Knowledge Base // Vulnerability Research

SECURITY_BLOG .

Offensive security write-ups, web/API/cloud vulnerability analysis, and research notes. Documenting exploitation to better understand defense.

QUERY

FILTERS

CATEGORIES

Showing 13 entries
SORT: NEWEST
HTB-2026-SNAPPED2026-03-23MEDIUM

Snapped

Offensive security write-up.

WRITEUPHACKTHEBOXLINUXMEDIUMBACKUP-DISCLOSURENGINX-UICVE-2026-3888
READ_LOG >
HTB-2026-INTERPRETER2026-02-21MEDIUM

Interpreter

Offensive security write-up.

WRITEUPHACKTHEBOXLINUXMEDIUMDESERIALIZATIONCVE-2023-43208F-STRING-INJECTION
READ_LOG >
HTB-2026-OVERWATCH2026-02-07MEDIUM

Overwatch

Offensive security write-up.

WRITEUPHACKTHEBOXWINDOWSMEDIUMNTLM-CAPTUREWCF-SERVICECOMMAND-INJECTION
READ_LOG >
HTB-2026-BROWSED2026-01-10MEDIUM

Browsed

Offensive security write-up.

WRITEUPHACKTHEBOXLINUXMEDIUMSSRFCOMMAND-INJECTIONCACHE-POISONING
READ_LOG >
HTB-2026-MONITORSFOUR2025-12-06EASY

MonitorsFour

Offensive security write-up.

WRITEUPHACKTHEBOXWINDOWSEASYCACTICVE-2025-24367DOCKER-ESCAPE
READ_LOG >
HTB-2026-GAVEL2025-11-29MEDIUM

Gavel

Offensive security write-up.

WRITEUPHACKTHEBOXLINUXMEDIUMSQLIRUNKITSUID-EXECUTION
READ_LOG >
HTB-2026-EIGHTEEN2025-11-15EASY

Eighteen

Offensive security write-up.

WRITEUPHACKTHEBOXWINDOWSEASYDMSABADSUCCESSORKERBEROS-PAC
READ_LOG >
HTB-2026-CONVERSOR2025-10-25EASY

Conversor

Offensive security write-up.

WRITEUPHACKTHEBOXLINUXEASYPATH-TRAVERSALCRON-HIJACKNEEDRESTART
READ_LOG >
HTB-2025-0112025-10-11MEDIUM

Signed

Offensive security write-up.

WRITEUPHACKTHEBOXWINDOWSMSSQLKERBEROSSILVER-TICKETMEDIUM
READ_LOG >
HTB-2026-DARKZERO2025-10-04HARD

DarkZero

Offensive security write-up.

WRITEUPHACKTHEBOXWINDOWSHARDCROSS-FORESTMSSQL-LINKCVE-2024-30088
READ_LOG >
HTB-2025-0022025-09-20EASY

Expressway

Hack The Box Expressway write-up: IKE aggressive mode enumeration, offline PSK crack, SSH foothold, and sudo privilege escalation.

WRITEUPHACKTHEBOXLINUXEASYVPNIPSECIKEPRIVESC
READ_LOG >
HTB-2026-TWOMILLION2025-09-20MEDIUM

TwoMillion

Offensive security write-up.

WRITEUPHACKTHEBOXLINUXMEDIUMAPI-BYPASSCOMMAND-INJECTIONCVE-2023-0386
READ_LOG >
HTB-2026-SOULMATE2025-09-06MEDIUM

Soulmate

Offensive security write-up.

WRITEUPHACKTHEBOXLINUXMEDIUMCONFIG-LEAKERLANGPORT-TUNNELING
READ_LOG >