Skip to content

franlrs/writeups

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

9 Commits
 
 
 
 
 
 

Repository files navigation

Kali Linux

🔐 Penetration Testing & CTF Writeup Collection

From reconnaissance to root — documented step by step.



📖 About This Repository

Hello World! I'm franlrs — a cybersecurity enthusiast documenting my hands-on journey through CTF machines and penetration testing labs. Each writeup covers the complete exploitation chain: reconnaissance → enumeration → exploitation → privilege escalation, with detailed explanations of every technique and tool used.

All writeups are also published on my personal site with a better reading experience — check it out at portfolio.franlrs.blog.

⚠️ Disclaimer: All content is for educational purposes only, performed in controlled lab environments. Never apply these techniques on systems you don't own or have explicit permission to test.


🐳 DockerLabs

🔗 Platform: dockerlabs.es — Free, Docker-based Linux machines.

# Machine Difficulty Key Techniques Writeup
01 🩸 BigWear Intermediate CVE-2025-34077 · Auth Bypass · RCE · PrivEsc Read
02 💼 BigWork Intermediate Read
03 🏜️ Duque Easy Read
04 🌳 Tproot Easy Read
05 🎒 Trailpack Easy Read

📦 Hack The Box

🔗 Platform: hackthebox.com — Industry-standard offensive security labs.

# Machine Difficulty Key Techniques Writeup
01 📅 Appointment Easy SQL Injection Read
02 🐊 Crocodile Easy FTP Anon · Directory Brute Read
03 💃 Dancing Easy SMB Enumeration Read
04 🦌 Fawn Easy FTP Anonymous Login Read
05 🐱 Meow Easy Telnet · Default Credentials Read
06 ☠️ Redeemer Easy Redis Enumeration Read
07 📡 Responder Easy LLMNR Poisoning · Hash Crack Read
08 🗃️ Sequel Easy MariaDB · SQL Enum Read
09 3️⃣ Three Easy AWS S3 · Subdomain Enum Read

🔴 TryHackMe

🔗 Platform: tryhackme.com — Guided, beginner-friendly security labs.

# Machine Difficulty Key Techniques Writeup
01 🏘️ Neighbour Easy IDOR · Access Control Read

🛠️ Tools & Methodology

Category Tools
🔍 Recon nmap masscan whois dig
🗺️ Enumeration gobuster ffuf wpscan nikto enum4linux
💣 Exploitation metasploit burpsuite sqlmap hydra
🐚 Shells netcat socat revshells.com
📈 PrivEsc linpeas pspy gtfobins sudo -l
🔑 Cracking john hashcat rockyou.txt

📊 Stats

Platform Machines Easy Medium Hard
🐳 DockerLabs 5 3 2 0
📦 Hack The Box 9 9 0 0
🔴 TryHackMe 1 1 0 0
Total 15 13 2 0

🔗 Links

Portfolio & Writeups


📄 MIT License · Star if useful!

About

CTF & penetration testing writeups covering DockerLabs, Hack The Box and TryHackMe. Full exploitation chains: recon → enumeration → exploitation → privilege escalation. Also published at portfolio.franlrs.blog/writeups

Topics

Resources

License

Stars

Watchers

Forks

Contributors

Languages