❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayAnonhack

DogCat – Exploiting LFI and Docker Privilege Escalation -TryHackMe Walkthrough

By: Jo
21 September 2024 at 11:45
In this walkthrough, we’ll explore the Dogcat room on TryHackMe, a box that features a Local File Inclusion (LFI) vulnerability and Docker privilege escalation. LFI allows us to read sensitive files from the system and eventually gain access to the server.There are a total of 4 flags in this machine which we need to find. […]

Prime: 1 – Walkthrough for OSCP Series

By: Jo
11 June 2023 at 12:05
Prime: 1 is a challenging boot2root machine created by Suraj Pandey. It is designed for those who are preparing for the OSCP exam and is a great way to practice your penetration testing skills. In this blog post, I will walk you through the steps I took to root the machine, including: Performing a port […]

digital world.local: Vengeance Walkthrough – OSCP Way

By: Jo
8 October 2022 at 13:13
Vengeance is one of the digital world.local series which makes vulnerable boxes closer to OSCP labs. This box has a lot of services and there could be multiple ways to exploit this, Below is what I have tried. Lab requirement: 1. Kali VM 2. Download Vengeance: https://www.vulnhub.com/entry/digitalworldlocal-vengeance,704 3. Some patience. I have written article already […]

The Binary Exploitation: Stack based Buffer overflow

By: Jo
19 March 2022 at 11:38
This article talks about cracking Level 13 Binary of Cyberstart CTF. The hint that was given for this challenge is β€œCyclic Pattern”, which means we need to use pattern finder tool to figure out the length of the buffer and then run the arbitrary function. Let’s crack this: Running the binary gives us this output: […]

Log4Shell Quick Lab Setup for Testing

By: Jo
10 January 2022 at 08:00
Last month, On December 09 2021, The release of a Remote Code Execution POC over twitter involving exploitation of Apache’s log4j2 logging class took everyone’s peace away. The attack was pretty simple and the fact that it can be easily exploited by anyone is what made this more terrifying. The first edition of this attack […]

digital world.local: Vengeance Walkthrough – OSCP Way

By: Jo
8 October 2022 at 13:13
Vengeance is one of the digital world.local series which makes vulnerable boxes closer to OSCP labs. This box has a lot of services and there could be multiple ways to exploit this, Below is what

Continue readingdigital world.local: Vengeance Walkthrough – OSCP Way

The Binary Exploitation: Stack based Buffer overflow

By: Jo
19 March 2022 at 11:38
This article talks about cracking Level 13 Binary of Cyberstart CTF. The hint that was given for this challenge is β€œCyclic Pattern”, which means we need to use pattern finder tool to figure out the

Continue readingThe Binary Exploitation: Stack based Buffer overflow

Log4Shell Quick Lab Setup for Testing

By: Jo
10 January 2022 at 08:00
Last month, On December 09 2021, The release of a Remote Code Execution POC over twitter involving exploitation of Apache’s log4j2 logging class took everyone’s peace away. The attack was pretty simple and the fact

Continue readingLog4Shell Quick Lab Setup for Testing

Insecure Code Management – Git

By: Jo
9 August 2021 at 07:04
Insecure code management is when part of the code exposes sensitive information which shouldn’t be exposed to the world. Now it can happen in a lot of situation where the API keys/Passwords are hard-coded and

Continue readingInsecure Code Management – Git

❌
❌