Writeups & technical research
603 published writeups, synced live from my GitBook — publish a new page there and it appears here automatically. Every page renders the complete README: screenshots, network diagrams, payloads, code blocks and spoiler blocks, exactly as written.
Showing 603 of 603 writeups
About
1
HTB - Writeups
10
- Nanocorp HTB - HackTheBox Writeup
- CCTV HTB - Hack The Box Writeup
- Interpreter HTB - HackTheBox Writeup | By Alham Rizvi
- MonitorsFour HTB — HackTheBox Writeup
- Pterodactyl HTB — HackTheBox Writeup
- Overwatch HTB — HackTheBox Walkthrough
- Support HTB — HackTheBox Walkthrough
- Principal — HTB Walkthrough |HackTheBox
- VariaType — HTB Walkthrough | HackTheBox
- Facts — HTB Walkthrough | HackTheBox
HTB - CPTS Path
6
PicoCTF Writeups
308
- README
- picoCTF Writeups By Alham Rizvi
- Binary Exploitation
- Buffer Overflow 0
- Buffer Overflow 1
- Buffer Overflow 2
- CVE-XXXX-XXXX
- Clutter Overflow
- Format String3
- Format Strings 0
- Format string 2
- Heap0
- Local Target
- PIE time2
- PIe time
- Quizploit
- RPS
- Vault-door-1
- babygam01
- basic-file-exploit
- flag leak
- format string 1
- hash-only-1
- hash-only-2
- heap 2
- heap
- heap3
- picker IV
- stonks
- two-sum
- wne
- Cheatshi(ee)ts
- assemblybasics
- Cryptography
- PicoCTF – RSA Pop Quiz Writeup
- b00tl3grsa3
- b00tl3grsa4
- clusterRSA
- crack_the_power
- customencryption
- easy1
- Mini RSA – PicoCTF Writeup
- MiniRSA - PicoCTF Walkthrough | Cryptography
- rsa_oracle — picoCTF 2024 Solution (Simple Writeup)
- sharedsecrets
- small_trouble
- stegoRSA
- timestampped-secrets
- General Skills
- 1_wanna_b3_a_r0ck5tar
- ABSOLUTE NANO
- PW Crack 3
- PW Crack 5
- PW Crack4
- Password profiler
- bytemancy 0
- bytemancy 1
- first_grep
- multicode
- mus1c
- my git
- piece by piece
- ping-cmd
- Printer Shares — Writeup
- serpentine
- sudo-make-me-a-sandwich
- undo
- Reverse Engineering
- 0. README
- ARMssembly 0
- ARMssembly 1
- ARMssembly 2
- ARMssembly3
- ARMssembly4
- ASCII FTW
- B1ll_Gat35
- Binary Instrumentation 1
- Short Write-up (Part 2)
- Binary Instrumentation 4
- Binary Instrumentation 3.md
- Bit-O-Asm-1
- Bit-O-Asm-2
- Bit-O-Asm-3
- Bit-O-Asm-4
- Bypass Me — picoCTF 2026
- Classic Crackme 0x100
- Easy As GDB
- FactCheck
- Fresh Java
- GDB baby step 4
- GDB test Drive
- Hidden Cipher 1
- Hidden Cipher 2
- Let's get Dynamic
- M1n10n’5_53cr37
- No Way Out
- OTP implementation
- Perplexed
- Picker 2
- Picker 3
- Pico Bank
- Quantum Scrambler
- Ready Gladiator 0
- Ready Gladiator 1
- Ready Gladiator 2
- Rolling My Own
- Safe Opener 2
- Safe Opener
- Secure Password Database
- Silent Stream
- Tap into hash
- The Add ON trap
- Virtual Machine 0
- Virtual Machine 1
- asm1
- asm2
- asm3 Writeup
- asm4 Writeup
- autorev1
- bbbbloat
- bloat.py
- breadth
- checkpass
- chronohack
- crackme.py
- droids0
- droids1
- droids2
- droids3
- droids4
- file run 2
- file-run1
- forky
- gatekeeper
- gogo
- keygenme
- keygenme.py
- matrix
- need_for_speed
- not-crypto
- packer
- patchme.py
- picker 1
- powershelly
- reverse
- reverse_cipher
- Riscy Business writeup
- shop
- timer
- transformation
- unpackme
- unpackme.py
- vault-door-4
- vault-door-5
- vault-door-6
- vault-door-7
- vault-door-8
- vault-door3
- wierdsnake
- wizardalike
- forensics
- 1000.tar
- picoCTF – Metadata Timestamp Fix (Fast Writeup)
- Event_viewing
- Invisible Words
- Lookey
- Scrambled Bytes
- Side Channel
- Surfing The Waves
- Unforgotten bits
- advanced-potion-making
- b1g_Mac
- Bitlocker-1 Writeup
- c0rrupt
- can_you_see
- corrupted_file
- Disko 4
- endian-v2
- enhance!
- file_types
- Find and Open
- flag_in_flame
- forensics-git-0
- forensics-git-2
- glory_of_the_garden
- hide_me
- hideme
- information
- Investigation Encoded 2.md
- Investigation Encoded 1
- Simple Solution Explanation
- macrohard_weakedge
- matryoshuka_doll
- mobpsycho
- msb
- pcappoisoning
- secret_of_the_polygot
- So meta
- st3g0
- torrentanalyze
- tunn3l_v1s1on
- verify
- what_lies_within
- How I Found the Flag
- wierd_file
- .wav
- moonwalk2
- binary
- binary_digits
- disk
- DISKO2
- Pitter, Patter, Platters
- dear-diary
- disk_disk_sleuth
- disk_disk_sleuth2
- Disko 3
- forensics-git-3
- operation_oni
- operation_orchid
- sleuth_intro
- sleuthkit_apprentice
- timeline0
- Disk Forensics Writeup
- pcap
- Ph4nt0m_1ntrud3r
- Wireshark twoo twooo two twoo..
- Wireshark_doo_dooo_do_doo..
- eavesdrop
- packet_primer
- rogue_tower
- shark_on_wire1
- shark_on_wire2
- trivial-flag-transfer-protocol
- Phase 1: Checking the Network Traffic
- webnet0
- webnet1
- wpa-ingout
- redaction_gone_wrong
- reverse
- Investigative Reversing 1
- Investigative Reversing 2
- Investigative Reversing 3
- Investigative Reversing 4
- investigative reversing
- web exploitation
- Crack the gate 2
- Credential Stuffing — picoCTF 2026
- Fool the lockout
- Fool-the-Lockout
- Hashgate
- Irish-name-repo 3
- JaWT-scratchpad
- picoCTF — Most Cookies
- North-South writeup
- Notepad
- PicoCTF — ORDER ORDER Writeup
- Old Sessions
- SQL Map 1
- Secret Box
- Some Assembly Required 3
- Some Assembly Required 4
- Startup Company
- Super_Serial
- Web Gauntlet 2 — Filtered SQLite Injection Challenge #2
- X marks the spot
- byp4ss3d
- client-side-again
- **Challenge: Findme
- forbiddenpaths
- head-dump
- introtoburp
- login
- milkslap
- picoCTF — More Cookies
- more-cookies
- no-FA
- noted
- some-assembly-required1
- some-assembly-required2
- web-gauntlet-3
- Hack The Box
- Challenges
- AI & ML
- HTB Challenge SpinGlassBrain
- Forensics
- Diagonastic
- EMO
- Fishy HTTP
- Red Failure
- RedTrails
- HTB Forensics — Reminiscent
- Suspicious threat
- TrueSecrets
- Reversing
- ARMs Race
- Behind The Scenes
- Cyberpsychosis
- Rega's Town
- SPEC
- Simple Encryptor
- SpookyPass
- Machines
- Principal
- Sherlocks
- Malware Analysis
- Antarctica
- Lupin
Active Directory
25
- ACL Abuse in Active Directory
- Kerberos Fundamentals
- Page 2
- Deleted AD Objects & ACL Persistence
- Malicious VSIX Extensions via Writable SMB Shares
- Rubeus tgtdeleg — TGT Extraction Without Plaintext Credentials
- DMSA BadSuccessor — CVE-2025-26708
- Password Reuse
- LDAP Credential Capture via Application Misconfiguration
- Page 1
- ADCS ESC Vulnerabilities - Active Directory Certificate Services
- VMware Snapshot Memory Forensics
- AV Evasion Fundamentals
- Kerberos Authentication & Protected Users
- 02. NTLM Disabled
- 03. ADCS Overview
- 04. ESC13
- 05. Forest Trusts
- 06. Network Pivoting
- 07. gMSA Abuse
- 08. DACL Abuse
- 09. Group Scope
- 10. Cross Forest Tickets
- 11. ESC1
- 12. Cert Auth NT Hash
Binary Exploitation
61
- Binary Exploitation Learning Repository
- Binary Exploitation — The Basics
- Command Injection in Binary Exploitation
- Challenge
- hard
- Solution
- medium
- solution
- Integer Overflow in Binary Exploitation
- Challenge
- Challenge 1 — Easy: "The Vault"
- solution
- Challenge 3 — Hard: "The Scoreboard"
- solution
- Challenge 2 — Medium: "The Warehouse"
- solution
- 04. Stack Overflow
- Stack Overflow Vulnerability — Complete Theory Guide
- README.md: Understanding ret2win (The "Hello World" of Exploitation)
- ret2shellcode in Stack Overflow
- 04. ret2libc
- Stack Overflow Protections
- challenge
- easy
- solution1
- ret2shellcode
- chall1
- ret2win
- chall1
- chall2
- ROP
- ROP 01 — Fundamentals
- ROP 02 — Gadgets
- ROP 03 — Chain Construction
- ROP 04 — Techniques
- ROP 05 — Worked Examples
- 0x0A — Global Offset Table (GOT) and Procedure Linkage Table (PLT)
- 0x0B — Understanding ASLR and Its Bypass
- 0x0C — Return to PLT (Ret2PLT)
- 0x0D — Return to Syscall (Ret2Syscall)
- 0x0E — Sigreturn Oriented Programming (SROP)
- 0x0F — Return to CSU (Ret2CSU) and One Gadget
- 0x10 — Stack Pivoting
- 0x11 — Understanding Format String Vulnerability
- 14. Arbitary READ Write
- 0x12 — Arbitrary Read Using Format String Vulnerability
- 0x13 — Arbitrary Write Using Format String Vulnerability
- 0x14 — GOT Overwrite Attack Using Format String Vulnerability
- 0x15 — Format String + Buffer Overflow
- 0x16 — Understanding Heap: Malloc, Free, and Tcache
- 0x17 — Use-After-Free (UAF) Vulnerability — Tcache
- 0x18 — Double Free Vulnerability — Tcache
- CTF Binary Exploitation Toolkit
- cheatsheets
- Binary Exploitation CTF — Master Cheatsheet
- Pwntools Complete Cheatsheet
- GDB + pwndbg + peda Cheatsheet
- ROP (Return-Oriented Programming) Cheatsheet
- Heap Exploitation Cheatsheet
- Format String Vulnerability Cheatsheet
- Shellcode & Syscall Cheatsheet
Exploit Development
17
- ExploitDevelopment
- Cheatsheets
- Stack Buffer Overflow — Scripts & Commands Cheatsheet
- OSED Egghunter — Full Linux Cheatsheet + Scripts
- GDB + GEF Full Cheatsheet — Exploit Development & OSED
- WinDbg Cheatsheet — Exploit Development
- OSED Prep: Overcoming Space Restrictions — Egghunters
- Format String Specifier Attacks
- exploitation steps
- Reverse Engineering & Bug Hunting — OSED Study Reference
- SEH-Based Buffer Overflow — OSED Deep Dive
- Shellcode from Scratch — OSED Study Reference
- Stack Buffer Overflows — Complete OSED-Level Guide
- Finding JMP ESP Address
- Finding Offsets in SBO
- Writing an Exploit 1
- Stack Overflows & DEP/ASLR Bypass — Full OSED Reference
Linux Privelege Escalation
4
Cryptography
92
- README
- Basics
- 01.Basics-of-cryptography
- 02.Symmetric-Asymmetric-cryptography
- 03.Cryptanalysis
- 04.Bruteforce-Attacks
- Cheatsheets
- Hashing, AES, XOR, Encoding Cheat Sheet
- Operators
- Ciphers
- Caesar Cipher – Complete Notes
- Monoalphabetic Cipher
- Hashing
- 01. Structure
- Introduction to Hashing
- Hash Properties
- 04. One Way and Encryption
- 04_use_cases.md
- 06. Hashing Types 1
- 07. MD5
- 08. SHA-1
- 09. SHA-2
- 10. SHA-3
- 11. blake2
- 12. whirlpool
- 13. Ripemd-160
- 14. CRC32
- 13_murmurhash.md — MurmurHash
- 16. merkle damgard
- 15_sponge_construction.md — Sponge Construction (Deep Dive)
- 16_padding_rules.md — Padding Rules (Deep Dive)
- bcrypt
- 19. Compression Functions
- scrypt
- Argon2
- 20. bcrypt
- Salting
- Pepper
- Key Stretching
- Hexadecimal (Hex) Encoding
- Base64 Encoding
- Base32 Encoding
- ASCII
- Binary
- Preimage Attack
- Second Preimage Attack
- Collision Attack
- Avalanche Effect
- Brute Force Attack
- Dictionary Attack
- Hybrid Attack
- Rainbow Tables
- Collision Attack (Advanced)
- Chosen-Prefix Collision Attack
- Length Extension Attack
- Hash Flooding (HashDoS)
- 41. HMAC (Hash-based Message Authentication Code)
- 42. MAC vs Hash
- 43. Timing Attack on MAC
- 44. Hash Identification
- 45. Cracking Strategies
- 46. Common CTF Hash Tricks
- 47. Mixed CTF Hash Patterns
- 48. Hashcat
- 49. John the Ripper
- 50. CyberChef
- 51. HashPump
- 52. Online Hash Tools
- 57. Hash Types Reference Table
- RSA
- 02. Basic Enc and Dec
- 03. Breaking RSA
- 04. Small Exponent Attack
- Fermat Factorization Attack (Close Primes)
- 06. Common Modulus Attack
- CRT Attack (Håstad’s Broadcast Attack)
- Wiener’s Attack (Small d Attack)
- dp Leak Attack — Deep Explanation
- Partial d Exposure Attack
- 11. Franklin-Reiter Attack
- Short Pad Attack (Low Exponent + Small Padding)
- Known Prefix Attack (Structured Message Attack)
- Generalized Håstad Attack
- LSB Oracle Attack (Least Significant Bit Oracle)
- Boneh–Durfee Attack (Very Small d)
- Padding Oracle Attack (Bleichenbacher Attack)
- Timing Attacks on RSA
- Manger’s Attack (RSA-OAEP Oracle Attack)
- Cheatsheets
- Attack table
- RSA full basics table
- Templates
Cool Stuff
2
Hacking Cheatsheets
2
AWS Pentesting
15
- AWS PenTest Lab — Learn Cloud Hacking from Scratch
- cheatsheets
- AWS PenTest Cheatsheet — Quick Reference
- Resources & Tools
- labs
- CloudGoat Walkthroughs
- modules
- Module 01 — IAM Enumeration & Privilege Escalation
- Module 02 — S3 Bucket Misconfigurations
- Module 03 — EC2 Metadata Service & SSRF Attacks
- Module 04 — Lambda Function Abuse
- Module 05 — Secrets Manager & SSM Parameter Store Enumeration
- Module 06 — CloudTrail Evasion & Log Tampering
- Module 07 — Cross-Account Attacks
- Module 08 — ECS & Container Escape
Web Application Pentesting
13
- 01. Cross Site Scripting
- Post-XSS Attack Techniques
- XSS Cheatsheet
- 02. Open Redirect
- 03. CRLF Injection
- 04. HTTP Headers & Request Methods
- 05. Header Injection
- 06. XML External Entity (XXE) Injection
- XXE Injection - Complete Cheatsheet
- Lab: Exploiting XXE using external entities to retrieve files
- Lab: Exploiting XXE to perform SSRF attacks
- Lab: Exploiting XInclude to Retrieve Files
- Lab Writeup: Exploiting XXE via Image File Upload
AI pentesting
6
C2 Framework
7
C++ Notes
17
- 01. C++ Basics, Variables and datatypes
- 02. Constant
- 03. Namespaces
- 04. Typedef
- 05. using (Type Alias)
- 06. Arithmetic Operators
- 07. Type Conversion
- 08. User Input
- 09. Useful Math Functions
- 10. Practice Program -Hypotenuse Calculator
- 11. Conditionals — if, else, else if
- 12. Switch Statements
- 13. Practice Program - Basic Calculator
- 14. Ternary Operator
- 15. Logical Operators — &&, ||, !
- 1/5 project: Project: BMI (Body Mass Index) Calculator
- 17. Useful String Methods
Ethical Hacking
10
- 1. What is Hacking?
- Topic 2: Vulnerability Research and Disclosure Mechanisms
- Topic 3: Reconaissance: Footprinting and Information Gathering Methodology
- Topic 4: DNS Enumeration and Domain Intelligence
- Topic 5: Social Engineering and Human Exploitation Techniques
- Topic 6: Network Scanning and Port Scanning Techniques
- Topic 7: Enumeration and Service Identification
- Topic 8: System Hacking and Privilege Escalation Concepts
- Topic 9: Cryptography and Password Security Analysis
- Topic 10: Network Sniffing and Man-in-the-Middle Attacks