> File upload
> Password reuse
> Kerberos pre-auth timestamp
decryption
> Adcs ESC3
> CA certificate
rexkyris.github.io/posts/certif...
#HackTheBox #penetesting #redteaming #hacking #infosec
> File upload
> Password reuse
> Kerberos pre-auth timestamp
decryption
> Adcs ESC3
> CA certificate
rexkyris.github.io/posts/certif...
#HackTheBox #penetesting #redteaming #hacking #infosec
> CVE-2025-24071
> Shadow Credentials
> AD CS ESC16
rexkyris.github.io/posts/fluffy/
#HackTheBox #CVE #infosec #Pentesting #redteam #hacking
> CVE-2025-24071
> Shadow Credentials
> AD CS ESC16
rexkyris.github.io/posts/fluffy/
#HackTheBox #CVE #infosec #Pentesting #redteam #hacking
> splunk CVE-2024-36991
> password spraying
> shadow credentials
> SeImpersonatePrivilege
#HackTheBox #CVE #infosec #Pentesting #redteam #Hacking
rexkyris.github.io/posts/haze/
> splunk CVE-2024-36991
> password spraying
> shadow credentials
> SeImpersonatePrivilege
#HackTheBox #CVE #infosec #Pentesting #redteam #Hacking
rexkyris.github.io/posts/haze/
> browser cache smuggling
> filefix
> com hijacking
For initial access and persistence.
#CyberSecurity #activedirectory #infosec #Pentesting #Hacking
rexkyris.github.io/posts/beacon...
> browser cache smuggling
> filefix
> com hijacking
For initial access and persistence.
#CyberSecurity #activedirectory #infosec #Pentesting #Hacking
rexkyris.github.io/posts/beacon...
> unauthenticated nfs share
> bruteforcing certificate password
> adcs esc14
> dcsync
rexkyris.github.io/posts/scepter/
#hackthebox #htb #pentesting #cybersecurity #hacking #infosec #activedirectory
> unauthenticated nfs share
> bruteforcing certificate password
> adcs esc14
> dcsync
rexkyris.github.io/posts/scepter/
#hackthebox #htb #pentesting #cybersecurity #hacking #infosec #activedirectory