TryHackMe Labs

Wonderlandchevron-rightGhostcatchevron-rightOverPass3chevron-rightJokerchevron-rightWekor (Manual SQLi + memcache and python privesc)chevron-rightVulnnet (LFI of apache config file)chevron-rightOverPass (session Cookie bypass + /etc/hosts bash script privesc)chevron-rightArchangel (LFI with php filters + log poisoning)chevron-rightMustacchio (XXE Vulnerability + tail privesc)chevron-rightInferno (OSCP practice + tee privesc)chevron-rightJurrasic (SQL Injection)chevron-rightGlitch (ffuf POST request and firefox decrypt)chevron-rightCatPictures (Port Knocking and Docker Escape)chevron-rightHackerVsHacker (File upload bypass + process privesc)chevron-rightDear QA (Linux Binary Overflow)chevron-rightMindgames (RCE Brainfuck+Python + cap_setuid of openssl privesc)chevron-rightBiblioteca (SQLi + python library hijacking)chevron-rightPeak Hill (Python Pickles + decompyle .pyc + sourpickles)chevron-rightWWBuddy (SQLi new way + php cmd injection + USER env var privesc)chevron-righttoc2 (cms made simple 2.1.6 exploit + linux .c program race condition)chevron-rightVulnNet Active (Windows Redis + SMB scheduled job + SharpGPOAbuse)chevron-rightMadeye's castle (SQLite Injection + binary exploitation for privesc)chevron-rightGhizer (Wordpress+LimeSurvey + chisel ghidra port for RCE + .py privesc)chevron-rightContainMe (html path command injection + SUID privesc+lateral to container with ssh + mysql privesc)chevron-rightSafeZonechevron-rightVulnNet-Internal (SMB/NFS/Rsync exploit + TeamCity Privesc)chevron-rightVulnnet-Roasted (AS-REP Roasting + secretdump)chevron-rightVulnNet: Node (Node.js deserialization + /npm privesc and services privesc)chevron-rightEnterprise (Domain-Admin to RDP Users + PowerUp privesc)chevron-rightFusion Corp (Get-NPUsers + rcpclient + SeBackupPrivilege privesc)chevron-rightSet (users.xml + bruteforce SMB + plink + custom msfvenom module)chevron-rightYear of the Owl (SNMP + onesixtyone + snmpwalk + crackmapexec + RecycleBin + pwdump.py)chevron-rightRevenge (SQLi + sudoedit .service config)chevron-rightOpacity (RFI nullbyte bypass + .kdbx hash crack + pspy64 backup process LPE)chevron-rightIntranetchevron-right

Last updated