<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Password Spray on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/password-spray/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Sun, 09 Mar 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/password-spray/index.xml" rel="self" type="application/rss+xml"/><item><title>VULNLAB: Shinra</title><link>https://wearethebug.dev/posts/vl-shinra/</link><pubDate>Sun, 09 Mar 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-shinra/</guid><description>Shinra is a Hard-rated Red Team lab designed for those with foundational AD and pentesting knowledge to refine covert red teaming skills. Players focus on AD enumeration, exploitation, certificate services, lateral movement, phishing, CI/CD attacks, EDR bypass, backdooring apps, and relay attacks while evading real-time detections.</description></item><item><title>VULNLAB: Baby2</title><link>https://wearethebug.dev/posts/vl-baby2/</link><pubDate>Sun, 19 Jan 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-baby2/</guid><description>Baby2 is a medium-rated Active Directory machine on Vulnlab. The attack path involves initial SMB enumeration, password spraying to gain low-privileged domain user access, replacing a login VBS script in SYSVOL for a reverse shell, and escalating privileges by abusing GPO (Group Policy Object) DACL misconfigurations.</description></item><item><title>VULNLAB: Redelegate</title><link>https://wearethebug.dev/posts/vl-redelegate/</link><pubDate>Fri, 22 Nov 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-redelegate/</guid><description>Redelegate is a hard-difficultly Windows machine that starts with Anonymous FTP access, which allows the attacker to download sensitive Keepass Database files. The attacker then discovers that the credentials in the database are valid for MSSQL local login, which leads to enumerate SIDs and performs a password spray attack. Being a member of the HelpDesk group, the newly compromised user account Marie.Curie has a User-Force-Change-Password Access Control setup over the Helen.Frost user account; that user account has privileges to get a PS remoting session onto the Domain Controller. The Helen.Frost user account also has the SeEnableDelegationPrivilege assigned and has full control over the FS01$ machine account, essentially allowing the attacker account to modify the msDS-AllowedToDelegateTo LDAP attribute and change the password of a computer object and perform a Constrained Delegation attack.</description></item><item><title>VULNLAB: Shibuya</title><link>https://wearethebug.dev/posts/vl-shibuya/</link><pubDate>Thu, 21 Nov 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-shibuya/</guid><description>Shibuya is a Medium Windows machine that starts of with the SMB port exposed. Enumerating possible usernames through Kerberos an attacker is able to find the valid machine account red:red. With these credentials, he can further enumerate the remote users and discover that the user svc_autojoin has a password in its description. With this account in hand, he is able to discover some Windows Imaging Format (.wmi) files that contain hashes for the user simon.watson. Now, the attacker has command execution through SSH on the remote machine and is able to enumerate that another user has an active interactive session. By performing a cross-session relay attack he is able to steal the hash and crack the password for the user nigel.mills. The new user is member of the t1_admin groups which has enrolment rights on a certificate template that's vulnerable to ESC1 and by exploiting it we are able to gain SYSTEM privileges on the machine.</description></item><item><title>VULNLAB: Baby</title><link>https://wearethebug.dev/posts/vl-baby/</link><pubDate>Sat, 28 Sep 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-baby/</guid><description>Baby is an easy difficulty Windows machine that features LDAP enumeration, password spraying and exposed credentials. For privilege escalation, the SeBackupPrivilege is exploited to extract registry hives and the NTDS.dit file. A Pass-the-Hash attack can be performed using the uncovered domain hashes ultimately achieving Administrator access.</description></item><item><title>VULNLAB: Unintended</title><link>https://wearethebug.dev/posts/vl-unintended/</link><pubDate>Thu, 25 Apr 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-unintended/</guid><description>Unintended is an Medium chain that provides a hands-on experience with common missteps in Active Directory deployments, demonstrating how attackers can pivot between services to escalate privileges. It blends Linux privilege escalation techniques with Active Directory attack paths, making it a valuable practice ground for both offensive and defensive security practitioners.</description></item><item><title>VULNLAB: Sweep</title><link>https://wearethebug.dev/posts/vl-sweep/</link><pubDate>Fri, 01 Mar 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-sweep/</guid><description>Sweep is a medium difficulty Windows box that involves Active Directory and Lansweeper, a technology asset intelligence tool. The attacker abuses an enabled guest account to gain access to Lansweeper, which has Map Credentials configured, which are login/password combinations for accessing and scanning network assets remotely. The attacker deploys a honeypot SSH server to read the configured credentials. The compromised account is a member of the Lansweeper Discovery group, which has GenericAll ACL over the Lansweeper Admins group. Any account member of the Lansweeper Admins group has administrator privileges on the Lansweeper dashboard. The attacker creates and deploys a package on the Domain Controller to gain complete control.</description></item><item><title>VULNLAB: Sidecar</title><link>https://wearethebug.dev/posts/vl-sidecar/</link><pubDate>Fri, 15 Dec 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-sidecar/</guid><description>Sidecar is a Hard-rated small Active Directory chain that contains 2 Windows machines, however, attacks are not for beginners on Active Directory Pentesting. From initial enumeration through to full domain compromise, including Shell via a .lnk file, NTLM relay, WebDAV coercion, Shadow Credentials, PKINIT abuse, and a Silver Ticket attack.</description></item><item><title>VULNLAB: Control</title><link>https://wearethebug.dev/posts/vl-control/</link><pubDate>Fri, 21 Jul 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-control/</guid><description>Control is a Hard-rated chains focus on a small multi-host Linux environment that simulates a realistic internal network and endpoint-management infrastructure. The lab contains two primary hosts (os.control.vl and intra.control.vl) and a variety of services (web apps, OSCTRL/osquery, SSH, nginx, Docker) that chain together to a full domain compromise. It focuses on exploiting web applications, abusing management tooling (OSCTRL / osquery), and leveraging operational misconfigurations to move from an initial foothold to full root on multiple hosts.</description></item><item><title>VULNLAB: Reflection</title><link>https://wearethebug.dev/posts/vl-reflection/</link><pubDate>Sat, 10 Jun 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-reflection/</guid><description>Reflection is a medium-difficulty Active Directory chain that simulates a vulnerable enterprise environment and challenges users to progress from limited access to Domain Administrator. Including 3 machines, with anonymous SMB bind abuse, MSSQL abuse, NTLM relay attacks, Windows Credential Vault harvesting, Resource-Based Constrained Delegation (RBCD), and finally credential reuse.</description></item></channel></rss>