Published onAugust 13, 2023HTB FriendZone139/445---SMBDNSLFIpythonFunny box, met with a lot of memes which indicated I was getting closer or further from the objective, enumerating SMB & DNS, to then exploit LFI and privesc with python.
Published onJuly 22, 2023HTB CronOSnslookupDNSSQLiCommand-InjectioncrontabVery intriguing machine, where we exploit multiple different endpoints and pivot in ways where I was precisely mentally evaluated.
Published onJuly 21, 2023HTB BrainfuckDNSWordPressSMTPEnumerating DNS leads to finding a vulnerable WordPress endpoint, where we exploit SMTP to gain root.