Community Hub

📚 Writeups, Bug Bounty Reports & Resources

The latest community writeups, spoiler-safe hints, freshly launched labs, auto-gathered bug bounty reports from around the web, and a curated toolbox — one place, every link.

🐞 Bug Bounty Reports

Auto-gathered from public writeup feeds · refreshed every 6h

CVE-2024-45195: Apache OFBiz Unauthenticated Remote Code Execution (Fixed)
RCEForced browsingBroken authorization
Ryan Emmons · Apache OFBiz · 2024-09-05
Vulnerabilities in Open Source C2 Frameworks
RCEOS command injectionAuthentication bypassArbitrary file download
Laurence Tennant · Bishop Fox (Sliver), Havoc · 2024-09-18
Living off the VPN — Exploring VPN Post-Exploitation Techniques
Hardcoded secretsCredentials sent over unencrypted channel
Ori David (@oridavid123) · Ivanti (Connect Secure), Fortinet (Fortigate VPN) · 2024-08-07
Angular-ing for AuthZ, Problematic anti-patterns in Single Sign On Systems
SSOAuthentication bypass
Traceable ASPEN · - · 2024-03-05
Pwn2Own Miami: Aveva Edge Arbitrary DLL Loading Vulnerability
Arbitrary DLL loadingRCE
Piffd0s (@piffd0s) · AVEVA · 2024-08-01
When Certificates Fail: A Story of Bypassed MFA in Remote Access
2FA / MFA bypassCitrix
Michael Eder (@michael_eder_) · - · 2024-09-09
Data Theft in Salesforce: Manipulating Public Links
SOQL injection
Nitay Bachrach · Salesforce · 2024-09-16
Logic Flaw: I Can Block You from Accessing Your Own Account
Logic flaw
Hashim Amin · - · 2024-09-13
How to Bypass Golang SSL Verification
SSL verification bypassSecurity code review
Michael Pasternak · - · 2024-07-15
Plug Security Holes in React Apps That Can Lead to API Exploitation
SSOJWTBroken authenticationMissing authentication
Eaton Z. (@XeEaton) · Siemens · 2024-07-31
Attacking PowerShell CLIXML Deserialization
Insecure deserializationRCE
Alexander Andersson · Microsoft · 2024-09-13
Microsoft Windows MSI Installer - Repair to SYSTEM - A detailed journey
Local Privilege Escalation
Michael Baer · Microsoft (Windows) · 2024-09-12
Unmasking Harmful Content in a Medical Chatbot: A Red Team Perspective
AILLM JailbreakChatbot
William Wallace (@phyr3wall) · - · 2024-09-05
Spip Preauth RCE 2024: Part 2, A Big Upload
RCEFile uploadSecurity code review
Laluka (@TheLaluka) · SPIP · 2024-09-04
[2,500$ Bug Bounty Write-Up] Remote Code Execution (RCE) via unclaimed Node package
RCEDependency confusion 💰 2,500
Fuleki Ioan · - · 2024-09-18
Interesting Story of an Account Takeover Vulnerability
Account takeoverHost header injection 💰 2,000
Deepanshu (@golu_369) · - · 2024-09-12
Revival Hijack – PyPI hijack technique exploited in the wild, puts 22K packages at risk
CI/CDSupply chain attack
Andrey Polkovnichenko, Brian Moussalli · PyPI · 2024-09-04
Directory Traversal, SQL Injection and Server-Side Request Forgery
Path traversalSQL injectionSSRF
Chris McCurley (@chrisrmccurley) · Sage · 2024-09-10
Getting code execution on Veeam through CVE-2023-27532
RCEInsecure deserializationSecurity code review
Alain Mowat (@plopz0r) · Veeam · 2024-09-10
Microsoft Copilot: From Prompt Injection to Exfiltration of Personal Information
AILLMPrompt injection
Johann Rehberger (wunderwuzzi23) · GitHub (Copilot) · 2024-08-26
Government Emails at Risk: Critical Cross-Site Scripting Vulnerability in Roundcube Webmail
XSSSecurity code review
Oskar Zeino-Mahmalat · Roundcube · 2024-08-05
We Spent $20 To Achieve RCE And Accidentally Became The Admins Of .MOBI
RCETLD hacking
watchTowr (@watchtowrcyber) · - · 2024-09-11
Zero-Click Calendar invite — Critical zero-click vulnerability chain in macOS
RCEArbitrary file writeArbitrary file deleteTCC bypass
Mikko Kenttälä (@Turmio_) · Apple (macOS) · 2024-09-13
Escalating From Reader To Contributor In Azure API Management
Privilege escalation
Christian Håland · Microsoft (Azure) · 2024-09-13
Hijacking SQL Server Credentials using Agent Jobs for Domain Privilege Escalation
Privilege escalation
Scott Sutherland · - · 2024-09-10
Recursive Amplification Attacks: Botnet-as-a-Service
DDoS
Ben Kofman, Ryan Grunsten · - · 2024-07-24
Self-XSS to ATO via Site Features
Self-XSSAccount takeover
Hossein Shourabi (@hoseinshurabi) · - · 2024-09-08
$15k RCE Through Monitoring Debug Mode
RCELFIDebug mode enabled 💰 15,000
Omar (@0x0ld) · - · 2024-08-28
Back To School - Exploiting A Remote Code Execution Vulnerability In Moodle
RCESecurity code review
RedTeam Pentesting (@RedTeamPT) · Moodle · 2024-08-27
How I Got $250 For My Second Bug on HackerOne
OAuthSession expiration issue 💰 250
Likith Teki · - · 2024-09-01
Zomatoooo! IDOR in Saved Payments
IDOR
Prateek Srivastava · Zomato · 2024-09-04
CSRF Bypass Using Domain Confusion Leads To ATO
CSRFAccount takeover 💰 4,000
Osama Aly · - · 2024-08-28
P3 (Medium) : How I Gain Access To NASA's Internal Workspace?!
Information disclosure
Sri Shavin Kumar · NASA · 2024-09-03
IIS welcome page to source code review to LFI!
LFIBlind SSRFSecurity code review
Omar Ahmed (@spaceboy2O) · - · 2024-09-01
WordPress GiveWP POP to RCE (CVE-2024-5932)
RCEPHP pop chainPHP object injectionSecurity code review
Julien Ahrens (@MrTuxracer) · Wordfence · 2024-08-26
The Hunt for XXE to LFI: How I Uncovered CVE-2019–9670 in a Bug Bounty Program
XXELFIComponents with known vulnerabilities
Karthikeyan.V (@karthithehacker) · - · 2024-08-31
Bypassing CSP via URL Parser Confusions : XSS on Netlify’s Image CDN
XSSCSP bypass
Sudhanshu Rajbhar (@sudhanshur705) · Netlify · 2024-09-01
Basic HTTP Authentication Risk: Uncovering pyspider Vulnerabilities
Reflected XSSCSRFSecurity code review
Yaniv Nizry (@YNizry) · pyspider · 2024-09-02
Analysis of CVE-2024-43044 — From file read to RCE in Jenkins through agents
RCEArbitrary file read
Gabriel Quadros (@gqsilva), Ricardo Silva (@rick2600) · Jenkins · 2024-08-29
CVE-2024-37079:
Integer underflowBuffer OverflowMemory corruption
Grigory Dorodnov, Guy Lederfein (@glederfein) · VMware · 2024-08-28
Breaking Down Barriers: Exploiting Pre-Auth SQL Injection In WhatsUp Gold - CVE-2024-6670
SQL injectionReverse engineeringSecurity code review
Sina Kheirkhah (@SinSinology) · Progress (WhatsUp Gold) · 2024-08-30
Key and E: A Pentester’s Tale on How a Photo Opened Real Doors
Red team
Patricia Gagnon-Renaud · - · 2024-08-30
Ghost In The Ppl Part 1: Byovdll
Use-After-FreeMemory corruptionLSA Protection bypass
Clément Labro (@itm4n) · - · 2024-09-02
3CX Phone System Local Privilege Escalation Vulnerability
Local Privilege EscalationArbitrary file read
Adam Crosser · 3CX · 2024-08-28
Null Byte on Steroids
Null-Byte injectionAccount takeoverPassword resetSQL injection
Omar (@0x0ld) · - · 2024-02-06
$4,998 Bounty Awarded and 100,000 WordPress Sites Protected Against Unauthenticated Remote Code Execution Vulnerability Patched in GiveWP WordPress Plugin
RCEPHP pop chainPHP object injectionSecurity code review 💰 4,998
Villu Orav (@villu164) · Wordfence · 2024-08-19
4 exploits, 1 bug: exploiting cve-2024-20017 4 different ways
RCEBuffer OverflowMemory corruption
hyper (@hyprdude) · MediaTek · 2024-08-30
[$500] How I was able to give verification badge to any YouTube channel and bypass needed requirements
Parameter tampering 💰 500
Vojtech Cekal · Google (Youtube) · 2024-08-27
A Story About How I Found XSS in ASUS
XSS
Karthikeyan.V (@karthithehacker) · Asus · 2024-09-01
Bypassing airport security via SQL injection
SQL injection
Ian Carroll (@iangcarroll) · - · 2024-08-29
Double Agent: Exploiting Pass-through Authentication Credential Validation in Azure AD
CloudPrivilege escalationLateral movement
Ilan Kalendarov (@IKalendarov), Elad Beber · Microsoft (Entra ID / Azure AD) · 2024-08-15
Self XSS + Login CSRF + OAuth = Account Takeover
Account takeoverOAuthLogin CSRFSelf-XSS
LS (@Loupreme_) · - · 2024-07-02
How I got $24000 Bounty from a Log4j RCE in Apple App Store.
RCEComponents with known vulnerabilities 💰 24,000
Mehar huzaifa (@Hunter_Huzaifa_) · Apple · 2024-08-25
Addressed AWS defaults risks: OIDC, Terraform and Anonymous to AdministratorAccess
CloudOIDCTerraformPrivilege escalation
Eduard Agavriloae (@saw_your_packet) · AWS · 2024-08-15
How I Got Bugs From Google Dorks
Information disclosure
Chandan das · - · 2024-08-25
How I can easily get four P1 at NASA using Simple Google Dorking.
Information disclosure
Francesco Topol / k4tedu · NASA · 2024-08-23

📝 Community Writeups

Full writeups unlock on each machine page after you root it

Blacksite DB C
by noob6t5 · 2026-09-14
Axferia A
by rubanbe2003@gmail.com · 2026-09-14
Bastion B
by alvinpoon96 · 2026-09-14
Postmark A
by stratholme · 2026-09-14
DeployStation A
by nullf4c710n · 2026-09-13
Bootleak B
by mvx7aa · 2026-09-12
Driftsync A
by stratholme · 2026-09-10
Sidewinder A
by maimoharris · 2026-09-09
Nightfall A
by maimoharris · 2026-09-09
Corp Headers B
by maimoharris · 2026-09-09
API Users B
by maimoharris · 2026-09-09
Bastion A
by maimoharris · 2026-09-09
VoltCore B
by don · 2026-09-09
Walkabout B
by yucharotaro · 2026-09-07
Rootbase B
by stratholme · 2026-09-07
Meridian Hub B
by don · 2026-09-06
SolarGate B
by don · 2026-09-06
Axferia B
by yucharotaro · 2026-09-06
Loophole B
by stratholme · 2026-09-05
GridLock C
by stratholme · 2026-09-05
VoltCore B
by stratholme · 2026-09-05
Sidewinder D
by noob6t5 · 2026-09-04
DeployStation B
by shanx07 · 2026-09-03
TokenSmith A
by hoanggxyuuki · 2026-09-03
Switchgear B
by unijjw · 2026-09-02
Postmark B
by bistar · 2026-09-02
Bootleak B
by stratholme · 2026-09-02
Retrogate C
by stratholme · 2026-09-02
Listeria B
by stratholme · 2026-09-02
Walkabout B
by mahnoor27 · 2026-09-01

💡 Latest Hints

Spoiler-safe nudges submitted by the community

Bifrost Reconnaissance
"There is a python simple http server running. You can browse there and see what files are hosted."
Nightfall Privilege Escalation
They blocked the usual suspects — ; & | \ < >, cat/bash/sh, spaces, /bin, /etc/shadow. But notice what's missing from…
Nightfall Privilege Escalation
The script checks your input for danger, then hands it to eval as root. That gap between checking and executing is wh…
Bastion Privilege Escalation
There are no SUID surprises and no writable cron jobs here. Instead, look at what you're explicitly permitted to run …
VAULTNET-DC01 Enumeration
You're staring at a domain controller with SMB exposed. Anonymous access might seem unlikely on a production DC, but …
Sidewinder Enumeration
Look for all the users on the machine and the directories or files they have read, write, or execute rights to. Some…
Sidewinder Lateral Movement
This is not because ```ls``` show you an empty folder that there's nothing inside. ```man ls``` is your friend
Bastion Privilege Escalation
For Root-Flag when you land in a restricted shell that blocks commands, examine allowed utility list carefully. Int…
Switchgear Foothold
Your reach over the phone platform is administrative, and the service behind it isn't running as a locked-down user. …
Retrogate Enumeration
always try diffrent combinations and common username and passwords. admin:admin root:root rockyou.txt is best r…
Apex Foothold
You found the application path. Check the same folder for a configuration file
CIRT Gateway Privilege Escalation
Giving SUID to some things like find, vim, less, man etc, is basically handling out a root on a silver platter. Alway…
Corp Headers Foothold
While tryna connect to the ssh, don't forget the mention the port number correctly, not the default port
SolarGate Foothold
Old copies sometimes remember what the current system forgot.
Bootleak Reconnaissance
The server got a unknown ports which were used to access the web server which are FTP-30321, SSH-30322 and HTTP-30880…
Axferia Enumeration
DNS usually runs over UDP, but when it's sitting on TCP, it's not trying to be quirky. it's inviting you to have a l…
Inkblot Privilege Escalation
Check what files you can and can not write to. Think about what types of shells exist and where.
Meridian Hub Foothold
Before diving into exploits, take a moment to consider the basics of authentication hygiene. Many services ship with …
Porthaven Privilege Escalation
Once you have a foothold, don't stop at looking around your own home directory. Check what you're permitted to run wi…
Irongrep Privilege Escalation
Once you have a shell, don't go hunting for kernel exploits. Ask the system directly what commands you're permitted t…

🆕 Newest Labs

Freshly launched machines

Bastion Hard
launched 2026-08-29
Nightfall Hard
launched 2026-08-29
Sidewinder Medium
launched 2026-08-29
DeployStation Medium
RatSuite Hard
Switchgear Medium
Corp Headers Easy
launched 2026-08-08
Corp Webcrawl Easy
launched 2026-08-08
Corp Docs Medium
launched 2026-08-08
Corp Logs Medium
launched 2026-08-08
Corp OSINT Premium Hard
launched 2026-08-08
Nightglass Medium
launched 2026-08-01

🧭 Learning Paths

Guided tracks on the platform

🎯 OSCP Path
Exam-style Linux & Windows machines, full methodology.
🧭 CPTS Path
HTB-CPTS-aligned track from recon to AD.
📝 Pentest Reporting
Write and grade real pentest plans & reports.
⚡ Project Meridian
5-machine Linux privesc series inside SolarGate Energy.
📚 All Learning Paths
Browse every guided track on the platform.

🛠 Toolbox & References

Curated offensive-security resources

GTFOBins ↗Privesc
Unix binaries abused to bypass local restrictions.
LOLBAS ↗Privesc
Living-off-the-land binaries & scripts for Windows.
HackTricks ↗Reference
Encyclopedic pentest / CTF methodology.
PayloadsAllTheThings ↗Payloads
Payloads & bypasses for every common web bug class.
PortSwigger Web Security Academy ↗Learning
Free, hands-on web vuln labs.
OWASP Testing Guide ↗Reference
Structured web app testing methodology.
OWASP Cheat Sheet Series ↗Reference
Concise defensive + offensive cheat sheets.
HackerOne Hacktivity ↗Reports
Publicly disclosed bug bounty reports.
revshells.com ↗Tooling
Reverse shell generator for every language/listener.
CyberChef ↗Tooling
Encode/decode/crypto swiss-army knife.