Recent Posts

Zipper - Hack The Box

This is the writeup for Zipper, a Linux box running the Zabbix network monitoring software inside a docker container.

Giddy - Hack The Box

This is the writeup for Giddy, a Windows machine with an interesting twist on SQL injection, PowerShell Web Access and a priv exploiting improper permissions.

Ypuffy - Hack The Box

This is the writeup for Ypuffy, an OpenBSD machine from Hack the Box involving a somewhat easy shell access followed by a privesc using CA signed SSH keys.

Secnotes - Hack The Box

This blog post is a writeup of the Hack the Box SecNotes machine from 0xdf.

Oz - Hack The Box

This blog post is a writeup of the Oz machine from Hack the Box.

Mischief - Hack The Box

This blog post is a writeup of the Mischief machine from Hack the Box using the unintended LXC container privesc method.

Creating a custom shellcode crypter

For this last SLAE assignment, I’ve created a custom shellcode crypter using the Salsa20 stream cipher. Salsa20 is a family of 256-bit stream ciphers designed in 2005 and submitted to eSTREAM, the ECRYPT Stream Cipher Project.

Polymorphic Linux Shellcode

This blog post shows 3 polymorphic variants of common shellcodes found on shell-storm.org.