Recent Notes
keepalive.sh blog

my notes on ctf challenges and whatever im learning

Navigation
Home Archive RSS
Categories
note
hackthebox
academy
writeup
hackthebox
machine

No matches found.

infosec
Manage vaults...
Recent Notes
19-02-2026 / 10 min read

HackTheBox - Help

A Linux machine where a help desk application’s unauthenticated GraphQL endpoint exposes user credentials — and an authenticated SQL injection, combined with an older kernel vulnerability, escalates to root.

#htb #hackthebox #writeup #ffuf #linux #hash-identifier +2
Read note
19-02-2026 / 6 min read

HackTheBox - GoodGames

A Linux machine where weak database security and an internal admin panel lead to a foothold, with a creative Docker escape to reach the host as root.

#htb #hackthebox #ctf #writeup #linux #hashcat +16
Read note
18-02-2026 / 6 min read

HackTheBox - Curling

A Linux machine running a Joomla site where a hint hidden in the page source leads to credentials — and a password buried under layers of nested compression unlocks a path to a higher-privilege user.

#htb #hackthebox #ctf #writeup #linux
Read note
17-02-2026 / 4 min read

HackTheBox - Shocker

A Linux machine where directory enumeration uncovers a CGI script in an exposed cgi-bin directory — and a classic Bash vulnerability allows injecting commands through a crafted HTTP header.

#htb #hackthebox #ctf #writeup #ffuf #linux
Read note
17-02-2026 / 6 min read

HackTheBox - Valentine

A Linux machine named after its core vulnerability — a memory disclosure flaw in OpenSSL leaks just enough data to decrypt an encrypted RSA key found hiding in the web server’s directory listing.

#htb #hackthebox #ctf #writeup #ffuf #linux
Read note
16-02-2026 / 5 min read

HackTheBox - Access

A Windows machine where anonymous FTP access begins a credential chain — through a database file, an email archive, and a telnet session — ending with stored administrator credentials ready to leverage.

#htb #hackthebox #ctf #writeup #windows #msfvenom +2
Read note
15-02-2026 / 4 min read

HackTheBox - WingData

A Linux machine where an unauthenticated FTP server vulnerability opens the initial foothold, and an archive extraction flaw in a Python script allows writing files outside intended boundaries for privilege escalation.

#htb #hackthebox #ctf #writeup #linux #hashcat
Read note
14-02-2026 / 4 min read

HackTheBox - Lock

A Windows machine where a personal access token buried in a Gitea repository’s commit history unlocks a CI/CD pipeline — and a commercial PDF utility’s privilege escalation flaw delivers the final blow.

#htb #hackthebox #ctf #writeup #windows #msfvenom +3
Read note
13-02-2026 / 3 min read

HackTheBox - Data

A Linux machine where a path traversal in a popular metrics platform leaks its own database — and a misconfigured container environment offers an unconventional route to the underlying host.

#htb #hackthebox #ctf #writeup #linux #hashcat
Read note
09-02-2026 / 4 min read

HackTheBox - Writeup

A Linux machine where a vulnerable CMS yields credentials through a time-based blind injection — and membership in an unexpected system group enables hijacking a binary that runs automatically on every SSH login.

#htb #hackthebox #ctf #writeup #ffuf #linux +3
Read note
Newer
1 2 3 4 5
Older
htb 50 writeup 44 ctf 41 hackthebox 36 linux 21 hashcat 12 windows 11 ffuf 11 privilege-escalation 10 academy 6 note 6 msfvenom 5 ssh 4 crackmapexec 4 evil-winrm 4 rce 4 password-cracking 4 suid 4 apache 3 active-directory 3 domain-controller 3 kerberos 3 chisel 3 proxychains 3 impacket 3 sqlmap 3 ubuntu 3 nginx 3 vhost-enumeration 3 smbclient 2 impacket-secretsdump 2 sqlite 2 md5 2 python 2 ftp 2 anonymous-ftp 2 metasploit 2 pass-the-hash 2 netexec 2 john 2 sql-injection 2 docker 2 docker-escape 2 password-reuse 2 command-injection 2 sudo-abuse 2 linpeas 2 smb 2 ldap 2 bloodhound 2 rbcd 2 resource-based-constrained-delegation 2 windows-server-2019 2 ssh-key-injection 2 footprinting 1 information 1 gathering 1 web 1 edition 1 rpcinfo 1 showmount 1 mount 1 umount 1 ghidra 1 cookie-editor 1 netcat 1 jd-gui 1 psql 1 mysql 1 keepass 1 putty 1 smbmap 1 gpp-decrypt 1 impacket-GetUserSPNs 1 impacket-psexec 1 mdbtools 1 pst-utils 1 ldapsearch 1 smbpasswd 1 baby 1 qemu-nbd 1 clearml 1 cve-2024-24590 1 pickle 1 pytorch 1 xslt-injection 1 file-write 1 exslt 1 cronjob-abuse 1 reverse-shell 1 needrestart 1 CVE-2024-48990 1 iis 1 file-upload 1 aspx 1 meterpreter 1 ms10-015 1 kitrap0d 1 local-exploit-suggester 1 windows-server-2008 1 mssql 1 sql-impersonation 1 pbkdf2 1 rid-brute-force 1 winrm 1 bad-successor 1 dmsa 1 s4u2self 1 dcsync 1 windows-server-2025 1 hash-identifier 1 flask 1 werkzeug 1 ssti 1 server-side-template-injection 1 jinja2 1 subdomain-enumeration 1 git 1 xfreerdp 1 fscan 1 monitorsfour 1 kubernetes 1 minikube 1 etcd 1 kubelet 1 kubelet-api 1 misconfiguration 1 unauthenticated-access 1 service-account-token 1 privileged-pod 1 container-escape 1 hostpath-mount 1 twomillion 1 commix 1 whatweb 1 pspy 1 zoneminder 1 CVE-2024-51482 1 bcrypt 1 port-forwarding 1 motioneye 1 CVE-2025-60787 1 authenticated-rce 1 jar-decompilation 1 jadx 1 java 1 soap 1 apache-cxf 1 CVE-2022-46364 1 lfi 1 local-file-inclusion 1 hoverfly 1 CVE-2025-54123 1 middleware-injection 1 writable-binary 1 facts 1 aws 1 rodc 1 logon-script-abuse 1 scriptpath 1 forcepaswordchange 1 golden-ticket 1 rubeus 1 mimikatz 1 bloodyad 1 faketime 1 clock-skew 1 krbtgt 1 golang 1 privatebin 1 mcp 1 CVE-2026-23744 1 unauthenticated-rce 1 operator-group 1 volume-mount 1 kerberoasting 1 pre2k 1 pre-windows-2000 1 gmsa 1 gmsa-dump 1 ntlm-relay 1 coercion 1 s4u2proxy 1 spn-manipulation 1 lateral-movement 1 hyper-v 1 internal-network 1 next.js 1 cve-2025-55182 1 node-inspector 1 flowise 1 CVE-2025-58434 1 password-reset-token-disclosure 1 CVE-2025-59528 1 environment-variable-credentials 1 gogs 1 CVE-2025-8110 1 symlink-attack 1 git-exposed 1 git-dumper 1 hardcoded-credentials 1 fonttools 1 CVE-2025-66034 1 arbitrary-file-write 1 webshell 1 fontforge 1 CVE-2024-25082 1 setuptools 1 CVE-2025-47273 1 path-traversal 1 php 1

Vaultex

Version 1.0

Theme repository
View the source code, report issues, and contribute to the theme on GitHub.
Visit
Hexo framework
Hexo is a fast, simple, and powerful blog framework that powers this site.
Visit
Discussions
Ask questions, share ideas, and have in-depth discussions about the theme on GitHub.
Join
    ↑↓ to navigate ↵ to open ctrl ↵ to open in new tab esc to dismiss