YPYogeshwar Peelainexploitnotes.hashnode.dev·2d ago · 15 min readTryHackMe - SeaSurfer writeupExecutive Summary The engagement began with a single disclosed virtual host name leaking out of an HTTP response header on the target web server. That one leak unraveled the entire box: it led to a Wo00
YPYogeshwar Peelainexploitnotes.hashnode.dev·2d ago · 9 min readTryHackMe: MD2PDF WriteupSummary MD2PDF is a web app that converts user-submitted Markdown into a downloadable PDF using a server-side rendering engine. The input is not sanitized, so raw HTML is rendered as-is - including ta00
MSMolly Sohaneyinmollysohaney.hashnode.dev·Sep 29 · 6 min readCTF Writeup: Used Goods of Tomorrow | Web | SunshineCTF 2026Description Come to Tommorow-Mart for all your used goods! We even have a partnership with FutureBank to grant you 500 free credeits to start! I wonder who the first millionare will be to purchase th00
MSMolly Sohaneyinmollysohaney.hashnode.dev·Sep 27 · 5 min readCTF Writeup: Track Me | Web | MetaCTF September 2026 FlashDescription Every visit to the storefront leaves a mark. A small analytics box in the back office notes who came by, when they arrived, and how they got there. The owner reads it each morning over co00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Sep 22 · 8 min readTryHackMe: Python Playground WriteupSummary Python Playground is a hard-rated TryHackMe box built around a "sandboxed" Python code execution service fronted by a Node.js/Express web app. The site advertises a blacklist-based filter that00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Sep 10 · 10 min readTryHackMe - Olympus WriteupSummary Olympus is a Linux box built around an old Victor CMS 1.0 install hidden under /~webmaster/. An unauthenticated SQL injection in the CMS search feature was the root of the entire chain: it dum00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Sep 9 · 4 min readTryHackMe - CyberHeroes WriteupSummary CyberHeros is an easy-rated web challenge built on the iPortfolio Bootstrap template. The site advertises a "login page" challenge directly in its About section. Inspection of login.html revea00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Sep 1 · 6 min readWebVersePro : SnowedOut writeup1. Overview The target is "Pinehollow Plow Tracker," a fictional city snow-plow dashboard running on PHP 8.2.33 behind Cloudflare. The page accepts a zone GET parameter that "centers" the map on a nam00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 23 · 7 min readBrunnerCTF - php-2003 WriteupSummary A "Brunnerne Hosting" customer portal exposed a legacy reservation import form that fed user-controlled, base64-encoded data into unserialize(). Getting a flag required chaining three independ01J
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 23 · 8 min readBrunnerCTF : WordPressed to Root WriteupOverview The box ships a mostly-stock WordPress 7.0.0 install on PHP 8.2 / Apache, running on a Debian Trixie base image, packaged as a Docker/Kubernetes challenge deployment. Initial access comes thr00