UBUday Bhaleinhackwithrudraub.hashnode.dev·5d ago · 5 min readHack The Box: DancingMachine Overview Machine: Dancing Platform: Hack The Box Difficulty: Easy Focus: SMB Enumeration and File Share Access Objective The goal of this machine is to identify exposed services, discover avai00
UBUday Bhaleinhackwithrudraub.hashnode.dev·Aug 25 · 4 min readRecruiteX Project – Web Application Penetration Testing Written Short NotesFrom Enumeration to Exploitation The RecruiteX assessment was approached as a real-world web application penetration test rather than simply checking for known vulnerabilities. The objective was to un00
UBUday Bhaleinhackwithrudraub.hashnode.dev·Aug 17 · 7 min readPart 3: From Admin Panel to Remote Code ExecutionWe made it. After chaining IDOR → Information Disclosure → Weak Password Reset → Administrator Access, we finally reached the admin dashboard. But administrator access isn't the end of the attack. It'00
UBUday Bhaleinhackwithrudraub.hashnode.dev·Aug 16 · 5 min readWeak Password Reset Mechanism: From IDOR to Admin AccessThe IDOR from Part 1 gave us something much more valuable than just another user's profile. This is part 2 of the guided pen test lab. It gave us the administrator's email address. Now the question is00
UBUday Bhaleinhackwithrudraub.hashnode.dev·Aug 2 · 5 min readGuided Pentest: Web (Part 1)From Reconnaissance to Discovering an IDOR Status: 🚧 Work in Progress This write-up documents my learning journey through the Guided Pentest: Web room. This is Part 1, covering reconnaissance, techn00