easy
Overpass3 - Hosting
· ☕ 9 min read · ✍️ M4t35Z
dirfuzz --> backup --> gpg --> creds --> ftp --> pw reuse --> nfs

Overpass2 - hacked
· ☕ 4 min read · ✍️ M4t35Z
A box about pcap analysis and a SUID binary

Archangel
· ☕ 8 min read · ✍️ M4t35Z
A box about getting an RCE via LFI and Log Poisoning. Then abusing a cronjob that used a file with weak permissions. And then analysing a suid binary which used relative paths instead of absolute paths which made it vulnerable to path injection.

Overpass
· ☕ 7 min read · ✍️ M4t35Z
TryHackMe Overpass writeup

Omni
· ☕ 6 min read · ✍️ M4t35Z
HackTheBox Omni writeup. A Windows IOT box, with PSCredential encrypted flags

Bot Takeover 0x1
· ☕ 5 min read · ✍️ M4t35Z
Command injection in a discord BOT

Buff
· ☕ 5 min read · ✍️ M4t35Z
Buff writeup, ENUMERATE EVERYTHING. At the start the box was slow as hell like the majority of windows boxes lmao. Btw here's the process: Website enum --> cve --> Local enum --> cve --> root

Blunder
· ☕ 6 min read · ✍️ M4t35Z
Rooting Blunder

Traceback
· ☕ 5 min read · ✍️ M4t35Z
Traceback was a very enjoyable box. I used a little OSINT in the first part after I got in I used only manual enumeration techinques in order to get to the root user.

Sauna
· ☕ 5 min read · ✍️ M4t35Z
My writeup for an easy windows AD box.