pentestmedium

Кибервоин (Cyberwarrior)

hackerlab

Task: Pentest machine with web service vulnerable to SQL injection behind WAF. Solution: Bypass WAF using MySQL comments, write webshell via SQLi, crack encrypted ZIP for SSH credentials, escalate privileges via sudo php.

$ ls tags/ techniques/
sql_injectionwaf_bypass_commentsfile_write_sqliwebshellzip2johnpassword_crackingsudo_php_privesc

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]