~/mbt
Writeups

Security Writeups

CTF writeups, machine walkthroughs, and security challenge solutions.

All Writeups

42 available
hack the-boxmediumLinux

Silentium

01

VHost fuzzing

02

CVE-2025-58434 for account takeover

thunderciphermediumLinux

WebAdmin

01

Enumerated admin panel

02

Found authentication weakness

thunderciphermediumLinux

Trivarna

01

Scanned target with nmap

02

Enumerated web application

thunderciphermediumLinux

StegoVault

01

Enumerated steganography challenge

02

Extracted hidden data

thunderciphermediumLinux

PageVault

01

Scanned target with nmap

02

Enumerated page vault application

thunderciphermediumLinux

Mr.Robot

01

Enumerated target system

02

Found vulnerable service

thunderciphermediumLinux

Deathnote

01

Scanned target with nmap

02

Enumerated web application

thunderciphermediumLinux

Chain

01

Identified chain of vulnerabilities

02

Exploited initial foothold

thunderciphermediumLinux

Behind The Proxy

01

Enumerated proxy configuration

02

Found proxy bypass vulnerability

hack the-boxmediumLinux

Sorcery

01

Nmap scan revealed services

02

Enumerated web application

hack the-boxmediumLinux

Snapped

01

Initial enumeration

02

Discovered snapshot application

hack the-boxmediumLinux

Signed

01

Scanned target with nmap

02

Enumerated services

hack the-boxmediumLinux

Pterodactyl

01

Nmap scan revealed services

02

Enumerated game server panel

hack the-boxmediumWindows

Principal

01

AD enumeration

02

Identified vulnerable service

hack the-boxmediumLinux

Overwatch

01

Comprehensive enumeration

02

Identified monitoring system vulnerability

hack the-boxmediumLinux

Logging

01

Initial enumeration

02

Discovered logging application

hack the-boxmediumLinux

Interpreter

01

Nmap scan revealed services

02

Enumerated interpreter application

hack the-boxmediumWindows

Intelligence

01

AD enumeration

02

Identified GPO vulnerability

hack the-boxmediumLinux

Guardian

01

Initial enumeration

02

Discovered security application

hack the-boxmediumLinux

FireFlow

01

Comprehensive enumeration

02

Identified workflow engine vulnerability

hack the-boxmediumLinux

Eloquia

01

Initial enumeration

02

Discovered web application

hack the-boxmediumLinux

DevArea

01

Scanned target with nmap

02

Enumerated development environment

hack the-boxmediumLinux

Conversor

01

Nmap scan revealed services

02

Enumerated conversion service

hack the-boxmediumLinux

Cobblestone

01

Initial enumeration

02

Discovered web application

hack the-boxmediumLinux

Breach

01

Comprehensive enumeration

02

Identified vulnerable web application

tryhackmemediumLinux

VulnNet: dotpy

01

Scanned target with nmap

02

Enumerated Python web application

tryhackmemediumWindows

VulnNet: Roasted

01

AD enumeration

02

Identified ASREPRoastable accounts

tryhackmemediumWindows

VulnNet: Internal

01

Network enumeration

02

Identified internal services

tryhackmemediumWindows

VulnNet: Active

01

AD enumeration with BloodHound

02

Identified Kerberoastable accounts

tryhackmemediumLinux

Sustah

01

Initial enumeration

02

Discovered web application

tryhackmemediumLinux

RazorBlack

01

Scanned target with nmap

02

Enumerated web application

tryhackmemediumLinux

One Piece

01

Nmap scan revealed services

02

Enumerated web application

tryhackmemediumLinux

Ledger

01

Initial nmap scan

02

Enumerated web application

tryhackmemediumLinux

IronShade

01

Nmap scan revealed services

02

Enumerated web server

tryhackmemediumLinux

Inferno

01

Scanned target with nmap

02

Enumerated web application

tryhackmemediumLinux

Exfilibur

01

Nmap scan revealed web services

02

Enumerated application for data exfiltration vectors

tryhackmemediumLinux

Devie

01

Initial enumeration with nmap

02

Discovered web application with development endpoints

tryhackmemediumLinux

Debug

01

Nmap scan revealed multiple services

02

Enumerated web application for debugging endpoints

tryhackmemediumLinux

CupidCards

01

Scanned target with nmap

02

Enumerated web application endpoints

tryhackmemediumLinux

Chains of Love

01

Enumerated web application for SSRF vulnerabilities

02

Discovered internal services through SSRF

tryhackmemediumLinux

Brute

01

Scanned target with nmap

02

Enumerated web application for input vectors

tryhackmemediumWindows

Attacktive Directory

01

Enumerated AD environment using BloodHound

02

Identified Kerberoastable service accounts