Published onJanuary 4, 2025Vocateer WriteupBOLASQLILinuxHacking-ClubMáquina sobre Broken Access Control, BOLA, SQL Injection e linux capabilities.
Published onNovember 30, 2024Paradize WriteupSQLILinuxHacking-ClubOn the Paradize machine, we need to exploit an SQL injection to upload a webshell and explore a path hijacking vulnerability.
Published onNovember 14, 2024CAP WriteupAPI-RESTSQLIIDORLinuxHacking-ClubThe application has the following vulnerabilities: endpoint enumeration via FUZZ, SQL Injection, remote command execution (RCE), and privilege escalation via Linux capabilities.
Published onNovember 7, 2024Lion WriteupSQLIRCELinuxHacking-ClubThe Lion machine is vulnerable to SQL injection, allowing RCE through the upload of a webshell, and has privilege escalation via cron jobs.
Published onJune 16, 2024Guardian WriteupSQLICODE-INJECTIONLinuxHacking-ClubMachine involving SQL Injection, code injection, and reversing (PE).