Open to internships & CTF teams
Hi, I'm Certifa.
Offensive security student in Utrecht. I take things apart on HackTheBox, from Active Directory to Linux to web, and write down what I learn.
50+HTB boxes
MasterHTB rank
Pro Hackerpeak rank
9writeups
~/certifa · zsh
utc+1
$whoami
nameCertifa
roleoffsec student
schoolHogeschool Utrecht
focusAD · web · privesc
currentlystudying CCNA
$cat goals.txt
→ root more boxes (chasing 100)
→ complete more CTFs
→ earn CJCA + CPTS
→ land a red-team internship
$
#
utrecht · nl parrot · tmux · vim
Recent writeups
★ Latest writeup
Shocker
A CGI shell script backed by a vulnerable Bash lets a crafted HTTP header trigger Shellshock (CVE-2014-6271) for RCE. Privesc via a passwordless sudo rule on perl, one GTFOBins command to root.
platformHTB
difficultyeasy
filedJul 2026
tagslinux · web
read the post →
Kobold
A wildcard TLS certificate leaks a subdomain running MCPJam Inspector v1.4.2, whose /api/mcp/connect endpoint executes attacker-supplied commands with no authentication. Privesc via docker group membership: reactivated with newgrp, then a container mount of the host filesystem to root.
linux · web · subdomain-enumeration →
CCTV
Default credentials on an exposed ZoneMinder console lead to a blind SQL injection (CVE-2024-51482) that dumps a crackable hash for SSH. Root comes from a loopback-bound motionEye reached over an SSH tunnel, where a filename field is passed unsanitised to a Motion daemon running as root (CVE-2025-60787).
linux · web · zoneminder →
Pirate
Active HackTheBox machine. Full writeup published after retirement.
windows · active-directory · pre2k →
Things I've built
AD Home Lab infra
Server 2022 DC + 2 workstations. The same misconfigs I see on HTB, sitting in my apartment.
WS22Hyper-VBloodHound
→
recon.py tool
Python pipeline that wraps nmap, ffuf, gobuster, and crackmapexec into a single Markdown report.
Pythonasynciojinja2
→
HTB Tracker dashboard
Personal dashboard tracking 50+ boxes: difficulty, time-to-root, recurring techniques, paths.
JavaScriptGitHub Pages
→
HackTheBox Profile profile
The proving ground. Every writeup on this site started as a box here.
HTBPentestingAD
→
A bit about me
I'm 24, studying Cybersecurity & Cloud at Hogeschool Utrecht. Most of my free time goes into HackTheBox. The writeups on this site are the boxes that taught me something worth keeping.
Comfortable across the stack: Kerberos abuse and BloodHound paths in AD, weak services and SUID chains on Linux, chained logic bugs on the web. What interests me is how a few small misconfigs add up to a shell.
Right now that means CCNA, with CJCA and CPTS lined up after.
Read more →Boxes pwned · last 26 weeks
26w ago
less more
now Working on something interesting?
CTF teams, internship leads, lab trades, or feedback on a writeup. Pick a channel, they all reach me.