<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Hack-the-Box on Leandro&#39;s Code Cave</title>
    <link>https://iamleandrooooo.github.io/tags/hack-the-box/</link>
    <description>Recent content in Hack-the-Box on Leandro&#39;s Code Cave</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 21 May 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://iamleandrooooo.github.io/tags/hack-the-box/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>FireFlow - Chaining Langflow RCE, JWT Abuse, and Kubernetes nodes/proxy to Root an HTB Box</title>
      <link>https://iamleandrooooo.github.io/posts/fireflow_fullpwn/</link>
      <pubDate>Thu, 21 May 2026 00:00:00 +0000</pubDate>
      <guid>https://iamleandrooooo.github.io/posts/fireflow_fullpwn/</guid>
      <description>Challenge Description Difficulty: 🟡 Medium&#xA;Since Full Pwn challenges don&amp;rsquo;t have a description like other challenges, here&amp;rsquo;s a recipe for a great Cozido à Portuguesa:&#xA;Ingredients 500 g beef 1/2 chicken Pork ribs and pork ear 1 chouriço 1 morcela 1 farinheira Potatoes Carrots Cabbage Rice Salt and pepper Instructions Add the beef, chicken, and pork to a large pot with water, salt, and pepper. Boil and simmer for about 1.</description>
    </item>
    <item>
      <title>Dudsat - Reversing a Doppler-Disguised Permutation Cipher</title>
      <link>https://iamleandrooooo.github.io/posts/dudsat_reverse/</link>
      <pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate>
      <guid>https://iamleandrooooo.github.io/posts/dudsat_reverse/</guid>
      <description>Challenge Description Category: Reverse Engineering&#xA;Difficulty: 🟡 Medium&#xA;Networks trust its timing. So does a clearing system that moves money across four countries. Six weeks ago someone quietly bought ORBIT-9. Last week the clearing system froze for eleven hours. Yesterday a regional airport logged position drift during a HELIOS-7 pass. Not accidents. Tests. A burned asset codenamed FERRYMAN pulled one file off an ORBIT-9 maintenance laptop before going dark. A binary, lbproc, described internally as a link budget validation tool.</description>
    </item>
    <item>
      <title>Sysprobe - Five Layers of Onion, One DFT, One Flag</title>
      <link>https://iamleandrooooo.github.io/posts/sysprobe_reverse/</link>
      <pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate>
      <guid>https://iamleandrooooo.github.io/posts/sysprobe_reverse/</guid>
      <description>Challenge Category: Reverse Engineering&#xA;Difficulty: 🔴 Hard&#xA;Task Force Nightfall has intercepted a binary pulled from a compromised monitoring node inside a critical infrastructure operator. On the surface it is exactly what it claims to be - a routine diagnostics utility, the kind deployed silently across thousands of managed endpoints. Clean signature, legitimate-looking output, nothing that trips an alert. But the node it was found on had no business running it.</description>
    </item>
  </channel>
</rss>
