Writeup

MAQUINA JORDAK (Web RCE jordani 1.0.0 + PRIVESC 'env')chevron-rightMAQUINA ALGERNON (VULn 'smartermail v6985 RCE')chevron-rightMAQUINA TWIGGY (CMS MEZZANINA RCE VULN ZEROMQ ZMTP o API SALTSTACK 3000.1 'cve 2020 11651')chevron-rightMAQUINA BOOLEAN (Modificacion de REQUEST con Burpsuite ' confirmed = true ' + LFI + UPLOAD ID_RSA anchevron-rightMAQUINA AUTHBYT (FTP anonymous y credenciales por defecto + subida de archvio PHP revershell a FTPchevron-rightMAQUINA CLAMV (VULN SMTP 25 'clamv' Sendmail 8.13 SEARCHSPLOIT)chevron-rightMAQUINA COCKPIT (Gobuster extension php + Blaze CMS 'SQLI BYPASS LOGIN' + UBUNTU WEB + REVERSHELL +chevron-rightMAQUINA CODO (CODOFORUM 5.1 'RCE + UPLOAD IMG.' + LINPEAS)chevron-rightMAQUINA CVE-2023-40582 (Vulnerabilidad de Inyección de Comando en find exec)chevron-rightMAQUINA CVE-2023-46818 (RCE CVE 2023 46818 ispconfig.)chevron-rightMAQUINA DC 2 (Enum Users Wordpress WPSCAN + CEWL wordlists + BruteForce WPSCAN + PRIVESC bin git 'jechevron-rightMAQUINA DETECTION (WEB 'changedetection' port 5000 + VULN RCE 'changedetection RCE')chevron-rightMAQUINA ELECTION1 (Sito web Election 2.0 + PHPmyadmin login + Escalate Priv SERV U)chevron-rightMAQUINA DVR4 (web 'Argus Surveillance DVR version 4.0.0.0' + Vuln 'Argus Surveillance DVR DIRECTORYchevron-rightMAQUINA EXFILTRED Subrion CMS v4.2.1 File Upload Bypass to RCE (Authenticated) UPLOAD PHAR 'CMD' PRIchevron-rightMAQUINA FAIL (ENUM RSYNC 'PUERTO 873' + SSH- KEYGEN + PREVISEC 'GROUP FAIL2BAIN')chevron-rightMAQUINA FANTASTIC (GRAFANA 8.3 'vuln lfi' + PROMETHEUS 2.32 + ESCALATE PRIV 'group DISK = root + ID_chevron-rightMAQUINA FUNYBOX (CSE BOOKSTORE 1.0 Vuln rce no autenticado PRIVESC pkexec 'sudo l' extra bypass login SMALL CRM ADMIN 3.0)chevron-rightMAQUINA INTERNAL (WINDOWS SERVER 2008 + CVE 2009 3103 + METERPRETER RCE)chevron-rightMAQUINA HUB ( Enum web port 8082 + FUGUHUB + injeccion revershell en LUA)chevron-rightMAQUINA KEVIN (VULN HP POWER MANAGER 'admin admin' Metasploit PrivEsc 'hp manager filename' Metasploit BufferOverflow 'MANUAL')chevron-rightMAQUINA LEVRAM (Exploit GERAPY 0.9.6 RCE searchsploit + PRIVESC 'CAPABILITES python3.10')chevron-rightMAQUINA MEDJED (WEBDAV BarracudaDrive 6.5 + Revershell .php creado con msfvenom + PrivEsc local barracudadrive 6.5)chevron-rightMAQUINA NUKEM (WORDPRESS 5.5.1 ABUSED PLUGINS SIMPLE LIST 4.4.2 PIVOTING USER MYSQL PASSOWORD PIVOTING PUERTO Y TUNELIZACION SSH PRIVESC 'DOSBOX' CAMBIO DE PERMISOS SUDOERS CON REMMINA)chevron-rightMAQUINA PASS (FlatPass 1.2 Vuln 'file upload bypass RCE' Privesc 'apt get')chevron-rightMAQUINA PELICAN (RCE ZooKeeper v1 Web UI + RCE + PrivEsc 'gcore pid + extract password 'strings' = root)chevron-rightMAQUINA RAY PROJECT CVE 2023 6019 (COMMANDO INJECTION RAY PROJECT)chevron-rightMAQUINA SHENZI (Enum SMB 'nullsesion' + Directory Web = Nombre del recurso compartido + WORDPRESS RCchevron-rightMAQUINA BRATARINA (SMB null session + RCE 'OPENSMTPD 2.0.0') + (MODIFICACION passwd 'agregar password' + Subscribir archivo etc passwd)chevron-rightMAQUINA SQUID (web proxy SQUID 4.14 + 'RCE UPLOAD script' PHPMYADMIN 5.0.2)chevron-rightMAQUINA PC (PortForwarding port 65432 - PrivEsc 0-day 2022 rpc.py)chevron-rightMAQUINA FUNBOXEASY (Enum directory - RCE .php - Pivoting User - PrivEsc SUDO-L)chevron-rightMAQUINA SLORT (Enum de directorios Acceso a la maquina con LFI and RCI PrivEsc Auto Elevated Executable Hijacking)chevron-rightMAQUINA PASSPORT (Enum Directorios ss2john id rsa PrivEsc Creacion de archivo con permisos SUID)chevron-rightMAQUINA PYLOADER (pyload 0.5.0 Rce No autenticado)chevron-rightMAQUINA HUTCH (Netexec LDAP enum - PrivEsc Netexec DUMP Laps)chevron-rightMAQUINA GAARA (Brute Force SSH PrivEsc 'gdb' gtfobins)chevron-right