Knowledge Hub
Web Exploitation Labs
Available entries
-
Advent of Cyber 3 (2021)
TryHackMe room
-
NahamStore
----- In this room you will learn the basics of bug bounty hunting and web application hacking ---...
-
Tech_Supp0rt: 1
--- Hack into the scammer's under-development website to foil their plans. --- , Remote File Inclusion (RFI), and...
-
Game Zone
--- Learn to hack into this machine. Understand how to use SQLMap, crack some passwords, reveal services using a reverse SSH tunnel and...
-
Holo
--- Holo is an Active Directory (AD) and Web-App attack lab that aims to teach core web attack vectors and more advanced AD attack...
-
OWASP Broken Access Control
---- Exploit Broken Access Control: Number 1 of the Top 10 web security risks. ----...
-
PC
``` ┌──(witty㉿kali)-[~/Downloads] └─$ rustscan -a 10.10.11.214 --ulimit 5500 -b 65535 -- -A -Pn .----. .-. .-. .----..---. .----. .---....
-
PC
``` ┌──(witty㉿kali)-[~/Downloads] └─$ rustscan -a 10.10.11.214 --ulimit 5500 -b 65535 -- -A -Pn .----. .-. .-. .----..---. .----. .---....
-
Responder
``` blob:https://app.hackthebox.com/207ef7e2-d519-4814-8616-c6679d11f80a ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.129.89.108 PING...
-
Responder
``` blob:https://app.hackthebox.com/207ef7e2-d519-4814-8616-c6679d11f80a ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.129.89.108 PING...
-
Revenge
---- You've been hired by Billy Joel to get revenge on Ducky Inc...the company that fired him. Can you break into the server and...
-
Road
--- Inspired by a real-world pentesting engagement ---  competition by Splunk. ---...
-
Takedown
---- We have reason to believe a corporate webserver has been compromised by RISOTTO GROUP. Cyber interdiction is authorized for this...
-
25 Days of Cyber Security
TryHackMe room
-
Advent of Cyber 2 [2020]
TryHackMe room
-
Basic Static Analysis
---- Learn basic malware analysis techniques without running the malware. --- ### Introduction In the previous rooms of this module, we...
-
Brute Force Heroes
--- Walkthrough room to look at the different tools that can be used when brute forcing, as well as the different situations that might...
-
Burp Suite Extender
--- Learn how to use Extender to broaden the functionality of Burp Suite --- ### Outline Welcome to the Burp Suite Extender room! This...
-
Burp Suite: Intruder
--- Learn how to use Intruder to automate requests in Burp Suite --- ### Room Outline In previous rooms of this module, we have covered...
-
Capture!
---- Can you bypass the login form? ----  ### Objectives...
-
HackPark
--- Bruteforce a websites login with Hydra, identify and use a public exploit then escalate your privileges on this Windows machine! ---...
-
HeartBleed
--- SSL issues are still lurking in the wild. Can you exploit this web servers OpenSSL? ---...
-
IDOR
--- Learn how to find and exploit IDOR vulnerabilities in a web application giving you access to data that you shouldn't have. --- ###...
-
Ignite
--- A new start-up has a few issues with their web server. --- ...
-
Kubernetes for Everyone
--- A Kubernetes hacking challenge for DevOps/SRE enthusiasts. --- ...
-
New Hire Old Artifacts
---- Investigate the intrusion attack using Splunk. ---- ...
-
NoSQL injection Basics
--- A walkthrough depicting basic NoSQL injections on MongoDB. --- ...
-
Olympus
---- My first CTF ! ----  -[~/hackthebox] └─$ rustscan -a 10.129.95.191...
-
Oopsie
``` blob:https://app.hackthebox.com/40488db7-9438-4437-8c1a-5e50b5bc5bc3 ┌──(kali㉿kali)-[~/hackthebox] └─$ rustscan -a 10.129.95.191...
-
Outlook NTLM Leak
---- Leak password hashes from a user by sending them an email by abusing CVE-2023-23397. ---...
-
OWASP API Security Top 10 - 1
--- Learn the basic concepts for secure API development (Part 1). --- ...
-
OWASP Top 10 - 2021
---- Learn about and exploit each of the OWASP Top 10 vulnerabilities; the 10 most critical web security risks. ---...
-
Pilgrimage
``` ┌──(witty㉿kali)-[~/Downloads] └─$ tac /etc/hosts 10.10.11.219 pilgrimage.htb ┌──(witty㉿kali)-[~/Downloads] └─$ dirsearch -u...
-
Pilgrimage
``` ┌──(witty㉿kali)-[~/Downloads] └─$ tac /etc/hosts 10.10.11.219 pilgrimage.htb ┌──(witty㉿kali)-[~/Downloads] └─$ dirsearch -u...
-
Sea Surfer
---- Ride the Wave! ----   competition by Splunk. ---...
-
SQHell
---- Try and find all the flags in the SQL Injections ----  ###...
-
SSRF
--- Learn how to exploit Server-Side Request Forgery (SSRF) vulnerabilities, allowing you to access internal server resources. --- ###...
-
Surfer
---- Surf some internal webpages to find the flag! ----  --- -[~] └─$ ping 10.129.221.123 PING 10.129.221.123...
-
Appointment
``` blob:https://app.hackthebox.com/5be081bc-9048-421a-a11f-090c3e6d5944 ┌──(kali㉿kali)-[~] └─$ ping 10.129.221.123 PING 10.129.221.123...
-
Archangel
--- Boot2root, Web exploitation, Privilege escalation, LFI ---  ###...
-
Burp Suite: The Basics
TryHackMe room
-
Careers in Cyber
--- Learn about the different careers in cyber security. --- ...
-
CCT2019
---- Legacy challenges from the US Navy Cyber Competition Team 2019 Assessment sponsored by US TENTH Fleet ---...
-
CMSpit
---- This is a machine that allows you to practise web app hacking and privilege escalation using recent vulnerabilities. ----...
-
Command Injection
--- Learn about a vulnerability allowing you to execute commands through a vulnerable app, and its remediations. --- ### Introduction...
-
Conti
---- An Exchange server was compromised with ransomware. Use Splunk to investigate how the attackers compromised the server. ----...
-
ConvertMyVideo
---- My Script to convert videos to MP3 is super secure ----  ### Task 1 Hack the machine Start...
-
Corridor
--- Can you escape the Corridor? --- ...
-
CVE-2022-26923
---- Walkthrough on the exploitation of CVE-2022-26923, a vulnerability in AD Certificate Services. ---...
-
Cyber Kill Chain
--- The Cyber Kill Chain framework is designed for identification and prevention of the network intrusions. You will learn what the...
-
Cyber Scotland 2021
---- Follow along tutorials for Scottish Cyberweek Demos --- ### -[~] └─$ sudo nmap -sC -sV...
-
ExfilNode
TryHackMe room
-
Firewalls
--- Learn about and experiment with various firewall evasion techniques, such as port hopping and port tunneling. ---...
-
GamingServer
--- An Easy Boot2Root box for beginners ---  ###...
-
GLITCH
--- Challenge showcasing a web app and simple privilege escalation. Can you find the glitch? ---...
-
Grep
---- A challenge that tests your reconnaissance and OSINT skills. ----  ### Introduction Start...
-
Internal
--- Penetration Testing Challenge --- ...
-
Intro to Containerisation
--- Learn about the technologies and benefits of containerisation. ---  and experience an ethical hacker's job. ---...
-
Intro to Threat Emulation
---- A look into threat emulation practices as a means of cyber security assessment. ----...
-
Introduction to Cryptography
---- Learn about encryption algorithms such as AES, Diffie-Hellman key exchange, hashing, PKI, and TLS. ---...
-
Introduction to Flask
--- How it works and how can I exploit it? --- ...
-
Introduction to SIEM
--- An introduction to Security Information and Event Management. ---  for collecting and processing forensic artifacts ---...
-
Lesson Learned?
---- Have you learned your lesson? ---- ...
-
Linux Forensics
--- Learn about the common forensic artifacts found in the file system of Linux Operating System ---...
-
Linux Modules
TryHackMe room
-
Linux: Local Enumeration
--- Learn to efficiently enumerate a linux machine and identify possible weaknesses ---...
-
Living Off the Land
--- Learn the essential concept of "Living Off the Land" in Red Team engagements. ---...
-
Logless Hunt
TryHackMe room
-
Lookback
---- You’ve been asked to run a vulnerability test on a production environment. ---...
-
Lumberjack Turtle
---- No logs, no crime... so says the lumberjack. ---- ...
-
MAL: Strings
--- Investigating "strings" within an application and why these values are important! ---...
-
Metasploit
--- Learn to use Metasploit, a tool to probe and exploit vulnerabilities on networks and servers. ---...
-
Microsoft Windows Hardening
--- To learn key attack vectors used by hackers and how to protect yourself using different hardening techniques. ---...
-
Network Security
--- Learn about network security, understand attack methodology, and practice hacking into a target server. --- ### Introduction A...
-
Network Security Solutions
--- Learn about and experiment with various IDS/IPS evasion techniques, such as protocol and payload manipulation. ---...
-
NetworkMiner
--- Learn how to use NetworkMiner to analyse recorded traffic files and practice network forensics activities. --- ### Room Introduction...
-
Nmap Basic Port Scans
--- Learn in-depth how nmap TCP connect scan, TCP SYN port scan, and UDP port scan work. ---...
-
NoNameCTF
--- Buffer overflow, server-side template injection and more... --- ...
-
Obfuscation Principles
--- Leverage tool-agnostic software obfuscation practices to hide malicious functions and create unique code. ---...
-
Operating System Security
--- This room introduces users to operating system security and demonstrates SSH authentication on Linux. --- ### Introduction to...
-
Osiris
--- Can you Quack it? ---  ### Osiris...
-
Overpass3
``` Initial foothold ***enumerating ports with rustscan*** port 80 open Enumerating with gobuster allows to discover a hidden /backups...
-
OWASP API Security Top 10 - 2
--- Learn the basic concepts for secure API development (Part 2). --- ...
-
OWASP Top 10
TryHackMe room
-
ParrotPost: Phishing Analysis
---- Reveal how attackers can craft client-side credential-stealing webpages that evade detection by security tools. ----...
-
Password Attacks
--- This room introduces the fundamental techniques to perform a successful password attack against various services and scenarios. ---...
-
Phishing
--- Learn what phishing is and why it's important to a red team engagement. You will set up phishing infrastructure, write a convincing...
-
Phishing Emails 3
--- Learn the tools used to aid an analyst to investigate suspicious emails. --- %27%3E By using "username: *" and...
-
Phonebook
``` http://143.110.169.131:32061/login?message=%3Cimg%20src%20=%27x%27%20onerror=%20%27alert(1)%27%3E By using "username: *" and...
-
Plotted-TMS
--- Everything here is plotted! --- ...
-
Protocols and Servers
--- Learn about common protocols such as HTTP, FTP, POP3, SMTP and IMAP, along with related insecurities. --- ### Introduction This room...
-
Protocols and Servers 2
--- Learn about attacks against passwords and cleartext traffic; explore options for mitigation via SSH and SSL/TLS. ---...
-
Pyramid Of Pain
--- Learn what is the Pyramid of Pain and how to utilize this model to determine the level of difficulty it will cause for an adversary...
-
Red Team OPSEC
--- Learn how to apply Operations Security (OPSEC) process for Red Teams. --- -[~/hackthebox] └─$ ping 10.10.11.170 PING 10.10.11.170 (10.10.11.170) 56(84) bytes of data. 64 bytes from...
-
RedPanda
``` ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.10.11.170 PING 10.10.11.170 (10.10.11.170) 56(84) bytes of data. 64 bytes from...
-
Relevant
--- Penetration Testing Challenge --- ...
-
REMnux: Getting Started
TryHackMe room
-
Retro
--- New high score! ---  : its responsibilities, services, and data sources. --- ### Introduction to Security...
-
Security Principles
--- Learn about the security triad and common security models and principles. ---...
-
Set
--- Once again you find yourself on the internal network of the Windcorp Corporation. --- ### Set ...
-
Shoppy
``` ┌──(kali㉿kali)-[~/Downloads] └─$ sudo openvpn lab_wittyAle.ovpn ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.10.11.180 PING...
-
Shoppy
``` ┌──(kali㉿kali)-[~/Downloads] └─$ sudo openvpn lab_wittyAle.ovpn ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.10.11.180 PING...
-
Sigma
--- Provide understanding to Sigma, a Generic Signature Format for SIEM Systems. ---...
-
Snapped Phishing Line
---- Apply learned skills to probe malicious emails and URLs, exposing a vast phishing campaign. ----...
-
Snort Challenge - Live Attacks
--- Put your snort skills into practice and defend against a live attack --- ### Scenario 1 | Brute-Force Use the attached VM to finish...
-
Source
--- Exploit a recent vulnerability and hack Webmin, a web-based system configuration tool. --- ### rustscan > 10000/tcp open http...
-
Splunk 101
--- This room will cover the basics of Splunk. --- ...
-
Splunk: Basics
--- Learn the basics of Splunk. ---  ###...
-
Spring4Shell
--- This room will provide an overview of the Spring4Shell RCE vulnerability in Spring Core, as well as give you an opportunity to...
-
SQLMAP
--- Learn about and use Sqlmap to exploit the web application ---  Introduction...
-
Startup
--- Abuse traditional vulnerabilities via untraditional means. --- -[~/Downloads] └─$ rustscan -a 10.10.11.221 --ulimit 5500 -b 65535 -- -A -Pn .----....
-
TwoMillion
``` How many TCP ports are open? 2 ┌──(witty㉿kali)-[~/Downloads] └─$ rustscan -a 10.10.11.221 --ulimit 5500 -b 65535 -- -A -Pn .----....
-
Unattended
---- Use your Windows forensics knowledge to investigate an incident. ---- -[~/hackthebox] └─$ ping 10.129.247.247 PING...
-
Vaccine
``` blob:https://app.hackthebox.com/992bb2da-a712-4692-91e4-86edbc11e2d7 ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.129.247.247 PING...
-
Velociraptor
--- Learn Velociraptor, an advanced open-source endpoint monitoring, digital forensic and cyber response platform. ---...
-
Warzone 1
---- You received an IDS/IPS alert. Time to triage the alert to determine if its a true positive. ----...
-
Watcher
---- A boot2root Linux machine utilising web exploits along with some common privilege escalation techniques. ---...
-
Wazuh
--- Wazuh is a free, open source and enterprise-ready security monitoring solution for threat detection, integrity monitoring. ---...
-
Weaponization
--- Understand and explore common red teaming weaponization techniques. You will learn to build custom payloads using common methods...
-
Weather App
``` const weather = document.getElementById('weather'); const getWeather = async () => { let endpoint = 'api.openweathermap.org'; let...
-
Weather App
``` const weather = document.getElementById('weather'); const getWeather = async () => { let endpoint = 'api.openweathermap.org'; let...
-
Web Enumeration
--- Learn the methodology of enumerating websites by using tools such as Gobuster, Nikto and WPScan ---...
-
Wekor
---- CTF challenge involving Sqli , WordPress , vhost enumeration and recognizing internal services ;) ---...
-
Wgel CTF
--- Can you exfiltrate the root flag? --- ...
-
Year of the Pig
---- Some pigs do fly... ----  . ---...
-
Abusing Windows Internals
--- Leverage windows internals components to evade common detection solutions, using modern tool-agnostic approaches. ---...
-
Active Directory Basics(1)
### Introduction Microsoft's Active Directory is the backbone of the corporate world. It simplifies the management of devices and users...
-
Advanced SQL Injection
TryHackMe room
-
Alfred
--- Exploit Jenkins to gain an initial shell, then escalate your privileges by exploiting Windows authentication tokens. ---...
-
All in One
--- This is a fun box where you will get to exploit the system in several ways. Few intended and unintended paths to getting user and...
-
AllSignsPoint2Pwnage
--- A room that contains a rushed Windows based Digital Sign system. Can you breach it? ---...
-
Anonymous
--- Not the hacking group --- ...
-
APIWizards Breach
TryHackMe room
-
Aratus
---- Do you like reading? Do you like to go through tons of text? Aratus has what you need! ----...
-
AttackerKB
--- Learn how to leverage AttackerKB and learn about exploits in your workflow! --- > For our purposes, think of AttackerKB as similar...
-
Authentication Bypass
--- Learn how to defeat logins and other authentication mechanisms to allow you access to unpermitted areas. --- In this room, we will...
-
Autopsy
--- Learn how to use Autopsy to investigate artifacts from a disk image. Use your knowledge to investigate an employee who is being...
-
AWS API Gateway
TryHackMe room
-
b3dr0ck
--- Server trouble in Bedrock. --- ...
-
Badbyte
--- Infiltrate BadByte and help us to take over root. --- ### Reconnaissance  Nmap is a free open...
-
Bebop
--- Who thought making a flying shell was a good idea? ---  ###...
-
biteme
---- Stay out of my server! ---- -[~/Downloads/Blockchain] └─$ ftp 10.10.131.24 Connected to...
-
Blog
--- Billy Joel made a Wordpress blog! ---  ###...
-
Bolt
--- a hero is unleashed, This room is designed for users to get familiar with the Bolt CMS and how it can be exploited using...
-
Boogeyman 1
---- A new threat actor emerges from the wild using the name Boogeyman. Are you afraid of the Boogeyman? ---- ### [Introduction] New...
-
Bookstore
---- A Beginner level box with basic web enumeration and REST API Fuzzing. ----  ftp...
-
Brim
--- Learn and practice log investigation, pcap analysis and threat hunting with Brim. ---...
-
Brute
--- You as well, Brutus? --- ...
-
Burp Suite: Repeater
TryHackMe room
-
Bypass Really Simple Security
TryHackMe room
-
CALDERA
TryHackMe room
-
CAPA: The Basics
TryHackMe room
-
Carnage
TryHackMe room
-
Chocolate Factory
--- A Charlie And The Chocolate Factory themed room, revisit Willy Wonka's chocolate factory! --- ### rustscan > found port 21 ftp, port...
-
CMesS
---- Can you root this Gila CMS box? ---  ### Flags Start Machine Please add `MACHINE_IP cmess.thm`...
-
Common Linux Privesc
--- A room explaining common Linux privilege escalation --- ### Understanding Privesc What does "privilege escalation" mean? At it's...
-
Content Discovery
TryHackMe room
-
Core Windows Processes
--- Explore the core processes within a Windows operating system and understand what is normal behavior. This foundational knowledge...
-
Corp
--- Bypass Windows Applocker and escalate your privileges. You will learn about kerberoasting, evading AV, bypassing applocker and...
-
CORS & SOP
TryHackMe room
-
Couch
--- Hack into a vulnerable database server that collects and stores data in JSON-based document formats, in this semi-guided challenge....
-
Credentials Harvesting
--- Apply current authentication models employed in modern environments to a red team approach. ---...
-
Crocodile
``` blob:https://app.hackthebox.com/51f9dfe3-9c91-469a-8453-feab80baf3c3 ┌──(kali㉿kali)-[~] └─$ ping 10.129.165.101 PING 10.129.165.101...
-
Crocodile
``` blob:https://app.hackthebox.com/51f9dfe3-9c91-469a-8453-feab80baf3c3 ┌──(kali㉿kali)-[~] └─$ ping 10.129.165.101 PING 10.129.165.101...
-
Crylo
---- Learn about the CryptoJS library and JavaScript-based client-side encryption and decryption. ----...
-
CSRF
TryHackMe room
-
Custom Tooling Using Python
TryHackMe room
-
CVE-2019-18634
``` The stack is a very regimented section of memory which stores various important aspects of a program. The heap, on the other hand,...
-
CVE-2021-41773
``` A Brief History On the 5th of October 2021, a CVE detailing a path traversal attack on Apache HTTP Server v2.4.49 was released....
-
CVE-2023-38408
---- Learn how to move laterally abusing libraries' side effects in Ubuntu (CVE-2023-38408). ----...
-
CyberCrafted
---- Pwn this pay-to-win Minecraft server! --- ...
-
Daily Bugle
--- Compromise a Joomla CMS account via SQLi, practise cracking hashes and escalate your privileges by taking advantage of yum. ---...
-
DAST
TryHackMe room
-
Debug
---- Linux Machine CTF! You'll learn about enumeration, finding hidden password files and how to exploit php deserialization! ----...
-
Different CTF
---- interesting room, you can shoot the sun ---- ...
-
Digital Forensics Case B4DM755
---- Acquire the critical skills of evidence preservation, disk imaging, and artefact analysis for use in court. ----...
-
Dissecting PE Headers
---- Learn about Portable Executable files and how their headers work. ---- ...
-
Eavesdropper
--- Listen closely, you might hear a password! ---  ###...
-
Epoch
--- Be honest, you have always wanted an online tool that could help you convert UNIX dates and timestamps! ---...
-
Evading Logging and Monitoring
--- Learn how to bypass common logging and system monitoring, such as ETW, using modern tool-agnostic approaches. --- ![[Pasted image...
-
Extending Your Network
--- Learn about some of the technologies used to extend networks out onto the Internet and the motivations for this. --- ###...
-
Fawn
``` ┌──(kali㉿kali)-[~] └─$ ping 10.129.190.136 PING 10.129.190.136 (10.129.190.136) 56(84) bytes of data. 64 bytes from 10.129.190.136:...
-
Fawn
``` ┌──(kali㉿kali)-[~] └─$ ping 10.129.190.136 PING 10.129.190.136 (10.129.190.136) 56(84) bytes of data. 64 bytes from 10.129.190.136:...
-
Fowsniff CTF
--- Hack this machine and get the flag. There are lots of hints along the way and is perfect for beginners! ---...
-
Ghizer
---- lucrecia has installed multiple web applications on the server. ----  ### HA...
-
Hacked
``` It seems like our machine got hacked by an anonymous threat actor. However, we are lucky to have a .pcap file from the attack. Can...
-
Hardening Basics Part 1
--- Learn how to harden an Ubuntu Server! Covers a wide range of topics (Part 1) ---...
-
Hardening Basics Part 2
--- Continue learning about hardening --- ...
-
harder
---- Real pentest findings combined ---- ...
-
Hashing - Crypto 101
--- An introduction to Hashing, as part of a series on crypto --- ### Key Terms Before we start, we need to get some jargon out of the...
-
HaskHell
---- Teach your CS professor that his PhD isn't in security. ---- ...
-
HTTP Browser Desync
TryHackMe room
-
HTTP Request Smuggling
TryHackMe room
-
HTTP/2 Request Smuggling
TryHackMe room
-
IDE
--- An easy box to polish your enumeration skills! --- ...
-
John The Ripper
--- Learn how to use John the Ripper - An extremely powerful and adaptable hash cracking tool ---...
-
Joomify CVE-2023-23752
TryHackMe room
-
Juicy Details
TryHackMe room
-
Jurassic Park
--- A Jurassic Park CTF ---  ### Jurassic...
-
Keldagrim
--- The dwarves are hiding their gold! --- . ---...
-
Log Universe
TryHackMe room
-
Looking_Glass
``` Enumerating SSH When connecting to one of the ports (in this case trying one of the higher ones), the SSH server responds with...
-
Lunizz CTF
...
-
Madeye's Castle
---- A boot2root box that is modified from a box used in CuCTF by the team at Runcode.ninja ----...
-
magician
``` ┌──(kali㉿kali)-[~] └─$ sudo su [sudo] password for kali: ┌──(root㉿kali)-[/home/kali] └─# nano /etc/hosts ┌──(root㉿kali)-[/home/kali]...
-
Masterminds
---- Practice analyzing malicious traffic using Brim. ----  ### Task 1 Challenge Start...
-
Metasploit: Exploitation
--- Using Metasploit for scanning, vulnerability assessment and exploitation. ---...
-
Metasploit: Meterpreter
--- Take a deep dive into Meterpreter, and see how in-memory payloads can be used for post-exploitation. ---...
-
Mindgames
---- Just a terrible idea... ----   ### Task 1...
-
Mustacchio
--- Easy boot2root Machine ---  ``` ┌──(kali㉿kali)-[~/Downloads] └─$ rustscan -a 10.10.95.182...
-
Napping
--- Even Admins can fall asleep on the job --- ...
-
Neighbour
--- Check out our new cloud service, Authentication Anywhere. Can you find other user's secrets? ---...
-
Nessus
TryHackMe room
-
Net Sec Challenge
--- Practice the skills you have learned in the Network Security module. --- ### Introduction Use this challenge to test your mastery of...
-
Network Services
--- Learn about, then enumerate and exploit a variety of network services and misconfigurations. --- ### Understanding SMB **What is...
-
Network Services 2
--- Enumerating and Exploiting More Common Network Services & Misconfigurations --- ### Understanding NFS What is NFS? NFS stands for...
-
Networking Concepts
TryHackMe room
-
Networking Secure Protocols
TryHackMe room
-
Nmap Advanced Port Scans
--- Learn advanced techniques such as null, FIN, Xmas, and idle (zombie) scans, spoofing, in addition to FW and IDS evasion. ---...
-
Nmap Post Port Scans
--- Learn how to leverage Nmap for service and OS detection, use Nmap Scripting Engine (NSE), and save the results. ---...
-
Nmap: The Basics
TryHackMe room
-
OAuth Vulnerabilities
TryHackMe room
-
Oh My WebServer
--- Can you root me? ---  ###...
-
Ollie
--- Meet the world's most powerful hacker dog! ---  is an absolute fundamental model used...
-
Osquery: The Basics
--- Let's cover the basics of Osquery. --- -[~/Downloads/PHishing] └─$ wget http://0.0.0.0:8000/Email1.eml --2022-08-02 17:10:23-- http://0.0.0.0:8000/Email1.eml...
-
Polkit_CVE
``` What is the URL of the website you should submit dynamic flags to? https://flag.muir.land/ Overview In early 2021 a researcher named...
-
Polkit: CVE-2021-3560
TryHackMe room
-
PowerShell for Pentesters
--- This room covers the principle uses of PowerShell in Penetration Tests. Interacting with files, scanning the network and system...
-
PrintNightmare, again!
--- Search the artifacts on the endpoint to determine if the employee used any of the Windows Printer Spooler vulnerabilities to elevate...
-
Probe
TryHackMe room
-
Putting it all together
--- Learn how all the individual components of the web work together to bring you access to your favourite web sites. --- **Putting It...
-
pyLon
---- Can you penetrate the defenses and become root? ---- 
-
Recovery
---- Not your conventional CTF ----  ...
-
Search Skills
TryHackMe room
-
Secret Recipe
--- Perform Registry Forensics to Investigate a case. --- -[~] └─$ ping 10.129.71.100 PING 10.129.71.100...
-
Sequel
``` blob:https://app.hackthebox.com/75b7ab04-575b-4cf9-800c-bd03e22b0be6 ┌──(kali㉿kali)-[~] └─$ ping 10.129.71.100 PING 10.129.71.100...
-
Servidae: Log Analysis in ELK
TryHackMe room
-
Shells Overview
TryHackMe room
-
Shodan.io
TryHackMe room
-
Signature Evasion
--- Learn how to break signatures and evade common AV, using modern tool-agnostic approaches. ---...
-
Slingshot
TryHackMe room
-
Smag Grotto
--- Follow the yellow brick road. --- ...
-
Snort
--- Learn how to use Snort to detect real-time threats, analyse recorded traffic files and identify anomalies. ---...
-
Snort Challenge - The Basics
--- Put your snort skills into practice and write snort rules to analyse live capture network traffic. --- ### Introduction...
-
Snyk Code
TryHackMe room
-
SQLMap The Basics
TryHackMe room
-
Subdomain Enumeration
--- Learn the various ways of discovering subdomains to expand your attack surface of a target. --- Subdomain enumeration is the process...
-
TakeOver
--- This challenge revolves around subdomain enumeration. --- ...
-
The Impossible Challenge
--- Hmm ...
-
TheHive Project
--- Learn how to use TheHive, a Security Incident Response Platform, to report investigation findings ---...
-
Thompson
--- boot2root machine for FIT and bsides guatemala CTF --- -[~/Downloads] └─$ rustscan -a 10.10.11.217 --ulimit 5500 -b 65535 -- -A -Pn .----. .-. .-. .----..---. .----. .---....
-
Topology
``` ┌──(witty㉿kali)-[~/Downloads] └─$ rustscan -a 10.10.11.217 --ulimit 5500 -b 65535 -- -A -Pn .----. .-. .-. .----..---. .----. .---....
-
Tor
``` ***enumerating*** rustscan -a 10.10.9.58 --ulimit 5000 -b 65535 -- -A ***log ssh port 22*** via linux ssh thm@10.10.168.200 pass ->...
-
Training for New Analyst
--- Room for newbs ---  ### Log into VM...
-
Traverse
TryHackMe room
-
Valley
---- Can you find your way into the Valley? ----  ###...
-
Volt Typhoon
TryHackMe room
-
VulnNet: Internal
--- VulnNet Entertainment learns from its mistakes, and now they have something new for you... ---...
-
VulnNet: Node
--- After the previous breach, VulnNet Entertainment states it won't happen again. Can you prove they're wrong? ---...
-
Vulnversity
TryHackMe room
-
Warzone 2
---- You received another IDS/IPS alert. Time to triage the alert to determine if its a true positive. ----...
-
Web Application Security
TryHackMe room
-
What the Shell?
TryHackMe room
-
Windows Applications Forensics
TryHackMe room
-
Windows Forensics 1
--- Introduction to Windows Registry Forensics --- ...
-
Windows Forensics 2
--- Learn about common Windows file systems and forensic artifacts in the file systems. ---...
-
Windows Internals
--- Learn and understand the fundamentals of how Windows operates at its core. ---...
-
Windows Privilege Escalation
--- Learn the fundamentals of Windows privilege escalation techniques. --- ...
-
Windows Reversing Intro
---- Introduction to reverse engineering x64 Windows software. ----  ### Hack the machine and obtain the flags Start...
-
Year of the Rabbit
--- Let's have a nice gentle start to the New Year! Can you hack into the Year of the Rabbit box without falling down a hole? --- ###...
-
Zeek Exercises
--- Put your Zeek skills into practice and analyse network traffic. --- -[~] └─$ rustscan -a 10.129.232.196 --ulimit 5500...
-
Archetype
``` blob:https://app.hackthebox.com/4f38037f-6ebb-44b8-9c8c-992a446560fa ┌──(kali㉿kali)-[~] └─$ rustscan -a 10.129.232.196 --ulimit 5500...
-
Attacking Kerberos
--- Learn how to abuse the Kerberos Ticket Granting Service inside of a Windows Domain Controller --- This room will cover all of the...
-
AWS IAM Initial Access
TryHackMe room
-
AWS Lambda
TryHackMe room
-
Basic Pentesting
TryHackMe room
-
battery
---- CTF designed by CTF lover for CTF lovers ----  = -1 printf("Using debuggers? Here is tutoria"...) = -1 exit(1Using debuggers? Here is...
-
Binex
--- Escalate your privileges by exploiting vulnerable binaries. --- ...
-
Biohazard
--- A CTF room based on the old-time survival horror game, Resident Evil. Can you survive until the end? ---...
-
Blizzard
TryHackMe room
-
BlueTeam
--- For those who want to improve themselves in the Cyber Security Defense Field ---...
-
Boogeyman 2
TryHackMe room
-
Boogeyman 3
TryHackMe room
-
Borderlands
TryHackMe room
-
BountyHacker
``` Find open ports on the machine. First of all we’ll need to find open ports on our target machine, but if you are beginner you’ll...
-
Brainpan 1
--- Reverse engineer a Windows executable, find a buffer overflow and exploit it on a Linux machine. ---...
-
Brainstorm
--- Reverse engineer a chat program and write a script to exploit a Windows machine. ---  ### Deploy...
-
Breaching Active Directory
TryHackMe room
-
Breaking RSA
TryHackMe room
-
Brooklyn Nine Nine
--- This room is aimed for beginner level hackers but anyone can try to hack this box. There are two main intended ways to root the box....
-
Brute It
TryHackMe room
-
Buffer Overflow Prep
--- Practice stack based buffer overflows! --- -[~/Downloads/CVE-2022-46169-CACTI-1.2.22] └─$ rustscan -a 10.10.11.208 --ulimit 5500 -b 65535 -- -A -Pn .----. .-....
-
Busqueda
``` ┌──(witty㉿kali)-[~/Downloads/CVE-2022-46169-CACTI-1.2.22] └─$ rustscan -a 10.10.11.208 --ulimit 5500 -b 65535 -- -A -Pn .----. .-....
-
Bypass
TryHackMe room
-
Cactus
TryHackMe room
-
Cat Pictures
--- I made a forum where you can post cute cat pictures! --- ...
-
Critical
TryHackMe room
-
Crocc Crew
---- Crocc Crew has created a backdoor on a Cooctus Corp Domain Controller. We're calling in the experts to find the real back door!...
-
Crypto Failures
TryHackMe room
-
Custom Tooling using Burp
TryHackMe room
-
CVE-2021-41773/42013
TryHackMe room
-
CyberChef: The Basics
TryHackMe room
-
CyberHeroes
--- Want to be a part of the elite club of CyberHeroes? Prove your merit by finding a way to log in! ---...
-
Cyborg
--- A box involving encrypted archives, source code analysis and more --- ## vpn ``` tryhackme-vpn sudo openvpn WittyAle.ovpn ``` ###...
-
Dancing
``` blob:https://app.hackthebox.com/7ac8a74a-25d6-4db8-8341-4034e784d2ab ┌──(kali㉿kali)-[~] └─$ ping 10.129.141.78 PING 10.129.141.78...
-
Dancing
``` blob:https://app.hackthebox.com/7ac8a74a-25d6-4db8-8341-4034e784d2ab ┌──(kali㉿kali)-[~] └─$ ping 10.129.141.78 PING 10.129.141.78...
-
DDOS
``` https://tryhackme.com/room/blockchainvkkgjrphsh ┌──(kali㉿kali)-[~/Downloads/DDOS] └─$ ftp 10.10.161.202 Connected to 10.10.161.202....
-
Develpy
---- boot2root machine for FIT and bsides Guatemala CTF ----  [+] Install Complete! [+] Run the following commands in separate...
-
Encryption - Crypto 101
TryHackMe room
-
Enterprise
``` Enterprise es una máquina Windows Server 2019 configurada como Domain Controller. Para el acceso inicial tendremos que enumerar...
-
Examinerx9
TryHackMe room
-
ffuf
TryHackMe room
-
File Inclusion, Path Traversal
TryHackMe room
-
FilePeek
TryHackMe room
-
Fixit
TryHackMe room
-
Flatline
--- How low are your morals? ---  What are the...
-
Flip
---- Hey, do a flip! ----  ### Task 1...
-
Forgotten Implant
---- With almost no attack surface, you must use a forgotten C2 implant to get initial access. ----...
-
Frank & Herby make an app
TryHackMe room
-
Fusion Corp
---- Fusion Corp said they got everything patched... did they? ---- -[~/Downloads] └─$ curl 10.10.121.237 Go away! Nothing to see here, move along Notice: Hey guys, I set up the dev...
-
GoldenEye
--- Bond, James Bond. A guided CTF. --- ...
-
Google Dorking
TryHackMe room
-
Gotta Catch'em All!
--- This room is based on the original Pokemon series. Can you obtain all the Pokemon in this room? --- ### ssh...
-
Hack Back
TryHackMe room
-
Hack_printer
``` hydra -l printer -P /usr/share/wordlists/rockyou.txt 10.10.89.69 ssh Hydra v9.3 (c) 2022 by van Hauser/THC & David Maciejak - Please...
-
Hackfinity Battle Encore
TryHackMe room
-
Heist
TryHackMe room
-
Hip Flask
TryHackMe room
-
Hunt Me I: Payment Collectors
TryHackMe room
-
Hunt Me II: Typo Squatters
TryHackMe room
-
Hydra
TryHackMe room
-
Ice
TryHackMe room
-
Identification & Scoping
TryHackMe room
-
Inferno
---- eal Life machine + CTF. The machine is designed to be real-life (maybe not?) and is perfect for newbies starting out in penetration...
-
Insecure Deserialisation
TryHackMe room
-
Intermediate Nmap
--- Can you combine your great nmap skills with other tools to log in to this machine? ---...
-
Intranet
TryHackMe room
-
Intro to ISAC
--- Learn how to utilize Information Sharing and Analysis Centers to gather threat intelligence and collect IOCs. ---...
-
Intro to Logs
TryHackMe room
-
Intro To Pwntools
---- An introductory room for the binary exploit toolkit Pwntools. --- ...
-
Jacob the Boss
---- Find a way in and learn a little more. ---- -[~/Downloads] └─$ rustscan -a 10.10.248.160 --ulimit 5000 -b 65535 -- -A .----. .-. .-. .----..---. .----. .---. .--....
-
KoTH Food CTF
---- Practice Food KoTH alone, to get familiar with KoTH! --- ### FoodCTF Start Machine This is room for one of the King of the Hill...
-
KoTH Hackers
---- The Hackers KoTH box, to allow you to practice alone! ---- ### Task 1 Capture the flags Start Machine Capture the flags. Defend...
-
L2 MAC Flooding & ARP Spoofing
--- Learn how to use MAC Flooding to sniff traffic and ARP Cache Poisoning to manipulate network traffic as a MITM. ---...
-
LazyAdmin
 ``` ──(kali㉿kali)-[~] └─$ rustscan -a...
-
Learn Rust
TryHackMe room
-
Lian_Yu
TryHackMe room
-
Library
--- boot2root machine for FIT and bsides guatemala CTF --- -[~] └─$ rustscan -a 10.10.11.211 --ulimit 5500 -b 65535 -- -A -Pn .----. .-. .-. .----..---. .----. .---. .--. .-....
-
MonitorsTwo
``` ┌──(witty㉿kali)-[~] └─$ rustscan -a 10.10.11.211 --ulimit 5500 -b 65535 -- -A -Pn .----. .-. .-. .----..---. .----. .---. .--. .-....
-
Mouse Trap
TryHackMe room
-
Mr. Phisher
--- I received a suspicious email with a very weird looking attachment. It keeps on asking me to "enable macros". What are those? ---...
-
Nax
TryHackMe room
-
NerdHerd
---- Hack your way into this easy/medium level legendary TV series "Chuck" themed box! ----...
-
Network Device Hardening
TryHackMe room
-
Network Security Protocols
TryHackMe room
-
Networking Core Protocols
TryHackMe room
-
Ninja Skills
  (If you prefer to SSH into the machine, use the...
-
NIS - Linux Part I
--- Enhance your Linux knowledge with this beginner friendly room! --- ...
-
Overpass 3 - Hosting
TryHackMe room
-
OWASP Juice Shop
TryHackMe room
-
PaperCut: CVE-2023-27350
TryHackMe room
-
PassCode
TryHackMe room
-
Passive Reconnaissance
TryHackMe room
-
Pentesting Fundamentals
TryHackMe room
-
Phishing Analysis Fundamentals
TryHackMe room
-
Poster
--- The sys admin set up a rdbms in a safe way. ---  and (CVE-2021-34527). ---...
-
PrintNightmare, thrice!
--- The nightmare continues.. Search the artifacts on the endpoint, again, to determine if the employee used any of the Windows Printer...
-
Prototype Pollution
TryHackMe room
-
PS Eclipse
---- Use Splunk to investigate the ransomware activity. ---- ...
-
Public Key Cryptography Basics
TryHackMe room
-
Public Key Infrastructure
TryHackMe room
-
Ra
You have found WindCorp's internal network and their Domain Controller. Can you pwn their network? ...
-
Racetrack Bank
---- It's time for another heist. ---- ...
-
Red
---- A classic battle for the ages. ---- ...
-
Red Team Recon
TryHackMe room
-
Redeemer
``` blob:https://app.hackthebox.com/da9e33b6-5b40-44e1-851b-35f1e7f10447 ┌──(kali㉿kali)-[~] └─$ ping 10.129.87.135 PING 10.129.87.135...
-
Redeemer
``` blob:https://app.hackthebox.com/da9e33b6-5b40-44e1-851b-35f1e7f10447 ┌──(kali㉿kali)-[~] └─$ ping 10.129.87.135 PING 10.129.87.135...
-
Request Smuggling: WebSockets
TryHackMe room
-
ret2libc
---- This room teaches basic return-oriented programming (ROP), exploitation of binaries and an ASLR bypass. ---- ### Task 1...
-
Revil_Corp
``` ┌──(kali㉿kali)-[~/Downloads] └─$ xfreerdp /u:administrator /p:'letmein123!' /v:10.10.101.235 [17:16:55:731] [111859:111868]...
-
RustScan
TryHackMe room
-
Sakura Room
TryHackMe room
-
SAST
TryHackMe room
-
Sau
``` ┌──(witty㉿kali)-[~/Downloads] └─$ nmap 10.10.11.224 Starting Nmap 7.93 ( https://nmap.org ) at 2023-07-21 12:53 EDT Nmap scan report...
-
Sau
``` ┌──(witty㉿kali)-[~/Downloads] └─$ nmap 10.10.11.224 Starting Nmap 7.93 ( https://nmap.org ) at 2023-07-21 12:53 EDT Nmap scan report...
-
Secure Network Architecture
TryHackMe room
-
Security Awareness
TryHackMe room
-
Session Management
TryHackMe room
-
Skynet
--- A vulnerable Terminator themed Linux machine. ---  Hasta la vista, baby. Are you able to...
-
SOC L1 Alert Reporting
TryHackMe room
-
Solar, exploiting log4j
TryHackMe room
-
Splunk: Dashboards and Reports
TryHackMe room
-
Splunk: Setting up a SOC Lab
TryHackMe room
-
SQL Fundamentals
TryHackMe room
-
SQL Injection
TryHackMe room
-
SQL Injection Lab
TryHackMe room
-
Squid Game
TryHackMe room
-
SSTI
TryHackMe room
-
Super Secret TIp
TryHackMe room
-
Super-Spam
---- Defeat the evil Super-Spam, and save the day!! ---- -[~/Downloads] └─$ sudo openvpn lab_wittyAle.ovpn ┌──(witty㉿kali)-[~/Downloads] └─$ ip addr | grep tun0 6: tun0: mtu...
-
Templated
``` ┌──(witty㉿kali)-[~/Downloads] └─$ sudo openvpn lab_wittyAle.ovpn ┌──(witty㉿kali)-[~/Downloads] └─$ ip addr | grep tun0 6: tun0: mtu...
-
Temple
--- Can you gain access to the temple? --- ...
-
The Hacker Methodology
TryHackMe room
-
Threat Hunting: Pivoting
TryHackMe room
-
Threat Intelligence Tools
TryHackMe room
-
Tokyo Ghoul
--- Help kaneki escape jason room --- ...
-
TryHack3M: Bricks Heist
TryHackMe room
-
TryHack3M: Burg3r Bytes
TryHackMe room
-
TryHack3M: Sch3Ma D3Mon
TryHackMe room
-
TryHack3M: Subscribe
TryHackMe room
-
TShark Challenge II: Directory
TryHackMe room
-
TShark: Challenge I: Teamwork
TryHackMe room
-
TShark: CLI Wireshark Features
TryHackMe room
-
Tutorial
TryHackMe room
-
UltraTech
TryHackMe room
-
Unified
``` blob:https://app.hackthebox.com/9ea72111-db61-426b-b630-0afd1ffdd8a8 ┌──(kali㉿kali)-[~/hackthebox] └─$ rustscan -a 10.129.72.184...
-
Unified
``` blob:https://app.hackthebox.com/9ea72111-db61-426b-b630-0afd1ffdd8a8 ┌──(kali㉿kali)-[~/hackthebox] └─$ rustscan -a 10.129.72.184...
-
Vulnerability Capstone
--- Apply the knowledge gained throughout the Vulnerability Module in this challenge room. --- ### Introduction...
-
VulnNet: Roasted
--- VulnNet Entertainment quickly deployed another management instance on their very broad network... --- ### VulnNet: Roasted Start...
-
Weaponizing Vulnerabilities
TryHackMe room
-
Weasel
---- I think the data science team has been a bit fast and loose with their project resources. ---- ### Task 1 Start the VM Start...
-
WebGOAT
TryHackMe room
-
WebOSINT
TryHackMe room
-
Welcome
TryHackMe room
-
What is Networking?
TryHackMe room
-
Willow
---- What lies under the Willow Tree? ----   ### Task 1 Flags Start Machine Who knew? The dog has some bite!...
-
Year of the Owl
---- The foolish owl sits on his throne... ---- ...
-
You're in a cave
---- A room with some ctf elements inspired in text based RPGs ---- ...
-
ZeroLogon
--- Learn about and exploit the ZeroLogon vulnerability that allows an attacker to go from Zero to Domain Admin without any valid...