River

  • Home
  • Archive
  • Categories
  • Tags
  • Search
  • 2026

  • 2026-03-30
    HackTheBox: CCTV

    enumerating ZoneMinder version via cache timestamp, exploiting CVE-2024-51482 blind SQLi to dump credentials, then pivoting to sa_mark via motionEye CVE-2025-60787 RCE

  • 2026-03-26
    HackTheBox: Kobold

    exploiting CVE-2026-23744 unauthenticated RCE in MCPJAM, pivoting through container bind mounts to leak PrivateBin config, then using Arcane to spin up a root container

  • 2026-03-20
    HackTheBox: Wingdata

    exploiting CVE-2025-47812 lua injection in WingFTP for RCE, cracking a salted sha256 hash, then abusing CVE-2025-4138 PATH_MAX overflow to escape tarfile filter and get root

  • 2026-02-10
    HackTheBox: Pterodactyl

    exploiting a Pterodactyl game panel via path traversal, PAM environment poisoning, and a udisks2 XFS resize bug to get root

  • 2026-02-04
    HackTheBox: Facts

    another post im not done writing lolzzzzz

  • 2026-01-28
    ROP Emporium: callme

    Chaining PLT calls with a multi-argument ROP gadget to invoke three functions in sequence

  • 2026-01-27
    ROP Emporium: split

    Building a ROP chain to call system() with a custom string argument

  • 2026-01-25
    ROP Emporium: ret2win

    Classic buffer overflow exploiting a vulnerable read() to redirect execution to a win function

  • 2025

  • 2025-12-09
    wordpress xml-rpc vulnerability on a gov't contractor

    wordpress & its subsequent dangers

  • 2025-07-18
    You Are Not a Victim of Fate

    Process Over Product

Page 1 of 3
Copyright © 2024-2026 River
  • Home
  • Archive
  • Categories
  • Tags
  • Search