Jonas ZielkeJZ
HomeProjectsWriteupsContact
Let's Talk
HomeProjectsWriteupsContact
Let's Talk
Hack The Box

Writeup Catalog

Documented attack paths, enumeration, and lessons learned from retired Hack The Box machines – available in English and German.

Writeup available
LinuxInsane3 Jul 2025

Zero

An Insane Linux machine involving SFTP-hosted pages, an .htaccess file-read primitive, leaked SSH credentials, and an abusable Apache configuration check.

SFTP.htaccessApacheArbitrary File Read
Writeup available
LinuxMedium18 Jun 2026

Interpreter

Mirth Connect leads to RCE through CVE-2023-43208; database credentials, a cracked PBKDF2 hash, and f-string injection then provide root access.

Mirth ConnectCVE-2023-43208DeserializationMariaDB
Writeup available
LinuxHard20 Mar 2026

Snapped

An unauthenticated Nginx-UI backup provides the foothold; a TOCTOU race between snap-confine and systemd-tmpfiles enables escalation to root.

Nginx-UICVE-2026-27944CVE-2026-3888TOCTOU
Writeup available
LinuxMedium11 May 2026

Fireflow

A Langflow RCE leads to leaked credentials, JWT algorithm confusion, a malicious MCP tool, and ultimately compromise of the Kubernetes host.

LangflowCVE-2026-33017MCPJWT
Writeup available
WindowsInsane14 May 2026

Odyssey

An extensive Insane Windows chain spanning NoSQL injection, WebAuthn, prototype pollution, MSSQL, dMSA Ouroboros, and unsafe YAML deserialization.

WebAuthnNoSQLPrototype PollutionActive Directory
Jonas ZielkeDeveloper & Security Enthusiast
© 2026 Jonas Zielke. All rights reserved.
HomeProjectsWriteupsContactSitemapImpressumDatenschutz