DarkZeroReturns - HTB
A two-forest Active Directory maze that only starts at a Node.js web app.
Logging - HTB
Logging starts with a routine Active Directory assessment, where seemingly ordinary artifacts and a bit of intuition gradually reveal a chain of misconfigurations leading to full compromise.
Silentium - HTB
An easy Linux machine featuring web enumeration, password reset vulnerability, container escaping, and internal service access.
DevArea - HTB
A medium-difficulty Linux machine featuring SOAP services, middleware exploitation, and multiple privilege escalation vectors.
Conversor - HTB
Easy Linux box abusing XSLT injection to write a cron-executed script, then harvesting local SQLite creds and escalating via needrestart.
Eighteen - HTB
Easy Windows box starting with MSSQL creds, pivoting to WinRM via cracked app DB hashes, then abusing dMSA badSuccessor for Administrator access.
Pterodactyl - HTB
Medium Linux box exploiting a Pterodactyl Panel locale RCE, then escalating via polkit/udisks chained CVEs on openSUSE.
Guardian - HTB
Linux box with IDOR in student portal, XSS via PhpSpreadsheet, CSRF admin creation, PHP filter chain RCE, and sudo abuse for root.