>_ Tiago Galvão offensive security
Open to opportunities Contact
Practical Security Labs

Pentesting labs & technical writeups.

Structured walkthroughs covering reconnaissance, vulnerability discovery, exploitation and the lessons learned from practical offensive-security challenges.

THM Challenges

TryHackMe Web RFI RCE

RFI Challenge — TryHackMe

Exploiting insecure server-side file inclusion by hosting a remote PHP payload and using it to execute commands on the target.

TryHackMe IDOR LFI Command Injection

Support Web Challenge — TryHackMe

Chaining password brute force, client-side privilege manipulation, IDOR, file inclusion and command injection to obtain administrator access and remote execution.

TryHackMe Path Traversal SQLi SQLMap

Recruit Web Challenge — TryHackMe

Using exposed application information and arbitrary file disclosure to access the HR account before exploiting SQL injection to recover administrator credentials.

TryHackMe OTP Brute Force JWT RCE

Hammer — TryHackMe

Discovering exposed logs to identify a valid account, bypassing OTP rate limiting during password recovery, and manipulating a JWT signing key to escalate privileges and execute commands as administrator.

TryHackMe Stored XSS Session Hijacking CSRF

What's Your Name? — TryHackMe

Exploiting stored XSS to steal a moderator session, abusing exposed API functionality to elevate account privileges, and chaining the chat system with a CSRF attack to take over the administrator account.

TryHackMe SSRF LFI Log Poisoning

Include — TryHackMe

Abusing mass assignment to gain administrator privileges, using SSRF to access internal APIs and recover credentials, and chaining local file inclusion with mail log poisoning to achieve remote command execution.

TryHackMe SQLi SSTI Twig

Injectics — TryHackMe

Bypassing weak client-side SQL injection filtering to access the application, abusing a database recovery mechanism to obtain administrator credentials, and exploiting Twig SSTI to achieve remote command execution.

No writeups matched your search.