|
You are here |
www.thexero.co.uk | ||
| | | | |
srcincite.io
|
|
| | | | | Recently a past student came to me with a very interesting unauthenticated vulnerability in a Spring application that they were having a hard time exploiting... | |
| | | | |
blog.ikuamike.io
|
|
| | | | | Difficulty Release Date Author Beginner 15 Feb 2020 Love Summary In this box there's only one port open that is running a vulnerable version of sar2html that we take advantage of to get a low priv shell. For privilege escalation there was a cron job running as root that was running a script we could write in. Reconnaissance Nmap Nmap scan report for 192.168.56.107 Host is up (0.000040s latency). Not shown: 65534 closed ports PORT STATE SERVICE VERSION 80/tcp open http Apache httpd 2. | |
| | | | |
taeluralexis.com
|
|
| | | | | In this writeup, we'll exploit a Linux machine on Hack The Box with CVE-2023-46604, leveraging Java deserialization for remote code execution. | |
| | | | |
thehackernews.com
|
|
| | | State-backed hackers breached Southeast Asia telecoms using advanced tools-no data stolen, but stealth access achieved. | ||