A step-by-step walkthrough of passing the CRTA (Certified Red Team Analyst) exam by CyberWarFare Labs. The attack chain covers network reconnaissance with nmap, exploiting an SSRF vulnerability in a Flask app to read host files via the file:// scheme inside a Docker container, gaining SSH access, escalating privileges via GTFOBins (sudo vi), enumerating Docker containers, pivoting to an internal network, discovering Active Directory credentials in an elfinder file manager, performing a DCSync attack with impacket-secretsdump, and finally using Pass-the-Hash with smbclient to retrieve the final flag from the Domain Controller's Administrator Desktop.

7m read timeFrom infosecwriteups.com
Post cover image
80 Impressions