Return of Those Guys

Security Insights  /  Return of Those Guys

Reece Payne | Security Consultant | 24 July 2023

After many years Jake and I have finally returned to streaming our exploits (pun intended) online!

In our last stream we ran through a retired HackTheBox (HTB) capture the flag called "Precious". The VOD for the stream is located over on Youtube and you can read through a more detailed writeup at https://so.thosearethegui.se/2023/07/10/precious.html.

As a component of our streams and write-ups Jake and I also thought it would be good to take a higher-level view of either direct learnings we had from doing a box, or point out the learnings that might apply to you (the reader) in your day to day. You might be a student, studying towards a career in Cyber Security, a security practitioner who might find a handy reminder about something to look in to, or someone who is just curious. There's no great theme, and points might repeat over the weeks, but we hope you find them informative and helpful!

The flow of the "Precious" was:

In terms of realism versus gameyness, I would categorise this as having "abbreviated realism." Most of the steps were simple, without requiring much hunting or guesswork to exploit vulnerabilities. Additionally, the user credentials we found belonged to another user on a server, which allowed for escalation. While these scenarios are possible, in reality things aren't always so straightforward.

Key Takeaways

CONTACT US

Sign up or speak with a Fortian Security Specialist

Request a consultation with one of our security specialists today or sign up to receive our monthly newsletter via email.

Get in touch