YPYogeshwar Peelainexploitnotes.hashnode.dev·2d ago · 10 min readTryHackMe - Olympus WriteupSummary Olympus is a Linux box built around an old Victor CMS 1.0 install hidden under /~webmaster/. An unauthenticated SQL injection in the CMS search feature was the root of the entire chain: it dum00
JJebitokinsharonjebitok.com·3d ago · 25 min readShells & Listeners Fundamentals (TryHackMe)Link to the challenge on TryHackMe: Shells & Listeners Fundamentals Introduction In many real-world assessments, a minor bug becomes a foothold. Imagine a file upload feature that fails to validate co00
JJebitokinsharonjebitok.com·6d ago · 11 min readChallenge: Expose (TryHackMe)Challenge on TryHackme: Expose Introduction Expose is a TryHackMe room focused on the risks of leaving unnecessary services running on a machine. The attack surface includes FTP, SSH, DNS, HTTP on a n00
4F404 Foundersin404-founders.com·Sep 5 · 5 min readCyber Alert: Kestra CVE-2026-49869 Gives Unauthenticated Attackers Root RCE in the Worker ContainerCyber Alert: Kestra CVE-2026-49869 Gives Unauthenticated Attackers Root RCE in the Worker Container CVE: CVE-2026-49869 Severity: Critical, CVSS 10.0 Affected: Kestra OSS before 1.0.45, and 1.1.0 thr00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 25 · 11 min readHackSmarter - Casino WriteupSummary Casino is a Flask-based "Guest WiFi & Portal" resort captive portal. A leaked JS source-map exposes an unauthenticated internal API endpoint (/api/v1/rooms/status) that dumps the entire guest 00
LTLưu Tuấn Anhinblog.fiscybersec.com·Aug 25 · 11 min read600,000 WordPress Websites At Risk RCE: How Dangerous Is Forminator Vulnerability?Overview Imagine a seemingly impossible scenario: A completely unknown attacker with no admin account, no need to log in, and no need to trick anyone into clicking on a malicious link. With just a sin00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 24 · 9 min readTryHackMe : Umbrella WriteupIntroduction Umbrella is a medium-difficulty TryHackMe box built around a leaky Docker registry, an exposed Node.js time-tracking application, and a classic writable-log privilege escalation. The path00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 23 · 18 min readBrunnerCTF 2026 : The Three Ways WriteupSummary Two connected challenges built around the same Gitea/Drone/rollout-agent environment. The first stage (Flow) gets code execution on the Drone CI runner. The second stage (Feedback / Continuous00
KLKacper Leszczyńskiinszotgan.hashnode.dev·Aug 23 · 5 min readMercury: How a Missing Comma Led to Unauthenticated RCEOne of the things that inspired me to start this research was the RCE vulnerability in Marimo discovered this April. The speed at which things escalated there was remarkable: a missing validation chec11R
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 23 · 8 min readBrunnerCTF : WordPressed to Root WriteupOverview The box ships a mostly-stock WordPress 7.0.0 install on PHP 8.2 / Apache, running on a Debian Trixie base image, packaged as a Docker/Kubernetes challenge deployment. Initial access comes thr00