Skip to content

shashihacks/OSWE

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

10 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

HackTheBox

Linux

  1. Bashed [ PHP Bash, Scheduled task ]

  2. Popcorn [ Image upload vulnerability, MOTD File Tampering ]

  3. Celestial [ Node deserialization attack, Scheduled task, syslogs ]

  4. Nibbles [ Image upload,Default creds opensource/git sudoer sudoer file ]

  5. Cronos [ dig DNS,command injection Scheduled task laravel PHP ]

  6. Lame [ smb 3.0.2 usermapscript command execution ]

  7. Mirai [ default pi credentails grep ]

  8. Beep [ LFI SMTP SMTP to RFI ]

  9. Traverxec [ nostromo 1.9.6 RCE ssh2john.py journalctl gtfo binary ]

  10. Academy [ parameter tampering laravel RCE adm group user aureport log analysis composer ]

  11. Time [CVE-2019-12384 Jackson RCE And SSRF, scheduled task]

  12. Blunder [login brute force CSRF Bypass IP blacklist metasploit image upload authenticated sudoer CVE-2019-14287]

  13. Magic [Magic bytes image upload sql injection SUID binary ltrace]

  14. Waldo [directory and file traversal bypassing filters escaping rbash linux capabilities tac cap_dac read_search+ei]

  15. Solidstate [POP3 SIP rbash schedules task ]

  16. Irked [UnrealIRCd backdoor command injection steghide SUID binary ]

  17. Valentine [Heartbleed TMUX socket session ]

  18. Writeup [cms made simple sql injection staff group pspy ]

  19. Mango [nosql injection jjs suid binary ]

Windows

  1. Granny [ HTTP verb tampering, PUT, MOVE, ms15_051_client_copy_image, IIS 6.0 ]
  2. Grandpa [ HTTP verb tampering, PUT, MOVE, ms14_070_tcpip_ioctl, IIS 6.0 ]
  3. Optimum [ rejetto HTTPFileServer command execuation manual + metasploit Exploit suggestor ]
  4. Devel [ anonymous ftp msfvenom shell upload metasploit Exploit suggestor ]
  5. Legacy [ MS08-067 windows XP metasploit CVE-2008-4250 ]
  6. Remote [ nfs mount sdf file/binary umbraco authenticated RCE service misconfiguration ]
  7. Chisel [ Gym management system RCE chisel cloudme.exe]

Proving Grounds

  1. Potato [ PHP type Juggling, Nice Binary ]

  2. Sars

  3. Inclusiveness[LFI, Binary impersonation, Path hijacking]

  4. Solstice [ LFI ]

  5. FunBoxEasy [SQL Injection, GTFO Binaries, Time, pkexec, mtr]

Windows Privilege Escalation

Windows Privilege Escalation for OSCP & Beyond!

Linux Privilege Escalation

Linux Privilege Escalation for OSCP & Beyond!

Wargames

Overthewire - Wargames

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published