Macchine di HTB, PG e simili spiegate come appunti personali: comandi, output importanti e reasoning, niente fuffa.
- Articoli
- 19+ Note
- Focus
- OSCP · Red Team
- Struttura
- Recon → Exploit

Walkthroughs Articoli
Filtri
walkthroughsHTB Unattended Walkthrough: NGINX Alias Bug e Root via LUKS
Hack The Box Unattended writeup completo: NGINX alias bug, doppia SQL injection, LFI, session poisoning, cron poisoning e privilege escalation a root.
Continua a leggere Continua a leggere
walkthroughsTryHackMe Bolt: Walkthrough completo (RCE su Bolt CMS)
Write-Up della macchina Bolt di TryHackMe: enumerazione, scoperta credenziali, RCE autenticata su Bolt CMS via session hijacking e privesc a root.
Continua a leggere Continua a leggere
walkthroughsHTB Help Walkthrough: GraphQL e File Upload HelpDeskZ
Write-UP completo di Hack The Box: Help. Enumerazione GraphQL, bypass file upload su HelpDeskZ con analisi del codice PHP vulnerabile, privesc kernel a root.
Continua a leggere Continua a leggere
walkthroughsHTB Falafel Walkthrough: SQLi, PHP Type Juggling e Privesc
Write-Up alla macchina Falafel di Hack The Box: enumerazione utenti, blind SQL injection, bypass login PHP, RCE upload e privilege escalation Linux.
Continua a leggere Continua a leggere
walkthroughsHTB Shibuya Walkthrough: WIM, RemotePotato0 e ADCS ESC1
Hack The Box Shibuya Write-up: enumera utenti via Kerberos, estrai gli hash NTLM dai backup WIM e sfrutta RemotePotato0 e ADCS ESC1 fino a Domain Admin.
Continua a leggere Continua a leggere
walkthroughsHTB Redelegate Walkthrough: SeEnableDelegationPrivilege
WriteUp completo di Hack The Box Redelegate : FTP anonimo, KeePass, MSSQL, ForceChangePassword, SeEnableDelegationPrivilege, S4U, DCSync e Domain Admin.
Continua a leggere Continua a leggere
walkthroughsHTB Giddy Walkthrough: SQL Injection e CVE-2016-6914
Hack The Box Giddy write-up completo: SQL Injection, NTLMv2 hash capture, accesso WinRM , Bypass AV e privilege escalation a SYSTEM tramite CVE-2016-6914.
Continua a leggere Continua a leggere
walkthroughsHTB Love Walkthrough: SSRF, SQLi Time-Based e Privesc
Write-Up HTB Love,Easy VM : SQLi time-based, tentativo NTLM su Responder, SSRF verso la 5000 e privesc con AlwaysInstallElevated. Ogni vicolo cieco spiegato.
Continua a leggere Continua a leggere
walkthroughsHTB Eighteen Walkthrough: MSSQL e privesc BadSuccessor(dMSA)
WriteUp Hack The Bpx Eighteen: impersonation MSSQL, cracking hash Werkzeug PBKDF2, privilege escalation con BadSuccessor (CVE-2025-53779) su Windows Server 2025
Continua a leggere Continua a leggere
walkthroughsVoleur HTB: Writeup con Kerberoasting, DPAPI e WSL Privesc
Walkthrough completo di Voleur di Hack The Box: targeted Kerberoasting, abuso AD Recycle Bin, catena DPAPI e privilege escalation via WSL fino ad Administrator.
Continua a leggere Continua a leggere
walkthroughsHTB Scepter Walkthrough: NFS, ESC9, ESC14 e DCSync
WriteUp completo a Hack The Box Scepter: NFS, certificati PFX/PEM, ADCS ESC9, ESC14, altSecurityIdentities e DCSync finale.
Continua a leggere Continua a leggere
walkthroughsHTB Anubis Walkthrough — ASP SSTI, Jamovi RCE e ADCS ESC4
Walkthrough completo di Hack The Box Anubis (Insane, Windows): ASP SSTI per shell in Docker, CVE-2021-28079 su Jamovi per foothold su host, e privilege escalation via ADCS ESC4 con GenericAll su certificate template.
Continua a leggere Continua a leggere
walkthroughsHTB Haze Walkthrough: Splunk RCE e AD Attack Chain
Writeup HTB Haze: CVE-2024-36991 su Splunk, decryption credenziali con splunksecrets, GMSA abuse, Shadow Credentials su AD e RCE fino a SYSTEM.
Continua a leggere Continua a leggere
walkthroughsHTB Search Walktrough – GMSA, Kerberoast e AD Certificate
Writeup completo di HTB Search: foothold tramite credenziali in un'immagine, Kerberoasting, GMSA abuse e due path distinti verso Domain Admin.
Continua a leggere Continua a leggere
walkthroughsHTB Scrambled Walkthrough: Silver Ticket e .NET Deserialization
Writeup HTB Scrambled: Kerberoasting, Silver Ticket su MSSQL e RCE via BinaryFormatter insecure deserialization. Analisi statica con dnSpy e ysoserial.net
Continua a leggere Continua a leggere
walkthroughsHTB Sekhmet Walkthrough: Node.js Deserialization, WAF Bypass e DPAPI
HTB Sekhmet Insane,WriteUp Completo: insecure deserialization in node-serialize, bypass ModSecurity con Unicode encoding, ZipCrypto, Kerberos su Linux e DPAPI su Active Directory.
Continua a leggere Continua a leggere
walkthroughsHTB ProLab Dante: Review Completa 2026 – Vale la Pena Farlo?
Review HTB ProLab Dante: struttura del lab, punti di forza sul pivoting, problemi reali con OS datati e CVE unintended. A chi serve davvero e quando saltarlo.
Continua a leggere Continua a leggere
walkthroughsHTB Hathor Walkthrough ITA: AppLocker Bypass, DLL Hijacking e DCSync su Windows Insane
Walkthrough HTB Hathor: AppLocker bypass, DLL hijacking su SMB, code signing con certificato rubato e DCSync senza NTLM. Macchina Windows Insane
Continua a leggere Continua a leggere
walkthroughsOsaka Walkthrough – OffSec PG | BOF, ROP Chain & DEP Bypass
Walkthrough Osaka – OffSec Proving Grounds: format string → ASLR bypass, ROP chain con VirtualAlloc → DEP bypass, shellcode e SeDebugPrivilege → SYSTEM.
Continua a leggere Continua a leggere
