// SYSTEM_INFO — READ BEFORE PROCEEDING
Welcome to m4rthacks — a personal archive of CTF writeups, hacking notes, tools, and tips & tricks.
You'll find detailed walkthroughs of Capture The Flag challenges across categories like web exploitation, binary exploitation, cryptography, reverse engineering, forensics, and OSINT. Each writeup breaks down the thought process, the tools used, and the steps taken to get the flag.
Feel free to explore, learn, and hack responsibly.
WRITEUPS: 103
Hack The Box - Fries (Windows)
We start with supplied credentials that are valid only for the web applications. A misconfigured PWM instance and exposed Gitea repository lead to PostgreSQL command execution and a foothold inside the Docker environment. Abuse of the Docker TLS API yields root access to the Linux host, allowing recovery of the PWM configuration and Active Directory service account credentials. Finally, certipy reveals an AD CS misconfiguration that can be exploited through ESC6/ESC7 to obtain Domain Administrator privileges.
Hack The Box - Logging (Windows)
We start with credentials for the user `wallace.everette`. We enumerate the machine and find a log file that contains the credentials for the user `svc_recovery`. We use those credentials to perform a shadow credentials attack on the machine account `msa_health$` to get its nthash. We use that to get a shell on the machine. We abuse a DLL hijacking vulnerability in the UpdateMonitor program to become another user. Finally, we abuse a WSUS client that connects to `wsus.logging.htb` to run commands as admin.
Hack The Box - CCTV (Linux)
ZoneMinder time-based SQL injection reveals mark credentials. After SSH login, we find the MotionEye configuration files with the admin password. Finally, a MotionEye RCE vulnerability leads to root.
Hack The Box — DevArea (Linux)
Anonymous FTP and Apache CXF SSRF expose secrets that unlock Hoverfly RCE. A leaked config file yields the Flask secret and admin credentials. Session forgery opens the syswatch dashboard as admin. A command injection flaw then grants code execution as syswatch. From there, symlink abuse in syswatch leads to root compromise.
Hack The Box — WingData (Linux)
CVE-2025-47812 in Wing FTP Server v7.4.3 allows to get a reverse shell as wingftp. Some user data are contained in XML files and we can crack the password of user wacky and login via SSH. User wacky can run a Python script with sudo privileges. The script uses the tar package and `tar.extractall()`. CVE-2025-4517 allows to modify existing files, so we can modify /etc/passwd to add a root user.
Hack The Box — NanoCorp (Windows)
A File Explorer vulnerability (CVE-2025-24071) allows to steal the credentials of a user. That user can change the password of another user which has shell access on the machine. Finally we can exploit a vulnerability in Checkmk (CVE-2024-0670) to get a reverse shell as nt authority/system.
Hack The Box — VariaType (Linux)
Fonttools file write via CVE-2025-66034 exposes portal credentials, FontForge archive handling yields RCE as steve, and a setuptools path traversal in a sudo-allowed validator script leads to root.
Hack The Box — Facts (Linux)
A CMS role escalation exposes S3 credentials, a protected SSH key gets cracked, and a sudo-allowed Facter invocation leads to root.
Hack The Box — Interpreter (Linux)
A vulnerable bash routine runner turns a path-controlled argument into RCE, leading to a reverse shell and full root compromise.
Hack The Box - MonitorsFour (Windows)
Type juggling bypasses API token checks, exposed credentials and Cacti username enumeration lead to authenticated RCE, and a Docker Desktop API exposure provides a host filesystem escape to the Windows root flag.
Hack The Box — Pterodactyl (Linux)
Pterodactyl Panel LFI to config read, PEAR argument injection to RCE, MySQL hash cracking for SSH, and chained udisksd escalation via PAM CVE to root.
Hack The Box — Bad Grades (pwn)
Exploit a double-based buffer overflow to bypass a stack canary by taking advantage of scanf reading '-' without storing it, then build a ROP chain to get a shell using the provided libc.