<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Weak Password on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/weak-password/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Thu, 22 Aug 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/weak-password/index.xml" rel="self" type="application/rss+xml"/><item><title>VULNLAB: Retro2</title><link>https://wearethebug.dev/posts/vl-retro2/</link><pubDate>Thu, 22 Aug 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-retro2/</guid><description>Retro2 is an easy difficulty Windows machine, which highlights AD exploitation. Initial external enumeration reveals a publicly accessible SMB Share containing a Microsoft Access Database file, which is password protected. After cracking the password, the contents of the accdb file are accessible, enabling the retrieval of the VBA script inside, where AD credentials can be retrieved. Then, by abusing pre-created computer accounts , we gain access to a computer account with the GenericWrite privilege over another account, which, when leveraged, provides access to the system via RDP . Finally, exploiting the RpcEptMapper registry key results in privilege escalation to a system account.</description></item><item><title>VULNLAB: Unintended</title><link>https://wearethebug.dev/posts/vl-unintended/</link><pubDate>Thu, 25 Apr 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-unintended/</guid><description>Unintended is an Medium chain that provides a hands-on experience with common missteps in Active Directory deployments, demonstrating how attackers can pivot between services to escalate privileges. It blends Linux privilege escalation techniques with Active Directory attack paths, making it a valuable practice ground for both offensive and defensive security practitioners.</description></item><item><title>VULNLAB: Sendai</title><link>https://wearethebug.dev/posts/vl-sendai/</link><pubDate>Fri, 15 Mar 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-sendai/</guid><description>Sendai is a medium-difficulty Windows Active Directory machine focused on weak account hygiene, GMSA abuse, and ADCS misconfigurations. Initial access is gained through anonymous SMB enumeration, revealing files that hint at expired accounts with weak passwords. RID brute-forcing identifies users, and login attempts highlight accounts in a forced password reset state. By resetting thomas.powell’s password, the attacker obtains a domain foothold. BloodHound analysis shows that Powell’s group membership can be leveraged to compromise the MGTSVC$ GMSA account, enabling remote code execution on the domain controller. Further local enumeration uncovers inline credentials for clifford.davey, whose CA-OPERATORS group membership grants GenericAll rights over a certificate template. Abusing ESC4/ESC1 conditions with Certipy, the attacker forges a certificate for the administrator account, retrieves its NT hash, and authenticates via WinRM, achieving full domain compromise.</description></item><item><title>VULNLAB: Slonik</title><link>https://wearethebug.dev/posts/vl-slonik/</link><pubDate>Fri, 27 Oct 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-slonik/</guid><description>Slonik is a Medium-difficulty Linux machine that focuses on NFS, PostgreSQL abuse, and privilege escalation through insecure backup automation. Initial access is obtained by enumerating exposed NFS shares and leveraging UID/GID trust relationships to access a home directory. History files within the share reveal database credentials and reference a locally bound PostgreSQL socket. Although direct SSH access is restricted, the socket is tunneled over SSH to interact with the database, where built-in PostgreSQL functionality is leveraged to achieve remote code execution. Privilege escalation is accomplished by monitoring system processes and identifying a root-executed backup script, ultimately leveraging pg_basebackup behavior and SUID permissions to obtain a root shell.</description></item><item><title>VULNLAB: Sync</title><link>https://wearethebug.dev/posts/vl-sync/</link><pubDate>Tue, 25 Apr 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-sync/</guid><description>Sync is an Easy-rated Linux machine on the Vulnlab platform that focuses on service enumeration and exploiting an insecure Rsync configuration, custom hash cracking, and privilege escalation.</description></item></channel></rss>