Recent Notes
keepalive.sh blog

my notes on ctf challenges and whatever im learning

Navigation
Home Archive RSS
Categories
note
hackthebox
academy
writeup
hackthebox
machine

No matches found.

infosec
Manage vaults...
Recent Notes
16-02-2026 / 5 min read

HackTheBox - Access

A Windows machine where anonymous FTP access begins a credential chain — through a database file, an email archive, and a telnet session — ending with stored administrator credentials ready to leverage.

#htb #hackthebox #ctf #writeup #windows #msfvenom +2
Read note
15-02-2026 / 5 min read

HackTheBox - WingData

A Linux machine where an unauthenticated FTP server vulnerability opens the initial foothold, and an archive extraction flaw in a Python script allows writing files outside intended boundaries for privilege escalation.

#htb #hackthebox #ctf #writeup #linux #hashcat
Read note
14-02-2026 / 4 min read

HackTheBox - Lock

A Windows machine where a personal access token buried in a Gitea repository’s commit history unlocks a CI/CD pipeline — and a commercial PDF utility’s privilege escalation flaw delivers the final blow.

#htb #hackthebox #ctf #writeup #windows #msfvenom +3
Read note
13-02-2026 / 3 min read

HackTheBox - Data

A Linux machine where a path traversal in a popular metrics platform leaks its own database — and a misconfigured container environment offers an unconventional route to the underlying host.

#htb #hackthebox #ctf #writeup #linux #hashcat
Read note
09-02-2026 / 4 min read

HackTheBox - Writeup

A Linux machine where a vulnerable CMS yields credentials through a time-based blind injection — and membership in an unexpected system group enables hijacking a binary that runs automatically on every SSH login.

#htb #hackthebox #ctf #writeup #ffuf #linux +3
Read note
08-02-2026 / 11 min read

HackTheBox - Pterodactyl

A Linux machine running a game server panel with a file inclusion flaw that leaks database credentials — and a two-CVE privilege escalation chain in a disk management daemon reaches root.

#htb #hackthebox #ctf #writeup #ffuf #linux +1
Read note
07-02-2026 / 7 min read

HackTheBox - Bastion

A Windows machine where anonymous SMB access exposes virtual disk images containing registry hives — and a remote management tool’s encrypted credential store yields the final administrator password.

#htb #hackthebox #ctf #writeup #windows #smbclient +3
Read note
06-02-2026 / 6 min read

HackTheBox - Active

A Windows Active Directory machine where an outdated Group Policy misconfiguration leaks an encrypted password — and a Kerberos ticket attack against a highly privileged service account completes the path to Domain Admin.

#htb #hackthebox #ctf #writeup #windows #smbmap +4
Read note
04-02-2026 / 6 min read

HackTheBox - Facts

A Linux machine where a mass assignment vulnerability in a CMS elevates a regular account to admin — and SSH keys stored in a cloud bucket, combined with a fact-gathering tool, lead to root.

#htb #hackthebox #ctf #writeup #ffuf #linux +4
Read note
04-02-2026 / 10 min read

HackTheBox - TwoMillion

A Linux machine themed around an older version of HackTheBox — where deobfuscating JavaScript reveals an invite code, an API privilege flaw escalates access, and a kernel vulnerability finalizes root.

#htb #hackthebox #ctf #writeup #linux #twomillion +1
Read note
Newer
1 2 3 4 5
Older
htb 47 writeup 43 ctf 41 hackthebox 31 linux 20 ffuf 11 hashcat 11 windows 10 privilege-escalation 8 ssh 5 msfvenom 5 academy 4 note 4 apache 4 password-cracking 4 crackmapexec 3 evil-winrm 3 password-reuse 3 sqlmap 3 smbclient 2 impacket-secretsdump 2 ftp 2 hardcoded-credentials 2 sudo-abuse 2 ubuntu 2 sql-injection 2 command-injection 2 suid 2 md5 2 python 2 metasploit 2 active-directory 2 domain-controller 2 kerberos 2 pass-the-hash 2 chisel 2 proxychains 2 impacket 2 netexec 2 john 2 docker 2 docker-escape 2 nginx 2 vhost-enumeration 2 footprinting 1 information 1 gathering 1 web 1 edition 1 rpcinfo 1 showmount 1 mount 1 umount 1 ghidra 1 cookie-editor 1 netcat 1 jd-gui 1 psql 1 mysql 1 keepass 1 putty 1 mdbtools 1 pst-utils 1 smbmap 1 gpp-decrypt 1 impacket-GetUserSPNs 1 impacket-psexec 1 ldapsearch 1 smbpasswd 1 baby 1 qemu-nbd 1 elastix 1 lfi 1 local-file-inclusion 1 voip 1 asterisk 1 webmin 1 legacy-tls 1 centos 1 wordpress 1 minecraft 1 directory-enumeration 1 jar-decompilation 1 jadx 1 java 1 phpmyadmin 1 zoneminder 1 CVE-2024-51482 1 bcrypt 1 port-forwarding 1 motioneye 1 CVE-2025-60787 1 authenticated-rce 1 xslt-injection 1 file-write 1 exslt 1 cronjob-abuse 1 reverse-shell 1 sqlite 1 needrestart 1 CVE-2024-48990 1 iis 1 anonymous-ftp 1 file-upload 1 aspx 1 meterpreter 1 ms10-015 1 kitrap0d 1 local-exploit-suggester 1 windows-server-2008 1 mssql 1 sql-impersonation 1 pbkdf2 1 rid-brute-force 1 winrm 1 bad-successor 1 dmsa 1 s4u2self 1 dcsync 1 windows-server-2025 1 facts 1 aws 1 flask 1 werkzeug 1 ssti 1 server-side-template-injection 1 jinja2 1 subdomain-enumeration 1 hash-identifier 1 golang 1 privatebin 1 mcp 1 CVE-2026-23744 1 unauthenticated-rce 1 operator-group 1 volume-mount 1 git 1 xfreerdp 1 fscan 1 monitorsfour 1 smb 1 ldap 1 kerberoasting 1 pre2k 1 pre-windows-2000 1 gmsa 1 gmsa-dump 1 ntlm-relay 1 rbcd 1 resource-based-constrained-delegation 1 coercion 1 s4u2proxy 1 spn-manipulation 1 bloodhound 1 lateral-movement 1 windows-server-2019 1 hyper-v 1 internal-network 1 kubernetes 1 minikube 1 etcd 1 kubelet 1 kubelet-api 1 misconfiguration 1 unauthenticated-access 1 service-account-token 1 privileged-pod 1 container-escape 1 hostpath-mount 1 twomillion 1 commix 1 git-exposed 1 git-dumper 1 fonttools 1 CVE-2025-66034 1 arbitrary-file-write 1 webshell 1 fontforge 1 CVE-2024-25082 1 setuptools 1 CVE-2025-47273 1 path-traversal 1 ssh-key-injection 1 php 1 whatweb 1 pspy 1

Vaultex

Version 1.0

Theme repository
View the source code, report issues, and contribute to the theme on GitHub.
Visit
Hexo framework
Hexo is a fast, simple, and powerful blog framework that powers this site.
Visit
Discussions
Ask questions, share ideas, and have in-depth discussions about the theme on GitHub.
Join
    ↑↓ to navigate ↵ to open ctrl ↵ to open in new tab esc to dismiss