4 min read

A Linux machine where an insecure direct object reference on a PCAP endpoint exposes plaintext credentials — and a Linux capability assigned to the Python interpreter provides a clean, direct path to root.

#htb #ctf #writeup
Read note
2 min read

A Linux machine where a server-side request forgery vulnerability proxies access to a hidden internal service — and a one-liner privilege escalation through an interactive pager command closes the loop.

#htb #ctf #writeup
Read note
3 min read

A Linux machine where an unauthenticated directory traversal in a monitoring platform exposes database credentials — and a forgotten API token hiding in version history becomes the key to remote code execution.

#htb #ctf #writeup
Read note
7 min read

A Linux machine where a pre-authentication vulnerability in a business intelligence platform grants an initial foothold — and credentials left in environment variables, combined with a kernel flaw, complete the privilege escalation.

#htb #ctf #writeup
Read note
9 min read

A Windows machine where a single request parameter grants a privileged application role — and an internal application’s request forwarding feature, combined with a missing DLL, opens the path to SYSTEM.

#htb #ctf #writeup #windows
Read note
4 min read

A Linux machine where a sandboxed JavaScript environment isn’t quite sandboxed enough — and a subtle shell scripting flaw in a privileged backup script turns cracked credentials into root access.

#htb #ctf #writeup
Read note