0xdf

@0xdf.bsky.social

Principal Training Architect @ HackTheBox CTF Addict "Potentially a legit researcher" he/him Website: https://0xdf.gitlab.io/ YouTube: https://www.youtube.com/c/0xdf0xdf Twitter: 0xdf_ Discord: 0xdf Mastadon: 0xdf@infosec.exchange

MonitorsFour from @hackthebox.bsky.social features PHP type juggling to dump users, CVE-2025-24367 for RCE in Cacti, and CVE-2025-9074 to abuse the Docker Desktop API and mount the Windows host drive for root. Beyond Root: a shell on Windows." 0xdf.gitlab.io/2026/05/23/h...

HTB: MonitorsFour

MonitorsFour continues the Monitors series, this time on a Windows host. A company website exposes an authenticated API endpoint that returns every employee’s record. I’ll bypass auth with a PHP type ...

0xdf.gitlab.io