HTB Writeup – BigBang
Posted on 2025-01-28
Exploit a classic Glibc buffer overflow on PHP heaps & APK Reversing
Exploit a classic Glibc buffer overflow on PHP heaps & APK Reversing
Exploit open-source C2s: Havoc (CVE-2024-41570) & Hardhat
Windows AD CS exploitation for Red Teaming practise with ESC4
Exploit Ghost CMS 5.58.0 CVE-2023-40028 after a Git leak
Zabbix CVE-2024-36467 (JSON RPC IDOR) & CVE-2024-42327 (SQLi)
LFI, JWT Forgery, SQLi, Crontab abuse, Mercurial hook, Rsync privesc
XSS + RCE for PrestaShop & exploit SSTI on ChangeDetection.io
Exploit H2 Database for Java web app & abuse Apache Thrift
SQLPad RCE vulnerability & Froxlor exploit via Chrome remote debugging
RCE for CACTI monitor system, Auth bypass for Duplicati backup solution.