<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Xp_cmdshell on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/xp_cmdshell/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Tue, 14 Feb 2023 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/xp_cmdshell/index.xml" rel="self" type="application/rss+xml"/><item><title>VULNLAB: Breach</title><link>https://wearethebug.dev/posts/vl-breach/</link><pubDate>Tue, 14 Feb 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-breach/</guid><description>Breach is a medium difficulty Windows machine, where guest access to an SMB share is available. By leveraging write permissions on that SMB share, NTLMv2 hashes of a domain user are captured to obtain valid credentials. With access as a low-privileged domain user, a kerberoastable service account (svc_mssql) is revealed. After getting access to the service account, a Silver Ticket attack is performed to impersonate the `Administrator` user and gain access to Microsoft SQL Server. Through the xp_cmdshell feature, remote code execution is achieved as the svc_mssql service account. Finally, privilege escalation is performed by abusing the SeImpersonatePrivilege privilege.</description></item></channel></rss>