11 writeups

> Filter Writeups

Challenges Locked

Hack The Box - EncoDecept

Rails+Django contract system: markdown XSS via ISO-2022-JP charset confusion, nginx cache poisoning to reach the review bot, a Django ORM filter oracle for the admin password, and Ruby Marshal deserialization for RCE.

#cache-poisoning #deserialization #hackthebox #medium #orm-injection #university-ctf-2024 #web #xss 1 views · 2026-09-06
Challenges Locked

Hack The Box - Ether Tag

Blind reverse-engineering of a sim EtherNet/IP controller: pycomm3-framed UCMM Unconnected_Send with a symbolic CIP Read retrieves the FLAG tag as 21 UTF-16 code units.

#challenges #cip #ethernet-ip #hackthebox #ics #scada 3 views · 2026-09-06
Challenges Locked

Hack The Box - OpenSecret

Leaking a hardcoded JWT secret from inline client-side JS on a help-desk portal, then forging a signed admin token to read internal support tickets.

#hackthebox #holme #jwt #web 2 views · 2026-09-06
Challenges Locked

Hack The Box - Lucky Dice

Automate a dice-keeping bot that must score 100 rounds in under 0.3 seconds each — parse player rolls, sum scores, and answer with the winner.

#automation #hackthebox #misc #parsing #python 4 views · 2026-09-06
Challenges Locked

Hack The Box - Espresso

ESP32-Firmware-Reverse-Engineering: Der XOR-40h-Flag-Blob im DROM wird per Literal-Pool-Crossreference und Xtensa-Disassembly gefunden und dekodiert - ohne Emulation.

#easy #esp32 #firmware #hackthebox #hardware #reverse-engineering 2 views · 2026-09-06
Challenges Locked

Hack The Box - Flag Command

Hidden /api/options endpoint leaks all game commands including a secret cheat that returns the flag — solution through browser DevTools source inspection.

#api-enumeration #easy #hackthebox #source-code-analysis #web 0 views · 2026-09-06
Challenges Locked

HackTheBox - SpookyPass

A 3-minute reversing challenge: crack a password-protected ZIP, then pull the flag from an unstripped ELF binary with a hardcoded strcmp comparison.

#easy #hackthebox #reversing 1 views · 2026-09-06
Machines Locked

Hack The Box - Pirate

Hard multi-host AD chain: Pre-Windows 2000 computer account into gMSA secrets, WinRM on the DC, a Chisel pivot to the inner network, EFSRPC coercion relayed into RBCD for the user flag, then LSA-secrets password leaks and SPN jacking for Domain Admin.

#active-directory #hackthebox #hard #windows 4 views · 2026-09-05
Challenges Hack The Box Locked

Hack The Box - Baby Frame

A Hack The Box coding challenge exploring spacecraft communications and the CCSDS packet format.

#ccsds #challenge #hack the box #misc #space packet protocol #tc space data link 5 views · 2026-09-04
Machines Hack The Box

Hack The Box - Legacy

A beginner-friendly Windows machine exploring SMB vulnerabilities and their impact on remote system access.

Windows Easy #ctf #hack the box #walkthrough #legacy 1044 views · 2024-12-27
Machines Hack The Box

Hack The Box - Lame

An introductory Linux machine focused on service enumeration and exploiting a vulnerable Samba service.

Linux Easy #ctf #hack the box #walkthrough #samba 1013 views · 2024-12-17