<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Louizi Yassine — Writeups</title><description>Penetration tester &amp; cybersecurity student, ENSAM Casablanca — Top 1% on TryHackMe, found a critical P1 at OCP Group. Writeups on web exploitation &amp; privesc.</description><link>https://louizi-yassine.vercel.app/</link><language>en</language><item><title>HTB: Abducted</title><link>https://louizi-yassine.vercel.app/writeups/abducted/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/abducted/</guid><description>A guest-writable printer share on Samba is pre-auth RCE (CVE-2026-4480), rclone&apos;s reversible &quot;obscure&quot; format hands over a reused SSH password, and a Samba force-user share with insecure wide-link support becomes an arbitrary-file-write into a root-writable systemd drop-in.</description><pubDate>Mon, 10 Aug 2026 00:00:00 GMT</pubDate><category>HackTheBox</category><category>samba</category><category>rce</category><category>privesc</category><category>password-reuse</category></item><item><title>Hacker Holidays — Day 14: Management Wants a Word</title><link>https://louizi-yassine.vercel.app/writeups/hacker-holidays-day14/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/hacker-holidays-day14/</guid><description>A KAPE triage image of an abandoned laptop yields one saved Chrome password, decrypted entirely offline through a DPAPI masterkey → Local State → AES-GCM chain, which turns out to be the passphrase for a hidden VeraCrypt volume holding the real evidence.</description><pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate><category>TryHackMe</category><category>hacker-holidays</category><category>forensics</category><category>dpapi</category><category>veracrypt</category></item><item><title>HTB: Nimbus</title><link>https://louizi-yassine.vercel.app/writeups/nimbus/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/nimbus/</guid><description>Enumeration notes only — this box is still active on HackTheBox, so the exploit chain stays unpublished until it retires. Recon points at a cloud-native, container/AWS-emulation themed target.</description><pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate><category>HackTheBox</category><category>enumeration</category><category>recon</category></item><item><title>Hacker Holidays — Day 12: After Hours</title><link>https://louizi-yassine.vercel.app/writeups/hacker-holidays-day12/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/hacker-holidays-day12/</guid><description>Persistence hiding outside every autoruns tool&apos;s coverage — a malicious WMI class buried in the raw CIM repository carries a compressed .NET payload that only detonates on the domain controller by name.</description><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate><category>TryHackMe</category><category>hacker-holidays</category><category>forensics</category><category>wmi-persistence</category><category>dotnet-reversing</category></item><item><title>HTB: Nexus</title><link>https://louizi-yassine.vercel.app/writeups/nexus/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/nexus/</guid><description>Two independent leaks combine to log into a CRM as the wrong-but-reused password, an authenticated file-upload CVE gets a shell, and a custom root-owned systemd timer with unsanitised git plumbing is abused via a hand-crafted malicious tree object to plant an SSH key as root.</description><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate><category>HackTheBox</category><category>credential-access</category><category>file-upload</category><category>privesc</category><category>git-internals</category></item><item><title>Hacker Holidays — Day 11: Infinity Pool</title><link>https://louizi-yassine.vercel.app/writeups/hacker-holidays-day11/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/hacker-holidays-day11/</guid><description>The same unsanitised shell=True command injection shows up twice on this box — first as a low-priv foothold via a &quot;connectivity check&quot; tool, then again in a root-owned automation service reached by pivoting through internal-only FreePBX and Chisel tunnels.</description><pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate><category>TryHackMe</category><category>hacker-holidays</category><category>command-injection</category><category>pivoting</category><category>privesc</category></item><item><title>HTB: Fireflow</title><link>https://louizi-yassine.vercel.app/writeups/fireflow/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/fireflow/</guid><description>An unauthenticated Langflow RCE (CVE-2026-33017) leads to leaked superuser credentials via process environment, password reuse for user access, a JWT alg:none forgery against a custom MCP server, and finally a Kubernetes nodes/proxy verb bypass to a privileged pod for host root.</description><pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate><category>HackTheBox</category><category>rce</category><category>jwt</category><category>kubernetes</category><category>privesc</category><category>password-reuse</category></item><item><title>Hacker Holidays — Day 10: The Hollow Shell</title><link>https://louizi-yassine.vercel.app/writeups/hacker-holidays-day10/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/hacker-holidays-day10/</guid><description>A zip-slip flaw in a staff upload feature lets an extracted archive entry escape its per-upload folder and overwrite the app&apos;s own live Jinja template, turning a simple file upload into persistent SSTI/RCE.</description><pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate><category>TryHackMe</category><category>hacker-holidays</category><category>zip-slip</category><category>ssti</category><category>file-upload</category></item><item><title>HTB: Cap</title><link>https://louizi-yassine.vercel.app/writeups/cap/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/cap/</guid><description>A &quot;Security Snapshot&quot; dashboard lets any user page through other users&apos; packet captures by ID — one of them leaks an FTP password reused for SSH, and a stray Linux capability on python3.8 hands over root instantly.</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate><category>HackTheBox</category><category>idor</category><category>pcap-analysis</category><category>linux-capabilities</category><category>privesc</category></item><item><title>Hacker Holidays — Day 9: Crypto Cabana</title><link>https://louizi-yassine.vercel.app/writeups/hacker-holidays-day9/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/hacker-holidays-day9/</guid><description>An Azure static website leaks an over-scoped account SAS token, which exposes a hidden storage container holding service-principal credentials — and from there, a Key Vault secret whose &quot;rotated&quot; value is still recoverable in its previous version.</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate><category>TryHackMe</category><category>hacker-holidays</category><category>azure</category><category>cloud</category><category>sas-token</category><category>key-vault</category></item><item><title>Hacker Holidays — Day 8: Towel on the Sunbed</title><link>https://louizi-yassine.vercel.app/writeups/hacker-holidays-day8/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/hacker-holidays-day8/</guid><description>A crypto rewards app rate-limits its daily claim to once per 24h, but the check-then-act isn&apos;t atomic — firing 30 parallel requests with Burp&apos;s last-byte sync lets every one of them win the race.</description><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate><category>TryHackMe</category><category>hacker-holidays</category><category>race-condition</category><category>business-logic</category></item><item><title>Hacker Holidays — Day 7: Do Not Disturb</title><link>https://louizi-yassine.vercel.app/writeups/hacker-holidays-day7/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/hacker-holidays-day7/</guid><description>A NoSQL injection auth bypass leads to an EJS SSTI RCE, then an exposed Node --inspect debugger and disk-group membership chain all the way to a raw block-device read of root.txt.</description><pubDate>Sun, 02 Aug 2026 00:00:00 GMT</pubDate><category>TryHackMe</category><category>hacker-holidays</category><category>nosql-injection</category><category>ssti</category><category>privesc</category></item><item><title>Hacker Holidays — Day 6: Overheard at Breakfast</title><link>https://louizi-yassine.vercel.app/writeups/hacker-holidays-day6/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/hacker-holidays-day6/</guid><description>A screenshotted chat reveals an email address and a hint about a &quot;free profile linker starting with G&quot; — hashing the email for Gravatar and pulling its JSON profile surfaces a hidden bio with the flag.</description><pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate><category>TryHackMe</category><category>hacker-holidays</category><category>osint</category></item><item><title>TryHackMe: Wreath</title><link>https://louizi-yassine.vercel.app/writeups/wreath/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/wreath/</guid><description>A three-host network pivot: a Webmin RCE foothold, chisel/socat relays into an isolated GitStack server and a personal PC, a leaked git repo revealing a file-upload webshell, PHP payload obfuscation for AV evasion, and an unquoted-service-path privesc to SYSTEM.</description><pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate><category>TryHackMe</category><category>pivoting</category><category>av-evasion</category><category>privesc</category><category>rce</category><category>credential-access</category></item><item><title>Hacker Holidays — Day 5: Beach Bar</title><link>https://louizi-yassine.vercel.app/writeups/hacker-holidays-day5/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/hacker-holidays-day5/</guid><description>Demo creds in an HTML comment lead to an unsafe YAML deserialization RCE in a playlist importer, then a root password exposed in plain process arguments gets reused directly for su root.</description><pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate><category>TryHackMe</category><category>hacker-holidays</category><category>insecure-deserialization</category><category>privesc</category><category>credential-access</category></item><item><title>Hacker Holidays — Day 4: Packed Light</title><link>https://louizi-yassine.vercel.app/writeups/hacker-holidays-day4/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/hacker-holidays-day4/</guid><description>A PCAP shows a covert channel exfiltrating one byte per HTTP request inside a Cookie header — base64 plus a single-byte XOR, broken instantly with a known-plaintext crib on the flag format.</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate><category>TryHackMe</category><category>hacker-holidays</category><category>forensics</category><category>network-forensics</category></item><item><title>Hacker Holidays — Day 3: Complimentary</title><link>https://louizi-yassine.vercel.app/writeups/hacker-holidays-day3/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/hacker-holidays-day3/</guid><description>A &quot;free&quot; wellness app hands out unauthenticated Cognito guest credentials, and an over-scoped IAM role lets those guest credentials Scan the entire DynamoDB table instead of just one record.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate><category>TryHackMe</category><category>hacker-holidays</category><category>cloud</category><category>aws</category><category>idor</category></item><item><title>Hacker Holidays — Day 2: Room 404</title><link>https://louizi-yassine.vercel.app/writeups/hacker-holidays-day2/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/hacker-holidays-day2/</guid><description>A Flask app leaves .git/ reachable — git-dumper reconstructs the full repo, and a &quot;remove before launch&quot; note in the staging README hands over the flag directly.</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate><category>TryHackMe</category><category>hacker-holidays</category><category>web</category><category>source-code-disclosure</category></item><item><title>Hacker Holidays — Day 1: The Concierge Knows Too Much</title><link>https://louizi-yassine.vercel.app/writeups/hacker-holidays-day1/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/hacker-holidays-day1/</guid><description>An LLM hotel concierge gates its system prompt behind guest &quot;trust&quot; rather than real auth — claiming a recognized name plus asking it to reveal its instructions dumps the whole prompt, escalation code included.</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate><category>TryHackMe</category><category>hacker-holidays</category><category>llm-security</category><category>prompt-injection</category></item><item><title>TryHackMe: You Got Mail</title><link>https://louizi-yassine.vercel.app/writeups/you-got-mail/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/you-got-mail/</guid><description>OSINT-harvested employee emails feed a credential spray against an hMailServer instance, and the resulting SMTP access is used to phish a reverse-shell payload straight to the mail server itself.</description><pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate><category>TryHackMe</category><category>osint</category><category>phishing</category><category>credential-access</category><category>privesc</category></item><item><title>HTB Academy: Password Attacks — Skills Assessment</title><link>https://louizi-yassine.vercel.app/writeups/htb-password-attacks-skills-assessment/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/htb-password-attacks-skills-assessment/</guid><description>Chained credential attacks across a segmented AD network: SSH user enumeration, cleartext creds in a Password Safe backup, a SOCKS pivot through a jump host, and an LSASS dump feeding a DCSync.</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate><category>HackTheBox</category><category>active-directory</category><category>password-attacks</category><category>credential-access</category><category>pivoting</category></item><item><title>TryHackMe: Interceptor</title><link>https://louizi-yassine.vercel.app/writeups/interceptor/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/interceptor/</guid><description>Two-factor login bypassed via OTP mass assignment (brute force also works, but was not the intended path), then a curl-injection bug in a feed importer used to read /var/www/user.txt off the box.</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate><category>TryHackMe</category><category>web</category><category>mass-assignment</category><category>brute-force</category><category>rce</category></item><item><title>TryHackMe: IronHold</title><link>https://louizi-yassine.vercel.app/writeups/ironhold/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/ironhold/</guid><description>White-box Java Spring app: hardcoded/actuator-leaked credentials, a UNION-based SQL injection, mass-assignment privilege escalation to WARDEN, and a commons-collections gadget chain for RCE.</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate><category>TryHackMe</category><category>web</category><category>sql-injection</category><category>deserialization</category><category>privesc</category><category>source-code-review</category></item><item><title>TryHackMe: Operation Endgame</title><link>https://louizi-yassine.vercel.app/writeups/operation-endgame/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/operation-endgame/</guid><description>Active Directory chain: guest-account Kerberoasting, password reuse, a targeted Kerberoast via GenericWrite, and hardcoded creds in a PowerShell script leading to a SYSTEM shell.</description><pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate><category>TryHackMe</category><category>active-directory</category><category>kerberoasting</category><category>password-spraying</category><category>privesc</category></item><item><title>VulnHub: Boot2root (Rick &amp; Morty)</title><link>https://louizi-yassine.vercel.app/writeups/boot2root-rickmorty/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/boot2root-rickmorty/</guid><description>A CeWL-generated wordlist cracks Joomla admin, template editing gets a reverse shell, and hardcoded credentials in an automation script complete a sudo (ALL:ALL) escalation to root.</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><category>VulnHub</category><category>web</category><category>cms</category><category>privesc</category><category>credential-access</category></item><item><title>VulnHub: DC-1</title><link>https://louizi-yassine.vercel.app/writeups/dc-1/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/dc-1/</guid><description>Drupalgeddon2 (CVE-2018-7600) gets an in-memory shell via Metasploit, then a SUID find binary hands over root through a one-line GTFOBins exploit.</description><pubDate>Sat, 11 Apr 2026 00:00:00 GMT</pubDate><category>VulnHub</category><category>web</category><category>cms</category><category>rce</category><category>privesc</category></item><item><title>VulnHub: Venom</title><link>https://louizi-yassine.vercel.app/writeups/venom/</link><guid isPermaLink="true">https://louizi-yassine.vercel.app/writeups/venom/</guid><description>An MD5 hash in a page comment cracks FTP access, a hint file and a Vigenère cipher unlock a CMS admin panel, and a known Subrion CMS RCE leads to root via a hardcoded backup password.</description><pubDate>Sat, 11 Apr 2026 00:00:00 GMT</pubDate><category>VulnHub</category><category>web</category><category>cms</category><category>rce</category><category>cryptography</category><category>credential-access</category></item></channel></rss>