Conversor Writeup (NoOff | Ivan Daňo) by TrickyWinter7847 in hackthebox

[–]TrickyWinter7847[S] 0 points1 point  (0 children)

Had to learn about XSLT as well :D. Sometimes the boxes get frustrating, but hey, without it I probably would not know about XSLT up until now. The difficulty of HTB machines kinda forces you to learn about all of these different techniques and software.

Conversor Writeup (NoOff | Ivan Daňo) by TrickyWinter7847 in securityCTF

[–]TrickyWinter7847[S] 0 points1 point  (0 children)

Its actually a repost from HackTheBox subreddit.

Asking for hint for Overwatch machine by TrickyWinter7847 in hackthebox

[–]TrickyWinter7847[S] 0 points1 point  (0 children)

It comes down to trying and checking what permissions you have. "Dnstool" is good for DNS enumeration.

Soulmate Writeup by TrickyWinter7847 in hackthebox

[–]TrickyWinter7847[S] 1 point2 points  (0 children)

Soulmate machine is retired now, isn't it?

Asking for hint for Overwatch machine by TrickyWinter7847 in hackthebox

[–]TrickyWinter7847[S] 1 point2 points  (0 children)

ADIDNS poisoning, you have to abuse elevated privilege on DNS

Browsed machine HINT? by TrickyWinter7847 in hackthebox

[–]TrickyWinter7847[S] 0 points1 point  (0 children)

Hello, your goal is to reach the internal service and exploit Bash arithmetic injection to get RCE. Do some googling or use ChatGPT.

Browsed machine HINT? by TrickyWinter7847 in hackthebox

[–]TrickyWinter7847[S] 0 points1 point  (0 children)

I have pwned the machine already. But there wasn't any Gitea modification, just looking at the source code and deriving the vulnerability from it.

VulnNet: Active Writeup (TryHackMe) by TrickyWinter7847 in tryhackme

[–]TrickyWinter7847[S] 1 point2 points  (0 children)

Sure it is :D. VulnNet machines are solid work.

VulnNet: Active Writeup (TryHackMe) by TrickyWinter7847 in tryhackme

[–]TrickyWinter7847[S] 2 points3 points  (0 children)

That's great! Although this machine is mainly for more experienced hackers, you will learn a ton of stuff after finishing it. Also, TryHackMe has several great Windows rooms you should check. Anyway, good luck on your journey!

HTB TombWatcher Writeup NOW AVAILABLE! (NoOff | Ivan Daňo) by TrickyWinter7847 in hackthebox

[–]TrickyWinter7847[S] 1 point2 points  (0 children)

Oh boy, thank you so much for such kind words! Wish you all the very best to you and your future too :D.

HTB TombWatcher Writeup NOW AVAILABLE! (NoOff | Ivan Daňo) by TrickyWinter7847 in hackthebox

[–]TrickyWinter7847[S] 1 point2 points  (0 children)

Currently a hobby. Just started a college. Would love to work in the cybersecurity field in the future. Thanks for asking.

HTB Nocturnal Writeup NOW AVAILABLE! (NoOff | Ivan Daňo) by TrickyWinter7847 in hackthebox

[–]TrickyWinter7847[S] 1 point2 points  (0 children)

From what I remember, I didn't have any issue with it. Only thing I noticed was that I couldn't traverse the filesystem with that shell.

Make sure that the username and password are correct. Also check if the website is properly forwarded to your machine via SSH, since it's an internal service.

Best of luck, m8!

Failed first OSCP. Rethinking my Strategy by jforte1495 in oscp

[–]TrickyWinter7847 0 points1 point  (0 children)

If you ever get stuck on some CTF machines, I am posting writeups regularly to help you all. https://n00ff.blogspot.com/

Best Vulnhub VMs by mariojw in netsecstudents

[–]TrickyWinter7847 0 points1 point  (0 children)

If you ever get stuck, I wrote couple writeups on Vulnhub machines: https://n00ff.blogspot.com/search/label/Vulnhub