Categories
Tags
Active Directory Arbitrary File Read BackdropCMS bbot Bookstack CVE-2024-36991 Cypher Injection DPAPI Easy GenericAll GenericWrite Gibbon LMS Gitea GodPotato GPO Hard ImageMagick Insane Kerberos Linux Medium Neo4j Password Spraying Pre2K Pyjail Race Condition RBCD Recycle Bin SeImpersonatePrivilege Shadow Credentials Splunk Targeted ASREProasting Teampass TOTP Windows WriteOwner
Vintage
2025-01-15
Vintage is a challenging Active Directory machine characterized by disabled NTLM authentication, enabled antivirus protection, and complex security configurations. The machine involves exploiting a Pre-2000 computer account, leveraging multiple ACL/ACE vulnerabilities, decrypting Data Protection API (DPAPI) secrets, and manipulating Resource-Based Constrained Delegation.
2327 words
|
12 minutes
