Search

Type to search posts.

es
Writeups

HackTheBox: Sea

Sea is an easy Linux machine: a WonderCMS XSS (CVE-2023-41425) hijacks the admin session and leads to RCE via a malicious theme, a Blowfish hash gives SSH access, and a log-reading LFI with command injection gives root.

Writeups

HackTheBox: Curling

Curling is an easy Linux machine: a Joomla site leads to admin access and RCE through a template webshell, a hexdump reveals SSH credentials, and PwnKit (CVE-2021-4034) gives root.

Writeups

HackTheBox: OpenAdmin

OpenAdmin is an easy Linux machine: an outdated OpenNetAdmin panel gives RCE, credential reuse and a hidden internal service lead to an SSH key, and a sudo nano misconfig gives root via GTFOBins.

Writeups

HackTheBox: Heist

Heist is an easy Windows machine: a leaked Cisco config exposes crackable password hashes, a password spray gets a foothold, and dumping Firefox from memory with Procdump reveals the admin credentials.

Writeups

HackTheBox: Jab

Jab is a medium Windows AD machine: Kerbrute user enumeration and AS-REP Roasting give a foothold, an Openfire XMPP chat room leaks credentials, and CVE-2023-32315 on the Openfire console leads to SYSTEM.

Writeups

HackTheBox: Codify

Codify is an easy Linux machine: a vm2 sandbox escape gives RCE, a SQLite database yields a crackable hash, and a bash pattern-matching pitfall in a sudo script (with pspy) reveals the root password.

All Posts