<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Insane on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/insane/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Sat, 12 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/insane/index.xml" rel="self" type="application/rss+xml"/><item><title>HTB: TrustFall</title><link>https://wearethebug.dev/posts/htb-trustfall/</link><pubDate>Sat, 12 Sep 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-trustfall/</guid><description>TrustFall is an Insane-rated hybrid machine featuring a complex, multi-stage kill chain that bridges external web exploitation with deep Active Directory and ADCS abuse. Initial access requires chaining an osTicket arbitrary file read with a legacy telnetd vulnerability to compromise a Linux pivot host. Lateral movement involves intricate ACL/OU inheritance abuse, AS-REP roasting, and a sophisticated WSUS Man-in-the-Middle attack powered by a rogue certificate (ESC17) for local privilege escalation. The endgame tests cryptographic weaknesses and PKI administration, requiring the prediction of a time-seeded VBScript PRNG to compromise a PKI Manager, ultimately leading to full Certificate Authority takeover (ESC7) and Domain Admin compromise via DCSync.</description></item><item><title>VULNLAB: Shiva</title><link>https://wearethebug.dev/posts/vl-shiva/</link><pubDate>Thu, 17 Apr 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-shiva/</guid><description>Shiva is an insane-difficulty Red Team lab on Vulnlab that simulates a hardened hybrid Active Directory environment (on-premises and Azure) with 10+ machines and active users. All protected by Endpoint Detection and Response (EDR), SIEM solutions, Windows Defender Application Control (WDAC), and common enterprise software.</description></item><item><title>VULNLAB: Klendathu</title><link>https://wearethebug.dev/posts/vl-klendathu/</link><pubDate>Fri, 24 May 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-klendathu/</guid><description>Klendathu is an Insane difficulty chain hosted on Vulnlab, involved coercion with an undocumented function/procedure on MSSQL, forging a silver ticket, spoofing domain users on linux with GSSAPI authentication, and decrypting RDCMan credentials with domain backup keys.</description></item><item><title>VULNLAB: Reaper2</title><link>https://wearethebug.dev/posts/vl-reaper2/</link><pubDate>Fri, 10 May 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-reaper2/</guid><description>ReaperTwo is an Insane Windows machine that involves both browser and kernel exploitation. The attack chain begins with enumeration of exposed services and access to an SMB share containing development artifacts. A vulnerable web application leveraging the V8 JavaScript engine allows for arbitrary JavaScript execution, which is escalated to remote code execution through a type confusion vulnerability in Harmony Set methods, combined with WebAssembly-based shellcode execution. After gaining an initial foothold as a low-privileged user, privilege escalation is achieved by exploiting a vulnerable kernel driver that exposes a function pointer execution primitive. The exploit bypasses modern protections such as kASLR, DEP, and SMEP by leaking kernel addresses via MSRs, performing a stack pivot, and constructing a ROP chain to modify Page Table Entries (PTEs). Finally, custom kernel shellcode is executed to steal a SYSTEM token, resulting in full system compromise.</description></item><item><title>VULNLAB: Reaper</title><link>https://wearethebug.dev/posts/vl-reaper/</link><pubDate>Fri, 18 Aug 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-reaper/</guid><description>Reaper is an Insane Windows machine that begins with an exposed FTP service. Within the FTP share resides a Windows binary vulnerable to both format-string and buffer-overflow attacks. By exploiting these flaws, an attacker can leak sensitive memory regions, hijack the program’s execution flow, and ultimately obtain a reverse shell on the target as the user keysvc. After gaining initial access, the attacker discovers a file containing a DPAPI blob. Once decrypted, this blob provides valid credentials for RDP access as keysvc. Continued enumeration reveals a custom kernel driver present and actively running on the system. Through reverse-engineering the driver, the attacker determines that it permits arbitrary kernel-level writes. Leveraging this capability, the attacker is able to steal a privileged token and escalate to a full SYSTEM shell (NT AUTHORITY\SYSTEM).</description></item><item><title>VULNLAB: Zero</title><link>https://wearethebug.dev/posts/vl-zero/</link><pubDate>Fri, 25 Feb 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-zero/</guid><description>Zero is an Insane difficulty Linux machine that features a web application that allows for the creation of credentials to be used on an SFTP server where users can create their own HTML pages. This service is exploitable by uploading a malicious .htaccess file to gain arbitrary file read access to the web servers' asset files. By viewing the source code of these files players will find hard coded credentials that allow for access to the target over SSH. The Apache server configuration is periodically managed by a cronjob that checks the integrity of the Apache configurations and can be abused by satisfying the conditions of the cronjob task to include a malicious line into the restored configuration to leak the contents of files owned by root.</description></item></channel></rss>