<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>HTB - Tag - My Personal Blog</title><link>https://f0dh1l.github.io/blog/tags/htb/</link><description>HTB - Tag - My Personal Blog</description><generator>Hugo -- gohugo.io</generator><language>en</language><managingEditor>benhibafodhil@gmail.com (F0DH1L)</managingEditor><webMaster>benhibafodhil@gmail.com (F0DH1L)</webMaster><copyright>2025 F0DH1L</copyright><lastBuildDate>Thu, 23 Oct 2025 14:01:34 +0100</lastBuildDate><atom:link href="https://f0dh1l.github.io/blog/tags/htb/" rel="self" type="application/rss+xml"/><item><title>HTB Machine Writeup "TombWatcher"</title><link>https://f0dh1l.github.io/blog/posts/htb_tombwatcher/</link><pubDate>Thu, 23 Oct 2025 14:01:34 +0100</pubDate><author>benhibafodhil@gmail.com (F0DH1L)</author><guid>https://f0dh1l.github.io/blog/posts/htb_tombwatcher/</guid><description><![CDATA[<h1 id="htb-machine-tombwatcher---writeup">HTB Machine: TombWatcher - Writeup</h1>
<h2 id="machine-information">Machine Information</h2>
<ul>
<li><strong>Difficulty</strong>: Medium</li>
<li><strong>Key Concepts</strong>: Kerberoasting, LDAP Enumeration, BloodHound Analysis, Active Directory Privilege Escalation, Deleted Object Recovery, ADCS ESC15 Vulnerability</li>
</ul>
<p></p>
<h2 id="overview">Overview</h2>
<p><strong>TombWatcher</strong> is a Medium Windows machine from HackTheBox that demonstrates a complex Active Directory attack path involving Kerberoasting, group membership manipulation, GMSA password extraction, ownership changes, recovering and restoring deleted AD objects, and ultimately exploiting an ADCS vulnerability (ESC15) to achieve domain administrator privileges.</p>]]></description></item><item><title>HTB Machine Writeup "Artificial"</title><link>https://f0dh1l.github.io/blog/posts/htb_artificial/</link><pubDate>Thu, 23 Oct 2025 13:48:04 +0100</pubDate><author>benhibafodhil@gmail.com (F0DH1L)</author><guid>https://f0dh1l.github.io/blog/posts/htb_artificial/</guid><description><![CDATA[<h1 id="htb-machine-artificial---writeup">HTB Machine: Artificial - Writeup</h1>
<h2 id="machine-information">Machine Information</h2>
<ul>
<li><strong>Difficulty</strong>: Easy</li>
<li><strong>OS</strong>: Linux</li>
<li><strong>Key Concepts</strong>: TensorFlow/Keras Vulnerability, File Upload, Privilege Escalation Through Backrest service</li>
</ul>
<p></p>
<h2 id="overview">Overview</h2>
<p><strong>Artificial</strong> is an Easy Linux machine from HackTheBox that demonstrates the dangers of accepting user uploaded machine learning models. The path to root involves exploiting a TensorFlow remote code execution vulnerability, database credential extraction, and abusing a backup service to read the root flag.</p>]]></description></item></channel></rss>