Writeups
5 writeups
Connected Writeup - HackTheBox
Exploit MongoDB misconfiguration with unauthenticated access to enumerate databases and retrieve credentials, ultimately gaining root on an easy Linux box.
SmartHire Writeup - HackTheBox
SSTI via resume upload, exploiting a Flask/Jinja2 template injection in a smart hiring app to achieve RCE and capture the flag.
Helix Writeup - HackTheBox
A writeup covering enumeration, initial access, lateral movement, and privilege escalation through misconfigurations and internal service abuse.