Openssl

  • Published on
    Enumerated users with crackmapexec, smbclient, and eventually cracked a .pfx file, converted it into a cert.pem and key.pem, then obtained foothold. For root, we have credentials in a LAPS group which provides root.
  • Published on
    Decrypt a file with openssl, gain credentials, take advantage of H2 database for file read root, then exploited h2.py to get root.