active Retires on: October 15, 2026
Hard
HTB DarkZero Returns Complete Writeup: CVE-2026-33937 (Handlebars AST Injection), Gitea Actions Abuse and Cross Forest Trust Root Escalation
A comprehensive penetration testing guide exploiting a Handlebars AST injection (CVE-2026-33937) for an initial foothold, abusing Gitea Actions through Kerberos SSPI to steal user.txt, pivoting into an internal Active Directory network across two forests, and escalating to host root on a Domain Controller through delegated OU rights, a cracked NTLM hash, and a forged cross forest golden ticket.
Table of Contents
Unlock this write-up to reveal its sections.
Content Locked
Have the password? Enter it above to read this write-up.
Comments