<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Reverse Engineering on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/reverse-engineering/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Sun, 09 Mar 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/reverse-engineering/index.xml" rel="self" type="application/rss+xml"/><item><title>VULNLAB: Shinra</title><link>https://wearethebug.dev/posts/vl-shinra/</link><pubDate>Sun, 09 Mar 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-shinra/</guid><description>Shinra is a Hard-rated Red Team lab designed for those with foundational AD and pentesting knowledge to refine covert red teaming skills. Players focus on AD enumeration, exploitation, certificate services, lateral movement, phishing, CI/CD attacks, EDR bypass, backdooring apps, and relay attacks while evading real-time detections.</description></item><item><title>VULNLAB: Atlas</title><link>https://wearethebug.dev/posts/vl-atlas/</link><pubDate>Sun, 19 Jan 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-atlas/</guid><description>Atlas is a Hard-difficulty machine focusing on Java deserialization and .NET cryptographic analysis. The foothold involves exploiting a vulnerable Castor XML library in a Spring Boot app and reverse-engineering a .NET application to recover credentials.</description></item><item><title>VULNLAB: Lustrous2</title><link>https://wearethebug.dev/posts/vl-lustrous2/</link><pubDate>Wed, 11 Sep 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-lustrous2/</guid><description>LustrousTwo is a hard-rated Windows machine that deals with LDAP signing, channel binding, and disabled NTLM authentication. The machine has a web server vulnerable to arbitrary file read, which helps attackers capture a Net-NTLMv2 hash for the service account, using it to request Service Tickets via s4u2self, a stealthier alternative to Silver Ticket, to bypass protective measures like Account is sensitive and cannot be delegated. After reversing and auditing the source code, the attacker achieves Remote Code Execution. For privilege escalation, the attacker exploits a misconfigured, insecure Velociraptor installation.</description></item><item><title>VULNLAB: Vigilant</title><link>https://wearethebug.dev/posts/vl-vigilant/</link><pubDate>Mon, 15 Apr 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-vigilant/</guid><description>Vigilant is a Hard hybrid Active Directory chain. The environment consists of a domain-joined Linux system and a Windows Domain Controller, presenting a realistic enterprise attack surface. It designed to evaluate penetration testing capabilities in hybrid Windows-Linux environments. Participants begin with zero initial access and must systematically escalate privileges to achieve Domain Administrator-level compromise.</description></item><item><title>VULNLAB: Reaper</title><link>https://wearethebug.dev/posts/vl-reaper/</link><pubDate>Fri, 18 Aug 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-reaper/</guid><description>Reaper is an Insane Windows machine that begins with an exposed FTP service. Within the FTP share resides a Windows binary vulnerable to both format-string and buffer-overflow attacks. By exploiting these flaws, an attacker can leak sensitive memory regions, hijack the program’s execution flow, and ultimately obtain a reverse shell on the target as the user keysvc. After gaining initial access, the attacker discovers a file containing a DPAPI blob. Once decrypted, this blob provides valid credentials for RDP access as keysvc. Continued enumeration reveals a custom kernel driver present and actively running on the system. Through reverse-engineering the driver, the attacker determines that it permits arbitrary kernel-level writes. Leveraging this capability, the attacker is able to steal a privileged token and escalate to a full SYSTEM shell (NT AUTHORITY\SYSTEM).</description></item><item><title>VULNLAB: Trusted</title><link>https://wearethebug.dev/posts/vl-trusted/</link><pubDate>Tue, 20 Sep 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-trusted/</guid><description>Trusted is an Easy small Active Directory chain involving two domain controllers (labdc.lab.trusted.vl and trusteddc.trusted.vl) that focuses on web vulnerabilities, local privilege escalation, and cross-domain trust abuse. An internal network access is provided with no credentials, and the goal is to assess the security posture of the AD environment.</description></item><item><title>VULNLAB: Rainbow2</title><link>https://wearethebug.dev/posts/vl-rainbow2/</link><pubDate>Mon, 06 Jun 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-rainbow2/</guid><description>Rainbow2 is a Hard Windows machine centered around exploit development for a custom network file-sharing service. Initial enumeration reveals anonymous FTP access and an unknown service listening on TCP port 2121. The FTP share exposes the vulnerable service binary, a developer README, and a copy of SysWOW64\kernel32.dll. The README confirms that the service was rebuilt with ASLR, DEP, and GS enabled. Static and dynamic analysis then shows that the service is still vulnerable to a format string issue and a stack-based overflow that overwrites the SEH chain. The format string leak provides a reliable ASLR bypass by disclosing a pointer inside filesrv.exe; the SEH overwrite provides control of the exception handler; and a ROP chain calls VirtualAlloc to bypass DEP. Privilege escalation is achieved by abusing SeDebugPrivilege to migrate into a SYSTEM process.</description></item><item><title>VULNLAB: Unchained</title><link>https://wearethebug.dev/posts/vl-unchained/</link><pubDate>Fri, 04 Mar 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-unchained/</guid><description>Unchained is a Medium-rated Linux machine available on Vulnlab platform. Starting with NFS share enumeration then a source code analysis allows a JSONPICKLE deserialization to obtain a reverse shell as user. For the privilege escalation, CVE-2021-44730 (Dirty snap-confine LPE) or CVE-2022-0847 (DirtyPipe) can be exploited.</description></item><item><title>VULNLAB: Rainbow</title><link>https://wearethebug.dev/posts/vl-rainbow/</link><pubDate>Mon, 17 Jan 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-rainbow/</guid><description>Rainbow is a medium-difficulty Windows machine exposing FTP and HTTP services on ports 21 and 80 &amp; 8080 respectively. From the FTP server, we can retrieve the web server binary and a PowerShell restart script, which is used to relaunch the server in the event of a crash automatically. The HTTP service on port 8080 is vulnerable to an SEH-based buffer overflow and exploiting this yields code execution as the rainbow user. Because rainbow is a member of the Administrators group, we achieved full elevation by bypassing UAC via the FodHelper technique.</description></item></channel></rss>