the🖊️testing.ninja

the🖊️testing.ninja

Hacking and Offensive Security Content.

HTB: Interpreter Writeup

🔒 HTB: Interpreter Writeup

Detailed writeup of Season 10 Hack The Box Interpreter machine.  🔒 Protected Content

in
HTB: Giveback Writeup

HTB: Giveback Writeup

Giveback is a medium Linux machine involving a GiveWP PHP Object Injection RCE, pivoting through Kubernetes pods via chisel, exploiting PHP-CGI parameter injection, and escaping to root via a runc wrapper misconfiguration

in
HackSmarter: GitOops Writeup

HackSmarter: GitOops Writeup

A medium-difficulty HackSmarter lab where a public Gitea instance leaks a Terraform state file from a misconfigured S3 bucket, exposing an SSH private key and enabling an Atlantis RCE chain to root.

in
HTB: Soulmate Writeup

HTB: Soulmate Writeup

A Linux box featuring CrushFTP exploitation, credential discovery in Erlang configuration files, and privilege escalation through an Erlang SSH daemon allowing arbitrary command execution as root.

in
HTB: WingData Writeup

🔒 HTB: WingData Writeup

Detailed writeup of Season 10 Hack The Box WingData machine.  🔒 Protected Content

in
HTB: Signed Writeup

HTB: Signed Writeup

A Windows Active Directory box involving SQL Server authentication relay attacks, Kerberos ticket forging, and NTLM reflection to achieve SYSTEM access through creative pivoting techniques.

in
HTB: Pterodactyl Writeup

🔒 HTB: Pterodactyl Writeup

Detailed writeup of Season 10 Hack The Box Pterodactyl machine.  🔒 Protected Content

in
HTB: Facts Writeup

🔒 HTB: Facts Writeup

Detailed writeup of Season 10 Hack The Box Facts machine.  🔒 Protected Content

in
HTB: CodePartTwo Writeup

HTB: CodePartTwo Writeup

CodePartTwo is an easy-difficulty Linux machine featuring a vulnerable JavaScript execution sandbox that can be escaped to gain initial access, followed by weak credential recovery and privilege escalation through backup utility manipulation.

in
HackSmarter: StellarComms Writeup

HackSmarter: StellarComms Writeup

Step-by-step guide for StellarComms, a medium Active Directory box on HackSmarter. We exploit DACL misconfigurations and perform advanced credential recovery.

in
HackTheBox: Overwatch Writeup

🔒 HackTheBox: Overwatch Writeup

Detailed writeup of Hack The Box Overwatch machine.  🔒 Protected Content

in
HTB: Imagery Writeup

HTB: Imagery Writeup

Imagery is a medium-difficulty Linux box where blind XSS leads to admin access, file traversal leaks source code, command injection gains a shell, and a sudo-abused backup tool escalates to root.

in