#
LFI
3 posts
StreamIO — SQL Injection to RFI, Firefox Creds, and LAPS Abuse on a Windows DC
MSSQL injection on a movie streaming site leaks password hashes, chained with LFI and a dangerous PHP eval() to land a shell — then Firefox saved passwords and BloodHound ACL abuse lead to reading LAPS and becoming Administrator.
HTB Pov: ASP.NET ViewState Deserialization and SeDebugPrivilege Abuse
A path traversal on an IIS endpoint leaks the ASP.NET machineKey, enabling ViewState deserialization RCE. Credential extraction from a PSCredential XML file pivots to a user with SeDebugPrivilege, abused to migrate into a SYSTEM process.
Trick — DNS Zone Transfer to Fail2Ban Privilege Escalation
A multi-stage attack chain combining DNS Zone Transfer, SQL Injection, FILE privilege abuse, LFI, SSH key theft, and a Fail2Ban misconfiguration to obtain root access.