PwnSec CTF 2026
PwnSec CTF 26: two easy web solves, a boolean blind SQLi built on a PHP type-confusion crash, and a pickle sandbox escape using OBJ instead of REDUCE
CCTV
HTB Easy Linux machine — default creds into ZoneMinder, time-based SQL injection (CVE-2024-51482) to dump password hashes, and root via motionEye command injection (CVE-2025-60787)





