the🖊️testing.ninja

the🖊️testing.ninja

Hacking and Offensive Security Content.

HTB: VariaType Writeup

🔒 HTB: VariaType Writeup

Detailed writeup of Season 10 Hack The Box VariaType machine.  🔒 Protected Content

in
HTB: Gavel Writeup

🔒 HTB: Gavel Writeup

Detailed writeup of Season 10 Hack The Box Gavel machine.  🔒 Protected Content

in
HTB: Principal Writeup

🔒 HTB: Principal Writeup

Detailed writeup of Season 10 Hack The Box Principal machine.  🔒 Protected Content

in
HackTheBox: Expressway Writeup

HackTheBox: Expressway Writeup

Easy Linux box involving UDP enumeration, IKE Aggressive Mode PSK capture and cracking, SSH foothold, and privilege escalation via CVE-2025-32462 sudo hostname bypass.

in
HTB: CCTV Writeup

🔒 HTB: CCTV Writeup

Detailed writeup of Season 10 Hack The Box CCTV machine.  🔒 Protected Content

in
HackSmarter: City Council Writeup

HackSmarter: City Council Writeup

Medium Windows AD box where credential capture from a trojanized app leads through Kerberoasting, NTLM theft, DPAPI extraction, and SeImpersonatePrivilege abuse to Domain Admin.

in
HTB: Pirate Writeup

🔒 HTB: Pirate Writeup

Detailed writeup of Season 10 Hack The Box Pirate machine.  🔒 Protected Content

in
HackSmarter: Exception Writeup

HackSmarter: Exception Writeup

Medium Linux box from HackSmarter. Exploit CVE-2021-22911 NoSQL injection in Rocket.Chat 3.12.1 to achieve RCE, find database credentials in a leftover backup file that works for SSH, and escalate via a misconfigured sudo rule.

in
HTB: Interpreter Writeup

🔒 HTB: Interpreter Writeup

Detailed writeup of Season 10 Hack The Box Interpreter machine.  🔒 Protected Content

in
HTB: Giveback Writeup

HTB: Giveback Writeup

Giveback is a medium Linux machine involving a GiveWP PHP Object Injection RCE, pivoting through Kubernetes pods via chisel, exploiting PHP-CGI parameter injection, and escaping to root via a runc wrapper misconfiguration

in
HackSmarter: GitOops Writeup

HackSmarter: GitOops Writeup

A medium-difficulty HackSmarter lab where a public Gitea instance leaks a Terraform state file from a misconfigured S3 bucket, exposing an SSH private key and enabling an Atlantis RCE chain to root.

in
HTB: Soulmate Writeup

HTB: Soulmate Writeup

A Linux box featuring CrushFTP exploitation, credential discovery in Erlang configuration files, and privilege escalation through an Erlang SSH daemon allowing arbitrary command execution as root.

in