<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Writeups :: X3ric Blog</title><link>https://x3ric.com/blog/writeups/</link><description>Challenge and machine writeups.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 06 Jun 2026 21:41:13 +0200</lastBuildDate><atom:link href="https://x3ric.com/blog/writeups/index.xml" rel="self" type="application/rss+xml"/><item><title>HackTheBox Agriweb Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Agriweb-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Agriweb-Challenge/</guid><pubDate>Sat, 06 Jun 2026 00:00:00 +0200</pubDate><category>challenge</category><category>htb</category><category>code</category><category>nodejs</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox CommNet Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-CommNet-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-CommNet-Challenge/</guid><pubDate>Sat, 06 Jun 2026 00:00:00 +0200</pubDate><category>challenge</category><category>htb</category><category>code</category><category>nodejs</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Cred Hunter Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Cred-Hunter-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Cred-Hunter-Challenge/</guid><pubDate>Sat, 06 Jun 2026 00:00:00 +0200</pubDate><category>challenge</category><category>htb</category><category>code</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Flagportation Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Flagportation-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Flagportation-Challenge/</guid><pubDate>Sat, 06 Jun 2026 00:00:00 +0200</pubDate><category>challenge</category><category>htb</category><category>crypto</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox FlappyFlopper Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-FlappyFlopper-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-FlappyFlopper-Challenge/</guid><pubDate>Sat, 06 Jun 2026 00:00:00 +0200</pubDate><category>challenge</category><category>htb</category><category>gamepwn</category><category>unity</category><category>unity-mono</category><category>unity-il2cpp</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Hexecution Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Hexecution-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Hexecution-Challenge/</guid><pubDate>Sat, 06 Jun 2026 00:00:00 +0200</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>angr</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Hydroadmin Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Hydroadmin-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Hydroadmin-Challenge/</guid><pubDate>Sat, 06 Jun 2026 00:00:00 +0200</pubDate><category>challenge</category><category>htb</category><category>code</category><category>nodejs</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Jigsaw Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Jigsaw-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Jigsaw-Challenge/</guid><pubDate>Sat, 06 Jun 2026 00:00:00 +0200</pubDate><category>challenge</category><category>htb</category><category>mobile</category><category>android</category><category>frida</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Not Posixtive Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Not-Posixtive-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Not-Posixtive-Challenge/</guid><pubDate>Sat, 06 Jun 2026 00:00:00 +0200</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Phoenix Pipeline Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Phoenix-Pipeline-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Phoenix-Pipeline-Challenge/</guid><pubDate>Sat, 06 Jun 2026 00:00:00 +0200</pubDate><category>challenge</category><category>htb</category><category>code</category><category>php</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox PINsmith Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-PINsmith-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-PINsmith-Challenge/</guid><pubDate>Sat, 06 Jun 2026 00:00:00 +0200</pubDate><category>challenge</category><category>htb</category><category>code</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Pivot Chain Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Pivot-Chain-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Pivot-Chain-Challenge/</guid><pubDate>Sat, 06 Jun 2026 00:00:00 +0200</pubDate><category>challenge</category><category>htb</category><category>code</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Powergrid Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Powergrid-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Powergrid-Challenge/</guid><pubDate>Sat, 06 Jun 2026 00:00:00 +0200</pubDate><category>challenge</category><category>htb</category><category>code</category><category>nodejs</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Resourcehub Core Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Resourcehub-Core-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Resourcehub-Core-Challenge/</guid><pubDate>Sat, 06 Jun 2026 00:00:00 +0200</pubDate><category>challenge</category><category>htb</category><category>code</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Social Media Investigation Hub Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Social-Media-Investigation-Hub-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Social-Media-Investigation-Hub-Challenge/</guid><pubDate>Sat, 06 Jun 2026 00:00:00 +0200</pubDate><category>challenge</category><category>htb</category><category>osint</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox The Suspicious Domain Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-The-Suspicious-Domain-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-The-Suspicious-Domain-Challenge/</guid><pubDate>Sat, 06 Jun 2026 00:00:00 +0200</pubDate><category>challenge</category><category>htb</category><category>osint</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox The Suspicious Reviewer Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-The-Suspicious-Reviewer-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-The-Suspicious-Reviewer-Challenge/</guid><pubDate>Sat, 06 Jun 2026 00:00:00 +0200</pubDate><category>challenge</category><category>htb</category><category>osint</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox TicTacToed Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-TicTacToed-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-TicTacToed-Challenge/</guid><pubDate>Sat, 06 Jun 2026 00:00:00 +0200</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>bof</category><category>format-string</category><category>heap</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox CachedWeb Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-CachedWeb-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-CachedWeb-Challenge/</guid><pubDate>Tue, 23 Sep 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>ssrf</category><category>path-traversal</category><category>file-upload</category><category>rce</category><category>flask</category><description>CachedWeb: chain SSRF with path control to reach the internal target and read the flag.</description></item><item><title>HackTheBox LicenseGenerator</title><link>https://x3ric.com/blog/posts/HackTheBox-LicenseGenerator/</link><guid>https://x3ric.com/blog/posts/HackTheBox-LicenseGenerator/</guid><pubDate>Fri, 27 Jun 2025 01:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>xor</category><category>linux</category><description>LicenseGenerator: recover the XOR transform from the binary and invert it to reveal the flag.</description></item><item><title>HackTheBox SatelliteHijack</title><link>https://x3ric.com/blog/posts/HackTheBox-SatelliteHijack/</link><guid>https://x3ric.com/blog/posts/HackTheBox-SatelliteHijack/</guid><pubDate>Fri, 27 Jun 2025 01:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>gdb</category><category>xor</category><category>linux</category><description>SatelliteHijack: trace the binary, isolate the validation routine, and invert it to recover the flag.</description></item><item><title>HackTheBox 400Curves Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-400Curves-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-400Curves-Challenge/</guid><pubDate>Mon, 05 May 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>rsa</category><category>lattice</category><category>ecc</category><description>400Curves: turn the RSA leak into a lattice recovery, rebuild the secret values, and decrypt the flag.</description></item><item><title>HackTheBox A Nightmare On Math Street Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-A-Nightmare-On-Math-Street-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-A-Nightmare-On-Math-Street-Challenge/</guid><pubDate>Mon, 05 May 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>A Nightmare On Math Street: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox Defusal Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Defusal-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Defusal-Challenge/</guid><pubDate>Mon, 05 May 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>signal</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Dark Runes Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Dark-Runes-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Dark-Runes-Challenge/</guid><pubDate>Sun, 02 Mar 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>cve-2023-0835</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Amidst Us Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Amidst-Us-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Amidst-Us-Challenge/</guid><pubDate>Fri, 28 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>rce</category><description>Amidst Us: find the command execution path, trigger it cleanly, and read the flag.</description></item><item><title>HackTheBox baby sql Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-baby-sql-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-baby-sql-Challenge/</guid><pubDate>Fri, 28 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>sql-injection</category><description>baby sql: exploit the SQL injection, extract the needed data, and reach the flag.</description></item><item><title>HackTheBox Letter Dispair Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Letter-Dispair-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Letter-Dispair-Challenge/</guid><pubDate>Fri, 28 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>rce</category><category>php</category><category>cve-2016-10045</category><description>Letter Dispair: find the command execution path, trigger it cleanly, and read the flag.</description></item><item><title>HackTheBox M0rsarchive Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-M0rsarchive-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-M0rsarchive-Challenge/</guid><pubDate>Fri, 28 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>M0rsarchive: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox Money Flowz Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Money-Flowz-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Money-Flowz-Challenge/</guid><pubDate>Fri, 28 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>osint</category><category>blockchain</category><description>Money Flowz: correlate the public clues, pivot through the evidence, and identify the final answer.</description></item><item><title>HackTheBox OnlyHacks Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-OnlyHacks-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-OnlyHacks-Challenge/</guid><pubDate>Fri, 28 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>xss</category><description>OnlyHacks: use the client-side injection path to steal the needed proof and recover the flag.</description></item><item><title>HackTheBox 0ld is g0ld Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-0ld-is-g0ld-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-0ld-is-g0ld-Challenge/</guid><pubDate>Sun, 16 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>0ld is g0ld: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox BinCrypt Breaker Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-BinCrypt-Breaker-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-BinCrypt-Breaker-Challenge/</guid><pubDate>Sun, 16 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>xor</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Console Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Console-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Console-Challenge/</guid><pubDate>Sun, 16 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>php</category><description>Console: abuse php to cross the web trust boundary and recover the flag.</description></item><item><title>HackTheBox Curse Breaker Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Curse-Breaker-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Curse-Breaker-Challenge/</guid><pubDate>Sun, 16 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Curse Breaker: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Down the Rabinhole Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Down-the-Rabinhole-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Down-the-Rabinhole-Challenge/</guid><pubDate>Sun, 16 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>rsa</category><description>Down the Rabinhole: exploit the RSA structure, recover the missing secret, and decrypt the flag.</description></item><item><title>HackTheBox secure source Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-secure-source-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-secure-source-Challenge/</guid><pubDate>Sun, 16 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>prng</category><category>lattice</category><category>ecc</category><category>hash</category><description>secure source: reconstruct the PRNG state from the leak, replay it, and recover the flag.</description></item><item><title>HackTheBox signup Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-signup-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-signup-Challenge/</guid><pubDate>Sun, 16 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>hash</category><description>signup: reduce the hash constraint to a small search, test candidates, and recover the flag.</description></item><item><title>HackTheBox Spooky RSA Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Spooky-RSA-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Spooky-RSA-Challenge/</guid><pubDate>Sun, 16 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>rsa</category><description>Spooky RSA: exploit the RSA structure, recover the missing secret, and decrypt the flag.</description></item><item><title>HackTheBox The secret of a Queen Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-The-secret-of-a-Queen-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-The-secret-of-a-Queen-Challenge/</guid><pubDate>Sun, 16 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>The secret of a Queen: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox TurboCipher Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-TurboCipher-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-TurboCipher-Challenge/</guid><pubDate>Sun, 16 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><description>TurboCipher: model the crypto leak, recover the missing secret, and decrypt the flag.</description></item><item><title>HackTheBox BitsNBytes Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-BitsNBytes-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-BitsNBytes-Challenge/</guid><pubDate>Fri, 14 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>BitsNBytes: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox Branching Tactics Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Branching-Tactics-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Branching-Tactics-Challenge/</guid><pubDate>Fri, 14 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Branching Tactics: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox fs0ciety Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-fs0ciety-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-fs0ciety-Challenge/</guid><pubDate>Fri, 14 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>fs0ciety: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox Hackerman Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Hackerman-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Hackerman-Challenge/</guid><pubDate>Fri, 14 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Hackerman: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox Hidden Path Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Hidden-Path-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Hidden-Path-Challenge/</guid><pubDate>Fri, 14 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Hidden Path: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox Insane Bolt Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Insane-Bolt-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Insane-Bolt-Challenge/</guid><pubDate>Fri, 14 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Insane Bolt: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox Path of Survival Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Path-of-Survival-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Path-of-Survival-Challenge/</guid><pubDate>Fri, 14 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Path of Survival: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox QuickR Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-QuickR-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-QuickR-Challenge/</guid><pubDate>Fri, 14 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>QuickR: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox Type Exception Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Type-Exception-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Type-Exception-Challenge/</guid><pubDate>Fri, 14 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Type Exception: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox alphascii clashing Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-alphascii-clashing-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-alphascii-clashing-Challenge/</guid><pubDate>Thu, 13 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>hash</category><description>alphascii clashing: reduce the hash constraint to a small search, test candidates, and recover the flag.</description></item><item><title>HackTheBox APKrypt Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-APKrypt-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-APKrypt-Challenge/</guid><pubDate>Thu, 13 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>mobile</category><category>android</category><description>APKrypt: inspect the Android app, trace the validation path, and recover the flag.</description></item><item><title>HackTheBox Don't Overreact Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Dont-Overreact-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Dont-Overreact-Challenge/</guid><pubDate>Thu, 13 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>mobile</category><category>android</category><description>Don't Overreact: inspect the Android app, trace the validation path, and recover the flag.</description></item><item><title>HackTheBox Manager Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Manager-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Manager-Challenge/</guid><pubDate>Thu, 13 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>mobile</category><category>android</category><description>Manager: inspect the Android app, trace the validation path, and recover the flag.</description></item><item><title>HackTheBox Pinned Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Pinned-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Pinned-Challenge/</guid><pubDate>Thu, 13 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>mobile</category><category>android</category><category>frida</category><description>Pinned: hook the mobile app with Frida, bypass the check, and recover the flag.</description></item><item><title>HackTheBox Supermarket Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Supermarket-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Supermarket-Challenge/</guid><pubDate>Thu, 13 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>mobile</category><category>android</category><category>frida</category><description>Supermarket: hook the mobile app with Frida, bypass the check, and recover the flag.</description></item><item><title>HackTheBox Maze Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Maze-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Maze-Challenge/</guid><pubDate>Tue, 04 Feb 2025 17:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>dotnet</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Partial Encryption Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Partial-Encryption-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Partial-Encryption-Challenge/</guid><pubDate>Tue, 04 Feb 2025 17:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Canvas Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Canvas-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Canvas-Challenge/</guid><pubDate>Tue, 04 Feb 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Canvas: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox Lazy Ballot Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Lazy-Ballot-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Lazy-Ballot-Challenge/</guid><pubDate>Tue, 04 Feb 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Lazy Ballot: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox Digital-Safety-Annex Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Digital-Safety-Annex-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Digital-Safety-Annex-Challenge/</guid><pubDate>Tue, 04 Feb 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>ecc</category><category>hash</category><description>Digital-Safety-Annex: use the curve leak or invalid-curve path to recover the secret and decrypt the flag.</description></item><item><title>HackTheBox Interception Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Interception-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Interception-Challenge/</guid><pubDate>Fri, 31 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>lattice</category><category>hash</category><description>Interception: model the leak as a small lattice problem, recover the secret, and verify the flag.</description></item><item><title>HackTheBox Multipage Recyclings Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Multipage-Recyclings-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Multipage-Recyclings-Challenge/</guid><pubDate>Fri, 31 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>aes</category><description>Multipage Recyclings: abuse the AES misuse, derive the missing key material, and decrypt the flag.</description></item><item><title>HackTheBox Not that random Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Not-that-random-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Not-that-random-Challenge/</guid><pubDate>Fri, 31 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>prng</category><category>hash</category><description>Not that random: reconstruct the PRNG state from the leak, replay it, and recover the flag.</description></item><item><title>HackTheBox Nuclear Sale Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Nuclear-Sale-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Nuclear-Sale-Challenge/</guid><pubDate>Fri, 31 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><description>Nuclear Sale: model the crypto leak, recover the missing secret, and decrypt the flag.</description></item><item><title>HackTheBox One Step Closer Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-One-Step-Closer-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-One-Step-Closer-Challenge/</guid><pubDate>Fri, 31 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>rsa</category><description>One Step Closer: exploit the RSA structure, recover the missing secret, and decrypt the flag.</description></item><item><title>HackTheBox Partial Tenacity Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Partial-Tenacity-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Partial-Tenacity-Challenge/</guid><pubDate>Fri, 31 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>rsa</category><description>Partial Tenacity: exploit the RSA structure, recover the missing secret, and decrypt the flag.</description></item><item><title>HackTheBox pcalc Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-pcalc-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-pcalc-Challenge/</guid><pubDate>Fri, 31 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><description>pcalc: identify the broken request handling, prove control, and use it to recover the flag.</description></item><item><title>HackTheBox Permuted Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Permuted-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Permuted-Challenge/</guid><pubDate>Fri, 31 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>rsa</category><category>aes</category><category>hash</category><description>Permuted: exploit the RSA structure, recover the missing secret, and decrypt the flag.</description></item><item><title>HackTheBox RLotto Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-RLotto-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-RLotto-Challenge/</guid><pubDate>Fri, 31 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>prng</category><description>RLotto: reconstruct the PRNG state from the leak, replay it, and recover the flag.</description></item><item><title>HackTheBox sanitize Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-sanitize-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-sanitize-Challenge/</guid><pubDate>Fri, 31 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>sql-injection</category><description>sanitize: exploit the SQL injection, extract the needed data, and reach the flag.</description></item><item><title>HackTheBox Weak RSA Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Weak-RSA-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Weak-RSA-Challenge/</guid><pubDate>Fri, 31 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>rsa</category><description>Weak RSA: exploit the RSA structure, recover the missing secret, and decrypt the flag.</description></item><item><title>HackTheBox Whole Lotta Candy Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Whole-Lotta-Candy-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Whole-Lotta-Candy-Challenge/</guid><pubDate>Fri, 31 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>aes</category><category>xor</category><description>Whole Lotta Candy: abuse the AES misuse, derive the missing key material, and decrypt the flag.</description></item><item><title>HackTheBox Behind the Scenes Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Behind-the-Scenes-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Behind-the-Scenes-Challenge/</guid><pubDate>Thu, 30 Jan 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>gdb</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Cyberpsychosis Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Cyberpsychosis-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Cyberpsychosis-Challenge/</guid><pubDate>Thu, 30 Jan 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox ReRop Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-ReRop-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-ReRop-Challenge/</guid><pubDate>Thu, 30 Jan 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>xor</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Coffee Invocation Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Coffee-Invocation-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Coffee-Invocation-Challenge/</guid><pubDate>Wed, 29 Jan 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Factory Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Factory-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Factory-Challenge/</guid><pubDate>Wed, 29 Jan 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>signal</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Line Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Line-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Line-Challenge/</guid><pubDate>Wed, 29 Jan 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>signal</category><category>cve-2014-6271</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Photon-Lockdown Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Photon-Lockdown-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Photon-Lockdown-Challenge/</guid><pubDate>Wed, 29 Jan 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>signal</category><description>Photon-Lockdown: decode the captured signal, map the bitstream, and recover the flag.</description></item><item><title>HackTheBox Sudoking Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Sudoking-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Sudoking-Challenge/</guid><pubDate>Wed, 29 Jan 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Backfire Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Backfire/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Backfire/</guid><pubDate>Mon, 27 Jan 2025 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>cve-2024-41570</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox EscapeTwo Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-EscapeTwo/</link><guid>https://x3ric.com/blog/posts/HackTheBox-EscapeTwo/</guid><pubDate>Mon, 27 Jan 2025 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>smb</category><category>ldap</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox NoMap3D Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-NoMap3D-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-NoMap3D-Challenge/</guid><pubDate>Mon, 27 Jan 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>gamepwn</category><category>sdl</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox NoRadar Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-NoRadar-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-NoRadar-Challenge/</guid><pubDate>Mon, 27 Jan 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>gamepwn</category><category>sdl</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Bare Metal Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Bare-Metal-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Bare-Metal-Challenge/</guid><pubDate>Fri, 24 Jan 2025 00:23:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>signal</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Project Power Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Project-Power-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Project-Power-Challenge/</guid><pubDate>Fri, 24 Jan 2025 00:21:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>signal</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Bounty Head Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Bounty-Head-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Bounty-Head-Challenge/</guid><pubDate>Fri, 24 Jan 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>signal</category><category>cve-2017-7650</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Debugging Interface Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Debugging-Interface-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Debugging-Interface-Challenge/</guid><pubDate>Fri, 24 Jan 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>logic-analyzer</category><category>signal</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Interstellar Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Interstellar-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Interstellar-Challenge/</guid><pubDate>Fri, 24 Jan 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>sql-injection</category><category>ssrf</category><category>rce</category><category>php</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Mission Pinpossible Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Mission-Pinpossible-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Mission-Pinpossible-Challenge/</guid><pubDate>Fri, 24 Jan 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>i2c</category><category>logic-analyzer</category><category>signal</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox RFlag Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-RFlag-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-RFlag-Challenge/</guid><pubDate>Fri, 24 Jan 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>signal</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Anti Flag Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Anti-Flag-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Anti-Flag-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Anti Flag: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Art Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Art-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Art-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Art: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox Baby Crypt Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Baby-Crypt-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Baby-Crypt-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>xor</category><category>linux</category><description>Baby Crypt: recover the XOR transform from the binary and invert it to reveal the flag.</description></item><item><title>HackTheBox Baby RE Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Baby-RE-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Baby-RE-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>elf</category><category>linux</category><description>Baby RE: trace the binary, isolate the validation routine, and invert it to recover the flag.</description></item><item><title>HackTheBox Eat the Cake! Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Eat-the-Cake-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Eat-the-Cake-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Eat the Cake: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Encryption Bot Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Encryption-Bot-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Encryption-Bot-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Encryption Bot: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Impossible Password Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Impossible-Password-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Impossible-Password-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>xor</category><category>linux</category><description>Impossible Password: recover the XOR transform from the binary and invert it to reveal the flag.</description></item><item><title>HackTheBox Inside the Matrix Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Inside-the-Matrix-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Inside-the-Matrix-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>rsa</category><category>lattice</category><description>Inside the Matrix: turn the RSA leak into a lattice recovery, rebuild the secret values, and decrypt the flag.</description></item><item><title>HackTheBox IRCWare Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-IRCWare-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-IRCWare-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>IRCWare: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Jenny From The Block Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Jenny-From-The-Block-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Jenny-From-The-Block-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>hash</category><description>Jenny From The Block: reduce the hash constraint to a small search, test candidates, and recover the flag.</description></item><item><title>HackTheBox Living with Elegance Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Living-with-Elegance-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Living-with-Elegance-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><description>Living with Elegance: model the crypto leak, recover the missing secret, and decrypt the flag.</description></item><item><title>HackTheBox Lost Modulus Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Lost-Modulus-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Lost-Modulus-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>rsa</category><description>Lost Modulus: exploit the RSA structure, recover the missing secret, and decrypt the flag.</description></item><item><title>HackTheBox LunaCrypt Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-LunaCrypt-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-LunaCrypt-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>xor</category><description>LunaCrypt: derive the XOR key stream, invert the transform, and recover the flag.</description></item><item><title>HackTheBox Mayday Mayday Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Mayday-Mayday-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Mayday-Mayday-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>lattice</category><description>Mayday Mayday: model the leak as a small lattice problem, recover the secret, and verify the flag.</description></item><item><title>HackTheBox Metagaming Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Metagaming-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Metagaming-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Metagaming: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox MSS Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-MSS-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-MSS-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>rsa</category><category>aes</category><category>hash</category><description>MSS: exploit the RSA structure, recover the missing secret, and decrypt the flag.</description></item><item><title>HackTheBox Ouija Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Ouija-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Ouija-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Ouija: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Ransom Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Ransom-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Ransom-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Ransom: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Rebuilding Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Rebuilding-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Rebuilding-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Rebuilding: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox Secured Transfer Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Secured-Transfer-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Secured-Transfer-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Secured Transfer: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Sekure Decrypt Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Sekure-Decrypt-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Sekure-Decrypt-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Sekure Decrypt: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Shuffleme Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Shuffleme-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Shuffleme-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>elf</category><category>linux</category><description>Shuffleme: trace the binary, isolate the validation routine, and invert it to recover the flag.</description></item><item><title>HackTheBox Snakecode Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Snakecode-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Snakecode-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Snakecode: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Tear Or Dear Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Tear-Or-Dear-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Tear-Or-Dear-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>dotnet</category><category>linux</category><description>Tear Or Dear: decompile the .NET logic, rebuild the check, and recover the accepted input.</description></item><item><title>HackTheBox The Art of Reversing Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-The-Art-of-Reversing-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-The-Art-of-Reversing-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>dotnet</category><category>linux</category><description>The Art of Reversing: decompile the .NET logic, rebuild the check, and recover the accepted input.</description></item><item><title>HackTheBox You Cant C Me Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-You-Cant-C-Me-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-You-Cant-C-Me-Challenge/</guid><pubDate>Thu, 23 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>You Cant C Me: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox AHS512 Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-AHS512-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-AHS512-Challenge/</guid><pubDate>Wed, 22 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>prng</category><category>hash</category><description>AHS512: reconstruct the PRNG state from the leak, replay it, and recover the flag.</description></item><item><title>HackTheBox Arranged Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Arranged-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Arranged-Challenge/</guid><pubDate>Wed, 22 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>aes</category><category>lattice</category><category>ecc</category><category>hash</category><description>Arranged: abuse the AES misuse, derive the missing key material, and decrypt the flag.</description></item><item><title>HackTheBox baby quick maffs Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-baby-quick-maffs-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-baby-quick-maffs-Challenge/</guid><pubDate>Wed, 22 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><description>baby quick maffs: model the crypto leak, recover the missing secret, and decrypt the flag.</description></item><item><title>HackTheBox Bank-er-smith Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Bank-er-smith-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Bank-er-smith-Challenge/</guid><pubDate>Wed, 22 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>rsa</category><category>hash</category><description>Bank-er-smith: exploit the RSA structure, recover the missing secret, and decrypt the flag.</description></item><item><title>HackTheBox Battle in OrlOn Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Battle-in-OrlOn-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Battle-in-OrlOn-Challenge/</guid><pubDate>Wed, 22 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>ai</category><category>pytorch</category><category>prompt-injection</category><category>neural-network</category><description>Battle in OrlOn: shape the prompt path, bypass the model guard, and recover the target output.</description></item><item><title>HackTheBox BBGun06 Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-BBGun06-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-BBGun06-Challenge/</guid><pubDate>Wed, 22 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>rsa</category><description>BBGun06: exploit the RSA structure, recover the missing secret, and decrypt the flag.</description></item><item><title>HackTheBox Bloom Bloom Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Bloom-Bloom-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Bloom-Bloom-Challenge/</guid><pubDate>Wed, 22 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>aes</category><category>lattice</category><category>hash</category><description>Bloom Bloom: abuse the AES misuse, derive the missing key material, and decrypt the flag.</description></item><item><title>HackTheBox Brainy's Chyper Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Brainys-Chyper-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Brainys-Chyper-Challenge/</guid><pubDate>Wed, 22 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>rsa</category><description>Brainy's Chyper: exploit the RSA structure, recover the missing secret, and decrypt the flag.</description></item><item><title>HackTheBox Classic, yet complicated! Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Classic-yet-complicated-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Classic-yet-complicated-Challenge/</guid><pubDate>Wed, 22 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>vigenere</category><description>Classic, yet complicated: recover the Vigenere key from the ciphertext, decrypt the message, and verify the flag.</description></item><item><title>HackTheBox Death's Glance Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Deaths-Glance-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Deaths-Glance-Challenge/</guid><pubDate>Wed, 22 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>ai</category><category>pytorch</category><category>prompt-injection</category><category>neural-network</category><description>Death's Glance: shape the prompt path, bypass the model guard, and recover the target output.</description></item><item><title>HackTheBox ElElGamal Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-ElElGamal-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-ElElGamal-Challenge/</guid><pubDate>Wed, 22 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>ecc</category><description>ElElGamal: use the curve leak or invalid-curve path to recover the secret and decrypt the flag.</description></item><item><title>HackTheBox Fast Carmichael Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Fast-Carmichael-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Fast-Carmichael-Challenge/</guid><pubDate>Wed, 22 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>ecc</category><description>Fast Carmichael: use the curve leak or invalid-curve path to recover the secret and decrypt the flag.</description></item><item><title>HackTheBox How The Columns Have Turned Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-How-The-Columns-Have-Turned-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-How-The-Columns-Have-Turned-Challenge/</guid><pubDate>Wed, 22 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><description>How The Columns Have Turned: model the crypto leak, recover the missing secret, and decrypt the flag.</description></item><item><title>HackTheBox I know Mag1k Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-I-know-Mag1k-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-I-know-Mag1k-Challenge/</guid><pubDate>Wed, 22 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>xor</category><description>I know Mag1k: derive the XOR key stream, invert the transform, and recover the flag.</description></item><item><title>HackTheBox I'm gRoot Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Im-gRoot-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Im-gRoot-Challenge/</guid><pubDate>Wed, 22 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>hash</category><description>I'm gRoot: reduce the hash constraint to a small search, test candidates, and recover the flag.</description></item><item><title>HackTheBox Iced Tea Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Iced-Tea-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Iced-Tea-Challenge/</guid><pubDate>Wed, 22 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>aes</category><category>ecc</category><description>Iced Tea: abuse the AES misuse, derive the missing key material, and decrypt the flag.</description></item><item><title>HackTheBox Sigma Technology Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Sigma-Technology-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Sigma-Technology-Challenge/</guid><pubDate>Wed, 22 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>ai</category><category>prompt-injection</category><category>neural-network</category><description>Sigma Technology: shape the prompt path, bypass the model guard, and recover the target output.</description></item><item><title>HackTheBox Under Construction Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Under-Construction-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Under-Construction-Challenge/</guid><pubDate>Wed, 22 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>sql-injection</category><category>jwt</category><description>Under Construction: exploit the SQL injection, extract the needed data, and reach the flag.</description></item><item><title>HackTheBox CDNio Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-CDNio-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-CDNio-Challenge/</guid><pubDate>Sat, 11 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Jailbreak Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Jailbreak-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Jailbreak-Challenge/</guid><pubDate>Sat, 11 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><description>Jailbreak: identify the broken request handling, prove control, and use it to recover the flag.</description></item><item><title>HackTheBox Under the web Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Under-the-web-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Under-the-web-Challenge/</guid><pubDate>Sat, 11 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Rauth Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Rauth-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Rauth-Challenge/</guid><pubDate>Thu, 09 Jan 2025 12:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Noisy Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Noisy-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Noisy-Challenge/</guid><pubDate>Wed, 08 Jan 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Triangles Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Triangles-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Triangles-Challenge/</guid><pubDate>Wed, 08 Jan 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Urgent Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Urgent-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Urgent-Challenge/</guid><pubDate>Wed, 08 Jan 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>forensics</category><category>git</category><description>Urgent: isolate the relevant artifact, decode the evidence, and extract the flag.</description></item><item><title>HackTheBox Alien Cradle Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Alien-Cradle-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Alien-Cradle-Challenge/</guid><pubDate>Tue, 07 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>forensics</category><category>powershell</category><description>Alien Cradle: isolate the relevant artifact, decode the evidence, and extract the flag.</description></item><item><title>HackTheBox Android-in-the-Middle Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Android-in-the-Middle-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Android-in-the-Middle-Challenge/</guid><pubDate>Tue, 07 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>aes</category><category>hash</category><description>Android-in-the-Middle: abuse the AES misuse, derive the missing key material, and decrypt the flag.</description></item><item><title>HackTheBox Full of Stars Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Full-of-Stars-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Full-of-Stars-Challenge/</guid><pubDate>Tue, 07 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>ai</category><category>prompt-injection</category><category>neural-network</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Like a Glove Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Like-a-Glove-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Like-a-Glove-Challenge/</guid><pubDate>Tue, 07 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>ai</category><category>embeddings</category><category>prompt-injection</category><category>neural-network</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Lost in Hyperspace Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Lost-in-Hyperspace-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Lost-in-Hyperspace-Challenge/</guid><pubDate>Tue, 07 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>ai</category><category>sklearn</category><category>embeddings</category><category>prompt-injection</category><category>neural-network</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Man In The Middle Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Man-In-The-Middle-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Man-In-The-Middle-Challenge/</guid><pubDate>Tue, 07 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Man In The Middle: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox Micro Storage Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Micro-Storage-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Micro-Storage-Challenge/</guid><pubDate>Tue, 07 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Prometheon Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Prometheon-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Prometheon-Challenge/</guid><pubDate>Tue, 07 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>ai</category><category>prompt-injection</category><category>neural-network</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Red Miners Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Red-Miners-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Red-Miners-Challenge/</guid><pubDate>Tue, 07 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>forensics</category><description>Red Miners: isolate the relevant artifact, decode the evidence, and extract the flag.</description></item><item><title>HackTheBox Secure Server Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Secure-Server-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Secure-Server-Challenge/</guid><pubDate>Tue, 07 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Spin Glass Brain Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Spin-Glass-Brain-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Spin-Glass-Brain-Challenge/</guid><pubDate>Tue, 07 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>ai</category><category>prompt-injection</category><category>neural-network</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Deterministic Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Deterministic-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Deterministic-Challenge/</guid><pubDate>Tue, 07 Jan 2025 00:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Rega's Town Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Regas-Town-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Regas-Town-Challenge/</guid><pubDate>Mon, 06 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox NoClip Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-NoClip-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-NoClip-Challenge/</guid><pubDate>Fri, 03 Jan 2025 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>gamepwn</category><category>memory</category><category>sdl</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Mini Line Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Mini-Line-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Mini-Line-Challenge/</guid><pubDate>Tue, 31 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>signal</category><description>Mini Line: decode the captured signal, map the bitstream, and recover the flag.</description></item><item><title>HackTheBox Out of Time Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Out-of-Time-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Out-of-Time-Challenge/</guid><pubDate>Tue, 31 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>signal</category><description>Out of Time: decode the captured signal, map the bitstream, and recover the flag.</description></item><item><title>HackTheBox Space Heist Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Space-Heist-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Space-Heist-Challenge/</guid><pubDate>Tue, 31 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>signal</category><description>Space Heist: decode the captured signal, map the bitstream, and recover the flag.</description></item><item><title>HackTheBox Exatlon Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Exatlon-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Exatlon-Challenge/</guid><pubDate>Sat, 28 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox UnderPass Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-UnderPass/</link><guid>https://x3ric.com/blog/posts/HackTheBox-UnderPass/</guid><pubDate>Sat, 28 Dec 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>docker</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox APKey Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-APKey-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-APKey-Challenge/</guid><pubDate>Sat, 21 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>mobile</category><category>android</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Bashic Calculator Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Bashic-Calculator-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Bashic-Calculator-Challenge/</guid><pubDate>Sat, 21 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Cat Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Cat-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Cat-Challenge/</guid><pubDate>Sat, 21 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>mobile</category><category>android</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Cryptohorrific Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Cryptohorrific-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Cryptohorrific-Challenge/</guid><pubDate>Sat, 21 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>mobile</category><category>android</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Investigator Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Investigator-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Investigator-Challenge/</guid><pubDate>Sat, 21 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>mobile</category><category>android</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Nostalgia Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Nostalgia-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Nostalgia-Challenge/</guid><pubDate>Sat, 21 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>gamepwn</category><category>gdb</category><category>gba</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox SAW Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-SAW-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-SAW-Challenge/</guid><pubDate>Sat, 21 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>mobile</category><category>android</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Spooky License Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Spooky-License-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Spooky-License-Challenge/</guid><pubDate>Sat, 21 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Spooky License: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox CubeMadness1 Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-CubeMadness1-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-CubeMadness1-Challenge/</guid><pubDate>Fri, 20 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>gamepwn</category><category>unity</category><category>memory</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox CubeMadness2 Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-CubeMadness2-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-CubeMadness2-Challenge/</guid><pubDate>Fri, 20 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>gamepwn</category><category>unity</category><category>unity-il2cpp</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox FastJson and Furious Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-FastJson-and-Furious-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-FastJson-and-Furious-Challenge/</guid><pubDate>Fri, 20 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>mobile</category><category>android</category><description>FastJson and Furious: inspect the Android app, trace the validation path, and recover the flag.</description></item><item><title>HackTheBox InfiniteDoge Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-InfiniteDoge-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-InfiniteDoge-Challenge/</guid><pubDate>Fri, 20 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>gamepwn</category><category>unity</category><category>unity-mono</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox LightningFast Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-LightningFast-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-LightningFast-Challenge/</guid><pubDate>Fri, 20 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>gamepwn</category><category>unity</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Signals Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Signals-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Signals-Challenge/</guid><pubDate>Fri, 20 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>signal</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox StayInTheBoxCorp Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-StayInTheBoxCorp-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-StayInTheBoxCorp-Challenge/</guid><pubDate>Fri, 20 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>gamepwn</category><category>unity</category><category>unity-il2cpp</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox The Needle Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-The-Needle-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-The-Needle-Challenge/</guid><pubDate>Fri, 20 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>signal</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Trace Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Trace-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Trace-Challenge/</guid><pubDate>Fri, 20 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>signal</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Wander Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Wander-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Wander-Challenge/</guid><pubDate>Fri, 20 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>signal</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox CubeBreaker Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-CubeBreaker-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-CubeBreaker-Challenge/</guid><pubDate>Thu, 19 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>gamepwn</category><category>unity</category><category>unity-mono</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox ChromeMiner Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-ChromeMiner-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-ChromeMiner-Challenge/</guid><pubDate>Wed, 18 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>ChromeMiner: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Sneak peek Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Sneak-peek-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Sneak-peek-Challenge/</guid><pubDate>Wed, 18 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>signal</category><description>Sneak peek: decode the captured signal, map the bitstream, and recover the flag.</description></item><item><title>HackTheBox Compressor Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Compressor-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Compressor-Challenge/</guid><pubDate>Tue, 17 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Compressor: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox Cubicle Riddle Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Cubicle-Riddle-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Cubicle-Riddle-Challenge/</guid><pubDate>Tue, 17 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Cubicle Riddle: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox Gawk Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Gawk-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Gawk-Challenge/</guid><pubDate>Tue, 17 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>signal</category><description>Gawk: decode the captured signal, map the bitstream, and recover the flag.</description></item><item><title>HackTheBox Locked Away Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Locked-Away-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Locked-Away-Challenge/</guid><pubDate>Tue, 17 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Locked Away: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox Secure Digital Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Secure-Digital-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Secure-Digital-Challenge/</guid><pubDate>Tue, 17 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>spi</category><category>logic-analyzer</category><category>signal</category><description>Secure Digital: decode the captured signal, map the bitstream, and recover the flag.</description></item><item><title>HackTheBox Vault-breaker Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Vault-breaker-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Vault-breaker-Challenge/</guid><pubDate>Tue, 17 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Vault-breaker: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox Heal Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Heal/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Heal/</guid><pubDate>Sun, 15 Dec 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox Baby Time Capsule Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Baby-Time-Capsule-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Baby-Time-Capsule-Challenge/</guid><pubDate>Fri, 13 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>rsa</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox BabyEncryption Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-BabyEncryption-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-BabyEncryption-Challenge/</guid><pubDate>Fri, 13 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Birds of randomness Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Birds-of-randomness-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Birds-of-randomness-Challenge/</guid><pubDate>Fri, 13 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>rsa</category><category>prng</category><category>lattice</category><category>ecc</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Broken Decryptor Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Broken-Decryptor-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Broken-Decryptor-Challenge/</guid><pubDate>Fri, 13 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>xor</category><category>prng</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Diagnostic Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Diagnostic-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Diagnostic-Challenge/</guid><pubDate>Fri, 13 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>forensics</category><category>powershell</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Embryonic Plant Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Embryonic-Plant-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Embryonic-Plant-Challenge/</guid><pubDate>Fri, 13 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>aes</category><category>prng</category><category>hash</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Lost Modulus Again Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Lost-Modulus-Again-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Lost-Modulus-Again-Challenge/</guid><pubDate>Fri, 13 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>rsa</category><category>lattice</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox LostKey Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-LostKey-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-LostKey-Challenge/</guid><pubDate>Fri, 13 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>rsa</category><category>aes</category><category>lattice</category><category>ecc</category><category>hash</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Low Logic Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Low-Logic-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Low-Logic-Challenge/</guid><pubDate>Fri, 13 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>signal</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox POPO Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-POPO-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-POPO-Challenge/</guid><pubDate>Fri, 13 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Protein Coockies Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Protein-Coockies-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Protein-Coockies-Challenge/</guid><pubDate>Fri, 13 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Quantum Safe Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Quantum-Safe-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Quantum-Safe-Challenge/</guid><pubDate>Fri, 13 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>rsa</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Quick Maffs Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Quick-Maffs-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Quick-Maffs-Challenge/</guid><pubDate>Fri, 13 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>lattice</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox ReMeeting the Wheel Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-ReMeeting-the-Wheel-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-ReMeeting-the-Wheel-Challenge/</guid><pubDate>Fri, 13 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>rsa</category><category>aes</category><category>hash</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox RSAisEasy Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-RSAisEasy-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-RSAisEasy-Challenge/</guid><pubDate>Fri, 13 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>rsa</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Signing Factory Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Signing-Factory-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Signing-Factory-Challenge/</guid><pubDate>Fri, 13 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>prng</category><category>hash</category><description>Signing Factory: reconstruct the PRNG state from the leak, replay it, and recover the flag.</description></item><item><title>HackTheBox The Last Dance Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-The-Last-Dance-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-The-Last-Dance-Challenge/</guid><pubDate>Fri, 13 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>xor</category><category>ecc</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox XorXorXor Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-XorXorXor-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-XorXorXor-Challenge/</guid><pubDate>Fri, 13 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>aes</category><category>xor</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox AI SPACE Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-AI-SPACE-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-AI-SPACE-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>ai</category><category>sklearn</category><category>embeddings</category><category>prompt-injection</category><category>neural-network</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox An unusual sighting Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-An-unusual-sighting-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-An-unusual-sighting-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>forensics</category><description>An unusual sighting: isolate the relevant artifact, decode the evidence, and extract the flag.</description></item><item><title>HackTheBox ApacheBlaze Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-ApacheBlaze-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-ApacheBlaze-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><description>ApacheBlaze: identify the broken request handling, prove control, and use it to recover the flag.</description></item><item><title>HackTheBox Breathtaking View Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Breathtaking-View-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Breathtaking-View-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>template-injection</category><category>rce</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox DoxPit Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-DoxPit-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-DoxPit-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>template-injection</category><category>ssrf</category><category>file-upload</category><category>flask</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox FlagCasino Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-FlagCasino-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-FlagCasino-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>elf</category><category>linux</category><description>FlagCasino: trace the binary, isolate the validation routine, and invert it to recover the flag.</description></item><item><title>HackTheBox Getting Started Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Getting-Started-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Getting-Started-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>bof</category><category>linux</category><description>Getting Started: calculate the overflow offset, redirect control flow, and land a reliable flag read.</description></item><item><title>HackTheBox Hunting License Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Hunting-License-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Hunting-License-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>elf</category><category>xor</category><category>linux</category><description>Hunting License: trace the binary, isolate the validation routine, and invert it to recover the flag.</description></item><item><title>HackTheBox Insomnia Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Insomnia-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Insomnia-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>php</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox JerryTok Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-JerryTok-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-JerryTok-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>ecc</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox LinkHands Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-LinkHands-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-LinkHands-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>LinkHands: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox NextPath Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-NextPath-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-NextPath-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>path-traversal</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox No Threshold Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-No-Threshold-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-No-Threshold-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><description>No Threshold: identify the broken request handling, prove control, and use it to recover the flag.</description></item><item><title>HackTheBox PDFy Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-PDFy-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-PDFy-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>php</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Pentest Notes Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Pentest-Notes-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Pentest-Notes-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>sql-injection</category><category>rce</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox POP Restaurant Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-POP-Restaurant-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-POP-Restaurant-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>php</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox ProxyAsAService Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-ProxyAsAService-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-ProxyAsAService-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><description>ProxyAsAService: identify the broken request handling, prove control, and use it to recover the flag.</description></item><item><title>HackTheBox Pursue the Tracks Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Pursue-the-Tracks-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Pursue-the-Tracks-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>forensics</category><description>Pursue the Tracks: isolate the relevant artifact, decode the evidence, and extract the flag.</description></item><item><title>HackTheBox Questionnaire Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Questionnaire-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Questionnaire-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>bof</category><category>format-string</category><category>canary</category><category>linux</category><description>Questionnaire: use the format-string bug for a leak or write, then redirect execution to the flag path.</description></item><item><title>HackTheBox Rhome Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Rhome-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Rhome-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>aes</category><category>prng</category><category>hash</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Shamir's Secret Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Shamirs-Secret-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Shamirs-Secret-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>lattice</category><category>shamir</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Space Pirate Going Deeper Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Space-Pirate-Going-Deeper-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Space-Pirate-Going-Deeper-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Space Pirate Going Deeper: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox Terrorfryer Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Terrorfryer-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Terrorfryer-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Terrorfryer: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Wizard's Diary Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Wizards-Diary-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Wizards-Diary-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>bof</category><category>linux</category><description>Wizard's Diary: calculate the overflow offset, redirect control flow, and land a reliable flag read.</description></item><item><title>HackTheBox Writing on the Wall Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Writing-on-the-Wall-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Writing-on-the-Wall-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Writing on the Wall: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox YALM Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-YALM-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-YALM-Challenge/</guid><pubDate>Thu, 12 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>rsa</category><category>lattice</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox AbuseHumanDB Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-AbuseHumanDB-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-AbuseHumanDB-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><description>AbuseHumanDB: identify the broken request handling, prove control, and use it to recover the flag.</description></item><item><title>HackTheBox Ancored Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Ancored-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Ancored-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>mobile</category><category>android</category><description>Ancored: inspect the Android app, trace the validation path, and recover the flag.</description></item><item><title>HackTheBox Computational Recruting Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Computational-Recruting-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Computational-Recruting-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Computational Recruting: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox Crushing Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Crushing-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Crushing-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Crushing: reverse the validation logic, model the transform, and recover the accepted input.</description></item><item><title>HackTheBox Easy Phish Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Easy-Phish-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Easy-Phish-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>osint</category><description>Easy Phish: correlate the public clues, pivot through the evidence, and identify the final answer.</description></item><item><title>HackTheBox Entity Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Entity-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Entity-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Entity: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox Foggy Intrusion Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Foggy-Intrusion-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Foggy-Intrusion-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>forensics</category><category>pcap</category><category>git</category><description>Foggy Intrusion: isolate the relevant artifact, decode the evidence, and extract the flag.</description></item><item><title>HackTheBox Fuel Crisis Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Fuel-Crisis-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Fuel-Crisis-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>ai</category><category>tensorflow</category><category>prompt-injection</category><category>neural-network</category><description>Fuel Crisis: shape the prompt path, bypass the model guard, and recover the target output.</description></item><item><title>HackTheBox Golfer Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Golfer-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Golfer-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>elf</category><category>linux</category><description>Golfer: trace the binary, isolate the validation routine, and invert it to recover the flag.</description></item><item><title>HackTheBox Graverobber Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Graverobber-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Graverobber-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>gdb</category><category>linux</category><description>Graverobber: trace the binary, isolate the validation routine, and invert it to recover the flag.</description></item><item><title>HackTheBox Illumination Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Illumination-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Illumination-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>forensics</category><description>Illumination: isolate the relevant artifact, decode the evidence, and extract the flag.</description></item><item><title>HackTheBox Infiltration Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Infiltration-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Infiltration-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>osint</category><description>Infiltration: correlate the public clues, pivot through the evidence, and identify the final answer.</description></item><item><title>HackTheBox Override Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Override-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Override-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>spi</category><category>signal</category><description>Override: decode the captured signal, map the bitstream, and recover the flag.</description></item><item><title>HackTheBox Perfect Synchronization Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Perfect-Synchronization-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Perfect-Synchronization-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>aes</category><category>ecc</category><category>vigenere</category><description>Perfect Synchronization: recover the Vigenere key from the ciphertext, decrypt the message, and verify the flag.</description></item><item><title>HackTheBox Pixel Audio Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Pixel-Audio-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Pixel-Audio-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Pixel Audio: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox Potion Master Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Potion-Master-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Potion-Master-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>xor</category><category>linux</category><description>Potion Master: recover the XOR transform from the binary and invert it to reveal the flag.</description></item><item><title>HackTheBox Prision Pipeline Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Prision-Pipeline-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Prision-Pipeline-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Prision Pipeline: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox Quantum Conundrum Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Quantum-Conundrum-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Quantum-Conundrum-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Quantum Conundrum: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox QuickScan Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-QuickScan-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-QuickScan-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>elf</category><category>linux</category><description>QuickScan: trace the binary, isolate the validation routine, and invert it to recover the flag.</description></item><item><title>HackTheBox RaceCar Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-RaceCar-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-RaceCar-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>format-string</category><category>linux</category><description>RaceCar: use the format-string bug for a leak or write, then redirect execution to the flag path.</description></item><item><title>HackTheBox Sp00ky Theme Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Sp00ky-Theme-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Sp00ky-Theme-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>forensics</category><description>Sp00ky Theme: isolate the relevant artifact, decode the evidence, and extract the flag.</description></item><item><title>HackTheBox VHDLock Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-VHDLock-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-VHDLock-Challenge/</guid><pubDate>Wed, 11 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>signal</category><description>VHDLock: decode the captured signal, map the bitstream, and recover the flag.</description></item><item><title>HackTheBox The Last Frontier Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-The-Last-Frontier-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-The-Last-Frontier-Challenge/</guid><pubDate>Tue, 10 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>signal</category><description>The Last Frontier: decode the captured signal, map the bitstream, and recover the flag.</description></item><item><title>HackTheBox El Mundo Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-El-Mundo-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-El-Mundo-Challenge/</guid><pubDate>Mon, 09 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>bof</category><category>linux</category><description>El Mundo: calculate the overflow offset, redirect control flow, and land a reliable flag read.</description></item><item><title>HackTheBox El Pipo Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-El-Pipo-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-El-Pipo-Challenge/</guid><pubDate>Mon, 09 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>bof</category><category>linux</category><description>El Pipo: calculate the overflow offset, redirect control flow, and land a reliable flag read.</description></item><item><title>HackTheBox RsaCtfTool Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-RsaCtfTool-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-RsaCtfTool-Challenge/</guid><pubDate>Mon, 09 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>aes</category><category>hash</category><description>RsaCtfTool: abuse the AES misuse, derive the missing key material, and decrypt the flag.</description></item><item><title>HackTheBox LinkVortex Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-LinkVortex/</link><guid>https://x3ric.com/blog/posts/HackTheBox-LinkVortex/</guid><pubDate>Sun, 08 Dec 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>docker</category><category>cve-2023-40028</category><description>LinkVortex: use CVE-2023-40028 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Bizness Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Bizness/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Bizness/</guid><pubDate>Thu, 05 Dec 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2023-49070</category><category>cve-2023-51467</category><description>Bizness: use CVE-2023-49070 and CVE-2023-51467 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Inject Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Inject/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Inject/</guid><pubDate>Thu, 05 Dec 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>cve-2022-22963</category><description>Inject: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Unrested Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Unrested/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Unrested/</guid><pubDate>Thu, 05 Dec 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2024-36467</category><category>cve-2024-42327</category><description>Unrested: use CVE-2024-36467 and CVE-2024-42327 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Vintage Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Vintage/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Vintage/</guid><pubDate>Wed, 04 Dec 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>ldap</category><description>Vintage: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Kernel Adventures 2 Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Kernel-Adventures-2-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Kernel-Adventures-2-Challenge/</guid><pubDate>Tue, 03 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>shellcode</category><category>linux</category><description>Kernel Adventures 2: build the shellcode path, control execution, and read the flag.</description></item><item><title>HackTheBox ScreenCrack Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-ScreenCrack-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-ScreenCrack-Challenge/</guid><pubDate>Tue, 03 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>ssrf</category><category>rce</category><category>php</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Touch Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Touch-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Touch-Challenge/</guid><pubDate>Tue, 03 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Bag Secured Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Bag-Secured-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Bag-Secured-Challenge/</guid><pubDate>Sun, 01 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Bag Secured: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox Intrusion Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Intrusion-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Intrusion-Challenge/</guid><pubDate>Sun, 01 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>signal</category><description>Intrusion: decode the captured signal, map the bitstream, and recover the flag.</description></item><item><title>HackTheBox MultiDigilingual Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-MultiDigilingual-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-MultiDigilingual-Challenge/</guid><pubDate>Sun, 01 Dec 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>MultiDigilingual: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox Addition Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Addition-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Addition-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Addition: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox C.O.P Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-C.O.P-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-C.O.P-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>sql-injection</category><category>deserialization</category><category>rce</category><description>C.O.P: exploit the SQL injection, extract the needed data, and reach the flag.</description></item><item><title>HackTheBox CandyVault Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-CandyVault-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-CandyVault-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><description>CandyVault: model the crypto leak, recover the missing secret, and decrypt the flag.</description></item><item><title>HackTheBox Cursed Stale Policy Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Cursed-Stale-Policy-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Cursed-Stale-Policy-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>websocket</category><description>Cursed Stale Policy: abuse websocket to cross the web trust boundary and recover the flag.</description></item><item><title>HackTheBox DLLAMA Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-DLLAMA-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-DLLAMA-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>deserialization</category><description>DLLAMA: abuse unsafe deserialization to cross the trust boundary and reach the flag.</description></item><item><title>HackTheBox Execute Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Execute-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Execute-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>bof</category><category>shellcode</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Fishy HTTP Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Fishy-HTTP-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Fishy-HTTP-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>forensics</category><category>pcap</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Gunship Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Gunship-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Gunship-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><description>Gunship: identify the broken request handling, prove control, and use it to recover the flag.</description></item><item><title>HackTheBox Jscalc Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Jscalc-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Jscalc-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>path-traversal</category><description>Jscalc: use path traversal to escape the intended read path and recover the flag.</description></item><item><title>HackTheBox Juggling facts Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Juggling-facts-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Juggling-facts-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><description>Juggling facts: identify the broken request handling, prove control, and use it to recover the flag.</description></item><item><title>HackTheBox KORP Terminal Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-KORP-Terminal-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-KORP-Terminal-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>sql-injection</category><description>KORP Terminal: exploit the SQL injection, extract the needed data, and reach the flag.</description></item><item><title>HackTheBox MinMax Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-MinMax-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-MinMax-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>MinMax: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox misDIRection Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-misDIRection-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-misDIRection-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>misDIRection: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox Neonify Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Neonify-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Neonify-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><description>Neonify: identify the broken request handling, prove control, and use it to recover the flag.</description></item><item><title>HackTheBox Nothing Without A Cost Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Nothing-Without-A-Cost-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Nothing-Without-A-Cost-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Nothing Without A Cost: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox Oddly Even Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Oddly-Even-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Oddly-Even-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Oddly Even: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox Optimus Prime Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Optimus-Prime-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Optimus-Prime-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><description>Optimus Prime: model the crypto leak, recover the missing secret, and decrypt the flag.</description></item><item><title>HackTheBox PetPet Rcbee Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-PetPet-Rcbee-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-PetPet-Rcbee-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>file-upload</category><description>PetPet Rcbee: abuse file-upload to cross the web trust boundary and recover the flag.</description></item><item><title>HackTheBox Phonebook Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Phonebook-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Phonebook-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><description>Phonebook: identify the broken request handling, prove control, and use it to recover the flag.</description></item><item><title>HackTheBox Prying Eyes Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Prying-Eyes-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Prying-Eyes-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>path-traversal</category><category>file-upload</category><description>Prying Eyes: use path traversal to escape the intended read path and recover the flag.</description></item><item><title>HackTheBox Replacement Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Replacement-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Replacement-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Replacement: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox Reversal Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Reversal-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Reversal-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>misc</category><description>Reversal: reduce the custom rules to a scriptable check and use the smallest reliable path to the flag.</description></item><item><title>HackTheBox SpookTastic Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-SpookTastic-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-SpookTastic-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>xss</category><description>SpookTastic: use the client-side injection path to steal the needed proof and recover the flag.</description></item><item><title>HackTheBox TimeKORP Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-TimeKORP-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-TimeKORP-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>path-traversal</category><description>TimeKORP: use path traversal to escape the intended read path and recover the flag.</description></item><item><title>HackTheBox Toxic Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Toxic-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Toxic-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>deserialization</category><category>rce</category><category>php</category><description>Toxic: abuse unsafe deserialization to cross the trust boundary and reach the flag.</description></item><item><title>HackTheBox Trapped Source Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Trapped-Source-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Trapped-Source-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><description>Trapped Source: identify the broken request handling, prove control, and use it to recover the flag.</description></item><item><title>HackTheBox Weather App Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Weather-App-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Weather-App-Challenge/</guid><pubDate>Sat, 30 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>ssrf</category><description>Weather App: use SSRF to reach the hidden service or file path and pull the flag.</description></item><item><title>HackTheBox Alert Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Alert/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Alert/</guid><pubDate>Sun, 24 Nov 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox Ancient Encodings Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Ancient-Encodings-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Ancient-Encodings-Challenge/</guid><pubDate>Sat, 23 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><description>Ancient Encodings: model the crypto leak, recover the missing secret, and decrypt the flag.</description></item><item><title>HackTheBox Dont't Panic Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Dontt-Panic-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Dontt-Panic-Challenge/</guid><pubDate>Sat, 23 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>ghidra</category><category>linux</category><description>Dont't Panic: trace the binary, isolate the validation routine, and invert it to recover the flag.</description></item><item><title>HackTheBox El Teteo Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-El-Teteo-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-El-Teteo-Challenge/</guid><pubDate>Sat, 23 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>shellcode</category><category>linux</category><description>El Teteo: build the shellcode path, control execution, and read the flag.</description></item><item><title>HackTheBox FF Jump Street Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-FF-Jump-Street-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-FF-Jump-Street-Challenge/</guid><pubDate>Sat, 23 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>signal</category><description>FF Jump Street: decode the captured signal, map the bitstream, and recover the flag.</description></item><item><title>HackTheBox Flippin Bank Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Flippin-Bank-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Flippin-Bank-Challenge/</guid><pubDate>Sat, 23 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>aes</category><category>prng</category><description>Flippin Bank: reconstruct the generator state, derive the AES material, and decrypt the final ciphertext.</description></item><item><title>HackTheBox Gonna Lift Em All Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Gonna-Lift-Em-All-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Gonna-Lift-Em-All-Challenge/</guid><pubDate>Sat, 23 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>prng</category><description>Gonna Lift Em All: reconstruct the PRNG state from the leak, replay it, and recover the flag.</description></item><item><title>HackTheBox Hacky Bird Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Hacky-Bird-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Hacky-Bird-Challenge/</guid><pubDate>Sat, 23 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>gamepwn</category><category>memory</category><description>Hacky Bird: inspect the game logic, control the relevant state, and recover the flag.</description></item><item><title>HackTheBox Mathematricks Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Mathematricks-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Mathematricks-Challenge/</guid><pubDate>Sat, 23 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Mathematricks: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox Que Onda Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Que-Onda-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Que-Onda-Challenge/</guid><pubDate>Sat, 23 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Que Onda: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox Regularity Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Regularity-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Regularity-Challenge/</guid><pubDate>Sat, 23 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>Regularity: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox SpellBrewery Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-SpellBrewery-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-SpellBrewery-Challenge/</guid><pubDate>Sat, 23 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>pwn</category><category>linux</category><description>SpellBrewery: build the exploit primitive, stabilize the payload, and use it to read the flag.</description></item><item><title>HackTheBox yoU ART Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-yoU-ART-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-yoU-ART-Challenge/</guid><pubDate>Sat, 23 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>hardware</category><category>firmware</category><category>signal</category><description>yoU ART: decode the captured signal, map the bitstream, and recover the flag.</description></item><item><title>HackTheBox BlockBlock Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-BlockBlock/</link><guid>https://x3ric.com/blog/posts/HackTheBox-BlockBlock/</guid><pubDate>Tue, 19 Nov 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox Ghost Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Ghost/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Ghost/</guid><pubDate>Tue, 19 Nov 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>ldap</category><category>docker</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox WayBack Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Wayback-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Wayback-Challenge/</guid><pubDate>Mon, 18 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Administrator Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Administrator/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Administrator/</guid><pubDate>Sun, 17 Nov 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>ldap</category><description>Administrator: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Binary Basis Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Binary-Basis-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Binary-Basis-Challenge/</guid><pubDate>Sat, 16 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><description>Binary Basis: model the crypto leak, recover the missing secret, and decrypt the flag.</description></item><item><title>HackTheBox Brevi Moduli Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Brevi-Moduli-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Brevi-Moduli-Challenge/</guid><pubDate>Sat, 16 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>rsa</category><category>lattice</category><description>Brevi Moduli: turn the RSA leak into a lattice recovery, rebuild the secret values, and decrypt the flag.</description></item><item><title>HackTheBox Hybrid Unifier Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Hybrid-Unifier-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Hybrid-Unifier-Challenge/</guid><pubDate>Sat, 16 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>aes</category><category>hash</category><description>Hybrid Unifier: abuse the AES misuse, derive the missing key material, and decrypt the flag.</description></item><item><title>HackTheBox Inizialization Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Inizialization-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Inizialization-Challenge/</guid><pubDate>Sat, 16 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>aes</category><category>xor</category><description>Inizialization: abuse the AES misuse, derive the missing key material, and decrypt the flag.</description></item><item><title>HackTheBox Read Before You Sign Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Read-Before-You-Sign-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Read-Before-You-Sign-Challenge/</guid><pubDate>Sat, 16 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><description>Read Before You Sign: model the crypto leak, recover the missing secret, and decrypt the flag.</description></item><item><title>HackTheBox Sekur Julius Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Sekur-Julius-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Sekur-Julius-Challenge/</guid><pubDate>Sat, 16 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>prng</category><description>Sekur Julius: reconstruct the PRNG state from the leak, replay it, and recover the flag.</description></item><item><title>HackTheBox SPG Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-SPG-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-SPG-Challenge/</guid><pubDate>Sat, 16 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>aes</category><category>prng</category><category>hash</category><description>SPG: reconstruct the generator state, derive the AES material, and decrypt the final ciphertext.</description></item><item><title>HackTheBox Sugar Free Candies Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Sugar-Free-Candies-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Sugar-Free-Candies-Challenge/</guid><pubDate>Sat, 16 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><description>Sugar Free Candies: model the crypto leak, recover the missing secret, and decrypt the flag.</description></item><item><title>HackTheBox Certified Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Certified/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Certified/</guid><pubDate>Thu, 07 Nov 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>ldap</category><description>Certified: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Feedback Flux Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Feedback-Flux-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Feedback-Flux-Challenge/</guid><pubDate>Sat, 02 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>web</category><category>xss</category><category>php</category><description>Feedback Flux: use the client-side injection path to steal the needed proof and recover the flag.</description></item><item><title>HackTheBox Blazorized Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Blazorized/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Blazorized/</guid><pubDate>Fri, 01 Nov 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>ldap</category><description>Blazorized: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Epsilon Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Epsilon/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Epsilon/</guid><pubDate>Fri, 01 Nov 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Epsilon: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox Secure Singning Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Secure-Singning-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Secure-Singning-Challenge/</guid><pubDate>Fri, 01 Nov 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>crypto</category><category>xor</category><category>hash</category><description>Secure Singning: derive the XOR key stream, invert the transform, and recover the flag.</description></item><item><title>HackTheBox Shattered Tablet Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Shattered-Tablet-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Shattered-Tablet-Challenge/</guid><pubDate>Wed, 30 Oct 2024 09:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>ghidra</category><category>linux</category><description>Shattered Tablet: trace the binary, isolate the validation routine, and invert it to recover the flag.</description></item><item><title>HackTheBox Mist Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Mist/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Mist/</guid><pubDate>Sat, 26 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>smb</category><category>ldap</category><category>cve-2024-9405</category><description>Mist: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Axlle Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Axlle/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Axlle/</guid><pubDate>Tue, 22 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>smb</category><category>ldap</category><description>Axlle: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Bypass Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Bypass-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Bypass-Challenge/</guid><pubDate>Tue, 22 Oct 2024 01:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>dotnet</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Beep Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Beep/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Beep/</guid><pubDate>Sun, 20 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2012-4869</category><description>Beep: use CVE-2012-4869 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox MagicGardens Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-MagicGardens/</link><guid>https://x3ric.com/blog/posts/HackTheBox-MagicGardens/</guid><pubDate>Sun, 20 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>docker</category><description>MagicGardens: turn the exposed service into a shell, pivot through the container boundary, and escalate to root.</description></item><item><title>HackTheBox Simple Encryptor Challenge</title><link>https://x3ric.com/blog/posts/HackTheBox-Simple-Encryptor-Challenge/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Simple-Encryptor-Challenge/</guid><pubDate>Sun, 20 Oct 2024 01:20:00 +0800</pubDate><category>challenge</category><category>htb</category><category>rev</category><category>elf</category><category>xor</category><category>linux</category><description>Enter the challenge flag to unlock this writeup.</description></item><item><title>HackTheBox Chemistry Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Chemistry/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Chemistry/</guid><pubDate>Sat, 19 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2024-23334</category><category>cve-2024-23346</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox Compiled Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Compiled/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Compiled/</guid><pubDate>Fri, 18 Oct 2024 15:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>cve-2024-20656</category><category>cve-2024-32002</category><description>Compiled: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Union Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Union/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Union/</guid><pubDate>Wed, 16 Oct 2024 09:22:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Union: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox Jarmis Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Jarmis/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Jarmis/</guid><pubDate>Wed, 16 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>cve-2021-38647</category><description>Jarmis: use CVE-2021-38647 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Lantern Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Lantern/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Lantern/</guid><pubDate>Tue, 15 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2022-38580</category><description>Lantern: use CVE-2022-38580 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox MonitorsThree Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-MonitorsThree/</link><guid>https://x3ric.com/blog/posts/HackTheBox-MonitorsThree/</guid><pubDate>Mon, 14 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2024-25641</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox Resource Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Resource/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Resource/</guid><pubDate>Mon, 14 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>docker</category><description>Resource: turn the exposed service into a shell, pivot through the container boundary, and escalate to root.</description></item><item><title>HackTheBox Instant Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Instant/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Instant/</guid><pubDate>Sat, 12 Oct 2024 12:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Enter the password to unlock this machine writeup.</description></item><item><title>HackTheBox YPuffy Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-YPuffy/</link><guid>https://x3ric.com/blog/posts/HackTheBox-YPuffy/</guid><pubDate>Sat, 12 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>smb</category><category>ldap</category><category>cve-2018-14665</category><description>YPuffy: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>TryHackMe Brains Writeup</title><link>https://x3ric.com/blog/posts/TryHackMe-Brains/</link><guid>https://x3ric.com/blog/posts/TryHackMe-Brains/</guid><pubDate>Thu, 10 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>thm</category><category>linux</category><category>cve-2024-27198</category><description>Brains: use CVE-2024-27198 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Help Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Help/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Help/</guid><pubDate>Wed, 09 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>cve-2017-16995</category><category>cve-2017-5899</category><category>cve-2021-22555</category><description>Help: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox GoodGames Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-GoodGames/</link><guid>https://x3ric.com/blog/posts/HackTheBox-GoodGames/</guid><pubDate>Sun, 06 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>docker</category><description>GoodGames: turn the exposed service into a shell, pivot through the container boundary, and escalate to root.</description></item><item><title>HackTheBox Valentine Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Valentine/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Valentine/</guid><pubDate>Sun, 06 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2014-0160</category><category>cve-2016-5195</category><description>Valentine: use CVE-2014-0160 and CVE-2016-5195 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Yummy Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Yummy/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Yummy/</guid><pubDate>Sun, 06 Oct 2024 00:15:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Yummy: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox EvilCUPS Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-EvilCUPS/</link><guid>https://x3ric.com/blog/posts/HackTheBox-EvilCUPS/</guid><pubDate>Thu, 03 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2024-47076</category><category>cve-2024-47175</category><category>cve-2024-47176</category><category>cve-2024-47177</category><description>EvilCUPS: use CVE-2024-47076 and CVE-2024-47175 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>TryHackMe Flip Challenge</title><link>https://x3ric.com/blog/posts/TryHackMe-Flip-Challenge/</link><guid>https://x3ric.com/blog/posts/TryHackMe-Flip-Challenge/</guid><pubDate>Thu, 03 Oct 2024 09:20:00 +0800</pubDate><category>challenge</category><category>thm</category><category>crypto</category><category>aes</category><category>xor</category><description>Flip: abuse the AES misuse, derive the missing key material, and decrypt the flag.</description></item><item><title>TryHackMe Prioritise Writeup</title><link>https://x3ric.com/blog/posts/TryHackMe-Prioritise/</link><guid>https://x3ric.com/blog/posts/TryHackMe-Prioritise/</guid><pubDate>Thu, 03 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>thm</category><category>linux</category><description>Prioritise: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>TryHackMe Pyrat Writeup</title><link>https://x3ric.com/blog/posts/TryHackMe-Pyrat/</link><guid>https://x3ric.com/blog/posts/TryHackMe-Pyrat/</guid><pubDate>Thu, 03 Oct 2024 09:20:00 +0800</pubDate><category>machine</category><category>thm</category><category>linux</category><description>Pyrat: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox Cicada Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Cicada/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Cicada/</guid><pubDate>Wed, 02 Oct 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>smb</category><category>ldap</category><description>Cicada: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Gobox Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Gobox/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Gobox/</guid><pubDate>Mon, 30 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Gobox: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox Bashed Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Bashed/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Bashed/</guid><pubDate>Fri, 27 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Bashed: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox Shocker Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Shocker/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Shocker/</guid><pubDate>Fri, 27 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2014-6271</category><description>Shocker: use CVE-2014-6271 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox TwoMillion Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-TwoMillion/</link><guid>https://x3ric.com/blog/posts/HackTheBox-TwoMillion/</guid><pubDate>Fri, 27 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2023-0386</category><description>TwoMillion: use CVE-2023-0386 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Soccer Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Soccer/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Soccer/</guid><pubDate>Wed, 25 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>cve-2021-45010</category><description>Soccer: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox GreenHorn Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-GreenHorn/</link><guid>https://x3ric.com/blog/posts/HackTheBox-GreenHorn/</guid><pubDate>Mon, 23 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2023-50564</category><description>GreenHorn: use CVE-2023-50564 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox BoardLight Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-BoardLight/</link><guid>https://x3ric.com/blog/posts/HackTheBox-BoardLight/</guid><pubDate>Sun, 22 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2022-37706</category><category>cve-2023-30253</category><description>BoardLight: use CVE-2022-37706 and CVE-2023-30253 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Editorial Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Editorial/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Editorial/</guid><pubDate>Sun, 22 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Editorial: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox PermX Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-PermX/</link><guid>https://x3ric.com/blog/posts/HackTheBox-PermX/</guid><pubDate>Sun, 22 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2023-4220</category><description>PermX: use CVE-2023-4220 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Headless Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Headless/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Headless/</guid><pubDate>Sat, 21 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Headless: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox Trickster Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Trickster/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Trickster/</guid><pubDate>Sat, 21 Sep 2024 09:20:00 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2023-47268</category><category>cve-2024-32651</category><category>cve-2024-34716</category><description>Trickster: use CVE-2023-47268 and CVE-2024-32651 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Sea Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Sea/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Sea/</guid><pubDate>Mon, 16 Sep 2024 00:12:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2023-41425</category><description>Sea: use CVE-2023-41425 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Caption Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Caption/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Caption/</guid><pubDate>Mon, 16 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Caption: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>HackTheBox Bastion Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Bastion/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Bastion/</guid><pubDate>Fri, 13 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>smb</category><description>Bastion: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Curling Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Curling/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Curling/</guid><pubDate>Fri, 13 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>joomla</category><description>Curling: abuse the Joomla exposure for a shell, then use local enumeration to reach root.</description></item><item><title>HackTheBox Sightless Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Sightless/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Sightless/</guid><pubDate>Fri, 13 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>docker</category><category>cve-2022-0944</category><category>cve-2024-34070</category><description>Sightless: use CVE-2022-0944 and CVE-2024-34070 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Spooktrol Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Spooktroll/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Spooktroll/</guid><pubDate>Fri, 13 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>docker</category><description>Spooktrol: turn the exposed service into a shell, pivot through the container boundary, and escalate to root.</description></item><item><title>HackTheBox Writeup Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Writeup/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Writeup/</guid><pubDate>Fri, 13 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>cve-2022-41544</category><description>Writeup: use CVE-2022-41544 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Active Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Active/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Active/</guid><pubDate>Thu, 12 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>active-directory</category><category>kerberos</category><category>smb</category><category>ldap</category><description>Active: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Codify Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Codify/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Codify/</guid><pubDate>Thu, 12 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>kerberos</category><description>Codify: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.</description></item><item><title>HackTheBox Paper Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Paper/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Paper/</guid><pubDate>Thu, 12 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>windows</category><category>linux</category><category>wordpress</category><category>cve-2019-17671</category><category>cve-2021-3560</category><description>Paper: use CVE-2019-17671 and CVE-2021-3560 where it fits the service, gain a shell, and escalate to root.</description></item><item><title>HackTheBox Perfection Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-Perfection/</link><guid>https://x3ric.com/blog/posts/HackTheBox-Perfection/</guid><pubDate>Thu, 12 Sep 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><description>Perfection: enumerate the services, turn the exposed weakness into a shell, and escalate to root.</description></item><item><title>TryHackMe SQHell Challenge</title><link>https://x3ric.com/blog/posts/TryHackMe-SQHell-Challenge/</link><guid>https://x3ric.com/blog/posts/TryHackMe-SQHell-Challenge/</guid><pubDate>Fri, 16 Aug 2024 23:20:00 +0800</pubDate><category>challenge</category><category>thm</category><category>web</category><category>sql-injection</category><description>SQHell: exploit the SQL injection, extract the needed data, and reach the flag.</description></item><item><title>TryHackMe DearQA Challenge</title><link>https://x3ric.com/blog/posts/TryHackMe-DearQA-Challenge/</link><guid>https://x3ric.com/blog/posts/TryHackMe-DearQA-Challenge/</guid><pubDate>Fri, 28 Jun 2024 01:20:00 +0800</pubDate><category>challenge</category><category>thm</category><category>pwn</category><category>bof</category><category>format-string</category><category>heap</category><category>shellcode</category><category>linux</category><description>DearQA: shape the heap state, gain the needed write or leak, and pivot to flag access.</description></item><item><title>TryHackMe Blog Writeup</title><link>https://x3ric.com/blog/posts/TryHackMe-Blog/</link><guid>https://x3ric.com/blog/posts/TryHackMe-Blog/</guid><pubDate>Thu, 13 Jun 2024 03:20:00 +0800</pubDate><category>machine</category><category>thm</category><category>windows</category><category>linux</category><category>wordpress</category><description>Blog: abuse the WordPress foothold, stabilize the shell, and escalate through the local weakness.</description></item><item><title>HackTheBox DevVortex Writeup</title><link>https://x3ric.com/blog/posts/HackTheBox-DevVortex/</link><guid>https://x3ric.com/blog/posts/HackTheBox-DevVortex/</guid><pubDate>Tue, 16 Apr 2024 00:10:50 +0800</pubDate><category>machine</category><category>htb</category><category>linux</category><category>joomla</category><category>cve-2023-23752</category><description>DevVortex: use CVE-2023-23752 where it fits the service, gain a shell, and escalate to root.</description></item></channel></rss>