<Tag: cyberapocalypse2026 />
Found 13 posts with this tag.
HTB - The Ashen Field
Exploit a standard implementation of the Hidden Field Equations protocol via Groebner Basis
HTB - False Witness
Predictable hash function that results in breaking the decisional problem by enumerating all group elements.
HTB - Fractured Seal
Recover RSA private key given leaked information from PEM file using Coppersmith's small roots
HTB - Thermal Receipt
Connect to PRET PJL mode, enumerate device files, recover the latest journal receipt, follow the NVRAM reference, and read NVRAM to recover the flag.
HTB - Caldrin's Day Away
This writeup details how to drain an ERC-4626-style vault in HTB's "Caldrin's Day Away" challenge by leveraging a massive flash loan to manipulate an AMM reserve, feeding the poisoned data through a flawed oracle to artificially inflate the vault's share price.
HTB - Bought Riot
In this medium-difficulty Cloud challenge, you must trace the origins and financial backing of a malicious rumor to stop a framed Stormbound captain from being wrongfully stripped of their crucial guard post.
HTB - Cadence in the Cord
Cadence in the Cord is a Sigrok/UART challenge where the apparent serial message only serves as a guide to a second, covert channel encoded in the inter-frame timing—short gaps as 0, long gaps as 1.
HTB - Line Tap
Line Tap demonstrates how a forgotten Telnet maintenance interface on an ICS host can be turned into instant, unauthenticated root via CVE-2026-24061 by abusing the NEW-ENVIRON USER=-f root trick, making the challenge a clean lesson in legacy service risk, argument injection, and critical exposure in operational technology environments.
HTB - Corroded Crown
Corroded Crown from the Cyber Apocalypse 2026 CTF was an easy Pwn challenge vulnerable to a classic Use-After-Free (UAF) due to un-cleared dangling pointers and missing state validation. By leveraging an unsorted bin leak to bypass ASLR and poisoning the unencrypted GLIBC 2.31 tcache bins, we successfully redirected __free_hook to system(). Triggering a final memory cleanup operation immediately spawned an interactive shell to capture the flag.
HTB - Heavy Is The Krown
Heavy Is The Krown is a hard Linux kernel exploitation challenge from HTB Cyber Apocalypse 2026 that revolves around a kmalloc-512 Use-After-Free in a custom `/dev/krown` driver, letting an attacker hijack slab objects shared by “lord” and “vassal” structures. By overlaying a freed vassal with procfs `seq_file` data to defeat KASLR and then abusing the dangling pointer to overwrite `modprobe_path`, the exploit script gains root execution via a crafted helper script and extracts the flag.
HTB - The Emptiness Machine
The Emptiness Machine is a modern FSOP-based pwn challenge from Hack The Box’s Cyber Apocalypse 2026 that demonstrates how glibc file stream structures in a fully mitigated Linux x86_64 environment can still be abused for powerful exploitation. By combining a controlled leak from stdout to defeat ASLR with a carefully aligned House of Apple 2 attack on stderr, the solver script reliably turns program teardown (_IO_flush_all()) into a remote shell and captures the flag.
HTB - The Hinge Whisper
The Hinge Whisper ultimately illustrates how a single, well-placed information leak paired with an executable, unprotected stack can unravel modern mitigations, turning a lore-flavored hatch service into a clean, textbook shellcode entry point. By leaking the exact stack buffer address, carefully shaping a compact execve payload that respects stack dynamics, and overwriting the function’s return address to pivot execution into our own bytes, we transform Rin’s quiet investigation of Maelor’s sealed strongbox into a full compromise that opens both the hatch and the path to the hidden flag.
HTB - Words from the Past
Words from the Past is a x86_64 Linux pwn challenge centered around constrained 5-byte micro-shellcode execution across a two-stage state machine. The binary implements multiple layers of anti-analysis and anti-debugging protections, including timing anomaly detection (rdtsc), library preloading detection, ptrace detection (/proc/self/status parsing), and execution inside a forked child process. The crux of the challenge relies on mastering x86_64 32-bit relative branching (call rel32 and jmp rel32), Linux memory allocation behavior (mmap hints with and without MAP_FIXED), register state manipulation, and overcoming lightweight 3-bit Process ID (PID) entropy (pid & 7) to redirect control flow to a glibc one_gadget.