Filtering by category tryhackme
-
Library
Brute forcing SSH access and escalating using a poorly configured sudo rule
-
CyberLens
Exploiting Apache Tika 1.17 with MetaSploit and abusing `AlwaysInstallElevated` to escalate to SYSTEM
-
TryHack3M: Bricks Heist
Exploiting Wordpress v1.9.5 (CVE-2024-25600) and blockchain forensics
-
Pyrat
RCE through an open port which executes Python code, finding credentials in a Git config file and brute forcing a Python service
-
Lookup
Using FFUF to brute force a user name and password and abusing a binary to read files as root
-
The Sticker Shop
Basic XSS in through a form
-
Whiterose
Vhost fuzzing, Server-side template injection (STTI) for EJS and privilege escalation through sudoedit
-
Anonforce
Anonymous FTP access and cracking a private GPG key file
-
Brooklyn Nine Nine
Steganography and a GTFOBin for Nano and Less
-
U.A. High School
RCE through a hidden command injection parameter, finding credetials with steghide on an image and privilege escalation through a bash script with sudo permissions