<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Python on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/python/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Sat, 12 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/python/index.xml" rel="self" type="application/rss+xml"/><item><title>bloodyAD</title><link>https://wearethebug.dev/posts/bloodyad/</link><pubDate>Sat, 12 Sep 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/bloodyad/</guid><description>Active Directory privilege escalation swiss-army knife. Quick reference for common bloodyAD operations.</description></item><item><title>NetExec Advanced</title><link>https://wearethebug.dev/posts/netexec-advanced/</link><pubDate>Fri, 28 Aug 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/netexec-advanced/</guid><description>Follow-up to the NetExec cheatsheet: deeper Active Directory abuse techniques, delegation attacks, and operational tooling for experienced operators.</description></item><item><title>NetExec</title><link>https://wearethebug.dev/posts/netexec/</link><pubDate>Sat, 25 Jul 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/netexec/</guid><description>Swiss-army knife for Active Directory and network protocol enumeration/exploitation, successor to CrackMapExec.</description></item><item><title>VULNLAB: Flagsalad</title><link>https://wearethebug.dev/posts/vl-flagsalad/</link><pubDate>Wed, 08 Jan 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-flagsalad/</guid><description>Flagsalad is a medium-severity crypto challenge where the flag is encoded as a vector, multiplied by a random matrix, and obscured with noise.</description></item><item><title>VULNLAB: Share</title><link>https://wearethebug.dev/posts/vl-share/</link><pubDate>Wed, 08 Jan 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-share/</guid><description>Share is an easy crypto challenge where the flag is encoded in a polynomial function f(x) = flag + a₁x + a₂x² + a₃x³, with 10 known points (x, f(x)) provided.</description></item><item><title>VULNLAB: Reaper2</title><link>https://wearethebug.dev/posts/vl-reaper2/</link><pubDate>Fri, 10 May 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-reaper2/</guid><description>ReaperTwo is an Insane Windows machine that involves both browser and kernel exploitation. The attack chain begins with enumeration of exposed services and access to an SMB share containing development artifacts. A vulnerable web application leveraging the V8 JavaScript engine allows for arbitrary JavaScript execution, which is escalated to remote code execution through a type confusion vulnerability in Harmony Set methods, combined with WebAssembly-based shellcode execution. After gaining an initial foothold as a low-privileged user, privilege escalation is achieved by exploiting a vulnerable kernel driver that exposes a function pointer execution primitive. The exploit bypasses modern protections such as kASLR, DEP, and SMEP by leaking kernel addresses via MSRs, performing a stack pivot, and constructing a ROP chain to modify Page Table Entries (PTEs). Finally, custom kernel shellcode is executed to steal a SYSTEM token, resulting in full system compromise.</description></item><item><title>VULNLAB: Reaper</title><link>https://wearethebug.dev/posts/vl-reaper/</link><pubDate>Fri, 18 Aug 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-reaper/</guid><description>Reaper is an Insane Windows machine that begins with an exposed FTP service. Within the FTP share resides a Windows binary vulnerable to both format-string and buffer-overflow attacks. By exploiting these flaws, an attacker can leak sensitive memory regions, hijack the program’s execution flow, and ultimately obtain a reverse shell on the target as the user keysvc. After gaining initial access, the attacker discovers a file containing a DPAPI blob. Once decrypted, this blob provides valid credentials for RDP access as keysvc. Continued enumeration reveals a custom kernel driver present and actively running on the system. Through reverse-engineering the driver, the attacker determines that it permits arbitrary kernel-level writes. Leveraging this capability, the attacker is able to steal a privileged token and escalate to a full SYSTEM shell (NT AUTHORITY\SYSTEM).</description></item><item><title>VULNLAB: Rainbow</title><link>https://wearethebug.dev/posts/vl-rainbow/</link><pubDate>Mon, 17 Jan 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-rainbow/</guid><description>Rainbow is a medium-difficulty Windows machine exposing FTP and HTTP services on ports 21 and 80 &amp; 8080 respectively. From the FTP server, we can retrieve the web server binary and a PowerShell restart script, which is used to relaunch the server in the event of a crash automatically. The HTTP service on port 8080 is vulnerable to an SEH-based buffer overflow and exploiting this yields code execution as the rainbow user. Because rainbow is a member of the Administrators group, we achieved full elevation by bypassing UAC via the FodHelper technique.</description></item></channel></rss>