<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Adversarial Work</title><description>Cybersecurity writeups, research notes, and offensive security experiments from Eddison King.</description><link>https://adversarial.work/</link><item><title>HTB Writeup - Freelancer</title><link>https://adversarial.work/blog/writeup-freelancer/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-freelancer/</guid><description>**No Spoilers Hints** - Registration flows reveal more than they should. - Look for admin tooling and backend trust mistakes. Enumeration We start off with a...</description><pubDate>Thu, 20 Feb 2025 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Windows</category><category>Web</category><category>Active</category><category>Directory</category><author>Eddison King</author></item><item><title>HTB Writeup - Cicada</title><link>https://adversarial.work/blog/writeup-cicada/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-cicada/</guid><description>**No Spoilers Hints** - Start with SMB and read-only shares. - Directory data leaks more than the login screen. Enumeration As usual, we start off with an nm...</description><pubDate>Mon, 10 Feb 2025 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Windows</category><author>Eddison King</author></item><item><title>HTB Writeup - Caption</title><link>https://adversarial.work/blog/writeup-caption/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-caption/</guid><description>**No Spoilers Hints** - Git hosting and SQL tooling both deserve attention. - Internal services sit behind a trust boundary. Enumeration As usual, we start o...</description><pubDate>Wed, 15 Jan 2025 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Linux</category><author>Eddison King</author></item><item><title>HTB Writeup - Gobox</title><link>https://adversarial.work/blog/writeup-gobox/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-gobox/</guid><description>**No Spoilers Hints** - Template rendering deserves a closer look. - Go-based services often hide surprising injection paths. Enumeration As per usual, we st...</description><pubDate>Sun, 05 Jan 2025 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Linux</category><author>Eddison King</author></item><item><title>HTB Writeup - Sightless</title><link>https://adversarial.work/blog/writeup-sightless/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-sightless/</guid><description>**No Spoilers Hints** - The first foothold is a browser-based SQL tool. - Local-only services and admin panels matter later. Enumeration As usual, we start o...</description><pubDate>Fri, 20 Dec 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Linux</category><author>Eddison King</author></item><item><title>HTB Writeup - Blurry</title><link>https://adversarial.work/blog/writeup-blurry/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-blurry/</guid><description>**No Spoilers Hints** - The web app wants local setup before anything useful. - Look closely at ML tooling and model handling. Enumeration As usual, we start...</description><pubDate>Sun, 01 Dec 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Linux</category><category>Python</category><category>ClearML</category><author>Eddison King</author></item><item><title>HTB Writeup - Trickster</title><link>https://adversarial.work/blog/writeup-trickster/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-trickster/</guid><description>**No Spoilers Hints** - Source control leaks the important admin path. - Containerized tooling hides the real privilege boundary. Enumeration As usual, start...</description><pubDate>Fri, 22 Nov 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Linux</category><author>Eddison King</author></item><item><title>HTB Writeup - Instant</title><link>https://adversarial.work/blog/writeup-instant/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-instant/</guid><description>**No Spoilers Hints** - The mobile app is part of the attack surface. - Inspect the APK, not just the website. Enumeration As usual, we start off with an nma...</description><pubDate>Wed, 16 Oct 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Linux</category><author>Eddison King</author></item><item><title>HTB Writeup - Grandpa</title><link>https://adversarial.work/blog/writeup-grandpa/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-grandpa/</guid><description>**No Spoilers Hints** - Old IIS-era web servers deserve immediate scrutiny. - Classic web-server CVEs fit this box. Enumeration As usual, we start off with a...</description><pubDate>Sat, 14 Sep 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Windows</category><author>Eddison King</author></item><item><title>HTB Writeup - Paper</title><link>https://adversarial.work/blog/writeup-paper/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-paper/</guid><description>**No Spoilers Hints** - WordPress is only the start here. - Linux service abuse appears later in the chain. Enumeration Let&apos;s start off with an nmap scan as...</description><pubDate>Thu, 12 Sep 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Linux</category><category>Sudo v1.8.29</category><category>rocket.chat</category><author>Eddison King</author></item><item><title>HTB Writeup - Sau</title><link>https://adversarial.work/blog/writeup-sau/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-sau/</guid><description>**No Spoilers Hints** - Proxying requests to localhost opens the real target. - A sudo pager can become a shell. Enumeration As usual, we start off with an n...</description><pubDate>Mon, 09 Sep 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Linux</category><category>SSRF</category><category>Command Injection</category><author>Eddison King</author></item><item><title>HTB Writeup - Buff</title><link>https://adversarial.work/blog/writeup-buff/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-buff/</guid><description>**No Spoilers Hints** - A flaky local service can break the whole chain. - Restarting can bring the missing piece back. Hints 1. There is something in this b...</description><pubDate>Sat, 07 Sep 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Windows</category><author>Eddison King</author></item><item><title>HTB Writeup - Traverxec</title><link>https://adversarial.work/blog/writeup-traverxec/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-traverxec/</guid><description>**No Spoilers Hints** - A vintage web server exposes home-directory content. - Configuration files and user-owned archives matter. Enumeration As usual, we s...</description><pubDate>Thu, 05 Sep 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Linux</category><author>Eddison King</author></item><item><title>HTB Writeup - Traceback</title><link>https://adversarial.work/blog/writeup-traceback/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-traceback/</guid><description>**No Spoilers Hints** - Hidden comments point to the real entry point. - Watch for login-time scripts and writable MOTD files. Enumeration As usual, we start...</description><pubDate>Tue, 03 Sep 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Linux</category><author>Eddison King</author></item><item><title>HTB Writeup - Precious</title><link>https://adversarial.work/blog/writeup-precious/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-precious/</guid><description>**No Spoilers Hints** - Rendered documents are the weak link. - Watch where URLs become PDFs. Enumeration As usual, we start with an nmap scan to get a listi...</description><pubDate>Mon, 02 Sep 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Linux</category><author>Eddison King</author></item><item><title>HTB Writeup - Knife</title><link>https://adversarial.work/blog/writeup-knife/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-knife/</guid><description>**No Spoilers Hints** - Version-specific PHP behavior is the key clue. - Check scheduled tasks and sudo allowances after entry. Enumeration As usual, we star...</description><pubDate>Sun, 01 Sep 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Linux</category><category>PHP</category><author>Eddison King</author></item><item><title>HTB Writeup - Greenhorn</title><link>https://adversarial.work/blog/writeup-greenhorn/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-greenhorn/</guid><description>**No Spoilers Hints** - Look for reused secrets in the web app. - CMS plugins and local services both matter. Enumeration As usual, we start off with an nmap...</description><pubDate>Wed, 28 Aug 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Linux</category><category>Web</category><author>Eddison King</author></item><item><title>HTB Writeup - MonitorsThree</title><link>https://adversarial.work/blog/writeup-monitorsthree/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-monitorsthree/</guid><description>**No Spoilers Hints** - The monitoring stack leaks useful application context. - Internal backup tooling becomes relevant later. Enumeration As usual, we sta...</description><pubDate>Sun, 25 Aug 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Linux</category><author>Eddison King</author></item><item><title>HTB Writeup - Cap</title><link>https://adversarial.work/blog/writeup-cap/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-cap/</guid><description>**No Spoilers Hints** - Packet captures can leak the first breadcrumb. - Capability scans matter more than SUID here. Hints Enumeration As usual, we start wi...</description><pubDate>Wed, 21 Aug 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Linux</category><category>Capability</category><category>cap_setuid</category><category>pcap</category><author>Eddison King</author></item><item><title>HTB Writeup - Nibbles</title><link>https://adversarial.work/blog/writeup-nibbles/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-nibbles/</guid><description>**No Spoilers Hints** - Old blog software and plugin paths are important. - Local privilege checks finish the job. Hints - Ensure that you are enumerating th...</description><pubDate>Tue, 20 Aug 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Linux</category><author>Eddison King</author></item><item><title>HTB Writeup - Devel</title><link>https://adversarial.work/blog/writeup-devel/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-devel/</guid><description>**No Spoilers Hints** - FTP and web content share the same writable surface. - Think legacy Windows web-service flaws after that. Enumeration nmap to start o...</description><pubDate>Sun, 18 Aug 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Windows</category><author>Eddison King</author></item><item><title>HTB Writeup - Bashed</title><link>https://adversarial.work/blog/writeup-bashed/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-bashed/</guid><description>**No Spoilers Hints** - Hunt the developer-only path hidden from normal browsing. - A scheduled script changes hands in a writable directory. Enumeration We...</description><pubDate>Sun, 28 Jul 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Linux</category><category>Bash</category><category>Web</category><author>Eddison King</author></item><item><title>HTB Writeup - Legacy</title><link>https://adversarial.work/blog/writeup-legacy/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-legacy/</guid><description>**No Spoilers Hints** - Old Windows networking is the whole story. - A classic SMB-era flaw fits the banner. Enumeration We start with an nmap as usual: We s...</description><pubDate>Sun, 28 Jul 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>SMB</category><category>MS08-067</category><category>CVE-2008-4250</category><author>Eddison King</author></item><item><title>HTB Writeup - Optimum</title><link>https://adversarial.work/blog/writeup-optimum/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-optimum/</guid><description>**No Spoilers Hints** - Simple file-serving software is the real target. - Banner versioning points to a classic Windows flaw. Enumeration We start with an n...</description><pubDate>Sun, 28 Jul 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Linux</category><category>Web</category><author>Eddison King</author></item><item><title>HTB Writeup - Blue</title><link>https://adversarial.work/blog/writeup-blue/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-blue/</guid><description>**No Spoilers Hints** - SMB versioning tells you almost everything here. - Patch-level Windows flaws beat brute-force enumeration. Background Just from the n...</description><pubDate>Fri, 26 Jul 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Windows</category><category>EternalBlue</category><author>Eddison King</author></item><item><title>HTB Writeup - Netmon</title><link>https://adversarial.work/blog/writeup-netmon/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-netmon/</guid><description>**No Spoilers Hints** - Monitoring software often stores sensitive configuration. - FTP and web management should both be checked. Enumeration We start of wi...</description><pubDate>Fri, 26 Jul 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>PRTG Network Monitor</category><category>FTP</category><author>Eddison King</author></item><item><title>HTB Writeup - IClean</title><link>https://adversarial.work/blog/writeup-iclean/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-iclean/</guid><description>**No Spoilers Hints** - Template rendering and serialization both deserve scrutiny. - Configuration files may reveal the useful pivot. Enumeration Firstly, w...</description><pubDate>Mon, 22 Jul 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>XSS</category><category>MySQL</category><category>SSTI</category><category>Jinja2</category><category>Python</category><author>Eddison King</author></item><item><title>HTB Writeup - Runner</title><link>https://adversarial.work/blog/writeup-runner/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-runner/</guid><description>**No Spoilers Hints** - CI/CD infrastructure is the real attack surface. - Backup and container features both matter. Enumeration As usual, we start off with...</description><pubDate>Fri, 19 Jul 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>TeamCity</category><category>Docker</category><category>Portainer</category><author>Eddison King</author></item><item><title>HTB Writeup - Cascade</title><link>https://adversarial.work/blog/writeup-cascade/</link><guid isPermaLink="true">https://adversarial.work/blog/writeup-cascade/</guid><description>**No Spoilers Hints** - Null sessions still matter on this domain controller. - Shares and directory services hide the first clues. Breaking In Starting off...</description><pubDate>Fri, 05 Jul 2024 00:00:00 GMT</pubDate><category>HTB</category><category>writeup</category><category>Active Directory</category><author>Eddison King</author></item><item><title>AI and the Primates That Forgot How to Make Fire</title><link>https://adversarial.work/blog/ai-and-the-primates-that-forgot-how-to-make-fire/</link><guid isPermaLink="true">https://adversarial.work/blog/ai-and-the-primates-that-forgot-how-to-make-fire/</guid><description>AI and the primates that forgot how to make fire There&apos;s no denying that AI is an incredibly disruptive technology. Disruptive. Or whatever fancy words marke...</description><pubDate>Sun, 05 Nov 2023 03:33:00 GMT</pubDate><category>ai</category><category>rant</category><author>Eddison King</author></item></channel></rss>