Published onAugust 30, 2023HTB TimelapsecrackmapexecOpenSSLevil-winrmnet-userEnumerated users with crackmapexec, smbclient, and eventually cracked a .pfx file, converted it into a cert.pem and key.pem, then obtained foothold. For root, we have credentials in a LAPS group which provides root.
Published onAugust 19, 2023HTB Lightweight22---sshOpenSSLWiresharktcpdumpExploited tcpdump, privesc'd with openssl from the e= capability.
Published onAugust 10, 2023HTB HawkDrupalH2OpenSSLDecrypt a file with openssl, gain credentials, take advantage of H2 database for file read root, then exploited h2.py to get root.