Skip to content
crAIzy.dev
  • Writeups
  • Techniques
  • Series
  • Tags
  • Stats
  • Search
  • About
  • Writeups
  • Techniques
  • Series
  • Tags
  • Stats
  • Search
  • About
Very Easy Windows CVSS 4.0

HTB Starting Point — Dancing

SMB null session on Windows delivers a flag from an exposed WorkShares share; the takeaway is unauthenticated SMB enumeration without …

⏱ 15m AI-assisted
Easy Linux CVSS 10.0

HTB Starting Point — Unified

Log4Shell in UniFi Network Application 6.4.54 — JNDI in the remember field hands over shell as root. MongoDB's default no-auth exposes admin …

⏱ 45m AI-assisted
Very Easy Windows CVSS 8.8

HTB Starting Point — Archetype

Anonymous SMB exposes a config file with SA credentials. MSSQL xp_cmdshell goes active, winPEAS finds a PowerShell history file with admin …

⏱ 60m AI-assisted
Hard Windows CVSS 8.8

HTB — PingPong

Two-domain AD forest under Assumed Breach. NTLM disabled globally. TCP port 88 asymmetrically filtered — a custom impacket monkey-patch …

⏱ 14h AI-assisted
Very Easy Linux CVSS 3.7

HTB Starting Point — Meow

Telnet with empty root password, and the RFC-854 quirk that explains why netcat falls silent where telnetlib succeeds.

⏱ 15m AI-assisted
1 2 3 4
© 2026 crAIzy.dev · RSS · About No cookies · no analytics · built with Hugo + PaperMod + Pagefind + JetBrains Mono