<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://rodrigo-hckr.github.io/</id><title>Rodrigo's CTF Writeups</title><subtitle>A minimal, responsive and feature-rich Jekyll theme for technical writing.</subtitle> <updated>2026-08-14T23:34:20+00:00</updated> <author> <name>Rodrigo Moguel Mendoza</name> <uri>https://rodrigo-hckr.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://rodrigo-hckr.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://rodrigo-hckr.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Rodrigo Moguel Mendoza </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>DockerLabs WinFake</title><link href="https://rodrigo-hckr.github.io/posts/dockerlabs-winfake/" rel="alternate" type="text/html" title="DockerLabs WinFake" /><published>2026-08-14T14:41:47+00:00</published> <updated>2026-08-14T14:41:47+00:00</updated> <id>https://rodrigo-hckr.github.io/posts/dockerlabs-winfake/</id> <content type="text/html" src="https://rodrigo-hckr.github.io/posts/dockerlabs-winfake/" /> <author> <name>Rodrigo Moguel Mendoza</name> </author> <category term="CTF" /> <category term="DockerLabs" /> <summary>📋 Resumen Laboratorio de dificultad fácil de DockerLabs cuyo nombre (“WinFake”) resume el concepto: un sitio web estático esconde un acróstico que revela un usuario SSH y, tras autenticar, el login cae en un intérprete de comandos falso escrito en Python que simula PowerShell/Windows sobre un sistema Linux real. Leyendo el código fuente del propio wrapper (accesible vía path traversal en su ún...</summary> </entry> <entry><title>WhoamI Labs - Vulnerable 3</title><link href="https://rodrigo-hckr.github.io/posts/whoami-labs-vulnerable-3/" rel="alternate" type="text/html" title="WhoamI Labs - Vulnerable 3" /><published>2026-08-12T18:11:51+00:00</published> <updated>2026-08-12T18:11:51+00:00</updated> <id>https://rodrigo-hckr.github.io/posts/whoami-labs-vulnerable-3/</id> <content type="text/html" src="https://rodrigo-hckr.github.io/posts/whoami-labs-vulnerable-3/" /> <author> <name>Rodrigo Moguel Mendoza</name> </author> <category term="CTF" /> <category term="WhoamiLabs" /> <summary>📋 Resumen Laboratorio de dificultad media que simula una arquitectura de microservicios (“NovaCloud Systems”). Un SSRF en el verificador de webhooks del Portal deriva en LFI y expone un PHP-FPM accesible directamente en la red interna, lo que permite RCE. Con RCE se pivota hacia la API interna, se filtra el secreto usado para firmar JWT y se forja un token de administrador para obtener acceso ...</summary> </entry> <entry><title>WhoamI Labs - Vulnerable 1</title><link href="https://rodrigo-hckr.github.io/posts/whoami-labs-vulnerable-1/" rel="alternate" type="text/html" title="WhoamI Labs - Vulnerable 1" /><published>2026-08-10T21:15:00+00:00</published> <updated>2026-08-10T21:15:00+00:00</updated> <id>https://rodrigo-hckr.github.io/posts/whoami-labs-vulnerable-1/</id> <content type="text/html" src="https://rodrigo-hckr.github.io/posts/whoami-labs-vulnerable-1/" /> <author> <name>Rodrigo Moguel Mendoza</name> </author> <category term="CTF" /> <category term="WhoamiLabs" /> <summary>📋 Resumen Ejecutivo El laboratorio “Vulnerable 1” expone una superficie de ataque amplia (17 puertos), pero el vector real resulta ser un share SMB (cosmos) con permisos de escritura/lectura para sesiones anónimas, que contiene un archivo con credenciales en texto plano. Una de esas credenciales tiene una regla de sudo mal configurada sobre /usr/bin/vim, permitiendo escalar a root mediante una...</summary> </entry> <entry><title>WhoamI Labs - Vulnerability</title><link href="https://rodrigo-hckr.github.io/posts/whoami-labs-vulnerability/" rel="alternate" type="text/html" title="WhoamI Labs - Vulnerability" /><published>2026-08-10T12:45:00+00:00</published> <updated>2026-08-10T12:45:00+00:00</updated> <id>https://rodrigo-hckr.github.io/posts/whoami-labs-vulnerability/</id> <content type="text/html" src="https://rodrigo-hckr.github.io/posts/whoami-labs-vulnerability/" /> <author> <name>Rodrigo Moguel Mendoza</name> </author> <category term="CTF" /> <category term="WhoamiLabs" /> <summary>📋 Resumen Ejecutivo El laboratorio “Vulnerability” expone un servidor Samba 3.0.20-Debian — una versión extremadamente antigua (2006) vulnerable a CVE-2007-2447, conocida como “Samba username map script Command Execution”. El servicio permite acceso anónimo de escritura sobre un share SMB, y el propio proceso smbd corre con privilegios de root, por lo que la explotación entrega acceso administ...</summary> </entry> <entry><title>WhoamI Labs - Transferencia</title><link href="https://rodrigo-hckr.github.io/posts/whoami-labs-transferencia/" rel="alternate" type="text/html" title="WhoamI Labs - Transferencia" /><published>2026-08-10T08:55:00+00:00</published> <updated>2026-08-10T08:55:00+00:00</updated> <id>https://rodrigo-hckr.github.io/posts/whoami-labs-transferencia/</id> <content type="text/html" src="https://rodrigo-hckr.github.io/posts/whoami-labs-transferencia/" /> <author> <name>Rodrigo Moguel Mendoza</name> </author> <category term="CTF" /> <category term="WhoamiLabs" /> <summary>📋 Resumen Ejecutivo El laboratorio “Transferencia” expone un servidor con FTP anónimo habilitado, permitiendo la descarga sin autenticación de un archivo con credenciales en texto plano. Una de esas credenciales es válida para SSH, y una vez dentro, un binario /usr/bin/bash con el bit SUID activado permite escalar directamente a root sin necesidad de exploits adicionales. Campo...</summary> </entry> </feed>
