Archive
33 posts

Absolute
HackTheBox · Windows · Insane
AS-REP roasting, credential extraction from reverse-engineered binaries, BloodHound-based privilege escalation (Certipy/GenericAll), and KrbRelay for Domain Admin compromise.

Anomaly
HackSmarter · Windows
Jenkins RCE via Groovy script console, Linux privilege escalation through insecure binary execution, and AD domain compromise via ESC1 (ADCS) and machine account creation.

Principal
HackTheBox · Linux · Medium
Web authentication bypass via CVE-2026-29000, followed by credential harvesting and SSH certificate forgery for root privilege escalation.

Overwatch
HackTheBox · Windows · Medium
Initial access via exposed MSSQL instance, credential harvesting through SQL linked server poisoning, and system-level compromise via SOAP command injection.

House of Illusions
My Labs · 0xL4ugh v5 · web3
Privilege escalation via non-canonical ABIv1 encoding, leveraging offset/length overlap and dirty address word truncation to bypass admission gates and achieve Curator status.

Void Bound Blade
My Labs · 0xL4ugh v5 · web3
Access control bypass via fixed-offset selector confusion, Merkle path redirection via XOR manipulation, and relic-to-blade struct type confusion.

Flag 27 - Message replies
Hextree · Android
Sending IPC messages with a reply Messenger to capture response data from services.

Flag 26 - Basic message handler
Hextree · Android
Communicating with background Services via Messenger IPC and Message handlers.

Flag 25 - Service lifecycle
Hextree · Android
Binding to Android Services (bindService) and navigating service lifecycle states.

Flag 24 - Basic service start
Hextree · Android
Invoking exported Android background Services directly using startService.

Flag 23 - Hijack pending intent
Hextree · Android
Mutating mutable PendingIntents to escalate privileges and access non-exported components.

Flag 22 - Receive pending intent
Hextree · Android
Triggering PendingIntents received from services to execute unauthorized actions.

Flag 21 - Hijack notification button
Hextree · Android
Extracting and manipulating PendingIntents embedded in system notification actions.

Flag 20 - Notification button intents
Hextree · Android
Spoofing notification action button intent broadcasts to trigger background handlers.

Flag 19 - Widget System Intents
Hextree · Android
Spoofing App Widget update broadcasts (ACTION_APPWIDGET_UPDATE) to extract widget data.

Flag 18 - Hijack broadcast intent
Hextree · Android
Hijacking unsecured broadcast intents in transit to intercept leaked flag payloads.

Flag 17 - Receiver with response
Hextree · Android
Broadcasting intents to exposed receivers and reading returned result data.

Flag 16 - Basic exposed receiver
Hextree · Android
Exploiting exposed BroadcastReceivers by sending crafted broadcast intents.

Flag 15 - Create a intent-flag15 link
Hextree · Android
Crafting intent:// URI scheme links to invoke Android components directly from HTML.

Flag 14 - Hijack Web Login
Hextree · Android
Interception of web login implicit intents to capture authentication tokens.

Flag 13 - Create a hex-open link
Hextree · Android
Exploiting BROWSABLE deep links (hex://open) with browser application ID extras.

Flag 12 - Careful Intent Conditions
Hextree · Android
Satisfying complex Intent Filter conditions combining actions, categories, schemes, and types.

Flag 11 - Responding to an Implicit Intent
Hextree · Android
Building a custom activity to handle implicit intents and return required response data.

Flag 10 - Hijack Implicit Intent with the Flag
Hextree · Android
Hijacking implicit intents by registering a matching intent filter to steal outgoing data.

Flag 9 - Receive Result with Flag
Hextree · Android
Capturing and parsing sensitive flag data returned via onActivityResult Intent extras.

Flag 8 - Did You Expect a Result?
Hextree · Android
Using startActivityForResult to invoke an activity and trigger its result handler.

Flag 7 - Activity Lifecycle Tricks
Hextree · Android
Manipulating activity lifecycle state transitions (onPause/onResume) to trigger flag logic.

Flag 6 - Not Exported
Hextree · Android
Reaching non-exported Flag6Activity via Intent redirection through an exported activity.

Flag 5 - Intent in Intent
Hextree · Android
Wrapping a target Intent inside an extra parameter to exploit Intent-in-Intent parsing.

Flag 4 - State Machine
Hextree · Android
Invoking activities in a sequential state machine pattern to reach the final flag state.

Flag 3 - Intent with a Data URI
Hextree · Android
Constructing Intent Data URIs (https://hextree.io/flag) to pass URI verification.

Flag 2 - Intents With Extras
Hextree · Android
Passing required Intent extras to satisfy condition checks in Flag2Activity.

Flag 1 - Basic Exported Activities
Hextree · Android
Bypassing access controls by invoking explicit intents against exported Flag1Activity.
No signal found. Try a broader search or clear the active tags.