<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>SMB Share on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/smb-share/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Thu, 17 Apr 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/smb-share/index.xml" rel="self" type="application/rss+xml"/><item><title>VULNLAB: Shiva</title><link>https://wearethebug.dev/posts/vl-shiva/</link><pubDate>Thu, 17 Apr 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-shiva/</guid><description>Shiva is an insane-difficulty Red Team lab on Vulnlab that simulates a hardened hybrid Active Directory environment (on-premises and Azure) with 10+ machines and active users. All protected by Endpoint Detection and Response (EDR), SIEM solutions, Windows Defender Application Control (WDAC), and common enterprise software.</description></item><item><title>VULNLAB: Shinra</title><link>https://wearethebug.dev/posts/vl-shinra/</link><pubDate>Sun, 09 Mar 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-shinra/</guid><description>Shinra is a Hard-rated Red Team lab designed for those with foundational AD and pentesting knowledge to refine covert red teaming skills. Players focus on AD enumeration, exploitation, certificate services, lateral movement, phishing, CI/CD attacks, EDR bypass, backdooring apps, and relay attacks while evading real-time detections.</description></item><item><title>VULNLAB: Odori</title><link>https://wearethebug.dev/posts/vl-odori/</link><pubDate>Fri, 17 Jan 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-odori/</guid><description>Odori is a medium-difficulty machine on Vulnlab that involves gaining access to a Bitlocker encrypted disk image, in order to retrieve DPAPI protected credentials. Furthermore we will use SFTP to bypass login restrictions and manipulate a python cache file to gain root privileges.</description></item><item><title>VULNLAB: Shibuya</title><link>https://wearethebug.dev/posts/vl-shibuya/</link><pubDate>Thu, 21 Nov 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-shibuya/</guid><description>Shibuya is a Medium Windows machine that starts of with the SMB port exposed. Enumerating possible usernames through Kerberos an attacker is able to find the valid machine account red:red. With these credentials, he can further enumerate the remote users and discover that the user svc_autojoin has a password in its description. With this account in hand, he is able to discover some Windows Imaging Format (.wmi) files that contain hashes for the user simon.watson. Now, the attacker has command execution through SSH on the remote machine and is able to enumerate that another user has an active interactive session. By performing a cross-session relay attack he is able to steal the hash and crack the password for the user nigel.mills. The new user is member of the t1_admin groups which has enrolment rights on a certificate template that's vulnerable to ESC1 and by exploiting it we are able to gain SYSTEM privileges on the machine.</description></item><item><title>VULNLAB: Cicada</title><link>https://wearethebug.dev/posts/vl-cicada/</link><pubDate>Thu, 26 Sep 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-cicada/</guid><description>Cicada is a Medium-rated Windows Active Directory machine hosted on the VulnLab platform, that involves discovering a password inside an image on a public share. With that password an attacker is able to discover that the machine is vulnerable to ESC8 and can use Kerberos relaying to bypass self-relay restrictions in order to get a certificate as the machine account itself. With this new certificate, we are able to dump the hashes of the Administrator user and thus compromise the whole domain.</description></item><item><title>VULNLAB: Retro2</title><link>https://wearethebug.dev/posts/vl-retro2/</link><pubDate>Thu, 22 Aug 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-retro2/</guid><description>Retro2 is an easy difficulty Windows machine, which highlights AD exploitation. Initial external enumeration reveals a publicly accessible SMB Share containing a Microsoft Access Database file, which is password protected. After cracking the password, the contents of the accdb file are accessible, enabling the retrieval of the VBA script inside, where AD credentials can be retrieved. Then, by abusing pre-created computer accounts , we gain access to a computer account with the GenericWrite privilege over another account, which, when leveraged, provides access to the system via RDP . Finally, exploiting the RpcEptMapper registry key results in privilege escalation to a system account.</description></item><item><title>VULNLAB: Wutai</title><link>https://wearethebug.dev/posts/vl-wutai/</link><pubDate>Tue, 20 Aug 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-wutai/</guid><description>Wutai is a Medium-difficulty Red Team lab featuring 15+ machines across multiple networks, domains, and forests, challenging players to achieve Enterprise Admin status. Players refine AD enumeration, exploitation, certificate services, lateral movement, EDR bypass, reverse engineering, and covert operations while abusing trust relationships.</description></item><item><title>VULNLAB: Vigilant</title><link>https://wearethebug.dev/posts/vl-vigilant/</link><pubDate>Mon, 15 Apr 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-vigilant/</guid><description>Vigilant is a Hard hybrid Active Directory chain. The environment consists of a domain-joined Linux system and a Windows Domain Controller, presenting a realistic enterprise attack surface. It designed to evaluate penetration testing capabilities in hybrid Windows-Linux environments. Participants begin with zero initial access and must systematically escalate privileges to achieve Domain Administrator-level compromise.</description></item><item><title>VULNLAB: Sendai</title><link>https://wearethebug.dev/posts/vl-sendai/</link><pubDate>Fri, 15 Mar 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-sendai/</guid><description>Sendai is a medium-difficulty Windows Active Directory machine focused on weak account hygiene, GMSA abuse, and ADCS misconfigurations. Initial access is gained through anonymous SMB enumeration, revealing files that hint at expired accounts with weak passwords. RID brute-forcing identifies users, and login attempts highlight accounts in a forced password reset state. By resetting thomas.powell’s password, the attacker obtains a domain foothold. BloodHound analysis shows that Powell’s group membership can be leveraged to compromise the MGTSVC$ GMSA account, enabling remote code execution on the domain controller. Further local enumeration uncovers inline credentials for clifford.davey, whose CA-OPERATORS group membership grants GenericAll rights over a certificate template. Abusing ESC4/ESC1 conditions with Certipy, the attacker forges a certificate for the administrator account, retrieves its NT hash, and authenticates via WinRM, achieving full domain compromise.</description></item><item><title>VULNLAB: Sidecar</title><link>https://wearethebug.dev/posts/vl-sidecar/</link><pubDate>Fri, 15 Dec 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-sidecar/</guid><description>Sidecar is a Hard-rated small Active Directory chain that contains 2 Windows machines, however, attacks are not for beginners on Active Directory Pentesting. From initial enumeration through to full domain compromise, including Shell via a .lnk file, NTLM relay, WebDAV coercion, Shadow Credentials, PKINIT abuse, and a Silver Ticket attack.</description></item><item><title>VULNLAB: Delegate</title><link>https://wearethebug.dev/posts/vl-delegate/</link><pubDate>Fri, 06 Oct 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-delegate/</guid><description>Delegate is a medium-rated Windows machine that involves Active Directory attacks. The machine has the guest account enabled, allowing the attacker to read files that contain hard-coded credentials. The credentials allow us to WriteProperty of a user account that is allowed to have WinRM sessions on the Domain Controller. The compromised user has the SeEnableDelegationPrivilege privilege assigned, which allows us to modify the TRUSTED_FOR_DELEGATION flag for AD objects, enabling us to perform Unconstrained Delegation.</description></item><item><title>VULNLAB: Push</title><link>https://wearethebug.dev/posts/vl-push/</link><pubDate>Fri, 22 Sep 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-push/</guid><description>Push is a Hard-rated small Windows Active Directory chain featuring a one domain controller and one member server. This chain focuses on advanced attack techniques including ClickOnce application exploitation, SCCM coercion, and ADCS exploitation via Golden Certificate attacks.</description></item><item><title>VULNLAB: Retro</title><link>https://wearethebug.dev/posts/vl-retro/</link><pubDate>Fri, 11 Aug 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-retro/</guid><description>Retro is an Easy Windows machine that showcases an Active Directory Domain Controller. Through SMB enumeration and pre-created machine account exploitation, we gain access to the system. Through the exploitation of the Active Directory Certificate Service and specifically by using the ESC1 attack, which involves exploiting certificate templates to impersonate the Administrative user, privilege escalation is achieved.</description></item><item><title>VULNLAB: Reflection</title><link>https://wearethebug.dev/posts/vl-reflection/</link><pubDate>Sat, 10 Jun 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-reflection/</guid><description>Reflection is a medium-difficulty Active Directory chain that simulates a vulnerable enterprise environment and challenges users to progress from limited access to Domain Administrator. Including 3 machines, with anonymous SMB bind abuse, MSSQL abuse, NTLM relay attacks, Windows Credential Vault harvesting, Resource-Based Constrained Delegation (RBCD), and finally credential reuse.</description></item><item><title>VULNLAB: Breach</title><link>https://wearethebug.dev/posts/vl-breach/</link><pubDate>Tue, 14 Feb 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-breach/</guid><description>Breach is a medium difficulty Windows machine, where guest access to an SMB share is available. By leveraging write permissions on that SMB share, NTLMv2 hashes of a domain user are captured to obtain valid credentials. With access as a low-privileged domain user, a kerberoastable service account (svc_mssql) is revealed. After getting access to the service account, a Silver Ticket attack is performed to impersonate the `Administrator` user and gain access to Microsoft SQL Server. Through the xp_cmdshell feature, remote code execution is achieved as the svc_mssql service account. Finally, privilege escalation is performed by abusing the SeImpersonatePrivilege privilege.</description></item><item><title>VULNLAB: Intercept</title><link>https://wearethebug.dev/posts/vl-intercept/</link><pubDate>Sat, 25 Dec 2021 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-intercept/</guid><description>Intercept is a small Active Directory scenario rated as Hard that provides hands-on experience with common Active Directory vulnerabilities and misconfigurations, demonstrating relay attacks and authentication coercion attacks can be used to get access to the domain.</description></item></channel></rss>