<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Certifa · Writeups</title><description>HackTheBox writeups across Active Directory, Linux, and web.</description><link>https://certifa.net/</link><item><title>Shocker</title><link>https://certifa.net/writeups/htb-shocker/</link><guid isPermaLink="true">https://certifa.net/writeups/htb-shocker/</guid><description>A CGI shell script backed by a vulnerable Bash lets a crafted HTTP header trigger Shellshock (CVE-2014-6271) for RCE. Privesc via a passwordless sudo rule on perl, one GTFOBins command to root.</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate><category>linux</category><category>web</category><category>cgi</category><category>shellshock</category><category>cve-2014-6271</category><category>sudo</category><category>gtfobins</category><category>privesc</category></item><item><title>Kobold</title><link>https://certifa.net/writeups/htb-kobold/</link><guid isPermaLink="true">https://certifa.net/writeups/htb-kobold/</guid><description>A wildcard TLS certificate leaks a subdomain running MCPJam Inspector v1.4.2, whose /api/mcp/connect endpoint executes attacker-supplied commands with no authentication. Privesc via docker group membership: reactivated with newgrp, then a container mount of the host filesystem to root.</description><pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate><category>linux</category><category>web</category><category>subdomain-enumeration</category><category>MCP</category><category>CVE-2026-23744</category><category>docker</category><category>privesc</category></item><item><title>CCTV</title><link>https://certifa.net/writeups/htb-cctv/</link><guid isPermaLink="true">https://certifa.net/writeups/htb-cctv/</guid><description>Default credentials on an exposed ZoneMinder console lead to a blind SQL injection (CVE-2024-51482) that dumps a crackable hash for SSH. Root comes from a loopback-bound motionEye reached over an SSH tunnel, where a filename field is passed unsanitised to a Motion daemon running as root (CVE-2025-60787).</description><pubDate>Sat, 07 Mar 2026 00:00:00 GMT</pubDate><category>linux</category><category>web</category><category>zoneminder</category><category>sqli</category><category>CVE-2024-51482</category><category>motioneye</category><category>CVE-2025-60787</category><category>ssh-tunneling</category><category>command-injection</category></item><item><title>Pirate</title><link>https://certifa.net/writeups/htb-pirate/</link><guid isPermaLink="true">https://certifa.net/writeups/htb-pirate/</guid><description>Active HackTheBox machine. Full writeup published after retirement.</description><pubDate>Sun, 01 Mar 2026 00:00:00 GMT</pubDate><category>windows</category><category>active-directory</category><category>pre2k</category><category>gmsa</category><category>kerberos</category><category>ntlm-relay</category><category>rbcd</category><category>constrained-delegation</category><category>spn-jacking</category><category>ligolo-ng</category><category>privesc</category></item><item><title>Gavel</title><link>https://certifa.net/writeups/htb-gavel/</link><guid isPermaLink="true">https://certifa.net/writeups/htb-gavel/</guid><description>Linux web box: exposed .git repo leaks PHP source revealing a SQLi, admin panel RCE via PHP rule engine, then privesc by abusing a root-run auction daemon that executes YAML-defined PHP rules.</description><pubDate>Sun, 12 Oct 2025 00:00:00 GMT</pubDate><category>linux</category><category>web</category><category>sqli</category><category>git-dumper</category><category>php</category><category>rce</category><category>yaml</category><category>suid</category><category>privesc</category></item><item><title>DarkZero</title><link>https://certifa.net/writeups/htb-darkzero/</link><guid isPermaLink="true">https://certifa.net/writeups/htb-darkzero/</guid><description>Active Directory box featuring MSSQL lateral movement across two domains, kernel exploitation (CVE-2024-30088) via Metasploit, and Golden Ticket via Rubeus + PetitPotam to compromise the forest.</description><pubDate>Sun, 05 Oct 2025 00:00:00 GMT</pubDate><category>windows</category><category>active-directory</category><category>mssql</category><category>kerberos</category><category>CVE-2024-30088</category><category>golden-ticket</category><category>rubeus</category><category>privesc</category></item><item><title>Return</title><link>https://certifa.net/writeups/htb-return/</link><guid isPermaLink="true">https://certifa.net/writeups/htb-return/</guid><description>LDAP credential capture from a printer web panel, followed by Server Operators privilege escalation via service binary path modification.</description><pubDate>Sat, 04 Oct 2025 00:00:00 GMT</pubDate><category>windows</category><category>active-directory</category><category>ldap</category><category>privesc</category><category>server-operators</category></item><item><title>Cicada</title><link>https://certifa.net/writeups/htb-cicada/</link><guid isPermaLink="true">https://certifa.net/writeups/htb-cicada/</guid><description>Beginner-friendly Windows AD box: anonymous SMB enumeration leads to default credentials, password spraying finds a foothold, and SeBackupPrivilege escalates to Administrator via SAM dump.</description><pubDate>Fri, 03 Oct 2025 00:00:00 GMT</pubDate><category>windows</category><category>active-directory</category><category>smb</category><category>password-spray</category><category>SeBackupPrivilege</category><category>pass-the-hash</category></item><item><title>Expressway</title><link>https://certifa.net/writeups/htb-expressway/</link><guid isPermaLink="true">https://certifa.net/writeups/htb-expressway/</guid><description>Linux box with IKE/ISAKMP on UDP/500: crack the PSK with psk-crack, SSH in, then exploit a vulnerable sudo version (CVE-2025-32463) to root.</description><pubDate>Mon, 22 Sep 2025 00:00:00 GMT</pubDate><category>linux</category><category>ike</category><category>vpn</category><category>psk-crack</category><category>ssh</category><category>CVE-2025-32463</category><category>sudo</category><category>privesc</category></item></channel></rss>