Projects

TryHackMe

Offensive security labs.

2026University Coursework

Overview

The practical component of a Security Engineering module. TryHackMe hosts deliberately vulnerable machines to attack in a contained environment.

I escalated from a standard user to root on Linux by abusing misconfigured sudo rules, SUID binaries and capabilities. Scanned hosts to find services on non-standard ports, brute forced login forms, cracked password hashes, and pulled credentials out of captured traffic. Exploited XSS and SQL injection by hand, including blind cases where the application gives nothing back and the data has to be sent somewhere I controlled.

Stack

  • Linux
  • sudo
  • SUID
  • Capabilities
  • John the Ripper
  • nmap
  • Hydra
  • Wireshark
  • Netcat
  • Burp Suite
  • XSS
  • SQL injection