-
Library
Brute forcing SSH access and escalating using a poorly configured sudo rule
-
CyberLens
Exploiting Apache Tika 1.17 with MetaSploit and abusing `AlwaysInstallElevated` to escalate to SYSTEM
-
Lookup
Using FFUF to brute force a user name and password and abusing a binary to read files as root
-
Cicada
Ldap search for users and smb enum. User has SeBackupPrivilege and SeRestorePrivilege to backup the ntds.dit and system hive
-
Anonforce
Anonymous FTP access and cracking a private GPG key file
-
Brooklyn Nine Nine
Steganography and a GTFOBin for Nano and Less
-
Easy Peasy
Finding hidden directories, using steghide and abusing a cronjob to escalate to root
-
Enumeration & Brute Force
Brute forcing basic auth with Hydra and a OTP with a custom python script
-
mKingdom
Using default credentials to access the CMS, uploading a malicious PHP file to get RCE and escalating privileges using write access to /etc/hosts
-
Cyborg
Cracking the password of a Borg archive and abusing permissions to execute code as root