Writeups & Labs

Canonical lab writeups & walkthroughs.

Web Exploitation

TryHackMe web rfi

RFI Challenge — TryHackMe

Remote File Inclusion exploitation.

TryHackMe xss web

Stored XSS Cookie Exfiltration

Stored XSS to extract session cookies.

TryHackMe cms

Bolt CMS — RCE

Bolt CMS exploitation leading to RCE.

TryHackMe web

Pickle Rick

Web enum → creds → sudo escalation.

Enumeration & Authentication

TryHackMe auth

Username / Password Enumeration

Hydra + Burp authentication enumeration.

TryHackMe intruder

Burp Intruder Ticket Enumeration

ID brute via Sniper + 200 OK logic.

TryHackMe

HA Joker CTF

Enum + bruteforce + cracking chain.

Privilege Escalation

TryHackMe

Simple CTF

CMS exploit → crack → root.

TryHackMe

Pyrat

Reverse shell → git creds → SSH → root.

TryHackMe

Mr Robot

WordPress → shell → SUID Nmap.

Full CTF Walkthroughs

TryHackMe

Basic Pentesting

Full engagement chain.