Skip to main content

Documentation Index

Fetch the complete documentation index at: https://rootea.es/llms.txt

Use this file to discover all available pages before exploring further.

All machines

Full catalog: 203 retired machines with 615 validated writeups. Cmd+K / Ctrl+K.

Linux (140)

MachineDifficultySkillsWriteups
Admirer🟢 EasyInformation Leakage Admirer Exploitation (Abusing LOAD DATA LOCAL Query) Abusin…3
Antique🟢 EasySNMP Enumeration Network Printer Abuse CUPS Administration Exploitation (ErrorL…3
Backdoor🟢 EasyLocal File Inclusion (LFI) · Remote Code Execution (RCE)3
Bank🟢 EasyTransferencia de zona DNS · SUID binaries · Remote Code Execution (RCE)3
Bashed🟢 EasyAbuso de cron · Abuso de sudo · phpbash (web shell PHP)2
Beep🟢 EasyLocal File Inclusion (LFI) · Shellshock (CVE-2014-6271) · Elastix LFI · Remote Code Execution (RCE)3
Blocky🟢 EasyWordPress Enumeration Information Leakage Analyzing a jar file - JD-Gui + SSH A…3
Blunder🟢 EasyBludit CMS Exploitation Bypassing IP Blocking (X-Forwarded-For Header) Director…3
BountyHunter🟢 EasyXML External Entity3
Delivery🟢 EasyVirtual Hosting Enumeration Abusing Support Ticket System Access to MatterMost…3
Doctor🟢 EasyRemote Code Execution (RCE)3
Frolic🟢 EasyRemote Code Execution (RCE)3
GoodGames🟢 EasySQL Injection3
Haystack🟢 EasyElasticSearch Enumeration Information Leakage Kibana Enumeration Kibana Exploit…3
Horizontall🟢 EasyInformation Leakage Port Forwarding Strapi CMS Exploitation Laravel Exploitation3
Knife🟢 EasyRemote Code Execution (RCE)3
Laboratory🟢 EasySUID binaries · Remote Code Execution (RCE)3
Lame🟢 EasySMB (139/445)4
Late🟢 EasyVirtual Hosting Enumeration Abusing Upload File - Image to Text Flask Utility S…3
Mirai🟢 EasyCredenciales por defecto · USB forensics · Pi-hole credenciales por defecto2
Nibbles🟢 EasyRemote Code Execution (RCE)3
NodeBlog🟢 EasySQL Injection · XML External Entity3
NunChucks🟢 EasyNodeJS SSTI (Server Side Template Injection) AppArmor Profile Bypass (Privilege…3
OpenSource🟢 EasyLocal File Inclusion (LFI) · Remote Code Execution (RCE)3
Pandora🟢 EasyRemote Code Execution (RCE) · SQL Injection3
Paper🟢 EasyInformation Leakage Abussing WordPress - Unauthenticated View Private/Draft Pos…3
Postman🟢 EasyRedis Enumeration Redis Exploitation - Write SSH Key Webmin Exploitation - Pyth…3
RouterSpace🟢 EasylinPEAS · Remote Code Execution (RCE)3
Safe🟢 EasyInformation Leakage Buffer Overflow [x64] [ROP Attacks using PwnTools] [NX Bypa…3
ScriptKiddie🟢 EasyRemote Code Execution (RCE)3
Secret🟢 EasyCode Analysis Abusing an API Json Web Tokens (JWT) Abusing/Leveraging Core Dump…3
Sense🟢 EasypfSense · Remote Code Execution (RCE)3
Shocker🟢 EasyShellshock (CVE-2014-6271)3
SteamCloud🟢 EasyKubernetes API Enumeration (kubectl) Kubelet API Enumeration (kubeletctl) Comma…3
SwagShop🟢 EasyRemote Code Execution (RCE)3
Tabby🟢 EasyLocal File Inclusion (LFI)3
Teacher🟢 EasyFuzzing de directorios · Remote Code Execution (RCE)3
Traverxec🟢 EasyNostromo Exploitation Abusing Nostromo HomeDirs Configuration Exploiting Journa…3
Valentine🟢 EasySSL Heartbleed Exploitation Cracking Hashes Tmux Socket File Session [Privilege…3
Validation🟢 EasySQL Injection · Remote Code Execution (RCE)3
Apocalyst🟡 MediumRemote Code Execution (RCE)3
Aragog🟡 MediumXML External Entity3
Backend🟡 MediumRemote Code Execution (RCE)3
BackendTwo🟡 MediumRemote Code Execution (RCE)3
Bolt🟡 MediumInformation Leakage Subdomain Enumeration SSTI (Server Side Template Injection)…3
Book🟡 MediumCross-Site Scripting (XSS)3
Cache🟡 MediumSQL Injection · Remote Code Execution (RCE)3
Catch🟡 MediumSQL Injection · Remote Code Execution (RCE)3
Celestial🟡 MediumRemote Code Execution (RCE)3
Chaos🟡 MediumRemote Code Execution (RCE)3
Cronos🟡 MediumTransferencia de zona DNS · SQL Injection3
DevOops🟡 MediumXML External Entity3
Devzat🟡 MediumFuzzing de directorios · Remote Code Execution (RCE)3
Enterprise🟡 MediumSQL Injection3
Epsilon🟡 MediumRemote Code Execution (RCE)3
Europa🟡 MediumSQL Injection · Remote Code Execution (RCE)3
Flustered🟡 MediumRemote Code Execution (RCE)3
FluxCapacitor🟡 MediumFuzzing de directorios3
Forge🟡 MediumServer-Side Request Forgery3
Haircut🟡 MediumServer-Side Request Forgery3
Hawk🟡 MediumRemote Code Execution (RCE)3
Inception🟡 MediumLocal File Inclusion (LFI) · WebDAV · Fuzzing de directorios3
Jewel🟡 MediumRemote Code Execution (RCE)3
Lazy🟡 MediumSUID binaries3
Luke🟡 MediumFTP Enumeration Information Leakage Abusing NodeJS Application API Enumeration…3
Mango🟡 MediumSQL Injection · SUID binaries3
Meta🟡 MediumRemote Code Execution (RCE)3
Nineveh🟡 MediumRemote Code Execution (RCE) · Local File Inclusion (LFI)3
Node🟡 MediumSUID binaries3
Noter🟡 MediumFuzzing de directorios · Remote Code Execution (RCE)4
Obscurity🟡 MediumRemote Code Execution (RCE)3
October🟡 MediumAbusing October CMS (Upload File Vulnerability) Buffer Overflow - Bypassing ASL…3
Passage🟡 MediumCuteNews Exploitation Code Analysis USBCreator D-Bus Privilege Escalation Pytho…3
Pit🟡 MediumRemote Code Execution (RCE)3
Poison🟡 MediumLocal File Inclusion (LFI) · Remote Code Execution (RCE)3
Ransom🟡 MediumLogin Bypass (Type Juggling Attack) Decrypting a ZIP file (PlainText Attack - B…3
RedCross🟡 MediumRemote Code Execution (RCE) · Cross-Site Scripting (XSS)3
Retired🟡 MediumLocal File Inclusion (LFI)3
Schooled🟡 MediumRemote Code Execution (RCE) · Cross-Site Scripting (XSS)3
Seal🟡 MediumRemote Code Execution (RCE)3
Shibboleth🟡 MediumRemote Code Execution (RCE)3
SneakyMailer🟡 MediumInformation Leakage Mass Emailing Attack with SWAKS Password Theft Abusing Pypi…3
SolidState🟡 MediumAbuso de cron3
Stratosphere🟡 MediumApache Struts Exploitation (CVE-2017-5638) Python Library Hijacking (Privilege…3
TartarSauce🟡 MediumRemote File Inclusion (RFI) · Remote Code Execution (RCE)4
Tenet🟡 MediumPHP Deserialization Attack Abusing Race Condition3
Tenten🟡 MediumWordpress Enumeration CV filename disclosure on Job-Manager Wordpress Plugin [C…3
TheNotebook🟡 MediumAbusing JWT (Gaining privileges) Abusing Upload File Docker Breakout [CVE-2019-…3
Time🟡 MediumServer-Side Request Forgery · Remote Code Execution (RCE)3
Timing🟡 MediumLocal File Inclusion (LFI)3
Undetected🟡 MediumRemote Code Execution (RCE)3
Unicode🟡 MediumLocal File Inclusion (LFI)3
Union🟡 MediumSQL Injection · Remote Code Execution (RCE)3
Waldo🟡 MediumLocal File Inclusion (LFI)3
Wall🟡 MediumSUID binaries · Fuzzing de directorios · Remote Code Execution (RCE)3
Writer🟡 MediumSQL Injection3
AdmirerToo🟠 HardRemote Code Execution (RCE) · Server-Side Request Forgery3
Altered🟠 HardSQL Injection · Remote Code Execution (RCE)3
Charon🟠 HardSQL Injection · SUID binaries3
CrimeStoppers🟠 HardLocal File Inclusion (LFI) · Remote Code Execution (RCE)3
Dab🟠 HardServer-Side Request Forgery · SUID binaries · Fuzzing de directorios · Remote Code Execution (RCE)3
EarlyAccess🟠 HardSQL Injection · Local File Inclusion (LFI) · Cross-Site Scripting (XSS)3
Ellingson🟠 HardSUID binaries · Remote Code Execution (RCE)3
Falafel🟠 HardSQL Injection3
Feline🟠 HardRemote Code Execution (RCE)3
Flujab🟠 HardSQL Injection · SUID binaries · Remote Code Execution (RCE)3
Holiday🟠 HardSQL Injection · Remote Code Execution (RCE) · Cross-Site Scripting (XSS)3
Joker🟠 HardRemote Code Execution (RCE)3
Kotarak🟠 HardServer-Side Request Forgery3
Mischief🟠 HardSNMP Enumeration Information Leakage IPV6 ICMP Data Exfiltration (Python Scapy)4
Monitors🟠 HardLocal File Inclusion (LFI) · Remote Code Execution (RCE)3
Oouch🟠 HardRemote Code Execution (RCE)3
Overflow🟠 HardSQL Injection · Remote Code Execution (RCE)3
OverGraph🟠 HardCross-Site Scripting (XSS) · SQL Injection · Fuzzing de directorios · Server-Side Request Forgery · SUID binaries · Remote Code Execution (RCE)3
Oz🟠 HardSQL Injection · Remote Code Execution (RCE)3
Phoenix🟠 HardSQL Injection3
Player🟠 HardRemote Code Execution (RCE)3
Pressed🟠 HardPassword Guessing WordPress Abusing RPC Calls WordPress XML-RPC Create WebShell…3
Quick🟠 HardRemote Code Execution (RCE) · Cross-Site Scripting (XSS)3
Scavenger🟠 HardTransferencia de zona DNS · SQL Injection3
Shrek🟠 HardInformation Leakage Steganography Challenge - Hidden message in the spectrogram…3
Static🟠 HardSUID binaries · Remote Code Execution (RCE)3
Talkative🟠 HardRemote Code Execution (RCE)3
Tentacle🟠 HardActive Directory3
Travel🟠 HardRemote Code Execution (RCE)3
Unbalanced🟠 HardPi-hole credenciales por defecto · Remote Code Execution (RCE)3
Unobtainium🟠 HardLocal File Inclusion (LFI) · Remote Code Execution (RCE)3
Zetta🟠 HardSQL Injection · Remote Code Execution (RCE)3
Ariekei🔴 InsaneShellshock (CVE-2014-6271)3
Brainfuck🔴 InsaneTLS Certificate Inspection WordPress Enumeration WordPress WP Support Plus Resp…3
CrossFit🔴 InsaneRemote Code Execution (RCE) · Cross-Site Scripting (XSS)3
CTF🔴 InsaneRemote Code Execution (RCE)3
Fortune🔴 InsaneCommand Injection OpenSSL - Creating a new key OpenSSL - Creating a CSR file (C…3
Fulcrum🔴 InsaneRemote File Inclusion (RFI) · XML External Entity · Active Directory · Server-Side Request Forgery · Remote Code Execution (RCE)3
Jail🔴 InsaneCode Analysis Binary Exploitation Buffer Overflow x32 - Socket Re-Use Shellcode…3
Nightmare🔴 InsaneSQL Injection · Remote Code Execution (RCE) · Cross-Site Scripting (XSS)2
Reddish🔴 InsaneAbusing Node-Red Chisel & Socat Usage Redis-Cli Exploitation Rsync Abusing Cron…3
Sink🔴 InsaneHTTP Request Smuggling Exploitation (Leak Admin Cookie) Cookie Hijacking Inform…3
Stacked🔴 InsaneRemote Code Execution (RCE) · Cross-Site Scripting (XSS)3
Toby🔴 InsaneAbusing GOGS (Project Enumeration) Static Code Analysis (Finding a backdoor wit…3

Windows (63)

MachineDifficultySkillsWriteups
Active🟢 EasyKerberoasting · SMB (139/445) · Group Policy Preferences (GPP)3
Arctic🟢 EasyAdobe ColdFusion 8 Exploitation Directory Traversal Vulnerability Cracking Hash…3
Blue🟢 EasyEternalBlue (MS17-010)3
Bounty🟢 EasyFuzzing de directorios · IIS (Microsoft Web Server)3
Buff🟢 EasyRemote Code Execution (RCE)3
Curling🟢 EasyRemote Code Execution (RCE)3
Devel🟢 EasyIIS (Microsoft Web Server)3
Driver🟢 EasyPassword Guessing SCF Malicious File Print Spooler Local Privilege Escalation (…3
Forest🟢 EasyTransferencia de zona DNS · BloodHound · DCSync3
Grandpa🟢 EasyWebDAV · IIS (Microsoft Web Server) · Remote Code Execution (RCE)3
Granny🟢 EasyWebDAV · IIS (Microsoft Web Server) · Remote Code Execution (RCE)3
Heist🟢 EasySMB (139/445)3
Jerry🟢 EasyInformation Leakage Abusing Tomcat [Intrusion & Privilege Escalation]3
Legacy🟢 EasyEternalBlue (MS17-010)3
Love🟢 EasyServer-Side Request Forgery3
Netmon🟢 EasyRemote Code Execution (RCE)3
Optimum🟢 EasyHttpFileServer (CVE-2014-6287) · Remote Code Execution (RCE)3
Remote🟢 EasyRemote Code Execution (RCE)3
Return🟢 EasyAbusing Printer Abusing Server Operators Group Service Configuration Manipulati…3
Sauna🟢 EasyBloodHound · GetNPUsers (Impacket) · AutoLogon credentials · winPEAS · DCSync3
ServMon🟢 EasyLocal File Inclusion (LFI)3
TimeLapse🟢 EasySMB (139/445)3
Toolbox🟢 EasySQL Injection · Remote Code Execution (RCE)3
Atom🟡 MediumSMB (139/445) · Remote Code Execution (RCE)3
Bart🟡 MediumFuzzing de directorios · Remote Code Execution (RCE)3
Bastard🟡 MediumRemote Code Execution (RCE) · SQL Injection3
Cascade🟡 MediumActive Directory · Kerberoasting · GetNPUsers (Impacket) · SQL Injection · SMB (139/445)3
Chatterbox🟡 MediumAchat 0.150 beta7 - Buffer Overflow (Windows 7 32 bits) Generating a Shellcode…3
Giddy🟡 MediumSQL Injection3
Intelligence🟡 MediumActive Directory · BloodHound · Remote Code Execution (RCE)3
Jeeves🟡 MediumJenkins Exploitation (Groovy Script Console) RottenPotato (SeImpersonatePrivile…3
Json🟡 MediumRemote Code Execution (RCE)3
Monteverde🟡 MediumRemote Code Execution (RCE)3
Querier🟡 MediumActive Directory3
Resolute🟡 MediumSMB (139/445)2
Scrambled🟡 MediumKerberoasting · GetNPUsers (Impacket) · SMB (139/445) · Remote Code Execution (RCE)6
SecNotes🟡 MediumSQL Injection · Fuzzing de directorios · IIS (Microsoft Web Server) · Cross-Site Scripting (XSS)3
Silo🟡 MediumAbusing Oracle Database Oracle Database Attacking Tool (ODAT) Installation Orac…3
Sniper🟡 MediumRemote File Inclusion (RFI) · Local File Inclusion (LFI) · SMB (139/445) · Remote Code Execution (RCE)4
StreamIO🟡 MediumRemote File Inclusion (RFI) · Local File Inclusion (LFI) · SQL Injection · BloodHound · AS-REP Roasting · SMB (139/445) · Remote Code Execution (RCE)3
Worker🟡 MediumFuzzing de directorios · IIS (Microsoft Web Server) · Remote Code Execution (RCE)3
Acute🟠 HardVirtual Hosting Information Leakage Abusing Windows PowerShell Web Access Real-…3
Blackfield🟠 HardActive Directory · BloodHound · GetNPUsers (Impacket) · SMB (139/445) · Remote Code Execution (RCE)3
Breadcrumbs🟠 HardLocal File Inclusion (LFI) · SQL Injection3
Conceal🟠 HardIIS (Microsoft Web Server) · Remote Code Execution (RCE)3
Control🟠 HardSQL Injection · winPEAS · Remote Code Execution (RCE)3
Hancliffe🟠 HardRemote Code Execution (RCE)3
Helpline🟠 HardRemote Code Execution (RCE)5
Mantis🟠 HardActive Directory · BloodHound3
Object🟠 HardActive Directory · BloodHound · Remote Code Execution (RCE)3
RE🟠 HardXML External Entity · IIS (Microsoft Web Server) · Remote Code Execution (RCE)3
Reel🟠 HardActive Directory · Remote Code Execution (RCE)3
Reel2🟠 HardRemote Code Execution (RCE)3
Search🟠 HardActive Directory · Kerberoasting · BloodHound · SMB (139/445)3
Tally🟠 HardRemote Code Execution (RCE)3
Anubis🔴 InsaneCross-Site Scripting (XSS) · SMB (139/445) · Remote Code Execution (RCE)3
APT🔴 InsanewinPEAS · SMB (139/445)3
Bankrobber🔴 InsaneSQL Injection · SMB (139/445) · Remote Code Execution (RCE) · Cross-Site Scripting (XSS)3
Fighter🔴 InsaneSQL Injection · Abuso de cron · Remote Code Execution (RCE)3
Hackback🔴 InsaneFuzzing de directorios · Remote Code Execution (RCE)3
Minion🔴 InsaneServer-Side Request Forgery3
MultiMaster🔴 InsaneActive Directory · SQL Injection · BloodHound · AS-REP Roasting · SMB (139/445) · Remote Code Execution (RCE)3
Sizzle🔴 InsaneActive Directory · Kerberoasting · BloodHound · DCSync · SMB (139/445)3