

<feed xmlns="http://www.w3.org/2005/Atom">
  <id>https://0xc4rc3l.github.io/</id>
  <title>0xc4rc3l's Blog</title>
  <subtitle>Red team trainee focused on AD exploitation, C2 frameworks, and real-world attack simulations.</subtitle>
  <updated>2026-03-19T19:07:49+00:00</updated>
  <author>
    <name>0xc4rc3l</name>
    <uri>https://0xc4rc3l.github.io/</uri>
  </author>
  <link rel="self" type="application/atom+xml" href="https://0xc4rc3l.github.io/feed.xml"/>
  <link rel="alternate" type="text/html" hreflang="en"
    href="https://0xc4rc3l.github.io/"/>
  <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator>
  <rights> © 2026 0xc4rc3l </rights>
  <icon>/assets/img/favicons/favicon.ico</icon>
  <logo>/assets/img/favicons/favicon-96x96.png</logo>


  
  <entry>
    <title>HackTheBox | CodePartTwo</title>
    <link href="https://0xc4rc3l.github.io/posts/HackTheBox-CodePartTwo/" rel="alternate" type="text/html" title="HackTheBox | CodePartTwo" />
    <published>2026-01-31T00:00:00+00:00</published>
  
    <updated>2026-01-31T00:00:00+00:00</updated>
  
    <id>https://0xc4rc3l.github.io/posts/HackTheBox-CodePartTwo/</id>
    <content type="text/html" src="https://0xc4rc3l.github.io/posts/HackTheBox-CodePartTwo/" />
    <author>
      <name>0xc4rc3l</name>
    </author>

  
    
    <category term="HackTheBox" />
    
    <category term="HackTheBox-Easy" />
    
  

  <summary>CodePartTwo is an Easy Linux machine that features a vulnerable Flask-based web application. Initial web enumeration reveals a JavaScript code editor powered by a vulnerable version of js2py, which allows for remote code execution via sandbox escape. Exploiting this flaw grants access to the system as an unprivileged user. Further enumeration reveals an SQLite database containing password hashe...</summary>

  </entry>

  
  <entry>
    <title>HackTheBox | Puppy</title>
    <link href="https://0xc4rc3l.github.io/posts/HackTheBox-Puppy/" rel="alternate" type="text/html" title="HackTheBox | Puppy" />
    <published>2025-09-27T00:00:00+00:00</published>
  
    <updated>2026-03-19T17:10:12+00:00</updated>
  
    <id>https://0xc4rc3l.github.io/posts/HackTheBox-Puppy/</id>
    <content type="text/html" src="https://0xc4rc3l.github.io/posts/HackTheBox-Puppy/" />
    <author>
      <name>0xc4rc3l</name>
    </author>

  
    
    <category term="Hackthebox" />
    
    <category term="HackTheBox-Medium" />
    
  

  <summary>Puppy is a Medium Difficulty machine that features a non-default SMB share called DEV. With the provided credentials for user levi.james, enumeration of the domain is possible. The enumeration reveals that this user has GenericWrite privileges over the Developers group. After adding Levi to this group, we can access the previously inaccessible DEV share. This share contains the backup of a KeeP...</summary>

  </entry>

  
  <entry>
    <title>HackTheBox | Fluffy</title>
    <link href="https://0xc4rc3l.github.io/posts/HackTheBox-Fluffy/" rel="alternate" type="text/html" title="HackTheBox | Fluffy" />
    <published>2025-09-20T00:00:00+00:00</published>
  
    <updated>2026-03-19T17:10:12+00:00</updated>
  
    <id>https://0xc4rc3l.github.io/posts/HackTheBox-Fluffy/</id>
    <content type="text/html" src="https://0xc4rc3l.github.io/posts/HackTheBox-Fluffy/" />
    <author>
      <name>0xc4rc3l</name>
    </author>

  
    
    <category term="HackTheBox" />
    
    <category term="HackTheBox-Easy" />
    
  

  <summary>Fluffy is an easy-difficulty Windows machine designed around an assumed breach scenario, where credentials for a low-privileged user are provided. By exploiting CVE-2025-24071, the credentials of another low-privileged user can be obtained. Further enumeration reveals the existence of ACLs over the winrm_svc and ca_svc accounts. WinRM can then be used to log in to the target using the winrc_svc...</summary>

  </entry>

  
  <entry>
    <title>Fixing Kerberos Clock Skew</title>
    <link href="https://0xc4rc3l.github.io/posts/Fixing-Kerberos-Clock-Skew/" rel="alternate" type="text/html" title="Fixing Kerberos Clock Skew" />
    <published>2025-04-20T00:00:00+00:00</published>
  
    <updated>2026-03-19T18:07:19+00:00</updated>
  
    <id>https://0xc4rc3l.github.io/posts/Fixing-Kerberos-Clock-Skew/</id>
    <content type="text/html" src="https://0xc4rc3l.github.io/posts/Fixing-Kerberos-Clock-Skew/" />
    <author>
      <name>0xc4rc3l</name>
    </author>

  
    
    <category term="Active-Directory" />
    
  

  <summary>Fixing Kerberos Clock Skew    TL;DR: Two commands. Thirty seconds. Back to hacking.     The problem  You’ve got valid credentials. You’ve got your tooling ready. Then you fire off secretsdump, psexec, or evil-winrm — and get nothing back but a wall of red:  [-] Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great)   Kerberos is paranoid about time. By design, it rejects any authenticatio...</summary>

  </entry>

  
  <entry>
    <title>HackTheBox | Administrator</title>
    <link href="https://0xc4rc3l.github.io/posts/HackTheBox-Administrator/" rel="alternate" type="text/html" title="HackTheBox | Administrator" />
    <published>2025-04-19T00:00:00+00:00</published>
  
    <updated>2026-03-19T19:07:38+00:00</updated>
  
    <id>https://0xc4rc3l.github.io/posts/HackTheBox-Administrator/</id>
    <content type="text/html" src="https://0xc4rc3l.github.io/posts/HackTheBox-Administrator/" />
    <author>
      <name>0xc4rc3l</name>
    </author>

  
    
    <category term="HackTheBox-Medium" />
    
    <category term="Active Directory Exploitation Track" />
    
  

  <summary>Administrator is a medium-difficulty Windows machine designed around a complete domain compromise scenario, where credentials for a low-privileged user are provided. To gain access to the michael account, ACLs (Access Control Lists) over privileged objects are enumerated, leading us to discover that the user olivia has GenericAll permissions over michael, allowing us to reset his password. With...</summary>

  </entry>

</feed>


