-
LazyAdmin
RCE through command injection and priv esc through a backup script we can write to
-
Kiba
Exploiting Kibana Timelion to get a reverse shell and escalating with cap_setuid in Python
-
Agent T
PHP v8.1.0-dev backdoor
-
Epoch
RCE through command injection in an url parameter
-
Git Happens
Using git-dumper to download the repo and using git history to find credentials
-
Glitch
RCE through POST parameter and privilege escalation through a FireFox profile
-
Dogcat
Exploiting an LFI and breaking out of a Docker container
-
Capture!
Custom python script for brute forcing with username and password dictionaries
-
Boiler CTF
sar2html Remote Code Execution on a Joomla site and find has an suid bit set
-
Inclusion
LFI to get SSH credentials and escalating to root with socat