<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Rafid Ahmed</title>
    <description>The latest articles on DEV Community by Rafid Ahmed (@rafidths).</description>
    <link>https://dev.to/rafidths</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4163159%2Fe7dd8752-6ea4-4185-a6af-9b1b98e98f88.jpeg</url>
      <title>DEV Community: Rafid Ahmed</title>
      <link>https://dev.to/rafidths</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/rafidths"/>
    <language>en</language>
    <item>
      <title>Hack The Box — Hercules Write-up | Advanced Active Directory &amp; AD CS</title>
      <dc:creator>Rafid Ahmed</dc:creator>
      <pubDate>Mon, 05 Oct 2026 07:54:31 +0000</pubDate>
      <link>https://dev.to/rafidths/hack-the-box-hercules-write-up-advanced-active-directory-ad-cs-45l9</link>
      <guid>https://dev.to/rafidths/hack-the-box-hercules-write-up-advanced-active-directory-ad-cs-45l9</guid>
      <description>&lt;p&gt;Around three months ago, I successfully compromised Hercules, an Insane-rated Windows Active Directory machine on Hack The Box.&lt;/p&gt;

&lt;p&gt;Hercules was an interesting challenge because it required chaining multiple Active Directory weaknesses rather than relying on a single misconfiguration.&lt;/p&gt;

&lt;p&gt;The attack path required understanding how seemingly limited permissions could be chained together to obtain increasingly powerful access within the domain.&lt;/p&gt;

&lt;p&gt;Full Kill Chain:&lt;/p&gt;

&lt;p&gt;LDAP Injection → LFI → ASP.NET Cookie Forgery → NetNTLMv2 capture → Hash cracking → BloodHound recon → OU takeover → Disabled account resurrection → certificate abuse → Certificate impersonation → WinRM lateral movement → ForceChangePassword → Computer account takeover → RBCD + S4U2Self/U2U + S4U2Proxy → Domain Admin&lt;/p&gt;

&lt;p&gt;Key moments:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;LDAP blind injection: Wildcard wasn't filtered. Information is gathered character by character.&lt;/li&gt;
&lt;li&gt;Forged ASP.NET cookie: Forged an auth cookie as a privileged user via cryptography config leak.&lt;/li&gt;
&lt;li&gt;Certificate abuse: Smartcard Operators. Woke it up, grabbed the vulnerable template, then minted certificates for whomever I wanted. AD CS did all the work.&lt;/li&gt;
&lt;li&gt;RBCD-S4U2Self/S4U2Proxy: machine account had delegation rights to the DC. Synced its hash with the Kerberos session key, abused.&lt;/li&gt;
&lt;li&gt;S4U2Self/U2U/S4U2Proxy obtained a service ticket as a domain admin. Didn't touch their password once.&lt;/li&gt;
&lt;li&gt;WinRM: Imported the ticket. Full shell on the DC. Objective complete.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;Full Write-up&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I documented the complete methodology, enumeration process, exploitation steps, attack chain, and technical analysis in my full write-up on Medium.&lt;/p&gt;

&lt;p&gt;Read the full Hercules write-up on Medium:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://medium.com/@rafidahmed/chained-trust-a-full-compromise-of-htb-hercules-via-ldap-injection-credential-harvesting-and-c81a033c5dcc?sk=3c12b9f28b36557b946521975a3855cb" rel="noopener noreferrer"&gt;https://medium.com/@rafidahmed/chained-trust-a-full-compromise-of-htb-hercules-via-ldap-injection-credential-harvesting-and-c81a033c5dcc?sk=3c12b9f28b36557b946521975a3855cb&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The full article goes into significantly more detail, including the complete attack path and the techniques used to compromise the machine.&lt;/p&gt;

&lt;p&gt;Thanks to Hack The Box for creating such a challenging and technically interesting machine.&lt;/p&gt;

&lt;p&gt;If you're working through Hercules yourself, I hope the write-up helps you understand the attack chain and the underlying Active Directory concepts.&lt;/p&gt;

</description>
      <category>hackthebox</category>
      <category>ldapinjection</category>
      <category>hacking</category>
      <category>adcs</category>
    </item>
  </channel>
</rss>
