Walkthroughs focused on training-lab enumeration, initial access, privilege escalation, and reusable offensive-security lessons.
5 published writeups
Published writeups
Writeup Proving Grounds Practice Medium
SpiderSociety — Proving Grounds
A Proving Grounds Linux walkthrough covering virtual-host discovery, default control-panel credentials, FTP access to application source code, a hidden environment file exposing reusable credentials, SSH access as spidey, and privilege escalation through a writable systemd service with limited passwordless systemctl permissions.
An exposed rConfig instance was taken over through an administrator password reset, then leveraged through an upload-validation bypass to obtain a shell as apache and escalate through a SUID find binary.
A Proving Grounds Linux walkthrough covering ZoneMinder SQL injection, a MySQL file write into the Apache web root, a reverse shell as www-data, and privilege escalation through a MySQL UDF.