<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://blog.bravosec.net/</id><title>Blog | bravosec</title><subtitle>Writeups and articles for Hack The Box, Try Hack Me, CTF, Penetration Testing, Red Team Training, Cyber Security related stuff.</subtitle> <updated>2026-05-23T23:47:16-08:00</updated> <author> <name>Fate Walker</name> <uri>https://blog.bravosec.net/</uri> </author><link rel="self" type="application/atom+xml" href="https://blog.bravosec.net/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://blog.bravosec.net/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Fate Walker </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>HackTheBox Writeup - Soulmate</title><link href="https://blog.bravosec.net/posts/HackTheBox-Writeup-Soulmate/" rel="alternate" type="text/html" title="HackTheBox Writeup - Soulmate" /><published>2025-11-04T01:49:55-08:00</published> <updated>2026-05-18T00:40:32-08:00</updated> <id>https://blog.bravosec.net/posts/HackTheBox-Writeup-Soulmate/</id> <content type="text/html" src="https://blog.bravosec.net/posts/HackTheBox-Writeup-Soulmate/" /> <author> <name>Fate Walker</name> </author> <category term="HackTheBox - Machines" /> <category term="1. HTB - Easy" /> <summary>Soulmate is an easy difficulty Linux machine that showcases exploitation of CVE-2025-31161, an authentication bypass vulnerability in CrushFTP, allowing players to access an admin user account. By uploading a malicious PHP file to the application’s web root, remote command execution is achieved. For privilege escalation, CVE-2025-32433, another remote command execution vulnerability in the Erla...</summary> </entry> <entry><title>HackTheBox Writeup - Conversor</title><link href="https://blog.bravosec.net/posts/HackTheBox-Writeup-Conversor/" rel="alternate" type="text/html" title="HackTheBox Writeup - Conversor" /><published>2025-10-27T16:10:18-08:00</published> <updated>2026-05-08T22:54:12-08:00</updated> <id>https://blog.bravosec.net/posts/HackTheBox-Writeup-Conversor/</id> <content type="text/html" src="https://blog.bravosec.net/posts/HackTheBox-Writeup-Conversor/" /> <author> <name>Fate Walker</name> </author> <category term="HackTheBox - Machines" /> <category term="1. HTB - Easy" /> <summary>Conversor is an easy-difficulty Linux machine featuring a web application that converts XML documents into visually formatted HTML documents using XSLT stylesheets. By registering an account and reviewing the downloadable source code, we discover that the application processes user-supplied XSLT files without proper sanitisation, leading to an XSLT injection vulnerability. This allows us to wri...</summary> </entry> <entry><title>HackTheBox Writeup - Signed</title><link href="https://blog.bravosec.net/posts/HackTheBox-Writeup-Signed/" rel="alternate" type="text/html" title="HackTheBox Writeup - Signed" /><published>2025-10-17T02:16:44-08:00</published> <updated>2026-05-08T22:54:12-08:00</updated> <id>https://blog.bravosec.net/posts/HackTheBox-Writeup-Signed/</id> <content type="text/html" src="https://blog.bravosec.net/posts/HackTheBox-Writeup-Signed/" /> <author> <name>Fate Walker</name> </author> <category term="HackTheBox - Machines" /> <category term="2. HTB - Medium" /> <summary>Signed is a medium-difficulty Windows machine that demonstrates the exploitation of an MSSQL server by extracting the NTLMv2 hash of the service account running the instance and cracking the hash to obtain its password. This enables the issuance of silver tickets for user impersonation and service access. The domain is then enumerated via the MSSQL instance to gather the necessary information t...</summary> </entry> <entry><title>HackTheBox Writeup - DarkZero</title><link href="https://blog.bravosec.net/posts/HackTheBox-Writeup-DarkZero/" rel="alternate" type="text/html" title="HackTheBox Writeup - DarkZero" /><published>2025-10-05T20:38:20-08:00</published> <updated>2025-10-05T20:38:20-08:00</updated> <id>https://blog.bravosec.net/posts/HackTheBox-Writeup-DarkZero/</id> <content type="text/html" src="https://blog.bravosec.net/posts/HackTheBox-Writeup-DarkZero/" /> <author> <name>Fate Walker</name> </author> <category term="HackTheBox - Machines" /> <category term="3. HTB - Hard" /> <summary>Recon Hosts pt command is a custom pentest framework to manage hosts and variables, it is not required to reproduce the steps in this writeup ┌──(bravosec㉿fsociety)-[~/htb/DarkZero] └─$ pt init '10.10.11.89 DC01.darkzero.htb darkzero.htb DC01' +----------+--------+-------------+-------------------+ | PROFILE | STATUS | IP | DOMAIN | +----------+--------+------------...</summary> </entry> <entry><title>HackTheBox Writeup - Imagery</title><link href="https://blog.bravosec.net/posts/HackTheBox-Writeup-Imagery/" rel="alternate" type="text/html" title="HackTheBox Writeup - Imagery" /><published>2025-09-30T04:22:18-08:00</published> <updated>2026-05-08T22:54:12-08:00</updated> <id>https://blog.bravosec.net/posts/HackTheBox-Writeup-Imagery/</id> <content type="text/html" src="https://blog.bravosec.net/posts/HackTheBox-Writeup-Imagery/" /> <author> <name>Fate Walker</name> </author> <category term="HackTheBox - Machines" /> <category term="2. HTB - Medium" /> <summary>Imagery is a medium-difficulty Linux machine that involves gaining admin access via exploiting a blind XSS. With admin privileges, the attacker exploits arbitrary file read to read sensitive files and source code. By reading the web app’s source code, the attacker discovers a feature that allows them to modify/transform an image, thereby making it vulnerable to remote code execution. After gain...</summary> </entry> </feed>
