HackTheBox - Management
Writeup pending - this machine hasn't retired on HackTheBox yet.
[email protected]:~$ whoami
Rahul R · Security Engineer · Penetration Tester
Dubai, UAE
[email protected]:~$ cat interests.txt
pentesting · active directory · cloud · android
reverse engineering · malware · hardware · ctf
[email protected]:~$ ls -la blog/
14 posts 4 htb-writeups
9 categories 20 tags
[email protected]:~$ htb --status
Elite Hacker · #107 global · 1536 pts · 251/232 owns
[email protected]:~$ ▍Writeup pending - this machine hasn't retired on HackTheBox yet.
Writeup pending - this machine hasn't retired on HackTheBox yet.
Writeup pending - this machine hasn't retired on HackTheBox yet.
Writeup pending - this machine hasn't retired on HackTheBox yet.
How a cheap IP camera and some 'procrastination' led to a full Remote Code Execution vulnerability.
Technical Walkthrough on solving the TokenBleed challenge from MobileHackingLabs
In this post, I reverse engineer a real-world Android malware campaign targeting SBI bank customers, uncovering how attackers use APK droppers to deploy SMS-hijacking trojans.
Creating Speed Hack and Super Jump on Pwn Adventure 3 using Cheat Engine
Creating God Mode and One Hit Kills on Pwn Adventure 3 using Cheat Engine
This is the walkthrough for the newly introduced challenge category GamePWN on HackTheBox
Ra is a windows machine which starts with a typical business website for Windcorp where there is a password reset function which can be used to change a user's password to gain access to a SMB share to download spark live chat application which is vulnerable that can be used to harvest a user's NTLM hash that can be used to gain initial access to the machine.On further exploring the machine a script can be seen that contains a username who's password can be changed since the user has extended rights to change password as he is a member of the account operator group.Analysing the script we can see that there is command injection vulnerability that can be abused to gain admin privilege and pwn the machine
Here is a short write-up on an interesting bug that I found while testing a site where I was able to chain multiple IDORs to execute Code on the server
This is the walkthrough for the challenges that were provided as a part of COCON's DomeCTF
This is the walkthrough for the challenges that were provided as a part of Sector443's CTF