-
Ignite
Exploiting FuleCMS v1.4 and escalating to root with password reuse
-
MD2PDF
Injecting an iframe in a markdown file to gain access to an HTTP server which only allows connections from localhost
-
Atom
Malicious PDF file to remote code execution and abusing Redis to get the admin credentials
-
Agent Sudo
Password attack with hydra and stegseek
-
GamingServer
Finding an encrypyed SSH key and dictionary and escalating through LXC
-
Brute It
HTTP post form attack with Hydra and cat-ing passwd and the shadow file
-
ConvertMyVideo
Remote file execution through an api
-
Hacker vs Hacker
Gaining access to an already compromised machine and stopping a script that tries to kick us out
-
Lesson Learned
SQL injection using `AND 1=1-- -` instead of `OR 1=1-- -`
-
Cat Pictures 2
Security through obscurity, exploiting a Ansible playbook script and a kernel exploit