<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>NTFS Junction on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/ntfs-junction/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Fri, 13 Oct 2023 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/ntfs-junction/index.xml" rel="self" type="application/rss+xml"/><item><title>VULNLAB: Media</title><link>https://wearethebug.dev/posts/vl-media/</link><pubDate>Fri, 13 Oct 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-media/</guid><description>Media is a Medium-rated machine that features an Apache XAMPP stack on Windows hosting a custom PHP web application. The web application allows the upload of a Windows Media Player compatible file that can be leveraged to leak the NTLMv2 hash of the user account that opens it. This hash can be cracked to obtain user credentials that can be used to authenticate to the target via SSH. Upon gaining initial access the source code of the application can be analyzed to determine the generate storage path of uploaded files on the web application which can lead to an NTFS Junction (directory symbolic link) attack to upload a malicious PHP web shell for RCE. Once a shell under the context of the web server's service account, players can abuse the SeTcbPrivilege - Act as part of the operating system, a Windows privilege that lets code impersonate any user and achieve administrative privileges. Alternative methods for privilege escalation involve regaining the SeImpersonate privilege to elevate to NT Authority\SYSTEM.</description></item></channel></rss>