HackTheBox β DarkZero Returns
An Insane-rated, two-forest Active Directory machine. The full writeup is embargoed until the box retires β root it and enter the flag to read it early.
$ ls ./writeups/
HackTheBox / TryHackMe machine writeups, penetration testing walkthroughs, and security research notes. Published after the official disclosure window.
An Insane-rated, two-forest Active Directory machine. The full writeup is embargoed until the box retires β root it and enter the flag to read it early.
Abusing a careers-portal zip upload to leak and crack web_svc's NTLMv2 hash via CVE-2025-24071 / CVE-2025-24054, walking a BloodHound ACL chain to monitoring_svc, then hijacking a vulnerable Checkmk agent's MSI self-repair (CVE-2024-0670) through RunasCs to execute code as SYSTEM.
Chaining an authenticated RoundCube RCE exploit, MySQL session token harvesting with DES3 decryption, and a CVE-2025-27591 symlink attack via a world-writable log directory to reach root.
Exploiting a web-accessible phpbash shell for initial access, then escalating via sudo to scriptmanager and abusing a cron-run Python script to land root.
Abusing anonymous FTP access to steal PRTG Network Monitor config files with backup credentials, then exploiting a PRTG command injection vulnerability (CVE-2018-9276) for SYSTEM shell.
Highlights and solutions from TryHackMe's Advent of Cyber 2024 β covering OSINT, OPSEC analysis, log forensics, and web vulnerability hunting.