
ippsec
@ippsec
Followers
119K
Following
1K
Media
610
Statuses
5K
Joined December 2016
#HackTheBox EscapeTwo Video is now up! This is an easy Windows box that starts out with finding an MSSQL Password on a File Share and ends with taking over a user, which can then take over a certificate template (ESC4). Check it out:
2
20
162
#HackTheBox BigBang Video is up! And it shows something I didn't know was possible, getting RCE on a file_get_contents call within PHP. It is patched as of PHP 8.3.8 (~June 2024) but I'm sure there are unpatched webservers out there.
1
27
152
I'm at a loss for words with how quick the netexec team puts in fixes. Video has been out for 4 hours, and @mpgn_x64 already put in a fix. Some open source communities are just flat out amazing.
The HackTheBox Vintage video is now up! This was a Hard Assumed Breach Box that was almost 100% Active Directory, the only piece that isn't technically AD is decrypting the DPAPI Credential Store. Definitely a fun one for those AD Lovers
2
32
290
RT @IAMERICAbooted: If you have valid user creds and you know the victim uses Confluence and SSO, but M365 requires MFA, you can use those….
0
10
0
#HackTheBox LinkVortex video is up! An easy box that starts off with discovering a .git dir, which contains a cached file with a cred, that leads to exploiting an outdated version of blogging software. Root is a bash script which we exploit 3 diff ways
1
15
90
#HackTheBox Ghost is up! This box feels like you are attacking a small network. Some things we will exploit: LDAP Injection, Rust Webserver, AD Federation, MSSQL Linked Databases, and escalating from a child -> Parent domain via bi-directional trust.
3
38
189
#HackTheBox MonitorsThree is up! The root of this box features exploiting backup software to create and restore a malicious backup. There's also a pretty good example of when to use error based SQL injection as part of getting a foothold on the box.
2
20
137