Lisandre
  • Methodology
    • Penetration Tests
    • Web Apps & APIs
    • Cloud
    • Mobile Apps
    • Desktop Apps
    • Wireless / Wifi
    • Social Engineering
    • Capture the Flag
    • Physical
    • Blue Team
    • Purple Team
    • Red Team
    • Evasion & Bypass
    • Artificial Intelligence
  • Cheat Sheets
    • All Cheat Sheets
    • Databases
    • Languages & Formats
    • Operating Systems
    • Ports & Protocols
    • Security Controls
    • Tools
  • Walk-Through
    • Cybereco
    • HackAPrompt
    • Hack the Box (HTB)
    • Hackfest & iHack
    • NorthSec
    • Metasploitable2
    • SANS Holiday Hack
    • Vulnhub
    • WebSecurity Academy
    • (Hackerone)
    • (Mossé)
    • (Root Me)
    • (TryHackMe)
  • Blog
  • About
    • GitHub
    • LinkedIn

Vulnerabilities

List of vulnerabilities with PoC.

  • jQuery XSS (CVE-2015-9251)
  • RCE in Log4j (CVE-2021-44228)
  • Sudo 1.8.25p – Buffer Overflow (CVE-2019-18634)
  • OpenSSH 2.3 < 7.7 – Username Enumeration (CVE-2018-15473)
  • Cisco ASA firewall: Cisco CLI “jail break” (CVE-2014-3390)
  • Oracle E-Business Suite SSRF, CRLF (CVE-2025-61882)
  • Progress MoveIT Transfer SFTP Authentication Bypass (CVE-2024-5806)
  • React2Shell (CVE-2025-55182)
  • AnyDesk – port 7070 (TCP) / 50001 (UDP) – (RCE CVE-2020-13160, unquoted service path)
  • Exploit 47930: Citrixmash (CVE-2019-19781), see Citrix
  • CVE-2021-41773 (Apache HTTP Server 2.4.49 only), see Apache Web Server
  • Shellshock (CVE-2014-6271), see Perl Cheat Sheet
  • AS-REP Roasting
  • Escape restricted shells

Active Directory

  • Zerologon (CVE-2020-1472)
  • PetitPotam NTLM Relay

Samba

  • Samba RCE (CVE-2008-4250 / MS08-067)
  • EternalBlue (CVE-2017-0144 / MS17-010)
  • EternalRed / SambaCry (CVE-2017-7494)

UNIX Privilege Escalation

  • DirtyCow (CVE-2016-5195)
  • Polkit’s pkexec utility exploit (CVE-2021-4034)
  • Reusing Sudo Tokens

Windows Privilege Escalation

  • PrintSpoofer
  • RottenPotatoNG
  • Juicy Potato
  • Windows Unquoted Service Path
  • UAC Bypass – EventVwr

Post Categories

Favorite links

  • Bypassing URL/Domain/IP
  • Scripts & Files
  • Data Exfiltration
  • File Transfer
  • Missing Security Controls Calculator
  • Password Attacks
  • Privesc: Unix | Windows
  • Post-Exploit: Unix | Windows
  • OS: Unix | Windows

External Tools & Resources

  • AsciiFlow
  • CSbyGB
  • CVSS Calculator: FIRST | NVD
  • CyberChef
  • European Vulnerability Database (EUVD)
  • Exploit Database
  • HackTricks
  • HighOn.Coffee
  • ipify API (My IP address, text format)
  • Is this a public IP?
  • OWASP Testing Guide
  • Search Vulnerability Database (NVD)
  • SecLists
  • TunnelsUp
  • Webhook.site
  • Wikimandine

Infosec News

  • The Hacker News
  • Krebs on Security
  • SC Magazine
  • Infosec Reactions
  • Cyber Security Hub
Lisandre

Lisandre.com contains notes on the steps and tools used during pentesting, cheat sheets for quick reference on tools, languages, operating systems, ports, and walk-through guides of Capture the Flag (CTF) challenges.

  • Privacy Policy
  • Sitemap