
VulnHub-DC1-Writeup
VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

Indirect syscalls + DInvoke made simple.

Proof-of-concept exploit for CVE-2020-0728 demonstrating local privilege escalation via Windows TrustedInstaller COM service abuse to bypass file…

Journey to Try Harder !!!

Kioptrix Level 1 writeup - CVE-2003-0201 Samba trans2open

Bypassing UAC with SSPI Datagram Contexts

Amsi Bypass payload that works on Windwos 11

DCOM in memory and fileless lateral movement techniques through .Net deserilization

A PoC for achieving persistence via push notifications on Windows

An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer

HackTheBox TwoMillion machine writeup — API abuse, command injection & CVE-2023-0386