Hack The Box - EncoDecept
Rails+Django contract system: markdown XSS via ISO-2022-JP charset confusion, nginx cache poisoning to reach the review bot, a Django ORM filter oracle for the admin password, and Ruby Marshal deserialization for RCE.
╔════════════════════════════════════════╗
║ TERMINAL TROUBLE - HTB WRITEUPS ║
║ > root@kali:~# cat /root/flag.txt ║
╚════════════════════════════════════════╝
11 writeups
Rails+Django contract system: markdown XSS via ISO-2022-JP charset confusion, nginx cache poisoning to reach the review bot, a Django ORM filter oracle for the admin password, and Ruby Marshal deserialization for RCE.
Blind reverse-engineering of a sim EtherNet/IP controller: pycomm3-framed UCMM Unconnected_Send with a symbolic CIP Read retrieves the FLAG tag as 21 UTF-16 code units.
Leaking a hardcoded JWT secret from inline client-side JS on a help-desk portal, then forging a signed admin token to read internal support tickets.
Automate a dice-keeping bot that must score 100 rounds in under 0.3 seconds each — parse player rolls, sum scores, and answer with the winner.
ESP32-Firmware-Reverse-Engineering: Der XOR-40h-Flag-Blob im DROM wird per Literal-Pool-Crossreference und Xtensa-Disassembly gefunden und dekodiert - ohne Emulation.
Hidden /api/options endpoint leaks all game commands including a secret cheat that returns the flag — solution through browser DevTools source inspection.
A 3-minute reversing challenge: crack a password-protected ZIP, then pull the flag from an unstripped ELF binary with a hardcoded strcmp comparison.
Hard multi-host AD chain: Pre-Windows 2000 computer account into gMSA secrets, WinRM on the DC, a Chisel pivot to the inner network, EFSRPC coercion relayed into RBCD for the user flag, then LSA-secrets password leaks and SPN jacking for Domain Admin.
A Hack The Box coding challenge exploring spacecraft communications and the CCSDS packet format.
A beginner-friendly Windows machine exploring SMB vulnerabilities and their impact on remote system access.
An introductory Linux machine focused on service enumeration and exploiting a vulnerable Samba service.