Locked Posts

Artificial - HTB
An Easy-rated HTB box exploiting TensorFlow deserialization RCE to gain initial access, followed by backup abuse, pas...
BigBang - HTB
Exploitation of a WordPress and Grafana setup via leaked credentials, JWT abuse on a custom APK API, and command inje...
Certificate - HTB
Web-to-root HTB box featuring a ZIP upload bypass with null-byte injection, credential harvesting, shadow credential ...
Environment HTB
Initial foothold via broken remember-me parameter, preprod environment bypass, PHP webshell upload, GPG decryption fo...
Fluffy - HTB
Initial access via SMB creds, BloodHound enumeration, NTLMv2 cracking, shadow credentials, and Administrator via cert...
Mirage - HTB
Windows AD lab with misconfigurations across DNS, LDAP, and certificate services, leading to full domain compromise.
Outbound - HTB
nitial foothold via Roundcube exploit, user access through decrypted IMAP creds, and root via sudo misconfiguration i...
Planning - HTB
Initial access via admin credentials, exploit of vulnerable Grafana service, enumeration of Docker and environment va...
Puppy - HTB
Active Directory attack chain on Puppy involving BloodHound analysis, GenericWrite abuse, KeePass file cracking, and ...
Rustykey - HTB
Full Active Directory exploitation on Rusty Key from initial access to domain admin. Includes SPN cracking, AddSelf a...
Sorcery -HTB
A brutal, multi-layered HTB box featuring Cypher injection, Docker abuse, custom CA phishing, Kafka RCE, and FreeIPA ...
Tombwatcher - HTB
Initial access with user credentials, SPN abuse via targetedKerberoast, GMSA password read, cross-user escalation, ac...
Voleur - HTB
Full Domain Compromise via DPAPI Credential Theft and AD Dump
WhiteRabbit - HTB
Full walkthrough of WhiteRabbit HTB box involving vhost enumeration, SQLi via HMAC signature spoofing, restic backup ...
Era - HTB
Blind RCE through a custom file reader and AV evasion attempts via binary replacement.
Editor - HTB
A misconfigured content system where user access leads to unexpected control.
Cobblestone - HTB
A web-focused HTB box leveraging SQL injection, and an exposed Cobbler XML-RPC API—leading to a chained privilege esc...
Codetwo - HTB
Initial access via █████ RCE on web app → SSH as █████ (cracked creds) → npbackup-cli → root
Expressway - HTB
Compromised Expressway HTB from VPN user to root via IKEv1 PSK and Sudo privilege escalation
Guardian - HTB
A university portal with weak authentication and insecure web features leads to account takeover, chained into exploi...
Imagery - HTB
From XSS to cookie theft, LFI for secrets, then abusing ImageMagick injection and a custom backup utility for root.
Previous - HTB
Enumeration of a Next.js application leads to sensitive information disclosure and misuse of Terraform for privilege ...
Soulmate - HTB
Compromising a matchmaking webapp through CrushFTP auth bypass and chaining Erlang's remote shell for privilege escal...