ArticleHack The Box - Haircut Part 1
Hack The Box Haircut Part 1: Gain a foothold on the target via command execution, upgrade to an interactive TTY, and retrieve the user flag. • HackTh…
Practical security research, write-ups, guides, and lessons learned.
ArticleHack The Box Haircut Part 1: Gain a foothold on the target via command execution, upgrade to an interactive TTY, and retrieve the user flag. • HackTh…
ArticleHack The Box Sneaky: Enumerate a web server exposing only port 80. Pivot to SSH over IPv6 using a leaked RSA private key discovered via the /dev port…
ArticleHack The Box October Part 2: Identify a SUID binary, analyze it for unsafe use of strcpy (or similar), determine the exact overwrite offset, and craf…
ArticleFinally back hopefully! also made some improvements on xsisec.com: Finally I started to work fully again though it has been a lots of work in a new p…
ArticleHack The Box Apocalyst: Gain initial access to the WordPress host and escalate privileges to root. Capture user and root flags. • PortSwigger • wordp…
ArticleHack The Box blue: Exploit MS17‑010 (EternalBlue) on the target and obtain shells for user and SYSTEM. • HackTheBox • metasploit, msf
ArticleHack The Box Grandpa: Gain initial access to the target and escalate privileges to obtain user and root/Administrator flags on the Hack The Box machi…
ArticleHack The Box Joker: Gain initial access and escalate to root on 10.10.10.21, documenting each step with commands, reasoning, and evidence. • Security…
ArticleHack The Box Tentan: Gain user and root on the target at 10.10.10.10 by enumerating a WordPress site, abusing a vulnerable plugin to discover an uplo…
ArticleHack The Box Brainfuck: Gain initial access and retrieve the user flag on brainfuck.htb using web/app layer enumeration and misconfigurations. (Root…
ArticleBURP Suite procedure for enumeration nested directories: I completed yesterday the the Beep box though I found a lots of necessary stuff I should mak…
ArticleHack The Box Beep: Exploit the Elastix/vTigerCRM stack on beep.htb to obtain local credentials via Local File Inclusion (LFI), pivot to SSH, and capt…