/explore

Click through on any links that interest you or select the planets on the right to continue exploring the Outer Web.
You are here

shellsharks.com
| | securitypimp.net
2.0 parsecs away

Travel
| | The challenge given by Remote will have you breaking into the Umbraco CMS system on multiple levels.
| | blog.ikuamike.io
1.7 parsecs away

Travel
| | Summary As the name suggests this box had a instance of gitlab where the initial foothold involves getting credentials from obfuscated javascript and once logged into the gitlab instance we abuse webhooks to add our own code and execute it to get a reverse shell. Read on to see how I able to root the box. Enumeration As usual I start with a quick nmap scan to find open ports and then run a second scan for service and version detection.
| | www.justus.pw
2.0 parsecs away

Travel
| | [AI summary] The user successfully gained access to a system by exploiting a Heartbleed vulnerability, decrypted an RSA key using a password obtained from memory, and then used that key to log in as the 'hype' user. After enumerating the system, they accessed a Tmux session to gain root access and retrieved the root flag.
| | blog.adolus.com
15.8 parsecs away

Travel
| A summary of aDolus' response to the vulnerability in the #XZ Utils library and how we reassured our customers that they were at no risk from this threat.