root@z2r:~/blog/category#ls -la

<All Posts />

Browse all cybersecurity writeups, tool releases, and research. (Page 3)

> grep -i
CTF WRITEUPSHARDWARE

HTB - Thermal Receipt

HackTheBoxEasy

Connect to PRET PJL mode, enumerate device files, recover the latest journal receipt, follow the NVRAM reference, and read NVRAM to recover the flag.

August 5, 20265 min read
CTF WRITEUPSAI/LLM

THM - BankGPT

TryHackMeEasy

This writeup demonstrates how to bypass a banking AI's security guardrails by chaining context manipulation and audit pretexting to ultimately extract hidden API keys through a subtle "Leakage in Refusal" vulnerability.

August 5, 20265 min read
CTF WRITEUPSBLOCKCHAIN

HTB - Caldrin's Day Away

HackTheBoxEasy

This writeup details how to drain an ERC-4626-style vault in HTB's "Caldrin's Day Away" challenge by leveraging a massive flash loan to manipulate an AMM reserve, feeding the poisoned data through a flawed oracle to artificially inflate the vault's share price.

August 4, 202610 min read
CTF WRITEUPSCLOUD

HTB - Bought Riot

HackTheBoxMedium

In this medium-difficulty Cloud challenge, you must trace the origins and financial backing of a malicious rumor to stop a framed Stormbound captain from being wrongfully stripped of their crucial guard post.

August 4, 20264 min read
CTF WRITEUPSHARDWARE

HTB - Cadence in the Cord

HackTheBoxEasy

Cadence in the Cord is a Sigrok/UART challenge where the apparent serial message only serves as a guide to a second, covert channel encoded in the inter-frame timing—short gaps as 0, long gaps as 1.

July 30, 20266 min read
CTF WRITEUPSICS/OT

HTB - Line Tap

HackTheBoxEasy

Line Tap demonstrates how a forgotten Telnet maintenance interface on an ICS host can be turned into instant, unauthenticated root via CVE-2026-24061 by abusing the NEW-ENVIRON USER=-f root trick, making the challenge a clean lesson in legacy service risk, argument injection, and critical exposure in operational technology environments.

July 30, 20266 min read