HTB Writeup – Signed
Posted on 2025-10-13
Ticket Forgery & Token Abuse with a service account in Win AD
Hackthebox CTF writeups.
Ticket Forgery & Token Abuse with a service account in Win AD
From bi-directional MSSQL linked servers in to CVE-2024-30088 LPE
Exploit IKE IPSec via UDP discovery & the SUDO binex privesc
Python SSTI and Django Cache poisoning with Pickle Deserialization
CrushFTP auth bypass (CVE-2025-31161) and Erlang shell manipulation
Next.js auth bypass (CVE-2025-29927) & Hashicorp Terraform abusing
CVE-2024-47533: Cobbler XML-RPC flaw to steal root files