Eye of Ra
SECURITY RESEARCHAsbawy

Writeups

Detailed walkthroughs covering the full kill chain — from recon to root.

Difficulty
Vector / Category
TryHackMeMedium

Ledger — TryHackMe Writeup

A comprehensive writeup for the Medium TryHackMe machine Ledger. We exploit an anonymous LDAP directory dump leaking credentials inside user descriptions, analyze the AD forest and ESC1 template misconfigurations using pharaohound, navigate around a stubborn PKINIT KDC error, and achieve Domain Admin compromise by abusing guest-level GenericWrite permissions over the domain controller via Resource-Based Constrained Delegation (RBCD).

2026-09-17Windows
#Active Directory#LDAP#Credential Leak
Read
TryHackMeMedium
AUTOSOLVE

Temple — TryHackMe Writeup

A comprehensive writeup for the Medium TryHackMe machine Temple, detailing recursive directory discovery to uncover a hidden registration endpoint, character-filtered Jinja2 SSTI bypassed via hex-escaped attributes and cycler globals to land RCE as bill, and escalating to root by weaponizing an auto-reloading, world-writable Logstash pipeline.

2026-09-17Linux
#Web#SSTI#Flask
Read
TryHackMeHard

Contrabando — TryHackMe Writeup

A Hard-rated TryHackMe machine featuring HTTP Request Smuggling (CVE-2023-25690) against Apache mod_proxy, command injection in a backend PHP script for container access, internal pivot via SSRF and SSTI in a host Flask app, bash glob pattern matching oracle in a sudo vault script, and Python 2 input() eval RCE to root.

2026-08-17Linux
#HTTP Request Smuggling#CVE-2023-25690#Command Injection
Read
HackTheBoxInsane

Jail — HackTheBox Machine Writeup

An Insane Linux box with five stages: a beginner-friendly 32-bit stack buffer overflow behind a jail service, an NFS no_all_squash share that hands us the next user, a restricted-vim escape, and a crypto chain (Atbash -> RAR -> Wiener) that unlocks root.

2026-08-14Linux
#Buffer Overflow#NFS#SUID
Read
HackTheBoxHard
AUTOSOLVE

Ghostlink — HackTheBox Machine Writeup

A Hard Windows Active Directory box: leak internal hosts over anonymous MQTT, coerce a service account over a health-check, relay it to a file-share, abuse a double URL-encoded path traversal to steal a KeePass vault, land a Gogs symlink RCE (CVE-2025-8110), then abuse ESC11 to forge a Domain Controller certificate.

2026-08-13Windows
#Windows#Active Directory#MQTT
Read
HackTheBoxEasy

Forest — HackTheBox Machine Writeup

An Easy Windows AD machine involving AS-REP Roasting, nested group ACL abuse (Account Operators → Exchange Windows Permissions → WriteDacl → DCSync), and pass-the-hash. Analysis powered by pharaohound.

2026-08-09Windows
#Active Directory#AS-REP Roasting#BloodHound
Read
HackTheBoxEasy

Active — HackTheBox Machine Writeup

An Easy Windows domain controller box: anonymous SMB access to a DFS Replication share leaks a GPP password, which unlocks Kerberoasting of the Administrator account and full Domain Admin compromise.

2026-08-06Windows
#Active Directory#SMB#GPP
Read
HackTheBoxEasy

Sauna — HackTheBox Machine Writeup

A classic easy Active Directory box: usernames harvested from a public web page feed an AS-REP roast, and a forgotten AutoLogon password unlocks a DCSync-capable service account.

2026-08-06Windows
#Active Directory#AS-REP Roasting#Kerberos
Read
HackTheBoxInsane

WhiteRabbit — HackTheBox Machine Writeup

An Insane Linux box that chains an Uptime Kuma status page leak of internal subdomains into a WikiJS article exposing an n8n workflow's HMAC secret and injectable SQL, an error-based SQLi dump of a command log revealing a restic backup repository, a password-cracked 7z archive yielding a container SSH key, a sudo-restic abuse to steal the host user's SSH key, and a time-seeded password generator reverse-engineered down to the exact millisecond to become root.

2026-08-04Linux
#Web#Uptime Kuma#WikiJS
Read
HackTheBoxEasy
AUTOSOLVE

Busqueda — HackTheBox Machine Writeup

An Easy Linux box that starts with an eval() injection in Searchor 2.4.0 behind a Flask app, leads to credential harvesting from a leaked .git/config, and ends with a relative-path hijack of a sudo-run system script.

2026-08-03Linux
#Web#Flask#Searchor
Read
HackTheBoxEasy
AUTOSOLVE

Nexus — HackTheBox Machine Writeup

An Easy Linux box chaining a Gitea git-history password leak into a Krayin CRM file-upload RCE, a .env credential reuse for SSH, and a root-run template-sync script abused with crafted git tree objects containing a literal '..' directory to write a sudoers rule.

2026-08-03Linux
#Web#Gitea#Git History Leak
Read
HackTheBoxHard
AUTOSOLVE

Hexecution — HackTheBox Challenge Writeup

Reversing a kitchen-themed custom virtual machine ('cook') on Linux, analyzing custom assembly opcodes ('recipe.asm'), reversing a two-stage permutation algorithm, and automating key recovery and VM emulation in Python.

2026-08-01Linux
#Reverse Engineering#Custom VM#Custom ISA
Read
HackTheBoxHard
AUTOSOLVE

Neural Detonator — HackTheBox Challenge Writeup

Reversing a malicious Keras model ('mlcious.keras') that hides a two-stage Python payload: a Lambda layer embedding a base64+marshal trampoline, a weight-derived XOR key, and an encrypted flag steganographically stored in a Dense layer's bias.

2026-08-01Linux
#Machine Learning#Keras Model#Lambda Layer
Read
TryHackMeEasy
AUTOSOLVE

Packed Light — TryHackMe Challenge Writeup

A TryHackMe Network Forensics challenge involving PCAP inspection of HTTP C2 traffic, extracting a Python keylogger C2 script, reverse engineering its XOR encryption quirk, and recovering the keystroke stream from HTTP cookie headers — plus an automated Python solver script.

2026-07-31
#Network Forensics#PCAP Analysis#Wireshark
Read
TryHackMeEasy
AUTOSOLVE

Complimentary — TryHackMe Writeup

An easy-rated cloud machine exploring AWS Cognito Identity Pools, overprivileged unauthenticated IAM roles, and DynamoDB data exfiltration via guest credentials — plus a full automation script to solve it in seconds.

2026-07-30Misc
#Cloud#AWS#Cognito
Read
TryHackMeHard

Extract — TryHackMe Writeup

A TryHackMe machine involving Server-Side Request Forgery (SSRF) escalated to internal service interaction via Gopher, bypassing Next.js middleware authentication, and exploiting PHP object serialization for 2FA bypass.

2026-07-25Linux
#Web#SSRF#Gopher
Read
TryHackMeHard

El Bandito — TryHackMe Writeup

A comprehensive writeup for the TryHackMe El Bandito machine, covering WebSocket Request Smuggling via SSRF to access restricted Spring Boot Actuators, and exploiting a chat application to capture a user's cookie via HTTP Request Smuggling.

2026-07-23Linux
#Web#Request Smuggling#WebSocket
Read
TryHackMeMedium

Clocky — TryHackMe Writeup

A medium-rated TryHackMe machine involving source code recovery from an exposed zip archive, predictable password-reset token forgery via SHA-1 timestamp abuse, SSRF filter bypass using an open redirect, MySQL credential extraction, and caching_sha2_password hash cracking to escalate to root.

2026-07-22Linux
#Web#Source Code Analysis#Token Forgery
Read
TryHackMeMedium

Include — TryHackMe Writeup

A medium-rated TryHackMe machine combining Broken Object Property Level Authorization to escalate to admin on a Node.js app, SSRF via the admin settings panel to exfiltrate internal API credentials, LFI on the System Monitoring Portal to extract /etc/passwd, and SSH brute-forcing with Hydra to gain shell access and capture the final flag.

2026-07-22Linux
#Web#SSRF#LFI
Read
HackTheBoxHard

Curveware — HackTheBox Challenge Writeup

Reversing a Windows ransomware binary, exploiting ECDSA partial nonce leakage (40-bit LSB), and recovering the AES-256 key via LLL lattice reduction on the Hidden Number Problem (HNP).

2026-07-21Windows
#Cryptography#Elliptic Curve#Hidden Number Problem
Read
HackTheBoxVery Easy

SpookyPass — HackTheBox Challenge Writeup

A beginner-friendly Hack The Box Reverse Engineering challenge involving static binary analysis, hardcoded password extraction via string inspection, and C decompiler tracing with Ghidra.

2026-07-21Misc
#Reverse Engineering#ELF#Binary Analysis
Read
TryHackMeMedium

Hammer — TryHackMe Writeup

Chaining a leaked email in an open log, a 4-digit recovery-code brute force, and an HS256 JWT forgery to reach command execution on a custom port-1337 web app.

2026-07-20Linux
#Web#JWT#OTP-Bypass
Read
HackTheBoxEasy

Headless — HackTheBox Writeup

An easy-rated Linux machine involving blind XSS cookie exfiltration from an admin dashboard, command injection in a reporting feature, and privilege escalation via a PAM authentication backdoor injected through a relative path hijack in a sudo script.

2026-07-18Linux
#XSS#Cookie Stealing#Command Injection
Read