
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Bukhari&#39;s Archive </title>
      <link>https://b3ta-blocker.github.io/blog</link>
      <description>A hands-on hacking blog covering penetration testing walkthroughs by Hassaan Ali Bukhari.</description>
      <language>en-us</language>
      <managingEditor>root.b3ta.blocker@gmail.com (Hassaan Ali Bukhari)</managingEditor>
      <webMaster>root.b3ta.blocker@gmail.com (Hassaan Ali Bukhari)</webMaster>
      <lastBuildDate>Thu, 10 Jul 2025 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://b3ta-blocker.github.io/tags/active-directory/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://b3ta-blocker.github.io/blog/fluffy</guid>
    <title>Fluffy Machine (HackTheBox) — Step-by-Step Walkthrough</title>
    <link>https://b3ta-blocker.github.io/blog/fluffy</link>
    <description>Compromise of a Windows HackTheBox Active Directory machine by exploiting CVE-2025-24071 via a malicious library-ms file to capture NTLM hashes via Responder, abusing GenericWrite permissions through BloodHound enumeration to perform Shadow Credential attacks, and escalating to Domain Admin by exploiting an ESC16 ADCS misconfiguration with Certipy.</description>
    <pubDate>Thu, 10 Jul 2025 00:00:00 GMT</pubDate>
    <author>root.b3ta.blocker@gmail.com (Hassaan Ali Bukhari)</author>
    <category>windows</category><category>hackthebox</category><category>easy</category><category>active-directory</category><category>cve-2025-24071</category><category>privilege-escalation</category>
  </item>

    </channel>
  </rss>
