Recent Notes
keepalive.sh blog

my notes on ctf challenges and whatever im learning

Navigation
Home Archive RSS
Categories
note
hackthebox
academy
writeup
hackthebox
machine

No matches found.

infosec
Manage vaults...
Recent Notes
18-03-2026 / 4 min read

HackTheBox - VariaType

A Linux web machine built around font processing tools — leaking source code leads to credentials, and a chain of vulnerabilities in font libraries carries the attack from initial access all the way to root.

#htb #hackthebox #ctf #writeup #linux #privilege-escalation +18
Read note
10-03-2026 / 11 min read

HackTheBox Academy - File Transfers

This module covers file transfer techniques leveraging tools commonly available across all versions of Windows and Linux systems.

#htb #hackthebox #academy #note
Read note
08-03-2026 / 4 min read

HackTheBox - CCTV

A Linux machine running two vulnerable surveillance applications — a SQL injection in ZoneMinder leads to credentials, and an authenticated RCE in motionEye is leveraged to set a SUID bit and escalate to root.

#htb #hackthebox #ctf #writeup #linux #hashcat +16
Read note
06-03-2026 / 4 min read

HackTheBox - Pirate

A Windows Active Directory machine that chains Pre-Windows 2000 misconfigurations, gMSA credential abuse, NTLM relay with RBCD, and SPN manipulation to pivot from a low-privileged domain account all the way to Domain Admin.

#htb #hackthebox #ctf #writeup #windows #crackmapexec +28
Read note
04-03-2026 / 4 min read

HackTheBox - Devel

A classic retired Windows machine that chains anonymous FTP write access with an unpatched kernel vulnerability to achieve full system compromise.

#htb #hackthebox #ctf #writeup #windows #msfvenom +12
Read note
02-03-2026 / 5 min read

HackTheBox Academy - Information Gathering - Web Edition

This module equips learners with essential web reconnaissance skills, crucial for ethical hacking and penetration testing. It explores both active and passive techniques, including DNS enumeration, web crawling, analysis of web archives and HTTP headers, and fingerprinting web technologies.

#htb #hackthebox #academy #note #information #gathering +2
Read note
28-02-2026 / 28 min read

HackTheBox Academy - Footprinting

Introinformation gathering using active (scans) and passive (use of third-party providers) methods. Enumeration Mythology Infrastructure Based EnumerationDomain Informationpassivel…
#htb #hackthebox #academy #note #footprinting
Read note
26-02-2026 / 6 min read

HackTheBox - Conversor

A Linux machine where an XSLT stylesheet processor accepts attacker-controlled input — and the ability to write arbitrary files, combined with a scheduled task and a vulnerable system utility, leads to root.

#htb #hackthebox #ctf #writeup #ffuf #linux +14
Read note
24-02-2026 / 9 min read

HackTheBox - Eighteen

A Windows domain controller where SQL Server impersonation exposes a cracked hash — and a recently disclosed Active Directory attack against delegated service accounts enables a complete domain takeover.

#htb #hackthebox #ctf #writeup #windows #hashcat +20
Read note
22-02-2026 / 4 min read

HackTheBox - Interpreter

A healthcare integration platform exposes an unpatched RCE, but cracking a non-standard password scheme is only the halfway point — getting to root means finding the flaw hidden inside a server that claims to be safe.

#htb #hackthebox #writeup #hashcat
Read note
Newer
1 2 3 4 5
Older
htb 50 writeup 44 ctf 41 hackthebox 36 linux 21 hashcat 12 windows 11 ffuf 11 privilege-escalation 10 academy 6 note 6 msfvenom 5 ssh 4 crackmapexec 4 evil-winrm 4 rce 4 password-cracking 4 suid 4 apache 3 active-directory 3 domain-controller 3 kerberos 3 chisel 3 proxychains 3 impacket 3 sqlmap 3 ubuntu 3 nginx 3 vhost-enumeration 3 smbclient 2 impacket-secretsdump 2 sqlite 2 md5 2 python 2 ftp 2 anonymous-ftp 2 metasploit 2 pass-the-hash 2 netexec 2 john 2 sql-injection 2 docker 2 docker-escape 2 password-reuse 2 command-injection 2 sudo-abuse 2 linpeas 2 smb 2 ldap 2 bloodhound 2 rbcd 2 resource-based-constrained-delegation 2 windows-server-2019 2 ssh-key-injection 2 footprinting 1 information 1 gathering 1 web 1 edition 1 rpcinfo 1 showmount 1 mount 1 umount 1 ghidra 1 cookie-editor 1 netcat 1 jd-gui 1 psql 1 mysql 1 keepass 1 putty 1 smbmap 1 gpp-decrypt 1 impacket-GetUserSPNs 1 impacket-psexec 1 mdbtools 1 pst-utils 1 ldapsearch 1 smbpasswd 1 baby 1 qemu-nbd 1 clearml 1 cve-2024-24590 1 pickle 1 pytorch 1 xslt-injection 1 file-write 1 exslt 1 cronjob-abuse 1 reverse-shell 1 needrestart 1 CVE-2024-48990 1 iis 1 file-upload 1 aspx 1 meterpreter 1 ms10-015 1 kitrap0d 1 local-exploit-suggester 1 windows-server-2008 1 mssql 1 sql-impersonation 1 pbkdf2 1 rid-brute-force 1 winrm 1 bad-successor 1 dmsa 1 s4u2self 1 dcsync 1 windows-server-2025 1 hash-identifier 1 flask 1 werkzeug 1 ssti 1 server-side-template-injection 1 jinja2 1 subdomain-enumeration 1 git 1 xfreerdp 1 fscan 1 monitorsfour 1 kubernetes 1 minikube 1 etcd 1 kubelet 1 kubelet-api 1 misconfiguration 1 unauthenticated-access 1 service-account-token 1 privileged-pod 1 container-escape 1 hostpath-mount 1 twomillion 1 commix 1 whatweb 1 pspy 1 zoneminder 1 CVE-2024-51482 1 bcrypt 1 port-forwarding 1 motioneye 1 CVE-2025-60787 1 authenticated-rce 1 jar-decompilation 1 jadx 1 java 1 soap 1 apache-cxf 1 CVE-2022-46364 1 lfi 1 local-file-inclusion 1 hoverfly 1 CVE-2025-54123 1 middleware-injection 1 writable-binary 1 facts 1 aws 1 rodc 1 logon-script-abuse 1 scriptpath 1 forcepaswordchange 1 golden-ticket 1 rubeus 1 mimikatz 1 bloodyad 1 faketime 1 clock-skew 1 krbtgt 1 golang 1 privatebin 1 mcp 1 CVE-2026-23744 1 unauthenticated-rce 1 operator-group 1 volume-mount 1 kerberoasting 1 pre2k 1 pre-windows-2000 1 gmsa 1 gmsa-dump 1 ntlm-relay 1 coercion 1 s4u2proxy 1 spn-manipulation 1 lateral-movement 1 hyper-v 1 internal-network 1 next.js 1 cve-2025-55182 1 node-inspector 1 flowise 1 CVE-2025-58434 1 password-reset-token-disclosure 1 CVE-2025-59528 1 environment-variable-credentials 1 gogs 1 CVE-2025-8110 1 symlink-attack 1 git-exposed 1 git-dumper 1 hardcoded-credentials 1 fonttools 1 CVE-2025-66034 1 arbitrary-file-write 1 webshell 1 fontforge 1 CVE-2024-25082 1 setuptools 1 CVE-2025-47273 1 path-traversal 1 php 1

Vaultex

Version 1.0

Theme repository
View the source code, report issues, and contribute to the theme on GitHub.
Visit
Hexo framework
Hexo is a fast, simple, and powerful blog framework that powers this site.
Visit
Discussions
Ask questions, share ideas, and have in-depth discussions about the theme on GitHub.
Join
    ↑↓ to navigate ↵ to open ctrl ↵ to open in new tab esc to dismiss