<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Machine :: X3ric Blog</title><link>https://x3ric.com/blog/categories/machine/</link><description>CTF notes, systems work, and writeups.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 06 Jun 2026 21:41:13 +0200</lastBuildDate><atom:link href="https://x3ric.com/blog/categories/machine/index.xml" rel="self" type="application/rss+xml"/><item><title>HackTheBox Backfire Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Backfire/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Backfire/</guid><pubDate>Mon, 27 Jan 2025 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>cve-2024-41570</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox EscapeTwo Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-EscapeTwo/</link><guid>https://x3ric.com/blog/posts/HackTheBox-EscapeTwo/</guid><pubDate>Mon, 27 Jan 2025 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>smb</category><category>ldap</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox UnderPass Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-UnderPass/</link><guid>https://x3ric.com/blog/posts/HackTheBox-UnderPass/</guid><pubDate>Sat, 28 Dec 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>docker</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox Heal Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Heal/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Heal/</guid><pubDate>Sun, 15 Dec 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox LinkVortex Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-LinkVortex/</link><guid>https://x3ric.com/blog/posts/HackTheBox-LinkVortex/</guid><pubDate>Sun, 08 Dec 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>docker</category><category>cve-2023-40028</category><description>LinkVortex: use CVE-2023-40028 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Bizness Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Bizness/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Bizness/</guid><pubDate>Thu, 05 Dec 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2023-49070</category><category>cve-2023-51467</category><description>Bizness: use CVE-2023-49070 and CVE-2023-51467 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Inject Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Inject/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Inject/</guid><pubDate>Thu, 05 Dec 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>cve-2022-22963</category><description>Inject: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Unrested Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Unrested/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Unrested/</guid><pubDate>Thu, 05 Dec 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2024-36467</category><category>cve-2024-42327</category><description>Unrested: use CVE-2024-36467 and CVE-2024-42327 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Vintage Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Vintage/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Vintage/</guid><pubDate>Wed, 04 Dec 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>ldap</category><description>Vintage: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Alert Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Alert/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Alert/</guid><pubDate>Sun, 24 Nov 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox BlockBlock Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-BlockBlock/</link><guid>https://x3ric.com/blog/posts/HackTheBox-BlockBlock/</guid><pubDate>Tue, 19 Nov 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox Ghost Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Ghost/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Ghost/</guid><pubDate>Tue, 19 Nov 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>ldap</category><category>docker</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox Administrator Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Administrator/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Administrator/</guid><pubDate>Sun, 17 Nov 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>ldap</category><description>Administrator: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Certified Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Certified/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Certified/</guid><pubDate>Thu, 07 Nov 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>ldap</category><description>Certified: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Blazorized Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Blazorized/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Blazorized/</guid><pubDate>Fri, 01 Nov 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>ldap</category><description>Blazorized: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Epsilon Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Epsilon/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Epsilon/</guid><pubDate>Fri, 01 Nov 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Epsilon: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox Mist Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Mist/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Mist/</guid><pubDate>Sat, 26 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>smb</category><category>ldap</category><category>cve-2024-9405</category><description>Mist: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Axlle Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Axlle/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Axlle/</guid><pubDate>Tue, 22 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>smb</category><category>ldap</category><description>Axlle: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Beep Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Beep/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Beep/</guid><pubDate>Sun, 20 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2012-4869</category><description>Beep: use CVE-2012-4869 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox MagicGardens Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-MagicGardens/</link><guid>https://x3ric.com/blog/posts/HackTheBox-MagicGardens/</guid><pubDate>Sun, 20 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>docker</category><description>MagicGardens: turn the exposed service into a shell, pivot through the container boundary, and escalate to root.</description></item><item><title>HackTheBox Chemistry Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Chemistry/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Chemistry/</guid><pubDate>Sat, 19 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2024-23334</category><category>cve-2024-23346</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox Compiled Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Compiled/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Compiled/</guid><pubDate>Fri, 18 Oct 2024 15:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>cve-2024-20656</category><category>cve-2024-32002</category><description>Compiled: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Union Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Union/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Union/</guid><pubDate>Wed, 16 Oct 2024 09:22:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Union: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox Jarmis Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Jarmis/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Jarmis/</guid><pubDate>Wed, 16 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>cve-2021-38647</category><description>Jarmis: use CVE-2021-38647 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Lantern Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Lantern/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Lantern/</guid><pubDate>Tue, 15 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2022-38580</category><description>Lantern: use CVE-2022-38580 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox MonitorsThree Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-MonitorsThree/</link><guid>https://x3ric.com/blog/posts/HackTheBox-MonitorsThree/</guid><pubDate>Mon, 14 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2024-25641</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox Resource Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Resource/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Resource/</guid><pubDate>Mon, 14 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>docker</category><description>Resource: turn the exposed service into a shell, pivot through the container boundary, and escalate to root.</description></item><item><title>HackTheBox Instant Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Instant/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Instant/</guid><pubDate>Sat, 12 Oct 2024 12:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox YPuffy Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-YPuffy/</link><guid>https://x3ric.com/blog/posts/HackTheBox-YPuffy/</guid><pubDate>Sat, 12 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>smb</category><category>ldap</category><category>cve-2018-14665</category><description>YPuffy: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>TryHackMe Brains Writeup</title><link>https://x3ric.com/blog/posts/TryHackMe-Brains/</link><guid>https://x3ric.com/blog/posts/TryHackMe-Brains/</guid><pubDate>Thu, 10 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>thm</category><category>linux</category><category>cve-2024-27198</category><description>Brains: use CVE-2024-27198 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Help Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Help/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Help/</guid><pubDate>Wed, 09 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>cve-2017-16995</category><category>cve-2017-5899</category><category>cve-2021-22555</category><description>Help: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox GoodGames Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-GoodGames/</link><guid>https://x3ric.com/blog/posts/HackTheBox-GoodGames/</guid><pubDate>Sun, 06 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>docker</category><description>GoodGames: turn the exposed service into a shell, pivot through the container boundary, and escalate to root.</description></item><item><title>HackTheBox Valentine Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Valentine/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Valentine/</guid><pubDate>Sun, 06 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2014-0160</category><category>cve-2016-5195</category><description>Valentine: use CVE-2014-0160 and CVE-2016-5195 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Yummy Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Yummy/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Yummy/</guid><pubDate>Sun, 06 Oct 2024 00:15:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Yummy: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox EvilCUPS Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-EvilCUPS/</link><guid>https://x3ric.com/blog/posts/HackTheBox-EvilCUPS/</guid><pubDate>Thu, 03 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2024-47076</category><category>cve-2024-47175</category><category>cve-2024-47176</category><category>cve-2024-47177</category><description>EvilCUPS: use CVE-2024-47076 and CVE-2024-47175 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>TryHackMe Prioritise Writeup</title><link>https://x3ric.com/blog/posts/TryHackMe-Prioritise/</link><guid>https://x3ric.com/blog/posts/TryHackMe-Prioritise/</guid><pubDate>Thu, 03 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>thm</category><category>linux</category><description>Prioritise: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>TryHackMe Pyrat Writeup</title><link>https://x3ric.com/blog/posts/TryHackMe-Pyrat/</link><guid>https://x3ric.com/blog/posts/TryHackMe-Pyrat/</guid><pubDate>Thu, 03 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>thm</category><category>linux</category><description>Pyrat: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox Cicada Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Cicada/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Cicada/</guid><pubDate>Wed, 02 Oct 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>smb</category><category>ldap</category><description>Cicada: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Gobox Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Gobox/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Gobox/</guid><pubDate>Mon, 30 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Gobox: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox Bashed Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Bashed/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Bashed/</guid><pubDate>Fri, 27 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Bashed: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox Shocker Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Shocker/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Shocker/</guid><pubDate>Fri, 27 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2014-6271</category><description>Shocker: use CVE-2014-6271 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox TwoMillion Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-TwoMillion/</link><guid>https://x3ric.com/blog/posts/HackTheBox-TwoMillion/</guid><pubDate>Fri, 27 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2023-0386</category><description>TwoMillion: use CVE-2023-0386 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Soccer Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Soccer/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Soccer/</guid><pubDate>Wed, 25 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>cve-2021-45010</category><description>Soccer: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox GreenHorn Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-GreenHorn/</link><guid>https://x3ric.com/blog/posts/HackTheBox-GreenHorn/</guid><pubDate>Mon, 23 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2023-50564</category><description>GreenHorn: use CVE-2023-50564 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox BoardLight Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-BoardLight/</link><guid>https://x3ric.com/blog/posts/HackTheBox-BoardLight/</guid><pubDate>Sun, 22 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2022-37706</category><category>cve-2023-30253</category><description>BoardLight: use CVE-2022-37706 and CVE-2023-30253 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Editorial Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Editorial/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Editorial/</guid><pubDate>Sun, 22 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Editorial: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox PermX Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-PermX/</link><guid>https://x3ric.com/blog/posts/HackTheBox-PermX/</guid><pubDate>Sun, 22 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2023-4220</category><description>PermX: use CVE-2023-4220 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Headless Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Headless/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Headless/</guid><pubDate>Sat, 21 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Headless: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox Trickster Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Trickster/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Trickster/</guid><pubDate>Sat, 21 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2023-47268</category><category>cve-2024-32651</category><category>cve-2024-34716</category><description>Trickster: use CVE-2023-47268 and CVE-2024-32651 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Sea Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Sea/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Sea/</guid><pubDate>Mon, 16 Sep 2024 00:12:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2023-41425</category><description>Sea: use CVE-2023-41425 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Caption Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Caption/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Caption/</guid><pubDate>Mon, 16 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Caption: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox Bastion Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Bastion/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Bastion/</guid><pubDate>Fri, 13 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>smb</category><description>Bastion: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Curling Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Curling/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Curling/</guid><pubDate>Fri, 13 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>joomla</category><description>Curling: abuse the Joomla exposure for a shell, then use local enumeration to reach root.</description></item><item><title>HackTheBox Sightless Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Sightless/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Sightless/</guid><pubDate>Fri, 13 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>docker</category><category>cve-2022-0944</category><category>cve-2024-34070</category><description>Sightless: use CVE-2022-0944 and CVE-2024-34070 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Spooktrol Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Spooktroll/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Spooktroll/</guid><pubDate>Fri, 13 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>docker</category><description>Spooktrol: turn the exposed service into a shell, pivot through the container boundary, and escalate to root.</description></item><item><title>HackTheBox Writeup Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Writeup/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Writeup/</guid><pubDate>Fri, 13 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2022-41544</category><description>Writeup: use CVE-2022-41544 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Active Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Active/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Active/</guid><pubDate>Thu, 12 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>smb</category><category>ldap</category><description>Active: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Codify Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Codify/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Codify/</guid><pubDate>Thu, 12 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>kerberos</category><description>Codify: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Paper Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Paper/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Paper/</guid><pubDate>Thu, 12 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>wordpress</category><category>cve-2019-17671</category><category>cve-2021-3560</category><description>Paper: use CVE-2019-17671 and CVE-2021-3560 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Perfection Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Perfection/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Perfection/</guid><pubDate>Thu, 12 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Perfection: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>TryHackMe Blog Writeup</title><link>https://x3ric.com/blog/posts/TryHackMe-Blog/</link><guid>https://x3ric.com/blog/posts/TryHackMe-Blog/</guid><pubDate>Thu, 13 Jun 2024 03:20:00 +0800</pubDate><category>machine</category><category>thm</category><category>windows</category><category>linux</category><category>wordpress</category><description>Blog: abuse the WordPress foothold, stabilize the shell, and escalate through the local weakness.</description></item><item><title>HackTheBox DevVortex Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-DevVortex/</link><guid>https://x3ric.com/blog/posts/HackTheBox-DevVortex/</guid><pubDate>Tue, 16 Apr 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>joomla</category><category>cve-2023-23752</category><description>DevVortex: use CVE-2023-23752 where it fits the service, gain a shell, and escalate to root.</description></item></channel></rss>