Writeups

Machine and challenge writeups from HTB, CTFs, and bug bounty. Mostly offensive security.

June 2026

10 writeups
  1. HTB: TombWatcher

    A Medium Windows box where a BloodHound ACL chain reaches john, Reanimate-Tombstones restores a deleted cert_admin into an OU where you have GenericAll, and ESC15 issues a domain …

    esc15acl-abuseinheritancereanimate-tombstonewindows
  2. HTB: StreamIO

    A Medium Windows box that chains SQL injection on a hidden subdomain through PHP eval RCE to a LAPS read. Firefox saved passwords and JDgodd's group ownership are the two pivots.

    lapsps-remotingsqlirfiwindows
  3. HTB: Pandora

    An Easy Linux box where SNMP with the default community string leaks SSH creds from process arguments. An unauthenticated SQLi on Pandora FMS hijacks a session for RCE, and a SUID …

    path-hijacksqlicve-exploitttylinux
  4. HTB: Scrambled

    A Medium Windows box where NTLM is disabled domain-wide, forcing pure Kerberos. Kerberoasting yields sqlsvc, a silver ticket forged from its NT hash bypasses MSSQL access …

    forge-silver-ticketkerberosmssqlwindows
  5. HTB: Escape

    A Medium Windows box where a PDF on a public SMB share leaks MSSQL guest credentials. NTLM coercion via xp_dirtree cracks sql_svc, a mistyped login leaks Ryan.Cooper's password, …

    mssqladcswindows
  6. HTB: Authority

    A Medium Windows box where cracking Ansible Vault files on a public share leads to a PWM portal. Redirecting its LDAP config to Responder gets cleartext creds, and ESC1 via LDAPS …

    pwmadcswindows
  7. HTB: Administrator

    A Medium box built around a BloodHound ACL chain with starting credentials. Three password resets walk you down to a Password Safe on FTP, and a fake SPN plus targeted …

    acl-abusepsafewindows
  8. HTB: Return

    An Easy Windows box where the printer admin panel's LDAP settings page leaks svc-printer's credentials to a netcat listener. Server Operators membership and a service binary hijack …

    server-operatorswindows
  9. HTB: EscapeTwo

    An Easy Windows box that starts with given credentials. A spreadsheet on an SMB share leaks the MSSQL sa password, a config file exposes ryan's, and WriteOwner over ca_svc chains …

    adcsmssqlwindows
  10. HTB: Cicada

    An Easy Windows box where one default password in an HR share starts a credential chain. An AD description field and a backup script leak two more accounts, and Backup Operators …

    vssnxcwindows