HTB: Buff

Windows machine demonstrating unauthenticated file upload leading to CloudMe buffer overflow exploitation and administrator access.

March 5, 2026 · 5 min

HTB: Analytics

Linux machine demonstrating Metabase pre-auth RCE, Docker environment credential disclosure, and OverlayFS kernel exploitation.

December 19, 2025 · 6 min

HTB: Broker

Linux machine demonstrating Apache ActiveMQ CVE-2023-46604 exploitation and sudo nginx abuse for root access.

December 18, 2025 · 4 min

VulnLab: Lock

Windows machine demonstrating Gitea access token exposure, repository-backed web deployment, mRemoteNG credential recovery, and PDF24 local privilege escalation.

October 16, 2025 · 7 min