From reconnaissance to root — documented step by step.
Hello World! I'm franlrs — a cybersecurity enthusiast documenting my hands-on journey through CTF machines and penetration testing labs. Each writeup covers the complete exploitation chain: reconnaissance → enumeration → exploitation → privilege escalation, with detailed explanations of every technique and tool used.
All writeups are also published on my personal site with a better reading experience — check it out at portfolio.franlrs.blog.
⚠️ Disclaimer: All content is for educational purposes only, performed in controlled lab environments. Never apply these techniques on systems you don't own or have explicit permission to test.
🔗 Platform: dockerlabs.es — Free, Docker-based Linux machines.
| # | Machine | Difficulty | Key Techniques | Writeup |
|---|---|---|---|---|
| 01 | 🩸 BigWear | CVE-2025-34077 · Auth Bypass · RCE · PrivEsc | ||
| 02 | 💼 BigWork | — | ||
| 03 | 🏜️ Duque | — | ||
| 04 | 🌳 Tproot | — | ||
| 05 | 🎒 Trailpack | — |
🔗 Platform: hackthebox.com — Industry-standard offensive security labs.
🔗 Platform: tryhackme.com — Guided, beginner-friendly security labs.
| # | Machine | Difficulty | Key Techniques | Writeup |
|---|---|---|---|---|
| 01 | 🏘️ Neighbour | IDOR · Access Control |
| Category | Tools |
|---|---|
| 🔍 Recon | nmap masscan whois dig |
| 🗺️ Enumeration | gobuster ffuf wpscan nikto enum4linux |
| 💣 Exploitation | metasploit burpsuite sqlmap hydra |
| 🐚 Shells | netcat socat revshells.com |
| 📈 PrivEsc | linpeas pspy gtfobins sudo -l |
| 🔑 Cracking | john hashcat rockyou.txt |
| Platform | Machines | Easy | Medium | Hard |
|---|---|---|---|---|
| 🐳 DockerLabs | 5 | 3 | 2 | 0 |
| 📦 Hack The Box | 9 | 9 | 0 | 0 |
| 🔴 TryHackMe | 1 | 1 | 0 | 0 |
| Total | 15 | 13 | 2 | 0 |