Jund Creativity Primer

Jund Creativity Primer by alemilan19

August 9, 2024 · 8 min

Magic drafts - Tips and Tricks

Magic drafts - Tips and Tricks

August 9, 2024 · 2 min

Headless - HackTheBox

Headless its a easy hackthebox machine that is vulnerable to xss in a contact form. Using that vulnerability we can grab a cookie and gain admin access to the web app. Following that we detect a command injection which allows the foothold into the machine. Inside the machine we gain root by exploiting a script containing a path hijack vulnerability.

April 1, 2024 · 4 min

Analytics - HackTheBox

Analytics is a easy hackthebox machine that explores a vulnerability in a service called metabase. After gaining foothold into a docker continer we get credentials used in both the database and the ssh. Inside the machine we use a vulnerability in a service called overlayfs to get root.

March 29, 2024 · 3 min

Umbrella - TryHackMe

Breach Umbrella Corp’s time-tracking server by exploiting misconfigurations around containerization. Link - https://tryhackme.com/room/umbrella

January 22, 2024 · 5 min