Time ๐ Apr 15, 2021 ยท โ 9 min read ยท โ๏ธ M4t35Z My HackTheBox Time writeup (Jackson rce --> Weak permissions)
Overpass3 - Hosting ๐ Mar 11, 2021 ยท โ 9 min read ยท โ๏ธ M4t35Z dirfuzz --> backup --> gpg --> creds --> ftp --> pw reuse --> nfs
Feline ๐ Feb 20, 2021 ยท โ 12 min read ยท โ๏ธ M4t35Z A box featuring java deserialization multiple CVE's and a docker privesc
The Great Escape ๐ Feb 20, 2021 ยท โ 14 min read ยท โ๏ธ M4t35Z robots --> backup --> dev api --> command injection --> injection --> git log --> port knocking --> docker -H
Overpass2 - hacked ๐ Feb 7, 2021 ยท โ 4 min read ยท โ๏ธ M4t35Z A box about pcap analysis and a SUID binary
Archangel ๐ Feb 6, 2021 ยท โ 8 min read ยท โ๏ธ M4t35Z A box about getting an RCE via LFI and Log Poisoning. Then abusing a cronjob that used a file with weak permissions. And then analysing a suid binary which used relative paths instead of absolute paths which made it vulnerable to path injection.
hackerNote ๐ Feb 5, 2021 ยท โ 5 min read ยท โ๏ธ M4t35Z A box about user enumeration(I did it with the hint fuctionality), brute forcing and abusing a well-known sudo cve (pwfeedback bof)
Omni ๐ Jan 20, 2021 ยท โ 6 min read ยท โ๏ธ M4t35Z HackTheBox Omni writeup. A Windows IOT box, with PSCredential encrypted flags
Bot Takeover 0x1 ๐ Dec 19, 2020 ยท โ 5 min read ยท โ๏ธ M4t35Z Command injection in a discord BOT