cube[ Hackache ]

Mis [notas] de hacking, [writeups] & [dolores de cabeza]


Cover

BreakMySSH

Muy Fácil Linux

  • SSH

Cover

Fruits

Principiante Linux

  • Enumeration

  • Local File Inclusion

  • Brute force SSH

  • Sudoers

Cover

Mirage

Hard Windows

  • Unauthenticated NFS share

  • Insecure Dynamic DNS Updates

  • Rogue NATS Server / Traffic Capture

  • Credential Leak via NATS Streams

  • Kerberoasting

  • Cross-Session NET-NTLMv2 Capture

  • gMSA Password Disclosure

  • Public-Information Attribute Write

  • ESC10 (UPN Mapping / Weak CA Binding)

  • DCSync

Cover

Trust

Muy Fácil Linux

  • Fuzzing

  • Brute force

  • Sudoers

Cover

Lower7

Low Linux

  • ftp

  • Shadow group

Cover

RustyKey

Hard Windows

  • Timeroasting Attack

  • Active Directory ACL abuse

  • Windows Group Policy Enumeration to abuse the 7-Zip Shell Extension

  • Active Directory Delegations

  • SPN-less Resource-Based Constrained Delegation attack

Cover

Horizontall

Easy Linux

  • Subdomain

  • Strapi RCE

  • Port forwarding

  • Laravel debug mode

Cover

Previse

Easy Linux

  • EAR (Execution After Redirect)

  • Abusing PHP exec()

  • Hash cracking

  • PATH hijacking

Cover

Brainfuck

Insane Linux

  • Wordpress

  • telnet

  • Vigenere cipher

  • RSA Decryption

Cover

Joker

Hard Linux

  • tftp

  • squid proxy

  • sudoedit

  • tar

Cover

Crafty

Easy Windows

  • Log4j

  • Plugins

  • Credenciales hardcodeadas

Cover

Perfection

Easy Linux

  • SSTI

  • Remote Code Execution

  • Privilegios sudo

Cover

RedPanda

Easy Linux

  • Spring Boot Framework

  • SSTI

  • cron job

  • XXE

  • Private key

Cover

Ghost

Insane Windows

  • LDAP injection

  • Gitea

  • Arbitrary file read

  • RCE

  • Kerberos ticket

  • DNS entry

  • GMSA

  • Golden SAML

  • MSSQL

  • Bidirectional trust

  • Golden Kerberos ticket

ghostGhost

Stay in touch!

[🫡] LinkedInarrow-up-right # Githubarrow-up-right # HackTheBoxarrow-up-right [🫡]

Last updated