Avatar 🤖

Gill.Singh.A

Undergraduate Student at IIT Kanpur

  1. Home
  2. Archives
  3. Search
    1. Dark Mode

Archives

2026 4
2025 4
2024 5

Categories

Hacking Privilege Escalation Lateral-Movement Cybersecurity Ssh Cracking Infrastructure Development Docker Infosec

Tags

Cybersecurity Infosec Hacking Privilege Escalation Lateral-Movement Ssh Bmc Brute Force Cctv Cracking
Featured image of post From an Exposed iLO to Persistent Root via CVE-2017-12542
Hacking Infrastructure Privilege Escalation

From an Exposed iLO to Persistent Root via CVE-2017-12542

In this blog, I walk through how a single unpatched out-of-band management interface (HP iLO 4) let me take full control of a physical server — from one unauthenticated request to a pre-OS root shell and a permanent SSH backdoor — without ever knowing an operating-system credential.

Jul 31, 2026
9 minute read
Featured image of post From IPMI to Full Infrastructure Compromise via Proxmox
Hacking Infrastructure Privilege Escalation Proxmox

From IPMI to Full Infrastructure Compromise via Proxmox

In this blog, I walk through how a single exposed IPMI/BMC interface let me take full control of a physical server — which turned out to be a Proxmox hypervisor — handing me every virtual machine, container, and backup running on top of it.

Jul 31, 2026
10 minute read
Featured image of post Privilege Escalation via Insecure NFS Mounts
Hacking Privilege Escalation Nfs

Privilege Escalation via Insecure NFS Mounts

In this blog, I walk through escalating from a low-privileged user to root on a remote server by abusing an insecurely configured NFS export (no_root_squash) — planting a root-owned SUID binary to earn a root shell, along with practical mitigations for defenders.

Jul 26, 2026
4 minute read
Featured image of post From Directory Listing to Root Shell
Hacking Privilege Escalation Lateral-Movement Postgresql

From Directory Listing to Root Shell

In this blog, I demonstrate how a simple directory listing vulnerability led to full system compromise during a penetration test — from exposed configuration files and PostgreSQL credentials to remote code execution, SSH access, privilege escalation, and lateral movement.

Feb 07, 2026
2 minute read
Featured image of post Dumping Source Code and Accessing Internal Databases via a Phpunit Vulnerability
Hacking Nuclei Php Mysql

Dumping Source Code and Accessing Internal Databases via a Phpunit Vulnerability

Exposed PHPUnit `eval-stdin.php` (CVE-2017-9841) under a web-accessible `vendor` folder allowed file-read payloads to dump site source and reveal DB credentials. Using the compromised host as a pivot, I accessed internal databases and extracted data — ends with practical defensive mitigations for defenders.

Nov 06, 2025
11 minute read
1 2 3
© 2020 - 2026 Gill.Singh.A
Built with Hugo
Theme Stack designed by Jimmy