HTB Writeup – Signed
Posted on 2025-10-13
Ticket Forgery & Token Abuse with a service account in Win AD
Capture the flags!
Ticket Forgery & Token Abuse with a service account in Win AD
From bi-directional MSSQL linked servers in to CVE-2024-30088 LPE
Pwn heap UAF, IO FILE exploit, VM, serialization, protobuf
Exploit IKE IPSec via UDP discovery & the SUDO binex privesc
Python SSTI and Django Cache poisoning with Pickle Deserialization
CrushFTP auth bypass (CVE-2025-31161) and Erlang shell manipulation
Next.js auth bypass (CVE-2025-29927) & Hashicorp Terraform abusing