HTB: Jarvis
Linux machine demonstrating manual union-based SQL injection, phpMyAdmin web-shell creation, Python command injection, and SUID systemctl abuse.
Linux machine demonstrating manual union-based SQL injection, phpMyAdmin web-shell creation, Python command injection, and SUID systemctl abuse.
Windows machine demonstrating MSSQL injection, forced NTLM authentication, WinRM access, and UniFi Video service abuse for SYSTEM privileges.
Windows machine demonstrating AChat buffer overflow exploitation, custom shellcode generation, credential discovery, and password reuse for Administrator access.
Windows machine demonstrating unauthenticated file upload leading to CloudMe buffer overflow exploitation and administrator access.
Linux machine demonstrating exposed PHP web shell access, sudo-based lateral movement, and cron-driven privilege escalation.
Windows machine demonstrating Adobe ColdFusion remote code execution and kernel-based privilege escalation to SYSTEM.
Windows machine demonstrating IIS upload bypass with web.config abuse and kernel exploit privilege escalation.
Linux machine demonstrating Apache ActiveMQ CVE-2023-46604 exploitation and sudo nginx abuse for root access.
Active Directory machine demonstrating NTLM hash capture, SMB abuse, password reuse, IIS pivoting, and SeImpersonatePrivilege escalation.
Windows machine demonstrating phishing through a malicious LibreOffice document, IIS web root abuse, SeImpersonatePrivilege, and local administrator access through GodPotato and RunasCs.