HTB Writeup – Gavel
Posted on 2025-11-30
SQL injection abusing PDO substitution in PHP Prepared Statement
SQL injection abusing PDO substitution in PHP Prepared Statement
There is no excerpt because this is a protected post.
BadSuccessor attack by creating a malicious dMSA object in AD
There is no excerpt because this is a protected post.
Transform XSLT to HTML with extensions → special XML “SSTI”
There is no excerpt because this is a protected post.
Ticket Forgery & Token Abuse with a service account in Win AD
From bi-directional MSSQL linked servers in to CVE-2024-30088 LPE