
User Completes Fusion Corp Challenge on TryHackMe Using Phone and GitHub Codespace
cybersecurityTryHackMepenetration_testingAS-REP_roastingWinRMLDAPSeBackupPrivilegeTermuxGitHub_Codespacesred_team
The user completed the Fusion Corp challenge on TryHackMe using Termux on their phone, with a free GitHub Codespace for Hashcat. They exploited an AS-REP roasting attack to gain a WinRM shell, discovered a password stored in an LDAP description field, and used SeBackupPrivilege to obtain the admin flag. The domain compromise was enabled by a password left in a description box and a user assigned to the Backup Operators group.