River

  • Home
  • Archive
  • Categories
  • Tags
  • Search
  • 2026

  • 2026-03-30
    HackTheBox: CCTV

    enumerating ZoneMinder version via cache timestamp, exploiting CVE-2024-51482 blind SQLi to dump credentials, then pivoting to sa_mark via motionEye CVE-2025-60787 RCE

  • 2026-03-26
    HackTheBox: Kobold

    exploiting CVE-2026-23744 unauthenticated RCE in MCPJAM, pivoting through container bind mounts to leak PrivateBin config, then using Arcane to spin up a root container

  • 2026-03-20
    HackTheBox: Wingdata

    exploiting CVE-2025-47812 lua injection in WingFTP for RCE, cracking a salted sha256 hash, then abusing CVE-2025-4138 PATH_MAX overflow to escape tarfile filter and get root

  • 2024

  • 2024-08-13
    litCTF: JWT

    Exploiting JSON Web Tokens

  • 2024-08-13
    N00bzCTF: Sillygoose

    Exploiting a simple number search binary game

Copyright © 2024-2026 River
  • Home
  • Archive
  • Categories
  • Tags
  • Search