Detailed, step-by-step writeups of vulnerable machines from multiple cybersecurity platforms.
Each writeup covers the full attack lifecycle: Reconnaissance → Enumeration → Exploitation → Privilege Escalation.
| Platform | Difficulty |
|---|---|
| 🐳 DockerLabs | Very Easy / Easy / Medium |
| 🧪 TheHackersLabs | Beginner / Advanced |
Each writeup includes:
- 🔎 Reconnaissance: Port scanning and service enumeration (Nmap, Gobuster)
- 🧠 Vulnerability Analysis: Identifying misconfigurations and exploitable services
- 💥 Exploitation: Gaining initial access through web exploits, brute force, or service-specific attacks
- 🛠️ Privilege Escalation: Escalating from low-privilege user to root/admin
- 🏁 Flags: Capturing
user.txtandroot.txtas proof of compromise
Nmap · Burp Suite · Gobuster · Hydra · LinPEAS · John the Ripper · Metasploit · Netcat · SQLMap · Custom Scripts
📦 Maquinas_Laboratorios
├── 📂 MAQUINAS/
│ ├── 📂 Dockerlabs/
│ │ ├── 📂 Muy_facil/
│ │ ├── 📂 Facil/
│ │ └── 📂 Medio/
│ └── 📂 TheHackerLabs/
│ ├── 📂 Principiante/
│ └── 📂 Avanzado/
└── 📂 Images/ (Screenshots for each writeup)
This project is designed for anyone who:
- 🔒 Is learning penetration testing and wants real-world practice examples
- 🧩 Gets stuck on a step and needs a detailed walkthrough
- 📖 Wants to see different approaches to solving the same machine
- 🎯 Is preparing for cybersecurity certifications (eJPT, OSCP, CEH)
I'm Sleider Morales, an IT Support Specialist and aspiring Cybersecurity Professional based in Bogotá, Colombia.
- 🎓 Systems Engineering student at UNIMINUTO
- 🔧 Professional experience in IT Support & Hardware Diagnostics
- 🌍 Fluent in English (C1 Advanced — Certified) and Spanish (Native)
- 💼 Available for freelance IT Support & Security work
This repository is for educational and ethical hacking purposes only.
All machines were attacked in controlled, authorized environments.
Never use these techniques on systems without explicit permission.
⚔️ Ethical hacker always!
Happy Hacking! 🧠💻🖤