Published onJuly 27, 2024Saori WriteupCVE-2024-29510LinuxHacking-ClubMachine for network traffic analysis and vulnerability exploitation in Ghostscript (CVE-2024-29510).
Published onJuly 19, 2024Moon WriteupCVE-2022-24112LinuxHacking-ClubThe application has Remote Code Execution vulnerabilities in Apache APISIX (CVE-2022-24112) and privilege escalation via the SUID binary lua.
Published onJuly 13, 2024Renderizer WriteupSSTIRCELinuxHacking-ClubExploring an SSTI vulnerability in a live rendering application, it is possible to gain RCE on the server. The privilege escalation involves sudo permissions on logstash.
Published onJune 29, 2024Reader WriteupSSRFRFILinuxHacking-ClubThe Reader machine has SSRF and RFI vulnerabilities that allow RCE and privilege escalation to root via capabilities in the Perl binary.
Published onJune 16, 2024Guardian WriteupSQLICODE-INJECTIONLinuxHacking-ClubMachine involving SQL Injection, code injection, and reversing (PE).