Research
Security write-ups
Exploitation walkthroughs from Hack The Box Season 8 and bug bounty CTF challenges. Searchable, tagged, and statically generated.
Season 8 active machines (May–August 2025). Additional walkthroughs on Medium.
8 results
Editor
3mA Linux machine involving XWiki exploitation via CVE-2025-24893, credential extraction, and PATH hijacking for privilege escalation.
Era
3mA Linux machine involving vhost enumeration, IDOR vulnerability, hash cracking, SSRF exploitation, and binary signing for privilege escalation.
JinjaCare
3mA web application vulnerability challenge focusing on SSTI (Server-Side Template Injection) and RCE exploitation techniques.
NeoVault
3mA banking web application challenge involving MongoDB Object ID prediction and JWT token exploitation.
Code
3mA Python-based web application with command injection vulnerabilities and privilege escalation challenges.
Nocturnal
3mA challenging Hack The Box Linux-based machine involving web exploitation and privilege escalation techniques.
Dog
3mA Linux machine involving git repository dumping, RCE exploitation, and privilege escalation through sudo misconfiguration.
Outbound
3mA Linux machine featuring Roundcube webmail exploitation, session decryption, and privilege escalation through log symlink vulnerability.