// ctf · mars
Writeups
25 TryHackMe rooms. Step-by-step methodology, from enumeration to root.
TryHackMe Profile
0xb0rn3
All rooms below are documented with full attack methodology from initial recon to root.
Pickle Rick
Web enumeration and command injection on a Rick and Morty themed challenge.
Agent Sudo
Steganography chain and CVE-2019-14287 — a sudo privilege bypass without a password.
Bounty Hacker
FTP enumeration, SSH brute-force, and a classic sudo privilege escalation.
Simple CTF
SQL injection for initial access, followed by sudo abuse for root.
Sticker Shop
Stored XSS exploitation to exfiltrate session data and capture the flag.
Hidden Deep Into My Heart
Web enumeration and directory brute-forcing to uncover hidden flags.
W1seGuy
XOR cipher analysis and key recovery through frequency analysis.
0Day
Custom exploit development chain targeting a vulnerable web service for RCE.
Attacktive Directory
Active Directory enumeration, Kerberoasting, and full domain compromise.
Biohazard
Multi-stage challenge: web enumeration, steganography, and encoding chains.
Cheese
Web application exploitation and post-exploitation privilege escalation.
Chill Hack
Web foothold via command injection, then Docker container escape to root.
Crypto Failures
Exploiting weak cryptography in a web application to gain unauthorized access.
Dogcat
PHP LFI vulnerability escalated to RCE via Apache log poisoning.
Ghizer
Multi-vulnerability chain from web foothold through to root escalation.
Rabbit Store
SSRF, JWT manipulation, and privilege escalation chained for full root compromise.
Relevant
Windows SMB enumeration and token impersonation for privilege escalation.
Rootme
Web shell upload to initial access, then SUID binary abuse for root.
Silver Platter
Service enumeration leads to credential exposure and a clear path to root.
UltraTech
API command injection followed by Docker socket abuse for container escape.
VulnNet: Internal
Internal service enumeration across NFS, Redis, and SMB to full compromise.
Wgel CTF
WordPress enumeration leads to SSH key exposure, then sudo privilege escalation.
Wonderland
Alice in Wonderland themed privilege escalation chain involving PATH hijacking.
Year of the Pig
Custom web application exploitation chained with Linux privilege escalation.
Snowy Armageddon
Advent of Cyber 2023 side quest — extended multi-stage challenge chain.