Web
- Unionize
UNION-based SQL injection against a SQLite-backed school lookup, enumerating the schema one column at a time.
- Rick and Morty
Creds on the page and in robots.txt fed a webshell, where less beat a cat blacklist and sudo less finished it.
- Mr. Robot
A WordPress brute force off a robots.txt dictionary gave a shell, and SUID nmap gave root. Three keys.
- Carnage
SQLi on 81 and a double-extension upload bypass on 82 gave a duku shell and several web-root flags.
- Internal
WordPress theme injection, an SSH-tunnelled Jenkins, and a note in /opt chained to root across two hosts.
- Tyler
A file-upload webshell, an SMB share with creds, and SUID vim writing sudoers gave root.
- H1: Easy
Default CMS creds and two PHP upload points reached serv3, then a writable cron gave root.
- Jack
A WordPress plugin privesc gave a shell, a readable SSH key gave a user, and a writable module in a root cron gave root.
- Lion
An outdated nostromo server on 8080 had a public RCE for a user shell.
- Res
An unauthenticated Redis wrote a PHP webshell, then SUID xxd read root.