/ Writeups

Break systems. Document truth.

Every machine written up after it retires, from first port to domain admin. Active Directory, web, and the unglamorous middle where most of the work actually happens.

9

Machines

49

Techniques

6

Named CVEs

4

Active Directory

4

Web

Filtering by

hard windows · retired

DarkZero

Active Directory box featuring MSSQL lateral movement across two domains, kernel exploitation (CVE-2024-30088) via Metasploit, and Golden Ticket via Rubeus + PetitPotam to compromise the forest.

+3

Read the walkthrough →

hard windows · retired

Pirate

Pre-Windows 2000 computer accounts leak a gMSA hash over Kerberos, landing WinRM on the DC. NTLM coercion relayed to unsigned LDAP configures RBCD for Administrator on WEB01, then an SPN moved onto the DC turns constrained delegation into Domain Admin.

+6

Read the walkthrough →

easy linux · retired

Shocker

A CGI shell script backed by a vulnerable Bash lets a crafted HTTP header trigger Shellshock (CVE-2014-6271) for RCE. Privesc via a passwordless sudo rule on perl, one GTFOBins command to root.

+3

Read the walkthrough →

easy linux · retired

Kobold

A wildcard TLS certificate leaks a subdomain running MCPJam Inspector v1.4.2, whose /api/mcp/connect endpoint executes attacker-supplied commands with no authentication. Privesc via docker group membership: reactivated with newgrp, then a container mount of the host filesystem to root.

+2

Read the walkthrough →

easy linux · retired

CCTV

Default credentials on an exposed ZoneMinder console lead to a blind SQL injection (CVE-2024-51482) that dumps a crackable hash for SSH. Root comes from a loopback-bound motionEye reached over an SSH tunnel, where a filename field is passed unsanitised to a Motion daemon running as root (CVE-2025-60787).

+4

Read the walkthrough →

medium linux · retired

Gavel

Linux web box: exposed .git repo leaks PHP source revealing a SQLi, admin panel RCE via PHP rule engine, then privesc by abusing a root-run auction daemon that executes YAML-defined PHP rules.

+4

Read the walkthrough →

easy windows · retired

Return

LDAP credential capture from a printer web panel, followed by Server Operators privilege escalation via service binary path modification.

Read the walkthrough →

easy windows · retired

Cicada

Beginner-friendly Windows AD box: anonymous SMB enumeration leads to default credentials, password spraying finds a foothold, and SeBackupPrivilege escalates to Administrator via SAM dump.

+1

Read the walkthrough →

easy linux · retired

Expressway

Linux box with IKE/ISAKMP on UDP/500: crack the PSK with psk-crack, SSH in, then exploit a vulnerable sudo version (CVE-2025-32463) to root.

+3

Read the walkthrough →

Nothing matches that. Try a technique, an OS, or a machine name.

9 of 9 writeups

Copied