-
LazyAdmin
RCE through command injection and priv esc through a backup script we can write to
-
Kiba
Exploiting Kibana Timelion to get a reverse shell and escalating with cap_setuid in Python
-
Tomghost
Exploiting Tomcat v9.0.30 (CVE-2020-1938) and privilege escalation through the zip binary with sudo permissions
-
Agent T
PHP v8.1.0-dev backdoor
-
Epoch
RCE through command injection in an url parameter
-
Git Happens
Using git-dumper to download the repo and using git history to find credentials
-
Glitch
RCE through POST parameter and privilege escalation through a FireFox profile
-
Opacity
RCE through command injection, cracking a Keepass database and exploiting permissions on a script
-
Dogcat
Exploiting an LFI and breaking out of a Docker container
-
Valley
Web enumeration, pcacp investigation and privilege escalation through a Python cronjob with root permissions