/ tags
#privesc
7 writeups tagged privesc.
Shocker easy featured
A CGI shell script backed by a vulnerable Bash lets a crafted HTTP header trigger Shellshock (CVE-2014-6271) for RCE. Privesc via a passwordless sudo rule on perl, one GTFOBins command to root.
linuxwebcgishellshockcve-2014-6271sudogtfobinsprivesc
01 Jul 2026
HTB
Kobold easy featured
A wildcard TLS certificate leaks a subdomain running MCPJam Inspector v1.4.2, whose /api/mcp/connect endpoint executes attacker-supplied commands with no authentication. Privesc via docker group membership: reactivated with newgrp, then a container mount of the host filesystem to root.
linuxwebsubdomain-enumerationMCPCVE-2026-23744dockerprivesc
15 Mar 2026
HTB
Pirate hard featured
Active HackTheBox machine. Full writeup published after retirement.
windowsactive-directorypre2kgmsakerberosntlm-relayrbcdconstrained-delegationspn-jackingligolo-ngprivesc
01 Mar 2026
HTB
Gavel medium
Linux web box: exposed .git repo leaks PHP source revealing a SQLi, admin panel RCE via PHP rule engine, then privesc by abusing a root-run auction daemon that executes YAML-defined PHP rules.
linuxwebsqligit-dumperphprceyamlsuidprivesc
12 Oct 2025
HTB
DarkZero hard featured
Active Directory box featuring MSSQL lateral movement across two domains, kernel exploitation (CVE-2024-30088) via Metasploit, and Golden Ticket via Rubeus + PetitPotam to compromise the forest.
windowsactive-directorymssqlkerberosCVE-2024-30088golden-ticketrubeusprivesc
05 Oct 2025
HTB
Return easy featured
LDAP credential capture from a printer web panel, followed by Server Operators privilege escalation via service binary path modification.
windowsactive-directoryldapprivescserver-operators
04 Oct 2025
HTB
Expressway easy
Linux box with IKE/ISAKMP on UDP/500: crack the PSK with psk-crack, SSH in, then exploit a vulnerable sudo version (CVE-2025-32463) to root.
linuxikevpnpsk-cracksshCVE-2025-32463sudoprivesc
22 Sept 2025
HTB