CyberSaif
/ write-ups

Hack the Box.
CTFs.

Documented guides on challenges, user access, and privilege escalation.

Hack the Box

HTB: Cohort

An easy-difficulty machine with an SSRF vulnerability that exposes internal services and is running an older version of PackageKit.

Web Exploitation · Easy Open ↗
Hack the Box

HTB: Orion

A very simple machine with vulnerable versions of Craft CMS and Telnet.

Web Exploitation · Easy Open ↗
Hack the Box

HTB: Connected

Exploiting CVE-2025-57819 in the FreePBX system, and abusing incron.d and dahdi.conf for privilege escalation.

Web Exploitation · Medium Open ↗
Hack the Box

HTB: Silentium

Easy machine running Flowise AI. It's vulnerable to CVE-2025-58434, which leaks user credentials, and CVE-2025-59528, which enables RCE through the CustomMCP node.

Web Exploitation · Easy Open ↗