Skip to content

Hacking Articles

Raj Chandel's Blog

  • Courses We Offer
  • CTF Challenges
  • Penetration Testing
  • Web Penetration Testing
  • Red Teaming
  • Donate us
Privilege Escalation

Linux Privilege Escalation: PwnKit (CVE 2021-4034)

February 7, 2022 by raj4 Min Reading

Team Qualys discovered a local privilege escalation vulnerability in PolicyKit’s (polkit) setuid tool pkexec, known as PwnKit (CVE 2021-4034), which allows low-level users to run

Persistence

Domain Persistence: Computer Accounts

February 5, 2022 by raj7 Min Reading

Typically, while configuring Active Directories, system admins overlook the harm caused by allowing a local administrator account on a system assigned to a specific user.

CTF Challenges, HackTheBox

Anubis HackTheBox Walkthrough

February 4, 2022 by raj6 Min Reading

Anubis is an “insane” level CTF box available on the HackTheBox platform designed by 4ndr34z. The box covers a real-life scenario of initial exploitation by

Privilege Escalation

Linux Privilege Escalation: Polkit (CVE 2021-3560)

January 30, 2022 by raj7 Min Reading

According to Red Hat, “Polkit stands for PolicyKit which is a framework that provides an authorization API used by privileged programs.” Pkexec is a tool

Persistence

Domain Persistence: Golden Certificate Attack

January 27, 2022 by raj11 Min Reading

Security analysts who have some knowledge about Active Directory and pentesting would know the concept of tickets. Kerberos, the default authentication mechanism in an AD,

CTF Challenges, HackTheBox

Forge HackTheBox Walkthrough

January 24, 2022 by raj5 Min Reading

Forge is a CTF Linux box rated “medium” on the difficulty scale on the HackTheBox platform. The box covers subdomain enumeration, SSRF attacks and basic

Defense Evasion, Red Teaming

Process Ghosting Attack

January 23, 2022 by raj8 Min Reading

Gabriel Landau released a post on Elastic Security here which talks about a technique through which antivirus evasion was found to be possible. The technique

CTF Challenges, VulnHub

Corrosion: 2 VulnHub Walkthrough

January 23, 2022 by raj5 Min Reading

Proxy Programmer’s Corrosion: 2 is a Vulnhub medium machine. We can download the lab from here. This lab is designed for experienced CTF players who

CTF Challenges, HackTheBox

Intelligence HacktheBox Walkthrough

January 23, 2022 by raj7 Min Reading

HackTheBox rates Intelligence as a CTF Windows box with a difficulty of “medium”. The machine covers OSINT, AD attacks, and silver ticket for privilege escalation.

Posts pagination

Previous 1 … 15 16 17 … 155 Next

Categories

Join Our Training Program

Join Our Telegram Channel

Join Our Discord Channel

Cyber Security Mindmap

Follow us on Twitter

Follow us on Linkedin

© All Rights Reserved 2021 Theme: Prefer by Template Sell.