Bumblebee
https://app.hackthebox.com/sherlocks/Bumblebee
https://app.hackthebox.com/sherlocks/Bumblebee
What was the username of the external contractor?
What IP address did the contractor use to create their account?
What is the post_id of the malicious post that the contractor made?
What is the full URI that the credential stealer sends its data to?
When did the contractor log into the forum as the administrator? (UTC)
In the forum there are plaintext credentials for the LDAP connection, what is the password?
What is the user agent of the Administrator user?
What time did the contractor add themselves to the Administrator group? (UTC)
What time did the contractor download the database backup? (UTC)
What was the size in bytes of the database backup as stated by access.log?