<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://xxanael.github.io/xxanael-vlog/</id><title>xxa.nael</title><subtitle>Blog de cybersécurité, Write-ups CTF (OSINT, Web, Forensics, Reverse) et fiches techniques.</subtitle> <updated>2026-08-30T01:19:16+01:00</updated> <author> <name>xxanael</name> <uri>https://xxanael.github.io/xxanael-vlog/</uri> </author><link rel="self" type="application/atom+xml" href="https://xxanael.github.io/xxanael-vlog/feed.xml"/><link rel="alternate" type="text/html" hreflang="fr" href="https://xxanael.github.io/xxanael-vlog/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 xxanael </rights> <icon>/xxanael-vlog/assets/img/favicons/favicon.ico</icon> <logo>/xxanael-vlog/assets/img/favicons/favicon-96x96.png</logo> <entry><title>Hack The Box — Shocker : Writeup</title><link href="https://xxanael.github.io/xxanael-vlog/posts/HackTheBox-shocker/" rel="alternate" type="text/html" title="Hack The Box — Shocker : Writeup" /><published>2026-08-28T23:00:00+01:00</published> <updated>2026-08-29T15:20:28+01:00</updated> <id>https://xxanael.github.io/xxanael-vlog/posts/HackTheBox-shocker/</id> <content type="text/html" src="https://xxanael.github.io/xxanael-vlog/posts/HackTheBox-shocker/" /> <author> <name>xxanael</name> </author> <category term="Box" /> <category term="HackTheBox" /> <summary>Résolution de la machine Shocker sur Hack The Box : reconnaissance des services, découverte du répertoire CGI, exploitation de Shellshock pour obtenir un reverse shell et élévation de privilèges via Perl.</summary> </entry> <entry><title>Hack The Box — Bashed : Writeup</title><link href="https://xxanael.github.io/xxanael-vlog/posts/HackTheBox-bashed/" rel="alternate" type="text/html" title="Hack The Box — Bashed : Writeup" /><published>2026-08-24T23:00:00+01:00</published> <updated>2026-08-25T13:09:13+01:00</updated> <id>https://xxanael.github.io/xxanael-vlog/posts/HackTheBox-bashed/</id> <content type="text/html" src="https://xxanael.github.io/xxanael-vlog/posts/HackTheBox-bashed/" /> <author> <name>xxanael</name> </author> <category term="Box" /> <category term="HackTheBox" /> <summary>Résolution de la machine Bashed sur Hack The Box : reconnaissance des services, découverte d'un répertoire caché, exploitation d'un webshell PHP et élévation de privilèges via un script exécuté avec les privilèges de scriptmanager.</summary> </entry> <entry><title>Hack The Box — Nibbles : Writeup</title><link href="https://xxanael.github.io/xxanael-vlog/posts/HackTheBox-nibbles/" rel="alternate" type="text/html" title="Hack The Box — Nibbles : Writeup" /><published>2026-08-23T00:00:00+01:00</published> <updated>2026-08-23T00:00:00+01:00</updated> <id>https://xxanael.github.io/xxanael-vlog/posts/HackTheBox-nibbles/</id> <content type="text/html" src="https://xxanael.github.io/xxanael-vlog/posts/HackTheBox-nibbles/" /> <author> <name>xxanael</name> </author> <category term="Box" /> <category term="HackTheBox" /> <summary>Résolution de la machine Nibbles sur Hack The Box : énumération d'un CMS, contournement de blacklist, reverse shell manuel suite à l'échec de Metasploit, et élévation de privilèges via un script sudo modifiable.</summary> </entry> <entry><title>TryHackMe — Vulnversity : Writeup</title><link href="https://xxanael.github.io/xxanael-vlog/posts/TryHackMe-vulnversity/" rel="alternate" type="text/html" title="TryHackMe — Vulnversity : Writeup" /><published>2026-08-20T00:22:00+01:00</published> <updated>2026-08-20T00:22:00+01:00</updated> <id>https://xxanael.github.io/xxanael-vlog/posts/TryHackMe-vulnversity/</id> <content type="text/html" src="https://xxanael.github.io/xxanael-vlog/posts/TryHackMe-vulnversity/" /> <author> <name>xxanael</name> </author> <category term="Room" /> <category term="TryHackMe" /> <summary>Résolution de la room RootMe sur TryHackMe : contournement de blacklist d'upload, reverse shell et privilège escalation via un binaire SUID systemctl.</summary> </entry> <entry><title>Matryoshka Bits : Forensic &amp; Automatisation</title><link href="https://xxanael.github.io/xxanael-vlog/posts/DojoCTF-MatryoshkaBits/" rel="alternate" type="text/html" title="Matryoshka Bits : Forensic &amp;amp; Automatisation" /><published>2026-08-17T15:00:00+01:00</published> <updated>2026-08-17T15:00:00+01:00</updated> <id>https://xxanael.github.io/xxanael-vlog/posts/DojoCTF-MatryoshkaBits/</id> <content type="text/html" src="https://xxanael.github.io/xxanael-vlog/posts/DojoCTF-MatryoshkaBits/" /> <author> <name>xxanael</name> </author> <category term="CTF" /> <category term="Created Challenges" /> <summary>Matryoshka Bits : automatisation de l'extraction de 150 archives imbriquées en Python et reconstruction d'une image JPEG à partir de bits ASCII.</summary> </entry> </feed>
