<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>AETH3RON — recovered files</title><description>Offensive security writeups and research.</description><link>https://aeth3ron.io/</link><language>en</language><item><title>React2Shell (CVE-2025-55182)</title><link>https://aeth3ron.io/en/research/react2shell-cve-2025-55182/</link><guid isPermaLink="true">https://aeth3ron.io/en/research/react2shell-cve-2025-55182/</guid><description>Complete technical analysis of CVE-2025-55182 (React2Shell): insecure deserialization in the RSC Flight protocol of React 19 enabling pre-auth RCE with CVSS 10.0.</description><pubDate>Wed, 10 Dec 2025 00:00:00 GMT</pubDate><category>rce</category><category>critical</category><category>web</category><category>CVE-2025-55182</category></item><item><title>Langflow RCE (CVE-2025-3248)</title><link>https://aeth3ron.io/en/research/langflow-rce-cve-2025-3248/</link><guid isPermaLink="true">https://aeth3ron.io/en/research/langflow-rce-cve-2025-3248/</guid><description>Technical analysis of CVE-2025-3248: unauthenticated remote code execution in Langflow through the Python code validation endpoint with CVSS 9.8.</description><pubDate>Tue, 06 May 2025 00:00:00 GMT</pubDate><category>rce</category><category>critical</category><category>ai</category><category>CVE-2025-3248</category></item><item><title>Vault</title><link>https://aeth3ron.io/en/writeups/vault/</link><guid isPermaLink="true">https://aeth3ron.io/en/writeups/vault/</guid><description>Guest SMB write access exploited via malicious LNK file to capture NTLMv2 hash; cracked for WinRM foothold, then GenericWrite on Default Domain Policy abused with SharpGPOAbuse for admin.</description><pubDate>Thu, 20 Feb 2025 00:00:00 GMT</pubDate><category>windows</category><category>active-directory</category><category>smb</category><category>ntlm-theft</category><category>responder</category><category>hashcat</category><category>genericwrite</category><category>gpo-abuse</category><category>sharphound</category><category>bloodhound</category></item><item><title>Editor</title><link>https://aeth3ron.io/en/writeups/editor/</link><guid isPermaLink="true">https://aeth3ron.io/en/writeups/editor/</guid><description>Exploiting XWiki (CVE-2025-24893) for RCE and privilege escalation via SUID abuse on ndsudo (CVE-2024-32019).</description><pubDate>Mon, 17 Feb 2025 00:00:00 GMT</pubDate><category>linux</category><category>xwiki</category><category>cve-2025-24893</category><category>suid</category><category>cve-2024-32019</category><category>rce</category><category>credentials-exposure</category></item><item><title>Resourced</title><link>https://aeth3ron.io/en/writeups/resourced/</link><guid isPermaLink="true">https://aeth3ron.io/en/writeups/resourced/</guid><description>Credentials leaked in LDAP description field give access to ntds.dit backup; hashes dumped for WinRM foothold, then RBCD attack via GenericWrite on DC for SYSTEM.</description><pubDate>Wed, 12 Feb 2025 00:00:00 GMT</pubDate><category>windows</category><category>active-directory</category><category>ntds-dit</category><category>pass-the-hash</category><category>genericwrite</category><category>rbcd</category><category>bloodhound</category><category>kerberos</category></item><item><title>Heist</title><link>https://aeth3ron.io/en/writeups/heist/</link><guid isPermaLink="true">https://aeth3ron.io/en/writeups/heist/</guid><description>SSRF for NTLM hash capture with Responder, GMSA password reading for lateral movement, and SeRestorePrivilege Utilman binary hijack for SYSTEM.</description><pubDate>Mon, 10 Feb 2025 00:00:00 GMT</pubDate><category>windows</category><category>ssrf</category><category>ntlm-relay</category><category>responder</category><category>gmsa</category><category>serestoreprivilege</category><category>utilman</category><category>bloodhound</category><category>active-directory</category></item><item><title>Nagoya</title><link>https://aeth3ron.io/en/writeups/nagoya/</link><guid isPermaLink="true">https://aeth3ron.io/en/writeups/nagoya/</guid><description>Multi-stage attack chain in AD: username harvesting, password spraying, GenericAll abuse, Silver Ticket forgery for MSSQL, and SeImpersonatePrivilege exploitation.</description><pubDate>Mon, 10 Feb 2025 00:00:00 GMT</pubDate><category>windows</category><category>active-directory</category><category>genericall</category><category>kerberoasting</category><category>silver-ticket</category><category>mssql</category><category>seimpersonateprivilege</category><category>printspoofer</category></item><item><title>Hokkaido</title><link>https://aeth3ron.io/en/writeups/hokkaido/</link><guid isPermaLink="true">https://aeth3ron.io/en/writeups/hokkaido/</guid><description>Multi-stage pivoting in a Windows AD environment: from SMB share discovery to MSSQL impersonation, Targeted Kerberoasting, and SeBackupPrivilege abuse.</description><pubDate>Wed, 05 Feb 2025 00:00:00 GMT</pubDate><category>windows</category><category>active-directory</category><category>mssql</category><category>kerberoasting</category><category>sebackupprivilege</category><category>pivoting</category><category>bloodhound</category></item><item><title>Slort</title><link>https://aeth3ron.io/en/writeups/slort/</link><guid isPermaLink="true">https://aeth3ron.io/en/writeups/slort/</guid><description>RFI vulnerability exploitation for foothold as rupert, then replacing a scheduled TFTP.EXE binary with an msfvenom payload to escalate to administrator.</description><pubDate>Sat, 01 Feb 2025 00:00:00 GMT</pubDate><category>windows</category><category>rfi</category><category>lfi</category><category>file-inclusion</category><category>php</category><category>scheduled-task</category><category>msfvenom</category></item><item><title>Hutch</title><link>https://aeth3ron.io/en/writeups/hutch/</link><guid isPermaLink="true">https://aeth3ron.io/en/writeups/hutch/</guid><description>Information disclosure in LDAP description fields for foothold, WebDAV exploitation, and LAPS password retrieval for SYSTEM.</description><pubDate>Thu, 30 Jan 2025 00:00:00 GMT</pubDate><category>windows</category><category>ldap</category><category>information-disclosure</category><category>webdav</category><category>laps</category><category>active-directory</category></item><item><title>Kevin</title><link>https://aeth3ron.io/en/writeups/kevin/</link><guid isPermaLink="true">https://aeth3ron.io/en/writeups/kevin/</guid><description>Exploitation of HP Power Manager 4.2 via a buffer overflow (CVE-2009-3999) for immediate SYSTEM access.</description><pubDate>Sat, 25 Jan 2025 00:00:00 GMT</pubDate><category>windows</category><category>hp-power-manager</category><category>buffer-overflow</category><category>metasploit</category><category>cve-2009-3999</category></item><item><title>Internal</title><link>https://aeth3ron.io/en/writeups/internal/</link><guid isPermaLink="true">https://aeth3ron.io/en/writeups/internal/</guid><description>Exploitation of the MS09-050 SMBv2 vulnerability for immediate remote code execution as NT AUTHORITY\\SYSTEM.</description><pubDate>Mon, 20 Jan 2025 00:00:00 GMT</pubDate><category>windows</category><category>smb</category><category>ms09-050</category><category>metasploit</category><category>legacy-windows</category><category>rce</category></item><item><title>Intentions</title><link>https://aeth3ron.io/en/writeups/intentions/</link><guid isPermaLink="true">https://aeth3ron.io/en/writeups/intentions/</guid><description>Leverage SQL injection for authentication bypass, exploit PHP Imagick for RCE, recover hardcoded Git credentials, and perform a side-channel attack using file capabilities.</description><pubDate>Thu, 15 Aug 2024 00:00:00 GMT</pubDate><category>linux</category><category>sqli</category><category>api-manipulation</category><category>imagick</category><category>git</category><category>side-channel</category><category>capabilities</category></item><item><title>Sau</title><link>https://aeth3ron.io/en/writeups/sau/</link><guid isPermaLink="true">https://aeth3ron.io/en/writeups/sau/</guid><description>Exploiting Request Baskets 1.2.1 SSRF (CVE-2023-27163) chained with Maltrail v0.53 command injection for RCE, and privilege escalation via sudo abuse on systemctl.</description><pubDate>Sun, 10 Dec 2023 00:00:00 GMT</pubDate><category>linux</category><category>request-baskets</category><category>cve-2023-27163</category><category>ssrf</category><category>maltrail</category><category>command-injection</category><category>systemctl</category></item></channel></rss>