Hack The Box - Season 10 HTB Facts Writeup - Easy- Weekly - January 31th, 2026

Hack The Box - Season 10 HTB Facts Writeup - Easy- Weekly - January 31th, 2026

Facts is an Easy-rated Linux machine featuring a Ruby on Rails CMS called Camaleon. The attack path involves exploiting an Insecure Direct Object Reference (IDOR) vulnerability to escalate privileges within the CMS, extracting cloud storage credentials, recovering an SSH private key from a misconfigured MinIO bucket, and finally abusing sudo permissions on the Facter system profiling tool to achieve root access.
Hack The Box - Season 9 HTB NanoCorp Writeup - Hard- Weekly - November 8th, 2025

Hack The Box - Season 9 HTB NanoCorp Writeup - Hard- Weekly - November 8th, 2025

The Enchanted Hiring Hall A mystical corporation sought new wizards through an enchanted portal. A cursed scroll disguised as parchment stole a gatekeeper's essence. Following threads of ancient permissions through the company's spell-work, a monitoring apprentice—bound by protective wards—summoned an ally. Together they exploited a flaw in the castle's self-repair enchantment, ascending to the Archmage's tower
Hack The Box - Season 9 HTB Hercules Writeup - Insane - Weekly - October 18th, 2025

Hack The Box - Season 9 HTB Hercules Writeup - Insane - Weekly - October 18th, 2025

A determined challenger systematically dismantled layers of protection through careful observation and creative problem-solving. Starting with surface-level reconnaissance, they discovered hidden pathways and exploited trust relationships to gradually expand their influence. Through persistence and methodical advancement, they transformed from an outsider into someone with complete authority over the entire domain.
OffSec Gauntlet - ProtoVault Breach Complete Investigation - Advanced - October 15th, 2025

OffSec Gauntlet - ProtoVault Breach Complete Investigation - Advanced - October 15th, 2025

In the storm-battered peaks of a forgotten mountain range, the crystalline walls of ProtoVault shimmered with failing enchantments. The Everbound Order's most sacred sanctuary - guardian of arcane knowledge that maintained the balance of the Cyber Realms - had been breached. A ransom scroll arrived, threatening to unleash the Corespell unless Archivist Verin surrendered himself. But magic alone couldn't solve this digital crisis - it required the skills of a codecaster to trace the breach to its source._
Hack The Box - Season 9 HTB Signed Writeup - Medium - Weekly - October 11th, 2025

Hack The Box - Season 9 HTB Signed Writeup - Medium - Weekly - October 11th, 2025

In the crystalline fortress of Signed, a humble visitor discovers that whispering the right incantations to the castle's mirrors causes the servants to reveal their secret names in hushed confessions. These stolen whispers, once decoded by moonlight, become silver keys that grant the power to wear masks of nobility—transforming peasant into prince with each ethereal disguise. The traveler learns to forge celestial tickets in the realm's ancient forge, each one a shimmering passport to rooms previously forbidden, climbing ever higher through chambers of increasing grandeur. By weaving these silver threads of borrowed authority and speaking in tongues of trusted spirits, the wanderer ultimately dons the crown of shadows itself. The journey ends at the highest tower where the golden flag awaits, proof that even the mightiest citadel bows to one who masters the art of becoming everyone and no one at once.
OffSec Gauntlet - Complete Grimoire Tutorial Walkthrough  - October 7th, 2025

OffSec Gauntlet - Complete Grimoire Tutorial Walkthrough - October 7th, 2025

The ancient grimoire lay open on the dusty library table, its pages filled with cryptic symbols and hidden meanings. Each puzzle within demanded patience and precision - one wrong interpretation would seal the book forever. The apprentice traced each marking carefully, knowing that masters before had failed at this very challenge. Success required not just knowledge, but the wisdom to see patterns others missed. Only those who could "try harder" would unlock the secrets within
Hack The Box - Season 9 HTB Expressway Writeup - Easy - Weekly - September 20th, 2025

Hack The Box - Season 9 HTB Expressway Writeup - Easy - Weekly - September 20th, 2025

From the silence of UDP port 500 where IKE whispers its aggressive confessions, through hashes that bleed like ink in water revealing a secret borrowed from the collective unconscious of rockyou—into the SSH portal as 'ike' who carries the name of his own betrayal, until sudo's chroot prison crumbles at the touch of a poisoned NSS library, teaching us that the path to root flows not through the guarded TCP gates but through the forgotten protocols that speak their truths too loudly to those who remember the old languages of exploitation.