<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Medium on João Vítor Moutinho Bonin</title>
    <link>https://joaobonin.com/tags/medium/</link>
    <description>Recent content in Medium on João Vítor Moutinho Bonin</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Mon, 01 Jun 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://joaobonin.com/tags/medium/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>HTB Monteverde - Azure AD Connect Password Extraction</title>
      <link>https://joaobonin.com/posts/htb-monteverde/</link>
      <pubDate>Mon, 01 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://joaobonin.com/posts/htb-monteverde/</guid>
      <description>Monteverde is a Medium Windows Active Directory box from HackTheBox. We enumerate domain users via null session, discover a username-as-password credential for SABatchJobs, find an Azure AD Connect config file containing plaintext credentials in an SMB share, and escalate to Administrator by decrypting the Azure AD Sync service account password from the local MSSQL Express database.</description>
    </item>
    <item>
      <title>HTB: Giddy</title>
      <link>https://joaobonin.com/posts/htb-giddy/</link>
      <pubDate>Sun, 31 May 2026 00:00:00 +0000</pubDate>
      <guid>https://joaobonin.com/posts/htb-giddy/</guid>
      <description>Giddy is a Medium Windows box on HackTheBox. SQL injection in an ASP.NET app is abused to force NTLM authentication outbound, capturing and cracking a hash for a WinRM shell. Privilege escalation abuses CVE-2016-6914, a local privesc in Ubiquiti UniFi Video that hijacks taskkill.exe.</description>
    </item>
    <item>
      <title>HTB: Editorial</title>
      <link>https://joaobonin.com/posts/htb-editorial/</link>
      <pubDate>Fri, 22 May 2026 00:00:00 +0000</pubDate>
      <guid>https://joaobonin.com/posts/htb-editorial/</guid>
      <description>SSRF on a book publishing platform leaks an internal API running on port 5000. The API exposes hardcoded dev credentials, landing us a shell. From there, git history reveals prod credentials, and a sudo-allowed GitPython script is vulnerable to ext:: protocol injection — setting SUID on bash and giving us root.</description>
    </item>
    <item>
      <title>HTB: Escape</title>
      <link>https://joaobonin.com/posts/htb-escape/</link>
      <pubDate>Fri, 22 May 2026 00:00:00 +0000</pubDate>
      <guid>https://joaobonin.com/posts/htb-escape/</guid>
      <description>Escape is a Medium Windows Active Directory machine where a publicly readable SMB share leaks SQL Server credentials in a PDF. Those creds lead to MSSQL access, NTLM hash capture via xp_dirtree, and eventually an ESC1 ADCS attack to compromise the domain administrator.</description>
    </item>
    <item>
      <title>HTB Certified - Active Directory Certificate Services and ESC9</title>
      <link>https://joaobonin.com/posts/htb-certified/</link>
      <pubDate>Thu, 21 May 2026 00:00:00 +0000</pubDate>
      <guid>https://joaobonin.com/posts/htb-certified/</guid>
      <description>Certified is a Medium Windows AD box where you chain WriteOwner and GenericWrite ACL abuses to reach a certificate authority operator, then exploit ESC9 to forge an admin certificate and own the domain.</description>
    </item>
    <item>
      <title>HTB Chatterbox - AChat Buffer Overflow and Registry Credentials</title>
      <link>https://joaobonin.com/posts/htb-chatterbox/</link>
      <pubDate>Thu, 21 May 2026 00:00:00 +0000</pubDate>
      <guid>https://joaobonin.com/posts/htb-chatterbox/</guid>
      <description>Chatterbox is a Medium Windows box running the AChat chat server, vulnerable to a classic stack buffer overflow. Foothold comes from a custom Python exploit with a unicode-encoded payload, and privesc is a gift left in the registry - autologon credentials that also work for Administrator.</description>
    </item>
    <item>
      <title>HTB Write-up: Builder</title>
      <link>https://joaobonin.com/posts/htb-builder/</link>
      <pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate>
      <guid>https://joaobonin.com/posts/htb-builder/</guid>
      <description>Jenkins 2.441 LFI to credential theft, Groovy shell for foothold, then decrypting an encrypted SSH key stored in Jenkins to reach root.</description>
    </item>
  </channel>
</rss>
