Recent Posts

HackTheBox: BoardLight

7 minute read

This box is rated easy difficulty on HTB. It involves us using default credentials on a subdomain that’s running a CRM site. Being an outdated version, we ca...

HackTheBox: Soccer

9 minute read

This box is rated easy difficulty on HTB. It involves us getting administrative access to a file manager website using default credentials and exploiting a p...

TryHackMe: Wekor

14 minute read

This box is rated medium difficulty on THM. It involves us discovering an eCommerce website that’s vulnerable to SQL injection and a subdomain hosting Wordpr...

TryHackMe: Blueprint

5 minute read

This box is rated easy difficulty on THM. It involves us finding a version of OsCommerce that is vulnerable to RCE which grants us a high-level shell on the ...

TryHackMe: Napping

7 minute read

This box is rated medium difficulty on THM. It involves us peforming a reverse tabnabbing attack to steal administrator credentials on a website. That same p...

HackTheBox: Flight

12 minute read

This box is rated hard difficulty on HTB. It involves LFI, NTLM theft, password spraying, uploading reverse shells, plenty of enumeration, port forwarding, a...

HackTheBox: Cicada

6 minute read

This box is rated easy difficulty on THM. It involves using Guest authentication to discover a default password on an SMB share, finding more passwords throu...

HackTheBox: Usage

7 minute read

This box is rated easy difficulty on HTB. It involves us exploiting SQL injection to dump a web application’s database and sign in as an Administrator. Then ...

HackTheBox: Keeper

5 minute read

This box is rated easy difficulty on HTB. It involves us logging into a ticket support site with default credentials which leads to grabbing a plaintext pass...

Masterpiece

6 minute read

This is vulnerable machine was a side project of mine that also served as great practice for Python, web exploitation, and Linux privilege escalation techniq...