
TryHackMe-Atlassian-CVE-2022-26134
Atlassian, CVE-2022-26134 An interactive lab showcasing the Confluence Server and Data Center un-authenticated RCE vulnerability.

Atlassian, CVE-2022-26134 An interactive lab showcasing the Confluence Server and Data Center un-authenticated RCE vulnerability.

analysis of the sudo buffer overflow affect sudo version <1.8.26 and how to use GCC to compile publicly availible exploits

Explicação e demonstração da vulnerabilidade ZeroLogon (CVE-2020-1472)

A complete, modern demonstration lab for CVE-2014-6271 (Shellshock), including architecture, exploitation steps, Burp Suite usage, reverse shells,…

This is an automated exploitation script for the Hack The Box machine *Titanic*. It extracts Gitea user hashes via LFI, assists in cracking them, and…

Dockerized lab for training on NGINX rewrite vulnerability (CVE-2026-42945) with vulnerable and patched instances, benign test scripts, and…

Privilege Escalation on HTB "Poison" using PwnKit (CVE-2021-4034)

OS command injection vulnerability in Samba that received the maximum possible CVSS v3.1 score of 10.0

CTF challenge deploying CVE-2022-0847 (Dirty Pipe) exploit to overwrite read-only files. Includes setup scripts, hints, and verification for kernel…

CVE-2022-46152: Improper Validation of Array Index in the `cleanup_shm_refs' function.

This is an exercise built around CVE-2021-3560

Step-by-step CTF walkthrough exploiting the vsftpd 2.3.4 backdoor (CVE-2011-2523) to capture and crack /etc/shadow and /etc/passwd from…

This report details exploiting Trickster via an XSS in PrestaShop (CVE-2024-34716) to gain www-data access, extracting database credentials for SSH…

Hands-on lab demonstrating the Shellshock (CVE-2014-6271) Bash vulnerability with privilege escalation via environment variable injection, based on…

Modular Bash toolkit that hardens Debian/Ubuntu systems for CyberPatriot competitions, automating account, firewall, SSH, PAM, and service hardening…

Steganography brute-force utility to uncover hidden data inside files

DO NOT RUN THIS.

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.