Writeup

  • HTB: Heal - Medium
    In this blog post, I will detail the process through which I successfully gained both user and root access on the HackTheBox machine, ‘Heal’.
  • HTB: UnderPass - Easy
    In this blog post, I will detail the process through which I successfully gained both user and root access on the HackTheBox machine, ‘UnderPass’.
  • HTB: Administrator - Medium
    In this blog post, I will detail the process through which I successfully gained both user and root access on the HackTheBox machine, ‘Administrator’.
  • HTB: LinkVortex - Easy
    In this blog post, I will detail the process through which I successfully gained both user and root access on the HackTheBox machine, ‘LinkVortex’.
  • HTB: Dog - Easy
    In this blog post, I will detail the process through which I successfully gained both user and root access on the HackTheBox machine, ‘Dog’.
  • HTB: Titanic - Easy
    In this blog post, I will detail the process through which I successfully gained both user and root access on the HackTheBox machine, ‘Titanic’.
  • HTB: CozyHosting - Easy
    In this box we identify session cookies that are stored in plaintext and are accessible to all users, decompile the Java code to analyze its functionality and leverage GTFOBins to escalate privileges effectively.
  • HTB: Topology - Easy
    Exploiting a website that contains a LaTeX vulnerability. Privilege escalation is possible by a process ran in the background on a specific shell file.
  • HTB: PC - Easy
    Exploited gRPC service with SQL injection to get SSH access, then escalated to root using a vulnerability in the discovered pyLoad service.
  • HTB: MonitorsTwo - Easy
    Exploited vulnerable cacti application for initial access, cracked MySQL credentials for SSH, and escalated to root through Docker vulnerability CVE-2021-41091.