Playing Hacks and Stuffs!
OffSec Proving Grounds (PG) Play and Practice is a modern network for practicing penetration testing skills on exploitable, real-world vectors.
JWT Confusion Attack, SQLite Injection, ZipCrypto
Weak Authentication, SSRF, Sudo
LFI, Weak Permissions
Scripting, Python Library Hijack
Macros, File Upload, PrintSpoofer
File Upload, Docker, SNMP RCE, Reverse Engineering, Path Hijack, Capabilities
Wordpress, LFI, Redis, Cron
Ident, Rbash, Docker
Gitlab, Cron, Symbolic Link
API, Remote Code Execution, Suid
Python Wergzeug Misconfiguration, Service Abuse
Salt API RCE
Misconfiguration, Gogs, Command Injection
Cryptography, Webmin, Capability
ManageEngine ServiceDesk Plus
Sqli, Reverse Engineering, Path Hijack
Outdated Web Server, Cron, Apt
Source Code Review, Insecure Deserialization (Java), Sudoedit
Command Injection
Cron, Misconfiguration, Weak Password
PHP Type Juggling, LFI2RCE, NFS
XPATH Injection, Reverse Engineering
Symfony, Mysql, Ftp
Gitea, Path Hijack, Cron
Redis, ROP
H2 Database, PaperStream IP
CVE-2009-3103
RCE, Suid
Grafana, Disk Group
Squid Proxy, PHPMyAdmin
Open SMTP
Smatter Mail
Node JS, Command Injection, Suid