Vulndev

  • Home
  • Blog
  • Tools
    • Shellcode Converter
  • Misc
    • Exploits
    • Machine List
    • Cheats – Windows
    • Cheats – Linux
    • Cheats – Shells
    • Cheats – Cracking
  • Vulnlab
  • Discord
  • About Me
  • Home
  • Blog
  • Tools
    • Shellcode Converter
  • Misc
    • Exploits
    • Machine List
    • Cheats – Windows
    • Cheats – Linux
    • Cheats – Shells
    • Cheats – Cracking
  • Vulnlab
  • Discord
  • About Me

Home

xct2021-09-10T07:02:29+00:00
28JanJanuary 28, 2023

VL Shinra Part 4 – Reverse Engineering, Binary Exploitation & Ansible

xct2023-01-28T09:25:14+00:00

This is part four of the Shinra series. We will get to access to a linux server via ssh, exploit a small authenticator app & use ansible to move to the next box.

By xctVulnlabansible, binary exploitation, linux
Read more...
18JanJanuary 18, 2023

VL Shinra Part 3 – Initial Payload Design, Host Enumeration & getting SYSTEM

xct2023-01-18T17:06:46+00:00

This is the third video of the Shinra series. We will get a shell on Ashleighs machine & escalate privileges.

By xctVulnlabactive directory, c2, evasion, phishing, runas, windows
Read more...
10JanJanuary 10, 2023

VL Shinra Part 2 – Enumerate, Enumerate, Enumerate!

xct2023-01-18T17:07:53+00:00

This is the second video of the Shinra series. Before setting foot onto any of the network's internal machines, we are going to spend a bit of time enumerating various things from our machine

By xctVulnlabactive directory, linux, windows
Read more...
08JanJanuary 8, 2023

Real World CTF 2023 – NonHeavyFTP

xct2023-01-08T14:08:29+00:00

This is a short writeup on the "NonHeavyFTP" challenge from Real World CTF 2023. This was one of the easier challenges with the goal of exploiting LightFTP in Version 2.2 (the latest one on github at the time). I ended up with a file-read vulnerability that allowed to read the...

By xctCTF, Fuzzingcustom exploitation, ftp, linux
Read more...
07JanJanuary 7, 2023

VL Shinra Part 1 – SQLi, Command Injection & Hash Cracking

xct2023-01-18T17:07:44+00:00

This is the first video of a series about Shinra, a virtual company in a private red team lab. We will conduct a full pentest on Shinra and explore various topics along the way.

By xctVulnlabcommand injection, linux, password cracking, sql injection
Read more...
03NovNovember 3, 2022

Ekoparty 2022 BFS Windows Challenge

xct2022-11-07T20:24:46+00:00

In this blog post, we will solve the Windows userland challenge that Blue Frost Security published for Ekoparty 2022.

By xctCTF, Windows Userland Exploitationbinary exploitation, windows
Read more...
12…22Next  
Support me on Patreon!

Categories

  • Browser Exploitation (1)
  • CTF (110)
  • Fuzzing (4)
  • Misc (2)
  • Tools (1)
  • Vulnerability (2)
  • Vulnlab (8)
  • Windows Kernel Exploitation (5)
  • Windows Userland Exploitation (3)

Latest Posts

VL Shinra Part 4 – Reverse Engineering, Binary Exploitation & Ansible
January 28, 2023
VL Shinra Part 3 – Initial Payload Design, Host Enumeration & getting SYSTEM
January 18, 2023
VL Shinra Part 2 – Enumerate, Enumerate, Enumerate!
January 10, 2023
Real World CTF 2023 – NonHeavyFTP
January 8, 2023
VL Shinra Part 1 – SQLi, Command Injection & Hash Cracking
January 7, 2023
Ekoparty 2022 BFS Windows Challenge
November 3, 2022

Tags

active directory arbitrary file write binary exploitation command injection crypto cve dcsync deserialization docker dynamorio electron ftp gitlab hackthebox heap java kernel exploit laps ldap lfi linux metasploit node openbsd password cracking password spraying path hijacking pg practice phishing php privileges registry responder reversing rop seimpersonate smb sql injection sticky notes sudo tryhackme vulnlab web windows xss

Contact

  • Email: xct@vulndev.io

Follow

Twitter Youtube Linkedin
© Copyright 2022. All Rights Reserved.