HTB · Medium
StreamIO — SQL Injection to RFI, Firefox Creds, and LAPS Abuse on a Windows DC
MSSQL injection on a movie streaming site leaks password hashes, chained with LFI and a dangerous PHP eval() to land a shell — then Firefox saved passwords and BloodHound ACL abuse lead to reading LAPS and becoming Administrator.