🖊️testing.ninja

Menu

  • Home
  • About
  • Certifications
  • Writeups
  • Website
  • Contact
  • Home
  • About
  • Certifications
  • Writeups
  • Website
  • Contact
Search
4 posts tagged

active-directory

HTB: Signed Writeup
8 min read Feb 7, 2026

HTB: Signed Writeup

A Windows Active Directory box involving SQL Server authentication relay attacks, Kerberos ticket forging, and NTLM reflection to achieve SYSTEM access through creative pivoting techniques.

thepentesting.ninja's Picture
thepentesting.ninja in signed windows active-directory mssql kerberos ntlm-relay ntlm-reflection
HackSmarter: StellarComms Writeup
7 min read Jan 29, 2026

HackSmarter: StellarComms Writeup

Step-by-step guide for StellarComms, a medium Active Directory box on HackSmarter. We exploit DACL misconfigurations and perform advanced credential recovery.

thepentesting.ninja's Picture
thepentesting.ninja in writeup hacksmarter windows active-directory
HTB: Voleur Writeup
24 min read Nov 1, 2025

HTB: Voleur Writeup

Voleur is a medium-difficulty Active Directory machine featuring password-protected Excel files, targeted Kerberoasting via WriteSPN abuse, AD object restoration, DPAPI credential extraction, and privileged access through WSL-accessible domain backups.

thepentesting.ninja's Picture
thepentesting.ninja in htb voleur active-directory kerberoasting dpapi ntds kerberos writespn restore-ad-object
HackSmarter: Welcome Writeup
10 min read Jun 11, 2025

HackSmarter: Welcome Writeup

A complete writeup of the HackSmarter 'Welcome' machine. Learn about Active Directory privilege escalation, PDF cracking, and ADCS certificate abuse.

thepentesting.ninja's Picture
thepentesting.ninja in active-directory adcs password-cracking writeup
1 post tagged

adcs

HackSmarter: Welcome Writeup
10 min read Jun 11, 2025

HackSmarter: Welcome Writeup

A complete writeup of the HackSmarter 'Welcome' machine. Learn about Active Directory privilege escalation, PDF cracking, and ADCS certificate abuse.

thepentesting.ninja's Picture
thepentesting.ninja in active-directory adcs password-cracking writeup
1 post tagged

ai

HTB Cyber Apocalypse 2025 - AI Challenges
9 min read Mar 26, 2025

HTB Cyber Apocalypse 2025 - AI Challenges

Exploring the AI category in the HTB Cyber Apocalypse 2025 CTF. This write-up covers prompt injection and model manipulation challenges with step-by-step logic.

thepentesting.ninja's Picture
thepentesting.ninja in ctf htb writeup ai
2 posts tagged

api

APISEC-CON CTF May 2025 - Writeups
12 min read May 25, 2025

APISEC-CON CTF May 2025 - Writeups

Solutions for the API security challenges featured in the APISEC-CON CTF (May 2025). I cover broken object-level authorization and complex API vulnerability.

thepentesting.ninja's Picture
thepentesting.ninja in api ctf apisec writeup
APISEC CTF 2025 - Writeup
11 min read Mar 3, 2025

APISEC CTF 2025 - Writeup

A detailed walkthrough of the APISEC CTF 2025, featuring the 'One Request to Rule Them All' challenge. Includes a full video guide and technical methodology.

thepentesting.ninja's Picture
thepentesting.ninja in api ctf apisec writeup
2 posts tagged

apisec

APISEC-CON CTF May 2025 - Writeups
12 min read May 25, 2025

APISEC-CON CTF May 2025 - Writeups

Solutions for the API security challenges featured in the APISEC-CON CTF (May 2025). I cover broken object-level authorization and complex API vulnerability.

thepentesting.ninja's Picture
thepentesting.ninja in api ctf apisec writeup
APISEC CTF 2025 - Writeup
11 min read Mar 3, 2025

APISEC CTF 2025 - Writeup

A detailed walkthrough of the APISEC CTF 2025, featuring the 'One Request to Rule Them All' challenge. Includes a full video guide and technical methodology.

thepentesting.ninja's Picture
thepentesting.ninja in api ctf apisec writeup
1 post tagged

atlantis

HackSmarter: GitOops Writeup
15 min read Feb 19, 2026

HackSmarter: GitOops Writeup

A medium-difficulty HackSmarter lab where a public Gitea instance leaks a Terraform state file from a misconfigured S3 bucket, exposing an SSH private key and enabling an Atlantis RCE chain to root.

thepentesting.ninja's Picture
thepentesting.ninja in gitoops hacksmarter terraform gitea atlantis s3
1 post tagged

bscp

BSCP Certification: Review
16 min read May 5, 2025

BSCP Certification: Review

Reviewing the Burp Suite Certified Practitioner (BSCP) exam. Learn the best strategies for using Burp Suite Professional to pass this rigorous web cert exam.

thepentesting.ninja's Picture
thepentesting.ninja in certifications bscp webapp review portswigger burpsuite
1 post tagged

burpsuite

BSCP Certification: Review
16 min read May 5, 2025

BSCP Certification: Review

Reviewing the Burp Suite Certified Practitioner (BSCP) exam. Learn the best strategies for using Burp Suite Professional to pass this rigorous web cert exam.

thepentesting.ninja's Picture
thepentesting.ninja in certifications bscp webapp review portswigger burpsuite
1 post tagged

capenx

CAPenX Certification: Review
11 min read Feb 17, 2025

CAPenX Certification: Review

My comprehensive review of the SecOps Group CAPenX certification. I share my exam experience, study resources, and essential tips for passing on your first try.

thepentesting.ninja's Picture
thepentesting.ninja in certifications capenx webapp review
1 post tagged

cbbh

CBBH/CWES Certification: Review
12 min read Feb 17, 2025

CBBH/CWES Certification: Review

A deep dive into the Hack The Box CBBH, now CWES certification. Explore my preparation strategy, exam difficulty review, and advice for aspiring web testers.

thepentesting.ninja's Picture
thepentesting.ninja in certifications cbbh cwes webapp review hackthebox
4 posts tagged

certifications

OSCP Certification: Review
9 min read Jan 17, 2026

OSCP Certification: Review

My journey to earning the OSCP: How I scored 100 points in just 7 hours. This review covers my preparation, the exam environment, and crucial success tips.

thepentesting.ninja's Picture
thepentesting.ninja in certifications oscp pentesting review offsec
BSCP Certification: Review
16 min read May 5, 2025

BSCP Certification: Review

Reviewing the Burp Suite Certified Practitioner (BSCP) exam. Learn the best strategies for using Burp Suite Professional to pass this rigorous web cert exam.

thepentesting.ninja's Picture
thepentesting.ninja in certifications bscp webapp review portswigger burpsuite
CBBH/CWES Certification: Review
12 min read Feb 17, 2025

CBBH/CWES Certification: Review

A deep dive into the Hack The Box CBBH, now CWES certification. Explore my preparation strategy, exam difficulty review, and advice for aspiring web testers.

thepentesting.ninja's Picture
thepentesting.ninja in certifications cbbh cwes webapp review hackthebox
CAPenX Certification: Review
11 min read Feb 17, 2025

CAPenX Certification: Review

My comprehensive review of the SecOps Group CAPenX certification. I share my exam experience, study resources, and essential tips for passing on your first try.

thepentesting.ninja's Picture
thepentesting.ninja in certifications capenx webapp review
1 post tagged

charcol

HTB: Imagery Writeup
11 min read Jan 24, 2026

HTB: Imagery Writeup

Imagery is a medium-difficulty Linux box where blind XSS leads to admin access, file traversal leaks source code, command injection gains a shell, and a sudo-abused backup tool escalates to root.

thepentesting.ninja's Picture
thepentesting.ninja in htb linux xss lfi command-injection charcol
1 post tagged

codeparttwo

HTB: CodePartTwo Writeup
8 min read Jan 31, 2026

HTB: CodePartTwo Writeup

CodePartTwo is an easy-difficulty Linux machine featuring a vulnerable JavaScript execution sandbox that can be escaped to gain initial access, followed by weak credential recovery and privilege escalation through backup utility manipulation.

thepentesting.ninja's Picture
thepentesting.ninja in codeparttwo linux js2py sandbox-escape npbackup htb
1 post tagged

command-injection

HTB: Imagery Writeup
11 min read Jan 24, 2026

HTB: Imagery Writeup

Imagery is a medium-difficulty Linux box where blind XSS leads to admin access, file traversal leaks source code, command injection gains a shell, and a sudo-abused backup tool escalates to root.

thepentesting.ninja's Picture
thepentesting.ninja in htb linux xss lfi command-injection charcol
1 post tagged

crushftp

HTB: Soulmate Writeup
6 min read Feb 14, 2026

HTB: Soulmate Writeup

A Linux box featuring CrushFTP exploitation, credential discovery in Erlang configuration files, and privilege escalation through an Erlang SSH daemon allowing arbitrary command execution as root.

thepentesting.ninja's Picture
thepentesting.ninja in htb soulmate crushftp erlang cve-2025-31161 linux
5 posts tagged

ctf

APISEC-CON CTF May 2025 - Writeups
12 min read May 25, 2025

APISEC-CON CTF May 2025 - Writeups

Solutions for the API security challenges featured in the APISEC-CON CTF (May 2025). I cover broken object-level authorization and complex API vulnerability.

thepentesting.ninja's Picture
thepentesting.ninja in api ctf apisec writeup
b01lersc CTF 2025 - Web Writeup
7 min read Apr 21, 2025

b01lersc CTF 2025 - Web Writeup

Detailed write-up for two challenging web tasks from b01lersc CTF 2025. I break down the exploitation chain from discovery to obtaining the final flag easily.

thepentesting.ninja's Picture
thepentesting.ninja in web ctf writeup
HTB Cyber Apocalypse 2025 - Web Challenges
16 min read Mar 26, 2025

HTB Cyber Apocalypse 2025 - Web Challenges

Comprehensive solutions for the Web challenges during the HTB Cyber Apocalypse 2025 CTF. Learn about modern web vulnerabilities and bypasses used in the event.

thepentesting.ninja's Picture
thepentesting.ninja in ctf htb writeup web
HTB Cyber Apocalypse 2025 - AI Challenges
9 min read Mar 26, 2025

HTB Cyber Apocalypse 2025 - AI Challenges

Exploring the AI category in the HTB Cyber Apocalypse 2025 CTF. This write-up covers prompt injection and model manipulation challenges with step-by-step logic.

thepentesting.ninja's Picture
thepentesting.ninja in ctf htb writeup ai
APISEC CTF 2025 - Writeup
11 min read Mar 3, 2025

APISEC CTF 2025 - Writeup

A detailed walkthrough of the APISEC CTF 2025, featuring the 'One Request to Rule Them All' challenge. Includes a full video guide and technical methodology.

thepentesting.ninja's Picture
thepentesting.ninja in api ctf apisec writeup
1 post tagged

cve-2024-4577

HTB: Giveback Writeup
14 min read Feb 21, 2026

HTB: Giveback Writeup

Giveback is a medium Linux machine involving a GiveWP PHP Object Injection RCE, pivoting through Kubernetes pods via chisel, exploiting PHP-CGI parameter injection, and escaping to root via a runc wrapper misconfiguration

thepentesting.ninja's Picture
thepentesting.ninja in giveback htb linux kubernetes cve-2024-4577 runc cve-2024-5932
1 post tagged

cve-2024-5932

HTB: Giveback Writeup
14 min read Feb 21, 2026

HTB: Giveback Writeup

Giveback is a medium Linux machine involving a GiveWP PHP Object Injection RCE, pivoting through Kubernetes pods via chisel, exploiting PHP-CGI parameter injection, and escaping to root via a runc wrapper misconfiguration

thepentesting.ninja's Picture
thepentesting.ninja in giveback htb linux kubernetes cve-2024-4577 runc cve-2024-5932
1 post tagged

cve-2025-31161

HTB: Soulmate Writeup
6 min read Feb 14, 2026

HTB: Soulmate Writeup

A Linux box featuring CrushFTP exploitation, credential discovery in Erlang configuration files, and privilege escalation through an Erlang SSH daemon allowing arbitrary command execution as root.

thepentesting.ninja's Picture
thepentesting.ninja in htb soulmate crushftp erlang cve-2025-31161 linux
1 post tagged

cwes

CBBH/CWES Certification: Review
12 min read Feb 17, 2025

CBBH/CWES Certification: Review

A deep dive into the Hack The Box CBBH, now CWES certification. Explore my preparation strategy, exam difficulty review, and advice for aspiring web testers.

thepentesting.ninja's Picture
thepentesting.ninja in certifications cbbh cwes webapp review hackthebox
1 post tagged

dpapi

HTB: Voleur Writeup
24 min read Nov 1, 2025

HTB: Voleur Writeup

Voleur is a medium-difficulty Active Directory machine featuring password-protected Excel files, targeted Kerberoasting via WriteSPN abuse, AD object restoration, DPAPI credential extraction, and privileged access through WSL-accessible domain backups.

thepentesting.ninja's Picture
thepentesting.ninja in htb voleur active-directory kerberoasting dpapi ntds kerberos writespn restore-ad-object
1 post tagged

erlang

HTB: Soulmate Writeup
6 min read Feb 14, 2026

HTB: Soulmate Writeup

A Linux box featuring CrushFTP exploitation, credential discovery in Erlang configuration files, and privilege escalation through an Erlang SSH daemon allowing arbitrary command execution as root.

thepentesting.ninja's Picture
thepentesting.ninja in htb soulmate crushftp erlang cve-2025-31161 linux
1 post tagged

gitea

HackSmarter: GitOops Writeup
15 min read Feb 19, 2026

HackSmarter: GitOops Writeup

A medium-difficulty HackSmarter lab where a public Gitea instance leaks a Terraform state file from a misconfigured S3 bucket, exposing an SSH private key and enabling an Atlantis RCE chain to root.

thepentesting.ninja's Picture
thepentesting.ninja in gitoops hacksmarter terraform gitea atlantis s3
1 post tagged

gitoops

HackSmarter: GitOops Writeup
15 min read Feb 19, 2026

HackSmarter: GitOops Writeup

A medium-difficulty HackSmarter lab where a public Gitea instance leaks a Terraform state file from a misconfigured S3 bucket, exposing an SSH private key and enabling an Atlantis RCE chain to root.

thepentesting.ninja's Picture
thepentesting.ninja in gitoops hacksmarter terraform gitea atlantis s3
1 post tagged

giveback

HTB: Giveback Writeup
14 min read Feb 21, 2026

HTB: Giveback Writeup

Giveback is a medium Linux machine involving a GiveWP PHP Object Injection RCE, pivoting through Kubernetes pods via chisel, exploiting PHP-CGI parameter injection, and escaping to root via a runc wrapper misconfiguration

thepentesting.ninja's Picture
thepentesting.ninja in giveback htb linux kubernetes cve-2024-4577 runc cve-2024-5932
2 posts tagged

hacksmarter

HackSmarter: GitOops Writeup
15 min read Feb 19, 2026

HackSmarter: GitOops Writeup

A medium-difficulty HackSmarter lab where a public Gitea instance leaks a Terraform state file from a misconfigured S3 bucket, exposing an SSH private key and enabling an Atlantis RCE chain to root.

thepentesting.ninja's Picture
thepentesting.ninja in gitoops hacksmarter terraform gitea atlantis s3
HackSmarter: StellarComms Writeup
7 min read Jan 29, 2026

HackSmarter: StellarComms Writeup

Step-by-step guide for StellarComms, a medium Active Directory box on HackSmarter. We exploit DACL misconfigurations and perform advanced credential recovery.

thepentesting.ninja's Picture
thepentesting.ninja in writeup hacksmarter windows active-directory
1 post tagged

hackthebox

CBBH/CWES Certification: Review
12 min read Feb 17, 2025

CBBH/CWES Certification: Review

A deep dive into the Hack The Box CBBH, now CWES certification. Explore my preparation strategy, exam difficulty review, and advice for aspiring web testers.

thepentesting.ninja's Picture
thepentesting.ninja in certifications cbbh cwes webapp review hackthebox
7 posts tagged

htb

HTB: Giveback Writeup
14 min read Feb 21, 2026

HTB: Giveback Writeup

Giveback is a medium Linux machine involving a GiveWP PHP Object Injection RCE, pivoting through Kubernetes pods via chisel, exploiting PHP-CGI parameter injection, and escaping to root via a runc wrapper misconfiguration

thepentesting.ninja's Picture
thepentesting.ninja in giveback htb linux kubernetes cve-2024-4577 runc cve-2024-5932
HTB: Soulmate Writeup
6 min read Feb 14, 2026

HTB: Soulmate Writeup

A Linux box featuring CrushFTP exploitation, credential discovery in Erlang configuration files, and privilege escalation through an Erlang SSH daemon allowing arbitrary command execution as root.

thepentesting.ninja's Picture
thepentesting.ninja in htb soulmate crushftp erlang cve-2025-31161 linux
HTB: CodePartTwo Writeup
8 min read Jan 31, 2026

HTB: CodePartTwo Writeup

CodePartTwo is an easy-difficulty Linux machine featuring a vulnerable JavaScript execution sandbox that can be escaped to gain initial access, followed by weak credential recovery and privilege escalation through backup utility manipulation.

thepentesting.ninja's Picture
thepentesting.ninja in codeparttwo linux js2py sandbox-escape npbackup htb
HTB: Imagery Writeup
11 min read Jan 24, 2026

HTB: Imagery Writeup

Imagery is a medium-difficulty Linux box where blind XSS leads to admin access, file traversal leaks source code, command injection gains a shell, and a sudo-abused backup tool escalates to root.

thepentesting.ninja's Picture
thepentesting.ninja in htb linux xss lfi command-injection charcol
HTB: Voleur Writeup
24 min read Nov 1, 2025

HTB: Voleur Writeup

Voleur is a medium-difficulty Active Directory machine featuring password-protected Excel files, targeted Kerberoasting via WriteSPN abuse, AD object restoration, DPAPI credential extraction, and privileged access through WSL-accessible domain backups.

thepentesting.ninja's Picture
thepentesting.ninja in htb voleur active-directory kerberoasting dpapi ntds kerberos writespn restore-ad-object
HTB Cyber Apocalypse 2025 - Web Challenges
16 min read Mar 26, 2025

HTB Cyber Apocalypse 2025 - Web Challenges

Comprehensive solutions for the Web challenges during the HTB Cyber Apocalypse 2025 CTF. Learn about modern web vulnerabilities and bypasses used in the event.

thepentesting.ninja's Picture
thepentesting.ninja in ctf htb writeup web
HTB Cyber Apocalypse 2025 - AI Challenges
9 min read Mar 26, 2025

HTB Cyber Apocalypse 2025 - AI Challenges

Exploring the AI category in the HTB Cyber Apocalypse 2025 CTF. This write-up covers prompt injection and model manipulation challenges with step-by-step logic.

thepentesting.ninja's Picture
thepentesting.ninja in ctf htb writeup ai
1 post tagged

js2py

HTB: CodePartTwo Writeup
8 min read Jan 31, 2026

HTB: CodePartTwo Writeup

CodePartTwo is an easy-difficulty Linux machine featuring a vulnerable JavaScript execution sandbox that can be escaped to gain initial access, followed by weak credential recovery and privilege escalation through backup utility manipulation.

thepentesting.ninja's Picture
thepentesting.ninja in codeparttwo linux js2py sandbox-escape npbackup htb
1 post tagged

kerberoasting

HTB: Voleur Writeup
24 min read Nov 1, 2025

HTB: Voleur Writeup

Voleur is a medium-difficulty Active Directory machine featuring password-protected Excel files, targeted Kerberoasting via WriteSPN abuse, AD object restoration, DPAPI credential extraction, and privileged access through WSL-accessible domain backups.

thepentesting.ninja's Picture
thepentesting.ninja in htb voleur active-directory kerberoasting dpapi ntds kerberos writespn restore-ad-object
2 posts tagged

kerberos

HTB: Signed Writeup
8 min read Feb 7, 2026

HTB: Signed Writeup

A Windows Active Directory box involving SQL Server authentication relay attacks, Kerberos ticket forging, and NTLM reflection to achieve SYSTEM access through creative pivoting techniques.

thepentesting.ninja's Picture
thepentesting.ninja in signed windows active-directory mssql kerberos ntlm-relay ntlm-reflection
HTB: Voleur Writeup
24 min read Nov 1, 2025

HTB: Voleur Writeup

Voleur is a medium-difficulty Active Directory machine featuring password-protected Excel files, targeted Kerberoasting via WriteSPN abuse, AD object restoration, DPAPI credential extraction, and privileged access through WSL-accessible domain backups.

thepentesting.ninja's Picture
thepentesting.ninja in htb voleur active-directory kerberoasting dpapi ntds kerberos writespn restore-ad-object
1 post tagged

kubernetes

HTB: Giveback Writeup
14 min read Feb 21, 2026

HTB: Giveback Writeup

Giveback is a medium Linux machine involving a GiveWP PHP Object Injection RCE, pivoting through Kubernetes pods via chisel, exploiting PHP-CGI parameter injection, and escaping to root via a runc wrapper misconfiguration

thepentesting.ninja's Picture
thepentesting.ninja in giveback htb linux kubernetes cve-2024-4577 runc cve-2024-5932
1 post tagged

lfi

HTB: Imagery Writeup
11 min read Jan 24, 2026

HTB: Imagery Writeup

Imagery is a medium-difficulty Linux box where blind XSS leads to admin access, file traversal leaks source code, command injection gains a shell, and a sudo-abused backup tool escalates to root.

thepentesting.ninja's Picture
thepentesting.ninja in htb linux xss lfi command-injection charcol
4 posts tagged

linux

HTB: Giveback Writeup
14 min read Feb 21, 2026

HTB: Giveback Writeup

Giveback is a medium Linux machine involving a GiveWP PHP Object Injection RCE, pivoting through Kubernetes pods via chisel, exploiting PHP-CGI parameter injection, and escaping to root via a runc wrapper misconfiguration

thepentesting.ninja's Picture
thepentesting.ninja in giveback htb linux kubernetes cve-2024-4577 runc cve-2024-5932
HTB: Soulmate Writeup
6 min read Feb 14, 2026

HTB: Soulmate Writeup

A Linux box featuring CrushFTP exploitation, credential discovery in Erlang configuration files, and privilege escalation through an Erlang SSH daemon allowing arbitrary command execution as root.

thepentesting.ninja's Picture
thepentesting.ninja in htb soulmate crushftp erlang cve-2025-31161 linux
HTB: CodePartTwo Writeup
8 min read Jan 31, 2026

HTB: CodePartTwo Writeup

CodePartTwo is an easy-difficulty Linux machine featuring a vulnerable JavaScript execution sandbox that can be escaped to gain initial access, followed by weak credential recovery and privilege escalation through backup utility manipulation.

thepentesting.ninja's Picture
thepentesting.ninja in codeparttwo linux js2py sandbox-escape npbackup htb
HTB: Imagery Writeup
11 min read Jan 24, 2026

HTB: Imagery Writeup

Imagery is a medium-difficulty Linux box where blind XSS leads to admin access, file traversal leaks source code, command injection gains a shell, and a sudo-abused backup tool escalates to root.

thepentesting.ninja's Picture
thepentesting.ninja in htb linux xss lfi command-injection charcol
1 post tagged

mssql

HTB: Signed Writeup
8 min read Feb 7, 2026

HTB: Signed Writeup

A Windows Active Directory box involving SQL Server authentication relay attacks, Kerberos ticket forging, and NTLM reflection to achieve SYSTEM access through creative pivoting techniques.

thepentesting.ninja's Picture
thepentesting.ninja in signed windows active-directory mssql kerberos ntlm-relay ntlm-reflection
1 post tagged

npbackup

HTB: CodePartTwo Writeup
8 min read Jan 31, 2026

HTB: CodePartTwo Writeup

CodePartTwo is an easy-difficulty Linux machine featuring a vulnerable JavaScript execution sandbox that can be escaped to gain initial access, followed by weak credential recovery and privilege escalation through backup utility manipulation.

thepentesting.ninja's Picture
thepentesting.ninja in codeparttwo linux js2py sandbox-escape npbackup htb
1 post tagged

ntds

HTB: Voleur Writeup
24 min read Nov 1, 2025

HTB: Voleur Writeup

Voleur is a medium-difficulty Active Directory machine featuring password-protected Excel files, targeted Kerberoasting via WriteSPN abuse, AD object restoration, DPAPI credential extraction, and privileged access through WSL-accessible domain backups.

thepentesting.ninja's Picture
thepentesting.ninja in htb voleur active-directory kerberoasting dpapi ntds kerberos writespn restore-ad-object
1 post tagged

ntlm-reflection

HTB: Signed Writeup
8 min read Feb 7, 2026

HTB: Signed Writeup

A Windows Active Directory box involving SQL Server authentication relay attacks, Kerberos ticket forging, and NTLM reflection to achieve SYSTEM access through creative pivoting techniques.

thepentesting.ninja's Picture
thepentesting.ninja in signed windows active-directory mssql kerberos ntlm-relay ntlm-reflection
1 post tagged

ntlm-relay

HTB: Signed Writeup
8 min read Feb 7, 2026

HTB: Signed Writeup

A Windows Active Directory box involving SQL Server authentication relay attacks, Kerberos ticket forging, and NTLM reflection to achieve SYSTEM access through creative pivoting techniques.

thepentesting.ninja's Picture
thepentesting.ninja in signed windows active-directory mssql kerberos ntlm-relay ntlm-reflection
1 post tagged

offsec

OSCP Certification: Review
9 min read Jan 17, 2026

OSCP Certification: Review

My journey to earning the OSCP: How I scored 100 points in just 7 hours. This review covers my preparation, the exam environment, and crucial success tips.

thepentesting.ninja's Picture
thepentesting.ninja in certifications oscp pentesting review offsec
1 post tagged

oscp

OSCP Certification: Review
9 min read Jan 17, 2026

OSCP Certification: Review

My journey to earning the OSCP: How I scored 100 points in just 7 hours. This review covers my preparation, the exam environment, and crucial success tips.

thepentesting.ninja's Picture
thepentesting.ninja in certifications oscp pentesting review offsec
1 post tagged

password-cracking

HackSmarter: Welcome Writeup
10 min read Jun 11, 2025

HackSmarter: Welcome Writeup

A complete writeup of the HackSmarter 'Welcome' machine. Learn about Active Directory privilege escalation, PDF cracking, and ADCS certificate abuse.

thepentesting.ninja's Picture
thepentesting.ninja in active-directory adcs password-cracking writeup
1 post tagged

pentesting

OSCP Certification: Review
9 min read Jan 17, 2026

OSCP Certification: Review

My journey to earning the OSCP: How I scored 100 points in just 7 hours. This review covers my preparation, the exam environment, and crucial success tips.

thepentesting.ninja's Picture
thepentesting.ninja in certifications oscp pentesting review offsec
1 post tagged

portswigger

BSCP Certification: Review
16 min read May 5, 2025

BSCP Certification: Review

Reviewing the Burp Suite Certified Practitioner (BSCP) exam. Learn the best strategies for using Burp Suite Professional to pass this rigorous web cert exam.

thepentesting.ninja's Picture
thepentesting.ninja in certifications bscp webapp review portswigger burpsuite
1 post tagged

restore-ad-object

HTB: Voleur Writeup
24 min read Nov 1, 2025

HTB: Voleur Writeup

Voleur is a medium-difficulty Active Directory machine featuring password-protected Excel files, targeted Kerberoasting via WriteSPN abuse, AD object restoration, DPAPI credential extraction, and privileged access through WSL-accessible domain backups.

thepentesting.ninja's Picture
thepentesting.ninja in htb voleur active-directory kerberoasting dpapi ntds kerberos writespn restore-ad-object
4 posts tagged

review

OSCP Certification: Review
9 min read Jan 17, 2026

OSCP Certification: Review

My journey to earning the OSCP: How I scored 100 points in just 7 hours. This review covers my preparation, the exam environment, and crucial success tips.

thepentesting.ninja's Picture
thepentesting.ninja in certifications oscp pentesting review offsec
BSCP Certification: Review
16 min read May 5, 2025

BSCP Certification: Review

Reviewing the Burp Suite Certified Practitioner (BSCP) exam. Learn the best strategies for using Burp Suite Professional to pass this rigorous web cert exam.

thepentesting.ninja's Picture
thepentesting.ninja in certifications bscp webapp review portswigger burpsuite
CBBH/CWES Certification: Review
12 min read Feb 17, 2025

CBBH/CWES Certification: Review

A deep dive into the Hack The Box CBBH, now CWES certification. Explore my preparation strategy, exam difficulty review, and advice for aspiring web testers.

thepentesting.ninja's Picture
thepentesting.ninja in certifications cbbh cwes webapp review hackthebox
CAPenX Certification: Review
11 min read Feb 17, 2025

CAPenX Certification: Review

My comprehensive review of the SecOps Group CAPenX certification. I share my exam experience, study resources, and essential tips for passing on your first try.

thepentesting.ninja's Picture
thepentesting.ninja in certifications capenx webapp review
1 post tagged

runc

HTB: Giveback Writeup
14 min read Feb 21, 2026

HTB: Giveback Writeup

Giveback is a medium Linux machine involving a GiveWP PHP Object Injection RCE, pivoting through Kubernetes pods via chisel, exploiting PHP-CGI parameter injection, and escaping to root via a runc wrapper misconfiguration

thepentesting.ninja's Picture
thepentesting.ninja in giveback htb linux kubernetes cve-2024-4577 runc cve-2024-5932
1 post tagged

s3

HackSmarter: GitOops Writeup
15 min read Feb 19, 2026

HackSmarter: GitOops Writeup

A medium-difficulty HackSmarter lab where a public Gitea instance leaks a Terraform state file from a misconfigured S3 bucket, exposing an SSH private key and enabling an Atlantis RCE chain to root.

thepentesting.ninja's Picture
thepentesting.ninja in gitoops hacksmarter terraform gitea atlantis s3
1 post tagged

sandbox-escape

HTB: CodePartTwo Writeup
8 min read Jan 31, 2026

HTB: CodePartTwo Writeup

CodePartTwo is an easy-difficulty Linux machine featuring a vulnerable JavaScript execution sandbox that can be escaped to gain initial access, followed by weak credential recovery and privilege escalation through backup utility manipulation.

thepentesting.ninja's Picture
thepentesting.ninja in codeparttwo linux js2py sandbox-escape npbackup htb
1 post tagged

signed

HTB: Signed Writeup
8 min read Feb 7, 2026

HTB: Signed Writeup

A Windows Active Directory box involving SQL Server authentication relay attacks, Kerberos ticket forging, and NTLM reflection to achieve SYSTEM access through creative pivoting techniques.

thepentesting.ninja's Picture
thepentesting.ninja in signed windows active-directory mssql kerberos ntlm-relay ntlm-reflection
1 post tagged

soulmate

HTB: Soulmate Writeup
6 min read Feb 14, 2026

HTB: Soulmate Writeup

A Linux box featuring CrushFTP exploitation, credential discovery in Erlang configuration files, and privilege escalation through an Erlang SSH daemon allowing arbitrary command execution as root.

thepentesting.ninja's Picture
thepentesting.ninja in htb soulmate crushftp erlang cve-2025-31161 linux
1 post tagged

terraform

HackSmarter: GitOops Writeup
15 min read Feb 19, 2026

HackSmarter: GitOops Writeup

A medium-difficulty HackSmarter lab where a public Gitea instance leaks a Terraform state file from a misconfigured S3 bucket, exposing an SSH private key and enabling an Atlantis RCE chain to root.

thepentesting.ninja's Picture
thepentesting.ninja in gitoops hacksmarter terraform gitea atlantis s3
1 post tagged

voleur

HTB: Voleur Writeup
24 min read Nov 1, 2025

HTB: Voleur Writeup

Voleur is a medium-difficulty Active Directory machine featuring password-protected Excel files, targeted Kerberoasting via WriteSPN abuse, AD object restoration, DPAPI credential extraction, and privileged access through WSL-accessible domain backups.

thepentesting.ninja's Picture
thepentesting.ninja in htb voleur active-directory kerberoasting dpapi ntds kerberos writespn restore-ad-object
2 posts tagged

web

b01lersc CTF 2025 - Web Writeup
7 min read Apr 21, 2025

b01lersc CTF 2025 - Web Writeup

Detailed write-up for two challenging web tasks from b01lersc CTF 2025. I break down the exploitation chain from discovery to obtaining the final flag easily.

thepentesting.ninja's Picture
thepentesting.ninja in web ctf writeup
HTB Cyber Apocalypse 2025 - Web Challenges
16 min read Mar 26, 2025

HTB Cyber Apocalypse 2025 - Web Challenges

Comprehensive solutions for the Web challenges during the HTB Cyber Apocalypse 2025 CTF. Learn about modern web vulnerabilities and bypasses used in the event.

thepentesting.ninja's Picture
thepentesting.ninja in ctf htb writeup web
3 posts tagged

webapp

BSCP Certification: Review
16 min read May 5, 2025

BSCP Certification: Review

Reviewing the Burp Suite Certified Practitioner (BSCP) exam. Learn the best strategies for using Burp Suite Professional to pass this rigorous web cert exam.

thepentesting.ninja's Picture
thepentesting.ninja in certifications bscp webapp review portswigger burpsuite
CBBH/CWES Certification: Review
12 min read Feb 17, 2025

CBBH/CWES Certification: Review

A deep dive into the Hack The Box CBBH, now CWES certification. Explore my preparation strategy, exam difficulty review, and advice for aspiring web testers.

thepentesting.ninja's Picture
thepentesting.ninja in certifications cbbh cwes webapp review hackthebox
CAPenX Certification: Review
11 min read Feb 17, 2025

CAPenX Certification: Review

My comprehensive review of the SecOps Group CAPenX certification. I share my exam experience, study resources, and essential tips for passing on your first try.

thepentesting.ninja's Picture
thepentesting.ninja in certifications capenx webapp review
1 post tagged

welcome

Welcome to my blog 👋
1 min read Feb 17, 2025

Welcome to my blog 👋

Welcome to my cybersecurity blog! Join me as I document my journey through certifications, CTFs, and lab walkthroughs while sharing technical insights daily.

thepentesting.ninja's Picture
thepentesting.ninja in welcome whoami
1 post tagged

whoami

Welcome to my blog 👋
1 min read Feb 17, 2025

Welcome to my blog 👋

Welcome to my cybersecurity blog! Join me as I document my journey through certifications, CTFs, and lab walkthroughs while sharing technical insights daily.

thepentesting.ninja's Picture
thepentesting.ninja in welcome whoami
2 posts tagged

windows

HTB: Signed Writeup
8 min read Feb 7, 2026

HTB: Signed Writeup

A Windows Active Directory box involving SQL Server authentication relay attacks, Kerberos ticket forging, and NTLM reflection to achieve SYSTEM access through creative pivoting techniques.

thepentesting.ninja's Picture
thepentesting.ninja in signed windows active-directory mssql kerberos ntlm-relay ntlm-reflection
HackSmarter: StellarComms Writeup
7 min read Jan 29, 2026

HackSmarter: StellarComms Writeup

Step-by-step guide for StellarComms, a medium Active Directory box on HackSmarter. We exploit DACL misconfigurations and perform advanced credential recovery.

thepentesting.ninja's Picture
thepentesting.ninja in writeup hacksmarter windows active-directory
1 post tagged

writespn

HTB: Voleur Writeup
24 min read Nov 1, 2025

HTB: Voleur Writeup

Voleur is a medium-difficulty Active Directory machine featuring password-protected Excel files, targeted Kerberoasting via WriteSPN abuse, AD object restoration, DPAPI credential extraction, and privileged access through WSL-accessible domain backups.

thepentesting.ninja's Picture
thepentesting.ninja in htb voleur active-directory kerberoasting dpapi ntds kerberos writespn restore-ad-object
7 posts tagged

writeup

HackSmarter: StellarComms Writeup
7 min read Jan 29, 2026

HackSmarter: StellarComms Writeup

Step-by-step guide for StellarComms, a medium Active Directory box on HackSmarter. We exploit DACL misconfigurations and perform advanced credential recovery.

thepentesting.ninja's Picture
thepentesting.ninja in writeup hacksmarter windows active-directory
HackSmarter: Welcome Writeup
10 min read Jun 11, 2025

HackSmarter: Welcome Writeup

A complete writeup of the HackSmarter 'Welcome' machine. Learn about Active Directory privilege escalation, PDF cracking, and ADCS certificate abuse.

thepentesting.ninja's Picture
thepentesting.ninja in active-directory adcs password-cracking writeup
APISEC-CON CTF May 2025 - Writeups
12 min read May 25, 2025

APISEC-CON CTF May 2025 - Writeups

Solutions for the API security challenges featured in the APISEC-CON CTF (May 2025). I cover broken object-level authorization and complex API vulnerability.

thepentesting.ninja's Picture
thepentesting.ninja in api ctf apisec writeup
b01lersc CTF 2025 - Web Writeup
7 min read Apr 21, 2025

b01lersc CTF 2025 - Web Writeup

Detailed write-up for two challenging web tasks from b01lersc CTF 2025. I break down the exploitation chain from discovery to obtaining the final flag easily.

thepentesting.ninja's Picture
thepentesting.ninja in web ctf writeup
HTB Cyber Apocalypse 2025 - Web Challenges
16 min read Mar 26, 2025

HTB Cyber Apocalypse 2025 - Web Challenges

Comprehensive solutions for the Web challenges during the HTB Cyber Apocalypse 2025 CTF. Learn about modern web vulnerabilities and bypasses used in the event.

thepentesting.ninja's Picture
thepentesting.ninja in ctf htb writeup web
HTB Cyber Apocalypse 2025 - AI Challenges
9 min read Mar 26, 2025

HTB Cyber Apocalypse 2025 - AI Challenges

Exploring the AI category in the HTB Cyber Apocalypse 2025 CTF. This write-up covers prompt injection and model manipulation challenges with step-by-step logic.

thepentesting.ninja's Picture
thepentesting.ninja in ctf htb writeup ai
APISEC CTF 2025 - Writeup
11 min read Mar 3, 2025

APISEC CTF 2025 - Writeup

A detailed walkthrough of the APISEC CTF 2025, featuring the 'One Request to Rule Them All' challenge. Includes a full video guide and technical methodology.

thepentesting.ninja's Picture
thepentesting.ninja in api ctf apisec writeup
1 post tagged

xss

HTB: Imagery Writeup
11 min read Jan 24, 2026

HTB: Imagery Writeup

Imagery is a medium-difficulty Linux box where blind XSS leads to admin access, file traversal leaks source code, command injection gains a shell, and a sudo-abused backup tool escalates to root.

thepentesting.ninja's Picture
thepentesting.ninja in htb linux xss lfi command-injection charcol

Latest Posts

HTB: Giveback Writeup
14 min read Feb 21, 2026

HTB: Giveback Writeup

thepentesting.ninja's Picture
thepentesting.ninja
HackSmarter: GitOops Writeup
15 min read Feb 19, 2026

HackSmarter: GitOops Writeup

thepentesting.ninja's Picture
thepentesting.ninja

Explore Tags

active-directory adcs ai api apisec atlantis bscp burpsuite capenx cbbh certifications charcol codeparttwo command-injection crushftp ctf cve-2024-4577 cve-2024-5932 cve-2025-31161 cwes dpapi erlang gitea gitoops giveback hacksmarter hackthebox htb js2py kerberoasting kerberos kubernetes lfi linux mssql npbackup ntds ntlm-reflection ntlm-relay offsec oscp password-cracking pentesting portswigger restore-ad-object review runc s3 sandbox-escape signed soulmate terraform voleur web webapp welcome whoami windows writespn writeup xss
2026 © thepentesting.ninja | Pentesting & Offensive Security Blog.