tag

Htb

373 posts
pwn

Regularity

Regularity: build the exploit primitive, stabilize the payload, and use it to read the flag.

pwn

SpellBrewery

SpellBrewery: build the exploit primitive, stabilize the payload, and use it to read the flag.

hardware

yoU ART

yoU ART: decode the captured signal, map the bitstream, and recover the flag.

machinemachine

Administrator

Administrator: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.

crypto

Binary Basis

Binary Basis: model the crypto leak, recover the missing secret, and decrypt the flag.

crypto

Brevi Moduli

Brevi Moduli: turn the RSA leak into a lattice recovery, rebuild the secret values, and decrypt the flag.

crypto

Hybrid Unifier

Hybrid Unifier: abuse the AES misuse, derive the missing key material, and decrypt the flag.

crypto

Inizialization

Inizialization: abuse the AES misuse, derive the missing key material, and decrypt the flag.

crypto

Read Before You Sign

Read Before You Sign: model the crypto leak, recover the missing secret, and decrypt the flag.

crypto

Sekur Julius

Sekur Julius: reconstruct the PRNG state from the leak, replay it, and recover the flag.

crypto

SPG

SPG: reconstruct the generator state, derive the AES material, and decrypt the final ciphertext.

crypto

Sugar Free Candies

Sugar Free Candies: model the crypto leak, recover the missing secret, and decrypt the flag.

machinemachine

Certified

Certified: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.

web

Feedback Flux

Feedback Flux: use the client-side injection path to steal the needed proof and recover the flag.

machinemachine

Blazorized

Blazorized: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.

machinemachine

Epsilon

Epsilon: enumerate the services, turn the exposed weakness into a shell, and escalate to root.

crypto

Secure Singning

Secure Singning: derive the XOR key stream, invert the transform, and recover the flag.

rev

Shattered Tablet

Shattered Tablet: trace the binary, isolate the validation routine, and invert it to recover the flag.

machinemachine

Mist

Mist: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.

machinemachine

Axlle

Axlle: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.

machinemachine

Beep

Beep: use CVE-2012-4869 where it fits the service, gain a shell, and escalate to root.

machinemachine

MagicGardens

MagicGardens: turn the exposed service into a shell, pivot through the container boundary, and escalate to root.