Sign in

0xdf

@0xdf.bsky.social
1K followers 254 following 389 posts

Principal Training Architect @ HackTheBox CTF Addict "Potentially a legit researcher" he/him Website: 0xdf.gitlab.io YouTube: www.youtube.com/c/0xdf0xdf Twitter: 0xdf_ Discord: 0xdf Mastadon: 0xdf@infosec.exchange

PostsRepliesMedia
0xdf @0xdf.bsky.social · 26/09/2026
SmartHire from HackTheBox features an MLflow instance with creds from the docs, pickle deserialization in a PyFunc model for RCE, and a Python path configuration file dropped into a writable plugin directory for root.
0xdf.gitlab.io
HTB: SmartHire
SmartHire is a Linux box hosting an AI-powered HR site that trains AI models to score resumes. I’ll find an MLflow instance on a subdomain behind HTTP basic auth, and get in with example credentials from the MLflow documentation. From there I’ll abuse a deserialization vulnerability in how MLflow loads PyFunc models, overwriting the pickled model over the artifacts API so that my code runs the next time the site scores a resume, giving a shell. To escalate, I’ll find a script that runs with sudo and adds a writable directory to the Python path. I’ll craft a malicious path configuration file, which Python executes as code when the script starts.
020
0xdf @0xdf.bsky.social · 21/09/2026
Hercules from HackTheBox features LDAP injection with a rate limit bypass, an ASP.NET machine key leak to forge auth cookies, odt auth coercion, shadow credentials, ESC3, and S4U2self abuse for the domain.
0xdf.gitlab.io
HTB: Hercules
Hercules is a Windows domain controller running an ASP.NET site. I’ll slip past the filters to an LDAP injection, and with a rate limit bypass, I’ll brute force the directory and pull a default password out of a user description. An arbitrary file read in the download handler leaks the machine key from the site’s configuration, which lets me forge an authentication cookie carrying the Web Administrators role and unlock the file upload. An uploaded document coerces an authentication attempt that cracks, opening a long chain of Active Directory abuse that runs through shadow credentials, moving an account into an organizational unit to bring it under rights I already hold, and ESC3 against the certificate authority. Finally I’ll trigger a cleanup task that strips admin protections from a privileged account, then abuse delegation to reach the machine account that can dump the domain.
021
0xdf @0xdf.bsky.social · 15/09/2026
Ghostlink from HackTheBox has an open MQTT broker used to coerce auth, NTLM relay into a hidden site, file read to a KeePass DB, a Gogs symlink write for a shell, and ADCS ESC11 for the domain.
0xdf.gitlab.io
HTB: Ghostlink
Ghostlink is built around a fictional threat group running its operations on a Windows domain controller, with a message broker quietly announcing infrastructure I can’t otherwise reach. I’ll subscribe to that broker anonymously to find internal sites, then publish a tampered health check message to coerce the host into authenticating to me. Relaying that authentication gets me into a restricted file sharing site, where an unchecked path in the download endpoint gives arbitrary file read, leading to a user’s registry hive and a password database. Those credentials unlock the Gogs instance, where a symbolic link flaw in the content API lets me overwrite a Git config and get a shell on the virtual machine hosting it. I’ll crack a password hash from the Gogs database to reach a domain account, and finish by relaying coerced machine account authentication to the certificate authority to get a certificate for the domain controller and dump the domain. In Beyond Root, I’ll show why the other certificate services path never had a chance, and reverse engineer the file sharing application.
141
0xdf @0xdf.bsky.social · 12/09/2026
Silentium from HackTheBox features a password reset token leak in Flowise leading to account takeover, then RCE via its custom MCP node. Container env vars give an SSH password, and a symlink bug in Gogs gets root.
0xdf.gitlab.io
HTB: Silentium
Silentium hosts an investment firm website with a staging subdomain running Flowise, a visual AI agent builder. I’ll abuse an unauthenticated forgot password endpoint that returns the reset token directly in the API response to take over an account. From there I’ll exploit a node that passes user-supplied configuration to the JavaScript Function constructor, getting code execution as root inside a Docker container. The container’s environment variables leak a password that is reused for SSH on the host. To escalate, I’ll find an internal Gogs instance running as root and abuse its handling of symbolic links in the file write API to drop an authorized keys file into root’s home directory. In Beyond Root, I’ll reverse engineer the Flowise front end Vite application.
240
0xdf @0xdf.bsky.social · 05/09/2026
Pirate from HackTheBox is an AD assume-breach box: pre-Windows 2000, gMSA password, NTLMv1 coerce-and-relay for RBCD, and SPN-jacking to impersonate the domain admin. Unintended path using RemotePotato0 to cross-session relay.
0xdf.gitlab.io
HTB: Pirate
Pirate is a Windows assume-breach Active Directory box, providing credentials for a low-privileged domain account. Enumerating the domain, I’ll find pre-Windows 2000 machine accounts whose passwords match their hostnames, and one belongs to a group allowed to read group-managed service account passwords, which gets me a WinRM shell on the domain controller. From there I’ll tunnel to an internal web server and coerce its machine account into authenticating, then downgrade and relay that authentication to configure resource-based constrained delegation and take over that host as Administrator. Dumping its secrets exposes a user who can reset another account’s password, and that account has constrained delegation I’ll abuse with an SPN-jacking attack, moving a service principal name onto the domain controller and switching service classes to impersonate the domain administrator. In Beyond Root, I’ll show an alternate cross-session relay with RemotePotato0.
032
0xdf @0xdf.bsky.social · 02/09/2026
With no HackTheBox retirements for the last two weeks, here's Nexus, an non-competitive releasei featuring Krayin CRM and a deep dive into Git internals. Root was harder than easy for sure.
0xdf.gitlab.io
HTB: Nexus
Nexus hosts a Krayin CRM instance backed by a Gitea server. I’ll dig through a public Gitea repository to find a Docker Compose file and environment configuration, recovering credentials to log into Krayin. From there, I’ll exploit an authenticated arbitrary file upload in Krayin’s TinyMCE endpoint to drop a PHP webshell and get a foothold as the web user. Krayin’s environment file leaks a database password that is reused for a system account, giving a shell as that user. To escalate to root, I’ll abuse a template sync script that runs as root, chaining Git’s permissive safe.directory setting, its use of ls-tree instead of checkout, and an unsanitized path join to poison a Gitea repository with a directory-traversal tree object and write a file anywhere on disk. In Beyond Root, I’ll cover an unauthenticated installer bypass that takes over the admin account, and how the Laravel debug bar leaks internal application details.
011
0xdf @0xdf.bsky.social · 15/08/2026
Cobblestone from HackTheBox features a second-order SQL injection, stored XSS to hijack an admin session, and Twig template injection for code execution under AppArmor. Then multiple paths to root through Cobbler running as root.
0xdf.gitlab.io
HTB: Cobblestone
Cobblestone hosts a cluster of Minecraft-themed PHP sites across a few subdomains. I’ll find a second-order SQL injection, use it to read the application source, and abuse stored cross-site scripting to hijack an admin session. That admin access opens up a Twig template injection for code execution as the web user, which is locked down hard by AppArmor. I’ll pull credentials from the database and crack one to get an SSH login as the next user. From there I’ll find Cobbler running as root and show multiple ways to abuse it for a root shell, reaching its API through both default credentials and an authentication bypass. In Beyond Root, I’ll dig into why the SQL injection crashes the page.
000
0xdf @0xdf.bsky.social · 08/08/2026
Helix from HackTheBox features an anonymous Apache NiFi instance with H2 JDBC code execution, an SSH key pivot, and an OPC UA reactor server where tampering with calibration values opens a maintenance window to get root.
0xdf.gitlab.io
HTB: Helix
Helix builds an industrial control theme around a chemical reactor that operators monitor and adjust through a control server. I’ll get a foothold on an anonymously-accessible Apache NiFi instance running an old, vulnerable version, abusing the H2 database driver’s ability to run a script on connection to register and call arbitrary Java for execution. From there I’ll find an SSH key on the box and pivot to the next user. That user can run a maintenance console as root, but only while a maintenance window is open. I’ll connect to the reactor’s control server and tamper with its calibration offset to push the temperature past a safety threshold, which opens the window and lets the console drop into a root shell. In Beyond Root, I’ll recover the encrypted NiFi database password.
000
0xdf @0xdf.bsky.social · 01/08/2026
Kobold from HackTheBox features unauthenticated RCE in MCPJam, a PrivateBin template LFI turned webshell via a mounted volume, password reuse into an Arcane Docker panel, and container abuse mounting the host filesystem for root.
0xdf.gitlab.io
HTB: Kobold
Kobold hosts several services behind an Nginx reverse proxy, including an MCPJam inspector instance, a PrivateBin paste site, and an Arcane Docker management panel. I’ll exploit an unauthenticated remote code execution vulnerability in MCPJam that stems from it binding to all interfaces and installing an attacker-controlled MCP server, getting a shell. From there I’ll abuse a local file inclusion in PrivateBin’s template-selection feature, writing a PHP webshell into a host directory that is mounted into the PrivateBin container to get execution inside it. The container’s configuration leaks a database password that I’ll reuse to log into Arcane. With control over the Docker panel, I’ll create a container that mounts the host filesystem, drop an SSH key for root, and log in to take over the box.
001
0xdf @0xdf.bsky.social · 26/07/2026
Fries from HackTheBox is a Windows box fronting a mess of Linux containers. It features a pgAdmin eval RCE, Docker cert forging for root, PWM config decryption, a readable gMSA, and an ADCS ESC7 -> ESC6 + ESC16 chain to Administrator.
0xdf.gitlab.io
HTB: Fries
Fries is an assume breach Windows box that hides a sprawl of Linux services behind the domain controller. I’ll start with a set of credentials that don’t work anywhere obvious and use them to log into a Gitea instance, recovering database and pgAdmin access along the way. An outdated pgAdmin is vulnerable to a Python eval remote code execution bug that lands a shell in a container. From environment variables and the pgAdmin database I’ll collect more credentials and spray them to get a shell on the Docker host, which is itself a Hyper-V guest. There I’ll abuse a network file share by recreating a domain user locally to read the Docker daemon’s certificates, forge a client certificate, and use the Docker API to mount the host filesystem and become root. Root on that host holds a PWM configuration with an encrypted service account password, which I’ll recover to move into the domain. That account can read a group managed service account password, and from there I’ll abuse control over the certificate authority, chaining three ADCS misconfigurations to forge a certificate for the administrator and take over the domain.
031
0xdf @0xdf.bsky.social · 18/07/2026
Logging from HackTheBox is an assume breach AD box. It has a leaked password in a log share, a Kerberos-only service account, a shadow credential, an insecure auto-updater loading a malicious DLL, ADCS ESC17, and a rogue WSUS server for domain admin.
0xdf.gitlab.io
HTB: Logging
Logging is a Windows domain controller offered as an assume breach box, starting with credentials for a low privileged domain user. I’ll find an application log on an open SMB share that leaks an old password for a service account, then guess the current password by incrementing the year. That account can only authenticate over Kerberos, and it has GenericWrite over a health monitoring machine account, which I’ll abuse with a shadow credential and gMSA credentials to get a shell. From there I’ll hijack an insecure auto-update program that loads a DLL from a world-writable directory to pivot to the next user. That user is in the IT group with enrollment rights on a certificate template vulnerable to ESC17, which lets me request a certificate for any server name. I’ll issue a certificate for the decommissioned WSUS server, add a DNS record pointing it at my host, and stand up a rogue WSUS server that pushes a malicious update adding my initial user to the administrators group for full control of the domain.
031
0xdf @0xdf.bsky.social · 14/07/2026
Orion from HackTheBox features an unauthenticated Craft CMS RCE via a Yii object-injection flaw and PHP session poisoning, a bcrypt hash cracked from the database, and a legacy GNU telnetd running as root with a -f root auth bypass.
0xdf.gitlab.io
HTB: Orion
Orion is a Linux box running a Craft CMS website. I’ll exploit an unauthenticated remote code execution vulnerability in Craft’s image transform endpoint, abusing an object injection flaw in the underlying Yii framework to poison a PHP session file and execute my payload, landing a shell as the web user. Reading the Craft configuration, I’ll find database credentials, dump the users table, and crack a bcrypt hash to reach the next user, though that step turns out to be optional. For root, I’ll find inetd serving telnet, and abuse an authentication bypass that provides access as root by smuggling a “-f root” value through the USER environment variable.
010
0xdf @0xdf.bsky.social · 11/07/2026
CCTV from HackTheBox features a blind SQL injection in ZoneMinder and network sniffing to recover a password, then command injection in motionEye for root. Beyond Root shows an unintended path via Motion's unauthenticated control interface.
0xdf.gitlab.io
HTB: CCTV
CCTV hosts a ZoneMinder surveillance install. I’ll exploit a blind SQL injection in ZoneMinder’s event handling to dump the user database, and crack a bcrypt hash to get a foothold over SSH. I’ll use tcpdump configured to let non-privileged users capture traffic to sniff and recover another user’s password leaking in the clear. That password unlocks a motionEye instance on localhost, where I’ll abuse an authenticated command injection in the still-image filename setting, working around client-side input validation, to execute code as root. In Beyond Root, I’ll show the unintended path that reaches root directly by talking to Motion’s unauthenticated control interface.
020
0xdf @0xdf.bsky.social · 07/07/2026
Abducted from HackTheBox went straight to retired in early June on a newsworthy Samba CVE. Command injection in the print subsystem, an rclone-obfuscated password, wide-link abuse to hijack a home dir, and a writable smbd systemd drop-in for root.
0xdf.gitlab.io
HTB: Abducted
Abducted is a Linux box running Samba. I’ll exploit a command injection in Samba’s printing subsystem, where a client-controlled print job name is passed to a shell without escaping, to get a foothold. From there, I’ll find an rclone backup config with an obfuscated password, decode it with rclone, and use it to access the next user. That user owns a Samba share configured to follow wide links and to run as a third user, which I’ll abuse to drop an SSH key into that user’s home directory and log in. The final user belongs to a group with write access to the smbd systemd drop-in directory and a polkit rule permitting them to restart the service, so I’ll add an ExecStartPre command that creates a SetUID bash and get root.
022
0xdf @0xdf.bsky.social · 04/07/2026
DevArea from HackTheBox features an Apache CXF file-read SSRF, a Hoverfly middleware command injection, a forged Flask session from a leaked secret, and a symlink-check bypass in a sudo script for root.
0xdf.gitlab.io
HTB: DevArea
DevArea hosts a freelance developer marketplace backed by several web applications on different stacks. I’ll find a JAR file on an open FTP server that matches one of the web services that uses a vulnerable version of Apache CXF. I’ll abuse its attachment handling to read arbitrary files off the host. Those files leak credentials for a Hoverfly API simulation instance, where a command injection in the middleware feature gives a shell as the first user. From there I’ll pivot through a custom SysWatch monitoring app, forging a session cookie with a secret pulled from a world-readable environment file and slipping a command past a weak input filter to run as the service account. Finally, I’ll exploit a flawed symlink check in a script that account runs as root to read the root login key and get a shell. In Beyond Root I’ll explore why I couldn’t read user.txt from the initial file read, and look at the admin password from the syswatch application.
031
0xdf @0xdf.bsky.social · 27/06/2026
WingData from HackTheBox features a null-byte Lua injection in Wing FTP Server for RCE, cracked password hashes for a pivot, and a Python tarfile extraction-filter bypass for arbitrary write to root.
0xdf.gitlab.io
HTB: WingData
WingData runs a Wing FTP Server instance with anonymous access enabled. I’ll abuse a null-byte injection flaw in the web interface that smuggles Lua code into the session file, giving remote code execution and a shell. From there, I’ll find Wing FTP’s account files holding salted password hashes, crack one, and reuse it to move to the next user. That user can run a Python backup-restore script as root that unpacks tar archives using the tarfile module’s “data” extraction filter. I’ll exploit a path-validation bypass in that filter to write outside the extraction directory and drop a key into the root account for full access.
000
0xdf @0xdf.bsky.social · 20/06/2026
NanoCorp from HackTheBox is a Windows AD box. A careers site extracts uploaded zips, so a .library-ms file leaks a Net-NTLMv2 hash. Then ACL abuse to reset a Protected Users account, and a Checkmk agent privesc to SYSTEM.
0xdf.gitlab.io
HTB: NanoCorp
NanoCorp is a Windows Active Directory machine built around a careers portal that accepts uploaded application archives. I’ll craft a malicious archive that leaks a service account’s authentication to my host when an automated job extracts it, and crack the result to get a foothold. With BloodHound, I’ll map a permissions chain that lets me add my user to a support group and then reset a second service account’s password. That account sits in the Protected Users group, so I’ll authenticate over Kerberos to get a shell. From there, I’ll find the Checkmk monitoring agent installed and abuse CVE-2024-0670 to drop write-protected files into a temp directory that the agent runs as SYSTEM, taking full control of the host. In Beyond Root, I’ll dig into the scheduled automations that keep the box in its intended state.
011
0xdf @0xdf.bsky.social · 13/06/2026
VariaType from HackTheBox has an exposed Git repo, a path traversal filter bypass for file read, an arbitrary file write in fontTools for a webshell, FontForge archive command injection, and a setuptools path traversal for root.
0xdf.gitlab.io
HTB: VariaType
VariaType hosts a pair of websites for a font foundry, a Flask-based font generator and a PHP validation portal. I’ll recover the portal’s source from an exposed Git repository to get credentials, and then abuse a single-pass filter bypass in its download feature to read files off the host. With the Flask application’s source in hand, I’ll exploit an arbitrary file write in fontTools’ variable font generation to drop a PHP webshell and get a foothold. A cron job validates uploaded fonts with an outdated FontForge build, which I’ll exploit through command injection in a malicious archive’s filenames to pivot to the next user. Finally, I’ll abuse a sudo-allowed plugin installer that downloads files with a vulnerable version of setuptools, using a path traversal in its PackageIndex to write an SSH key to root’s home directory.
010
0xdf @0xdf.bsky.social · 06/06/2026
Facts from HackTheBox features mass assignment in Camaleon CMS, MinIO S3 creds leading to an encrypted SSH key, and sudo on Puppet's facter with custom Ruby facts for root.
0xdf.gitlab.io
HTB: Facts
Facts is a Linux box hosting a trivia website built on the Camaleon CMS, a Ruby on Rails application. I’ll abuse a mass assignment vulnerability in Camaleon to promote my account to administrator, then use credentials from the admin panel to authenticate to a local MinIO S3 service. From the bucket I’ll grab an encrypted SSH private key, crack its passphrase with john, and SSH in as the next user. For root, I’ll abuse a sudo rule on facter, Puppet’s system inventory tool, that lets me load arbitrary Ruby code from a custom facts directory and run it as root. In Beyond Root, I’ll show an alternative foothold using a path traversal in Camaleon’s S3 uploader to read arbitrary files, and use the leaked Rails master key to decrypt the application’s encrypted credentials and session cookies.
000
0xdf @0xdf.bsky.social · 05/06/2026
AI vocabulary is moving fast and getting muddled. New glossary covering LLMs, models, tokens, MCPs, frontier vs open-weight labs, clients, harnesses, and lab initiatives. One of many neat cheatsheets on 0xdf hacks stuff.
0xdf.gitlab.io
AI Glossary
AI as a technology is moving fast. From the time ChatGPT went mainstream in 2023, it’s grown from a cute way to generate funny poems to a defining technology that is likely to change everything. With its amazingly quick rise, it’s tricky to get the terms and language correct. Even the tech media doesn’t understand it, comparing Mythos to MDASH to Daybreak, when those comparisons make no sense! Let’s understand models vs harnesses vs labs vs initiatives and all that lays between.
000
0xdf @0xdf.bsky.social · 03/06/2026
Watching Ippsec inspired a question - How does auto-calibration (-ac) work in ffuf? Let's explore it! www.youtube.com/watch?v=scHc...
youtube.com
ffuf Auto Calibration Demystified
YouTube video by 0xdf
142
0xdf @0xdf.bsky.social · 30/05/2026
Interpreter from HackTheBox features unauthenticated XStream deserialization in Mirth Connect for RCE, cracking a password hash from the Mirth database, and Python f-string injection through eval for root.
0xdf.gitlab.io
HTB: Interpreter
Interpreter is a Linux box hosting Mirth Connect, a Java-based healthcare integration engine. I’ll exploit an unauthenticated XStream deserialization vulnerability in the Mirth API to get remote code execution and a foothold as the mirth service account. From the Mirth config I’ll grab database credentials, dump a user password hash from MariaDB, and crack it to pivot to the next user. For root, I’ll abuse a localhost Flask notification server that wraps XML-supplied fields in an evaluated f-string, allowing Python code execution as root.
021
0xdf @0xdf.bsky.social · 24/05/2026
MonitorsFour from @hackthebox.bsky.social features PHP type juggling to dump users, CVE-2025-24367 for RCE in Cacti, and CVE-2025-9074 to abuse the Docker Desktop API and mount the Windows host drive for root. Beyond Root: a shell on Windows." 0xdf.gitlab.io/2026/05/23/h...
0xdf.gitlab.io
HTB: MonitorsFour
MonitorsFour continues the Monitors series, this time on a Windows host. A company website exposes an authenticated API endpoint that returns every employee’s record. I’ll bypass auth with a PHP type ...
011
0xdf @0xdf.bsky.social · 16/05/2026
Pterodactyl from HackTheBox features unauth directory traversal in Pterodactyl Panel, pearcmd trick for RCE, and a Polkit + udisks chain mounting a SetUID XFS image for root. Beyond Root: two recent Linux kernel page-cache LPEs.
0xdf.gitlab.io
HTB: Pterodactyl
Pterodactyl hosts a Minecraft community site alongside an instance of the Pterodactyl game-server management panel. I’ll exploit an unauthenticated directory traversal in the panel’s locale endpoint that gets PHP to include arbitrary files on disk, and chain it with the classic PEAR pearcmd technique to write and execute a webshell. From there I’ll read database credentials, crack a bcrypt hash, and pivot to a user who reuses that password. The box runs openSUSE, where I’ll abuse a PAM environment-variable flaw to convince Polkit I’m a local console session, then exploit a libblockdev/udisks vulnerability to mount a crafted XFS image carrying a SetUID-root shell and escalate to root. In Beyond Root, I’ll get CopyFail and DirtyFrag (two recent Linux kernel page-cache privilege-escalation exploits) working on the host.
022
0xdf @0xdf.bsky.social · 09/05/2026
Diving into Dirty Frag, the second Linux page-cache local privesc in two weeks. CVE-2026-43284 + CVE-2026-43500 provide full distro coverage. I walk through both variants, the broken disclosure, and demo both versions on the HTB Snapped machine. www.youtube.com/watch?v=B5eU...
youtube.com
Dirty Frag Explained
YouTube video by 0xdf
033
0xdf @0xdf.bsky.social · 09/05/2026
Overwatch from HackTheBox features anonymous SMB, .NET reverse engineering, MSSQL linked server abuse with AD-integrated DNS to capture cleartext credentials via Responder, and a PowerShell command injection in a WCF service for SYSTEM.
0xdf.gitlab.io
HTB: Overwatch
Overwatch starts with anonymous SMB access to a software share that hosts a custom .NET monitoring binary. I’ll reverse engineer it to recover SQL Server credentials and identify a WCF service with a PowerShell command injection sink. With the SQL creds, I’ll find a linked server pointing to a non-resolving host and abuse CREATE_CHILD on the AD-integrated DNS zone to add a record pointing the hostname at my host, capturing cleartext SQL authentication with Responder when the linked server connects out. Those credentials provide WinRM as a user in Remote Management Users. From there, I’ll exploit the WCF KillProcess command injection on a localhost SOAP endpoint to get code execution as SYSTEM, demonstrating four different ways to interact with the WCF service. In Beyond Root, I’ll look at a log that captured the Windows Administrator password from an HTB pre-release cleanup script.
042
0xdf @0xdf.bsky.social · 30/04/2026
Diving into the latest Linux exploit, Copy Fail. I'll show how it works, deobfuscate the author's POC, and run it on a HackTheBox machine (and show how to cleanup). www.youtube.com/watch?v=wQ91...
youtube.com
Copy Fail Explained [CVE-2026-31431]
YouTube video by 0xdf
062
0xdf @0xdf.bsky.social · 25/04/2026
Sorcery from HackTheBox has Cypher injection, passkey XSS on a headless Chrome bot, Kafka wire protocol SSRF, Xvfb framebuffer reads, .NET reversing for Docker Registry OTPs, and FreeIPA role abuse for root.
0xdf.gitlab.io
HTB: Sorcery
Sorcery is a Linux box with a Rust Rocket web app backed by Neo4j, Gitea, and a Kafka message bus. I’ll exploit Cypher injection in a derive-macro-generated query to leak the seller registration key, then use XSS in a product description to register a passkey on the admin account through a headless Chrome bot. I’ll also show a shortcut to change the admin’s password using cypher injection. As admin, a port-debug tool becomes an SSRF I can use to send Kafka wire protocol messages, which I’ll use to get RCE in the DNS container. From there, I’ll recover a CA keypair from FTP, phish the next user with mitmproxy proxying their own Gitea login page, read a password out of an Xvfb framebuffer, and reverse a .NET binary to generate OTPs for Docker Registry auth. Pulling layers out of a pushed image leaks another password, and the final pivots abuse FreeIPA roles to change one user’s password over LDAP and bootstrap sudo rights to root. I’ll show a couple unintended paths using pspy to capture creds as well.
001
0xdf @0xdf.bsky.social · 18/04/2026
AirTouch from HackTheBox is a wireless box featuring SNMP enumeration, WPA2-PSK capture and crack, WireShark traffic decryption, client-side cookie role bypass with a phtml upload, and an evil twin via eaphammer to capture a crackable challenge.
0xdf.gitlab.io
HTB: AirTouch
AirTouch simulates a wireless network environment. I’ll start by pulling a default password from SNMP to SSH as a consultant user inside a container with virtual wireless interfaces. From there, I’ll capture and crack a WPA2-PSK handshake to join the tablet network, then decrypt the captured traffic in WireShark to recover session cookies for a router management site. A client-side role cookie gates an admin upload feature, where I’ll bypass the PHP extension filter with a phtml file to get RCE. Hardcoded credentials in the source give me the next user, and sudo gets me root, where I find the CA and server certs for the corporate wireless network. I’ll use those with eaphammer to stand up an evil twin of AirTouch-Office and capture a PEAP-MSCHAPv2 challenge, which cracks to reveal a user’s password. That gets me onto the corporate network, where a hostapd eap_user file leaks an admin password, and sudo gets me to root.
122
0xdf @0xdf.bsky.social · 11/04/2026
Eighteen from HackTheBox is an assume breach Windows Server 2025 box featuring MSSQL impersonation, Werkzeug hash cracking, password spraying, and Bad Successor (CVE-2025-53779) to abuse dMSA migration for domain admin.
0xdf.gitlab.io
HTB: Eighteen
Eighteen is a Windows Server 2025 assume-breach box starting with MSSQL credentials. I’ll use MSSQL login impersonation to access the financial planner database and recover a Werkzeug PBKDF2 hash for the web admin. After cracking the hash and spraying the password against domain users, I’ll get a WinRM shell. From there, I’ll identify that the domain is running at the Windows 2025 functional level and exploit Bad Successor, abusing the dMSA migration feature to create a delegated managed service account that inherits the Administrator’s group memberships, giving full domain admin access.
011
0xdf @0xdf.bsky.social · 04/04/2026
DarkZero from HackTheBox features cross-forest MSSQL linked servers, four privesc paths (token theft, ADCS/RunAsCS, NTLM reflection via CMTI, CVE-2024-30088), and cross-forest TGT delegation for domain takeover.
0xdf.gitlab.io
HTB: DarkZero
DarkZero is an assume breach Windows box with two forests connected by a bidirectional cross-forest trust. Starting with given credentials, I’ll enumerate MSSQL on DC01 and find a linked server to DC02 in the other forest where the mapped account is sysadmin. I’ll enable xp_cmdshell on DC02 to get a shell as the SQL service account. To escalate to SYSTEM on DC02, I’ll show four paths: recovering SeImpersonatePrivilege from the original logon token via named pipe impersonation, using ADCS certificate enrollment to get an NT hash and change the password for a service logon with RunAsCS, NTLM authentication reflection using the CMTI DNS record trick to relay the machine account back to its own LDAPS, and CVE-2024-30088. As SYSTEM on DC02, I’ll abuse the cross-forest TGT delegation to capture DC01’s machine account TGT and use it to dump all domain hashes from DC01.
000
0xdf @0xdf.bsky.social · 01/04/2026
Snapped from HackTheBox features CVE-2026-27944 to download and decrypt Nginx UI backups without auth, bcrypt cracking for a shell, and CVE-2026-3888 to exploit a snapd race condition for root.
0xdf.gitlab.io
HTB: Snapped
Snapped is a Linux box hosting a static site behind nginx, with an Nginx UI admin panel. I’ll exploit CVE-2026-27944 to decrypt a backup download from the Nginx UI to find bcrypt password hashes in a SQLite database. I’ll crack one to get SSH access. To escalate to root, I’ll exploit CVE-2026-3888, a recent vulnerability in snapd where systemd-tmpfiles deletes snap-confine’s private temp directory, allowing me to win a race condition and replace the dynamic linker with a malicious payload that runs as root.
032
0xdf @0xdf.bsky.social · 30/03/2026
Principal from HackTheBox features a pac4j JWT authentication bypass (CVE-2026-29000) to forge admin tokens using just the public key, password reuse to SSH, and abusing an SSH CA private key to sign a root certificate.
0xdf.gitlab.io
HTB: Principal
Principal is a Linux box with a Java web application using pac4j for JWT authentication. I’ll exploit a vulnerability in pac4j-jwt that allows forging encrypted JWTs using only the server’s public RSA key, bypassing signature verification to access the admin dashboard. From there, I’ll find credentials in the settings and spray them against SSH to get a shell as svc-deploy. For root, I’ll abuse access to an SSH certificate authority private key to sign a certificate for the root principal and SSH in.
000
0xdf @0xdf.bsky.social · 28/03/2026
Browsed from HackTheBox features Chrome extension analysis and SSRF via a malicious extension, Bash arithmetic injection through -eq evaluation for RCE, and Python pycache bytecode poisoning for root.
0xdf.gitlab.io
HTB: Browsed
Browsed is a Linux box hosting a browser extension repository where uploaded extensions are tested in a headless Chrome instance. I’ll analyze the Chrome debug logs to discover an internal Gitea instance and a Python Flask app running on localhost. By crafting a malicious Chrome extension with a background service worker, I’ll perform SSRF to reach the internal Flask app and exploit a Bash arithmetic evaluation injection in a shell script to get remote code execution. For root, I’ll abuse a world-writable pycache directory to poison a Python bytecode file imported by a sudo-allowed script, getting code execution as root.
000
0xdf @0xdf.bsky.social · 21/03/2026
Conversor from HackTheBox features XSLT injection and os.path.join abuse for file write, and CVE-2024-48990 in needrestart (plus a config GTFObin) for root.
0xdf.gitlab.io
HTB: Conversor
Conversor is a Linux box hosting a Flask web application that converts nmap XML output to HTML using XSLT. I’ll find the source code and exploit insecure use of os.path.join to write a Python reverse shell into a cron-executed scripts directory, or alternatively abuse XSLT’s exslt:document extension to write files to the server. From there, I’ll find an MD5-hashed password in the SQLite database and crack it to pivot to the next user. For root, I’ll exploit CVE-2024-48990 in needrestart by poisoning the PYTHONPATH environment variable, or abuse needrestart’s Perl config file to get direct code execution.
020
0xdf @0xdf.bsky.social · 14/03/2026
Gavel from HackTheBox features a novel PDO prepared statement SQLi bypass, PHP runkit code injection for RCE, and overwriting a sandbox php.ini to escalate from restricted PHP execution to root.
0xdf.gitlab.io
HTB: Gavel
Gavel is a Linux box hosting a PHP auction website with an exposed .git directory. I’ll recover the source code with git-dumper and exploit a novel SQL injection technique that bypasses PDO’s backtick-quoted prepared statements to dump the database. After cracking a bcrypt hash, I’ll access the admin panel and exploit PHP’s runkit extension to inject arbitrary code into auction rules, getting RCE. I’ll pivot to the next user via password reuse, then reverse engineer a custom daemon that validates submitted PHP rules against a restrictive php.ini. Since file_put_contents isn’t disabled, I’ll overwrite the php.ini to remove all restrictions, then use a second submission to get a root shell.
030
0xdf @0xdf.bsky.social · 07/03/2026
Expressway from HackTheBox features IKE Aggressive Mode identity leaking and PSK cracking for SSH access. Privesc is CVEs in sudo. I'll show both hostname spoofing to bypass host-based sudoers rules, and chroot abuse via a malicious NSS library.
0xdf.gitlab.io
HTB: Expressway
Expressway is a Linux box with only SSH and an IKE VPN service on UDP. I’ll use ike-scan in aggressive mode to leak the VPN identity and capture a pre-shared key hash, which cracks quickly with hashcat. Connecting to the IPSEC VPN doesn’t provide any additional attack surface, but the PSK works for SSH access. For privilege escalation, I’ll show exploitation of two different CVEs in sudo. In Beyond Root, I’ll look at the sudo config that allowed one of the exploits and show how to connect to the IPSec VPN with strongSwan.
020
0xdf @0xdf.bsky.social · 03/03/2026
Barrier from VulnLab now on HackTheBox features a SAML signature bypass to get GitLab admin, Authentik API abuse via a CI/CD token, SSH key extraction from Guacamole's MariaDB, and a password in bash history for root.
0xdf.gitlab.io
HTB: Barrier
Barrier is a Linux box with GitLab, Authentik, and Apache Guacamole. I’ll exploit a SAML signature bypass vulnerability in GitLab’s Ruby SAML library to forge a SAML assertion and log in as admin. From GitLab’s CI/CD variables, I’ll recover an Authentik API token and use it to create an admin account. With Authentik admin access, I’ll impersonate a user in Guacamole to get an SSH shell. From there, I’ll find database credentials for Guacamole’s MariaDB backend and extract an SSH private key and passphrase for another user. That user’s bash history contains a password that works with sudo to get root.
041
0xdf @0xdf.bsky.social · 28/02/2026
Guardian from HackTheBox features chat IDOR, XSS via PhpSpreadsheet CVE-2025-22131, CSRF to create an admin account, PHP filter chain LFI-to-RCE, password cracking, Python script injection, and bypassing a custom Apache config validator many ways.
0xdf.gitlab.io
HTB: Guardian
Guardian is a Linux box hosting a university portal built with PHP. I’ll exploit an IDOR in the chat feature to find Gitea credentials, then use the source code to identify a vulnerability in PhpSpreadsheet that allows XSS through a malicious XLSX file to steal a lecturer’s session cookie. From the lecturer account, I’ll combine a CSRF vulnerability with a weak CSRF token implementation to create an admin account. As admin, I’ll abuse a local file include with PHP filter chain injection to get RCE. After cracking a database password hash, I’ll pivot through users by modifying a writable Python script. I’ll escalate to root abusing a silly binary wrapper around apache2ctl many ways.
031
0xdf @0xdf.bsky.social · 24/02/2026
Bruno from VulnLab (now on HackTheBox) features .NET reverse engineering, ZipSlip archive path traversal into a DLL hijack for foothold, then Kerberos relay via KrbRelayUp abusing missing LDAP signing for RBCD and Administrator access.
0xdf.gitlab.io
HTB: Bruno
Bruno is a Windows Active Directory box. I’ll start by finding a .NET sample scanning application on FTP, and after reverse engineering it, discover a ZipSlip vulnerability in how it handles zip archives. Combining that with a DLL hijack, I’ll get a shell as the service account that runs the scanner. For privilege escalation, I’ll exploit the lack of LDAP signing by performing a Kerberos relay attack, setting up resource-based constrained delegation to impersonate the Administrator.
031
0xdf @0xdf.bsky.social · 21/02/2026
Giveback from HackTheBox is a Kubernetes box with GiveWP PHP object injection for RCE, PHP-CGI argument injection via Best-Fit characters on a legacy internal app, K8s API secret dumping, and a container escape through runc two ways.
0xdf.gitlab.io
HTB: Giveback
Giveback starts with a WordPress website with a donation plugin that’s vulnerable to a RCE exploit. I’ll get a shell in a Kubernetes pod, and use it to scan an internal legacy app running PHP-CGI. I’ll abuse a vulnerability in that application to get to the next pod, where I’ll find a Kubernetes secret to interact with the API and dump secrets. I’ll use an SSH password to get on the host. For root I’ll abuse a custom wrapper around runc two different ways.
010
0xdf @0xdf.bsky.social · 14/02/2026
Soulmate from HackTheBox features a PHP dating site and CrushFTP with two auth bypass CVEs (race condition and AWS4-HMAC abuse) for admin access, PHP webshell upload for foothold, and hardcoded credentials in an Erlang SSH server for root.
0xdf.gitlab.io
HTB: Soulmate
Soulmate has a PHP-based dating website, as well as an instance of CrushFTP. I’ll showcase two different authentication bypass CVEs to get admin access to CrushFTP. From there I can upload a PHP webshell and get a foothold on the box. I’ll find hardcoded credentials in an Erlang SSH server, and use them to get to the next user. I’ll also use them to connect to this SSH server and navigate the Erlang console as root to solve the challenge.
000
0xdf @0xdf.bsky.social · 12/02/2026
Slonik from HackTheBox features NFS root filesystem escape to read sensitive files, UNIX socket SSH tunneling to PostgreSQL, RCE through PostgreSQL for a shell, and poisoning a pg_basebackup cron job with a SetUID binary for root.
0xdf.gitlab.io
HTB: Slonik
Slonik showcases some interesting Linux techniques around NFS and PostgreSQL. I’ll start with an insecurely configured NFS mount where I can list and read files from anywhere on the filesystem as any user except root. I’ll find hashes for a service account in the shadow file and in a postgres history file, and crack either. The service account doesn’t have a shell set, so I can’t get a shell over SSH. I can port forward to a UNIX socket, which provides access to PostgreSQL. I’ll use that to get a shell as the postgres user. To escalate to root, I’ll abuse a cron running a PostgreSQL backup utility. In Beyond Root, I’ll talk about a bug I found and fixed in Netexec and its neat NFS tools.
030
0xdf @0xdf.bsky.social · 11/02/2026
Netexec has some really nice NFS capabilities. I found a some weird behavior in one of them, which turned out to be a bug that just got patched. Let's walk through it.
youtube.com
Finding and Fixing a Bug in Netexec NFS
Netexec has some awesome NFS capabilities. While playing Slonik from VulnLab / HackTheBox, I found an issue I couldn't understand. I'll walk through how Nete...
011
0xdf @0xdf.bsky.social · 10/02/2026
Breach from HackTheBox and VulnLab is an AD box with a writable SMB share, ntlm_theft for hash capture, Kerberoasting, a silver ticket to get sysadmin on MSSQL, and GodPotato for SYSTEM.
0xdf.gitlab.io
HTB: Breach
Breach is a Windows domain controller box. I’ll start by using guest access to a writable SMB share to drop ntlm_theft lure files, capturing a NetNTLMv2 hash for a domain user with Responder. After cracking that hash, I’ll use BloodHound to find a Kerberoastable MSSQL service account and crack its hash as well. Both accounts map to guest on MSSQL, but I’ll forge a silver ticket as Administrator to get sysadmin access, enable xp_cmdshell, and use GodPotato to escalate to SYSTEM.
020
0xdf @0xdf.bsky.social · 07/02/2026
Signed from HackTheBox is an assume breach MSSQL box featuring silver ticket forging with group injection, OPENROWSET BULK for privileged file reads, NTLM relay via crafted DNS records, and SeImpersonate recovery from a restricted service token.
0xdf.gitlab.io
HTB: Signed
Signed is an assume breach Windows box where I’m given credentials for a local MSSQL account. I’ll enumerate the database, coerce authentication from the MSSQL service account using xp_dirtree, and crack the NetNTLMv2 hash. With the service account password, I’ll forge a silver ticket with the IT group’s RID to gain sysadmin privileges on the database and get command execution. For root, I’ll show three paths: using OPENROWSET BULK impersonation with silver tickets to read files as Domain Admins and find the Administrator’s password in PowerShell history, relaying NTLM authentication from the DC using a crafted DNS record, and recovering SeImpersonatePrivilege from the original logon token to escalate with GodPotato.
130
0xdf @0xdf.bsky.social · 03/02/2026
Bamboo from HackTheBox and VulnLab features Squid proxy enumeration, CVE-2023-27350 authentication bypass to RCE in PaperCut NG, and binary hijacking of a root-executed script for privilege escalation.
0xdf.gitlab.io
HTB: Bamboo
Bamboo offers a Squid HTTP proxy through which I’ll access a PaperCut NG instance. I’ll use Spose to scan through the proxy and discover the print management application. I’ll exploit an authentication bypass vulnerability in PaperCut and use application access to enabling print scripting to get code execution. For privilege escalation, I’ll abuse a root process that runs a script from the papercut user’s home directory.
021
0xdf @0xdf.bsky.social · 31/01/2026
CodeTwo from HackTheBox features a js2py sandbox escape via CVE-2024-28397, MD5 hash cracking from SQLite, and abusing npbackup-cli sudo permissions to read root's SSH key from backups.
0xdf.gitlab.io
HTB: CodeTwo
CodeTwo is a Linux box hosting a developer sandbox where users can execute JavaScript code. The site uses js2py, which I’ll exploit via CVE-2024-28397 to escape the sandbox and get remote code execution. From there, I’ll find MD5 password hashes in the SQLite database and crack one to pivot to marco. Marco can run npbackup-cli with sudo, and I’ll abuse this to read files from root’s backup, including the SSH private key, which I’ll use to get a shell as root.
040
0xdf @0xdf.bsky.social · 29/01/2026
I had the chance last weekend to play the Barbhack 2025 CTF from the NetExec team. Pirates features GPP creds, NTLMv1 relay to RBCD, DPAPI, GMSA recovery, MSSQL impersonation + SeImpersonate, constrained delegation, and NTDS forensics.
0xdf.gitlab.io
Barbhack 2025 CTF
Welcome to the NetExec Active Directory Lab! This lab is designed to teach you how to exploit Active Directory (AD) environments using the powerful tool NetExec. Originally featured in the Barbhack 2025 CTF, this lab is now available for free to everyone! In this lab, you’ll explore how to use the powerful tool NetExec to efficiently compromise an Active Directory domain during an internal pentest. The ultimate goal? Become Domain Administrator by following various attack paths! Ahoy, matey! Time to conquer the Seven Seas and claim the PIRATES.BRB domain!
011
0xdf @0xdf.bsky.social · 28/01/2026
Released a bit of a different video today. The State of 0xdf (2026). We'll look at the last year for my website and YT channel, go over some numbers. Definitely looking for feedback on if people like this kind of insight. www.youtube.com/watch?v=KCo6...
youtube.com
State of 0xdf (2026)
YouTube video by 0xdf
000