💡 Ctrl + K to quickly focus search box

Down

There is a simple code review and a trick use of curl,kind of interesting.

2025-10-04 07:45 11.0 KB 8 images HTB Easy

BabyTwo

Overall, it's a very basic AD machine. The only unexpected thing is checking whether the user's password is the same as the username, which is definitely not something I would consider when attacking ...

2025-10-04 07:45 29.1 KB 4 images HTB Medium

Imagery

In general, for the foothold exploitation part, the initial upload vulnerability turned out to be a rabbit hole, and the XSS vulnerability used was also expected.

2025-10-04 07:45 18.8 KB 11 images HTB Medium

Race

Overall, the use of the foothold is very interesting, especially the use of the forgotten password link is really unexpected. Without a certain reading of the code, it is difficult to guess that the e...

2025-10-04 07:45 25.1 KB 16 images HTB Hard

Shibuya

This AD domain machine is incredibly useful, especially for lateral movement. Using RemotePotato0 to perform Cross Session Relay is a classic example. This type of abuse is always effective, especiall...

2025-10-04 07:45 45.3 KB 4 images HTB Hard

Delegate

It is a very standard AD domain machine. The overall difficulty is not high, and it is not difficult to confirm the vulnerability, especially for the privilege escalation part. The technique of abusin...

2025-09-28 06:17 30.3 KB 1 images HTB Medium

Media

The only thing I find odd and annoying about this machine is that the reverse shell code I use won't work anyway, forcing me to resort to using the msfvenom exe payload.

2025-09-28 06:17 28.0 KB 6 images HTB Medium

Baby

A very basic AD domain machine, the use of Exploit SeBackupPrivilege for privilege escalation is also very common.

2025-09-22 14:14 29.3 KB HTB Easy

Forgotten

Very simple and typical LimeSurveyexploit path and the root path is simple and easy to find out.

2025-09-22 14:14 15.7 KB 12 images HTB Easy

HackNet

Overall, this machine is quite interesting. The exploits for the SSTI and XSS vulnerabilities are quite clever, but the lack of hardcode is particularly disturbing.

2025-09-22 14:14 23.6 KB 17 images HTB Medium
Jump to