Hack The Box – Percetron
Full Web Exploitation Writeup (SSRF → HAProxy Bypass → MongoDB Wire Protocol → Neo4j Cypher Injection → Command Injection → RCE)
Read the storyramveil / writeups
Short notes and writeups on security, CTFs, and bug hunting.
Full Web Exploitation Writeup (SSRF → HAProxy Bypass → MongoDB Wire Protocol → Neo4j Cypher Injection → Command Injection → RCE)
Read the storyStored XSS exploitation via polyglot WAV file upload, strict CSP bypass using script-src self, Puppeteer admin bot abuse, and flag exfiltration through agent-controlled fields.
Read the storyCSP evaluator SSRF via localhost blacklist bypass, then time-based regex (ReDoS) exfiltration against a secret validation endpoint to recover the flag.
Read the storyAbusing NaN behavior in Python JSON handling to bypass score validation and instantly claim the flag.
Read the storyWeb Exploitation Writeup (SSRF + SQLi bypass to leak internal admin secrets)
Read the storyglibc 2.23 heap exploitation with an off-by-one overflow, unsorted-bin leaks, fastbin manipulation, stack chunk placement, and __free_hook → system.
Read the story