Filtering by category tryhackme
-
Brute It
HTTP post form attack with Hydra and cat-ing passwd and the shadow file
-
ConvertMyVideo
Remote file execution through an api
-
Hacker vs Hacker
Gaining access to an already compromised machine and stopping a script that tries to kick us out
-
Wgel CTF
Enumeration and privilege escalation through wget with sudo permissions
-
Lesson Learned
SQL injection using `AND 1=1-- -` instead of `OR 1=1-- -`
-
Cat Pictures 2
Security through obscurity, exploiting a Ansible playbook script and a kernel exploit
-
LazyAdmin
RCE through command injection and priv esc through a backup script we can write to
-
Kiba
Exploiting Kibana Timelion to get a reverse shell and escalating with cap_setuid in Python
-
Tomghost
Exploiting Tomcat v9.0.30 (CVE-2020-1938) and privilege escalation through the zip binary with sudo permissions
-
Agent T
PHP v8.1.0-dev backdoor