DarkZeroReturns - HTB
A two-forest Active Directory maze that only starts at a Node.js web app.
Logging - HTB
Logging starts with a routine Active Directory assessment, where seemingly ordinary artifacts and a bit of intuition gradually reveal a chain of misconfigurations leading to full compromise.
Silentium - HTB
An easy Linux machine featuring web enumeration, password reset vulnerability, container escaping, and internal service access.
DevArea - HTB
A medium-difficulty Linux machine featuring SOAP services, middleware exploitation, and multiple privilege escalation vectors.
Web Shell via Polyglot ZIP + PDF Upload Bypass
Bypassing file upload filters using ZIP/PDF polyglots or directory tricks.
Certificate - HTB
A hard Windows Active Directory machine featuring file upload vulnerabilities, lateral movement, and ADCS exploitation for privilege escalation.
Fluffy - HTB
Easy Windows AD chain starting from provided creds, NTLM capture via CVE-2025-24071, shadow credentials to WinRM, then ADCS abuse to Administrator.
Giveback - HTB
Medium Linux box chaining GiveWP deserialization RCE with container pivoting, PHP-CGI injection, Kubernetes secret theft, and runc debug abuse for root.