DarkZeroReturns - HTB
A two-forest Active Directory maze that only starts at a Node.js web app.
Logging - HTB
Logging starts with a routine Active Directory assessment, where seemingly ordinary artifacts and a bit of intuition gradually reveal a chain of misconfigurations leading to full compromise.
Silentium - HTB
An easy Linux machine featuring web enumeration, password reset vulnerability, container escaping, and internal service access.
DevArea - HTB
A medium-difficulty Linux machine featuring SOAP services, middleware exploitation, and multiple privilege escalation vectors.
Low access (Privilege escalation)
Low access (Privilege escalation) techniques and commands for Active Directory security assessment.
RustyKey - HTB
Hard Windows machine with Kerberos time abuse, AD ACL misconfigurations, 7-Zip shell extension hijack, and SPN-less RBCD for domain admin.
UnderPass - HTB
Easy Linux target using SNMP to leak RADIUS secrets and user creds, then SSH access and service abuse for root.
Web Shell via Polyglot ZIP + PDF Upload Bypass
Bypassing file upload filters using ZIP/PDF polyglots or directory tricks.