RGROSEC
open-menucloseme
Home
About me
github linkedin
  • Hack The Box - Timing Walkthrough

    calendar Jun 4, 2022 · 11 min read · Hack the Box Linux  ·
    Share on: twitter facebook linkedin copy
    Hack The Box - Timing Walkthrough

    Today we will be taking a look at Timing from Hack the Box. Timing is considered to be of medium difficulty, and requires the usage of a local file inclusion to eventually find credentials for the box. We then find an application that we can run with sudo permissions, and misuse it to gain root access. Foothold Let's …


    Read More
  • Hack The Box - Unicode Walkthrough

    calendar May 7, 2022 · 8 min read · Hack the Box Linux  ·
    Share on: twitter facebook linkedin copy
    Hack The Box - Unicode Walkthrough

    Hello everyone, today we are going to take a look at Unicode from Hack The Box. Unicode is a medium box that involves JWT manipulation, local file inclusion and a custom made application that can be used to access the root flag. Foothold As usual, we start off with an nmap scan to enumerate all ports, services and …


    Read More
  • Hack The Box - Shibboleth Walkthrough

    calendar Mar 31, 2022 · 7 min read · Hack the Box Linux  ·
    Share on: twitter facebook linkedin copy
    Hack The Box - Shibboleth Walkthrough

    Today we will be taking a look at "Shibboleth" from Hack the Box. To get get a foothold onto the box we first exploit the vulnerable-by-design IPMI protocol to obtain an administrator hash for Zabbix, and crack it. Through Zabbix we can execute local commands and obtain a shell. We can then use a recent …


    Read More
  • Hack The Box - Backdoor Walkthrough

    calendar Mar 29, 2022 · 3 min read · Hack the Box Linux  ·
    Share on: twitter facebook linkedin copy
    Hack The Box - Backdoor Walkthrough

    Welcome to my walkthrough for the "Backdoor" machine from Hack The Box. Backdoor is considered to be an easy box. We get a foothold onto the box through the exploitation of a vulnerable web service running at an unusual port. We can then escalate privileges through a screen session that was still open, which …


    Read More
  • Linux Privilege Escalation Techniques

    calendar Feb 17, 2022 · 10 min read · Privilege Escalation Linux  ·
    Share on: twitter facebook linkedin copy
    Linux Privilege Escalation Techniques

    This post is based on the notes and cheatsheets I wrote while studying for the Offensive Security Certified Professional (OSCP) exam, and can be used as a brief reference while looking for basic Linux privilege escalation methods. The contents of this blog originate from the "Linux Privilege Escalation for OSCP …


    Read More
    • ««
    • «
    • 1
    • 2
    • 3
    • »
    • »»

Ruben Groenewoud

Security researcher at Elastic, writing about detection engineering, Linux security, and offensive security.
Read More

Featured Posts

  • Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild
  • Hooked on Linux: Rootkit Detection Engineering
  • Illuminating VoidLink: Technical analysis of the VoidLink rootkit framework
  • Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenario
  • Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)
  • Hooked on Linux: Rootkit Taxonomy, Hooking Techniques and Tradecraft
  • Outlaw Linux Malware: Persistent, Unsophisticated, and Surprisingly Effective
  • Linux Detection Engineering - The Grand Finale on Linux Persistence Mechanisms

Recent Posts

  • Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild
  • Hooked on Linux: Rootkit Detection Engineering
  • Illuminating VoidLink: Technical analysis of the VoidLink rootkit framework
  • Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenario
  • Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)
  • Hooked on Linux: Rootkit Taxonomy, Hooking Techniques and Tradecraft
  • Outlaw Linux Malware: Persistent, Unsophisticated, and Surprisingly Effective
  • Linux Detection Engineering - The Grand Finale on Linux Persistence Mechanisms

Categories

ELASTIC 18 DETECTION ENGINEERING 12 LINUX 12 MALWARE ANALYSIS 7 WALKTHROUGHS 7 PERSISTENCE 5 WEB APPLICATION HACKING 4 BINARY EXPLOITATION 2 PRIVILEGE ESCALATION 2 CVE 1

Tags

LINUX 25 ELASTIC 18 DETECTION ENGINEERING 12 HACK THE BOX 7 MALWARE ANALYSIS 7 HUNTING 5 PERSISTENCE 5 OWASP 4 WEBAPP 4 WINDOWS 4 BUFFER OVERFLOW 2 CONTAINERS 2 PRIVILEGE ESCALATION 2 ROOTKIT 2
All Tags
AUDITD1 BUFFER OVERFLOW2 CONTAINERS2 CVE1 DETECTION ENGINEERING12 ELASTIC18 HACK THE BOX7 HUNTING5 LINUX25 MALWARE ANALYSIS7 OWASP4 PERSISTENCE5 PRIVILEGE ESCALATION2 ROOTKIT2 WEBAPP4 WINDOWS4
[A~Z][0~9]
RGROSEC

Copyright  RGROSEC. All Rights Reserved

to-top