HTB: Jarvis
Linux machine demonstrating manual union-based SQL injection, phpMyAdmin web-shell creation, Python command injection, and SUID systemctl abuse.
Linux machine demonstrating manual union-based SQL injection, phpMyAdmin web-shell creation, Python command injection, and SUID systemctl abuse.
Linux machine demonstrating SSRF-based internal API access, credential disclosure through Git history, and GitPython command injection for root access.
Windows machine demonstrating unauthenticated file upload leading to CloudMe buffer overflow exploitation and administrator access.