BoardLight is an easy difficulty Linux machine that features a Dolibarr instance vulnerable to CVE-2023-30253. This vulnerability is leveraged to gain access as www-data. After enumerating and dumping the web configuration file contents, plaintext credentials lead to SSH access to the machine. Enumerating the system, a SUID binary related to enlightenment is identified which is vulnerable to privilege escalation via CVE-2022-37706 and can be abused to leverage a root shell.
ls ./writeups
# writeups
BoardLight
EscapeTwoEscapeTwo is an easy Windows machine that demonstrates a full Active Directory domain compromise by chaining credential recovery, credential spraying, MSSQL and WinRM access, and the exploitation of a misconfigured ADCS deployment to obtain the Administrator hash.
CicadaCicada is an easy-difficult Windows machine that focuses on beginner Active Directory enumeration and exploitation. In this machine, players will enumerate the domain, identify users, navigate shares, uncover plaintext passwords stored in files, execute a password spray, and use the `SeBackupPrivilege` to achieve full system compromise.
Retro2Retro2 is a Windows AD challenge involving guest SMB access to an MS Access database, LDAP credential recovery from VBA, and lateral movement via machine account abuse, concluding with a privilege escalation to SYSTEM through RpcEptMapper.
RetroComprehensive walk-through of the Retro machine, demonstrating a transition from guest SMB access to Domain Admin. The process involves credential harvesting from public shares, exploiting pre-created computer accounts via Kerberos TGT requests, and leveraging misconfigured AD CS templates (ESC2/ESC3) for identity impersonation.
LockA Windows-based challenge where an exposed Gitea access token leads to source code tampering and remote code execution, followed by credential extraction from mRemoteNG and a final privilege escalation to SYSTEM through the PDF24 Creator vulnerability CVE‑2023‑49147.
EscapeThis challenge involves compromising a Windows host exposed via RDP, starting from a passwordless kiosk account. After enumerating the service with Nmap and bypassing NLA, access to a restricted desktop is obtained. By escaping kiosk mode, extracting encrypted credentials from a third-party application (Remote Desktop Pro), the administrator password is recovered, leading to privilege escalation and full administrative access.
BabyThis challenge involved enumerating a Windows domain environment, obtaining valid credentials, and abusing SeBackupPrivilege to extract and decrypt the NTDS database, ultimately achieving domain administrator access.
No writeups match your search.