<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cyberchef" on zer0arc4</title><link>https://zer0arc4.github.io/tags/cyberchef/</link><description>Recent content in Cyberchef" on zer0arc4</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 06 Sep 2026 01:17:37 +0530</lastBuildDate><atom:link href="https://zer0arc4.github.io/tags/cyberchef/index.xml" rel="self" type="application/rss+xml"/><item><title>Vvveb | VulNyx Writeup</title><link>https://zer0arc4.github.io/writeups/vulnyx/vvveb-vulnyx-writeup/</link><pubDate>Sun, 06 Sep 2026 01:00:41 +0530</pubDate><guid>https://zer0arc4.github.io/writeups/vulnyx/vvveb-vulnyx-writeup/</guid><description>Compromised the Vvveb machine by identifying Vvveb CMS 1.0.5, discovering the exposed /system/secret endpoint and recovering administrator credentials, abusing the authenticated Code Editor for arbitrary PHP code execution and a www-data shell, pivoting to bunny through exposed database credentials, recovering a world-readable SSH private key for zer0arc4, cracking its passphrase, and achieving root through a malicious Debian package executed via sudo-enabled dpkg.</description></item></channel></rss>