the🖊️testing.ninja

the🖊️testing.ninja

Hacking and Offensive Security Content.

HTB: VariaType Writeup

HTB: VariaType Writeup

Medium Linux box chaining a fonttools varLib arbitrary write for initial access, FontForge CVE-2024-25082 tar injection for lateral movement, and a setuptools URL-decode bypass to overwrite sudoers as root.

in
HTB: Connected Writeup

🔒 HTB: Connected Writeup

Detailed writeup of Season 11 Hack The Box Connected machine.  🔒 Protected Content

in
WebVerse Pro: Noshrun Writeup

WebVerse Pro: Noshrun Writeup

NoshRun is an Austin food-delivery startup hiding seven flags across its multi-service stack. SQL injection, host header poisoning, JWT forgery, race conditions, and command injection.

in
HackSmarter: Kiosk Writeup

HackSmarter: Kiosk Writeup

Break out of a locked Windows VDI kiosk over RDP, recover credentials from an unattend.xml, exploit an unquoted service path, and weaponize a DLL plugin hijack to gain local admin.

in
HTB: DevHub Writeup

🔒 HTB: DevHub Writeup

Detailed writeup of Season 11 Hack The Box DevHub machine.  🔒 Protected Content

in
WebVerse Pro: Murmur Writeup

WebVerse Pro: Murmur Writeup

A Series-B social platform across sixteen services. GraphQL mass assignment hands over credentials, ExifTool RCE pivots to the internal network, and a Drone CI pipeline injection closes it out.

in
HTB: Reactor Writeup

🔒 HTB: Reactor Writeup

Detailed writeup of Season 11 Hack The Box Reactor machine.  🔒 Protected Content

in
HTB: SmartHire Writeup

🔒 HTB: SmartHire Writeup

Detailed writeup of Hack The Box SmartHire machine.  🔒 Protected Content

in
HTB: Helix Writeup

🔒 HTB: Helix Writeup

Detailed writeup of Hack The Box Helix machine.  🔒 Protected Content

in
HackSmarter: Martini Writeup

HackSmarter: Martini Writeup

Black-box internal pentest against a Windows AD domain. Guest SMB access exposes credentials, leading to Kerberoasting, a WinRM foothold, and full domain compromise via password reuse and DCSync.

in
WebVerse Pro: BedRock Writeup

WebVerse Pro: BedRock Writeup

Six services, four languages, one engagement. BedRock is a sprawling property-management WebRange where the bugs live in the seams

in
HackSmarter: ShadowGate Writeup

HackSmarter: ShadowGate Writeup

Black-box Windows AD engagement against a single DC. AS-REP roasting yields initial credentials, shadow credential abuse pivots to a domain user, and ESC8 relay achieves DCSync.

in