Garfield — HackTheBox Walkthrough (Hard, Active Directory)
Hard Windows AD box. Chains writable SYSVOL → Logon Script Hijack → ForceChangePassword pivot → AddSelf to RODC Administrators → R…
Walkthroughs → All Walkthroughs articles
Hard Windows AD box. Chains writable SYSVOL → Logon Script Hijack → ForceChangePassword pivot → AddSelf to RODC Administrators → R…
A complete HackTheBox DevArea walkthrough covering FTP enumeration, Apache CXF SSRF (CVE-2022-46364), credential extraction, Hover…
Full security assessment walkthrough for Baby on Vulnlab. Includes reconnaissance, enumeration, exploitation steps, and a professi…
Full security assessment walkthrough for Escape on Vulnlab. Includes reconnaissance, enumeration, exploitation steps, and a profes…
Full security assessment walkthrough for Sweep on Vulnlab. Includes reconnaissance, enumeration, exploitation steps, and a profess…
Full walkthrough of the HackTheBox AWS Fortress. Covers S3 public bucket credential leakage, IAM privilege escalation via AssumeRo…
Complete Faraday Fortress writeup. 8 flags: SMTP debug catcher → exposed /.git → git-dumper → Flask render_template_string SSTI → …
Complete walkthrough of both Synacktiv HTB Fortress versions. v1 covers path traversal double-encoding, SSTI Jinja2 RCE, and PHP d…
Complete Akerva Fortress writeup translated from the xchg2pwn Spanish original. 8 flags: HTML comment leak → SNMP public v2c → HTT…
Full security assessment walkthrough for Academy on HackTheBox. Includes reconnaissance, enumeration, exploitation steps, and a pr…