demonstrate how silver tickets can be used with service accounts in a Active Directory environment.</description></item></channel></rss>