Hack The Box: University Machine Walkthrough ā Insane Walkthrough
Compromised university.htb by exploiting ReportLab RCE (CVE-2023-33733) to gain initial access as wao. Forged a professor certificate to impersonate george, then uploaded a malicious lecture to compromise Martin.T.
Escalated privileges by exploiting a scheduled task with a malicious .url file, used LocalPotato (CVE-2023-21746) for elevation on WS-3, and abused SeBackupPrivilege to extract NTDS.dit, ultimately retrieving Domain Admin credentials.
š A great hands-on challenge combining web exploitation, privilege escalation, and Active Directory abuse.
#CyberSecurity #RedTeam #CTF #PrivilegeEscalation #HTB #InfoSec #WindowsExploitation #PenetrationTesting #EthicalHacking #HackTheBox
The post Hack The Box: University Machine Walkthrough ā Insane Walkthrough appeared first on Threatninja.net.