~/mbt
Writeups

Security Writeups

CTF writeups, machine walkthroughs, and security challenge solutions. Active machines show approach only — full writeups available after retirement.

Active Machines

approach only

Retired Writeups

17 available
hack the-boxmediumLinux retired

Silentium

01

VHost fuzzing

02

CVE-2025-58434 for account takeover

hack the-boxmediumLinux retired

Sorcery

01

Nmap scan revealed services

02

Enumerated web application

hack the-boxmediumLinux retired

Snapped

01

Initial enumeration

02

Discovered snapshot application

hack the-boxmediumLinux retired

Signed

01

Scanned target with nmap

02

Enumerated services

hack the-boxmediumLinux retired

Pterodactyl

01

Nmap scan revealed services

02

Enumerated game server panel

hack the-boxmediumWindows retired

Principal

01

AD enumeration

02

Identified vulnerable service

hack the-boxmediumLinux retired

Overwatch

01

Comprehensive enumeration

02

Identified monitoring system vulnerability

hack the-boxmediumLinux retired

Logging

01

Initial enumeration

02

Discovered logging application

hack the-boxmediumLinux retired

Interpreter

01

Nmap scan revealed services

02

Enumerated interpreter application

hack the-boxmediumWindows retired

Intelligence

01

AD enumeration

02

Identified GPO vulnerability

hack the-boxmediumLinux retired

Guardian

01

Initial enumeration

02

Discovered security application

hack the-boxmediumLinux retired

FireFlow

01

Comprehensive enumeration

02

Identified workflow engine vulnerability

hack the-boxmediumLinux retired

Eloquia

01

Initial enumeration

02

Discovered web application

hack the-boxmediumLinux retired

DevArea

01

Scanned target with nmap

02

Enumerated development environment

hack the-boxmediumLinux retired

Conversor

01

Nmap scan revealed services

02

Enumerated conversion service

hack the-boxmediumLinux retired

Cobblestone

01

Initial enumeration

02

Discovered web application

hack the-boxmediumLinux retired

Breach

01

Comprehensive enumeration

02

Identified vulnerable web application