Capture the Flag

Machines & Write-ups

Twenty-six TryHackMe machines worked end to end, from web footholds and privilege escalation to Active Directory and crypto.

TryHackMe — 0xb0rn3 Live profile, badges, and completion stats. View profile ↗
26 machines
EasyTryHackMe Pickle Rick Web enumeration and command injection on a Rick and Morty themed challenge. EasyTryHackMe Agent Sudo Steganography chain and CVE-2019-14287, a sudo privilege bypass without a password. EasyTryHackMe Bounty Hacker FTP enumeration, SSH brute-force, and a classic sudo privilege escalation. EasyTryHackMe Simple CTF SQL injection for initial access, followed by sudo abuse for root. EasyTryHackMe Sticker Shop Stored XSS exploitation to exfiltrate session data and capture the flag. EasyTryHackMe Hidden Deep Into My Heart Web enumeration and directory brute-forcing to uncover hidden flags. EasyTryHackMe W1seGuy XOR cipher analysis and key recovery through frequency analysis. MediumTryHackMe 0Day Custom exploit development chain targeting a vulnerable web service for RCE. MediumTryHackMe Attacktive Directory Active Directory enumeration, Kerberoasting, and full domain compromise. MediumTryHackMe Biohazard Multi-stage challenge: web enumeration, steganography, and encoding chains. MediumTryHackMe Cheese Web application exploitation and post-exploitation privilege escalation. MediumTryHackMe Chill Hack Web foothold via command injection, then Docker container escape to root. MediumTryHackMe Crypto Failures Exploiting weak cryptography in a web application to gain unauthorized access. MediumTryHackMe Dogcat PHP LFI vulnerability escalated to RCE via Apache log poisoning. MediumTryHackMe Ghizer Multi-vulnerability chain from web foothold through to root escalation. MediumTryHackMe Rabbit Store SSRF, JWT manipulation, and privilege escalation chained for full root compromise. MediumTryHackMe Relevant Windows SMB enumeration and token impersonation for privilege escalation. MediumTryHackMe Rootme Web shell upload to initial access, then SUID binary abuse for root. MediumTryHackMe Silver Platter Service enumeration leads to credential exposure and a clear path to root. MediumTryHackMe UltraTech API command injection followed by Docker socket abuse for container escape. MediumTryHackMe VulnNet: Internal Internal service enumeration across NFS, Redis, and SMB to full compromise. MediumTryHackMe Wgel CTF WordPress enumeration leads to SSH key exposure, then sudo privilege escalation. MediumTryHackMe Wonderland Alice in Wonderland themed privilege escalation chain involving PATH hijacking. MediumTryHackMe Year of the Pig Custom web application exploitation chained with Linux privilege escalation. HardTryHackMe Daily Bugle Joomla 3.7.0 CVE-2017-8917 unauthenticated SQLi, bcrypt cracking, and GTFObins yum privilege escalation on CentOS 7. InsaneTryHackMe Snowy Armageddon Advent of Cyber 2023 side quest, an extended multi-stage challenge chain.