
Hi, I’m Surajit — known online as blackXploit.
I’m a BCA student passionate about cybersecurity, Linux, and web application security.
This is where I document what I learn while solving Hack The Box and TryHackMe machines, competing in CTFs, experimenting with web technologies, and building practical projects — mostly on the backend side of things.
Well, everyone’s a developer until a script kiddie gets a remote shell on their machine. So instead of chasing pixel-perfect UIs, I focus on secure development — rate limiting, manual auth systems, business logic, secure file upload systems — because design really isn’t my thing.
btw what you’ll find here
- Hack The Box & CTF Writeups
- Linux & Windows Privilege Escalation
- Web Exploitation
- Enumeration Techniques
- Security Research
- OSINT & Digital Forensics — what I love the most
- Linux Notes & Networking
- Security Tools
I’m currently learning:
- AWS Penetration Testing
- Advanced Enumeration
- Active Directory
Thanks for visiting!
Latest Writeups & Articles
All Writeups & Articles (26)
-
HTB Support Writeup | SMB Share Loot → Hardcoded LDAP Creds → LDAP Password Leak → RBCD → DCSync Domain Compromise
Overview -
HTB DanglingTree Writeup | SMB Enumeration to Windows Admin Center RCE to Domain Compromise
HTB DanglingTree Writeup -
HTB Cohort Writeup | SSRF to Marimo Pre-auth RCE (WS Terminal) to Root via PackageKit LPE (CVE-2026-41651)
Overview -
HTB Enigma Writeup | OpenSTAManager RCE (CVE-2025-69212) to Root via OliveTin
Overview -
HTB Devhub Writeup | MCPJam RCE (CVE-2026-23744) to Root via Jupyter Notebook
Overview -
HackSmarter AWS Privilege Escalation Lab | wp2shell RCE to Secrets Manager
HackSmarter AWS + wp2shell Lab Writeup [ second ] -
HTB BedSide Writeup | PDFMiner LFI (CVE-2025-64512) to Root via PyTorch Deserialization
Overview -
Why You Should Never Blindly `sudo dpkg -i` Unknown .deb Files
Why You Should Never Blindly sudo dpkg -i Unknown .deb Files -
Hack The Box Paperwork Writeup | Complete HTB Walkthrough (LPD, PJL & Privilege Escalation)
A complete Hack The Box Paperwork writeup with step-by-step exploitation, LPD command injection, PJL path traversal, SCM_RIGHTS privilege escalation, and root access. -
Hack The Box Reactor Writeup | Complete HTB Walkthrough & Privilege Escalation
A detailed Hack The Box Reactor writeup covering reconnaissance, exploitation, privilege escalation, and full machine compromise. -
Hack The Box Helix Writeup | Complete HTB Walkthrough & Privilege Escalation
A detailed Hack The Box Helix writeup with reconnaissance, exploitation, privilege escalation, and full machine compromise. -
No VPS? No Problem - Catch Reverse Shells Without a VPS
Disclaimer This post is intended for educational purposes only. Only use these techniques on systems you own or have explicit written permission to test. Unauthorized access is illegal.... -
Google Colab Hack
want to get a free cloud based vm not fully but yes..kind of vm. -
HTB – Snapped
Initial Enumeration -
Hack The Box Devarea Writeup | Complete HTB Walkthrough & Privilege Escalation
A detailed Hack The Box Devarea writeup with reconnaissance, exploitation, privilege escalation, and full machine compromise. -
HTB – CCTV
-
CVE-2026-20841
Guys , another stupid CVE was disclosed in Windows Notepad that allows command execution via crafted Markdown links. scary and stupid right ? -
HTB-Facts
-
CVE-2026-24061
Telnet’s Backdoor: How a Simple Argument Injection Let Anyone Be Root -
THM - BackTrack
after getting the target ip i first run rustscan -
HTB – MonitorsFour
HTB MonitorsFour: From Web App to Windows Host -
HTB – Expressway
Expressway: HackTheBox Writeup -
THM-Classic Passwd Challenge
-
THM-HaskHell Challenge
-
Running Windows Apps on Linux with Wine & Bottles
Running Windows Apps on Linux with Wine & Bottles -
Welcome to Portfolio V-10
I’m kinda lazy when it comes to frontend stuff. Playing with design, CSS, all that… not really my thing.
Page 1 of 1