Brunner Mifflin (Root)
IT terminal creds + sudo NOPASSWD on /usr/bin/mail. GTFOBins payload spawns a root shell for the flag.
IT terminal creds + sudo NOPASSWD on /usr/bin/mail. GTFOBins payload spawns a root shell for the flag.
IDOR + broken access control in an HR web app. Manipulate a client-side role in localStorage to unlock admin access and grab the flag.
A force-push hid a commit, but ORIG_HEAD and the dangling object survived. Recovered the leaked reliquary credentials.
Analyzing NTUSER.DAT hives with RegRipper to trace CROWQUILL's stolen-credential access to vmarr's machine, uncovering KeeFarce credential theft and a staged/exfiltrated archive via 7-Zip artifacts.
Stored XSS via unescaped EJS output, CSP bypassed using a Google JSONP endpoint, payload delivered to an admin bot that exfiltrated the flag from the admin inbox back to us.
An Elysia backend's signed session cookie fails to verify signatures (CVE-2025-66457), letting a forged session=inside cookie bypass auth.
Fingerprinted a Telnet service running vulnerable GNU InetUtils telnetd, exploited CVE-2026-24061 via USER env injection to bypass auth and grab root shell + flag.
Anonymous LDAP enumeration exposes domain users. Password spraying identifies a second account. SeBackupPrivilege is abused to extract ntds.dit, leading to a full domain compromise via Pass-the-Hash.
An unsanitized XSLT parser allows arbitrary file writes for RCE. Credentials are recovered from a SQLite database. A Perl config injection grants a root shell.
A null-byte injection CVE-2025-47812. Credentials for a second user are recovered from config files. A symlink and hardlink chaining technique CVE-2025-4517.