<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>PTH on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/pth/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Sat, 28 Sep 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/pth/index.xml" rel="self" type="application/rss+xml"/><item><title>VULNLAB: Baby</title><link>https://wearethebug.dev/posts/vl-baby/</link><pubDate>Sat, 28 Sep 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-baby/</guid><description>Baby is an easy difficulty Windows machine that features LDAP enumeration, password spraying and exposed credentials. For privilege escalation, the SeBackupPrivilege is exploited to extract registry hives and the NTDS.dit file. A Pass-the-Hash attack can be performed using the uncovered domain hashes ultimately achieving Administrator access.</description></item></channel></rss>