HTB Cohort Writeup
Due to Hack The Box policies, this writeup is protected and is not publicly served while the Hack The Box machine is active.
I'm a BCA student passionate about cybersecurity, Linux, and web application security.
This is where I document what I learn while solving Hack The Box and TryHackMe machines, competing in CTFs, experimenting with web technologies, and building practical projects — mostly on the backend side of things.
Well, everyone's a developer until a script kiddie gets a remote shell on their machine. So instead of chasing pixel-perfect UIs, I focus on secure development — rate limiting, manual auth systems, business logic, secure file upload systems — because design really isn't my thing.
Due to Hack The Box policies, this writeup is protected and is not publicly served while the Hack The Box machine is active.
Due to Hack The Box policies, this writeup is protected and is not publicly served while the Hack The Box machine is active.
Due to Hack The Box policies, this writeup is protected and is not publicly served while the Hack The Box machine is active.
AWS privilege escalation lab writeup: Pacu enumeration, Lambda credential leakage, wp2shell WordPress SQLi RCE (CVE-2026-63030, CVE-2026-60137), EC2 IMDS credential theft, and AWS Secrets Manager compromise.
Due to Hack The Box policies, this writeup is protected and is not publicly served while the Hack The Box machine is active.
A hands-on look at how easy it is to backdoor a Linux package, and how to stop it happening to you.
Due to Hack The Box policies, this writeup is protected and is not publicly served while the Hack The Box machine is active.
Due to Hack The Box policies, this writeup is protected and is not publicly served while the Hack The Box machine is active.
Complete Hack The Box Helix walkthrough covering Apache NiFi RCE, lateral movement to operator, and OPC UA-based privilege escalation.