Writeups
Detailed walkthroughs covering the full kill chain — from recon to root.
Ledger — TryHackMe Writeup
A comprehensive writeup for the Medium TryHackMe machine Ledger. We exploit an anonymous LDAP directory dump leaking credentials inside user descriptions, analyze the AD forest and ESC1 template misconfigurations using pharaohound, navigate around a stubborn PKINIT KDC error, and achieve Domain Admin compromise by abusing guest-level GenericWrite permissions over the domain controller via Resource-Based Constrained Delegation (RBCD).
Temple — TryHackMe Writeup
A comprehensive writeup for the Medium TryHackMe machine Temple, detailing recursive directory discovery to uncover a hidden registration endpoint, character-filtered Jinja2 SSTI bypassed via hex-escaped attributes and cycler globals to land RCE as bill, and escalating to root by weaponizing an auto-reloading, world-writable Logstash pipeline.
Contrabando — TryHackMe Writeup
A Hard-rated TryHackMe machine featuring HTTP Request Smuggling (CVE-2023-25690) against Apache mod_proxy, command injection in a backend PHP script for container access, internal pivot via SSRF and SSTI in a host Flask app, bash glob pattern matching oracle in a sudo vault script, and Python 2 input() eval RCE to root.
Jail — HackTheBox Machine Writeup
An Insane Linux box with five stages: a beginner-friendly 32-bit stack buffer overflow behind a jail service, an NFS no_all_squash share that hands us the next user, a restricted-vim escape, and a crypto chain (Atbash -> RAR -> Wiener) that unlocks root.
Ghostlink — HackTheBox Machine Writeup
A Hard Windows Active Directory box: leak internal hosts over anonymous MQTT, coerce a service account over a health-check, relay it to a file-share, abuse a double URL-encoded path traversal to steal a KeePass vault, land a Gogs symlink RCE (CVE-2025-8110), then abuse ESC11 to forge a Domain Controller certificate.
Forest — HackTheBox Machine Writeup
An Easy Windows AD machine involving AS-REP Roasting, nested group ACL abuse (Account Operators → Exchange Windows Permissions → WriteDacl → DCSync), and pass-the-hash. Analysis powered by pharaohound.
Active — HackTheBox Machine Writeup
An Easy Windows domain controller box: anonymous SMB access to a DFS Replication share leaks a GPP password, which unlocks Kerberoasting of the Administrator account and full Domain Admin compromise.
Sauna — HackTheBox Machine Writeup
A classic easy Active Directory box: usernames harvested from a public web page feed an AS-REP roast, and a forgotten AutoLogon password unlocks a DCSync-capable service account.
WhiteRabbit — HackTheBox Machine Writeup
An Insane Linux box that chains an Uptime Kuma status page leak of internal subdomains into a WikiJS article exposing an n8n workflow's HMAC secret and injectable SQL, an error-based SQLi dump of a command log revealing a restic backup repository, a password-cracked 7z archive yielding a container SSH key, a sudo-restic abuse to steal the host user's SSH key, and a time-seeded password generator reverse-engineered down to the exact millisecond to become root.
Busqueda — HackTheBox Machine Writeup
An Easy Linux box that starts with an eval() injection in Searchor 2.4.0 behind a Flask app, leads to credential harvesting from a leaked .git/config, and ends with a relative-path hijack of a sudo-run system script.
Nexus — HackTheBox Machine Writeup
An Easy Linux box chaining a Gitea git-history password leak into a Krayin CRM file-upload RCE, a .env credential reuse for SSH, and a root-run template-sync script abused with crafted git tree objects containing a literal '..' directory to write a sudoers rule.
Hexecution — HackTheBox Challenge Writeup
Reversing a kitchen-themed custom virtual machine ('cook') on Linux, analyzing custom assembly opcodes ('recipe.asm'), reversing a two-stage permutation algorithm, and automating key recovery and VM emulation in Python.
Neural Detonator — HackTheBox Challenge Writeup
Reversing a malicious Keras model ('mlcious.keras') that hides a two-stage Python payload: a Lambda layer embedding a base64+marshal trampoline, a weight-derived XOR key, and an encrypted flag steganographically stored in a Dense layer's bias.
Packed Light — TryHackMe Challenge Writeup
A TryHackMe Network Forensics challenge involving PCAP inspection of HTTP C2 traffic, extracting a Python keylogger C2 script, reverse engineering its XOR encryption quirk, and recovering the keystroke stream from HTTP cookie headers — plus an automated Python solver script.
Complimentary — TryHackMe Writeup
An easy-rated cloud machine exploring AWS Cognito Identity Pools, overprivileged unauthenticated IAM roles, and DynamoDB data exfiltration via guest credentials — plus a full automation script to solve it in seconds.
Extract — TryHackMe Writeup
A TryHackMe machine involving Server-Side Request Forgery (SSRF) escalated to internal service interaction via Gopher, bypassing Next.js middleware authentication, and exploiting PHP object serialization for 2FA bypass.
El Bandito — TryHackMe Writeup
A comprehensive writeup for the TryHackMe El Bandito machine, covering WebSocket Request Smuggling via SSRF to access restricted Spring Boot Actuators, and exploiting a chat application to capture a user's cookie via HTTP Request Smuggling.
Clocky — TryHackMe Writeup
A medium-rated TryHackMe machine involving source code recovery from an exposed zip archive, predictable password-reset token forgery via SHA-1 timestamp abuse, SSRF filter bypass using an open redirect, MySQL credential extraction, and caching_sha2_password hash cracking to escalate to root.
Include — TryHackMe Writeup
A medium-rated TryHackMe machine combining Broken Object Property Level Authorization to escalate to admin on a Node.js app, SSRF via the admin settings panel to exfiltrate internal API credentials, LFI on the System Monitoring Portal to extract /etc/passwd, and SSH brute-forcing with Hydra to gain shell access and capture the final flag.
Curveware — HackTheBox Challenge Writeup
Reversing a Windows ransomware binary, exploiting ECDSA partial nonce leakage (40-bit LSB), and recovering the AES-256 key via LLL lattice reduction on the Hidden Number Problem (HNP).
SpookyPass — HackTheBox Challenge Writeup
A beginner-friendly Hack The Box Reverse Engineering challenge involving static binary analysis, hardcoded password extraction via string inspection, and C decompiler tracing with Ghidra.
Hammer — TryHackMe Writeup
Chaining a leaked email in an open log, a 4-digit recovery-code brute force, and an HS256 JWT forgery to reach command execution on a custom port-1337 web app.
Headless — HackTheBox Writeup
An easy-rated Linux machine involving blind XSS cookie exfiltration from an admin dashboard, command injection in a reporting feature, and privilege escalation via a PAM authentication backdoor injected through a relative path hijack in a sudo script.
