Research · Labs
Writeups
Full attack chains from recon through root. Enumeration notes, exploit paths, and privilege escalation documented as-run.
HackTheBox
Gavel
HTB Gavel writeup — a leaked .git repo, a clever PDO SQLi bypass, PHP-as-a-bidding-rule RCE, and a sandbox escape for root.
HackTheBox
Era
HTB Era writeup covering vhost discovery, an IDOR chain into admin, a PHP stream wrapper RCE, and ELF signature abuse for root.
HackTheBox
CodePartTwo
HTB CodePartTwo writeup covering enumeration and js2py sandbox escape.
Lab