the๐Ÿ–Š๏ธtesting.ninja

the๐Ÿ–Š๏ธtesting.ninja

Hacking and Offensive Security Content.

HTB: Helix Writeup

HTB: Helix Writeup

Medium Linux box featuring Apache NiFi CVE-2023-34468 for initial access, SSH key recovery for a foothold, and OPC-UA industrial protocol manipulation to trigger a privileged maintenance console.

in
HTB: Kobold Writeup

HTB: Kobold Writeup

Kobold is an easy Linux machine featuring an MCPJam inspector RCE, a PrivateBin template cookie LFI for container escape, and Docker API abuse to reach root.

in
HackSmarter: SysAdmins Writeup

HackSmarter: SysAdmins Writeup

Anonymous FTP leaks a breach notice pointing at a public paste of stolen passwords. Spraying fails everywhere except SNMPv3, where the MIB gives up an SSH password, and sudo chroot hands over root.

in
HTB: BedSide Writeup

๐Ÿ”’ HTB: BedSide Writeup

Detailed writeup / walkthrough of Season 11 Hack The Box (HTB) BedSide machine.  ๐Ÿ”’ Protected Content

in
HTB: Paperwork Writeup

๐Ÿ”’ HTB: Paperwork Writeup

Detailed writeup / walkthrough of Season 11 Hack The Box (HTB) Paperwork machine.  ๐Ÿ”’ Protected Content

in
HackSmarter: Dark Writeup

HackSmarter: Dark Writeup

A WordPress site running a vulnerable Modular DS plugin falls to CVE-2026-23550, an unauthenticated admin takeover bug, leading to a plugin-based shell and a Docker group escape to root.

in
HTB: MakeSense Writeup

๐Ÿ”’ HTB: MakeSense Writeup

Detailed writeup / walkthrough of Season 11 Hack The Box (HTB) MakeSense machine.  ๐Ÿ”’ Protected Content

in
HTB: Enigma Writeup

๐Ÿ”’ HTB: Enigma Writeup

Detailed writeup / walkthrough of Season 11 Hack The Box (HTB) Enigma machine.  ๐Ÿ”’ Protected Content

in
HTB: NanoCorp Writeup

HTB: NanoCorp Writeup

NanoCorp is a Windows AD box: a job-application zip upload leaks an NTLM hash via CVE-2025-24071, AD group abuse pivots accounts, and an NTLM reflection trick (CVE-2025-33073) lands a privileged DC shell.

in
HTB: Nimbus Writeup

๐Ÿ”’ HTB: Nimbus Writeup

Detailed writeup / walkthrough of Season 11 Hack The Box (HTB) Nimbus machine.  ๐Ÿ”’ Protected Content

in
WebVerse Pro: HookLink Writeup

WebVerse Pro: HookLink Writeup

A WebVerse engagement against HookLink, a Miami dating app, chaining mass assignment into moderator access, a shell-out command injection, and a client-trusted geolocation oracle for full compromise.

in
HTB: VariaType Writeup

HTB: VariaType Writeup

Medium Linux box chaining a fonttools varLib arbitrary write for initial access, FontForge CVE-2024-25082 tar injection for lateral movement, and a setuptools URL-decode bypass to overwrite sudoers as root.

in