▐◣ ⬤ ▄█▀ ▀█▀ ▄█▀

2025

1 post

HackTheBox - Shibuya

13 min read

A comprehensive walkthrough of the Hard-rated Shibuya machine from HackTheBox, featuring Windows registry extraction from WIM files, cross-session COM/DCOM relay attacks with RemotePotato0, BloodHound enumeration, and Active Directory Certificate Services (ADCS) ESC1 exploitation for domain takeover.

2023

2 posts

SSRF

6 min read

SSRF is a type of web attack where a server can make requests on behalf of an attacker.

CSRF

11 min read

CSRF is an attack that tricks the victim into submitting a malicious request.