tag

Thm

7 posts
machinemachine

Brains

Brains: use CVE-2024-27198 where it fits the service, gain a shell, and escalate to root.

crypto

Flip

Flip: abuse the AES misuse, derive the missing key material, and decrypt the flag.

machinemachine

Prioritise

Prioritise: enumerate the services, turn the exposed weakness into a shell, and escalate to root.

machinemachine

Pyrat

Pyrat: enumerate the services, turn the exposed weakness into a shell, and escalate to root.

web

SQHell

SQHell: exploit the SQL injection, extract the needed data, and reach the flag.

pwn

DearQA

DearQA: shape the heap state, gain the needed write or leak, and pivot to flag access.

machinemachine

Blog

Blog: abuse the WordPress foothold, stabilize the shell, and escalate through the local weakness.