Use / or Ctrl+K for the command palette. Filters and search work together.

14 posts
HackTheBox Devhub Walkthrough Shell

A staged walkthrough shell for Devhub from Season 11: Season of the Punk, ready for recon, foothold, escalation, and debrief notes.

open draft shell
HackTheBox Lab Notes

A growing machine index for HackTheBox write-ups, beginning with Devhub from Season 11: Season of the Punk.

open hub
PortSwigger Authentication Labs

A growing, screenshot-led walkthrough covering username enumeration and a direct account-page bypass of 2FA.

read post
TryHackMe Valley: Complete Walkthrough

The full Valley path from web leaks and PCAP analysis through binary reversing, lateral movement, and Python module hijacking for root.

read walkthrough
TryHackMe Lab Notes

A growing index of recon-to-root room write-ups, beginning with the completed Valley challenge.

open hub
PortSwigger SSTI Labs Write-Up

A full SSTI walkthrough covering ERB, Tornado, FreeMarker, Handlebars, Django, and Twig with screenshot-driven reasoning for every lab.

read post
PortSwigger JWT Labs Write-Up

A Burp-first walkthrough of PortSwigger's JWT labs, covering none-alg abuse, weak secrets, header injection, and algorithm confusion without Python automation.

read post
Frankenstein NAS Build

Turning an old ISP router and a powered 1TB drive into a working home NAS, including Windows 11 SMB fixes, iPhone access, and the limits of a LAN-only build.

read post
OWASP Juice Shop Write-Up

A practical walkthrough of OWASP Juice Shop, covering challenge discovery, exploitation paths, and the use of Burp Suite against a modern training target.

read post
PortSwigger SQLi Labs Write-Up

A structured walkthrough of PortSwigger SQL injection labs, including manual testing, Python-assisted exploitation, and the reasoning behind each step.

read post