Axios : Supply Chain Attack
π¨ Axios Supply Chain Attack = Simple Explanation of What Happened A major software supply chain attack has just impacted the JavaScript ecosystem, targeting one of the most widely used libraries i...
π¨ Axios Supply Chain Attack = Simple Explanation of What Happened A major software supply chain attack has just impacted the JavaScript ecosystem, targeting one of the most widely used libraries i...
Expressway is an easy-difficulty linux machine from Hack The Box where we start with Enumeration (TCP/UDP Scans) β> IKE-Scan β> PSK Cracking (psk-crack) β> SSH Access β> Sudo CVE Check ...
GiveBack is a medium-difficulty Linux machine from Hack The Box where we exploited an unauthenticated PHP object injection in the GiveWP plugin (CVE-2024-5932) to achieve remote code execution insi...
Soulmate is an easy-difficulty Linux machine from Hack The Box where we found the hidden subdomain ftp.soulmate.htb exposing CrushFTP β abused CVE-2025-31161 auth bypass to register a new admin acc...
Signed is a medium-difficulty Windows machine where we start with provided MSSQL credentials (scott / Sm230#C5NatH) β abuse xp_dirtree + Responder to capture & crack the mssqlsvc NTLMv2 hash (p...
CodeTwo is an easy-difficulty linux machine from Hack The Box when you need to register in a website and run a code that is vulnrable to js2py to get RCE β getting username and password from users....
Imagery is a medium machine from HackThebox where i started with XSS in Bug Report β> Admin Cookie Theft β> LFI in Log Download β> Database Leak β> Command Injection in Image Transform ...
WhiteRabbit is an insane machine from HackThebox where i started with Virtual host fuzzing revealed internal status subdomain β> Misconfigured Uptime Kuma / WikiJS stack exposed GoPhish webhook ...
Outbound is an easy-difficulty linux machine from Hack The Box where you start with credentials for the following account tyler / LhKL1o9Nm3X2 Roundcube RCE β> MySQL Credentials β> DES3 Decr...
My CRTP Journey: A Hands-On Dive into Active Directory Red Teaming Hey everyone! Itβs been a week since I earned my Certified Red Team Professional (CRTP) certification from Altered Security, and ...