<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Privesc on João Vítor Moutinho Bonin</title>
    <link>https://joaobonin.com/tags/privesc/</link>
    <description>Recent content in Privesc on João Vítor Moutinho Bonin</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Mon, 01 Jun 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://joaobonin.com/tags/privesc/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>HTB Monteverde - Azure AD Connect Password Extraction</title>
      <link>https://joaobonin.com/posts/htb-monteverde/</link>
      <pubDate>Mon, 01 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://joaobonin.com/posts/htb-monteverde/</guid>
      <description>Monteverde is a Medium Windows Active Directory box from HackTheBox. We enumerate domain users via null session, discover a username-as-password credential for SABatchJobs, find an Azure AD Connect config file containing plaintext credentials in an SMB share, and escalate to Administrator by decrypting the Azure AD Sync service account password from the local MSSQL Express database.</description>
    </item>
    <item>
      <title>HTB: Giddy</title>
      <link>https://joaobonin.com/posts/htb-giddy/</link>
      <pubDate>Sun, 31 May 2026 00:00:00 +0000</pubDate>
      <guid>https://joaobonin.com/posts/htb-giddy/</guid>
      <description>Giddy is a Medium Windows box on HackTheBox. SQL injection in an ASP.NET app is abused to force NTLM authentication outbound, capturing and cracking a hash for a WinRM shell. Privilege escalation abuses CVE-2016-6914, a local privesc in Ubiquiti UniFi Video that hijacks taskkill.exe.</description>
    </item>
  </channel>
</rss>
