A detailed walkthrough of the HackTheBox machine 'Bruno', a Windows Active Directory domain controller. The attack chain starts with anonymous FTP access to download a .NET scanning application, which is reverse-engineered to discover a ZipSlip vulnerability in its zip extraction logic. This is exploited to drop a malicious DLL
•30m read time• From 0xdf.gitlab.io
Sort: