Posts
N0xi0us
Cancel

Doctor Writeup [HTB]

Doctor is a linux machine rated as easy from Hack The Box, it consists on finding a virtual hosts which contains a messaging service vulnerable to server-side template injection, then after obtaini...

Compromised Writeup [HTB]

Compromised is a linux machine rated as difficult from Hack The Box, it consists on enumerating to find credentials for admin access, then as lots of php functions are disabled, a php bypass exploi...

Omni Writeup [HTB]

Omni is a Windows IoT machine rated as easy from Hack The Box, it consists on exploiting an RCE vulnerability to gain initial access and then using some Powershell tricks to find credentials and de...

HTB x UNI CTF 2020

Writeups for some challenges of different categories from HackTheBox University CTF 2020.

Buff Writeup [HTB]

Buff is a Windows machine rated as easy from Hack The Box, it consists on exploiting Gym Manager Software 1.0 to obtain initial access, and then, by doing port forwarding we can exploit a binary ru...

Tabby Writeup [HTB]

Tabby is a Linux machine rated as easy from Hack The Box, it consists on using a local file inclusion vulnerability to obtain tomcat host manager credentials and then upload and deploy a war revers...

SECARMY CTF

This is a box created for Secarmy 2020 ctf during GrayHat containing 10 challenges inside it covering different topics from pentesting to crypto and pwn.

Blunder Writeup [HTB]

Blunder is a Linux machine rated as easy from Hack The Box, it consists on finding credentials to log in to Bludit and then use a RCE exploit to gain an initial shell, then some database files can ...

Cache Writeup [HTB]

Cache is a linux machine rated as medium from Hack The Box, it consists on enumerating to find another website running OpenEMR, then pivoting to a user with credentials obtained from the initial we...

Blackfield Writeup [HTB]

Blackfield is a Windows machine rated as difficult from HackTheBox, it is an Active Directory machine where a kerberoasting attack is performed and then some forensics is required in order to obtai...