Filtering by category tryhackme
-
MD2PDF
Injecting an iframe in a markdown file to gain access to an HTTP server which only allows connections from localhost
-
Agent Sudo
Password attack with hydra and stegseek
-
GamingServer
Finding an encrypyed SSH key and dictionary and escalating through LXC
-
Brute It
HTTP post form attack with Hydra and cat-ing passwd and the shadow file
-
ConvertMyVideo
Remote file execution through an api
-
Hacker vs Hacker
Gaining access to an already compromised machine and stopping a script that tries to kick us out
-
Lesson Learned
SQL injection using `AND 1=1-- -` instead of `OR 1=1-- -`
-
Cat Pictures 2
Security through obscurity, exploiting a Ansible playbook script and a kernel exploit
-
LazyAdmin
RCE through command injection and priv esc through a backup script we can write to
-
Kiba
Exploiting Kibana Timelion to get a reverse shell and escalating with cap_setuid in Python