Touch
Writeup dropping soon.
I'm a BCA student passionate about cybersecurity, Linux, and web application security.
This is where I document what I learn while solving Hack The Box and TryHackMe machines, competing in CTFs, experimenting with web technologies, and building practical projects — mostly on the backend side of things.
Well, everyone's a developer until a script kiddie gets a remote shell on their machine. So instead of chasing pixel-perfect UIs, I focus on secure development — rate limiting, manual auth systems, business logic, secure file upload systems — because design really isn't my thing.
Writeup dropping soon.
Hack The Box Reactor walkthrough: Next.js React2Shell RCE (CVE-2025-55182), then attaching to a root-owned Node inspector port for command execution as root.
Complete Hack The Box Helix walkthrough covering Apache NiFi RCE, lateral movement to operator, and OPC UA-based privilege escalation.
No VPS no problem - catch reverse shells without a VPS using gsocket, pinggy, and other tunneling services for CTF and authorized penetration testing.
google colab gone wrong !
A Hack The Box Snapped walkthrough covering Nginx UI backup exploitation, credential recovery, and Linux privilege escalation.
Hack The Box DevArea writeup: full enumeration, initial foothold, exploitation and privilege escalation chain, captured step by step with user and root flags.
Hack The Box CCTV writeup: a ZoneMinder blind SQL injection, weak database credentials, and an authenticated motionEye RCE chain to a root shell.
Hack The Box Facts writeup: an exposed MinIO server leaks AWS credentials, CVE-2025-2304 gives RCE, and a cracked SSH key plus sudo chain reaches root.