A staged walkthrough shell for Devhub from Season 11: Season of the Punk, ready for recon, foothold, escalation, and debrief notes.
open draft shellA growing machine index for HackTheBox write-ups, beginning with Devhub from Season 11: Season of the Punk.
open hubA growing, screenshot-led walkthrough covering username enumeration and a direct account-page bypass of 2FA.
read postThe full Valley path from web leaks and PCAP analysis through binary reversing, lateral movement, and Python module hijacking for root.
read walkthroughA growing index of recon-to-root room write-ups, beginning with the completed Valley challenge.
open hubA full SSTI walkthrough covering ERB, Tornado, FreeMarker, Handlebars, Django, and Twig with screenshot-driven reasoning for every lab.
read postA Burp-first walkthrough of PortSwigger's JWT labs, covering none-alg abuse, weak secrets, header injection, and algorithm confusion without Python automation.
read postTurning an old ISP router and a powered 1TB drive into a working home NAS, including Windows 11 SMB fixes, iPhone access, and the limits of a LAN-only build.
read postA practical walkthrough of OWASP Juice Shop, covering challenge discovery, exploitation paths, and the use of Burp Suite against a modern training target.
read postA structured walkthrough of PortSwigger SQL injection labs, including manual testing, Python-assisted exploitation, and the reasoning behind each step.
read postTry a broader keyword or switch back to the full archive.