Access — Credential Sprawl Across Legacy Services
Anonymous FTP and archive recovery expose credentials that grant Telnet access, then escalate through cached credential abuse.
Security case studies
I document offensive-security and digital-forensics work: repeatable methods, evidence, and analysis from Linux and Windows machines and DFIR investigations. Browse the curated highlights, then filter the full case-study explorer by focus or keyword.
Choose an analytical lens.
Web and service exploitation, credential recovery, and local privilege escalation.
32Active Directory attack paths, delegation, and domain escalation.
3Timeline reconstruction, log analysis, and persistence.
↗Hands-on learning and profile links.
The six most recently added case studies, by portfolio-addition date.
A share readable by a low-privileged domain account exposes a live MSSQL sa credential, enabling command execution and configuration-file password reuse before AD CS ESC4 template abuse issues a certificate for the administrative identity.
Web enumeration exposes an accessible PHP web shell for command execution, followed by a constrained sudo identity transition and a writable root-executed script to reach root.
Linux machineWeb enumeration exposes a custom Java plugin; decompilation reveals hardcoded credentials for SSH access, and an unrestricted sudo policy yields root.
Linux machineVirtual host enumeration reveals a Dolibarr CRM instance with default credentials; authenticated RCE, credential reuse, and an Enlightenment SUID flaw chain to root.
Linux machineAn Apache ActiveMQ deployment with a vulnerable OpenWire service and default console credentials yields a service-account shell; unrestricted nginx sudo enables a root file-write path.
Linux machineUnauthenticated Jenkins CLI file read (CVE-2024-23897) exposes a password hash and Script Console access, and credential storage reveals a path to root.
70 results
Browse all 70 published case studies, then narrow by focus or keyword.
Anonymous FTP and archive recovery expose credentials that grant Telnet access, then escalate through cached credential abuse.
An SMB share exposes a protected certificate archive, and PowerShell history leaks a service account with LAPS read access.
Anonymous SMB and MSSQL coercion recover credentials, then AD CS ESC1 certificate abuse yields the privileged account NT hash.
Misconfigured object permissions drive a multi-hop chain through Kerberoasting, credential capture, and DCSync to domain compromise.
A malicious Windows theme upload on the ThemeBleed path yields a shell, then CLFS abuse escalates to SYSTEM.
A password-reset token returned in an API response, unsafe dynamic configuration evaluation in an AI-agent platform, and container secret exposure chain through an internal service to privileged access.
An exposed Ansible vault and rogue LDAP listener expose service credentials, enabling ESC1 certificate abuse for Domain Administrator.
Exposed version-control metadata and a custom-header development virtual host lead to an upload blocklist bypass and race condition for a web-service shell; a SUID Python 2 input() helper and a package-installer sudo rule reach root.
Web enumeration exposes an accessible PHP web shell for command execution, followed by a constrained sudo identity transition and a writable root-executed script to reach root.
Web enumeration exposes a custom Java plugin; decompilation reveals hardcoded credentials for SSH access, and an unrestricted sudo policy yields root.
Virtual host enumeration reveals a Dolibarr CRM instance with default credentials; authenticated RCE, credential reuse, and an Enlightenment SUID flaw chain to root.
A guest-readable logon script and excessive directory permissions lead through Kerberos delegation abuse to domain compromise.
An Apache ActiveMQ deployment with a vulnerable OpenWire service and default console credentials yields a service-account shell; unrestricted nginx sudo enables a root file-write path.
HTB Sherlock case study covering SSH authentication analysis, session correlation, and privileged-account persistence.
Unauthenticated Jenkins CLI file read (CVE-2024-23897) exposes a password hash and Script Console access, and credential storage reveals a path to root.
Unsafe evaluation in a Searchor search request yields command execution; exposed Git credentials, container environment inspection through sudo, and relative-path execution in a root script extend access.
Anonymous LDAP disclosure, SMB configuration artifacts, audit-app analysis, and AD Recycle Bin data combine into a credential-exposure chain.
A time-based blind SQL injection in ZoneMinder recovers credential hashes for SSH access, then filename command injection in a root-run motionEye service leads to root.
Group and account-control permissions form an ACL chain ending in AD CS ESC9 certificate abuse.
Guest SMB, LDAP attributes, and embedded script credentials chain into Backup Operators hive extraction and domain compromise.
XWiki SolrSearch unauthenticated Groovy code execution (CVE-2025-24893) provides a foothold; reused database credentials enable SSH, and a SUID Netdata ndsudo helper is hijacked through PATH to reach root.
An API access-control flaw exposes password hashes, and an unauthenticated Docker daemon allows a privileged container escape to host root.
A Spring Boot Actuator session leak grants admin access and command injection in the SSH feature provides a foothold; credentials from the application JAR and an SSH ProxyCommand sudo rule lead to root.
Grafana path traversal (CVE-2021-43798) extracts the application database for offline credential cracking, and a permissive docker exec sudo rule mounts the host filesystem to reach root.
NETLOGON script credentials and GenericWrite over a delegation admin enable Kerberoasting, PetitPotam coercion, and DCSync.
A share readable by a low-privileged domain account exposes a live MSSQL sa credential, enabling command execution and configuration-file password reuse before AD CS ESC4 template abuse issues a certificate for the administrative identity.
IKE Aggressive Mode with PSK authentication exposes a crackable hash for SSH access, and a non-standard sudo binary is abused through a hostname-based policy bypass (CVE-2025-32463) to reach root.
A Gitea credential leak and pgAdmin container RCE lead through NFS certificate extraction and Docker control to ESC7 domain compromise.
A leaked Cisco configuration yields SMB and WinRM access, then Firefox process memory recovery exposes the Administrator password.
Unauthenticated Apache NiFi command execution through CVE-2023-34468 and an H2 database driver, a recovered operator SSH key, and a cracked operations guide open an OPC UA maintenance window that grants root.
A GraphQL endpoint leaks HelpDeskZ credentials and an attachment-upload weakness stores rejected PHP files under predictable names for web-service code execution; a kernel eBPF flaw (CVE-2017-16995) escalates to root.
Leaked Gogs source exposes hardcoded API credentials and a Flask eval() call for container root; database credential reuse, a Gogs SSH key, and HashiCorp Vault SSH OTP then provide host root.
PDF metadata and a default onboarding password enable DNS record injection and NTLM capture, then GMSA silver-ticket abuse reaches Domain Administrator.
Mirth Connect XStream deserialization (CVE-2023-43208) provides an unauthenticated shell; database credentials and a PBKDF2 hash give SSH access, then a double eval() in a root-owned Flask service yields root.
Default Tomcat Manager credentials allow WAR deployment, producing an immediate SYSTEM shell.
Default Request Tracker credentials and a password stored in a comment field provide user access; KeePass master-password recovery from a crash dump (CVE-2023-32784) unlocks an unencrypted root SSH key.
A backdoored PHP 8.1.0-dev build executes code through the User-Agentt header, and an unrestricted sudo rule for the Chef knife tool is abused via knife exec to reach root.
An exposed .git directory on a development virtual host reveals a CMS password for authenticated RCE; a sudo cleanup script with a user-controlled glob and a two-hop symlink chain bypass kernel symlink protection to read a protected file.
Virtual host enumeration exposes an administrative interface and a pre-authentication backup disclosure that leaks AES key material; decrypting the application database recovers an SSH credential, and local enumeration identifies a privilege-escalation path.
HTB Sherlock case study reconstructing a single-host Windows event-log timeline with Chainsaw: interactive logon, discovery-tool detection, audit-policy tampering, scheduled-task persistence, and Firewall log clearing.
SQL injection in a login page and PNG magic-byte upload evasion provide a foothold; MySQL credentials tunneled through Chisel and reused admin credentials enable lateral movement, and a SUID sysinfo binary is hijacked through PATH to reach root.
RID brute forcing, password spraying, and a legacy backup expose ManageCA rights, enabling the AD CS ESC7 abuse chain to domain compromise.
Guest SMB null authentication and a stored CliXml credential lead to Azure AD Sync database decryption and a domain administrator password.
A weakly secured MSSQL database yields cracked credentials, then badsuccessor OU delegation and DCSync complete domain compromise.
A zip-upload SSRF captures an NTLMv2 hash, and delegation abuse plus an MSI repair flaw create a domain administrator.
A leaked backup exposes upload source with weak MIME and extension checks, enabling a double-extension PHP web shell; command injection through filenames in a cron script and input validation gaps in a sudo network script lead to privileged access.
Craft CMS pre-authentication RCE (CVE-2025-32432) and plaintext database credentials lead to an administrator hash and SSH access; a GNU inetutils telnet authentication bypass (CVE-2026-24061) on loopback yields root.
Authenticated Roundcube RCE (CVE-2025-49113) and session-table password decryption with the application DES key lead to SSH access; a symlink attack on the below utility's error log (CVE-2025-27591) yields root.
A monitoring binary leaks MSSQL credentials; ADIDNS poisoning captures more, and WCF command injection returns a SYSTEM shell.
SNMP enumeration leaks credentials for SSH access; an internal Pandora FMS instance reached through SSH dynamic forwarding is SQL-injected for session hijacking, and a SUID backup binary calling tar by relative name enables PATH hijacking to root.
Kerberos clock-skew alignment, gMSA enumeration, and an NTLM relay pivot lead through delegation abuse to domain controller compromise.
A PHP loose-comparison flaw bypasses authentication; a ZIP archive's ZipCrypto encryption is broken via known-plaintext to recover an SSH key, and a hardcoded credential in Laravel source provides root.
Correlating a packet capture with Windows Security event logs to investigate a suspected NTLM relay and authenticated SMB share activity.
An LDAP description attribute and PowerShell transcripts expose administrative credentials, then DNSAdmins abuse loads a malicious DLL for SYSTEM.
Guest SMB notes and a pre-created computer account lead to an ESC1 certificate template and administrator impersonation.
A printer admin panel's LDAP configuration is redirected to capture service credentials, then Server Operators escalation reaches Administrator.
SSRF in request-baskets (CVE-2023-27163) reaches an internal Maltrail service vulnerable to command injection, and a NOPASSWD systemctl status rule is escalated through a less-pager escape (CVE-2023-26604) to root.
A weak password reset enables Kerberoasting and silver-ticket forgery, then SeImpersonate abuse escalates to SYSTEM via GodPotato.
Default credentials on exposed file-management software and an executable upload provide a web-service shell; WebSocket SQL injection recovers an SSH credential, and a doas rule for dstat is abused through plugin loading to reach root.
SSRF in a book-cover upload exposes an internal API and development credentials; Git history reveals production credentials, and a sudo-permitted GitPython script vulnerable to CVE-2022-24439 yields root.
An exposed application archive identifies legacy Apache Struts upload handling, and CVE-2024-53677 path traversal yields a service-account shell; a stored credential enables SSH, and a sudo tcpdump post-rotate hook reaches root.
Guest-accessible tooling, reversible credential obfuscation, and excessive computer-object permissions form a path to privileged access.
Gibbon LMS enumeration and database credential recovery lead to a Group Policy Creator Owners path toward Domain Administrator.
A download endpoint's path traversal exposes Gitea configuration and database data for password recovery and SSH access; an ImageMagick shared-library hijack (CVE-2024-41817) in a scheduled process provides elevated access.
SQL injection in a password-reset workflow and a Laravel-admin upload-validation bypass provide a foothold; reused Monit credentials enable SSH, and wildcard and @listfile handling in a sudo 7-Zip backup reach a protected root key.
Share-hosted documents, Kerberoasting, AD Recycle Bin recovery, and a WSL pivot lead into offline directory-backup analysis.
Anonymous FTP exposes an OpenWrt backup containing a wireless key reused for SSH access; a raw-packet-capable reaver and a default WPS PIN recover a WPA key that grants root SSH.
Default OpenPLC credentials and a Structured Text C extension provide container root; wireless scanning and a WPS PixieDust attack recover a WPA passphrase, and association leads to passwordless root SSH on a router.
A log-file credential leak, Shadow Credentials abuse, and a rogue update server chain to SYSTEM code execution.
A mail server path traversal exposes a configuration hash, and a crafted document triggers privileged code execution on a client host.
No studies match filters. Try another focus or search term.