iconBjarne Verschorre

  1. Blog
  2. Write-ups
  3. Private
../easy/

#easy

🔒 Total withheld posts: 2


Usage

Webpage with SQLi and file upload vulnerability. Escalate to root by abusing a script that runs as sudo.


Perfection

A Ruby webserver with a template injection vulnerability, leading to a reverse shell and brute-forcing hashes for a privilege escalation to root.


Headless

Simple webserver with a contact form vulnerable to XSS. Escalate to root by abusing a script that runs as sudo.


Hacker vs Hacker

Someone has compromised this server already! Can you get in and evade their countermeasures?