/// HACKINGCLUB

<< Back to Writeups

[ MACHINES ]

  • Techscope Hard
    Git Exposed, PHP Object Injection in Yii2 Framework to achieve RCE and Command Injection via cron binary reading from world-writable config file (privesc).
  • SynthLabs Medium
    Git Exposed, JWT modification, Command Injection with bypass, WordPress user create via PHP script using wp-load.php and RCE in WordPress by modifying the themes functions.php file.
  • Guardian Easy
    Bypass Verification with SQL Injection, Code Review to get RCE and Reverse Engineering to get root via Path Hijacking (privesc).
  • Vorfall Easy
    Broken Access Control, Path Traversal, Reverse Malware Engineering to get RCE and Sudo Exec Permission via smbclient (privesc)
  • UHC V20 Final Hard
    LFI via PHP, change user to UHC using Prototype Pollution and File with Sudo Exec Permission via Node (privesc).
  • Biscuit Medium
    Default Password, Type Juggling via Cookies, Insecure Desserialization in PHP with RFI and File with Sudo Exec Permission via Format String Python (privesc).
  • Maldev Easy
    Git Exposed, Type Juggling, LFI and Cron Binary run-parts (/usr/local/sbin).
  • KOF Easy
    SQL Injection, Hash Crack, Command Injection, Bash SUID and Docker Breakout/Escape.
  • Lion Easy
    Union-based SQL injection, PHP webshell upload via SQLi, and cron job misconfiguration for privesc.
  • Poisoning Easy
    LFI, log poisoning via User-Agent injection, and Linux capabilities exploitation.