YPYogeshwar Peelainexploitnotes.hashnode.dev·Sep 22 · 8 min readTryHackMe: Python Playground WriteupSummary Python Playground is a hard-rated TryHackMe box built around a "sandboxed" Python code execution service fronted by a Node.js/Express web app. The site advertises a blacklist-based filter that00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Sep 10 · 10 min readTryHackMe - Olympus WriteupSummary Olympus is a Linux box built around an old Victor CMS 1.0 install hidden under /~webmaster/. An unauthenticated SQL injection in the CMS search feature was the root of the entire chain: it dum00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 23 · 18 min readBrunnerCTF 2026 : The Three Ways WriteupSummary Two connected challenges built around the same Gitea/Drone/rollout-agent environment. The first stage (Flow) gets code execution on the Drone CI runner. The second stage (Feedback / Continuous00
LTLưu Tuấn Anhinblog.fiscybersec.com·Aug 20 · 12 min readWindRelay: New Malware Duo Behind the Wave of FraudOverview Did you know that it only takes 13 short minutes from the moment the victim picks up the phone to receive the support call from the "bank employee" until all the money in the account is evapo00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 18 · 8 min readTryHackMe : Athena WriteupOverview Athena is an easy-rated TryHackMe box that chains a leaked internal path (found via an anonymous SMB share) into a command injection vulnerability in a "router panel" ping tool, followed by a00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 15 · 11 min readTryHackMe : Different CTF writeupSummary Different CTF is an easy-rated Linux box built around a WordPress install with an exposed wp-config.php, an FTP service reachable with credentials hidden inside a steganographic image, and a c00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 7 · 11 min readTryHackMe : Infinity Pool WriteupSummary Recon on <MACHINE_IP> revealed a Gunicorn-hosted "Byte Lotus" hotel site with two paths disallowed in robots.txt - /internal/ and /status. The /status page exposes an internal staff tool ("Sis21N
NINeville Iregiinm0ng00s3-blog.hashnode.dev·May 5 · 9 min readHack The Box: PennyworthPennyworth is a Linux machine that focuses on exploiting weak credentials and remote command execution in. Default credentials can be used to get administrative access into Jenkins with which the Scri00
Rrecca0120inrecca0120.hashnode.dev·Apr 21 · 3 min readreverse_ssh: Manage Reverse Shells With Native SSH Syntax, No VPN RequiredOriginally published at recca0120.github.io You need to connect to a machine behind NAT with no public IP and inbound traffic blocked. The usual answers are VPN or ngrok-style tunnels, but both require setup on the target. reverse_ssh has the target ...00
NINeville Iregiinm0ng00s3-blog.hashnode.dev·Mar 21 · 12 min readHack The Box Lab: ThreeOrganizations of every type, size, and industry are using the cloud for a wide variety of use cases, such as data backup, storage, disaster recovery, email, virtual desktops, software development and 00