<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Hackerspot: WriteUps]]></title><description><![CDATA[This section will share the writeups related to CTF, Challenges, HackTheBox solutions,etc.]]></description><link>https://www.hackerspot.net/s/writeups</link><image><url>https://substackcdn.com/image/fetch/$s_!o8CQ!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d62e87e-ddb5-4613-87de-9c210c430032_160x160.png</url><title>Hackerspot: WriteUps</title><link>https://www.hackerspot.net/s/writeups</link></image><generator>Substack</generator><lastBuildDate>Thu, 16 Apr 2026 23:41:59 GMT</lastBuildDate><atom:link href="https://www.hackerspot.net/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Hackerspot]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[hackerspot@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[hackerspot@substack.com]]></itunes:email><itunes:name><![CDATA[Chady]]></itunes:name></itunes:owner><itunes:author><![CDATA[Chady]]></itunes:author><googleplay:owner><![CDATA[hackerspot@substack.com]]></googleplay:owner><googleplay:email><![CDATA[hackerspot@substack.com]]></googleplay:email><googleplay:author><![CDATA[Chady]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[HTB Track - OWASP Top 10: sanitize]]></title><description><![CDATA[The OWASP Top 10 is a great starting point when learning web application security.]]></description><link>https://www.hackerspot.net/p/htb-track-owasp-top-10-sanitize</link><guid isPermaLink="false">https://www.hackerspot.net/p/htb-track-owasp-top-10-sanitize</guid><dc:creator><![CDATA[Chady]]></dc:creator><pubDate>Wed, 18 Dec 2024 04:42:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!UZ2D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc85d5dfb-a2cd-4620-8145-8458949e26b3_440x440.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The OWASP Top 10 is a great starting point when learning web application security. HackTheBox offers a track called "The OWASP Top 10," designed to teach these common vulnerabilities through hands-on challenges. In this article, I&#8217;ll walk you through the challenge called &#8220;sanitize&#8220;. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UZ2D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc85d5dfb-a2cd-4620-8145-8458949e26b3_440x440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UZ2D!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc85d5dfb-a2cd-4620-8145-8458949e26b3_440x440.png 424w, https://substackcdn.com/image/fetch/$s_!UZ2D!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc85d5dfb-a2cd-4620-8145-8458949e26b3_440x440.png 848w, https://substackcdn.com/image/fetch/$s_!UZ2D!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc85d5dfb-a2cd-4620-8145-8458949e26b3_440x440.png 1272w, https://substackcdn.com/image/fetch/$s_!UZ2D!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc85d5dfb-a2cd-4620-8145-8458949e26b3_440x440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UZ2D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc85d5dfb-a2cd-4620-8145-8458949e26b3_440x440.png" width="334" height="334" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c85d5dfb-a2cd-4620-8145-8458949e26b3_440x440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:440,&quot;resizeWidth&quot;:334,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Track Cover Image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Track Cover Image" title="Track Cover Image" srcset="https://substackcdn.com/image/fetch/$s_!UZ2D!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc85d5dfb-a2cd-4620-8145-8458949e26b3_440x440.png 424w, https://substackcdn.com/image/fetch/$s_!UZ2D!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc85d5dfb-a2cd-4620-8145-8458949e26b3_440x440.png 848w, https://substackcdn.com/image/fetch/$s_!UZ2D!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc85d5dfb-a2cd-4620-8145-8458949e26b3_440x440.png 1272w, https://substackcdn.com/image/fetch/$s_!UZ2D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc85d5dfb-a2cd-4620-8145-8458949e26b3_440x440.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1><strong>Let&#8217;s Start</strong></h1><p>Here is what the web page looks like:</p>
      <p>
          <a href="https://www.hackerspot.net/p/htb-track-owasp-top-10-sanitize">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[HTB Track - OWASP Top 10: looking glass]]></title><description><![CDATA[The OWASP Top 10 is a great starting point when learning web application security.]]></description><link>https://www.hackerspot.net/p/hack-the-box-walkthrough-looking</link><guid isPermaLink="false">https://www.hackerspot.net/p/hack-the-box-walkthrough-looking</guid><dc:creator><![CDATA[Chady]]></dc:creator><pubDate>Wed, 11 Dec 2024 04:26:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!7R5C!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb5c52e4-7763-44cb-968b-88c30e18c3ba_1600x1000.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The OWASP Top 10 is a great starting point when learning web application security. HackTheBox offers a track called "The OWASP Top 10," designed to teach these common vulnerabilities through hands-on challenges. In this article, I&#8217;ll walk you through the first challenge in the OWASP Top 10 track, called "Looking Glass." solutions. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7R5C!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb5c52e4-7763-44cb-968b-88c30e18c3ba_1600x1000.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7R5C!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb5c52e4-7763-44cb-968b-88c30e18c3ba_1600x1000.png 424w, https://substackcdn.com/image/fetch/$s_!7R5C!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb5c52e4-7763-44cb-968b-88c30e18c3ba_1600x1000.png 848w, https://substackcdn.com/image/fetch/$s_!7R5C!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb5c52e4-7763-44cb-968b-88c30e18c3ba_1600x1000.png 1272w, https://substackcdn.com/image/fetch/$s_!7R5C!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb5c52e4-7763-44cb-968b-88c30e18c3ba_1600x1000.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7R5C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb5c52e4-7763-44cb-968b-88c30e18c3ba_1600x1000.png" width="1456" height="910" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/db5c52e4-7763-44cb-968b-88c30e18c3ba_1600x1000.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:910,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:90034,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7R5C!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb5c52e4-7763-44cb-968b-88c30e18c3ba_1600x1000.png 424w, https://substackcdn.com/image/fetch/$s_!7R5C!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb5c52e4-7763-44cb-968b-88c30e18c3ba_1600x1000.png 848w, https://substackcdn.com/image/fetch/$s_!7R5C!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb5c52e4-7763-44cb-968b-88c30e18c3ba_1600x1000.png 1272w, https://substackcdn.com/image/fetch/$s_!7R5C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb5c52e4-7763-44cb-968b-88c30e18c3ba_1600x1000.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Whether you&#8217;re new to &#8230;</p>
      <p>
          <a href="https://www.hackerspot.net/p/hack-the-box-walkthrough-looking">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Root me: Bash — System 1]]></title><description><![CDATA[In this post, we solve one of the &#8220;Root me&#8221; challenges called &#8220;Bash &#8212; System 1&#8221;.]]></description><link>https://www.hackerspot.net/p/root-me-bash-system-1</link><guid isPermaLink="false">https://www.hackerspot.net/p/root-me-bash-system-1</guid><dc:creator><![CDATA[Chady]]></dc:creator><pubDate>Thu, 07 Nov 2024 01:32:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ru9F!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc7dfe4-23a5-45a0-9b60-339e010baae1_697x323.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this post, we solve one of the &#8220;Root me&#8221; challenges called &#8220;Bash &#8212; System 1&#8221;. We have a binary file with SUID bit and the C code to understand the binary.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xxTY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa68655bc-0639-4ea0-95b6-9fe2bac3d4e2_902x164.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xxTY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa68655bc-0639-4ea0-95b6-9fe2bac3d4e2_902x164.png 424w, https://substackcdn.com/image/fetch/$s_!xxTY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa68655bc-0639-4ea0-95b6-9fe2bac3d4e2_902x164.png 848w, https://substackcdn.com/image/fetch/$s_!xxTY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa68655bc-0639-4ea0-95b6-9fe2bac3d4e2_902x164.png 1272w, https://substackcdn.com/image/fetch/$s_!xxTY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa68655bc-0639-4ea0-95b6-9fe2bac3d4e2_902x164.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xxTY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa68655bc-0639-4ea0-95b6-9fe2bac3d4e2_902x164.png" width="902" height="164" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a68655bc-0639-4ea0-95b6-9fe2bac3d4e2_902x164.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:164,&quot;width&quot;:902,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!xxTY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa68655bc-0639-4ea0-95b6-9fe2bac3d4e2_902x164.png 424w, https://substackcdn.com/image/fetch/$s_!xxTY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa68655bc-0639-4ea0-95b6-9fe2bac3d4e2_902x164.png 848w, https://substackcdn.com/image/fetch/$s_!xxTY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa68655bc-0639-4ea0-95b6-9fe2bac3d4e2_902x164.png 1272w, https://substackcdn.com/image/fetch/$s_!xxTY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa68655bc-0639-4ea0-95b6-9fe2bac3d4e2_902x164.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><figcaption class="image-caption">SUID bit has been enabled on ch11</figcaption></figure></div><p>The code:</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.hackerspot.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Hackerspot! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><pre><code>#include &lt;stdlib.h&gt;
#include &lt;sys/types.h&gt;
#include &lt;unistd.h&gt;

i&#8230;</code></pre>
      <p>
          <a href="https://www.hackerspot.net/p/root-me-bash-system-1">
              Read more
          </a>
      </p>
   ]]></content:encoded></item></channel></rss>