Vvveb | VulNyx Writeup
Compromised the Vvveb machine by identifying Vvveb CMS 1.0.5, discovering the exposed /system/secret endpoint and …
Compromised the Vvveb machine by identifying Vvveb CMS 1.0.5, discovering the exposed /system/secret endpoint and …
Compromised the ZeroTrace machine by discovering a hidden .admin directory and exploiting LFI to enumerate /proc …
Compromised the Trace machine by enumerating an exposed NFS share, discovering internal domains, bypassing a PHP …
Compromised the NorthWing machine by exploiting Local File Inclusion with a PHP filter wrapper, recovering and cracking …
Compromised the Blind machine by exploiting command injection in the DNSRecon GUI, obtaining a reverse shell as …
Compromised the WellPlayed machine through unauthenticated WordPress WP2Shell RCE, obtained credentials from a sensitive …
Compromised the VisionLab machine by abusing an insecure PyTorch model upload, executing a malicious serialized payload …
Compromised the University machine by abusing password reset information disclosure, obtaining default Moodle …
Compromised the Explorer machine by discovering eXtplorer through robots.txt, authenticating with default credentials, …
A Volt walkthrough demonstrating access-control bypass, admin credential brute-forcing, command injection, credential …
Compromised the Open machine by abusing default OpenPLC credentials, recovering a valid ttyd username, brute-forcing the …
Compromised the Care machine by exploiting a Local File Inclusion vulnerability to poison Squid proxy logs and achieve …
Compromised the Lookup machine by abusing an unrestricted DNS Zone Transfer to enumerate employee accounts, reused the …
Compromised the Startup machine by abusing an anonymous writable FTP share to upload a PHP web shell, recovered SSH …
Exploited the Ghostcat vulnerability to read Tomcat configuration files, recovered SSH credentials, cracked a GPG …
Exploited a vulnerable WebDAV configuration to upload a PHP web shell, gained remote code execution, and escalated …
Enumerated web directories, extracted Borg archives, recovered credentials, and exploited sudo permissions for root …
Discovered hidden web directories, recovered FTP credentials, extracted SSH credentials from steganographic content, and …
Exploited anonymous SMB access, leaked JWT credentials, bypassed file upload restrictions for RCE, recovered KeePass …
Exploited LFI to retrieve an encrypted SSH key, cracked its passphrase, gained SSH access, and escalated privileges via …
Enumerated users through the Finger service, obtained SSH access with weak credentials, and escalated privileges via a …
Recovered FTP credentials from a leaked username, uploaded a Node.js reverse shell, obtained access as a low-privileged …
Enumerated a Redis instance, recovered stored credentials, gained SSH access, and abused a misconfigured gdb capability …
Exploited an LFI vulnerability to poison Apache logs, gained a reverse shell, abused sudo permissions, cracked a GPG …
Mounted an exposed NFS share, uploaded a PHP reverse shell, gained initial access, and escalated privileges through a …
Enumerated a valid user using the Ident protocol, brute-forced SSH credentials, and abused sudo access to multitail to …
Enumerated services, identified a username from an SSH banner, brute-forced Telnet credentials, and gained root by …
Discovered a hidden virtual host, generated custom passwords using CeWL, obtained SSH access through weak credentials, …
chmod, chown, SUID, SGID, sticky bit reference guide.