tag

Linux

134 posts
machinemachine

BoardLight

BoardLight: use CVE-2022-37706 and CVE-2023-30253 where it fits the service, gain a shell, and escalate to root.

machinemachine

Editorial

Editorial: enumerate the services, turn the exposed weakness into a shell, and escalate to root.

machinemachine

PermX

PermX: use CVE-2023-4220 where it fits the service, gain a shell, and escalate to root.

machinemachine

Headless

Headless: enumerate the services, turn the exposed weakness into a shell, and escalate to root.

machinemachine

Trickster

Trickster: use CVE-2023-47268 and CVE-2024-32651 where it fits the service, gain a shell, and escalate to root.

machinemachine

Sea

Sea: use CVE-2023-41425 where it fits the service, gain a shell, and escalate to root.

machinemachine

Caption

Caption: enumerate the services, turn the exposed weakness into a shell, and escalate to root.

machinemachine

Bastion

Bastion: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.

machinemachine

Curling

Curling: abuse the Joomla exposure for a shell, then use local enumeration to reach root.

machinemachine

Sightless

Sightless: use CVE-2022-0944 and CVE-2024-34070 where it fits the service, gain a shell, and escalate to root.

machinemachine

Spooktrol

Spooktrol: turn the exposed service into a shell, pivot through the container boundary, and escalate to root.

machinemachine

Writeup

Writeup: use CVE-2022-41544 where it fits the service, gain a shell, and escalate to root.

notesnotes

Nmap

Nmap Scanning: run focused Nmap scans, capture service evidence, and keep enumeration reproducible.

machinemachine

Active

Active: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.

machinemachine

Codify

Codify: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.

machinemachine

Paper

Paper: use CVE-2019-17671 and CVE-2021-3560 where it fits the service, gain a shell, and escalate to root.

machinemachine

Perfection

Perfection: enumerate the services, turn the exposed weakness into a shell, and escalate to root.

notesnotes

Bluetooth Linux Fix

Bluetooth Linux Fix: reset the Linux Bluetooth stack, verify adapter state, and pair from a clean baseline.

pwn

DearQA

DearQA: shape the heap state, gain the needed write or leak, and pivot to flag access.

machinemachine

Blog

Blog: abuse the WordPress foothold, stabilize the shell, and escalate through the local weakness.

machinemachine

DevVortex

DevVortex: use CVE-2023-23752 where it fits the service, gain a shell, and escalate to root.

notesnotes

SSH

Compact OpenSSH reference for key authentication, client and server config, tunneling, X11 forwarding, and public-key troubleshooting.