Challenge Log

Indexed attack chains from HackTheBox seasons 8, 10, 11 and standalone competitions, plus the pwn.college dojo log below. Full overview on the CTF Achievements page.

12+
Machines PWNED
9
CVEs exploited
3
HTB Seasons
2
AD forests owned
CCTV
HTB Season 10 · Linux / Ubuntu 24.04
EASY Linux PWNED
CVE-2024-51482 · CVE-2025-60787
ZoneMinder admin:admin -> sqlmap time-based SQLi (tid) -> mark:opensesame SSH -> port forward :8765 -> motionEye image_file_name RCE -> root
SQLi blindSSH port forwardCommand injectionDefault credssqlmap
Kobold
HTB Season 10 · Linux / Ubuntu 24.04
MEDIUM Linux PWNED
MCPJam RCE · PrivateBin LFI · Docker escape
MCPJam serverConfig RCE -> ben shell -> PrivateBin template cookie LFI -> PHP webshell -> conf.php (arcane:ComplexP@sswordAdmin1928) -> Portainer -> docker run -v /:/hostfs -> root
MCP RCELFI via cookieDocker escapePortainer
VariaType
HTB Season 10 · Linux / Debian
MEDIUM Linux PWNED
CVE-2025-66034 · CVE-2024-25081 · CVE-2025-47273
vhost fuzz -> .git dump -> gitbot creds -> CVE-2025-66034 CDATA path traversal webshell -> www-data -> CVE-2024-25081 ZIP filename cron -> steve -> sudo CVE-2025-47273 setuptools %2F -> root
git dumpCDATA injectionPath traversalCron abusesudo escape
Overwatch
HTB Season 10 · Windows Server 2022 / AD
HARD Windows AD PWNED
DNS poisoning · Responder capture · SOAP injection
SMB null -> software$ share -> strings .NET: sqlsvc creds -> MSSQL -> linked server SQL07 -> dnstool.py DNS record -> Responder cleartext sqlmgmt -> WinRM -> chisel :8000 -> SOAP KillProcess injection -> local admin
SMB enum.NET analysisDNS poisoningResponderSOAP injectionChisel
Garfield
HTB Season 10 · Windows Server 2019 / AD
HARD Windows AD PWNED
BloodHound ACL · RBCD · RODC Golden Ticket · Key List Attack
BloodHound -> WriteProperty scriptPath -> SYSVOL logon bat -> l.wilson shell -> ForceChangePassword l.wilson_adm -> WinRM -> Ligolo-ng -> RBCD RODC01 -> Mimikatz krbtgt_8245 AES256 -> PRP mod -> RODC Golden Ticket -> Key List Attack -> Admin NTLM -> PTH DC01
BloodHoundACL abuseRBCDLigolo-ngRODC Golden TicketKey List AttackPTH
Pirate
HTB Season 10 · Windows / AD
HARD Windows AD PWNED
PetitPotam NTLM coercion · Kerberoasting · Rubeus
BloodHound -> Kerberoasting -> PetitPotam coercion -> Rubeus ticket manipulation -> Administrator DC01 + WEB01
KerberoastingPetitPotamNTLM coercionRubeusChisel
DevHub
HTB Season 11 · Linux / Ubuntu
MEDIUM Linux PWNED
MCPJam Inspector unauthenticated RCE · hardcoded API key
MCPJam /api/mcp/connect unauthenticated RCE -> mcp-dev -> ps: Jupyter token + OpsMCP :5000 -> chisel tunnel -> Jupyter terminal (analyst) -> user.txt -> server.py hardcoded VALID_API_KEY -> ops._admin_dump ssh_keys -> root SSH -> root.txt
MCPJam RCEProcess enumerationChiselJupyter pivotHardcoded key
Fluffy
HTB Season 8 · Windows / AD
MEDIUM Windows AD PWNED
CVE-2025-24071 (ZIP shortcut NTLM hash leak) · ESC16 ADCS
CVE-2025-24071 ZIP hash leak via Explorer thumbnail -> Shadow Credentials attack -> ESC16 ADCS exploitation -> Domain Admin
CVE-2025-24071Shadow CredentialsESC16 ADCS
Outbound
HTB Season 8 · Linux
MEDIUM Linux PWNED
CVE-2025-49113 (RoundCube RCE) · CVE-2025-27591 (Below privesc)
CVE-2025-49113 RoundCube RCE -> 3DES session decryption -> CVE-2025-27591 Below privilege escalation -> root
RoundCube RCE3DES decryptionPrivesc
Mirage
HTB Season 8 · Windows / AD
HARD Windows AD PWNED
DNS Hijacking · NATS protocol exploitation · RBCD · DCSync
DNS hijacking + NATS exploit -> foothold -> Kerberoasting -> RBCD -> DCSync -> Domain Admin
DNS HijackingNATSKerberoastingRBCDDCSync
Artificial
HTB Season 8 · Linux / ML
MEDIUM Linux PWNED
TensorFlow malicious model RCE · Backrest privesc
Malicious TensorFlow model upload -> RCE -> hash extraction and cracking -> Backrest service privilege escalation -> root
TensorFlow RCEModel poisoningHash crackingBackrest privesc
DarkZero Returns
HTB Season 11 · Windows/Linux · 2 AD forests
HARD Windows AD PWNED
CVE-2026-33937 (Handlebars.js AST injection) · Gitea 1.25 PR approval bypass
Handlebars AST RCE (darkzero) -> .env creds -> bcrypt crack josh -> Kerberos kinit SSO Gitea -> fork + malicious workflow + PR comment (no approval needed) -> svc-runner -> CREATECHILD OU=GiteaMigration + ksu SUID -> root SRV01 -> celia -> DCSync krbtgt EXT -> Golden Ticket + extra-SID RID 1603 -> forest trust -> Backup Operators HTB -> RegSaveKey SAM/SYSTEM/SECURITY -> DC01$ NTLM -> DCSync Administrator HTB -> PTH root.txt
Handlebars RCEAST injectionGitea CI exploitCREATECHILD OUksu SUIDDCSyncGolden TicketSID HistoryForest trustRegSaveKey
Connected
HTB Competition · Linux / FreePBX
MEDIUM Linux USER FLAG
CVE-2025-57819 (FreePBX 16 webshell upload RCE)
CVE-2025-57819 FreePBX RCE -> webshell -> asterisk shell -> incron rule + DAHDI restart chain identified -> init.conf injection (in progress)
CVE-2025-57819FreePBX RCEincron abuseIn progress

Activity Timeline

HTB Season 11 - 2025/2026

Active season. DevHub (Medium) fully compromised via MCP Inspector RCE chain. DarkZero Returns (Hard) - 2 AD forests compromised via Handlebars.js AST injection through to domain admin. Connected (Medium) - user flag obtained, root privesc ongoing.

DevHub - PWNEDDarkZero Returns - PWNEDConnected - USER
HTB Season 10 - 2025

6 machines fully owned across Linux and Windows AD environments.

CCTVKoboldVariaTypeOverwatchGarfieldPirate
HTB Season 8 - 2024/2025

4 machines across Linux ML workloads and Windows AD environments. First large-scale ADCS and RBCD chaining.

FluffyOutboundMirageArtificial
404CTF - 2023 & 2024

Annual French CTF. Focus on web, cryptography, reverse engineering, OSINT and steganography challenges.

pwn.college Dojo Log

Module log for the pwn.college training listed on the CTF Achievements page. Covers shell fundamentals through to x86-64/aarch64 memory exploitation, ahead of the categories validated in the proctored ESGI exam (Memory Errors, Shellcode Injection, Sandboxing, Heap Exploitation).

Pwntools / Linux FundamentalsBash
15+ MODULES COMPLETED
Techniques: Bracket globbing and exclusion globbing, path-relative glob resolution, stdout/stderr/stdin redirection, append vs truncate mode, stream duplication with tee, simultaneous stdout/stderr routing via process substitution >(), environment variable export scoping, command substitution $()
Globbing: matching-with, matching-paths-with, mixing-globs, exclusionary-globbing -> Piping: redirecting-output/errors/input, grepping-stored-results, grepping-live-output, duplicating-piped-data-with-tee, writing-to-multiple-programs, split-piping-stderr-and-stdout -> Variables: setting, multi-word, exporting, storing-command-output -> Man: learning-complex-usage
GlobbingI/O RedirectionteeProcess SubstitutionCommand SubstitutionBash
ARM Dojo - Introduction to ARMaarch64
7 LEVELS COMPLETED
Techniques: 16-bit immediate loading via mov/movk register composition, arithmetic instructions (mul, add, fused multiply-add madd), integer division and modulo (udiv + msub), targeted byte extraction via logical shifts (lsr/lsl). Solved with pwntools' aarch64 assembler and a scripted process harness.
Level 1: 16-bit mov -> Level 2: movk 64-bit composition -> Level 3-4: register arithmetic (mul/add, madd) -> Level 5: division/modulo (udiv/msub) -> Level 6-7: bit shifting for byte isolation
aarch64pwntoolsRegister ArithmeticBit Shifting
Program Security - Computer Memoryx86-64
8 LEVELS COMPLETED
Techniques: Direct memory dereferencing at fixed addresses, single/double/triple pointer chasing, offset-based dereferencing, using the process exit code as a covert validation channel for read values
loading-from-memory -> more-loading-practice -> dereferencing-pointers -> dereferencing-with-offsets -> dereferencing-yourself -> double-dereference -> triple-dereference -> stored-addresses
x86-64 ASMPointer DereferencingMemory Addressing
Program Security - Memory Errors & Assembly Crash Coursex86-64
COMPLETED
Techniques: Stack frame layout analysis, buffer overflow via oversized payload to flip a downstream "win" variable, stack canary and saved-return-address overwrite behavior, register-level arithmetic (imul/add), bitwise parity checks (xor/and), and hand-written NASM routines: non-zero byte counter, in-place string lowercasing via an external per-character callback, and a most-common-byte frequency counter using a 256-entry stack-allocated table
babymem_level1.0/1.1 (stack overflow, canary) -> set-register / add-to-register -> linear-equation-registers -> check-even (parity) -> memory-read -> count_non_zero -> string_lower -> most_common_byte
Stack OverflowStack CanaryNASMRegister ArithmeticCustom ASM Routines
System Security - Hello Hackers & Data DealingsLinux syscalls / SUID Python
7 LEVELS COMPLETED
Techniques: Raw write/exit syscalls without libc, syscall chaining, multi-byte string writes, reading arbitrary-length stdin data straight from a syscall, exploiting SUID Python scripts through password/stdin handling, newline-handling edge cases, reasoning about file-based vs stdin-based input paths
Hello Hackers: writing-output -> chaining-syscalls -> writing-strings -> reading-data | Data Dealings: whats-the-password -> newline-troubles -> reasoning-about-files
SyscallsSUID ExploitationStdin/StdoutLinux Internals
pwn.college Profile Full Achievement Overview