-
Anonforce
Anonymous FTP access and cracking a private GPG key file
-
Brooklyn Nine Nine
Steganography and a GTFOBin for Nano and Less
-
U.A. High School
RCE through a hidden command injection parameter, finding credetials with steghide on an image and privilege escalation through a bash script with sudo permissions
-
Easy Peasy
Finding hidden directories, using steghide and abusing a cronjob to escalate to root
-
TakeOver
Vhost / subdomain enumeration and domain takeover
-
Enumeration & Brute Force
Brute forcing basic auth with Hydra and a OTP with a custom python script
-
Publisher
Exploiting SPIP 4.2.0 (CVE-2023-27372) and privilege escalation through Docker
-
mKingdom
Using default credentials to access the CMS, uploading a malicious PHP file to get RCE and escalating privileges using write access to /etc/hosts
-
Cyborg
Cracking the password of a Borg archive and abusing permissions to execute code as root
-
Ignite
Exploiting FuleCMS v1.4 and escalating to root with password reuse