How I Hacked a Cybersecurity Training Academy and Company !
A detailed blog about How I Hacked a Cybersecurity Training Academy & Company ! Real btw
I'm a BCA student passionate about cybersecurity, Linux, and web application security.
This is where I document what I learn while solving Hack The Box and TryHackMe machines, competing in CTFs, experimenting with web technologies, and building practical projects — mostly on the backend side of things.
Well, everyone's a developer until a script kiddie gets a remote shell on their machine. So instead of chasing pixel-perfect UIs, I focus on secure development — rate limiting, manual auth systems, business logic, secure file upload systems — because design really isn't my thing.
A detailed blog about How I Hacked a Cybersecurity Training Academy & Company ! Real btw
HTB Management walkthrough: Hack The Box Linux box solved with OpenAM 16.0.5 pre-auth RCE (CVE-2026-33439), GLPI encrypted secret decryption, and rdiff-backup sudo privesc (CVE-2022-40093). Full writeup publishes when the box retires.
Complete HackSmarter Aftermath walkthrough covering Rustscan enumeration, SMTP VRFY user enumeration with smtp-user-enum, Roundcube Webmail password spraying with cubeSpraying, mailbox flag recovery, and root privilege escalation via passwordless apt-get APT::Update::Pre-Invoke.
Complete Hack The Box Abducted walkthrough covering Samba printer share RCE via CVE-2026-4480, rclone obscure password decryption, credential reuse to scott, SMB force-user plus wide-links pivot to marcus, and root via systemd drop-in.
A step-by-step walkthrough on how to get a free working website on a .arpa domain by abusing IPv6 reverse DNS delegation through Hurricane Electric, configuring DNS with deSEC, and hosting a live site on Surge.
Due to Hack The Box policies, this writeup is protected and is not publicly served while the Hack The Box machine is active.
Complete HackSmarter: Casino walkthrough covering full port scan, directory enumeration, source map discovery, IDOR-style room status exposure, Flask/Jinja2 SSTI leading to RCE, reverse shell as www-data, credential discovery via .bash_history, user pivot to david, and root escalation via provisioning.log credential.
HTB Support is a Windows Active Directory machine where anonymous SMB share access exposes an internal .NET tool with hardcoded LDAP credentials. Using the recovered account enables LDAP enumeration that leaks a plaintext user password via an attribute, leading to WinRM access. Post-exploitation ACL
Due to Hack The Box policies, this writeup is protected and is not publicly served while the Hack The Box machine is active.