<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>thedevilhunter</title>
    <link>https://thedevilhunter.dev/</link>
    <atom:link href="https://thedevilhunter.dev/feed.xml" rel="self" type="application/rss+xml"/>
    <description>Offensive security research, Hack The Box and TryHackMe writeups, CTF solutions, and red-team notes.</description>
    <language>en-us</language>
    <lastBuildDate>Mon, 27 Jul 2026 00:00:00 GMT</lastBuildDate>
    <item>
      <title>SEKAI CTF 2026: apbq-rsa-iv</title>
      <link>https://thedevilhunter.dev/posts/sekai-ctf-2026-apbq-rsa-iv.html</link>
      <guid isPermaLink="true">https://thedevilhunter.dev/posts/sekai-ctf-2026-apbq-rsa-iv.html</guid>
      <pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate>
      <description>Three mixed RSA hints become one public lattice vector. A hidden split, a CRT-idempotent equation, and a multivariate Coppersmith construction recover the factors.</description>
      <category>crypto</category>
      <category>rsa</category>
      <category>lattice</category>
      <category>lll</category>
      <category>coppersmith</category>
      <category>crt</category>
      <category>small-roots</category>
      <category>sekai-ctf</category>
    </item>
    <item>
      <title>HTB: Devvortex</title>
      <link>https://thedevilhunter.dev/posts/htb-devvortex.html</link>
      <guid isPermaLink="true">https://thedevilhunter.dev/posts/htb-devvortex.html</guid>
      <pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
      <description>A vhost hiding a Joomla install leaks admin creds via CVE-2023-23752, which opens a PHP webshell foothold. From there, cracked MySQL hashes and a sudo-able apport-cli GTFOBin hand over root.</description>
      <category>joomla</category>
      <category>cve-2023-23752</category>
      <category>vhost-fuzzing</category>
      <category>sudo</category>
      <category>apport-cli</category>
      <category>gtfobins</category>
      <category>hashcat</category>
    </item>
    <item>
      <title>THM: Blue</title>
      <link>https://thedevilhunter.dev/posts/thm-blue.html</link>
      <guid isPermaLink="true">https://thedevilhunter.dev/posts/thm-blue.html</guid>
      <pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate>
      <description>The classic EternalBlue room. Fingerprint an unpatched Windows 7 box, fire MS17-010 through Metasploit for a SYSTEM shell, then migrate, dump hashes, and crack them offline.</description>
      <category>eternalblue</category>
      <category>ms17-010</category>
      <category>smb</category>
      <category>metasploit</category>
      <category>windows</category>
      <category>hashdump</category>
      <category>cve-2017-0144</category>
    </item>
    <item>
      <title>picoCTF: Cookie Monster</title>
      <link>https://thedevilhunter.dev/posts/ctf-web-cookie-monster.html</link>
      <guid isPermaLink="true">https://thedevilhunter.dev/posts/ctf-web-cookie-monster.html</guid>
      <pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate>
      <description>A login form that trusts a base64 cookie a little too much. Decode it, flip the admin flag, re-encode, and the flag drops straight into the response.</description>
      <category>web</category>
      <category>cookies</category>
      <category>base64</category>
      <category>authentication-bypass</category>
      <category>burp</category>
    </item>
    <item>
      <title>Building a Repeatable Enumeration Methodology</title>
      <link>https://thedevilhunter.dev/posts/building-a-methodology.html</link>
      <guid isPermaLink="true">https://thedevilhunter.dev/posts/building-a-methodology.html</guid>
      <pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate>
      <description>Most boxes aren&apos;t lost at exploitation — they&apos;re lost at enumeration. Here&apos;s the checklist-driven recon workflow I run on every target so I never miss the obvious foothold again.</description>
      <category>methodology</category>
      <category>enumeration</category>
      <category>recon</category>
      <category>nmap</category>
      <category>checklist</category>
    </item>
  </channel>
</rss>
