HackTheBox - Lame
A classic beginner-friendly Linux box: a tempting service turns out to be a dead end, an overlooked daemon opens the door, and a misconfigured SUID binary hands over root.
A classic beginner-friendly Linux box: a tempting service turns out to be a dead end, an overlooked daemon opens the door, and a misconfigured SUID binary hands over root.
This box involves exploiting a known deserialization vulnerability in a self-hosted ML platform, then chaining it with a misconfigured sudo permission to escalate privileges via a malicious PyTorch model file.
This module is designed to help you understand and learn the basic concepts of different password attacks.
A Linux machine where a publicly exposed JAR file reveals a vulnerable internal SOAP service, and a chain of misconfigurations — from exposed credentials to a world-writable binary — leads all the way to root.
The Metasploit Framework is an open-source set of tools used for network enumeration, attacks, testing security vulnerabilities, evading detection, performing privilege escalation attacks, and performing post-exploitation.
Version 1.0