 
      
    | You are here | blog.brokennetwork.ca | ||
| | | | | blog.thestateofme.com | |
| | | | | IT mixology and other thoughts about tech, life the universe and everything | |
| | | | | harrisonsand.com | |
| | | | | This blog post walks through the efforts of reverse engineering the Zaptec Pro, an electric vehicle charger found in many parking lots and apartment buildings around Norway. | |
| | | | | saccade.com | |
| | | | | ||
| | | | | 0xdf.gitlab.io | |
| | | One of the neat things about HTB is that it exposes Windows concepts unlike any CTF I'd come across before it. Forest is a great example of that. It is a domain controller that allows me to enumerate users over RPC, attack Kerberos with AS-REP Roasting, and use Win-RM to get a shell. Then I can take advantage of the permissions and accesses of that user to get DCSycn capabilities, allowing me to dump hashes for the administrator user and get a shell as the admin. In Beyond Root, I'll look at what DCSync looks like on the wire, and look at the automated task cleaning up permissions. | ||