Blind SQL Injection with Conditional Errors
Practitioner-level PortSwigger lab exploiting error-based blind SQL injection on Oracle DB via the TrackingId cookie to extract the administrator password

Practitioner-level PortSwigger lab exploiting error-based blind SQL injection on Oracle DB via the TrackingId cookie to extract the administrator password

Practitioner-level PortSwigger lab exploiting boolean-based blind SQL injection via the TrackingId cookie to extract the administrator password character by character
Experiencia y metodología aplicada para obtener la certificación eJPT de INE/eLearnSecurity. Un examen práctico de penetration testing en un entorno corporativo simulado.

Medium difficulty IR challenge involving ransomware analysis, PCAP forensics, and AI-assisted flag recovery

Easy Linux machine involving SQL Injection and password reset token exploitation.

AI-powered pentesting assistant built with Python that integrates Google Gemini 2.5 Flash. Automates reconnaissance, enumeration, and provides intelligent analysis of scan results.

Easy Linux machine focused on basic web exploitation and straightforward privilege escalation.

Easy Linux machine featuring Dolibarr CMS exploitation and SUID privilege escalation

Desktop application developed in Java with JavaFX to securely store, manage, and retrieve passwords using encryption.