Time 📅 Apr 15, 2021 · ☕ 9 min read · ✍️ M4t35Z My HackTheBox Time writeup (Jackson rce --> Weak permissions)
The Great Escape 📅 Feb 20, 2021 · ☕ 14 min read · ✍️ M4t35Z robots --> backup --> dev api --> command injection --> injection --> git log --> port knocking --> docker -H
hackerNote 📅 Feb 5, 2021 · ☕ 5 min read · ✍️ M4t35Z A box about user enumeration(I did it with the hint fuctionality), brute forcing and abusing a well-known sudo cve (pwfeedback bof)
OpenKeyS 📅 Dec 11, 2020 · ☕ 4 min read · ✍️ M4t35Z Writeup for OpenKeyS, a medium OpenBSD box. Web enum --> source --> auth bypass cve --> cookie --> id_rsa --> authroot cve --> root
Sneaky Mailer 📅 Nov 29, 2020 · ☕ 10 min read · ✍️ M4t35Z Subdomain enum --> smtp --> phishing --> creds --> imap --> more creds --> ftp(upload a revshell) --> pypi privesc --> user.txt --> gtfobins --> root.txt
Fuse 📅 Nov 1, 2020 · ☕ 8 min read · ✍️ M4t35Z Fuse writeup. http --> crawl --> cme --> passreset --> rpc --> printerpass --> winrm --> groups --> Admin