<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Credential Manager on bokkapig</title><link>https://bokkapig.pages.dev/tags/credential-manager/</link><description>Recent content in Credential Manager on bokkapig</description><generator>Hugo</generator><language>en-gb</language><lastBuildDate>Sat, 08 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://bokkapig.pages.dev/tags/credential-manager/index.xml" rel="self" type="application/rss+xml"/><item><title>DanglingTree</title><link>https://bokkapig.pages.dev/writeups/danglingtree/</link><pubDate>Sat, 08 Aug 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/danglingtree/</guid><description>DanglingTree is a Windows Server 2025 domain controller whose only externally useful services are SMB and a Windows Admin Center gateway on 6600. A guest-readable IT share leaks an RoE PDF with anderson.w&amp;rsquo;s credentials; WAC 2.6.4.11 is vulnerable to CVE-2026-26119 (&amp;lsquo;Domain Overlord&amp;rsquo;), letting that low-privileged account reach the powershellApi/invokeCommand endpoint and run PowerShell on the DC. SmarterMail 100.0.9504 listens only on localhost:17017, so it is only reachable post-foothold — CVE-2026-23760 (the IsSysAdmin=true force-reset-password auth bypass) resets svc_mail to system administrator, whose Volume-Mount &amp;lsquo;command&amp;rsquo; feature is OS command execution. SmarterMail stores mailbox passwords reversibly; decrypting noah.b&amp;rsquo;s yields RiverDragon#Storm25, reused as her AD password (LogonUser impersonation -&amp;gt; user.txt). Root is a three-link AD chain: noah.b&amp;rsquo;s Windows Credential Manager holds a DPAPI-protected domain credential for alex.o (SunsetMountainPeak@2025), decrypted with noah.b&amp;rsquo;s password and master key; alex.o is in support-it which has ForceChangePassword over jake.h; and jake.h (Template_Editors) has CreateChild on the AD CS Certificate Templates container. The CA is configured to issue templates (RemoteAccessVPN, EmployeeAuthTemplate, VPNUserTemplate) that do not exist as objects — recreating one as a vulnerable ESC1 template, enrolling a certificate for Administrator, and authenticating with it yields the Administrator hash and root.</description></item></channel></rss>