JJebitokinsharonjebitok.com·1d ago · 21 min readFools Mate, Revenge (TryHackMe)Link to the challenge on TryHackMe: Fools Mate, Revenge Introduction I recently worked through a two-part TryHackMe room built around a deceptively simple web app: a chess "Endgame Trainer" with a mat00
YPYogeshwar Peelainexploitnotes.hashnode.dev·2d ago · 10 min readTryHackMe - Olympus WriteupSummary Olympus is a Linux box built around an old Victor CMS 1.0 install hidden under /~webmaster/. An unauthenticated SQL injection in the CMS search feature was the root of the entire chain: it dum00
MM1Hinm1h.hashnode.dev·3d ago · 5 min readOSCP-LK: Achieving System Administrator Privileges via Credential Harvesting, MSSQL Impersonation, and Registry ExtractionOverview: This box is an OSCP preparation, a hosted version of the OSCP-LK set. OSCP-LK is a set of machines in the style of the PEN 200 labs and exam to help you sharpen your enumeration, creative th10
YPYogeshwar Peelainexploitnotes.hashnode.dev·3d ago · 4 min readTryHackMe - CyberHeroes WriteupSummary CyberHeros is an easy-rated web challenge built on the iPortfolio Bootstrap template. The site advertises a "login page" challenge directly in its About section. Inspection of login.html revea00
VGVivek Goswamiinvivekgoswami.hashnode.dev·Sep 3 · 5 min readMidnight Sunset Walkthrough 2026 - Proving Grounds/VulnhubStart by downloading the Vulnerable machine from - https://www.vulnhub.com/entry/sunset-midnight,517/ Add it to virtual box and adjust the network setting as per your convenience , i set it to host on10
MM1Hinm1h.hashnode.dev·Sep 4 · 3 min readLDAP Enumeration & NFS Misconfiguration To Privilege Escalation as RootObjective: You have been assigned a penetration test on a critical Linux server in the client's environment. The primary objective is to gain root-level access to this system to demonstrate maximum im10
YPYogeshwar Peelainexploitnotes.hashnode.dev·Sep 1 · 6 min readWebVersePro : SnowedOut writeup1. Overview The target is "Pinehollow Plow Tracker," a fictional city snow-plow dashboard running on PHP 8.2.33 behind Cloudflare. The page accepts a zone GET parameter that "centers" the map on a nam00
NNanoinblog.0xnano.com·Aug 31 · 7 min readMagical Palindrome | CTF WriteUpIf we take a look at the source code from the website, we'll see that there is a POST request being made with the data we send as the palindrome, based on the request, we'll get a different response 10
JJebitokinsharonjebitok.com·Aug 29 · 15 min readOperation Promotion (TryHackMe)Challenge on TryHackMe: Operation Promotion You are up for promotion at Hadron Security. Your senior lead, Mara, has handed you a solo engagement against RecruitCorp, a small recruiting firm with a pu00
ARAbdul Rehmaninskin-security.hashnode.dev·Aug 29 · 5 min readBad Reception — Intigriti August 2026 CTF WriteupFirst Look The challenge drops you on a page with a retro TV showing static noise, channel buttons 1–10, a volume knob, and a report button in the corner. The hint is right there in the subtitle: "Mak00