TABARIK
Home
Portfolio
Blog
// Security Research & HTB Writeups
FIELD NOTES
Technical writeups from HackTheBox machines, bug bounty research, and security engineering. No fluff — just methodology, findings, and lessons.
22
Writeups
2
Platforms
PRO HACKER
HTB Rank
FILTER:
ALL
LINUX
WINDOWS
BUG BOUNTY
SECURITY ENGINEERING
May 15 2026
EASY
LINUX
Reset
Abuse of password reset token predictability and file write to gain foothold, service exploitation for root
Password Reset
Token Abuse
Linux
May 12 2026
EASY
LINUX
Expressway
IKEv1 aggressive mode PSK cracking via ike-scan then sudo CVE-2025-32463 for root
CVE-2025-32463
VPN
IKE
sudo
May 08 2026
EASY
LINUX
Editor
XWiki SSTI via CVE-2025-24893 for foothold, ndsudo PATH hijack for privilege escalation
CVE-2025-24893
SSTI
XWiki
PATH Hijack
May 04 2026
EASY
LINUX
Dog
Backdrop CMS unauthenticated code exec via bee eval module, git credential leak for root
CMS
RCE
Git
Apr 30 2026
EASY
LINUX
LinkVortex
Ghost CMS arbitrary file read via CVE-2023-40028, symlink TOCTOU race for credential access
CVE-2023-40028
Ghost CMS
TOCTOU
LFI
Apr 26 2026
EASY
LINUX
BoardLight
Dolibarr ERP CVE-2023-30253 PHP injection for foothold, Enlightenment SUID binary for root
CVE-2023-30253
CVE
SUID
PHP Injection
Apr 06 2026
EASY
LINUX
Broker
Apache ActiveMQ CVE-2023-46604 ClassInfo deserialization RCE, sudo nginx GTFO for root
CVE-2023-46604
ActiveMQ
Deserialization
RCE
Apr 02 2026
EASY
LINUX
CozyHosting
Spring Boot Actuator exposes active sessions, command injection via SSH username field, postgres credential dump
Spring Boot
RCE
Command Injection
Mar 29 2026
EASY
LINUX
TwoMillion
Invite code generation via JS reverse engineering, API v1 admin endpoint abuse, OverlayFS CVE for root
API Abuse
JS Reversing
Kernel CVE
Mar 25 2026
EASY
LINUX
Sau
Request Baskets SSRF via CVE-2023-27163 to reach internal Maltrail service with unauthenticated RCE
CVE-2023-27163
SSRF
SSRF Chain
RCE
Mar 21 2026
EASY
LINUX
Keeper
Default credentials on Request Tracker, KeePass memory dump CVE-2023-32784 leaks master password
CVE-2023-32784
Default Creds
KeePass
Memory Dump
Mar 17 2026
EASY
LINUX
Busqueda
Searchor CLI eval() command injection via crafted search query, sudo script git config hijack for root
Command Injection
eval()
sudo
Mar 13 2026
EASY
LINUX
Soccer
Tiny File Manager default creds for webshell upload, WebSocket-based blind SQLi, doas privesc
SQLi
WebSocket
File Upload
Mar 09 2026
EASY
LINUX
Cap
IDOR on PCAP download endpoint leaks FTP plaintext credentials, Python cap_setuid privilege escalation
IDOR
PCAP
Linux Capabilities
Mar 05 2026
EASY
LINUX
Help
HelpDeskZ unauthenticated file upload via timestamp bypass, Linux kernel dirty cow variant for root
File Upload
Kernel Exploit
HelpDeskZ
Mar 01 2026
EASY
LINUX
Bashed
phpbash webshell left exposed on dev server, sudo scriptmanager abuse and cron-based privesc
Webshell
sudo
Cron
Feb 24 2026
EASY
LINUX
Shocker
Shellshock CGI bash vulnerability via User-Agent header, sudo perl GTFO for root
Shellshock
CGI
sudo
Feb 20 2026
EASY
LINUX
Lame
Samba CVE-2007-2447 username map script command injection gives direct root shell — classic entry box
CVE-2007-2447
Samba
CVE
RCE
Apr 14 2026
EASY
WINDOWS
Support
LDAP credentials hardcoded in .NET binary, Resource-Based Constrained Delegation (RBCD) for Domain Admin
Active Directory
RBCD
.NET Reversing
Apr 10 2026
EASY
WINDOWS
Mailing
hMailServer open relay for phishing, Outlook MonikerLink CVE-2024-21413 for NTLM capture and relay
CVE-2024-21413
Mail Server
NTLM Relay
Outlook
Apr 18 2026
HARD
LINUX
Intentions
API mass assignment to escalate user role, ImageMagick MSL file write RCE, GitHub Actions token abuse for root
Mass Assignment
ImageMagick
CI/CD Abuse
Apr 22 2026
MEDIUM
LINUX
Monitored
SNMP community string leaks service account credentials, Nagios XI authenticated SQLi, npcd binary hijack
SNMP
SQLi
Service Hijack