<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>RCE on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/rce/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Sun, 17 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/rce/index.xml" rel="self" type="application/rss+xml"/><item><title>HTB: SmartHire</title><link>https://wearethebug.dev/posts/htb-smarthire/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-smarthire/</guid><description>SmartHire is a Medium-rated Linux machine that chains MLflow unsafe deserialization (CVE-2024-37054) to pivot from an unauthenticated web portal into a foothold as the svcweb user. Root falls to a Python .pth injection via a group-writable plugin directory, abused through a passwordless sudo misconfiguration to spawn a SUID shell and fully compromise the box.</description></item><item><title>HTB: Heron</title><link>https://wearethebug.dev/posts/htb-heron/</link><pubDate>Fri, 14 Nov 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-heron/</guid><description>Heron is a small Active Directory scenario that involves typical vulnerabilities found in real word company environments. It's designed for penetration testers and red teamers in search of a quick and challenging lab.</description></item><item><title>VULNLAB: Shinra</title><link>https://wearethebug.dev/posts/vl-shinra/</link><pubDate>Sun, 09 Mar 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-shinra/</guid><description>Shinra is a Hard-rated Red Team lab designed for those with foundational AD and pentesting knowledge to refine covert red teaming skills. Players focus on AD enumeration, exploitation, certificate services, lateral movement, phishing, CI/CD attacks, EDR bypass, backdooring apps, and relay attacks while evading real-time detections.</description></item><item><title>VULNLAB: Down</title><link>https://wearethebug.dev/posts/vl-down/</link><pubDate>Fri, 20 Sep 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-down/</guid><description>Down is an easy-rated Linux machine that involves exploiting an arbitrary file read by bypassing a protocol-based filter to discover the source code of the running PHP web app, eventually, a remote code execution to gain an initial foothold. The attacker finds a readable pswm encrypted file in the user's home directory. The pwsm uses Python's cryptocode module and a master password to encrypt and decrypt the data. The attacker is supposed to write a small script to decrypt the blob and compromise the user. The compromised user is a member of the sudo group, allowing the user to escalate and obtain root access.</description></item><item><title>VULNLAB: Lustrous2</title><link>https://wearethebug.dev/posts/vl-lustrous2/</link><pubDate>Wed, 11 Sep 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-lustrous2/</guid><description>LustrousTwo is a hard-rated Windows machine that deals with LDAP signing, channel binding, and disabled NTLM authentication. The machine has a web server vulnerable to arbitrary file read, which helps attackers capture a Net-NTLMv2 hash for the service account, using it to request Service Tickets via s4u2self, a stealthier alternative to Silver Ticket, to bypass protective measures like Account is sensitive and cannot be delegated. After reversing and auditing the source code, the attacker achieves Remote Code Execution. For privilege escalation, the attacker exploits a misconfigured, insecure Velociraptor installation.</description></item><item><title>VULNLAB: Watcher</title><link>https://wearethebug.dev/posts/vl-watcher/</link><pubDate>Wed, 24 Jul 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-watcher/</guid><description>Watcher is a medium difficulty Linux box that involves Zabbix and is vulnerable to CVE-2024-22120, which allows an attacker to gain Remote Code Execution. After getting RCE, the attacker discovers that a web app can be backdoored, allowing them to gain credentials for a user account. The user is allowed to access TeamCity, which is running as root, and an agent terminal is active, allowing an attacker to gain a reverse shell as the root user.</description></item><item><title>VULNLAB: Reset</title><link>https://wearethebug.dev/posts/vl-reset/</link><pubDate>Wed, 07 Feb 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-reset/</guid><description>Reset is an Easy difficulty Linux machine which showcases abusing a password reset functionality in a web application following a log poisoning attack, to achieve Remote Code Execution. For privilege escalation, Rservices are abused, then a detached tmux session is used to abuse sudo privileges on nano text editor and execute commands as the root user.</description></item><item><title>VULNLAB: Forgotten</title><link>https://wearethebug.dev/posts/vl-forgotten/</link><pubDate>Fri, 08 Dec 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-forgotten/</guid><description>Forgotten is an Easy Linux machine on VulnLab that challenges players to exploit an unfinished LimeSurvey installation by deploying a controlled MariaDB instance to gain admin access. Players then upload a malicious plugin for remote code execution inside a Docker container, discover an environment variable for host access, and escalate privileges by chaining low host access with container root privileges via a setuid binary.</description></item><item><title>VULNLAB: Hybrid</title><link>https://wearethebug.dev/posts/vl-hybrid/</link><pubDate>Thu, 22 Jun 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-hybrid/</guid><description>Hybrid is an Easy-rated, simplified Active Directory chain with 2 servers MAIL01 (Roundcube webmail) and DC01. Exploited a vulnerable Roundcube plugin via a crafted email, escalated privileges via NFS, and abused AD CS with certipy to achieve Domain Admin.</description></item><item><title>VULNLAB: Job</title><link>https://wearethebug.dev/posts/vl-job/</link><pubDate>Sat, 27 Nov 2021 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-job/</guid><description>Job is a Medium-rated Windows box. It runs an SMTP server and its website accepts LibreOffice-compatible documents, providing a vector to deliver a document with embedded macros that leads to remote code execution as user jack.black. jack.black is a member of the DEVELOPERS group, which has write access to the IIS web root, allowing files to be placed in the webroot and achieve code execution as the IIS AppPool service account. The IIS AppPool account has the SeImpersonate privilege, creating conditions that allow token-impersonation techniques to be used to escalate privileges to Administrator.</description></item></channel></rss>