ArticleCommand Injection Part 1 TryHackMe | Owasp Top 10
Command Injection Part 1 TryHackMe | Owasp Top 10: I have started to relearn and get even more basics about different methods to be able to break int…
Practical security research, write-ups, guides, and lessons learned.
ArticleCommand Injection Part 1 TryHackMe | Owasp Top 10: I have started to relearn and get even more basics about different methods to be able to break int…
ArticleHack The Box Help: Gain an initial foothold on 10.10.10.121 by exploiting an unauthenticated file upload in HelpDeskZ 1.0.2, obtain a reverse shell,…
ArticleHack The Box Explore user flag: Capture at least one user flag per day. This entry documents a box where initial scans missed the path to user, follo…
ArticleHack The Box CAP root flag: Gain root on the target after obtaining user nathan, documenting the exact steps, commands, and evidence. • HackTheBox •…
ArticleReported my first Bug Bounty finding: Bug Bounty Hunting Journey – First Steps • BugBounty • XSS • bugbounty, xss
ArticleHack The Box Wall User and Root flag: Gain initial access to the host, then escalate privileges to root. • HackTheBox • brute force, nmap
ArticleHack The Box Luke User and Root flag: Gain initial foothold and escalate to read user and root flags, documenting the JWT weaknesses and the API/port…
ArticleHack The Box Calamity user flag: Re‑establish workflow after a break and warm up on a lighter web box. Enumerate a minimal surface (HTTP + SSH). Iden…
ArticleHack The Box Bank Root Flag: Gain root on the target by leveraging local privilege escalation. Document the minimal steps, verification, and hardenin…
ArticleHack The Box Bank user flag: Gain user access on bank.htb by abusing the support.php file upload to achieve remote code execution and retrieve the us…
ArticleHack The Box Europa Part 2: Escalate from a low privilege shell (from Part 1) to root by abusing a writable cron executed script, and capture the roo…
ArticleHack The Box Europa Part 1: Obtain the user flag on the Hack The Box machine Europe by enumerating the web app and exploiting it for code execution.…