Recent Posts

HackTheBox: Sizzle

23 minute read

This box is rated insane difficulty on HTB. It involves finding a writeable directory in an SMB share that we mounted, leading to an NTLMv2 hash theft and th...

HackTheBox: Zipper

12 minute read

This box is rated hard difficulty on HTB. It involves us discovering a Zabbix instance on a web server that allows for guest logins. Using an event notice, w...

HackTheBox: Sekhmet

24 minute read

This box is rated insane difficulty on HTB. It involves us getting a foothold on a domain-joined Linux web server through insecure deserialization. Then we d...

HackTheBox: Cereal

19 minute read

This box is rated hard difficulty on HTB. It involves us finding a subdomain with an exposed code repository, leading us to forge a valid JWT with a secret k...

HackTheBox: Rebound

16 minute read

This box is rated insane difficulty on HTB. It involves us performing unauthenticated Kerberoasting via AS-REP Roasting and cracking the hash in order to get...

HackTheBox: Freelancer

16 minute read

This box is rated hard difficulty on HTB. It involves us registering an account on a website where we can reset our password in order to bypass an activation...

HackTheBox: Falafel

13 minute read

This box is rated hard difficulty on HTB. It involves us grabbing password hashes from a website vulnerable to Time-Based SQL injection, letting us login. Us...

HackTheBox: Haze

13 minute read

This box is rated hard difficulty on HTB. It involves us discovering a path traversal vulnerability in Splunk that lets us grab an encrypted LDAP bind passwo...