<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://miisterc.github.io/</id><title>Sc17</title><subtitle>blog,sc17,cybersecurity,infosec,security,student,github </subtitle> <updated>2025-10-12T07:18:41+00:00</updated> <author> <name>Sc17</name> <uri>https://miisterc.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://miisterc.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://miisterc.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2025 Sc17 </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>Snare</title><link href="https://miisterc.github.io/posts/Snare/" rel="alternate" type="text/html" title="Snare" /><published>2025-10-12T04:00:00+00:00</published> <updated>2025-10-12T04:00:00+00:00</updated> <id>https://miisterc.github.io/posts/Snare/</id> <content type="text/html" src="https://miisterc.github.io/posts/Snare/" /> <author> <name>Sc17</name> </author> <category term="PwnTillDawn" /> <summary>Snare was a easy level box , where we leveraged a RFI to get a foothold in the system then after enumeration we found out , we had write access on a critical system file m by overwriting it , we got to root. Initial Enumeration. Nmap Result. $ nmap -vvv -p 22,80 -4 -sV -oN nmap 10.150.150.18 PORT STATE SERVICE REASON VERSION 22/tcp open ssh syn-ack OpenSSH 8.2p1 Ubuntu 4ubuntu0.1 (Ubun...</summary> </entry> <entry><title>SilentDev</title><link href="https://miisterc.github.io/posts/SilentDev/" rel="alternate" type="text/html" title="SilentDev" /><published>2025-10-05T04:00:00+00:00</published> <updated>2025-10-05T04:00:00+00:00</updated> <id>https://miisterc.github.io/posts/SilentDev/</id> <content type="text/html" src="https://miisterc.github.io/posts/SilentDev/" /> <author> <name>Sc17</name> </author> <category term="hmv" /> <summary>SilentDev was a very simple Linux Box , where we got initial foothold by leveraging a file upload vulnerability as www-data user , then we performed a lateral movement to developer user by exploiting a wildcard injection in a cronjob, then we move again to alfonso user by exploiting a injection vulnerability in a custom bash script that can be run by developer and land a shell as alfonso user ,...</summary> </entry> </feed>
