Writeups

Machine and challenge writeups from HTB, CTFs, and bug bounty. Mostly offensive security.

June 2026

10 writeups
  1. HTB: Ghost

    Insane Windows box. LDAP injection to foothold, SSH ControlMaster hijack to steal a Kerberos ticket, Golden SAML via ADFS private keys, and a cross-forest Golden Ticket to take …

    htbwindowsadfsgolden-samlmssqlldap-injectionkerberosactive-directoryforest-trust
  2. HTB: Flight

    Hard Windows box where UNC coercion is the whole story. PHP's file functions hand UNC paths straight to the Windows API, so the LFI param is really a credential stealer. Then …

    htbwindowsntlm-coercionntlm-theftiisseimpersonateprivilegeactive-directorypassword-spray
  3. HTB: VulnCicada

    A Medium Windows AD box where an NFS share leaks a password from a photo, and NTLM being disabled domain-wide turns a standard ESC8 web enrollment relay into a Kerberos relay via …

    esc8krbrelaynfsntlm-disabledwindows
  4. HTB: Trick

    An Easy Linux box that chains a DNS zone transfer into a time-based blind SQLi, then pivots to a second preprod subdomain where unfiltered LFI gives michael's SSH key. The …

    fail2banlfisqlilinux
  5. HTB: Postman

    An Easy Linux box where unauthenticated Redis lets you inject an SSH key for a foothold. A cracked SSH key backup from /opt turns out to be Matt's Webmin password, and …

    webminredislinux
  6. HTB: Media

    A Medium Windows box where uploading a malicious .m3u file coerces an NTLMv2 hash from the server via Windows Media Player's automatic UNC path fetching. A junction symlink …

    tcbsymlinkwindows
  7. HTB: Jeeves

    A Medium Windows box where a fake Ask Jeeves search page on port 80 hides an unauthenticated Jenkins instance on port 50000. The Groovy script console gives code execution, a …

    keepassjenkinswindows
  8. HTB: Voleur

    A Medium Windows box where NTLM is fully disabled and a leaked spreadsheet in an SMB share hands you passwords for accounts you can't yet reach. The chain runs through targeted …

    ntlm-disableddpapireanimate-tombstonekerberoastingwindows
  9. HTB: Pov

    A Medium Windows box where an LFI in a dev subdomain's CV download feature leaks the ASP.NET machineKey. Forging a malicious ViewState gets code execution, and SeDebugPrivilege …

    ppidaspnetrunaswindows
  10. HTB: Fluffy

    An Easy Windows box where CVE-2025-24071 coerces an NTLMv2 hash via a malicious .library-ms file. Shadow Credentials get lateral movement into WinRM, and ESC16 issues a domain …

    esc16kerberosadcsshadow-credentialswindows