A detailed walkthrough of the HackTheBox machine 'Bruno', a Windows Active Directory domain controller. The attack chain starts with anonymous FTP access to download a .NET scanning application, which is reverse-engineered to discover a ZipSlip vulnerability in its zip extraction logic. This is exploited to drop a malicious DLL

30m read timeFrom 0xdf.gitlab.io
Post cover image
Table of contents
Box InfoReconAuth as svc_scanShell as svc_scanShell as Administrator

Sort: