Eighteen
Eighteen
Eighteen 805
Eighteen
RETIRED MACHINE

Eighteen

Eighteen - Windows Windows
Eighteen - Easy Easy

2.4

MACHINE RATING

7149

USER OWNS

3844

SYSTEM OWNS

15/11/2025

RELEASED
Created by kavigihan

Machine Synopsis

`Eighteen` is an easy difficulty Windows machine that demonstrates common weaknesses in database access control and Active Directory misconfigurations. Initial access is obtained by identifying valid MSSQL credentials and abusing impersonation privileges to access backend application data. Extracted password hashes are cracked offline and used for password spraying, leading to WinRM access as a domain user. Privilege escalation is achieved by abusing delegated permissions in Active Directory. Specifically, membership in a group with CreateChild rights over an Organisational Unit allows exploitation of the BadSuccessor technique to create a delegated Managed Service Account (dMSA) linked to the Administrator account, ultimately leading to full domain compromise.

Machine Matrix

Ready to start your
hacking journey?