HackTheBox: Celestial
Celestial is a medium difficulty machine which focuses on deserialization exploits. It is not the most realistic, however it provides a practical example of abusing client-size serialized objects in NodeJS framework.
Hello, cyber enthusiasts! Chinmay Patel here, Security Specialist at Digital Boundary Group. Former Bug Bounty Hunter turned defender. Let's navigate the digital realm together!
Celestial is a medium difficulty machine which focuses on deserialization exploits. It is not the most realistic, however it provides a practical example of abusing client-size serialized objects in NodeJS framework.
Popcorn, while not overly complicated, contains quite a bit of content and it can be difficult for some users to locate the proper attack vector at first. This machine mainly focuses on different methods of web exploitation.
Legacy is a fairly straightforward beginner-level machine which demonstrates the potential security risks of SMB on Windows. Only one publicly available exploit is required to obtain administrator access.
Lame is a beginner level machine, requiring only one exploit to obtain root access. In this post, we will exploit the vulnerability manually as well as with the help of Metasploit.