$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: hard Windows AD domain controller (codeby.cdb / EXPANSE). Solution: LDAP anonymous bind for user enumeration, AS-REP roast + crack, harvest base64 creds from an SMB share script, abuse Account Operators to add self to a custom LAPS ReadOnly group, read ms-Mcs-AdmPwd to get local/domain admin, read flags over SMB C$.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar