// Writeups
8 writeups found
Signed - Hack The Box
[USER] Initial credentials provided:
Imagery β HTB Writeup
[USER] The web runs an Image Gallery application.
Hacknet β HTB Writeup
[USER] This writeup covers user access only using a Burp Suite workflow (no curl). Chain: SSTI in username β IDOR on likes β leak email & password β SSH.
Previous - Hack The Box
[USER] Most relevant: - 22/tcp SSH - 80/tcp HTTP (nginx β Next.js app behind it)
Era - Hack The Box
[USER] Add it to the /etc/hosts file:
Voleur - Hack The Box
[USER] We receive a default username/password for the machine:
The Frizz - Hack The Box
[ROOT] Nice chain, lots of pain, but even more learning! π
TombWatcher - Hack The Box
[ROOT] Platform: Windows IP: 10.10.11.72