# \[ Hackache ]

## \[<mark style="color:yellow;">hacking notes</mark>], \[<mark style="color:blue;">writeups</mark>] & \[<mark style="color:purple;">head aches</mark>]

***

<table data-view="cards"><thead><tr><th align="center"></th><th align="center"></th><th align="center"></th><th></th><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td align="center"><strong>Principal</strong></td><td align="center"><code>Hack The Box</code></td><td align="center"><mark style="color:yellow;">Medium</mark></td><td><ul><li>JWT bypass</li><li>Cred leak</li><li>SSH reuse</li><li>CA privesc</li></ul></td><td><a href="hack-the-box/machines/principal">principal</a></td><td data-object-fit="contain"><a href="https://1261483422-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTAjoMGhyi4qD4wiYqHYf%2Fuploads%2FpxgGuEUNv9isfN1jJsag%2FPrincipal.png?alt=media&#x26;token=a1563fbc-58d0-415c-a59d-0c904f9695ba">Principal.png</a></td></tr><tr><td align="center"><strong>Browsed</strong></td><td align="center"><code>Hack The Box</code></td><td align="center"><mark style="color:yellow;">Medium</mark></td><td><ul><li>SSRF</li><li>RCE</li><li>Sudo abuse</li><li>Python import hijacking</li></ul></td><td><a href="hack-the-box/machines/browsed">browsed</a></td><td data-object-fit="contain"><a href="https://1261483422-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTAjoMGhyi4qD4wiYqHYf%2Fuploads%2F5aXXLkBNFbHiwVyJLRFp%2FBrowsed.png?alt=media&#x26;token=b9e9a5e2-510e-4ae7-a172-daa4fe1360fd">Browsed.png</a></td></tr><tr><td align="center"><strong>Jack-of-All-Trades</strong></td><td align="center"><code>Try Hack Me</code></td><td align="center"><mark style="color:$success;">Easy</mark></td><td><ul><li>Port misconfiguration</li><li>Encoding / decoding chain</li><li>Stego</li><li>RCE</li><li>Brute force</li><li>SUID abuse</li></ul></td><td><a href="try-hack-me/rooms/jack-of-all-trades">jack-of-all-trades</a></td><td data-object-fit="contain"><a href="https://1261483422-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTAjoMGhyi4qD4wiYqHYf%2Fuploads%2FOzXkUynahl38uhjBAg5V%2FJack-of-All-Trades.jpeg?alt=media&#x26;token=00c37708-1322-4a7d-8258-a42cac6a9c54">Jack-of-All-Trades.jpeg</a></td></tr><tr><td align="center"><strong>Jax sucks alot.............</strong></td><td align="center"><code>Try Hack Me</code></td><td align="center"><mark style="color:$success;">Easy</mark></td><td><ul><li>Insecure deserialization</li><li>Sudo misconfiguration</li></ul></td><td><a href="try-hack-me/rooms/jax-sucks-alot">jax-sucks-alot</a></td><td data-object-fit="contain"><a href="https://1261483422-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTAjoMGhyi4qD4wiYqHYf%2Fuploads%2FZfghWL0GGY7NUPXb6VZC%2FJax%20sucks%20alot..............png?alt=media&#x26;token=b461d917-12a5-4a65-9939-c5cc2d91f794">Jax sucks alot..............png</a></td></tr><tr><td align="center"><strong>Crylo</strong></td><td align="center"><code>Try Hack Me</code></td><td align="center"><mark style="color:yellow;">Medium</mark></td><td><ul><li>SQLi</li><li>Bypass 2F</li><li>Decrypt</li><li><code>sudoers</code></li></ul></td><td><a href="try-hack-me/rooms/crylo">crylo</a></td><td data-object-fit="contain"><a href="https://1261483422-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTAjoMGhyi4qD4wiYqHYf%2Fuploads%2Fnmjbj9Gyaf6YipOD8zs0%2FCrylo.png?alt=media&#x26;token=db566556-b273-45a8-89d4-a497151b5bce">Crylo.png</a></td></tr><tr><td align="center"><strong>Break Out The Cage</strong></td><td align="center"><code>Try Hack Me</code></td><td align="center"><mark style="color:$success;">Easy</mark></td><td><ul><li>Anonymous FTP</li><li>Spectrogram → Vigenere key</li><li>base64 + Vigenere → SSH creds</li><li>Writable .quotes + cron injection → cage shell</li><li>Email → Vigenere → root password</li></ul></td><td><a href="try-hack-me/rooms/break-out-the-cage">break-out-the-cage</a></td><td data-object-fit="contain"><a href="https://1261483422-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTAjoMGhyi4qD4wiYqHYf%2Fuploads%2Fo3HwZUpZsSFlo8BDNemq%2FBreak%20Out%20The%20Cage.jpeg?alt=media&#x26;token=076b8fe3-b9d1-47b6-ab0a-5b77542389ec">Break Out The Cage.jpeg</a></td></tr><tr><td align="center">Hijack</td><td align="center"><code>Try Hack Me</code></td><td align="center"><mark style="color:$success;">Easy</mark></td><td><ul><li>NFS misconfiguration</li><li>UID impersonation</li><li>FTP credential exposure</li><li>Password list brute force</li><li>Cookie forgery (Base64 + MD5)</li><li>Hardcoded DB credentials</li><li><code>LD_LIBRARY_PATH</code> hijacking</li><li>Shared library injection</li></ul></td><td><a href="try-hack-me/rooms/hijack">hijack</a></td><td data-object-fit="contain"><a href="https://1261483422-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTAjoMGhyi4qD4wiYqHYf%2Fuploads%2FxoSu7sSd6IayAZFbTZdE%2FHijack.png?alt=media&#x26;token=0e7f045a-9137-4bc6-a593-b959cf339a0e">Hijack.png</a></td></tr><tr><td align="center"><strong>All in One</strong></td><td align="center"><code>Try Hack Me</code></td><td align="center"><mark style="color:$success;">Easy</mark></td><td><ul><li>WordPress plugin LFI</li><li>WordPress theme editor</li><li>Plaintext password in world-readable file</li><li>sudoers</li></ul></td><td><a href="try-hack-me/rooms/all-in-one">all-in-one</a></td><td data-object-fit="contain"><a href="https://1261483422-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTAjoMGhyi4qD4wiYqHYf%2Fuploads%2FoIVZX97jKFkNatJORneH%2FAll%20in%20One.png?alt=media&#x26;token=8616796a-ab6b-4bf2-8c0d-ea51e2511249">All in One.png</a></td></tr><tr><td align="center"><strong>Anonforce</strong></td><td align="center"><code>Try Hack Me</code></td><td align="center"><mark style="color:$success;">Easy</mark></td><td><ul><li>Anonymous FTP access</li><li>Exposed filesystem via FTP</li><li>PGP private key leak</li><li>Weak PGP passphrase</li><li>Shadow file backup exposure</li><li>Root hash cracking</li></ul></td><td><a href="try-hack-me/rooms/anonforce">anonforce</a></td><td data-object-fit="contain"><a href="https://1261483422-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTAjoMGhyi4qD4wiYqHYf%2Fuploads%2FNumJjWXihRM6xBuuw1UQ%2FAnonforce.jpeg?alt=media&#x26;token=8e93cb38-6a02-4cc2-95c0-7b651fd3bfdb">Anonforce.jpeg</a></td></tr></tbody></table>

<h2 align="center"><mark style="color:yellow;">Stay in touch!</mark></h2>

<p align="center">[🐕] <a href="https://www.linkedin.com/in/esteban-zarate/">LinkedIn</a> # <a href="https://github.com/estebanzarate">Github</a> # <a href="https://app.hackthebox.com/profile/1089152">HackTheBox</a> # <a href="https://tryhackme.com/p/no0funny">TryHackMe</a> # <a href="https://estebanzarate.vercel.app/">Portfolio</a> [🐶]</p>
