HackTheBox — Bashed Walkthrough
Full walkthrough of the HackTheBox machine Bashed. We exploit a web-accessible phpbash shell, escalate via sudo to scriptmanager, then abuse a cron-run Python script to get root.
2025-04-10
$ ls ./videos/
Video walkthroughs of HackTheBox / TryHackMe machines, penetration testing techniques, and security concepts.
Full walkthrough of the HackTheBox machine Bashed. We exploit a web-accessible phpbash shell, escalate via sudo to scriptmanager, then abuse a cron-run Python script to get root.
2025-04-10
Exploiting a vulnerable HFS (HTTP File Server) 2.3 on this Windows machine using Metasploit, then escalating privileges via an unquoted service path.
2025-03-22
Exploiting a file upload bypass to get RCE, then pivoting through a network script injection vulnerability for privilege escalation on this Linux box.
2025-02-14
A deep dive into classic 32-bit buffer overflow exploitation — from fuzzing and finding the EIP offset, to controlling execution and popping a shell.
2025-01-30
Going through the best challenges from TryHackMe's Advent of Cyber 2024 — covering OSINT, web attacks, cryptography, and forensics.
2024-12-26
Want more? Subscribe on YouTube.
▶ Subscribe on YouTube