DarkZeroReturns - HTB
A two-forest Active Directory maze that only starts at a Node.js web app.
Logging - HTB
Logging starts with a routine Active Directory assessment, where seemingly ordinary artifacts and a bit of intuition gradually reveal a chain of misconfigurations leading to full compromise.
Silentium - HTB
An easy Linux machine featuring web enumeration, password reset vulnerability, container escaping, and internal service access.
DevArea - HTB
A medium-difficulty Linux machine featuring SOAP services, middleware exploitation, and multiple privilege escalation vectors.
Expressway - HTB
Linux target using IKE aggressive mode to crack PSK, SSH as ike, and sudo chroot vulnerability (CVE-2025-32463) for root.
HackNet - HTB
Medium Linux machine with Django SSTI in a social feed, cache deserialization abuse, GPG passphrase cracking, and DB backup recovery for root.
Imagery - HTB
Medium Linux box using blind XSS for admin session theft, LFI to source read, ImageMagick command injection for RCE, pyAesCrypt backup decryption, and Charcol cron abuse for root.
CCTV - HTB
Easy Linux CCTV machine abusing ZoneMinder and MotionEye flaws through SQL injection and escalation. [Unintended]