Security Exploits & Vulnerabilities

Standout exploitation techniques pulled from active HackTheBox seasons and lab work - full per-machine writeups, attack chains and CVE references live on the CTF Achievements page and the challenge log; binary exploitation fundamentals (ARM64, x86-64 memory, syscalls) are in the pwn.college dojo log.

CVE-2026-33937

Cross-Forest AD

Handlebars.js AST type confusion RCE on DarkZero Returns (HTB Hard), chained through a Gitea CI approval bypass and a forest trust abuse (Golden Ticket + SID History) to Domain Admin across two AD forests.

AST Injection Gitea CI Forest Trust

Triple-CVE Chain

Web to Root

VariaType (HTB Medium): fonttools CDATA injection + path traversal (CVE-2025-66034) for a webshell, then a FontForge ZIP-filename command injection (CVE-2024-25081) via cron, then a setuptools path traversal (CVE-2025-47273) for root SSH.

CDATA Injection Cron Abuse sudo Escape

RODC Golden Ticket

AD Attack

Garfield (HTB Hard): BloodHound ACL abuse into a logon script foothold, RBCD onto an RODC, then a Key List Attack via a forged RODC Golden Ticket to recover the Administrator NTLM hash for Pass-the-Hash on the DC.

RBCD Golden Ticket Key List Attack

DNS Poisoning

MSSQL / AD

Overwatch (HTB Hard): credentials pulled from a .NET binary led to an unresolved MSSQL linked server, poisoned via a forged DNS record to capture cleartext creds with Responder, then a SOAP/WCF command injection for root.

Linked Server Responder SOAP Injection

Docker Escape

Container Breakout

Kobold (HTB Medium): MCP serverConfig command injection for a foothold, an LFI via a cookie-controlled template path for Portainer credentials, then a privileged container mount (-v /:/hostfs) for root on the host.

MCP RCE LFI Portainer

PetitPotam Coercion

AD Attack

Pirate (HTB Hard): BloodHound-guided enumeration, Kerberoasting for service credentials, then a PetitPotam NTLM coercion combined with Rubeus ticket manipulation to reach Domain Admin.

Kerberoasting NTLM Coercion Rubeus

Fork Bomb

DoS Attack

Developed fork bomb implementations in both Bash and C language for system resource exhaustion and denial of service testing.

Bash C DoS

OS Hardening

Defense

Windows and Linux system hardening based on CIS benchmarks and ANSSI GNU/Linux security recommendations. NGINX/Apache2 server security configuration.

CIS ANSSI NGINX

Infrastructure Deployment

Experience in deploying and securing various infrastructure components:

Network Security

  • pfSense Firewall Configuration
  • AdGuard Home DNS Filtering
  • Suricata IDS/IPS Deployment
  • Wazuh SIEM Integration

Application Security

  • Passbolt Password Manager
  • FireflyIII Financial Platform
  • PKI Certificate Authority
  • GLPI Asset Management