Hack The Box — Perspective: ASP.NET Crypto Exploitation
Perspective chains SSI file disclosure, forged ASP.NET authentication, RC4 keystream reuse, ViewState deserialization and an AES padding oracle.
Read write-uproot@kali:~$ ls ./writeups/machines
Complete, evidence-backed attack paths for retired Hack The Box machines.
Knowledge base
From initial enumeration to foothold, privilege escalation and final technical takeaways.
8 write-ups
Perspective chains SSI file disclosure, forged ASP.NET authentication, RC4 keystream reuse, ViewState deserialization and an AES padding oracle.
Read write-upCrossFitTwo chains WebSocket SQL injection, DNS rebinding, CSWSH, Node.js module hijacking and YubiKey OTP forgery to achieve full OpenBSD root access.
Read write-upA practical Mailroom walkthrough chaining stored XSS, internal SSRF, MongoDB injection, container command injection, and KeePass keystroke capture.
Read write-upCaption chains Git history, Varnish cache poisoning, XSS, H2C smuggling, copyparty traversal and Apache Thrift command injection for root access.
Read write-upValidation turns a stored SQL injection into MySQL FILE abuse, a PHP web shell, a www-data foothold, and root through reused database credentials.
Read write-upA practical Hack The Box Soccer walkthrough covering Tiny File Manager RCE, blind WebSocket SQL injection, SSH access, and doas/dstat privilege escalation.
Read write-upA hands-on Ghost lab journal: LDAP injection, Gitea source review, Linux and Kerberos pivots, Golden SAML, linked MSSQL, in-memory privilege escalation and forest compromise.
Read write-upHack The Box NodeBlog walkthrough: JSON NoSQL injection, XXE source disclosure, node-serialize RCE, an admin shell, and sudo privilege escalation.
Read write-upTry a broader search or clear one of the filters.