Hacker101/Micro-CMS v1Hacker101 Micro-CMS v1 — full clearWalkthrough of all four flags: IDOR, stored XSS, broken access control on edit, and a hidden admin panel.WebeasyGitHub#web#idor#xssMay 16, 2026
Google CTF 2024/sandbox-cookie·178ptsGoogle CTF 2024 — sandbox-cookieBypass the cookie sandbox via prototype pollution chained with a templated response.WebmediumGitHub#web#prototype-pollutionMay 16, 2026
pwn.college/Program Misusepwn.college — Program Misuse video walkthroughWorking through the dojo's SUID-binary misuse warm-ups one tool at a time.PwneasyYouTube#linux#pwn#suidMay 16, 2026
OWASP Juice Shop/Find the Score BoardJuice Shop — Score Board discovery walkthroughFind the hidden score board via client-side route discovery in the bundled Angular app.WebeasyBlog#web#juice-shop#client-sideMay 16, 2026
PortSwigger Web Security Academy/SQL injection in WHERE clausePortSwigger — SQLi in WHERE clause (filter products)Bypass the category filter with a UNION-based SELECT against a known column count.Webeasy#web#sqli#unionMay 16, 2026
VulnHub/Mr-Robot: 1Mr-Robot:1 — full chain (WordPress → fsociety)Dir busting reveals a WordPress install. Brute the login, drop a reverse shell via theme editor, then chase the three keys to root.WebmediumBlog#linux#boot2root#wordpressMay 16, 2026
Damn Vulnerable Web Application (DVWA)/Brute Force (Low)DVWA — Brute Force (Low)Hydra against the basic login form. No CSRF, no lockout, no rate limit — textbook target.Webeasy#web#beginner#dvwaMay 16, 2026
CryptoHack/RSA Starter 1·10ptsRSA Starter 1 — CryptoHackCompute 101^17 mod 22663 — the foundational primitive that powers every later RSA challenge.Cryptoeasy#crypto#rsa#modular-exponentiationMay 16, 2026
OverTheWire/Bandit Level 0 → 1OverTheWire Bandit Level 0 → 1SSH in as bandit0, read the password from a plain text file.Misceasy#beginner#linux#sshMay 16, 2026
picoCTF/Mod 26·10ptsMod 26 — picoCTFROT-13 the ciphertext — the title is a hint.Cryptoeasy#beginner#crypto#caesarMay 16, 2026
TryHackMe/BlueTryHackMe Blue — EternalBlue walkthroughClassic MS17-010 exploitation walkthrough using metasploit on a TryHackMe Windows 7 target.Misceasy#windows#smb#eternalblueMay 16, 2026
picoCTF 2024/Weirder RSA·200ptsWeirder RSA — solving with lattice reductionSmall private exponent: Wiener attack via continued fractions recovers d directly.CryptomediumMedium#crypto#rsa#wienerMay 16, 2026
Hack The Box/Weak RSA·20ptsHTB Weak RSA — factoring small N with FactorDBPublic modulus is in FactorDB. Recover p,q,d in seconds and decrypt the ciphertext.Cryptoeasy#crypto#rsa#factordbMay 16, 2026
TryHackMe/Pickle RickPickle Rick — TryHackMeThemed web room — three flags via dir busting, command panel bypass, and a sudo misconfig.Webeasy#web#enumeration#command-injectionMay 16, 2026
picoCTF/Obedient Cat·5ptsObedient Cat — picoCTFA friendly first challenge, solved in one line.Misceasy#beginner#linuxMay 16, 2026
Hack The Box/Emdee five for life·20ptsEmdee five for life — HTBSpeedrun MD5 challenge — keep one session, parse the string, post back the digest.Webeasy#web#scripting#md5May 16, 2026
Hack The Box/SmartHireSmartHire — Hack The BoxRecon turns up a careers portal and a staging API behind the same cert.Miscmedium#linux#medium#hacktheboxMay 16, 2026
Hack The Box/HelixHelix — Hack The BoxAn exposed research site leaks version hints and a backup path.Miscmedium#linux#medium#hacktheboxMay 9, 2026
Hack The Box/PingPongPingPong — Hack The BoxInitial access starts from an oddly exposed management listener on Windows.Miscinsane#windows#insane#hacktheboxApr 25, 2026
Hack The Box/LoggingLogging — Hack The BoxThe box centers on centralized log ingestion with weak boundaries between collectors and readers.Miscmedium#windows#medium#hacktheboxApr 18, 2026