YPuffy: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.
Machine
62 postsBrains
Brains: use CVE-2024-27198 where it fits the service, gain a shell, and escalate to root.
Help
Help: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.
GoodGames
GoodGames: turn the exposed service into a shell, pivot through the container boundary, and escalate to root.
Valentine
Valentine: use CVE-2014-0160 and CVE-2016-5195 where it fits the service, gain a shell, and escalate to root.
Yummy
Yummy: enumerate the services, turn the exposed weakness into a shell, and escalate to root.
EvilCUPS
EvilCUPS: use CVE-2024-47076 and CVE-2024-47175 where it fits the service, gain a shell, and escalate to root.
Prioritise
Prioritise: enumerate the services, turn the exposed weakness into a shell, and escalate to root.
Pyrat
Pyrat: enumerate the services, turn the exposed weakness into a shell, and escalate to root.
Cicada
Cicada: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.
Gobox
Gobox: enumerate the services, turn the exposed weakness into a shell, and escalate to root.
Bashed
Bashed: enumerate the services, turn the exposed weakness into a shell, and escalate to root.
Shocker
Shocker: use CVE-2014-6271 where it fits the service, gain a shell, and escalate to root.
TwoMillion
TwoMillion: use CVE-2023-0386 where it fits the service, gain a shell, and escalate to root.
Soccer
Soccer: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.
GreenHorn
GreenHorn: use CVE-2023-50564 where it fits the service, gain a shell, and escalate to root.
BoardLight
BoardLight: use CVE-2022-37706 and CVE-2023-30253 where it fits the service, gain a shell, and escalate to root.
Editorial
Editorial: enumerate the services, turn the exposed weakness into a shell, and escalate to root.
PermX
PermX: use CVE-2023-4220 where it fits the service, gain a shell, and escalate to root.
Headless
Headless: enumerate the services, turn the exposed weakness into a shell, and escalate to root.
Trickster
Trickster: use CVE-2023-47268 and CVE-2024-32651 where it fits the service, gain a shell, and escalate to root.
Sea
Sea: use CVE-2023-41425 where it fits the service, gain a shell, and escalate to root.
Caption
Caption: enumerate the services, turn the exposed weakness into a shell, and escalate to root.
Bastion
Bastion: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.
Curling
Curling: abuse the Joomla exposure for a shell, then use local enumeration to reach root.
Sightless
Sightless: use CVE-2022-0944 and CVE-2024-34070 where it fits the service, gain a shell, and escalate to root.
Spooktrol
Spooktrol: turn the exposed service into a shell, pivot through the container boundary, and escalate to root.
Writeup
Writeup: use CVE-2022-41544 where it fits the service, gain a shell, and escalate to root.