Kobold - HTB
An easy-difficulty Linux machine featuring multiple web vulnerabilities.
VariaType - HTB
A medium-difficulty Linux machine centered around a custom font-generation web application. The challenge involves exploring file handling behavior, analyzing backend processing logic, and chaining multiple issues in the font processing pipeline to move from initial access to full system compromise.
CCTV - HTB
Easy Linux CCTV machine abusing ZoneMinder and MotionEye flaws through SQL injection and escalation. [Unintended]
Pirate - HTB
Windows Active Directory challenge centered on delegation, Kerberos, and privilege escalation workflows.
Linux Privilege Escalation via Sudo Misconfiguration
Sudo misconfigurations on Linux systems provide a common vector for privilege escalation. Attackers exploit overly permissive sudo rules to gain root-level access.
Guardian - HTB
Guardian is a Linux box combining IDOR in a student portal, XSS via PhpSpreadsheet, CSRF admin creation, PHP filter chain RCE, and sudo misconfigurations to read root files.
Hercules - HTB
Insane Windows AD chain featuring LDAP injection, forged ASP.NET auth cookies, file-based hash capture, ADCS abuse, and RBCD to full domain compromise.
Admin Access
Admin Access techniques and commands for Active Directory security assessment.