Back to feed
Dev.to
Dev.to
6/26/2026
HackTheBox: JobTwo Writeup

HackTheBox: JobTwo Writeup

Short summary

Windows Server 2022 CTF walkthrough documenting a complete attack chain from initial phishing access via Word macro with PowerShell reverse shell, through credential extraction from hMailServer, lateral movement between users, to privilege escalation via CVE-2023-27532 (Veeam RCE). Includes Nmap reconnaissance, exploitation techniques, and detailed command examples.

  • Phishing vector: VBA macro embedded in .docm Word document executes PowerShell reverse shell when opened
  • Lateral movement: Extract hMailServer database credentials to pivot from julian to ferdinand account
  • Privilege escalation: Exploit CVE-2023-27532 in Veeam Backup & Replication for SYSTEM-level access

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more