โŒ

Reading view

There are new articles available, click to refresh the page.

Hack The Box: Fries Machine Walkthrough โ€“ Hard Difficulty

Just wrapped up another Hack The Box machine: Fries (Hard).

TThis machine provided a realistic attack path that started with source code review in Gitea, where leaked credentials in a Git commit led to authenticated PostgreSQL RCE through pgAdmin. From there, I pivoted through the internal Docker network using Ligolo-ng, abused an exposed NFS share and debugfs to gain host access, then exploited PWM configuration weaknesses to capture LDAP credentials. The final stage involved Active Directory enumeration and AD CS (ESC6/ESC7) abuse to obtain an administrator certificate and compromise the domain. A great lab for practising web exploitation, Docker security, Linux privilege escalation, internal pivoting, and Active Directory attacks.

#HackTheBox #HTB #CyberSecurity #PenetrationTesting #RedTeam #ActiveDirectory #ADCS #Docker #Ligolo #PostgreSQL #Gitea #EthicalHacking #Writeup #CTF โ€ฆ

Learn MoreHack The Box: Fries Machine Walkthrough โ€“ Hard Difficulty

The post Hack The Box: Fries Machine Walkthrough โ€“ Hard Difficulty appeared first on Threatninja.net.

I ditched 4 subscription services with the Raspberry Pi gathering dust in my drawer

Subscription creep is a real problem. It is one thing for $20 a month, and then another for $5, and before you know it, you're forking over hundreds monthly for services you might not even use. If you have a Raspberry Pi sitting around waiting for a project, you can turn it into a small self-hosting hub that can replace several subscription services as long as you take the right precautions.

โŒ