#writeup

2026-02-04

VulNyx Misconfigured Writeup

A Step-by-Step Walkthrough of Enumerating AD Services and Gaining Administrator Access on the Misconfigured Machine
thecybercraft.medium.com/vulny

#writeup #ctf #infosec #cybersecurity #pentest #vm

VulNyx Misconfigured Writeup
2026-02-02

I might be a few months late, but I finally found some time to publish my "magnetic_tape" crypto challenge from #NullCon #Berlin #HackIM #CTF 2025:

github.com/OOTS/magnetic_tape

I included the source code (was published anyway during the CTF), my own solution, my own #writeup, and some internal files (#Dockerfile, docker-compose, minimal #python #unittests).

Also: #NullCon #Goa #HackIM #CTF 2026 is happening in a few days: ctf.nullcon.net
Go check it out!

Collectors Realm 3 - Vintage gay porn, Jack Drago, and Bob's Guyscollectorsrealm3.net@web.brid.gy
2026-01-24
Collectors Realm 3 - Vintage gay porn, Jack Drago, and Bob's Guyscollectorsrealm3.net@web.brid.gy
2026-01-18
1337 Sheets1337sheets
2025-12-16

🤯 Eloquia (Insane) Writeup Dropped!
This Windows box required a 4-step chain:
* OAuth CSRF Takeover
* SQLite RCE
* Edge DPAPI Credential Extract
* Service Binary Race Condition \to SYSTEM
Full Guide: kzs.me/s6su26

1337 Sheets1337sheets
2025-12-08

Just dropped our writeup for MonitorsFour 🖥️ here: kaizenl.ink/5zen6j

A Windows machine featuring:
🔹 API IDOR for credential leakage
🔹 RCE via Cacti (CVE-2025-24367)
🔹 System compromise via Docker API escape

Collectors Realm 3 - Vintage gay porn, Jack Drago, and Bob's Guyscollectorsrealm3.net@web.brid.gy
2025-12-02
maschmiinw
2025-11-30

With the Era box on retired I now finally can publish my writeup of this box

blog.maschmi.net/era-htb/

Thank you @mkalmes for reading it a few months ago and for the feedback on it. It helped me going forward with this!

I also submitted it as a community supplied walkthrough. Now I wait and hope it will be accepted 🤞

1337 Sheets1337sheets
2025-11-30

Just dropped our writeup for HackTheBox Gavel on 🔨
A Medium Linux machine featuring:
🔹 SQLi bypassing PDO protection
🔹 RCE via runkit_function_add()
🔹 Root privesc using YAML injection

Check out the full walkthrough here:
kaizenl.ink/7e8dgm

KOREONEKOREONE
2025-11-06

New post on kore.one: BjörnCTF 2025 – phantom-parameters Challenge Writeup - kore.one/bjornctf-2025-phantom

KOREONEKOREONE
2025-11-05

New post on kore.one: BjörnCTF 2025 – gamal-vs-elgamal Challenge Writeup - kore.one/bjornctf-2025-gamal-v

KOREONEKOREONE
2025-11-04

New post on kore.one:
BjörnCTF 2025 – ez-poly Challenge Writeup - kore.one/bjornctf-2025-ez-poly

2025-11-04

Три неудачных патча и одно озарение: реверсим клиентскую аутентификацию на HTB

Название: Bypass Категория: Reversing Сложность: Easy Ссылка: app.hackthebox.com/challenges/ Разбираю задачу Bypass с Hack The Box. Путь от трех неудачных патчей в IDA Pro до элегантного решения с помощью dnSpy. Показываю, как выбор правильного инструмента решает всё.

habr.com/ru/articles/963086/

#hacking #hackthebox #реверсинжиниринг #htb #writeup #bypass #ida_pro #net #c# #dnspy

Collectors Realm 3 - Vintage gay porn, Jack Drago, and Bob's Guyscollectorsrealm3.net@web.brid.gy
2025-10-29
KOREONEKOREONE
2025-10-25
Collectors Realm 3 - Vintage gay porn, Jack Drago, and Bob's Guyscollectorsrealm3.net@web.brid.gy
2025-10-09

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst