HTB: Buff

Windows machine demonstrating unauthenticated file upload leading to CloudMe buffer overflow exploitation and administrator access.

March 5, 2026 · 5 min

HTB: Bashed

Linux machine demonstrating exposed PHP web shell access, sudo-based lateral movement, and cron-driven privilege escalation.

March 3, 2026 · 4 min

HTB: Arctic

Windows machine demonstrating Adobe ColdFusion remote code execution and kernel-based privilege escalation to SYSTEM.

March 2, 2026 · 4 min

HTB: Bounty

Windows machine demonstrating IIS upload bypass with web.config abuse and kernel exploit privilege escalation.

March 1, 2026 · 5 min

HTB: Broker

Linux machine demonstrating Apache ActiveMQ CVE-2023-46604 exploitation and sudo nginx abuse for root access.

December 18, 2025 · 4 min

HTB: Flight

Active Directory machine demonstrating NTLM hash capture, SMB abuse, password reuse, IIS pivoting, and SeImpersonatePrivilege escalation.

November 1, 2025 · 9 min

VulnLab: Job

Windows machine demonstrating phishing through a malicious LibreOffice document, IIS web root abuse, SeImpersonatePrivilege, and local administrator access through GodPotato and RunasCs.

October 13, 2025 · 6 min