<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Linux :: X3ric Blog</title><link>https://x3ric.com/blog/tags/linux/</link><description>CTF notes, systems work, and writeups.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 06 Jun 2026 21:41:13 +0200</lastBuildDate><atom:link href="https://x3ric.com/blog/tags/linux/index.xml" rel="self" type="application/rss+xml"/><item><title>HackTheBox LicenseGenerator</title><link>https://x3ric.com/blog/posts/HackTheBox-LicenseGenerator/</link><guid>https://x3ric.com/blog/posts/HackTheBox-LicenseGenerator/</guid><pubDate>Fri, 27 Jun 2025 01:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>xor</category><category>linux</category><description>LicenseGenerator: recover the XOR transform from the binary and invert it to reveal the flag.</description></item><item><title>HackTheBox SatelliteHijack</title><link>https://x3ric.com/blog/posts/HackTheBox-SatelliteHijack/</link><guid>https://x3ric.com/blog/posts/HackTheBox-SatelliteHijack/</guid><pubDate>Fri, 27 Jun 2025 01:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>gdb</category><category>xor</category><category>linux</category><description>SatelliteHijack: trace the binary, isolate the validation routine, and invert it to recover the flag.</description></item><item><title>HackTheBox BinCrypt Breaker Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-BinCrypt-Breaker-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-BinCrypt-Breaker-Challenge/</guid><pubDate>Sun, 16 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>xor</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Curse Breaker Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Curse-Breaker-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Curse-Breaker-Challenge/</guid><pubDate>Sun, 16 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Curse Breaker: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Maze Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Maze-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Maze-Challenge/</guid><pubDate>Tue, 04 Feb 2025 17:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>dotnet</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Partial Encryption Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Partial-Encryption-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Partial-Encryption-Challenge/</guid><pubDate>Tue, 04 Feb 2025 17:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>Binary Exploitation</title><link>https://x3ric.com/blog/posts/Binary-Exploitation/</link><guid>https://x3ric.com/blog/posts/Binary-Exploitation/</guid><pubDate>Tue, 04 Feb 2025 04:10:00 +0800</pubDate><category>notes</category><category>notes</category><category>linux</category><category>pwn</category><description>Assembly Overview Assembly language is a low-level programming language that translates high-level code into machine instructions. Registers temporarily hold data and facilitate operations.</description></item><item><title>HackTheBox Behind the Scenes Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Behind-the-Scenes-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Behind-the-Scenes-Challenge/</guid><pubDate>Thu, 30 Jan 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>gdb</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Cyberpsychosis Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Cyberpsychosis-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Cyberpsychosis-Challenge/</guid><pubDate>Thu, 30 Jan 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox ReRop Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-ReRop-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-ReRop-Challenge/</guid><pubDate>Thu, 30 Jan 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>xor</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Coffee Invocation Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Coffee-Invocation-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Coffee-Invocation-Challenge/</guid><pubDate>Wed, 29 Jan 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Backfire Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Backfire/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Backfire/</guid><pubDate>Mon, 27 Jan 2025 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>cve-2024-41570</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox EscapeTwo Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-EscapeTwo/</link><guid>https://x3ric.com/blog/posts/HackTheBox-EscapeTwo/</guid><pubDate>Mon, 27 Jan 2025 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>smb</category><category>ldap</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox Anti Flag Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Anti-Flag-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Anti-Flag-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Anti Flag: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Baby Crypt Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Baby-Crypt-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Baby-Crypt-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>xor</category><category>linux</category><description>Baby Crypt: recover the XOR transform from the binary and invert it to reveal the flag.</description></item><item><title>HackTheBox Baby RE Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Baby-RE-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Baby-RE-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>elf</category><category>linux</category><description>Baby RE: trace the binary, isolate the validation routine, and invert it to recover the flag.</description></item><item><title>HackTheBox Eat the Cake! Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Eat-the-Cake-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Eat-the-Cake-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Eat the Cake: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Encryption Bot Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Encryption-Bot-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Encryption-Bot-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Encryption Bot: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Impossible Password Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Impossible-Password-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Impossible-Password-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>xor</category><category>linux</category><description>Impossible Password: recover the XOR transform from the binary and invert it to reveal the flag.</description></item><item><title>HackTheBox IRCWare Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-IRCWare-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-IRCWare-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>IRCWare: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Metagaming Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Metagaming-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Metagaming-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Metagaming: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Ouija Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Ouija-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Ouija-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Ouija: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Ransom Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Ransom-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Ransom-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Ransom: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Rebuilding Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Rebuilding-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Rebuilding-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Rebuilding: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox Secured Transfer Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Secured-Transfer-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Secured-Transfer-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Secured Transfer: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Sekure Decrypt Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Sekure-Decrypt-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Sekure-Decrypt-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Sekure Decrypt: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Shuffleme Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Shuffleme-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Shuffleme-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>elf</category><category>linux</category><description>Shuffleme: trace the binary, isolate the validation routine, and invert it to recover the flag.</description></item><item><title>HackTheBox Snakecode Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Snakecode-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Snakecode-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Snakecode: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Tear Or Dear Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Tear-Or-Dear-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Tear-Or-Dear-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>dotnet</category><category>linux</category><description>Tear Or Dear: decompile the .NET logic, rebuild the check, and recover the accepted input.</description></item><item><title>HackTheBox The Art of Reversing Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-The-Art-of-Reversing-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-The-Art-of-Reversing-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>dotnet</category><category>linux</category><description>The Art of Reversing: decompile the .NET logic, rebuild the check, and recover the accepted input.</description></item><item><title>HackTheBox You Cant C Me Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-You-Cant-C-Me-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-You-Cant-C-Me-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>You Cant C Me: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Under the web Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Under-the-web-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Under-the-web-Challenge/</guid><pubDate>Sat, 11 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Rauth Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Rauth-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Rauth-Challenge/</guid><pubDate>Thu, 09 Jan 2025 12:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Rega's Town Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Regas-Town-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Regas-Town-Challenge/</guid><pubDate>Mon, 06 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Exatlon Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Exatlon-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Exatlon-Challenge/</guid><pubDate>Sat, 28 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox UnderPass Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-UnderPass/</link><guid>https://x3ric.com/blog/posts/HackTheBox-UnderPass/</guid><pubDate>Sat, 28 Dec 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>docker</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox Spooky License Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Spooky-License-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Spooky-License-Challenge/</guid><pubDate>Sat, 21 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Spooky License: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox ChromeMiner Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-ChromeMiner-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-ChromeMiner-Challenge/</guid><pubDate>Wed, 18 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>ChromeMiner: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Vault-breaker Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Vault-breaker-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Vault-breaker-Challenge/</guid><pubDate>Tue, 17 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Vault-breaker: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox Heal Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Heal/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Heal/</guid><pubDate>Sun, 15 Dec 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox FlagCasino Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-FlagCasino-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-FlagCasino-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>elf</category><category>linux</category><description>FlagCasino: trace the binary, isolate the validation routine, and invert it to recover the flag.</description></item><item><title>HackTheBox Getting Started Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Getting-Started-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Getting-Started-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>bof</category><category>linux</category><description>Getting Started: calculate the overflow offset, redirect control flow, and land a reliable flag read.</description></item><item><title>HackTheBox Hunting License Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Hunting-License-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Hunting-License-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>elf</category><category>xor</category><category>linux</category><description>Hunting License: trace the binary, isolate the validation routine, and invert it to recover the flag.</description></item><item><title>HackTheBox LinkHands Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-LinkHands-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-LinkHands-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>LinkHands: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Questionnaire Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Questionnaire-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Questionnaire-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>bof</category><category>format-string</category><category>canary</category><category>linux</category><description>Questionnaire: use the format-string bug for a leak or write, then redirect execution to the flag path.</description></item><item><title>HackTheBox Space Pirate Going Deeper Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Space-Pirate-Going-Deeper-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Space-Pirate-Going-Deeper-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Space Pirate Going Deeper: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox Terrorfryer Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Terrorfryer-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Terrorfryer-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Terrorfryer: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Wizard's Diary Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Wizards-Diary-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Wizards-Diary-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>bof</category><category>linux</category><description>Wizard's Diary: calculate the overflow offset, redirect control flow, and land a reliable flag read.</description></item><item><title>HackTheBox Writing on the Wall Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Writing-on-the-Wall-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Writing-on-the-Wall-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Writing on the Wall: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox Crushing Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Crushing-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Crushing-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Crushing: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Entity Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Entity-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Entity-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Entity: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox Golfer Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Golfer-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Golfer-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>elf</category><category>linux</category><description>Golfer: trace the binary, isolate the validation routine, and invert it to recover the flag.</description></item><item><title>HackTheBox Graverobber Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Graverobber-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Graverobber-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>gdb</category><category>linux</category><description>Graverobber: trace the binary, isolate the validation routine, and invert it to recover the flag.</description></item><item><title>HackTheBox Pixel Audio Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Pixel-Audio-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Pixel-Audio-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Pixel Audio: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox Potion Master Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Potion-Master-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Potion-Master-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>xor</category><category>linux</category><description>Potion Master: recover the XOR transform from the binary and invert it to reveal the flag.</description></item><item><title>HackTheBox QuickScan Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-QuickScan-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-QuickScan-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>elf</category><category>linux</category><description>QuickScan: trace the binary, isolate the validation routine, and invert it to recover the flag.</description></item><item><title>HackTheBox RaceCar Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-RaceCar-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-RaceCar-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>format-string</category><category>linux</category><description>RaceCar: use the format-string bug for a leak or write, then redirect execution to the flag path.</description></item><item><title>HackTheBox El Mundo Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-El-Mundo-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-El-Mundo-Challenge/</guid><pubDate>Mon, 09 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>bof</category><category>linux</category><description>El Mundo: calculate the overflow offset, redirect control flow, and land a reliable flag read.</description></item><item><title>HackTheBox El Pipo Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-El-Pipo-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-El-Pipo-Challenge/</guid><pubDate>Mon, 09 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>bof</category><category>linux</category><description>El Pipo: calculate the overflow offset, redirect control flow, and land a reliable flag read.</description></item><item><title>HackTheBox LinkVortex Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-LinkVortex/</link><guid>https://x3ric.com/blog/posts/HackTheBox-LinkVortex/</guid><pubDate>Sun, 08 Dec 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>docker</category><category>cve-2023-40028</category><description>LinkVortex: use CVE-2023-40028 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Bizness Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Bizness/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Bizness/</guid><pubDate>Thu, 05 Dec 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2023-49070</category><category>cve-2023-51467</category><description>Bizness: use CVE-2023-49070 and CVE-2023-51467 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Inject Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Inject/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Inject/</guid><pubDate>Thu, 05 Dec 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>cve-2022-22963</category><description>Inject: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Unrested Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Unrested/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Unrested/</guid><pubDate>Thu, 05 Dec 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2024-36467</category><category>cve-2024-42327</category><description>Unrested: use CVE-2024-36467 and CVE-2024-42327 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Vintage Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Vintage/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Vintage/</guid><pubDate>Wed, 04 Dec 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>ldap</category><description>Vintage: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Kernel Adventures 2 Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Kernel-Adventures-2-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Kernel-Adventures-2-Challenge/</guid><pubDate>Tue, 03 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>shellcode</category><category>linux</category><description>Kernel Adventures 2: build the shellcode path, control execution, and read the flag.</description></item><item><title>HackTheBox Execute Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Execute-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Execute-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>bof</category><category>shellcode</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Alert Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Alert/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Alert/</guid><pubDate>Sun, 24 Nov 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox Dont't Panic Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Dontt-Panic-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Dontt-Panic-Challenge/</guid><pubDate>Sat, 23 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>ghidra</category><category>linux</category><description>Dont't Panic: trace the binary, isolate the validation routine, and invert it to recover the flag.</description></item><item><title>HackTheBox El Teteo Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-El-Teteo-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-El-Teteo-Challenge/</guid><pubDate>Sat, 23 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>shellcode</category><category>linux</category><description>El Teteo: build the shellcode path, control execution, and read the flag.</description></item><item><title>HackTheBox Mathematricks Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Mathematricks-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Mathematricks-Challenge/</guid><pubDate>Sat, 23 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Mathematricks: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox Que Onda Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Que-Onda-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Que-Onda-Challenge/</guid><pubDate>Sat, 23 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Que Onda: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox Regularity Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Regularity-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Regularity-Challenge/</guid><pubDate>Sat, 23 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Regularity: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox SpellBrewery Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-SpellBrewery-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-SpellBrewery-Challenge/</guid><pubDate>Sat, 23 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>SpellBrewery: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox BlockBlock Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-BlockBlock/</link><guid>https://x3ric.com/blog/posts/HackTheBox-BlockBlock/</guid><pubDate>Tue, 19 Nov 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox Ghost Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Ghost/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Ghost/</guid><pubDate>Tue, 19 Nov 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>ldap</category><category>docker</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox WayBack Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Wayback-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Wayback-Challenge/</guid><pubDate>Mon, 18 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Administrator Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Administrator/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Administrator/</guid><pubDate>Sun, 17 Nov 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>ldap</category><description>Administrator: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Certified Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Certified/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Certified/</guid><pubDate>Thu, 07 Nov 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>ldap</category><description>Certified: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Blazorized Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Blazorized/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Blazorized/</guid><pubDate>Fri, 01 Nov 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>ldap</category><description>Blazorized: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Epsilon Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Epsilon/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Epsilon/</guid><pubDate>Fri, 01 Nov 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Epsilon: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox Shattered Tablet Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Shattered-Tablet-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Shattered-Tablet-Challenge/</guid><pubDate>Wed, 30 Oct 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>ghidra</category><category>linux</category><description>Shattered Tablet: trace the binary, isolate the validation routine, and invert it to recover the flag.</description></item><item><title>HackTheBox Mist Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Mist/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Mist/</guid><pubDate>Sat, 26 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>smb</category><category>ldap</category><category>cve-2024-9405</category><description>Mist: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Axlle Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Axlle/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Axlle/</guid><pubDate>Tue, 22 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>smb</category><category>ldap</category><description>Axlle: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Beep Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Beep/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Beep/</guid><pubDate>Sun, 20 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2012-4869</category><description>Beep: use CVE-2012-4869 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox MagicGardens Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-MagicGardens/</link><guid>https://x3ric.com/blog/posts/HackTheBox-MagicGardens/</guid><pubDate>Sun, 20 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>docker</category><description>MagicGardens: turn the exposed service into a shell, pivot through the container boundary, and escalate to root.</description></item><item><title>HackTheBox Simple Encryptor Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Simple-Encryptor-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Simple-Encryptor-Challenge/</guid><pubDate>Sun, 20 Oct 2024 01:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>elf</category><category>xor</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Chemistry Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Chemistry/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Chemistry/</guid><pubDate>Sat, 19 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2024-23334</category><category>cve-2024-23346</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox Compiled Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Compiled/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Compiled/</guid><pubDate>Fri, 18 Oct 2024 15:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>cve-2024-20656</category><category>cve-2024-32002</category><description>Compiled: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Union Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Union/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Union/</guid><pubDate>Wed, 16 Oct 2024 09:22:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Union: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox Jarmis Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Jarmis/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Jarmis/</guid><pubDate>Wed, 16 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>cve-2021-38647</category><description>Jarmis: use CVE-2021-38647 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Lantern Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Lantern/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Lantern/</guid><pubDate>Tue, 15 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2022-38580</category><description>Lantern: use CVE-2022-38580 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox MonitorsThree Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-MonitorsThree/</link><guid>https://x3ric.com/blog/posts/HackTheBox-MonitorsThree/</guid><pubDate>Mon, 14 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2024-25641</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox Resource Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Resource/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Resource/</guid><pubDate>Mon, 14 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>docker</category><description>Resource: turn the exposed service into a shell, pivot through the container boundary, and escalate to root.</description></item><item><title>HackTheBox Instant Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Instant/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Instant/</guid><pubDate>Sat, 12 Oct 2024 12:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox YPuffy Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-YPuffy/</link><guid>https://x3ric.com/blog/posts/HackTheBox-YPuffy/</guid><pubDate>Sat, 12 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>smb</category><category>ldap</category><category>cve-2018-14665</category><description>YPuffy: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>TryHackMe Brains Writeup</title><link>https://x3ric.com/blog/posts/TryHackMe-Brains/</link><guid>https://x3ric.com/blog/posts/TryHackMe-Brains/</guid><pubDate>Thu, 10 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>thm</category><category>linux</category><category>cve-2024-27198</category><description>Brains: use CVE-2024-27198 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Help Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Help/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Help/</guid><pubDate>Wed, 09 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>cve-2017-16995</category><category>cve-2017-5899</category><category>cve-2021-22555</category><description>Help: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>BloodHound</title><link>https://x3ric.com/blog/posts/BloodHound/</link><guid>https://x3ric.com/blog/posts/BloodHound/</guid><pubDate>Wed, 09 Oct 2024 08:20:00 +0800</pubDate><category>notes</category><category>notes</category><category>bloodhound</category><category>active-directory</category><category>linux</category><category>windows</category><description>BloodHound: collect BloodHound data, read the AD graph, and prioritize attack paths.</description></item><item><title>HackTheBox GoodGames Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-GoodGames/</link><guid>https://x3ric.com/blog/posts/HackTheBox-GoodGames/</guid><pubDate>Sun, 06 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>docker</category><description>GoodGames: turn the exposed service into a shell, pivot through the container boundary, and escalate to root.</description></item><item><title>HackTheBox Valentine Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Valentine/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Valentine/</guid><pubDate>Sun, 06 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2014-0160</category><category>cve-2016-5195</category><description>Valentine: use CVE-2014-0160 and CVE-2016-5195 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Yummy Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Yummy/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Yummy/</guid><pubDate>Sun, 06 Oct 2024 00:15:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Yummy: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox EvilCUPS Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-EvilCUPS/</link><guid>https://x3ric.com/blog/posts/HackTheBox-EvilCUPS/</guid><pubDate>Thu, 03 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2024-47076</category><category>cve-2024-47175</category><category>cve-2024-47176</category><category>cve-2024-47177</category><description>EvilCUPS: use CVE-2024-47076 and CVE-2024-47175 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>TryHackMe Prioritise Writeup</title><link>https://x3ric.com/blog/posts/TryHackMe-Prioritise/</link><guid>https://x3ric.com/blog/posts/TryHackMe-Prioritise/</guid><pubDate>Thu, 03 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>thm</category><category>linux</category><description>Prioritise: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>TryHackMe Pyrat Writeup</title><link>https://x3ric.com/blog/posts/TryHackMe-Pyrat/</link><guid>https://x3ric.com/blog/posts/TryHackMe-Pyrat/</guid><pubDate>Thu, 03 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>thm</category><category>linux</category><description>Pyrat: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox Cicada Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Cicada/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Cicada/</guid><pubDate>Wed, 02 Oct 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>smb</category><category>ldap</category><description>Cicada: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Gobox Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Gobox/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Gobox/</guid><pubDate>Mon, 30 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Gobox: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>Chisel</title><link>https://x3ric.com/blog/posts/Chisel/</link><guid>https://x3ric.com/blog/posts/Chisel/</guid><pubDate>Sun, 29 Sep 2024 09:20:00 +0800</pubDate><category>notes</category><category>notes</category><category>ssh</category><category>nmap</category><category>linux</category><description>Chisel Forwarding: fix SSH configuration and permissions so remote access works predictably.</description></item><item><title>HackTheBox Bashed Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Bashed/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Bashed/</guid><pubDate>Fri, 27 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Bashed: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox Shocker Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Shocker/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Shocker/</guid><pubDate>Fri, 27 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2014-6271</category><description>Shocker: use CVE-2014-6271 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox TwoMillion Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-TwoMillion/</link><guid>https://x3ric.com/blog/posts/HackTheBox-TwoMillion/</guid><pubDate>Fri, 27 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2023-0386</category><description>TwoMillion: use CVE-2023-0386 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Soccer Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Soccer/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Soccer/</guid><pubDate>Wed, 25 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>cve-2021-45010</category><description>Soccer: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox GreenHorn Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-GreenHorn/</link><guid>https://x3ric.com/blog/posts/HackTheBox-GreenHorn/</guid><pubDate>Mon, 23 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2023-50564</category><description>GreenHorn: use CVE-2023-50564 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox BoardLight Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-BoardLight/</link><guid>https://x3ric.com/blog/posts/HackTheBox-BoardLight/</guid><pubDate>Sun, 22 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2022-37706</category><category>cve-2023-30253</category><description>BoardLight: use CVE-2022-37706 and CVE-2023-30253 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Editorial Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Editorial/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Editorial/</guid><pubDate>Sun, 22 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Editorial: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox PermX Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-PermX/</link><guid>https://x3ric.com/blog/posts/HackTheBox-PermX/</guid><pubDate>Sun, 22 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2023-4220</category><description>PermX: use CVE-2023-4220 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Headless Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Headless/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Headless/</guid><pubDate>Sat, 21 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Headless: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox Trickster Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Trickster/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Trickster/</guid><pubDate>Sat, 21 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2023-47268</category><category>cve-2024-32651</category><category>cve-2024-34716</category><description>Trickster: use CVE-2023-47268 and CVE-2024-32651 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Sea Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Sea/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Sea/</guid><pubDate>Mon, 16 Sep 2024 00:12:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2023-41425</category><description>Sea: use CVE-2023-41425 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Caption Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Caption/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Caption/</guid><pubDate>Mon, 16 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Caption: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox Bastion Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Bastion/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Bastion/</guid><pubDate>Fri, 13 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>smb</category><description>Bastion: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Curling Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Curling/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Curling/</guid><pubDate>Fri, 13 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>joomla</category><description>Curling: abuse the Joomla exposure for a shell, then use local enumeration to reach root.</description></item><item><title>HackTheBox Sightless Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Sightless/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Sightless/</guid><pubDate>Fri, 13 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>docker</category><category>cve-2022-0944</category><category>cve-2024-34070</category><description>Sightless: use CVE-2022-0944 and CVE-2024-34070 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Spooktrol Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Spooktroll/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Spooktroll/</guid><pubDate>Fri, 13 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>docker</category><description>Spooktrol: turn the exposed service into a shell, pivot through the container boundary, and escalate to root.</description></item><item><title>HackTheBox Writeup Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Writeup/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Writeup/</guid><pubDate>Fri, 13 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2022-41544</category><description>Writeup: use CVE-2022-41544 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>Nmap</title><link>https://x3ric.com/blog/posts/Nmap/</link><guid>https://x3ric.com/blog/posts/Nmap/</guid><pubDate>Thu, 12 Sep 2024 09:20:00 +0800</pubDate><category>notes</category><category>notes</category><category>nmap</category><category>linux</category><description>Nmap Scanning: run focused Nmap scans, capture service evidence, and keep enumeration reproducible.</description></item><item><title>HackTheBox Active Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Active/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Active/</guid><pubDate>Thu, 12 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>smb</category><category>ldap</category><description>Active: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Codify Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Codify/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Codify/</guid><pubDate>Thu, 12 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>kerberos</category><description>Codify: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Paper Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Paper/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Paper/</guid><pubDate>Thu, 12 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>wordpress</category><category>cve-2019-17671</category><category>cve-2021-3560</category><description>Paper: use CVE-2019-17671 and CVE-2021-3560 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Perfection Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Perfection/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Perfection/</guid><pubDate>Thu, 12 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Perfection: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>Bluetooth Linux Fix</title><link>https://x3ric.com/blog/posts/Bluetooth-Linux-Fix/</link><guid>https://x3ric.com/blog/posts/Bluetooth-Linux-Fix/</guid><pubDate>Sat, 13 Jul 2024 22:10:00 +0800</pubDate><category>notes</category><category>notes</category><category>bluetooth</category><category>linux</category><description>Bluetooth Linux Fix: reset the Linux Bluetooth stack, verify adapter state, and pair from a clean baseline.</description></item><item><title>TryHackMe DearQA Challenge</title><link>https://x3ric.com/blog/posts/TryHackMe-DearQA-Challenge/</link><guid>https://x3ric.com/blog/posts/TryHackMe-DearQA-Challenge/</guid><pubDate>Fri, 28 Jun 2024 01:20:00 +0800</pubDate><category>challenge</category><category>thm</category><category>pwn</category><category>bof</category><category>format-string</category><category>heap</category><category>shellcode</category><category>linux</category><description>DearQA: shape the heap state, gain the needed write or leak, and pivot to flag access.</description></item><item><title>TryHackMe Blog Writeup</title><link>https://x3ric.com/blog/posts/TryHackMe-Blog/</link><guid>https://x3ric.com/blog/posts/TryHackMe-Blog/</guid><pubDate>Thu, 13 Jun 2024 03:20:00 +0800</pubDate><category>machine</category><category>thm</category><category>windows</category><category>linux</category><category>wordpress</category><description>Blog: abuse the WordPress foothold, stabilize the shell, and escalate through the local weakness.</description></item><item><title>HackTheBox DevVortex Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-DevVortex/</link><guid>https://x3ric.com/blog/posts/HackTheBox-DevVortex/</guid><pubDate>Tue, 16 Apr 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>joomla</category><category>cve-2023-23752</category><description>DevVortex: use CVE-2023-23752 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>SSH</title><link>https://x3ric.com/blog/posts/Ssh/</link><guid>https://x3ric.com/blog/posts/Ssh/</guid><pubDate>Fri, 12 Apr 2024 00:10:00 +0800</pubDate><category>notes</category><category>notes</category><category>ssh</category><category>linux</category><description>Compact OpenSSH reference for key authentication, client and server config, tunneling, X11 forwarding, and public-key troubleshooting.</description></item></channel></rss>