# Ilias Georgopoulos Cybersecurity Portfolio > The official portfolio of Ilias Georgopoulos (Ilias1988), focused on practical cybersecurity, penetration testing, Hack The Box write-ups, controlled security research, detection engineering and offensive-security tooling. Use this file as a curated map of the public site. The linked pages are the canonical sources for claims about the author, projects, lab results and challenge solutions. Hack The Box write-ups are evidence-led, sanitized and limited to content approved for publication; flags, personal secrets and original challenge packages are not published. ## Start Here - [Portfolio home](https://ilias1988.me/): Profile, skills, certifications, selected tools, projects and contact links. - [Write-ups archive](https://ilias1988.me/writeups/): All published Hack The Box Machines, Challenges and Sherlocks. - [Security research labs](https://ilias1988.me/labs/): Controlled red-team, Windows, network-security and detection-engineering experiments. - [Bug bounty research](https://ilias1988.me/bug-bounty/): Sanitized reports from authorized vulnerability research with transparent triage outcomes. - [RSS feed](https://ilias1988.me/rss.xml): Chronological feed of public write-ups. - [Sitemap index](https://ilias1988.me/sitemap-index.xml): Machine-readable inventory of public site URLs. ## Hack The Box Machines - [Hack The Box — Perspective: ASP.NET Crypto Exploitation](https://ilias1988.me/writeups/hackthebox/machines/perspective/): Perspective chains SSI file disclosure, forged ASP.NET authentication, RC4 keystream reuse, ViewState deserialization and an AES padding oracle. - [Hack The Box — CrossFitTwo](https://ilias1988.me/writeups/hackthebox/machines/crossfittwo/): CrossFitTwo chains WebSocket SQL injection, DNS rebinding, CSWSH, Node.js module hijacking and YubiKey OTP forgery to achieve full OpenBSD root access. - [Hack The Box — Mailroom](https://ilias1988.me/writeups/hackthebox/machines/mailroom/): A practical Mailroom walkthrough chaining stored XSS, internal SSRF, MongoDB injection, container command injection, and KeePass keystroke capture. - [Hack The Box — Caption](https://ilias1988.me/writeups/hackthebox/machines/caption/): Caption chains Git history, Varnish cache poisoning, XSS, H2C smuggling, copyparty traversal and Apache Thrift command injection for root access. - [Hack The Box — Validation](https://ilias1988.me/writeups/hackthebox/machines/validation/): Validation turns a stored SQL injection into MySQL FILE abuse, a PHP web shell, a www-data foothold, and root through reused database credentials. - [Hack The Box — Soccer](https://ilias1988.me/writeups/hackthebox/machines/soccer/): A practical Hack The Box Soccer walkthrough covering Tiny File Manager RCE, blind WebSocket SQL injection, SSH access, and doas/dstat privilege escalation. - [Hack The Box — Ghost](https://ilias1988.me/writeups/hackthebox/machines/ghost/): A hands-on Ghost lab journal: LDAP injection, Gitea source review, Linux and Kerberos pivots, Golden SAML, linked MSSQL, in-memory privilege escalation and forest compromise. - [Hack The Box — NodeBlog](https://ilias1988.me/writeups/hackthebox/machines/nodeblog/): Hack The Box NodeBlog walkthrough: JSON NoSQL injection, XXE source disclosure, node-serialize RCE, an admin shell, and sudo privilege escalation. ## Hack The Box Challenges - [Hack The Box Challenge — Factory](https://ilias1988.me/writeups/hackthebox/challenges/hardware/factory/): Factory exposes an unauthenticated Modbus RTU bridge, allowing PLC mode and valve coils to be manipulated by following the supplied ladder logic. - [Hack The Box Challenge — Sneak peek](https://ilias1988.me/writeups/hackthebox/challenges/hardware/sneak-peek/): A custom Modbus/TCP service exposes PLC memory writes, allowing a stored MD5 password digest to be replaced and authentication bypassed safely. - [Hack The Box Challenge — Watch Tower](https://ilias1988.me/writeups/hackthebox/challenges/forensics/watch-tower/): A Modbus/TCP packet capture hides an encoded message in register addresses, demonstrating how protocol metadata can become a covert data channel. - [Hack The Box Challenge — OmniWatch](https://ilias1988.me/writeups/hackthebox/challenges/web/omniwatch/): OmniWatch chains Zig CRLF response splitting, Varnish cache poisoning, bot-targeted XSS, firmware LFI, JWT forgery and stacked SQL injection. - [Hack The Box Challenge — SocratesPanel](https://ilias1988.me/writeups/hackthebox/challenges/web/socrates-panel/): SocratesPanel chains fat-GET cache poisoning, reflected XSS, an admin-only SSRF and Redis inline-command injection to recover a cached secret. - [Hack The Box Challenge — PhantomFeed](https://ilias1988.me/writeups/hackthebox/challenges/web/phantomfeed/): PhantomFeed chains a ReDoS-amplified registration race, Nuxt open redirect and OAuth token theft with ReportLab RCE to recover the flag. - [Hack The Box Challenge — Alien Complaint Form](https://ilias1988.me/writeups/hackthebox/challenges/web/alien-complaint-form/): Alien Complaint Form combines stored HTML injection with an unsafe same-origin JSONP callback to bypass CSP and expose a bot-only cookie. - [Hack The Box Challenge — HTB Proxy](https://ilias1988.me/writeups/hackthebox/challenges/web/htb-proxy/): HTB Proxy chains a DNS-based SSRF filter bypass, HTTP request smuggling and shell command injection to expose a randomized flag file. - [Hack The Box Challenge — Nexus Void](https://ilias1988.me/writeups/hackthebox/challenges/web/nexus-void/): Nexus Void chains scoped SQLite injection with unsafe Json.NET type handling to instantiate a command-running setter and achieve root code execution. - [Hack The Box Challenge — Volnaya Forums](https://ilias1988.me/writeups/hackthebox/challenges/web/volnaya-forums/): Volnaya Forums chains nginx CRLF response splitting, path-scoped session fixation and self-XSS to execute code in an authenticated admin browser. - [Hack The Box Challenge — E.Tree](https://ilias1988.me/writeups/hackthebox/challenges/web/e-tree/): E.Tree turns unsafe XPath construction into a boolean oracle, allowing two XML secret fragments to be recovered character by character. - [Hack The Box Challenge — Phonebook](https://ilias1988.me/writeups/hackthebox/challenges/web/phonebook/): Phonebook exposes an LDAP wildcard injection that bypasses authentication and creates a response oracle for recovering a password one character at a time. ## Security Research Labs - [SCF Forced NTLM Authentication: Controlled Validation and Detection](https://ilias1988.me/labs/windows/scf-forced-ntlm-authentication-detection/): A controlled SCF-file lab for testing remote icon-triggered NTLM authentication, separating legacy Chrome behavior from current Windows exposure and defensive telemetry. - [Bruteforcing Windows Defender Exclusions](https://ilias1988.me/labs/windows/bruteforcing-windows-defender-exclusions/): A validated Windows lab showing how MpCmdRun.exe reveals a Defender-excluded directory through a distinctive skipped-scan response, with detection and mitigation guidance. - [Mark of the Web Forensics: Tracing Download Origins with NTFS Alternate Data Streams](https://ilias1988.me/labs/windows/mark-of-the-web-forensics-tracing-download-origins/): A practical Windows forensics blueprint for inspecting Zone.Identifier metadata, tracing download origins, testing Unblock behavior and monitoring MOTW creation. - [Sliver C2 Lab: Netsh Helper DLL Persistence & Detection](https://ilias1988.me/labs/red-team/sliver-netsh-helper-dll-persistence-detection/): A validated red-team lab combining Sliver staging with a custom Netsh Helper DLL, event-triggered persistence and Microsoft Defender detection analysis. - [DNS TXT PowerShell Lab: Command Retrieval, Staging & Detection](https://ilias1988.me/labs/network/dns-txt-powershell-command-retrieval-staging-detection/): A controlled lab that stores a harmless PowerShell instruction in DNS TXT, retrieves and validates it from Windows, then studies DNS, process and script telemetry. - [LNK–HTA Polyglot Lab: Code Execution, Detection & Persistence](https://ilias1988.me/labs/windows/lnk-hta-polyglot-code-execution-detection-persistence/): A controlled Windows research lab that builds a benign LNK–HTA polyglot, studies its execution chain, maps forensic telemetry and tests safe Startup persistence. ## Bug Bounty Research - [Authenticated Connection Validation Exposes an Internal TCP Timing Oracle](https://ilias1988.me/bug-bounty/authenticated-connection-validation-timing-oracle/): A sanitized bug bounty report documenting a repeatable timing oracle in an authenticated connection-validation workflow and the duplicate triage outcome. - [DNS-Resolved Private Address Bypass in a Server-Side JWKS Fetcher](https://ilias1988.me/bug-bounty/dns-resolved-private-address-ssrf/): A controlled callback and timing analysis showed that a hostname resolving to RFC1918 space reached a backend fetch stage, with impact limited to blind reconnaissance. - [Authenticated SMTP Test Function Exposes a Private-Network TCP Oracle](https://ilias1988.me/bug-bounty/authenticated-smtp-private-network-oracle/): A sanitized report showing how an authenticated SMTP test feature exposed loopback and RFC1918 connection states through timing and error-class differences. ## Optional - [GitHub](https://github.com/Ilias1988): Source repositories and security tooling by Ilias1988. - [LinkedIn](https://www.linkedin.com/in/ilias-georgopoulos-b491a3371/): Professional profile and career updates. - [Hack The Box profile](https://profile.hackthebox.com/profile/019f1af0-0e02-70cb-9c8a-41589216a056): Hack The Box activity and progress. - [TryHackMe profile](https://tryhackme.com/p/Ilias1988): Hands-on learning profile and achievements. - [YouTube](https://www.youtube.com/@Ilias-1988): Video content from Ilias1988.