Web
- HaskHell
A Haskell class site ran uploaded code, and sudo flask run finished the box.
- Panda
hydra found SSH, WordPress gave a shell, and sudo ftp with a SUID find reached root.
- Bookstore
REST API v1 fuzzing leaked a debugger PIN, the Werkzeug console gave a shell, and a SUID binary reversed to a XOR check.
- Hogwarts
SQL injection on two portals gave SSH creds, then sudo date and SUID ip to root.