Writeups
9 writeups from self-directed lab work, plus one appendix kept with the writeup they belong to. Difficulty and vulnerability class are taken straight from the front matter of each file.
- 01
Beach Bar — PyYAML Deserialization RCE and Root Privilege Escalation via Process Arguments
Unsafe Deserialization (PyYAML RCE), Default Credentials, Credential Exposure in Process Arguments, Password Reuse, Privilege Escalation
- 02
Complimentary — Overprivileged Cognito unauthenticated role with dynamodb:Scan
AWS Cognito identity pool misconfiguration, IAM overprivileged role, DynamoDB Scan exposure, NoSQL data exfiltration
- 03
CryptoCabana — Azure Blob SAS token abuse to Key Vault secret rotation
exposed cloud credentials, Azure Blob Storage SAS token, service principal abuse, Azure Key Vault, secret rotation
- 04
Do Not Disturb — NoSQL login bypass to EJS RCE and a loopback Node Inspector pivot
NoSQL Injection, Server-Side Template Injection, Remote Code Execution, Privilege Escalation
- 05
Overheard at Breakfast — OSINT Email-to-Hash Mapping Against Gravatar's Public API
OSINT, Social Media Analysis, Email Hashing (MD5), Third-Party Profile Enumeration, Base64 Decoding
- 06
Packed Light — PCAP analysis of a cookie-based covert exfiltration channel
network forensics, PCAP analysis, covert channel / data exfiltration, XOR encryption, Base64 encoding, weak cryptographic key handling
- 07
Room 404 — Git Repository Exposure via an Unprotected .git Directory
Information Disclosure, Exposed Version Control Directory (.git), Directory Enumeration with ffuf
- 08
SQL Injection (THM) — four oracles, one endpoint
SQL Injection, UNION-based, Authentication Bypass, Boolean Blind, Time-based Blind
- 09
XSS Introduction — Reflected, Stored, DOM and Blind Cross-Site Scripting
Cross-Site Scripting (Reflected, Stored, DOM-based, Blind), Insufficient Output Encoding, Inadequate Input Validation, Missing Content Security Policy