Search
Methodology
Penetration Tests
Web Apps & APIs
Cloud
Mobile Apps
Desktop Apps
Wireless / Wifi
Social Engineering
Capture the Flag
Physical
Blue Team
Purple Team
Red Team
Evasion & Bypass
Cheat Sheets
All Cheat Sheets
Databases
Languages & Formats
Operating Systems
Ports & Protocols
Security Controls
Tools
Walk-Through
Cybereco
Hack the Box (HTB)
Hackfest & iHack
NorthSec
Metasploitable2
SANS Holiday Hack
Vulnhub
WebSecurity Academy
(Hackerone)
(Mossé)
(Root Me)
(TryHackMe)
Blog
About
GitHub
LinkedIn
Category:
Exploits & Vulns
jQuery XSS (CVE-2015-9251)
UAC Bypass – EventVwr
Samba RCE (CVE-2008-4250 / MS08-067)
Reusing Sudo Tokens
Polkit’s pkexec utility exploit (CVE-2021-4034)
DirtyCow (CVE-2016-5195)
AS-REP Roasting
Zerologon (CVE-2020-1472)
Escape restricted shells
EternalBlue (CVE-2017-0144 / MS17-010)
EternalRed / SambaCry (CVE-2017-7494)
PrintSpoofer
RottenPotatoNG
Juicy Potato
RCE in log4j – CVE-2021-44228
Kerberoasting
Windows Unquoted Service Path
HTML Applications (HTA)
Bypass Antivirus & Endpoint Detection and Response (EDR)
Microsoft Office Macros
Dependency confusion
Bypass web filtering
HTTP Response Splitting / Web Cache Poisoning
Incubated vulnerability
IMAP / SMTP Injection
Exploit 47995: Sudo 1.8.25p – Buffer Overflow (CVE-2019-18634)
Exploit 45233: OpenSSH 2.3 < 7.7 - Username Enumeration (CVE-2018-15473)
Cisco ASA firewall: Cisco CLI “jail break” (CVE-2014-3390)