<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>KeePass on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/keepass/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Fri, 22 Nov 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/keepass/index.xml" rel="self" type="application/rss+xml"/><item><title>VULNLAB: Redelegate</title><link>https://wearethebug.dev/posts/vl-redelegate/</link><pubDate>Fri, 22 Nov 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-redelegate/</guid><description>Redelegate is a hard-difficultly Windows machine that starts with Anonymous FTP access, which allows the attacker to download sensitive Keepass Database files. The attacker then discovers that the credentials in the database are valid for MSSQL local login, which leads to enumerate SIDs and performs a password spray attack. Being a member of the HelpDesk group, the newly compromised user account Marie.Curie has a User-Force-Change-Password Access Control setup over the Helen.Frost user account; that user account has privileges to get a PS remoting session onto the Domain Controller. The Helen.Frost user account also has the SeEnableDelegationPrivilege assigned and has full control over the FS01$ machine account, essentially allowing the attacker account to modify the msDS-AllowedToDelegateTo LDAP attribute and change the password of a computer object and perform a Constrained Delegation attack.</description></item><item><title>VULNLAB: Mythical</title><link>https://wearethebug.dev/posts/vl-mythical/</link><pubDate>Wed, 06 Nov 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-mythical/</guid><description>Mythical is a Medium-rated small active directory chain on Vulnlab in which we start with an already running Mythic C2 beacon on an internal system. It is designed to practice operating through a C2 framework in a modern, challenging windows environment.</description></item><item><title>VULNLAB: Kaiju</title><link>https://wearethebug.dev/posts/vl-kaiju/</link><pubDate>Fri, 02 Feb 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-kaiju/</guid><description>Kaiju is a Hard-rated Active Directory chain, from initial reconnaissance to full domain compromise, covering FileZilla exploitation, KeePass database extraction, NTLM relay attacks, and ADCS abuse (ESC8).</description></item><item><title>VULNLAB: Hybrid</title><link>https://wearethebug.dev/posts/vl-hybrid/</link><pubDate>Thu, 22 Jun 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-hybrid/</guid><description>Hybrid is an Easy-rated, simplified Active Directory chain with 2 servers MAIL01 (Roundcube webmail) and DC01. Exploited a vulnerable Roundcube plugin via a crafted email, escalated privileges via NFS, and abused AD CS with certipy to achieve Domain Admin.</description></item></channel></rss>