00ordin0ord.hashnode.dev·Jul 23 · 7 min readHackTheBox Monitors WalkthroughHackTheBox Monitors Walkthrough HасkTheBox іs a pоpulаr ѕеrvіce offering оvеr 240 maсhіnеѕ and tоnѕ of challenges so you can extend and improve your cybersecurity skills. HTB Monitors is an advanced 01F
00ordin0ord.hashnode.dev·Jul 23 · 5 min readHackTheBox Timelapse WriteupTіmеlapsе is a bеginnеr-frіеndlу Windows-basеd mаchіnе, thаt аllowѕ уou to practice cracking passwords, work with certificate files, and exploit LAPS. HTB is a popular service allowing people interest00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Jul 17 · 4 min readHackTheBox : WayWitch WriteupSummary The ticket portal generates guest session JWTs client-side, signing them with an HMAC secret (halloween-secret) that's hardcoded directly in the page's JavaScript. Since the server verifies to00
MSMOHIT SINGH PAPOLAinblog.reapsec.com·Dec 27, 2025 · 5 min readWanted AliveOVERVIEW So we are given file to download and an instance to spawn Let’s do it and see what’s inside the zipSo we found a wanted.hta file let’s see its file type and its contents Its a HTML document with ASCII text which is very long so when i ins...00
MSMOHIT SINGH PAPOLAinblog.reapsec.com·Oct 3, 2025 · 2 min readSpookTasticOVERVIEW So we were given instance and a file to download so let’s do it and checkout the website and the content of the file we downloaded Since most of the buttons are just not useful we see a newsletter functionality Its accepting the mail but...00
MSMOHIT SINGH PAPOLAinblog.reapsec.com·Oct 1, 2025 · 2 min readAn Unusual SightingOVERVIEW Start the Instance and Download the given files . We were given two files sshd and bash_history Now First Let’s see what is there in the instance So We were asked a questionQues 1) What is the IP Address and Port of the SSH Server (IP:POR...00
MSMOHIT SINGH PAPOLAinblog.reapsec.com·Sep 18, 2025 · 2 min readVoid WhispersOVERVIEW So Download the given files from the site and open the instance and Let’s check it out Hmm The Site allows as to send mail through sendmail Path which looks kinda suspicious Let’s check the downloaded files to see any vulnerability there ...00
MSMOHIT SINGH PAPOLAinblog.reapsec.com·Sep 17, 2025 · 3 min readArmaxisOVERVIEW So Let’s Open the instances and checkout the web pages and Downloaded files Lets see website with port no 55423 first: It have Register, Login and Forgot Password Functionality so now let’s checkout second port no 39739 In here we can see...00
MSMOHIT SINGH PAPOLAinblog.reapsec.com·Sep 15, 2025 · 3 min readNeoVaultOVERVIEW So we already started an instance and now lets move on the web page . So Let’s start by creating an account and login with it to get access of the dashboard. After Logged in you can see a recent transaction from a user neo_system and y...00