<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>CyberSec Writeups</title><link>https://mrbeetrootpwn.com/</link><description>Recent content on CyberSec Writeups</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 26 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://mrbeetrootpwn.com/index.xml" rel="self" type="application/rss+xml"/><item><title>Windows Privilege Escalation Cheatsheet</title><link>https://mrbeetrootpwn.com/tools-techniques/windows-privesc/</link><pubDate>Tue, 26 May 2026 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/tools-techniques/windows-privesc/</guid><description>A practical, ordered checklist for Windows local privilege escalation during labs, CTFs, and authorised internal testing.</description></item><item><title>Linux Privilege Escalation Cheatsheet</title><link>https://mrbeetrootpwn.com/tools-techniques/linux-privesc/</link><pubDate>Mon, 25 May 2026 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/tools-techniques/linux-privesc/</guid><description>A practical Linux privilege escalation reference covering high-impact enumeration checks, common misconfigurations, credential hunting, container escapes, and last-resort kernel exploits.</description></item><item><title>VulnLab: Breach</title><link>https://mrbeetrootpwn.com/write-ups/vuln-breach/</link><pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/vuln-breach/</guid><description>Active Directory machine demonstrating NTLM hash capture through a writable SMB share, Kerberoasting, MSSQL Silver Ticket abuse, and SeImpersonatePrivilege escalation.</description></item><item><title>VulnLab: Baby2</title><link>https://mrbeetrootpwn.com/write-ups/vuln-baby2/</link><pubDate>Sun, 22 Mar 2026 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/vuln-baby2/</guid><description>Active Directory machine demonstrating SMB user enumeration, weak password reuse, writable logon script abuse, and GPO-based privilege escalation.</description></item><item><title>VulnLab: Baby</title><link>https://mrbeetrootpwn.com/write-ups/vuln-baby/</link><pubDate>Sat, 21 Mar 2026 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/vuln-baby/</guid><description>Active Directory machine demonstrating anonymous LDAP enumeration, password reset abuse, SeRestorePrivilege execution, and manual NTDS extraction.</description></item><item><title>HTB: Access</title><link>https://mrbeetrootpwn.com/write-ups/htb-access/</link><pubDate>Sat, 07 Mar 2026 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/htb-access/</guid><description>Windows machine demonstrating anonymous FTP exposure, credential recovery from MDB and PST files, Telnet access, and stored credential abuse.</description></item><item><title>HTB: Buff</title><link>https://mrbeetrootpwn.com/write-ups/htb-buff/</link><pubDate>Thu, 05 Mar 2026 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/htb-buff/</guid><description>Windows machine demonstrating unauthenticated file upload leading to CloudMe buffer overflow exploitation and administrator access.</description></item><item><title>HTB: Bashed</title><link>https://mrbeetrootpwn.com/write-ups/htb-bashed/</link><pubDate>Tue, 03 Mar 2026 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/htb-bashed/</guid><description>Linux machine demonstrating exposed PHP web shell access, sudo-based lateral movement, and cron-driven privilege escalation.</description></item><item><title>HTB: Arctic</title><link>https://mrbeetrootpwn.com/write-ups/htb-arctic/</link><pubDate>Mon, 02 Mar 2026 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/htb-arctic/</guid><description>Windows machine demonstrating Adobe ColdFusion remote code execution and kernel-based privilege escalation to SYSTEM.</description></item><item><title>HTB: Bounty</title><link>https://mrbeetrootpwn.com/write-ups/htb-bounty/</link><pubDate>Sun, 01 Mar 2026 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/htb-bounty/</guid><description>Windows machine demonstrating IIS upload bypass with web.config abuse and kernel exploit privilege escalation.</description></item><item><title>HTB: Builder</title><link>https://mrbeetrootpwn.com/write-ups/htb-builder/</link><pubDate>Sat, 21 Feb 2026 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/htb-builder/</guid><description>Linux machine demonstrating Jenkins CLI arbitrary file read, Jenkins user hash extraction, credential cracking, and SSH key abuse for root access.</description></item><item><title>HTB: BoardLight</title><link>https://mrbeetrootpwn.com/write-ups/htb-boardlight/</link><pubDate>Wed, 18 Feb 2026 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/htb-boardlight/</guid><description>Linux machine demonstrating vhost discovery, Dolibarr authenticated RCE, credential disclosure, and Enlightenment SUID privilege escalation.</description></item><item><title>HTB: Busqueda</title><link>https://mrbeetrootpwn.com/write-ups/htb-busqueda/</link><pubDate>Sun, 15 Feb 2026 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/htb-busqueda/</guid><description>Linux machine demonstrating Python eval command injection, credential reuse, Docker configuration disclosure, and sudo script abuse.</description></item><item><title>HTB: Analytics</title><link>https://mrbeetrootpwn.com/write-ups/htb-analytics/</link><pubDate>Fri, 19 Dec 2025 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/htb-analytics/</guid><description>Linux machine demonstrating Metabase pre-auth RCE, Docker environment credential disclosure, and OverlayFS kernel exploitation.</description></item><item><title>HTB: Broker</title><link>https://mrbeetrootpwn.com/write-ups/htb-broker/</link><pubDate>Thu, 18 Dec 2025 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/htb-broker/</guid><description>Linux machine demonstrating Apache ActiveMQ CVE-2023-46604 exploitation and sudo nginx abuse for root access.</description></item><item><title>HTB: Escape</title><link>https://mrbeetrootpwn.com/write-ups/htb-escape/</link><pubDate>Sun, 09 Nov 2025 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/htb-escape/</guid><description>Active Directory machine demonstrating MSSQL abuse leading to credential leakage and AD CS certificate abuse for full domain compromise.</description></item><item><title>HTB: Cicada</title><link>https://mrbeetrootpwn.com/write-ups/htb-cicada/</link><pubDate>Fri, 07 Nov 2025 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/htb-cicada/</guid><description>Active Directory machine demonstrating exposed SMB data, credential reuse, and Backup Operators abuse to dump domain hashes.</description></item><item><title>HTB: Forest</title><link>https://mrbeetrootpwn.com/write-ups/htb-forest/</link><pubDate>Wed, 05 Nov 2025 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/htb-forest/</guid><description>Active Directory machine demonstrating anonymous LDAP enumeration, AS-REP Roasting, nested group abuse, and DCSync-based domain compromise.</description></item><item><title>HTB: Return</title><link>https://mrbeetrootpwn.com/write-ups/htb-return/</link><pubDate>Wed, 05 Nov 2025 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/htb-return/</guid><description>Active Directory machine demonstrating LDAP credential capture through a printer admin panel, WinRM access, and Server Operators abuse leading to DCSync.</description></item><item><title>HTB: Blackfield</title><link>https://mrbeetrootpwn.com/write-ups/htb-blackfield/</link><pubDate>Tue, 04 Nov 2025 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/htb-blackfield/</guid><description>Active Directory machine demonstrating AS-REP Roasting, BloodHound-driven lateral movement, LSASS credential extraction, and Backup Operators abuse.</description></item><item><title>HTB: Flight</title><link>https://mrbeetrootpwn.com/write-ups/htb-flight/</link><pubDate>Sat, 01 Nov 2025 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/htb-flight/</guid><description>Active Directory machine demonstrating NTLM hash capture, SMB abuse, password reuse, IIS pivoting, and SeImpersonatePrivilege escalation.</description></item><item><title>HTB: Timelapse</title><link>https://mrbeetrootpwn.com/write-ups/htb-timelapse/</link><pubDate>Fri, 31 Oct 2025 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/htb-timelapse/</guid><description>Active Directory machine demonstrating exposed SMB backups, certificate-based WinRM access, PowerShell history credential discovery, and LAPS abuse.</description></item><item><title>HTB: Monteverde</title><link>https://mrbeetrootpwn.com/write-ups/htb-monteverde/</link><pubDate>Mon, 27 Oct 2025 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/htb-monteverde/</guid><description>Azure AD Connect misconfiguration leading to credential extraction and domain compromise.</description></item><item><title>HTB: Sauna</title><link>https://mrbeetrootpwn.com/write-ups/htb-sauna/</link><pubDate>Mon, 27 Oct 2025 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/htb-sauna/</guid><description>Active Directory machine demonstrating username generation, AS-REP Roasting, AutoLogon credential discovery, and DCSync-based domain compromise.</description></item><item><title>HTB: Active</title><link>https://mrbeetrootpwn.com/write-ups/htb-active/</link><pubDate>Fri, 17 Oct 2025 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/htb-active/</guid><description>Classic Active Directory machine demonstrating GPP credential exposure leading to Kerberoasting and domain compromise.</description></item><item><title>VulnLab: Lock</title><link>https://mrbeetrootpwn.com/write-ups/vuln-lock/</link><pubDate>Thu, 16 Oct 2025 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/vuln-lock/</guid><description>Windows machine demonstrating Gitea access token exposure, repository-backed web deployment, mRemoteNG credential recovery, and PDF24 local privilege escalation.</description></item><item><title>VulnLab: Job2</title><link>https://mrbeetrootpwn.com/write-ups/vuln-job2/</link><pubDate>Wed, 15 Oct 2025 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/vuln-job2/</guid><description>Windows machine demonstrating macro-based phishing, hMailServer database credential recovery, lateral movement over RDP, and Veeam Backup exploitation.</description></item><item><title>VulnLab: Job</title><link>https://mrbeetrootpwn.com/write-ups/vuln-job/</link><pubDate>Mon, 13 Oct 2025 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/vuln-job/</guid><description>Windows machine demonstrating phishing through a malicious LibreOffice document, IIS web root abuse, SeImpersonatePrivilege, and local administrator access through GodPotato and RunasCs.</description></item><item><title>VulnLab: Escape</title><link>https://mrbeetrootpwn.com/write-ups/vuln-escape/</link><pubDate>Sun, 12 Oct 2025 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/vuln-escape/</guid><description>Windows kiosk-style machine demonstrating RDP access, file-system browsing through Edge, binary restriction bypass via renaming, password recovery from Remote Desktop Plus, and GUI-based UAC elevation.</description></item><item><title>VulnLab: Data</title><link>https://mrbeetrootpwn.com/write-ups/vuln-data/</link><pubDate>Tue, 20 May 2025 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/vuln-data/</guid><description>Linux machine demonstrating Grafana arbitrary file read, Grafana credential cracking, SSH access, and Docker privileged container abuse.</description></item><item><title>VulnLab: Sync</title><link>https://mrbeetrootpwn.com/write-ups/vuln-sync/</link><pubDate>Mon, 12 May 2025 00:00:00 +0000</pubDate><guid>https://mrbeetrootpwn.com/write-ups/vuln-sync/</guid><description>Linux machine demonstrating anonymous rsync access, salted MD5 cracking, FTP-based SSH key placement, password reuse, and cronjob abuse.</description></item></channel></rss>