00ordin0ord.hashnode.dev·4d ago · 4 min readTryHackMe Boiler WalkthroughTryHackMe Boiler Walkthrough TrуHаckMe iѕ a famouѕ infоѕес-focused leаrnіng plауgrоund оfferіng еducation and practicing rooms for everyone interested. The Boiler CTF room is considered an intermedia00
00ordin0ord.hashnode.dev·Jul 23 · 7 min readHackTheBox Monitors WalkthroughHackTheBox Monitors Walkthrough HасkTheBox іs a pоpulаr ѕеrvіce offering оvеr 240 maсhіnеѕ and tоnѕ of challenges so you can extend and improve your cybersecurity skills. HTB Monitors is an advanced 01F
00ordin0ord.hashnode.dev·Jul 23 · 5 min readHackTheBox Timelapse WriteupTіmеlapsе is a bеginnеr-frіеndlу Windows-basеd mаchіnе, thаt аllowѕ уou to practice cracking passwords, work with certificate files, and exploit LAPS. HTB is a popular service allowing people interest00
LVLong Voinlongvh0904.hashnode.dev·Jul 21 · 42 min readHTB Attack Diaries - Bedside: The Clinic That Deserialized Its Own DeathIntroduction Bedside is a Medium-rated Linux box dressed up as a heart clinic "transitioning into the age of AI." And like most things that promise AI, what sits underneath the glossy paint is a chain00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Jul 18 · 4 min readFAM CTF : The Vault Door WriteupSummary NexaVault is a mock internal dashboard app that gates an "Admin Vault" panel behind a role claim in a JWT. The app issues a user-role token on login, stored in the nx_access cookie, and trusts00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Jul 18 · 7 min readFAM CTF : The Cloud writeupSummary The target exposed a webhook endpoint (/internal/webhook) meant to act as an internal-only proxy, blocking direct requests to private and link-local IP ranges. That blocklist checked resolved 00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Jul 18 · 13 min readFAM CTF: The Library to The Endpoint WriteupExecutive Summary FAM is a mobile CTF challenge distributed as an Android APK (fam-ctf.apk) with four staged flags, each themed around a different layer of the app's Firebase backend: The Library (nat00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Jul 17 · 4 min readHackTheBox : Void Whispers WriteupSummary The "Void Whispers" mail-settings panel passes the user-supplied sendMailPath field directly into shell_exec("which $sendMailPath") with no escaping. The app only filters literal whitespace, w00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Jul 17 · 19 min readHackTheBox : Race WriteupSummary Race is a Linux box built around Grav CMS. The path in is a chain of small information leaks rather than one big bug: an exposed phpsysinfo instance with default creds leaks a process list, th00
LMLakindu Mansarainlmsecurity.hashnode.dev·Jul 15 · 12 min readOverTheWire Bandit: Level 15 → Level 20 Walk-through Introduction Welcome back to my OverTheWire Bandit journey! In this article, I continue from Level 15 and work through to Level 20. These levels introduce more networking concepts, secure communicatio00