the🖊️testing.ninja

the🖊️testing.ninja

Hacking and Offensive Security Content.

HackTheBox: DarkZero Writeup

HackTheBox: DarkZero Writeup

Hard Windows Active Directory machine featuring MSSQL linked server lateral movement across two forests, CVE-2024-30088 kernel LPE to SYSTEM, and unconstrained delegation abuse for domain takeover.

in
HackTheBox: StreamIO Writeup

HackTheBox: StreamIO Writeup

StreamIO is a medium Windows Active Directory box. SQL injection on a PHP login page leaks MD5 hashes, cracking them gets admin panel access, where a hidden debug parameter enables LFI and PHP source disclosure leading to RCE via eval(). Pivoting through MSSQL and Firefox saved credentials exposes an AD path through LAPS.

in
HTB: Garfield Writeup

🔒 HTB: Garfield Writeup

Detailed writeup of Season 10 Hack The Box Garfield machine.  🔒 Protected Content

in
HackTheBox: Authority Writeup

HackTheBox: Authority Writeup

Medium Windows Active Directory box where Ansible Vault secrets on an SMB share lead to PWM credential theft, then ESC1 ADCS abuse for domain admin.

in
HackTheBox: Craft Writeup

HackTheBox: Craft Writeup

Craft is a medium Linux machine featuring a Python eval injection in a craft beer REST API, credential leakage via a self-hosted Gogs instance, and privilege escalation through HashiCorp Vault OTP SSH.

in
HackTheBox: VulnCicada Writeup

HackTheBox: VulnCicada Writeup

Windows AD machine where NFS exposes a credential in a sticky note photo, NTLM is disabled forcing Kerberos throughout, and ESC8 lets us relay the DC machine account to ADCS for a certificate-based takeover.

in
HackTheBox: Jeeves Writeup

HackTheBox: Jeeves Writeup

A medium Windows box featuring an unauthenticated Jenkins instance, a KeePass database holding an NTLM hash, and a flag hidden inside an NTFS Alternate Data Stream.

in
HTB: DevArea Writeup

🔒 HTB: DevArea Writeup

Detailed writeup of Season 10 Hack The Box DevArea machine.  🔒 Protected Content

in
HackTheBox: Media Writeup

HackTheBox: Media Writeup

Medium Windows box where a hiring page file upload is abused to steal an NTLMv2 hash via a Windows Media Player playlist, leading to SSH access and a SeTcbPrivilege escalation to SYSTEM.

in
HackTheBox: Administrator Writeup

HackTheBox: Administrator Writeup

Medium Windows Active Directory box starting with given credentials. Exploit an ACL chain to pivot accounts, crack a PasswordSafe backup, and abuse GenericWrite to Kerberoast a DCSync-capable user.

in
HTB: Kobold Writeup

🔒 HTB: Kobold Writeup

Detailed writeup of Season 10 Hack The Box Kobold machine.  🔒 Protected Content

in
HackTheBox: Conversor Writeup

HackTheBox: Conversor Writeup

Conversor is a medium Linux machine featuring XSLT injection via an EXSLT file-write primitive, credential harvesting from a SQLite database, and privilege escalation through a misconfigured needrestart sudo rule.

in