Cerberus - HackTheBox
Una máquina desafiante en la que explotaremos un Icinga Web 2 y abusaremos de Firejail como también de un remote port forwarding.
Windows Firejail Icinga Port Forwarding Container BashUna máquina desafiante en la que explotaremos un Icinga Web 2 y abusaremos de Firejail como también de un remote port forwarding.
Windows Firejail Icinga Port Forwarding Container BashCan you gain access to this gaming server built by amateurs with no experience of web development and take advantage of the deployment system.
ssh2john id_rsa Gobuster lxd Docker container sudoersThis CTF focuses on success through enumeration.
mysql ssh suidMedium-level machine, where the ‘SQL Server management studio’ tool is exploited, in addition to making use of vulnerable certificates for privilege escalation.
Active Directory Windows SMB Template Certificate WinrmA box of medium difficulty in which concepts such as: Json attacks, code analysis, script creation, etc. are presented.
LFI Python Json Deserialization sudoers dotnet Ilspy f#Opacity is an easy machine that can help you in the penetration testing learning process. There are 2 hash keys located on the machine (user - local.txt and root - proof.txt). Can you find them and become root?
PHP File Upload RCE Python Scripting KeepassA box that sees a lot of fuzzing, plus exploits targeting ‘dompdf’ with relatively easy privilege escalation.
dompdf NextJS api exiftool metadataHard box in which the Windows ‘smb’ service is listed, as well as using password cracking techniques, RFI, Port Forwarding, etc.
Windows RFI crackmapexec Port Forwarding Chisel PowershellIn this machine, we will learn about LFI (Local File Inclusion) and How to create an exploit or poisoning via apache access.log (apache log poisoning through lfi). For Privilege Escalation is how to change index.php codes to PHP simple reverse shell script on the webserver.
Path Traversal Apache Log Poisoning Internal Web Server PHPDifficulty: Intermediate Flags: Your Goal is to get root and read /root/flag.txt
Criptography Decoding Bruteforce Hydra Crunch SSH