the🖊️testing.ninja

the🖊️testing.ninja

Hacking and Offensive Security Content.

HackTheBox: Conversor Writeup

HackTheBox: Conversor Writeup

Conversor is a medium Linux machine featuring XSLT injection via an EXSLT file-write primitive, credential harvesting from a SQLite database, and privilege escalation through a misconfigured needrestart sudo rule.

in
HackTheBox: Postman Writeup

HackTheBox: Postman Writeup

Postman is an easy Linux box featuring an unauthenticated Redis instance, SSH key injection for initial access, a crackable encrypted private key, and a Webmin RCE vulnerability for root.

in
HackTheBox: Trick Writeup

HackTheBox: Trick Writeup

Trick is an easy Linux machine on HackTheBox combining DNS zone transfer enumeration, SQL injection, local file inclusion, and SMTP mail poisoning for foothold, then abusing a writable fail2ban action directory to escalate to root.

in
CTF: Ouro no Pescoço Revenge Writeup

CTF: Ouro no Pescoço Revenge Writeup

Multi-stage web challenge chaining DOM poisoning, dual CSPT, a semicolon-based query parser discrepancy between Flask and Quarkus, and a Unicode SSRF bypass via furl to read and exfiltrate a server-side flag.

in
HTB: VariaType Writeup

🔒 HTB: VariaType Writeup

Detailed writeup of Season 10 Hack The Box VariaType machine.  🔒 Protected Content

in
HTB: Gavel Writeup

HTB: Gavel Writeup

Gavel is a medium Linux machine featuring an exposed .git repository, a creative backtick-based SQL injection, PHP rule code execution via an admin panel, and a custom YAML-driven privilege escalation.

in
HTB: Principal Writeup

HTB: Principal Writeup

Medium Linux box exploiting CVE-2026-29000, a critical auth bypass in pac4j-jwt using a forged PlainJWT to gain admin access, leading to RCE via SSH certificate forgery.

in
HackTheBox: Expressway Writeup

HackTheBox: Expressway Writeup

Easy Linux box involving UDP enumeration, IKE Aggressive Mode PSK capture and cracking, SSH foothold, and privilege escalation via CVE-2025-32462 sudo hostname bypass.

in
HTB: CCTV Writeup

🔒 HTB: CCTV Writeup

Detailed writeup of Season 10 Hack The Box CCTV machine.  🔒 Protected Content

in
HackSmarter: City Council Writeup

HackSmarter: City Council Writeup

Medium Windows AD box where credential capture from a trojanized app leads through Kerberoasting, NTLM theft, DPAPI extraction, and SeImpersonatePrivilege abuse to Domain Admin.

in
HTB: Pirate Writeup

🔒 HTB: Pirate Writeup

Detailed writeup of Season 10 Hack The Box Pirate machine.  🔒 Protected Content

in
HackSmarter: Exception Writeup

HackSmarter: Exception Writeup

Medium Linux box from HackSmarter. Exploit CVE-2021-22911 NoSQL injection in Rocket.Chat 3.12.1 to achieve RCE, find database credentials in a leftover backup file that works for SSH, and escalate via a misconfigured sudo rule.

in