Published onJanuary 4, 2025Vocateer WriteupBOLASQLILinuxHacking-ClubMáquina sobre Broken Access Control, BOLA, SQL Injection e linux capabilities.
Published onNovember 30, 2024Paradize WriteupSQLILinuxHacking-ClubOn the Paradize machine, we need to exploit an SQL injection to upload a webshell and explore a path hijacking vulnerability.
Published onNovember 25, 2024Injection WriteupCVE-2022-36231Command-InjectionLinuxHacking-ClubThe Injection machine is vulnerable to Command Injection (CVE-2022-36231) and privilege escalation via sudo.
Published onNovember 23, 2024Bin Trunk WriteupBOLALinuxHacking-ClubApplication has a BOLA vulnerability, unauthorized file access, SSH key usage, privilege escalation via SUID, and code execution.
Published onNovember 19, 2024Uploader WriteupLFIRCELinuxThe application has vulnerabilities of Local File Inclusion (LFI), Remote Code Execution (RCE) via Jenkins, and privilege escalation using a SUID binary.