Browsed — Medium Linux machine walkthrough cover

Browsed — HackTheBox Walkthrough

Browsed is a devious medium Linux box where you weaponize a Chrome extension upload feature to chain browser automation, bash arithmetic injection, and Python bytecode poisoning into a full root compromise.

January 10, 2026 · 9 min · Logan Dawson
Eloquia — Insane Windows machine walkthrough cover

Eloquia — HackTheBox Walkthrough

An Insane-rated Windows box chaining AngularJS CSTI, a subtle OAuth logical flaw, SQLite’s load_extension for DLL-based RCE, Edge DPAPI credential decryption, and .NET AppDomainManager injection to reach SYSTEM.

December 13, 2025 · 13 min · Logan Dawson
Fries — Hard Windows machine walkthrough cover

Fries — HackTheBox Walkthrough

Fries is a Hard Windows box that takes you through a dense multi-layer attack chain: credential leaks in Gitea, authenticated RCE in pgAdmin, Docker CA key theft, LDAP credential poisoning, and finally ADCS certificate abuse to own the domain.

November 22, 2025 · 9 min · Logan Dawson
Conversor — Easy Linux machine walkthrough cover

Conversor — HackTheBox Walkthrough

A Flask-based XML/XSLT converter with exposed source code, an unsanitized file upload, and a cron-powered RCE — topped off with a fresh needrestart CVE for root.

October 25, 2025 · 6 min · Logan Dawson
NanoCorp — HackTheBox Windows machine walkthrough cover

NanoCorp — HackTheBox Walkthrough

NanoCorp chains a sneaky NTLM capture through a hiring portal’s file upload, Active Directory ACL abuse via BloodHound, and a Checkmk MSI repair privilege escalation — all on a fully patched Windows Server 2022 DC.

8 min · Logan Dawson