Published onNovember 14, 2024CAP WriteupAPI-RESTSQLIIDORLinuxHacking-ClubThe application has the following vulnerabilities: endpoint enumeration via FUZZ, SQL Injection, remote command execution (RCE), and privilege escalation via Linux capabilities.
Published onNovember 13, 2024iNotes WriteupIDORWindowsHacking-ClubThis is a HackingClub championship machine where we found an IDOR that provides initial access and Privilege Escalation through XAMPP.