<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Htb :: Tag :: GatRoot</title><link>https://zeke.cat/en/tags/htb/index.html</link><description/><generator>Hugo</generator><language>en</language><lastBuildDate>Fri, 09 Jan 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://zeke.cat/en/tags/htb/index.xml" rel="self" type="application/rss+xml"/><item><title>Media</title><link>https://zeke.cat/en/ctf/media/index.html</link><pubDate>Fri, 09 Jan 2026 00:00:00 +0000</pubDate><guid>https://zeke.cat/en/ctf/media/index.html</guid><description>edia is unique for requiring a crafted video file for an**NTLM Leak** attack, followed by **File System Redirection** to an upload directory outside of webroot, then using **SeTcbPrivilege** to gain full system compromise.</description></item><item><title>TombWatcher</title><link>https://zeke.cat/en/ctf/tombwatcher/index.html</link><pubDate>Tue, 06 Jan 2026 00:00:00 +0000</pubDate><guid>https://zeke.cat/en/ctf/tombwatcher/index.html</guid><description>ombwatcher serves a straight forward demonstration for a **Active Directory** attack chain for **Lateral Movement**, where you discover deleted **Active Directory Objects** which contains permissions required to attack an **Active Directory Certificate Services** instance.</description></item><item><title>Pov</title><link>https://zeke.cat/en/ctf/pov/index.html</link><pubDate>Mon, 05 Jan 2026 00:00:00 +0000</pubDate><guid>https://zeke.cat/en/ctf/pov/index.html</guid><description>A demonstration of using **File Disclosure** to find sensitive keys enabling a **Object Deserialization** attack for command execution, followed by finding exposed credentials leading to **SeDebugPrivilege** abuse.</description></item><item><title>Postman</title><link>https://zeke.cat/en/ctf/postman/index.html</link><pubDate>Tue, 30 Dec 2025 00:00:00 +0000</pubDate><guid>https://zeke.cat/en/ctf/postman/index.html</guid><description>**Postman** brings exposure to a misconfigured **Redis** instance, leading into a hunt for interesting readable files, and a finale interaction through a web-based system administration tool.</description></item><item><title>Trick</title><link>https://zeke.cat/en/ctf/trick/index.html</link><pubDate>Mon, 22 Dec 2025 00:00:00 +0000</pubDate><guid>https://zeke.cat/en/ctf/trick/index.html</guid><description>Trick provides a field to practice **Web Recon** techniques, **Local File Inclusion** vulnerabilities to view environment configurations, and an interesting interaction with **Fail2Ban**.</description></item><item><title>Jeeves</title><link>https://zeke.cat/en/ctf/jeeves/index.html</link><pubDate>Wed, 17 Dec 2025 00:00:00 +0000</pubDate><guid>https://zeke.cat/en/ctf/jeeves/index.html</guid><description>Discovering your foothold through a **Jenkins** web application, a test on file enumeration and uncovering alternate data streams.</description></item><item><title>Fluffy</title><link>https://zeke.cat/en/ctf/fluffy/index.html</link><pubDate>Mon, 15 Dec 2025 00:00:00 +0000</pubDate><guid>https://zeke.cat/en/ctf/fluffy/index.html</guid><description>Fluffy provides a strong introduction into AD Certificate Services, a relevant testing tool **Certipy**, and your common **ACL** abuse.</description></item></channel></rss>