Filtering by category tryhackme
-
Epoch
RCE through command injection in an url parameter
-
Git Happens
Using git-dumper to download the repo and using git history to find credentials
-
Glitch
RCE through POST parameter and privilege escalation through a FireFox profile
-
Opacity
RCE through command injection, cracking a Keepass database and exploiting permissions on a script
-
Dogcat
Exploiting an LFI and breaking out of a Docker container
-
Valley
Web enumeration, pcacp investigation and privilege escalation through a Python cronjob with root permissions
-
Capture!
Custom python script for brute forcing with username and password dictionaries
-
Mustacchio
XML external entity (XXE) injection and privilege escalation through a binary with a relative path
-
VulnNet: Node
NodeJS serialization exploit and privilege escalation through NPM and sudo on vulnnet-job service
-
Year Of The Rabbit
Web enumeration, FTP brute force with custom password list, decoding a Brainfuck script and privilege escalation with non root sudo permission on vi