the🖊️testing.ninja

the🖊️testing.ninja

Hacking and Offensive Security Content.

HTB: Soulmate Writeup

🔒 HTB: Soulmate Writeup

Detailed writeup of Hack The Box Pterodactyl machine.  🔒 Protected Content

in
HTB: WingData Writeup

🔒 HTB: WingData Writeup

Detailed writeup of Season 10 Hack The Box WingData machine.  🔒 Protected Content

in
HTB: Signed Writeup

HTB: Signed Writeup

A Windows Active Directory box involving SQL Server authentication relay attacks, Kerberos ticket forging, and NTLM reflection to achieve SYSTEM access through creative pivoting techniques.

in
HTB: Pterodactyl Writeup

🔒 HTB: Pterodactyl Writeup

Detailed writeup of Season 10 Hack The Box Pterodactyl machine.  🔒 Protected Content

in
HTB: Facts Writeup

🔒 HTB: Facts Writeup

Detailed writeup of Season 10 Hack The Box Facts machine.  🔒 Protected Content

in
HTB: CodePartTwo Writeup

HTB: CodePartTwo Writeup

CodePartTwo is an easy-difficulty Linux machine featuring a vulnerable JavaScript execution sandbox that can be escaped to gain initial access, followed by weak credential recovery and privilege escalation through backup utility manipulation.

in
HackSmarter: StellarComms Writeup

HackSmarter: StellarComms Writeup

Step-by-step guide for StellarComms, a medium Active Directory box on HackSmarter. We exploit DACL misconfigurations and perform advanced credential recovery.

in
HTB: Imagery Writeup

HTB: Imagery Writeup

Imagery is a medium-difficulty Linux box where blind XSS leads to admin access, file traversal leaks source code, command injection gains a shell, and a sudo-abused backup tool escalates to root.

in
OSCP Certification: Review

OSCP Certification: Review

My journey to earning the OSCP: How I scored 100 points in just 7 hours. This review covers my preparation, the exam environment, and crucial success tips.

in
HTB: Voleur Writeup

HTB: Voleur Writeup

Voleur is a medium-difficulty Active Directory machine featuring password-protected Excel files, targeted Kerberoasting via WriteSPN abuse, AD object restoration, DPAPI credential extraction, and privileged access through WSL-accessible domain backups.

in
HackSmarter: Welcome Writeup

HackSmarter: Welcome Writeup

A complete writeup of the HackSmarter 'Welcome' machine. Learn about Active Directory privilege escalation, PDF cracking, and ADCS certificate abuse.

in
APISEC-CON CTF May 2025 - Writeups

APISEC-CON CTF May 2025 - Writeups

Solutions for the API security challenges featured in the APISEC-CON CTF (May 2025). I cover broken object-level authorization and complex API vulnerability.

in