• Home
  • CTF Walkthroughs
    • Hack The Box
    • TryHackMe
    • VulnHub
  • Guides
    • Enumeration
    • Privilege Escalation
      • Linux
      • Windows
    • Web
    • Buffer Overflow
      • Stack Buffer Overflow
  • Reviews
    • Certifications
    • Training Labs
    • Learning Material
  • Resources
    • Cheat Sheets
    • Checklists
  • About
Steflan’s Security Blog
CTF Walkthroughs, Hack The Box

Hack The Box – Tenet Walkthrough

Introduction

This was an intermediate Linux box that involved exploiting a PHP deserialization vulnerability to gain initial access, and a vulnerable Bash script to overwrite the root user’s authorized SSH keys and escalate privileges.

Read more
June 13, 2021 | by Stefano Lanaro | Leave a comment
Share
CTF Walkthroughs, Hack The Box

Hack The Box – Devel Walkthrough

Introduction

This was an easy Windows box that involved exploiting an open FTP server to upload an ASPX shell and gain remote access to the host, and the MS10-015 KiTrap0D vulnerability to escalate privileges to SYSTEM.

Read more
June 11, 2021 | by Stefano Lanaro | Leave a comment
Share
CTF Walkthroughs, TryHackMe

TryHackMe – Basic Pentesting Walkthrough

Introduction

As the name suggests, this was a really simple challenge that involved accessing an open SMB share to identify usernames, performing a SSH brute-force attack to obtain access, and cracking the passphrase for a world-readable SSH key to escalate privileges.

Read more
June 11, 2021 | by Stefano Lanaro | Leave a comment
Share
CTF Walkthroughs, TryHackMe

TryHackMe – Web Fundamentals Mini CTF Walkthrough

Introduction

This mini CTF was part of the web fundamentals room and it aims to allow students to practice their web skills with GET/POST requests and cookies.

Read more
June 11, 2021 | by Stefano Lanaro | Leave a comment
Share
CTF Walkthroughs, Hack The Box

Hack The Box – Networked Walkthrough

Introduction

This was an easy Linux machine that involved exploiting a vulnerable file upload functionality to gain initial access and various misconfigured scripts on the box to escalate privileges to root.

Read more
June 11, 2021 | by Stefano Lanaro | Leave a comment
Share
Buffer Overflow, CTF Walkthroughs, Guides, Stack Buffer Overflow, TryHackMe

TryHackMe – Buffer Overflow Prep Walkthrough

Introduction

This room is part of the TryHackMe Offensive Security path and it aims to teach or consolidate stack buffer overflow exploitation skills for students aspiring to take on the OSCP certification exam.

Read more
June 10, 2021 | by Stefano Lanaro | Leave a comment
Share
CTF Walkthroughs, Hack The Box

Hack The Box – SkriptKiddie Walkthrough

Introduction

This was an easy Linux machine that involved exploiting a vulnerability in MSFVenom to gain remote code execution, a misconfigured Bash script to escalate to the “pwn” user, and a Sudo rule to escalate privileges to root.

Read more
June 9, 2021 | by Stefano Lanaro | Leave a comment
Share
Guides, Linux, Privilege Escalation

Linux Privilege Escalation – Exploiting NFS Shares

Introduction

Network File System is a protocol that allows users to access files over a computer network much like local storage is accessed, like many other protocols, it builds on the Open Network Computing Remote Procedure Call (ONC RPC) system. If misconfigured, it could allow regular users to escalate privileges to root.

Read more
June 2, 2021 | by Stefano Lanaro | Leave a comment
Share
CTF Walkthroughs, TryHackMe

TryHackMe – Internal Walkthrough

Introduction

This was an intermediate-level Linux machine that involved brute-forcing WordPress credentials to gain initial access through a malicious plugin upload and escalating privileges through a Jenkins instance with weak credentials.

Read more
June 1, 2021 | by Stefano Lanaro | Leave a comment
Share
CTF Walkthroughs, Hack The Box

Hack The Box – Jarvis Walkthrough

Introduction

This was an intermediate Linux machine that involved exploiting a SQL injection vulnerability to gain initial access, a misconfigured Python script to escalate to the “pepper” user and the Systemctl binary with SUID privileges set to escalate to root.

Read more
June 1, 2021 | by Stefano Lanaro | Leave a comment
Share
Older posts
Newer posts
  • Home
  • About
Powered by Piemont - Premium Wordpress Theme
×
  • Navigation

    • Home
    • CTF Walkthroughs
      • Hack The Box
      • TryHackMe
      • VulnHub
    • Guides
      • Enumeration
      • Privilege Escalation
        • Linux
        • Windows
      • Web
      • Buffer Overflow
        • Stack Buffer Overflow
    • Reviews
      • Certifications
      • Training Labs
      • Learning Material
    • Resources
      • Cheat Sheets
      • Checklists
    • About
  • About StefLan Security

    I am a penetration tester and cyber security / Linux enthusiast.

    Through this blog, I would like to share my passion for penetration testing, hoping that this might be of help for other students and professionals out there. I will be more than glad to exchange ideas with other fellow pentesters and enthusiasts.

  • Recent Posts

    • Certified Read Team Operator (CRTO) Review January 2, 2025
    • Certified Red Team Expert (CRTE) Review April 16, 2024
    • TryHackMe – Nax Walkthrough April 8, 2024
    • Certified Azure Red Team Professional (CARTP) Review December 23, 2023
    • A Complete Guide to Hacking GraphQL September 17, 2023