TryHackMe: Adventure Time Writeup
Summary Adventure Time is a hard-rated TryHackMe box themed around the cartoon, with a heavy focus on multi-layered encoding/decoding puzzles, steganography, and lateral movement through several user
Search for a command to run...
Articles tagged with #remote-code-execution
Summary Adventure Time is a hard-rated TryHackMe box themed around the cartoon, with a heavy focus on multi-layered encoding/decoding puzzles, steganography, and lateral movement through several user
Summary Python Playground is a hard-rated TryHackMe box built around a "sandboxed" Python code execution service fronted by a Node.js/Express web app. The site advertises a blacklist-based filter that
Summary Olympus is a Linux box built around an old Victor CMS 1.0 install hidden under /~webmaster/. An unauthenticated SQL injection in the CMS search feature was the root of the entire chain: it dum
Summary Lookup is an easy Linux box built around a login portal that redirects authenticated users to a vhost-hosted elFinder file manager. Username enumeration on the login form combined with passwor

TL;DR Byte Lotus Poolside is a Node.js/Express booking app. A NoSQL injection in the login endpoint bypasses authentication entirely and lands directly in the staff role. The staff console's booking-c

TL;DR Beach Bar is a Flask-based "DJ booth" web app for a beach bar jukebox. Default demo credentials (dj/dj) left enabled in an HTML comment get you into the dashboard, which exposes a YAML playlist
