// All writeups

Writeups

Category
Difficulty
HACKTHEBOX MEDIUM
Devarea
DevArea is a Linux machine hosting multiple vulnerable services. Initial access is gained through anonymous FTP revealing a JAR file vulnerable to Apache CXF SSRF (CVE-2022-46364), which exposes Hoverfly credentials in systemd service files. The Hoverfly instance is vulnerable to path traversal (CVE-2025-54123), leading to remote code execution. Privilege escalation exploits a world-writable `/bin/bash` binary combined with a passwordless sudo rule, allowing arbitrary command execution as root.
Kasemsh Mar 28, 2026
HACKTHEBOX EASY
facts
Facts is a medium-difficulty machine that revolves around exploiting a vulnerable CMS hosted on facts.htb. Initial enumeration reveals multiple exposed services, including a web application and SSH. The key to gaining access lies in a path traversal vulnerability within the CMS, allowing authenticated users to download sensitive files. By leveraging this flaw, we can retrieve the SSH private key for the 'trivia' user, crack it, and gain initial access. From there, we can escalate privileges using a misconfigured sudo permission on the 'facter' command.
Kasemsh Jan 31, 2026
HACKTHEBOX MEDIUM
gavel
Gavel is a medium-difficulty Linux machine that demonstrates the exploitation of a misused SQL PDO statement to achieve SQL injection and extract data from an internal database. The scenario further highlights a PHP code-injection flaw that is exploited to execute remote commands, thereby enabling initial access to the target. Privilege escalation is achieved by targeting a root-owned daemon that processes user-supplied YAML files; by submitting a crafted YAML payload, PHP code is executed within a sandboxed environment with root privileges.
Kasemsh Nov 29, 2025
HACKTHEBOX HARD
Fries
Fries is a hard Active Directory machine on Hack The Box. It involves various techniques such as LDAP enumeration, Kerberos attacks, and SMB exploitation to gain access to the system and escalate privileges to root.
Kasemsh Nov 22, 2025
HACKTHEBOX HARD
Nanocorp
Nanocorp is a Hard difficulty Active Directory machine that exploits CVE-2025-24054 to extract NTLM hashes via malicious .library-ms files. After gaining initial access and password cracking, privilege escalation is achieved through a Check MK Agent vulnerability by crafting a malicious MSI repair payload to execute code as SYSTEM.
Kasemsh Nov 08, 2025
HACKTHEBOX HARD
Eighteen
Kasemsh Nov 08, 2025
HACKTHEBOX EASY
MonitorsFour
MonitorsFour is an Active Directory machine on Hack The Box that features a vulnerable API endpoint leading to credential leakage, followed by an authenticated RCE in Cacti, and ultimately a full Docker escape via SSRF to achieve host compromise.
Kasemsh Nov 01, 2025
HACKTHEBOX EASY
Giveback
Giveback starts with a WordPress website with a donation plugin that’s vulnerable to a RCE exploit. I’ll get a shell in a Kubernetes pod, and use it to scan an internal legacy app running PHP-CGI. I’ll abuse a vulnerability in that application to get to the next pod, where I’ll find a Kubernetes secret to interact with the API and dump secrets. I’ll use an SSH password to get on the host. For root I’ll abuse a custom wrapper around runc two different ways.
Kasemsh Nov 01, 2025
TRYHACKME
TryHackMe: Sequence
Kasemsh Sep 22, 2025
TRYHACKME
TryHackMe: Voyage
Kasemsh Sep 01, 2025
TRYHACKME
TryHackMe: Extract
Kasemsh Aug 25, 2025
TRYHACKME
TryHackMe: Contrabando
Kasemsh Aug 18, 2025
TRYHACKME
TryHackMe: Soupedecode 01
Kasemsh Aug 02, 2025
TRYHACKME
TryHackMe: Ledger
Kasemsh May 05, 2025
TRYHACKME
TryHackMe: Moebius
Kasemsh Apr 28, 2025
TRYHACKME
TryHackMe: Robots
Kasemsh Mar 17, 2025
TRYHACKME
TryHackMe: Billing
Kasemsh Mar 08, 2025
TRYHACKME
TryHackMe: Crypto Failures
Kasemsh Mar 03, 2025
TRYHACKME
TryHackMe: Rabbit Store
Kasemsh Feb 24, 2025
TRYHACKME
TryHackMe: Decryptify
Kasemsh Feb 16, 2025
TRYHACKME
TryHackMe: You Got Mail
Kasemsh Feb 08, 2025
TRYHACKME
TryHackMe: TryPwnMe Two
Kasemsh Feb 03, 2025
TRYHACKME
TryHackMe: Smol
Kasemsh Jan 25, 2025
TRYHACKME
TryHackMe: Lo-Fi
Kasemsh Jan 20, 2025
TRYHACKME
TryHackMe: Light
Kasemsh Jan 20, 2025
TRYHACKME
TryHackMe: Silver Platter
Kasemsh Jan 11, 2025
TRYHACKME
TryHackMe: AoC 2024 Side Quest Two
Kasemsh Jan 01, 2025
TRYHACKME
TryHackMe: AoC 2024 Side Quest Three
Kasemsh Jan 01, 2025
TRYHACKME
TryHackMe: AoC 2024 Side Quest One
Kasemsh Jan 01, 2025
TRYHACKME
TryHackMe: AoC 2024 Side Quest Four
Kasemsh Jan 01, 2025
TRYHACKME
TryHackMe: AoC 2024 Side Quest Five
Kasemsh Jan 01, 2025
TRYHACKME
TryHackMe: The Sticker Shop
Kasemsh Dec 01, 2024
TRYHACKME
TryHackMe: Lookup
Kasemsh Nov 24, 2024
TRYHACKME
TryHackMe: Mouse Trap
Kasemsh Nov 18, 2024
TRYHACKME
TryHackMe: Hack Back
Kasemsh Nov 10, 2024
TRYHACKME
TryHackMe: SeeTwo
Kasemsh Nov 03, 2024
TRYHACKME
TryHackMe: Whiterose
Kasemsh Nov 01, 2024
TRYHACKME
TryHackMe: Rabbit Hole
Kasemsh Oct 28, 2024
TRYHACKME
TryHackMe: Mountaineer
Kasemsh Oct 21, 2024
TRYHACKME
TryHackMe: Extracted
Kasemsh Oct 17, 2024
TRYHACKME
TryHackMe: Backtrack
Kasemsh Oct 13, 2024
TRYHACKME
TryHackMe: Brains
Kasemsh Oct 05, 2024
TRYHACKME
TryHackMe: Pyrat
Kasemsh Oct 02, 2024
TRYHACKME
TryHackMe: K2
Kasemsh Sep 29, 2024
TRYHACKME
TryHackMe: The London Bridge
Kasemsh Sep 27, 2024
TRYHACKME
TryHackMe: Cheese CTF
Kasemsh Sep 25, 2024
TRYHACKME
TryHackMe: Breakme
Kasemsh Sep 22, 2024
TRYHACKME
TryHackMe: CERTain Doom
Kasemsh Sep 16, 2024
TRYHACKME
TryHackMe: TryPwnMe One
Kasemsh Sep 08, 2024
TRYHACKME
TryHackMe: Hammer
Kasemsh Aug 31, 2024
TRYHACKME
TryHackMe: U.A. High School
Kasemsh Aug 25, 2024
TRYHACKME
TryHackMe: Block
Kasemsh Aug 10, 2024
TRYHACKME
TryHackMe: Injectics
Kasemsh Jul 28, 2024
TRYHACKME
TryHackMe: DX2: Hell's Kitchen
Kasemsh Jul 22, 2024
TRYHACKME
TryHackMe: New York Flankees
Kasemsh Jul 13, 2024
TRYHACKME
TryHackMe: NanoCherryCTF
Kasemsh Jul 07, 2024
TRYHACKME
TryHackMe: Publisher
Kasemsh Jun 30, 2024
TRYHACKME
TryHackMe: W1seGuy
Kasemsh Jun 23, 2024
TRYHACKME
TryHackMe: mKingdom
Kasemsh Jun 16, 2024
TRYHACKME
TryHackMe: Airplane
Kasemsh Jun 09, 2024
TRYHACKME
TryHackMe: Include
Kasemsh Jun 03, 2024
TRYHACKME
TryHackMe: CyberLens
Kasemsh May 18, 2024
TRYHACKME
TryHackMe: Whats Your Name?
Kasemsh Apr 27, 2024
TRYHACKME
TryHackMe: TriCipher Summit
Kasemsh Apr 18, 2024
TRYHACKME
TryHackMe: Burg3r Bytes
Kasemsh Apr 18, 2024
TRYHACKME
TryHackMe: Creative
Kasemsh Apr 14, 2024
TRYHACKME
TryHackMe: Bypass
Kasemsh Apr 06, 2024
TRYHACKME
TryHackMe: Clocky
Kasemsh Apr 01, 2024
TRYHACKME
TryHackMe: El Bandito
Kasemsh Mar 25, 2024
TRYHACKME
TryHackMe: Hack Smarter Security
Kasemsh Mar 16, 2024
TRYHACKME
TryHackMe: Chrome
Kasemsh Mar 03, 2024
TRYHACKME
TryHackMe: Exfilibur
Kasemsh Feb 26, 2024
TRYHACKME
TryHackMe: Breaking RSA
Kasemsh Feb 18, 2024
TRYHACKME
TryHackMe: Kitty
Kasemsh Feb 05, 2024
TRYHACKME
TryHackMe: Reset
Kasemsh Jan 29, 2024
TRYHACKME
TryHackMe: Umbrella
Kasemsh Jan 22, 2024
TRYHACKME
TryHackMe: WhyHackMe
Kasemsh Jan 08, 2024
TRYHACKME
TryHackMe: Dodge
Kasemsh Jan 05, 2024
No writeups match the current filters.