Lakera: Gandalf Password Reveal
Lakera Gandalf walkthrough demonstrating prompt injection, output transformation, incremental disclosure, and semantic side-channel techniques across all eight Password Reveal levels.
HTB: Jarvis
Linux machine demonstrating manual union-based SQL injection, phpMyAdmin web-shell creation, Python command injection, and SUID systemctl abuse.
HTB: Mailing
Windows machine demonstrating hMailServer credential disclosure through path traversal, NTLM capture through a malicious email, and LibreOffice command execution.
HTB: Heist
Windows machine demonstrating Cisco password recovery, RID brute forcing, password spraying, and credential extraction from Firefox process memory.
HTB: Giddy
Windows machine demonstrating MSSQL injection, forced NTLM authentication, WinRM access, and UniFi Video service abuse for SYSTEM privileges.
HTB: Forgotten
Linux machine demonstrating an unfinished LimeSurvey installation, malicious plugin upload, Docker credential exposure, and SUID abuse through a shared volume.
HTB: Devvortex
Linux machine demonstrating Joomla information disclosure, authenticated template modification, database credential extraction, and apport-cli privilege escalation.
HTB: CozyHosting
Linux machine demonstrating Spring Boot Actuator session disclosure, cookie hijacking, command injection, JAR credential discovery, and sudo SSH abuse.
HTB: Codify
Linux machine demonstrating a vm2 sandbox escape, SQLite credential recovery, and Bash wildcard abuse leading to root.
HTB: Chatterbox
Windows machine demonstrating AChat buffer overflow exploitation, custom shellcode generation, credential discovery, and password reuse for Administrator access.