- HTB: Heal - Medium
19 Mar '25
In this blog post, I will detail the process through which I successfully gained both user and root access on the HackTheBox machine, ‘Heal’.
- HTB: LinkVortex - Easy
13 Mar '25
In this blog post, I will detail the process through which I successfully gained both user and root access on the HackTheBox machine, ‘LinkVortex’.
- HTB: Dog - Easy
10 Mar '25
In this blog post, I will detail the process through which I successfully gained both user and root access on the HackTheBox machine, ‘Dog’.
- HTB: Titanic - Easy
9 Mar '25
In this blog post, I will detail the process through which I successfully gained both user and root access on the HackTheBox machine, ‘Titanic’.
- Vim in Tmux configuration
14 Dec '24
In this post, I’ll share my daily-use tmux configuration. This setup enables Vim keybindings, seamless copy-pasting, and includes a logging feature to capture terminal output.
- HTB: CozyHosting - Easy
2 Sep '23
In this box we identify session cookies that are stored in plaintext and are accessible to all users, decompile the Java code to analyze its functionality and leverage GTFOBins to escalate privileges effectively.
- HTB: Topology - Easy
10 Jun '23
Exploiting a website that contains a LaTeX vulnerability. Privilege escalation is possible by a process ran in the background on a specific shell file.
- HTB: PC - Easy
21 May '23
Exploited gRPC service with SQL injection to get SSH access, then escalated to root using a vulnerability in the discovered pyLoad service.
- HTB: MonitorsTwo - Easy
29 Apr '23
Exploited vulnerable cacti application for initial access, cracked MySQL credentials for SSH, and escalated to root through Docker vulnerability CVE-2021-41091.
- HTB: Inject - Easy
11 Mar '23
Exploited image parameter LFI to enumerate system, used Spring Cloud Function vulnerability for initial access, and escalated to root through a writable Ansible playbook.