Writing
Notes and writeups on software, security, and AI engineering.
- Hack The Box - PhantomPhantom is a Windows machine running Active Directory. Guest authentication over SMB makes it possible to enumerate shares and recover an onboarding…
- Hack The Box - AnalysisAnalysis is a Windows machine running Active Directory. An internal subdomain hosts a webpage vulnerable to LDAP injection, which can be exploited to…
- Hack The Box - CicadaCicada is a Windows machine running Active Directory with an open SMB share that contains a default password. Usernames can be enumerated by…
- Hack The Box - EscapeTwoEscapeTwo is a Windows machine running Active Directory. The box starts with a set of given credentials, which can be used to enumerate SMB shares…
- Hack The Box - AdministratorAdministrator is a Windows machine running Active Directory. The box starts with a given set of credentials, which can be used to gather domain data…
- Hack The Box - AxlleAxlle is a Windows machine running Active Directory. A hosted website displays a maintenance notice, but also mentions that outstanding invoices or…
- Hack The Box - ObjectObject is a Windows machine running Active Directory. Access to a Jenkins instance allows for triggering builds that execute batch commands. By…
- Hack The Box - MonitoredMonitored is a Linux machine running an instance of Nagios XI. A username and password for Nagios can be discovered from SNMP data, which reveals a…
- Hack The Box - BlurryBlurry is a Linux machine running an application with a vulnerable version of ClearML, which contains a deserialization flaw (CVE-2024-24590). This…
- Hack The Box - EvilCUPSEvilCUPS is a Linux machine affected by several vulnerabilities discovered in CUPS (Common Unix Printing System) in September 2024. These…
- Hack The Box - BuilderBuilder is a Linux machine running a version of Jenkins with an arbitrary file read vulnerability via the CLI (CVE-2024-23897). This vulnerability…
- Hack The Box - AeroAero is a Windows machine hosting a website that allows users to upload custom Windows 11 themes. Due to a known RCE vulnerability in Windows Themes…
- Hack The Box - VisualVisual is a Windows machine hosting a website that compiles Visual Studio projects from a remote Git repository. Command execution on the box can be…
- Hack The Box - JabJab is a Windows machine running Active Directory with an XMPP server that allows open registration. Once an account has been created, a list of…
- Hack The Box - ManagerManager is a Windows machine running Active Directory. After gathering a list of domain users by brute-forcing RIDs, one of the users is found to…
- Hack The Box - BlackfieldBlackfield is a Windows machine running Active Directory. A list of potential usernames can be created based on user directories found in an open SMB…
- Hack The Box - ReelReel is a Windows machine running Active Directory with an open FTP server that contains a few documents, one of which reveals an email address…
- Hack The Box - EscapeEscape is a Windows machine running Active Directory with an open SMB share containing credentials for an MSSQL instance. After connecting to the…
- Hack The Box - ScrambledScrambled is a Windows machine running Active Directory. A username can be found on a hosted webpage as well as a message indicating that some…
- Hack The Box - CascadeCascade is a Windows machine running Active Directory. An anonymous LDAP bind allows for enumeration of the environment, leading to the discovery of…
- Hack The Box - MonteverdeMonteverde is a Windows machine with an Active Directory environment featuring Azure AD. After enumerating domain users, it can be discovered that a…
- Hack The Box - ResoluteResolute is a Windows machine running Active Directory. A few different methods can be used to enumerate users on the system and reveal an initial…
- TryHackMe - VulnNet: ActiveVulnNet: Active is a Windows machine running Active Directory with an instance of Redis that doesn't require authentication. This can be leveraged to…
- Hack The Box - TimelapseTimelapse is a Windows machine running Active Directory with an open SMB share that contains a password-protected ZIP archive. The password can be…
- Hack The Box - BlueBlue is a Windows machine running SMB. A scan with Nmap can reveal that the box is vulnerable to EternalBlue, an exploit that targets a flaw in the…
- Hack The Box - ReturnReturn is a Windows machine running Active Directory. A webpage featuring a printer admin panel can be leveraged to reveal LDAP credentials, allowing…
- Hack The Box - SaunaSauna is a Windows machine featuring an Active Directory environment. A list of potential usernames can be generated based on a webpage that contains…
- Hack The Box - ActiveActive is a Windows machine running Active Directory with an open SMB share that contains an encrypted GPP (Group Policy Preferences) password for…
- Hack The Box - ForestForest is a Windows machine running Active Directory. An anonymous LDAP bind allows for enumeration of the system which can be leveraged to…
- Hack The Box - CronosCronos is a Linux machine hosting a website with an admin subdomain that contains a login form with a SQL injection vulnerability. After bypassing…
- Hack The Box - AuthorityAuthority is a Windows machine running Active Directory that has an open SMB share containing ansible vault encrypted credentials. Once decrypted…
- Hack The Box - TopologyTopology is a Linux machine hosting a website with a PNG image generator based on LaTeX inline math mode commands. This feature can be exploited to…
- Hack The Box - InjectInject is a Linux machine hosting a cloud storage and collaboration app built with Java and the Spring framework. A route on the app has a query…
- Hack The Box - MonitorsTwoMonitorsTwo is a Linux machine with a web application that uses Cacti, a web based monitoring and fault management framework. The version of Cacti…
- Hack The Box - BusquedaBusqueda is a Linux machine featuring a web application that provides users with a URL for a variety of search engines across the web with an…
- Hack The Box - PCPC is a Linux machine with an open port running gRPC (Google Remote Procedure Call). Interaction with the server using grpcui allows for the creation…
- Hack The Box - TwoMillionTwoMillion is a Linux machine hosting a web application with an API that has a command injection vulnerability. This vulnerability can be exploited…
- Hack The Box - MiraiMirai features a Raspberry Pi device with default credentials that can be used to log in over SSH. Enumeration of the machine reveals a USB block…
- Hack The Box - Diogenes' RageDiogenes' Rage is a web challenge featuring a vending machine application that enables users to purchase items using a coupon worth $1.00 that can be…