• Home
  • CTF Walkthroughs
    • Hack The Box
    • TryHackMe
    • VulnHub
  • Guides
    • Enumeration
    • Privilege Escalation
      • Linux
      • Windows
    • Web
    • Buffer Overflow
      • Stack Buffer Overflow
  • Reviews
    • Certifications
    • Training Labs
    • Learning Material
  • Resources
    • Cheat Sheets
    • Checklists
  • About
Steflan’s Security Blog
CTF Walkthroughs, TryHackMe

TryHackMe – Attacktive Directory Walkthrough

Introduction

This was an intermediate Windows machine that involved enumerating an active directory domain, using ASREPRoasting to obtain initial access, and performing a DCSync attack to escalate privileges to Administrator-level access.

Read more
July 9, 2021 | by Stefano Lanaro | Leave a comment
Share
CTF Walkthroughs, TryHackMe

TryHackMe – Retro Walkthrough

Introduction

This was a Windows machine that required to enumerate a WordPress instance to identify user credentials and remotely authenticate via RDP and exploit the Windows COM Vulnerability to escalate privileges to SYSTEM.

Read more
July 8, 2021 | by Stefano Lanaro | Leave a comment
Share
CTF Walkthroughs, Hack The Box

Hack The Box – Ophiuchi Walkthrough

Introduction

This was an intermediate Linux machine that involved exploiting a deserialization vulnerability in the SnakeYaml parser to gain initial access, and a misconfigured WebAssembly binary with Sudo permissions set to escalate privileges to root.

Read more
July 5, 2021 | by Stefano Lanaro | Leave a comment
Share
CTF Walkthroughs, Hack The Box

Hack The Box – Spectra Walkthrough

Introduction

This was an easy Linux machine that involved finding database credentials contained in a backup WordPress instance to gain initial access and exploiting the /sbin/initctl binary with Sudo permissions to escalate privileges to root.

Read more
June 28, 2021 | by Stefano Lanaro | Leave a comment
Share
CTF Walkthroughs, TryHackMe

TryHackMe – LazyAdmin Walkthrough

Introduction

This was an easy Linux machine that involved exploiting a backup disclosure issue in SweetRice CMS to gain remote execution and a misconfigured script with root permissions to escalate privileges to root.

Read more
June 19, 2021 | by Stefano Lanaro | Leave a comment
Share
Buffer Overflow, CTF Walkthroughs, Guides, Stack Buffer Overflow, TryHackMe

TryHackMe – Gatekeeper Walkthrough

Introduction

This was an intermediate Windows machine that involved exploiting a stack buffer overflow vulnerability to gain initial access and dumping and decrypting Mozilla Firefox credentials stored on the box to escalate privileges to system.

Read more
June 18, 2021 | by Stefano Lanaro | Leave a comment
Share
CTF Walkthroughs, Hack The Box

Hack The Box – Nineveh Walkthrough

Introduction

This was an intermediate Linux machine that involved chaining a local file inclusion and remote code execution vulnerability to gain initial access, and exploiting an issue with the Chkrootkit software to escalate privileges.

Read more
June 16, 2021 | by Stefano Lanaro | Leave a comment
Share
Buffer Overflow, CTF Walkthroughs, Guides, Stack Buffer Overflow, TryHackMe

TryHackMe – Brainstorm Walkthrough

Introduction

This was an intermediate Linux machine that involved exploiting a stack buffer overflow vulnerability to gain SYSTEM level access to the box.

Read more
June 15, 2021 | by Stefano Lanaro | Leave a comment
Share
CTF Walkthroughs, TryHackMe

TryHackMe – RootMe Walkthrough

Introduction

This was an easy Linux machine that involved exploiting a vulnerable file upload functionality to gain initial access and Python with the SetUID bit assigned to it to escalate privileges to root.

Read more
June 15, 2021 | by Stefano Lanaro | Leave a comment
Share
CTF Walkthroughs, TryHackMe

TryHackMe – Simple CTF Walkthrough

Introduction

This was an easy Linux box that involved exploiting a blind SQL injection vulnerability in CMS Made Simple to obtain initial access and the Vim text editor allowed to run as root to escalate privileges to root.

Read more
June 15, 2021 | by Stefano Lanaro | Leave a comment
Share
Older posts
Newer posts
  • Home
  • About
Powered by Piemont - Premium Wordpress Theme
×
  • Navigation

    • Home
    • CTF Walkthroughs
      • Hack The Box
      • TryHackMe
      • VulnHub
    • Guides
      • Enumeration
      • Privilege Escalation
        • Linux
        • Windows
      • Web
      • Buffer Overflow
        • Stack Buffer Overflow
    • Reviews
      • Certifications
      • Training Labs
      • Learning Material
    • Resources
      • Cheat Sheets
      • Checklists
    • About
  • About StefLan Security

    I am a penetration tester and cyber security / Linux enthusiast.

    Through this blog, I would like to share my passion for penetration testing, hoping that this might be of help for other students and professionals out there. I will be more than glad to exchange ideas with other fellow pentesters and enthusiasts.

  • Recent Posts

    • OffSec Web Expert (OSWE) Review November 11, 2025
    • Certified Read Team Operator (CRTO) Review January 2, 2025
    • Certified Red Team Expert (CRTE) Review April 16, 2024
    • TryHackMe – Nax Walkthrough April 8, 2024
    • Certified Azure Red Team Professional (CARTP) Review December 23, 2023