Discussion — Any questions? Ask and discuss freely in the community.
blackXploit

Hi, I'm Surajit — known online as blackXploit.

I'm a BCA student passionate about cybersecurity, Linux, and web application security.

This is where I document what I learn while solving Hack The Box and TryHackMe machines, competing in CTFs, experimenting with web technologies, and building practical projects — mostly on the backend side of things.

Well, everyone's a developer until a script kiddie gets a remote shell on their machine. So instead of chasing pixel-perfect UIs, I focus on secure development — rate limiting, manual auth systems, business logic, secure file upload systems — because design really isn't my thing.


btw what you'll find here


I'm currently learning:

Thanks for visiting!

Latest Writeups & Articles

Hack The BoxComing Soon
Touch machine artwork
Touch
Easy Windows ★ 4.3

Touch

Writeup dropping soon.

Hack The Box retired
MonitorsFour machine artwork
MonitorsFour
Easy ★ 3.5

HTB – MonitorsFour

Hack The Box MonitorsFour writeup: a leaked .env file, PHP type juggling (CVE-2025-24367), CVE-2025-9074 RCE, and a Docker API escape onto a Windows host.

By Surajit Sen · · 6 min read · 167 views

Hack The Box retired
Expressway machine artwork
Expressway
Easy ★ 4.1

HTB – Expressway

Hack The Box Expressway writeup: an IPsec VPN in IKE Aggressive Mode leaks crackable PSK hashes over weak 3DES and modp1024, then Linux privesc.

By Surajit Sen · · 4 min read · 174 views