Challenge-1 Blemflarck The Galactic Federation is taking control over the universe using a group of superheroes. The world’s redemption is in your hands. Enter the intergalactic portal and sabotag...
Sep 12 2022-09-12T18:00:00+05:30
Recently, I stumbled on an initiative “The Auror Project” by Sudarshan Pisupati which was starting a course called “3 Machine Labs”. “3 Machine Labs” is a challenge based learning approach to soli...
Jun 30 2022-06-30T13:13:13+05:30
Vault is medium to hard difficulty machine, which requires bypassing host and file upload restrictions, tunneling, creating malicious OpenVPN configuration files and PGP decryption. Reconnaissance ...
Sep 9, 2021 2021-09-09T19:35:00+05:30
Knife is an easy difficulty Linux machine that features an application which is running on a backdoored version of PHP: PHP/8.1.0-dev. This vulnerability is leveraged to obtain the foothold on the...
Aug 29, 2021 2021-08-29T13:55:00+05:30
Ypuffy is medium difficulty machine which highlights the danger of allowing LDAP null sessions. It also features an interesting SSH CA authentication privilege escalation, via the OpenBSD doas com...
Aug 21, 2021 2021-08-21T14:40:00+05:30
Giddy is a super cool box which gives real-life experience by Bypassing Windows Defender, Applock and Constrained Language Mode. It starts with enumeration leading to a site which is vulnerable to ...
Aug 17, 2021 2021-08-17T12:50:00+05:30
Love is an easy box, Awesome for beginners. Starts with a SSRF to access a forbidden page meant to be accessed locally which leaks credentials for a Voting system. That voting system allows anyone ...
Aug 17, 2021 2021-08-17T01:25:00+05:30
Foothold starts with Wordpress plugin gwolle-gb which is vulnerable to Remote File-Inclusion. You can get user by exploiting sudo privileges on tar, then grabbing MySQL DB password from web-root an...
Aug 10, 2021 2021-08-10T11:20:00+05:30
Olympus is CTF-like box. Starting with exploting X-Debug plugin in Apache with just HTTP Headers which gives you a container shell. You pivot to other containers while exploring techniques like 802...
Aug 6, 2021 2021-08-06T13:30:00+05:30
Stratosphere is a pretty cool box with an Apache Struts vulnerability in which endpoints ending with .action, .go, .do can be injected with a specially crafted Content-Header leading to Remote code...
Aug 5, 2021 2021-08-05T16:05:00+05:30