CTF write-ups
Hack The Box, Proving Grounds, TryHackMe, and other CTF-style walkthroughs.

PG • CTF • Algernon • Write-Up
Published: at 12:42 PMProving Grounds Algernon write-up: exploit the SmarterMail Build 6985 RCE bug on port 9998 to get a SYSTEM shell on Windows with almost no extra steps.

PG • CTF • Vault • Write-Up
Published: at 12:41 PMProving Grounds Vault write-up: drop a malicious URL/SCF file into a writable SMB share, capture a domain user hash, get a WinRM shell and abuse SeRestorePrivilege with Utilman.

PG • CTF • Resourced • Write-Up
Published: at 12:40 PMProving Grounds Resourced: domain recon, password spraying, dumping LSA secrets, and abusing Resource-Based Constrained Delegation (RBCD) to compromise the host.

PG • CTF • Nagoya • Write-Up
Published: at 12:39 PMProving Grounds Nagoya: SMB and MSSQL enumeration, Kerberoasting a service account, forging a Silver Ticket, and abusing impersonation tokens to land SYSTEM.