Dev.to
6/26/2026

HackTheBox: JobTwo Writeup
Short summary
Windows Server 2022 CTF walkthrough documenting a complete attack chain from initial phishing access via Word macro with PowerShell reverse shell, through credential extraction from hMailServer, lateral movement between users, to privilege escalation via CVE-2023-27532 (Veeam RCE). Includes Nmap reconnaissance, exploitation techniques, and detailed command examples.
- •Phishing vector: VBA macro embedded in .docm Word document executes PowerShell reverse shell when opened
- •Lateral movement: Extract hMailServer database credentials to pivot from julian to ferdinand account
- •Privilege escalation: Exploit CVE-2023-27532 in Veeam Backup & Replication for SYSTEM-level access
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



