Hack The Box: (UpDown) Upload Phar File for RCE
What is Phar Deserizalition to Remote Code Execution? Phar file also known as PHP Archive will normally contain metadata that is written in a serialized format. As a result, the…
Security Awareness for all users
What is Phar Deserizalition to Remote Code Execution? Phar file also known as PHP Archive will normally contain metadata that is written in a serialized format. As a result, the…
What is API Penetration Testing? For those who are not familiar with API Penetration Testing, it’s a test activity that involves all the processes of vulnerability assessment and ensures that…
In this post, I would like to share some information on the Insecure Direct Object Reference (IDOR) vulnerability. What is IDOR Vulnerability? For those who are not familiar with IDOR…
In this post, I would like to share some knowledge about SQL Injection which can be useful during Penetration Testing activity. Before we went deeper into it, I will try…
What is JuicyPotato Vulnerability? Those who have experienced Pentester and had a good time testing with Windows Escalation Method, they are surely heard about JuicyPotato at least once. Therefore, for…
In this post, I would like to share a walkthrough of the Vessel Machine from Hack the Box This room will be considered a medium machine on Hack the Box What will…
In this post, I would like to share a walkthrough of the Health Machine from Hack the Box This room will be considered a medium machine on Hack the Box What will…
In this post, I would like to share a walkthrough of the Outdated Machine from Hack the Box This room will be considered a medium machine on Hack the Box What will…
In this post, I would like to share a walkthrough of the Moderators Machine from Hack the Box This room will be considered a Hard machine on Hack The Box What will…
In this post, I would like to share a walkthrough of the Faculty Machine from Hack the Box This room will be considered a Medium machine on Hack The box What will…