HTB: Jarvis
Linux machine demonstrating manual union-based SQL injection, phpMyAdmin web-shell creation, Python command injection, and SUID systemctl abuse.
Linux machine demonstrating manual union-based SQL injection, phpMyAdmin web-shell creation, Python command injection, and SUID systemctl abuse.
Windows machine demonstrating hMailServer credential disclosure through path traversal, NTLM capture through a malicious email, and LibreOffice command execution.
Linux machine demonstrating Spring Boot Actuator session disclosure, cookie hijacking, command injection, JAR credential discovery, and sudo SSH abuse.
Linux machine demonstrating a vm2 sandbox escape, SQLite credential recovery, and Bash wildcard abuse leading to root.
Windows machine demonstrating unauthenticated file upload leading to CloudMe buffer overflow exploitation and administrator access.
Linux machine demonstrating Metabase pre-auth RCE, Docker environment credential disclosure, and OverlayFS kernel exploitation.
Linux machine demonstrating Apache ActiveMQ CVE-2023-46604 exploitation and sudo nginx abuse for root access.
Windows machine demonstrating Gitea access token exposure, repository-backed web deployment, mRemoteNG credential recovery, and PDF24 local privilege escalation.