<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>TryHackMe on Th3B0yWh0L1v3d — Security Writeups</title>
    <link>https://th3b0ywh0l1v3d.github.io/thm/</link>
    <description>Recent content in TryHackMe on Th3B0yWh0L1v3d — Security Writeups</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 09 Jun 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://th3b0ywh0l1v3d.github.io/thm/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Flip Dat Bit — TryHackMe</title>
      <link>https://th3b0ywh0l1v3d.github.io/thm/flip-dat-bit/</link>
      <pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/thm/flip-dat-bit/</guid>
      <description>A TCP service hands you the AES-CBC ciphertext of your own input and asks you to return a ciphertext that decrypts to contain admin credentials — solved with a single-byte XOR flip.</description>
    </item>
    <item>
      <title>Intermediate Nmap — TryHackMe</title>
      <link>https://th3b0ywh0l1v3d.github.io/thm/intermediate-nmap/</link>
      <pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/thm/intermediate-nmap/</guid>
      <description>A full-range nmap scan uncovers a port 31337 service broadcasting SSH credentials in plaintext — connecting the dots between -sV output and an SSH login to grab the flag.</description>
    </item>
    <item>
      <title>Reset — TryHackMe</title>
      <link>https://th3b0ywh0l1v3d.github.io/thm/reset/</link>
      <pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/thm/reset/</guid>
      <description>Anonymous SMB leaks a default onboarding password; AS-REP roasting cracks TABATHA_BRITT; a three-link BloodHound ACL chain of forced password resets leads to DARLA_WINTERS, whose constrained delegation with protocol transition lets us impersonate Administrator via S4U2Self/S4U2Proxy for a full domain dump.</description>
    </item>
    <item>
      <title>El Bandito — TryHackMe</title>
      <link>https://th3b0ywh0l1v3d.github.io/thm/el-bandito/</link>
      <pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/thm/el-bandito/</guid>
      <description>An exposed Spring Boot Actuator plus an nginx /.;/ path-ACL bypass leaks admin creds and the first flag; an HTTP/2 H2.CL desync then captures an internal bot&amp;rsquo;s request, stealing its flag cookie.</description>
    </item>
    <item>
      <title>HeartBleed — TryHackMe</title>
      <link>https://th3b0ywh0l1v3d.github.io/thm/heartbleed/</link>
      <pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/thm/heartbleed/</guid>
      <description>A vulnerable nginx server exposes OpenSSL&amp;rsquo;s Heartbleed bug (CVE-2014-0160), allowing unauthenticated heap memory disclosure that leaks a plaintext HTTP POST body — and the flag — straight out of an active SSL session.</description>
    </item>
    <item>
      <title>Padelify — TryHackMe</title>
      <link>https://th3b0ywh0l1v3d.github.io/thm/padelify/</link>
      <pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/thm/padelify/</guid>
      <description>A padel-tournament portal behind a deny-list ModSecurity WAF falls to a three-step chain: a User-Agent header bypass, a stored XSS that steals a moderator bot&amp;rsquo;s session cookie, and an LFI that leaks admin creds via full per-character URL-encoding.</description>
    </item>
    <item>
      <title>Plant Photographer — TryHackMe</title>
      <link>https://th3b0ywh0l1v3d.github.io/thm/plant-photographer/</link>
      <pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/thm/plant-photographer/</guid>
      <description>SSRF via a pycurl download endpoint chains into file:// LFI, Werkzeug debug PIN cracking, and full RCE on a Dockerised Flask app.</description>
    </item>
    <item>
      <title>Robots — TryHackMe</title>
      <link>https://th3b0ywh0l1v3d.github.io/thm/robots/</link>
      <pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://th3b0ywh0l1v3d.github.io/thm/robots/</guid>
      <description>XSS in a registration form exfiltrates the admin&amp;rsquo;s session cookie; RFI via the admin URL-tester gives www-data code execution; double-MD5 cracking yields SSH access, and a sudo apache2 logging trick writes a root SSH key.</description>
    </item>
  </channel>
</rss>
