6 min read

A Linux machine where insecure direct object references expose files belonging to other users — and a chain of archived databases, cracked hashes, and a version history leak lead to code execution as root.

#htb #ctf #writeup
Read note
11 min read

A Windows Active Directory machine where database server features leak website backup archives — and a misconfigured certificate authority turns limited domain access into full administrator control.

#htb #ctf #writeup
Read note
5 min read

A Linux machine where a WordPress plugin’s SQL injection leaks database credentials — and an XML external entity vulnerability in the media upload handler reveals FTP credentials from a configuration file.

#htb #ctf #writeup
Read note
1 min read

A Linux machine where a blogging platform’s permissive file upload allows a PHP webshell — and a world-writable script with sudo rights closes out the privilege escalation.

#htb #ctf #writeup
Read note
2 min read

A Linux machine where credentials hidden in a JavaScript source file open an image processing application — and two separate but classic misconfigurations chain together for full system compromise.

#htb #ctf #writeup
Read note