
HTB Forgotten CTF Writeup
Complete walkthrough of HTB Forgotten, an Easy difficulty Linux machine featuring LimeSurvey exploitation, malicious plugin upload for RCE, and container escape via shared mount points.

Complete walkthrough of HTB Forgotten, an Easy difficulty Linux machine featuring LimeSurvey exploitation, malicious plugin upload for RCE, and container escape via shared mount points.

An "is it down" web app passes user-supplied URLs to curl without proper argument sanitization, allowing file reads via the file:// scheme and argument injection. A hidden TCP mode exposes a netcat -e RCE vector. Internally, the user's pswm password vault is brute-forced to retrieve SSH credentials, and sudo group membership trivially grants root.

Unauthenticated LDAP enumeration reveals a plaintext password in a user description field. A password spray uncovers an account flagged STATUS_PASSWORD_MUST_CHANGE, and after resetting it, SeBackupPrivilege is abused to dump NTDS.dit via diskshadow and robocopy, yielding the Administrator hash.

Only RDP is exposed; disabling NLA reveals kiosk credentials for a restricted session. UAC is bypassed by renaming cmd.exe to msedge, then an encrypted Remote Desktop Plus profile is decrypted using BulletsPassView to recover admin credentials. RunasCs with --bypass-uac spawns a fully privileged shell.

A Gitea API key leaked in git commit history reveals a private repository with active CI/CD; deploying a webshell via git push yields a foothold. mRemoteNG credentials are decrypted to pivot to another user, and a PDF24 MSI repair local privilege escalation via opportunistic lock (oplock) abuse grants a SYSTEM shell.

Insane-rated Windows Active Directory box on Hack The Box. SMB RID-bruting leads to AS-REP roasting and Kerberoasting. BloodHound maps a path via shadow credentials and password spraying to ServiceMGMT. A RemotePotato cross-session relay captures a hash for GMSA read and RBCD-based domain compromise.

Hard-rated Windows Active Directory box. An LFI in a PHP web app triggers SMB hash capture via LLMNR/NBT-NS poisoning. Unconstrained delegation is weaponized with PrinterBug coercion to steal the domain controller's TGT and execute DCSync.

Medium-rated Windows Active Directory box. BloodHound reveals GenericAll over a security group, enabling self-addition for access to a KeePass database in SMB. DPAPI secrets decrypted from the database recover credentials used for privilege escalation.

Hard-rated Windows Active Directory box. An SMTP service accepts external mail with weaponized RTF attachments that exploit a memory corruption bug for initial access. BloodHound maps misconfigured ACLs through the AD environment to Domain Admin.

Insane-rated Windows Active Directory box. OWA credential spraying grants mailbox access. A phished malicious LibreOffice macro captures Net-NTLMv2 hashes for cracking. Wamp misconfigurations and AD lateral movement lead to full domain compromise.