Jack Writeup

Jack Writeup - Tryhackme https://tryhackme.com/room/jack Compromise a web  server running Wordpress, obtain a low privileged user and escalate your privileges to root using a Python module.How this helps your pentesting career:Web-application Pentesting, specifically WordPressPractice brute-forcing authenticationRemote-Code-Execution with WordPress malicious pluginPractice Linux Privilege Escalation to get…

Post-Exploitation Basics Writeup

Post-Exploitation Basics Writeup - Tryhackme https://tryhackme.com/room/postexploit Learn the basics of post-exploitation and maintaining access with mimikatz, bloodhound, powerview and msfvenomHow this helps your pentesting career:This room will be related to very real world applicationsEnumerating with Windows Server ManagerHow to approach a network after you have…

Steel Mountain Writeup

THM: Steel Mountain Walkthrough https://tryhackme.com/room/steelmountain How this helps your pentesting career:exploit Rejetto HFS 2.3 to get remote shell w/ both Metasploit and manual exploitationpractice Windows privilege escalation technique: Unquoted service paths Task 1 #1 Deploy the machine.Who is the employee of the month?The page source…

Vulnserver Buffer Overflow Walkthrough

Exploiting Vulnserver Buffer Overflow Walkthrough http://www.thegreycorner.com/p/vulnserver.html I just finished the buffer overflow section of studying for OSCP.  Let's apply the methodology and techniques in the textbook to vulnserver, a service that is purposefully vulnerable.  It is only available on Windows machines. What you will need…

Ignite Writeup

Ignite Writeup https://tryhackme.com/room/ignite Ignite is a room that has no instructions other than to get two flags: User.txt and Root.txt, essential a black-box.  No hand-holding or guiding of any sort.  Let's put everything we've learned up til this point and hack the box! Scan the…

Windows Virtual Lab Setup

Windows Virtual Lab Setup Guide If you are interesting in learning more about PowerShell or system administration you would likely benefit from having an isolated virtual Windows lab. A physical lab is great if you have the space and the money for it, but most…

Blue Primer: Volatility Writeup

Blue Primer: Volatility Writeup https://tryhackme.com/room/bpvolatility Welcome! This writeup goes over how to use volatility to perform file forensics on a memory capture file, and analyze the extracted files for malware.   "Volatility is a free memory forensics tool developed and maintained by Volatility labs. Regarded as…

Red Primer: Powershell Empire Writeup

Red Primer: PS Empire Writeup https://tryhackme.com/room/rppsempire Welcome!  This writeup goes over how to use PS Empire to set up a listener and get the stager for the listener onto the target Windows server. Empire is a pure PowerShell post-exploitation agent built on cryptologically-secure communications and…

Reverse Engineering for Beginners

Reverse Engineering for Beginners https://www.begin.re/ Welcome!  This page will serve as a writeup on the reverse engineering online workshop by Ophir Harpaz.  Background info on the workshop can be found on its about page.There is no official write-up yet as of me writing this, so…

Musical Stego Writeup

Musical Stego Writeup https://tryhackme.com/room/musicalstego This is a more open-ended steganography challenge compared to the previous room we did (https://hex-men.tech/cc-stego/). Everything we learned in the stego crash course is going to be very useful in finding the final flag. Find the Flag Let's start by listening…

