asbawy:~/writeups$ls -la --sort=date
/writeups_
Detailed walkthroughs covering the full kill chain — from recon to root. Each write-up documents the exact tools, techniques, and thought process used.
2 machines pwned2 platforms
▸all_writeups(2)
Medium: 1Easy: 1
TryHackMe·Machine
Linux3.5
Hammer — TryHackMe Writeup
Chaining a leaked email in an open log, a 4-digit recovery-code brute force, and an HS256 JWT forgery to reach command execution on a custom port-1337 web app.
WebJWTOTP-BypassRCE
Medium2026-07-2012 min
HackTheBox·Machine
Linux4.6
Headless — HackTheBox Writeup
An easy-rated Linux machine involving blind XSS cookie exfiltration from an admin dashboard, command injection in a reporting feature, and privilege escalation via a PAM authentication backdoor injected through a relative path hijack in a sudo script.
XSSCookie StealingCommand InjectionSudo Abuse+5
Easy2026-07-1810 min
