
WhatTheHack
A collection of challenge based hack-a-thons including student guide, coach guide, lecture presentations, sample/instructional code and templates. …

A collection of challenge based hack-a-thons including student guide, coach guide, lecture presentations, sample/instructional code and templates. …

Penetration testing assessment of a vulnerable IIS 6.0 WebDAV server, demonstrating reconnaissance, enumeration, exploitation (CVE-2017-7269), and…

Technical write-up on CVE-2024-21413 (Moniker Link vulnerability)

Technical audit of Kioptrix Level 1. Focus: Samba 2.2.1a exploitation (CVE-2003-0201), manual enumeration, and internal infrastructure hardening.

Research on CVE-2025-3052, an Insyde firmware vulnerability that exposes an arbitrary write primitive capable of modifying security-critical pointers.

Step-by-step demonstration of a local privilege escalation vulnerability in Lenovo PC Manager, exploiting weak file permissions on a system service…

The objective is to conduct a full-scale security assessment of a WordPress-based web application, culminating in a complete server compromise. The…

This vulnerability allows attackers to perform relay attacks against the SMB (Server Message Block) protocol. If successful, it can lead to Elevation…

Educational demonstration of the Log4Shell vulnerability (CVE-2021-44228) with JNDI LDAP payloads for experimental testing on your own systems.

A vulnerable version of Rails that follows the OWASP Top 10

A lab demonstration of the log4shell vulnerability: CVE-2021-44228

SOC287 - Arbitrary File Read on Checkpoint Security Gateway [CVE-2024-24919]

Lab testing documentation for CVE-2026-31431 (Copy Fail) Linux kernel LPE

Expolit for CVE-2024-23334 (aiohttp >= 1.0.5> && <=3.9.1)

CVE-1999-0678- /doc directory browsable

Mongo Vulnub Lab...Try to Hack IT.....!

PowerShell-based provisioning framework for deploying complex lab environments on Hyper-V and Azure. Supports Windows, Linux, and products like AD,…

Local privilege escalation exploit for CVE-2026-3888 targeting snap-confine and systemd-tmpfiles on Ubuntu, providing SUID and capabilities variants…