Discussion — Any questions? Ask and discuss freely in the community.
blackXploit

Hi, I'm Surajit — known online as blackXploit.

I'm a BCA student passionate about cybersecurity, Linux, and web application security.

This is where I document what I learn while solving Hack The Box and TryHackMe machines, competing in CTFs, experimenting with web technologies, and building practical projects — mostly on the backend side of things.

Well, everyone's a developer until a script kiddie gets a remote shell on their machine. So instead of chasing pixel-perfect UIs, I focus on secure development — rate limiting, manual auth systems, business logic, secure file upload systems — because design really isn't my thing.


btw what you'll find here


I'm currently learning:

Thanks for visiting!

Latest Writeups & Articles

Hack The BoxComing Soon
Touch machine artwork
Touch
Easy Windows ★ 4.3

Touch

Writeup dropping soon.

Hack The Box retired
Helix machine artwork
Helix
Medium ★ 4.5

HTB Helix Writeup

Complete Hack The Box Helix walkthrough covering Apache NiFi RCE, lateral movement to operator, and OPC UA-based privilege escalation.

By Surajit Sen · · 11 min read · 273 views

Hack The Box retired
CCTV machine artwork
CCTV
Easy ★ 3.6

HTB – CCTV

Hack The Box CCTV writeup: a ZoneMinder blind SQL injection, weak database credentials, and an authenticated motionEye RCE chain to a root shell.

By Surajit Sen · · 6 min read · 179 views

Hack The Box retired
Facts machine artwork
Facts
Easy ★ 4.5

HTB-Facts

Hack The Box Facts writeup: an exposed MinIO server leaks AWS credentials, CVE-2025-2304 gives RCE, and a cracked SSH key plus sudo chain reaches root.

By Surajit Sen · · 6 min read · 165 views