JJebitokinsharonjebitok.com·1d ago · 21 min readFools Mate, Revenge (TryHackMe)Link to the challenge on TryHackMe: Fools Mate, Revenge Introduction I recently worked through a two-part TryHackMe room built around a deceptively simple web app: a chess "Endgame Trainer" with a mat00
YPYogeshwar Peelainexploitnotes.hashnode.dev·2d ago · 10 min readTryHackMe - Olympus WriteupSummary Olympus is a Linux box built around an old Victor CMS 1.0 install hidden under /~webmaster/. An unauthenticated SQL injection in the CMS search feature was the root of the entire chain: it dum00
YPYogeshwar Peelainexploitnotes.hashnode.dev·2d ago · 4 min readTryHackMe - CyberHeroes WriteupSummary CyberHeros is an easy-rated web challenge built on the iPortfolio Bootstrap template. The site advertises a "login page" challenge directly in its About section. Inspection of login.html revea00
JJebitokinsharonjebitok.com·6d ago · 11 min readChallenge: Expose (TryHackMe)Challenge on TryHackme: Expose Introduction Expose is a TryHackMe room focused on the risks of leaving unnecessary services running on a machine. The attack surface includes FTP, SSH, DNS, HTTP on a n00
JJebitokinsharonjebitok.com·6d ago · 8 min readChallenge: Hammer (TryHackMe)Challenge on TryHackMe: Hammer Introduction Hammer is a web-focused THM challenge that chains together several small missteps into a full authentication bypass and RCE. The box exposes a login portal 00
JJebitokinsharonjebitok.com·6d ago · 20 min readChallenges: Grep (TryHackMe)Challenge on TryHackMe: Grep Introduction TryHackMe's Grep room bills itself as an OSINT challenge under the Red Teaming path, and that framing turned out to be the whole point. Coming into this box e00
VGVivek Goswamiinvivekgoswami.hashnode.dev·6d ago · 2 min readZico2 - Vulnhub 2026 WriteupBox: Zico2: 1 Author: Rafael Difficulty: Beginner–Intermediate Download: https://www.vulnhub.com/entry/zico2-1,210/ Goal: Get a foothold on the web server, pivot to a local user, then escalate to root10
YPYogeshwar Peelainexploitnotes.hashnode.dev·Sep 1 · 6 min readWebVersePro : SnowedOut writeup1. Overview The target is "Pinehollow Plow Tracker," a fictional city snow-plow dashboard running on PHP 8.2.33 behind Cloudflare. The page accepts a zone GET parameter that "centers" the map on a nam00
JJebitokinsharonjebitok.com·Aug 29 · 20 min readFools Mate (TryHackMe)Challenge on TryHackMe: Fools Mate t's mate in one. You know it, the engine knows it, my grandma knows it. The board says checkmate is one click away. The engine says no. Settle the argument. You can 10
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 25 · 11 min readHackSmarter - Casino WriteupSummary Casino is a Flask-based "Guest WiFi & Portal" resort captive portal. A leaked JS source-map exposes an unauthenticated internal API endpoint (/api/v1/rooms/status) that dumps the entire guest 00