<?xml version="1.0" encoding="UTF-8" ?>
  <rss version="2.0">
    <channel>
      <title>Zor0ark's Blog</title>
      <link>https://z2r.zor0ark.me</link>
      <description>CTF Writeups, Security Research, and DevSecOps.</description>
      <language>en-us</language>
      
        <item>
          <title><![CDATA[THM - After Hours]]></title>
          <link>https://z2r.zor0ark.me/posts/thm-forensics-after-hours</link>
          <guid>https://z2r.zor0ark.me/posts/thm-forensics-after-hours</guid>
          <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
          <description><![CDATA[A hunt through a resort's offline WMI repository that traces a fileless backdoor from a "clean" event-log binding down through Base64-and-UTF16-encoded PowerShell, a reflectively-loaded .NET payload hidden in a custom Win32_HardwareTelemetry class, and a quietly planted net user backdoor account.]]></description>
        </item>
      
        <item>
          <title><![CDATA[HackSmarter - MartiniAD]]></title>
          <link>https://z2r.zor0ark.me/posts/hacksmarter-ad-martiniad</link>
          <guid>https://z2r.zor0ark.me/posts/hacksmarter-ad-martiniad</guid>
          <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
          <description><![CDATA[MartiniAD is an Easy-difficulty Active Directory lab hosted by HackSmarter. The domain `DRY.MARTINI.BARS` is fronted by a single Domain Controller (`DC01`) that permits unauthenticated SMB null/guest sessions. This allows enumeration of a non-default share containing plaintext credentials for a low-privileged domain user. Those credentials are used to Kerberoast a service account, whose cracked password grants a foothold via WinRM. Password reuse between the service account and a linked human Tier-0 admin account (which sits in Domain Admins) then provides full domain compromise, culminating in a DCSync attack to extract the KRBTGT hash.]]></description>
        </item>
      
        <item>
          <title><![CDATA[HackSmarter - ShadowGate]]></title>
          <link>https://z2r.zor0ark.me/posts/hacksmarter-ad-shadowgate</link>
          <guid>https://z2r.zor0ark.me/posts/hacksmarter-ad-shadowgate</guid>
          <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
          <description><![CDATA[Compromising the ShadowGate Active Directory lab through a chained attack path — from AS-REP roasting and ACL abuse via Shadow Credentials, to coercing the Domain Controller with PetitPotam and relaying its authentication into a certificate-based DCSync — culminating in full domain compromise via the krbtgt hash.]]></description>
        </item>
      
        <item>
          <title><![CDATA[HackSmarter - SysAdmins]]></title>
          <link>https://z2r.zor0ark.me/posts/hacksmarter-b2r-sysadmins</link>
          <guid>https://z2r.zor0ark.me/posts/hacksmarter-b2r-sysadmins</guid>
          <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
          <description><![CDATA[In this HackSmarter SysAdmins lab, I chained anonymous FTP disclosure, OSINT, SNMPv3 username and credential reuse, and a critical sudo privilege escalation (CVE-2025-32463) to move from initial access to full root compromise.]]></description>
        </item>
      
        <item>
          <title><![CDATA[HackSmarter - Rotation]]></title>
          <link>https://z2r.zor0ark.me/posts/hacksmarter-cloud-rotation</link>
          <guid>https://z2r.zor0ark.me/posts/hacksmarter-cloud-rotation</guid>
          <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
          <description><![CDATA[This is a Medium AWS Challenge Lab, it is an IAM privilege escalation via access key rotation abuse.]]></description>
        </item>
      
        <item>
          <title><![CDATA[HTB - The Ashen Field]]></title>
          <link>https://z2r.zor0ark.me/posts/htb-crypto-ashen-field</link>
          <guid>https://z2r.zor0ark.me/posts/htb-crypto-ashen-field</guid>
          <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
          <description><![CDATA[Exploit a standard implementation of the Hidden Field Equations protocol via Groebner Basis]]></description>
        </item>
      
        <item>
          <title><![CDATA[HTB - False Witness]]></title>
          <link>https://z2r.zor0ark.me/posts/htb-crypto-false-witness</link>
          <guid>https://z2r.zor0ark.me/posts/htb-crypto-false-witness</guid>
          <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
          <description><![CDATA[Predictable hash function that results in breaking the decisional problem by enumerating all group elements.]]></description>
        </item>
      
        <item>
          <title><![CDATA[HTB - Fractured Seal]]></title>
          <link>https://z2r.zor0ark.me/posts/htb-crypto-fractured-seal</link>
          <guid>https://z2r.zor0ark.me/posts/htb-crypto-fractured-seal</guid>
          <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
          <description><![CDATA[Recover RSA private key given leaked information from PEM file using Coppersmith's small roots]]></description>
        </item>
      
        <item>
          <title><![CDATA[HTB - Thermal Receipt]]></title>
          <link>https://z2r.zor0ark.me/posts/htb-hardware-thermal-receipt</link>
          <guid>https://z2r.zor0ark.me/posts/htb-hardware-thermal-receipt</guid>
          <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
          <description><![CDATA[Connect to PRET PJL mode, enumerate device files, recover the latest journal receipt, follow the NVRAM reference, and read NVRAM to recover the flag.]]></description>
        </item>
      
        <item>
          <title><![CDATA[THM - BankGPT]]></title>
          <link>https://z2r.zor0ark.me/posts/thm-ai-bankgpt</link>
          <guid>https://z2r.zor0ark.me/posts/thm-ai-bankgpt</guid>
          <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
          <description><![CDATA[This writeup demonstrates how to bypass a banking AI's security guardrails by chaining context manipulation and audit pretexting to ultimately extract hidden API keys through a subtle "Leakage in Refusal" vulnerability.]]></description>
        </item>
      
        <item>
          <title><![CDATA[HTB - Caldrin's Day Away]]></title>
          <link>https://z2r.zor0ark.me/posts/htb-blockchain-caldrins-day-away</link>
          <guid>https://z2r.zor0ark.me/posts/htb-blockchain-caldrins-day-away</guid>
          <pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate>
          <description><![CDATA[This writeup details how to drain an ERC-4626-style vault in HTB's "Caldrin's Day Away" challenge by leveraging a massive flash loan to manipulate an AMM reserve, feeding the poisoned data through a flawed oracle to artificially inflate the vault's share price.]]></description>
        </item>
      
        <item>
          <title><![CDATA[HTB - Bought Riot]]></title>
          <link>https://z2r.zor0ark.me/posts/htb-cloud-bought-riot</link>
          <guid>https://z2r.zor0ark.me/posts/htb-cloud-bought-riot</guid>
          <pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate>
          <description><![CDATA[In this medium-difficulty Cloud challenge, you must trace the origins and financial backing of a malicious rumor to stop a framed Stormbound captain from being wrongfully stripped of their crucial guard post.]]></description>
        </item>
      
        <item>
          <title><![CDATA[HTB - Cadence in the Cord]]></title>
          <link>https://z2r.zor0ark.me/posts/htb-hardware-cadence-in-the-cord</link>
          <guid>https://z2r.zor0ark.me/posts/htb-hardware-cadence-in-the-cord</guid>
          <pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate>
          <description><![CDATA[Cadence in the Cord is a Sigrok/UART challenge where the apparent serial message only serves as a guide to a second, covert channel encoded in the inter-frame timing—short gaps as 0, long gaps as 1.]]></description>
        </item>
      
        <item>
          <title><![CDATA[HTB - Line Tap]]></title>
          <link>https://z2r.zor0ark.me/posts/htb-ics-line-tap</link>
          <guid>https://z2r.zor0ark.me/posts/htb-ics-line-tap</guid>
          <pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate>
          <description><![CDATA[Line Tap demonstrates how a forgotten Telnet maintenance interface on an ICS host can be turned into instant, unauthenticated root via CVE-2026-24061 by abusing the NEW-ENVIRON USER=-f root trick, making the challenge a clean lesson in legacy service risk, argument injection, and critical exposure in operational technology environments.]]></description>
        </item>
      
        <item>
          <title><![CDATA[HTB - Corroded Crown]]></title>
          <link>https://z2r.zor0ark.me/posts/htb-pwn-corroded-crown</link>
          <guid>https://z2r.zor0ark.me/posts/htb-pwn-corroded-crown</guid>
          <pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate>
          <description><![CDATA[Corroded Crown from the Cyber Apocalypse 2026 CTF was an easy Pwn challenge vulnerable to a classic Use-After-Free (UAF) due to un-cleared dangling pointers and missing state validation. By leveraging an unsorted bin leak to bypass ASLR and poisoning the unencrypted GLIBC 2.31 tcache bins, we successfully redirected __free_hook to system(). Triggering a final memory cleanup operation immediately spawned an interactive shell to capture the flag.]]></description>
        </item>
      
        <item>
          <title><![CDATA[HTB - Heavy Is The Krown]]></title>
          <link>https://z2r.zor0ark.me/posts/htb-pwn-heavy-is-the-krown</link>
          <guid>https://z2r.zor0ark.me/posts/htb-pwn-heavy-is-the-krown</guid>
          <pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate>
          <description><![CDATA[Heavy Is The Krown is a hard Linux kernel exploitation challenge from HTB Cyber Apocalypse 2026 that revolves around a kmalloc-512 Use-After-Free in a custom `/dev/krown` driver, letting an attacker hijack slab objects shared by “lord” and “vassal” structures. By overlaying a freed vassal with procfs `seq_file` data to defeat KASLR and then abusing the dangling pointer to overwrite `modprobe_path`, the exploit script gains root execution via a crafted helper script and extracts the flag.]]></description>
        </item>
      
        <item>
          <title><![CDATA[HTB - The Emptiness Machine]]></title>
          <link>https://z2r.zor0ark.me/posts/htb-pwn-the-emptiness-machine</link>
          <guid>https://z2r.zor0ark.me/posts/htb-pwn-the-emptiness-machine</guid>
          <pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate>
          <description><![CDATA[The Emptiness Machine is a modern FSOP-based pwn challenge from Hack The Box’s Cyber Apocalypse 2026 that demonstrates how glibc file stream structures in a fully mitigated Linux x86_64 environment can still be abused for powerful exploitation. By combining a controlled leak from stdout to defeat ASLR with a carefully aligned House of Apple 2 attack on stderr, the solver script reliably turns program teardown (_IO_flush_all()) into a remote shell and captures the flag.]]></description>
        </item>
      
        <item>
          <title><![CDATA[HTB - The Hinge Whisper]]></title>
          <link>https://z2r.zor0ark.me/posts/htb-pwn-the-hinge-whisper</link>
          <guid>https://z2r.zor0ark.me/posts/htb-pwn-the-hinge-whisper</guid>
          <pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate>
          <description><![CDATA[The Hinge Whisper ultimately illustrates how a single, well-placed information leak paired with an executable, unprotected stack can unravel modern mitigations, turning a lore-flavored hatch service into a clean, textbook shellcode entry point. By leaking the exact stack buffer address, carefully shaping a compact execve payload that respects stack dynamics, and overwriting the function’s return address to pivot execution into our own bytes, we transform Rin’s quiet investigation of Maelor’s sealed strongbox into a full compromise that opens both the hatch and the path to the hidden flag.]]></description>
        </item>
      
        <item>
          <title><![CDATA[HTB - Words from the Past]]></title>
          <link>https://z2r.zor0ark.me/posts/htb-pwn-words-ft-past</link>
          <guid>https://z2r.zor0ark.me/posts/htb-pwn-words-ft-past</guid>
          <pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate>
          <description><![CDATA[Words from the Past is a x86_64 Linux pwn challenge centered around constrained 5-byte micro-shellcode execution across a two-stage state machine. The binary implements multiple layers of anti-analysis and anti-debugging protections, including timing anomaly detection (rdtsc), library preloading detection, ptrace detection (/proc/self/status parsing), and execution inside a forked child process.

The crux of the challenge relies on mastering x86_64 32-bit relative branching (call rel32 and jmp rel32), Linux memory allocation behavior (mmap hints with and without MAP_FIXED), register state manipulation, and overcoming lightweight 3-bit Process ID (PID) entropy (pid & 7) to redirect control flow to a glibc one_gadget.]]></description>
        </item>
      
    </channel>
  </rss>