<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>UAC Bypass on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/uac-bypass/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Tue, 22 Oct 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/uac-bypass/index.xml" rel="self" type="application/rss+xml"/><item><title>VULNLAB: Puppet</title><link>https://wearethebug.dev/posts/vl-puppet/</link><pubDate>Tue, 22 Oct 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-puppet/</guid><description>Puppet is a Medium-rated small active directory chain in which you start with an already running Sliver C2 beacon on an internal system. It is designed to practice operating through a C2 framework in a modern, challenging hybrid environment.</description></item><item><title>VULNLAB: Ifrit</title><link>https://wearethebug.dev/posts/vl-ifrit/</link><pubDate>Sun, 15 Sep 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-ifrit/</guid><description>Ifrit is an Assumed-Breach scenario with the main objective is getting domain administrator privileges in the ifrit.vl Domain. It designed for those with foundational AD and pentesting knowledge to hone covert red teaming skills. Players aim for Domain Admin while evading real-time detections, practicing AD enumeration, exploitation, certificate services, lateral movement, EDR bypass, and relay attacks across multiple forests.</description></item><item><title>VULNLAB: Escape</title><link>https://wearethebug.dev/posts/vl-escape/</link><pubDate>Fri, 16 Feb 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-escape/</guid><description>Escape is an Easy Windows machine where users can log in restricted Kiosk mode via RDP without a password. By exploiting the file:// scheme in Microsoft Edge, attackers can browse the file system, bypass restrictions, and open PowerShell. Further enumeration reveals a Remote Desktop Plus profile, whose password can be extracted using BulletsPassView, allowing admin access and UAC bypass to read the root flag.</description></item><item><title>VULNLAB: Rainbow</title><link>https://wearethebug.dev/posts/vl-rainbow/</link><pubDate>Mon, 17 Jan 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-rainbow/</guid><description>Rainbow is a medium-difficulty Windows machine exposing FTP and HTTP services on ports 21 and 80 &amp; 8080 respectively. From the FTP server, we can retrieve the web server binary and a PowerShell restart script, which is used to relaunch the server in the event of a crash automatically. The HTTP service on port 8080 is vulnerable to an SEH-based buffer overflow and exploiting this yields code execution as the rainbow user. Because rainbow is a member of the Administrators group, we achieved full elevation by bypassing UAC via the FodHelper technique.</description></item></channel></rss>