Logo Nitel's Red Logs
  • Home
  • About
  • Experiences
  • Posts
  • Writeups
  • Dark Theme
    Light Theme Dark Theme System Theme
Logo Inverted Logo
  • Tags
  • Active-Directory
  • CVE-2023-43364
  • Easy
  • File-Upload
  • GodPotato
  • Gtfobins
  • Hackthebox
  • HMailServer
  • IIS
  • Intro
  • Lfi
  • LibreOffice
  • Linux
  • Lpe-Windows
  • Macros
  • Medium
  • Oscp
  • Phar-Wrapper
  • Privilege-Escalation
  • Python2-Injection
  • Sebackupprivilege
  • SeImpersonate
  • Ssh
  • Vulnlab
  • Windows
  • Writeup
Hero Image
Cicada — HackTheBox Writeup

An easy-rated HTB Active Directory machine. The attack chain involves SMB guest enumeration, RID brute-forcing, password spraying, LDAP dumping, and finally abusing SeBackupPrivilege to extract the Administrator hash.

Monday, January 12, 2026 | 3 minutes Read
Hero Image
Media - VulnLab Writeup

Exploiting a .wax file upload to steal NTLMv2 credentials, then escalating privileges via SeImpersonate using GodPotato on a Windows target.

Sunday, January 11, 2026 | 3 minutes Read
Hero Image
UpDown - HackTheBox Writeup

UpDown is a medium Linux box where you chain an exposed .git repo, a custom header bypass, and a Phar wrapper LFI + file upload to get a shell. Root involves Python 2 input() injection on a SUID binary, then easy_install sudo abuse via GTFOBins.

Friday, January 9, 2026 | 4 minutes Read

Liability Notice: All content, technical materials, and write-ups published on this site are provided strictly for educational and research purposes. The author is not responsible for any misuse, damage, or illegal activities resulting from the use of the information presented. Readers are solely responsible for ensuring their actions comply with applicable laws and regulations.


Toha Theme Logo Toha
© 2026 Copyright.
Powered by Hugo Logo