Eye of Ra
SECURITY RESEARCHAsbawy

Asbawy

Security Research & Offensive Operations

Offensive security research, reverse engineering, endpoint security, and CTF walkthroughs. Documenting exploit development, low-level internals, and red teaming tools.

Live Interactive Operations TerminalInteractive shell session
asbawy-ops // bash v5.2
ASBAWY OFFENSIVE OPERATIONS CONSOLE [v2.6.4-SEC]
Type 'help' for available commands or try 'latest', 'tools', 'whoami'.
visitor@asbawy-ops:~$

CTF Walkthroughs & Pwned Machines

View all
TryHackMeMedium

Ledger — TryHackMe Writeup

A comprehensive writeup for the Medium TryHackMe machine Ledger. We exploit an anonymous LDAP directory dump leaking credentials inside user descriptions, analyze the AD forest and ESC1 template misconfigurations using pharaohound, navigate around a stubborn PKINIT KDC error, and achieve Domain Admin compromise by abusing guest-level GenericWrite permissions over the domain controller via Resource-Based Constrained Delegation (RBCD).

2026-09-17Windows
#Active Directory#LDAP#Credential Leak
Read
TryHackMeMedium
AUTOSOLVE

Temple — TryHackMe Writeup

A comprehensive writeup for the Medium TryHackMe machine Temple, detailing recursive directory discovery to uncover a hidden registration endpoint, character-filtered Jinja2 SSTI bypassed via hex-escaped attributes and cycler globals to land RCE as bill, and escalating to root by weaponizing an auto-reloading, world-writable Logstash pipeline.

2026-09-17Linux
#Web#SSTI#Flask
Read
TryHackMeHard

Contrabando — TryHackMe Writeup

A Hard-rated TryHackMe machine featuring HTTP Request Smuggling (CVE-2023-25690) against Apache mod_proxy, command injection in a backend PHP script for container access, internal pivot via SSRF and SSTI in a host Flask app, bash glob pattern matching oracle in a sudo vault script, and Python 2 input() eval RCE to root.

2026-08-17Linux
#HTTP Request Smuggling#CVE-2023-25690#Command Injection
Read
HackTheBoxInsane

Jail — HackTheBox Machine Writeup

An Insane Linux box with five stages: a beginner-friendly 32-bit stack buffer overflow behind a jail service, an NFS no_all_squash share that hands us the next user, a restricted-vim escape, and a crypto chain (Atbash -> RAR -> Wiener) that unlocks root.

2026-08-14Linux
#Buffer Overflow#NFS#SUID
Read