YPYogeshwar Peelainexploitnotes.hashnode.dev·1d ago · 15 min readHackTheBox : Pterodactyl WriteupSummary Pterodactyl is a Linux box built around an unauthenticated RCE in the Pterodactyl game-server management panel. A static "MonitorLand" landing page on port 80 gives no functionality of its own00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Jul 4 · 10 min readHackTheBox: Watcher WriteupSummary Watcher is a Linux box built around a self-hosted Zabbix monitoring stack. The front door isn't a permissions misconfig at all - it's a real Zabbix CVE (CVE-2024-22120), a time-based blind SQL00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Jul 4 · 18 min readHackTheBox: Phoenix WriteupSummary Phoenix is a WordPress box with a long, winding path to root. The short version: an unauthenticated SQL injection in a forum plugin leaks the whole WordPress database, which gives admin creden00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Jul 2 · 7 min readHackTheBox: vulnEscape WriteupSummary Escape is a Windows box that exposes only RDP (3389). The RDP session drops you into a locked-down kiosk account (KioskUser0) meant for a "Conference Display" app. The box is solved entirely t00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Jul 2 · 11 min readHackTheBox: Manage WriteupSummary Manage is a Linux box built around an exposed Java RMI / JMX service running alongside an Apache Tomcat 10.1.19 web server. The JMX endpoint had no authentication configured, which allowed a r00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Jun 28 · 7 min readHackTheBox: Sloink WriteupSummary NFS shares exposed the target's home directory and PostgreSQL backups. The user's psql history contained an MD5 hash that cracked to service. SSH with that account drops you immediately (shell00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Jun 27 · 18 min readHackTheBox: FireFlow WriteupExecutive Summary FireFlow is a Linux machine running a fictional "Task Force Nightfall" intelligence platform. The web application exposes a Langflow instance (flow.fireflow.htb) with a public flow p00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Jun 27 · 11 min readHackTheBox: Down WriteupExecutive Summary Down is an easy Linux machine running a simple "Is it down or just me?" web checker. The site uses curl server-side to test URLs - making it a classic SSRF target. The protocol filte00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Jun 26 · 14 min readHackTheBox: Orion WriteupExecutive Summary JobTwo is a Windows Server 2022 machine that simulates a realistic corporate phishing and privilege escalation scenario. The attack chain begins with a job posting website that solic00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Jun 26 · 16 min readHackTheBox: JobTwo WriteupExecutive Summary JobTwo is a Windows Server 2022 machine that simulates a realistic corporate phishing and privilege escalation scenario. The attack chain begins with a job posting website that solic00