Logging - HTB
Logging starts with a routine Active Directory assessment, where seemingly ordinary artifacts and a bit of intuition gradually reveal a chain of misconfigurations leading to full compromise.
Silentium - HTB
An easy Linux machine featuring web enumeration, password reset vulnerability, container escaping, and internal service access.
DevArea - HTB
A medium-difficulty Linux machine featuring SOAP services, middleware exploitation, and multiple privilege escalation vectors.
Kobold - HTB
An easy-difficulty Linux machine featuring multiple web vulnerabilities.
Artificial - HTB
An easy Linux machine featuring AI model exploitation and backup abuse for privilege escalation.
Environment - HTB
Medium Linux box abusing an env parameter to bypass login, then file upload to webshell and GPG key decryption to SSH, finishing with BASH_ENV sudo abuse.
BigBang - HTB
Hard Linux box chaining WordPress LFI, DB creds, Grafana hash cracking, and an Android API command injection for root.
Eighteen - HTB
Easy Windows box starting with MSSQL creds, pivoting to WinRM via cracked app DB hashes, then abusing dMSA badSuccessor for Administrator access.