✍️
Imtodess
  • CTF writeups
  • Proving Grounds
    • Warmups
      • Linux
        • Pebbles
        • wombo
        • Bratarina
        • ClamAV
        • Exfiltrated
      • Windows
        • Internal
        • Metallus
        • Kevin
        • Algernon
    • Get to work
      • Linux
        • Payday
        • Hunit
        • Dibbles
        • Zino
        • Hetemit
        • Postfish
        • Sybaris
    • Try Harder
      • Peppo
  • Vulnhub
    • Linux
      • Devguru
      • DC~9
Powered by GitBook
On this page
  • Tj_null's List :
  • PG walkthroughs:
  • Vulnhub Walkthroughs:
  • Hackthebox:

Was this helpful?

CTF writeups

Walkthrough for some of the boxes I am doing while preparing for OSCP.

NextWarmups

Last updated 3 years ago

Was this helpful?

Tj_null's List :

I will be doing boxes mostly from this list as well as some extras.

PG walkthroughs:

Machine

OS

Rating

Remarks

Windows

Warmup(10)

CVE, Easy exploitation, No Privilege escalation

Linux

Warmup(10)

CVE, SQLmap, No Privilege Escalation

Linux

Warmup(10)

CVE, Easy, No privilege escalation

Linux

Warmup(10)

CVE, metasploit, No P.E

Linux

Warmup(10)

CVE, No P.E

Linux

Warmup(10)

CVE, Vulnerable CMS, weak credential, cronjob, Vulnerable application (exiftool)

Windows

Warmup(10)

CVE, Authenticated RCE, No P.E

Windows

Warmup(10)

walkthrough in progress

Windows

Warmup(10)

walkthrough in progress

Linux

Get2Work(20)

Sensitive information disclosure through api , Weak permission which leads to exploiting cronjob for P.E

Linux

Get2Work(20)

Cookie manipulation, command injection to RCE. Exploiting SUID for P.E

Linux

Get2Work(20)

Enumeration, CVE, Exploit cronjob for P.E

Linux

Get2Work(20)

Command Injection, Insecure permission, Exploit service file to get P.E

Linux

Get2Work(20)

SMTP, Phising, Insecure file permission and sudo misconfiguration.

Linux

Get2Work(20)

Weak Credential, CVE, File upload, Sudo misconfiguration

Linux

Get2Work(20)

Anonymous login, Redis load module, Cronjob, ld_library_path

Linux

TryHarder(25)

Weak Credential, Docker Escape for P.E

Vulnhub Walkthroughs:

Machine name

os

Remarks

Linux

Like OSCP, web, exposed git, CVE, command injection, sudo misconfiguration,

Linux

Like OSCP, SQLi, LFI, Bruteforcing SSH, Sensitive information disclosure, Vulnerable script with sudo privilege.

Hackthebox:

Coming soon

Internal
Pebbles
Bratarina
Wombo
Clamav
Exfiltrated
Metallus
KEVIN
Algernon
Hunit
Dibbles
Zino
Hetemit
Postfish
Payday
Sybaris
Peppo
Devguru
DC: 9