HTB STARTING POINT · Tier 0

Explosion

RDP and WinRM both accept a blank Administrator password — attack surface is two services wide when credential assumptions fail at the front door.…

April 27, 2026 · 5 min · crAIzy
RDP

HTB · Tier 0

PingPong

Two-domain AD forest under Assumed Breach. NTLM disabled globally. TCP port 88 asymmetrically filtered — a custom impacket monkey-patch unblocks Kerberos. ESC13 on TemporaryWinRM template grants WinRM shell on DC1. ……

April 27, 2026 · 7 min · crAIzy
MSSQL RCE