root@z2r:~/blog/category#ls -la

<All Posts />

Browse all cybersecurity writeups, tool releases, and research.

> grep -i
CTF WRITEUPSSATELLITE

HTB - First Contact

HackTheBoxEasy

In this Hack The Box challenge, I had to act as a backup pass prediction system for a ground station. By parsing Two-Line Element (TLE) sets and calculating satellite passes above 30 degrees of elevation using Python's `skyfield` library, I wrote an automated solver to determine upcoming visibility windows, overcome strict timing checks, and retrieve the flag.

August 27, 20266 min read
CTF WRITEUPSWEB

WebVerse Pro | Labs - BowBuy

WebVerse ProEasy

A premium archery store whose new-member '\$300 welcome credit' is applied at checkout through a check-then-act race. The redeem endpoint reads a one-time flag, pauses to 'authorize', then adds the credit and sets the flag — so concurrent redeems all pass the check and each adds \$300. By stacking the credit past an item's price and placing the order, the confirmation page renders the flag as a gift.

August 23, 20265 min read
CTF WRITEUPSWEB

WebVerse Pro | Challenge - VelvetRope

WebVerse ProEasy

I found that Gilt & Grain's Members Portal authenticated against an unescaped LDAP filter, letting me bypass login entirely with a wildcard payload that matched any directory entry instead of verifying real credentials. The bug came down to the app treating "a matching record was found" as proof of a correct password, rather than performing an actual LDAP bind to check it.

August 17, 20265 min read
CTF WRITEUPSWEB

WebVerse Pro | Challenge - Walkthrough

WebVerse ProEasy

A missing server-side MFA enforcement check allowed full authentication bypass — sessions were treated as fully authenticated immediately after password verification, letting an attacker skip the 6-digit OTP step entirely and access sensitive client data.

August 16, 20265 min read
CTF WRITEUPSFORENSICS

THM - After Hours

TryHackMeMedium

A hunt through a resort's offline WMI repository that traces a fileless backdoor from a "clean" event-log binding down through Base64-and-UTF16-encoded PowerShell, a reflectively-loaded .NET payload hidden in a custom Win32_HardwareTelemetry class, and a quietly planted net user backdoor account.

August 8, 202613 min read
CTF WRITEUPSACTIVE DIRECTORY

HackSmarter - MartiniAD

HackSmarterEasy

MartiniAD is an Easy-difficulty Active Directory lab hosted by HackSmarter. The domain `DRY.MARTINI.BARS` is fronted by a single Domain Controller (`DC01`) that permits unauthenticated SMB null/guest sessions. This allows enumeration of a non-default share containing plaintext credentials for a low-privileged domain user. Those credentials are used to Kerberoast a service account, whose cracked password grants a foothold via WinRM. Password reuse between the service account and a linked human Tier-0 admin account (which sits in Domain Admins) then provides full domain compromise, culminating in a DCSync attack to extract the KRBTGT hash.

August 6, 202610 min read
[< Prev][Next >]