HackTheBox: Sau Machine Walkthrough
Complete walkthrough of the Sau machine from HackTheBox, covering SSRF exploitation, request-baskets vulnerability (CVE-2023-27163), and privilege escalation via Maltrail.
Security research, CTF solutions, tool tutorials, and the latest in cybersecurity.
Complete walkthrough of the Sau machine from HackTheBox, covering SSRF exploitation, request-baskets vulnerability (CVE-2023-27163), and privilege escalation via Maltrail.
Exploiting a blind SQL injection to leak admin credentials and leveraging a custom management portal to gain shell access.
Manual exploit development for a custom vulnerable binary. Fuzzing, finding offset, and overwriting EIP for local privilege escalation.
Using double encoding, white-space manipulation, and unconventional protocol usage to slip payloads past modern firewalls.
Exploiting insecure SMB shares and using Impacket's secretsdump to harvest NTLM hashes for Active Directory takeover.
Developing YAML-based templates to automate the discovery of unique business logic vulnerabilities at scale.
How a simple stored XSS was combined with a broken session management vulnerability to compromise any user account.
How to write and chain custom Nuclei templates to discover unique vulnerabilities at scale across massive attack surfaces.
Breaking down the latest critical vulnerability affecting millions of servers worldwide.
Learn the fundamentals of attacking and defending Active Directory environments.
How I found an IDOR vulnerability in a major SaaS platform and earned a $5,000 bounty.