Categories
Tags
#HackTheBox Active_Directory ADCS brotli COM constrained_delegations Cross-Session-Relay CVE-2023-46818 CVE-2023-47268 CVE-2024-32651 CVE-2024-34716 CVE-2024-6886 DCOM decompiling_dll Defender dll Docker easy elpscrk ESC1 fscan FTP Git git-dumper Gitea HackTheBox hard idor IIS IIS_KERBEROS_AUTH Insane ISPConfig kerberos kerbrute KioskMode linux Log_Analysis Medium MySQL OXID-Resolver pbkdf2-sha256 PrusaSlicer RBCD RCE rid_bruteforcing S4U2Proxy S4U2Self SMB SQLite SSTI U2U UAC_Bypass Velociraptor VeraCrypt Windows windows_internals WSL xss
HTB: Cicada (Windows/Easy)
Cicada is an excellent beginner-friendly Windows box designed for those new to Windows pentesting, without requiring any knowledge of Active Directory or its attack vectors and strategies. It focuses on the early stages of enumeration, which are essential for tackling more advanced machines, as well as some basic manual checks you can perform once you obtain a user shell.
984 words
|
5 minutes

HTB: DarkCorp (Windows/Insane)
This is an insane Windows machine with one of the largest attack surfaces I’ve ever encountered on a single target. One could even argue that it deserves to be published as an Endgame or perhaps even a mini Pro Lab.
75 words
|
1 minutes

HTB: Trickster (Linux/Medium)
2025-02-01
"Trickster" is a medium-difficulty Linux machine on HackTheBox that challenges you with technologies like Git, MySQL, Docker, and vulnerabilities such as SSTI and CSRF. This write-up covers the key steps and techniques I used to exploit the machine, highlighting the creative enumeration and exploitation required to capture the flags.
1999 words
|
10 minutes
