the🖊️testing.ninja

the🖊️testing.ninja

Hacking and Offensive Security Content.

WebVerse: Murmur Writeup

🔒 WebVerse: Murmur Writeup

A Series-B social platform across sixteen services. GraphQL mass assignment hands over credentials, ExifTool RCE pivots to the internal network, and a Drone CI pipeline injection closes it out.  🔒 Protected Content

in
HTB: Reactor Writeup

🔒 HTB: Reactor Writeup

Detailed writeup of Season 11 Hack The Box Reactor machine.  🔒 Protected Content

in
HTB: SmartHire Writeup

🔒 HTB: SmartHire Writeup

Detailed writeup of Hack The Box SmartHire machine.  🔒 Protected Content

in
HTB: Helix Writeup

🔒 HTB: Helix Writeup

Detailed writeup of Hack The Box Helix machine.  🔒 Protected Content

in
HackSmarter: Martini Writeup

HackSmarter: Martini Writeup

Black-box internal pentest against a Windows AD domain. Guest SMB access exposes credentials, leading to Kerberoasting, a WinRM foothold, and full domain compromise via password reuse and DCSync.

in
WebVerse Pro: BedRock Writeup

WebVerse Pro: BedRock Writeup

Six services, four languages, one engagement. BedRock is a sprawling property-management WebRange where the bugs live in the seams

in
HackSmarter: ShadowGate Writeup

HackSmarter: ShadowGate Writeup

Black-box Windows AD engagement against a single DC. AS-REP roasting yields initial credentials, shadow credential abuse pivots to a domain user, and ESC8 relay achieves DCSync.

in
HTB: PingPong Writeup

🔒 HTB: PingPong Writeup

Detailed writeup of Season 10 Hack The Box PingPong machine.  🔒 Protected Content

in
HTB: Redelegate Writeup

HTB: Redelegate Writeup

Hard Windows Active Directory box involving FTP enumeration, KeePass cracking, MSSQL credential abuse, ForceChangePassword ACL exploitation, and constrained delegation abuse to achieve DCSync.

in
HTB: Logging Writeup

🔒 HTB: Logging Writeup

Detailed writeup of Season 10 Hack The Box Logging machine.  🔒 Protected Content

in
HackSmarter: Samurai Writeup

HackSmarter: Samurai Writeup

Samurai is a Linux machine featuring a Joomla 4.2.5 instance vulnerable to CVE-2023-23752, leaking database credentials and sensitive information granting admin access, leading to RCE and a command injection privesc via a SUID-like custom binary.

in
HTB: Silentium Writeup

🔒 HTB: Silentium Writeup

Detailed writeup of Season 10 Hack The Box Silentium machine.  🔒 Protected Content

in