<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>404Gh0st Blog</title><description>CTF writeups, HackTheBox notes, and security work.</description><link>https://404gh0st.my.id/</link><item><title>BITSCTF 2026</title><link>https://404gh0st.my.id/blog/bitsctf/</link><guid isPermaLink="true">https://404gh0st.my.id/blog/bitsctf/</guid><description>Writeup for BITSCTF 2026</description><pubDate>Sun, 22 Feb 2026 00:00:00 GMT</pubDate></item><item><title>HTB: Fluffy</title><link>https://404gh0st.my.id/blog/fluffy/</link><guid isPermaLink="true">https://404gh0st.my.id/blog/fluffy/</guid><description>Fluffy is an easy Windows machine that demonstrates CVE-2025-24071, Shadow Credentials technique, and ESC16 vulnerability on ADCS.</description><pubDate>Sat, 31 May 2025 00:00:00 GMT</pubDate></item><item><title>HTB: Nocturnal</title><link>https://404gh0st.my.id/blog/nocturnal/</link><guid isPermaLink="true">https://404gh0st.my.id/blog/nocturnal/</guid><description>Nocturnal is an easy Linux machine that demonstrates command injection bypass and privilege escalation using CVE-2023-46818.</description><pubDate>Sat, 31 May 2025 00:00:00 GMT</pubDate></item><item><title>HTB: Planning</title><link>https://404gh0st.my.id/blog/planning/</link><guid isPermaLink="true">https://404gh0st.my.id/blog/planning/</guid><description>Planning is an easy Linux machine that demonstrates CVE-2024-9264 to get initial access and using crontab-ui to escalate privilege.</description><pubDate>Sat, 31 May 2025 00:00:00 GMT</pubDate></item><item><title>HTB: Puppy</title><link>https://404gh0st.my.id/blog/puppy/</link><guid isPermaLink="true">https://404gh0st.my.id/blog/puppy/</guid><description>Puppy is a medium Windows machine. This is a grey box machine with a supplied credential. With the credential, we can take advantage of GenericWrite to get access to specific shares. Then, we found a KeePass database file that contains a valid credential for another user account. This user account has GenericAll to another user account that belongs to the Remote Management Users group. There will be a backup file that contains another credential inside the machine. Using the credential, we found a saved credential in the DPAPI that contains a credential for administrative user account.</description><pubDate>Fri, 30 May 2025 00:00:00 GMT</pubDate></item><item><title>HTB: Environment</title><link>https://404gh0st.my.id/blog/environment/</link><guid isPermaLink="true">https://404gh0st.my.id/blog/environment/</guid><description>Environment is a Linux machine. The box involves exploiting a Laravel web application vulnerability (CVE-2024-52301) to bypass authentication and upload a shell. It involves finding and decrypting a GPG backup file to obtain credentials, and finally escalating privileges to root by abusing sudo permissions and the BASH_ENV variable.</description><pubDate>Sun, 04 May 2025 00:00:00 GMT</pubDate></item><item><title>HTB: Haze</title><link>https://404gh0st.my.id/blog/haze/</link><guid isPermaLink="true">https://404gh0st.my.id/blog/haze/</guid><description>Haze is a challenging Active Directory machine characterized by a vulnerable Splunk installation and security configurations. The machine involves CVE-2024-36991, decrypting the Splunk secret, exploiting multiple ACL/ACE vulnerabilities, and abusing SeImpersonatePrivilege.</description><pubDate>Mon, 31 Mar 2025 00:00:00 GMT</pubDate></item><item><title>HTB: Code</title><link>https://404gh0st.my.id/blog/code/</link><guid isPermaLink="true">https://404gh0st.my.id/blog/code/</guid><description>Code is an easy Linux machine that demonstrates a Python Jail / Sandbox escape and privilege escalation from backy program.</description><pubDate>Sun, 23 Mar 2025 00:00:00 GMT</pubDate></item><item><title>HTB: TheFrizz</title><link>https://404gh0st.my.id/blog/thefrizz/</link><guid isPermaLink="true">https://404gh0st.my.id/blog/thefrizz/</guid><description>TheFrizz is a medium Windows machine. The box involves attacking a domain controller using Kerberos authentication, abusing Group Policy Objects (GPO), and leveraging the Recycle Bin. The attack path includes exploiting CVE-2023-45878 on Gibbon LMS, obtaining credentials, manipulating GPO settings, and finally achieving system access.</description><pubDate>Mon, 17 Mar 2025 00:00:00 GMT</pubDate></item><item><title>HTB: Dog</title><link>https://404gh0st.my.id/blog/dog/</link><guid isPermaLink="true">https://404gh0st.my.id/blog/dog/</guid><description>Dog is an easy Linux machine that demonstrates exposed Git repository, vulnerable Backdrop CMS installation, and privilege escalation through Backdrop CMS bee utility program.</description><pubDate>Mon, 10 Mar 2025 00:00:00 GMT</pubDate></item><item><title>HTB: Cypher</title><link>https://404gh0st.my.id/blog/cypher/</link><guid isPermaLink="true">https://404gh0st.my.id/blog/cypher/</guid><description>Cypher is a medium-difficulty box that demonstrates Cypher injection, JAR file reversing, and privilege escalation through bbot.</description><pubDate>Sun, 02 Mar 2025 00:00:00 GMT</pubDate></item><item><title>HTB: Checker</title><link>https://404gh0st.my.id/blog/checker/</link><guid isPermaLink="true">https://404gh0st.my.id/blog/checker/</guid><description>Checker is a challenging machine that demonstrates CVE-2023-1545 on Teampass, CVE-2023-6199 on BookStack, the use of Google Authenticator as SSH TOTP, and a race condition on shared memory for privilege escalation.</description><pubDate>Fri, 28 Feb 2025 00:00:00 GMT</pubDate></item><item><title>HTB: Titanic</title><link>https://404gh0st.my.id/blog/titanic/</link><guid isPermaLink="true">https://404gh0st.my.id/blog/titanic/</guid><description>Titanic is an easy Linux machine that demonstrates a basic Arbitrary File Read vulnerability, Gitea hash cracking, and exploitation of a vulnerable version of ImageMagick.</description><pubDate>Sat, 22 Feb 2025 00:00:00 GMT</pubDate></item><item><title>HTB: DarkCorp</title><link>https://404gh0st.my.id/blog/darkcorp/</link><guid isPermaLink="true">https://404gh0st.my.id/blog/darkcorp/</guid><description>Coming Soon</description><pubDate>Sat, 15 Feb 2025 00:00:00 GMT</pubDate></item><item><title>HTB: Vintage</title><link>https://404gh0st.my.id/blog/vintage/</link><guid isPermaLink="true">https://404gh0st.my.id/blog/vintage/</guid><description>Vintage is a challenging Active Directory machine characterized by disabled NTLM authentication, enabled antivirus protection, and complex security configurations. The machine involves exploiting a Pre-2000 computer account, leveraging multiple ACL/ACE vulnerabilities, decrypting Data Protection API (DPAPI) secrets, and manipulating Resource-Based Constrained Delegation.</description><pubDate>Wed, 15 Jan 2025 00:00:00 GMT</pubDate></item></channel></rss>