Brunner Mifflin (Root)
IT terminal creds + sudo NOPASSWD on /usr/bin/mail. GTFOBins payload spawns a root shell for the flag.
IT terminal creds + sudo NOPASSWD on /usr/bin/mail. GTFOBins payload spawns a root shell for the flag.
IDOR + broken access control in an HR web app. Manipulate a client-side role in localStorage to unlock admin access and grab the flag.
Fingerprinted a Telnet service running vulnerable GNU InetUtils telnetd, exploited CVE-2026-24061 via USER env injection to bypass auth and grab root shell + flag.
Anonymous LDAP enumeration exposes domain users. Password spraying identifies a second account. SeBackupPrivilege is abused to extract ntds.dit, leading to a full domain compromise via Pass-the-Hash.
An unsanitized XSLT parser allows arbitrary file writes for RCE. Credentials are recovered from a SQLite database. A Perl config injection grants a root shell.
A null-byte injection CVE-2025-47812. Credentials for a second user are recovered from config files. A symlink and hardlink chaining technique CVE-2025-4517.