HackTheBox - Forge

Bypass SSRF filters using domain redirection and abusing Python PDB

HackTheBox - Secret

Secret starts with analyzing web source to recover a secret token from older commit. The secret is …

HackTheBox - BountyHunter

BountyHunter features a website that is vulnerable to XXE attack. Exploiting it allows me to …

H@cktivitycon 2021 - Web

Another late CTF writeups for H@cktivitycon 2021 web category.

HackTheBox - Validation

Second-order SQL injection

HackTheBox - Schooled

Moodle exploitation using CVEs

HackTheBox - Gobox

SSTI in Golang, abuse S3 bucket, and NGINX backdoor

HackTheBox - Cereal (User)

Chaining XSS, SSRF, and deserialization vulnerabilities to get RCE

HackTheBox - Bucket

Pentesting against simulated AWS S3 Bucket

HackTheBox - Magic

SQLi for login bypass and embed webshell to an image file