Nexus Writeup - HackTheBox
SQL injection on a web app leads to credential extraction, enabling SSH access. Privilege escalation via misconfigured Linux permissions yields root.
HackIndex
Language
51 writeups
SQL injection on a web app leads to credential extraction, enabling SSH access. Privilege escalation via misconfigured Linux permissions yields root.
Memory forensics challenge using Volatility to analyze a Linux memory dump, extracting artifacts to uncover hidden flags through process and file analysis.
Linear programming attack on a custom XOR-based encryption scheme to recover the flag by solving constraints derived from the cipher's operations.
Exploit a plant photography web app via SQLi to extract creds, abuse Shoot! tool for RCE, pivot through user flags, and escalate via SUID binary.
Exploit MongoDB misconfiguration with unauthenticated access to enumerate databases and retrieve credentials, ultimately gaining root on an easy Linux box.
Exploiting a cloud misconfiguration in a hard Linux HackTheBox machine involving AWS/cloud enumeration, privilege escalation through misconfigured services.
Windows medium box involving checkpoint security mechanisms, requiring careful enumeration, privilege escalation, and bypassing security controls to gain root access.
Exploit a Flask SSTI vulnerability in a developer hub app to gain RCE, then escalate privileges via misconfigured sudo or SUID binaries on Linux.
Windows medium box involving log analysis and exploitation of logging mechanisms to gain foothold and escalate privileges through misconfigured services.
Exploit SUID binary and bypass AppArmor restrictions to escalate privileges on a Linux machine through careful enumeration and profile analysis.
Easy Windows box involving LDAP enumeration, custom binary reverse engineering to extract credentials, and Kerberos resource-based constrained delegation abuse for SYSTEM.
Exploiting JWT algorithm confusion and SSTI vulnerabilities on a Linux machine to escalate privileges and capture the flag.
Exploit information disclosure on a Linux web challenge by enumerating exposed endpoints to uncover hidden facts and capture the flag.
Exploit a Pterodactyl game panel via subdomain enumeration, command injection, and privilege escalation to root on this medium Linux box.
SQL injection in Cacti leads to RCE, followed by port forwarding and privilege escalation techniques to fully compromise this Windows machine.
We use cookies to improve your browsing experience, analyze site traffic, and personalize content. By clicking "Accept All", you consent to our use of cookies. Privacy Policy.