Plant Photographer Writeup - TryHackMe
Exploit a plant photography web app via SQLi to extract creds, abuse Shoot! tool for RCE, pivot through user flags, and escalate via SUID binary.
HackIndex
Language
Browse by service or platform, or jump straight to an attack phase: Reconnaissance, Enumeration, Exploitation, Privilege Escalation. Find the exact cheatsheet or technique you need.
709+
Cheatsheets, blogs & guides
61+
Services & platforms
63+
CTF writeups
31+
CVEs PoC's
Each service contains attack phases and individual technique cheatsheets. This is a horizontally scrolling list of services. You can tab through items.
HTTP/HTTPS pentesting covers recon, enum, vuln discovery, and exploitation of web apps via XSS, SQLi, RCE, LFI, SSRF, JWT flaws, file uploads, and more through to exfil and persistence
Linux attack reference covering enumeration, privesc via SUID and sudo, shell upgrades, lateral movement via SSH, persistence through cron and systemd, and data exfiltration techniques
Windows pentesting reference covering exploitation, privesc, lateral movement via SMB, WMI and RDP, persistence, AD enumeration, and data exfiltration over HTTP, DNS, and FTP
Wireless pentesting covering monitor mode setup, passive recon, AP and client enumeration, PMKID capture, WEP/WPA cracking, rogue APs, and post-auth traffic decryption
Active Directory is Microsoft's directory service for managing users, computers, and policies in Windows networks. It is the central authentication and authorization backbone of most enterprise environments.
Covers attacking AI systems across recon of endpoints and APIs, threat modeling agent permissions, finding vulns in LLMs and RAG, exploiting AI infra, and poisoning supply chains
Open source intelligence platform covering target profiling, identity tracing, corporate and domain mapping, SOCMINT, dark web monitoring, threat actor attribution, and analysis using only publicly available sources
FTP file transfer service. Attackers check banners, anonymous access, writable dirs, cleartext creds, CVEs, and backdoors, then exploit for shells, brute-force, or data exfiltration
Detailed walkthroughs of HTB machines and CTF challenges.
Exploit a plant photography web app via SQLi to extract creds, abuse Shoot! tool for RCE, pivot through user flags, and escalate via SUID binary.
Exploit SUID binary and bypass AppArmor restrictions to escalate privileges on a Linux machine through careful enumeration and profile analysis.
Easy Windows box involving LDAP enumeration, custom binary reverse engineering to extract credentials, and Kerberos resource-based constrained delegation abuse for SYSTEM.
Exploit Index
Browse CVEs, GHSA advisories, and PoC exploits curated by our team.
CVE-2026-44262 - dedoc/scramble Unauthenticated RCE
CVE-2026-2991 KiviCare authentication bypass
CVE-2026-3891 - Pix for WooCommerce Unauthenticated File Upload
CVE-2025-66398 - SignalK Server RCE
CVE-2024-56348 - JetBrains TeamCity Authentication Bypass + RCE
Ask questions, and stay current with techniques.
We use cookies to improve your browsing experience, analyze site traffic, and personalize content. By clicking "Accept All", you consent to our use of cookies. Privacy Policy.