Skip to content

Latest commit

 

History

History
86 lines (58 loc) · 2.73 KB

File metadata and controls

86 lines (58 loc) · 2.73 KB

🛡️ CTF Writeups — Penetration Testing Practice

Detailed, step-by-step writeups of vulnerable machines from multiple cybersecurity platforms.
Each writeup covers the full attack lifecycle: Reconnaissance → Enumeration → Exploitation → Privilege Escalation.


📊 Platforms & Progress

Platform Difficulty
🐳 DockerLabs Very Easy / Easy / Medium
🧪 TheHackersLabs Beginner / Advanced

🔍 What You'll Find Here

Each writeup includes:

  • 🔎 Reconnaissance: Port scanning and service enumeration (Nmap, Gobuster)
  • 🧠 Vulnerability Analysis: Identifying misconfigurations and exploitable services
  • 💥 Exploitation: Gaining initial access through web exploits, brute force, or service-specific attacks
  • 🛠️ Privilege Escalation: Escalating from low-privilege user to root/admin
  • 🏁 Flags: Capturing user.txt and root.txt as proof of compromise

🛠️ Tools Frequently Used

Nmap · Burp Suite · Gobuster · Hydra · LinPEAS · John the Ripper · Metasploit · Netcat · SQLMap · Custom Scripts


📁 Repository Structure

📦 Maquinas_Laboratorios
├── 📂 MAQUINAS/
│   ├── 📂 Dockerlabs/
│   │   ├── 📂 Muy_facil/
│   │   ├── 📂 Facil/
│   │   └── 📂 Medio/
│   └── 📂 TheHackerLabs/
│       ├── 📂 Principiante/
│       └── 📂 Avanzado/
└── 📂 Images/                (Screenshots for each writeup)

🙌 Who Is This For?

This project is designed for anyone who:

  • 🔒 Is learning penetration testing and wants real-world practice examples
  • 🧩 Gets stuck on a step and needs a detailed walkthrough
  • 📖 Wants to see different approaches to solving the same machine
  • 🎯 Is preparing for cybersecurity certifications (eJPT, OSCP, CEH)

👤 About Me

I'm Sleider Morales, an IT Support Specialist and aspiring Cybersecurity Professional based in Bogotá, Colombia.

  • 🎓 Systems Engineering student at UNIMINUTO
  • 🔧 Professional experience in IT Support & Hardware Diagnostics
  • 🌍 Fluent in English (C1 Advanced — Certified) and Spanish (Native)
  • 💼 Available for freelance IT Support & Security work

📧 sleidermorales@gmail.com


⚠️ Disclaimer

This repository is for educational and ethical hacking purposes only.
All machines were attacked in controlled, authorized environments.
Never use these techniques on systems without explicit permission.
⚔️ Ethical hacker always!


Happy Hacking! 🧠💻🖤