<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Tgtdeleg on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/tgtdeleg/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Thu, 13 Jun 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/tgtdeleg/index.xml" rel="self" type="application/rss+xml"/><item><title>VULNLAB: Heron</title><link>https://wearethebug.dev/posts/vl-heron/</link><pubDate>Thu, 13 Jun 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-heron/</guid><description>Heron is a medium-difficulty chain hosted on Vulnlab, featuring an assumed breach from a domain-joined linux jump server access to domain controller. Starting with an enumeration of the internal website for domain users and performing AS-REP roasting, decrypting GPP password from the sysvol share, leading to smb share having write access to web.config, gaining a shell by using AspNetCoreModule for executing powershell commands which lead to finding linux admin’s credentials, reusing the same password that will lead to another user which has WriteAccountRestrictions on dc that leads to resource based delegation</description></item></channel></rss>