xsspresso
CTF Writeups
Tags
Blog
Projects
About
⌘K
Tags
303 tags across 144 writeups — click any tag to see related writeups.
RCE
37
AD
21
Sudo
15
FTP
13
File Upload
12
LFI
12
SQLi
12
SSRF
9
Apache
8
Command Injection
8
SMB
8
ADCS
7
BloodHound
5
Cron
5
CVE
5
Default Creds
5
Kernel Exploit
5
MSSQL
5
Path Traversal
5
SUID
5
WordPress
5
Brute Force
4
CMS
4
DCSync
4
File Read
4
PHP
4
ACL Abuse
3
Anonymous Login
3
Deserialization
3
Drupal
3
IIS
3
ImageMagick
3
Joomla
3
Kerberos
3
Metasploit
3
Password Reuse
3
SMTP
3
Token Impersonation
3
Web Shell
3
WebDAV
3
XSS
3
API
2
ASPX
2
ASREPRoasting
2
Cacti
2
CentOS
2
Certificate Abuse
2
Credential Enum
2
DNS
2
Dovecot
2
ESC4
2
EternalBlue
2
File Upload Bypass
2
Fuzzing
2
Gitea
2
Grafana
2
Kerberoasting
2
LAPS
2
MantisBT
2
MariaDB
2
Node.js
2
NTLM
2
NTLM Relay
2
PHP Webshell
2
POP3
2
ProFTPD
2
RBCD
2
RFI
2
Samba
2
Shadow Credentials
2
SNMP
2
SQLite Injection
2
Tomcat
2
VNC
2
VoIP
2
Webmin
2
Webshell
2
WinRM
2
Abyss Web Server
1
ActiveMQ
1
Actuator
1
AI
1
aiohttp
1
AJP
1
AlwaysInstallElevated
1
API Key
1
APK
1
APOC
1
Apport
1
Asterisk
1
Auth Bypass
1
Azure AD
1
b2evolution
1
Backdoor
1
Binwalk
1
Bookstack
1
Buffer Overflow
1
Bug Bounty
1
Bypass
1
C2 Framework
1
Centreon
1
CGI
1
chkrootkit
1
CHM
1
CIF Parser
1
Cisco
1
Code Injection
1
ColdFusion
1
Config Disclosure
1
Consul
1
Credential Leak
1
Credential Reuse
1
CVE-2007-2447
1
CVE-2009-2265
1
CVE-2014-0160
1
CVE-2014-4688
1
CVE-2014-6271
1
CVE-2014-6287
1
CVE-2017-7269
1
CVE-2018-7600
1
CVE-2019-10149
1
CVE-2019-15107
1
CVE-2020-1938
1
CVE-2021-22205
1
CVE-2021-27928
1
CVE-2022-25765
1
CVE-2022-44268
1
CVE-2022-46169
1
CVE-2023-23752
1
CVE-2023-27163
1
CVE-2023-30253
1
CVE-2023-32784
1
CVE-2023-38646
1
CVE-2023-40028
1
CVE-2023-40931
1
CVE-2023-46604
1
CVE-2024-21413
1
CVE-2024-23346
1
CVE-2024-38472
1
CVE-2024-41817
1
CVE-2024-46987
1
CVE-2025-24071
1
Cypher Injection
1
daloRADIUS
1
Delegation
1
Directory Traversal
1
DirtyCow
1
DNSmasq
1
Docker
1
Dolibarr
1
Dolphin CMS
1
DPAPI
1
Drupalgeddon2
1
Elastix
1
Enumeration
1
Env Injection
1
ESC1
1
ESC9
1
eval
1
eval()
1
Exim
1
Exposed Database
1
File Manager
1
File Write
1
FileZilla
1
Finger
1
Firewall
1
Flask
1
Formula Injection
1
Forum
1
FreePBX
1
GenericWrite
1
Ghost CMS
1
Ghostcat
1
Git Disclosure
1
GitLab
1
GPP
1
GraphQL
1
GravCMS
1
Groovy
1
GTFOBins
1
Hash Cracking
1
Heartbleed
1
HFS
1
hMailServer
1
IDOR
1
ifcfg
1
Image Upload
1
IPFire
1
IPMI
1
IRC
1
ISPConfig
1
James
1
Jenkins
1
JWT Forgery
1
Kartris
1
KeePass
1
Laravel
1
LDAP
1
LimeSurvey
1
Linked Servers
1
LLM
1
Log Poisoning
1
LXD
1
Magento
1
Markdown
1
MD5
1
Memory Dump
1
Memory Forensics
1
Metabase
1
Misconfiguration
1
MongoDB
1
Monitoring
1
MS08-067
1
MS17-010
1
MySQL
1
Nagios
1
Neo4j
1
NFS
1
Nginx
1
Nibbleblog
1
NSClient++
1
NTDS
1
NVMS-1000
1
ODAT
1
OpenEMR
1
OpenNetAdmin
1
OpenSSL
1
Oracle DB
1
OverlayFS
1
Password Reset
1
Password Spray
1
Pdfkit
1
pfSense
1
PFX
1
PHAR Deserialization
1
PHP Backdoor
1
PHP Injection
1
Port Forwarding
1
Port Knocking
1
PostgreSQL
1
Privilege Escalation
1
Prompt Injection
1
Protocol Analysis
1
Prototype Pollution
1
Python
1
Python Hijacking
1
Quick.CMS
1
RAKP
1
RDP
1
Responder
1
REST API
1
Reverse Engineering
1
Reverse Proxy
1
RPC
1
RSA
1
Ruby
1
Sandbox Escape
1
Scheduled Tasks
1
Scheduler RCE
1
Script Console
1
SeBackupPrivilege
1
Server Operators
1
Service Exploit
1
Shellshock
1
Silver Ticket
1
Sliver
1
Solar-PuTTY
1
Splunk
1
Spring Boot
1
SQLite
1
SSH
1
SSH Tunneling
1
SSTI
1
Steganography
1
Subdomain Takeover
1
Swagger
1
Symlink
1
SYSTEM
1
systemctl SUID
1
tar
1
TeamCity
1
TeamSpeak
1
TeamViewer
1
Template Editor
1
TikiWiki
1
tmux
1
uftpd
1
Umbraco
1
Vigenère
1
Volatility
1
WAR
1
Weak Credentials
1
Web
1
wget
1
Wildcard
1
Windows 10
1
Windows 7
1
Wing FTP
1
WonderCMS
1
XAMPP
1
xp_cmdshell
1
YAML Deserialization
1