Priviledge Escalate to root exploiting a cap_setuid capability and library load feature in OpenSSL.
    
    
    
    
    
 
        
            
    
        
    
    
    
    
    
    
    
    
        Lots of tools to learn: NFS, Redis & rsync. Top it off with a sweet PrivEsc exploit.
    
    
    
    
    
 
        
            
    
        
    
    
    
    
    
    
    
    
        Learn about hash-cracking and a good deal of XXE attacks. Add some path hijacking to it!
    
    
    
    
    
 
        
            
    
        
    
    
    
    
    
    
    
    
        Straightforward room. Learn about shell-shock and kernel exploit.
    
    
    
    
    
 
        
            
    
        
    
    
    
    
    
    
    
    
        Some web-work, brute-forcing and tons of steganography.
    
    
    
    
    
 
        
            
    
        
    
    
    
    
    
    
    
    
        Learn about FTP, SMB, understand workings of shady scripts, set-uid bits
    
    
    
    
    
 
        
            
    
        
    
    
    
    
    
    
    
    
        Learn about Active Directory, SMB, Kerberos, Evil Win RM.
    
    
    
    
    
 
        
            
    
        
    
    
    
    
    
    
    
    
        A fun CTF room. Lots of enumeration, exploration and decoding - txt and otherwise.
    
    
    
    
    
 
        
            
    
        
    
    
    
    
    
    
    
    
        Learn about WordPress, SMB, brute-forcing WordPress accounts and some binary reversing.
    
    
    
    
    
 
        
            
    
        
    
    
    
    
    
    
    
    
        Hack into a Windows machine, leveraging common misconfigurations issues. Learn about Metasploit & hash-cracking. Great for beginners.