the🖊️testing.ninja

the🖊️testing.ninja

Hacking and Offensive Security Content.

HackTheBox: Jeeves Writeup

HackTheBox: Jeeves Writeup

A medium Windows box featuring an unauthenticated Jenkins instance, a KeePass database holding an NTLM hash, and a flag hidden inside an NTFS Alternate Data Stream.

in
HTB: DevArea Writeup

🔒 HTB: DevArea Writeup

Detailed writeup of Season 10 Hack The Box DevArea machine.  🔒 Protected Content

in
HackTheBox: Media Writeup

HackTheBox: Media Writeup

Medium Windows box where a hiring page file upload is abused to steal an NTLMv2 hash via a Windows Media Player playlist, leading to SSH access and a SeTcbPrivilege escalation to SYSTEM.

in
HackTheBox: Administrator Writeup

HackTheBox: Administrator Writeup

Medium Windows Active Directory box starting with given credentials. Exploit an ACL chain to pivot accounts, crack a PasswordSafe backup, and abuse GenericWrite to Kerberoast a DCSync-capable user.

in
HTB: Kobold Writeup

🔒 HTB: Kobold Writeup

Detailed writeup of Season 10 Hack The Box Kobold machine.  🔒 Protected Content

in
HackTheBox: Conversor Writeup

HackTheBox: Conversor Writeup

Conversor is a medium Linux machine featuring XSLT injection via an EXSLT file-write primitive, credential harvesting from a SQLite database, and privilege escalation through a misconfigured needrestart sudo rule.

in
HackTheBox: Postman Writeup

HackTheBox: Postman Writeup

Postman is an easy Linux box featuring an unauthenticated Redis instance, SSH key injection for initial access, a crackable encrypted private key, and a Webmin RCE vulnerability for root.

in
HackTheBox: Trick Writeup

HackTheBox: Trick Writeup

Trick is an easy Linux machine on HackTheBox combining DNS zone transfer enumeration, SQL injection, local file inclusion, and SMTP mail poisoning for foothold, then abusing a writable fail2ban action directory to escalate to root.

in
CTF: Ouro no Pescoço Revenge Writeup

CTF: Ouro no Pescoço Revenge Writeup

Multi-stage web challenge chaining DOM poisoning, dual CSPT, a semicolon-based query parser discrepancy between Flask and Quarkus, and a Unicode SSRF bypass via furl to read and exfiltrate a server-side flag.

in
HTB: VariaType Writeup

🔒 HTB: VariaType Writeup

Detailed writeup of Season 10 Hack The Box VariaType machine.  🔒 Protected Content

in
HTB: Gavel Writeup

HTB: Gavel Writeup

Gavel is a medium Linux machine featuring an exposed .git repository, a creative backtick-based SQL injection, PHP rule code execution via an admin panel, and a custom YAML-driven privilege escalation.

in
HTB: Principal Writeup

HTB: Principal Writeup

Medium Linux box exploiting CVE-2026-29000, a critical auth bypass in pac4j-jwt using a forged PlainJWT to gain admin access, leading to RCE via SSH certificate forgery.

in