the🖊️testing.ninja

the🖊️testing.ninja

Hacking and Offensive Security Content.

HTB: Silentium Writeup

🔒 HTB: Silentium Writeup

Detailed writeup of Season 10 Hack The Box Silentium machine.  🔒 Protected Content

in
HTB: Eighteen Writeup

HTB: Eighteen Writeup

Eighteen is a Windows Server 2025 domain controller where MSSQL impersonation leads to a cracked PBKDF2 hash and a password spray foothold, then BadSuccessor dMSA abuse escalates to Domain Admin.

in
HTB: EscapeTwo Writeup

HTB: EscapeTwo Writeup

EscapeTwo is an easy Windows Active Directory machine on HackTheBox. Starting with provided credentials, we enumerate SMB shares to recover plaintext credentials from Excel files, pivot through MSSQL to a shell as sql_svc, recover ryan credentials from a SQL installer config, then abuse ESC4 via the ca_svc account to forge an administrator certificate and own the domain.

in
HTB: DarkZero Writeup

HTB: DarkZero Writeup

Hard Windows Active Directory machine featuring MSSQL linked server lateral movement across two forests, CVE-2024-30088 kernel LPE to SYSTEM, and unconstrained delegation abuse for domain takeover.

in
HTB: StreamIO Writeup

HTB: StreamIO Writeup

StreamIO is a medium Windows Active Directory box. SQL injection on a PHP login page leaks MD5 hashes, cracking them gets admin panel access, where a hidden debug parameter enables LFI and PHP source disclosure leading to RCE via eval(). Pivoting through MSSQL and Firefox saved credentials exposes an AD path through LAPS.

in
HTB: Garfield Writeup

🔒 HTB: Garfield Writeup

Detailed writeup of Season 10 Hack The Box Garfield machine.  🔒 Protected Content

in
HTB: Authority Writeup

HTB: Authority Writeup

Medium Windows Active Directory box where Ansible Vault secrets on an SMB share lead to PWM credential theft, then ESC1 ADCS abuse for domain admin.

in
HTB: Craft Writeup

HTB: Craft Writeup

Craft is a medium Linux machine featuring a Python eval injection in a craft beer REST API, credential leakage via a self-hosted Gogs instance, and privilege escalation through HashiCorp Vault OTP SSH.

in
HTB: VulnCicada Writeup

HTB: VulnCicada Writeup

Windows AD machine where NFS exposes a credential in a sticky note photo, NTLM is disabled forcing Kerberos throughout, and ESC8 lets us relay the DC machine account to ADCS for a certificate-based takeover.

in
HTB: Jeeves Writeup

HTB: Jeeves Writeup

A medium Windows box featuring an unauthenticated Jenkins instance, a KeePass database holding an NTLM hash, and a flag hidden inside an NTFS Alternate Data Stream.

in
HTB: DevArea Writeup

🔒 HTB: DevArea Writeup

Detailed writeup of Season 10 Hack The Box DevArea machine.  🔒 Protected Content

in
HTB: Media Writeup

HTB: Media Writeup

Medium Windows box where a hiring page file upload is abused to steal an NTLMv2 hash via a Windows Media Player playlist, leading to SSH access and a SeTcbPrivilege escalation to SYSTEM.

in