Touch
Writeup dropping soon.
I'm a BCA student passionate about cybersecurity, Linux, and web application security.
This is where I document what I learn while solving Hack The Box and TryHackMe machines, competing in CTFs, experimenting with web technologies, and building practical projects — mostly on the backend side of things.
Well, everyone's a developer until a script kiddie gets a remote shell on their machine. So instead of chasing pixel-perfect UIs, I focus on secure development — rate limiting, manual auth systems, business logic, secure file upload systems — because design really isn't my thing.
Writeup dropping soon.
Hack The Box Support writeup: an anonymous SMB share leaks hardcoded LDAP credentials, enumeration exposes a plaintext password, then WinRM and Windows privesc.
Hack The Box DanglingTree, a Windows AD box: SMB enumeration, an exposed IT share, credential disclosure and WinAC command execution. Steps after retirement.
Hack The Box Cohort machine overview: an SSRF localhost filter bypass, pre-auth Marimo WebSocket RCE and PackageKit TOCTOU privesc. Full steps after retirement.
Hack The Box Enigma machine overview: NFS enumeration, OpenSTAManager RCE, credential harvesting and cracking, and an OliveTin privesc. Steps after retirement.
Hack The Box Devhub overview: MCPJam RCE, internal service discovery, SSH key extraction via a hidden API and an OPSMCP admin tool. Steps after retirement.
AWS privesc lab: Pacu enumeration, Lambda credential leakage, wp2shell WordPress SQLi RCE (CVE-2026-63030), EC2 IMDS theft, Secrets Manager.
Hack The Box BedSide machine overview: PDFMiner path traversal, SSH key theft and PyTorch deserialization. Full walkthrough published after the machine retires.
A hands-on look at how easy it is to backdoor a Linux package, and how to stop it happening to you.
Hack The Box Paperwork machine overview: LPD command injection, PJL path traversal and file descriptor hijacking with SCM_RIGHTS. Full steps after retirement.