All Writeups

Comprehensive collection of CTF challenges, solutions, and insights.


Filter by tag:

DarkNet Services Stage 3 Penetration Test

Six-machine multi-subnet compromise chaining SSRF, XML injection, ECDSA nonce reuse, LFI, TOCTOU race condition, MCP prompt injection, Docker container forensics, network pivoting, and a fresh kernel exploit to root every host and capture all five flags.

DarkNet Services Stage 2 Penetration Test

Four-machine /24 network compromise, chaining SQLi, SSTI, SMB enumeration, SNMP credential extraction, LD_PRELOAD privesc, and PHP deserialization RCE to root all hosts, then hijacking a live Cloudflare-tunneled domain by replacing its Flask backend with a socat proxy to the defaced web server.