Entradas recientes

Bankrobber - Hack The Box

8 minuto(s) de lectura

Bankrobber is a web app box with a simple XSS and SQL injection that we have to exploit in order to get the source code of the application and discover a com...

Zetta - Hack The Box

6 minuto(s) de lectura

Zetta is another amazing box by jkr. The first part was kinda tricky because you had to pay attention to the details on the webpage and spot the references t...

JSON - Hack The Box

8 minuto(s) de lectura

To get remote code execution on JSON, I exploited a deserialization vulnerability in the web application using the Json.net formatter. After getting a shell ...

RE - Hack The Box

10 minuto(s) de lectura

I had fun solving RE but I did it using an unintended path. After getting a shell with a macroed .ods file, I saw that the Winrar version had a CVE which all...

Mini WebSocket CTF

3 minuto(s) de lectura

During the holidays, @stackfault (sysop from the BottomlessAbyss BBS) ran a month long CTF with challenges being released every couple of days. Some of chall...