Open in app

Sign in

Write

Sign in

HotPlugin
HotPlugin

77 Followers

Home

About

Nov 3

Topology — HackTheBox

Topology is a Linux machine hosting a website with a PNG image generator based on LaTeX inline math mode commands. This feature can be exploited to read arbitrary files on the server, resulting in the exposure of a password hash for a user that can then be cracked and used…

Hackthebox

5 min read

Topology — HackTheBox
Topology — HackTheBox
Hackthebox

5 min read


Oct 28

NoSQL Injection — Portswigger

NoSQL injection is a security vulnerability that arises in non-relational databases, allowing attackers to manipulate or exploit the system. Unlike traditional SQL injection, NoSQL injection occurs when unsanitized or malicious input is used to query NoSQL databases, potentially leading to unauthorized access, data leakage, or data corruption.

Web Security

10 min read

NoSQL Injection — Portswigger
NoSQL Injection — Portswigger
Web Security

10 min read


Oct 6

PC — HackTheBox

PC is an easy machine from HackTheBox. It involves identifying and exploiting SQL injection in gRPC service to dump database for foothold, and exploiting CVE-2023–0297 (RCE in pyLoad) for escalating privileges to root. NMAP PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.7 (Ubuntu Linux; protocol 2.0) …

Hackthebox

5 min read

PC — HackTheBox
PC — HackTheBox
Hackthebox

5 min read


Aug 12

Busqueda — HackTheBox

Busqueda is an easy machine from HackTheBox. It involves exploiting Arbitrary Code Injection in website using vulnerable searcher library to gain initial access, taking advantage of password reuse and abusing custom python script for privilege escalation. NMAP PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH…

Hackthebox

4 min read

Busqueda — HackTheBox
Busqueda — HackTheBox
Hackthebox

4 min read


Aug 5

Agile — HackTheBox

Agile is a medium machine from HackTheBox. It involves extracting Werkzeug debug console pin with the help of Directory traversal vulnerability, getting credentials from chrome remote debugging window, and exploiting CVE in sudoedit to modify the file used in a cron running as root. NMAP PORT STATE SERVICE REASON…

Hackthebox

7 min read

Agile — HackTheBox
Agile — HackTheBox
Hackthebox

7 min read


Jul 30

Cerberus — HackTheBox

Introduction Cerberus is a hard machine from HackTheBox. It involves exploiting File Read and RCE CVEs in icinga to get foothold, escalating privileges by LPE CVE in firejail, pivoting to DC and finally getting SYSTEM by exploiting RCE in ADSelfService Plus. NMAP PORT STATE SERVICE VERSION 8080/tcp open…

Hackthebox

7 min read

Cerberus — HackTheBox
Cerberus — HackTheBox
Hackthebox

7 min read


Jun 24

Stocker — HackTheBox

Stocker is an easy machine from HackTheBox. It involves bypassing authentication via NoSQL injection, exploiting HTML injection in PDF generation to read source code from the host containing credentials that leads to foothold. Finally, misconfigured sudo privilege allowing execution of NodeJS scripts leads to shell as root. NMAP PORT…

Hackthebox

4 min read

Stocker — HackTheBox
Stocker — HackTheBox
Hackthebox

4 min read


Jun 17

Escape — HackTheBox

Escape is a medium machine from HackTheBox. It involves enumerating smb shares and finding PDF containing SQL Server credentials, stealing NTLMv2 hash of SQL service, reading log files for credentials and finally abusing the AD CS template for getting shell as administrator. NMAP PORT STATE SERVICE…

Hackthebox

6 min read

Escape — HackTheBox
Escape — HackTheBox
Hackthebox

6 min read


Jun 11

Soccer — HackTheBox

Soccer is an easy machine from HackTheBox. It involves exploiting file upload CVE in an old version of tiny file manager, finding another running application and exploiting sqli in the vulnerable websocket leading to foothold. …

Hackthebox

6 min read

Soccer — HackTheBox
Soccer — HackTheBox
Hackthebox

6 min read


Jun 9

Metapwned — Cloud Security Challenges

These fun challenges are created and hosted by Ian Austin. You can provide your feedback on their Linkedin. Challenge 1

Ctf

3 min read

Metapwned — Cloud Security Challenges
Metapwned — Cloud Security Challenges
Ctf

3 min read

HotPlugin

HotPlugin

77 Followers

Learning for Fun! UwU

Following
  • Prof Bill Buchanan OBE

    Prof Bill Buchanan OBE

  • ARZ101

    ARZ101

  • Root ♊

    Root ♊

  • Kevin Beaumont

    Kevin Beaumont

  • Fahad Hasan

    Fahad Hasan

See all (29)

Help

Status

About

Careers

Blog

Privacy

Terms

Text to speech

Teams