Overview

Offensive Security (OffSec) Proving Grounds are a collection of continually updated CTF-like machines to test understanding and reinforce learning concepts taught in OffSec Courses. Boxes can be authored by OffSec themselves or user-submitted. These machines are further separated into 'Practice' and 'Play' categories, where 'Practice' is accessed with a paid subscription.

OffSec provides a box difficulty rating matrix, 'Easy', 'Intermediate', and 'Hard'. In my experience, 'Easy' rated boxes usually focus on a public vulnerablity or simple misconfig that grants a foothold, and sometimes you land as root, bypassing the need for privilege escalation. 'Intermediate', however, requires more research, testing, and once you have a foothold, further enumeration of the box itself to either PrivEsc laterally or vertically to obtain proof.txt.

Unforturnately, I have not been able to solve any 'Hard' boxes, yet.

To the side, you will see all boxes I have completed on Proving Grounds, sorted into Linux and Windows. As always, for anyone who finds this site, it is paramount to first try to solve the box before looking at walkthroughs or hints, but my writeups can serve as just one example on how to exploit these boxes. If they are any inconsistencies or mistakes, please let me know.

Happy Hacking!