All Posts

  • Published on
    Connect via IPSEC VPN to get access to the host, clues from SNMP to get connected, found out its a Windows host, uploaded a webshell via FTP, then privesc with JuicyPotato.
  • Published on
    Decrypt a file with openssl, gain credentials, take advantage of H2 database for file read root, then exploited h2.py to get root.
  • Published on
    Great machine that provides an excellent way of presenting XXE Injection, leading to an SSH key, and then privesc'ing with pwnkit.
  • Published on
    Discovered SQLi to then enumerate the database, authenticate as admin, realize it is vulnerable to some sort of max character length exploit, pivoting from www-data to moshe, then yossi, and finally root.