<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Season 11 on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/season-11/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Sat, 12 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/season-11/index.xml" rel="self" type="application/rss+xml"/><item><title>HTB: TrustFall</title><link>https://wearethebug.dev/posts/htb-trustfall/</link><pubDate>Sat, 12 Sep 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-trustfall/</guid><description>TrustFall is an Insane-rated hybrid machine featuring a complex, multi-stage kill chain that bridges external web exploitation with deep Active Directory and ADCS abuse. Initial access requires chaining an osTicket arbitrary file read with a legacy telnetd vulnerability to compromise a Linux pivot host. Lateral movement involves intricate ACL/OU inheritance abuse, AS-REP roasting, and a sophisticated WSUS Man-in-the-Middle attack powered by a rogue certificate (ESC17) for local privilege escalation. The endgame tests cryptographic weaknesses and PKI administration, requiring the prediction of a time-seeded VBScript PRNG to compromise a PKI Manager, ultimately leading to full Certificate Authority takeover (ESC7) and Domain Admin compromise via DCSync.</description></item><item><title>HTB: DanglingTree</title><link>https://wearethebug.dev/posts/htb-danglingtree/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-danglingtree/</guid><description>DanglingTree is a Medium-difficulty Windows machine focusing on Windows Admin Center (WAC) exploitation and cryptographic analysis. The foothold involves exploiting CVE-2026-26119 in WAC to execute PowerShell commands and abusing SmarterMail vulnerabilities (CVE-2026-23760/CVE-2026-24423) to gain initial access. The path to root requires DLL decompilation for DES decryption, DPAPI credential recovery, ACL abuse, and ADCS exploitation to escalate privileges to Administrator.</description></item><item><title>HTB: DarkZeroReturns</title><link>https://wearethebug.dev/posts/htb-darkzeroreturns/</link><pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-darkzeroreturns/</guid><description>Heron is an advanced Active Directory scenario featuring complex multi-step exploitation chains including web entry points (like SSTI leading to RCE), cross-realm Kerberos trust abuses, CI/CD runner pivots, and forest trust navigation.</description></item><item><title>HTB: Reactor</title><link>https://wearethebug.dev/posts/htb-reactor/</link><pubDate>Sun, 24 May 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-reactor/</guid><description>Reactor is an Easy-rated Linux machine where initial access is gained by exploiting CVE-2025-55182 (React2Shell), a pre-auth RCE in React Server Components triggered via a crafted Next-Action header, yielding a shell as node. Credentials are extracted from a SQLite database dump, cracked to reveal valid SSH access for lateral movement to the user engineer. Privilege escalation abuses an exposed Node.js debug port (9229), reached via SSH tunnel, to call process.mainModule.require and execute commands as root.</description></item><item><title>HTB: SmartHire</title><link>https://wearethebug.dev/posts/htb-smarthire/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-smarthire/</guid><description>SmartHire is a Medium-rated Linux machine that chains MLflow unsafe deserialization (CVE-2024-37054) to pivot from an unauthenticated web portal into a foothold as the svcweb user. Root falls to a Python .pth injection via a group-writable plugin directory, abused through a passwordless sudo misconfiguration to spawn a SUID shell and fully compromise the box.</description></item></channel></rss>