CTF write-ups
Hack The Box, Proving Grounds, TryHackMe, and other CTF-style walkthroughs.

HTB • CTF • EscapeTwo • Write-Up
Updated: at 10:46 AMHack The Box EscapeTwo: MSSQL `xp_cmdshell` foothold, plaintext creds in config files, ESC4 certificate abuse, and a WriteOwner ACL chain to Domain Admin.

HTB • CTF • Cicada • Write-Up
Published: at 01:14 PMHack The Box CTF - Cicada. SMB shares, password spraying, RID brute-forcing, PrivEsc via Token Abuse

HTB • CTF • Chemistry • Write-Up
Updated: at 10:46 AMHack The Box CTF - Chemistry. Pymatgen CIF parser RCE, Credentials from SQLite database, Python aiohttp app vulnerable to path traversal (CVE-2024-23334).

Mr. Windoclin - ICSD2024
Published: at 09:00 AMMr. Windoclin — Challenge №12 from the ICSD 2024 'Who am I' CTF. Walkthrough of the Windows-themed challenge I authored, with the intended solution path.