<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Smb on João Vítor Moutinho Bonin</title>
    <link>https://joaobonin.com/tags/smb/</link>
    <description>Recent content in Smb on João Vítor Moutinho Bonin</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Thu, 04 Jun 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://joaobonin.com/tags/smb/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>HTB: Flight</title>
      <link>https://joaobonin.com/posts/htb-flight/</link>
      <pubDate>Thu, 04 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://joaobonin.com/posts/htb-flight/</guid>
      <description>Flight is a Hard Windows Active Directory box from HackTheBox. An LFI on a PHP school subdomain escalates to NTLM hash capture via UNC path. Crack svc_apache&amp;#39;s hash, password spray to S.Moon, use ntlm_theft via the Shared share to coerce C.Bum&amp;#39;s hash, pivot through a PHP webshell to meterpreter, RunasCs to C.Bum, discover an internal IIS dev site, upload an ASPX webshell, and escalate to SYSTEM via SeImpersonatePrivilege and EfsPotato.</description>
    </item>
    <item>
      <title>HTB Monteverde - Azure AD Connect Password Extraction</title>
      <link>https://joaobonin.com/posts/htb-monteverde/</link>
      <pubDate>Mon, 01 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://joaobonin.com/posts/htb-monteverde/</guid>
      <description>Monteverde is a Medium Windows Active Directory box from HackTheBox. We enumerate domain users via null session, discover a username-as-password credential for SABatchJobs, find an Azure AD Connect config file containing plaintext credentials in an SMB share, and escalate to Administrator by decrypting the Azure AD Sync service account password from the local MSSQL Express database.</description>
    </item>
    <item>
      <title>HTB: Forest</title>
      <link>https://joaobonin.com/posts/htb-forest/</link>
      <pubDate>Sun, 31 May 2026 00:00:00 +0000</pubDate>
      <guid>https://joaobonin.com/posts/htb-forest/</guid>
      <description>Forest is an Easy Windows Active Directory box on HackTheBox. The path goes through AS-REP roasting a service account, then using BloodHound to find a WriteDacl abuse chain through Exchange groups to grant DCSync and dump the domain.</description>
    </item>
    <item>
      <title>HTB: Escape</title>
      <link>https://joaobonin.com/posts/htb-escape/</link>
      <pubDate>Fri, 22 May 2026 00:00:00 +0000</pubDate>
      <guid>https://joaobonin.com/posts/htb-escape/</guid>
      <description>Escape is a Medium Windows Active Directory machine where a publicly readable SMB share leaks SQL Server credentials in a PDF. Those creds lead to MSSQL access, NTLM hash capture via xp_dirtree, and eventually an ESC1 ADCS attack to compromise the domain administrator.</description>
    </item>
    <item>
      <title>HTB: Active - OSCP Prep Write-up</title>
      <link>https://joaobonin.com/posts/htb-active/</link>
      <pubDate>Tue, 19 May 2026 00:00:00 -0300</pubDate>
      <guid>https://joaobonin.com/posts/htb-active/</guid>
      <description>Write-up for the HackTheBox machine Active - GPP credentials buried in the Replication share expose SVC_TGS, and Kerberoasting that account cracks the Administrator password.</description>
    </item>
    <item>
      <title>HTB: Cicada - OSCP Prep Write-up</title>
      <link>https://joaobonin.com/posts/htb-cicada/</link>
      <pubDate>Tue, 19 May 2026 00:00:00 -0300</pubDate>
      <guid>https://joaobonin.com/posts/htb-cicada/</guid>
      <description>Write-up for the HackTheBox machine Cicada - a Windows AD box built around SMB enumeration, password spraying, credential leakage, and SeBackupPrivilege abuse.</description>
    </item>
  </channel>
</rss>
