Broker
Walkthrough of the Broker machine – exploiting an unauthenticated RCE in Apache ActiveMQ to gain a foothold as the activemq user, then escalating to root via a sudo misconfiguration on nginx.
Walkthrough of the Broker machine – exploiting an unauthenticated RCE in Apache ActiveMQ to gain a foothold as the activemq user, then escalating to root via a sudo misconfiguration on nginx.
Walkthrough of the Active machine – enumerating anonymous SMB shares to find a Group Policy Preferences (GPP) password in Groups.xml, decrypting it with gpp-decrypt for a domain user foothold, then escalating to Domain Admin by Kerberoasting a service ticket for the Administrator account and cracking it with hashcat.
Walkthrough of the Access machine – anonymous FTP leading to a chain of leaked credentials across a database, a password-protected zip, and an Outlook mailbox, followed by a telnet foothold and privesc via cached Administrator credentials.
Walkthrough of the Devel machine – anonymous FTP tied to an IIS webroot, an msfvenom aspx webshell for initial access, and a Windows kernel exploit (kitrap0d) for SYSTEM.
Walkthrough of the Blocky machine – WordPress/Minecraft enumeration, credentials leaked from a decompiled Java plugin, and a sudo ALL misconfiguration for root.
Walkthrough of the Beep machine – Elastix/FreePBX enumeration, SIP extension bruteforcing with svwar, remote code execution via a public exploit, and sudo NOPASSWD nmap privilege escalation.
Walkthrough of the Bashed machine – directory fuzzing to a web shell, sudo NOPASSWD misconfiguration to pivot users, and a cron job script overwrite for root.

PortSwigger Web Security Academy - Cross-Site Scripting (XSS) vulnerabilities labs

A comprehensive, structured guide to understanding, exploiting, and preventing SQL injection vulnerabilities — covering Union-based, Blind, Error-based, Time-based, and Out-of-Band techniques, database-specific differences, WAF bypass, tools, payloads, and step-by-step methodology.

PortSwigger Web Security Academy - SQL Injection vulnerabilities labs

A comprehensive, structured guide to understanding, exploiting, and preventing authentication vulnerabilities — covering 18 vulnerability classes, tools, commands, and step-by-step methodology.

PortSwigger Web Security Academy - Information Disclosure vulnerabilities labs