Avatar 🤖

Gill.Singh.A

Undergraduate Student at IIT Kanpur

  1. Home
  2. Archives
  3. Search
    1. Dark Mode

Archives

2026 2
2025 4
2024 5

Categories

Hacking Lateral-Movement Cybersecurity Privilege Escalation Ssh Cracking Development Docker Infosec Mysql

Tags

Cybersecurity Infosec Hacking Lateral-Movement Ssh Privilege Escalation Brute Force Cctv Cracking Development
Featured image of post Privilege Escalation via Insecure NFS Mounts
Hacking Privilege Escalation Nfs

Privilege Escalation via Insecure NFS Mounts

In this blog, I walk through escalating from a low-privileged user to root on a remote server by abusing an insecurely configured NFS export (no_root_squash) — planting a root-owned SUID binary to earn a root shell, along with practical mitigations for defenders.

Jul 26, 2026
4 minute read
Featured image of post From Directory Listing to Root Shell
Hacking Privilege Escalation Lateral-Movement Postgresql

From Directory Listing to Root Shell

In this blog, I demonstrate how a simple directory listing vulnerability led to full system compromise during a penetration test — from exposed configuration files and PostgreSQL credentials to remote code execution, SSH access, privilege escalation, and lateral movement.

Feb 07, 2026
2 minute read
Featured image of post Dumping Source Code and Accessing Internal Databases via a Phpunit Vulnerability
Hacking Nuclei Php Mysql

Dumping Source Code and Accessing Internal Databases via a Phpunit Vulnerability

Exposed PHPUnit `eval-stdin.php` (CVE-2017-9841) under a web-accessible `vendor` folder allowed file-read payloads to dump site source and reveal DB credentials. Using the compromised host as a pivot, I accessed internal databases and extracted data — ends with practical defensive mitigations for defenders.

Nov 06, 2025
11 minute read
Featured image of post Cracking Linux Hashes and Expanding Access
Ssh Hacking Lateral-Movement Cracking

Cracking Linux Hashes and Expanding Access

In this blog, I’ll walk through how I gained access to multiple machines within an organization by cracking Linux user hashes and leveraging Shodan to identify additional targets. This post will focus on the post-exploitation phase, including hash extraction, cracking, and lateral movement.

Mar 21, 2025
4 minute read
Featured image of post Exploiting Unencrypted Private Keys and Misconfigured SSH Settings to Breach Multiple Systems
Ssh Hacking Lateral-Movement

Exploiting Unencrypted Private Keys and Misconfigured SSH Settings to Breach Multiple Systems

In this post, I'll walk through how I was able to gain unauthorized access to multiple machines by exploiting unencrypted private keys and misconfigured SSH settings.

Feb 24, 2025
3 minute read
1 2 3
© 2020 - 2026 Gill.Singh.A
Built with Hugo
Theme Stack designed by Jimmy