HTB: blazorized Writeup
blazorized is a Hard-difficulty Windows domain controller machine from HackTheBox.
2024 Business CTF - Vault of Hope: Submerged
Full penetration test of web server with SPIP CMS exploitation, leading to initial access and system compromise
HTB: wifinetictwo Writeup
wifinetictwo is a Medium-difficulty Linux machine featuring OpenPLC Runtime exploitation and WiFi security attacks.
2024 Cyber Apocalypse: SerialFlow
Exploit memcached injection and Python pickle deserialization for RCE
2024 Cyber Apocalypse: Web SerialFlow
Exploit serialization vulnerabilities to achieve RCE through pickle deserialization
HTB Hack The Boo Practice: Web Pumpkinspice
Command injection vulnerability in localhost-restricted endpoint
HTB Hack The Boo Practice: Web Spellbound Servants
Pickle deserialization exploitation for remote code execution
2023 Business CTF: Lagmon
Exploit WordPress plugin vulnerabilities and LLM prompt injection for RCE
2023 Business CTF: Web Watersnake
Exploit a Java deserialization vulnerability in a water level monitoring application.
2023 Cyber Apocalypse: Hijack
Exploit Python deserialization vulnerabilities in YAML and Pickle
2022 Hack The Boo: Evaluation Deck
Code injection via unsafe use of Python compile() and exec() in arithmetic evaluation
2022 Hack The Boo: Spookifier
Server-Side Template Injection (SSTI) in Mako template engine leading to RCE