<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Medium on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/medium/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Sun, 27 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/medium/index.xml" rel="self" type="application/rss+xml"/><item><title>HTB: Layover</title><link>https://wearethebug.dev/posts/htb-layover/</link><pubDate>Sun, 27 Sep 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-layover/</guid><description>Layover is a Medium-rated Linux machine that chains WiFi traffic sniffing and CMS RCE to pivot from a contractor foothold into a web portal's internal secrets, landing user access via password reuse. Root falls to a local CUPS vulnerability that leaks an admin token, used to write privileged files and fully compromise the box.</description></item><item><title>HTB: DanglingTree</title><link>https://wearethebug.dev/posts/htb-danglingtree/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-danglingtree/</guid><description>DanglingTree is a Medium-difficulty Windows machine focusing on Windows Admin Center (WAC) exploitation and cryptographic analysis. The foothold involves exploiting CVE-2026-26119 in WAC to execute PowerShell commands and abusing SmarterMail vulnerabilities (CVE-2026-23760/CVE-2026-24423) to gain initial access. The path to root requires DLL decompilation for DES decryption, DPAPI credential recovery, ACL abuse, and ADCS exploitation to escalate privileges to Administrator.</description></item><item><title>HTB: SmartHire</title><link>https://wearethebug.dev/posts/htb-smarthire/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-smarthire/</guid><description>SmartHire is a Medium-rated Linux machine that chains MLflow unsafe deserialization (CVE-2024-37054) to pivot from an unauthenticated web portal into a foothold as the svcweb user. Root falls to a Python .pth injection via a group-writable plugin directory, abused through a passwordless sudo misconfiguration to spawn a SUID shell and fully compromise the box.</description></item><item><title>ERTLabs: Calipendula</title><link>https://wearethebug.dev/posts/ertlabs-calipendula/</link><pubDate>Sat, 08 Nov 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/ertlabs-calipendula/</guid><description>Calipendula is a hybrid GCP and Active Directory breach scenario, pushing you through cloud IAM enumeration, service account chaining, RBCD relay attacks, multi-hop tunnelling in a segmented network.</description></item><item><title>ERTLabs: MailService</title><link>https://wearethebug.dev/posts/ertlabs-mailservice/</link><pubDate>Fri, 29 Aug 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/ertlabs-mailservice/</guid><description>MailService is a multi-stage internal penetration test scenario that required chaining several techniques across both Linux and Windows domains.</description></item><item><title>VULNLAB: Phantom</title><link>https://wearethebug.dev/posts/vl-phantom/</link><pubDate>Wed, 26 Feb 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-phantom/</guid><description>Phantom is a medium-difficulty Windows AD exploitation machine. The foothold involves discovering a publicly accessible SMB share, cracking a VeraCrypt container, and abusing Resource-Based Constrained Delegation (RBCD) to escalate privileges.</description></item><item><title>VULNLAB: Baby2</title><link>https://wearethebug.dev/posts/vl-baby2/</link><pubDate>Sun, 19 Jan 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-baby2/</guid><description>Baby2 is a medium-rated Active Directory machine on Vulnlab. The attack path involves initial SMB enumeration, password spraying to gain low-privileged domain user access, replacing a login VBS script in SYSVOL for a reverse shell, and escalating privileges by abusing GPO (Group Policy Object) DACL misconfigurations.</description></item><item><title>VULNLAB: Odori</title><link>https://wearethebug.dev/posts/vl-odori/</link><pubDate>Fri, 17 Jan 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-odori/</guid><description>Odori is a medium-difficulty machine on Vulnlab that involves gaining access to a Bitlocker encrypted disk image, in order to retrieve DPAPI protected credentials. Furthermore we will use SFTP to bypass login restrictions and manipulate a python cache file to gain root privileges.</description></item><item><title>VULNLAB: Flagsalad</title><link>https://wearethebug.dev/posts/vl-flagsalad/</link><pubDate>Wed, 08 Jan 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-flagsalad/</guid><description>Flagsalad is a medium-severity crypto challenge where the flag is encoded as a vector, multiplied by a random matrix, and obscured with noise.</description></item><item><title>VULNLAB: Barrier</title><link>https://wearethebug.dev/posts/vl-barrier/</link><pubDate>Thu, 02 Jan 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-barrier/</guid><description>Barrier is a medium-rated machine that features exposed credentials and exploiting SSO authentication, privileged API access and CI/CD runners. Initial access is gained by discovering credentials in a public repository and then exploiting a SAML authentication bypass in GitLab to obtain administrative access. From there, a CI/CD runner is abused to execute code and extract sensitive information from environment variables. With the authorization token, the Authentik API can be exploited to obtain administrative control of the identity platform. Access to the Authentik admin panel allows user impersonation and access to Apache Guacamole. Then an existing connection within Guacamole provides remote access to the host. Finally, a private SSH key is recovered from MySQL and privilege escalation is achieved through credential disclosure in shell history.</description></item><item><title>VULNLAB: Shibuya</title><link>https://wearethebug.dev/posts/vl-shibuya/</link><pubDate>Thu, 21 Nov 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-shibuya/</guid><description>Shibuya is a Medium Windows machine that starts of with the SMB port exposed. Enumerating possible usernames through Kerberos an attacker is able to find the valid machine account red:red. With these credentials, he can further enumerate the remote users and discover that the user svc_autojoin has a password in its description. With this account in hand, he is able to discover some Windows Imaging Format (.wmi) files that contain hashes for the user simon.watson. Now, the attacker has command execution through SSH on the remote machine and is able to enumerate that another user has an active interactive session. By performing a cross-session relay attack he is able to steal the hash and crack the password for the user nigel.mills. The new user is member of the t1_admin groups which has enrolment rights on a certificate template that's vulnerable to ESC1 and by exploiting it we are able to gain SYSTEM privileges on the machine.</description></item><item><title>VULNLAB: Mythical</title><link>https://wearethebug.dev/posts/vl-mythical/</link><pubDate>Wed, 06 Nov 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-mythical/</guid><description>Mythical is a Medium-rated small active directory chain on Vulnlab in which we start with an already running Mythic C2 beacon on an internal system. It is designed to practice operating through a C2 framework in a modern, challenging windows environment.</description></item><item><title>VULNLAB: Puppet</title><link>https://wearethebug.dev/posts/vl-puppet/</link><pubDate>Tue, 22 Oct 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-puppet/</guid><description>Puppet is a Medium-rated small active directory chain in which you start with an already running Sliver C2 beacon on an internal system. It is designed to practice operating through a C2 framework in a modern, challenging hybrid environment.</description></item><item><title>VULNLAB: Cicada</title><link>https://wearethebug.dev/posts/vl-cicada/</link><pubDate>Thu, 26 Sep 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-cicada/</guid><description>Cicada is a Medium-rated Windows Active Directory machine hosted on the VulnLab platform, that involves discovering a password inside an image on a public share. With that password an attacker is able to discover that the machine is vulnerable to ESC8 and can use Kerberos relaying to bypass self-relay restrictions in order to get a certificate as the machine account itself. With this new certificate, we are able to dump the hashes of the Administrator user and thus compromise the whole domain.</description></item><item><title>VULNLAB: Wutai</title><link>https://wearethebug.dev/posts/vl-wutai/</link><pubDate>Tue, 20 Aug 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-wutai/</guid><description>Wutai is a Medium-difficulty Red Team lab featuring 15+ machines across multiple networks, domains, and forests, challenging players to achieve Enterprise Admin status. Players refine AD enumeration, exploitation, certificate services, lateral movement, EDR bypass, reverse engineering, and covert operations while abusing trust relationships.</description></item><item><title>VULNLAB: Watcher</title><link>https://wearethebug.dev/posts/vl-watcher/</link><pubDate>Wed, 24 Jul 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-watcher/</guid><description>Watcher is a medium difficulty Linux box that involves Zabbix and is vulnerable to CVE-2024-22120, which allows an attacker to gain Remote Code Execution. After getting RCE, the attacker discovers that a web app can be backdoored, allowing them to gain credentials for a user account. The user is allowed to access TeamCity, which is running as root, and an agent terminal is active, allowing an attacker to gain a reverse shell as the root user.</description></item><item><title>VULNLAB: Heron</title><link>https://wearethebug.dev/posts/vl-heron/</link><pubDate>Thu, 13 Jun 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-heron/</guid><description>Heron is a medium-difficulty chain hosted on Vulnlab, featuring an assumed breach from a domain-joined linux jump server access to domain controller. Starting with an enumeration of the internal website for domain users and performing AS-REP roasting, decrypting GPP password from the sysvol share, leading to smb share having write access to web.config, gaining a shell by using AspNetCoreModule for executing powershell commands which lead to finding linux admin’s credentials, reusing the same password that will lead to another user which has WriteAccountRestrictions on dc that leads to resource based delegation</description></item><item><title>VULNLAB: Unintended</title><link>https://wearethebug.dev/posts/vl-unintended/</link><pubDate>Thu, 25 Apr 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-unintended/</guid><description>Unintended is an Medium chain that provides a hands-on experience with common missteps in Active Directory deployments, demonstrating how attackers can pivot between services to escalate privileges. It blends Linux privilege escalation techniques with Active Directory attack paths, making it a valuable practice ground for both offensive and defensive security practitioners.</description></item><item><title>VULNLAB: Tengu</title><link>https://wearethebug.dev/posts/vl-tengu/</link><pubDate>Thu, 28 Mar 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-tengu/</guid><description>Tengu is a medium-rated chained machine on VulnLab, features a mixed environment with two Windows hosts and one Linux host. Exploiting Node-RED on Linux (with MSSQL) grants command execution, decrypts service passwords, and pivots to dump NTLM hash. Constrained delegation allows impersonating MSSQL admin for local admin access then recover Domain Admin credentials via DPAPI and Kerberos to compromise the Domain Controller (DC).</description></item><item><title>VULNLAB: Sendai</title><link>https://wearethebug.dev/posts/vl-sendai/</link><pubDate>Fri, 15 Mar 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-sendai/</guid><description>Sendai is a medium-difficulty Windows Active Directory machine focused on weak account hygiene, GMSA abuse, and ADCS misconfigurations. Initial access is gained through anonymous SMB enumeration, revealing files that hint at expired accounts with weak passwords. RID brute-forcing identifies users, and login attempts highlight accounts in a forced password reset state. By resetting thomas.powell’s password, the attacker obtains a domain foothold. BloodHound analysis shows that Powell’s group membership can be leveraged to compromise the MGTSVC$ GMSA account, enabling remote code execution on the domain controller. Further local enumeration uncovers inline credentials for clifford.davey, whose CA-OPERATORS group membership grants GenericAll rights over a certificate template. Abusing ESC4/ESC1 conditions with Certipy, the attacker forges a certificate for the administrator account, retrieves its NT hash, and authenticates via WinRM, achieving full domain compromise.</description></item><item><title>VULNLAB: Sweep</title><link>https://wearethebug.dev/posts/vl-sweep/</link><pubDate>Fri, 01 Mar 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-sweep/</guid><description>Sweep is a medium difficulty Windows box that involves Active Directory and Lansweeper, a technology asset intelligence tool. The attacker abuses an enabled guest account to gain access to Lansweeper, which has Map Credentials configured, which are login/password combinations for accessing and scanning network assets remotely. The attacker deploys a honeypot SSH server to read the configured credentials. The compromised account is a member of the Lansweeper Discovery group, which has GenericAll ACL over the Lansweeper Admins group. Any account member of the Lansweeper Admins group has administrator privileges on the Lansweeper dashboard. The attacker creates and deploys a package on the Domain Controller to gain complete control.</description></item><item><title>VULNLAB: Tea</title><link>https://wearethebug.dev/posts/vl-tea/</link><pubDate>Fri, 05 Jan 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-tea/</guid><description>Tea is a medium-rate small Active Directory chain that provides hands-on experience with common Active Directory and DevOps vulnerabilities and misconfigurations, demonstrating how attackers can pivot between services and retrieve sensitive data to move laterally and escalate privileges.</description></item><item><title>VULNLAB: Slonik</title><link>https://wearethebug.dev/posts/vl-slonik/</link><pubDate>Fri, 27 Oct 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-slonik/</guid><description>Slonik is a Medium-difficulty Linux machine that focuses on NFS, PostgreSQL abuse, and privilege escalation through insecure backup automation. Initial access is obtained by enumerating exposed NFS shares and leveraging UID/GID trust relationships to access a home directory. History files within the share reveal database credentials and reference a locally bound PostgreSQL socket. Although direct SSH access is restricted, the socket is tunneled over SSH to interact with the database, where built-in PostgreSQL functionality is leveraged to achieve remote code execution. Privilege escalation is accomplished by monitoring system processes and identifying a root-executed backup script, ultimately leveraging pg_basebackup behavior and SUID permissions to obtain a root shell.</description></item><item><title>VULNLAB: Media</title><link>https://wearethebug.dev/posts/vl-media/</link><pubDate>Fri, 13 Oct 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-media/</guid><description>Media is a Medium-rated machine that features an Apache XAMPP stack on Windows hosting a custom PHP web application. The web application allows the upload of a Windows Media Player compatible file that can be leveraged to leak the NTLMv2 hash of the user account that opens it. This hash can be cracked to obtain user credentials that can be used to authenticate to the target via SSH. Upon gaining initial access the source code of the application can be analyzed to determine the generate storage path of uploaded files on the web application which can lead to an NTFS Junction (directory symbolic link) attack to upload a malicious PHP web shell for RCE. Once a shell under the context of the web server's service account, players can abuse the SeTcbPrivilege - Act as part of the operating system, a Windows privilege that lets code impersonate any user and achieve administrative privileges. Alternative methods for privilege escalation involve regaining the SeImpersonate privilege to elevate to NT Authority\SYSTEM.</description></item><item><title>VULNLAB: Delegate</title><link>https://wearethebug.dev/posts/vl-delegate/</link><pubDate>Fri, 06 Oct 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-delegate/</guid><description>Delegate is a medium-rated Windows machine that involves Active Directory attacks. The machine has the guest account enabled, allowing the attacker to read files that contain hard-coded credentials. The credentials allow us to WriteProperty of a user account that is allowed to have WinRM sessions on the Domain Controller. The compromised user has the SeEnableDelegationPrivilege privilege assigned, which allows us to modify the TRUSTED_FOR_DELEGATION flag for AD objects, enabling us to perform Unconstrained Delegation.</description></item><item><title>VULNLAB: Bamboo</title><link>https://wearethebug.dev/posts/vl-bamboo/</link><pubDate>Sat, 10 Jun 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-bamboo/</guid><description>Bamboo is an medium-rated Linux machine that begins with discovering a Squid proxy. The proxy is used to scan internal ports and reveals a PaperCut NG instance. A known PaperCut vulnerability CVE-2023-27350 is exploited to gain a foothold. Local enumeration reveals a writable directory containing a script that runs with root privileges. By modifying the script, we obtain a shell as root.</description></item><item><title>VULNLAB: Reflection</title><link>https://wearethebug.dev/posts/vl-reflection/</link><pubDate>Sat, 10 Jun 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-reflection/</guid><description>Reflection is a medium-difficulty Active Directory chain that simulates a vulnerable enterprise environment and challenges users to progress from limited access to Domain Administrator. Including 3 machines, with anonymous SMB bind abuse, MSSQL abuse, NTLM relay attacks, Windows Credential Vault harvesting, Resource-Based Constrained Delegation (RBCD), and finally credential reuse.</description></item><item><title>VULNLAB: Breach</title><link>https://wearethebug.dev/posts/vl-breach/</link><pubDate>Tue, 14 Feb 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-breach/</guid><description>Breach is a medium difficulty Windows machine, where guest access to an SMB share is available. By leveraging write permissions on that SMB share, NTLMv2 hashes of a domain user are captured to obtain valid credentials. With access as a low-privileged domain user, a kerberoastable service account (svc_mssql) is revealed. After getting access to the service account, a Silver Ticket attack is performed to impersonate the `Administrator` user and gain access to Microsoft SQL Server. Through the xp_cmdshell feature, remote code execution is achieved as the svc_mssql service account. Finally, privilege escalation is performed by abusing the SeImpersonatePrivilege privilege.</description></item><item><title>VULNLAB: Bruno</title><link>https://wearethebug.dev/posts/vl-bruno/</link><pubDate>Sat, 02 Jul 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-bruno/</guid><description>Bruno is a medium-rated Windows domain box that chains insecure application configuration and weak Active Directory hygiene to go from no access to domain admin. The service-facing component is a custom .NET application that extracts ZIP entries unsafely using Path.Combine, allowing crafted archives to perform a zip-slip and place files under the app folder. That capability enables a DLL-search-path hijack - an attacker who can write to the queue share can drop a malicious dll and achieve code execution as the service user. On the network/AD side, an account svc_scan is discoverable and kerberoastable/AS-REP crackable; its recovered credentials grant write access to the queue share, which is used to trigger the DLL payload and get a low-privilege shell. From there the default machine account quota of authenticated users and RBCD are abused to perform a Kerberos relay/RBCD attack that resets the Administrator password and yields full domain compromise.</description></item><item><title>VULNLAB: Unchained</title><link>https://wearethebug.dev/posts/vl-unchained/</link><pubDate>Fri, 04 Mar 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-unchained/</guid><description>Unchained is a Medium-rated Linux machine available on Vulnlab platform. Starting with NFS share enumeration then a source code analysis allows a JSONPICKLE deserialization to obtain a reverse shell as user. For the privilege escalation, CVE-2021-44730 (Dirty snap-confine LPE) or CVE-2022-0847 (DirtyPipe) can be exploited.</description></item><item><title>VULNLAB: Rainbow</title><link>https://wearethebug.dev/posts/vl-rainbow/</link><pubDate>Mon, 17 Jan 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-rainbow/</guid><description>Rainbow is a medium-difficulty Windows machine exposing FTP and HTTP services on ports 21 and 80 &amp; 8080 respectively. From the FTP server, we can retrieve the web server binary and a PowerShell restart script, which is used to relaunch the server in the event of a crash automatically. The HTTP service on port 8080 is vulnerable to an SEH-based buffer overflow and exploiting this yields code execution as the rainbow user. Because rainbow is a member of the Administrators group, we achieved full elevation by bypassing UAC via the FodHelper technique.</description></item><item><title>VULNLAB: Job</title><link>https://wearethebug.dev/posts/vl-job/</link><pubDate>Sat, 27 Nov 2021 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-job/</guid><description>Job is a Medium-rated Windows box. It runs an SMTP server and its website accepts LibreOffice-compatible documents, providing a vector to deliver a document with embedded macros that leads to remote code execution as user jack.black. jack.black is a member of the DEVELOPERS group, which has write access to the IIS web root, allowing files to be placed in the webroot and achieve code execution as the IIS AppPool service account. The IIS AppPool account has the SeImpersonate privilege, creating conditions that allow token-impersonation techniques to be used to escalate privileges to Administrator.</description></item></channel></rss>