HTB: Jarvis
Linux machine demonstrating manual union-based SQL injection, phpMyAdmin web-shell creation, Python command injection, and SUID systemctl abuse.
Linux machine demonstrating manual union-based SQL injection, phpMyAdmin web-shell creation, Python command injection, and SUID systemctl abuse.
Linux machine demonstrating an unfinished LimeSurvey installation, malicious plugin upload, Docker credential exposure, and SUID abuse through a shared volume.
Linux machine demonstrating Joomla information disclosure, authenticated template modification, database credential extraction, and apport-cli privilege escalation.
Linux machine demonstrating Spring Boot Actuator session disclosure, cookie hijacking, command injection, JAR credential discovery, and sudo SSH abuse.
Linux machine demonstrating a vm2 sandbox escape, SQLite credential recovery, and Bash wildcard abuse leading to root.
Linux machine demonstrating exposed Git repository abuse, Backdrop CMS authenticated RCE, password reuse, and sudo abuse through the bee CLI utility.
A practical guide for compiling older C exploits with matching GCC and GLIBC versions using Docker.
Linux machine demonstrating SSRF-based internal API access, credential disclosure through Git history, and GitPython command injection for root access.
A practical Linux privilege escalation reference covering high-impact enumeration checks, common misconfigurations, credential hunting, container escapes, and last-resort kernel exploits.
Linux machine demonstrating exposed PHP web shell access, sudo-based lateral movement, and cron-driven privilege escalation.