RSSAmplifier

Blog

Aldeid News

Aldeid.com is a wiki about Network and Web Applications Security, Ethical Hacking, Network Forensics, Reverse Engineering and Malware Analysis.

aldeid.comRSS feed ↗10 posts

Latest posts

Navigating the Dark Web

TryHackMe > Unbaked Pie

Don’t over-baked your pie! Please allow 5 minutes for this instance to fully deploy before attacking. This VM was developed in collaboration with @ch4rm, thanks to him for the foothold and privilege escalation ideas. Contents 1 User Flag 1.1 Services 1.2 Django application 1.3 Pickle in the search 1.4 Exploit 1.5 Evade docker 1.6 Database 1.7 Brute force ramsey’s SSH account 1.8 Ramsey’s flag 2…

TryHackMe > Cooctus Stories

This room is about the Cooctus Clan. Previously on Cooctus Tracker Overpass has been hacked! The SOC team (Paradox, congratulations on the promotion) noticed suspicious activity on a late night shift while looking at shibes, and managed to capture packets as the attack happened. (From Overpass 2 - Hacked by NinjaJc01) Present times Further investigation revealed that the hack was made possible by…

TryHackMe > VulnNet Roasted

VulnNet Entertainment quickly deployed another management instance on their very broad network… VulnNet Entertainment just deployed a new instance on their network with the newly-hired system administrators. Being a security-aware company, they as always hired you to perform a penetration test, and see how system administrators are performing. Difficulty: Easy Operating System: Windows This is a…

TryHackMe > VulnNet Internal

VulnNet Entertainment learns from its mistakes, and now they have something new for you… VulnNet Entertainment is a company that learns from its mistakes. They quickly realized that they can’t make a properly secured web application so they gave up on that idea. Instead, they decided to set up internal services for business purposes. As usual, you’re tasked to perform a penetration test of their…

TryHackMe > toc2

It’s a setup... Can you get the flags in time? I have a theory that the truth is never told during the nine-to-five hours. - Hunter S. Thompson Contents 1 Find and retrieve the user.txt flag 1.1 Services 1.2 CMS information 1.3 CMS Made Simple / Reverse Shell 1.4 User flag 2 Escalate your privileges and acquire root.txt _frank)"> 2.1 Lateral move (www-data -> frank) 2.2 The readcreds binary 2.3…

TryHackMe > The Marketplace

Can you take over The Marketplace’s infrastructure? The sysadmin of The Marketplace, Michael, has given you access to an internal server of his, so you can pentest the marketplace platform he and his team has been working on. He said it still has a few bugs he and his team need to iron out. Can you take advantage of this and will you be able to gain root access on his server? Contents 1 What is…

TryHackMe > Debug

Linux Machine CTF! You’ll learn about enumeration, finding hidden password files and how to exploit php deserialization! Contents 1 User flag 1.1 Open ports 1.2 Web enumeration 1.3 The index.php.bak file 1.4 PHP serialization exploit 1.5 James password 1.6 User flag 2 Root flag 2.1 Message from root 2.2 The motd service 2.3 Reverse shell and root flag User flag Open ports Nmap reveals 2 open…

TryHackMe > En-pass

Get what you can’t. Think-out-of-the-box Contents 1 Name The Path. 1.1 Enumeration (1st level) 1.2 The zip directory 1.3 The web directory 2 What is the user flag? 2.1 SSH private key 2.2 The reg.php page 2.3 403 Fuzzing 2.4 SSH Connection 3 What is the root flag? 3.1 Cronjob 3.2 The script 3.3 Exploit 3.4 Root shell Name The Path. Nmap detects 2 open ports: PORT STATE SERVICE VERSION 22/tcp open…

TryHackMe > Wekor

CTF challenge involving Sqli , WordPress , vhost enumeration and recognizing internal services ;) Hey Everyone! This Box is just a little CTF I’ve prepared recently. I hope you enjoy it as it is my first time ever creating something like this ! This CTF is focused primarily on enumeration, better understanding of services and thinking out of the box for some parts of this machine. Feel free to ask…