I need a place where I can share stuff I'm learning, even if talking to the walls, anyone is welcome to talk, its important to keep on technology but I guess we can escape a bit, no? Came here from hikarich.
I'll start:
I'm at the end of a long journey through some extensive material for a certification I have to get, the HTB CPTS. Being a wagie is tough, but I'm enjoying the material, though sometimes it's just a grind. I'm finishing the Windows privilege escalation module and also following some esoteric blog posts I found from security researchers.
What infuriates me is the damn ACLs, just look at this:
[code]
sc.exe sdshow DNS
D:(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SO)(A;;RPWP;;;S-1-5-21-669053619-2741956077-1013132368-1109)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)
[/code]
The number of times I've had to consult the MS documentation just to not get lost is absurd. Meanwhile, in Linux, as far as I know, you just use ls -l, you get the permissions, and you're done. The objects Windows uses for every single file make this model a living hell.
And the worst part is, there's no escaping it. Just take that string I threw up there from sdshow DNS. At first glance, it looks like a messed-up hash, but it's a damn list of permissions. The so-called SDDL.
Post too long. Click here to view the full text.