<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Writeups on HEKK</title>
    <link>https://hekk.one/writeups/</link>
    <description>Recent content in Writeups on HEKK</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <managingEditor>info@hekk.one</managingEditor>
    <webMaster>info@hekk.one</webMaster>
    <copyright>© 2026 </copyright>
    <lastBuildDate>Tue, 01 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://hekk.one/writeups/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title>OFFSEC - Proving Grounds - FLINK</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/flink/</link>
      <pubDate>Tue, 01 Sep 2026 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/flink/</guid>
      <description>Apache Flink 2.0.0 on port 8081 is exploited via Metasploit’s JAR Upload RCE module for initial access. LinPEAS identifies Pack2TheRoot (CVE-2026-41651), enabling privilege escalation to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/flink/feature_flink.jpeg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - CARRYOVER</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/carryover/</link>
      <pubDate>Sun, 30 Aug 2026 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/carryover/</guid>
      <description>Carvilla on port 80 is vulnerable to SQL injection, providing initial access via SQLmap. An exposed LD_PRELOAD variable enables a custom shared object to be executed with sudo, escalating privileges to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/carryover/feature_carryover.jpeg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - ZAB</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/zab/</link>
      <pubDate>Sun, 30 Aug 2026 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/zab/</guid>
      <description>Gobuster finds local.txt on port 80. A Mage web app on port 6789 provides browser-based terminal access. The server is vulnerable to Pack2TheRoot (CVE-2026-41651), enabling privilege escalation to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/zab/feature_zab.jpeg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - GLIDER</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/glider/</link>
      <pubDate>Sat, 29 Aug 2026 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/glider/</guid>
      <description>XXE on port 80 enables PHP file reads and RCE. After gaining access, pspy64 reveals Mosquitto credentials; subscribing to the MQTT topic exposes root credentials.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/glider/feature_glider.jpeg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - BACKUPBUDDY</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/backupbuddy/</link>
      <pubDate>Fri, 28 Aug 2026 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/backupbuddy/</guid>
      <description>PHP File Manager on port 80 allows default login and path traversal to Brian’s SSH key. SSH access is gained, then CVE-2026-41651 is exploited to become root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/backupbuddy/feature_backupbuddy.jpeg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - PATHWAY</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/pathway/</link>
      <pubDate>Fri, 28 Aug 2026 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/pathway/</guid>
      <description>Port 4566 exposes credentials, enabling SSH access. Sudo permits passwordless &lt;code&gt;/usr/bin/ping&lt;/code&gt;, and the set LD_PRELOAD variable can be abused to compile a C payload and escalate privileges to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/pathway/feature_pathway.jpeg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - CASSIOS</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/cassios/</link>
      <pubDate>Thu, 27 Aug 2026 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/cassios/</guid>
      <description>SMB share exposes recycler.ser; app source reveals credentials. Login enables ysoserial RCE, then PwnKit (CVE-2021-4034) escalates to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/cassios/feature_cassios.jpeg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - ARIN</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/arin/</link>
      <pubDate>Tue, 25 Aug 2026 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/arin/</guid>
      <description>Port 43 WHOIS and an ARIN web app expose registered data. After signup, SMTP receives the link. RWHOIS manipulation and a Fail2Ban tilde escape enable RCE and root access.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/arin/feature_arin.jpeg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - DEPTHB2R</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/depthb2r/</link>
      <pubDate>Mon, 24 Aug 2026 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/depthb2r/</guid>
      <description>Gobuster finds a JSP file on port 8080 enabling directory listing. Enumeration reveals SSH access as bill after disabling UFW. Initial access allows sudoing to root via bash.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/depthb2r/feature_depthb2r.jpeg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - BORN2ROOT</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/born2root/</link>
      <pubDate>Sun, 23 Aug 2026 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/born2root/</guid>
      <description>Initial access is gained via an SSH key in icons. A cronjob is abused for a jimmy shell, then Hydra finds hadi’s reused password, enabling root access.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/born2root/feature_born2root.jpeg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - NULLBYTE</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/nullbyte/</link>
      <pubDate>Sun, 23 Aug 2026 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/nullbyte/</guid>
      <description>Exiftool reveals a hidden directory. Hydra bypasses the key, SQL injection dumps a hash, which is cracked for SSH access. DirtyCow (CVE-2016-5195) is exploited to gain root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/nullbyte/feature_nullbyte.jpeg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - DECEPTION</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/deception/</link>
      <pubDate>Sat, 22 Aug 2026 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/deception/</guid>
      <description>WordPress enumeration revealed users and a hint leading to a split password. We combined it to gain SSH access, then exploited SUID /usr/bin/python2.7 to escalate privileges to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/deception/feature_deception.jpeg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - FOWSNIFF</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/fowsniff/</link>
      <pubDate>Sat, 22 Aug 2026 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/fowsniff/</guid>
      <description>GitHub credentials enable POP3 access to retrieve an SSH password. Hydra finds valid credentials for SSH access. A writable cube.sh used by the MOTD is abused to gain root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/fowsniff/feature_fowsniff.jpeg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - LAZYSYSADMIN</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/lazysysadmin/</link>
      <pubDate>Sat, 22 Aug 2026 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/lazysysadmin/</guid>
      <description>SMB share access revealed WordPress credentials. After logging into WordPress, we achieved RCE and initial access. Reused togie’s password to gain sudo privileges and escalate to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/lazysysadmin/feature_lazysysadmin.jpeg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - SCARECROW1.1</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/scarecrow1.1/</link>
      <pubDate>Sat, 22 Aug 2026 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/scarecrow1.1/</guid>
      <description>Used XXE and PHP wrappers to read files/source code, bypassed the upload blacklist with a PHP reverse shell for initial access, then exploited SUID find to escalate privileges to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/scarecrow1.1/feature_scarecrow11.jpeg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - FIVE86.2</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/five86.2/</link>
      <pubDate>Fri, 21 Aug 2026 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/five86.2/</guid>
      <description>A WordPress site is compromised via brute-forced credentials and an exploited vulnerable plugin. Initial access is gained, then LinPEAS identifies PwnKit (CVE-2021-4034), enabling privilege escalation to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/five86.2/feature_five862.jpeg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - PWNLAB</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/pwnlab/</link>
      <pubDate>Fri, 21 Aug 2026 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/pwnlab/</guid>
      <description>Exploited PHP wrappers/LFI to access DB credentials, extract web credentials, upload a malicious GIF/PHP reverse shell, gain access, then exploit DirtyCow (CVE-2016-5195) for root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/pwnlab/feature_pwnlab.jpeg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - CONFUSION</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/confusion/</link>
      <pubDate>Thu, 20 Aug 2026 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/confusion/</guid>
      <description>A Cacti HTTPS exploit is adapted for RCE. Database credentials enable lateral movement to james, who can modify /usr/local/sbin/systeminfo and run it as root via doas, enabling privilege escalation.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/confusion/feature_confusion.jpeg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - FUXA</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/fuxa/</link>
      <pubDate>Thu, 20 Aug 2026 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/fuxa/</guid>
      <description>Fuxa v1.2.4-2188 is exposed on port 1881. A public exploit for the SCADA/HMI software provides remote code execution, allowing us to gain root access to the server.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/fuxa/feature_fuxa.jpeg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - NEEDLE</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/needle/</link>
      <pubDate>Wed, 19 Aug 2026 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/needle/</guid>
      <description>Exploit on port 80 the contact form’s SVG upload function with a special HTTP header to access the medical dashboard. Abuse XSL_PATH during PDF discharge summary generation to inject a custom XSL file and achieve RCE.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/needle/feature_needle.jpeg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - MEDITRACK</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/meditrack/</link>
      <pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/meditrack/</guid>
      <description>SQLi on port 9000 dumps creds. Crack meditrackDev for Gitea access. Find Flask secret to forge admin cookie, then import snapshot for Pickle RCE. Escalate to root via CVE-2026-41651.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/meditrack/feature_meditrack.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - VANITY</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/vanity/</link>
      <pubDate>Mon, 13 Oct 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/vanity/</guid>
      <description>Rsync on 873 shares web application source code, using cmd injection gains initial access. Abuse rsync cronjob with -e option to get root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/vanity/feature_vanity.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - POSTFISH</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/postfish/</link>
      <pubDate>Sun, 12 Oct 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/postfish/</guid>
      <description>Website PostFish on port 80 and SMTP on port 25 reveal usernames. Hydra finds credentials, sending an email with a reset link grants brian access. Pwnkit (CVE-2021-4034) escalates to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/postfish/feature_postfish.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - RUSSIANDOLLS</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/russiandolls/</link>
      <pubDate>Sun, 12 Oct 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/russiandolls/</guid>
      <description>On port 8080 the website loads images via local http URLs, found open port 4242 with FILE VIEWER app. Path traversal exposes passwords and allows access via SSH. sudo v1.9.15 exploited for root access using CVE-2025-32463 chroot escalation.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/russiandolls/feature_russiandolls.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - DEVELOP</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/develop/</link>
      <pubDate>Sat, 11 Oct 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/develop/</guid>
      <description>Access Git repository on port 80 for credentials, login application on port 8080 and use command injection to retrieve a SSH key. Exploit CVE-2021-4034 to become root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/develop/feature_develop.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - PASSPORT</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/passport/</link>
      <pubDate>Sat, 11 Oct 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/passport/</guid>
      <description>Access website on port 80, extract credentials, log into FTP. Crack Luigi&amp;rsquo;s SSH key and gain initial access. Move laterally to luca and attach to a root tmux session for privilege escalation.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/passport/feature_passport.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - SYBARIS</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/sybaris/</link>
      <pubDate>Fri, 10 Oct 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/sybaris/</guid>
      <description>FTP on port 21 allows anonymous login and is writable. Redis 5.0.9 on port 6379 is exploitable by uploading a Redis module via FTP and exploit Redis for pablo access, then use pwnkit (CVE-2021-4034) to escalate to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/sybaris/feature_sybaris.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - DRIBBLE</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/dribble/</link>
      <pubDate>Thu, 09 Oct 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/dribble/</guid>
      <description>Web application on port 3000 allows admin access via modified cookie. Exploit Sudo Baron Samedit (CVE-2021-3156) to gain root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/dribble/feature_dibble.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - LUNAR</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/lunar/</link>
      <pubDate>Wed, 08 Oct 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/lunar/</guid>
      <description>Download zip from port 80, exploit PHP for LFI, use log poisoning for RCE as www-data. SSH with liam&amp;rsquo;s key for lateral movement and escalate to root via NFS no_root_squash.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/lunar/feature_lunar.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - MARKETING</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/marketing/</link>
      <pubDate>Sun, 05 Oct 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/marketing/</guid>
      <description>LimeSurvey 5.3.24 on port 80 has weak credentials, RCE gives www-data access. Find credentials and move laterally to t.miller, use sudo sync.sh to reach m.sander, then sudo to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/marketing/feature_marketing.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - SPLODGE</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/splodge/</link>
      <pubDate>Sun, 05 Oct 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/splodge/</guid>
      <description>Git repository on port 80 yields password via git-dumper. Login to admin panel on 8080, exploit preg_replace for initial access. Use pwnkit (CVE-2021-4034) to get root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/splodge/feature_splodge.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - SONA</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/sona/</link>
      <pubDate>Sun, 28 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/sona/</guid>
      <description>Brute-force NEXUS admin password on port 23. Use credentials on port 8081 and using CVE-2020-10199 gives initial access. move laterally to sona and edit cronjob’s base64.py for root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/sona/feature_sona.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - AUDIO</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/audio/</link>
      <pubDate>Sat, 27 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/audio/</guid>
      <description>Port 80 allows MP3/MPEG uploads. Upload MP3 with .php extension via BURP to get initial access. Find MySQL credentials reused by jason to move laterally. Run /usr/bin/git with sudo to gain root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/audio/feature_audio.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - ERP</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/erp/</link>
      <pubDate>Sat, 27 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/erp/</guid>
      <description>webERP on port 80 with weak credentials. SQL injection (CVE-2019-13292) reveals inoERP application, exploited for www-data access. SSH forwarding to port 8443 uncovers monitorr 1.7.6 which we can exploit for root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/erp/feature_erp.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - HETEMIT</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/hetemit/</link>
      <pubDate>Sat, 27 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/hetemit/</guid>
      <description>Werkzeug/1.0.1 on port 50000 has RCE endpoint, gain initial access as cmeeks. Edit /etc/systemd/system/pythonapp.service and use sudo to reboot the target to escalate to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/hetemit/feature_hetemit.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - FLIMSY</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/flimsy/</link>
      <pubDate>Thu, 25 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/flimsy/</guid>
      <description>OpenResty on port 43500 with APISIX/2.8 has RCE vulnerability (CVE-2022-24112). Exploit this and get initial access, write custom script in /etc/apt/apt.conf.d to escalate to root via cronjob.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/flimsy/feature_flimsy.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - BANZAI</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/banzai/</link>
      <pubDate>Sun, 21 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/banzai/</guid>
      <description>FTP on port 21 with weak credentials holds web dirirectory for port 8295. Upload PHP shell to gain initial access. MySQL UDF exploit sets SUID on bash and allows us to escalates to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/banzai/feature_banzai.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - WHEELS</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/wheels/</link>
      <pubDate>Sun, 21 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/wheels/</guid>
      <description>Wheels CarService website on port 80 has XPATH injection vulnerability which leads to gaining credentials for initial access. SUID on a binary with path traversal vulnerability to dump /etc/shadow. Crack hash with hashcat to gain root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/wheels/feature_wheels.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - BUNYIP</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/bunyip/</link>
      <pubDate>Sat, 20 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/bunyip/</guid>
      <description>S3cur3 r3pl application on port 8000 is vulnerable to MD5 length extension, exploiting this gives initial access. Pwnkit (CVE-2021-4034) escalates to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/bunyip/feature_bunyip.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - WOMBO</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/wombo/</link>
      <pubDate>Sat, 20 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/wombo/</guid>
      <description>Redis 5.0.9 on port 6379 has RCE vulnerability, exploiting it grants initial access as root user.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/wombo/feature_wombo.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - GROOVE</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/groove/</link>
      <pubDate>Fri, 19 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/groove/</guid>
      <description>ChurchCRM 4.5.1 on port 80 has weak credentials. Using an SQL injection via sqlmap reveals the root hash. Cracking it grants root access.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/groove/feature_groove.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - SPAGHETTI</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/spaghetti/</link>
      <pubDate>Fri, 19 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/spaghetti/</guid>
      <description>IRC server on port 6667, message to bot gives access to source code. Analyzing code gives code exeecution and initial access. Pwnkit exploit used to escalate to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/spaghetti/feature_spaghetti.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - DEPLOYER</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/deployer/</link>
      <pubDate>Thu, 18 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/deployer/</guid>
      <description>Anonymous FTP on port 21 gives site config and PHP code. Exploit LFI, drop PHP shell, gain initial access. Upload SSH key, use sudo &lt;code&gt;docker build&lt;/code&gt; to get &lt;code&gt;/opt/id_rsa.bak&lt;/code&gt; and escalate to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/deployer/feature_deployer.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - CONVERTEX</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/convertex/</link>
      <pubDate>Tue, 16 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/convertex/</guid>
      <description>XXE in web application on port 5000 and leaks gustavo SSH private key for initial access. Forward selenium port 4444 with chisel, exploit with Python script to gain root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/convertex/feature_convertex.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - MZEEAV</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/mzeeav/</link>
      <pubDate>Sun, 14 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/mzeeav/</guid>
      <description>Web application on port 80 has a ZIP backup with source code. Upload PHP webshell via MZ magic byte check, gain initial access and escalate to root using renamed find binary in /opt/fileS.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/mzeeav/feature_mzeeav.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - PAYDAY</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/payday/</link>
      <pubDate>Sun, 14 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/payday/</guid>
      <description>INTERNETSHOP on port 80 uses CS-CART. Weak credentials allow login and RCE via template editor with PHP webshell. Gain patrick user access via weak credentials and escalate to root using sudo bash.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/payday/feature_payday.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - PEPPO</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/peppo/</link>
      <pubDate>Sun, 14 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/peppo/</guid>
      <description>Ident on port 113 reveals process owner eleanor on port 10000. SSH access via weak credentials to get initial access in rbash, escape rbash using ed, set PATH and exploit pwnkit (CVE-2021-4034) to gain root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/peppo/feature_peppo.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - ZENPHOTO</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/zenphoto/</link>
      <pubDate>Sun, 14 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/zenphoto/</guid>
      <description>Website on port 80 runs ZENPHOTO 1.4.1.4, vulnerable to RCE exploit, granting www-data access. RDS Protocol LPE (CVE-2010-3904) escalates to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/zenphoto/feature_zenphoto.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - SILICON</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/silicon/</link>
      <pubDate>Sat, 13 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/silicon/</guid>
      <description>KORTEX ADVOCATED software on port 8000 which has SQLi vulnerability (CVE-2024-7640). Dump and crack hashes for initial access, escalate to root via ruby3.1.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/silicon/feature_silicon.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - AIR</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/air/</link>
      <pubDate>Fri, 12 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/air/</guid>
      <description>Aria2 WebUI on port 8888 is vulnerable to path traversal (CVE-2023-39141). Steal deathflash SSH key for initial access, find RPC key, forward port 6800 with chisel, configure app, upload SSH key to root for root access.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/air/feature_air.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - CACTI</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/cacti/</link>
      <pubDate>Fri, 12 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/cacti/</guid>
      <description>Cacti v1.2.28 on port 80 exploited via CVE-2025-24367 for webshell, gaining initial access as www-data. Found credentials in config.php, reused to escalate to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/cacti/feature_cacti.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - HAWAT</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/hawat/</link>
      <pubDate>Wed, 10 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/hawat/</guid>
      <description>Nextcloud runs on port 50080 with weak credentials and has a ZIP file with SQL-vulnerable application code. Abusing the SQL injection we get initial access as the root user.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/hawat/feature_hawat.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - EDUCATED</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/educated/</link>
      <pubDate>Mon, 08 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/educated/</guid>
      <description>WISDOM SCHOOL site on port 80 has Gosfem alogin page. RCE gives initial access. Crack msander&amp;rsquo;s hash, find emiller credentials in APK. Sudo escalates to root via bash.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/educated/feature_educated.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - GRAPH</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/graph/</link>
      <pubDate>Sun, 07 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/graph/</guid>
      <description>On port 80 is a graphql endpoint with SQL injection and gets hashes. Crack one for initial access. Python script with newline injection sets josh password. As josh, read /etc/shadow, crack root&amp;rsquo;s hash and escalate to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/graph/feature_graph.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - PIER</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/pier/</link>
      <pubDate>Sun, 07 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/pier/</guid>
      <description>Torrentpier on port 80 has a insecure object deserialization vulnerability (CVE-2024-1651) for RCE. Gain access as the pier user, use sudo to run bash as root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/pier/feature_pier.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - SORCERER</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/sorcerer/</link>
      <pubDate>Sun, 07 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/sorcerer/</guid>
      <description>Zipfiles on port 7742 contain users home directories. A found id_rsa key allows scp only. Upload authorized_keys, gain SSH access, and use SUID binary to escalate to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/sorcerer/feature_sorcerer.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - CHARLOTTE</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/charlotte/</link>
      <pubDate>Sat, 06 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/charlotte/</guid>
      <description>Use credentials or mount shares for application code. Leak creds via nginx (80) using BURP. Exploit RCE as www-data. Deploy JS to abuse a cronjob and move laterally. Escalate to root with sudo/bash.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/charlotte/feature_charlotte.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - CLIPPER</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/clipper/</link>
      <pubDate>Sat, 06 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/clipper/</guid>
      <description>ClipBucketV5 on port 80 has RCE vulnerability (CVE-2025-21624). Gain initial access and reuse credentials for lateral movement, exploit sudo lsof to set LD_LIBRARY_PATH and create own .so file to escalate to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/clipper/feature_clipper.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - FAIL</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/fail/</link>
      <pubDate>Fri, 05 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/fail/</guid>
      <description>Upload SSH key via rsync for initial access. Abuse fail2ban&amp;rsquo;s actioncheck in iptables-multiport.conf and trigger it by failed SSH logins to escalate to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/fail/feature_fail.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - TICO</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/tico/</link>
      <pubDate>Thu, 04 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/tico/</guid>
      <description>Use OFFSEC SSH credentials for initial access or exploit NodeBB on 8080 (CVE-2020-15149) for admin access. Write SSH key to root&amp;rsquo;s authorized_keys to escalate to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/tico/feature_tico.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - PHOBOS</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/phobos/</link>
      <pubDate>Wed, 03 Sep 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/phobos/</guid>
      <description>Find svn directory on port 80, enumerate logs for hostname. Register user and exploit code for LFI/RCE and initial access, use pwnkit (CVE-2021-4034) or crack root SHA-512 from MongoDB to escalate to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/phobos/feature_phobos.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - HUGS</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/hugs/</link>
      <pubDate>Sun, 31 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/hugs/</guid>
      <description>SSH with provided creds or exploit HugeGraph 1.2.0 (CVE-2024-27348) on 8080 for initial acces. Get mesbaha credentials from rest-server.properties file and SSH laterally, exploit sudo /home/mesbaha/reporter.sh to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/hugs/feature_hugs.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - SHIFTDEL</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/shiftdel/</link>
      <pubDate>Sun, 31 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/shiftdel/</guid>
      <description>Access via provided credentials or exploit WordPress 4.9.6 (CVE-2019-17671) for a password. Delete .htaccess, and get credentials, use phpMyAdmin RCE (CVE-2018-12613) for initial access and exploit command misconfiguration to get root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/shiftdel/feature_shiftdel.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - DETECTION</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/detection/</link>
      <pubDate>Sat, 30 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/detection/</guid>
      <description>Exploit RCE in changedetection v0.45.1 on port 5000 to gain initial access as the root user.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/detection/feature_detection.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - FRACTAL</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/fractal/</link>
      <pubDate>Sat, 30 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/fractal/</guid>
      <description>Exploit Symfony 3.4.46 on port 80 via /_fragment RCE for initial access. Use MySQL creds from proftpd to add benoit user, log in via FTP, add SSH key, and escalate to root with sudo.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/fractal/feature_fractal.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - MANTIS</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/mantis/</link>
      <pubDate>Sat, 30 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/mantis/</guid>
      <description>Gobuster finds /bugtracker with MantisBT 2.0. Exploit CVE-2017-12419 for MySQL credentials, crack a hash and get www-data via RCE. Mysqldump process runs with credentials and can be reused. Escalate using sudo.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/mantis/feature_mantis.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - SYNAPSE</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/synapse/</link>
      <pubDate>Fri, 29 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/synapse/</guid>
      <description>Synapse web app on port 80 allows SSI abuse via profile picture upload. Gain www-data access, crack GPG key to become mindsflee user, then use sudo synapse_commander.py with socat to escalate to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/synapse/feature_synapse.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - COBBLES</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/cobbles/</link>
      <pubDate>Thu, 28 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/cobbles/</guid>
      <description>Gain initial access via credentials or ZoneMinder exploit. As www-data, exploit HAProxy failover to access backup server as root in Docker. Escalate by copying bash to shared mount for host root access.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/cobbles/feature_cobbles.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - SIROL</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/sirol/</link>
      <pubDate>Wed, 27 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/sirol/</guid>
      <description>Exploit Kibana 6.5.0 (CVE-2019-7609) for initial access, then mount the host filesystem to get root or exploit glusterfs (CVE-2018-1088) to escalate to root via a created cronjob.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/sirol/feature_sirol.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - OUTDATED</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/outdated/</link>
      <pubDate>Tue, 26 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/outdated/</guid>
      <description>SSH or initial access by exploiting the website using mPDF 6.0 and downloading credentials, reuse creds for Webmin on port 10000 to escalate to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/outdated/feature_outdated.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - BITFORGE</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/bitforge/</link>
      <pubDate>Sun, 24 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/bitforge/</guid>
      <description>Git on port 80 leaks MySQL credentials. RCE in Simple Planning v1.52.01 for initial access, with pspy64 find jack&amp;rsquo;s credentials and changing flask script escalates to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/bitforge/feature_bitforge.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - PYLOADER</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/pyloader/</link>
      <pubDate>Sun, 24 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/pyloader/</guid>
      <description>Exploit CVE-2023-0297 on pyload (port 9666) via unauthenticated RCE to gain root access.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/pyloader/feature_pyloader.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - RUBYDOME</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/rubydome/</link>
      <pubDate>Sun, 24 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/rubydome/</guid>
      <description>Access target via SSH or exploit CVE-2022-25765 on port 3000. Gain initial access as the andrew user, escalate to root via sudo ruby script.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/rubydome/feature_rubydome.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - BOOLEAN</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/boolean/</link>
      <pubDate>Sat, 23 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/boolean/</guid>
      <description>Login screen can be bypassed via register JSON tweak and provides access remi&amp;rsquo;s .ssh directory. Upload our own SSH key for initial access and get root&amp;rsquo;s private key for privilege escalation.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/boolean/feature_boolean.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - LAVITA</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/lavita/</link>
      <pubDate>Fri, 22 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/lavita/</guid>
      <description>SSH in or exploit Laravel 8.4.0 with APP_DEBUG is set to true to gain www-data access. Abuse skunk&amp;rsquo;s script to escalate to skunk and use sudo /usr/bin/composer to edit composer.json to escalate privileges.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/lavita/feature_lavita.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - PLUM</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/plum/</link>
      <pubDate>Thu, 21 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/plum/</guid>
      <description>PluXml on port 80 uses weak credentials. Edit page to add PHP reverse shell for initial access. Find root password in /var/mail/www-data.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/plum/feature_plum.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - VMDAK</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/vmdak/</link>
      <pubDate>Wed, 20 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/vmdak/</guid>
      <description>Prison management system on port 9443 vulnerable to SQL injection &amp;amp; RCE once initial access got MySQL creds and SSH in. Using port forward on 8080 we can exploit Jenkins (CVE-2024-23897) for root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/vmdak/feature_vmdak.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - BLACKGATE</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/blackgate/</link>
      <pubDate>Mon, 18 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/blackgate/</guid>
      <description>Redis 4.0.14 on port 6379 exploited for initial access. &lt;code&gt;linpeas.sh&lt;/code&gt; reveals pwnkit vulnerability (CVE-2021-4034) which leads to privilege escalation.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/blackgate/feature_blackgate.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - IMAGE</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/image/</link>
      <pubDate>Mon, 18 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/image/</guid>
      <description>ImageMagick 6.9.6-4 on port 80 exploited for initial access. SUID on the strace binary leads to root privilege escalation.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/image/feature_image.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - SPX</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/spx/</link>
      <pubDate>Mon, 18 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/spx/</guid>
      <description>Tiny File Manager 2.5.3 on port 80; Exploiting CVE-2024-42007 and uploaded PHP reverse shell gives initial access, making own Makefile to set SUID on /bin/bash escalates our privileges</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/spx/feature_zipper.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - OCHIMA</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/ochima/</link>
      <pubDate>Sun, 17 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/ochima/</guid>
      <description>Maltrail 0.52 on port 8338 allows unauthenticated RCE, granting initial access. Exploit /var/backups/etc_Backup.sh as it&amp;rsquo;s run by root every minute, to escalate to root privileges.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/ochima/feature_ochima.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - ZIPPER</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/zipper/</link>
      <pubDate>Sun, 17 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/zipper/</guid>
      <description>Zipper website on port 80 allows file uploads. Use ZIP PHP wrapper for initial access and escalate to root via /opt/backup.sh script.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/zipper/feature_zipper.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - SCRUTINY</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/scrutiny/</link>
      <pubDate>Sat, 16 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/scrutiny/</guid>
      <description>Initial access via OFFSEC credentials or TeamCity CVE-2024-27198 exploit, get id_rsa key for marcot and password of multiple users. Briand runs /usr/bin/systemctl as root, escalate to root using GTFOBins.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/scrutiny/feature_scrutiny.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - TWIGGY</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/twiggy/</link>
      <pubDate>Sat, 16 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/twiggy/</guid>
      <description>SaltStack on port 8000 is vulnerable for CVE-2020-11651 &amp;amp; CVE-2020-11652 RCE exploit, enabling root reverse shell access.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/twiggy/feature_twiggy.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - WORKAHOLIC</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/workaholic/</link>
      <pubDate>Sat, 16 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/workaholic/</guid>
      <description>Use OFFSEC creds or scan Wordpress. Exploit a Wordpress vulnerability (CVE-2024-9796), crack hashes for charlie/ted. FTP as ted and SSH in as charlie. Escalate to root via SUID binary with custom shared object.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/workaholic/feature_workaholic.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - CLUE</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/clue/</link>
      <pubDate>Fri, 15 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/clue/</guid>
      <description>Remote file read on Cassandra Web (port 3000) exposes cassie credentials. RCE via FreeSwitch (8021). As cassie, run cassandra-web as root, get a RSA key and login as root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/clue/feature_clue.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - EXTPLORER</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/extplorer/</link>
      <pubDate>Fri, 15 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/extplorer/</guid>
      <description>eXtplorer application on port 80 with weak credentials which allows PHP reverse shell. As www-data, we can&amp;rsquo;t read local.txt. Crack dora&amp;rsquo;s hash, switch to dora in disk group, read proof.txt.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/extplorer/feature_extplorer.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - FLU</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/flu/</link>
      <pubDate>Fri, 15 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/flu/</guid>
      <description>Atlassian Confluence 7.13.6 on port 8090 has CVE-2022-26134 exploit for initial access. Add reverse shell to script for root privileges.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/flu/feature_flu.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - PRESS</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/press/</link>
      <pubDate>Fri, 15 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/press/</guid>
      <description>FlatPress on port 8089 allows login with weak credentials, PHP reverse shell upload via GIF magic byte, and privilege escalation to root using sudo apt-get.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/press/feature_press.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - CODO</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/codo/</link>
      <pubDate>Thu, 14 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/codo/</guid>
      <description>Codoforum on port 80 uses weak credentials. Exploit CVE-2022-31854 to upload malicious PHP logo, gain initial access and find root password in /var/www/html.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/codo/feature_codo.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - CRANE</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/crane/</link>
      <pubDate>Thu, 14 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/crane/</guid>
      <description>SuiteCRM on port 80 has weak admin:admin credentials. Use CVE-2022–23940 for RCE, then escalate to root via sudo /usr/sbin/service</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/crane/feature_crane.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - FIRED</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/fired/</link>
      <pubDate>Thu, 14 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/fired/</guid>
      <description>OpenFire 4.7.3 on port 9090 is vulnerable to CVE-2023-32315. Exploit and upload a .jar plugin for RCE. Root password found in script file to escalate privileges.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/fired/feature_fired.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - HUB</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/hub/</link>
      <pubDate>Thu, 14 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/hub/</guid>
      <description>FuguHub 8.4 on port 8082 is vulnerable to RCE exploit (CVE-2024-27697), granting direct root access.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/hub/feature_hub.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - JORDAK</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/jordak/</link>
      <pubDate>Tue, 12 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/jordak/</guid>
      <description>Jorani v1.0.0 on port 80 vulnerable to CVE-2023-26469, allows path traversal and code execution. User jordak has sudo access to /usr/bin/env, enabling root privilege escalation.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/jordak/feature_jordak.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - LAW</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/law/</link>
      <pubDate>Mon, 04 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/law/</guid>
      <description>Exploit CVE-2022-35914 on htmLawed 1.2.5 (port 80) with curl for RCE, get www-data shell. Pspy finds root script owned by www-data, run every minute. Add reverse shell, wait for root shell.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/law/feature_law.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - WALLA</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/walla/</link>
      <pubDate>Sun, 03 Aug 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/walla/</guid>
      <description>WFUZZ login credentials on port 8091, exploited RaspAP 2.5, CVE-2020-24572, then gained root via PwnKit.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/walla/feature_walla.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - SNOOKUMS</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/snookums/</link>
      <pubDate>Sun, 27 Jul 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/snookums/</guid>
      <description>PHP Gallery v0.8 has a RFI flaw. Use PHP shell, get michael&amp;rsquo;s MySQL creds, SSH in, find writable /etc/passwd via linpeas, set root password with OpenSSL and gain root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/snookums/feature_snookums.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - ASTRONAUT</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/astronaut/</link>
      <pubDate>Tue, 22 Jul 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/astronaut/</guid>
      <description>SSH with provided credentials or exploit GravCMS on port 80. Use SUID bit on php7.4 binary to escalate to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/astronaut/feature_astronaut.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - QUACKERJACK</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/quackerjack/</link>
      <pubDate>Tue, 22 Jul 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/quackerjack/</guid>
      <description>rConfig on port 8081 has SQLi leaking admin hash. CrackStation decrypts it for credentials. CVE-2019-19509 grants access. SUID find binary escalates to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/quackerjack/feature_quackerjack.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - BRATARINA</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/bratarina/</link>
      <pubDate>Mon, 21 Jul 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/bratarina/</guid>
      <description>SSH access with OFFSEC credentials or exploit OpenSTMPD on port 25 for remote code execution as root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/bratarina/feature_bratarina.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - APEX</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/apex/</link>
      <pubDate>Sun, 20 Jul 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/apex/</guid>
      <description>Exploit filemanager vuln on port 80 for OpenEMR SQL creds. Login to MySQL, get admin hash for app access. Use app exploit for initial access, reuse password for root escalation.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/apex/feature_apex.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - NUKEM</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/nukem/</link>
      <pubDate>Sun, 20 Jul 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/nukem/</guid>
      <description>Access target via SSH or exploit WordPress with wpscan using simple-file-list vuln. Get http user, find commander creds in wp-config.php, use SUID dosbox for root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/nukem/feature_nukem.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - PC</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/pc/</link>
      <pubDate>Sun, 20 Jul 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/pc/</guid>
      <description>SSH or browser terminal on port 8000 for initial access. Escalate privileges via RPC server running as root using Python exploit script (CVE-2022-35411) to gain root access.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/pc/feature_pc.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - LEVRAM</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/levram/</link>
      <pubDate>Sat, 19 Jul 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/levram/</guid>
      <description>Port 8000 redirects to GERAPY v0.9.7 login. Use default credentials for access. Auth RCE grants initial access. /usr/bin/python3.10 with cap_setuid=ep gives root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/levram/feature_levram.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - NIBBLES</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/nibbles/</link>
      <pubDate>Sat, 19 Jul 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/nibbles/</guid>
      <description>PostgreSQL port open, default creds allow login. Command execution (9.3+) runs reverse shell for access. SUID find enables root escalation.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/nibbles/feature_nibbles.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - EXFILTRATED</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/exfiltrated/</link>
      <pubDate>Thu, 17 Jul 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/exfiltrated/</guid>
      <description>SSH or Subrion CMS 4.2.1 file upload for access. Run linpeas to find CVE-2021-4034 (PwnKit) &amp;amp; cronjob with exiftool (CVE-2021-22204) for root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/exfiltrated/feature_exfiltrated.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - COCKPIT</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/cockpit/</link>
      <pubDate>Tue, 15 Jul 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/cockpit/</guid>
      <description>SQL inject login to get admin &amp;amp; additional creds. Use credentials in Ubuntu Web Console. Exploit sudo tar wildcard to escalate to root.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/cockpit/feature_pelican.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - PELICAN</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/pelican/</link>
      <pubDate>Mon, 14 Jul 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/pelican/</guid>
      <description>Exploitable Exhibitor for ZooKeeper on port 8080. Initial access user has gcore sudo privileges, can dump password-store process to reveal root credentials.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/pelican/feature_pelican.jpg" />
    </item>
    
    <item>
      <title>OFFSEC - Proving Grounds - ZINO</title>
      <link>https://hekk.one/writeups/offsec/pg_practice/zino/</link>
      <pubDate>Sun, 13 Jul 2025 00:00:00 +0000</pubDate>
      <author>info@hekk.one</author>
      <guid>https://hekk.one/writeups/offsec/pg_practice/zino/</guid>
      <description>Access server with SMB file and use a Python exploit for PHP webshell in Booked Scheduler. Escalate to root via cronjob.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://hekk.one/writeups/offsec/pg_practice/zino/feature_zino.jpg" />
    </item>
    
  </channel>
</rss>
