💡 Ctrl + K to quickly focus search box

NanoCorp

Overall, it's a very simple machine; both the starting point and the privilege escalation seem to be the expected steps.

2025-11-09 05:32 18.2 KB 6 images HTB Hard

Breach

Breach (medium, Windows): guest SMB write access is used to capture NTLMv2 hashes and obtain a low-privileged domain account. A kerberoastable svc_mssql service account is discovered and cracked; with...

2025-11-08 14:57 30.2 KB 1 images HTB Medium

Giveback

Overall, it's a very classic WordPress to Kubernetes migration machine. While it has some hard-coded elements and a CTF-like design.

2025-11-08 14:57 25.2 KB 10 images HTB Medium

Dump

By exploiting the website's PCAP upload/packaging function, malicious wildcards were injected into the zip command to achieve RCE and obtain a shell; the password from the database was used to move to...

2025-11-08 14:57 12.1 KB 6 images HTB Hard

Redelegate

On Redelegate, the attacker first downloaded the KeePass database via anonymous FTP and used the credentials to log into the local MSSQL database. They then performed enumeration and password spraying...

2025-11-08 14:57 33.5 KB 2 images HTB Hard

Store

The system exploits directory traversal through Express file storage to leak files encrypted with weak XOR (9 bytes), decrypts them to obtain SFTP credentials, accesses the host via SFTP, obtains an i...

2025-11-08 14:57 33.0 KB 10 images HTB Hard

Ten

Ten is a misconfigured shared-hosting box: register for FTP, abuse weak MySQL/FTP integration to pivot to a local user, then poison the etcd-driven Apache config reload to gain root.

2025-11-08 14:57 21.6 KB 11 images HTB Hard

Conversor

In general, it is a very CTF machine, mainly examining code review and the use of Xtensible Stylesheet Language Transformations.

2025-10-28 13:30 12.6 KB 7 images HTB Easy

Sendai

Sendai is a medium-difficulty AD box: anonymous SMB and RID brute force reveal expired/weak accounts; resetting thomas.powell yields a domain foothold. BloodHound shows abuse paths to the MGTSVC$ GMSA...

2025-10-28 13:30 42.7 KB 2 images HTB Medium

Hercules

It is a very complex and lengthy AD domain mixed web abnormal level machine, and it can even be said that the utilization path is more abnormal than DarkCorp.

2025-10-23 14:12 77.1 KB 37 images HTB Insane
Jump to