Skip to main content
taktak.hu

Security case studies

taktak.hu

I document offensive-security and digital-forensics work: repeatable methods, evidence, and analysis from Linux and Windows machines and DFIR investigations. Browse the curated highlights, then filter the full case-study explorer by focus or keyword.

70published studies
67machine studies
3DFIR studies
2content types

Browse by focus

Choose an analytical lens.

Latest additions

The six most recently added case studies, by portfolio-addition date.

Windows machine

EscapeTwo — AD CS ESC4 Template Abuse via WriteOwner and Shadow Credentials

A share readable by a low-privileged domain account exposes a live MSSQL sa credential, enabling command execution and configuration-file password reuse before AD CS ESC4 template abuse issues a certificate for the administrative identity.

Objective
Escalate from a low-privileged domain account to domain administrative access through credential discovery, MSSQL command execution, and AD CS template-permission abuse.
Tools
netexec, smbget, impacket, certipy, evil-winrm
Skill demonstrated
Active Directory escalation through credential reuse, MSSQL command execution, and AD CS certificate-template abuse
Outcome
Administrative certificate authentication through an ESC4-abused template, reached after shadow-credential recovery of the CA service account hash and configuration-file password reuse.
Linux machine

Bashed: Web Shell to Scheduled-Task Privilege Escalation

Web enumeration exposes an accessible PHP web shell for command execution, followed by a constrained sudo identity transition and a writable root-executed script to reach root.

Linux machine

Blocky: Plugin Source Exposure to Privileged Access

Web enumeration exposes a custom Java plugin; decompilation reveals hardcoded credentials for SSH access, and an unrestricted sudo policy yields root.

Linux machine

BoardLight — Dolibarr RCE to Enlightenment Privilege Escalation

Virtual host enumeration reveals a Dolibarr CRM instance with default credentials; authenticated RCE, credential reuse, and an Enlightenment SUID flaw chain to root.

Linux machine

Broker: ActiveMQ Exposure and Unsafe Daemon Sudo

An Apache ActiveMQ deployment with a vulnerable OpenWire service and default console credentials yields a service-account shell; unrestricted nginx sudo enables a root file-write path.

Linux machine

Builder: Jenkins CLI File Read and Credential Exposure

Unauthenticated Jenkins CLI file read (CVE-2024-23897) exposes a password hash and Script Console access, and credential storage reveals a path to root.

Case-study explorer

70 results

Browse all 70 published case studies, then narrow by focus or keyword.

Linux machine

AI Platform Attack-Chain Case Study

A password-reset token returned in an API response, unsafe dynamic configuration evaluation in an AI-agent platform, and container secret exposure chain through an internal service to privileged access.

linuxwebai-platform
Linux machine

Bashed: Web Shell to Scheduled-Task Privilege Escalation

Web enumeration exposes an accessible PHP web shell for command execution, followed by a constrained sudo identity transition and a writable root-executed script to reach root.

linuxweb-enumerationprivilege-escalation
Linux machine

Blocky: Plugin Source Exposure to Privileged Access

Web enumeration exposes a custom Java plugin; decompilation reveals hardcoded credentials for SSH access, and an unrestricted sudo policy yields root.

linuxweb-enumerationcredential-managementsudo
Windows machine

Breach: Active Directory Delegation Exposure

A guest-readable logon script and excessive directory permissions lead through Kerberos delegation abuse to domain compromise.

windowsactive-directorykerberosdelegation

No studies match filters. Try another focus or search term.