Blind SQL Injection with Conditional Errors
Practitioner-level PortSwigger lab exploiting error-based blind SQL injection on Oracle DB via the TrackingId cookie to extract the administrator password
Writeups for HTB, THM, and other platform machines.

Practitioner-level PortSwigger lab exploiting error-based blind SQL injection on Oracle DB via the TrackingId cookie to extract the administrator password

Practitioner-level PortSwigger lab exploiting boolean-based blind SQL injection via the TrackingId cookie to extract the administrator password character by character

Medium difficulty IR challenge involving ransomware analysis, PCAP forensics, and AI-assisted flag recovery

Easy Linux machine involving SQL Injection and password reset token exploitation.

Easy Linux machine focused on basic web exploitation and straightforward privilege escalation.

Easy Linux machine featuring Dolibarr CMS exploitation and SUID privilege escalation