<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>CyberStefan — CTF Writeups</title>
  <subtitle>HackTheBox &amp; TryHackMe writeups: recon, exploitatie en privilege escalation.</subtitle>
  <link href="https://cyberstefan.nl/feed.xml" rel="self"/>
  <link href="https://cyberstefan.nl/writeups/"/>
  <id>https://cyberstefan.nl/</id>
  <updated>2026-06-02T00:00:00Z</updated>
  <author><name>CyberStefan</name><uri>https://cyberstefan.nl</uri></author>
  <entry>
    <title>MonitorsFour — HackTheBox CTF Writeup</title>
    <link href="https://cyberstefan.nl/writeup/monitorsfour/"/>
    <id>https://cyberstefan.nl/writeup/monitorsfour/</id>
    <updated>2026-06-02T00:00:00Z</updated>
    <summary>HackTheBox — MonitorsFour (Easy) Writeup MonitorsFour is an easy Windows machine (10.129.7.65). We leak the user database through a PHP type juggling…</summary>
    <category term="HackTheBox"/>
    <category term="Easy"/>
  </entry>
  <entry>
    <title>Eighteen — HackTheBox CTF Writeup</title>
    <link href="https://cyberstefan.nl/writeup/eighteen/"/>
    <id>https://cyberstefan.nl/writeup/eighteen/</id>
    <updated>2026-05-19T00:00:00Z</updated>
    <summary>HackTheBox — Eighteen (Easy) Eighteen is a Windows Server 2025 Domain Controller. The chain starts small: HTB creds for , an MSSQL impersonate to , a…</summary>
    <category term="HackTheBox"/>
    <category term="Easy"/>
  </entry>
  <entry>
    <title>Support — HackTheBox CTF Writeup</title>
    <link href="https://cyberstefan.nl/writeup/support/"/>
    <id>https://cyberstefan.nl/writeup/support/</id>
    <updated>2026-04-30T00:00:00Z</updated>
    <summary>HackTheBox — Support (Easy) Support is an AD box. The chain is long but every link is small: an anonymous SMB share, a .NET binary with a hardcoded LDAP…</summary>
    <category term="HackTheBox"/>
    <category term="Easy"/>
  </entry>
  <entry>
    <title>Busqueda — HackTheBox CTF Writeup</title>
    <link href="https://cyberstefan.nl/writeup/busqueda/"/>
    <id>https://cyberstefan.nl/writeup/busqueda/</id>
    <updated>2026-04-04T00:00:00Z</updated>
    <summary>HackTheBox — Busqueda (Easy) Recon Just 22 and 80. Port 80 redirected to , so I added that to first (forgot to, got a connection error, then remembered —…</summary>
    <category term="HackTheBox"/>
    <category term="Easy"/>
  </entry>
  <entry>
    <title>Cap — HackTheBox CTF Writeup</title>
    <link href="https://cyberstefan.nl/writeup/cap/"/>
    <id>https://cyberstefan.nl/writeup/cap/</id>
    <updated>2026-04-04T00:00:00Z</updated>
    <summary>HackTheBox — Cap (Easy) Recon FTP, SSH and a web app on 80: vsftpd 3.0.3 on 21, OpenSSH 8.2p1 on 22, and Gunicorn serving a &quot;Security Dashboard&quot; on 80.…</summary>
    <category term="HackTheBox"/>
    <category term="Easy"/>
  </entry>
  <entry>
    <title>Sau — HackTheBox CTF Writeup</title>
    <link href="https://cyberstefan.nl/writeup/sau/"/>
    <id>https://cyberstefan.nl/writeup/sau/</id>
    <updated>2026-04-01T00:00:00Z</updated>
    <summary>HackTheBox — Sau (Easy) Recon Started with a full port scan, like always: Three things came back: 22 (SSH), 80 as , and 55555 running a Golang HTTP…</summary>
    <category term="HackTheBox"/>
    <category term="Easy"/>
  </entry>
</feed>
