Discussion — Any questions? Ask and discuss freely in the community.
blackXploit

Hi, I'm Surajit — known online as blackXploit.

I'm a BCA student passionate about cybersecurity, Linux, and web application security.

This is where I document what I learn while solving Hack The Box and TryHackMe machines, competing in CTFs, experimenting with web technologies, and building practical projects — mostly on the backend side of things.

Well, everyone's a developer until a script kiddie gets a remote shell on their machine. So instead of chasing pixel-perfect UIs, I focus on secure development — rate limiting, manual auth systems, business logic, secure file upload systems — because design really isn't my thing.


btw what you'll find here


I'm currently learning:

Thanks for visiting!

Latest Writeups & Articles

Hack The BoxComing Soon
Touch machine artwork
Touch
Easy Windows ★ 4.3

Touch

Writeup dropping soon.

Hack The Box active
DanglingTree machine artwork
DanglingTree
Medium ★ 4.2

HTB DanglingTree Writeup

Hack The Box DanglingTree, a Windows AD box: SMB enumeration, an exposed IT share, credential disclosure and WinAC command execution. Steps after retirement.

By Surajit Sen · · 1 min read · 207 views

Login to Unlock

Hack The Box active
Cohort machine artwork
Cohort
Easy ★ 3.8

HTB Cohort Writeup

Hack The Box Cohort machine overview: an SSRF localhost filter bypass, pre-auth Marimo WebSocket RCE and PackageKit TOCTOU privesc. Full steps after retirement.

By Surajit Sen · · 1 min read · 291 views

Login to Unlock

Hack The Box active
Enigma machine artwork
Enigma
Easy ★ 4.3

HTB Enigma Writeup

Hack The Box Enigma machine overview: NFS enumeration, OpenSTAManager RCE, credential harvesting and cracking, and an OliveTin privesc. Steps after retirement.

By Surajit Sen · · 1 min read · 303 views

Login to Unlock

Hack The Box active
DevHub machine artwork
DevHub
Medium ★ 4.0

HTB Devhub Writeup

Hack The Box Devhub overview: MCPJam RCE, internal service discovery, SSH key extraction via a hidden API and an OPSMCP admin tool. Steps after retirement.

By Surajit Sen · · 1 min read · 203 views

Login to Unlock

Hack The Box active
Bedside machine artwork
Bedside
Medium ★ 4.3

HTB BedSide Writeup

Hack The Box BedSide machine overview: PDFMiner path traversal, SSH key theft and PyTorch deserialization. Full walkthrough published after the machine retires.

By Surajit Sen · · 1 min read · 211 views

Login to Unlock

Hack The Box active
Paperwork machine artwork
Paperwork
Easy ★ 4.1

HTB Paperwork Writeup

Hack The Box Paperwork machine overview: LPD command injection, PJL path traversal and file descriptor hijacking with SCM_RIGHTS. Full steps after retirement.

By Surajit Sen · · 1 min read · 172 views

Login to Unlock