HTB: Jarvis
Linux machine demonstrating manual union-based SQL injection, phpMyAdmin web-shell creation, Python command injection, and SUID systemctl abuse.
Linux machine demonstrating manual union-based SQL injection, phpMyAdmin web-shell creation, Python command injection, and SUID systemctl abuse.
Windows machine demonstrating hMailServer credential disclosure through path traversal, NTLM capture through a malicious email, and LibreOffice command execution.
Windows machine demonstrating Cisco password recovery, RID brute forcing, password spraying, and credential extraction from Firefox process memory.
Windows machine demonstrating MSSQL injection, forced NTLM authentication, WinRM access, and UniFi Video service abuse for SYSTEM privileges.
Linux machine demonstrating an unfinished LimeSurvey installation, malicious plugin upload, Docker credential exposure, and SUID abuse through a shared volume.
Linux machine demonstrating Joomla information disclosure, authenticated template modification, database credential extraction, and apport-cli privilege escalation.
Linux machine demonstrating Spring Boot Actuator session disclosure, cookie hijacking, command injection, JAR credential discovery, and sudo SSH abuse.
Linux machine demonstrating a vm2 sandbox escape, SQLite credential recovery, and Bash wildcard abuse leading to root.
Windows machine demonstrating AChat buffer overflow exploitation, custom shellcode generation, credential discovery, and password reuse for Administrator access.
Linux machine demonstrating exposed Git repository abuse, Backdrop CMS authenticated RCE, password reuse, and sudo abuse through the bee CLI utility.