<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://zerotoone.initialt.pl/</id><title>zeroToOne</title><subtitle>A personal blog about learning new things in tech, programming, and hacking.</subtitle> <updated>2026-02-11T16:04:19+01:00</updated> <author> <name>Initial T</name> <uri>https://zerotoone.initialt.pl/</uri> </author><link rel="self" type="application/atom+xml" href="https://zerotoone.initialt.pl/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://zerotoone.initialt.pl/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Initial T </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>HackTheBox | Signed</title><link href="https://zerotoone.initialt.pl/posts/HTB-Signed/" rel="alternate" type="text/html" title="HackTheBox | Signed" /><published>2026-02-11T15:09:01+01:00</published> <updated>2026-02-11T15:09:01+01:00</updated> <id>https://zerotoone.initialt.pl/posts/HTB-Signed/</id> <content type="text/html" src="https://zerotoone.initialt.pl/posts/HTB-Signed/" /> <author> <name>Initial T</name> </author> <category term="CTF" /> <category term="walk-trough" /> <category term="hackthebox" /> <summary>Signed is a retired Windows machine on HackTheBox, after some initial scanning: └─$ nmap signed.htb -T5 -Pn Starting Nmap 7.95 ( https://nmap.org ) at 2025-12-28 12:21 EST Nmap scan report for signed.htb (10.10.11.90) Host is up (0.033s latency). Not shown: 999 filtered tcp ports (no-response) PORT STATE SERVICE 1433/tcp open ms-sql-s we have only mssql port open, and provided us...</summary> </entry> <entry><title>HackTheBox | Imagery</title><link href="https://zerotoone.initialt.pl/posts/HTB-Imagery/" rel="alternate" type="text/html" title="HackTheBox | Imagery" /><published>2026-02-11T15:09:01+01:00</published> <updated>2026-02-11T15:09:01+01:00</updated> <id>https://zerotoone.initialt.pl/posts/HTB-Imagery/</id> <content type="text/html" src="https://zerotoone.initialt.pl/posts/HTB-Imagery/" /> <author> <name>Initial T</name> </author> <category term="CTF" /> <category term="walk-trough" /> <category term="hackthebox" /> <summary>Imagery is finally retired machine so I can post my write-up. Nmap shows two open ports PORT STATE SERVICE 22/tcp open ssh 8000/tcp open http-alt At the port 8000 we can see web application called Imagery, which is Python Flask gallery allowing user to upload his images. Scanning for directories and files didn’t give anything useful. My first thought was to try upload some shell in...</summary> </entry> <entry><title>Yippee Ki-yay Merry Christmas</title><link href="https://zerotoone.initialt.pl/posts/Yippee-Ki-yay-Merry-Christmas/" rel="alternate" type="text/html" title="Yippee Ki-yay Merry Christmas" /><published>2025-12-21T13:00:01+01:00</published> <updated>2025-12-21T14:47:28+01:00</updated> <id>https://zerotoone.initialt.pl/posts/Yippee-Ki-yay-Merry-Christmas/</id> <content type="text/html" src="https://zerotoone.initialt.pl/posts/Yippee-Ki-yay-Merry-Christmas/" /> <author> <name>Initial T</name> </author> <category term="electronics" /> <category term="3d printing" /> <summary>Yippee Ki-yay Christmas Tree Decoration Die Hard is my wife’s and my favorite Christmas movie, so this year, inspired by the Ajaxjones project we decided to make our own version. The result was a Christmas tree decoration in the form of John McClane in the Nakatomi ventilation shaft from the first part of the film. The decoration is interactive, the lighter is actually a diode, and there is a ...</summary> </entry> <entry><title>HackTheBox | CodePartTwo</title><link href="https://zerotoone.initialt.pl/posts/HTB-CodePartTwo/" rel="alternate" type="text/html" title="HackTheBox | CodePartTwo" /><published>2025-11-15T16:26:01+01:00</published> <updated>2025-11-29T16:05:56+01:00</updated> <id>https://zerotoone.initialt.pl/posts/HTB-CodePartTwo/</id> <content type="text/html" src="https://zerotoone.initialt.pl/posts/HTB-CodePartTwo/" /> <author> <name>Initial T</name> </author> <category term="CTF" /> <category term="walk-trough" /> <category term="hackthebox" /> <summary>That was the easiest machine on HTB so far, so this is going to be a quick post. Let’s start with some scanning: └─$ nmap -p- 10.10.11.82 -T5 -Pn Starting Nmap 7.95 ( https://nmap.org ) at 2025-11-11 18:41 EST Nmap scan report for 10.10.11.82 Host is up (0.026s latency). Not shown: 65532 closed tcp ports (reset) PORT STATE SERVICE 22/tcp open ssh 8000/tcp open http-alt...</summary> </entry> <entry><title>HackTheBox | Soulmate</title><link href="https://zerotoone.initialt.pl/posts/HTB-Soulmate/" rel="alternate" type="text/html" title="HackTheBox | Soulmate" /><published>2025-11-11T20:36:00+01:00</published> <updated>2025-11-11T20:36:00+01:00</updated> <id>https://zerotoone.initialt.pl/posts/HTB-Soulmate/</id> <content type="text/html" src="https://zerotoone.initialt.pl/posts/HTB-Soulmate/" /> <author> <name>Initial T</name> </author> <category term="CTF" /> <category term="walk-trough" /> <category term="hackthebox" /> <summary>Soulmate is the Hackbox machine with two flags to catch. Starting with a regular account in the portal, I tried to register as admin and get in return, maybe it will be useful later. Registering under a different name gives us access to a panel where we have several fields to fill out in a form that appears to be invulnerable to any simple techniques. Username already exists Register pa...</summary> </entry> </feed>
