<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><title>0x4p0ll0</title><link>https://0x4p0ll0.me/</link><description>Security writeups, CTF walkthroughs, and the notes I take along the way.</description><language>en</language><item><title>Craft</title><link>https://0x4p0ll0.me/posts/craft.html</link><guid>https://0x4p0ll0.me/posts/craft.html</guid><pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate><category>Machines</category><description>A public API repo on a Gogs server leaks an unsanitised eval() in the brew-ABV check, and a second commit leaks the API creds needed to reach it, so a JSON field turns into RCE inside a Docker container. DB creds from settings.py dump the user table, Gilfoyle reused his password on Gogs, and the same password again decrypts an SSH key from a private repo. His .vault-token is scoped to a HashiCorp Vault root_otp SSH role, so vault ssh just hands me a one-time root password.</description></item><item><title>Trick</title><link>https://0x4p0ll0.me/posts/trick.html</link><guid>https://0x4p0ll0.me/posts/trick.html</guid><pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate><category>Machines</category><description>A DNS zone transfer leaks a preprod payroll vhost with a SQL injection that hands me file-read on the box. The nginx config points at a second vhost carrying a path-traversal LFI that leaks michael's SSH key, and a sudo-able fail2ban restart plus write access to action.d turns a ban action into a root shell.</description></item><item><title>Editorial</title><link>https://0x4p0ll0.me/posts/editorial.html</link><guid>https://0x4p0ll0.me/posts/editorial.html</guid><pubDate>Fri, 04 Sep 2026 00:00:00 +0000</pubDate><category>Machines</category><description>An SSRF in a book-cover upload form leaks an internal API and dev creds; deleted-but-not-forgotten git history hands over prod creds, and a GitPython ext:: protocol bug (CVE-2022-24439) finishes the job as root.</description></item><item><title>Pilgrimage</title><link>https://0x4p0ll0.me/posts/pilgrimage.html</link><guid>https://0x4p0ll0.me/posts/pilgrimage.html</guid><pubDate>Fri, 04 Sep 2026 00:00:00 +0000</pubDate><category>Machines</category><description>An arbitrary file read in a bundled ImageMagick binary (CVE-2022-44268) leaks the site's SQLite database and a user's password, and a root-owned malware-scanning script running a vulnerable binwalk (CVE-2022-4510) is abused for a path-traversal write that plants a reverse shell as root.</description></item><item><title>Inject</title><link>https://0x4p0ll0.me/posts/inject.html</link><guid>https://0x4p0ll0.me/posts/inject.html</guid><pubDate>Sat, 22 Aug 2026 00:00:00 +0000</pubDate><category>Machines</category><description>An LFI in an image viewer leaks source and a vulnerable Spring Cloud Function dependency (CVE-2022-22963); a cron-run Ansible play then hands over root.</description></item><item><title>UpDown</title><link>https://0x4p0ll0.me/posts/updown.html</link><guid>https://0x4p0ll0.me/posts/updown.html</guid><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><category>Machines</category><description>An exposed .git repo reveals a dev vhost; a PHP LFI plus the phar:// wrapper gives RCE, then a SUID Python app and a sudo easy_install reach root.</description></item><item><title>Headless</title><link>https://0x4p0ll0.me/posts/headless.html</link><guid>https://0x4p0ll0.me/posts/headless.html</guid><pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate><category>Machines</category><description>Stored XSS in a request header steals an admin cookie, a command injection in the admin dashboard lands a shell, and a sudo maintenance script gives root.</description></item><item><title>Hospital</title><link>https://0x4p0ll0.me/posts/hospital.html</link><guid>https://0x4p0ll0.me/posts/hospital.html</guid><pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate><category>Machines</category><description>A PHP upload filter bypass drops a webshell, a GhostScript RCE (CVE-2023-36664) and a cracked hash move laterally, and a writable service path reaches SYSTEM.</description></item><item><title>Mustacchio</title><link>https://0x4p0ll0.me/posts/mustacchio.html</link><guid>https://0x4p0ll0.me/posts/mustacchio.html</guid><pubDate>Mon, 10 Aug 2026 00:00:00 +0000</pubDate><category>Machines</category><description>An exposed SQLite backup leaks an admin hash, an XXE in a hidden panel exfiltrates an SSH key, and PATH hijacking on a SUID binary escalates to root.</description></item><item><title>Lame</title><link>https://0x4p0ll0.me/posts/lame.html</link><guid>https://0x4p0ll0.me/posts/lame.html</guid><pubDate>Sat, 08 Aug 2026 00:00:00 +0000</pubDate><category>Machines</category><description>A classic box: a vulnerable Samba username-map script (CVE-2007-2447) gives an unauthenticated root shell in a single request.</description></item><item><title>GoldenEye</title><link>https://0x4p0ll0.me/posts/goldeneye.html</link><guid>https://0x4p0ll0.me/posts/goldeneye.html</guid><pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate><category>Machines</category><description>Credential reuse and mailbox enumeration expose a Moodle admin login; a Moodle spell-check RCE lands a shell, and an outdated kernel gets root.</description></item></channel></rss>
