Thm
- Tyler
A file-upload webshell, an SMB share with creds, and SUID vim writing sudoers gave root.
- Wonderland
A hidden path leaked creds, a sudo module hijack and a PATH-hijacked SUID stepped through users, and perl setuid gave root.
- H1: Easy
Default CMS creds and two PHP upload points reached serv3, then a writable cron gave root.
- Jack
A WordPress plugin privesc gave a shell, a readable SSH key gave a user, and a writable module in a root cron gave root.
- Lion
An outdated nostromo server on 8080 had a public RCE for a user shell.
- Res
An unauthenticated Redis wrote a PHP webshell, then SUID xxd read root.
- Production
Anonymous FTP leaked an SSH key, then a sudo su chain and sudo git reached root.
- HaskHell
A Haskell class site ran uploaded code, and sudo flask run finished the box.
- Panda
hydra found SSH, WordPress gave a shell, and sudo ftp with a SUID find reached root.
- Bookstore
REST API v1 fuzzing leaked a debugger PIN, the Werkzeug console gave a shell, and a SUID binary reversed to a XOR check.