Blog

CTF writeups, security research, and technical articles.

Category

Tags

Timeline

Showing 182 posts

LOCKED writeup

HTB: DevArea Writeup

DevArea is a Medium-difficulty Linux machine released as part of HTB season 10.

#htb #writeup #s10
+1
LOCKED writeup

HTB: Kobold Writeup

Kobold is a Easy-difficulty Linux machine released as part of HTB season 10.

#htb #writeup #s10
+1
LOCKED writeup

HTB: CCTV Writeup

CCTV is a Easy-difficulty Linux machine released as part of HTB season 10.

#htb #writeup #s10
+1
LOCKED writeup

HTB: Pirate Writeup

Pirate is a Hard-difficulty Windows machine released as part of HTB Season 10. Exploit Pre-Windows 2000 machine accounts, dump gMSA hashes, pivot through internal networks, and chain RBCD relay with SPN injection to achieve full Domain Admin.

#htb #writeup #s10
+4
guides

Ephemeral DigitalOcean Build Pipeline for Kasm Images (GitHub Actions)

Use GitHub Actions to provision an ephemeral amd64 DigitalOcean droplet, build Docker images natively, push to registry, and tear everything down automatically.

#github-actions #digitalocean #docker
+4
guides

How to Add a Custom Docker Image to Kasm Workspaces (End-to-End)

Build a custom Docker image for Kasm Workspaces, push it to a registry, and register it so it appears as a selectable workspace.

#kasm #docker #workspaces
+3
LOCKED writeup

HTB: Interpreter Writeup

Interpreter is a Medium-difficulty Linux machine released as part of HTB season 10.

#htb #writeup #s10
+1
guides

Deploying Kasm Workspaces on DigitalOcean: Secure HTTPS + Domain + Hardening

Deploy Kasm Workspaces on a DigitalOcean droplet, attach a domain, enable HTTPS with Let's Encrypt, and harden the server for secure remote browser access.

#kasm #digitalocean #ubuntu
+5
LOCKED writeup

HTB: Pterodactyl Writeup

Pterodactyl is a Medium-difficulty Linux machine released as part of HTB season 10.

#htb #writeup #s10
+1
LOCKED writeup

HTB: WingData Writeup

WingData is a Easy-difficulty Linux machine released as part of HTB season 10.

#htb #writeup #s10
+1
guides

Safe Git Workflow for Reviewing Remote Server Changes

Download files from a remote server, compare them safely in a local branch, and decide whether to discard, merge, or push changes to a remote repository.

#git #devops #workflow
+4
meta

Welcome to d3v0mi.com

First post on the blog — what to expect from this site and what I'll be writing about.

#meta #announcement
guides

Ubuntu Remote Workstation on DigitalOcean: Xfce + xRDP + GlobalProtect

Build a fast, cloud-based Ubuntu workstation using Xfce and xRDP, then connect it securely to corporate networks using OpenConnect (GlobalProtect-compatible).

#ubuntu #rdp #xfce
+5
LOCKED writeup

HTB: Facts Writeup

Facts is a Easy-difficulty Linux machine released as part of HTB season 10.

#htb #writeup #s10
+1
writeup

2025 Cyber Apocalypse: Crypto Traces

Exploit AES-CTR mode vulnerability in a custom IRC-like server with reused counter initialization

#htb #ctf #cryptography
+3
writeup

2025 Cyber Apocalypse: Silent Trap

Analyze compromised system through network traffic and memory forensics to uncover malware deployment and credential theft

#htb #ctf #forensics
+4
writeup

2025 Cyber Apocalypse: Stealth Invasion

Analyze memory dump of compromised Linux system to uncover malicious Chrome extension and credential theft

#htb #ctf #forensics
+4
writeup

2025 Cyber Apocalypse: Arcane Auctions

Identify and exploit secure coding vulnerabilities in a web application

#htb #ctf #secure-coding
+2
writeup

2025 Cyber Apocalypse: Web Cyber Attack

Exploit path traversal vulnerability in a PHP web application to extract the flag

#htb #ctf #web
+3
writeup

HTB: code Writeup

code is a Easy-difficulty Linux machine from HackTheBox.

#htb #writeup #linux
+2
writeup

HTB: EscapeTwo Writeup

EscapeTwo is an Easy-difficulty Windows Active Directory machine from HackTheBox featuring SMB enumeration, credential extraction from Excel files, SQL Server exploitation, and Kerberos abuse.

#htb #writeup #windows
+7
writeup

2024 Hack The Boo: Ghostly Persistence

Analyze Windows event logs to uncover two-part flag hidden in PowerShell command execution and log artifacts

#htb #ctf #forensics
+3
writeup

2024 Hack The Boo: TerrorFryer

Reverse engineer a binary that uses Fisher-Yates shuffling to find the original input string

#htb #ctf #reversing
+3
writeup

2024 Hack The Boo: Practice

Reverse engineer encoded strings from JavaScript code to extract hidden data

#htb #ctf #forensics
+2
writeup

2024 Hack The Boo: Cursed Stale Policy

Exploit stale cache policy vulnerabilities in a web application with Content Security Policy analysis

#htb #ctf #web
+3
writeup

2024 Hack The Boo: Waywitch

Exploit JWT authentication bypass and token manipulation in a Node.js web application

#htb #ctf #web
+3
writeup

HTB: inflitrator Writeup

inflitrator is a Hard-difficulty Windows machine from HackTheBox.

#htb #writeup #windows
+4
writeup

HTB: PermX Writeup

PermX is an Easy-difficulty Linux machine from HackTheBox.

#htb #writeup #linux
writeup

HTB: blazorized Writeup

blazorized is a Hard-difficulty Windows domain controller machine from HackTheBox.

#htb #writeup #windows
+7
writeup

HTB: axlle Writeup

axlle is a Hard-difficulty Windows machine from HackTheBox.

#htb #writeup #windows
+5
writeup

HTB: editorial Writeup

editorial is an Easy-difficulty Linux machine from HackTheBox featuring SSRF vulnerability and GitPython RCE.

#htb #writeup #linux
+6
writeup

HTB: blurry Writeup

blurry is a Medium-difficulty Linux machine from HackTheBox.

#htb #writeup #linux
+3
writeup

HTB: freelancer Writeup

freelancer is a Hard-difficulty Windows machine from HackTheBox.

#htb #writeup #windows
+3
writeup

HTB: boardlight Writeup

boardlight is an Easy-difficulty Linux machine from HackTheBox featuring Dolibarr ERP/CRM exploitation.

#htb #writeup #linux
+5
writeup

2024 Business CTF - Vault of Hope: Recruitment

Smart contract challenge requiring multi-step validation including hacking skills, stealth, engineering, and demolition expertise

#htb #ctf #blockchain
+2
writeup

2024 Business CTF - Vault of Hope: Exciting Outpost Recon

Cryptography challenge using known plaintext attack to break XOR-based encryption with SHA-256 key derivation

#htb #ctf #crypto
+3
writeup

2024 Business CTF - Vault of Hope: Protrude

AWS IAM and cloud security challenge involving credential enumeration and permission analysis

#htb #ctf #cloud
+3
writeup

2024 Business CTF - Vault of Hope: Scurried

AWS IAM role ARN extraction challenge using role ID to construct proper ARN format

#htb #ctf #cloud
+3
writeup

2024 Business CTF - Vault of Hope: Submerged

Full penetration test of web server with SPIP CMS exploitation, leading to initial access and system compromise

#htb #ctf #fullpwn
+3
writeup

2024 Business CTF - Vault of Hope: Caving

Windows forensics challenge analyzing PowerShell logs and obfuscated scripts to detect intrusion attempts

#htb #ctf #forensics
+3
writeup

2024 Business CTF - Vault of Hope: Survivor

Full penetration test of Ubuntu web server with SSH and HTTP services

#htb #ctf #fullpwn
+2
writeup

2024 Business CTF - Vault of Hope: Swarm

Full penetration test with multi-service enumeration including SSH and HTTP on multiple ports

#htb #ctf #fullpwn
+2
writeup

2024 Business CTF - Vault of Hope: Sneak Peak

ICS/SCADA challenge involving Modbus protocol communication with industrial control systems

#htb #ctf #ics
+3
writeup

2024 Business CTF - Vault of Hope: Rev FlagCasino

Binary reverse engineering challenge involving libc random number prediction and brute-force seed discovery

#htb #ctf #reversing
+3
writeup

HTB: magicgarden Writeup

magicgarden is a Insane-difficulty Linux machine from HackTheBox.

#htb #writeup #linux
+3
writeup

HTB: solarlab Writeup

solarlab is a Medium-difficulty Windows machine featuring SMB enumeration, credential extraction from Excel files, ReportHub web application exploitation, and CVE-2023-33733 (ReportLab RCE).

#htb #writeup #windows
+6
writeup

HTB: mailing Writeup

mailing is a Easy-difficulty Windows machine from HackTheBox.

#htb #writeup #windows
+5
writeup

HTB: Intuition Writeup

Intuition is a Hard-difficulty Linux machine from HackTheBox.

#htb #writeup #linux
+3
writeup

HTB: usage Writeup

usage is a Easy-difficulty Linux machine from HackTheBox.

#htb #writeup #linux
+5
writeup

HTB: iClean Writeup

iClean (Capiclean) is a Medium-difficulty Linux machine featuring Flask SSTI exploitation and JWT-based authentication bypass.

#htb #writeup #linux
+6
writeup

HTB: mist Writeup

mist is a Insane-difficulty Windows machine from HackTheBox.

#htb #writeup #windows
+4
writeup

HTB: wifinetictwo Writeup

wifinetictwo is a Medium-difficulty Linux machine featuring OpenPLC Runtime exploitation and WiFi security attacks.

#htb #writeup #linux
+5
writeup

2024 Cyber Apocalypse: Dynasty

Reverse a custom Caesar cipher variant with position-dependent shift

#htb #ctf #crypto
+3
writeup

2024 Cyber Apocalypse: Blunt

Exploit weak Diffie-Hellman with small parameters to recover shared secret and decrypt AES-CBC ciphertext

#htb #ctf #crypto
+3
writeup

2024 Cyber Apocalypse: Russian Roulette

Exploit a weak Diffie-Hellman key exchange with small prime modulus

#htb #ctf #blockchain
+3
writeup

2024 Cyber Apocalypse: Iced Tea

Identify TEA cipher from DELTA constant and decrypt ECB-mode ciphertext with known key

#htb #ctf #crypto
+3
writeup

2024 Cyber Apocalypse: Permuted

Break Diffie-Hellman over permutation groups using DLP algorithm on permutation cycles

#htb #ctf #crypto
+3
writeup

2024 Cyber Apocalypse: Makeshift

Reverse a trivial string transformation: reverse flag then rearrange groups of three

#htb #ctf #crypto
+2
writeup

2024 Cyber Apocalypse: Primary Knowledge

Exploit RSA implementation using prime modulus instead of semiprime

#htb #ctf #crypto
+2
writeup

2024 Cyber Apocalypse: Data Siege

Exploit ActiveMQ vulnerability, extract .NET malware, decrypt C2 communications, and recover multi-part flag

#htb #ctf #forensics
+5
writeup

2024 Cyber Apocalypse: Phreaky

Analyze PCAP to detect SMTP exfiltration and reconstruct PDF from parts

#htb #ctf #forensics
+4
writeup

2024 Cyber Apocalypse: Confinement

Analyze disk image to extract and decrypt ransomware, then decrypt encrypted files

#htb #ctf #forensics
+4
writeup

2024 Cyber Apocalypse: An Unusual Sighting

Extract flag from HTML content hidden in email file

#htb #ctf #forensics
+3
writeup

2024 Cyber Apocalypse: Fake Boost

Extract obfuscated PowerShell from PCAP, deobfuscate, decrypt AES payload, and recover flag parts

#htb #ctf #forensics
+5
writeup

2024 Cyber Apocalypse: Game Invitation

Analyze malicious DOCM file, extract XOR-encrypted payload, decrypt JavaScript layers, and recover C2 beacon

#htb #ctf #forensics
+5
writeup

2024 Cyber Apocalypse: Oblique Final

Analyze memory dump with Volatility and extract artifacts from system state

#htb #ctf #forensics
+3
writeup

2024 Cyber Apocalypse: Pursue The Tracks

Analyze MFT records to answer forensic questions about file activity

#htb #ctf #forensics
+4
writeup

2024 Cyber Apocalypse: Urgent

Decode base64 email attachments and URL-decode payloads to uncover phishing attack details

#htb #ctf #forensics
+4
writeup

2024 Cyber Apocalypse: Character

Automate character-by-character flag extraction from server using socket programming

#htb #ctf #misc
+3
writeup

2024 Cyber Apocalypse: Hardware Rids

Interface with W25Q128 flash memory via SPI to read flag from device

#htb #ctf #hardware
+4
writeup

2024 Cyber Apocalypse: Cubicle Riddle

Construct Python bytecode to find min/max values and answer the cube's riddle

#htb #ctf #misc
+3
writeup

2024 Cyber Apocalypse: Stop Drop and Roll

Script game responses to survive The Fray video game challenge

#htb #ctf #misc
+3
writeup

2024 Cyber Apocalypse: Unbreakable

Bypass blacklist filters in Python eval() to read the flag

#htb #ctf #misc
+3
writeup

2024 Cyber Apocalypse: Delulu

Exploit format string vulnerability to overwrite target variable

#htb #ctf #pwn
+2
writeup

2024 Cyber Apocalypse: Pwn Tutorial

Answer integer overflow questions to retrieve the flag

#htb #ctf #pwn
+2
writeup

2024 Cyber Apocalypse: Writing on the Wall

Exploit off-by-one vulnerability and strcmp null byte behavior

#htb #ctf #pwn
+3
writeup

2024 Cyber Apocalypse: BoxCutter

Use strace to identify file access attempts and retrieve the flag

#htb #ctf #reverse
+3
writeup

2024 Cyber Apocalypse: Crushing

Reverse engineer a compression algorithm and decode serialized data

#htb #ctf #reverse
+3
writeup

2024 Cyber Apocalypse: Testimonial

Exploit gRPC path traversal to overwrite application files

#htb #ctf #web
+3
writeup

2024 Cyber Apocalypse: TimeKORP

Exploit command injection in time-based functionality

#htb #ctf #web
+2
writeup

2024 Cyber Apocalypse: KorpTerminal

Exploit SQL injection to retrieve credentials and login

#htb #ctf #web
+2
writeup

2024 Cyber Apocalypse: PackedAway

Unpack UPX-compressed executable to reveal hidden strings and flag

#htb #ctf #reverse
+3
writeup

2024 Cyber Apocalypse: Labyrinth Linguist

Exploit Apache Velocity Server-Side Template Injection (SSTI)

#htb #ctf #web
+3
writeup

2024 Cyber Apocalypse: LockTalk

Exploit JWT vulnerabilities in python-jwt version 3.3.3

#htb #ctf #web
+3
writeup

2024 Cyber Apocalypse: SerialFlow

Exploit memcached injection and Python pickle deserialization for RCE

#htb #ctf #web
+4
writeup

2024 Cyber Apocalypse: Web SerialFlow

Exploit serialization vulnerabilities to achieve RCE through pickle deserialization

#htb #ctf #web
+3
writeup

HTB: formulax Writeup

formulax is a Hard-difficulty Linux machine from HackTheBox.

#htb #writeup #linux
+3
writeup

HTB: Perfection Writeup

Perfection is an Easy-difficulty Linux machine from HackTheBox featuring Server-Side Template Injection (SSTI) in a Ruby web application.

#htb #writeup #linux
+7
writeup

HTB: crafty Writeup

crafty is a Easy-difficulty Windows machine from HackTheBox.

#htb #writeup #windows
+4
writeup

HTB: skyfall Writeup

skyfall is an Insane-difficulty Linux machine from HackTheBox featuring CVE-2023-28432 (Minio info disclosure), HashiCorp Vault integration, and advanced privilege escalation techniques.

#htb #writeup #linux
+6
writeup

HTB: pov Writeup

pov is a Medium-difficulty Windows machine from HackTheBox.

#htb #writeup #windows
+3
writeup

HTB: analysis Writeup

analysis is a Hard-difficulty Windows machine from HackTheBox.

#htb #writeup #windows
+3
writeup

HTB: monitored Writeup

monitored is a Medium-difficulty Linux machine from HackTheBox.

#htb #writeup #linux
+5
writeup

HTB: bizness Writeup

bizness is a Easy-difficulty Linux machine from HackTheBox.

#htb #writeup #linux
+5
writeup

HTB: corporate Writeup

corporate is a Insane-difficulty Linux machine from HackTheBox.

#htb #writeup #linux
writeup

HTB: Surveillance Writeup

Surveillance is a Medium-difficulty Linux machine from HackTheBox featuring Craft CMS and ZoneMinder exploitation.

#htb #writeup #linux
+7
writeup

HTB: devvortex Writeup

devvortex is an Easy-difficulty Linux machine from HackTheBox. Exploitation involves Joomla vulnerability discovery, credential extraction, and privilege escalation via apport-cli pager escape.

#htb #writeup #linux
+9
writeup

HTB: hospital Writeup

hospital is a Medium-difficulty Windows machine from HackTheBox.

#htb #writeup #windows
+6
writeup

HTB Hack The Boo Practice: Hexoding64

Decode a flag split between hex and base64 encoding

#htb #ctf #crypto
+3
writeup

HTB Hack The Boo Practice: SPG

Reverse engineer a password generator to decrypt an encrypted flag

#htb #ctf #crypto
+3
writeup

HTB Hack The Boo Practice: yesnce

Exploit AES-CTR mode with predictable counter and key recovery

#htb #ctf #crypto
+3
writeup

HTB Hack The Boo Practice: Candyvault

NoSQL injection in login form to bypass authentication

#htb #ctf #web
+3
writeup

HTB Hack The Boo Practice: Web Pumpkinspice

Command injection vulnerability in localhost-restricted endpoint

#htb #ctf #web
+3
writeup

HTB Hack The Boo Practice: Web Spellbound Servants

Pickle deserialization exploitation for remote code execution

#htb #ctf #web
+4
writeup

HTB Hack The Boo Practice: Web Spooktastic

XSS via filter bypass using noembed tag

#htb #ctf #web
+3
writeup

HTB Hack The Boo Practice: Web Candyvault

NoSQL injection in authentication bypass with MongoDB

#htb #ctf #web
+3
writeup

HTB: napper Writeup

napper is a Hard-difficulty Windows machine from HackTheBox.

#htb #writeup #windows
+2
writeup

HTB Hack The Boo 2023: Rev Spellbrewery

.NET binary reverse engineering challenge

#htb #ctf #reverse-engineering
+2
writeup

HTB Hack The Boo 2023: Web HauntMart

SSRF vulnerability leading to admin account creation

#htb #ctf #web
+3
writeup

HTB: manager Writeup

manager is a Medium-difficulty Windows machine from HackTheBox.

#htb #writeup #windows
+3
writeup

HTB: Drive Writeup

Drive is a Hard-difficulty Linux machine from HackTheBox featuring a Django-based file management application with SQLite databases.

#htb #writeup #linux
+5
writeup

HTB: Analytics Writeup

Analytics is an Easy-difficulty Linux machine from HackTheBox featuring Metabase RCE exploitation and overlayFS privilege escalation.

#htb #writeup #linux
+6
writeup

HTB: visual Writeup

visual is a Medium-difficulty Windows machine from HackTheBox.

#htb #writeup #windows
+3
writeup

HTB: cozyhosting Writeup

cozyhosting is an Easy-difficulty Linux machine from HackTheBox featuring Spring Boot Actuator exposure, session hijacking, command injection, and SSH privilege escalation.

#htb #writeup #linux
+6
writeup

HTB: zipping Writeup

zipping is a Medium-difficulty Linux machine from HackTheBox featuring file upload bypass via null byte injection and privilege escalation through shared object hijacking.

#htb #writeup #linux
+5
writeup

HTB: cybermonday Writeup

cybermonday is a Hard-difficulty Linux machine from HackTheBox.

#htb #writeup #linux
+3
writeup

HTB: keeper Writeup

keeper is an Easy-difficulty Linux machine from HackTheBox featuring Request Tracker enumeration, default credential exploitation, and KeePass memory dump vulnerability exploitation.

#htb #writeup #linux
+5
writeup

HTB: download Writeup

download is a Hard-difficulty Linux machine from HackTheBox. Partial writeup with reconnaissance findings documented.

#htb #writeup #linux
+4
writeup

HTB: gofer Writeup

gofer is a Hard-difficulty Linux machine from HackTheBox.

#htb #writeup #linux
+4
writeup

HTB: registrytwo Writeup

registrytwo is a Hard-difficulty Linux machine from HackTheBox.

#htb #writeup #linux
+4
writeup

2023 Business CTF: 2244 Elections

Exploit a backdoored e-voting smart contract to manipulate election results

#htb #ctf #blockchain
+2
writeup

2023 Business CTF: Confidentiality

Forge NFT signatures to gain access to confidential Board of Arodor documents

#htb #ctf #blockchain
+3
writeup

2023 Business CTF: Contempt - Revenge

Full system compromise requiring exploitation chain through multiple vulnerabilities

#htb #ctf #fullpwn
+2
writeup

2023 Business CTF: Funds Secured

Exploit a multi-signature wallet to steal crowdfunding campaign funds

#htb #ctf #blockchain
+3
writeup

2023 Business CTF: Initialization

Break AES-CTR encryption with nonce reuse vulnerability

#htb #ctf #crypto
+3
writeup

2023 Business CTF: Unveiled

Enumerate and exploit misconfigured AWS S3 buckets to access confidential information

#htb #ctf #cloud
+3
writeup

2023 Business CTF: Interception

Exploit weak PRNG in RSA system to decrypt enemy communications

#htb #ctf #crypto
+3
writeup

2023 Business CTF: Vitrium Stash

Forge DSA signatures to access vitalium resource coordinates

#htb #ctf #crypto
+3
writeup

2023 Business CTF: Paid Contr-actor

Sign a contract with a simple condition to complete military enrollment paperwork

#htb #ctf #blockchain
+2
writeup

2023 Business CTF: I'm gRoot

Forge Merkle tree signatures to detect a blockchain backdoor

#htb #ctf #crypto
+3
writeup

2023 Business CTF: Lagmon

Exploit WordPress plugin vulnerabilities and LLM prompt injection for RCE

#htb #ctf #fullpwn
+4
writeup

2023 Business CTF: Vanguard

Full exploitation of a web application with file upload vulnerability, command injection, and privilege escalation.

#htb #ctf #fullpwn
+4
writeup

2023 Business CTF: Device Control

Exploit a device control server to manipulate devices or gain system access.

#htb #ctf #pwn
+3
writeup

2023 Business CTF: PAC Breaker

Exploit a surveillance system tracking application by bypassing file restrictions and causing heap corruption.

#htb #ctf #pwn
+4
writeup

2023 Business CTF: Hackback

Exploit a Command and Control (C2) service by exploiting vulnerabilities in its bot management system.

#htb #ctf #pwn
+4
writeup

2023 Business CTF: Snow Scan

Bypass a bitmap scanning application by crafting a malicious BMP file to trigger code execution.

#htb #ctf #pwn
+4
writeup

2023 Business CTF: Cobalt COBOL

Reverse engineer an ancient COBOL punch card program representing a facility update.

#htb #ctf #reverse-engineering
+3
writeup

2023 Business CTF: Breach

Exploit a Modbus-based SCADA door control system by manipulating sensors and coils.

#htb #ctf #scada
+4
writeup

2023 Business CTF: ICS Intrusion

Analyze captured Modbus network traffic to extract sensitive data from industrial control registers.

#htb #ctf #scada
+5
writeup

2023 Business CTF: ICS Watch Tower

Analyze network captures to identify intruder reconnaissance and data tampering on industrial systems.

#htb #ctf #scada
+4
writeup

2023 Business CTF: Web Watersnake

Exploit a Java deserialization vulnerability in a water level monitoring application.

#htb #ctf #web
+5
writeup

HTB: authority Writeup

authority is a Medium-difficulty Windows machine from HackTheBox.

#htb #writeup #windows
+3
writeup

HTB: sau Writeup

sau is an Easy-difficulty Linux machine from HackTheBox involving SSRF, command injection, and privilege escalation.

#htb #writeup #linux
+5
writeup

HTB: Pilgrimage Writeup

Pilgrimage is an Easy-difficulty Linux machine featuring an image shrinking service with exposed git repository, ImageMagick LFI, and Binwalk RCE vulnerabilities.

#htb #writeup #linux
+6
writeup

HTB: twomillion Writeup (Incomplete)

twomillion is an Easy-difficulty Linux machine from HackTheBox. This writeup is a skeleton with limited documentation.

#htb #writeup #linux
+1
writeup

HTB: pc Writeup

pc is a Easy-difficulty Linux machine from HackTheBox.

#htb #writeup #linux
+3
writeup

HTB: busquedas Writeup

busquedas is a Easy-difficulty Linux machine from HackTheBox.

#htb #writeup #linux
+3
writeup

2023 Cyber Apocalypse: Small sTeps

Exploit RSA with small public exponent e=3 using Coppersmith's attack

#htb #ctf #crypto
+3
writeup

2023 Cyber Apocalypse: Multipage Recyclings

Exploit custom AES ECB implementation with block recycling vulnerability

#htb #ctf #crypto
+3
writeup

2023 Cyber Apocalypse: Extraterrestrial Persistence

Analyze and decode malicious script with systemd persistence mechanism

#htb #ctf #forensics
+3
writeup

2023 Cyber Apocalypse: Perfect Synchronization

Exploit AES ECB mode encryption with known plaintext and partial key recovery

#htb #ctf #crypto
+3
writeup

2023 Cyber Apocalypse: Ancient Encodings

Reverse engineer a multi-layer encoding scheme involving hex conversion and base64

#htb #ctf #crypto
+3
writeup

2023 Cyber Apocalypse: HW Debug

Hardware debugging and analysis of timing/electrical signals

#htb #ctf #hardware
+2
writeup

2023 Cyber Apocalypse: Hijack

Exploit Python deserialization vulnerabilities in YAML and Pickle

#htb #ctf #misc
+4
writeup

2023 Cyber Apocalypse: Janken

Win 100 rounds of Janken by exploiting logic in string matching

#htb #ctf #misc
+3
writeup

2023 Cyber Apocalypse: Persistence

Automate repeated HTTP requests to extract flag from endpoint

#htb #ctf #misc
+3
writeup

2023 Cyber Apocalypse: Nehebkaus Trap

Exploit Python exec() filter bypass using character encoding

#htb #ctf #misc
+3
writeup

2023 Cyber Apocalypse: Remote Computation

Automate mathematical expression evaluation over TCP socket

#htb #ctf #misc
+3
writeup

2023 Cyber Apocalypse: Restricted

Escape restricted SSH environment using bash profile bypass

#htb #ctf #misc
+3
writeup

2023 Cyber Apocalypse: The Chasm Crossing Conundrum

Solve bridge crossing puzzle using optimal algorithm

#htb #ctf #misc
+3
writeup

2023 Cyber Apocalypse: Questionnaire

Buffer overflow via fgets() vulnerability in vulnerable C binary

#htb #ctf #pwn
+3
writeup

2023 Cyber Apocalypse: Getting Started

Buffer overflow exploitation using controlled payload delivery

#htb #ctf #pwn
+3
writeup

2023 Cyber Apocalypse: CSHells

Reverse engineer custom shell binary and crack XOR-encrypted password

#htb #ctf #reverse
+3
writeup

2023 Cyber Apocalypse: Cave System

Solve complex multi-condition logic puzzle in binary

#htb #ctf #reverse
+2
writeup

2023 Cyber Apocalypse: Shattered Tablet

Reconstruct input string by analyzing multi-byte field access patterns

#htb #ctf #reverse
+2
writeup

2023 Cyber Apocalypse: Orbital

Exploit SQL injection vulnerability and use path traversal to extract flag

#htb #ctf #web
+3
writeup

2023 Cyber Apocalypse: Didactic Octo Paddle

Exploit IDOR and JWT vulnerabilities in shopping application

#htb #ctf #web
+3
writeup

2023 Cyber Apocalypse: Hunting License

Crack three-stage password validation in binary using string reversal and XOR

#htb #ctf #reverse
+3
writeup

2023 Cyber Apocalypse: Passman

Exploit IDOR vulnerability in GraphQL API to access admin data

#htb #ctf #web
+3
writeup

HTB: inject Writeup

inject is a Easy-difficulty Linux machine from HackTheBox.

#htb #writeup #linux
+3
writeup

HTB: interface Writeup

interface is a Medium-difficulty Linux machine from HackTheBox.

#htb #writeup #linux
+3
writeup

HTB: stocker Writeup

stocker is an Easy-difficulty Linux machine from HackTheBox.

#htb #writeup #linux
writeup

HTB: soccer Writeup

soccer is an Easy-difficulty Linux machine from HackTheBox featuring web file manager exploitation, SQL injection via WebSocket, and privilege escalation through doas.

#htb #writeup #linux
+7
writeup

2022 Hack The Boo: Gonna Lift Em All

Discrete log problem with extremely small prime - trivial brute force attack

#htb #ctf #crypto
+3
writeup

2022 Hack The Boo: Whole Lotta Candy

AES encryption challenge with multiple block cipher modes - exploit ECB mode weakness

#htb #ctf #crypto
+4
writeup

2022 Hack The Boo: Cursed Party

JWT authentication bypass through XSS to steal admin session and access flag

#htb #ctf #web
+5
writeup

2022 Hack The Boo: Evaluation Deck

Code injection via unsafe use of Python compile() and exec() in arithmetic evaluation

#htb #ctf #web
+5
writeup

2022 Hack The Boo: Horror Feeds

SQL injection in user registration leading to authentication bypass and flag theft

#htb #ctf #web
+4
writeup

2022 Hack The Boo: Juggling Facts

IP spoofing via X-Forwarded-For header to bypass localhost-only admin access

#htb #ctf #web
+4
writeup

2022 Hack The Boo: Spookifier

Server-Side Template Injection (SSTI) in Mako template engine leading to RCE

#htb #ctf #web
+5
writeup

HTB: Photoshop Writeup

Photoshop is a Medium-difficulty Windows machine from HackTheBox.

#htb #writeup #windows
writeup

HTB: ambassador Writeup

ambassador is a Medium-difficulty Linux machine from HackTheBox.

#htb #writeup #linux
+3