// SYSTEM_INFO — READ BEFORE PROCEEDING
Welcome to m4rthacks — a personal archive of CTF writeups, hacking notes, tools, and tips & tricks.
You'll find detailed walkthroughs of Capture The Flag challenges across categories like web exploitation, binary exploitation, cryptography, reverse engineering, forensics, and OSINT. Each writeup breaks down the thought process, the tools used, and the steps taken to get the flag.
Feel free to explore, learn, and hack responsibly.
WRITEUPS: 103
Hack The Box — SmartHire (Linux)
We start with a MLflow vulnerability to get a reverse shell as the user svcweb. Then, we exploit a Python script vulnerability to get code execution as root.
Hack The Box — Silentium (Linux)
We begin with a subdomain running Flowise where a password reset vulnerability leaks a temporary token for the user Ben. We use this token to reset the password, log in, and exploit a custom MCP node-load method vulnerability to achieve remote code execution inside a Docker container. After finding plaintext credentials in the container's environment variables, we log in via SSH to the host system. Finally, we forward a local port running Gogs and exploit a command execution vulnerability in the Git service to gain root access.
Hack The Box — Hercules (Windows)
LDAP injection reveals domain users and a password in an Active Directory description. Kerberos access leads to web application machine-key forgery, NTLM capture, shadow credentials, OU manipulation, AD CS ESC3 abuse, and an SPN-less resource-based constrained delegation attack to compromise Administrator.
Hack The Box — Pirate (Windows)
We begin with a low-privileged account on the Pirate domain, which allows us to discover pre-created computer accounts and extract sensitive gMSA passwords. Using these credentials, we gain access to the WEB01 machine. From there, a NTLM relay attack allows us to impersonate Administrator on WEB01. We harvest the credentials of a.white. Finally, we manipulate the SPNs of WEB01 to perform a resource-based constrained delegation attack, allowing us to impersonate Administrator on the domain controller.
Hack The Box — Cobblestone (Linux)
We begin with a SQL injection in a web application, which allows us to read files on the remote system. We can also upload a PHP web shell, which allows us to read the users table in a database. We crack a password and log in via SSH. Finally, we exploit a vulnerability in Cobbler XML-RPC API to get root.
Hack The Box - Helix (Linux)
We find a hidden virtual host flow.helix.htb that runs Apache NiFi 1.21.0, which is vulnerable to CVE-2023-34468. We exploit this vulnerability to get a reverse shell as the user operator. We find the operator's SSH private key and use it to SSH into the target machine. We find that we can run the program helix-maint-console as root, but it requires a privileged maintenance window to be open. We find an OPC UA port that allows us to change some values in the plant, which opens the privileged maintenance window, allowing us to run helix-maint-console and get a root shell.
Hack The Box - Kobold (Linux)
We exploit a remote code execution vulnerability in MCPJam (CVE-2026-23744), getting an initial foothold as the user ben. We write a malicious php script in a PrivateBin folder and include it via the template cookie (CVE-2025-64714), getting a reverse shell in a docker container. The application config file exposes a hardcoded password. We use that password to access the Arcane Docker management portal on port 3552, where we create a new container with root privileges, allowing us to read the host file system and retrieve the root flag.
RINg the Bell (pwn)
Exploit a buffer overflow vulnerability to call the `bell` function and spawn a shell.
The Corroded Crown (pwn)
Exploit a use-after-free vulnerability to leak a libc address, then perform tcache poisoning to overwrite __malloc_hook with the address of a shellcode on the stack, and finally execute the shellcode to get a shell.
The Emptiness Machine (pwn)
Exploit a file stream oriented programming (FSOP) vulnerability to execute system.
The Hinge Whisper (pwn)
Exploit a buffer overflow vulnerability to inject shellcode into the stack and execute it.
Words from the Past (pwn)
After patching out the debugger check, we discover an RWX memory region that directly executes a five-byte payload. We first send a relative CALL instruction to loop back to main, triggering a second stage that maps executable memory right next to libc. Using a relative JMP instruction, we target a one_gadget inside libc to hijack execution flow and spawn a shell. Because the target memory address depends on the child process ID, we brute-force the eight possible PID offsets to reliably gain full control.