Writeups perso de CTF / labs de pentest — TryHackMe et HackTheBox.
Chaque writeup contient l'énumération complète, la chaîne d'exploitation et les leçons retenues.
Les valeurs de flags sont volontairement [REDACTED] (convention communautaire HTB/THM) — seule la méthodologie compte ici.
| Room | Catégorie | Statut |
|---|---|---|
| Publisher | SPIP CMS (CVE-2023-27372) + bypass AppArmor/SFTP | Rooted (user + root) |
| Smol | Linux priv-esc chain (PAM misconfig, leaked SSH key, zip cracking) | Rooted (user + root) |
| Valenfind | Web | Résolu |
| When Hearts Collide | Web | Résolu |
| Folles Mate Revenge | Web (prototype pollution) | Résolu |
| Cache Me Outside | OSINT/Web | Résolu |
| Machine | OS | Statut |
|---|---|---|
| Fireflow | Linux | User (root bloqué — limitation plateforme) |
| Connecte | Linux | Rooted (user + root) |
| DevArea | Linux | Rooted (user + root) |
| DevHub | Linux | Rooted (user + root) |
| Enigma | Linux | Rooted (user + root) |
| Cap | Linux | Rooted (user + root) |
| Nimbus | Linux | User (root en cours) |
| Checkpoint | Windows / AD | En cours (update) |
| Reactor | — | En cours (recon) |
| Abducted | Linux | En cours |
| MakeSens | Web | En cours |
| Sherlock | Type | Statut |
|---|---|---|
| Brutus | Forensics — compromission SSH | Résolu |
| Challenge | Catégorie | Statut |
|---|---|---|
| rev_spookypass | Reverse Engineering | Résolu |
| Bobby's Bistro | Web (JWK confusion) | Résolu |
| Secure Notes | Web (prototype pollution) | Exploit prêt, non confirmé |
| Challenge | Catégorie | Statut |
|---|---|---|
| SSTI 2 | Web (Jinja2 SSTI, filter bypass) | Résolu |
| Lab | Catégorie | Statut |
|---|---|---|
| AD103 | Active Directory (ADCS ESC1) | Résolu |
- Windows Security & Active Directory — authentification Windows (NTLM/Kerberos), contrôle d'accès, registre, services réseau, SIEM, QCM + examen.
Contenu à but éducatif — tests réalisés uniquement sur environnements de lab autorisés (TryHackMe, HackTheBox).